1.测试test.php info.php php_info.php phpinfo.php
# _/ C8 s$ W, `# M! {( [% `7 z7 x$ J% l! |9 r+ V% W& b h
2.扫描看有没有fck编辑器,如果有就用fckeditor\editor\dialog\fck_spellerpages\spellerpages\server-scripts\spellchecker.php爆
% I& D' Y% q5 y& [, j" Y- b$ x t0 ?4 [+ o9 Q1 _$ z
3.看看有没有phpmyadmin或者phpMyAdmin利用phpMyAdmin/libraries/select_lang.lib.php9 P0 `3 S( }* ?/ b/ l* Z4 C# {3 f
phpMyAdmin/darkblue_orange/layout.inc.php- R: o! [) |: G) t
phpMyAdmin/index.php?lang[]=1
6 [" a: E/ v' `" _phpmyadmin/themes/darkblue_orange/layout.inc.php: h" S; w' k/ a, m) V$ m, Y
4.利用搜索引擎爆绝对路径$ d7 ] ^' l0 i" U8 B+ s
site:www.huangse.com Warning/ \5 k* c. W4 h
site:www.huangse.com inurl:Warning( M- U1 O/ y/ u! D1 t
& G+ W8 t8 K# u! p. }) X* }等以后慢慢往上补吧,利用单引号的方法俺就不说了。。。
. |6 j$ T7 x4 Y" p' a8 ?; W |