$str=preg_replace("/\s+/", " ", $str); //¹ýÂ˶àÓà»Ø³µ
$str=preg_replace("/<[ ]+/si","<",$str); //¹ýÂË<__("<"ºÅºóÃæ´ø¿Õ¸ñ)
$str=preg_replace("/<\!--.*?-->/si","",$str); //×¢ÊÍ
$str=preg_replace("/<(\!.*?)>/si","",$str); //¹ýÂËDOCTYPE
$str=preg_replace("/<(\/?html.*?)>/si","",$str); //¹ýÂËhtml±êÇ©
$str=preg_replace("/<(\/?head.*?)>/si","",$str); //¹ýÂËhead±êÇ©
$str=preg_replace("/<(\/?meta.*?)>/si","",$str); //¹ýÂËmeta±êÇ©
$str=preg_replace("/<(\/?body.*?)>/si","",$str); //¹ýÂËbody±êÇ©
$str=preg_replace("/<(\/?link.*?)>/si","",$str); //¹ýÂËlink±êÇ©
$str=preg_replace("/<(\/?form.*?)>/si","",$str); //¹ýÂËform±êÇ©
$str=preg_replace("/cookie/si","COOKIE",$str); //¹ýÂËCOOKIE±êÇ©
$str=preg_replace("/<(applet.*?)>(.*?)<(\/applet.*?)& ......
ÓöàÖÖ±à¼Èí¼þÐ޸ĹýµÄphpÍøÕ¾¿ÉÄÜ»áÓöµ½Ò»ºÜ¹ÖÎÊÌ⣺ÓÃincludeÒýÈëµÄfooterºÍheaderÎļþ¶¼ÔÚÉÏÃæ¶à³öÒ»¿Õ°×ÐУ¬Ö±½Ó°Ñ±»ÒýÈëµÄÎļþ·ÅÈëÔòûÎÊÌâ¡£Õâ¸öÎÊÌ⼫ÓпÉÄÜÊDZàÂëÎÊÌâÒýÆðµÄ¡£Èç¹û²ÉÓÃutf-8±àÂëÒªÉèÖÃΪÎÞbom£¬²¢ÇÒÒªËùÓеÄÉæ¼°µ½µÄÒ³Ãæ°üÀ¨css¼°ÆäËûÎļþ¶¼ÒªÒÔÎÞbomµÄutf-8±àÂë¡£¾ßÌå·½·¨¿ÉÒÔÊÇ£ºÔÚDreamweaverÀï µã“Ð޸Ĕ£¬Ñ¡Ôñ“Ò³ÃæÊôÐÔ”£¬“±êÌâ/±àÂ딣¬°Ñ °üÀ¨unicodeÇ©Ãû(bom) µÄ¹´È¡Ïû¡£ ......
¸ù¾ÝÄãµÄʹÓÃÄ¿µÄÎÒ¾õµÃÕâ¸öº¯ÊýÓÐÁ½·½ÃæµÄÓÃ;£º
·ÀÖ¹SQL Injection¹¥»÷£¬Ò²¾ÍÊÇÄã±ØÐëÑéÖ¤Óû§µÄÊäÈë
²Ù×÷Êý¾ÝµÄʱºò±ÜÃâ²»±ØÒªµÄ×Ö·ûµ¼Ö´íÎó
mysql_real_escape_string() º¯ÊýתÒå SQL Óï¾äÖÐʹÓõÄ×Ö·û´®ÖеÄÌØÊâ×Ö·û¡£
ÏÂÁÐ×Ö·ûÊÜÓ°Ï죺
\x00
\n
\r
\
'
"
\x1a
Èç¹û³É¹¦£¬Ôò¸Ãº¯Êý·µ»Ø±»×ªÒåµÄ×Ö·û´®¡£Èç¹ûʧ°Ü£¬Ôò·µ»Ø false¡£
¹¥»÷µÄÀý×Ó£Û1£Ý
Àý×Ó 1
<?php
$con = mysql_connect("localhost", "hello", "321");
if (!$con)
{
die('Could not connect: ' . mysql_error());
}
// »ñµÃÓû§ÃûºÍÃÜÂëµÄ´úÂë
// תÒåÓû§ÃûºÍÃÜÂ룬ÒÔ±ãÔÚ SQL ÖÐʹÓÃ
$user = mysql_real_escape_string($user);
$pwd = mysql_real_escape_string($pwd);
$sql = "SELECT * from users WHERE
user='" . $user . "' AND password='" . $pwd . "'"
// ¸ü¶à´úÂë
mysql_close($con);
?>
Àý×Ó 2
Êý¾Ý¿â¹¥»÷¡£±¾ÀýÑÝʾÈç¹ûÎÒÃDz»¶ÔÓû§ÃûºÍÃÜÂëÓ¦Óà mysql_real_escape_string() º¯Êý»á·¢Éúʲô£º
<?php
$con = mysql_connect("localhost", "hello", " ......
