I'm also a newbie, struggling with a similar issue. I've just installed WinSCP which uses ssh to connect to my Linux machine and want to restrict access to certain directories.
To change the default directory that the user account logs into I think you can edit /etc/passwd, find the user account in question and change the directory from /home/user to /var/www/html.
The bit I haven't solved yet is stopping them from having browsing other directories. What I think we need is something like 'bash --restricted' (which you can run from the bash prompt - I'm using red hat 9 by the way), but when I change /bin/bash to "/bin/bash --restricted" in /etc/passwd I can no longer log in.
|