<table cellspacing="0" cellpadding="0"><tr><td class="t_f" id="postmessage_43472"> <div class="blockcode"> <div id="code_TAp"><ol> <li> <li> <?php <li>//防注入函数</li> <li>function inject_check($sql_str){</li> <li> $check = eregi('select|insert|update|delete|\*|\/\*|\'|\.\.\/|\.\/|UNION|into|load_file|outfile',$sql_str);</li> <li> if($check){ </li> <li> page_href("http://".$_SERVER['HTTP_HOST']."/home/sitemap.php");</li> <li> exit(); </li> <li> }else{</li> <li> return $sql_str;</li> <li> }</li> <li>}</li> <li>//防跨站攻击</li> <li>function inject_check2($sql_str){</li> <li> $check = </li> <li> eregi('javascript|vbscript|expression|applet|meta|xml|blink|link|style|script|embed|object|iframe|frame|</li> <li>frameset|ilayer|layer</li> <li>|bgsound|title|base|onabort|onact</li> <li> ivate|onafterprint|onafterupdate|onbeforeactivate|onbeforecopy|onbeforecut|onbeforedeactivate|onbeforeeditfocus</li> <li>|onbeforepaste|onbeforeprint|onbeforeunload|onb</li> <li> eforeupdate|onblur|onbounce|oncellchange|onchange|onclick|oncontextmenu|oncontrolselect|oncopy|oncut|</li> <li>ondataavailable</li> <li>|ondatasetchanged|ondatasetcomplete|ondblc</li> <li> lick|ondeactivate|ondrag|ondragend|ondragenter|ondragleave|ondragover|ondragstart|</li> <li>ondrop|onerror|onerrorupdate</li> <li>|onfilterchange|onfinish|onfocus|onfocusin|onfoc</li> <li> usout|onhelp|onkeydown|onkeypress|onkeyup|onlayoutcomplete|onload|onlosecapture</li> <li>|onmousedown|onmouseenter|</li> <li>onmouseleave|onmousemove|onmouseout|onmouseover|onmou</li> <li> seup|onmousewheel|onmove|onmoveend|onmovestart|onpaste|onpropertychange|onreadystatechange|onreset|</li> <li>onresize|onresizeend|onresizestart|onrowenter|onrowexit|onr</li> <li> owsdelete|onrowsinserted|onscroll|onselect|onselectionchange|onselectstart|onstart|onstop|</li> <li>onsubmit|onunload',$sql_str);</li> <li> if($check){ </li> <li> page_href("http://".$_SERVER['HTTP_HOST']."/home/sitemap.php");</li> <li> exit(); </li> <li> }else{</li> <li> //return $sql_str;</li> <li> }</li> <li>} //by bbs.it-home.org</li> <li>?></li> </ol></div> <em onclick="copycode($('code_TAp'));">复制代码</em> </div> </td></tr></table> <div id="comment_43472" class="cm"> </div> <div id="post_rate_div_43472"></div> <br><br>