/snap/core20/2922/usr/sbin
NameSizeModeActions
aa-remove-unknown30680755editdlrm
aa-status88390755editdlrm
aa-teardown1390755editdlrm
add-shell8600755editdlrm
addgroup377850755editdlrm
adduser377850755editdlrm
agetty690000755editdlrm
apparmor_parser15263680755editdlrm
apparmor_status88390755editdlrm
arpd801440755editdlrm
arptables2204880755editdlrm
arptables-nft2204880755editdlrm
arptables-nft-restore2204880755editdlrm
arptables-nft-save2204880755editdlrm
arptables-restore2204880755editdlrm
arptables-save2204880755editdlrm
badblocks351440755editdlrm
blkdeactivate148370755editdlrm
blkdiscard350480755editdlrm
blkid1210960755editdlrm
blkzone719120755editdlrm
blockdev678160755editdlrm
bridge1047600755editdlrm
capsh310320755editdlrm
cfdisk1050480755editdlrm
chcpu473360755editdlrm
chgpasswd677920755editdlrm
chmem637200755editdlrm
chpasswd596000755editdlrm
chroot433520755editdlrm
cpgr617840755editdlrm
cppw617840755editdlrm
cryptdisks_start15440755editdlrm
cryptdisks_stop8440755editdlrm
cryptsetup1387920755editdlrm
cryptsetup-reencrypt1078480755editdlrm
ctrlaltdel391440755editdlrm
debugfs2312240755editdlrm
delgroup164950755editdlrm
deluser164950755editdlrm
depmod1744240755editdlrm
devlink1540800755editdlrm
dhclient5212000755editdlrm
dhclient-script163040755editdlrm
dmsetup1751280755editdlrm
dmstats1751280755editdlrm
dosfsck594720755editdlrm
dosfslabel553760755editdlrm
dumpe2fs311120755editdlrm
e2freefrag188160755editdlrm
e2fsck3350640755editdlrm
e2image434000755editdlrm
e2label1091120755editdlrm
e2mmpstatus311120755editdlrm
e2scrub72960755editdlrm
e2scrub_all53950755editdlrm
e2undo229120755editdlrm
e4crypt311040755editdlrm
e4defrag351280755editdlrm
ebtables2204880755editdlrm
ebtables-nft2204880755editdlrm
ebtables-nft-restore2204880755editdlrm
ebtables-nft-save2204880755editdlrm
ebtables-restore2204880755editdlrm
ebtables-save2204880755editdlrm
faillock144880755editdlrm
fatlabel553760755editdlrm
fdformat350480755editdlrm
fdisk1538800755editdlrm
filefrag187680755editdlrm
findfs145680755editdlrm
fsck555760755editdlrm
fsck.cramfs391760755editdlrm
fsck.ext23350640755editdlrm
fsck.ext33350640755editdlrm
fsck.ext43350640755editdlrm
fsck.fat594720755editdlrm
fsck.minix1251840755editdlrm
fsck.msdos594720755editdlrm
fsck.vfat594720755editdlrm
fsfreeze145680755editdlrm
fstab-decode146480755editdlrm
fstrim719120755editdlrm
genl842640755editdlrm
getcap146480755editdlrm
getpcaps146480755editdlrm
getty690000755editdlrm
groupadd931360755editdlrm
groupdel888480755editdlrm
groupmems637360755editdlrm
groupmod971360755editdlrm
grpck636720755editdlrm
grpconv594480755editdlrm
grpunconv594480755editdlrm
halt9965840755editdlrm
hwclock1048080755editdlrm
iconvconfig311280755editdlrm
init16202240755editdlrm
insmod1744240755editdlrm
installkernel26380755editdlrm
integritysetup616720755editdlrm
invoke-rc.d170420755editdlrm
ip6119600755editdlrm
ip6tables992960755editdlrm
ip6tables-apply70570755editdlrm
ip6tables-legacy992960755editdlrm
ip6tables-legacy-restore992960755editdlrm
ip6tables-legacy-save992960755editdlrm
ip6tables-nft2204880755editdlrm
ip6tables-nft-restore2204880755editdlrm
ip6tables-nft-save2204880755editdlrm
ip6tables-restore992960755editdlrm
ip6tables-restore-translate2204880755editdlrm
ip6tables-save992960755editdlrm
ip6tables-translate2204880755editdlrm
iptables992960755editdlrm
iptables-apply70570755editdlrm
iptables-legacy992960755editdlrm
iptables-legacy-restore992960755editdlrm
iptables-legacy-save992960755editdlrm
iptables-nft2204880755editdlrm
iptables-nft-restore2204880755editdlrm
iptables-nft-save2204880755editdlrm
iptables-restore992960755editdlrm
iptables-restore-translate2204880755editdlrm
iptables-save992960755editdlrm
iptables-translate2204880755editdlrm
isosize309520755editdlrm
killall5270160755editdlrm
ldattach350480755editdlrm
ldconfig3870755editdlrm
ldconfig.real10537680755editdlrm
logsave144960755editdlrm
losetup1129920755editdlrm
lsmod1744240755editdlrm
luksformat34010755editdlrm
mkdosfs353280755editdlrm
mke2fs1378480755editdlrm
mkfs145680755editdlrm
mkfs.bfs350480755editdlrm
mkfs.cramfs431680755editdlrm
mkfs.ext21378480755editdlrm
mkfs.ext31378480755editdlrm
mkfs.ext41378480755editdlrm
mkfs.fat353280755editdlrm
mkfs.minix1087840755editdlrm
mkfs.msdos353280755editdlrm
mkfs.vfat353280755editdlrm
mkhomedir_helper227040755editdlrm
mklost+found146480755editdlrm
mkswap1087840755editdlrm
modinfo1744240755editdlrm
modprobe1744240755editdlrm
netplan7980755editdlrm
newusers1011680755editdlrm
nfnl_osf187360755editdlrm
nologin146400755editdlrm
pam-auth-update203350755editdlrm
pam_extrausers_chkpwd431682755editdlrm
pam_extrausers_update431680755editdlrm
pam_getenv28900755editdlrm
pam_tally145040755editdlrm
pam_tally2186000755editdlrm
pam_timestamp_check144880755editdlrm
pivot_root145680755editdlrm
poweroff9965840755editdlrm
pwck595680755editdlrm
pwconv553440755editdlrm
pwunconv553520755editdlrm
raw145680755editdlrm
readprofile227920755editdlrm
reboot9965840755editdlrm
remove-shell9040755editdlrm
resize2fs679680755editdlrm
rfkill514320755editdlrm
rmmod1744240755editdlrm
rmt599520755editdlrm
rmt-tar599520755editdlrm
rtacct494480755editdlrm
rtcwake473360755editdlrm
rtmon801200755editdlrm
runlevel9965840755editdlrm
runuser678160755editdlrm
service92620755editdlrm
setcap146480755editdlrm
sfdisk1415440755editdlrm
shadowconfig8850755editdlrm
shutdown9965840755editdlrm
sshd8845200755editdlrm
start-stop-daemon484560755editdlrm
sulogin514320755editdlrm
swaplabel186640755editdlrm
swapoff227600755editdlrm
swapon514320755editdlrm
switch_root145680755editdlrm
sysctl309600755editdlrm
tarcat9360755editdlrm
tc5421600755editdlrm
telinit9965840755editdlrm
tipc1292640755editdlrm
tune2fs1091120755editdlrm
tzconfig1060755editdlrm
unix_chkpwd431602755editdlrm
unix_update431600755editdlrm
update-ca-certificates54180755editdlrm
update-mime94020755editdlrm
update-passwd353920755editdlrm
update-rc.d171610755editdlrm
useradd1471600755editdlrm
userdel1012640755editdlrm
usermod1428400755editdlrm
veritysetup530640755editdlrm
vigr702000755editdlrm
vipw702000755editdlrm
visudo2234320755editdlrm
wipefs473360755editdlrm
wpa_action17350755editdlrm
wpa_cli1558720755editdlrm
wpa_supplicant29013280755editdlrm
xtables-legacy-multi992960755editdlrm
xtables-monitor2204880755editdlrm
xtables-nft-multi2204880755editdlrm
zic637840755editdlrm
zramctl1170880755editdlrm
Edit: /snap/core20/2922/usr/sbin/iptables-apply (7057B)
