Requires a validation string to be passed between pages.Randomly generates a string when the page is generated,As a must parameter is passed in all connections. At the same time, save the string in session.
Point connection or form into the page,
Eval (Phpcode) required. Specify the PHP code to be computed.
Example 1
The code is as follows
Copy Code
$string = ' Cup ';$name = ' coffee ';$str = ' This $string is fitted with $name . ';Echo $str;Eval ("$str =" $str "
Basic error handling: Using the Die () functionThe first example shows a simple script that opens a text file:
The code is as follows
Copy Code
$file =fopen ("Welcome.txt", "R");?>
If the file does not exist,
1: Basic Type,Include $module. '. PHP '; $module If you get it directly, then this is a very destructive bug, Linux makes you miserable, Windows let you dump production, such security will be directly discovered by people, and effectively blocked.
(1) Open PHP security mode
PHP's Safe mode is a very important embedded security mechanism, can control some PHP functions, such as system (), while a lot of file operation functions to control the permissions, also does not allow some key word
The general idea of SQL injection attack
• Find SQL injection location;• Judge the background database type;• Determination of xp_cmdshell performance• Discovery Web Virtual directory• Upload asp,php,jsp Trojan;• Get admin privileges;
? PhpPHP
The code is as follows
Copy Code
Session_Start (); if (Isset ($_post[' submit ')) {if ($_session[' security_code '] = = $_post[' Security_code '] &&!empty ($_session[' Security_code '))) {Insert your code for processing the "form"
Must start or continue session and save CAPTCHA string in $_session for
It to being available to the other requests
if (!isset ($_session)) {
Session_Start ();
Header (' cache-control:private ');
}
Create a 65*20 pixel image
$width = 65;
Method One
The code is as follows
Copy Code
echo strip_tags ("Hello world!");
Strip_tags---To remove html and PHP tags from strings
Syntax: string strip_tags (String str [, String allowable_tags])
Description
Introduction to forged cross-station requests
The forgery of cross station requests is more difficult to guard against, and the harm is great, in this way attackers can play pranks, send spam information, delete data, and so on. Common
Take a look at the topic first
echo ' 1 '. Print (2) +3;
The correct result should be
511 for this answer, I say "! @##¥%¥% ... ", there is no way the answer is true.So let's analyze why this is the answer, as the title says, this is a priority
PHP programs sometimes need to execute regularly, using Linux crontab to execute PHP scripts, complete the PHP planning task. For example, the use of a lot of micro-blog app application-Del Piero time Machine, is to achieve the function of sending
1, the security of the server itself
Install Denyhost, prevent SSH brute force, concrete installation method Reference "denyhost prevent SSH brute force to crack, protect your Linux" a article.
Also add an I permission to some important files in
For file upload, we need to use the type = file type of the form in HTML and its enctype attribute. This is what we all need. Of course, we must use the FILE function library, string function library, directory function library, and $ _ FILES [] in
/** Function: encode the URL* Parameter description: $ web_url URL, which does not contain "http: //", for example, 111cn.net* Source: http://111cn.net*/ The code is as follows:Copy code Function HashURL ($ url ){$ SEED = "Mining PageRank is
First, a sessionid is generated during verification; The code is as follows:Copy code Session_start ();$ SessionId = session_id (); // Obtain the sessionid. // Send the session to the client.........?> The client carries the sessionid variable
Php Tutorial file download instanceHere we mainly use the php fopen function to read files one by one and send them to the customer's local device. If you need it, please refer to it. -->Set_time_limit (24*60*60 );If (! Isset ($ _ POST ['submit '])
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.
A Free Trial That Lets You Build Big!
Start building with 50+ products and up to 12 months usage for Elastic Compute Service