/
snap
/
core24
/
1643
/
usr
/
sbin
/
/snap/core24/1643/usr/sbin
mkdir
upload
Name
Size
Mode
Actions
aa-load
39680
0755
edit
dl
rm
aa-remove-unknown
3225
0755
edit
dl
rm
aa-status
40000
0755
edit
dl
rm
aa-teardown
137
0755
edit
dl
rm
add-shell
1053
0755
edit
dl
rm
agetty
60992
0755
edit
dl
rm
apparmor_parser
1629848
0755
edit
dl
rm
apparmor_status
40000
0755
edit
dl
rm
arpd
26960
0755
edit
dl
rm
arptables
224424
0755
edit
dl
rm
arptables-nft
224424
0755
edit
dl
rm
arptables-nft-restore
224424
0755
edit
dl
rm
arptables-nft-save
224424
0755
edit
dl
rm
arptables-restore
224424
0755
edit
dl
rm
arptables-save
224424
0755
edit
dl
rm
badblocks
35144
0755
edit
dl
rm
blkdeactivate
16351
0755
edit
dl
rm
blkdiscard
22912
0755
edit
dl
rm
blkid
55720
0755
edit
dl
rm
blkzone
35200
0755
edit
dl
rm
blockdev
35200
0755
edit
dl
rm
bridge
111096
0755
edit
dl
rm
capsh
58456
0755
edit
dl
rm
cfdisk
97008
0755
edit
dl
rm
chcpu
31104
0755
edit
dl
rm
chgpasswd
59720
0755
edit
dl
rm
chmem
35200
0755
edit
dl
rm
chpasswd
55736
0755
edit
dl
rm
chroot
39432
0755
edit
dl
rm
cpgr
49608
0755
edit
dl
rm
cppw
49608
0755
edit
dl
rm
cryptdisks_start
1544
0755
edit
dl
rm
cryptdisks_stop
844
0755
edit
dl
rm
cryptsetup
231320
0755
edit
dl
rm
ctrlaltdel
14720
0755
edit
dl
rm
dcb
82448
0755
edit
dl
rm
debugfs
231288
0755
edit
dl
rm
depmod
174328
0755
edit
dl
rm
devlink
154480
0755
edit
dl
rm
dhcpcd
404888
0755
edit
dl
rm
dmsetup
175160
0755
edit
dl
rm
dmstats
175160
0755
edit
dl
rm
dosfsck
80264
0755
edit
dl
rm
dosfslabel
39304
0755
edit
dl
rm
dumpe2fs
35136
0755
edit
dl
rm
e2freefrag
18744
0755
edit
dl
rm
e2fsck
373080
0755
edit
dl
rm
e2image
43328
0755
edit
dl
rm
e2label
113216
0755
edit
dl
rm
e2mmpstatus
35136
0755
edit
dl
rm
e2scrub
7294
0755
edit
dl
rm
e2scrub_all
5394
0755
edit
dl
rm
e2undo
22840
0755
edit
dl
rm
e4crypt
31104
0755
edit
dl
rm
e4defrag
35128
0755
edit
dl
rm
ebtables
224424
0755
edit
dl
rm
ebtables-nft
224424
0755
edit
dl
rm
ebtables-nft-restore
224424
0755
edit
dl
rm
ebtables-nft-save
224424
0755
edit
dl
rm
ebtables-restore
224424
0755
edit
dl
rm
ebtables-save
224424
0755
edit
dl
rm
ebtables-translate
224424
0755
edit
dl
rm
ethtool
667320
0755
edit
dl
rm
faillock
22848
0755
edit
dl
rm
fatlabel
39304
0755
edit
dl
rm
fdisk
117168
0755
edit
dl
rm
filefrag
18760
0755
edit
dl
rm
findfs
14720
0755
edit
dl
rm
fsck
43440
0755
edit
dl
rm
fsck.cramfs
31168
0755
edit
dl
rm
fsck.ext2
373080
0755
edit
dl
rm
fsck.ext3
373080
0755
edit
dl
rm
fsck.ext4
373080
0755
edit
dl
rm
fsck.fat
80264
0755
edit
dl
rm
fsck.minix
55712
0755
edit
dl
rm
fsck.msdos
80264
0755
edit
dl
rm
fsck.vfat
80264
0755
edit
dl
rm
fsfreeze
14720
0755
edit
dl
rm
fstab-decode
14648
0755
edit
dl
rm
fstrim
43392
0755
edit
dl
rm
genl
123472
0755
edit
dl
rm
getcap
14648
0755
edit
dl
rm
getpcaps
14648
0755
edit
dl
rm
getty
60992
0755
edit
