PalmaSolutions

phpsh.php

Apr 17th, 2018
288
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 24.50 KB | None | 0 0
  1. <?php
  2.  
  3.  
  4. // Quick way to add your IP Address to
  5. // the allowedIPs list
  6. // see below for details or to add multiple
  7. // IPs.
  8. $MyIPAddress = '67.253.254.46';
  9.  
  10. /* PHPsh
  11. ** Copyright (C) 2005 P. Deegan. All Rights Reserved.
  12. **
  13. **
  14. ** PHPsh allows you to have shell commands run on your behalf by
  15. ** any webserver which serves PHP pages.
  16. **
  17. ** ***READ*** the license and additional info below. Enjoy :-)
  18. **
  19. ** ================ LICENSE/CONDITIONS OF USE ==============
  20. **
  21. ** You may use and modify this Program for personal or
  22. ** professional activities under the following four (4)
  23. ** conditions:
  24. **
  25. ** 1) You do not modify the licensing terms or copyright notices,
  26. ** including those visible on the program's output (page footer,
  27. ** etc.).
  28. **
  29. ** 2) You do not redistribute this Program but instead refer
  30. ** any other users to the PHPsh homepage
  31. ** (http://www.psychogenic.com/en/products/PHPsh.php).
  32. **
  33. ** 3) You only use this software to access data and perform
  34. ** activities for which you have legal rights (be nice).
  35. **
  36. ** 4) You read and accept the following "NO WARRANTY" clause:
  37. ** BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY
  38. ** FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN
  39. ** OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES
  40. ** PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER
  41. ** EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
  42. ** WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
  43. ** THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM
  44. ** IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST
  45. ** OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
  46. **
  47. ** IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
  48. ** WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY, BE LIABLE
  49. ** TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR
  50. ** CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE
  51. ** PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED
  52. ** INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF
  53. ** THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER
  54. ** OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES
  55. **
  56. ** Any attempt otherwise to use, modify or distribute the Program is void,
  57. ** and will automatically terminate your rights under this License.
  58. ** ==========================================================================
  59. **
  60. **
  61. ** This program can be very usefull on hosts that do not allow regular (SSH) shell access.
  62. ** However, there are a few things to keep in mind:
  63. **
  64. ** - it is web-based and potentially provides anyone with access with a
  65. ** *great deal* of information and access to the system internals. In order to keep
  66. ** your server's safe, you MUST correctly set and maintain the 'allowedIPs' configuration
  67. ** directive. You should consider uploading the program (e.g. through FTP) to your server
  68. ** before each use, and removing it when you are done, each time in order to prevent
  69. ** a stale configuration from giving an unauthorized user access.
  70. **
  71. ** - if you can, install and access the script through an SSL encrypted channel
  72. ** (https://www.example.com/phpsh.php)
  73. **
  74. **
  75. ** - commands are run by the webserver and execute with its priveleges
  76. ** This means you won't have all your regular rights (e.g. you can't write
  77. ** files to certain directories, etc.) but you will have read permissions to
  78. ** all files the webserver can serve up.
  79. **
  80. ** - a number of configuration settings are available within the
  81. ** $PHPshConfig associative array. Read the comments.
  82. */
  83.  
  84. $PHPshConfig = array(
  85.  
  86. /* allowedIPs -- your first, and only, defense from baddies!
  87. **
  88. ** The allowedIPs array specifies the list of remote addresses
  89. ** the shell will accept commands from.
  90. **
  91. ** Connections from unlisted IPs get a message indicating their
  92. ** origin, so you can use that to set the IP as allowed and FTP
  93. ** the modified version to the remote system.
  94. **
  95. ** Example: array('127.0.0.1', '61.93.66.102'),
  96. ** would allow connections only from localhost and 61.93.66.102.
  97. ** There are no wildcards -- be specific and your system will be
  98. ** relatively secure.
  99. **
  100. ** Also, remove the script or at least the IP if you are using
  101. ** a shared address (such as through dialup) where someone else
  102. ** will eventually be connected using the same I.P.
