/snap/core22/2437/usr/sbin
NameSizeModeActions
aa-remove-unknown30680755editdlrm
aa-status641200755editdlrm
aa-teardown1370755editdlrm
add-shell10510755editdlrm
addgroup382470755editdlrm
adduser382470755editdlrm
agetty568960755editdlrm
apparmor_parser15480640755editdlrm
apparmor_status641200755editdlrm
arpd269600755editdlrm
arptables2242960755editdlrm
arptables-nft2242960755editdlrm
arptables-nft-restore2242960755editdlrm
arptables-nft-save2242960755editdlrm
arptables-restore2242960755editdlrm
arptables-save2242960755editdlrm
badblocks351440755editdlrm
blkdeactivate163510755editdlrm
blkdiscard229120755editdlrm
blkid516240755editdlrm
blkzone352000755editdlrm
blockdev311040755editdlrm
bridge947120755editdlrm
capsh310320755editdlrm
cfdisk970080755editdlrm
chcpu311040755editdlrm
chgpasswd595280755editdlrm
chmem352000755editdlrm
chpasswd554640755editdlrm
chroot394320755editdlrm
cpgr494480755editdlrm
cppw494480755editdlrm
cryptdisks_start15440755editdlrm
cryptdisks_stop8440755editdlrm
cryptsetup1740000755editdlrm
cryptsetup-reencrypt925440755editdlrm
cryptsetup-ssh240960755editdlrm
ctrlaltdel147200755editdlrm
dcb824480755editdlrm
debugfs2353200755editdlrm
delgroup164950755editdlrm
deluser164950755editdlrm
depmod1743280755editdlrm
devlink1462880755editdlrm
dhclient4532800755editdlrm
dhclient-script163040755editdlrm
dmsetup1751280755editdlrm
dmstats1751280755editdlrm
dosfsck843600755editdlrm
dosfslabel393040755editdlrm
dumpe2fs310400755editdlrm
e2freefrag146480755editdlrm
e2fsck3602800755editdlrm
e2image433280755editdlrm
e2label1050160755editdlrm
e2mmpstatus310400755editdlrm
e2scrub72960755editdlrm
e2scrub_all53950755editdlrm
e2undo228400755editdlrm
e4crypt311040755editdlrm
e4defrag310320755editdlrm
ebtables2242960755editdlrm
ebtables-nft2242960755editdlrm
ebtables-nft-restore2242960755editdlrm
ebtables-nft-save2242960755editdlrm
ebtables-restore2242960755editdlrm
ebtables-save2242960755editdlrm
faillock144880755editdlrm
fatlabel393040755editdlrm
fdisk1130720755editdlrm
filefrag187600755editdlrm
findfs147200755editdlrm
fsck434400755editdlrm
fsck.cramfs311680755editdlrm
fsck.ext23602800755editdlrm
fsck.ext33602800755editdlrm
fsck.ext43602800755editdlrm
fsck.fat843600755editdlrm
fsck.minix557120755editdlrm
fsck.msdos843600755editdlrm
fsck.vfat843600755editdlrm
fsfreeze147200755editdlrm
fstab-decode187440755editdlrm
fstrim433920755editdlrm
genl926080755editdlrm
getcap146480755editdlrm
getpcaps146480755editdlrm
getty568960755editdlrm
groupadd685200755editdlrm
groupdel642320755editdlrm
groupmems554880755editdlrm
groupmod684240755editdlrm
grpck595280755editdlrm
grpconv512080755editdlrm
grpunconv512080755editdlrm
halt15013040755editdlrm
hwclock517120755editdlrm
iconvconfig311280755editdlrm
init1008160755editdlrm
insmod1743280755editdlrm
installkernel26590755editdlrm
integritysetup553680755editdlrm
invoke-rc.d165070755editdlrm
ip7729200755editdlrm
ip6tables2242960755editdlrm
ip6tables-apply70570755editdlrm
ip6tables-legacy992720755editdlrm
ip6tables-legacy-restore992720755editdlrm
ip6tables-legacy-save992720755editdlrm
ip6tables-nft2242960755editdlrm
ip6tables-nft-restore2242960755editdlrm
ip6tables-nft-save2242960755editdlrm
ip6tables-restore2242960755editdlrm
ip6tables-restore-translate2242960755editdlrm
