Re: ftp access

From: Steve Ames (steve@virtual-voodoo.com)
Date: 02/27/01


Date: Tue, 27 Feb 2001 17:39:23 -0500
From: Steve Ames <steve@virtual-voodoo.com>
To: George.Giles@mcmail.vanderbilt.edu

Specify a "shell" that won't actually allow shell access.
I believe /bin/true (or /sbin/nologin) would work but there
are some specific ports that you can use to provide some info
to the user when their telnet fails...

From /usr/ports/sysutils/no-login/pkg-descr:

This program will refuse login to a user, and make a note of it in the
system logs (syslog). This is suitable for use as a "login shell" for
a user that you want to temporarily deny access to. Just set that user's
shell to /usr/local/sbin/nologin.

-Steve

On Tue, Feb 27, 2001 at 04:22:33PM -0600, George.Giles@mcmail.vanderbilt.edu wrote:
> What do I use in passwd to allow ftp, but not shell access on account ?
>
>
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: scponly, allowing sftp and denying ssh access
    ... > shell access on a Solaris 10 system. ... > The old trick used for restricting traditional FTP access only was to ... > which prohibits user shell access but allows sftp and ftp access. ...
    (comp.security.ssh)
  • Re: User Accounts with no shell access
    ... With the exception of 3 users, users do not need any shell ... > users that need no shell access there appears to be no need for a home ... procedures as well at the start, leaving the manual process in there so ... that it is clearly understood what the script does. ...
    (alt.os.linux.suse)
  • scponly, allowing sftp and denying ssh access
    ... shell access on a Solaris 10 system. ... The old trick used for restricting traditional FTP access only was to ... which prohibits user shell access but allows sftp and ftp access. ...
    (comp.security.ssh)
  • Re: Shell for tiny terminal
    ... > I'm the author of Anyterm, a javascript thing that gives you ... > shell access to your machine from a web browser. ... Sure you can have every command to pipe its output to ...
    (comp.unix.shell)
  • Re: shell ISP
    ... Don't know if you'll find one for $5/month that offers shell access. ... but those that offer shell usually charge around $20-30/month. ... DeeDee, don't press that button! ...
    (comp.unix.shell)