?
Solved

How to restrict users to their own home directory

Posted on 1998-08-05
2
Medium Priority
?
371 Views
Last Modified: 2010-05-18
I would like to restrict users to their own home directory , so that they cannot cd to the root and other directories.
This is to be so when they perform ftp or telnet.

Any body can help ?

Thanks.
0
Comment
Question by:keoktay
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 

Accepted Solution

by:
dima_sherman earned 100 total points
ID: 2009206
Hi, first of all, do:
$adduser
this will ask ya for home directory for the user that ya wanna add. if this fails do this.
for non-shadowed
*****************
$ pico /etc/passwd
insert:
<username>::666:666:/home/<username>:/bin/bash
^X(save & quit)
$ mkdir /home/<username>
$ passwd <username> (Change his password quickly!)

for Shadowed
************
$ pico /etc/passwd
insert:
<username>:x:666:666:/home/<username>:/bin/bash
^X(save & quit)
$ pico /etc/shadow
<username>::
^X(save & quit)
$ passwd <username> (Change his password quickly!)
$ mkdir /home/<username>
To check if your system is shadowed do:
$ grep ":0:" /etc/passwd
if the place where the password should be is 'X' = SHADOWED!
now ask your user to login and he will automaticly login to his directory, when he will try to do cd /root he will get 'permission denied', also try to do
$ chmod o-rwx /root
This will make only you the only user (root) who can read, write and execute programs in directory /root.
I hope i've helped ya. :)
btw: DASH LE AVI SHAWA!
0
 
LVL 1

Expert Comment

by:albberat
ID: 2009207

 well what the dima_sherman is saying is quite long. If they have shell access(they use telnet for that) you should change the permissions for every file/directory(build a script or use the umask when creating new files/dirs) and they are not able to change dir(cd now has no value) but if they use telnet(shell access) how they can use "ls" command if the /bin dir can not be reached. in ftp you can use "the dialup user" where the user entry is not anymore in /etc/passwd(shell access is not permitted -- ISP's do this always) and when he logs via ftp he can jump up and down his dirs and he will not see other dirs.
 
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Why Shell Scripting? Shell scripting is a powerful method of accessing UNIX systems and it is very flexible. Shell scripts are required when we want to execute a sequence of commands in Unix flavored operating systems. “Shell” is the command line i…
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
This video shows how to set up a shell script to accept a positional parameter when called, pass that to a SQL script, accept the output from the statement back and then manipulate it in the Shell.
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question