【问题标题】:How to avoid Navigation of folders through URL manipulation如何避免通过 URL 操作导航文件夹
【发布时间】:2012-05-09 16:56:24
【问题描述】:

我的网站需要您的帮助(测试阶段)。 我有一个这种性质的文件系统...

     www (root)  
  {

           school { //main project folder

                  images //images folder

                  uploads //user uploads folder 

                  JavaScripts //JS folder

                  CSS // css folder

                 includes //includes folder

             index.php

            contactus.php

            aboutus.php

            register.php

           } //main project folder
  } //www folder               

当用户执行以下操作时,如何防止用户浏览我的文件夹系统:

 http://127.0.0.1/school/css
 http://127.0.0.1/school/images
 http://127.0.0.1/school/includes
 http://127.0.0.1/school/uploads
 http://127.0.0.1/school/javascripts

感谢您的帮助....

【问题讨论】:

  • 通常默认情况下不允许直接列出目录。当您尝试直接访问文件夹时看到了什么?
  • @truth 我运行 Apache (WAMP)。当我通过 URL 查看这些文件夹时,我会看到文件夹的索引,即所有脚本或所有图像或 CSS 文件或 Javascripts...文件夹的所有内容

标签: php url directory root


【解决方案1】:

您还可以在每个文件夹中放置一个名为 index.php 或 index.html 的空 php 或 html 文件。 用户将无法浏览这些目录。

【讨论】:

    【解决方案2】:

    See the following article on how to disable direct directory browsing

    具体来说,在您的 .htaccess 文件中搜索 Options Indexes。如果不存在,则将以下行添加到您的 .htaccess 中:

    Options -Indexes
    

    目录浏览应该不可用。

    更多方法可以在上面的文章中找到。

    【讨论】:

      【解决方案3】:

      创建一个 .htaccess 文件到您不想通过 url 输入导航的目录..

      在文件里面,放这一行:

      Deny from all
      

      仅此而已..享受..

      出于安全目的,请改用以下行:

      Options -Indexes
      

      【讨论】:

        猜你喜欢
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 1970-01-01
        • 2016-09-23
        • 2019-02-06
        • 1970-01-01
        相关资源
        最近更新 更多