aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-11-07 08:25:02 -0500
committerLibravatar netblue30 <netblue30@yahoo.com>2016-11-07 08:25:02 -0500
commitde5b53608af7b120608ce89e63e46f5d689bc6d0 (patch)
tree5b15c225165abf885f81741cbc854750f64c3a23
parentMerge pull request #898 from valoq/master (diff)
downloadfirejail-de5b53608af7b120608ce89e63e46f5d689bc6d0.tar.gz
firejail-de5b53608af7b120608ce89e63e46f5d689bc6d0.tar.zst
firejail-de5b53608af7b120608ce89e63e46f5d689bc6d0.zip
profiles
-rw-r--r--etc/disable-common.inc9
-rw-r--r--etc/virtualbox.profile1
-rw-r--r--platform/debian/conffiles1
3 files changed, 10 insertions, 1 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index e77f2d369..071d217bb 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -42,6 +42,7 @@ blacklist ${HOME}/.VeraCrypt
42# var 42# var
43blacklist /var/spool/cron 43blacklist /var/spool/cron
44blacklist /var/spool/anacron 44blacklist /var/spool/anacron
45blacklist /var/mail
45blacklist /var/run/acpid.socket 46blacklist /var/run/acpid.socket
46blacklist /var/run/minissdpd.sock 47blacklist /var/run/minissdpd.sock
47blacklist /var/run/rpcbind.sock 48blacklist /var/run/rpcbind.sock
@@ -52,7 +53,7 @@ blacklist /var/lib/mysql/mysql.sock
52blacklist /var/run/docker.sock 53blacklist /var/run/docker.sock
53 54
54# etc 55# etc
55blacklist /etc/cron.* 56blacklist /etc/cron*
56blacklist /etc/profile.d 57blacklist /etc/profile.d
57blacklist /etc/rc.local 58blacklist /etc/rc.local
58blacklist /etc/anacrontab 59blacklist /etc/anacrontab
@@ -147,6 +148,8 @@ blacklist /usr/local/sbin
147blacklist ${PATH}/umount 148blacklist ${PATH}/umount
148blacklist ${PATH}/mount 149blacklist ${PATH}/mount
149blacklist ${PATH}/fusermount 150blacklist ${PATH}/fusermount
151blacklist ${PATH}/ntfs-3g
152blacklist ${PATH}/at
150blacklist ${PATH}/su 153blacklist ${PATH}/su
151blacklist ${PATH}/sudo 154blacklist ${PATH}/sudo
152blacklist ${PATH}/xinput 155blacklist ${PATH}/xinput
@@ -171,6 +174,10 @@ blacklist ${PATH}/chfn
171blacklist ${PATH}/chage 174blacklist ${PATH}/chage
172blacklist ${PATH}/expiry 175blacklist ${PATH}/expiry
173blacklist ${PATH}/unix_chkpwd 176blacklist ${PATH}/unix_chkpwd
177blacklist ${PATH}/procmail
178
179# other SUID binaries
180blacklist /usr/lib/virtualbox
174 181
175# prevent lxterminal connecting to an existing lxterminal session 182# prevent lxterminal connecting to an existing lxterminal session
176blacklist /tmp/.lxterminal-socket* 183blacklist /tmp/.lxterminal-socket*
diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile
index 148b7efc8..49f8f8b24 100644
--- a/etc/virtualbox.profile
+++ b/etc/virtualbox.profile
@@ -3,6 +3,7 @@
3noblacklist ${HOME}/.VirtualBox 3noblacklist ${HOME}/.VirtualBox
4noblacklist ${HOME}/VirtualBox VMs 4noblacklist ${HOME}/VirtualBox VMs
5noblacklist ${HOME}/.config/VirtualBox 5noblacklist ${HOME}/.config/VirtualBox
6noblacklist /usr/bin/virtualbox
6include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc 8include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-passwdmgr.inc 9include /etc/firejail/disable-passwdmgr.inc
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index ae8db5a67..ff3909c17 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -170,5 +170,6 @@
170/etc/firejail/xiphos.profile 170/etc/firejail/xiphos.profile
171/etc/firejail/display.profile 171/etc/firejail/display.profile
172/etc/firejail/Wire.profile 172/etc/firejail/Wire.profile
173/etc/firejail/wire.profile
173/etc/firejail/mumble.profile 174/etc/firejail/mumble.profile
174/etc/firejail/zoom.profile 175/etc/firejail/zoom.profile