Pseudo-static conversion, dynamic execution, injection

Source: Internet
Author: User

When I post for the first time, I will give you a thought of yesterday.
Tested CMS: site building star.
Because it is easier for SEO to do pseudo-static operations, many CMS also have pseudo-static operations. However, pseudo-static is mainly used to hide the passed parameter name. It is only a method for URL rewriting. Since parameter input is acceptable, injection cannot be prevented.
We can see that there are many pseudo-static injection methods on the Internet.
Eg.
Http://www.XXX.com/play/Diablo' and 1w.'1.html and http://www.XXX.com/play/Diablo' and 1w.'2.html to judge
That's why I didn't use this method this time.
I downloaded a website builder. After the local build, the following instances are available after the test.
I don't know if this is correct. Please give me some advice.
Http://www.kinhan.cc/mod_article-fullist-caa_id-19.html
Let me try the injection like this:

No. no results have been returned after several battles.
Then I changed my posture. After the local test, I tried the following link.
Http://www.kinhan.cc/index.php? _... Ullist & caa_id = 1
The two are actually the same. Let's try dropping SQLMAP.

Here is just an idea. Because some CMS can be downloaded. So it can be used. Test it locally.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.