You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows服务器网站无Root权限(仅FTP)简易文件夹密码保护咨询

Windows服务器FTP权限下的简易目录密码保护方案(无Root权限)

根据你的需求(仅FTP访问、单用户密码保护、无需复杂系统),可以根据服务器的Web环境选择以下方案:

方案1:IIS环境(主流Windows服务器配置)

方式A:自定义Forms认证(无需服务器本地用户)

这种方式不需要在服务器上创建用户,仅通过上传2个文件即可实现:

  1. 创建并上传web.config到目标目录:
<?xml version="1.0"?>
<configuration>
  <system.web>
    <authentication mode="Forms">
      <forms loginUrl="login.aspx" name=".ASPXFORMSAUTH">
        <credentials passwordFormat="SHA1">
          <!-- 替换为你的用户名和SHA1加密后的密码 -->
          <user name="myuser" password="5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8" />
        </credentials>
      </forms>
    </authentication>
    <authorization>
      <deny users="?" /> <!-- 拒绝匿名访问 -->
      <allow users="myuser" /> <!-- 仅允许指定用户访问 -->
    </authorization>
  </system.web>
</configuration>
  • 生成SHA1密码:本地用PowerShell执行[System.Web.Security.FormsAuthentication]::HashPasswordForStoringInConfigFile("你的明文密码", "SHA1")即可得到加密字符串。
  1. 创建并上传login.aspx到同一目录:
<%@ Page Language="C#" %>
<!DOCTYPE html>
<html>
<head>
    <title>登录验证</title>
</head>
<body>
    <form method="post" action="login.aspx">
        用户名: <input type="text" name="username" /><br/>
        密码: <input type="password" name="password" /><br/>
        <input type="submit" value="登录" />
    </form>
    <% if (IsPostBack) {
        string inputUser = Request.Form["username"];
        string inputPwd = Request.Form["password"];
        if (System.Web.Security.FormsAuthentication.Authenticate(inputUser, inputPwd)) {
            System.Web.Security.FormsAuthentication.RedirectFromLoginPage(inputUser, false);
        } else {
            Response.Write("<p>用户名或密码错误</p>");
        }
    } %>
</body>
</html>

上传后,访问目标目录会自动跳转到登录页,验证通过后才能访问内容。

方式B:IIS基本认证(需服务器允许)

如果服务器已开启基本认证,且你能使用服务器上已存在的用户(无需创建新用户),可以上传web.config:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <system.webServer>
    <security>
      <authentication>
        <anonymousAuthentication enabled="false" />
        <basicAuthentication enabled="true" />
      </authentication>
      <authorization>
        <add accessType="Allow" users="已存在的用户名" />
        <add accessType="Deny" users="*" />
      </authorization>
    </security>
  </system.webServer>
</configuration>

方案2:Apache for Windows环境

和Linux环境完全一致,直接上传.htaccess和.htpasswd文件:

  1. 创建.htaccess文件:
AuthType Basic
AuthName "受保护区域"
# 替换为服务器上.htpasswd的绝对路径(可通过FTP查看目录路径)
AuthUserFile "C:/inetpub/wwwroot/your-folder/.htpasswd"
Require valid-user
  1. 创建.htpasswd文件:
    本地用Apache自带的htpasswd.exe生成(如XAMPP的bin/htpasswd.exe),命令为:
htpasswd -c .htpasswd 你的用户名

按提示输入密码后,将生成的.htpasswd文件上传到指定路径即可。

内容的提问来源于stack exchange,提问作者Xeddon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 10:25:29