aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2020-01-02 20:58:56 +0000
committerLibravatar GitHub <noreply@github.com>2020-01-02 20:58:56 +0000
commit4bb5f58ae402cc2c03aeea538c15e509b1744c2f (patch)
treece9bb3aea8b345ccae0429be3a01b2a0916702c6
parentHarden artha.profile (diff)
downloadfirejail-4bb5f58ae402cc2c03aeea538c15e509b1744c2f.tar.gz
firejail-4bb5f58ae402cc2c03aeea538c15e509b1744c2f.tar.zst
firejail-4bb5f58ae402cc2c03aeea538c15e509b1744c2f.zip
Additional hardening for whois
-rw-r--r--etc/whois.profile14
1 files changed, 9 insertions, 5 deletions
diff --git a/etc/whois.profile b/etc/whois.profile
index b993264a5..bd0870bea 100644
--- a/etc/whois.profile
+++ b/etc/whois.profile
@@ -7,19 +7,23 @@ include whois.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11
10include disable-common.inc 12include disable-common.inc
11# include disable-devel.inc 13include disable-devel.inc
12include disable-exec.inc 14include disable-exec.inc
13# include disable-interpreters.inc 15include disable-interpreters.inc
14include disable-passwdmgr.inc 16include disable-passwdmgr.inc
15include disable-programs.inc 17include disable-programs.inc
16#include disable-xdg.inc 18include disable-xdg.inc
17 19
18include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
19include whitelist-var-common.inc 21include whitelist-var-common.inc
20 22
21caps.drop all 23caps.drop all
22# ipc-namespace 24hostname whois
25ipc-namespace
26machine-id
23netfilter 27netfilter
24no3d 28no3d
25nodbus 29nodbus
@@ -41,7 +45,7 @@ private
41private-bin bash,sh,whois 45private-bin bash,sh,whois
42private-cache 46private-cache
43private-dev 47private-dev
44# private-etc alternatives,hosts,services,whois.conf 48private-etc alternatives,hosts,jwhois.conf,services,whois.conf
45private-lib 49private-lib
46private-tmp 50private-tmp
47 51