¡¡ÔÚPHP¿ª·¢ÖÐ¶Ô±ÈÆðCookie£¬session ÊÇ´æ´¢ÔÚ·þÎñÆ÷¶ËµÄ»á»°£¬Ïà¶Ô°²È«£¬²¢ÇÒ²»Ïñ Cookie ÄÇÑùÓд洢³¤¶ÈÏÞÖÆ£¬±¾Îļòµ¥½éÉÜ session µÄʹÓá£
¡¡¡¡ÓÉÓÚ Session ÊÇÒÔÎı¾ÎļþÐÎʽ´æ´¢ÔÚ·þÎñÆ÷¶ËµÄ£¬ËùÒÔ²»Å¿ͻ§¶ËÐÞ¸Ä Session ÄÚÈÝ¡£Êµ¼ÊÉÏÔÚ·þÎñÆ÷¶ËµÄ Session Îļþ£¬PHP ×Ô¶¯ÐÞ¸Ä session ÎļþµÄȨÏÞ£¬Ö»±£ÁôÁËϵͳ¶ÁºÍдȨÏÞ£¬¶øÇÒ²»ÄÜͨ¹ý ftp Ð޸ģ¬ËùÒÔ°²È«µÃ¶à¡£PHPChina ¿ªÔ´ÉçÇøÃÅ»§
¡¡¡¡¶ÔÓÚ Cookie À´Ëµ£¬¼ÙÉèÎÒÃÇÒªÑéÖ¤Óû§ÊÇ·ñµÇ½£¬¾Í±ØÐëÔÚ Cookie Öб£´æÓû§ÃûºÍÃÜÂë(¿ÉÄÜÊÇ md5 ¼ÓÃܺó×Ö·û´®)£¬²¢ÔÚÿ´ÎÇëÇóÒ³ÃæµÄʱºò½øÐÐÑéÖ¤¡£Èç¹ûÓû§ÃûºÍÃÜÂë´æ´¢ÔÚÊý¾Ý¿â£¬Ã¿´Î¶¼ÒªÖ´ÐÐÒ»´ÎÊý¾Ý¿â²éѯ£¬¸øÊý¾Ý¿âÔì³É¶àÓàµÄ¸ºµ£¡£ÒòΪÎÒÃDz¢²»ÄÜÖ»×öÒ»´ÎÑéÖ¤¡£ÎªÊ²Ã´ÄØ?ÒòΪ¿Í»§¶Ë Cookie ÖеÄÐÅÏ¢ÊÇÓпÉÄܱ»Ð޸ĵġ£¼ÙÈçÄã´æ´¢ $admin ±äÁ¿À´±íʾÓû§ÊÇ·ñµÇ½£¬$admin Ϊ true µÄʱºò±íʾµÇ½£¬Îª false µÄʱºò±íʾδµÇ¼£¬ÔÚµÚÒ»´Îͨ¹ýÑéÖ¤ºó½« $admin µÈÓÚ true ´æ´¢ÔÚ Cookie£¬Ï´ξͲ»ÓÃÑéÖ¤ÁË£¬ÕâÑù¶Ôô?´íÁË£¬¼ÙÈçÓÐÈËαÔìÒ»¸öֵΪ true µÄ $admin ±äÁ¿ÄDz»ÊǾÍÁ¢¼´È¡µÄÁ˹ÜÀíȨÏÞô?·Ç³£µÄ²»°²È«¡£
¡¡¡¡¶ø Session ¾Í²»Í¬ÁË£¬Session ÊÇ´æ´¢ÔÚ·þÎ ......
Ò»´ÎNginx+PHP+MysqlµÄ²¢·¢²âÊÔ¾Àú
Ò»¡¢Ó²¼þ»·¾³
CPU:4ºËIntel(R) Xeon(R) CPU E5504 @ 2.00GHz
6GÄڴ棬120GÓ²ÅÌ
¶þ¡¢Èí¼þ»·¾³
Linux centos12 2.6.18-164.6.1.el5 #1 SMP x86_64 GNU/Linux
nginx-0.7.61.tar.gz
mysql-5.1.35.tar.gz
php-5.2.10.tar.gz
memcache-2.2.5.tgz
eaccelerator-0.9.5.3.tar.bz2
ZendOptimizer-3.3.9-linux-glibc23-x86_64.tar.gz
Èý¡¢Ïà¹ØÈí¼þÅäÖÃ
1¡¢NginxÅäÖÃÎļþ
user www www;
#worker_processes 1;
#ÒòΪÎÒÊÇ4ºËcpuËùÒÔÉèÖÃΪ4
worker_processes 4;
error_log /web/logs/nginx_error.log crit;
pid /usr/local/nginx/logs/nginx.pid;
#Specifies the value for maxim ......
Ò»´ÎNginx+PHP+MysqlµÄ²¢·¢²âÊÔ¾Àú
Ò»¡¢Ó²¼þ»·¾³
CPU:4ºËIntel(R) Xeon(R) CPU E5504 @ 2.00GHz
6GÄڴ棬120GÓ²ÅÌ
¶þ¡¢Èí¼þ»·¾³
Linux centos12 2.6.18-164.6.1.el5 #1 SMP x86_64 GNU/Linux
nginx-0.7.61.tar.gz
mysql-5.1.35.tar.gz
php-5.2.10.tar.gz
memcache-2.2.5.tgz
eaccelerator-0.9.5.3.tar.bz2
ZendOptimizer-3.3.9-linux-glibc23-x86_64.tar.gz
Èý¡¢Ïà¹ØÈí¼þÅäÖÃ
1¡¢NginxÅäÖÃÎļþ
user www www;
#worker_processes 1;
#ÒòΪÎÒÊÇ4ºËcpuËùÒÔÉèÖÃΪ4
worker_processes 4;
error_log /web/logs/nginx_error.log crit;
pid /usr/local/nginx/logs/nginx.pid;
#Specifies the value for maxim ......
PHPÊǸöΰ´óµÄweb¿ª·¢ÓïÑÔ£¬Áé»îµÄÓïÑÔ£¬µ«ÊÇ¿´µ½php³ÌÐòÔ±Öܶø¸´Ê¼µÄ·¸µÄһЩ´íÎó¡£ÎÒ×öÁËÏÂÃæÕâ¸öÁÐ±í£¬ÁгöÁËPHP³ÌÐòÔ±¾³£·¸µÄ10ÖдíÎ󣬴ó¶àÊýºÍ°²È«Ïà¹Ø¡£¿´¿´Äã·¸Á˼¸ÖÖ
1.²»×ªÒâhtml entities
Ò»¸ö»ù±¾µÄ³£Ê¶£ºËùÓв»¿ÉÐÅÈεÄÊäÈë£¨ÌØ±ðÊÇÓû§´ÓformÖÐÌá½»µÄÊý¾Ý£© £¬Êä³ö֮ǰ¶¼Òª×ªÒâ¡£
echo $_GET['usename'] ;
Õâ¸öÀý×ÓÓпÉÄÜÊä³ö£º
<script>/*¸ü¸ÄadminÃÜÂëµÄ½Å±¾»òÉèÖÃcookieµÄ½Å±¾*/</script>
ÕâÊÇÒ»¸öÃ÷ÏԵݲȫÒþ»¼£¬³ý·ÇÄã±£Ö¤ÄãµÄÓû§¶¼ÕýÈ·µÄÊäÈë¡£
ÈçºÎÐÞ¸´ £º
ÎÒÃÇÐèÒª½«"< ",">","and" µÈת»»³ÉÕýÈ·µÄHTML±íʾ(< , >', and ")£¬º¯Êýhtmlspecialchars ºÍ htmlentities()ÕýÊǸÉÕâ¸ö»îµÄ¡£
ÕýÈ·µÄ·½·¨£º
echo htmlspecialchars($_GET['username'], ENT_QUOTES);
2. ²»×ªÒâSQLÊäÈë
ÎÒÔø¾ÔÚһƪÎÄÕÂÖÐ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÌÖÂÛ¹ýÕâ¸öÎÊÌâ²¢¸ø³öÁËÒ»¸ö¼òµ¥µÄ·½·¨ ¡£ÓÐÈ˶ÔÎÒ˵£¬ËûÃÇÒѾÔÚphp.iniÖн«magic_quotesÉèÖÃΪOn£¬ËùÒÔ²»±Øµ£ÐÄÕâ¸öÎÊÌ⣬µ«ÊDz»ÊÇËùÓеÄÊäÈë¶¼ÊÇ´Ó$_GET, $_POST»ò $_COOKIEÖеĵõ½µÄ£¡
ÈçºÎÐÞ¸´£º
ºÍÔÚ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÖÐÒ»ÑùÎÒ»¹ÊÇ ......
