- 主动攻击(主动攻击server)
- 被动攻击(上传木马程序,用户訪问时触发http陷阱)
- client验证
- 服务端验证(输入值验证。输出值转义)
php
$clean = array();
$mysql = array();
$clean['last_name'] = "O'Reilly";
$mysql['last_name'] = mysql_real_escape_string($clean['last_name']);
$sql = "INSERT
INTO user (last_name)
VALUES ('{$mysql['last_name']}')";
?>
mysqli_real_escape_string
(PHP 5)
mysqli::real_escape_string -- mysqli_real_escape_string — Escapes
special characters in a string for use in an SQL statement, taking into account the current charset of the connection
尽量使用为你的数据库设计的转义函数。
假设没有,使用函数addslashes()是终于的比較好的方法。
$str
)返回字符串。该字符串为了数据库查询语句等的须要在某些字符前加上了反斜线。
这些字符是单引號(')、双引號(")、反斜线(\)与
NUL( NULL
字符)。
- '&' (ampersand) becomes '&'
- '"' (double quote) becomes '"' when
ENT_NOQUOTES
is not set. - "'" (single quote) becomes ''' (or ') only when
ENT_QUOTES
is
set. - '<' (less than) becomes '<'
- '>' (greater than) becomes '>'
php
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuc2h1emhpZHVvLmNvbS9Vc2Vycy9ndW94aWFvdGluZy9BcHBEYXRhL0xvY2FsL1lOb3RlL2RhdGEvcGV0ZXIudGFuZ2RvbmdAMTYzLmNvbS9hYTQ0ODllOGMzOTY0ODhmYTAxMWVlMDUwM2IxNzYwNC9jbGlwYm9hcmQucG5n.png?w=700&webp=1)
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/.jpg?w=700&webp=1)
watermark/2/text/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvdGQ5MDExMDV0ZA==/font/5a6L5L2T/fontsize/400/fill/I0JBQkFCMA==/dissolve/70/gravity/Center" alt="">
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/.jpg?w=700&webp=1)
watermark/2/text/aHR0cDovL2Jsb2cuY3Nkbi5uZXQvdGQ5MDExMDV0ZA==/font/5a6L5L2T/fontsize/400/fill/I0JBQkFCMA==/dissolve/70/gravity/Center" alt="">
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/.jpg?w=700&webp=1aHR0cHM6Ly93d3cuc2h1emhpZHVvLmNvbS9Vc2Vycy9ndW94aWFvdGluZy9BcHBEYXRhL0xvY2FsL1lOb3RlL2RhdGEvcGV0ZXIudGFuZ2RvbmdAMTYzLmNvbS8zNWZjOTgxMTY2NjE0Zjk1OWI0Mjk0NDE4YmJiODQ3ZS9jbGlwYm9hcmQucG5n)
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/.jpg?w=700&webp=1aHR0cHM6Ly9iYnNtYXguaWthZmFuLmNvbS9zdGF0aWMvTDNCeWIzaDVMMmgwZEhBdmFXMW5MbUpzYjJjdVkzTmtiaTV1WlhRdk1qQXhOVEEyTWpVeE5UQTJNekl3TnpVL2QyRjBaWEp0WVhKckx6SXZkR1Y0ZEM5aFNGSXdZMFJ2ZGt3eVNuTmlNbU4xV1ROT2EySnBOWFZhV0ZGMlpFZFJOVTFFUlhoTlJGWXdXa0U5UFM5bWIyNTBMelZoTmt3MVRESlVMMlp2Ym5SemFYcGxMelF3TUM5bWFXeHNMMGt3U2tKUmEwWkRUVUU5UFM5a2FYTnpiMngyWlM4M01DOW5jbUYyYVhSNUwwTmxiblJsY2c9PS5qcGc=)
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/.jpg?w=700&webp=1aHR0cHM6Ly9iYnNtYXguaWthZmFuLmNvbS9zdGF0aWMvTDNCeWIzaDVMMmgwZEhBdmFXMW5MbUpzYjJjdVkzTmtiaTV1WlhRdk1qQXhOVEEyTWpVeE5UQTNNVEUzTXpNL2QyRjBaWEp0WVhKckx6SXZkR1Y0ZEM5aFNGSXdZMFJ2ZGt3eVNuTmlNbU4xV1ROT2EySnBOWFZhV0ZGMlpFZFJOVTFFUlhoTlJGWXdXa0U5UFM5bWIyNTBMelZoTmt3MVRESlVMMlp2Ym5SemFYcGxMelF3TUM5bWFXeHNMMGt3U2tKUmEwWkRUVUU5UFM5a2FYTnpiMngyWlM4M01DOW5jbUYyYVhSNUwwTmxiblJsY2c9PS5qcGc=)
![web攻击方式和防御方法 web攻击方式和防御方法](https://image.shishitao.com:8440/.jpg?w=700&webp=1aHR0cHM6Ly93d3cuc2h1emhpZHVvLmNvbS9Vc2Vycy9ndW94aWFvdGluZy9BcHBEYXRhL0xvY2FsL1lOb3RlL2RhdGEvcGV0ZXIudGFuZ2RvbmdAMTYzLmNvbS9iNmRlMGE3OWZjN2Y0MzgxOTNkNzhiYTRmNzY3N2FjZS9jbGlwYm9hcmQucG5n)