小灰博客--小灰IT技术博客 | sky00.com

360大牛提供的PHP防注入代码,你敢用吗?

<?php
//Code By Safe3
function customError($errno, $errstr, $errfile, $errline)
{
echo “<b>Error number:</b> [$errno],error on line $errline in $errfile<br />” ;
die();
}
set_error_handler(“customError”,E_ERROR);
$getfilter=”‘|(and|or)\\b.+?(>|<|=|in|like)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?Select|Update.+?SET|Insert\\s+INTO.+?VALUES|(Select|Delete).+?FROM|(Create|Alter|Drop|TRUNCATE)\\s+(TABLE|DATABASE)” ;
$postfilter=”\\b(and|or)\\b.{1,6}?(=|>|<|\\bin\\b|\\blike\\b)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?Select|Update.+?SET|Insert\\s+INTO.+?VALUES|(Select|Delete).+?FROM|(Create|Alter|Drop|TRUNCATE)\\s+(TABLE|DATABASE)” ;
$cookiefilter=”\\b(and|or)\\b.{1,6}?(=|>|<|\\bin\\b|\\blike\\b)|\\/\\*.+?\\*\\/|<\\s*script\\b|\\bEXEC\\b|UNION.+?Select|Update.+?SET|Insert\\s+INTO.+?VALUES|(Select|Delete).+?FROM|(Create|Alter|Drop|TRUNCATE)\\s+(TABLE|DATABASE)” ;
function StopAttack($StrFiltKey,$StrFiltValue,$ArrFiltReq){

if(is_array($StrFiltValue))
{
$StrFiltValue=implode($StrFiltValue);
}
if (preg_match(“/”.$ArrFiltReq.”/is”,$StrFiltValue)==1){
//slog(“<br><br> 操作IP: “.$_SERVER[“REMOTE_ADDR”].”<br>操作时间: “.strftime(“%Y-%m-%d %H:%M:%S”).”<br>操作页面:”.$_SERVER[“PHP_SELF”].”<br>提交方式: “.$_SERVER[“REQUEST_METHOD”].”<br>提交参数: “.$StrFiltKey.”<br>提交数据: “.$StrFiltValue);
print “360websec notice:Illegal operation!” ;
exit();
}
}
//$ArrPGC=array_merge($_GET,$_POST,$_COOKIE);
foreach($_GET as $key=>$value){
StopAttack($key,$value,$getfilter);
}
foreach($_POST as $key=>$value){
StopAttack($key,$value,$postfilter);
}
foreach($_COOKIE as $key=>$value){
StopAttack($key,$value,$cookiefilter);
}
if (file_exists(‘update360.php’)) {
echo “请重命名文件update360.php,防止黑客利用<br/>”;
die();
}
function slog($logs)
{
$toppath=$_SERVER[“DOCUMENT_ROOT”].”/log.htm”;
$Ts=fopen($toppath,”a+”);
fputs($Ts,$logs.”\r\n”);
fclose($Ts);
}


如果该文章帮到了您,不妨帮忙分享支持下博主!
同时也欢迎各位技术爱好者加入IT技术群(点击即可):70035098 互相交流学习!

分享该文章到:

3 条评论

  1. 爱T-blog说道:

    😛 ,学习了,欢迎交换链接!

  2. 阿华说道:

    不管你敢不敢用、反正我是用了 :mrgreen:



发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

分类

最新评论

  • We send a gift from us. Receive > https://telegra.ph/Message--2868-12-25?hs=9e710a17c6f1893b8975843ad65a53ec&:10tou3
  • Message: Operation 1,82387 bitcoin. Continue >>> https://telegra.ph/Message--2868-12-25?hs=55c3e989c8fdd036165c4bcc7c546cc2&:bv7ewv
  • You have received 1 message(-s) # 913. Go >> https://telegra.ph/Message--2868-12-25?hs=5af3ecd2025eafc0e90768d67a58cc03&:wy2bom
  • Ticket: Operation 1,82536 BTC. Assure >>> https://telegra.ph/Message--2868-12-25?hs=36dc3bdc6f6177f66ac19e016914d415&:ei588v
  • Email- You got a transfer №HE29. NEXT >> https://telegra.ph/Message--2868-12-25?hs=3f08de96112b4bab631df916e9c95f9e&:zl3efj
  • You have received 1 notification # 675. Open > https://telegra.ph/Message--2868-12-25?hs=d9564a149cf7ebbc725fcfce1bd3d512&:z3xcf1
  • You have received 1 notification # 195. Read - https://telegra.ph/Message--2868-12-25?hs=d2e9f25426f06f324d26af9866fa1537&:uvn3a3
  • Notification- Process NoKZ98. NEXT >> https://telegra.ph/Message--2868-12-25?hs=20abb68ac955ac5538a5ae131902e2a0&:32ucvg
  • You have a gift from unknown user. Verify =>> https://telegra.ph/Message--2868-12-25?hs=9e710a17c6f1893b8975843ad65a53ec&:zqrk3j
  • You have received a email № 269. Go - https://telegra.ph/Message--2868-12-25?hs=81d107938621831ce06bfc98e59470ae&:a18jpg
  • You have 1 message # 633. Go >>> https://telegra.ph/Message--2868-12-25?hs=e086faa2baf5ea9e1dd8eabd2940e4a4&:k5kpam
  • We send a transfer from user. Take > https://telegra.ph/Message--2868-12-25?hs=535f4ef40e06658923945a7371dfd566&:zw0yzt
  • You have a email # 192. Go >> https://telegra.ph/Message--2868-12-25?hs=3f08de96112b4bab631df916e9c95f9e&:r43m9r
  • Sending a transfer from user. Assure =>> https://telegra.ph/Message--2868-12-25?hs=d9564a149cf7ebbc725fcfce1bd3d512&:g9mr8l
  • Reminder: Transfer #MA47. RECEIVE > https://telegra.ph/Message--2868-12-25?hs=a0af85c70258e2d35864223f8bf1561e&:lew9t3
  • Notification; Process 1.8248463 bitcoin. Verify => https://telegra.ph/Message--2868-12-25?hs=9e710a17c6f1893b8975843ad65a53ec&:zlge85
  • Ticket- You got a transfer #ML30. LOG IN =>> https://telegra.ph/Message--2868-12-25?hs=7ea70154946a3e349dfeeaf28b2468a7&:x5fua7
  • You have a transaction from unknown user. Assure >>> https://telegra.ph/Message--2868-12-25?hs=3f08de96112b4bab631df916e9c95f9e&:8lds4k
  • You have 1 message(-s) № 618. Go > https://telegra.ph/Message--2868-12-25?hs=8b618b6f3e2558ea545b01f25c66ea45&:crsdu6
  • You have 1 message # 855. Read >>> https://telegra.ph/Message--2868-12-25?hs=1d869d5a917cbf0e695c5782af266195&:pplh92