PHP ³£·¸µÄ 10 ¸ö´íÎó £¨×ªÔØ£©
PHPÊǸöΰ´óµÄweb¿ª·¢ÓïÑÔ£¬Áé»îµÄÓïÑÔ£¬µ«ÊÇ¿´µ½php³ÌÐòÔ±Öܶø¸´Ê¼µÄ·¸µÄһЩ´íÎó¡£ÎÒ×öÁËÏÂÃæÕâ¸öÁÐ±í£¬ÁгöÁËPHP³ÌÐòÔ±¾³£·¸µÄ10ÖдíÎ󣬴ó¶àÊýºÍ°²È«Ïà¹Ø¡£¿´¿´Äã·¸Á˼¸ÖÖ
1.²»×ªÒâhtml entities
Ò»¸ö»ù±¾µÄ³£Ê¶£ºËùÓв»¿ÉÐÅÈεÄÊäÈë£¨ÌØ±ðÊÇÓû§´ÓformÖÐÌá½»µÄÊý¾Ý£© £¬Êä³ö֮ǰ¶¼Òª×ªÒâ¡£
echo $_GET['usename'] ;
Õâ¸öÀý×ÓÓпÉÄÜÊä³ö£º
<script>/*¸ü¸ÄadminÃÜÂëµÄ½Å±¾»òÉèÖÃcookieµÄ½Å±¾*/</script>
ÕâÊÇÒ»¸öÃ÷ÏԵݲȫÒþ»¼£¬³ý·ÇÄã±£Ö¤ÄãµÄÓû§¶¼ÕýÈ·µÄÊäÈë¡£
ÈçºÎÐÞ¸´ £º
ÎÒÃÇÐèÒª½«"< ",">","and" µÈת»»³ÉÕýÈ·µÄHTML±íʾ(< , >', and ")£¬º¯Êýhtmlspecialchars ºÍ htmlentities()ÕýÊǸÉÕâ¸ö»îµÄ¡£
ÕýÈ·µÄ·½·¨£º
echo htmlspecialchars($_GET['username'], ENT_QUOTES);
2. ²»×ªÒâSQLÊäÈë
ÎÒ
Ôø¾ÔÚһƪÎÄÕÂÖÐ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÌÖÂÛ¹ýÕâ¸öÎÊÌâ²¢¸ø³öÁËÒ»¸ö¼òµ¥µÄ·½·¨
¡£ÓÐÈ˶ÔÎÒ˵£¬ËûÃÇÒѾÔÚphp.iniÖн«magic_quotesÉèÖÃΪOn£¬ËùÒÔ²»±Øµ£ÐÄÕâ¸öÎÊÌ⣬µ«ÊDz»ÊÇËùÓеÄÊäÈë¶¼ÊÇ´Ó$_GET,
$_POST»ò $_COOKIEÖеĵõ½µÄ£¡
ÈçºÎÐÞ¸´£º
ºÍÔÚ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÖÐÒ»ÑùÎÒ»¹ÊÇÍÆ¼öʹÓÃmysql_real_escape_string()º¯Êý
ÕýÈ·×ö·¨£º
<?php
$sql = "UPDATE users SET
name='.mysql_real_escape_string($name).'
WHERE id='.mysql_real_escape_string ($id).'";
mysql_query($sql);
?>
3.´íÎóµÄʹÓÃHTTP-header Ïà¹ØµÄº¯Êý: header(), session_start(), setcookie()
Óöµ½¹ýÕâ¸ö¾¯¸æÂð?"warning: Cannot add header information - headers already sent [....]
ÿ´Î´Ó·þÎñÆ÷ÏÂÔØÒ»¸öÍøÒ³µÄʱºò£¬·þÎñÆ÷µÄÊä³ö¶¼·Ö³ÉÁ½¸ö²¿·Ö£ºÍ·²¿ºÍÕýÎÄ¡£
Í·²¿°üº¬ÁËһЩ·Ç¿ÉÊÓµÄÊý¾Ý£¬ÀýÈçcookie¡£Í·²¿×ÜÊÇÏȵ½´ï¡£ÕýÎIJ¿·Ö°üÀ¨¿ÉÊÓµÄhtml£¬Í¼Æ¬µÈÊý¾Ý¡£
Èç
¹ûoutput_bufferingÉèÖÃΪOff£¬ËùÓеÄHTTP-headerÏà¹ØµÄº¯Êý±ØÐëÔÚÓÐÊä³ö֮ǰµ÷Óá£ÎÊÌâÔÚÓÚÄãÔÚÒ»¸ö»·¾³Öпª·¢£¬¶øÔÚ²¿Êð
µ½ÁíÒ»¸ö»·¾³ÖÐÈ¥µÄʱºò£¬output_bufferingµÄÉèÖÿÉÄܲ»Ò»Ñù¡£½á¹ûתÏòÍ£Ö¹ÁË£¬cookieºÍsession¶¼Ã»ÓÐÕýÈ·µÄÉè
ÖÃ........¡£
ÈçºÎÐÞ¸´:
È·±£ÔÚÊä³ö֮ǰµ÷ÓÃhttp-headerÏà¹ØµÄº¯Êý£¬²¢ÇÒÁîoutput_buffering = Off
¡£
4. Require »ò include µÄÎļþʹÓò»°²È«µÄÊý¾Ý
ÔÙ´ÎÇ¿µ÷£º²»ÒªÏàÐŲ»ÊÇÄã×Ô¼ºÏÔʽÉ
Ïà¹ØÎĵµ£º
<?php
if(empty($_GET[submit]))
{
?>
<form enctype="multipart/form-data" action="<?php $_SERVER['PHP_SELF']?>?submit=1" method="post">
<input name="filename" type="file">
<input type="submit" value="È·¶¨ÉÏ´«">
</form>
<?php
}
else{
......
