No it cannot be disabled.
I am not wanting to argue security with you. I am asking if the Open Terminal option can be disabled in any way. The vendor needs shell access.
So what's the point then, if the vendor can run commands anyway?
Unfortunately the vendor needs to ssh into the system to run commands also.
Disable a shell access to your server for vendor accounts.
We are wanting to use winscp on a jumpbox for vendord access to our *Nix systems. The one issue we have is winscp allowing remote commands to be run. Our session logging software captures file transfers and commands in the same stream. It becomes very difficult to find arbitrary commands within a giant binary log.
Is there a way to disable Open Terminal in winscp?