![]() |
|
Ê×Ò³ ©¦ Apache ©¦ Linux©¦ Java©¦ MySQL©¦ ×¢²á©¦°ïÖú | |||
ÈçҪͶËß»òÌá³öÒâ¼û½¨Ò飬Çëµ½
Õ¾Îñ½¨ÒéͶËß°É·´À¡¡£
¶ÔÓÚÎÞÀ©Õ¹ÃûµÄPHP³ÌÐòµÄÑо¿
×÷ÕߣºHackfan
»·¾³£ºWinXp Pro + Apache 2.0.49 + PHP 4.3.5 (Module)
¡¡¡¡½«Ã»ÓÐÀ©Õ¹ÃûµÄPHP´úÂ룬¸øPHP½âÊÍÆ÷½âÊÍ£¬ºÃ´¦ÔÚÓÚ´ó´óÔö¼ÓÁ˰²È«ÐÔ£¬¸øÈëÇÖµÄÈË¡¢µÁÁ´µÄÈË£¬Ôö¼ÓÁËÃÔ»óÐÔ¡£ÀýÈ磺
http://www.msger.net/chat?username=Hackfan
http://www.msger.net/images/test.gif
¡¡¡¡´ÓÒ»°ãÈÏʶÀ´¿´£¬ÉÏÎĵÄ2¸öURLºÜÓпÉÄÜÊÇÕâÑùµÄ£º
/
|-chat/
|-index.php
|-images/
|-test.gif
¡¡¡¡µ«ÊÇApache + PHP¿ÉÒÔÈÃchat¡¢images±ä³ÉÒ»¸öPHP³ÌÐò£¬¶ø°ÑºóÃæµÄ²¿·Ö×÷Ϊ²ÎÊý¡£ÊÂʵÉÏ£¬Õâ2¸öURLºÜÓпÉÄÜ£º
/
|-chat. (PHP File)
|-images. (PHP File)
|-imagessecret/ (Directory)
¡¡¡¡¶øhttp://www.msger.net/images/test ... ÌÐòµÄ²¿·Ö»·¾³±äÁ¿£º
_SERVER["REQUEST_URI"] = /images/test.gif
_SERVER["SCRIPT_NAME"] = /images
_SERVER["PATH_INFO"] = /test.gif
_SERVER["PHP_SELF"] = /images/test.gif
¡¡¡¡´ó¼Ò×¢Òâµ½ÁË£¬Apache³ýÁ˶Ô_SERVER["SCRIPT_NAME"]ÓÐÕýÈ·µÄÅжÏÒÔÍ⣬ÆäËûµÄÐÅÏ¢¼¸ºõ¶¼ÊDZ»ÎÒÃÇÆÛÆÁË¡£²»ÖªµÀ´ó¼ÒÏëµ½ÀûÓÃÕâ¸öÐÔÖÊÎÒÃÇ¿ÉÒÔ×öʲô£¬·´ÕýÎÒÏëµ½ÁË¿ÉÒÔ·ÀֹͼƬ±»µÁÁ´¡£
¡¡¡¡ÁíÍ⣬ÕÒ±éÁ˺ܶà×ÊÁÏ£¬×îºó»¹ÊÇͨ¹ý×Ô¼º£¬Ê¹µÃApacheÄܹ»¶ÔûÓÐÀ©Õ¹ÃûµÄPHPÎļþ½øÐÐÕýÈ·µÄ½âÊÍ£º
¡¡¡¡ÐÞ¸Ähttpd.conf£¬ÕÒµ½
¡¡¡¡×îºóһЩÒÅÁôÎÊÌ⣺
¡¡¡¡¶ÔÓÚhttp://www.msger.net/images/../t ... ¬ÒòΪIE×Ô¶¯»á´¦Àí¡£
¡¡¡¡»¶ÓÓÐÐËȤµÄÅóÓѺÍÎÒ½»Á÷£¬QQ: 106814

