3 ms·
Have a look at OpenSnitch: https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch Never used it myself, only remembering it from my
by thg 5y ago
Have a look at OpenSnitch: https://github.com/evilsocket/opensnitch https://github.com/evilsocket/opensnitch
Never used it myself, only remembering it from my thesis days about essentially the same topic. I see they made the jump away from Python to Go and I'm also somewhat surprised the project is not only still active, but appears to have matured nicely. Guess I'll have to check it out now!
Here's the initial HN discussion of OpenSnitch from 5 years ago: https://news.ycombinator.com/item?id=14245270 https://news.ycombinator.com/item?id=14245270
- cookiengineer 5y agoI'm using OpenSnitch for over 2 years now on my desktop systems. Can fully recommend. I've set the default timeout to 30 seconds so I have time to decide/chime in, and the default action to one-time deny so it doesn't mess up my rules when I'm not at the computer. Compared to previous Linux firewalls it's able to filter by binary and command line path (e.g. is able to differ between python server.py and python malware.py), which I think is pretty amazing. Though I have to say due to the nature of wine, allowing things in nice rules there is a little harder (cause everything uses rundll32.dll anyways :-/ ).