3 ms·
> Except of course on Linux, the firewall isn't application-aware, so you can't even control which processes are allowed to open inbound communication. You cer
by tene 17y ago
> Except of course on Linux, the firewall isn't application-aware, so you can't even control which processes are allowed to open inbound communication.
You certainly can set application-level network privileges, and Red Hat derived distros do by default. For example, to list all the applications that are allowed to bind to port 80:
[sweeks@kweh ~]$ sudo sesearch --allow -t http_port_t -p name_bind
Found 15 semantic av rules:
allow httpd_t http_port_t : tcp_socket { name_bind name_connect } ;
allow kerneloops_t http_port_t : tcp_socket { name_bind name_connect } ;
allow varnishd_t http_port_t : tcp_socket { name_bind name_connect } ;
allow dnsmasq_t port_type : udp_socket { recv_msg send_msg name_bind } ;
allow svirt_t port_type : tcp_socket { name_bind name_connect } ;
allow svirt_t port_type : udp_socket { recv_msg send_msg name_bind } ;
allow squid_t http_port_t : tcp_socket { name_bind name_connect } ;
allow corenet_unconfined_type port_type : tcp_socket { recv_msg send_msg name_bind name_connect } ;
allow portreserve_t port_type : tcp_socket name_bind ;
allow corenet_unconfined_type port_type : udp_socket { recv_msg send_msg name_bind } ;
allow portreserve_t port_type : udp_socket name_bind ;
allow varnishd_t port_type : tcp_socket { name_bind name_connect } ;
allow qemu_t port_type : tcp_socket { name_bind name_connect } ;
allow qemu_t port_type : udp_socket { recv_msg send_msg name_bind } ;
allow squid_t port_type : tcp_socket { name_bind name_connect } ;
Any processes running under other domains won't be allowed to bind to port 80.