Apache HTTP Server£¬×÷Ϊ»¥ÁªÍøÉÏ×îÁ÷ÐÐµÄ Web ·þÎñÆ÷Èí¼þÖ®Ò»£¬³ÐÔØ×ÅÎÞÊýÍøÕ¾ºÍ·þÎñ
È»¶ø£¬Apache µÄÇ¿´ó¹¦ÄÜÒ²°éËæ×ÅDZÔڵݲȫ·çÏÕ£¬ÓÈÆäÊǵ±ÅäÖò»µ±»òȨÏÞÉèÖò»ºÏÀíʱ
±¾ÎĽ«ÉîÈë̽ÌÖ Linux »·¾³Ï Apache µÄȨÏÞ¹ÜÀí£¬Ö¼ÔÚ°ïÖúϵͳ¹ÜÀíÔ±¹¹½¨°²È«¸ßЧµÄ Web ·þÎñÆ÷»·¾³
Ò»¡¢Àí½â Linux ÎļþȨÏÞϵͳ ÔÚÉîÈë̽ÌÖ Apache ȨÏÞ֮ǰ£¬ÎÒÃÇÊ×ÏÈÐèÒªÀí½â Linux ϵͳµÄ»ù±¾ÎļþȨÏÞÄ£ÐÍ
Linux ʹÓÃÒ»ÖÖ»ùÓÚÓû§£¨User£©¡¢×飨Group£©ºÍÆäËûÈË£¨Others£©µÄȨÏÞÄ£ÐÍÀ´¿ØÖƶÔÎļþºÍĿ¼µÄ·ÃÎÊ
ÿ¸öÎļþ»òĿ¼¶¼ÓÐÈý¸ö»ù±¾µÄȨÏÞÀà±ð£º¶Á£¨Read, r£©¡¢Ð´£¨Write, w£©ºÍÖ´ÐУ¨Execute, x£©
¶ÁȨÏÞ£ºÔÊÐí²é¿´ÎļþÄÚÈÝ»òÁгöĿ¼ÄÚÈÝ
- дȨÏÞ£ºÔÊÐíÐÞ¸ÄÎļþÄÚÈÝ»ò´´½¨/ɾ³ý/ÖØÃüÃûĿ¼ÖеÄÎļþ
Ö´ÐÐȨÏÞ£ºÔÊÐíÖ´ÐÐÎļþ»ò½øÈëĿ¼
ͨ¹ý `ls -l` ÃüÁî¿ÉÒԲ鿴Îļþ»òĿ¼µÄÏêϸȨÏÞÐÅÏ¢£¬ÀýÈç `-rwxr-xr--` ±íʾÕâÊÇÒ»¸ö¿ÉÖ´ÐÐÎļþ£¬ËùÓÐÕßÓµÓжÁдִÐÐȨÏÞ£¬Í¬×éÓû§ÓµÓжÁÖ´ÐÐȨÏÞ£¬¶øÆäËûÓû§½öÓжÁȨÏÞ
¶þ¡¢Apache ·þÎñÆ÷µÄÔËÐÐÓû§Óë×é Apache ͨ³£²»»áÒÔ root Óû§Éí·ÝÔËÐУ¬ÕâÊdzöÓÚ°²È«¿¼ÂÇ
ÔÚ´ó¶àÊý Linux ·¢ÐаæÉÏ£¬Apache ĬÈÏÒÔ`apache`£¨»ò `httpd`¡¢`www-data` µÈ£¬È¡¾öÓÚ¾ßÌå·¢Ðа棩Óû§Éí·ÝÔËÐÐ
Õâ¸öÓû§Í¨³£±»·ÖÅäÁËÒ»¸öµÍȨÏÞµÄÕË»§£¬ÏÞÖÆÁËÆä¶Ôϵͳ¹Ø¼ü×ÊÔ´µÄ·ÃÎÊ
- ÔËÐÐÓû§£ºApache ·þÎñ½ø³ÌÔËÐÐʱµÄϵͳÓû§
- ÔËÐÐ×飺Óë¸ÃÓû§¹ØÁªµÄ×飬ÓÃÓÚ¿ØÖÆÎļþ·ÃÎÊȨÏÞ
Èý¡¢ºÏÀíÉèÖà Apache Ŀ¼ºÍÎļþȨÏÞ 1.Web ¸ùĿ¼ȨÏÞ Web ¸ùĿ¼£¨Èç`/var/www/html`£©ÊÇ´æ·ÅÍøÕ¾ÎļþµÄµØ·½
ΪÁ˰²È«Æð¼û£¬Õâ¸öĿ¼ӦÉèÖÃΪ½öÔÊÐí Apache Óû§¶ÁÈ¡ºÍÖ´ÐУ¨Èç¹ûÊÇĿ¼£©£¬µ«²»ÔÊÐíдÈë
