Solved

Lock down a user to just their home directroy

Posted on 2004-05-02
4
338 Views
Last Modified: 2013-12-16

I have a group of people that I want to have read/write access to a directory.  They are windows users that will be useing the winscp software to download pictures of homes.  

I want to limit them to just that one directory.  They are currenty a memeber of the "user's" group and have a shell of /bin/bash.

Should I change the shell to nothing? Should I create a new group and not give them rights to anything.  Should I to a changeroot jail.

I do not want anybody deleting any of my system files and I do not want them viewing any images on my system that were not intended for them to view.

Winscp is working NOW so I would like to get this fixed before someone gets curious

timfox123
0
Comment
Question by:TIMFOX123
  • 2
  • 2
4 Comments
 
LVL 38

Accepted Solution

by:
yuzh earned 500 total points
Comment Utility
You can setup "chroot login" to do the job, have a look at the following doc to get some
idea about how to set it up:

http://www.tjw.org/chroot-login-HOWTO/

also have a look at:

http://chrootssh.sourceforge.net/index.php
0
 

Author Comment

by:TIMFOX123
Comment Utility
I am reviewing this.  It appears scponly is a grand tool for his and I am evaluating this.  

Any commnents on scponly ?

Dave
0
 
LVL 38

Expert Comment

by:yuzh
Comment Utility
Here's another example of chroot login setup:

http://www.kegel.com/crosstool/current/doc/chroot-login-howto.html
0
 

Author Comment

by:TIMFOX123
Comment Utility
scponly really ROCKS !!!!

I have a passworded share and the windows users use a gui winscp to drag/drop to my share.  They are change root jailed so they can not mess with my other files.   Easy safe secure (ish).  

This was so much easier than making a jail, you just typed in the make jail and it made a change root jail.  

Wahhooo, I am happy.  Now the other people in the Home Owners Association do not think I am a moron (untill another day).

Dave
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

In this tutorial I will explain how to make squid prevent malwares in five easy steps: Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-…
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now