Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: sftp virtual users question |
|---|---|
| Date: | Wed, 2 Feb 2005 09:58:18 -0800 (PST) |
check out scponly. that lets you chroot a user, and only allow scp/sftp.
On Tue, 1 Feb 2005, Bob Rasmussen wrote:
On Tue, 1 Feb 2005, Lukasz Chruszczyk wrote:
Helo 1.Is it possible to prevent a user to get access to shell (by means of ssh), but give him/her access to sftp (or scp) 2.Is it possible to manage users independently for ssh and sftp(scp) subsystems? 3.Documentation about sftp-server subsystem is very poor? Where can I get more info?
First, I assume you're talking about OpenSSH's implementation; is that right?
You are right that there is very little configurability. You might want to force a particular directory as the user's home directory for SFTP (different from their login directory). You might also want to restrict their navigation.
As far as I can tell there is no way to do this with OpenSSH's implementation. This would be a good area for someone to expand upon.
Regards, ....Bob Rasmussen, President, Rasmussen Software, Inc.
personal e-mail: ras@anzio.com company e-mail: rsi@anzio.com voice: (US) 503-624-0360 (9:00-6:00 Pacific Time) fax: (US) 503-624-0760 web: http://www.anzio.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: OpenSSH shell access failure, Bauer, Henry |
|---|---|
| Next by Date: | RE: AllowGroups and ldap, Tay, Gary |
| Previous by Thread: | Re: sftp virtual users question, Bob Rasmussen |
| Next by Thread: | Re: sftp virtual users question, Jose Hidalgo Herrera |
| Indexes: | [Date] [Thread] [Top] [All Lists] |