How can I disable some commands in SFTP?SFTP logging: is there a way?Where can I find logs for SFTP?Passwordless sftp upload commands not executed using a shell scriptHow to disable sftp for some users, but keep ssh enabled?Allow SFTP but disallow SSH?SSH - cannot start sftp-server when trying to force internal sftpDisable chmod in openssh-serverhow to create sftp accountHow to disable sftp access to user with ssh already disabled (user shell = /bin/false, but connection still works with sftp)How can I disable sftp temporarily without reloading the service?

Mysterious procedure calls without parameters - but no exceptions generated

Beginner looking to learn/master musical theory and instrumental ability. Where should I begin?

Did this character show any indication of wanting to rule before S8E6?

Why A=2 and B=1 in the call signs for Spirit and Opportunity?

Popcorn is the only acceptable snack to consume while watching a movie

Take elements from a list based on two criteria

What is the meaning of "<&3" and "done < file11 3< file22"

What Armor Optimization applies to a Mithral full plate?

The art of clickbait captions

Why didn't Thanos use the Time Stone to stop the Avengers' plan?

Of strange atmospheres - the survivable but unbreathable

What did the 'turbo' button actually do?

Is it truly impossible to tell what a CPU is doing?

Why do Russians almost not use verbs of possession akin to "have"?

Why does this if statement return true

How can I make an argument that my time is valuable?

Best material to absorb as much light as possible

How do I superimpose two math symbols?

Python program to take in two strings and print the larger string

Shorten or merge multiple lines of `&> /dev/null &`

Why are GND pads often only connected by four traces?

Why haven't we yet tried accelerating a space station with people inside to a near light speed?

What was the idiom for something that we take without a doubt?

What is the use case for non-breathable waterproof pants?



How can I disable some commands in SFTP?


SFTP logging: is there a way?Where can I find logs for SFTP?Passwordless sftp upload commands not executed using a shell scriptHow to disable sftp for some users, but keep ssh enabled?Allow SFTP but disallow SSH?SSH - cannot start sftp-server when trying to force internal sftpDisable chmod in openssh-serverhow to create sftp accountHow to disable sftp access to user with ssh already disabled (user shell = /bin/false, but connection still works with sftp)How can I disable sftp temporarily without reloading the service?






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








2















How can I disable some commands in SFTP for my clients, like ln & symlink?



I've checked man sftp, but didn't find what I'm searching for.










share|improve this question






















  • This doesn't make much sense. Why do you want to do this?

    – Michael Hampton
    Mar 4 '17 at 3:32











  • As Michael Hampton said, this doesn't make sense. The only thing I can think to do is disallow access to those commands with Linux ACLs from the users that log onto your server via SFTP and/or, depending if you're running SFTP in a chroot jail, the specific user that is running SFTP.

    – cerberus
    Mar 4 '17 at 4:15

















2















How can I disable some commands in SFTP for my clients, like ln & symlink?



I've checked man sftp, but didn't find what I'm searching for.










share|improve this question






















  • This doesn't make much sense. Why do you want to do this?

    – Michael Hampton
    Mar 4 '17 at 3:32











  • As Michael Hampton said, this doesn't make sense. The only thing I can think to do is disallow access to those commands with Linux ACLs from the users that log onto your server via SFTP and/or, depending if you're running SFTP in a chroot jail, the specific user that is running SFTP.

    – cerberus
    Mar 4 '17 at 4:15













2












2








2


1






How can I disable some commands in SFTP for my clients, like ln & symlink?



I've checked man sftp, but didn't find what I'm searching for.










share|improve this question














How can I disable some commands in SFTP for my clients, like ln & symlink?



I've checked man sftp, but didn't find what I'm searching for.







sftp






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Mar 4 '17 at 3:25









user134969user134969

1851313




1851313












  • This doesn't make much sense. Why do you want to do this?

    – Michael Hampton
    Mar 4 '17 at 3:32











  • As Michael Hampton said, this doesn't make sense. The only thing I can think to do is disallow access to those commands with Linux ACLs from the users that log onto your server via SFTP and/or, depending if you're running SFTP in a chroot jail, the specific user that is running SFTP.

    – cerberus
    Mar 4 '17 at 4:15

















  • This doesn't make much sense. Why do you want to do this?

    – Michael Hampton
    Mar 4 '17 at 3:32











  • As Michael Hampton said, this doesn't make sense. The only thing I can think to do is disallow access to those commands with Linux ACLs from the users that log onto your server via SFTP and/or, depending if you're running SFTP in a chroot jail, the specific user that is running SFTP.

    – cerberus
    Mar 4 '17 at 4:15
















This doesn't make much sense. Why do you want to do this?

– Michael Hampton
Mar 4 '17 at 3:32





This doesn't make much sense. Why do you want to do this?

– Michael Hampton
Mar 4 '17 at 3:32













As Michael Hampton said, this doesn't make sense. The only thing I can think to do is disallow access to those commands with Linux ACLs from the users that log onto your server via SFTP and/or, depending if you're running SFTP in a chroot jail, the specific user that is running SFTP.

– cerberus
Mar 4 '17 at 4:15





As Michael Hampton said, this doesn't make sense. The only thing I can think to do is disallow access to those commands with Linux ACLs from the users that log onto your server via SFTP and/or, depending if you're running SFTP in a chroot jail, the specific user that is running SFTP.

– cerberus
Mar 4 '17 at 4:15










2 Answers
2






active

oldest

votes


















5














You did not specify, what SFTP server are you using. I'm assuming the OpenSSH.



The sftp-server (and the compatible internal-sftp) has the -P and -p switches to black/white list certain SFTP requests.



You can use them to disallow the symlink requests:



Subsystem sftp internal-sftp -P symlink





share|improve this answer

























  • I've tried this, but it doesn't work.

    – user134969
    Mar 4 '17 at 21:21






  • 2





    What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

    – Martin Prikryl
    Mar 5 '17 at 6:44











  • Doesn't work a specific user as it is not usable in a Match block

    – Erdal G.
    Aug 24 '17 at 12:44











  • @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

    – Martin Prikryl
    Aug 24 '17 at 12:49


















0














You can only pass args to the sftp command when using ForceCommand, not Subsystem. If you do what the other answer says, the -P arg will be silently ignored!



The correct way:



Subsystem sftp internal-sftp

ForceCommand internal-sftp -P symlink


(you possibly also want to put a Match block around the second line)






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f836212%2fhow-can-i-disable-some-commands-in-sftp%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    2 Answers
    2






    active

    oldest

    votes








    2 Answers
    2






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    5














    You did not specify, what SFTP server are you using. I'm assuming the OpenSSH.



    The sftp-server (and the compatible internal-sftp) has the -P and -p switches to black/white list certain SFTP requests.



    You can use them to disallow the symlink requests:



    Subsystem sftp internal-sftp -P symlink





    share|improve this answer

























    • I've tried this, but it doesn't work.

      – user134969
      Mar 4 '17 at 21:21






    • 2





      What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

      – Martin Prikryl
      Mar 5 '17 at 6:44











    • Doesn't work a specific user as it is not usable in a Match block

      – Erdal G.
      Aug 24 '17 at 12:44











    • @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

      – Martin Prikryl
      Aug 24 '17 at 12:49















    5














    You did not specify, what SFTP server are you using. I'm assuming the OpenSSH.



    The sftp-server (and the compatible internal-sftp) has the -P and -p switches to black/white list certain SFTP requests.



    You can use them to disallow the symlink requests:



    Subsystem sftp internal-sftp -P symlink





    share|improve this answer

























    • I've tried this, but it doesn't work.

      – user134969
      Mar 4 '17 at 21:21






    • 2





      What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

      – Martin Prikryl
      Mar 5 '17 at 6:44











    • Doesn't work a specific user as it is not usable in a Match block

      – Erdal G.
      Aug 24 '17 at 12:44











    • @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

      – Martin Prikryl
      Aug 24 '17 at 12:49













    5












    5








    5







    You did not specify, what SFTP server are you using. I'm assuming the OpenSSH.