  103. */
  104. 'allowedIPs' => array( $MyIPAddress,
  105. '66.66.235.145',),
  106.  
  107.  
  108.  
  109. /* usefilecmd set to TRUE to use `file` command rather than relying on
  110. ** mime magic to determine file content type when fetching.
  111. ** NOTE: This only works
  112. ** - On Un*x systems
  113. ** - With 'commands' => 'file' set correctly, below.
  114. **
  115. */
  116. 'usefilecmd' => TRUE, // set to TRUE to use `file` command
  117.  
  118.  
  119. // numhistory number of previous commands to hold in history queue
  120. 'numhistory' => 50,
  121.  
  122. // use aliases to setup command aliases, e.g. 'lh -10'
  123. // gets executed as 'ls -l | head -10'
  124. 'aliases' => array(
  125.  
  126. 'ls' => 'ls -F',
  127. 'lh' => 'ls -F -lth | head ',
  128. 'fgr' => 'find . -type f | xargs -n 100 grep ',
  129. 'psa' => 'ps waux',
  130. ),
  131.  
  132. /* disablecommands -- dissallow use of these commands.
  133. ** This is EASY to get arround for anyone with the slightest bit of
  134. ** experience, so these are mainly used as 'guidelines' or safeguards
  135. ** for non-evil users.
  136. **
  137. ** To thwart evil users, see the 'allowedIPs' above.
  138. */
  139. 'disabledcommands' => array('rm', 'ssh', 'passwd', 'su', 'ping', 'telnet'),
  140.  
  141.  
  142.  
  143. 'enableformatting' => TRUE,
  144.  
  145. // formatcommandoutput commands on which to post-process/format, if
  146. // enableformatting is TRUE.
  147. 'formatcommandoutput' => array(
  148. 'ls' => TRUE,
  149. 'find' => TRUE,
  150. 'ps' => TRUE,
  151. 'psa' => TRUE,
  152. ),
  153.  
  154. // commands Path to filesystem executables used
  155. 'commands' => array(
  156. 'hostname' => '/bin/hostname',
  157. 'file' => '/usr/bin/file',
  158. ),
  159.  
  160.  
  161. // formatting Search and replace regexes used for formatting.
  162. 'formatting' => array(
  163. '/(\s+|^)([^\s:\'<\[]+)\*/'
  164. => '\1<span class="exec">\2</span>',
  165. '/(\s+|^)([^\s:\'<\[]+)\@/'
  166. => '\1<span class="symlink">\2</span>',
  167. '/(\s+|^)([^\s:\'<\[]+)\/([\w\d\.]+)?/'
  168. => '\1<span class="dir">\2/\3</span>',
  169. '/([^="\'])?(http(s?):\/\/[\w\d\/=\?\.\-]+)/'
  170. => '\1<span class="url">\2</span>',
  171. '/\[([^\]]+)\]/'
  172. => '[<span class="array">\1</span>]',
  173. ),
  174.  
  175. // maxexecseconds -- *Should* kill programs that exec too long.
  176. // Non-functional, so don't use interactive commands
  177. // that hang.
  178. 'maxexecseconds' => 45, // not really functional... see TODO:FIXME below...
  179.  
  180.  
  181. 'promptfulldirpath' => FALSE, // set to TRUE to include full path in prompt
  182.  
  183. // sesskeys keys used in session, leave 'em alone.
  184. 'sesskeys' => array(
  185.  
  186. 'commandhistory' => '_cmdhist',
  187. 'pwd' => '_pwd',
  188. 'lastwd' => '_lwd',
  189. 'hostname' => '_hname',
  190. 'escape' => '_esc',
  191. ),
  192.  
  193.  
  194. 'sessname' => 'phpshell',
  195.  
  196. 'nooutputescape' => FALSE, // set to TRUE to avoid escaping by default
  197.  
  198.  
  199.  
  200.  
  201. );
  202.  
  203. $PHPshVersion = '1.0.1';
  204.  
  205.  
  206. class PHPsh {
  207.  
  208. var $pwd, $lastwd, $homedir, $hostname;
  209.  
  210. function PHPsh ()
  211. {
  212. global $PHPshConfig;
  213.  
  214. $this->init();
  215.  
  216. }
  217.  
  218. function init ()
  219. {
  220. global $PHPshConfig;
  221. session_name($PHPshConfig['sessname']);
  222. session_start();
  223.  
  224. $sess =& $this->getSession();
  225.  
  226. $this->homedir = dirname(__FILE__);
  227. if (array_key_exists($PHPshConfig['sesskeys']['pwd'], $sess))
  228. {
  229. $this->pwd = $sess[$PHPshConfig['sesskeys']['pwd']];
  230. if (array_key_exists($PHPshConfig['sesskeys']['lastwd'], $sess))
  231. $this->lastwd = $sess[$PHPshConfig['sesskeys']['lastwd']];
  232. else
  233. $this->lastwd = $this->pwd;
  234.  
  235. } else {
  236. $this->pwd = $this->homedir;
  237. $this->lastwd = $this->homedir;
  238. }
  239.  
  240.  
  241.  
  242. if (array_key_exists($PHPshConfig['sesskeys']['hostname'], $sess))
  243. {
  244. $this->hostname = $sess[$PHPshConfig['sesskeys']['hostname']];
  245. } else {
  246.  
  247. if ( file_exists($PHPshConfig['commands']['hostname']) )
  248. {
  249. $this->hostname =
  250. preg_replace('/\s*/', '', $this->popenAndReadCommand(
  251. $PHPshConfig['commands']['hostname']));
  252. } else {
  253. if (is_array($_SERVER) && array_key_exists('SERVER_NAME', $_SERVER))
  254. $this->hostname = $_SERVER['SERVER_NAME'];
  255. else
  256. $this->hostname = 'host';
  257.  
  258.  
  259. }
  260.  
  261. $sess[$PHPshConfig['sesskeys']['hostname']] = $this->hostname;
  262. }
  263.  
  264. if (array_key_exists($PHPshConfig['sesskeys']['hostname'], $sess))
  265. {
  266. // TODO
  267. }
  268.  
  269. return ;
  270.  
  271. } // end method init
  272.  
  273. function & getSession ()
  274. {
  275. return $_SESSION;
  276. }
  277.  
  278. function currentDir ()
  279. {
  280. return $this->pwd;
  281. }
  282.  
  283. function moveToCurrentDir ()
  284. {
  285.  
  286. chdir($this->pwd);
  287. }
  288.  
  289. function getPrompt ()
  290. {
  291. global $PHPshConfig;
  292. $dir = $this->currentDir();
  293. if (! $PHPshConfig['promptfulldirpath'])
  294. {
  295. if (preg_match('/[^\/]/', $dir))
  296. {
  297. $dir = preg_replace('/(.+)\/([^\/]+)$/', '\2', $dir);
  298. }
  299. }
  300.  
  301. return '[' . $this->hostname . "&nbsp;$dir]&nbsp;\$ ";
  302. }
  303.  
  304.  
  305.  
  306. function execCommand ($cmd, $escapeOutput=TRUE)
  307. {
  308. global $PHPshConfig;
  309.  
  310. if (! empty ($cmd) )
  311. {
  312. $this->historyPush($cmd);
  313. $matches = array();
  314. if (preg_match('/^\s*cd\s+(.*)/', $cmd, $matches))
  315. {
  316.  
  317. $this->changeDir($matches[1]);
  318. } else {
  319.  
  320. $contents = NULL;
  321. if ($escapeOutput)
  322. {
  323. $contents = htmlentities($this->popenAndReadCommand($cmd));
  324.  
  325. } else {
  326. $contents = $this->popenAndReadCommand($cmd);
  327. }
  328.  
  329.  
  330. if ($PHPshConfig['enableformatting'])
  331. {
  332. $matches = array();
  333. if (preg_match('/^\s*([^\s]+)/', $cmd, $matches))
  334. {
  335. if (array_key_exists($matches[1],
  336. $PHPshConfig['formatcommandoutput']))
  337. {
  338.  
