I have an account on debian named 'usera'. 'usera' has a home directory of /home/whatever
When I log in to WinSCP using 'usera' and its credentials - I am able to go "up" one directory into /home and then eventually into '/'. I specifically made this account to restrict access to this home directory as the credentials are shared.
Note: This directory is also used as web root for an apache2 virtual host, but 'usera' is in the 'www-data' group, so I don't think that apache has anything to do with this problem.
Any suggestions?