__ __ __ __ _____ _ _ _____ _ _ _ | \/ | \ \ / / | __ \ (_) | | / ____| | | | | | \ / |_ __\ V / | |__) | __ ___ ____ _| |_ ___ | (___ | |__ ___| | | | |\/| | '__|> < | ___/ '__| \ \ / / _` | __/ _ \ \___ \| '_ \ / _ \ | | | | | | |_ / . \ | | | | | |\ V / (_| | || __/ ____) | | | | __/ | | |_| |_|_(_)_/ \_\ |_| |_| |_| \_/ \__,_|\__\___| |_____/|_| |_|\___V 2.1 if you need WebShell for Seo everyday contact me on Telegram Telegram Address : @jackleetFor_More_Tools:
# Lenient profile that is intended to be used when 'Ux' is desired but
# does not provide enough environment sanitizing. This effectively is an
# open profile that blacklists certain known dangerous files and also
# does not allow any capabilities. For example, it will not allow 'm' on files
# owned be the user invoking the program. While this provides some additional
# protection, please use with care as applications running under this profile
# are effectively running without any AppArmor protection. Use this profile
# only if the process absolutely must be run (effectively) unconfined.
#
# Usage:
# Because this abstraction defines the sanitized_helper profile, it must only
# be included once. Therefore this abstraction should typically not be
# included in other abstractions so as to avoid parser errors regarding
# multiple definitions.
#
# Limitations:
# 1. This does not work for root owned processes, because of the way we use
# owner matching in the sanitized helper. We could do a better job with
# this to support root, but it would make the policy harder to understand
# and going unconfined as root is not desirable any way.
#
# 2. For this sanitized_helper to work, the program running in the sanitized
# environment must open symlinks directly in order for AppArmor to mediate
# it. This is confirmed to work with:
# - compiled code which can load shared libraries
# - python imports
# It is known not to work with:
# - perl includes
# 3. Sanitizing ruby and java
#
# Use at your own risk. This profile was developed as an interim workaround for
# LP: #851986 until AppArmor utilizes proper environment filtering.
abi <abi/4.0>,
profile sanitized_helper {
include <abstractions/base>
include <abstractions/X>
include if exists <local/ubuntu-helpers>
# Allow all networking
network inet,
network inet6,
# Allow all DBus communications
include <abstractions/dbus-session-strict>
include <abstractions/dbus-strict>
dbus,
# Needed for Google Chrome
ptrace (trace) peer=**//sanitized_helper,
# Allow exec of anything, but under this profile. Allow transition
# to other profiles if they exist.
/{usr/,usr/local/,}{bin,sbin}/* Pixr,
# Allow exec of libexec applications in /usr/lib* and /usr/local/lib*
/usr/{,local/}lib*/{,**/}* Pixr,
# Allow exec of software-center scripts. We may need to allow wider
# permissions for /usr/share, but for now just do this. (LP: #972367)
/usr/share/software-center/* Pixr,
# Allow exec of texlive font build scripts (LP: #1010909)
/usr/share/texlive/texmf{,-dist}/web2c/{,**/}* Pixr,
# While the chromium and chrome sandboxes are setuid root, they only link
# in limited libraries so glibc's secure execution should be enough to not
# require the santized_helper (ie, LD_PRELOAD will only use standard system
# paths (man ld.so)).
/usr/lib/chromium-browser/chromium-browser-sandbox PUxr,
/usr/lib/chromium{,-browser}/chrome-sandbox PUxr,
/opt/google/chrome{,-beta,-unstable}/chrome-sandbox PUxr,
/opt/google/chrome{,-beta,-unstable}/google-chrome Pixr,
/opt/google/chrome{,-beta,-unstable}/chrome Pixr,
/opt/google/chrome{,-beta,-unstable}/chrome_crashpad_handler Pixr,
/opt/google/chrome{,-beta,-unstable}/{,**/}lib*.so{,.*} m,
# The same is needed for Brave
/opt/brave.com/brave{,-beta,-dev,-nightly}/chrome-sandbox PUxr,
/opt/brave.com/brave{,-beta,-dev,-nightly}/brave-browser{,-beta,-dev,-nightly} Pixr,
/opt/brave.com/brave{,-beta,-dev,-nightly}/brave Pixr,
/opt/brave.com/brave{,-beta,-dev,-nightly}/chrome_crashpad_handler Pixr,
/opt/brave.com/brave{,-beta,-dev,-nightly}/{,**/}lib*.so{,.*} m,
# Full access
/ r,
/** rwkl,
/{,usr/,usr/local/}lib{,32,64}/{,**/}*.so{,.*} m,
# Dangerous files
audit deny owner /**/* m, # compiled libraries
audit deny owner /**/*.py* r, # python imports
}
| Name | Type | Size | Permission | Actions |
|---|---|---|---|---|
| apparmor_api | Folder | 0755 |
|
|
| ubuntu-browsers.d | Folder | 0755 |
|
|
| X | File | 1.94 KB | 0644 |
|
| apache2-common | File | 1.09 KB | 0644 |
|
| aspell | File | 412 B | 0644 |
|
| audio | File | 2.01 KB | 0644 |
|
| authentication | File | 2.14 KB | 0644 |
|
| base | File | 6.93 KB | 0644 |
|
| bash | File | 1.58 KB | 0644 |
|
| consoles | File | 903 B | 0644 |
|
| crypto | File | 992 B | 0644 |
|
| cups-client | File | 820 B | 0644 |
|
| dbus | File | 694 B | 0644 |
|
| dbus-accessibility | File | 745 B | 0644 |
|
| dbus-accessibility-strict | File | 760 B | 0644 |
|
| dbus-network-manager-strict | File | 1.37 KB | 0644 |
|
| dbus-session | File | 747 B | 0644 |
|
| dbus-session-strict | File | 1.23 KB | 0644 |
|
| dbus-strict | File | 781 B | 0644 |
|
| dconf | File | 344 B | 0644 |
|
| dovecot-common | File | 675 B | 0644 |
|
| dri-common | File | 542 B | 0644 |
|
| dri-enumerate | File | 393 B | 0644 |
|
| enchant | File | 2.17 KB | 0644 |
|
| exo-open | File | 1.88 KB | 0644 |
|
| fcitx | File | 558 B | 0644 |
|
| fcitx-strict | File | 821 B | 0644 |
|
| fonts | File | 2.23 KB | 0644 |
|
| freedesktop.org | File | 1.64 KB | 0644 |
|
| gio-open | File | 1.51 KB | 0644 |
|
| gnome | File | 3.73 KB | 0644 |
|
| gnupg | File | 459 B | 0644 |
|
| groff | File | 1.86 KB | 0644 |
|
| gtk | File | 1.58 KB | 0644 |
|
| gvfs-open | File | 1.15 KB | 0644 |
|
| hosts_access | File | 511 B | 0644 |
|
| ibus | File | 992 B | 0644 |
|
| kde | File | 3.25 KB | 0644 |
|
| kde-globals-write | File | 413 B | 0644 |
|
| kde-icon-cache-write | File | 256 B | 0644 |
|
| kde-language-write | File | 575 B | 0644 |
|
| kde-open5 | File | 3.58 KB | 0644 |
|
| kerberosclient | File | 1.44 KB | 0644 |
|
| ldapclient | File | 856 B | 0644 |
|
| libpam-systemd | File | 770 B | 0644 |
|
| likewise | File | 595 B | 0644 |
|
| mdns | File | 554 B | 0644 |
|
| mesa | File | 1.21 KB | 0644 |
|
| mir | File | 694 B | 0644 |
|
| mozc | File | 573 B | 0644 |
|
| mysql | File | 739 B | 0644 |
|
| nameservice | File | 4.46 KB | 0644 |
|
| nis | File | 625 B | 0644 |
|
| nss-systemd | File | 1.22 KB | 0644 |
|
| nvidia | File | 1.09 KB | 0644 |
|
| opencl | File | 370 B | 0644 |
|
| opencl-common | File | 516 B | 0644 |
|
| opencl-intel | File | 673 B | 0644 |
|
| opencl-mesa | File | 636 B | 0644 |
|
| opencl-nvidia | File | 896 B | 0644 |
|
| opencl-pocl | File | 2.85 KB | 0644 |
|
| openssl | File | 642 B | 0644 |
|
| orbit2 | File | 197 B | 0644 |
|
| p11-kit | File | 999 B | 0644 |
|
| perl | File | 974 B | 0644 |
|
| php | File | 1.1 KB | 0644 |
|
| php-worker | File | 558 B | 0644 |
|
| php5 | File | 208 B | 0644 |
|
| postfix-common | File | 1.32 KB | 0644 |
|
| private-files | File | 1.62 KB | 0644 |
|
| private-files-strict | File | 1.18 KB | 0644 |
|
| python | File | 2.24 KB | 0644 |
|
| qt5 | File | 863 B | 0644 |
|
| qt5-compose-cache-write | File | 399 B | 0644 |
|
| qt5-settings-write | File | 514 B | 0644 |
|
| recent-documents-write | File | 466 B | 0644 |
|
| ruby | File | 1008 B | 0644 |
|
| samba | File | 1.27 KB | 0644 |
|
| samba-rpcd | File | 817 B | 0644 |
|
| smbpass | File | 581 B | 0644 |
|
| snap_browsers | File | 1.54 KB | 0644 |
|
| ssl_certs | File | 1.49 KB | 0644 |
|
| ssl_keys | File | 938 B | 0644 |
|
| svn-repositories | File | 1.72 KB | 0644 |
|
| transmission-common | File | 4.28 KB | 0644 |
|
| trash | File | 3.54 KB | 0644 |
|
| ubuntu-bittorrent-clients | File | 821 B | 0644 |
|
| ubuntu-browsers | File | 1.58 KB | 0644 |
|
| ubuntu-console-browsers | File | 731 B | 0644 |
|
| ubuntu-console-email | File | 718 B | 0644 |
|
| ubuntu-email | File | 1.06 KB | 0644 |
|
| ubuntu-feed-readers | File | 456 B | 0644 |
|
| ubuntu-gnome-terminal | File | 300 B | 0644 |
|
| ubuntu-helpers | File | 3.82 KB | 0644 |
|
| ubuntu-konsole | File | 453 B | 0644 |
|
| ubuntu-media-players | File | 2.3 KB | 0644 |
|
| ubuntu-unity7-base | File | 2.5 KB | 0644 |
|
| ubuntu-unity7-launcher | File | 311 B | 0644 |
|
| ubuntu-unity7-messaging | File | 313 B | 0644 |
|
| ubuntu-xterm | File | 346 B | 0644 |
|
| user-download | File | 987 B | 0644 |
|
| user-mail | File | 944 B | 0644 |
|
| user-manpages | File | 1000 B | 0644 |
|
| user-tmp | File | 760 B | 0644 |
|
| user-write | File | 972 B | 0644 |
|
| video | File | 596 B | 0644 |
|
| vulkan | File | 1.11 KB | 0644 |
|
| wayland | File | 713 B | 0644 |
|
| web-data | File | 811 B | 0644 |
|
| winbind | File | 882 B | 0644 |
|
| wutmp | File | 788 B | 0644 |
|
| xad | File | 984 B | 0644 |
|
| xdg-desktop | File | 782 B | 0644 |
|
| xdg-open | File | 2.23 KB | 0644 |
|