This article will introduce you to the usage of PHP variable names. This is just the name of variable variables. Let's take a look.
Sometimes variable names bring great convenience to programming. That is to say, the variable name can be dynamically named and used. Generally, variables are named using the following statement:
| The Code is as follows: |
Copy code |
|
<? Php
$ A = 'hello ';
?> |
A variable name uses the value of a variable as the name of the variable. In the above example, by using two $ symbols, you can set hello as a variable name, as shown below.
| The Code is as follows: |
Copy code |
<? Php
$ A = 'World ';
?>
|
Using the preceding two statements, two variables are defined: the variable $ a, which contains "hello" and the variable $ hello, and the variable "world ". The following language:
| The Code is as follows: |
Copy code |
|
<? Php
Echo "$ a $ {$ }";
?> |
The output is exactly the same as that of the following statement:
| The Code is as follows: |
Copy code |
|
<? Php
Echo "$ a $ hello ";
?> |
They all output: hello world.
To use the variable name of the array, you need to solve the ambiguity problem. That is, if you write $ a [1], the parser needs to understand whether you mean to treat $ a [1] as a variable, we still need to regard $ a as a variable. [1] refers to the index of this variable. The syntax for solving this ambiguity is: $ {$ a [1]} is used in the first case, and $ {$ a} [1] is used in the second case.
Class attributes can also be accessed through variable attribute names. The variable property name is obtained from the access range of the variable where the call is generated. For example, if your expression is like this: $ foo-> $ bar, the runtime will look for the variable $ bar in the local variable range, the value is used as an attribute name of the $ foo object. It can also be used if $ bar is an array.
Example 1 variable name
| The Code is as follows: |
Copy code |
|
<? Php
Class foo {
Var $ bar = 'I am bar .';
}
$ Foo = new foo ();
$ Bar = 'bar ';
$ Baz = array ('foo', 'bar', 'baz', 'quux ');
Echo $ foo-> $ bar. "n ";
Echo $ foo-> $ baz [1]. "n ";
?>
The above example will output the following results:
I am bar.
I am bar. |
Warning
Note that the variable name cannot be used for super Global Array variables in PHP functions and classes. Variable $ this is also a special variable that cannot be dynamically named.
Discussion on PHP variable security
Variable variables are a very convenient feature of PHP. As mentioned in the manual, variable variables mean that variable names can be dynamically set!
So what security issues will occur when the variable name can be dynamically set? Let's take a look:
| The Code is as follows: |
Copy code |
<? Php
$ A = 'phpinfo ';
$ ();
?>
|
This code is easy to understand. The type of the variable is character-type phpinfo. The variable is dynamically added with (), so the variable is changed to the phpinfo function for dynamic execution!
Following the same principle, we reference the example of variable variables in the manual:
| The Code is as follows: |
Copy code |
<? Php
$ A = 'phpinfo ';
$ {$ ()};
?>
$ () |
This dynamic function is put into a dynamic variable. Of course, this statement is not professional or variable. We will find that the phpinfo function is still executed!
If you have read the manual and the example I have given, you will surely think this is not magical. This is the syntax feature of PHP, and then we will scale this thing into one line:
| The Code is as follows: |
Copy code |
<? Php
$ A = "$ {$ {phpinfo ()}}";
?>
|
This is a nested variable. We just enter the variable content in the previous example. In fact, a function is actually assigned to a variable, as a result, the phpinfo function is finally executed and becomes a prototype of various vulnerabilities and webshells!
You should know why I was asked to go to the PHP manual at the beginning. However, this article is over now. I also missed a point. Daniel said that security is the foundation, we haven't figured out why the variables in the previous example use single quotation marks, and the final example uses double quotation marks. If you think of this question, I think you must have great potential for security. In the future, it will be a great opportunity to be inaccurate!
The difference between single quotes and double quotes in PHP is still related to variables. Let's look at the example below:
| The Code is as follows: |
Copy code |
<? Php
$ A = 'phpinfo ()';
Echo $ a; // output the phpinfo () String
Echo '$ a'; // output $ a string
Echo "$ a"; // output the phpinfo () String
?>
|
The content in double quotation marks is parsed by PHP syntax, And the content in single quotation marks is directly identified as a string!
So this article is really over here, so everyone should understand why the cool-man told me to read more PHP manuals and security is the basic idea.