Nginx 如何配置防盜鏈
需求:通常站點(diǎn),都會(huì)想讓自己網(wǎng)站的視頻和圖片,免被盜用,畢竟視頻流量,花的都是白花花銀子(土豪可以不用考慮)~~。
一、單刀直入,先上nginx配置文件
- server {
- listen 80;
- server_name www.test.com;
- root /data/web/;
- index index.php index.html;
- access_log /data/logs/nginx/biao.madacode.access.log main;
- location /{
- root /home/data/;
- }
- error_page 404 /usr/local/nginx/html/404.html;
- location ~ .*\.(wma|wmv|asf|mp3|mp4|mmf|zip|rar|jpg|gif|png|swf|flv)$
- {
- valid_referers none blocked server_names *.test.com http://IP;
- if ($invalid_referer) {
- return 403;
- }
- expires 24h;
- access_log off;
- }
- location ~ /\.
- {
- deny all;
- }
- }
二、防盜鏈核心配置文件解釋
- location ~ .*\.(wma|wmv|asf|mp3|mp4|mmf|zip|rar|jpg|gif|png|swf|flv)$
- {
- valid_referers none blocked server_names *.test.com http://IP;
- if ($invalid_referer) {
- return 403;
- }
- expires 24h;
- access_log off;
- }
vaild_referers 有效的引用連接,如下,否則就進(jìn)入$invaild_refere,返回403 forbiden。
1. none
"Referer" 來源頭部為空的情況
2. blocked
"Referer"來源頭部不為空,但是里面的值被代理或者防火墻刪除了,這些值都不以http://或者h(yuǎn)ttps://開頭.
3. server_names
"Referer"來源頭部包含當(dāng)前的server_names(當(dāng)前域名)
三、模擬案例測試
添加 --referer 模擬引用,看結(jié)果直接403.證明上面配置是OK的
- [root@test]# curl --referer http://baidu.com -I http://www.test.com/temp/T19254/20190820/video_out_out/1/0011.mp4
- HTTP/1.1 403 Forbidden
- Server: Tengine
- Date: Wed, 21 Aug 2019 09:54:44 GMT
- Content-Type: text/html
- Content-Length: 639
- Connection: keep-alive