Iptables для ньюфага(запретить выход конкретному приложению)
Привет, делал по инструкции
https://serverfault.com/questions/550276/how-to-block-internet-access-to-certain-programs-on-linux
Create, validate new group; add required users to this group:
Create: groupadd no-internet
Validate: grep no-internet /etc/group
Add user: useradd -g no-internet username
Note: If you’re modifying already existing user you should run: usermod -a -G no-internet userName check with : sudo groups userName
Create a script in your path and make it executable:
Create: nano /home/username/.local/bin/no-internet
Executable: chmod 755 /home/username/.local/bin/no-internet
Content: #!/bin/bash sg no-internet «$@»
Add iptables rule for dropping network activity for group no-internet:
iptables -I OUTPUT 1 -m owner –gid-owner no-internet -j DROP
Note: Don’t forget to make the changes permanent, so it would be applied automatically after reboot. Doing it, depends on your Linux distribution.
- Check it, for example on Firefox by running:
no-internet «firefox»
После того как ввожу no-internet «firefox» или sudo no-internet «firefox» получаю bash/sudo соответственно no-internet: command not found Что я делаю не так?