<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: simple FTP and root-jailing in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991308#M548586</link>
    <description>Hello Ivan,&lt;BR /&gt;thank you - your answer has brought the solution. We've missed two things - the trailing slash at the home-dir and stupidly the /bin/false-shell.&lt;BR /&gt;&lt;BR /&gt;Mui bien&lt;BR /&gt;Greetings to Paraguay&lt;BR /&gt;Charly</description>
    <pubDate>Mon, 17 Jul 2006 09:38:30 GMT</pubDate>
    <dc:creator>Charly Preis</dc:creator>
    <dc:date>2006-07-17T09:38:30Z</dc:date>
    <item>
      <title>simple FTP and root-jailing</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991306#M548584</link>
      <description>Shalom alltogether,&lt;BR /&gt;we're working on a rx4640 machine under 11.23 and have the following needs:&lt;BR /&gt;We have one ftp-user who should only get an ftp-access (no os-access like other users). &lt;BR /&gt;&lt;BR /&gt;We created this using &lt;USERADD -u="" 222="" -g="" 500="" -d=""&gt;. &lt;BR /&gt;&lt;BR /&gt;This user should be able to read/write any file below this directory (also put/get them) - but he shouldn't be able to navigate above the home-directory.&lt;BR /&gt;&lt;BR /&gt;We've already read some instructions in the book 'Installing and configuring internet services' - espacially the chapter over 'anonymous ftp access' - but our user is still able to navigate above his home-dir. &lt;BR /&gt;&lt;BR /&gt;Hopefully awaiting your answers&lt;BR /&gt;Thanx&lt;BR /&gt;Charly&lt;/USERADD&gt;</description>
      <pubDate>Mon, 17 Jul 2006 09:01:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991306#M548584</guid>
      <dc:creator>Charly Preis</dc:creator>
      <dc:date>2006-07-17T09:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: simple FTP and root-jailing</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991307#M548585</link>
      <description>Can you describe the process that you did?&lt;BR /&gt;&lt;BR /&gt;Some tips:&lt;BR /&gt;&lt;BR /&gt;1- Ensure that the user have a invalid shell, like /bin/false. This will prevent to the user logon locally.&lt;BR /&gt;&lt;BR /&gt;2- The ftpaccess file should look like this:&lt;BR /&gt;&lt;BR /&gt;class   all   real,guest,anonymous  *&lt;BR /&gt;&lt;BR /&gt;limit   all   60   Any              /etc/msgs/msg.dead&lt;BR /&gt;&lt;BR /&gt;readme  README*    login&lt;BR /&gt;readme  README*    cwd=*&lt;BR /&gt;&lt;BR /&gt;message /welcome.msg            login&lt;BR /&gt;message .message                cwd=*&lt;BR /&gt;&lt;BR /&gt;compress        no             all&lt;BR /&gt;tar             no             all&lt;BR /&gt;&lt;BR /&gt;delete     no   anonymous,guest               # delete permission?&lt;BR /&gt;overwrite  no   anonymous,guest               # overwrite permission?&lt;BR /&gt;rename     no   anonymous,guest               # rename permission?&lt;BR /&gt;chmod      no   anonymous,guest               # chmod permission?&lt;BR /&gt;umask      no   anonymous,guest               # umask permission?&lt;BR /&gt;&lt;BR /&gt;log commands real&lt;BR /&gt;log transfers anonymous,real inbound,outbound&lt;BR /&gt;&lt;BR /&gt;shutdown /etc/shutmsg&lt;BR /&gt;&lt;BR /&gt;email root@clu-oas.sis.personal.net.py&lt;BR /&gt;&lt;BR /&gt;# CHROOT Users&lt;BR /&gt;guestuser username1 username2&lt;BR /&gt;&lt;BR /&gt;3- Ensure that the home for these users in the passwd ends with /./&lt;BR /&gt;&lt;BR /&gt;username1:*:211:214:CHROOT User:/path/to/home/./:/bin/false</description>
      <pubDate>Mon, 17 Jul 2006 09:27:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991307#M548585</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-07-17T09:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: simple FTP and root-jailing</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991308#M548586</link>
      <description>Hello Ivan,&lt;BR /&gt;thank you - your answer has brought the solution. We've missed two things - the trailing slash at the home-dir and stupidly the /bin/false-shell.&lt;BR /&gt;&lt;BR /&gt;Mui bien&lt;BR /&gt;Greetings to Paraguay&lt;BR /&gt;Charly</description>
      <pubDate>Mon, 17 Jul 2006 09:38:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991308#M548586</guid>
      <dc:creator>Charly Preis</dc:creator>
      <dc:date>2006-07-17T09:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: simple FTP and root-jailing</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991309#M548587</link>
      <description>See the above solution from Ivan.</description>
      <pubDate>Mon, 17 Jul 2006 09:40:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991309#M548587</guid>
      <dc:creator>Charly Preis</dc:creator>
      <dc:date>2006-07-17T09:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: simple FTP and root-jailing</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991310#M548588</link>
      <description>with HP-UX Secure Shell (T1471AA) a script named ssh_chroot_setup.sh (in /opt/ssh)is shipped which will do the job for you if you would like to use sftp. &lt;BR /&gt;I'm still working on it to get it working properly together with using LDAP but without LDAP it is working fine !&lt;BR /&gt;&lt;BR /&gt;See also the following doc:&lt;BR /&gt;&lt;A href="http://www4.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000082447780" target="_blank"&gt;http://www4.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000082447780&lt;/A&gt;</description>
      <pubDate>Tue, 18 Jul 2006 02:43:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/simple-ftp-and-root-jailing/m-p/4991310#M548588</guid>
      <dc:creator>SGUX</dc:creator>
      <dc:date>2006-07-18T02:43:33Z</dc:date>
    </item>
  </channel>
</rss>

