Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

¡¾×ª¡¿¸ß¼¶PHPÓ¦ÓóÌÐò©¶´ÉóºË¼¼Êõ




×÷ÕߣºPh4nt0m Security Team
À´Ô´£ºhttp://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x03_0x06.txt
==Ph4nt0m Security Team==

Issue 0x03, Phile #0x06 of 0x07

|=---------------------------------------------------------------------------=|
|=---------------------=[ ¸ß¼¶PHPÓ¦ÓóÌÐò©¶´ÉóºË¼¼Êõ ]=---------------------=|
|=---------------------------------------------------------------------------=|
|=---------------------------------------------------------------------------=|
|=----------------------=[ By www.80vul.com ]=------------------------=|
|=------------------------=[ <www.80vul.com> ]=--------------------------=|
|=---------------------------------------------------------------------------=|
[Ŀ¼]
1. ǰÑÔ
2. ´«Í³µÄ´úÂëÉ󼯼¼Êõ
3. PHP°æ±¾ÓëÓ¦ÓôúÂëÉó¼Æ
4. ÆäËûµÄÒòËØÓëÓ¦ÓôúÂëÉó¼Æ
5. À©Õ¹ÎÒÃǵÄ×Öµä
5.1 ±äÁ¿±¾ÉíµÄkey
5.2 ±äÁ¿¸²¸Ç
5.2.1 ±éÀú³õʼ»¯±äÁ¿
5.2.2 parse_str()±äÁ¿¸²¸Ç©¶´
5.2.3 import_request_variables()±äÁ¿¸²¸Ç©¶´
5.2.4 PHP5 Globals
5.3 magic_quotes_gpcÓë´úÂ밲ȫ
5.3.1 ʲôÊÇmagic_quotes_gpc
5.3.2 ÄÄЩµØ·½Ã»ÓÐħÊõÒýºÅµÄ±£»¤
5.3.3 ±äÁ¿µÄ±àÂëÓë½âÂë
5.3.4 ¶þ´Î¹¥»÷
5.3.5 ħÊõÒýºÅ´øÀ´µÄÐµİ²È«ÎÊÌâ
5.3.6 ±äÁ¿keyÓëħÊõÒýºÅ
5.4 ´úÂë×¢Éä
5.4.1 PHPÖпÉÄܵ¼Ö´úÂë×¢ÉäµÄº¯Êý
5.4.2 ±äÁ¿º¯ÊýÓëË«ÒýºÅ
5.5 PHP×ÔÉíº¯Êý©¶´¼°È±ÏÝ
5.5.1 PHPº¯ÊýµÄÒç³ö©¶´
5.5.2 PHPº¯ÊýµÄÆäËû©¶´
5.5.3 session_destroy()ɾ³ýÎļþ©¶´
5.5.4 Ëæ»úº¯Êý
5.6 ÌØÊâ×Ö·û
5.6.1 ½Ø¶Ï
5.6.1.1 include½Ø¶Ï
5.6.1.2 Êý¾Ý½Ø¶Ï
5.6.1.3 Îļþ²Ù×÷ÀïµÄÌØÊâ×Ö·û
6. Ôõô½øÒ»²½Ñ°ÕÒеÄ×Öµä
7. DEMO
8. ºó»°
9. ¸½Â¼
Ò»¡¢Ç°ÑÔ
PHPÊÇÒ»ÖÖ±»¹ã·ºÊ¹ÓõĽű¾ÓïÑÔ£¬ÓÈÆäÊʺÏÓÚweb¿ª·¢¡£¾ßÓÐ¿çÆ½Ì¨£¬ÈÝÒ×ѧϰ£¬¹¦ÄÜÇ¿
´óµÈÌØµã£¬¾Ýͳ¼ÆÈ«ÊÀ½çÓг¬¹ý34%µÄÍøÕ¾ÓÐphpµÄÓ¦Ó㬰üÀ¨Yahoo¡¢sina¡¢163¡¢sohuµÈ´óÐÍ
ÃÅ»§ÍøÕ¾¡£¶øÇҺܶà¾ßÃûµÄwebÓ¦ÓÃϵͳ£¨°üÀ¨bbs,blog,wiki,cmsµÈµÈ£©¶¼ÊÇʹÓÃphp¿ª·¢


Ïà¹ØÎĵµ£º

phpʵÏÖ×¢Ê͵Äɾ³ý¡¾Ö§³Ö//£¬/*£¬/**¡¿

<?php
 $fileName="function.js";
 $file=fopen($fileName,"r");
 
 $writeStr="";
 $flag=false;//ÅжÏÊÇ·ñÓÐ/***/±ê×¼
 while($strLine=fgets($file))
 {
  if(stripos($strLine,"/*")===false || stripos($strLine,"/**")===false)
  {
 &nbs ......

