phpÓйصļ¸ÖÖ³£¼û°²È«Ïê½â
(1) ´ò¿ªphpµÄ°²È«Ä£Ê½
phpµÄ°²È«Ä£Ê½ÊǸö·Ç³£ÖØÒªµÄÄÚǶµÄ°²È«»úÖÆ£¬Äܹ»¿ØÖÆÒ»Ð©phpÖеĺ¯Êý£¬±ÈÈçsystem()£¬
ͬʱ°ÑºÜ¶àÎļþ²Ù×÷º¯Êý½øÐÐÁËȨÏÞ¿ØÖÆ£¬Ò²²»ÔÊÐí¶ÔijЩ¹Ø¼üÎļþµÄÎļþ£¬±ÈÈç/etc/passwd£¬
µ«ÊÇĬÈϵÄphp.iniÊÇûÓдò¿ª°²È«Ä£Ê½µÄ£¬ÎÒÃǰÑËü´ò¿ª£º
safe_mode = on
(2) Óû§×鰲ȫ
µ±safe_mode´ò¿ªÊ±£¬safe_mode_gid±»¹Ø±Õ£¬ÄÇôphp½Å±¾Äܹ»¶ÔÎļþ½øÐзÃÎÊ£¬¶øÇÒÏàͬ
×éµÄÓû§Ò²Äܹ»¶ÔÎļþ½øÐзÃÎÊ¡£
½¨ÒéÉèÖÃΪ£º
safe_mode_gid = off
Èç¹û²»½øÐÐÉèÖ㬿ÉÄÜÎÒÃÇÎÞ·¨¶ÔÎÒÃÇ·þÎñÆ÷ÍøÕ¾Ä¿Â¼ÏµÄÎļþ½øÐвÙ×÷ÁË£¬±ÈÈçÎÒÃÇÐèÒª
¶ÔÎļþ½øÐвÙ×÷µÄʱºò¡£
(3) °²È«Ä£Ê½ÏÂÖ´ÐгÌÐòÖ÷Ŀ¼
Èç¹û°²È«Ä£Ê½´ò¿ªÁË£¬µ«ÊÇÈ´ÊÇÒªÖ´ÐÐijЩ³ÌÐòµÄʱºò£¬¿ÉÒÔÖ¸¶¨ÒªÖ´ÐгÌÐòµÄÖ÷Ŀ¼£º
safe_mode_exec_dir = D:/usr/bin
Ò»°ãÇé¿öÏÂÊDz»ÐèÒªÖ´ÐÐʲô³ÌÐòµÄ£¬ËùÒÔÍÆ¼ö²»ÒªÖ´ÐÐϵͳ³ÌÐòĿ¼£¬¿ÉÒÔÖ¸ÏòÒ»¸öĿ¼£¬
È»ºó°ÑÐèÒªÖ´ÐеijÌÐò¿½±´¹ýÈ¥£¬±ÈÈ磺
safe_mode_exec_dir = D:/tmp/cmd
µ«ÊÇ£¬ÎÒ¸üÍÆ¼ö²»ÒªÖ´ÐÐÈκγÌÐò£¬ÄÇô¾Í¿ÉÒÔÖ¸ÏòÎÒÃÇÍøÒ³Ä¿Â¼£º
safe_mode_exec_dir = D:/usr/www
(4) °²È«Ä£Ê½Ï°üº¬Îļþ
Èç¹ûÒªÔÚ°²È«Ä£Ê½Ï°üº¬Ä³Ð©¹«¹²Îļþ£¬ÄÇô¾ÍÐÞ¸ÄÒ»ÏÂÑ¡Ï
safe_mode_include_dir = D:/usr/www/include/
Æäʵһ°ãphp½Å±¾Öаüº¬Îļþ¶¼ÊÇÔÚ³ÌÐò×Ô¼ºÒѾдºÃÁË£¬Õâ¸ö¿ÉÒÔ¸ù¾Ý¾ßÌåÐèÒªÉèÖá£
(5) ¿ØÖÆphp½Å±¾ÄÜ·ÃÎʵÄĿ¼
ʹÓÃopen_basedirÑ¡ÏîÄܹ»¿ØÖÆPHP½Å±¾Ö»ÄÜ·ÃÎÊÖ¸¶¨µÄĿ¼£¬ÕâÑùÄܹ»±ÜÃâPHP½Å±¾·ÃÎÊ
²»Ó¦¸Ã·ÃÎʵÄÎļþ£¬Ò»¶¨³Ì¶ÈÉÏÏÞÖÆÁËphpshellµÄΣº¦£¬ÎÒÃÇÒ»°ã¿ÉÒÔÉèÖÃΪֻÄÜ·ÃÎÊÍøÕ¾Ä¿Â¼£º
open_basedir = D:/usr/www
(6) ¹Ø±ÕΣÏÕº¯Êý
Èç¹û´ò¿ªÁ˰²È«Ä£Ê½£¬ÄÇôº¯Êý½ûÖ¹ÊÇ¿ÉÒÔ²»ÐèÒªµÄ£¬µ«ÊÇÎÒÃÇΪÁ˰²È«»¹ÊÇ¿¼ÂǽøÈ¥¡£±ÈÈ磬
ÎÒÃǾõµÃ²»Ï£ÍûÖ´ÐаüÀ¨system()µÈÔÚÄǵÄÄܹ»Ö´ÐÐÃüÁîµÄphpº¯Êý£¬»òÕßÄܹ»²é¿´phpÐÅÏ¢µÄ
phpinfo()µÈº¯Êý£¬ÄÇôÎÒÃǾͿÉÒÔ½ûÖ¹ËüÃÇ£º
