搭建ftp服务器
11:首先,更新软件源,保证源是最新的,这样有利于下面在线通过apt-get install命令安装ftp。 22:使用sudo apt-get install vsftp命令安装vsftp,安装软件需要root权限,我们使用sudo来暂时获取。 33:安装好ftp后默认是会自动创建ftp用户的,然后我们设置ftp用户的密码,输入 44:sudo passwd ftp,然后输入密码,再确认密码。 5 为 ftp用户创建的目录 默认为/srv/ftp 65:对/etc/vsftpd.conf配置文件进行一定的修改。使用 sudo gedit /etc/vsftpd.conf打开配置文件。 7将配置文件中”anonymous_enable=YES (是否允许匿名ftp,若不允许选NO) 8 9取消如下配置前的注释符号: 10 11local_enable=YES(是否允许本地用户登录) 27行附近: #本地用户,liyafei ,密码 12 13write_enable=YES(是否允许本地用户写的权限) 29行附近: 14 15chroot_local_user=YES(是否将所有用户限制在主目录) 121行附近: 16 17chroot_list_enable=YES(是否启动限制用户的名单) 18 19chroot_list_file=/etc/vsftpd.chroot_list(可在文件中设置多个账号) 20 21/*********************** /etc/vsftpd.conf ***************************/ 22 23# the user does not have write access to the top level directory within the 24 25# chroot) 26 27chroot_local_user=YES 28 29chroot_list_enable=YES 30 31# (default follows) 32 33chroot_list_file=/etc/vsftpd.chroot_list 34 35#chroot_list_file=/etc/chroot_list 36 37然后重启ftp服务,使用命令sudo service vsftpd restart重启ftp服务浏览器通过ftp://192.168.100.91访问成功该目录成功 38 39 40成功 41 42https://jingyan.baidu.com/article/a948d6512ef9d00a2dcd2ea3.html
通过filezilla进行上传文件
home目录下可以创建很多用户目录。对/etc/vsftpd.conf进行如下配置
1userlist_deny=NO 2userlist_file=/etc/allowed_users 3seccomp_sandbox=NO 4local_root=/home/ftp
那么在/etc/allowed_users中的用户就可以通过用户名和密码登录到服务器访问/home/ftp
/etc/allowed_users 文件内容
user1 user2
那么 user1,user2 用户和 本地用户 就可以访问/home/ftp中的内容.
一般哪一个使用哪一个用户名,就访问哪一个用户的主目录,在home目录下面会为每一个用户创建一个目录。
浏览器默认使用ftp用户,访问srv/ftp目录下的内容。就算其它用户在浏览器登录了,也不行。除非将/srv/ftp 目录删除。
用filezilla客户端对文件进行上传,因为/home/ftp中的文件夹都没有写权限,所以进行上传时提示: 553 Could not create file
我们需要在/home/ftp文件夹下创建一个具有写权限的文件夹 ,例如创建文件夹write;
1首先在ftp的目录中创建一个目录,然后设置权限为777 2$ sudo mkdir /home/ftp/write 3$ sudo chmod -R 777 /home/ftp/write 4然后修改vsftp的配置文件/etc/vsftpd.conf文件 5在最后添加上 6local_root=/home/ftp #这是allowed_users 文件夹中的用户访问的路径,上面的配置文件,已经添加过 7保存,然后杀死vsftpd进程,然后重启vsftpd服务器程序。 8试试看,将文件上传到write目录,这个时候可以正常的上传文件了。
一定要将创建的目录权限修改为可写w,否则提示错误;
1响应: 227 Entering Passive Mode (192,168,100,91,84,116). 2命令: STOR 网站设计.docx 3响应: 553 Could not create file. 4错误: 严重文件传输错误
这时就可以向/home/ftp/write 文件夹中上传文件。
如果以user3用户登录,user3用户的目录又在/home/user3 下面,那么使用java客户端上传文件时,路径是从/home/user3开始的。不再加前面的/home/user3
bashPath=/home/usre3就可以省去。
// if (!ftp.changeWorkingDirectory(basePath+filePath)) { if (!ftp.changeWorkingDirectory(filePath)) {
同样,我们也可以在/srv/ftp文件夹中创建 具有写权限的文件夹,供用户名为ftp的用户 进行添加文件。
当想要加载其中的文件时,需要将文件目录所有者root改为使用的用户。 chown -hR liyafei:liyafei ./liyafei
总结:用户名ftp的用户访问/srv/ftp文件夹
本地用户和allowed_users中的用户访问指定的local_root文件夹
如果需要上传功能,需要在文件夹下创建具有写功能的文件夹
在html页面下载ftp服务器内容,通过在连接中指定用户名和密码,和与用户名密码对应的文件位置就可以下载。
例如:下载uftp用户下的/home/ftp/public/file/vsftpd.conf 文件 。uftp用户对应的根目录为/home/ftp,如下所示
1<!DOCTYPE html> 2<html lang="en"> 3<head> 4 <meta charset="UTF-8"> 5 <title>Title</title> 6</head> 7<body> 8直接使用一个超链接: ftp://用户名:密码@ip:端口号/该用户下面的目录,省去 local_root 目录。 9<a href='ftp://uftp:1367356@192.168.100.91:21/public/file/vsftpd.conf' download="vsftpd"> 点击FTP下载 </a> 10</body> 11</html>
配置文件:
1# Example config file /etc/vsftpd.conf 2# 3 4# The default compiled in settings are fairly paranoid. This sample file 5# loosens things up a bit, to make the ftp daemon more usable. 6# Please see vsftpd.conf.5 for all compiled in defaults. 7# 8# READ THIS: This example file is NOT an exhaustive list of vsftpd options. 9# Please read the vsftpd.conf.5 manual page to get a full idea of vsftpd's 10# capabilities. 11# 12# 13# Run standalone? vsftpd can run either from an inetd or as a standalone 14# daemon started from an initscript. 15listen=YES 16# 17# Run standalone with IPv6? 18# Like the listen parameter, except vsftpd will listen on an IPv6 socket 19# instead of an IPv4 one. This parameter and the listen parameter are mutually 20# exclusive. 21#listen_ipv6=YES 22# 23# Allow anonymous FTP? (Disabled by default) 24anonymous_enable=YES 25# 26# Uncomment this to allow local users to log in. 27local_enable=YES 28# 29# Uncomment this to enable any form of FTP write command. 30#write_enable=YES 31write_enable=YES 32# 33# Default umask for local users is 077. You may wish to change this to 022, 34# if your users expect that (022 is used by most other ftpd's) 35#local_umask=022 36# 37# Uncomment this to allow the anonymous FTP user to upload files. This only 38# has an effect if the above global write enable is activated. Also, you will 39# obviously need to create a directory writable by the FTP user. 40anon_upload_enable=YES 41# 42# Uncomment this if you want the anonymous FTP user to be able to create 43# new directories. 