From: mitty <mitty@7d2118f6-f56c-43e7-95a2-4bb3031d96e7> Date: Tue, 26 Jan 2010 06:48:23 +0000 (+0000) Subject: * add Sn Uploader from http://sugachan.dip.jp/obsolete/snup/ X-Git-Url: http://lab.mitty.jp/git/?a=commitdiff_plain;h=b8bd724add704529a9fa2187e330f4ab304e7d7e;p=lab.git * add Sn Uploader from sugachan.dip.jp/obsolete/snup/ git-svn-id: https://lab.mitty.jp/svn/lab/vendor@29 7d2118f6-f56c-43e7-95a2-4bb3031d96e7 --- diff --git a/SnUploader/snup_051010e.zip b/SnUploader/snup_051010e.zip new file mode 100644 index 0000000..89610de Binary files /dev/null and b/SnUploader/snup_051010e.zip differ diff --git a/SnUploader/snup_051010e/readme.txt b/SnUploader/snup_051010e/readme.txt new file mode 100644 index 0000000..403cdea --- /dev/null +++ b/SnUploader/snup_051010e/readme.txt @@ -0,0 +1,204 @@ +21:05 2005/10/10 +suga@snpn.net + +Sn Uploader + +ÊÌ(½ +Äpt@CAbv[_Å· +v¤æ¤È̪³©Á½ÌÅ +±ÌÛìÁÄÝܵ½ + +XNvg{ÌÍ +/uploader/ NoCGI.pmÅ +/uploader+cgipm/ CGI.pmÅ +ÌfBNgÉi[³êĢܷ + +KÉìÁ½àñÈÌÅ +^CgÌÝèÚÈÇÍ èܹñ +fUCϦ½¢êÍ»êÙÇïµÈ¢Æv¢Ü·ÌÅ +\[X»ÌÜÜ¢ÀÁľ³¢ + +î{IÈ®ìÍCGI.pmÅ/NoCGI.pmŤÉÏíèܹñª +NoCGI.pmÅÌûªptH[}Xªæ¢v¢Ü· +µ¤TCYª ñÜèeʪå«È¢êÍÇ¿çÅà©ÜíÈ¢©Æ +ȨIISÅÍAbv[hÅ«È¢±ÆàÈ¢Æv¢Ü·ª +®ìªsRÉÈéXüª éÌÅoêÎð¯½ûªæ³»¤Å· + +A[JCuÉYt³êÄ¢éXNvgÌ +¿R[hÍShift-JIS/üsR[hÍCRLFÉÈÁĢܷ + +¦ +±ÌXNvgÌì ÍìÒÉA®µÜ·ª +pÒÌÓCɨ¢Ä©RÉüÏ,^p·é±ÆªÅ«Ü· +ܽpµ½±ÆÉæÁĶµ½¹QÉ뵀 +ìÒÍêØÌÓ±ðíÈ¢àÌƵܷ + +////// +Ýuû@ +1. Ýu·éfBNgð쬵ܷ + Ȩ±ÌfBNgÍCGIÀs ÀÅ«ßéæ¤É + @suEXEC«ÈçÎ701 »Ì¼Èç 777Ìæ¤Ép[~bVðÝè·é + suEXEC«Š777ÈÇɵ½êXNvgÉANZX·éÆ 500 Internal Server Error ªoé±Æª èÜ· +2. upload.cgiðGfB^ÅJ«Í¶ßÌûÌp[^ðÝè·é +@ î{IÉÍ$set{'admin_pass'}ÌÏXÆPerlÌPATHÌmF¾¯Å¢¢Æv¢Ü· +3. T[oÉAbv[hµKxÉp[~bVex.(suEXEC:700 other:755)ðÝè·é +4. uEUÅ upload.cgiɼÚANZX·éÆOt@C/fBNgð©®IÉ쬵ܷ + Abv[_ÖÌNÍupload.cgiÅÍÈ upload.html(1y[WÚÌAhX)ɵľ³¢ + upload.cgiÉANZX³ê½êͳÊÉvZXðN®µÄupload.htmlÉ]·é¾¯Å· + + * ßÄANZXµ½ÛÉuCOÌì¬É¸sµÜµ½vÈÇÌ\¦ªo½êÍ + 1.ÌfBNgÌp[~bVÝè𩼵ľ³¢ + + ÆÍKÉÝèƩϦÄÝľ³¢ +Ȩ1y[WÚðindex.htmlÉ·éÆURLª¿åÁÆZÈé©àµêܹñ +Ýuµ½fBNgÉÍindex.htmlð쬵ȢÌÅ + CfbNXXgª\¦³êé«ÌûÍãLÌæ¤ÉÝè·é© + óÌindex.htmlÅàAbv[hµÄ¾³¢ + +suEXECÌ\¬á +-- upload [701] / upload.cgi [700] +@@| log.cgi [600] --- ©®ì¬ +@@| upload.html[604] --- ©®ì¬ + | +@@+-- src [701] --- ©®ì¬ + +»Ì¼êÊIÈ\¬ +-- upload [777] / upload.cgi [755] +@@| log.cgi [666] --- ©®ì¬ +@@| upload.html[666] --- ©®ì¬ + | +@@+-- src [777] --- ©®ì¬ +////// + +t@CÌíû@ + 1.t@CNoÌÉNoðüêÜ· + up0001.jpg -> 1, 0001 , up0001 , up0001.jpg lªoÅ«êÎ(hoge001.pngÅà)OKÅ· + JavaScriptªLøÈê "D" ƾ¤¶ªt@C¼Ì¶¤ÉoÄ«Ü·ÌÅ»êðNbN³êÄà\Å· + 2.íL[ªKvÈÆ«ÍüÍ·é + ÇÒPASSðüêéÆSÄÌt@CªíÂ\Å· + ܽíÌIPAhXªeIPAhXÌæ3INebg(192.168.0.9 Ì 192.168.0.)ÜÅ + êv·éêÍ[U[ÅLIDªêv·éêÉÀÁÄÍíL[ÍKvÅÍ èܹñ + 3.delð· + ,ÇÒÍSUSS(Sn Uploader Support Script)ÉOC·é±ÆÉæèIð/êíªÅ«Ü· + +HTMLðXVµ½¢ê + XNvgüÏ/POSTKeyL³ÅtH[fUCªÏíÁÄXVµ½¢êÍ + ítH[ÉNoðüê¸KeyÌÉÇÒPASS($set{'admin_pass'})ÌlðüêÄdelðµÄ¾³¢ + ÍSUSS(Sn Uploader Support Script)ÉOCµÄìÆðµÄ¾³¢ + +SUSS(Sn Uploader Support Script) + v·éÉÇæÊÅ· ³XÊXNvgŵ½ª³êܵ½ + SUSSÉOC·é½ßÉÍ ítH[Ì DelÉÝèµ½ÇÒOCID + KeyÉÇÒpX[h ðü͵ÄdelðµÜ· + OC·éÆÇÒæÊÉØèÖíè OÌêí/G[O\¦/Ýè\¦ÈÇð©é±ÆªÅ«Ü· + +CookieÉ墀 + ±ÌXNvgÅÍCookieðgpµÄ¢Ü· åÉíâƵÄg¢Ü· + SN_UPLOAD(JavaScript) etH[ÌDelKey/PostKeyðL¯µÜ· + SN_DEL (JavaScript) ítH[ÌKeyðL¯µÜ· lªÈ¢êSN_UPLOADÌDelKeyðRs[µÜ· + SN_USER (HTML_META) [U[ÅLIDðL¯µÜ· + CookieÌÛ¶ÌúÀÆ©ÍÁɧÀµÄ¢È¢ÌÅCÉHíÈ©Á½çYªðC³µÄ¾³¢ + ÇÒÍܸítH[ÉÇÒPASSðüê[del]ðµL¯³¹éÆ + t@CíâSUSSÉüÁ½è·éÛÉ¢ç©yÉÈéÆv¢Ü· + +oOð©Â¯½çc + ¼·ÛØÍ èܹñªf¦ÂÉñà禽çPµ½¢Æv¢Ü· + + ñÜèåµ½±ÆÅÍÈ¢±Æ + HÉÝu³ê½Abv[_É ét@CÌíËÈǪºÌNðHÁÄ + ±¿çÉé±Æª éÌÅ ftHgÅÍȪ³êĢܷª + Å«êÎ $set{'home_url'}([HOME]ÌNæÌl) ÍßÄÙµ¢©àµêܹñ + Ȩ±ÌlÍ ../ â http://example.org/~user/ ÈÇÎpXÅàâÎpXÅà\¢Ü¹ñ + +³çÉåµ½±ÆÅÍÈ¢±Æ + zzA[JCuÌÉ éXNvgt@CÍWIÈGfB^Åà + ÒWµâ·¢æ¤É¶R[hÉShift-JISðgpµÄ¢Ü· + »Ì½ßoOÆ¢¤©Shift-JISÌê̶R[hª\ÆdÈÁÄ¢ée¿Å + t@C¼É"\,\,\,["ÈǪÜÜêÄ¢éÆt@C¼ªrÅØêÜ· + fUCÏXŶðÇÁ}üµ½ê êÉæÁÄÍ500G[ªÅé±Æà èÜ· + ÊÉoCiª»¯½è·éí¯ÅÍÈ¢ÌÅ·ªCÉÈélÍ + GfB^ÅXNvgSÌðEUCÉÏ··é̪梩Æv¢Ü· + ÝèÚÌIíèÌûÉ $set{'html_head'} Æ¢¤Úª éÌÅcharsetð euc-jp É·éÆ + roHTMLÌMETA^OªÍ«·íèÜ· + r©çEUCÉØèÖ¦éÆ«ÍOt@CÌÏ·à¨Yê¸É... + +{Éåµ½±ÆÅÍÈ¢±Æ + ±ÌXNvgÌftHgÅͶ¬·éHTMLÌEºÉzzy[WÖÌNª£ÁÄ èÜ·ª + fUCÌÏXâsãíµ½¢êÍ(à¿ëñcµÄ¸¯êÎðµ¢ÌÅ·ª) + NyÑ\¦ðíµÄ¸¢ÄàêüÉ\¢Ü¹ñ + Aµ±êÍXNvgÌì ðúü·éÆ¢¤±ÆÅÍ èܹñ + + +â« + XNvgàÌà¾ÅXྪ«èÈ¢Æ±ëª é©àµêܹñÌÅ⫵Ĩ«Ü· + +$set{'interval'} + ¯êIP©çÌA±eðwèµ½bÌÔ۵ܷ + ftHgÍ0bÉÈÁĢܷª á¦Î10ªÈçÎ 60*10 Æ\LµÄàâè èܹñ + ȨÅIeÌIP/Ôŵ©»fµÄ¢È¢ÌÅãLÌáÅ·Æ + 10ªÈàɼÌlªAbv[hðµ½êÍð³êĵܢܷ + +$set{'max_all_flag'} + ±ÌlðLøÉ·éÆeÈOÉt@CÌeÊÅàO¿ð»è·éæ¤ÉÈèÜ· + ^T[oÈÇeʪÀçêÄ¢éêðɧÂÌÅÍȢŵ天H + ÓƵÄÍ á¦Î 1t@CÌÅåeʪ10MB($set{'max_size'} = 10*1024), + eÊ50MB($set{'max_all_size'}= 50*1024) ÉÝèµ½ê + T[oÉùÉ50MB éóÔÅ 10MBÌt@CðAbv[h³êéÆ + êIÉ 50MB+10MB = 60MB ªÁï³êÜ· ܽ¡¯Abv[hÉà¯ḻƪ¾¦Ü·ÌÅ + µ]TðÁÄ(T[o§ÀÊæèÍÈßÉ)Ýèµ½Ù¤ªæ³»¤Å· + ܽۧÀ໤ŷª p[~bVÝè,ANZX ÈÇÌÖWÅ + t@CªíÅ«È©Á½êÍ(t@CªÀÛÉcÁÄ¢éÌÅ)CO©çÍíµÄ¢Ü¹ñ + æÁÄÝèO/eÊæèÀÛÌO/eʪ½Èé±Æª èÜ· + +$set{'up_all'} + ±ÌlðLøÉ·éÆ$set{'up_ext'}Éo^³êÄ¢éàÌÈOÅàAbv[hðó¯t¯Ü· + $set{'ext_org'}ª³øÉÈÁÄ¢éê(=0)Íg£q'.bin'Åo^³êÜ· + $set{'ext_org'}ªLøÉÈÁÄ¢éê(=1)ÍeÌg£qÉÈèÜ· + $set{'ext_org'}ðLøÉ·éê(=1)Í + XNvg¾êÈÇ\ú¹Ê®ìð·éêª èÜ·ÌÅ + ZL eB[ÉÍ\ªCð¯ĺ³¢ + +$set{'find_crypt'} + ±ÌlªLøÉÈÁÄ¢éÆAbv[h³ê½A[JCuªÃ»³êĢ驲×Ü·(ZIPÌÝ) + û³êÄ¢éêÍCOMMENTÌÅÉÔÌ"*"ªt«Ü· + åÌooÄéi ÆvíêéêÉÍroHTMLÌDZ©É*ÍPASSt¾ ƢĨ¯Î + _E[h·é¤Éà½Íbg!?ª é©ÈÆv¢Ü· + +$set{'binary_compare'} + ±ÌlªLøÉÈÁÄ¢éÆùÉAbv[h³êÄ¢ét@CÆoCiärðµÜ· + êvµ½çt@CðAbv[h³¹Ü¹ñ + +$set{'post_key'} + $set{'post_flag'}ªLøÉÈÁÄ¢éê(=1)ͱÌlðtH[ÉüÍµÈ¢Æ + Abv[hÅ«ÈÈèÜ· PostKeyÍ,ÅæØé±ÆÅ¡s·é±ÆªÅ« + COÉÍõlƵÄe³ê½ÛÌPostKeyªL^³êÜ· + r©çPostKeyðLøÉ·éêÍetH[ÉPostKeyÌÚª èܹñÌÅ + XNvgðÝèµ½çãLÌuHTMLðXVµ½¢êvðQlÉHTMLðXVµÄ¾³¢ + +$set{'dlkey'} + DLKeyÌgpÌL³ + Abv[h³ê½t@Cð ./src/up****.*** ©ç ./src/up****.***_[a-zA-Z0-9]{20}/up****.*** + Él[·é±ÆÉæÁÄ쬳êét@CXgÌNæèHêȵܷ + ÀURLÍeÝèµ½DLKeyÉÄFØ·é±ÆÉæÁÄQÆÅ«Ü· + perlð³ÊÉN®µ½È¢êÍ $set{'dummy_html'} Ìlð 2ÈãÉ·éÆA + FØÌHTMLðÃIHTMLÅf«o·æ¤ÉÈèÜ·B + ³ÊÈCGIÌN®ª¸èÜ·ÌÅâèªÈ¯êÎÃIHTMLðf«o·æ¤É·é±Æð¨©ßµÜ·B + +$set{'zero_clear'} + FTPÈÇCGIÈO©çÌìÅt@Cðíµ½ê + COÉÍîñªcÁÄ¢éªNæÌt@CªÈ¢Æ¢¤±Æª èÜ· + ±ÌlªLøÈêñt@CAbv[hÉYt@CîñðCO©çíµÜ· + LøɵȩÁ½êÍñXV©çà0oCgÌt@CƵÄHTMLt@CXgÉLÚ³êÜ· + +$set{'http_src_path'} + HÉt@CXgÌNÉÎPATHðg¦È¢P[Xª èÜ·ÌÅ + »Ìæ¤ÈêͱÌlðÝè·éÉæÁľ¦IÉt@CÌÊuðwèÅ«Ü· + ®wèµ½êÍ t@CÛ¶fBNg $set{'src_dir'} ÉÍ + /home/user/public_html/upload/src/ ÈÇÌT[oàâÎPATHðgp·é±ÆàÅ«Ü· + ÎPATH(ftHg)ÅâèÈ¢êÍÁÉÝèµÈÄ\¢Ü¹ñ + +$set{'link_target'} + t@C¼É£çêÄ¢éNÌtarget®«Å· + VKÌEBhEÅJ«½¢êÍ _blank Æü͵ܷ + +Sn Uploader (c) 2003-2005 SUGA All rights reserved. diff --git a/SnUploader/snup_051010e/snfaq.txt b/SnUploader/snup_051010e/snfaq.txt new file mode 100644 index 0000000..2485d4c --- /dev/null +++ b/SnUploader/snup_051010e/snfaq.txt @@ -0,0 +1,180 @@ +21:34 2005/10/10 + +KÈ Sn Uploader FAQ + +Q1. ±êͽŷ©H +Q2. PerlÅ·©HPHPÅ·©H +Q3. Ýuūܹñ(®«Ü¹ñ,500G[ªÅé) +Q4. NoCGI.pmÅÆCGI.pmÅÇÁ¿g¦Î¢¢ñÅ·©H +Q5. ÝèÌ 0Æ© 1Æ© ÁĽŷ©H +Q6. t[ðgÁÄ¢éy[WÈÌÅNðNbNµ½çVµ¢EBhEÅJ«½¢ +Q7. ÝèÍftHgÌÜܶ᢯ȢÌH +Q8. [U©çkeyÍ ÁÄé(͸È)ÌÉt@Cªíūܹñƾíêé +Q9. G[bZ[WªS\¦³êܹñ +Q10. NoCGI.pmÅÅG[bZ[WÉPOSTf[^s®SÆåÊÉcÁĢܷ +Q11. Ç[hÉüé̪Ê|Å· +Q12. Ô¢"*"ÁĽH +Q13. POSTKey¡ÝèÅ«éÁĽÌÓ¡ª éñÅ·©H +Q14. íKeyðYêĵܢܵ½ítH[Éà©®üͳêÄܹñ +Q15. [Upload][Cancel]Ì[Upload]ªÁ¦¿á¢Üµ½ +Q16. IISÅÍ®©È¢ÌH +Q17. ANHTTPD,BlackJumboDogÅ஫ܷ©H +Q18. ^CgÌ"Uploader" â "Now.. Testing.." Æ\¦³êÄ¢éªð«·¦½¢ +Q19. XgÌÔªeÔÅÍ èܹñªÈºÅµå¤©H +Q20. Ýuµ½çT[oªdÈèܵ½ ½©üP·éû@Í èÜ·©H +Q21. ÅåeeÊÍÇêç¢ÜÅ¢¯Ü·©H +Q22. eʧÀª éT[oÅÍÇÌæ¤ÈÝèª]ܵ¢Ìŵ天H +Q23. g£qMP4(å¶)ðÇÁµ½ÌÅ·ªF¯³êܹñ +Q24. g£qMP4(å¶)ðAbv[h·éƬ¶ÉÈÁĵܤ + +/////////////////////////////////////////////// + +Q1. ±êͽŷ©H +A1. Äpt@CAbv[_Å· + CyÉuEU©çT[oÉt@CðAbv[h·é±ÆªÅ«Ü· + +Q2. PerlÅ·©HPHPÅ·©H +A2. PerlXNvgÅ· Perl5Èç®Æv¢Ü· PHPXNvgÅÍ èܹñ + +Q3. Ýuūܹñ(®«Ü¹ñ,500G[ªÅé) +A3. ùɼÌCGIvOðÝuµÄ¢éêÍ»ÌÝèðQlɵÄÝľ³¢ + åÉPerlÌPATHªá¤êâsuexecÈÌÉÝufBNgÌp[~bVª777ÈÇÌꪽ¢æ¤Å· + ܽOt@Cât@CÛ¶fBNgÍñANZXÉ©®¶¬µÜ·ÌÅ + FTPìÈÇÅÍìçÈ¢ûª½Å· + +Q4. NoCGI.pmÅÆCGI.pmÅÇÁ¿g¦Î¢¢ñÅ·©H +A4. ÇÁ¿Åà\¢Ü¹ñª NoCGI.pmÅÌûªAbv[hª½¬¢Ý½¢Å· + +Q5. ÝèÌ 0Æ© 1Æ© ÁĽŷ©H +A5. î{IÉON©OFFÅÝè·éàÌÍ ON=1,OFF=0 Żʵܷ + +Q6. t[ðgÁÄ¢éy[WÈÌÅNðNbNµ½çVµ¢EBhEÅJ«½¢ +A6. $set{'link_target'} ÌlÉ _blank ðÝèµÄ¾³¢ + +Q7. ÝèÍftHgÌÜܶ᢯ȢÌH +A7. î{IÉÍÇÒPASSÌÏX¾¯Å\íÈ¢Æv¢Ü· + ÝèÌdvxÍ(ÂlIÉÍ)ãÌ ºÌûÍêÌûªg¤æ¤È´¶¾Æv¢Ü· + +Q8. [U©çkeyÍ ÁÄé(͸È)ÌÉt@Cªíūܹñƾíêé +A8. íðª ÁÄÈ¢Æv¢Ü· (L[M)m~~ + ÀÛâÁÄÝÄÁ¦È©Á½çA¾³¢ + 031003È~ÉÍÂÊCookieÅÌ»èªÇÁ³êÄÜ· + +Q9. G[bZ[WªS\¦³êܹñ +A9. 031003ÈOÌàÌÍdlÅ·...031003È~ÉÍG[\¦@\ªÂ¢Ä¢Ü· + +Q10.NoCGI.pmÅÅG[bZ[WÉPOSTf[^s®SÆåÊÉcÁĢܷ +A10.Abv[hÉuEU[Ì~ÈÇð·Æ»¤L^³êÜ· + POSTf[^s®S = [U[Abv[h~ Æl¦ÄàçÁÄ\¢Ü¹ñ + ¿ÈÝÉNoCGI.pmŪAbv[h~Xª½¢Æ¾¤í¯ÅÍ èܹñ + CGI.pmÅÍfR[hû@ªá¢Ü·ÌűÌèÌo[`ª³¢¾¯Å· + ¼ÌAbv[_ÉÍÈ¢(L^·éxÅÍÈ¢)G[bZ[WÌÞÈÌÅ + ¢çÈ¢Æv¦Îq¶ãOÉL^µÈ¢æ¤Éµ½Ù¤ª¢¢©àµÜ¹ñ +> 1004žÆXNvgJ¢Ä POSTf[^s®S Åõ·éÆÅãÌûÉ +> elsif($no == 108){ $flag = 1; $message = "POSTf[^s®S" ` +> Æ èÜ·ÌÅ@±±ð +> # elsif($no == 108){ $flag = 1; $message = "POSTf[^s®S" ` +> Æ æªÉ # ðÇÁ·éÆ +> G[bZ[WÉÍL^µÈÈèÜ·B + +Q11.Ç[hÉüé̪Ê|Å· +A11.ÇlÍܸítH[ÉÇlPASSðo¦³¹Ä¾³¢ + Cookie&JavaScriptªg¦éêÍ ©çÍtH[ÉPASSª©®üͳêÜ·ÌÅ + ðüêéÆt@Cí,Ç[UIDüêéÆÇæÊÉüêÜ· + +Q12.Ô¢"*"ÁĽH +A12.KÈÆ©ÀÉæéûZIPoÌ}[LOÅ· + ൩µ½çë»ÊµÄéêà é©àµêܹñ + +Q13.POSTKey¡ÝèÅ«éÁĽÌÓ¡ª éñÅ·©H +A13.ÂlÉs·éÆNª °Ä驪©é©àµêܹñ + FTPÌAJEgIDÆPASSð1lɳ¦½çêãÉÍ + Ⱥ©»ÌAJEgIDÆPASSÅ¡NCAgªqªÁĽƢ¤ + bðm袩緢½ÌÅÇÌPOSTKeyÅAbv[hµÄé© + L^µÄÝéÆÊ¢©ÈÆ¡ÝèÅ«éæ¤ÉµÄÝܵ½ + +Q14.íKeyðYêĵܢܵ½ítH[Éà©®üͳêÄܹñ +A14.etH[É©®üͪcÁÄ¢éêÉÀÁÄÍ + 1.ítH[ÌNo,key¤É¢ê¸É[del]ð·(íCookieNA) + 2.etH[Ì[Upload]ð·(íCookieRs[) + ãLìÅetH[ÌDelKeyªRs[³êénYÅ· + +Q15.[Upload][Cancel]Ì[Upload]ªÁ¦¿á¢Üµ½ +A15.¶R[hðEUCɵæ¤Æµ½ÌÅÍȢŵ天H + $set{'charset'} = euc-jp; ɵÄà ¶R[hªSHIFT-JISÌÜÜÌê + »Ìæ¤É\¦³êé±Æª èÜ· + GfB^âFTP]ÅXNvg̶R[hàEUCÉÏ·µÄ¾³¢ + +Q16.IISÅÍ®©È¢ÌH +A16.S®©È¢±ÆàȢŷª±¿çÌmFµ½ÀèÅÍ®ìÉsRÈ_ª é½ß¨©ßµÜ¹ñ + ÁèÌìð·éÆvZXªIíçÈÈèCPUgp¦ª100%ÌÜÜÉÈèÜ· +@@»ÌlÈP[XÉ×Á½êÍ [WebTCgÌvpeB] ©çAvP[VÌ [A[h] ðµÄ¾³¢ + 2003/10/11»Ý ±¿çÅÌêÊèÌ®ìðmFµ½Â«Í CGI.pmÅ/NoCGI.pmÅ¤É + @ WinXPPro (Perl5.8.0) -> Apache1.3.28/2.0.47 ANHTTPD1.42k BlackJumboDog3.3.5 + Redhat6.2 (Perl5.6.1) -> Apache1.3.27 + @ FreeBSD4.8R(Perl5.005_3) -> Apache1.3.27/2.0.47 + Solaris8 (Perl5.6.1) -> Apache1.3.27 + ÆÈÁĢܷ(¢¸êài386,RedhatÆFreeBSDÍsuEXEC) + ©êΪ©éæ¤É±¿çƵÄÍî{IÉhttpdÉÍApache§Å· + +Q17.ANHTTPD,BlackJumboDogÅ஫ܷ©H +A17.NoCGI.pmÅ/CGI.pmŤÉâèÈ®Æv¢Ü·ª + ptH[}XÌÊÅ©éÆ Apache + NoCGI.pmÅ ªæ³»¤Å· + +Q18.^CgÌ"Uploader" â "Now.. Testing.." Æ\¦³êÄ¢éªð«·¦½¢ +A18.ùÉ é¶ð«·¦éöxÈçXNvgàðY¶ÅõµÄu«·¦Ä¾³¢ + HTMLwb_ÈÇÍ\qAhL gÅ¢Ä骪½¢ÌÅ + HTML^OÌm¯ª êÎärIÈPÉ«·¦çêéÆv¢Ü· + +Q19.XgÌÔªeÔÅÍ èܹñªÈºÅµå¤©H +A19.XgÉ\¦³êéeÔÍ POSTJn ÌÔÅ· + OªXV³êéÌÍ POST®¹ã ÈÌÅOÌÔ\LÌÔª½üêÖíé±Æª èÜ· + ÂlIÉÍPOSTðnß½ÔðeÔƵ½¢ÌűÌæ¤ÈdlÉÈÁĢܷ + # Æ¢¤©]èCɵÄܹñŵ½ + ǤµÄàXgàÔɵ½¢Æ¢¤ÌÈçÎDATEð POST®¹ã ÌÔÉ·êÎ梩Æv¢Ü· +> $new[0] Åõð©¯éÆ +> $new[0] = "$no<>$in{'addr'}<>$in{'time'}<>1\n"; +> Æ¢¤sª èÜ·ÌÅ »ÌsÌãÉÅà +> $in{'date'} = conv_date(time()); +> Æ¢¤sð«·Æ DATE ÉL^³êéÔÍ POST®¹ã ÌÔÆÈèÜ· +> # $in{'date'} = conv_date(time()); ÆùÉ©êÄ¢ésª éàÌðgÁÄ¢éÌÈçÎ +> æªÌ # ðí·é¾¯Å\Å· + +Q20.Ýuµ½çT[oªdÈèܵ½ ½©üP·éû@Í èÜ·©H +A20.(;LDM) ñܳµÈ¢Å¾³¢ + ÊÌf¦ÂÉä×éÆf[^Ìoüͪ½síêéÌÅ + ñü/CPU×ÍßÉÈéP[Xª½¢Æv¢Ü· + pÒlâÛ¶/t@CTCYÈÇðl¶µÄgÁÄ¢½¾¯êÎ梩Æv¢Ü· + +Q21.ÅåeeÊÍÇêç¢ÜÅ¢¯Ü·©H +A21.A1É¢½æ¤ÈÊuï¾ÆvÁĢܷÌųÈÝè/g¢û͵Ȣûªæ¢©Æ + ê100MbpsLAN«(A16ÌApache«/Client-Win2000ProIE6)ÅÍ1GBöxÜÅmFµÜµ½ª + T[o«ENCAg«Eñüi¿â»Ì¼gp«É˶µÜ·µ + ܽÂ\ÆÀpÍá¢Ü·ÌÅ éöxÌ^pðÁÄÝuÒ©gª»fµÄ¾³¢ + Aµ ÜèÉå«¢TCYÌt@CÍFTPÈÇÊvgRÅâèæèµ½Ù¤ªæ³»¤Å· + +Q22.eʧÀª éT[oÅÍÇÌæ¤ÈÝèª]ܵ¢Ìŵ天H +A22._IÉÍ©ÈèÌ]Tð½¹½Ýèð·é̪³ïÅ· + Æ¢¤Ìà ±ÌXNvgÅÍ 1t@C ½èÌeÊ, ÛO(t@C), eÊ + ðÝèÅ«Ü·ªeʧÀª éT[oɨ¢ÄͱêçÌÝèÉÓ·é_ª èÜ· + [Abv[h] ---> [O/eÊ`FbN] ---> [O¿ªÍí] + Æ¢¤ÅXNvgÍðµÄ¢éÌÅ á¦Î50MB̧Àª|¯çêÄ¢éAJEgÅ + 1t@C ½èÌÅåeÊð 50MB ÉÝè·éÆ 1t@CÚÉ50MBðAbv[hµ½ê + ÛOª1 Åà 2t@CÚðAbv[hÅ«ÈÈÁĵܤ±Æª èÜ· + ±êÍ Abv[h®¹ÜÅÉ 1t@CÚªcÁÄ¢é±Æª´öÆÈèÜ· + 2t@CÚÌAbv[hJnƯÉ1ÂÚðÁ¹Îâ誳ÈélÉ੦ܷª + Abv[h®¹ÜŻꪳíÉIíé©Ç¤©Íª©èܹñ + µ©µÈªç»ÌlÈdlɵ½¢êÍXNvgð éöxüÏ·é±ÆÅÂ\ÉÈèÜ· + ܽ¡[U[©ç̯(Àñ)Abv[hà¯lÈÌÅpxª½¢æ¤Èç + N©ªAbv[hÉÍAbv[h³¹È¢æ¤É·éÈÇÌHvðµ½ûªÇ¢©àµêܹñ + +Q23.g£qMP4(å¶)ðÇÁµ½ÌÅ·ªF¯³êܹñ +Q24.g£qMP4ðAbv[h·éƬ¶ÉÈÁĵܤ +A23.A24 g£qtB^[ÌÌÖWÅ + $set{'up_ext'} É MP4 ðÇÁ·éÌÝÅÍF¯³êܹñ + ±êͳt@C¼g£qðêU¬¶ÉÏ·µ½ãÉ + g£qÏ·ð|¯Ä¢é±ÆÉöèÜ·. + ȺÌû@Åñð·é±ÆªÅ«Ü· + $set{'up_ext'} Abv[hÅ«éî{g£q É MP4 ðÇÁ + $set{'change_ext'} g£qÏ· É@mp4->MP4 ðÇÁ +/////////////////////////////////////////////// diff --git a/SnUploader/snup_051010e/uploader+cgipm/upload.cgi b/SnUploader/snup_051010e/uploader+cgipm/upload.cgi new file mode 100644 index 0000000..15bec93 --- /dev/null +++ b/SnUploader/snup_051010e/uploader+cgipm/upload.cgi @@ -0,0 +1,1008 @@ +#!/usr/bin/perl +use CGI; +use vars qw(%set %in); +use strict; +$set{'log_file'} = './log.cgi'; #Ot@C¼ +$set{'max_log'} = 30; #Û +$set{'max_size'} = 1*1024; #ÅåeeÊ(KB) +$set{'min_flag'} = 0; #ŬeʧÀðgp·é=1 +$set{'min_size'} = 100; #ŬeeÊ(KB) +$set{'max_all_flag'} = 0; #eʧÀðgp·é=1 +$set{'max_all_size'} = 20*1024; #§ÀeÊ(KB) +$set{'file_pre'} = 'up'; #t@CÚª« +$set{'pagelog'} = 10; #1y[WÉ\¦·ét@C +$set{'base_html'} = 'upload.html'; #1y[WÚÌt@C¼ +$set{'interval'} = 0; #¯êIPeÔub +$set{'deny_host'} = ''; #eÖ~IP/HOST ,ÅæØé ex.