Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP¼ì²âÉÏ´«ÎļþµÄÀàÐÍ

×ªÔØ×Ô£ºhttp://hi.baidu.com/thinkinginlamp/blog/item/5da6905211f719050df3e356.html
×÷ÕߣºÀÏÍõ
×îÀõķ½·¨¾ÍÊÇͨ¹ý$_FILES[...]['type']À´¼ì²âÉÏ´«ÎļþµÄÀàÐÍ£¬ÒòΪֻÐè¼òµ¥ÐÞ¸ÄÎļþÀ©Õ¹Ãû¾Í¿ÉÒÔαÔìËü¡£
ÁíÒ»¸öÏà¶Ô°²È«µãµÄ·½·¨ÊÇͨ¹ýÎļþÍ·Á½¸ö×Ö½ÚµÄÄÚÈÝÀ´ÅжÏÉÏ´«ÎļþµÄÀàÐÍ£¬Àý×Ó´úÂëÈçÏ£º
01 $handle = fopen($_FILES[...]['tmp_name'], 'rb');
02 $content = fread($handle, 2);
03 fclose($handle);
04
05 $info = unpack('c2chars', $content);
06
07 if (empty($info['chars1']) || empty($info['chars2'])) {
08     exit('Error!');
09 }
10
11 if ($info['chars1'] < 0) {
12     $info['chars1'] += 256;
13 }
14 if ($info['chars2'] < 0) {
15     $info['chars2'] += 256;
16 }
17
18 $code = $info['chars1'] . $info['chars2'];
PHPÖеÄpack&unpackº¯ÊýºÜìÅ£¬ÓÐÐËȤµÄ¿ÉÒÔ¿´£ºHandling binary data in PHP with pack() and unpack()
×¢£ºÍøÉÏËÑË÷µÄ´ó¶àÊýÏà¹ØµÄ³ÌÐòûÓÐ×ö256µÄÏà¹Ø²Ù×÷£¬ÕâÊÇÎÒͨ¹ýÊÔÑéÊý¾Ý×Ô¼ºÒâÒùµÄTDD½á¹û£¬²»¿Ï¶¨ÊÇ·ñÒ»¶¨ÕýÈ·£¬¶ÁÕß×Ô¼ºÕå×á£
ͨ¹ýswitchÅжÏ$code±äÁ¿£¬¾Í¿ÉÒÔ¶ÔÓ¦µ½ÎļþÀàÐÍ£¬³£¼ûµÄͼƬÀàÐͽá¹û´óÖÂÈçÏ£º
GIF£º7173
JPG£º255216
PNG£º13780
µ±È»Ò²¿ÉÒÔÅÐ¶ÏÆäËûµÄÎļþÀàÐÍ£¬×Ô¼º×ö×öÊÔÑé¾ÍÖªµÀÊýÖµ´óСÁË¡£µ«´Ë·½·¨Ò²²»ÊÇÒ»¶¨°²È«µÄ£¬ÒòΪǰÁ½¸ö×Ö½ÚµÄÄÚÈÝÒ²ÊÇ¿ÉÒÔαÔìµÄ£¬ËùÒÔ×îºÃ»¹ÒªÏÞÖÆÒ»ÏÂÎļþµÄÀ©Õ¹Ãû£¬ÒÔ·ÀÒâÍâµÄ½âÎö£¬±ÈÈç˵£¬Äã´´½¨Ò»¸öÃûΪfoobar.phpµÄÎļþ£¬ÄÚÈÝÈçÏ£º
GIF89
<?php eval(...); ?>
µ±ÄãʹÓÃǰÁ½¸ö×Ö½ÚÈ¥¼ì²âÎļþÀàÐ͵Äʱºò£¬¾Í»áµÃ³öGIF£º7173µÄ½á¹û£¬¼´±ãʹÓÃshellϵÄfileÃüÁîÈ¥¼ì²â£¬Ò»Ñù»áÎóÈÏΪÊÇGIFͼƬ£º
# file foobar.php
foobar.php: GIF image data 16188 x 26736
ÓÉÓÚÀ©Õ¹ÃûÊÇ.php£¬ÄÇô´ËÎļþ¾Í±»phpÒýÇæ½âÎöÁË£¬Èç´ËÒ»À´¾Í¸øÁ˺ڿÍÒ»¸öweb shell£¬°²È«Ò²¾ÍÎÞ´Ó̸ÆðÁË¡£ËùÒÔ˵ÏÞÖÆÎļþÀ©Õ¹Ãû·Ç³£ÖØÒª£¬Çмǣ¡ÖÁÓÚÒѾ­ÈçºÎ·¢ÏÖÕâÀàαװ£¬×î¼òµ¥µÄ·½·¨ÊÇÔÚÓÃshellÃüÁî¹ýÂËÒ»±é£º
# strings foobar.php
| grep -i "<?php"
<?php eval(...); ?>
Èç¹ûÏë³¹µ×ÆÁ±Î´ËÀàΣÏÕ£¬¿ÉÒÔ¿¼ÂÇʹÓÃgd
£¬imagemagick
£¬graphicsmagick
µÈ¹¤¾ß°ÑÓû§ÉÏ´«µÄͼƬ½øÐбØÒªµÄ±à¼­ºóÔÙת´æ£¬ÕâÑù¾ÍÄÜĨȥ¿ÉÄܵÄǶÈë´úÂë¡


