一个不错的php通用防注入程序
时间:2021-07-01 10:21:17
帮助过:26人阅读
function jk1986_checksql() - {
- $bad_str = "and|select|update|'|delete|insert|*";
- $bad_Array = explode("|",$bad_str);
- /** 过滤Get参数 **/
- foreach ($bad_Array as $bad_a)
- {
- foreach ($_GET as $g)
- {
- if (substr_count(strtolower($g),$bad_a) > 0)
- {
- echo "";
- exit();
- }
- }
- }
/** 过滤Post参数 **/ foreach ($bad_Array as $bad_a) - {
- foreach ($_POST as $p)
- {
- if (substr_count(strtolower($p),$bad_a) > 0)
- {
- echo "";
- exit();
- }
- }
- }
/** 过滤Cookies参数 **/ foreach ($bad_Array as $bad_a) - {
- foreach ($_COOKIE as $co)
- {
- if (substr_count(strtolower($co),$bad_a) > 0)
- {
- echo "";
- exit();
- }
- }
- }
- }
- ?>
|