[ת]phpÖж¨½ç·û<<<µÄ×÷ÓÃ
phpÖж¨½ç·û<<<µÄ×÷Óà - [phpÓï
ÑÔ
]
[Time:2009-08-18]
°æÈ¨ÉùÃ÷
£º×ªÔØÊ±ÇëÒÔ³¬Á´½ÓÐÎʽ±êÃ÷ÎÄÕÂÔʼ³ö´¦ºÍ×÷ÕßÐÅÏ¢¼°±¾ÉùÃ÷
ת×Ô:http://star210.blogbus.com/logs/44486135.html
ÒòΪPHPÊÇÒ»¸öWeb±à³ÌÓïÑÔ£¬ÔÚ±à³Ì¹ý³ÌÖÐÄÑÃâ»áÓöµ½ÓÃechoÀ´Êä³ö´ó¶ÎµÄhtmlºÍjavascript
½Å
±¾µÄÇé¿ö£¬Èç¹ûÓô«Í³µÄÊä³ö·½·¨
——°´×Ö·û´®Êä³öµÄ»°£¬¿Ï¶¨ÒªÓдóÁ¿µÄתÒå·ûÀ´¶Ô×Ö·û´®ÖеÄÒýºÅµÈÌØÊâ×Ö·û½øÐÐתÒ壬ÒÔÃâ³öÏÖÓï·¨´íÎó¡£Èç¹ûÊÇÒ»Á½´¦»¹¿ÉÒÔÈÝÈÌ£¬µ«ÊÇÒªÊÇÒ»¸öÍêÕûµÄ
htmlÎı¾»òÕßÊÇÒ»¸ö200ÐеÄjsÎÒÏëÊÇ˶¼»á±ÀÀ£µÄ¡£Õâ¾ÍÊÇPHPΪʲôҪÒýÈëÒ»¸ö¶¨½ç·ûµÄÔÒò——ÖÁÉÙÒ»´ó²¿·ÖÔÒòÊÇÕâÑùµÄ¡£
1.PHP¶¨½ç·ûµÄ×÷ÓþÍÊǰ´ÕÕÔÑù£¬°üÀ¨»»ÐиñʽʲôµÄ£¬Êä³öÔÚÆäÄÚ²¿µÄ¶«Î÷£»
2.ÔÚPHP¶¨½ç·ûÖеÄÈκÎÌØÊâ×Ö·û
¶¼²»ÐèҪתÒ壻
3.PHP¶¨½ç·ûÖеÄPHP±äÁ¿»á±»Õý³£µÄÓÃÆäÖµÀ´Ìæ»»¡£
PHPÖе͍½ç·û¸ñʽÊÇÕâÑùµÄ£º
<<<Eof……Eof
;
¿´ÆðÀ´ºÜ¼òµ¥£¬µ«ÊÇÆäÖÐÓÐÐí¶àµØ·½ÐèҪעÒâ¡£
Ê×ÏÈÔÚ<<<Ö®ºóµÄ×Ö·ûEofÊÇ×Ô¼º¶¨ÒåµÄ£¬Ëæ±ãʲô¶¼ÊÇ¿ÉÒÔµÄ(±ÈÈçAAA¶¼¿ÉÒÔ)£¬µ«Êǽáβ´¦µÄ×Ö·ûÒ»¶¨ÒªºÍËûÒ»Ñù£¬ËûÃÇÊÇ
³É¶Ô³öÏֵ쬾ÍÏñ{}ÕâÑùµÄ——ÕâÊÇ×î»ù±¾µÄ¡£
ÔÚPHP¶¨½ç·ûʹÓõĹý³ÌÖУ¬µÚ¶þ¸öÐèҪעÒâµÄÎÊÌâ——Ò²ÊÇ×î¾³£³öÏÖÎÊÌâµÄµØ·½£º
½áβµÄÒ»ÐУ¨ÈçÉÏÀýµÄEof;£©£¬Ò»¶¨ÒªÁíÆðÒ»ÐУ¬²¢ÇÒ¸ÄÐгýÁËEof;Õâ¸ö¶¨½ç·û½áβ±êʶ֮Íâ²»ÄÜÓÐÈÎºÎÆäËû×Ö·û£¬Ç°ºó¶¼²»ÄÜÓУ¬°üÀ¨¿Õ¸ñ¡£Èç¹û
ÔÚ±¾ÐÐ×îǰ»òÕß×îºó³öÏÖ¿Õ¸ñ£¬ÖƱí·ûµÄ»°£¬Äã»áÊÕµ½Ò»¸öÕâÑùµÄ´íÎóÐÅÏ¢£º
Parse error: parse error,
unexpected $end in……£¬ÌáʾÄãÓï·¨´íÎó£»
µÚÈý¸öÐèҪעÒâµÄÊÇ£¬Èç¹ûÔÚ¶¨½ç·ûÖмä³öÏÖÓÐPHPµÄ±äÁ¿£¬ÄãÖ»ÐèÒªÏñÔÚÆäËü×Ö·û´®ÖÐÊä³öÒ»Ñùд¾ÍÐÐÁË£¬ÀýÈç
