Secure FTP (sftp)

Eric Peters eric at linuxsystems.net
Tue Oct 23 08:16:59 UTC 2007


Well yes and no,

>From the sounds of it the user is trusted and if it is a public box
any admin would have other counter measures in

On 10/22/07, Michael R. Head <burner at suppressingfire.org> wrote:
>
> On Mon, 2007-10-22 at 16:46 -0500, Bill Asher wrote:
> > Anyone have a good HOWTO link for setting up a chrooted sftp server.
> > I need to do this for some outside vendors to dump files to our
> > office.  But I really don't want to setup a full blown ftp server like
> > vsftpd or proftpd as all the functionality of these are not needed.
> > I'd like to use SSH but I need it chrooted, maybe authentication keys
> > too?
>
> Keep in mind, chroot isn't a security tool, it's a debugging/development
> tool.
>
> http://www.bpfh.net/simes/computing/chroot-break.html
> http://en.wikipedia.org/wiki/Chroot
> http://kerneltrap.org/Linux/Abusing_chroot
>
> >
> > Thought I'd ask the list at this point, I've googled and there seems
> > to be a lot of opinions, just looking for a proven one.
> >
> >
> >
> > Thanks,
> >
> > Bill
> >
> >
> > --
> > ubuntu-server mailing list
> > ubuntu-server at lists.ubuntu.com
> > https://lists.ubuntu.com/mailman/listinfo/ubuntu-server
> > More info: https://wiki.ubuntu.com/ServerTeam
> --
> Michael R. Head <burner at suppressingfire.org>
> http://picasaweb.google.com/demiri.head.wedding
>




More information about the ubuntu-server mailing list