PHP³ÌÐò61ÌõÃæÏò¶ÔÏó·ÖÎöÉè¼ÆµÄ¾ÑéÔÔò (ת)
Äã²»±ØÑϸñ×ñÊØÕâЩÔÔò£¬Î¥±³ËüÃÇÒ²²»»á±»´¦ÒÔ×Ú½ÌÐÌ·£¡£µ«ÄãÓ¦µ±°ÑÕâЩÔÔò¿´³É¾¯Á壬ÈôÎ¥±³ÁËÆäÖеÄÒ»Ìõ£¬ÄÇô¾¯Áå¾Í»áÏìÆð ¡£ ----- Arthur J.Riel
(1)ËùÓÐÊý¾Ý¶¼Ó¦¸ÃÒþ²ØÔÚËùÔÚµÄÀàµÄÄÚ²¿¡£
(2)ÀàµÄʹÓÃÕß±ØÐëÒÀÀµÀàµÄ¹²Óнӿڣ¬µ«À಻ÄÜÒÀÀµËüµÄʹÓÃÕß¡£
(3)¾¡Á¿¼õÉÙÀàµÄÐÒéÖеÄÏûÏ¢¡£
(4)ʵÏÖËùÓÐÀ඼Àí½âµÄ×î»ù±¾¹«ÓнӿÚ[ÀýÈ磬¿½±´²Ù×÷(É±´ºÍdz¿½±´)¡¢ÏàµÈÐÔÅжϡ¢ÕýÈ·Êä³öÄÚÈÝ¡¢´ÓASCIIÃèÊö½âÎöµÈµÈ]¡£
(5)²»Òª°ÑʵÏÖϸ½Ú(ÀýÈç·ÅÖù²ÓôúÂëµÄ˽Óк¯Êý)·Åµ½ÀàµÄ¹«ÓнӿÚÖС£
Èç¹ûÀàµÄÁ½¸ö·½·¨ÓÐÒ»¶Î¹«¹²´úÂ룬ÄÇô¾Í¿ÉÒÔ´´½¨Ò»¸ö·ÀÖ¹ÕâЩ¹«¹²´úÂëµÄ˽Óк¯Êý¡£
(6)²»ÒªÒÔÓû§ÎÞ·¨Ê¹Óûò²»¸ÐÐËȤµÄ¶«Î÷ÈÅÂÒÀàµÄ¹«Óнӿڡ£
(7)ÀàÖ®¼äÓ¦¸ÃÁãñîºÏ£¬»òÕßÖ»Óе¼³öñîºÏ¹Øϵ¡£Ò²¼´£¬Ò»¸öÀàҪôͬÁíÒ»¸öÀàºÁÎÞ¹Øϵ£¬ÒªÃ´Ö»Ê¹ÓÃÁíÒ»¸öÀàµÄ¹«ÓнӿÚÖеIJÙ×÷¡£
(8)ÀàÓ¦¸ÃÖ»±íʾһ¸ö¹Ø¼ü³éÏó¡£
°üÖеÄËùÓÐÀà¶ÔÓÚͬһÀàÐÔÖʵı仯Ӧ¸ÃÊǹ²Í¬·â±ÕµÄ¡£Ò»¸ö±ä»¯Èô¶ÔÒ»¸ö°üÓ°Ï죬Ôò½«¶Ô°üÖеÄËùÓÐÀà²úÉúÓ°Ï죬¶ø¶ÔÆäËûµÄ°ü²»¡¡¡¡Ôì³ÉÈκÎÓ°Ïì .
(9)°ÑÏà¹ØµÄÊý¾ÝºÍÐÐΪ¼¯ÖзÅÖá£
Éè¼ÆÕßÓ¦µ±ÁôÒâÄÇЩͨ¹ýgetÖ®Àà²Ù×÷´Ó±ðµÄ¶ÔÏóÖлñÈ¡Êý¾ÝµÄ¶ÔÏó¡£ÕâÖÖÀàÐ͵ÄÐÐΪ°µÊ¾×ÅÕâÌõ¾ÑéÔÔò±»Î¥·´ÁË¡£
(10)°Ñ²»Ïà¹ØµÄÐÅÏ¢·ÅÔÚÁíÒ»¸öÀàÖÐ(Ò²¼´£º»¥²»¹µÍ¨µÄÐÐΪ)¡£
³¯×ÅÎȶ¨µÄ·½Ïò½øÐÐÒÀÀµ.
