diff options
author | Kelvin M. Klann <kmk3.code@protonmail.com> | 2021-01-21 04:37:34 -0300 |
---|---|---|
committer | Kelvin M. Klann <kmk3.code@protonmail.com> | 2021-01-22 04:41:11 -0300 |
commit | add6ee8c23bc500c27ba9e4258be8d0f7a26945e (patch) | |
tree | f3550fd1524902113142f9fbeaf6cc6716e53601 /etc/templates | |
parent | refactor nodejs applications (npm & yarn) (#3876) (diff) | |
download | firejail-add6ee8c23bc500c27ba9e4258be8d0f7a26945e.tar.gz firejail-add6ee8c23bc500c27ba9e4258be8d0f7a26945e.tar.zst firejail-add6ee8c23bc500c27ba9e4258be8d0f7a26945e.zip |
ssh: move auth socket blacklist to disable-common.inc
That was added on the commit e93fbf3bd ("disable ssh-agent sockets in
disable-programs.inc").
Currently, it's the only ssh-related entry on disable-programs.inc.
Further, it seems that all the other socket blacklists live on
disable-common.inc. Also, even though this socket does not necessarily
allow arbitrary command execution on the local machine (like some paths
on disable-common.inc do), it could still do so for remote systems.
Put it above the "top secret" section, like the terminal sockets are
above the terminal server section.
Diffstat (limited to 'etc/templates')
0 files changed, 0 insertions, 0 deletions