  339. foreach ($PHPshConfig['formatting']
  340. as $search => $replace)
  341. {
  342. $contents =
  343. preg_replace($search, $replace, $contents);
  344. }
  345.  
  346. } // end if we format the output of this command
  347.  
  348. } // end if we could extract this command from string
  349.  
  350. } // end if formatting is even enabled
  351.  
  352. print $contents;
  353.  
  354. } // end if this is a simple cd to another dir
  355. } // end if we have a command
  356.  
  357. return;
  358.  
  359. }
  360.  
  361.  
  362. function popenAndReadCommand ($cmd)
  363. {
  364. global $PHPshConfig;
  365.  
  366. if (empty($cmd))
  367. return "";
  368.  
  369. $this->moveToCurrentDir();
  370.  
  371. if (! preg_match('/>/', $cmd))
  372. {
  373. $cmd .= ' 2>&1';
  374. }
  375.  
  376.  
  377.  
  378. $matches = array();
  379. if (preg_match('/^\s*([^\s]+)/', $cmd, $matches))
  380. {
  381. if (array_key_exists($matches[1], $PHPshConfig['aliases']))
  382. {
  383. $cmd = preg_replace('/^\s*' . $matches[1] . '/',
  384. $PHPshConfig['aliases'][$matches[1]], $cmd);
  385. }
  386. }
  387.  
  388. foreach ($PHPshConfig['disabledcommands'] as $badCommand)
  389. {
  390. if (preg_match('/(^\s*|;\s*|`\s*)' . $badCommand . '/', $cmd))
  391. {
  392. return "$badCommand is disabled";
  393. }
  394. }
  395.  
  396.  
  397.  
  398. $contents = '';
  399.  
  400. $startTime = time();
  401. $handle = popen($cmd, 'r');
  402. if ($handle)
  403. {
  404. $timeout = FALSE;
  405.  
  406. /* TODO:FIXME maxexecseconds
  407. ** It has to date been impossible to implement a clean
  408. ** and cross-platform method of cancelling processes that
  409. ** hang or run indefinitely (e.g. launching an interactive
  410. ** 'vi' session, or 'ping hostname.example.com' on a linux box).
  411. **
  412. ** The timeout code below forces the pipe closed but this can
  413. ** leave the process running in the background nonetheless... meaning
  414. ** you can end up with a server running 20 instances of vi as 'nobody'...
  415. **
  416. ** Not so great. For the moment, this is a TODO... likely infinite
  417. ** commands can be barred using the 'disabledcommands' array.
  418. */
  419. while (! ($timeout || feof($handle)) )
  420. {
  421. $timeSpent = time() - $startTime;
  422. if ($timeSpent >= $PHPshConfig['maxexecseconds'])
  423. {
  424. $timeout = TRUE;
  425. $contents .= "\nTimed out after $timeSpent seconds..."
  426. . "\nSet 'maxexecseconds' to change this.\n";
  427.  
  428. flush();
  429. pclose($handle);
  430. } else {
  431.  
  432. $contents .= fread($handle, 128);
  433. }
  434.  
  435. }
  436.  
  437. if (! $timeout)
  438. pclose($handle);
  439.  
  440.  
  441. } else {
  442. $contents = "Could not open handle for command '$cmd'\n";
  443. }
  444.  
  445.  
  446.  
  447.  
  448.  
  449. return $contents;
  450. }
  451.  
  452. function changeDir ($dir)
  453. {
  454. global $PHPshConfig;
  455.  
  456. if ($dir == '~')
  457. {
  458. $dir = $this->homedir;
  459. } else if ($dir == '-')
  460. {
  461. $dir = $this->lastwd;
  462. }
  463.  
  464. $lastDir = $this->pwd;
  465. chdir($lastDir);
  466.  
  467. if (! file_exists($dir))
  468. {
  469. print "cd: $dir: No such file or directory<br />\n";
  470. return;
  471. }
  472.  
  473. if (! @chdir($dir) )
  474. {
  475. print "cd $dir: Failed<br />\n";
  476. return;
  477. }
  478.  
