[ת]PHP SQL ×¢Èë¹¥»÷µÄ¼¼ÊõʵÏÖÒÔ¼°Ô¤·À°ì·¨
¡¡¡¡1. php ÅäÖÃÎļþ php.ini ÖÐµÄ magic_quotes_gpc Ñ¡ÏîûÓдò¿ª£¬±»ÖÃΪ off
¡¡¡¡2. ¿ª·¢ÕßûÓжÔÊý¾ÝÀàÐͽøÐмì²éºÍתÒå
¡¡¡¡²»¹ýÊÂʵÉÏ£¬µÚ¶þµã×îΪÖØÒª¡£ÎÒÈÏΪ, ¶ÔÓû§ÊäÈëµÄÊý¾ÝÀàÐͽøÐмì²é£¬Ïò MYSQL Ìá½»ÕýÈ·µÄÊý¾ÝÀàÐÍ£¬ÕâÓ¦¸ÃÊÇÒ»¸ö web ³ÌÐòÔ±×î×î»ù±¾µÄËØÖÊ¡£µ«ÏÖʵÖУ¬³£³£ÓÐÐí¶àС°×ʽµÄ Web ¿ª·¢ÕßÍüÁËÕâµã, ´Ó¶øµ¼ÖºóÃŴ󿪡£
¡¡¡¡ÎªÊ²Ã´ËµµÚ¶þµã×îΪÖØÒª£¿ÒòΪÈç¹ûûÓеڶþµãµÄ±£Ö¤£¬magic_quotes_gpc Ñ¡Ï²»ÂÛΪ on£¬»¹ÊÇΪ off£¬¶¼ÓпÉÄÜÒý·¢ SQL ×¢Èë¹¥»÷¡£ÏÂÃæÀ´¿´Ò»Ï¼¼ÊõʵÏÖ£º
Ò». magic_quotes_gpc = Off ʱµÄ×¢Èë¹¥»÷
¡¡¡¡magic_quotes_gpc = Off ÊÇ php ÖÐÒ»Öַdz£²»°²È«µÄÑ¡Ïа汾µÄ php ÒѾ½«Ä¬ÈϵÄÖµ¸ÄΪÁË On¡£µ«ÈÔÓÐÏ൱¶àµÄ·þÎñÆ÷µÄÑ¡ÏîΪ off¡£±Ï¾¹£¬ÔٹŶµÄ·þÎñÆ÷Ò²ÊÇÓÐÈËÓõġ£
¡¡¡¡µ±magic_quotes_gpc = On¡¡Ê±£¬Ëü»á½«Ìá½»µÄ±äÁ¿ÖÐËùÓÐµÄ '(µ¥ÒýºÅ)¡¢"(Ë«ºÅºÅ)¡¢\(·´Ð±Ïß)¡¢¿Õ°××Ö·û£¬¶¼ÎªÔÚÇ°Ãæ×Ô¶¯¼ÓÉÏ \¡£ÏÂÃæÊÇ php µÄ¹Ù·½ËµÃ÷£º
magic_quotes_gpc boolean Sets the magic_quotes state for GPC (Get/Post/Cookie) operations. When magic_quotes are on, all ' (single-quote), " (double quote), \ (backslash) and NUL's are escaped with a backslash automaticallyÈç¹ûûÓÐתÒ壬¼´ off Çé¿öÏ£¬¾Í»áÈù¥»÷ÕßÓлú¿É³Ë¡£ÒÔÏÂÁвâÊԽű¾ÎªÀý£º
<? if ( isset($_POST["f_login"] ) ) { // Á¬½ÓÊý¾Ý¿â... // ...´úÂëÂÔ... // ¼ì²éÓû§ÊÇ·ñ´æÔÚ $t_strUname = $_POST["f_uname"]; $t_strPwd = $_POST["f_pwd"]; $t_strSQL = "SELECT * FROM tbl_users WHERE username='$t_strUname' AND password = '$t_strPwd' LIMIT 0,1"; if ( $t_hRes = mysql_query($t_strSQL) ) { // ³É¹¦²éѯ֮ºóµÄ´¦Àí. ÂÔ... } } ?> <html><head><title>sample test</title></head> <body> <form method=post action=""> Username: <input type="text" name="f_uname" size=30><br> Password: <input type=text name="f_pwd" size=30><br> <input type="submit" name="f_login" value="µÇ¼"> </form> </body>ÔÚÕâ¸ö½Å±¾ÖУ¬µ±Óû§ÊäÈëÕý³£µÄÓû§ÃûºÍÃÜÂ룬¼ÙÉèÖµ·Ö±ðΪ zhang3¡¢abc123£¬ÔòÌá½»µÄ SQL Óï¾äÈçÏ£º
SELECT * FROM tbl_users WHERE username='zhang3' AND password = 'abc123' LIMIT 0,1Èç¹û¹¥»÷ÕßÔÚ username ×Ö¶ÎÖÐÊäÈ룺zhang3' OR 1=1 #£¬ÔÚ password ÊäÈë abc123£¬ÔòÌá½»µÄ SQL Óï¾ä±ä³ÉÈçÏ£º
SELECT * FROM tbl_users WHERE username='zhang3' OR 1=1 #' AND password = 'abc123' LIMIT 0,1ÓÉÓÚ # ÊÇ mysqlÖеÄ×¢ÊÍ·û, #Ö®ºóµÄÓï¾ä²»±»Ö´ÐУ¬ÊµÏÖÉÏÕâÐÐÓï¾ä¾Í³ÉÁË£º