#!/bin/bash # iptables-apply -- a safer way to update iptables remotely # # Usage: # iptables-apply [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]} # # Versions: # * 1.0 Copyright 2006 Martin F. Krafft # Original version # * 1.1 Copyright 2010 GW # Added parameter -c (run command) # Added parameter -w (save successfully applied rules to file) # Major code cleanup # # Released under the terms of the Artistic Licence 2.0 # set -eu PROGNAME="${0##*/}" VERSION=1.1 ### Default settings DEF_TIMEOUT=10 MODE=0 # apply rulesfile mode # MODE=1 # run command mode case "$PROGNAME" in (*6*) SAVE=ip6tables-save RESTORE=ip6tables-restore DEF_RULESFILE="/etc/network/ip6tables.up.rules" DEF_SAVEFILE="$DEF_RULESFILE" DEF_RUNCMD="/etc/network/ip6tables.up.run" ;; (*) SAVE=iptables-save RESTORE=iptables-restore DEF_RULESFILE="/etc/network/iptables.up.rules" DEF_SAVEFILE="$DEF_RULESFILE" DEF_RUNCMD="/etc/network/iptables.up.run" ;; esac ### Functions function blurb() { cat <<-__EOF__ $PROGNAME $VERSION -- a safer way to update iptables remotely __EOF__ } function copyright() { cat <<-__EOF__ $PROGNAME has been published under the terms of the Artistic Licence 2.0. Original version - Copyright 2006 Martin F. Krafft . Version 1.1 - Copyright 2010 GW . __EOF__ } function about() { blurb echo copyright } function usage() { blurb echo cat <<-__EOF__ Usage: $PROGNAME [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]} The script will try to apply a new rulesfile (as output by iptables-save, read by iptables-restore) or run a command to configure iptables and then prompt the user whether the changes are okay. If the new iptables rules cut the existing connection, the user will not be able to answer affirmatively. In this case, the script rolls back to the previous working iptables rules after the timeout expires. Successfully applied rules can also be written to savefile and later used to roll back to this state. This can be used to implement a store last good configuration mechanism when experimenting with an iptables setup script: $PROGNAME -w $DEF_SAVEFILE -c $DEF_RUNCMD When called as ip6tables-apply, the script will use ip6tables-save/-restore and IPv6 default values instead. Default value for rulesfile is '$DEF_RULESFILE'. Options: -t seconds, --timeout seconds Specify the timeout in seconds (default: $DEF_TIMEOUT). -w savefile, --write savefile Specify the savefile where successfully applied rules will be written to (default if empty string is given: $DEF_SAVEFILE). -c runcmd, --command runcmd Run command runcmd to configure iptables instead of applying a rulesfile (default: $DEF_RUNCMD). -h, --help Display this help text. -V, --version Display version information. __EOF__ } function checkcommands() { for cmd in "${COMMANDS[@]}"; do if ! command -v "$cmd" >/dev/null; then echo "Error: needed command not found: $cmd" >&2 exit 127 fi done } function revertrules() { echo -n "Reverting to old iptables rules... " "$RESTORE" <"$TMPFILE" echo "done." } ### Parsing and checking parameters TIMEOUT="$DEF_TIMEOUT" SAVEFILE="" SHORTOPTS="t:w:chV"; LONGOPTS="timeout:,write:,command,help,version"; OPTS=$(getopt -s bash -o "$SHORTOPTS" -l "$LONGOPTS" -n "$PROGNAME" -- "$@") || exit $? for opt in $OPTS; do case "$opt" in (-*) unset