diff options
author | Kristóf Marussy <kris7topher@gmail.com> | 2020-02-22 21:52:23 +0100 |
---|---|---|
committer | Kristóf Marussy <kris7topher@gmail.com> | 2020-02-23 17:13:13 +0100 |
commit | 9860590b25e1478367650a1c5ff694abf70a5b65 (patch) | |
tree | 943f410d5f11e0b14a8ee317c893a3b190cb82d7 /etc/XMind.profile | |
parent | misc things (diff) | |
download | firejail-9860590b25e1478367650a1c5ff694abf70a5b65.tar.gz firejail-9860590b25e1478367650a1c5ff694abf70a5b65.tar.zst firejail-9860590b25e1478367650a1c5ff694abf70a5b65.zip |
Harden dhcp by checking for /sbin/dhclient
Running /sbin/dhclient or /usr/sbin/dhclient avoids PATH-based vulnerabilities.
We also check that the dhclient is owned by root.
We take an approach similar to netfiler.c and assume that the required binary
ar in /sbin or /usr/sbin, or (like on Arch) /sbin is a symlink to /usr/bin.
Diffstat (limited to 'etc/XMind.profile')
0 files changed, 0 insertions, 0 deletions