Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

ÖØȼÄãµÄPHP°²È«Ö®»ð

¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾­³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°
£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒÃÇÒªµÄ²»ÊÇÓã¶øÊÇÓæ¡£ÔÚ¹úÄÚ£¬¸÷ÖÖ¸÷ÑùµÄphp
³ÌÐò1.0°æ£¬2.0°æÏñÓêºó´ºËñÒ»ÑùµÄð³öÀ´£¬¿ÉÊÇ£¬´ó¼Ò¹Ø×¢µÄ¶¼ÊÇһЩÖøÃûµÄcms£¬ÂÛ̳£¬blog³ÌÐò£¬ºÜÉÙµÄÈËÔÚ¶ÔÄÇЩ²»³öÃûµÄ³ÌÐò×ö°²È«¼ì²â£¬¶ÔÓÚÔ½À´Ô½¶àµÄphp³ÌÐòÔ±ºÍÕ¾³¤À´Ëµ£¬³ýÁËÒÀ¿¿·þÎñÆ÷
µÄ±¤ÀÝÉèÖÃÍ⣬php³ÌÐò±¾ÉíµÄ°²È«¶àÉÙÄã×ܵö®µã°É¡£
¡¡
¡¡ÓÐÈË˵ÄãÃÇ×öphp°²È«Î޷ǾÍÊǸã¸ã×¢ÈëºÍ¿çվʲôʲôµÄ£¬´ó´íÌØ´í£¬Èç¹ûÕâÑùµÄ»°£¬Ò»¸ömagic_quotes_gpc»òÕß·þÎñÆ÷ÀïµÄһЩ°²È«ÉèÖÃ
¾ÍÈÃÎÒÃÇȫû»î·ÁË£º(¡£ÎÒ½ñÌìҪ˵µÄ²»ÊÇ×¢È룬²»ÊÇ¿çÕ¾£¬¶øÊÇ´æÔÚÓÚphp³ÌÐòÖеÄһЩ°²È«Ï¸½ÚÎÊÌâ¡£OK!ÇÐÈëÕýÌâ¡£
¡¡¡¡×¢ÒâһЩº¯Êý
µÄ
¹ýÂËÓÐЩº¯ÊýÔÚ³ÌÐòÖÐÊǾ­³£Ê¹Óõģ¬Ïñ
include()£¬require()£¬fopen()£¬fwrite()£¬readfile()£¬unlink()£¬eval()ÒÔ¼°ËüÃǵıäÌ庯Êý
µÈµÈ¡£ÕâЩº¯Êý¶¼ºÜʵÓã¬ÊµÓò¢²»´ú±íÈÃÄã¶àÊ¡ÐÄ£¬Ä㻹µÃΪËüÃǶà·ÑµãÐÄ¡£ £º)
¡¡¡¡1.include()£¬require()ºÍ
fopen()£¬include_once()£¬require_once()ÕâЩ¶¼¿ÉÒÔÔ¶³Ìµ÷ÓÃÎļþ£¬¶ÔÓÚËüÃǵÄΣº¦£¬googleËÑÒ»ÏÂÄã¾Í»áºÜÃ÷
ÁË£¬¶ÔÓÚËù°üº¬µ÷ÓõıäÁ¿Ã»¹ýÂ˺㬾ͿÉÒÔÈÎÒâ°üº¬Îļþ´Ó¶øÈ¥Ö´ÐС£¾Ù¸öÀý×Ó£¬¿´print.php……
¡¡¡¡if (empty ($bn) ) { //¼ì²éÊDZäÁ¿$bnÊÇ·ñΪ¿Õinclude ("$cfg_dir/site_${site}.php"); //°Ñ$cfg_dirÕâ¸ö·¾¶ÀïµÄsite_${site}.php°üº¬½øÀ´……
¡¡
¡¡²»¹Ü´æ²»´æÔÚ$cfg_dirĿ¼£¬$siteÕâ¸ö±äÁ¿Äã¿ÉÒÔºÜ×ÔÈ»µÄȥʹÓã¬ÒòΪËû¸ù±¾Ã»¼ì²é$site±äÁ¿°¡¡£¿ÉÒ԰ѱäÁ¿$siteÖ¸¶¨Ô¶³ÌÎļþÈ¥
µ÷Óã¬Ò²¿ÉÒÔÊDZ¾µØµÄÒ»¸öÎļþ£¬ÄãËùÖ¸¶¨µÄÎļþÀïдÉÏphpµÄÓï¾ä£¬È»ºóËü¾ÍÈ¥°üº¬Ö´ÐÐÕâ¸öº¬ÓÐphpÓï¾äµÄÎļþÁË¡£¾ÍÏñÕâÑùÁгöÎļþĿ¼ÉõÖÁ¿ÉÒÔÀ©Õ¹µ½
°üº¬Ò»Ð©¹ÜÀíÔ±Îļþ£¬ÌáÉýȨÏÞ£¬µäÐ͵ÄÏñÒÔÇ°phpwind£¬bo-blogµÄ©¶´Ò»Ñù¡£³ýÁËÒÀ¿¿php.iniÀïµÄallow_url_fopenÉèΪ
off½ûÖ¹Ô¶³ÌʹÓÃÎļþºÍopen_base_dir½ûֹʹÓÃĿ¼ÒÔÍâµÄÎļþÍ⣬Ä㻹µÃÊÂÏÈÉùÃ÷ºÃÖ»ÄÜ°üº¬ÄÄЩÎļþ£¬ÕâÀï¾Í²»¶à˵·Ï»°ÁË¡£
¡¡¡¡2.fopen()£¬file()£¬readfile()£¬openfile()£¬µÈÒ²ÊǸÃÌرðÁôÒâµÄµØ·½