    The sftp-server (and the compatible internal-sftp) has the -P and -p switches to black/white list certain SFTP requests.



    You can use them to disallow the symlink requests:



    Subsystem sftp internal-sftp -P symlink





    share|improve this answer















    You did not specify, what SFTP server are you using. I'm assuming the OpenSSH.



    The sftp-server (and the compatible internal-sftp) has the -P and -p switches to black/white list certain SFTP requests.



    You can use them to disallow the symlink requests:



    Subsystem sftp internal-sftp -P symlink






    share|improve this answer














    share|improve this answer



    share|improve this answer








    edited Sep 12 '17 at 15:52

























    answered Mar 4 '17 at 6:30









    Martin PrikrylMartin Prikryl

    5,3642660




    5,3642660












    • I've tried this, but it doesn't work.

      – user134969
      Mar 4 '17 at 21:21






    • 2





      What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

      – Martin Prikryl
      Mar 5 '17 at 6:44











    • Doesn't work a specific user as it is not usable in a Match block

      – Erdal G.
      Aug 24 '17 at 12:44











    • @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

      – Martin Prikryl
      Aug 24 '17 at 12:49

















    • I've tried this, but it doesn't work.

      – user134969
      Mar 4 '17 at 21:21






    • 2





      What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

      – Martin Prikryl
      Mar 5 '17 at 6:44











    • Doesn't work a specific user as it is not usable in a Match block

      – Erdal G.
      Aug 24 '17 at 12:44











    • @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

      – Martin Prikryl
      Aug 24 '17 at 12:49
















    I've tried this, but it doesn't work.

    – user134969
    Mar 4 '17 at 21:21





    I've tried this, but it doesn't work.

    – user134969
    Mar 4 '17 at 21:21




    2




    2





    What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

    – Martin Prikryl
    Mar 5 '17 at 6:44





    What did you try? What does not work? What does it do instead? What version of OpenSSH are you using?

    – Martin Prikryl
    Mar 5 '17 at 6:44













    Doesn't work a specific user as it is not usable in a Match block

    – Erdal G.
    Aug 24 '17 at 12:44





    Doesn't work a specific user as it is not usable in a Match block

    – Erdal G.
    Aug 24 '17 at 12:44













    @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

    – Martin Prikryl
    Aug 24 '17 at 12:49





    @ErdalG. You are right. I've removed that part. You can use ForceCommand though (but that would disallow shell access, what you actually want to do anyway probably, if you want to limit what user can do).

    – Martin Prikryl
    Aug 24 '17 at 12:49













    0














    You can only pass args to the sftp command when using ForceCommand, not Subsystem. If you do what the other answer says, the -P arg will be silently ignored!



    The correct way:



    Subsystem sftp internal-sftp

    ForceCommand internal-sftp -P symlink


    (you possibly also want to put a Match block around the second line)






    share|improve this answer





























      0














      You can only pass args to the sftp command when using ForceCommand, not Subsystem. If you do what the other answer says, the -P arg will be silently ignored!



      The correct way:



      Subsystem sftp internal-sftp

      ForceCommand internal-sftp -P symlink


      (you possibly also want to put a Match block around the second line)






      share|improve this answer



























        0












        0








        0







        You can only pass args to the sftp command when using ForceCommand, not Subsystem. If you do what the other answer says, the -P arg will be silently ignored!



        The correct way:



        Subsystem sftp internal-sftp

        ForceCommand internal-sftp -P symlink


        (you possibly also want to put a Match block around the second line)






        share|improve this answer















        You can only pass args to the sftp command when using ForceCommand, not Subsystem. If you do what the other answer says, the -P arg will be silently ignored!



        The correct way:



        Subsystem sftp internal-sftp

        ForceCommand internal-sftp -P symlink


        (you possibly also want to put a Match block around the second line)







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited May 11 at 0:12









        womble

        86.3k18147205




        86.3k18147205










        answered May 10 at 23:32









        ruforufo

        312




        312



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f836212%2fhow-can-i-disable-some-commands-in-sftp%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            Popular posts from this blog

            Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

            Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

            Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020