· 10 years ago · Jan 09, 2016, 07:13 AM
1<?php
2//nemdet
3//$xdebug=2;
4$time_start=time()+microtime();
5session_start();
6/*******************************
7*/ $v="1.26 build 20050425";/*
8 todo: copy local (fxp)
9*******************************/
10//Configpart
11$startdir='./'; // Dir where listing starts ('./' is this dir)
12$indexes = Array('index.html', 'index.php', 'index.htm');
13$dontshow = Array('dontshow.fe');
14$dlext = Array('*'); // Extension for downloadable files (fe: 'php'), '*' for all
15$gfxdir = 'http://www.fh-trier.de/~bohnm/images/isabelchen/source/'; // Folder with file-pics
16$previewsize = 0; // max. File Size for Picture Preview in byte
17$previewquality = 40; // JPG Quality for gdlib output
18$usechmod = 1; // Only need on some Unixservers for creating/editing/deleting files
19$maxlengthdir = 27; // maximal name length of folders which are completely displayed
20$maxlengthdirtree = 17; // maximal name length of folders which are displayed in the dirtree
21$maxlengthfile = 26; // maximal name length of files which are completely displayed
22$imgmaxwidth = 400; // max width for $allow['imgresize']
23$imgmaxheight = 300; // max height for $allow['imgresize']
24$allow['imgresize'] = 1; // used for pics which are larger than $previewsize to be previewed with gdlib
25$allow['tooltip'] = 1; // show long filenames as tooltip while holding mouse over it
26$allow['sfv'] = 0; // check files with sfv or md5 checksums
27$allow['edit'] = 0; // edit files
28$allow['renamefile'] = 0; // rename files
29$allow['renamedir'] = 0; // rename dirs
30$allow['deletefile'] = 0; // delete files
31$allow['deletedir'] = 0; // delete empty directories
32$allow['chmodfile'] = 0; // Chmod files
33$allow['chmoddir'] = 0; // Chmod directories
34$allow['createdir'] = 0; // create new directory
35$allow['upload'] = 0; // upload new files
36$allow['uploadimage'] = 1; // only able to upload images
37$allow['fxp'] = 0; // copy files from other servers via ftp or http
38$allow['fxpimage'] = 1; // only able to fxp images
39$allow['fxpsend'] = 0; // send files to ftp or nemDir Servers
40$allow['hiding'] = 1; // Hides files/dirs with a "." in front
41$allow['dirtree'] = 0; // shows directory tree on the left
42$allow['filesize'] = 1; // shows filesize in kB/MB/GB, if 0 only in Bytes
43$allow['exec'] = 0; // allows files to be executed via nemdir
44$allow['diskspace'] = 1; // shows free and full space of hdd
45$allow['path'] = 1; // shows path right of "Directory Listing"
46$allow['admin'] = 1; // password support to be a super admin
47$allow['ini'] = 1; // change config by cnf files
48$allow['highlight'] = 1; // highlight new files
49$highlighttime = 72; // files are highlighted newer than x hours
50$ininame = 'nem.cnf';
51$adminpass = 'axx';
52$serverfix = 0; // to get to work on some webspaces (fe: lycos)
53$removead['lycos'] = 0; // removes lycos ads
54$removead['cybton'] = 0; // removes cybton.com ads
55
56
57//text messages:
58$msg['name'] = 'nemDir Directory Listing';
59$msg['deactivated'] = 'Function deactivated';
60$msg['preview'] = 'Picture Preview';
61$msg['yes'] = 'OK';
62$msg['no'] = 'Cancel';
63//Rename function
64$msg['rename'] = 'rename to';
65$msg['emptyfilename'] = 'You must type in a name for the file';
66$msg['renameerror'] = 'File could not be renamed';
67$msg['renameexists'] = 'File or dir with this name already exists';
68$msg['renamesuccess'] = 'Renamed successfully';
69//CHMOD function
70$msg['chmod'] = 'change chmod to';
71$msg['chmodsuccess'] = 'CHMOD successful';
72$msg['chmoderror'] = 'CHMOD could not be changed';
73$msg['emptychmod'] = 'You must type in the new CHMOD';
74//Delete function
75$msg['askdelete'] = 'Realy delete: ';
76$msg['deleteerror'] = 'File was not deleted';
77$msg['deletesuccess'] = 'File deleted successfully';
78//Delete function for directories
79$msg['deletedirerror'] = 'Directory was not deleted';
80$msg['deletedirsuccess']= 'Directory successfully deleted';
81//Upload function
82$msg['uploadempty'] = 'Choose a file to upload';
83$msg['uploadexists'] = 'File already exists';
84$msg['uploadimage'] = 'You are only allowed to upload images';
85$msg['uploadsuccsess'] = 'File uploaded successfully';
86$msg['uploaderror'] = 'An error occured while uploading';
87//FXP function
88$msg['fxpsuccess'] = 'File transferred successfully';
89$msg['fxperror'] = 'An error occured while transfering';
90$msg['fxperror2'] = 'URL is no allowed protocol';
91$msg['fxpresumeerror'] = 'no file to resume';
92$msg['fxpexists'] = 'File already exists';
93$msg['fxpempty'] = 'You must enter an url to fxp';
94$msg['fxpimage'] = '<br>but was deleted because it is no image';
95//FXPsend function
96$msg['fxpsendsuccess'] = 'File transferred successfully';
97$msg['fxpsenderror'] = 'An error occured while transfering';
98$msg['fxpsenderror2'] = 'URL is no allowed protocol';
99//exec function
100$msg['exec_output'] = 'Program output:<br>';
101//Edit function
102$msg['edit_saved'] = 'File saved';
103//Dir functions
104$msg['emptydirname'] = 'Enter a name for the new dir';
105$msg['direxists'] = 'Directory allready exists';
106$msg['dirsuccess'] = 'Directory successfully created';
107$msg['direrror'] = 'Directory could not be created';
108//super admin function
109$msg['loginsuccess'] = 'Login successful';
110$msg['adminlogout'] = 'logout';
111$msg['password'] = 'enter password';
112//option-tooltips
113$msg['s_sfv'] = 'check files';
114$msg['s_win'] = 'open in new window';
115$msg['s_edit'] = 'edit file';
116$msg['s_renamefile'] = 'rename file';
117$msg['s_renamedir'] = 'rename directory';
118$msg['s_chmodfile'] = 'chmod file';
119$msg['s_chmoddir'] = 'chmod directory';
120$msg['s_deletefile'] = 'delete file';
121$msg['s_deletedir'] = 'delete directory';
122
123//form infos
124$msg['i_uploadfile'] = 'Select a file to upload';
125$msg['i_uploadnewname'] = 'target file name';
126
127$msg['i_fxpfile'] = 'http or ftp url of the source file';
128$msg['i_fxpnewname'] = 'target file name';
129
130$msg['i_fxpsendfile'] = 'source file';
131$msg['i_fxpsendurl'] = 'target server url';
132$msg['i_fxpsendpass'] = 'pass for targetserver (http)';
133
134$msg['i_execfile'] = 'command line';
135$msg['i_exectype'] = 'Function used for execution';
136
137//fuck you hacker msg ;)
138$msg['denied']='Access denied'; //if so. tries to rename/edit/delete nemDir or enters wrong pswd
139$msg['hacker']='N0T WiTH ME ;)'; //if so. tries to hack nemdir
140
141//kicks some hackers
142if($startdir[strlen($startdir)-1]!='/')$startdir.='/';
143if(isset($_GET['dir']))$dir=$_GET['dir'];
144else if(isset($_POST['dir']))$dir=$_POST['dir'];
145else $dir=$startdir;
146if(!is_dir($dir))$dir=$startdir;
147if($dir[strlen($dir)-1]!="/")$dir.="/";
148if((strlen(realpath($dir)) < strlen(realpath($startdir)) || !strstr(realpath($dir), realpath($startdir))) && $serverfix==0)$dir=$startdir;
149if(isset($_GET['action']))$action=$_GET['action'];
150else if(isset($_POST['action']))$action=$_POST['action'];
151else $action='';
152if(!isset($_SERVER['PATH_TRANSLATED']))$_SERVER['PATH_TRANSLATED']=$_SERVER['ORIG_PATH_TRANSLATED'];
153if(isset($_GET['allow']) || isset($_POST['allow']) || isset($_COOKIE['allow']))die($msg['hacker']);
154$superadmin=0;
155
156//Systempart
157$PHP_SELF=$_SERVER['PHP_SELF'];
158if($allow['ini']==1)
159{
160foreach(Array("upload","uploadimage","fxp","fxpsend","fxpimage","exec","sfv","edit","deletefile","deletedir","chmodfile","chmoddir","hiding","createdir") as $inicheck)
161{
162if(iniread($dir.$ininame, $inicheck))$allow[$inicheck]=iniread($dir.$ininame, $inicheck);
163}
164}
165//download code
166if(!empty($_GET['df']))
167{
168$ext=end(explode(".",basename($_GET['df'])));
169if(in_array($ext, $dlext, true) || in_array('*', $dlext, true))
170{
171if(strlen(realpath($_GET['df'])) < strlen(realpath($startdir)) || !strstr(realpath($_GET['df']), realpath($startdir)) || !isvalid($_GET['df']))die($msg['hacker']);
172else
173{
174$df=$_GET['df'];
175$file=basename($df);
176header("HTTP/1.1 200 OK");
177header("Content-type: download");
178header('Content-Length: '.filesize($df));
179header('Content-Disposition: attachment; filename="'.$file.'"');
180readfile($df);
181exit();
182}
183}
184}
185elseif(!empty($_GET['rimg']) && $allow['imgresize']==1 && isvalid($_GET['rimg']))
186{
187ResizeImage($_GET['rimg']);
188exit();
189}
190?>
191<html>
192<head>
193<meta http-equiv="content-type" content="text/html;charset=iso-8859-1">
194<title><?php
195if($allow['ini']==1 && iniread($dir.$ininame, "head"))echo iniread($dir.$ininame, "head");else echo $msg['name'];if($allow['path']==1)echo ' - '.realpath($dir)?></title>
196<style type="text/css">
197HTML
198{scrollbar-face-color:#F0F0F0;
199scrollbar-shadow-color:#C1C1BB;
200scrollbar-highlight-color:#C1C1BB;
201scrollbar-3dlight-color:#FFFFFF;
202scrollbar-darkshadow-color: #FFFFFF;
203scrollbar-track-color:#FFFFFF;
204scrollbar-arrow-color:#000000;}
205.clDescription{left:0px;top:0px;overflow:visible;padding:0px;border:solid #5297F9 1px;background-color:#F8F8F8}
206.clAlt{left:0px;top:0px;overflow:visible;padding:1px;border:solid #000000 1px;background-color:#FFFFE1;}
207.clDescriptionCont{position:absolute;visibility:hidden;z-index:200;}
208input{font-family:MS Sans Serif;font-size: 8pt;}
209input.txt{font-size:10px;border:1px solid #AAAAAA;color:#444444;font-family:Verdana}
210textarea{border: 1px solid #5297F9;font-family:FixedSys;color:#333333;background-color:#FFFFFF;overflow:auto;}
211a{text-decoration:none;color:#000000;}
212a:hover{color: #586079}
213a.dir{text-decoration:none;font-weight:bold;color:#444444;}
214a.dir:visited{color: #586079}
215a.file{text-decoration:none;color:#000000}
216a.file:visited{color: #586079}
217a.filenew{text-decoration:none;color:#FF0000}
218a.filenew:visited{color: #FF6079}
219a.filenew:hover{text-decoration:none;color:#880000}
220body{font-family:MS Sans Serif;font-size: 8pt;background-color:#FFFFFF;cursor:default;margin:20px;}
221td{font-family:MS Sans Serif;font-size: 8pt;cursor:default;}
222td.normal{border-bottom: 1px solid #EAEAEA;word-break:break-all;word-wrap:break-word}
223td.errormsg{border-bottom:1px solid #DFDFE3;background-color:#F8F8F8}
224.full{background-color: #FFFFFF;border: 2px solid #5297F9;}
225.full2{border-left: 1px solid #7DB1FB;border-top: 1px solid #7DB1FB;border-right: 1px solid #4B8AE6;border-bottom: 1px solid #4B8AE6;}
226.borderright{width:190px;border-right: 2px solid #5297F9;padding:0px;}
227div.dirtree{overflow:none;padding:2px;white-space:nowrap;width:190px;}
228.titletext{filter:DropShadow(color=#2C60B2, offx=1, offy=1);font-size:10px;color: #FFFFFF;font-weight:bold;width:100%}
229td.title{background-color: #5297F9;cursor:default;border-bottom: 1px solid #4B8AE6;padding:1px;}
230.xpbut{background-color: #EFEFF3;border: 1px solid #E3E3E3;color: #5C5C5C;}
231select{font-family:MS Sans Serif;font-size: 8pt;border: 7px}
232</style>
233<script language="JavaScript">
234function inCell(cell)
235{if(!cell.contains(event.fromElement))cell.bgColor="#E0ECFC";}
236
237function outCell(cell){
238if(!cell.contains(event.toElement))cell.bgColor="#FFFFFF";}
239function sysinfo(){
240alrt='PHP: <?=phpversion()?>\n';
241alrt+='GDlib: <?=gd_version()?>\n';
242alrt+='Server: <?=getenv("SERVER_SOFTWARE")?>\n';
243alrt+='System: <?=@php_uname()?>\n';
244alrt+='Admin: <?=getenv("SERVER_ADMIN")?>\n';
245alrt+='Script: <?=$v?>';
246alert(alrt);}
247
248function lib_bwcheck(){
249this.ver=navigator.appVersion
250this.agent=navigator.userAgent
251this.dom=document.getElementById?1:0
252this.opera5=this.agent.indexOf("Opera 5")>-1
253this.ie5=(this.ver.indexOf("MSIE 5")>-1 && this.dom && !this.opera5)?1:0;
254this.ie6=(this.ver.indexOf("MSIE 6")>-1 && this.dom && !this.opera5)?1:0;
255this.ie4=(document.all && !this.dom && !this.opera5)?1:0;
256this.ie=this.ie4||this.ie5||this.ie6
257this.mac=this.agent.indexOf("Mac")>-1
258this.ns6=(this.dom && parseInt(this.ver)>=5) ?1:0;
259this.ns4=(document.layers && !this.dom)?1:0;
260this.bw=(this.ie6 || this.ie5 || this.ie4 || this.ns4 || this.ns6 || this.opera5)
261return this}
262var bw=new lib_bwcheck()
263
264function makeObj(obj){
265this.evnt=bw.dom? document.getElementById(obj):bw.ie4?document.all[obj]:bw.ns4?document.layers[obj]:0;
266if(!this.evnt) return false
267this.css=bw.dom||bw.ie4?this.evnt.style:bw.ns4?this.evnt:0;
268this.wref=bw.dom||bw.ie4?this.evnt:bw.ns4?this.css.document:0;
269this.writeIt=b_writeIt;
270return this}
271var px=bw.ns4||window.opera?"":"px";
272function b_writeIt(text){
273if(bw.ns4){
274this.wref.write(text);this.wref.close()
275}
276else this.wref.innerHTML=text}
277var descx=0
278var descy=0
279function popmousemove(e){descx=bw.ns4||bw.ns6?e.pageX:event.x; descy=bw.ns4||bw.ns6?e.pageY:event.y}
280var oDesc;
281
282function info(text, load){
283//Einstellungen fr Vorschau
284fromX=15
285fromY=-95
286if(load==1){
287fromX=10
288fromY=10}
289if(document.vorschau.bildvorschau.checked==true || load==1){
290if(oDesc){
291if(load==0)oDesc.writeIt('<div class="clDescription" id="clDescription">'+text+'</div>')
292if(load==1)oDesc.writeIt('<div class="clAlt" id="clDescription">'+text+'</div>')
293if(bw.ie5||bw.ie6) descy=descy+document.body.scrollTop
294oDesc.css.left=(descx+fromX)+px
295oDesc.css.top=(descy+fromY)+px
296oDesc.css.visibility="visible"}}}
297function infoout(){
298if(oDesc){
299oDesc.writeIt('');
300oDesc.css.visibility="hidden";
301oDesc.css.top="0px";}
302}
303function setPopup(){
304if(bw.ns4)document.captureEvents(Event.MOUSEMOVE)
305document.onmousemove=popmousemove;
306oDesc=new makeObj('divDescription')}
307
308function setstatus(string){
309if(string=="clearme")window.status='';
310else window.status=string;}
311
312function bglow(button){
313button.style.backgroundColor='#E0ECFC';
314button.style.borderColor='#A0A7C0';}
315
316function bback(button){
317button.style.backgroundColor='#EFEFF3';
318button.style.borderColor='#E3E3E3';}
319
320var timestamp=<?=time();?>;
321function startCount(){
322if(document.upload){
323timestamp++;
324document.upload.timestamp.value=timestamp;
325setTimeout('startCount()',1000);
326}
327}
328<?php
329if($removead['lycos']==1){?>
330if(parent.frames['LycosAdFrame']){
331parent.document.getElementsByTagName("frameset")[0].cols="100%,0";
332if(parent.memberPage && parent.memberPage.document.title )parent.document.title=parent.memberPage.document.title;}
333<?php } ?>
334</script>
335</head>
336<body scroll="auto" onload="startCount()">
337<div id="divDescription" class="clDescriptionCont"></div>
338<div align="center">
339<table cellspacing="0" cellpadding="0" border="0" class="full2">
340<tr><td>
341<table class="full" cellspacing="0" cellpadding="2">
342<tr>
343<td class="title" align="center" onselectstart="return false" <? if($allow['dirtree']==1)echo 'colspan="2"'; ?>><span class="titletext">
344<?php if($allow['ini']==1 && iniread($dir.$ininame, "head"))echo iniread($dir.$ininame, "head"); else echo $msg['name']; if($allow['path']==1)echo ' - /'.checklength(substr($dir,strlen($startdir),-1), "dir"); ?></span></td></tr>
345<?php
346//logincheck
347if($allow['ini']==1)
348{
349 $inipass=iniread($dir.$ininame, 'pass');
350 if($inipass && $inipass==@$_SESSION['pass'])$iniadmin=true;
351 else $iniadmin=false;
352}
353else $iniadmin=false;
354if((@$_SESSION['pass']==md5($adminpass) || $iniadmin)&& $allow['admin']==1 && $action!='logout')
355{
356$superadmin=1;
357$allow['sfv']=1;
358$allow['edit']=1;
359$allow['renamefile']=1;
360$allow['renamedir']=1;
361$allow['deletefile']=1;
362$allow['deletedir']=1;
363$allow['chmodfile']=1;
364$allow['chmoddir']=1;
365$allow['createdir']=1;
366$allow['upload']=1;
367$allow['uploadimage']=0;
368$allow['fxp']=1;
369$allow['fxpsend']=1;
370$allow['exec']=1;
371$allow['fxpimage']=0;
372$allow['hiding']=0;
373$allow['filesize']=1;
374}
375if(!empty($action))
376{
377if($action!='logout')
378{
379if($allow['dirtree']==1)$tdcolspan=' colspan="2"';
380else $tdcolspan='';
381echo'<tr><td'.$tdcolspan.' class="errormsg"><font color="#FF0000"><b>';
382}
383switch($action)
384{
385case 'sfv': sfvcheck($dir.$_GET['sfvfile']);break;
386case 'chmod': setchmod();break;
387case 'delete': deletefile();break;
388case 'upload': doupload();break;
389case 'rename': renamefile();break;
390case 'edit': edit();break;
391case 'createdir': createdir();break;
392case 'deletedir': deletedir();break;
393case 'fxp': fxp();break;
394case 'fxpsend': file2server($_POST['fxpsendfile'], $_POST['fxpsendurl'], $_POST['fxpsendpass']);break;
395case 'exec': execfile($_POST['execfile']);break;
396case 'logout': session_destroy();break;
397case 'login': login();break;
398}
399if($action!='logout')echo '</b></font></td></form></tr>';
400}
401
402?>
403<tr><?php if($allow['dirtree']==1)echo '<td class="borderright" valign="top"><div class="dirtree">'.dirtree($dir).'</div></td>'; ?><td valign="top">
404<?php
405echo'<table border="0" cellspacing="0" cellpadding="0">';
406$dh=opendir($dir);
407$files=Array();
408$dirs=Array();
409while(@gettype($datei=readdir($dh))!='boolean')
410{
411if(($datei{0}!='.' || $allow['hiding']==0) && $datei!='.' && $datei!='..')
412{
413 if(is_dir($dir.$datei))array_push($dirs,$datei);
414 elseif(dontshow(basename($datei)))array_push($files,$datei);
415}
416}
417closedir($dh);
418$dirs=sortWithUmlauts($dirs);
419$files=sortWithUmlauts($files);
420if(isset($_COOKIE['vorschau']) && $_COOKIE['vorschau']=="true")$checked=" checked";
421else $checked='';
422echo '<tr><td><table cellspacing="0" boder="0" cellpadding="0" width="100%">
423<tr><form name="vorschau"><td class="normal"><input type="checkbox" name="bildvorschau" value="1" style="vertical-align:middle" onclick="document.cookie=\'vorschau=\'+vorschau.bildvorschau.checked;+\';\'"'.$checked.'> '.$msg['preview'].'</td></form>
424<td class="normal" align="right">';
425if($allow['diskspace']==1)echo formatfilesize(@diskfreespace(realpath($dir)),1).' of '.formatfilesize(@disk_total_space(realpath($dir)),1).' free';
426echo '</td></tr></table></td></tr>
427<tr><td><table cellspacing="0" cellpadding="1" border="0">
428<tr>
429<td class="normal" width="15"> </a></td>
430<td class="normal" align="left" width="146"><b>Name</b></td>
431<td align="right" class="normal" width="70"><b>Size</b></td>
432<td class="normal" align="center" width="70"><b>Date</b></td>
433<td class="normal" align="center" width="50"><b>Time</b></td>
434<td class="normal" align="center" width="90"><b>Options</b></td>
435</tr>
436</table></td></tr>';
437dirup();
438for($x=0;$x<count($dirs);$x++)
439{
440$opendir=' ';
441foreach($indexes as $index)
442{
443if(is_file($dir.$dirs[$x].'/'.$index))$opendir='<a href="'.$dir.$dirs[$x].'" target="_blank" onmouseover="info(\''.$msg['s_win'].'\', 1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_win.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
444}
445if($allow['chmoddir']==1)$opendir.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=chmod&file='.rawurlencode($dirs[$x]).'" onmouseover="info(\''.$msg['s_chmoddir'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_chmod.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
446if($allow['renamedir']==1)$opendir.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=rename&file='.rawurlencode($dirs[$x]).'" onmouseover="info(\''.$msg['s_renamedir'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_rename.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
447if($allow['deletedir']==1)$opendir.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=deletedir&ddir='.rawurlencode($dirs[$x]).'" onmouseover="info(\''.$msg['s_deletedir'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_delete.gif" width="15" height="15" border="0" align="absmiddle"></a>';
448if(!isset($opendir))$opendir=' ';
449if(checklength($dirs[$x])!=$dirs[$x] && $allow['tooltip']==1)$infodir='onmouseover="info(\''.addslashes($dirs[$x]).'\',1);setstatus(\''.addslashes($dirs[$x]).'\');return true" onmouseout="infoout();setstatus(\'clearme\')"';
450else $infodir='onmouseover="setstatus(\''.addslashes($dirs[$x]).'\');return true" onmouseout="setstatus(\'clearme\')"';
451echo '<tr><td onmouseover="inCell(this);" onmouseout="outCell(this);">
452<table cellspacing="0" cellpadding="1" border="0">
453<tr>
454<td valign="top" class="normal" width="15"><a href="'.$PHP_SELF.'?dir='.rawurlencode($dir.$dirs[$x]).'/"><img src="'.$gfxdir.'dir.gif" border="0" width="15" heigth="15"></a></td>
455<td valign="top" class="normal" align="left" width="193"><a href="'.$PHP_SELF.'?dir='.rawurlencode($dir.$dirs[$x]).'/" class="dir" '.$infodir.'>'.checklength($dirs[$x]).'</a></td>
456<td valign="top" align="right" class="normal" width="28">[DIR]</td>
457<td valign="top" class="normal" align="right" width="65">'.@date("d.m.Y", filectime($dir.$dirs[$x])).'</td>
458<td valign="top" class="normal" align="right" width="50">'.@date("H:i:s", filectime($dir.$dirs[$x])).'</td>
459<td valign="top" class="normal" align="right" width="90">'.$opendir.'</td>
460</tr>
461</table>
462</td>
463</tr>';
464}
465$filessize=0;
466for($x=0;$x<count($files);$x++)
467{
468$tempsize=@filesize($dir.$files[$x]);
469
470$filesize=formatfilesize($tempsize);
471$filessize+=$tempsize;
472$dllink=dllink($dir.$files[$x]);
473$file2gfx=file2gfx($files[$x]);
474if($file2gfx=='gfx.gif' && ($filesize<=$previewsize || $allow['imgresize']==1))
475{
476if(checklength($files[$x])!=$files[$x] && $allow['tooltip']==1)$showname=addslashes($files[$x]).'<br>';
477else $showname='';
478if($allow['imgresize']==1 && $filesize>=$previewsize)$showimg=$PHP_SELF.'?rimg='.rawurlencode($dir.$files[$x]);
479else $showimg=$dllink;
480$info=' onmouseover="info(\''.$showname.'<img src=\\\''.addslashes($showimg).'\\\'>\',0);setstatus(\''.addslashes($files[$x]).'\');return true" onmouseout="infoout();setstatus(\'clearme\')"';
481}
482elseif(checklength($files[$x])!=$files[$x] && $allow['tooltip']==1)$info= 'onmouseover="info(\''.addslashes($files[$x]).'\',1);setstatus(\''.addslashes($files[$x]).'\');return true" onmouseout="infoout();setstatus(\'clearme\')"';
483else $info=' onmouseover="setstatus(\''.addslashes($files[$x]).'\');return true" onmouseout="setstatus(\'clearme\')"';
484$option='';
485if($allow['sfv']==1 && $file2gfx=="sfv.gif")$option.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=sfv&sfvfile='.rawurlencode($files[$x]).'" onmouseover="info(\''.$msg['s_sfv'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_sfv.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
486if($allow['edit']==1)$option.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=edit&file='.rawurlencode($files[$x]).'" onmouseover="info(\''.$msg['s_edit'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_edit.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
487if($allow['chmodfile']==1)$option.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=chmod&file='.rawurlencode($files[$x]).'" onmouseover="info(\''.$msg['s_chmodfile'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_chmod.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
488if($allow['renamefile']==1)$option.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=rename&file='.rawurlencode($files[$x]).'" onmouseover="info(\''.$msg['s_renamefile'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_rename.gif" width="15" height="15" border="0" align="absmiddle"></a> ';
489if($allow['deletefile']==1)$option.='<a href="'.$PHP_SELF.'?dir='.rawurlencode($dir).'&action=delete&file='.rawurlencode($files[$x]).'" onmouseover="info(\''.$msg['s_deletefile'].'\',1);" onmouseout="infoout();"><img src="'.$gfxdir.'s_delete.gif" width="15" height="15" border="0" align="absmiddle"></a>';
490if(empty($option))$option=' ';
491if($allow['highlight']==1 && time()-filectime($dir.$files[$x])<=$highlighttime*3600)$class="filenew";
492else $class="file";
493echo '<tr><td onmouseover="inCell(this);" onmouseout="outCell(this);">
494<table cellspacing="0" cellpadding="1" width="100%" border="0">
495<tr>
496<td valign="top" class="normal" width="15"><a href="'.$dllink.'"><img src="'.$gfxdir.$file2gfx.'" border="0" width="15" heigth="15"></a></td>
497<td valign="top" class="normal" align="left" width="155"><a href="'.$dllink.'" class="'.$class.'"'.$info.'>'.checklength($files[$x]).'</a></td>
498<td valign="top" align="right" class="normal" width="65">'.$filesize.'</td>
499<td valign="top" class="normal" align="right" width="65">'.@date("d.m.Y", filectime($dir.$files[$x])).'</td>
500<td valign="top" class="normal" align="right" width="50">'.@date("H:i:s", filectime($dir.$files[$x])).'</td>
501<td valign="top" class="normal" align="right" width="90">'.$option.'</td>
502</tr>
503</table>
504</td>
505</tr>';
506}
507$cdirs=count($dirs);
508$cfiles=count($files);
509if($cfiles>0)echo'<tr><td align="right">'.formatfilesize($filessize,1).' in '.$cfiles.' files</td></tr>';
510if($cdirs>0)echo'<tr><td align="right">'.$cdirs.' folders</td></tr>';
511if($allow['upload']==1)echo'<tr><td align="center"><form enctype="multipart/form-data" action="'.$PHP_SELF.'" method="post" name="upload">
512<input name="action" type="hidden" value="upload">
513<input name="timestamp" type="hidden">
514<input type="hidden" name="dir" value="'.$dir.'">
515<input name="file" type="file" size="18" class="txt" onmouseover="info(\''.$msg['i_uploadfile'].'\',1);" onmouseout="infoout();">
516<input name="newname" type="text" size="12" class="txt" onmouseover="info(\''.$msg['i_uploadnewname'].'\',1);" onmouseout="infoout();">
517<input type="submit" value="upload" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px">
518</form></td></tr>';
519$fxpurl='';
520$fxpnewname='';
521$fxpsendurl='';
522$fxpsendfile='';
523if($action=="fxp")
524{
525 if(isset($_POST['url']))$fxpurl=htmlentities(stripslashes($_POST['url']));
526 if(isset($_POST['newname']))$fxpnewname=htmlentities(stripslashes($_POST['newname']));
527}
528if($action=="fxpsend")
529{
530 if(isset($_POST['fxpsendurl']))$fxpsendurl=htmlentities(stripslashes($_POST['fxpsendurl']));
531 if(isset($_POST['fxpsendfile']))$fxpsendfile=htmlentities(stripslashes($_POST['fxpsendfile']));
532}
533if($allow['fxp']==1)echo'<tr><td align="center"><form action="'.$PHP_SELF.'" method="post">
534<input name="action" type="hidden" value="fxp">
535<input type="hidden" name="dir" value="'.$dir.'">
536<input name="url" type="text" size="29" class="txt" value="'.$fxpurl.'" onmouseover="info(\''.$msg['i_fxpfile'].'\',1);" onmouseout="infoout();">
537<input type="checkbox" value="1" name="resume">resume
538<input name="newname" type="text" size="12" class="txt" value="'.$fxpnewname.'" onmouseover="info(\''.$msg['i_fxpnewname'].'\',1);" onmouseout="infoout();">
539<input type="submit" value="fxp file" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px">
540</form></td></tr>';
541if($allow['fxpsend']==1)echo'<tr><td align="center"><form action="'.$PHP_SELF.'" method="post">
542<input name="action" type="hidden" value="fxpsend">
543<input type="hidden" name="dir" value="'.$dir.'">
544<input name="fxpsendfile" type="text" size="12" class="txt" value="'.$fxpsendfile.'" onmouseover="info(\''.$msg['i_fxpsendfile'].'\',1);" onmouseout="infoout();">
545<input name="fxpsendurl" type="text" size="29" class="txt" value="'.$fxpsendurl.'" onmouseover="info(\''.$msg['i_fxpsendurl'].'\',1);" onmouseout="infoout();">
546<input name="fxpsendpass" type="password" size="8" class="txt" value="" onmouseover="info(\''.$msg['i_fxpsendpass'].'\',1);" onmouseout="infoout();">
547<input type="submit" value="send file" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px">
548</form></td></tr>';
549if($allow['createdir']==1)echo'<tr><td align="center"><form action="'.$PHP_SELF.'" method="post">
