aboutsummaryrefslogtreecommitdiffstats
path: root/etc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar valoq <valoq@mailbox.org>2016-10-26 17:51:07 +0200
committerLibravatar valoq <valoq@mailbox.org>2016-10-26 17:51:07 +0200
commitad773dec65ec32e0fcba1b123b3da5b9edcbf9d4 (patch)
tree0e35dd6dc35f3c8d5ea32a6c076e270524b3db36 /etc/disable-common.inc
parentremoved blacklist duplate (diff)
parentremoved ping blacklisting (diff)
downloadfirejail-ad773dec65ec32e0fcba1b123b3da5b9edcbf9d4.tar.gz
firejail-ad773dec65ec32e0fcba1b123b3da5b9edcbf9d4.tar.zst
firejail-ad773dec65ec32e0fcba1b123b3da5b9edcbf9d4.zip
resolve conflict
Diffstat (limited to 'etc/disable-common.inc')
-rw-r--r--etc/disable-common.inc54
1 files changed, 24 insertions, 30 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 19a23d764..82398473d 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -137,6 +137,11 @@ blacklist /etc/gshadow+
137blacklist /etc/ssh 137blacklist /etc/ssh
138blacklist /var/backup 138blacklist /var/backup
139 139
140# system directories
141blacklist /sbin
142blacklist /usr/sbin
143blacklist /usr/local/sbin
144
140# system management 145# system management
141# blacklist ${PATH}/umount 146# blacklist ${PATH}/umount
142# blacklist ${PATH}/mount 147# blacklist ${PATH}/mount
@@ -149,11 +154,22 @@ blacklist ${PATH}/xev
149blacklist ${PATH}/strace 154blacklist ${PATH}/strace
150blacklist ${PATH}/nc 155blacklist ${PATH}/nc
151blacklist ${PATH}/ncat 156blacklist ${PATH}/ncat
152 157blacklist ${PATH}/gpasswd
153# system directories 158blacklist ${PATH}/newgidmap
154blacklist /sbin 159blacklist ${PATH}/newgrp
155blacklist /usr/sbin 160blacklist ${PATH}/newuidmap
156blacklist /usr/local/sbin 161blacklist ${PATH}/pkexec
162blacklist ${PATH}/sg
163blacklist ${PATH}/rsh
164blacklist ${PATH}/rlogin
165blacklist ${PATH}/rcp
166blacklist ${PATH}/crontab
167blacklist ${PATH}/ksu
168blacklist ${PATH}/chsh
169blacklist ${PATH}/chfn
170blacklist ${PATH}/chage
171blacklist ${PATH}/expiry
172blacklist ${PATH}/unix_chkpwd
157 173
158# prevent lxterminal connecting to an existing lxterminal session 174# prevent lxterminal connecting to an existing lxterminal session
159blacklist /tmp/.lxterminal-socket* 175blacklist /tmp/.lxterminal-socket*
@@ -173,28 +189,6 @@ blacklist ${PATH}/terminix
173blacklist ${PATH}/urxvtc 189blacklist ${PATH}/urxvtc
174blacklist ${PATH}/urxvtcd 190blacklist ${PATH}/urxvtcd
175 191
176# disable common suid programms 192# kernel files
177blacklist ${PATH}/firejail 193blacklist /vmlinuz*
178blacklist ${PATH}/sudo 194blacklist /initrd*
179blacklist ${PATH}/su
180blacklist ${PATH}/mount
181blacklist ${PATH}/umount
182blacklist ${PATH}/fusermount
183blacklist ${PATH}/passwd
184blacklist ${PATH}/gpasswd
185blacklist ${PATH}/newgidmap
186blacklist ${PATH}/newgrp
187blacklist ${PATH}/newuidmap
188blacklist ${PATH}/pkexec
189blacklist ${PATH}/sg
190blacklist ${PATH}/rsh
191blacklist ${PATH}/rlogin
192blacklist ${PATH}/rcp
193blacklist ${PATH}/crontab
194blacklist ${PATH}/ksu
195blacklist ${PATH}/chsh
196blacklist ${PATH}/chfn
197blacklist ${PATH}/chage
198blacklist ${PATH}/expiry
199blacklist ${PATH}/ping
200blacklist ${PATH}/unix_chkpwd