aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2023-08-22 19:18:18 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2023-08-22 19:18:18 -0400
commit96beb3358c430a5e470ce02fd64ffc3f7fc23706 (patch)
treeeb9cc9ce3be9533ca9bab75905e19a17c0adaf51 /etc/inc/disable-common.inc
parentMerge branch 'master' of ssh://github.com/netblue30/firejail (diff)
downloadfirejail-96beb3358c430a5e470ce02fd64ffc3f7fc23706.tar.gz
firejail-96beb3358c430a5e470ce02fd64ffc3f7fc23706.tar.zst
firejail-96beb3358c430a5e470ce02fd64ffc3f7fc23706.zip
a second round of blacklisting in disable-common.inc
Diffstat (limited to 'etc/inc/disable-common.inc')
-rw-r--r--etc/inc/disable-common.inc31
1 files changed, 30 insertions, 1 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 010cb05b6..bcf90e9ed 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -170,7 +170,7 @@ blacklist ${RUNUSER}/gsconnect
170blacklist ${HOME}/.config/systemd 170blacklist ${HOME}/.config/systemd
171blacklist ${HOME}/.local/share/systemd 171blacklist ${HOME}/.local/share/systemd
172blacklist ${PATH}/systemctl 172blacklist ${PATH}/systemctl
173blacklist ${PATH}/systemd-run 173blacklist ${PATH}/systemd*
174blacklist ${RUNUSER}/systemd 174blacklist ${RUNUSER}/systemd
175blacklist /etc/credstore* 175blacklist /etc/credstore*
176blacklist /etc/systemd/network 176blacklist /etc/systemd/network
@@ -518,7 +518,10 @@ blacklist ${PATH}/kdesudo
518blacklist ${PATH}/ksu 518blacklist ${PATH}/ksu
519blacklist ${PATH}/mount 519blacklist ${PATH}/mount
520blacklist ${PATH}/mount.ecryptfs_private 520blacklist ${PATH}/mount.ecryptfs_private
521blacklist ${PATH}/mountpoint
521blacklist ${PATH}/nc 522blacklist ${PATH}/nc
523blacklist ${PATH}/nc.traditional
524blacklist ${PATH}/nc.openbsd
522blacklist ${PATH}/ncat 525blacklist ${PATH}/ncat
523blacklist ${PATH}/nmap 526blacklist ${PATH}/nmap
524blacklist ${PATH}/newgidmap 527blacklist ${PATH}/newgidmap
@@ -572,7 +575,28 @@ blacklist ${PATH}/nmtui-hostname
572blacklist ${PATH}/networkctl 575blacklist ${PATH}/networkctl
573blacklist ${PATH}/ss 576blacklist ${PATH}/ss
574blacklist ${PATH}/traceroute 577blacklist ${PATH}/traceroute
578# since firejail version 0.9.73
575blacklist ${PATH}/dpkg* 579blacklist ${PATH}/dpkg*
580blacklist ${PATH}/fakeroot*
581blacklist ${PATH}/apt*
582blacklist ${PATH}/dumpcap
583blacklist ${PATH}/efibootdump
584blacklist ${PATH}/efibootmgr
585blacklist ${PATH}/passmass
586blacklist ${PATH}/proxy
587blacklist ${PATH}/aa-*
588blacklist ${PATH}/airscan-discover
589blacklist ${PATH}/avahi*
590blacklist ${PATH}/dbus-*
591blacklist ${PATH}/debconf*
592blacklist ${PATH}/grub-*
593blacklist ${PATH}/kernel-install # from systemd package
594
595# binaries installed by firejail
596blacklist ${PATH}/firemon
597blacklist ${PATH}/firecfg
598blacklist ${PATH}/jailcheck
599blacklist ${PATH}/firetools
576 600
577# other SUID binaries 601# other SUID binaries
578blacklist /opt/microsoft/msedge*/msedge-sandbox 602blacklist /opt/microsoft/msedge*/msedge-sandbox
@@ -653,10 +677,13 @@ blacklist ${HOME}/sent
653blacklist /proc/config.gz 677blacklist /proc/config.gz
654 678
655# prevent DNS malware attempting to communicate with the server using regular DNS tools 679# prevent DNS malware attempting to communicate with the server using regular DNS tools
680blacklist ${PATH}/delv
656blacklist ${PATH}/dig 681blacklist ${PATH}/dig
657blacklist ${PATH}/dlint 682blacklist ${PATH}/dlint
658blacklist ${PATH}/dns2tcp 683blacklist ${PATH}/dns2tcp
659blacklist ${PATH}/dnssec-* 684blacklist ${PATH}/dnssec-*
685blacklist ${PATH}/dnstap-read
686blacklist ${PATH}/mdig
660blacklist ${PATH}/dnswalk 687blacklist ${PATH}/dnswalk
661blacklist ${PATH}/drill 688blacklist ${PATH}/drill
662blacklist ${PATH}/host 689blacklist ${PATH}/host
@@ -667,6 +694,8 @@ blacklist ${PATH}/knsupdate
667blacklist ${PATH}/ldns-* 694blacklist ${PATH}/ldns-*
668blacklist ${PATH}/ldnsd 695blacklist ${PATH}/ldnsd
669blacklist ${PATH}/nslookup 696blacklist ${PATH}/nslookup
697blacklist ${PATH}/nsupdate
698blacklist ${PATH}/nstat
670blacklist ${PATH}/resolvectl 699blacklist ${PATH}/resolvectl
671blacklist ${PATH}/unbound-host 700blacklist ${PATH}/unbound-host
672 701