  479. $curDir = getcwd();
  480. $this->pwd = $curDir;
  481.  
  482. $sess =& $this->getSession();
  483. $sess[$PHPshConfig['sesskeys']['pwd']] = $curDir;
  484. $sess[$PHPshConfig['sesskeys']['lastwd']] = $lastDir;
  485.  
  486. } // end method changeDir
  487.  
  488. function historyPush ($cmd)
  489. {
  490.  
  491. global $PHPshConfig;
  492. $sess =& $this->getSession();
  493.  
  494. /* make sure we have a command history array */
  495. if (! (array_key_exists($PHPshConfig['sesskeys']['commandhistory'], $sess)
  496. && is_array($sess[$PHPshConfig['sesskeys']['commandhistory']])))
  497. $sess[$PHPshConfig['sesskeys']['commandhistory']] = array();
  498.  
  499.  
  500. /* make sure the command history doesn't grow too large */
  501. if (count($sess[$PHPshConfig['sesskeys']['commandhistory']])
  502. >= $PHPshConfig['numhistory'])
  503. {
  504. // too large, shrink it to max size - 1
  505. $shrunkenArray = array_slice($sess[$PHPshConfig['sesskeys']['commandhistory']],
  506. 0, $PHPshConfig['numhistory'] - 1);
  507.  
  508. $sess[$PHPshConfig['sesskeys']['commandhistory']] = $shrunkenArray;
  509. }
  510.  
  511.  
  512. /* add this command to the front of the array */
  513. if (
  514. (! count($sess[$PHPshConfig['sesskeys']['commandhistory']]))
  515. ||
  516. ($cmd != $sess[$PHPshConfig['sesskeys']['commandhistory']][0])
  517. )
  518. array_unshift($sess[$PHPshConfig['sesskeys']['commandhistory']], $cmd);
  519.  
  520. return;
  521.  
  522. } // end method historyPush
  523.  
  524.  
  525. function getHistoryOptions ()
  526. {
  527.  
  528. global $PHPshConfig;
  529. $sess =& $this->getSession();
  530.  
  531.  
  532. $retArray = array();
  533.  
  534. if (! (array_key_exists($PHPshConfig['sesskeys']['commandhistory'], $sess)
  535. && is_array($sess[$PHPshConfig['sesskeys']['commandhistory']])))
  536.  
  537. return $retArray;
  538.  
  539. foreach ($sess[$PHPshConfig['sesskeys']['commandhistory']] as $cmd)
  540. {
  541. $escapedCmd = htmlentities($cmd);
  542. array_push($retArray,
  543. '<option value="' . $escapedCmd . "\">$escapedCmd</option>");
  544. }
  545.  
  546. return $retArray;
  547. }
  548.  
  549. function showFile ($fname, $escapeOutput=TRUE)
  550. {
  551. global $PHPshConfig;
  552.  
  553. $fullpath = $this->currentDir() . "/$fname";
  554. if (! is_readable($fullpath))
  555. {
  556. print "Unable to read $fullpath";
  557. return;
  558. }
  559.  
  560. $ctype = 'text/plain';
  561. if ($PHPshConfig['usefilecmd'] && is_readable($PHPshConfig['commands']['file']))
  562. {
  563. $f = escapeshellarg($fullpath);
  564. $cmd = $PHPshConfig['commands']['file'] . " -bi $f";
  565. $ctype = trim( `$cmd` );
  566.  
  567. $ctype = preg_replace('/[,\s].*$/', '', $ctype);// sometimes file includes
  568. // weirdness, chop it off.
  569.  
  570. } else if (function_exists('mime_content_type'))
  571. {
  572.  
  573. $ctype = mime_content_type($fullpath) ;
  574. }
  575.  
  576. if ($ctype == 'text/html' && $escapeOutput)
  577. {
  578. // it's html and we do want to escape...
  579. // send it as plain text
  580. header("Content-type: text/plain\r\n\r\n");
  581. } else {
  582. header( "Content-type: $ctype\r\n\r\n");
  583. }
  584.  