50¸ö·Ç³£ÓÐÓõÄPHP¹¤¾ß

PHPÊÇʹÓÃ×îΪ¹ã·ºµÄ¿ªÔ´·þÎñÆ÷¶Ë½Å±¾ÓïÑÔÖ®Ò»£¬µ±È»PHP²¢
²»ÊÇËÙ¶È×î¿ì
µÄ£¬µ«ËüÈ´ÊÇ
×î³£ÓõĽű¾ÓïÑÔ
¡£ÕâÀïÓÐ50¸öÓÐÒæµÄPHP¹¤¾ß£¬¿ÉÒÔ´ó´óÌá¸ßÄãµÄ±à³Ì¹¤×÷£º
µ÷ÊÔ¹¤¾ß
Webgrind
 
Xdebug
 
Gubed PHP Debugger
 
DBG
PHP_Debug
PHP_Dyn
MacGDBp
²âÊÔºÍÓÅ»¯¹¤¾ß
PHPUnit
SimpleTest
......

phpѧϰ±Ê¼Ç£¨6£©:PHPÑ­»·Óï¾äµÄ½éÉÜÓëÓ¦ÓÃ

PHPÑ­»·Óï¾äµÄ½éÉÜÓëÓ¦ÓÃ
1¡¢break n Ñ­»·¿ØÖÆÓï¾ä
Break Ìø³öÒ»²ã£¨±¾´Î£©Ñ­»·;break n Ìø³ön²ãÑ­»·;
2.Continue:continue ÔÚÑ­»·½á¹¹ÓÃÓÃÀ´Ìø¹ý±¾´ÎÑ­»·ÖÐÊ£ÓàµÄ´úÂë²¢ÔÚÌõ¼þÇóÖµÎªÕæÊ±¿ªÊ¼Ö´ÐÐÏÂÒ»´ÎÑ­»·¡£×¢:×¢ÒâÔÚ PHP ÖРswitch Óï¾ä±»ÈÏΪÊÇ¿ÉÒÔʹÓàcon ......

PHP±ÈASPÓÅÐãµÄÆß¸öÀíÓÉ ÄÏÈý·½

ASPÊÇ΢Èí¹«Ë¾ÊµÏÖ¶¯Ì¬ÍøÒ³µÄÒ»ÖÖ¼¼Êõ¡£
ASPÖ§³ÖһЩ½Å±¾ÓïÑÔ£¬Ö÷ÒªÒÔVBScriptΪÖ÷¡£
ÓëASPÏà±È½Ï£¬Ä㻹¿ÉÒÔÑ¡ÔñÁíÒ»Öпª·ÅÔ´´úÂë±à³ÌÓïÑÔ——PHP£¬PHP¿ÉÒÔÔËÐÐÔÚ¶àÖÖ²Ù×÷ϵͳÏ£¬ÆäÖаüÀ¨LinuxºÍwindows¡£
ËäÈ»ASPÊÇÒ»ÖÖ²»´íµÄ¼¼Êõ£¬µ«´Ó³¤Ô¶¿¼ÂÇÎÒÏàÐÅPHPÔÚ½«À´µÄ¼¼ÊõÁìÓòÀï»áÓв»·²µÄ±íÏÖ¡£
ÎÒÈÏΪÓÐÆß¸ ......

php ²»ÓÃCOM Éú³ÉexcelÎļþ

ÓÃphpÉú³ÉexcelÎļþ
<?
header("Content-type:application/vnd.ms-excel");
header("Content-Disposition:filename=test.xls");
echo "test1/t";
echo "test2/t/n";
echo "test1/t";
echo "test2/t/n";
echo "test1/t";
echo "test2/t/n";
echo "test1/t";
echo "test2/t/n";
echo "test1/t";
echo "test2 ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