- function inject_check($sql_str) { //防止注入
- $check = eregi('select|insert|update|delete|'|/*|*|../|./|union|into|load_file|outfile', $sql_str);
- if ($check) {
- echo "输入非法注入内容!";
- exit ();
- } else {
- return $sql_str;
- }
- }
- function checkurl() { //检查来路
- if (preg_replace("/https?://([^:/]+).*/i", "1", $_server['http_referer']) !== preg_replace("/([^:]+).*/", "1", $_server['http_host'])) {
- header("location: http://www.Vevb.com");
- exit();
- }
- }
- //调用
- checkurl();
- $str = $_get['url'];
- inject_check($sql_str);//这条可以在获取参数时执行操作
新闻热点
疑难解答