We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
答: HTML 怎么也得过滤,PHP中叫消毒 -- 吴子棋
答: 过滤输入的比过滤输出的容易处理些把。主要是防xss洞 -- skccc
答: 过虑输入要比在输出时处理的点要少,但逻辑要复杂很多,存在不少逃过检测的方法 -- 水浸街
答: 人工review的成本挺高的,一般只是抽查 -- 水浸街
The text was updated successfully, but these errors were encountered:
No branches or pull requests
变量注入:不要从来自外部的数据导入变量
xss注入:输入时过滤验证,输出时转义
系统命令注入:禁用相应的提供系统操作的函数 -- 杨锡坤
答: HTML 怎么也得过滤,PHP中叫消毒 -- 吴子棋
答: 过滤输入的比过滤输出的容易处理些把。主要是防xss洞 -- skccc
答: 过虑输入要比在输出时处理的点要少,但逻辑要复杂很多,存在不少逃过检测的方法 -- 水浸街
答: 人工review的成本挺高的,一般只是抽查 -- 水浸街
答:没啥业务或者业务简单几百年不变的写几个nginx lua脚本处理确实靠谱,性能又好 — 合一
答:php代码规范可以直接用PSR规范 — skc
答:SVN的钩子有设定,不满足格式的代码,无法提交 -- 夜丶有雪
答:git下的hook也可以 — Hank
The text was updated successfully, but these errors were encountered: