php °²È«Ä£Ê½µÄ²»×ã
PHPµÄsafe_modeÑ¡ÏîµÄÄ¿µÄÊÇΪÁ˽â¾ö±¾ÕÂËùÊöµÄijЩÎÊÌâ¡£
µ«ÊÇ£¬ÔÚPHP²ãÃæÉÏÈ¥½â¾öÕâÀàÎÊÌâ´Ó¼Ü¹¹ÉÏÀ´¿´ÊDz»ÕýÈ·µÄ£¬ÕýÈçPHPÊÖ²áËùÊö(http://php.net/features.safe-mode)¡£
µ±°²È«Ä£Ê½ÉúЧʱ£¬PHP»á¶ÔÕýÔÚÖ´ÐеĽű¾Ëù¶ÁÈ¡£¨»òËù²Ù×÷£©ÎļþµÄÊôÖ÷½øÐмì²é£¬ÒÔ±£Ö¤Óë¸Ã½Å±¾µÄÊôÖ÷ÊÇÏàͬµÄ¡£
ËäÈ»ÕâÑùȷʵ¿ÉÒÔ·À·¶±¾ÕÂÖеĺܶàÀý×Ó£¬µ«Ëü²»»áÓ°ÏìÆäËüÓïÑÔ±àдµÄ³ÌÐò¡£
ÀýÈ磬ʹÓÃBashдµÄCGI½Å±¾£º
#!/bin/bash
echo "Content-Type:text/plain"
echo ""
cat /home/victim/inc/db.inc
Bash½âÎöÆ÷»áÈ¥¹ØÐÄÉõÖÁ¼ì²éPHPÅäÖÃÎļþÖеĴò¿ª°²È«Ä£Ê½µÄÅäÖÃ×Ö·û´®Âð£¿
µ±È»²»»á¡£Í¬ÑùµÄ£¬¸Ã·þÎñÆ÷Ö§³ÖµÄÆäËüÓïÑÔ£¬ÈçPerl£¬PythonµÈ¶¼²»»áÈ¥¹ØÐÄÕâ¸ö¡£
±¾ÕÂÖеÄËùÓÐÀý×Ó¿ÉÒԺܼòµ¥µØ±»¸Ä±à³ÉÆäËü±à³ÌÓïÑÔ¡£
ÁíÒ»¸öµäÐ͵ÄÎÊÌâÊǰ²È«Ä£Ê½²»»á¾Ü¾øÊôÓÚWEB·þÎñÆ÷ÎļþµÄ·ÃÎÊ¡£
ÕâÊÇÓÉÓÚÒ»¶Î½Å±¾¿ÉÒÔÓÃÓÚ½¨Á¢ÁíÒ»¶Î½Å±¾£¬¶øÐ½ű¾ÊÇÊôÓÚWEB·þÎñÆ÷µÄ£¬Òò´ËËü¿ÉÒÔ·ÃÎÊËùÓÐÊôÓÚWEB·þÎñÆ÷µÄÎļþ£º
<?php
$filename='file.php';
$script='<?php
header(\'Content-Type:text/plain\');
readfile($_GET[\'file\']);
?>';
file_put_contents($filename,$script);
?>
ÉÏÃæµÄ½Å±¾½¨Á¢ÁËÏÂÃæµÄÎļþ£º
<?php
header('Content-Type:text/plain');
readfile($_GET['file']);
?>
ÓÉÓÚ¸ÃÎļþÊÇÓÉWeb·þÎñÆ÷Ëù½¨Á¢µÄ£¬Òò´ËËüµÄÊôÖ÷ÊÇWeb·þÎñÆ÷£¨ApacheÒ»°ãÒÔnobodyÓû§ÔËÐУ©£º
$ls file.php
-rw-r--r-- 1 nobody nobody 72 May 21 12:34 file.php
Òò´Ë£¬Õâ¸ö½Å±¾¿ÉÒÔÈÆ¹ýºÜ¶à°²È«Ä£Ê½ËùÌṩµÄ°²È«´ëÊ©¡£
¼´Ê¹´ò¿ªÁ˰²È«Ä£Ê½£¬¹¥»÷ÕßÒ²ÄÜÏÔʾһЩÐÅÏ¢Èç±£´æÔÚ/tmpĿ¼ÄڵĻỰÐÅÏ¢£¬
ÕâÊÇÓÉÓÚÕâЩÎļþÊÇÊôÓÚWeb·þÎñÆ÷µÄ£¨nobody£©¡£
PHPµÄ°²È«Ä£Ê½È·ÊµÆðµ½ÁËһЩ×÷Ó㬿ÉÒÔÈÏΪËüÊÇÒ»ÖÖÉî¶È·À·¶»úÖÆ¡£
¿ÉÊÇ£¬ËüÖ»ÌṩÁË¿ÉÁ¯µÄ±£»¤£¬Í¬Ê±ÔÚ±¾ÕÂÖÐҲûÓÐÆäËü°²È«´ëÊ©À´Ìæ´úËü¡£
Ïà¹ØÎĵµ£º
header
(PHP 3, PHP 4, PHP 5)
header -- ·¢ËÍÒ»¸öÔʼ HTTP ±êÍ·
˵Ã÷
void header ( string string [, bool replace [, int http_response_code]] )
header() º¯ÊýÓÃÀ´·¢ËÍÒ»¸öÔʼ HTTP ±êÍ·¡£ÓÐ¹Ø HTTP ±êÍ·µÄ¸ü¶àÄÚÈݼû HTTP/1.1 ¹æ·¶¡£
¿ÉÑ¡²ÎÊý replace Ö¸Ã÷ÊÇÌæ»»µôǰһÌõÀàËÆµÄ±êÍ·»¹ÊÇÔö¼ÓÒ»ÌõÏàͬÀàÐ͵ ......