44anon_mkdir_write_enable=YES 45# 46anon_other_write_enable=YES 47# Activate directory messages - messages given to remote users when they 48# go into a certain directory. 49dirmessage_enable=YES 50# 51# If enabled, vsftpd will display directory listings with the time 52# in your local time zone. The default is to display GMT. The 53# times returned by the MDTM FTP command are also affected by this 54# option. 55use_localtime=YES 56# 57# Activate logging of uploads/downloads. 58xferlog_enable=YES 59# 60# Make sure PORT transfer connections originate from port 20 (ftp-data). 61connect_from_port_20=YES 62# 63# If you want, you can arrange for uploaded anonymous files to be owned by 64# a different user. Note! Using "root" for uploaded files is not 65# recommended! 66# 67#chown_uploads=YES 68#chown_username=whoever 69# 70# You may override where the log file goes if you like. The default is shown 71# below. 72#xferlog_file=/var/log/vsftpd.log 73# 74# If you want, you can have your log file in standard ftpd xferlog format. 75# Note that the default log file location is /var/log/xferlog in this case. 76#xferlog_std_format=YES 77# 78# You may change the default value for timing out an idle session. 79#idle_session_timeout=600 80# 81# You may change the default value for timing out a data connection. 82#data_connection_timeout=120 83# 84# It is recommended that you define on your system a unique user which the 85# ftp server can use as a totally isolated and unprivileged user. 86#nopriv_user=ftpsecure 87# 88# Enable this and the server will recognise asynchronous ABOR requests. Not 89# recommended for security (the code is non-trivial). Not enabling it, 90# however, may confuse older FTP clients. 91#async_abor_enable=YES 92# 93# By default the server will pretend to allow ASCII mode but in fact ignore 94# the request. Turn on the below options to have the server actually do ASCII 95# mangling on files when in ASCII mode. 96# Beware that on some FTP servers, ASCII support allows a denial of service 97# attack (DoS) via the command "SIZE /big/file" in ASCII mode. vsftpd 98# predicted this attack and has always been safe, reporting the size of the 99# raw file. 100# ASCII mangling is a horrible feature of the protocol. 101#ascii_upload_enable=YES 102#ascii_download_enable=YES 103# 104# You may fully customise the login banner string: 105#ftpd_banner=Welcome to blah FTP service. 106# 107# You may specify a file of disallowed anonymous e-mail addresses. Apparently 108# useful for combatting certain DoS attacks. 109#deny_email_enable=YES 110# (default follows) 111#banned_email_file=/etc/vsftpd.banned_emails 112# 113# You may restrict local users to their home directories. See the FAQ for 114# the possible risks in this before using chroot_local_user or 115# chroot_list_enable below. 116#chroot_local_user=YES 117# 118# You may specify an explicit list of local users to chroot() to their home 119# directory. If chroot_local_user is YES, then this list becomes a list of 120# users to NOT chroot(). 121# (Warning! chroot'ing can be very dangerous. If using chroot, make sure that 122# the user does not have write access to the top level directory within the 123# chroot) 124chroot_local_user=YES 125chroot_list_enable=NO 126# (default follows) 127chroot_list_file=/etc/vsftpd.chroot_list 128# 129# You may activate the "-R" option to the builtin ls. This is disabled by 130# default to avoid remote users being able to cause excessive I/O on large 131# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume 132# the presence of the "-R" option, so there is a strong case for enabling it. 133#ls_recurse_enable=YES 134# 135# Customization 136# 137# Some of vsftpd's settings don't fit the filesystem layout by 138# default. 139# 140# This option should be the name of a directory which is empty. Also, the 141# directory should not be writable by the ftp user. This directory is used 142# as a secure chroot() jail at times vsftpd does not require filesystem 143# access. 144secure_chroot_dir=/var/run/vsftpd/empty 145# 146# This string is the name of the PAM service vsftpd will use. 147pam_service_name=vsftpd 148# 149# This option specifies the location of the RSA certificate to use for SSL 150# encrypted connections. 151rsa_cert_file=/etc/ssl/certs/ssl-cert-snakeoil.pem 152# This option specifies the location of the RSA key to use for SSL 153# encrypted connections. 154rsa_private_key_file=/etc/ssl/private/ssl-cert-snakeoil.key 155userlist_deny=NO 156userlist_file=/etc/allowed_users 157seccomp_sandbox=NO 158#pasv_enable=YES 159#pasv_min_port=3000 160#pasv_max_port=4000 161local_root=/home/ftp