ืžืขืœื“ื•ื ื’ ืคื•ืŸ Firejail ืึทืคึผืคึผืœื™ืงืึทื˜ื™ืึธืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืกื™ืกื˜ืขื 0.9.72

ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ 0.9.72 ืื™ื– ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ. ืขืก ืื ื˜ื•ื•ื™ืงืœื˜ ื ืกื™ืกื˜ืขื ืคืืจ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืข ืื•ื™ืกืคื™ืจื•ื ื’ ืคื•ืŸ ื’ืจืืคื™ืฉืข, ืงืื ืกืืœ, ืื•ืŸ ืกืขืจื•ื•ืขืจ ืืคืœื™ืงืืฆื™ืขืก, ืžื™ื ื™ืžื™ื–ื™ืจื ื“ื™ื’ ื“ืขื ืจื™ื–ื™ืงืข ืคื•ืŸ โ€‹โ€‹ืงืืžืคืจืืžื™ื˜ื™ืจืŸ ื“ืขื ื”ืื•ืกื˜ ืกื™ืกื˜ืขื ื•ื•ืขืŸ ืžืขืŸ ืœื•ื™ืคื˜ ื ื™ืฉื˜-ืคืืจื˜ืจื•ื™ื˜ืข ืื“ืขืจ ืคืื˜ืขื ืฆื™ืขืœ ืฉื•ื•ืื›ืข ืคืจืื’ืจืืžืขืŸ. ื“ื™ ืคืจืื’ืจืื ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C, ืคืืจืฉืคืจื™ื™ื˜ ืื•ื ื˜ืขืจ ื“ืขืจ GPLv2 ืœื™ืฆืขื ืฅ, ืื•ืŸ ืœื•ื™ืคื˜ ืื•ื™ืฃ ื™ืขื“ืขืจ ืคืืจืฉืคืจื™ื™ื˜ื•ื ื’. Linux ืžื™ื˜ ืึท ืงืขืจื ืขืœ ืขืœื˜ืขืจ ื•ื•ื™ 3.0. ื’ืจื™ื™ื˜ืข ืคึผืึทืงืึทื“ื–ืฉืึทื– ืžื™ื˜ Firejail ื•ื•ืขืจืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืื™ืŸ deb ืคึฟืึธืจืžืึทื˜ืŸ (Debian, Ubuntu) ืื•ืŸ ืจืคึผื (CentOS, ืคืขื“ืึธืจืึท).

ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ ื ื™ืฆื˜ ื ืขื™ื-ืกืคึผื™ื™ืกื™ื–, ืึทืคึผืึทืจืžืึธืจ, ืื•ืŸ ืกื™ืกื˜ืขื ืจื•ืฃ ืคึฟื™ืœื˜ืขืจื™ื ื’ (ืกืขืงืึธืžืคึผ-ื‘ืคึผืฃ) ืคึฟืึทืจ ืื™ื–ืึธืœืึทืฆื™ืข. Linuxืึทืžืึธืœ ืœืึธื ื˜ืฉื˜, ื ื•ืฆืŸ ืึท ืคึผืจืึธื’ืจืึทื ืื•ืŸ ืึทืœืข ืื™ืจืข ืงื™ื ื“ ืคึผืจืึธืฆืขืกืŸ ื‘ืึทื–ื•ื ื“ืขืจืข ืจืขืคึผืจืขื–ืขื ื˜ืึทืฆื™ืขืก ืคื•ืŸ ืงืขืจื ืขืœ ืจืขืกื•ืจืกืŸ, ืึทื–ืึท ื•ื•ื™ ื“ื™ ื ืขืฅ ืกื˜ืขืง, ืคึผืจืึธืฆืขืก ื˜ืึทื‘ืขืœืข, ืื•ืŸ ืžืึธื•ื ื˜ ืคื•ื ืงื˜ืŸ. ืื™ื ื˜ืขืจ-ืึธืคึผื”ืขื ื’ื™ืงืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ืงืึทืžื‘ื™ื™ื ื“ ืื™ืŸ ืึท ืื™ื™ืŸ ื’ืขื˜ื™ื™ืœื˜ ื–ืึทืžื“ืงืึทืกื˜ืŸ. ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ ืงืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืœื•ื™ืคืŸ ื“ืึธืงืขืจ, LXC, ืื•ืŸ OpenVZ ืงืึทื ื˜ื™ื™ื ืขืจื–.

