aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Kelvin M. Klann <kmk3.code@protonmail.com>2021-01-21 04:37:34 -0300
committerLibravatar Kelvin M. Klann <kmk3.code@protonmail.com>2021-01-22 04:41:11 -0300
commitadd6ee8c23bc500c27ba9e4258be8d0f7a26945e (patch)
treef3550fd1524902113142f9fbeaf6cc6716e53601
parentrefactor nodejs applications (npm & yarn) (#3876) (diff)
downloadfirejail-add6ee8c23bc500c27ba9e4258be8d0f7a26945e.tar.gz
firejail-add6ee8c23bc500c27ba9e4258be8d0f7a26945e.tar.zst
firejail-add6ee8c23bc500c27ba9e4258be8d0f7a26945e.zip
ssh: move auth socket blacklist to disable-common.inc
That was added on the commit e93fbf3bd ("disable ssh-agent sockets in disable-programs.inc"). Currently, it's the only ssh-related entry on disable-programs.inc. Further, it seems that all the other socket blacklists live on disable-common.inc. Also, even though this socket does not necessarily allow arbitrary command execution on the local machine (like some paths on disable-common.inc do), it could still do so for remote systems. Put it above the "top secret" section, like the terminal sockets are above the terminal server section.
-rw-r--r--etc/inc/disable-common.inc3
-rw-r--r--etc/inc/disable-programs.inc1
2 files changed, 3 insertions, 1 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 0de539d57..eeafe3ec4 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -347,6 +347,9 @@ read-only ${HOME}/.local/share/mime
347# Write-protection for thumbnailer dir 347# Write-protection for thumbnailer dir
348read-only ${HOME}/.local/share/thumbnailers 348read-only ${HOME}/.local/share/thumbnailers
349 349
350# prevent access to ssh-agent
351blacklist /tmp/ssh-*
352
350# top secret 353# top secret
351blacklist ${HOME}/*.kdb 354blacklist ${HOME}/*.kdb
352blacklist ${HOME}/*.kdbx 355blacklist ${HOME}/*.kdbx
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 74cbfbcbe..2ef40b23a 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -856,7 +856,6 @@ blacklist ${HOME}/.yarncache
856blacklist ${HOME}/.yarnrc 856blacklist ${HOME}/.yarnrc
857blacklist ${HOME}/.zoom 857blacklist ${HOME}/.zoom
858blacklist /tmp/akonadi-* 858blacklist /tmp/akonadi-*
859blacklist /tmp/ssh-*
860blacklist /tmp/.wine-* 859blacklist /tmp/.wine-*
861blacklist /var/games/nethack 860blacklist /var/games/nethack
862blacklist /var/games/slashem 861blacklist /var/games/slashem