Windows服务器网站无Root权限(仅FTP)简易文件夹密码保护咨询
Windows服务器FTP权限下的简易目录密码保护方案(无Root权限)
根据你的需求(仅FTP访问、单用户密码保护、无需复杂系统),可以根据服务器的Web环境选择以下方案:
方案1:IIS环境(主流Windows服务器配置)
方式A:自定义Forms认证(无需服务器本地用户)
这种方式不需要在服务器上创建用户,仅通过上传2个文件即可实现:
- 创建并上传
web.config到目标目录:
<?xml version="1.0"?> <configuration> <system.web> <authentication mode="Forms"> <forms loginUrl="login.aspx" name=".ASPXFORMSAUTH"> <credentials passwordFormat="SHA1"> <!-- 替换为你的用户名和SHA1加密后的密码 --> <user name="myuser" password="5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8" /> </credentials> </forms> </authentication> <authorization> <deny users="?" /> <!-- 拒绝匿名访问 --> <allow users="myuser" /> <!-- 仅允许指定用户访问 --> </authorization> </system.web> </configuration>
- 生成SHA1密码:本地用PowerShell执行
[System.Web.Security.FormsAuthentication]::HashPasswordForStoringInConfigFile("你的明文密码", "SHA1")即可得到加密字符串。
- 创建并上传
login.aspx到同一目录:
<%@ Page Language="C#" %> <!DOCTYPE html> <html> <head> <title>登录验证</title> </head> <body> <form method="post" action="login.aspx"> 用户名: <input type="text" name="username" /><br/> 密码: <input type="password" name="password" /><br/> <input type="submit" value="登录" /> </form> <% if (IsPostBack) { string inputUser = Request.Form["username"]; string inputPwd = Request.Form["password"]; if (System.Web.Security.FormsAuthentication.Authenticate(inputUser, inputPwd)) { System.Web.Security.FormsAuthentication.RedirectFromLoginPage(inputUser, false); } else { Response.Write("<p>用户名或密码错误</p>"); } } %> </body> </html>
上传后,访问目标目录会自动跳转到登录页,验证通过后才能访问内容。
方式B:IIS基本认证(需服务器允许)
如果服务器已开启基本认证,且你能使用服务器上已存在的用户(无需创建新用户),可以上传web.config:
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <security> <authentication> <anonymousAuthentication enabled="false" /> <basicAuthentication enabled="true" /> </authentication> <authorization> <add accessType="Allow" users="已存在的用户名" /> <add accessType="Deny" users="*" /> </authorization> </security> </system.webServer> </configuration>
方案2:Apache for Windows环境
和Linux环境完全一致,直接上传.htaccess和.htpasswd文件:
- 创建
.htaccess文件:
AuthType Basic AuthName "受保护区域" # 替换为服务器上.htpasswd的绝对路径(可通过FTP查看目录路径) AuthUserFile "C:/inetpub/wwwroot/your-folder/.htpasswd" Require valid-user
- 创建
.htpasswd文件:
本地用Apache自带的htpasswd.exe生成(如XAMPP的bin/htpasswd.exe),命令为:
htpasswd -c .htpasswd 你的用户名
按提示输入密码后,将生成的.htpasswd文件上传到指定路径即可。
内容的提问来源于stack exchange,提问作者Xeddon
相关产品推荐
相关产品推荐

