phpÐòÁл¯
1£®Ç°ÑÔ
PHP £¨´Ó PHP 3.05
¿ªÊ¼£©Îª±£´æ¶ÔÏóÌṩÁËÒ»×éÐòÁл¯ºÍ·´ÐòÁл¯µÄº¯Êý£ºserialize¡¢unserialize¡£²»¹ýÔÚ PHP
ÊÖ²áÖжÔÕâÁ½¸öº¯ÊýµÄ˵Ã÷½öÏÞÓÚÈçºÎʹÓ㬶ø¶ÔÐòÁл¯½á¹ûµÄ¸ñʽȴû×öÈκÎ˵Ã÷¡£Òò´Ë£¬Õâ¶ÔÔÚÆäËûÓïÑÔÖÐʵÏÖ PHP
·½Ê½µÄÐòÁл¯À´Ëµ£¬¾Í±È½ÏÂé·³ÁË¡£ËäÈ»ÒÔǰҲËѼ¯ÁËһЩÆäËûÓïÑÔʵÏÖµÄ PHP ÐòÁл¯µÄ³ÌÐò
£¬
²»¹ýÕâЩʵÏÖ¶¼²»ÍêÈ«£¬µ±ÐòÁл¯»ò·´ÐòÁл¯Ò»Ð©±È½Ï¸´ÔӵĶÔÏóʱ£¬¾Í»á³ö´íÁË¡£ÓÚÊÇÎÒ¾ö¶¨Ð´Ò»·Ý¹ØÓÚ PHP
ÐòÁл¯¸ñʽÏê½âµÄÎĵµ£¨Ò²¾ÍÊÇÕâһƪÎĵµ£©£¬ÒÔ±ãÔÚ±àдÆäËûÓïÑÔʵÏÖµÄ php
ÐòÁл¯³ÌÐòʱÄÜÓÐÒ»¸ö±È½ÏÍêÕûµÄ²Î¿¼¡£ÕâÆªÎÄÕÂÖÐËùдµÄÄÚÈÝÊÇÎÒͨ¹ý±àд³ÌÐò²âÊÔºÍÔĶÁ PHP Ô´´úÂëµÃµ½µÄ£¬ËùÒÔ£¬ÎÒ²»ÄÜ 100%
±£Ö¤ËùÓеÄÄÚÈݶ¼ÊÇÕýÈ·µÄ£¬²»¹ýÎһᾡÁ¿±£Ö¤ÎÒËùдϵÄÄÚÈݵÄÕýÈ·ÐÔ£¬¶ÔÓÚÎÒ»¹²»Ì«Çå³þµÄµØ·½£¬ÎÒ»áÔÚÎÄÖÐÃ÷È·Ö¸³ö£¬Ò²Ï£Íû´ó¼ÒÄܹ»¸øÓè²¹³äºÍÍêÉÆ¡£
2£®¸ÅÊö
PHP
ÐòÁл¯ºóµÄÄÚÈÝÊǼòµ¥µÄÎı¾¸ñʽ£¬µ«ÊǶÔ×Öĸ´óСдºÍ¿Õ°×£¨¿Õ¸ñ¡¢»Ø³µ¡¢»»Ðеȣ©Ãô¸Ð£¬¶øÇÒ×Ö·û´®Êǰ´ÕÕ×Ö½Ú£¨»òÕß˵ÊÇ 8
λµÄ×Ö·û£©¼ÆËãµÄ£¬Òò´Ë£¬¸üºÏÊʵÄ˵·¨ÊÇ PHP
ÐòÁл¯ºóµÄÄÚÈÝÊÇ×Ö½ÚÁ÷¸ñʽ¡£Òò´ËÓÃÆäËûÓïÑÔʵÏÖʱ£¬Èç¹ûËùʵÏÖµÄÓïÑÔÖеÄ×Ö·û´®²»ÊÇ×Ö½Ú´¢´æ¸ñʽ£¬¶øÊÇ Unicode
´¢´æ¸ñʽµÄ»°£¬ÐòÁл¯ºóµÄÄÚÈݲ»Êʺϱ£´æÎª×Ö·û´®£¬¶øÓ¦±£´æÎª×Ö½ÚÁ÷¶ÔÏó»òÕß×Ö½ÚÊý×飬·ñÔòÔÚÓë PHP ½øÐÐÊý¾Ý½»»»Ê±»á²úÉú´íÎó¡£
PHP ¶Ô²»Í¬ÀàÐ͵ÄÊý¾ÝÓò»Í¬µÄ×Öĸ½øÐбêʾ£¬Yahoo ¿ª·¢ÍøÕ¾ÌṩµÄ Using Serialized PHP with Yahoo! Web Services
Ò»ÎÄÖиø³öËùÓеÄ×Öĸ±êʾ¼°Æäº¬Ò壺
a - array
b - boolean
d - double
i - integer
o - common object
r - reference
s - string
C - custom object
O - class
N - null
R - pointer reference
U - unicode string
N ±íʾµÄÊÇ NULL£¬¶ø b¡¢d¡¢i¡¢s ±íʾµÄÊÇËÄÖÖ±êÁ¿ÀàÐÍ£¬Ä¿Ç°ÆäËüÓïÑÔËùʵÏÖµÄ PHP ÐòÁл¯³ÌÐò»ù±¾É϶¼ÊµÏÖÁ˶ÔÕâЩÀàÐ͵ÄÐòÁл¯ºÍ·´ÐòÁл¯£¬²»¹ýÓÐһЩʵÏÖÖÐ¶Ô s £¨×Ö·û´®£©µÄʵÏÖ´æÔÚÎÊÌâ¡£
