±ÜÃâXSS¹¥»÷
XSS£¨¿çÕ¾¾ç±¾£©¹¥»÷Ò²Êdz£¼ûµÄÍøÕ¾Çå¾²ÎÊÌâ¡£¿ÉÒÔͨ¹ýÒÔÏÂÒªÁì±ÜÃâXSS¹¥»÷£º
Êä³ö±àÂ룺¶ÔÓû§ÊäÈëµÄÊý¾Ý¾ÙÐбàÂ룬ÒÔ±ÜÃâ¶ñÒâ¾ç±¾±»Ö´ÐС£ÀýÈ磬ÔÚHTMLÊä³öʱʹÓÃhtmlspecialcharsº¯Êý£ºechohtmlspecialchars($user_input,ENT_QUOTES,'UTF-8');ContentSecurityPolicy£¨CSP£©£ºÊ¹ÓÃCSPÍ·²¿À´ÏÞÖÆ¶ñÒâ¾ç±¾µÄ¼ÓÔØ£¬¿ÉÒÔÔÚ·þÎñÆ÷ÉèÖÃÖÐÉèÖãºadd_headerContent-Security-Policy"script-src'self'";
×°ÖÃÀú³ÌÖеij£¼ûÎÊÌâ
Êý¾Ý¿âÅþÁ¬Ê§°Ü£ºÈôÊÇÔÚ°²?×°Àú³ÌÖÐÓöµ½Êý¾Ý¿âÅþÁ¬Ê§°ÜµÄÎÊÌ⣬Çë¼ì²éconfig.phpÎļþÖеÄÊý¾Ý¿âÉèÖÃÊÇ·ñ׼ȷ£¬°üÀ¨Êý¾Ý¿âÃû³Æ¡¢Óû§ÃûºÍÃÜÂ롣ȷ±£Êý¾Ý¿â·þÎñÆ÷ÕýÔÚÔËÐУ¬²¢ÇÒûÓÐÍøÂçÎÊÌâ¡£
ÎļþȨÏÞ¹ýʧ£º×°ÖÃÀú³ÌÖпÉÄÜ»áÓöµ½ÎļþȨÏÞ¹ýʧ¡£È·±£ÉÏ´«µÄÎļþºÍĿ¼ȨÏÞÉèÖÃ׼ȷ£¬ÌØÊâÊÇuploadsĿ¼£¬Ó¦¸ÃÉèÖÃΪ777»ò755¡£
²å?¼þ³åÍ»£ºÓÐʱ¼ä×°ÖõIJå¼þ¿ÉÄÜ»áÓë½¹µãϵͳ»òÆäËû²å¼þ±¬·¢³åÍ»¡£ÔÚÓöµ½ÎÊÌâʱ£¬ÊµÑé½ûÓÃÆäËû²å¼þ£¬Öð¸öÅŲ飬ÕÒ³ö³åÍ»µÄÔµ¹ÊÔÓÉ¡£
ÓïÑÔ°ü¼ÓÔØ¹ýʧ£ºÈôÊÇÍøÕ¾ÏÔʾÓïÑÔ¹ýʧ»ò²¿·ÖÓïÑÔ°üδ¼ÓÔØ£¬Çë¼ì²éÓïÑÔÎļþÊÇ·ñÉÏ´«×¼È·£¬²¢È·±£Â·¾¶ÉèÖÃÎÞÎó¡£
ÏÂÔØ²¢ÉèÖÃÍøÕ¾Ô´Âë
ÏÂÔØÔ´Â룺´Ó¹Ù·½»ò¿ÉÐŵÄȪԴÏÂÔØÍøÕ¾µÄÔ´Âë¡£Ò»Ñùƽ³£¿ÉÒÔÔÚGitHub»òÕß¹Ù·½ÍøÕ¾ÕÒµ½×îеÄÔ´Âë¡£
ÉÏ´«Ô´Â룺ʹÓÃSCP¡¢FTPµÈ¹¤¾ß½«Ô´ÂëÉÏ´«µ½·þÎñÆ÷µÄÖ¸¶¨Ä¿Â¼£¬Ò»Ñùƽ³£½¨Ò齫ÆäÉÏ´«µ½/var/www/html¡£
½âѹ²¢ÖØÃüÃû£ºÈôÊÇÔ´ÂëÊÇѹËõ°üÃûÌã¬ÏȽâѹ²¢½«ÆäÖеÄÎļþ¼ÐÖØÃüÃûΪlightbody£¨»òÕ߯äËûÄúϲ»¶µÄÃû³Æ£©¡£
ÉèÖÃÊý¾Ý¿â£ºÆ¾Ö¤ÍøÕ¾µÄ×°ÖÃÌáÐÑ£¬µ¼ÈëÊý¾Ý¿â²¢ÉèÖÃÏà¹ØµÄÊý¾Ý¿â²ÎÊý£¬ÈçÊý¾Ý¿âÃû¡¢Óû§ÃûºÍÃÜÂëµÈ¡£