OPT_STATE ;; (*) case "${OPT_STATE:-}" in (SET_TIMEOUT) eval TIMEOUT=$opt;; (SET_SAVEFILE) eval SAVEFILE=$opt [ -z "$SAVEFILE" ] && SAVEFILE="$DEF_SAVEFILE" ;; esac ;; esac case "$opt" in (-t|--timeout) OPT_STATE="SET_TIMEOUT";; (-w|--write) OPT_STATE="SET_SAVEFILE";; (-c|--command) MODE=1;; (-h|--help) usage >&2; exit 0;; (-V|--version) about >&2; exit 0;; (--) break;; esac shift done # Validate parameters if [ "$TIMEOUT" -ge 0 ] 2>/dev/null; then TIMEOUT=$(($TIMEOUT)) else echo "Error: timeout must be a positive number" >&2 exit 1 fi if [ -n "$SAVEFILE" -a -e "$SAVEFILE" -a ! -w "$SAVEFILE" ]; then echo "Error: savefile not writable: $SAVEFILE" >&2 exit 8 fi case "$MODE" in (1) # Treat parameter as runcmd (run command mode) RUNCMD="${1:-$DEF_RUNCMD}" if [ ! -x "$RUNCMD" ]; then echo "Error: runcmd not executable: $RUNCMD" >&2 exit 6 fi # Needed commands COMMANDS=(mktemp "$SAVE" "$RESTORE" "$RUNCMD") checkcommands ;; (*) # Treat parameter as rulesfile (apply rulesfile mode) RULESFILE="${1:-$DEF_RULESFILE}"; if [ ! -r "$RULESFILE" ]; then echo "Error: rulesfile not readable: $RULESFILE" >&2 exit 2 fi # Needed commands COMMANDS=(mktemp "$SAVE" "$RESTORE") checkcommands ;; esac ### Begin work # Store old iptables rules to temporary file TMPFILE=`mktemp /tmp/$PROGNAME-XXXXXXXX` trap "rm -f $TMPFILE" EXIT HUP INT QUIT ILL TRAP ABRT BUS \ FPE USR1 SEGV USR2 PIPE ALRM TERM if ! "$SAVE" >"$TMPFILE"; then # An error occured if ! grep -q ipt /proc/modules 2>/dev/null; then echo "Error: iptables support lacking from the kernel" >&2 exit 3 else echo "Error: unknown error saving old iptables rules: $TMPFILE" >&2 exit 4 fi fi # Legacy to stop the fail2ban daemon if present [ -x /etc/init.d/fail2ban ] && /etc/init.d/fail2ban stop # Configure iptables case "$MODE" in (1) # Run command in background and kill it if it times out echo -n "Running command '$RUNCMD'... " "$RUNCMD" & CMD_PID=$! ( sleep "$TIMEOUT"; kill "$CMD_PID" 2>/dev/null; exit 0 ) & CMDTIMEOUT_PID=$! if ! wait "$CMD_PID"; then echo "failed." echo "Error: unknown error running command: $RUNCMD" >&2 revertrules exit 7 else echo "done." fi ;; (*) # Apply iptables rulesfile echo -n "Applying new iptables rules from '$RULESFILE'... " if ! "$RESTORE" <"$RULESFILE"; then echo "failed." echo "Error: unknown error applying new iptables rules: $RULESFILE" >&2 revertrules exit 5 else echo "done." fi ;; esac # Prompt user for confirmation echo -n "Can you establish NEW connections to the machine? (y/N) " read -n1 -t "$TIMEOUT" ret 2>&1 || : case "${ret:-}" in (y*|Y*) # Success echo if [ ! -z "$SAVEFILE" ]; then # Write successfully applied rules to the savefile echo "Writing successfully applied rules to '$SAVEFILE'..." if ! "$SAVE" >"$SAVEFILE"; then echo "Error: unknown error writing successfully applied rules: $SAVEFILE" >&2 exit 9 fi fi echo "... then my job is done. See you next time." ;; (*) # Failed echo if [ -z "${ret:-}" ]; then echo "Timeout! Something happened (or did not). Better play it safe..." else echo "No affirmative response! Better play it safe..." fi revertrules exit 255 ;; esac # Legacy to start the fail2ban daemon again [ -x /etc/init.d/fail2ban ] && /etc/init.d/fail2ban start exit 0 # vim:noet:sw=8