(bbtec.net,219.119.66,ac.jp) +$set{'admin_name'} = 'admin'; #ÇÒOCID +$set{'admin_pass'} = '1234'; #ÇÒpX[h + +# Ⱥ5ÚðÄÝè·éÛÉÍPATHCfBNgÍ / ÅIíé±Æ +# $set{'html_dir'},$set{'base_cgi'}ð ./ ÈOÉÝè·éê, +# ܽÍDLkeyðgpµ Ȩ©ÂHTMLLbV ($set{'dummy_html'} = 2 or 3)ðgp·éêÍ +# $set{'base_cgi'} , $set{'http_html_path'} , $set{'http_src_path'} ðtpX(http://`` or /``)ÅLq·é +$set{'html_dir'} = './'; # àHTMLÛ¶fBNg +$set{'src_dir'} = './src/'; # àt@CÛ¶fBNg +$set{'base_cgi'} = './upload.cgi'; # ±ÌXNvg¼ http://`ÌwèÂ\ +$set{'http_html_path'} = './'; # htmlQÆ httpPATH http://`ÌwèÂ\ +$set{'http_src_path'} = './src/'; # fileQÆ httpPATH http://`ÌwèÂ\ + +$set{'dlkey'} = 0; # DLKeyðgp·é=1,DLkeyK{=2 +$set{'up_ext'} = 'txt,lzh,zip,rar,gca,mpg,mp3,avi,swf,bmp,jpg,gif,png'; #Abv[hÅ«éî{g£q ¼pp¬¶ ,ÅæØé +$set{'up_all'} = 0; #o^ÈOÌàÌàUP³¹çêéæ¤É·é=1 +$set{'ext_org'} = 0; #$set{'up_all'}ª1ÌIWiÌg£qÉ·é=1 +$set{'deny_ext'} = 'php,php3,phtml,rb,sh,bat,dll'; #eÖ~Ìg£q ¼pp¬¶ ,ÅæØé +$set{'change_ext'} = 'cgi->txt,pl->txt,log->txt,jpeg->jpg,mpeg->mpg'; #g£qÏ· O->ã ¼pp¬¶ ,ÅæØé + +$set{'home_url'} = ''; #[HOME]ÌNæ ÎpXÍ http://©çnÜéâÎpX +$set{'html_all'} = 1; #[ALL]ðo·=1 +$set{'dummy_html'} = 0; #t@CÂÊHTMLð쬷é Êít@CÌÝ=1,DLKeyÝèt@CÌÝ=2,·×Ä=3 +$set{'find_crypt'} = 1; #ûZIPðo·é=1 +$set{'binary_compare'} = 0; #ù¶t@CÆoCiär·é=1 +$set{'post_flag'} = 0; #PostKeyðgp·é=1 +$set{'post_key'} = 'postkey'; #PostKey ,ÅæØéÆ¡wè ex.(postkey1,postkey2) +$set{'disp_error'} = 1; #[U[ÉG[ð\¦·é=1 +$set{'error_level'} = 1; #G[OðL^·é=1 +$set{'error_log'} = './error.cgi'; #G[Ot@C¼ +$set{'error_size'} = 1024; # G[OÅåeÊ(KB) §Àȵ=0 +$set{'zero_clear'} = 1; #t@Cª©Â©çÈ¢êO©çí·é=1 + +$set{'disp_comment'} = 1; #Rgð\¦·é=1 +$set{'disp_date'} = 1; #útð\¦·é=1 +$set{'disp_size'} = 1; #TCYð\¦·é=1 +$set{'disp_mime'} = 1; #MIMETYPEð\¦·é=1 +$set{'disp_orgname'} = 1; #IWit@C¼ð\¦·é=1 + +$set{'per_upfile'} = 0666; #Abv[ht@CÌp[~bV suexec=0604,other=0666 +$set{'per_dir'} = 0777; #\[XAbvfBNgÌp[~bV suexec=0701,other=0777 +$set{'per_logfile'} = 0666; #Ot@CÌp[~bV@suexec=0600,other=0666 +$set{'link_target'} = ''; #target®« + +#------ +$set{'ver'} = '2005/10/10e CGI.pm'; +$set{'char_delname'} = 'D'; + +$in{'time'} = time(); $in{'date'} = conv_date($in{'time'}); +$in{'addr'} = $ENV{'REMOTE_ADDR'}; +$in{'host'} = gethostbyaddr(pack('C4',split(/\./, $in{'addr'})), 2) || $ENV{'REMOTE_HOST'} || '(none)'; +if($in{'addr'} eq $in{'host'}){ $in{'host'} = '(none)'; } + +$set{'html_head'} =<<"EOM"; +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> +<html lang="ja"> +<HEAD> +<META name="robots" content="noindex,nofollow"> +<META name="ROBOTS" content="NOINDEX,NOFOLLOW"> +<META http-equiv="Content-type" content="text/html; charset=Shift_JIS"> +<META http-equiv="Pragma" content="no-cache"> +<META http-equiv="Cache-Control" content="no-cache"> +<META http-equiv="Expires" content="0"> +<TITLE>Uploader</TITLE> +EOM + +$set{'html_css'} =<<"EOM"; +<META http-equiv="Content-Style-Type" content="text/css"> +<STYLE type="text/css"><!-- +input,td{ font-size: 10pt;font-family:Chicago,Verdana,Arial,sans-serif,"lr oSVbN"; } +a:hover { background-color:#EECCCC; } +input,textarea{ border-top : 1px solid ; border-bottom : 1px solid ; border-left : 1px solid ; border-right : 1px solid ;font-size:10pt;background-color:#FFFFFF; } +--> +</STYLE> +EOM + +unless(-e $set{'log_file'}){ &init; } +unless(-e $set{'base_html'}){ &makehtml; } + +{ #fR[h + if ($ENV{'REQUEST_METHOD'} eq "POST" && $ENV{'CONTENT_TYPE'} =~ /multipart\/form-data/i){ + if ($ENV{'CONTENT_LENGTH'} > ($set{'max_size'} * 1024 + 1024)){ if($ENV{'SERVER_SOFTWARE'} =~ /IIS/){ while(read(STDIN,my $buff,8192)){} } &error(106,$ENV{'CONTENT_LENGTH'});} + }else{ + if ($ENV{'CONTENT_LENGTH'} > 1024*100){ error(98); } + } + my %ck; foreach(split(/;/,$ENV{'HTTP_COOKIE'})){ my($key,$val) = split(/=/); $key =~ s/\s//g; $ck{$key} = $val;} + my @ck = split(/<>/,$ck{'SN_USER'}); + if(length($ck[0]) < 5){ + my @salt = ('a'..'z', 'A'..'Z', '0'..'9', '.', '/'); srand; + my $salt = $salt[int(rand(@salt))] . $salt[int(rand(@salt))]; + $in{'user'} = crypt($in{'addr'}.$in{'time'}, $salt); + }else{ $in{'user'} = $ck[0]; } + + my $q = new CGI; + $in{'upfile'} = $q->param('upfile'); + $in{'tmpfile'} = $q->tmpFileName($in{'upfile'}); + $in{'type'} = $q->uploadInfo($in{'upfile'})->{'Content-Type'} if ($in{'upfile'}); + $in{'pass'} = $q->param('pass'); $in{'mode'} = $q->param('mode'); + $in{'delno'} = $q->param('delno'); $in{'comment'} = $q->param('comment'); + $in{'jcode'} = $q->param('jcode'); $in{'delpass'} = $q->param('delpass'); + $in{'orgname'} = $in{'upfile'}; $in{'postkey'} = $q->param('postkey'); + $in{'org_pass'} = $in{'pass'}; + $in{'checkmode'} = $q->param('checkmode'); + $in{'file'} = $q->param('file'); $in{'dlkey'} = $q->param('dlkey'); + $in{'admin_delno'} = join(',',$q->param('admin_delno')); + my @denyhost = split(/,/,$set{'deny_host'}); + foreach my $value (@denyhost){ + if ($in{'addr'} =~ /$value/ || $in{'host'} =~ /$value/){ &error(101);} + } + + my @form = ($in{'comment'},$in{'orgname'},$in{'type'},$in{'dlkey'}); + foreach my $value (@form) { + if (length($value) > 128) { $value = substr($value,0,128).'...'; } +# $value =~ s/&/&/g; + $value =~ s/"/"/g; + $value =~ s/</</g; + $value =~ s/>/>/g; + $value =~ s/\r//g; + $value =~ s/\n//g; + $value =~ s/\t//g; + $value =~ s/\0//g; + } + ($in{'comment'},$in{'orgname'},$in{'type'},$in{'dlkey'}) = @form; + $in{'tmpfile2'} = &filewrite() if ($in{'upfile'}); +} + +if($in{'delno'} eq $set{'admin_name'} && $in{'delpass'} eq $set{'admin_pass'}){ &admin_mode(); } +if(!$in{'delno'} && $in{'delpass'} eq $set{'admin_pass'}){ &makehtml(); &quit(); } +if($in{'mode'} eq 'dl'){ &dlfile;} #DL +if($in{'mode'} eq 'delete'){ &delete(); &quit(); } + +{#C + if(!$in{'upfile'}){ &error(99); } + if($set{'post_flag'} && !check_postkey($in{'postkey'})){ error(109); } + if($set{'dlkey'} == 2 && !$in{'dlkey'}){ unlink("$in{'tmpfile2'}"); &error(61); } + open(IN,$set{'log_file'})||&error(303); + my @log = <IN>; + close(IN); + my ($no,$lastip,$lasttime) = split(/<>/,$log[0]); + + if($set{'interval'} && $set{'interval'} && $in{'time'} <= ($lasttime + $set{'interval'}) && $in{'addr'} eq $lastip){ &error(203);} + $in{'ext'} = extfind($in{'orgname'}); if(!$in{'ext'} && $in{'upfile'}){ &error(202); } + + my $orgname; + if(split(/\//,$in{'orgname'}) > split(/\\/,$in{'orgname'})){ my @name = split(/\//,$in{'orgname'}); $orgname = $name[$#name]; } + else{ my @name = split(/\\/,$in{'orgname'}); $orgname = $name[$#name];} + + my @salt = ('a'..'z', 'A'..'Z', '0'..'9', '.', '/'); + srand; + my $salt = $salt[int(rand(@salt))] . $salt[int(rand(@salt))]; + $in{'pass'} = crypt($in{'pass'}, $salt); + + if($set{'binary_compare'}){ + my @files = globfile("$set{'src_dir'}",".*"); + my @dir = globdir("$set{'src_dir'}",".*"); + foreach my $dir (@dir){ push(@files,globfile($dir."/",".*")); } + foreach my $value (@files){ + next if($value =~ /\.temporary$/); + if(binarycmp($in{'tmpfile2'},$value)){ unlink($in{'tmpfile2'}); &error(205,$value);} + } + } + + if($set{'find_crypt'}){ + open(FILE,$in{'tmpfile'}); binmode(FILE); seek(FILE,0,0); read(FILE,my $buff,4); my $crypt_flag = 0; + if($buff =~ /^\x50\x4b\x03\x04$/){ seek(FILE,6,0); read(FILE,my $buff,1); $crypt_flag = 1 if(($buff & "\x01") eq "\x01"); } + close(FILE); + $in{'comment'} = '<font color="#FF0000">*</font>'.$in{'comment'} if($crypt_flag); + } + + open(IN,$set{'log_file'})||&error(303); + @log = <IN>; + close(IN); + ($no,$lastip,$lasttime) = split(/<>/,$log[0]); + shift(@log); + $no++; + my $tmpno = sprintf("%04d",$no); + + my $dlsalt; + my $filedir; + my $allsize = (-s $in{'tmpfile2'}); + + if($set{'dlkey'} && $in{'dlkey'}){ + my @salt = ('a'..'z', 'A'..'Z', '0'..'9'); srand; + for (my $c = 1; $c <= 20; ++$c) { $dlsalt .= $salt[int(rand(@salt))]; } + $filedir = "$set{'src_dir'}$set{'file_pre'}${tmpno}.$in{'ext'}_$dlsalt/"; + mkdir($filedir,$set{'per_dir'}); + rename("$in{'tmpfile2'}","$filedir$set{'file_pre'}$tmpno.$in{'ext'}"); + open(OUT,">${filedir}index.html"); + close(OUT); + chmod($set{'per_upfile'},"${filedir}index.html"); + $in{'comment'} = '<font color="#FF0000">[DLKey] </font>'.$in{'comment'}; + }else{ + undef $in{'dlkey'}; + rename("$in{'tmpfile2'}","$set{'src_dir'}$set{'file_pre'}$tmpno.$in{'ext'}"); + } + + if (length($orgname) > 128) { $orgname = substr($orgname,0,128).'...'; } + + my @note; + if($set{'post_flag'} && $set{'post_key'}){ + push(@note,'PostKey:'.$in{'postkey'}); + } + if($ENV{'SERVER_SOFTWARE'} =~ /Apache|IIS/){ + my $disptime; + my $time = time() - $in{'time'}; + my @str = ('Upload:','b'); + my $disptime = $time.$str[1]; + push(@note,$str[0].$disptime); + } + if($in{'dlkey'}){ + my @salt = ('a'..'z', 'A'..'Z', '0'..'9', '.', '/'); srand; + my $salt = $salt[int(rand(@salt))] . $salt[int(rand(@salt))]; + my $crypt_dlkey = crypt($in{'dlkey'}, $salt); + push(@note,"DLKey<!-- DLKey:".$crypt_dlkey." --><!-- DLpath:".$dlsalt." -->"); + } + my $note = join(',',@note); + my $usersalt = substr($in{'user'},0,2); + my $userid = crypt($in{'user'},$usersalt); + $in{'time'} = time(); +# $in{'date'} = conv_date(time()); + my @new; + $new[0] = "$no<>$in{'addr'}<>$in{'time'}<>1\n"; + my $addlog = "$no<>$in{'ext'}<>$in{'date'}<>$in{'comment'}<>$in{'type'}<>$orgname<>$in{'addr'}<>$in{'host'}<>$in{'pass'},$userid<>$set{'file_pre'}<>$note<>1\n"; + $new[1] = $addlog; + +# open(OUT,">>./alllog.cgi"); print OUT $addlog; close(OUT); + + my $i = 2; + + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$value); + if(!$dummy){ $filepre = $set{'file_pre'};} + $no = sprintf("%04d",$no); + + my $filename; + my $filedir; + if($note =~ /DLpath:(.+)\s/){ + my $dlpath = $1; + $filename = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/$filepre$no.$ext"; + $filedir = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/"; + }else{ + $filename = "$set{'src_dir'}$filepre$no.$ext"; + } + $allsize += (-s $filename); + + if($i <= $set{'max_log'} && !($set{'max_all_flag'} && $set{'max_all_size'}*1024 < $allsize)){ + if((-e $filename)||!$set{'zero_clear'}){ push(@new,$value); $i++; } + }else{ + if(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } } rmdir($filedir); + }elsif(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } } rmdir($filedir); + }elsif(-e $filename){ + push(@new,$value); + }else{ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } } rmdir($filedir); + } + } + } + logwrite(@new); + if($in{'dlkey'} && ( $set{'dummy_html'} == 2 || $set{'dummy_html'} == 3)){ + &makedummyhtml("$set{'file_pre'}$tmpno.$in{'ext'}",$in{'comment'},"$set{'file_pre'}$tmpno.$in{'ext'}",$dlsalt,$in{'date'},$in{'type'},$orgname,$no); + }elsif(!$in{'dlkey'} && ($set{'dummy_html'} == 1 || $set{'dummy_html'} == 3)){ + &makedummyhtml("$set{'file_pre'}$tmpno.$in{'ext'}"); + } + &makehtml(); &quit(); +} + +sub makehtml{ + + my ($buff,$init,$postval,$dlkey); + my $page = 0; my $i = 1; + + open(IN,$set{'log_file'})||&error(303); + my $log = my @log = <IN>; + close(IN); + + if($log == 1){ $log++; $init++;} + my $lastpage = int(($log - 2)/$set{'pagelog'}) + 1; + $postval = ' obj.postkey.value = unescape(p[1]);' if($set{'post_flag'}); + my $header =<<"EOM"; +$set{'html_head'}<META http-equiv="Content-Script-Type" content="text/javascript"> +<script type="text/javascript"> +<!-- +function getCookie(obj,cookiename){ + var i,str; c = new Array(); p = new Array("",""); str = document.cookie;c = str.split(";"); + for (i = 0; i < c.length; i++) { if (c[i].indexOf(cookiename+"=") >= 0) { p = (c[i].substr(c[i].indexOf("=")+1)).split("<>"); break; }} + if(cookiename == "SN_UPLOAD"){ obj.pass.value = unescape(p[0]);$postval } + else if(cookiename == "SN_DEL"){ obj.delpass.value = unescape(p[0]);} + return true; +} +function delnoin(no){ + document.Del.delno.value = no; + document.Del.del.focus(); +} +//--> +</script> +$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF" onload="getCookie(document.Form,'SN_UPLOAD');getCookie(document.Del,'SN_DEL');"> +<table summary="title" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Uploader</font></strong></td></tr></table> +<p> +Now.. Testing.. +</p> +EOM + my $maxsize = 'Max '.dispsize($set{'max_size'}*1024); + my ($minsize,$total); + if($set{'min_flag'}){ $minsize = 'Min '.dispsize($set{'min_size'}*1024).' - '; } + if($set{'max_all_flag'}){ $total .= ' Total '.dispsize($set{'max_all_size'}*1024);} + $header .= qq|<FORM METHOD="POST" ENCTYPE="multipart/form-data" ACTION="$set{'base_cgi'}" name="Form">FILE $minsize$maxsize (*$set{'max_log'}Files$total)<br>|; + $header .='<INPUT TYPE=file SIZE="40" NAME="upfile">'; + $header .= ' DLKey: <INPUT TYPE=text SIZE="8" NAME="dlkey" maxlength="8">' if($set{'dlkey'}); + $header .= ' +DELKey: <INPUT TYPE=password SIZE="10" NAME="pass" maxlength="8"><br> +COMMENT<br> +<INPUT TYPE=text SIZE="45" NAME="comment"> +<INPUT TYPE=hidden NAME="jcode" VALUE="¿"> +<INPUT TYPE=submit VALUE="Upload"><INPUT TYPE=reset VALUE="Cancel"><br> +'; + if($set{'post_flag'}){ $header .= 'PostKey<br><INPUT TYPE=password SIZE="10" NAME="postkey" maxlength="10">'; } + $header .