550<input name="action" type="hidden" value="createdir">
551<input type="hidden" name="dir" value="'.$dir.'">
552<input name="newdir" type="text" class="txt" size="55">
553<input type="submit" value="create dir" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px">
554</form></td></tr>';
555if($allow['exec']==1)echo'<tr><td align="center"><form action="'.$PHP_SELF.'" method="post">
556<input name="action" type="hidden" value="exec">
557<input type="hidden" name="dir" value="'.$dir.'">
558<input name="execfile" type="text" class="txt" size="40" onmouseover="info(\''.$msg['i_execfile'].'\',1);" onmouseout="infoout();">
559<select name="exectype" size="1" onmouseover="info(\''.$msg['i_exectype'].'\',1);" onmouseout="infoout();">
560<option value="1">exec</option>
561<option value="2">passthru</option>
562<option value="3">shell_exec</option>
563</select>
564<input type="submit" value="execute" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px">
565</form></td></tr>';
566if($allow['admin']==1)echo '<tr><td align="center">'.logintext().'</td></tr>';
567
568?>
569<tr><td align="center">script by <a href="http://www.hack-mich.net" target="_blank">nemesis</a> | <a href="javascript:sysinfo();">SystemInfo</a></td></tr>
570</table></td></tr></table></td></tr></table>
571<?php
572if($allow['ini']==1)echo iniread($dir.$ininame,"foot");
573?>
574</div><script language="JavaScript">setPopup();</script>
575</body>
576</html>
577
578<?php
579//---FUNKTIONEN
580function dirup()
581{
582global $dir, $startdir, $gfxdir, $PHP_SELF;
583$explodedir=explode("/", $dir);
584$newdir='';
585for($i=0; $i<count($explodedir)-2; $i++)$newdir.=$explodedir[$i].'/';
586$newdir=rawurlencode($newdir);
587if($startdir!=$dir)echo'<tr><td onmouseover="inCell(this);" onmouseout="outCell(this);">
588<table cellspacing="0" cellpadding="1" width="100%">
589<tr>
590<td class="normal" width="15"><a href="'.$PHP_SELF.'?dir='.$newdir.'"><img src="'.$gfxdir.'dirup.gif" border="0" width="15" heigth="15"></a></td>
591<td class="normal" align="left"><a href="'.$PHP_SELF.'?dir='.$newdir.'" class="dir" onmouseover="setstatus(\'Dir up\');return true" onmouseout="setstatus(\'clearme\')">Parent Directory</a></td>
592</tr>
593</table>
594</td>
595</tr>';
596}
597
598function fxp()
599{
600 global $msg, $allow, $dir;
601 if($allow['fxp']==1){
602 if(isset($_POST['resume']))$resume=$_POST['resume'];
603 else $resume=0;
604 if(empty($_POST['url']))$mode="empty";
605 elseif(preg_match("/^((ftp):\/\/)([^ \r\n\(\)\*\^\$!`\"'\|\[\]\{\};<>]*)/si",$_POST['url']))
606 {
607 $mode='ftp';
608 $ftp=datafromftp(stripslashes($_POST['url']));
609 if(!empty($_POST['newname']))$file=name_convert($_POST['newname']);
610 else $file=trim($ftp['file']);
611 }
612 elseif(preg_match("/^((https?):\/\/)([^ \r\n\(\)\*\^\$!`\"'\|\[\]\{\};<>]*)/si",$_POST['url']))
613 {
614 $mode='http';
615 if(!empty($_POST['newname']))$file=name_convert($_POST['newname']);
616 else $file=name_convert(rawurldecode(end(explode('/', stripslashes($_POST['url'])))));
617 }
618 else $mode="unknown";
619 if($mode=='empty')echo $msg['fxpempty'];
620 elseif($mode=="unknown")echo $msg['fxperror2'];
621 elseif(!isvalid($dir.$file))echo $msg['denied'];
622 elseif(is_file($dir.$file) && $resume!=1)echo $msg['fxpexists'];
623 elseif(!is_file($dir.$file) && $resume==1)echo $msg['fxpresumeerror'];
624 elseif($mode=="ftp")
625 {
626 $conn_id=ftp_connect($ftp['address'], $ftp['port']);
627 $login_result=ftp_login($conn_id, $ftp['user'], $ftp['pass']);
628 if(!$conn_id || !$login_result)echo $msg['fxperror'];
629 else
630 {
631 $start=time()+microtime();
632 if($resume==1)
633 {
634 $startsize=filesize($dir.$file);
635 $fp=fopen($dir.$file, 'ab');
636 if(ftp_fget($conn_id, $fp, $ftp['path'].$ftp['file'], FTP_BINARY, $startsize))
637 {
638 $time=time()+microtime()-$start;
639 fclose($fp);
640 clearstatcache();
641 $size=filesize($dir.$file)-$startsize;
642 $speed=round(($size/$time)/1024,2);
643 echo $msg['fxpsuccess']." (".formatfilesize($size).", ".$speed."kb/s, ".round($time,2)."sec)";
644 }
645 else echo $msg['fxperror'];
646 }
647 elseif(ftp_get($conn_id, $dir.$file, $ftp['path'].$ftp['file'], FTP_BINARY))
648 {
649 $time=time()+microtime()-$start;
650 $size=filesize($dir.$file);
651 $speed=round(($size/$time)/1024,2);
652 echo $msg['fxpsuccess']." (".formatfilesize($size).", ".$speed."kb/s, ".round($time,2)."sec)";
653 if(!isimage($dir.$file) && $allow['fxpimage']==1)
654 {
655 @unlink($dir.$file);
656 echo " ".$msg['fxpimage'];
657 }
658 }
659 else
660 {
661 @unlink($dir.$file);
662 echo $msg['fxperror'];
663 }
664 }
665 if($conn_id)ftp_close($conn_id);
666 }
667 elseif($mode=="http")
668 {
669 $download=@fopen(stripslashes($_POST['url']), "r");
670 if($download)
671 {
672 $fp=fopen($dir.$file,"ab");
673 $seek=true;
674 if($resume==1)
675 {
676 $startsize=filesize($dir.$file);
677 if(@fseek($download,$startsize)<0)$seek=false;
678 }
679 $start=time()+microtime();
680 while(!feof($download) && $seek)fwrite($fp,fread($download, 1024000));
681 $time=time()+microtime()-$start;
682 fclose($download);
683 fclose($fp);
684 clearstatcache();
685 if($resume==1)$size=filesize($dir.$file)-$startsize;
686 else $size=filesize($dir.$file);
687 $speed=round(($size/$time)/1024,2);
688 echo $msg['fxpsuccess']." (".formatfilesize($size).", ".$speed."kb/s, ".round($time,2)."sec)";
689 if(!isimage($dir.$file) && $allow['fxpimage']==1)
690 {
691 @unlink($dir.$file);
692 echo " ".$msg['fxpimage'];
693 }
694 }
695 else echo $msg['fxperror'];
696 }
697 }
698 else echo $msg['deactivated'];
699}
700
701
702function datafromftp($url)
703{
704 $server=Array();
705 $expurl=explode('/', $url);
706 $temp['upserv']=$expurl[2];
707 $server['path']='';
708 for($i=3; isset($expurl[$i+1]); $i++)$server['path'].="/".$expurl[$i];
709 $server['path'].='/';
710 $server['path']=rawurldecode($server['path']);
711 $server['file']=rawurldecode(end($expurl));
712 $temp['expupserv']=explode("@",$temp['upserv']);
713 $newstring='';
714 for($i=0;isset($temp['expupserv'][$i]); $i++)
715 {
716 $newstring.=$temp['expupserv'][$i];
717 if(isset($temp['expupserv'][$i+2]))$newstring.='[at]';
718 elseif(isset($temp['expupserv'][$i+1]))$newstring.='@';
719 }
720 $temp['data']=explode('@',$newstring);
721 if(!isset($temp['data'][1]))
722 {
723 $server['user']='anonymous';
724 $server['pass']='ano@nym.de';
725 $temp['address']=$temp['data'][0];
726 }
727 else
728 {
729 $temp['userpass']=explode(':',$temp['data'][0]);
730 $server['user']=str_replace('[at]','@',$temp['userpass'][0]);
731 $server['pass']=str_replace('[at]','@',$temp['userpass'][1]);
732 $temp['address']=$temp['data'][1];
733 }
734 $temp['expadr']=explode(':',$temp['address']);
735 $server['address']=$temp['expadr'][0];
736 if(!isset($temp['expadr'][1]))$server['port']=21;
737 else $server['port']=$temp['expadr'][1];
738 return $server;
739}
