{"id":450,"date":"2009-06-08T19:53:00","date_gmt":"2009-06-08T11:53:00","guid":{"rendered":""},"modified":"2009-06-08T19:53:00","modified_gmt":"2009-06-08T11:53:00","slug":"","status":"publish","type":"post","link":"https:\/\/kyle.ai\/blog\/450.html","title":{"rendered":"PHP\u4e07\u80fd\u5bc6\u7801"},"content":{"rendered":"<p><html><head><meta http-equiv=\"Content-Type\" content=\"text\/html; charset=utf-8\" \/><title>PHP\u4e07\u80fd\u5bc6\u7801<\/title><\/head><body><\/p>\n<h1 style=\"display:none\">PHP\u4e07\u80fd\u5bc6\u7801<\/h1>\n<div>\n<p>\u8bf4\u5b9e\u8bdd\u5982\u679c\u4e00\u4e2a\u7f51\u7ad9\u7684\u524d\u53f0\u90fd\u662f\u6ce8\u5165\u6f0f\u6d1e\uff0c\u90a3\u4e48\u51ed\u7ecf\u9a8c\uff0c\u4e07\u80fd\u5bc6\u7801\u8fdb\u540e\u53f0\u7684\u51e0\u7387\u57fa\u672c\u4e0a\u662f\u767e\u5206\u4e4b\u767e\u3002<\/p>\n<p>\u53ef\u662f\u6709\u7684\u4eba\u8bf4\u5bf9PHP\u7684\u7ad9\u5982\u679c\u662fGPC\u9b54\u672f\u8f6c\u6362\u5f00\u542f\uff0c\u5c31\u4f1a\u5bf9\u7279\u6b8a\u7b26\u53f7\u8f6c\u4e49\uff0c\u5c31\u5f7b\u5e95\u675c\u7edd\u4e86PHP\u6ce8\u5165\u3002<\/p>\n<p>\u5176\u5b9e\u8bf4\u8fd9\u8bdd\u7684\u4eba\u6ca1\u6709\u597d\u597d\u60f3\u8fc7\uff0c\u66f4\u6ca1\u6709\u5c1d\u8bd5\u8fc7\u7528\u4e07\u80fd\u5bc6\u7801\u8fdbPHP\u7684\u540e\u53f0\u3002<\/p>\n<p>\u5176\u5b9eGPC\u9b54\u672f\u8f6c\u6362\u662f\u5426\u5f00\u542f\u5bf9\u7528\u4e07\u80fd\u5bc6\u7801\u8fdb\u540e\u53f0\u4e00\u70b9\u5f71\u54cd\u4e5f\u6ca1\u6709\u3002<\/p>\n<p>\u5982\u679c\u4f60\u7528\u8fd9\u6837\u7684\u4e07\u80fd\u5bc6\u7801&#8217;or&#8217;=&#8217;or&#8217;\uff0c\u5f53\u7136\u8fdb\u4e0d\u53bb\uff0c\u7406\u7531\u662fGPC\u5f00\u542f\u7684\u65f6\u5019\u5355\u5f15\u53f7\u4f1a\u88ab\u8f6c\u6362\u3002<\/p>\n<p>PHP\u6ce8\u5165\u65f6\u6211\u5e38\u7528\u7684\u4e07\u80fd\u5bc6\u7801\u662f:&#8217;or 1=1\/*.<\/p>\n<p>\u90a3\u6211\u4eec\u5206\u6790\u4e00\u4e0b\u4e3a\u4ec0\u4e48\u8fd9\u53ef\u4ee5\u8fdb\u540e\u53f0\u3002<\/p>\n<p>\u5982\u679csql\u8bed\u53e5\u8fd9\u6837\u5199:&quot;SELECT * FROM admin where name=&#8217;&quot;.$_POST[&#8216;name&#8217;].&quot;&#8217;and password=&#8217;&quot;.$_POST[&#8216;password&#8217;].&quot;&#8217;&quot;,\u90a3\u6211\u4eec\u5728\u5e10\u53f7\u5904\u8f93\u5165\u4e07\u80fd\u5bc6\u7801&#8217;or 1=1\/*\uff0c\u5bc6\u7801\u968f\u4fbf\u8f93\uff0csql\u8bed\u53e5\u5c31\u6210\u4e86select * from admin where name=&#8217;&rsquo;or 1=1\/*&#8217; and password=&#8217;\u4efb\u610f\u5b57\u7b26&#8217;\u3002\/*\u4e3amysql\u7684\u6ce8\u91ca\u7b26\uff0c\u8fd9\u6837\u540e\u9762\u7684\u4e1c\u897f\u5c31\u90fd\u88ab\u6ce8\u91ca\u6389\u4e86\uff0c\u4e5f\u5c31\u662f\u4e3a\u4ec0\u4e48\u5bc6\u7801\u968f\u4fbf\u8f93\u7684\u539f\u56e0\u3002<\/p>\n<p>\u5047\u8bbeGPC\u8f6c\u6362\u6ca1\u6709\u5f00\u542f\uff0c\u90a3\u4e48\u8bf7\u770b\uff1awhere name=&#8217;&rsquo;or 1=1\uff08*\/\u540e\u9762\u7684\u4e1c\u897f\u88ab\u6ce8\u91ca\u6389\u4e86\uff09\uff0cname=&#8217;&rsquo;\u7684\u903b\u8f91\u503c\u4e3a\u5047\uff0c\u800c\u540e\u9762\u76841=1\u903b\u8f91\u503c\u5219\u4e3a\u771f\uff0c\u5bf9\u4e8e\u6574\u4f53\u5c31\u6210\u4e86\u5047 or \u771f\uff0c\u6700\u7ec8\u7684\u903b\u8f91\u503c\u8fd8\u662f\u771f\uff0c\u5c31\u8fdb\u540e\u53f0\u4e86\u3002<\/p>\n<p>\u90a3\u4e48\u5982\u679cGPC\u8f6c\u6362\u5f00\u542f\u4e86\uff0c\u5c31\u5bf9\u5355\u5f15\u53f7\u8fdb\u884c\u4e86\u8f6c\u6362\u3002\u8bed\u53e5\u5c31\u53d8\u6210\u4e86where name=&#8217;\\&rsquo;or 1=1,\u5728\u770b\u4e00\u4e0b\u548c\u521a\u624d\u6709\u4ec0\u4e48\u533a\u522b\uff0c\u65e0\u975e\u662f\u591a\u4e86\u4e2a\\\u3002name=&#8217;\\&#8217;\u4e0ename=&#8221;\u7684\u903b\u8f91\u503c\u4e00\u6837\uff0c\u90fd\u4e3a\u5047\uff0c\u90a31=1\u4e3a\u771f\uff0c\u603b\u7684sql\u8bed\u53e5\u7684\u903b\u8f91\u503c\u4e0d\u8fd8\u662f\u771f\u5417\uff1f\u90a3\u6709\u8fdb\u4e0d\u53bb\u540e\u53f0\u7684\u7406\u7531\u5417\uff1f<\/p>\n<p>\u6240\u4ee5\u603b\u7684\u6765\u8bf4\uff0cphp\u7f51\u7ad9\u7684\u4e07\u80fd\u5bc6\u7801\u53ef\u4ee5\u8fd9\u6837\u5199:&#8217;or 1=1\/*\uff0c\u800cGPC\u8f6c\u6362\u662f\u5426\u5f00\u542f\u5bf9\u5b83\u6ca1\u6709\u4efb\u4f55\u5f71\u54cd\uff01<\/p>\n<p>\u6240\u4ee5\u8bf7\u6539\u53d8\u4f60\u7684\u60f3\u6cd5\uff1a\u5b58\u5728\u5b57\u7b26\u578b\u6ce8\u5165\u7684php\u7f51\u7ad9\u662f\u53ef\u4ee5\u7528\u4e07\u80fd\u5bc6\u7801&#8217;or 1=1\/*\u7684\n <\/p>\n<\/div>\n<p><\/body><\/html><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PHP\u4e07\u80fd\u5bc6\u7801 PHP\u4e07\u80fd\u5bc6\u7801 \u8bf4\u5b9e\u8bdd\u5982\u679c\u4e00\u4e2a\u7f51\u7ad9\u7684\u524d\u53f0\u90fd\u662f\u6ce8\u5165\u6f0f\u6d1e\uff0c\u90a3\u4e48\u51ed\u7ecf\u9a8c\uff0c\u4e07\u80fd\u5bc6\u7801\u8fdb\u540e\u53f0\u7684\u51e0\u7387\u57fa\u672c\u4e0a\u662f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-450","post","type-post","status-publish","format-standard","hentry","category-skill"],"_links":{"self":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/comments?post=450"}],"version-history":[{"count":0,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/posts\/450\/revisions"}],"wp:attachment":[{"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/media?parent=450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/categories?post=450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kyle.ai\/blog\/wp-json\/wp\/v2\/tags?post=450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}