= '</FORM>'; + + my $allsize = 0; + my @files = globfile("$set{'src_dir'}",".*"); + my @dir = globdir("$set{'src_dir'}",".*"); + foreach my $dir (@dir){ push(@files,globfile($dir."/",".*")); } + foreach my $value (@files){ $allsize += (-s "$value"); } + + $allsize = dispsize($allsize); + + my $footer = "</table><HR size=1>Used ${allsize}\n<br>"; + if($set{'up_all'} && !$set{'ext_org'}){ $footer .= $set{'up_ext'}.' +'; } + elsif(!$set{'up_all'}){ $footer .= $set{'up_ext'}; } + $footer .= "\n<table summary=\"footer\" width=\"100%\"><tr><td><div align=left><FORM METHOD=POST ACTION=\"$set{'base_cgi'}\" name=\"Del\"><span style='font-size:9pt'><input type=hidden name=mode value=delete>No.<input type=text size=4 name=delno> key<input type=password size=4 name=delpass> <input type=submit value=\"del\" name=del></span></form></div>\n"; + $footer .= "</td><td><div align=right><!-- $set{'ver'} --><a href=\"http://sugachan.dip.jp/download/\" target=\"_blank\"><small>Sn Uploader</small></a></div></td></tr></table>\n</body>\n</html>"; + + my $info_title = "<table summary=\"upinfo\" width=\"100%\">\n<tr><td></td><td>NAME</td>"; + if($set{'disp_comment'}){ $info_title .= "<td>COMMENT</td>"; } if($set{'disp_size'}){ $info_title .= "<td>SIZE</td>"; } if($set{'disp_date'}){ $info_title .= "<td>DATE</td>"; } + if($set{'disp_mime'}){ $info_title .= "<td>MIME</td>"; } if($set{'disp_orgname'}){ $info_title .= "<td>ORIG</td>"; } + $info_title .= "</tr>\n"; + + my $home_url_link; + if($set{'home_url'}){ $home_url_link = qq|<a href="$set{'home_url'}">[HOME]</a> |;} + if($set{'html_all'}){ + my $buff; my $no = 1; my $time = time; my $subheader; + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$dummy) = split(/<>/,$value); + if(!$dummy){ next; } + $buff .= makeitem($value); + } + $subheader .= "[ALL] "; + while($no <= $lastpage){ + if($no == $page) { $subheader .= "\[$no\] ";} + else{ if($no == 1){ $subheader .= "<a href=\"$set{'http_html_path'}$set{'base_html'}?$time\">\[$no\]</a> "} + else{$subheader .= "<a href=\"$set{'http_html_path'}$no.html?$time\">\[$no\]</a> ";} } + $no++; + } + $subheader .= $info_title; + open(OUT,">$set{'html_dir'}all.html")||&error(306,"$set{'html_dir'}all.html"); + print OUT $header."<hr size=1>".$home_url_link.$subheader."<hr size=1>".$buff.$footer; + close(OUT); + chmod($set{'per_upfile'},"$set{'html_dir'}all.html"); + }else{ unlink("$set{'html_dir'}all.html"); } + + while($log > $i){ + $buff .= makeitem($log[$i]) unless($init); + if(($i % $set{'pagelog'}) == 0||$i == $log -1){ + $page++; my $subheader; my $no = 1; my $time = time; + if($set{'html_all'}){ $subheader .= "<a href=\"./all.html?$time\">[ALL]</a> "; } + while($no <= $lastpage){ + if($no == $page) { $subheader .= "\[$no\] ";} + else{ if($no == 1){ $subheader .= "<a href=\"$set{'http_html_path'}$set{'base_html'}?$time\">\[$no\]</a> "} + else{$subheader .= "<a href=\"$set{'http_html_path'}$no.html?$time\">\[$no\]</a> ";} + } + $no++; + } + $subheader .= $info_title; + my $loghtml; + if($page == 1){ $loghtml = "$set{'html_dir'}$set{'base_html'}"; } + else{ $loghtml = "$set{'html_dir'}$page.html"; } + + open(OUT,">$loghtml") || &error(306,"$loghtml"); + print OUT $header."<hr size=1>".$home_url_link.$subheader."<hr size=1>".$buff.$footer; + close(OUT); + chmod($set{'per_upfile'},$loghtml); + undef $buff; + } + $i++; + } + + while($page < 1000){ + $page ++; + if(-e "$set{'html_dir'}$page.html"){ unlink("$set{'html_dir'}$page.html"); }else{ last; } + } +} + +sub filewrite{ + my $random = int(rand(900000)) + 100000; + if(-e "$set{'src_dir'}$random.temporary"){ $random++; } + if(-e "$set{'src_dir'}$random.temporary"){ &error(204); } + open (FILE,">$set{'src_dir'}$random.temporary") || &error(204); + binmode(FILE); + eval{ while(my $read = read($in{'upfile'}, my $buff, 8192)){ print FILE $buff; }}; + close(FILE); + chmod($set{'per_upfile'},"$set{'src_dir'}$random.temporary"); + if((-s "$set{'src_dir'}$random.temporary") == 0){ unlink("$set{'src_dir'}$random.temporary"); &error(99); } + my $size = (-s "$set{'src_dir'}$random.temporary"); + if($set{'min_flag'} && ($size < $set{'min_size'} * 1024)){ unlink("$set{'src_dir'}$random.temporary"); &error(107,$size);} + if($size > $set{'max_size'} * 1024){ unlink("$set{'src_dir'}$random.temporary"); &error(106,$size);} + eval { close($in{'upfile'});}; + unlink($in{'tmpfile'}); + return("$set{'src_dir'}$random.temporary"); +} + +sub delete{ + my $mode = $_[0]; + my @delno = split(/,/,$_[1]); + my $delno; my $flag = 0; my $tmpaddr; + my $delnote; + + if($in{'delno'} =~ /(\d+)/){ $delno = $1; } + if($mode ne 'admin' && !$in{'delno'}){ return; } + elsif($mode ne 'admin' && !$delno){ &error(401,$in{'delno'}); } + + open(IN,$set{'log_file'})|| &error(303); + my @log = <IN>; + close(IN); + + if($in{'addr'} =~ /(\d+).(\d+).(\d+).(\d+)/){ $tmpaddr = "$1.$2.$3."; } + my $findflag = 0; + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$value); + $delnote = $note; + my $delflag = 0; + if(!$addr){ next; } + if($mode eq 'admin'){ + foreach my $delno (@delno){ if($no == $delno){ $delflag = 1; last; } } + }elsif($no == $delno){ + $findflag = 1; + unless ($addr =~ /^$tmpaddr/){ + my ($pass,$id) = split(/,/,$pass); + my $delpass = $in{'delpass'} || $in{'addr'}.time(); + my $salt = substr($pass, 0, 2); $delpass = crypt($delpass,$salt); + my $usersalt = substr($in{'user'},0,2); my $userid = crypt($in{'user'},$usersalt); + if ($in{'delpass'} ne $set{'admin_pass'} && $delpass ne $pass && $userid ne $id){ + if($mode ne 'admin'){ if(!$dummy){ $filepre = $set{'file_pre'};} $no = sprintf("%04d",$no); &error(404,"$filepre$no.$ext");} + } + } + $delflag = 1; + } + if($delflag){ +# open(OUT,">>./del.cgi"); print OUT $value; close(OUT); + $flag = 1; + if(!$dummy){ $filepre = $set{'file_pre'};} + $no = sprintf("%04d",$no); + my $filename; + my ($dlpath,$filedir); + if($delnote =~ /DLpath:(.+)\s/){ + $dlpath = $1; + $filename = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/$filepre$no.$ext"; + $filedir = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/"; + }else{ + $filename = "$set{'src_dir'}$filepre$no.$ext"; + } + + if(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } rmdir($filedir);} undef $value; + }elsif(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } rmdir($filedir);} undef $value; + }elsif(!(-e $filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } rmdir($filedir);} undef $value; + }else{ + if($mode ne 'admin'){ &error(403,"$filepre$no.$ext");} + } + } + } + if($mode ne 'admin' && !$findflag){ &error(402,$delno); } + if($flag){ + logwrite(@log); + &makehtml(); + } +} + +sub quit{ + my ($cookiename,$buff); + my $flag = 0; + my @tmpfiles = globfile("$set{'src_dir'}","\.temporary"); + foreach my $value (@tmpfiles){ if((stat($value))[10] < time - 60*60){ unlink("$value"); $flag++; } } + &makehtml() if($flag); + $buff =<<"EOM"; +$set{'html_head'}<META HTTP-EQUIV="Refresh" CONTENT="1;URL=$set{'http_html_path'}$set{'base_html'}"> +EOM + if($in{'jcode'} || $in{'mode'} eq 'delete'){ + $buff .=<<"EOM"; +<META HTTP-EQUIV="Set-Cookie" content="SN_USER=$in{'user'}<>1; path=/; expires=Tue, 31-Dec-2030 23:59:59 GMT"> +<META HTTP-EQUIV="CONTENT-SCRIPT-TYPE" CONTENT="text/javascript"> +<script type="text/javascript"> +<!-- +setCookie(); +function setCookie() { + var key1,key2; + var tmp = "path=/; expires=Tue, 31-Dec-2030 23:59:59; "; +EOM + if($in{'jcode'}){ + my %ck; foreach(split(/;/,$ENV{'HTTP_COOKIE'})){ my($key,$val) = split(/=/); $key =~ s/\s//g; $ck{$key} = $val;} + my @ck = split(/<>/,$ck{'SN_DEL'}); + if(!$ck[0] && $in{'org_pass'}){ $buff .= qq|\tdocument.cookie = "SN_DEL="+escape('$in{'org_pass'}')+"<>;"+ tmp;\n|;} + $cookiename = 'SN_UPLOAD'; $buff .= "\tkey1 = escape('$in{'org_pass'}'); key2 = escape('$in{'postkey'}');\n";} + else{ $cookiename = 'SN_DEL'; $buff .= "\tkey1 = escape('$in{'delpass'}'); key2 = '';\n"; } + $buff .= qq|\tdocument.cookie = "$cookiename="+key1+"<>"+key2+"; "+ tmp;\n}\n//-->\n</script>\n|; + } + $buff .=<<"EOM"; +<body> +<br><br><div align=center><font size="+1"><br><br> +<a href="$set{'http_html_path'}$set{'base_html'}?$in{'time'}">click here!</a></font><br> +</div> +</body></html> +EOM + print "Content-type: text/html\n\n"; + print $buff; + exit; +} + +sub admin_mode{ + &errorclear() if($in{'mode'} eq 'errorclear'); + &delete('admin',$in{'admin_delno'}) if($in{'mode'} eq 'delete'); + + open(IN,$set{'log_file'})||error(303); + my @log = <IN>; + close(IN); + + my ($header,$buff,$footer,$value); + $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +EOM + + $buff .= leaddisp(0,1,1).'<a name="up"></a><table summary="title" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Upload Info</font></strong></td></tr></table>'; + $buff .= qq|<table summary="check"><tr><td><form action="$set{'base_cgi'}" method="POST"><input type=hidden name="checkmode" value="allcheck"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="·×Ä`FbN"></form></td><td><form action="$set{'base_cgi'}" method="POST"><input type=hidden name="checkmode" value="nocheck"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="·×ÄO·"></form></td><td><form action="$set{'base_cgi'}" method="POST"><input type=hidden name=delpass value="$set{'admin_pass'}"><input type=submit value="HTMLðXV·é/OAEg"></form></td></tr></table>\n<form action="$set{'base_cgi'}" method="POST"><input type=hidden name="mode" value="delete"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="`FbNµ½àÌðí"><br>\n|."<table summary=\"upinfo\" width=\"100%\">\n<tr><td>DEL</td><td>NAME</td><td>COMMENT</td><td>SIZE</td><td>ADDR</td><td>HOST</td><td>DATE</td><td>NOTE</td><td>MIME</td><td>ORIG</td></tr>\n"; + shift(@log); + foreach (@log){ $buff .= makeitem($_,'admin'); } + $buff .= '</table></form><br><br>'; + + if($set{'error_level'}){ + $buff .= leaddisp(-1,0,1).'<a name="error"></a><table summary="errortitle" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Error Info</font></strong></td></tr></table>'; + $buff .= qq|<form action="$set{'base_cgi'}" method="POST"><input type=hidden name=mode value="errorclear"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="G[ONA"></form>|; + $buff .= "<table summary=\"errorinfo\" width=\"100%\">\n<tr><td>DATE</td><td>ADDR</td><td>HOST</td><td>NOTE</td></tr>\n"; + if(open(IN,$set{'error_log'})){ @log = reverse(<IN>); close(IN); foreach (@log){ my ($date,$no,$note,$addr,$host) = split(/<>/); $buff .= "<tr><td>$date</td><td>$addr</td><td>$host</td><td>$note</td></tr>\n"; }} + $buff .= "</table><br><br>\n"; + } + + $buff .= leaddisp(-1,-1,0); + $buff .= '<a name="set"></a><table summary="settitle" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Setting Info</font></strong></td></tr></table>'."\n<table summary=\"setting\">\n"; + $buff .= tablestr('XNvgVer',$set{'ver'}); + $buff .= tablestr('COt@C',$set{'log_file'}); + if($set{'error_level'}){ + $buff .= tablestr('G[Ot@C',$set{'error_log'}); + if($set{'error_size'}){ $buff .= tablestr('G[OÅåeÊ',dispsize($set{'error_size'}*1024).' '.($set{'error_size'}*1024).'Bytes'); } + else{ $buff .= tablestr('G[OÅåeʧÀ','³'); } + }else{ $buff .= tablestr('G[OL^','³'); } + $buff .= tablestr('Û',$set{'max_log'}); + $buff .= tablestr('ÅåeeÊ',dispsize($set{'max_size'}*1024).' '.($set{'max_size'}*1024).'Bytes'); + + if($set{'min_flag'}){ $buff .= tablestr('Ŭ§ÀeÊ',dispsize($set{'min_size'}*1024).' '.($set{'min_size'}*1024).'Bytes'); } + else{ $buff .= tablestr('Ŭ§ÀeÊ',"³"); } + if($set{'max_all_flag'}){ $buff .= tablestr('eʧÀ',dispsize($set{'max_all_size'}*1024).' '.($set{'max_all_size'}*1024).'Bytes'); } + else{ $buff .= tablestr('eʧÀ',"³"); } + + $buff .= tablestr("t@CÚª«",$set{'file_pre'}); + $buff .= tablestr("HTMLÛ¶fBNg",$set{'html_dir'}); + $buff .= tablestr("t@CÛ¶fBNg",$set{'src_dir'}); + if($set{'http_html_path'} && $set{'html_dir'} ne $set{'http_html_path'}){ $buff .= "<tr><td>HTTP_HTML_PATH</td><td>$set{'http_html_path'}</td></tr>\n";} + if($set{'http_src_path'} && $set{'src_dir'} ne $set{'http_src_path'}){ $buff .= "<tr><td>HTTP_SRC_PATH</td><td>$set{'http_src_path'}</td></tr>\n";} + $buff .= tablestr('1y[WÉ\¦·ét@C',$set{'pagelog'}); + if($set{'interval'} > 0){ $value = $set{'interval'}.'b'; }else{ $value = '³'; } + $buff .= tablestr('¯êIPeÔub§À',$value); + if($set{'up_ext'}){ $set{'up_ext'} =~ s/,/ /g; $buff .= tablestr('eÂ\î{g£q',$set{'up_ext'}); } + if($set{'deny_ext'}){ $set{'deny_ext'} =~ s/,/ /g; $buff .= tablestr('eÖ~g£q',$set{'deny_ext'}); } + if($set{'change_ext'}){ $set{'change_ext'} =~ s/,/ /g; $set{'change_ext'} =~ s/>/>/g; $buff .= tablestr('g£qÏ·',$set{'change_ext'}); } + + if($set{'up_all'}){ $buff .= tablestr('wèOg£qAbv[hÂ','L'); if($set{'ext_org'}){ $buff .= tablestr('wèOt@Cg£q','IWi'); }else{ $buff .= tablestr('wèOt@Cg£q','bin'); }} + else{$buff .