Ïà¹ØÎĵµ£º

¼ò½éÁ½¿îPHP¿ª·¢µÄ¿ªÔ´µÄÔÚÏ߰칫Èí¼þ

    ÖîÈç Google Doc µÈWebÓ¦Óã¬ÔÊÐíͨ¹ý»¥ÁªÍø¹²ÏíÐÅÏ¢½øÐÐЭͬ¹¤×÷£¬¸øÎÒÃÇ´øÀ´ÁËȫеÄÈÕ³£°ì¹«ÌåÑé¡£Ëæ×Å´óÁ¿µÄ×ÀÃæÓ¦Óñ»ÒÆÖ²µ½ Web »·¾³£¬ÎÞÂÛÊÇ´¿´âµÄ HTML+CSS+JS »òÕß RIA ¶¼½«¸üÊÜ×·Åõ¡£
    ÒÔÏÂÊÇÁ½¿î¿ª·ÅÔ´´úÂëµÄ Web °ì¹«Èí¼þ£º
    1. OpenGoo
 &nbs ......

Smarty Ä£°å ´Óphp·ÖÅäµÄ±äÁ¿ Êý×é

index.php:
$smarty = new Smarty;
$smarty->assign('Contacts',
array('555-222-9876',
'zaphod@slartibartfast.com',
array('555-444-3333',
'555-111-1234')));
$smarty->display('index.tpl');
index.tpl:
{$Contacts[0]}<br>
{$Contacts[1]}<br>
{* you can print arrays of arrays ......

PHPÆóÒµ½¨Õ¾×ÔÖú¹ÜÀíϵͳ

 ÆóÒµ½¨Õ¾×ÔÖú¹ÜÀíϵͳÊÇÓÉEÒ×ÍøÂç(68ws.cn)»ùÓÚphp+mysql¿ª·¢£¬¼¯Ò×ÓÃÐÔºÍÇ¿´ó¹¦ÄÜΪһÌåÆóÒµ½¨Õ¾ÏµÍ³£¬¾ßÓзḻ¶à²ÊµÄÍøÕ¾ÆóÒµ½¨Õ¾Ä£°æ£¬Áé»îµÄÀ¸Ä¿¹ÜÀíºÍÎÄÕ¡¢Í¼ÎÄ¡¢ÏÂÔØ¡¢¹ã¸æµÈ¹ÜÀí¹¦ÄÜ£¬Ö§³ÖÔĶÁȨÏÞ¿ØÖƺͻáԱȨÏÞ¹ÜÀí£¬Ö§³ÖHTML¾²Ì¬ÍøÒ³Éú³ÉºÍ¶àÓïÑÔ£¬¿ÉÓÃÓÚ´´½¨¸÷ÖÖÆóÒµÍøÕ¾½¨Éè¡£
Ò»¡¢Ö÷Òª¹¦ÄÜÄ£¿é
»áÔ± ......

phpµÄ³£Á¿ºÍ±äÁ¿


Ô­ÎÄÁ´½Ó£ºhttp://www.phpdo.net/index.php/2010/01/28/1-4/
ǰÎĽéÉÜÁËPHPµÄÓïÑÔ¹¹³ÉÓ빤×÷Ô­Àí£¬½ÓÏÂÀ´Õýʽ½éÈëPHPµÄÓï·¨¡£
 ÔÚPHPÖУ¬»ù±¾Êý¾Ý¿É·ÖΪ³£Á¿ºÍ±äÁ¿Á½ÖÖ¡£¶øphpµÄ³£Á¿ºÍ±äÁ¿Ãûͨ³£³ÆÎª±êʶ·û¡£
 ÐèҪעÒâµÄÊDZêʶ·û±ØÐëÒÔ×Öĸ»òÕßÏ»®Ïß¿ªÍ·£¬²¢ÇÒÖ»ÄܰüÀ¨×Öĸ¡¢Êý×ÖºÍÏ»®Ïß¡£
 ³£Á¿µÄ ......

PHP Yii¿ò¼ÜʹÓñʼ

YiiÊÇÎÒ·¢ÏÖµÄĿǰ½ÏºÃÓõÄPHP¿ò¼ÜÖ®Ò»¡£Éè¼ÆÉÏÓ¦¸ÃÊÇÎüÈ¡ÁËZend FrameWorkµÄ¾«»ª£¬¸öÈ˸оõʹÓÃÆðÀ´¸üÊæ·þһЩ£¬ÐÔÄÜËٶȸüºÃһЩ¡£Ò²ÓÉÓÚYiiÍŶÓÊÇÖйúµÄͬ°û£¬Îª±íÖ§³Ö£¬¾õµÃÊÔÓÃһϡ£Ä¿±ê£ºÎªÁË¿ìËÙÉÏÊÖ£¬¸ÃÔìYii×Ô´øµÄblog, ¸ÄÔìÔ­Óй¦ÄÜ£¬Ôö¼Óй¦ÄÜ£¬¸ÄÔìÔ­ÓÐCSS£¬×îºóÍê³Éºº»¯¡£
·þÎñ¶ËÈí¼þ£ºAppServ£¨°²×°Â·¾¶D: ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