<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>meisw's blog</title>
		<link>http://meisw.wdlinux.cn//</link>
		<description>工作,学习,生活,这里将会有一些记录.     备用域名:http://meisw.wdlinux.cn</description>
		<copyright>Copyright (C) 2004 Security Angel Team [S4T] All Rights Reserved.</copyright>
		<generator>SaBlog-X Version 1.6 Build 20080806</generator>
		<lastBuildDate>Sun, 20 Sep 2026 23:57:19 +0000</lastBuildDate>
		<ttl>30</ttl>
		<item>
			<guid>http://meisw.wdlinux.cn//show-934-1.html</guid>
			<title>pure-ftpd.conf</title>
			<author>admin</author>
			<description><![CDATA[<p><span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">ChrootEveryone &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 启用chroot</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">BrokenClientsCompatibility &nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 兼容不同客户端</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">Daemonize &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 后台运行</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">MaxClientsPerIP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;20&nbsp; &nbsp; &nbsp;&nbsp;# 每个ip最大连接数</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">VerboseLog &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 记录日志</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">DisplayDotFiles &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no&nbsp; &nbsp; &nbsp;&nbsp;# 显示隐藏文件</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AnonymousOnly &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 只允许匿名用户访问</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">NoAnonymous &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no&nbsp; &nbsp; &nbsp;&nbsp;# 运行匿名用户连接</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">SyslogFacility &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;none&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;# 不将日志在syslog日志中显示</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">DontResolve &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 不进行客户端DNS解析</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">MaxIdleTime &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;15&nbsp; &nbsp; &nbsp;&nbsp;# 最大空闲时间</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">LimitRecursion &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;2000&nbsp;8&nbsp; &nbsp; &nbsp;&nbsp;# 浏览限制，文件2000，目录8层</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AnonymousCanCreateDirs &nbsp; &nbsp; &nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 匿名用户可以创建目录</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">MaxLoad &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;4&nbsp;&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;# 超出负载后禁止下载</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">PassivePortRange &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;45000&nbsp;50000&nbsp;# 被动模式端口范围</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AnonymousRatio &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;1&nbsp;10&nbsp; &nbsp; &nbsp; &nbsp;&nbsp;# 匿名用户上传/下载比率</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AntiWarez &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 禁止下载匿名用户上传但未经验证的文件</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AnonymousBandwidth &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;200&nbsp;&nbsp; &nbsp;&nbsp;# 匿名用户带宽限制（KB）</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">Umask &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;133:022 &nbsp; &nbsp;&nbsp;# 创建文件/目录默认掩码</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">MinUID &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;100&nbsp;&nbsp; &nbsp;&nbsp;# 最大UID限制</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AllowUserFXP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;no&nbsp; &nbsp; &nbsp;&nbsp;# 仅运行用户进行FXP传输</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AllowAnonymousFXP &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no&nbsp; &nbsp; &nbsp;&nbsp;# 对匿名用户和非匿名用户允许进行匿名 FXP 传输</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">ProhibitDotFilesWrite &nbsp; &nbsp; &nbsp; no&nbsp; &nbsp; &nbsp;&nbsp;# 不能删除/写入隐藏文件</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">ProhibitDotFilesRead &nbsp; &nbsp; &nbsp; &nbsp;no&nbsp; &nbsp; &nbsp;&nbsp;# 禁止读取隐藏文件</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AutoRename &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 有同名文件时自动重新命名</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AnonymousCantUpload &nbsp; &nbsp; &nbsp; &nbsp; no&nbsp; &nbsp; &nbsp;&nbsp;# 不允许匿名用户上传文件</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">AltLog &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;clf:/var/log/pureftpd.log &nbsp;&nbsp;# clf格式日志文件位置</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">MaxDiskUsage &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;99&nbsp; &nbsp; &nbsp;&nbsp;# 当磁盘使用量打到99%时禁止上传</span><br style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);" />
<span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);">CustomerProof &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;yes&nbsp;&nbsp; &nbsp;&nbsp;# 防止命令误操作</span></p>