Ïà¹ØÎĵµ£º

PHP header() º¯Êý


¶¨ÒåºÍÓ÷¨
header() º¯ÊýÏò¿Í»§¶Ë·¢ËÍԭʼµÄ HTTP ±¨Í·¡£
ÈÏʶµ½Ò»µãºÜÖØÒª£¬¼´±ØÐëÔÚÈκÎʵ¼ÊµÄÊä³ö±»·¢ËÍ֮ǰµ÷Óà header() º¯Êý£¨ÔÚ PHP 4 ÒÔ¼°¸ü¸ßµÄ°æ±¾ÖУ¬Äú¿ÉÒÔʹÓÃÊä³ö»º´æÀ´½â¾ö´ËÎÊÌ⣩£º
<html>
<?php
// ½á¹û³ö´í
// ÔÚµ÷Óà header() ֮ǰÒÑ´æÔÚÊä³ö
header('Location: http://www.example ......

PHP´úÂë¹æ·¶

1. ½éÉÜ
1.1. ±ê×¼»¯µÄÖØÒª**
±ê×¼»¯ÎÊÌâÔÚijЩ·½ÃæÉÏÈÃÿ¸öÈËÍ·Í´£¬ÈÃÈËÈ˶¼¾õµÃ´ó¼Ò´¦ÓÚͬÑùµÄ¾³µØ¡£ÕâÓÐÖúÓÚÈÃÕâЩ½¨ÒéÔÚÐí¶àµÄÏîÄ¿Ö⻶ÏÑݽø£¬Ðí¶à¹«Ë¾»¨·ÑÁËÐí¶àÐÇÆÚÖð×Ó×ÖÖð¾äµÄ½øÐÐÕùÂÛ¡£±ê×¼»¯²»ÊÇÌØÊâµÄ¸öÈË·ç¸ñ£¬Ëü¶Ô±¾µØ¸ÄÁ¼ÊÇÍêÈ«¿ª·ÅµÄ¡£
1.2. Óŵã
µ±Ò»¸öÏîÄ¿³¢ÊÔ×Å×ñÊع«Óõıê׼ʱ£¬»áÓÐÒÔϺô¦£ ......

php ͼƬÉÏ´«Àà´úÂë

<?
//http://www.jb51.net
class upLoad{
public $length; //ÏÞ¶¨Îļþ´óС
public $file; //ÅжϴËÀàÊÇÓÃÓÚͼƬÉÏ´«»¹ÊÇÎļþÉÏ´«
public $fileName; //ÎļþÃû
public $fileTemp; //ÉÏ´«ÁÙʱÎļþ
public $fileSize; //ÉÏ´«Îļþ´óС
public $error; //ÉÏ´«ÎļþÊÇ·ñÓдí,php4ûÓÐ
public $fileType; //ÉÏ ......

PHP MVC¡¢Ä£°åÒýÇ漰ȨÏÞÉè¼Æ

±¾ÎÄת×Ô"PHP°®ºÃÕß"£ºhttp://www.phpfans.org/?cat=1
Ò»°ãÓõ½“ÒýÇæ”Á½×Ö¶¼»á¸Ð¾õ±È½Ï¸ß¼¶£¬"Ä£°åÒýÇæ"ÕâËĸö×ÖÌýÆðÀ´ºÜ¸ßÉîµÄÑù×Ó£¬ÀàËÆÓÎÏ·3DÒýÇæ¡¢ZendÒýÇæµÈ£¬Æäʵ¶¼ÊÇ»£È˵ģ¬Æ­ÍâÐÐÈ˵ġ£ËùÒÔÔÚÎÒ³õѧPHPµÄÄǻᣬҲÒòΪÕâËĸö×Öµ¼ÖÂÁËÎÒ¾õµÃºÜÄѶøûÓÐÈ¥¿´Ëûµ½µ×ÊÇʲôÑùÒ»¸ö¶«Î÷£¬Ö±µ½ºÜ³¤Ê±¼äÒÔºóÊ¹Ó ......

PHPºÍJAVA¿ª·¢µÄOAÐÔÄܱȽÏ

ÏÖÔÚ»¹ÓкܶàÈ˸㲻¶®PHPºÍJAVA¿ª·¢µÄЭͬOAµ½µ×ÓÐʲô²»Í¬£¬¶Ô×Ô¼ºµ½µ×ÓÐʲôӰÏ죬ÒÔÖÁÓÚ×ö³öÁË´íÎóµÄÑ¡Ôñ¶øêݺ¦ÎÞÇî¡£±ÊÕ߸ù¾ÝÁ½ÖÖ¼¼ÊõµÄÌصãÖØÐÂÕûÀíÁËÒ»¸ö¶Ô±È£¬¸ø¹ØÐÄЭͬOA¼¼ÊõµÄ¶ÁÕß×ö¸ö²Î¿¼¡£
         »ªÌ춯Á¦Ð­Í¬OAÊDzÉÓÃJAVA¼¼ÊõµÄµäÐÍ´ú±í£¬²¢¾ßÓÐһϵÁÐÓÅ»¯É ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