a¡¢O ÊôÓÚ×î³£Óõĸ´ºÏÀàÐÍ£¬´ó²¿·ÖÆäËûÓïÑÔµÄʵÏÖ¶¼ºÜºÃµÄʵÏÖÁË¶Ô a µÄÐòÁл¯ºÍ·´ÐòÁл¯£¬µ«¶Ô O ֻʵÏÖÁË PHP4 ÖжÔÏóÐòÁл¯¸ñʽ£¬¶øÃ»ÓÐÌṩ¶Ô PHP 5 ÖÐÀ©Õ¹µÄ¶ÔÏóÐòÁл¯¸ñʽµÄÖ§³Ö¡£
r¡¢R ·Ö±ð±íʾ¶ÔÏóÒýÓúÍÖ¸ÕëÒýÓã¬ÕâÁ½¸öÒ²±È½ÏÓÐÓã¬ÔÚÐòÁл¯±È½Ï¸´ÔÓµÄÊý×éºÍ¶ÔÏóʱ¾Í»á²úÉú´øÓÐÕâÁ½¸ö±êʾµÄÊý¾Ý£¬ºóÃæÎÒÃǽ«Ïêϸ½²½âÕâÁ½¸ö±êʾ£¬Ä¿Ç°ÕâÁ½¸ö±êʾÉÐûÓ
Ïà¹ØÎĵµ£º
1¡¢´´½¨ ºÍ ÐÞ¸Ä Êý×é
PHPÖÐʹÓÃarrayÀ´´´½¨Ò»¸öÊý×飺
array( key=>value , key=>value …… )
Àý×Ó£º
$arr = array (3,5,7,9,6);
&nb ......
×÷ÕߣºPh4nt0m Security Team
À´Ô´£ºhttp://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x03_0x06.txt
==Ph4nt0m Security Team==
Issue 0x03, Phile #0x06 of 0x07
|=---------------------------------------- ......
<?php
function vCode($num=4,$size=20, $width=0,$height=0){
!$width && $width = $num*$size*4/5+5;
!$height && $height = $size + 10;
// È¥µôÁË 0 1 O l µÈ
$str = "23456789abcdefghijkmnpqrstuvwxyzABCDEFGHIJKLMNPQRSTUVW";
$code ......
ÔÚÍøÉÏÕÒÁ˺ܶàIIS+PHPµÄÅäÖõķ½·¨£¬ÊÔ¹ýÖ®ºóºÜ¶à¶¼²»ÄܴﵽЧ¹û¡£ÓÚÊÇ×ܽáÁ˴󲿷ֵÄÎÄÕºó¾ÍµÃ³öÁËÕâÑùµÄ·½·¨£º£¨±¾´Î²Ù×÷ϵͳÒÔWin2000ΪÀý£¬Èç¹ûÄãÒª¸ÄΪÆäËüϵͳ¾Í°Ñϵͳ¸ùĿ¼±äһϾÍOkÁË£©
Ò»¡¢ÏÂÔØ±ØÐëµÄ³ÌÐò£º
(1) Ïȵ½PHPµÄ¹Ù·½ÍøÕ¾ÏÂÔØÒ»¸öPHP£¨±¾ÎľÍÒÔPHP 4.4.2ΪÀý£©¡£ ......
ϸ²ì PHP V5.3.0 ÌØÐÔ
¼¶±ð£º Öм¶
Stephen B. Morris, CTO, Omey Communications
2009 Äê 12 ÔÂ 07 ÈÕ
Ëæ×ÅÁ÷ÐÐµÄ PHP ÓïÑԵIJ»¶ÏÑݱ䣬ºÜ¶àÐÂÌØÐÔʹËüÔÚÃæÏò¶ÔÏó·½ÃæÓÐÁ˽øÒ»²½µÄÔöÇ¿¡£±¾ÎÄͨ¹ýһЩ PHP V5.3 ʵÀýÑÝʾÑÓ³Ù¾²Ì¬°ó¶¨¡¢Ãû³Æ¿Õ¼äÖ§³Ö¡¢Àà·½·¨ÖØÔØÒÔ¼°±äÁ¿½âÎöºÍ heredoc Ö§³Ö¡£
ÐèÇó
³ýÁË¶Ô PHP ºÍ H ......