¸ù¾ÝÄãµÄʹÓÃÄ¿µÄÎÒ¾õµÃÕâ¸öº¯ÊýÓÐÁ½·½ÃæµÄÓÃ;£º
·ÀÖ¹SQL Injection¹¥»÷£¬Ò²¾ÍÊÇÄã±ØÐëÑéÖ¤Óû§µÄÊäÈë
²Ù×÷Êý¾ÝµÄʱºò±ÜÃâ²»±ØÒªµÄ×Ö·ûµ¼Ö´íÎó
mysql_real_escape_string() º¯ÊýתÒå SQL Óï¾äÖÐʹÓõÄ×Ö·û´®ÖеÄÌØÊâ×Ö·û¡£
ÏÂÁÐ×Ö·ûÊÜÓ°Ï죺
\x00
\n
\r
\
'
"
\x1a
Èç¹û³É¹¦£¬Ôò¸Ãº¯Êý·µ»Ø±»×ªÒåµÄ×Ö·û´®¡£Èç¹ûʧ°Ü£¬Ôò·µ»Ø false¡£
¹¥»÷µÄÀý×Ó£Û1£Ý
Àý×Ó 1
<?php
$con = mysql_connect("localhost", "hello", "321");
if (!$con)
{
die('Could not connect: ' . mysql_error());
}
// »ñµÃÓû§ÃûºÍÃÜÂëµÄ´úÂë
// תÒåÓû§ÃûºÍÃÜÂ룬ÒÔ±ãÔÚ SQL ÖÐʹÓÃ
$user = mysql_real_escape_string($user);
$pwd = mysql_real_escape_string($pwd);
$sql = "SELECT * from users WHERE
user='" . $user . "' AND password='" . $pwd . "'"
// ¸ü¶à´úÂë
mysql_close($con);
?>
Àý×Ó 2
Êý¾Ý¿â¹¥»÷¡£±¾ÀýÑÝʾÈç¹ûÎÒÃDz»¶ÔÓû§ÃûºÍÃÜÂëÓ¦Óà mysql_real_escape_string() º¯Êý»á·¢Éúʲô£º
<?php
$con = mysql_connect("localhost", "hello", " ......
PHPÊý×麯ÊýÖÐòËÆûÓÐÌṩɾ³ýÊý×éÖеÄij¸öÔªËصĺ¯Êý
µ«È´ÓÐÒ»¸öarray_search£¨²éÕÒÊý×éÖеÄij¸öÔªËØ£¬²¢·µ»ØÆä¼üÃû£©
ÄÇô¾ÍÓÃÒ»ÏÂËüÁË
$array_key = array_search($target_value,$target_array);
if($array_key||$array_key==0)unset($target_array[$target_value]);
//ÕâÀïµÄÌõ¼þÓÃ$array_key!==falseÒ²ÊÇ¿ÉÒԵİÉ
OKÁË
±¾À´ÏëÖ±½Ó
$target_array[$target_value] = NULL;
¶ø²»ÏëÓÃunsetµÄ
¼ÇµÃÀÏʦ˵°ÑÒ»¸ö±äÁ¿¸³ÖµÎªNULL¾ÍÏ൱ÓÚunsetµôÁË
ÒòΪºÃÏñÔÚÄÄÀï¿´µ½Ëµ¸³ÖµµÄЧÂÊÒª±Èº¯ÊýµÄЧÂʸߺܶà
¾ÍÏñ×îºÃÓÃ
$array[] = $value;
´úÌæ
array_push($array,$value);
Ò»Ñù
µ«ºóÀ´Ò»²âÊÔ·¢ÏÖ²»ÐÐ
$target_array[$target_value] = NULL;
µÄ»°
Êý×éÀﻹÊÇÓÐÕâ¸öÔªËØ£¬Ö»²»¹ýֵΪNULLÁË
ËùÒÔ»¹ÊÇÀÏÀÏʵʵµÄunsetµÄ°É ......
