Restricted shells are really fairly worthless security wise.  You can do
this with cudo and chroot, or with jail, or with sshd2 which is in ports.
This can become tricky getting all the programs you want to function.

sshd2 would be the easy way to do this.  It is in ports.  Only problem is
its not our beloved OpenSSH

-----Original Message-----
From: Gautam Gopalakrishnan [mailto:[EMAIL PROTECTED]
Sent: Wednesday, January 28, 2004 9:42 PM
Subject: Re: locking a user into one directory

On Wed, Jan 28, 2004 at 09:59:11PM -0500, Lowell Gilbert wrote:
> Dragoncrest <[EMAIL PROTECTED]> writes:
> >     I've seen this explained before, but I've never taken much
> > interest in it as I never had a need for it.  Well, it's starting to
> > look like I do.  What I'm wanting to do is give shell access to a user
> > to shell into the mail server, check their mail, and that's it.  I
> > don't want them to be able to wander outside of their home directory.
> > I think it's called a jail, but I don't remember.  Does anyone know
> > what it is I need and have a tutorial for it or know where I can find
> > one?  Much appreciated.
> Um, you mean "man jail"?
> Or maybe "man chroot"...

Or you could use a restricted shell, maybe zsh or bash.


[EMAIL PROTECTED] mailing list
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

CONFIDENTIALITY NOTE: This electronic transmission, including all
attachments, is directed in confidence solely to the person(s) to whom it is
addressed, or an authorized recipient, and may not otherwise be distributed,
copied or disclosed. The contents of the transmission may also be subject to
intellectual property rights and all such rights are expressly claimed and
are not waived. If you have received this transmission in error, please
notify the sender immediately by return electronic transmission and then
immediately delete this transmission, including all attachments, without
copying, distributing or disclosing same. 

[EMAIL PROTECTED] mailing list
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to