关于屏蔽ecshop的SQL报错提示

2016-09-11 20:39 来源:www.chinab4c.com 作者:ecshop专家

把ecshop的SQL报错提示全部屏蔽了,这有个好处,可以防止注入!让SQL报错不显示,是优化ECSHOP不得不做的方法!

找到ECSHOP程序

 

找到 \\includes\\cls_mysql.php

 

function ErrorMsg($message = '', $sql = '') 

if ($message) 

echo "<b>ECSHOP info</b>: $message\\n\\n<br /><br />"; 

//print('<a href="http://faq.comsenz.com/?type=mysql&dberrno=2003&dberror=Can%27t%20connect%20to%20MySQL%20server%20on" target="_blank">http://faq.comsenz.com/</a>'); 

else 

echo "<b>MySQL server error report:"; 

print_r($this->error_message); 

//echo "<br /><br /><a href='http://faq.comsenz.com/?type=mysql&dberrno=" . $this->error_message[3]['errno'] . "&dberror=" . urlencode($this->error_message[2]['error']) . "'

target='_blank'>http://faq.comsenz.com/</a>"; 

}

 


修改为

 

function ErrorMsg($message = '', $sql = '') 


if ($message) 


//echo "<b>ECSHOP info</b>: $message\\n\\n<br /><br />"; 

//print('<a href="http://faq.comsenz.com/?type=mysql&dberrno=2003&dberror=Can%27t%20connect%20to%20MySQL%20server%20on" target="_blank">http://faq.comsenz.com/</a>'); 


else 


//echo "<b>MySQL server error report:"; 

//print_r($this->error_message); 

//echo "<br /><br /><a href='http://faq.comsenz.com/?type=mysql&dberrno=" . $this->error_message[3]['errno'] . "&dberror=" . urlencode($this->error_message[2]['error']) . "'

target='_blank'>http://faq.comsenz.com/</a>"; 


 

exit; 

} exit; 

}

 

即把所有的错误输出屏蔽 这样很方便的就解决了注入问题。增加网店的安全系数!