# vim:syntax=apparmor # privacy-violations contains rules for common files that you want to # explicitly deny access # privacy violations (don't audit files under $HOME otherwise get a # lot of false positives when reading contents of directories) deny @{HOME}/.*history mrwkl, deny @{HOME}/.fetchmail* mrwkl, deny @{HOME}/.viminfo* mrwkl, deny @{HOME}/.*~ mrwkl, deny @{HOME}/.*.swp mrwkl, deny @{HOME}/.*~1~ mrwkl, deny @{HOME}/.*.bak mrwkl, # special attention to (potentially) executable files audit deny @{HOME}/bin/{,**} wl, audit deny @{HOME}/.config/ w, audit deny @{HOME}/.config/autostart/{,**} wl, audit deny @{HOME}/.config/upstart/{,**} wl, audit deny @{HOME}/.init/{,**} wl, audit deny @{HOME}/.kde{,4}/ w, audit deny @{HOME}/.kde{,4}/Autostart/{,**} wl, audit deny @{HOME}/.kde{,4}/env/{,**} wl, audit deny @{HOME}/.local/{,share/} w, audit deny @{HOME}/.local/share/thumbnailers/{,**} wl, audit deny @{HOME}/.pki/ w, audit deny @{HOME}/.pki/nssdb/{,*.so{,.[0-9]*}} wl, # don't allow reading/updating of run control files deny @{HOME}/.*rc mrk, audit deny @{HOME}/.*rc wl, # bash deny @{HOME}/.bash* mrk, audit deny @{HOME}/.bash* wl, deny @{HOME}/.inputrc mrk, audit deny @{HOME}/.inputrc wl, # sh/dash/csh/tcsh/pdksh/zsh deny @{HOME}/.{,z}profile* mrk, audit deny @{HOME}/.{,z}profile* wl, deny @{HOME}/.{,z}log{in,out} mrk, audit deny @{HOME}/.{,z}log{in,out} wl, deny @{HOME}/.zshenv mrk, audit deny @{HOME}/.zshenv wl,
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
apparmor_api | Folder | 0755 |
|
|
lxc | Folder | 0755 |
|
|
ubuntu-browsers.d | Folder | 0755 |
|
|
X | File | 1.86 KB | 0644 |
|
apache2-common | File | 869 B | 0644 |
|
aspell | File | 308 B | 0644 |
|
audio | File | 1.72 KB | 0644 |
|
authentication | File | 1.55 KB | 0644 |
|
base | File | 6.21 KB | 0644 |
|
bash | File | 1.48 KB | 0644 |
|
consoles | File | 798 B | 0644 |
|
cups-client | File | 714 B | 0644 |
|
dbus | File | 593 B | 0644 |
|
dbus-accessibility | File | 630 B | 0644 |
|
dbus-accessibility-strict | File | 637 B | 0644 |
|
dbus-session | File | 638 B | 0644 |
|
dbus-session-strict | File | 919 B | 0644 |
|
dbus-strict | File | 677 B | 0644 |
|
dconf | File | 246 B | 0644 |
|
dovecot-common | File | 572 B | 0644 |
|
enchant | File | 1.96 KB | 0644 |
|
fcitx | File | 456 B | 0644 |
|
fcitx-strict | File | 712 B | 0644 |
|
fonts | File | 1.93 KB | 0644 |
|
freedesktop.org | File | 2.37 KB | 0644 |
|
gnome | File | 3.3 KB | 0644 |
|
gnupg | File | 356 B | 0644 |
|
ibus | File | 640 B | 0644 |
|
kde | File | 2.01 KB | 0644 |
|
kerberosclient | File | 1.08 KB | 0644 |
|
launchpad-integration | File | 824 B | 0644 |
|
ldapclient | File | 686 B | 0644 |
|
libpam-systemd | File | 659 B | 0644 |
|
likewise | File | 489 B | 0644 |
|
mdns | File | 436 B | 0644 |
|
mir | File | 593 B | 0644 |
|
mozc | File | 471 B | 0644 |
|
mysql | File | 641 B | 0644 |
|
nameservice | File | 3.75 KB | 0644 |
|
nis | File | 524 B | 0644 |
|
nvidia | File | 519 B | 0644 |
|
openssl | File | 470 B | 0644 |
|
orbit2 | File | 93 B | 0644 |
|
p11-kit | File | 899 B | 0644 |
|
perl | File | 872 B | 0644 |
|
php | File | 974 B | 0644 |
|
php5 | File | 105 B | 0644 |
|
postfix-common | File | 1.08 KB | 0644 |
|
private-files | File | 1.48 KB | 0644 |
|
private-files-strict | File | 1006 B | 0644 |
|
python | File | 1.5 KB | 0644 |
|
ruby | File | 906 B | 0644 |
|
samba | File | 834 B | 0644 |
|
smbpass | File | 476 B | 0644 |
|
ssl_certs | File | 924 B | 0644 |
|
ssl_keys | File | 650 B | 0644 |
|
svn-repositories | File | 1.61 KB | 0644 |
|
tor | File | 547 B | 0644 |
|
ubuntu-bittorrent-clients | File | 698 B | 0644 |
|
ubuntu-browsers | File | 1.62 KB | 0644 |
|
ubuntu-console-browsers | File | 611 B | 0644 |
|
ubuntu-console-email | File | 601 B | 0644 |
|
ubuntu-email | File | 902 B | 0644 |
|
ubuntu-feed-readers | File | 339 B | 0644 |
|
ubuntu-gnome-terminal | File | 182 B | 0644 |
|
ubuntu-helpers | File | 3.35 KB | 0644 |
|
ubuntu-konsole | File | 343 B | 0644 |
|
ubuntu-media-players | File | 2.18 KB | 0644 |
|
ubuntu-unity7-base | File | 2.39 KB | 0644 |
|
ubuntu-unity7-launcher | File | 191 B | 0644 |
|
ubuntu-unity7-messaging | File | 192 B | 0644 |
|
ubuntu-xterm | File | 237 B | 0644 |
|
user-download | File | 876 B | 0644 |
|
user-mail | File | 837 B | 0644 |
|
user-manpages | File | 889 B | 0644 |
|
user-tmp | File | 654 B | 0644 |
|
user-write | File | 864 B | 0644 |
|
video | File | 123 B | 0644 |
|
wayland | File | 580 B | 0644 |
|
web-data | File | 705 B | 0644 |
|
winbind | File | 739 B | 0644 |
|
wutmp | File | 585 B | 0644 |
|
xad | File | 883 B | 0644 |
|
xdg-desktop | File | 673 B | 0644 |
|