LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 10-12-2005, 04:40 PM   #1
The_JinJ
Member
 
Registered: Apr 2004
Location: Scotland
Distribution: Suse, OpenWRT
Posts: 299

Rep: Reputation: 30
Arrow Best way to lockdown users


Hi all

I want to lock down a user to their home directory and offer them no commands to run a part from whats in $HOME/bin (one command)
So I don't need cd, ls etc for the users - only the one command local to them.

I think I need to remove /etc/profile, /etc/bashrc and just have the path set to $HOME/bin in .bash_profile. Would this let them see nothing?
I tried to change /home to no rwx but then ssh can't change to the users home directory because it doesn't have permission.

I may be going about this the long, wrong way - anyone offer any advice?

So in summary - user logs in via SSH, can't leave own directory, has no commands to run apart from whats in $HOME/bin.

Thanks in advance
 
Old 10-12-2005, 06:46 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
If the scope is strictly users logging in tru ssh, then there's chrootssh.sourceforge.net (BTW, if anyone ever needs to allow users access to only scp/sftp there's also shells that only allow that: Google for Rssh or Scponly). Since Chrootssh uses the default chroot syscall, please consider hardening it using the GRSecurity kernel patch (and get much more hardening options in return than only making chroot "better").
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
lockdown program daven1 Programming 9 02-04-2009 01:50 PM
Desktop Lockdown jjfate Linux - Enterprise 8 02-07-2007 03:37 PM
is there such thing as a lockdown command? poiuytrewq Linux - Security 4 04-16-2005 06:53 AM
Lockdown Obie Linux - Security 10 07-30-2004 03:07 AM
Lockdown or not? neil Linux - Security 5 04-08-2002 02:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 12:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration