|
楼主 |
发表于 2006-11-12 13:42:34
|
显示全部楼层
我安装在dedecms31_lit11目录下
一.登陆目标CMS系统设置
1.登陆POST信息获取
POST /dedecms31_lit11/dede/login.php HTTP/1.1
Accept: */*
Referer: http://127.0.0.1:800/dedecms31_l ... s31_lit11%2Fdede%2F
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Host: 127.0.0.1:800
Content-Length: 87
Connection: Keep-Alive
Cache-Control: no-cache
Cookie: AJSTAT_ok_times=1; AJSTAT_ok_times=2; AJSTAT_ok_pages=4; ENV_GOBACK_URL=%2Fdedecms31_lit11%2Fdede%2Fcontent_list.php%3Fadminid%3D1; PHPSESSID=8c5f7a245068c6df8830f3534b9bfb60
gotopage=%2Fdedecms31_lit11%2Fdede%2F&dopost=login&userid=admin&pwd=admin&validate=ehtk
----------------------------------------------------------------------------------------------------------------------
这个POST后面是登陆地址后缀 POST /dedecms31_lit11/dede/login.php
要去掉目录 登陆地址后缀 框中 应该填入的是 /dede/login.php
这个Referer后面是来源页面后缀
Referer: http://127.0.0.1:800/dedecms31_l ... s31_lit11%2Fdede%2F
要去掉目录 来源页面后缀 框中 应该填入的是 /dede/login.php?gotopage=%2Fdedecms31_lit11%2Fdede%2F
这个是填入登陆POST数据框中的数据
gotopage=%2Fdedecms31_lit11%2Fdede%2F&dopost=login&userid=admin&pwd=admin&validate=ehtk
换掉变动参数后为
gotopage=%2Fdedecms31_lit11%2Fdede%2F&dopost=login&userid=用户名&pwd=密码&validate=验证码
[ 本帖最后由 终端传媒 于 2006-11-12 15:09 编辑 ] |
|