FTP Help
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationFTP Help

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old June 20th, 2006, 05:41 PM
misterdanny's Avatar
misterdanny misterdanny is offline
Null Pointer Exception
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Mar 2006
Location: america
Posts: 2,271 misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Weeks 4 Days 3 h 56 m 35 sec
Reputation Power: 313
Not allowing ftp login user to see above a certain directory

im using vsFTPD on centOS with webmin control panel.

i figured out how to make an account and only allow them to modify files in their "home directory" the problem is in the FTP they can view the other directories above their home directory. ie user2 s home directory is /var/www/html/user2 but if they wanted to they could go into /var/www/html and see everything there as well as download the files.

this is a serioues breach in secruity obviously becasue they can freely view any file in the server which could be holding all sorts of information their not supposed to see.

i can't figure out how to change this i think it might have to do with what "shell" they are using (theres a drop down to pick different shells) but changing it either seemed to do nothing different or it didn't let them login at all

Reply With Quote
  #2  
Old June 20th, 2006, 07:38 PM
jharnois's Avatar
jharnois jharnois is offline
mod_dev_shed
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Sep 2002
Location: Atlanta, GA
Posts: 14,461 jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level)jharnois User rank is Lieutenant General (80000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 2 Days 15 h 14 m
Reputation Power: 825
You need to "chroot" them, but I have no idea how you would go about that with your software on your OS in your control panel
__________________
# Jeremy

Explain your problem instead of asking how to do what you decided was the solution.

Reply With Quote
  #3  
Old June 20th, 2006, 07:49 PM
misterdanny's Avatar
misterdanny misterdanny is offline
Null Pointer Exception
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Mar 2006
Location: america
Posts: 2,271 misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level)misterdanny User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Weeks 4 Days 3 h 56 m 35 sec
Reputation Power: 313
i found out where to enable chroot, but now they cant modify anything only view stuff (but they arent alloud to see above their home directory which is good)

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationFTP Help > Not allowing ftp login user to see above a certain directory


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT