1.测试test.php info.php php_info.php phpinfo.php
* m* M5 `. c; u/ G2 Y9 \: Y0 C/ j5 x7 p# @% `
2.扫描看有没有fck编辑器,如果有就用fckeditor\editor\dialog\fck_spellerpages\spellerpages\server-scripts\spellchecker.php爆( G3 u8 X" J: t2 `" _
" j H1 ]6 o: I; y4 y* A- Q
3.看看有没有phpmyadmin或者phpMyAdmin利用phpMyAdmin/libraries/select_lang.lib.php* p: ^* B: @# J3 b* V" @2 ^$ _
phpMyAdmin/darkblue_orange/layout.inc.php$ A4 X; c$ S4 X5 P) B- C+ _" A
phpMyAdmin/index.php?lang[]=13 T' a# r. |- x F* W( \/ e& F
phpmyadmin/themes/darkblue_orange/layout.inc.php" `( K9 `7 U8 n7 D# }5 o
4.利用搜索引擎爆绝对路径0 R# @1 Z* S5 k% n
site:www.huangse.com Warning. I1 f7 k$ N( M- f
site:www.huangse.com inurl:Warning
0 v1 n$ ?3 C$ _9 N' G9 b# Y6 [- C) I" g7 z* q
等以后慢慢往上补吧,利用单引号的方法俺就不说了。。。 k3 N6 D3 j, n% G
|