Ä¿Ç°LAMP (Linux + Apache + MySQL + PHPspan style="font-family: Verdana;">) ½ü¼¸ÄêÀ´·¢Õ¹Ñ¸ËÙ£¬ÒѾ³ÉΪWeb ·þÎñÆ÷µÄÊÂʵ±ê×¼¡£LAMPÕâ¸ö´ÊµÄÓÉÀ´×îÔçʼÓڵ¹úÔÓÖ¾“c't Mag
azine”£¬Michael KunzeÔÚ1990Äê×îÏÈ°ÑÕâЩÏîÄ¿×éºÏÔÚÒ»Æð´´ÔìÁËLAMPµÄËõд×Ö¡£ÕâЩ×é¼þËäÈ»²¢²»ÊÇ¿ª¿ªÊ¼¾ÍÉè¼ÆΪһÆðʹÓõģ¬µ«ÊÇ£¬ÕâЩ¿ªÔ´Èí¼þ¶¼¿ÉÒԺܷ½±ãµÄËæʱ»ñµÃ²¢Ãâ·Ñ»ñµÃ¡£Õâ¾Íµ¼ÖÂÁËÕâЩ×é¼þ¾³£ÔÚÒ»ÆðʹÓá£ÔÚ¹ýÈ¥µÄ¼¸ÄêÀÕâЩ×é¼þµÄ¼æÈÝÐÔ²»¶ÏÍêÉÆ£¬ÔÚÒ»ÆðµÄÓ¦ÓÃÇéÐαäµÃ·Ç³£Æձ㡣ΪÁ˸ÄÉƲ»Í¬×é¼þÖ®¼äµÄÐ×÷£¬ÒѾ´´½¨ÁËijЩÀ©Õ¹¹¦ÄÜ¡£Ä¿Ç°£¬¼¸ºõÔÚËùÓеÄLinux·¢²¼°æÖж¼Ä¬ÈÏ°üº¬ÁË“LAMP stack”µÄ²úÆ·¡£ÕâЩ²úÆ·×é³ÉÁËÒ»¸öÇ¿´óµÄWebÓ¦ÓóÌÐòƽ̨¡£“LAMP stack”ÖеÄÿһ¸ö×é¼þ¶¼ÊÇÒ»¸öFOSS(Ãâ·Ñ»òÕß¿ªÔ´Èí¼þ/Free or Open Source Software)µÄʵÀý¡£FOSS·½·¨µÄºÃ´¦ÓÐÈý¸ö·½Ãæ¡£µÚÒ»£¬FOSSÈí¼þµÄÐÔÖÊÒâζ×ÅÓ¦ÓóÌÐò¿ÉÒÔÃâ·ÑÏÂÔØ£¬Äܹ»Èøü¹ã·ºµÄÈËÃDz»Óø¶·Ñ¾Í¿ÉÒÔʹÓÃÕâ¸öÓ¦ÓÃÈí¼þ¡£ÕâÖÖÃâ·ÑµÄ·½Ê½¶ÔÓÚ¹ã´óÓû§Ìرð¾ßÓÐÎüÒýÁ¦¡£ÕâЩÓû§Èç¹û²»Ê¹ÓÃÃâ·ÑµÄÈí¼þ¾ÍÐèÒª¸¶·Ñ¹ºÂò“רҵ”µÄÉÌÓÃÈí¼þ¹¤¾ß¡£ÕâÔÚÖÆ×÷ÍøÕ¾·½Ãæͨ³£Ê ......
Ä¿Ç°LAMP (Linux + Apache + MySQL + PHPspan style="font-family: Verdana;">) ½ü¼¸ÄêÀ´·¢Õ¹Ñ¸ËÙ£¬ÒѾ³ÉΪWeb ·þÎñÆ÷µÄÊÂʵ±ê×¼¡£LAMPÕâ¸ö´ÊµÄÓÉÀ´×îÔçʼÓڵ¹úÔÓÖ¾“c't Mag
azine”£¬Michael KunzeÔÚ1990Äê×îÏÈ°ÑÕâЩÏîÄ¿×éºÏÔÚÒ»Æð´´ÔìÁËLAMPµÄËõд×Ö¡£ÕâЩ×é¼þËäÈ»²¢²»ÊÇ¿ª¿ªÊ¼¾ÍÉè¼ÆΪһÆðʹÓõģ¬µ«ÊÇ£¬ÕâЩ¿ªÔ´Èí¼þ¶¼¿ÉÒԺܷ½±ãµÄËæʱ»ñµÃ²¢Ãâ·Ñ»ñµÃ¡£Õâ¾Íµ¼ÖÂÁËÕâЩ×é¼þ¾³£ÔÚÒ»ÆðʹÓá£ÔÚ¹ýÈ¥µÄ¼¸ÄêÀÕâЩ×é¼þµÄ¼æÈÝÐÔ²»¶ÏÍêÉÆ£¬ÔÚÒ»ÆðµÄÓ¦ÓÃÇéÐαäµÃ·Ç³£Æձ㡣ΪÁ˸ÄÉƲ»Í¬×é¼þÖ®¼äµÄÐ×÷£¬ÒѾ´´½¨ÁËijЩÀ©Õ¹¹¦ÄÜ¡£Ä¿Ç°£¬¼¸ºõÔÚËùÓеÄLinux·¢²¼°æÖж¼Ä¬ÈÏ°üº¬ÁË“LAMP stack”µÄ²úÆ·¡£ÕâЩ²úÆ·×é³ÉÁËÒ»¸öÇ¿´óµÄWebÓ¦ÓóÌÐòƽ̨¡£“LAMP stack”ÖеÄÿһ¸ö×é¼þ¶¼ÊÇÒ»¸öFOSS(Ãâ·Ñ»òÕß¿ªÔ´Èí¼þ/Free or Open Source Software)µÄʵÀý¡£FOSS·½·¨µÄºÃ´¦ÓÐÈý¸ö·½Ãæ¡£µÚÒ»£¬FOSSÈí¼þµÄÐÔÖÊÒâζ×ÅÓ¦ÓóÌÐò¿ÉÒÔÃâ·ÑÏÂÔØ£¬Äܹ»Èøü¹ã·ºµÄÈËÃDz»Óø¶·Ñ¾Í¿ÉÒÔʹÓÃÕâ¸öÓ¦ÓÃÈí¼þ¡£ÕâÖÖÃâ·ÑµÄ·½Ê½¶ÔÓÚ¹ã´óÓû§Ìرð¾ßÓÐÎüÒýÁ¦¡£ÕâЩÓû§Èç¹û²»Ê¹ÓÃÃâ·ÑµÄÈí¼þ¾ÍÐèÒª¸¶·Ñ¹ºÂò“רҵ”µÄÉÌÓÃÈí¼þ¹¤¾ß¡£ÕâÔÚÖÆ×÷ÍøÕ¾·½Ãæͨ³£Ê ......
Ä¿Ç°LAMP (Linux + Apache + MySQL + PHPspan style="font-family: Verdana;">) ½ü¼¸ÄêÀ´·¢Õ¹Ñ¸ËÙ£¬ÒѾ³ÉΪWeb ·þÎñÆ÷µÄÊÂʵ±ê×¼¡£LAMPÕâ¸ö´ÊµÄÓÉÀ´×îÔçʼÓڵ¹úÔÓÖ¾“c't Mag
azine”£¬Michael KunzeÔÚ1990Äê×îÏÈ°ÑÕâЩÏîÄ¿×éºÏÔÚÒ»Æð´´ÔìÁËLAMPµÄËõд×Ö¡£ÕâЩ×é¼þËäÈ»²¢²»ÊÇ¿ª¿ªÊ¼¾ÍÉè¼ÆΪһÆðʹÓõģ¬µ«ÊÇ£¬ÕâЩ¿ªÔ´Èí¼þ¶¼¿ÉÒԺܷ½±ãµÄËæʱ»ñµÃ²¢Ãâ·Ñ»ñµÃ¡£Õâ¾Íµ¼ÖÂÁËÕâЩ×é¼þ¾³£ÔÚÒ»ÆðʹÓá£ÔÚ¹ýÈ¥µÄ¼¸ÄêÀÕâЩ×é¼þµÄ¼æÈÝÐÔ²»¶ÏÍêÉÆ£¬ÔÚÒ»ÆðµÄÓ¦ÓÃÇéÐαäµÃ·Ç³£Æձ㡣ΪÁ˸ÄÉƲ»Í¬×é¼þÖ®¼äµÄÐ×÷£¬ÒѾ´´½¨ÁËijЩÀ©Õ¹¹¦ÄÜ¡£Ä¿Ç°£¬¼¸ºõÔÚËùÓеÄLinux·¢²¼°æÖж¼Ä¬ÈÏ°üº¬ÁË“LAMP