<p><span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);"><br />
</span></p>
<p><span style="color: rgb(85, 85, 85); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px; background-color: rgb(244, 245, 247);"><br />
</span></p>
<p><strong style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">重置用户属性</strong><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁用文件数配额，执行 pure-pw usermod -n &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁用文件大小配额，执行 pure-pw usermod -N &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁用上传/下载比率，执行 pure-pw usermod -q &rdquo; -Q &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁用下载带宽限制，执行 pure-pw usermod -t &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁止上传带宽限制，执行 pure-pw usermod -T &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁止IP地址过滤，使用 pure-pw usermod &lt;-i,-I,-r or -R&gt; &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁止登陆时间限制，执行 pure-pw usermod -z &rdquo;</span><br style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;" />
<span style="color: rgb(51, 51, 51); font-family: 微软雅黑, Helvetica, Times, Arial, serif; font-size: 12px; line-height: 18px;">要禁止最大并发数控制，执行 pure-pw usermod -y &rdquo;</span></p>]]></description>
			<link>http://meisw.wdlinux.cn//show-934-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2017-04-22 12:31</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-713-1.html</guid>
			<title>vsftpd yum 安装</title>
			<author>admin</author>
			<description><![CDATA[<p>vsftpd yum 安装,使用系统帐号</p>
<p>pam_service_name=vsftpd</p>]]></description>
			<link>http://meisw.wdlinux.cn//show-713-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2012-07-13 15:57</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-626-1.html</guid>
			<title>pure-ftpd的参数设置</title>
			<author>admin</author>
			<description><![CDATA[<p>-0: 当存在同名文件时，旧版本的文件不被删除或者截断，而是采用临时文件。当整个文件上传完毕之后，才指向新的文件。这个开关选项跟虚拟配额不兼容。<br />
-1: 在系统日志的输出中，记录每个会话（ Session ）的 PID 。<br />
-4: 只监听 IPv4 的连接<br />
-6: 只监听 IPv6 的连接<br />
-a &lt;gid&gt;: 只有通过认证的用户才可以直接访问它的 home 目录。该选项对没有 shell 的系统用户特别有用。注意，这里的 &lt;gid&gt; 是组的数组，而非字母显示。并且， root 始终对整个文件系统有完整的访问权。<br />
-A: 除了 root 之外，都可以使用 chroot()<br />
-b: 忽略部分 RFC 的标准，以处理完全坏掉的客户端、穿越防火墙或者 NAT 盒<br />
-B: 以标准的方式在后台启动服务器<br />
-c &lt;num&gt;: 允许同时连接的客户端数列。默认是 50<br />
-C &lt;num&gt;: 同一 IP 最大连接数<br />
-d: 在系统日志中记录各种信息，口令不会记入日志中，推荐只有需要 debug 时使用。如果两个 -d ，相应信息也一并记入日志。<br />
-D: 即使当客户端没有使用 -a 选项时，同样列出所有以 &rdquo;.&rdquo; 开头的隐藏文件。不推荐使用。<br />
-e: 只开放匿名用户访问<br />
-E: 只开放认证用户使用，匿名访问被禁止<br />
-f &lt;facility&gt;: 使用指定程序记录系统日志，默认时 &rsquo;ftp&rsquo; 。如果使用 &rsquo;-f none&rsquo; 则不记录日志。<br />
-F &lt;fortune file&gt;: 在登陆的时候显示一个 fortune 信息，而不是固定的登陆信息。其中 &lt;fortune file&gt; 是符合 fortune 格式的文本文件，fortune信息之间用'%'号隔开。 这是需要在编译时加入 &rsquo;&mdash;with-cookie&rsquo; 选项。如果仅仅是一个简单的文本文件，则在每次登陆是显示相同的信息。<br />
-g &lt;pid file&gt;: 改变默认 pid 文件的位置。默认是位于 /var/run/pure-ftpd.pid<br />
-G: 不允许重命名<br />
-H: 系统默认是要对 IP 地址进行解析，才记入日志文件中。使用这个选项，则可以避免这样做。从而避免带宽的浪费。<br />
-i: 不论目录的权限设置，匿名用户始终不能进行上传<br />
-I &lt;timeout&gt;: 发呆的时间，以分钟为单位。默认是 15 分钟<br />
-j: 如果用户的 home 目录不存在，就自动创建<br />
-k &lt;percentage&gt;: 当 FTP 服务器占用空间超过规定的百分比，则不能再上传文件了。不用加 &rsquo;%<br />
-K: 允许用户 resume 和 upload 文件，但是不可以删除和重命名这些文件。空的文件夹也可以被删除。可以通过 &rsquo;-r&rsquo; 禁止该选项。<br />
-l &lt;authentication&gt; 或者 -l &lt;authentication&gt;:&lt;config file&gt;: 添加一个新的规则<br />
-L &lt;max files&gt;:&lt;max depth&gt;: 默认的， pure-ftpd 不会显示超过 2000 个文件或者深度大于 5 的路径<br />
-m &lt;cpu load&gt;: 如果 CPU 负载超过指定值，则不运行匿名用户下载。但是上传依然允许<br />
-M: 允许匿名用户创建目录<br />
-n &lt;max files&gt;:&lt;max size&gt;: 如果服务器被编译成支持虚拟配额，则该选项可以约束所有的用户（新任组的用户出外）。其中，最大的文件大小以 M 为单位<br />
-N:NAT 模式，强制 Active 。当 ftp 服务器位于 NAT 、伪装网关或者路由器后面时，如果无法正常访问，可以采用此选项。<br />
-o: 将所有上传的文件写入 &rsquo;/var/run/pure-ftpd.upload.pipe&rsquo; ，使得 &rsquo;pure-uploadscipte&rsquo; 程序可以运行。<br />
-O &lt;format&gt;:&lt;log file&gt;: 以指定格式将文件传输记入日志文件中。目前支持的格式包括： CLF 、 Stats 、 W3C 和 xferlog<br />
-p &lt;first port&gt;:&lt;last port&gt;: 包括被动模式在内，服务器只会选择从开始到结束的端口进行监听。<br />
-P &lt;ip address or host name&gt;: 对 PASV 、 EPSV 和 SPSV 命令的相应，强制以指定的 IP 地址或 hostname 相应。<br />
-q &lt;upload ratio&gt;:&lt;download ratio&gt;: 为匿名用户指定上传和下载 ration<br />
-Q &lt;upload ratio&gt;:&lt;download ratio&gt;: 为除了 root 组的用户外的所有人指定上传和下载 ratio 。 root 组的用户没有 ratio 限制<br />
-r: 永远不覆盖已经存在的文件。这是，上传一个已经存在的文件时，会自动为其重命名，入： xyz 、 xyz.1 、 xyz.2 。如果编译时使用 &rdquo; make AUTORENAME_REVERSE_ORDER=1&rdquo; ，则重命名的文件是 1.xyz 、 2.xyz<br />
-R: 即使是非匿名用户（除了 root 之外），也不允许使用 chmod 命令<br />
-s: 不允许匿名用户下载属主是 ftp 的文件（其它匿名用户上传的文件）。这样可以保证必须经过管理员的修改，这些文件才能被匿名用户下载。<br />
-S&nbsp; 绑定到指定的地址和端口。例：<br />
/usr/local/sbin/pure-ftpd -S 21<br />
/usr/local/sbin/pure-ftpd -S 192.168.0.1<br />
/usr/local/sbin/pure-ftpd -S 192.168.0.1,21<br />
/usr/local/sbin/pure-ftpd -S mci.uestc.edu.cn,21<br />
-t &lt;bandwidth&gt; 和 -T &lt;bandwidth&gt;: 带宽限制。 &lt;bandwidth&gt; 是以 k/s 为单位，同时可以指定上传和下载的带宽，支持 [&lt;upload&gt;]:[&lt;download&gt;] 语法<br />
-u &lt;uid&gt;: 禁止 uid 小于 &lt;uid&gt; 的用户登陆。 -u 1 可以禁止 root 用户登陆， -u 100 可以禁止绝大多数系统虚拟用户登陆。<br />
-U &lt;umask for files&gt;:&lt;umask for dirs&gt;: 改变默认的掩码，默认的是 133:022 。如果希望上传的文件只能被上传该文件的用户读，使用 &rsquo;-U 177:077&rsquo; 。如果希望上传的文件可以被执行，使用 022:022 （文件可以被其它用户读，但是不能写）。 077:077 文件只能被所有者执行或者读。 Pure-ftpd 支持 SITE CHMOD ，使得用户可以被改变自己文件的属性。<br />
-V &lt;ip address&gt;: 只允许在指定地址的非匿名的 FTP 访问。这时，可以将公网 IP 路由到一个指定的内网 IP 地址，或者将新任的 IP 地址路由到指定的内网 IP 地址。<br />
-v &lt;name&gt;: 支持苹果的 Bonjor ，只有当 Bonjor 选择在编译的时候支持是，苹果的 MacOS X 才能有此属性。<br />
-w: 只对认证的用户支持 FXP 协议<br />
-W: 支持 FXP 协议<br />
-x: 默认时，非匿名用户可以读和写以 &rsquo;.&rsquo; 开头的隐藏文件，而匿名用户则不可以。当该选项指定时，用户只能下载这些文件，但是不能覆盖和创建，即使该用户时是该文件的属主。如果希望是用户可以访问特定的以 &rsquo;.&rsquo; 开头的文件，可以通过建立该文件的链接（非 &rsquo;.&rsquo; 开头的文件名）达到目的<br />
-X: 用户除了不能写以 &rsquo;.&rsquo; 开头的文件，如果使用了该选项，用户不能读这样的文件，也不能进入这样的目录。（当以 &rsquo;-a&rsquo; 参数启动，受信的用户可以绕开 &rsquo;-x&rsquo; 和 &rsquo;-X&rsquo; 的限制）<br />
-y &lt;max user logins&gt;:&lt;max anonymous logins&gt;: 如果编译时加入了 --with-peruserlimits 选项，该选项限制了同一个用户可以同时拥有的 session 数目。空值 &rsquo;0&rsquo; 意味着没有限制<br />
-z: 允许匿名用户读以 &rsquo;.&rsquo; 开头的文件和目录<br />
-Z: 避免用户犯简单的错误。当前，该选项可以避免用户错误的使用 chmod 命令，防止他们不能访问自己的文件或者目录。该选项在将来还会有更多的功能。所以，推荐 host 服务器打开该参数</p>]]></description>
			<link>http://meisw.wdlinux.cn//show-626-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2012-01-07 11:20</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-623-1.html</guid>
			<title>pureftpd</title>
			<author>admin</author>
			<description><![CDATA[<p>各参数注释<br />
User：用户名<br />
status：状态 1为激活状态 0为非激活状态<br />
Password ：密码<br />
Uid：用户系统ID号<br />
GID：用户组ID号<br />
ULBandwidth ：上传最大带宽 单位 KB/S<br />
DLBandwidth：下载最大带宽&nbsp; 单位 KB/S<br />
comment&nbsp; ：注释<br />
ipaccess ：允许访问IP地址 <br />
QuotaSize ：磁盘配额总大小 单位MB<br />
QuotaFiles&nbsp; ：允许存放的文件数目个数 0为不限制</p>
<p>然后用这个帐号测试，/home/askwan1自动建立<br />
新增加帐号可以通过phpmyadmin来添加。</p>
<p>相关连接和参考资料文档：<br />
&nbsp;&nbsp; PureFTPd: <a href="http://www.pureftpd.org">http://www.pureftpd.org</a><br />
&nbsp;&nbsp;&nbsp; MySQL: <a href="http://www.mysql.com">http://www.mysql.com</a><br />
&nbsp;&nbsp;&nbsp; phpMyAdmin: <a href="http://www.phpmyadmin.net">http://www.phpmyadmin.net</a></p>]]></description>
			<link>http://meisw.wdlinux.cn//show-623-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2012-01-01 17:40</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-607-1.html</guid>
			<title>pure-ftpd.conf设置</title>
			<author>admin</author>
			<description><![CDATA[<p>限制用户在其主目录<br />
ChrootEveryone yes<br />
兼容ie等比较非正规化的ftp客户端，否则用IE打开不自动弹出登陆对话框<br />
BrokenClientsCompatibility yes<br />
服务器总共允许同时连接的最大用户数<br />
MaxClientsNumber 500<br />
同一IP允许同时连接的用户数<br />
MaxClientsPerIP 500<br />
不允许匿名连接，仅允许认证用户使用，否则不自动打开登陆对话框<br />
NoAnonymous yes<br />
MySQL 配置文件 (参考 README.MySQL)<br />
MySQLConfigFile /etc/pureftpd-mysql.conf<br />
启用简单的 Unix系统 认证方式(/etc/passwd), 使linux用户可登陆<br />
UnixAuthentication yes<br />
认证用户允许登陆的最小组ID（UID），设为0使root可登陆<br />
MinUID 0<br />
用户主目录不存在的话，自动创建<br />
CreateHomeDir yes<br />
# 被动连接响应的端口范围。- for firewalling.<br />
PassivePortRange&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 30000 50000<br />
要启用被动模式，需在防火墙开放30000:50000端口<br />
vi /etc/sysconfig/iptables<br />
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 30000:50000 -j ACCEPT<br />
<br />
<br />
<br />
<br />
<br />
<br />
pure-ftpd.conf 中文说明<br />
<br />
<br />
<br />
<br />
# 如果你想要使用配置文件代替命令行选项来运行 Pure-FTPd ，请运行下面的命令：<br />
#<br />
# RPM 缺省使用另外一个配置文件：<br />
# /etc/sysconfig/pure-ftpd<br />
#<br />
# 请不要忘了浏览一下 <a href="http://www.pureftpd.org/documentation.html" target="_blank"><font color="#4d6c80">http://www.pureftpd.org/documentation.html</font></a> 的<br />
# 文档，查看全部的选项列表。<br />
# 限制所有用户在其主目录中<br />
&nbsp; ChrootEveryone&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 如果前一个指令被设置为了 &quot;no&quot;，下面组的成员(GID)就不受主目录的限制了。而其他的用户还是<br />
# 会被限制在自己的主目录里。如果你不想把任何用户限制在自己的主目录里，只要注释掉 ChrootEveryone<br />
# 和 TrustedGID 就可以了。<br />
# TrustedGID&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 100<br />
# 兼容ie等比较非正规化的ftp客户端<br />
&nbsp; BrokenClientsCompatibility&nbsp; no<br />
# 服务器总共允许同时连接的最大用户数<br />
&nbsp; MaxClientsNumber&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 50<br />
# 做为守护(doemon)进程运行(Fork in background)<br />
&nbsp; Daemonize&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 同一IP允许同时连接的用户数（Maximum number of sim clients with the same IP address）<br />
&nbsp; MaxClientsPerIP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 8<br />
# 如果你要记录所有的客户命令，设置这个指令为 &quot;yes&quot;。<br />
# This directive can be duplicated to also log server responses.<br />
&nbsp; VerboseLog&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no<br />
# 即使客户端没有发送 '-a' 选项也列出隐藏文件( dot-files 。<br />
&nbsp; DisplayDotFiles&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 不允许认证用户 - 仅作为一个公共的匿名FTP。<br />
&nbsp; AnonymousOnly&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no<br />
# 不允许匿名连接，仅允许认证用户使用。<br />
&nbsp; NoAnonymous&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no<br />
# Syslog facility (auth, authpriv, daemon, ftp, security, user, local*)<br />
# 缺省的功能( facility 是 &quot;ftp&quot;。 &quot;none&quot; 将禁止日志。<br />
&nbsp; SyslogFacility&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; ftp<br />
# 定制用户登陆后的显示信息（Display fortune cookies）<br />
# FortunesFile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /usr/share/fortune/zippy<br />
# 在日志文件中不解析主机名。日志没那么详细的话，就使用更少的带宽。在一个访问量很大&nbsp; <br />
# 的站点中，设置这个指令为 &quot;yes&quot; ，如果你没有一个能工作的DNS的话。<br />
&nbsp; DontResolve&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 客户端允许的最大的空闲时间（分钟，缺省15分钟）<br />
&nbsp; MaxIdleTime&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 15<br />
# LDAP 配置文件 (参考 README.LDAP)<br />
# LDAPConfigFile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /etc/pureftpd-ldap.conf<br />
# MySQL 配置文件 (参考 README.MySQL)<br />
# MySQLConfigFile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /etc/pureftpd-mysql.conf<br />
# Postgres 配置文件 (参考 README.PGSQL)<br />
# PGSQLConfigFile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /etc/pureftpd-pgsql.conf<br />
# PureDB 用户数据库 (参考 README.Virtual-Users)<br />
# PureDB&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /etc/pureftpd.pdb<br />
# pure-authd 的socket 路径(参考 README.Authentication-Modules)<br />
# ExtAuth&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /var/run/ftpd.sock<br />
# 如果你要启用 PAM 认证方式, 去掉下面行的注释。<br />
# PAMAuthentication&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 如果你要启用 简单的 Unix系统 认证方式(/etc/passwd), 去掉下面行的注释。<br />
# UnixAuthentication&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 请注意，LDAPConfigFile, MySQLConfigFile, PAMAuthentication 和<br />
# UnixAuthentication 这些指令只能被使用一次，不过，他们能被混合在一起用。例如：如果你使用了<br />
# MySQLConfigFile 和 UnixAuthentication，那么 SQL 服务器将被访问。如果因为用户名未找<br />
# 到而使 SQL 认证失败的话，就会在/etc/passwd 和 /etc/shadow 中尝试另外一种认证，如果因<br />
# 为密码错误而使 SQL 认证失败的话，认证就会在此结束了。认证方式由它们被给出来的顺序而被链<br />
# 接了起来。<br />
# 'ls' 命令的递归限制。第一个参数给出文件显示的最大数目。第二个参数给出最大的子目录深度。<br />
&nbsp; LimitRecursion&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 2000 8<br />
# 允许匿名用户创建新目录？<br />
&nbsp; AnonymousCanCreateDirs&nbsp; &nbsp; &nbsp; no<br />
# 如果系统被 loaded 超过下面的值，匿名用户会被禁止下载。<br />
&nbsp; MaxLoad&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 4<br />
# 被动连接响应的端口范围。- for firewalling.<br />
# PassivePortRange&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 30000 50000<br />
# 强制一个IP地址使用被动响应（ PASV/EPSV/SPSV replies）。 - for NAT.<br />
# Symbolic host names are also accepted for gateways with dynamic IP<br />
# addresses.<br />
# ForcePassiveIP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 192.168.0.1<br />
# 匿名用户的上传/下载的比率。<br />
# AnonymousRatio&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1 10<br />
# 所有用户的上传/下载的比率。<br />
# This directive superscedes the previous one.<br />
# UserRatio&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1 10<br />
# 不接受所有者为 &quot;ftp&quot; 的文件的下载。例如：那些匿名用户上传后未被本地管理员验证的文件。<br />
&nbsp; AntiWarez&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 服务监听的IP 地址和端口。(缺省是所有IP地址和21端口)<br />
# Bind&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 127.0.0.1,21<br />
# 匿名用户的最大带宽（KB/s）。<br />
# AnonymousBandwidth&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 8<br />
# 所有用户的最大带宽（KB/s），包括匿名用户。<br />
# Use AnonymousBandwidth *or* UserBandwidth, both makes no sense.<br />
# UserBandwidth&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 8<br />
# 新建目录及文件的属性掩码值。&lt;文件掩码&gt;:&lt;目录掩码&gt; .<br />
# 177:077 if you feel paranoid.<br />
&nbsp; Umask&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 133:022<br />
# 认证用户允许登陆的最小组ID（UID） 。<br />
&nbsp; MinUID&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 100<br />
# 仅允许认证用户进行 FXP 传输。<br />
&nbsp; AllowUserFXP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 对匿名用户和非匿名用户允许进行匿名 FXP 传输。<br />
&nbsp; AllowAnonymousFXP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no<br />
# 用户不能删除和写点文件（文件名以 '.' 开头的文件），即使用户是文件的所有者也不行。<br />
# 如果 TrustedGID 指令是 enabled ，文件所属组用户能够访问点文件(dot-files)。<br />
&nbsp; ProhibitDotFilesWrite&nbsp; &nbsp; &nbsp; no<br />
# 禁止读点文件（文件名以 '.' 开头的文件） (.history, .ssh...)<br />
&nbsp; ProhibitDotFilesRead&nbsp; &nbsp; &nbsp; &nbsp; no<br />
# 永不覆盖文件。当上传的文件，其文件名已经存在时，自动重命名，如： file.1, file.2, file.3, ...<br />
&nbsp; AutoRename&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; no<br />
# 不接受匿名用户上传新文件( no = 允许上传)<br />
&nbsp; AnonymousCantUpload&nbsp; &nbsp; &nbsp; &nbsp; no<br />
# 仅允许来自以下IP地址的非匿名用户连接。你可以使用这个指令来打开几个公网IP来提供匿名FTP，<br />
# 而保留一个私有的防火墙保护的IP来进行远程管理。你还可以只允许一内网地址进行认证，而在另外<br />
# 一个IP上提供纯匿名的FTP服务。<br />
#TrustedIP&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 10.1.1.1<br />
# 如果你要为日志每一行添加 PID&nbsp; 去掉下面行的注释。<br />
# LogPID&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 使用类似于Apache的格式创建一个额外的日志文件，如：<br />
# fw.c9x.org - jedi [13/Dec/1975:19:36:39] &quot;GET /ftp/linux.tar.bz2&quot; 200 21809338<br />
# 这个日志文件能被 www 流量分析器处理。<br />
# AltLog&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; clf:/var/log/pureftpd.log<br />
# 使用优化过的格式为统计报告创建一个额外的日志文件。<br />
# AltLog&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; stats:/var/log/pureftpd.log<br />
# 使用标准的W3C格式创建一个额外的日志文件。（与大部分的商业日志分析器兼容）<br />
# AltLog&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; w3c:/var/log/pureftpd.log<br />
# 不接受 CHMOD 命令。用户不能更改他们文件的属性。<br />
# NoChmod&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 允许用户恢复和上传文件，却不允许删除他们。<br />
# KeepAllFiles&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 用户主目录不存在的话，自动创建。<br />
# CreateHomeDir&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; yes<br />
# 启用虚拟的磁盘限额。第一个数字是最大的文件数。<br />
# 第二个数字是最大的总的文件大小(单位：Mb)。<br />
# 所以，1000:10 就限制每一个用户只能使用 1000 个文件，共10Mb。<br />
# Quota&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 1000:10<br />
# 如果你的 pure-ftpd 编译时加入了独立服务器( standalone 支持，你能够改变 pid 文件<br />
# 的位置。缺省位置是 /var/run/pure-ftpd.pid 。<br />
# PIDFile&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; /var/run/pure-ftpd.pid<br />
# 如果你的 pure-ftpd 编译时加入了 pure-uploadscrīpt 支持，这个指令将会使 pure-ftpd<br />
# 发送关于新上传的情况信息到 /var/run/pure-ftpd.upload.pipe，这样 pure-uploadscrīpt<br />
# 就能读然后调用一个脚本去处理新的上传。<br />
# CallUploadscrīpt yes<br />
# 这个选项对允许匿名上传的服务器是有用的。当 /var/ftp 在 /var 里时，需要保留一定磁盘空间<br />
# 来保护日志文件。当所在磁盘分区使用超过百分之 X 时，将不在接受新的上传。<br />
&nbsp; MaxDiskUsage&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 99<br />
# 如果你不想要你的用户重命名文件的话，就设置为 'yes' 。<br />
# NoRename yes<br />
# 是 'customer proof' : 工作区(workaround)反对普通的客户错误，类似于：'chmod 0 public_html' 的错误。<br />
# 那是一个有效的命令，不过，将导致无知的客户所定他们自己的文件，将使你的技术支持忙于愚蠢的的问题中。<br />
# 如果你确信你所有的用户都有基本的Unix知识的话，这个特性将没什么用了。不过，如果你是一个主机提供商<br />
# 的话，启用它。<br />
CustomerProof yes<br />
# 每一个用户的并发限制。只有在添加了 --with-peruserlimits 编译选项进行编译后，这个指令才起<br />
# 作用。(大部分的二进制的发布版本就是例子)<br />
# 格式是 : &lt;每一个用户最大允许的进程&gt;:&lt;最大的匿名用户进程&gt;<br />
# 例如： 3:20 意思是同一个认证用户最大可以有3个同时活动的进程。而且同时最多只能有20个匿名用户进程</p>]]></description>
			<link>http://meisw.wdlinux.cn//show-607-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2011-09-27 20:55</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-442-1.html</guid>
			<title>pureftpd-mysql.conf</title>
			<author>admin</author>
			<description><![CDATA[<p>MYSQLSocket&nbsp;&nbsp;&nbsp;&nbsp; /tmp/mysql.sock<br />
MYSQLServer&nbsp;&nbsp;&nbsp;&nbsp; localhost<br />
MYSQLPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3306<br />
MYSQLUser&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ftp<br />
MYSQLPassword&nbsp;&nbsp; 123456<br />
MYSQLDatabase&nbsp;&nbsp; ftpusers<br />
MYSQLCrypt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; md5<br />
MYSQLGetPW&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SELECT Password FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)<br />
MYSQLGetUID&nbsp;&nbsp;&nbsp;&nbsp; SELECT Uid FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)<br />
MYSQLGetGID&nbsp;&nbsp;&nbsp;&nbsp; SELECT Gid FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)<br />
MYSQLGetDir&nbsp;&nbsp;&nbsp;&nbsp; SELECT Dir FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)<br />
MySQLGetQTASZ&nbsp;&nbsp; SELECT QuotaSize FROM users WHERE User=&quot;\L&quot;<br />
MySQLGetBandwidthUL SELECT ULBandwidth FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)<br />
MySQLGetBandwidthDL SELECT DLBandwidth FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)</p>
<p>&nbsp;</p>
<p>--------------------------------------------</p>
<p># If you want to use the Socket connect methode comment out the<br />
# Lines with MMYSQLServer and MYSQLPort.<br />
# If you want to use the Port methode comment out the MYSQLSocket line<br />
#//IMPORTENT!!!If display 530 error,please check the following MYSQL parameter!!<br />
MYSQLSocket&nbsp;&nbsp;&nbsp;&nbsp; /tmp/mysql.sock<br />
MYSQLServer&nbsp;&nbsp;&nbsp;&nbsp; localhost<br />
MYSQLPort&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3306<br />
MYSQLUser&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ftp<br />
MYSQLPassword&nbsp;&nbsp; 123456<br />
MYSQLDatabase&nbsp;&nbsp; ftpusers<br />
MYSQLCrypt&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; md5</p>
<p># In the following directives, parts of the strings are replaced at<br />
# run-time before performing queries :<br />
#<br />
# \L is replaced by the login of the user trying to authenticate.<br />
# \I is replaced by the IP address the user connected to.<br />
# \P is replaced by the port number the user connected to.<br />
# \R is replaced by the IP address the user connected from.<br />
# \D is replaced by the remote IP address, as a long decimal number.<br />
#<br />
# Very complex queries can be performed using these substitution strings,<br />
# especially for virtual hosting.</p>
<p><br />
# Query to execute in order to fetch the password</p>
<p>MYSQLGetPW&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SELECT Password FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)</p>
<p><br />
# Query to execute in order to fetch the system user name or uid</p>
<p>MYSQLGetUID&nbsp;&nbsp;&nbsp;&nbsp; SELECT Uid FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)</p>
<p><br />
# Optional : default UID - if set this overrides MYSQLGetUID</p>
<p>#MYSQLDefaultUID 1000</p>
<p><br />
# Query to execute in order to fetch the system user group or gid</p>
<p>MYSQLGetGID&nbsp;&nbsp;&nbsp;&nbsp; SELECT Gid FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)</p>
<p># Optional : default GID - if set this overrides MYSQLGetGID</p>
<p>#MYSQLDefaultGID 1000</p>
<p><br />
# Query to execute in order to fetch the home directory</p>
<p>MYSQLGetDir&nbsp;&nbsp;&nbsp;&nbsp; SELECT Dir FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)</p>
<p># Optional : query to get the maximal number of files<br />
# Pure-FTPd must have been compiled with virtual quotas support.</p>
<p># MySQLGetQTAFS&nbsp; SELECT QuotaFiles FROM users WHERE User=&quot;\L&quot;</p>
<p># Optional : query to get the maximal disk usage (virtual quotas)<br />
# The number should be in Megabytes.<br />
# Pure-FTPd must have been compiled with virtual quotas support.</p>
<p># MySQLGetQTASZ&nbsp; SELECT QuotaSize FROM users WHERE User=&quot;\L&quot;</p>
<p><br />
# Optional : ratios. The server has to be compiled with ratio support.</p>
<p># MySQLGetRatioUL SELECT ULRatio FROM users WHERE User=&quot;\L&quot;<br />
# MySQLGetRatioDL SELECT DLRatio FROM users WHERE User=&quot;\L&quot;</p>
<p><br />
# Optional : bandwidth throttling.<br />
# The server has to be compiled with throttling support.<br />
# Values are in KB/s .</p>
<p>MySQLGetBandwidthUL SELECT ULBandwidth FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)<br />
MySQLGetBandwidthDL SELECT DLBandwidth FROM users WHERE User=&quot;\L&quot; AND Status=&quot;1&quot; AND (Ipaddress = &quot;*&quot; OR Ipaddress LIKE &quot;\R&quot;)</p>
<p># Enable ~ expansion. NEVER ENABLE THIS BLINDLY UNLESS :<br />
# 1) You know what you are doing.<br />
# 2) Real and virtual users match.</p>
<p># MySQLForceTildeExpansion 1</p>
<p><br />
# If you upgraded your tables to transactionnal tables (Gemini,<br />
# BerkeleyDB, Innobase...), you can enable SQL transactions to<br />
# avoid races. Leave this commented if you are using the<br />
# traditionnal MyIsam databases or old (&lt; 3.23.x) MySQL versions.</p>
<p># MySQLTransactions On</p>]]></description>
			<link>http://meisw.wdlinux.cn//show-442-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2011-06-19 20:41</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-300-1.html</guid>
			<title>配置vsftp支持ssl</title>
			<author>admin</author>
			<description><![CDATA[<div style="text-indent: 15.75pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.5" class="MsoNormal"><font size="3"><span lang="EN-US"><font face="Calibri">ftp</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">传输数据是明文，弄个抓包软件就可以通过数据包来分析到账号和密码，为了搭建一个安全性比较高</span><span lang="EN-US"><font face="Calibri">ftp</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">，可以结合</span><span lang="EN-US"><font face="Calibri">SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">来解决问题</span></font></div>
<div style="margin: 0cm 0cm 0pt" class="MsoNormal"><span lang="EN-US"><o:p><font size="3" face="Calibri">&nbsp;</font></o:p></span></div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal"><font size="3"><font face="Calibri"><strong style="mso-bidi-font-weight: normal"><span lang="EN-US">SSL</span></strong><span lang="EN-US">(Secure Socket Layer)</span></font><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">工作于传输层和应用程序之间</span><span lang="EN-US"><font face="Calibri">.</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">作为一个中间层</span><span lang="EN-US"><font face="Calibri">,</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">应用程序只要采用</span><span lang="EN-US"><font face="Calibri">SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">提供的一套</span><span lang="EN-US"><font face="Calibri">SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">套接字</span><span lang="EN-US"><font face="Calibri">API</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">来替换标准的</span><span lang="EN-US"><font face="Calibri">Socket</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">套接字</span><span lang="EN-US"><font face="Calibri">,</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">就可以把程序转换为</span><span lang="EN-US"><font face="Calibri">SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">化的安全网络程序</span><span lang="EN-US"><font face="Calibri">,</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">在传输过程中将由</span><span lang="EN-US"><font face="Calibri">SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">协议实现数据机密性和完整性的保证</span><span lang="EN-US"><font face="Calibri">.SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">取得大规模成功后</span><span lang="EN-US"><font face="Calibri">,IETF</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">将</span><span lang="EN-US"><font face="Calibri">SSL</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">作了标准化</span><span lang="EN-US"><font face="Calibri">,</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">并将其称为</span><span lang="EN-US"><font face="Calibri">TLS(Transport Layer Security).Ftp</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">结合</span><span lang="EN-US"><font face="Calibri">SSL,</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">将实现传输数据的加密</span><span lang="EN-US"><font face="Calibri">,</font></span><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">保证数据不被别人窃取</span></font></div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal">&nbsp;</div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal">&nbsp;</div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal"><font size="3"><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">让vsftpd支持SSL，必须让OPENSSL&ge;0.9.6版本，还有就是本身vsftpd版本是否支持 <br />
查询vsftpd软件是否支持SSL <br />
