Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 363
  • Last Modified:

Create an Account that has access to ftp only to one particular folder?

I've solaris and apache server installed.
The rootDirectory of apache server is /var/apache/htdocs
Only Root account has access to that folder. Now i'd like to create a new account that can only ftp to this folder only.
How do i do it?
1 Solution
Let's say, you want to give fred read and write permission
for /var/apache/htdocs

you can simply do:

cd /var/appache
chown  fred htdocs

Instead of chown'ing htdocs to fred, you're better off creating a 'htdocs' group and doing something like
  chgrp htdocs /var/apache/htdocs
  chmod g+rwx /var/apache/htdocs

Though you might not even want fred to be able to write directly in htdocs but rather in some set of subdirectories.
Also, you might not want to use FTP, since it sends passwords as clear-text over the network. Instead consider SSH/SCP/SFTP (see www.openssh.com for free implementations)
You can create an ftp only account:

create a file /bin/ftpaccess

echo 'echo "This account is for ftp access only"' > /bin/ftpaccess

chmod a+x /bin/ftpaccess to give it execution rights

Add /bin/ftpaccess into the /etc/shells file
*It is important to have the other shells there as well

create an account that you want to have the ftp access only and for its shell, put /bin/ftpaccess

You will have to set the rights to the directory that you want the account go to.

If you try to telnet to that account, you will get the message "This account is for ftp access only".

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now