·ÖÎöPHPµÄob_start()
ÔÚPHP±à³ÌÖÐ, ÎÒÃǾ³£»áÓöµ½Ò»Ð©Ö±½Ó²úÉúÊä³öµÄº¯Êý, Èçpassthru(),readfile(), var_dump() µÈ. µ«ÓÐʱÎÒÃÇÏë°ÑÕâЩº¯ÊýµÄÊä³öµ¼Èëµ½ÎļþÖÐ,»òÕßÏȾ¹ý´¦ÀíÔÙÊä³ö, »òÕß°ÑÕâЩº¯ÊýµÄÊä³ö×÷Ϊ×Ö·û´®À´´¦Àí.
¡¡¡¡ÕâʱÎÒÃǾÍÒªÓõ½ Output Buffer(Êä³ö»º³å) º¯ÊýÁË.
´¦ÀíÊä³ö»º³åµÄº¯ÊýÖ÷ÒªÓÐÕâô¼¸¸ö:
ob_start() ¿ªÊ¼Êä³ö»º³å, ÕâʱPHPÍ£Ö¹Êä³ö, ÔÚÕâÒÔºóµÄÊä³ö¶¼±»×ªµ½Ò»¸öÄÚ²¿µÄ»º³åÀï.
ob_get_contents() Õâ¸öº¯Êý·µ»ØÄÚ²¿»º³åµÄÄÚÈÝ. Õâ¾ÍµÈÓÚ°ÑÕâЩÊä³ö¶¼±ä³ÉÁË×Ö·û´®.
ob_get_ length() ·µ»ØÄÚ²¿»º³åµÄ³¤¶È.
ob_end_flush() ½áÊøÊä³ö»º³å, ²¢Êä³ö»º³åÀïµÄÄÚÈÝ. ÔÚÕâÒÔºóµÄÊä³ö¶¼ÊÇÕý³£Êä³ö.
ob_end_clean() ½áÊøÊä³ö»º³å, ²¢ÈÓµô»º³åÀïµÄÄÚÈÝ.
¡¡¡¡¾Ù¸öÀý×Ó, var_dump()º¯ÊýÊä³öÒ»¸ö±äÁ¿µÄ½á¹¹ºÍÄÚÈÝ, ÕâÔÚµ÷ÊÔµÄʱºòºÜÓÐÓÃ.
µ«Èç¹û±äÁ¿µÄÄÚÈÝÀïÓÐ < , > µÈHTMLµÄÌØÊâ×Ö·û, Êä³öµ½ÍøÒ³Àï¾Í¿´²»¼ûÁË. Ôõô°ìÄØ?
ÓÃÊä³ö»º³åº¯ÊýÄܺÜÈÝÒ׵Ľâ¾öÕâ¸öÎÊÌâ.
ob_start();
var_dump($var);
$out = ob_get_contents();
ob_end_clean();
Õâʱvar_dump()µÄÊä³öÒѾ´æÔÚ $out ÀïÁË. Äã¿ÉÒÔÏÖÔÚ¾ÍÊä³ö:
echo ''<pre>'' . htmlspecialchars($out) . ''</pre>'' ;
»òÕߵȵ½½«À´, ÔÙ»òÕß°ÑÕâ¸ö×Ö·û´®Ë͵½Ä£°å(Template)ÀïÔÙÊä³ö
Ïà¹ØÎĵµ£º
ÎÒд¹ýµÄ½Ì³Ì²»¶à£¬¶øÇҴ󲿷ֶ¼ÊÇÀ´Ô´ÓÚ±ðÈ˵Ľ̳̣¬²»¹ý£¬ÕâÀïËù½éÉܵģ¬¶¼ÊÇÈÚÈëÎÒËù×ܽáµÄ¾Ñ飮££ÒýÑÔ
¡¡¡¡
¡¡¡¡PHPµÄÖ´ÐÐЧÂÊÊÇÓÐÄ¿¹²¶ÃµÄ£¬ÕâÒ²ÊÇÎÒϲ»¶ËüµÄÔÒòÖ®Ò»£¬ºÍËü³ÆΪ¾øÃî´îµµµÄMysqlÒÔ¼°ApacheÏëÈںϣ¬²»Äܲ»¾ªÌ¾ÆäЧÂÊÁË¡£PHP¸üÐÂÒ²ºÜ¿ì£¬ÕâÀïÁоÙÁËÄ¿Ç°×îа汾PHP4.3.2RC4£¨¼¸ºõûÓÐBUGÁË£¬¹À¼ÆÐ´Í ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands
executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......
1
£®
Çë¶Ô
POSIX
·ç¸ñºÍ¼æÈÝ
Perl
·ç¸ñÁ½ÖÖÕýÔò
±í´ïʽµÄÖ÷Òªº¯Êý½øÐÐÀà±È˵Ã÷
ereg
preg_match
ereg_replace
preg_replace
2
£®
Çë˵Ã÷ÔÚ
php
.ini
ÖÐ
safe_mode
¿ªÆôÖ®ºó¶ÔÓÚ
PHP
ϵͳ
º¯ÊýµÄÓ°Ïì
3
£®
PHP5
ÖÐħÊõ
·½·¨
º¯ÊýÓÐÄļ¸¸ö£¬Çë¾ÙÀý˵à ......
1.Ò³ÃæÖ®¼äÎÞ·¨´«µÝ±äÁ¿
get,post,sessionÔÚ×îеÄphp°æ±¾ÖÐ×Ô¶¯È«¾Ö±äÁ¿Êǹرյģ¬ËùÒÔÒª´ÓÉÏÒ»Ò³ÃæÈ¡µÃÌá½»¹ýÀ´µÃ±äÁ¿ÒªÊ¹ÓÃ$_GET['foo'],$_POST['foo'],$_SESSION['foo']À´µÃµ½¡£µ±È»Ò²¿ÉÒÔÐÞ¸Ä×Ô¶¯È«¾Ö±äÁ¿Îª¿ª(php.ini¸ÄΪregister_globals = On)£»¿¼Âǵ½¼æÈÝÐÔ£¬»¹ÊÇÇ¿ÆÈ×Ô¼ºÊìϤеÄд·¨±È½ÏºÃ¡£
2.Win32 ......
×òÌìµ÷ÓÃͬʵÄÒ»¸öjson½Ó¿Ú£¬·¢ÏÖµ÷ÓÃphpÖеĺ¯Êýjson_decodeÎÞ·¨×ª»¯ÎªÊý×é¡£
<?php
$json = "{'d':[['xxx','Öйú','¹ãÎ÷','xjr7670@sina.com','2010-05-01 13:35:02'],['xxx','Öйú','¹ãÎ÷','xjr7670@sina.com','2010-05-01 13:35:02']],'c':13659,'n':759}";
print_r( ......