[root@localhost vsftpd]# ldd /usr/sbin/vsftpd |grep libssl<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; libssl.so.6 =&gt; /lib/libssl.so.6 (0xf7f27000)&nbsp;&nbsp; ==&egrave;说明此版本支持 <br />
如没有输出libssl.so.6 =&gt; /lib/libssl.so.6 (0xf7f27000)类似文本，说明此vsftpd版本不支持SSL</span></font></div>
<p><font size="3"><span style="font-family: 宋体; mso-fareast-font-family: 宋体; mso-fareast-theme-font: minor-fareast; mso-ascii-font-family: calibri; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: calibri; mso-hansi-theme-font: minor-latin">
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal"><br />
openssl req -x509 -nodes -days 365 -newkey rsa:1024 \-keyout /etc/vsftpd/vsftpd.pem \-out /etc/vsftpd/vsftpd.pem&nbsp; ==&egrave;生成vsftpd.pem 证书</div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal"><br />
vi /etc/vsftpd/vsftpd.conf&nbsp; ==&egrave;编辑主配置文件，添加以下参数ssl_enable=YES<br />
allow_anon_ssl=NO<br />
force_local_data_ssl=YES<br />
force_local_logins_ssl=YES<br />
ssl_tlsv1=YES<br />
ssl_sslv2=NO<br />
ssl_sslv3=NO<br />
rsa_cert_file=/etc/vsftpd/vsftpd.pem</div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal">service vsftpd restart</div>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal"><br />
下面是ssl参数一些定义，根据自己需求去修改 <br />
ssl_enable=yes/no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //是否启用 SSL,默认为no<br />
allow_anon_ssl=yes/no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //是否允许匿名用户使用SSL,默认为no<br />
rsa_cert_file=/path/to/file&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //rsa证书的位置<br />
dsa_cert_file=/path/to/file&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //dsa证书的位置<br />
force_local_logins_ssl=yes/no&nbsp;&nbsp;&nbsp; //非匿名用户登陆时是否加密,默认为yes<br />
force_local_data_ssl=yes/no&nbsp;&nbsp;&nbsp;&nbsp; //非匿名用户传输数据时是否加密,默认为yes<br />
force_anon_logins_ssl=yes/no&nbsp;&nbsp;&nbsp; //匿名用户登录时是否加密,默认为no<br />
force_anon_data_ssl=yes/no&nbsp;&nbsp;&nbsp;&nbsp; //匿名用户数据传输时是否加密,默认为no<br />
ssl_sslv2=yes/no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //是否激活sslv2加密,默认no<br />
ssl_sslv3=yes/no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //是否激活sslv3加密,默认no<br />
ssl_tlsv1=yes/no&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //是否激活tls v1加密,默认yes<br />
ssl_ciphers=加密方法&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; //默认是DES-CBC3-SHA</div>
</span></font></p>
<div style="text-indent: 10.55pt; margin: 0cm 0cm 0pt; mso-char-indent-count: 1.0" class="MsoNormal">&nbsp;</div>]]></description>
			<link>http://meisw.wdlinux.cn//show-300-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2010-10-19 22:42</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-249-1.html</guid>
			<title>编译vsftp sysdeputil.c出错的解决办法</title>
			<author>admin</author>
			<description><![CDATA[<p>specified for parameter 'sendfile'<br />
sysdeputil.c:186: error: storage class specified for parameter 'environ'<br />
sysdeputil.c:187: error: storage class specified for parameter 's_proctitle_space'<br />
sysdeputil.c:187: error: parameter 's_proctitle_space' is initialized<br />
sysdeputil.c:188: error: storage class specified for parameter 's_proctitle_inited'<br />
sysdeputil.c:188: error: parameter 's_proctitle_inited' is initialized<br />
sysdeputil.c:189: error: storage class specified for parameter 's_p_proctitle'<br />
sysdeputil.c:189: error: parameter 's_p_proctitle' is initialized<br />
sysdeputil.c:201: error: storage class specified for parameter 'do_sendfile'<br />
sysdeputil.c:202: error: storage class specified for parameter 'vsf_sysutil_setproctitle_internal'<br />
sysdeputil.c:203: error: storage class specified for parameter 's_proctitle_prefix_str'<br />
sysdeputil.c:278: error: storage class specified for parameter 's_pamh'<br />
sysdeputil.c:279: error: storage class specified for parameter 's_pword_str'<br />
sysdeputil.c:281: error: storage class specified for parameter 'pam_conv_func'<br />
sysdeputil.c:282: error: storage class specified for parameter 'vsf_auth_shutdown'<br />
sysdeputil.c:288: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:383: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:398: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:436: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:474: error: storage class specified for parameter 'do_checkcap'<br />
sysdeputil.c:478: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:497: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:514: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:527: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:604: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:641: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:796: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:803: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:809: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:856: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:889: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:930: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:935: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:976: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:1012: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:1128: error: storage class specified for parameter 's_uwtmp_inserted'<br />
sysdeputil.c:1129: error: storage class specified for parameter 's_utent'<br />
sysdeputil.c:1134: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:1173: error: expected '=', ',', ';', 'asm' or '__attribute__' before '{' token<br />
sysdeputil.c:1189: error: old-style parameter declarations in prototyped function definition<br />
sysdeputil.c:162: error: parameter name omitted<br />
sysdeputil.c:162: error: parameter name omitted<br />
sysdeputil.c:162: error: parameter name omitted<br />
sysdeputil.c:1189: error: expected '{' at end of input<br />
make: *** [sysdeputil.o] Error 1</p>
<p>&nbsp;</p>
<p><font color="#ff0000">这几个包可能不是REDHAT的，这个问题的原因是sysdeputil.c 文件出错，真正解决方法是给其打补丁：<br />
# patch sysdeputil.c attachment.bin <br />
&nbsp;&nbsp;# make<br />
attachment.bin 的位置在：</font><a href="http://linuxfromscratch.org/pipermail/lfs-dev/attachments/20061019/fd9b9f56/attachment.bin" target="_blank">http://linuxfromscratch.org/pipe ... 9f56/attachment.bin</a><br />
<font color="#ff0000">注明： 当前目录为vsftp**/</font></p>]]></description>
			<link>http://meisw.wdlinux.cn//show-249-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2010-05-18 19:10</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-236-1.html</guid>
			<title>vsftpd</title>
			<author>admin</author>
			<description><![CDATA[<p><a href="http://vsftpd.beasts.org/#download">http://vsftpd.beasts.org/#download</a><br />
<a href="ftp://vsftpd.beasts.org/users/cevans/">ftp://vsftpd.beasts.org/users/cevans/</a><br />
<a href="ftp://vsftpd.beasts.org/users/cevans/vsftpd-2.2.2.tar.gz">ftp://vsftpd.beasts.org/users/cevans/vsftpd-2.2.2.tar.gz</a></p>
<p>tar zxvf<br />
cd<br />
sed -i 's/define VSF_BUILD_PAM/undef VSF_BUILD_PAM/' builddefs.h</p>
<p>make<br />
mkdir /usr/share/empty<br />
mkdir /www/servers/vsftpd<br />
install -m 755 vsftpd /www/servers/vsftpd/vsftpd<br />
install -m 644 vsftpd.8 /usr/share/man/man8<br />
install -m 644 vsftpd.conf.5 /usr/share/man/man5<br />
install -m 644 vsftpd.conf /etc/vsftpd.conf</p>
<p>[root@local cf]# cat vsftpd.denyuser<br />
echo 'root<br />
bin<br />
daemon<br />
shutdown<br />
halt<br />
ftp<br />
nobody<br />
vcsa<br />
nscd<br />
rpm<br />
haldaemon<br />
sshd<br />
rpc<br />
rpcuser<br />
mailnull<br />
smmsp<br />
pcap<br />
apache<br />
named<br />
mysql' &gt; /etc/vsftpd.denyuser</p>
<p>&nbsp;</p>
<p>cat vsftpd.conf<br />
echo 'anonymous_enable=NO<br />
local_enable=YES<br />
write_enable=YES<br />
local_umask=022<br />
dirmessage_enable=YES<br />
xferlog_enable=YES<br />
connect_from_port_20=YES<br />
xferlog_file=/var/log/vsftpd.log<br />
idle_session_timeout=600<br />
listen=YES<br />
listen_port=21<br />
chroot_local_user=YES<br />
pasv_enable=YES<br />
pasv_min_port=10240<br />
pasv_max_port=10250<br />
userlist_enable=YES<br />
userlist_deny=YES<br />
userlist_file=/etc/vsftpd.denyuser' &gt; /etc/vsftpd.conf</p>
<p><br />
iptables<br />
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 21 -j ACCEPT<br />
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 10240:10250 -j ACCEPT</p>
<p><br />
X86_64<br />
修改vi vsf_findlibs.sh内容为 locate_library /lib64/libpam.so.0 &amp;&amp; echo &quot;/lib/libpam.so.0&quot;;<br />
if locate_library /lib64/libcap.so.1; then <br />
&nbsp; echo &quot;/lib64/libcap.so.1&quot;; <br />
else <br />
&nbsp; locate_library /usr/lib64/libcap.so &amp;&amp; echo &quot;-lcap&quot;; <br />
&nbsp; locate_library /lib64/libcap.so &amp;&amp; echo &quot;-lcap&quot;; <br />
fi <br />
再次执行make</p>]]></description>
			<link>http://meisw.wdlinux.cn//show-236-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2010-02-04 13:21</pubDate>
		</item>
		<item>
			<guid>http://meisw.wdlinux.cn//show-105-1.html</guid>
			<title>vsftpd配置文件</title>
			<author>admin</author>
			<description><![CDATA[<p>系统用户,部分配置文件</p>
<p>listen=YES<br />
listen_port=102<br />
#listen_data_port=20<br />
chroot_local_user=YES<br />
pasv_enable=YES<br />
pasv_min_port=10240<br />
pasv_max_port=10250<br />
userlist_enable=YES<br />
userlist_deny=YES<br />
userlist_file=/etc/vsftpd.denyuser</p>
<p>&nbsp;</p>
<p>虚拟用户</p>
<p>anonymous_enable=NO<br />
local_enable=YES<br />
local_umask=022<br />
anon_umask=022<br />
write_enable=NO<br />
anon_upload_enable=NO<br />
anon_mkdir_write_enable=NO<br />
anon_other_write_enable=NO<br />
chroot_local_user=YES<br />
guest_enable=YES<br />
guest_username=datad<br />
listen=YES<br />
pam_service_name=vsftpd.pam<br />
user_config_dir=/servers/vsftpdv/user<br />
pasv_enable=YES<br />
pasv_min_port=10240<br />
pasv_max_port=10250<br />
userlist_enable=YES<br />
userlist_deny=YES<br />
userlist_file=/etc/vsftpd.denyuser</p>
<p>把用户密码放在login.txt上</p>
<p>单用户名双密码的规则</p>
<p>然后在/servers/vsftpdv/user目录下创建相应目录</p>
<p>然后如下更新</p>
<p>db_load -T -t hash -f /servers/vsftpdv/login.txt /servers/vsftpdv/vsftpd_login.db</p>
<p>&nbsp;</p>]]></description>
			<link>http://meisw.wdlinux.cn//show-105-1.html</link>
			<category domain="http://meisw.wdlinux.cn//category-17-1.html">ftp</category>
			<pubDate>2008-02-15 10:21</pubDate>
		</item>
	</channel>
</rss>
