php代码审计中的重要函数,总结自《代码审计:企业级web代码安全架构》
- magic_quotes_gpc
- addslashes
- mysql_real_escape_string
- intval
- pirnt_r
- echo
- printf
- sprintf
- die
- var_dump
- var_export
- include
- include_once
- require
- require_once
- file_get_contents
- highlight_file
- fopen
- readfile
- fread
- fget
- fgets
- parse_ini_file
- show_source
- file
- move_upload_file
- eval
- assert
- preg_replace
- call_user_func
- call_user_func_array
- array_map
- system
- exec
- shell_exec
- passthru
- pcntl_exec
- popen
- proc_open
- ectract
- parse_str
- import_request_variables
- $$
- floor
- updatexml
- extractvalue
- GeometryCollection
- polygon
- multipoint
- multilinestring
- multipolygon
- linestring
- exp
- addslashes
- mysql_real_escape_string
- mysql_escape_string
- str_replace
- strops
- htmlspecialchars
- strip_args
- escapeshellcmd
- escapeshellarg