= tablestr('wèOg£qAbv[hÂ','³');} + + if($set{'find_crypt'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('ûA[JCuo(ZIP)',$value); + if($set{'binary_compare'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('oCiär',$value); + if($set{'post_flag'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('PostKeye§À',$value); + if($set{'dlkey'}){ if($set{'dlkey'} == 2){$value = 'K{'}else{$value = 'CÓ';}}else{ $value = '³';} + $buff .= tablestr('DLkey',$value); + if($set{'dummy_html'}){ if($set{'dummy_html'} == 3){$value = 'ALL'}elsif($set{'dummy_html'} == 2){$value = 'DLKeyÌÝ';}else{$value = 'Êít@CÌÝ';}}else{ $value = '³';} + $buff .= tablestr('ÂÊHTMLLbV ',$value); + if($set{'disp_error'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('[UG[\¦',$value); + if($set{'zero_clear'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('íÏt@CXg©®Á',$value); + if($set{'home_url'}){ $buff .= "<tr><td>HOMEURL</td><td>$set{'home_url'}</td></tr>\n";} + + $buff .= '</table></body></html>'; + + print "Content-type: text/html\n\n"; + print $buff; + exit; +} + +sub extfind{ + my $orgname = @_[0]; + my @filename = split(/\./,$orgname); + my $ext = $filename[$#filename]; + $ext =~ tr/[A-Z]/[a-z]/; + foreach my $value (split(/,/,$set{'change_ext'})){ my ($src,$dst) = split(/->/,$value); if($ext eq $src){ $ext = $dst; last; }} + foreach my $value (split(/,/,$set{'deny_ext'})){ if($ext eq $value){ &error(206,$ext); }} + foreach my $value (split(/,/,$set{'up_ext'})){ if ($ext eq $value) { return $value; } } + if(length($ext) >= 5 || length($ext) == 0){ $ext = 'bin'; } + unless ($ext =~ /^[A-Za-z0-9]+$/){ $ext = 'bin'; } + if($set{'up_all'} && $set{'ext_org'}){ return $ext;} + elsif($set{'up_all'}){ return 'bin'; } + return 0; +} + +sub conv_date{ + my @date = gmtime($_[0] + 9*60*60); + $date[5] -= 100; $date[4]++; + if ($date[5] < 10) { $date[5] = "0$date[5]" ; } if ($date[4] < 10) { $date[4] = "0$date[4]" ; } + if ($date[3] < 10) { $date[3] = "0$date[3]" ; } if ($date[2] < 10) { $date[2] = "0$date[2]" ; } + if ($date[1] < 10) { $date[1] = "0$date[1]" ; } if ($date[0] < 10) { $date[0] = "0$date[0]" ; } + my @w = ('Sun','Mon','Tue','Wed','Thu','Fri','Sat'); + return ("$date[5]/$date[4]/$date[3]($w[$date[6]]),$date[2]:$date[1]:$date[0]"); +} + +sub dispsize{ + my $size = $_[0]; + if($size >= 1024*1024*1024*100){ $size = int($size/1024/1024/1024).'GB';} + elsif($size >= 1024*1024*1024*10){ $size = sprintf("%.1fGB",$size/1024/1024/1024);} + elsif($size > 1024*1024*1024){ $size = sprintf("%.2fGB",$size/1024/1024/1024);} + elsif($size >= 1024*1024*100){ $size = int($size/1024/1024).'MB'; } + elsif($size > 1024*1024){ $size = sprintf("%.1fMB",$size/1024/1024); } + elsif($size > 1024){ $size = int($size/1024).'KB'; } + else{ $size = int($size).'B';} + return $size; +} + +sub makeitem{ + my ($src,$mode) = @_; my ($buff,$check,$target); + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$src); + if(!$dummy){ $filepre = $set{'file_pre'}; } + my $orgno = $no; + $no = sprintf("%04d",$no); + my $size = 0; + my $dlpath = 0; + + if($note =~ /DLpath:(.+)\s/){ + $dlpath = $1; + $size = dispsize(-s "$set{'src_dir'}$filepre$no.${ext}_$dlpath/$filepre$no.$ext"); + }else{ + $size = dispsize(-s "$set{'src_dir'}$filepre$no.$ext"); + } + + my $path = $set{'http_src_path'} || $set{'src_dir'}; + if($set{'link_target'}){ $target = qq| target="$set{'link_target'}"|; } + if($mode eq 'admin'){ + if($dlpath){ $path .= "$filepre$no.${ext}_$dlpath/"; } + if($addr eq $host){ undef $host; } + if($in{'checkmode'} eq 'allcheck'){$check = ' checked';} + $buff = "<tr><td><INPUT TYPE=checkbox NAME=\"admin_delno\" VALUE=\"$no\"$check></td><td><a href=\"$path$filepre$no.$ext\"$target>$filepre$no.$ext</a></td><td>$comment</td><td>$size</td><td>$addr</td><td>$host</td><td>$date</td><td>$note</td><td>$mime</td><td>$orgname</td></tr>\n"; + }else{ + my($d_com,$d_date,$d_size,$d_mime,$d_org); + if($set{'disp_comment'}){ $d_com = "<td>$comment</td>"; } if($set{'disp_size'}){ $d_size = "<td>$size</td>"; } if($set{'disp_date'}){ $d_date= "<td>$date</td>"; } + if($set{'disp_mime'}){ $d_mime = "<td>$mime</td>"; } if($set{'disp_orgname'}){ $d_org = "<td>$orgname</td>"; } + if(-e "$set{'src_dir'}$filepre$no.$ext.html"){$buff = "<tr><td><SCRIPT type=\"text/javascript\" Language=\"JavaScript\"><!--\ndocument.write(\"<a href=\\\"javascript:delnoin($orgno)\\\">$set{'char_delname'}<\\/a>\");\n// --></SCRIPT></td><td><a href=\"$path$filepre$no.$ext.html\"$target>$filepre$no.$ext</a></td>$d_com$d_size$d_date$d_mime$d_org</tr>\n";} + elsif($dlpath){$buff = "<tr><td><SCRIPT type=\"text/javascript\" Language=\"JavaScript\"><!--\ndocument.write(\"<a href=\\\"javascript:delnoin($orgno)\\\">$set{'char_delname'}<\\/a>\");\n// --></SCRIPT></td><td><a href=\"$set{'base_cgi'}?mode=dl&file=$orgno\">$filepre$no.$ext</a></td>$d_com$d_size$d_date$d_mime$d_org</tr>\n";} + else{ $buff = "<tr><td><SCRIPT type=\"text/javascript\" Language=\"JavaScript\"><!--\ndocument.write(\"<a href=\\\"javascript:delnoin($orgno)\\\">$set{'char_delname'}<\\/a>\");\n// --></SCRIPT></td><td><a href=\"$path$filepre$no.$ext\"$target>$filepre$no.$ext</a></td>$d_com$d_size$d_date$d_mime$d_org</tr>\n";} + } + return $buff; +} + +sub makedummyhtml{ + my ($filename,$com,$file,$orgdlpath,$date,$mime,$orgname,$no) = @_; + my $buff; + + if(!$no){ + $buff = "<html><head><title>$filename</title></head><body>"; + $buff .= qq|Download <a href="./$filename">$filename</a>|; + $buff .= '</body></html>'; + }else{ + $buff = cryptfiledl($com,$file,$orgdlpath,$date,$mime,$orgname,$no); + } + + open(OUT,">$set{'src_dir'}$filename.html")||&error(307,"$set{'src_dir'}$filename.html"); + print OUT $buff; + close(OUT); + chmod($set{'per_upfile'},"$set{'src_dir'}$filename.html"); + return 1; +} + +sub logwrite{ + my @log = @_; + open(OUT,"+>$set{'log_file'}")||&error(304); + eval{ flock(OUT, 2);}; + eval{ truncate(OUT, 0);}; + seek(OUT, 0, 0); + print OUT @log; + eval{ flock(OUT, 8);}; + close(OUT); + chmod($set{'per_upfile'},$set{'log_file'}); + return 1; +} + +sub binarycmp{ + my ($src,$dst) = @_; + return 0 if (-s $src != -s $dst); + open(SRC,$src)||return 0; open(DST,$dst)||return 0; + my ($buff,$buff2); + binmode(SRC); binmode(DST); seek(SRC,0,0); seek(DST,0,0); + while(read(SRC,$buff,8192)){ read(DST,$buff2,8192); if($buff ne $buff2){ close(SRC); close(DST); return 0; } } + close(SRC); close(DST); + return 1; +} + +sub init{ + my $buff; + if(open(OUT,">$set{'log_file'}")){ + print OUT "0<>0<>0<>1\n"; + close(OUT); + chmod($set{'per_logfile'},$set{'log_file'}); + }else{ + $buff = "<tr><td>COÌì¬É¸sµÜµ½</td></tr>"; + } + + unless (-d "$set{'src_dir'}"){ + if(mkdir("$set{'src_dir'}",$set{'per_dir'})){ + chmod($set{'per_dir'},"$set{'src_dir'}"); + open(OUT,">$set{'src_dir'}index.html"); + close(OUT); + chmod($set{'per_upfile'},"$set{'src_dir'}index.html"); + }else{ + $buff .= "<tr><td>SourceÛ¶fBNgÌì¬É¸sµÜµ½</td></tr>"; + } + } + + unless (-d "$set{'html_dir'}"){ + if(mkdir("$set{'html_dir'}",$set{'per_dir'})){ + chmod($set{'per_dir'},"$set{'html_dir'}"); + }else{ + $buff .= "<tr><td>HTMLÛ¶fBNgÌì¬É¸sµÜµ½</td></tr>"; + } + } + + if($buff){ + $buff .= "<tr><td>fBNgÉ«Ý Àª é©mFµÄ¾³¢</td></tr>"; + &error_disp($buff,'init'); + } +} + +sub check_postkey{ + my $inputkey = @_[0]; + my @key = split(/,/,$set{'post_key'}); + foreach my $key (@key){ if($inputkey eq $key){ return 1; } } + return 0; +} + +sub leaddisp{ + my @src = @_; + my ($str,$count); + foreach my $value (@src){ + my ($mark,$name,$link); $count++; + if($count == 1){ $name = 'Upload Info'; $link = 'up'; } + elsif($count == 2){ $name = 'Error Info'; $link = 'error'; next if(!$set{'error_level'}); } + elsif($count == 3){ $name = 'Setting Info'; $link = 'set'; } + if($value){ if($value > 0){ $mark = '¥'; }else{ $mark = '£'; } $str .= qq|<a href="#$link">${mark}${name}</a> |; } + else{ $str .= qq|[$name] |; } + } + return $str; +} + +sub errorclear{ + open(OUT,">$set{'error_log'}")||return 0; + eval{ flock(OUT, 2);}; eval{ truncate(OUT, 0);}; seek(OUT, 0, 0); eval{ flock(OUT, 8);}; close(OUT); + chmod($set{'per_upfile'},$set{'log_file'}); + return 1; +} + +sub tablestr{ + my ($value1,$value2) = @_; + return ("<tr><td>$value1</td><td>$value2</td></tr>\n"); +} + +sub globfile{ + my ($src_dir,$filename) = @_; + opendir(DIR,$src_dir)||return 0; my @dir = readdir(DIR); closedir(DIR); + my @new = (); foreach my $value (@dir){ push(@new,"$src_dir$value") if($value =~ /$filename/ && !(-d "$src_dir$value")); } + return @new; +} + +sub globdir{ + my ($src_dir,$dir) = @_; + opendir(DIR,$src_dir)||return 0; my @dir = readdir(DIR); closedir(DIR); + my @new = (); foreach my $value (@dir){ if($value eq '.' ||$value eq '..' ){ next; } push(@new,"$src_dir$value") if($value =~ /$dir/ && (-d "$src_dir$value")); } + return @new; +} + +sub error_disp{ + my ($message,$mode) = @_; + my $url; + if($mode eq 'init'){ $url = qq|<a href="$set{'base_cgi'}">[[h]</a>|; }else{ $url = qq|<a href="$set{'http_html_path'}$set{'base_html'}">[ßé]</a>|; } + my $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +<div align="center"> +<table summary="error"> +$message +<tr><td></td></tr> +<tr><td><div align="center">$url</div></td></tr> +</table> +<br><br> +<table summary="info"> +<tr> +<td>DATE</td><td>$in{'date'}</td></tr> +<tr><td>ADDR</td><td>$in{'addr'}</td></tr> +<tr><td>HOST</td><td>$in{'host'}</td></tr> +</table> +</div> +</body></html> +EOM + print "Content-type: text/html\n\n"; + print $buff; + exit; +} + +sub error{ + my ($no,$note) = @_; + if (length($note) > 64) { $note = substr($note,0,64).'...'; } + $note =~ s/&/&/g; $note =~ s/\"/"/g; $note =~ s/</</g; $note =~ s/>/>/g; $note =~ s/\r//g; $note =~ s/\n//g; $note =~ s/\t//g; $note =~ s/\0//g; + my ($message,$dispmsg,$flag); + if($no == 98){ $message = ""; } + elsif($no == 99){ $message = "UpFileȵ"; } + elsif($no == 101){ $message = "eÖ~HOST"; } + elsif($no == 106){ $flag = 1; $message = "POSTTCY´ß"; $note = dispsize($note); $dispmsg= '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>Abv[ht@C('.$note.')Í ÅåeÊÝè('.dispsize($set{'max_size'}*1024).')ðz¦Ä¢Ü·</td></tr>';} + elsif($no == 107){ $flag = 1; $message = "POSTTCY߬"; $note = dispsize($note); $dispmsg= '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>Abv[ht@C('.$note.')Í Å¬eÊÝè('.dispsize($set{'min_size'}*1024).')¢Å·</td></tr>';} +# elsif($no == 108){ $flag = 1; $message = "POSTf[^s®S"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>POSTf[^ªs®SÅ·</td></tr>';} + elsif($no == 109){ $flag = 1; $message = "POSTKeysêv"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>POSTKeyªêvµÜ¹ñ</td></tr>';} + elsif($no == 202){ $flag = 1; $message = "g£qí¸"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>eÅ«ég£qÍ'.$set{'up_ext'}.'Å·</td></tr>';} + elsif($no == 203){ $flag = 1; $message = "e·¬"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>¯êIPAhX©ç'.$set{'interval'}.'bÈàÉÄeūܹñ</td></tr>';} + elsif($no == 204){ $flag = 1; $message = "êt@C«ß¸"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>êt@CÌì¬É¸sµÜµ½</td></tr>';} + elsif($no == 205){ $flag = 1; $message = "¯êt@C¶Ý"; $note =~ /([^\/]+)$/; my $filename = $1; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>¯êt@Cª '.$filename.' ɶݵܷ</td></tr>';} + elsif($no == 206){ $flag = 1; $message = "Ö~g£q"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>g£q '.$note.' ÍAbv[hūܹñ</td></tr>';} + elsif($no == 303){ $flag = 1; $message = "Ot@CÉÇÝ߸"; $dispmsg = '<tr><td>COÌÇÝÝɸsµÜµ½</td></tr>';} + elsif($no == 304){ $flag = 1; $message = "Ot@Cɫ߸"; $dispmsg = '<tr><td>COÌ«ÝɸsµÜµ½</td></tr>';} + elsif($no == 306){ $message = "t@CXgHTML«ß¸";} + elsif($no == 307){ $message = "t@CHTMLt@C«ß¸";} + elsif($no == 401){ $flag = 1; $message = "íNo.oÅ«¸"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>'.$note.' ©çíNo.ðoūܹñŵ½</td></tr><tr><td>'.$set{'file_pre'}.'0774.zipÌê No.ÉÍ 774 ðü͵ܷ</td></tr>';} + elsif($no == 402){ $flag = 1; $note = sprintf("%04d",int($note)); $message = "íNo.¶Ý¹¸"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>'.$set{'file_pre'}.$note.'.*** ÍCOɶݵܹñ</td></tr>';} + elsif($no == 403){ $flag = 1; $message = "íANZXÛ"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>t@CíðͽµÄ¢Ü·ª '.$note.' Ìt@CÌíªÛ³êܵ½</td></tr><tr><td>ANZXªßèÈêÍÔðu¢ÄÄì·éÆíÅ«é±Æª èÜ·</td></tr>';} + elsif($no == 404){ $flag = 1; $message = "íKeysêv"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>'.$note.' íKeyªêvµÜ¹ñŵ½</td></tr>';} + + elsif($no == 51){ $flag = 1; $message = "[DLMode] No.©Â©ç¸"; $dispmsg = '<tr><td>[DLMode] t@Cª©Â©èܹñŵ½</td></tr><tr><td>'.$note.' ©çt@CNo.ðoūܹñŵ½</td></tr>'; } + elsif($no == 52){ $flag = 1; $message = "[DLMode] File©Â©ç¸"; $dispmsg = '<tr><td>[DLMode] t@Cª©Â©èܹñŵ½</td></tr><tr><td>'.$set{'file_pre'}.$note.'.