<<<Eofhello{$name}Eof
;
±äÁ¿$nameÖ®ËùÒÔÒªÓÃ{}À¨ÆðÀ´ÊÇÒª¸æËßPHP½âÎöÆ÷ÕâÊÇÒ»¸öPHP±äÁ¿£¬Æäʵ²»ÓÃÒ²ÊÇ¿ÉÒԵ쬵«ÊÇÓпÉÄÜ»á²úÉúÆçÒ壬ÀýÈçÄãµÄ±äÁ¿ºóÃæ¸ÕºÃ²»
ÊÇÒ»×Öĸ»òÕßÌØÊâ·ûºÅʲôµÄ»áÔõôÑùÄØ£¿Ç§Íò²»ÄÜÓÐÕâÑùµÄд·¨
<<<Eofhello<?php
echo
$name
?>
Eof;
ÕâÑùµÄÇé¿ö£¬ÄãͬÑù»áÊÕµ½Ò»¸öÓï·¨´íÎóµÄÐÅÏ¢
Ïà¹ØÎĵµ£º
//È¥³ý script ½Å ±¾
function delScript($string){
$pregfind = array("/<script.*>.*<\/script>/siU",'/on(mousewheel|mouseover|click|load|onload|submit|focus|blur)="[^"]*"/i');
$pregreplace = array('','');
$string = preg_replace($pregfind, $pregreplace, $string);
return $str ......
¡¡×î½üÔÚÕÛÌÚ PHP + MYSQL
µÄ±à³Ì¡£Á˽âÁËһЩ PHP SQL ×¢Èë¹¥»÷
µÄ֪ʶ£¬ÓÚÊÇдÁËÕâÆªÎÄÕ¡¡http://www.xiaohui.com/weekly/20070314.htm£¬×ܽáһϾÑé¡£ÔÚÎÒ¿´À´£¬Òý·¢ SQL ×¢Èë¹¥»÷
µÄÖ÷ÒªÔÒò£¬ÊÇÒòΪÒÔÏÂÁ½µãÔÒò£º
¡¡¡¡1. php ÅäÖÃÎļþ php.ini ÖÐµÄ magic_quotes_gpc
Ñ¡ÏîûÓдò¿ª£¬±»ÖÃΪ off
¡¡¡¡2. ¿ª·¢ ......
phpÖÐis_dirÖÐÄÜ·ñÕýÈ··µ»ØÈ·ÊµºÍĿ¼ȨÏÞÉèÖÃÓйØÏµ¡£¡£¡£
ŪÁ˺þᣡ£Ò»Ö±ÒÔΪ²»ÊÇȨÏÞÎÊÌâ¡£
»·¾³ÊÇiis6.0+php5.2
ÍøÕ¾Ä¿Â¼ÊÇÔÚd:\vhost\web1
ÒªÓÃis_dirº¯Êý±ØÐëÉèÖÃȨÏÞd:\£¬d:\vhostΪ¿É¶Á¿ÉÁÐĿ¼
Ò²¾ÍÊÇweb1Ç°Ãæ¼¸¼¶µÄĿ¼¶¼ÒªÓпɶÁ¿ÉÁÐĿ¼µÄȨÏÞ¡£ ......
×î½üÓÐÈËÔÚÕбêÒª×ö¸öÏñ£ºwww.webjianzhi.com ÕâÑùµÄÈ˲ÅÕ¾£¬³õ¿´£¬Õâ¸öÍøÂç¼æÖ°Íø£¬½çÃæ»¹ÊDZȽÏÇåÎúµÄ¡£
ÕûÌå·ÖÎöÁËһϣ¬Ò»¸öÐÂÎÅÎÄÕ·¢²¼ÏµÍ³£¬Õâ¸ö²»ÊǺÜÄÑ£¬ÁíÒ»¸ö¾ÍÊÇ×ֶε÷ÓÃϵͳ£¬¾ÍÊÇÊ×Ò³µÄÖ°Òµ½éÉÜ£¬¼æÖ°ÈËÆø£¬µÄÕâЩµ÷Óá£
ÁíÒ»¸ö¾ÍÊÇ»áÔ±·¢²¼ÏµÍ³¡£
Õû¸öÓñí¸ñ²¼¾Ö£¬ÃÀ¹¤Éϲ»´æÔ ......