Äêǰ°ïsw666Ç¨ÒÆÍøÕ¾µ½ÎÒÃÇ·þÎñÆ÷£¬½á¹û£¬Åú·¢ÖÐÐÄÁ½ÕÅͼƬ²»ÏÔʾ£¬ÉÌÆ·Ìí¼ÓµÄËõÂÔͼ²»ÏÔʾ£¬ÓÉÓÚµÚÒ»´Î´îPHP»·¾³£¬ËùÒÔÕÕ×ÅÍøÉϵĽ̳ÌÒ»²½²½¸ã£¬´îºÃºóÄÜ·ÃÎÊ£¬µ«¾ÍÊÇͼƬÓÐÎÊÌâ¡£ÔõôŪ¶¼¸ã²»¶¨
ǰ¼¸ÌìÖÜÉлԴó¸ç˵ÊÇgd¿âµÄÎÊÌ⣬ÎÒ¾ÍÅäÖÃÁËÏÂphp.iniÎļþ£¬¸Ä³ÉÖ§³ÖÁËgd¿â£¬ºóÃæÒª²é¿´ÊÇ·ñÓÐgd¿â£¬±àдphp.phpÎļþ
< ......
»¨ÁËÈýÌìµÄʱ¼ä£¬ÖÕÓÚÀûÓÃphp+mysqlÖÆ×÷Á˸öÔÚÏ߱ʼDZ¾£¬±¾À´ÊÇÔÚÍøÉÏÕÒÁËһЩµ¥»úµÄ¼Çʱ¾£¬
ÎÒ¿¿£¬Òª²»ÊÇÐèҪע²áÂ룬Ҫ²»ÊDz»·ûºÏ×Ô¼ºµÄÐèÇó£¬ÔÙ˵µ¥»úµÄÐèÒªÔÚ±¾µØ°²×°¡£
Ö÷ÒªµÄÄ¿µÄÊÇÓÃÀ´×öÒ»¸ötodo list¹¦ÄÜ£¬Ä¿Ç°Ö§³ÖµÄ¹¦ÄܱȽϼòµ¥£ºÔö¼Ó£¬É¾³ý£¬Í³¼Æ£¬
ÉÏ´«Îļþ£¬ÀûÓÃfckeditor½øÐб༣¬°²È«·½Ãæ×öÁËЩ¼òµ¥´ ......
×î½üÈ¥ÃæÊÔPHP³ÌÐòÔ± ³öÁËÒ»µÀÕâÑùµÄÌâ “php±éÀúÕû¸öĿ¼µÄÎļþÒÔ¼°Îļþ¼Ð ·â×°³Éº¯Êý”˳±ãÒ²¾ÍÌùÁËÉÏÀ´¡£ÐèÒªµÄÅóÓÑ¿ÉÒÔÄÃÈ¥ÓÃÓ㬽ö¹©Ñ§Ï°½»Á÷ʹÓá£ÈçÓв»Ç¡µ±µÄµØ·½»¹Çë¸÷λ¸ßÊÖ“×ìÏÂÁôÈË” °¡£¡
<?php
$path=$_SERVER["DOCUMENT_ROOT"];
$path=str_replace("/","\\",$path);
$path="$ ......
VC6ÊÇʲô£¿
VC6¾ÍÊÇlegacy Visual
Studio 6 compiler£¬¾ÍÊÇʹÓÃÕâ¸ö±àÒëÆ÷±àÒëµÄ
VC9ÊÇʲô£¿
VC9¾ÍÊÇthe Visual Studio
2008 compiler£¬¾ÍÊÇÓÃ΢ÈíµÄVS±à¼Æ÷±àÒëµÄ
ÄÇÎÒÃÇÈçºÎÑ¡ÔñÏÂÔØÄĸö°æ±¾µÄPHPÄØ£¿
Èç¹ûÄãÊÇÔÚwindowsÏÂ
ʹÓÃApache+PHPµÄ£¬ÇëÑ¡ÔñVC6°æ±¾£»
Èç¹ûÄãÊÇÔÚwindowsÏÂʹÓÃIIS+PHPµÄ£¬ÇëÑ¡ÔñVC9 ......