PHP $_GET $_POST
$_GET ±äÁ¿ÓÃÓÚÊÕ¼¯À´×Ô method="get" µÄ±íµ¥ÖеÄÖµ¡£
$_GET ±äÁ¿
$_GET ±äÁ¿ÊÇÒ»¸öÊý×飬ÄÚÈÝÊÇÓÉ HTTP GET ·½·¨·¢Ë͵ıäÁ¿Ãû³ÆºÍÖµ¡£
$_GET ±äÁ¿ÓÃÓÚÊÕ¼¯À´×Ô method="get" µÄ±íµ¥ÖеÄÖµ¡£´Ó´øÓÐ GET ·½·¨µÄ±íµ¥·¢Ë͵ÄÐÅÏ¢£¬¶ÔÈκÎÈ˶¼ÊǿɼûµÄ£¨»áÏÔʾÔÚä¯ÀÀÆ÷µÄµØÖ·À¸£©£¬²¢ÇÒ¶Ô·¢Ë͵ÄÐÅÏ¢Á¿Ò²ÓÐÏÞÖÆ£¨×î¶à 100 ¸ö×Ö·û£©¡£
Àý×Ó
<form action="welcome.php" method="get">
Name: <input type="text" name="name" />
Age: <input type="text" name="age" />
<input type="submit" />
</form>
µ±Óû§µã»÷Ìá½»°´Å¥Ê±£¬·¢Ë굀 URL »áÀàËÆÕâÑù£º
http://www.w3school.com.cn/welcome.php?name=Peter&age=37
"welcome.php" ÎļþÏÖÔÚ¿ÉÒÔͨ¹ý $_GET ±äÁ¿À´»ñÈ¡±íµ¥Êý¾ÝÁË£¨Çë×¢Ò⣬±íµ¥ÓòµÄÃû³Æ»á×Ô¶¯³ÉΪ $_GET Êý×éÖÐµÄ ID ¼ü£©£º
Welcome <?php echo $_GET["name"]; ?>.<br />
You are <?php echo $_GET["age"]; ?> years old!
ΪʲôʹÓà $_GET£¿
×¢ÊÍ£ºÔÚʹÓà $_GET ±äÁ¿Ê±£¬ËùÓеıäÁ¿ÃûºÍÖµ¶¼»áÏÔʾÔÚ URL ÖС£ËùÒÔÔÚ·¢ËÍÃÜÂë»òÆäËûÃô¸ÐÐÅϢʱ£¬²»Ó¦¸ÃʹÓÃÕâ¸ö·½·¨¡£²»¹ý£¬ÕýÒòΪ±äÁ¿ÏÔʾÔÚ URL ÖУ¬Òò´Ë¿ÉÒÔÔÚÊղؼÐÖÐÊղظÃÒ³Ãæ¡£ÔÚijЩÇé¿öÏ£¬ÕâÊǺÜÓÐÓõġ£
×¢ÊÍ£ºHTTP GET ·½·¨²»ÊʺϴóÐ͵ıäÁ¿Öµ£»ÖµÊDz»Äܳ¬¹ý 100 ¸ö×Ö·ûµÄ¡£
$_REQUEST ±äÁ¿
PHP µÄ $_REQUEST ±äÁ¿°üº¬ÁË $_GET, $_POST ÒÔ¼° $_COOKIE µÄÄÚÈÝ¡£
PHP µÄ $_REQUEST ±äÁ¿¿ÉÓÃÀ´È¡µÃͨ¹ý GET ºÍ POST ·½·¨·¢ËÍµÄ±íµ¥Êý¾ÝµÄ½á¹û¡£
Àý×Ó
Welcome <?php echo $_REQUEST["name"]; ?>.<br />
You are <?php echo $_REQUEST["age"]; ?> years old!
