Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 5 Mar 2001 18:48:58 +0100
From:      Walter Hop <walter@binity.com>
To:        "G D McKee" <freebsd@gdmckee.com>
Cc:        "peter pajak" <peterpajak@hotmail.com>, freebsd-questions@FreeBSD.ORG
Subject:   Re: Jail USER in HOME dir
Message-ID:  <164186379910.20010305184858@binity.com>
In-Reply-To: <001501c0a58f$79ca95c0$0500a8c0@gdmckee.local>
References:  <F96NIiJg52jvaZS8nhq000034a4@hotmail.com> <001501c0a58f$79ca95c0$0500a8c0@gdmckee.local>

next in thread | previous in thread | raw e-mail | index | archive | help
[in reply to freebsd@gdmckee.com, 05-03-2001]

>> >How can I stop a user leaving their home dir?
>> >
>> >Gordon
>> >PS Please can you reply direct as I am not currently subscribed to the
>> >mailing list
>
> Has anyone got any ides that work?

Yes. I have compiled and set up "chrsh" with success on a shell box I
administer. http://www.aarongifford.com/computers/chrsh.html

Beware for a false sense of security, though. The shell is probably not
the only means of traveling through the filesystem; if you run a shared
webserver or allow people to use scripts somewhere (in procmail for
example), you cannot guarantee this type of security.

If you need help in setting up a convenient jail environment for
day-to-day use email me back. I would write something about this, if it
weren't for my exams....

walter

--
 "There's a time when you have to give the customer trouble if that is what
  they are asking for. If they truly want NT then provide it to the best that
  it can be done and then when it falls apart, you can tell them: ``OK, now
  that we have gone down that road and you have satisfied yourself that it's
  worthless, let me do it the right way for you now.''" -- Ted Mittelstaedt



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?164186379910.20010305184858>