  585. readfile( $fullpath);
  586.  
  587.  
  588. return;
  589. }
  590.  
  591.  
  592.  
  593.  
  594. } // end PHPsh class definition
  595.  
  596.  
  597. /* Oh, how I loathe 'magic' !! */
  598. /* P.S. this request to disable the magic
  599. ** doesn't seem to work very well...
  600. ** code above uses stripslashes if its still on */
  601. set_magic_quotes_runtime(0);
  602. ini_set('magic_quotes_gpc', 0);
  603.  
  604.  
  605. /* Important security check!! */
  606. $allowAccess = FALSE;
  607. if (array_key_exists('REMOTE_ADDR', $_SERVER))
  608. {
  609. foreach($PHPshConfig['allowedIPs'] as $ip)
  610. {
  611. if ($ip == $_SERVER['REMOTE_ADDR'])
  612. $allowAccess = TRUE;
  613. }
  614. }
  615.  
  616.  
  617. $shell = new PHPsh;
  618.  
  619.  
  620.  
  621.  
  622.  
  623. $CurDir = $shell->currentDir();
  624. $Command = NULL;
  625. $OutputEscapeFlag = TRUE;
  626. $MySess =& $shell->getSession();
  627. if (array_key_exists($PHPshConfig['sesskeys']['escape'], $MySess))
  628. {
  629. $OutputEscapeFlag = $MySess[$PHPshConfig['sesskeys']['escape']];
  630. }
  631.  
  632. /* Take care of getfile requests right away, using the escape flag from session */
  633. if ($allowAccess)
  634. {
  635. if (is_array($_GET) )
  636. {
  637. if (array_key_exists('getfile', $_GET))
  638. {
  639. $shell->showFile($_GET['getfile'], $OutputEscapeFlag);
  640. exit(1);
  641. }
  642. }
  643.  
  644. }
  645.  
  646.  
  647. $HaveUpload = FALSE;
  648. if (is_array($_FILES) && array_key_exists('uploadfile', $_FILES)
  649. && is_array($_FILES['uploadfile'])
  650. && array_key_exists('name', $_FILES['uploadfile'])
  651. && strlen($_FILES['uploadfile']['name'])
  652. && array_key_exists('tmp_name', $_FILES['uploadfile'])
  653. && $_FILES['uploadfile']['tmp_name'])
  654. {
  655. $HaveUpload = TRUE;
  656. }
  657.  
  658.  
  659.  
  660. if (is_array($_GET) && array_key_exists('command', $_GET))
  661. {
  662. $Command = $_GET['command'];
  663.  
  664. if (array_key_exists('escapeoutput', $_GET))
  665. $OutputEscapeFlag = $_GET['escapeoutput'];
  666. }
  667.  
  668. if (is_array($_POST))
  669. {
  670.  
  671.  
  672. if (array_key_exists('command', $_POST) && $_POST['command'])
  673. $Command = $_POST['command'];
  674. else if (array_key_exists('prevcommand', $_POST)
  675. && $_POST['prevcommand'])
  676. $Command = $_POST['prevcommand'];
  677.  
  678.  
  679.  
  680. if (array_key_exists('escapeoutput', $_POST))
  681. {
  682. $OutputEscapeFlag = $_POST['escapeoutput'];
  683. }
  684.  
  685. if (get_magic_quotes_gpc())
  686. {
  687. $Command = stripslashes($Command);
  688. }
  689.  
  690. }
  691.  
  692. if ($Command && preg_match('/^\s*cd\s+/', $Command))
  693. {
  694. $CurDir = ""; // will change, don't print.
  695. }
  696.  
  697.  
  698. $MySess[$PHPshConfig['sesskeys']['escape']] = $OutputEscapeFlag;
  699.  
  700.  
