PHPÍòÄÜÃÜÂë
¶ÔPHP°²È«·½ÃæµÄ×ÊÁÏ×÷ÁËЩÊÕ¼¯ºÍ²éÔÄ£¬PHP×¢ÈëÊ×µ±Æä³å£¬Ò»ÆªÉñÃØСǿµÄPHPÍòÄÜÃÜÂëдµÃ²»´í£¬ÕªÂ¼£º
˵ʵ»°Èç¹ûÒ»¸öÍøÕ¾µÄǰ̨¶¼ÊÇ×¢È멶´£¬ÄÇôƾ¾Ñ飬ÍòÄÜÃÜÂë½øºǫ́µÄ¼¸ÂÊ»ù±¾ÉÏÊÇ°Ù·ÖÖ®°Ù¡£
¿ÉÊÇÓеÄÈË˵¶ÔPHPµÄÕ¾Èç¹ûÊÇGPCħÊõת»»¿ªÆô£¬¾Í»á¶ÔÌØÊâ·ûºÅתÒ壬¾Í³¹µ×¶Å¾øÁËPHP×¢Èë¡£Æäʵ˵Õâ»°µÄÈËûÓкúÃÏë¹ý£¬¸üûÓг¢ÊÔ¹ýÓÃÍòÄÜÃÜÂë½øPHPµÄºǫ́¡£ÆäʵGPCħÊõת»»ÊÇ·ñ¿ªÆô¶ÔÓÃÍòÄÜÃÜÂë½øºǫ́һµãÓ°ÏìҲûÓС£Èç¹ûÄãÓÃÕâÑùµÄÍòÄÜÃÜÂë'or'='or'£¬µ±È»½ø²»È¥£¬ÀíÓÉÊÇGPC¿ªÆôµÄʱºòµ¥ÒýºÅ»á±»×ª»»¡£
PHP×¢ÈëʱÎÒ³£ÓõÄPHPÍòÄÜÃÜÂëÊÇ£º
'or 1=1/*.
ÄÇÎÒÃÇ·ÖÎöÒ»ÏÂΪʲôÕâ¿ÉÒÔ½øºǫ́¡£
Èç¹ûSQLÓï¾äÕâÑùд£º
"SELECT * from admin where name='".$_POST['name']."'and password='".$_POST['password']."'"
ÄÇÎÒÃÇÔÚÕʺŴ¦ÊäÈëÍòÄÜÃÜÂë'or 1=1/*£¬ÃÜÂëËæ±ãÊ䣬sqlÓï¾ä¾Í³ÉÁË£º
SELECT * from admin where name=''or 1=1/*' and password='ÈÎÒâ×Ö·û'
/*ΪmysqlµÄ×¢ÊÍ·û£¬ÕâÑùºóÃæµÄ¶«Î÷¾Í¶¼±»×¢Ê͵ôÁË£¬Ò²¾ÍÊÇΪʲôÃÜÂëËæ±ãÊäµÄÔÒò¡£
¼ÙÉèGPCת»»Ã»ÓпªÆô£¬ÄÇôÇë¿´£ºwhere name=''or 1=1£¨*/ºóÃæµÄ¶«Î÷±»×¢Ê͵ôÁË£©£¬name='' µÄÂ߼ֵΪ¼Ù£¬¶øºóÃæµÄ1=1Âß¼ÖµÔòΪÕ棬¶ÔÓÚÕûÌå¾Í³ÉÁ˼٠or Õ棬×îÖÕµÄÂß¼Öµ»¹ÊÇÕ棬¾Í½øºǫ́ÁË¡£
ÄÇôÈç¹ûGPCת»»¿ªÆôÁË£¬¾Í¶Ôµ¥ÒýºÅ½øÐÐÁËת»»¡£Óï¾ä¾Í±ä³ÉÁË£ºwhere name='\'or 1=1£¨*/ºóÃæµÄ¶«Î÷±»×¢Ê͵ôÁË£©£¬ÔÚ¿´Ò»Ïº͸ղÅÓÐʲôÇø±ð£¬ÎÞ·ÇÊǶàÁ˸ö\¡£name='\'Óëname=''µÄÂß¼ÖµÒ»Ñù£¬¶¼Îª¼Ù£¬ÄÇ1=1ΪÕ棬×ܵÄsqlÓï¾äµÄÂß¼Öµ²»»¹ÊÇÕæÂð£¿ÄÇÓнø²»È¥ºǫ́µÄÀíÓÉÂð£¿
ËùÒÔ×ܵÄÀ´Ëµ£¬phpÍøÕ¾µÄÍòÄÜÃÜÂë¿ÉÒÔÕâÑùд:'or 1=1/*£¬¶øGPCת»»ÊÇ·ñ¿ªÆô¶ÔËüûÓÐÈκÎÓ°Ï죡
ËùÒÔÇë¸Ä±äÄãµÄÏë·¨£º´æÔÚ×Ö·ûÐÍ×¢ÈëµÄPHPÍøÕ¾ÊÇ¿ÉÒÔÓÃÍòÄÜÃÜÂë'or 1=1/*µÄ¡£
