Basically, if you know who the the user is, you can try to create a chroot jail.
This prevents them from logging in using su to get privs and then editing files outside their new "root" directectory.
However, user with root access can defeat a chroot jail.
Here is an example for a ssh chroot jail:
http://www.fuschlberger.net/programs...p-chroot-jail/