Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 5 Dec 1997 14:55:07 +0000 (GMT)
From:      Scot Elliott <scot@duff-beer.com>
To:        Bradley Dunn <bradley@dunn.org>
Cc:        Gaetan Feige <Gaetan@vsg.mobistar.be>, freebsd-isp@FreeBSD.ORG
Subject:   Re: User security
Message-ID:  <Pine.BSF.3.96.971205145409.20530A-100000@homer.duff-beer.com>
In-Reply-To: <Pine.BSF.3.96.971205091912.10211A-100000@ns3.harborcom.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Try giving the user an invalid shell (like /nonexistant or a valid one
like /bin/false).

On Fri, 5 Dec 1997, Bradley Dunn wrote:

> On Fri, 5 Dec 1997, Gaetan Feige wrote:
> 
> > I am wondering what is the best way to give a user access to email on a bsd
> > box and block him from anything else like telnet, ftp into his account...
> 
> Don't run telnetd, ftpd, etc. :)
> 
> Seriously, black box mail servers that only allow access via IMAP or POP
> are the way to go if you can. You can use SSH for remote administration,
> and with SSH's "AllowUsers" configuration option you can specify exactly
> who can connect via SSH.
> 
> Bradley
> 
> 

-----------------------------------------------------------------------------
Scot Elliott (scot@poptart.org)			|    Work: +44 (0)1344 899401
PGP fingerprint: FCAE9ED3A234FEB59F8C7F9DDD112D |    Home: +44 (0)181 8961019
-----------------------------------------------------------------------------
Public key available by finger at:   finger scot@poptart.org
			    or at:   http://www.poptart.org/pgpkey.html





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.96.971205145409.20530A-100000>