Ò׽ؽØÍ¼Èí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

PHP³ÌÐòÔ±×îÒ×·¸10ÖÖ´íÎó


1.²»×ªÒâhtml entities
Ò»¸ö»ù±¾µÄ³£Ê¶£ºËùÓв»¿ÉÐÅÈεÄÊäÈë£¨ÌØ±ðÊÇÓû§´ÓformÖÐÌá½»µÄÊý¾Ý£© £¬Êä³ö֮ǰ¶¼Òª×ªÒâ¡£
echo $_GET['usename'] ;
Õâ¸öÀý×ÓÓпÉÄÜÊä³ö£º
<scrīpt>/*¸ü¸ÄadminÃÜÂëµÄ½Å±¾»òÉèÖÃcookieµÄ½Å±¾*/</scrīpt>
ÕâÊÇÒ»¸öÃ÷ÏԵݲȫÒþ»¼£¬³ý·ÇÄã±£Ö¤ÄãµÄÓû§¶¼ÕýÈ·µÄÊäÈë¡£
ÈçºÎÐÞ¸´ £º
ÎÒÃÇÐèÒª½«"< ",">","and" µÈת»»³ÉÕýÈ·µÄHTML±íʾ(< , >', and ")£¬º¯Êýhtmlspecialchars ºÍ htmlentities()ÕýÊǸÉÕâ¸ö»îµÄ¡£
ÕýÈ·µÄ·½·¨£º
echo htmlspecialchars($_GET['username'], ENT_QUOTES);

2. ²»×ªÒâSQLÊäÈë
ÎÒÔø¾­ÔÚһƪÎÄÕÂÖÐ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÌÖÂÛ¹ýÕâ¸öÎÊÌâ²¢¸ø³öÁËÒ»¸ö¼òµ¥µÄ·½·¨¡£ÓÐÈ˶ÔÎÒ˵£¬ËûÃÇÒѾ­ÔÚphp.ini
Öн«magic_quotesÉèÖÃΪOn£¬ËùÒÔ²»±Øµ£ÐÄÕâ¸öÎÊÌ⣬µ«ÊDz»ÊÇËùÓеÄÊäÈë¶¼ÊÇ´Ó$_GET, $_POST»ò $_COOKIEÖеĵõ½µÄ£¡
ÈçºÎÐÞ¸´£º
ºÍÔÚ×î¼òµ¥µÄ·ÀÖ¹sql×¢ÈëµÄ·½·¨(php+mysqlÖÐ)ÖÐÒ»ÑùÎÒ»¹ÊÇÍÆ¼öʹÓÃmysql_real_escape_string()º¯Êý
ÕýÈ·×ö·¨£º
<?php
$sql = "UPDATE users SET
name='.mysql_real_escape_string($name).'
WHERE id='.mysql_real_escape_string ($id).'";
mysql_query($sql);
?>


3.´íÎóµÄʹÓÃHTTP-header Ïà¹ØµÄº¯Êý: header(), session_start(), setcookie()
Óöµ½¹ýÕâ¸ö¾¯¸æÂð?"warning: Cannot add header information - headers already sent [....]
ÿ´Î´Ó·þÎñÆ÷ÏÂÔØÒ»¸öÍøÒ³µÄʱºò£¬·þÎñÆ÷µÄÊä³ö¶¼·Ö³ÉÁ½¸ö²¿·Ö£ºÍ·²¿ºÍÕýÎÄ¡£
Í·²¿°üº¬ÁËһЩ·Ç¿ÉÊÓµÄÊý¾Ý£¬ÀýÈçcookie¡£Í·²¿×ÜÊÇÏȵ½´ï¡£ÕýÎIJ¿·Ö°üÀ¨¿ÉÊÓµÄhtml£¬Í¼Æ¬µÈÊý¾Ý¡£
Èç¹ûoutput_bufferingÉèÖÃΪOff£¬ËùÓеÄHTTP-headerÏà¹ØµÄº¯Êý±ØÐëÔÚÓÐÊä³ö֮ǰµ÷Óá£ÎÊÌâÔÚÓÚÄãÔÚÒ»¸ö»·¾³Öпª·¢£¬¶øÔÚ²¿
Êðµ½ÁíÒ»¸ö»·¾³ÖÐÈ¥µÄʱºò£¬output_bufferingµÄÉèÖÿÉÄܲ»Ò»Ñù¡£½á¹ûתÏòÍ£Ö¹ÁË£¬cookieºÍsession¶¼Ã»ÓÐÕýÈ·µÄÉè
ÖÃ........¡£
ÈçºÎÐÞ¸´:
È·±£ÔÚÊä³ö֮ǰµ÷ÓÃhttp-headerÏà¹ØµÄº¯Êý£¬²¢ÇÒÁîoutput_buffering = Off
¡£

4. Require »ò include µÄÎļþʹÓò»°²È«µÄÊý¾Ý
ÔÙ´ÎÇ¿µ÷£º²»ÒªÏàÐŲ»ÊÇÄã×Ô¼ºÏÔʽÉùÃ÷µÄÊý¾Ý¡£²»Òª Include »ò require ´Ó$_GET, $_POST »ò $_COOKIE Öеõ½µÄÎļþ¡£
ÀýÈç:
index.php
<?
//including header, config, database connection, etc
include(