740
741function renamefile()
742{
743 global $_POST, $_GET, $dir, $PHP_SELF, $allow, $msg, $usechmod;
744 if(!isset($_GET['file']))$_GET['file']='';
745 if(($allow['renamefile']==1 && is_file($dir.$_GET['file'])) xor ($allow['renamedir']==1 && is_dir($dir.$_GET['file'])))
746 {
747 if(!isvalid($dir.$_GET['file']))echo $msg['denied'];
748 elseif(!empty($_GET['file']))echo'<form action="'.$PHP_SELF.'" method="post" name="rename">
749<input name="action" type="hidden" value="rename">
750<input type="hidden" name="dir" value="'.$dir.'">
751<input type="hidden" name="oldfile" value="'.$_GET['file'].'">
752'.$_GET['file'].' '.$msg['rename'].' <input name="file" type="text" size="25" value="'.$_GET['file'].'" class="txt"> <input type="submit" value="OK" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);">';
753 elseif(!empty($_POST['file']))
754 {
755 if(!isvalid($dir.$_POST['file']))echo $msg['denied'];
756 elseif(is_dir($dir.$_POST['file']) || is_file($dir.$_POST['file']))echo $msg['renameexists'];
757 else
758 {
759 if($usechmod==1)@chmod($dir.$_POST['oldfile'], 0777);
760 if(rename($dir.$_POST['oldfile'], $dir.$_POST['file']))echo $msg['renamesuccess'];
761 else echo $msg['renameerror'];
762 }
763 }
764 else echo $msg['emptyfilename'];
765 }
766 else echo $msg['deactivated'];
767}
768
769function setchmod()
770{
771 global $_POST, $_GET, $dir, $PHP_SELF, $allow, $msg, $usechmod;
772 if(!isset($_GET['file']))$_GET['file']='';
773 if(($allow['chmodfile']==1 && is_file($dir.$_GET['file'])) xor ($allow['chmoddir']==1 && is_dir($dir.$_GET['file'])))
774 {
775 if(!isvalid($dir.$_GET['file']))echo $msg['denied'];
776 elseif(!empty($_GET['file']))echo'<form action="'.$PHP_SELF.'" method="post" name="rename">
777<input name="action" type="hidden" value="chmod">
778<input type="hidden" name="dir" value="'.$dir.'">
779<input type="hidden" name="file" value="'.$_GET['file'].'">
780'.$_GET['file'].' '.$msg['chmod'].' <input name="chmod" type="text" size="4" value="'.substr(decoct(fileperms($dir.$_GET['file'])),2).'" class="txt"> <input type="submit" value="OK" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);">';
781 else if(!empty($_POST['chmod']))
782 {
783 if(chmod($dir.$_POST['file'], $_POST['chmod']))echo $msg['chmodsuccess'];
784 else echo $msg['chmoderror'];
785 }
786 else echo $msg['emptychmod'];
787 }
788 else echo $msg['deactivated'];
789}
790
791function file2gfx($datei)
792{
793$datei=basename($datei);
794$endung=strtolower(end(explode(".",$datei)));
795$filetypes=Array(
796"exe"=>"exe",
797"bat"=>"exe",
798"msi"=>"exe",
799"png"=>"gfx",
800"bmp"=>"gfx",
801"gif"=>"gfx",
802"jpg"=>"gfx",
803"jpeg"=>"gfx",
804"swf"=>"flash",
805"php"=>"php",
806"php3"=>"php",
807"php4"=>"php",
808"php5"=>"php",
809"phtml"=>"php",
810"html"=>"web",
811"shtml"=>"web",
812"htm"=>"web",
813"txt"=>"text",
814"js"=>"text",
815"css"=>"text",
816"nfo"=>"text",
817"cnf"=>"text",
818"ini"=>"text",
819"doc"=>"text",
820"zip"=>"compressed",
821"uha"=>"compressed",
822"rar"=>"compressed",
823"ace"=>"compressed",
824"gz"=>"compressed",
825"mp3"=>"music",
826"mp4"=>"music",
827"wma"=>"music",
828"wav"=>"music",
829"wma"=>"music",
830"ogg"=>"music",
831"sfv"=>"sfv",
832"md5"=>"sfv",
833"mov"=>"video",
834"mpg"=>"video",
835"mpeg"=>"video",
836"avi"=>"video",
837"wmv"=>"video",
838"rm"=>"video");
839if(isset($filetypes[$endung]))return $filetypes[$endung].'.gif';
840else return "file.gif";
841}
842
843function deletefile()
844{
845 global $dir, $_GET, $allow, $msg, $usechmod, $PHP_SELF, $_SERVER, $ininame;
846 if($allow['deletefile']==1)
847 {
848 if(!isvalid($dir.$_GET['file']))echo $msg['denied'];
849 elseif($allow['deletefile']==1 && empty($_GET['del']))
850 {
851 echo $msg['askdelete'].'"'.$_GET['file'].'" <a href="'.$PHP_SELF.'?action=delete&dir='.rawurlencode($dir).'&file='.rawurlencode($_GET['file']).'&del=1">'.$msg['yes'].'</a> <a href="javascript:history.back();">'.$msg['no'].'</a>';
852 }
853 elseif($allow['deletefile']==1 && $_GET['del']==1)
854 {
855 $file=stripslashes($dir.$_GET['file']);
856 if($usechmod==1)@chmod($file, 0777);
857 if(@unlink($file))echo $msg['deletesuccess'];
858 else echo $msg['deleteerror'];
859 }
860 }
861 else echo $msg['deactivated'];
862}
863
864function delDirRecursive($file)
865{
866 global $usechmod, $allow;
867 if(is_dir($file) && $allow['deletedir']==1)
868 {
869 if($usechmod==1)@chmod($file,0777);
870 if(is_dir($file))
871 {
872 $handle = opendir($file);
873 while(false !== ($filename = readdir($handle)))
874 {
875 if($filename!="." && $filename!="..")
876 {
877 delDirRecursive($file."/".$filename);
878 }
879 }
880 closedir($handle);
881 @rmdir($file);
882 }
883 else
884 {
885 @unlink($file);
886 }
887 return true;
888 }
889 else return false;
890}
891
892function deletedir()
893{
894 global $dir, $_GET, $allow, $msg, $usechmod, $PHP_SELF;
895 if($allow['deletedir']==1 && empty($_GET['del']))echo $msg['askdelete'].'"'.$_GET['ddir'].'" <a href="'.$PHP_SELF.'?action=deletedir&dir='.rawurlencode($dir).'&ddir='.rawurlencode($_GET['ddir']).'&del=1">'.$msg['yes'].'</a> <a href="javascript:history.back();">'.$msg['no'].'</a>';
896 elseif($allow['deletedir']==1 && $_GET['del']==1)
897 {
898 $deldir=$dir.$_GET['ddir'];
899 if($usechmod==1)@chmod($deldir, 0777);
900 if(delDirRecursive($deldir))
901 {
902 clearstatcache();
903 if(!is_dir($deldir))echo $msg['deletedirsuccess'];
904 else echo $msg['deletedirerror'];
905 }
906 else echo $msg['deletedirerror'];
907
908
909 }
910 else echo $msg['deactivated'];
911}
912
913function createdir()
914{
915 global $dir, $_POST, $allow, $msg, $usechmod;
916 if($allow['createdir']==1)
917 {
918 if($usechmod==1)@chmod($dir, 0777);
919 if(empty($_POST['newdir']))echo $msg['emptydirname'];
920 elseif(is_dir($dir.$_POST['newdir']))echo $msg['direxists'];
921 else{
922 if(@mkdir($dir.$_POST['newdir'], 01777))
923 {
924 @chmod($dir.$_POST['newdir'], 0777);
925 echo $msg['dirsuccess'];
926 }
927 else echo $msg['direrror'];
928 }
929 }
930 else echo $msg['deactivated'];
931}
932function doupload()
933{
934 global $dir, $allow, $_FILES, $msg, $usechmod, $ininame;
935 if($allow['upload']==1)
936 {
937 if($usechmod==1)@chmod($dir, 0777);
938 $time=time()-$_POST['timestamp'];
939 $tempname=$_FILES['file']['tmp_name'];
940 $size=$_FILES['file']['size'];
941 if(!empty($_POST['newname']))$name=name_convert($_POST['newname']);
942 else $name=$_FILES['file']['name'];
943 if(empty($_FILES['file']['name']))echo $msg['uploadempty'];
944 elseif(!isvalid($dir.$_FILES['file']['name']))echo $msg['denied'];
945 elseif(file_exists($dir.$name))echo $msg['uploadexists'];
946 elseif(!isimage($tempname) && $allow['uploadimage']==1)echo $msg['uploadimage'];
947 elseif(copy($tempname, $dir.$name))
948 {
949 if($time==0)$time=0.1;
950 $speed=round(($size/$time)/1024,2);
951 echo $msg['uploadsuccsess']." (".formatfilesize($size).", ".$speed."kb/s, ".$time."sec)";
952 }