ǰһ¶Îʱ¼äÔÚ¹«Ë¾×öÒ»¸öphpµÄÏîÄ¿£¬×îºó½«ÏîÄ¿°²×°ÔÚ¿Í»§µÄ¸öÈ˵çÄÔÉϵÄʱºòºÜ¶àÒ³Ãæ±äÐÎÁË£¬ÕÒÁ˺ܾö¼Ã»Óз¢ÏÖÊÇʲôÎÊÌ⣬¸ãµÃÎÒºÜÓôÃÆ¡£µÚ¶þÌìÓÃzend studio ´ò¿ªÏîÄ¿µÄÅäÖÃÎļþʱ·¢ÏÖÔÚÎļþµÄ¿ªÊ¼µÄµØ·½³öÏÖÁËÒ»¸öµãµã£¬¶øÇÒÓÃÆäËûµÄ±à¼¹¤¾ß¿´²»µ½Õâ¸öµãµã¡£ÎÒÔÚzendÏÂÃæ°ÑÄǸö ......
·¢²¼Ê±¼ä:2009-11-17 11:15 ¡¡×÷Õß: PHPChina ¡¡ÐÅÏ¢À´Ô´: PHPchina¡¡ ·¢±íÆÀÂÛ
1.Èç¹ûÒ»¸ö·½·¨Äܱ»¾²Ì¬£¬ÄǾÍÉùÃ÷ËûΪ¾²Ì¬µÄ£¬ËÙ¶È¿ÉÌá¸ß1/4;
2.echoµÄЧÂʸßÓÚprint,ÒòΪechoûÓзµ»ØÖµ£¬print·µ»ØÒ»¸öÕûÐÍ;
3.ÔÚÑ»·Ö®Ç°ÉèÖÃÑ»·µÄ×î´ó´ÎÊý£¬¶ø·ÇÔÚÔÚÑ»·ÖÐ;
4.Ïú»Ù±äÁ¿È¥ÊÍ·ÅÄÚ´æ£¬ÌØ±ðÊÇ´óµÄÊý×é;
5.±ÜÃâÊ ......
ÎÒÊÇѧµç×ÓÉÌÎñµÄѧÉú£¬Ö÷Ҫѧϰ·½ÏòÊǵç×ÓÉÌÎñ¼¼Êõ²ãÃæµÄ¶«Î÷¡£Ñ§ÁËÒ»Äê¶àµÄʱ¼äÁË£¬¸Ð¾õСÓÐÊÕ»ñ¡£
ǰ¶Îʱ¼ä³öÈ¥ÃæÊÔflashµÄʱºò·¢ÏÖ×Ô¼ººÍ±ðÈ˵ÄÒªÇó²î¾àÉõÔ¶£¬»Øµ½Ñ§Ð£ºóŬÁ¦µÄѧϰPHP£¬×ÔÎҸоõ»¹²»´í£¬È«°àֻʣϼ¸¸öÈËÔÚѧºǫ́ÓïÑÔÁË£¬²»ÖªµÀÊÇÒòΪÓÐÁËÉÏÒ»´ÎµÄ´ò»÷»¹ÊÇÒòΪÎÒÊʺÏѧPHP£¬×ÔÈÏΪѧµÃ±È½Ï¿ì£¬ÖÁÉÙ±ÈÖ ......
ÔÎÄÄÚÈÝ
£º
ͻ񻣼
½ÏÔçµÄʱºò£¬ÓиöÅóÓѼ«Á¦ÍƼöÎÒÈ¥¿´¿´Ò»¿îPHPÎʾíµ÷²éϵͳ¡£ÎÒËäÈ»´ÓÊÂÈí¼þÁìÓòµÄʱ¼ä
²¢²»Ì«³¤£¬µ«Ò²ÖªµÀ¹úÄÚÔÚÕâ¸öÁìÓòÑо¿ºÍ´ÓÊÂµÄÆóÒµºÍ¸öÈ˲¢²»ÉÙ£¬Ö®Ç°Ò²¹Ø×¢¹ýºÍÆÀ¹À¹ýһЩ²úÆ·»òϵͳ£¬×ÜÌåÉÏ¿´À´£¬´ó¶àÊý²úÆ·µÄÉÌÒµ»¯³Ì¶È²»¸ß£¬ÖÊÁ¿²Î
²î²»Æë£¬Àë³ÉÊìµÄÈí¼þϵͳ»¹ÓÐÏ൱һ¸ö¾àÀë¡ ......