The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Customer has SFTP access to all directories on server

Discussion in 'General Discussion' started by vecdeal, Apr 27, 2011.

  1. vecdeal

    vecdeal Registered

    Joined:
    Apr 27, 2011
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    I've got a clean WHM installation on a clean VPS (provided by Memset). I've added a couple of customer accounts, eg. mysite.com. When I SFTP to mysite.com, using the customer's username/password, I land in /home/mysite, and as expected cannot see /home/anyothersites.

    However, from /home/mysite, I can navigate upwards to /home, and then to /, and then on to all the other folders on the VPS - and can read and write files anywhere. Surely I shouldn't be allowed to do this...? Is this normal for a default installation? How do I stop it?

    Thanks.
     
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,482
    Likes Received:
    203
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    You may be able to see files but you should not have permission to write to them.
     
Loading...

Share This Page