  701. ?>
  702. <html>
  703. <head>
  704. <title>PHPsh</title>
  705. <!-- Edit the following stylesheet to change the 'highlighting' color scheme
  706. and size of the file list box -->
  707. <style><!--
  708. .exec {
  709. font-family: "Trebuchet MS", Arial, sans-serif;
  710. color: #90C3E2;
  711. }
  712. .dir {
  713. font-family: "Trebuchet MS", Arial, sans-serif;
  714. color: #CCC3E2;
  715. }
  716. .symlink {
  717. font-family: "Trebuchet MS", Arial, sans-serif;
  718. color: #90C3FF;
  719. }
  720. .url {
  721. font-family: "Trebuchet MS", Arial, sans-serif;
  722. color: #900000;
  723. }
  724. .array {
  725. font-family: "Trebuchet MS", Arial, sans-serif;
  726. color: #11AAAA;
  727. }
  728. .filelist {
  729. height: 250px;
  730. width: 250px;
  731. overflow: auto;
  732. }
  733.  
  734. -->
  735. </style>
  736.  
  737.  
  738.  
  739. <script language="javascript" type="text/javascript" src="http://phpsh.psychogenic.com/js/phpshell.js"></script>
  740.  
  741. <body onLoad="sf()" bgcolor="#FEFEFF">
  742.  
  743.  
  744. <h3><a href="http://www.psychogenic.com/en/products/PHPsh.php">PHPsh</a><?php if ($allowAccess && $CurDir){ print " : $CurDir"; } ?></h3>
  745. <p>
  746. <form method="POST" action="<?php print $_SERVER['PHP_SELF']; ?>" enctype="multipart/form-data" id="commands" name="commands">
  747.  
  748. <table border="0" width="100%">
  749. <tr valign="top">
  750. <?php
  751.  
  752.  
  753.  
  754. if ($allowAccess)
  755. {
  756.  
  757.  
  758. if ($Command) {
  759. ?>
  760. <td align="right" width="250px" valign="top">
  761. <?php
  762. print $shell->getPrompt() ;
  763. ?>
  764. </td>
  765. <td align="left" valign="top">
  766. <?php
  767.  
  768. print htmlentities($Command) ;
  769. ?>
  770. </td></tr>
  771. <tr valign="top">
  772. <td align="left" colspan="2">
  773. <pre>
  774. <?php
  775.  
  776. $shell->execCommand($Command, $OutputEscapeFlag);
  777. ?>
  778. </pre>
  779. </td>
  780. </tr>
  781.  
  782. </table>
  783. <table border="0" width="100%">
  784. <tr valign="top">
  785.  
  786. <?php
  787. } else {
  788.  
  789. // make sure we move into the current dir anyway.
  790. $shell->moveToCurrentDir();
  791.  
  792. } // end if command sent
  793.  
  794. ?>
  795.  
  796.  
  797. <td align="right" valign="top" width="250px">
  798. <?php
  799. print $shell->getPrompt();
  800.  
  801. ?>
  802. </td>
  803. <td align="left" valign="top">
  804. <input type="text" size="60" name="command" value="" tabindex="1"/>
  805. </td>
  806. </tr>
  807.  
  808.  
  809.  
  810. <?php
  811. $history = $shell->getHistoryOptions();
  812. if (count($history))
  813. {
  814. ?>
  815. <tr>
  816. <td align="left">
  817. <div class="filelist">
  818. <?php
  819.  
  820.  
  821. if ($HaveUpload)
  822. {
  823. // we have a file upload.
  824. $uploaddir = $shell->currentDir();
  825. $uploadfile = $uploaddir . '/' . basename($_FILES['uploadfile']['name']);
  826. if (! move_uploaded_file($_FILES['uploadfile']['tmp_name'], $uploadfile))
  827. {
  828. print "Unable to move ".
  829. $_FILES['userfile']['tmp_name']
  830. . " file to<br />$uploadfile<br />";
  831. }
  832.  
  833. }
  834.  
  835.  
  836. if ($handle = opendir($shell->currentDir())) {
  837.  
  838. $dirs = array();
  839. $files = array();
  840. while (false !== ($file = readdir($handle))) {
  841.  
  842.  
  843. if ($file != ".") {
  844.  
  845.  
  846. if (is_dir($file))
  847. {
  848. $dirs[] = $file;
  849.  