$_POST ±äÁ¿ÓÃÓÚÊÕ¼¯À´×Ô method="post" µÄ±íµ¥ÖеÄÖµ¡£$_POST ±äÁ¿$_POST ±äÁ¿ÊÇÒ»¸öÊý×飬ÄÚÈÝÊÇÓÉ HTTP POST ·½·¨·¢Ë͵ıäÁ¿Ãû³ÆºÍÖµ¡£$_POST ±äÁ¿ÓÃÓÚÊÕ¼¯À´×Ô method="post" µÄ±íµ¥ÖеÄÖµ¡£´Ó´øÓÐ POST ·½·¨µÄ±íµ¥·¢Ë͵ÄÐÅÏ¢£¬¶ÔÈκÎÈ˶¼ÊDz»¿É¼ûµÄ£¨²»»áÏÔʾÔÚä¯ÀÀÆ÷µÄµØÖ·À¸£©£¬²¢ÇÒ¶Ô·¢ËÍÐÅÏ¢µÄÁ¿Ò²Ã»ÓÐÏÞÖÆ¡£Àý×Ó<form action="welcome.php" method="post">
Enter your name: <input type="text" name="name" />
Enter your age: <input type="text" name="age" />
<input type="submit" />
</form>
µ±Óû§µã»÷Ìá½»°´Å¥£¬URL ²»»áº¬ÓÐÈÎºÎ±íµ¥Êý¾Ý£¬¿´ÉÏÈ¥ÀàËÆÕâÑù£º
http://www.w3s
Ïà¹ØÎĵµ£º
(1) ´ò¿ªphpµÄ°²È«Ä£Ê½
phpµÄ°²È«Ä£Ê½ÊǸö·Ç³£ÖØÒªµÄÄÚǶµÄ°²È«»úÖÆ£¬Äܹ»¿ØÖÆÒ»Ð©phpÖеĺ¯Êý£¬±ÈÈçsystem()£¬
ͬʱ°ÑºÜ¶àÎļþ²Ù×÷º¯Êý½øÐÐÁËȨÏÞ¿ØÖÆ£¬Ò²²»ÔÊÐí¶ÔijЩ¹Ø¼üÎļþµÄÎļþ£¬±ÈÈç/etc/passwd£¬
µ«ÊÇĬÈϵÄphp.iniÊÇûÓдò¿ª°²È«Ä£Ê½µÄ£¬ÎÒÃǰÑËü´ò¿ª£º
safe_mode = on
(2) Óû§×鰲ȫ
µ±safe_mode´ò¿ªÊ±£¬ ......
ÎÒд¹ýµÄ½Ì³Ì²»¶à£¬¶øÇҴ󲿷ֶ¼ÊÇÀ´Ô´ÓÚ±ðÈ˵Ľ̳̣¬²»¹ý£¬ÕâÀïËù½éÉܵ쬶¼ÊÇÈÚÈëÎÒËù×ܽáµÄ¾Ñ飮££ÒýÑÔ
¡¡¡¡
¡¡¡¡PHPµÄÖ´ÐÐЧÂÊÊÇÓÐÄ¿¹²¶ÃµÄ£¬ÕâÒ²ÊÇÎÒϲ»¶ËüµÄÔÒòÖ®Ò»£¬ºÍËü³ÆÎª¾øÃî´îµµµÄMysqlÒÔ¼°ApacheÏëÈںϣ¬²»Äܲ»¾ªÌ¾ÆäЧÂÊÁË¡£PHP¸üÐÂÒ²ºÜ¿ì£¬ÕâÀïÁоÙÁËĿǰ×îа汾PHP4.3.2RC4£¨¼¸ºõûÓÐBUGÁË£¬¹À¼ÆÐ´Í ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands
executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......
1
£®
Çë¶Ô
POSIX
·ç¸ñºÍ¼æÈÝ
Perl
·ç¸ñÁ½ÖÖÕýÔò
±í´ïʽµÄÖ÷Òªº¯Êý½øÐÐÀà±È˵Ã÷
ereg
preg_match
ereg_replace
preg_replace
2
£®
Çë˵Ã÷ÔÚ
php
.ini
ÖÐ
safe_mode
¿ªÆôÖ®ºó¶ÔÓÚ
PHP
ϵͳ
º¯ÊýµÄÓ°Ïì
3
£®
PHP5
ÖÐħÊõ
·½·¨
º¯ÊýÓÐÄö£¬Çë¾ÙÀý˵à ......
ÔÚĬÈÏÇé¿öÏ£¬phpµÄÏîÄ¿ÐèÒª½¨ÔÚApache Group\Apache\htdocsĿ¼Ï²ſÉÒÔÕý³£·ÃÎÊ¡£µ±ÎÒÃÇÐèÒª×Ô¼º½¨Á¢Ò»¸ö²»ÔÚApache Group\Apache\htdocsĿ¼ÏµĹ¤×÷Çø¼äʱ£¬¾ÍÐèÒª¸Ä±äApacheµÄ·ÃÎÊÖ¸¶¨Â·¾¶¡£°²×°ºÃApache ºó£¬ÔÚApache Group\Apache\conf ÏÂÓÐÒ»¸öÎļþhttpd.conf£¬ËüÀïÃæ°üº¬×Å ......