Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP³ÌÐòÔ±×îÒ×·¸10ÖÖ´íÎó

PHPÊǸöΰ´óµÄweb¿ª·¢ÓïÑÔ£¬Áé»îµÄÓïÑÔ£¬µ«ÊÇ¿´µ½php³ÌÐòÔ±Öܶø¸´Ê¼µÄ·¸µÄһЩ´íÎó¡£ÎÒ×öÁËÏÂÃæÕâ¸öÁÐ±í£¬ÁгöÁËPHP³ÌÐòÔ±¾­³£·¸µÄ10ÖдíÎ󣬴ó¶àÊýºÍ°²È«Ïà¹Ø¡£¿´¿´Äã·¸Á˼¸ÖÖ
1.²»×ªÒâhtml entities
  Ò»¸ö»ù±¾µÄ³£Ê¶£ºËùÓв»¿ÉÐÅÈεÄÊäÈë£¨ÌØ±ðÊÇÓû§´ÓformÖÐÌá½»µÄÊý¾Ý£© £¬Êä³ö֮ǰ¶¼Òª×ªÒâ¡£
echo $_GET['usename'] ;
Õâ¸öÀý×ÓÓпÉÄÜÊä³ö£º
<script>/*¸ü¸ÄadminÃÜÂëµÄ½Å±¾»òÉèÖÃcookieµÄ½Å±¾*/ </script>
ÕâÊÇÒ»¸öÃ÷ÏԵݲȫÒþ»¼£¬³ý·ÇÄã±£Ö¤ÄãµÄÓû§¶¼ÕýÈ·µÄÊäÈë¡£
ÈçºÎÐÞ¸´ £º
ÎÒÃÇÐèÒª½«" < ",">","and" µÈת»»³ÉÕýÈ·µÄHTML±íʾ( < , >', and ")£¬º¯Êýhtmlspecialchars ºÍ htmlentities()ÕýÊǸÉÕâ¸ö»îµÄ¡£
ÕýÈ·µÄ·½·¨£º
echo htmlspecialchars($_GET['username'], ENT_QUOTES);
2. ²»×ªÒâSQLÊäÈë
ÎÒÔø¾­ÔÚһƪÎÄÕÂÖÐ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÌÖÂÛ¹ýÕâ¸öÎÊÌâ²¢¸ø³öÁËÒ»¸ö¼òµ¥µÄ·½·¨¡£ÓÐÈ˶ÔÎÒ˵£¬ËûÃÇÒѾ­ÔÚphp.iniÖн«magic_quotesÉèÖÃΪOn£¬ËùÒÔ²»±Øµ£ÐÄÕâ¸öÎÊÌ⣬µ«ÊDz»ÊÇËùÓеÄÊäÈë¶¼ÊÇ´Ó$_GET, $_POST»ò $_COOKIEÖеĵõ½µÄ£¡
ÈçºÎÐÞ¸´£º
ºÍÔÚ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÖÐÒ»ÑùÎÒ»¹ÊÇÍÆ¼öʹÓÃmysql_real_escape_string()º¯Êý
ÕýÈ·×ö·¨£º
<?php
$sql = "UPDATE users SET
name='.mysql_real_escape_string($name).'
WHERE id='.mysql_real_escape_string ($id).'";
mysql_query($sql);
?>
3.´íÎóµÄʹÓÃHTTP-header Ïà¹ØµÄº¯Êý: header(), session_start(), setcookie()
Óö


Ïà¹ØÎÊ´ð£º

¸¶·ÑÇóÒ»¶Îphp´úÂ룬֧³ÖÌÔ±¦½»Ò× - PHP / »ù´¡±à³Ì

¸÷λ´óÏÀ 
ÇóÒ»¶Îphp´úÂë 
¿ÉÒÔʵÏÖÒÔϹ¦ÄÜ 
Õë¶Ô²»Í¬µÄä¯ÀÀÆ÷ÏÔʾ²»Í¬µÄͼƬ 
¾ÍÊÇÓÐÒ»ÕÅͼƬ£¬Ö»Ïë¸øie6Óû§¿´µ½ 
Èç¹ûie7¡¢chrome¡¢firefoxÓû§ä¯ÀÀÔòÏÔʾÁíÍâÒ»ÕÅͼƬ  ......

¸¶·ÑÇóÒ»¶Îphp´úÂ룬֧³ÖÌÔ±¦½»Ò× - PHP / Framework

¸÷λ´óÏÀ 
ÇóÒ»¶Îphp´úÂë 
¿ÉÒÔʵÏÖÒÔϹ¦ÄÜ 
Õë¶Ô²»Í¬µÄä¯ÀÀÆ÷ÏÔʾ²»Í¬µÄͼƬ 
¾ÍÊÇÓÐÒ»ÕÅͼƬ£¬Ö»Ïë¸øie6Óû§¿´µ½ 
Èç¹ûie7¡¢chrome¡¢firefoxÓû§ä¯ÀÀÔòÏÔʾÁíÍâÒ»ÕÅͼƬ  ......

Çë½Ì PHP ÌØÊâ×Ö´¦ÀíÎÊÌâ

ÀýÈçÒ»¾äÎı¾ AAA'BBB\CCC 
ÓÃÁË mysql_real_escape_string ºó ¿ÉÒÔ´æ½øÊý¾Ý¿â
µ«¶Á³öÀ´µÄʱºò£¬¾Í³ÉÁË
AAA\'BBB\\\CCC 
ÈçºÎ»¹Ô­Îª AAA'BBB\CCC
addslashes
stripslashes

[b][/b]ÒýÓÃ
adds ......

ÐèÒªÊÓÆµ½Ì³ÌµÄÐÂÊÖ½ø php + mysql + apache ÅäÖÃ

Õâ¸öÊÓÆµ½²µÄºÜÏêϸ, ¶ÔÐÂÊַdz£ÓÐÓÃ, »ù±¾ÉÏÒ»¿´¾Í¶®
ÓÉÓÚÌ«´óÁË(50m, ÎÒÖ»ÄÜÉÏ´«20m), ÎÒÉÏ´«²»ÁË, Ö»ºÃÌù³öÏÂÔØµØÖ·
ÏÂÔØµØÖ·: http://ftel1.3800hk.com/0807/080720djxnzj.rar
ºÃ¶«Î÷,ϸö¿´¿´


......

ÀûÓÃPHPͨ¹ýapacheÏÂÔØwavÒôÀÖÎļþÎÞ·¨´ò¿ªÎļþ

µ±ÎÒÓÃPHPÏÂÔØ·þÎñÆ÷ÉϵÄwavÒôÀÖÎļþʱ£¬wavÎļþÄܹ»ÏÂÔØÏÂÀ´£¬²¢ÇÒ´óСÏàͬ£¬µ«ÊÇÈ´²»Äܲ¥·Å¡£µ«ÈôÊÇͨ¹ýÎļþ·þÎñÆ÷¿½±´µ½±¾µØ£¬ÊÇ¿ÉÒÔ²¥·Å¸ÃÎļþµÄ£¬²»ÖªµÀÈçºÎÔ­Òò¡£Í¨¹ýMD5sum¼ì²â£¬¸ÃÎļþÏÂÔØºóÒѸı䣬²»ÖªµÀÔ ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