Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

SFTP can access everything

General questions about VestaCP
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
ZipperZapper
Posts: 13
Joined: Fri Feb 06, 2015 11:37 am

SFTP can access everything
  • Quote

Post by ZipperZapper » Mon Aug 10, 2015 9:22 am

Is it just me, or is it extremely dangerous to use SFTP with VestaCP?

I found out SFTP is enabled for everybody by default, also when the SSH-access is set to 'nologin' in the user settings. Fine, I think vsftpd is handling this? Looked good for me, SFTP is much more secure than FTP and I would love it if users could use it.

Quickly I found out it's not possible to open the directories of other users at the server, so that's a good thing too. But now comes my point:

Every user is able to go all the way up in the tree, is able to open for example /etc and can see, download and open ALL files in there. So every single user is able to look at all configuration-files for the sever.

This sounds dangerous to me. Why is it users can't access files from other users, but are able to just open every single other document at the server. Is there a way to work around this?
Top

tjebbeke
Collaborator
Posts: 783
Joined: Mon May 11, 2015 8:43 am
Contact:
Contact tjebbeke
Website

Os: CentOS 6x
Web: apache + nginx
Re: SFTP can access everything
  • Quote

Post by tjebbeke » Mon Aug 10, 2015 11:12 am

You can try this: http://superuser.com/a/370955
Top

ZipperZapper
Posts: 13
Joined: Fri Feb 06, 2015 11:37 am

Re: SFTP can access everything
  • Quote

Post by ZipperZapper » Mon Aug 10, 2015 2:34 pm

Code: Select all

chroot_local_user=YES
That one is enabled by default by Vesta, but doesn't seem to work as described in your link. It's indeed true I can't access the stuff other users own, but I can access all other files on the server. That just seems odd to me.
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: SFTP can access everything
  • Quote

Post by skurudo » Mon Aug 10, 2015 4:55 pm

Yep, there is no jails for this yet (it's planned). But there is no bug, but, sadly, sshd thing.

viewtopic.php?f=10&t=7231&p=22959&hilit=sftp#p22959
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

Login  •  Register

I forgot my password