xampp 默认开启 indexes 选项,导致无首页文件时暴露目录列表,属安全隐患;需在每个虚拟主机的 directory 块中显式移除 indexes 并重启 apache。

直接说结论:XAMPP 默认开启 Indexes 选项,只要目录下没有 index.html 或 index.php,就会列出所有文件——这不是“功能”,是安全隐患;禁用它只需删掉配置里的 Indexes,但必须在每个生效的 <directory></directory> 块里单独处理,不能只改全局根目录。
为什么 localhost:8081 会暴露文件列表?
Apache 的 Options Indexes 是开关。XAMPP 的默认配置(尤其在 httpd.conf 和 httpd-xampp.conf 中)普遍包含:Options Indexes FollowSymLinks Includes ExecCGI。一旦某个端口对应的 <virtualhost></virtualhost> 指向的目录没放首页文件,且该目录的 <directory></directory> 块没显式关闭 Indexes,浏览器就会看到可点击的文件列表。
常见错误现象:
- 访问
http://localhost:8081/显示一堆 .php/.js/.css 文件链接 - 用不同端口跑多个项目,只有某一个端口出问题——说明配置没同步到对应
<directory></directory> - 改了主
htdocs的配置,但新端口仍能列目录——因为虚拟主机里另写了<directory></directory>,覆盖了全局设置
在 httpd-vhosts.conf 中为每个端口单独关掉 Indexes
推荐把多端口配置统一写在 conf/extra/httpd-vhosts.conf(确保 httpd.conf 中已取消注释 Include conf/extra/httpd-vhosts.conf)。每个 <virtualhost></virtualhost> 必须配自己的 <directory></directory>,且里面不能带 Indexes。
实操建议:
XAMPP 8.0.30 是一款免费、开源的跨平台 Web 服务器集成包,专为快速搭建本地 PHP 开发环境而设计。该版本核心组件包括:Apache 2.4.56、MySQL 8.0.33、PHP 8.0.30、phpMyAdmin 5.2.1 等。它支持 Windows、Linux 和 macOS 系统,可让开发者在个人电脑上轻松模拟服务器环境,无需复杂配置即可运行 WordPress、Thin
- 不要复用默认的
DocumentRoot "C:/xampp/htdocs"配置块,每个端口都写完整<directory></directory> -
Options行明确写成:Options FollowSymLinks Includes ExecCGI(确认不含Indexes) - 如果项目不需要 CGI 或 SSI,可以进一步精简为:
Options FollowSymLinks - 务必检查
AllowOverride和Require权限是否匹配——例如 XAMPP 2.4+ 要用Require all granted,不是Allow from all
示例(监听 8081 端口):
<virtualhost>
DocumentRoot "E:/projects/api"
ServerName localhost:8081
<directory>
Options FollowSymLinks
AllowOverride None
Require all granted
</directory></virtualhost>
别漏掉 httpd-xampp.conf 里的安全限制
XAMPP 自带的安全策略文件 conf/extra/httpd-xampp.conf 会在多个位置插入 <locationmatch></locationmatch> 和 <directory></directory> 块,其中部分配置可能强制开启 Indexes 或覆盖你写的规则。特别是这个区块:
<directory>
Options Indexes FollowSymLinks Includes ExecCGI
...
</directory>
如果你的某个端口也指向 htdocs 子目录(比如 "C:/xampp/htdocs/project-a"),而上面这个块没被覆盖,Indexes 就依然有效。解决方法:
- 要么把项目挪到
htdocs外的独立路径(如E:/projects),彻底避开该块影响 - 要么在你自己的
<directory></directory>块中显式重写Options,优先级更高 - 不建议直接删或注释
httpd-xampp.conf里的Options Indexes——它保护的是 XAMPP 自带的控制面板等敏感路径
最易被忽略的一点:改完任何配置文件后,必须用 httpd -t 命令验证语法(在 XAMPP 控制台点 “Shell” 进入命令行执行),再重启 Apache。仅靠控制面板“Restart”按钮无法捕获 Options 拼写错误或路径引号缺失这类低级问题。










