php ·À×¢Èë¹¥»÷º¯Êý
/*php ·À×¢È뺯Êý
string $feifa ÏÞÖÆÔªËØ×é³É
ÈçÓзǷ¨×Ö·ûÌø×ªµ½ÉÏÒ»Ò³ ·µ»Ø 0 ûÓзµ»Ø 1
*/
//ʹÓ÷½·¨
//$feifa=array("select","delete","from","update","create","destory","drop","alter","and","or","like","exec","count","*","chr","mid","master","truncate","char","declare",";","-","+");
//$arrpostget=array("http://www.baidu.select cretecomdmin","wangw");
//echo saftsql($feifa,$arrpostget);
function saftsql($feifa,$arrpostget){
//
$arrpostget=array_merge((array)$HTTP_PSOT_VARS,(array)$HTTP_GET_VARS);
if($arrpostget){
foreach($arrpostget as $key=>$value){
for($i=0;$i<count($feifa);$i++){
//ÕÒ·Ç·¨×Ö·ûÔÚ$valueÖеÄλÖÃ
$flag=strpos($value,$feifa[$i]);
if($flag)
{
echo "<script
type=\"text/javascript\">alert('URLÓзǷ¨×Ö·û');</script>";
 
Ïà¹ØÎĵµ£º
ÏÖÔÚÊг¡ÉϵÄoa»ù±¾ÉϿɹé½áΪÁ½´óÕóÓª£¬¼´phpÕóÓªºÍjavaÕóÓª¡£µ«¶Ô½Ó´¥oa²»¾ÃµÄÓû§À´Ëµ£¬¿´µ½µÄÍùÍùÖ»ÊÇËüÃǵıíÏֻ࣬ÊÇÃ÷ÏԵļ۸ñ²îÒ죬ȴºÜÄÑ¿´³öËüÃÇÖ®¼äµÄʵ¼Ê²îÒì¡£Æäʵ£¬ PHP + MYSQL ²»ÖµÇ®²»½ö½ö¾ÖÏÞÓÚoaÈí¼þ£¬¶øÊÇÕûÌåÉÏPHP + MYSQL¿ª·¢µÄÈí¼þ¶¼²»Èçjava¿ª·¢µÄÈí¼þֵǮ¡£ÎªÊ²Ã´PHP + MYSQL µÄOAΪʲô²»ÖµÇ®Ä ......
ÔÚÏßʵʱÁÄÌìϵͳ£¬Ò»Ö±ÊÇÒ»¸ö±È½ÏÂé·³µÄ¶«Î÷¡£
Ò»°ãʵÏÖÔÚÏßʵʱÁÄÌ죬ÊÇÀûÓÃJSÔÚ¿Í»§¶ËʹÓÃajaxÿ¸ôÒ»¶¨µÄʱ¼ä¾Í·µ»Ø·þÎñÆ÷ÇëÇóÊý¾Ý£¬Èç¹ûÓÐеÄÁÄÌìÐÅÏ¢ÔòÓÃJS³ÊÏÖ¸øÓû§
ÎÒÃDz»ËµÕâÑù×öµÄÀû±×£¬Ö±½ÓÇÐÈëÕýÌ⣬ÈçºÎÀ´ÊµÏÖ·þÎñÆ÷ÍÆµÄÔÚÏßÁÄÌìϵͳ
Ê×ÏÈ£¬ÎÒÏÈÇë´ó¼Ò¿´Ò»¸öÀý×Ó
¸´ÖÆ´úÂë
<?php
while(true){
&n ......
ÔÚÏîÄ¿¿ª·¢Öз¢ÏÖ¶ÔphpµÄÎĵµÈ±ÉÙ¹ÜÀí,±ðÈËдÁËÒ»¸ö,¹¦Äܲ»¶à
<?php
/**
* ˈ̞: doc
*
ÃèÊö: ÎĵµÉú³ÉÀà
* ÆäËû: ¿ÉÒÔ¶ÔĿ¼½øÐйýÂË,ÉèÖúÃԴĿ¼ºó,ÇëÓþø¶Ô·¾¶Ö¸¶¨Éú³ÉĿ¼,ģʽ¿Éµ÷,ģʽ
*
1Ϊ³£¹æÀàÐÍ,¼´ÒÔ Ð±Ïß**¿ªÍ·,ÒÔ*бÏß ½áÊø
* 2ΪÀ©Õ¹ÀàÐÍ,·²ÊÇ Ð±Ïß*¿ªÍ·ÒÔ*бÏß ½áÊøµÄ²¿·Ö¶¼½«³ÉΪÎÄ ......
Ò»Ö±ÈÏΪphpÖÐ×Ö×Ö·û´®±È½ÏÖ±½ÓÓÃ==À´Åжϻ¹ÊǺܷ½±ãµÄ,µ«½ñÌìÓöµ½µÄÒ»¸öÎÊÌâ,³¹µ×ÈÃÎÒÃ÷°×ÁËʹÓÃstrcmpµÄ±ØÒªÐÔ.Õâ¸öÎÊÌâºÜ¶àÀÏÊÖ¶¼¿ÉÄÜ»áºöÂÔµÄ.
½ñÌìÔڵǼ×Ô¼º×öµÄ³ÌÐòʱ,ÔÚÊäÈëÑéÖ¤Âëºó,ÏëÖ±½Ó°´Ð¡¼üÅÌÉϻسµµÇ¼(³ÌÐò¼ì²éÁ˻سµÊ¼þ)£¬½á¹û°´»Ø³µ°´³ÉÁ˼üÅÌÉϻسµ¼üÅÔ±ßСÊýµÄÄǸö¼ü,ÑéÖ¤ÂëÀ¸¾Í¶àÊäÈëÁËÒ»¸öµã¡£ÓÉÓÚ ......
¡¡sessionÊÇÍøÕ¾±£´æÓû§ÐÅÏ¢µÄÒ»ÖÖÊֶΣ¬Ó¦ÓÃÏ൱¹ã·º¡£ÀýÈçµÚÎå½ìÅÅÐаñ¾ÍʹÓÃÁËsession¡£¾¹ý¶ÔµÚÎå½ìÅÅÐаñµÄÐ޸ģ¬ÎÒ×ܽáÁËÒ»ÏÂphpÖÐsessionµÄÓ÷¨¡£
£¨Ò»£©¿ªÊ¼session
¡¡¡¡ÔÚÿһ´ÎʹÓÃsession֮ǰ£¬¶¼Òª¼ÓÉÏÕâÒ»¾ä£º“session_start();”¡£¹ËÃû˼Ò壬Õâ¸öº¯ÊýµÄ×÷ÓþÍÊÇ¿ªÊ¼Ê¹ÓÃsession¡£
£¨¶þ£©×¢ ......