You might be interested in how to limit users to nologin shell coupled with subsystem access:
https://news.ycombinator.com/item?id=3527754
I found this[1] one while looking around, the thread has some additional interesting remarks, including an LD_PRELOAD attack vector.
[1]: https://news.ycombinator.com/item?id=3550944
You might be interested in how to limit users to nologin shell coupled with subsystem access:
https://news.ycombinator.com/item?id=3527754