Files
bpfire/html/cgi-bin
Peter Müller 0b6a2e761b Tor: Enable syscall sandbox
This makes post-exploitation activities harder, in case the local Tor
instance has been compromised. It is worth noticing that Tor won't
respond to a "GETINFO address" command on the control port if sandboxed,
but our CGI does not make use of it, and neither is any legitimate
service on IPFire doing so.

Tested on a small middle relay running on an IPFire machine.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2021-10-22 10:20:37 +00:00
..
2021-04-08 10:11:34 +00:00
2021-06-10 14:30:51 +01:00
2021-04-08 10:11:34 +00:00
2021-09-12 09:42:47 +00:00
2021-07-07 09:34:31 +00:00
2021-06-10 14:30:52 +01:00
2021-07-09 12:56:17 +00:00
2021-06-10 14:30:53 +01:00
2021-06-10 14:30:53 +01:00
2021-06-10 14:30:53 +01:00
2021-04-08 10:11:34 +00:00
2021-04-08 10:11:34 +00:00
2021-04-08 10:11:34 +00:00
2021-06-10 14:30:54 +01:00
2021-04-08 10:11:34 +00:00
2021-04-08 10:11:34 +00:00
2021-10-13 12:22:49 +00:00
2021-10-22 10:20:37 +00:00
2021-04-08 10:11:34 +00:00
2021-04-08 10:19:55 +00:00