aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-11-12 16:55:18 -0500
committerLibravatar netblue30 <netblue30@protonmail.com>2021-11-12 16:55:18 -0500
commitbd49232be8d32abafb9acadfef596784a63f563d (patch)
tree522b2d81008ca423a5f8940d5cf1fe4f52a72e60 /etc/inc/disable-common.inc
parentreadme update (diff)
downloadfirejail-bd49232be8d32abafb9acadfef596784a63f563d.tar.gz
firejail-bd49232be8d32abafb9acadfef596784a63f563d.tar.zst
firejail-bd49232be8d32abafb9acadfef596784a63f563d.zip
telnet and ftp
Diffstat (limited to 'etc/inc/disable-common.inc')
-rw-r--r--etc/inc/disable-common.inc9
1 files changed, 6 insertions, 3 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index bdc5ff6b2..3f4c69dfe 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -494,7 +494,6 @@ blacklist ${PATH}/unix_chkpwd
494blacklist ${PATH}/xev 494blacklist ${PATH}/xev
495blacklist ${PATH}/xinput 495blacklist ${PATH}/xinput
496# from 0.9.67 496# from 0.9.67
497blacklist ${PATH}/ssh
498blacklist /usr/lib/openssh 497blacklist /usr/lib/openssh
499blacklist /usr/lib/ssh 498blacklist /usr/lib/ssh
500blacklist /usr/libexec/openssh 499blacklist /usr/libexec/openssh
@@ -583,8 +582,7 @@ blacklist ${HOME}/sent
583# kernel configuration 582# kernel configuration
584blacklist /proc/config.gz 583blacklist /proc/config.gz
585 584
586# prevent DNS malware attempting to communicate with the server 585# prevent DNS malware attempting to communicate with the server using regular DNS tools
587# using regular DNS tools
588blacklist ${PATH}/dig 586blacklist ${PATH}/dig
589blacklist ${PATH}/dlint 587blacklist ${PATH}/dlint
590blacklist ${PATH}/dns2tcp 588blacklist ${PATH}/dns2tcp
@@ -602,6 +600,11 @@ blacklist ${PATH}/nslookup
602blacklist ${PATH}/resolvectl 600blacklist ${PATH}/resolvectl
603blacklist ${PATH}/unbound-host 601blacklist ${PATH}/unbound-host
604 602
603# prevent an intruder to guess passwords using regular network tools
604blacklist ${PATH}/ftp
605blacklist ${PATH}/ssh
606blacklist ${PATH}/telnet
607
605# rest of ${RUNUSER} 608# rest of ${RUNUSER}
606blacklist ${RUNUSER}/*.lock 609blacklist ${RUNUSER}/*.lock
607blacklist ${RUNUSER}/inaccessible 610blacklist ${RUNUSER}/inaccessible