phpÓйصļ¸ÖÖ³£¼û°²È«Ïê½â
(1) ´ò¿ªphpµÄ°²È«Ä£Ê½
phpµÄ°²È«Ä£Ê½ÊǸö·Ç³£ÖØÒªµÄÄÚǶµÄ°²È«»úÖÆ£¬Äܹ»¿ØÖÆÒ»Ð©phpÖеĺ¯Êý£¬±ÈÈçsystem()£¬
ͬʱ°ÑºÜ¶àÎļþ²Ù×÷º¯Êý½øÐÐÁËȨÏÞ¿ØÖÆ£¬Ò²²»ÔÊÐí¶ÔijЩ¹Ø¼üÎļþµÄÎļþ£¬±ÈÈç/etc/passwd£¬
µ«ÊÇĬÈϵÄphp.iniÊÇûÓдò¿ª°²È«Ä£Ê½µÄ£¬ÎÒÃǰÑËü´ò¿ª£º
safe_mode = on
(2) Óû§×鰲ȫ
µ±safe_mode´ò¿ªÊ±£¬safe_mode_gid±»¹Ø±Õ£¬ÄÇôphp½Å±¾Äܹ»¶ÔÎļþ½øÐзÃÎÊ£¬¶øÇÒÏàͬ
×éµÄÓû§Ò²Äܹ»¶ÔÎļþ½øÐзÃÎÊ¡£
½¨ÒéÉèÖÃΪ£º
safe_mode_gid = off
Èç¹û²»½øÐÐÉèÖ㬿ÉÄÜÎÒÃÇÎÞ·¨¶ÔÎÒÃÇ·þÎñÆ÷ÍøÕ¾Ä¿Â¼ÏµÄÎļþ½øÐвÙ×÷ÁË£¬±ÈÈçÎÒÃÇÐèÒª
¶ÔÎļþ½øÐвÙ×÷µÄʱºò¡£
(3) °²È«Ä£Ê½ÏÂÖ´ÐгÌÐòÖ÷Ŀ¼
Èç¹û°²È«Ä£Ê½´ò¿ªÁË£¬µ«ÊÇÈ´ÊÇÒªÖ´ÐÐijЩ³ÌÐòµÄʱºò£¬¿ÉÒÔÖ¸¶¨ÒªÖ´ÐгÌÐòµÄÖ÷Ŀ¼£º
safe_mode_exec_dir = D:/usr/bin
Ò»°ãÇé¿öÏÂÊDz»ÐèÒªÖ´ÐÐʲô³ÌÐòµÄ£¬ËùÒÔÍÆ¼ö²»ÒªÖ´ÐÐϵͳ³ÌÐòĿ¼£¬¿ÉÒÔÖ¸ÏòÒ»¸öĿ¼£¬
È»ºó°ÑÐèÒªÖ´ÐеijÌÐò¿½±´¹ýÈ¥£¬±ÈÈ磺
safe_mode_exec_dir = D:/tmp/cmd
µ«ÊÇ£¬ÎÒ¸üÍÆ¼ö²»ÒªÖ´ÐÐÈκγÌÐò£¬ÄÇô¾Í¿ÉÒÔÖ¸ÏòÎÒÃÇÍøÒ³Ä¿Â¼£º
safe_mode_exec_dir = D:/usr/www
(4) °²È«Ä£Ê½Ï°üº¬Îļþ
Èç¹ûÒªÔÚ°²È«Ä£Ê½Ï°üº¬Ä³Ð©¹«¹²Îļþ£¬ÄÇô¾ÍÐÞ¸ÄÒ»ÏÂÑ¡Ï
safe_mode_include_dir = D:/usr/www/include/
Æäʵһ°ãphp½Å±¾Öаüº¬Îļþ¶¼ÊÇÔÚ³ÌÐò×Ô¼ºÒѾдºÃÁË£¬Õâ¸ö¿ÉÒÔ¸ù¾Ý¾ßÌåÐèÒªÉèÖá£
(5) ¿ØÖÆphp½Å±¾ÄÜ·ÃÎʵÄĿ¼
ʹÓÃopen_basedirÑ¡ÏîÄܹ»¿ØÖÆPHP½Å±¾Ö»ÄÜ·ÃÎÊÖ¸¶¨µÄĿ¼£¬ÕâÑùÄܹ»±ÜÃâPHP½Å±¾·ÃÎÊ
²»Ó¦¸Ã·ÃÎʵÄÎļþ£¬Ò»¶¨³Ì¶ÈÉÏÏÞÖÆÁËphpshellµÄΣº¦£¬ÎÒÃÇÒ»°ã¿ÉÒÔÉèÖÃΪֻÄÜ·ÃÎÊÍøÕ¾Ä¿Â¼£º
open_basedir = D:/usr/www
(6) ¹Ø±ÕΣÏÕº¯Êý
Èç¹û´ò¿ªÁ˰²È«Ä£Ê½£¬ÄÇôº¯Êý½ûÖ¹ÊÇ¿ÉÒÔ²»ÐèÒªµÄ£¬µ«ÊÇÎÒÃÇΪÁ˰²È«»¹ÊÇ¿¼ÂǽøÈ¥¡£±ÈÈ磬
ÎÒÃǾõµÃ²»Ï£ÍûÖ´ÐаüÀ¨system()µÈÔÚÄǵÄÄܹ»Ö´ÐÐÃüÁîµÄphpº¯Êý£¬»òÕßÄܹ»²é¿´phpÐÅÏ¢µÄ
phpinfo()µÈº¯Êý£¬ÄÇôÎÒÃǾͿÉÒÔ½ûÖ¹ËüÃÇ£º
disable_functions = system,passthru,exec,shell_exec,popen,phpinfo
Èç¹ûÄãÒª½ûÖ¹ÈκÎÎļþºÍĿ¼µÄ²Ù×÷£¬ÄÇô¿ÉÒԹرպܶàÎļþ²Ù×÷