*** ÍCOɶݵܹñ</td></tr>'; } + elsif($no == 53){ $flag = 1; $message = "[DLMode] DLkey¢Ýè"; $dispmsg = '<tr><td>[DLMode] orgDLkeyError</td></tr><tr><td>'.$note.' DLKeyª¢ÝèÅ·</td></tr>'; } + elsif($no == 54){ $flag = 1; $message = "[DLMode] DLkeysêv"; $dispmsg = '<tr><td>[DLMode] orgDLkeyError</td></tr><tr><td>'.$note.' DLKeyªêvµÜ¹ñŵ½</td></tr>'; } + elsif($no == 55){ $flag = 1; $message = "[DLMode] File Oepn Error"; $dispmsg = '<tr><td>[DLMode] Open Error</td></tr><tr><td>'.$note.' t@CÌÇÝÝɸsµÜµ½</td></tr>'; } + elsif($no == 56){ $flag = 1; $message = "[DLMode] File Not Found"; $dispmsg = '<tr><td>[DLMode] Not Found</td></tr><tr><td>'.$note.' t@Cª¶ÝµÜ¹ñ</td></tr>'; } + + elsif($no == 61){ $flag = 1; $message = "DLkey¢Ýè"; $dispmsg = '<tr><td>DLKeyª¢ÝèÅ·</td></tr>'; } + + if($note){$message .= ' ';} + eval { close($in{'upfile'}); }; + unlink($in{'tmpfile'}); + if($set{'error_level'} && $no > 100){ + unless(-e $set{'error_log'}){ + open(OUT,">$set{'error_log'}"); + close(OUT); + chmod($set{'per_logfile'},$set{'error_log'}); + } + if($set{'error_size'} && ((-s $set{'error_log'}) > $set{'error_size'} * 1024)){ + my $err_bkup = "$set{'error_log'}.bak.cgi"; + unlink($err_bkup); + rename($set{'error_log'},$err_bkup); + open(OUT,">$set{'error_log'}"); + close(OUT); + chmod($set{'per_logfile'},$set{'error_log'}); + } + open(OUT,">>$set{'error_log'}"); + print OUT "$in{'date'}<>$no<>$message$note<>$in{'addr'}<>$in{'host'}<>1\n"; + close(OUT); + } + &error_disp($dispmsg) if($flag && $set{'disp_error'}); + &quit(); +} + +sub dlfile{ + my $msg; + my ($orgdlkey,$orgdlpath); + my ($dlext,$dlfilepre); + my ($dl_date,$dl_comment,$dl_size,$dl_mime,,$dl_orgname); + my $dlno = 0; + my $findflag; + + open(IN,$set{'log_file'})||&error(303); + my @log = <IN>; + close(IN); + shift(@log); + + if($in{'file'} =~ /(\d+)/){ $dlno = $1; } + if($dlno == 0) { &error(51,$in{'file'}); } + + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$value); + my @note = split(/,/,$note); + if(int($dlno) == $no){ + $dl_comment = $comment; + $dl_mime = $mime; + $dl_date = $date; + $dl_orgname = $orgname; + $dlext = $ext; + $dlfilepre = $filepre; + foreach my $tmpnote (@note){ + if($tmpnote =~ /\!--\sDLKey:(.+)\s--.*\!--\sDLpath:(.+)\s--/){ + $orgdlkey = $1; + $orgdlpath = $2; + last; + } + } + $findflag = 1; + last; + } + } + + my $dlfile = $dlfilepre.sprintf("%04d",int($dlno)).'.'.$dlext; + if(!(-e "$set{'src_dir'}${dlfile}_$orgdlpath/$dlfile")){ &error(56,"$dlfile----$set{'src_dir'}${dlfile}_$orgdlpath/$dlfile"); } + + if($in{'dlkey'}){ + my $dlsalt = substr($orgdlkey,0,2); + my $dlkey = crypt($in{'dlkey'},$dlsalt); + + if($findflag == 0){ &error(52,$dlfile); } + elsif(!$orgdlkey){ &error(53,$dlfile); } + elsif($orgdlkey ne $dlkey && $set{'admin_pass'} ne $in{'dlkey'}){ &error(54,$dlfile); } + #print "Location: $set{'http_src_path'}${dlfile}_$orgdlpath/$dlfile\n\n"; + my $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'} +<META HTTP-EQUIV="Refresh" CONTENT="1;URL=$set{'http_src_path'}${dlfile}_$orgdlpath/$dlfile"> +</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +<div align="center"> +<br> +<table summary="dlfrom"> +<tr><td>òÎÈ¢êÍ <a href="$set{'http_src_path'}${dlfile}_$orgdlpath/$dlfile">±¿ç</a> ©ç</td></tr> +</table> +</div> +</body></html> +EOM + print "Content-type: text/html\n\n"; + print $buff; + }else{ + my $buff = cryptfiledl($dl_comment,$dlfile,$orgdlpath,$dl_date,$dl_mime,$dl_orgname,$dlno); + print "Content-type: text/html\n\n"; + print $buff; + } + exit; +} + +sub cryptfiledl{ + my($com,$file,$orgdlpath,$date,$mime,$orgname,$no) = @_; + my($d_com,$d_date,$d_size,$d_mime,$d_org); + + if($set{'disp_comment'}){ $d_com = "<tr><td>COMMENT</td><td>$com</td></td>"; } if($set{'disp_size'}){ $d_size = "<tr><td>SIZE</td><td>".dispsize(-s "$set{'src_dir'}${file}_$orgdlpath/$file")." (".(-s "$set{'src_dir'}${file}_$orgdlpath/$file")."bytes)"."</td></tr>"; } if($set{'disp_date'}){ $d_date= "<tr><td>DATE</td><td>$date</td></tr>"; } + if($set{'disp_mime'}){ $d_mime = "<tr><td>ORGMIME</td><td>$mime</td></tr>"; } if($set{'disp_orgname'}){ $d_org = "<tr><td>ORGNAME</td><td>$orgname</td></tr>"; } + + my $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +<div align="center"> +<br> +$file ÉÍDLKeyªÝè³êĢܷ +<table summary="dlform"> +<tr><td></td></tr> +<FORM METHOD=POST ACTION="$set{'base_cgi'}" name="DL"> +<tr><td> +<input type=hidden name=file value=$no> +<input type=hidden name=jcode value="¿"> +<input type=hidden name=mode value=dl></td></tr> +$d_com$d_date$d_size$d_mime$d_org +<tr><td>DLKey:<input type=text size=8 name="dlkey"></td></tr> +<tr><td><input type=submit value="DownLoad"></td></tr> +</FORM> +</table> +</div> +</body></html> +EOM + + return $buff; +} \ No newline at end of file diff --git a/SnUploader/snup_051010e/uploader/upload.cgi b/SnUploader/snup_051010e/uploader/upload.cgi new file mode 100644 index 0000000..aa2993e --- /dev/null +++ b/SnUploader/snup_051010e/uploader/upload.cgi @@ -0,0 +1,1078 @@ +#!/usr/bin/perl +use vars qw(%set %in); +use strict; +$set{'log_file'} = './log.cgi'; #Ot@C¼ +$set{'max_log'} = 30; #Û +$set{'max_size'} = 1*1024; #ÅåeeÊ(KB) +$set{'min_flag'} = 0; #ŬeʧÀðgp·é=1 +$set{'min_size'} = 100; #ŬeeÊ(KB) +$set{'max_all_flag'} = 0; #eʧÀðgp·é=1 +$set{'max_all_size'} = 20*1024; #§ÀeÊ(KB) +$set{'file_pre'} = 'up'; #t@CÚª« +$set{'pagelog'} = 10; #1y[WÉ\¦·ét@C +$set{'base_html'} = 'upload.html'; #1y[WÚÌt@C¼ +$set{'interval'} = 0; #¯êIPeÔub +$set{'deny_host'} = ''; #eÖ~IP/HOST ,ÅæØé ex.(bbtec.net,219.119.66,ac.jp) +$set{'admin_name'} = 'admin'; #ÇÒOCID +$set{'admin_pass'} = '1234'; #ÇÒpX[h + +# Ⱥ5ÚðÄÝè·éÛÉÍPATHCfBNgÍ / ÅIíé±Æ +# $set{'html_dir'},$set{'base_cgi'}ð ./ ÈOÉÝè·éê, +# ܽÍDLkeyðgpµ Ȩ©ÂHTMLLbV ($set{'dummy_html'} = 2 or 3)ðgp·éêÍ +# $set{'base_cgi'} , $set{'http_html_path'} , $set{'http_src_path'} ðtpX(http://`` or /``)ÅLq·é +$set{'html_dir'} = './'; # àHTMLÛ¶fBNg +$set{'src_dir'} = './src/'; # àt@CÛ¶fBNg +$set{'base_cgi'} = './upload.cgi'; # ±ÌXNvg¼ http://`ÌwèÂ\ +$set{'http_html_path'} = './'; # htmlQÆ httpPATH http://`ÌwèÂ\ +$set{'http_src_path'} = './src/'; # fileQÆ httpPATH http://`ÌwèÂ\ + +$set{'dlkey'} = 0; # DLKeyðgp·é=1,DLkeyK{=2 +$set{'up_ext'} = 'txt,lzh,zip,rar,gca,mpg,mp3,avi,swf,bmp,jpg,gif,png'; #Abv[hÅ«éî{g£q ¼pp¬¶ ,ÅæØé +$set{'up_all'} = 0; #o^ÈOÌàÌàUP³¹çêéæ¤É·é=1 +$set{'ext_org'} = 0; #$set{'up_all'}ª1ÌIWiÌg£qÉ·é=1 +$set{'deny_ext'} = 'php,php3,phtml,rb,sh,bat,dll'; #eÖ~Ìg£q ¼pp¬¶ ,ÅæØé +$set{'change_ext'} = 'cgi->txt,pl->txt,log->txt,jpeg->jpg,mpeg->mpg'; #g£qÏ· O->ã ¼pp¬¶ ,ÅæØé + +$set{'home_url'} = ''; #[HOME]ÌNæ ÎpXÍ http://©çnÜéâÎpX +$set{'html_all'} = 1; #[ALL]ðo·=1 +$set{'dummy_html'} = 0; #t@CÂÊHTMLð쬷é Êít@CÌÝ=1,DLKeyÝèt@CÌÝ=2,·×Ä=3 +$set{'find_crypt'} = 1; #ûZIPðo·é=1 +$set{'binary_compare'} = 0; #ù¶t@CÆoCiär·é=1 +$set{'post_flag'} = 0; #PostKeyðgp·é=1 +$set{'post_key'} = 'postkey'; #PostKey ,ÅæØéÆ¡wè ex.(postkey1,postkey2) +$set{'disp_error'} = 1; #[U[ÉG[ð\¦·é=1 +$set{'error_level'} = 1; #G[OðL^·é=1 +$set{'error_log'} = './error.cgi'; #G[Ot@C¼ +$set{'error_size'} = 1024; # G[OÅåeÊ(KB) §Àȵ=0 +$set{'zero_clear'} = 1; #t@Cª©Â©çÈ¢êO©çí·é=1 + +$set{'disp_comment'} = 1; #Rgð\¦·é=1 +$set{'disp_date'} = 1; #útð\¦·é=1 +$set{'disp_size'} = 1; #TCYð\¦·é=1 +$set{'disp_mime'} = 1; #MIMETYPEð\¦·é=1 +$set{'disp_orgname'} = 1; #IWit@C¼ð\¦·é=1 + +$set{'per_upfile'} = 0666; #Abv[ht@CÌp[~bV suexec=0604,other=0666 +$set{'per_dir'} = 0777; #\[XAbvfBNgÌp[~bV suexec=0701,other=0777 +$set{'per_logfile'} = 0666; #Ot@CÌp[~bV@suexec=0600,other=0666 +$set{'link_target'} = ''; #target®« + +#------ +$set{'ver'} = '2005/10/10e'; +$set{'char_delname'} = 'D'; + +$in{'time'} = time(); $in{'date'} = conv_date($in{'time'}); +$in{'addr'} = $ENV{'REMOTE_ADDR'}; +$in{'host'} = gethostbyaddr(pack('C4',split(/\./, $in{'addr'})), 2) || $ENV{'REMOTE_HOST'} || '(none)'; + +if($in{'addr'} eq $in{'host'}){ $in{'host'} = '(none)'; } + +$set{'html_head'} =<<"EOM"; +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> +<html lang="ja"> +<HEAD> +<META name="robots" content="noindex,nofollow"> +<META name="ROBOTS" content="NOINDEX,NOFOLLOW"> +<META http-equiv="Content-type" content="text/html; charset=Shift_JIS"> +<META http-equiv="Pragma" content="no-cache"> +<META http-equiv="Cache-Control" content="no-cache"> +<META http-equiv="Expires" content="0"> +<TITLE>Uploader</TITLE> +EOM + +$set{'html_css'} =<<"EOM"; +<META http-equiv="Content-Style-Type" content="text/css"> +<STYLE type="text/css"><!-- +input,td{ font-size: 10pt;font-family:Chicago,Verdana,Arial,sans-serif,"lr oSVbN"; } +a:hover { background-color:#EECCCC; } +input,textarea{ border-top : 1px solid ; border-bottom : 1px solid ; border-left : 1px solid ; border-right : 1px solid ;font-size:10pt;background-color:#FFFFFF; } +--> +</STYLE> +EOM + +unless(-e $set{'log_file'}){ &init; } +unless(-e $set{'base_html'}){ &makehtml; } +{ #fR[h + my $readbuffsize = 1024*8; + if ($ENV{'REQUEST_METHOD'} eq "POST" && $ENV{'CONTENT_TYPE'} =~ /multipart\/form-data/i){ + if ($ENV{'CONTENT_LENGTH'} > ($set{'max_size'} * 1024 + 1024)){ if($ENV{'SERVER_SOFTWARE'} =~ /IIS/){ while(read(STDIN,my $buff,$readbuffsize)){} } &error(106,$ENV{'CONTENT_LENGTH'});} + }else{ + if ($ENV{'CONTENT_LENGTH'} > 1024*100){ error(98); } + } + my %ck; foreach(split(/;/,$ENV{'HTTP_COOKIE'})){ my($key,$val) = split(/=/); $key =~ s/\s//g; $ck{$key} = $val;} + my @ck = split(/<>/,$ck{'SN_USER'}); + if(length($ck[0]) < 5){ + my @salt = ('a'..'z', 'A'..'Z', '0'..'9', '.', '/'); srand; + my $salt = $salt[int(rand(@salt))] . $salt[int(rand(@salt))]; + $in{'user'} = crypt($in{'addr'}.$in{'time'}, $salt); + }else{ $in{'user'} = $ck[0]; } + + if($ENV{'REQUEST_METHOD'} eq "POST" && $ENV{'CONTENT_TYPE'} =~ /multipart\/form-data/i){ + my %FORM; my $subbuff; my $filename; my $valuename; + my $upflag; my $valueflag; my $bound; my $mime; + my $readlength = 0; + my $random = int(rand(900000)) + 100000; + my $endflag = 0; + binmode(STDIN); + while(<STDIN>){ $readlength += length($_); if(/(--.*)\r\n$/){ $bound = $1; last; }} + if(-e "$set{'src_dir'}$random.temporary"){ $random++; } + if(-e "$set{'src_dir'}$random.temporary"){ $random++; } + if(-e "$set{'src_dir'}$random.temporary"){ &error(204); } + + open(OUT,">$set{'src_dir'}$random.temporary"); + binmode(OUT); + my $formbuff; + while(my $buff = <STDIN>){ + $readlength += length($buff); + if($upflag == 1){ if($buff =~ /Content-Type:\s(.*)\r\n$/i){ $mime = $1; } $upflag++; next;} + if($upflag == 2){ + while(1){ + my $readblen; my $filebuff; + if($ENV{'CONTENT_LENGTH'} - $readlength < $readbuffsize){ $readblen = $ENV{'CONTENT_LENGTH'} - $readlength; } + else{ $readblen = $readbuffsize; } + if(!read(STDIN,$filebuff,$readblen)){ last }; + $readlength += length($filebuff); + if($ENV{'CONTENT_LENGTH'} - $readlength < $readbuffsize){ + my $readblen = $ENV{'CONTENT_LENGTH'} - $readlength; + read(STDIN,my $subbuff,$readblen); + $readlength += length($subbuff); + $filebuff .= $subbuff; + $endflag = 1; + } + my $offset = index($filebuff,$bound); + if($offset >= 0){ + $buff = substr($filebuff,0,$offset-2); my $subbuff = substr($filebuff,$offset); + print OUT $buff; $upflag = 0; $formbuff .= $subbuff; last; + }else{ print OUT $filebuff; } + } + if($endflag){ last; } + next; + } + if($buff =~ /^Content-Disposition:\sform-data;\sname=\"upfile\";\sfilename=\"(.*)\"\r\n$/i){ + $filename = $1; $upflag = 1; next; + } + $formbuff .= $buff; + } + close(OUT); + chmod($set{'per_upfile'},"$set{'src_dir'}$random.temporary"); + { my $value; + foreach my $buff(split(/\r\n/,$formbuff)){ + $buff .= "\r\n"; + if($buff =~ /^$bound\-\-/){ $FORM{$value} =~ s/\r\n$//; $valueflag = 0; last;} + if($buff =~ /^$bound/){ $FORM{$value} =~ s/\r\n$//; $valueflag = 0; next;} + if($valueflag == 1){ $valueflag++; next; } + if($valueflag == 2){ $FORM{$value} .= $buff; } + if($buff =~ /^Content-Disposition: form-data; name=\"(.+)\"\r\n$/){ $value = $1; $valueflag++; } + } + } + if($upflag || $valueflag){ unlink("$set{'src_dir'}$random.temporary"); &error(108);} + + $in{'org_pass'} = $in{'pass'} = $FORM{'pass'}; + $in{'dlkey'} = $FORM{'dlkey'}; + $in{'comment'} = $FORM{'comment'}; + $in{'jcode'} = $FORM{'jcode'}; + $in{'postkey'} = $FORM{'postkey'}; + $in{'upfile'} = $filename; + $in{'type'} = $mime; + $in{'tmpfile'} = "$set{'src_dir'}$random.temporary"; + $in{'orgname'} = $in{'upfile'}; + if(-s "$in{'tmpfile'}" == 0){ unlink("$in{'tmpfile'}"); &error(99) } + if($set{'min_flag'} && ((-s "$in{'tmpfile'}") < $set{'min_size'} * 1024)){ &error(107,(-s "$in{'tmpfile'}"));} + if((-s "$in{'tmpfile'}") > $set{'max_size'} * 1024){ &error(106,(-s "$in{'tmpfile'}"));} + if($set{'post_flag'} && !check_postkey($in{'postkey'})){ &error(109); } + if($set{'dlkey'} == 2 && !