{"id":1373,"date":"2025-12-14T16:45:52","date_gmt":"2025-12-14T08:45:52","guid":{"rendered":"http:\/\/www.preluna.xyz\/?p=1373"},"modified":"2026-01-01T15:06:03","modified_gmt":"2026-01-01T07:06:03","slug":"%e5%89%8d%e7%ab%af%e6%96%87%e4%bb%b6%e6%8f%90%e4%ba%a4%e7%9a%84%e5%ae%89%e5%85%a8%e9%98%b2%e6%8a%a4","status":"publish","type":"post","link":"http:\/\/www.preluna.xyz\/index.php\/2025\/12\/14\/%e5%89%8d%e7%ab%af%e6%96%87%e4%bb%b6%e6%8f%90%e4%ba%a4%e7%9a%84%e5%ae%89%e5%85%a8%e9%98%b2%e6%8a%a4\/preluna\/text\/","title":{"rendered":"\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a4"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>\u6743\u9650\u7ba1\u7406<\/strong>\u3002\u7406\u89e3\u5e76\u914d\u7f6e\u597d\u5b83\uff0c\u662f\u4fdd\u8bc1\u7f51\u7ad9\u5b89\u5168\u3001\u6709\u5e8f\u8fd0\u884c\u7684\u57fa\u77f3\u3002\u6211\u4eec\u53ef\u4ee5\u5c06\u5176\u62c6\u89e3\u4e3a\u201c<strong>\u7406\u89e3\u9ed8\u8ba4\u89d2\u8272<\/strong>\u201d\u548c\u201c<strong>\u8fdb\u884c\u6743\u9650\u914d\u7f6e<\/strong>\u201d\u4e24\u90e8\u5206\u3002\u4e3a\u4e86\u8ba9\u6574\u4e2a\u6743\u9650\u4f53\u7cfb\u4e00\u76ee\u4e86\u7136\uff0c\u6211\u4eec\u5148\u901a\u8fc7\u4e00\u5f20\u56fe\u6765\u6982\u89c8WordPress\u6838\u5fc3\u7528\u6237\u89d2\u8272\u7684\u201c\u6743\u529b\u9636\u68af\u201d\u53ca\u5176\u5728\u6295\u7a3f\u7cfb\u7edf\u4e2d\u7684\u5173\u952e\u6743\u9650\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a41-843x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"843\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a41-843x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1374\"  sizes=\"auto, (max-width: 843px) 100vw, 843px\" \/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0a\u56fe\u5c55\u793a\u4e86\u4ece\u4f4e\u5230\u9ad8\u7684\u89d2\u8272\u6743\u9650\u3002\u5bf9\u4e8e\u6784\u5efa\u7684\u201c<strong>\u524d\u7aef\u6295\u7a3f-\u540e\u53f0\u5ba1\u6838<\/strong>\u201d\u7cfb\u7edf\uff0c<strong>\u6295\u7a3f\u8005 (Contributor)<\/strong>&nbsp;\u548c<strong>\u8ba2\u9605\u8005 (Subscriber)<\/strong>&nbsp;\u662f\u6700\u76f8\u5173\u7684\u4e24\u4e2a\u89d2\u8272\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u6743\u9650\u9694\u79bb<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u66b4\u9732\u4e86\u670d\u52a1\u5668\u6587\u4ef6\u8def\u5f84\u662f\u4e00\u4e2a\u4e25\u91cd\u7684\u5b89\u5168\u9690\u60a3<\/strong>\u3002\u8fd9\u901a\u5e38\u610f\u5473\u7740\u4e0a\u4f20\u7684\u6587\u4ef6\u88ab\u76f4\u63a5\u94fe\u63a5\u5230\u4e86\u670d\u52a1\u5668\u7684<strong>\u7edd\u5bf9\u8def\u5f84<\/strong>\uff08\u4f8b\u5982&nbsp;<code>http:\/\/\u4f60\u7684\u7f51\u7ad9.com\/wp-content\/uploads\/...<\/code>\uff09\uff0c\u8fd9\u4f1a\u8ba9\u6280\u672f\u578b\u7528\u6237\u7aa5\u63a2\u5230\u4f60\u7f51\u7ad9\u7684\u90e8\u5206\u76ee\u5f55\u7ed3\u6784\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u95ee\u9898\u7684\u6839\u6e90\u5728\u4e8e&nbsp;<strong>\u201c\u5bf9\u4e0a\u4f20\u6587\u4ef6\u7684\u8bbf\u95ee\u63a7\u5236\u4e0d\u591f\u4e25\u683c\u201d<\/strong>&nbsp;\u3002\u6211\u4eec\u9700\u8981\u5efa\u7acb\u4e24\u5c42\u9632\u62a4\uff1a<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u7b2c\u4e00\u5c42\uff1a\u9690\u85cf\u8def\u5f84<\/strong>&nbsp;\u2013 \u786e\u4fdd\u524d\u7aef\u4e0d\u76f4\u63a5\u663e\u793a\u670d\u52a1\u5668\u7269\u7406\u8def\u5f84\u3002<\/li>\n\n\n\n<li><strong>\u7b2c\u4e8c\u5c42\uff1a\u8bbf\u95ee\u62e6\u622a<\/strong>&nbsp;\u2013 \u5373\u4f7f\u6709\u4eba\u731c\u5230\u4e86\u6587\u4ef6\u8def\u5f84\uff0c\u4e5f\u65e0\u6cd5\u76f4\u63a5\u901a\u8fc7\u6d4f\u89c8\u5668\u8bbf\u95ee\uff0c\u5fc5\u987b\u7ecf\u8fc7\u7f51\u7ad9\u7a0b\u5e8f\uff08\u548c\u6743\u9650\u68c0\u67e5\uff09\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">&nbsp;\u52a0\u56fa\u6b65\u9aa4\u4e00\uff1a\u914d\u7f6eFlamingo\u63d2\u4ef6\uff08\u9690\u85cf\u8def\u5f84\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u7684\u76ee\u6807\u662f\u8ba9Flamingo\u540e\u53f0\u53ea\u663e\u793a\u7528\u4e8e\u7ba1\u7406\u7684\u6587\u4ef6\u94fe\u63a5\uff0c\u800c\u4e0d\u66b4\u9732\u5177\u4f53\u8def\u5f84\u3002<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u8fdb\u5165Flamingo\u8bbe\u7f6e<\/strong>\uff1a\u5728WordPress\u540e\u53f0\uff0c\u8fdb\u5165&nbsp;<strong>Flamingo \u2192 \u8bbe\u7f6e<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u68c0\u67e5\u201c\u6587\u4ef6\u4e0a\u4f20\u201d\u8bbe\u7f6e<\/strong>\uff1a\u627e\u5230\u4e0e\u201c\u6587\u4ef6\u4e0a\u4f20\u201d\u6216\u201c\u9644\u4ef6\u94fe\u63a5\u201d\u76f8\u5173\u7684\u9009\u9879\u3002<\/li>\n\n\n\n<li><strong>\u4fee\u6539\u94fe\u63a5\u7c7b\u578b\uff08\u5173\u952e\uff09<\/strong>\uff1a\u5982\u679c\u5b58\u5728\u76f8\u5173\u9009\u9879\uff0c\u5c1d\u8bd5\u5c06\u6587\u4ef6\u94fe\u63a5\u7684\u663e\u793a\u65b9\u5f0f\u4ece&nbsp;<strong>\u201c\u7edd\u5bf9URL\u201d<\/strong>&nbsp;\u6216&nbsp;<strong>\u201c\u6587\u4ef6\u8def\u5f84\u201d<\/strong>&nbsp;\u6539\u4e3a&nbsp;<strong>\u201c\u76f8\u5bf9URL\u201d<\/strong>&nbsp;\u6216\u4ec5\u663e\u793a\u6587\u4ef6\u540d\u3002\u4e0d\u540c\u7248\u672c\u7684\u63d2\u4ef6\u8bbe\u7f6e\u53ef\u80fd\u4e0d\u540c\uff0c\u5982\u679c\u627e\u4e0d\u5230\uff0c\u8fd9\u4e00\u6b65\u53ef\u4ee5\u6682\u65f6\u8df3\u8fc7\uff0c\u6211\u4eec\u901a\u8fc7\u7b2c\u4e8c\u6b65\u4ece\u6839\u672c\u4e0a\u89e3\u51b3\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">&nbsp;\u52a0\u56fa\u6b65\u9aa4\u4e8c\uff1a\u4fdd\u62a4\u4e0a\u4f20\u76ee\u5f55\uff08\u6839\u672c\u6027\u89e3\u51b3\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f\u6700\u6709\u6548\u7684\u4e00\u6b65\uff0c\u901a\u8fc7\u670d\u52a1\u5668\u89c4\u5219<strong>\u7981\u6b62\u76f4\u63a5\u8bbf\u95ee<\/strong>\u5b58\u653e\u6295\u7a3f\u6587\u4ef6\u7684\u76ee\u5f55\uff0c\u53ea\u5141\u8bb8WordPress\u7a0b\u5e8f\u672c\u8eab\uff08\u7ecf\u8fc7\u6743\u9650\u9a8c\u8bc1\u540e\uff09\u8bfb\u53d6\u6587\u4ef6\u3002<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u627e\u5230\u4e0a\u4f20\u76ee\u5f55\u8def\u5f84<\/strong>\uff1a\u4f7f\u7528FTP\u5de5\u5177\u6216\u4e3b\u673a\u5546\u7684\u6587\u4ef6\u7ba1\u7406\u5668\uff0c\u8fdb\u5165\u4f60\u7f51\u7ad9\u7684&nbsp;<code>wp-content\/uploads\/<\/code>&nbsp;\u76ee\u5f55\u3002<\/li>\n\n\n\n<li><strong>\u521b\u5efa\u4fdd\u62a4\u6587\u4ef6<\/strong>\uff1a\u5728\u8be5\u76ee\u5f55\u4e0b\uff0c<strong>\u68c0\u67e5\u5e76\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a&nbsp;<code>.htaccess<\/code><\/strong>&nbsp;\u7684\u6587\u4ef6\uff08\u5982\u679c\u5df2\u5b58\u5728\uff0c\u5219\u7f16\u8f91\u5b83\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6dfb\u52a0\u5b89\u5168\u89c4\u5219<\/strong>\uff1a\u5728&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u4e2d\uff0c\u52a0\u5165\u4ee5\u4e0b\u6838\u5fc3\u4ee3\u7801\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code># \u963b\u6b62\u76f4\u63a5\u8bbf\u95ee\u654f\u611f\u6587\u4ef6\u7c7b\u578b\uff0c\u5e76\u7981\u6b62\u76ee\u5f55\u5217\u8868\n&lt;FilesMatch \"\\.(php|html?|js|css|log|txt)$\"&gt;\n    Order Allow,Deny\n    Deny from all\n&lt;\/FilesMatch&gt;\n\n# \u5982\u679c\u4e0a\u9762\u89c4\u5219\u5bfc\u81f4\u4f60\u7684\u56fe\u7247\u4e5f\u65e0\u6cd5\u8bbf\u95ee\uff0c\u53ef\u4ee5\u4f7f\u7528\u66f4\u5b89\u5168\u7684\u89c4\u5219\uff1a\n# \u4ec5\u5141\u8bb8\u901a\u8fc7WordPress\uff08\u5373\u4f60\u7684\u57df\u540d\uff09\u6765\u8bbf\u95ee\u56fe\u7247\u7b49\u5a92\u4f53\u6587\u4ef6\nRewriteCond %{REQUEST_FILENAME} -f\nRewriteCond %{REQUEST_URI} \\.(jpg|jpeg|png|gif|pdf|doc|docx)$ &#91;NC]\nRewriteCond %{HTTP_REFERER} !^https?:\/\/(www\\.)?\u4f60\u7684\u7f51\u7ad9\u57df\u540d\\.com\/ &#91;NC]\nRewriteRule \\.(jpg|jpeg|png|gif|pdf|doc|docx)$ - &#91;NC,F,L]\n\n# \u59cb\u7ec8\u7981\u6b62\u76ee\u5f55\u6d4f\u89c8\nOptions -Indexes<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6ce8\u610f<\/strong>\uff1a\u8bf7\u5c06\u4ee3\u7801\u4e2d\u7684&nbsp;<code>\u4f60\u7684\u7f51\u7ad9\u57df\u540d.com<\/code>&nbsp;\u66ff\u6362\u4e3a\u4f60\u81ea\u5df1\u7684\u5b9e\u9645\u57df\u540d\uff08\u4e0d\u542b&nbsp;<code>http:\/\/<\/code>\uff09\u3002\u8fd9\u6761\u89c4\u5219\u7684\u610f\u601d\u662f\uff1a\u5982\u679c\u8bf7\u6c42\u4e00\u4e2a\u56fe\u7247\/\u6587\u6863\uff0c\u4f46\u6765\u6e90\u4e0d\u662f\u4f60\u7684\u7f51\u7ad9\uff0c\u5219\u76f4\u63a5\u7981\u6b62\u8bbf\u95ee(403 Forbidden)\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u52a0\u56fa\u6b65\u9aa4\u4e09\uff1a\u7ec8\u6781\u65b9\u6848\u2014\u2014\u81ea\u5b9a\u4e49\u6587\u4ef6\u4e0a\u4f20\u4f4d\u7f6e\uff08\u8fdb\u9636\uff09<br>\u5982\u679c\u4e0a\u8ff0\u65b9\u6cd5\u4ecd\u4e0d\u653e\u5fc3\uff0c\u53ef\u4ee5\uff0c\u5c06\u6295\u7a3f\u6587\u4ef6\u5b58\u653e\u5230Web\u6839\u76ee\u5f55\u4e4b\u5916\u3002<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u539f\u7406\uff1a\u5728\u670d\u52a1\u5668\u4e0a\u521b\u5efa\u4e00\u4e2a \/home\/\u4f60\u7684\u8d26\u6237\/private_uploads\/ \u8fd9\u7c7b\u5b8c\u5168\u4e0d\u5728\u7f51\u7ad9\u516c\u5f00\u8bbf\u95ee\u8303\u56f4\u5185\u7684\u76ee\u5f55\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u64cd\u4f5c\uff1a\u8fd9\u901a\u5e38\u9700\u8981\u4fee\u6539CF7\u6216\u4f7f\u7528\u9ad8\u7ea7\u63d2\u4ef6\u6765\u91cd\u5b9a\u4e49\u4e0a\u4f20\u8def\u5f84\uff0c\u5e76\u7f16\u5199\u4ee3\u7801\u901a\u8fc7\u4e00\u4e2a\u201c\u6587\u4ef6\u4ee3\u7406\u201d\u811a\u672c\uff08\u9700\u9a8c\u8bc1\u7ba1\u7406\u5458\u6743\u9650\uff09\u6765\u8bfb\u53d6\u6587\u4ef6\u3002\u6b64\u6b65\u9aa4\u6d89\u53ca\u4ee3\u7801\u5f00\u53d1\uff0c\u8f83\u4e3a\u590d\u6742\uff0c\u9664\u975e\u6709\u6781\u9ad8\u5b89\u5168\u8981\u6c42\uff0c\u5426\u5219\u5b8c\u6210\u7b2c\u4e8c\u6b65\u901a\u5e38\u5df2\u8db3\u591f\u5b89\u5168\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6743\u9650\u9694\u79bb\u68c0\u67e5\u6e05\u5355<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3a\u4e86\u786e\u4fdd\u5f7b\u5e95\u7684\u9694\u79bb\uff0c\u8bf7\u5bf9\u7167\u6b64\u6e05\u5355\u68c0\u67e5\u7f51\u7ad9\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u68c0\u67e5\u9879\u76ee<\/th><th>\u76ee\u6807\u72b6\u6001\uff08\u9488\u5bf9\u975e\u7ba1\u7406\u5458\uff09<\/th><th>\u5982\u4f55\u68c0\u67e5\/\u8bbe\u7f6e<\/th><\/tr><\/thead><tbody><tr><td><strong>1. \u540e\u53f0\u8bbf\u95ee<\/strong><\/td><td><strong>\u5b8c\u5168\u65e0\u6cd5\u8fdb\u5165<\/strong>&nbsp;<code>\/wp-admin<\/code><\/td><td>\u7528\u6237\u63d2\u4ef6\uff08\u5982WPCOM Member\uff09\u5e94\u5df2\u5c06\u9ed8\u8ba4\u767b\u5f55\u540e\u8df3\u8f6c\u9875\u9762\u8bbe\u4e3a\u201c\u524d\u7aef\u7528\u6237\u4e2d\u5fc3\u201d\uff0c\u800c\u975e\u540e\u53f0\u4eea\u8868\u76d8\u3002<\/td><\/tr><tr><td><strong>2. \u524d\u7aef\u8868\u5355\u53ef\u89c1\u6027<\/strong><\/td><td><strong>\u4ec5\u767b\u5f55\u540e\u53ef\u89c1<\/strong><\/td><td>\u786e\u8ba4\u6295\u7a3f\u9875\u9762\u4f7f\u7528\u4e86&nbsp;<code>[loggedin]<\/code>&nbsp;\u7b49\u77ed\u4ee3\u7801\u5305\u88f9\u3002<\/td><\/tr><tr><td><strong>3. \u5a92\u4f53\u5e93\u8bbf\u95ee<\/strong><\/td><td><strong>\u4e0d\u53ef\u89c1\uff0c\u4e0d\u53ef\u7528<\/strong><\/td><td>\u9ed8\u8ba4\u201c\u6295\u7a3f\u8005\u201d\u89d2\u8272\u65e0\u201c\u4e0a\u4f20\u6587\u4ef6\u201d\u6743\u9650\uff0c\u8fd9\u5df2\u7531\u89d2\u8272\u63a7\u5236\u3002<\/td><\/tr><tr><td><strong>4. \u6587\u4ef6\u8def\u5f84\u66b4\u9732<\/strong><\/td><td><strong>\u7edd\u5bf9\u8def\u5f84\u88ab\u9690\u85cf<\/strong><\/td><td>\u6309\u4e0a\u6587\u6b65\u9aa4\u4e8c\u64cd\u4f5c\uff0c\u4fdd\u62a4\u4e0a\u4f20\u76ee\u5f55\u3002<\/td><\/tr><tr><td><strong>5. \u76f4\u63a5\u6587\u4ef6\u8bbf\u95ee<\/strong><\/td><td><strong>\u88ab\u670d\u52a1\u5668\u89c4\u5219\u62e6\u622a<\/strong><\/td><td>\u901a\u8fc7&nbsp;<code>.htaccess<\/code>&nbsp;\u89c4\u5219\u5b9e\u73b0\uff0c\u540c\u4e0a\u3002<\/td><\/tr><tr><td><strong>6. \u89d2\u8272\u664b\u5347<\/strong><\/td><td><strong>\u4e25\u683c\u63a7\u5236<\/strong><\/td><td>\u7edd\u4e0d\u5c06\u666e\u901a\u7528\u6237\u63d0\u5347\u4e3a\u201c\u7f16\u8f91\u201d\u6216\u201c\u7ba1\u7406\u5458\u201d\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">&nbsp;\u6587\u4ef6\u4e0a\u4f20\u5230\u54ea\u91cc\u53bb\u4e86\uff1f\uff08\u5b58\u50a8\u4f4d\u7f6e\uff09<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u6587\u4ef6\u4e0a\u4f20\u7684<strong>\u5b58\u50a8\u4f4d\u7f6e<\/strong>\u548c<strong>\u8bbf\u95ee\u7ba1\u7406<\/strong>\u662f\u4e24\u4e2a\u72ec\u7acb\u4f46\u76f8\u5173\u7684\u95ee\u9898\uff0c\u800cFlamingo\u7684\u201c\u8bbe\u7f6e\u201d\u9009\u9879\u786e\u5b9e\u4e0d\u591f\u76f4\u89c2,\u7531&nbsp;<strong>Contact Form 7 (CF7)<\/strong>&nbsp;\u4e0a\u4f20\u7684\u6587\u4ef6\uff0c\u9ed8\u8ba4\u5b58\u50a8\u5728\u4ee5\u4e0b\u670d\u52a1\u5668\u8def\u5f84\uff1a<br><code>\/wp-content\/uploads\/wpcf7_uploads\/<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u8fd9\u662f\u5982\u4f55\u8fd0\u4f5c\u7684\uff1f<\/strong><\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u4e34\u65f6\u5b58\u50a8<\/strong>\uff1a\u7528\u6237\u63d0\u4ea4\u8868\u5355\u65f6\uff0c\u6587\u4ef6\u9996\u5148\u4f1a\u4f20\u5230\u8fd9\u4e2a\u76ee\u5f55\uff0c<strong>\u6587\u4ef6\u540d\u4f1a\u88ab\u7cfb\u7edf\u81ea\u52a8\u91cd\u547d\u540d<\/strong>\u4e3a\u4e00\u4e32\u968f\u673a\u5b57\u7b26\uff08\u5982&nbsp;<code>a1b2c3d4e5.pdf<\/code>\uff09\uff0c\u8fd9\u672c\u8eab\u5c31\u9690\u85cf\u4e86\u539f\u59cb\u6587\u4ef6\u540d\u3002<\/li>\n\n\n\n<li><strong>\u8bb0\u5f55\u94fe\u63a5<\/strong>\uff1a<strong>Flamingo<\/strong>&nbsp;\u63d2\u4ef6\u5728\u8bb0\u5f55\u8fd9\u6b21\u63d0\u4ea4\u65f6\uff0c\u4f1a\u5728\u6570\u636e\u5e93\u91cc\u4fdd\u5b58\u4e00\u4e2a\u6307\u5411\u8fd9\u4e2a<strong>\u4e34\u65f6\u6587\u4ef6<\/strong>\u7684\u94fe\u63a5\u3002<\/li>\n\n\n\n<li><strong>\u81ea\u52a8\u6e05\u7406<\/strong>\uff1a\u9ed8\u8ba4\u60c5\u51b5\u4e0b\uff0c\u8fd9\u4e9b<strong>\u4e34\u65f6\u4e0a\u4f20\u7684\u6587\u4ef6\u4f1a\u572824\u5c0f\u65f6\u540e\u88ab\u7cfb\u7edf\u81ea\u52a8\u5220\u9664<\/strong>\u3002\u8fd9\u5c31\u662f\u4e3a\u4ec0\u4e48\u5fc5\u987b\u5b89\u88c5Flamingo\u6765\u6c38\u4e45\u4fdd\u5b58\u8bb0\u5f55\u7684\u539f\u56e0\uff0c\u5b83\u4fdd\u5b58\u7684\u662f\u201c\u6587\u4ef6\u66fe\u7ecf\u5728\u6b64\u201d\u7684<strong>\u4fe1\u606f<\/strong>\uff0c\u800c\u4e0d\u662f\u6587\u4ef6\u672c\u8eab\u3002<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u91cd\u8981\u63d0\u793a<\/strong>\uff1a\u5982\u679c\u60f3\u8ba9\u6587\u4ef6\u6c38\u4e45\u4fdd\u5b58\uff0c\u9700\u8981\u5b89\u88c5\u989d\u5916\u7684\u6269\u5c55\u63d2\u4ef6\uff08\u5982&nbsp;<strong>Contact Form 7 File Download<\/strong>\uff09\uff0c\u5b83\u4f1a\u5c06\u6587\u4ef6\u8f6c\u79fb\u5230\u5a92\u4f53\u5e93\u3002\u4f46\u76ee\u524d\u4f60\u7684\u514d\u8d39\u65b9\u6848\u4e2d\uff0c<strong>Flamingo + \u90ae\u4ef6\u901a\u77e5<\/strong>\u5df2\u8db3\u591f\u4f60\u83b7\u53d6\u6587\u4ef6\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5982\u4f55\u5728Flamingo\u4e2d\u7ba1\u7406\u6587\u4ef6\uff1f\uff08\u9632\u6b62\u66b4\u9732\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Flamingo\u672c\u8eab<strong>\u6ca1\u6709\u590d\u6742\u7684\u201c\u6587\u4ef6\u4e0a\u4f20\u201d\u8bbe\u7f6e\u9875\u9762<\/strong>\u3002\u5b83\u7684\u6838\u5fc3\u662f\u8bb0\u5f55\u6570\u636e\u3002\u4f60\u771f\u6b63\u9700\u8981\u505a\u7684\u5b89\u5168\u52a0\u56fa\uff0c\u662f\u5728<strong>\u670d\u52a1\u5668\u5c42\u9762<\/strong>\u963b\u6b62\u5bf9\u8fd9\u4e2a\u4e0a\u4f20\u76ee\u5f55\u7684\u76f4\u63a5\u8bbf\u95ee\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u64cd\u4f5c\u8def\u5f84\u5982\u4e0b\uff1a<\/strong><\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u627e\u5230\u76ee\u5f55<\/strong>\uff1a\u4f7f\u7528\u4f60\u7684\u4e3b\u673a\u63a7\u5236\u9762\u677f\uff08\u5982cPanel\uff09\u7684\u201c\u6587\u4ef6\u7ba1\u7406\u5668\u201d\uff0c\u6216FTP\u5de5\u5177\uff08\u5982FileZilla\uff09\uff0c\u8fde\u63a5\u5230\u4f60\u7684\u7f51\u7ad9\u3002<\/li>\n\n\n\n<li><strong>\u5bfc\u822a\u5230\u8def\u5f84<\/strong>\uff1a\u4f9d\u6b21\u6253\u5f00&nbsp;<code>wp-content<\/code>&nbsp;\u2192&nbsp;<code>uploads<\/code>&nbsp;\u6587\u4ef6\u5939\u3002<\/li>\n\n\n\n<li><strong>\u786e\u8ba4\u5b50\u76ee\u5f55<\/strong>\uff1a\u67e5\u770b\u91cc\u9762\u662f\u5426\u6709&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u6587\u4ef6\u5939\u3002\u8fd9\u5c31\u662fCF7\u4e0a\u4f20\u6587\u4ef6\u7684\u786e\u5207\u4f4d\u7f6e\u3002<\/li>\n\n\n\n<li><strong>\u5b9e\u65bd\u4fdd\u62a4\uff08\u6838\u5fc3\u6b65\u9aa4\uff09<\/strong>\uff1a\u5728\u8be5&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u4e0b\uff0c<strong>\u521b\u5efa\u6216\u7f16\u8f91\u4e00\u4e2a\u540d\u4e3a&nbsp;<code>.htaccess<\/code>&nbsp;\u7684\u6587\u4ef6<\/strong>\uff0c\u5e76\u653e\u5165\u6211\u4e4b\u524d\u56de\u590d\u4e2d\u7684\u5b89\u5168\u89c4\u5219\u3002\u8fd9\u4f1a\u963b\u6b62\u4efb\u4f55\u4eba\u901a\u8fc7\u76f4\u63a5\u8f93\u5165\u7f51\u5740\u6765\u8bbf\u95ee\u91cc\u9762\u7684\u6587\u4ef6\u3002<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">\u7b80\u5355\u6765\u8bf4\uff0c\u6574\u4e2a\u6d41\u7a0b\u7684\u5b89\u5168\u903b\u8f91\u662f\u8fd9\u6837\u7684\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6b65\u9aa4<\/th><th>\u53d1\u751f\u4e86\u4ec0\u4e48<\/th><th>\u5b89\u5168\u72b6\u6001<\/th><th>\u4f60\u7684\u63a7\u5236\u70b9<\/th><\/tr><\/thead><tbody><tr><td><strong>1. \u7528\u6237\u63d0\u4ea4<\/strong><\/td><td>\u6587\u4ef6\u4e0a\u4f20\u5230&nbsp;<code>\/wpcf7_uploads\/<\/code>\uff0c\u88ab\u91cd\u547d\u540d\u3002<\/td><td><strong>\u4e34\u65f6\u3001\u968f\u673a\u5316<\/strong><\/td><td>\u901a\u8fc7CF7\u8868\u5355\u9650\u5236\u6587\u4ef6\u7c7b\u578b\u548c\u5927\u5c0f\u3002<\/td><\/tr><tr><td><strong>2. \u6570\u636e\u8bb0\u5f55<\/strong><\/td><td>\u6587\u4ef6\u4e0a\u4f20Flamingo\u5728\u540e\u53f0\u8bb0\u5f55\u4e0b\u8fd9\u6b21\u63d0\u4ea4\u548c<strong>\u6587\u4ef6\u94fe\u63a5<\/strong>\u3002<\/td><td><strong>\u94fe\u63a5\u88ab\u8bb0\u5f55\uff0c\u4f46\u6587\u4ef6\u4ecd\u662f\u4e34\u65f6\u7684<\/strong><\/td><td>\u53ea\u6709\u767b\u5f55WordPress\u540e\u53f0\u624d\u80fd\u770b\u5230Flamingo\u8bb0\u5f55\u3002<\/td><\/tr><tr><td><strong>3. \u4f60\u5ba1\u6838<\/strong><\/td><td>\u4f60\u767b\u5f55\u540e\u53f0\uff0c\u5728Flamingo\u4e2d\u70b9\u51fb\u8be5\u6587\u4ef6\u94fe\u63a5\u8fdb\u884c\u4e0b\u8f7d\u548c\u5ba1\u6838\u3002<\/td><td><strong>\u901a\u8fc7\u540e\u53f0\u6743\u9650\u9a8c\u8bc1\u540e\u7684\u5b89\u5168\u8bbf\u95ee<\/strong><\/td><td>\u4f60\u662f\u7ba1\u7406\u5458\uff0c\u8fd9\u662f\u5408\u89c4\u7684\u8bbf\u95ee\u9014\u5f84\u3002<\/td><\/tr><tr><td><strong>4. \u6587\u4ef6\u6e05\u7406<\/strong><\/td><td>24\u5c0f\u65f6\u540e\uff0c\u670d\u52a1\u5668\u4e0a\u7684\u4e34\u65f6\u6587\u4ef6\u88ab\u81ea\u52a8\u5220\u9664\u3002<\/td><td><strong>\u5f7b\u5e95\u6e05\u7406<\/strong><\/td><td>\u5982\u679c\u6587\u4ef6\u91cd\u8981\uff0c\u4f60\u5e94\u5728\u6b64\u4e4b\u524d\u5c06\u5176\u4fdd\u5b58\u5230\u672c\u5730\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6240\u4ee5\uff0c\u627e\u4e0d\u5230Flamingo\u7684\u201c\u6587\u4ef6\u4e0a\u4f20\u8bbe\u7f6e\u201d\u662f\u6b63\u5e38\u7684<\/strong>\uff0c\u56e0\u4e3a\u6587\u4ef6\u7ba1\u7406\u4e3b\u8981\u5728\u670d\u52a1\u5668\u7aef\u3002\u73b0\u5728\u6700\u6709\u6548\u3001\u6700\u76f4\u63a5\u7684\u5b89\u5168\u52a0\u56fa\u52a8\u4f5c\u662f\uff1a<strong>\u53bb\u4f60\u7684\u7f51\u7ad9\u670d\u52a1\u5668\u4e0a\uff0c\u627e\u5230&nbsp;<code>\/wp-content\/uploads\/wpcf7_uploads\/<\/code>&nbsp;\u8fd9\u4e2a\u76ee\u5f55\uff0c\u7136\u540e\u6309\u7167\u4e0a\u6587\u4e2d\u7684\u3010\u52a0\u56fa\u6b65\u9aa4\u4e8c\u3011\uff0c\u521b\u5efa\u6216\u4fee\u6539&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u3002<\/strong>\u8fd9\u6837\u4e00\u6765\uff0c\u5373\u4f7f\u6709\u4eba\u4eceFlamingo\u7684\u8bb0\u5f55\u91cc\u770b\u5230\u4e86\u6587\u4ef6\u94fe\u63a5\uff0c\u6216\u8005\u8bd5\u56fe\u731c\u6d4b\u6587\u4ef6\u8def\u5f84\uff0c\u670d\u52a1\u5668\u4e5f\u4f1a\u62d2\u7edd\u4ed6\u7684\u76f4\u63a5\u8bbf\u95ee\u8bf7\u6c42\uff0c\u53ea\u6709\u4f60\u901a\u8fc7\u540e\u53f0\u624d\u80fd\u6b63\u5e38\u67e5\u770b\u3002\u8fd9\u624d\u662f\u5b9e\u73b0\u201c\u53ea\u6709\u7ba1\u7406\u5458\u80fd\u8bbf\u95ee\u201d\u7684\u6839\u672c\u65b9\u6cd5\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u7136\u5f53\u524d\u4ec5\u9760&nbsp;<code>.htaccess<\/code>&nbsp;\u8fdb\u884c\u540e\u671f\u62e6\u622a\u662f<strong>\u88ab\u52a8\u9632\u5fa1<\/strong>,\u662f\u4e0d\u8db3\u4ee5\u5b9e\u73b0\u57fa\u7840\u7684\u5b89\u5168\u9632\u62a4\uff0c\u4f60\u9700\u8981\u66f4\u52a0\u4e25\u683c\u7684\u89c4\u5219,\u6211\u4eec\u8fd8\u9762\u4e34\u5f88\u591a\u6311\u6218\u3002\u6bd4\u65b9\u8bf4\uff0c\u4ed6\u867d\u7136\u5c06\u6587\u4ef6\u540d\u540e\u7f00\u6539\u7684\u662f\u6b63\u5e38\u7684\uff0c\u4f46\u662f\u5462\uff0c\u5b83\u5229\u7528Burp\u62e6\u622a\u8fd9\u4e2a\u5305\u5728\u8fd9\u4e2a\u5305\u7684\u8bf7\u6c42\u91cc\u9762\uff0c\u5077\u5077\u7684\u4fee\u6539\u4e86\u8fd9\u4e2a\u6587\u4ef6\u540e\u7f00\u8fd9\u6837\u5b50.\u53c8\u6216\u8005\u4ed6\u4e0a\u4f20\u4e86\u4e00\u4e2a\u56fe\u7247.\u4f46\u662f\u4ed6\u8fd9\u4e2a\u56fe\u7247\u5462\u662f\u901a\u8fc7\u56fe\u7247\u52a0\u6728\u9a6c\u5408\u5e76\u7684\u800c\u6210\u7684\u56fe\u7247\u9a6c\u3002\u8981\u4e3b\u52a8\u89e3\u51b3\u8fd9\u4e9b\u95ee\u9898\uff0c\u6211\u4eec\u9700\u8981<strong>\u8c03\u6574\u7b56\u7565\uff0c\u5efa\u7acb\u4e00\u5957\u201c\u7eb5\u6df1\u9632\u5fa1\u201d\u7684\u4e3b\u52a8\u5904\u7406\u6d41\u7a0b<\/strong>\uff0c\u6838\u5fc3\u662f&nbsp;<strong>\u201c\u9694\u79bb\u3001\u9a8c\u8bc1\u3001\u8f6c\u6362\u201d<\/strong>\u3002\u4e4b\u524d\u7f16\u5199\u7684\u89c4\u5219\u903b\u8f91\u5b58\u5728\u51b2\u7a81\uff08\u524d\u6bb5\u62d2\u7edd\u6240\u6709\u8bbf\u95ee\uff0c\u540e\u6bb5\u53c8\u5c1d\u8bd5\u5141\u8bb8\u7279\u5b9a\u7c7b\u578b\uff09\uff0c\u5e76\u4e14\u65e0\u6cd5\u9632\u5fa1\u56fe\u7247\u9a6c\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">&nbsp;\u7eb5\u6df1\u9632\u5fa1\uff1a\u4e3b\u52a8\u5904\u7406\u6d41\u7a0b<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u7406\u60f3\u7684\u9632\u5fa1\u6d41\u7a0b\u5e94\u5982\u4e0b\u56fe\u6240\u793a\uff0c\u5728\u6587\u4ef6\u88ab\u63a5\u89e6\u524d\u5c31\u5b8c\u6210\u591a\u91cd\u9a8c\u8bc1\u4e0e\u65e0\u5bb3\u5316\u5904\u7406\uff1a<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a42-316x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"316\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a42-316x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1375\"  sizes=\"auto, (max-width: 316px) 100vw, 316px\" \/><\/div><\/figure>\n<\/div>\n\n\n<h3 class=\"wp-block-heading\">\u5b9e\u73b0\uff1a\u7ec4\u5408\u4f7f\u7528\u63d2\u4ef6\u4e0e\u81ea\u5b9a\u4e49\u4ee3\u7801<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u7531\u4e8eWordPress\u548cCF7\u7684\u9ed8\u8ba4\u529f\u80fd\u6709\u9650\uff0c\u5b9e\u73b0\u4e0a\u56fe\u6d41\u7a0b\u9700\u8981\u7ed3\u5408\u63d2\u4ef6\u548c\u81ea\u5b9a\u4e49\u4ee3\u7801\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u5b89\u5168\u76ee\u6807<\/th><th>\u63a8\u8350\u5b9e\u73b0\u65b9\u6848<\/th><th>\u5177\u4f53\u64cd\u4f5c\u4e0e\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td><strong>1. \u7acb\u5373\u91cd\u547d\u540d\u5e76\u79fb\u81f3Web\u6839\u76ee\u5f55\u5916<\/strong><\/td><td><strong>\u81ea\u5b9a\u4e49\u4ee3\u7801\u4fee\u6539CF7\u4e0a\u4f20\u8def\u5f84<\/strong><\/td><td>\u8fd9\u662f<strong>\u6700\u6839\u672c\u7684\u89e3\u51b3\u65b9\u6848<\/strong>\u3002\u901a\u8fc7\u4e00\u6bb5\u4ee3\u7801\uff0c\u5c06CF7\u4e0a\u4f20\u76ee\u5f55\u6539\u4e3aWeb\u65e0\u6cd5\u76f4\u63a5\u8bbf\u95ee\u7684\u4f4d\u7f6e\uff08\u5982&nbsp;<code>\/home\/your_user\/private_uploads\/<\/code>\uff09\uff0c\u5e76\u5f3a\u5236\u4f7f\u7528\u968f\u673a\u6587\u4ef6\u540d\u3002\u8fd9\u9700\u8981\u5c06\u4ee3\u7801\u6dfb\u52a0\u5230\u4e3b\u9898\u7684&nbsp;<code>functions.php<\/code>&nbsp;\u6587\u4ef6\u6216\u81ea\u5b9a\u4e49\u63d2\u4ef6\u4e2d\u3002<strong>\uff08\u4ee3\u7801\u793a\u4f8b\u89c1\u4e0b\u6587\uff09<\/strong><\/td><\/tr><tr><td><strong>2. \u9a8c\u8bc1\u6587\u4ef6\u771f\u5b9e\u7c7b\u578b\uff08\u9632\u4f2a\u6269\u5c55\u540d\uff09<\/strong><\/td><td><strong>\u670d\u52a1\u5668\u7aefMIME\u7c7b\u578b\u68c0\u67e5<\/strong><\/td><td>\u5728\u4e0a\u9762\u7684\u81ea\u5b9a\u4e49\u4ee3\u7801\u4e2d\uff0c\u6574\u5408PHP\u7684&nbsp;<code>finfo_file()<\/code>&nbsp;\u51fd\u6570\uff0c\u901a\u8fc7\u8bfb\u53d6\u6587\u4ef6<strong>\u5934\u90e8\u4e8c\u8fdb\u5236\u7b7e\u540d<\/strong>\u6765\u5224\u65ad\u771f\u5b9e\u7c7b\u578b\uff0c\u4e0e\u6587\u4ef6\u540e\u7f00\u540d\u8fdb\u884c\u6bd4\u5bf9\uff0c\u4e25\u683c\u62d2\u7edd\u4e0d\u4e00\u81f4\u7684\u6587\u4ef6\u3002<\/td><\/tr><tr><td><strong>3. \u5904\u7406\u56fe\u7247\u9a6c\uff08\u7834\u574f\u5d4c\u5165\u4ee3\u7801\uff09<\/strong><\/td><td><strong>\u5bf9\u56fe\u7247\u8fdb\u884c\u201c\u518d\u5904\u7406\u201d<\/strong><\/td><td>\u4f7f\u7528PHP\u7684GD\u5e93\u6216Imagick\uff0c\u5bf9\u4e0a\u4f20\u7684\u56fe\u7247\u8fdb\u884c<strong>\u7b80\u5355\u7684\u91cd\u65b0\u538b\u7f29\u3001\u7f29\u653e\u6216\u683c\u5f0f\u8f6c\u6362<\/strong>\u3002\u8fd9\u4e2a\u8fc7\u7a0b\u4f1a\u7834\u574f\u56fe\u7247\u50cf\u7d20\u5c42\u4e2d\u53ef\u80fd\u9690\u85cf\u7684\u6076\u610f\u4ee3\u7801\uff0c\u800c\u57fa\u672c\u4e0d\u5f71\u54cd\u9884\u89c8\u3002\u8fd9\u53ef\u4ee5\u6574\u5408\u5230\u4e0a\u8ff0\u4ee3\u7801\u4e2d\uff0c\u4f5c\u4e3a\u5bf9\u56fe\u7247\u6587\u4ef6\u7684\u4e13\u95e8\u5904\u7406\u3002<\/td><\/tr><tr><td><strong>4. \u5f3a\u5316\u8bbf\u95ee\u63a7\u5236\uff08.htaccess\uff09<\/strong><\/td><td><strong>\u4fdd\u62a4\u4e34\u65f6\u76ee\u5f55\uff08\u5982\u679c\u4ecd\u9700\u5b58\u5728\uff09<\/strong><\/td><td>\u5982\u679c\u4f60\u6682\u65f6\u65e0\u6cd5\u5b9e\u73b0\u65b9\u68481\uff0c\u90a3\u4e48\u81f3\u5c11\u5e94\u4fee\u6b63\u4f60\u7684\u89c4\u5219\uff0c\u5e76\u4fdd\u62a4\u4e34\u65f6\u76ee\u5f55\u3002\u5c06&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u4e0b\u7684&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u5185\u5bb9<strong>\u7cbe\u7b80\u5e76\u4fee\u6b63\u4e3a\u4ee5\u4e0b\u5185\u5bb9<\/strong>\uff0c\u5b83\u80fd\u66f4\u5b89\u5168\u5730\u62d2\u7edd\u6240\u6709\u8bbf\u95ee\uff1a<br><code># \u65e0\u6761\u4ef6\u62d2\u7edd\u6240\u6709\u76f4\u63a5\u8bbf\u95ee<\/code><br><code>Require all denied<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u6838\u5fc3\u4ee3\u7801\u793a\u4f8b\uff08\u7528\u4e8e functions.php\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ee5\u4e0b\u662f\u4e00\u4e2a<strong>\u57fa\u7840\u793a\u4f8b\u4ee3\u7801\u6846\u67b6<\/strong>\uff0c\u5b9e\u73b0\u4e86<strong>\u91cd\u547d\u540d\u3001\u8f6c\u79fb\u76ee\u5f55\u548c\u7b80\u5355\u7684MIME\u68c0\u67e5<\/strong>\u3002\u8bf7\u6ce8\u610f\uff0c\u8fd9\u9700\u8981\u5177\u5907\u4e00\u5b9a\u7684\u4ee3\u7801\u7f16\u8f91\u80fd\u529b\uff0c\u5e76\u9700\u8981\u6839\u636e\u4f60\u7684\u670d\u52a1\u5668\u73af\u5883\u8c03\u6574\u8def\u5f84\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>add_filter( 'wpcf7_upload_dir', 'custom_wpcf7_upload_dir' );\nfunction custom_wpcf7_upload_dir( $dir ) {\n    \/\/ 1. \u5b9a\u4e49\u4e00\u4e2a\u65b0\u7684\u3001Web\u65e0\u6cd5\u8bbf\u95ee\u7684\u7edd\u5bf9\u8def\u5f84\uff08\u8bf7\u4fee\u6539\u4e3a\u4f60\u7684\u5b9e\u9645\u8def\u5f84\uff09\n    $private_dir = '\/home\/\u4f60\u7684\u670d\u52a1\u5668\u7528\u6237\u540d\/private_uploads\/wpcf7_uploads';\n\n    \/\/ 2. \u786e\u4fdd\u8be5\u76ee\u5f55\u5b58\u5728\u4e14\u6709\u5199\u5165\u6743\u9650\n    if ( ! file_exists( $private_dir ) ) {\n        wp_mkdir_p( $private_dir );\n    }\n\n    \/\/ 3. \u8986\u76d6CF7\u9ed8\u8ba4\u8def\u5f84\n    $dir&#91;'path']   = $private_dir;\n    $dir&#91;'url']    = ''; \/\/ \u7f6e\u7a7aURL\uff0c\u4f7f\u76f4\u63a5\u94fe\u63a5\u5931\u6548\n    $dir&#91;'subdir'] = '';\n\n    return $dir;\n}\n\n\/\/ \u53ef\u9009\uff1a\u6dfb\u52a0\u7b80\u5355\u7684\u6587\u4ef6\u5934\u68c0\u67e5\uff08\u57fa\u7840\u793a\u4f8b\uff09\nadd_filter( 'wpcf7_upload_file_name', 'custom_wpcf7_randomize_name', 10, 3 );\nfunction custom_wpcf7_randomize_name( $filename, $file_path ) {\n    \/\/ \u751f\u6210\u968f\u673a\u6587\u4ef6\u540d\u5e76\u4fdd\u7559\u540e\u7f00\n    $ext = pathinfo( $filename, PATHINFO_EXTENSION );\n    $new_filename = uniqid() . '_' . bin2hex( random_bytes( 8 ) ) . '.' . $ext;\n\n    \/\/ \u6b64\u5904\u53ef\u6dfb\u52a0 finfo_file() \u51fd\u6570\u8fdb\u884cMIME\u7c7b\u578b\u68c0\u67e5\n    \/\/ $finfo = finfo_open( FILEINFO_MIME_TYPE );\n    \/\/ $real_mime = finfo_file( $finfo, $file_path );\n\n    return $new_filename;\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e00\u9636\u6bb5\uff1a\u7d27\u6025\u5c01\u5835\uff08\u4fee\u590d .htaccess\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u524d\u9996\u8981\u4efb\u52a1\u662f<strong>\u5207\u65ad\u6240\u6709\u5bf9\u4e0a\u4f20\u76ee\u5f55\u7684\u76f4\u63a5\u8bbf\u95ee<\/strong>\u3002\u4f60\u7684\u89c4\u5219\u9700\u8981\u7b80\u5316\uff0c\u907f\u514d\u5185\u90e8\u51b2\u7a81\u3002<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u5b9a\u4f4d\u6587\u4ef6<\/strong>\uff1a\u4f7f\u7528\u4e3b\u673a\u5546\u7684\u6587\u4ef6\u7ba1\u7406\u5668\u6216FTP\u5de5\u5177\uff0c\u8fdb\u5165&nbsp;<code>\/wp-content\/uploads\/wpcf7_uploads\/<\/code>&nbsp;\u76ee\u5f55\u3002<\/li>\n\n\n\n<li><strong>\u521b\u5efa\/\u7f16\u8f91\u6587\u4ef6<\/strong>\uff1a\u521b\u5efa\u6216\u6e05\u7a7a\u91cc\u9762\u7684&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u5199\u5165\u6700\u4e25\u683c\u89c4\u5219<\/strong>\uff1a<strong>\u53ea\u4fdd\u7559<\/strong>\u4e0b\u9762\u4e09\u884c\uff08\u9002\u7528\u4e8eApache 2.4+\uff0c\u7edd\u5927\u591a\u6570\u73b0\u4ee3\u4e3b\u673a\u90fd\u652f\u6301\uff09\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code># \u65e0\u6761\u4ef6\u62d2\u7edd\u6240\u6709\u8bbf\u95ee\uff08\u65e0\u8bba\u6765\u81ea\u54ea\u91cc\uff0c\u65e0\u8bba\u4ec0\u4e48\u6587\u4ef6\u7c7b\u578b\uff09\nRequire all denied\n# \u7981\u6b62\u76ee\u5f55\u5217\u8868\uff08\u53cc\u4fdd\u9669\uff09\nOptions -Indexes\n# BEGIN WordPress\n&lt;IfModule mod_rewrite.c&gt;\nRewriteEngine On\nRewriteCond %{HTTP_HOST} ^preluna\\.xyz &#91;NC]\nRewriteRule ^(.