dl
rm
groupadd
72840
0755
edit
dl
rm
groupdel
64424
0755
edit
dl
rm
groupmems
59744
0755
edit
dl
rm
groupmod
72744
0755
edit
dl
rm
grpck
59720
0755
edit
dl
rm
grpconv
51368
0755
edit
dl
rm
grpunconv
51368
0755
edit
dl
rm
halt
1501304
0755
edit
dl
rm
iconvconfig
35296
0755
edit
dl
rm
init
100816
0755
edit
dl
rm
insmod
174328
0755
edit
dl
rm
installkernel
2659
0755
edit
dl
rm
integritysetup
68672
0755
edit
dl
rm
invoke-rc.d
16517
0755
edit
dl
rm
ip
718896
0755
edit
dl
rm
ip6tables
224424
0755
edit
dl
rm
ip6tables-apply
7052
0755
edit
dl
rm
ip6tables-legacy
95176
0755
edit
dl
rm
ip6tables-legacy-restore
95176
0755
edit
dl
rm
ip6tables-legacy-save
95176
0755
edit
dl
rm
ip6tables-nft
224424
0755
edit
dl
rm
ip6tables-nft-restore
224424
0755
edit
dl
rm
ip6tables-nft-save
224424
0755
edit
dl
rm
ip6tables-restore
224424
0755
edit
dl
rm
ip6tables-restore-translate
224424
0755
edit
dl
rm
ip6tables-save
224424
0755
edit
dl
rm
ip6tables-translate
224424
0755
edit
dl
rm
iptables
224424
0755
edit
dl
rm
iptables-apply
7052
0755
edit
dl
rm
iptables-legacy
95176
0755
edit
dl
rm
iptables-legacy-restore
95176
0755
edit
dl
rm
iptables-legacy-save
95176
0755
edit
dl
rm
iptables-nft
224424
0755
edit
dl
rm
iptables-nft-restore
224424
0755
edit
dl
rm
iptables-nft-save
224424
0755
edit
dl
rm
iptables-restore
224424
0755
edit
dl
rm
iptables-restore-translate
224424
0755
edit
dl
rm
iptables-save
224424
0755
edit
dl
rm
iptables-translate
224424
0755
edit
dl
rm
isosize
14720
0755
edit
dl
rm
killall5
26856
0755
edit
dl
rm
ldattach
27008
0755
edit
dl
rm
ldconfig
387
0755
edit
dl
rm
ldconfig.real
1051280
0755
edit
dl
rm
logsave
14496
0755
edit
dl
rm
losetup
76304
0755
edit
dl
rm
lsmod
174328
0755
edit
dl
rm
mkdosfs
52048
0755
edit
dl
rm
mke2fs
133752
0755
edit
dl
rm
mkfs
14720
0755
edit
dl
rm
mkfs.bfs
22912
0755
edit
dl
rm
mkfs.cramfs
35144
0755
edit
dl
rm
mkfs.ext2
133752
0755
edit
dl
rm
mkfs.ext3
133752
0755
edit
dl
rm
mkfs.ext4
133752
0755
edit
dl
rm
mkfs.fat
52048
0755
edit
dl
rm
mkfs.minix
43408
0755
edit
dl
rm
mkfs.msdos
52048
0755
edit
dl
rm
mkfs.vfat
52048
0755
edit
dl
rm
mkhomedir_helper
22872
0755
edit
dl
rm
mklost+found
14648
0755
edit
dl
rm
mkswap
51592
0755
edit
dl
rm
modinfo
174328
0755
edit
dl
rm
modprobe
174328
0755
edit
dl
rm
netplan
802
0755
edit
dl
rm
newusers
89048
0755
edit
dl
rm
nfnl_osf
18736
0755
edit
dl
rm
nologin
14640
0755
edit
dl
rm
pam_extrausers_chkpwd
26944
2755
edit
dl
rm
pam_extrausers_update
35136
0755
edit
dl
rm
pam_namespace_helper
467
0755
edit
dl
rm
pam_timestamp_check
14656
0755
edit
dl
rm
pivot_root
14720
0755
edit
dl
rm
plymouthd
150088
0755
edit
dl
rm
poweroff
1501304
0755
edit
dl
rm
pwck
55592
0755
edit
dl
rm
pwconv
47272
0755
edit
dl
rm
pwhistory_helper
22848
0755
edit
dl
rm
pwunconv
47272
0755
edit
dl
rm
readprofile
22944
0755
edit
dl
rm
reboot
1501304
