aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-11-04 14:35:08 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2021-11-04 14:35:08 -0400
commitd681e0e2d9548c56bf67131b9fe4a75d8e1b9060 (patch)
tree7c5d2dc58bfc53f1daaf2791c3a01e5ec8eeff3f /etc/inc/disable-common.inc
parentREADME: bump debian stable codename (diff)
downloadfirejail-d681e0e2d9548c56bf67131b9fe4a75d8e1b9060.tar.gz
firejail-d681e0e2d9548c56bf67131b9fe4a75d8e1b9060.tar.zst
firejail-d681e0e2d9548c56bf67131b9fe4a75d8e1b9060.zip
adding more SUID executables to disable-common.inc
Diffstat (limited to 'etc/inc/disable-common.inc')
-rw-r--r--etc/inc/disable-common.inc8
1 files changed, 7 insertions, 1 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index ae84ee38a..f3d685d18 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -458,7 +458,7 @@ blacklist /sbin
458blacklist /usr/local/sbin 458blacklist /usr/local/sbin
459blacklist /usr/sbin 459blacklist /usr/sbin
460 460
461# system management 461# system management and various SUID executables
462blacklist ${PATH}/at 462blacklist ${PATH}/at
463blacklist ${PATH}/busybox 463blacklist ${PATH}/busybox
464blacklist ${PATH}/chage 464blacklist ${PATH}/chage
@@ -493,6 +493,12 @@ blacklist ${PATH}/umount
493blacklist ${PATH}/unix_chkpwd 493blacklist ${PATH}/unix_chkpwd
494blacklist ${PATH}/xev 494blacklist ${PATH}/xev
495blacklist ${PATH}/xinput 495blacklist ${PATH}/xinput
496blacklist /usr/lib/openssh/ssh-keysign
497blacklist ${PATH}/passwd
498blacklist /usr/lib/xorg/Xorg.wrap
499blacklist /usr/lib/policykit-1/polkit-agent-helper-1
500blacklist /usr/lib/dbus-1.0/dbus-daemon-launch-helper
501blacklist /usr/lib/eject/dmcrypt-get-device
496 502
497# other SUID binaries 503# other SUID binaries
498blacklist /usr/lib/virtualbox 504blacklist /usr/lib/virtualbox