From 4c712cbaaf593e4e8cd39d798fba714a2aff51ea Mon Sep 17 00:00:00 2001 From: Ondřej Nový Date: Fri, 17 Jul 2020 10:38:29 +0200 Subject: Hardend Zoom profile --- etc/profile-m-z/zoom.profile | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/etc/profile-m-z/zoom.profile b/etc/profile-m-z/zoom.profile index 6eac10703..b3125ee50 100644 --- a/etc/profile-m-z/zoom.profile +++ b/etc/profile-m-z/zoom.profile @@ -10,8 +10,11 @@ noblacklist ${HOME}/.zoom include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc +include disable-passwdmgr.inc include disable-programs.inc +include disable-xdg.inc mkdir ${HOME}/.cache/zoom mkfile ${HOME}/.config/zoomus.conf @@ -20,14 +23,25 @@ whitelist ${HOME}/.cache/zoom whitelist ${HOME}/.config/zoomus.conf whitelist ${HOME}/.zoom include whitelist-common.inc +include whitelist-runuser-common.inc +include whitelist-usr-share-common.inc +include whitelist-var-common.inc caps.drop all netfilter nodvd +nogroups nonewprivs noroot notv +nou2f protocol unix,inet,inet6,netlink seccomp !chroot +shell none +tracelog +disable-mnt +private-cache +private-dev +private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl private-tmp -- cgit v1.2.3-54-g00ecf