DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2011-02-17 14:01:57

shad0wca7
Member
Registered: 2011-01-07
Posts: 13

Ftp users & Security

Hi everyone, I'm something of a linux n00b so I could just be being dumb... Here is my problem:

I set up a user with a particular home directory and I only want them to have read access to that directory and nothing else. I did this originally in the web interface - however now the 'read only' access doesn't seem to be working. They are still in a chroot jail but can rename files etc

A more concerning thing is that the user can ssh to the box and get to the root directory and do whatver they want. They are presented with the busybox shell prompt but that is easy to get around.

How can I stop this? I'd like to be able to give some user/passes to friends and would like to set up an anonymous area but don't want any shenanigans!

Offline

 

#2 2011-02-17 14:51:10

shad0wca7
Member
Registered: 2011-01-07
Posts: 13

Re: Ftp users & Security

Quick update, I solved the 'any users can use shell' issue this way:

I couldn't direct the shell to /dev/null as then their ftp access wouldn't work. I found out that this is because pure-ftpd needs all users to have a shall listed in /etc/shells .. So I added /dev/null as a shell and it works fine now. Users can ftp in and they can't get shell access.

Now... does any user apart from root (that I use to do admin stuff) actually need shell access?

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB