在 Linux 上搭建 FTP 服务(如 vsftpd、ProFTPD、Pure-FTPd)时,常面临暴力破解、匿名滥用、目录穿越、明文嗅探等攻击。下面从服务配置、系统层、网络层、运维监控几个维度说明防护方法。
anonymous_enable=NO
防止匿名用户上传/下载/遍历文件。
local_enable=YES
chroot_local_user=YES
allow_writeable_chroot=YES
防止用户跳出 home 目录(目录穿越)。
userlist_enable=YES
userlist_file=/etc/vsftpd/user_list
userlist_deny=NO
只放行白名单用户。
ascii_upload_enable=NO
ascii_download_enable=NO
防止 ASCII 模式导致的命令注入风险。
pasv_enable=YES
pasv_min_port=30000
pasv_max_port=31000
便于防火墙精确放行。
apt install fail2ban
配置 /etc/fail2ban/jail.local:
[vsftpd]
enabled = true
port = ftp
logpath = /var/log/vsftpd.log
maxretry = 5
bantime = 3600
auth required pam_tally2.so deny=5 unlock_time=600
ufw allow 21
ufw allow 30000:31000/tcp
或 iptables 同理。
ufw allow from 10.0.0.0/8 to any port 21
SFTP 基于 SSH,天然加密、防嗅探:
subsystem sftp internal-sftp
禁用 FTP:
systemctl stop vsftpd
systemctl disable vsftpd
ssl_enable=YES
rsa_cert_file=/etc/ssl/certs/vsftpd.pem
rsa_private_key_file=/etc/ssl/private/vsftpd.key
force_local_data_ssl=YES
force_local_logins_ssl=YES
避免账号密码明文传输。
usermod -s /usr/sbin/nologin ftpuser
chmod 750 /home/ftpuser
apt update && apt upgrade
xferlog_enable=YES
log_ftp_protocol=YES
grep "FAIL" /var/log/vsftpd.log
✅ 内网使用 → vsftpd + chroot + fail2ban
✅ 公网使用 → SFTP(首选) 或 FTPS
❌ 公网不要开匿名 FTP
❌ 不要使用明文 FTP
如果你愿意,可以告诉我:
我可以给你一份可直接用的安全配置模板。