From c4f5a07d20d989c1155fcd0fb863bbaa5d6ab36a Mon Sep 17 00:00:00 2001 From: "Kelvin M. Klann" Date: Wed, 11 Oct 2023 07:20:04 -0300 Subject: disable-common.inc: add more suid programs Programs: $ pacman -Qo fusermount3 groupmems mount.cifs wall write /usr/bin/fusermount3 is owned by fuse3 3.16.1-1 /usr/bin/groupmems is owned by shadow 4.14.0-4 /usr/bin/mount.cifs is owned by cifs-utils 7.0-3 /usr/bin/wall is owned by util-linux 2.39.2-1 /usr/bin/write is owned by util-linux 2.39.2-1 --- etc/inc/disable-common.inc | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) (limited to 'etc') diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc index d42ec5964..021c5bd20 100644 --- a/etc/inc/disable-common.inc +++ b/etc/inc/disable-common.inc @@ -515,16 +515,17 @@ blacklist ${PATH}/evtest blacklist ${PATH}/expiry blacklist ${PATH}/fping blacklist ${PATH}/fping6 -blacklist ${PATH}/fusermount +blacklist ${PATH}/fusermount* blacklist ${PATH}/gksu blacklist ${PATH}/gksudo blacklist ${PATH}/gpasswd +blacklist ${PATH}/groupmems blacklist ${PATH}/hostname #blacklist ${PATH}/ip # breaks --ip=dhcp blacklist ${PATH}/kdesudo blacklist ${PATH}/ksu blacklist ${PATH}/mount -blacklist ${PATH}/mount.ecryptfs_private +blacklist ${PATH}/mount.* blacklist ${PATH}/mountpoint blacklist ${PATH}/mtr blacklist ${PATH}/mtr-packet @@ -563,6 +564,8 @@ blacklist ${PATH}/tcpdump blacklist ${PATH}/traceroute blacklist ${PATH}/umount blacklist ${PATH}/unix_chkpwd +blacklist ${PATH}/wall +blacklist ${PATH}/write blacklist ${PATH}/wshowkeys blacklist ${PATH}/xev blacklist ${PATH}/xinput -- cgit v1.2.3-54-g00ecf