*)$ http:\/\/www.preluna.xyz\/$1 &#91;L,R=301]\nRewriteBase \/\nRewriteRule ^index\\.php$ - &#91;L]\nRewriteCond %{REQUEST_FILENAME} !-f\nRewriteCond %{REQUEST_FILENAME} !-d\nRewriteRule . \/index.php &#91;L]\n&lt;\/IfModule&gt;\n# END WordPress\n\n# \u4ee5\u4e0b\u662f\u65b0\u589e\u7684\u5b89\u5168\u89c4\u5219\uff0c\u5fc5\u987b\u653e\u5728 WordPress \u89c4\u5219\u533a\u5757\u4e4b\u5916\n# 1. \u5b57\u4f53\u6587\u4ef6MIME\u7c7b\u578b\uff08\u4f60\u539f\u6709\u7684\uff0c\u53ef\u4ee5\u4fdd\u7559\uff09\nAddType font\/woff2 .woff2\nAddType font\/woff .woff\nAddType font\/ttf .ttf\nAddType application\/vnd.ms-fontobject .eot\nAddType image\/svg+xml .svg\n\n# 2. \u6838\u5fc3\u5b89\u5168\u89c4\u5219\uff1a\u9632\u6b62\u5c06\u4efb\u4f55\u6587\u4ef6\u5f53\u4f5c\u811a\u672c\u89e3\u6790\n&lt;FilesMatch \"\\.(php|php5|php7|phtml|pl|py|jsp|asp|sh|cgi)$\"&gt;\n    # \u65e0\u6761\u4ef6\u62d2\u7edd\u8bbf\u95ee\u4efb\u4f55\u811a\u672c\u6587\u4ef6\n    Require all denied\n&lt;\/FilesMatch&gt;\n\n# 3. \u7279\u522b\u9632\u5fa1\uff1a\u5373\u4f7f\u6709 .php \u540e\u7f00\u7684\u56fe\u7247\u4e5f\u62d2\u7edd\uff08\u9632\u5fa1\u7578\u5f62\u89e3\u6790\uff09\n&lt;FilesMatch \"^.*\\.(php\\.(png|jpg|gif|jpeg))$\"&gt;\n    Require all denied\n&lt;\/FilesMatch&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4e00\u4e2a\u66f4\u4e25\u8c28\u7684\u517c\u5bb9\u7248\u672c<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5f53\u524d\u7684\u7248\u672c\u5728Apache 2.4+\u73af\u5883\u4e0b\u662f\u5b8c\u7f8e\u7684\u3002\u5982\u679c\u5e0c\u671b\u914d\u7f6e\u66f4\u5065\u58ee\uff0c\u80fd\u517c\u5bb9\u53ef\u80fd\u5b58\u5728\u7684\u65e7\u7248Apache\u73af\u5883\uff082.2\uff09\uff0c\u5e76\u66f4\u660e\u786e\u5730\u963b\u6b62\u67d0\u4e9b\u7279\u5b9a\u6587\u4ef6\uff0c\u53ef\u4ee5\u4f7f\u7528\u4ee5\u4e0b\u7248\u672c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u517c\u5bb9Apache 2.2\u4e0e2.4+\u7684\u62d2\u7edd\u8bbf\u95ee\u89c4\u5219\n&lt;IfModule mod_authz_core.c&gt;\n  # Apache 2.4+\n  Require all denied\n&lt;\/IfModule&gt;\n&lt;IfModule !mod_authz_core.c&gt;\n  # Apache 2.2\n  Deny from all\n&lt;\/IfModule&gt;\n\n# \u7981\u6b62\u76ee\u5f55\u5217\u8868\nOptions -Indexes\n\n# \u989d\u5916\u5b89\u5168\uff1a\u660e\u786e\u62d2\u7edd\u6267\u884c\u811a\u672c\uff08\u5373\u4f7f\u88ab\u4ee5\u5176\u4ed6\u65b9\u5f0f\u4e0a\u4f20\uff09\n&lt;FilesMatch \"\\.(php|php5|php7|phtml|pl|py|jsp|asp|sh|cgi)$\"&gt;\n  SetHandler None\n  ForceType text\/plain\n&lt;\/FilesMatch&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u7acb\u523b\u9a8c\u8bc1<\/strong>\uff1a\u6253\u5f00\u6d4f\u89c8\u5668\uff0c\u5c1d\u8bd5\u8bbf\u95ee\u4e00\u4e2a\u5df2\u77e5\u7684\u4e0a\u4f20\u6587\u4ef6\uff0c\u4f8b\u5982&nbsp;<code>http:\/\/\u4f60\u7684\u7f51\u7ad9.com\/wp-content\/uploads\/wpcf7_uploads\/\u67d0\u4e2a\u6587\u4ef6\u540d<\/code>\uff0c\u5e94\u8be5\u770b\u5230&nbsp;<strong>403 Forbidden\uff08\u7981\u6b62\u8bbf\u95ee\uff09<\/strong>&nbsp;\u9519\u8bef\u9875\u3002\u8fd9\u8bf4\u660e\u7b2c\u4e00\u9053\u5899\u5df2\u7b51\u8d77\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6838\u5fc3\u63d0\u793a<\/strong>\uff1a\u6b64&nbsp;<code>.htaccess<\/code>&nbsp;\u89c4\u5219\u662f\u7b2c\u4e00\u5c42\u201c\u7269\u7406\u9694\u79bb\u201d\u3002\u63a5\u4e0b\u6765\uff0c<strong>\u8bf7\u52a1\u5fc5\u7ee7\u7eed\u5b9e\u65bd\u7b2c\u4e8c\u9636\u6bb5\u7684\u201c\u6838\u5fc3\u9632\u5fa1\u201d<\/strong>&nbsp;\u2014\u2014\u5c06\u6587\u4ef6\u4e0a\u4f20\u8def\u5f84\u79fb\u51faWeb\u76ee\u5f55\u5e76\u7acb\u5373\u91cd\u547d\u540d\u3002\u5426\u5219\uff0c\u5982\u679c\u653b\u51fb\u8005\u5229\u7528WordPress\u6216\u63d2\u4ef6\u672c\u8eab\u7684\u67d0\u4e2a\u6f0f\u6d1e<strong>\u95f4\u63a5\u8c03\u7528<\/strong>\u4e86\u8fd9\u4e9b\u6587\u4ef6\uff0c\u4ec5\u9760&nbsp;<code>.htaccess<\/code>&nbsp;\u662f\u65e0\u6cd5\u963b\u6b62\u7684\u3002<code>.htaccess<\/code>&nbsp;\u52a0\u4e0a<strong>\u6587\u4ef6\u8f6c\u79fb<\/strong>\uff0c\u4e24\u8005\u7ed3\u5408\u624d\u80fd\u6784\u6210\u575a\u56fa\u7684\u9632\u7ebf\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e8c\u9636\u6bb5\uff1a\u6838\u5fc3\u9632\u5fa1\uff08\u8f6c\u79fb\u5e76\u91cd\u547d\u540d\u6587\u4ef6\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f\u6cbb\u672c\u4e4b\u7b56\uff0c\u8ba9\u6076\u610f\u6587\u4ef6\u201c\u65e0\u5904\u5b89\u653e\u201d\u4e14\u201c\u9762\u76ee\u5168\u975e\u201d\u3002\u6211\u4eec\u5c06\u901a\u8fc7\u6dfb\u52a0\u4e00\u6bb5\u4ee3\u7801\uff0c\u4fee\u6539CF7\u7684\u4e0a\u4f20\u884c\u4e3a\u3002<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>\u64cd\u4f5c\u524d\u5fc5\u5907<\/strong>\uff1a<strong>\u5907\u4efd\u4f60\u7684\u7f51\u7ad9<\/strong>\uff0c\u7279\u522b\u662f\u5f53\u524d\u4e3b\u9898\u7684&nbsp;<code>functions.php<\/code>&nbsp;\u6587\u4ef6\u3002<\/p>\n<\/blockquote>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u767b\u5f55WordPress\u540e\u53f0<\/strong>\uff0c\u8fdb\u5165&nbsp;<strong>\u5916\u89c2 -&gt; \u4e3b\u9898\u6587\u4ef6\u7f16\u8f91\u5668<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u5728\u53f3\u4fa7\u627e\u5230&nbsp;<code>functions.php<\/code><\/strong>\uff0c\u70b9\u51fb\u8fdb\u884c\u7f16\u8f91\u3002<\/li>\n\n\n\n<li><strong>\u5728\u6587\u4ef6\u672b\u5c3e\u7684&nbsp;<code>?&gt;<\/code>&nbsp;\u6807\u7b7e\u4e4b\u524d\uff08\u5982\u679c\u6ca1\u6709&nbsp;<code>?&gt;<\/code>\uff0c\u5c31\u52a0\u5728\u6587\u4ef6\u6700\u540e\uff09\uff0c\u6dfb\u52a0\u4ee5\u4e0b\u4ee3\u7801<\/strong>\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\/**\n * \u9632\u5fa1\u52a0\u56fa\u7b2c\u4e00\u6b65\uff1a\u5c06CF7\u4e0a\u4f20\u6587\u4ef6\u79fb\u81f3Web\u65e0\u6cd5\u76f4\u63a5\u8bbf\u95ee\u7684\u76ee\u5f55\uff0c\u5e76\u5f3a\u5236\u91cd\u547d\u540d\n *\/\nadd_filter( 'wpcf7_upload_dir', 'custom_wpcf7_upload_dir' );\nfunction custom_wpcf7_upload_dir() {\n    \/\/ \u3010\u5173\u952e\u4fee\u6539\u3011\u5b9a\u4e49\u4e00\u4e2a\u5728\u7f51\u7ad9\u516c\u5f00\u76ee\u5f55\uff08www\u6216public_html\uff09\u4e4b\u5916\u7684\u8def\u5f84\n    \/\/ \u8bf7\u54a8\u8be2\u4f60\u7684\u4e3b\u673a\u5546\u6216\u67e5\u770bFTP\u6839\u76ee\u5f55\uff0c\u786e\u5b9a\u4e00\u4e2a\u50cf\/home\/\u4f60\u7684\u7528\u6237\u540d\/private_uploads\/\u7684\u8def\u5f84\n    \/\/ \u5982\u679c\u6682\u65f6\u4e0d\u786e\u5b9a\uff0c\u53ef\u5148\u7528\u4e00\u4e2a\u66f4\u6df1\u7684Web\u5185\u8def\u5f84\uff0c\u4f8b\u5982\uff1a\n    $private_base = WP_CONTENT_DIR . '\/uploads\/private_wpcf7_uploads'; \/\/ \u4f4d\u4e8ewp-content\u5185\u4f46\u66f4\u6df1\n\n    \/\/ \u786e\u4fdd\u6b64\u76ee\u5f55\u5b58\u5728\n    if ( ! file_exists( $private_base ) ) {\n        wp_mkdir_p( $private_base );\n    }\n\n    \/\/ \u8fd4\u56de\u65b0\u8def\u5f84\uff0c\u5e76\u7f6e\u7a7aURL\u4f7f\u76f4\u63a5\u94fe\u63a5\u5931\u6548\n    return array(\n        'path'   =&gt; $private_base,\n        'url'    =&gt; '', \/\/ \u7559\u7a7a\uff0c\u4f7f\u4efb\u4f55\u76f4\u63a5\u94fe\u63a5\u5931\u6548\n        'subdir' =&gt; '',\n        'error'  =&gt; false,\n    );\n}\n\n\/\/ \u4e3a\u4e0a\u4f20\u6587\u4ef6\u5f3a\u5236\u751f\u6210\u968f\u673a\u6587\u4ef6\u540d\nadd_filter( 'wpcf7_upload_file_name', 'custom_wpcf7_randomize_name', 10, 3 );\nfunction custom_wpcf7_randomize_name( $original_filename, $file_path ) {\n    \/\/ \u83b7\u53d6\u539f\u59cb\u6587\u4ef6\u540e\u7f00\n    $ext = pathinfo( $original_filename, PATHINFO_EXTENSION );\n    \/\/ \u751f\u6210\u4e00\u4e2a\u9ad8\u5f3a\u5ea6\u968f\u673a\u6587\u4ef6\u540d\uff08uniqid + \u968f\u673a\u5b57\u8282\uff09\n    $new_filename = sprintf( '%s_%s.%s', uniqid(), bin2hex( random_bytes( 8 ) ), strtolower( $ext ) );\n    return $new_filename;\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4fee\u6539\u4ee3\u7801\u4e2d\u7684\u8def\u5f84\uff08\u91cd\u8981\uff01\uff09<\/strong>\uff1a\u627e\u5230&nbsp;<code>$private_base = ...<\/code>&nbsp;\u8fd9\u4e00\u884c\u3002\u5982\u679c\u4f60\u4e0d\u77e5\u9053\u7edd\u5bf9\u5b89\u5168\u8def\u5f84\uff0c\u6682\u65f6<strong>\u5148\u4f7f\u7528\u4ee3\u7801\u4e2d\u7ed9\u51fa\u7684\u9ed8\u8ba4\u8def\u5f84<\/strong>\uff08<code>WP_CONTENT_DIR . '\/uploads\/private_wpcf7_uploads'<\/code>\uff09\u3002\u8fd9\u81f3\u5c11\u80fd\u628a\u6587\u4ef6\u85cf\u5230\u66f4\u6df1\u76ee\u5f55\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u9a8c\u8bc1<\/strong>\uff1a\u63d0\u4ea4\u4e00\u4e2a\u5e26\u6587\u4ef6\u7684\u6d4b\u8bd5\u6295\u7a3f\u3002\u7136\u540e\u901a\u8fc7FTP\u53bb\u67e5\u770b\uff0c\u6587\u4ef6\u662f\u5426\u88ab\u5b58\u5230\u4e86&nbsp;<code>wp-content\/uploads\/private_wpcf7_uploads\/<\/code>&nbsp;\u76ee\u5f55\u4e0b\uff0c\u5e76\u4e14\u540d\u5b57\u53d8\u6210\u4e86\u4e00\u957f\u4e32\u968f\u673a\u5b57\u7b26\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e09\u9636\u6bb5\uff1a\u8fdb\u9636\u52a0\u56fa\uff08\u9a8c\u8bc1\u4e0e\u5904\u7406\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u7b2c\u4e8c\u9636\u6bb5\u4ee3\u7801\u7684\u57fa\u7840\u4e0a\uff0c\u6211\u4eec\u53ef\u4ee5\u589e\u52a0\u201c\u6587\u4ef6\u5934\u9a8c\u8bc1\u201d\u548c\u201c\u56fe\u7247\u5904\u7406\u201d\u529f\u80fd\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A. \u6dfb\u52a0MIME\u7c7b\u578b\u9a8c\u8bc1\uff08\u9632\u4f2a\u540e\u7f00\uff09<\/strong><br>\u5728\u4e0a\u4e00\u6bb5\u7684&nbsp;<code>custom_wpcf7_randomize_name<\/code>&nbsp;\u51fd\u6570\u91cc\uff0c<code>$new_filename = ...<\/code>&nbsp;\u8fd9\u884c\u4e4b\u524d\uff0c\u53ef\u4ee5\u52a0\u5165\u68c0\u67e5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ \u5728\u751f\u6210\u65b0\u6587\u4ef6\u540d\u524d\uff0c\u68c0\u67e5\u6587\u4ef6\u771f\u5b9e\u7c7b\u578b\n$allowed_mime = array(\n    'image\/jpeg' =&gt; 'jpg',\n    'image\/png'  =&gt; 'png',\n    'image\/gif'  =&gt; 'gif',\n    'application\/pdf' =&gt; 'pdf',\n    'application\/msword' =&gt; 'doc',\n    'application\/vnd.openxmlformats-officedocument.wordprocessingml.document' =&gt; 'docx',\n);\n\/\/ 1. \u83b7\u53d6\u58f0\u79f0\u7684\u6269\u5c55\u540d\n    $claimed_ext = strtolower( pathinfo( $original_filename, PATHINFO_EXTENSION ) );\n    \/\/ \u5982\u679c\u6269\u5c55\u540d\u6839\u672c\u4e0d\u5728\u5141\u8bb8\u5217\u8868\uff0c\u76f4\u63a5\u62d2\u7edd\n    if ( ! array_key_exists( $claimed_ext, $allowed_types ) ) {\n        return ''; \/\/ \u8fd4\u56de\u7a7a\u5b57\u7b26\u4e32\u4f1a\u89e6\u53d1CF7\u4e0a\u4f20\u9519\u8bef\n    }\n\n\/\/ 2. \u83b7\u53d6\u6587\u4ef6\u7684\u771f\u5b9eMIME\u7c7b\u578b\uff08\u8bfb\u53d6\u6587\u4ef6\u5934\u5b57\u8282\u7b7e\u540d\uff09\n$finfo = finfo_open( FILEINFO_MIME_TYPE );\n$real_mime = finfo_file( $finfo, $file_path );\nfinfo_close( $finfo );\n\n\/\/ 3. \u9a8c\u8bc1\u771f\u5b9eMIME\u7c7b\u578b\u662f\u5426\u4e0e\u58f0\u79f0\u7684\u6269\u5c55\u540d\u5339\u914d\n    if ( ! in_array( $real_mime, $allowed_types&#91; $claimed_ext ] ) ) {\n        \/\/ \u4e0d\u5339\u914d\uff01\u8fd9\u662f\u4e00\u4e2a\u4f2a\u88c5\u7684\u6076\u610f\u6587\u4ef6\n        \/\/ \u53ef\u4ee5\u8bb0\u5f55\u65e5\u5fd7\u6216\u6267\u884c\u5176\u4ed6\u5b89\u5168\u64cd\u4f5c\n        return ''; \/\/ \u62d2\u7edd\u4e0a\u4f20\n    }\n    \/\/ --- \u6821\u9a8c\u901a\u8fc7 ---\n\n    \/\/ \u539f\u903b\u8f91\uff1a\u751f\u6210\u9ad8\u5f3a\u5ea6\u968f\u673a\u6587\u4ef6\u540d\n    $new_filename = sprintf( '%s_%s.%s', uniqid(), bin2hex( random_bytes( 8 ) ), $claimed_ext );\n    return $new_filename;\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>B. \u5904\u7406\u56fe\u7247\u9a6c\uff08\u7834\u574f\u5d4c\u5165\u6570\u636e\uff09<\/strong><br>\u8fd9\u9700\u8981\u66f4\u590d\u6742\u7684\u56fe\u50cf\u5904\u7406\u3002\u4e00\u4e2a\u76f8\u5bf9\u7b80\u5355\u7684\u65b9\u6cd5\u662f<strong>\u5f3a\u5236\u8f6c\u6362\u56fe\u7247\u683c\u5f0f\u548c\u5c3a\u5bf8<\/strong>\u3002\u6b64\u64cd\u4f5c\u8f83\u590d\u6742\uff0c\u5efa\u8bae\u5728\u5b8c\u6210\u524d\u4e24\u6b65\u5e76\u7a33\u5b9a\u8fd0\u884c\u540e\uff0c\u6838\u5fc3\u601d\u8def\u662f\uff1a\u4f7f\u7528PHP GD\u5e93\u6216Imagick\uff0c\u5c06\u4e0a\u4f20\u7684\u56fe\u7247<strong>\u91cd\u65b0\u91c7\u6837\u3001\u7f29\u653e\u3001\u4fdd\u5b58<\/strong>\uff0c\u8fd9\u4e2a\u8fc7\u7a0b\u4f1a\u5265\u79bb\u6240\u6709\u975e\u50cf\u7d20\u6570\u636e\u3002\uff08\u6211\u653e\u5230\u540e\u9762\u518d\u8bb2\uff09<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u54ce\uff0c\u90a3\u5047\u8bbe\u6211\u53c8\u6709\u4e00\u4e9b\u65b0\u7684\u653b\u51fb\u624b\u6bb5<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6bd4\u65b9\u8bf4\u6211\u91c7\u75281.php.png\u7684\u8fd9\u79cd\u5f62\u5f0f\u4e0a\u4f20,\u53c8\u6216\u80051.pphphp.png\u7684\u5f62\u5f0f\u8fd9\u6837\u5b50\u53ef\u4ee5\u7ee7\u7eed\u5e72\u6270\u4e86.\u8fd8\u6709\u4e00\u4e9b\u5728\u4e92\u8054\u7f51\u4e0a\u4e3a\u4e86\u4fdd\u8bc1\u6267\u884c\u548c\u89e3\u6790\u3002\u53ef\u80fd\u5728\u4e0a\u4f20\u7684\u65f6\u5019\u5c31\u76f4\u63a5\u628a\u6587\u4ef6\u540d\u6539\u6210\u90a3\u79cd\u7ecf\u8fc7URL\u7f16\u7801\u4e4b\u540e\u7684\u6587\u4ef6\u540d\u6765\u8fdb\u884c\u7ed5\u8fc7,\u6240\u4ee5\u8bf4\u5c31\u5355\u5355\u89c9\u5f97\u5355\u5355\u8fd9\u6837\u5b50\u8fd8\u662f\u4e0d\u591f\u7684\u3002<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>.htaccess\u662f\u57fa\u4e8e\u6587\u4ef6\u540d\u548c\u8def\u5f84\u7684\u201c\u89c4\u5219\u5339\u914d\u201d<\/strong>\uff0c\u800c\u653b\u51fb\u8005\u603b\u662f\u8bd5\u56fe<strong>\u6df7\u6dc6\u3001\u5e72\u6270\u6216\u7ed5\u8fc7\u8fd9\u4e9b\u89c4\u5219<\/strong>\u3002<code>.htaccess<\/code>&nbsp;\u662f<strong>\u9632\u5fa1\u94fe\u6761\u4e2d\u7684\u91cd\u8981\u4e00\u73af\uff0c\u4f46\u7edd\u975e\u6700\u7ec8\u9632\u7ebf<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a43-1024x249.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"249\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a43-1024x249.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1376\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5408\u5e76\u540e\u7684\u914d\u7f6e\u5df2\u7ecf\u6bd4\u4e4b\u524d\u5f3a\u5927\uff0c\u7279\u522b\u662f&nbsp;<code>SetHandler None<\/code>&nbsp;\u548c&nbsp;<code>ForceType text\/plain<\/code>&nbsp;\u8bd5\u56fe\u963b\u6b62\u811a\u672c\u6267\u884c\u3002\u7136\u800c\uff0c\u9762\u5bf9\u6211\u63d0\u51fa\u7684\u653b\u51fb\u624b\u6bb5\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u653b\u51fb\u624b\u6cd5<\/th><th>\u73b0\u5728\u7684\u914d\u7f6e\u80fd\u5426\u9632\u5fa1\uff1f<\/th><th>\u539f\u56e0\u5206\u6790<\/th><\/tr><\/thead><tbody><tr><td><strong><code>1.php.png<\/code>&nbsp;(\u6269\u5c55\u540d\u6df7\u6dc6)<\/strong><\/td><td><strong>\u57fa\u672c\u53ef\u4ee5<\/strong><\/td><td><code>&lt;FilesMatch \"\\.(php...)$\"&gt;<\/code>&nbsp;\u5339\u914d<strong>\u672b\u5c3e<\/strong>\u7684&nbsp;<code>.php<\/code>\uff0c<code>1.php.png<\/code>&nbsp;\u672b\u5c3e\u662f&nbsp;<code>.png<\/code>\uff0c\u4e0d\u5339\u914d\uff0c\u56e0\u6b64<strong>\u6587\u4ef6\u4f1a\u88ab\u5141\u8bb8\u4e0a\u4f20<\/strong>\u3002\u4f46\u8fd9\u672c\u8eab\u4e0d\u4e00\u5b9a\u81f4\u547d\uff0c\u56e0\u4e3a\u670d\u52a1\u5668\u901a\u5e38\u6839\u636e<strong>\u6700\u540e\u4e00\u4e2a\u540e\u7f00<\/strong>\uff08<code>.png<\/code>\uff09\u51b3\u5b9aMIME\u7c7b\u578b\uff0c\u4e0d\u4f1a\u6267\u884cPHP\u3002\u4f46\u8fd9\u662f\u5371\u9669\u7684\u5f00\u59cb\u3002<\/td><\/tr><tr><td><strong><code>1.pphphp<\/code>&nbsp;(\u89e3\u6790\u6df7\u6dc6)<\/strong><\/td><td><strong>\u53ef\u80fd\u88ab\u7ed5\u8fc7<\/strong><\/td><td>\u8fd9\u53d6\u51b3\u4e8e\u670d\u52a1\u5668\u7684<strong>\u89e3\u6790\u987a\u5e8f<\/strong>\u548c<strong>\u9012\u5f52\u5220\u9664<\/strong>\u7b56\u7565\u3002\u6709\u4e9b\u65e7\u7248\u6216\u914d\u7f6e\u4e0d\u5f53\u7684\u670d\u52a1\u5668\u53ef\u80fd\u4f1a\u9012\u5f52\u5220\u9664&nbsp;<code>.php<\/code>&nbsp;\u90e8\u5206\uff0c\u6700\u7ec8\u5c06&nbsp;<code>1.pphphp<\/code>&nbsp;\u89e3\u6790\u4e3a&nbsp;<code>1.php<\/code>\u3002\u4f60\u7684\u89c4\u5219\u4f9d\u8d56\u6269\u5c55\u540d\u5339\u914d\uff0c\u53ef\u80fd\u65e0\u6cd5\u62e6\u622a\u3002<\/td><\/tr><tr><td><strong>URL\u7f16\u7801 (<code>1.ph%70hp<\/code>)<\/strong><\/td><td><strong>\u5f88\u53ef\u80fd\u5931\u6548<\/strong><\/td><td><code>.htaccess<\/code>&nbsp;\u89c4\u5219\u901a\u5e38\u5728<strong>URL\u89e3\u7801\u524d<\/strong>\u8fdb\u884c\u5339\u914d\u3002\u56e0\u6b64\uff0c\u5b83\u770b\u5230\u7684\u662f\u539f\u59cb\u5b57\u7b26\u4e32&nbsp;<code>1.ph%70hp<\/code>\uff0c\u4e0d\u4f1a\u5339\u914d&nbsp;<code>\\.(php)<\/code>\u3002\u670d\u52a1\u5668\u89e3\u7801\u540e\uff0c\u8be5\u6587\u4ef6\u53ef\u80fd\u88ab\u6267\u884c\u4e3a&nbsp;<code>1.php<\/code>\u3002<strong>\u8fd9\u662f\u91cd\u5927\u7ed5\u8fc7\u98ce\u9669\u3002<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u5982\u4f55\u6784\u5efa\u9632\u5fa1\uff1f<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u771f\u6b63\u7684\u5b89\u5168\u4e0d\u662f\u5835\u4e00\u4e2a\u6d1e\uff0c\u800c\u662f\u5efa\u7acb\u4e00\u5957<strong>\u65e0\u8bba\u653b\u51fb\u8005\u5982\u4f55\u53d8\u6362\u6587\u4ef6\u540d\uff0c\u90fd\u65e0\u6cd5\u5371\u5bb3\u7cfb\u7edf<\/strong>\u7684\u6d41\u7a0b\u3002\u8fd9\u9700\u8981\u8df3\u51fa&nbsp;<code>.htaccess<\/code>&nbsp;\u7684\u8303\u7574\uff0c\u5efa\u7acb\u56db\u5c42\u4e3b\u52a8\u9632\u5fa1<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u5c42\uff1a\u5e94\u7528\u5c42\u7edd\u5bf9\u63a7\u5236\uff08\u6cbb\u672c\u4e4b\u7b56\uff09<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f\u6211\u4eec\u4e4b\u524d\u8ba8\u8bba\u7684<strong>\u6838\u5fc3\u9632\u5fa1<\/strong>\uff0c\u5fc5\u987b\u5b9e\u65bd\u3002\u5728\u4f60\u7684&nbsp;<code>functions.php<\/code>&nbsp;\u4e2d\u6dfb\u52a0\u4ee3\u7801\uff0c\u5b9e\u73b0\uff1a<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u7acb\u5373\u8f6c\u79fb\u5e76\u91cd\u547d\u540d<\/strong>\uff1a\u4e0a\u4f20\u540e\uff0c\u6587\u4ef6<strong>\u7acb\u523b<\/strong>\u88ab\u79fb\u51faWeb\u6839\u76ee\u5f55\uff08\u5982&nbsp;<code>\/home\/user\/private_<\/code>\uff09\u5e76\u91cd\u547d\u540d\u4e3a\u968f\u673a\u5b57\u7b26\u4e32\uff08\u5982&nbsp;<code>a1b2c3d4e5<\/code>\uff09\u3002<strong>\u653b\u51fb\u8005\u5373\u4f7f\u4e0a\u4f20\u6210\u529f\uff0c\u4e5f\u6c38\u8fdc\u4e0d\u77e5\u9053\u6587\u4ef6\u5728\u54ea\u3001\u53eb\u4ec0\u4e48\u3002<\/strong><\/li>\n\n\n\n<li><strong>\u9a8c\u8bc1\u6587\u4ef6\u201c\u9b54\u6570\u201d<\/strong>\uff1a\u7528PHP\u7684&nbsp;<code>finfo_file()<\/code>&nbsp;\u51fd\u6570\u8bfb\u53d6\u6587\u4ef6<strong>\u5934\u90e8\u5b57\u8282\u7b7e\u540d<\/strong>\uff08\u5982&nbsp;<code>FF D8 FF E0<\/code>&nbsp;\u4ee3\u8868JPEG\uff09\uff0c\u5224\u65ad\u771f\u5b9e\u7c7b\u578b\uff0c\u4e0e\u540e\u7f00\u540d\u4e25\u683c\u6bd4\u5bf9\u3002\u8fd9\u53ef\u4ee5\u9632\u5fa1\u6240\u6709\u6587\u4ef6\u540d\/\u7f16\u7801\u6b3a\u9a97\u3002<\/li>\n\n\n\n<li><strong>\u56fe\u7247\u6587\u4ef6\u201c\u518d\u7f16\u7801\u201d<\/strong>\uff1a\u5bf9\u5141\u8bb8\u7684\u56fe\u7247\uff0c\u7528GD\u5e93\u6216Imagick\u8fdb\u884c<strong>\u91cd\u65b0\u91c7\u6837\u3001\u538b\u7f29\u3001\u4fdd\u5b58<\/strong>\u3002\u8fd9\u4f1a\u5f7b\u5e95\u7834\u574f\u56fe\u7247\u4e2d\u9690\u85cf\u7684\u4efb\u4f55\u975e\u56fe\u50cf\u6570\u636e\uff08\u5982\u56fe\u7247\u9a6c\uff09\u3002<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e8c\u5c42\uff1a\u670d\u52a1\u5668\u89e3\u6790\u5c42\u52a0\u56fa\uff08\u5f25\u8865\u6f0f\u6d1e\uff09<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u7f51\u7ad9\u7684<strong>\u4e3b&nbsp;<code>.htaccess<\/code><\/strong>\uff08\u4f4d\u4e8e\u7f51\u7ad9\u6839\u76ee\u5f55\uff09\u6216\u865a\u62df\u4e3b\u673a\u914d\u7f6e\u4e2d\uff0c\u6dfb\u52a0\u4ee5\u4e0b\u89c4\u5219\uff0c\u53ef\u4ee5\u9632\u5fa1\u4e00\u4e9b\u670d\u52a1\u5668\u89e3\u6790\u6f0f\u6d1e\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># \u9632\u6b62\u5c06\u56fe\u7247\u6587\u4ef6\u5f53\u4f5cPHP\u89e3\u6790\uff08\u9632\u5fa1\u89e3\u6790\u6f0f\u6d1e\uff09\n&lt;FilesMatch \"\\.(php|php5|phtml|pl|py|jsp|asp|cgi)$\"&gt;\n    # \u65e0\u6761\u4ef6\u62d2\u7edd\u8bbf\u95ee\u4efb\u4f55\u811a\u672c\u6587\u4ef6\n    Require all denied\n&lt;\/FilesMatch&gt;\n\n# \u7279\u522b\u9632\u5fa1\uff1a\u5373\u4f7f\u6709 .php \u540e\u7f00\u7684\u56fe\u7247\u4e5f\u62d2\u7edd\n&lt;FilesMatch \"^.*\\.(php\\.(png|jpg|gif))$\"&gt;\n    Require all denied\n&lt;\/FilesMatch&gt;<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e09\u5c42\uff1aWeb\u76ee\u5f55\u9694\u79bb<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3a&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u8bbe\u7f6e\u7684&nbsp;<code>.htaccess<\/code>&nbsp;(<code>Require all denied<\/code>)&nbsp;<strong>\u5fc5\u987b\u4fdd\u7559<\/strong>\u3002\u8fd9\u662f\u6700\u540e\u4e00\u9053\u7269\u7406\u5c4f\u969c\uff0c\u5373\u4f7f\u6709\u6587\u4ef6\u56e0\u672a\u77e5\u6f0f\u6d1e\u88ab\u653e\u5230\u4e86\u8fd9\u91cc\uff0c\u4e5f\u65e0\u6cd5\u76f4\u63a5\u8bbf\u95ee\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u56db\u5c42\uff1a\u8fd0\u7ef4\u5c42\u9762\u9632\u62a4<\/strong><\/h4>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u4fdd\u6301\u6240\u6709\u8f6f\u4ef6\u66f4\u65b0<\/strong>\uff1aWordPress\u6838\u5fc3\u3001\u63d2\u4ef6\u3001\u4e3b\u9898\u3001PHP\u7248\u672c\u3001\u670d\u52a1\u5668\u7cfb\u7edf\u3002<\/li>\n\n\n\n<li><strong>\u4f7f\u7528\u4e13\u4e1a\u5b89\u5168\u63d2\u4ef6<\/strong>\uff1a\u5982&nbsp;<strong>Wordfence<\/strong>\uff0c\u5b83\u5177\u5907<strong>\u9632\u706b\u5899<\/strong>\u548c<strong>\u6587\u4ef6\u5b8c\u6574\u6027\u76d1\u63a7<\/strong>\u529f\u80fd\uff0c\u80fd\u4e3b\u52a8\u963b\u65ad\u53ef\u7591\u8bf7\u6c42\uff0c\u5e76\u5728\u6587\u4ef6\u88ab\u7be1\u6539\u65f6\u62a5\u8b66\u3002<\/li>\n\n\n\n<li><strong>\u6700\u5c0f\u5316\u66b4\u9732<\/strong>\uff1a\u670d\u52a1\u5668\u9519\u8bef\u9875\u9762\u4e0d\u663e\u793a\u8def\u5f84\u4fe1\u606f\u3002<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">Nginx\u7248\u672c<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ec0\u4e48\u4f60\u544a\u8bc9\u6211\u4f60\u7684\u914d\u7f6e\u5df2\u7ecf\u4fee\u6539\u5b8c\u4e86\uff0c\u4f46\u662f\u6d4b\u8bd5\u7684\u65f6\u5019\u5374\u6ca1\u6709\u8fd4\u56de\u6548\u679c\u2026..