PHPÖÐÖ´ÐÐϵͳÍⲿÃüÁî
PHP×÷ΪһÖÖ·þÎñÆ÷¶ËµÄ½Å±¾ÓïÑÔ£¬Ïó±àд¼òµ¥£¬»òÕßÊǸ´ÔӵĶ¯Ì¬ÍøÒ³ÕâÑùµÄÈÎÎñ£¬ËüÍêÈ«Äܹ»Ê¤ÈΡ£µ«ÊÂÇé²»×ÜÊÇÈç´Ë£¬ÓÐʱΪÁËʵÏÖij¸ö¹¦ÄÜ£¬±ØÐë½èÖúÓÚ
²Ù×÷ϵͳµÄÍⲿ³ÌÐò£¨»òÕß³ÆÖ®ÎªÃüÁ£¬ÕâÑù¿ÉÒÔ×öµ½Ê°빦±¶¡£
¡¡¡¡ÄÇô£¬ÊÇ·ñ¿ÉÒÔÔÚPHP½Å±¾Öе÷ÓÃÍⲿÃüÁîÄØ£¿Èç¹ûÄÜ£¬ÈçºÎÈ¥×öÄØ£¿
ÓÐЩʲô·½ÃæµÄ¹ËÂÇÄØ£¿ÏàÐÅÄã¿´Á˱¾Îĺ󣬿϶¨Äܹ»»Ø´ðÕâЩÎÊÌâÁË¡£
ÊÇ·ñ¿ÉÒÔ£¿
¡¡¡¡´ð°¸Êǿ϶¨µÄ¡£PHPºÍÆäËüµÄ³ÌÐòÉè
¼ÆÓïÑÔÒ»Ñù£¬ÍêÈ«¿ÉÒÔÔÚ³ÌÐòÄÚµ÷ÓÃÍⲿÃüÁ²¢ÇÒÊǺܼòµ¥µÄ£ºÖ»ÒªÓÃÒ»¸ö»ò¼¸¸öº¯Êý¼´¿É¡£
ǰÌáÌõ¼þ
¡¡¡¡ÓÉÓÚPHP»ù±¾ÊÇ
ÓÃÓÚWEB³ÌÐò¿ª·¢µÄ£¬ËùÒÔ°²È«ÐÔ³ÉÁËÈËÃÇ¿¼ÂǵÄÒ»¸öÖØÒª·½Ãæ¡£ÓÚÊÇPHPµÄÉè¼ÆÕßÃǸøPHP¼ÓÁËÒ»¸öÃÅ£º°²È«Ä£Ê½¡£Èç¹ûÔËÐÐÔÚ°²È«Ä£Ê½Ï£¬ÄÇôPHP½Å
±¾Öн«Êܵ½ÈçÏÂËĸö·½ÃæµÄÏÞÖÆ£º
Ö´ÐÐÍⲿÃüÁî
ÔÚ´ò¿ªÎļþʱÓÐЩÏÞÖÆ
Á¬½ÓMySQLÊý¾Ý¿â
»ùÓÚHTTPµÄÈÏÖ¤
¡¡
¡¡ÔÚ°²È«Ä£Ê½Ï£¬Ö»ÓÐÔÚÌØ¶¨Ä¿Â¼ÖеÄÍⲿ³ÌÐò²Å¿ÉÒÔ±»Ö´ÐУ¬¶ÔÆäËü³ÌÐòµÄµ÷Óý«±»¾Ü¾ø¡£Õâ¸öĿ¼¿ÉÒÔÔÚphp.iniÎļþÖÐÓÃ
safe_mode_exec_dirÖ¸Á»òÔÚ±àÒëPHPÊǼÓÉÏ--with-exec-dirÑ¡ÏîÀ´Ö¸¶¨£¬Ä¬ÈÏÊÇ/usr/local/php
/bin¡£
Èç¹ûÄãµ÷ÓÃÒ»¸öÓ¦¸Ã¿ÉÒÔÊä³ö½á¹ûµÄÍⲿÃüÁÒâ˼ÊÇPHP½Å±¾Ã»ÓдíÎ󣩣¬µÃµ½µÄÈ´ÊÇһƬ¿Õ°×£¬ÄÇôºÜ¿ÉÄÜÄãµÄÍø¹ÜÒѾ°Ñ
PHPÔËÐÐÔÚ°²È«Ä£Ê½ÏÂÁË¡£
ÈçºÎ×ö£¿
ÔÚPHPÖе÷ÓÃÍⲿÃüÁ¿ÉÒÔÓÃÈçÏÂÈýÖÖ·½·¨À´ÊµÏÖ£º
1£©
ÓÃPHPÌṩµÄרÃź¯Êý
PHPÌṩ¹²ÁË3¸öרÃŵÄÖ´ÐÐÍⲿÃüÁîµÄº¯Êý£ºsystem()£¬exec()£¬passthru()¡£
system()
Ô
ÐÍ£ºstring system (string command [, int return_var])
system()º¯ÊýºÜÆäËü
ÓïÑÔÖеIJ¶à£¬ËüÖ´Ðиø¶¨µÄÃüÁÊä³öºÍ·µ»Ø½á¹û¡£µÚ¶þ¸ö²ÎÊýÊÇ¿ÉÑ¡µÄ£¬ÓÃÀ´µÃµ½ÃüÁîÖ´ÐкóµÄ״̬Âë¡£
Àý×Ó£º
<?php
system
(
"/usr/local/bin/webalizer/webalizer"
);
?>
exec()
ÔÐÍ£ºstring exec (string command [,
string array [, int return_var]])
exec()º¯ÊýÓësystem()ÀàËÆ£¬Ò²Ö´Ðиø¶¨µÄÃüÁµ«²»
Êä³ö½á¹û£¬¶øÊÇ·µ»Ø½á¹ûµÄ×îºóÒ»ÐС£ËäÈ»ËüÖ»·µ»ØÃüÁî½á¹ûµÄ×îºóÒ»ÐУ¬µ«Óõڶþ¸ö²ÎÊýarray¿ÉÒԵõ½ÍêÕûµÄ½á¹û£¬·½·¨Êǰѽá¹ûÖðÐÐ×·¼Óµ½arrayµÄ