$in{'dlkey'}){ unlink("$in{'tmpfile'}"); &error(61); } + }else{ + my ($buffer,%FORM,@admin_delno); + if ($ENV{'REQUEST_METHOD'} eq "POST") { read(STDIN, $buffer, $ENV{'CONTENT_LENGTH'});} + else { $buffer = $ENV{'QUERY_STRING'}; } + my @pairs = split(/&/,$buffer); + foreach my $pair (@pairs) { + my ($name, $value) = split(/=/, $pair); + $value =~ tr/+/ /; + $value =~ s/%([a-fA-F0-9][a-fA-F0-9])/pack("C", hex($1))/eg; + if($name eq 'admin_delno'){ + push(@admin_delno,$value); + }else{ + $FORM{$name} = $value; + } + } + $in{'delpass'} = $FORM{'delpass'}; + $in{'delno'} = $FORM{'delno'}; + $in{'file'} = $FORM{'file'}; + $in{'dlkey'} = $FORM{'dlkey'}; + $in{'mode'} = $FORM{'mode'}; + $in{'checkmode'} = $FORM{'checkmode'}; + $in{'admin_delno'} = join(',',@admin_delno); + if($in{'delno'} eq $set{'admin_name'} && $in{'delpass'} eq $set{'admin_pass'}){ &admin_mode(); } + if(!$in{'delno'} && $in{'delpass'} eq $set{'admin_pass'}){ &makehtml; &quit; } + } + + my @denyhost = split(/,/,$set{'deny_host'}); + foreach my $value (@denyhost){ + if ($in{'addr'} =~ /$value/ || $in{'host'} =~ /$value/){ &error(101);} + } + + my @form = ($in{'comment'},$in{'orgname'},$in{'type'},$in{'dlkey'}); + foreach my $value (@form) { + if (length($value) > 128) { $value = substr($value,0,128).'...'; } +# $value =~ s/&/&/g; + $value =~ s/"/"/g; + $value =~ s/</</g; + $value =~ s/>/>/g; + $value =~ s/\r//g; + $value =~ s/\n//g; + $value =~ s/\t//g; + $value =~ s/\0//g; + } + ($in{'comment'},$in{'orgname'},$in{'type'},$in{'dlkey'}) = @form; +} + + +if($in{'mode'} eq 'delete'){ &delete(); &quit(); } +if($in{'mode'} eq 'dl'){ &dlfile;} #DL +if(!$in{'upfile'}){ &error(99); } + +{#C + + open(IN,$set{'log_file'})||&error(303); + my @log = <IN>; + close(IN); + my ($no,$lastip,$lasttime) = split(/<>/,$log[0]); + + if($set{'interval'} && $in{'time'} <= ($lasttime + $set{'interval'}) && $in{'addr'} eq $lastip){ &error(203);} + $in{'ext'} = extfind($in{'orgname'}); if(!$in{'ext'}){ &error(202); } + + my $orgname; + if(split(/\//,$in{'orgname'}) > split(/\\/,$in{'orgname'})){ my @name = split(/\//,$in{'orgname'}); $orgname = $name[$#name]; } + else{ my @name = split(/\\/,$in{'orgname'}); $orgname = $name[$#name];} + + my @salt = ('a'..'z', 'A'..'Z', '0'..'9', '.', '/'); + srand; + my $salt = $salt[int(rand(@salt))] . $salt[int(rand(@salt))]; + $in{'pass'} = crypt($in{'pass'}, $salt); + + if($set{'binary_compare'}){ + my @files = globfile("$set{'src_dir'}",".*"); + my @dir = globdir("$set{'src_dir'}",".*"); + foreach my $dir (@dir){ push(@files,globfile($dir."/",".*")); } + foreach my $value (@files){ + next if($value =~ /\.temporary$/); + if(binarycmp($in{'tmpfile'},$value)){ unlink($in{'tmpfile'}); &error(205,$value);} + } + } + + if($set{'find_crypt'}){ + open(FILE,$in{'tmpfile'}); binmode(FILE); seek(FILE,0,0); read(FILE,my $buff,4); my $crypt_flag = 0; + if($buff =~ /^\x50\x4b\x03\x04$/){ seek(FILE,6,0); read(FILE,my $buff,1); $crypt_flag = 1 if(($buff & "\x01") eq "\x01"); } + close(FILE); + $in{'comment'} = '<font color="#FF0000">*</font>'.$in{'comment'} if($crypt_flag); + } + + open(IN,$set{'log_file'})||&error(303); + @log = <IN>; + close(IN); + ($no,$lastip,$lasttime) = split(/<>/,$log[0]); + shift(@log); + $no++; + my $tmpno = sprintf("%04d",$no); + + my $dlsalt; + my $filedir; + my $allsize = (-s $in{'tmpfile'}); + + if($set{'dlkey'} && $in{'dlkey'}){ + my @salt = ('a'..'z', 'A'..'Z', '0'..'9'); srand; + for (my $c = 1; $c <= 20; ++$c) { $dlsalt .= $salt[int(rand(@salt))]; } + $filedir = "$set{'src_dir'}$set{'file_pre'}${tmpno}.$in{'ext'}_$dlsalt/"; + mkdir($filedir,$set{'per_dir'}); + rename("$in{'tmpfile'}","$filedir$set{'file_pre'}$tmpno.$in{'ext'}"); + open(OUT,">${filedir}index.html"); + close(OUT); + chmod($set{'per_upfile'},"${filedir}index.html"); + $in{'comment'} = '<font color="#FF0000">[DLKey] </font>'.$in{'comment'}; + }else{ + undef $in{'dlkey'}; + rename("$in{'tmpfile'}","$set{'src_dir'}$set{'file_pre'}$tmpno.$in{'ext'}"); + } + + if (length($orgname) > 128) { $orgname = substr($orgname,0,128).'...'; } + + my @note; + if($set{'post_flag'} && $set{'post_key'}){ + push(@note,'PostKey:'.$in{'postkey'}); + } + if($ENV{'SERVER_SOFTWARE'} =~ /Apache|IIS/){ + my $disptime; + my $time = time() - $in{'time'}; + my @str = ('Upload:','b'); + my $disptime = $time.$str[1]; + push(@note,$str[0].$disptime); + } + if($in{'dlkey'}){ + my @salt = ('a'..'z', 'A'..'Z', '0'..'9', '.', '/'); srand; + my $salt = $salt[int(rand(@salt))] . $salt[int(rand(@salt))]; + my $crypt_dlkey = crypt($in{'dlkey'}, $salt); + push(@note,"DLKey<!-- DLKey:".$crypt_dlkey." --><!-- DLpath:".$dlsalt." -->"); + } + my $note = join(',',@note); + my $usersalt = substr($in{'user'},0,2); + my $userid = crypt($in{'user'},$usersalt); + $in{'time'} = time(); +# $in{'date'} = conv_date(time()); + my @new; + $new[0] = "$no<>$in{'addr'}<>$in{'time'}<>1\n"; + my $addlog = "$no<>$in{'ext'}<>$in{'date'}<>$in{'comment'}<>$in{'type'}<>$orgname<>$in{'addr'}<>$in{'host'}<>$in{'pass'},$userid<>$set{'file_pre'}<>$note<>1\n"; + $new[1] = $addlog; + +# open(OUT,">>./alllog.cgi"); print OUT $addlog; close(OUT); + + my $i = 2; + + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$value); + if(!$dummy){ $filepre = $set{'file_pre'};} + $no = sprintf("%04d",$no); + + my $filename; + my $filedir; + if($note =~ /DLpath:(.+)\s/){ + my $dlpath = $1; + $filename = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/$filepre$no.$ext"; + $filedir = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/"; + }else{ + $filename = "$set{'src_dir'}$filepre$no.$ext"; + } + $allsize += (-s $filename); + + if($i <= $set{'max_log'} && !($set{'max_all_flag'} && $set{'max_all_size'}*1024 < $allsize)){ + if((-e $filename)||!$set{'zero_clear'}){ push(@new,$value); $i++; } + }else{ + if(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } } rmdir($filedir); + }elsif(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } } rmdir($filedir); + }elsif(-e $filename){ + push(@new,$value); + }else{ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } } rmdir($filedir); + } + } + } + logwrite(@new); + if($in{'dlkey'} && ( $set{'dummy_html'} == 2 || $set{'dummy_html'} == 3)){ + &makedummyhtml("$set{'file_pre'}$tmpno.$in{'ext'}",$in{'comment'},"$set{'file_pre'}$tmpno.$in{'ext'}",$dlsalt,$in{'date'},$in{'type'},$orgname,$no); + }elsif(!$in{'dlkey'} && ($set{'dummy_html'} == 1 || $set{'dummy_html'} == 3)){ + &makedummyhtml("$set{'file_pre'}$tmpno.$in{'ext'}"); + } + &makehtml(); &quit(); +} + +sub makehtml{ + + my ($buff,$init,$postval,$dlkey); + my $page = 0; my $i = 1; + + open(IN,$set{'log_file'})||&error(303); + my $log = my @log = <IN>; + close(IN); + + if($log == 1){ $log++; $init++;} + my $lastpage = int(($log - 2)/$set{'pagelog'}) + 1; + $postval = ' obj.postkey.value = unescape(p[1]);' if($set{'post_flag'}); + my $header =<<"EOM"; +$set{'html_head'}<META http-equiv="Content-Script-Type" content="text/javascript"> +<script type="text/javascript"> +<!-- +function getCookie(obj,cookiename){ + var i,str; c = new Array(); p = new Array("",""); str = document.cookie;c = str.split(";"); + for (i = 0; i < c.length; i++) { if (c[i].indexOf(cookiename+"=") >= 0) { p = (c[i].substr(c[i].indexOf("=")+1)).split("<>"); break; }} + if(cookiename == "SN_UPLOAD"){ obj.pass.value = unescape(p[0]);$postval } + else if(cookiename == "SN_DEL"){ obj.delpass.value = unescape(p[0]);} + return true; +} +function delnoin(no){ + document.Del.delno.value = no; + document.Del.del.focus(); +} +//--> +</script> +$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF" onload="getCookie(document.Form,'SN_UPLOAD');getCookie(document.Del,'SN_DEL');"> +<table summary="title" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Uploader</font></strong></td></tr></table> +<p> +Now.. Testing.. +</p> +EOM + my $maxsize = 'Max '.dispsize($set{'max_size'}*1024); + my ($minsize,$total); + if($set{'min_flag'}){ $minsize = 'Min '.dispsize($set{'min_size'}*1024).' - '; } + if($set{'max_all_flag'}){ $total .= ' Total '.dispsize($set{'max_all_size'}*1024);} + $header .= qq|<FORM METHOD="POST" ENCTYPE="multipart/form-data" ACTION="$set{'base_cgi'}" name="Form">FILE $minsize$maxsize (*$set{'max_log'}Files$total)<br>|; + $header .='<INPUT TYPE=file SIZE="40" NAME="upfile">'; + $header .= ' DLKey: <INPUT TYPE=text SIZE="8" NAME="dlkey" maxlength="8">' if($set{'dlkey'}); + $header .= ' +DELKey: <INPUT TYPE=password SIZE="10" NAME="pass" maxlength="8"><br> +COMMENT<br> +<INPUT TYPE=text SIZE="45" NAME="comment"> +<INPUT TYPE=hidden NAME="jcode" VALUE="¿"> +<INPUT TYPE=submit VALUE="Upload"><INPUT TYPE=reset VALUE="Cancel"><br> +'; + if($set{'post_flag'}){ $header .= 'PostKey<br><INPUT TYPE=password SIZE="10" NAME="postkey" maxlength="10">'; } + $header .= '</FORM>'; + + my $allsize = 0; + my @files = globfile("$set{'src_dir'}",".*"); + my @dir = globdir("$set{'src_dir'}",".*"); + foreach my $dir (@dir){ push(@files,globfile($dir."/",".*")); } + foreach my $value (@files){ $allsize += (-s "$value"); } + + $allsize = dispsize($allsize); + + my $footer = "</table><HR size=1>Used ${allsize}\n<br>"; + if($set{'up_all'} && !$set{'ext_org'}){ $footer .= $set{'up_ext'}.' +'; } + elsif(!$set{'up_all'}){ $footer .= $set{'up_ext'}; } + $footer .= "\n<table summary=\"footer\" width=\"100%\"><tr><td><div align=left><FORM METHOD=POST ACTION=\"$set{'base_cgi'}\" name=\"Del\"><span style='font-size:9pt'><input type=hidden name=mode value=delete>No.<input type=text size=4 name=delno> key<input type=password size=4 name=delpass> <input type=submit value=\"del\" name=del></span></form></div>\n"; + $footer .= "</td><td><div align=right><!-- $set{'ver'} --><a href=\"http://sugachan.dip.jp/download/\" target=\"_blank\"><small>Sn Uploader</small></a></div></td></tr></table>\n</body>\n</html>"; + + my $info_title = "<table summary=\"upinfo\" width=\"100%\">\n<tr><td></td><td>NAME</td>"; + if($set{'disp_comment'}){ $info_title .= "<td>COMMENT</td>"; } if($set{'disp_size'}){ $info_title .= "<td>SIZE</td>"; } if($set{'disp_date'}){ $info_title .= "<td>DATE</td>"; } + if($set{'disp_mime'}){ $info_title .= "<td>MIME</td>"; } if($set{'disp_orgname'}){ $info_title .= "<td>ORIG</td>"; } + $info_title .= "</tr>\n"; + + my $home_url_link; + if($set{'home_url'}){ $home_url_link = qq|<a href="$set{'home_url'}">[HOME]</a> |;} + if($set{'html_all'}){ + my $buff; my $no = 1; my $time = time; my $subheader; + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$dummy) = split(/<>/,$value); + if(!$dummy){ next; } + $buff .= makeitem($value); + } + $subheader .= "[ALL] "; + while($no <= $lastpage){ + if($no == $page) { $subheader .= "\[$no\] ";} + else{ if($no == 1){ $subheader .= "<a href=\"$set{'http_html_path'}$set{'base_html'}?$time\">\[$no\]</a> "} + else{$subheader .= "<a href=\"$set{'http_html_path'}$no.html?$time\">\[$no\]</a> ";} } + $no++; + } + $subheader .= $info_title; + open(OUT,">$set{'html_dir'}all.html")||&error(306,"$set{'html_dir'}all.html"); + print OUT $header."<hr size=1>".$home_url_link.$subheader."<hr size=1>".$buff.$footer; + close(OUT); + chmod($set{'per_upfile'},"$set{'html_dir'}all.html"); + }else{ unlink("$set{'html_dir'}all.html"); } + + while($log > $i){ + $buff .= makeitem($log[$i]) unless($init); + if(($i % $set{'pagelog'}) == 0||$i == $log -1){ + $page++; my $subheader; my $no = 1; my $time = time; + if($set{'html_all'}){ $subheader .= "<a href=\"./all.html?$time\">[ALL]</a> "; } + while($no <= $lastpage){ + if($no == $page) { $subheader .= "\[$no\] ";} + else{ if($no == 1){ $subheader .= "<a href=\"$set{'http_html_path'}$set{'base_html'}?$time\">\[$no\]</a> "} + else{$subheader .= "<a href=\"$set{'http_html_path'}$no.html?$time\">\[$no\]</a> ";} + } + $no++; + } + $subheader .= $info_title; + my $loghtml; + if($page == 1){ $loghtml = "$set{'html_dir'}$set{'base_html'}"; } + else{ $loghtml = "$set{'html_dir'}$page.html"; } + + open(OUT,">$loghtml") || &error(306,"$loghtml"); + print OUT $header."<hr size=1>".$home_url_link.$subheader."<hr size=1>".$buff.$footer; + close(OUT); + chmod($set{'per_upfile'},$loghtml); + undef $buff; + } + $i++; + } + + while($page < 1000){ + $page ++; + if(-e "$set{'html_dir'}$page.html"){ unlink("$set{'html_dir'}$page.html"); }else{ last; } + } +} + +sub delete{ + my $mode = $_[0]; + my @delno = split(/,/,$_[1]); + my $delno; my $flag = 0; my $tmpaddr; + my $delnote; + + if($in{'delno'} =~ /(\d+)/){ $delno = $1; } + if($mode ne 'admin' && !$in{'delno'}){ return; } + elsif($mode ne 'admin' && !$delno){ &error(401,$in{'delno'}); } + + open(IN,$set{'log_file'})|| &error(303); + my @log = <IN>; + close(IN); + + if($in{'addr'} =~ /(\d+).(\d+).(\d+).(\d+)/){ $tmpaddr = "$1.$2.$3."; } + my $findflag = 0; + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$value); + $delnote = $note; + my $delflag = 0; + if(!