ºìÁªLinuxÃÅ»§
Linux°ïÖú

APACHEÓû§ÊÚȨºÍ·ÃÎÊ¿ØÖÆ

·¢²¼Ê±¼ä:2006-11-08 01:09:20À´Ô´:ºìÁª×÷Õß:Emperor
Óû§ÊÚȨºÍ·ÃÎÊ¿ØÖÆ

ÄãÒ²ÐíÔÚ·ÃÎÊÄ³Ð©ÍøÕ¾Ê±»áÓöµ½¹ýÕâÑùµÄÇé¿ö£¬µ±Äãµã»÷ij¸öÁ¬½Óʱ£¬ÄãµÄä¯ÀÀÆ÷»áµ¯³öÒ»¸öÉí·ÝÑéÖ¤µÄ¶Ô»°¿ò£¬ÒªÇóÊäÈëÕ˺ż°ÃÜÂ룬Èç¹ûûÓУ¬¾ÍÎÞ·¨¼ÌÐøä¯ÀÀÁË¡£ÓÐÈË»áÒÔΪÕâÊÇÓÃCGI×ö³öÀ´µÄ£¬Æäʵ²»È»£¬ÕâÊÇWWW·þÎñÆ÷µÄÓû§ÊÚȨºÍ·ÃÎÊ¿ØÖÆ»úÖÆÔÚ·¢»Ó×÷Óá£
ÄãÊÇ·ñ»¹¼ÇµÃÔÚÉèÖÃApache·þÎñ»·¾³µÄ¹ý³ÌÖУ¬ÓС­¡­..<./Directory>Õâ¸öÖ¸Á¿ÉÒÔ¶Ô²»Í¬µÄĿ¼Ìṩ²»Í¬µÄ±£»¤¡£µ«ÊÇÕâÑùµÄÉ趨£¬ÐèÒªÖØÐÂÆô¶¯·þÎñÆ÷²Å»áÉúЧ£¬Áé»îÐԽϲͨ¹ýAccessFileÖ¸ÁîÖ¸¶¨·ÃÎÊ¿ØÖÆÎļþµÄ·½Ê½Ôò±È½ÏÁé»î£¬ÔÚApache·þÎñÆ÷ÖÐÉèÖÃÓû§µÄ·ÃÎÊ¿ØÖÆÈ¨ÏÞ²½ÖèÈçÏ£º

1¡¢Ê×ÏȶÔhttpd.confÎļþ½øÐÐÉèÖÃÈçÏ£º


# AllowOverride FileInfo AuthConfig Limit
# Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec
Options Includes FollowSymLinks Indexes
AllowOverride All //*×¢ÒâAllowOverride Ò»¶¨ÒªÉèÖÃΪAll£¬ÕâÑùºóÃæµÄ.htaccessÎļþ²Å»áÆð×÷ÓÃ

Order allow,deny
Allow from all

#
# Order deny,allow
# Deny from all
#


#Ö¸¶¨ÅäÖôæÈ¡¿ØÖÆÈ¨ÏÞµÄÎļþÃû³Æ
AccessFileName .htaccess

2¡¢´´½¨.htaccessÎļþ?ÈÝ

Òª¿ØÖÆÄ³Ä¿Â¼µÄ·ÃÎÊȨÏÞ±ØÐ뽨Á¢Ò»·ÃÎÊ¿ØÖÆÎļþ£¬ÎļþÃûÇ°ÃæÖ¸¶¨µÄ¡°.htaccess¡±£¬ÆäÄÚÈݸñʽÈçÏ£º

AuthUserFile Óû§ÕʺÅÃÜÂëÎļþÃû
AuthGroupFile Ⱥ×éÕʺÅÃÜÂëÎļþÃû
AuthName »­ÃæÌáʾÎÄ×Ö
AuthType ÑéÖ¤·½Ê½

