Home Backend Development PHP Tutorial Summary of some safe hidden codes in php_PHP tutorial

Summary of some safe hidden codes in php_PHP tutorial

Jul 13, 2016 pm 05:10 PM
php code install Safety right application develop Summarize of program programmer hide

The security of program code is a reflection of a programmer’s multi-faceted qualities in developing applications. Let me summarize my experience below. Friends who need to know more can refer to it.

Baidu. After setting open_basedir, only php scripts in the specified directory and subdirectory will be executed.
Using php to read directories or files other than open_basedir will report an error
Insufficient permissions
Generally, virtual host providers are set to /tmp and /home

This is what users are used to. We need to find ways to solve these problems. Here is a summary of some PHP security issues.

1. Be careful when including. Check whether you have this file locally to avoid security vulnerabilities.
For example:

The code is as follows
 代码如下 复制代码
include $module.'.php';
?>
Copy code


Include $module.'.php';
?>
 代码如下 复制代码
if(file_exists($module.'.php')){
include $module.'.php';
}
?>



It is assumed here that $module is function/42833.htm target=_blank>global variable.
This script gives the attacker the opportunity to execute any PHP code on your server. For example, he can just add ?module=http://example.com/my after the browser URL. When PHP receives this URL, the value of the "$module" variable in the script will be set to http://example.com/my. Therefore, it is very dangerous when php executes include...
Solution: Check when closing register_globals or include in php.ini.

2. Run scripts across sites. Simply put, an attacker can execute some client-side scripts, such as js, on the user's browser, and then steal the user's cookies or other important data.
The code is as follows
Copy code
 代码如下 复制代码
$query "select login_id from users where user='$user' and pwd='$pw'";
mysql_query($query);
?>
If(file_exists($module.'.php')){
include $module.'.php';
}

?>
 代码如下 复制代码
$query = "select login_id from user where user='admin' or (user = '' and pwd='') or user=''";
mysql_query($query);
?>


For example If you click the button, your local cookie information will be sent to someone's email address (this shows how easy it is to create a website that steals user information). 3.SQL injection Personally, I feel that the flexibility and ease of use of SQL itself have a negative impact on me.
The code is as follows Copy code
$query "select login_id from users where user='$user' and pwd='$pw'";<🎜> Mysql_query($query);<🎜> ?> For example, if someone writes it http://example.com/login.php?user=admin'%20OR%20(user='&pwd=')%20R%20user=' Your php code may become.
The code is as follows Copy code
$query = "select login_id from user where user='admin' or (user = '' and pwd='') or user=''";<🎜> Mysql_query($query);<🎜> ?> You can use functions to filter out (') ("), (), etc.

www.bkjia.comtruehttp: //www.bkjia.com/PHPjc/629659.htmlTechArticleThe security of program code is a programmer’s multi-faceted quality in developing applications. Let me summarize it below Let’s talk about my own experience, and friends who need to know more can refer to it. Baidu one...
Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
2 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Hello Kitty Island Adventure: How To Get Giant Seeds
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
Two Point Museum: All Exhibits And Where To Find Them
1 months ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

CakePHP Project Configuration CakePHP Project Configuration Sep 10, 2024 pm 05:25 PM

In this chapter, we will understand the Environment Variables, General Configuration, Database Configuration and Email Configuration in CakePHP.

PHP 8.4 Installation and Upgrade guide for Ubuntu and Debian PHP 8.4 Installation and Upgrade guide for Ubuntu and Debian Dec 24, 2024 pm 04:42 PM

PHP 8.4 brings several new features, security improvements, and performance improvements with healthy amounts of feature deprecations and removals. This guide explains how to install PHP 8.4 or upgrade to PHP 8.4 on Ubuntu, Debian, or their derivati

CakePHP Date and Time CakePHP Date and Time Sep 10, 2024 pm 05:27 PM

To work with date and time in cakephp4, we are going to make use of the available FrozenTime class.

CakePHP File upload CakePHP File upload Sep 10, 2024 pm 05:27 PM

To work on file upload we are going to use the form helper. Here, is an example for file upload.

CakePHP Routing CakePHP Routing Sep 10, 2024 pm 05:25 PM

In this chapter, we are going to learn the following topics related to routing ?

Discuss CakePHP Discuss CakePHP Sep 10, 2024 pm 05:28 PM

CakePHP is an open-source framework for PHP. It is intended to make developing, deploying and maintaining applications much easier. CakePHP is based on a MVC-like architecture that is both powerful and easy to grasp. Models, Views, and Controllers gu

CakePHP Creating Validators CakePHP Creating Validators Sep 10, 2024 pm 05:26 PM

Validator can be created by adding the following two lines in the controller.

How To Set Up Visual Studio Code (VS Code) for PHP Development How To Set Up Visual Studio Code (VS Code) for PHP Development Dec 20, 2024 am 11:31 AM

Visual Studio Code, also known as VS Code, is a free source code editor — or integrated development environment (IDE) — available for all major operating systems. With a large collection of extensions for many programming languages, VS Code can be c

See all articles