aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2023-08-20 12:26:00 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2023-08-20 12:26:00 -0400
commitd94f54736f48a089c5fa19632c2c42e8da3db5a8 (patch)
treea0a210fe03ee539d7613245df17d77730f283da8 /etc/inc
parentmore domains for static-ip-map (diff)
downloadfirejail-d94f54736f48a089c5fa19632c2c42e8da3db5a8.tar.gz
firejail-d94f54736f48a089c5fa19632c2c42e8da3db5a8.tar.zst
firejail-d94f54736f48a089c5fa19632c2c42e8da3db5a8.zip
disable all ssh utilities in disable-common.inc
Diffstat (limited to 'etc/inc')
-rw-r--r--etc/inc/allow-ssh.inc2
-rw-r--r--etc/inc/disable-common.inc11
2 files changed, 3 insertions, 10 deletions
diff --git a/etc/inc/allow-ssh.inc b/etc/inc/allow-ssh.inc
index 024d87be7..6b2c5846e 100644
--- a/etc/inc/allow-ssh.inc
+++ b/etc/inc/allow-ssh.inc
@@ -6,7 +6,7 @@ noblacklist ${HOME}/.ssh
6noblacklist /etc/ssh 6noblacklist /etc/ssh
7noblacklist /etc/ssh/ssh_config 7noblacklist /etc/ssh/ssh_config
8noblacklist /etc/ssh/ssh_config.d 8noblacklist /etc/ssh/ssh_config.d
9noblacklist ${PATH}/ssh 9noblacklist ${PATH}/ssh*
10noblacklist /tmp/ssh-* 10noblacklist /tmp/ssh-*
11# Arch Linux and derivatives 11# Arch Linux and derivatives
12noblacklist /usr/lib/ssh 12noblacklist /usr/lib/ssh
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index ce4f08958..438e90499 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -319,16 +319,10 @@ read-only ${HOME}/.zshenv
319read-only ${HOME}/.zshrc 319read-only ${HOME}/.zshrc
320read-only ${HOME}/.zshrc.local 320read-only ${HOME}/.zshrc.local
321 321
322# Remote access 322# Remote access - ${HOME}/.ssh directory blacklisted in top secret section below
323blacklist ${HOME}/.rhosts 323blacklist ${HOME}/.rhosts
324blacklist ${HOME}/.shosts 324blacklist ${HOME}/.shosts
325blacklist ${HOME}/.ssh/authorized_keys
326blacklist ${HOME}/.ssh/authorized_keys2
327blacklist ${HOME}/.ssh/environment
328blacklist ${HOME}/.ssh/rc
329blacklist /etc/hosts.equiv 325blacklist /etc/hosts.equiv
330read-only ${HOME}/.ssh/config
331read-only ${HOME}/.ssh/config.d
332 326
333# Initialization files that allow arbitrary command execution 327# Initialization files that allow arbitrary command execution
334read-only ${HOME}/.caffrc 328read-only ${HOME}/.caffrc
@@ -536,7 +530,6 @@ blacklist ${PATH}/umount
536blacklist ${PATH}/unix_chkpwd 530blacklist ${PATH}/unix_chkpwd
537blacklist ${PATH}/xev 531blacklist ${PATH}/xev
538blacklist ${PATH}/xinput 532blacklist ${PATH}/xinput
539# from 0.9.67
540blacklist /usr/lib/openssh 533blacklist /usr/lib/openssh
541blacklist /usr/lib/ssh 534blacklist /usr/lib/ssh
542blacklist /usr/libexec/openssh 535blacklist /usr/libexec/openssh
@@ -672,7 +665,7 @@ blacklist ${PATH}/unbound-host
672 665
673# prevent an intruder to guess passwords using regular network tools 666# prevent an intruder to guess passwords using regular network tools
674blacklist ${PATH}/ftp 667blacklist ${PATH}/ftp
675blacklist ${PATH}/ssh 668blacklist ${PATH}/ssh*
676blacklist ${PATH}/telnet 669blacklist ${PATH}/telnet
677 670
678# rest of ${RUNUSER} 671# rest of ${RUNUSER}