°²×°phpÖ§³Ömssql,curl,gd¿âµÈ
ÏȰ²×°µÄzlib ./configure --prefix=/usr/local/zlib È»ºó×°µÄcurl ./configure --prefix=/usr/local/curl --with-zlib=/usr/local/zlib °²×°gdĬÈϰ²×° ./configure --prefix=/usr/local/gd --with-zlib=/usr/local/zlib (ÓÐÐ©Ç°ÃæÏȰ²×°jepg,png...with¾Í¿ÉÒÔÁË,Ö®ºóphpµÄʱºò¿´./configure --helpÀïÃæÓоßÌåµÄ) °²×°freetdsÖ§³Ömssql ./configure --prefix=/usr/local/freetds \
--with-tdsver=8.0 \
--enable-msdblib \
--enable-dbmfix \
--with-gnu-ld \
--enable-shared \
--enable-static °²×°libmcrypt Ö§³Ömcrypt ./configure --prefix=/usr/local/freetds \ --disable-posix-threads ĬÈÏmysqlºÍapache¶¼Êǰ²×°ºÃµÄ ÈçÏÂÅäÖà ./configure --prefix=/usr/www/php \
--with-apxs2=/usr/www/apache/bin/apxs \
--with-config-file-scan-dir=/etc/ \
--with-zlib=/usr/local/zlib \
--enable-bcmath \
--with-bz2 \
--with-curl=/usr/local/curl \
--enable-dbase \
--enable-exif \
--enable-ftp \
--with-pdo-dblib=/usr/local/freetds \
--with-pdo-mysql=/usr/www/mysql \
--with-gd=/usr/local/gd \
--enable-mbstring=cn \
--enable-calendar \
--enable-bcmath \
--with-libmbfl \
--with-mcrypt=/usr/local/libmcrypt \
-with-mssql=/usr/local/freetds \
-with-mysql=/usr/www/mysql/ \
--with-mysqli=/usr/www/mysql/bin/mysql_config \
--enable-embedded-mysqli=share \
--enable-soap \
--enable-sockets \
--with-xmlrpc \
--with-pear=/usr/www/php/PEAR\
--enable-zip $make $make install Ö®ºóÊÇÅäÖÃÎļþcp php.ini-dist /etc/php.ini#ÒòΪÎÒÔÚÇ°ÃæµÄ±àÒëÀïÉèÖÃÁËÔÚ/etcÖмÓÔØphp.ini ÐÞ¸ÄapacheµÄhttpd.confÈ·±£ÓÐÒÔÏÂÒ»ÐÐ,Ò»°ãĬÈÏÊÇÓÐµÄ LoadModule php5_module modules/libphp5.so Ìí¼ÓÈçÏÂ,ʹapacheÄܹ»½âÊÍ.php½áβµÄÎļþ SetHandler application/x-httpd-php ÕâʱºòÆô¶¯apacheÓ¦¸Ã¿ÉÒÔÁËÖ§³ÖphpÁË ÓбØÒªÉèÖÃÐéÄâÖ÷»úÐèÒª´ò¿ª¼ÓÔØvhostµÄ×¢ÊÍ È»ºó±à¼apache/conf/extrahttpd-vhosts.conf Ìí¼ÓÓòÃûÖ§³Ö,ÕâÀï²»ÔÙ׸Êö,
Ïà¹ØÎĵµ£º
Ò»¡¢ ¿ª·¢³ÉÔ±
a)ÏîÄ¿Ö÷¹Ü
b)Ò³ÃæÃÀ¹¤
c)Ò³Ãæ¿ª·¢
d)·þÎñ¶Ë³ÌÐò¿ª·¢
e)ϵͳÓëÊý¾Ý¹ÜÀí
f)²âÊÔÓë°æ±¾¿ØÖÆ
¶þ¡¢ ÍøÕ¾×鿪·¢¼òÃ÷Á÷³Ì
Èý¡¢ ¿ª·¢¹¤¾ßÓë»·¾³
a) ·þÎñÆ÷ÅäÖÃ
i. WEB·þÎñÆ÷£º FreeBSD6.1+Apache2.0+PHP5.0£¬SVN°æ±¾¿ØÖÆ·þÎñ(½ö²âÊÔ»ú)¡£
ii. Êý¾Ý¿â·þÎñÆ÷£º WIN2003 server+SQL server 2000+ ......
