LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-04-2016, 10:36 PM   #1
sneakyimp
Senior Member
 
Registered: Dec 2004
Posts: 1,056

Rep: Reputation: 78
possible to bar a process/application from accessing network?


I'm considering installing Anki on my workstation. It's available via the Ubuntu Software Center. I'm a bit unsure whether this software is trustworthy and was hoping to mitigate my exposure to trouble by blocking this program's access to the network entirely.

Is such a thing possible?

Alternatively, if anyone could recommend trustworthy spaced repetition software (or better yet an algorithm!), I'd greatly appreciate it.
 
Old 05-05-2016, 03:06 AM   #2
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,308
Blog Entries: 3

Rep: Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721
You could try making an apparmor profile for it and using that to block net access. If you haven't done it before, it is not hard though it requires a significant time investment for reading the documentation. I think it might be enough to leave the 'network' declarations out as well as access to some net-related /proc ones, though I'm not sure about the latter. You'll have to develop the profile in complain mode and watch the logs while running the program through its paces before trying in enforce mode.
 
Old 05-05-2016, 03:12 AM   #3
cliffordw
Member
 
Registered: Jan 2012
Location: South Africa
Posts: 509

Rep: Reputation: 203Reputation: 203Reputation: 203
Hi there,

Another approach might be to try it in a virtual machine (KVM / Virtualbox) with no network access. That is probably quicker to setup than apparmor of you're not familiar with it.
 
1 members found this post helpful.
Old 05-05-2016, 08:35 AM   #4
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,308
Blog Entries: 3

Rep: Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721
After looking at Anki for Apparmor, it seems to want all kinds of access around the system. So I'd go with cliffordw's approach of locking it in a netless VM like KVM/VirtualBox/Qemu.
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Trouble in accessing device register using BAR gthakur Linux - General 1 07-14-2008 12:32 PM
how do i block an application from accessing network? firewall? hisnumber666isback Linux - Software 1 05-06-2006 10:45 PM
Accessing the task bar without a mouse superztnt Linux - Newbie 2 06-08-2004 07:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration