phpÐòÁл¯
1£®Ç°ÑÔ
PHP £¨´Ó PHP 3.05
¿ªÊ¼£©Îª±£´æ¶ÔÏóÌṩÁËÒ»×éÐòÁл¯ºÍ·´ÐòÁл¯µÄº¯Êý£ºserialize¡¢unserialize¡£²»¹ýÔÚ PHP
ÊÖ²áÖжÔÕâÁ½¸öº¯ÊýµÄ˵Ã÷½öÏÞÓÚÈçºÎʹÓ㬶ø¶ÔÐòÁл¯½á¹ûµÄ¸ñʽȴû×öÈκÎ˵Ã÷¡£Òò´Ë£¬Õâ¶ÔÔÚÆäËûÓïÑÔÖÐʵÏÖ PHP
·½Ê½µÄÐòÁл¯À´Ëµ£¬¾Í±È½ÏÂé·³ÁË¡£ËäÈ»ÒÔǰҲËѼ¯ÁËһЩÆäËûÓïÑÔʵÏÖµÄ PHP ÐòÁл¯µÄ³ÌÐò
£¬
²»¹ýÕâЩʵÏÖ¶¼²»ÍêÈ«£¬µ±ÐòÁл¯»ò·´ÐòÁл¯Ò»Ð©±È½Ï¸´ÔӵĶÔÏóʱ£¬¾Í»á³ö´íÁË¡£ÓÚÊÇÎÒ¾ö¶¨Ð´Ò»·Ý¹ØÓÚ PHP
ÐòÁл¯¸ñʽÏê½âµÄÎĵµ£¨Ò²¾ÍÊÇÕâһƪÎĵµ£©£¬ÒÔ±ãÔÚ±àдÆäËûÓïÑÔʵÏÖµÄ php
ÐòÁл¯³ÌÐòʱÄÜÓÐÒ»¸ö±È½ÏÍêÕûµÄ²Î¿¼¡£ÕâÆªÎÄÕÂÖÐËùдµÄÄÚÈÝÊÇÎÒͨ¹ý±àд³ÌÐò²âÊÔºÍÔĶÁ PHP Ô´´úÂëµÃµ½µÄ£¬ËùÒÔ£¬ÎÒ²»ÄÜ 100%
±£Ö¤ËùÓеÄÄÚÈݶ¼ÊÇÕýÈ·µÄ£¬²»¹ýÎһᾡÁ¿±£Ö¤ÎÒËùдϵÄÄÚÈݵÄÕýÈ·ÐÔ£¬¶ÔÓÚÎÒ»¹²»Ì«Çå³þµÄµØ·½£¬ÎÒ»áÔÚÎÄÖÐÃ÷È·Ö¸³ö£¬Ò²Ï£Íû´ó¼ÒÄܹ»¸øÓè²¹³äºÍÍêÉÆ¡£
2£®¸ÅÊö
PHP
ÐòÁл¯ºóµÄÄÚÈÝÊǼòµ¥µÄÎı¾¸ñʽ£¬µ«ÊǶÔ×Öĸ´óСдºÍ¿Õ°×£¨¿Õ¸ñ¡¢»Ø³µ¡¢»»Ðеȣ©Ãô¸Ð£¬¶øÇÒ×Ö·û´®Êǰ´ÕÕ×Ö½Ú£¨»òÕß˵ÊÇ 8
λµÄ×Ö·û£©¼ÆËãµÄ£¬Òò´Ë£¬¸üºÏÊʵÄ˵·¨ÊÇ PHP
ÐòÁл¯ºóµÄÄÚÈÝÊÇ×Ö½ÚÁ÷¸ñʽ¡£Òò´ËÓÃÆäËûÓïÑÔʵÏÖʱ£¬Èç¹ûËùʵÏÖµÄÓïÑÔÖеÄ×Ö·û´®²»ÊÇ×Ö½Ú´¢´æ¸ñʽ£¬¶øÊÇ Unicode
´¢´æ¸ñʽµÄ»°£¬ÐòÁл¯ºóµÄÄÚÈݲ»Êʺϱ£´æÎª×Ö·û´®£¬¶øÓ¦±£´æÎª×Ö½ÚÁ÷¶ÔÏó»òÕß×Ö½ÚÊý×飬·ñÔòÔÚÓë PHP ½øÐÐÊý¾Ý½»»»Ê±»á²úÉú´íÎó¡£
PHP ¶Ô²»Í¬ÀàÐ͵ÄÊý¾ÝÓò»Í¬µÄ×Öĸ½øÐбêʾ£¬Yahoo ¿ª·¢ÍøÕ¾ÌṩµÄ Using Serialized PHP with Yahoo! Web Services
Ò»ÎÄÖиø³öËùÓеÄ×Öĸ±êʾ¼°Æäº¬Ò壺
a - array
b - boolean
d - double
i - integer
o - common object
r - reference
s - string
C - custom object
O - class
N - null
R - pointer reference
U - unicode string
N ±íʾµÄÊÇ NULL£¬¶ø b¡¢d¡¢i¡¢s ±íʾµÄÊÇËÄÖÖ±êÁ¿ÀàÐÍ£¬Ä¿Ç°ÆäËüÓïÑÔËùʵÏÖµÄ PHP ÐòÁл¯³ÌÐò»ù±¾É϶¼ÊµÏÖÁ˶ÔÕâЩÀàÐ͵ÄÐòÁл¯ºÍ·´ÐòÁл¯£¬²»¹ýÓÐһЩʵÏÖÖÐ¶Ô s £¨×Ö·û´®£©µÄʵÏÖ´æÔÚÎÊÌâ¡£
