Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP³ÌÐòÔ±×îÒ×·¸10ÖÖ´íÎó

PHPÊǸöΰ´óµÄweb¿ª·¢ÓïÑÔ£¬Áé»îµÄÓïÑÔ£¬µ«ÊÇ¿´µ½php³ÌÐòÔ±Öܶø¸´Ê¼µÄ·¸µÄһЩ´íÎó¡£ÎÒ×öÁËÏÂÃæÕâ¸öÁÐ±í£¬ÁгöÁËPHP³ÌÐòÔ±¾­³£·¸µÄ10ÖдíÎ󣬴ó¶àÊýºÍ°²È«Ïà¹Ø¡£¿´¿´Äã·¸Á˼¸ÖÖ
1.²»×ªÒâhtml entities
   Ò»¸ö»ù±¾µÄ³£Ê¶£ºËùÓв»¿ÉÐÅÈεÄÊäÈ루ÌرðÊÇÓû§´ÓformÖÐÌá½»µÄÊý¾Ý£© £¬Êä³ö֮ǰ¶¼Òª×ªÒâ¡£
echo $_GET['usename'] ;
Õâ¸öÀý×ÓÓпÉÄÜÊä³ö£º
<script>/*¸ü¸ÄadminÃÜÂëµÄ½Å±¾»òÉèÖÃcookieµÄ½Å±¾*/</script>
ÕâÊÇÒ»¸öÃ÷ÏԵݲȫÒþ»¼£¬³ý·ÇÄã±£Ö¤ÄãµÄÓû§¶¼ÕýÈ·µÄÊäÈë¡£
ÈçºÎÐÞ¸´ £º
ÎÒÃÇÐèÒª½«"< ",">","and" µÈת»»³ÉÕýÈ·µÄHTML±íʾ(< , >', and ")£¬º¯Êýhtmlspecialchars ºÍ htmlentities()ÕýÊǸÉÕâ¸ö»îµÄ¡£
ÕýÈ·µÄ·½·¨£º
echo htmlspecialchars($_GET['username'], ENT_QUOTES);
2. ²»×ªÒâSQLÊäÈë
ÎÒÔø¾­ÔÚһƪÎÄÕÂÖÐ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÌÖÂÛ¹ýÕâ¸öÎÊÌâ²¢¸ø³öÁËÒ»¸ö¼òµ¥µÄ·½·¨ ¡£ÓÐÈ˶ÔÎÒ˵£¬ËûÃÇÒѾ­ÔÚphp.iniÖн«magic_quotesÉèÖÃΪOn£¬ËùÒÔ²»±Øµ£ÐÄÕâ¸öÎÊÌ⣬µ«ÊDz»ÊÇËùÓеÄÊäÈ붼ÊÇ´Ó$_GET, $_POST»ò $_COOKIEÖеĵõ½µÄ£¡
ÈçºÎÐÞ¸´£º
ºÍÔÚ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÖÐÒ»ÑùÎÒ»¹ÊÇÍƼöʹÓÃmysql_real_escape_string()º¯Êý
ÕýÈ·×ö·¨£º
<?php
$sql = "UPDATE users SET
name='.mysql_real_escape_string($name).'
WHERE id='.mysql_real_escape_string ($id).'";
mysql_query($sql);
?>
3.´íÎóµÄʹÓÃHTTP-header Ïà¹ØµÄº¯Êý: header(), session_start(), setcookie()
Óöµ½¹ýÕâ¸ö¾¯¸æÂð?"warning: Cannot add header information - headers already sent [....]
ÿ´Î´Ó·þÎñÆ÷ÏÂÔØÒ»¸öÍøÒ³µÄʱºò£¬·þÎñÆ÷µÄÊä³ö¶¼·Ö³ÉÁ½¸ö²¿·Ö£ºÍ·²¿ºÍÕýÎÄ¡£
Í·²¿°üº¬ÁËһЩ·Ç¿ÉÊÓµÄÊý¾Ý£¬ÀýÈçcookie¡£Í·²¿×ÜÊÇÏȵ½´ï¡£ÕýÎIJ¿·Ö°üÀ¨¿ÉÊÓµÄhtml£¬Í¼Æ¬µÈÊý¾Ý¡£
Èç¹ûoutput_bufferingÉèÖÃΪOff£¬ËùÓеÄHTTP-headerÏà¹ØµÄº¯Êý±ØÐëÔÚÓÐÊä³ö֮ǰµ÷Óá£ÎÊÌâÔÚÓÚÄãÔÚÒ»¸ö»·¾³Öпª·¢£¬¶øÔÚ²¿Êðµ½ÁíÒ»¸ö»·¾³ÖÐÈ¥µÄʱºò£¬output_bufferingµÄÉèÖÿÉÄܲ»Ò»Ñù¡£½á¹ûתÏòÍ£Ö¹ÁË£¬cookieºÍsession¶¼Ã»ÓÐÕýÈ·µÄÉèÖÃ........¡£
ÈçºÎÐÞ¸´:
È·±£ÔÚÊä³ö֮ǰµ÷ÓÃhttp-headerÏà¹ØµÄº¯Êý£¬²¢ÇÒÁîoutput_buffering = Off
¡£
4. Require »ò include µÄÎļþʹÓò»°²È«µÄÊý¾Ý
ÔÙ´ÎÇ¿µ÷£º²»ÒªÏàÐŲ»ÊÇÄã×Ô¼ºÏÔʽÉùÃ÷µÄÊý¾Ý¡£²»Òª Include »ò require ´Ó$_GET, $_POST »ò $_COOKIE Öе