½áβ´¦¡£ËùÒÔÈç¹ûarray²»Êǿյģ¬ÔÚµ÷ÓÃ֮ǰ×îºÃÓÃunset()×îËüÇåµô¡£Ö»ÓÐÖ¸¶¨Á˵ڶþ¸ö²ÎÊýʱ£¬²Å¿ÉÒÔÓõÚÈý¸ö²ÎÊý£¬ÓÃÀ´È¡µÃÃüÁîÖ´ÐеÄ״̬
Âë¡£
Àý×Ó£º
<?php
exec
(
"/bin/ls -l"
);
e
Ïà¹ØÎĵµ£º
1.ʹÓÃip2long() ºÍlong2ip()º¯ÊýÀ´°ÑIPµØÖ·×ª»¯³ÉÕûÐÍ´æ´¢µ½Êý¾Ý¿âÀï¡£
¡¡¡¡ÕâÖÖ·½·¨°Ñ´æ´¢¿Õ¼ä½µµ½Á˽ӽüËÄ·ÖÖ®Ò»(char(15)µÄ15¸ö×Ö½Ú¶ÔÕûÐεÄ4¸ö×Ö½Ú)£¬¼ÆËãÒ»¸öÌØ¶¨µÄµØÖ·ÊDz»ÊÇÔÚÒ»¸öÇø¶ÎÄÚÒ³¸ü¼òµ¥ÁË£¬¶øÇÒ¼Ó¿ìÁËËÑË÷ºÍÅÅÐòµÄËÙ¶È(ËäÈ»ÓÐʱ½ö½öÊÇ¿ìÁËÒ»µã)¡£
¡¡¡¡2.ÔÚÑéÖ¤EmailµØÖ·µÄʱºòʹÓÃcheckdnsrr() º¯ÊýÑéÖ¤ ......
Õâ¸ö©¶´ÑϸñÉÏ˵²¢²»ÊÇ Nginx ºÍ PHP ±¾ÉíµÄ©¶´Ôì³ÉµÄ£¬¶øÊÇÓÉÅäÖÃÔì³ÉµÄ¡£ÔÚÎÒ֮ǰдµÄÐí¶àÅäÖÃÖУ¬¶¼ÆÕ±é´æÔÚÕâ¸ö©¶´¡£
¼òÒ×¼ì²â·½·¨£º
´ò¿ª Nginx + PHP ·þÎñÆ÷ÉϵÄÈÎÒâÒ»ÕÅͼƬ£¬È磺
http://blog.lrenwang.com/test.png
Èç¹ûÔÚͼƬÁ´½Óºó¼ÓÒ»´® /xxx.php £¨xxxΪÈÎÒâ×Ö·û£©ºó£¬È磺
http://blog.lrenwang.com/ ......
Ô¤ÆÚ×¼±¸£º
Ò»¸ö139ÓÊÏ䣬ÊÕµ½Óʼþºó£¬¿ÉÒÔÃâ·Ñ¸øÄã¶ÌÐÅÌáÐÑ¡£Èç¹ûÄã²»ÐèÒª¶ÌÐÅÌáÐѹ¦ÄÜ£¬ÓÃʲôÓÊÏä¶¼¿ÉÒÔ
ÁíÍâÒ»¸ö¿ÉÒÔÔËÐÐPHPÎļþµÄWeb·þÎñÆ÷£¨Ï൱ÓÚ¼à¿Ø·þÎñÆ÷£©£¬ÏÖÔÚÃâ·ÑµÄPHPÍøÕ¾¿Õ¼äºÜ¶à£¬ÉÏÍøËÑËÑ¡£Èç¹û½«PHP¼à¿ØÎļþ·Åµ½Äã×Ô¼ºµÄ·þÎñ
Æ÷ÉÏ£¬Õâ¸ö¼à¿ØÎļþÒ²¾ÍµÈÓÚ°ÚÉ裬·þÎñÆ÷¹ÒµôÁË£¬ËüÒ²ÎÞ·¨ÔËÐÐÁË£¬ÔõÃ´Ä ......
ÎÒÔÚmy.cnfÖÐ×¢Ê͵ôlog-bin=mysql-binºÍbinlog_format=mixedºó,ÎÞ·¨Æô¶¯mysql
ÎÒÖØÆôvpsºó,ÄÜÆô¶¯mysqlÀ²
ÓÃweb·½Ê½ÔËÐÐphp,Õý³£
µ«ÊÇÔÚcrontabÀïÖ´ÐеÄphp½Å±¾,Ìáʾ: Can't connect to local MySQL server through socket '/var/lib/mysql/mysql.sock' (2) ²é¿´µ½/var/lib/mysql/Ŀ¼ÏÂ,ÓÐÒ»¸ömysql.s ......
isset() ¡¾1¡¿
Returns TRUE if var
exists and has value other
than NULL, FALSE otherwise.
ÊäÈë¿ÉÒÔÊǶà¸ö±äÁ¿£¬Ö»ÓÐËùÓеıäÁ¿ÎªÕæµÄʱºò£¬·µ»ØÕæ
empty()¡¾2¡¿
Returns FALSE if var
has a non-empty
and non-zero value.
The following things are considered to be empty:
"" (an em ......