(11)È·±£ÄãΪ֮½¨Ä£µÄ³éÏó¸ÅÄîÊÇÀ࣬¶ø²»Ö»ÊǶÔÏó°çÑݵĽÇÉ«¡£
(12)ÔÚˮƽ·½ÏòÉϾ¡¿ÉÄÜͳһµØ·Ö²¼ÏµÍ³¹¦ÄÜ£¬Ò²¼´£º°´ÕÕÉè¼Æ£¬¶¥²ãÀàÓ¦µ±Í³Ò»µØ¹²Ïí¹¤×÷¡£
(13)ÔÚÄãµÄϵͳÖв»Òª´´½¨È«ÄÜÀà/¶ÔÏ󡣶ÔÃû×Ö°üº¬Driver¡¢Manager¡¢System¡¢SusystemµÄÀàÒªÌرð¶à¼ÓСÐÄ¡£
¹æ»®Ò»¸ö½Ó¿Ú¶ø²»ÊÇʵÏÖÒ»¸ö½Ó¿Ú¡£
(14)¶Ô¹«¹²½Ó¿ÚÖж¨ÒåÁË´óÁ¿·ÃÎÊ·½·¨µÄÀà¶à¼ÓСÐÄ¡£´óÁ¿·ÃÎÊ·½·¨Òâζ×ÅÏà¹ØÊý¾ÝºÍÐÐΪûÓм¯Öдæ·Å¡£
(15)¶Ô°üº¬Ì«¶à»¥²»¹µÍ¨µÄÐÐΪµÄÀà¶à¼ÓСÐÄ¡£
Õâ¸öÎÊÌâµÄÁíÒ»±íÏÖÊÇÔÚÄãµÄÓ¦ÓóÌÐòÖеÄÀàµÄ¹«ÓнӿÚÖд´½¨Á˺ܶàµÄgetºÍsetº¯Êý¡£
(16)ÔÚÓÉͬÓû§½çÃæ½»»¥µÄÃæÏò¶ÔÏóÄ£Ð͹¹³ÉµÄÓ¦ÓóÌÐòÖУ¬Ä£ÐͲ»Ó¦¸ÃÒÀÀµÓÚ½çÃ棬½çÃæÔòÓ¦µ±ÒÀÀµÓÚÄ£ÐÍ¡£
(17)¾¡¿ÉÄܵذ´ÕÕÏÖʵÊÀ½ç½¨Ä£(ÎÒÃdz£³£ÎªÁË×ñÊØϵͳ¹¦ÄÜ·Ö²¼ÔÔò¡¢±ÜÃâÈ«ÄÜÀàÔÔòÒÔ¼°¼¯ÖзÅÖÃÏà¹ØÊý¾ÝºÍÐÐ
Ïà¹ØÎĵµ£º
ËùÐèÈí¼þ£¨×¢Òâ°æ±¾£¡£©£º
Apache2.2.3
PHP5.1.5
MySQL5.0.24
ÕâÈý¸öÈí¼þ¶¼ÊÇÃâ·ÑµÄ£¬¿É´Ó¹ÙÍøÉÏÏÂÔØ£¬Ä¿Ç°ÎÒËùÓеÄÈí¼þÃûΪ£º
apache_2.2.3-win32-x86-no_ssl.msi
mysql-5.0.24-win32.zip
php-5.1.5-Win32.zip
»ùÓÚwindows²Ù×÷ϵͳ£¬ÔÚWindows XPÏ°²×°Ê¹Óãº
1¡¢°²×°¹ý³Ì£º
Ê×ÏÈ°²×°Apache·þÎñÆ÷£¬Ë«»÷apa ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°
£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......
PHPÅúÁ¿È¡µÃcheckboxµÄÖµ
1¡¢ÃüÃû
<input type='checkbox' name='checkbox[]' value=$dwmyrow[banzhu] />
2¡¢Ê¹ÓÃ
µ±¼Æ»®µ±×÷sqlÖ¸ÁîµÄÒ»²¿·Öʱ£ºÈç¹û²ÎÓë¿ØÖƵÄ×Ö¶ÎÊÇÊýÖµÐ͵ģ¬Ôò
if(! empty($_POST['checkbox'])) {
$expr = join(",", $_POST['checkbox']);
$sql = "select * from tbl_name where field in ......
PHP4:
<?
$sample1 = new StdClass();
$sample1->name = "Hasin";
$sample2 = $sample1;
$sample2->name = "Afif";
echo $sample1->name;
?>
In PHP4 it works differently; it will output Hasin, as both are different from
each other.
PHP5:
<?
$sample1 = new StdClass();
$ ......