Security Basics mailing list archives

Re: Public Web server Help


From: Glenn English <ghe () slsware com>
Date: Fri, 26 Mar 2004 15:20:47 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Friday 26 March 2004 11:34 am, Shawn Jackson wrote:

Does anyone know of any of have any document on how to lock users
in their home directories using SSH? In the UNIX/Telnet world there
was a way, I just don't know if it migrated to the Linux world.

According to man sshd, during the login process sshd executes 
$HOME/.ssh/rc, if it exists. so "chroot $HOME"?

And according to the O'Reilly book on ssh, there's an ssh2 config file 
parameter called "ChRootUsers." But I can't find any mention of that 
on my (pretty well updated) Linux systems. Maybe they're just 
kidding...

Does anyone know of any or have any documents on how to properly
setup Apache (HTTPD) for this environment. I've setup normal
websites using Apache, Virtual Hosts, Aliases, etc but this seams
to be a different beast altogether.

Virtual hosts with home directories of $HOME/<domain name>?

- -- 
Glenn English
ghe () slsware com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAZKy/4yo0yP04eqkRArAnAJ41WFV28RU+sjreYtYC+Y6wOJVeCwCgkbE0
3vp3qXSi8GGj5dcaKyf1JXU=
=tovW
-----END PGP SIGNATURE-----

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: