LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-16-2017, 08:54 PM   #1
oxidante
LQ Newbie
 
Registered: Feb 2017
Distribution: Debian
Posts: 2

Rep: Reputation: Disabled
Question Restricting networking connections by executable file path?


Hello, I use iptables to restrict connections by IP, protocol, and port. However, it doesn't seem to support the creation of rules based on executable file paths. The Windows 7/8 and 10 come with a native firewall that lets the user to select a file path and to create rules for it. I've found various answers on Stackoverflow and similars, but all of them give a solution that only works with old versions of iptables. I really need to know how to use iptables or netfilter to accomplish this task, because I want to create a white list of allowed executables that can access remote servers.
 
Old 02-16-2017, 09:37 PM   #2
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
Hello and welcome to LQ.

What happens when you try something like this? http://serverfault.com/questions/550...grams-on-linux

See notes at bottom for naming groups.
 
1 members found this post helpful.
Old 02-16-2017, 10:01 PM   #3
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,309
Blog Entries: 3

Rep: Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721
Welcome.

If your distro has apparmor, then you can use it to a certain extent. It has limited capabilities to restrict networking but it does have something. The apparmor profiles are applied based on the application's path. The newer versions of apparmor have more capabilities. Apparently there's a long-standing ticket open in the bug tracker in regards to more fine-grained networking restrictions, but do check to see what your distro has.
 
1 members found this post helpful.
Old 02-17-2017, 07:17 AM   #4
camp0
Member
 
Registered: Dec 2016
Location: Dublin
Distribution: Fedora
Posts: 70

Rep: Reputation: 4
I think the best option for you is iptables as jefro mention.
 
Old 02-17-2017, 05:54 PM   #5
oxidante
LQ Newbie
 
Registered: Feb 2017
Distribution: Debian
Posts: 2

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by jefro View Post
Hello and welcome to LQ.

What happens when you try something like this? http://serverfault.com/questions/550...grams-on-linux

See notes at bottom for naming groups.
Thanks for your answer, jefro. I thought this old method wasn't working anymore, but I was wrong.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] How to get the absolute path of the running executable file and current work path ? 915086731 Programming 3 11-01-2011 09:28 AM
Adding a executable file $PATH Variable ajeet@linux Solaris / OpenSolaris 3 03-18-2010 12:30 PM
executable file: Which path will go from _start to main function valpa Programming 1 09-04-2008 08:08 PM
Executable file path problem jinics Linux - General 5 02-22-2007 06:51 AM
restricting remote connections dominant Linux - General 0 03-03-2004 11:56 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:06 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration