<?php
include_once $_SERVER['DOCUMENT_ROOT'] . '/include/shared-manual.inc';
$TOC = array();
$TOC_DEPRECATED = array();
$PARENTS = array();
include_once dirname(__FILE__) ."/toc/refs.basic.other.inc";
$setup = array (
  'home' => 
  array (
    0 => 'index.php',
    1 => 'PHP Manual',
  ),
  'head' => 
  array (
    0 => 'UTF-8',
    1 => 'zh',
  ),
  'this' => 
  array (
    0 => 'book.taint.php',
    1 => 'Taint',
    2 => 'Taint',
  ),
  'up' => 
  array (
    0 => 'refs.basic.other.php',
    1 => '其它基本扩展',
  ),
  'prev' => 
  array (
    0 => 'yaconf.has.php',
    1 => 'Yaconf::has',
  ),
  'next' => 
  array (
    0 => 'taint.setup.php',
    1 => '安装/配置',
  ),
  'alternatives' => 
  array (
  ),
  'source' => 
  array (
    'lang' => 'zh',
    'path' => 'reference/taint/book.xml',
  ),
  'history' => 
  array (
  ),
  'extra_header_links' => 
  array (
    'rel' => 'alternate',
    'href' => '/manual/en/feeds/book.taint.atom',
    'type' => 'application/atom+xml',
  ),
);
$setup["toc"] = $TOC;
$setup["toc_deprecated"] = $TOC_DEPRECATED;
$setup["parents"] = $PARENTS;
manual_setup($setup);

contributors($setup);

?>
<div id="book.taint" class="book">
 
 <h1 class="title">Taint</h1>
 

 <div id="intro.taint" class="preface">
  <h1 class="title">简介</h1>
  <p class="simpara">
   Taint 是一个污点追踪扩展，用于检测 XSS 代码（即被污染的字符串），
   也可以用来发现 SQL 注入、命令注入、文件路径注入等类似漏洞。
  </p>
  <p class="simpara">
   开启 taint 后，来自用户输入 ——
   <var class="varname"><a href="reserved.variables.get.php" class="classname">$_GET</a></var>、<var class="varname"><a href="reserved.variables.post.php" class="classname">$_POST</a></var>
   和 <var class="varname"><a href="reserved.variables.cookies.php" class="classname">$_COOKIE</a></var> —— 的字符串会在请求开始时被标记为
   已污染，并且该标记会随字符串操作一路传递。当一个被污染的字符串
   到达危险的汇点（sink，如输出、SQL 查询、shell 命令、文件路径等）时，
   taint 会在该处发出警告。完整的清单见
   <a href="taint.detail.php" class="link">传播规则与被检查的汇点</a>。
  </p>
  <p class="simpara">
   Taint 是开发和审计工具，而不是运行时的防御手段：它只报告可能
   存在的问题，既不会拦截也不会修改数据。它有意采用保守策略，宁可
   多报，因此一次&quot;干净&quot;的运行只意味着&quot;taint 没有发现任何污点&quot;，
   绝不等于&quot;已证明安全&quot;。不要在生产环境中开启它。
  </p>
  <div class="example" id="example-1">
   <p><strong>示例 #1 Taint 示例</strong></p>
   <div class="example-contents">
<div class="phpcode"><pre><code style="color: #000000"><span style="color: #0000BB">&lt;?php
$a </span><span style="color: #007700">= </span><span style="color: #0000BB">trim</span><span style="color: #007700">(</span><span style="color: #0000BB">$_GET</span><span style="color: #007700">[</span><span style="color: #DD0000">'a'</span><span style="color: #007700">]);

</span><span style="color: #0000BB">$file_name </span><span style="color: #007700">= </span><span style="color: #DD0000">'/tmp/' </span><span style="color: #007700">. </span><span style="color: #0000BB">$a</span><span style="color: #007700">;
</span><span style="color: #0000BB">$output    </span><span style="color: #007700">= </span><span style="color: #DD0000">"Welcome, </span><span style="color: #007700">{</span><span style="color: #0000BB">$a</span><span style="color: #007700">}</span><span style="color: #DD0000"> !!!"</span><span style="color: #007700">;
</span><span style="color: #0000BB">$sql       </span><span style="color: #007700">= </span><span style="color: #DD0000">"SELECT * FROM users WHERE name = " </span><span style="color: #007700">. </span><span style="color: #0000BB">$a</span><span style="color: #007700">;

echo </span><span style="color: #0000BB">$output</span><span style="color: #007700">;
print </span><span style="color: #0000BB">$output</span><span style="color: #007700">;
include </span><span style="color: #0000BB">$file_name</span><span style="color: #007700">;
</span><span style="color: #0000BB">mysqli_query</span><span style="color: #007700">(</span><span style="color: #0000BB">$link</span><span style="color: #007700">, </span><span style="color: #0000BB">$sql</span><span style="color: #007700">);
</span><span style="color: #0000BB">?&gt;</span></code></pre></div>
   </div>

   <div class="example-contents"><p>以上示例的输出类似于：</p></div>
   <div class="example-contents screen">
<div class="cdata"><pre>
Warning: main() [echo]: Attempt to echo a string that might be tainted in /path/to/script.php on line 9

Warning: main() [print]: Attempt to print a string that might be tainted in /path/to/script.php on line 10

Warning: main() [include]: File path contains data that might be tainted in /path/to/script.php on line 11

Warning: main() [mysqli_query]: SQL statement contains data that might be tainted in /path/to/script.php on line 12
</pre></div>
   </div>
  </div>
 </div>

 







 







 








<ul class="chunklist chunklist_book"><li><a href="taint.setup.php">安装/配置</a><ul class="chunklist chunklist_book chunklist_children"><li><a href="taint.requirements.php">需求</a></li><li><a href="taint.installation.php">安装</a></li><li><a href="taint.configuration.php">运行时配置</a></li><li><a href="taint.resources.php">资源类型</a></li></ul></li><li><a href="taint.detail.php">传播规则与被检查的汇点</a><ul class="chunklist chunklist_book chunklist_children"><li><a href="taint.detail.basic.php">污点标记如何传播</a></li><li><a href="taint.detail.sinks.php">taint 在哪里发出警告</a></li></ul></li><li><a href="ref.taint.php">Taint 函数</a><ul class="chunklist chunklist_book chunklist_children"><li><a href="function.is-tainted.php">is_tainted</a> — 检查一个字符串是否被污染</li><li><a href="function.taint.php">taint</a> — 将字符串标记为已污染</li><li><a href="function.untaint.php">untaint</a> — 清除字符串上的污点标记</li></ul></li></ul></div><?php manual_footer($setup); ?>