403Webshell
Server IP : 104.21.80.248  /  Your IP : 172.71.28.155
Web Server : Apache/2.4.25 (Win32) OpenSSL/1.0.2j PHP/5.6.30
System : Windows NT WIN-ECQAAA40806 6.2 build 9200 (Windows Server 2012 Standard Edition) i586
User : SYSTEM ( 0)
PHP Version : 5.6.30
Disable Function : NONE
MySQL : ON  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  /Inetpub/www/myoffice/2563/modules_241262/usersch/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /Inetpub/www/myoffice/2563/modules_241262/usersch/login.php
<div align="center">
  <table cellspacing="0" cellpadding="0" width="1000" border="0">
    <tbody>
      <tr>
        <td width="20"><img id="b1_r1_c7" height="15" alt="" 
                  src="images/main/b1_r1_c1.gif" width="20" border="0" /></td>
        <td background="images/main/b1_top_bg.gif" width="500"><img id="b1_r1_c8" 
                  height="15" alt="" src="images/main/b1_top_bg.gif" width="500" 
                  border="0" /></td>
        <td width="19"><img id="b1_r1_c9" height="15" alt="" 
                  src="images/main/b1_r1_c4.gif" width="19" 
              border="0" /></td>
      </tr>
    </tbody>
  </table>
  <table align="center"cellspacing="0" cellpadding="0" width="540" border="0">
    <tbody>
      <tr>
        <td width="10" background="images/main/b1_r2_c1.gif" 
                  height="100%"><img id="b1_r2_c4" height="10" alt="" 
                  src="images/main/b1_r2_c1.gif" width="10" border="0" /></td>
        <td valign="top" width="100%" background="images/main/b1_ct_bg.gif" 
                height="100%"><div align="center">
          <table align="center"cellspacing="0" cellpadding="0" width="98%" border="0">
            <tbody>
              <tr>
                <td><table width="100%"align="center" >
                  <tr>
                    <td><?
//Check Admin
$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
$res[usersch] = $db->select_query("SELECT * FROM ".TB_usersch." WHERE username='".$_POST[username]."' AND password='".md5($_POST[password])."'  "); 
$rows[usersch] = $db->rows($res[usersch]); 
if($rows[usersch]){
	$arr[usersch] = $db->fetch($res[usersch]);
}
$db->closedb ();
if(USE_CAPCHA){
	if($_SESSION['security_code'] != $_POST['security_code'] OR empty($_POST['security_code'])) {
		echo "<script language='javascript'>" ;
		echo "alert('!!!! กรุณากรอกโค๊ดให้ถูกต้อง !!!!')" ;
		echo "</script>" ;
		echo "<script language='javascript'>javascript:history.go(-1)</script>";
		exit();
	}
}

//Can Login
if($arr[usersch][id]){
	//Login ผ่าน
	ob_start();
	$_SESSION['usersch_user'] = $_POST[username] ;
	$_SESSION['usersch_pwd'] = md5($_POST[password]) ;
	$_SESSION['ip'] = $_SERVER['REMOTE_ADDR'];
	session_write_close();
	ob_end_flush();
			$timeoutseconds=10*60;
			$_SESSION['timestamp2']=time();
			$timeout=$_SESSION['timestamp2'] - $timeoutseconds;
//////////////////////		 เพิ่ม  สมาชิกออนไลน์   ////////////////////////////
			$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
			$res[user2] = $db->select_query("SELECT * FROM ".TB_useronline." WHERE useronline='".$_SESSION['usersch_user']."' ");
			$rows[user2] = $db->rows($res[user2]); 
			$db->closedb ();
			
			if($rows[user2]){

				$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
				$db->update_db(TB_useronline,array(
					"post_date"=>"".$_SESSION['timestamp2'].""
//					"useronline"=>"".$_SESSION['user_user'].""
				)," useronline='".$_SESSION['usersch_user']."' ");
				$db->closedb ();
			
			}else{
				$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);	
				$db->add_db(TB_useronline,array(
					"post_date"=>"".$_SESSION['timestamp2']."",
					"useronline"=>"".$_SESSION['usersch_user'].""
			));
			