Ïà¹ØÎĵµ£º

PHPÖеÄereg()Óëeregi()º¯ÊýµÄ²»Í¬


ereg()
×Ö·û´®±È¶Ô½âÎö¡£
Óï·¨: int ereg(string pattern, string string, array [regs]);
·µ»ØÖµ: ÕûÊý/Êý×é
º¯ÊýÖÖÀà: ×ÊÁÏ´¦Àí
ÄÚÈÝ˵Ã÷
±¾º¯ÊýÒÔ pattern µÄ¹æÔòÀ´½âÎö±È¶Ô×Ö·û´® string¡£±È¶Ô½á¹û·µ»ØµÄÖµ·ÅÔÚÊý×é²ÎÊý regs Ö®ÖУ¬regs[0] ÄÚÈݾÍÊÇÔ­×Ö·û´® string¡¢regs[1] ΪµÚÒ»¸öºÏºõ¹æÔòµÄ×Ö·û´®¡¢regs ......

phpͼƬÉÏ´«

 <?php
if(empty($_GET[submit]))
{
?>
<form enctype="multipart/form-data" action="<?php $_SERVER['PHP_SELF']?>?submit=1" method="post">
<input name="filename" type="file">
<input type="submit" value="È·¶¨ÉÏ´«">
</form>
<?php
}
else{
   ......

php½â¾öcheckboxÎÊÌâ

<script language="javascript" type="text/javascript">
function checkbox()
{
var str=document.getElementsByName("chk");
var objarray=str.length;
var chestr="";
for (i=0;i<objarray;i++)
{
if(str[i].checked == true)
{
chestr+="1";
} else{
chestr+="0";
}
}
document.ge ......

php½Ì³Ì

¿µÊ¢²©¿ÍÌṩԭ´´PHP½Ì³Ì£¬Èç¹ûÓÐÐËȤÇë¼ÓȺ£º6430092.Óû¼Ó´ÓËÙ£¡£¡£¡±¾À´ÔÚCSDN´´½¨²©¿ÍÊÇÏë°Ñ×Ô¼ºµÄÎÄÕÂÈøü¶àµÄÈË¿´µ½£¬Èç¹ûÄܹ»Îª´ó¼Ò´øÀ´°ïÖúÄÇÊǸüºÃ²»¹ýµÄÊÂÁË¡£±¾½Ì³ÌÖ»ÊDZ¾È˵Äѧϰ±Ê¼Ç£¬Çв»¿ÉÕæÄÃÀ´µ±php½Ì³ÌÀ´¶ÁÖ»¿É×÷Ϊ²Î¿¼£¡ºóÀ´²Å·¢ÏÖ£¬×ªÔØÎÄÕÂÕæµÄÌ«·Ñʱ¼ä£¬ËùÒÔ¾ÍתÔظöĿ¼°É£¬±¾ÎIJ»»á¸üУ¬ËùÒÔÈç¹ûÓÐ ......

PHP´¦ÀíÔÚÏßÓû§

 ×ªÌù×Ô: http://hi.baidu.com/isnono/blog/item/3c94ea11a54a0fc7a7ef3f94.html
¾­³£ÔÚCSDNµÄPHPÂÛ̳ÉÏ¿´µ½ÓÐÅóÓÑÎÊ´¦ÀíÔÚÏßÓû§µÄÎÊÌâ,ÎÒд¹ýÀàËƵĴúÂë,¾ÍÄóöÀ´Ï׳óÁË,ÓеãÀ¬»ø,»ù±¾ÉÏʵÏÖÁ˹¦ÄÜ, ͬÊÇÒ²Äܹ»À©Õ¹£¬±ÈÈçͬʱֻÔÊÐíÒ»¸öÕʺÅÔÚÏߵȡ£
/*
³ÌÐòÓÃ;£º¼ì²âÔÚÏßÓû§
³ÌÐò×÷Õߣºheiyeluren
д×÷ʱ¼ä ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