stack”µÄ²úÆ·¡£ÕâЩ²úÆ·×é³ÉÁËÒ»¸öÇ¿´óµÄWebÓ¦ÓóÌÐòƽ̨¡£“LAMP stack”ÖеÄÿһ¸ö×é¼þ¶¼ÊÇÒ»¸öFOSS(Ãâ·Ñ»òÕß¿ªÔ´Èí¼þ/Free or Open Source Software)µÄʵÀý¡£FOSS·½·¨µÄºÃ´¦ÓÐÈý¸ö·½Ãæ¡£µÚÒ»£¬FOSSÈí¼þµÄÐÔÖÊÒâζ×ÅÓ¦ÓóÌÐò¿ÉÒÔÃâ·ÑÏÂÔØ£¬Äܹ»Èøü¹ã·ºµÄÈËÃDz»Óø¶·Ñ¾Í¿ÉÒÔʹÓÃÕâ¸öÓ¦ÓÃÈí¼þ¡£ÕâÖÖÃâ·ÑµÄ·½Ê½¶ÔÓÚ¹ã´óÓû§Ìرð¾ßÓÐÎüÒýÁ¦¡£ÕâЩÓû§Èç¹û²»Ê¹ÓÃÃâ·ÑµÄÈí¼þ¾ÍÐèÒª¸¶·Ñ¹ºÂò“רҵ”µÄÉÌÓÃÈí¼þ¹¤¾ß¡£ÕâÔÚÖÆ×÷ÍøÕ¾·½Ãæͨ³£Ê ......
ÕâƪÎÄÕ½éÉÜÈçºÎÅäÖÃIISÒÔÖ§³ÖÔÚͬһ̨·þÎñÆ÷µÄ¶à¸ö°æ±¾µÄPHP¡£ÕâÔÚÐèÒª²âÊÔ²»Í¬PHP°æ±¾Ó¦ÓóÌÐòµÄ¿ª·¢»·¾³Öа²×°ÊǷdz£ÓÐÓõġ£´ËÍ⣬Ëü¾³£±»ÓÃÔÚÉú²ú»·¾³ÖУ¬Ðí¶àPHPÓ¦ÓóÌÐòפÁôÔÚͬһ̨·þÎñÆ÷ÉÏ£¬ÆäÖÐһЩÒÀÀµÓÚij¸öÌض¨µÄPHP°æ±¾¡£
ΪÁËÔÚͬһIIS·þÎñÆ÷ÉÏͬʱ°²×°¶à¸ö°æ±¾µÄPHP£¬±ØÐë°´ÕÕphp.netÎĵµIIS 5.1ºÍIIS 6.0¼°IIS 7.0ºÍ¸ü¸ß°æ±¾ÖÐÃèÊöµÄ²½ÖèÊÖ¶¯°²×°¡£²»ÒªÊ¹ÓÃPHPµÄWindows°²×°³ÌÐò£¬ÒòΪËü²»Ö§³Ö²¢Ðа²×°¡£
ÔÚÌض¨µÄPHP°æ±¾°´ÕÕ˵Ã÷°²×°Íê³Éºó£¬ÏÂÔØÁíÒ»¸ö°æ±¾µÄPHP£¬ÌáÈ¡µ½Ò»¸öµ¥¶ÀµÄĿ¼£¬²¢¸ù¾ÝÊÖ¹¤°²×°²½ÖèÀ´¶ÔËü½øÐÐÅäÖá£ÔÚ´ËÖ®ºó°´ÒÔÏÂ˵Ã÷ÅäÖÃÿһ¸öIIS·þÎñÆ÷£º
· IIS 5.1
· IIS 6.0
· IIS 7.0ºÍ¸ü¸ß°æ±¾
×¢Ò⣺£ºÔÚÏÂÃæÁ½¸öPHP°æ±¾ÖеÄËùÓÐÀý×ÓÊÇ°²×°ÔÚͬһ̨·þÎñÆ÷ÉÏ¡£PHPµÄ5.2.11ÎļþλÓÚC£º\ PHP5211 \Ŀ¼ºÍPHP 5.3.1ÎļþλÓÚC£º\ PHP531 \Ŀ¼¡£
IIS 5.1ÖÐ
FastCGIÀ©Õ¹°ü¿ÉÅäÖõ½Í¬Ò»Ì¨·þÎñÆ÷ºÍÍøÕ¾¼¶±ð¡£ÒòΪ5.1ÖÐÖ»ÄÜÓÐÒ»¸öÍøÕ¾£¬Ëü²»ÊÇ¿ÉÒÔÅäÖÃËüÓÐÁ½¸ö°æ ......