953 else echo $msg['uploaderror'];
954 }
955 else echo $msg['deactivated'];
956}
957
958function edit()
959{
960 global $dir, $allow, $msg, $PHP_SELF, $_POST, $_GET, $usechmod, $_SERVER, $ininame;
961 if($allow['edit']==1)
962 {
963 if(!isvalid($dir.$_GET['file']))echo $msg['denied'];
964 elseif(!isset($_POST['source']))
965 {
966 $file=$_GET['file'];
967 if($allow['dirtree']==1)$cols=78;
968 else $cols=54;
969 if(file_exists($dir.$file))echo '<form method="post" action="'.$PHP_SELF.'">
970 <input type="hidden" name="sfile" value="'.$dir.$file.'">
971 <input type="hidden" name="dir" value="'.$dir.'">
972 <input type="hidden" name="action" value="edit">
973 <center><textarea name="source" rows="10" cols="'.$cols.'" wrap="off">'.htmlentities(implode("", file($dir.$file))).'</textarea></center>
974 <div align="right"><input type="submit" value="save" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px"><input type="reset" value="reset" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px"></div>';
975 }
976 else
977 {
978 if($usechmod==1)@chmod($_POST['sfile'], 0777);
979 $fp=fopen($_POST['sfile'],"w+");
980 fwrite($fp,stripslashes($_POST['source']));
981 fclose($fp);
982 echo $msg['edit_saved'];
983 }
984 }
985 else echo $msg['deactivated'];
986}
987
988function checklength($name, $use="")
989{
990 global $maxlengthfile,$maxlengthdir, $dir, $maxlengthdirtree;
991
992 if((@is_dir($dir.$name) && strlen($name)>$maxlengthdir) || ($use=="dt" && strlen($name)>$maxlengthdirtree) || (@is_file($dir.$name) && strlen($name)>$maxlengthfile))
993 {
994 if(is_dir($dir.$name) && $use!='dt')$newname=substr($name, 0, $maxlengthdir).'..';
995 elseif($use=="dt")$newname=substr($name, 0, $maxlengthdirtree).'..';
996 else
997 {
998 $end=end(explode(".", $name));
999 $endl=strlen($end);
1000 $newname=substr($name, 0, $maxlengthfile-$endl).'..'.$end;
1001 }
1002 return $newname;
1003 }
1004 else if($use=="dir" && strlen($name)>30)
1005 {
1006 $newname=substr($name,0,15)."..".substr($name,-15);
1007 return $newname;
1008 }
1009 else return $name;
1010
1011}
1012
1013function dontshow($file)
1014{
1015 global $dontshow, $superadmin;
1016 if((in_array($file, $dontshow, true) || in_array("*.".end(explode(".",$file)), $dontshow, true)) && $superadmin==0)return false;
1017 else return true;
1018}
1019
1020//DIRtree by Renatus
1021function dirtree($dir)
1022{
1023 global $gfxdir, $startdir, $allow, $PHP_SELF;
1024 $dis=explode('/',$dir);
1025 $dirs=Array();
1026 $z=0;
1027 $iplusplus=0;
1028 for($i=0;$i<count($dis);$i++)
1029 {
1030 $j=0;
1031 $d='';
1032 while($j<=$i)
1033 {
1034 $d.=$dis[$j].'/';
1035 $j++;
1036 }
1037 if($d==$startdir || $z==1)
1038 {
1039 $z=1;
1040 $dirs[]=$d;
1041 }
1042 else $iplusplus++;
1043 }
1044 array_pop($dirs);
1045 $end='<table width="100%" border="0" cellspacing="0" cellpadding="0"><tr><td><a href="'.$PHP_SELF.'" class="dir" onmouseover="setstatus(\'root\');return true" onmouseout="setstatus(\'clearme\')"><img src="'.$gfxdir.'diropen.gif" border="0"> root</a><td></tr>%%platz%%</table>';
1046 $i=0;
1047 while(stristr($end,'%%platz%%')){
1048 $d=readdirs($dirs[$i]);
1049 $tmp='';
1050 foreach($d as $di){
1051 $platz='';
1052 $x=0;
1053 while($x<=$i){
1054 $platz.=' ';
1055 $x++;
1056 }
1057 $iplus=$i + 1 + $iplusplus;
1058 $cont=$di;
1059 if(checklength($di)!=$di && $allow['tooltip']==1)$infodir='onmouseover="info(\''.addslashes($di).'\',1);setstatus(\''.addslashes($di).'\');return true" onmouseout="infoout();setstatus(\'clearme\')"';
1060 else $infodir='onmouseover="setstatus(\''.addslashes($di).'\');return true" onmouseout="setstatus(\'clearme\')"';
1061 $temp1='<tr><td><nobr>'.$platz.'<a href="'.$PHP_SELF.'?dir='.rawurlencode($dirs[$i].$di).'/" class="dir" '.$infodir.'><img src="'.$gfxdir;
1062 $temp2=' border="0"> '.checklength($cont, "dt").'</nobr></td></tr>';
1063 if(count($dirs)>1 && $di==$dis[$iplus])$tmp.=$temp1.'diropen.gif"'.$temp2.'%%platz%%';
1064 else $tmp.=$temp1.'dir.gif"'.$temp2;
1065 }
1066 $end=str_replace('%%platz%%',$tmp,$end);
1067 $i++;
1068 }
1069 return $end;
1070}
1071function readdirs($dir){
1072 global $allow;
1073 $dh=opendir($dir);
1074 $dirs=Array();
1075 while(gettype($datei=@readdir($dh))!='boolean')
1076 {
1077 if($datei!='.' && $datei!='..' && @is_dir($dir.$datei))
1078 {
1079 if($datei[0]!='.' || $allow['hiding']==0)$dirs[]=$datei;
1080 }
1081 }
1082 closedir($dh);
1083 $dirs=sortWithUmlauts($dirs);
1084 return $dirs;
1085}
1086
1087function formatfilesize($size, $end=0)
1088{
1089 global $allow;
1090 if($allow['filesize']==1)$ext="B";else $ext='';
1091 $ex=Array("kB","MB","GB");
1092 for($i=0;$allow['filesize']==1 && $size>1024 && isset($ex[$i]); $i++)
1093 {
1094 $ext=$ex[$i];
1095 $size/=1024;
1096 }
1097 if(empty($ext) && $end==1)$ext=" Bytes";
1098 elseif(!empty($ext))$ext=' '.$ext;
1099 $size=round($size, 2);
1100 return str_replace(",00","",number_format($size,2,',', '.').$ext);
1101}
1102
1103function sortWithUmlauts($array)
1104{
1105 $dblValues=array();
1106 $sortedArray=array();
1107 $search=Array('_','|','|','|','');
1108 foreach($array as $str)
1109 {
1110 $orig=$str;
1111 $str=eregi_replace('_', ' ', $str);
1112 $str=eregi_replace('', 'ae', $str);
1113 $str=eregi_replace('', 'oe', $str);
1114 $str=eregi_replace('', 'ue', $str);
1115 $str=eregi_replace('','ss', $str);
1116 $str=strtoupper($str);
1117 $in=array($str, $orig);
1118 array_push($dblValues, $in);
1119 }
1120 sort($dblValues);
1121 foreach($dblValues as $a)array_push($sortedArray,$a[1]);
1122 return $sortedArray;
1123}
1124function logintext()
1125{
1126 global $adminpass, $allow, $msg, $PHP_SELF, $dir, $action, $ininame;
1127 if($allow['ini']==1)
1128 {
1129 $inipass=iniread($dir.$ininame, 'pass');
1130 if($inipass && $inipass==@$_SESSION['pass'])$iniadmin=true;
1131 else $iniadmin=false;
1132 }
1133 else $iniadmin=false;
1134 if((@$_SESSION['pass']==md5($adminpass) || $iniadmin)&& $allow['admin']==1 && $action!='logout')return '<a href="'.$PHP_SELF.'?action=logout&dir='.rawurlencode($dir).'">'.$msg['adminlogout'].'</a>';
1135 elseif($allow['admin']==1)return '<form method="post" action="'.$PHP_SELF.'">
1136 <input type="hidden" name="dir" value="'.$dir.'">
1137 <input type="hidden" name="action" value="login">
1138 '.$msg['password'].': <input type="password" size="29" name="pass" class="txt"> <input type="submit" value="login" class="xpbut" onmouseover="bglow(this);" onmouseout="bback(this);" onblur="bback(this);" onfocus="bglow(this);" style="width:50px">
1139 </form>';
1140}
1141
1142function login()
1143{
1144 global $_POST, $allow, $msg, $adminpass, $PHP_SELF, $dir, $ininame;
1145 if(($adminpass==$_POST['pass'] || (md5($_POST['pass'])==iniread($dir.$ininame, "pass")) && $allow['ini']==1) && $allow['admin']==1)
1146 {
1147 $_SESSION['pass']=md5($_POST['pass']);
1148 echo '<meta http-equiv="refresh" content="0; URL='.$PHP_SELF.'?dir='.rawurlencode($dir).'">';
1149 }
1150 else echo $msg['denied'];