ÔÎÄÄÚÈÝ
£º
ͻ񻣼
½ÏÔçµÄʱºò£¬ÓиöÅóÓѼ«Á¦ÍƼöÎÒÈ¥¿´¿´Ò»¿îPHPÎʾíµ÷²éϵͳ¡£ÎÒËäÈ»´ÓÊÂÈí¼þÁìÓòµÄʱ¼ä
²¢²»Ì«³¤£¬µ«Ò²ÖªµÀ¹úÄÚÔÚÕâ¸öÁìÓòÑо¿ºÍ´ÓÊÂµÄÆóÒµºÍ¸öÈ˲¢²»ÉÙ£¬Ö®Ç°Ò²¹Ø×¢¹ýºÍÆÀ¹À¹ýһЩ²úÆ·»òϵͳ£¬×ÜÌåÉÏ¿´À´£¬´ó¶àÊý²úÆ·µÄÉÌÒµ»¯³Ì¶È²»¸ß£¬ÖÊÁ¿²Î
²î²»Æë£¬Àë³ÉÊìµÄÈí¼þϵͳ»¹ÓÐÏ൱һ¸ö¾àÀë¡£
ÏÈÊÇ×ßÂí¹Û»¨Ê½ä¯ÀÀÒ»¸öËùνµÄEnableQµÄÈí¼þ²úÆ·¡£Æð³õÎÒ²¢²»±§Ê²Ã´ÆÚÍû£¬¾õµÃ²»¹ýÊÇÖÚ¶àÆ½Ó¹ÖеÄÒ»¸ö¡£²»ÁϽá¹û¸øÁËÎÒ¸öÕ𺳣¬ºÜ¾ÃûÓп´¹ýÕâÑùÈÃÈ˼¤¶¯µÄ¹ú²úPHPÎʾíµ÷²éϵͳÁË¡£
ºÜ³¤Ê±¼ä²»Ð´¹ØÓÚÈí¼þ²úÆ·ÍÆ¼öµÄÎÄÕ£¬½ñÌìÆÆÀý£¬¾ÍÊÇÒòÉÏÊöÔÓÉ¡£
¹ØÓÚPHPÎʾíµ÷²éϵͳÕâ¸öÁìÓò
ʵ¼ÊÉÏ£¬Óë´ó¶àÊýÈËÀí½â²»Í¬£¬Îʾíµ÷²é(Survey)ϵͳÊÇÒ»¸ö°ÑIT¼¼ÊõÓ¦Óõ½ÐÐÒµÓ¦Óõĸ´ÔÓϵͳ£¬²¢·ÇÊÇÒ»°ãÔںܶàÃÅ»§ÍøÕ¾ÉϾ³£¿´µ½µÄһЩͶƱµ÷²é(Poll)£¬ÕâÁ½ÕßÖ®¼ä´æÔڷdz£±¾ÖʵÄÇø±ð£º
1)ͶƱµ÷²éÒ»°ã½öÒªÇó·Ç³£ÉÙµÄÎÊÌâÌâÐÍ£¬Ò»°ãÖ§³Öµ¥Ñ¡¡¢¶àÑ¡¾Í¿ÉÒÔÁË£¬µ«Îʾíµ÷²éÔòÒªÇó¸ü¶àµÄÎÊÌâÌâÐÍ£¬ÒÔ±ãÔÚÒ»ÕÅÎʾíÖÐÉè¼Æ³ö¸ü¶àµÄÆÀ¹À·½Ïò£»
2)ͶƱµ÷²éÒ»°ã½ö¼Ç¼ÔÚÎÊÌâÑ¡ÏîÉϵÄ×ÜͶƱÊý£¬¶øÎʾíµ÷²éÕâÑùµÄÊý¾Ý»ù±¾ÉÏÊÇûÓÐÈκÎÒâÒåµÄ£¬ËùÒÔÐèÒª¼Ç¼ÿһ¸öÑù±¾µÄÏêϸÌîÐ ......
