aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-07-13 07:26:05 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2021-07-13 07:26:05 -0400
commit110a74f094abcb4f2763d76e204fb3c9743fa9a1 (patch)
tree7f26a41d4095df0f146ac6e30ef0669e439f854b /etc/inc
parentFix #4396 -- tracelog causes anki to segfault (diff)
downloadfirejail-110a74f094abcb4f2763d76e204fb3c9743fa9a1.tar.gz
firejail-110a74f094abcb4f2763d76e204fb3c9743fa9a1.tar.zst
firejail-110a74f094abcb4f2763d76e204fb3c9743fa9a1.zip
disable-common.inc update
Diffstat (limited to 'etc/inc')
-rw-r--r--etc/inc/disable-common.inc15
1 files changed, 15 insertions, 0 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 4c83284ee..1283a3a3d 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -162,6 +162,9 @@ deny ${HOME}/.local/share/systemd
162deny /var/lib/systemd 162deny /var/lib/systemd
163deny ${PATH}/systemd-run 163deny ${PATH}/systemd-run
164deny ${RUNUSER}/systemd 164deny ${RUNUSER}/systemd
165deny ${PATH}/systemctl
166deny /etc/systemd/system
167deny /etc/systemd/network
165# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf 168# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf
166#blacklist /var/run/systemd 169#blacklist /var/run/systemd
167 170
@@ -257,6 +260,18 @@ deny /etc/modules*
257deny /etc/logrotate* 260deny /etc/logrotate*
258deny /etc/adduser.conf 261deny /etc/adduser.conf
259 262
263# hide config for various intrusion detection systems
264deny /etc/rkhunter.conf
265deny /var/lib/rkhunter
266deny /etc/chkrootkit.conf
267deny /etc/lynis
268deny /etc/aide
269deny /etc/logcheck
270deny /etc/tripwire
271deny /etc/snort
272deny /etc/fail2ban.conf
273deny /etc/suricata
274
260# Startup files 275# Startup files
261read-only ${HOME}/.antigen 276read-only ${HOME}/.antigen
262read-only ${HOME}/.bash_aliases 277read-only ${HOME}/.bash_aliases