File permission


 
Thread Tools Search this Thread
Operating Systems Linux Ubuntu File permission
# 1  
Old 08-26-2011
File permission

Hi Friends,
I want to create one user on my server in such a way that when he logged in by ssh on server,he can able to access ONLY /var/www/drupal-6.2 this directory. Please tell me how should i do that.
# 2  
Old 08-26-2011
Change his home directory in /etc/passwd to /var/www/drupal-6.2. But it's a weak measure.
# 3  
Old 08-26-2011
If you have bash, you can change his login shell to rbash and he will be extremely limited in what operations he can do. You will need to change his home directory to drupal's, because he won't be able to cd at all in rbash. See RESTRICTED SHELL under man bash for a complete list of what a BASH restricted shell will and won't let him do.

Be sure not to allow him to edit his startup files or put any folders he has write-access to in PATH. (restricted shell will stop him from running ./myscript.sh because of the /, but if he could just dump the script somewhere...)
# 4  
Old 08-26-2011
I set rbash to that user & home dir to /var/www/drupal-6.2 but the problem is i want he can access anything inside drupal. rbash restricts cd command.
# 5  
Old 08-26-2011
You don't have to cd to do things. / in parameters isn't restricted.

Code:
nano path/to/file

mv /path/to/this path/to/that

This won't restrict him from editing things outside of drupal though. You could use user file ownership and permissions to do that.

Come to think of it, the whole "restrict to one directory" thing is a bit of a red herring for any operating system with relative and absolute paths. Any user can cd into /usr/, but can they edit files in there? Probably not. Any user can create files in /tmp/, but do they cd into /tmp/ when they do so? Probably not. cd is just a convenience, file permissions are what control the actual security.

Better to consider file ownership than what directory he's in. You could make him use a limited user where the drupal folder and things in it belong to his user. He could cd other places, but so what? He wouldn't be able to accomplish much by doing so.

Last edited by Corona688; 08-26-2011 at 03:53 AM..
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. HP-UX

File permission

Hi, Could you please tell me the OS command to grant as similar to below permission? rwxrwxr-x OS -- HP-UX Regards, Maddy (8 Replies)
Discussion started by: Maddy123
8 Replies

2. Shell Programming and Scripting

MV file with other permission

Hello All I have a file with rw-rw-r permission I need to mv the file into different directory (dir has rwx-rwx-rwx permission) with an others permission The application which is moving the file falls in other group I am getting the error mv cannot renamed permission denied ... (12 Replies)
Discussion started by: Pratik4891
12 Replies

3. Shell Programming and Scripting

File permission

I have an application with the user mark and another user james is trying to run the application and ending up with file permission issues. The user mark has set the umask as 002, I wanted to have a setting so that anyone can run the application without any file permission issues. Can anyone... (2 Replies)
Discussion started by: Muthuraj K
2 Replies

4. Shell Programming and Scripting

file permission

Hi All, https://www.unix.com/unix-advanced-expert-users/105758-chmod-parent-sub-directories.html I have to change permission for the directories and subdirectories in single command when googled i found some updates but i understand what is switch. If there is a command please... (2 Replies)
Discussion started by: thelakbe
2 Replies

5. Solaris

file permission

hi frnds can u explain /etc/shadow file have read and write permissions for root only but while normal user changes his passwd it also updated in that file whats the logic behind that. (2 Replies)
Discussion started by: sravan ega
2 Replies

6. Cybersecurity

file permission/acl: 2 users with write access on 1 file...

Hello, i need some help/advice on how to solve a particular problem. these are the users: |name | group | ---------- --------------- |boss | department1 | |assistant | department1 | |employee | department1 | |spy | department2 | this is the... (0 Replies)
Discussion started by: elzalem
0 Replies

7. UNIX for Dummies Questions & Answers

File Permission

Hi, When I listed one directory in Sun, it showed that : -rwsr-xr-x 1 root bsmbin 78004 Oct 21 2004 bsmprsm I don't know meaning of the character "s" in "rws" above. I have searched in Sun admin documents but no result. Would you please explain it ? :) Thank you so much. (1 Reply)
Discussion started by: msg098
1 Replies

8. Solaris

File permission

Hi Folks I have a file with the following permission. -r-sr-lr-- 1 apps appsgp 7612 Dec 19 2001 startup Any idea what is the in the group means? In my mind I believe I need to be root to set l in the group. Am I right? I don't have root access now. When I (as apps) a chmod... (2 Replies)
Discussion started by: hlee411
2 Replies

9. Shell Programming and Scripting

The file permission

there is a directory eg. /home/edp/ , all the files under this directory : 1. the file and directory owner is "user1" , 2. the permission is 644 I want everyone hv permission to overwrite all files and write a new file to it , but I want the file owner and permssion keep unchange , could... (1 Reply)
Discussion started by: ust
1 Replies

10. UNIX for Dummies Questions & Answers

The file permission

I have a file ( /tmp/file.txt ) , the file owner is user1:edp , the permission is 644 , I want everyone can overwrite the file but don't change the file owner and permssion , could suggest what can I do ? thx (2 Replies)
Discussion started by: ust
2 Replies
Login or Register to Ask a Question