³õ?ʼÉèÖúÍÓÅ»¯
ºǫ́ÖÎÀí£ºµÇ¼ºǫ́ÖÎÀíϵͳ£¬Ê×Ïȼì²é²¢¸üÐÂËùÓвå¼þºÍ½¹µãϵͳ¡£È·±£ËùÓÐÈí¼þ¶¼ÊÇ×îа汾£¬ÒÔ×èÖ¹Çå¾²Îó²îºÍ¼æÈÝÐÔÎÊÌâ¡£
Óû§ÉèÖãºÉèÖÃÓû§×¢²á?ºÍµÇ¼µÄÏà¹Ø²ÎÊý£¬È·±£ÇкÏÍøÕ¾µÄÔËÓªÐèÇ󡣿ÉÒÔÆôÓÃË«ÖØÈÏÖ¤£¨2FA£©À´ÔöÌíÇå¾²ÐÔ¡£
ÄÚÈÝÖÎÀí£º×îÏÈÉÏ´«ºÍÖÎÀíÄúµÄ¹âÉíÓñÈËÊÓÆµÄÚÈÝ¡£È·±£ËùÓÐÊÓÆµÎļþÃûÌüæÈÝ£¬²¢ÉèÖÃÊʵ±µÄ°æÈ¨ºÍ±êÇ©¡£
SEOÓÅ»¯£ºÎªÁËÌá¸ßÍøÕ¾µÄËÑË÷ÒýÇæÅÅÃû£¬¾ÙÐлù±¾?µÄSEOÓÅ»¯¡£°üÀ¨ÉèÖÃÍøÕ¾ÎÊÌâ¡¢ÐÎò¡¢Òªº¦´ÊµÈ¡£
Çå¾²¼ì²é?£º°´ÆÚ¼ì²éÍøÕ¾µÄÇ徲״̬£¬È·±£Ã»ÓжñÒâ´ú?ÂëºÍľÂí¡£¿ÉÒÔʹÓÃÇå¾²²å¼þ¾ÙÐÐɨÃèºÍÐÞ¸´¡£
³£¼ûÎÊÌâÈý£ºÉÏ´«Îļþʧ°Ü
ÈôÊÇÔÚÍøÕ¾ÖÐÓöµ½ÉÏ´«Îļþʧ°ÜµÄÎÊÌ⣬¿ÉÒÔʵÑéÒÔϰ취£º
¼ì²éPHPÉèÖãºÉó²é/etc/php/7.x/fpm/php.iniÎļþ£¬È·±£upload_max_filesizeºÍpost_max_sizeÉèÖÃ׼ȷ¡£
ÐÞ¸ÄNginxÉèÖãºÔÚNginxÉèÖÃÎļþÖÐÔöÌíÒÔÏÂÉèÖãº
client_max_body_size100M;ÖØÆôNginx£ºÖØÆôNginxÒÔÓ¦ÓÃеÄÉèÖãºsudosystemctlrestartnginx
×¼±¸ÊÂÇé
ÔÚ×îÏÈ×°ÖùâÉíÓñÈËÊÓÆµÍøÕ¾Ö®Ç°£¬ÐèҪ׼±¸ÒÔϹ¤¾ßºÍ×ÊÔ´£º
ÓòÃûºÍÍйܷþÎñ£ºÄúÐèÒªÒ»¸ö¿É¿¿µÄÓòÃûºÍÍйܷþÎñ¡£ÍƼöÑ¡ÔñÄÇЩÌṩ24/7ÊÖÒÕÖ§³ÖµÄ·þÎñÉÌ£¬ÕâÑù¿ÉÒÔ¸üºÃµØ½â¾öºóÐø¿ÉÄÜ·ºÆðµÄÎÊÌâ¡£
·þÎñÆ÷ÇéÐΣºÈ·±£·þÎñÆ÷Öª×ãÍøÕ¾ÔËÐÐËùÐèµÄÇéÐΣ¬°üÀ¨PHP°æ±¾¡¢MySQLÊý¾Ý¿âµÈ?¡£´ó´ó¶¼ÊÓÆµÍøÕ¾ÐèÒªPHP7.2¼°ÒÔÉϰ汾ºÍMySQL5.6¼°ÒÔÉϰ汾?¡£
Çå¾²Ö¤Ê飺ΪÁ˱£»¤Óû§µÄ?Òþ˽ºÍÊý¾ÝÇå¾²£¬½¨Ò鹺ÖÃSSLÖ¤Ê飬ÕâÑù¿ÉÒÔÈ·±£ÍøÕ¾µÄHTTPS»á¼û¡£
×°Öðü£ºÏÂÔØ×îа汾µÄ¹âÉíÓñÈËÊÓÆµÍøÕ¾×°Öðü£¬È·±£°ü?º¬ËùÓÐÐëÒªµÄÎļþºÍÒÀÀµ¡£
У¶Ô£º·½±£ƒS(1C0m4pJyqZtPma0S7t9ZFfz4hTykKag)