disable_functions = chdir,chroot,dir,getcwd,opendir,readdir,scandir,fopen,unlink,delete,copy,mkdir, rmdir,rename,file,file_get_contents,fputs,fwrite,chgrp,chmod,chown
ÒÔÉÏÖ»ÊÇÁÐÁ˲¿·Ö²»½Ð³£ÓõÄÎļþ´¦Àíº¯Êý£¬ÄãÒ²¿ÉÒÔ°ÑÉÏÃæÖ´ÐÐÃüÁÊýºÍÕâ¸öº¯Êý½áºÏ£¬
¾ÍÄܹ»µÖÖÆ´ó²¿·ÖµÄphpshellÁË¡£
Ïà¹ØÎĵµ£º
<?php
$zip_filename = "testpm.zip";
$zip_filename = key_exists('zip', $_GET) && $_GET['zip']?$_GET['zip']:$zip_filename;
$zip_filepath = str_replace('\\', '/', dirname(__FILE__)) . '/' . $zip_filename;
if(!is_file($zip_filepath))
{
die('Îļþ"'.$zip_ ......
ÉùÃ÷£¨±¾ÎÄ×ªÔØ×Ô£©£ºhttp://www.phpzc.com/read.php?tid=643
ltrim();//È¥µô×Ö·û´®×ó¿Õ¸ñ;
rtrim();//È¥µô×Ö·û´®ÓÒ¿Õ¸ñ;
trim(); //È¥µô×Ö·û´®Á½±ß¿Õ¸ñ;
//È¥µô¿Õ¸ñÊÇ·µ»ØÒ»¸öеÄ×Ö·û´®;Ô×Ö·û´®²»±ä;
strlen(); //¼ÆËã×Ö·û´®³¤¶È;
......
£¨1£©
Warning: mysql_query() [function.mysql-query]: Access denied for user
'ODBC'@'localhost' (using password: NO) in C:\Program Files\Apache
Software Foundation\Apache2.2\htdocs\TM\conn\conn.php on line 32
Warning: mysql_query() [function.mysql-query]: A link to the server could
not be est ......
phpºÍjavaͨÓÃsqlÓï¾ä·¨
SELECT max(id) from table
¸Ã·½·¨ÔÚ¶àÏ̵߳ÈÇé¿öÏ¿ÉÄÜ»áÔì³É²»ÕýÈ·¡£
javaÈýÖÖ·½·¨
1¡¢¸ù¾ÝpsµÄgetGeneratedKeys
PreparedStatement ps = conn.prepareStatement(sql,Statement.RETURN_GENERATED_KEYS); //ºìÉ«Êǹؼü
ps.executeUpdate(); //Ö´Ðкó
ResultSet rs = ps.getGeneratedKeys ......
PHPµÄÒ»¸öÊý¾Ý¿â²Ù×÷Àà,ÒÔUTF8¸ñʽдÈë,Êý¾Ý¿âÄÚÖ±½ÓÏÔʾÕý³£ÖÐÎÄ,·ÀÖ¹²éѯ³ö´í
/**
* @author xggxnn
* ±¾ÀàÓÃÓÚʵÏÖÓйØÊý¾Ý¿âµÄ·ÃÎÊ
*
*/
class DBConnection {
private $host = "";
private $user = "";
private $pass = "";
private $DBname = "";
public $isConnected = false;
/**
* ¹¹Ôìº ......