rob@xxxxxxxxx said the following on 2/21/2005 7:59 AM:
Tom,

Two area's of concern. QIBM_QTMF_SVR_LOGON Will be where you set initial directory.
QIBM_QTMF_SERVER_REQ will be where you make sure that they do not go to another directory. Beware of a patch I need to make to my version, (as pointed out on this list). If you lock them down to a directory /ftp/customer123/upload/*, the hack would be /ftp/customer123/upload/../../customer456/upload
It was suggested that I actually do the CD and then just check the resultant directory against what directory was intended.


Rob Berendt

1- SRV_LOGON is the one that I seem to be having trouble with; I can't get it to plop the user into the specified directory. I must be processing the Application Specific DS incorrectly; check this link for more on that:


http://archive.midrange.com/midrange-l/200502/msg00914.html


2- SERVER_REQ: I've had it in place for a couple of years. In that program I process a db of "allowed commands" specific to each user, and it's worked well mainly because our FTP access has been very restrictive. But that approach won't work for "Tech Support", because that group needs to do whatever they want within the home directory, but only within that directory (or its subdirectories). I'll work on this little gem once I get the 'homedir' issue(s) resolved.


Tom


As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.