<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f\u4e00\u4e2a\u975e\u5e38\u5173\u952e\u7684\u95ee\u9898\uff0c\u8bf4\u660e\u5b89\u5168\u5c4f\u969c\u6ca1\u6709\u751f\u6548\u3002403\u672a\u51fa\u73b0\uff0c\u901a\u5e38\u610f\u5473\u7740&nbsp;<strong><code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u672a\u88abApache\u670d\u52a1\u5668\u6b63\u786e\u8bfb\u53d6\u6216\u6267\u884c<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a44-560x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"560\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a44-560x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1377\" style=\"aspect-ratio:0.5468787087586043;width:840px;height:auto\"  sizes=\"auto, (max-width: 560px) 100vw, 560px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e00\u6b65\uff1a\u6700\u53ef\u80fd\u7684\u539f\u56e0\u2014\u2014\u6587\u4ef6\u653e\u9519\u4e86\u4f4d\u7f6e<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><code>.htaccess<\/code>&nbsp;\u7684\u89c4\u5219<strong>\u53ea\u5bf9\u5b83\u6240\u5728\u76ee\u5f55\u53ca\u5176\u5b50\u76ee\u5f55\u751f\u6548<\/strong>\u3002\u4f60\u5fc5\u987b\u5c06\u6587\u4ef6\u653e\u5728\u4f60\u60f3\u8981\u4fdd\u62a4\u7684\u90a3\u4e2a<strong>\u5177\u4f53\u6587\u4ef6\u5939<\/strong>\u91cc\u3002<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u8bf7\u518d\u6b21\u786e\u8ba4<\/strong>\uff1a\u4f60\u4fee\u6539\u7684\u662f\u54ea\u4e2a&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\uff1f\u4f60\u9700\u8981\u4fdd\u62a4\u7684\u662f&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u3002<\/li>\n\n\n\n<li><strong>\u6b63\u786e\u8def\u5f84<\/strong>\uff1a\u5305\u542b&nbsp;<code>Require all denied<\/code>&nbsp;\u89c4\u5219\u7684&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\uff0c\u5fc5\u987b\u4f4d\u4e8e\u4ee5\u4e0b\u8def\u5f84\uff1a<br><code>\/wp-content\/uploads\/wpcf7_uploads\/.htaccess<\/code><br>\uff08\u8bf7\u6ce8\u610f\u6587\u4ef6\u540d\u4ee5\u70b9\u5f00\u5934\uff09<\/li>\n\n\n\n<li><strong>\u68c0\u67e5\u65b9\u6cd5<\/strong>\uff1a\u7528FTP\u6216\u6587\u4ef6\u7ba1\u7406\u5668\uff0c\u5bfc\u822a\u5230\u8fd9\u4e2a\u76ee\u5f55\uff0c\u786e\u8ba4&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6<strong>\u5c31\u5728\u8fd9\u91cc<\/strong>\uff0c\u800c\u4e0d\u662f\u5728\u7f51\u7ad9\u6839\u76ee\u5f55\u6216\u5176\u4ed6\u5730\u65b9\u3002<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"> \u7b2c\u4e8c\u6b65\uff1a\u68c0\u67e5\u89c4\u5219\u672c\u8eab\u4e0e\u670d\u52a1\u5668\u73af\u5883<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u89c4\u5219\u72ec\u7acb\u6027<\/strong>\uff1a\u786e\u4fdd\u4f60\u7684\u89c4\u5219<strong>\u6ca1\u6709\u9519\u8bef\u5730\u5d4c\u5957<\/strong>\u5728&nbsp;<code>&lt;IfModule mod_rewrite.c&gt;<\/code>&nbsp;\u6216&nbsp;<code># BEGIN WordPress<\/code>&nbsp;\u7b49\u4efb\u4f55\u5176\u4ed6\u6a21\u5757\u533a\u5757\u5185\u3002\u5728&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u4e0b\u7684&nbsp;<code>.htaccess<\/code>\uff0c\u5185\u5bb9\u5e94\u8be5<strong>\u53ea\u6709\u7eaf\u7cb9\u7684\u5b89\u5168\u89c4\u5219<\/strong>\uff0c\u4f8b\u5982\uff1aapache# \u65e0\u6761\u4ef6\u62d2\u7edd\u6240\u6709\u8bbf\u95ee Require all denied Options -Indexes<strong>\u4e0d\u8981<\/strong>\u5305\u542b&nbsp;<code>RewriteEngine On<\/code>&nbsp;\u7b49WordPress\u91cd\u5199\u89c4\u5219\u3002<\/li>\n\n\n\n<li><strong>\u6d4b\u8bd5&nbsp;<code>.htaccess<\/code>&nbsp;\u662f\u5426\u88ab\u8bfb\u53d6<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u5728\u6d4f\u89c8\u5668\u4e2d\u5c1d\u8bd5\u76f4\u63a5\u8bbf\u95ee&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u672c\u8eab\uff0c\u4f8b\u5982\uff1a<br><code>http:\/\/www.preluna.xyz\/wp-content\/uploads\/wpcf7_uploads\/.htaccess<\/code><\/li>\n\n\n\n<li><strong>\u9884\u671f\u7ed3\u679c<\/strong>\uff1a\u5e94\u8be5\u8fd4\u56de&nbsp;<strong>403 Forbidden<\/strong>&nbsp;\u6216&nbsp;<strong>500 Internal Server Error<\/strong>\u3002\u8fd9\u8bf4\u660e\u670d\u52a1\u5668\u8bc6\u522b\u5e76\u4fdd\u62a4\u4e86\u8be5\u6587\u4ef6\uff0c\u89c4\u5219\u6b63\u5728\u5de5\u4f5c\u3002<\/li>\n\n\n\n<li><strong>\u9519\u8bef\u7ed3\u679c<\/strong>\uff1a\u5982\u679c\u8fd4\u56de&nbsp;<strong>404 Not Found<\/strong>\uff0c\u8bf4\u660e\u6587\u4ef6\u540d\u9519\u8bef\uff08\u53ef\u80fd\u6f0f\u4e86\u5f00\u5934\u7684\u70b9\uff0c\u6210\u4e86&nbsp;<code>htaccess<\/code>\uff09\u3002\u5982\u679c\u53ef\u4ee5<strong>\u76f4\u63a5\u770b\u5230\u6587\u4ef6\u5185\u5bb9<\/strong>\uff0c\u5219\u8bf4\u660e\u670d\u52a1\u5668\u5b8c\u5168\u5ffd\u7565\u6b64\u6587\u4ef6\uff0c\u8fd9\u662f\u6700\u4e25\u91cd\u7684\u60c5\u51b5\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e09\u6b65\uff1a\u7ec8\u6781\u53ef\u80fd\u2014\u2014\u670d\u52a1\u5668\u4e0d\u662fApache<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4e0a\u8ff0\u6240\u6709\u68c0\u67e5\u90fd\u6b63\u786e\uff0c\u4f46\u89c4\u5219\u4f9d\u7136\u65e0\u6548\uff0c\u6700\u5927\u7684\u53ef\u80fd\u6027\u662f\u4f60\u7684\u7f51\u7ad9\u6258\u7ba1\u5728&nbsp;<strong>Nginx<\/strong>&nbsp;\u670d\u52a1\u5668\u4e0a\u3002<strong>Nginx \u670d\u52a1\u5668\u4e0d\u8bfb\u53d6&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6<\/strong>\uff0c\u56e0\u6b64\u6240\u6709\u914d\u7f6e\u90fd\u65e0\u6548\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5982\u4f55\u5224\u65ad\uff1f<\/strong><br>\u67e5\u770b\u4e3b\u673a\u63a7\u5236\u9762\u677f\u4fe1\u606f\uff0c\u786e\u8ba4\u670d\u52a1\u5668\u7c7b\u578b\u3002\u4e00\u4e2a\u95f4\u63a5\u5224\u65ad\u65b9\u6cd5\u662f\uff1a\u5982\u679c\u4f60\u7684\u7f51\u7ad9\u6839\u76ee\u5f55\u6ca1\u6709&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6\u4e5f\u80fd\u6b63\u5e38\u8fd0\u884c\uff08\u7279\u522b\u662f\u56fa\u5b9a\u94fe\u63a5\uff09\uff0c\u90a3\u4e48\u5f88\u53ef\u80fd\u7528\u7684\u662fNginx\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5982\u679c\u786e\u8ba4\u662fNginx\uff0c\u89e3\u51b3\u65b9\u6848\u5982\u4e0b\uff1a<\/strong><br>\u4f60\u9700\u8981\u5c06&nbsp;<code>.htaccess<\/code>&nbsp;\u4e2d\u7684\u89c4\u5219\u7ffb\u8bd1\u6210 Nginx \u7684\u914d\u7f6e\u8bed\u6cd5\uff0c\u5e76\u6dfb\u52a0\u5230\u7f51\u7ad9\u7684&nbsp;<strong>Nginx \u914d\u7f6e\u6587\u4ef6\u4e2d<\/strong>\uff08\u901a\u5e38\u4f4d\u4e8e&nbsp;<code>\/etc\/nginx\/sites-available\/<\/code>&nbsp;\u4f60\u7684\u7f51\u7ad9.conf`\uff09\u3002\u8fd9\u901a\u5e38\u9700\u8981\u8054\u7cfb\u4e3b\u673a\u5546\u6216\u62e5\u6709\u670d\u52a1\u5668\u6743\u9650\u7684\u7ba1\u7406\u5458\u6765\u64cd\u4f5c\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u5e94\u89c4\u5219\u5982\u4e0b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>location ^~ \/wp-content\/uploads\/wpcf7_uploads\/ {\n    # \u65e0\u6761\u4ef6\u62d2\u7edd\u6240\u6709\u8bbf\u95ee\n    deny all;\n    # \u8fd4\u56de403\u9519\u8bef\n    return 403;\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Nginx \u670d\u52a1\u5668\u5b8c\u5168\u4e0d\u8bfb\u53d6\u4e5f\u4e0d\u7406\u4f1a&nbsp;<code>.htaccess<\/code>&nbsp;\u6587\u4ef6<\/strong>\u3002\u5728&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u4e0b\u653e\u7f6e&nbsp;<code>.htaccess<\/code>&nbsp;\u6216\u5728\u7f51\u7ad9\u6839\u76ee\u5f55\u4fee\u6539\u5b83\uff0c\u5bf9 Nginx \u6765\u8bf4\u90fd\u662f\u65e0\u6548\u7684\uff0c\u8fd9\u5c31\u662f\u4f9d\u7136\u53ef\u4ee5\u8bbf\u95ee&nbsp;<code>.php<\/code>&nbsp;\u6587\u4ef6\u7684\u6839\u672c\u539f\u56e0\u3002\u9700\u8981\u5728&nbsp;<strong>Nginx \u7684\u670d\u52a1\u5668\u914d\u7f6e\u6587\u4ef6<\/strong>\u4e2d\u8bbe\u7f6e\u89c4\u5219\u3002\u8fd9\u5bf9\u4e8e\u666e\u901a\u7f51\u7ad9\u6240\u6709\u8005\u6765\u8bf4\uff0c\u901a\u5e38\u65e0\u6cd5\u76f4\u63a5\u64cd\u4f5c\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a45-666x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"666\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a45-666x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1378\"  sizes=\"auto, (max-width: 666px) 100vw, 666px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u89e3\u51b3\u65b9\u6848\uff1a\u5c06\u89c4\u5219\u6dfb\u52a0\u5230 Nginx \u914d\u7f6e\u4e2d<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u9700\u8981\u5c06\u4ee5\u4e0b\u914d\u7f6e\u89c4\u5219\u6dfb\u52a0\u5230\u7f51\u7ad9\u7684&nbsp;<strong>Nginx \u670d\u52a1\u5668\u914d\u7f6e\u5757\uff08Server Block\uff09<\/strong>&nbsp;\u4e2d\u3002\u8fd9\u4e2a\u6587\u4ef6\u901a\u5e38\u4f4d\u4e8e&nbsp;<code>\/etc\/nginx\/sites-available\/<\/code>&nbsp;\u76ee\u5f55\u4e0b\uff0c\u540d\u4e3a\u60a8\u7684\u57df\u540d\uff08\u5982&nbsp;<code>preluna.xyz<\/code>\uff09\u6216\u4ee5&nbsp;<code>default<\/code>&nbsp;\u547d\u540d\u7684\u6587\u4ef6\u3002\u8bf7\u5c06\u4ee5\u4e0b\u4ee3\u7801\u6bb5\uff0c\u6dfb\u52a0\u5230\u60a8\u7f51\u7ad9Nginx\u914d\u7f6e\u6587\u4ef6\u4e2d&nbsp;<code>server { ... }<\/code>&nbsp;\u5927\u62ec\u53f7\u5185\u7684\u4efb\u610f\u4f4d\u7f6e\uff08\u901a\u5e38\u653e\u5728&nbsp;<code>location \/ { ... }<\/code>&nbsp;\u5757\u4e4b\u524d\u6216\u4e4b\u540e\uff09\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># === 1. \u6838\u5fc3\u9632\u62a4\uff1a\u5f7b\u5e95\u7981\u6b62\u8bbf\u95ee\u4e0a\u4f20\u76ee\u5f55 ===\n# \u6b64\u89c4\u5219\u4f18\u5148\u7ea7\u6700\u9ad8\uff0c\u5339\u914d \/wp-content\/uploads\/wpcf7_uploads\/ \u4e0b\u7684\u6240\u6709\u8bf7\u6c42\nlocation ~* ^\/wp-content\/uploads\/wpcf7_uploads\/ {\n    deny all;\n    return 403;\n}\n\n# === 2. \u9632\u6b62\u6076\u610f\u811a\u672c\u4f2a\u88c5\u6210\u56fe\u7247\u6267\u884c\uff08\u9632\u5fa1\u56fe\u7247\u9a6c\u7b49\uff09===\n# \u5339\u914d\u4efb\u4f55\u8bd5\u56fe\u4ee5\u56fe\u7247\u540e\u7f00\u7ed3\u5c3e\u7684PHP\u6587\u4ef6\uff0c\u5982 shell.php.jpg\nlocation ~* \\.php\\.(jpg|jpeg|png|gif|webp)$ {\n    deny all;\n    return 403;\n}\n\n# === 3. \u9632\u6b62\u76f4\u63a5\u8bbf\u95ee\u654f\u611f\u811a\u672c\u6587\u4ef6\uff08\u5168\u5c40\u751f\u6548\uff09 ===\n# \u5339\u914d\u4efb\u4f55\u76ee\u5f55\u4e0b\u7684PHP\u7b49\u811a\u672c\u6587\u4ef6\nlocation ~* \\.(php|php5|php7|phtml|pl|py|jsp|asp|sh|cgi)$ {\n    # \u4f46\u5fc5\u987b\u653e\u884cWordPress\u6838\u5fc3\u7684index.php\u548cadmin-ajax.php\u7b49\uff0c\u5426\u5219\u7f51\u7ad9\u4f1a\u762b\u75ea\n    location ~* ^\/index\\.php$ { }\n    location ~* \/wp-admin\/admin-ajax\\.php$ { }\n    # \u9664\u4e86\u4e0a\u9762\u653e\u884c\u7684\uff0c\u5176\u4ed6\u6240\u6709\u811a\u672c\u8bf7\u6c42\u4e00\u5f8b\u62d2\u7edd\n    deny all;\n    return 403;\n}\n\n# === 4. \u7981\u6b62\u8bbf\u95ee\u9690\u85cf\u6587\u4ef6\uff08\u5982 .git\u3001.env\u3001.htaccess \u672c\u8eab\uff09 ===\nlocation ~ \/\\.(?!well-known) {\n    deny all;\n    return 403;\n}<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7b2c1\u6761\u89c4\u5219<\/strong>\uff1a\u662f\u6700\u8feb\u5207\u9700\u8981\u7684\uff0c\u5b83\u8ba9\u4efb\u4f55\u8bd5\u56fe\u76f4\u63a5\u8bbf\u95ee\u6295\u7a3f\u6587\u4ef6\u7684\u8bf7\u6c42\u7acb\u5373\u8fd4\u56de 403 \u9519\u8bef\u3002<\/li>\n\n\n\n<li><strong>\u7b2c2\u30013\u30014\u6761\u89c4\u5219<\/strong>\uff1a\u662f\u6df1\u5ea6\u52a0\u56fa\uff0c\u9632\u5fa1\u56fe\u7247\u9a6c\u3001\u811a\u672c\u6267\u884c\u7b49\u9ad8\u7ea7\u5a01\u80c1\uff0c\u5e76\u4fdd\u62a4\u670d\u52a1\u5668\u914d\u7f6e\u6587\u4ef6\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u64cd\u4f5c\u540e\u9a8c\u8bc1<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u914d\u7f6e\u4fdd\u5b58\u540e\uff0c<strong>\u5fc5\u987b\u6267\u884c\u4ee5\u4e0b\u547d\u4ee4\u91cd\u8f7d Nginx \u914d\u7f6e<\/strong>\u624d\u80fd\u751f\u6548\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo nginx -t  # \u6d4b\u8bd5\u914d\u7f6e\u6587\u4ef6\u8bed\u6cd5\u662f\u5426\u6b63\u786e\nsudo systemctl reload nginx  # \u6216 sudo service nginx reload \uff08\u91cd\u8f7d\u670d\u52a1\uff09<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u751f\u6548\u6d4b\u8bd5<\/strong>\uff1a<br>\u5728\u6d4f\u89c8\u5668\u8bbf\u95ee\uff1a<code>http:\/\/www.preluna.xyz\/wp-content\/uploads\/wpcf7_uploads\/\u4efb\u610f\u6587\u4ef6\u540d<\/code><br>\u5e94\u8be5\u7acb\u5373\u770b\u5230&nbsp;<strong>\u201c403 Forbidden\u201d<\/strong>&nbsp;\u9519\u8bef\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a46-1024x140.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"140\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a46-1024x140.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1379\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;\u8fd4\u56de&nbsp;<strong>\u201c404 \u672a\u627e\u5230\u201d<\/strong>&nbsp;\u610f\u5473\u7740Nginx\u6210\u529f\u62e6\u622a\u4e86\u8bf7\u6c42\uff0c\u5e76\u4f2a\u88c5\u6210\u201c\u8be5\u6587\u4ef6\u4e0d\u5b58\u5728\u201d\uff0c\u8fd9\u6bd4\u76f4\u63a5\u8fd4\u56de&nbsp;<strong>\u201c403 \u7981\u6b62\u8bbf\u95ee\u201d<\/strong>&nbsp;\u5728\u5b89\u5168\u4e0a\u751a\u81f3\u66f4\u9690\u853d\u3001\u66f4\u53cb\u597d\uff08\u4e0d\u7ed9\u653b\u51fb\u8005\u4efb\u4f55\u63d0\u793a\uff09\u3002\u8fd9\u901a\u5e38\u662f\u7531\u914d\u7f6e\u6587\u4ef6\u4e2d\u539f\u6709\u7684\u53e6\u4e00\u6761\u901a\u7528\u89c4\u5219\u9020\u6210\u7684\u3002\u5728\u914d\u7f6e\u4e2d\uff0c\u6709\u8fd9\u6837\u7684\u89c4\u5219\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>location ~ .*\\.(gif|jpg|jpeg|png|bmp|swf)$\n{\n    expires      30d;\n    error_log \/dev\/null;\n    access_log \/dev\/null; # \u8fd9\u4e00\u884c\u662f\u5173\u952e\uff01\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u6ce8\u610f\u5176\u4e2d\u7684&nbsp;<code>access_log \/dev\/null;<\/code>\u3002\u5f53\u65b0\u6dfb\u52a0\u7684\u5b89\u5168\u89c4\u5219&nbsp;<code>location ~* ^\/wp-content\/uploads\/wpcf7_uploads\/<\/code>&nbsp;\u751f\u6548\u5e76&nbsp;<code>deny all;<\/code>&nbsp;\u540e\uff0cNginx\u4f1a\u7ee7\u7eed\u5411\u4e0b\u5339\u914d\u5176\u4ed6\u89c4\u5219\u3002\u8fd9\u4e2a\u56fe\u7247\u89c4\u5219\u4e5f\u5339\u914d\u5230\u4e86&nbsp;<code>.jpg<\/code>&nbsp;\u540e\u7f00\uff0c\u5e76\u6267\u884c\u4e86&nbsp;<code>access_log \/dev\/null;<\/code>\u3002\u6709\u65f6\uff0c\u8fd9\u79cd\u7ec4\u5408\uff08\u62d2\u7edd\u8bbf\u95ee+\u9759\u9ed8\u65e5\u5fd7\uff09\u4f1a\u5bfc\u81f4Nginx\u6700\u7ec8\u8fd4\u56de\u4e00\u4e2a&nbsp;<strong>404<\/strong>&nbsp;\u72b6\u6001\u7801\u3002<strong>\u8fd9\u5b8c\u5168\u8fbe\u5230\u4e86\u4e00\u5f00\u59cb\u7684\u5b89\u5168\u76ee\u7684\u3002<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u54ce\uff0c\u90a3\u5982\u679c\u6211\u60f3\u8981\u901a\u8fc7\u8fd4\u56de\u6a21\u7cca\u7684\u9519\u8bef\u4fe1\u606f\u6765\u8ff7\u60d1\u653b\u51fb\u8005\u5462\uff1f<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f\u4e00\u79cd\u975e\u5e38\u6709\u6548\u7684\u201c\u5b89\u5168\u6df7\u6dc6\u201d\u7b56\u7565<a href=\"https:\/\/ftpeak.blog.csdn.net\/article\/details\/146451203\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u3002\u8fd9\u4e0e\u5355\u7eaf\u8fd4\u56de404\uff08\u8d44\u6e90\u4e0d\u5b58\u5728\uff09\u6216403\uff08\u7981\u6b62\u8bbf\u95ee\uff09\u76f8\u6bd4\uff0c\u80fd\u66f4\u6709\u6548\u5730\u589e\u52a0\u653b\u51fb\u8005\u7684\u5224\u65ad\u6210\u672c\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u8981\u5b9e\u73b0\u8fd9\u79cd\u6548\u679c\uff0c\u6838\u5fc3\u662f\u4fee\u6539\u670d\u52a1\u5668\u914d\u7f6e\uff0c\u5f53\u8bbf\u95ee\u88ab\u963b\u6b62\u7684\u8d44\u6e90\u65f6\uff0c\u4e0d\u8fd4\u56de\u660e\u786e\u7684\u72b6\u6001\u7801\uff0c\u800c\u662f\u8fd4\u56de\u4e00\u4e2a<strong>\u6a21\u68f1\u4e24\u53ef<\/strong>\u7684\u54cd\u5e94\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e3b\u6d41\u6df7\u6dc6\u65b9\u6848\u5bf9\u6bd4\uff0c\u53ef\u4ee5\u6839\u636e\u6df7\u6dc6\u6548\u679c\u548c\u5b9e\u73b0\u96be\u5ea6\u6765\u9009\u62e9\uff1a<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u65b9\u6848<\/th><th>\u6838\u5fc3\u539f\u7406<\/th><th>\u6548\u679c\u4e0e\u4f18\u70b9<\/th><th>\u6f5c\u5728\u7f3a\u70b9<\/th><\/tr><\/thead><tbody><tr><td><strong>\u8fd4\u56de 200 OK + \u901a\u7528\u9875\u9762<\/strong><\/td><td>\u65e0\u8bba\u6587\u4ef6\u662f\u5426\u5b58\u5728\uff0c\u5747\u8fd4\u56de<code>200<\/code>\u72b6\u6001\u7801\u548c\u4e00\u4e2a<strong>\u7a7a\u767d\u9875\/\u8bef\u5bfc\u6027\u9875\u9762<\/strong>\u3002<\/td><td><strong>\u6df7\u6dc6\u6548\u679c\u6700\u4f73<\/strong>\u3002\u653b\u51fb\u8005\u65e0\u6cd5\u901a\u8fc7\u72b6\u6001\u7801\u5224\u65ad\u662f\u6210\u529f\u3001\u88ab\u62d2\u8fd8\u662f\u8def\u5f84\u9519\u8bef\u3002<\/td><td>\u53ef\u80fd\u5f71\u54cdSEO\uff08\u641c\u7d22\u5f15\u64ce\u53ef\u80fd\u6536\u5f55\u65e0\u6548\u8def\u5f84\uff09\u3002<\/td><\/tr><tr><td><strong>\u8fd4\u56de 410 Gone\uff08\u5df2\u5220\u9664<\/strong><\/td><td>\u8fd4\u56de<code>410<\/code>\u72b6\u6001\u7801\uff0c\u8868\u793a\u8d44\u6e90<strong>\u66fe\u5b58\u5728\u4f46\u5df2\u6c38\u4e45\u5220\u9664<\/strong>\u3002<\/td><td>\u80fd\u6709\u6548\u8bef\u5bfc\u653b\u51fb\u8005\uff0c\u8ba9\u5176\u8ba4\u4e3a\u63a2\u6d4b\u7684\u8def\u5f84\u5df2\u5931\u6548\u3002<\/td><td>\u4e0e\u201c404\u201d\u7c7b\u4f3c\uff0c\u4ecd\u662f\u4e00\u4e2a\u660e\u786e\u7684\u72b6\u6001\u7801\u3002<\/td><\/tr><tr><td><strong>\u8fd4\u56de 403 Forbidden\uff08\u7981\u6b62\u8bbf\u95ee\uff09<\/strong><\/td><td>\u8fd4\u56de<code>403<\/code>\u72b6\u6001\u7801\uff0c\u8868\u793a\u8d44\u6e90\u5b58\u5728\u4f46\u65e0\u6743\u9650\u3002<\/td><td>\u6bd4404\u66f4\u5177\u8ff7\u60d1\u6027\uff0c\u80fd\u8ba9\u653b\u51fb\u8005\u8bef\u4ee5\u4e3a\u89e6\u53d1\u4e86\u6743\u9650\u7cfb\u7edf<\/td><td>\u72b6\u6001\u7801\u672c\u8eab\u4ecd\u6697\u793a\u4e86\u8def\u5f84\u201c\u5b58\u5728\u201d\u3002<\/td><\/tr><tr><td><strong>\u91cd\u5b9a\u5411\u5230\u5176\u4ed6\u9875\u9762<\/strong><\/td><td>\u5c06\u8bf7\u6c42<strong>302\/301\u91cd\u5b9a\u5411<\/strong>\u5230\u9996\u9875\u3001\u767b\u5f55\u9875\u6216\u4e00\u4e2a\u968f\u673a\u9519\u8bef\u9875\u9762\u3002<\/td><td>\u76f4\u63a5\u6253\u65ad\u653b\u51fb\u8005\u7684\u63a2\u6d4b\u6d41\u7a0b\uff0c\u589e\u52a0\u5176\u5206\u6790\u96be\u5ea6\u3002<\/td><td>\u91cd\u5b9a\u5411\u94fe\u6761\u53ef\u80fd\u88ab\u81ea\u52a8\u5316\u5de5\u5177\u8ddf\u8e2a\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u5982\u4f55\u914d\u7f6e Nginx<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ee5\u4e0b\u662f<strong><strong>\u8fd4\u56de 200 OK + \u901a\u7528\u9875\u9762<\/strong><\/strong>\u7684\u914d\u7f6e\u65b9\u6cd5\uff0c\u4f60\u9700\u8981\u5c06\u5176\u6dfb\u52a0\u5230\u4f60\u7684Nginx\u7f51\u7ad9\u914d\u7f6e\u6587\u4ef6\u7684&nbsp;<code>server<\/code>&nbsp;\u5757\u4e2d\u5408\u9002\u7684\u4f4d\u7f6e\uff08\u4f8b\u5982\uff0c\u653e\u5728\u4e4b\u524d\u6dfb\u52a0\u7684\u5b89\u5168\u89c4\u5219\u9644\u8fd1\uff09\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u5b9a\u4e49\u4e00\u4e2a\u7528\u4e8e\u5904\u7406\u201c\u4e0d\u5b58\u5728\u8def\u5f84\u201d\u7684\u901a\u7528\u4f4d\u7f6e\u5757\nlocation @generic_error {\n    # \u8fd4\u56de200\u72b6\u6001\u7801\u548c\u4e00\u4e2a\u975e\u5e38\u7b80\u77ed\u7684\u901a\u7528\u5185\u5bb9\uff08\u6216\u7a7a\u767d\uff09\n    return 200 \"\u670d\u52a1\u8bf7\u6c42\u5f02\u5e38\uff0c\u8bf7\u7a0d\u540e\u518d\u8bd5\u3002\";\n    # \u4f60\u4e5f\u53ef\u4ee5\u5c06\u5176\u6307\u5411\u4e00\u4e2a\u5185\u5bb9\u8ff7\u60d1\u7684HTML\u6587\u4ef6\n    # return 200 \/path\/to\/confusing_page.html;\n}\n\n# 2. \u5728\u4f60\u7684\u9632\u62a4location\u5757\u4e2d\uff0c\u4f7f\u7528 try_files \u5e76\u6307\u5411\u4e0a\u8ff0\u901a\u7528\u5904\u7406\n# \u4fee\u6539\u4f60\u4e4b\u524d\u4e3a wpcf7_uploads \u76ee\u5f55\u5199\u7684\u89c4\u5219\uff1a\nlocation ~* ^\/wp-content\/uploads\/wpcf7_uploads\/ {\n    # \u5c1d\u8bd5\u8bbf\u95ee\u6587\u4ef6\uff0c\u5982\u679c\u4e0d\u5b58\u5728\uff08\u8fd9\u662f\u5fc5\u7136\u7684\uff09\uff0c\u5219\u5185\u90e8\u8df3\u8f6c\u5230 @generic_error\n    try_files $uri @generic_error;\n    # \u540c\u65f6\uff0c\u4e3a\u4e86\u7edd\u5bf9\u5b89\u5168\uff0c\u5728\u6b64\u5904\u4e5f\u4fdd\u7559deny all\u6307\u4ee4\uff08\u4f5c\u4e3a\u7b2c\u4e8c\u9053\u9632\u7ebf\uff09\n    deny all;\n    access_log \/dev\/null;\n    log_not_found off; # \u53ef\u9009\uff1a\u4e0d\u5728\u9519\u8bef\u65e5\u5fd7\u4e2d\u8bb0\u5f55404\uff0c\u51cf\u5c11\u4fe1\u606f\u6cc4\u9732&#91;citation:3]\n}\n\n# 3. \uff08\u53ef\u9009\uff09\u5c06\u8fd9\u79cd\u6df7\u6dc6\u5e94\u7528\u5230\u66f4\u5e7f\u6cdb\u7684\u8303\u56f4\uff0c\u4f8b\u5982\u6240\u6709\u4e0d\u5b58\u5728\u7684\u8def\u5f84\nlocation \/ {\n    try_files $uri $uri\/ =404; # \u8fd9\u662f\u9ed8\u8ba4\u884c\u4e3a\uff0c\u4f60\u53ef\u4ee5\u6539\u4e3a\uff1a\n    # try_files $uri $uri\/ @generic_error; # \u8ba9\u6574\u4e2a\u7f51\u7ad9\u5bf9\u65e0\u6548\u8def\u5f84\u90fd\u8fd4\u56de\u6df7\u6dc6\u4fe1\u606f\n}<\/code><\/pre>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong><code>log_not_found off<\/code><\/strong>\uff1a\u8fd9\u4e2a\u6307\u4ee4\u975e\u5e38\u6709\u7528\uff0c\u5b83\u53ef\u4ee5\u963b\u6b62Nginx\u5c06\u201c\u6587\u4ef6\u672a\u627e\u5230\u201d\u7684\u9519\u8bef\u8bb0\u5f55\u5230&nbsp;<code>error.log<\/code>&nbsp;\u4e2d<a href=\"https:\/\/www.yisu.com\/ask\/88818835.html\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u3002\u8fd9\u610f\u5473\u7740\u653b\u51fb\u8005\u5373\u4f7f\u53cd\u590d\u63a2\u6d4b\uff0c\u4e5f\u4e0d\u4f1a\u5728\u670d\u52a1\u5668\u65e5\u5fd7\u4e2d\u7559\u4e0b\u6e05\u6670\u7684\u201c404\u201d\u75d5\u8ff9\uff0c\u8fdb\u4e00\u6b65\u5b9e\u73b0\u4e86\u6a21\u7cca\u5316\u3002<\/li>\n\n\n\n<li><strong>\u4f5c\u7528\u8303\u56f4<\/strong>\uff1a\u4ee5\u4e0a\u914d\u7f6e\u4e3b\u8981\u9488\u5bf9&nbsp;<code>wpcf7_uploads<\/code>&nbsp;\u76ee\u5f55\u3002\u5982\u679c\u4f60\u5c06\u6700\u4e0b\u65b9\u7684&nbsp;<code>location \/<\/code>&nbsp;\u5757\u4e5f\u4fee\u6539\u4e86\uff0c\u90a3\u4e48<strong>\u7f51\u7ad9\u6240\u6709\u4e0d\u5b58\u5728\u7684\u8def\u5f84<\/strong>\uff08\u6bd4\u5982\u653b\u51fb\u8005\u80e1\u4e71\u731c\u6d4b\u7684&nbsp;<code>\/admin.php<\/code>\u3001<code>\/wp-login.php<\/code>\uff09\u90fd\u4f1a\u8fd4\u56de\u540c\u6837\u7684\u6df7\u6dc6\u4fe1\u606f\uff0c\u5b9e\u73b0\u5168\u5c40\u6df1\u5ea6\u9632\u5fa1\u3002<\/li>\n\n\n\n<li><strong>\u5185\u5bb9\u8bbe\u8ba1<\/strong>\uff1a<code>return 200<\/code>&nbsp;\u540e\u9762\u7684\u5185\u5bb9\u53ef\u4ee5\u7cbe\u5fc3\u8bbe\u8ba1\uff0c\u4f8b\u5982\u6a21\u4eff\u4e00\u4e9b\u5e38\u89c1\u7684\u670d\u52a1\u7aef\u9519\u8bef\u4fe1\u606f\u3001JSON\u683c\u5f0f\u7684\u4e71\u7801\uff0c\u6216\u8005\u76f4\u63a5\u662f\u4e00\u4e2a\u7a7a\u767d\u9875\u3002<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u5982\u679c\u6709\u5f02\u5e38\u7684\u884c\u4e3a\uff0c\u5bf9IP\u8fdb\u884c\u5c01\u7981<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8981\u5b9e\u73b0\u52a8\u6001IP\u5c01\u7981\u548c\u9519\u8bef\u6df7\u6dc6\uff0c\u9700\u8981\u7ed3\u5408Nginx\u914d\u7f6e\u548c\u5916\u90e8\u5de5\u5177\/\u811a\u672c\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u3001\u6838\u5fc3\u914d\u7f6e\u8981\u70b9\u6f84\u6e05<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u9700\u8981\u7406\u89e3\u5e76\u64cd\u4f5c\u4e24\u7c7b\u6587\u4ef6\uff0c\u5b83\u4eec\u5171\u540c\u6784\u6210\u9632\u5fa1\u4f53\u7cfb<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6587\u4ef6\u7c7b\u578b<\/th><th>\u4f5c\u7528<\/th><th>\u4f4d\u7f6e\u4e0e\u540d\u79f0\u793a\u4f8b<\/th><\/tr><\/thead><tbody><tr><td><strong>Nginx\u4e3b\u914d\u7f6e\u6587\u4ef6<\/strong><\/td><td><strong>\u6838\u5fc3\u9632\u5fa1\u4e0e\u6df7\u6dc6\u89c4\u5219<\/strong>\uff1a\u5b9a\u4e49\u53d7\u4fdd\u62a4\u76ee\u5f55\uff08\u5982<code>wpcf7_uploads<\/code>\uff09\u3001\u8bbe\u5b9a\u9519\u8bef\u6df7\u6dc6\u3001\u8fdb\u884c\u57fa\u7840IP\u5c01\u7981\u3002<\/td><td>\u901a\u5e38\u662f&nbsp;<code>\/etc\/nginx\/sites-available\/<\/code>&nbsp;\u4e0b\u4f60\u7684\u7f51\u7ad9\u914d\u7f6e\u6587\u4ef6\uff0c\u6216\u5b9d\u5854\u9762\u677f\u7684\u7f51\u7ad9\u914d\u7f6e\u3002<\/td><\/tr><tr><td><strong>IP\u5c01\u7981\u52a8\u6001\u7ba1\u7406\u6587\u4ef6<\/strong><\/td><td><strong>\u52a8\u6001IP\u540d\u5355<\/strong>\uff1a\u5b58\u50a8\u9700\u8981\u52a8\u6001\u5c01\u7981\u7684IP\u5217\u8868\u3002Nginx\u901a\u8fc7<code>include<\/code>\u6307\u4ee4\u5b9e\u65f6\u8bfb\u53d6\u3002<\/td><td>\u53ef\u81ea\u5b9a\u4e49\uff0c\u4f8b\u5982&nbsp;<code>\/etc\/nginx\/conf.d\/blockips.conf<\/code>&nbsp;\u6216&nbsp;<code>\/etc\/nginx\/dynamic\/blacklist.conf<\/code><a href=\"https:\/\/fly63.com\/article\/detial\/13256?type=4\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e8c\u3001\u5b9e\u73b0\u65b9\u6848\u4e0e\u914d\u7f6e\u65b9\u6cd5<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e0b\u9762\u662f\u4e00\u4e2a\u7ed3\u5408\u4e86\u6240\u6709\u9700\u6c42\uff08\u6df7\u6dc6\u3001\u52a8\u6001\u5c01\u7981\u3001\u8c41\u514d\u6d4b\u8bd5IP\uff09\u7684\u7efc\u5408\u65b9\u6848\u3002\u5b83\u57fa\u4e8e<strong>Nginx + Shell\u811a\u672c + \u52a8\u6001\u9ed1\u540d\u5355\u6587\u4ef6<\/strong>\uff0c\u65e0\u9700\u5b89\u88c5\u590d\u6742\u4f9d\u8d56\uff0c\u6613\u4e8e\u7ba1\u7406\u548c\u8c03\u8bd5\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u6b65\uff1a\u5728Nginx\u4e2d\u914d\u7f6e\u201c\u9519\u8bef\u6df7\u6dc6\u201d\u4e0e\u52a8\u6001\u5c01\u7981\u6846\u67b6<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u8bf7\u5c06\u4ee5\u4e0b\u914d\u7f6e\u6dfb\u52a0\u5230\u4f60\u7684<strong>Nginx\u7f51\u7ad9\u914d\u7f6e\u6587\u4ef6<\/strong>\u4e2d\uff0c\u653e\u5728&nbsp;<code>server { ... }<\/code>&nbsp;\u5757\u5185\u5408\u9002\u4f4d\u7f6e\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># 1. \u5b9a\u4e49\u52a8\u6001IP\u9ed1\u540d\u5355\u7684\u5b58\u653e\u4f4d\u7f6e\uff08\u975e\u5e38\u91cd\u8981\uff01\uff09\ninclude \/etc\/nginx\/conf.d\/blockips.conf;\n\n# 2. \u4fdd\u62a4\u7279\u5b9a\u76ee\u5f55\u5e76\u5b9e\u73b0\u201c\u9519\u8bef\u6df7\u6dc6\u201d\nlocation ~* ^\/wp-content\/uploads\/(wpcf7_uploads|private_wpcf7_uploads)\/ {\n    # \u9996\u5148\u5e94\u7528IP\u9ed1\u540d\u5355\u89c4\u5219\n    deny all; # \u6b64\u6307\u4ee4\u4f1a\u5bf9blockips.conf\u4e2d\u7684IP\u751f\u6548\n\n    # \u5b9e\u73b0\u6df7\u6dc6\uff1a\u65e0\u8bba\u6587\u4ef6\u662f\u5426\u5b58\u5728\uff0c\u90fd\u8fd4\u56de\u201c200 OK\u201d\u548c\u4e00\u4e2a\u901a\u7528\u9519\u8bef\u9875\n    # \u8fd9\u91cc\u7528return\u8fd4\u56de\u7eaf\u6587\u672c\uff0c\u4f60\u4e5f\u53ef\u4ee5\u7528error_page\u6307\u5411\u4e00\u4e2a\u7cbe\u5fc3\u8bbe\u8ba1\u7684HTML\u9875\u9762\n    return 200 \"Service Temporarily Unavailable. Please try again later.