Unix Technical Forum

Restrict non-anonymous from change directory outside "home"

This is a discussion on Restrict non-anonymous from change directory outside "home" within the HP-UX Operating System forums, part of the Unix Operating Systems category; --> I had create this user account mainly for FTP use. I had already setup FTPD with ftpaccess functionality. The ...


Go Back   Unix Technical Forum > Unix Operating Systems > HP-UX Operating System

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-16-2008, 06:47 PM
Ultra Kiasu
 
Posts: n/a
Default Restrict non-anonymous from change directory outside "home"

I had create this user account mainly for FTP use.

I had already setup FTPD with ftpaccess functionality.

The following is the content of my /etc/ftpd/ftpaccess
#=====
class local real *.mydomain.com
class outsider real !*.mydomain.com

loginfails 3
banner /etc/ftpd/banner.msg
greeting terse
noretrieve /etc/passwd core

upload class=local / * no
upload class=local /files/upload/ * yes guser itstaff 0660 nodirs
#======

There is numerous subdirectories within /files/upload, which this user
can change directory to, but I am having problem restrict this user
from exit outside /files/upload. It currently able to even able to cd
to / (root) and perform dir listing.

Anyone able to help me??

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 06:47 PM
Florian Anwander
 
Posts: n/a
Default Re: Restrict non-anonymous from change directory outside "home"

Hi Ultra

> There is numerous subdirectories within /files/upload, which this user
> can change directory to, but I am having problem restrict this user
> from exit outside /files/upload. It currently able to even able to cd
> to / (root) and perform dir listing.

Look for "anonymous ftp" and "chroot" command in your favourite search
machine.

Florian

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-16-2008, 06:47 PM
Sun
 
Posts: n/a
Default Re: Restrict non-anonymous from change directory outside "home"

Use rsh shell, with this they can't go ouside of home directory.

-SR

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:56 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com