ื ื™ื˜ ืขื ืœืขืš ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ืงืึทื ื˜ื™ื™ื ืขืจ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜, Firejail ืื™ื– ื’ืึธืจ ืคึผืฉื•ื˜ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ื“ื™ ืฆื•ื’ืจื™ื™ื˜ื•ื ื’ ืคื•ืŸ ืึท ืกื™ืกื˜ืขื ื‘ื™ืœื“ - ื“ืขืจ ืงืึทื ื˜ื™ื™ื ืขืจ ื–ืึทืฅ ืื™ื– ื’ืขืฉืืคืŸ ืื•ื™ืฃ ื“ื™ ืคืœื™ืขืŸ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ื“ื™ ืงืจืึทื ื˜ ื˜ืขืงืข ืกื™ืกื˜ืขื ืื•ืŸ ืื™ื– ืื•ื™ืกื’ืขืžืขืงื˜ ื ืึธืš ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืื™ื– ื’ืขืขื ื“ื™ืงื˜. ืคืœืขืงืกืึทื‘ืึทืœ ืžื™ื˜ืœ ืคื•ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืึทืงืกืขืก ื›ึผืœืœื™ื ืฆื• ื“ื™ ื˜ืขืงืข ืกื™ืกื˜ืขื ืื™ืจ ืงืขื ืขืŸ ื‘ืึทืฉื˜ื™ืžืขืŸ ื•ื•ืึธืก ื˜ืขืงืขืก ืื•ืŸ ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ื–ืขื ืขืŸ ืขืจืœื•ื™ื‘ื˜ ืึธื“ืขืจ ื’ืขืœื™ื™ืงื ื˜ ืึทืงืกืขืก, ืคืึทืจื‘ื™ื ื“ืŸ ืฆื™ื™ื˜ื•ื•ื™ื™ืœื™ื’ืข ื˜ืขืงืข ืกื™ืกื˜ืขืžืขืŸ (ื˜ืžืคึผืคืก) ืคึฟืึทืจ ื“ืึทื˜ืŸ, ื‘ืึทื’ืจืขื ืขืฆืŸ ืึทืงืกืขืก ืฆื• ื˜ืขืงืขืก ืึธื“ืขืจ ื“ื™ืจืขืงื˜ืขืจื™ื– ืฆื• ืœื™ื™ืขื ืขืŸ-ื‘ืœื•ื™ื–, ืคืึทืจื‘ื™ื ื“ืŸ ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ื“ื•ืจืš; ื‘ื™ื ื“ืŸ-ื‘ืืจื’ ืื•ืŸ ืึธื•ื•ื•ืขืจืœื™ื™ืคืก.

ืคึฟืึทืจ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ืคืึธืœืงืก ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืคื™ืจืขืคืึธืงืก, ืงืจืึธื•ืžื™ืึทื, ื•ื•ืœืง ืื•ืŸ ื˜ืจืึทื ืกืžื™ืกื™ืข, ืคืึทืจื˜ื™ืง ืกื™ืกื˜ืขื ืจื•ืคืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืคึผืจืึธื•ืคื™ื™ืœื– ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜. ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื ื™ื™ื˜ื™ืง ืฆื• ืฉื˜ืขืœืŸ ืึท ื–ืึทืžื“ื‘ืึธืงืกืขื“ ืกื•ื•ื™ื•ื•ืข, ื“ื™ ืคื™ืจืขื“ื–ืฉืึทื™ืœ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืžื™ื˜ ื“ื™ SUID ื•ื•ืึธืจืฆืœ ืคืึธืŸ (ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื–ืขื ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืง ื ืึธืš ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื™ืฉืึทืŸ). ืฆื• ืœื•ื™ืคืŸ ืึท ืคึผืจืึธื’ืจืึทื ืื™ืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืžืึธื“ืข, ืคืฉื•ื˜ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื ืึธืžืขืŸ ื•ื•ื™ ืึทืŸ ืึทืจื’ื•ืžืขื ื˜ ืฆื• ื“ื™ ืคื™ื™ืจื“ื–ืฉืึทื™ืœ ื ื•ืฆืŸ, ืœืžืฉืœ, "firejail firefox" ืึธื“ืขืจ "sudo firejail /etc/init.d/nginx start".

ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’:

  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ืกืขืงืึธืžืคึผ ืคื™ืœื˜ืขืจ ืคึฟืึทืจ ืกื™ืกื˜ืขื ืจื•ืคื˜ ื•ื•ืึธืก ื‘ืœืึทืงืก ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ื ืึทืžืขืกืคึผืึทืกืขืก (ื“ื™ "--restrict-namespaces" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• ื’ืขื‘ืŸ). ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืกื™ืกื˜ืขื ืจื•ืคืŸ ื˜ื™ืฉืŸ ืื•ืŸ ืกืขืงืึธืžืคึผ ื’ืจื•ืคึผืขืก.
  • ื™ืžืคึผืจื•ื•ื•ื“ ืงืจืึทืคื˜-ื ืึธื ืขื•ืคึผืจื™ื•ื•ื– ืžืึธื“ืข (NO_NEW_PRIVS), ื•ื•ืึธืก ืคึผืจื™ื•ื•ืขื ืฅ ื ื™ื™ึทืข ืคึผืจืึทืกืขืกืึทื– ืคื•ืŸ ื’ื™ื™ื ื™ื ื’ ื ืึธืš ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–.
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืึทืคึผืึทืจืžืึธืจ ืคึผืจืึธื•ืคื™ื™ืœื– (ื“ื™ "--ืึทืคึผืคึผืึทืจืžืึธืจ" ืึธืคึผืฆื™ืข ืื™ื– ื’ืขืคึฟื™ื ื˜ ืคึฟืึทืจ ืงืฉืจ).
  • ื“ื™ ื ืขื˜ื˜ืจืึทืกืข ื ืขืฅ ืคืึทืจืงืขืจ ื˜ืจืึทืงื™ื ื’ ืกื™ืกื˜ืขื, ื•ื•ืึธืก ื“ื™ืกืคึผืœื™ื™ื– ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ IP ืื•ืŸ ืคืึทืจืงืขืจ ื™ื ื˜ืขื ืกื™ื˜ื™ ืคื•ืŸ ื™ืขื“ืขืจ ืึทื“ืจืขืก, ื™ืžืคึผืœืึทืžืึทื ืฅ ICMP ืฉื˜ื™ืฆืŸ ืื•ืŸ ืึธืคืคืขืจืก ื“ื™ "--dnstrace", "--icmptrace" ืื•ืŸ "--snitrace" ืึธืคึผืฆื™ืขืก.
  • ื“ื™ --cgroup ืื•ืŸ --shell ืงืึทืžืึทื ื“ื– ื–ืขื ืขืŸ ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ (ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืื™ื– --shell=none). Firetunnel ื‘ื•ื™ืขืŸ ืื™ื– ืกื˜ืึทืคึผื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜. ืคืึทืจืงืจื™ืคึผืœื˜ chroot, private-lib ืื•ืŸ tracelog ืกืขื˜ื˜ื™ื ื’ืก ืื™ืŸ /etc/firejail/firejail.config. ื’ืจืกืขืงื•ืจื™ื˜ื™ ืฉื˜ื™ืฆืŸ ืื™ื– ื“ื™ืกืงืึทื ื˜ื™ื ื™ื•ื“.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster