Sincerely,
CookieMonster.
- Code: Select all
subject /usr/sbin/apache2 op {
/usr/share r
/etc r
/etc/grsec h
/etc/ld.so.cache r
/tmp rwxcld
/lib rx
/usr/lib rx
/var/lib/php5/ rxwcd
/var/log/apache2 a
/var/log/apache a
/var/run/apache.pid wclrd
/var/run/apache2.pid wclrd
/var/run/apache2 crwxdl
/var/www rxwlcd
/proc r
/proc/meminfo r
/proc/filesystems r
/proc/sys/kernel r
/dev/null rw
/dev/urandom rx
/bin/dash rx
/usr/bin/cronolog rx
/usr/sbin/apache2 rx
/usr/sbin/sendmail rx
/usr/sbin/postdrop rx
/
-CAP_ALL
+CAP_DAC_OVERRIDE
+CAP_KILL
+CAP_SETGID
+CAP_SETUID
+CAP_NET_BIND_SERVICE
+CAP_CHOWN
RES_CRASH 1 10m
connect 0.0.0.0:3306 stream tcp ip
connect 0.0.0.0/0:80 stream tcp ip
connect 0.0.0.0/0:53 dgram udp
bind 0.0.0.0/0:80 stream tcp
bind 0.0.0.0/0:443 stream tcp
}
subject /usr/sbin/apache2:/bin/dash {
/ r
/usr/bin/cronolog x
/usr/sbin/sendmail x
/usr/sbin/postdrop x
/usr/bin h
/bin h
/usr/sbin h
/sbin h
/etc/grsec h
connect disabled
bind disabled
-CAP_ALL
}
subject /usr/sbin/apache2:/bin/dash:/usr/bin/cronolog {
/ h
/mnt/log rwcdl
connect disabled
bind disabled
-CAP_ALL
}
subject /usr/sbin/apache2:/bin/dash:/usr/sbin/sendmail {
/ rwxlcd
/etc/grsec h
connect 0.0.0.0/0:25 stream ip tcp
connect 0.0.0.0/0:0 dgram ip tcp
bind 0.0.0.0/0:0 dgram ip
-CAP_ALL
}
subject /usr/sbin/apache2:/usr/sbin/sendmail {
/ rwxlcd
/usr/sbin/postdrop x
/usr/bin h
/bin h
/usr/sbin h
/sbin h
/etc/grsec h
connect disabled
bind disabled
-CAP_ALL
}
subject /usr/sbin/apache2:/usr/sbin/sendmail:/usr/sbin/postdrop {
/ rwxlcd
/usr/bin h
/bin h
/usr/sbin h
/sbin h
/etc/grsec h
connect disabled
bind disabled
-CAP_ALL
}