delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2008/12/02/03:23:18

X-Recipient: archive-cygwin AT delorie DOT com
X-Spam-Check-By: sourceware.org
References: <664060 DOT 6380 DOT qm AT web34704 DOT mail DOT mud DOT yahoo DOT com> <49341625 DOT 2090804 AT cygwin DOT com> <933558 DOT 98400 DOT qm AT web34705 DOT mail DOT mud DOT yahoo DOT com> <4934527E DOT 2070200 AT cygwin DOT com>
Date: Tue, 2 Dec 2008 00:22:17 -0800 (PST)
From: TheO <idgajelas AT yahoo DOT com>
Subject: Re: Finally managed to create a jailed SFTP server, but how secure?
To: cygwin AT cygwin DOT com
MIME-Version: 1.0
Message-ID: <961872.64997.qm@web34701.mail.mud.yahoo.com>
X-IsSubscribed: yes
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

> 

> If you're happy with the results, that's fine.  However, you asked how
> secure SFTP was.  The answer is as I've said.  Cygwin is not the O/S.
> It cannot enforce restrictions on the O/S.  Only the O/S can restrict
> or grant access to users.
> 

Thanks Larry,

The reason why Cygwin is ideal for me to provide SFTP service is that it
provides a free SFTP solution for Windows platform. My programmers come
from Windows world, they are more familiar with .NET than Unix but sometimes,
they are required to build a system featuring an SFTP server where our user
can upload his files to be processed by our .NET application and finally,
he download the response files from SFTP. Cygwin makes this possible in an
economic way.

> 
> I have not attempted to set up a jailed SFTP environment on Cygwin.  It
> may be that what you've done hems the user into the area you want when
> he/she is using Cygwin tools.  However, this does not restrict the user
> with Windows native tools.  If he/she is able to leverage those inside
> the jail, then the user has the keys he/she wants to get out.
> 

He might be able to upload "nasty" tools but What else could he possibly do 
if he has access to only a restricted SFTP subsystem? 


      

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019