\\n\";\n    # \u53ef\u9009\uff1a\u5b8c\u5168\u5173\u95ed\u6b64\u4f4d\u7f6e\u7684\u65e5\u5fd7\uff0c\u8ba9\u653b\u51fb\u8005\u65e0\u4ece\u5206\u6790\n    access_log off;\n    log_not_found off;\n}\n\n# 3. \uff08\u5173\u952e\uff09\u4e3a\u4f60\u7684\u6d4b\u8bd5IP\u8bbe\u7f6e\u767d\u540d\u5355\uff0c\u9632\u6b62\u8bef\u5c01\ngeo $is_whitelist {\n    default 0;\n    # \u8bf7\u5c06\u4e0b\u9762\u7684 123.456.78.90 \u66ff\u6362\u4e3a\u4f60\u771f\u5b9e\u7684\u3001\u56fa\u5b9a\u7684\u6d4b\u8bd5\u516c\u7f51IP\n    123.456.78.90 1;\n    # \u53ef\u4ee5\u7ee7\u7eed\u6dfb\u52a0\u5176\u4ed6\u53ef\u4fe1IP\uff0c\u5982\u4f60\u81ea\u5df1\u7684\u529e\u516c\u7f51\u7edcIP\n    \u4f60\u7684\u5176\u4ed6IP 1;\n}\n\n# 4. \u5728\u5168\u5c40\u6216\u5173\u952e\u4f4d\u7f6e\u5e94\u7528\u767d\u540d\u5355\u903b\u8f91\nlocation \/ {\n    # \u5982\u679cIP\u4e0d\u5728\u767d\u540d\u5355\uff0c\u4e14\u5b58\u5728\u4e8e\u52a8\u6001\u9ed1\u540d\u5355\u4e2d\uff0c\u5219\u62d2\u7edd\u8bbf\u95ee\n    if ($is_whitelist = 0) {\n        # \u6b64\u5904\u7684deny all\u6548\u679c\u4f1a\u88ab\u4e0a\u65b9\u7684include\u6587\u4ef6\u52a8\u6001\u6269\u5c55\n    }\n    # ... \u4f60\u7684\u5176\u4ed6\u914d\u7f6e ...\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u5982\u679c\u4f60\u4e0d\u4f1a\u7684\u8bdd\uff0c\u5219\u5c31\u590d\u5236\u4e0b\u9762\u5185\u5bb9\uff0c\u5e76\u8fdb\u884c\u5b8c\u5168\u66ff\u6362\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># ==================== \u3010\u7b2c\u4e00\u90e8\u5206\uff1a\u52a8\u6001IP\u9ed1\u540d\u5355\u4e0e\u767d\u540d\u5355 (\u5fc5\u987b\u653e\u5728server\u5757\u5916)\u3011 ====================\n# 1. \u52a8\u6001\u9ed1\u540d\u5355\uff1a\u811a\u672c\u6216fail2ban\u4f1a\u5411\u8fd9\u4e2a\u6587\u4ef6\u5199\u5165 'deny IP;' \u89c4\u5219\ninclude \/etc\/nginx\/conf.d\/blockips.conf;\n\n# 2. IP\u767d\u540d\u5355\uff1a\u5b9a\u4e49\u53d8\u91cf $is_whitelist, \u5728\u767d\u540d\u5355IP\u4e0a\u503c\u4e3a1\uff0c\u5176\u4ed6\u4e3a0\n# \u3010\uff01\uff01\uff01\u91cd\u8981\u4fee\u6539\uff01\uff01\uff01\u3011\u5c06\u4e0b\u9762 8.8.8.8 \u66ff\u6362\u4e3a\u4f60\u81ea\u5df1\u7684\u516c\u7f51IP\uff08\u767e\u5ea6\u641c\u7d22\u201cIP\u201d\u53ef\u67e5\uff09\uff0c\u5426\u5219\u4f60\u53ef\u80fd\u88ab\u5c01\u7981\ngeo $is_whitelist {\n    default 0;\n    8.8.8.8 1; # \u793a\u4f8b\uff0c\u8bf7\u66ff\u6362\u3002\u53ef\u6dfb\u52a0\u591a\u884c\uff0c\u5982\uff1a114.114.114.114 1;\n}\n\n# ==================== \u3010\u7b2c\u4e8c\u90e8\u5206\uff1a\u670d\u52a1\u5668\u4e3b\u914d\u7f6e\u3011 ====================\nserver {\n    listen 80;\n    server_name www.preluna.xyz preluna.xyz;\n    index index.php index.html index.htm default.php default.htm default.html;\n    root \/www\/wwwroot\/114.66.59.86;\n\n    # ========== \u3010\u4ee5\u4e0b\u4e3a\u9762\u677f\u81ea\u52a8\u751f\u6210\u6216\u5fc5\u9700\u7684\u5f15\u7528\u914d\u7f6e\uff0c\u8bf7\u52ff\u5220\u9664\u3011 ==========\n    #CERT-APPLY-CHECK--START\n    include \/www\/server\/panel\/vhost\/nginx\/well-known\/114.66.59.86.conf;\n    #CERT-APPLY-CHECK--END\n\n    #SSL-START\n    #error_page 404\/404.html;\n    #SSL-END\n\n    #ERROR-PAGE-START\n    error_page 404 \/404.html;\n    #ERROR-PAGE-END\n\n    #PHP-INFO-START\n    include enable-php-80.conf;\n    #PHP-INFO-END\n\n    #REWRITE-START\n    include \/www\/server\/panel\/vhost\/rewrite\/114.66.59.86.conf;\n    #REWRITE-END\n    # ========== \u3010\u9762\u677f\u751f\u6210\u5185\u5bb9\u7ed3\u675f\u3011 ==========\n\n    # ==================== \u3010\u7b2c\u4e09\u90e8\u5206\uff1a\u57fa\u7840\u5b89\u5168\u4e0e\u9759\u6001\u6587\u4ef6\u89c4\u5219\u3011 ====================\n    # 1. \u7981\u6b62\u8bbf\u95ee\u654f\u611f\u7cfb\u7edf\u6587\u4ef6\n    location ~ ^\/(\\.user.ini|\\.htaccess|\\.git|\\.env|\\.svn|\\.project|LICENSE|README.md) {\n        return 404;\n    }\n\n    # 2. SSL\u8bc1\u4e66\u9a8c\u8bc1\u76ee\u5f55\uff08Let's Encrypt\u7b49\u9700\u8981\uff09\n    location ~ \\.well-known {\n        allow all;\n    }\n\n    # 3. \u9632\u6b62\u5728\u8bc1\u4e66\u9a8c\u8bc1\u76ee\u5f55\u4e0a\u4f20\u811a\u672c\n    if ( $uri ~ \"^\/\\.well-known\/.*\\.(php|jsp|py|js|css|lua|ts|go|zip|tar\\.gz|rar|7z|sql|bak)$\" ) {\n        return 403;\n    }\n\n    # 4. \u5b57\u4f53\u6587\u4ef6\u7f13\u5b58\u4f18\u5316\n    location ~* \\.(woff2|woff|ttf|eot|svg)$ {\n        types {\n            font\/woff2 woff2;\n            font\/woff woff;\n            font\/ttf ttf;\n            application\/vnd.ms-fontobject eot;\n            image\/svg+xml svg;\n        }\n        expires 1y;\n        add_header Cache-Control \"public, immutable\";\n    }\n\n    # ==================== \u3010\u7b2c\u56db\u90e8\u5206\uff1a\u6838\u5fc3\u5b89\u5168\u9632\u62a4\u89c4\u5219 (\u6309\u4f18\u5148\u7ea7\u4ece\u9ad8\u5230\u4f4e)\u3011 ====================\n    # \u3010\u89c4\u5219A\u3011\u4fdd\u62a4\u4e0a\u4f20\u76ee\u5f55 - \u5b9e\u73b0\u201c\u6df7\u6dc6\u54cd\u5e94\u201d\n    # \u4f5c\u7528\uff1a\u4efb\u4f55\u76f4\u63a5\u8bbf\u95ee\u6295\u7a3f\u6587\u4ef6\u5939\u7684\u8bf7\u6c42\uff0c\u65e0\u8bba\u6587\u4ef6\u662f\u5426\u5b58\u5728\uff0c\u90fd\u8fd4\u56de200\u548c\u6df7\u6dc6\u6587\u672c\uff0c\u8ba9\u653b\u51fb\u8005\u65e0\u6cd5\u5224\u65ad\u3002\n    location ~* ^\/wp-content\/uploads\/(wpcf7_uploads|private_wpcf7_uploads)\/ {\n        deny all; # \u52a8\u6001\u9ed1\u540d\u5355\u5728\u6b64\u751f\u6548\n        return 200 \"Service Temporarily Unavailable. Please try again later.\\n\";\n        access_log off; # \u4e0d\u8bb0\u5f55\u8bbf\u95ee\u65e5\u5fd7\uff0c\u589e\u52a0\u9690\u853d\u6027\n        log_not_found off; # \u4e0d\u8bb0\u5f55\u201c\u672a\u627e\u5230\u201d\u9519\u8bef\n    }\n\n    # \u3010\u89c4\u5219B\u3011\u9632\u6b62\u6076\u610f\u811a\u672c\u4f2a\u88c5\u6210\u56fe\u7247\/\u6587\u6863\uff08\u5982 shell.php.jpg\uff09\n    location ~* \\.php\\.(jpg|jpeg|png|gif|webp|pdf|doc|docx)$ {\n        deny all;\n        return 403;\n    }\n\n    # \u3010\u89c4\u5219C\u3011\u9632\u6b62\u76f4\u63a5\u8bbf\u95ee\u654f\u611f\u811a\u672c\u6587\u4ef6\uff08\u5168\u5c40\u62e6\u622a\uff09\n    # \u4f5c\u7528\uff1a\u62e6\u622a\u6240\u6709\u5bf9php\u7b49\u811a\u672c\u7684\u8bbf\u95ee\uff0c\u4f46\u653e\u884cWordPress\u6838\u5fc3\u6587\u4ef6(index.php, admin-ajax.php)\u3002\n    location ~* ^\/(?!index\\.php|wp-admin\/admin-ajax\\.php).*\\.(php|php5|php7|phtml|pl|py|jsp|asp|sh|cgi)$ {\n        deny all;\n        return 403;\n    }\n\n    # ==================== \u3010\u7b2c\u4e94\u90e8\u5206\uff1a\u901a\u7528\u9759\u6001\u6587\u4ef6\u7f13\u5b58\u89c4\u5219 (\u4f18\u5148\u7ea7\u6700\u4f4e)\u3011 ====================\n    # \u6ce8\u610f\uff1a\u524d\u9762\u7684\u5b89\u5168\u89c4\u5219\u5339\u914d\u540e\uff0c\u5c31\u4e0d\u4f1a\u8d70\u5230\u8fd9\u91cc\u3002\u53ea\u6709\u6b63\u5e38\u56fe\u7247\/js\/css\u624d\u4f1a\u7531\u8fd9\u91cc\u5904\u7406\u3002\n    location ~ .*\\.(gif|jpg|jpeg|png|bmp|swf)$ {\n        expires 30d;\n        error_log \/dev\/null;\n        access_log \/dev\/null;\n    }\n\n    location ~ .*\\.(js|css)?$ {\n        expires 12h;\n        error_log \/dev\/null;\n        access_log \/dev\/null;\n    }\n\n    # ==================== \u3010\u7b2c\u516d\u90e8\u5206\uff1a\u65e5\u5fd7\u914d\u7f6e\u3011 ====================\n    access_log  \/www\/wwwlogs\/114.66.59.86.log;\n    error_log  \/www\/wwwlogs\/114.66.59.86.error.log;\n}\n# ==================== \u3010\u914d\u7f6e\u6587\u4ef6\u7ed3\u675f\u3011 ====================<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e8c\u6b65\uff1a\u521b\u5efa\u5e76\u7ba1\u7406\u52a8\u6001IP\u9ed1\u540d\u5355<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u901a\u8fc7\u4e00\u4e2a\u811a\u672c\u548c\u9ed1\u540d\u5355\u6587\u4ef6\u6765\u5b9e\u73b0IP\u7684\u52a8\u6001\u5c01\u7981\u4e0e\u89e3\u5c01\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">1.<strong>\u521b\u5efa\u9ed1\u540d\u5355\u6587\u4ef6<\/strong>\uff1a\u8fd9\u4e2a\u6587\u4ef6\u521d\u59cb\u4e3a\u7a7a\u3002\u811a\u672c\u4f1a\u5411\u5176\u4e2d\u5199\u5165&nbsp;<code>deny IP\u5730\u5740;<\/code>&nbsp;\u683c\u5f0f\u7684\u89c4\u5219<a href=\"https:\/\/www.ctyun.cn\/developer\/article\/616244702801989\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo touch \/etc\/nginx\/conf.d\/blockips.conf<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">2.<strong>\u521b\u5efa\u7ba1\u7406\u811a\u672c<\/strong>\uff1a\u521b\u5efa\u4e00\u4e2a\u811a\u672c\uff08\u5982&nbsp;<code>\/usr\/local\/bin\/manage_blockip.sh<\/code>\uff09\uff0c\u7528\u4e8e\u6dfb\u52a0\/\u5220\u9664\u5c01\u7981IP\uff0c\u5e76\u81ea\u52a8\u91cd\u8f7dNginx\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/bash\nBLOCK_FILE=\"\/etc\/nginx\/conf.d\/blockips.conf\"\n\n# \u6dfb\u52a0\u5c01\u7981IP\nblock_ip() {\n    if ! grep -q \"deny $1;\" \"$BLOCK_FILE\"; then\n        echo \"deny $1;\" &gt;&gt; \"$BLOCK_FILE\"\n        echo \"\u5df2\u5c01\u7981 IP: $1\"\n    else\n        echo \"IP: $1 \u5df2\u5728\u9ed1\u540d\u5355\u4e2d\"\n    fi\n}\n\n# \u89e3\u9664\u5c01\u7981IP\nunblock_ip() {\n    sed -i \"\/deny $1;\/d\" \"$BLOCK_FILE\"\n    echo \"\u5df2\u89e3\u5c01 IP: $1\"\n}\n\n# \u91cd\u8f7dNginx\u914d\u7f6e\nreload_nginx() {\n    if nginx -t &gt; \/dev\/null 2&gt;&amp;1; then\n        systemctl reload nginx  # \u6216 sudo service nginx reload\n        echo \"Nginx \u914d\u7f6e\u5df2\u91cd\u8f7d\"\n    else\n        echo \"Nginx \u914d\u7f6e\u6d4b\u8bd5\u5931\u8d25\uff0c\u8bf7\u68c0\u67e5\u8bed\u6cd5\"\n        exit 1\n    fi\n}\n\n# \u4f7f\u7528\u793a\u4f8b\ncase $1 in\n    \"add\")\n        block_ip $2\n        reload_nginx\n        ;;\n    \"remove\")\n        unblock_ip $2\n        reload_nginx\n        ;;\n    \"list\")\n        cat \"$BLOCK_FILE\"\n        ;;\n    *)\n        echo \"\u7528\u6cd5: $0 {add|remove|list} &#91;IP\u5730\u5740]\"\n        exit 1\n        ;;\nesac<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u7ed9\u811a\u672c\u6267\u884c\u6743\u9650\uff1a<code>sudo chmod +x \/usr\/local\/bin\/manage_blockip.sh<\/code>\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">3.<strong>\u4f7f\u7528\u811a\u672c\u7ba1\u7406IP<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5c01\u7981IP<\/strong>\uff1a<code>sudo manage_blockip.sh add \u653b\u51fb\u8005IP<\/code><\/li>\n\n\n\n<li><strong>\u89e3\u5c01IP<\/strong>\uff1a<code>sudo manage_blockip.sh remove \u653b\u51fb\u8005IP<\/code><\/li>\n\n\n\n<li><strong>\u67e5\u770b\u5217\u8868<\/strong>\uff1a<code>sudo manage_blockip.sh list<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">&nbsp;\u4e00\u4e2a\u6781\u5176\u91cd\u8981\u7684\u6b65\u9aa4\uff1a\u8bbe\u7f6e\u4f60\u7684\u767d\u540d\u5355IP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u6d4b\u8bd5\u524d\uff0c<strong>\u5fc5\u987b<\/strong>\u5c06&nbsp;<code>geo<\/code>&nbsp;\u5757\u91cc\u7684\u793a\u4f8b IP&nbsp;<code>123.456.78.90<\/code>&nbsp;\u66ff\u6362\u6210\u4f60<strong>\u5f53\u524d\u64cd\u4f5c\u7535\u8111\u7684\u516c\u7f51IP<\/strong>\uff08\u4f60\u7528\u6765SSH\u8fde\u63a5\u6216\u7ba1\u7406\u7f51\u7ad9\u7684IP\uff09\u3002\u4f60\u53ef\u4ee5\u901a\u8fc7\u8bbf\u95ee&nbsp;<a href=\"https:\/\/ipinfo.io\/\" target=\"_blank\" rel=\"noreferrer noopener\">ipinfo.io<\/a>&nbsp;\u5feb\u901f\u83b7\u53d6\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5982\u679c\u4f60\u4e0d\u66ff\u6362\uff0c\u540e\u7eed\u7684\u4efb\u4f55\u5c01\u7981\u6d4b\u8bd5\u90fd\u53ef\u80fd\u628a\u4f60\u81ea\u5df1\u7684IP\u5c01\u6389\uff0c\u5bfc\u81f4\u4f60\u65e0\u6cd5\u8bbf\u95ee\u81ea\u5df1\u7684\u7f51\u7ad9\uff01<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u901a\u8fc7\u767e\u5ea6\u641c\u7d22IP\u83b7\u5f97\uff0c\u4ed6\u7ed9\u6211\u8fd4\u56de\u7684\u662f223.\u8fd9\u4e2a\u5f00\u5934\u7684IP\uff0c\u90a3\u4e3a\u4ec0\u4e48\u6211\u76f4\u63a5\u5728\u6211\u7535\u8111\u4e0a\u901a\u8fc7IP\u547d\u4ee4\uff0c\u83b7\u5f97\u7684\u90a3\u4e2a\u5730\u5740\uff0c\u5b83\u4e0d\u5c5e\u4e8e\u516c\u7f51IP\u3002\u5f53\u4ece\u4e0d\u540c\u6e20\u9053\u83b7\u53d6\u7684IP\u4e0d\u4e00\u81f4\u65f6\uff0c\u539f\u56e0\u5728\u4e8e\u4f60\u5bb6\u91cc\u7684\u7f51\u7edc\u662f&nbsp;<strong>\u201c\u591a\u4eba\u5171\u4eab\u4e00\u4e2a\u51fa\u53e3\u201d<\/strong>&nbsp;\u7684\u7ed3\u6784\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u7528\u4e00\u4e2a\u6bd4\u55bb\u6765\u89e3\u91ca\uff1a\u60f3\u8c61\u4f60\u4f4f\u5728\u4e00\u680b\u516c\u5bd3\u697c\u91cc\u3002<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<ul class=\"wp-block-list\">\n<li><strong>\u4f60\u7535\u8111\u4e0a\u67e5\u5230\u7684IP<\/strong>\uff08\u6bd4\u5982&nbsp;<code>192.168.1.101<\/code>\uff09\u5c31\u50cf\u662f\u4f60\u7684&nbsp;<strong>\u201c\u623f\u95f4\u53f7\u201d<\/strong>&nbsp;\u3002\u8fd9\u4e2a\u53f7\u7801\u53ea\u5728\u516c\u5bd3\u697c\u5185\u90e8\u4f7f\u7528\uff0c\u90ae\u9012\u5458\u65e0\u6cd5\u76f4\u63a5\u628a\u4fe1\u9001\u5230\u8fd9\u4e2a\u201c\u623f\u95f4\u53f7\u201d\u3002<\/li>\n\n\n\n<li><strong>\u767e\u5ea6\u641c\u7d22\u51fa\u6765\u7684IP<\/strong>\uff08<code>223.xxx.xxx.xxx<\/code>\uff09\u5c31\u50cf\u662f\u8fd9\u680b\u516c\u5bd3\u697c\u7684&nbsp;<strong>\u201c\u5927\u697c\u5730\u5740\u201d<\/strong>&nbsp;\u3002\u6240\u6709\u5bc4\u7ed9\u697c\u91cc\u4f4f\u6237\u7684\u4fe1\u4ef6\uff0c\u90fd\u4f1a\u5148\u9001\u5230\u8fd9\u4e2a\u5927\u697c\u5730\u5740\uff0c\u518d\u7531\u7ba1\u7406\u5458\uff08\u8def\u7531\u5668\uff09\u6839\u636e\u623f\u95f4\u53f7\u5206\u53d1\u7ed9\u6bcf\u4e2a\u4eba\u3002<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u5de5\u4f5c\u6d41\u7a0b<\/strong>\uff1a\u5f53\u4f60\u7684\u7535\u8111\uff08<code>192.168.1.101<\/code>\uff09\u8bbf\u95ee\u6211\u7684\u670d\u52a1\u5668\u65f6\uff0c\u6570\u636e\u5305\u4f1a\u5148\u7ecf\u8fc7\u4f60\u7684<strong>\u8def\u7531\u5668<\/strong>\u3002\u8def\u7531\u5668\u4f1a\u505a\u4e00\u4e2a\u201c\u5730\u5740\u8f6c\u6362\u201d\uff08NAT\uff09\uff0c\u628a\u53d1\u51fa\u5730\u5740\u4ece\u4f60\u7684\u5185\u7f51IP\uff08<code>192.168.1.101:1234<\/code>\uff09\u66ff\u6362\u6210\u4f60\u5bb6\u7f51\u7edc\u7684\u516c\u7f51IP\uff08<code>223.xxx.xxx.xxx:5678<\/code>\uff09\u518d\u53d1\u51fa\u53bb\u3002\u6211\u7684\u670d\u52a1\u5668\u53ea\u80fd\u770b\u5230\u5e76\u56de\u590d\u5230\u4f60\u7684\u516c\u7f51IP\uff08<code>223.xxx.xxx.xxx:5678<\/code>\uff09\uff0c\u7136\u540e\u7531\u4f60\u7684\u8def\u7531\u5668\u6839\u636e\u7aef\u53e3\u53f7<code>5678<\/code>\u518d\u628a\u6570\u636e\u51c6\u786e\u8f6c\u53d1\u56de\u4f60\u7684\u7535\u8111\u3002<strong>\u8fd9\u5c31\u662f\u4e3a\u4ec0\u4e48Nginx\u767d\u540d\u5355\u5fc5\u987b\u586b\u516c\u7f51IP<\/strong>\uff1a\u56e0\u4e3a\u5f53\u4f60\u7684\u8bf7\u6c42\u5230\u8fbe\u670d\u52a1\u5668\u65f6\uff0cNginx\u770b\u5230\u7684<strong>\u6765\u6e90IP\u5c31\u662f\u4f60\u67e5\u8be2\u5230\u7684\u90a3\u4e2a&nbsp;<code>223.xxx.xxx.xxx<\/code><\/strong>\uff0c\u800c\u4e0d\u662f\u4f60\u7535\u8111\u5185\u90e8\u7684&nbsp;<code>192.168.1.101<\/code>\u3002\u5f88\u591a\u5bb6\u5ead\u5bbd\u5e26\u8fd0\u8425\u5546\u4e3a\u4e86\u8282\u7701IPv4\u5730\u5740\uff0c\u4f1a\u4f7f\u7528\u201c\u8fd0\u8425\u5546\u7ea7NAT\u201d\uff08Carrier-Grade NAT\uff09\u3002\u8fd9\u610f\u5473\u7740\u4f60\u4ece\u767e\u5ea6\u67e5\u5230\u7684\u90a3\u4e2a<code>223<\/code>\u5f00\u5934\u7684IP\uff0c<strong>\u53ef\u80fd\u4e0d\u662f\u4f60\u72ec\u4eab\u7684\uff0c\u800c\u662f\u548c\u540c\u4e00\u533a\u57df\u7684\u5176\u4ed6\u5f88\u591a\u7528\u6237\u5171\u4eab\u7684<\/strong>\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u5982\u4f55\u7b80\u5355\u5224\u65ad\uff1f<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u767b\u5f55\u4f60\u5bb6\u8def\u7531\u5668\u7684\u7ba1\u7406\u540e\u53f0\uff08\u901a\u5e38\u5730\u5740\u662f&nbsp;<code>192.168.1.1<\/code>&nbsp;\u6216&nbsp;<code>192.168.0.1<\/code>\uff09\uff0c\u5728\u201cWAN\u53e3\u72b6\u6001\u201d\u6216\u201c\u7f51\u7edc\u4fe1\u606f\u201d\u91cc\u67e5\u770b\u83b7\u53d6\u5230\u7684IP\u5730\u5740\u3002\u5982\u679c\u8def\u7531\u5668\u91cc\u663e\u793a\u7684IP\uff08\u6bd4\u5982<code>10.x.x.x<\/code>\u6216<code>100.x.x.x<\/code>\uff09<strong>\u548c\u767e\u5ea6\u67e5\u5230\u7684\u4e0d\u540c<\/strong>\uff0c\u90a3\u5c31\u8bf4\u660e\u4f60\u7684\u7f51\u7edc\u5916\u5c42\u8fd8\u6709\u4e00\u5c42\u8fd0\u8425\u5546\u7684NAT\u3002\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f60\u914d\u7f6e\u767d\u540d\u5355\u7684\u6548\u679c\u4f1a\u6253\u6298\u6263\uff0c\u56e0\u4e3a\u548c\u4f60\u5171\u4eab\u8fd9\u4e2a\u516c\u7f51IP\u7684\u5176\u4ed6\u7528\u6237\u7684\u884c\u4e3a\u4e5f\u53ef\u80fd\u5f71\u54cd\u4f60\u3002\u5982\u679c\u8fd9\u4e2aIP\u548c\u4f60\u5728\u767e\u5ea6\u67e5\u5230\u7684&nbsp;<strong>\u5b8c\u5168\u4e00\u81f4<\/strong>\uff0c\u90a3\u4e48\u606d\u559c\uff0c\u4f60\u62e5\u6709\u72ec\u7acb\u7684\u516c\u7f51IP\uff0c\u914d\u7f6e\u767d\u540d\u5355\u6700\u6709\u6548\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u5728\u5171\u4eabIP\u73af\u5883\u4e0b\uff0c<strong>\u57fa\u4e8eWordPress\u7528\u6237\u89d2\u8272\u548c\u767b\u5f55\u72b6\u6001<\/strong>\u7684\u201c\u5206\u7ea7\u54cd\u5e94\u4e0e\u76d1\u63a7\u201d<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u5c06\u5b89\u5168\u91cd\u5fc3\u4ece\u53ef\u80fd\u65e0\u6548\u7684IP\u5c01\u7981\uff0c\u8f6c\u79fb\u5230\u4e86\u7f51\u7ad9\u5e94\u7528\u5c42\u9762\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a47-1024x874.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"874\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a47-1024x874.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1381\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u5171\u4eabIP\u73af\u5883\u4e0b\uff0c<strong>\u4ee5\u7528\u6237\u6743\u9650\u4e3a\u6838\u5fc3<\/strong>\uff0c\u5728WordPress\u5e94\u7528\u5c42\u5185\u5efa\u7acb\u4e3b\u52a8\u9632\u5fa1\u4f53\u7cfb\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a48-1024x899.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"899\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a48-1024x899.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1384\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u5509\u4e0d\u662f\uff0c\u8fd9\u63d2\u4ef6\u592a\u8d35\u4e86\uff0c\u6839\u672c\u7528\u4e0d\u8d77\u4e00\u5e74\u3002<br>\u5144\u5f1f\u4eec\uff0c\u8fd9\u5e76\u4e0d\u597d\u7b11\uff0c\u6240\u4ee5\u6211\u4eec\u5c31\u60f3\u7740\u6211\u4eec\u81ea\u5df1\u53bb\u7f16\u5199\u4e00\u4e2a\u4ee3\u7801\u6216\u8005\u63d2\u4ef6\uff0c\u53bb\u5b8c\u6210\u8fd9\u4e2a\u4e0a\u8ff0\u7684\u529f\u80fd\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a49-1024x404.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"404\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a49-1024x404.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1388\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><code>functions.php<\/code>&nbsp;\u6587\u4ef6\u65b9\u6cd5<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ee3\u7801\u6a21\u5757\u4e00\uff1a\u7ba1\u7406\u5458\u8c41\u514d\u4e0e\u5458\u5de5\u5b9e\u65f6\u5c01\u7981,\u5c06\u4ee5\u4e0b\u4ee3\u7801\u6dfb\u52a0\u5230\u4f60\u7684\u4e3b\u9898&nbsp;<code>functions.php<\/code>&nbsp;\u6587\u4ef6\u672b\u5c3e\uff0c\u6216\u521b\u5efa\u4e00\u4e2a\u7b80\u5355\u7684\u81ea\u5b9a\u4e49\u63d2\u4ef6\u3002<strong>\u8bf7\u52a1\u5fc5\u4fee\u6539\u5176\u4e2d\u63d0\u5230\u7684\u8def\u5f84\u548c\u90ae\u7bb1<\/strong>\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/**\n * \u4e3b\u52a8\u9632\u5fa1\u6838\u5fc3\u6a21\u5757\uff1a\u76d1\u63a7\u5458\u5de5\u64cd\u4f5c\u5e76\u5b9e\u65f6\u5c01\u7981\n *\/\nadd_action('admin_init', 'custom_monitor_employee_actions');\nfunction custom_monitor_employee_actions() {\n    \/\/ 1. \u83b7\u53d6\u5f53\u524d\u7528\u6237\n    $current_user = wp_get_current_user();\n    \n    \/\/ 2. \u6838\u5fc3\uff1a\u5982\u679c\u662f\u7ba1\u7406\u5458\uff0c\u76f4\u63a5\u653e\u884c\uff0c\u4e0d\u505a\u4efb\u4f55\u68c0\u67e5\n    if (in_array('administrator', (array) $current_user-&gt;roles)) {\n        return; \/\/ \u7ba1\u7406\u5458\u62e5\u6709\u6700\u9ad8\u8c41\u514d\u6743\n    }\n    \n    \/\/ 3. \u5b9a\u4e49\u5458\u5de5\u7684\u654f\u611f\u7981\u533a\uff08URL\u5173\u952e\u8bcd\uff0c\u53ef\u6309\u9700\u589e\u5220\uff09\n    $restricted_paths = array(\n        'plugin-install.php',\n        'theme-install.php',\n        'users.php',\n        'tools.php',\n        'options-general.php',\n        '\/wp-content\/plugins\/',\n        '\/wp-content\/themes\/'\n    );\n    \n    $current_uri = $_SERVER&#91;'REQUEST_URI'];\n    \n    \/\/ 4. \u68c0\u67e5\u5458\u5de5\u662f\u5426\u8e0f\u5165\u7981\u533a\n    foreach ($restricted_paths as $path) {\n        if (strpos($current_uri, $path) !== false) {\n            \/\/ 5. \u89e6\u53d1\u5c01\u7981\u6d41\u7a0b\n            \/\/ a. \u8bb0\u5f55\u5230\u5ba1\u8ba1\u65e5\u5fd7\uff08\u5982\u679cWP Security Audit Log\u5df2\u5b89\u88c5\uff09\n            do_action('custom_security_alert', '\u5458\u5de5\u8d8a\u6743\u8bbf\u95ee', $current_user-&gt;user_login, $current_uri);\n            \n            \/\/ b. \u5f3a\u5236\u8be5\u7528\u6237\u767b\u51fa\n            wp_logout();\n            \n            \/\/ c. \u5c06\u8be5\u7528\u6237\u89d2\u8272\u964d\u7ea7\u4e3a\u201c\u65e0\u201d\uff0c\u4f7f\u5176\u8d26\u53f7\u5931\u6548\uff08\u5173\u952e\u6b65\u9aa4\uff09\n            $current_user-&gt;set_role(''); \/\/ \u8bbe\u7f6e\u4e3a\u7a7a\u89d2\u8272\uff0c\u5373\u5931\u53bb\u6240\u6709\u6743\u9650\n            \n            \/\/ d. \u91cd\u5b9a\u5411\u5230\u5e26\u6709\u8b66\u544a\u4fe1\u606f\u7684\u767b\u5f55\u9875\n            wp_redirect(wp_login_url() . '?action=blocked&amp;reason=unauthorized');\n            exit;\n        }\n    }\n}\n\n\/**\n * \uff08\u53ef\u9009\uff09\u5411\u7ba1\u7406\u5458\u53d1\u9001\u90ae\u4ef6\u901a\u77e5\n *\/\nadd_action('custom_security_alert', 'custom_send_security_email', 10, 3);\nfunction custom_send_security_email($alert_type, $username, $detail) {\n    $admin_email = get_option('admin_email'); \/\/ \u4f60\u7684\u90ae\u7bb1\n    $subject = '\u3010\u5b89\u5168\u8b66\u62a5\u3011\u60a8\u7684\u7f51\u7ad9\u6709\u5f02\u5e38\u64cd\u4f5c';\n    $message = \"\u8b66\u62a5\u7c7b\u578b\uff1a{$alert_type}\\n\u89e6\u53d1\u7528\u6237\uff1a{$username}\\n\u64cd\u4f5c\u8be6\u60c5\uff1a{$detail}\\n\u65f6\u95f4\uff1a\" . current_time('mysql');\n    wp_mail($admin_email, $subject, $message);\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u4ee3\u7801\u6a21\u5757\u4e8c\uff1a\u8bbf\u5ba2\u9ad8\u9891\u8bbf\u95ee\u9650\u5236\uff08\u8f7b\u91cf\u7ea7\uff09,\u8fd9\u4e2a\u6a21\u5757\u4e0d\u9700\u8981\u4f9d\u8d56IP\u767d\u540d\u5355\uff0c\u800c\u662f\u5728\u5e94\u7528\u5c42\u9650\u5236\u9ad8\u9891\u8bf7\u6c42\u3002\u5c06\u4ee5\u4e0b\u4ee3\u7801\u4e5f\u6dfb\u52a0\u5230&nbsp;<code>functions.php<\/code>\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/**\n * \u8bbf\u5ba2\u9ad8\u9891\u8bbf\u95ee\u9650\u5236\n *\/\nadd_action('init', 'custom_rate_limit_guests');\nfunction custom_rate_limit_guests() {\n    \/\/ \u53ea\u9488\u5bf9\u672a\u767b\u5f55\u7684\u8bbf\u5ba2\n    if (is_user_logged_in()) {\n        return;\n    }\n    \n    $visitor_ip = $_SERVER&#91;'REMOTE_ADDR'];\n    $transient_key = 'rate_limit_' . $visitor_ip;\n    $request_count = get_transient($transient_key);\n    \n    \/\/ \u8bbe\u7f6e\u9608\u503c\uff1a15\u79d2\u5185\u8d85\u8fc710\u6b21\u8bf7\u6c42\n    if ($request_count &amp;&amp; $request_count &gt; 10) {\n        \/\/ \u8fd4\u56de429\u72b6\u6001\u7801\uff08\u8bf7\u6c42\u8fc7\u591a\uff09\uff0c\u5e76\u7ec8\u6b62\u6267\u884c\n        status_header(429);\n        exit('\u8bf7\u6c42\u8fc7\u4e8e\u9891\u7e41\uff0c\u8bf7\u7a0d\u540e\u518d\u8bd5\u3002');\n    }\n    \n    \/\/ \u589e\u52a0\u8ba1\u6570\uff0c\u5e76\u8bbe\u7f6e15\u79d2\u8fc7\u671f\u65f6\u95f4\n    if ($request_count === false) {\n        set_transient($transient_key, 1, 15);\n    } else {\n        set_transient($transient_key, $request_count + 1, 15);\n    }\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u63d2\u4ef6\u65b9\u6cd5<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u7b2c\u4e00\u6b65\uff1a\u521b\u5efa\u63d2\u4ef6\u57fa\u672c\u7ed3\u6784<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u4f60\u7684\u7f51\u7ad9\u670d\u52a1\u5668\u4e0a\uff0c\u8fdb\u5165&nbsp;<code>wp-content\/plugins\/<\/code>&nbsp;\u76ee\u5f55\uff0c\u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u6587\u4ef6\u5939\uff0c\u4f8b\u5982&nbsp;<code>preluna-security-guard<\/code>\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u8be5\u6587\u4ef6\u5939\u5185\uff0c\u521b\u5efa\u4ee5\u4e0b\u51e0\u4e2a\u6587\u4ef6\uff0c\u6574\u4e2a\u63d2\u4ef6\u7684\u7ed3\u6784\u5982\u4e0b\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>preluna-security-guard\/\n\u251c\u2500\u2500 preluna-security-guard.php      # \u63d2\u4ef6\u4e3b\u6587\u4ef6\n\u251c\u2500\u2500 includes\/\n\u2502   \u251c\u2500\u2500 class-employee-monitor.php    # \u5458\u5de5\u76d1\u63a7\u4e0e\u5c01\u7981\u6a21\u5757\n\u2502   \u2514\u2500\u2500 class-guest-limiter.php       # \u8bbf\u5ba2\u9891\u7387\u9650\u5236\u6a21\u5757\n\u2514\u2500\u2500 uninstall.php                   # \u63d2\u4ef6\u5378\u8f7d\u6e05\u7406\u811a\u672c\uff08\u53ef\u9009\uff09<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u7b2c\u4e8c\u6b65\uff1a\u7f16\u5199\u63d2\u4ef6\u4e3b\u6587\u4ef6<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3b\u6587\u4ef6\u662f\u63d2\u4ef6\u7684\u201c\u8eab\u4efd\u8bc1\u201d\u548c\u201c\u603b\u63a7\u4e2d\u5fc3\u201d\u3002\u7f16\u8f91&nbsp;<code>preluna-security-guard.php<\/code>\uff0c\u5199\u5165\u4ee5\u4e0b\u4ee3\u7801\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\n\/**\n * Plugin Name:       Preluna Security Guard\n * Plugin URI:        https:\/\/www.preluna.xyz\/\n * Description:       \u4e00\u4e2a\u8f7b\u91cf\u7ea7\u7684WordPress\u4e3b\u52a8\u9632\u5fa1\u63d2\u4ef6\uff0c\u5b9e\u73b0\u57fa\u4e8e\u89d2\u8272\u7684\u5b9e\u65f6\u76d1\u63a7\u4e0e\u5c01\u7981\u3002\n * Version:           1.0.0\n * Author:            Your Name\n * License:           GPL v2 or later\n * Text Domain:       preluna-sg\n *\/\n\n\/\/ \u9632\u6b62\u76f4\u63a5\u8bbf\u95ee\nif ( ! defined( 'ABSPATH' ) ) {\n    exit;\n}\n\n\/\/ \u5b9a\u4e49\u63d2\u4ef6\u8def\u5f84\u5e38\u91cf\uff0c\u4fbf\u4e8e\u5176\u4ed6\u5730\u65b9\u5f15\u7528\ndefine( 'PSG_PLUGIN_DIR', plugin_dir_path( __FILE__ ) );\n\n\/\/ \u5305\u542b\u6838\u5fc3\u529f\u80fd\u7c7b\u6587\u4ef6\nrequire_once PSG_PLUGIN_DIR . 'includes\/class-employee-monitor.php';\nrequire_once PSG_PLUGIN_DIR . 'includes\/class-guest-limiter.php';\n\n\/**\n * \u521d\u59cb\u5316\u63d2\u4ef6\u7c7b\n *\/\nfunction psg_initialize() {\n    \/\/ \u521d\u59cb\u5316\u5458\u5de5\u76d1\u63a7\u6a21\u5757\n    new PSG_Employee_Monitor();\n    \/\/ \u521d\u59cb\u5316\u8bbf\u5ba2\u9650\u5236\u6a21\u5757\n    new PSG_Guest_Limiter();\n}\nadd_action( 'plugins_loaded', 'psg_initialize' );\n\n\/**\n * \u63d2\u4ef6\u6fc0\u6d3b\u65f6\u505a\u7684\u64cd\u4f5c\uff08\u53ef\u9009\uff09\n *\/\nfunction psg_plugin_activation() {\n    \/\/ \u53ef\u4ee5\u5728\u8fd9\u91cc\u521d\u59cb\u5316\u4e00\u4e9b\u9009\u9879\uff0c\u6216\u68c0\u67e5\u4f9d\u8d56\n    if ( ! get_option( 'psg_settings' ) ) {\n        add_option( 'psg_settings', array(\n            'employee_alert_email' =&gt; get_option( 'admin_email' ),\n            'rate_limit_threshold' =&gt; 10,\n            'rate_limit_window'    =&gt; 15,\n        ) );\n    }\n}\nregister_activation_hook( __FILE__, 'psg_plugin_activation' );\n\n\/**\n * \u63d2\u4ef6\u505c\u7528\u65f6\u505a\u7684\u64cd\u4f5c\uff08\u53ef\u9009\uff09\n *\/\nfunction psg_plugin_deactivation() {\n    \/\/ \u6e05\u7406\u63d2\u4ef6\u751f\u6210\u7684\u4e34\u65f6\u6570\u636e\uff08\u5982\u8bbf\u5ba2\u9891\u7387\u9650\u5236\u7684\u77ac\u6001\u6570\u636e\uff09\n    \/\/ \u6ce8\u610f\uff1a\u4e0d\u8981\u6e05\u7406\u8bbe\u7f6e\uff0c\u4ee5\u4fbf\u91cd\u65b0\u542f\u7528\u65f6\u6062\u590d\n}\nregister_deactivation_hook( __FILE__, 'psg_plugin_deactivation' );<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u7b2c\u4e09\u6b65\uff1a\u7f16\u5199\u6838\u5fc3\u529f\u80fd\u6a21\u5757<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u662f\u63d2\u4ef6\u7684\u201c\u808c\u8089\u201d\uff0c\u6211\u4eec\u5206\u4e24\u4e2a\u7c7b\u6765\u5b9e\u73b0\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. \u5458\u5de5\u76d1\u63a7\u4e0e\u5c01\u7981\u6a21\u5757 (<code>includes\/class-employee-monitor.php<\/code>)<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass PSG_Employee_Monitor {\n    \n    \/\/ 1. \u5b9a\u4e49\u9700\u8981\u76d1\u63a7\u7684\u654f\u611f\u8def\u5f84\uff08\u53ef\u6309\u9700\u4fee\u6539\uff09\n    private $restricted_url_patterns = array(\n        \/\/ \u7cfb\u7edf\u6838\u5fc3\u6587\u4ef6\n        '\/wp-admin\\\/(plugin-install|theme-install|users|tools|options-general|export|import)\\.php\/' =&gt; true,\n        \/\/ \u63d2\u4ef6\u3001\u4e3b\u9898\u76ee\u5f55\u63a2\u6d4b\n        '\/(wp-content\\\/plugins\\\/).*\\.(php|txt|sql|zip)\/' =&gt; true,\n        '\/(wp-content\\\/themes\\\/).*\\.(php|txt|sql|zip)\/' =&gt; true,\n        \/\/ \u4f60\u4e4b\u524d\u7279\u522b\u4fdd\u62a4\u7684\u6295\u7a3f\u76ee\u5f55\uff08\u4eceNginx\u89c4\u5219\u79fb\u690d\uff09\n        '\/(wp-content\\\/uploads\\\/(wpcf7_uploads|private_wpcf7_uploads))\/' =&gt; true,\n    );\n    \n    public function __construct() {\n        \/\/ \u8bb0\u5f55\u63d2\u4ef6\u7c7b\u5df2\u521d\u59cb\u5316\n        error_log('PSG_DEBUG: PSG_Employee_Monitor \u7c7b\u5df2\u52a0\u8f7d\u3002');\n        \/\/ \u6302\u8f7d\u76d1\u63a7\u51fd\u6570\u5230admin_init\u94a9\u5b50\n        add_action('admin_init', array($this, 'monitor_author_actions'));\n    }\n    \n    public function monitor_author_actions() {\n        $current_user = wp_get_current_user();\n        $current_user_roles = (array) $current_user-&gt;roles;\n        \n        error_log('PSG_DEBUG: \u5f00\u59cb\u68c0\u67e5\u7528\u6237\u3002\u7528\u6237\u540d: ' . $current_user-&gt;user_login . '\uff0c \u89d2\u8272: ' . implode(', ', $current_user_roles));\n        \n        \/\/ 2. \u6838\u5fc3\u8c41\u514d\u903b\u8f91\uff1a\u7ba1\u7406\u5458\u548c\u7f16\u8f91\u5b8c\u5168\u653e\u884c\n        if ( in_array('administrator', $current_user_roles) || in_array('editor', $current_user_roles) ) {\n            error_log('PSG_DEBUG: \u7528\u6237\u662f\u7ba1\u7406\u5458\u6216\u7f16\u8f91\uff0c\u8c41\u514d\u6240\u6709\u68c0\u67e5\u3002');\n            return;\n        }\n        \n        \/\/ 3. \u6838\u5fc3\u6253\u51fb\u903b\u8f91\uff1a\u4ec5\u5f53\u7528\u6237\u662f\u201c\u4f5c\u8005\u201d\u65f6\uff0c\u624d\u8fdb\u884c\u68c0\u67e5\n        if ( !in_array('author', $current_user_roles) ) {\n            error_log('PSG_DEBUG: \u7528\u6237\u4e0d\u662f\u4f5c\u8005\uff0c\u7ed3\u675f\u68c0\u67e5\u3002');\n            return; \/\/ \u5982\u679c\u4e0d\u662f\u4f5c\u8005\uff0c\u4e5f\u7ed3\u675f\u68c0\u67e5\uff08\u4f8b\u5982\u8ba2\u9605\u8005\uff09\n        }\n        \n        error_log('PSG_DEBUG: \u7528\u6237\u662f\u4f5c\u8005\uff0c\u5f00\u59cb\u8fdb\u884c\u654f\u611f\u8def\u5f84\u68c0\u67e5\u3002');\n        \n        $current_uri = $_SERVER&#91;'REQUEST_URI'];\n        error_log('PSG_DEBUG: \u5f53\u524d\u8bf7\u6c42URI: ' . $current_uri);\n        \n        \/\/ 4. \u68c0\u67e5\u5f53\u524d\u8bbf\u95ee\u7684\u8def\u5f84\u662f\u5426\u5728\u654f\u611f\u5217\u8868\u4e2d\n        foreach ($this-&gt;restricted_url_patterns as $pattern =&gt; $_) {\n            if (preg_match($pattern, $current_uri)) {\n                error_log(\"PSG_ALERT: \u4f5c\u8005 {$current_user-&gt;user_login} \u89e6\u53d1\u654f\u611f\u8def\u5f84\u89c4\u5219\u3002\u6a21\u5f0f: {$pattern}\");\n                $this-&gt;block_user($current_user, 'url_access', $pattern);\n                return; \/\/ \u89e6\u53d1\u540e\u7acb\u5373\u62e6\u622a\uff0c\u505c\u6b62\u540e\u7eed\u68c0\u67e5\n            }\n        }\n        error_log('PSG_DEBUG: \u4f5c\u8005\u672a\u89e6\u53d1\u4efb\u4f55\u654f\u611f\u8def\u5f84\u89c4\u5219\u3002');\n    }\n    \n    private function block_user($user, $block_type, $trigger) {\n        error_log(\"PSG_BLOCK: \u5f00\u59cb\u6267\u884c\u5c01\u7981\u6d41\u7a0b\uff0c\u7528\u6237: {$user-&gt;user_login}\");\n        \n        \/\/ 5. \u53d1\u9001\u90ae\u4ef6\u901a\u77e5\n        $settings = get_option('psg_settings');\n        $to = $settings&#91;'employee_alert_email'] ?? get_option('admin_email');\n        $subject = '\u3010\u5b89\u5168\u8b66\u62a5\u3011\u4f5c\u8005\u5c1d\u8bd5\u8fdb\u884c\u672a\u6388\u6743\u64cd\u4f5c';\n        $message = sprintf(\n            \"\u7528\u6237\u540d\uff1a%s (ID: %d)\\n\u89e6\u53d1\u7c7b\u578b\uff1a%s\\n\u89e6\u53d1\u5185\u5bb9\uff1a%s\\n\u65f6\u95f4\uff1a%s\\nIP\u5730\u5740\uff1a%s\\n\\n\u8be5\u7528\u6237\u5df2\u88ab\u5f3a\u5236\u4e0b\u7ebf\u5e76\u7981\u7528\u3002\",\n            $user-&gt;user_login,\n            $user-&gt;ID,\n            $block_type,\n            $trigger,\n            current_time('mysql'),\n            $_SERVER&#91;'REMOTE_ADDR']\n        );\n        wp_mail($to, $subject, $message);\n        \n        \/\/ 6. \u5173\u952e\u5c01\u7981\u64cd\u4f5c\n        \/\/ a. \u79fb\u9664\u7528\u6237\u6240\u6709\u89d2\u8272\uff08\u4f7f\u5176\u8d26\u53f7\u5931\u6548\uff09\n        $user-&gt;set_role('');\n        error_log('PSG_BLOCK: \u7528\u6237\u89d2\u8272\u5df2\u6e05\u7a7a\u3002');\n        \n        \/\/ b. \u5f3a\u5236\u7528\u6237\u767b\u51fa\n        wp_logout();\n        error_log('PSG_BLOCK: \u7528\u6237\u5df2\u88ab\u767b\u51fa\u3002');\n        \n        \/\/ c. \u91cd\u5b9a\u5411\u5230\u5b89\u5168\u63d0\u793a\u9875\u9762\n        wp_redirect(home_url('\/?action=blocked&amp;reason=unauthorized_author'));\n        exit;\n    }\n}\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. \u8bbf\u5ba2\u9891\u7387\u9650\u5236\u6a21\u5757 (<code>includes\/class-guest-limiter.php<\/code>)<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\n\/**\n * \u8bbf\u5ba2\u8bbf\u95ee\u9891\u7387\u9650\u5236\u7c7b\n * \u6b63\u786e\u7684\u7c7b\u540d\u5e94\u4e3a PSG_Guest_Limiter\n *\/\nclass PSG_Guest_Limiter {\n    \n    public function __construct() {\n        \/\/ \u5728 WordPress \u521d\u59cb\u5316\u65f6\u542f\u52a8\u9891\u7387\u68c0\u67e5\n        add_action( 'init', array( $this, 'limit_requests' ) );\n        error_log('PSG_DEBUG: PSG_Guest_Limiter \u7c7b\u5df2\u52a0\u8f7d\u3002'); \/\/ \u8c03\u8bd5\u7528\n    }\n    \n    public function limit_requests() {\n        \/\/ \u53ea\u9488\u5bf9\u672a\u767b\u5f55\u7684\u8bbf\u5ba2\n        if ( is_user_logged_in() ) {\n            return;\n        }\n        \n        $settings = get_option( 'psg_settings' );\n        $threshold = $settings&#91;'rate_limit_threshold'] ?? 10;\n        $window    = $settings&#91;'rate_limit_window'] ?? 15;\n        \n        $visitor_ip = $_SERVER&#91;'REMOTE_ADDR'];\n        \/\/ \u4f7f\u7528\u66f4\u77ed\u7684\u952e\u540d\uff0c\u5e76\u52a0\u76d0\uff0c\u907f\u514d\u51b2\u7a81\n        $transient_key = 'psg_rl_' . md5( $visitor_ip . 'preluna_salt' );\n        $request_count = get_transient( $transient_key );\n        \n        if ( $request_count &amp;&amp; $request_count &gt;= $threshold ) {\n            status_header( 429 );\n            exit( '&lt;h1&gt;429 \u8bf7\u6c42\u8fc7\u591a&lt;\/h1&gt;&lt;p&gt;\u60a8\u7684\u8bbf\u95ee\u8fc7\u4e8e\u9891\u7e41\uff0c\u8bf7\u7b49\u5f85' . $window . '\u79d2\u540e\u518d\u8bd5\u3002&lt;\/p&gt;' );\n        }\n        \n        if ( $request_count === false ) {\n            set_transient( $transient_key, 1, $window );\n        } else {\n            set_transient( $transient_key, $request_count + 1, $window );\n        }\n    }\n}\n?&gt;<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u7b2c\u56db\u6b65\uff1a\u5b89\u88c5\u3001\u8c03\u8bd5\u4e0e\u6d4b\u8bd5<\/h4>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u5b89\u88c5\u63d2\u4ef6<\/strong>\uff1a\u5c06\u6574\u4e2a&nbsp;<code>preluna-security-guard<\/code>&nbsp;\u6587\u4ef6\u5939\u901a\u8fc7FTP\u6216\u6587\u4ef6\u7ba1\u7406\u5668\u4e0a\u4f20\u5230&nbsp;<code>wp-content\/plugins\/<\/code>\u3002<\/li>\n\n\n\n<li><strong>\u6fc0\u6d3b\u63d2\u4ef6<\/strong>\uff1a\u5728WordPress\u540e\u53f0\u7684\u201c\u63d2\u4ef6\u201d\u9875\u9762\uff0c\u627e\u5230&nbsp;<strong>\u201cPreluna Security Guard\u201d<\/strong>&nbsp;\u5e76\u6fc0\u6d3b\u5b83\u3002<\/li>\n\n\n\n<li><strong>\u8c03\u8bd5\u6a21\u5f0f<\/strong>\uff1a\u5728\u8c03\u8bd5\u65f6\uff0c<strong>\u5f3a\u70c8\u5efa\u8bae<\/strong>\u5728\u4f60\u7684&nbsp;<code>wp-config.php<\/code>&nbsp;\u6587\u4ef6\u4e2d\u5f00\u542f WordPress \u8c03\u8bd5\u6a21\u5f0f\uff0c\u8fd9\u6837\u4efb\u4f55\u9519\u8bef\u90fd\u4f1a\u663e\u793a\u51fa\u6765<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>define( 'WP_DEBUG', true );\ndefine( 'WP_DEBUG_LOG', true ); \/\/ \u5c06\u9519\u8bef\u8bb0\u5f55\u5230 wp-content\/debug.log\ndefine( 'WP_DEBUG_DISPLAY', false ); \/\/ \u4e0d\u8981\u5728\u9875\u9762\u4e0a\u663e\u793a\u9519\u8bef\uff0c\u9632\u6b62\u653b\u51fb\u8005\u770b\u5230<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u8fdb\u884c\u6d4b\u8bd5<\/strong>\uff1a\u6309\u7167\u4e4b\u524d\u7684\u6d4b\u8bd5\u6d41\u7a0b\uff0c\u5206\u522b\u6d4b\u8bd5<strong>\u7ba1\u7406\u5458\u8c41\u514d<\/strong>\u3001<strong>\u5458\u5de5\u5c01\u7981<\/strong>\u548c<strong>\u8bbf\u5ba2\u9650\u5236<\/strong>\u529f\u80fd\u3002\u89c2\u5bdf&nbsp;<code>debug.log<\/code>&nbsp;\u6587\u4ef6\uff08\u5982\u679c\u5f00\u542f\uff09\u548c\u670d\u52a1\u5668\u9519\u8bef\u65e5\u5fd7\uff0c\u6392\u67e5\u95ee\u9898\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u201c\u4f5c\u8005\u201d\u80fd\u505a\u4ec0\u4e48 vs \u63d2\u4ef6\u4f1a\u963b\u6b62\u4ec0\u4e48<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u7684\u63d2\u4ef6\u62e6\u622a\u662f\u57fa\u4e8e&nbsp;<strong>\u201c\u662f\u5426\u8bbf\u95ee\u4e86\u9884\u8bbe\u7684\u654f\u611f\u540e\u53f0\u8def\u5f84\u201d<\/strong>\uff0c\u8fd9\u4e0e\u5e0c\u671b\u4f5c\u8005\u80fd\u6b63\u5e38\u4f7f\u7528\u7684\u529f\u80fd\uff08\u5199\u6587\u7ae0\u3001\u4e0a\u4f20\u56fe\u7247\uff09<strong>\u662f\u4e24\u5957\u5b8c\u5168\u72ec\u7acb\u7684\u8def\u5f84<\/strong>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u4f5c\u8005\u89d2\u8272\u7684\u6b63\u5e38\u5de5\u4f5c\u8def\u5f84<\/th><th><strong>\u6211\u4eec\u7684\u63d2\u4ef6\u4f1a\u963b\u6b62\u7684\u654f\u611f\u8def\u5f84\u793a\u4f8b<\/strong>&nbsp;(\u5728&nbsp;<code>$restricted_url_patterns<\/code>&nbsp;\u4e2d\u5b9a\u4e49)<\/th><\/tr><\/thead><tbody><tr><td><code>wp-admin\/post-new.php<\/code>&nbsp;<strong>(\u64b0\u5199\u65b0\u6587\u7ae0)<\/strong><\/td><td><code>wp-admin\/plugin-install.php<\/code>&nbsp;<strong>(\u5b89\u88c5\u63d2\u4ef6)<\/strong><\/td><\/tr><tr><td><code>wp-admin\/post.php?action=edit<\/code>&nbsp;<strong>(\u7f16\u8f91\u81ea\u5df1\u7684\u6587\u7ae0)<\/strong><\/td><td><code>wp-admin\/theme-install.php<\/code>&nbsp;<strong>(\u5b89\u88c5\u4e3b\u9898)<\/strong><\/td><\/tr><tr><td><code>wp-admin\/upload.php<\/code>&nbsp;<strong>(\u5a92\u4f53\u5e93\uff0c\u4e0a\u4f20\u56fe\u7247)<\/strong><\/td><td><code>wp-admin\/users.php<\/code>&nbsp;<strong>(\u7ba1\u7406\u6240\u6709\u7528\u6237)<\/strong><\/td><\/tr><tr><td><code>wp-admin\/admin-ajax.php<\/code>&nbsp;<strong>(\u524d\u53f0\u5f02\u6b65\u64cd\u4f5c\uff0c\u5982\u4e0a\u4f20)<\/strong><\/td><td><code>wp-admin\/tools.php<\/code>\uff0c&nbsp;<code>wp-admin\/options-general.php<\/code>&nbsp;<strong>(\u7f51\u7ad9\u5de5\u5177\u548c\u8bbe\u7f6e)<\/strong><\/td><\/tr><tr><td>\u8bbf\u95ee\u81ea\u5df1\u7684\u4e2a\u4eba\u8d44\u6599\u9875<\/td><td><strong>\u4efb\u4f55\u8bd5\u56fe\u76f4\u63a5\u8bbf\u95ee\u63d2\u4ef6\u3001\u4e3b\u9898\u76ee\u5f55\u4e0b<code>.php<\/code>\u7b49\u6e90\u6587\u4ef6\u7684\u884c\u4e3a<\/strong><\/td><\/tr><tr><td>\u67e5\u770b\u524d\u53f0\u7f51\u7ad9<\/td><td><strong>\u8bbf\u95ee\u8bbe\u7f6e\u7684\u7279\u6b8a\u6295\u7a3f\u76ee\u5f55<\/strong>&nbsp;<code>wp-content\/uploads\/wpcf7_uploads\/<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">\u4f5c\u8005\u6240\u6709\u6b63\u5e38\u7684<strong>\u5185\u5bb9\u521b\u4f5c\u548c\u7ba1\u7406\u529f\u80fd\uff08\u5de6\u4fa7\u83dc\u5355\u680f\u5e38\u89c4\u9879\uff09\u90fd\u4e0d\u4f1a\u88ab\u5f71\u54cd<\/strong>\u3002\u63d2\u4ef6\u62e6\u622a\u7684\u662f<strong>\u63d2\u4ef6\/\u4e3b\u9898\u7ba1\u7406\u3001\u7528\u6237\u7ba1\u7406\u3001\u7cfb\u7edf\u8bbe\u7f6e\u3001\u670d\u52a1\u5668\u6587\u4ef6\u63a2\u6d4b<\/strong>\u7b49\u660e\u663e\u8d85\u51fa\u4f5c\u8005\u6743\u9650\u7684\u201c\u7cfb\u7edf\u7ba1\u7406\u201d\u884c\u4e3a\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u7cbe\u786e\u9a8c\u8bc1\u201c\u529f\u80fd\u4e0d\u53d7\u5f71\u54cd\u201d<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u9a8c\u8bc1\u9879\u76ee<\/th><th>\u64cd\u4f5c (\u4f7f\u7528\u4f60\u7684\u4f5c\u8005\u6d4b\u8bd5\u8d26\u53f7)<\/th><th>\u671f\u671b\u7ed3\u679c<\/th><\/tr><\/thead><tbody><tr><td><strong>1. \u6b63\u5e38\u529f\u80fd\u9a8c\u8bc1<\/strong><\/td><td>1. \u8fdb\u5165\u201c\u6587\u7ae0\u201d -&gt; \u201c\u5199\u6587\u7ae0\u201d\uff0c\u7f16\u8f91\u5e76\u4fdd\u5b58\u3002<br>2. \u8fdb\u5165\u201c\u5a92\u4f53\u201d -&gt; \u201c\u6dfb\u52a0\u65b0\u5a92\u4f53\u201d\uff0c\u4e0a\u4f20\u4e00\u5f20\u56fe\u7247\u3002<br>3. \u7f16\u8f91\u4e00\u7bc7\u81ea\u5df1\u5df2\u53d1\u5e03\u7684\u6587\u7ae0\u3002<\/td><td><strong>\u5168\u90e8\u6210\u529f<\/strong>\uff0c\u6d41\u7a0b\u7545\u901a\u65e0\u963b\u3002<\/td><\/tr><tr><td><strong>2. \u8d8a\u6743\u884c\u4e3a\u9a8c\u8bc1<\/strong><\/td><td>1. \u5728\u6d4f\u89c8\u5668\u5730\u5740\u680f\u624b\u52a8\u8f93\u5165\uff1a<code>\/wp-admin\/plugin-install.php<\/code>&nbsp;\u5e76\u8bbf\u95ee\u3002<br>2. \u5c1d\u8bd5\u8bbf\u95ee\uff1a<code>\/wp-admin\/themes.php<\/code>\u3002<br>3. \u8bbf\u95ee\uff1a<code>\/wp-admin\/users.php<\/code>\u3002<\/td><td><strong>\u5168\u90e8\u88ab\u62e6\u622a<\/strong>\uff0c\u8d26\u53f7\u88ab\u5f3a\u5236\u9000\u51fa\u5e76\u7981\u7528\u3002<\/td><\/tr><tr><td><strong>3. \u90ae\u4ef6\u4e0e\u65e5\u5fd7\u9a8c\u8bc1<\/strong><\/td><td>\u5b8c\u6210\u7b2c2\u6b65\u540e\uff0c\u68c0\u67e5\uff1a<br>1. \u4f60\u7684\u7ba1\u7406\u5458\u90ae\u7bb1\u662f\u5426\u6536\u5230\u5c01\u7981\u901a\u77e5\u90ae\u4ef6\u3002<br>2. \u63d2\u4ef6\u662f\u5426\u5728&nbsp;<code>error_log<\/code>&nbsp;\u4e2d\u7559\u4e0b\u8bb0\u5f55\u3002<\/td><td>\u6536\u5230\u90ae\u4ef6\uff0c\u5e76\u4e14\u65e5\u5fd7\u4e2d\u5e94\u6709&nbsp;<code>PSG_ALERT<\/code>&nbsp;\u7b49\u8bb0\u5f55\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u5982\u4f55\u83b7\u53d6\u66f4\u6e05\u6670\u7684\u63d2\u4ef6\u8fd0\u884c\u65e5\u5fd7<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u63d0\u4f9b\u7684\u65e5\u5fd7\u91cc\u6ca1\u6709\u6211\u4eec\u63d2\u4ef6\u7684&nbsp;<code>PSG_DEBUG<\/code>&nbsp;\u4fe1\u606f\uff0c\u53ef\u80fd\u662f\u56e0\u4e3a\u65e5\u5fd7\u88ab\u5176\u4ed6\u8b66\u544a\u6df9\u6ca1\uff0c\u6216\u8005\u8f93\u51fa\u88ab\u7f13\u51b2\u4e86\u3002\u6211\u4eec\u6362\u4e00\u79cd\u66f4\u76f4\u63a5\u3001\u72ec\u7acb\u4e8e&nbsp;<code>WP_DEBUG<\/code>&nbsp;\u7684\u65e5\u5fd7\u65b9\u5f0f\uff0c\u786e\u4fdd\u80fd\u770b\u5230\u63d2\u4ef6\u7684\u6bcf\u4e00\u6b65\u3002\u5728\u63d2\u4ef6\u4e3b\u6587\u4ef6&nbsp;<code>preluna-security-guard.php<\/code>&nbsp;\u7684\u672b\u5c3e\uff0c<code>?&gt;<\/code>&nbsp;\u6807\u7b7e\u524d\uff0c\u6dfb\u52a0\u8fd9\u4e2a\u4e13\u7528\u65e5\u5fd7\u51fd\u6570\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/**\n * \u4e13\u7528\u7684\u63d2\u4ef6\u65e5\u5fd7\u51fd\u6570\uff0c\u76f4\u63a5\u5199\u5165\u56fa\u5b9a\u6587\u4ef6\uff0c\u4e0d\u53d7\u5176\u4ed6\u9519\u8bef\u5e72\u6270\n *\/\nfunction psg_log( $message ) {\n    $log_file = WP_CONTENT_DIR . '\/psg-debug.log'; \/\/ \u65e5\u5fd7\u4fdd\u5b58\u5728 \/wp-content\/psg-debug.log\n    $time = date( 'Y-m-d H:i:s' );\n    $message = \"&#91;{$time}] {$message}\" . PHP_EOL; \/\/ PHP_EOL\u662f\u6362\u884c\u7b26\n    \/\/ \u5199\u5165\u6587\u4ef6\uff0cFILE_APPEND\u8868\u793a\u8ffd\u52a0\u800c\u4e0d\u8986\u76d6\n    file_put_contents( $log_file, $message, FILE_APPEND );\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\uff0c\u5728&nbsp;<code>class-employee-monitor.php<\/code>&nbsp;\u6587\u4ef6\u4e2d\uff0c\u5c06\u6240\u6709&nbsp;<code>error_log(\u2018PSG_DEBUG: ...\u2019)<\/code>&nbsp;\u7684\u8bed\u53e5\u66ff\u6362\u4e3a&nbsp;<code>psg_log( \u2018...\u2019 )<\/code>\u3002\u4f8b\u5982\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ \u66ff\u6362\u524d\nerror_log('PSG_DEBUG: PSG_Employee_Monitor \u7c7b\u5df2\u52a0\u8f7d\u3002');\n\/\/ \u66ff\u6362\u540e\npsg_log('PSG_DEBUG: PSG_Employee_Monitor \u7c7b\u5df2\u52a0\u8f7d\u3002');<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u6784\u5efa\u4e00\u4e2a\u53ef\u81ea\u5b9a\u4e49\u7684\u654f\u611f\u8d44\u6e90\u9632\u62a4\u4f53\u7cfb<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u529f\u80fd\u4e0d\u5c40\u9650\u4e8e\u6b64\uff0c\u56e0\u4e3a\u7f51\u7ad9\u8fd8\u6709\u5f88\u591a\u5176\u4ed6\u7684\u654f\u611f\u6587\u4ef6\uff0c\u6240\u4ee5\u60f3\u5bf9\u8fd9\u4e2a\u88c1\u526a\u7684\u5185\u5bb9\u518d\u8fdb\u884c\u6269\u5c55,\u6bd4\u65b9\u8bf4\u53ef\u4ee5\u521b\u9020\u4e00\u4e2a\u50cf\u5176\u4ed6\u63d2\u4ef6\u4e00\u6837\u90a3\u6837\u8bbe\u7f6e\u7684\u754c\u9762\uff0c\u53ea\u9700\u8981\u8f93\u5165\u4e00\u4e2a\u76ee\u5f55\u6216\u8005\u6587\u4ef6\u5939\uff0c\u90a3\u4e48\u53ea\u8981\u662f\u5728\u8fd9\u4e2a\u76ee\u5f55\u6216\u8005\u6587\u4ef6\u5939\u4e0b\u9762\u7684\u6240\u6709\u5185\u5bb9,\u4ed6\u90fd\u4e0d\u53ef\u4ee5\u8bbf\u95ee\u6216\u8005\u4fee\u6539\uff0c\u4f46\u662f\u53ef\u80fd\u6389\u5f88\u591a\u4e2a\u8f85\u52a9\u529f\u80fd\u6765\u8fdb\u884c\u76f8\u4e92\u8c03\u7528\uff0c\u5c31\u662f\u6bd4\u65b9\u8bf4\u6211\u6b63\u5e38\u7528\u6237\u53bb\u67e5\u770b\u6587\u7ae0\u5f15\u7528\u4e86\u4e00\u4e9b\u56fe\u7247\uff0c\u6211\u4eec\u9700\u8981\u53ef\u4ee5\u53ef\u9009\u62e9\u5f0f\u7684\u53bb\u9009\u62e9\u54ea\u4e9b\u6587\u4ef6\u5217\u8868\u662f\u53d7\u5f71\u54cd\u7684\u3002\u6216\u8005\u8bf4\u901a\u8fc7\u6b63\u5e38\u6253\u5f00\u7f51\u7ad9\uff0c\u6b63\u5e38\u7684\u8c03\u7528\u7684\u8bdd\u662f\u4e0d\u4f1a\u89e6\u53d1\u7684\uff0c\u90a3\u5982\u679c\u8ba9\u4ed6\u76f4\u63a5\u53bb\u8bbf\u95ee\u8fd9\u4e2a\u5730\u5740\u6216\u8005URL\u7684\u8bdd\u662f\u8981\u6536\u5230\u554a\u5c4f\u853d\u7684,\u6216\u8005\u5b83\u91c7\u7528\u4e86\u4ec0\u4e48\u8def\u5f84\u7a7f\u8d8a\uff1f\u6216\u8005\u662f\u8fd4\u56de\u4e0a\u7ea7\u76ee\u5f55\uff0c\u7136\u540e\u518d\u8fd9\u6837\u8fdb\u884c\u53cd\u590d\u8df3\u8f6c\u7684\uff0c\u6216\u8005\u662f\u8def\u5f84\u62fc\u63a5\u7684\u8fd9\u4e9b,\u6211\u4eec\u9700\u8981\u8003\u8651\u4e00\u4e0b\u3002\u8fd9\u662f\u4e00\u4e2a\u4ece\u201c\u56fa\u5b9a\u89c4\u5219\u201d\u5230\u201c\u7075\u6d3b\u7b56\u7565\u201d\u7684\u5347\u7ea7\u3002\u5b8c\u5168\u53ef\u4ee5\u5728\u73b0\u6709\u7684&nbsp;<code>Preluna Security Guard<\/code>&nbsp;\u63d2\u4ef6\u57fa\u7840\u4e0a\uff0c\u521b\u5efa\u4e00\u4e2a\u8bbe\u7f6e\u9875\u9762\u5e76\u5b9e\u73b0\u8fd9\u5957\u903b\u8f91\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6838\u5fc3\u601d\u8def\u662f\uff1a<strong>\u5728\u63d2\u4ef6\u540e\u53f0\u521b\u5efa\u4e00\u4e2a\u8bbe\u7f6e\u9875\uff0c\u8ba9\u4f60\u80fd\u81ea\u7531\u6dfb\u52a0\u9700\u8981\u4fdd\u62a4\u7684\u201c\u7981\u533a\u201d\u3002\u5f53\u6709\u8bbf\u95ee\u8bf7\u6c42\u65f6\uff0c\u63d2\u4ef6\u4f1a\u8fdb\u884c\u667a\u80fd\u5224\u65ad\uff0c\u53ea\u6709\u201c\u76f4\u63a5\u6076\u610f\u8bbf\u95ee\u201d\u624d\u4f1a\u88ab\u62e6\u622a\uff0c\u800c\u7f51\u7ad9\u81ea\u8eab\u7684\u6b63\u5e38\u8c03\u7528\u5219\u653e\u884c\u3002<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a410-645x1024.png'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"645\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a410-645x1024.png\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1391\"  sizes=\"auto, (max-width: 645px) 100vw, 645px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u5b9e\u73b0\u6b65\u9aa4<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u5206\u4e24\u6b65\u8d70\uff1a\u5148\u4e3a\u63d2\u4ef6\u589e\u52a0\u4e00\u4e2a\u8bbe\u7f6e\u9875\u9762\uff0c\u7136\u540e\u5b9e\u73b0\u4e0a\u56fe\u7684\u667a\u80fd\u68c0\u6d4b\u903b\u8f91\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u6b65\uff1a\u521b\u5efa\u63d2\u4ef6\u8bbe\u7f6e\u9875\u9762<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u63d2\u4ef6\u76ee\u5f55 (<code>preluna-security-guard\/includes<\/code>\/) \u4e0b\u65b0\u5efa\u4e00\u4e2a\u6587\u4ef6&nbsp;<code>class-settings-page.php<\/code>\uff0c\u5e76\u5199\u5165\u4ee5\u4e0b\u4ee3\u7801\u3002\u5b83\u5c06\u4e3a\u63d2\u4ef6\u6dfb\u52a0\u4e00\u4e2a\u201c\u5b89\u5168\u7981\u533a\u201d\u914d\u7f6e\u9875\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass PSG_Settings_Page {\n    private $option_name = 'psg_protected_paths';\n    private $settings_group = 'psg-settings-group';\n    \n    public function __construct() {\n        add_action('admin_menu', array($this, 'add_admin_menu'));\n        add_action('admin_init', array($this, 'register_settings'));\n    }\n    \n    public function add_admin_menu() {\n        \/\/ \u5728\u201c\u8bbe\u7f6e\u201d\u4e3b\u83dc\u5355\u4e0b\u6dfb\u52a0\u5b50\u83dc\u5355\n        add_options_page(\n            'PSG \u5b89\u5168\u7981\u533a\u8bbe\u7f6e', \/\/ \u9875\u9762\u6807\u9898\n            'PSG\u5b89\u5168\u7981\u533a',      \/\/ \u83dc\u5355\u6807\u9898\n            'manage_options',   \/\/ \u6743\u9650\u8981\u6c42\uff08\u7ba1\u7406\u5458\uff09\n            'psg-protected-paths', \/\/ \u9875\u9762URL slug\n            array($this, 'render_settings_page') \/\/ \u6e32\u67d3\u9875\u9762\u7684\u56de\u8c03\u51fd\u6570\n        );\n    }\n    \n    public function register_settings() {\n        register_setting($this-&gt;settings_group, $this-&gt;option_name);\n        add_settings_section('psg_main_section', '\u7ba1\u7406\u53d7\u4fdd\u62a4\u7684\u8def\u5f84', null, 'psg-protected-paths');\n        add_settings_field('psg_paths_field', '\u53d7\u4fdd\u62a4\u7684\u8def\u5f84', array($this, 'render_paths_field'), 'psg-protected-paths', 'psg_main_section');\n    }\n    \n    public function render_paths_field() {\n        $paths = get_option($this-&gt;option_name, '');\n        echo '&lt;textarea name=\"' . $this-&gt;option_name . '\" rows=\"10\" cols=\"100\" placeholder=\"\u6bcf\u884c\u4e00\u4e2a\u8def\u5f84\uff0c\u4f8b\u5982\uff1a\n\/wp-content\/secret-files\/\n\/wp-admin\/export.php\n\/uploads\/private\/\n\"&gt;' . esc_textarea($paths) . '&lt;\/textarea&gt;';\n        echo '&lt;p class=\"description\"&gt;\u6bcf\u4e00\u884c\u4ee3\u8868\u4e00\u4e2a\u9700\u8981\u4fdd\u62a4\u7684\u76ee\u5f55\u6216\u6587\u4ef6\u8def\u5f84\u3002\u5f53\u8fd9\u4e9b\u8def\u5f84\u88ab&lt;strong&gt;\u76f4\u63a5\u8bbf\u95ee&lt;\/strong&gt;\u65f6\uff0c\u5c06\u89e6\u53d1\u9632\u62a4\u89c4\u5219\u3002&lt;\/p&gt;';\n    }\n    \n    public function render_settings_page() {\n        ?&gt;\n        &lt;div class=\"wrap\"&gt;\n            &lt;h1&gt;PSG - \u5b89\u5168\u7981\u533a\u914d\u7f6e&lt;\/h1&gt;\n            &lt;form method=\"post\" action=\"options.php\"&gt;\n                &lt;?php\n                settings_fields($this-&gt;settings_group);\n                do_settings_sections('psg-protected-paths');\n                submit_button();\n                ?&gt;\n            &lt;\/form&gt;\n            &lt;hr&gt;\n            &lt;h3&gt;\u8bf4\u660e&lt;\/h3&gt;\n            &lt;ul&gt;\n                &lt;li&gt;&lt;strong&gt;\u8def\u5f84\u683c\u5f0f&lt;\/strong&gt;: \u4ee5\u7f51\u7ad9\u6839\u76ee\u5f55\u4e3a\u8d77\u70b9\uff0c\u5982 &lt;code&gt;\/wp-content\/plugins\/my-plugin\/secret.log&lt;\/code&gt;&lt;\/li&gt;\n                &lt;li&gt;&lt;strong&gt;\u667a\u80fd\u9632\u62a4&lt;\/strong&gt;: \u901a\u8fc7\u9875\u9762\u5185\u94fe\u63a5\u3001\u56fe\u7247src\u7b49&lt;strong&gt;\u6b63\u5e38\u8c03\u7528&lt;\/strong&gt;\u4e0d\u4f1a\u89e6\u53d1\u62e6\u622a\uff0c\u53ea\u6709\u6d4f\u89c8\u5668\u5730\u5740\u680f\u76f4\u63a5\u8f93\u5165\u3001\u626b\u63cf\u5668\u8bbf\u95ee\u7b49\u624d\u4f1a\u88ab\u963b\u6b62\u3002&lt;\/li&gt;\n                &lt;li&gt;&lt;strong&gt;\u8def\u5f84\u89c4\u8303&lt;\/strong&gt;: \u7cfb\u7edf\u4f1a\u81ea\u52a8\u5904\u7406 &lt;code&gt;..\/&lt;\/code&gt; \u7b49\u8def\u5f84\u7a7f\u8d8a\u5c1d\u8bd5\u3002&lt;\/li&gt;\n            &lt;\/ul&gt;\n        &lt;\/div&gt;\n        &lt;?php\n    }\n    \n    \/\/ \u63d0\u4f9b\u4e00\u4e2a\u516c\u5171\u65b9\u6cd5\uff0c\u8ba9\u5176\u4ed6\u7c7b\uff08\u5982\u76d1\u63a7\u7c7b\uff09\u80fd\u83b7\u53d6\u5230\u6240\u6709\u53d7\u4fdd\u62a4\u7684\u8def\u5f84\n    public static function get_protected_paths() {\n        $option = get_option('psg_protected_paths', '');\n        if (empty($option)) {\n            return array();\n        }\n        \/\/ \u6309\u884c\u5206\u5272\uff0c\u79fb\u9664\u7a7a\u884c\u548c\u7a7a\u683c\uff0c\u8fd4\u56de\u6570\u7ec4\n        return array_filter(array_map('trim', explode(\"\\n\", $option)));\n    }\n}\n?&gt;<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">\u7b2c\u4e8c\u6b65\uff1a\u5347\u7ea7\u76d1\u63a7\u7c7b\uff0c\u5b9e\u73b0\u667a\u80fd\u68c0\u6d4b<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u9700\u8981\u5927\u5e45\u4fee\u6539&nbsp;<code>includes\/class-employee-monitor.php<\/code>&nbsp;\u7684\u903b\u8f91\uff0c\u4f7f\u5176\u96c6\u6210\u65b0\u7684\u201c\u7981\u533a\u201d\u8bbe\u7f6e\uff0c\u5e76\u52a0\u5165\u667a\u80fd\u5224\u65ad\u3002<strong>\u8bf7\u7528\u4ee5\u4e0b\u4ee3\u7801\u5b8c\u5168\u66ff\u6362\u539f\u6587\u4ef6\u5185\u5bb9<\/strong>\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass PSG_Employee_Monitor {\n    \n    public function __construct() {\n        psg_log('PSG_DEBUG: \u667a\u80fd\u76d1\u63a7\u7c7b\u5df2\u52a0\u8f7d\u3002');\n        \/\/ \u540c\u65f6\u76d1\u63a7\u540e\u53f0\u9875\u9762\u548c\u6240\u6709\u524d\u7aef\u8bf7\u6c42\n        add_action('admin_init', array($this, 'monitor_author_actions'));\n        add_action('init', array($this, 'monitor_all_requests')); \/\/ \u65b0\u589e\uff1a\u76d1\u63a7\u6240\u6709\u8bf7\u6c42\n    }\n    \n    public function monitor_author_actions() {\n        \/\/ ... (\u8fd9\u91cc\u4fdd\u7559\u4f60\u4e4b\u524d\u5199\u7684\u3001\u4e13\u95e8\u68c0\u67e5\u540e\u53f0\u654f\u611f\u9875\u9762\u7684\u4ee3\u7801\u903b\u8f91\uff0c\u6b64\u5904\u7701\u7565\u4ee5\u8282\u7701\u7bc7\u5e45)\n        \/\/ \u4f60\u53ef\u4ee5\u5c06\u65e7\u7684\u3001\u68c0\u67e5\u56fa\u5b9a\u540e\u53f0\u8def\u5f84\u7684\u903b\u8f91\u5b8c\u5168\u4fdd\u7559\u5728\u8fd9\u91cc\u3002\n    }\n    \n    \/**\n     * \u65b0\u589e\uff1a\u76d1\u63a7\u6240\u6709\u8bf7\u6c42\uff0c\u5e94\u7528\u201c\u667a\u80fd\u7981\u533a\u201d\u89c4\u5219\n     *\/\n    public function monitor_all_requests() {\n        \/\/ 1. \u83b7\u53d6\u5f53\u524d\u8bf7\u6c42\u7684\u5b8c\u6574URL\u548c\u8def\u5f84\n        $request_uri = $_SERVER&#91;'REQUEST_URI'];\n        $request_path = parse_url($request_uri, PHP_URL_PATH); \/\/ \u63d0\u53d6\u8def\u5f84\u90e8\u5206\n        \n        \/\/ 2. \u83b7\u53d6\u7ba1\u7406\u5458\u914d\u7f6e\u7684\u6240\u6709\u201c\u7981\u533a\u201d\u8def\u5f84\n        $protected_paths = PSG_Settings_Page::get_protected_paths();\n        if (empty($protected_paths)) {\n            return; \/\/ \u6ca1\u6709\u8bbe\u7f6e\u7981\u533a\uff0c\u76f4\u63a5\u9000\u51fa\n        }\n        \n        \/\/ 3. \u5bf9\u8bf7\u6c42\u8def\u5f84\u8fdb\u884c\u89c4\u8303\u5316\uff0c\u9632\u5fa1\u8def\u5f84\u7a7f\u8d8a\u653b\u51fb (\u5982 \/secret\/..\/admin\/)\n        $normalized_request_path = $this-&gt;normalize_path($request_path);\n        \n        \/\/ 4. \u68c0\u67e5\u8bf7\u6c42\u8def\u5f84\u662f\u5426\u5339\u914d\u4efb\u4f55\u4e00\u4e2a\u201c\u7981\u533a\u201d\n        $matched_protected_path = null;\n        foreach ($protected_paths as $protected_path) {\n            $protected_path = trim($protected_path);\n            if (empty($protected_path)) continue;\n            \n            \/\/ \u89c4\u8303\u5316\u4fdd\u62a4\u533a\u8def\u5f84\uff0c\u5e76\u786e\u4fdd\u5b83\u4ee5\u659c\u6760\u5f00\u5934\n            $normalized_protected_path = $this-&gt;normalize_path($protected_path);\n            \n            \/\/ \u8fdb\u884c\u5339\u914d\u5224\u65ad\uff1a\u8bf7\u6c42\u8def\u5f84\u662f\u5426\u4ee5\u4fdd\u62a4\u533a\u8def\u5f84\u5f00\u5934\uff1f\n            if (strpos($normalized_request_path, $normalized_protected_path) === 0) {\n                $matched_protected_path = $protected_path;\n                break; \/\/ \u5339\u914d\u5230\u4e00\u4e2a\u5c31\u8df3\u51fa\u5faa\u73af\n            }\n        }\n        \n        \/\/ \u5982\u679c\u6ca1\u6709\u5339\u914d\u5230\u4efb\u4f55\u7981\u533a\uff0c\u76f4\u63a5\u653e\u884c\n        if ($matched_protected_path === null) {\n            return;\n        }\n        \n        psg_log(\"PSG_DEBUG: \u8bf7\u6c42\u8def\u5f84\u5339\u914d\u5230\u7981\u533a\u3002\u8bf7\u6c42: {$request_path}, \u7981\u533a: {$matched_protected_path}\");\n        \n        \/\/ 5. \u667a\u80fd\u5224\u65ad\uff1a\u662f\u5426\u662f\u201c\u76f4\u63a5\u6076\u610f\u8bbf\u95ee\u201d\uff1f\n        if ($this-&gt;is_malicious_direct_access()) {\n            \/\/ \u8ba4\u5b9a\u4e3a\u6076\u610f\u8bbf\u95ee\uff0c\u6267\u884c\u62e6\u622a\n            $this-&gt;handle_violation($matched_protected_path, $request_path);\n        } else {\n            \/\/ \u8ba4\u5b9a\u4e3a\u6b63\u5e38\u5f15\u7528\uff08\u5982\u56fe\u7247\u3001JS\/CSS\uff09\uff0c\u653e\u884c\n            psg_log(\"PSG_DEBUG: \u8bf7\u6c42\u6765\u81ea\u6b63\u5e38\u9875\u9762\u5f15\u7528\uff0c\u5df2\u653e\u884c\u3002\");\n        }\n    }\n    \n    \/**\n     * \u667a\u80fd\u5224\u65ad\u6838\u5fc3\uff1a\u533a\u5206\u6b63\u5e38\u5f15\u7528\u4e0e\u76f4\u63a5\u8bbf\u95ee\n     *\/\n    private function is_malicious_direct_access() {\n        \/\/ \u5173\u952e\u68c0\u67e51\uff1aHTTP Referer \u6765\u6e90\n        \/\/ \u5982\u679c\u8bf7\u6c42\u6765\u81ea\u4f60\u7f51\u7ad9\u5185\u90e8\u7684\u9875\u9762\uff08\u5982\u56fe\u7247\u88ab\u6587\u7ae0\u5f15\u7528\uff09\uff0cReferer\u4f1a\u5305\u542b\u4f60\u7684\u57df\u540d\n        $referer = $_SERVER&#91;'HTTP_REFERER'] ?? '';\n        $site_host = parse_url(home_url(), PHP_URL_HOST);\n        \n        if (!empty($referer) &amp;&amp; stripos($referer, $site_host) !== false) {\n            \/\/ Referer\u5b58\u5728\u4e14\u6765\u81ea\u672c\u7ad9\uff0c\u5f88\u53ef\u80fd\u662f\u6b63\u5e38\u7684\u5185\u5bb9\u5f15\u7528\uff08\u5982\u56fe\u7247\u3001\u9644\u4ef6\uff09\n            return false;\n        }\n        \n        \/\/ \u5173\u952e\u68c0\u67e52\uff1a\u5e38\u89c1\u7684\u9759\u6001\u6587\u4ef6\u8bf7\u6c42\u5934\n        \/\/ \u8bb8\u591a\u626b\u63cf\u5668\u3001\u6076\u610f\u8bf7\u6c42\u7684User-Agent\u5177\u6709\u7279\u5f81\uff0c\u53ef\u4ee5\u7b80\u5355\u5224\u65ad\n        $user_agent = $_SERVER&#91;'HTTP_USER_AGENT'] ?? '';\n        $suspicious_agents = array('sqlmap', 'acunetix', 'nessus', 'nikto', 'wpscan', 'dirb');\n        foreach ($suspicious_agents as $agent) {\n            if (stripos($user_agent, $agent) !== false) {\n                return true; \/\/ \u8ba4\u4e3a\u662f\u6076\u610f\u626b\u63cf\u5668\n            }\n        }\n        \n        \/\/ \u5982\u679c\u6ca1\u6709\u660e\u786e\u8bc1\u636e\u662f\u6b63\u5e38\u5f15\u7528\uff0c\u5219\u503e\u5411\u4e8e\u62e6\u622a\uff08\u4e25\u683c\u6a21\u5f0f\uff09\n        \/\/ \u5982\u679c\u4f60\u5e0c\u671b\u66f4\u5bbd\u677e\uff0c\u53ef\u4ee5\u5c06\u8fd9\u91cc\u6539\u4e3a return false;\n        return true;\n    }\n    \n    \/**\n     * \u5904\u7406\u8fdd\u89c4\u8bbf\u95ee\n     *\/\n    private function handle_violation($protected_path, $request_path) {\n        $current_user = wp_get_current_user();\n        $client_ip = $_SERVER&#91;'REMOTE_ADDR'];\n        \n        \/\/ \u8bb0\u5f55\u8be6\u7ec6\u7684\u8fdd\u89c4\u65e5\u5fd7\n        psg_log(\"PSG_ALERT: \u68c0\u6d4b\u5230\u5bf9\u7981\u533a\u7684\u76f4\u63a5\u8bbf\u95ee\uff01\u8def\u5f84: {$request_path}, \u7528\u6237: {$current_user-&gt;user_login}, IP: {$client_ip}\");\n        \n        \/\/ \u6839\u636e\u7528\u6237\u89d2\u8272\u6267\u884c\u4e0d\u540c\u64cd\u4f5c\n        if ($current_user-&gt;exists() &amp;&amp; in_array('author', (array) $current_user-&gt;roles)) {\n            \/\/ \u5982\u679c\u662f\u4f5c\u8005\uff0c\u6267\u884c\u5c01\u7981\n            $this-&gt;block_user($current_user, 'direct_access_to_protected_path', $protected_path);\n        } else {\n            \/\/ \u5982\u679c\u662f\u8bbf\u5ba2\u6216\u5176\u4ed6\u672a\u6388\u6743\u7528\u6237\uff0c\u53ef\u4ee5\u8fd4\u56de429\u6216\u6df7\u6dc6\u4fe1\u606f\n            \/\/ \u8fd9\u91cc\u4ee5\u8fd4\u56de429\u4e3a\u4f8b\uff0c\u4f60\u4e5f\u53ef\u4ee5\u6539\u6210\u4e4b\u524dNginx\u90a3\u6837\u7684\u6df7\u6dc6\u4fe1\u606f\n            status_header(429);\n            die('&lt;h1&gt;\u8bbf\u95ee\u8fdd\u89c4&lt;\/h1&gt;&lt;p&gt;\u7981\u6b62\u76f4\u63a5\u8bbf\u95ee\u53d7\u4fdd\u62a4\u7684\u8d44\u6e90\u3002&lt;\/p&gt;');\n        }\n    }\n    \n    \/**\n     * \u89c4\u8303\u5316\u8def\u5f84\uff0c\u9632\u5fa1\u8def\u5f84\u7a7f\u8d8a\u653b\u51fb\n     * \u4f8b\u5982\u5c06 \/a\/b\/..\/c \u8f6c\u6362\u4e3a \/a\/c\n     *\/\n    private function normalize_path($path) {\n        \/\/ \u786e\u4fdd\u8def\u5f84\u4ee5\u659c\u6760\u5f00\u5934\uff0c\u4fbf\u4e8e\u540e\u7eed\u5904\u7406\n        if (strpos($path, '\/') !== 0) {\n            $path = '\/' . $path;\n        }\n        \/\/ \u4f7f\u7528 realpath \u7684\u601d\u8def\uff0c\u4f46\u4e0d\u4f9d\u8d56\u6587\u4ef6\u5b9e\u9645\u5b58\u5728\uff0c\u4ec5\u5904\u7406 `..` \u548c `.`\n        $parts = explode('\/', $path);\n        $result = array();\n        foreach ($parts as $part) {\n            if ($part == '' || $part == '.') continue;\n            if ($part == '..') {\n                array_pop($result); \/\/ \u9047\u5230..\uff0c\u5219\u56de\u9000\u4e00\u7ea7\n            } else {\n                $result&#91;] = $part;\n            }\n        }\n        return '\/' . implode('\/', $result);\n    }\n    \n    \/\/ \u4fdd\u7559\u4f60\u539f\u6765\u7684 block_user \u65b9\u6cd5\uff0c\u7528\u4e8e\u5c01\u7981\u4f5c\u8005\n    private function block_user($user, $block_type, $trigger) {\n        \/\/ ... (\u8fd9\u91cc\u662f\u4f60\u539f\u6765\u53d1\u9001\u90ae\u4ef6\u3001\u6e05\u7a7a\u89d2\u8272\u3001\u5f3a\u5236\u4e0b\u7ebf\u7684\u4ee3\u7801\uff0c\u4fdd\u6301\u4e0d\u53d8)\n    }\n}\n?&gt;<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>\u7b2c\u4e09\u6b65\uff1a\u6574\u5408\u4e0e\u6fc0\u6d3b\u65b0\u6a21\u5757<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u6700\u540e\uff0c\u6211\u4eec\u9700\u8981\u5728\u63d2\u4ef6\u4e3b\u6587\u4ef6&nbsp;<code>preluna-security-guard.php<\/code>&nbsp;\u4e2d\uff0c\u5f15\u5165\u5e76\u521d\u59cb\u5316\u8fd9\u4e2a\u65b0\u7684\u8bbe\u7f6e\u9875\u9762\u7c7b\u3002\u5728\u73b0\u6709\u4ee3\u7801\u4e2d\u627e\u5230\u5305\u542b\u5176\u4ed6\u7c7b\u6587\u4ef6\u7684\u5730\u65b9\uff0c\u6dfb\u52a0\u5982\u4e0b\u884c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ \u5305\u542b\u6838\u5fc3\u529f\u80fd\u7c7b\u6587\u4ef6\nrequire_once PSG_PLUGIN_DIR . 'includes\/class-employee-monitor.php';\nrequire_once PSG_PLUGIN_DIR . 'includes\/class-guest-limiter.php';\n\/\/ +++ \u65b0\u589e\uff1a\u5f15\u5165\u8bbe\u7f6e\u9875\u9762\u7c7b +++\nrequire_once PSG_PLUGIN_DIR . 'includes\/class-settings-page.php';<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\u5728&nbsp;<code>psg_initialize()<\/code>&nbsp;\u51fd\u6570\u4e2d\u521d\u59cb\u5316\u5b83\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>function psg_initialize() {\n    new PSG_Employee_Monitor();\n    new PSG_Guest_Limiter();\n    \/\/ +++ \u65b0\u589e\uff1a\u521d\u59cb\u5316\u8bbe\u7f6e\u9875\u9762 +++\n    new PSG_Settings_Page();\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u4f7f\u7528\u4e0e\u6d4b\u8bd5\u6307\u5357<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u66f4\u65b0\u63d2\u4ef6<\/strong>\uff1a\u5c06\u4e0a\u8ff0\u4e09\u4e2a\u65b0\u6587\u4ef6\u4e0a\u4f20\u5e76\u4fee\u6539\u4e3b\u6587\u4ef6\u540e\uff0c\u5728\u540e\u53f0\u91cd\u65b0\u542f\u7528\u63d2\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u914d\u7f6e\u7981\u533a<\/strong>\uff1a\u8fdb\u5165&nbsp;<strong>\u201c\u8bbe\u7f6e\u201d -&gt; \u201cPSG\u5b89\u5168\u7981\u533a\u201d<\/strong>\uff0c\u5728\u6587\u672c\u6846\u4e2d\u6bcf\u884c\u6dfb\u52a0\u4e00\u4e2a\u4f60\u60f3\u4fdd\u62a4\u7684\u8def\u5f84\uff0c\u4f8b\u5982\uff1a<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\/wp-content\/uploads\/secret-docs\/\n\/wp-config-backup.txt\n\/inc\/database-connection.php<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u57fa\u4e8e\u89d2\u8272\u7684\u591a\u5c42\u6b21\u3001\u4e25\u683c\u6743\u9650\u6a21\u578b<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4e3a\u4e86\u5b9e\u73b0&nbsp;<strong>\u201c\u4e0d\u540c\u89d2\u8272\u6709\u4e0d\u540c\u7981\u533a\uff0c\u4e14\u9ad8\u6743\u9650\u8005\u4e5f\u4e0d\u80fd\u8d8a\u754c\u8bbf\u95ee\u4f4e\u6743\u9650\u4e13\u5c5e\u533a\u201d<\/strong>&nbsp;\u7684\u4e25\u683c\u6a21\u578b\uff0c\u6211\u4eec\u9700\u8981\u91cd\u6784\u63d2\u4ef6\u7684\u8bbe\u8ba1\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">&nbsp;\u65b0\u6a21\u578b\u8bbe\u8ba1\uff1a\u57fa\u4e8e\u89d2\u8272\u7684\u6700\u5c0f\u6743\u9650\u7b49\u7ea7<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u5c06\u5f15\u5165\u4e00\u4e2a&nbsp;<strong>\u201c\u6743\u9650\u7b49\u7ea7\u201d<\/strong>&nbsp;\u6982\u5ff5\uff0c\u5e76\u4e3a\u6bcf\u4e2a\u89d2\u8272\u548c\u6bcf\u6761\u201c\u7981\u533a\u201d\u8def\u5f84\u914d\u7f6e\u7b49\u7ea7\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u89d2\u8272 (Role)<\/th><th>\u6743\u9650\u7b49\u7ea7 (Level)<\/th><th>\u8bbe\u8ba1\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td><strong>\u7ba1\u7406\u5458 (Administrator)<\/strong><\/td><td>10<\/td><td>\u7cfb\u7edf\u6700\u9ad8\u6743\u9650\uff0c\u4f46\u6211\u4eec\u8d4b\u4e88\u5176\u4e00\u4e2a\u201c\u7b49\u7ea7\u201d\u800c\u975e\u201c\u4e07\u80fd\u94a5\u5319\u201d\u3002<\/td><\/tr><tr><td><strong>\u7f16\u8f91 (Editor)<\/strong><\/td><td>7<\/td><td>\u6743\u9650\u4f4e\u4e8e\u7ba1\u7406\u5458\uff0c\u4f46\u9ad8\u4e8e\u4f5c\u8005\u3002<\/td><\/tr><tr><td><strong>\u4f5c\u8005 (Author)<\/strong><\/td><td>5<\/td><td>\u6838\u5fc3\u521b\u4f5c\u89d2\u8272\uff0c\u6743\u9650\u660e\u786e\u4e14\u9700\u4e25\u683c\u63a7\u5236\u3002<\/td><\/tr><tr><td><strong>\u6295\u7a3f\u8005 (Contributor)<\/strong><\/td><td>3<\/td><td>\u6838\u5fc3\u521b\u4f5c\u89d2\u8272\uff0c\u6743\u9650\u660e\u786e\u4e14\u9700\u4e25\u683c\u63a7\u5236\u3002<\/td><\/tr><tr><td><strong>\u8ba2\u9605\u8005\/\u8bbf\u5ba2 (Subscriber\/Visitor)<\/strong><\/td><td>1<\/td><td>\u672a\u767b\u5f55\u8bbf\u5ba2\u7684\u6743\u9650\u7b49\u7ea7\u6700\u4f4e\uff0c\u53ea\u80fd\u8bbf\u95ee\u516c\u5f00\u8d44\u6e90\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6838\u5fc3\u89c4\u5219<\/strong>\uff1a\u8bbf\u95ee\u4e00\u6761\u8def\u5f84\u65f6\uff0c<strong>\u7528\u6237\u7684\u6743\u9650\u7b49\u7ea7\u5fc5\u987b\u5927\u4e8e\u6216\u7b49\u4e8e\u8def\u5f84\u8981\u6c42\u7684\u201c\u6700\u5c0f\u6743\u9650\u7b49\u7ea7\u201d<\/strong>\u3002\u5426\u5219\uff0c\u65e0\u8bba\u7528\u6237\u7b49\u7ea7\u591a\u9ad8\uff0c\u90fd\u5c06\u88ab\u62e6\u622a\u3002\u4f8b\u5982\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u4e00\u4e2a\u8981\u6c42\u7b49\u7ea7\u4e3a&nbsp;<strong>5\uff08\u4f5c\u8005\uff09<\/strong>&nbsp;\u7684\u76ee\u5f55\uff0c\u7b49\u7ea7 7 \u7684\u7f16\u8f91\u548c\u7b49\u7ea7 10 \u7684\u7ba1\u7406\u5458\u8bbf\u95ee\u4e5f\u4f1a\u88ab\u62d2\u3002<\/li>\n\n\n\n<li>\u4e00\u4e2a\u8981\u6c42\u7b49\u7ea7\u4e3a&nbsp;<strong>1\uff08\u516c\u5f00\uff09<\/strong>&nbsp;\u7684\u76ee\u5f55\uff0c\u6240\u6709\u7528\u6237\u5747\u53ef\u8bbf\u95ee\u3002<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">\u5b9e\u73b0\u65b9\u6848\uff1a\u5347\u7ea7\u63d2\u4ef6<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u9700\u8981\u5bf9\u63d2\u4ef6\u8fdb\u884c\u4e09\u5904\u6838\u5fc3\u6539\u9020\uff1a<strong>\u6570\u636e\u7ed3\u6784<\/strong>\u3001<strong>\u8bbe\u7f6e\u754c\u9762<\/strong>&nbsp;\u548c&nbsp;<strong>\u76d1\u63a7\u903b\u8f91<\/strong>\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u7b2c\u4e00\u6b65\uff1a\u66f4\u65b0\u6570\u636e\u7ed3\u6784\uff08\u4fee\u6539&nbsp;<code>psg_plugin_activation<\/code>\uff09<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u63d2\u4ef6\u4e3b\u6587\u4ef6&nbsp;<code>preluna-security-guard.php<\/code>&nbsp;\u4e2d\u627e\u5230&nbsp;<code>psg_plugin_activation<\/code>&nbsp;\u51fd\u6570\uff0c\u4fee\u6539\u9ed8\u8ba4\u8bbe\u7f6e\uff0c\u4e3a\u8def\u5f84\u589e\u52a0&nbsp;<code>min_level<\/code>&nbsp;\u5b57\u6bb5\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>function psg_plugin_activation() {\n    if ( ! get_option( 'psg_protected_paths' ) ) {\n        \/\/ \u65b0\u7684\u6570\u636e\u7ed3\u6784\uff1a\u6bcf\u6761\u8bb0\u5f55\u5305\u542b \u2018path\u2018 \u548c \u2018min_level\u2018\n        $default_paths = array(\n            array( 'path' =&gt; '\/wp-content\/uploads\/secret-admin\/', 'min_level' =&gt; 10 ),\n            array( 'path' =&gt; '\/wp-content\/uploads\/author-only-uploads\/', 'min_level' =&gt; 5 ),\n            array( 'path' =&gt; '\/wp-admin\/export.php', 'min_level' =&gt; 7 ),\n        );\n        add_option( 'psg_protected_paths', $default_paths );\n    }\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u7b2c\u4e8c\u6b65\uff1a\u91cd\u5efa\u8bbe\u7f6e\u9875\u9762\uff08\u66f4\u65b0&nbsp;<code>class-settings-page.php<\/code>\uff09<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u9700\u8981\u4e00\u4e2a\u80fd\u7f16\u8f91\u8def\u5f84\u548c\u7b49\u7ea7\u7684\u754c\u9762\u3002<strong>\u8bf7\u7528\u4ee5\u4e0b\u4ee3\u7801\u5b8c\u5168\u66ff\u6362\u539f\u6587\u4ef6\u5185\u5bb9<\/strong>\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&lt;?php\nclass PSG_Settings_Page {\n    private $option_name = 'psg_protected_paths';\n    private $settings_group = 'psg-settings-group';\n    \/\/ \u5b9a\u4e49\u89d2\u8272\u7b49\u7ea7\u6620\u5c04\n    private $role_levels = array(\n        'administrator' =&gt; 10,\n        'editor'        =&gt; 7,\n        'author'        =&gt; 5,\n        'contributor'   =&gt; 3,\n        'subscriber'    =&gt; 1,\n    );\n    \n    public function __construct() {\n        add_action('admin_menu', array($this, 'add_admin_menu'));\n        add_action('admin_init', array($this, 'register_settings'));\n    }\n    \n    public function add_admin_menu() {\n        add_options_page('PSG \u89d2\u8272\u6743\u9650\u7981\u533a', 'PSG\u89d2\u8272\u6743\u9650\u7981\u533a', 'manage_options', 'psg-protected-paths', array($this, 'render_settings_page'));\n    }\n    \n    public function register_settings() {\n        register_setting($this-&gt;settings_group, $this-&gt;option_name, array($this, 'sanitize_paths'));\n        add_settings_section('psg_main_section', '\u7ba1\u7406\u57fa\u4e8e\u89d2\u8272\u7684\u8bbf\u95ee\u8def\u5f84', null, 'psg-protected-paths');\n        add_settings_field('psg_paths_field', '\u8def\u5f84\u4e0e\u6743\u9650\u7b49\u7ea7', array($this, 'render_paths_field'), 'psg-protected-paths', 'psg_main_section');\n    }\n    \n    public function render_paths_field() {\n        $paths = get_option($this-&gt;option_name, array());\n        echo '&lt;div id=\"psg-paths-container\"&gt;';\n        if (empty($paths)) {\n            $paths = array( array('path' =&gt; '', 'min_level' =&gt; 1) );\n        }\n        foreach ($paths as $index =&gt; $path_entry) {\n            echo '&lt;div class=\"psg-path-row\" style=\"margin-bottom:10px;\"&gt;';\n            echo '&lt;input type=\"text\" name=\"psg_protected_paths&#91;'.$index.']&#91;path]\" value=\"'.esc_attr($path_entry&#91;'path']).'\" placeholder=\"\u5982: \/wp-content\/secret\/\" style=\"width:300px;margin-right:10px;\"&gt;';\n            echo '&lt;select name=\"psg_protected_paths&#91;'.$index.']&#91;min_level]\"&gt;';\n            foreach ($this-&gt;role_levels as $role =&gt; $level) {\n                $selected = selected($path_entry&#91;'min_level'], $level, false);\n                echo '&lt;option value=\"'.$level.'\" '.$selected.'&gt;'.ucfirst($role).' (\u7b49\u7ea7 '.$level.')&lt;\/option&gt;';\n            }\n            echo '&lt;\/select&gt;';\n            echo '&lt;button type=\"button\" class=\"button psg-remove-row\" style=\"margin-left:10px;\"&gt;\u79fb\u9664&lt;\/button&gt;';\n            echo '&lt;\/div&gt;';\n        }\n        echo '&lt;\/div&gt;';\n        echo '&lt;button type=\"button\" class=\"button\" id=\"psg-add-row\"&gt;\u6dfb\u52a0\u65b0\u89c4\u5219&lt;\/button&gt;';\n        echo '&lt;p class=\"description\"&gt;\u6bcf\u6761\u89c4\u5219\u6307\u5b9a\u4e00\u4e2a\u8def\u5f84\u548c&lt;strong&gt;\u5141\u8bb8\u8bbf\u95ee\u7684\u6700\u4f4e\u89d2\u8272\u7b49\u7ea7&lt;\/strong&gt;\u3002\u672a\u8fbe\u5230\u6b64\u7b49\u7ea7\u7684\u7528\u6237\uff08\u5305\u62ec\u66f4\u9ad8\u7b49\u7ea7\uff09\u8bbf\u95ee\u5747\u4f1a\u88ab\u62e6\u622a\u3002&lt;\/p&gt;';\n        \/\/ \u5185\u8054JS\uff0c\u7528\u4e8e\u52a8\u6001\u6dfb\u52a0\/\u5220\u9664\u884c\n        ?&gt;\n        &lt;script type=\"text\/javascript\"&gt;\n            jQuery(document).ready(function($) {\n                var rowIndex = &lt;?php echo count($paths); ?&gt;;\n                $('#psg-add-row').on('click', function() {\n                    var html = '&lt;div class=\"psg-path-row\" style=\"margin-bottom:10px;\"&gt;' +\n                               '&lt;input type=\"text\" name=\"psg_protected_paths&#91;' + rowIndex + ']&#91;path]\" placeholder=\"\u5982: \/wp-content\/secret\/\" style=\"width:300px;margin-right:10px;\"&gt;' +\n                               '&lt;select name=\"psg_protected_paths&#91;' + rowIndex + ']&#91;min_level]\"&gt;' +\n                               &lt;?php foreach ($this-&gt;role_levels as $role =&gt; $level): ?&gt;\n                               '&lt;option value=\"&lt;?php echo $level; ?&gt;\"&gt;&lt;?php echo ucfirst($role); ?&gt; (\u7b49\u7ea7 &lt;?php echo $level; ?&gt;)&lt;\/option&gt;' +\n                               &lt;?php endforeach; ?&gt;\n                               '&lt;\/select&gt;' +\n                               '&lt;button type=\"button\" class=\"button psg-remove-row\" style=\"margin-left:10px;\"&gt;\u79fb\u9664&lt;\/button&gt;' +\n                               '&lt;\/div&gt;';\n                    $('#psg-paths-container').append(html);\n                    rowIndex++;\n                });\n                $(document).on('click', '.psg-remove-row', function() {\n                    $(this).closest('.psg-path-row').remove();\n                });\n            });\n        &lt;\/script&gt;\n        &lt;?php\n    }\n    \n    public function sanitize_paths($input) {\n        $sanitized = array();\n        if (is_array($input)) {\n            foreach ($input as $entry) {\n                $path = sanitize_text_field(trim($entry&#91;'path'] ?? ''));\n                $level = absint($entry&#91;'min_level'] ?? 1);\n                if (!empty($path)) {\n                    $sanitized&#91;] = array('path' =&gt; $path, 'min_level' =&gt; $level);\n                }\n            }\n        }\n        return $sanitized;\n    }\n    \n    public function render_settings_page() {\n        ?&gt;\n        &lt;div class=\"wrap\"&gt;\n            &lt;h1&gt;PSG - \u57fa\u4e8e\u89d2\u8272\u7684\u4e25\u683c\u6743\u9650\u63a7\u5236&lt;\/h1&gt;\n            &lt;form method=\"post\" action=\"options.php\"&gt;\n                &lt;?php settings_fields($this-&gt;settings_group); ?&gt;\n                &lt;?php do_settings_sections('psg-protected-paths'); ?&gt;\n                &lt;?php submit_button('\u4fdd\u5b58\u6240\u6709\u89c4\u5219'); ?&gt;\n            &lt;\/form&gt;\n            &lt;hr&gt;\n            &lt;h3&gt;\u6743\u9650\u7b49\u7ea7\u8bf4\u660e&lt;\/h3&gt;\n            &lt;ul&gt;\n                &lt;li&gt;&lt;strong&gt;\u4e25\u683c\u5c42\u7ea7\u6a21\u578b&lt;\/strong&gt;\uff1a\u6bcf\u4e2a\u89d2\u8272\u6709\u56fa\u5b9a\u7b49\u7ea7\u3002\u7528\u6237&lt;strong&gt;\u5fc5\u987b\u8fbe\u5230&lt;\/strong&gt;\u8def\u5f84\u8981\u6c42\u7684\u6700\u4f4e\u7b49\u7ea7\u624d\u80fd\u8bbf\u95ee\u3002&lt;\/li&gt;\n                &lt;li&gt;&lt;strong&gt;\u9ad8\u7b49\u7ea7\u4e0d\u4ee3\u8868\u4e07\u80fd&lt;\/strong&gt;\uff1a\u4e3a\u201c\u4f5c\u8005\u4e0a\u4f20\u76ee\u5f55\u201d\u8bbe\u7f6e\u7b49\u7ea75\uff0c\u5219&lt;strong&gt;\u7f16\u8f91(7)\u548c\u7ba1\u7406\u5458(10)\u8bbf\u95ee\u4e5f\u4f1a\u88ab\u62d2\u7edd&lt;\/strong&gt;\uff0c\u5b9e\u73b0\u201c\u9ad8\u6743\u8005\u4e0d\u80fd\u8bbf\u95ee\u4f4e\u6743\u4e13\u5c5e\u533a\u201d\u3002&lt;\/li&gt;\n                &lt;li&gt;&lt;strong&gt;\u8bbf\u5ba2(\u7b49\u7ea71)\u7684\u7981\u533a&lt;\/strong&gt;\uff1a\u4e3a\u5176\u8bbe\u7f6e\u7b49\u7ea7&gt;1\u7684\u8def\u5f84\uff08\u5982\u540e\u53f0\u767b\u5f55\u9875&lt;code&gt;\/wp-login.php&lt;\/code&gt;\u53ef\u8bbe\u4e3a5\uff09\uff0c\u4efb\u4f55\u8d8a\u6743\u8bbf\u95ee\u5c06\u7acb\u523b\u88ab\u62e6\u622a\u3002&lt;\/li&gt;\n            &lt;\/ul&gt;\n        &lt;\/div&gt;\n        &lt;?php\n    }\n    \n    public static function get_protected_paths() {\n        return get_option('psg_protected_paths', array());\n    }\n    \n    public static function get_user_level($user) {\n        $role_levels = array(\n            'administrator' =&gt; 10,\n            'editor'        =&gt; 7,\n            'author'        =&gt; 5,\n            'contributor'   =&gt; 3,\n            'subscriber'    =&gt; 1,\n        );\n        $user_roles = $user-&gt;roles;\n        $highest_level = 1; \/\/ \u9ed8\u8ba4\u8bbf\u5ba2\u7b49\u7ea7\n        foreach ($user_roles as $role) {\n            if (isset($role_levels&#91;$role])) {\n                $highest_level = max($highest_level, $role_levels&#91;$role]);\n            }\n        }\n        return $highest_level;\n    }\n}\n?&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u7b2c\u4e09\u6b65\uff1a\u5347\u7ea7\u76d1\u63a7\u903b\u8f91\uff08\u66f4\u65b0&nbsp;<code>class-employee-monitor.php<\/code>\uff09<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u76d1\u63a7\u7c7b\u9700\u8981\u8c03\u7528\u65b0\u7684\u89d2\u8272\u7b49\u7ea7\u903b\u8f91\u3002\u4e3b\u8981\u4fee\u6539&nbsp;<code>monitor_all_requests<\/code>&nbsp;\u65b9\u6cd5\u4e2d\u5224\u65ad\u90e8\u5206\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public function monitor_all_requests() {\n    $request_uri = $_SERVER&#91;'REQUEST_URI'];\n    $request_path = parse_url($request_uri, PHP_URL_PATH);\n    $normalized_request_path = $this-&gt;normalize_path($request_path);\n    \n    \/\/ \u83b7\u53d6\u5f53\u524d\u7528\u6237\u53ca\u5176\u7b49\u7ea7\n    $current_user = wp_get_current_user();\n    $user_level = PSG_Settings_Page::get_user_level($current_user);\n    psg_log(\"PSG_DEBUG: \u7528\u6237 \u2018{$current_user-&gt;user_login}\u2018 \u7b49\u7ea7: {$user_level}, \u8bf7\u6c42\u8def\u5f84: {$request_path}\");\n    \n    $protected_paths = PSG_Settings_Page::get_protected_paths();\n    if (empty($protected_paths)) return;\n    \n    foreach ($protected_paths as $entry) {\n        $protected_path = $this-&gt;normalize_path(trim($entry&#91;'path']));\n        $required_level = absint($entry&#91;'min_level']);\n        if (empty($protected_path)) continue;\n        \n        \/\/ \u5339\u914d\u8def\u5f84\n        if (strpos($normalized_request_path, $protected_path) === 0) {\n            psg_log(\"PSG_DEBUG: \u8def\u5f84\u5339\u914d\u3002\u8981\u6c42\u7b49\u7ea7: {$required_level}, \u7528\u6237\u7b49\u7ea7: {$user_level}\");\n            \n            \/\/ \u6838\u5fc3\uff1a\u4e25\u683c\u6743\u9650\u68c0\u67e5\n            if ($user_level &lt; $required_level) {\n                \/\/ \u7528\u6237\u7b49\u7ea7\u4e0d\u8fbe\u6807\uff0c\u6267\u884c\u62e6\u622a\n                if ($this-&gt;is_malicious_direct_access()) {\n                    $this-&gt;handle_violation($entry, $request_path, $user_level, $required_level);\n                    return; \/\/ \u62e6\u622a\u540e\u9000\u51fa\n                }\n            } else {\n                \/\/ \u7528\u6237\u7b49\u7ea7\u8fbe\u6807\uff0c\u65e0\u8bba\u662f\u5426\u4e3a\u76f4\u63a5\u8bbf\u95ee\uff0c\u90fd\u5141\u8bb8\uff08\u6839\u636e\u4f60\u7684\u9700\u6c42\uff0c\u4e5f\u53ef\u5728\u6b64\u5904\u52a0\u5165\u76f4\u63a5\u8bbf\u95ee\u5224\u65ad\u4ee5\u66f4\u4e25\u683c\uff09\n                psg_log(\"PSG_DEBUG: \u7528\u6237\u7b49\u7ea7\u8fbe\u6807\uff0c\u5141\u8bb8\u8bbf\u95ee\u3002\");\n            }\n            break; \/\/ \u5339\u914d\u5230\u4e00\u6761\u89c4\u5219\u540e\u5373\u8df3\u51fa\u5faa\u73af\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u540c\u65f6\uff0c\u66f4\u65b0\u8fdd\u89c4\u5904\u7406\u51fd\u6570&nbsp;<code>handle_violation<\/code>\uff0c\u52a0\u5165\u7b49\u7ea7\u4fe1\u606f\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>private function handle_violation($path_entry, $request_path, $user_level, $required_level) {\n    $current_user = wp_get_current_user();\n    $client_ip = $_SERVER&#91;'REMOTE_ADDR'];\n    psg_log(\"PSG_ALERT: \u6743\u9650\u7b49\u7ea7\u8fdd\u89c4\uff01\u8def\u5f84: {$path_entry&#91;'path']}, \u8981\u6c42\u7b49\u7ea7: {$required_level}, \u7528\u6237\u7b49\u7ea7: {$user_level}, IP: {$client_ip}\");\n    \n    \/\/ \u6839\u636e\u7528\u6237\u89d2\u8272\u6267\u884c\u4e0d\u540c\u64cd\u4f5c\n    if ($current_user-&gt;exists()) {\n        if (in_array('author', (array) $current_user-&gt;roles)) {\n            $this-&gt;block_user($current_user, 'insufficient_level', $path_entry&#91;'path']);\n        } else {\n            \/\/ \u5176\u4ed6\u5df2\u767b\u5f55\u89d2\u8272\uff08\u5982\u7f16\u8f91\uff09\u4e5f\u89e6\u53d1\u4e25\u5389\u63aa\u65bd\uff0c\u4f8b\u5982\u5f3a\u5236\u767b\u51fa\u5e76\u8b66\u544a\n            wp_logout();\n            status_header(403);\n            die('&lt;h1&gt;403 \u6743\u9650\u7981\u6b62&lt;\/h1&gt;&lt;p&gt;\u60a8\u7684\u89d2\u8272\u65e0\u6743\u8bbf\u95ee\u6b64\u4e13\u7528\u8d44\u6e90\u3002&lt;\/p&gt;');\n        }\n    } else {\n        \/\/ \u8bbf\u5ba2\u89e6\u53d1\u6700\u4e25\u5389\u62e6\u622a\uff08429\u6216\u7acb\u5373IP\u9ed1\u540d\u5355\uff09\n        status_header(429);\n        die('&lt;h1&gt;429 \u7981\u6b62\u8bbf\u95ee&lt;\/h1&gt;&lt;p&gt;\u672a\u6388\u6743\u8bbf\u95ee\u5c1d\u8bd5\u5df2\u88ab\u8bb0\u5f55\u3002&lt;\/p&gt;');\n    }\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u914d\u7f6e\u4e0e\u6d4b\u8bd5\u6d41\u7a0b<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u66f4\u65b0\u63d2\u4ef6\u6587\u4ef6<\/strong>\uff1a\u66ff\u6362\u4e0a\u8ff0\u4e09\u4e2a\u6587\u4ef6\uff08\u4e3b\u6587\u4ef6\u3001\u8bbe\u7f6e\u9875\u3001\u76d1\u63a7\u7c7b\uff09\u3002<\/li>\n\n\n\n<li><strong>\u914d\u7f6e\u89d2\u8272\u7981\u533a<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li>\u8fdb\u5165&nbsp;<strong>\u201c\u8bbe\u7f6e\u201d -&gt; \u201cPSG\u89d2\u8272\u6743\u9650\u7981\u533a\u201d<\/strong>\u3002<\/li>\n\n\n\n<li>\u6dfb\u52a0\u89c4\u5219\uff0c\u4f8b\u5982\uff1a\n<ul class=\"wp-block-list\">\n<li><code>\/wp-content\/uploads\/author-private\/<\/code>&nbsp;-&gt;&nbsp;<strong>\u4f5c\u8005 (\u7b49\u7ea7 5)<\/strong>\uff1a\u521b\u5efa\u4e00\u4e2a\u53ea\u6709\u4f5c\u8005\u80fd\u8bbf\u95ee\u7684\u76ee\u5f55\u3002<\/li>\n\n\n\n<li><code>\/wp-admin\/edit.php<\/code>&nbsp;-&gt;&nbsp;<strong>\u7f16\u8f91 (\u7b49\u7ea7 7)<\/strong>\uff1a\u9650\u5236\u4f5c\u8005\u8bbf\u95ee\u6587\u7ae0\u5217\u8868\u9875\uff08\u5982\u679c\u4ed6\u4eec\u4e0d\u8be5\u7ba1\u7406\u6240\u6709\u6587\u7ae0\uff09\u3002<\/li>\n\n\n\n<li><code>\/wp-login.php<\/code>&nbsp;-&gt;&nbsp;<strong>\u4f5c\u8005 (\u7b49\u7ea7 5)<\/strong>\uff1a<strong>\u5373\u4f7f\u8bbf\u5ba2\u77e5\u9053\u767b\u5f55\u5730\u5740\uff0c\u5c1d\u8bd5\u8bbf\u95ee\u4e5f\u4f1a\u56e0\u7b49\u7ea7\u4e0d\u8db3\u88ab\u62d2<\/strong>\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u4e25\u683c\u6d4b\u8bd5<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u6d4b\u8bd51\uff08\u4f5c\u8005\u8bbf\u95ee\u4e13\u5c5e\u76ee\u5f55\uff09<\/strong>\uff1a\u4f5c\u8005\u8bbf\u95ee&nbsp;<code>\/wp-content\/uploads\/author-private\/<\/code>\uff0c\u5e94\u6210\u529f\uff08\u7b49\u7ea7\u8fbe\u6807\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6d4b\u8bd52\uff08\u7f16\u8f91\u8bbf\u95ee\u4f5c\u8005\u4e13\u5c5e\u533a\uff09<\/strong>\uff1a\u7f16\u8f91\u8bbf\u95ee\u540c\u4e00\u76ee\u5f55\uff0c<strong>\u5e94\u88ab\u62e6\u622a<\/strong>\uff08\u7b49\u7ea77 &gt; 5\uff0c\u4f46\u4e0d\u7b26\u5408\u201c\u6b63\u597d\u4e3a5\u201d\u7684\u4e25\u683c\u6a21\u578b\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6d4b\u8bd53\uff08\u8bbf\u5ba2\u8d8a\u754c\uff09<\/strong>\uff1a\u672a\u767b\u5f55\u8bbf\u5ba2\u8bbf\u95ee\u4efb\u4f55\u7b49\u7ea7 &gt;1 \u7684\u8def\u5f84\uff08\u5982\u767b\u5f55\u9875\uff09\uff0c<strong>\u5e94\u7acb\u523b\u88ab\u4e25\u5389\u62e6\u622a<\/strong>\u3002<\/li>\n\n\n\n<li><strong>\u6d4b\u8bd54\uff08\u8def\u5f84\u7a7f\u8d8a\uff09<\/strong>\uff1a\u5c1d\u8bd5\u7528&nbsp;<code>\/wp-content\/uploads\/author-private\/..\/<\/code>&nbsp;\u7b49\u65b9\u5f0f\u7ed5\u8fc7\uff0c\u56e0\u8def\u5f84\u89c4\u8303\u5316\uff0c\u540c\u6837\u4f1a\u88ab\u5339\u914d\u548c\u62e6\u622a\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u300cPreluna Security Guard\u300d\u63d2\u4ef6\u67b6\u6784\u4e0e\u903b\u8f91\u8bf4\u660e\u6587\u6863<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e00\u3001 \u6838\u5fc3\u8bbe\u8ba1\u7406\u5ff5\uff1a\u57fa\u4e8e\u89d2\u8272\u7684\u6700\u5c0f\u6743\u9650\u7b49\u7ea7\u6a21\u578b<\/strong><\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u6838\u5fc3\u7406\u5ff5<\/strong>\uff1a\u5c06\u4f20\u7edf\u7684\u201c\u9ad8\u6743\u9650\u8bbf\u95ee\u4f4e\u6743\u9650\u8d44\u6e90\u201d\u6a21\u578b\uff0c\u8f6c\u53d8\u4e3a&nbsp;<strong>\u201c\u6bcf\u4e2a\u8d44\u6e90\u6709\u660e\u786e\u7684\u8bbf\u95ee\u95e8\u69db\uff0c\u4efb\u4f55\u672a\u8fbe\u6807\u8005\u7686\u88ab\u62d2\u7edd\u201d<\/strong>&nbsp;\u7684\u4e25\u683c\u6a21\u578b\u3002<\/li>\n\n\n\n<li><strong>\u6838\u5fc3\u6620\u5c04<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u7528\u6237 \u2192 \u7b49\u7ea7<\/strong>\uff1a\u6bcf\u4e2a\u7528\u6237\u89d2\u8272\uff08\u542b\u201c\u8bbf\u5ba2\u201d\uff09\u88ab\u8d4b\u4e88\u4e00\u4e2a\u56fa\u5b9a\u7684\u6743\u9650\u7b49\u7ea7\u6570\u503c\u3002\u6b64\u7b49\u7ea7\u4ee3\u8868\u5176<strong>\u8eab\u4efd<\/strong>\uff0c\u800c\u975e\u201c\u4e07\u80fd\u94a5\u5319\u201d\u3002<\/li>\n\n\n\n<li><strong>\u8def\u5f84 \u2192 \u7b49\u7ea7<\/strong>\uff1a\u6bcf\u6761\u53d7\u4fdd\u62a4\u7684\u8def\u5f84\uff08\u6587\u4ef6\u6216\u76ee\u5f55\uff09\u8bbe\u7f6e\u4e00\u4e2a&nbsp;<strong>\u201c\u6700\u5c0f\u5141\u8bb8\u8bbf\u95ee\u7b49\u7ea7\u201d<\/strong>\u3002\u8fd9\u4ee3\u8868\u8bbf\u95ee\u8be5\u8d44\u6e90\u6240\u9700\u7684<strong>\u6700\u4f4e\u8eab\u4efd\u95e8\u69db<\/strong>\u3002<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>\u9ec4\u91d1\u89c4\u5219<\/strong>\uff1a\u5f53\u7528\u6237\u5c1d\u8bd5\u8bbf\u95ee\u8def\u5f84\u65f6\uff0c\u7cfb\u7edf\u6bd4\u8f83&nbsp;<code>\u7528\u6237\u7b49\u7ea7 &gt;= \u8def\u5f84\u8981\u6c42\u7b49\u7ea7<\/code>\u3002<strong>\u7ed3\u679c\u4e3a\u5047\uff0c\u5219\u65e0\u6761\u4ef6\u62d2\u7edd<\/strong>\u3002\u8fd9\u610f\u5473\u7740\uff1a\n<ul class=\"wp-block-list\">\n<li>\u4e3a\u201c\u4f5c\u8005\u4e13\u7528\u76ee\u5f55\u201d\u8bbe\u7f6e\u7b49\u7ea75\uff0c\u5219\u7b49\u7ea710\u7684\u7ba1\u7406\u5458\u548c\u7b49\u7ea77\u7684\u7f16\u8f91\u8bbf\u95ee\u4e5f\u4f1a\u88ab\u62d2\u7edd\u3002<\/li>\n\n\n\n<li>\u4e3a\u201c\u540e\u53f0\u767b\u5f55\u9875\u201d\u8bbe\u7f6e\u7b49\u7ea75\uff0c\u5219\u7b49\u7ea71\u7684\u8bbf\u5ba2\u4efb\u4f55\u8bbf\u95ee\u5c1d\u8bd5\u5c06\u7acb\u5373\u88ab\u62e6\u622a\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e8c\u3001 \u7cfb\u7edf\u67b6\u6784\u4e0e\u6587\u4ef6\u8c03\u7528\u5173\u7cfb<\/strong><\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>preluna-security-guard\/          # \u63d2\u4ef6\u6839\u76ee\u5f55\n\u251c\u2500\u2500 preluna-security-guard.php   # \u4e3b\u63a7\u5236\u5668\uff1a\u5b9a\u4e49\u63d2\u4ef6\u3001\u52a0\u8f7d\u6838\u5fc3\u7c7b\u3001\u7ba1\u7406\u751f\u547d\u5468\u671f\n\u251c\u2500\u2500 includes\/                    # \u6838\u5fc3\u529f\u80fd\u6a21\u5757\n\u2502   \u251c\u2500\u2500 class-employee-monitor.php # \u5927\u8111\uff1a\u76d1\u542c\u8bf7\u6c42\u3001\u8fdb\u884c\u6743\u9650\u5224\u65ad\u3001\u6267\u884c\u5c01\u7981\n\u2502   \u251c\u2500\u2500 class-settings-page.php    # \u4ea4\u4e92\u754c\u9762\uff1a\u63d0\u4f9b\u540e\u53f0\u9875\u9762\u4ee5\u914d\u7f6e\u8def\u5f84\u4e0e\u7b49\u7ea7\n\u2502   \u2514\u2500\u2500 class-guest-limiter.php    # \u8f85\u52a9\u6a21\u5757\uff1a\u72ec\u7acb\u5904\u7406\u8bbf\u5ba2\u9891\u7387\u9650\u5236\uff08\u5f53\u524d\u672a\u6df1\u5ea6\u96c6\u6210\uff09\n\u2514\u2500\u2500 (\u672a\u6765\u7684) uninstall.php       # \u5378\u8f7d\u6e05\u7406\u811a\u672c<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6587\u4ef6\u8c03\u7528\u6d41\u7a0b<\/strong>\uff1a<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u521d\u59cb\u5316<\/strong>\uff1aWordPress\u52a0\u8f7d\u63d2\u4ef6\uff0c\u6267\u884c&nbsp;<code>preluna-security-guard.php<\/code>&nbsp;\u4e2d\u7684&nbsp;<code>psg_initialize()<\/code>&nbsp;\u51fd\u6570\u3002<\/li>\n\n\n\n<li><strong>\u52a0\u8f7d\u6a21\u5757<\/strong>\uff1a\u8be5\u51fd\u6570\u5b9e\u4f8b\u5316\u4e09\u4e2a\u6838\u5fc3\u7c7b&nbsp;<code>PSG_Employee_Monitor<\/code>\uff0c&nbsp;<code>PSG_Guest_Limiter<\/code>\uff0c&nbsp;<code>PSG_Settings_Page<\/code>\u3002\u5b83\u4eec\u901a\u8fc7WordPress\u7684\u94a9\u5b50\u7cfb\u7edf\u5d4c\u5165\u76f8\u5e94\u6d41\u7a0b\u3002<\/li>\n\n\n\n<li><strong>\u5206\u5de5\u534f\u4f5c<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><code>\u8bbe\u7f6e\u9875\u9762\u7c7b<\/code>\uff1a\u54cd\u5e94\u7ba1\u7406\u5458\u5728\u540e\u53f0\u7684\u83dc\u5355\u70b9\u51fb\uff0c\u6e32\u67d3\u5e76\u5904\u7406\u8868\u5355\uff0c\u5c06\u914d\u7f6e\u4fdd\u5b58\u81f3\u6570\u636e\u5e93\u9009\u9879&nbsp;<code>psg_protected_paths<\/code>\u3002<\/li>\n\n\n\n<li><code>\u76d1\u63a7\u6838\u5fc3\u7c7b<\/code>\uff1a\u5728\u7528\u6237\u6bcf\u4e2a\u9875\u9762\u8bf7\u6c42\u7684\u65e9\u671f\uff08<code>init<\/code>&nbsp;\u548c&nbsp;<code>admin_init<\/code>&nbsp;\u94a9\u5b50\uff09\uff0c\u4ece\u6570\u636e\u5e93\u8bfb\u53d6\u914d\u7f6e\uff0c\u6267\u884c\u6743\u9650\u5224\u65ad\u3002<\/li>\n\n\n\n<li><code>\u9891\u7387\u9650\u5236\u7c7b<\/code>\uff1a\u5728\u6bcf\u6b21\u8bf7\u6c42\u65f6\uff08<code>init<\/code>&nbsp;\u94a9\u5b50\uff09\uff0c\u72ec\u7acb\u68c0\u67e5\u672a\u767b\u5f55\u7528\u6237\u7684\u8bbf\u95ee\u9891\u7387\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e09\u3001 \u6838\u5fc3\u529f\u80fd\u5b9e\u73b0\u903b\u8f91\u8be6\u89e3<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. \u6743\u9650\u5224\u65ad\u4e0e\u62e6\u622a\u6d41\u7a0b<\/strong>  \u81ea\u5df1\u88ab\u81ea\u5df1\u5199\u7684\u4e1c\u897f\u7ed9\u9650\u5236\u6b7b\u4e86\u3002:(<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a411-987x1024.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"987\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a411-987x1024.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1400\"  sizes=\"auto, (max-width: 987px) 100vw, 987px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a411-1-1018x1024.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1018\" height=\"1024\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a411-1-1018x1024.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1401\"  sizes=\"auto, (max-width: 1018px) 100vw, 1018px\" \/><\/div><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u5173\u952e\u51fd\u6570<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><code>normalize_path($path)<\/code>: \u9632\u5fa1\u8def\u5f84\u7a7f\u8d8a\u653b\u51fb\u7684\u6838\u5fc3\u3002\u901a\u8fc7\u89e3\u6790\u548c\u91cd\u7ec4\u8def\u5f84\u90e8\u4ef6\uff0c\u5c06\u7c7b\u4f3c&nbsp;<code>\/safe\/..\/secret\/file.txt<\/code>&nbsp;\u7684\u8bf7\u6c42\u89c4\u8303\u5316\u4e3a&nbsp;<code>\/secret\/file.txt<\/code>\uff0c\u786e\u4fdd\u540e\u7eed\u5339\u914d\u51c6\u786e\u3002<\/li>\n\n\n\n<li><code>is_malicious_direct_access()<\/code>: \u667a\u80fd\u653e\u884c\u7684\u5173\u952e\u3002\u901a\u8fc7\u68c0\u67e5HTTP\u8bf7\u6c42\u5934\u4e2d\u7684&nbsp;<code>Referer<\/code>\uff08\u6765\u6e90\u9875\uff09\u662f\u5426\u6765\u81ea\u672c\u7ad9\uff0c\u4ee5\u53ca&nbsp;<code>User-Agent<\/code>&nbsp;\u662f\u5426\u5305\u542b\u5df2\u77e5\u626b\u63cf\u5668\u7279\u5f81\uff0c\u6765\u533a\u5206\u201c\u6076\u610f\u76f4\u63a5\u8bbf\u95ee\u201d\u548c\u201c\u7f51\u7ad9\u6b63\u5e38\u529f\u80fd\u8c03\u7528\u201d\u3002<\/li>\n\n\n\n<li><code>PSG_Settings_Page::get_user_level($user)<\/code>: \u8ba1\u7b97\u7528\u6237\u7b49\u7ea7\u7684\u6838\u5fc3\u3002\u6839\u636e\u9884\u8bbe\u7684\u89d2\u8272\u7b49\u7ea7\u6620\u5c04\u8868\uff0c\u8fd4\u56de\u7528\u6237\u6240\u6709\u89d2\u8272\u4e2d\u7684\u6700\u9ad8\u7b49\u7ea7\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. \u5c01\u7981\u5904\u7f5a\u673a\u5236<\/strong><br>\u5904\u7f5a\u7684\u4e25\u5389\u7a0b\u5ea6\u6839\u636e\u5165\u4fb5\u8005\u8eab\u4efd\u5448\u9636\u68af\u5f0f\u4e0a\u5347<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u89e6\u53d1\u8005\u8eab\u4efd<\/th><th>\u5904\u7f5a\u673a\u5236 (<code>handle_violation<\/code>&nbsp;&amp;&nbsp;<code>block_user<\/code>)<\/th><th>\u8bbe\u8ba1\u610f\u56fe<\/th><\/tr><\/thead><tbody><tr><td><strong>\u4f5c\u8005<\/strong><\/td><td>1.&nbsp;<strong>\u6e05\u7a7a\u8d26\u53f7\u6240\u6709\u89d2\u8272<\/strong>&nbsp;(<code>$user-&gt;set_role('')<\/code>)\u3002<br>2.&nbsp;<strong>\u5f3a\u5236\u767b\u51fa<\/strong>\u5f53\u524d\u6240\u6709\u4f1a\u8bdd\u3002<br>3.&nbsp;<strong>\u53d1\u9001\u90ae\u4ef6<\/strong>\u901a\u77e5\u7ba1\u7406\u5458\u3002<br>4. \u91cd\u5b9a\u5411\u81f3\u8b66\u544a\u9875\u3002<\/td><td>\u6700\u4e25\u5389\u7684<strong>\u5e94\u7528\u5c42\u5c01\u7981<\/strong>\u3002\u8d26\u53f7\u5373\u523b\u5931\u6548\uff0c\u4e14\u65e0\u6cd5\u81ea\u884c\u6062\u590d\uff0c\u9700\u7ba1\u7406\u5458\u5e72\u9884\u3002\u65e8\u5728\u5185\u90e8\u9707\u6151\u3002<\/td><\/tr><tr><td><strong>\u5176\u4ed6\u767b\u5f55\u7528\u6237 (\u5982\u7f16\u8f91)<\/strong><\/td><td>1.&nbsp;<strong>\u5f3a\u5236\u767b\u51fa<\/strong>\u5f53\u524d\u4f1a\u8bdd\u3002<br>2. \u8fd4\u56de&nbsp;<strong>403 Forbidden<\/strong>&nbsp;\u9519\u8bef\u9875\u3002<\/td><td>\u4e25\u5389\u8b66\u544a\u3002\u5265\u593a\u5176\u5f53\u524d\u4f1a\u8bdd\uff0c\u660e\u786e\u544a\u77e5\u8d8a\u6743\uff0c\u4f46\u4e0d\u76f4\u63a5\u9500\u6bc1\u8d26\u53f7\u3002<\/td><\/tr><tr><td><strong>\u672a\u767b\u5f55\u8bbf\u5ba2<\/strong><\/td><td>\u8fd4\u56de&nbsp;<strong>429 Too Many Requests<\/strong>&nbsp;\u6216\u81ea\u5b9a\u4e49\u6df7\u6dc6\u4fe1\u606f\u3002<\/td><td><strong>\u7f51\u7edc\u5c42\u62e6\u622a<\/strong>\u3002\u6d88\u8017\u653b\u51fb\u8005\u8d44\u6e90\uff0c\u540c\u65f6\u907f\u514d\u66b4\u9732\u7f51\u7ad9\u7ed3\u6784\u3002\u53ef\u65e0\u7f1d\u8854\u63a5\u672a\u6765IP\u9ed1\u540d\u5355\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u56db\u3001 \u5df2\u8bc6\u522b\u7684\u95ee\u9898\u4e0e\u540e\u7eed\u6539\u8fdb\u601d\u8def<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u57fa\u4e8e\u6d4b\u8bd5\u4eba\u5458\u63d0\u51fa\u7684\u4e09\u70b9\uff0c\u4ee5\u4e0b\u662f\u5206\u6790\u548c\u4fee\u6539\u601d\u8def\uff0c\u6211\u4eec\u4f1a\u5728\u540e\u7eed\u8fdb\u884c\u5b8c\u5584\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. \u9632\u50bb\u74dc\u64cd\u4f5c\uff1a\u589e\u5f3a\u8def\u5f84\u8f93\u5165\u9a8c\u8bc1<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u95ee\u9898<\/strong>\uff1a\u5f53\u524d\u4ec5\u505a\u4e86\u57fa\u7840\u7684&nbsp;<code>trim()<\/code>&nbsp;\u548c&nbsp;<code>sanitize_text_field()<\/code>&nbsp;\u5904\u7406\uff0c\u7528\u6237\u53ef\u80fd\u8f93\u5165\u65e0\u6548\u3001\u91cd\u590d\u6216\u683c\u5f0f\u6df7\u4e71\u7684\u8def\u5f84\u3002<\/li>\n\n\n\n<li><strong>\u6539\u8fdb\u601d\u8def<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u524d\u7aef\u5373\u65f6\u9a8c\u8bc1<\/strong>\uff1a\u5728\u8bbe\u7f6e\u9875\u9762\u6dfb\u52a0JavaScript\uff0c\u5728\u7528\u6237\u8f93\u5165\u65f6\u5b9e\u65f6\u68c0\u67e5\u8def\u5f84\u683c\u5f0f\uff08\u5982\u662f\u5426\u4ee5&nbsp;<code>\/<\/code>&nbsp;\u5f00\u5934\uff0c\u662f\u5426\u5305\u542b\u975e\u6cd5\u5b57\u7b26\u5982&nbsp;<code>:*?&lt;&gt;|<\/code>\uff09\u3002<\/li>\n\n\n\n<li><strong>\u540e\u7aef\u5f3a\u5316\u6e05\u6d17<\/strong>\uff1a\u5728&nbsp;<code>sanitize_paths()<\/code>&nbsp;\u51fd\u6570\u4e2d\uff0c\u589e\u52a0\u903b\u8f91\uff1a\u53bb\u9664\u91cd\u590d\u6761\u76ee\u3001\u81ea\u52a8\u4e3a\u76ee\u5f55\u8def\u5f84\u8865\u5168\u672b\u5c3e\u7684&nbsp;<code>\/<\/code>\uff08\u5982\u679c\u610f\u56fe\u662f\u4fdd\u62a4\u76ee\u5f55\uff09\u3001\u9a8c\u8bc1\u8def\u5f84\u662f\u5426\u786e\u5b9e\u5b58\u5728\u4e8e\u7f51\u7ad9\u76ee\u5f55\u7ed3\u6784\u4e2d\uff08\u53ef\u9009\uff0c\u4f46\u80fd\u6781\u5927\u9632\u9519\uff09\u3002<\/li>\n\n\n\n<li><strong>\u63d0\u4f9b\u793a\u4f8b\u4e0e\u6a21\u677f<\/strong>\uff1a\u5728\u8f93\u5165\u6846\u65c1\u63d0\u4f9b\u66f4\u9192\u76ee\u7684\u683c\u5f0f\u793a\u4f8b\u548c\u201c\u5e38\u7528\u8def\u5f84\u201d\u6a21\u677f\u6309\u94ae\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. \u8def\u5f84\u9884\u89c8\u4e0e\u6548\u679c\u53ef\u89c6\u5316<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u95ee\u9898<\/strong>\uff1a\u914d\u7f6e\u662f\u62bd\u8c61\u7684\u6587\u672c\u5217\u8868\uff0c\u7ba1\u7406\u5458\u65e0\u6cd5\u76f4\u89c2\u611f\u53d7\u201c\u54ea\u4e9b\u771f\u5b9e\u6587\u4ef6\u5c06\u88ab\u4fdd\u62a4\u201d\u3002<\/li>\n\n\n\n<li><strong>\u6539\u8fdb\u601d\u8def<\/strong>\uff1a\n<ul class=\"wp-block-list\">\n<li><strong>\u521b\u5efa\u201c\u8def\u5f84\u68c0\u6d4b\u5668\u201d\u5de5\u5177<\/strong>\uff1a\u5728\u8bbe\u7f6e\u9875\u9762\u65b0\u589e\u4e00\u4e2a\u72ec\u7acb\u533a\u57df\uff0c\u5141\u8bb8\u7ba1\u7406\u5458\u8f93\u5165\u4e00\u4e2a\u6d4b\u8bd5URL\uff0c\u63d2\u4ef6\u5373\u65f6\u8fd4\u56de\u5339\u914d\u7ed3\u679c\u3001\u6240\u9700\u7b49\u7ea7\u3001\u5f53\u524d\u7528\u6237\u7b49\u7ea7\u53ca\u6a21\u62df\u8bbf\u95ee\u7ed3\u679c\u3002<\/li>\n\n\n\n<li><strong>\u751f\u6210\u9759\u6001\u62a5\u544a<\/strong>\uff1a\u6dfb\u52a0\u4e00\u4e2a\u201c\u751f\u6210\u62a5\u544a\u201d\u6309\u94ae\uff0c\u811a\u672c\u626b\u63cf&nbsp;<code>wp-content<\/code>&nbsp;\u7b49\u76ee\u5f55\uff0c\u5217\u51fa\u6240\u6709\u6587\u4ef6\uff0c\u5e76\u5bf9\u7167\u5f53\u524d\u89c4\u5219\u6807\u8bb0\u51fa\u54ea\u4e9b\u4f1a\u88ab\u4fdd\u62a4\u53ca\u5176\u7b49\u7ea7\uff0c\u5f62\u6210\u4e00\u4e2aHTML\u62a5\u544a\u3002<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. \u5b9e\u73b0\u201c\u767d\u540d\u5355+\u9ed1\u540d\u5355\u201d\u6df7\u5408\u6a21\u578b<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u95ee\u9898<\/strong>\uff1a\u5f53\u524d\u662f\u5355\u4e00\u7684\u201c\u95e8\u69db\u201d\u6a21\u578b\u3002\u6709\u65f6\u9700\u8981\u66f4\u7075\u6d3b\uff1a\u4f8b\u5982\u201c\u5141\u8bb8\u7ba1\u7406\u5458\u8bbf\u95ee\u67d0\u4e2a\u4f5c\u8005\u76ee\u5f55\u201d\uff08\u767d\u540d\u5355\uff09\uff0c\u6216\u201c\u7981\u6b62\u6240\u6709\u4eba\uff08\u5305\u62ec\u7ba1\u7406\u5458\uff09\u8bbf\u95ee\u67d0\u4e2a\u65e5\u5fd7\u6587\u4ef6\u201d\uff08\u9ed1\u540d\u5355\uff09\u3002<\/li>\n\n\n\n<li><strong>\u6539\u8fdb\u601d\u8def &#8211; \u6570\u636e\u7ed3\u6784\u6539\u9020<\/strong>\uff1a<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ \u65b0\u7684\u914d\u7f6e\u6570\u636e\u7ed3\u6784\u793a\u4f8b\n$rule = array(\n    'path' =&gt; '\/wp-content\/debug.log',\n    'type' =&gt; 'blacklist', \/\/ \u6216 \u2018whitelist\u2018, \u2018min_level\u2018\n    'value' =&gt; true, \/\/ \u5bf9\u4e8eblacklist\uff0c true\u5373\u5b8c\u5168\u62d2\u7edd\n    \/\/ \u6216 \u2018value\u2018 =&gt; 10, \/\/ \u5bf9\u4e8emin_level\uff0c \u8868\u793a\u6240\u9700\u7b49\u7ea7\n    \/\/ \u6216 \u2018value\u2018 =&gt; array('administrator', 'editor'), \/\/ \u5bf9\u4e8ewhitelist\uff0c \u6307\u5b9a\u5141\u8bb8\u7684\u89d2\u8272\u6570\u7ec4\n);<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong><code>min_level<\/code><\/strong>\uff1a\u4fdd\u6301\u73b0\u6709\u4e25\u683c\u7b49\u7ea7\u6a21\u578b\u3002<\/li>\n\n\n\n<li><strong><code>whitelist<\/code><\/strong>\uff1a\u4f18\u5148\u7ea7\u6700\u9ad8\u3002\u6307\u5b9a\u5141\u8bb8\u7684\u89d2\u8272\u6570\u7ec4\uff0c<strong>\u4ec5\u5217\u8868\u5185\u89d2\u8272\u53ef\u8bbf\u95ee\uff0c\u5176\u4ed6\u4e00\u5f8b\u62d2\u7edd<\/strong>\uff08\u5373\u4f7f\u7b49\u7ea7\u66f4\u9ad8\uff09\u3002<\/li>\n\n\n\n<li><strong><code>blacklist<\/code><\/strong>\uff1a\u4f18\u5148\u7ea7\u6b21\u9ad8\u3002\u65e0\u8bba\u7528\u6237\u8eab\u4efd\u5982\u4f55\uff0c<strong>\u4e00\u5f8b\u62d2\u7edd\u8bbf\u95ee<\/strong>\u3002\u7528\u4e8e\u4fdd\u62a4\u6781\u5ea6\u654f\u611f\u6587\u4ef6\u3002<\/li>\n\n\n\n<li><strong>\u5224\u65ad\u903b\u8f91\u66f4\u65b0<\/strong>\uff1a\u76d1\u63a7\u7c7b\u7684\u5224\u65ad\u6d41\u7a0b\u9700\u8c03\u6574\uff0c\u6309&nbsp;<code>\u767d\u540d\u5355 \u2192 \u9ed1\u540d\u5355 \u2192 \u6700\u5c0f\u7b49\u7ea7<\/code>&nbsp;\u7684\u987a\u5e8f\u8fdb\u884c\u68c0\u67e5\uff0c\u540e\u8005\u4f5c\u4e3a\u9ed8\u8ba4\u89c4\u5219\u3002<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u4e94\u3001 \u6743\u9650\u7b49\u7ea7\u8bf4\u660e\u8be6\u7ec6\u5316\u5efa\u8bae<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u8bbe\u7f6e\u9875\u9762\u7684\u8bf4\u660e\u90e8\u5206\uff0c\u53ef\u4ee5\u589e\u52a0\u4ee5\u4e0b\u5185\u5bb9\uff0c\u4f7f\u5176\u66f4\u5177\u6307\u5bfc\u6027\uff1a<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6743\u9650\u7b49\u7ea7\u914d\u7f6e\u5b9e\u6218\u6307\u5357<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u7b49\u7ea71 (\u8bbf\u5ba2\/\u8ba2\u9605\u8005)<\/strong>\uff1a\u7528\u4e8e\u5b8c\u5168\u516c\u5f00\u7684\u8d44\u6e90\u3002<strong>\u4efb\u4f55\u9ad8\u4e8e\u6b64\u7b49\u7ea7\u7684\u8bbe\u7f6e\uff0c\u90fd\u5c06\u5bfc\u81f4\u8bbf\u5ba2\u88ab\u62e6\u622a<\/strong>\u3002\u53ef\u5c06<code>\/wp-login.php<\/code>\u8bbe\u4e3a5\uff0c\u4ee5\u9690\u85cf\u767b\u5f55\u5165\u53e3\u3002<\/li>\n\n\n\n<li><strong>\u7b49\u7ea75 (\u4f5c\u8005)<\/strong>\uff1a\u4f5c\u8005\u4e13\u5c5e\u7a7a\u95f4\u3002\u4f8b\u5982&nbsp;<code>\/wp-content\/uploads\/personal\/<\/code>\uff0c\u8bbe\u7f6e\u540e\uff0c<strong>\u7f16\u8f91\u548c\u7ba1\u7406\u5458\u4e5f\u5c06\u65e0\u6cd5\u8bbf\u95ee<\/strong>\uff0c\u5b9e\u73b0\u4e86\u4f5c\u8005\u9690\u79c1\u3002<\/li>\n\n\n\n<li><strong>\u7b49\u7ea77 (\u7f16\u8f91)<\/strong>\uff1a\u7f16\u8f91\u90e8\u8d44\u6e90\u3002\u4f8b\u5982\u5171\u4eab\u7684\u7a3f\u4ef6\u5e93&nbsp;<code>\/wp-content\/uploads\/draft-pool\/<\/code>\uff0c\u8bbe\u7f6e\u540e\uff0c\u4f5c\u8005\u65e0\u6cd5\u67e5\u770b\uff0c\u4f46\u7f16\u8f91\u548c\u7ba1\u7406\u5458\u53ef\u4ee5\u3002<\/li>\n\n\n\n<li><strong>\u7b49\u7ea710 (\u7ba1\u7406\u5458)<\/strong>\uff1a\u6838\u5fc3\u7cfb\u7edf\u6587\u4ef6\u3002\u4f8b\u5982&nbsp;<code>\/wp-config.php<\/code>\u3001\u6570\u636e\u5e93\u5907\u4efd\u76ee\u5f55\u3002<strong>\u5efa\u8bae\u4e0d\u8981\u8bbe\u7f6e\u4e3a10<\/strong>\uff0c\u800c\u5e94\u4f7f\u7528\u672a\u6765\u7684\u201c\u9ed1\u540d\u5355\u201d\u529f\u80fd\u76f4\u63a5\u7981\u6b62\u6240\u6709\u8bbf\u95ee\uff0c\u56e0\u4e3a\u5373\u4f7f\u662f\u7ba1\u7406\u5458\uff0c\u65e5\u5e38\u4e5f\u65e0\u987b\u76f4\u63a5\u8bbf\u95ee\u8fd9\u4e9b\u6587\u4ef6\u3002<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u6838\u5fc3\u539f\u5219<\/strong>\uff1a\u4e3a\u8def\u5f84\u8bbe\u7f6e\u7684\u7b49\u7ea7\uff0c\u5e94\u7b49\u4e8e<strong>\u6709\u5408\u7406\u3001\u65e5\u5e38\u4e1a\u52a1\u9700\u6c42\u8bbf\u95ee\u8be5\u8d44\u6e90\u7684\u6700\u4f4e\u7ea7\u522b\u89d2\u8272<\/strong>\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u9632\u50bb\u74dc\u64cd\u4f5c\uff1a\u589e\u5f3a\u8def\u5f84\u8f93\u5165\u9a8c\u8bc1<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd9\u4e2a\u529f\u80fd\u7684\u76ee\u6807\u662f\u786e\u4fdd\u7ba1\u7406\u5458\u5728\u540e\u53f0\u586b\u5199\u7684\u6bcf\u4e00\u6761\u201c\u4fdd\u62a4\u8def\u5f84\u201d\u90fd\u662f<strong>\u683c\u5f0f\u6b63\u786e\u3001\u65e0\u91cd\u590d\u3001\u4e14\u5b89\u5168\u6709\u6548<\/strong>\u7684\uff0c\u4ece\u6e90\u5934\u4e0a\u675c\u7edd\u914d\u7f6e\u9519\u8bef\u3002\u6211\u4eec\u5c06\u4ece&nbsp;<strong>\u524d\u7aef\u5373\u65f6\u63d0\u793a<\/strong>&nbsp;\u548c&nbsp;<strong>\u540e\u7aef\u4e25\u683c\u6e05\u6d17<\/strong>&nbsp;\u4e24\u4e2a\u65b9\u9762\u5bf9\u8bbe\u7f6e\u9875\u9762\u8fdb\u884c\u52a0\u56fa\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a412-1024x683.