Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP¼ÓÃÜÀ©Õ¹¿âMcrypt°²×°¼°Ó¦Óü¼ÇÉ

PHP³ÌÐòÔ±ÃÇÔÚ±àд´úÂë³ÌÐòʱ£¬³ýÁËÒª±£Ö¤´úÂëµÄ¸ßÐÔÄÜÖ®Í⣬»¹ÓÐÒ»µãÊǷdz£ÖØÒªµÄ£¬ÄǾÍÊdzÌÐòµÄ°²È«ÐÔ±£ÕÏ¡£PHP³ýÁË×Ô´øµÄ¼¸ÖÖ¼ÓÃܺ¯ÊýÍ⣬»¹Óй¦ÄܸüÈ«ÃæµÄPHP¼ÓÃÜÀ©Õ¹¿âMcryptºÍMhash¡£
ÆäÖУ¬McryptÀ©Õ¹¿â¿ÉÒÔʵÏÖ¼ÓÃܽâÃܹ¦ÄÜ£¬¾ÍÊǼÈÄܽ«Ã÷ÎļÓÃÜ£¬Ò²¿ÉÒÔÃÜÎÄ»¹Ô­¡£
1.PHP¼ÓÃÜÀ©Õ¹¿âMcrypt°²×°
ÔÚ±ê×¼µÄPHP°²×°¹ý³ÌÖв¢Ã»ÓаÑMrcypt°²×°ÉÏ£¬µ«PHPµÄÖ÷Ŀ¼Ï°üº¬ÁËlibmcrypt.dllºÍlibmhash.dllÎļþ (libmhash.dllÊÇMhashÀ©Õ¹¿â£¬ÕâÀï¿ÉÒÔÒ»Æð×°ÉÏ)¡£Ê×ÏÈ£¬½«ÕâÁ½¸öÎļþ¸´ÖƵ½ÏµÍ³Ä¿Â¼windows\system32Ï£¬È»ºóÔÚ PHP.iniÎļþÖа´Ctrl+F¿ì½Ý¼üÌø³ö²éÕÒ¿ò£¬²¢ÕÒµ½£»extension=php-mcrypt.dllºÍ; extension=php_mhash.dllÕâÁ½¸öÓï¾ä£¬½Ó׎«Ç°ÃæµÄ“£»”È¥µô£»×îºó£¬±£´æ²¢ÖØÆôApache·þÎñÆ÷¼´¿ÉÉúЧ¡£
2.PHP¼ÓÃÜÀ©Õ¹¿âMcryptµÄËã·¨ºÍ¼ÓÃÜģʽ
Mcrypt¿âÖ§³Ö20¶àÖÖ¼ÓÃÜËã·¨ºÍ8ÖÖ¼ÓÃÜģʽ£¬¾ßÌå¿ÉÒÔͨ¹ýº¯Êýmcrypt_list_algorithms()ºÍmcrypt_list_modes()À´ÏÔʾ£¬½á¹ûÈçÏ£º
McryptÖ§³ÖµÄËã·¨ÓУºcast-128 gost rijndael-128 twofish arcfour cast-256 loki97 rijndael-192 saferplus wake blowfish-compat des rijndael-256 serpent xtea blowfish enigma rc2 tripledes
McryptÖ§³ÖµÄ¼ÓÃÜģʽÓУºcbc cfb ctr ecb ncfb nofb ofb stream
ÕâЩËã·¨ºÍģʽÔÚÓ¦ÓÃÖÐÒªÒÔ³£Á¿À´±íʾ£¬Ð´µÄʱºò¼ÓÉÏǰ׺MCRYPT_ºÍMCRYPT_À´±íʾ£¬ÈçÏÂÃæMcryptÓ¦ÓõÄÀý×Ó£º
DESËã·¨±íʾΪMCRYPT_DES;
ECBģʽ±íʾΪMCRYPT_MODE_ECB£»
3.PHP¼ÓÃÜÀ©Õ¹¿âMcryptÓ¦ÓÃ
ÏÈ¿´Ò»¸öÀý×Ó£¬Á˽âMcryptµÄ¹¤×÷Á÷³Ì£¬ÔÙÀ´¿´¿´²¿·ÖÁ÷³ÌʹÓõĺ¯Êý£º
< ?php $str = "ÎÒµÄÃû×ÖÊÇ£¿Ò»°ãÈËÎÒ²»¸æËßËû£¡"; //¼ÓÃÜÄÚÈÝ $key = "key:111"; //ÃÜÔ¿ $cipher = MCRYPT_DES; //ÃÜÂëÀàÐÍ $modes = MCRYPT_MODE_ECB; //ÃÜÂëģʽ $iv = mcrypt_create_iv(mcrypt_get_iv_size($cipher,$modes),MCRYPT_RAND);//³õʼ»¯ÏòÁ¿ echo "¼ÓÃÜÃ÷ÎÄ£º".$str."<p>"; $str_encrypt = mcrypt_encrypt($cipher,$key,$str,$modes,$iv); //¼ÓÃܺ¯Êý echo "¼ÓÃÜÃÜÎÄ£º".$str_encrypt." <p>"; $str_decrypt = mcrypt_decrypt($cipher,$key,$str_encrypt,$modes,$iv); //½âÃܺ¯Êý echo "»¹Ô­£º".$str_decrypt; ?>
ÔËÐнá¹û£º
¼ÓÃÜÃ÷ÎÄ£ºÎÒµÄÃû×ÖÊÇ£¿Ò»°ãÈËÎÒ²»¸æËßËû£¡
¼ÓÃÜÃÜÎÄ£º ï³盌?]鸴?q攦軄L Ц 郺葄"簻 Ɩ


