? ????? ? ? ?? ??? ????, ?? 360???? ??? ?? ???? ?????. ???, 360? ??? ?? ?? ?? ????
sql ??
??? ?? 1:
http: //xxx.com:80/index.php?alias=message&action=comment?comment-diary-id=1&comment-ip=182.118.33.8&comment-author=88888&comment-email =hacker@hacker.org&comment-url=http: //www.hacker.org/&comment-text=88888&comment-submit=SEND&comment-parent=0 RLIKE (SELECT (CASE WHEN (4725=4725) THEN 0 ELSE 0x28 END))
??? ?? 2:
http: //xxx.com:80/index.php?alias=message' AND SLEEP(5)%20%23
??? ?? 3:
http: //xxx.com:80/index .php?cat=note' AND 'dSob'='dSob
xss
??? ??:
http: //xxx.com:80/admin/login.php?req_url=/admin/index.php"><script>alert(42873)</script>
??????? ? ? ?? ???? ??? ? ? ??? ?????? ????? ?? 1? ?? 2? ???? ????
? ?? ???? ??? ???? ?? ??????.
??? ??? ?? ???? ??? ????. ??? ??? ?????, ??? ??? ???? ??? ?? ??? ??? ????.
??????? ??? ???? ?? ?? ??? ??????.
PS, ?? ??? SF? ?? ???? ????? http:
?? ??? ?????.
????? ?? ???? ????...?? sql? ?? ? ??????
??????? ??? ?? ?? ??? ????.
?????? ??? ?? ??? ?? ????
???擁有18年軟件開發(fā)和IT教學(xué)經(jīng)驗。曾任多家上市公司技術(shù)總監(jiān)、架構(gòu)師、項目經(jīng)理、高級軟件工程師等職務(wù)。 網(wǎng)絡(luò)人氣名人講師,...
xss ??? html ???? ??, ????? html ???? ????? ???. ?? htmlspecialchars
Connection 1? mysql? ???? ???? mysql? ???? ????. ?? ???? ????? ???.
??, ??? ???? ?? ?? ??? ???? ???? ????! ! ! !
SQL ?? ???? ?? ?????? ??? ???? ?? ?? ????.
xss? ???? ???? ?? <script>
? ?? ???? ??? ???? ? ????.