{"id":111,"date":"2012-11-07T18:49:28","date_gmt":"2012-11-07T10:49:28","guid":{"rendered":"http:\/\/www.yeetrack.com\/post\/2012-11-07\/php%25E8%25BF%2587%25E6%25BB%25A4%25E5%2599%25A8"},"modified":"2013-04-20T17:29:16","modified_gmt":"2013-04-20T09:29:16","slug":"php%e8%bf%87%e6%bb%a4%e5%99%a8","status":"publish","type":"post","link":"https:\/\/www.yeetrack.com\/?p=111","title":{"rendered":"php\u8fc7\u6ee4\u5668"},"content":{"rendered":"<p> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Web\u7a0b\u5e8f\u540e\u53f0\u5904\u7406\u8bf7\u6c42\u65f6\uff0c\u4e0d\u80fd\u76f8\u4fe1\u5ba2\u6237\u7aef\u7684\u8f93\u5165\uff0c\u8981\u628a\u4e00\u5207\u8f93\u5165\u90fd\u770b\u505a\u5e26\u6709\u6076\u610f\u6570\u636e\u3002<\/p>\n<p><!--more--><\/p>\n<p>\u5bf9\u7528\u6237\u8f93\u5165\u7684\u5185\u5bb9\u8981\u8fdb\u884c\u5404\u79cd\u8fc7\u6ee4\uff0c\u786e\u4fdd\u7a0b\u5e8f\u5728\u6309\u7167\u6307\u5b9a\u7684\u8def\u5f84\u8fd0\u884c\u3002PHP\u81ea\u5e26\u4e86\u4e00\u4e9b\u8fc7\u6ee4\u51fd\u6570\u3002 <\/p>\n<ul>\n<li>\n<p>filter_var() - \u901a\u8fc7\u4e00\u4e2a\u6307\u5b9a\u7684\u8fc7\u6ee4\u5668\u6765\u8fc7\u6ee4\u5355\u4e00\u7684\u53d8\u91cf<\/p>\n<\/li>\n<li>\n<p>filter_var_array() - \u901a\u8fc7\u76f8\u540c\u7684\u6216\u4e0d\u540c\u7684\u8fc7\u6ee4\u5668\u6765\u8fc7\u6ee4\u591a\u4e2a\u53d8\u91cf<\/p>\n<\/li>\n<li>\n<p>filter_input - \u83b7\u53d6\u4e00\u4e2a\u8f93\u5165\u53d8\u91cf\uff0c\u5e76\u5bf9\u5b83\u8fdb\u884c\u8fc7\u6ee4<\/p>\n<\/li>\n<li>\n<p>filter_input_array - \u83b7\u53d6\u591a\u4e2a\u8f93\u5165\u53d8\u91cf\uff0c\u5e76\u901a\u8fc7\u76f8\u540c\u7684\u6216\u4e0d\u540c\u7684\u8fc7\u6ee4\u5668\u5bf9\u5b83\u4eec\u8fdb\u884c\u8fc7\u6ee4<\/p>\n<\/li>\n<\/ul>\n<p>\u4e0b\u9762\u4f7f\u7528filter_var()\u6765\u9a8c\u8bc1\u4e00\u4e2a\u6574\u6570\uff1a<\/p>\n<pre config=\"brush:php;toolbar:false;\">&lt;?php\n$int=123;\n              \nif(filter_var($int, FILTER_VALIDATE_INT)) \/\/FILTER_VALIDATE_INT\u662f\u6574\u6570\u8fc7\u6ee4\u5668\necho &quot;\u6570\u5b57\u6709\u6548&quot;;\nelse\necho &quot;\u6570\u5b57\u975e\u6cd5&quot;;\n?&gt;<\/pre>\n<p>filter_input() \u51fd\u6570\u7528\u6765\u8fc7\u6ee4\u8f93\u5165\u7684\u6570\u636e\uff0cfilter_input()\u53ef\u4ee5\u83b7\u53d6\u8f93\u5165\u7684\u53d8\u91cf\uff0c\u5982\u4e0b\u4ee3\u7801\uff1a<\/p>\n<pre config=\"brush:php;toolbar:false;\">&lt;?php\nif(!filter_has_var(INPUT_GET,&quot;email&quot;)) \/\/INPUT_GET\u7528\u4e8e\u83b7\u53d6\u5168\u5c40\u53d8\u91cf\uff0c\u8fd9\u91cc\u7528\u6765\u83b7\u53d6\u7528GET\u65b9\u6cd5\u63d0\u4ea4\u7684\u6570\u636e\uff0c\u53c2\u89c1\uff1a&lt;A href='http:\/\/www.51cto.com\/art\/200710\/58950.htm&quot;&gt;http:\/\/www.51cto.com\/art\/200710\/58950.htm'&gt;http:\/\/www.51cto.com\/art\/200710\/58950.htm&quot;&gt;http:\/\/www.51cto.com\/art\/200710\/58950.htm&lt;\/A&gt;\necho &quot;\u6570\u636e\u4e0d\u5b58\u5728&quot;;\nelse\n{\nif(!filter_input(INPUT_GET,&quot;email&quot;,FILTER_VALIDATE_EMAIL)) \/\/\u7528FILTER_VALIDATE_EMAIL\u8fc7\u6ee4\u5668\u6765\u9a8c\u8bc1\u7528\u6237\u8f93\u5165\u7684\u90ae\u7bb1\u662f\u5426\u5408\u6cd5\necho &quot;\u90ae\u7bb1\u975e\u6cd5&quot;;\nelse\necho &quot;\u90ae\u7bb1\u5408\u6cd5&quot;;\n}\n?