能否创建仅可操作指定文件夹的FTP用户用于WordPress备份
Restricting an FTP Account to Specific Backup Folder Operations (Download & Delete Only)
Absolutely doable, and it’s a smart security practice to limit your FTP account’s access to only the operations it needs. Here’s a step-by-step breakdown to set this up:
1. Lock Down the FTP User to a Chroot Jail
First, you’ll need to configure your FTP server to restrict the user to your WordPress backup folder exclusively:
- Create a dedicated FTP user (e.g.,
wp_backup_agent) — avoid using your main site admin or system user for this. - Set this user’s home directory directly to your WordPress backup folder (e.g.,
/var/www/your-wp-site/wp-content/backups/). - Enable chroot jail in your FTP server config (works with vsftpd, ProFTPD, etc.). This prevents the user from navigating outside the backup folder entirely.
2. Assign Precise File/Folder Permissions
Next, fine-tune permissions so the user can only download new backups and delete old ones:
- For the backup folder itself: Grant the user read, write, and execute permissions (this lets them enter the folder and delete files). Use this command if you’re using ACLs for granular control:
setfacl -m u:wp_backup_agent:rwx /var/www/your-wp-site/wp-content/backups/ - For existing and future backup files: Restrict the user to read-only access (so they can download but not modify files). Run this to apply it to current files:
If your backup plugin generates new files automatically, set a default ACL to apply this permission to future backups:setfacl -m u:wp_backup_agent:r-- /var/www/your-wp-site/wp-content/backups/*setfacl -d -m u:wp_backup_agent:r-- /var/www/your-wp-site/wp-content/backups/
3. Validate Plugin & FTP Account Behavior
- In your WordPress backup plugin’s settings, make sure it’s configured to use this dedicated FTP account (not the server’s local file system permissions). Some plugins default to direct file access, so double-check this to ensure the plugin relies on the FTP user’s restricted permissions.
- Test the workflow thoroughly:
- Generate a new backup and confirm the FTP user can download it.
- Try deleting an old backup and verify the operation succeeds.
- Attempt to navigate to other WordPress directories (like
wp-content/uploads/or the site root) to confirm the chroot jail blocks access.
4. Bonus Security Upgrades
- Switch to SFTP: FTP transmits credentials and data in plaintext, so use SFTP (SSH File Transfer Protocol) instead. The permission and chroot logic applies the same way, but everything is encrypted.
- Use SSH key authentication for SFTP instead of passwords to eliminate brute-force risks.
- Regularly check your FTP/SFTP server logs for any unexpected access attempts.
内容的提问来源于stack exchange,提问作者SM Web Dev
相关产品推荐
相关产品推荐