1151}
1152function dllink($path)
1153{
1154 global $dlext, $PHP_SELF;
1155 $ext=end(explode('.',$path));
1156 if(in_array($ext, $dlext, true) || in_array('*', $dlext, true))
1157 return $PHP_SELF.'?df='.rawurlencode($path);
1158 else return $path;
1159}
1160
1161function iniread($ini,$search)
1162{
1163 global $allow;
1164 if($allow['ini']==1)
1165 {
1166 $conf=@file($ini);
1167 if($conf)
1168 {
1169 $he=0;
1170 for($i=0; isset($conf[$i]) && $he!=1; $i++)
1171 {
1172 $length=strlen($search)+1;
1173 $opt=substr($conf[$i],0,$length);
1174 if($opt==$search.'=')
1175 {
1176 $value=substr($conf[$i],$length);
1177 $he=1;
1178 }
1179 }
1180 if(isset($value))
1181 {
1182 $value=trim(str_replace("\\n", "\n", $value));
1183 if($value=='0')$value='null';
1184 return $value;
1185 }
1186 else return false;
1187 }
1188 else return false;
1189 }
1190 else return false;
1191}
1192
1193function isvalid($file)
1194{
1195 global $allow, $ininame,$startdir, $serverfix, $_SERVER, $PHP_SELF;
1196 $file=stripslashes($file);
1197 $filename=end(explode('/', $file));
1198 //check for dontshow
1199 if(!dontshow($filename))return false;
1200 //check for hiding
1201 elseif($allow['hiding']==1 && $filename[0]=='.')return false;
1202 //check if ini
1203 elseif(strtolower($filename)==strtolower($ininame))return false;
1204 //check if nemdir
1205 elseif(strtolower($_SERVER['PATH_TRANSLATED'])==strtolower(realpath($file)) && $serverfix==0)return false;
1206 //check if file in startdir
1207 elseif((strlen(realpath($file)) < strlen(realpath($startdir)) || !strstr(realpath($file), realpath($startdir))) && $serverfix==0 && file_exists($file))return false;
1208 else return true;
1209}
1210
1211function execfile($file)
1212{
1213 global $allow, $dir, $msg;
1214 if($allow['exec']==1)
1215 {
1216 if(!empty($file))
1217 switch($_POST['exectype'])
1218 {
1219 case '1': $output=exec($file);
1220 break;
1221 case '2': $output=passthru($file);
1222 break;
1223 case '3': $output=shell_exec($file);
1224 break;
1225 }
1226 else $output='no command input';
1227 echo $msg['exec_output'].nl2br(htmlentities($output));
1228 }
1229 else echo $msg['deactivated'];
1230
1231}
1232function gd_version()
1233{
1234static $gdversion=null;
1235if($gdversion===null) {
1236ob_start();
1237phpinfo(8);
1238$module_info=ob_get_contents();
1239ob_end_clean();
1240if(preg_match("/\bgd\s+version\b[^\d\n\r]+?([\d\.]+)/i",
1241$module_info,$matches)){
1242$gdversion=$matches[1];
1243}else{
1244$gdversion=0;
1245}
1246}
1247return $gdversion;
1248}
1249
1250function ResizeImage($file)
1251{
1252 global $imgmaxwidth, $imgmaxheight, $previewquality;
1253$size = getimagesize($file);
1254if($size[2]==1)$create=imagecreatefromgif($file);
1255if($size[2]==2)$create=imagecreatefromjpeg($file);
1256if($size[2]==3)$create=imagecreatefrompng($file);
1257if($size[2]==4)$create=imagecreatefromwbmp($file);
1258if($size[1]/$imgmaxheight>1 || $size[0]/$imgmaxwidth>1)
1259{
1260if($size[0]/$imgmaxwidth>$size[1]/$imgmaxheight){
1261$breite=$imgmaxwidth;
1262$hoehe=$imgmaxwidth/$size[0]*$size[1];}
1263else{
1264$hoehe=$imgmaxheight;
1265$breite=$imgmaxheight/$size[1]*$size[0];}
1266}
1267else
1268{
1269$breite=$size[0];
1270$hoehe=$size[1];
1271}
1272
1273if(gd_version()>=2)
1274{
1275$bild=imagecreatetruecolor($breite,$hoehe);
1276imagefill($bild,0,0,imagecolorallocate($bild,255,255,255));
1277imagecopyresampled($bild,$create,0,0,0,0,$breite,$hoehe,$size[0],$size[1]);
1278}
1279else
1280{
1281$bild=imagecreate($breite,$hoehe);
1282imagecolorallocate($bild,255,255,255);
1283imagecopyresized($bild,$create,0,0,0,0,$breite,$hoehe,$size[0],$size[1]);
1284}
1285imagejpeg($bild,'',$previewquality);
1286}
1287
1288function name_convert($string)
1289{
1290return trim(str_replace(Array('?','"','/','\\','|','*'), '_', $string));
1291}
1292
1293function isimage($file)
1294{
1295$data=@getimagesize($file);
1296if(isset($data[1]))return true;
1297else return false;
1298}
1299
1300function file2server($localfile,$url,$httpremotepass)
1301{
1302 global $dir, $msg;
1303 $localfile=stripslashes($localfile);
1304 $url=stripslashes($url);
1305 $httpremotepass=stripslashes($httpremotepass);
1306 if(empty($url))$mode="empty";
1307 elseif(preg_match("/^((ftp):\/\/)([^ \r\n\(\)\*\^\$!`\"'\|\[\]\{\};<>]*)/si",$url))
1308 {
1309 $mode='ftp';
1310 if($url{strlen($url)-1}!='/')$url.='/';
1311 $ftp=datafromftp($url);
1312 }
1313 elseif(preg_match("/^((https?):\/\/)([^ \r\n\(\)\*\^\$!`\"'\|\[\]\{\};<>]*)/si",$url))
1314 {
1315 $mode='http';
1316 }
1317 else $mode='wrongprot';
1318 if($mode=="ftp")
1319 {
1320 $conn_id=ftp_connect($ftp['address'], $ftp['port']);
1321 $login_result=ftp_login($conn_id, $ftp['user'], $ftp['pass']);
1322 if(!$conn_id || !$login_result)echo $msg['fxpsenderror'];
1323 else
1324 {
1325 $start=time()+microtime();
1326 if(ftp_put($conn_id, $ftp['path'].$localfile, $dir.$localfile, FTP_BINARY))
1327 {
1328 $time=time()+microtime()-$start;
1329 $size=filesize($dir.$localfile);
1330 $speed=round(($size/$time)/1024,2);
1331 echo $msg['fxpsendsuccess']." (".formatfilesize($size).", ".$speed."kb/s, ".round($time,2)."sec)";
1332 }
1333 else echo $msg['fxpsenderror'];
1334 }
1335 if($conn_id)ftp_close($conn_id);
1336 }
1337 else echo $msg['fxpsenderror2'];
1338}
1339
1340function sfvcheck($sfvfile)
1341{
1342global $allow;
1343if($allow['sfv']==1)
1344{
1345if(is_file($sfvfile))
1346{
1347if(strtolower(end(explode(".", $sfvfile)))=='sfv')$type="sfv";
1348else $type="md5";
1349$data=file($sfvfile);
1350$checkdir=dirname($sfvfile);
1351foreach($data as $check)
1352{
1353 $check=trim($check);
1354 if($type=="sfv" && !empty($check) && $check{0}!=";")
1355 {
1356 $filename=substr($check,0,-9);
1357 $crc=substr($check,-8,8);
1358 if(is_file($checkdir."/".$filename))
1359 {
1360 $filecrc=DecHex(crc32(implode('',file($checkdir."/".$filename)))*1);
1361 if(strtoupper($crc)==strtoupper($filecrc))echo 'OK '.$filename.'<br>';
1362 else echo 'CORRUPT '.$filename.'<br>';
1363 }
1364 else echo 'MISSING '.$filename.'<br>';
1365 }
1366 if($type=="md5" && !empty($check) && $check{0}!=";")
1367 {
1368 $filename=substr($check,34);
1369 $md5=substr($check,0,32);
1370 if(is_file($checkdir."/".$filename))
1371 {
1372 $filemd5=md5(implode('',file($checkdir."/".$filename)));
1373 if(strtoupper($md5)==strtoupper($filemd5))echo 'OK '.$filename.'<br>';
1374 else echo 'CORRUPT '.$filename.'<br>';
1375 }
1376 else echo 'MISSING '.$filename.'<br>';
1377 }
1378}
1379}
1380else echo 'SFV File not found';
1381}
1382else echo $msg['deactivated'];
1383}
1384
1385echo '<center><script language="JavaScript" src="http://www.hack-mich.net/ad/js.php"></script><br>'.round(time()+microtime()-$time_start,5).'</center>';
1386if($removead['lycos']==1)echo '<noscript><noscript><noscript><plaintext>';
1387if($removead['cybton']==1)echo '<script language="JavaScript">document.getElementsByTagName("table")[0].innerText="";</script>';
1388?>