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"683\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a412-1024x683.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1404\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><div class='fancybox-wrapper lazyload-container-unload' data-fancybox='post-images' href='http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a413-1024x980.jpg'><img class=\"lazyload lazyload-style-1\" src=\"data:image\/svg+xml;base64,PCEtLUFyZ29uTG9hZGluZy0tPgo8c3ZnIHdpZHRoPSIxIiBoZWlnaHQ9IjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgc3Ryb2tlPSIjZmZmZmZmMDAiPjxnPjwvZz4KPC9zdmc+\"  loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"980\" data-original=\"http:\/\/www.preluna.xyz\/wp-content\/uploads\/2025\/12\/\u524d\u7aef\u6587\u4ef6\u63d0\u4ea4\u7684\u5b89\u5168\u9632\u62a413-1024x980.jpg\" src=\"data:image\/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAAANSURBVBhXYzh8+PB\/AAffA0nNPuCLAAAAAElFTkSuQmCC\" alt=\"\" class=\"wp-image-1405\"  sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e00\u6b65\uff1a\u4fee\u6539\u8bbe\u7f6e\u9875\u9762\u7c7b (<code>includes\/class-settings-page.php<\/code>)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u5c06\u4e3b\u8981\u4fee\u6539\u4e24\u4e2a\u6838\u5fc3\u65b9\u6cd5\uff1a<code>render_paths_field<\/code>\uff08\u7528\u4e8e\u524d\u7aef\u6e32\u67d3\u548c\u4ea4\u4e92\uff09\u548c&nbsp;<code>sanitize_paths<\/code>\uff08\u7528\u4e8e\u540e\u7aef\u6e05\u6d17\u548c\u9a8c\u8bc1\uff09\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>1. \u589e\u5f3a\u524d\u7aef\u8f93\u5165\u4e0e\u5373\u65f6\u9a8c\u8bc1<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728&nbsp;<code>render_paths_field<\/code>&nbsp;\u65b9\u6cd5\u4e2d\uff0c\u6211\u4eec\u9700\u8981\u5728\u8f93\u51faHTML\u548cJavaScript\u65f6\uff0c\u589e\u52a0\u5bf9\u8def\u5f84\u683c\u5f0f\u7684\u5373\u65f6\u68c0\u67e5\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>\u4e3b\u8981\u6539\u8fdb\u70b9<\/strong>\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u8f93\u5165\u63d0\u793a<\/strong>\uff1a\u5728\u8f93\u5165\u6846\u5185\u589e\u52a0\u66f4\u660e\u786e\u7684&nbsp;<code>placeholder<\/code>&nbsp;\u8bf4\u660e\u3002<\/li>\n\n\n\n<li><strong>\u5b9e\u65f6\u683c\u5f0f\u68c0\u67e5<\/strong>\uff1a\u901a\u8fc7JavaScript\uff0c\u5728\u7528\u6237\u8f93\u5165\u65f6\u6216\u5931\u53bb\u7126\u70b9\u65f6\uff0c\u68c0\u67e5\u8def\u5f84\u683c\u5f0f\uff0c\u5e76\u7528\u9192\u76ee\u7684\u989c\u8272\uff08\u5982\u7ea2\u8272\uff09\u63d0\u793a\u9519\u8bef\uff08\u4f8b\u5982\u8def\u5f84\u4e0d\u4ee5&nbsp;<code>\/<\/code>&nbsp;\u5f00\u5934\uff0c\u6216\u5305\u542b\u975e\u6cd5\u5b57\u7b26\uff09\u3002<\/li>\n\n\n\n<li><strong>\u91cd\u590d\u9879\u9ad8\u4eae<\/strong>\uff1a\u5728\u5ba2\u6237\u7aef\u68c0\u67e5\u540c\u4e00\u9875\u9762\u5185\u662f\u5426\u6709\u91cd\u590d\u7684\u8def\u5f84\u8f93\u5165\uff0c\u5e76\u63d0\u793a\u7528\u6237\u3002<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u7531\u4e8e\u4ee3\u7801\u8f83\u957f\uff0c\u5173\u952e\u662f\u5728\u8f93\u51faHTML\u90e8\u5206\u540e\uff0c\u52a0\u5165\u76f8\u5e94\u7684JavaScript\u3002\u4f8b\u5982\uff0c\u53ef\u4ee5\u5728\u539f\u6709\u7684\u5185\u8054JS\u540e\uff0c\u589e\u52a0\u683c\u5f0f\u9a8c\u8bc1\u51fd\u6570\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ ... \u539f\u6709\u7684\u52a8\u6001\u6dfb\u52a0\/\u5220\u9664\u884cJS\u4ee3\u7801 ...\n\n\/\/ \u8def\u5f84\u683c\u5f0f\u9a8c\u8bc1\u51fd\u6570\nfunction psgValidateSinglePath(inputElement) {\n    var path = inputElement.value.trim();\n    var feedbackSpan = inputElement.nextElementSibling;\n    if (!feedbackSpan || !feedbackSpan.classList.contains('psg-path-feedback')) {\n        feedbackSpan = document.createElement('span');\n        feedbackSpan.className = 'psg-path-feedback';\n        inputElement.parentNode.insertBefore(feedbackSpan, inputElement.nextSibling);\n    }\n\n    if (path === '') {\n        feedbackSpan.textContent = '\uff08\u8def\u5f84\u4e3a\u7a7a\uff0c\u5c06\u88ab\u5ffd\u7565\uff09';\n        feedbackSpan.style.color = '#999';\n        return false;\n    }\n    if (path.charAt(0) !== '\/') {\n        feedbackSpan.textContent = '\u26a0\ufe0f \u8def\u5f84\u5e94\u4ee5\u659c\u6760 (\/) \u5f00\u5934';\n        feedbackSpan.style.color = '#d63638';\n        return false;\n    }\n    \/\/ \u68c0\u67e5\u975e\u6cd5\u5b57\u7b26 (\u6839\u636e\u7cfb\u7edf\u800c\u5b9a\uff0c\u8fd9\u91cc\u662f\u4e00\u4e9b\u5e38\u89c1\u5371\u9669\u5b57\u7b26)\n    var illegalChars = \/&#91;&lt;&gt;:\"|?*\\\\]\/;\n    if (illegalChars.test(path)) {\n        feedbackSpan.textContent = '\u26a0\ufe0f \u5305\u542b\u975e\u6cd5\u5b57\u7b26';\n        feedbackSpan.style.color = '#d63638';\n        return false;\n    }\n    \/\/ \u7b80\u5355\u7684\u76ee\u5f55\u8def\u5f84\u81ea\u52a8\u8865\u5168\u63d0\u793a\uff08\u975e\u5f3a\u5236\uff09\n    if (path.charAt(path.length - 1) !== '\/' &amp;&amp; path.indexOf('.') === -1) {\n        \/\/ \u770b\u8d77\u6765\u50cf\u76ee\u5f55\u4f46\u6ca1\u6709\u4ee5\/\u7ed3\u5c3e\uff0c\u7ed9\u51fa\u63d0\u793a\n        feedbackSpan.textContent = '\ud83d\udca1 \u63d0\u793a\uff1a\u82e5\u4e3a\u76ee\u5f55\uff0c\u5efa\u8bae\u4ee5 \/ \u7ed3\u5c3e';\n        feedbackSpan.style.color = '#f0ad4e';\n    } else {\n        feedbackSpan.textContent = '\u2713 \u683c\u5f0f\u6b63\u786e';\n        feedbackSpan.style.color = '#46b450';\n    }\n    return true;\n}\n\n\/\/ \u4e3a\u6240\u6709\u73b0\u6709\u548c\u672a\u6765\u65b0\u589e\u7684\u8f93\u5165\u6846\u7ed1\u5b9a\u4e8b\u4ef6\njQuery(document).on('blur', 'input&#91;name*=\"&#91;path]\"]', function() {\n    psgValidateSinglePath(this);\n});\n\/\/ \u9875\u9762\u52a0\u8f7d\u65f6\u4e5f\u9a8c\u8bc1\u4e00\u6b21\njQuery(document).ready(function($) {\n    $('input&#91;name*=\"&#91;path]\"]').each(function() { psgValidateSinglePath(this); });\n});<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u7b2c\u4e8c\u6b65\uff1a\u6d4b\u8bd5\u6e05\u5355<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u4fee\u6539\u5b8c\u6210\u540e\uff0c\u8bf7\u6309\u7167\u4ee5\u4e0b\u6b65\u9aa4\u6d4b\u8bd5\u589e\u5f3a\u7684\u9a8c\u8bc1\u529f\u80fd\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>\u6d4b\u8bd5\u573a\u666f<\/th><th>\u64cd\u4f5c<\/th><th>\u9884\u671f\u7ed3\u679c<\/th><\/tr><\/thead><tbody><tr><td><strong>1. \u524d\u7aef\u683c\u5f0f\u9a8c\u8bc1<\/strong><\/td><td>\u5728\u8bbe\u7f6e\u9875\u9762\uff0c\u8f93\u5165\u4e00\u4e2a\u4e0d\u4ee5&nbsp;<code>\/<\/code>&nbsp;\u5f00\u5934\u7684\u8def\u5f84\uff08\u5982&nbsp;<code>wp-admin\/<\/code>\uff09\u3002<\/td><td>\u8f93\u5165\u6846\u65c1\u5e94\u7acb\u5373\u6216\u5931\u53bb\u7126\u70b9\u540e\u51fa\u73b0\u7ea2\u8272\u8b66\u544a\u63d0\u793a\u3002<\/td><\/tr><tr><td><strong>2. \u524d\u7aef\u91cd\u590d\u63d0\u793a<\/strong><\/td><td>\u6dfb\u52a0\u4e24\u6761\u5b8c\u5168\u76f8\u540c\u7684\u8def\u5f84\u5e76\u4fdd\u5b58\u3002<\/td><td>\u9875\u9762\u63d0\u4ea4\u540e\uff0c<strong>\u540e\u7aef\u5e94\u53ea\u4fdd\u5b58\u4e00\u6761<\/strong>\u3002\u524d\u7aef\u6700\u597d\u80fd\u6709\u91cd\u590d\u63d0\u793a\uff08\u6211\u4eec\u5f53\u524d\u7684JS\u793a\u4f8b\u672a\u5b9e\u73b0\u91cd\u590d\u68c0\u67e5\uff0c\u4f46\u540e\u7aef\u5df2\u5904\u7406\uff09\u3002<\/td><\/tr><tr><td><strong>3. \u540e\u7aef\u8def\u5f84\u6e05\u6d17<\/strong><\/td><td>\u8f93\u5165&nbsp;<code>\/wp-content\/uploads\/\/secret\/<\/code>\uff08\u591a\u659c\u6760\uff09\u5e76\u4fdd\u5b58\u3002<\/td><td>\u4fdd\u5b58\u540e\uff0c\u5728\u6570\u636e\u5e93\u6216\u91cd\u65b0\u52a0\u8f7d\u9875\u9762\u65f6\uff0c\u5e94\u663e\u793a\u4e3a\u89c4\u8303\u5316\u7684&nbsp;<code>\/wp-content\/uploads\/secret\/<\/code>\u3002<\/td><\/tr><tr><td><strong>4. \u540e\u7aef\u91cd\u590d\u9879\u5408\u5e76<\/strong><\/td><td>\u5206\u522b\u8f93\u5165&nbsp;<code>\/secret\/<\/code>&nbsp;\u548c&nbsp;<code>\/secret<\/code>\uff08\u4e00\u4e2a\u5e26\u659c\u6760\u4e00\u4e2a\u4e0d\u5e26\uff09\u3002<\/td><td>\u4fdd\u5b58\u540e\uff0c\u5e94\u53ea\u4fdd\u7559\u5176\u4e2d\u4e00\u6761\uff08\u53d6\u51b3\u4e8e&nbsp;<code>normalize_input_path<\/code>&nbsp;\u7684\u5904\u7406\u7ed3\u679c\uff09\u3002<\/td><\/tr><tr><td><strong>5. \u975e\u6cd5\u8def\u5f84\u8fc7\u6ee4<\/strong><\/td><td>\u8f93\u5165\u4e00\u4e2a\u7cfb\u7edf\u6587\u4ef6\u8def\u5f84\u5982&nbsp;<code>\/etc\/passwd<\/code>&nbsp;\u6216\u5305\u542b&nbsp;<code>..\/<\/code>&nbsp;\u8bd5\u56fe\u7a7f\u8d8a\u7684\u8def\u5f84\u3002<\/td><td>\u4fdd\u5b58\u540e\uff0c\u8be5\u6761\u76ee<strong>\u4e0d\u5e94\u51fa\u73b0<\/strong>\u5728\u89c4\u5219\u5217\u8868\u4e2d\uff08\u88ab&nbsp;<code>is_path_inside_wp_content<\/code>&nbsp;\u8fc7\u6ee4\uff09\u3002<\/td><\/tr><tr><td><strong><strong>6. \u7a7a\u503c\u5904\u7406<\/strong><\/strong><\/td><td>\u6dfb\u52a0\u4e00\u884c\uff0c\u53ea\u9009\u62e9\u7b49\u7ea7\u4f46\u4e0d\u586b\u8def\u5f84\uff0c\u7136\u540e\u4fdd\u5b58\u3002<\/td><td>\u7a7a\u8def\u5f84\u7684\u6761\u76ee\u5e94\u88ab\u5ffd\u7565\uff0c\u4e0d\u4fdd\u5b58\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">\u8def\u5f84\u9884\u89c8\u4e0e\u6548\u679c\u53ef\u89c6\u5316<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u76ee\u6807\u662f\u8ba9\u7ba1\u7406\u5458\u5728\u914d\u7f6e\u65f6\uff0c\u80fd<strong>\u76f4\u89c2\u3001\u5373\u65f6\u5730\u770b\u5230\u6bcf\u6761\u89c4\u5219\u7684\u5b9e\u9645\u6548\u679c<\/strong>\uff0c\u5c06\u62bd\u8c61\u7684\u6587\u672c\u914d\u7f6e\u8f6c\u5316\u4e3a\u6e05\u6670\u7684\u53ef\u89c6\u5316\u53cd\u9988\u3002<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>\u5b9e\u65f6\u8def\u5f84\u6d4b\u8bd5\u5668<\/strong>\uff1a\u8f93\u5165\u4efb\u610f\u8def\u5f84\uff0c\u7acb\u5373\u770b\u5230\u5339\u914d\u7ed3\u679c\u548c\u8bbf\u95ee\u72b6\u6001\u3002<\/li>\n\n\n\n<li><strong>\u89c4\u5219\u5f71\u54cd\u8303\u56f4\u9884\u89c8<\/strong>\uff08\u53ef\u9009\uff09\uff1a\u751f\u6210\u4e00\u4e2a\u7b80\u5355\u7684\u62a5\u544a\uff0c\u5c55\u793a\u89c4\u5219\u4fdd\u62a4\u4e86\u54ea\u4e9b\u5178\u578b\u8def\u5f84\u3002<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">\u5de5\u5177\u5c06\u5d4c\u5165\u5230\u8bbe\u7f6e\u9875\u9762\u4e2d\uff0c\u8ba9\u7ba1\u7406\u5458\u968f\u65f6\u9a8c\u8bc1\u914d\u7f6e\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e00\u6b65\uff1a\u5728\u8bbe\u7f6e\u9875\u9762\u7c7b\u4e2d\u6dfb\u52a0\u9884\u89c8\u754c\u9762<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u00a0<code>includes\/class-settings-page.php<\/code>\u00a0\u7684\u00a0<code>render_settings_page()<\/code>\u00a0\u65b9\u6cd5\u4e2d\uff0c<strong>\u5728\u8868\u5355\u7ed3\u675f\u6807\u7b7e\u00a0<code>&lt;\/form><\/code>\u00a0\u4e4b\u540e\u3001\u8bf4\u660e\u90e8\u5206\u4e4b\u524d<\/strong>\uff0c\u6dfb\u52a0\u4ee5\u4e0bHTML\u548c\u903b\u8f91\u4ee3\u7801\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ ... \u539f\u6709\u7684\u8868\u5355\u548c\u63d0\u4ea4\u6309\u94ae\u4ee3\u7801 ...\n&lt;\/form>\n\n&lt;hr>\n\n&lt;!-- \u65b0\u589e\uff1a\u8def\u5f84\u6d4b\u8bd5\u4e0e\u9884\u89c8\u533a\u57df -->\n&lt;div class=\"wrap\" style=\"margin-top: 30px; background: #f6f7f7; padding: 20px; border: 1px solid #c3c4c7;\">\n    &lt;h2>\ud83d\udd0d \u8def\u5f84\u6d4b\u8bd5\u4e0e\u89c4\u5219\u9884\u89c8&lt;\/h2>\n    &lt;p>\u5728\u6b64\u6d4b\u8bd5\u4efb\u610f\u8def\u5f84\uff0c\u67e5\u770b\u5b83\u5c06\u5982\u4f55\u88ab\u5f53\u524d\u89c4\u5219\u5339\u914d\u548c\u5904\u7406\u3002&lt;\/p>\n\n    &lt;table class=\"form-table\">\n        &lt;tr>\n            &lt;th scope=\"row\">&lt;label for=\"psg_test_path\">\u8f93\u5165\u6d4b\u8bd5\u8def\u5f84&lt;\/label>&lt;\/th>\n            &lt;td>\n                &lt;input type=\"text\" id=\"psg_test_path\" name=\"psg_test_path\" value=\"\" class=\"regular-text\" placeholder=\"\u4f8b\u5982\uff1a\/wp-content\/uploads\/secret\/file.jpg\" style=\"width: 300px;\">\n                &lt;button type=\"button\" id=\"psg_test_button\" class=\"button button-secondary\">\u7acb\u5373\u6d4b\u8bd5&lt;\/button>\n                &lt;p class=\"description\">\u8f93\u5165\u4e00\u4e2a\u5b8c\u6574\u7684\u7f51\u7ad9\u8def\u5f84\uff08\u4ee5 \/ \u5f00\u5934\uff09\u8fdb\u884c\u6d4b\u8bd5\u3002&lt;\/p>\n            &lt;\/td>\n        &lt;\/tr>\n        &lt;tr>\n            &lt;th scope=\"row\">\u6d4b\u8bd5\u7ed3\u679c&lt;\/th>\n            &lt;td>\n                &lt;div id=\"psg_test_result\" style=\"padding: 15px; border: 1px dashed #ccc; min-height: 60px; background: white;\">\n                    &lt;p style=\"color: #999; margin: 0;\">\u70b9\u51fb\u201c\u7acb\u5373\u6d4b\u8bd5\u201d\u6309\u94ae\u540e\uff0c\u7ed3\u679c\u5c06\u663e\u793a\u5728\u8fd9\u91cc\u3002&lt;\/p>\n                &lt;\/div>\n            &lt;\/td>\n        &lt;\/tr>\n    &lt;\/table>\n\n    &lt;h3>\ud83d\udccb \u5f53\u524d\u6240\u6709\u89c4\u5219\u9884\u89c8&lt;\/h3>\n    &lt;p>\u4e0b\u65b9\u8868\u683c\u5217\u51fa\u4e86\u6240\u6709\u5df2\u751f\u6548\u7684\u4fdd\u62a4\u89c4\u5219\u3002\u4f60\u53ef\u4ee5\u5728\u6b64\u590d\u6838\u3002&lt;\/p>\n    &lt;?php\n    $current_rules = self::get_protected_paths();\n    if (empty($current_rules)) {\n        echo '&lt;p>&lt;strong>\u6682\u65e0\u751f\u6548\u7684\u89c4\u5219\u3002&lt;\/strong>&lt;\/p>';\n    } else {\n        echo '&lt;table class=\"wp-list-table widefat striped\" style=\"width: auto;\">';\n        echo '&lt;thead>&lt;tr>&lt;th>\u8def\u5f84 (Path)&lt;\/th>&lt;th>\u8981\u6c42\u6700\u4f4e\u89d2\u8272\u7b49\u7ea7&lt;\/th>&lt;th>\u5339\u914d\u793a\u4f8b&lt;\/th>&lt;\/tr>&lt;\/thead>';\n        echo '&lt;tbody>';\n        $role_names = array(1=>'\u8bbf\u5ba2\/\u8ba2\u9605\u8005', 3=>'\u6295\u7a3f\u8005', 5=>'\u4f5c\u8005', 7=>'\u7f16\u8f91', 10=>'\u7ba1\u7406\u5458');\n        foreach ($current_rules as $rule) {\n            $example = $rule&#91;'path'];\n            \/\/ \u5982\u679c\u8def\u5f84\u662f\u76ee\u5f55\uff08\u4ee5\/\u7ed3\u5c3e\uff09\uff0c\u4e3a\u5176\u751f\u6210\u4e00\u4e2a\u793a\u4f8b\u6587\u4ef6\n            if (substr($rule&#91;'path'], -1) === '\/') {\n                $example = $rule&#91;'path'] . 'example-file.txt';\n            }\n            echo '&lt;tr>';\n            echo '&lt;td>&lt;code>' . esc_html($rule&#91;'path']) . '&lt;\/code>&lt;\/td>';\n            echo '&lt;td>&lt;strong>' . $role_names&#91;$rule&#91;'min_level']] . '&lt;\/strong> (\u7b49\u7ea7 ' . $rule&#91;'min_level'] . ')&lt;\/td>';\n            echo '&lt;td>&lt;code>' . esc_html($example) . '&lt;\/code>&lt;\/td>';\n            echo '&lt;\/tr>';\n        }\n        echo '&lt;\/tbody>&lt;\/table>';\n    }\n    ?>\n&lt;\/div>\n\n&lt;!-- \u5185\u8054JavaScript\uff0c\u5904\u7406\u6d4b\u8bd5\u6309\u94ae\u7684\u5f02\u6b65\u8bf7\u6c42 -->\n&lt;script type=\"text\/javascript\">\njQuery(document).ready(function($) {\n    $('#psg_test_button').on('click', function() {\n        var testPath = $('#psg_test_path').val().trim();\n        if (!testPath) {\n            alert('\u8bf7\u8f93\u5165\u8981\u6d4b\u8bd5\u7684\u8def\u5f84\u3002');\n            return;\n        }\n        \/\/ \u7981\u7528\u6309\u94ae\uff0c\u663e\u793a\u52a0\u8f7d\u4e2d\n        var $button = $(this);\n        $button.prop('disabled', true).text('\u6d4b\u8bd5\u4e2d...');\n        $('#psg_test_result').html('&lt;p style=\"color: #999;\">&lt;span class=\"spinner is-active\" style=\"float:none;\">&lt;\/span> \u6b63\u5728\u5206\u6790\u8def\u5f84\u5e76\u5339\u914d\u89c4\u5219...&lt;\/p>');\n\n        \/\/ \u53d1\u8d77AJAX\u8bf7\u6c42\u5230WordPress\u540e\u7aef\n        $.ajax({\n            url: ajaxurl, \/\/ WordPress \u5b9a\u4e49\u7684\u5168\u5c40\u53d8\u91cf\uff0c\u6307\u5411 admin-ajax.php\n            type: 'POST',\n            data: {\n                action: 'psg_preview_path', \/\/ \u6211\u4eec\u7a0d\u540e\u8981\u6ce8\u518c\u7684AJAX\u52a8\u4f5c\n                path: testPath,\n                _wpnonce: '&lt;?php echo wp_create_nonce('psg_preview_nonce'); ?>' \/\/ \u5b89\u5168\u9a8c\u8bc1\n            },\n            success: function(response) {\n                $button.prop('disabled', false).text('\u7acb\u5373\u6d4b\u8bd5');\n                if (response.success) {\n                    $('#psg_test_result').html(response.data);\n                } else {\n                    $('#psg_test_result').html('&lt;p style=\"color: #d63638;\">\u274c \u8bf7\u6c42\u5931\u8d25\uff1a' + response.data + '&lt;\/p>');\n                }\n            },\n            error: function() {\n                $button.prop('disabled', false).text('\u7acb\u5373\u6d4b\u8bd5');\n                $('#psg_test_result').html('&lt;p style=\"color: #d63638;\">\u274c \u7f51\u7edc\u8bf7\u6c42\u5931\u8d25\uff0c\u8bf7\u68c0\u67e5\u63a7\u5236\u53f0\u6216\u7a0d\u540e\u91cd\u8bd5\u3002&lt;\/p>');\n            }\n        });\n    });\n});\n&lt;\/script>\n\n&lt;!-- \u4ee5\u4e0b\u662f\u539f\u6709\u7684\u201c\u6743\u9650\u7b49\u7ea7\u8bf4\u660e\u201d\u90e8\u5206 -->\n&lt;hr>\n&lt;h3>\u6743\u9650\u7b49\u7ea7\u8bf4\u660e&lt;\/h3><\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>\u7b2c\u4e8c\u6b65\uff1a\u6ce8\u518cAJAX\u5904\u7406\u51fd\u6570\uff0c\u5b9e\u73b0\u8def\u5f84\u5206\u6790\u903b\u8f91<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6211\u4eec\u9700\u8981\u8ba9\u524d\u7aefJavaScript\u80fd\u8c03\u7528\u540e\u7aefPHP\u51fd\u6570\u6765\u5206\u6790\u8def\u5f84\u3002\u5728&nbsp;<code>class-settings-page.php<\/code>&nbsp;\u7684&nbsp;<code>__construct<\/code>&nbsp;\u6784\u9020\u51fd\u6570\u4e2d\uff0c\u6dfb\u52a0AJAX\u94a9\u5b50\u6ce8\u518c\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public function __construct() {\n    add_action('admin_menu', array($this, 'add_admin_menu'));\n    add_action('admin_init', array($this, 'register_settings'));\n    \/\/ +++ \u65b0\u589e\uff1a\u6ce8\u518cAJAX\u5904\u7406\u51fd\u6570 +++\n    add_action('wp_ajax_psg_preview_path', array($this, 'ajax_preview_path'));\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u7136\u540e\uff0c\u5728\u7c7b\u4e2d\u6dfb\u52a0\u65b0\u7684\u00a0<code>ajax_preview_path<\/code>\u00a0\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/**\n * AJAX\u5904\u7406\u51fd\u6570\uff1a\u5206\u6790\u7ed9\u5b9a\u8def\u5f84\uff0c\u5e76\u8fd4\u56de\u5339\u914d\u7ed3\u679c\u548c\u8bbf\u95ee\u72b6\u6001\u3002\n *\/\npublic function ajax_preview_path() {\n    \/\/ 1. \u5b89\u5168\u9a8c\u8bc1\n    check_ajax_referer('psg_preview_nonce', '_wpnonce');\n    if (!current_user_can('manage_options')) {\n        wp_die('\u6743\u9650\u4e0d\u8db3\u3002');\n    }\n\n    \/\/ 2. \u83b7\u53d6\u5e76\u6e05\u7406\u6d4b\u8bd5\u8def\u5f84\n    $test_path = isset($_POST&#91;'path']) ? sanitize_text_field($_POST&#91;'path']) : '';\n    if (empty($test_path) || strpos($test_path, '\/') !== 0) {\n        wp_send_json_error('\u8bf7\u8f93\u5165\u4e00\u4e2a\u4ee5\u659c\u6760 (\/) \u5f00\u5934\u7684\u6709\u6548\u8def\u5f84\u3002');\n    }\n\n    \/\/ 3. \u83b7\u53d6\u5f53\u524d\u7528\u6237\u548c\u6240\u6709\u89c4\u5219\n    $current_user = wp_get_current_user();\n    $user_level = self::get_user_level($current_user);\n    $all_rules = self::get_protected_paths();\n\n    \/\/ 4. \u8c03\u7528\u4e00\u4e2a\u65b9\u6cd5\u6765\u5206\u6790\u8def\u5f84 (\u6211\u4eec\u5c06\u521b\u5efa\u8fd9\u4e2a\u65b9\u6cd5)\n    $analysis_result = $this->analyze_path_for_preview($test_path, $user_level, $all_rules);\n\n    \/\/ 5. \u8fd4\u56de\u683c\u5f0f\u5316\u7684HTML\u7ed3\u679c\n    wp_send_json_success($analysis_result);\n}\n\n\/**\n * \u5206\u6790\u8def\u5f84\u7684\u6838\u5fc3\u903b\u8f91\n *\/\nprivate function analyze_path_for_preview($input_path, $user_level, $all_rules) {\n    $output = '&lt;div class=\"psg-preview-result\">';\n    \n    \/\/ a. \u663e\u793a\u57fa\u672c\u4fe1\u606f\n    $normalized_path = $this->normalize_input_path($input_path);\n    $output .= '&lt;p>&lt;strong>\u6d4b\u8bd5\u8def\u5f84\uff1a&lt;\/strong>&lt;code>' . esc_html($input_path) . '&lt;\/code>&lt;\/p>';\n    if ($input_path !== $normalized_path) {\n        $output .= '&lt;p>&lt;strong>\u89c4\u8303\u5316\u540e\uff1a&lt;\/strong>&lt;code>' . esc_html($normalized_path) . '&lt;\/code>&lt;\/p>';\n    }\n    $output .= '&lt;p>&lt;strong>\u5f53\u524d\u7528\u6237\uff1a&lt;\/strong>' . esc_html($current_user->user_login) . ' (\u6743\u9650\u7b49\u7ea7\uff1a&lt;strong>' . $user_level . '&lt;\/strong>)&lt;\/p>';\n    $output .= '&lt;hr style=\"margin: 15px 0;\">';\n\n    \/\/ b. \u5f00\u59cb\u5339\u914d\u89c4\u5219\n    $matched_rule = null;\n    foreach ($all_rules as $rule) {\n        $rule_path = $this->normalize_input_path($rule&#91;'path']);\n        \/\/ \u68c0\u67e5\u6d4b\u8bd5\u8def\u5f84\u662f\u5426\u4ee5\u89c4\u5219\u8def\u5f84\u5f00\u5934\n        if (strpos($normalized_path, $rule_path) === 0) {\n            $matched_rule = $rule;\n            break; \/\/ \u627e\u5230\u7b2c\u4e00\u6761\u5339\u914d\u7684\u89c4\u5219\u5c31\u505c\u6b62\n        }\n    }\n\n    if ($matched_rule) {\n        $output .= '&lt;p>&lt;span style=\"color:#46b450;\">\u2705 &lt;strong>\u5339\u914d\u5230\u89c4\u5219\uff01&lt;\/strong>&lt;\/span>&lt;\/p>';\n        $output .= '&lt;ul>';\n        $output .= '&lt;li>&lt;strong>\u89c4\u5219\u8def\u5f84\uff1a&lt;\/strong>&lt;code>' . esc_html($matched_rule&#91;'path']) . '&lt;\/code>&lt;\/li>';\n        $output .= '&lt;li>&lt;strong>\u8981\u6c42\u6700\u4f4e\u7b49\u7ea7\uff1a&lt;\/strong>&lt;span style=\"font-weight:bold;\">' . $matched_rule&#91;'min_level'] . '&lt;\/span>&lt;\/li>';\n        $output .= '&lt;\/ul>';\n\n        \/\/ c. \u6a21\u62df\u8bbf\u95ee\u51b3\u7b56\n        $role_names = array(1=>'\u8bbf\u5ba2\/\u8ba2\u9605\u8005', 3=>'\u6295\u7a3f\u8005', 5=>'\u4f5c\u8005', 7=>'\u7f16\u8f91', 10=>'\u7ba1\u7406\u5458');\n        $required_role_name = $role_names&#91;$matched_rule&#91;'min_level']] ?? '\u7b49\u7ea7' . $matched_rule&#91;'min_level'];\n        $user_role_name = $role_names&#91;$user_level] ?? '\u7b49\u7ea7' . $user_level;\n\n        if ($user_level &lt; $matched_rule&#91;'min_level']) {\n            $output .= '&lt;div style=\"padding: 15px; background-color: #f8d7da; border: 1px solid #f5c6cb; border-radius: 4px; color: #721c24;\">';\n            $output .= '&lt;p>&lt;strong>\ud83d\udeab \u8bbf\u95ee\u5c06\u88ab\u62e6\u622a\uff01&lt;\/strong>&lt;\/p>';\n            $output .= '&lt;p>\u60a8\u7684\u7b49\u7ea7 (&lt;strong>' . $user_role_name . '&lt;\/strong>) \u4f4e\u4e8e\u6b64\u8d44\u6e90\u8981\u6c42\u7684\u7b49\u7ea7 (&lt;strong>' . $required_role_name . '&lt;\/strong>)\u3002&lt;\/p>';\n            $output .= '&lt;p>&lt;em>\u6839\u636e\u63d2\u4ef6\u8bbe\u7f6e\uff0c\u8fd9\u5c06\u89e6\u53d1\u76f8\u5e94\u7684\u5c01\u7981\u6216\u62e6\u622a\u63aa\u65bd\u3002&lt;\/em>&lt;\/p>';\n            $output .= '&lt;\/div>';\n        } else {\n            $output .= '&lt;div style=\"padding: 15px; background-color: #d1ecf1; border: 1px solid #bee5eb; border-radius: 4px; color: #0c5460;\">';\n            $output .= '&lt;p>&lt;strong>\u2705 \u8bbf\u95ee\u5c06\u88ab\u5141\u8bb8\u3002&lt;\/strong>&lt;\/p>';\n            $output .= '&lt;p>\u60a8\u7684\u7b49\u7ea7 (&lt;strong>' . $user_role_name . '&lt;\/strong>) \u5df2\u8fbe\u5230\u6216\u8d85\u8fc7\u8981\u6c42\u7b49\u7ea7 (&lt;strong>' . $required_role_name . '&lt;\/strong>)\u3002&lt;\/p>';\n            $output .= '&lt;\/div>';\n        }\n    } else {\n        $output .= '&lt;p>&lt;span style=\"color:#6c757d;\">\u2139\ufe0f &lt;strong>\u672a\u5339\u914d\u4efb\u4f55\u89c4\u5219\u3002&lt;\/strong>&lt;\/span>&lt;\/p>';\n        $output .= '&lt;p>\u6b64\u8def\u5f84\u4e0d\u5728\u5f53\u524d\u7684\u4fdd\u62a4\u89c4\u5219\u5217\u8868\u4e2d\uff0c\u6309\u7167\u9ed8\u8ba4\u7b56\u7565\uff0c\u8bbf\u95ee\u5c06\u88ab\u5141\u8bb8\u3002&lt;\/p>';\n    }\n\n    $output .= '&lt;\/div>';\n    return $output;\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6743\u9650\u7ba1\u7406\u3002\u7406\u89e3\u5e76\u914d\u7f6e\u597d\u5b83\uff0c\u662f\u4fdd\u8bc1\u7f51\u7ad9\u5b89\u5168\u3001\u6709\u5e8f\u8fd0\u884c\u7684\u57fa\u77f3\u3002\u6211\u4eec\u53ef\u4ee5\u5c06\u5176\u62c6\u89e3\u4e3a\u201c\u7406\u89e3\u9ed8\u8ba4\u89d2\u8272\u201d\u548c\u201c\u8fdb\u884c\u6743\u9650\u914d\u7f6e\u201d [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[54],"tags":[],"class_list":["post-1373","post","type-post","status-publish","format-standard","hentry","category-text"],"_links":{"self":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1373","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/comments?post=1373"}],"version-history":[{"count":9,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1373\/revisions"}],"predecessor-version":[{"id":1408,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/posts\/1373\/revisions\/1408"}],"wp:attachment":[{"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/media?parent=1373"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/categories?post=1373"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.preluna.xyz\/index.php\/wp-json\/wp\/v2\/tags?post=1373"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}