0755
edit
dl
rm
remove-shell
1111
0755
edit
dl
rm
resize2fs
71992
0755
edit
dl
rm
resolvconf
162480
0755
edit
dl
rm
rfkill
30952
0755
edit
dl
rm
rmmod
174328
0755
edit
dl
rm
rmt
56024
0755
edit
dl
rm
rmt-tar
56024
0755
edit
dl
rm
rtacct
28992
0755
edit
dl
rm
rtcwake
35200
0755
edit
dl
rm
rtmon
119312
0755
edit
dl
rm
runlevel
1501304
0755
edit
dl
rm
runuser
55680
0755
edit
dl
rm
service
9104
0755
edit
dl
rm
setcap
14648
0755
edit
dl
rm
sfdisk
108928
0755
edit
dl
rm
shadowconfig
2273
0755
edit
dl
rm
shutdown
1501304
0755
edit
dl
rm
sshd
921416
0755
edit
dl
rm
start-stop-daemon
48632
0755
edit
dl
rm
sudo_logsrvd
254464
0755
edit
dl
rm
sudo_sendlog
134832
0755
edit
dl
rm
sulogin
43392
0755
edit
dl
rm
swaplabel
18816
0755
edit
dl
rm
swapoff
22912
0755
edit
dl
rm
swapon
43392
0755
edit
dl
rm
switch_root
22912
0755
edit
dl
rm
sysctl
31112
0755
edit
dl
rm
tarcat
936
0755
edit
dl
rm
tc
645200
0755
edit
dl
rm
telinit
1501304
0755
edit
dl
rm
tipc
92688
0755
edit
dl
rm
tune2fs
113216
0755
edit
dl
rm
ub-device-create
22856
0755
edit
dl
rm
unix_chkpwd
31040
2755
edit
dl
rm
unix_update
35136
0755
edit
dl
rm
update-ca-certificates
5446
0755
edit
dl
rm
update-passwd
35392
0755
edit
dl
rm
update-shells
3984
0755
edit
dl
rm
useradd
143232
0755
edit
dl
rm
userdel
93192
0755
edit
dl
rm
usermod
130712
0755
edit
dl
rm
vdpa
35392
0755
edit
dl
rm
veritysetup
44992
0755
edit
dl
rm
vigr
62144
0755
edit
dl
rm
vipw
62144
0755
edit
dl
rm
visudo
258776
0755
edit
dl
rm
wipefs
39296
0755
edit
dl
rm
wpa_action
1735
0755
edit
dl
rm
wpa_cli
143680
0755
edit
dl
rm
wpa_supplicant
3372472
0755
edit
dl
rm
xtables-legacy-multi
95176
0755
edit
dl
rm
xtables-monitor
224424
0755
edit
dl
rm
xtables-nft-multi
224424
0755
edit
dl
rm
zic
67984
0755
edit
dl
rm
zramctl
55824
0755
edit
dl
rm
Edit:
/snap/core24/1643/usr/sbin/iptables-apply
(7052B)
#!/bin/bash # iptables-apply -- a safer way to update iptables remotely # # Usage: # iptables-apply [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]} # # Versions: # * 1.0 Copyright 2006 Martin F. Krafft <madduck@madduck.net> # Original version # * 1.1 Copyright 2010 GW <gw.2010@tnode.com or http://gw.tnode.com/> # Added parameter -c (run command) # Added parameter -w (save successfully applied rules to file) # Major code cleanup # # Released under the terms of the Artistic Licence 2.0 # set -eu PROGNAME="${0##*/}" VERSION=1.1 ### Default settings DEF_TIMEOUT=10 MODE=0 # apply rulesfile mode # MODE=1 # run command mode case "$PROGNAME" in (*6*) SAVE=ip6tables-save RESTORE=ip6tables-restore DEF_RULESFILE="/etc/network/ip6tables.up.rules" DEF_SAVEFILE="$DEF_RULESFILE" DEF_RUNCMD="/etc/network/ip6tables.up.run" ;; (*) SAVE=iptables-save RESTORE=iptables-restore DEF_RULESFILE="/etc/network/iptables.up.rules" DEF_SAVEFILE="$DEF_RULESFILE" DEF_RUNCMD="/etc/network/iptables.up.run" ;; esac ### Functions function blurb() { cat <<-__EOF__ $PROGNAME $VERSION -- a safer way to update iptables remotely __EOF__ } function copyright() { cat <<-__EOF__ $PROGNAME has been published under the terms of the Artistic Licence 2.0. Original version - Copyright 2006 Martin F. Krafft <madduck@madduck.net>. Version 1.1 - Copyright 2010 GW <gw.2010@tnode.com or http://gw.tnode.com/>. __EOF__ } function about() { blurb echo copyright } function usage() { blurb echo cat <<-__EOF__ Usage: $PROGNAME [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]} The script will try to apply a new rulesfile (as output by iptables-save, read by iptables-restore) or run a command to configure iptables and then prompt the user whether the changes are okay. If the new iptables rules cut the existing connection, the user will not be able to answer affirmatively. In this case, the script rolls back to the previous working iptables rules after the timeout expires. Successfully applied rules can also be written to savefile and later used to roll back to this state. This can be used to implement a store last good configuration mechanism when experimenting with an iptables setup script: $PROGNAME -w $DEF_SAVEFILE -c $DEF_RUNCMD When called as ip6tables-apply, the script will use ip6tables-save/-restore and IPv6 default values instead. Default value for rulesfile is '$DEF_RULESFILE'. Options: -t seconds, --timeout seconds Specify the timeout in seconds (default: $DEF_TIMEOUT). -w savefile, --write savefile Specify the savefile where successfully applied rules will be written to (default if empty string is given: $DEF_SAVEFILE). -c runcmd, --command runcmd Run command runcmd to configure iptables instead of applying a rulesfile (default: $DEF_RUNCMD). -h, --help Display this help text. -V, --version Display version information. __EOF__ } function checkcommands() { for cmd in "${COMMANDS[@]}"; do if ! command -v "$cmd" >/dev/null; then echo "Error: needed command not found: $cmd" >&2 exit 127 fi done } function revertrules() { echo -n "Reverting to old iptables rules... " "$RESTORE" <"$TMPFILE" echo "done." } ### Parsing and checking parameters TIMEOUT="$DEF_TIMEOUT" SAVEFILE="" SHORTOPTS="t:w:chV"; LONGOPTS="timeout:,write:,command,help,version"; OPTS=$(getopt -s bash -o "$SHORTOPTS" -l "$LONGOPTS" -n "$PROGNAME" -- "$@") || exit $? for opt in $OPTS; do case "$opt" in (-*) unset OPT_STATE ;; (*) case "${OPT_STATE:-}" in (SET_TIMEOUT) eval TIMEOUT="$opt";; (SET_SAVEFILE) eval SAVEFILE="$opt" [ -z "$SAVEFILE" ] && SAVEFILE="$DEF_SAVEFILE" ;; esac ;; esac case "$opt" in (-t|--timeout) OPT_STATE="SET_TIMEOUT";; (-w|--write) OPT_STATE="SET_SAVEFILE";; (-c|--command) MODE=1;; (-h|--help) usage >&2; exit 0;; (-V|--version) about >&2; exit 0;; (--) break;; esac shift done # Validate parameters