ip6tables-save2242960755editdlrm
ip6tables-translate2242960755editdlrm
iptables2242960755editdlrm
iptables-apply70570755editdlrm
iptables-legacy992720755editdlrm
iptables-legacy-restore992720755editdlrm
iptables-legacy-save992720755editdlrm
iptables-nft2242960755editdlrm
iptables-nft-restore2242960755editdlrm
iptables-nft-save2242960755editdlrm
iptables-restore2242960755editdlrm
iptables-restore-translate2242960755editdlrm
iptables-save2242960755editdlrm
iptables-translate2242960755editdlrm
isosize147200755editdlrm
killall5311120755editdlrm
ldattach270080755editdlrm
ldconfig3870755editdlrm
ldconfig.real12139600755editdlrm
logsave144960755editdlrm
losetup722080755editdlrm
lsmod1743280755editdlrm
luksformat34010755editdlrm
mkdosfs520480755editdlrm
mke2fs1337520755editdlrm
mkfs147200755editdlrm
mkfs.bfs229120755editdlrm
mkfs.cramfs351440755editdlrm
mkfs.ext21337520755editdlrm
mkfs.ext31337520755editdlrm
mkfs.ext41337520755editdlrm
mkfs.fat520480755editdlrm
mkfs.minix434080755editdlrm
mkfs.msdos520480755editdlrm
mkfs.vfat520480755editdlrm
mkhomedir_helper227040755editdlrm
mklost+found146480755editdlrm
mkswap474960755editdlrm
modinfo1743280755editdlrm
modprobe1743280755editdlrm
netplan7980755editdlrm
newusers765200755editdlrm
nfnl_osf187360755editdlrm
nologin146400755editdlrm
pam-auth-update209920755editdlrm
pam_extrausers_chkpwd226802755editdlrm
pam_extrausers_update308720755editdlrm
pam_getenv28900755editdlrm
pam_timestamp_check144880755editdlrm
pivot_root147200755editdlrm
plymouthd1541680755editdlrm
poweroff15013040755editdlrm
pwck513360755editdlrm
pwconv471120755editdlrm
pwunconv430160755editdlrm
readprofile229440755editdlrm
reboot15013040755editdlrm
remove-shell10990755editdlrm
resize2fs678960755editdlrm
rfkill309520755editdlrm
rmmod1743280755editdlrm
rmt599760755editdlrm
rmt-tar599760755editdlrm
rtacct289920755editdlrm
rtcwake352000755editdlrm
rtmon925600755editdlrm
runlevel15013040755editdlrm
runuser556800755editdlrm
service90970755editdlrm
setcap146480755editdlrm
sfdisk1048320755editdlrm
shadowconfig8850755editdlrm
shutdown15013040755editdlrm
sshd9212880755editdlrm
start-stop-daemon484880755editdlrm
sudo_logsrvd2049040755editdlrm
sudo_sendlog1099120755editdlrm
sulogin433920755editdlrm
swaplabel188160755editdlrm
swapoff229120755editdlrm
swapon433920755editdlrm
switch_root229120755editdlrm
sysctl309600755editdlrm
tarcat9360755editdlrm
tc6288160755editdlrm
telinit15013040755editdlrm
tipc926080755editdlrm
tune2fs1050160755editdlrm
tzconfig1060755editdlrm
unix_chkpwd267762755editdlrm
unix_update308720755editdlrm
update-ca-certificates54180755editdlrm
update-passwd353920755editdlrm
update-rc.d173240755editdlrm
update-shells38060755editdlrm
useradd1307200755editdlrm
userdel889360755editdlrm
usermod1264240755editdlrm
vdpa312960755editdlrm
veritysetup448080755editdlrm
vigr578880755editdlrm
vipw578880755editdlrm
visudo2250640755editdlrm
wipefs392960755editdlrm
wpa_action17350755editdlrm
wpa_cli1436800755editdlrm
wpa_supplicant33970480755editdlrm
xtables-legacy-multi992720755editdlrm
xtables-monitor2242960755editdlrm
xtables-nft-multi2242960755editdlrm
zic638160755editdlrm
zramctl558240755editdlrm
Edit: /snap/core22/2437/usr/sbin/iptables-apply (7057B)
