LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-12-2015, 01:03 AM   #1
SantoshSonavale
LQ Newbie
 
Registered: Mar 2009
Posts: 10

Rep: Reputation: 0
how to restrict /bin/false user from executing /bin/chmod command


how to restrict /bin/false user from executing /bin/chmod command
 
Old 08-12-2015, 01:26 AM   #2
Keruskerfuerst
Senior Member
 
Registered: Oct 2005
Location: Horgau, Germany
Distribution: Manjaro KDE, Win 10
Posts: 2,199

Rep: Reputation: 164Reputation: 164
info false
 
Old 08-12-2015, 04:28 AM   #3
SantoshSonavale
LQ Newbie
 
Registered: Mar 2009
Posts: 10

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by Keruskerfuerst View Post
info false
As i know, user will not get access to any shell.... but he can able to do ftp through ftp client such as winscp, filezilla etc..
& as /bin/false shell is assigned to FTP users... so how can i restrict sftp users from changing the permissions.. so i want to restrict them to user /bin/chmod command...
 
Old 08-12-2015, 08:09 AM   #4
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,830

Rep: Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308
sftp does not use /bin/chmod at all. You need to restrict directory access (to avoid permission changes) I think, but we need more info to help further (for example how the ftp server was configured, what files/dirs should be protected - show an example)
 
Old 08-13-2015, 12:33 AM   #5
SantoshSonavale
LQ Newbie
 
Registered: Mar 2009
Posts: 10

Original Poster
Rep: Reputation: 0
thanks for your reply... sftp server is configured through ssh (rhel 6.2)... users home directory should be need to protected... as he is owner of directory he is able to change permissions... i want to restrict user from changing the permission of directory & sub directory...
 
Old 08-13-2015, 01:48 AM   #6
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,830

Rep: Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308Reputation: 7308
I think you can simply remove write access on home dir (as root) and subdirs too, (even the owner can be changed).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/bin/false users command history SantoshSonavale Linux - Server 1 08-12-2015 05:17 AM
chmod u+x /usr/bin/lptout does not work for not su - user cwc Fedora 3 08-03-2010 12:34 AM
echo $PATH = /home/g3rc4n/bin:/usr/local/bin:/usr/bin:/bin:/usr/games ? i_heart_pandas Linux - Software 7 09-18-2009 08:33 AM
sudo /usr/bin/chroot /home/chroot /bin/su - xxx| /bin/su: user xxx does not exist saavik Linux - General 3 07-04-2007 10:30 AM
problems with /bin/false reactnet Slackware 5 08-29-2005 10:19 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 12:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration