ÀûÓÃPHPͨ¹ýapacheÏÂÔØwavÒôÀÖÎļþÎÞ·¨´ò¿ªÎļþ
µ±ÎÒÓÃPHPÏÂÔØ·þÎñÆ÷ÉϵÄwavÒôÀÖÎļþʱ£¬wavÎļþÄܹ»ÏÂÔØÏÂÀ´£¬²¢ÇÒ´óСÏàͬ£¬µ«ÊÇÈ´²»Äܲ¥·Å¡£µ«ÈôÊÇͨ¹ýÎļþ·þÎñÆ÷¿½±´µ½±¾µØ£¬ÊÇ¿ÉÒÔ²¥·Å¸ÃÎļþµÄ£¬²»ÖªµÀÈçºÎÔÒò¡£Í¨¹ýMD5sum¼ì²â£¬¸ÃÎļþÏÂÔØºóÒѸı䣬²»ÖªµÀÔÚÄÄÀï±»Ð޸ģ¬Çë½Ì´ó¼Ò£¬Ð»Ð»£¡
PHP code:
<?php
include ("./lib/defines.php");
include ("./lib/functions.php");
include ("./lib/database.php");
session_start();
getpost_ifset(array('confno', 'bookid'));
$query = "SELECT confOwner from " . DB_TABLESCHED . " WHERE bookid=?";
$data = array($bookid);
$result = $db->query($query, $data);
$row = $result->fetchRow();
if ($_SESSION['auth'] && ($_SESSION['privilege'] == "Admin" ||
$row[0] == $_SESSION['userid'])) {
if (is_numeric($confno) && is_numeric($bookid)) {
$file = "meetme-conf-rec-".$confno . "-" . $bookid . ".wav";
$playfile = "/var/lib/asterisk/sounds/" . $file ;
$mimetype = "audio/x-wav";
$content_len = filesize($playfile);
header("Content-Type:".$mimetype);
header("Content-Transfer-Encoding:binary");
header("Content-Length:".$content_len);
header("Cache-Control:private");
Ïà¹ØÎÊ´ð£º
ʹÓÃPHPµÄexecº¯Êýµ÷ÓÃlinuxµÄshellÃüÁÈçdateÈ¥ÐÞ¸Äʱ¼ä»òshutdownȥʵÏֹػú/ÖØÆô£¬µ«ÊÇ·µ»ØÖµ¶¼ÊÇʧ°ÜµÄ¡£¾¹ý¶à´ÎÊÔÑ飬È϶¨ÊÇûÓÐȨÏÞµÄÎÊÌâ¡£
ËùÒÔ£¬Ð¡µÜÔÚ´ËÇë½Ì¸÷룬ÈçºÎ²ÅÄÜÉèÖÃȨÏÞ£¬µ÷ÓÃlinux shellà ......
¸÷λ´óÏÀ
ÇóÒ»¶Îphp´úÂë
¿ÉÒÔʵÏÖÒÔϹ¦ÄÜ
Õë¶Ô²»Í¬µÄä¯ÀÀÆ÷ÏÔʾ²»Í¬µÄͼƬ
¾ÍÊÇÓÐÒ»ÕÅͼƬ£¬Ö»Ïë¸øie6Óû§¿´µ½
Èç¹ûie7¡¢chrome¡¢firefoxÓû§ä¯ÀÀÔòÏÔʾÁíÍâÒ»ÕÅͼƬ  ......
ÎÒÔÚphpÒ»¸ö½çÃæË¢ÐÂÒÔºóÏëÔÚ1·ÖÖÓÒÔºó½øÐвÙ×÷£¨±ÈÈç˵µ¯³ö¸öÌáʾ¿ò£©
¸ßÊÖÖ¸µãÈçºÎ²Ù×÷
ÊÇÓÃsessionµÄÉú´æÊ±¼äÉèÖÃÂ𣿻¹ÊDZðµÄʲô·½·¨
Çë˵Ïêϸµã¡£¹òÇó¡£
ʲôÒâ˼£¿Ò»·ÖÖӺ󵯳öÌáʾÌáʾ¿ò£¿ÄÇÓÃjavascrip ......
ÀýÈçÒ»¾äÎı¾ AAA'BBB\CCC
ÓÃÁË mysql_real_escape_string ºó ¿ÉÒÔ´æ½øÊý¾Ý¿â
µ«¶Á³öÀ´µÄʱºò£¬¾Í³ÉÁË
AAA\'BBB\\\CCC
ÈçºÎ»¹ÔΪ AAA'BBB\CCC
addslashes
stripslashes
[b][/b]ÒýÓÃ
adds ......
¸÷λ´óЩ
ÇóÒ»¶Îphp´úÂë
¿ÉÒÔʵÏÖÒÔϹ¦ÄÜ
Õë¶Ô²»Í¬µÄä¯ÀÀÆ÷ÏÔʾ²»Í¬µÄͼƬ
¾ÍÊÇÓÐÒ»ÕÅͼƬ£¬Ö»Ïë¸øie6Óû§¿´µ½
Èç¹ûie7¡¢chrome¡¢firefoxÓû§ä¯ÀÀÔòÏÔʾÁíÍâÒ»ÕÅͼƬ
¼Û¸ñ²»ÒªÌ«ÀëÆ×¾ÍÐÐ ......