Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Secure Shell
Protecting a file in internal-sftp jail (chroot) Sep 25 2009 11:49AM
Eriberto (eriberto eriberto pro br) (2 replies)
Re: Protecting a file in internal-sftp jail (chroot) Sep 29 2009 06:35AM
docks (at) gmx (dot) li [email concealed] (docks gmx li)
Re: Protecting a file in internal-sftp jail (chroot) Sep 25 2009 01:16PM
Stefan Hornburg (racke linuxia de)
Eriberto wrote:
> Hi all,
>
> I made a jail using sftp-internal (Debian Lenny 5.0.3 / OpenSSH
> 5.1p1). I followed the steps found at
> http://www.debian-administration.org/articles/590 and it is working
> fine. But I have a little problem. I am using this process to give
> access to users put files in directories into /var/www (Apache) and
> each directory has a .htaccess to force a password to access from a
> browser.
>
> My problem is: the jail user can delete the .htaccess file and I need
> to prevent it. But, in jail, the user has root power.
>
> Final question: how to make to protect a file in a jail made using
> internal-sftp?
>
> Thanks a lot in advanced.

What about moving the directives in .htaccess into Apache configuration
file(s)?

That is faster anyway.

Regards
Racke

--
LinuXia Systems => http://www.linuxia.de/
Expert Interchange Consulting and System Administration
ICDEVGROUP => http://www.icdevgroup.org/
Interchange Development Team

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus