General Security Discussions Discuss anything that is security related here.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 15th January 2010, 09:45
Tsukasa's Avatar
-=Ninja Pirate=-
 
Join Date: Jun 2008
Location: ::1
Posts: 491
Rep Power: 14
Reputation: 319
Tsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the dark
sftp - jailed & nologin?

So i searched a little and not really coming up with what I am looking for so posting it here to ask, its also almost 4am so i'm not about to search irc servers for an answer i'm gonna head to bed.


using openssh as the sftp

I want to create a jailed nologin user to upload/download without browsing files or exe privs.

Example how I would do this in vsftp.
useradd --home /jailed/dir --shell /usr/sbin/nologin UserAccountName
* This user is not allowed to login to a shell
* nologin was added into /etc/shells

vsftpd.userlist would contain the above created user name to be allowed to use only the ftp and jailed to its dir.

Anyone of do such task for the sftp?
__________________
"...a computer is a stupid machine with the ability to do incredibly
smart things, while computer programmers are smart people with the
ability to do incredibly stupid things. They are, in short, a perfect
match".
Reply With Quote
  #2  
Old 18th January 2010, 16:46
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,405
Blog Entries: 36
Rep Power: 10
Reputation: 198
MaXe has made his way up the systemMaXe has made his way up the system
Re: sftp - jailed & nologin?

I might only know it if it was the normal sftp and not vsftpd.

I guess Xires might be able to help you or eventually me when I try it out sometime soon :-)
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
  #3  
Old 20th January 2010, 17:21
 
Join Date: Jan 2009
Location: D/FW, TX
Posts: 25
Rep Power: 7
Reputation: 35
Xires is on the way to become something
Re: sftp - jailed & nologin?

I think what you're looking for is scponly. rssh is also available but in my experience it's not as clean or quite as good. scponly is about as simple as it gets; just install it and set it as the user's shell. That's all there is to it. You don't need to modify your SSHd configuration or anything.

Do keep in mind, however, that it can make it somewhat annoying to 'su' to since the 'su' command launches the user's shell as defined in /etc/passwd. Thus, just specify the shell when you wish to su to that user(e.g. su -s ${SHELL} someacct).
__________________
-Xires

Last edited by Xires; 20th January 2010 at 17:22. Reason: fix rssh URL
Reply With Quote
  #4  
Old 21st January 2010, 06:41
Tsukasa's Avatar
-=Ninja Pirate=-
 
Join Date: Jun 2008
Location: ::1
Posts: 491
Rep Power: 14
Reputation: 319
Tsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the dark
Re: sftp - jailed & nologin?

Ya Xires you told me about it in irc but also a good thing to have posted here for others to know as well.
__________________
"...a computer is a stupid machine with the ability to do incredibly
smart things, while computer programmers are smart people with the
ability to do incredibly stupid things. They are, in short, a perfect
match".
Reply With Quote
  #5  
Old 2nd February 2010, 16:38
MaXe's Avatar
Studying shellcode..
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 3,405
Blog Entries: 36
Rep Power: 10
Reputation: 198
MaXe has made his way up the systemMaXe has made his way up the system
Re: sftp - jailed & nologin?

Thanks Xires, i didn't know there was a scponly shell :-) Very much useful, +rep!
__________________

Quote:
Originally Posted by Norph
MaXe, I really doubt that you are able to browse ANY site more than 2 minutes before you start pwning it xD
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT +2. The time now is 13:56.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1