------
·ÀÖ¹PHPÍòÄÜÃÜÂë×¢È룬¼ÇµÃ¹ýÂ˽ÓÊÕ×Ö·û´®Öеĵ¥ÒýºÅºÍ*ºÅ¡£
Ïà¹ØÎĵµ£º
µ¥¼þģʽҪ½â¾öµÄÎÊÌâ¾ÍÊÇ“ÈçºÎÈÃÕâ¸öÀàÖ»ÓÐÒ»¸öʵÀý”¡£
ÎÒÃǵÄwebÓ¦ÓÃÖУ¬´óÁ¿Ê¹ÓÃÁËÊý¾Ý¿âÁ¬½Ó£¬Èç¹û·´¸´½¨Á¢ÓëÊý¾Ý¿âµÄÁ¬½Ó±ØÈ»ÏûºÄ¸ü¶àµÄϵͳ×ÊÔ´¡£
ÎÒÃÇÈçºÎ½â¾öÕâ¸öÎÊÌ⣬½¨Á¢Î¨Ò»µÄÊý¾Ý¿âÁ¬½ÓÊDZØÒªµÄ·½Ê½¡£
ÎÒÃÇÓÖÈçºÎÖªµÀÓëÕâ¸öÊý¾Ý¿âµÄÁ¬½ÓÊÇ·ñÒѾ½¨Á¢£¿ »¹ÊÇÐèÒªÏÖÔÚ½¨Á¢£¿
µ¥¼þģʽ¿ÉÒÔ½â¾öÕ ......
ÀàʵÏÖ½Ó¿ÚҪʹÓà implements ¡£ÀàʵÏÖ½Ó¿ÚҪʵÏÖÆäÖеijéÏó·½·¨¡£Ò»¸öÀà¿ÉÒÔʵÏÖ¶à¸ö½Ó¿Ú¡£
Ò»¸öÀà¿ÉÒÔʹÓà implements ʵÏÖ½Ó¿Ú£¬ÉõÖÁ¿ÉÒÔʵÏÖ¶à¸ö½Ó¿Ú¡£
´ó²¿·ÖµÄÊé˵£¬ÕâÑùÊÇΪÁËʵÏÖPHPµÄ¶à¼Ì³Ð¡£ÎªÊ²Ã´ÄØ£¿
PHP5Êǵ¥¼Ì³ÐµÄ£¬Ò»¸öÀàÖ»¿ÉÒԼ̳Ð×ÔÒ»¸ö¸¸Àà¡£½Ó¿Ú¿ÉÒÔʵÏÖ¶à¸ö£¬ÕâÑù¾ÍÊǶà¼Ì³ÐÁË¡£
ÕâÑù˵ÓÐЩµÀÀí¡£ ......
<?php
header("Content-type:text/html","Charset=UTF-8");
$file="config/config.php";
if(is_writable($file)!=null){
echo "Îļþ¿ÉдÈë \n";
}else{
echo "Îļþ²»¿Éд|";
exit();
}
if(isset($_POST["install"])){
$string = "<?php \n";
$string .="\$mysql_host=\"$_P ......
×î½üÔÚŪnginxºÍxen+php.ÖмäÒ²·ÑÁ˲»ÉÙµÄÖÜÕÛ.¼Ç¼һÏÂ.Ò²ËãÒ»¸öС³É¹û.
²Ù×÷ϵͳ°æ±¾,×îºó»¹ÊÇÑ¡ÔñCentOS-5.4-x86_64-bin-DVD.iso.
CentOS-5.4-x86_64-bin-DVD.iso µÄ°²×°:
°²×°µÄʱºò»ù±¾ÉÏlibºÍ¿ª·¢¹¤¾ß¶¼ÒªÑ¡.×ÀÃæµÄ¿ª·¢»·¾³ÎÒÒ²¶¼Ñ¡ÁË.
˵²»¶¨Äĸöº¯ÊýÖ§³Ö¾ÍÒªÓõ½Õâ¸ö¿â.
mysql-5.1.41.tar.gz:
¾Ý˵¸ü¸ß°æ±¾µÄ ......
Ñ»·Óï¾äÊÇ ÎªÁ˽â¾ö±à³ÌÖÐ "ÐèÒªÖظ´Ò»¶ÎÖ¸ÁîÖ±µ½Âú×ãÌض¨Ìõ¼þΪֹ" µÄÒ»ÖÖÑ»·»úÖÆ
1¡¢while
whileÓï¾äÖ¸¶¨ÁËÒ»¸öÌõ¼þ£¬ÔÚÆäǶÈë´úÂë½áÊøÖ´ÐÐÇ°£¬±ØÐëÂú×ãÕâ¸öÌõ¼þ¡£
Óï·¨£º
while(expression){
& ......