aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-10-10 12:39:26 -0400
committerLibravatar Tad <tad@spotco.us>2017-10-10 12:39:26 -0400
commit9627229b6ffe1566ffd26f9d3a8be2938784cc21 (patch)
treea08f0866e11f07fe239982957d5e03250a2b57e6 /etc
parentprivate-lib (diff)
downloadfirejail-9627229b6ffe1566ffd26f9d3a8be2938784cc21.tar.gz
firejail-9627229b6ffe1566ffd26f9d3a8be2938784cc21.tar.zst
firejail-9627229b6ffe1566ffd26f9d3a8be2938784cc21.zip
Add a profile for ZAProxy
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/zaproxy.profile42
2 files changed, 43 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 064e60294..0e5400dd6 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -20,6 +20,7 @@ blacklist ${HOME}/.TelegramDesktop
20blacklist ${HOME}/.ViberPC 20blacklist ${HOME}/.ViberPC
21blacklist ${HOME}/.VirtualBox 21blacklist ${HOME}/.VirtualBox
22blacklist ${HOME}/.Wolfram Research 22blacklist ${HOME}/.Wolfram Research
23blacklist ${HOME}/.ZAP
23blacklist ${HOME}/.aMule 24blacklist ${HOME}/.aMule
24blacklist ${HOME}/.android 25blacklist ${HOME}/.android
25blacklist ${HOME}/.arduino15 26blacklist ${HOME}/.arduino15
diff --git a/etc/zaproxy.profile b/etc/zaproxy.profile
new file mode 100644
index 000000000..3cce79a2e
--- /dev/null
+++ b/etc/zaproxy.profile
@@ -0,0 +1,42 @@
1# Firejail profile for zaproxy
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/zaproxy.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.java
9noblacklist ${HOME}/.ZAP
10
11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16mkdir ${HOME}/.ZAP
17whitelist ${HOME}/.java
18whitelist ${HOME}/.ZAP
19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
21
22caps.drop all
23ipc-namespace
24netfilter
25no3d
26nodvd
27nogroups
28nonewprivs
29noroot
30nosound
31notv
32novideo
33protocol unix,inet,inet6
34seccomp
35shell none
36
37disable-mnt
38private-dev
39private-tmp
40
41noexec ${HOME}
42noexec /tmp