ͨ³££¬Web ¸ùĿ¼µÄȨÏÞÉèÖÃΪ`755`£¨rwxr-xr-x£©£¬Òâζ×ÅËùÓÐÕß¿ÉÒÔ¶ÁдִÐУ¬×éÓû§ºÍÆäËûÓû§Ö»ÄܶÁÈ¡ºÍÖ´ÐÐ
bash chmod 755 /var/www/html chown -R apache:apache /var/www/html ÕâÀ`chown` ÃüÁîÓÃÓÚ¸ü¸ÄĿ¼µÄËùÓÐÕߺÍ×éΪ Apache ÔËÐÐÓû§ºÍ×é
2.ÍøÕ¾ÎļþȨÏÞ ÍøÕ¾Öеľ²Ì¬Îļþ£¨Èç HTML¡¢CSS¡¢JS¡¢Í¼Æ¬µÈ£©Ó¦ÉèÖÃΪ½öÔÊÐí¶ÁÈ¡£¨644 »ò 444£©
`644` ÔÊÐíËùÓÐÕß¶Áд£¬×éÓû§ºÍÆäËûÓû§¶ÁÈ¡£»¶ø `444` Ôò¸üΪÑϸñ£¬½öÔÊÐíËùÓÐÈ˶ÁÈ¡
bash find /var/www/html -type f -exec chmod 644{} ; ¶ÔÓÚÃô¸ÐÎļþ£¬ÈçÅäÖÃÎļþ»òÈÕÖ¾Îļþ£¬Ó¦¸ü¼ÓÑϸñµØÏÞÖÆ·ÃÎÊȨÏÞ
ÀýÈ磬ÅäÖÃÎļþ¿ÉÒÔÉèÖÃΪ `600`£¨rw-------£©£¬½öÔÊÐíËùÓÐÕß¶ÁÈ¡ºÍдÈë
3.Ŀ¼ÉÏ´«È¨ÏÞ Èç¹ûÍøÕ¾ÐèÒªÓû§ÉÏ´«Îļþ£¨Èçͨ¹ý WordPress ¹ÜÀíºǫ́£©£¬ÄÇôÉÏ´«Ä¿Â¼ÐèÒªÊʵ±µÄдȨÏÞ
ͨ³££¬Õâ¸öĿ¼»áÉèÖÃΪ`755` »ò`775`£¨rwxrwxr-x£©£¬ÔÊÐíËùÓÐÕß¡¢×éÓû§Ð´È룬¶øÆäËûÓû§½ö¶ÁÈ¡ºÍÖ´ÐУ¨×¢Ò⣺`775` ¿ÉÄÜ»á´øÀ´°²È«·çÏÕ£¬Ðè½÷É÷ʹÓã©
bash chmod 755 /var/www/html/wp-content/uploads chmod g+s /var/www/html/wp-content ÉèÖà SGID£¬È·±£ÐÂÎļþ¼Ì³Ð×éȨÏÞ ÕâÀ`chmod g+s` ÃüÁîÉèÖÃÁË¡°Set Group ID¡±£¨SGID£©Î»£¬È·±£ÔÚ¸ÃĿ¼Ï´´½¨µÄÐÂÎļþºÍĿ¼¼Ì³Ð¸¸Ä¿Â¼µÄ×éȨÏÞ
ËÄ¡¢SELinux »ò AppArmor Ç¿»¯°²È« ³ýÁË»ù±¾µÄÎļþϵͳȨÏÞ£¬Linux »¹ÌṩÁË SELinux£¨Security-Enhanced Linux£©ºÍ AppArmor ÕâÑùµÄÇ¿ÖÆ·ÃÎÊ¿ØÖÆÏµÍ³£¬½øÒ»²½Ï¸»¯¶Ô Apache ½ø³ÌµÄȨÏÞ¿ØÖÆ
- SELinux£ºÍ¨¹ý²ßÂÔÎļþ¶¨Òå½ø³Ì¡¢ÎļþºÍ¶Ë¿ÚÖ®¼äµÄ·ÃÎʹæÔò£¬¿ÉÒÔ¼«´óµØ¼õÉÙDZÔڵĹ¥»÷Ãæ
- AppArmor£ºÓë SELinux ÀàËÆ£¬µ«