ÃÜÂëÑéÖ¤·½Ê½

Óû§ÑéÖ¤·½Ê½AuthTypeĿǰÌṩÁËBasicºÍDigestÁ½ÖÖ¡£
ÃÜÂë¼ìÑéÉ趨·½·¨Óëhttpd.confÖеÄÏà¹ØÉ趨Ïàͬ¡£
¾ßÌåÀý×ÓÈçÏ£º
AuthUserFile /etc/secure.user
AuthName °²È«ÈÏÖ¤ÖÐÐÄ
AuthType Basic

require valid-user


3¡¢½¨Á¢Óû§ÃÜÂëÎļþ

Èç¹ûÄãÊǵÚÒ»´Î´´½¨Óû§ÃÜÂ룬ÃüÁî¸ñʽÈçÏ£º
htpasswd -c ÃÜÂëÎļþÃû Óû§Ãû³Æ
ÔÚÉÏÃæµÄÀý×ÓÖУ¬ÎÒÃǽ«Óû§ÃÜÂëÎļþ·Åµ½ÁË/etc/secure.userÎļþÖУ¬ËùÒÔÕâÀïÓ¦°´ÕÕÈçϽøÐвÙ×÷£º
htpasswd -c /etc/secure.user sword
³ÌÐò»áÌáʾÄãÊäÈëÁ½´ÎÓû§µÄ¿ÚÁȻºóÓû§ÃÜÂëÎļþ¾ÍÒѾ­´´½¨swordÕâ¸öÓû§Ò²Ìí¼ÓÍê±ÏÁË¡£
Èç¹ûÒªÏòÃÜÂëÎļþÖÐÌí¼ÓеÄÓû§£¬°´ÕÕÈçÏÂÃüÁî¸ñʽ½øÐвÙ×÷£º
htpasswd ÃÜÂëÎļþ Óû§Ãû³Æ
ÕâÑù£¬ÖØÐÂÆô¶¯httpdºó£¬½øÐиÃWEBĿ¼ʱ¾Í»áÓÐÒ»¸ö¶Ô»°¿òµ¯³ö£¬ÒªÇóÊäÈëÓû§Ãû¼°Óû§¿ÚÁîÁË¡£

4¡¢ÈçºÎ¼õÉÙ·ÃÎÊ¿ØÖƶÔApacheÐÔÄܵÄÓ°Ïì
Ƶ·±µÄʹÓ÷ÃÎÊ¿ØÖÆ»á¶ÔApacheµÄÐÔÄܲúÉú½Ï´óµÄÓ°Ï죬ÄÇô£¬ÈçºÎ²ÅÄܼõÉÙÕâÖÖÓ°ÏìÄØ£¿×î¼òµ¥Ò²ÊÇ×îÓÐЧµÄ·½·¨Ö®Ò»¾ÍÊǼõÉÙ.htaccessÎļþµÄÊýÄ¿£¬ÕâÑù¿ÉÒÔ±ÜÃâApache¶Ôÿһ¸öÇëÇó¶¼Òª°´ÕÕ.htaccessÎļþµÄÄÚÈݽøÐÐÊÚȨ¼ì²é¡£Ëü²»½öÔÚµ±Ç°µÄĿ¼ÖвéÕÒ.htaccessÎļþ£¬Ëü»¹»áÔÚµ±Ç°Ä¿Â¼µÄ¸¸Ä¿Â¼ÖвéÕÒ¡£

/
/usr
/usr/local
/usr/local/etc
/usr/local/etc/httpd
/usr/local/etc/httpd/htdocs
/usr/local/etc/httpd/htdocs/docs
ͨ³£ÔÚ¸ùĿ¼ÏÂûÓÐhtaccessÎļþ£¬µ«ApacheÈÔÈ»»á½øÐÐÀýÐмì²éÒÔÈ·¶¨¸ÃÎļþȷʵ²»´æÔÚ¡£ÕâÊÇÓ°ÏìºÜÓ°Ïì·þÎñÆ÷¹¤×÷ЧÂʵÄÊÂÇé¡£ÏÂÃæµÄ·½·¨¿ÉÒÔÏû³ýÕâ¸öÌÖÑáµÄ¹ý³Ì£º½«AllowOverrideÑ¡ÉèÖÃΪNone£¬ÕâÑùApache¾Í»á¼ì²é.htaccessÎļþÁË¡£½«/¸ùĿ¼µÄ AllowOverrideÑ¡ÏîÉèΪNone£¬Ö»½«ÐèÒª½øÐзÃÎÊ¿ØÖƵÄĿ¼ÏµÄAllowOverrideÑ¡ÏîÉèÖÃΪall£¬ÈçÏÂÃæµÄÀý×ÓÖн«/¸ùĿ¼µÄ AllowOverride Ñ¡Ïî¹Ø±ÕÁË£¬Ö»´ò¿ªÁË/usr/local/etc/httpd/htdocsĿ¼ÏµÄAllowOerrideÑ¡ÏÕâÑù£¬ÏµÍ³¾ÍÖ»ÔÚ /usr/local/etc/httpd/htdocsÖмì²é.htaccessÎļþ£¬´ïµ½µÄÌá¸ß·þÎñЧÂʵÄÄ¿µÄ¡£


