Running Tor Browser Bundle in a sandbox

fedorauser fedorauser at vfemail.net
Wed Aug 21 09:47:00 UTC 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi!

since F19 my default browser is
'sandbox -X -t sandbox_web_t firefox %u'
which makes me feel a little bit more comfortable when browsing the
web without NoScript enabled.

Now I'd like to also move the Tor Browser Bundle [1] into a sandbox,
has anyone tried to do that yet?

Besides outgoing connections TBB will also try to open two listeners
at 127.0.0.1:9150 and 127.0.0.1:9151.

So far a simple test failed:

cd tor-browser_en-US-3.0-alpha-3
sandbox -X -H . -t sandbox_net_t ./start-tor-browser
Error: Tor Browser exited abnormally. Exit code: 127

Is there another sandbox type (-t) that would be more appropriate for
this?
Does sandbox_net_t allow to open local listeners (9150+9151)?

thanks!


[1] https://archive.torproject.org/tor-package-archive/torbrowser/3.0a3/

-----BEGIN PGP SIGNATURE-----

iQEcBAEBCgAGBQJSFIyUAAoJEHgmGhf8XKddI/AH/2Ukzmk83DafCDeuylIkyWWG
Vu5SDJWHt+/TUye3bsdb1W33dn6Q1tuAZoBitMxOgGFL5mOBEyNi4egZXTlVVlv/
jxKi6jR2b5OMQw5yogNWcsTwPp87EUCNMaeJe8VUdY23Mk0G6LipaJnluKNMMveu
jkFowl9XRqJcAwqM7FibOOezaCpTGFp/s1F83gkTChsvS36EomXs0uliPYsBxJc9
9UOzJ6cL6kzQfcfuG3zDnK4ANYO9kx+6N5pi8/GbtB+EAx2AvHI8+b3nInsjTdF6
Ujgw06DQgtNBW5D5knye6Sw6ynhklw4fWtKHZlP9GJ5UwocIryzUMkZgY5jmBSg=
=9lis
-----END PGP SIGNATURE-----

-------------------------------------------------

VFEmail.net - http://www.vfemail.net
$14.95 ONETIME Lifetime accounts with Privacy Features!  
15GB disk! No bandwidth quotas!
Commercial and Bulk Mail Options!  


More information about the selinux mailing list