Le script sid-owner.txt
est un
petit exemple montrant comment utiliser la correspondance SID. Il
n'a rien de réel, en lançant la commande iptables -L -v vous verrez les
règles examinées actuellement.
#!/bin/bash # # sid-owner.txt - Example rule on how the sid-owner match could be used. # # Copyright (C) 2001 Oskar Andreasson <bluefluxATkoffeinDOTnet> # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; version 2 of the License. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program or from the site that you downloaded it # from; if not, write to the Free Software Foundation, Inc., 59 Temple # Place, Suite 330, Boston, MA 02111-1307 USA # SID=`ps -eo sid,args |grep httpd |head -n 1 |cut -b 1-5` /usr/local/sbin/iptables -A OUTPUT -p TCP -m owner --sid-owner $SID -j ACCEPT