AllowOverride None



AllowOverride All



Èç¹û³ýÁ˸ùĿ¼ÒÔÍ⣬»¹ÓÐÆäËü´æ·ÅWWWÎļþµÄĿ¼£¬ÄãÒ²¿ÉÒÔ²ÉȡͬÑùµÄ·½·¨½øÐÐÉèÖᣱÈÈ磺Èç¹ûÄãʹÓÃUserDirÀ´ÔÊÐíÓû§·ÃÎÊ×Ô¼ºµÄĿ¼£¬AllowOverrideµÄÉèÖÃÈçÏ£º

AllowOverride FileInfo Indexes IncludesNOEXEC


5¡¢·ÀÖ¹Óû§·ÃÎÊÖ¸¶¨µÄÎļþ
ϵͳÖÐÓÐһЩÎļþÊDz»ÊÊÒËÌṩ¸øWWWÓû§µÄ£¬È磺.htaccess¡¢htpasswd¡¢*.plµÈ£¬¿ÉÒÔÓôﵽÕâ¸öÄ¿µÄ£º

order allow,deny
deny from all

Óû§·ÃÎÊ¿ØÖÆÈý¸ö.htaccessÎļþ¡¢.htpasswdºÍ.htgroup£¨ÓÃÓÚÓû§ÊÚȨ£© £¬ÎªÁ˰²È«Æð¼û£¬Ó¦¸Ã·ÀÖ¹Óû§ä¯ÀÀÆäÖÐÄÚÈÝ£¬¿ÉÒÔÔÚhttpd.confÖмÓÈëÒÔÏÂÄÚÈÝ×èÖ¹Óû§¶ÔÆä½øÐзÃÎÊ£º

Order deny, allow
Deny from all

ÕâÑùÕâÈý¸öÎļþ¾Í²»»á±»Óû§·ÃÎÊÁË¡£

6¡¢ÏÞÖÆÄ³Ð©Óû§·ÃÎÊÌØ¶¨Îļþ
¿ÉÒÔ¶ÔĿ¼½øÐÐÔ¼Êø£¬ÒªÏÞÖÆÄ³Ð©Óû§¶Ôij¸öÌØ¶¨ÎļþµÄ·ÃÎÊ¿ÉÒÔʹÓ㬱ÈÈ磺²»ÔÊÐí·Çdomain.comÓòÄÚµÄÓû§¶Ô/prices/internal.html½øÐзÃÎÊ£¬¿ÉÒÔÓÃÈçϵÄÉèÖãº


order deny,allow
deny from all
allow from .domain.com

Èç¹ûÄãÒªÊÚÓÚÏàӦȨÏ޵ĻúÆ÷ûÓй«¿ªµÄÓòÃû£¬ÇëÔÚÄãµÄ/etc/hostsÎļþÖУ¬½«ÆäIPµØÖ·Ó³É䵽ij¸öÖ¸¶¨µÄÃû³Æ£¬È»ºóÔÚLocationÖÐ¶ÔÆä½øÐÐÉèÖ㬷ñÔò¸ÃÑ¡ÏîÊDz»Æð×÷Óõġ£

7¡¢Ö»½ÓÊÜÀ´×ÔÌØ¶¨Á´½ÓµÄ·ÃÎÊ
ÀýÈ磬ֻÈÃËùÓÐÀ´×Ô http://www.sina.com.cn/* µÄÁ´½ÓµÄÓû§½øÈë´ËĿ¼£¬ÓÉÆäËüÁ´½ÓÀ´µÄ·Ã¿Í¶¼²»µÃ½øÈ룻 " * "±íʾ´ËÍøÕ¾µ×ÏÂËùÓеÄÁ´½Ó¡£ÆäÖÐµÄ http://www.sina.com.cn/* Ò²¿ÉÒÔÊÇ£ºhttp://202.106.184.200/* »òÊÇÖ¸¶¨Îļþ http://www.sina.com.cn/news.html
.htaccessÎļþµÄÄÚÈÝÈçÏ£º
AuthUserFile /dev/null
AuthGroupFile /dev/null
AuthName ExampleAllowFromSpecificURL
AuthType Basic

order deny,allow
deny from all
referer allow from http://www.sina.com.cn/*
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0 ÌõÆÀÂÛ