php恶意代码,php 恶意代码过滤函数_PHP教程

php 恶意代码过滤函数

Public Function DecodeFilter(html, filter)

html=LCase(html)

filter=split(filter,",")

For Each i In filter

Select Case i

Case "SCRIPT" ' 去除所有客户端脚本javascipt,vbscript,jscript,js,vbs,event,...

html = exeRE("(javascript|jscript|vbscript|vbs):", "#", html)

html = exeRE("?script[^>]*>", "", html)

html = exeRE("on(mouse|exit|error|click|key)", "", html)

Case "TABLE": ' 去除表格html = exeRE("?table[^>]*>", "", html)

html = exeRE("?tr[^>]*>", "", html)

html = exeRE("?th[^>]*>", "", html)

html = exeRE("?td[^>]*>", "", html)

html = exeRE("?tbody[^>]*>", "", html)

Case "CLASS" ' 去除样式类class=""

html = exeRE("(]+) class=[^ |^>]*([^>]*>)", "$1 $2", html)

Case "STYLE" ' 去除样式style=""

html = exeRE("(]+) style=""[^""]*""([^>]*>)", "$1 $2", html)

html = exeRE("(]+) style='[^']*'([^>]*>)", "$1 $2", html)

Case "IMG" ' 去除样式style=""

html = exeRE("?img[^>]*>", "", html)

Case "XML" ' 去除XML

html = exeRE("]*>", "", html)

Case "NAMESPACE" ' 去除命名空间>>

html = exeRE("]*>", "", html)

Case "FONT" ' 去除字体

html = exeRE("?font[^>]*>", "", html)

html = exeRE("?a[^>]*>", "", html)

html = exeRE("?span[^>]*>", "", html)

html = exeRE("?br[^>]*>", "", html)

Case "MARQUEE" ' 去除字幕

html = exeRE("?marquee[^>]*>", "", html)

Case "OBJECT" ' 去除对象

html = exeRE("?object[^>]*>", "", html)

html = exeRE("?param[^>]*>", "", html)

'html = exeRE("?embed[^>]*>", "", html)

Case "EMBED"

html = exeRE("?embed[^>]*>", "", html)

Case "DIV" ' 去除对象

html = exeRE("?div([^>])*>", "$1", html)

html = exeRE("?p([^>])*>", "$1", html)

Case "ONLOAD" ' 去除样式style=""

html = exeRE("(]+) οnlοad=""[^""]*""([^>]*>)", "$1 $2", html)

html = exeRE("(]+) οnlοad='[^']*'([^>]*>)", "$1 $2", html)

Case "ONCLICK" ' 去除样式style=""

html = exeRE("(]+) οnclick=""[^""]*""([^>]*>)", "$1 $2", html)

html = exeRE("(]+) οnclick='[^']*'([^>]*>)", "$1 $2", html)

Case "ONDBCLICK" ' 去除样式style=""

html = exeRE("(]+) ondbclick=""[^""]*""([^>]*>)", "$1 $2", html)

html = exeRE("(]+) ondbclick='[^']*'([^>]*>)", "$1 $2", html)

End Select

Next

'html = Replace(html,"

'html = Replace(html,"

'html = Replace(html,"

DecodeFilter = html

End Function

http://www.bkjia.com/PHPjc/629754.htmlwww.bkjia.comtruehttp://www.bkjia.com/PHPjc/629754.htmlTechArticlephp 恶意代码过滤函数 Public Function DecodeFilter(html, filter) html=LCase(html) filter=split(filter,,) For Each i In filter Select Case i Case SCRIPT ' 去除所有客户端...

相关文章

相关视频

网友评论

文明上网理性发言,请遵守 新闻评论服务协议我要评论

47d507a036d4dd65488c445c0974b649.png

立即提交

专题推荐064df72cb40df78e80e61b7041ee044f.png独孤九贱-php全栈开发教程

全栈 100W+

主讲:Peter-Zhu 轻松幽默、简短易学,非常适合PHP学习入门

7dafe36c040e31d783922649aefe0be1.png玉女心经-web前端开发教程

入门 50W+

主讲:灭绝师太 由浅入深、明快简洁,非常适合前端学习入门

04246fdfe8958426b043c89ded0857f1.png天龙八部-实战开发教程

实战 80W+

主讲:西门大官人 思路清晰、严谨规范,适合有一定web编程基础学习

php中文网:公益在线php培训,帮助PHP学习者快速成长!

Copyright 2014-2020 https://www.php.cn/ All Rights Reserved | 苏ICP备2020058653号-1e6cebb680dfe320dad7e62bd6442c3a6.gif

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值