ÍøÂçѧԺ w3popÉçÇø ÍøÂç×ÊÔ´ ITÐÂÎÅ

w3pop.com :: ÍøÂçѧԺ :: PHP :: PHP ¿çÕ¾µã½Å±¾¹¥»÷

»áÔ±µÇ½

ÕʺÅ

ÃÜÂë

»Ø´ð

¼ÇסÃÜÂë

Íü¼ÇÃÜÂë? ×¢²á

PHP
WINDOWSϰ²×°MyS..
PHP ÖÆ×÷ ÍøÕ¾/·þ..
ÓÃPHPºÍCSSÖÆ×÷»î..
PHP µ¥¼þģʽ
PHP MVCģʽ£¬Àà·..
PHP ÖÐʹÓÃÕýÔò±í..
PHP ·ÀÖ¹ SQL ×¢È..
PHP ¿çÕ¾µã½Å±¾¹¥..
PHP ·ÀÖ¹Óû§²Ù×Ý..
PHP ·ÀÖ¹Ô¶³Ì±íµ¥..

PHP ¿çÕ¾µã½Å±¾¹¥»÷


×÷Õß:ibm.com ·­Òë/ÕûÀí:w3pop.com ·¢²¼:2007-10-11 ä¯ÀÀ:2262 :: ::

ÔÚ¿çÕ¾µã½Å±¾£¨XSS£©¹¥»÷ÖУ¬ÍùÍùÓÐÒ»¸ö¶ñÒâÓû§ÔÚ±íµ¥ÖУ¨»òͨ¹ýÆäËûÓû§ÊäÈ뷽ʽ£©ÊäÈëÐÅÏ¢£¬ÕâЩÊäÈ뽫¶ñÒâµÄ¿Í»§¶Ë±ê¼Ç²åÈë¹ý ³Ì»òÊý¾Ý¿âÖС£ÀýÈ磬¼ÙÉèÕ¾µãÉÏÓÐÒ»¸ö¼òµ¥µÄÀ´¿ÍµÇ¼Ç²¾³ÌÐò£¬È÷ÃÎÊÕßÄܹ»ÁôÏÂÐÕÃû¡¢µç×ÓÓʼþµØÖ·ºÍ¼ò¶ÌµÄÏûÏ¢¡£¶ñÒâÓû§¿ÉÒÔÀûÓÃÕâ¸ö»ú»á²åÈë¼ò¶ÌÏûÏ¢Ö® ÍâµÄ¶«Î÷£¬±ÈÈç¶ÔÓÚÆäËûÓû§²»ºÏÊʵÄͼƬ»ò½«Óû§Öض¨Ïòµ½ÁíÒ»¸öÕ¾µãµÄ JavaScript£¬»òÕßÇÔÈ¡ cookie ÐÅÏ¢¡£

ÐÒÔ˵ÄÊÇ£¬PHP ÌṩÁË strip_tags() º¯Êý£¬Õâ¸öº¯Êý¿ÉÒÔÇå³ýÈκΰüΧÔÚ HTML ±ê¼ÇÖеÄÄÚÈÝ¡£strip_tags() º¯Êý»¹ÔÊÐíÌṩÔÊÐí±ê¼ÇµÄÁÐ±í£¬±ÈÈç <b> »ò <i>¡£

Çåµ¥ 16 ¸ø³öÒ»¸öʾÀý£¬Õâ¸öʾÀýÊÇÔÚǰһ¸öʾÀýµÄ»ù´¡ÉϹ¹½¨µÄ¡£


Çåµ¥ 16. ´ÓÓû§ÊäÈëÖÐÇå³ý HTML ±ê¼Ç


<?php
if ($_POST['submit'] == "go"){
//Çå³ý±êÇ©
$name = strip_tags($_POST['name']);
$name = substr($name,0,40);
//Çå³ý16½øÖÆ×Ö·û
$name = cleanHex($name);
//continue processing....
}

function cleanHex($input){
$clean = preg_replace\
("![\][xX]([A-Fa-f0-9]{1,3})!", "",$input);
return $clean;
}
?>


<form action=\
"<?php echo $_SERVER['PHP_SELF'];?>" method="post">
<p><label for="name">Name</label>
<input type=\
"text" name="name" id="name" size="20" maxlength="40"/></p>

<p><input type="submit" name="submit" value="go"/></p>
</form>

 

´Ó°²È«µÄ½Ç¶ÈÀ´¿´£¬¶Ô¹«¹²Óû§ÊäÈëʹÓà strip_tags() ÊDZØÒªµÄ¡£Èç¹û±íµ¥ÔÚÊܱ£»¤ÇøÓò£¨±ÈÈçÄÚÈݹÜÀíϵͳ£©ÖУ¬¶øÇÒÄúÏàÐÅÓû§»áÕýÈ·µØÖ´ÐÐËûÃǵÄÈÎÎñ£¨±ÈÈçΪ Web Õ¾µã´´½¨ HTML ÄÚÈÝ£©£¬ÄÇôʹÓà strip_tags() ¿ÉÄÜÊDz»±ØÒªµÄ£¬»áÓ°Ï칤×÷ЧÂÊ¡£

»¹ÓÐÒ»¸öÎÊÌ⣺Èç¹ûÒª½ÓÊÜÓû§ÊäÈ룬±ÈÈç¶ÔÌù×ӵįÀÂÛ»òÀ´¿ÍµÇ¼ÇÏ²¢ÐèÒª½«Õâ¸öÊäÈëÏòÆäËûÓû§ÏÔʾ£¬ÄÇôһ¶¨Òª½«ÏìÓ¦·ÅÔÚ PHP µÄ htmlspecialchars() º¯ÊýÖС£Õâ¸öº¯Êý½«Óë·ûºÅ¡¢< ºÍ > ·ûºÅת»»Îª HTML ʵÌå¡£ÀýÈ磬Óë·ûºÅ£¨&£©±ä³É &amp;¡£ÕâÑùµÄ»°£¬¼´Ê¹¶ñÒâÄÚÈݶ㿪ÁËǰ¶Ë strip_tags() µÄ´¦Àí£¬Ò²»áÔÚºó¶Ë±» htmlspecialchars() ´¦Àíµô¡£

ÆÀÂÛ (0) All