PHPÊǸöΰ´óµÄweb¿ª·¢ÓïÑÔ£¬Áé»îµÄÓïÑÔ£¬µ«ÊÇ¿´µ½php³ÌÐòÔ±Öܶø¸´Ê¼µÄ·¸µÄһЩ´íÎó¡£ÎÒ×öÁËÏÂÃæÕâ¸öÁÐ±í£¬ÁгöÁËPHP³ÌÐòÔ±¾³£·¸µÄ10ÖдíÎ󣬴ó¶àÊýºÍ°²È«Ïà¹Ø¡£¿´¿´Äã·¸Á˼¸ÖÖ
1.²»×ªÒâhtml entities
Ò»¸ö»ù±¾µÄ³£Ê¶£ºËùÓв»¿ÉÐÅÈεÄÊäÈë£¨ÌØ±ðÊÇÓû§´ÓformÖÐÌá½»µÄÊý¾Ý£© £¬Êä³ö֮ǰ¶¼Òª×ªÒâ¡£
echo $_GET['usename'] ;
Õâ¸öÀý×ÓÓпÉÄÜÊä³ö£º
<script>/*¸ü¸ÄadminÃÜÂëµÄ½Å±¾»òÉèÖÃcookieµÄ½Å±¾*/</script>
ÕâÊÇÒ»¸öÃ÷ÏԵݲȫÒþ»¼£¬³ý·ÇÄã±£Ö¤ÄãµÄÓû§¶¼ÕýÈ·µÄÊäÈë¡£
ÈçºÎÐÞ¸´ £º
ÎÒÃÇÐèÒª½«"< ",">","and" µÈת»»³ÉÕýÈ·µÄHTML±íʾ(< , >', and ")£¬º¯Êýhtmlspecialchars ºÍ htmlentities()ÕýÊǸÉÕâ¸ö»îµÄ¡£
ÕýÈ·µÄ·½·¨£º
echo htmlspecialchars($_GET['username'], ENT_QUOTES);
2. ²»×ªÒâSQLÊäÈë
ÎÒ
Ôø¾ÔÚһƪÎÄÕÂÖÐ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÌÖÂÛ¹ýÕâ¸öÎÊÌâ²¢¸ø³öÁËÒ»¸ö¼òµ¥µÄ·½·¨
¡£ÓÐÈ˶ÔÎÒ˵£¬ËûÃÇÒѾÔÚphp.iniÖн«magic_quotesÉèÖÃΪOn£¬ËùÒÔ²»±Øµ£ÐÄÕâ¸öÎÊÌ⣬µ«ÊDz»ÊÇËùÓеÄÊäÈë¶¼ÊÇ´Ó$_GET,
$_POST»ò $_COOKIEÖеĵõ½µÄ£¡
ÈçºÎÐÞ¸´£º
ºÍÔÚ×î¼òµ ......
array array_diff
( array array1, array array2 [, array
...] )
array_diff()
·µ»ØÒ»¸öÊý×飬¸ÃÊý×é°üÀ¨ÁËËùÓÐÔÚ array1
Öе«ÊDz»ÔÚÈÎºÎÆäËü²ÎÊýÊý×éÖеÄÖµ¡£×¢Òâ¼üÃû±£Áô²»±ä¡£
Ã͵ÄÒ»¿´Õâ¸ö·½·¨£¬»¹ÒÔΪÊǽ«Á½¸öÊý×éÖв»Í¬µÄ·µ»ØÀ´ÄØ£¬ÊÂʵÉϲ»ÊÇ£¬·µ»ØµÄÊÇÔÚarray1Öе쬵«ÊDz»ÔÚÆäËûÊý×éÖеġ£ ......