From f34bd8dfd248a1fff20fa23839153397a5609f48 Mon Sep 17 00:00:00 2001 From: pabloFuente Date: Thu, 12 Jul 2018 15:25:45 +0200 Subject: [PATCH] openvidu-test-e2e: restricted chrome iptables rules updated --- openvidu-test-e2e/docker/chrome/script.sh | 34 +++++++++++------------ 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/openvidu-test-e2e/docker/chrome/script.sh b/openvidu-test-e2e/docker/chrome/script.sh index 01476ea9..1205dc4f 100755 --- a/openvidu-test-e2e/docker/chrome/script.sh +++ b/openvidu-test-e2e/docker/chrome/script.sh @@ -10,23 +10,23 @@ sudo apt-get -y update && sudo apt-get -y install iptables && sudo apt-get -y in # UDP rules (DROP all) -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 80 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 443 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 4444 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 6080 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 5900 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 4200 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 4443 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --dport 3478 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 80 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 443 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 4444 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 6080 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 5900 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 4200 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 4443 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --dport 3478 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 80 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 443 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 4444 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 6080 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 5900 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 4200 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 4443 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp --sport 3478 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 80 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 443 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 4444 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 6080 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 5900 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 4200 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 4443 -j ACCEPT +sudo iptables -A OUTPUT -p tcp --sport 3478 -j ACCEPT sudo iptables -A OUTPUT -p tcp --sport 53 -j ACCEPT sudo iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT @@ -37,7 +37,7 @@ sudo iptables -A INPUT -p tcp --dport 53 -j ACCEPT sudo iptables -A INPUT -p udp --sport 53 -j ACCEPT sudo iptables -A INPUT -p udp --dport 53 -j ACCEPT -sudo iptables -A OUTPUT -o eth0 -p tcp -j DROP +sudo iptables -A OUTPUT -p tcp -j DROP sudo iptables -A OUTPUT -p udp --dport 0:65535 -j DROP sudo iptables -A INPUT -p udp --dport 0:65535 -j DROP