#!/bin/bash # iptables-apply -- a safer way to update iptables remotely # # Usage: # iptables-apply [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]} # # Versions: # * 1.0 Copyright 2006 Martin F. Krafft # Original version # * 1.1 Copyright 2010 GW # Added parameter -c (run command) # Added parameter -w (save successfully applied rules to file) # Major code cleanup # # Released under the terms of the Artistic Licence 2.0 # set -eu PROGNAME="${0##*/}" VERSION=1.1 ### Default settings DEF_TIMEOUT=10 MODE=0 # apply rulesfile mode # MODE=1 # run command mode case "$PROGNAME" in (*6*) SAVE=ip6tables-save RESTORE=ip6tables-restore DEF_RULESFILE="/etc/network/ip6tables.up.rules" DEF_SAVEFILE="$DEF_RULESFILE" DEF_RUNCMD="/etc/network/ip6tables.up.run" ;; (*) SAVE=iptables-save RESTORE=iptables-restore DEF_RULESFILE="/etc/network/iptables.up.rules" DEF_SAVEFILE="$DEF_RULESFILE" DEF_RUNCMD="/etc/network/iptables.up.run" ;; esac ### Functions function blurb() { cat <<-__EOF__ $PROGNAME $VERSION -- a safer way to update iptables remotely __EOF__ } function copyright() { cat <<-__EOF__ $PROGNAME has been published under the terms of the Artistic Licence 2.0. Original version - Copyright 2006 Martin F. Krafft . Version 1.1 - Copyright 2010 GW . __EOF__ } function about() { blurb echo copyright } function usage() { blurb echo cat <<-__EOF__ Usage: $PROGNAME [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]} The script will try to apply a new rulesfile (as output by iptables-save, read by iptables-restore) or run a command to configure iptables and then prompt the user whether the changes are okay. If the new iptables rules cut the existing connection, the user will not be able to answer affirmatively. In this case, the script rolls back to the previous working iptables rules after the timeout expires. Successfully applied rules can also be written to savefile and later used to roll back to this state. This can be used to implement a store last good configuration mechanism when experimenting with an iptables setup script: $PROGNAME -w $DEF_SAVEFILE -c $DEF_RUNCMD When called as ip6tables-apply, the script will use ip6tables-save/-restore and IPv6 default values instead. Default value for rulesfile is '$DEF_RULESFILE'. Options: -t seconds, --timeout seconds Specify the timeout in seconds (default: $DEF_TIMEOUT). -w savefile, --write savefile Specify the savefile where successfully applied rules will be written to (default if empty string is given: $DEF_SAVEFILE). -c runcmd, --command runcmd Run command runcmd to configure iptables instead of applying a rulesfile (default: $DEF_RUNCMD). -h, --help Display this help text. -V, --version Display version information. __EOF__ } function checkcommands() { for cmd in "${COMMANDS[@]}"; do if ! command -v "$cmd" >/dev/null; then echo "Error: needed command not found: $cmd" >&2 exit 127 fi done } function revertrules() { echo -n "Reverting to old iptables rules... " "$RESTORE" <"$TMPFILE" echo "done." } ### Parsing and checking parameters TIMEOUT="$DEF_TIMEOUT" SAVEFILE="" SHORTOPTS="t:w:chV"; LONGOPTS="timeout:,write:,command,help,version"; OPTS=$(getopt -s bash -o "$SHORTOPTS" -l "$LONGOPTS" -n "$PROGNAME" -- "$@") || exit $? for opt in $OPTS; do case "$opt" in (-*) unset OPT_STATE ;; (*) case "${OPT_STATE:-}" in (SET_TIMEOUT) eval TIMEOUT=$opt;; (SET_SAVEFILE) eval SAVEFILE=$opt [ -z "$SAVEFILE" ] && SAVEFILE="$DEF_SAVEFILE" ;; esac ;; esac case "$opt" in (-t|--timeout) OPT_STATE="SET_TIMEOUT";; (-w|--write) OPT_STATE="SET_SAVEFILE";; (-c|--command) MODE=1;; (-h|--help) usage >&2; exit 0;; (-V|--version) about >&2; exit 0;; (--) break;; esac shift done # Validate parameters if [ "$TIMEOUT" -ge 0 ] 2>/dev/null; then TIMEOUT=$(($TIMEOUT)) else echo "Error: timeout must be a positive number" >&2 exit 1 fi if [ -n "$SAVEFILE" -a -e "$SAVEFILE" -a ! -w "$SAVEFILE" ]; then echo "Error: savefile not writable: $SAVEFILE" >&2 exit 8 fi case "$MODE" in (1) # Treat parameter as runcmd (run command mode) RUNCMD="${1:-$DEF_RUNCMD}" if [ ! -x "$RUNCMD" ]; then echo "Error: runcmd not executable: $RUNCMD" >&2 exit 6 fi # Needed commands COMMANDS=(mktemp "$SAVE" "$RESTORE" "$RUNCMD") checkcommands ;; (*) # Treat parameter as rulesfile (apply rulesfile mode) RULESFILE="${1:-$DEF_RULESFILE}"; if [ ! -r "$RULESFILE" ]; then echo "Error: rulesfile not readable: $RULESFILE" >&2 exit 2 fi # Needed commands COMMANDS=(mktemp "$SAVE" "$RESTORE") checkcommands ;; esac ### Begin work # Store old iptables rules to temporary file TMPFILE=`mktemp /tmp/$PROGNAME-XXXXXXXX` trap "rm -f $TMPFILE" EXIT HUP INT QUIT ILL TRAP ABRT BUS \ FPE USR1 SEGV USR2 PIPE ALRM TERM if ! "$SAVE" >"$TMPFILE"; then # An error occured if ! grep -q ipt /proc/modules 2>/dev/null; then echo "Error: iptables support lacking from the kernel" >&2 exit 3 else echo "Error: unknown error saving old iptables rules: $TMPFILE" >&2 exit 4 fi fi # Legacy to stop the fail2ban daemon if present [ -x /etc/init.d/fail2ban ] && /etc/init.d/fail2ban stop # Configure iptables case "$MODE" in (1) # Run command in background and kill it if it times out echo -n "Running command '$RUNCMD'... " "$RUNCMD" & CMD_PID=$! ( sleep "$TIMEOUT"; kill "$CMD_PID" 2>/dev/null; exit 0 ) & CMDTIMEOUT_PID=$! if ! wait "$CMD_PID"; then echo "failed." echo "Error: unknown error running command: $RUNCMD" >&2 revertrules exit 7 else echo "done." fi ;; (*) # Apply iptables rulesfile echo -n "Applying new iptables rules from '$RULESFILE'... " if ! "$RESTORE" <"$RULESFILE"; then echo "failed." echo "Error: unknown error applying new iptables rules: $RULESFILE" >&2 revertrules exit 5 else echo "done." fi ;; esac # Prompt user for confirmation echo -n "Can you establish NEW connections to the machine? (y/N) " read -n1 -t "$TIMEOUT" ret 2>&1 || : case "${ret:-}" in (y*|Y*) # Success echo if [ ! -z "$SAVEFILE" ]; then # Write successfully applied rules to the savefile echo "Writing successfully applied rules to '$SAVEFILE'..." if ! "$SAVE" >"$SAVEFILE"; then echo "Error: unknown error writing successfully applied rules: $SAVEFILE" >&2 exit 9 fi fi echo "... then my job is done. See you next time." ;; (*) # Failed echo if [ -z "${ret:-}" ]; then echo "Timeout! Something happened (or did not). Better play it safe..." else echo "No affirmative response! Better play it safe..." fi revertrules exit 255 ;; esac # Legacy to start the fail2ban daemon again [ -x /etc/init.d/fail2ban ] && /etc/init.d/fail2ban start exit 0 # vim:noet:sw=8