Guest User

apparmor profil, tcpdump

a guest
Jul 20th, 2013
135
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.05 KB | None | 0 0
  1. # Last Modified: Sat Jul 20 11:54:32 2013
  2. # Author: Jamie Strandboge <[email protected]>
  3.  
  4. #include <tunables/global>
  5.  
  6. /usr/sbin/tcpdump {
  7. #include <abstractions/base>
  8. #include <abstractions/nameservice>
  9. #include <abstractions/user-tmp>
  10. #include <local/usr.sbin.tcpdump>
  11.  
  12.  
  13. capability dac_override,
  14. capability net_admin,
  15. capability net_raw,
  16. capability setgid,
  17. capability setuid,
  18. capability sys_module,
  19.  
  20. network packet,
  21. network raw,
  22.  
  23. audit deny @{HOME}/.* mrwlk,
  24. audit deny @{HOME}/.*/ rw,
  25. audit deny @{HOME}/.*/** mrwlk,
  26. audit deny @{HOME}/bin/ rw,
  27. audit deny @{HOME}/bin/** mrwlk,
  28.  
  29. /**.[pP][cC][aA][pP] rw,
  30. /bin/bzip2 rix,
  31. /bin/gzip rix,
  32. /dev/bus/usb/ r,
  33. /dev/bus/usb/** r,
  34. /dev/bus/usb/**/[0-9]* w,
  35. /dev/usbmon* r,
  36. /etc/ethers r,
  37. /sys/bus/usb/devices/ r,
  38. /sys/class/net/ r,
  39. /sys/devices/**/net/* r,
  40. /usr/sbin/tcpdump r,
  41. /var/log/snort/*log* r,
  42. owner @{HOME}/ r,
  43. owner @{HOME}/** rw,
  44. @{PROC}/[0-9]*/net/dev r,
  45. @{PROC}/bus/usb/ r,
  46. @{PROC}/bus/usb/** r,
  47.  
  48. }
Add Comment
Please, Sign In to add comment