if [ "$TIMEOUT" -ge 0 ] 2>/dev/null; then TIMEOUT=$((TIMEOUT)) else echo "Error: timeout must be a positive number" >&2 exit 1 fi if [ -n "$SAVEFILE" ] && [ -e "$SAVEFILE" ] && [ ! -w "$SAVEFILE" ]; then echo "Error: savefile not writable: $SAVEFILE" >&2 exit 8 fi case "$MODE" in (1) # Treat parameter as runcmd (run command mode) RUNCMD="${1:-$DEF_RUNCMD}" if [ ! -x "$RUNCMD" ]; then echo "Error: runcmd not executable: $RUNCMD" >&2 exit 6 fi # Needed commands COMMANDS=(mktemp "$SAVE" "$RESTORE" "$RUNCMD") checkcommands ;; (*) # Treat parameter as rulesfile (apply rulesfile mode) RULESFILE="${1:-$DEF_RULESFILE}"; if [ ! -r "$RULESFILE" ]; then echo "Error: rulesfile not readable: $RULESFILE" >&2 exit 2 fi # Needed commands COMMANDS=(mktemp "$SAVE" "$RESTORE") checkcommands ;; esac ### Begin work # Store old iptables rules to temporary file TMPFILE=$(mktemp "/tmp/$PROGNAME-XXXXXXXX") trap 'rm -f $TMPFILE' EXIT HUP INT QUIT ILL TRAP ABRT BUS \ FPE USR1 SEGV USR2 PIPE ALRM TERM if ! "$SAVE" >"$TMPFILE"; then # An error occured if ! grep -q ipt /proc/modules 2>/dev/null; then echo "Error: iptables support lacking from the kernel" >&2 exit 3 else echo "Error: unknown error saving old iptables rules: $TMPFILE" >&2 exit 4 fi fi # Legacy to stop the fail2ban daemon if present [ -x /etc/init.d/fail2ban ] && /etc/init.d/fail2ban stop # Configure iptables case "$MODE" in (1) # Run command in background and kill it if it times out echo -n "Running command '$RUNCMD'... " "$RUNCMD" & CMD_PID=$! ( sleep "$TIMEOUT"; kill "$CMD_PID" 2>/dev/null; exit 0 ) & if ! wait "$CMD_PID"; then echo "failed." echo "Error: unknown error running command: $RUNCMD" >&2 revertrules exit 7 else echo "done." fi ;; (*) # Apply iptables rulesfile echo -n "Applying new iptables rules from '$RULESFILE'... " if ! "$RESTORE" <"$RULESFILE"; then echo "failed." echo "Error: unknown error applying new iptables rules: $RULESFILE" >&2 revertrules exit 5 else echo "done." fi ;; esac # Prompt user for confirmation echo -n "Can you establish NEW connections to the machine? (y/N) " read -r -n1 -t "$TIMEOUT" ret 2>&1 || : case "${ret:-}" in (y*|Y*) # Success echo if [ -n "$SAVEFILE" ]; then # Write successfully applied rules to the savefile echo "Writing successfully applied rules to '$SAVEFILE'..." if ! "$SAVE" >"$SAVEFILE"; then echo "Error: unknown error writing successfully applied rules: $SAVEFILE" >&2 exit 9 fi fi echo "... then my job is done. See you next time." ;; (*) # Failed echo if [ -z "${ret:-}" ]; then echo "Timeout! Something happened (or did not). Better play it safe..." else echo "No affirmative response! Better play it safe..." fi revertrules exit 255 ;; esac # Legacy to start the fail2ban daemon again [ -x /etc/init.d/fail2ban ] && /etc/init.d/fail2ban start exit 0 # vim:noet:sw=8
Save
cmd:
run