1.取反导致的逻辑问题
0的取反是1,false的取反也是1
例如strpos
data:image/s3,"s3://crabby-images/7f668/7f6681c416f043a3e98fea57fc362f49eca97e56" alt=""
2.in_array
data:image/s3,"s3://crabby-images/d863d/d863d0c2f8b7f46afed20a6301c45323ef3ce738" alt=""
3.filter_var
不会检测协议
data:image/s3,"s3://crabby-images/e5d70/e5d70688565c9c9e9c9e16ffee871b2d3bbfe515" alt=""
如果直接将输出filter_var($_GET['url'], FILTER_VALIDATE_URL))
url=javascript://comment%250aalert(1)
用来XSS
4.parse_str 变量覆盖
data:image/s3,"s3://crabby-images/771e2/771e2678c91b822f832bcaf73b45303beec0beb8" alt=""
5.extract() 变量覆盖
data:image/s3,"s3://crabby-images/ae436/ae436ee603deb1e1115a8bc15980f464c2e45c90" alt=""
5.preg_replace() /e (5.5.0以上/e 修饰符已经被弃用了)
data:image/s3,"s3://crabby-images/2abe4/2abe40ba75bbfabb6d0dbca1876fda13476bd816" alt=""
6.is_numberic() 0x...
hex编码替代字符串明文,虽然不能直接注入,但是可能引起二次注入或者xss等漏洞.
7.双等和三等于
双等于在做比较之前会强制转换数据类型,三等于不会
网友评论