Scientific Linux Forum.org



Pages: (2) 1 2  ( Go to first unread post ) Reply to this topicStart new topicStart Poll

> Discussion on how to secure SL
Slonick
 Posted: Jun 30 2011, 10:56 AM
Quote Post


SLF Newbie


Group: Members
Posts: 2
Member No.: 362
Joined: 30-June 11









As for leaving the console for a short period of time I found 'vlock -a' helpfull.
PM
^
U308
 Posted: Aug 7 2011, 12:37 PM
Quote Post


SLF Expert
******

Group: Members
Posts: 506
Member No.: 32
Joined: 11-April 11









Strange sandbox works fine with firefox & gftp but has stopped working with opera for some reason. http://dl.dropbox.com/u/2835777/BangHead1.gif
PM
^
Backslash
 Posted: Jan 31 2013, 12:42 PM
Quote Post


SLF Newbie


Group: Members
Posts: 9
Member No.: 2138
Joined: 14-December 12









QUOTE (U308 @ Jun 19 2011, 06:23 PM)
It's nice but sandbox is overkill for simple home user like me.

Anyway to save downloads:  ( Thanks to Dan Walsh )

mkdir /tmp/myweb ~/myweb
sandbox -X -T /tmp/myweb -H ~/myweb -t sandbox_web_t firefox

Then you can download any content, setup bookmarks ... and the sandbox will not remove them when you are done.  If you later run a command with the same sandbox homedir and tmpdir, the content will be there.
Works a treat !

user posted image


I am using the following to sandbox Firefox
mkdir /tmp/myweb ~/myweb
sandbox -X -T /tmp/myweb -H ~/myweb -t sandbox_web_t firefox

If I install Adobe Flash Player, will Flash Player be sandboxed when I run the following?
sandbox -X -T /tmp/myweb -H ~/myweb -t sandbox_web_t firefox
PM
^
log69
 Posted: Apr 11 2013, 09:57 PM
Quote Post


SLF Member
***

Group: Members
Posts: 98
Member No.: 1325
Joined: 24-February 12









Notes to some of the replies:

Yes, flash plugin will be sandbox'd too.

sandbox_web_t allows this session to connect to "Ports required for web browsing" as the manual states. You can't use a socks proxy here for example. Likewise sandbox_net_t allows it to connect to any port.

The -w option switch is useful to specify a custom window size, but unfortunately it cannot be manually resized after all. Though there was a time between SL 6.2 and 6.3 when there was a TUV patch that made this possible. They removed it from 6.4.
PM
^
0 User(s) are reading this topic (0 Guests and 0 Anonymous Users)
0 Members:

Topic OptionsPages: (2) 1 2  Reply to this topicStart new topicStart Poll