Ïà¹ØÎĵµ£º

php×¢Êͱê×¼

4.1 ¿é×¢ÊÍ
¿é×¢ÊÍͨ³£ÓÃÓÚÌṩ¶ÔÎļþ£¬·½·¨£¬Êý¾Ý½á¹¹ºÍËã·¨µÄÃèÊö¡£¿é×¢Êͱ»ÖÃÓÚÿ¸öÎļþµÄ¿ªÊ¼´¦ÒÔ¼°Ã¿¸ö·½·¨Ö®Ç°¡£ËüÃÇÒ²¿ÉÒÔ±»ÓÃÓÚÆäËûµØ·½£¬±ÈÈç·½·¨ÄÚ²¿¡£ÔÚ¹¦Äܺͷ½·¨ÄÚ²¿µÄ¿é×¢ÊÍÓ¦¸ÃºÍËüÃÇËùÃèÊöµÄ´úÂë¾ßÓÐÒ»ÑùµÄËõ½ø¸ñʽ¡£
¿é×¢ÊÍÖ®Ê×Ó¦¸ÃÓÐÒ»¸ö¿ÕÐУ¬ÓÃÓÚ°Ñ¿é×¢ÊͺʹúÂë·Ö¸î¿ªÀ´£¬±ÈÈ磺
/*
* ÕâÀïÊÇ¿é×¢ÊÍ ......

ÓÃPHPÉú³ÉÑéÖ¤Âë¿ÉÒÔ½øÐеã»÷Ë¢ÐÂ

ÑéÖ¤ÂëµÄ´óÖÂÔ­ÀíÊÇÕâÑùµÄ£¬Ê×ÏÈÉú³ÉÒ»¸öËæ»úÊý£¬È»ºóÔÚÊý¾ÝÊýÉÏÃæ¼ÓÉϸÉÈÅͼƬ£¬Í¬Ê±°Ñ¸ÃÊý¾ÝÉú³ÉͼƬ²¢Êä³ö¡£
Õâ¸öÊý¾Ý±£´æÔÚsessionÖС£È»ºó°ÑÓû§µÄÊäÈëÓë±£´æÔÚsessionÖеÄÊý¾Ý½øÐÐÆ¥Å䣬½øÐÐÑéÖ¤¡£
verifyCode.php´úÂëÈçÏ£º
<?php
Header("Content-type: image/PNG");
session_start();
//× ......

ÉîÈë·ÖÎö¼¸ÖÖPHP»ñÈ¡¿Í»§¶ËIPµÄÇé¿ö


PHP»ñÈ¡¿Í»§¶ËIPµÄÇé¿ö·ÖΪ£ºÃ»ÓÐʹÓôúÀí·þÎñÆ÷µÄÇé¿ö¡¢Ê¹ÓÃ͸Ã÷´úÀí·þÎñÆ÷µÄÇé¿ö¡¢Ê¹ÓÃÆÕͨÄäÃû´úÀí·þÎñÆ÷µÄÇé¿ö¡¢Ê¹ÓÃÆÛÆ­ÐÔ´úÀí·þÎñÆ÷µÄÇé¿ö¡¢Ê¹ÓøßÄäÃû´úÀí·þÎñÆ÷µÄÇé¿ö¡£
ÔÚÕâÆªÎÄÕÂÖУ¬ÎÒÃǽ«»áΪ´ó¼ÒÏêϸ½éÉÜPHP»ñÈ¡¿Í»§¶ËIPµÄ¼¸ÖÖÇé¿ö·ÖÎö¡£ÎÒÃÇÔÚʹÓÃPHP»ñÈ¡µÄIP¿ÉÄÜÊǿͻ§¶ËÕæÊµµÄIP£¬Ò²¿ÉÄÜÊÇ´úÀí·þÎñÆ÷µÄI ......

PHP±à³Ì·½Ê½µÄÖØÐÂ˼Ë÷(ÏÂ)

ÍÏÁËÁ½Ì죬½ñÍíÖÕÓÚÓеãʱ¼äÀ´Ð´ÏÂÆªÁË¡£¿ÉÊÇ£¬¶Ô×ŵçÄÔ£¬È´Óе㲻֪µÀ´ÓºÎ˵Æð¡£»òÐí£¬¾ÍÕÕ×ÅZEND FRAMEWORKÀ´Ëµ°É¡£µ±È»£¬ÎÒ»á°ÑÎÕÒªµã£¬¼ÇµÃÕâÆªÎÄÕÂÊÇÒÔzend frameworkΪÀýÀ´²ûÊöÎÒ¶ÔÃæÏò¶ÔÏó·½Ê½±à³ÌµÄÈÏʶ£¬¶ø²»ÊÇһƪzend frameworkµÄÈëÃÅÊֲᣬ²¢ÇÒ£¬ÕâÒ²²»»áÊÇÒ»¸öÃæÏò¶ÔÏóµÄÈëÃŽ̳̣¬¶øÊÇÎÒ¶ÔÃæÏò¶ÔÏóµÄÀí½â¡£
......

PHPÊý¾ÝÀàÐ͵Äת»»

Ô­ÎÄÁ´½Ó£ºhttp://www.phpdo.net/index.php/2010/02/09/1-12/
PHPµÄÊý¾ÝÀàÐ͵Äת»»ÓÐÁ½ÖÖ·½·¨¿ÉÒÔ°ìµ½£ºÖ±½ÓÊäÈëÄ¿±êµÄÊý¾ÝÀàÐͺÍͨ¹ýsettypeº¯ÊýʵÏÖ¡£
PHPÊý¾Ýת»»³ÉÕûÊý
FloatÐÍÊý¾Ýת»»³ÉintÐÍ
FloatÐÍת»»³ÉintÐÍ£¬Ð¡ÊýµãºóµÄÊý½«±»ÉáÆú¡£Èç¹ûfloatÊý³¬¹ó³¬¹ýÁËÕûÐ͵Äȡֵ·¶Î§£¬ÄÇô½á¹û¿ÉÄÜÊÇ0»òÕßÊÇÕûÐεÄ×îС¸º ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØÍ¼ | ¸ÓICP±¸09004571ºÅ