[scponly] tilde allowed from ALLOWABLE ... worst case scenario ?

Ensel Sharon user at dhp.com
Wed Jun 28 17:57:14 EDT 2006


So I need to allow the tilde ~ character because some folks have filenames
with them (!)

The obvious method is to just add ~ to ALLOWABLE in scponly.h ...

How bad of an idea (if bad at all) is this ?  What is the worst thing that
could happen, security-wise ?

I am running my users with the chroot binary, scponlyc, and their home
directories are traversable by them only so they can traverse through to
their incoming dir ... so, I wouldn't think ~ gives them anything that
they didn't have before.  They still can't read/write in the ~
directory...

All comments appreciated, even far out scary ones...




More information about the scponly mailing list