			}
			
			$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
			$db->del(TB_useronline," post_date<$timeout "); 
			$db->closedb ();


	$db->connectdb(DB_NAME,DB_USERNAME,DB_PASSWORD);
	$q[Pageview] = "UPDATE ".TB_usersch." SET last_date = update_date,pageview = pageview+1,ip = '".$_SESSION['ip'] ."' WHERE username='".$_POST[username]."' ";
	$sql[Pageview] = mysql_query ( $q[Pageview] ) or sql_error ( "db-query",mysql_error() );
	
?>
                      <br />
                      <br />
                      <center>
                        <a href="?name=usersch&amp;file=main"><img src="images/icon/login-welcome.gif" border="0" /></a><br />
                        <br />
                        <font color="#336600"><b>ได้ทำการเข้าระบบเรียบร้อยแล้ว</b></font><br />
                        <br />
                        <a href="indexarea"><b>รอสักครู่กำลังนำคุณเข้าสู่หน้าหลัก</b></a>
					  </center>
                      <br />
                      <br />
                     <meta http-equiv='refresh' content='2 ;url=index.php'> <?
}else{
	//Login ไม่ผ่าน
?>
                      <br />
                      <br />
                      <center>
                        <b><font color="#FF0000">ชื่อผู้ใช้ หรือ รหัสผ่าน ไม่ถูกต้อง กรุณาตรวจสอบ</font></b>
                      </center>
                      <form method="post" action="?name=usersch&amp;file=login">
                        <table width="300" align="center">
                          <tr>
                            <td width="100" align="right"><b>ชื่อผู้ใช้ : </b></td>
                            <td><input type="text" name="username" /></td>
                          </tr>
                          <tr>
                            <td width="100" align="right"><b>รหัสผ่าน : </b></td>
                            <td><input type="password" name="password" /></td>
                          </tr>
                          <?
if(USE_CAPCHA){
?>
                          <tr>
                            <td width="100" align="right"><?if(CAPCHA_TYPE == 1){ 
							echo "<img src=\"capcha/CaptchaSecurityImages.php?width=".CAPCHA_WIDTH."&height=".CAPCHA_HEIGHT."&characters=".CAPCHA_NUM."\" width=\"".CAPCHA_WIDTH."\" height=\"".CAPCHA_HEIGHT."\" align=\"absmiddle\" />";
						}else if(CAPCHA_TYPE == 2){ 
							echo "<img src=\"capcha/val_img.php?width=".CAPCHA_WIDTH."&height=".CAPCHA_HEIGHT."&characters=".CAPCHA_NUM."\" width=\"".CAPCHA_WIDTH."\" height=\"".CAPCHA_HEIGHT."\" align=\"absmiddle\" />";
						};?>
                            </td>
                            <td><input name="security_code" type="text" id="security_code" maxlength="6" /></td>
                          </tr>
                          <?
}
?>
                          <tr>
                            <td width="100" align="right"></td>
                            <td><input type="submit" value=" เข้าระบบ " /></td>
                          </tr>
                        </table>
                      </form>
                      <?
}
?></td>
                  </tr>
                </table></td>
              </tr>
            </tbody>
          </table>
        </div></td>
        <td width="10" background="images/main/b1_r2_c5.gif" 
                  height="100%"><img id="b1_r2_c6" height="10" alt="" 
                  src="images/main/b1_r2_c5.gif" width="10" 
              border="0" /></td>
      </tr>
    </tbody>
  </table>
  <table cellspacing="0" cellpadding="0" width="100%" border="0">
    <tbody>
      <tr>
        <td width="20"><img id="b1_r4_c7" height="15" alt="" 
                  src="images/main/b1_r4_c1.gif" width="20" border="0" /></td>
        <td background="images/main/b1_foot_bg.gif" width="500"><img id="b1_r4_c8" 
                  height="15" alt="" src="images/main/b1_foot_bg.gif" width="500" 
                  border="0" /></td>
        <td width="19"><img id="b1_r4_c9" height="15" alt="" 
                  src="images/main/b1_r4_c4.gif" width="19" 
              border="0" /></td>
      </tr>
    </tbody>
  </table>
</div>
 

Youez - 2016 - github.com/yon3zu
LinuXploit