Sandboxing applications on Scientific Linux and family

Discussion in 'all things UNIX' started by Ocky, Jun 19, 2011.

Thread Status:
Not open for further replies.
  1. Ocky

    Ocky Registered Member

    Joined:
    May 6, 2006
    Posts:
    2,713
    Location:
    George, S.Africa
    I am convinced this is overkill, but it works nicely. (First install the policycoreutils-sandbox package:- yum install policycoreutils-sandbox)
    mkdir /tmp/myweb ~/myweb
    sandbox -X -T /tmp/myweb -H ~/myweb -t sandbox_web_t firefox

    Then you can download any content, setup bookmarks ... and the sandbox will not remove them when you are done. If you later run a command with the same sandbox homedir and tmpdir, the content will be there.
    (From Dan Walsh site)

    Just replace firefox with whatever eg. gftp, opera etc. The saved stuff will be in ~/myweb

    Sandbox.png

    (Posting here in case you didn't see it in SL forum)

    Edit:-
    The -i flag.

    sandbox -X -t sandbox_web_t -i /home/user/.opera opera

    Copies the contents of the .opera directory into the sandbox. Probably not a great idea
    if passwords are not removed beforehand.

    Sandbox i flag.png
     
    Last edited: Jun 20, 2011
  2. mack_guy911

    mack_guy911 Registered Member

    Joined:
    Mar 21, 2007
    Posts:
    2,677
    very nice tutorial indeed we want more tutorials ocky :argh:

    making them help you when you needed them also newbie like me :p
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Can we do it on Ubuntu? I wish some one makes a GUI tool for these things.
     
  4. Ocky

    Ocky Registered Member

    Joined:
    May 6, 2006
    Posts:
    2,713
    Location:
    George, S.Africa
    SELinux is apparently available in Ubuntu. https://wiki.ubuntu.com/Security/Features#SELinux
    However Apparmor is the preferred Mac. SELinux may slow down your computing a little.
    Please note that I have never tried SELinux on any Ubuntus, but it works really nice on Scientific Linux 6 and I have not noticed any slowness compared to Ubuntu.
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.