spender's proc acl
Posted: Wed Mar 06, 2002 3:15 pm
Here's my proc acl:
/usr/X11R6/bin/XFree86 {
/ rwx
/var/log/XFree86.0.log rwo
+CAP_SYS_RAWIO
+CAP_SYS_MODULE
}
/usr/sbin/sshd hp {
/ rwx
/etc/shadow ro
/var/log/lastlog rwo
+CAP_NET_BIND_SERVICE
}
/usr/bin/ssh {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/bin/wine {
/ rwx
+CAP_SYS_RAWIO
}
/usr/bin/wineserver {
/ rwx
+CAP_SYS_RAWIO
}
/usr/bin/cdp {
/ rwx
+CAP_SYS_RAWIO
}
/bin/su {
/ rwx
/etc/shadow ro
}
/bin/login {
/ rwx
/etc/shadow ro
/var/log/lastlog rwo
}
/etc/rc.d/init.d/halt vk {
/ rwx
+CAP_SYS_ADMIN
+CAP_SYS_RAWIO
+CAP_NET_ADMIN
}
/etc/rc.d/rc vk {
/ rwx
+CAP_SYS_ADMIN
+CAP_NET_ADMIN
}
/usr/sbin/httpd {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/lib/postfix/master {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/sbin/named {
/ rwx
+CAP_NET_BIND_SERVICE
+CAP_SYS_CHROOT
+CAP_SETPCAP
}
/usr/sbin/proftpd {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/sbin/xinetd {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/local/bin/snort {
/ rwx
/var/log/snort rwo
}
/usr/X11R6/bin/XFree86 {
/ rwx
/var/log/XFree86.0.log rwo
+CAP_SYS_RAWIO
+CAP_SYS_MODULE
}
/usr/sbin/sshd hp {
/ rwx
/etc/shadow ro
/var/log/lastlog rwo
+CAP_NET_BIND_SERVICE
}
/usr/bin/ssh {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/bin/wine {
/ rwx
+CAP_SYS_RAWIO
}
/usr/bin/wineserver {
/ rwx
+CAP_SYS_RAWIO
}
/usr/bin/cdp {
/ rwx
+CAP_SYS_RAWIO
}
/bin/su {
/ rwx
/etc/shadow ro
}
/bin/login {
/ rwx
/etc/shadow ro
/var/log/lastlog rwo
}
/etc/rc.d/init.d/halt vk {
/ rwx
+CAP_SYS_ADMIN
+CAP_SYS_RAWIO
+CAP_NET_ADMIN
}
/etc/rc.d/rc vk {
/ rwx
+CAP_SYS_ADMIN
+CAP_NET_ADMIN
}
/usr/sbin/httpd {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/lib/postfix/master {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/sbin/named {
/ rwx
+CAP_NET_BIND_SERVICE
+CAP_SYS_CHROOT
+CAP_SETPCAP
}
/usr/sbin/proftpd {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/sbin/xinetd {
/ rwx
+CAP_NET_BIND_SERVICE
}
/usr/local/bin/snort {
/ rwx
/var/log/snort rwo
}