disable_functions = system,passthru,exec,shell_exec,popen,phpinfo
Èç¹ûÄãÒª½ûÖ¹ÈκÎÎļþºÍĿ¼µÄ²Ù×÷£¬ÄÇô¿ÉÒԹرպܶàÎļþ²Ù×÷
disable_functions = chdir,chroot,dir,getcwd,opendir,readdir,scandir,fopen,unlink,delete,copy,mkdir, rmdir,rename,file,file_get_contents,fputs,fwrite,chgrp,chmod,chown
ÒÔÉÏÖ»ÊÇÁÐÁ˲¿·Ö²»½Ð³£ÓõÄÎļþ´¦Àíº¯Êý£¬ÄãÒ²¿ÉÒÔ°ÑÉÏÃæÖ´ÐÐÃüÁÊýºÍÕâ¸öº¯Êý½áºÏ£¬
¾ÍÄܹ»µÖÖÆ´ó²¿·ÖµÄphpshellÁË¡£
Ïà¹ØÎĵµ£º
<?php
$zip_filename = "testpm.zip";
$zip_filename = key_exists('zip', $_GET) && $_GET['zip']?$_GET['zip']:$zip_filename;
$zip_filepath = str_replace('\\', '/', dirname(__FILE__)) . '/' . $zip_filename;
if(!is_file($zip_filepath))
{
die('Îļþ"'.$zip_ ......
JAVAÎļþ²Ù×÷×ܽá
FileÀà
File f = new File(path);
pathΪʵ¼Ê·¾¶£¬¸Ã·¾¶¿ÉÒÔÊÇÎļþ£¬»òÎļþ¼Ð£¬Ò²¿ÉÒÔÊDz»´æÔڵġ£
f.exists() ¿ÉÒÔÅжϸ÷ÊÇ·ñ´æÔÚ¡£
f.isDirectory() ¿ÉÒÔÅжÏÊÇ·ñÊÇÎļþ¼Ð¡£
f.mkdirs(); µÝ¹é´´½¨Îļþ¼Ð
FileºÍÊäÈëÊä³öÁ÷Ö®¼äŦ´øFileInutStream£¬FileOutputStream
URL url = new URL(strUr ......
1. ¼ÆËã»úÏà¹Ø×¨Òµ±¾¿Æ¼°ÒÔÉÏѧÀú£¬2ÄêÒÔÉÏÏà¹Ø¹¤×÷¾Ñé
2. ¾«Í¨PHP+Mysql¡¢AjaxµÈÏà¹Ø¿ª·¢
3. ¾«Í¨Javascript¡¢Html¡¢CSSµÈǰ¶Ë¼¼Êõ£¬²¢ÄÜÊìÁ·Ê¹ÓÃPrototype¡¢jQueryµÈ¿ªÔ´¿ò¼Ü
4. ¾«Í¨Mysql¡¢SqlServerµÈÊý¾Ý¿â
5. ÊìϤMVCģʽ¿ª·¢
6. ÊìϤWINDOWS¡¢LINUX¡¢UNIXµÈ²Ù×÷ϵͳ
7. ÊìϤApache¡¢IIS¡¢ZENDµÈÓ¦ÓÃ
3 ......
// µ¥ÐÐ×¢½â
/* */ ¶àÐÐ×¢½â
ÒýºÅµÄʹÓÃ
’ ’ µ¥ÒýºÅ,ûÓÐÈκÎÒâÒå,²»¾Èκδ¦ÀíÖ±½ÓÄùýÀ´;
" "Ë«ÒýºÅ,php¶¯Ì¬´¦ÀíÈ»ºóÊä³ö,Ò»°ãÓÃÓÚ±äÁ¿.
±äÁ¿ÐÎ̬:
Ò»ÖÖÊÇTrue ¼´ ÕæµÄ;
ÁíÒ»ÖÖÊÇFalse ¼´¼ÙµÄ
³£¼û±äÁ¿ÐÎ̬:
string ×Ö´®(Êý×Ö\ºº×Ö\µÈµÈ)
integer ÕûÊý(1¡¢2¡¢3¡¢4¡¢5¡¢0¡¢-1¡¢-2¡¢µÈµ ......