SELECT * FROM tbl_users WHERE username='zhang3' OR 1=1ÕâÑù¹¥»÷Õ߾ͿÉÒÔÈƹýÈÏÖ¤ÁË¡£Èç¹û¹¥»÷ÕßÖªµÀÊý¾Ý¿â½á¹¹£¬ÄÇôËü¹¹½¨Ò»¸ö UNION SELECT£¬ÄǾ͸üΣÏÕÁË£º
¡¡¡¡¼ÙÉèÔÚ username ÖÐÊäÈ룺zhang3 ' OR 1 =1 UNION select cola, colb,cold FROM tbl_b #
¡¡¡¡ÔÚpassword ÊäÈë: abc123£¬
¡¡¡¡ÔòÌá½»µÄ SQL Óï¾ä±ä³É£º
SELECT * FROM tbl_users WHERE username='zhang3 ' OR 1 =1 UNION select cola, colb,cold FROM tbl_b #' AND password = 'abc123' LIMIT 0,1ÕâÑù¾ÍÏ൱ΣÏÕÁË¡£Èç¹ûagic_quotes_gpcÑ¡ÏîΪ on£¬ÒýºÅ±»×ªÒ壬ÔòÉÏÃæ¹¥»÷Õß¹¹½¨µÄ¹¥»÷Óï¾ä¾Í»á±ä³ÉÕâÑù£¬´Ó¶øÎÞ·¨´ïµ½ÆäÄ¿µÄ£º
SELECT * FROM tbl_users WHERE username='zhang3\\' OR 1=1 #' AND password = 'abc123' LIMIT 0,1 SELECT * FROM tbl_users WHERE username='zhang3 \\' OR 1 =1 UNION select cola, colb,cold FROM tbl_b #' AND password = 'abc123' LIMIT 0,1¶þ. magic_quotes_gpc = On ʱµÄ×¢Èë¹¥»÷
¡¡¡¡µ± magic_quotes_gpc = On ʱ£¬¹¥»÷ÕßÎÞ·¨¶Ô×Ö·ûÐ͵Ä×ֶνøÐÐ SQL ×¢Èë¡£Õâ²¢²»´ú±íÕâ¾Í°²È«ÁË¡£Õâʱ£¬¿ÉÒÔͨ¹ýÊýÖµÐ͵Ä×ֶνøÐÐSQL×¢Èë¡£
¡¡¡¡ÔÚ×îаæµÄ MYSQL 5.x ÖУ¬ÒѾÑϸñÁËÊý¾ÝÀàÐ͵ÄÊäÈ룬ÒÑĬÈϹرÕ×Ô¶¯ÀàÐÍת»»¡£ÊýÖµÐ͵Ä×ֶΣ¬²»ÄÜÊÇÒýºÅ±ê¼ÇµÄ×Ö·ûÐÍ¡£Ò²¾ÍÊÇ˵£¬¼ÙÉè uid ÊÇÊýÖµÐ͵ģ¬ÔÚÒÔÇ°µÄ mysql °æ±¾ÖУ¬ÕâÑùµÄÓï¾äÊǺϷ¨µÄ£º
ÍƼöÐÅÏ¢
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- php³£ÓÃÕýÔò±í´ïʽ
- phpÐÔÄܼà²âÄ£¿éXHProf
- ÈÃCI¿ò¼ÜÖ§³Öservice²ã
- ʹÓÃPHPÉú³É´øLOGOµÄ¸öÐÔ»¯¶þάÂëͼÏñ
- ¹ØÓÚCodeIgniterÄã¿ÉÄܲ»ÖªµÀµÄ5¸ö֪ʶµã
- Memcache ºÁÃ뼶³¬Ê±¼°ÆäËû³£¼ûÎÊÌâ»ã×Ü
- [PHP±Ê¼Ç]PHPQueryÒ»¸ö´¦ÀíDOMµÄÀûÆ÷
ÈÈÃÅÐÅÏ¢
- nohup: redirecting stderr to stdou....
- ʹÓÃlog_formatΪNginx·þÎñÆ÷ÉèÖøüÏêϸµÄÈÕÖ¾¸ñʽ
- jquery easyUI--dataGrid-Json
- [Ô´´]·ÂGoogle Reader¡¢ÐÂÀË΢²©¡¢ÌÚѶ΢²©µ....
- ÀûÓÃKeepalived+mysql¹¹½¨¸ß¿ÉÓÃMySQLË«Ö÷×Ô¶....
- Nginx+keepalivedʵÏÖ¸ºÔؾùºâºÍË«»úÈȱ¸¸ß¿ÉÓÃ
- jqueryʵÏÖÒ³Ãæ¼ÓÔؽø¶ÈÌõ
- Rolling cURL: PHP²¢·¢×î¼Ñʵ¼ù
- codeigniter ·ÓÉÖÕ¼«ÓÅ»¯(url rewrite)
- linuxÏÂÉèÖÃsshÎÞÃÜÂëµÇ¼
×î½ü¸üÐÂ
- PHP»ñÈ¡Óû§µÄÕæʵIP£¬²¢ÅжÏÊÇ·ñÄÚÍøIP
- PHP ´íÎóÈÕÖ¾ error_log
- ÀûÓÃbigpipe»úÖÆʵÏÖÒ³ÃæÄ£¿éµÄÒì²½äÖȾ chunked¼¼Êõ
- php¿ØÖÆÎļþÏÂÔØËÙ¶È
- js + php ¶ÁÈ¡¡¢²¥·ÅÊÓƵÁ÷ ¼æÈÝfirefox£¬c....
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- UNICODE Óë UTF-8 µÄ¹Øϵ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- phpʹÓÃmb_detect_encoding¼ì²â×Ö·û´®±àÂë
ÆÀÂÛ