Ïà¹ØÎĵµ£º

phpѧϰ±Ê¼Ç£¨8£©:PHPº¯ÊýºÍ×Ô¶¨Ò庯Êý


1¡¢PHPº¯Êý½éÉÜ
PHPº¯Êý·ÖΪ£ºÏµÍ³ÄÚ²¿º¯Êý ºÍ ×Ô¶¨Ò庯Êý 
¸ñʽ£ºFunction($a1,$s2....){};
Àý×Ó£ºdate("Y-m-d");
          Md5("CHAUVET");
º¯ÊýµÄÓÅÔ½ÐÔ£º
A)¿ØÖƳÌÐòÉè¼ÆµÄ¸´ÔÓÐÔ
B)Ìá¸ßÈí¼þµÄ¿É¿¿ÐÔ
C)Ìá¸ßÈí¼þ¿ª·¢Ð§ÂÊ
D)Ìá¸ßÈí¼þµÄ¿É ......

¡¾×ª¡¿¸ß¼¶PHPÓ¦ÓóÌÐò©¶´ÉóºË¼¼Êõ




×÷ÕߣºPh4nt0m Security Team
À´Ô´£ºhttp://www.ph4nt0m.org-a.googlepages.com/PSTZine_0x03_0x06.txt
==Ph4nt0m Security Team==

Issue 0x03, Phile #0x06 of 0x07

|=---------------------------------------- ......

PHP Óë JS µÄÁíÒ»ÖÖÊý¾Ý´«µÝ·½Ê½ ÐòÁл¯

¡¡¡¡´Ó PHP 3 ¿ªÊ¼Îª±£´æ¶ÔÏóÌṩÁËÒ»×éÐòÁл¯ºÍ·´ÐòÁл¯µÄº¯Êý£ºserialize¡¢unserialize£¬Ëü¿ÉÒÔ·½±ãµÄ±£´æÊý¾Ý·½±ãµÄ×ö³ÉCACHE£¬¶ø´æ´¢Ìå»ýÒ²±ÈXMLҪСµÄ¶à£¬Ëü½á¹¹Óë JS µÄ JSON ÏàÄâ£¬ÍøÉÏÓÐÒ»×éÓà JS Ä£Äâ serialize ʵÏֵķ½·¨£¬Ê¹ÓÃËü¿ÉÒÔºÍPHP ÔÚÊý¾Ý´«µÝÉϸü½ôÃܵĽáºÏ£®
 
¡¡¡¡JavaScript °æ±¾£¨stable£©£ ......

[ת]ϸ²ì PHP V5.3.0 ÌØÐÔ


ϸ²ì PHP V5.3.0 ÌØÐÔ
¼¶±ð£º Öм¶
Stephen B. Morris, CTO, Omey Communications
2009 Äê 12 ÔÂ 07 ÈÕ
Ëæ×ÅÁ÷ÐÐµÄ PHP ÓïÑԵIJ»¶ÏÑݱ䣬ºÜ¶àÐÂÌØÐÔʹËüÔÚÃæÏò¶ÔÏó·½ÃæÓÐÁ˽øÒ»²½µÄÔöÇ¿¡£±¾ÎÄͨ¹ýһЩ PHP V5.3 ʵÀýÑÝʾÑÓ³Ù¾²Ì¬°ó¶¨¡¢Ãû³Æ¿Õ¼äÖ§³Ö¡¢Àà·½·¨ÖØÔØÒÔ¼°±äÁ¿½âÎöºÍ heredoc Ö§³Ö¡£
ÐèÇó
³ýÁË¶Ô PHP ºÍ H ......

IISÏÂPHPµÄISAPIºÍFastCGI±È½Ï

    Ô­ÎÄÁ´½Ó£ºhttp://www.williamlong.info/archives/1846.html
    ÔÚWindows IIS
6.0ÏÂÅäÖÃPHP
£¬Í¨³£ÓÐCGI
¡¢ISAPI
ºÍFastCGI
ÈýÖÖÅäÖ÷½Ê½£¬ÕâÈýÖÖģʽ¶¼¿ÉÒÔÔÚIIS
6.0ϳɹ¦ÔËÐУ¬ÏÂÃæÎҾͽ²Ò»ÏÂÕâÈýÖÖ·½Ê½ÅäÖõÄÇø±ðºÍÐÔÄÜÉϵIJîÒì¡£
¡¡¡¡1¡¢CGI
£¨Í¨ÓÃÍø¹Ø½Ó¿Ú/Common Ga ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