$addr){ next; } + if($mode eq 'admin'){ + foreach my $delno (@delno){ if($no == $delno){ $delflag = 1; last; } } + }elsif($no == $delno){ + $findflag = 1; + unless ($addr =~ /^$tmpaddr/){ + my ($pass,$id) = split(/,/,$pass); + my $delpass = $in{'delpass'} || $in{'addr'}.time(); + my $salt = substr($pass, 0, 2); $delpass = crypt($delpass,$salt); + my $usersalt = substr($in{'user'},0,2); my $userid = crypt($in{'user'},$usersalt); + if ($in{'delpass'} ne $set{'admin_pass'} && $delpass ne $pass && $userid ne $id){ + if($mode ne 'admin'){ if(!$dummy){ $filepre = $set{'file_pre'};} $no = sprintf("%04d",$no); &error(404,"$filepre$no.$ext");} + } + } + $delflag = 1; + } + if($delflag){ +# open(OUT,">>./del.cgi"); print OUT $value; close(OUT); + $flag = 1; + if(!$dummy){ $filepre = $set{'file_pre'};} + $no = sprintf("%04d",$no); + my $filename; + my ($dlpath,$filedir); + if($delnote =~ /DLpath:(.+)\s/){ + $dlpath = $1; + $filename = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/$filepre$no.$ext"; + $filedir = "$set{'src_dir'}$filepre$no.${ext}_$dlpath/"; + }else{ + $filename = "$set{'src_dir'}$filepre$no.$ext"; + } + + if(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } rmdir($filedir);} undef $value; + }elsif(unlink($filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } rmdir($filedir);} undef $value; + }elsif(!(-e $filename)){ + unlink("$set{'src_dir'}$filepre$no.$ext.html"); if($filedir){ foreach(globfile($filedir,".*")){ unlink; } rmdir($filedir);} undef $value; + }else{ + if($mode ne 'admin'){ &error(403,"$filepre$no.$ext");} + } + } + } + if($mode ne 'admin' && !$findflag){ &error(402,$delno); } + if($flag){ + logwrite(@log); + &makehtml(); + } +} + + +sub quit{ + my ($cookiename,$buff); + my $flag = 0; + my @tmpfiles = globfile("$set{'src_dir'}","\.temporary"); + foreach my $value (@tmpfiles){ if((stat($value))[10] < time - 60*60){ unlink("$value"); $flag++; } } + &makehtml() if($flag); + $buff =<<"EOM"; +$set{'html_head'}<META HTTP-EQUIV="Refresh" CONTENT="1;URL=$set{'http_html_path'}$set{'base_html'}"> +EOM + if($in{'jcode'} || $in{'mode'} eq 'delete'){ + $buff .=<<"EOM"; +<META HTTP-EQUIV="Set-Cookie" content="SN_USER=$in{'user'}<>1; path=/; expires=Tue, 31-Dec-2030 23:59:59 GMT"> +<META HTTP-EQUIV="CONTENT-SCRIPT-TYPE" CONTENT="text/javascript"> +<script type="text/javascript"> +<!-- +setCookie(); +function setCookie() { + var key1,key2; + var tmp = "path=/; expires=Tue, 31-Dec-2030 23:59:59; "; +EOM + if($in{'jcode'}){ + my %ck; foreach(split(/;/,$ENV{'HTTP_COOKIE'})){ my($key,$val) = split(/=/); $key =~ s/\s//g; $ck{$key} = $val;} + my @ck = split(/<>/,$ck{'SN_DEL'}); + if(!$ck[0] && $in{'org_pass'}){ $buff .= qq|\tdocument.cookie = "SN_DEL="+escape('$in{'org_pass'}')+"<>;"+ tmp;\n|;} + $cookiename = 'SN_UPLOAD'; $buff .= "\tkey1 = escape('$in{'org_pass'}'); key2 = escape('$in{'postkey'}');\n";} + else{ $cookiename = 'SN_DEL'; $buff .= "\tkey1 = escape('$in{'delpass'}'); key2 = '';\n"; } + $buff .= qq|\tdocument.cookie = "$cookiename="+key1+"<>"+key2+"; "+ tmp;\n}\n//-->\n</script>\n|; + } + $buff .=<<"EOM"; +<body> +<br><br><div align=center><font size="+1"><br><br> +<a href="$set{'http_html_path'}$set{'base_html'}?$in{'time'}">click here!</a></font><br> +</div> +</body></html> +EOM + print "Content-type: text/html\n\n"; + print $buff; + exit; +} + +sub admin_mode{ + &errorclear() if($in{'mode'} eq 'errorclear'); + &delete('admin',$in{'admin_delno'}) if($in{'mode'} eq 'delete'); + + open(IN,$set{'log_file'})||error(303); + my @log = <IN>; + close(IN); + + my ($header,$buff,$footer,$value); + $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +EOM + + $buff .= leaddisp(0,1,1).'<a name="up"></a><table summary="title" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Upload Info</font></strong></td></tr></table>'; + $buff .= qq|<table summary="check"><tr><td><form action="$set{'base_cgi'}" method="POST"><input type=hidden name="checkmode" value="allcheck"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="·×Ä`FbN"></form></td><td><form action="$set{'base_cgi'}" method="POST"><input type=hidden name="checkmode" value="nocheck"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="·×ÄO·"></form></td><td><form action="$set{'base_cgi'}" method="POST"><input type=hidden name=delpass value="$set{'admin_pass'}"><input type=submit value="HTMLðXV·é/OAEg"></form></td></tr></table>\n<form action="$set{'base_cgi'}" method="POST"><input type=hidden name="mode" value="delete"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="`FbNµ½àÌðí"><br>\n|."<table summary=\"upinfo\" width=\"100%\">\n<tr><td>DEL</td><td>NAME</td><td>COMMENT</td><td>SIZE</td><td>ADDR</td><td>HOST</td><td>DATE</td><td>NOTE</td><td>MIME</td><td>ORIG</td></tr>\n"; + shift(@log); + foreach (@log){ $buff .= makeitem($_,'admin'); } + $buff .= '</table></form><br><br>'; + + if($set{'error_level'}){ + $buff .= leaddisp(-1,0,1).'<a name="error"></a><table summary="errortitle" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Error Info</font></strong></td></tr></table>'; + $buff .= qq|<form action="$set{'base_cgi'}" method="POST"><input type=hidden name=mode value="errorclear"><input type=hidden name=delno value="$in{'delno'}"><input type=hidden name=delpass value="$in{'delpass'}"><input type=submit value="G[ONA"></form>|; + $buff .= "<table summary=\"errorinfo\" width=\"100%\">\n<tr><td>DATE</td><td>ADDR</td><td>HOST</td><td>NOTE</td></tr>\n"; + if(open(IN,$set{'error_log'})){ @log = reverse(<IN>); close(IN); foreach (@log){ my ($date,$no,$note,$addr,$host) = split(/<>/); $buff .= "<tr><td>$date</td><td>$addr</td><td>$host</td><td>$note</td></tr>\n"; }} + $buff .= "</table><br><br>\n"; + } + + $buff .= leaddisp(-1,-1,0); + $buff .= '<a name="set"></a><table summary="settitle" width="100%"><tr><td bgcolor="#caccff"><strong><font size="4" color="#3366cc">Setting Info</font></strong></td></tr></table>'."\n<table summary=\"setting\">\n"; + $buff .= tablestr('XNvgVer',$set{'ver'}); + $buff .= tablestr('COt@C',$set{'log_file'}); + if($set{'error_level'}){ + $buff .= tablestr('G[Ot@C',$set{'error_log'}); + if($set{'error_size'}){ $buff .= tablestr('G[OÅåeÊ',dispsize($set{'error_size'}*1024).' '.($set{'error_size'}*1024).'Bytes'); } + else{ $buff .= tablestr('G[OÅåeʧÀ','³'); } + }else{ $buff .= tablestr('G[OL^','³'); } + $buff .= tablestr('Û',$set{'max_log'}); + $buff .= tablestr('ÅåeeÊ',dispsize($set{'max_size'}*1024).' '.($set{'max_size'}*1024).'Bytes'); + + if($set{'min_flag'}){ $buff .= tablestr('Ŭ§ÀeÊ',dispsize($set{'min_size'}*1024).' '.($set{'min_size'}*1024).'Bytes'); } + else{ $buff .= tablestr('Ŭ§ÀeÊ',"³"); } + if($set{'max_all_flag'}){ $buff .= tablestr('eʧÀ',dispsize($set{'max_all_size'}*1024).' '.($set{'max_all_size'}*1024).'Bytes'); } + else{ $buff .= tablestr('eʧÀ',"³"); } + + $buff .= tablestr("t@CÚª«",$set{'file_pre'}); + $buff .= tablestr("HTMLÛ¶fBNg",$set{'html_dir'}); + $buff .= tablestr("t@CÛ¶fBNg",$set{'src_dir'}); + if($set{'http_html_path'} && $set{'html_dir'} ne $set{'http_html_path'}){ $buff .= "<tr><td>HTTP_HTML_PATH</td><td>$set{'http_html_path'}</td></tr>\n";} + if($set{'http_src_path'} && $set{'src_dir'} ne $set{'http_src_path'}){ $buff .= "<tr><td>HTTP_SRC_PATH</td><td>$set{'http_src_path'}</td></tr>\n";} + $buff .= tablestr('1y[WÉ\¦·ét@C',$set{'pagelog'}); + if($set{'interval'} > 0){ $value = $set{'interval'}.'b'; }else{ $value = '³'; } + $buff .= tablestr('¯êIPeÔub§À',$value); + if($set{'up_ext'}){ $set{'up_ext'} =~ s/,/ /g; $buff .= tablestr('eÂ\î{g£q',$set{'up_ext'}); } + if($set{'deny_ext'}){ $set{'deny_ext'} =~ s/,/ /g; $buff .= tablestr('eÖ~g£q',$set{'deny_ext'}); } + if($set{'change_ext'}){ $set{'change_ext'} =~ s/,/ /g; $set{'change_ext'} =~ s/>/>/g; $buff .= tablestr('g£qÏ·',$set{'change_ext'}); } + + if($set{'up_all'}){ $buff .= tablestr('wèOg£qAbv[hÂ','L'); if($set{'ext_org'}){ $buff .= tablestr('wèOt@Cg£q','IWi'); }else{ $buff .= tablestr('wèOt@Cg£q','bin'); }} + else{$buff .= tablestr('wèOg£qAbv[hÂ','³');} + + if($set{'find_crypt'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('ûA[JCuo(ZIP)',$value); + if($set{'binary_compare'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('oCiär',$value); + if($set{'post_flag'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('PostKeye§À',$value); + if($set{'dlkey'}){ if($set{'dlkey'} == 2){$value = 'K{'}else{$value = 'CÓ';}}else{ $value = '³';} + $buff .= tablestr('DLkey',$value); + if($set{'dummy_html'}){ if($set{'dummy_html'} == 3){$value = 'ALL'}elsif($set{'dummy_html'} == 2){$value = 'DLKeyÌÝ';}else{$value = 'Êít@CÌÝ';}}else{ $value = '³';} + $buff .= tablestr('ÂÊHTMLLbV ',$value); + if($set{'disp_error'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('[UG[\¦',$value); + if($set{'zero_clear'}){ $value = 'L'; }else{ $value = '³';} + $buff .= tablestr('íÏt@CXg©®Á',$value); + if($set{'home_url'}){ $buff .= "<tr><td>HOMEURL</td><td>$set{'home_url'}</td></tr>\n";} + + $buff .= '</table></body></html>'; + + print "Content-type: text/html\n\n"; + print $buff; + exit; +} + +sub extfind{ + my $orgname = @_[0]; + my @filename = split(/\./,$orgname); + my $ext = $filename[$#filename]; + $ext =~ tr/[A-Z]/[a-z]/; + foreach my $value (split(/,/,$set{'change_ext'})){ my ($src,$dst) = split(/->/,$value); if($ext eq $src){ $ext = $dst; last; }} + foreach my $value (split(/,/,$set{'deny_ext'})){ if($ext eq $value){ &error(206,$ext); }} + foreach my $value (split(/,/,$set{'up_ext'})){ if ($ext eq $value) { return $value; } } + if(length($ext) >= 5 || length($ext) == 0){ $ext = 'bin'; } + unless ($ext =~ /^[A-Za-z0-9]+$/){ $ext = 'bin'; } + if($set{'up_all'} && $set{'ext_org'}){ return $ext;} + elsif($set{'up_all'}){ return 'bin'; } + return 0; +} + + +sub conv_date{ + my @date = gmtime($_[0] + 9*60*60); + $date[5] -= 100; $date[4]++; + if ($date[5] < 10) { $date[5] = "0$date[5]" ; } if ($date[4] < 10) { $date[4] = "0$date[4]" ; } + if ($date[3] < 10) { $date[3] = "0$date[3]" ; } if ($date[2] < 10) { $date[2] = "0$date[2]" ; } + if ($date[1] < 10) { $date[1] = "0$date[1]" ; } if ($date[0] < 10) { $date[0] = "0$date[0]" ; } + my @w = ('Sun','Mon','Tue','Wed','Thu','Fri','Sat'); + return ("$date[5]/$date[4]/$date[3]($w[$date[6]]),$date[2]:$date[1]:$date[0]"); +} + +sub dispsize{ + my $size = $_[0]; + if($size >= 1024*1024*1024*100){ $size = int($size/1024/1024/1024).'GB';} + elsif($size >= 1024*1024*1024*10){ $size = sprintf("%.1fGB",$size/1024/1024/1024);} + elsif($size > 1024*1024*1024){ $size = sprintf("%.2fGB",$size/1024/1024/1024);} + elsif($size >= 1024*1024*100){ $size = int($size/1024/1024).'MB'; } + elsif($size > 1024*1024){ $size = sprintf("%.1fMB",$size/1024/1024); } + elsif($size > 1024){ $size = int($size/1024).'KB'; } + else{ $size = int($size).'B';} + return $size; +} + +sub makeitem{ + my ($src,$mode) = @_; my ($buff,$check,$target); + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$src); + if(!$dummy){ $filepre = $set{'file_pre'}; } + my $orgno = $no; + $no = sprintf("%04d",$no); + my $size = 0; + my $dlpath = 0; + + if($note =~ /DLpath:(.+)\s/){ + $dlpath = $1; + $size = dispsize(-s "$set{'src_dir'}$filepre$no.${ext}_$dlpath/$filepre$no.$ext"); + }else{ + $size = dispsize(-s "$set{'src_dir'}$filepre$no.$ext"); + } + + my $path = $set{'http_src_path'} || $set{'src_dir'}; + if($set{'link_target'}){ $target = qq| target="$set{'link_target'}"|; } + if($mode eq 'admin'){ + if($dlpath){ $path .= "$filepre$no.${ext}_$dlpath/"; } + if($addr eq $host){ undef $host; } + if($in{'checkmode'} eq 'allcheck'){$check = ' checked';} + $buff = "<tr><td><INPUT TYPE=checkbox NAME=\"admin_delno\" VALUE=\"$no\"$check></td><td><a href=\"$path$filepre$no.$ext\"$target>$filepre$no.$ext</a></td><td>$comment</td><td>$size</td><td>$addr</td><td>$host</td><td>$date</td><td>$note</td><td>$mime</td><td>$orgname</td></tr>\n"; + }else{ + my($d_com,$d_date,$d_size,$d_mime,$d_org); + if($set{'disp_comment'}){ $d_com = "<td>$comment</td>"; } if($set{'disp_size'}){ $d_size = "<td>$size</td>"; } if($set{'disp_date'}){ $d_date= "<td>$date</td>"; } + if($set{'disp_mime'}){ $d_mime = "<td>$mime</td>"; } if($set{'disp_orgname'}){ $d_org = "<td>$orgname</td>"; } + if(-e "$set{'src_dir'}$filepre$no.$ext.html"){$buff = "<tr><td><SCRIPT type=\"text/javascript\" Language=\"JavaScript\"><!--\ndocument.write(\"<a href=\\\"javascript:delnoin($orgno)\\\">$set{'char_delname'}<\\/a>\");\n// --></SCRIPT></td><td><a href=\"$path$filepre$no.$ext.html\"$target>$filepre$no.$ext</a></td>$d_com$d_size$d_date$d_mime$d_org</tr>\n";} + elsif($dlpath){$buff = "<tr><td><SCRIPT type=\"text/javascript\" Language=\"JavaScript\"><!--\ndocument.write(\"<a href=\\\"javascript:delnoin($orgno)\\\">$set{'char_delname'}<\\/a>\");\n// --></SCRIPT></td><td><a href=\"$set{'base_cgi'}?mode=dl&file=$orgno\">$filepre$no.