a¡¢O ÊôÓÚ×î³£Óõĸ´ºÏÀàÐÍ£¬´ó²¿·ÖÆäËûÓïÑÔµÄʵÏÖ¶¼ºÜºÃµÄʵÏÖÁË¶Ô a µÄÐòÁл¯ºÍ·´ÐòÁл¯£¬µ«¶Ô O ֻʵÏÖÁË PHP4 ÖжÔÏóÐòÁл¯¸ñʽ£¬¶øÃ»ÓÐÌṩ¶Ô PHP 5 ÖÐÀ©Õ¹µÄ¶ÔÏóÐòÁл¯¸ñʽµÄÖ§³Ö¡£
r¡¢R ·Ö±ð±íʾ¶ÔÏóÒýÓúÍÖ¸ÕëÒýÓã¬ÕâÁ½¸öÒ²±È½ÏÓÐÓã¬ÔÚÐòÁл¯±È½Ï¸´ÔÓµÄÊý×éºÍ¶ÔÏóʱ¾Í»á²úÉú´øÓÐÕâÁ½¸ö±êʾµÄÊý¾Ý£¬ºóÃæÎÒÃǽ«Ïêϸ½²½âÕâÁ½¸ö±êʾ£¬Ä¿Ç°ÕâÁ½¸ö±êʾÉÐûÓ
Ïà¹ØÎĵµ£º
²é¿´ÍêÕû°æ±¾ : ¡¾Ô´´¡¿ÎÒÓÃphpдµÄ¶Ô³Æ¼ÓÃÜËã·¨£¬´ó¼Ò¿´¿´°²È«ÐÔÈçºÎ¡£
panic
2006-02-05, 22:37
//phpÒѾÓÐÁËÍêÕûµÄ¼ÓÃÜ/½âÃÜ¿âÖ§³Ö£¬µ«ÊÇÔÚһЩÖ÷»úÉÏ£¬ÕâЩ¿âûÓб»ÆôÓã¬ËùÒÔ³öÓÚÎÞÄΣ¬²ÅдÁËÏÂÃæµÄËã·¨¡£
//»ù±¾ÔÀíÊÇ£ºÓÃÃ÷ÎĵĺÍkeyµÄ×éºÏÉú³Écrc£¬È»ºóÓÃÕâ¸öcrcºÍkey×éºÏÉú³ÉÒ»¸öhashÑÚÂ룬ÓÃhashÑÚÂëºÍÃ÷ÎÄ ......
×÷ÕߣºPh4nt0m Security Team
À´Ô´£ºhttp://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x03_0x06.txt
==Ph4nt0m Security Team==
Issue 0x03, Phile #0x06 of 0x07
|=---------------------------------------- ......
¡¡¡¡´Ó PHP 3 ¿ªÊ¼Îª±£´æ¶ÔÏóÌṩÁËÒ»×éÐòÁл¯ºÍ·´ÐòÁл¯µÄº¯Êý£ºserialize¡¢unserialize£¬Ëü¿ÉÒÔ·½±ãµÄ±£´æÊý¾Ý·½±ãµÄ×ö³ÉCACHE£¬¶ø´æ´¢Ìå»ýÒ²±ÈXMLҪСµÄ¶à£¬Ëü½á¹¹Óë JS µÄ JSON ÏàÄâ£¬ÍøÉÏÓÐÒ»×éÓà JS Ä£Äâ serialize ʵÏֵķ½·¨£¬Ê¹ÓÃËü¿ÉÒÔºÍPHP ÔÚÊý¾Ý´«µÝÉϸü½ôÃܵĽáºÏ£®
¡¡¡¡JavaScript °æ±¾£¨stable£©£ ......
JpgraphÏÂÔØÖ®ºó£¬°²×°·Ç³£¼òµ¥£¬½âѹµ½Ò»¸öÎļþ¼ÐÖУ¬ÀýÈ磺d:\Jpgraph£¬È»ºó´ò¿ªphpµÄ°²×°Ä¿Â¼£¬ÕÒµ½php.iniÎļþ£¬²¢ÐÞ¸ÄÆäÖеÄinlude_path²ÎÊý£¬²¢ÔÚÆäºó¼ÓÉÏJpgraphµÄ·¾¶£¬ÀýÈ磺inlude_path=".;d:\Jpgraph".
http://blog.csdn.net/zhuzhao/archive/2009/05/12/4174684.aspx ......