1¡¢¹ÅÀÏµÄÆÛÆSQLÓï¾ä
ÔÚĬÈÏģʽÏ£¬¼´Ê¹ÊÇÄãÍüÁ˰Ñphp.ini¿½µ½/usr/local/lib/php.iniÏ£¬php»¹ÊÇ´ò¿ªmagic_quotes_gpc=on¡£
ÕâÑùËùÓдÓGET/POST/CookieÀ´µÄ±äÁ¿µÄµ¥ÒýºÅ(')¡¢Ë«ÒýºÅ(")¡¢·´Ð±¸Übackslash(\)ÒÔ¼°¿Õ×ÖÔªNUL
(the null byte)¶¼»á±»¼ÓÉÏ·´Ð±¸Ü£¬ÒÔʹÊý¾Ý¿âÄܹ»ÕýÈ·²éѯ¡£
µ«ÊÇÔÚphp-4-RC2µÄʱºòÒýÈë ......
¶ÔÓڽű¾°²È«Õâ¸ö»°ÌâºÃÏñÓÀԶûÍêûÁË£¬Èç¹ûÄã¾³£µ½¹úÍâµÄ¸÷ÖÖ¸÷ÑùµÄbugtraqÉÏ£¬Äã»á·¢ÏÖÓÐÒ»°ëÒÔÉ϶¼ºÍ½Å±¾Ïà¹Ø£¬ÖîÈçSQL
injection£¬XSS£¬Path Disclosure£¬Remote commands executionÕâÑùµÄ×ÖÑ۱ȱȽÔÊÇ£¬ÎÒÃÇ¿´ÁËÖ®ºóµÄÓÃ;ÄѵÀ½ö½öÊÇ×¥È⼦?¶ÔÓÚÎÒÃÇÏë×öweb°²È«µÄÈËÀ´Ëµ£¬×îºÃ¾ÍÊÇÄÃÀ´Ñ§Ï°
£¬¿ÉÊÇÍòÎï×¥¸ùÔ´£¬ÎÒà ......
php ¹ºÎﳵʵÀý
<?php
/**
php ¹ºÎﳵʵÀý
ÍøÉÏËѵ½µÄ£¬¼òµ¥ÈÝÒ×Àí½â¡£cookie´æ¹ºÎï³µID£¬db´æ¹ºÎï³µÊý¾Ý¡£ ¹ºÎï³µsessionµÄ²úÉú´úÂë
*/
if(! $session && ! $scid) {
/*
sessionÓÃÀ´Çø±ðÿһ¸ö¹ºÎï³µ£¬Ï൱ÓÚÿ¸ö³µµÄÉí·ÝÖ¤ºÅ£»
scidÖ»ÓÃÀ´±êʶһ¸ö¹ºÎï³µidºÅ£¬¿ÉÒÔ¿´×öÊÇÿ¸ö³µµÄÃû×Ö£»
......
Ò»°ãÇé¿öÏ£¬ÔÚ¿ª·¢»·¾³ÖзÃÎÊÒ»¸ö¾ßÌåÉÌÆ·µÄURLÊÇÕâÑùµÄ£º
http://localhost/phptest/show.php?id=1
µ«ÊÇÎÒÐèÒª¸ü¸ÄÒ»ÏÂURL£¬¶ÔËÑË÷ÒýÇæ¸üÓѺã¬È磺
http://localhost/phptest/1.html
ÕâÖ»ÊǾÙÀý°ÕÁË¡£
ÏÂÃæÎÒÃÇÀ´¿´¿´£¬ÕâÁ½ÌìÁ´½Ó×îºó´ïµ½µÄЧ¹ûÊÇÒ»ÑùµÄ£¬Çë×¢Òâä¯ÀÀÆ÷µØÖ·£¡
1¡¢Õý³£·ÃÎÊ£º
2¡¢Î±¾²Ì¬ºó£º
½ÓÏÂÀ ......