$ext</a></td>$d_com$d_size$d_date$d_mime$d_org</tr>\n";} + else{ $buff = "<tr><td><SCRIPT type=\"text/javascript\" Language=\"JavaScript\"><!--\ndocument.write(\"<a href=\\\"javascript:delnoin($orgno)\\\">$set{'char_delname'}<\\/a>\");\n// --></SCRIPT></td><td><a href=\"$path$filepre$no.$ext\"$target>$filepre$no.$ext</a></td>$d_com$d_size$d_date$d_mime$d_org</tr>\n";} + } + return $buff; +} + +sub makedummyhtml{ + my ($filename,$com,$file,$orgdlpath,$date,$mime,$orgname,$no) = @_; + my $buff; + + if(!$no){ + $buff = "<html><head><title>$filename</title></head><body>"; + $buff .= qq|Download <a href="./$filename">$filename</a>|; + $buff .= '</body></html>'; + }else{ + $buff = cryptfiledl($com,$file,$orgdlpath,$date,$mime,$orgname,$no); + } + + open(OUT,">$set{'src_dir'}$filename.html")||&error(307,"$set{'src_dir'}$filename.html"); + print OUT $buff; + close(OUT); + chmod($set{'per_upfile'},"$set{'src_dir'}$filename.html"); + return 1; +} + + +sub logwrite{ + my @log = @_; + open(OUT,"+>$set{'log_file'}")||&error(304); + eval{ flock(OUT, 2);}; + eval{ truncate(OUT, 0);}; + seek(OUT, 0, 0); + print OUT @log; + eval{ flock(OUT, 8);}; + close(OUT); + chmod($set{'per_upfile'},$set{'log_file'}); + return 1; +} + +sub binarycmp{ + my ($src,$dst) = @_; + return 0 if (-s $src != -s $dst); + open(SRC,$src)||return 0; open(DST,$dst)||return 0; + my ($buff,$buff2); + binmode(SRC); binmode(DST); seek(SRC,0,0); seek(DST,0,0); + while(read(SRC,$buff,8192)){ read(DST,$buff2,8192); if($buff ne $buff2){ close(SRC); close(DST); return 0; } } + close(SRC); close(DST); + return 1; +} + +sub init{ + my $buff; + if(open(OUT,">$set{'log_file'}")){ + print OUT "0<>0<>0<>1\n"; + close(OUT); + chmod($set{'per_logfile'},$set{'log_file'}); + }else{ + $buff = "<tr><td>COÌì¬É¸sµÜµ½</td></tr>"; + } + + unless (-d "$set{'src_dir'}"){ + if(mkdir("$set{'src_dir'}",$set{'per_dir'})){ + chmod($set{'per_dir'},"$set{'src_dir'}"); + open(OUT,">$set{'src_dir'}index.html"); + close(OUT); + chmod($set{'per_upfile'},"$set{'src_dir'}index.html"); + }else{ + $buff .= "<tr><td>SourceÛ¶fBNgÌì¬É¸sµÜµ½</td></tr>"; + } + } + + unless (-d "$set{'html_dir'}"){ + if(mkdir("$set{'html_dir'}",$set{'per_dir'})){ + chmod($set{'per_dir'},"$set{'html_dir'}"); + }else{ + $buff .= "<tr><td>HTMLÛ¶fBNgÌì¬É¸sµÜµ½</td></tr>"; + } + } + + if($buff){ + $buff .= "<tr><td>fBNgÉ«Ý Àª é©mFµÄ¾³¢</td></tr>"; + &error_disp($buff,'init'); + } +} + +sub check_postkey{ + my $inputkey = @_[0]; + my @key = split(/,/,$set{'post_key'}); + foreach my $key (@key){ if($inputkey eq $key){ return 1; } } + return 0; +} + +sub leaddisp{ + my @src = @_; + my ($str,$count); + foreach my $value (@src){ + my ($mark,$name,$link); $count++; + if($count == 1){ $name = 'Upload Info'; $link = 'up'; } + elsif($count == 2){ $name = 'Error Info'; $link = 'error'; next if(!$set{'error_level'}); } + elsif($count == 3){ $name = 'Setting Info'; $link = 'set'; } + if($value){ if($value > 0){ $mark = '¥'; }else{ $mark = '£'; } $str .= qq|<a href="#$link">${mark}${name}</a> |; } + else{ $str .= qq|[$name] |; } + } + return $str; +} + +sub errorclear{ + open(OUT,">$set{'error_log'}")||return 0; + eval{ flock(OUT, 2);}; eval{ truncate(OUT, 0);}; seek(OUT, 0, 0); eval{ flock(OUT, 8);}; close(OUT); + chmod($set{'per_upfile'},$set{'log_file'}); + return 1; +} + +sub tablestr{ + my ($value1,$value2) = @_; + return ("<tr><td>$value1</td><td>$value2</td></tr>\n"); +} + +sub globfile{ + my ($src_dir,$filename) = @_; + opendir(DIR,$src_dir)||return 0; my @dir = readdir(DIR); closedir(DIR); + my @new = (); foreach my $value (@dir){ push(@new,"$src_dir$value") if($value =~ /$filename/ && !(-d "$src_dir$value")); } + return @new; +} + +sub globdir{ + my ($src_dir,$dir) = @_; + opendir(DIR,$src_dir)||return 0; my @dir = readdir(DIR); closedir(DIR); + my @new = (); foreach my $value (@dir){ if($value eq '.' ||$value eq '..' ){ next; } push(@new,"$src_dir$value") if($value =~ /$dir/ && (-d "$src_dir$value")); } + return @new; +} + +sub error_disp{ + my ($message,$mode) = @_; + my $url; + if($mode eq 'init'){ $url = qq|<a href="$set{'base_cgi'}">[[h]</a>|; }else{ $url = qq|<a href="$set{'http_html_path'}$set{'base_html'}">[ßé]</a>|; } + my $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +<div align="center"> +<table summary="error"> +$message +<tr><td></td></tr> +<tr><td><div align="center">$url</div></td></tr> +</table> +<br><br> +<table summary="info"> +<tr> +<td>DATE</td><td>$in{'date'}</td></tr> +<tr><td>ADDR</td><td>$in{'addr'}</td></tr> +<tr><td>HOST</td><td>$in{'host'}</td></tr> +</table> +</div> +</body></html> +EOM + print "Content-type: text/html\n\n"; + print $buff; + exit; +} + +sub error{ + my ($no,$note) = @_; + if (length($note) > 64) { $note = substr($note,0,64).'...'; } + $note =~ s/&/&/g; $note =~ s/\"/"/g; $note =~ s/</</g; $note =~ s/>/>/g; $note =~ s/\r//g; $note =~ s/\n//g; $note =~ s/\t//g; $note =~ s/\0//g; + my ($message,$dispmsg,$flag); + + if($no == 98){ $message = ""; } + elsif($no == 99){ $message = "UpFileȵ"; } + elsif($no == 101){ $message = "eÖ~HOST"; } + elsif($no == 106){ $flag = 1; $message = "POSTTCY´ß"; $note = dispsize($note); $dispmsg= '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>Abv[ht@C('.$note.')Í ÅåeÊÝè('.dispsize($set{'max_size'}*1024).')ðz¦Ä¢Ü·</td></tr>';} + elsif($no == 107){ $flag = 1; $message = "POSTTCY߬"; $note = dispsize($note); $dispmsg= '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>Abv[ht@C('.$note.')Í Å¬eÊÝè('.dispsize($set{'min_size'}*1024).')¢Å·</td></tr>';} + elsif($no == 108){ $flag = 1; $message = "POSTf[^s®S"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>POSTf[^ªs®SÅ·</td></tr>';} + elsif($no == 109){ $flag = 1; $message = "POSTKeysêv"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>POSTKeyªêvµÜ¹ñ</td></tr>';} + elsif($no == 202){ $flag = 1; $message = "g£qí¸"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>eÅ«ég£qÍ'.$set{'up_ext'}.'Å·</td></tr>';} + elsif($no == 203){ $flag = 1; $message = "e·¬"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>¯êIPAhX©ç'.$set{'interval'}.'bÈàÉÄeūܹñ</td></tr>';} + elsif($no == 204){ $flag = 1; $message = "êt@C«ß¸"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>êt@CÌì¬É¸sµÜµ½</td></tr>';} + elsif($no == 205){ $flag = 1; $message = "¯êt@C¶Ý"; $note =~ /([^\/]+)$/; my $filename = $1; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>¯êt@Cª '.$filename.' ɶݵܷ</td></tr>';} + elsif($no == 206){ $flag = 1; $message = "Ö~g£q"; $dispmsg = '<tr><td>t@CðAbv[hūܹñŵ½</td></tr><tr><td>g£q '.$note.' ÍAbv[hūܹñ</td></tr>';} + elsif($no == 303){ $flag = 1; $message = "Ot@CÉÇÝ߸"; $dispmsg = '<tr><td>COÌÇÝÝɸsµÜµ½</td></tr>';} + elsif($no == 304){ $flag = 1; $message = "Ot@Cɫ߸"; $dispmsg = '<tr><td>COÌ«ÝɸsµÜµ½</td></tr>';} + elsif($no == 306){ $message = "t@CXgHTML«ß¸";} + elsif($no == 307){ $message = "t@CHTMLt@C«ß¸";} + elsif($no == 401){ $flag = 1; $message = "íNo.oÅ«¸"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>'.$note.' ©çíNo.ðoūܹñŵ½</td></tr><tr><td>'.$set{'file_pre'}.'0774.zipÌê No.ÉÍ 774 ðü͵ܷ</td></tr>';} + elsif($no == 402){ $flag = 1; $note = sprintf("%04d",int($note)); $message = "íNo.¶Ý¹¸"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>'.$set{'file_pre'}.$note.'.*** ÍCOɶݵܹñ</td></tr>';} + elsif($no == 403){ $flag = 1; $message = "íANZXÛ"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>t@CíðͽµÄ¢Ü·ª '.$note.' Ìt@CÌíªÛ³êܵ½</td></tr><tr><td>ANZXªßèÈêÍÔðu¢ÄÄì·éÆíÅ«é±Æª èÜ·</td></tr>';} + elsif($no == 404){ $flag = 1; $message = "íKeysêv"; $dispmsg = '<tr><td>t@Cðíūܹñŵ½</td></tr><tr><td>'.$note.' íKeyªêvµÜ¹ñŵ½</td></tr>';} + + elsif($no == 51){ $flag = 1; $message = "[DLMode] No.©Â©ç¸"; $dispmsg = '<tr><td>[DLMode] t@Cª©Â©èܹñŵ½</td></tr><tr><td>'.$note.' ©çt@CNo.ðoūܹñŵ½</td></tr>'; } + elsif($no == 52){ $flag = 1; $message = "[DLMode] File©Â©ç¸"; $dispmsg = '<tr><td>[DLMode] t@Cª©Â©èܹñŵ½</td></tr><tr><td>'.$set{'file_pre'}.$note.'.*** ÍCOɶݵܹñ</td></tr>'; } + elsif($no == 53){ $flag = 1; $message = "[DLMode] DLkey¢Ýè"; $dispmsg = '<tr><td>[DLMode] orgDLkeyError</td></tr><tr><td>'.$note.' DLKeyª¢ÝèÅ·</td></tr>'; } + elsif($no == 54){ $flag = 1; $message = "[DLMode] DLkeysêv"; $dispmsg = '<tr><td>[DLMode] orgDLkeyError</td></tr><tr><td>'.$note.' DLKeyªêvµÜ¹ñŵ½</td></tr>'; } + elsif($no == 55){ $flag = 1; $message = "[DLMode] File Oepn Error"; $dispmsg = '<tr><td>[DLMode] Open Error</td></tr><tr><td>'.$note.' t@CÌÇÝÝɸsµÜµ½</td></tr>'; } + elsif($no == 56){ $flag = 1; $message = "[DLMode] File Not Found"; $dispmsg = '<tr><td>[DLMode] Not Found</td></tr><tr><td>'.$note.' t@Cª¶ÝµÜ¹ñ</td></tr>'; } + + elsif($no == 61){ $flag = 1; $message = "DLkey¢Ýè"; $dispmsg = '<tr><td>DLKeyª¢ÝèÅ·</td></tr>'; } + + unlink($in{'tmpfile'}); + if($note){$message .= ' ';} + if($set{'error_level'} && $no > 100){ + unless(-e $set{'error_log'}){ + open(OUT,">$set{'error_log'}"); + close(OUT); + chmod($set{'per_logfile'},$set{'error_log'}); + } + if($set{'error_size'} && ((-s $set{'error_log'}) > $set{'error_size'} * 1024)){ + my $err_bkup = "$set{'error_log'}.bak.cgi"; + unlink($err_bkup); + rename($set{'error_log'},$err_bkup); + open(OUT,">$set{'error_log'}"); + close(OUT); + chmod($set{'per_logfile'},$set{'error_log'}); + } + open(OUT,">>$set{'error_log'}"); + print OUT "$in{'date'}<>$no<>$message$note<>$in{'addr'}<>$in{'host'}<>1\n"; + close(OUT); + } + &error_disp($dispmsg) if($flag && $set{'disp_error'}); + &quit(); +} + +sub dlfile{ + my $msg; + my ($orgdlkey,$orgdlpath); + my ($dlext,$dlfilepre); + my ($dl_date,$dl_comment,$dl_size,$dl_mime,,$dl_orgname); + my $dlno = 0; + my $findflag; + + open(IN,$set{'log_file'})||&error(303); + my @log = <IN>; + close(IN); + shift(@log); + + if($in{'file'} =~ /(\d+)/){ $dlno = $1; } + if($dlno == 0) { &error(51,$in{'file'}); } + + foreach my $value (@log){ + my ($no,$ext,$date,$comment,$mime,$orgname,$addr,$host,$pass,$filepre,$note,$dummy) = split(/<>/,$value); + my @note = split(/,/,$note); + if(int($dlno) == $no){ + $dl_comment = $comment; + $dl_mime = $mime; + $dl_date = $date; + $dl_orgname = $orgname; + $dlext = $ext; + $dlfilepre = $filepre; + foreach my $tmpnote (@note){ + if($tmpnote =~ /\!--\sDLKey:(.+)\s--.*\!--\sDLpath:(.+)\s--/){ + $orgdlkey = $1; + $orgdlpath = $2; + last; + } + } + $findflag = 1; + last; + } + } + + my $dlfile = $dlfilepre.sprintf("%04d",int($dlno)).'.'.$dlext; + if(!(-e "$set{'src_dir'}${dlfile}_$orgdlpath/$dlfile")){ &error(56,"$dlfile----$set{'src_dir'}${dlfile}_$orgdlpath/$dlfile"); } + + if($in{'dlkey'}){ + my $dlsalt = substr($orgdlkey,0,2); + my $dlkey = crypt($in{'dlkey'},$dlsalt); + + if($findflag == 0){ &error(52,$dlfile); } + elsif(!$orgdlkey){ &error(53,$dlfile); } + elsif($orgdlkey ne $dlkey && $set{'admin_pass'} ne $in{'dlkey'}){ &error(54,$dlfile); } + #print "Location: $set{'http_src_path'}${dlfile}_$orgdlpath/$dlfile\n\n"; + my $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'} +<META HTTP-EQUIV="Refresh" CONTENT="1;URL=$set{'http_src_path'}${dlfile}_$orgdlpath/$dlfile"> +</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +<div align="center"> +<br> +<table summary="dlfrom"> +<tr><td>òÎÈ¢êÍ <a href="$set{'http_src_path'}${dlfile}_$orgdlpath/$dlfile">±¿ç</a> ©ç</td></tr> +</table> +</div> +</body></html> +EOM + print "Content-type: text/html\n\n"; + print $buff; + }else{ + my $buff = cryptfiledl($dl_comment,$dlfile,$orgdlpath,$dl_date,$dl_mime,$dl_orgname,$dlno); + print "Content-type: text/html\n\n"; + print $buff; + } + exit; +} + +sub cryptfiledl{ + my($com,$file,$orgdlpath,$date,$mime,$orgname,$no) = @_; + my($d_com,$d_date,$d_size,$d_mime,$d_org); + + if($set{'disp_comment'}){ $d_com = "<tr><td>COMMENT</td><td>$com</td></td>"; } if($set{'disp_size'}){ $d_size = "<tr><td>SIZE</td><td>".dispsize(-s "$set{'src_dir'}${file}_$orgdlpath/$file")." (".(-s "$set{'src_dir'}${file}_$orgdlpath/$file")."bytes)"."</td></tr>"; } if($set{'disp_date'}){ $d_date= "<tr><td>DATE</td><td>$date</td></tr>"; } + if($set{'disp_mime'}){ $d_mime = "<tr><td>ORGMIME</td><td>$mime</td></tr>"; } if($set{'disp_orgname'}){ $d_org = "<tr><td>ORGNAME</td><td>$orgname</td></tr>"; } + + my $buff =<<"EOM"; +$set{'html_head'}$set{'html_css'}</HEAD> +<body bgcolor="#ffffff" text="#000000" LINK="#6060FF" VLINK="#6060FF" ALINK="#6060FF"> +<div align="center"> +<br> +$file ÉÍDLKeyªÝè³êĢܷ +<table summary="dlform"> +<tr><td></td></tr> +<FORM METHOD=POST ACTION="$set{'base_cgi'}" name="DL"> +<tr><td> +<input type=hidden name=file value=$no> +<input type=hidden name=jcode value="¿"> +<input type=hidden name=mode value=dl></td></tr> +$d_com$d_date$d_size$d_mime$d_org +<tr><td>DLKey:<input type=text size=8 name="dlkey"></td></tr> +<tr><td><input type=submit value="DownLoad"></td></tr> +</FORM> +</table> +</div> +</body></html> +EOM + + return $buff; +} \ No newline at end of file