General Security Discussions Discuss anything that is security related here.

InterN0T Affiliates:
EvilZonepy1337

SirCapsAlot.NET

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 15th January 2010, 10:45
Tsukasa's Avatar
-=Ninja Pirate=-
 
Join Date: Jun 2008
Location: ::1
Posts: 460
Rep Power: 11
Reputation: 287
Tsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the dark
sftp - jailed & nologin?

So i searched a little and not really coming up with what I am looking for so posting it here to ask, its also almost 4am so i'm not about to search irc servers for an answer i'm gonna head to bed.


using openssh as the sftp

I want to create a jailed nologin user to upload/download without browsing files or exe privs.

Example how I would do this in vsftp.
useradd --home /jailed/dir --shell /usr/sbin/nologin UserAccountName
* This user is not allowed to login to a shell
* nologin was added into /etc/shells

vsftpd.userlist would contain the above created user name to be allowed to use only the ftp and jailed to its dir.

Anyone of do such task for the sftp?
__________________
"...a computer is a stupid machine with the ability to do incredibly
smart things, while computer programmers are smart people with the
ability to do incredibly stupid things. They are, in short, a perfect
match".
Reply With Quote
  #2  
Old 18th January 2010, 17:46
MaXe's Avatar
The Founder
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 2,692
Blog Entries: 31
Rep Power: 10
Reputation: 146
MaXe will become a Token soonMaXe will become a Token soon
Re: sftp - jailed & nologin?

I might only know it if it was the normal sftp and not vsftpd.

I guess Xires might be able to help you or eventually me when I try it out sometime soon :-)
__________________
Code:
                                ____/____\_________________
                      \|/      | OMG IT'S TEH LEET STORY!! |
    /*\         /\    -*-      |______  ________/\_________|
   // \\       /  \   /|\        /    \/    \  /  \
  /// \\\     /    \            /            \/    \
   // \\     /      \          /      \o/     \     \
    | |     /        \        /        |       \     \
 ___| |____/          \______/________/ \_______\_____\_________
          /     o      \
               #"=-
               /\
 __________________________________________________________
    On a mission, to find the lost member of Teh Unkwon.. 
Reply With Quote
  #3  
Old 20th January 2010, 18:21
 
Join Date: Jan 2009
Location: D/FW, TX
Posts: 21
Rep Power: 5
Reputation: 15
Xires is on the way to become something
Re: sftp - jailed & nologin?

I think what you're looking for is scponly. rssh is also available but in my experience it's not as clean or quite as good. scponly is about as simple as it gets; just install it and set it as the user's shell. That's all there is to it. You don't need to modify your SSHd configuration or anything.

Do keep in mind, however, that it can make it somewhat annoying to 'su' to since the 'su' command launches the user's shell as defined in /etc/passwd. Thus, just specify the shell when you wish to su to that user(e.g. su -s ${SHELL} someacct).
__________________
-Xires

Last edited by Xires; 20th January 2010 at 18:22. Reason: fix rssh URL
Reply With Quote
  #4  
Old 21st January 2010, 07:41
Tsukasa's Avatar
-=Ninja Pirate=-
 
Join Date: Jun 2008
Location: ::1
Posts: 460
Rep Power: 11
Reputation: 287
Tsukasa is a light in the darkTsukasa is a light in the darkTsukasa is a light in the dark
Re: sftp - jailed & nologin?

Ya Xires you told me about it in irc but also a good thing to have posted here for others to know as well.
__________________
"...a computer is a stupid machine with the ability to do incredibly
smart things, while computer programmers are smart people with the
ability to do incredibly stupid things. They are, in short, a perfect
match".
Reply With Quote
  #5  
Old 2nd February 2010, 17:38
MaXe's Avatar
The Founder
 
Join Date: Jun 2008
Location: Sweden - Ljusdal
Posts: 2,692
Blog Entries: 31
Rep Power: 10
Reputation: 146
MaXe will become a Token soonMaXe will become a Token soon
Re: sftp - jailed & nologin?

Thanks Xires, i didn't know there was a scponly shell :-) Very much useful, +rep!
__________________
Code:
                                ____/____\_________________
                      \|/      | OMG IT'S TEH LEET STORY!! |
    /*\         /\    -*-      |______  ________/\_________|
   // \\       /  \   /|\        /    \/    \  /  \
  /// \\\     /    \            /            \/    \
   // \\     /      \          /      \o/     \     \
    | |     /        \        /        |       \     \
 ___| |____/          \______/________/ \_______\_____\_________
          /     o      \
               #"=-
               /\
 __________________________________________________________
    On a mission, to find the lost member of Teh Unkwon.. 
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT +2. The time now is 08:39.
Copyright ©2007 - Forever, InterN0T & Teh Unkwon

Hosted by 1and1