  850.  
  851.  
  852. } else {
  853. $files[] = $file;
  854.  
  855.  
  856. }
  857.  
  858. }
  859. }
  860. @closedir($handle);
  861.  
  862. natcasesort($files);
  863. natcasesort($dirs);
  864. foreach ($dirs as $d)
  865. {
  866.  
  867. print '<a href="?command=cd+' . urlencode($d)
  868. . '"><emph>' . htmlentities($d)
  869. . "/</emph></a><br />\n";
  870. }
  871. print '<hr/>';
  872. foreach ($files as $f)
  873. {
  874. if (is_readable($f))
  875. {
  876. print '<a target="_blank" href="' . $_SERVER['PHP_SELF']
  877. . '/' .urlencode($f) . '?getfile='
  878. . urlencode($f)
  879. . '">' . htmlentities($f) . '</a>';
  880. } else {
  881. print htmlentities($f);
  882. }
  883.  
  884. print "<br />\n";
  885. }
  886.  
  887.  
  888. } else {
  889. print '<a href="?command=cd+.."><emph>../</emph></a><br />';
  890. print "No perms to read <br />" . $shell->currentDir();
  891. }
  892. ?>
  893.  
  894. </div>
  895. <?php
  896. if (is_writeable($shell->currentDir()))
  897. {
  898. print '<input type="file" name="uploadfile" size="18" />';
  899. }
  900. ?>
  901. </td>
  902. <td valign="top">
  903. <select name="prevcommand" size="14" style="width:500px;" onChange="refreshCommand(this)" onkeypress="sendCommand(this)" tabindex="2">
  904. <?php
  905. print join("\n", $history);
  906. ?>
  907. </select>
  908. </td>
  909. </tr>
  910. <?php
  911.  
  912. } // end if history available
  913. ?>
  914. <tr>
  915. <td align="left">
  916. Escape HTML output: <input type="radio" name="escapeoutput" value="1" <?php
  917. if ($OutputEscapeFlag)
  918. print 'checked="checked"';
  919. ?> >On |
  920. <input type="radio" name="escapeoutput" value="0" <?php
  921. if (! $OutputEscapeFlag)
  922. print 'checked="checked"';
  923. ?> >Off
  924. </td>
  925. <td align="right">
  926. <input type="submit" name="submitbutton" value="Do" />
  927. </td>
  928. <tr>
  929. <td colspan="2">
  930.  
  931.  
  932. <?php
  933. } else {
  934. // not allowed to display
  935. ?>
  936. <td align="left" colspan="2">
  937. <p>
  938. Welcome to the <a href="http://www.psychogenic.com/en/products/PHPsh.php">PHPsh</a>, by
  939. <a href="http://www.psychogenic.com/">Psychogenic Inc</a>!
  940. </p>
  941.  
  942. <p>This program allows a simplified form of shell access through a browser, to any host that allows you to run PHP. The latest version and more information is available on the <a href="http://www.psychogenic.com/en/products/PHPsh.php">PHPsh home page</a>.</p>
  943.  
  944.  
  945. <p>Unfortunately, you are currently accessing this page from an unauthorized I.P. address ( <b><?php echo $_SERVER['REMOTE_ADDR']; ?></b> ) so none of the functionality will be available...
  946. <br />&nbsp;<br /></p>
  947.  
  948. <?php
  949. } // end if access allowed
  950. ?>
  951.  
  952. </td>
  953. </tr>
  954. <tr>
  955. <td colspan="2">
  956. <p align="center"><a href="http://www.psychogenic.com/en/products/PHPsh.php">PHPsh</a> <?php print $PHPshVersion; ?>, Copyright (C) 2005 <a href="http://www.psychogenic.com/">Psychogenic Inc</a>. All Rights Reserved, see
  957. <a href="http://www.psychogenic.com/en/products/PHPsh.php#license">license</a> for details.</p>
  958. </td>
  959. </tr>
  960. </table>
  961. </form>
  962. </body>
  963. </html>
Advertisement
Add Comment
Please, Sign In to add comment