linuxÏÂphpÖ´ÐÐÃüÁîµÄÎÊÌâ
PHPÖÐÓÃmountÃüÁî½øÐйÒÔØÃ»·´Ó¦¡£µ«ÔÚlinuxÖÐÖ´ÐдËÃüÁîºÃÓá£
PHPÎļþ:test.php
<?php
$strCommond = 'sudo mount -t cifs //192.168.0.1/var/www /mnt/www -o iocharset=utf8,codepage=932,username=admin,password=admin';
if (exec($strCommond)) {
echo "OK";
} else {
echo "NG";
}
?>
ÔËÐнá¹ûÊÇ:NG
ÇëÕâλÅóÓѰïæ½â¾öÒ»ÏÂ
ÈçºÎ¿´apacheÓû§È¨ÏÞÄÜ·ñÖ´ÐÐsudo?
exec·µ»ØÖµÎª¿Õ
apache conf ÀïµÄ groupid userid ¸ú
ls -las sudo ¿´¿´¶ÔӦȨÏÞ
apache confÀïµÄuserºÍgroupÊÇdaemon
ls -las sudoÕâÃüÁî³ö´í
error:ls cannot access sudo
execÊÇûÓзµ»ØÖµµÄ
ÓÃDEMOÈ¥»ñÈ¡SUDOȨÏÞ¹À¼Æ¹»Çº¡£³ý·ÇÄãÄÇô·ÅÐİÑÄãµÄȨÏÞ½»³öÈ¥
Æäʵ½¨ÒéÄã¿ÉÒÔ×Ô¼ºÐ´¸öSHELL½Å±¾,SHELL½Å±¾Ìá½»¸øDEMO²Ù×÷Ö´ÐÐ
Äã×Ô¼ºÄDZ߿ØÖÆÈ¨ÏÞ²Ù×÷£¬¿ÉÄÜ»á¸üºÃµã
ÎÒд¹ýÒ»¸öSHELL£¬ÓÃPHPµ÷ÓÃSHELLÒ²²»ÐÐ
ÄÜ·ñ¸øÐ´¸öСÀý×Ó£¿
´´½¨ÄãµÄSH
½«ÄãµÄSH·ÅÈëdemoÓû§¿ÉÒÔ½ÓÈëµÄPATHÄÚ
ÐÞ¸ÄSHȨÏÞΪ 777°É£¨other×é¿ÉÖ´Ðм´¿É£©
exec("ȫ·¾¶µ½/SH");
ÁíÍâ¾ÍÊÇÄãµÄSHÀïµÄд·¨¡£ÄǾÍÊǹØÓÚSHELL½Å±¾±à³Ì·½ÃæÖªÊ¶ÁË
Äã²âÊÔµÄʱºò¿ÉÒÔÖ»ÔÚÀïÃæµ÷ÓÃÒ»¸ö¼òµ¥ÃüÁî
±ÈÈç
touch "test" > abc.txt
Èç¹û³É¹¦ÁË˵Ã÷ÖÁÉÙÄãPHPµ÷Óýű¾ÊÇÍê³ÉÁË¡£ÖÁÓÚÄãÒªÍê³ÉʲôÄǾÍÊÇÄã¶Ôϵͳ
Ïà¹ØÎÊ´ð£º
ÔÚ¹úÍâµÄ¿Õ¼ä£¬ÆäËüµÄphpÕ¾µã¶¼Õý³££¬¿ÉÖ»ÓÐ×î½ü½¨µÄÕâ¸öÕ¾µã£¬Ö»ÒªÒ»ä¯ÀÀphpÎļþ¾Í³öÏÖÏÂÔØÌáʾ£¬ÏÂÔØÏÂÀ´µÄÎļþ¶¼ÊÇ´øÓÐphpÔ´Â룬¸÷λ·¹ýµÄ£¬°ï°ïÎÒ£¬¿´¿´Ê²Ã´ÔÒò£¬ÏÈлÁË¡£
¿ÉÄÜÊÇÒòΪ¸ÃÕ¾µãûÓÐÄãÏëÒªµÄä¯ÀÀÆ ......
´úÂëÈçÏ£º
function uc_get_user($username, $isuid=0) {
$return = call_user_func(UC_API_FUNC, 'user', 'get_user', array('username'=>$username, 'isuid'=>$isuid));
return UC_CONNECT == 'mysql' ......
ÎÒ¸ÕѧϰphpÇëÎÊ£¬Èç¹ûÎÒ°ÑphpÎļþÉÏ´«ÖÁ·þÎñÆ÷ºó£¬ÀýÈçhttp://www.****.com/cast.phpÕâ¸öÎļþ»á²»»á±»±ðÈËÏÂÔØ»ò¸´Öư¢£¿
¿ÉÒÔ±»ÏÂÔØ£¬Ò²¿ÉÒÔ²»±»ÏÂÔØ£¬¿´web·þÎñÆ÷¶Ô¸ÃÎļþȨÏÞµÄÅäÖÃ
¿´Äã¶ÔÎļþȨÏÞµÄÉèÖÃ
......
PHP code:
$date = '2009-12-25';
$ptn = '/([\d]{4})[- \/](0?[\d]|1[0-2])[-\/ ](0?[\d]|[1-2][\d]|3[0-1])/';
if (preg_match($ptn,$date,$out))
{
print_r($out);exit();
}
½á¹ûΪ:
PHP code:
......
¹ýÍêÄêҪȥÎ人ÁË£¬ÏëÁ˽âÒ»ÏÂPHPÅàѵ±È½ÏÕý¹æ?
Ŷ ¶ÔÁË£¬»¹ÓУ¡PHPÊÖ²á±ØÐëµÃŪһ¸ö
àÅ ÌìÌìÔÚ¿´Ê¥¾£¨Ò»ÌìÒ²¾ÍÖ»ÄÜ¿´¸ö¶þʮҳ£©£¬PHP100ÊÓÆµ½Ì³Ì¿´ÁË33½²ÁË£¨Ò»ÌìÒ²Ö»¿´Ò»½²£©
ÎÒ»á¼á³Ö°ÑÕâ±¾ÊéºÍÊÓÆµ¸ã¶¨ ......