Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Registered User
    Join Date
    Feb 2010
    Posts
    3

    Default Some issues regarding SFTP

    Hi there,

    I've encoutered some issues when trying to use SFTP on a cPanel server.

    Since FTP is an old and insecure protocol is would like to use SFTP.

    The problem with SFTP is that an user can see system directorys and files when the user does an cd and ll or ls when in the root directory.
    Shell acces is turned of for the users, so they can't do any shell commands.

    I want to jail users who log on through sftp to their home directory.

    Has anybody else encoutered the same problems and found a good way to solve this issue while keeping things integrated with cPanel?

    I found some fixes on the net, but they involved adding users manualy to gain ftp access, i'm looking for a solution with integration in cPanel.

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2006
    Location
    Virginia Beach, VA
    Posts
    254
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    You might want to use FTP over Passive TLS instead of SFTP. That way you don't have to open port 22 or SSH access for your users, and their connections will still be secured via SSL certificate. You can set up an SSL in WHM > Service SSL Certificates

  3. #3
    Registered User
    Join Date
    Feb 2010
    Posts
    3

    Default

    Yeah, that is also an option. But i would prefer jailed SFTP.

    One of the reasons for sftp usage is the recent virusses that seem to be capable to nest themself in ftp software.

  4. #4
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,710
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by Alrik View Post
    Yeah, that is also an option. But i would prefer jailed SFTP.

    One of the reasons for sftp usage is the recent virusses that seem to be capable to nest themself in ftp software.
    But wouldn't customers just use the same software they're using now for SFTP? Many FTP clients that support FTPS also support SFTP.

    If you are concerned about spyware sniffing unencrypted traffic, you could use ProFTPd and configure it (via WHM) to only accept encrypted (FTPS) connections.

  5. #5
    Member
    Join Date
    Aug 2002
    Posts
    1,118

    Default

    I don't really see how FTP, SFTP, FTP over explict TLS, etc. really makes any difference in regards to these spyware/trojans/malware.

    I am assuming users are storing their password in the FTP application's site manager. Which if that is the case, why does it matter how the password is passed to the FTP server? The compromise has already been made. The compromise is through the FTP application and storing the FTP password.

    Maybe I'm missing something, but I've never really understood how passing the password in an encrypted manner is going to help with this.

    If a user has a malicious piece of software running on their computer, they need to be taking steps to remove the software.

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Sep 2006
    Location
    Virginia Beach, VA
    Posts
    254
    cPanel/Enkompass Access Level

    Root Administrator

  7. #7
    Member
    Join Date
    Jan 2003
    Location
    Jacksonville, FL
    Posts
    28

    Default

    Quote Originally Posted by Alrik View Post
    Hi there,

    The problem with SFTP is that an user can see system directorys and files when the user does an cd and ll or ls when in the root directory.
    Shell acces is turned of for the users, so they can't do any shell commands.
    I need to see if this will work in cPanel but on Plesk, I modify the shells permitted.

    With SFTP, you can set up an SFTP only shell. While users can still browse around to other directories it does limit shell access.

    Also will need to check the docs to see if the jail shell programs can be modified to work with SFTP.

  8. #8
    Registered User
    Join Date
    Feb 2010
    Posts
    3

    Default

    Quote Originally Posted by rackaid View Post
    I need to see if this will work in cPanel but on Plesk, I modify the shells permitted.

    With SFTP, you can set up an SFTP only shell. While users can still browse around to other directories it does limit shell access.

    Also will need to check the docs to see if the jail shell programs can be modified to work with SFTP.
    The only problem right now is showing all directories, users can't execute shell commands.
    SFTP would be perfect if an user only could see their home dir and nothing else.

    @everybody pointing out the malware issue:
    Yeah, if an users sw is compromised it does not really matter wich protocol is used. On the other hand, if only the data transmited is sniffed, then a secure protocol would improve security a lot. Let's say it would be a improvement in security not a complete solution.

  9. #9
    EWD
    EWD is offline
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Aug 2003
    Location
    NY
    Posts
    164

    Default

    Quote Originally Posted by Alrik View Post
    The only problem right now is showing all directories, users can't execute shell commands.
    SFTP would be perfect if an user only could see their home dir and nothing else.

    @everybody pointing out the malware issue:
    Yeah, if an users sw is compromised it does not really matter wich protocol is used. On the other hand, if only the data transmited is sniffed, then a secure protocol would improve security a lot. Let's say it would be a improvement in security not a complete solution.
    I have complained about this and it seems no one at cpanel seems to think it is an issue.
    Emerson

  10. #10
    Member
    Join Date
    Dec 2009
    Posts
    16

    Default rssh

    Quote Originally Posted by Alrik View Post
    Yeah, that is also an option. But i would prefer jailed SFTP.

    One of the reasons for sftp usage is the recent virusses that seem to be capable to nest themself in ftp software.
    Check out rssh. It has exactly what you need. It's a jailed shell that you can configure to support only SCP/SFTP (and a few others like rsync if you want) as well as create a chroot jail.

    Some assembly required.

Similar Threads & Tags
Similar threads

  1. SFTP Logging
    By BMR777 in forum New User Questions
    Replies: 4
    Last Post: 02-02-2011, 06:29 AM
  2. Can I allow SFTP without Shell?
    By BraveX in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-23-2009, 01:32 PM
  3. JailShell for SFTP?
    By yeahoi in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-27-2008, 09:44 AM
  4. Sftp
    By seby in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-01-2007, 03:21 AM
  5. FTP vs SFTP
    By BraveX in forum New User Questions
    Replies: 3
    Last Post: 05-24-2007, 12:02 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube