Skip to content

Commit

Permalink
Add blacklists of common dangerous directories
Browse files Browse the repository at this point in the history
  • Loading branch information
chiraag-nataraj committed Oct 2, 2016
1 parent 0ce9650 commit 5aa9387
Show file tree
Hide file tree
Showing 16 changed files with 80 additions and 7 deletions.
4 changes: 4 additions & 0 deletions brackets.profile
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,10 @@ whitelist ${HOME}/Documents
whitelist /opt/brackets/
whitelist /opt/google/

blacklist /boot
blacklist /media
blacklist /mnt

private-bin bash,brackets,readlink,dirname,google-chrome,cat
private-dev
whitelist /tmp/.X11-unix
Expand Down
5 changes: 5 additions & 0 deletions cin.profile
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@ private-bin cin
private-dev
private-etc fonts,pulse

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

whitelist /tmp/.X11-unix

noexec /home
Expand Down
5 changes: 5 additions & 0 deletions fetchmail.profile
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,11 @@ whitelist ${HOME}/Mail
whitelist ${HOME}/.procmailrc.gmail
whitelist ${HOME}/.procmailrc.brown

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

noroot
private-dev
caps.drop all
Expand Down
5 changes: 5 additions & 0 deletions gimp.profile
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,11 @@ whitelist ${HOME}/.themes
whitelist ${DOWNLOADS}
whitelist ${HOME}/Pictures

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

private-bin gimp,gimp-2.8,gimp-console,gimp-console-2.8,python2.7
private-dev
private-etc gimp,fonts
Expand Down
5 changes: 5 additions & 0 deletions inkscape.profile
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,11 @@ whitelist ${HOME}/.themes
whitelist ${DOWNLOADS}
whitelist ${HOME}/Pictures

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

private-bin inkscape
private-dev
private-etc fonts
Expand Down
4 changes: 2 additions & 2 deletions libreoffice.profile
Original file line number Diff line number Diff line change
Expand Up @@ -4,11 +4,11 @@ whitelist ${HOME}/.config/libreoffice
whitelist ${HOME}/.config/gtk-3.0
whitelist ${HOME}/.gtkrc-2.0
whitelist ${HOME}/.gtkrc.mine
blacklist /opt

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /ae108
blacklist /opt

private-dev
private-bin sh,libreoffice,dirname,grep,uname,ls,sed,pwd,basename,dbus-launch,dbus-send,fcitx-dbus-watcher,fcitx-remote
Expand Down
6 changes: 6 additions & 0 deletions linphone.profile
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,12 @@ whitelist ${HOME}/.linphone-history.db
whitelist ${HOME}/Downloads
whitelist ${HOME}/.gtkrc-2.0
whitelist ${HOME}/.gtkrc.mine

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

caps.drop all
noroot
seccomp
5 changes: 5 additions & 0 deletions lmms.profile
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,11 @@ whitelist ${HOME}/Music
whitelist ${HOME}/.lmmsrc.xml
whitelist ${HOME}/lmms

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

whitelist /tmp/.X11-unix

private-dev
Expand Down
15 changes: 10 additions & 5 deletions luminance-hdr.profile
Original file line number Diff line number Diff line change
@@ -1,13 +1,18 @@
private-bin luminance-hdr,luminance-hdr-cli,align_image_stack
private-dev
private-etc fonts,X11,alternatives
whitelist /tmp/.X11-unix

whitelist ${HOME}/Pictures
whitelist ${HOME}/Downloads
whitelist ${HOME}/.LuminanceHDR
whitelist ${HOME}/.config/Luminance

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

private-bin luminance-hdr,luminance-hdr-cli,align_image_stack
private-dev
private-etc fonts,X11,alternatives
whitelist /tmp/.X11-unix

noexec ${HOME}
noexec /tmp

Expand Down
6 changes: 6 additions & 0 deletions mpd.profile
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,12 @@ whitelist ${HOME}/.mpdconf
whitelist ${HOME}/.config/pulse/
whitelist ${HOME}/.pulse/
read-only ${HOME}/Music/

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

private-dev
private-bin mpd,bash
caps.drop all
Expand Down
5 changes: 5 additions & 0 deletions mutt.profile
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@ whitelist ${HOME}/.mutt_cache
whitelist ${HOME}/Mail
whitelist ${HOME}/.gnupg

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

# To store files
whitelist ${HOME}/Downloads

Expand Down
1 change: 1 addition & 0 deletions openshot.profile
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ blacklist /usr/local/sbin
blacklist /media
blacklist /mnt
blacklist /boot
blacklist /opt

# I use Downloads as my data transfer directory
whitelist ${HOME}/Downloads/
Expand Down
5 changes: 5 additions & 0 deletions qpdfview.profile
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@ whitelist ${HOME}/Documents

whitelist ${HOME}/.config/qpdfview

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

private-dev
private-etc fonts,X11,alternatives
private-bin qpdfview
Expand Down
6 changes: 6 additions & 0 deletions skype.profile
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
whitelist ${HOME}/.Skype
whitelist ${HOME}/Downloads

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

noexec ${HOME}/
noexec /tmp/
caps.drop all
Expand Down
5 changes: 5 additions & 0 deletions synfigstudio.profile
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
whitelist ${DOWNLOADS}
whitelist ${HOME}/.synfig

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

private-bin synfigstudio
private-etc fonts,X11,synfig,synfig_modules.cfg
private-dev
Expand Down
5 changes: 5 additions & 0 deletions virtualbox.profile
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@ whitelist ${HOME}/.gtkrc-2.0
whitelist ${HOME}/.gtkrc.mine
whitelist ${HOME}/.config/Trolltech.conf

blacklist /boot
blacklist /media
blacklist /mnt
blacklist /opt

whitelist /dev/vboxdrv
whitelist /dev/vboxdrvu
whitelist /dev/vboxnetctl
Expand Down

0 comments on commit 5aa9387

Please sign in to comment.