phpÕýÔòÌæ»»ÔÚÕýб¸Üǰ¼ÓÒ»·´Ð±¸Ü
<?php
// create a new curl resource
$ch = curl_init();
// set URL and other appropriate options
curl_setopt($ch, CURLOPT_URL, "http://www.baidu.com/");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_HEADER, 0);
// grab URL and pass it to the browser
$str=curl_exec($ch);
$str=preg_replace("/\//","\\\/",$str);
?>
<script>alert(" <?php echo $str ?>"); </script>
<?php
// close curl resource, and free up system resources
curl_close($ch);
?>
alertÔõô³ö´í°¡
ºÃÀÛ°¡ ÏÈÐÝϢһϠÔÙ¿´lzÎÊÌâ
ÎÒ¶¥
¾ÍÄÇô¸öÌæ»»£¬ÓÃÕýÔò£¿
{{
Ïà¹ØÎÊ´ð£º
ÎÒ¸ÕѧϰphpÇëÎÊ£¬Èç¹ûÎÒ°ÑphpÎļþÉÏ´«ÖÁ·þÎñÆ÷ºó£¬ÀýÈçhttp://www.****.com/cast.phpÕâ¸öÎļþ»á²»»á±»±ðÈËÏÂÔØ»ò¸´Öư¢£¿
¿ÉÒÔ±»ÏÂÔØ£¬Ò²¿ÉÒÔ²»±»ÏÂÔØ£¬¿´web·þÎñÆ÷¶Ô¸ÃÎļþȨÏÞµÄÅäÖÃ
¿´Äã¶ÔÎļþȨÏÞµÄÉèÖÃ
......
ÒѾÐÞ¸ÄÁË
£¨1£©PHP.iniÖеÄpost_max_size ºÍupload_max_filesize£¬²¢ÇÒ±£Ö¤ÁËǰÕß´óÓÚºóÕß
£¨2£©Windows\System32\inetsvr\MetaBase.xmlÖеÄAspMaxRequestEntityAllowed
ÐÞ¸ÄÍê±Ïºó£¬ÖØÐÂÆô¶¯ÁËIIS·þÎñ£¬²¢ÇÒ¼Æ ......
¹ýÍêÄêҪȥÎ人ÁË£¬ÏëÁ˽âÒ»ÏÂPHPÅàѵ±È½ÏÕý¹æ?
Ŷ ¶ÔÁË£¬»¹ÓУ¡PHPÊÖ²á±ØÐëµÃŪһ¸ö
àÅ ÌìÌìÔÚ¿´Ê¥¾£¨Ò»ÌìÒ²¾ÍÖ»ÄÜ¿´¸ö¶þʮҳ£©£¬PHP100ÊÓÆµ½Ì³Ì¿´ÁË33½²ÁË£¨Ò»ÌìÒ²Ö»¿´Ò»½²£©
ÎÒ»á¼á³Ö°ÑÕâ±¾ÊéºÍÊÓÆµ¸ã¶¨ ......
ÇëÎÊ
object(Helper_Uploader_File) {
protected '_file' => array(
'name' => string '4_¹âÓ°_1.jpg' (length=14)
'type ......
ÀýÈ磺
±ÈÈçÎÒµÄij¸öurl£¬
http://127.0.0.1/xxx/xxx.php?action=gg
ÊÇÈ¥Ö´ÐÐxxx.phpÖÐij¶Î´úÂë
if ($action == ....) {
...
...
return $arr;
}
¡£
ÎÒÔ ......