From owner-freebsd-questions@FreeBSD.ORG Thu Mar 31 06:24:51 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3F57F16A4CE for ; Thu, 31 Mar 2005 06:24:51 +0000 (GMT) Received: from splinter.bowdoin.edu (splinter.bowdoin.edu [139.140.181.132]) by mx1.FreeBSD.org (Postfix) with ESMTP id E054943D49 for ; Thu, 31 Mar 2005 06:24:50 +0000 (GMT) (envelope-from alec@thened.net) Received: by splinter.bowdoin.edu (Postfix, from userid 12008) id CFE18C0D5; Thu, 31 Mar 2005 01:24:49 -0500 (EST) Date: Thu, 31 Mar 2005 01:24:49 -0500 From: Alec Berryman To: freebsd-questions@freebsd.org Message-ID: <20050331062449.GE96244@thened.net> Mail-Followup-To: freebsd-questions@freebsd.org References: <424B13EF.6050400@att.net> <200503301628.56047.wizlayer@gmail.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="0QFb0wBpEddLcDHQ" Content-Disposition: inline In-Reply-To: <200503301628.56047.wizlayer@gmail.com> X-Ned-Wuz-Here: Yes X-GPG-Fingerprint: 3DB5 8785 53D9 8BF4 5049 B6B9 02E7 7FD9 881C 85C4 X-GPG-Key: http://www.thened.net/~alec/static/alec.asc User-Agent: Mutt/1.5.9i Subject: Re: ssh - restricted shell X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 31 Mar 2005 06:24:51 -0000 --0QFb0wBpEddLcDHQ Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable wizlayer on 2005-03-30 16:28:55 -0500: > I thought this was accomplished when initially setting up a user's=20 > account? I'm under the impression that when a user clients sshd,=20 > s/he still can't go beyong the boundaries of his/her existing=20 > account on the server. Of course: if $impression =3D "delusion"=20 > then someone _please_ correct me! fi :O If you mean 'outside of his home directory', then yes, a user can go outside 'his/her existing account on the server'. He can't read, modify, or execute files he doesn't have permission for, however. --0QFb0wBpEddLcDHQ Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.0 (FreeBSD) iD8DBQFCS5exAud/2YgchcQRAsngAKC0rZC5fVh8qJXBBNHPOVLPu4NlogCg1bPr OcR6N9QqWR+rONooEby/wJw= =WyPo -----END PGP SIGNATURE----- --0QFb0wBpEddLcDHQ--