[zt]À×°ÁÂÛ̳¹ýÂ˲»ÑÏ©¶´ µÚÒ»´ÎдÕâЩ¶«Î÷£¬»¶Ó´ó¼ÒÅÄש~ ÊÊÓð汾 leoBBS X ÂÛ̳ Ò»°ã¶¼´æÔڵĩ¶´ £¨²âÊÔÁ˼¸¸ö£¬¶¼Óеģ©~ ÊÊÓÃϵͳ win2000+ iis cgi ½âÎö·½Ê½ perl.exe %s %s ,perlis.dll ©¶´ÔÀí£º ÀûÓÃÁ˶ÔÓû§ÊäÈëµÄ¹ýÂ˲»ÑÏ£¬±àд´úÂ룬´Ó¶ø»ñµÃshell¡£ ½áºÏÀûÓÃregister.cgi ºÍpost.cgi ¹ýÂ˲»ÑÏ¡£ 1¡¢¿´ÏÂlb ÂÛ̳µÄregister.cgi×¢²áÖеĹýÂË£¬ for ('inmembername'...) $tp = $query->param($_); $tp = &unHTML("$tp"); ${$_} = $tp; } sub unHTML {} ÀïÃæµÄ¶«Î÷²»ÖØÒª¡£ &error("Óû§×¢²á&¶Ô²»Æð£¬ÄúÊäÈëµÄÓû§ÃûÓÐÎÊÌ⣬Çë²»ÒªÔÚÓû§ÃûÖаüº¬\@\#\$\%\^\*\(\)\+\=\\\{\}\;'\:\"\,\.\/\<\>\?\[\]ÕâÀà×Ö·û£¡") if ($inmembername =~ /[\a\f\n\e\0\r\t\`\~\!\@\#\$\%\^\&\*\(\)\+\=\\\{\}\;'\:\"\,\.\/\<\>\?\[\]]/); if($inmembername =~ /_/) { &error("Óû§×¢²á&Çë²»ÒªÔÚÓû§ÃûÖÐʹÓÃÏ»®Ïߣ¡"); } $inmembername =~ s/\ \;//ig; $inmembername =~ s/¡¡/ /g; $inmembername =~ s/©¡/ /g; $inmembername =~ s/[ ]+/ /g; $inmembername =~ s/[ ]+/_/; $inmembername =~ s/[_]+/_/; $inmembername =~ s/ÿ//isg; $inmembername =~ s///isg; $inmembername =~ s/¡¡//isg; $inmembername =~ s/©¡//isg; $inmembername =~ s/()+//isg; $inmembername =~ s/[\a\f\n\e\0\r\t\`\~\!\@\#\$\%\^\&\*\(\)\+\=\\\{\}\;'\:\"\,\.\/\<\>\?\[\]]//isg; $inmembername =~ s/\s*$//g; $inmembername =~ s/^\s*//g; &error("Óû§×¢²á&¶Ô²»Æð£¬ÄúÊäÈëµÄÓû§ÃûÓÐÎÊÌâ") if ($inmembername =~ /^q(.+?)-/ig); $inmembername =~ /guest/i)||($inmembername =~ /qq-/i)||($inmembername =~ /q-/i)||($inmembername =~ /qx-/i)||($inmembername =~ /qw-/i)||($inmembername =~ /qr-/i)||($inmembername =~ /no)||($inmembername eq "admin")||($inmembername display/i)||($inmembername =~ /^system/i)||($inmembername =~ /---/ieq "root")||($inmembername eq "copy")||($inmembername =~ /^sub/)||($inmembername =~ /^exec/)||($inmembername =~ /\@ARGV/i)||($inmembername =~ /^require/)||($inmembername =~ /^rename/i)||($inmembername =~ /^dir/i)||($inmembername =~ /^print/i)||($inmembername =~ /^con/i)||($inmembername =~ /^nul/i)||($inmembername =~ /^aux/i)||($inmembername =~ /^com/i)||($inmembername =~ /^lpt/i)); µÈµÈ¡£ ¹ýÂ˵Äͦ³¹µ×µÄŶ~ µ«ÊǺöÂÔÁË q¼° qq¡¢qwµÈµÄÔËÓû¹¿ÉÒÔÓÃЩÌØÊâµÄ·ûºÅµÄ£º©£¬ÕâÊÇ×î¹Ø¼üµÄÒ»²½¡?br /> 2¡¢ÔÙ¿´ÏÂpost.cgiÀï¶Ô·¢ÌùµÄ¹ýÂË for ('forum','topic','membername','password','action','postno','inshowsignature', 'notify','inshowemoticons','intopictitle','inshowchgfont', 'inpost','posticon','inhiddentopic','postweiwang','moneyhidden','moneypost','uselbcode','inwater') { next unless defined $_; next if $_ eq 'SEND_MAIL'; $tp = $query->param($_); $tp = &cleaninput("$tp"); ${$_} = $tp; } sub cleaninput { my ($self, $text) = _self_or_default(@_); # my $text = shift; study($text); $text =~ s/[\a\f\e\0\r\t]//isg; $text =~ s/\ / /g; $text =~ s/\@ARGV/\&\#64\;ARGV/isg; $text =~ s/\;/\&\#59\;/isg; $text =~ s/\&/\&/g; $text =~ s/\&\#/\&\#/isg; $text =~ s/\&\;(.{1,6})\&\#59\;/\&$1\;/isg; $text =~ s/\&\#([0-9]{1,6})\&\#59\;/\&\#$1\;/isg; $text =~ s/"/\"/g; $text =~ s/ / \ /g; $text =~ s/\</g; $text =~ s/>/\>/g; $text =~ s/ / /g; $text =~ s/\n\n/ /g; |
Ïà¹ØÊÓƵ
Ïà¹ØÔĶÁ Windows´íÎó´úÂë´óÈ« Windows´íÎó´úÂë²éѯ¼¤»îwindowsÓÐʲôÓÃMac QQºÍWindows QQÁÄÌì¼Ç¼ÔõôºÏ²¢ Mac QQºÍWindows QQÁÄÌì¼Ç¼Windows 10×Ô¶¯¸üÐÂÔõô¹Ø±Õ ÈçºÎ¹Ø±ÕWindows 10×Ô¶¯¸üÐÂwindows 10 rs4¿ìËÙÔ¤ÀÀ°æ17017ÏÂÔØ´íÎóÎÊÌâWin10Çï¼¾´´ÒâÕ߸üÐÂ16291¸üÐÂÁËʲô win10 16291¸üÐÂÄÚÈÝwindows10Çï¼¾´´ÒâÕ߸üÐÂʱ¼ä windows10Çï¼¾´´ÒâÕ߸üÐÂÄÚÈÝkb3150513²¹¶¡¸üÐÂÁËʲô Windows 10²¹¶¡kb3150513ÊÇʲô
ÈÈÃÅÎÄÕ ºÚ¿Í´óÕ½Ö±²¥ÍøÖ· ºÚ¿Í
×îÐÂÎÄÕÂ
MetaÊ×ϯ¿Æѧ¼Ò£º´óÄ£ºÚ¿Í´óÕ½Ö±²¥ÍøÖ· ºÚ¿Í
ÎÞÏßÍøÂçÃÜÂëÆƽâ½Ì³Ì£¨ÆƽâÎÞÏß·ÓÉWEP¼ÓÃܼÆËã»ú²¡¶¾ÊÇָʲôʲôÊÇľÂí,ʲôÊÇľÂí²¡¶¾ºÚ¿ÍÆƽâÃÜÂë³£Óõķ½·¨
ÈËÆøÅÅÐÐ ÈçºÎ¹¥»÷¾ÖÓòÍøµçÄÔÎÞÏßÍøÂçÃÜÂëÆƽâ½Ì³Ì£¨ÆƽâÎÞÏß·ÓÉWEP¼ÓÃÜÍøÕ¾»ñµÃϵͳȨÏÞ¹¥»÷½Ì³ÌÁ÷¹âÆƽâftpÃÜÂë½Ì³Ì¼ÆËã»ú²¡¶¾ÊÇָʲôºÚ¿ÍÆƽâÃÜÂë³£Óõķ½·¨ÈçºÎÃüÁîÐÐ/DOSÏÂÁгö½ø³ÌÃûÓë½ø³ÌÎļþ·¾¶Ê²Ã´ÊÇľÂí,ʲôÊÇľÂí²¡¶¾
²é¿´ËùÓÐ0ÌõÆÀÂÛ>>