1.测试test.php info.php php_info.php phpinfo.php, d! `0 @$ c0 v) v( W
# L: D, `' E, Q+ t
2.扫描看有没有fck编辑器,如果有就用fckeditor\editor\dialog\fck_spellerpages\spellerpages\server-scripts\spellchecker.php爆, d# E+ |0 j# y. E+ Y( u
* `" S. q* T' S7 @7 L: v- b
3.看看有没有phpmyadmin或者phpMyAdmin利用phpMyAdmin/libraries/select_lang.lib.php$ b4 _+ k3 m1 u4 O* P/ E% ?
phpMyAdmin/darkblue_orange/layout.inc.php
( \ {$ ^; b" F0 `! W7 iphpMyAdmin/index.php?lang[]=1$ B* v6 A# N; u! s3 u* ^
phpmyadmin/themes/darkblue_orange/layout.inc.php/ F% i, s& \2 Z- O/ K
4.利用搜索引擎爆绝对路径$ g \2 S |7 O+ R0 |
site:www.huangse.com Warning6 Y2 l& q3 I# v: q# u/ {- k! W
site:www.huangse.com inurl:Warning' O% F$ I5 {( F7 G6 ^, B* `
/ [+ n$ X4 A$ L2 n! v1 P+ ^+ W3 Z等以后慢慢往上补吧,利用单引号的方法俺就不说了。。。
d3 V( \& m8 Z9 U4 g2 r/ { |