&gt;<\/pre>\n<p>\u5c06\u4e0a\u9762\u4ee3\u7801\u4fdd\u5b58\u6210checkmail.php\u653e\u5230\u670d\u52a1\u5668\u4e0a\uff0c\u7136\u540e\u6211\u4eec\u518d\u7b80\u5355\u7f16\u5199\u4e00\u4e2aform\u8868\u5355\uff0c\u7528\u4e8e\u63d0\u4ea4\u90ae\u7bb1\uff0c\u5982\u4e0b\uff1a<\/p>\n<pre config=\"brush:html;toolbar:false;\">&lt;html&gt;\n&lt;body&gt;\n&lt;form method=&quot;get&quot; action=&quot;checkmail.php&quot;&gt;\n&lt;input type=&quot;text&quot; name=&quot;email&quot; &gt;\n&lt;input type=&quot;submit&quot;&gt;\n&lt;\/form&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;<\/pre>\n<p>\u5c06\u4e0a\u9762\u4ee3\u7801\u4fdd\u5b58\u6210submitmail.php\u653e\u5230\u670d\u52a1\u5668\u4e0a\uff0c\u76f4\u63a5\u8bbf\u95ee\u5373\u53ef\u3002<\/p>\n<p> &nbsp;&nbsp;FILTER_SANITIZE_URL\u7528\u6765\u8fc7\u6ee4\u8f93\u5165\u7684URL\uff0c\u5982\u4e0b\u4ee3\u7801\uff1a<\/p>\n<pre config=\"brush:php;toolbar:false;\">&lt;?php\nif(!filter_has_var(INPUT_POST, &quot;url&quot;)) \/\/\u68c0\u67e5\u662f\u5426\u83b7\u53d6\u5230post\u8fc7\u6765\u7684url\u6570\u636e\n{\necho(&quot;Input type does not exist&quot;);\n}\nelse\n{\n$url = filter_input(INPUT_POST, &quot;url&quot;, FILTER_SANITIZE_URL);\necho $url;\n}\n?&gt;<\/pre>\n<p>\u4e0a\u9762\u4ee3\u7801\u4fdd\u5b58\u4e3acheckurl.php,\u7136\u540e\u7f16\u5199form\u8868\u5355\u5982\u4e0b\uff1a<\/p>\n<pre config=\"brush:html;toolbar:false;\">&lt;html&gt;\n&lt;body&gt;\n&lt;form method=&quot;post&quot; action=&quot;checkurl.php&quot;&gt;\n&lt;input type=&quot;text&quot; name=&quot;url&quot;&gt; &lt;!--\u8fd9\u91cc\u53ef\u4ee5\u8f93\u5165\u975e\u6cd5\u7684url\uff0c\u4f8b\u5982 &lt;A href=&quot;http:\/\/ye\u6c49\u5b57etrack.com&quot;&gt;http:\/\/ye\u6c49\u5b57etrack.com&lt;\/A&gt; --&gt;\n&lt;input type=&quot;submit&quot; value=&quot;submit&quot;&gt;\n&lt;\/form&gt;\n&lt;\/body&gt;\n&lt;\/html&gt;<\/pre>\n<p>\u540c\u6837\u4fdd\u5b58\u5230\u670d\u52a1\u5668\uff0c\u76f4\u63a5\u8bbf\u95ee\u5373\u53ef\u3002<br \/> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u6211\u4eec\u8fd8\u53ef\u4ee5\u81ea\u5b9a\u4e49\u8fc7\u6ee4\u5668\uff0c\u5982\u4e0b\uff0c\u4e0b\u9762\u7684\u4ee3\u7801\u5c06\u5355\u5f15\u53f7\u524d\u9762\u52a0\u4e0a\uff0c\u53d6\u6d88\u5176\u7279\u6b8a\u610f\u4e49\uff0c\u5e38\u7528\u6765\u9632\u5fa1sql\u6ce8\u5165\u3002<\/p>\n<pre config=\"brush:php;toolbar:false;\">&lt;?php\nfunction myFilter($string)\n{\nreturn str_replace(&quot;'&quot;, &quot;'&quot;, $string);\n}\n     \n$string = &quot;admin' or 1=1-- &quot;;\n     \necho filter_var($string, FILTER_CALLBACK, array(&quot;options&quot;=&gt;&quot;myFilter&quot;));\n?&gt;<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Web\u7a0b\u5e8f\u540e\u53f0\u5904\u7406\u8bf7\u6c42\u65f6\uff0c\u4e0d\u80fd\u76f8\u4fe1\u5ba2\u6237\u7aef\u7684\u8f93\u5165\uff0c\u8981\u628a\u4e00\u5207\u8f93\u5165\u90fd\u770b\u505a\u5e26\u6709\u6076\u610f\u6570\u636e\u3002<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"pgc_sgb_lightbox_settings":"","footnotes":""},"categories":[33],"tags":[24,7],"class_list":["post-111","post","type-post","status-publish","format-standard","hentry","category-coding","tag-php","tag-7"],"views":3591,"_links":{"self":[{"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=\/wp\/v2\/posts\/111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=111"}],"version-history":[{"count":2,"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=\/wp\/v2\/posts\/111\/revisions"}],"predecessor-version":[{"id":422,"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=\/wp\/v2\/posts\/111\/revisions\/422"}],"wp:attachment":[{"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.yeetrack.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}