Page 2 of 2

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Thu Sep 03, 2015 10:51 pm
by ruy.benton
Thrawn wrote:ABE is specifically for filtering HTTP requests. It's a web firewall, not a general-purpose one. FTP is out of scope
:( lets search another option

Thank you

barbaz wrote:And I missed yet another detail in the rule...

Code: Select all

Site ^(?:[0-9A-Za-z-]+tps?|wss?)://[^/:]+[/:].*\.(?:exe|bat|dll|sh|dmg|cmd|cpl|lnk|pif|scr|vbs|vbe|vb|ws|wsc|wsf|msi|reg|jse|bas|chm|scf|sct|com)(?:[^0-9A-Za-z/].*)?$
Deny INC
Apparently there is also a "ws" protocol that communicates with Internet...
Thanks

barbaz wrote:Yep. (Well, had to dual boot anyway, but using Lubuntu as my main OS.) I'd rather not get into the details of why here.
(see viewtopic.php?p=74942#p74942 for some of it)
Ubuntu send some info ... de-install Amazon ... and he connect to geo.ubuntu.com
I can guide to disable all that ...
RedHAT and Fedora much NSA :lol:

barbaz wrote: ...
Oddly I didn't have very much better luck even starting with a pre-built VM that already had a desktop environment (again, I could use it "as-is" but getting other software onto it was still a problem.)
Any advice for me for next time I decide to try it again?
Yeap no problem ... I test in my side

ruy.benton wrote:Nooooooo ... you sug. Sandbox ...

"I would like a plugin, to alert Firefox -> write files in the system.
I can use lsof ... but lots of work"
barbaz wrote:Well a sandbox will know everything that's written through it... so am I misunderstanding what you're wondering about?
I need only the info ... the path he write ... but i can't find.

And for full protection KVM linux, XEN, Virtualbox, OpenVZ ... for ex.
barbaz wrote:https://l3net.wordpress.com/projects/firejail/
This link looks very interesting to me for a number of reasons. Thanks! :)
I can send more ... other subjects :lol:

Kind Regards,
Ruy

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Thu Sep 03, 2015 11:19 pm
by barbaz
ruy.benton wrote:Ubuntu send some info ... de-install Amazon ... and he connect to geo.ubuntu.com
I can guide to disable all that ...
Thanks, but I think I'm good there. This is part of the reason I'm using *L*ubuntu and not Ubuntu.
In Ubuntu 14.04 I could only partially remove that stuff, but I think I was able to remove it all in a Ubuntu 15.04 VM. Lubuntu (at least the 14.04.1 ISOs) doesn't come with any of it.
(And I don't especially care for the versions of Unity for Ubuntu > 12.04.x anyway.)

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Fri Sep 04, 2015 9:57 pm
by ruy.benton
barbaz wrote: Thanks, but I think I'm good there. This is part of the reason I'm using *L*ubuntu and not Ubuntu.
In Ubuntu 14.04 I could only partially remove that stuff, but I think I was able to remove it all in a Ubuntu 15.04 VM. Lubuntu (at least the 14.04.1 ISOs) doesn't come with any of it.
(And I don't especially care for the versions of Unity for Ubuntu > 12.04.x anyway.)
You can test with "netstat -a" or "netstat -an and see if there is conn. when you enable the wifi or ether.
It's immediate after enable.

The other problem is search ... files, msg ... doesn't mater ... he send to some hosts ... disable in System Settings.

Thank you for your comments and prompt reply

Ruy

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Fri Sep 04, 2015 10:25 pm
by barbaz
ruy.benton wrote:You can test with "netstat -a" or "netstat -an and see if there is conn. when you enable the wifi or ether.
It's immediate after enable.
All the connections that I see are ones that I initiated.
ruy.benton wrote:The other problem is search ... files, msg ... doesn't mater ... he send to some hosts ... disable in System Settings.
I just went through & deinstalled the online scopes, is that not enough?

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Sun Sep 06, 2015 9:53 pm
by ruy.benton
barbaz wrote: All the connections that I see are ones that I initiated.
Test 10 ... 15 min or 1 hour interv.
barbaz wrote:I just went through & deinstalled the online scopes, is that not enough?
Ubuntu -> Privacy other OS ... diferent names.
"Click if you want your history ... " files, png, jpg, odt, pdf

Alert: W$n 10 in last versions ... it's code in Kernal
We de-select and they ( OS ) send.
We need take other action ... Install software and change some var.

Kind Regards,
Ruy

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Sat Dec 24, 2016 10:39 am
by yes_noscript
I dont know why but the rule #1 break .asc & .sig (PGP) files with NoScript 2.9.5.2rc5
The funny thing is, that open the file with browser works, but if i try to save it, a error pop up and in error console i get that:

Code: Select all

Deny INCLUSION on {GET <URL> <<< chrome://browser/content/browser.xul - 1}
#1

Code: Select all

Site ^(?:[0-9A-Za-z-]+tps?|wss?)://[^/:]+[/:].*\.(?:exe|bat|dll|sh|dmg|cmd|cpl|lnk|pif|scr|vbs|vbe|vb|ws|wsc|wsf|msi|reg|jse|bas|chm|scf|sct|com)(?:[^0-9A-Za-z/].*)?$
Deny INC
You can test it with:
"https://download.documentfoundation.org ... 64.msi.asc"
"http://www.palemoon.org/pgp/palemoon-27 ... er.exe.sig"

It look it make difference if the link is HTTPS or not. HTTPS seams to work, but HTTP not. :shock:


The spam filter here is strange. I musst remove URLs and other stuff.

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Sat Dec 24, 2016 5:17 pm
by barbaz
@yes_noscript: known bug viewtopic.php?p=85536#p85536

Re: Block files -> .exe .bat .dll .sh .dmg .cmd .cpl .lnk

Posted: Sat Dec 24, 2016 7:50 pm
by yes_noscript
Thanks.

I add Accept from chrome