查看完整版本: phpweb程序windows系统的目录权限设置

幸福在右 2019-8-2 11:01

phpweb程序windows系统的目录权限设置

<p>在设置安全权限之前要在phpweb后台对网站做好升级</p>
<div><span style="background-color: rgb(255, 153, 0);">登录后台--设置--软件升级更新:</span></div>
<div><br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 204, 0);">再设置下phpweb的会员权限,如果不设置会引起网站被发帖机不停的发垃圾文章,使得网站很卡</span></div>
<div><span style="background-color: rgb(255, 204, 0);">如果不关闭会员上传图像和上传图片/附件的权限会引起网站被入侵挂马:</span></div>
<div><br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 204, 0);">取消会员的相关权限:</span></div>
<div><br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 0, 0);"><span style="color: rgb(255, 255, 0);"><strong><span style="font-size: 14px;">下面是网站安全设置详细教程(防挂马、防入侵):</span></strong></span></span></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 255, 0);"><span style="font-size: 14px;">1、首先关闭全站的写入权限</span></span></div>
<div>有2种方法操作,一种是直接在我们空间管理平台,主机管理中, 设置写入权限--关闭此网站的写入权限</div>
<div>另外一种方法是远程登录服务器里设置权限,我们这里详细介绍远程登录服务器设置网站的写入权限</div>
<div>关闭全站写入权限是为了让有漏洞或注入点的网站不能被上传网马或修改网站源代码(挂马或挂黑友链等):</div>
<div><span style="background-color: rgb(255, 255, 0);">A、在WIN2003种的设置方法:</span></div>
<div><br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 255, 0);">B、在WIN2008-WIN2012中设置方法:</span></div>
<div><br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 255, 0);"><span style="font-size: 14px;">2、再单独打开如下目录的写入权限</span></span></div>
<div>因为这些目录是附件目录,不单独打开写入权限,网站就无法上传产品图片和附件或修改模板:</div>
<div>/advs/pics/</div>
<div>/base/pics/</div>
<div>/comment/pics/</div>
<div>/diy/pics/</div>
<div>/effect/pics/</div>
<div>/feedback/pics/</div>
<div>/index/pics/</div>
<div>/job/pics/</div>
<div>/member/pics/</div>
<div>/menu/pics/</div>
<div>/news/pics/</div>
<div>/page/pics/</div>
<div>/photo/pics/</div>
<div>/product/pics/</div>
<div>/search/pics/</div>
<div>/shop/pics/</div>
<div>/tools/pics/</div>
<div>因为是三级目录只能远程登服务器进行设置,不能通过空间管理平台里设置</div>
<div><span style="background-color: rgb(0, 255, 0);">下面教程中只演示了一个目录的<span style="background-color: rgb(255, 0, 0);">写入</span>权限设置,其他目录类同</span></div>
<div><span style="background-color: rgb(255, 255, 0);">A、在WIN2003中设置方法:</span></div>
<div>&nbsp;<br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 255, 0);">B、在WIN2008-WIN2012中设置方法:</span></div>
<div>&nbsp;<br></div>
<div>&nbsp;</div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 255, 0);"><span style="font-size: 14px;">3、然后关闭如下目录的执行权限</span></span></div>
<div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/advs/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/base/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/comment/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/diy/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/effect/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/feedback/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/index/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/job/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/member/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/menu/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/news/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/page/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/photo/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/product/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/search/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/shop/pics/</div>
<div style="padding: 0px; margin: 0px; color: rgb(73, 73, 73); font-family: verdana, arial, helvetica, sans-serif, 宋体;">/tools/pics/</div>
</div>
<div>关闭执行权限后这些目录就无法运行asp/php/net等代码</div>
<div>因为上面对这些附件目录开了写入权限,如果网站有漏洞会被上传网马进这些目录</div>
<div>关闭了这些目录的执行权限后,就算上传了网马也是没办法运行,网站也就不会被黑</div>
<div>设置网站目录的执行权限是在IIS中设置</div>
<div><span style="background-color: rgb(0, 255, 0);">下面教程中只演示了一个目录的<span style="background-color: rgb(255, 0, 0);">执行</span>权限设置,其他目录类同</span></div>
<div><span style="background-color: rgb(255, 255, 0);">A、在WIN2003的IIS6中设置方法:</span></div>
<div>&nbsp;<br></div>
<div>&nbsp;</div>
<div><span style="background-color: rgb(255, 255, 0);">B、在WIN2008-WIN2012中的IIS7-IIS8种设置方法:</span></div>
<div>&nbsp;<br></div>
<div>&nbsp;</div>
<div><br></div>
<div>&nbsp;</div>
<div>&nbsp;以上教程请参考。</div>
页: [1]
查看完整版本: phpweb程序windows系统的目录权限设置